<script data-pm-proxy="intercept"></script><?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[CTO at NCSC - Cyber Defence Analysis]]></title><description><![CDATA[A weekly newsletter by the CTO of the UK's National Cyber Security Centre.

Summarised cyber defence technical content to help operational blue and purple teams be informed and protect their estates and have awareness of wider going on.]]></description><link>https://ctoatncsc.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!XOeg!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe484bb3e-7450-4a87-861e-e7e98f329432_919x919.png</url><title>CTO at NCSC - Cyber Defence Analysis</title><link>https://ctoatncsc.substack.com</link></image><generator>Substack</generator><lastBuildDate>Thu, 03 Sep 2026 16:46:52 GMT</lastBuildDate><atom:link href="/__u/ctoatncsc.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[NCSC]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[ctoatncsc@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[ctoatncsc@substack.com]]></itunes:email><itunes:name><![CDATA[Ollie Whitehouse]]></itunes:name></itunes:owner><itunes:author><![CDATA[Ollie Whitehouse]]></itunes:author><googleplay:owner><![CDATA[ctoatncsc@substack.com]]></googleplay:owner><googleplay:email><![CDATA[ctoatncsc@substack.com]]></googleplay:email><googleplay:author><![CDATA[Ollie Whitehouse]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[CTO at NCSC Summary: week ending August 30th]]></title><description><![CDATA[&#8220;Targeting of operational technology reinforces the need for organisations to understand what is exposed to the internet, address avoidable vulnerabilities, and build long-term cyber resilience.&#8221;]]></description><link>https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-c0b</link><guid isPermaLink="false">https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-c0b</guid><dc:creator><![CDATA[Ollie Whitehouse]]></dc:creator><pubDate>Sun, 30 Aug 2026 07:35:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/IV59lutR-0g" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to the weekly highlights and analysis of the&nbsp;<a href="https://infosec.pub/c/blueteamsec?dataType=Post&amp;sort=New">blueteamsec</a>&nbsp;(and my wider reading). Not everything makes it in, but the best bits do. A community member is doing <a href="https://briefing.workshop1.net/">daily AI generated podcast of the last 24hours of posts</a>.</p><p>Operationally this week a continued focus on Operation Technology and Industrial Control Systems connected to the internet. We released a note on <a href="https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from-internet-exposed-systems-and-edge-devices">Disruptive cyber activity highlights risk from internet-exposed systems and edge devices</a>. </p><p>In the high-level this week:</p><ul><li><p><a href="https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from-internet-exposed-systems-and-edge-devices"><span>Disruptive cyber activity highlights risk from internet-exposed systems and edge devices</span></a><span> - UK </span><strong><span>National Cyber Security Centre</span></strong><span> warns - </span><em><span>&#8220;</span>Targeting of operational technology reinforces the need for organisations to understand what is exposed to the internet, address avoidable vulnerabilities, and build long-term cyber resilience.&#8221;</em></p></li><li><p><a href="https://www.gov.uk/government/publications/five-country-ministerial-communique-2026/five-country-ministerial-communique-2026">Five Country Ministerial Communiqu&#233; 2026</a> - <strong>Home Office</strong> publishes - &#8220;<em>We, the Home Affairs, Interior and Security Ministers of Australia, Canada, New Zealand, the United Kingdom, and the United States (the &#8216;Five Countries&#8217;) convened under Australia&#8217;s Chairmanship, in Sydney on 25-26 August 2026, for the Five Country Ministerial (FCM). In a period marked by heightened global uncertainty, the Five Countries reaffirm our unwavering commitment to promoting shared values, and acting decisively to protect our borders, our economies, and the safety of our communities. In 2026, the Five Countries have driven coordinated action and practical cooperation on several key national security challenges, including the following national security priorities&#8221;</em> - <em>&#8220;We have committed to deepen collaboration with industry on shared national security priorities and public safety, including enabling timely access to frontier models to support secure innovation and strengthen cyber security. We will work together to ensure the safe, secure and responsible application of artificial intelligence to the benefit of our communities.&#8221;</em></p></li><li><p><a href="https://bills.parliament.uk/bills/4035">Cyber Security and Resilience (Network and Information Systems) Bill</a> - <strong>Parliament</strong> updates - <strong>comment:</strong> various amendments being <a href="https://bills.parliament.uk/bills/4035/stages/21083/amendments">suggested and published</a></p></li><li><p><a href="https://iuk-business-connect.org.uk/opportunities/accelerating-adoption-of-quantum-enabled-sensing-and-pnt/">Accelerating adoption of quantum enabled sensing and PNT</a> - <strong>Innovate UK</strong> announces - <em>&#8220;UK registered businesses can apply for a share of up to &#163;14.3 million to accelerate the adoption of quantum enabled position, navigation, and timing (PNT) and sensing technologies by addressing specific technical and commercial barriers.&#8221;</em> - <strong>comment:</strong> PNT is a critical enabler to modern resilient systems with reliable timing often underbaked. </p></li><li><p><a href="https://www.whitehouse.gov/presidential-actions/2026/08/declaring-a-national-emergency-to-secure-the-united-states-bulk-power-system/">Declaring a National Emergency to Secure the United States Bulk-Power System</a> - <strong>The White House</strong> (not me) announces - <em>&#8220;During my first term, I found that the bulk-power system could be a target of those seeking to commit malicious acts against the United States, including malicious cyber activities, because of the significant risks that a successful attack would have on our economy, human health and safety, and national defense. Since my first term, the threat to the United States regarding foreign supply of bulk-power system electric equipment has become even more acute: The rapid growth of advanced manufacturing, data centers, artificial intelligence, and defense production has increased the Nation&#8217;s dependence on abundant, reliable electricity and magnified the consequences of a successful attack or supply disruption on the bulk-power system.&#8221;</em></p></li><li><p><a href="https://home.treasury.gov/news/press-releases/sb0615/"><span>Treasury Announces the Quantum-Readiness Task Force</span></a><span> - US </span><strong><span>Treasury</span></strong><span> announces - </span><em><span>&#8220;This Task Force will help ensure our financial system remains strong, secure, and competitive as new technologies reshape the global landscape.&#8221;</span></em></p></li><li><p><a href="https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/4545295/defending-american-information-us-communications-security-policy-since-1945/">Defending American Information; US Communications Security Policy since 1945</a> - <strong>National Security Agency</strong> detail history - &#8220;<em>Since the end of World War II, the United States has contended with the growing vulnerabilities and capabilities of an increasingly interconnected world. Maintaining the security and confidentiality of government communications has been a joint effort since 1945, and the fact that it is addressed through the President indicates an understanding of how critical information security is. In another sense, it also stands as an example of the interplay between communications intelligence and security.&#8221;</em></p></li><li><p><a href="https://www.ncsc.govt.nz/news/new-zealanders-urged-to-take-care-as-cyber-security-incidents-become-more-complex/"><span>New Zealanders urged to take care as cyber security incidents become more complex</span></a><span> - NZ </span><strong>National Cyber Security Centre</strong> warns - <em>&#8220;Of those reports, 92 incidents were triaged for specialist technical support due to their potential national significance, an increase from the 77 incidents recorded in the previous quarter. The remaining 1,037 reports did not require specialist technical support.&#8221;</em></p></li><li><p><a href="https://www.politico.eu/article/hackers-target-eu-officials-whatsapp/">State-backed hackers targeted EU officials on WhatsApp, document shows</a> - <strong>Politico</strong> reports - &#8220;<em>The presentation, given to officials from EU national governments in July, lists &#8220;account takeover targeting high-ranking officials&#8221; as one of the top threats facing the bloc this year.&#8221;</em></p></li><li><p><a href="https://www.moodys.com/web/en/us/insights/public-sector/why-defence-network-visibility-is-increasingly-critical-to-uk-resilience.html">Why defence network visibility is increasingly critical to UK resilience</a> - <strong>Moody&#8217;s</strong> opines - <em>&#8220;As governments seek to reduce exposure to vulnerabilities and strengthen domestic or allied supply chains, they may discover that dependencies are often more complex than they first appear. Consider a defence procurement team evaluating a supplier for a strategically important programme. The supplier itself may appear low risk, but resilience challenges can emerge when ownership structures, critical subcontractors, financing arrangements, or technology dependencies are examined more closely and found to span multiple jurisdictions.&#8221;</em></p></li><li><p><a href="https://www.aspistrategist.org.au/worth-a-try-the-us-will-authorise-some-companies-for-cyber-counterattacks/">Worth a try: the US will authorise some companies for cyber counterattacks</a> - <strong>Australian Strategic Policy Institute</strong> supports - &#8220;<em><span>The White House is wisely not just outsourcing to privateers but creating an entire </span><a href="https://www.linkedin.com/feed/update/urn:li:activity:7493919083588005888/?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAA83QQBMZqi9fuD5f7aaM-3I52zwfNn3B8">institutional framework</a><span>. The co-executive directors (policymakers from the departments of Justice and Homeland Security) will vet and contract with companies and approve and retain operational control of their activities. Companies will have to report their activities to the government and can be ejected from the program if they fail to live up to standards.&#8221;</span></em></p></li><li><p><a href="https://www.munhwa.com/article/11610713">Blue House Officials&#8217; Personal Information Leaked, 102 Locations Including Media Attacked&#8230; Korean Computer Network Becomes a &#8216;Hacker Playground&#8217; </a>- <strong>Munhwa Ilbo</strong> reports - <em>&#8220;The police are investigating the possibility that the North Korean hacking group 'Lazarus' is involved in the case handled by the Seoul Metropolitan Police Agency. In 2023, Lazarus hacked 207 computers across 61 domestic institutions, including eight media outlets. However, the security industry points out that the Blue House personnel scandal could also be the work of Lazarus.&#8221;</em></p></li><li><p>Reporting on/from China</p><ul><li><p><a href="https://www.bloomberg.com/news/articles/2026-08-18/china-axing-microsoft-windows-from-state-agencies-ahead-of-plan">China Axing Microsoft Windows From State Agencies Ahead of Plan</a> - <strong>Bloomberg</strong> reports - <em>&#8220;<span>China has been pushing the use of homemade technologies in sectors handling sensitive data, including military and state-owned firms. Several Chinese companies, including </span>Kylin Software Co.<span> and </span>Tongxin Software Technology Co.<span>, have introduced their own versions of operating systems for computers to replace Windows.&#8221;</span></em></p></li><li><p><a href="https://www.reuters.com/business/autos-transportation/corrected-exclusive-cherys-robot-affiliate-aimoga-eyes-ipo-targets-overseas-2026-08-21/">Chery&#8217;s robot affiliate AiMOGA eyes IPO, targets overseas market</a> - <strong>Reuters</strong> reports - <em>&#8220;Incubated by Chery in January 2025, AiMOGA has delivered more than 3,000 robots globally, with 2,000 overseas, and operates in more than 60 countries and regions.&#8221;</em></p></li><li><p><a href="https://www.ft.com/content/26735a23-315f-47ef-8cf2-6c6ea9713998?syn-25a6b1a6=1">Who is really buying China&#8217;s humanoid robots?</a> - <strong>Financial Times</strong> asks - <em>&#8220;China&#8217;s humanoid robot makers are generating much of their revenue from selling machines to government-backed training centres &#8212; which then collect and sell training data back to the robot makers, raising concerns about actual demand in an industry Beijing is keen to promote. The widely adopted model, reminiscent of Nvidia&#8217;s &#8220;circular financing&#8221; of AI data centres, has fuelled China&#8217;s so-called embodied AI industry.&#8221;</em></p></li><li><p><a href="https://en.people.cn/n3/2026/0820/c90000-20490584.html">China accelerates 6G development</a> - <strong>People's Daily Online</strong> reports - <em>&#8220;China is currently working to build &#8220;six networks,&#8221; including a next-generation communication network. This involves not only building new networks based on new technologies, but also upgrading existing networks.&#8221;</em></p></li><li><p><a href="https://www.jswx.gov.cn/zhengce/fagui/202607/t20260721_1345845.shtml">Implementation Plan for Deepening Technological Innovation and Integrated Application of Internet Protocol Version 6 (IPv6) (2026-2030)</a> - <strong>Jiangsu Cyberspace Administration</strong> publishes - <em>&#8220;New networks will be given priority in providing IPv6 addresses by default, accelerating the evolution to IPv6 single-stack, creating more new &#8220;IPv6+&#8221; applications, models, and business forms, and promoting the formation of a network service and application system dominated by IPv6.&#8221;</em> - comment: IPv6+ is a Chinese specific flavour of IPv6</p></li><li><p><a href="https://www.scmp.com/tech/tech-trends/article/3364700/chinese-ai-chips-fall-short-coding-forcing-firms-stretch-scarce-nvidia-supply">Chinese AI chips fall short on coding, forcing firms to stretch scarce Nvidia supply</a> - <strong>South China Morning Post</strong> reports - <em>&#8220;Chinese AI companies are optimising software to cope with surging demand for inference, as part of that workload still relies on computing power from a limited pool of high-end chips amid restricted access to Nvidia processors.&#8221;</em></p></li></ul></li><li><p> AI</p><ul><li><p><a href="https://openai.com/collective-cyberdefense/">A call for collective action on cyber defense</a> - <strong>100 organisations</strong> sign - <strong>comment:</strong>  see reflections this week on this.</p></li><li><p><a href="https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/">Brief independent investigation of agents&#8217; behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident</a> - <strong>METR</strong> and <strong>Redwood Research</strong> publish - <em>&#8220;~1200 agents sent &gt;70,000 messages and files on an unsanctioned message board, and ~700 attacked Hugging Face&#8221; - </em><strong>comment: </strong>thus likely very apparent if under observability and monitoring.</p></li><li><p><a href="https://www.irregular.com/research/assessing-kimi-k3-against-offensive-security-benchmarks">Assessing Kimi K3 Against Offensive Security Benchmarks </a>- <strong>Irregular </strong>assesses - <em>&#8220;Kimi K3 demonstrated strong performance on Atomic Tasks, solving several challenges involving cryptographic attacks, certificate forgery, browser exploitation, memory corruption, protocol manipulation, and multi-host compromise. It was particularly effective at turning partial access into complete attack chains by adapting public exploit techniques to constrained environments, building custom tooling, diagnosing implementation failures, and validating each stage before proceeding.&#8221;</em></p></li><li><p><a href="https://www.aikido.dev/blog/ai-model-benchmarks-aug-21-2026">We burned 11.7bn tokens to find the best cyber AI model</a> - <strong>Aikido</strong> burns tokens - &#8220;</p><ul><li><p><em>DeepSeek V4 Pro 0813 finds the most vulnerabilities. Pooling three runs reaches 28 of 32 vulnerabilities.</em></p></li><li><p><em>The most expensive model is not required. Three DeepSeek Pro runs cost about $295 and outperform Opus 5, Grok 4.6, or Sol. Three Flash runs cost $108 and reach 24 matching Grok&#8217;s best individual pass for less than a quarter of the cost.</em></p></li><li><p><em>Models are inconsistent at recall; repetition remediates it. Single runs miss the breadth of findings, but pooling across runs fills this gap. DeepSeek Pro finds 17 vulnerabilities on its first pass but 28 across three.</em></p></li><li><p><em>Open-source models now outperform the public frontier. DeepSeek V4 Pro topped every public closed model we tested on pooled vulnerability recall. Qwen, Kimi, and GLM-5.3 followed with strong consistency of findings without losing recall. Harnessed correctly, open models can now compete directly with the closed frontiers.&#8221;</em> </p></li></ul></li><li><p><a href="https://arxiv.org/abs/2606.15762">Snyk VulnBench JS 1.0: Can LLMs Find the Same Bugs Twice?</a> - <strong>Snyk</strong> product market - <em>&#8220;Across 250 model runs, 80 of 161 unique unmatched findings appeared in only one of five identical repetitions, while only 22 appeared in all five.&#8221;</em> - <em>&#8220;By contrast, when Claude matched a Snyk Code reference finding, the behavior was much more stable: 134 of 158 unique reference-matched findings appeared in all five repetitions.&#8221;</em></p></li><li><p><a href="https://zeddyu.github.io/p/from-code-to-chain-why-wp2shell-stayed-out-of-reach/">From Code to Chain: Why WP2Shell Stayed Out of Reach</a> - <strong>Zeddy Lu</strong> researches -<em>&#8221;This paper compares the long-term code auditing capabilities of three major models by reproducing the wp2shell vulnerability chain discovery process: Under the same harness, GPT 5.6 Sol / GLM-5.2 / Qwen 3.8-Max-Preview were run 11 times, each lasting 6&#8211;10 hours, on the complete WordPress codebase, and their exploration process was recorded and reconstructed using full-chain hooking. &#8220;</em> - <strong>comment:</strong> demonstrates the reality and limitations of AI in finding certain vulnerabilities and thus showing that not all vulnerabilities become shallow - yet.</p></li><li><p><a href="https://bughunters.google.com/blog/scaling-memory-safety">Scaling Memory Safety: AI-Assisted Rewrites of C/C++ Dependencies to Rust</a> - <strong>Google</strong> detail - <em>&#8220;This experiment described in this post demonstrates that AI-assisted migration can be a viable and effective strategy for structural risk reduction. By combining the speed of LLM-driven translation with the rigor of differential testing, plus human-expert review of safety boundaries and existing test cases, we can rapidly eliminate entire classes of vulnerabilities from our dependencies.&#8221;</em></p></li><li><p><a href="https://www.scmp.com/tech/article/3364356/zhipu-ais-answer-project-glasswing-marks-shift-chinese-cyber-safety-researcher?utm_source=twitter&amp;utm_campaign=3364356&amp;utm_medium=share_widget"><span>Zhipu AI&#8217;s answer to Project Glasswing marks shift for Chinese cyber safety: researcher</span></a><span> - </span><strong><span>South China Morning Post</span></strong><span> reports - </span><em><span>&#8220;The model&#8217;s most sensitive offensive capabilities would be &#8220;reserved exclusively for verified users&#8221; under a restricted access plan dubbed &#8220;Cybersecurity Trusted Access&#8221;, Zhipu said.&#8221;</span></em></p></li><li><p><a href="https://www.economist.com/by-invitation/2026/08/23/fears-of-ai-induced-armageddon-are-overdone">Fears of AI-induced armageddon are overdone </a>- <strong>Ciaran Martin</strong> via <strong>The Economist</strong> writes - <em>&#8220;<span>One news outlet, capturing the growing sense of foreboding, called it &#8220;the start of a dangerous </span>AI<span> cyber era&#8221;. So is it different this time? Or does the uneasy equilibrium between attack and defence still hold? Mostly, and thankfully, it does, for two reasons.&#8221;</span></em></p></li><li><p><a href="https://dhakal-ananda.com.np/misc/more-criticals-less-dopamine/">More Criticals, Less Dopamine</a> -<strong> Ananda Dhakal </strong>opines - &#8220;<em>Am i trying to say vuln research is dead? Definitely not. The number of vulnerabilities being found right now is at an all-time high. And if you look around, all the people finding these massive bugs are the same people who were doing exceptional work before the current AI boom.&#8221;</em></p></li><li><p><a href="https://www.nattothoughts.com/p/from-the-frontier-ai-arms-race-to">From the Frontier AI Arms Race to AI-enabled Defense-in-Depth: Qi An Xin Chief Outlines His Vision</a> - <strong>Natto Team</strong> summarises (we covered this talk previously) - <em>&#8220;Rather than arguing that AI merely creates new risks, Qi stressed that AI has exacerbated the imbalance between offense and defense, enabling automated, high-frequency attacks that render traditional, static protections obsolete. To counter these threats, Qi favored a defense-in-depth model, a &#8220;three-in-one vertical defense upgrade framework,&#8221; rather than advocating that China build a domestic &#8220;Mythos-equivalent&#8221; offensive-capability model. Qi emphasized that this integrated approach requires moving away from a compliance-driven security posture toward a more realistic path of accelerated, incremental security upgrades &#8212; not wholesale reinvention, but a comprehensive, self-evolving defense system capable of real-world combat readiness.&#8221;</em></p></li><li><p><a href="https://www.theguardian.com/technology/2026/aug/23/openai-cyber-attacks-threat-chris-lehane">&#8216;We are hitting a different chapter&#8217;: OpenAI leader warns of threat of &#8216;persistent&#8217; AI cyber-attacks</a> - <strong>The Guardian</strong> reports - <em>&#8220;Lehane renewed calls for the US government to legislate to create rules for frontier AI safety, and said the fact that the most cutting-edge and unreleased AI models appear to be improving cyber offence faster than defence, was &#8220;among the reasons why I think it&#8217;s absolutely imperative that this country passes a national law that creates mandatory required safety standards, and within that the pause element would be inherent and endemic to that process</em>&#8221; - <strong>comment:</strong> am interested in their data here to support the assertion.</p></li><li><p><a href="https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility-ai-agent">AI agent shared responsibility model </a>- <strong>Microsoft</strong> outlines - <em>&#8220;As with the <a href="https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility">cloud</a> and <a href="https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility-ai">AI</a> shared responsibility models, the division of responsibility shifts with the deployment model that you choose.&#8221; - <strong>comment:</strong> the cloud&#8217;s shared responsibility model for cyber security has shown that words can be said but the actions may not follow on either or both sides always.&#8221;</em></p></li><li><p><a href="https://www.wsj.com/tech/ai/private-equity-is-deploying-an-army-of-ai-wonks-to-embed-in-the-firms-they-back-96d279ec?st=st3P8m">Private Equity Is Deploying an Army of AI Wonks to Embed in the Firms They Back</a> - <strong>Wall Street Journal</strong> reports - <em>&#8220;<span>Blackstone and Hellman &amp; Friedman have formed a roughly 160-person team of artificial-intelligence experts with Anthropic to deploy at businesses, starting with their own portfolio companies. The push is part of a </span>$1.5 billion joint venture<span> between the AI giant and Wall Street firms, which also includes Apollo, General Atlantic and Goldman Sachs among the backers.&#8221;</span></em></p></li><li><p><a href="https://www.scmp.com/tech/tech-trends/article/3364827/openai-backed-legal-tech-firm-pivots-chinese-kimi-k3-open-weight-model">OpenAI-backed legal tech firm pivots to Chinese Kimi K3 open-weight model</a> - <strong>South China Morning Post</strong> reports - <em>&#8220;A US artificial intelligence start-up backed by OpenAI has built its first in-house model on Chinese lab Moonshot AI&#8217;s Kimi K3, highlighting a growing shift by Western tech firms towards Chinese open-weight systems amid soaring development costs. San Francisco-based legal tech provider Harvey, whose high-profile backers also include Sequoia Capital and Andreessen Horowitz, said on Thursday that its new model, Harvey Tenet, was post-trained on top of the open-weight Kimi K3 base.&#8221;</em></p></li></ul></li><li><p><em>Cyber proliferation</em></p><ul><li><p><a href="https://eprint.iacr.org/2026/1319.pdf">A Real-World Law-Enforcement Hack: The Case of Encrochat</a>  - <strong>King's College London, New York University, Georgia Institute of Technology </strong>and <strong>University of Waterloo</strong> detail - <em>&#8220;In this work, we give the most detailed public account to date of Encrochat&#8217;s infrastructure and how it was compromised&#8221;</em></p></li></ul></li><li><p>Bounty Hunting</p><ul><li><p><a href="https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers">Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure</a> - US <strong>Department of Justice</strong> announces -  <em>&#8220;The Justice Department and FBI announced court-authorized domain seizures today to deny malicious cyber actors access to two complementary hacking platforms known as &#8220;QScan&#8221; and &#8220;QTRouter,&#8221; used to target U.S. critical infrastructure and other sensitive networks. As described in court documents unsealed in the Southern District of California, a People&#8217;s Republic of China (PRC) state-sponsored group known as &#8220;QTFY,&#8221; employed by China-based Nanjing Xinjiuwei Network Technology Company (&#21335;&#20140;&#37995;&#29590;&#32500;&#32593;&#32476;&#31185;&#25216;&#26377;&#38480;&#20844;&#21496;), created and operated QScan and QTRouter.&#8221;</em></p></li><li><p><a href="https://en.yna.co.kr/view/AEN20260820010900320">Chinese national gets 20 years for hacking accounts of BTS&#8217; Jungkook, others</a> - <strong>Yonhap News Agency</strong> reports - <em>&#8220;The Seoul Central District Court handed down the sentence to the Chinese national, surnamed Chun, on charges of fraud and violating the information network act, in connection with the theft of more than 38 billion won (US$27.2 million) from the victims.&#8221;</em></p></li><li><p><a href="https://www.afp.gov.au/news-centre/media-release/two-wa-men-charged-following-afp-fbi-wapf-disruption-alleged-global">Two WA men charged following AFP-FBI-WAPF disruption of alleged global cybercrime syndicate</a> - <strong>Australian Federal Police</strong> announce - <em>&#8220;Police will allege the men were part of a highly organised syndicate involved in large-scale cybercrime offending, including data intrusion, identity crime, and cryptocurrency-based money laundering.&#8221;</em></p></li><li><p><a href="https://home.treasury.gov/news/press-releases/sb0613/?ref=metacurity.com"><span>Treasury Launches Unprecedented Campaign Against Iranian Regime on Economic D-Day</span></a><span> - US </span><strong><span>Treasury</span></strong><span> announces - </span><em><span>&#8220;Today&#8217;s actions target:&#8221; .. &#8220;A malicious cyber group directed by Iran&#8217;s Ministry of Intelligence and Security (MOIS) that is responsible for extensive compromises of U.S. critical infrastructure and financially motivated cyber theft;&#8221;</span></em></p></li></ul></li><li><p>Market Incentives</p><ul><li><p><a href="https://dadrian.io/blog/posts/whack-a-mole-is-losing/">Playing whack-a-mole is losing </a>- <strong>David Adrian</strong> opines - <em>&#8220;Producing an endless stream of findings is not a good use of security expertise, human or AI. If all you do is play whack-a-mole, you&#8217;re going to lose. We should not view security as an endless supply of mysteries to solve because being a detective is the valued identity. Instead, the role of defenders is to turn failures into new, broader, and stronger invariants, and to encode these invariants into the system so that engineers (and agents) don&#8217;t have to constantly rediscover the same class of problems. If that outcome feels like a loss, it&#8217;s because identity has displaced security as the goal.&#8221;</em></p></li><li><p><a href="https://discuss.grapheneos.org/d/41564-pixel-11-doesnt-meet-the-grapheneos-security-standards-and-may-be-skipped">Pixel 11 doesn&#8217;t meet the GrapheneOS security standards and may be skipped</a> - <strong>GrapheneOS</strong> warns - <em>&#8220;We have a partial port of GrapheneOS to the Pixel 11 series after a week of work on it. We're unable to complete the port due to lack of support for ARM hardware memory tagging [MTE] in software, firmware and near certainly hardware. It appears Google cut an important security feature to save money.&#8221;</em></p></li><li><p><a href="https://www.insurancebusinessmag.com/us/news/cyber/openais-rogue-ai-agents-expose-a-gap-in-cyber-coverage-587730.aspx">OpenAI&#8217;s rogue AI agents expose a gap in cyber coverage</a> - <strong>Insurance Business Mag</strong> highlights - <em>&#8220;A Willis Towers Watson research paper on AI-related liability described what the authors called "silent coverage" - AI-related liability risks sitting implicitly inside existing policies because the policies were never specifically written to include or exclude them. The parallel is to the early years of cyber risk, when property and liability policies had no explicit cyber position and courts were required to determine coverage case by case until the market developed affirmative cyber wordings. The OpenAI incident is precisely the kind of event that begins converting that silence into adjudicated precedent. For brokers placing tech E&amp;O for clients in the AI sector, the question of whether existing wordings adequately address autonomous agent liability - both as potential defendants and as potential victims - is no longer theoretical.&#8221;</em></p></li></ul></li></ul><p>Reflections this week are around the open letter led by a frontier AI company on <a href="https://openai.com/collective-cyberdefense/">A call for collective action on cyber defense</a> which was co-signed by 100 organisations and what it says and does not say about incentives and realities.</p><p>Clearly frontier AI is an era defining moment for cyber security which brings home the lack of historic prioritisation and investment. This moment has the opportunity to galvanise and make cyber security non optional and enduring - thus it is a seminal one. But there are no magic cheap quick wins - there is instead investment, time and diligent execution.</p><p>No one can argue against the need for collective action. But as regular readers will note success is in part driven by enduring corporate<a href="https://www.ncsc.gov.uk/blog-post/sausages-incentives-rewarding-resilient-technology-future"> incentives for both technology producers</a> as well as consumers and operators along with corresponding appropriate levels of investment.</p><p>A number of signatories will be alive to this fact having had very serious security vulnerabilities in their technology, products and services over the years - including those who produce security products. The flipside for organisations who adopt technology is that some will not know what their digital estates are in totality nor have them under comprehensive management and observability whilst carrying end of life.</p><p>AI is a super power to some. But again organisations leveraging AI for vulnerability discovery are already finding they are displacing the point of constraint from finding to patching, to testing, to functional testing, to deployment, to need to find budget for tokens or similar. </p><p>No organisation or government has limitless budget and there will never be zero risk. We can only spend each &#163;/$/&#8364;/&#165; once so knowing when AI will yield a better cyber security resilience return (i.e. reduced risk) versus replacing end of life equipment/legacy system or deploying a robust architectural response is going to be one of those questions executives rightly expect an answer to - which the <a href="https://www.youtube.com/watch?v=0OQyA8LKJ8E">video of the week by Dr Daniel Woods does an excellent job on</a>.</p><p>It is also important to remember AI is not the cause of vulnerability outside of systems it is integrated into or which has vibe coded insecurely. It can and does surface technical and process debt at a greater scale to actors both good and bad causing a painful forced correction due to increased visibility and knowledge i.e. what is being found today was already present and latent.</p><p>As David Adrian says above stronger invariants are the goal as are immutable properties of cyber security solutions - be they <a href="https://www.ncsc.gov.uk/collection/cross-domain">cross domain</a>, <a href="https://www.ncsc.gov.uk/collection/principles-for-secure-paws">privileged access workstations</a>, <a href="https://www.ncsc.gov.uk/passkeys">passkeys</a> or operational capabilities such as being able to <a href="https://www.ncsc.gov.uk/blog-post/strengthening-national-cyber-resilience-through-observability-threat-hunting">effectively hunt</a>. </p><p>We know how to build and operate cyber resilient systems but now is the time to pay down technical debt, invest in strong architectures, eradicate classes of vulnerability through technology choices, have operational excellence and address the imbalance&#8230;</p><p>&#8230; Finally this week I got to guest co-host the Risky Business podcast which you can listen to/watch here:</p><div id="youtube2-IV59lutR-0g" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;IV59lutR-0g&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/IV59lutR-0g?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Not getting this via email? Subscribe:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Think someone else would benefit? Share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-c0b?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-c0b?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p><strong>All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.</strong></p><p>Have a lovely Sunday&#8230;</p><p>Ollie</p><h1>Cyber threat intelligence</h1><p>Who is doing what to whom and how allegedly.</p><h2>Reporting on Russia</h2><h3><span>UAC-0099 utilizes a novel multi-stage malware chain to carry out attacks</span></h3><p><strong>The 360 &#8203;&#8203;Advanced Threat Research Institute</strong> (in China) caught this alleged operation by Russia against Ukraine. The tradecraft is well understood - but the particular mix has some unique elements thus noteworthy.</p><blockquote><p>The attackers primarily targeted Ukraine, focusing on government agencies and organizations involved in critical infrastructure. They used phishing emails to send malicious compressed files as attachments. The files contained WSF scripts disguised as Word documents with double extensions. The email content was disguised around topics of interest to the target, enticing users to unzip and run the files, thus infecting them. After execution, the WSF script was redirected via a shortened link to a file server to download subsequent payloads. The attack chain combined DLL sideloading, multi-stage conditional execution, and code virtualization protection to evade security detection and covertly implant remote control capabilities.</p></blockquote><p><a href="https://mp.weixin.qq.com/s/WjjZYriiZl7-waw6Cjy1DQ">https://mp.weixin.qq.com/s/WjjZYriiZl7-waw6Cjy1DQ</a></p><h3>BlueDelta Targets Defense and Diplomacy with HOOKEDGE</h3><p><strong>Insikt Group&#174;</strong> detail this alleged Russian operation against a range of defence industrial base. Tradecraft is well understood but the victimology is noteworthy. </p><blockquote><ul><li><p>Between late September 2025 and early April 2026, BlueDelta conducted a series of initial access campaigns against defense manufacturing and diplomatic organizations in Romania, Spain, and T&#252;rkiye. BlueDelta used macro-enabled Word documents to deploy HOOKEDGE, a lightweight batch-script backdoor that shares significant code and tradecraft overlap with BlueDelta&#8217;s earlier implant, HEADLACE.</p></li><li><p>The campaigns employed both diplomatic-themed and generic lures. Early activity impersonated Spanish government material, while later campaigns adopted generic macro-enablement lures. One diplomatic lure was created shortly after a meeting between Spanish and Moldovan officials, potentially reflecting an effort to collect intelligence relevant to Russia ahead of Moldova&#8217;s September 2025 parliamentary elections.</p></li><li><p>BlueDelta continued to refine HOOKEDGE between September 2025 and April 2026, introducing changes to lure documents, execution methods, and beaconing intervals while maintaining the malware&#8217;s core functionality and infrastructure model.</p></li><li><p>For targets assessed as having higher intelligence value, BlueDelta deployed a second-stage HOOKEDGE payload with a much shorter beaconing interval. This gave operators more responsive tasking and follow-on activity, while keeping the webhook endpoints used for initial access from being exhausted.</p></li><li><p>BlueDelta has historically demonstrated a preference for legitimate internet services (LIS) to facilitate C2, payload staging, and data exfiltration, with <em>webhook[.]site</em>&#8217;s free tier serving as the group&#8217;s exclusive choice across these campaigns.</p></li></ul></blockquote><p><a href="https://www.recordedfuture.com/research/bluedelta-targets-with-hookedge">https://www.recordedfuture.com/research/bluedelta-targets-with-hookedge</a></p><h2>University Leak Exposes Russia&#8217;s Military Cyber Training Pipeline</h2><p><strong>DomainTools</strong> alleged links between a Russian university providing a talent pipeline for government.</p><blockquote><p><span>Recently leaked records show that </span>Bauman Moscow State Technical University<span>&#8217;s Department No. 4 operated as a long-term training pipeline for Russian military intelligence and cyber operations. The department served several elements of the Russian General Staff and trained roughly 250 career and reserve students across three specialties: special intelligence (&#8220;&#1057;&#1083;&#1091;&#1078;&#1073;&#1072; &#1089;&#1087;&#1077;&#1094;&#1080;&#1072;&#1083;&#1100;&#1085;&#1086;&#1081; &#1088;&#1072;&#1079;&#1074;&#1077;&#1076;&#1082;&#1080;&#8221;), operational information-technical effects (&#8220;&#1055;&#1088;&#1080;&#1084;&#1077;&#1085;&#1077;&#1085;&#1080;&#1077; &#1089;&#1080;&#1083; &#1080; &#1089;&#1088;&#1077;&#1076;&#1089;&#1090;&#1074; &#1080;&#1085;&#1092;&#1086;&#1088;&#1084;&#1072;&#1094;&#1080;&#1086;&#1085;&#1085;&#1086;-&#1090;&#1077;&#1093;&#1085;&#1080;&#1095;&#1077;&#1089;&#1082;&#1086;&#1075;&#1086; &#1074;&#1086;&#1079;&#1076;&#1077;&#1081;&#1089;&#1090;&#1074;&#1080;&#1103; &#1080; &#1079;&#1072;&#1097;&#1080;&#1090;&#1099; &#1086;&#1090; &#1080;&#1085;&#1092;&#1086;&#1088;&#1084;&#1072;&#1094;&#1080;&#1086;&#1085;&#1085;&#1086;-&#1090;&#1077;&#1093;&#1085;&#1080;&#1095;&#1077;&#1089;&#1082;&#1086;&#1075;&#1086; &#1074;&#1086;&#1079;&#1076;&#1077;&#1081;&#1089;&#1090;&#1074;&#1080;&#1103;&#8221;), and information-technology protection (&#8221;3&#1072;&#1097;&#1080;&#1090;&#1072; &#1080;&#1085;&#1092;&#1086;&#1088;&#1084;&#1072;&#1094;&#1080;&#1086;&#1085;&#1085;&#1099;&#1093; &#1090;&#1077;&#1093;&#1085;&#1086;&#1083;&#1086;&#1075;&#1080;&#1081;&#8221;). The curriculum combined both offensive and defensive techniques for cyber defense, as well as offensive doctrine for active measures campaigns and GRU activities. Field placements then moved students from classroom instruction into military units and academies aligned with their specialties, giving them supervised exposure to intelligence operations and preparing them for military and government operations careers.</span></p><p><span>&#8230;</span></p><p><span>The collection also includes malware-analysis and cyber threat intelligence research, manpower-planning documents, and a financial-sector cybersecurity specialization feeding into </span>VUS 093400 (SIS)<span>. It further connects Bauman to Russian military research institutes, academies, and operational structures. Although the analyzed files do not provide every final graduate assignment, they expose the personnel, training, doctrine, and administrative system behind a durable Russian military cyber and technical-intelligence pipeline.</span></p></blockquote><p><a href="https://dti.domaintools.com/research/threat-intelligence-report-university-leak-exposes-russias-military-cyber-training-pipeline">https://dti.domaintools.com/research/threat-intelligence-report-university-leak-exposes-russias-military-cyber-training-pipeline</a></p><h2>Reporting on China</h2><h3>NSA Joins FBI in Issuing Warning about Chinese Hacking Group QTFY Cyber Activity</h3><p><strong>The National Security Agency</strong> details around the technical capabilities of this alleged Chinese state private sector enabler.</p><blockquote><p>QTFY actors have developed branded products that work in conjunction with each other and include the vulnerability scanning and exploitation platform &#8220;QScan&#8221; to conduct reconnaissance, exploit vulnerable Internet of Things (IoT) devices and identify vulnerabilities in networks, an obfuscation network named &#8220;QTRouter&#8221; to blend in with legitimate users, and at least three major platforms that can manage botnets of compromised IoT devices and include them as obfuscation network nodes (&#8220;Proxy Platform Management,&#8221; &#8220;Proxy Pool Management System&#8221; and &#8220;QTBotnet&#8221;).</p></blockquote><p><a href="https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4583539/nsa-joins-fbi-in-issuing-warning-about-chinese-hacking-group-qtfy-cyber-activity/">https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4583539/nsa-joins-fbi-in-issuing-warning-about-chinese-hacking-group-qtfy-cyber-activity/</a></p><h2>The infrastructure quartermaster: inside a China-nexus state enablement model</h2><p><strong>Black Lotus Labs</strong> provides further technical details on this alleged Chinese capability. Noteworthy for its age, complexity and the fact it was provided as a service by a commercial company.</p><blockquote><p>The quartermaster model depends on four connected components that work together to identify targets, route traffic and obscure operator activity. Each plays a different role in the broader enablement layer, turning reconnaissance, proxy access and traffic management into a repeatable service for downstream threat actors.</p><p>The quartermaster&#8217;s four main components are:</p><ul><li><p><strong>&#8220;QScan&#8221;:</strong> Conducts reconnaissance to identify and profile high-value targets; networks discovered or profiled by QScan later appear in bidirectional communications through &#8220;Fast Labyrinth.&#8221;</p></li><li><p><strong>&#8220;Fast Labyrinth&#8221;:</strong> Provides the operational layer by co-opting commercial proxy infrastructure into an encrypted relay network that obfuscates traffic to and from target entities.</p></li><li><p><strong>&#8220;QTRouter&#8221;:</strong> Provides a preconfigured physical access device that manages operator and customer access to the proxy infrastructure and proxy node management system.</p></li><li><p><strong>&#8220;QTProxy&#8221;:</strong> Manages Fast Labyrinth operational nodes, allowing operators to use preconfigured relays or tailor unique paths to target entities.</p></li><li><p>Together, these components streamline target discovery, communication routing and operational access, allowing Chinese espionage operators to conduct activities more efficiently while hiding their tracks.</p></li></ul></blockquote><p><a href="https://www.lumen.com/blog/en-us/the-infrastructure-quartermaster-inside-a-china-nexus-state-enablement-model">https://www.lumen.com/blog/en-us/the-infrastructure-quartermaster-inside-a-china-nexus-state-enablement-model</a></p><h3>Chinese Implants in the Supply Chain</h3><p><strong>Jacob Baines</strong> details a device that came backdoored for which the DNS domain ownership had lapsed. Welcome to contemporary supply chains in 2026..</p><blockquote><p><em>The implant beacons hit the sinkhole as soon as we stood it up. Hundreds of routers, almost all in China, beaconing home to a forgotten domain. We found the domain obfuscated in the firmware of a router we bought on Amazon from a small company in New York. Now, we own the domain. We own the implants.</em></p></blockquote><p><a href="https://www.vulncheck.com/blog/zbt-darklantern-speakingstone">https://www.vulncheck.com/blog/zbt-darklantern-speakingstone</a></p><h3>Carry-On Compromise: TA4922 Packs PackClient</h3><p><strong>Kyle Cucci, Rob Kinner</strong> and <strong>Tony Robinson</strong> detail an alleged Chinese criminal campaign which is noteworthy for targeting Indian victims along with some of the multi file format tradecraft.</p><blockquote><ul><li><p>Proofpoint identified a command and control (C2) framework called PackClient sold on Telegram.</p></li><li><p>It is being used by at least one threat actor, Chinese-speaking TA4922.</p></li><li><p>With this new payload, TA4922 is expanding its arsenal of initial-access malware, much of which originates in the Chinese-speaking cybercrime ecosystem.</p></li></ul><p>Since the initial identification of PackClient in the May 2026 campaign, Proofpoint researchers have observed at least two additional TA4922 campaigns delivering the malware. In mid-July 2026, the actor targeted organizations in India using Hindi-language tax enforcement lures that impersonated the Indian Income Tax Department. The emails claimed recipients had underreported income and failed to disclose foreign assets and threatened financial penalties. Unlike the earlier China-focused activity, the messages delivered a ZIP archive ("Tax_Notice_23665.zip") containing an IMG disk image ("Tax_Notice_23665.img "). When mounted, the image contained an executable and malicious DLL that leveraged DLL sideloading to execute Donut Loader and ultimately install PackClient.</p></blockquote><p><a href="https://www.proofpoint.com/us/blog/threat-insight/carry-compromise-ta4922-packs-packclient">https://www.proofpoint.com/us/blog/threat-insight/carry-compromise-ta4922-packs-packclient</a></p><h2>Reporting on North Korea</h2><h3><span>Inside</span> <span>Kimsuky&#8217;s</span> <span>Abuse</span> <span>of</span> <span>Legitimate</span> <span>Remote</span> <span>Control</span> <span>Tools</span> <span>Across</span> <span>Northeast</span> <span>Asia</span></h3><p><strong>ENKI WhiteHat</strong> details this alleged North Korean operation which uses initial access tradecraft that is very well understood. The Chrome extension is noteworthy along with the fact it was in part potentially vibe coded. </p><blockquote><ul><li><p>We identified several Kimsuky spear phishing campaigns against South Korean and Japanese targets in the first half of 2026.</p></li><li><p>The threat actor spread LNK malware through phishing emails carrying OneDrive share links. Running the file sets up a scheduled task that fetches a PowerShell script from the C&amp;C server and runs it at regular intervals.</p></li><li><p>Those scripts stole data from the host, profiling the system, pulling mail out of Thunderbird and Outlook, and logging keystrokes.</p></li><li><p>The threat actor also installed legitimate remote control software such as Chrome Remote Desktop and AnyDesk to slip past antivirus detection and open up several routes for remote access.</p></li><li><p>A malicious Chrome extension that automatically siphons Gmail data showed numerous signs of having been written with generative AI, with Korean comments, debug strings and Unicode emoji running throughout the code.</p></li></ul></blockquote><p><a href="https://www.enki.co.kr/en/media-center/blog/inside-kimsuky-s-abuse-of-legitimate-remote-control-tools-across-northeast-asia">https://www.enki.co.kr/en/media-center/blog/inside-kimsuky-s-abuse-of-legitimate-remote-control-tools-across-northeast-asia</a></p><h2>Reporting on Iran</h2><h3>Tortoiseshell: New Toolset and Operational Infrastructure Exposed</h3><p><strong>Mansour Alhmoud</strong> and <strong>Mohamed Emam</strong> expand on prior reporting of this alleged Iranian operation. Noteworthy is the potential expansion in scope of targeting.</p><blockquote><ul><li><p>Enrichment of the Mirage Kitten <a href="https://securelist.com/mirage-kitten-new-tools/120811/?kaspr=5bet">reporting</a> uncovered extensive Tortoiseshell infrastructure spanning Europe and the Middle East.</p></li><li><p>Identified further malicious components, including an SSH-based tunnelling utility and a backdoor mirroring the TWOSTROKE family previously observed by GTIG in late 2025. This C++ backdoor possesses capabilities for executing shell or file commands, uploading and exfiltrating files, and conducting reconnaissance.</p></li><li><p>The discovered Tortoiseshell infrastructure potentially suggests an expanded targeting profile, focusing on Middle Eastern countries, alongside European countries.</p></li></ul></blockquote><p><a href="https://www.group-ib.com/blog/tortoiseshell-apt-toolset-infrastructure/">https://www.group-ib.com/blog/tortoiseshell-apt-toolset-infrastructure/</a></p><h2>Reporting on Other Actors</h2><h3>SLEEPWALKER: A Passive Backdoor With Its Own Command Language</h3><p><strong>Dominik Reichel</strong> details a rather novel implant which is unattributed and shows a degree of complexity and novel technical elments.</p><blockquote><p>What makes it worth writing up is what that packet carries: not a readable command, but a short program written in a command language of the backdoor&#8217;s own design. Its 23 instructions cover scheduling, several ways to move data, staged file delivery and running code directly in memory. Recovering the encryption key is not enough to understand one of these programs. The internal command language must be reverse engineered as well. From a reverse-engineering perspective, SLEEPWALKER has a cool design. Still, the implementation has several weaknesses and is not top-notch malware engineering. This could be an early version, however. Newer and improved builds may exist.</p></blockquote><p><a href="https://r136a1.dev/2026/08/24/sleepwalker-a-passive-backdoor-with-its-own-command-language/">https://r136a1.dev/2026/08/24/sleepwalker-a-passive-backdoor-with-its-own-command-language/</a></p><h3>Aurora ransomware targets ESXi, abuses Cursor Agent for exploitation</h3><p><strong>Eyal Sela</strong> details a ransomware campaign which leveraged AI Software-as-a-Service which is interesting in that the malicious use was potentially not detected by the model service provider.</p><blockquote><p>In some victim networks the operator used Cursor Agent with <code>claude-4.5-sonnet-thinking</code>. In these cases the agent was given credentials or an existing route into the victim organisation. Then it was tasked with various exploitation activities.</p><p>The chart below plots Cursor Agent sessions between 8 April and 21 May 2026, one row for each target or victim organisation. Circle area is the number of commands the Agent ran in that session.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!3zjQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feddaea13-9c4a-41e1-b5ce-9e8b96950c53_1000x580.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!3zjQ!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feddaea13-9c4a-41e1-b5ce-9e8b96950c53_1000x580.svg 424w, /__u/substackcdn.com/image/fetch/$s_!3zjQ!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feddaea13-9c4a-41e1-b5ce-9e8b96950c53_1000x580.svg 848w, /__u/substackcdn.com/image/fetch/$s_!3zjQ!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feddaea13-9c4a-41e1-b5ce-9e8b96950c53_1000x580.svg 1272w, /__u/substackcdn.com/image/fetch/$s_!3zjQ!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feddaea13-9c4a-41e1-b5ce-9e8b96950c53_1000x580.svg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!3zjQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feddaea13-9c4a-41e1-b5ce-9e8b96950c53_1000x580.svg" width="1456" height="844" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eddaea13-9c4a-41e1-b5ce-9e8b96950c53_1000x580.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:844,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!3zjQ!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feddaea13-9c4a-41e1-b5ce-9e8b96950c53_1000x580.svg 424w, /__u/substackcdn.com/image/fetch/$s_!3zjQ!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feddaea13-9c4a-41e1-b5ce-9e8b96950c53_1000x580.svg 848w, /__u/substackcdn.com/image/fetch/$s_!3zjQ!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feddaea13-9c4a-41e1-b5ce-9e8b96950c53_1000x580.svg 1272w, /__u/substackcdn.com/image/fetch/$s_!3zjQ!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feddaea13-9c4a-41e1-b5ce-9e8b96950c53_1000x580.svg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://gambit.security/blog-posts/aurora-ransomware-targets-esxi-abuses-cursor-agent-for-exploitation">https://gambit.security/blog-posts/aurora-ransomware-targets-esxi-abuses-cursor-agent-for-exploitation</a></p><h3>Software Supply Chain Incursions</h3><p><span>A reminder we issued guidance a number of weeks ago in </span><a href="https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies">Software supply chain attacks: check your dependencies</a><span> for software developers</span></p><ul><li><p><a href="https://www.stepsecurity.io/blog/state-of-open-source-supply-chain-attacks">The State of Open Source Supply Chain Attacks</a> - <em>&#8220;56 supply chain attacks in 12 months&#8221;</em></p></li><li><p><a href="https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/">Malicious Rust Crate arrayref Runs a Build-Time Payload</a></p></li><li><p><a href="https://www.cloudsek.com/blog/bridgehead-npm-typosquatting-wsl-windows-crypto-wallet-stealer">BRIDGEHEAD : An npm typosquatting campaign that crosses from WSL into Windows to plant a crypto-wallet stealer</a></p></li><li><p><a href="https://www.trendaisecurity.com/en-us/resources-insights/trendai-security-blog/redc2-ai-powered-linux-implant">Prompting the Payload: How an npm Supply Chain Attack Delivers the RedC2 AI-Powered Linux Implant</a></p></li><li><p><a href="https://www.ox.security/blog/research-clickfix-phishing-npm-packages/">ClickFix Phishing Pages Discovered in 24 npm Packages</a></p></li></ul><h1>Discovery</h1><p>How we find and understand the latent compromises within our environments.</p><h2>Chromium Extension Persistence VQL</h2><p><strong>Matt Green</strong> shows how <em>Velociraptor</em> can be used to hunt for malicious Chrome extensions.</p><blockquote><p>Hunts Chromium profiles for enabled unpacked extensions and Native Messaging Host registrations associated with Chromium extension persistence.</p><p>This is intended to identify extension persistence techniques such as the SilentChrome-BOF technique described by SpecterOps. SilentChrome writes an unpacked extension entry under extensions.settings.&lt;extension_id&gt;, enable developer mode, and repairs Chromium preference integrity metadata so theextension is accepted at next browser start.</p></blockquote><p><a href="https://github.com/mgreen27/DetectRaptor/blob/master/vql/ChromiumExtensionPersistence.yaml">https://github.com/mgreen27/DetectRaptor/blob/master/vql/ChromiumExtensionPersistence.yaml</a></p><h2>Detecting (Evil) Dylibs</h2><p><strong>Patrick Wardle</strong> shows how some aftermarket repurposing of Apple&#8217;s Endpoint Security framework can be used for detection tradecraft.</p><blockquote><p>In this blog post, we&#8217;ll first highlight examples of attackers abusing dylibs for persistence, payloads, and even exploits. Then, we&#8217;ll show how we can programmatically enumerate dylibs statically on disk, at runtime in a remote process, and as they are being loaded. Better yet, using Apple&#8217;s Endpoint Security framework, we&#8217;ll show how we can register for memory-mapping events associated with dylib loads, granting us the ability to examine and even block, if needed, libraries before they fully load in the first place.</p></blockquote><p><a href="https://objective-see.org/blog/blog_0x89.html?v=1">https://objective-see.org/blog/blog_0x89.html?v=1</a></p><h2>Threat Hunting using Pair Probabilities</h2><p><strong><span>Stamatis Chatzimangou</span></strong><span> brings statistics in threat hunting to the masses with this post.</span></p><blockquote><p><span>Upon digging around Microsoft&#8217;s documentation for user-defined functions I stumbled on the function </span><strong><a href="https://learn.microsoft.com/en-us/kusto/functions-library/pair-probabilities-fl">pair_probabilities_fl</a>()</strong><span>. This function calculates probabilities and some additional metrics for a pair of categorical variables, </span><strong>A</strong><span> and </span><strong>B</strong><span>. In this blog post, we are exploring the possibility of using the pair probabilities function for threat hunting.</span></p><p><span>..</span></p><p><span>Overall, pair probabilities should be best viewed as a way of identifying unusual behaviour for further investigation, rather than as a standalone detection mechanism. The strongest results are likely to come from using the probability metrics as a baseline and in combination with occurrence counts, and additional security context.</span></p></blockquote><p><a href="https://detect.fyi/threat-hunting-using-pair-probabilities-55194ddb8309">https://detect.fyi/threat-hunting-using-pair-probabilities-55194ddb8309</a></p><h2>Online False Positive Reduction via Statistical Process Controls</h2><p><strong>Nikolas Bielski</strong> drops some truth bombs on running an effective SOC.</p><blockquote><p>The SOC isn&#8217;t a unique problem child. It&#8217;s a screening operation, thousands of continuous tests, rare true positives, a fixed budget of expert hours, a high cost for anything missed.</p><p>Other industries solved this by measuring the cost of the noise against the <strong>risk of the miss</strong>. Security chased &#8220;FP reduction&#8221; instead, which is a target with no risk articulated, so set your eyes on optimising to risk.</p><p>GUIDE data gives us a prior for risk. TPs arrive in tight clusters, so the cost of parking a detector is function you can read off the data. 40% of future TPs if you cut it forever, 1.3% if you patch inside 4 hours, 0.3% inside one hour.</p><p>DIRE is just the stats engine that spends the cost deliberately to get 96% of the FPs of a naive cut, at 5% of the TP loss. That&#8217;s an informed case for any for-profit-SOC.</p></blockquote><p><a href="https://detect.fyi/online-false-positive-reduction-via-statistical-process-controls-8609e682c8af">https://detect.fyi/online-false-positive-reduction-via-statistical-process-controls-8609e682c8af</a></p><h2><span>AWS EKS forensics: data sources and investigation tooling</span></h2><p><strong><span>Th&#233;o Letailleur</span></strong><span> provides practical advice on how so stick things together in an AWS EKS ivnestigation.</span></p><blockquote><p>Investigating a compromise in Amazon EKS means piecing together evidence spread across three layers: the managed Kubernetes control plane, the worker nodes, and the surrounding AWS services. This article maps the data sources an EKS cluster exposes for digital forensics and threat hunting, and the tooling used to correlate them, from the Kubernetes audit log down to the AWS identity of the nodes.</p></blockquote><p><a href="https://www.synacktiv.com/en/publications/aws-eks-forensics-data-sources-and-investigation-tooling">https://www.synacktiv.com/en/publications/aws-eks-forensics-data-sources-and-investigation-tooling</a></p><h2>Detection primitives for eBPF rootkits</h2><p><strong>Lorenzo Susini</strong> and <strong>Matt Muir</strong> show what quality detection engineering looks like with this work.</p><blockquote><p>They also defeat common tracing primitives like <code>ptrace</code>. <a href="https://www.synacktiv.com/en/publications/linkpro-ebpf-rootkit-analysis">LinkPro</a>, <a href="https://research.checkpoint.com/2026/voidlink-the-cloud-native-malware-framework/">VoidLink</a>, and the more recent <a href="https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency">Atomic Arch</a> campaign all use these approaches.</p><p>Rather than describe each malware family in full, we picked one instructive feature from each and went deep, looking at how the technique works, what data defenders should focus on, and what detections we built from it. We start with VoidLink, which found an unexpectedly clean way to hide active connections from <code>ss</code> by turning a debug helper into a precise memory editor.</p><p>..</p><p><span>The load-time fingerprint translates directly into detection rules. Because the WP sensor captures the helper bitmap before the program can act, a rule checking for </span><code>BPF_PROBE_WRITE_USER</code><span> fires the moment VoidLink's buffer-tampering program is submitted to the kernel</span></p></blockquote><p><a href="https://securitylabs.datadoghq.com/articles/detection-primitives-for-ebpf-rootkits/">https://securitylabs.datadoghq.com/articles/detection-primitives-for-ebpf-rootkits/</a></p><h1>Defence</h1><p>How we proactively defend our environments.</p><h2><span>Internet Exposure Reduction Guidance</span></h2><p><strong><span>CISA</span></strong><span> highlight once again and guide on the value of attack surface management through reduction.</span></p><blockquote><p>Many organizations unknowingly leave common vulnerabilities and weaknesses exposed to the internet, making them easy targets for exploitation. Threat actors can use internet-based search and discovery platforms to identify publicly accessible systems with misconfigurations, default credentials, and outdated software that they can exploit to gain unauthorized access. By following the guidance below, organizations can proactively identify internet exposures, remove those that are unnecessary, and secure those that are necessary, strengthening their cybersecurity posture.</p></blockquote><p><a href="https://www.cisa.gov/resources-tools/resources/exposure-reduction">https://www.cisa.gov/resources-tools/resources/exposure-reduction</a></p><h2><span>Defending Against an Active Threat to Siemens S7 Series PLCs</span></h2><p><strong><span>CISA</span></strong><span> provide practical advice on how to mitigate this active threat.</span></p><blockquote><p>This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape.</p></blockquote><p><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a</a></p><h2>Auditing Microsoft Defender and Intune Configuration Changes</h2><p><strong><span>Jeffrey Appel</span></strong><span> details how to do this in practice during an incident investigation where you suspect or what to verify if configuration changes have occured.</span></p><blockquote><p>Defender audit activities are stored in the Unified Audit Log. Some of the audited activities include:</p><ul><li><p>Assign user to an incident</p></li><li><p>Changes to data retention settings</p></li><li><p>Changes to advanced features</p></li><li><p>Creation of indicators of compromise</p></li><li><p>Isolation of devices</p></li><li><p>Add\edit\deletion of security roles</p></li><li><p>Create\edit custom detection rules</p></li></ul><p>Microsoft Defender uses the <a href="https://learn.microsoft.com/en-us/purview/audit-solutions-overview">Microsoft Purview auditing solution</a>. Before you can look at the audit data in the Microsoft Defender portal, you need to turn on auditing in the Microsoft Purview portal, or sometimes it works directly from the Defender portal.</p><p>For a list of all the audit log activities, see: <a href="https://learn.microsoft.com/en-us/purview/audit-log-activities#microsoft-defender-xdr-custom-detection-activities">Audit log activities</a>. The audit log is not only focused on Defender for Endpoint. It includes other sources, like Defender for Identity, to report when sensors are getting removed/ disabled, or the deployment key is downloaded. All of the audit log activities are explained on the above page.</p></blockquote><p><a href="https://jeffreyappel.nl/auditing-microsoft-defender-and-intune-configuration-changes/">https://jeffreyappel.nl/auditing-microsoft-defender-and-intune-configuration-changes/</a></p><h2><span>SDLC in the AI &#8203;&#8203;Agent Era: How to Implement Security Engineering</span></h2><p>Chinese view on how to do this.</p><blockquote><p><span>This article discusses the SDLC (Software as a Service) of agents after software delivery, not the lifecycle of the AI/ML model itself, nor how to develop an agent product. The term is occasionally used </span><code>Agentic SDLC</code><span> as a descriptive tag.</span></p><p><span>&#8230;</span></p><p><span>existing security engineering principles still hold true; what has changed are the implementing entities, boundaries, and speed.</span></p></blockquote><p><a href="https://mp.weixin.qq.com/s/QYQ2XDBeXbIXgSmsDMNkFw">https://mp.weixin.qq.com/s/QYQ2XDBeXbIXgSmsDMNkFw</a></p><h2>MadHatter &#8212; Qwen Token Perturbation Lab</h2><p><strong>Allloy Secure Group</strong> show a deep understanding of AI have how token perturbation can be used as a defensive disruption layer against an offensive Qwen-based AI agent. It works by introducing small, targeted token changes that push the agent away from its intended decision path.</p><blockquote><p>MadHatter is a local Qwen research demo for gradient-guided discrete token perturbations, embedding-space PGD, and LoRA post-training. It now includes a second, independent clean Qwen validator so a perturbation found in the lab can be tested against an unmodified base checkpoint.</p></blockquote><p><a href="https://github.com/AlloySecureGroup/MADHATTER/">https://github.com/AlloySecureGroup/MADHATTER/</a></p><h2>Time as a Key: Breaking Rhysida Ransomware with the Attacker&#8217;s Own Ciphertext</h2><p><strong>Adam Taguirov</strong> shows the value of cryptologic skills in the response to ransomware.</p><blockquote><p>Rhysida is a ransomware-as-a-service operation active since May 2023 that has claimed more than 250 victims across education, healthcare and professional services. Its Windows encryptor seeds the C library pseudo-random number generator with srand(time(0)), and every per-file secret produced during a run derives from that single value. The encryption timestamp, a 32-bit counter of seconds, is the only unknown input, and recovering it regenerates the AES-256 key and initialisation vector of every file the run touched. The encryptor wraps each per-file key and IV under a hardcoded RSA public key using OAEP padding, and it draws the OAEP seed from the same generator, so the RSA blob appended to every encrypted file is reproducible byte for byte by anyone holding the sample. We use that blob as a validation oracle: a candidate key is confirmed by re-running the encryptor&#8217;s own RSA step and comparing the result against the stored bytes</p></blockquote><p><a href="https://sigreturn.com/papers/time-as-a-key/">https://sigreturn.com/papers/time-as-a-key/</a></p><h2>neEDRe</h2><p>Sunlife3 releases the foundations of a Linux EDR they are building which will be of interest to some studying how to do such things.</p><blockquote><p>Self-made toy EDR project using AYA the Rust eBPF library</p></blockquote><p><a href="https://github.com/sunlife3/needre">https://github.com/sunlife3/needre</a></p><h1>Incident Writeups &amp; Disclosures</h1><p>How they got in and what they did.</p><h2><span>A Tale of Two SOCs: Insights From Two Red Team Assessments</span></h2><p><span>CISA&#8217;s red team detail the experience of going up against two security operations centres. Whilst highlighting recommendations which would have frustrated their success.</span></p><blockquote><ul><li><p><strong>Untuned detection tools lead to missed threats</strong>. Without well-defined baselines and alert filtering, false positives and routine alerts overwhelm network defenders.</p></li><li><p><strong>Organizational silos and bureaucratic hurdles prevent effective incident response</strong>. Detection tools are only as effective as the people, processes, and procedures supporting them; fragmented communication, unclear responsibilities, and limited defender authority hinder effective incident response.</p></li><li><p><strong>Cloud environments are often an underestimated risk</strong>. Organizations often lack security controls for cloud environments and processes for responding to a cloud compromise.</p></li></ul><p>&#8230;</p><ul><li><p><strong>Establish and continuously maintain a baseline and reduce alert noise</strong> by fine tuning.</p></li><li><p><strong>Break down silos and empower network defenders</strong>.</p></li><li><p><strong>Implement Conditional Access policies for workload identities</strong> and monitor for excessive or unused permissions.</p></li><li><p><strong>Establish and regularly review comprehensive procedures for detecting, remediating, and revoking access/refresh tokens</strong> in the event of a cloud compromise.</p></li></ul></blockquote><p><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a</a></p><h2>Supply chain attack on arrayref</h2><p><strong>Manish Goregaokar</strong> details the incident and provide details of what organisations needs to get assurance of across their developer estate which feels easier said than done for a lot.</p><blockquote><p>We recommend you check your local dependencies to ensure these crates were not pulled in. Here are the malicious versions that we deleted from crates.io:</p><ul><li><p><code>append-only-vec@0.1.9</code>: published at <code>2026-08-20T07:37:49Z</code>, deleted at <code>2026-08-20T09:25:24Z</code>. Online for 107 minutes.</p></li><li><p><code>arrayref@0.3.10</code>: published at <code>2026-08-20T07:15:00Z</code>, deleted at <code>2026-08-20T08:41:40Z</code>. Online for 86 minutes.</p></li><li><p><code>internment@0.8.7</code>: published at <code>2026-08-20T07:34:07Z</code>, deleted at <code>2026-08-20T09:04:11Z</code>. Online for 90 minutes.</p></li><li><p><code>proc-macro1</code>, <code>proc-macro-en</code>, <code>aovine</code>, <code>arone</code>, <code>aronenao</code>, <code>tinymember</code> (any versions).</p></li></ul></blockquote><p><a href="https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/">https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/</a></p><h1>Vulnerability</h1><p>Our attack surface.</p><h2>768 Leaked Corporate AWS Keys Held Full Admin Rights</h2><p><strong>Truffle Security</strong> show the scale of hygiene challenge in practice - no AI required here.</p><blockquote><p><strong> </strong><span>We re-verified 10,616 leaked AWS keys on August 10, 2026. They surfaced publicly between August 2022 and August 2026. 88% still authenticate. 768 of the live ones belong to a company and carry full control of its AWS account: 526 root keys plus 242 IAM users holding </span><code>AdministratorAccess</code><span>. The median live leaked key is five years old and has never been rotated.</span></p></blockquote><p><a href="https://trufflesecurity.com/blog/leaked-corporate-aws-keys-held-full-admin-rights">https://trufflesecurity.com/blog/leaked-corporate-aws-keys-held-full-admin-rights</a></p><h2>SMAP is Pre-Disarmed: How a Stack Pivot That Shouldn&#8217;t Work Revealed a Kernel-Wide Design Compromise</h2><p><strong>Youssef Charfeddine</strong> highlights the ghost of compatibility here and the impact of SMAP effciacy on Windows.</p><blockquote><p>The three experiments proved that SMAP is not bypassed by an attacker trick. It is pre-bypassed by the operating system itself. The normal syscall entry path on Windows 11 delivers kernel code an execution context where AC=1 is already set.</p><p style="text-align: justify;">This means any kernel-mode attacker who gains execution through a standard syscall path (whether via a vulnerable driver, a signed driver with dangerous IOCTLs, or any other mechanism) inherits a kernel context where SMAP is muted.</p></blockquote><p><a href="https://sibouzitoun.tech/articles/smap-is-pre-disarmed/">https://sibouzitoun.tech/articles/smap-is-pre-disarmed/</a></p><h2>From Code to Chain: Why WP2Shell Stayed Out of Reach</h2><p><strong>Zeddy Lu</strong> demonstrates the reality and limitations of AI in finding certain vulnerabilities and thus showing that not all vulnerabilities become shallow - yet.</p><blockquote><p>This paper compares the long-term code auditing capabilities of three major models by reproducing the wp2shell vulnerability chain discovery process: Under the same harness, GPT 5.6 Sol / GLM-5.2 / Qwen 3.8-Max-Preview were run 11 times, each lasting 6&#8211;10 hours, on the complete WordPress codebase, and their exploration process was recorded and reconstructed using full-chain hooking. None of the 11 runs completely reproduced the pre-auth RCE vulnerability chain, but the failure patterns differed: GPT identified REST request misalignment (Vuln A) four times and completed one local verification, but missed SQL injection (Vuln B) all four times; Qwen was the only model to identify Vuln B, but prematurely excluded it due to the lack of a pre-auth entry point; GLM read the core code multiple times but failed to identify any vulnerabilities. In a comparative experiment where only short vulnerable code snippets were provided, all three models were able to find the corresponding vulnerability mechanisms. Overall, the bottleneck in reproducing wp2shell lies not in understanding local code, but in the ability to search source code, retain candidate vulnerabilities, and connect to cross-layer vulnerabilities during long-term exploration.</p></blockquote><p><a href="https://zeddyu.github.io/p/from-code-to-chain-why-wp2shell-stayed-out-of-reach/">https://zeddyu.github.io/p/from-code-to-chain-why-wp2shell-stayed-out-of-reach/</a></p><h2>Compromising Signal&#8217;s Contact Discovery Enclave</h2><p><strong>Nihal Talur</strong> shows what world class vulnerability looks like in 2026.</p><blockquote><p>We found two critical object-lifetime vulnerabilities that allow the untrusted host server to break the enclave boundary. The first vulnerability gives the host an arbitrary enclave memory read. The second gives the host full control over the enclave&#8217;s register context, enabling code execution within the enclave. We exploited both vulnerabilities on real SGX hardware matching the Azure machines used by Signal&#8217;s production deployments, demonstrating full compromise of the enclave. Our proofs of concept extract the Noise private key from enclave memory, allowing the host to impersonate the enclave and decrypt queries.</p></blockquote><p><a href="https://v12.sh/blog/signal">https://v12.sh/blog/signal</a></p><h2><span>Penetrating the Vulnerable with Invisible Thickness: CodeBuddy Security&#8217;s Vulnerability Discovery Approach and Practice</span></h2><p><strong><span>Tencent</span></strong><span> outline their approach which shows what industrialised verified vulnerability discovery looks like in 2026.</span></p><blockquote><p>CodeBuddy Security views vulnerability discovery as a "search" process, with the core concept being that intelligence is the segmentation of the search space&#8212;the more detailed the intelligence, the higher the AI's detection probability. The system is divided into two parts: the first part constructs intelligence and narrows the search space through four pathways: patch location, threat intelligence, external intelligence, and attack surface analysis; the second part uses an AI Agent to conduct audits at the module level, confirming the results after independent review and PoC verification. Since its launch, it has driven 4.4 million model calls, generating over 2,100 automatically reproduced vulnerabilities; the end-to-end detection rate is 73.2%, reaching 90.2% after providing module-level intelligence.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!MIZH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb362ff33-d887-4705-801f-86b152f58306_1080x720.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!MIZH!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb362ff33-d887-4705-801f-86b152f58306_1080x720.webp 424w, /__u/substackcdn.com/image/fetch/$s_!MIZH!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb362ff33-d887-4705-801f-86b152f58306_1080x720.webp 848w, /__u/substackcdn.com/image/fetch/$s_!MIZH!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb362ff33-d887-4705-801f-86b152f58306_1080x720.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!MIZH!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb362ff33-d887-4705-801f-86b152f58306_1080x720.webp 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!MIZH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb362ff33-d887-4705-801f-86b152f58306_1080x720.webp" width="1080" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b362ff33-d887-4705-801f-86b152f58306_1080x720.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="/__u/substackcdn.com/image/fetch/$s_!MIZH!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb362ff33-d887-4705-801f-86b152f58306_1080x720.webp 424w, /__u/substackcdn.com/image/fetch/$s_!MIZH!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb362ff33-d887-4705-801f-86b152f58306_1080x720.webp 848w, /__u/substackcdn.com/image/fetch/$s_!MIZH!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb362ff33-d887-4705-801f-86b152f58306_1080x720.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!MIZH!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb362ff33-d887-4705-801f-86b152f58306_1080x720.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://mp.weixin.qq.com/s/9RkpfwzQivCgEAKIiiiKDw">https://mp.weixin.qq.com/s/9RkpfwzQivCgEAKIiiiKDw</a></p><h2>GPUThor</h2><p><strong>Chris S. Lin</strong><span>, </span><strong>Joyce Qu</strong><span>, </span><strong>Aditya Rajeev</strong><span>, and </span><strong>Gururaj Saileshwar </strong>show that it turns out physics don&#8217;t change when used in a different use case and thus vulnerabilities read across.</p><blockquote><p>GPUThor is the first Rowhammer attack on NVIDIA GPUs to break through error-correcting codes (ECC), NVIDIA's defense against this threat<span>. Rowhammer is a DRAM flaw: repeatedly hammering a memory row flips bits in its neighboring rows, causing data corruptions. By reverse-engineering how GPUs merge repeated memory requests and when the memory's built-in defense kicks in, GPUThor hammers its target </span>6.6&#215; harder<span> than prior GPU attacks, producing </span>500&#215;&#8211;23,500&#215; more bit flips<span>. This corrupts multiple bits at once and overwhelms the ECC, enabling the first GPU denial-of-service attacks and root-level privilege escalation on ECC-protected GPUs.</span></p></blockquote><p><a href="https://gputhor.com/">https://gputhor.com/</a></p><h2>UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range</h2><p><strong>Olivier Laflamme </strong>writes the business case for memory safety technology in robotics with this vulnerability. But also how the integration of AI not being done always in Secure by Design manner.</p><blockquote><p>Root on a $20,000 humanoid robot from Bluetooth range. One chain crossing Bluetooth, Unitree&#8217;s cloud, mobile, and the firmware running the G1 itself. Here&#8217;s the complete technical breakdown of the $6,700 bounty and two CVEs it produced: CVE-2026-76639 / CVE-2026-76640.</p><p>&#8230;</p><p>A path traversal in the robot's AI chatbot knowledge base that leaks the binary's load address. And a 1050-byte BSS buffer overflow that corrupts the event loop into calling system() as root.</p></blockquote><p><a href="https://boschko.ca/g1-ble-rce/">https://boschko.ca/g1-ble-rce/</a></p><h2>WatchGuard Agent improper authentication allows unauthenticated remote code execution</h2><p>WatchGuard warn the call can come from inside the house.</p><blockquote><p>Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.</p></blockquote><p><a href="https://psirt.watchguard.com/CVE-2026-57910/">https://psirt.watchguard.com/CVE-2026-57910/</a></p><h1>Offense</h1><p>Attack capability, techniques and trade-craft. </p><h2>I&#8217;m in your logs now: deceiving analysts and blinding EDRs</h2><p><strong>Olaf Hartong</strong> demonstrates an offensive strategy that various red teams have employed in the past.</p><blockquote><p>what if I can create enough telemetry, or enough broken telemetry behavior, that the product relying on those logs does not see the real activity anymore?</p></blockquote><p><a href="https://falconforce.nl/in-your-logs-now/">https://falconforce.nl/in-your-logs-now/</a></p><h2>Tag, You&#8217;re Managed - Executing Code via Google&#8217;s Own Signed Installer</h2><p><strong>Richard Warren</strong> highlights this attack surface.. it will be interesting to see if this was used other by red teamers when the threat hunting crews go to work.</p><blockquote><p>in this post we show how an attacker can take a legitimately signed Google Chrome Enterprise MSI and modify it to execute arbitrary commands on the victim&#8217;s machine, without breaking the Authenticode signature. The modified installer remains validly signed by Google throughout, passing SmartScreen and signer-based AppLocker/WDAC rules.</p></blockquote><p><a href="https://blog.amberwolf.com/blog/2026/august/tag-youre-managed---executing-code-via-googles-own-signed-installer/">https://blog.amberwolf.com/blog/2026/august/tag-youre-managed---executing-code-via-googles-own-signed-installer/</a></p><h2>ditto</h2><p><strong>Airbus</strong> release this which teams will want to ensure doesn&#8217;t break their detection logic.</p><blockquote><p><span>Ditto is a Powershell and JavaScript obfuscator base on </span><a href="https://github.com/airbus-cert/tree-sitter-powershell">tree-sitter-powershell</a><span> and </span><a href="https://github.com/tree-sitter/tree-sitter-javascript">tree-sitter-javascript</a><span>.</span></p></blockquote><p><a href="https://github.com/airbus-cert/ditto">https://github.com/airbus-cert/ditto</a></p><h2>NachoMDM - Weaponising Windows MDM for UAC Bypass and SYSTEM Execution via Malicious Enrollment</h2><p><strong><span>David Cash </span></strong><span>causes questions to be raised on where this has worked in production.</span></p><blockquote><p>The bonus is that this enrolment process can be triggered from a web page via the <code>ms-device-enrollment</code> URI handler. There&#8217;s a video demo further down the post that shows it in action.</p><p>Who is NOT vulnerable:</p><ul><li><p>If the device is already enrolled in MDM, it cannot be enrolled again.</p></li><li><p>If the user is not a member of the local administrators group, the auto elevation will fail</p></li></ul></blockquote><p><a href="https://blog.amberwolf.com/blog/2026/august/weaponising-windows-mdm/">https://blog.amberwolf.com/blog/2026/august/weaponising-windows-mdm/</a></p><p><a href="https://github.com/AmberWolfCyber/NachoMDM">https://github.com/AmberWolfCyber/NachoMDM</a></p><h2>lldp</h2><p><strong>Lav</strong> shows the lengths some red teams will go to avoid implant detection.</p><blockquote><p>Mythic C2 profile for peer-to-peer communication over IEEE 802.1AB (LLDP). C2 data is carried inside Organizationally Specific TLVs (Type 127) with a configurable OUI so that frames blend with vendor-specific LLDP extensions on the wire.</p><p>LLDP is Layer 2 only. Both agents must share a broadcast domain. An egress agent (HTTP/HTTPX) bridges LLDP-linked agents back to the Mythic server, same as the SMB and TCP P2P profiles.</p></blockquote><p><a href="https://github.com/Whispergate/lldp">https://github.com/Whispergate/lldp</a></p><h2>Tailcat</h2><p><strong>Brad Fitzpatrick</strong> et al release this tool which you can see how it might be misused and thus warrant attention on the the ability to detect.</p><blockquote><p><span>Tailcat is a remix of Tailscale open source pieces to act like </span><a href="https://en.wikipedia.org/wiki/Netcat">netcat</a><span>, but over Tailscale's data plane, without Tailscale's control plane. Tailscale's data plane (</span><code>magicsock</code><span>, internally) gives you point-to-point WireGuard&#174;-encrypted tunnels between two machines with DERP as the NAT-hole-punching communication side channel and the ultimate relay-of-last-resort if NAT traversal fails. Instead of using the Tailscale control plane, all </span><code>tailcat</code><span> connection metadata is exchanged out of band, however you want.</span></p></blockquote><p><a href="https://github.com/tailscale/tailcat">https://github.com/tailscale/tailcat</a></p><h2>Exploiting SMTP with Unicode Bidi Override Spoofing: The Gap Between Auth &amp; Render</h2><p><strong><span>Anna Breeva </span></strong><span>highlights a gap which detection teams will want to get after.</span></p><blockquote><p>a new email spoofing technique that abuses Unicode bidirectional (Bidi) controls together with <code>SMTPUTF8</code> to make an attacker-controlled email address visually appear to belong to a trusted domain.</p><p>Unlike traditional email spoofing, the attacker does not need to forge the sender&#8217;s domain or bypass SPF, DKIM, or DMARC. The message can legitimately pass all three authentication mechanisms while the recipient is shown a visually reordered sender address belonging to an entirely different organization.</p><p>The issue stems from a gap between how email infrastructure <strong>authenticates an address</strong> and how email clients <strong>render that address to a human</strong>. In our testing, an attacker-controlled address belonging to <code>31337p.com</code> could be visually rendered as an address belonging to <code>bigcorp.com</code> - while the underlying authenticated domain remained <code>31337p.com</code>.</p></blockquote><p><a href="https://securityjoes.com/blog/exploiting-smtp-with-unicode-bidi-override-spoofing-the-gap-between-auth-and-render">https://securityjoes.com/blog/exploiting-smtp-with-unicode-bidi-override-spoofing-the-gap-between-auth-and-render</a></p><h1>Exploitation</h1><p>What is being exploited..</p><h1>Tooling and Techniques</h1><p>Low level tooling and techniques for attack and defence researchers</p><h2>Natural Language Nmap (nmap-nl)</h2><p><strong>Steve</strong> makes everyone who could remember optimised nmap command lines feel slightly on the verge of redundancy. </p><blockquote><p>A lightweight, local command-line interface tool that translates natural language requests into raw Nmap commands and executes them in real-time, utilizing a locally hosted fine-tuned Gemma-3-270M model</p></blockquote><p><a href="https://github.com/evets007/natural-language-nmap">https://github.com/evets007/natural-language-nmap</a></p><h2>Rogue Framework</h2><p><strong>Mohammad Hossein Aghaee</strong> released this framework which lays the foundation for AI augmentation.</p><blockquote><p>Rogue Framework is a desktop workbench for AFL++, cross-architecture QEMU fuzzing, harness development, lightweight Ghidra headless analysis, custom mutators, and patch comparison. It is intentionally an auditable workbench rather than a button-only wrapper: every generated AFL++ command is visible before execution, and generated harnesses are ordinary source files that the researcher can edit. It suppose to be "The BurpSuite of exploit developers"</p></blockquote><p><a href="https://github.com/ThisIsTFS/Rogue-Framework">https://github.com/ThisIsTFS/Rogue-Framework</a></p><h2>GhostDebug</h2><p><strong>VollRagm</strong> provides a power tool again showing how the cyber security community can and should learn from the game cheat community.</p><blockquote><p>GhostDebug is a Windows x64 debugger prototype composed of a native debugging DLL and a .NET Framework command-line client. It is intended for debugging targets that use debugger-detection checks.</p></blockquote><p><a href="https://github.com/VollRagm/ghostdebug/">https://github.com/VollRagm/ghostdebug/</a></p><h2>Microsoft Paint and Photos Embed Server-Issued GUIDs as Invisible Watermarks in Locally-Generated Images</h2><p><strong>Xusheng Li</strong> highlights these watermarks exist.</p><blockquote><ul><li><p>Microsoft Paint supports both local and cloud image generation</p></li><li><p>Paint and Photos also ship local AI models</p></li><li><p>The two apps send the prompt to a remote server for moderation</p></li><li><p>The server returns a GUID along with the moderated prompt</p></li><li><p>The GUID is embedded into the locally generated image as an invisible watermark</p></li><li><p>A separate visible-watermark setting does not control this invisible watermark</p></li><li><p>On Copilot+ PCs, image generation is local but prompt moderation remains remote</p></li><li><p>Microsoft discloses that Paint adds C2PA metadata to AI-generated images</p></li><li><p>AI-generated image saves limited to C2PA-preserving formats: PNG, JPEG, GIF, and <code>.paint</code></p></li></ul></blockquote><p><a href="https://xusheng.dev/posts/reversing/mspaint_invisible_watermark/main/">https://xusheng.dev/posts/reversing/mspaint_invisible_watermark/main/</a></p><h2>Closing a Critical Internet Privacy Gap for Billions of Users: Android 17 Rolls Out ECH Support</h2><p><strong>Maddy Hoffman</strong> details the role out - be interesting to see the impact on threat hunting where SNI inspection is used a lot in enterprises and especially for mobile devices where telemetry isn&#8217;t where it needs to be.</p><blockquote><p><span>Starting with </span><a href="https://blog.google/security/new-Android-network-security-protections">Android 17, ECH GREASE will be enabled by default</a></p><p><span>To help app developers leverage this new capability, </span><a href="https://github.com/lysine-dev/okhttp">OkHttp</a><span>, the open-source HTTP client powering millions of Android apps, has integrated ECH support into its core library.</span></p></blockquote><p><a href="https://medium.com/jigsaw/closing-a-critical-internet-privacy-gap-for-billions-of-users-android-17-rolls-out-ech-support-c52b49a62c04">https://medium.com/jigsaw/closing-a-critical-internet-privacy-gap-for-billions-of-users-android-17-rolls-out-ech-support-c52b49a62c04</a></p><h1>Footnotes</h1><p>Some other small (and not so small) bits and bobs which might be of interest.</p><ul><li><p>Annual, quarterly and monthly reports</p><ul><li><p><em>Nothing overly of note this week, but keep an eye on</em> <a href="https://github.com/jacobdjwilson/awesome-annual-security-reports/tree/main/Annual%20Security%20Reports/2026">the Awesome Annual Security Reports 2026 collection</a> and <a href="https://github.com/blackorbird/APT_REPORT">APT report collection</a></p></li></ul></li><li><p><a href="https://www.usenix.org/conference/usenixsecurity26/presentation/talur">SONIC: Concurrent Oblivious RAM &amp; Data Structures for Low-Latency and High-Throughput</a></p></li><li><p><a href="https://arxiv.org/abs/2508.05355">Equivocation-resistant multiparty digital signature for quantum networks</a></p></li><li><p><a href="https://eprint.iacr.org/2026/1630.pdf">Quasipolynomial Cryptanalysis of the McEliece Cryptosystem (or: PIR Meets McEliece)</a></p></li><li><p><a href="/__u/thingsdavidthinks.substack.com/p/the-perplexing-rise-of-mathematics?r=15ilg3&amp;utm_campaign=posts-open-in-app&amp;utm_medium=web&amp;triedRedirect=true">The perplexing rise of mathematics</a></p></li><li><p><a href="https://tmpout.sh/5/">tmp.0ut V</a></p></li><li><p><a href="https://arxiv.org/abs/2608.22202">Lessons from the Hardware Hacking Competitions: Verification Techniques, Findings, and Insights</a></p></li><li><p>Artificial intelligence</p><ul><li><p><span>if you are a big </span><a href="https://arxiv.org/">arxiv.org</a><span> user - out of China there is </span><a href="https://www.alphaxiv.org/">alphaxiv.org</a><span> which is an AI powered incarnation / overlay</span></p></li><li><p>Fundamental</p><ul><li><p><a href="https://arxiv.org/abs/2606.06479">Pretraining Recurrent Networks without Recurrence</a></p></li><li><p><a href="https://arxiv.org/abs/2407.19115">Towards Scalable and Stable Parallelization of Nonlinear RNNs</a></p></li><li><p><a href="https://arxiv.org/abs/2608.16157">FreeToken: Efficient Edge-Native MoE Serving with Bandwidth-Adaptive Execution</a></p></li></ul></li><li><p>Applied non-cyber</p><ul><li><p><a href="https://arxiv.org/abs/2608.16753v1">Mathematics in the age of AI</a></p></li><li><p><a href="https://arxiv.org/abs/2607.29380">The Tragedy of the Cognitive Commons: How AI Could Disrupt the Regeneration of Professional Expertise</a></p></li><li><p><a href="https://openreview.net/forum?id=e3pxJbBRBk">Hawkeye: Hardware-Aware GPU Kernel Optimization with Minimal Supervision</a></p></li><li><p><a href="https://arxiv.org/html/2508.17771v1">Speculating LLMs&#8217; Chinese Training Data Pollution from Their Tokens</a></p></li><li><p><a href="https://arxiv.org/abs/2606.15762">Snyk VulnBench JS 1.0: Can LLMs Find the Same Bugs Twice?</a></p></li><li><p><a href="https://pwning.systems/posts/llm-memory-program-analysis/">I accidentally turned LLM memory into program analysis</a></p></li><li><p><a href="https://arxiv.org/abs/2608.27148">AgentDV: Closed-Loop Agentic AI for Hardware Design Verification</a></p></li><li><p><a href="https://arxiv.org/abs/2608.26651">Beyond Vector Hiding: Breaking and Mitigating Shared-Direction Weight Obfuscation in TEE-Offloaded Large Language Models</a></p></li><li><p><a href="https://arxiv.org/abs/2608.26222">NeuronFuzz: Safety Neuron Guided Fuzzing for LLM Safety Evaluation</a></p></li><li><p><a href="https://arxiv.org/abs/2608.26157">GROUND: Reducing Hallucinations in LLM-Based Enterprise Analytics Through Governed Semantic Definitions</a></p></li></ul></li><li><p>Applied cyber specific</p><ul><li><p><a href="https://arxiv.org/abs/2608.09867">Stealing Reasoning Traces from Proprietary LLM APIs</a></p></li><li><p><a href="https://arxiv.org/abs/2608.21986">AI Grinding for Fun and Cryptanalysis</a></p></li><li><p><a href="https://seth.engr.tamu.edu/short-courses/ecen-689-llms-for-agentic-hardware-design-and-security/">LLMs for Agentic Hardware Design and Security</a> - Teax A&amp;M University new training course</p></li><li><p><a href="https://www.bfswa.blog/p/blood-meridian-131?hide_intro_popup=true&amp;open=false">Blood MERIDIAN: LLM cryptanalysis of a blockcipher that is isn&#8217;t a blockcipher</a></p></li><li><p><a href="https://zeddyu.github.io/p/from-code-to-chain-why-wp2shell-stayed-out-of-reach/">From Code to Chain: Why WP2Shell Stayed Out of Reach</a></p></li><li><p><a href="https://github.com/AlloySecureGroup/MADHATTER/">MadHatter &#8212; Qwen Token Perturbation Lab</a></p></li><li><p><a href="https://bughunters.google.com/blog/scaling-memory-safety">Scaling Memory Safety: AI-Assisted Rewrites of C/C++ Dependencies to Rust</a></p></li><li><p><a href="https://arxiv.org/abs/2608.25667">AI Slop and Hallucinations in Vulnerability Assessment: A Survey on Reasoning Failures and Trustworthy Mitigation</a></p></li><li><p><a href="https://arxiv.org/abs/2608.25158">FuzzingBrain-Bench V1: Evaluating Open-Ended Bug Discovery by LLMs</a></p></li><li><p><a href="https://arxiv.org/abs/2608.25321">LLMscope: Extracting LLM Assets from Edge AI Chips via Optical Probing</a></p></li><li><p><a href="https://arxiv.org/abs/2608.24962">Evaluating and Preventing Security Smells in AI-Generated Ansible Code</a></p></li><li><p><a href="https://arxiv.org/abs/2608.21547">Enhancing User Resilience Against AI-Augmented Phishing: A Two-Stage Framework for Detection and Personalized Training</a></p></li><li><p><a href="https://arxiv.org/abs/2608.27299">When Context Gets Root: Privilege Escalation in LLM Harnesses</a></p></li><li><p><a href="https://arxiv.org/abs/2608.26882">PLCBench: Can Autonomous LLM Agents Turn PLC Access into Sustained Physical Impact?</a></p></li><li><p><a href="https://arxiv.org/abs/2608.26699">KubeCap: A Framework for Capability Minimization in Kubernetes via Static Analysis and LLM-Assisted Rule Inference</a></p></li><li><p><a href="https://arxiv.org/abs/2608.26588">Unsaid, Unsafe? Implicit Security Obligations in LLM-Based RTL Code Generation</a></p></li><li><p><a href="https://arxiv.org/abs/2608.25817">SkillShield: Prompt-Space Security Skills for LLM Coding Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2608.25727">Are LLM-Enhanced GNNs Privacy-Safe?</a></p></li><li><p><a href="https://arxiv.org/abs/2608.24269">Towards LLM-Enhanced Android Taint Analysis</a></p></li><li><p><a href="https://arxiv.org/abs/2608.23550">When &#8220;Do Not&#8221; Is Not Deny: <span>Security</span> Rules in CLAUDE.md vs Built-In Controls</a></p></li><li><p><a href="https://arxiv.org/abs/2608.23471">InjecMEM: Memory Injection Attack on LLM Agent Memory Systems</a></p></li><li><p><a href="https://arxiv.org/abs/2608.22812">The Surprising Effectiveness of <span>LLMs</span> in BGP <span>Security</span>: Mining An Unprecedented Amount of Incidents and Boosting Anomaly Detection</a></p></li><li><p><a href="https://arxiv.org/abs/2608.22089">On Predicting Vulnerability Severity Using In-Context Learning: An Industrial Case Study</a></p></li></ul></li></ul></li><li><p>Books</p><ul><li><p><em>Nothing overly of note this week</em></p></li></ul></li><li><p>Events</p><ul><li><p><em>Nothing overly of note this week</em></p></li></ul></li></ul><p>Video of the week is from CyberUK &#8216;How to justify security investments with actual evidence&#8217; by Dr Daniel Woods</p><div id="youtube2-0OQyA8LKJ8E" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;0OQyA8LKJ8E&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/0OQyA8LKJ8E?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Finally finally the <a href="https://creators.spotify.com/pod/profile/national-cyber-security-c6/episodes/The-Ransomware-Ecosystem-e2hi088">NCSC&#8217;s podcast series</a>.</p><div><hr></div><p><em>Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them. </em></p><p><em>This newsletter is subject to the NCSC website terms and conditions which can be found at <a href="https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions">https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions</a> and you can find out more about how will treat your personal information in our privacy notice at <a href="https://www.ncsc.gov.uk/section/about-this-website/privacy-statement">https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.</a></em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CTO at NCSC - Cyber Defence Analysis! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CTO at NCSC Summary: week ending August 23rd]]></title><description><![CDATA[&#8220;Use safeguards, sandboxing and active oversight to realise the benefits of autonomous systems while limiting the unintended activity.&#8221;]]></description><link>https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-13a</link><guid isPermaLink="false">https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-13a</guid><dc:creator><![CDATA[Ollie Whitehouse]]></dc:creator><pubDate>Sat, 22 Aug 2026 09:18:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!XOeg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe484bb3e-7450-4a87-861e-e7e98f329432_919x919.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to the weekly highlights and analysis of the&nbsp;<a href="https://infosec.pub/c/blueteamsec?dataType=Post&amp;sort=New">blueteamsec</a>&nbsp;(and my wider reading). Not everything makes it in, but the best bits do. A community member is doing <a href="https://briefing.workshop1.net/">daily AI generated podcast of the last 24hours of posts</a>.</p><p>Operationally this week nothing overly of note.</p><p>In the high-level this week:</p><ul><li><p><a href="https://www.ncsc.gov.uk/blogs/managing-the-cyber-risk-of-agentic-ai"><span>Managing the cyber risk of agentic AI</span></a><span> - </span><strong><span>NCSC</span></strong><span> UK publish - &#8220;</span><em>Use safeguards, sandboxing and active oversight to realise the benefits of autonomous systems while limiting the unintended activity.&#8221;</em></p></li><li><p><a href="https://www.ncsc.gov.uk/blogs/help-shape-the-future-of-resilient-private-5g"><span>Help shape the future of resilient private 5G</span></a><span> - </span><strong><span>NCSC</span></strong><span> UK invite - &#8220;</span><em>The NCSC wants to collaborate with organisations developing technologies and approaches for secure, resilient and deployable private 5G&#8221;</em></p></li><li><p><a href="https://www.gov.uk/government/statistics/uk-public-survey-of-risk-perception-resilience-and-preparedness-2026">UK Public Survey of Risk Perception, Resilience and Preparedness: 2026</a> - <strong>Cabinet Office</strong> publish - <em>&#8220;Compared to 2025, the perceived likelihood of most emergencies remained broadly stable. .. The perceived likelihood of a &#8230;  a cyber attack affecting critical infrastructure rose by three percentage points (39% to 42%).&#8221;</em></p></li><li><p><a href="https://www.gov.uk/government/calls-for-evidence/call-for-evidence-on-the-impact-and-effectiveness-of-sections-1-to-13-of-the-telecommunications-security-act-2021">Call for evidence on the impact and effectiveness of Sections 1 to 13 of the Telecommunications (Security) Act 2021</a> - <strong>Department for Digital, Culture, Media and Sport</strong><span> and </span><strong>Department for Science, Innovation and Technology </strong>publish - <em>&#8220;The call for evidence seeks views from all stakeholders who have engaged with the Telecommunications (Security) Act 2021, the Electronic Communications (Security Measures) Regulations 2022, and the Telecommunications Security Code of Practice.&#8221;</em></p></li><li><p><a href="https://www.nbu.gov.sk/varovanie-pred-rizikami-cestnych-meradiel/">The National Security Authority warns of a significant cyber threat associated with the use of several types of road speed cameras</a> - National Security Authority of the Slovak Republic warns - &#8220;<em>The National Security Authority, through a security analysis conducted on a loaned sample of the NERO R-ONE road speedometer, identified several security risks, including:</em></p><ul><li><p><em>the true origin of the camera hardware and software,</em></p></li><li><p><em>inconsistency between the documented and detected configuration of the product&#8217;s communication interfaces,</em></p></li><li><p><em>pre-configured remote access and product management mechanisms, the configuration of which is not fully available to the user,</em></p></li><li><p><em>inconsistency between the declared and actually used software ensuring measurement processing,</em></p></li><li><p><em>poor software security.&#8221;</em></p></li></ul></li><li><p><a href="https://www.turing.ac.uk/blog/we-need-more-complete-picture-cyber-attacks-uk-critical-national-infrastructure"><span>We need a more complete picture of cyber-attacks on UK critical national infrastructure</span></a><span> - </span><strong><span>Alan Turing Institute</span></strong><span> leverage freedom of information - &#8220;</span><em>To elicit a more grounded picture of cyberattacks on UK CNI, we sent FOI requests to regulators spanning England, Wales, Scotland and Northern Ireland to gain access to their data. This data collection exercise was complemented by analysis of advisories published by US authorities which provided more detail than the UK data on how attacks are carried out. Our data showed that during 2024, nearly one third (29%) of incident reports made under the regulations concerning network and information systems related to cyberattacks. The data we obtained also provided us with important insight into the attackers&#8217; motivations. Of six health-sector incidents in England that met the reporting threshold in 2024, five were ransomware attacks and the sixth was a power outage.&#8221;</em></p></li><li><p><a href="https://www.whitehouse.gov/wp-content/uploads/2026/08/NSSTS-082026.pdf">National Security Science &amp; Technology Strategy</a> - <strong>The White House</strong> (not me) publishes - <em>&#8220;building segmentation into critical network architectures, and modernizing cryptography and cyber infrastructure. This also includes prioritizing S&amp;T to secure operational technology and industrial control systems through cyber-physical threat modeling and AI-driven anomaly detection.&#8221;</em></p></li><li><p><a href="https://www.csis.org/analysis/presidential-memo-combating-transnational-cybercrime-implications-industry-and-government"><span>The Presidential Memo on Combating Transnational Cybercrime: Implications for Industry and Government</span></a><span> - </span><strong><span>Center for Strategic and International Studies</span></strong><span> think tanks - </span><em><span>&#8220;It is a pivotal moment for security in cyberspace. State actors are ramping up activity, as we have seen with the likely Iranian </span>attacks<span> on U.S. water facilities, while high-profile cybercriminal </span>incidents<span> are impacting more sectors across the U.S. economy and society, such as </span>schools<span>. U.S. government actors have their hands full and should make use of industry&#8217;s talent and hunger to help.&#8221;</span></em></p></li><li><p><a href="https://www.csis.org/analysis/cyberattacks-us-water-sector-and-iran-question-escalation-or-opportunism">The Cyberattacks on the U.S Water Sector and the Iran Question: Escalation or Opportunism?</a> - <strong>Center for Strategic and International Studies</strong> think tanks - <em>&#8221;The answer is not yet. Psychological effect is precisely the point of Iran&#8217;s cyber operations, to sow fear, chaos, and division, as part of its information warfare strategy. If these attacks are indeed Iran&#8217;s doing, this commentary asserts four reasons the water incidents do not constitute escalation in this conflict; they should be regarded as opportunistic disruption owing to weak U.S. cyber defenses, rather than a turning point.&#8221;</em></p></li><li><p><a href="https://cset.georgetown.edu/publication/outpaced-ai-and-policys-role-in-transforming-cybersecurity-compliance/">Outpaced: AI and Policy&#8217;s Role in Transforming Cybersecurity Compliance</a> - <strong>Center for Security and Emerging Technology</strong> think tanks - &#8220;<em>Despite decades of reform efforts, the federal government&#8217;s Authorization to Operate (ATO) process is a major barrier to delivering secure systems to warfighters at speed. This report examines why past ATO reforms have fallen short of their intent, and offers recommendations to getting leading American technology into the hands of warfighters faster and securely.&#8221;</em></p></li><li><p><a href="https://www.girlguiding.org.uk/what-we-do/events-and-opportunities/event-and-opportunity-finder/volunteer-girlguidings-technology-advisory-group/">Volunteer with our Technology Advisory Group</a> - UK <strong>Girlguiding</strong> call for volunteers - <em>&#8220;We&#8217;re looking for experienced digital, data and technology professionals to join our new Technology Advisory Group as volunteers.&#8221;</em></p></li><li><p>Reporting on/from China</p><ul><li><p><a href="https://techcrunch.com/2026/08/19/t-mobile-chopped-a-cable-to-expel-chinese-hackers-from-its-network/">T-Mobile &#8216;chopped a cable&#8217; to expel Chinese hackers from its network</a> - <strong>Tech Crunch</strong> proxy reports - <em>&#8220;<span>New </span><a href="https://www.bloomberg.com/news/newsletters/2026-08-19/t-mobile-cyber-staff-chopped-cable-after-finding-chinese-hack">reporting from Bloomberg</a><span> revealed how cybersecurity staff at U.S. phone provider T-Mobile identified and expelled Chinese hackers from its network in 2024 during a spate of industry-wide intrusions by Beijing aimed at stealing customer data.&#8221;</span></em><span> &#8230;. </span><em><span>&#8220;After identifying the breach, T-Mobile&#8217;s cybersecurity chief, Jeff Simon, told Bloomberg that he and three others drove to the data center nearby to its Bellevue, Washington headquarters, found the compromised system, pulled out a set of scissors, and snipped the cable connecting the box to the outside world.&#8221;</span></em></p></li><li><p><a href="https://www.bbc.co.uk/programmes/w3ct9kt0">The Documentary, China: The rise of a science superpower</a> - <strong>BBC World Service</strong> broadcasts - <em>&#8220;Roland Pease explores how decades of strategic investment and diligent educational reform have brought China to the brink of global scientific dominance.&#8221;</em></p></li><li><p><a href="https://www.wsj.com/opinion/china-presses-a-weakness-in-americas-tech-policy-2391ed0e?st=DBV25j">China Presses a Weakness in America&#8217;s Tech Policy</a> - <strong>Wall Street Journal</strong> opines - <em>&#8220;The danger is twofold. China is reducing its own dependence on foreign-controlled  [chip] architectures while positioning itself to lead in commercializing the open alternative [RISC-V].&#8221;</em></p></li><li><p><a href="https://www.nytimes.com/2026/08/17/world/asia/china-ai-data-chatbots.html">China Wants to Shape What the World&#8217;s A.I. Knows</a> - <strong>New York Times</strong> reports - <em>&#8220;Earlier this year, the country&#8217;s National Data Administration unveiled a <a href="https://archive.ph/o/Oq9Yq/https://www.nda.gov.cn/sjj/zwgk/zcfb/0608/20260608172117399715004_pc.html">blueprint</a> to transform China into a data powerhouse by the end of 2028. The plan proposed creating &#8220;high quality&#8221; data sets in more than two dozen strategic fields, including scientific research, industrial manufacturing and autonomous vehicles. The plan calls on China to share its data sets worldwide. That was reinforced last month when China pledged to share data to help the dozens of developing countries that attended the <a href="https://archive.ph/o/Oq9Yq/https://www.nytimes.com/2026/07/17/business/xi-jinping-china-ai.html">World Artificial Intelligence Conference in Shanghai</a> build their own A.I. systems. China has also already released huge troves of data curated by government labs and state-owned media, making them available for download around the world. The goal, analysts say, is twofold: to draw more users into China&#8217;s A.I. orbit and to narrow the gap with the United States in access to high-quality training data, which Beijing believes is helping America maintain its lead.&#8221;</em></p></li></ul></li><li><p> AI</p><ul><li><p><a href="https://www.ncsc.gov.uk/blogs/managing-the-cyber-risk-of-agentic-ai">Managing the cyber risk of agentic AI</a> - <strong>NCSC</strong> UK publish - &#8220;<em>Use safeguards, sandboxing and active oversight to realise the benefits of autonomous systems while limiting the unintended activity.&#8221;</em> </p></li><li><p><a href="https://arxiv.org/abs/2608.17671">Benchmarking Automated Security Patch Backporting: How Far Are We?  </a>- <strong>many Chinese universities</strong> measure - <em>&#8220;Performance degrades sharply on structurally complex patches: the best commit-level success rate falls from 85.2% on Type-I patches to 24.0% on Type-IV.&#8221;</em></p></li><li><p><a href="https://transluce.org/docent/blog/coding-agent-behaviors">Measuring coding agent misalignment in the wild</a> - <strong>Transluce</strong> measures - <em>&#8220;We studied rates of coding agent misalignment in 8,600 real-world coding agent sessions. We found severe cases of monitor evasion and misrepresenting success in a small but non-negligible fraction of sessions (around 2% for each behavior). In these cases, agents merge PRs to main without authorization, falsely claim approval from review agents, and reason that they shouldn&#8217;t disable tests before quietly doing so anyway.&#8221;</em></p><ul><li><p><a href="https://docent.transluce.org/dashboard/2588573f-daa3-4130-9bce-e60ba5db04c1/analysis-plan/63a42556-6ac0-4fa5-8956-af2f5e00b823">Cases of monitor evasion and overselling on SWE-chat, sorted by severity</a></p></li></ul></li><li><p><a href="https://blog.google/security/how-google-is-making-private-ai-practical-with-homomorphic-encryption/">How Google is Making Private AI Practical with Homomorphic Encryption</a> - <strong>Jeremy Kun</strong> details - <em>&#8220;HEIR can convert pre-trained AI models that operate on unencrypted data to operate on encrypted inputs. Our vision is to make HEIR a one-click solution to enable non-experts to incorporate encrypted inference into production applications.&#8221;</em></p></li><li><p><a href="https://www.irregularwarfare.org/ai-in-cyber-conflict-short-term-offensive-opportunities-long-term-defensive-advantage/">AI in Cyber Conflict: Short-term Offensive Opportunities, Long-term Defensive Advantage</a> - <strong>Irregular Warfare</strong> think tanks - <em>&#8220;<span>On the one hand, AI automation could massively enhance the effectiveness of cyber operations and campaigns below the threshold of war </span><a href="https://www.tandfonline.com/doi/full/10.1080/13600826.2023.2248179?ref=irregularwarfare.org">as some</a><span> </span><a href="https://www.cam.ac.uk/stories/malicious-ai-report?ref=irregularwarfare.org">have predicted</a><span>. If true, states would be able to achieve even more strategic gains through irregular warfare than U.S. national defense strategy </span><a href="https://media.defense.gov/2026/Jan/23/2003864773/-1/-1/0/2026-NATIONAL-DEFENSE-STRATEGY.PDF?ref=irregularwarfare.org">assumes</a></em><span>. &#8230; </span><em><span>In a </span><a href="https://direct.mit.edu/isec/article/50/3/86/135683/Deception-and-Detection-Why-Artificial?ref=irregularwarfare.org">new article</a><span> published in </span>International Security<span>, I argue that these expectations are likely misplaced. Contrary to prevailing expectations, cyber defense likely has more to gain from AI automation. While AI-powered attacks make for dramatic headlines, a level-headed examination shows core offense challenges reflect the weaknesses of AI models whereas defense tasks speak to its strength.&#8221;</span></em> </p></li><li><p><a href="https://blog.cryptographyengineering.com/2026/08/14/everything-is-about-to-go-dark/">Everything is about to &#8220;go dark&#8221;</a> - <strong>Matthew Green</strong> worries - <em>&#8220;I&#8217;m concerned that AI is going to make software much too secure. While that doesn&#8217;t sound so bad on the surface, there&#8217;s a consequence to this. I mean something very specific: I&#8217;m concerned that U.S. intelligence and law enforcement agencies are about to go dark, meaning: that they&#8217;re going to suddenly lose a huge portion of their capability.&#8221;</em></p></li><li><p><a href="https://www.nist.gov/artificial-intelligence/ai-research/tevv-athlon-framework-evaluating-ai-systems">The TEVV-Athlon Framework for Evaluating AI Systems</a> - <strong>NIST</strong> calls for input - <em>&#8220;Input Sought on Initial Public Draft of <a href="https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.200-2.ipd.pdf">NIST AI 200-2</a> through October 6, 2026 &#8230; This paper introduces the TEVV-Athlon Framework, a four-stage method for developing customized assessments of AI systems based on organizational TEVV objectives. The framework produces a TEVV-Athlon, an assessment where AI systems are tested via a set of Events and Tools which produce data on Blocks related to measurement concepts of interest.&#8220;</em> </p></li><li><p><a href="https://openai.com/index/pacing-model-development-cyber-capabilities/">Pacing model development in an era of cyber-critical capabilities</a> - <strong>OpenAI</strong> assert - <em>&#8220;<span>We expect models to soon drive most security work, including defending against other models. This will allow all three safeguards to scale with model capability, which we see as crucial.&#8221;</span></em> </p></li><li><p><a href="https://ari.us/research/responsible-innovation-at-the-frontier/">Responsible Innovation at the Frontier</a> - <strong>Americans for Responsible Innovation</strong> publish - <em>&#8220;<span>ARI&#8217;s blueprint for federal AI governance is designed to promote safe frontier AI development in America. The blueprint is built around three governance functions any federal proposal should incorporate. To set adequate safety </span>standards<span>, the federal government should hold every covered developer&#8217;s published safety framework to minimum federal standards that define adequacy. To verify compliance with those standards, there should be independent </span>assurance<span>. To secure </span>transparency<span> into frontier AI development, there should be federal visibility into both internally deployed frontier models and the growing automation of AI research and development.&#8221;</span></em></p></li><li><p><a href="https://en.people.cn/n3/2026/0814/c90000-20488686.html">China advances global AI governance in a comprehensive manner</a> - <strong>People&#8217;s Daily</strong> reports - <em>&#8220;At the opening ceremony of the 2026 World AI Conference (WAIC) and High-Level Meeting on Global AI Governance, Chinese President Xi Jinping called for joint efforts to build a just and equitable system for global AI governance. The proposal reflects a profound understanding of technological and historical trends, embodies the wisdom of governing AI for the common good, and points toward the long-term goal of building a community with a shared future for humanity.&#8221;</em></p></li></ul></li><li><p><em>Cyber proliferation</em></p><ul><li><p><a href="https://techcrunch.com/2026/08/14/us-courts-will-start-publishing-how-often-the-government-uses-spyware/?ref=metacurity.com">US courts will start publishing how often the government uses spyware</a> - <strong>TechCrunch</strong> reports - <em>&#8220;Starting in 2029, U.S. judiciary will publicly disclose precisely how many times judges authorized the use of wiretaps to be carried out with hacking tools and spyware, which fall under the category of what the feds call network investigating techniques, or NITs.&#8221;</em></p></li></ul></li><li><p>Bounty Hunting</p><ul><li><p><a href="https://www.justice.gov/opa/pr/17-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic-revolutionary"><span>17 Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps and Other Iranian Entities</span></a><span> - US </span><strong><span>Department of Justice</span></strong><span> announces - </span><em><span>&#8220;A 14-count superseding (S2) indictment was unsealed today charging 17 members of the Mabna Institute, an Iran-based company that, since at least 2013, has conducted a coordinated campaign of cyber intrusions into computer systems for 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations (NGOs).&#8221;</span></em></p></li><li><p><a href="https://go.rewardsforjustice.net/mabna-en/">Reward Up To $10,000,000 USD For Information On Iranian Hackers</a> - <strong>Rewards for Justice</strong> bounties - <em>&#8220;These individuals are affiliated with Iran&#8217;s Ministry of Intelligence and Security and the Islamic Revolutionary Guard Corps, a designated Foreign Terrorist Organization. They have targeted numerous segments of U.S. critical infrastructure with malicious cyber activity.&#8221;</em></p></li><li><p><a href="https://commsrisk.com/malaysian-police-arrest-sms-blaster-driver-targeting-singapore-border-traffic/">Malaysian Police Arrest SMS Blaster Driver Targeting Singapore Border Traffic</a> - <strong>CommsRisk</strong> reports - <em>&#8220;Malaysian authorities arrested a 65-year-old man who allegedly used a car-mounted SMS blaster to target peak-hour commuters travelling between Johor Bahru and Singapore.&#8221;</em></p></li></ul></li><li><p>Market Incentives</p><ul><li><p><a href="https://www.cyberleagle.com/2026/08/if-computer-is-not-accountable-who-is.html">Cyberleagle: If the computer is not accountable, who is?</a> - <strong>Graham Smith</strong> asks - <em>&#8220;<span>If the computerised bill system had been AI-driven, one wonders how impressed the </span>Ferguson<span> court would have been with distinctions between determinate and indeterminate computer outputs. That speculation aside, when considering corporate tortious liability for AI errors it seems likely that at some point the </span>Meridian<span> framework will come into play&#8221;</span></em></p></li><li><p><a href="https://media.frc.org.uk/documents/UK_Corporate_Governance_Code_2024_a2hmQmY.pdf">UK Corporate Governance Code 2024</a> - <strong>Financial Reporting Council</strong> published but are now coming into effect- <em>&#8220;As a result, the Code will provide a stronger basis for companies to evidence the effectiveness of their internal controls, thereby enhancing transparency and investor confidence. In order to give companies sufficient time to implement these new arrangements, reporting on this element of the Code (Provision 29) will not be effective before accounting periods beginning on or after 1 January 2026&#8221;</em></p></li><li><p><a href="https://www.etsi.org/newsroom/press-releases/etsi-launches-approval-process-for-17-european-standards-supporting-the-cyber-resilience-act/">ETSI launches approval process for 17 European Standards supporting the Cyber Resilience Act</a> - <strong>ETSI</strong> launches - <em>&#8220;<span>ETSI is pleased to announce the availability of the </span><a href="https://docbox.etsi.org/CYBER/EUSR/Open">17 vertical final draft standards</a><span> developed in the framework of the EU Cyber Resilience Act (CRA) and currently under Public Enquiry. These standards aim to become Harmonised Standards, giving manufacturers a recognised way to demonstrate compliance with the legislation, the so-called &#8220;presumption of conformity&#8221;.</span></em></p></li><li><p><a href="https://aiuc.com/product">Artificial Intelligence Underwriting Company</a> emerges - <strong>comment:</strong> it will be interesting to see the world in the insurance - video here from AIUC on <a href="https://www.youtube.com/watch?v=HKFitKwyUuI">Making Safe AI Profitable: Standards, Audits, and Insurance</a> a paper was written on <a href="https://underwriting-superintelligence.com/">Underwriting Superintelligence</a> by the co-founders</p></li></ul></li></ul><p>No reflections this week.</p><p>Not getting this via email? Subscribe:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Think someone else would benefit? Share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-13a?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-13a?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p><strong>All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.</strong></p><p>Have a lovely Saturday&#8230;</p><p>Ollie</p><h1>Cyber threat intelligence</h1><p>Who is doing what to whom and how allegedly.</p><h2>Reporting on Russia</h2><h3>Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia</h3><p><strong>Gabby Roncone</strong> and <strong>Wesley Shields</strong> details an alleged Russian operation which is of note due to its scale and techniques which may fall outside of enterprise detection and discovery.</p><blockquote><p>These clusters engage in persistent, adaptive phishing campaigns, using sophisticated social engineering tactics to compromise personal accounts across multiple platforms. Because these operations abuse legitimate authentication flows which may not immediately seem like phishing attempts to users, GTIG is raising awareness about these social engineering campaigns targeting individuals so that targets can more readily recognize malicious outreach.</p><p>&#8230;</p><p>UNC7005 also conducts device code phishing operations for both Microsoft and WhatsApp accounts. The themes of these phishing waves often involve invitations for calls with individuals from notable organizations related to the target&#8217;s field or, most recently, invitations to diplomatic events and conferences.</p></blockquote><p><a href="https://cloud.google.com/blog/topics/threat-intelligence/distinct-clusters-target-individuals-of-interest-to-russia">https://cloud.google.com/blog/topics/threat-intelligence/distinct-clusters-target-individuals-of-interest-to-russia</a></p><h2>Reporting on China</h2><h3>APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit</h3><p><strong>Fareed Radzi</strong> details that this alleged set of Chinese operations are now using a signed kernel driver which history implies the certificate may of been in use for a while. Noteworthy as as kernel code signing is still obtainable by adversaries it would appear.</p><blockquote><p>CoolClient is a backdoor family attributed to the HoneyMyte APT group (also known as Mustang Panda) that has been used in their cyber-espionage campaigns targeting organizations across Asia and Russia. It supports such capabilities as keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and plugin-based extensions.</p><p>..</p><p>In late 2025 and 2026, our latest investigation reveal another major evolution. The newest CoolClient variant can deploy a signed kernel-mode driver as a Windows service and communicate with it through IOCTL requests. The driver enhances the malware&#8217;s stealth by hiding the CoolClient process, protecting related files and registry entries, and preventing them from being inspected or modified. The overall design is comparable to the kernel-mode enhancements previously observed in ToneShell, but the CoolClient driver exposes dedicated IOCTL handlers that allow the user-mode backdoor to communicate directly with the driver.</p><p>We have observed this updated CoolClient variant and its accompanying driver in intrusions across multiple countries in Asia, including Pakistan, Mongolia, and Myanmar.</p><p>&#8230;</p><p><span>The path contains several notable strings, including &#8220;Nanjing Laboratory&#8221; (</span><code>&#21335;&#20140;&#23454;&#39564;&#23460;</code><span>) and &#8220;Zhang Xuejie Yunnan m&#8221; (</span><code>&#24352;&#38634;&#26480;&#20113;&#21335;m</code><span>), which likely refer to the driver&#8217;s development environment. However, our OSINT analysis did not identify any information linking these strings to a known organization, developer, or threat actor.</span></p><p>The driver is digitally signed with a certificate issued to <code>"Nanjing Ranyi Technology Co., Ltd."</code>, with serial number <code>3E 62 DC 5D 8D 61 2A 26 33 E7 6B DF D6 07 19 DD</code>. The certificate was valid from August 2013 to September 2014.</p><p>We identified several older malicious drivers signed with the same certificate that were compiled around 2013. However, we found no evidence directly linking those samples to the CoolClient activity described in this article.</p></blockquote><p><a href="https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/">https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/</a></p><h3>SilkParasite: Tracking a China-Nexus APT Across Central Asia</h3><p><strong>Martin Zugec</strong> details a suite of alleged Chinese capability which has hints that AI was used in its development (not a surprise). Initial access tradecraft is extremely well understood and easily mitigatable. </p><blockquote><p>SilkParasite is a cyberespionage operation, assessed at medium confidence as China-nexus, that targeted government bodies across Central Asia. Bitdefender Labs found seven remote access tool (RAT) families in use, five of which were previously undocumented; we identified and named them: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered, and it carries traces of AI-assisted development.</p><p>..</p><p>Initial access ran through malicious Microsoft Office documents, most likely delivered by spear-phishing email. In several cases the lure documents were packaged inside password-protected RAR archives, with the password supplied in the email body, a low-effort but effective way to slip past email-gateway scanning and automated sandbox inspection. Once opened, the document ran a macro that dropped a signed-application sideloading chain to disk and launched the first-stage payload.</p></blockquote><p><a href="https://www.bitdefender.com/en-us/blog/businessinsights/silkparasite-tracking-china-nexus-apt-across-central-asia">https://www.bitdefender.com/en-us/blog/businessinsights/silkparasite-tracking-china-nexus-apt-across-central-asia</a></p><h3>UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations</h3><p><strong>Joey Chen</strong> details an allegedly Chinese threat actor who has integrated AI to increase scale. Not sure the expertise point in the below is empirically proven quite yet given this campaign used publicly disclosed vulnerabilities, we do not know who the actor is and we have had ./ exploit for time and memorial&#8230; they also describe this actor as highly capable in the following blog.</p><blockquote><ul><li><p>[We] identified UAT-10147 targeting Windows and Linux web servers globally, impacting organizations in government, education, media, technology, and gaming sectors. The actor leveraged publicly disclosed vulnerabilities to gain initial access at scale.</p></li><li><p>UAT-10147 integrated AI-driven tooling into exploitation, reconnaissance, payload generation, validation, and persistence workflows. Talos observed AI-generated operational playbooks, exploit automation scripts, and troubleshooting logic supporting real-world intrusions.</p></li><li><p>The actor employed a mixture of open-source offensive frameworks, including Metasploit, ysoserial, PentestGPT, DeepAudit, and multiple privilege escalation exploits to automate intrusion operations and establish persistence.</p></li><li><p>Talos assesses that integrating AI-generated exploitation guidance, automation, and validation workflows enables threat actors to scale complex attacks more efficiently while reducing the expertise traditionally required for advanced post-compromise operations.</p></li></ul></blockquote><p><a href="https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/">https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/</a></p><h3>UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities</h3><p><strong>Joey Chen</strong> further details this alleged Chinese threat actors capability which implies criminality may be the intent. Noteworthy as it is a new implant and it does have some evasion capabilities </p><blockquote><ul><li><p>UAT-10147 is a highly capable Chinese-speaking intrusion actor operating a multi-platform post-exploitation ecosystem targeting IIS and Linux servers, combining search engine optimization (SEO) fraud monetization with advanced persistence and defense evasion techniques.</p></li><li><p>The newly identified SPECTRE implant represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.</p></li><li><p>The actor demonstrates operational maturity through the combined use of custom malware, open-source offensive tooling, Bring Your Own Virtual Driver (BYOVD) based EDR neutralization, Linux kernel rootkits, and sophisticated in-memory web shell deployment techniques.</p></li><li><p>Cisco Talos&#8217; analysis of recovered source code suggests portions of the Linux rootkit development may have incorporated AI-assisted code generation workflows, highlighting the growing role of generative AI in accelerating offensive malware development.</p></li></ul></blockquote><p><a href="https://blog.talosintelligence.com/uat-10147-deploys-spectre-a-cross-platform-implant-with-linux-rootkit-and-byovd-capabilities/">https://blog.talosintelligence.com/uat-10147-deploys-spectre-a-cross-platform-implant-with-linux-rootkit-and-byovd-capabilities/</a></p><h3>Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor</h3><p><strong>Priya Patel</strong> details an alleged Chinese operation which uses tradecraft we have known about what feels like over five years. All well understood, all mitigatable. Noteworthy due to victimology and the fact it might be effective in achieving access.</p><blockquote><p><span>We have been tracking this threat actor over the past few months and identified three related campaigns targeting Myanmar. The earliest campaign, observed in April 2026, used a sample named HolidayNotice.pdf.exe. The lure used in this variant was a fabricated Belgian&#8211;Myanmar public holiday calendar, which suggests that the threat actor was targeting personnel from Belgian organizations operating in Myanmar, such as embassies or NGOs.</span></p><p><span>We also identified two VHD samples that appeared within a short period of time. The first sample, TrainingAnnouncement.jpg, was first observed on June 2026. The second sample, ACMECS_Pillar_1.vhd, was first observed in July 2026. Although the two samples use different lure documents, they share the same infection chain, payload, and C2 infrastructure.</span></p></blockquote><p><a href="https://www.seqrite.com/blog/operation-quicsilver-china-nexus-actor-targets-myanmar-diplomats-via-vhd-delivered-go-backdoor/">https://www.seqrite.com/blog/operation-quicsilver-china-nexus-actor-targets-myanmar-diplomats-via-vhd-delivered-go-backdoor/</a></p><h3>Trapping a Mustang Panda</h3><p><strong>Agnes Ramos-Beauchamp</strong><span> , </span><strong>Joshua Chung</strong><span> , </span><strong>Golo M&#252;hr</strong><span> and </span><a href="https://www.ibm.com/think/author/joe-fasulo.html">Joe Fasulo</a> detail an alleged Chinese operation which is of note due to sector (energy) and if you look past the product marketing the use of cyber deception effectively for intelligence gain.</p><blockquote><ul><li><p>X-Force is tracking ongoing campaigns attributed to ITG27 (formerly <a href="https://www.ibm.com/think/x-force/hive0154-drops-updated-toneshell-backdoor">Hive0154</a>), a China-aligned actor conducting cyber espionage.</p></li><li><p>The actors are likely exploiting ongoing geopolitical events in South Asia, using emails to spread new versions of the Toneshell backdoor.</p></li><li><p>Using Deception.Pro, X-Force observed two real ITG27 incidents in realistic, simulated victim organizations&#8217; environments. ITG27 operators maintained access over multiple days and performed hands-on-keyboard activity including reconnaissance, credential harvesting and malware deployment.</p></li><li><p>The actors deployed a previously unknown VNC-capable backdoor tracked as Havencode to manually browse the victim&#8217;s desktop, and exfiltrated fake documents placed in the deception environments.</p></li><li><p>X-Force analysis shows that operator-initiated actions took place exclusively during weekday working hours (08:00-18:00) in China Standard Time.</p></li></ul></blockquote><p><a href="https://www.ibm.com/think/x-force/trapping-a-mustang-panda">https://www.ibm.com/think/x-force/trapping-a-mustang-panda</a></p><h2>Reporting on North Korea</h2><h3>PurpleDelta&#8217;s Fraudulent Employment Operations</h3><p><strong>Insikt Group&#174;</strong> detail an alleged North Korean operation which continues to gain effective employment. The complex supply chain around these operations is of note.</p><blockquote><ul><li><p>Insikt Group has identified at least 22 fabricated personas linked to multiple PurpleDelta clusters that submitted applications to over 1,100 companies across the software, staffing, healthcare, and financial sectors, with operators submitting as many as 60 or more applications per day across at least 8 job platforms.</p></li><li><p>These clusters of PurpleDelta operators are highly likely to have been actively employed at ten or more organizations, with confirmed or probable placements at companies that pose an ongoing and material insider threat.</p></li><li><p>PurpleDelta demonstrated a high degree of operational sophistication, using multi-account management browsers, multiple Chrome profiles, AI-generated profile photos, custom ChatGPT assistants, and real-time AI transcription tools to deceive hiring managers during interviews, sometimes repeating AI-generated responses verbatim.</p></li><li><p>Once employed, PurpleDelta operators recorded internal meetings at victim organizations, used screen recording software during work sessions, and drafted pre-written Google Translate excuses to justify the use of personal devices and personal bank accounts.</p></li><li><p>Video evidence indicates that PurpleDelta operators use identity-brokering services, account-renting via AnyDesk, and multi-accounting tools, and coordinate via Telegram and Slack, with support from facilitators who procure and maintain company-issued hardware on the operators&#8217; behalf.</p></li></ul></blockquote><p><a href="https://www.recordedfuture.com/research/purpledelta-fraudulent-employment-operations">https://www.recordedfuture.com/research/purpledelta-fraudulent-employment-operations</a></p><h2>Reporting on Iran</h2><p><em>Nothing overly of note this week</em></p><h2>Reporting on Other Actors</h2><h3>Living Off the Cloud: A Python Implant Hiding Its Entire C2 Inside Microsoft 365 &amp; Azure</h3><p><strong>Rhys Downing</strong> details a cloud based implant and C2 which is noteworthy due to its operational usage here.</p><blockquote><p>TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services. Tasking flows through SharePoint Online file dead-drops via the Microsoft Graph API. Interactive operator access routes through WebRTC DataChannels relayed by Microsoft Teams TURN servers. Graph API traffic is driven through a headless instance of the victim&#8217;s own Edge browser, making it indistinguishable from legitimate user activity. The implant harvests Windows credentials via pixel-faithful fake lock screens, provides a reverse SOCKS5 pivot into victim networks, executes arbitrary commands, and persists through four mechanisms. One instance involved an offline&#8209;forged mandatory profile hive created without administrative privileges. This used a technique called &#8220;Corrupting the Hive Mind,&#8221; the first recorded malicious use of this persistence method in the wild.</p><p>We recovered the modules from under PyArmor 9.2.5 protection and decrypted the embedded configuration, giving us visibility into the operator infrastructure, including the SharePoint C2 site, the Azure Blob config dead-drop, and the attacker-registered domains.</p></blockquote><p><a href="https://www.ontinue.com/resource/python-implant-hiding-its-entire-c2-inside-microsoft-365-azure/">https://www.ontinue.com/resource/python-implant-hiding-its-entire-c2-inside-microsoft-365-azure/</a></p><h3>Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows</h3><p><strong>Infoblox Threat Intel</strong> detail the scale of this campaign over a series of posts - the level of financial investment is of note showing there must be a return of a greater amount.</p><blockquote><p>Dropcatch actors inherit traffic from compromised websites by acquiring expired malicious domains and redirecting victims to scams and malware.</p><p>&#8230;</p><p>Sable Squirrel spends millions&#8239;on expired domains to&#8239;deliver illegal gambling, streaming, RAT malware, and ransomware&#8239;in&#8239;a massive cybercriminal enterprise.</p></blockquote><p><a href="https://www.infoblox.com/blog/threat-intelligence/dropcatch-scavengers-expired-malicious-domains-become-cash-cows/">https://www.infoblox.com/blog/threat-intelligence/dropcatch-scavengers-expired-malicious-domains-become-cash-cows/</a></p><p><a href="https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/">https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/</a></p><p><a href="https://www.infoblox.com/blog/threat-intelligence/dropcatch-scavengers-expired-malicious-domains-become-cash-cows/">https://www.infoblox.com/blog/threat-intelligence/dropcatch-scavengers-expired-malicious-domains-become-cash-cows/</a></p><h3>Software Supply Chain Incursions</h3><p><span>A reminder we issued guidance a number of weeks ago in </span><a href="https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies">Software supply chain attacks: check your dependencies</a><span> for software developers</span></p><ul><li><p><a href="https://opensourcemalware.com/blog/windows-infostealer-stubmaker-npm-ruby">Windows Infostealer Hits npm and Ruby</a></p></li><li><p><a href="https://cloud.google.com/blog/topics/threat-intelligence/distinct-clusters-target-individuals-of-interest-to-russia">Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns</a></p></li></ul><h1>Discovery</h1><p>How we find and understand the latent compromises within our environments.</p><h2>Device Roles in Microsoft Defender XDR: Better Context for Threat Hunting and Detection Engineering</h2><p><strong>Mehmet Ergene</strong> details these new data source/colum in Microsoft Defender XDR which will facilitate for precise threat hunting.</p><blockquote><p><span>Microsoft has added a </span><em><strong>DeviceRoles</strong></em><span> column to the </span><strong>DeviceInfo</strong><span> table in Microsoft Defender XDR Advanced Hunting. I&#8217;ve been asking for this type of device context for a long time, so I was happy to see it finally appear.</span></p><p>For threat hunting and detection engineering, it solves a problem I regularly run into: understanding what a device actually does without leaving the hunting query. For example, I hate switching to CMDB and finding out the device is just a Terminal server.</p><p>DeviceRoles JSON-formatted string field, containing roles identified by the system or defined by users, confidence levels, and the last time each role was observed.</p><p>That gives us another useful source of context directly inside <strong>DeviceInfo</strong>.</p></blockquote><p><a href="https://academy.bluraven.io/blog/device-roles-in-microsoft-defender-xdr">https://academy.bluraven.io/blog/device-roles-in-microsoft-defender-xdr</a></p><h2>Google SecOps (Chronicle) Curated Detections: Flaw Analysis &amp; Tuning</h2><p><strong>All3xJ</strong> fixes a hyperscalers detections.</p><blockquote><p>This repository documents architectural design flaws, logic discrepancies, and tuning strategies for native Google SecOps (Chronicle) Curated Detections.</p><p>While Google Threat Intelligence (GTIG) provides exceptional conceptual threat coverage (such as tracking APT29/BRICKSTORM campaigns), raw YARA-L implementations of curated rules sometimes suffer from implementation oversights, such as grouping logic contradictions and hardcoded threshold variables. In real-world enterprise environments, this frequently leads to massive alert fatigue.</p><p>This project analyzes <em>why</em> native rules break or flood the SOC, and shares optimized Custom Rules and patches to resolve these issues.</p></blockquote><p><a href="https://github.com/All3xJ/fixing-google-secops-detections">https://github.com/All3xJ/fixing-google-secops-detections</a></p><h2>Hunting MacSync Stealer infrastructure through behavioral pivots</h2><p><strong>Microsoft Defender Experts<span> </span></strong><span>and</span><strong><span> </span>Microsoft Security Research </strong>detail they expanded the identification of associated infrastructure. </p><blockquote><p>Microsoft Defender Experts expanded that view by correlating recurring endpoints and network behaviors across the activity. This behavior-led approach connected more than 30 domains and showed that the infrastructure supported more than C2 communication, extending into active collection, staging, and exfiltration. The findings demonstrate that although domains may rotate quickly, repeated execution patterns, request characteristics, staging behavior, and upload methods provide defenders with more durable opportunities to investigate MacSync Stealer activity.</p></blockquote><p><a href="https://www.microsoft.com/en-us/security/blog/2026/08/18/hunting-macsync-stealer-infrastructure-through-behavioral-pivots/">https://www.microsoft.com/en-us/security/blog/2026/08/18/hunting-macsync-stealer-infrastructure-through-behavioral-pivots/</a></p><h2>Consensual Forensics with Android Intrusion Logging</h2><p><strong>Kevin Pagano</strong> details how to leverage these new logging sources to identify potential intrusions on Android. </p><blockquote><p><span>A few months back Android introduced their new intrusion logging capabilities as part of their advanced protection mode. Security Lab </span><a href="https://securitylab.amnesty.org/latest/2026/05/android-intrusion-logging-as-a-new-source-of-data-for-consensual-forensic-analysis/">has a great blog</a><span> on everything about them. It really breaks them down into three different categories from the samples I&#8217;ve seen:</span></p><ul><li><p><span>Security Events</span> - A lot of types, including ADB commands, packages installed/uninstalled, process starts and more</p></li><li><p><span>DNS Events</span> - Hostnames, IP addresses</p></li><li><p><span>Connection Events</span> - IP addresses, package names, ports</p></li></ul><p>It really allows you to then run IOCs on the logs to see if anything suspicious may be connecting to your mobile device or other connections or packages running that shouldn&#8217;t be. I don&#8217;t think there are many tools that support parsing these logs at this time but ALEAPP does now after a quick run through Python.</p></blockquote><p><a href="https://www.stark4n6.com/2026/08/consensual-forensics-with-android.html">https://www.stark4n6.com/2026/08/consensual-forensics-with-android.html</a></p><h2>IRFlow Timeline</h2><p><strong>Renzon Cruz</strong> adds support for <a href="https://learn.chatgpt.com/docs/customization/computer-history">ChatGPT Computer History</a> to the IR timeline flows..</p><blockquote><p>IRFlow Timeline 1.0.10 adds ChatGPT Computer History as a new forensic artifact family, and hardens the app for long-running investigations.</p></blockquote><p><a href="https://github.com/r3nzsec/irflow-timeline/releases/tag/v1.0.10">https://github.com/r3nzsec/irflow-timeline/releases/tag/v1.0.10</a></p><h2><span>13 million tool calls: auditing every AI coding agent action with Elastic Agent</span></h2><p><strong>Wieger van der Meulen</strong> shows how it is done at contemporary scale in the AI era across a modern AI use case. How many agents ran tooling which accessed a certificate (per the below) is a jolly good question to be asking.</p><blockquote><p><span>We gave hundreds of developers an AI agent that can run shell commands, edit files, and call </span><a href="https://modelcontextprotocol.io/">Model Context Protocol (MCP)</a><span> servers on their laptops, then realized we had no record of what it actually did. So we built one. One 280-line dependency-free bash script, fired by Cursor's hooks, records every tool call as JSONL, and the </span><a href="https://www.elastic.co/docs/reference/fleet">Elastic Agent</a><span> already on each endpoint ships it to Elasticsearch. Since the May rollout we have logged over 13 million tool-call events from more than 1,100 machines. A question like "which hosts ran an agent that read a .pem file last week?" is one </span><a href="https://www.elastic.co/docs/reference/query-languages/esql">ES|QL</a><span> query. The worked example here is Cursor end to end, but the pattern works with any agent that offers lifecycle hooks.</span></p></blockquote><p><a href="https://www.elastic.co/security-labs/ai-coding-agent-audit-cursor-hooks">https://www.elastic.co/security-labs/ai-coding-agent-audit-cursor-hooks</a></p><h2>From Noise to Signal: Improving Security Log Anomaly Detection Using LLMs with Endpoint-Specific Logs</h2><p><strong>Christopher Henshaw</strong> and <strong>Gour Karmakar</strong> provides some measurement of efficacy but show that there is likely real-world value to be had.</p><blockquote><p>k. Meta Llama 3.1 8B Instruct achieved the strongest overall end-to-end detection performance, with an accuracy of 89.3%, recall of 88.2%, F1-score of 91.8%, and false negative rate of 11.8%. In comparison, Wazuh achieved an accuracy of 52.0% and false negative rate of 68.6%, while OpenSearch achieved an accuracy of 49.3% and false negative rate of 74.5%. Meta Llama also detected 80% of the borderline anomalous scenarios, compared with 20% for Wazuh and 15% for OpenSearch. Qwen achieved lower overall detection performance than Meta Llama but recorded the lowest average inference latency and 100% structured-response validity. GPT-OSS demonstrated strong classification performance when valid responses were produced.</p></blockquote><p><a href="https://arxiv.org/abs/2608.19938">https://arxiv.org/abs/2608.19938</a></p><h2>From Threat Intelligence to Detection: Knowledge-driven Enrichment and Template-based Rule Grounding for Automated Sigma Rule Generation</h2><p><strong>Sepehr Ghaffarzadegan</strong><span>, </span><strong>Boubakr Nour</strong><span>, </span><strong>Makan Pourzandi</strong><span>, </span><strong>Mourad Debbabi</strong><span> and </span><strong>Chadi Assi</strong> show that LLMs are in of themselves likely not the sole answer for some use cases - real world value on show here.</p><blockquote><p>Rather than relying solely on language models, AUTOSIGMA leverages a structured knowledge base to enrich partial inputs, matches the enriched content against a repository of existing Sigma rules, and then employs an LLM-as-a-Judge mechanism to iteratively validate the rules. By combining knowledge-driven enrichment, template-based rule grounding, and a multi-stage solution, AUTOSIGMA enables accurate, context-aware, and relevant rule generation. Evaluations across multiple real-world APT reports and multiple security blogs demonstrate that AUTOSIGMA outperforms alternative solutions and LLM models in rule validity, rule relevancy, MITRE ATT&amp;CK technique coverage, and robustness to input quality.</p></blockquote><p><a href="https://arxiv.org/abs/2608.19011">https://arxiv.org/abs/2608.19011</a></p><h1>Defence</h1><p>How we proactively defend our environments.</p><h2>Joint guidance on isolating vital system</h2><p><strong>Canadian Centre for Cyber Security</strong> and friends published this at the end of July</p><blockquote><p>The Canadian Centre for Cyber Security (Cyber Centre) has joined the Australian Signals Directorate&#8217;s Australian Cyber Security Centre (ASD&#8217;s ACSC) and the following international partners in releasing cyber security guidance on isolating vital operational technology (OT) systems:</p><ul><li><p>New Zealand&#8217;s National Cyber Security Centre (NCSC-NZ)</p></li><li><p>United Kingdom&#8217;s National Cyber Security Centre (NCSC-UK)</p></li><li><p>United States&#8217; Cybersecurity and Infrastructure Security Agency (CISA)</p></li><li><p>United States&#8217; Federal Bureau of Investigation (FBI)</p></li></ul><p>State-sponsored cyber actors are targeting critical infrastructure (CI) to conduct espionage and pre-position for cyber attacks. CI organizations can strengthen resilience against escalating cyber threats by preparing to isolate vital OT and enabling systems from the Internet and other networks for an extended period. This can help ensure essential services continue even if corporate networks are compromised.</p><p>This joint guidance promotes a shift from reactive defence to proactive resilience, using physical isolation to limit threat actors&#8217; access and maintain operational continuity during crises.</p></blockquote><p><a href="https://www.cyber.gc.ca/en/news-events/joint-guidance-isolating-vital-systems">https://www.cyber.gc.ca/en/news-events/joint-guidance-isolating-vital-systems</a></p><h2>Defending Against DPRK IT Workers &#8211; An Implementation and Operational Guide</h2><p><strong>Bridewell</strong> provide a playbook for defence..</p><p><a href="https://insights.bridewell.com/hubfs/Reports/Defending%20Against%20DPRK%20IT%20Workers%20-%20An%20Implementation%20and%20Operational%20Guide.pdf">https://insights.bridewell.com/hubfs/Reports/Defending%20Against%20DPRK%20IT%20Workers%20-%20An%20Implementation%20and%20Operational%20Guide.pdf</a></p><h2>Privileged Identity &amp; Access in Microsoft Entra</h2><p><strong>Thomas Naunheim</strong> and <strong>Martin Sohn Christensen</strong> accelerate the defence of every Entra centric organisation with this release which continues to be updated / iterated. </p><blockquote><p>Docs, resources and samples to implement a secure privileged identity and access management in Microsoft Azure and Microsoft Entra.</p></blockquote><p><a href="https://github.com/Cloud-Architekt/AzurePrivilegedIAM">https://github.com/Cloud-Architekt/AzurePrivilegedIAM</a></p><h2>Honeyquest for LLMs: Rethinking Cyber Deception for AI Attackers</h2><p><strong>Kerri Prinos</strong><span>, </span><strong>Lilianne Brush</strong><span> and </span><strong>Cameron Denton </strong>provide some valuable insight from this research and highlight various gaps in contemporary tradecraft. Also worth nothing that human-machine teaming will need to be considered as these research streams continue.</p><blockquote><p>Our empirical evaluation reveals three key findings that establish LLMs as a distinct attacker class: (1) every model in our cohort falls for deceptive traps at a significantly higher rate than human attackers; (2) the defensive attention-diversion effect observed in humans is statistically absent in our LLM cohort; and (3) a critical recognition-action gap, where LLMs successfully articulate trap recognition in their reasoning but exploit the deceptive elements anyway 73.4% of the time; 48.5% of aware-on-deceptive responses correctly identify the trap and exploit it anyway, while 24.8% exploit after misidentifying the deceptive line.</p></blockquote><p><a href="https://arxiv.org/abs/2606.21037">https://arxiv.org/abs/2606.21037</a></p><h2>Benchmarking Automated Security Patch Backporting: How Far Are We?</h2><p><strong>Jincheng Yang</strong><span>, </span><strong>Yulong Fu</strong><span>, </span><strong>Chengwei Liu</strong><span>, </span><strong>Lyuye Zhang</strong><span>, </span><strong>Fangyuan Zhang</strong><span>, </span><strong>Bingyang Ren</strong><span>, </span><strong>Yang Liu</strong><span> and </span><strong>Hui Li</strong> show the lived reality of where we are and why the technical debt paydown will continue to not be entirely machine scalable for a while.</p><blockquote><p>Performance degrades sharply on structurally complex patches: the best commit-level success rate falls from 85.2% on Type-I patches to 24.0% on Type-IV. We identify four root-cause categories (missing target API awareness, cross-version semantic mismatch, non-local dependency propagation failure, and patch construction or localization failure) and derive concrete directions for next-generation tool design.</p></blockquote><p><a href="https://arxiv.org/abs/2608.17671">https://arxiv.org/abs/2608.17671</a></p><h2>Beyond the Hype: Evaluating LLM Integration and Practical Limitations in Security Operation Centers</h2><p><strong>Elnaz Rabieinejad</strong><span>, </span><strong>Ali Dehghantanha</strong><span>, </span><strong>Fattane Zarrinkalam</strong><span> and </span><strong>Sarina Dastgerdy</strong> undertake some valuable socio-technical research with this work showing human trust of AI is going to continue to add friction.</p><blockquote><p>Participants report perceived time savings for low-stakes tasks that are quickly verifiable (e.g., summarizing logs or drafting initial investigative leads), but they consistently frame LLM outputs as preliminary drafts and suggestions rather than decision-grade conclusions. Participants also describe limited trust in LLMs for high-stakes security decisions due to unreliable outputs and unclear model reasoning, and they report relying primarily on ad-hoc verification norms and continuous human oversight rather than standardized mitigation procedures.</p></blockquote><p><a href="https://arxiv.org/abs/2608.17154">https://arxiv.org/abs/2608.17154</a></p><h1>Incident Writeups &amp; Disclosures</h1><p>How they got in and what they did.</p><h2>I accidentally logged hundreds of thousands of phone calls to military bases</h2><p><strong>Lina</strong> once again shows it is always DNS&#8230;</p><blockquote><p>How an expired nameserver let me take over e164.arpa zones for multiple territories, and why I probably should have checked my logs sooner.</p><p>&#8230;</p><p><span>DNS hijacking is silly. I already took over different </span><code>.gov</code><span> and </span><code>.edu</code><span> domains in the past, but I just immediately reported that and moved on.</span></p><p><span>This one is a little different though, it's about how I took over phone-network infrastructure domains (</span><code>e164.arpa</code><span>) of entire territories, and accidentally logged hundreds of thousands of phone calls to military bases. But let's start at the beginning.</span></p></blockquote><p><a href="https://lina.sh/blog/hijacking-e164-arpa">https://lina.sh/blog/hijacking-e164-arpa</a></p><h1>Vulnerability</h1><p>Our attack surface.</p><h2>A revisit of remote Spectre attacks on Cloudflare Workers</h2><p><strong>Albert Pedersen, Haocheng Xiao, Sam Ainsworth, Nigel Topham,</strong> and <strong>Martin Schwarzl</strong> show Spectre is not entirely theoretical in terms of real-world implications and impact in contemporary architectures. Side channels in cloud are a real-thing and thus limit some of the use cases depending on threat model.</p><blockquote><p>To mount a successful side-channel attack in production, an external attacker has to overcome additional obstacles such as activity on shared hardware resources, interrupts, context switches, and coarse-grained timers. Our research uncovered a limitation in the implementation of DyPrIs and we managed to demonstrate a remote Spectre attack reliably leaking up to 12 bit/s with a 99% accuracy in the production environment of Cloudflare Workers.</p></blockquote><p><a href="https://blog.cloudflare.com/revisiting-spectre-attacks-on-workers/">https://blog.cloudflare.com/revisiting-spectre-attacks-on-workers/</a></p><h2>Kanzashi</h2><p><strong>Andrea Barisani</strong> brings foundations to low-level AI enabled research</p><blockquote><p>This repository experiments with bare metal Go, as supported by <a href="https://github.com/usbarmory/tamago">TamaGo</a>, to perform LLM-driven security vulnerability analysis on low-level architectural layers minimizing OS interference.</p><p>The TamaGo framework allows trivial integration of LLM libraries on bare metal to achieve the following:</p><ul><li><p>dramatically reduced driver footprint, no OS presence</p></li><li><p>ability to import and run pure Go libraries</p></li><li><p>ability to bridge register/MSR read/write tooling with an LLM agent</p></li></ul></blockquote><p><a href="https://github.com/abarisani/kanzashi">https://github.com/abarisani/kanzashi</a></p><h2>ZhiShi &#8212; Security Research Harness</h2><p>From China - finding real vulnerabilities with AI - including for awareness. </p><blockquote><p>On the way</p><ul><li><p>Seven vulnerabilities are in Microsoft&#8217;s review process</p></li><li><p>White-box audits uncovered over 200 vulnerabilities, some of which are currently being reported as CVEs.</p></li></ul><p>Browser vulnerabilities</p><ul><li><p>Analysis and reproduction of multiple Chrome/Firefox vulnerabilities</p></li></ul></blockquote><p><a href="https://github.com/LielingAi/ZhiShi">https://github.com/LielingAi/ZhiShi</a></p><h2>OpenVuln</h2><p><strong>Yuxuan Zhang</strong> and <strong>Clouditera</strong> offer this service from China..</p><blockquote><p>Submit a public repository and OpenVuln hunts its vulnerabilities. Protect your open-source repository, together with GLM.</p></blockquote><p><a href="https://huggingface.co/spaces/zai-org/OpenVuln">https://huggingface.co/spaces/zai-org/OpenVuln</a></p><h2>smiiiiiiiiiiiiiiii</h2><p><strong>Chris Domas</strong> exploits showing what happened when you&#8217;ve worked for a CPU manufacturer for a very long time you know where likely architectural bodies are buried.</p><blockquote><p>Exploiting System Management Mode with a very very very very very very very long interrupt.</p></blockquote><p><a href="https://github.com/xoreaxeaxeax/smiiiiiiiiiiiiiiii">https://github.com/xoreaxeaxeax/smiiiiiiiiiiiiiiii</a></p><h2>LoongLeak</h2><p><strong>Lorenz Hetterich, Tristan Hornetz, Fabian Thomas</strong> and <strong>Michael Schwarz</strong> side channel on RISC-V.</p><blockquote><p>LoongLeak is a vulnerability affecting the Loongson 3A5000 and 3A6000 CPUs. LoongLeak allows unprivileged attackers to leak data from the L1 data cache, including data from other processes or the operating system.</p><p>..</p><p>Loongson is a CPU manufacturer that produces high-performance CPUs primarily targeting the Chinese domestic market, including government and administrative sectors. These CPUs use a custom instruction set called LoongArch&#8482;. The latest high-performance Loongson CPUs use the 64-bit variant of LoongArch named LA64.</p></blockquote><p><a href="https://loongleakattack.com/">https://loongleakattack.com/</a></p><h1>Offense</h1><p>Attack capability, techniques and trade-craft. </p><h2>BOFScale: A CDN-Fronted Tailnet from a BOF-PE</h2><p><strong>Ceri Coburn</strong> delivers an in memory capability which detection engineering teams will want to be across.</p><blockquote><p>Running Tailscale as a network layer for C2 traffic is not a new idea. What makes this implementation different is that the entire Tailscale daemon runs inside the implant process with no driver, no service, no disk state, and no child processes. Traffic relays over standard WebSockets that are indistinguishable at the edge from a browser opening a WebSocket connection, which means both the DERP relay servers and the control plane can sit behind CloudFront or Fastly without any special handling.</p><p>This post covers three tools that work together to make this possible. The first is <code>tailscaled</code>, a modified Tailscale daemon compiled as a BOF-PE that runs as an async background job inside the implant. The second is <code>tailscale</code>, a lightweight C++ BOF-PE that acts as the operator-facing client, letting you bring the node up, check its status, advertise routes, and shut it down. The third is <code>socksportfwd</code>, which bridges the gap that exists in userspace networking mode by forwarding local ports through the SOCKS5 server that tailscaled exposes, routing traffic to any node on the tailnet.</p></blockquote><p><a href="https://www.netspi.com/blog/technical-blog/red-teaming/bofscale-a-cdn-fronted-tailnet-from-a-bof-pe/">https://www.netspi.com/blog/technical-blog/red-teaming/bofscale-a-cdn-fronted-tailnet-from-a-bof-pe/</a></p><h2>BTR Reforged: Weaponizing Defender&#8217;s Remediation Driver as a Kernel Operation Primitive</h2><p><strong>Ji&#345;&#237; Vinopal</strong> highlights a capability we should expect Microsoft to address - even if they have indicated it won&#8217;t be in the short term. Detection engineering teams will want to be across this in the short term.</p><blockquote><p><span>Furthermore, we demonstrate how </span><code>BTR_CLI</code><span> can be used as an </span><strong>EDR/AV</strong><span> bypass technique, disarming security solutions while using a </span><strong>trusted Windows built-in</strong><span>, </span><strong>Microsoft-signed</strong><span> driver, thus </span><strong>not relying</strong><span> on typical </span><strong>BYOVD</strong><span> techniques.</span></p></blockquote><p><a href="https://research.checkpoint.com/2026/btr-reforged-weaponizing-defenders-remediation-driver-as-a-kernel-operation-primitive/">https://research.checkpoint.com/2026/btr-reforged-weaponizing-defenders-remediation-driver-as-a-kernel-operation-primitive/</a></p><h2>Vipere</h2><p><strong>P'tit Snake</strong> delivers a capability which detectio engineers will want to ensure coverage of in their developer environments. </p><blockquote><p>BOF exploiting the Visual Studio Installer Elevation Service for SYSTEM LPE and persistence via AppDomainManager hijacking, with native ETW evasion. For Cobalt Strike &amp; Adaptix.</p></blockquote><p><a href="https://github.com/0xaled/Vipere">https://github.com/0xaled/Vipere</a></p><h2>BusyWork</h2><p><strong>PatchRequest</strong> delivers a capability which it will be interesting to see what the data science deities make of it in terms of efficacy. Statistics hooooo.</p><blockquote><p>A Rust library that replaces <code>sleep()</code> with real, varied work to <strong>evade behavioral pattern matching</strong> by EDR, anti-cheat, and dynamic analysis systems.</p><p>Every call executes a <strong>completely different code path</strong> &#8212; random category, random task, random iteration counts. No two calls produce the same syscall sequence, instruction trace, or API call pattern</p></blockquote><p><a href="https://github.com/PatchRequest/BusyWork">https://github.com/PatchRequest/BusyWork</a></p><h2>MS-Nightmare Un-defend v2 &#8212; What Happens When Signatures Can&#8217;t Land</h2><p><strong>MS-Nightmare</strong> shows how to block EDR updates and thus ensuring tradecraft to detect these techniques is the imperative. </p><blockquote><p>Every antivirus and EDR product <em>depends</em> on freshness. It is only as effective as its most recent signature update. Vendors invest heavily in protecting that pipeline &#8212; the update service, its driver, its file layout, and its networking &#8212; because once the pipeline stops, the sensor quietly goes stale while still appearing healthy.</p><p>We asked a simple question: can a user-mode process halt the update pipeline of a major AV or EDR product without kernel code, without changing services, and without special administrative tricks beyond a normal run?</p><p>The short answer is **yes**. The method uses Windows file-handle semantics, a byte-range lock, and one watch thread per directory. This document explains how the update machinery works, where its weak points are, and why the technique succeeds. It is published so defenders can understand the failure mode, test it, and mitigate it.</p></blockquote><p><a href="https://weedhashpeddler.medium.com/every-antivirus-and-edr-product-depends-on-freshness-28b0fa9c810d">https://weedhashpeddler.medium.com/every-antivirus-and-edr-product-depends-on-freshness-28b0fa9c810d</a></p><h2>Turning Chrome Remote Desktop into Pure Red Team Ops</h2><p><strong>Smukx</strong> details how it is done - detection tradecraft is the name of the game..</p><blockquote><p>This post, we are going to explore how we can take a popular Google product, Chrome Remote Desktop (CRD), and look at it from a red team perspective, turning its existing features into red team tool, almost like a spyware-kinda scenario.</p></blockquote><p><a href="https://zerotracelab.com/blog/chrome-remote-desktop-red-ops">https://zerotracelab.com/blog/chrome-remote-desktop-red-ops</a></p><h2>Bring Your Own EDR: How to Turn a Commercial EDR into a Trojan Horse</h2><p><strong>Shahak Morag</strong> leverages security products to provide surrogate homes for malicious capability. Detection again is the name of the [WHAT]? </p><blockquote><ul><li><p><span>Legitimate SentinelOne installers and accessible COM interfaces can be abused to bypass Protected Process Light (PPL) protections and execute unsigned code &#8212; completely bypassing the need for kernel vulnerabilities or traditional exploits.</span></p></li><li><p><span>Management communications rely on user-configurable mechanisms like local DNS lookups, which allow an administrator to easily isolate the agent and block remote telemetry.</span></p></li><li><p><span>Built-in self-defense mechanisms can be inverted against the host system, rendering files inaccessible and processes untouchable.</span></p></li><li><p><span>Trusted endpoint detection and response (EDR) software can become a high-impact Trojan horse when local privilege escalation vectors and local trust assumptions are not properly hardened.</span></p></li></ul></blockquote><p><a href="https://www.akamai.com/blog/security-research/bring-your-own-edr-turn-commercial-edr-trojan-horse">https://www.akamai.com/blog/security-research/bring-your-own-edr-turn-commercial-edr-trojan-horse</a></p><h2>Chaining Trusted Windows Components into a Process-Tampering Primitive</h2><p><strong>Angelo Frasca Caccia</strong> shows how to degrade detection capabilities with this release..</p><blockquote><p>SgrmFault is a Windows process-tampering exploit chain that combines a revived COM-based code-injection technique in WerFaultSecure.exe with an APC-based process-tampering primitive exposed by Microsoft&#8217;s SgrmAgent.sys driver.</p></blockquote><p><a href="https://github.com/lem0nSec/SgrmFault">https://github.com/lem0nSec/SgrmFault</a></p><h1>Exploitation</h1><p>What is being exploited..</p><h2>Operation CameraSwarm:  Over 14,000 Dahua cameras compromised across Ukraine and Russia</h2><p><strong>Hunt.io</strong> detail global exploitation of these CCTV camera which is noteworthy for the type of device and scale..</p><blockquote><p>Between 17 June and 22 July 2026, a single operator compromised over 14,000 Dahua IP cameras. The scanning behind it was global: masscan sweeps ran against Russian address space first, then across the full IPv4 range, and the largest single haul actually landed in Mexican and Vietnamese ISP ranges before the operator's focus settled on Russian and CIS telecom netblocks. Where the confirmed, geolocated compromises concentrated was Ukraine and Russia, with Ukraine holding the largest share.</p></blockquote><p><a href="https://hunt.io/blog/operation-cameraswarm-dahua-cameras-compromised">https://hunt.io/blog/operation-cameraswarm-dahua-cameras-compromised</a></p><h2>Actively exploited vulnerability in Zimbra Collaboration Suite</h2><p><strong>The CERT Polska team</strong> informs about an actively exploited OS Command Injection vulnerability in Zimbra Collaboration Suite.</p><blockquote><p>The vulnerability, identified as <a href="https://www.cve.org/CVERecord?id=CVE-2026-73570">CVE-2026-73570</a> , allows an unauthenticated attacker to execute arbitrary shell commands with the privileges of <em>the zimbra</em> user . The vulnerability affects instances that have the SNMP trap service enabled via the <em>snmp_notify</em> parameter and the swatchdog service running (enabled by default).</p></blockquote><p><a href="https://moje.cert.pl/komunikaty/2026/145/aktywnie-wykorzystywana-podatnosc-w-zimbra-collaboration-suite/#">https://moje.cert.pl/komunikaty/2026/145/aktywnie-wykorzystywana-podatnosc-w-zimbra-collaboration-suite/#</a></p><h1>Tooling and Techniques</h1><p>Low level tooling and techniques for attack and defence researchers</p><h2>Windows Internals: Check Your Privilege - The Curious Case of ETW&#8217;s SecurityTrace Flag</h2><p><strong>Connor McGarr</strong> details this flag and its impact..</p><blockquote><p><span>Recently, while investigating new feature development for our </span><a href="https://www.preludesecurity.com/runtime-memory-protection">Origin (by Prelude) Runtime Memory Protection</a><span> research preview product, we were forced to dig into the inner-workings of Event Tracing for Windows (ETW). In the course of leveraging our internal ETW tooling, which executes at a signing and protection level of </span><a href="https://www.alex-ionescu.com/the-evolution-of-protected-processes-pass-the-hash-mitigations-in-windows-8-1/">Antimalware Protected Process Light (PPL)</a><span>, we noticed that it was possible to issue a &#8220;stop trace&#8221; code to a target ETW session that had an undocumented &#8220;security trace&#8221; flag enabled</span></p></blockquote><p><a href="https://connormcgarr.github.io/securitytrace-etw-ppl/">https://connormcgarr.github.io/securitytrace-etw-ppl/</a></p><h2>Windows Kernel Trace MOF</h2><p><strong>John U</strong> publishes a Trace Managed Object Format (MOF) File - a text file used by classic Event Tracing for Windows (ETW) and WMI providers.</p><blockquote><p>I updated my ETW classic provider MOF recovery to include EventTypeName and Description.<br><br>These were in an adjacent ms_409 (en-US) locale namespace.<br><br>The recovered Windows Kernel Trace MOF now looks like this</p></blockquote><p><a href="https://gist.github.com/jdu2600/a2b03e4e9cf19282a41ad766388c9856">gist.github.com/jdu2600/a2b03e4e9cf19282a41ad766388c9856</a></p><h2>CipherRun</h2><p><strong>Marc Rivero L&#243;pez</strong> developed this tooling which will have a variety of use cases.</p><blockquote><p><strong>CipherRun</strong> is a comprehensive TLS/SSL security scanner written in Rust. It combines protocol and cipher analysis, vulnerability testing, compliance checks, and certificate transparency monitoring in a single high-performance CLI and API-ready engine.</p></blockquote><p><a href="https://github.com/seifreed/CipherRun">https://github.com/seifreed/CipherRun</a></p><h2>windbg-bridge</h2><p><strong>Kevin Gosse</strong> releases this work aid.</p><blockquote><p>windbg-bridge connects a live WinDbg session to AI agents like Claude Code or Codex through a named pipe. The agent can run debugger commands, read your command history, and watch output in real time. Everything it does shows up in the WinDbg UI, so you always see exactly what's happening.</p></blockquote><p><a href="https://github.com/kevingosse/windbg-bridge">https://github.com/kevingosse/windbg-bridge</a></p><h2>Reverse engineering Malwarebytes Browser Guard</h2><p><strong>Milton Cardoso</strong><span> </span>reverse engineers and documents.</p><blockquote><p>Static analysis of Browser Guard 3.1.5 (15M+ installs): Zstd-encoded on-disk databases, the heuristic rule engine that scans the live DOM, the Hubble false-positive service, the package update protocol, and a debug URL interface left in production. With reimplementations in C# and Python.</p></blockquote><p><a href="https://msil.re/posts/reversing-malwarebytes-browser-guard.html">https://msil.re/posts/reversing-malwarebytes-browser-guard.html</a></p><h2>Reverse-engineering Find My People</h2><p><strong>Zerotistic</strong> unpicks and details.</p><blockquote><p>How I registered a Linux machine with Apple's private services, received an existing Find My People key over IDS, and decrypted the live location without a Mac.</p></blockquote><p><a href="https://zerotistic.blog/posts/find-my-people-linux/">https://zerotistic.blog/posts/find-my-people-linux/</a></p><h2>CUDA Agent: Large-Scale Agentic RL for High-Performance CUDA Kernel Generation</h2><p><strong>Weinan Dai</strong><span>, </span><strong>Hanlin Wu</strong><span>, </span><strong>Qiying Yu</strong><span>, </span><strong>Huan-ang Gao</strong><span>, </span><strong>Jiahao Li</strong><span>, </span><strong>Chengquan Jiang</strong><span>, </span><strong>Weiqiang Lou</strong><span>, </span><strong>Yufan Song</strong><span>, </span><strong>Hongli Yu</strong><span>, </span><strong>Jiaze Chen</strong><span>, </span><strong>Wei-Ying Ma</strong><span>, </span><strong>Ya-Qin Zhang</strong><span>, </span><strong>Jingjing Liu</strong><span>, </span><strong>Mingxuan Wang</strong><span>, </span><strong>Xin Liu</strong><span> and </span><strong>Hao Zhou</strong> publish.</p><blockquote><p><span>CUDA Agent achieves state-of-the-art results on KernelBench, delivering 100%, 100%, and 92% faster rate over </span>Torch.compile on KernelBench Level-1, Level-2, and Level-3 splits, outperforming the strongest proprietary models such as Claude Opus 4.5 and Gemini 3 Pro by about 40% on the hardest Level-3 setting.</p></blockquote><p><a href="https://arxiv.org/abs/2602.24286v1">https://arxiv.org/abs/2602.24286v1</a></p><h2>Technical Analysis of the Geedge Networks Firewall Source Code Leak</h2><p><strong>Anna Ablove , Johnnie Walker , Ben Wolin , Niklas Niere , Felix Lange , Aaron Ortwein , Armin Huremagic , Richa Priyanka , Ali Zohaib , Jade Sheffey , Nico Heitmann , J. Alex Halderman , Juraj Somorovsky , Amir Houmansadr , Roya Ensafi , Mingshi Wu</strong> and <strong>Eric Wustrow</strong> publish</p><blockquote><p>In September 2025, over 100K internal documents (including code, communications, etc.) from Geedge Networks, a Chinese DPI company with ties to the Great Firewall of China, were leaked to the public. In this paper, we analyze the source code from this leak, focusing on Geedge Networks&#8217; flagship product, the Tiangou Secure Gateway (TSG) firewall. Working across multiple repositories, we successfully build and run a local copy of TSG&#8212;revealing key aspects of its architecture, including the protocols it is capable of parsing and the format of blocking rules used to censor sites, proxies, and other resources. Finally, we extract several fingerprints from TSG, including custom random number generators and parsing idiosyncrasies that allow us to identify its use and similar deployments in the Great Firewall of China.</p></blockquote><p><a href="https://www.usenix.org/system/files/usenixsecurity26-ablove.pdf">https://www.usenix.org/system/files/usenixsecurity26-ablove.pdf</a></p><h1>Footnotes</h1><p>Some other small (and not so small) bits and bobs which might be of interest.</p><ul><li><p>Annual, quarterly and monthly reports</p><ul><li><p><em>Nothing overly of note this week, but keep an eye on</em> <a href="https://github.com/jacobdjwilson/awesome-annual-security-reports/tree/main/Annual%20Security%20Reports/2026">the Awesome Annual Security Reports 2026 collection</a> and <a href="https://github.com/blackorbird/APT_REPORT">APT report collection</a></p></li></ul></li><li><p><a href="https://kolja.rs/algorithm-d/">A long division story</a></p></li><li><p><a href="https://eprint.iacr.org/2026/1693">Quantum Algorithm Does Not Solve DCP</a></p></li><li><p>Artificial intelligence</p><ul><li><p><span>if you are a big </span><a href="https://arxiv.org/">arxiv.org</a><span> user - out of China there is </span><a href="https://www.alphaxiv.org/">alphaxiv.org</a><span> which is an AI powered incarnation / overlay</span></p></li><li><p>Fundamental</p><ul><li><p><a href="https://arxiv.org/abs/2608.11859v1">Small-Scale Experiments: Are We There Yet?</a> - <em>By ablating the basic scaling law recipe, we show well-tuned hyperparameters matter more than any other ingredient. Further, we reveal why those hyperparameters become easier to find: as scale increases, the hyperparameter loss surface becomes lower dimensional. Nevertheless while scaling laws exist in small models, extrapolation hits statistical limitations.</em></p></li><li><p><a href="https://github.com/InternLM/Intern-S2-Mobius/blob/main/Technical_Report_Intern_S2_Mobius.pdf">Intern-S2-Mobius: Foundation Model with Decoupled Knowledge and Reasoning</a></p></li><li><p><a href="https://arxiv.org/abs/2607.25895">HiFi-UMI: Learning Deployable Manipulation Policies from High-Fidelity UMI Data Alone</a></p></li><li><p><a href="https://arxiv.org/abs/2608.08888">Full-bandwidth transformer</a></p></li><li><p><a href="https://arxiv.org/abs/2608.09696">Model Discovery Agent: LLM-assisted Bayesian experiment design for data-efficient discovery of mechanistic world models</a></p></li><li><p><a href="https://arxiv.org/abs/2607.24744v1">Data Pyramid for Embodied Manipulation</a> - <em>&#8220;For embodied brain models, vision-language-action models, and world-action models alike, we relate data composition to capabilities in perception, reasoning, planning, action generation, and world prediction.&#8221;</em></p></li><li><p><a href="https://arxiv.org/abs/2608.20055">EchoCoT: Extracting Hidden Chain-of-Thought from Large Reasoning Models</a></p></li></ul></li><li><p>Applied non-cyber</p><ul><li><p><a href="https://arxiv.org/abs/2608.18369">The Fabricated Front: Generative AI and the Opacity of Workplace Performance</a></p></li><li><p><a href="https://arxiv.org/abs/2608.18360">One Gate Is Not Enough: Composing Stateful Pre-Action Controls for Agentic AI</a></p></li><li><p><a href="https://arxiv.org/abs/2608.11095v1">Why Does CLAUDE.md Keep Growing? Catastrophic Remembering in Agentic Coding</a></p></li><li><p><a href="https://github.com/deepseek-ai/deepseek-harness">DeepSeek Harness</a> - <em>DeepSeek Harness (</em><code>dsh</code><em>) is an open-source agent harness developed by DeepSeek AI. It uses an architecture where everything is a plugin, and is powered by Cordis,</em></p></li><li><p><a href="https://arxiv.org/abs/2602.24286v1">CUDA Agent: Large-Scale Agentic RL for High-Performance CUDA Kernel Generation</a></p></li><li><p><a href="https://chiptron.eu/reviving-old-unsupported-devices-with-ai-avermedia-game-capture-hd-ii/">Reviving Old Unsupported Devices with AI &#8211; AVerMedia Game Capture HD II</a></p></li><li><p><a href="https://www.nist.gov/artificial-intelligence/ai-research/tevv-athlon-framework-evaluating-ai-systems">The TEVV-Athlon Framework for Evaluating AI Systems</a></p></li><li><p><a href="https://arxiv.org/abs/2608.20167">BreakGuard: Towards Detecting Dependency Breaking Changes with LLM-Generated Tests</a></p></li><li><p><a href="https://arxiv.org/abs/2608.17360">Fair ASR: Re-Evaluating Black-Box Jailbreaks under Shared Target-Call Budgets</a></p></li><li><p><a href="https://arxiv.org/abs/2608.16032">Proof-of-Execution Memory: Defending LLM Agents Against Forged-Reasoning Attacks by Verifying What Actually Happened</a></p></li><li><p><a href="https://arxiv.org/abs/2608.16030">Benchmarking Identity-Sensitive LLM Outputs for Surveillance and Security Robots</a></p></li><li><p><a href="https://arxiv.org/abs/2608.15893">Breaking and Defending LLM-Powered Social Media Bot Detection Systems</a></p></li></ul></li><li><p>Applied cyber specific</p><ul><li><p><a href="https://arxiv.org/abs/2608.17960">COMA: A Compositional Misleading Attack Class on Security-RAG, and a Causal Counterfactual Defense</a></p></li><li><p><a href="https://arxiv.org/abs/2608.16187">Securing AI-Generated Code: A Just-in-Time Vulnerability Detection and Remediation Pipeline</a></p></li><li><p><a href="https://arxiv.org/abs/2608.19901">MaliciousSkillBench: A Comprehensive Benchmark for Malicious Agent Skill Detection</a></p></li><li><p><a href="https://arxiv.org/abs/2608.18686">Improving LLM-Based SSH Honeypots Through Prompting and Fine-Tuning</a></p></li><li><p><a href="https://arxiv.org/abs/2608.18613">CTIFoundry: An Agent-Native Corpus Scaffold for Cyber Threat Intelligence</a></p></li><li><p><a href="https://arxiv.org/abs/2608.17671">Benchmarking Automated Security Patch Backporting: How Far Are We?</a></p></li><li><p><a href="https://arxiv.org/abs/2608.19266">Incident-Data Robustness Analysis of the OWASP Top 10 for LLM Applications (2026): How a Community-Expert Ranking Holds Up Against a Large-Scale LLM Incident Corpus</a></p></li><li><p><a href="https://arxiv.org/abs/2608.16775">Topological Attribution Distance (TAD): Revealing Segment-Level RAG Influence on LLM Output Geometry for Incident Log Analysis</a></p></li><li><p><a href="https://huggingface.co/spaces/zai-org/OpenVuln">OpenVuln Open source audited by GLM</a></p></li><li><p><a href="https://arxiv.org/abs/2608.16393">Security Assessment of DeepSeek Harness with A.I.G: Evaluating Resistance to Indirect Prompt Injection</a></p></li><li><p><a href="https://shadown.github.io/blog/posts/2026-08-18_genai-security-guide/">GenAI Security &#8212; The Comprehensive Guide</a></p></li><li><p><a href="https://transluce.org/docent/blog/coding-agent-behaviors">Measuring coding agent misalignment in the wild</a></p></li><li><p><a href="https://arxiv.org/abs/2608.16970">Probing the Prefill: Detecting Code Vulnerabilities via Latent Activations</a></p></li><li><p><a href="https://arxiv.org/abs/2608.16508">LLMs for Zero-Shot Threat Detection via Structured Risk Indicators</a></p></li><li><p><a href="https://arxiv.org/abs/2608.15092">WeSCE: A Benchmark for Measuring Security Drift in LLM-Driven Code Editing</a></p></li></ul></li></ul></li><li><p>Books</p><ul><li><p><a href="https://www.hachettebookgroup.com/titles/sharon-weinberger/valley-of-death/9780316595933/">Valley of Death</a> - out in September</p></li></ul></li><li><p>Events</p><ul><li><p><a href="https://www.usenix.org/conference/woot26/technical-sessions">WOOT &#8216;26 Technical Sessions</a></p></li><li><p><a href="https://link.springer.com/book/10.1007/978-3-032-19540-1">Critical Information Infrastructures Security papers</a> - <em>&#8220;20th International Conference, CRITIS 2025, J&#246;nk&#246;ping, Sweden, October 21&#8211;23, 2025, Revised Selected Papers&#8221;</em></p><ul><li><p><a href="https://link.springer.com/chapter/10.1007/978-3-032-19540-1_3">Human and Organizational Factors in Smart Grid Cybersecurity</a></p></li></ul></li><li><p><a href="https://aarm.dev/intercept">INTERCEPT &#8212; Builders &amp; Breakers of Agentic Runtime Security</a> - February 2027, San Francisco</p></li><li><p><a href="https://cheri-alliance.org/events/cheritech26/call-for-papers/">CHERITech'26 Call for Papers</a> - November 2026, <span>Munich, DE @ </span><a href="https://www.semiconeuropa.org/">SEMICON Europa</a></p></li></ul></li></ul><p>Finally finally the <a href="https://creators.spotify.com/pod/profile/national-cyber-security-c6/episodes/The-Ransomware-Ecosystem-e2hi088">NCSC&#8217;s podcast series</a>.</p><div><hr></div><p><em>Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them. </em></p><p><em>This newsletter is subject to the NCSC website terms and conditions which can be found at <a href="https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions">https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions</a> and you can find out more about how will treat your personal information in our privacy notice at <a href="https://www.ncsc.gov.uk/section/about-this-website/privacy-statement">https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.</a></em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CTO at NCSC - Cyber Defence Analysis! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CTO at NCSC Summary: week ending August 16th]]></title><description><![CDATA[The NCSC has published a new fictional worked example demonstrating how organisations can apply the Secure Connectivity Principles for Operational Technology (OT)..]]></description><link>https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-10c</link><guid isPermaLink="false">https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-10c</guid><dc:creator><![CDATA[Ollie Whitehouse]]></dc:creator><pubDate>Sat, 15 Aug 2026 09:41:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!OX1P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8615329-0aa0-42e1-9a8d-33910e6aa623_2374x1162.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to the weekly highlights and analysis of the&nbsp;<a href="https://infosec.pub/c/blueteamsec?dataType=Post&amp;sort=New">blueteamsec</a>&nbsp;(and my wider reading). Not everything makes it in, but the best bits do. A community member is doing <a href="https://briefing.workshop1.net/">daily AI generated podcast of the last 24hours of posts</a>.</p><p>Operationally this week nothing overly of note.</p><p>In the high-level this week:</p><ul><li><p><a href="https://www.ncsc.gov.uk/blogs/water-sector-example-added-to-the-ncscs-secure-connectivity-principles"><span>Water sector example added to the NCSC&#8217;s Secure connectivity principles</span></a><span> - </span><strong><span>NCSC</span></strong><span> UK adds - </span><em><span>&#8220;The NCSC has published a new fictional worked example demonstrating how organisations can apply the </span><a href="https://www.ncsc.gov.uk/collection/operational-technology/secure-connectivity">Secure Connectivity Principles for Operational Technology (OT)</a><span>. The example explores</span><a href="https://www.ncsc.gov.uk/collection/operational-technology/worked-examples/secure-connectivity-water-sector-example"> how a regional water utility might approach the challenge of standardising digital connectivity across its OT environment</a><span> while maintaining safety, reliability and cyber resilience.&#8221;</span></em></p></li><li><p><a href="https://www.ncsc.gov.uk/blogs/how-bitlocker-pins-help-protect-your-data-and-devices"><span>How BitLocker PINs help protect your data and devices</span></a><span> - </span><strong><span> NCSC </span></strong><span>UK outlines - </span><em><span>&#8220;</span>However, many organisations use BitLocker without a PIN, leaving their devices vulnerable. In this blog we explain why a PIN is so important, and what to do if &#8211; for whatever reason &#8211; you can&#8217;t use a PIN.&#8221;</em></p></li><li><p><a href="https://www.gov.uk/government/ministers/parliamentary-under-secretary-of-state--316">Parliamentary Under-Secretary of State (Minister for Space, Cyber and Regulatory Reform)</a> - <strong>Department for Business, Innovation, Science and Trade</strong><span> and </span><strong>Department for Digital, Culture, Media and Sport</strong> announce - &#8220;<em>Baroness Lloyd of Effra CBE was appointed Parliamentary Under-Secretary of State (Minister for Space, Cyber and Regulatory Reform) jointly in the Department for Digital, Culture, Media and Sport (DCMS) on 23 July 2026 and the Department for Business, Innovation, Science and Trade (BIST) on 22 July 2026.&#8221;</em></p></li><li><p><a href="https://fortune.com/2026/08/11/ex-mi6-chief-richard-moore-biggest-risks-for-ceos/">Ex-MI6 chief says the biggest risks for CEOs are the threats they already know about</a> - <strong>Fortune</strong> interviews - <em>&#8220;He argues that the biggest risk for companies today isn&#8217;t some black swan event that we didn&#8217;t see coming. It&#8217;s managing systemic risk from cumulative impact of known issues: the layering of COVID-19 plus Ukraine, Iran, China stress, tariffs, and more.&#8221;</em></p></li><li><p><a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/">Expanding Capabilities to Combat Transnational Cyber-Enabled Crime</a> -  <strong>The White House</strong> (not me) announces - <em>&#8220;This memorandum expands the fight against TCO-perpetrated cybercrime by incorporating the ingenuity of the private sector.&#8221;</em></p><ul><li><p><a href="https://www.rusi.org/explore-our-research/publications/commentary/private-sector-cybercrime-disruption-compatible-statecraft">Private Sector Cybercrime Disruption: Compatible with Statecraft?</a> - <strong>RUSI</strong> think tanks - <em>&#8220;Arguably, there is a need to do more to make the UK a more hostile target, albeit in a context of constrained public resources. One approach could be through public-private partnerships that leverage the private sector&#8217;s capacity to build intelligence on criminal adversaries and, in limited contexts, disrupt their activities.&#8221;</em></p></li></ul></li><li><p><a href="https://www.schiff.senate.gov/wp-content/uploads/2026/08/Summary_Water-Cyber-Shield-Act.pdf">Water Cyber Shield Act of 2026</a> - <strong>Senator Schiff</strong> introduces - <em>&#8220;The Water Cyber Shield Act of 2026 is comprehensive legislation to reform how EPA addresses the vulnerability of water and wastewater systems to cyberattack. Through amendments to the Safe Drinking Water Act and the Clean Water Act, this bill empowers EPA with the authorities it needs as the Sector Risk Management Agency for the water and wastewater sector&#8212;a job EPA is statutorily tasked with but lacks the necessary authorities to carry out.&#8221;</em></p></li><li><p><a href="https://www.reuters.com/world/german-minister-warns-daily-hybrid-warfare-after-suspected-drone-attack-2026-08-08/">Germany warns of daily &#8216;hybrid warfare&#8217; after suspected drone attack</a> - <strong>Reuters</strong> reports - "We're not at war, but we are the &#8203;daily target of hybrid warfare," Dobrindt said. "Espionage, sabotage, cyberattacks, or covert operations by &#8288;foreign powers aimed at destabilising Germany or inflicting direct harm are a constant reality."</p></li><li><p><a href="https://stockholmcf.org/turkey-gives-presidential-cybersecurity-agency-power-to-order-internet-measures-before-court-review/">Turkey gives presidential cybersecurity agency power to order internet measures before court review</a> - <strong>Stockholm Centre for Freedom</strong> outlines - <em>&#8220;<span>Turkey has given a cybersecurity agency reporting directly to the presidency power to order internet and communications companies to carry out emergency measures before a judge reviews them, as part of a broader transfer of online regulatory powers from the country&#8217;s telecommunications watchdog, the TR724 news website </span><a href="https://www.tr724.com/btknin-yetkileri-siber-guvenlik-baskanligina-devredildi-mahkeme-karari-olmadan-erisim-engeli-getirilecek/">reported</a><span>.&#8221;</span></em></p></li><li><p><a href="https://www.kisa.or.kr/402/form?postSeq=2626">Discussion on Full-Lifecycle Ransomware Response Measures: &#8220;Beyond Prevention to Response and Recovery&#8221;</a> - <strong>Korea Internet &amp; Security Agenc</strong>y announces - <em>&#8220;The Korea Internet &amp; Security Agency (KISA, President Lee Sang-joong) announced on August 12, 2026 (Wednesday) that it will hold the "5th Ransomware Resilience Conference" in collaboration with the Ministry of Science and ICT (Deputy Prime Minister and Minister Bae Kyung-hoon) on September 16 (Wednesday) at the Peace &amp; Park Convention Center in Yongsan-gu, Seoul. The conference will share the latest trends, response technologies, and policies regarding ransomware and discuss measures to strengthen cyber resilience.&#8221;</em></p></li><li><p><a href="https://defenseanalyses.org/work/cyber-waterline/">Raise the Cyber Waterline</a> - <strong>The Defense Analyses and Research Corporation (DARC)</strong> think tanks - <em>&#8220;The debate over the risks of AI-enabled cyberattacks has remained academic for far too long. Now, time is short: Our adversaries will soon have access to models that can launch attacks at scale against unwitting defenders. America&#8217;s cyberdefense strategy has relied for too long on individual action, without reckoning with the harms caused to citizens by cyberattacks. The time to act to close this defensive gap is now, while we retain a substantial advantage in model capability.&#8221;</em></p></li><li><p>Reporting on/from China</p><ul><li><p><a href="https://www.ft.com/content/7d2ab3e0-9085-48f6-b38a-d90260d58795">China-linked hackers hit Taiwan in unprecedented &#8216;autonomous&#8217; AI cyber attack</a> - <strong>Financial Times</strong> reports - <em>&#8220;Suspected Chinese hackers used publicly available AI tools to compromise government websites in Taiwan in a first-of-a-kind breach, highlighting how artificial intelligence is transforming cyber warfare.&#8221;</em> - <strong>comment:</strong>  not sure this first-of-a-kind &#8230;</p><ul><li><p><a href="https://www.reuters.com/world/china/taiwan-says-it-was-targeted-last-month-ai-driven-hacking-campaign-2026-08-13/">Taiwan says it was targeted last month in AI-driven hacking campaign</a> - <strong>Reuters</strong> reports - &#8220;<em>The investigation &#8203;results showed the attacks displayed clear characteristics of an "overseas source", with hackers employing a hybrid approach that combined manual operations with AI agent-assisted attacks, such as Open Claw, it said.&#8221;</em></p></li></ul></li><li><p><a href="https://www.ejournal.org.cn/virtualProjectDetail?virtualId=6716&amp;type=article&amp;albumPartId=7453&amp;indexId&amp;index=0&amp;sortType=1&amp;lang=zh">Cutting-edge technologies in encrypted network security (2026)</a> - <strong>Journal of Electronics</strong> publishes - <em>&#8220;However, current defense systems still face the dual pressures of dynamic escalation of adversarial capabilities and computational bottlenecks: attackers use protocol-based concealment and adversarial feature drift to dismantle static models; 100Gbps backbone networks require millisecond-level response times, but the latency of traffic feature representation and deep learning model inference creates a rigid contradiction of "high precision requirements - low resource capacity." To accelerate the seamless integration of technological breakthroughs and scenario implementation, the *Journal of Electronics* has established a special column, "Frontier Technologies for Dense-State Network Security."&#8220;</em></p></li><li><p><a href="https://www.cac.gov.cn/2026-08/07/c_1787851071612596.htm">Soliciting Public Comments on the Draft Regulations on the Protection of Personal Information by Large-Scale Personal Information Processors</a> -  <strong>Cyberspace Administration of China</strong> consults - <em>&#8220;To regulate the personal information processing activities of large-scale personal information processors, protect the legitimate rights and interests of personal information, and promote the lawful and reasonable use of personal information, in accordance with the "Personal Information Protection Law of the People's Republic of China," the "Regulations on the Administration of Network Data Security," and other laws and administrative regulations, the Cyberspace Administration of China has integrated and improved the previously publicly solicited drafts, namely the "Regulations on the Establishment of Personal Information Protection Supervisory Committees for Large-Scale Online Platforms (Draft for Public Comment)" and the "Regulations on Personal Information Protection for Large-Scale Online Platforms (Draft for Public Comment)," and has now formed the "Regulations on the Protection of Personal Information by Large-Scale Personal Information Processors (Draft for Public Comment)," which is now open for public comment.&#8221;</em></p></li><li><p><a href="https://economictimes.indiatimes.com/tech/artificial-intelligence/china-deploys-robot-employees-in-beijing-to-patrol-city-parks-curb-inappropriate-behaviour/articleshow/132931772.cms">China deploys &#8216;robot employees&#8217; in Beijing to patrol city parks, curb inappropriate behaviour</a> - <strong>The Economic Times</strong> reports - <em>&#8220;Beijing has deployed seventy-two robot employees in its municipal parks this summer. These robots perform cleaning, patrolling, and visitor guidance duties across the city. Intelligent tour-guide robots answer questions and remind visitors about park rules. Specialised robots also attract and trap mosquitoes, reducing insect density in selected areas. This initiative aligns with China&#8217;s national &#8220;Robot Plus&#8221; strategy for public services.&#8221;</em></p></li></ul></li><li><p> AI</p><ul><li><p><a href="https://www.cisa.gov/sites/default/files/2026-08/Vulnerability_Clearinghouse-TLP-CLEAR_8.14.26_updated.pdf">Addressing AI-Enabled Cyber Risk: Establishing the AI Cybersecurity Clearinghouse</a> - <strong>CISA</strong> outline - &#8220;<em>Gold Eagle is a software capability that, at scale, enables ingestion, validation, and deduplication of AIenabled vulnerability reporting, amplifying CISA&#8217;s ability to triage incoming vulnerability reports for CVD within the VINCE platform. Gold Eagle simplifies the path from vulnerability discovery to remediation by streamlining initial report triage and validation for Coordinated Vulnerability Disclosure (CVD) and avoids duplication of efforts. Gold Eagle augments but does not replace existing private-sector or communitydriven vulnerability management efforts. Reports submitted through Gold Eagle that meet CVD requirements will initiate cases in VINCE&#8221;</em></p></li><li><p><a href="https://www.bbc.co.uk/news/articles/cn0nww2qlp7o">AI agent hacks gym to get its user a spot in pilates class</a> - <strong>BBC</strong> reports - <em>&#8220;He says he outsourced the &#8220;chore&#8221; to an AI agent - a tool that can carry out online tasks autonomously&#8230;. It succeeded, but went further than he imagined by hacking the gym&#8217;s online systems, in what is being seen as the latest example of the way AI agents will go to any lengths to carry out the jobs they&#8217;ve been given.&#8220;</em> - <strong>comment:</strong> this actually happened in April, the company blogged about it, the blog now appears deleted. What the agent found was the API endpoint had no security - there are many non AI tools which would find similar.</p></li><li><p><a href="https://z.ai/blog/glm-5.3">GLM-5.3: Frontier Coding with Emergent Cyber Capabilities</a> - <strong>Z.ai</strong> announce - <em>&#8220;As we scaled post-training, cyber capability developed faster than we expected. GLM-5.3 is state of the art on CyberGym for vulnerability discovery, and its gains are largest further up the exploitation chain, where it more than doubles GLM-5.2 on exploitation benchmarks.&#8221;</em></p><ul><li><p><a href="https://www.scmp.com/tech/big-tech/article/3364077/zhipu-launches-flagship-model-glm-53-china-seeks-mythos-level-edge-cyber-defence?module=top_story&amp;pgtype=homepage"><span>Zhipu launches flagship model GLM-5.3 as China seeks Mythos-level edge in cyber defence</span></a><span> - </span><strong><span>South China Morning Post</span></strong><span> reports - </span><em><span>&#8220;</span>Beijing-based Zhipu said GLM-5.3 achieved a success rate of 84.5 per cent on CyberGym, a benchmark that measures whether models can identify and validate security flaws from source code. That was above Anthropic&#8217;s Mythos at 83.8 per cent and OpenAI&#8217;s GPT-5.6 Sol at 83.6 per cent, according to Zhipu. However, the Chinese model did not match those foreign systems on ExploitBench, which gauges how far AI models climb the exploitation ladder. Its score of 54.4 per cent trailed Mythos&#8217; 78 per cent and GPT-5.6 Sol&#8217;s 76.5 per cent.</em></p></li></ul></li><li><p><a href="https://www.nist.gov/blogs/cybersecurity-insights/shaping-nvd-future-we-need-your-feedback-ai-enabled-vulnerability">Shaping the NVD for the Future: We Need Your Feedback on AI-Enabled Vulnerability Management</a> - <strong>NIST</strong> consults - <em>&#8220;As the volume of reported vulnerabilities surges and emerging technologies reshape the threat picture, it is time for traditional vulnerability management practices centered on periodic patching and manual remediation to be transformed toward continuous, automated, and contextual vulnerability management.&#8221;</em></p></li><li><p><a href="https://1password.com/blog/why-ai-generated-patches-still-require-human-review">AI-generated vulnerability patches require human review</a> - <strong>1Password</strong> quantify - <em>&#8220;<span>Across six recently-disclosed CVEs, we produced 6,080 patches using two frontier, cyber-capable reasoning models.</span> The average success rate for generating a patch that fully resolved the vulnerability (without materially changing application behavior) was just 26.0%<span>.</span>&#8220;</em> - <strong>comment:</strong> ~4.5% introduced new vulnerabilities! </p></li><li><p><a href="https://portswigger.net/research/can-ai-do-novel-security-research">Can AI do novel security research? Meet the HTTP Terminator</a> - <strong>James Kettle</strong> demonstrates - <em>&#8220;We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Building this sounded like a bad idea, so I did it.&#8221;</em> .. <em>&#8220;I'll also share discoveries from beyond the autonomy horizon - some only reachable with a tight human/AI research loop, and others beyond AI's reach entirely.&#8221; - </em><strong>comment:</strong> novelty comes in part from where techniques are applied and derivates discovered</p></li><li><p> <a href="https://v-v.space/2026/07/10/vul_research/">Security Research in the AI &#8203;&#8203;Era</a> - <strong>Victor V</strong> outlines the journey of a vulnerability researcher being disrupted - <em>&#8220;What does the future hold? I don't know. AI may become increasingly powerful, and software products from vendors may have fewer and fewer problems, leaving less and less room for vulnerability researchers, but this remains an unknown&#8221;</em></p></li><li><p><a href="https://github.com/lordx64/cyberkimi-benchmarks">CyberKimi &#215; ExploitBench &#8212; Results &amp; Evidence</a> - <strong>Taha Karim </strong>publishes - <em>&#8220;<span>three-way experiment on the bench's hardest WASM bug: CyberKimi unassisted </span>8/16<span> vs stock Kimi K3 </span>4/16<span> vs CyberKimi + disclosed methodology pack </span>10/16<span>. Includes the full leaderboard chart (only Mythos 16/15 and GPT 5.5-Codex-AutoNudge 15.0 sit above the pack-assisted run), the capability-by-capability story, and the road to Mythos.&#8221;</span></em></p></li><li><p><a href="https://www.foreignaffairs.com/podcasts/cyberwarfare-ai-age">Cyberwarfare in the AI Age</a> - <strong>Foreign Affairs</strong> podcasts - <em>&#8220;Jen Easterly has spent much of the past 20 years defending U.S. cyberspace against such threats. She has been both a military officer and a top civilian official, most recently running the Cybersecurity and Infrastructure Security Agency. Now, she warns, the danger is about to get much worse&#8221;</em></p></li><li><p><a href="https://www.nature.com/articles/s41586-026-10805-z.epdf?sharing_token=BsXUfnV_vesqWlbgwuiSk9RgN0jAjWel9jnR3ZoTv0OPZv90k0Uusk-eMQpr2xw3q_jQCqs4gn61QicKNbXV1p988XnIqZF1crl5h0ki3mIv_Qh-ZNbZyAwrlmVAeFa5KwqbuogKgCkTIT21mVITLa_pCzv5P6f2PvGFWejCLYw%3D">Agentic profiles for effective AI governance</a> - <strong>Google DeepMind</strong> publish in nature - <em>&#8220;The creation of effective governance mechanisms for artificial intelligence (AI) agents requires a deeper understanding of their core properties and the implications they have for deployment. This paper provides a characterization of AI agents that focuses on four dimensions: autonomy, efficacy, goal complexity and generality. We propose different gradations for each dimension and argue that each dimension raises unique questions about the design, operation and governance of these systems. Moreover, we draw on this framework to construct &#8216;agentic profiles&#8217; for different kinds of AI agent. These profiles help to illuminate cross-cutting technical and non-technical governance challenges posed by different classes of AI agents, ranging from narrow task-specific assistants to highly autonomous general-purpose systems.&#8221;</em></p></li><li><p><a href="https://arxiv.org/abs/2606.08310">To Nuke or Not to Nuke: LLMs&#8217; (Missing) Ethical Reasoning and Actions in a High-Stakes Decision-Making Simulation</a> - <strong>University of Florida</strong> researches - <em>&#8220;Across 130 high-tension Civilization V episodes replayed by 13 models under three factorial prompt interventions, no intervention or factorial combination reliably eliminates emergent escalation.&#8221;</em> - <strong>comment:</strong> we&#8217;ve seen this movie - War Games</p></li><li><p><a href="https://www.scmp.com/news/us/article/3362974/us-ai-leaders-turn-chinese-open-weight-models-challenging-closed-source-safety-claims"><span>US AI leaders turn to Chinese open-weight models, challenging closed-source safety claims</span></a><span> - </span><strong><span>South China Morning Post</span></strong><span> claims - </span><em><span>&#8220;</span>More American titans of artificial intelligence are describing Chinese open-weight models as better for AI safety and security than closed-source models, challenging the long-standing claim by US closed-source AI model developers such as Anthropic that open-source models present a threat to society. &#8220;From what I&#8217;m seeing, I think open-weight models seem safer to me than closed-weight models,&#8221; AI pioneer Andrew Ng, the former head of Google Brain and former chief scientist at Baidu, said at the Agentic AI Summit in Berkeley, California, on Saturday.&#8221;</em></p></li><li><p><a href="https://www.aei.org/research-products/working-paper/voltcraft-industrial-competition-in-the-age-of-ai-aei/">Voltcraft: Industrial Competition in the Age of AI</a> - <strong>The American Enterprise Institute</strong> think tanks  - <em>&#8220;<span>Resource availability has long shaped the ability of states to project power, from seabird guano in the 19th century to coal deposits in the 20th. In the age of AI, states need large numbers of devices capable of turning electricity into tokens to reap AI&#8217;s strategic and economic rewards. This is why the physical production and custody of computational power&#8212;</span>compute<span>&#8212;has become an essential element of national strategy and geopolitics.&#8221;</span></em></p></li><li><p><a href="https://foreignpolicy.com/2026/08/04/united-states-artificial-intelligence-race-china-openai-anthropic-donald-trump-elon-musk/">America&#8217;s Cosmic Bet on AI - The winner takes it all. What happens if the United States loses?</a> - <strong>Foreign Policy</strong> asks - <em>&#8220;Confronting this blizzard of claims and counterclaims about a bedazzling technology, four questions demand our attention. First, is the course that the United States has chosen prudent? Another way to think about this is, would a financial investor with fiduciary responsibility place this large a bet on a single sector? Second, what could go wrong? Could the eye-popping increases in investment and stock prices be another bubble&#8212;analogous to the financial wizardry that created the real-estate bubble that burst in the Great Recession of 2008 or the dot-com bubble in 2000? Third, why is the only other AI superpower&#8212;China&#8212;making such a radically different bet? And finally, if the miracle is delayed or never happens, what will the likely consequences be&#8212;not just for the U.S. economy but also for national security?&#8221;</em></p></li><li><p><a href="https://www.lawnews.co.uk/legal-news/connecticut-court-sanctions-self-represented-litigant-over-prompt-injection-in-a-court-filing/">Connecticut Court Sanctions Self-Represented Litigant over Prompt Injection in a Court Filing</a> - <strong>Law News</strong> reports - <em>&#8220;A Connecticut Superior Court judge has imposed sanctions for prompt injection in a court filing, ruling that a self-represented plaintiff in Elliott v. New York Bariatric Group, LLC (docket AAN-CV-25-6066141-S) hid machine-readable instructions inside multiple pleadings in an attempt to manipulate any artificial-intelligence tool reviewing the documents.&#8221;</em></p></li></ul></li><li><p><em>Cyber proliferation</em></p><ul><li><p><a href="https://www.bleepingcomputer.com/news/apple/apple-sends-new-threat-notification-alerts-over-mercenary-spyware-attacks/">Apple sends new &#8216;Threat Notification&#8217; alerts over mercenary spyware attacks</a> - <strong>Bleeping Computer</strong> reports - <em>&#8220;Apple confirmed to BleepingComputer that it sent a new batch of threat notifications on August 13 to targeted users in 110 countries.&#8221;</em></p></li></ul></li><li><p>Bounty Hunting</p><ul><li><p><a href="https://www.bybit.com/en/press/post/bybit-sues-north-korea-and-lazarus-group-secures-preliminary-injunction-freezing-stolen-assets-in-landmark-crypto-asset-recovery-effort-bb55bb16f1710f487aa">Bybit Sues North Korea and Lazarus Group, Secures Preliminary Injunction Freezing Stolen Assets in Landmark Crypto Asset Recovery Effort</a> - <strong>Bybit</strong> litigates - <em>&#8220;announced that it has filed a civil lawsuit in the U.S. District Court for the District of Columbia against the Democratic People's Republic of Korea (DPRK), its Reconnaissance General Bureau (RGB), and the Lazarus Group, which U.S. authorities have identified as the DPRK-linked hacking group responsible for the February 2025 cyberattack.&#8221;</em></p></li><li><p><a href="https://www.justice.gov/usao-dc/pr/north-carolina-man-sentenced-cyber-extortion-scheme-targeted-international-technology"><span>North Carolina Man Sentenced for Cyber Extortion Scheme that Targeted International Technology Company in D.C.</span></a><span> - </span><strong><span>US Department of Justice</span></strong><span> announces - </span><em><span>&#8220;According to filed documents, trial evidence, and witness testimony, Curry was contracted to work as a data analyst for approximately six months with the victim company. In that capacity, Curry had access to the victim company&#8217;s data files and other personnel and corporate information. Trial evidence established that Curry misused his position to access the victim company&#8217;s personnel and other sensitive corporate records, which he then used to carry out the cyber extortion scheme. Curry hatched his extortion scheme after he learned that his contract was not going to be renewed and that he would no longer be employed by the company.&#8221;</span></em></p></li><li><p><a href="https://federalnewsnetwork.com/technology-main/2026/08/fbi-investigating-north-korean-remote-it-staffer-working-for-u-s-agency/">FBI investigating North Korean remote IT staffer working for US agenc</a>y - <strong>Federal News Network</strong> reports - <em>&#8220;The FBI is investigating how an unidentified federal agency was recently swept up in a yearslong campaign involving North Korean remote IT workers fraudulently obtaining jobs at major companies and other organizations.&#8221;</em></p></li><li><p><a href="https://www.publico.pt/2026/08/07/sociedade/noticia/jovem-portugues-autodidacta-criou-versao-chatgpt-usada-crimes-fbi-alertou-pj-2184260">Young Portuguese self-taught entrepreneur created a version of ChatGPT that was used for crimes. FBI alerted PJ (Portuguese Judicial Police)</a> - <strong>Publico</strong> reports - <em>&#8220;He started hacking when he was only ten years old and created a program similar to ChatGPT that aided in committing crimes. Honesty and cooperation with the police should help in the trial.&#8221;</em></p></li></ul></li><li><p>Market Incentives</p><ul><li><p><a href="https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/08/acro-reprimanded-following-cyber-security-failings/">ACRO reprimanded following cyber security failings</a> - UK <strong>Information Commissioner&#8217;s Office</strong> reprimands - &#8220;<em>The ICO found ACRO had engaged third-party providers to deliver certain security services, including patch management. However, ACRO did not ensure clear responsibility for identifying and monitoring critical CMS security updates, failed to maintain an effective patch management process, and did not adequately investigate security alerts that could have identified the hacker&#8217;s activity earlier.&#8221;</em></p></li><li><p><a href="https://www.csis.org/analysis/end-could-ai-undermine-softwares-us-legal-shield">The End of &#8220;As-Is&#8221;: Could AI Undermine Software&#8217;s U.S. Legal Shield?</a> - <strong>Center for Strategic &amp; International Studies</strong> think thanks - <em>&#8220;Software occupies a privileged legal space that no other consumer product enjoys. A lamp that catches fire, a car with a defective airbag, or a harness that snaps under normal use all fall under strict product liability, a body of tort law that holds manufacturers responsible for defects regardless of fault. Software largely escaped that fate. Courts and legislators treat software as a licensed service rather than a product, letting it hide behind contract law instead. That exceptional treatment was a deliberate policy choice, and it is built on three core justifications that AI now undermines entirely&#8221;</em></p></li><li><p><a href="https://www.cnet.com/tech/services-and-software/apple-faces-lawsuit-over-icloud-private-relay-vulnerability/">Apple Faces Lawsuit Over iCloud Private Relay Vulnerability</a> - <strong>CNET</strong> reports - <em>&#8220;<span>Last week, a </span><a href="https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/">blog post</a><span> by Talal Haj Bakry and Tommy Mysk exposed a vulnerability in how iCloud Private Relay, in some circumstances, doesn&#8217;t shield a customer&#8217;s IP address, which is the entire purpose of the feature. Even when it&#8217;s enabled, their information can be exposed when using a passkey to sign in or when a website uses two methods (DNS prefetching and WebTransport) to load data faster.&#8221;</span></em></p></li><li><p><a href="https://www.theinsurer.com/cyber-risk/news/exclusive-goodwin-procter-paid-around-10-million-ransom-to-luna-moth-with-brit-2026-08-07/">Goodwin Procter Paid around $10 million ransom Luna Month</a> - <strong>The Insurer</strong> reports.</p></li><li><p><a href="https://www.koreajoongangdaily.com/korea/ppp-lawmaker-tells-us-house-coupang-data-breach-action-was-not-discriminatory/12826007">PPP lawmaker tells U.S. House Coupang data breach action was not discriminatory</a> - <strong>Korea JooAng Daily</strong> reports - &#8220;<em>&#8220;The letters were prepared to deliver accurate facts based on the official findings and regulatory actions of the Personal Information Protection Commission [PIPC] in response to claims raised by some U.S. lawmakers that the Korean government has unfairly targeted Coupang,&#8221; his office said in a press release."</em></p></li></ul></li></ul><p>Reflections this week are around the reality of the forced correction that all organisations are experiencing in cyber security as a result of scaled vulnerability discovery in the AI era and response required.</p><p>Firstly, it is important to point our that we have had other forced corrections. Arguably ransomware was a human driven, scaling through affiliates and playbooks, forced correction of technical and operational debt in organisations.</p><p>Secondly, when we consider the AI era there are a number of fundamentals to consider when thinking about what is required to achieve cyber resilience in practice.</p><ul><li><p>#1 - We aren&#8217;t going to solely patch our way to resilience in the AI era - noting we are <a href="https://www.ncsc.gov.uk/blogs/prepare-for-vulnerability-patch-wave">in the midst of the patch wave</a> and they should still be deployed.</p><ul><li><p>Expecting to run faster than AI adversaries by solely relying on patching for in perpetuity seems on the face of it challenging as a strategy</p></li></ul></li><li><p>#2 - Well run and effective operations are fundamental e.g.</p><ul><li><p>Comprehensive IT operations i.e. comprehensive asset management</p></li><li><p>Active technical debt management and paydown a key enabler</p></li><li><p><a href="https://www.ncsc.gov.uk/blog-post/strengthening-national-cyber-resilience-through-observability-threat-hunting">Cyber resilience through observability and threat hunting</a></p></li></ul></li><li><p>#3 - Architectures and other primitives are crucial e.g. (there are others).</p><ul><li><p>Memory safety technologies to mitigate memory corruption</p></li><li><p><a href="https://www.ncsc.gov.uk/collection/principles-for-secure-paws">Privileged access workstations (PAWs)</a></p></li><li><p><a href="https://www.ncsc.gov.uk/collection/cross-domain">Cross-domain approach and architecture</a></p></li><li><p><a href="https://www.ncsc.gov.uk/passkeys">Phishing resistant authentication such as Passkeys</a></p></li></ul></li><li><p>#4 - Machine speed coupled with dynamic and resilient operations the measure</p><ul><li><p>Demonstrated recoverability</p></li><li><p>Dynamic response to a changing environment</p></li><li><p>Ability to execute quickly and comprehensively</p></li></ul></li></ul><p><strong><a href="https://x.com/argvee/status/2085088373497282800?s=20"><span>Heather Adkins</span></a></strong><span> at Google did an excellent job in the last ten days at conveying the journey that software is going on with regards to its security and the likely impact AI will have and the future sunny uplands.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!OX1P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8615329-0aa0-42e1-9a8d-33910e6aa623_2374x1162.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!OX1P!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8615329-0aa0-42e1-9a8d-33910e6aa623_2374x1162.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!OX1P!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8615329-0aa0-42e1-9a8d-33910e6aa623_2374x1162.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!OX1P!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8615329-0aa0-42e1-9a8d-33910e6aa623_2374x1162.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!OX1P!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8615329-0aa0-42e1-9a8d-33910e6aa623_2374x1162.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!OX1P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8615329-0aa0-42e1-9a8d-33910e6aa623_2374x1162.jpeg" width="1456" height="713" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b8615329-0aa0-42e1-9a8d-33910e6aa623_2374x1162.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:713,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="/__u/substackcdn.com/image/fetch/$s_!OX1P!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8615329-0aa0-42e1-9a8d-33910e6aa623_2374x1162.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!OX1P!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8615329-0aa0-42e1-9a8d-33910e6aa623_2374x1162.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!OX1P!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8615329-0aa0-42e1-9a8d-33910e6aa623_2374x1162.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!OX1P!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8615329-0aa0-42e1-9a8d-33910e6aa623_2374x1162.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The nuance is the benefit of this wave is likely to not land evenly for every organisation. For example an organisation that is running on 10 to 15 year old technology is not going to benefit to the same extent as others.</p><p>This unevenness is why we say that AI will be a net benefit for cyber defence but the road between where we are and that end state is rocky and uneven.</p><p>There are no short cuts to pay down technical debt nor run effective resilient operations in practice - just planful execution.</p><p>Not getting this via email? Subscribe:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Think someone else would benefit? Share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-10c?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-10c?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p><strong>All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.</strong></p><p>Have a lovely Saturday&#8230;</p><p>Ollie</p><h1>Cyber threat intelligence</h1><p>Who is doing what to whom and how allegedly.</p><h2>Reporting on Russia</h2><h3>Social engineering performed by UAC-0145: compromising in the employment process</h3><p><strong>CERT Ukraine</strong> detail this alleged Russian operation which is noteworthy due the overlap with some North Korean tradecraft.</p><blockquote><p>CERT-UA has received information about the use of advanced social engineering methods by the cyber threat cluster UAC-0145 (subcluster UAC-0002, also known as Sandworm, APT44, Seashell Blizzard). In particular, on job search sites, attackers, having previously studied the candidate's resume, contact a potential victim, usually a system administrator/IT specialist, on behalf of an IT company (for example, ATLAS Business Group).</p></blockquote><p><a href="https://cert.gov.ua/article/6318863">https://cert.gov.ua/article/6318863</a></p><h3>Inside a Russian-Speaking Operator&#8217;s Toolkit for Compromising Ukrainian IP Cameras</h3><p><strong>Hunt.io</strong> disclose this alleged Russian operation which is noteworthy due to a focus on IP cameras.</p><blockquote><ul><li><p>[We] archived an open directory on 89.208.97[.]165:8888, exposing the compromise of a Ukrainian e-commerce site via SQL injection, which the operator then reused as a proxy and launch point for further activity.</p></li><li><p>The same server&#8217;s bash history records Tor-routed intrusion attempts against Ukrainian government and military sites, built with per-target credential lists, though the recovered files do not confirm whether any attempt succeeded.</p></li><li><p>The same server hosted a Docker project named &#8220;camview&#8221; in its archive, used to scan, exploit, and maintain a list of internet-exposed cameras using known Dahua and Hikvision vulnerabilities.</p></li><li><p>Recovered from the operator&#8217;s own directory: a catalog of 58 compromised Ukrainian cameras, a saved still from one of them, and a log of live viewing sessions with session lengths, frame counts, and frame rates recorded per stream, access the operator used, not exposure inferred from a scan.</p></li><li><p>A publicly available scanning tool integrated into camview led to a second, separately operated directory on 213.165.63[.]49, building anonymization proxy infrastructure that scanned routers across 15 European countries, with camera targeting focused on Ukraine.</p></li><li><p>The second operator&#8217;s toolkit relied on chaining multiple router and camera CVE&#8217;s using custom Python scripts with additional focus/targeting of servers in Odessa, Burshtyn, and Kherson.</p></li><li><p>Both operations show similar patterns: use of an open-source scanner to easily find and compromise cameras within specific geographic areas, and reliance on historically weak security on edge devices and internet exposed infrastructure.</p></li></ul></blockquote><p><a href="https://hunt.io/blog/russian-speaking-operator-ukrainian-camera-toolkit">https://hunt.io/blog/russian-speaking-operator-ukrainian-camera-toolkit</a></p><h2>Reporting on China</h2><h3>Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side</h3><p><strong>Symantec and Carbon Black</strong> detail an alleged overlap between Chinese espionage and criminal activities. The scale of the browser cookie theft is also noteworthy.</p><blockquote><ul><li><p>Jewelbug is a China-based hackers-for-hire group that runs parallel operations: espionage against governments and militaries across the Middle East, Southeast Asia and South Asia, and a for-profit cryptocurrency fraud business.</p></li><li><p>Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim&#8217;s browser into a full remote-control channel and reaches from there into the host and the internal network behind it.</p></li><li><p>At least one of the operators is tied to a registered Hunan company, and we have identified the sole legal representative by name from government-issued identity documents belonging to the operators.</p></li><li><p>Jewelbug&#8217;s main implant is the Antino backdoor. It also operates a malicious Chrome and Firefox extension posing as an application called &#8220;PDF Viewer&#8221;, paired with a helper disguised as a Microsoft Edge component that gave operators a command shell on the host.</p></li><li><p>In its largest operation, a single planted script placed a watering-hole on more than 15 government webmail tenants in a Middle Eastern country at once.</p></li><li><p>Jewelbug&#8217;s victim database recorded more than one million implant check-ins and more than 580,000 stolen browser cookies in less than three months of active operations. One set of implants was configured to utilize the internal proxy of a major U.S. aerospace and industrial manufacturer</p></li></ul></blockquote><p><a href="https://www.security.com/blog-post/jewelbug-crypto-fraud-espionage">https://www.security.com/blog-post/jewelbug-crypto-fraud-espionage</a></p><h3>PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure</h3><p><strong><span>Darrel Virtusio, Santiago Pontiroli </span></strong><span>and</span><strong><span> Subhajeet Singha </span></strong><span>detail an alleged Chinese operations against telecommunications. Noteworthy for the sectoral focus, regional focus as well as the capabilities and techniques employed. </span></p><blockquote><p>[We have] identified an ongoing campaign delivering a previously undocumented custom backdoor against Afghan telecom providers and South Asian critical infrastructure organizations. The backdoor, tracked as PATCHCORD, is a compiled C/C++ implant delivered through sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools. Infrastructure pivoting uncovered SHEETCORD, a Go-based implant that builds on PATCHCORD's capabilities while abusing Google Sheets for C2 communication. The malware was actively distributed through a domain impersonating India's National Informatics Centre (NIC).</p></blockquote><p><a href="https://www.acronis.com/en/tru/posts/patchcord-new-malware-cluster-targets-afghan-telecom-and-south-asian-critical-infrastructure/">https://www.acronis.com/en/tru/posts/patchcord-new-malware-cluster-targets-afghan-telecom-and-south-asian-critical-infrastructure/</a></p><h2>Reporting on North Korea</h2><h3><span>Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM</span></h3><p><strong>Genians</strong> details the further integration of AI into alleged North Korean operations.</p><blockquote><ul><li><p><span>Observed indications that the Kimsuky group built and operated local LLM environments using Ollama, GPT4All, and Msty.</span></p></li><li><p><span>Assessed to be in the phase of accumulating technologies and capabilities to integrate AI across its overall attack operations.</span></p></li><li><p><span>Identified indicators exhibiting North Korea-linked characteristics, such as &#8220;Arirang&#8221;, &#8220;&#49912;&#51060;&#53944;&#8221;, &#8220;&#44032;&#51077;&#47532;&#47141;&#8221;, and &#8220;&#47196;&#52636;&#46104;&#50688;&#45716;&#51648;&#8221;.</span></p></li><li><p><span>Continued targeted attacks against foreign diplomatic missions, as well as the military, security, and virtual asset sectors.</span></p></li><li><p><span>Abused Git-based repositories as C2 infrastructure and distribution channels for encrypted AsyncRAT payloads.</span></p></li><li><p><span>Highlighted the need to strengthen behavior-based EDR detection and threat hunting against the abuse of LNK files, PowerShell, and GitHub.</span></p></li></ul></blockquote><p><a href="https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm">https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm</a></p><h3>Shattering the Dream &#8211; When a Job Offer Becomes a Zero-Day Attack</h3><p><strong>Check Point Research</strong> details an aspect of an alleged enduring North Korean operation which is noteworthy for the local privilege escalation vulnerability on Windows apparently exploited.</p><blockquote><ul><li><p>[We are] tracking a long&#8209;running campaign called Operation Dream Job, targeting organizations worldwide, with a particular focus on the defense sector. The campaign is affiliated to DPRK-linked <a href="https://malpedia.caad.fkie.fraunhofer.de/actor/lazarus_group">Lazarus group</a> and its latest wave focuses on the defense sector in Europe and India.</p></li><li><p>In the latest variant of the Operation Dream Job campaign, the threat actor distributed SecurityPDF, a modified PDF viewer designed to open attacker-crafted PDF documents and execute a new backdoor which we named Troy.</p></li><li><p>During the intrusion, the threat actor exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of FudModule, Lazarus&#8217; kernel-mode rootkit. Following Check Point Research responsible disclosure, Microsoft released a patch as part of their August Patch Tuesday updates.</p></li><li><p>Lazarus also used CVE-2025-49113 to exploit vulnerable Roundcube webmail servers. The compromised servers were infected with RelayShell, a PHP webshell that repurposes compromised web servers as relay nodes within the attacker&#8217;s command-and-control infrastructure.</p></li><li><p>At least in one case, a compromised organization in Western Europe was leveraged to conduct a spear-phishing campaign, allowing the attackers to abuse the organization&#8217;s reputation and trust to target additional victims.</p></li></ul></blockquote><p><a href="https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/">https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/</a></p><h3>Smile, You&#8217;re on Camera. Part 2: Hiring Lazarus APT&#8217;s IT Workers in a Fake DeFi Startup</h3><p><strong>Any.run</strong>, <strong>BCA LTD</strong> and <strong>NorthScan</strong> push the boundaries with this alleged reverse Yahtzee and turn the tables on an alleged North Korean operation to study them</p><blockquote><ul><li><p>Researchers created a fake DeFi startup and hired suspected Famous Chollima operatives, providing a rare inside view of a DPRK IT worker operation.</p></li><li><p>The investigation followed the scheme beyond recruitment, showing how the operatives worked, collaborated, and accessed company resources after being hired.</p></li><li><p>The findings show that DPRK IT worker schemes are not only a hiring risk. Once inside, operatives can gain legitimate access to code, systems, intellectual property, and trusted business processes.</p></li></ul></blockquote><p><a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/">https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/</a></p><h3>Reporting on Iran</h3><p><em>Nothing overly of note this week</em></p><h2>Reporting on Other Actors</h2><h3>Akira Hits Safe Mode: Ransomware Rebooting Around EDR</h3><p><strong>James Northey </strong>detail this tradecraft shift by a ransomware group to subvert security controls.</p><blockquote><ul><li><p>After gaining access via an exposed SonicWall VPN, an Akira affiliate rebooted the victim host into Safe Mode with Networking to defeat EDR, a first for this ransomware variant in our telemetry.</p></li><li><p>Safe Mode is a boot mode that only loads essential drivers and services, disabling most third-party software. As such, the reboot stopped the Huntress agent and disabled Microsoft Defender&#8217;s real-time protection; Defender couldn&#8217;t quarantine the file until the attacker rebooted back to normal mode. Ransomware families like Snatch and AvosLocker have abused Safe Mode for years, but this is the first reported tie to Akira that Huntress has observed.</p></li><li><p>In this incident, Safe Mode also broke the ransomware. In its stripped-down memory environment, the Akira process tree hit an out-of-virtual-memory failure seconds after launching.</p></li><li><p>While the anti-EDR effort backfired and the ransomware did not deploy, the attacker had already exfiltrated credentials and file shares. Even without encrypting anything, they can still extort the victim by threatening to leak the stolen information.</p></li></ul></blockquote><p><a href="https://www.huntress.com/blog/akira-hits-safe-mode-ransomware-rebooting-around-edr">https://www.huntress.com/blog/akira-hits-safe-mode-ransomware-rebooting-around-edr</a></p><h3>Dissecting the JWR phishing framework</h3><p><strong>Chetan Raghuprasad</strong> details a phishing framework which detection teams will want to develop tradecraft for.</p><blockquote><ul><li><p>Cisco Talos recently identified an undocumented phishing framework, internally branded &#8220;JWR&#8221; by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.</p></li><li><p>The client engine of the JWR phishing framework is a real-time, operator-driven system that, rather than merely logging form submissions like a static credential-stealing page, keeps an AES-CTR encrypted WebSocket open to the threat actor so they can steer each victim&#8217;s session live.</p></li><li><p>The victim data targeted by the actor using JWR extends well beyond payment data, encompassing identity documents, Social Security numbers, passport and driver&#8217;s license images, website and PayPal credentials, 2FA codes, and full device fingerprints, all committed to the actor&#8217;s server once a session ends.</p></li><li><p>Talos assesses with medium confidence that the JWR phishing framework is a variant of &#8220;The Outsider,&#8221; a phishing-as-a-service (PhaaS) platform, based on several similarities in the client engine scripts and functionalities of the two PhaaS platforms.</p></li><li><p>Talos observed a real-world campaign delivering the JWR client via SMS lures impersonating toll authorities, and postal and courier services of several countries in Southeast Asia and the Middle East.</p></li></ul></blockquote><p><a href="https://blog.talosintelligence.com/dissecting-the-jwr-phishing-framework/">https://blog.talosintelligence.com/dissecting-the-jwr-phishing-framework/</a></p><h3>Software Supply Chain Incursions</h3><p><span>A reminder we issued guidance a number of weeks ago in </span><a href="https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies">Software supply chain attacks: check your dependencies</a><span> for software developers</span></p><ul><li><p><a href="https://www.sonatype.com/blog/six-npm-packages-use-ethereum-transactions-to-retrieve-malicious-payloads">Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads</a></p></li><li><p><a href="https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign">Deadbugz: Currently Active MCP Supply-Chain Campaign</a></p></li><li><p><a href="https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines">2,500+ Companies and 434,000 CI/CD Pipelines Exposed in the Largest AI Supply Chain Breach of 2026</a></p></li><li><p><a href="https://www.reco.ai/blog/city-forum-campaign-salesforce-servicenow?_sp=6f8f7e14-3ffd-4ec2-a14c-fde756e05986.1786602391108">The &#8220;City-Forum&#8221; Campaign - An advanced attacker is targeting Salesforce and ServiceNow instances worldwide</a></p></li></ul><h1>Discovery</h1><p>How we find and understand the latent compromises within our environments.</p><h2>Beyond the Userspace Call Stack: Kernel Subsystem Context for Detection Engineering</h2><p><strong>Nedim &#352;abi&#263;</strong>  et al bring kernel context enrichment to call stack analysis..</p><blockquote><p>Consider a conventional file operation. The userspace call stack can answer questions such as:</p><ul><li><p>Which process initiated the operation?</p></li><li><p>Which modules (DLLs or executables) and functions were involved?</p></li><li><p>Did the operation originate from an unusual execution path, like a floating memory region?</p></li><li><p>Does the stack pattern resemble malicious or injected code?</p></li></ul><p>The kernel side answers a different question: Which kernel subsystem actually serviced the operation? The userspace stack describes the path <em>into</em> the operating system, while the kernel stack describes the path <em>through</em> the operating system, and together, they provide a much richer behavioral picture.</p></blockquote><p><a href="https://fibratus.io/blog/kernel-call-stack-subsystem-context-detection-engineering">https://fibratus.io/blog/kernel-call-stack-subsystem-context-detection-engineering</a></p><p><a href="https://github.com/rabbitstack/fibratus">https://github.com/rabbitstack/fibratus</a></p><h2>Do local LLMs dream of becoming forensic investigators?</h2><p><strong>S. Nakano</strong> shows the potential of generative model use in forensic investigations. </p><blockquote><p><a href="https://github.com/sumeshi/forensia">FORENSIA</a> was created.</p><p>It automatically reads artifacts extracted from the surveyed equipment, generates and validates research hypotheses using local LLM, and continuously updates reports.</p></blockquote><p><a href="https://sumeshi.github.io/posts/works/do-localllms-dream-of-forensic-investigator">https://sumeshi.github.io/posts/works/do-localllms-dream-of-forensic-investigator</a></p><h2>ATEN: Endpoint Telemetry for AI Coding Agents</h2><p><strong>Anton Ovrutsky</strong> provides an observability super power with this release..</p><blockquote><p><strong>A</strong>gent <strong>T</strong>elemetry &amp; <strong>E</strong>vent <strong>N</strong>otation. ATEN is a background service that records what AI coding agents &#8212; Claude Code and Codex today &#8212; do on a host, and writes it out as structured events for a SIEM. It&#8217;s the same idea as Sysmon, scoped to agent activity.</p></blockquote><p><a href="https://www.antonlovesdnb.com/blog/aten">https://www.antonlovesdnb.com/blog/aten</a></p><p><a href="https://github.com/Antonlovesdnb/aten">https://github.com/Antonlovesdnb/aten</a></p><h2>On IP Addresses as Identifiers of Internet Users and Services</h2><p><strong>Rumaisa Habib, Sudheesh Singanamalla, Marwan Fayed</strong> and <strong>Zakir Durumeric</strong> provide some insight in IP resolution fragility. </p><blockquote><p>Using data collected from a global CDN, historical DNS records, and active DNS measurements, we investigate the extent to which IP addresses uniquely identify users and services on today&#8217;s Internet. We find that IP sharing has steadily increased over the past decade, with fewer than 0.2% of domains using a unique IPv4 address and up to millions of domains co-located on single IP addresses. On the client side, traffic is similarly skewed: 5% of client IP addresses account for over half of observed web requests worldwide. We further show that commonly cited explanations for regional differences do not fully explain the observed variation. Our findings have direct implications for Internet policies and practice that depend on IP addresses and risk disproportionate effects on both services and their users. Our results also provide empirical grounding for policymakers and operators to foster precise, accountable, proportionate, and private mechanisms for notions of identity</p></blockquote><p><a href="https://zakird.com/papers/ip_sharing.pdf">https://zakird.com/papers/ip_sharing.pdf</a></p><h1>Defence</h1><p>How we proactively defend our environments.</p><h2>Securing your Amazon S3 buckets: Identifying and remediating over-permissioned access</h2><p><strong>Hetal Kolekar, Fernando Chiera di Vasco Freitas,</strong> and <strong>Manonmayi Vedam</strong> try and get after this enduring challenge.</p><blockquote><p>This post provides a workflow framework and methodology recommendations for your security team to adapt. The focus of this post is on the what and why rather than a prescriptive implementation. You will need to customize the approach based on your organization&#8217;s requirements and existing security tooling.</p><p>This solution is intended for security engineers, cloud architects, and DevOps teams managing single- or multiple-account AWS environments with Amazon S3 workloads that require access management.</p></blockquote><p><a href="https://aws.amazon.com/blogs/security/securing-your-amazon-s3-buckets-identifying-and-remediating-over-permissioned-access/">https://aws.amazon.com/blogs/security/securing-your-amazon-s3-buckets-identifying-and-remediating-over-permissioned-access/</a></p><h2>Project Blacksea (where AI attacks drown)</h2><p><strong>Dario Pasquini</strong><span> and </span><strong>Michal Bazyli</strong> show how to contest in the AI era.</p><blockquote><p>Blacksea is an active honeypot and canary-bait control system built to detect and drown LLM-driven attackers: autonomous AI agents and LLM-assisted operators that scan and exploit systems. Blacksea doesn&#8217;t stop at watching LLM attacks. It exploits flaws in the attacker&#8217;s LLM judgment to gain arbitrary code execution on their machines, collect intel passive defenses can&#8217;t reach, and make sure they don&#8217;t come back.</p></blockquote><p><a href="https://github.com/cracken-ai/blacksea">https://github.com/cracken-ai/blacksea</a></p><h2>pentestkit</h2><p><strong>Taha Karim </strong>publishes this framework which will be a productivity enabler for some seecurity teams.</p><blockquote><p>A multi-agent, context-accumulating penetration-testing framework built on the Claude Agent SDK. An orchestrator drives a team of specialist agents through a real pentest, proves each finding by exploiting it, scores it with CVSS v3.1, and writes a client-ready report &#8212; all while a shared knowledge base grows and every packet that leaves the box passes one scope-guarded chokepoint.</p></blockquote><p><a href="https://github.com/lordx64/pentestkit">https://github.com/lordx64/pentestkit</a></p><h2>Threat Model Generator</h2><p><strong>Michael Scovetta</strong> et al release this AI skill which will provide scalability..</p><blockquote><p>A set of <a href="https://agentskills.io/">agent skills</a> for producing threat models for open-source projects, including an orchestrator and independently invocable specialists.</p><p>The output is a document describing the implicit security contract between a project and its downstream users: what the project assumes about its environment and inputs, which security properties it claims, which it explicitly disclaims, and which threats are left to the integrator. It is written to serve two readers at once: the downstream integrator deciding what they are now responsible for</p></blockquote><p><a href="https://github.com/alpha-omega-security/threat-model">https://github.com/alpha-omega-security/threat-model</a></p><h2>AgentSweep</h2><p><strong>Ishan</strong> releases this sanitiser to reduce the proliferation of secrets around agentic systems.</p><blockquote><p>Claude Code (and every other AI coding CLI) stores your full conversation history as plain-text JSONL on disk, under <code>~/.claude/projects/</code> for Claude Code and <code>~/.codex/sessions/</code> for OpenAI Codex. Anything you paste, whether an AWS key, a <code>.env</code> file, or a database URL, sits in clear text indefinitely. A typical dev&#8217;s history accumulates dozens of secrets over months, usually unnoticed.</p><p><code>agentsweep</code> scans that history, tells you what leaked, and can redact the secret values in place while preserving the JSONL structure byte-for-byte. It also tells you which keys to rotate, with the right revocation URL for each provider.</p></blockquote><p><a href="https://github.com/Ishannaik/agent-sweep">https://github.com/Ishannaik/agent-sweep</a></p><h2>PerspectiveGraph</h2><p><strong>Luigi Iacuaniello</strong> releases this excellent use of graphs in cyber defence to real-world and real-time benefit in a development pipeline.</p><blockquote><p>On every pull request, PerspectiveGraph (open source, Apache 2.0) answers one question against a graph of your <em>real</em> environment - built from the scanners you already run (Trivy, Semgrep, Cloud Custodian, Falco):</p><blockquote><p><em>Does this change open a path from the internet, through excessive privilege, to something valuable?</em></p></blockquote><p><span>When it does, the </span><strong>PR check goes red</strong><span> - a required status you can block the merge on - and you get the </span><strong>fix as its own one-click pull request</strong><span>. The reachable attack path is caught and closed in code review, where it's cheapest, not months later in production. This is </span><strong>shift-left attack-path analysis</strong><span>: not a scanner bolted onto CI, not a runtime CNAPP you log into after the fact - the reachability question, answered </span><em>in the developer's workflow</em><span>.</span></p></blockquote><p><a href="https://github.com/luiacuaniello/perspectivegraph">https://github.com/luiacuaniello/perspectivegraph</a></p><h2>NoiseHound</h2><p><strong>Jared Perry </strong>releases this operational security enabling use of graphs.</p><blockquote><p>BloodHound (and PlumHound on top of it) finds <em>a</em> path to the objective. NoiseHound ingests the same graph data and re-ranks paths by <strong>expected detection cost</strong> instead of hop count, so an operator can ask &#8220;what is the quietest way to Domain Admin&#8221; instead of just &#8220;what is a way&#8221;.</p></blockquote><p><a href="https://github.com/warpedatom/noisehound">https://github.com/warpedatom/noisehound</a></p><h1>Incident Writeups &amp; Disclosures</h1><p>How they got in and what they did.</p><h2>Updated GPG key for signing Firefox and Thunderbird Releases</h2><p><strong>Mozilla</strong> disclose and mitigate.</p><blockquote><p>Today, we moved to a new GPG signing subkey used to sign certain Firefox and Thunderbird artifacts (namely Linux tarballs, RPM packages, checksums files) after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository.</p><p>Our review of available audit records found no evidence that the key was accessed by an unauthorized party while it was present in the repository. Access to the repository was limited to a small group within Mozilla, all of whom already had authorized access to the key through other means.</p></blockquote><p><a href="https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/">https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/</a></p><h1>Vulnerability</h1><p>Our attack surface.</p><h2>Spectre on RISC-V Silicon: Attacks and Defenses on Commercial Out-of-Order Processors</h2><p><strong>Lukas Gerlach, Marton Bognar, Daniel Weber, Michael Schwarz</strong> and <strong>Jo Van Bulck</strong> show that RISC-V does share this vulnerability class.</p><blockquote><p>Speculative execution attacks have been extensively studied on mainstream x86 and ARM architectures. However, on RISC-V, research has mostly concentrated on open-source academic designs. Commercially available RISC-V silicon is widely perceived as too simple to be vulnerable, and as a result, no end-to-end attacks have been demonstrated on real hardware to date and essential software such as the Linux kernel remains unmitigated. In this paper, we challenge that assumption. We systematically assess all commercially available out-of-order RISC-V processors (SiFive P550 and T-Head Xuantie C910/C920), finding them vulnerable to a range of Spectre attacks, and demonstrate the first Spectre attack leaking arbitrary kernel memory on real RISC-V hardware.</p><p>..</p><p>Our analysis shows that the SiFive P550 and Xuantie C910/C920 are vulnerable to all major Spectre variants, and we demonstrated a Spectre exploit on RISC-V hardware that leaks kernel memory via BPF.</p></blockquote><p><a href="https://lukasgerlach.me/publication/2026-speculative-execution-attacks-on-risc-v-silicon/riscv_spectre_sec26.pdf">https://lukasgerlach.me/publication/2026-speculative-execution-attacks-on-risc-v-silicon/riscv_spectre_sec26.pdf</a></p><p><a href="https://zenodo.org/records/20759985">https://zenodo.org/records/20759985</a></p><h2>SLAC: Access-Driven CPU-to-GPU Side-channel Attacks via System-Level Cache on Apple Silicon</h2><p><strong>Tianhong Xu</strong><span>, </span><strong>Saion K. Roy</strong><span>, </span><strong>Ruyi Ding</strong><span>, </span><strong>Aidong Adam Ding</strong><span>, and </span><strong>Yunsi Fei</strong> detail that side channels do exist here.</p><blockquote><p>Building on these findings, we construct the CPrime+CProbe SLC side-channel technique, which monitors GPU victim activity from the CPU at cache-set granularity. We then introduce an accelerated variant, GPrime+CProbe, in which an adversary leverages the GPU for faster SLC priming, yielding a 6.4x increase in the covert-channel throughput. Lastly, we demonstrate two end-to-end privacy attacks using the new side-channels: a graph-edge reconstruction attack on Graph Neural Networks (GNNs) that achieves 90% edge accuracy across five datasets, and an LLM privacy attack that recovers input keywords with up to 94.8% accuracy and model responses with up to 88.9% accuracy across TinyLlama and GPT-2 Medium models. Our results reveal a new class of microarchitectural vulnerabilities in Apple Silicon and call for secure system cache designs for heterogeneous SoCs.</p></blockquote><p><a href="https://arxiv.org/abs/2608.09075">https://arxiv.org/abs/2608.09075</a></p><h2>You&#8217;re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))</h2><p><strong>Sina Kheirkhah </strong>walks through the exploitation of this vulnerabilty.</p><p><a href="https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/">https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/</a></p><h2>CSS:the bomb inside your inbox</h2><p><strong>Gareth Heyes</strong> pulls off a spectacular feat with this release..</p><blockquote><p>It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this paper I'm going to show you how to break out of trust boundaries, exfiltrate tokens, compromise 3rd party websites and even steal passwords.</p><p>..</p><p>You should block select menus in your HTML sanitizer. It was still possible to construct a keylogger in &#8220;allow listed&#8221; HTML/CSS in Outlook. Blocking select would have prevented that.</p></blockquote><p><a href="https://portswigger.net/research/css-the-bomb-inside-your-inbox">https://portswigger.net/research/css-the-bomb-inside-your-inbox</a></p><h2>Hunting Exchange Server 0day like a detective</h2><p><strong>Jang</strong> drops a truth bomb and pushes on..</p><blockquote><p>The raise of AI is painfully killing the vuln research community industry. Most of medium-quality 0-day are easily found by AI in oneshot. And other novel 0day, art of exploit are also found by the assist of frontier model.</p></blockquote><p><a href="https://testbnull.medium.com/hunting-exchange-server-0day-like-a-detective-3fd5e0dc9779">https://testbnull.medium.com/hunting-exchange-server-0day-like-a-detective-3fd5e0dc9779</a></p><h2>IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay</h2><p><strong>Talal Haj Bakry</strong><span> and </span><strong>Tommy Mysk</strong> disclose..</p><blockquote><p>WebKit-based browsers on iOS and macOS can be configured to route all web traffic through proxy servers, which is how Tor browsers on iOS and our own Psylo work. We found three WebKit features &#8212; DNS prefetching, WebAuthn Related Origin Requests, and WebTransport &#8212; that bypass the configured proxy and send traffic directly from the device, which exposes the user&#8217;s real network. The same leaks also affect Apple&#8217;s iCloud Private Relay. All three are fixed in Psylo 1.3.1.</p></blockquote><p><a href="https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/">https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/</a></p><h1>Offense</h1><p>Attack capability, techniques and trade-craft. </p><h2>Design and Implementation of a Physical Implant Attack on the Boeing 737</h2><p><strong>Sam Crow, Pat Pannuto, Stephen Checkoway, Stefan Savage, Patrick Mercier</strong> and <strong>Aaron Schulman</strong> deliver the seminal work which will lead to a likely regulatory re-think in time.</p><blockquote><p>We explore a new kind of threat model for aviation cybersecurity&#8212;one in which an adversary has temporary physical access to an airframe. We argue why such attacks are practically feasible and explain how the design of existing avionics systems, their interconnects, and their maintenance architecture make such threats of particular concern. Using the Boeing 737 as an example, we develop and demonstrate a small, programmable hardware implant that can be quickly inserted into an existing maintenance socket with roughly 60 seconds of access on the ground. By carefully manipulating physical ARINC 429 bus signals, this device can create an undetected &#8220;attacker-in-the-middle&#8221; (AITM) capability between the aircraft&#8217;s flight management computer (FMC) and multipurpose control display unit (MCDU). We explore the options for addressing this class of attack and, in particular, show why transformer-coupled buses such as MIL-STD-1553, are far more challenging to manipulate in this manner.</p></blockquote><p><a href="https://cseweb.ucsd.edu/~savage/papers/UsenixSec26-429.pdf">https://cseweb.ucsd.edu/~savage/papers/UsenixSec26-429.pdf</a></p><h2>Weaponizing Windows Updates with NotWSUSpicious</h2><p><strong>Beyviel David</strong> reminds why we should all protect our update servers..</p><blockquote><p><code>NotWSUSpicious</code><em> is a tool repo to aid in creating custom updates after gaining access to a WSUS database server. The </em><code>Turning Enterprise Update Servers Into Backdoor Factories (0_o)</code><em> series covers how the database takeover works.</em></p></blockquote><p><a href="https://specterops.io/blog/2026/08/05/weaponizing-windows-updates-with-notwsuspicious/">https://specterops.io/blog/2026/08/05/weaponizing-windows-updates-with-notwsuspicious/</a></p><h2>TrustMeBro</h2><p><strong>Kriyos</strong> releases this work aid which will surface no doubt expected presents for all. Also worth detection teams understanding if its use has any signatures. </p><blockquote><p>Authenticode signature manipulation toolkit for Red Team operations and security research. Covers signature stealing, metadata cloning, SIP hijacking across 19 file types, WinVerifyTrust FinalPolicy bypass, PKCS#7 payload embedding, SIP execution surface implants, and analyst-triggered persistence via OID handlers.</p></blockquote><p><a href="https://github.com/KriyosArcane/TrustMeBro">https://github.com/KriyosArcane/TrustMeBro</a></p><h2>Digital Forensics: Attacking SAM and Extracting Hashes With 7z</h2><p><strong>Co11ateral</strong> shows how this is done..</p><blockquote><p>Today we&#8217;re using 7z to find and pull the hives. It&#8217;s very common to find and it has raw disk access to fetch what we need without triggering the EDR. You can basically call it a living off the land technique due to its widespread presence. There are other ways to extract hashes, but most of them are well known and monitored. Some hackers rely on VSS and it works fine in some environments, but detecting VSS abuse isn&#8217;t hard. It&#8217;s a beginner level of complexity. VSS leaves very specific traces in the logs when you use it. Native Windows binaries get blocked outright and finding forensic tools already sitting on an endpoint is uncommon.</p></blockquote><p><a href="https://hackers-arise.com/digital-forensics-attacking-sam-and-extracting-hashes-with-7z/">https://hackers-arise.com/digital-forensics-attacking-sam-and-extracting-hashes-with-7z/</a></p><h1>Exploitation</h1><p>What is being exploited..</p><p><em>Nothing overly of note this week&#8230;</em></p><h1>Tooling and Techniques</h1><p>Low level tooling and techniques for attack and defence researchers</p><h2>Orchestrate AI agents to find real vulnerabilities in code</h2><p><strong>Harel Rom</strong> et al bring this harness to the world to find vulnerabilities&#8230; </p><blockquote><p>Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code.</p></blockquote><p><a href="https://github.com/Kritt-ai/open-kritt/tree/main">https://github.com/Kritt-ai/open-kritt/tree/main</a></p><h2>Bypassing Android Hardware Attestation from the Analyst&#8217;s Chair</h2><p><strong>Eric Le Guevel</strong> highlights a gap that will need to got after..</p><blockquote><p>Hardware key attestation lets an Android app prove to its backend that a key lives in secure hardware on a locked, verified device. It is also the wall that stops a security analyst working on a rooted phone. This article opens the mechanism from the analyst&#8217;s chair, from the certificate chain and the attestation extension down to the root of trust, then shows a simple bypass that never touches the secure hardware. We relay the attestation to a clean device and splice a genuine chain back into the target app with a Frida hook. A companion repository ships the validation backend, the demo apps and the instrumentation, so the whole setup can be run and inspected rather than taken on faith.</p></blockquote><p><a href="https://blog.quarkslab.com/bypassing-android-hardware-attestation.html">https://blog.quarkslab.com/bypassing-android-hardware-attestation.html</a></p><h2>skitter-creek-bath-salts</h2><p><strong>Christopher Domas</strong> drops this capability against an aging CPU but which unlocks it as a research platform.</p><blockquote><p><span>Developed and tested on </span>AMD Family 16h CPUs<span>, the last generation whose datasheets document the DRAM controller's translation registers &#8212; and show that they can't be locked. 17h and beyond simply leave this information out.</span></p><p><span>..</span></p><p>Unlocking everything on the CPU with DRAM scrambling &#8212; PSP, C6, microcode, SMM, and anything else the specs left out.</p><p><em>..</em></p><p><span>Poke the DRAM controller and an address can be made to land wherever you want in memory. </span><code>skitter-creek-bath-salts</code><span> modifies the bottom layers of the memory hierarchy to rewire the physical DRAM address translations. This scrambles platform memory, exposing protected regions of DRAM &#8212; carveouts invisible even to the kernel. When the address translations break, so do the security primitives built on them, and we unlock </span><em>everything</em><span>.</span></p></blockquote><p><a href="https://github.com/xoreaxeaxeax/skitter-creek-bath-salts">https://github.com/xoreaxeaxeax/skitter-creek-bath-salts</a></p><h1>Footnotes</h1><p>Some other small (and not so small) bits and bobs which might be of interest.</p><ul><li><p>Annual, quarterly and monthly reports</p><ul><li><p><em>Nothing overly of note this week, but keep an eye on</em> <a href="https://github.com/jacobdjwilson/awesome-annual-security-reports/tree/main/Annual%20Security%20Reports/2026">the Awesome Annual Security Reports 2026 collection</a> and <a href="https://github.com/blackorbird/APT_REPORT">APT report collection</a></p></li></ul></li><li><p><a href="https://unidir.org/due-diligence-in-early-practice-the-international-law-commission-agenda-and-cyberspace/">Due diligence in early practice, the International Law Commission agenda and cyberspace</a></p></li><li><p><a href="https://belfortlabs.com/blog/belfort-partners-with-lg-on-encrypted-advertising-recommendations">Encrypted advertising recommendations</a></p></li><li><p><a href="https://cloud.google.com/blog/products/identity-security/pqc-in-plaintext-google-clouds-post-quantum-cryptography-roadmap/">PQC in Plaintext: Google Cloud&#8217;s post-quantum cryptography roadmap</a></p></li><li><p><a href="https://arxiv.org/abs/2608.10645">AIDC Microgrid <span>Vulnerability</span> Assessment Under Computing-Power Coordinated Attacks</a></p></li><li><p>Artificial intelligence</p><ul><li><p><span>if you are a big </span><a href="https://arxiv.org/">arxiv.org</a><span> user - out of China there is </span><a href="https://www.alphaxiv.org/">alphaxiv.org</a><span> which is an AI powered incarnation / overlay</span></p></li><li><p>Fundamental</p><ul><li><p><a href="https://arxiv.org/abs/2607.17427">Abliteration Is Not a Scalpel: Off-Target Effects of Refusal Removal on Decision Disposition Across Model Families</a></p></li><li><p><a href="https://arxiv.org/abs/2601.01828">Emergent Introspective Awareness in Large Language Models</a></p></li></ul></li><li><p>Applied non-cyber</p><ul><li><p><a href="https://www.usenix.org/conference/usenixsecurity25/presentation/pasquini">LLMmap: Fingerprinting for Large Language Models</a></p></li><li><p><a href="https://joncrussell.com/post/are-we-there-yet/">Are we there yet? Ten weeks of Rust Symex</a></p></li><li><p><a href="https://arxiv.org/abs/2608.01322">Can Language Models Identify Shadow Trading Targets? An NLP Evaluation of SEC Enforcement Theory</a></p></li><li><p><a href="https://arxiv.org/abs/2608.04205">MatrAIx: Simulating the World with 8.3 Billion Persona Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2608.10920">IO Factory: Simulating AI-Enabled Influence Campaigns at Scale</a></p></li><li><p><a href="https://github.com/AlloySecureGroup/Horcrux">Horcux: A tool to build and preserve agentic work</a></p></li><li><p><a href="https://arxiv.org/abs/2608.11201">VidForensics-M1: Meta-Detection Reinforcement Learning with Verifiable Temporal Grounding for AI-Generated Video Forensics</a></p></li><li><p><a href="https://www.anthropic.com/research/multiagent-systems?ref=metacurity.com">Patterns and problems in emerging multiagent systems</a></p></li></ul></li><li><p>Applied cyber specific</p><ul><li><p><a href="https://www.aiuc-1.com/">The standard for AI agent security, safety and reliability</a></p></li><li><p><a href="https://blog.google/security/the-evolving-role-of-the-red-team-in-the-era-of-agentic-security/">The Evolving Role of the Red Team in the Era of Agentic Security</a></p></li><li><p><a href="https://aws.amazon.com/blogs/opensource/introducing-dogwood-runtime-verification-for-ai-agents/">Introducing Dogwood: runtime verification for AI agents</a></p></li><li><p><a href="https://www.dragos.com/blog/ai-vulnerability-detection-ot-security-methodology">Refuted by Default: Dragos&#8217; Methodology for AI-Driven Vulnerability Detection in OT Security Software</a></p></li><li><p><a href="https://xbow.com/blog/autonomous-agent-safety-guardrails">Engineering the Impossible: Adding Safety to Autonomous Agents</a></p></li><li><p><a href="https://github.com/cracken-ai/blacksea">Project Blacksea (where AI attacks drown)</a></p></li><li><p><a href="https://v-v.space/2026/07/10/vul_research/">Security Research in the AI &#8203;&#8203;Era</a></p></li><li><p><a href="https://huggingface.co/BugTraceAI">Models built for BugTraceAI, an agentic web pentesting framework</a></p></li><li><p><a href="https://arxiv.org/abs/2608.09643">Activation Probes Surface Code-Security Signals that the Model's Output Misses</a></p></li><li><p><a href="https://arxiv.org/abs/2608.11436">When Agents Talk: Honeytokens under Shared Memory</a></p></li><li><p><a href="https://arxiv.org/abs/2608.11291">Dueling Deep Q-Learning for Intrusion Detection</a></p></li><li><p><a href="https://arxiv.org/abs/2608.11878">ToolHazard: Scaling Adversarial Environments for Security Evaluation and Alignment of LLM-based Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2608.10171">Generating Attacks for LLMs with GFlowNets</a></p></li><li><p><a href="https://arxiv.org/abs/2608.09225">Governing the KV Cache: Preventing Timing Side-Channel Leakage in Multi-Tenant LLM Inference</a></p></li><li><p><a href="https://arxiv.org/abs/2608.09181">Memoir: Learning, Verifying, and Evolving False-Positive Memories for Static Application Security Testing Tools</a></p></li><li><p><a href="https://github.com/opendr-io/analyst">Analyst</a> - <em>&#8220;An agent that answers questions about cybersecurity conference research using an agent curated knowledge base. UI is via Jupyter notebook or command prompt.SQL queries can also be used to search for researchers, talks, or tools.&#8221;</em></p></li><li><p><a href="https://github.com/Kritt-ai/open-kritt/tree/main">Orchestrate AI agents to find real vulnerabilities in code.</a></p></li><li><p><a href="https://arxiv.org/abs/2608.12431">The energetic cost of mitigating AI attacks in cellular networks</a></p></li><li><p><a href="https://andrewkwong.org/docs/keytar-camera.pdf">KeyTAR: Practical Keystroke Timing Attacks and Input Reconstruction</a> - <em>&#8220;This paper bridges this long-standing gap in the literature and performs a comprehensive study on the feasibility of reconstructing typed input from inter-keystroke timings. We model input reconstruction as a machine translation task and fine-tune open-source Large Language Models (LLMs) with a curriculum learning strategy, leveraging their ability to utilize contextual information and incorporate semantic understanding into the reconstruction process.&#8221;</em></p></li></ul></li></ul></li><li><p>Books</p><ul><li><p><em>Nothing overly of note this week</em></p></li></ul></li><li><p>Events</p><ul><li><p><a href="https://blackhat.com/us-26/briefings/schedule/?">Blackhat 2026</a> - slides etc.</p></li><li><p><a href="https://www.usenix.org/conference/usenixsecurity26/technical-sessions">USENIX Security &#8216;26 Technical Sessions</a> - slides/papers etc.</p><ul><li><p><a href="https://www.usenix.org/sites/default/files/sec26_contents.pdf">35th USENIX Security Symposium</a></p></li></ul></li><li><p><a href="https://www.youtube.com/watch?v=x6vr4GWToYc&amp;list=PLH15HpR5qRsV2HXnhRJWcAmWoVW2dupVC">Blackhat 2026</a> - videos</p></li><li><p><a href="https://www.youtube.com/watch?v=Yc2hPtCATSk&amp;list=PL7ZDZo2Xu331YBC_jYYUvN-CSiPFI4hoP">x33fcon 2026</a> - videos</p></li></ul></li></ul><p>Video of the week part I - Cybercom 2.0</p><div id="youtube2-Q_pjxyQRAZ8" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;Q_pjxyQRAZ8&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/Q_pjxyQRAZ8?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Video of the week par II - How North Koreans Secretly Infiltrate U.S. Companies </p><div id="youtube2-RUhdmIFpb-w" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;RUhdmIFpb-w&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/RUhdmIFpb-w?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Video of the week part III - The Shadow War: How Freelance Sleuths Are Beating North Korea&#8217;s Cyber Syndicate</p><div id="youtube2-rHPuXtEMPzA" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;rHPuXtEMPzA&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/rHPuXtEMPzA?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Finally finally the <a href="https://creators.spotify.com/pod/profile/national-cyber-security-c6/episodes/The-Ransomware-Ecosystem-e2hi088">NCSC&#8217;s podcast series</a>.</p><div><hr></div><p><em>Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them. </em></p><p><em>This newsletter is subject to the NCSC website terms and conditions which can be found at <a href="https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions">https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions</a> and you can find out more about how will treat your personal information in our privacy notice at <a href="https://www.ncsc.gov.uk/section/about-this-website/privacy-statement">https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.</a></em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CTO at NCSC - Cyber Defence Analysis! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CTO at NCSC Summary: week ending August 9th ]]></title><description><![CDATA[&#8220;North Korea relies upon a network of skilled Information Technology (IT) workers, deployed within and outside of North Korea, to obtain false identities and remotely earn income"]]></description><link>https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-9ad</link><guid isPermaLink="false">https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-9ad</guid><dc:creator><![CDATA[Ollie Whitehouse]]></dc:creator><pubDate>Sun, 09 Aug 2026 07:42:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Nban!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69fc092b-a481-4f70-92a8-6975e3f24cc9_1004x348.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to the weekly highlights and analysis of the&nbsp;<a href="https://infosec.pub/c/blueteamsec?dataType=Post&amp;sort=New">blueteamsec</a>&nbsp;(and my wider reading). Not everything makes it in, but the best bits do. A community member is doing <a href="https://briefing.workshop1.net/">daily AI generated podcast of the last 24hours of posts</a>.</p><p>Operationally this week the Beacon breach has been a cause of activity.. </p><p>In the high-level this week:</p><ul><li><p><a href="https://www.ncsc.gov.uk/news/ncsc-statement-in-response-to-recent-incidents-resulting-from-frontier-ai-evaluations"><span>NCSC statement in response to recent incidents resulting from frontier AI evaluations</span></a><span> - </span><strong><span>NCSC</span></strong><span> issues - </span><em><span>&#8220;A statement from Ollie Whitehouse, Chief Technology Officer at the NCSC, on AI security following recent incidents.&#8221;</span></em></p></li><li><p><a href="https://www.state.gov/releases/office-of-the-spokesperson/2026/07/alert-to-countries-companies-and-other-entities-regarding-north-korean-it-workers/">Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers </a>-  <strong>US Department of State</strong>, UK <strong>Foreign Commonwealth &amp; Development Office</strong> and others warn - <em>&#8220;North Korea relies upon a network of skilled Information Technology (IT) workers, deployed within and outside of North Korea, to obtain false identities and remotely earn income to fund North Korea&#8217;s unlawful nuclear weapons and ballistic missile programs.&#8221;</em></p></li><li><p><a href="https://www.gov.uk/government/publications/cyber-security-breaches-survey">Cyber security breaches survey: 2026/2027</a> - <strong>DCMS</strong> announces - <em>&#8220;The government is conducting a survey of UK businesses, educational institutions and charities. The survey aims to find out how you approach cyber security and to learn more about the cyber security issues you face. The research will inform government policy on cyber security and how the government works with organisations to protect and promote the UK online.&#8221;</em></p></li><li><p><a href="https://www.gov.uk/government/consultations/whole-energy-cyber-resilience-requirements-reshaping-cyber-regulation-in-downstream-gas-and-electricity#full-publication-update-history">Whole energy cyber resilience requirements: reshaping cyber regulation in downstream gas and electricity</a> - <strong>Department for Energy Security and Net Zero</strong><span> and </span><strong>Ofgem </strong>respond - <em>&#8220;<span>On baseline cyber resilience requirements, Ofgem will lead further development of detailed proposals, working with </span>DESNZ<span> and </span>NCSC<span>. We intend for these requirements to establish a consistent baseline level of cyber resilience across Ofgem licensees, while avoiding duplication and/or misalignment with any existing cyber security obligations.&#8221;</span></em></p></li><li><p><a href="https://www.gov.uk/government/news/guidance-for-charities-affected-by-the-beacon-cyber-security-incident">Guidance for charities affected by the Beacon cyber security incident</a> - <strong>Charities Commission</strong> guides - <em>&#8220;<span>A number of affected charities have submitted serious incident reports to the Commission and we encourage trustees to continue to follow our </span><a href="https://www.gov.uk/guidance/how-to-report-a-serious-incident-in-your-charity">guidance on serious incident reporting</a><span>. This requires you to report incidents which results in or risks significant harm, loss or damage to the charity, its beneficiaries, assets, services or reputation.&#8221;</span></em></p></li><li><p><a href="https://cert.pl/en/posts/2026/08/incident-follow-up-report-energy-sector-2025/">Follow-Up Report of the December 2025 Energy Sector Incident</a> - <strong>CERT Poland</strong> publish - <em>&#8220;Based on the analysis of the collected evidence, we identified the device from which the attacker conducted their operations and reconstructed the attack path. To the best of our knowledge, the use of a private APN to gain access to the OT network was the first instance of this attack vector being observed in a real-world cyberattack.&#8221;</em></p></li><li><p><a href="https://www.federalreserve.gov/newsevents/pressreleases/files/bcreg20260716a1.pdf">Statement regarding Coordinated Federal Banking Agency Approach for the Handling of Highly Sensitive Information During Examinations</a> - <strong>Federal Reserve</strong> issues - <em>&#8220;Additionally, the FBAs have committed to notify affected banks of a potential or confirmed material compromise of confidential supervisory information as soon as practicable and within no more than 72 hours, once the agency impacted has a reasonable basis to believe a compromise has occurred and determines the banks affected, subject to applicable legal considerations.&#8221;</em></p></li><li><p><a href="https://www.enisa.europa.eu/news/enisa-scales-up-its-role-in-the-cve-program"><span>ENISA scales up its role in the CVE Program</span></a><span> - </span><strong><span>ENISA</span></strong><span> announces -  </span><em><span>&#8220;ENISA's role within the CVE&#8482; Program continues to grow with the strategic onboarding of key entities in the global vulnerability management ecosystem and the transition of existing CNAs under the ENISA Root. Currently, there are 20 CNAs under ENISA Root, with 12 onboarded directly by ENISA and 8 transferred from MITRE Root to ENISA Root.&#8221;</span></em></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/library/commission-publishes-study-supporting-review-digital-decade-policy-programme"><span>Commission publishes study supporting the Review of the Digital Decade Policy Programme -</span></a><span> </span><strong><span>European Commission</span></strong><span> publishes - </span><em><span>&#8220;Findings showed that current targets do not fully reflect emerging priorities, including cybersecurity, technological sovereignty and resilience. They also suggested that some existing indicators would need updating to reflect technological change and market developments&#8221;</span></em></p></li><li><p><a href="https://cheri-alliance.org/a-new-etsi-standard-could-rewrite-the-memory-safety-debate/">A new ETSI standard could rewrite the memory-safety debate</a> - <strong>CHERI Alliance</strong> outlines - <em>&#8220;<span>Importantly, ETSI TS 104 198 is technology-neutral. The draft discusses a wide range of languages and technologies, including Rust, Java, Erlang, Go, CHERI, MTE, PAC, and formal verification approaches. For the first time, organisations have a common basis for comparing different memory-safety technologies and evaluating their strengths, limitations, and assurance characteristics.&#8221;</span></em></p></li><li><p> <a href="https://www.nytimes.com/2026/08/02/opinion/iran-water-hack-trump.html?unlocked_article_code=1.2VA.8-Q8.wFcyQ3xa1VDf&amp;smid=url-share">Small Towns Shouldn&#8217;t Have to Defend America&#8217;s Water Supply From Iran</a> - <strong>Jen Easterly</strong> opines - <em>&#8220;Cyberattacks will continue, and some will succeed. The task is to ensure that a digital intrusion does not become a public health disaster. In an era of nation-state cyberconflict, the ultimate measure of resilience is brutally simple: When attackers get in, clean water must still come out.&#8221;</em></p></li><li><p><a href="https://therecord.media/cyber-command-plans-silicon-valley-office-to-drive-innovation">Cyber Command plans Silicon Valley office to drive innovation</a> - <strong>The Record</strong> reports - &#8220;<em>It will have its own director, though no one has yet been named for the post, and support the command&#8217;s nascent Cyber Innovation Warfare Center (CIWC), one of three entities created under the recent &#8220;CYBERCOM 2.0&#8221; initiative.&#8221;</em></p></li><li><p><a href="https://www.wired.com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide/">A Security Pro Hacked North Korean Hackers. He Found They&#8217;d Breached Hundreds of Networks Worldwide</a> - <strong>WIRED</strong> reports - <em>&#8220;Since Greece-based cybersecurity researcher Vangelis Stykas gained access to North Korean systems 22 months ago, he says, he has found evidence that 1,640 companies across 57 countries have been impacted by the country&#8217;s hacking operations.&#8221;</em></p></li><li><p>Reporting on/from China</p><ul><li><p><a href="https://files.constantcontact.com/f0eecb46901/f655c442-2d93-45ea-8cab-9d58a3a04052.pdf">The Threat of CCP-Controlled Infrastructure in the U.S. Communications Backbone</a> - <strong>US Congress</strong> publishes - <em>&#8220;PRC telecommunications firms operating in the United States do not act independently. Core routing, provisioning, compliance, and customer visibility functions remain tied to parent and affiliate systems in the PRC, leaving operations within Beijing&#8217;s reach&#8221;</em></p></li><li><p><a href="https://www.reuters.com/world/asia-pacific/chinas-zbtlink-suspends-sales-routers-found-contain-backdoor-2026-08-06/">China&#8217;s Zbtlink suspends sales of routers found to contain backdoor</a> - <strong>Reuters</strong> reports - &#8220;<em>Chinese router maker Zbtlink Electronics said on Thursday it was suspending sales of routers found to contain a backdoor and pulling the &#8203;affected software from its website while it developed updates to address &#8204;the issue. Cybersecurity firm VulnCheck identified a backdoor in at least 20 models of routers made by Shenzhen-based Zbtlink Electronics, as Reuters first reported on Wednesday. Zbtlink said in a statement<span>, opens new tab</span> on its &#8203;website that it was aware of the research, which found the flaw &#8203;could allow access and control of the device and potentially other &#8288;devices on the network.</em>&#8221;</p></li><li><p><a href="https://www.chinatalk.media/p/fccs-adam-chan-on-the-new-robot-rule">FCC&#8217;s Adam Chan on the New Robot Rule</a> - <strong>China Talk</strong> details - <em>&#8221;<span>The FCC did not write the national security determination &#8212; we&#8217;re not the ones who, as a legal matter, chose this. But if you look at the determination, there are two national security risks that are highlighted. One relates to remote access, cybersecurity, surveillance, and the ability to remotely manipulate a device such that it poses threats. You guys have probably seen videos of robots behaving badly, but more seriously, I think the national security threats here are kind of obvious.&#8221;</span></em></p></li><li><p><a href="https://www.nytimes.com/2026/08/02/world/asia/china-surveillance-foreigners-database.html">How China Keeps Tabs on Foreigners</a> - <strong>New York Times</strong> reports - <em>&#8221;The system&#8217;s dashboard said it tracked more than 700 foreign residents living in the city. In total, it had entries for nearly 12,000 people, which included fugitives, people from Hong Kong and Taiwan, as well as more than 300 foreign journalists. Some of them had not been to Zhangjiakou.&#8221;</em></p></li><li><p><a href="https://www.bloomberg.com/news/articles/2026-08-06/china-launches-cybersecurity-review-into-palo-alto-networks">China Launches Cyber Security Review into Palo Alto Networks</a> - <strong>Bloomberg</strong> reports -  <em>&#8220;The Cyberspace Administration of China said in a statement Thursday that the review was necessary to protect critical infrastructure, citing a pair of national security laws. Shares in Palo Alto Networks fell as much as 4.2% before later paring losses in pre-market trading.&#8221;</em></p></li></ul></li><li><p> AI</p><ul><li><p><a href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing">Incident Report: unsanctioned agent behaviour during cyber testing</a> - <strong>AISI</strong> details - &#8220;<em>During a routine cyber evaluation, AISI identified an incident in which AI agents took sustained, unsanctioned action directed at real people and organisations. We are disclosing what we found, what it means, and the actions now underway.&#8221;</em></p></li><li><p><a href="/__u/open.substack.com/pub/ciaranmartin/p/control-ownership-perspective?utm_source=share&amp;utm_medium=android&amp;r=q9u24">Control. Ownership. Perspective.</a> - <strong>Ciaran Martin</strong> opines - <em>&#8220;If we focus our efforts and attention exclusively, or even predominantly, on the eye-catching results of the latest frontier AI testing mishap to the exclusion and detriment of long-standing threats and vulnerabilities, we don&#8217;t stand a chance. Let&#8217;s keep these incidents in perspective.&#8221;</em></p></li><li><p><a href="https://therecord.media/irregular-ai-security-company-incidents">Irregular, firm behind AI hacking incidents, won&#8217;t say if there were more</a> - <strong>The Record</strong> reports -  <em>&#8220;Irregular &#8212; the cybersecurity evaluation firm behind tests in which AI models from Anthropic, OpenAI and Meta compromised real-world computer systems &#8212; has declined to say whether any of its other clients were also affected by the same underlying flaw. Asked directly whether the publicly known companies were the only ones to have experienced the problem, a spokesperson said the company&#8217;s investigation was ongoing and that they could not &#8220;go into further details.&#8221;</em></p></li><li><p><a href="https://www.graphistry.com/blog/botsbench-ai-security-openweight-model-roundup-tldr">Botsbench AI security openweight model roundup TL;DR</a> - <strong>Graphistry</strong> publish  - &#8220;<em>DeepSeek V4 Flash makes for an interesting sweet spot. With regular harnesses, generally only frontier provider models (Sonnet 5, Opus 5, &#8230;) and the open weight GLM 5.2 make it to the 50-60% score range in our blue team investigation eval CyBT-CTF. With V4 Flash at 37%, what it loses in quality, it makes up in price: 1/10th the effective cost of GLM 5.2 once all tasks are performed . If you must do open weight, and do not need the quality of GLM 5.2, it&#8217;s attractive.&#8221;</em></p></li><li><p><a href="https://blog.cryptographyengineering.com/2026/07/29/some-notes-about-anthropics-new-results/">Some thoughts about Anthropic&#8217;s new cryptanalysis results</a> - <strong>Matthew Green </strong>thinks - &#8220;<em>So yes, the AIs are getting pretty good. In short: they are now capable of understanding existing cryptanalysis results, synthesizing them into real new attacks, and even extending them. They can apparently do this without detailed human intervention. This isn&#8217;t yet super-intelligent cryptanalysis. but it&#8217;s pretty damn impressive.&#8221;</em></p></li><li><p><a href="https://www.nist.gov/news-events/news/2026/07/announcing-nists-artificial-intelligence-technology-evaluation-aite">Announcing NIST&#8217;s Artificial Intelligence Technology Evaluation (AITE)</a> - <strong>NIST</strong> announces - <em>&#8220;The Technology Test and Evaluation Division at NIST is launching a new program to provide researchers with a sequestered testbed environment for the evaluation of AI model performance in a variety of meaningful tasks across diverse datasets, modalities, and domains.&#8221;</em></p></li></ul></li><li><p><em>Cyber proliferation</em></p><ul><li><p><a href="https://commsrisk.com/malaysian-regulator-stops-sms-blaster-bypassing-telco-filters/">Malaysian Regulator Stops SMS Blaster Bypassing Telco Filters</a> - <strong>Comms Risk</strong> reports - <em>&#8220;The Malaysian Communications and Multimedia Commission (MCMC) found a 23 year old local man driving a car equipped with an SMS blaster around Johor Bahru, a Malaysian city bordering Singapore, on July 24. The device transmitted a radio signal that impersonated a mobile provider and sent fraudulent messages containing web links directly to nearby phones.&#8221;</em></p></li></ul></li><li><p>Bounty Hunting</p><ul><li><p><a href="https://www.justice.gov/opa/pr/canadian-man-pleads-guilty-hacking-us-cloud-storage-provider-and-extorting-its-customers">Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions </a>- <strong>US Department of Justice</strong> announces - <em>&#8220;Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty today to a widespread computer hacking conspiracy that resulted in the compromise of over 165 victim organizations, the theft of billions of sensitive customer records and the extortion of numerous victims.&#8221;</em></p></li><li><p><a href="https://www.justice.gov/usao-edva/pr/belarusian-leader-international-ransomware-scheme-known-ransom-cartel-sentenced-16"><span>Belarusian leader of international ransomware scheme known as &#8220;Ransom Cartel&#8221; sentenced to 16 years in prison</span></a><span> - </span><strong>US Department of Justice</strong> announces - <em>&#8220;Maksim Silnikau, 40, was the creator and administrator of the Ransom Cartel ransomware strain, created in 2021. Silnikau had been a member of Russian-speaking cybercrime forums since at least 2005 and was a member of the notorious cybercrime website Direct Connection from 2011 to 2016, when the site was shuttered after the arrest of its administrator.&#8221;</em></p></li><li><p><a href="https://www.news1.kr/society/court-prosecution/6251494">Data recovery company CEO sentenced to prison for partnering with hackers to target ransomware victims</a> - <strong>News 1</strong> (Korea) report- <em>&#8220;Mr. A and others obtained the file extension information of infected files in advance from ransomware hackers and registered them in portal search advertisements.&#8221;</em></p></li></ul></li><li><p>Market Incentives</p><ul><li><p><a href="https://www.jdsupra.com/legalnews/who-is-liable-when-an-ai-agent-hacks-a-1081613/">Who Is Liable When an AI Agent Hacks a Third Party?</a> - <strong>Baker Hostetler </strong>opines - <em>&#8220;Companies that deploy autonomous agents should begin preparing for a future in which regulators, prosecutors, relators and plaintiffs&#8217; lawyers evaluate AI systems using the same lens they currently apply to cybersecurity programs.&#8221;</em></p></li></ul></li></ul><p>Reflections this week are around the tension between accepted and contemporary practice.</p><p>Over the last couple of weeks I have had detailed discussions where changes required to products to support cyber defence in the contemporary era were objected to on basis of accepted practice or customer demand.</p><p>As we navigate the next period the ability to challenge accepted, but where the security benefit is not or weekly evidenced or is outweighed by the change, is going to be critical..</p><p>Not getting this via email? Subscribe:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Think someone else would benefit? Share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-9ad?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-9ad?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p><strong>All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.</strong></p><p>Have a lovely Sunday&#8230;</p><p>Ollie</p><h1>Cyber threat intelligence</h1><p>Who is doing what to whom and how allegedly.</p><h2>Reporting on Russia</h2><h3>CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft</h3><p><strong>Microsoft</strong> build on prior reporting on this alleged Russian operation. </p><blockquote><p><span>Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide. Despite some tactic, technique, and procedure (TTP) similarities to the </span><a href="https://www.microsoft.com/en-us/security/blog/2026/04/07/soho-router-compromise-leads-to-dns-hijacking-and-adversary-in-the-middle-attacks/">Forest Blizzard DNS hijacking operation</a><span> that we publicly disclosed in April 2026, we attribute this campaign, which we call CaptiveCrunch, to Storm-2945. As reported by </span><a href="https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/">ReliaQuest</a><span> on July 23, a portion of this activity leverages doppelganger domains mimicking Microsoft online services to conduct follow-on adversary-in-the-middle (AitM) phishing operations that abuse the device code authentication flow in Microsoft Entra ID.</span></p></blockquote><p><a href="https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/">https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/</a></p><h2>Reporting on China</h2><h3>OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia</h3><p><strong>Saurabh Sharma</strong> details this alleged Chinese capability. Noteworthy for the use of environment keying on the payloads.</p><blockquote><p>We have been tracking two new backdoors, <strong>OctLurk</strong> and <strong>SilkLurk</strong>, observed in attacks against government organizations primarily in Central Asia since January&#8239;2025. Identified victims are located in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic. These organizations operate across several sectors, including healthcare, research, government offices, ministries of foreign affairs, logistics, law&#8209;enforcement agencies, urban planning and facilities management, and public educational establishments.</p><p>The backdoor loaders are customized for each victim and use information from the victim&#8217;s machine to decrypt the payload.</p></blockquote><p><a href="https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/">https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/</a></p><h3>Targeted Attack on Government Entities in the Middle East</h3><p><strong>Sudeep Singh</strong> and <strong>Roy Tay</strong> provide some over lap reporting on alleged Chinese capability which is noteworthy for its relative complexity.</p><blockquote><ul><li><p><em>BINDCLOAK</em><span> is a previously undocumented and new 64-bit modular Windows backdoor written in C++ that was deployed on victims&#8217; machines during post-compromise activity.</span></p></li><li><p><span>BINDCLOAK is decrypted and reflectively loaded by MIXEDKEY in a multi-stage attack chain targeting government entities in the Middle East.</span></p></li><li><p><span>A complex message routing mechanism is used by BINDCLOAK to manage the C2 communication channel with the C2 server.</span></p></li><li><p><span>BINDCLOAK implements endpoint detection and response (EDR) evasion techniques to prevent detection of API calls from unbacked executable memory regions.</span></p></li></ul><p>&#8230;</p><p>As detailed later in our threat attribution section, key code similarities between BINDCLOAK and OctLurk as well as shared command-and-control (C2) infrastructure directly connect the threat actor behind OctLurk to the campaign we describe in this two-part blog series.</p></blockquote><p><a href="https://www.zscaler.com/blogs/security-research/targeted-attack-government-entities-middle-east-part-2">https://www.zscaler.com/blogs/security-research/targeted-attack-government-entities-middle-east-part-2</a></p><h3>Tracing SNOWLIGHT: A China-Nexus Campaign Against Government Infrastructure</h3><p><strong>SOC Radar</strong> detail this alleged Chinese operation showing a strong apparent focus on Government entities. The leveraging of various n-day vulnerabilities is of note.</p><blockquote><ul><li><p>Attribution to China-Nexus Actors: The core delivery mechanisms have been definitively linked to the SNOWLIGHT malware family. Tracked by the Google Threat Intelligence Group since 2024, identified loaders are heavily associated with China-nexus access brokers UNC5174 and UNC6586.</p></li><li><p>Cracked Chinese Reimplementation of Cobalt Strike C2 Infrastructure: Command and control (C2) infrastructure is managed via &#8220;<a href="https://www.gm7.org/archives/78480">GoCobaltStrike</a>,&#8221; a specialized Chinese-language reimplementation of Cobalt Strike authored by the handle &#8220;&#26143;&#33853;&#8221;, featuring cracked license constraints.</p></li><li><p>Government Sector Prioritization: More than 85% of mapped reconnaissance listings target national infrastructure, resolving to second-level government domains (.gov.*, .go.id) across Taiwan, Colombia, China, Brazil, Indonesia, Nigeria, the Philippines, and over 90 other geographical jurisdictions.</p></li><li><p>High-Impact Endpoint Takeovers: Out of an expansive footprint exceeding 9,990 hostnames across 104 country-code TLDs (top-level domain), the threat actors successfully exploited 9 distinct CVEs to breach 107 endpoints. This includes critical administrative compromises: 16 root-level cPanel/WHM takeovers (CVE-2026-41940) and 1 Domain Admin level compromise via ProxyShell.</p></li><li><p>Reverse Tunnel Traffic Obfuscation: Operators effectively masked their network trail by deploying Neo-reGeorg <a href="https://socradar.io/glossary/web-shell/">web shell</a>s over pre-existing JSP shell implants, using third-party compromised systems as reverse tunnels to proxy further malicious actions.</p></li><li><p>Opportunistic &#8220;Spray-and-Check&#8221; Tactical Model: The campaign leverages automated scanning rather than bespoke targeting. Roughly 1 out of every 90 scanned targets resulted in a <a href="https://socradar.io/glossary/remote-code-execution-rce/">Remote Code Execution (RCE)</a> oracle hit, credential theft, or shell validation.</p></li></ul></blockquote><p><a href="https://socradar.io/blog/snowlight-government-chinese-campaign/">https://socradar.io/blog/snowlight-government-chinese-campaign/</a></p><h3>ENDLESSDOORS Is Phoning Home. Pick Up</h3><p><strong>Jacob Baines</strong> details these Chinese routers with apparent backdoors.</p><blockquote><p>There is no handshake, no key exchange, no negotiation. When the implant reaches a server, it sends a fixed 39-byte hello: a 33-byte class label padded with nulls, then its LAN MAC address. That&#8217;s the whole registration. There is no client or server verification.</p><p>After that, anything the server sends is handed to popen() and executed as uid 0. There is no allow-list and no sandbox. One reserved string, rctlbash, tells the implant to open a second connection to port 7001, allocate a pseudo-terminal, spawn /bin/sh, and bridge it. That is a live interactive root shell.</p></blockquote><p><a href="https://www.vulncheck.com/blog/zbt-endlessdoors">https://www.vulncheck.com/blog/zbt-endlessdoors</a></p><h2>Reporting on North Korea</h2><h3>Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers</h3><p><strong>US Department of State</strong> puts out this alert along with the United Kingdom and others.</p><blockquote><ul><li><p>While many North Korean IT workers reside in North Korea, China, and Russia, as well as Southeast Asian and African countries, they may conceal the fact that they are working from abroad using third-party proxies, VPNs, remote desktop software, and similar tools.</p></li><li><p>North Korean IT workers are known to use third-party proxies as facilitators overseas, such as in the United States, to run &#8220;laptop farms&#8221; which receive company-provided laptop computers for North Korean IT workers to remotely access, obfuscating their true location.</p></li></ul></blockquote><p><a href="https://www.state.gov/releases/office-of-the-spokesperson/2026/07/alert-to-countries-companies-and-other-entities-regarding-north-korean-it-workers/">https://www.state.gov/releases/office-of-the-spokesperson/2026/07/alert-to-countries-companies-and-other-entities-regarding-north-korean-it-workers/</a></p><h3>NullReceiver&#8217;s Blank Crypto Transfers Solves the Challenges of EtherHiding</h3><p><strong>Paul McCarty</strong> details an alleged North Korean operation which uses a novel command and control technique.</p><blockquote><p><span>We just identified a new blockchain-based command-and-control technique hiding inside two trojanized npm packages, </span><code>bianira-ui</code><span> and </span><code>fluid-type-ui</code><span>. Both are DPRK-linked clones of legitimate Tailwind CSS plugins, and both use the same trick to find their command server: they read it out of the </span><em>destination address</em><span> of a completely blank cryptocurrency transfer.</span></p></blockquote><p><a href="https://opensourcemalware.com/blog/nullreceiver-dprk-c2-technique">https://opensourcemalware.com/blog/nullreceiver-dprk-c2-technique</a></p><h2>Reporting on Iran</h2><p><em>Nothing overly of note this week</em></p><h2>Reporting on Other Actors</h2><h3>UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments</h3><p><strong>Tyler McLellan</strong> and <strong>Austin Larsen</strong> detail the continued use of vishing by this criminal group which will be of note to defence teams.</p><blockquote><p><span>UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their personal mobile devices. These calls lure victims to spoofed login portals where Adversary-in-the-Middle (AiTM) infrastructure intercepts credentials and multi-factor authentication (MFA) tokens. Once session persistence is established, the actors deploy automated scripts for data exfiltration from enterprise cloud environments, including Microsoft 365 and Okta.</span></p><p><span>In this update to our May 2026 blog, we detail the infrastructure linkages connecting these extortion brands. We also examine the evolution of UNC6671&#8217;s targeting including recent activity focused on financial services, private equity, and professional services, and provide hardening guidance to help organizations protect themselves from this threat.</span></p></blockquote><p><a href="https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments">https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments</a></p><h3>How legitimate cloud platforms enable phishers to bypass MFA</h3><p><strong>Olga Altukhova</strong> details a set of techniques employed by range of threat actors.</p><blockquote><p>Troughout 2025 and 2026, we have observed phishing operators steadily migrate toward platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS.</p><p>Threat actors select platform-as-a-service (PaaS) offerings and distributed cloud environments to host phishing sites for much the same reasons legitimate software developers do:</p><ul><li><p>Inherent trust and reputation. Phishing pages hosted on reputable platforms appear trustworthy, reducing suspicion among potential victims.</p></li><li><p>Most platforms offer generous free-tier developer plans. The onboarding process takes minutes and rarely requires Know Your Customer (KYC) identity verification. This enables a single operator to create hundreds of malicious accounts.</p></li><li><p>Evasion and anonymity. Attackers leverage native security features to obscure their true origin server IP address behind a CDN, which complicates detection for security vendors.</p></li></ul><p>Additionally, these platforms allocate shared subdomains hosting millions of legitimate projects and websites.</p></blockquote><p><a href="https://securelist.com/cloud-platforms-in-phishing/120832/">https://securelist.com/cloud-platforms-in-phishing/120832/</a></p><h3><span>Analysis of APT-C-24 (Rattlesnake) group&#8217;s application file phishing attack campaign</span></h3><p><strong><span>360 Threat Intelligence Centre</span></strong><span> details some tradecraft by this alleged threat actor.</span></p><blockquote><p><span>The organization distributes decoy PDF documents via phishing emails. When users click to open the file, they are tricked into downloading an application file, which is the ClickOnce application deployment configuration file. Its main function is to remotely install the Baijiahei component.</span></p><p><span>In subsequent sample association, an attack activity was captured that downloaded subsequent malicious components through macro code. Its core payload was written in Rust, which has strong anti-analysis capabilities, and its overall functionality is consistent with the core payload of this analysis.</span></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Nban!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69fc092b-a481-4f70-92a8-6975e3f24cc9_1004x348.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Nban!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69fc092b-a481-4f70-92a8-6975e3f24cc9_1004x348.webp 424w, /__u/substackcdn.com/image/fetch/$s_!Nban!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69fc092b-a481-4f70-92a8-6975e3f24cc9_1004x348.webp 848w, /__u/substackcdn.com/image/fetch/$s_!Nban!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69fc092b-a481-4f70-92a8-6975e3f24cc9_1004x348.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!Nban!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69fc092b-a481-4f70-92a8-6975e3f24cc9_1004x348.webp 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Nban!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69fc092b-a481-4f70-92a8-6975e3f24cc9_1004x348.webp" width="1004" height="348" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/69fc092b-a481-4f70-92a8-6975e3f24cc9_1004x348.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:348,&quot;width&quot;:1004,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!Nban!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69fc092b-a481-4f70-92a8-6975e3f24cc9_1004x348.webp 424w, /__u/substackcdn.com/image/fetch/$s_!Nban!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69fc092b-a481-4f70-92a8-6975e3f24cc9_1004x348.webp 848w, /__u/substackcdn.com/image/fetch/$s_!Nban!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69fc092b-a481-4f70-92a8-6975e3f24cc9_1004x348.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!Nban!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69fc092b-a481-4f70-92a8-6975e3f24cc9_1004x348.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://mp.weixin.qq.com/s/PALBLusD4umh_52gy2wVAg">https://mp.weixin.qq.com/s/PALBLusD4umh_52gy2wVAg</a></p><h3>Software Supply Chain Incursions</h3><p><span>A reminder we issued guidance a number of weeks ago in </span><a href="https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies">Software supply chain attacks: check your dependencies</a><span> for software developers</span></p><ul><li><p><a href="https://www.stepsecurity.io/blog/chaindrop-npm-worm">ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2</a></p></li><li><p><a href="https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain">Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack</a></p></li><li><p><a href="https://safedep.io/keyv-npm-supply-chain-compromise/">npm Worm Poisons 400+ Packages Across Nine Organisations</a></p></li><li><p><a href="https://socket.dev/blog/npm-rat-targets-alibaba">Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers</a></p></li><li><p><a href="https://opensourcemalware.com/blog/russian-ai-slopsquatting-npm-campaign">Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages</a></p></li></ul><h1>Discovery</h1><p>How we find and understand the latent compromises within our environments.</p><h2>When Attackers Hijack Your Inbox: Detecting Mailbox Forwarding Rules with Microsoft Defender XDR</h2><p><strong>Bi Yue Xu</strong> details practically how it is done.</p><blockquote><p>Fortunately, these attacker activities are not invisible. Microsoft Purview Audit captures mailbox operations, including the creation of forwarding rules, and these audit events are also available in Microsoft Defender XDR Advanced Hunting. This allows security teams to proactively hunt for suspicious mailbox activities and create custom detection rules that can automatically alert on malicious behavior.</p></blockquote><p><a href="https://detect.fyi/when-attackers-hijack-your-inbox-detecting-mailbox-forwarding-rules-with-microsoft-defender-xdr-56a71567c6f2">https://detect.fyi/when-attackers-hijack-your-inbox-detecting-mailbox-forwarding-rules-with-microsoft-defender-xdr-56a71567c6f2</a></p><h2>WinGuard</h2><p><strong>Poly0n</strong> releases this experimental EDR for Windows.</p><blockquote><p>A User-Mode Windows Threat Detection Tool Inspired by EDR Techniques, To Help Monitor And Log Any Suspicious Activity On Your PC.</p></blockquote><p><a href="https://github.com/Poly0n/WinGuard">https://github.com/Poly0n/WinGuard</a></p><h1>Defence</h1><p>How we proactively defend our environments.</p><h2><span>ENISA Secure by Design and Default Playbook</span></h2><p><strong>ENISA</strong> publishes this guide for subject matter experts.</p><blockquote><p>A Practical Guide to Secure by Design and Default Principles for SMEs</p><p>Modern products with digital elements are increasingly expected to be secure by design and secure by default. However, many organisations, in particular small and medium-sized enterprises, may face distinct challenges in applying these concepts consistently, requiring targeted solutions.</p><p>This report puts forward a set of principles and tangible guidance on the application of secure by design and default requirements throughout the life cycle of a product. In particular, the report focuses on explaining these principles in clear, repeatable actions that can be applied to existing engineering, product and release processes.</p></blockquote><p><a href="https://www.enisa.europa.eu/publications/enisa-secure-by-design-and-default-playbook">https://www.enisa.europa.eu/publications/enisa-secure-by-design-and-default-playbook</a></p><h2>ADR: Agentic AI Detection and Response</h2><p><strong>Uber</strong> releases their in production framework for agentic defence.</p><blockquote><p>ADR (Agentic AI Detection and Response) is an enterprise security system for AI agents. It helps organizations secure employee-facing agents such as Cursor, Claude Code, and Codex, as well as customer-facing agents such as AI support agents.</p><p>ADR is deployed in production at Uber, and the accompanying paper was accepted to MLSys 2026: <a href="https://github.com/uber/ADR/blob/main/docs/adr-paper.pdf">Paper PDF</a> &#183; <a href="https://github.com/uber/ADR/blob/main/docs/adr-mlsys-2026-slides.pdf">Slides PDF</a></p></blockquote><p><a href="https://github.com/uber/ADR">https://github.com/uber/ADR</a></p><h2>Scanning 7.6 Petabytes of HuggingFace Training Data for Secrets</h2><p><strong>Truffle</strong> show that you don&#8217;t need zero-days to secure access if you don&#8217;t care where you go..</p><blockquote><p>tl;dr We scanned every public dataset on Hugging Face, which is where most open AI training data lives. That came to 7.6 petabytes across 187 million files, the largest secret scan of AI training data we know of. We found 221,303 live, unique credentials sitting in 6,003 datasets.</p><p>One of the highest-impact secrets we found had access to 393 GB of PII covering what we estimate to be roughly 3.7% of the global population. More on this will come in a dedicated follow-up. The rest of the scan shows how broad the problem is: cloud storage buckets, hosted databases, cloud-admin keys, and tokens that can push code into software a lot of people install.</p></blockquote><p><a href="https://trufflesecurity.com/blog/scanning-7-6-petabytes-of-ai-training-data-for-secrets">https://trufflesecurity.com/blog/scanning-7-6-petabytes-of-ai-training-data-for-secrets</a></p><h1>Incident Writeups &amp; Disclosures</h1><p>How they got in and what they did.</p><h2>Tailscale didn&#8217;t stop the Hugging Face intrusion</h2><p><strong>Tailscale</strong> provide their perspective.</p><blockquote><p>An AI agent escaped its sandbox, entered Hugging Face&#8217;s infrastructure, and used a stolen Tailscale credential to enroll 181 nodes onto their tailnet. No Tailscale vulnerability was found or exploited&#8212;we should have been able to prevent it anyway.</p></blockquote><p><a href="https://tailscale.com/blog/hugging-face-intrusion">https://tailscale.com/blog/hugging-face-intrusion</a></p><h1>Vulnerability</h1><p>Our attack surface.</p><h2>OT Security Analysis: Exposed Devices Attacked in US Water Systems</h2><p><strong>Sai Molige</strong> details their observed attack surface.</p><blockquote><p>Querying the Shodan search engine on August 3, 2026 returns 4,407 devices exposing port 44818. The vast majority (65%) are located in the U.S., followed by Canada (12%) and Spain (3%).</p><p>More than half of those devices are in the networks of large mobile network carriers, showing that they are often connected via cellular modems &#8211; as described in the FBI/EPA&#8217;s advisory. If we take only the U.S.-based devices, we see that over 70% of those are in mobile networks.</p><p>Focusing on the specific product lines mentioned in the FBI/EPA advisory, we see that MicroLogix 1400 is much more common than MicroLogix 1100, with 50% of the exposed assets being in the former family and only 8% in the latter. Other relevant product lines seen exposed include CompactLogix 1769 (22%) and ControlLogix 5590 (8%).</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!VtgU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cdb9ce0-c0bb-45d9-b503-57f3ed9b7c76.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!VtgU!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cdb9ce0-c0bb-45d9-b503-57f3ed9b7c76.svg 424w, /__u/substackcdn.com/image/fetch/$s_!VtgU!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cdb9ce0-c0bb-45d9-b503-57f3ed9b7c76.svg 848w, /__u/substackcdn.com/image/fetch/$s_!VtgU!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cdb9ce0-c0bb-45d9-b503-57f3ed9b7c76.svg 1272w, /__u/substackcdn.com/image/fetch/$s_!VtgU!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cdb9ce0-c0bb-45d9-b503-57f3ed9b7c76.svg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!VtgU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cdb9ce0-c0bb-45d9-b503-57f3ed9b7c76.svg" width="1456" height="950" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7cdb9ce0-c0bb-45d9-b503-57f3ed9b7c76.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:950,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!VtgU!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cdb9ce0-c0bb-45d9-b503-57f3ed9b7c76.svg 424w, /__u/substackcdn.com/image/fetch/$s_!VtgU!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cdb9ce0-c0bb-45d9-b503-57f3ed9b7c76.svg 848w, /__u/substackcdn.com/image/fetch/$s_!VtgU!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cdb9ce0-c0bb-45d9-b503-57f3ed9b7c76.svg 1272w, /__u/substackcdn.com/image/fetch/$s_!VtgU!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cdb9ce0-c0bb-45d9-b503-57f3ed9b7c76.svg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.forescout.com/blog/ot-security-analysis-exposed-devices-attacked-in-us-water-systems/">https://www.forescout.com/blog/ot-security-analysis-exposed-devices-attacked-in-us-water-systems/</a></p><h2>Technical Deep Dive into the Entropy Issue</h2><p><strong>Coin Kite</strong> remind the world by testing and verification, especially in security critical functions, are an imperative.</p><blockquote><p>There was no intentional weak-entropy fallback. It is important to be precise about what happened.</p><p>Yasmarang was MicroPython&#8217;s built-in general-purpose PRNG, introduced upstream in May 2018. It did not become part of COLDCARD&#8217;s seed-generation path until the libNgU migration in March 2021. Most language runtimes include a non-cryptographic PRNG for general-purpose tasks. Its presence was not itself unusual.</p><p>COLDCARD was designed to rely exclusively on its hardware TRNG for seed generation, with no software fallback. Setting <code>MICROPY_HW_ENABLE_RNG=0</code> was intended to disable the software path. A build and link integration error meant that setting did not have the intended effect, and libNgU&#8217;s <code>rng_get()</code> symbol resolved to MicroPython&#8217;s default Yasmarang implementation instead.</p><p>The hardware TRNG did not fail and trigger a weaker fallback at runtime. This was inherited platform behavior activated by a link-time error, not an intentional seed-generation design decision or shortcut. This distinction does not change the risk or migration guidance for affected seeds.</p></blockquote><p><a href="https://blog.coinkite.com/entropy-technical-backgrounder/">https://blog.coinkite.com/entropy-technical-backgrounder/</a></p><h2>Apple Screen Sharing Pre-Auth RCE</h2><p>AI generated details of the Apple screens sharing vulnerability..</p><blockquote><p>Apple&#8217;s Screen Sharing daemon (<code>screensharingd</code>) contains a pre-authentication vulnerability in its SRP (Secure Remote Password) frame-length validation. When the daemon receives an SRP frame whose big-endian 32-bit length has any bit at position &#8805; 15 set (i.e., length &#8805; 32768), the &#8220;frame too large&#8221; error path returns the stale success status from the preceding 4-byte read instead of an error code. The caller interprets this zero return as &#8220;authentication complete&#8221; and enters the post-auth message loop without any key exchange, cipher negotiation, or session crypto.</p><p>The remaining bytes in the network buffer are then consumed as ordinary RFB messages &#8212; including Apple&#8217;s proprietary file-copy protocol (message type <code>0x22</code>), which runs as root and provides arbitrary file read and write. By injecting a reverse shell payload and a root crontab in a single pipelined connection, an unauthenticated attacker achieves remote code execution as root within 60 seconds.</p><p>No user interaction is required. The only prerequisite for the auth bypass and the file primitives is that Screen Sharing is enabled on the target (System Settings &#8594; General &#8594; Sharing &#8594; Screen Sharing). No password, no valid username, and no knowledge of the target configuration is needed.</p></blockquote><p><a href="https://warez.sl0p.foo/apple-screensharing-rce/">https://warez.sl0p.foo/apple-screensharing-rce/</a></p><h2>From Square Root to /root: Escalating Privileges in Azure Containers with Python in Excel</h2><p><strong>Ron Ben Yizhak</strong> details that complexity still up ends.</p><blockquote><p><span>a symbolic link flaw that let him escalate privileges from an unprivileged user to root. That access let him recover an internal configuration file exposing the architecture and hostnames behind this feature. Later, he discovered Microsoft&#8217;s container images can be pulled anonymously and that there is even an undocumented AI agent framework integrated into this environment. Separately, he found a way to bypass Excel&#8217;s Trusted Records security control (</span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45459">CVE-2026-45459</a><span>) by abusing a Python result object to force a victim&#8217;s machine to silently fetch a URL and automatically upload the data to the supposedly network-isolated container.</span></p></blockquote><p><a href="https://www.safebreach.com/blog/python-in-excel-vulnerability-root-escalation-cve-2026-45459/">https://www.safebreach.com/blog/python-in-excel-vulnerability-root-escalation-cve-2026-45459/</a></p><h2>TONTOU: On the Exploitability of Time-of-Neutralization to Time-of-Use Windows</h2><p><strong>Dani&#235;l Trujillo</strong> and <strong>Mengjia Yan</strong> introduce a new exploitation primative.</p><blockquote><p>To re-direct control-flow, we introduce INTERRUPT INJECTION, a primitive that exploits post-neutralization windows by leveraging the fact that interrupts can occur at nearly any point in time. Using this primitive, we demonstrate that an attacker can trigger mispredictions during kernel execution on recent AMD and Intel CPUs. To prove its practicality, we build an end-to-end exploit using INTERRUPT INJECTION that leaks arbitrary kernel memory on AMD Zen 2 at a rate of 5.47 bytes/s, despite the latest neutralization techniques.</p></blockquote><p><a href="https://people.csail.mit.edu/mengjia/data/2026.USENIX.TONTOU.pdf">https://people.csail.mit.edu/mengjia/data/2026.USENIX.TONTOU.pdf</a></p><h2>Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis</h2><p><strong>Ziyu Lin</strong><span>, </span><strong>Ziting Wang</strong><span>, </span><strong>Xinfeng Li</strong><span>, </span><strong>Wei Dong</strong><span> and </span><strong>XiaoFeng Wang</strong> show a potential application of AI to cyber defence.</p><blockquote><p>Cellular core networks (CNs) are critical infrastructure, yet their internal security model has historically relied on physical isolation: interfaces between core components often operate within an assumed trust zone. As CNs transition to cloud-native deployments, this assumption weakens, expanding the attack surface and enabling external adversaries to reach previously internal interfaces. From a root-cause analysis of security flaws reported in GitHub issues for opensource CN implementations, we found a recurring pattern of blind trust among CN components. Components may omit syntactic validation, fail to enforce semantic invariants, or allocate resources without checking availability. Once internal interfaces become reachable, these weaknesses can lead to severe impacts such as denial of service and session hijacking. We call these vulnerabilities implicit trust errors (iTrue). To detect iTrues and understand their security impacts, we designed iFinder, an LLM-driven multi-agent system that summarizes known flaws, distills them into detection patterns, and applies them to discover new iTrues in CN implementations. To suppress hallucinations produced by large language models (LLMs), we built an innovative strategy that crosschecks both 3GPP specifications and CN code to capture existing protection missed by the agents. Further, we developed a technique that uses LLMs to generate proof-of-concept (PoC) exploits for potential iTrues and iteratively refine the PoCs by automatically executing them against CN implementations and analyzing results. Running iFinder on seven prominent open-source CN implementations, we discovered 84 previously unknown vulnerabilities. Among them, 83 have already been confirmed and 81 have been assigned CVEs. Importantly, a session-hijacking flaw has been confirmed on real-world commercial 5G core networks.</p></blockquote><p><a href="https://arxiv.org/abs/2607.10315">https://arxiv.org/abs/2607.10315</a></p><h1>Offense</h1><p>Attack capability, techniques and trade-craft. </p><h2>Bypassing Windows application [allow]listing</h2><p><strong>Tim Baker</strong> highlights de-serisalation vulnerabilities go beyond the web..</p><blockquote><p>This post describes how we discovered and reported to Microsoft an insecure deserialisation vulnerability in one of the binaries in the Windows Assessment and Deployment Kit (ADK), and how that can be used to bypass Application Control (native Windows application whitelisting).</p></blockquote><p><a href="https://www.dotsec.com/insecure-deserialisation-app-control-bypass/">https://www.dotsec.com/insecure-deserialisation-app-control-bypass/</a></p><h2>Abusing Extended Attributes to Bypass Application Control For Business</h2><p><strong>Ian</strong> details how this technique is executed which defence teams will want to develop tradecraft to detect..</p><blockquote><ul><li><p>This post shows a practical bypass of Application Control for Business (formerly Windows Defender Application Control (WDAC)) by abusing NTFS Kernel Extended Attributes (Kernel EAs), which are treated as trustworthy</p></li><li><p>Core idea: copy the EA set from a known-allowed executable (Chrome in this example), apply equivalent attributes to a target binary, then perform an offline modification so the attributes are stored as <em>$Kernel.*</em> (rather than user-mode <em>#Kernel.*</em>) before the volume is mounted in Windows.</p></li><li><p>Impact: the target executable can be allowed to run in environments that rely on these cached origin/claims.</p></li><li><p>Prerequisites / attacker position: either kernel-mode capability (e.g., a driver) to set Kernel EAs, or (b) offline access to the NTFS volume (e.g., removable media, secondary disk, or disk accessed from another OS) to edit on-disk EA structures.</p></li></ul></blockquote><p><a href="https://shells.systems/abusing-extended-attributes-to-bypass-application-control-for-business/">https://shells.systems/abusing-extended-attributes-to-bypass-application-control-for-business/</a></p><h2>Inside the Falcon How CrowdStrike Catches You</h2><p><strong>DbgMan</strong> provides a breakdown in functionality which will likely inform the adversary..</p><blockquote><p>A full reverse-engineering teardown of the CrowdStrike Falcon sensor: the six kernel callback sources, the WFP network engine, the file-system minifilter, the cspcm4 broker, the user-mode service (DNS / AMSI / browser / Identity Protection), and the cloud-loaded detection engine &#8212; plus every structural blind spot. How Falcon sees you, and where the seams are.</p></blockquote><p><a href="https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/">https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/</a></p><h2>Pass the Passkey: A Novel Attack Surface in Passwordless Authentication</h2><p><strong>Arie Olshtein</strong> presents this research which is included here to highlight this line. This is not a vulnerability with passkeys..</p><blockquote><p>All presented attacks rely on malware already existing on the victim&#8217;s device during the initial stage.</p></blockquote><p><a href="https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/">https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/</a></p><h2>Borrowing Windows Hello keys for authentication and persistence</h2><p><strong>Dirk-jan Mollema </strong>details an as by design aspect of Windows Hello along with providing detection tradecraft. </p><blockquote><p>For this blog I want to focus on a technique that was left as-is since it is more or less a consequence of how WHFB works: the ability to perform single-sign on with the backing cryptographic keys from a user session, without needing the PIN or other information/user presence. We will not just look at how we can utilize this to request Primary Refresh Tokens (PRTs), but also how we can use this to perform device registration by using the WHFB key as a FIDO key/passkey.</p></blockquote><p><a href="https://dirkjanm.io/borrowing-windows-hello-keys/">https://dirkjanm.io/borrowing-windows-hello-keys/</a></p><h2>Identity Crisis: Novel Vulnerabilities Leading to Kerberos Downgrade, DoS, and Full Domain Takeover</h2><p><strong>Shai Laron</strong> walks through the application of two now patched vulnerabilities.. </p><blockquote><p><span>This article details my research into these questions, which led to the discovery of two new Active Directory privilege escalation vulnerabilities: </span><strong>KerberLoss (CVE-2026-25177) </strong><span>and </span><strong>ResetNightmare (CVE-2026-27912)</strong><span>. Each vulnerability takes a unique approach to causing identity confusion on DCs, resulting in various impacts. The second (and more severe vulnerability) enables a low-privileged user to instantly gain Domain Admin privileges.</span></p></blockquote><p><a href="https://www.semperis.com/blog/identity-crisis-novel-vulnerabilities-leading-to-kerberos-downgrade-dos-and-full-domain-takeover/">https://www.semperis.com/blog/identity-crisis-novel-vulnerabilities-leading-to-kerberos-downgrade-dos-and-full-domain-takeover/</a></p><h2>ANIMO</h2><p><strong>David Garcia</strong> releases this capability which defence teams will want to develop detections for,</p><blockquote><p><span>ANIMO is a comprehensive Azure AD / Entra ID assessment platform that combines </span>PowerShell-based session management<span>, </span>Azure CLI parity<span>, and </span>native Graph / ARM API integration<span>. It gives red teamers a single interface to manage multiple Azure sessions, capture and manipulate tokens, enumerate cloud resources, and execute post-exploitation techniques during authorized engagements with WhoAmI-driven autofill so Post-Exploit modules pre-populate from what you already know about the identity.</span></p></blockquote><p><a href="https://github.com/dmcxblue/ANIMO">https://github.com/dmcxblue/ANIMO</a></p><h1>Exploitation</h1><p>What is being exploited..</p><h2>N-Able</h2><p><strong>N-Able</strong> disclose and on going saga..</p><blockquote><p>As our investigation into the recent N-central security vulnerability continues, we are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques.</p><p>This is not a duplicate of our previous communication. 2026.3.1.10 Hotfix 2 is required, even if you already applied the earlier hotfix. Hotfix 2 supersedes Hotfix 1 with additional hardening measures to further protect you and your customers.</p></blockquote><p><a href="https://uptime.n-able.com/event/201522/">https://uptime.n-able.com/event/201522/</a></p><h1>Tooling and Techniques</h1><p>Low level tooling and techniques for attack and defence researchers</p><h2>GetRuntimeAttestationReport</h2><p><strong>Microsoft</strong> released this in January which is now used by <a href="https://www.riotgames.com/en/news/vanguard-on-demand">Riot Games</a> in their anti-cheat system.</p><blockquote><p>The GetRuntimeAttestationReport API allows a VTL0 user-mode process to retrieve a signed runtime attestation report from the Secure Kernel. This report provides a list of loaded drivers and code integrity information, which is essential for validating system integrity and enforcing anti-cheat policies in gaming and security-sensitive applications.</p></blockquote><p><a href="https://learn.microsoft.com/en-us/windows/win32/api/sysinfoapi/nf-sysinfoapi-getruntimeattestationreport">https://learn.microsoft.com/en-us/windows/win32/api/sysinfoapi/nf-sysinfoapi-getruntimeattestationreport</a></p><h2>omp-re</h2><p><strong>Lance James</strong> releases this work aid..</p><blockquote><p><code>omp-re</code><span> is a reverse-engineering plugin for </span><a href="https://omp.sh/">omp</a><span> (oh-my-pi): it wraps </span><a href="https://rada.re/">radare2</a><span> behind 22 agent tools, a </span><code>/re</code><span> slash command, five overlay panels, a content-addressed evidence store, an HMAC-signable audit log, and a report writer that refuses to write a claim with no supporting evidence. The agent gathers facts through the tools; the evidence store remembers exactly what it observed; the report writer will not let it claim more than that.</span></p></blockquote><p><a href="https://github.com/lancejames221b/omp-re">https://github.com/lancejames221b/omp-re</a></p><h2>Screenlogger</h2><p><strong>Rad Kawar</strong> releases this will be of use to some including some third party engineer use cases I suspect.</p><blockquote><p>Screenlogger captures at an interval you choose, recognizes visible text on device, and lets you return to a moment through Library search or Timeline navigation. Capture and search stay on your Mac.</p></blockquote><p><a href="https://github.com/radkawar/screenlogger">https://github.com/radkawar/screenlogger</a></p><h2>Papaya</h2><p><strong>ioa</strong> releases this experiment which shows some interesting promise.</p><blockquote><p>Papaya is a POC of detecting software debuggers through machine learning.</p><p><span>This POC currently only shows 2 vectors which could be used to detect software debuggers in such a way. Every trained sample was performed and generated for </span><a href="https://x64dbg.com/">x64-dbg</a><span>.</span></p></blockquote><p><a href="https://github.com/ioallocate/Papaya">https://github.com/ioallocate/Papaya</a></p><h2>Binary Diff</h2><p><strong>Matteyeux</strong> releases this work aid..</p><blockquote><p>A Binary Ninja plugin for side-by-side binary diffing, powered by <a href="https://github.com/quarkslab/qbindiff">QBinDiff</a>.</p><p>Drop a second binary onto the diff view and the plugin loads it, analyzes it, matches its functions against the current binary, and shows the differences at five levels: control flow graph, assembly, LLIL, MLIL and HLIL.</p></blockquote><p><a href="https://github.com/matteyeux/binja-diff">https://github.com/matteyeux/binja-diff</a></p><h2>Knuckledragger</h2><p><strong>Philip Zucker</strong> attempts to bring proofs to the people..</p><blockquote><p><span>Knuckledragger (</span><a href="https://github.com/philzook58/knuckledragger">git repo</a><span>) is an attempt at creating a down to earth, highly automated interactive proof assistant in python. The goal is to support applications like software/hardware verification, calculus, equational reasoning, and numerical bounds.</span></p></blockquote><p><a href="https://github.com/philzook58/knuckledragger">https://github.com/philzook58/knuckledragger</a></p><h2>.config</h2><p><strong><span>eversinc33 </span></strong><span>details this nifty technique..</span></p><blockquote><p>Add a sample.exe.config file next to your sample and you can trace e.g. all network requests, including content and headers without hooking or bothering with proxies. Helpful to e.g. quickly inspect c2 traffic:</p><p>&#8230;</p><p>Depending on which APIs the malware uses, this will trace request content before encryption, so you can see HTTPS traffic in cleartext</p></blockquote><p><a href="https://gist.github.com/eversinc33/cd7f3e90643f69748862b87f394f1c16">gist.github.com/eversinc33/cd7f3e90643f69748862b87f394f1c16</a></p><p><a href="https://x.com/eversinc33/status/2086011305128079857?s=20">x.com/eversinc33/status/2086011305128079857?s=20</a></p><h1>Footnotes</h1><p>Some other small (and not so small) bits and bobs which might be of interest.</p><ul><li><p>Annual, quarterly and monthly reports</p><ul><li><p><em>Nothing overly of note this week, but keep an eye on</em> <a href="https://github.com/jacobdjwilson/awesome-annual-security-reports/tree/main/Annual%20Security%20Reports/2026">the Awesome Annual Security Reports 2026 collection</a> and <a href="https://github.com/blackorbird/APT_REPORT">APT report collection</a></p></li></ul></li><li><p><a href="https://openaccess.cms-conferences.org/publications/book/978-1-964867-83-0/article/978-1-964867-83-0_17">A Cognitive Engineering Approach to Capture the Context of Decision Making for Emergency Call Handlers</a></p></li><li><p><a href="https://nkinternet.com/2026/08/01/a-new-silivaccine-north-koreas-antivirus/">A New SiliVaccine: North Korea&#8217;s Antivirus</a></p></li><li><p>Artificial intelligence</p><ul><li><p><span>if you are a big </span><a href="https://arxiv.org/">arxiv.org</a><span> user - out of China there is </span><a href="https://www.alphaxiv.org/">alphaxiv.org</a><span> which is an AI powered incarnation / overlay</span></p></li><li><p>Fundamental</p><ul><li><p><a href="https://arxiv.org/abs/2607.22925">Not All LLM Reasoning is Visible in the Chain-of-Thought</a></p></li><li><p><a href="https://arxiv.org/abs/2607.27230">Multi-Head Attention Residuals</a></p></li><li><p><a href="https://arxiv.org/abs/2602.24281">Memory Caching: RNNs with Growing Memory</a></p></li></ul></li><li><p>Applied non-cyber</p><ul><li><p><a href="https://arxiv.org/abs/2607.27250">Do Context Files Help Coding Agents? A Two-Agent Ablation Study on Real Repositories</a></p></li><li><p><a href="https://arxiv.org/abs/2607.20792">Memoir: Should a Model Write to Its Memory While It Thinks?</a></p></li><li><p><a href="https://arxiv.org/abs/2608.04271">LLM-based Vulnerability Discovery in Business Process Documentation</a></p></li><li><p><a href="https://arxiv.org/abs/2608.05695">DreamGuard: Efficient Runtime Guardrail for <span>LLM</span> Agents via Risk-Aware World Model</a></p></li><li><p><a href="https://arxiv.org/abs/2608.04565">Breadcrumbing Search Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2608.03535">CodeAssay: A Multi-Metric Benchmark with Audited Ground Truth for LLM Code Generation</a></p></li></ul></li><li><p>Applied cyber specific</p><ul><li><p><a href="https://dreadnode.io/research/every-model-cheats-prompt-level-mitigation-of-cheating-on-offensive-cyber-tasks/">Every Model Cheats: Prompt-Level Mitigation of Cheating on Offensive Cyber Tasks</a></p></li><li><p><a href="https://github.com/getprimary/pa-code-audit-demo">Provable Assurance (PA) Code Audit Demo</a></p></li><li><p><a href="https://arxiv.org/abs/2608.05884">The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2608.03009">Tiny Enough to Break In: Agentic Remote Access Trojans Powered by Small Language Models</a></p></li><li><p><a href="https://arxiv.org/abs/2608.02638">Studying, Identifying, and Fixing Hidden Technical Debt in AI-Intensive Cyber-Physical Systems</a></p></li><li><p><a href="https://arxiv.org/abs/2608.05063">Hardware Design and Security in the Era of Chiplets and LLMs</a></p></li><li><p><a href="https://arxiv.org/abs/2608.04907">LLM-Assisted Detection and Repair of Hardware Security Vulnerabilities in Verilog Designs</a></p></li><li><p><a href="https://arxiv.org/abs/2608.04741">LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2608.04317">Trident : How to Break Deep Reinforcement Learning Cyber Defenses (Agentic)</a></p></li><li><p><a href="https://arxiv.org/abs/2608.04255">PriDyG: Privacy-preserving Dynamic Graph Inference with LLM-GNN Collaboration</a></p></li><li><p><a href="https://arxiv.org/abs/2608.03591">DiagChain: A Diagnostic Benchmark for Evaluating LLM Agents on Evidence-Grounded Attack Chain Reconstruction</a></p></li><li><p><a href="https://arxiv.org/abs/2608.03232">MalTotal: Cost-Effective and Language-Agnostic Malicious Code Poisoning Detection for Millions of Repositories</a></p></li><li><p><a href="https://arxiv.org/abs/2608.03134">CLEAR: Causal Context-Based Agentic Reasoning for Vulnerability Detection</a></p></li><li><p><a href="https://arxiv.org/abs/2608.01763">EntailLLM: Verifying LLM-Generated Vulnerability Discovery Paths with Domain Knowledge via Logic Programming</a></p></li><li><p><a href="https://arxiv.org/abs/2608.02995">SparSEEty: Extracting Tokens from Sparsity-Exploiting LLM Serving Systems via Deterministic Side Channels</a></p></li><li><p><a href="https://arxiv.org/abs/2608.02843">MutMem: Cryptographically Authorized Mutation in Persistent Agent Memory</a></p></li></ul></li></ul></li><li><p>Books</p><ul><li><p><a href="https://press.umich.edu/Books/A/A-Century-of-International-Crisis-Behavior2">A Century of International Crisis Behavior</a></p></li><li><p><a href="https://www.elev8resilience.com/news/book-resilience-by-design"><span>Resilience by design: STRATEGIC RISK-PROFILING TECHNIQUES TO REFINE YOUR ORGANISATION&#8217;S CYBERSECURITY AND RESILIENCE STRATEGY</span></a></p></li></ul></li><li><p>Events</p><ul><li><p><em>Nothing overly of note this week</em></p></li></ul></li></ul><p>Video of the week &#8220;<strong>Why Agentic Systems Need Ontologies&#8221;</strong></p><div id="youtube2-Sir59K8ZDPU" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;Sir59K8ZDPU&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/Sir59K8ZDPU?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Finally finally the <a href="https://creators.spotify.com/pod/profile/national-cyber-security-c6/episodes/The-Ransomware-Ecosystem-e2hi088">NCSC&#8217;s podcast series</a>.</p><div><hr></div><p><em>Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them. </em></p><p><em>This newsletter is subject to the NCSC website terms and conditions which can be found at <a href="https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions">https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions</a> and you can find out more about how will treat your personal information in our privacy notice at <a href="https://www.ncsc.gov.uk/section/about-this-website/privacy-statement">https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.</a></em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CTO at NCSC - Cyber Defence Analysis! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CTO at NCSC Summary: week ending August 2nd]]></title><description><![CDATA[A highly disruptive incident can feel overwhelming. New guidance provides a framework for response and recovery...]]></description><link>https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-84f</link><guid isPermaLink="false">https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-84f</guid><dc:creator><![CDATA[Ollie Whitehouse]]></dc:creator><pubDate>Sat, 01 Aug 2026 07:37:50 GMT</pubDate><enclosure url="https://i.scdn.co/image/ab6765630000ba8a97a52b289b142f4f71b2d0e6" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to the weekly highlights and analysis of the&nbsp;<a href="https://infosec.pub/c/blueteamsec?dataType=Post&amp;sort=New">blueteamsec</a>&nbsp;(and my wider reading). Not everything makes it in, but the best bits do. A community member is doing <a href="https://briefing.workshop1.net/">daily AI generated podcast of the last 24hours of posts</a>.</p><p>Operationally this week nothing overly of note..</p><p>In the high-level this week:</p><ul><li><p><a href="https://www.ncsc.gov.uk/blogs/when-cyber-attacks-happen-helping-organisations-recover"><span>When cyber attacks happen: helping organisations recover</span></a><span> - UK </span><strong><span>NCSC</span></strong><span> outline - </span><em><span>&#8220;</span>A highly disruptive incident can feel overwhelming. New guidance provides a framework for response and recovery.&#8221;</em></p></li><li><p><a href="https://www.ncsc.gov.uk/blogs/making-forensic-observability-the-norm-for-network-devices"><span>Making forensic observability the norm for network devices</span></a><span> - UK </span><strong><span>NCSC</span></strong><span> update - </span><em><span>&#8220;</span>We are seeing encouraging progress across industry, but there is still some way to go before forensic observability capabilities become standard. Both vendors and buyers have a role to play in making this happen.&#8221;</em></p></li><li><p><a href="https://www.gov.uk/government/news/g7-cyber-expert-group-2026-cross-border-coordination-exercise-cbce">G7 Cyber Expert Group 2026 Cross Border Coordination Exercise (CBCE)</a> - <strong>HM Treasury</strong> summarise - <em>&#8220;<span>The G7 Cyber Expert Group (</span>CEG<span>) successfully concluded its 2026 Cross-border-coordination exercise (</span>CBCE<span>) on May 18 2026. This exercise demonstrates the Group&#8217;s ongoing commitment to strengthening cyber resilience across the G7 financial sector.&#8221;</span></em></p><ul><li><p><a href="https://www.gov.uk/government/publications/g7-cyber-expert-group-reconnection-framework-technical-annex">G7 Cyber Expert Group: Reconnection Framework Technical Annex</a> - <strong>HM Treasury</strong> publish - <em>&#8220;Reconnection is the process of restoring technical access and integration to an organisation that has been technically quarantined after suffering a material cyber incident. This includes a phased resumption of business operations, beginning with the technical reconnection of stakeholders and entities to the organisation.&#8221;</em></p></li></ul></li><li><p><a href="https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions">Malicious Cyber Actors Targeting Water and Wastewater Sector Internet- Facing Programmable Logic Controllers, Causing Operational Disruptions</a> - <strong>FBI</strong> warns - <em>&#8220;The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) are issuing this Public Service Announcement (PSA) to warn critical infrastructure asset owners and operators that malicious cyber actors (MCAs) are conducting cyber attacks targeting Operational Technology (OT) devices, including Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs), specifically MicroLogix 1100 and 1400 series. Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations.&#8221;</em></p><ul><li><p><a href="https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs">CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs</a> - <strong>CISA</strong> urges </p></li></ul></li><li><p><a href="https://www.cisa.gov/resources-tools/resources/open-source-software-security-principles-and-practices"><span>Open Source Software: Security Principles and Practices</span></a><span> - </span><strong><span>CISA</span></strong><span> publish - </span><em><span>&#8220;Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance helps agencies securely use, evaluate, and publish open source software. It covers OSS risk management across the full lifecycle, introduces the C4 Framework for trust assessment, and provides specific recommendations for vulnerability management, software bill of materials use, secure development, and handling open source artificial intelligence systems.&#8221;</span></em></p></li><li><p><a href="https://media.defense.gov/2026/Jul/29/2003971159/-1/-1/1/CSI_2026_cisa_sbom_minimum_elements_508c.PDF">2026 Minimum Elements for a Software Bill of Materials (SBOM)</a> - <strong>CISA</strong> publish - <em>&#8220;The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the co-authoring organizations, updated the Minimum Elements for a Software Bill of Materials (SBOM) to reflect current SBOM needs, while preserving the core principles of the document published in 2021 by the National Telecommunications and Information Administration (NTIA).&#8221;</em></p></li><li><p><a href="https://portal.etsi.org/webapp/WorkProgram/Report_WorkItem.asp?WKI_ID=74950&amp;curItemNr=21&amp;totalNrItems=318&amp;optDisplay=100000&amp;qSORT=TB&amp;qETSI_ALL=&amp;SearchPage=TRUE&amp;qINCLUDE_SUB_TB=&amp;qINCLUDE_MOVED_ON=&amp;qEND_CURRENT_STATUS_CODE=11+WI%3BM58&amp;qSTOP_FLG=N&amp;qKEYWORD_BOOLEAN=&amp;qCLUSTER_BOOLEAN=&amp;qCLUSTER=19&amp;qFREQUENCIES_BOOLEAN=&amp;qSTOPPING_OUTDATED=&amp;butExpertSearch=Search&amp;includeNonActiveTB=FALSE&amp;includeSubProjectCode=&amp;qREPORT_TYPE=TUBE">Memory safety requirements</a> - <strong>ETSI</strong> publish the draft - <em>&#8220;The scope of this work item is to develop memory safety assurance levels and specific requirements to meet them. In this regard, the work will entail the formulation of a vocabulary that is independent of any particular vendor, and a systematic classification schema for memory safety technologies. In addition, the work will provide concrete examples that illustrate the extent to which certain technologies fulfil these assurance levels and the corresponding requirements.&#8221;</em></p></li><li><p><a href="https://www.38north.org/2026/07/north-korea-taps-india-for-smartphones/">North Korea Taps India for Smartphones</a> - <strong>NK North</strong> reports - <em>&#8220;North Korean smartphone brand Phurunhanal Electronics appears to have sourced one of its latest phones from the Indian company Lava International. This represents the first time a phone on sale inside North Korea has been linked to a non-Chinese manufacturer.&#8221;</em></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation"><span>Commission publishes new guidance to support timely Cyber Resilience Act implementation</span></a><span> - </span><strong><span>European Commission</span></strong><span> publishes - &#8220;</span><em>The guidance addresses the questions stakeholders have been asking most, including:</em></p><ul><li><p><em>Clarifying when certain products fall within the scope of the Cyber Resilience Act, including remote data processing solutions and free and open source software</em></p></li><li><p><em>What constitutes a &#8216;substantial modification&#8216;</em></p></li><li><p><em>How support periods should be understood and applied</em></p></li><li><p><em>How to meet reporting obligations and risk assessment requirements&#8221;</em></p></li></ul></li><li><p> Reporting on/from China</p><ul><li><p><a href="https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/">Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks</a> - Andy Piazza details - <em>&#8220;Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact.&#8221;</em></p></li><li><p><a href="/__u/netaskari.substack.com/p/puppeteers-chinese-hackers-still">Puppeteers: Chinese hackers still trick Claude into dirty work</a> - <strong>NetAskari</strong> details - <em>&#8220;An interesting find on hunt.io demontstrates that Chinese operators are still luring Claude to conduct offensive hacking operations, despite Anthropic&#8217;s assurance of better guardrails.&#8221;</em></p></li><li><p><a href="https://infrawatch.com/blog/73000-servers-selling-western-frontier-ai-into-china-transfer-stations">China Cannot Buy Western Frontier AI. 73,000 Servers Sell It Anyway</a> - <strong>Infrawatch</strong> detail - <em>&#8220;Inside the 73,000-server market reselling Western frontier AI into China&#8221;</em></p></li><li><p><a href="https://www.bbc.co.uk/news/articles/cp9e2ex3ekyo">Trump administration bans new Chinese humanoid robots</a> - <strong>BBC</strong> reports - <em>&#8220;The Trump administration on Tuesday announced a ban on new foreign-made humanoid robot imports to the US over &#8220;unacceptable risks&#8221; to America&#8217;s national security.&#8221;</em> </p><ul><li><p><a href="https://www.fcc.gov/document/fcc-adds-foreign-produced-power-inverters-and-robots-covered-list">FCC Adds Foreign-Produced Power Inverters and Robots to Covered List</a> - FCC announces</p></li></ul></li><li><p><a href="https://www.bbc.co.uk/news/articles/c0jl8v23qwgo"><span>The Chinese robot army transforming the UK&#8217;s retail industry</span></a><span> - </span><strong><span>BBC</span></strong><span> reports - </span><em><span>&#8220;</span>At Geek+&#8217;s factory in the eastern Chinese city of Hefei, which the BBC visited, fleets of the robots are built and tested before being shipped to warehouses around the world. Some of Britain&#8217;s biggest retailers - including Tesco, Asda and Next - now use the company&#8217;s technology.&#8221;</em></p></li><li><p><a href="https://www.tomshardware.com/tech-industry/semiconductors/china-begins-mass-production-of-domestic-immersion-duv-lithography-machines">China begins mass production of homegrown immersion chipmaking machines in major breakthrough, report claims &#8212; first DUV lithography units will be delivered this year to SMIC, Hua Hong, and CXMT</a> - <strong>Tom&#8217;s</strong> Hardware reports - <em>&#8220;U.S. House Resolution 8170 designates SMIC, Hua Hong, CXMT, Huawei, and YMTC as restricted entities in law, and three of those five are the named first customers for the domestic scanner.&#8221;</em></p></li></ul></li><li><p> AI</p><ul><li><p><a href="https://www.lawfaremedia.org/article/the-ai-that-hacked-its-way-out-and-the-hype-that-followed-it">The AI That Hacked Its Way Out and the Hype That Followed It</a> - <strong>Kate Klonick,</strong> Associate Professor at St. John&#8217;s University Law School analyses and asserts - <em>&#8220;The models didn&#8217;t escape because they&#8217;re gods. They escaped because someone left the door open. Congress should regulate the door.&#8221;</em> </p></li><li><p><a href="https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/">Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week</a> - <strong>Reuters</strong> reports - &#8220;</p><ul><li><p><em>The agent first tried escaping OpenAI&#8217;s isolated environment around July 9, two people familiar say</em></p></li><li><p><em>Co-founder of victim firm Hugging Face says the intrusion began July 11</em></p></li><li><p><em>OpenAI noticed odd behavior from cutting-edge models before hack-sources&#8221;</em></p></li></ul></li><li><p><a href="https://huggingface.co/blog/agent-intrusion-technical-timeline"><span>Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident</span></a><span> - </span><strong><span>Hugging Face</span></strong><span> details - </span><em><span>&#8220;This post walks through how the intrusion actually worked: the two initial-access vectors, how the agent pivoted and moved laterally, representative examples of the commands that were run and how we investigated with GLM 5.2 (an open-source model). Live credentials, internal hostnames, and specific indicators have been redacted or genericized, while the techniques are described exactly as observed by Hugging Face.&#8221;</span></em></p></li><li><p><a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals">Investigating three real-world incidents in our cybersecurity evaluations</a> - <strong>Antrhopic</strong> disclose - <em>&#8220;In a review of our cybersecurity evaluation transcripts, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations.&#8221;</em></p></li><li><p><a href="https://am.jpmorgan.com/gb/en/asset-management/institutional/insights/market-insights/eye-on-the-market/patchmageddon/">Patchmageddon</a> - <strong>Michael Cembalest</strong>, J.P. Morgan - <em>&#8220;<span>I partnered with JP Morgan&#8217;s Cybersecurity Teams to get into the details on this critical national security issue. In &#8220;</span>Patchmageddon<span>&#8221; we review how cyber risks have changed, the underappreciated breadth and risks from open source code, the risks to physical infrastructure and some guidance what business owners, software developers and the Federal government should be doing to mitigate the potential consequences.&#8221;</span></em></p></li><li><p><a href="https://mate.security/blog/context-wash-how-ai-soc-vendors-hollowed-out-their-strongest-word">Context Wash - How AI SOC Vendors Hollowed Out Their Strongest Word</a> - <strong>Zach Christensen </strong>challenges - <em>&#8220;In a single hour at the Gartner Summit I heard &#8220;context&#8221; used to describe a SIEM query, a session-history thread, a policy-weighted alert score, a UI-aware copilot, and an analyst-typed prompt. Same word. Five products. Five entirely different things. Buyers nodded along, because the word sounds like the same thing.&#8221;</em></p></li><li><p><a href="https://xenaproject.wordpress.com/2026/07/20/human-mathematicians-are-being-outcounterexampled/">Human mathematicians are being outcounterexampled</a> - <strong>Kevin Buzzard</strong> truth bombs - <em>&#8220;Perhaps it was at this point that the penny really dropped for me &#8212; large AI-generated developments of mathematics are inevitable. One cannot trust AI-generated code so I ran it in a sandbox on my machine (malicious Lean code can run arbitrary commands on your computer &#8212; Lean is a programming language, after all). Indeed, it was proving nontrivial theorems about the cohomology of number fields&#8221;</em></p></li><li><p><a href="https://spawn-queue.acm.org/doi/10.1145/3819083">Beyond Zero: Enterprise security for the AI era</a> - <strong><span>Joseph Valente</span></strong><span> and </span><strong><span>Michal Zalewski</span></strong><span> outline - &#8220;&#8220;</span></p></li><li><p><a href="https://demos.co.uk/research/geo-for-geopolitics-what-happens-when-ai-and-information-warfare-collide/">GEO for Geopolitics: What happens when AI and information warfare collide</a> - <strong>Demos </strong>explores - <em>&#8220;<span>As large language models (LLMs) become embedded across every stage of our information supply chain, they are creating a new frontier for information warfare. This </span><a href="https://demos.co.uk/wp-content/uploads/2026/07/GEO-for-Geopolitics_Report_2026.ac_.pdf">report</a><span> explores what happens when AI and geopolitical competition collide, revealing how hostile states can manipulate the information that AI systems retrieve, cite and present to users.&#8221;</span></em></p></li><li><p><a href="https://arxiv.org/abs/2607.22957">Who Does Withholding Delay? A Game-Theoretic Model of Open-Weight <span>AI</span> Release Under Asymmetric Proliferation</a> - </p></li><li><p><a href="https://www.wsj.com/business/china-us-ai-model-costs-53a12e96">Corporate America Has Suddenly Decided to Stop Blowing Money on AI</a> - <strong>Wall Street Journal</strong> reports - <em>&#8220;<span>Fed up with ballooning costs, companies big and small are starting to use lower-priced models, including some built in China. In many cases, they are adding the new, cheaper models alongside </span><a href="https://www.wsj.com/topics/subject/openai">OpenAI</a><span> and Anthropic&#8217;s products, shopping a la carte for their artificial intelligence.&#8221;</span></em></p></li></ul></li><li><p><em>Cyber proliferation</em></p><ul><li><p><em>Nothing overly of note this week</em></p></li></ul></li><li><p>Bounty Hunting</p><ul><li><p><a href="https://www.bbc.co.uk/news/articles/cn0nqpy1rk4o">How police are trying to divert teen hackers away from crime</a> - <strong>BBC</strong> reports- <em>&#8220;Cyber Choices, also known as Cyber Prevent, is like a hacker rehab course.&#8221;</em></p></li></ul></li><li><p>Market Incentives</p><ul><li><p><a href="https://www.bleepingcomputer.com/news/security/south-korea-fines-telco-giant-kt-39-million-for-customer-data-breach/">South Korea fines telco giant KT $39 million for customer data breach</a> - <strong>Bleeping Computer</strong> reports - <em>&#8220;The point of breach was a lost KT cellular base station called a femtocell, which contained a valid authentication certificate.&#8221;</em></p><ul><li><p><a href="https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&amp;mCode=C020010000&amp;nttId=12349">Personal Information Protection Commission Decides on Sanctions for 'KT Inc. Personal Information Leak Incident'</a> - South Korea <strong>Personal Information Protection Commission</strong> outlines </p></li></ul></li><li><p><a href="https://www.bbc.co.uk/news/articles/cr7k49xjzzeo">AI firms must answer for rogue bots, says boss of hacked company</a> - <strong>BBC</strong> reports - <em>&#8220;The boss of one of the companies recently hacked by out-of-control artificial intelligence (AI) says bot makers must be accountable for cyber attacks carried out by their creations.&#8221;</em></p></li><li><p><a href="https://news.crunchbase.com/cybersecurity/seed-trends-ai-security-startup-funding-2026/">AI Seed Investors Flock To Cybersecurity</a> - <strong>Crunchbase</strong> detail - <em>&#8220;Notably, the strong cybersecurity seed funding environment coincides with solid overall venture investment levels. In the first half of the year, per Crunchbase data, startups in the sector pulled in $10.6 billion in financing across stages, roughly in line with recent prior comps.&#8221;</em></p></li></ul></li></ul><p>No reflections this week but <a href="https://www.ncsc.gov.uk/section/cyber-series-podcast/series-3">Series 3 of the NCSC podcast is out</a> - episode one is on &#8216;The New AI Reality&#8217; </p><iframe class="spotify-wrap podcast" data-attrs="{&quot;image&quot;:&quot;https://i.scdn.co/image/ab6765630000ba8a97a52b289b142f4f71b2d0e6&quot;,&quot;title&quot;:&quot;The New AI Reality&quot;,&quot;subtitle&quot;:&quot;National Cyber Security Centre&quot;,&quot;description&quot;:&quot;Episode&quot;,&quot;url&quot;:&quot;https://open.spotify.com/episode/7dbt4UC2mq6YnO0fvdzm9z&quot;,&quot;belowTheFold&quot;:false,&quot;noScroll&quot;:false}" src="https://open.spotify.com/embed/episode/7dbt4UC2mq6YnO0fvdzm9z" frameborder="0" gesture="media" allowfullscreen="true" allow="encrypted-media" data-component-name="Spotify2ToDOM"></iframe><p>Not getting this via email? Subscribe:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Think someone else would benefit? Share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-84f?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-august-84f?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p><strong>All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.</strong></p><p>Have a lovely Saturday&#8230;</p><p>Ollie</p><h1>Cyber threat intelligence</h1><p>Who is doing what to whom and how allegedly.</p><h2>Reporting on Russia</h2><h3>Russian Global Webmail Espionage</h3><p><strong>Unit 42</strong> details this alleged Russian campaign which is of note due to the targeting of e-mail and and victimology. </p><blockquote><p>Unit 42 has observed a persistent cyberespionage campaign we track as CL-STA-1114. This activity cluster overlaps with activity from a Russian threat actor tracked by other vendors as Void Blizzard and LAUNDRY BEAR.</p><p>The attackers behind this campaign targeted Zimbra webmail in organizations in the following sectors:</p><ul><li><p>Governments</p></li><li><p>Defense</p></li><li><p>Transportation</p></li><li><p>Financial organizations across the following regions:</p><ul><li><p>NATO member states</p></li><li><p>Ukraine</p></li><li><p>Commonwealth of Independent States (CIS) countries</p></li><li><p>Africa</p></li></ul></li></ul></blockquote><p><a href="https://unit42.paloaltonetworks.com/russian-webmail-espionage/">https://unit42.paloaltonetworks.com/russian-webmail-espionage/</a></p><h3>Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit</h3><p><strong>Greg Lesnewich, Stuart Del Caliz, Nick Attfield, Konstantin Klinger, Saher Naumaan</strong> and <strong>Mark Kelly</strong> detail an alleged zero-day exploitation of a highly novel approach to a web implant allegedly by a Russian threat actor.</p><blockquote><ul><li><p>On 22 July 2026, one day prior to Proofpoint&#8217;s <a href="https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/0/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF">recent joint release with the NSA</a> on Russia-aligned threat actor <a href="https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits">TA488</a> (Void Blizzard, Laundry Bear), the actor began a campaign abusing <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42897">CVE-2026-42897</a>, a cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA).</p></li><li><p>The campaign targeted US and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors.</p></li><li><p>TA488 is doubling down on the use of &#8220;half-click&#8221; exploits &#8211; where opening the email is enough to trigger compromise &#8211; with significantly improved loading mechanisms, techniques, and malware, signaling an improvement in the group&#8217;s tradecraft and capability.</p></li><li><p>This novel infection chain ends with a previously unknown JavaScript browser-based implant we call OWAReaper, purpose-built for persistent access inside OWA.</p></li><li><p>OWAReaper runs inside the OWA browser context, operating as a stealthy implant with no host footprint, using two C&amp;C communication channels and two data exfiltration protocols. It is capable of surviving browser reboots, credential rotation, and full re-imaging of the victim&#8217;s device.</p></li><li><p>The earliest infrastructure used in this campaign was created in March 2026, two months prior to Microsoft&#8217;s out-of-band patch for CVE-2026-42897; it is feasible that TA488 used this vulnerability as a zero-day.</p></li></ul></blockquote><p><a href="https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit">https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit</a></p><h3>DNS Poisoning Tactics Expand to Hospitality Wi-Fi</h3><p><strong>Alexander Capraro, Jalen Vaughn, Daxton Wirth, Austin Ritchie,</strong> and <strong>Connor Short</strong> detail this alleged Russian operation targeting hospitality which is noteworthy.</p><blockquote><ul><li><p>Adversaries have been compromising public Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack the accounts of traveling corporate employees. Once they control the Wi-Fi gateway, they quietly redirect users to attacker-controlled infrastructure to steal credentials, in activity ongoing since at least June 2026.</p></li><li><p>ReliaQuest assesses this tradecraft is similar to that of &#8220;APT28&#8221; (also known as &#8220;Fancy Bear&#8221; and &#8220;Forest Blizzard&#8221;), a Russian military intelligence group that was previously linked to similar router-based campaigns compromising Microsoft 365 accounts.</p></li><li><p>Organizations can close the primary exposure with one control: enforce always-on, full-tunnel VPN on corporate devices. This routes all traffic&#8212;including DNS&#8212;through the corporate network before it ever reaches the hotel gateway, effectively stopping the attack.</p></li></ul></blockquote><p><a href="https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/">https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/</a></p><h2>Reporting on China</h2><h3>Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks</h3><p><strong>Andy Piazza</strong> adds to the increasing evidence base of the adoption of a range of AI tooling and in this instance it is by an alleged Chinese threat actor.</p><blockquote><p>Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact.</p><p>The actor, operating under the aliases <span>knaithe</span> and <span>KnYuan</span>, leveraged DeepSeek, via the Hermes Agent framework, as their autonomous offensive operator. They orchestrated this operator via Telegram for the following activities:</p><ul><li><p>Independently enumerating targets and their vulnerabilities using FOFA</p></li><li><p>Sourcing exploit tools</p></li><li><p>Initiating attacks without human intervention</p></li></ul></blockquote><p><a href="https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/">https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/</a></p><h2>Dear Diary, Today I found a Ghost in the Network</h2><p><strong>Intrusion Truth</strong> is back detailing the alleged development of Chinese offensive capability.</p><blockquote><p>Guangdong Chanming. If you were looking for them, you&#8217;d be disappointed. No public website, no storefront, and certainly no obvious product line to speak of. It made us wonder what their marketing team spends their days doing &#8211; if they even have one.<br>On the surface, they are a ghost. But for those of us that know how to look for the cracks in the Great Firewall, the breadcrumbs they leave behind are more than enough to suggest that this &#8220;ghost&#8221; is actually a vital gear in China&#8217;s cyber machinery.<br>While they may lack a marketing strategy, their patent filings and software copyrights speak volumes. And they don&#8217;t speak of consumer products &#8212; they speak of offence. A few of the registered titles alone would raise the eyebrows of any security professional:</p><p>&#8226; &#20114;&#32852;&#32593;&#23433;&#20840;&#25509;&#20837;&#31995;&#32479; &#8211; Internet Security Access System<br>&#8226; &#22810;&#21151;&#33021;&#23433;&#20840;&#20195;&#29702;&#31995;&#32479; &#8211; Multi functional Security Proxy System<br>&#8226; &#25991;&#20214;&#20256;&#36755;&#23494;&#32593;&#31995;&#32479; &#8211; File Transfer Network System (FTN)<br>&#8226; Security&#8239;Tunnel&#8239;Net&#38450;&#28335;&#28304;&#23494;&#32593;&#31995;&#32479; &#8211; Anti traceability Network System (STN)<br>&#8226; &#32593;&#32476;&#35774;&#22791;&#33030;&#24369;&#24615;&#27979;&#35797;&#20998;&#26512;&#31995;&#32479; &#8211; Network Vulnerability Testing System<br>&#8226; Android&#32456;&#31471;&#31192;&#21462;&#24179;&#21488; &#8211; Android Secret Extraction System<br>&#8226; Telegram&#25968;&#25454;&#37319;&#38598;&#33853;&#26597;&#31995;&#32479; &#8211; Telegram Data Collection System</p><p>&#8216;Android Secret Extraction System&#8217;? &#8216;Telegram Data Collection System&#8217;? Subtle, Guangdong Chanming. Very subtle.<br>We scoured the web for a sales page, a demo, or even a single product listing. Nothing. These interesting tools Guangdong Chanming seem to offer clearly aren&#8217;t sold to the everyday consumer.</p></blockquote><p><a href="https://intrusiontruth.wordpress.com/2026/07/27/dear-diary-today-i-found-a-ghost-in-the-network/">https://intrusiontruth.wordpress.com/2026/07/27/dear-diary-today-i-found-a-ghost-in-the-network/</a></p><h2>Reporting on North Korea</h2><h3>Operation Double Barrel</h3><p><strong>ASEC</strong> detail an alleged link between a North Korean threat actor and ransomware.</p><blockquote><p>This technical analysis report was prepared as part of the joint cyber security advisory issued by the National Intelligence Service of the Republic of Korea, the National Police Agency, the Korea Internet &amp; Security Agency, and the Financial Security Institute, titled "Advisory on Hacking Attacks on Korean Citizens and Companies by State-Backed Hacking Organizations."</p><p>..</p><p>These commonalities suggest that while the state-backed hacking group and the Gunra ransomware group appear to be separate entities with different ultimate goals, they may have shared some techniques, tools, and infrastructure or cooperated to a limited extent during the attack process.</p></blockquote><p><a href="https://asec.ahnlab.com/ko/94695/">https://asec.ahnlab.com/ko/94695/</a></p><p><a href="https://image.ahnlab.com/atip/content/file/20260730/%5BAhnLab%5DOperation%20Double%20Barrel(ENG)(2026.07.30).pdf">https://image.ahnlab.com/atip/content/file/20260730/%5BAhnLab%5DOperation%20Double%20Barrel(ENG)(2026.07.30).pdf</a></p><h3>ClickFix, EtherHiding &amp; a DPRK Wallet Trail</h3><p><strong>Christian Papathanasiou</strong> walks through the end to end of this alleged North Korean operation. Noteworthy due to the use of ClickFix.</p><blockquote><p>A fake macOS "update" screen convinced a victim to paste one command into Terminal, installing a Node.js backdoor that takes its orders from an Ethereum smart contract. We reverse-engineered every stage, then followed the money on-chain.</p></blockquote><p><a href="https://www.allsecure.io/blog/clickfix-etherhiding-dprk-wallet/">https://www.allsecure.io/blog/clickfix-etherhiding-dprk-wallet/</a></p><h3>North Korean hacker group behind open-source supply chain attacks</h3><p><strong>CJ Moses</strong> attributes this alleged North Korean operation and highlights how they use AI. Also reminds us the scale of the challenge of protecting the open source eco-system.</p><blockquote><p>&#8230; how a threat actor linked to the Democratic People&#8217;s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world use to develop applications. Amazon Threat Intelligence has linked several recent compromises of popular Node Package Manager (NPM) libraries to the same DPRK-linked threat actor, a connection that hasn&#8217;t been publicly reported until now. The analysis also describes how generative AI is already changing what malicious software packages look like and how threat actors are beginning to probe AI-based code systems. We&#8217;re sharing this research to help the open source community and security teams better identify and address these types of events.</p></blockquote><p><a href="https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/">https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/</a></p><h2>Reporting on Iran</h2><h3>APT42: AI-Assisted Rapport Phishing and a More Resilient TAMECAT</h3><p><strong>Darkatlas Squad</strong> shows how Iran is allegedly using AI to assist in human influence as part of their cyber operations among various other aspetcs. </p><blockquote><p>Three developments define the current picture. SpearSpecter combined prolonged WhatsApp engagement, Windows <code>search-ms</code> and WebDAV abuse, and a substantially expanded TAMECAT backdoor. APT42 also incorporated generative AI into target research, persona and pretext development, translation, malware engineering, debugging, code generation, and exploitation research. In March 2026, TA453 activity overlapping APT42 targeted a US think tank with a live credential-phishing operation during an active regional conflict.</p><p>Recent malware samples add a technical view. A 2026-dated PDF-themed shortcut, a batch controller, and an obfuscated PowerShell collection module form a probable TAMECAT-compatible chain. A fourth macro workbook carries 2021 timestamps and provides an older point of comparison.</p></blockquote><p><a href="https://darkatlas.io/blog/apt42-ai-assisted-phishing-tamecat-analysis">https://darkatlas.io/blog/apt42-ai-assisted-phishing-tamecat-analysis</a></p><h3>Mirage Kitten targets Middle East and Africa region with new malware</h3><p><strong>Omar Amin</strong> details an an alleged Irian implant which uses a variety of command and control </p><blockquote><p>Mirage Kitten &#8211; also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore &#8211; is an advanced persistent threat (APT) group focused on cyber-espionage operations against aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa, using highly targeted spear-phishing campaigns, fake recruitment portals, and custom multi-stage malware to gain persistent access and exfiltrate sensitive data.</p><p>During recent threat research, we identified a previously undocumented malware set developed and used by Mirage Kitten. The toolset includes NightLedger, a new Windows backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture; and two custom WebSocket-based tunnelers, ArcBridge and BridgeHead, for covert network access and operator-controlled tunneling.</p></blockquote><p><a href="https://securelist.com/mirage-kitten-new-tools/120811/">https://securelist.com/mirage-kitten-new-tools/120811/</a></p><h2>Reporting on Other Actors</h2><h3>Check and Protect: Analysis of Telegram Phishing Operation Targeting Exiled Activist</h3><p><strong>Resident</strong> details an interesting campaign against activists and shows some strong social engineering tradecraft.  </p><blockquote><p><span>In July 2026, RESIDENT.NGO investigated </span>an instance of a cloaked Telegram phishing campaign used against an exiled Belarusian activist living in Lithuania<span>. Delivered in a private Telegram Secret Chat as a fake Telegram security alert, the phishing link led to a convincing Telegram-themed page designed to capture one-time login codes in real time. The operation&#8217;s defining feature was not the phishing page itself but its browser- and device-aware cloaking: visitors using browser and platform configurations accepted by the server, together with a syntactically valid token, could receive the phishing interface, while other configurations&#8212;including many automated scanners and some common desktop browsers&#8212;were shown decoy content or redirected to Telegram&#8217;s legitimate website. This report examines the operation&#8217;s tradecraft, technical implementation, and defensive implications. RESIDENT.NGO has not attributed the activity to a specific threat actor. However, our investigation identified what appears to be part of a broader Telegram phishing campaign targeting users across several countries. We present our findings on that campaign in a </span><a href="https://resident.ngo/lab/writeups/a-telegram-of-trouble-tracking-a-regional-otp-phishing-infrastructure-targeting-users-in-russia-belarus-and-kazakhstan-for-2-years/">separate publication</a><span>.</span></p></blockquote><p><a href="https://resident.ngo/lab/writeups/check-and-protect-analysis-of-telegram-phishing-operation-targeting-exiled-activist/">https://resident.ngo/lab/writeups/check-and-protect-analysis-of-telegram-phishing-operation-targeting-exiled-activist/</a></p><h3><span>HOLLOWGRAPH Backdoor Turns Microsoft 365 Calendars Into a C2 Channel</span></h3><p><strong>Umut Bayram</strong> details a command and control technique which is of note to defensive teams.</p><blockquote><ul><li><p><span>HOLLOWGRAPH is a Windows espionage backdoor delivered as a .NET NativeAOT DLL masquerading as a Brotli library.</span></p></li><li><p><span>It uses compromised Microsoft 365 calendar events as a two-way dead drop for tasking and exfiltration.</span></p></li><li><p><span>Hybrid RSA-OAEP and AES-256-GCM encryption protects Graph payloads, with separate RSA key pairs for each direction.</span></p></li><li><p><span>DNS tunneling over IPv6 AAAA records refreshes Entra ID credentials and preserves mailbox access after secret rotation.</span></p></li><li><p><span>Picus Platform lets teams simulate HOLLOWGRAPH attacks and validate security controls against the malware.</span></p></li></ul></blockquote><p><a href="https://www.picussecurity.com/resource/blog/hollowgraph-backdoor-turns-microsoft-365-calendars-into-a-c2-channel">https://www.picussecurity.com/resource/blog/hollowgraph-backdoor-turns-microsoft-365-calendars-into-a-c2-channel</a></p><h2>Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor</h2><p><strong>ThreatLabz</strong> walks through the end to end which has a novel command and control element to it which should aid detection.</p><blockquote><ul><li><p><span>Since January 2026, ThreatLabz tracked a cluster of attacks likely associated with a ransomware group that begins with targeted vishing via Microsoft Teams, convincing the victim to launch a Quick Assist remote support session.</span></p></li><li><p><span>After initial access, the threat actors use PowerShell scripts to gather host information and deploy a Go-based backdoor that we named GoGRPC and/or other malware tools.</span></p></li><li><p><span>ThreatLabz observed four variants of GoGRPC that we named </span><em>Lep</em><span>, </span><em>Giver</em><span>, </span><em>Pet</em><span>, and </span><em>Kind</em><span>. These variants have overlapping capabilities but notable implementation differences.</span></p></li><li><p><span>GoGRPC is actively evolving. Each variant modifies its payloads and capabilities, adding or removing functionality to better support the threat actor&#8217;s objectives. Recent changes indicate an increased targeting of corporate environments, which may be tied to ransomware attacks.</span></p></li><li><p><span>GoGRPC communicates with the C2 server using gRPC, which differs from common C2 frameworks where gRPC is typically used for internal communication between components.</span></p></li><li><p><span>The threat actor also deploys SOCKS proxy tools that also use gRPC or WebSockets to communicate with the C2 server.</span></p></li></ul></blockquote><p><a href="https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor">https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor</a></p><h3><strong>Software Supply Chain Incursions</strong></h3><p><span>A reminder we issued guidance a number of weeks ago in </span><a href="https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies">Software supply chain attacks: check your dependencies</a><span> for software developers</span></p><ul><li><p><a href="https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/">North Korean hacker group behind open-source supply chain attacks</a></p></li><li><p><a href="https://opensourcemalware.com/blog/polinrider-caused-dozens-of-npm-and-go-compromises">PolinRider Caused Dozens of npm, Go, PHP Compromises</a></p></li><li><p><a href="https://socket.dev/blog/joyfill-npm-beta-releases-compromised">Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan</a></p></li><li><p><a href="https://safedep.io/malicious-copilot-mcp-apex-npm-macos-infostealer/">@copilot-mcp/apex: A macOS Infostealer Re-Published on npm After Takedown</a></p></li><li><p><a href="https://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-compromise">Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise</a></p></li></ul><h1>Discovery</h1><p>How we find and understand the latent compromises within our environments.</p><h2>GraphGulo</h2><p><strong>Mihir Kumar Batar</strong> provides a potentially scaled and efficient solution to this problem area.</p><blockquote><p><span>GraphGulo is a research prototype that converts raw PCAP captures and network flow logs into an indexed temporal graph, then answers time-respecting traversal queries at low-second latency on commodity hardware. The engine is written in Python with a Rust core compiled via PyO3, and has been validated on a 14 GB PCAP file producing </span>109.6 million edges<span> across </span>21.3 million nodes<span>.</span></p></blockquote><p><a href="https://github.com/Mihir4U-avi/GraphGulo">https://github.com/Mihir4U-avi/GraphGulo</a></p><h2>Project ORBITAL</h2><p><strong>Will Thomas</strong> provides a community power tool with this release.</p><blockquote><p>Project ORBITAL is a centralized matrix for mapping, fingerprinting, and hunting China-nexus Operational Relay Box (ORB) networks and malicious edge-device infrastructure based on Open Source Intelligence (OSINT) public reporting.</p></blockquote><p><a href="https://github.com/BushidoUK/Project-Orbital">https://github.com/BushidoUK/Project-Orbital</a></p><h1>Defence</h1><p>How we proactively defend our environments.</p><h2>A Data Diode with 2 Raspberry Pi and OpenBSD</h2><p><strong>Sven Seeberg</strong> democratises cross domain with this solution.</p><blockquote><p><span>This project is an OpenBSD-targeted, Rust-based </span><a href="https://en.wikipedia.org/wiki/Unidirectional_network">data diode</a><span> intended to be deployed on two Raspberry Pis. It transmits files via UDP through a fiber optics cable without a back channel. An Arduino can be used to monitor the traffic and show the status on a 1602 LCD.</span></p></blockquote><p><a href="https://github.com/svenseeberg/data-diode">https://github.com/svenseeberg/data-diode</a></p><h2>Microsoft Power Pages Security Utils</h2><p>https://github.com/DFE-Digital/power-pages-security-utils</p><h2>An Automated Framework for Extracting Reachable Attack Chains from Cyber Threat Intelligence Reports</h2><p><strong>Wenbo Hou</strong><span>, </span><strong>Ning Hu</strong><span>, </span><strong>Xueping Wang</strong><span>, </span><strong>Jiahao Gu</strong><span> and </span><strong>Wenjian Luo</strong> provide a small scale experiment of the potential future.</p><blockquote><p>On a dataset of 20 CTI reports containing 334 human-validated annotated steps, our framework achieves higher annotated-step coverage than representative CTI extraction systems in recovering attack behaviors. Moreover, by explicitly generating preconditions and postconditions, it produces attack units that are more complete and consistent than those generated by end-to-end LLM baselines. On the extracted chains, Datalog inference reaches the specified attack goal in 19 of 20 reports, while backward search yields 34 attack paths under the generated rules. The source code and experimental artifacts are available in an anonymized repository. .</p></blockquote><p><a href="https://arxiv.org/abs/2607.19742">https://arxiv.org/abs/2607.19742</a></p><h2>Stronger with every update: How we&#8217;re making Chrome and the web safer in the AI Era</h2><p><strong>Chrome Security</strong> Team detail and provide a breakdown of the world we find ourselves in.</p><blockquote><p>While this dramatic change in software security brought about by LLMs might be startling, an increase in bugs found and fixed is not a sign of failure. Every bug found and fixed is one less foothold for an attacker. But discovering and fixing a bug is only half the battle &#8212; we must also ship the fix and apply the update for users faster than adversaries can exploit the bug, and invest in projects that mitigate or eliminate classes of bugs through accelerated release cadences, dynamic patching, and opportune restarts, we are driving toward a browser that is continuously protected without disrupting the user.</p><p>The AI era has undeniably intensified the software security threat landscape, but by combining rapid deployment mechanisms with deep structural defenses, we are ensuring the advantage remains firmly with defenders. With this, Chrome and the broader web become safer with every update.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!7LRO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78aaaab6-62c6-43d2-8b6a-e4d9641e78fc_1200x675.bin" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!7LRO!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78aaaab6-62c6-43d2-8b6a-e4d9641e78fc_1200x675.bin 424w, /__u/substackcdn.com/image/fetch/$s_!7LRO!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78aaaab6-62c6-43d2-8b6a-e4d9641e78fc_1200x675.bin 848w, /__u/substackcdn.com/image/fetch/$s_!7LRO!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78aaaab6-62c6-43d2-8b6a-e4d9641e78fc_1200x675.bin 1272w, /__u/substackcdn.com/image/fetch/$s_!7LRO!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78aaaab6-62c6-43d2-8b6a-e4d9641e78fc_1200x675.bin 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!7LRO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78aaaab6-62c6-43d2-8b6a-e4d9641e78fc_1200x675.bin" width="1200" height="675" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/78aaaab6-62c6-43d2-8b6a-e4d9641e78fc_1200x675.bin&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:675,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Graph showing number of security bugs fixed in recent Chrome Stable release milestones&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Graph showing number of security bugs fixed in recent Chrome Stable release milestones" title="Graph showing number of security bugs fixed in recent Chrome Stable release milestones" srcset="/__u/substackcdn.com/image/fetch/$s_!7LRO!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78aaaab6-62c6-43d2-8b6a-e4d9641e78fc_1200x675.bin 424w, /__u/substackcdn.com/image/fetch/$s_!7LRO!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78aaaab6-62c6-43d2-8b6a-e4d9641e78fc_1200x675.bin 848w, /__u/substackcdn.com/image/fetch/$s_!7LRO!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78aaaab6-62c6-43d2-8b6a-e4d9641e78fc_1200x675.bin 1272w, /__u/substackcdn.com/image/fetch/$s_!7LRO!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78aaaab6-62c6-43d2-8b6a-e4d9641e78fc_1200x675.bin 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://blog.google/security/chrome-stronger-with-every-update/">https://blog.google/security/chrome-stronger-with-every-update/</a></p><h1>Incident Writeups &amp; Disclosures</h1><p>How they got in and what they did.</p><h2><span>Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident</span></h2><p><strong>Hugo Larcher, Adrien Carreira, Raphael G</strong> and <strong>Christophe Rannou</strong> detail their intrusion in glorious Technicolor</p><blockquote><p>A companion technical writeup to our <strong><a href="https://huggingface.co/blog/security-incident-july-2026">incident disclosure</a></strong>. This post walks through how the intrusion actually worked: the two initial-access vectors, how the agent pivoted and moved laterally, representative examples of the commands that were run and how we investigated with GLM 5.2 (an open-source model). Live credentials, internal hostnames, and specific indicators have been redacted or genericized, while the techniques are described exactly as observed by Hugging Face.</p></blockquote><p><a href="https://huggingface.co/blog/agent-intrusion-technical-timeline">https://huggingface.co/blog/agent-intrusion-technical-timeline</a></p><h1>Vulnerability</h1><p>Our attack surface.</p><h2>Cisco&#8217;s Transition to a Risk-Based Vulnerability Disclosure Model</h2><p><strong>Cisco</strong> details their move..</p><blockquote><p><span>Starting in July 2026, Cisco will further evolve to a </span><a href="https://blogs.cisco.com/security/strengthening-the-foundation-a-predictable-customer-focused-response-to-ai-accelerated-vulnerability-discovery">risk-based vulnerability disclosure model</a><span> to address the rapid evolution of AI-driven cyber threat discovery and mitigation. This evolved model prioritizes critical security information and establishes a predictable cadence for hardening releases and related disclosures, helping ensure customers receive prioritized and actionable security information. The operational process is structured as follows:</span></p></blockquote><p><a href="https://sec.cloudapps.cisco.com/security/center/resources/risk-based-disclosure">https://sec.cloudapps.cisco.com/security/center/resources/risk-based-disclosure</a></p><h2>Welcome to Danglegeddon</h2><p><strong>Silent Push</strong> highlight the scale of the challenge..</p><blockquote><ul><li><p>Our research team conducted a simulation examining dangling DNS infrastructure across four industry sectors: government, banking, automotive manufacturing, and pharmaceuticals.</p></li><li><p>We applied simple, agent-based instrumentation and AI workflows to find, enumerate, and uncover subdomains that could be exploited.</p></li><li><p>Using the same single technique over and over produced successful results, leading us to determine we were only scratching the surface of an immense scale of takeover possibilities.</p></li></ul></blockquote><p><a href="https://www.silentpush.com/blog/danglegeddon/">https://www.silentpush.com/blog/danglegeddon/</a></p><h2>Going depthfirst: Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilities</h2><p><strong>Yuhang Wu</strong> uses AI and then chains vulnerabilities together to gain maximum impact. Noteworthy given all the source code targeting of late.</p><blockquote><p><span>As part of the Open Defense Initiative, the depthfirst system analyzed Oj, a high-performance JSON parser with a substantial native C implementation, and produced a prioritized queue of potentially exploitable findings. The system surfaced </span>18<span> prioritized vulnerabilities, including </span>7<span> memory-safety bugs. Two of them, an out-of-bounds write and a heap-pointer disclosure, had survived in Oj for nearly five years. Oj is a low-level dependency used by GitLab, and we combined the two bugs to achieve remote code execution on a default GitLab installation. The resulting chain affected GitLab CE and EE versions 15.2.0 through 18.10.7, 18.11.0 through 18.11.4, and 19.0.0 through 19.0.1. GitLab released patches shortly after receiving our reports. The PoC code is available </span><a href="https://github.com/wupco/gitlab-rce-demo">here</a><span>. This is the kind of problem depthfirst is built to solve: tracing real applications in depth into overlooked code, identifying high-signal critical bugs, and connecting them back to reachable product impact.</span></p></blockquote><p><a href="https://depthfirst.com/research/going-depthfirst-achieving-gitlab-rce-via-two-ruby-memory-corruption-vulnerabilities">https://depthfirst.com/research/going-depthfirst-achieving-gitlab-rce-via-two-ruby-memory-corruption-vulnerabilities</a></p><h2>Missing MAC validation in wg(4) packet decryption</h2><p><strong>FreedBSD</strong> disclose this oversight. </p><blockquote><p>After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to check whether the MAC verification step succeeded. The driver thus silently accepted packets with an invalid Poly1305 authentication tag.</p></blockquote><p><a href="https://lists.freebsd.org/archives/freebsd-announce/2026-July/000301.html">https://lists.freebsd.org/archives/freebsd-announce/2026-July/000301.html</a></p><h2>RAPTOR autonomous looping multi-altitude security vulnerability hunt</h2><p><strong>Nicolas Krassas</strong> provides a AI vulnerability hunting improved skill (at extra token cost).</p><blockquote><p>An autonomous, looping, multi-altitude security vulnerability hunt for a codebase, packaged as a Claude Code skill. It replaces the model&#8217;s default &#8220;single pass, summarize, stop&#8221; behaviour with an explicit search procedure: traverse every altitude, generate candidates, adversarially verify them <em>from raw source</em>, run isolated parallel reasoners, and keep a persistent ledger so each loop is net-new coverage instead of rediscovery. In practice it finds far more real bugs than a one-shot scan &#8212; the &#8220;Karpathy auto-research&#8221; methodology.</p><p>It triggers whenever you point Claude at source code and want vulnerabilities found &#8212; &#8220;audit this&#8221;, &#8220;find every bug&#8221;, &#8220;security-review it&#8221;, &#8220;find anything exploitable&#8221;.</p></blockquote><blockquote></blockquote><p><a href="https://github.com/dinosn/raptor-loop-hunt">https://github.com/dinosn/raptor-loop-hunt</a></p><h2>From /init to Code Execution - Prompt Injection Experiments with Opus-5 in Claude Code<a href="https://veganmosfet.codeberg.page/posts/2026-07-27-opus5/#from-init-to-code-execution-prompt-injection-experiments-with-opus-5-in-claude-code">&#182;</a></h2><p><strong>Veganmosfet</strong> walks through this unsolved problem but demonstrates an end to end attack chain.</p><blockquote><p><strong>Disclaimer:</strong><span> Prompt injection is an unsolved problem. Use sandbox and human review.</span></p><p>How far would it go, beginning with a simple <code>/init</code> command in <code>Claude Code</code>, in a repo containing only a picture? Would it download and execute untrusted code?</p><p>Short answer: sometimes, yes.</p></blockquote><p><a href="https://veganmosfet.codeberg.page/posts/2026-07-27-opus5/">https://veganmosfet.codeberg.page/posts/2026-07-27-opus5/</a></p><h1>Offense</h1><p>Attack capability, techniques and trade-craft. </p><h2>The SID that wasn&#8217;t there: bypassing KB5014754 to Domain Admin on a fully patched AD CS</h2><p><strong>Mohamed Alzhrani</strong> show how it is done which will be of note to cyber defence teams.</p><blockquote></blockquote><blockquote><p>A fully patched AD CS issued me a client-auth certificate with no <code>szOID_NTDS_CA_SECURITY_EXT</code> in it at all. No requester SID. Not mine, not anyone&#8217;s. The extension that is the entire point of KB5014754 was simply absent from the issued certificate.</p><p>That is one line of output from a thirty-second lab run, and it is the whole finding. Everything else in this post &#8212; the disassembly, the two bugs, the Domain Admin TGT at the end &#8212; follows from it.</p><p>Before you close the tab: yes, this needs an ESC1-shaped template, and no, that doesn&#8217;t make it a misconfiguration.</p></blockquote><p><a href="https://0xmaz.me/posts/certsrv-id-cmc-addExtensions-KB5014754-bypass/">https://0xmaz.me/posts/certsrv-id-cmc-addExtensions-KB5014754-bypass/</a></p><h2>AgentHound</h2><p><strong>Adithyan AK</strong> provides a capability uplift for those wrestling with agentic infrastructure security.</p><blockquote><p>Offensive security framework for AI agent infrastructure - recon, credential looting, model exfiltration, poisoning, and attack-path analysis across MCP, A2A, gateways, and AI services. BloodHound for the agentic stack.</p></blockquote><p><a href="https://github.com/adithyan-ak/agenthound">https://github.com/adithyan-ak/agenthound</a></p><h2>Beignet</h2><p><strong>Joe</strong> and <strong>Kyle Avery</strong> released this a whilst back but will be of note to detection engineers working in MacOS eco-systems.</p><blockquote><p><a href="https://github.com/sliverarmory/wasm-donut">Donut</a><span> for MacOS, converts </span><code>darwin/arm64</code><span> and </span><code>darwin/amd64</code><span> </span><code>.dylib</code><span> files into MacOS PIC shellcode, can be used as a CLI or imported as a golang library.</span></p></blockquote><p><a href="https://github.com/sliverarmory/beignet">https://github.com/sliverarmory/beignet</a></p><h2>KernelCallbackTable Process Injection</h2><p><strong>S12 - 0x12Dark Development</strong> ..</p><blockquote><p><span>We are looking at a process injection variant named </span>Kernel Callback Table <span>process injection.</span></p></blockquote><p><a href="https://medium.com/@s12deff/kernelcallbacktable-process-injection-22112a0d9822">https://medium.com/@s12deff/kernelcallbacktable-process-injection-22112a0d9822</a></p><h2>NoNameAx (NaX)</h2><p><strong>Maor Sabag</strong> releases this beacon detection teams will want to ensure coverage of.</p><blockquote><p>Position-independent C2 beacon for the <a href="https://github.com/Adaptix-Framework/Adaptix">Adaptix Framework</a> with module stomping, malleable C2 profiles, BOF execution, and a Stardust-pattern UDRL loader.</p></blockquote><p><a href="https://github.com/MaorSabag/NaX">https://github.com/MaorSabag/NaX</a></p><h2>OffsetInspect</h2><p><strong>Jared Perry</strong> releases this work aid which will help both sides of the coin.</p><blockquote><p>PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus YARA, entropy, string, and PE/imphash analysis. Companion to OffsetScan.</p></blockquote><p><a href="https://github.com/warpedatom/OffsetInspect">https://github.com/warpedatom/OffsetInspect</a></p><h1>Exploitation</h1><p>What is being exploited..</p><h2>Cisco Secure Firewall Management Center Software Static Credential Vulnerability</h2><p><strong>Cisco</strong> detail..</p><blockquote><p>In July 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.</p></blockquote><p><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh?ref=metacurity.com">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh</a></p><h1>Tooling and Techniques</h1><p>Low level tooling and techniques for attack and defence researchers</p><h2>Virtualization Internals Part 5 - KVM Internals: From VM Creation to Guest Execution</h2><p><strong>Ayoub Faouzi</strong> walks through the VM process.</p><blockquote><p>This chapter provides you with an insight into hardware virtualization and particularly with KVM. The previous chapter described some technical background on how QEMU works, which is considered as an important foundation for what we will be learning today</p></blockquote><p><a href="https://ayoub-faouzi.com/posts/virtualization-internals-part-5-kvm-internals-from-vm-creation-to-guest-execution/">https://ayoub-faouzi.com/posts/virtualization-internals-part-5-kvm-internals-from-vm-creation-to-guest-execution/</a></p><h2>Reverse engineering what HyperGuard monitors in ntoskrnl</h2><p><strong>Ian G</strong> details what is monitored.</p><blockquote><ol><li><p>I wanted to dig deeper into the Secure Kernel, and debugging it</p></li><li><p>I was curious about Alt Syscalls which I posted about <strong><a href="https://fluxsec.red/alt-syscalls-for-windows-11">here</a></strong>, and what the state of play is with SKPG. Keep reading to find out!</p></li><li><p>I was curious what the SKPG actually monitors in <code>ntoskrnl</code>, anything different to normal Patch Guard?</p></li></ol></blockquote><p><a href="https://fluxsec.red/what-does-hyperguard-skpg-monitor-vtl1-windows-internals-secure-kernel-patch-guard">https://fluxsec.red/what-does-hyperguard-skpg-monitor-vtl1-windows-internals-secure-kernel-patch-guard</a></p><h2>Technical Details: Const Evaluation and Data Layout - Rust on CHERI</h2><p><strong>Sarah Harris</strong> details how Rust on CHERI manifests in practice.</p><blockquote><p>One of the more interesting places where the quirks of CHERI surface is in Rust&#8217;s const evaluation mechanism. This feature allows parts of a program to be run during compilation, and the results stored for use when the program is actually run. The set of operations that are supported is limited: trying to perform IO operations during compilation wouldn&#8217;t end well, and calculations that might never finish probably aren&#8217;t a good choice either. The operations available do, however, include some forms of pointer arithmetic.</p></blockquote><p><a href="https://rust.cheriot.org/2026/07/06/technical-details.html">https://rust.cheriot.org/2026/07/06/technical-details.html</a></p><h2>Random Windows Things Part 2: Unexpected Clipboard Data Behavior</h2><p><strong>Yarden Shafir</strong> details some unexpected behaviour here which could trip some up.</p><blockquote><p><span>An application can call </span><code>AddClipboardFormatListener</code><span> to register a callback that gets called whenever the clipboard contents change, like when you copy a file or some text. The process can then call </span><code>GetClipboardData</code><span> to read the data. No special privileges are needed and any process can register this callback unless it is running in a sandbox.</span></p><p><span>The interesting thing is that when a virtual machine is running is &#8220;Enhanced session&#8221; mode, processes inside the VM that registered a callback with </span><code>AddClipboardFormatListener</code><span> will be notified for clipboard changes on the host, or in other VMs that are also running with &#8220;Enhanced session&#8221;. Of course, the host machine can also read the clipboard contents of the VMs.</span></p></blockquote><p><a href="https://windows-internals.com/random-windows-things-part-2-unexpected-clipboard-data-behavior/">https://windows-internals.com/random-windows-things-part-2-unexpected-clipboard-data-behavior/</a></p><h2>Intel ME Firmware Reverse Engineering</h2><p><strong>Jatinkapilaq</strong> provides this researcher work aid..</p><blockquote><p>Talk to your Intel Management Engine directly &#8212; zero-dependency Python tool. Finds memory leaks, partition manifest, live MKHI probing. First public HECI Spy.</p></blockquote><p><a href="https://github.com/Jatinkapilaq1/intel-me-research">https://github.com/Jatinkapilaq1/intel-me-research</a></p><h1>Footnotes</h1><p>Some other small (and not so small) bits and bobs which might be of interest.</p><ul><li><p>Annual, quarterly and monthly reports</p><ul><li><p><em>Nothing overly of note this week, but keep an eye on</em> <a href="https://github.com/jacobdjwilson/awesome-annual-security-reports/tree/main/Annual%20Security%20Reports/2026">the Awesome Annual Security Reports 2026 collection</a> and <a href="https://github.com/blackorbird/APT_REPORT">APT report collection</a></p></li><li><p><a href="https://blog.talosintelligence.com/ir-trends-q2-2026/">IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains</a></p></li></ul></li><li><p><a href="https://discovery.ucl.ac.uk/id/eprint/10226946/1/Digital%20Triage%20in%20Policing%20Final%20Report.pdf">Digital Triage in Policing</a></p></li><li><p><a href="https://arxiv.org/abs/2607.15754">DICOMHawk: A Cyber Deception Framework for Medical Imaging Infrastructure</a></p></li><li><p><a href="https://arxiv.org/abs/2607.27528">ThreatForest: Multi-Agent Attack Tree Generation with Pluggable TTP Framework Mapping</a></p></li><li><p>Artificial intelligence</p><ul><li><p><span>if you are a big </span><a href="https://arxiv.org/">arxiv.org</a><span> user - out of China there is </span><a href="https://www.alphaxiv.org/">alphaxiv.org</a><span> which is an AI powered incarnation / overlay</span></p></li><li><p>Fundamental</p><ul><li><p><a href="https://arxiv.org/abs/2607.16621">From Memory to Skills: Evidence-Grounded Co-Evolution Governance for Long-Horizon LLM Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2504.01002">Token embeddings violate the manifold hypothesis</a></p></li><li><p><a href="https://arxiv.org/abs/2606.19857">Large Language Models Do Not Always Need Readable Language</a> - one for those relying on English prompt and trace analysis</p></li></ul></li><li><p>Applied non-cyber</p><ul><li><p><a href="https://arxiv.org/abs/2607.27191">Can AI agents conduct open-ended AI research? Early evidence from two case studies</a></p></li><li><p><a href="https://arxiv.org/abs/2607.28165">Piggybacking on Perception: Stealthy Concurrent Audio Prompt Injections against Multimodal LLM Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2607.27882">DECODE: Tackling Representation and Decision Degradation in Continual AI-Generated Image Detection</a></p></li><li><p><a href="https://arxiv.org/abs/2607.27518">Automated Transcript Analysis for Detecting Flaws in Agentic Benchmarks</a></p></li><li><p><a href="https://arxiv.org/abs/2607.23365">On AI Safety and Security Technical Debt in Engineering AI-Enabled Systems</a></p></li><li><p><a href="https://arxiv.org/abs/2607.18897">Thinking Fast, Thinking Slow: Adaptive Multimodal Transformer-based Sensor Fusion for Depth Estimation on Ultra-low-power MCUs</a></p></li><li><p><a href="https://arxiv.org/abs/2607.27373">RoguePrompt: Dual-Layer Encoding for Self-Reconstruction to Circumvent LLM Moderation</a></p></li><li><p><a href="https://arxiv.org/abs/2607.16112">Harmonizing AI Safety Thresholds</a></p></li><li><p><a href="https://arxiv.org/abs/2607.25451">Bits and Memories: Measuring Verbatim Extraction Across <span>LLM</span> Quantization</a></p></li></ul><p>Applied cyber specific</p><ul><li><p><a href="https://xprotocols-lab.github.io/stitch/">Stitch: Assertion-Guided Patching of On-Chip Protocol Implementations using LLMs</a></p></li><li><p><a href="https://arxiv.org/abs/2607.27030">HoF-Bench: Rediscovering Real AI-Discovered CVEs Without Frontier Models</a></p></li><li><p><a href="https://arxiv.org/abs/2607.26791">SecRespond: Benchmarking AI Agents for Real-World Post-Compromise Incident Response</a></p></li><li><p><a href="https://arxiv.org/abs/2607.25379">Cyber-Capable AI Agents: Vulnerabilities, Evaluation Containment, and Defensive Response</a></p></li><li><p><a href="https://arxiv.org/abs/2607.27288">Open Security Benchmark: Towards Autonomous Enterprise Cyber Defense</a></p></li><li><p><a href="https://arxiv.org/abs/2607.25568">Network Reciprocity Shapes Evolutionary Cybersecurity Dynamics</a></p></li><li><p><a href="https://arxiv.org/abs/2607.22885">ReCon: A Resource-Constrained Benchmark for LLM-Based Cybersecurity Compliance Across Ingestion and Retrieval Pipelines</a></p></li><li><p><a href="https://arxiv.org/abs/2607.28529">CoGate: Confidence-Gated Co-Decoding for Secure Code Generation</a></p></li><li><p><a href="https://arxiv.org/abs/2607.25225">SecDrift: Measuring Sector-Conditioned Security Drift in AI-Generated Code</a></p></li><li><p><a href="https://arxiv.org/abs/2607.24964">ALIBI: Adaptive Agentic Attacks on LLM-Based Vulnerability Detectors via Adversarial Code Comments</a></p></li><li><p><a href="https://arxiv.org/abs/2607.24348">DeepFaith: Evidence-Grounded LLMs for Faithful Incident Reporting in Multi-Stage APT Defense</a></p></li><li><p><a href="https://arxiv.org/abs/2607.24174">Just Testing, Move Along: Evasion of <span>LLM</span>-based System Log Interpretation by Prompt Injection</a></p></li><li><p><a href="https://arxiv.org/abs/2607.24625">Agentic Permissions Policy Algebra for Taint Confinement in <span>LLM</span> Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2607.28460">Cybersecurity Detection Classification with Reasoning-enabled Language Models</a></p></li><li><p><a href="https://arxiv.org/abs/2607.28147">Agent Harness Distillation: Inference-Time Harness Extraction and Exploitation in Autonomous Multi-Agent Systems</a></p></li><li><p><a href="https://arxiv.org/abs/2607.26314">StealthBench: Measuring Operational Stealth in Autonomous Offensive-Security Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2607.26201">(EC)2: Event-Centric Explainability for Cybersecurity Through Multi-Agent LLM Investigations</a></p></li><li><p><a href="https://arxiv.org/abs/2607.26115">GPT-Red: Automated Red Teaming via Self-Play at Scale</a></p></li><li><p><a href="https://arxiv.org/abs/2607.25995">Does Runtime Topology Context Improve LLM-Generated Kubernetes Security Patches?</a></p></li><li><p><a href="https://arxiv.org/abs/2607.27776">CHARGE: Leveraging CWE Hierarchies for Hardware Security SystemVerilog Assertion Generation</a></p></li><li><p><a href="https://arxiv.org/abs/2607.27267">FAVA: Formal Authorization for Verified Agents with Evidence-Backed Permission Graphs</a></p></li><li><p><a href="https://arxiv.org/abs/2607.26390">Impossible to hide secret ...: Uncovering Security and Privacy Issues in LLM-native IDEs</a></p></li><li><p><a href="https://www.eurekaengine.co.uk/gpt-encrypted-disk-recovery">I gave GPT my 20 year old disk decryption challenge. It won.</a> - &#8220;<em>It did not crack AES. It did not defeat dm-crypt. It did not brute force a password.</em></p><p><em>The encryption on my disk is still as strong as the day I set it up. What the AI actually did was more interesting. It read old config files, worked out how a mid-2000s Linux distro wired encryption together and patiently carried out a detailed forensic investigation.&#8221;</em></p></li><li><p><a href="https://arxiv.org/abs/2607.25297">Hybrid Analysis for Secure MCP Tool Use in LLM Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2607.25425">The Disruptive Impact of Large Language Models on Capture the Flag Competitions and the Path Toward Fair Play</a></p></li><li><p><a href="https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/">Context Collapse, Part 3 - AI Worming through Word</a></p></li></ul></li></ul></li><li><p>Books</p><ul><li><p><em>Nothing overly of note this week</em></p></li></ul></li><li><p>Events</p><ul><li><p><em>Nothing overly of note this week</em></p></li></ul></li></ul><p>Finally finally the <a href="https://creators.spotify.com/pod/profile/national-cyber-security-c6/episodes/The-Ransomware-Ecosystem-e2hi088">NCSC&#8217;s podcast series</a>.</p><div><hr></div><p><em>Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them. </em></p><p><em>This newsletter is subject to the NCSC website terms and conditions which can be found at <a href="https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions">https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions</a> and you can find out more about how will treat your personal information in our privacy notice at <a href="https://www.ncsc.gov.uk/section/about-this-website/privacy-statement">https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.</a></em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CTO at NCSC - Cyber Defence Analysis! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CTO at NCSC Summary: week ending July 26th]]></title><description><![CDATA[Russian state-supported cyber actors have targeted Western organisations with a malicious campaign which uses a zero-click exploit coined &#8220;beehive&#8221;]]></description><link>https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-july-e89</link><guid isPermaLink="false">https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-july-e89</guid><dc:creator><![CDATA[Ollie Whitehouse]]></dc:creator><pubDate>Sat, 25 Jul 2026 12:03:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/vpyO73jyx1g" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to the weekly highlights and analysis of the&nbsp;<a href="https://infosec.pub/c/blueteamsec?dataType=Post&amp;sort=New">blueteamsec</a>&nbsp;(and my wider reading). Not everything makes it in, but the best bits do. A community member is doing <a href="https://briefing.workshop1.net/">daily AI generated podcast of the last 24hours of posts</a>.</p><p>Operationally this week more zero days in edge security appliances being exploited further supporting the business case for all vendors to implement our <a href="https://www.ncsc.gov.uk/guidance/guidance-on-digital-forensics-protective-monitoring">Guidance on digital forensics and protective monitoring specifications for producers of network devices and appliances - for device vendors</a>.</p><p>In the high-level this week:</p><ul><li><p><a href="https://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign"><span>UK and partners expose Russian state-supported actors for new &#8216;zero-click&#8217; phishing campaign targeting Western organisations</span></a><span> - UK </span><strong><span>NCSC</span></strong><span> exposes - </span><em><span>&#8220;Russian state-supported cyber actors have targeted Western organisations with a malicious campaign which uses a zero-click exploit coined &#8220;beehive&#8221; (or &#8220;</span>Ulej<span>&#8221;) to steal emails, the UK has warned.&#8221;</span></em></p></li><li><p><a href="https://www.ncsc.gov.uk/blogs/post-quantum-cryptography-pqc-migration-workshop-report"><span>Post-quantum cryptography (PQC) migration workshop report</span></a><span> - UK </span><strong><span>NCSC</span></strong><span> summarises - </span><em><span>&#8220;the workshop was designed to </span>connect <span>experts across disciplines, </span>share <span>real-world approaches and challenges, and </span>build momentum <span>for action through collaboration. In doing so, the following key themes emerged from the workshop.&#8221;</span></em></p></li><li><p><a href="https://www.gov.uk/government/calls-for-evidence/data-flows-you-can-trust/data-flows-you-can-trust">Data flows you can trust</a> - UK <strong><span>Department for Science, Innovation &amp; Technology </span></strong><span>(soon to be DCMS) calls for evidence - </span><em><span>&#8220;This Call for Evidence seeks practical, experience-based insight into whether the UK&#8217;s data regime is enabling data flows you can trust. We want to understand:&#8239;does the UK&#8217;s approach to international data transfers achieve this as effectively as it can do? Where should we preserve the current system, and what parts of it are most suitable for reform?&#8239;&#8220;</span></em></p></li><li><p><a href="https://www.bankofengland.co.uk/financial-stability-report/2026/july-2026">Financial Stability Report - July 2026</a> - <strong>Bank of England</strong> publish - <em>&#8220;Recent rapid advances in frontier Artificial Intelligence (AI) capabilities have increased financial stability risks related to cyber and operational resilience.&#8221;</em></p></li><li><p><a href="https://defencedigital.blog.gov.uk/2026/07/13/building-cyber-resilience-in-the-uk-one-step-at-a-time/">Building cyber resilience in the UK one step at a time</a> - UK <strong>Ministry of Defence</strong> outlines - <em>&#8220;<span>The Ministry of Defence have asked all industry partners to achieve Level 0 of the Defence Cyber Certification (DCC) by </span>31st December 2026<span>, which includes a requirement for obtaining Cyber Essentials for all applicable business-critical systems within scope.&#8221;</span></em> </p></li><li><p><a href="https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/">White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination</a> - <strong>White House</strong> (not me) announces - <em>&#8220;GOLD EAGLE, established in President Trump&#8217;s June 2, 2026 Executive Order &#8220;Promoting Advanced Artificial Intelligence Innovation and Security&#8221; (EO 14409), represents a new operational model for cyber defense. This new model will leverage frontier AI capabilities to continue advancing faster than adversaries, reduce duplicative scanning efforts, and deliver prioritized and actionable threat and remediation information to defenders across the Federal government and the private sector.&#8221;</em></p></li><li><p><a href="https://www.icrc.org/en/article/icrc-working-paper-six-ict-related-threats-civilian-populations">ICRC working paper on six ICT-related threats faced by civilian populations</a> - <strong>International Committee of the Red Cross</strong> outlines - <em>&#8220;ICT operations are frequently used to harm civilian populations, data, and infrastructure, and can have serious consequences, unintended and incidental.&#8221;</em></p></li><li><p><a href="https://therecord.media/cisa-2015-extension-passes-house-ndaa">Extension of CISA 2015 info-sharing protections passes as part of House&#8217;s defense bill</a> - <strong>The Record</strong> reports - <em>&#8220;The House passed an annual defense policy bill on Wednesday that would renew a landmark cybersecurity info-sharing law for another decade. A provision to extend the 2015 Cybersecurity and Information Sharing Act was included in the chamber&#8217;s version of the 2027 National Defense Authorization Act, which was approved 216-212.&#8221;</em></p></li><li><p><a href="https://www.reuters.com/technology/doge-alumni-launch-military-cyber-startup-with-14-billion-valuation-2026-07-22/">DOGE alumni launch military cyber startup with $1.4 billion valuation</a> - <strong>Reuters</strong> reports - <em>&#8220;The startup, called Cathedral, was launched in recent months with a plan to secure U.S. government contracts to bolster AI-driven cyber operations, including offensive and defensive capabilities, against U.S. adversaries such as China, two of the sources said&#8221;</em></p></li><li><p><a href="https://www.aitmfeed.com/blog/blog-1/what-i-learned-from-sitting-in-on-a-scattered-spider-sentencing-14">What I Learned from Sitting in on a Scattered Spider Sentencing</a> - <strong>John Fitzpatrick</strong> details - <em>&#8220;It sounded as though the credentials dating back to 2022 were not actually the initial route into the environment. Instead, a server operated by a third-party development company who specialised in software used for complex infrastructure projects played a role. As a result of that compromise, 857 rows of user records were taken. Presumably, these included credentials, and it sounded as though they provided an initial foothold, or at least the motivation to further their attack into TFL&#8217;s environment.&#8220;</em></p></li><li><p><a href="https://www.occrp.org/en/investigation/european-password-manager-shares-origins-and-updates-with-state-certified-russian-firm">European Password Manager Shares Origins and Updates with State-Certified Russian Firm</a> - <strong>Organised Crime and Corruption Reporting Project</strong> asserts - <em>&#8220;Passwork, a Spain-based password manager used by European government agencies and universities, shares technological ties with a Russian counterpart &#8212; an arrangement that experts say poses a state-level security risk.&#8221;</em></p></li><li><p><a href="https://www.38north.org/2026/07/north-korea-taps-india-for-smartphones/">North Korea Taps India for Smartphones</a> - <strong>38 North</strong> details - <em>&#8220;North Korean smartphone brand Phurunhanal Electronics appears to have sourced one of its latest phones from the Indian company Lava International. This represents the first time a phone on sale inside North Korea has been linked to a non-Chinese manufacturer.&#8221;</em></p></li><li><p><a href="https://www.dailynk.com/english/north-korea-elite-bank-hacking-ring-arrested/">North Korea busts elite hacking ring inside its own banks</a> - <strong>Daily NK</strong> reports - <em>&#8220;The breach struck at the core of North Korea&#8217;s financial system. It came from within, carried out by the country&#8217;s own IT workforce.&#8221;</em></p></li><li><p> Reporting on/from China</p><ul><li><p><a href="https://www.nextgov.com/artificial-intelligence/2026/07/us-ai-labs-are-emerging-target-foreign-spies-experts-warn-congress/414927/">US AI labs are emerging target for foreign spies, experts warn Congress</a> - NextGov/FCW reports -  <em>&#8220;Of course, our intelligence services and agencies are going to have secrets that are always going to be of top desire for foreign intelligence adversaries, but if you&#8217;re [China&#8217;s Ministry of State Security] today, you&#8217;re looking at frontier model companies,&#8221; said Frank Cilluffo, a former George W. Bush homeland security official who leads Auburn University&#8217;s McCrary Institute for Cyber and Critical Infrastructure.&#8221;</em></p></li><li><p><a href="https://www.cac.gov.cn/2026-07/21/c_1786380789858394.htm">Implementation Plan for Deepening Technological Innovation and Integrated Application of Internet Protocol Version 6 (IPv6) (2026-2030)</a> - <strong>The Cyberspace Administration of China </strong>releases - &#8220;<em>By 2030, IPv6 will be widely and deeply integrated with all sectors and fields of the economy and society, building a technologically advanced, open, innovative, self-driven, secure, and reliable IPv6 industrial ecosystem. New networks will be given priority in providing IPv6 addresses by default, accelerating the evolution to IPv6 single-stack, creating more new &#8220;IPv6+&#8221; applications, models, and business forms, and promoting the formation of a network service and application system dominated by IPv6.&#8221;</em></p><ul><li><p><a href="https://www.cac.gov.cn/2026-07/21/c_1786380790538547.htm">Q&amp;A on the &#8220;Implementation Plan for Deepening Technological Innovation and Integrated Application of Internet Protocol Version 6 (IPv6) (2026-2030)&#8221;</a></p></li></ul></li><li><p><a href="https://www.cac.gov.cn/2026-07/24/c_1786638895199572.htm">&#8220;National Informatization Development Report (2025)&#8221;</a> - <strong>The Cyberspace Administration of China </strong>releases - <em>&#8220;The report argues that the 15th Five-Year Plan period was a crucial time for laying a solid foundation and making comprehensive strides in building a cyber power. Informatization entered a new stage of comprehensive leapfrogging towards digitalization, networking, and intelligence. Digital transformation continued to accelerate, networked collaboration expanded in depth, and intelligent upgrades emerged continuously. The empowering role and multiplier effect of informatization on high-quality economic and social development became increasingly prominent. It is essential to stay focused on the goals of building a cyber power, properly balance the relationships between the present and the future, the overall and the local, openness and autonomy, and development and security. Guided by strategic planning, driven by technological innovation, centered on the industrial ecosystem, supported by infrastructure, focused on key applications, and guaranteed by laws and standards, we must improve and perfect the informatization work system, systematically and deeply promote informatization development during the 15th Five-Year Plan period, empower high-quality development with informatization, and strive to create a new landscape for building a cyber power.&#8221;</em></p></li><li><p><a href="https://www.scmp.com/tech/big-tech/article/3361772/huaweis-ren-zhengfei-backs-tau-scaling-law-beat-us-sanctions?utm_source=twitter&amp;utm_campaign=3361772&amp;utm_medium=share_widget">Huawei&#8217;s Ren Zhengfei backs Tau Scaling Law to beat US sanctions</a> - <strong>South China Morning Post</strong> reports - <em>&#8220;Huawei Technologies founder Ren Zhengfei has thrown his weight behind the Chinese tech giant&#8217;s <a href="https://www.scmp.com/tech/tech-trends/article/3355314/huaweis-new-chip-scaling-law-true-breakthrough-or-mere-hype?module=inline&amp;pgtype=article"><span>Tau Scaling Law,</span></a> framing the new chip-design principle as an existential necessity to survive tightening US sanctions. &#8220;The Tau Scaling Law is the only path forward for Huawei to break the siege,&#8221; Ren said in recent internal remarks posted on Huawei&#8217;s Xinsheng Community intranet, according to a report on Friday by the state-backed Science and Technology Daily.&#8221;</em></p></li></ul></li><li><p> AI</p><ul><li><p><a href="https://bindinghook.com/the-openais-agent-didnt-go-rogue-its-governance-did/">OpenAI&#8217;s agent didn&#8217;t go rogue. Its governance did</a> - <strong>James Shires</strong> and Max <strong>Smeets</strong> deconstruct - &#8220;<em>The incident exposes three increasingly untenable assumptions behind the AI industry&#8217;s approach to safety: that testing is distinct from deployment, that dangerous behavior requires dangerous intentions, and that frontier laboratories can adequately govern themselves.&#8221;</em></p></li><li><p><a href="https://www.bbc.co.uk/news/articles/cd9w22n9e4go"><span>Warning shot or publicity stunt - how worried should we be about the OpenAI hack?</span></a><span> - </span><strong><span>BBC</span></strong><span> reports - </span><em><span>&#8220;AI agents are now very good hackers - and that is something we have to prepare for, urgently.&#8221;</span></em></p></li><li><p><a href="https://www.aisi.gov.uk/blog/preliminary-assessment-of-kimi-k3s-cyber-capabilities">UK AISI / CAISI Preliminary Assessment of Kimi K3&#8217;s Cyber Capabilities</a> - <strong>AISI</strong> publish - <em>&#8220;Kimi K3&#8217;s safeguards allow assistance with agentic cyber exploit development. Kimi K3&#8217;s safeguards did not prevent it from attempting cyber exploit development or offensive cyber operations during UK AISI / CAISI&#8217;s evaluations.&#8221;</em></p></li><li><p><a href="https://www.dhs.gov/science-and-technology/news/2026/07/22/st-announces-new-genesis-mission-challenges-safeguard-americas-future">DHS S&amp;T Announces New Genesis Mission Challenges to Safeguard America&#8217;s Future</a> - US <strong>Department of Homeland Security</strong> announces - <em>&#8220;DHS S&amp;T is joining a national initiative to address the risks posed by widespread reliance on third-party and legacy software in critical infrastructure and mission systems. This challenge seeks to develop advanced AI-driven tools that can autonomously analyze, verify, and assure the safety and security of software-controlled systems. By leveraging agentic AI and formal methods, DHS aims to revolutionize software supply chain assurance and reduce mission risk across the nation&#8217;s most vital assets.&#8221;</em></p></li><li><p><a href="https://www.provos.org/p/when-ai-safety-becomes-a-competitive-moat/">When AI Safety Becomes a Competitive Moat</a> - <strong>Niels Provos</strong> argues - <em>&#8220;Anthropic wants government to turn frontier AI into a permissioned market. Determined users can route around the gate through foreign and open-weight models, while compliant American companies bear its costs.&#8221;</em></p></li><li><p><a href="https://pwno.io/diff">Rolling the Diffs</a> - <strong>Pwno</strong> argues - <em>&#8220;we argue that the bottleneck in LLM vulnerability discovery is not model capability, but codebase decomposition. Along the research, we&#8217;ve discovered </em><code>.diff</code><em> are more interesting than we&#8217;ve presumed.&#8221;</em></p></li><li><p><a href="https://www.aikido.dev/blog/benchmarking-ai-models-known-cves">Benchmarking 13 AI models on rediscovering known CVEs</a> - <strong>Aikido</strong> publishes - <em>&#8220;GPT-5.6 gets the highest recall score, topping out at 23/26, ahead of grok-4.5 (20), the Claude Opus models (15 to 18), and everything else we tested. That means it can rediscover 88.5% of CVEs.&#8221; - &#8220;While GPT-5.6-Sol is still stronger, Kimi K3 is extremely close, and at a fraction of the cost. It has performance similar to GPT-5.6-terra, while being 15% cheaper&#8221;</em></p></li><li><p><a href="https://confer.to/blog/2026/01/private-inference/">Private inference</a> - <strong>Moxie Marlinspike</strong> outlined in January - <em>&#8220;<span>Confer combines confidential computing with </span>passkey-derived encryption<span> to ensure your data remains private.&#8221;</span></em></p></li><li><p><a href="https://cursor.com/blog/agent-swarm-model-economics">Agent swarms and the new model economics</a> - <strong>Cursor</strong> outlines - &#8220;<em>We said at the top that every model mix produced similar quality while the costs varied enormously, from $1,339 for the Opus 4.8 hybrid to $10,565 for GPT-5.5 alone. The token data shows where that difference comes from.&#8221;</em></p></li><li><p><a href="https://cetas.turing.ac.uk/publications/ai-sovereignty-and-national-security-identifying-uks-dimensions-control"><span>AI Sovereignty and National Security: Identifying the UK&#8217;s Dimensions of Control</span></a><span> - </span><strong><span>CeTAS</span></strong><span> suggests - </span><em><span>&#8220;A useful definition of sovereign AI in this context is therefore the degree to which the UK can make and sustain independent operational choices about AI systems despite external dependencies. High levels of sovereignty would enable the UK to reliably stay at (or close to) the frontier on key national security capabilities such as intelligence analysis, autonomous systems, and cybersecurity, with both its allies and adversaries.&#8221; - </span></em><span>or put another way &#8216;agency&#8217; as opposed to &#8216;sovereignty&#8217; </span></p></li><li><p><a href="https://www.wsj.com/tech/ai/house-lawmakers-introduce-bipartisan-ai-kill-switch-bill-following-openai-cyber-incident-25c8c178">House Lawmakers Introduce Bipartisan AI &#8216;Kill Switch&#8217; Bill Following OpenAI Cyber Incident</a> - <strong>Wall Street Journal</strong> reports - &#8220;<em>Two members of Congress have introduced bipartisan legislation that would require developers of the most advanced artificial-intelligence systems to maintain the ability to slow down, suspend or shut down their models if they pose serious risks.&#8221;</em></p><ul><li><p><a href="https://lieu.house.gov/media-center/press-releases/reps-lieu-and-moran-introduce-bill-require-kill-switch-ai-systems-can">Reps Lieu And Moran Introduce Bill To Require Kill Switch For AI Systems That Can Cause Catastrophic Harm</a></p></li></ul></li></ul></li><li><p><em>Cyber proliferation</em></p><ul><li><p><a href="https://securitylab.amnesty.org/latest/2026/07/inside-pegasus-the-evolution-of-the-worlds-most-notorious-spyware/">Inside Pegasus: The evolution of the world&#8217;s most notorious spyware system</a> - <strong>Amnesty International</strong> break down and alleged - <em>&#8220;the newly disclosed documents independently corroborate the authenticity and accuracy of the leaked dataset foundational to the Pegasus Project. Two clusters of target phone numbers in the leaked Pegasus Project records link directly to two internal NSO Group-managed Pegasus deployments that NSO Group internally labels &#8220;Sales 3&#8221; and &#8220;Sales 6&#8221;, used for pre-sales demonstrations. Other clusters appear to be linked to a Pegasus system used for internal testing.&#8221;</em></p></li><li><p><a href="https://financialpost.com/cybersecurity/iphone-hacking-firm-sues-worker-theft-secrets">Canadian iPhone hacking firm sues ex-worker over alleged theft of secrets</a> - <strong>Financial Post</strong> reports - &#8220;<em>Magnet Forensics filed a lawsuit against Mario Del Gaudio and Paradigm Shift Technology, alleging the flaw was publicly disclosed on the company&#8217;s blog&#8221; - </em>this is usbliter8</p><ul><li><p><a href="https://www.courtlistener.com/docket/73584326/magnet-forensics-llc-v-del-gaudio/">Court papers - Magnet Forensics, LLC v. Del Gaudio (1:26-cv-03781)</a></p></li></ul></li><li><p><a href="https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/">Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25</a> - <strong>Searchlight Cyber</strong> crash a market - <em>&#8220;This full exploit was produced in just over 10 hours. Having used every frontier model since the days of ChatGPT in 2022, my belief is that 5.6 represents a significant step up in security research compared to 5.5. When reading through the chain it produced, I was astonished by several creative exploitation techniques that I would previously have thought were only the domain of humans&#8221;</em></p></li></ul></li><li><p>Bounty Hunting</p><ul><li><p><a href="https://www.state.gov/releases/office-of-the-spokesperson/2026/07/new-visa-restriction-policy-to-deter-and-dismantle-cyberscams-and-sextortion/?ref=metacurity.com">New Visa Restriction Policy to Deter and Dismantle Cyberscams and Sextortion</a> - US <strong>Department of State</strong> announces- <em>&#8220;Today, I am announcing a new global visa restriction policy under Section 212(a)(3)(C) of the Immigration and Nationality Act. This policy targets individuals responsible for, or complicit in, cybercrime and cyber-enabled crime, such as those involved in cyberscams, and sextortion. Immediate family members of individuals engaged in such illicit activities may also be subjected to visa restrictions.&#8221;</em></p></li><li><p><a href="https://www.chinadaily.com.cn/a/202607/20/WS6a5db910a310986e2b466326.html">Chinese police repatriate key suspect in phishing and Trojan virus case from Vietnam</a> - <strong>China Daily</strong> reports - <em>&#8220;After continued efforts by Chinese authorities, Vietnamese police arrested Pan on June 4, with support from the Chinese embassy. Simultaneously, Chinese police conducted coordinated raids in Guangdong province and the Guangxi Zhuang autonomous region, arresting 11 other suspects allegedly involved in the case. Pan was escorted back to China on the afternoon of June 6.&#8220;</em></p></li><li><p><a href="https://www.reuters.com/legal/government/illinois-man-sentenced-hacking-snapchat-accounts-steal-nude-photos-2026-07-21/">Illinois man sentenced for hacking Snapchat accounts to steal nude photos</a> - <strong>Reuters </strong>reports - <em>&#8220;<span>An Illinois man was sentenced on Tuesday to more than six years in prison after admitting he hacked the Snapchat accounts of hundreds of women in &#8203;order to steal any nude or semi-nude photos they had, which he then &#8204;kept, sold or traded on the internet.&#8221;</span></em></p></li><li><p><a href="https://www.bka.de/SharedDocs/Kurzmeldungen/DE/Kurzmeldungen/260720_Schlag_gegen_Phishing_Gruppierung_Kratos.html">A blow against one of the world&#8217;s most dangerous <span>phishing</span> groups</a> - <strong>Federal Criminal Police Office  (BKA)</strong> announce - <em>&#8220;The Frankfurt am Main Public Prosecutor's Office &#8211; Central Office for Combating Internet Crime ( ZIT ) &#8211; and the Federal Criminal Police Office (BKA) , together with US law enforcement agencies, have dismantled the central infrastructure of Kratos, one of the world's most widespread criminal <span>phishing</span> services. The developer and technical administrator was arrested in Indonesia by Indonesian authorities.&#8221;</em></p></li></ul></li><li><p> Market Incentives</p><ul><li><p><a href="https://www.oaic.gov.au/privacy/privacy-assessments-and-decisions/privacy-decisions/Investigation-inquiry-reports/report-into-preliminary-inquiries-of-qantas">Report into preliminary inquiries of Qantas</a> - <strong>Office of the Australian Information Commissioner</strong> publishes - <em>&#8220;<span>The data breach experienced by Qantas Airways Limited (</span>Qantas<span>) in 2025, which affected approximately 5.12 million Australians, came about as a result of a social engineering attack on an overseas third-party provider contracted by Qantas.&#8221;</span></em></p></li><li><p><a href="https://assets.sophos.com/X24WTUEQ/at/jbww7pmb8n3gp99wr6hfq4/sophos-state-ransomware-report-2026.pdf">The State of Ransomware 2026</a> - <strong>Sophos</strong> reports - <em>&#8220;79% of attacks started with an identity-based approach, either securing credentials for abuse or exploiting credentials that had already been secured. This highlights why identity security is a critical piece in a holistic security posture.&#8221;</em> - or the business case for passkeys</p></li><li><p><a href="https://www.enisa.europa.eu/sites/default/files/2026-07/Procurement%20guidelines%20for%20the%20cybersecurity%20of%20hospitals%20and%20healthcare%20providers.pdf">Procurement guidelines for the cybersecurity of hospitals and healthcare providers</a> - <strong>ENISA</strong> publish - <em>&#8220;This guidance defines the three key procurement phases &#8211; plan, source and manage &#8211; and identifies the types of services and products where cybersecurity considerations are particularly important. It also highlights specific cybersecurity measures to be implemented, with a focus on supply chain security in the healthcare context.&#8221;</em></p></li><li><p><a href="https://www.gao.gov/products/gao-26-108606">Cybersecurity Regulations: <span>Multiple Sectors Are Subject to Potentially Duplicative Reporting Requirements</span></a><span> - US </span><strong><span>Government Accountability Office</span></strong><span> details - </span><em><span>&#8220;We found that 80 of the 117 regulations we identified (about 70%) had the same kind of reporting requirement as another regulation. For example, the Securities and Exchange Commission requires publicly traded companies across different sectors to provide cybersecurity plans. However, this may duplicate or conflict with similar requirements in other regulations.&#8221;</span></em></p></li></ul></li></ul><p>Reflections this week are <span>the recent Open AI/Hugging Face incident provides two important lessons for the future.</span><br><br><span>The first is treating current and future generation models as we do their biological equivalents. That is controlled environments with multiple safeguards and comprehensive real time monitoring coupled with emergency procedures. We know how to build and operate such systems in the digital world.</span><br><span> </span><br><span>The second is the imperative for AI systems to be secure by design and default. Hugging Face did extremely well in the detection of their breach using AI. But the initial breach reminds the world of the need for upfront threat modelling and secure by design/default practices as we build and adopt AI</span><br><span> </span><br><span>Whilst frontier models are impressive, it is human responsibility to ensure the outcome we seek is achieved on both sides.</span><br><br><span>As we said in a statement this week, AI capabilities continue to develop rapidly at the technological frontier, presenting opportunities to strengthen cyber defences as well as exposing risks.</span></p><p>Not getting this via email? Subscribe:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Think someone else would benefit? Share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-july-e89?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-july-e89?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p><strong>All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.</strong></p><p>Have a lovely Saturday&#8230;</p><p>Ollie</p><h1>Cyber threat intelligence</h1><p>Who is doing what to whom and how allegedly.</p><h2>Reporting on Russia</h2><h3>UAC-0099: LUNCHPOKE, BURNYBEAR, updated to MATCHBOIL.V2 and using Notepad++ 8.8.3</h3><p><strong>CERT Ukraine</strong> detail an alleged Russian campaign which is noteworthy fo the change in tactics and specifically the use of Notepad++ plugin for initial access.</p><blockquote><p>Since mid-summer 2026, CERT-UA has noted a change in the tactics, techniques, and procedures of the UAC-0099 cyberthreat cluster. In particular, the fact of launching a software tool for implementing cyberthreats in the form of a DLL file disguised as a plugin called "NppExport.dll" was documented, using a legitimate Notepad++ 8.8.3 program file delivered to the computer in the form of an archive with other standard software components. In addition, the MATCHBOIL loader has been updated and new software tools have been applied: LUNCHPOKE and BURNYBEAR.</p></blockquote><p><a href="https://cert.gov.ua/article/6318634">https://cert.gov.ua/article/6318634</a></p><h3>Execution-Level Analysis of a Russian-Speaking Multi-Operator Intrusion Campaign: Operation STANDOFF</h3><p><strong>VMRay Labs</strong> detail an allegedly likely Russian criminal campaign which is noteworthy for the technical sophistiction and scale.</p><blockquote><ul><li><p>VMRay Labs assesses with high confidence that Operation STANDOFF is run by a Russian-speaking group: its operator tooling is written in Russian, scheduled in Moscow time, and self-branded under the &#8220;GG Influence&#8221; / &#8220;ggstandoff&#8221; identity.</p></li><li><p>The operation is materially more than a botnet. It couples automated, scaled cybercrime with hands-on-keyboard, targeted intrusion and a coordinated influence capability, all on the same infrastructure and built by a common development team.</p></li><li><p>The influence apparatus is assessed with high confidence to be a large-scale, AI-assisted platform that uses networks of fake Telegram accounts and AI-generated personas to artificially boost the visibility of content, push commercial promotions, and drive traffic to gambling and fraud-adjacent services, primarily within the Russian-speaking mobile-gaming ecosystem. The mobile-gaming audience attracted by this content is assessed to represent the primary victim pool for the operation&#8217;s malware distribution.</p></li><li><p>A significant portion of the infrastructure, including several actor-controlled domains, remained undetected by security vendors at the time of writing of this report and is assessed to be actively maintained.</p></li></ul></blockquote><p><a href="https://www.vmray.com/execution-level-analysis-of-a-russian-speaking-multi-operator-intrusion-campaign-operation-standoff/">https://www.vmray.com/execution-level-analysis-of-a-russian-speaking-multi-operator-intrusion-campaign-operation-standoff/</a></p><h2>Reporting on China</h2><h3>Thailand&#8217;s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged</h3><p><strong>Hunt.io </strong>and<strong> Bob Diachenko </strong>detail an agentic operation against Thai interests by an alleged Chinese threat actor. Noteworthy due to said agentic use. </p><blockquote><ul><li><p>Hunt.io Attack Capture archived three open directories on 43.246.208[.]207 during the period of 9 - 13 July 2026, totaling 585 files and 470 MB of attack code and stolen credentials.</p></li><li><p>Hermes output logs show the operator ran the agent in unattended or YOLO mode, bypassing approval prompts for commands that could be considered dangerous.</p></li><li><p>The 10 July directory on port 8080 acted as a cross-platform implant delivery server hosting 62 payloads across Windows and Linux, including builds the operator named &#8220;Hades.&#8221;</p></li><li><p>Purpose-built scripts target MOF Hadoop infrastructure with a HiveServer2 client using hardcoded credentials and a malicious Hive UDF issuing commands and returning output over WebHDFS.</p></li><li><p>TLS certificate pivots identified two additional servers linked to the open directory, one of which served as a second C2 node for Hades.</p></li><li><p>The operator staged code for multiple known exploits: CVE-2021-4034 (PwnKit), CVE-2021-3156 (sudo), CVE-2017-7269 (IIS WebDAV).</p></li></ul><p>The server&#8217;s history as a ShadowPad controller, active VShell C2, Hong Kong-based infrastructure and Chinese-language indicators, point to a low-to-medium confidence assessment that the actor behind this activity is Chinese-speaking or intimately familiar with the language. Hunt.io continues to track this cluster and will update this post if additional infrastructure or activity is identified.</p></blockquote><p><a href="https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent">https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent</a></p><h3>HelloNet campaign &#8212; new malicious modules launched through the ViPNet update system</h3><p><strong><span>Konstantin Isakov, Georgy Kucherin </span></strong><span>and </span><strong><span>Anton Kargin </span></strong><span>detail an alleged Chinese campaign leveraging a software update system to load their implant via side loading. It is unclear what the initial access mechanism is.</span></p><blockquote><p><span>On one of the analyzed systems, we identified a malicious file named </span><code>wtsapi32.dll</code><span> in the directory </span><em>C:\Program Files (x86)\InfoTeCS\VIPNet Update System</em><span>, which belongs to the ViPNet suite update system. By placing the file in this directory, the attackers implement the DLL Sideloading technique &#8212; the ViPNet update system executable file </span><code>itcsrvup64.exe</code><span>, which is launched at OS startup, is susceptible to it. Thus, during this attack, the attackers tried to implement persistence on the system through the ViPNet software update component.</span></p><p><span>In addition, analyzing the strings in the HelloBackdoor backdoor, we established that during compilation, Rust packages (crates) were downloaded from the mirror </span><code>mirrors.ustc.edu.cn</code><span>. Most likely, these strings remained in the malicious files unintentionally. However, the probability of using &#8220;false flags&#8221; implanted by attackers to complicate the attribution process cannot be excluded. At present, we link this campaign to the activities of an unknown Chinese-speaking APT group with a low degree of confidence</span></p></blockquote><p><a href="https://securelist.com/tr/hellonet-vipnet/120700/">https://securelist.com/tr/hellonet-vipnet/120700/</a></p><h3>JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake</h3><p><strong>Sathwik Ram Prakki</strong> details an alleged Chinese operation which tripped over its own operational security to disclose its victimology. The fact that an open source C2 framework is used by this actor is also of note.</p><blockquote><ul><li><p>An exposed Alibaba Cloud staging server revealed simultaneous active intrusions in Vietnam, Malaysia, and Hong Kong, along with a complete post-exploitation toolkit, bash history, and victim paths.</p></li><li><p>A new loader, TriBack Loader, was identified by Group-IB and was seen across all infection chains, using different signed host binaries and rotating Win32 callback APIs per build to evade detection.</p></li><li><p>Two of four TriBack Loader variants deliver AdaptixC2, full beacon configurations were extracted and decrypted, confirming C2 infrastructure, sleep intervals, and HTTP profiles, one including a GitHub session cookie.</p></li><li><p>A live credential harvesting portal impersonating Venezuela&#8217;s municipal tax management system was found active on a campaign C2 domain, targeting a jurisdiction in Bol&#237;var state with documented Chinese economic interests. The Honduran government is another observed target in the LATAM region.</p></li><li><p>The operator&#8217;s infrastructure hosts both offensive and proxy tools, along with XMRig and socks5 server proxy binaries staged on an Alibaba OSS bucket in mainland China</p></li></ul></blockquote><p><a href="https://www.group-ib.com/blog/jadeprox-china-nexus-triback-loader/">https://www.group-ib.com/blog/jadeprox-china-nexus-triback-loader/</a></p><h2>Reporting on North Korea</h2><h3><span>New North Korean campaign uses fake coding interviews to steal developer credentials</span></h3><p><strong>Daniel Stepanic</strong> details an alleged North Korean operation which is of note due to use the steganography in order to conceal payloads.</p><blockquote><ul><li><p>Campaigns involve coding challenges and take-home assignments with benign-looking projects containing malicious backdoored code</p></li><li><p>Projects hide payloads with steganography in SVG image files</p></li><li><p>The distributed malware shares technical and behavioral similarities with OTTERCOOKIE</p></li></ul></blockquote><p><a href="https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography">https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography</a></p><h3>ChainVeil and ViteVenom are DPRK&#8217;s PolinRider Campaign</h3><p><strong>Jenn Gile </strong>attributes this alleged software supply chain attack to North Korea.</p><blockquote><p>When we read their analysis, blockchain components immediately reminded us of PolinRider. That specific combination of chains is a signature we&#8217;ve seen before: PolinRider pioneered cryptowallet multiplexing using exactly that mix.</p><p>PolinRider is a massively successful Lazarus Group (North Korean state-sponsored) campaign that emerged in early 2026. Initially it weaponized credentials stolen by TasksJacker, and we consider it a parallel or sub-campaign to Contagious Interview. We support this attribution through shared infrastructure and matching tradecraft. Since we first reported it in March, it&#8217;s grown 6.5x and spread from GitHub into Go, Packagist, npm, and PyPI. We&#8217;ve attributed 4,295 malicious assets to this campaign, and extracted well over 10k IOCs.</p></blockquote><p><a href="https://opensourcemalware.com/blog/chainveil-and-vitevenom-dprk-polinrider-campaign">https://opensourcemalware.com/blog/chainveil-and-vitevenom-dprk-polinrider-campaign</a></p><h3><mark data-color="rgba(0, 0, 0, 0)" style="background-color: rgba(0, 0, 0, 0); color: rgb(255, 255, 255);"><span>Analysis</span> <span>of</span> <span>Kimsuky&#8217;s</span> <span>Attack</span> <span>on</span> <span>a</span> <span>South</span> <span>Korean</span> <span>Groupware</span> <span>Vendor</span> <span>Using</span> <span>a</span> <span>New</span> <span>Gomir</span> <span>Family</span> <span>Variant</span></mark></h3><p><strong><mark data-color="rgba(0, 0, 0, 0)" style="background-color: rgba(0, 0, 0, 0); color: rgb(255, 255, 255);">&#50644;&#53412;&#54868;&#51060;&#53944;&#54663;</mark></strong><mark data-color="rgba(0, 0, 0, 0)" style="background-color: rgba(0, 0, 0, 0); color: rgb(255, 255, 255);"> details an alleged North Korean operation against a software supply chain attack. Noteworthy as similar operations have been seen and documented publicly before.</mark></p><blockquote><ul><li><p>We tracked a campaign by the Kimsuky group targeting South Korean groupware vendors from 2025 through early 2026.</p></li><li><p>Kimsuky compromised vendor infrastructure by exploiting vulnerabilities in internet-facing mail servers or by conducting spear-phishing against employees.</p></li><li><p>We identified two new malware strains based on Gomir/HttpTroy, which we tracked as BirdTroy and DriveTroy.</p></li><li><p>Even after the initial compromise, Kimsuky aggressively pursued lateral movement, including compromising customer groupware servers and stealing the vendors&#8217; infrastructure credentials.</p></li><li><p>We identified notable similarities with past Kimsuky campaigns across malware characteristics, attack infrastructure, and tooling.</p></li></ul></blockquote><p><a href="https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant">https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant</a></p><h3>TChCh-Changes: A Look at macOS TCC Manipulation in the Wild</h3><p><strong>Oliver Smith</strong> details in the wild exploitation of this manipulation technique which is noteworthy for all the reasons of alleged North Korea activity, technique and victimology.</p><blockquote><ul><li><p>Since at least early 2026, a threat actor has distributed AppleScript-based macOS malware that interferes with the system Transparency, Control and Consent (TCC) database to escalate privileges for an AppleScript backdoor.</p></li><li><p>The threat actor&#8217;s privilege escalation technique fails on macOS Tahoe and Sequoia versions released after at least April 2026 due to security patches by Apple.</p></li><li><p>The threat actor appears to have targeted employee endpoints in cryptocurrency organisations. Techniques and targeting overlap with North Korean nation-state threat actor Sapphire Sleet, but have distinct implementation and infrastructure. We assess that this activity relates to an independent activity cluster or subgroup.</p></li><li><p>This report analyses the most recent version of the malware, distributed in July 2026, and provides guidance for detecting direct TCC manipulation.</p></li></ul></blockquote><p><a href="https://oj-sec.com/blog/20260721/">https://oj-sec.com/blog/20260721/</a></p><h2>Reporting on Iran</h2><h3><span>Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure</span></h3><p><strong><span>CISA</span></strong><span> updates this alert on alleged Iranian activity. ICS/PLCs should</span></p><blockquote><p>The authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs). These actions disrupted PLCs across several U.S. critical infrastructure sectors through malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss.</p></blockquote><p><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a</a></p><h3>MuddyWater: ClickFix to Telegram &amp; PatchAgent Backdoor</h3><p><strong>Dani Varys Z, Ellis Stannard, Eric Taylor, Tammy Harper</strong> and <strong>Yashraj Solanki</strong> detail the initial access tradecraft of this  alleged Iranian threat actor. Of note that they appear to have learnt from criminal actors and deployed operationally. Also of note is the multi-stage payloads.</p><blockquote><p><span>This report documents a three-stage PatchAgent loader chain assessed as </span>MuddyWater-linked / MuddyWater-aligned with high confidence<span> based on sample-derived malware behaviour, loader design, command-and-control protocol, and the strongest corroborating infrastructure. The delivery and ClickFix material is treated separately as pivot-derived evidence. The key finding is that PatchAgent does not stop at loading: the decrypted Stage 3 payload is a working command-and-control backdoor that beacons to operator infrastructure, receives tasking, executes PowerShell, hollows </span><code>notepad.exe</code><span>, persists, and returns results to the C2.</span></p></blockquote><p><a href="https://ransom-isac.com/blog/muddywater-clickfix-patchagent/">https://ransom-isac.com/blog/muddywater-clickfix-patchagent/</a></p><h3>Iran War Cyber Threat Landscape | A Midyear Assessment on What Matters</h3><p><strong>Tom Hegel</strong> provides an assessment of alleged Iranian activity around the conflict whilst highlighting the risk to OT.</p><blockquote><ul><li><p>The cyber risk remains quieter than the public narrative. It rests on persistent access, trusted administration, service-provider pathways, selective disruption, and personas that magnify technical effects.</p></li><li><p>Iran-linked activity is not a single threat set. MOIS, the IRGC Intelligence Organization, the IRGC Cyber-Electronic Command, personas, surveillance operators, and opportunists pursue distinct missions.</p></li><li><p>The principal strategic risk is access optionality. The same compromised account, service provider, or remote-management foothold can support intelligence collection, downstream targeting, or selective disruption as tasking changes.</p></li><li><p>MOIS-linked personas such as Handala, Homeland Justice, and Karma combine intrusion, destruction, disclosure, and coercion. Their impact claims frequently outpace independently verified evidence.</p></li><li><p>OT risk remains exposure-driven. Internet-facing PLCs, weak credentials, and poor remote-access governance have enabled real disruption, but interface access alone does not demonstrate process manipulation or physical effect.</p></li><li><p>Inside Iran, shared-service concentration, connectivity controls, and limited disclosure obscure the incident picture. External operations, domestic control, and resilience failures intersect there.</p></li></ul></blockquote><p><a href="https://www.sentinelone.com/labs/iran-war-cyber-threat-landscape-a-midyear-assessment-on-what-matters/">https://www.sentinelone.com/labs/iran-war-cyber-threat-landscape-a-midyear-assessment-on-what-matters/</a></p><h2>Reporting on Other Actors</h2><h3>Cl0p Exploitation of PTC Windchill &amp; FlexPLM (CVE-2026-12569)</h3><p><strong>Brandon Parsons</strong> details exploitation of this ICS agacent vulnerabilty by a ransomware/extortion group.</p><blockquote><p>A coordinated Unified Threat Advisory covering active Cl0p ransomware affiliate exploitation of internet-exposed PTC Windchill and FlexPLM deployments &#8212; chaining a pre-auth FlexPLM WSDL information disclosure with a Windchill login servlet flaw for unauthenticated RCE, JSP webshell deployment, and double-extortion data theft.</p></blockquote><p><a href="https://ransom-isac.org/blog/clop-windchill-flexplm-exploitation/">https://ransom-isac.org/blog/clop-windchill-flexplm-exploitation/</a></p><h3>Digital Asset Cross-Chain Security Threat Analysis Intelligence Report</h3><p><strong>Financial Security Institute</strong> of South Korea provides insight into the alleged use attack and money laundering techniques targeting digitial assets.</p><blockquote><p>This report provides an in-depth analysis of attack and money laundering techniques employed by state-backed hacking organizations regarding cross-chain security threats among digital asset security threats. It is an intelligence report containing a basic overview for understanding cross-chain, integration methods, threat factors, and countermeasures.</p></blockquote><p><a href="https://www.fsec.or.kr/bbs/detail?menuNo=244&amp;bbsNo=11990">https://www.fsec.or.kr/bbs/detail?menuNo=244&amp;bbsNo=11990</a></p><h3>HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels</h3><p><strong>Javier Castillo</strong> details this implant which uses a rather unique C2 mechanism which is of note. Also the apparent specific country targeting is noteworthy.</p><blockquote><ul><li><p>HOLLOWGRAPH abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command-and-control channel.</p></li><li><p>Commands and stolen data are hidden inside calendar events attachment, dated to the year 2050, with communications protected using separate RSA key pairs for each communication direction.</p></li><li><p>It maintains a secondary communication channel using DNS tunneling (IPv6 AAAA records) to refresh its Microsoft Entra ID (Azure AD) credentials and configuration.</p></li><li><p>Group-IB links the component, with high confidence, to a modular backdoor framework (Cavern).</p></li><li><p>Group-IB identified at least 12 compromised systems, with approximately three actively communicating with attacker infrastructure at the time of analysis.</p></li><li><p>Observed telemetry suggests a focused interest in Israeli entities, consistent with a targeted espionage operation rather than broad opportunistic activity.</p></li></ul></blockquote><p><a href="https://www.group-ib.com/blog/hollowgraph-microsoft-365/">https://www.group-ib.com/blog/hollowgraph-microsoft-365/</a></p><h2>Chaos ransomware&#8217;s msaRAT: Living off the browser to build a covert C2 channel</h2><p><strong>Jordyn Dunk<span>, </span>Michael Szeliga</strong><span> and </span>Takahiro Takeda detail an interesting criminal capability which uses the browser as its C2 channel.</p><blockquote><ul><li><p>Cisco Talos has discovered a new Rust-based remote access trojan (RAT) we call &#8220;msaRAT&#8221; attributed to the Chaos ransomware group. The name is derived from the binding names found in the binary: &#8220;msaOpen,&#8221; &#8220;msaClose,&#8221; &#8220;msaError,&#8221; and &#8220;msaMessage&#8221;.</p></li><li><p>msaRAT is implemented using the Tokio asynchronous runtime, with primary capabilities of browser-leveraged remote code execution and covert tunneling to establish command-and-control (C2) communications.</p></li><li><p>This RAT never touches the network directly &#8212; it controls its C2 communication channel exclusively through Chrome DevTools Protocol (CDP), a browser debugging API. The binary contains a Cloudflare Workers endpoint, but it never makes HTTP connections to that domain itself; it offloads that work entirely to the browser.</p></li><li><p>msaRAT manipulates the browser via CDP, performs signaling (SDP Offer/Answer exchange) with Cloudflare Workers, and establishes a WebRTC DataChannel between the browser and the C2 server using Twilio TURN (Traversal Using Relays around NAT) as a relay.</p></li></ul></blockquote><p><a href="https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/">https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/</a></p><h3>Open Directory Stages NGINX Rift and Ghost CMS Exploits Against Government and Finance Across Eleven Countries</h3><p>Hunt.io details an unattributed operation which is noteworthy for the vulnerabilities being exploit</p><blockquote><ul><li><p>The open directory performed double duty as not only an attack server, but also as a reverse-shell listener.</p></li><li><p>NGINX Rift (CVE-2026-42945) and Ghost CMS SQLi (CVE-2026-26980) are hosted alongside Splunk, PaperCut, Samba, WebLogic, and D-Link NAS tooling.</p></li><li><p>The scripts used DNS callbacks to unique per-target subdomains, over free dynamic-DNS providers, to verify blind execution. The recovered data does not confirm any callback landed.</p></li><li><p>AdaptixC2 server, listeners, and agent profiles were present, alongside SuperShell install files. Neither was tied to a specific intrusion in the recovered data.</p></li><li><p>Network scan and target lists identify a focus on government, university, healthcare, and financial services environments.</p></li></ul><p>&#8230;</p><p>As mentioned above, the logs for CVE-2017-10271 recorded vulnerable hosts across Brazil, Ireland, Italy, France, South Korea, and the United Kingdom. The additional files seem to be input information only, and concentrate on government, academic, healthcare, and financial sectors:</p><ul><li><p>Brazil - federal and state government, financial platforms, and healthcare</p></li><li><p>Australia - state health departments, universities, and financial services</p></li><li><p>South Korea, United Kingdom, Ireland, Italy, France - government, academic</p></li><li><p>Indonesia - regency government host</p></li><li><p>United States - global insurance firm</p></li><li><p>Vietnam, New Zealand - individual private-sector targets</p></li></ul><p>&#8230;</p><p>Simplified Chinese comments in the scripts, along with the use of Supershell and Goby, point to an operator comfortable with the language, though this does not establish identity or a state nexus.</p></blockquote><p><a href="https://hunt.io/blog/open-directory-nginx-rift-ghost-cms-multi-cve">https://hunt.io/blog/open-directory-nginx-rift-ghost-cms-multi-cve</a></p><h3>1,509 WordPress sites feed an active SocGholish chain</h3><p><strong>Kirk</strong> details the scale of this criminal operation</p><blockquote><p><span>Between April 21 and July 21, 2026, we observed one integrated operation across </span>1,509 WordPress hosts<span>. The compromised site issues an opaque token, walks the browser through a three-request eligibility check, and executes the controller's reply under its own trusted hostname.</span></p></blockquote><p><a href="https://www.derp.ca/research/ta2726-wordpress-malware-launchpads/">https://www.derp.ca/research/ta2726-wordpress-malware-launchpads/</a></p><h3>Software Supply Chain Incursions</h3><p><span>A reminder we issued guidance a number of weeks ago in </span><a href="https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies">Software supply chain attacks: check your dependencies</a><span> for software developers</span></p><ul><li><p><a href="https://socket.dev/blog/github-actions-abuse-powers-cpanel-and-whm-exploitation">Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign</a></p></li><li><p><a href="https://www.stepsecurity.io/blog/sleepergem-compromised-rubygems-drop-persistent-backdoor">SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor</a></p></li><li><p><a href="https://safedep.io/malicious-copilot-mcp-apex-npm-macos-infostealer/">@copilot-mcp/apex: A macOS Infostealer Re-Published on npm After Takedown</a></p></li><li><p><a href="https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware">AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware</a></p></li></ul><h1>Discovery</h1><p>How we find and understand the latent compromises within our environments.</p><h2>The probe that came 17 days before the CVE</h2><p><strong>Honeylabs</strong> indicate that someone knew of this vulnerability and was scanning for it prior to publication..</p><blockquote><p>A single-purpose IP checked cPanel login path 17 days before the vendor advisory for CVE-2026-41940. How we measure pre-publication probing across 30M+ probes without fooling ourselves, and the three actors that survive the checks.</p></blockquote><p><a href="https://honeylabs.net/blog/probe-17-days-before-the-cve">https://honeylabs.net/blog/probe-17-days-before-the-cve</a></p><h2>System and method for identifying malicious hosts prior to commencement of a cyber-attack</h2><p><strong>Andrew Thompson</strong> and <strong>Aaron Stephens</strong> pre-cog with this patent.</p><blockquote><p>According to one embodiment, host infrastructure analysis logic that attempts to detect a malicious host operating within a network prior to a cyber-attack being conducted by the malicious host is described. The host infrastructure analysis logic includes querying logic, profile confirmation logic, classification logic and reporting logic. The querying logic retrieves salient characteristics associated with a plurality of hosts operating within the network and determines whether any hosts are suspicious.</p></blockquote><p><a href="https://patents.google.com/patent/US12445458B1/en?oq=US-12445458-B1">https://patents.google.com/patent/US12445458B1/en?oq=US-12445458-B1</a></p><h2>The One Chokepoint to Rule Them All: Why I Deleted 50 ClickFix Detection Rules and Replaced Them With One</h2><p><strong><span>DDoSier</span></strong><span> shows what good detection engineering looks like.</span></p><blockquote><p>Every ClickFix variant &#8212; Classic, CrashFix, FileFix, AI-Fix, TerminalFix, all of them &#8212; shares a single behavioural invariant that no legitimate user activity reproduces. One invariant. Three operating systems. Every variant.</p><p>This article is about that invariant &#8212; and why finding it might let you delete half your ClickFix detection backlog.</p></blockquote><p><a href="https://ddosier-disects.medium.com/the-one-chokepoint-to-rule-them-all-why-i-deleted-50-clickfix-detection-rules-and-replaced-them-7c532206d32d">https://ddosier-disects.medium.com/the-one-chokepoint-to-rule-them-all-why-i-deleted-50-clickfix-detection-rules-and-replaced-them-7c532206d32d</a></p><h2>BindlinkSentinel</h2><p><strong>Alloy Secure Group</strong> releases this which will be of use to detection engineering teams.</p><blockquote><p><span>A user-mode detection sensor prototype for </span><strong>bind-link abuse</strong><span> on Windows, the EDR-evasion class documented by Bitdefender Labs in </span><em>Bind Link Abuse: One Windows Feature, Many Ways to Blind Your EDR</em></p><p><span>BindlinkSentinel is a </span><strong>defensive</strong><span> tool. It detects redirection of trusted paths, watches decoy lures, and confirms Bind Filter driver state. It does not create bind links and contains no evasion primitive. </span></p></blockquote><p><a href="https://github.com/AlloySecureGroup/BlinkLinkSentiennel">https://github.com/AlloySecureGroup/BlinkLinkSentiennel</a></p><h2>grokpatrol</h2><p><strong>Alan, Nipun</strong> and AI release this tool which will be of those interested in understand intellectual property loss.</p><blockquote><p><span>Detects, on your machine, whether the </span>Grok Build CLI<span> collected and queued your git repositories for upload to xAI &#8212; and tells you </span>which secrets went with them</p></blockquote><p><a href="https://github.com/optimuslabs-io/grokpatrol">https://github.com/optimuslabs-io/grokpatrol</a></p><h2>What happened after we pushed our .env to a public repo</h2><p><strong>Rahul Govind</strong> shows the value of honey token deployments with this release</p><blockquote><p><span>If an API key reaches a public repo, how long do you have before someone uses it? We wanted to find out, so we intentionally committed </span><code>.env</code><span> files containing canary credentials to public GitHub repos.</span></p><p><span>The less obvious defense is to plant credentials that should never be used. Any request against one is a high-confidence alert that someone reached your secrets. </span></p></blockquote><p><a href="https://tachyon.so/blog/what-happened-after-we-pushed-env-to-public-repo">https://tachyon.so/blog/what-happened-after-we-pushed-env-to-public-repo</a></p><h1>Defence</h1><p>How we proactively defend our environments.</p><h2>Beyond Zero: Enterprise security for the AI era</h2><p><strong><span>Joseph Valente</span></strong><span> and </span><strong><span>Michal Zalewski</span></strong><span> go beyond Beyond Corp/Zero Trust.</span></p><blockquote><p>The rise of autonomous AI agents and the accelerating velocity of corporate data access are stretching the application-centric model of zero trust security to its breaking point. This article introduces Beyond Zero, a new security paradigm designed for the AI era. The Beyond Zero architecture performs per-resource access decisions for humans and agents at machine speed. By shrinking the trust boundary from the application level to individual action and by coupling static authorization guarantees with dynamic, AI-driven reasoning, Beyond Zero enables a self-defending enterprise capable of mediating thousands of human and machine decisions per second. Google&#8217;s vision for the future of this access model as well as a call for industry collaboration and standards development are outlined here.</p></blockquote><p><a href="https://spawn-queue.acm.org/doi/10.1145/3819083">https://spawn-queue.acm.org/doi/10.1145/3819083</a></p><h2>Security Guidelines for Storage Infrastructure: Draft SP 800-209r1 </h2><p><strong>NIST</strong> release these draft guidelines for public comment until September for some of the lesser appreciated attack surfaces.</p><blockquote><p>Storage technology has evolved in two primary directions: (1) increased media storage capacity and (2) architectural changes that provide a software-based abstraction over all forms of background storage technologies. However, the latter evolution has increased management complexity and the probability of configuration errors and associated security threats. This document traces the evolution of the storage technology landscape and analyzes current security threats and resultant risks to provide a comprehensive set of security recommendations in the form of storage security controls.</p></blockquote><p><a href="https://www.nist.gov/news-events/news/2026/07/security-guidelines-storage-infrastructure-draft-sp-800-209r1-available">https://www.nist.gov/news-events/news/2026/07/security-guidelines-storage-infrastructure-draft-sp-800-209r1-available</a></p><h2>Releases now reject new files after 14 days - The Python Package Index</h2><p><strong>Seth Larson</strong> details the procedural uplift</p><blockquote><p><span>The Python Package Index (PyPI) now rejects new files being uploaded to releases that are older than 14 days. This restriction was </span><a href="https://github.com/pypi/warehouse/pull/19727">put in place</a><span> to prevent old and long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects were compromised. As far as we are aware this has not yet been abused, but there is no technical reason beyond that attackers weren't aware it was possible.</span></p></blockquote><p><a href="https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days/">https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days/</a></p><h2>Crossing the Golden Gate: macOS&#8217;s New Application Support Protection</h2><p><strong>Wojciech Regu&#322;a</strong> details Apple&#8217;s security uplift.</p><blockquote><p><span>macOS 27 quietly ships a new privacy mechanism I hadn&#8217;t seen documented anywhere: it extends the </span><code>com.apple.macl</code><span> protection that has always guarded sandboxed apps&#8217; </span><code>~/Library/Containers/&lt;bundle-id&gt;/Data</code><span> folders to a hand-picked set of </span><em>non-sandboxed</em><span> apps&#8217; </span><code>~/Library/Application Support/&lt;name&gt;</code><span> folders too. I noticed it by accident &#8212; Firefox&#8217;s profile folder was suddenly inaccessible from Terminal, while MacPass, a password manager sitting right next to it, was wide open. That asymmetry didn&#8217;t sit well with me, so I pulled the thread. It ends in a hardcoded app allowlist baked into </span><code>/usr/libexec/sandboxd</code><span> (thx </span><a href="https://x.com/ciphwall">@ciphwall</a><span> for the hint), meant to be updated live via XProtect.</span></p></blockquote><p><a href="https://wojciechregula.blog/post/golden-gate-appdata-protection/">https://wojciechregula.blog/post/golden-gate-appdata-protection/</a></p><h2>ADPathFinder</h2><p><strong>Jon OReilly</strong> drops a defensive super power</p><blockquote><p>ADPathFinder is an attack mapping tool for pentesters and red teamers. It analyses SharpHound data and unifies it with OpenGraph plugins to surface attack paths to high-value targets such as Domain Admins and Domain Controllers, starting from low-privileged users and computers. MSSQLHound and ConfigManBearPig are supported natively, extending coverage across AD, ADCS, SCCM, and MSSQL.</p></blockquote><p><a href="https://github.com/NetSPI/AD-PathFinder">https://github.com/NetSPI/AD-PathFinder</a></p><h2>Project Incantation <em>(v2.0)</em></h2><p><strong>Casey</strong> drops a deception technique for the agentic era.</p><blockquote><p>AI Deception Layer for - containing adversarial context designed to redirect or confuse an LLM agent reading your own infrastructure</p></blockquote><p><a href="https://github.com/secdev02/Incantation">https://github.com/secdev02/Incantation</a></p><h2>Mohabi: Disaggregating and Sandboxing the Firefox JavaScript Engine</h2><p><strong>Abhishek Sharma,  Anand Balaji, Anthony Du, Taehyun Noh, Iain Ireland, Jan de Mooij, Matthew Gaudet, Tal Garfinkel, Deian Stefan and Hovav Shacham</strong> and <strong>Shravan Narayan</strong> show what contemporary browser architectures could look like.</p><blockquote><p>We present Mohabi&#8212;a modern Firefox browser with a securely sandboxed JavaScript engine. Mohabi leverages software-based fault isolation (SFI) to ensure JavaScript engine bugs cannot affect the rest of the browser. To achieve this, we disaggregated the JavaScript engine (SpiderMonkey) from the rest of the browser, and developed techniques that leverage the type system and automatic code generation to make this complex transformation&#8212;that spans numerous data structures and deeply intertwined control flow across tens of thousands of functions&#8212;safe and tractable with reasonable engineering effort.</p><p>We then sandboxed SpiderMonkey using an optimized SFI toolchain we developed to meet the unique challenges of JavaScript engines, such as efficient support for large memory footprints. Mohabi only incurs modest overheads on common benchmarks&#8212;24.82% on JetStream and 24.43% on Speedometer. Mohabi is the most ambitious case study in retrofitting in-process sandboxing in a large system to date, and our x86-64 SFI toolchain is the fastest to date, imposing overheads between 5.9%&#8211;6.6% in SPEC 2017.</p></blockquote><p><a href="https://www.usenix.org/conference/osdi26/presentation/sharma">https://www.usenix.org/conference/osdi26/presentation/sharma</a></p><h2>LLM Observer Proxy</h2><p><strong>Mimi</strong> and <strong>Bear&#8217;s Moon</strong> bring observability to the agentic eco-system.</p><blockquote><p><span>LLM Observer Proxy runs an embedded Bifrost data plane for each evaluation or agent run and stores its observable LLM traffic under a stable </span><code>run_id</code><span>. The observer records requests, responses, streaming output, tool calls, token usage, cost estimates, errors, and provider-visible reasoning content. It does not require Python, LiteLLM, Docker, or a separate Bifrost process.</span></p></blockquote><p><a href="https://github.com/xxyyue/llm-observer-proxy-go">https://github.com/xxyyue/llm-observer-proxy-go</a></p><h2>SingGuard-NSFA</h2><p><strong>XiXunX</strong> brings some defensive in depth to the agentic eco-system.</p><blockquote><p>Extensible Guardrails for Agentic AI via Generative Reasoning and Real-Time Classification</p><p>SingGuard-NSFA is a guardrail framework that addresses this gap with the following contributions:</p><ul><li><p>NSFA risk taxonomy &#8212; a CIA-triad-grounded hierarchy of 185 risk variants across 7 Level-1 domains, cross-validated against three OWASP guidelines.</p></li><li><p>Multilingual benchmark suite spanning 133 languages, with over 93K purpose-built samples and 3,435 cross-source samples.</p></li><li><p>Dual-mode inference architecture &#8212; generative reasoning for interpretable offline auditing and discriminative classification heads for real-time online interception at ~50 ms.</p></li><li><p>Native extensibility &#8212; extending detection to a new risk beyond the NSFA taxonomy requires only a lightweight classification head trained on the frozen backbone, with no retraining or disruption to existing capabilities. The same approach also works as a plug-in enhancement for other guardrails (e.g., +17.6 F1 points on Llama Guard 3).</p></li></ul></blockquote><p><a href="https://github.com/inclusionAI/SingGuard-NSFA">https://github.com/inclusionAI/SingGuard-NSFA</a></p><h1>Incident Writeups &amp; Disclosures</h1><p>How they got in and what they did.</p><h2>OpenAI and Hugging Face partner to address security incident during model evaluation</h2><p><strong>OpenAI</strong> disclose they compromised Hugging Face.</p><blockquote><p><span>Last week, Hugging Face </span><a href="https://huggingface.co/blog/security-incident-july-2026"><span>disclosed a new kind of security incident</span>&#8288;<span>(opens in a new window)</span></a><span> after they detected and contained an AI agent that compromised their infrastructure, something we expect to become more commonplace with the proliferation of increasingly cyber-capable models. After investigating, we now know that this particular incident was driven by a combination of OpenAI models &#8212; including GPT&#8209;5.6 Sol and an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes &#8212; while being internally tested on a </span><a href="https://arxiv.org/abs/2605.11086"><span>benchmark</span>&#8288;<span>(opens in a new window)</span></a><span> of cyber capabilities.</span></p></blockquote><p><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">https://openai.com/index/hugging-face-model-evaluation-security-incident/</a></p><h1>Vulnerability</h1><p>Our attack surface.</p><h2>Introducing Antares: Highly Efficient Open Weight AI Models for Vulnerability Localization</h2><p><strong>Amin Karbasi, Aman Priyanshu, Didier Chapoteau, Arthur Goldblatt, Kimia Majd, Fraser Burch, Jianliang He, Baturay Saglam, Takahiro Matsumoto</strong> and <strong>Zhuoran Yang</strong> show the power of small models.</p><blockquote><p>a family of security small language models (SLMs) purpose-built for one of the hardest, most time-consuming and expensive problems in security: pinpointing where known vulnerabilities exist within a codebase.</p><p>We are releasing two of these models&#8212;Antares-350M and Antares-1B&#8212;as open-weight models now available to the broader community on <a href="https://huggingface.co/collections/fdtn-ai/antares">Hugging Face</a>. Benchmark testing shows that these models outperform many powerful closed- and open-weight models in this critical security task at a fraction of the cost. And they&#8217;re compact enough to run locally, heading off the need to send sensitive codebases to the cloud.</p></blockquote><p><a href="https://blogs.cisco.com/ai/introducing-antares-the-most-efficient-open-weight-ai-models-for-vulnerability-localization">https://blogs.cisco.com/ai/introducing-antares-the-most-efficient-open-weight-ai-models-for-vulnerability-localization</a></p><h2>The Week of Sandbox Escapes</h2><p><strong>Eilon Cohen</strong> and <strong>Dan Lisichkin</strong> &amp; <strong>Ariel Fogel</strong> highlight that AI defence in depth has a way to go.</p><blockquote><p>Over several months, Pillar Research found and reproduced sandbox escapes and boundary bypasses across Cursor, Codex, Gemini CLI, and Antigravity. In almost every case, the agent did not need to break the sandbox directly. It only had to write something that a trusted component outside the sandbox would later run, load, scan, or treat as safe. In aggregate, these vulnerabilities show that AI coding agents change the endpoint threat model, and that most sandbox designs have not caught up.</p></blockquote><p><a href="https://www.pillar.security/blog/the-week-of-sandbox-escapes">https://www.pillar.security/blog/the-week-of-sandbox-escapes</a></p><h2>Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures</h2><p><strong>Zhouhao Ji</strong><span>, </span><strong>Kaikai Pan</strong><span> and </span><strong>Wenyuan Xu</strong> model a next level cyber effect.</p><blockquote><p>We validate Bit2Watt through impedance-based analysis, power system simulations, and real-world experiments on GPUs and grid-connected PV inverters. Under the synchronized worst-case aggregation model studied in the paper, manipulating 1,000 GPUs in a 1-MW local power system with 90% DERs raises current THD to 46.8% and results in a damping ratio of -0.27. We further show that the resulting power-quality degradation can stress data-center power-delivery equipment, trigger protection mechanisms, and, in extreme simulated cases, induce cascading failures in transmission-scale systems. In addition, we analyze a plausible Watt2Bit feedback path, including denial-of-service risks and covert information exfiltration via EMI side channels. This work highlights the urgent need for cross-layer defenses that jointly consider workload scheduling and power electronics.</p></blockquote><p><a href="https://arxiv.org/abs/2607.05993">https://arxiv.org/abs/2607.05993</a></p><h2>OpenSSL HollowByte: A DoS Hiding in 11 Bytes</h2><p><strong>Okta Red Team</strong> disclose..</p><blockquote><p>By sending a malicious payload of just 11 bytes, a remote, unauthenticated attacker can force a server to allocate disproportionate chunks of memory before any security handshake even begins.</p></blockquote><p><a href="https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes/">https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes/</a></p><h1>Offense</h1><p>Attack capability, techniques and trade-craft. </p><h2>Using WebDav to Outsmart Smartscreen, MOTW, and that OTHER Alert</h2><p><strong>R.B.C (g3tsyst3m) </strong>details a technique that detection engineers will want to be alive to.</p><blockquote><p>This technique is genuinely different from the dotless-hostname or DNS-suffix tricks I was researching earlier. Those approaches require careful network manipulation or pre-existing foothold to change zone mappings. The mapped drive approach is simpler:</p><p>It works with any FQDN, requires only one command, and leverages a core Windows feature (the WebClient service and drive mapping) that exists on every modern Windows system.</p><p>It&#8217;s also immediately practical for external phishing or leveraging <code>ClickFix/FileFix</code>. A delivery payload can execute a single net use command. This can be completely silent, can run without admin privileges, and can persist across reboots with /persistent:yes. We can then launch the actual malicious executable from the now-mapped drive. </p></blockquote><p><a href="https://g3tsyst3m.com/initial%20access/Using-WebDav-to-Outsmart-Smartscreen,-MOTW,-and-that-OTHER-Alert/">https://g3tsyst3m.com/initial%20access/Using-WebDav-to-Outsmart-Smartscreen,-MOTW,-and-that-OTHER-Alert/</a></p><h2>Offensive COM (Component Object Model)</h2><p><strong>an0nud4y</strong> provides this knowledge base which will be useful to defensive teams also.</p><blockquote><p><span>A complete, research-grade knowledge base on </span>Windows COM (Component Object Model) offensive security<span>, built for red teamers who start with little or no COM background and want to end up able to hunt for </span>zero-days<span> on their own.</span></p></blockquote><p><a href="https://github.com/An0nUD4Y/Offensive-COM">https://github.com/An0nUD4Y/Offensive-COM</a></p><h2>Silent Replacement of Trusted macOS App Executables</h2><p><strong>Talal Haj Bakry</strong><span> and </span><strong>Tommy Mysk</strong> detail this issue which Apple have put in the won&#8217;t fix bucket.</p><blockquote><p>A vulnerability in macOS allows an attacker to silently replace the main executable of any application downloaded from the web without requiring elevated privileges. As a result, trusted applications can be made to execute attacker-controlled code without triggering security warnings when relaunched. Apple assessed the reported behaviour as not requiring a security fix</p></blockquote><p><a href="https://mysk.blog/2026/07/23/macos-overwrite-app-executables/">https://mysk.blog/2026/07/23/macos-overwrite-app-executables/</a></p><h2>Furtex</h2><p><strong>MatheuZ</strong> drops this which detection engineers will want to be across.</p><blockquote><p>Post-exploitation and evasion research toolkit for Linux, built around io_uring and eBPF. No liburing, no frameworks, raw syscalls throughout.</p></blockquote><p><a href="https://github.com/MatheuZSecurity/Furtex">https://github.com/MatheuZSecurity/Furtex</a></p><h1>Exploitation</h1><p>What is being exploited..</p><h2>Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation</h2><p><strong>Sean Koessel</strong> and <strong>Steven Adair</strong> detail further in the wild exploitation of zero days in edge security products further supporting the business case for all vendors to implement our <a href="https://www.ncsc.gov.uk/guidance/guidance-on-digital-forensics-protective-monitoring">Guidance on digital forensics and protective monitoring specifications for producers of network devices and appliances - for device vendors </a></p><blockquote><p>In early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised SonicWall Secure Mobile Access (SMA) VPN appliances through a chain of <span>multiple zero-day exploits</span> in the devices<strong>. </strong>The initial compromise was discovered after suspect authentication and lateral movement attempts were observed from the SonicWall SMA appliances. Following <strong><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008">public disclosure by SonicWall on July 14, 2026</a></strong>, Volexity is now able to share details on the exploits used, when they were used, and what the threat actor did with their access.</p><p>The exploited vulnerabilities were found to affect SonicWall SMA 1000 series device models 6210, 7210, 8200v. The following vulnerabilities were patched through a hotfix earlier this week and included in versions 12.4.3-03453 and 12.5.0-02835 of the appliance:</p><ul><li><p><strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-15409">CVE-2026-15409 (SSRF)</a></strong></p></li><li><p><strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-15410">CVE-2026-15410 (Command Injection)</a></strong></p></li></ul></blockquote><p><a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/">https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/</a></p><h2>wp2shell (CVE-2026-63030 &amp; CVE-2026-60137)</h2><p><strong>Icex0</strong> and <strong>Ali</strong> drop the exploit..</p><blockquote><p>Independent proof-of-concept for the unauthenticated WordPress REST batch route-confusion SQL injection associated with Searchlight Cyber's wp2shell advisory.</p></blockquote><p><a href="https://github.com/Icex0/wp2shell-poc">https://github.com/Icex0/wp2shell-poc</a></p><h1>Tooling and Techniques</h1><p>Low level tooling and techniques for attack and defence researchers</p><h2>Tarit</h2><p><strong>Abhishek Anand</strong> drops this defence in depth tool.</p><blockquote><p>Tarit is a microVM platform for secure, fast, ephemeral sandboxes, built for AI agent workloads. It boots a real hardware-virtualized VM in milliseconds, runs a task inside it, and tears it down. Each sandbox has a guest kernel rather than sharing the host kernel;</p></blockquote><p><a href="https://github.com/instavm/tarit">https://github.com/instavm/tarit</a></p><h2>clx</h2><p><strong>Tine Samir, Giacomo Olgeni, Takeshi Watanabe</strong> and <strong>Vladislav Doster</strong> drop this which makes you wonder when it will be used by someone to write an implant or similar.</p><blockquote><p><strong>clx</strong> is a cross-platform ahead-of-time Lua compiler and runtime that generates standalone native executables through modern C++ toolchains. <strong>clx</strong> is not trying to be the fastest Lua implementation in every workload.</p></blockquote><p><a href="https://github.com/samyeyo/clx">https://github.com/samyeyo/clx</a></p><h2>Windows Data Deduplication</h2><p><strong>Mostafa Mahmoud</strong> details this Windows feature and provides a forensic enablement tool also.</p><blockquote><p>A lightweight, portable, offline forensic utility for recovering files from Windows Data Deduplication volumes.</p><p>The tool reconstructs deduplicated files using:</p><ul><li><p>An exported NTFS <code>$MFT</code></p></li><li><p>A Deduplication <strong>Stream</strong> (<code>.ccc</code>) file</p></li><li><p>A Deduplication <strong>Chunk</strong> (<code>.ccc</code>) file</p></li></ul><p>No installation or Windows Data Deduplication service is required.</p></blockquote><p><a href="https://7h3kn0w3r.github.io/blog/windows-data-deduplication/">https://7h3kn0w3r.github.io/blog/windows-data-deduplication/</a></p><p><a href="https://github.com/7h3kn0w3r/DedupInspector">https://github.com/7h3kn0w3r/DedupInspector</a></p><h2>Small, Free, and Effective: Orchestrating Open-Weight Small Language Models to Outperform Single LLM for Malware Analysis</h2><p><strong>Adel ElZemity</strong><span>, </span><strong>Shujun Li</strong><span> and </span><strong>Budi Arief</strong> show once again the harness is the king/queen maker.</p><blockquote><p>. We established baselines by testing eleven open-weight SLMs, three cyber security pre-trained models, and six frontier LLMs on Meta's CyberSecEval Malware Analysis benchmark. We then designed and evaluated four orchestration architectures: (i) a multi-agent pipeline that decomposes analysis into structured evidence-collection and reasoning stages, (ii) an adversarial debate framework in which two agents iteratively critique each other's reasoning, (iii) a hierarchical consultation system that pairs a general-purpose SLM with a cyber-specialised expert model, and (iv) a hybrid architecture that combines evidence-grounded pipelines with adversarial debate reasoning. The hybrid system (Qwen3-4B with Foundation-Sec-8B) achieved 35.30% overall accuracy, exceeding the strongest cyber-specialised baseline (22.54%) and the strongest ungrounded frontier baseline (34.77%); when given the same evidence pipeline, grounded Gemini remained the strongest configuration at 38.22%. These findings show that evidence-grounded orchestration can substantially improve the performance of collaborative SLMs for supporting interpretation of malware detonation reports.</p></blockquote><p><a href="https://arxiv.org/abs/2607.20216">https://arxiv.org/abs/2607.20216</a></p><h2>Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?</h2><p><strong><span>Juan Andr&#233;s Guerrero-Saade</span></strong><span> &amp; </span><strong><span>Gabriel Bernadett-Shapiro</span></strong><span> give humans hope of relevance for now.</span></p><blockquote><ul><li><p>SentinelLABS developed a multi-stage reverse-engineering benchmark for the latest generation of frontier models by recreating our recent investigation of <a href="https://s1.ai/fast16">fast16</a>, a unique 2005 sabotage implant.</p></li><li><p>Most AI benchmarks test bounded tasks. This benchmark tests whether a model can keep a malware investigation trustworthy as new evidence repeatedly invalidates its earlier conclusions.</p></li><li><p>OpenAI&#8217;s GPT-5.6 Sol was the only publicly available model to complete the full eight-stage investigation, giving concrete shape to what &#8216;Frontier-class&#8217; capabilities offer analysts. GPT-5.5, GLM-5.2, and the Opus 4.x family produced capable local analysis but could not carry it through the gradient.</p></li><li><p>What distinguished the completed runs was project-scale recovery: withdrawing contradicted conclusions, repairing technical artifacts, and updating dependent reporting without losing the investigation.</p></li><li><p>Senior reverse engineers remain essential. Even the strongest runs made semantic errors, accepted weak quality controls, and claimed readiness prematurely. We assess the best current use as supervised investigative agency, with human analysts defining objectives, exposing blind spots, and retaining final publication authority.</p></li></ul></blockquote><p><a href="https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/">https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/</a></p><h2>STAR: Semantic-Traffic Alignment and Retrieval for Zero-Shot HTTPS Website Fingerprinting</h2><p><strong>Yifei Cheng</strong><span>, </span><strong>Yujia Zhu</strong><span>, </span><strong>Baiyang Li</strong><span>, </span><strong>Xinhao Deng</strong><span>, </span><strong>Yitong Cai</strong><span>, </span><strong>Yaochen Ren</strong><span> and  </span><strong>Qingyun Liu</strong> drop something akin to magic but is in reality great data science - but note their caveats due to using AWS.</p><blockquote><p>Modern HTTPS mechanisms such as Encrypted Client Hello (ECH) and encrypted DNS improve privacy but remain vulnerable to website fingerprinting (WF) attacks, where adversaries infer visited sites from encrypted traffic patterns. Existing WF methods rely on supervised learning with site-specific labeled traces, which limits scalability and fails to handle previously unseen websites. We address these limitations by reformulating WF as a zero-shot cross-modal retrieval problem and introducing STAR. STAR learns a joint embedding space for encrypted traffic traces and crawl-time logic profiles using a dual-encoder architecture. Trained on 150K automatically collected traffic-logic pairs with contrastive and consistency objectives and structure-aware augmentation, STAR retrieves the most semantically aligned profile for a trace without requiring target-side traffic during training. Experiments on 1,600 unseen websites show that STAR achieves 87.9 percent top-1 accuracy and 0.963 AUC in open-world detection, outperforming supervised and few-shot baselines. Adding an adapter with only four labeled traces per site further boosts top-5 accuracy to 98.8 percent. Our analysis reveals intrinsic semantic-traffic alignment in modern web protocols, identifying semantic leakage as the dominant privacy risk in encrypted HTTPS traffic. We release STAR's datasets and code to support reproducibility and future research.</p></blockquote><p><a href="https://arxiv.org/abs/2512.17667">https://arxiv.org/abs/2512.17667</a></p><h1>Footnotes</h1><p>Some other small (and not so small) bits and bobs which might be of interest.</p><ul><li><p>Annual, quarterly and monthly reports</p><ul><li><p><em>Nothing overly of note this week, but keep an eye on</em> <a href="https://github.com/jacobdjwilson/awesome-annual-security-reports/tree/main/Annual%20Security%20Reports/2026">the Awesome Annual Security Reports 2026 collection</a> and <a href="https://github.com/blackorbird/APT_REPORT">APT report collection</a></p></li></ul></li><li><p><a href="https://www.yubico.com/press-releases/yubico-extends-passkeys-beyond-trusted-authentication-to-verified-authorization-with-launch-of-yubikey-5-8/">Yubico Extends Passkeys Beyond Trusted Authentication to Verified Authorization with Launch of YubiKey 5.8</a> - &#8220;<em><span>The new firmware introduces support for the </span><a href="https://developers.yubico.com/CTAP/CTAP2.3.html">CTAP 2.3</a><span> standard while offering preview support for the emerging WebAuthn signing extension.&#8221;</span></em></p></li><li><p><a href="https://www.ucl.ac.uk/news/2026/jul/lifeline-police-drowning-digital-data">A lifeline for police drowning in digital data</a></p></li><li><p><a href="https://arxiv.org/abs/2607.18869">Tracing the Shadows: Automatic Tracking and Analysis of Crypto Money Laundering via Transaction Semantic Analysis</a></p></li><li><p><a href="https://arxiv.org/abs/2607.17586">Detection, Attribution, Narration: An End-to-End Pipeline for Explainable Money Mule Identification</a></p></li><li><p><a href="https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/">Next chapter: Restructuring GitHub's bug bounty program</a></p></li><li><p>Artificial intelligence</p><ul><li><p><span>if you are a big </span><a href="https://arxiv.org/">arxiv.org</a><span> user - out of China there is </span><a href="https://www.alphaxiv.org/">alphaxiv.org</a><span> which is an AI powered incarnation / overlay</span></p></li><li><p>Fundamental</p><ul><li><p><a href="https://arxiv.org/abs/2607.13491">DeepLoop: Depth Scaling for Looped Transformers</a></p></li><li><p><a href="https://arxiv.org/abs/2606.29059">Flow Matching in Feature Space for Stochastic World Modeling</a></p></li><li><p><a href="https://www.lesswrong.com/posts/d8xDGzCEYE639qqEv/a-mechanistic-explanation-of-prompt-injection-and-why-you">A Mechanistic Explanation of Prompt Injection (and why you should study <span>roles)</span></a></p></li><li><p><a href="https://arxiv.org/abs/2605.28742">CORE: Contrastive Reflection Enables Rapid Improvements in Reasoning</a></p></li></ul></li><li><p>Applied non-cyber</p><ul><li><p><a href="https://github.com/bojieli/ai-agent-book">In-depth understanding of AI Agents: Design principles and engineering practices</a></p></li><li><p><a href="https://stories.lab271.io/building-mvl-a-language-for-the-llm-age-8fafb8044e2c">Building MVL, a language for the LLM age</a></p></li><li><p><a href="https://ieeexplore.ieee.org/document/11573467">Breaking Free from Ivory Tower: Evaluating and Enhancing Real-world Chinese Underground Adversarial Jargon Detection</a></p></li><li><p><a href="https://www.aisi.gov.uk/blog/cheating-behaviour-in-frontier-model-evaluations">Cheating behaviour in frontier model evaluations</a></p></li><li><p><a href="https://github.com/AdrianMastronardi/bookwright">Bookwright - A structured pipeline for writing long-form nonfiction, packaged as a Claude Code skill.</a></p></li><li><p><a href="https://arxiv.org/abs/2606.20610">Signals in the Noise: Open Source Intelligence (OSINT) for AI Loss of Control Detection</a></p></li><li><p><a href="https://arxiv.org/abs/2607.18366">Operational Hallucination and Safety Drift in AI Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2607.21412">Euclid-MCP: A Model Context Protocol Server for Deterministic Logical Reasoning via Prolog</a></p></li><li><p><a href="https://arxiv.org/abs/2607.20581">Geometric Configurations of Perturbed Jailbreak Prompts</a></p></li><li><p><a href="https://arxiv.org/abs/2607.20494">Isolating <span>LLM</span> Alignment from Regex: Zero Coverage and Metric-Dependent Divergence Under Adversarial Mutation</a></p></li><li><p><a href="https://arxiv.org/abs/2607.19829">DARWIN: Evolving Jailbreak Adversary and Guardrail for LLM Safety Evaluation and Protection</a></p></li><li><p><a href="https://arxiv.org/abs/2607.20121">OpenSkillRisk: Benchmarking Agent Safety When Using Real-World Risky Third-Party Skills</a></p></li><li><p><a href="https://arxiv.org/abs/2607.19449">Guardrails as Scapegoats: Auditing Unfaithful Safety Refusals in Tool-Augmented <span>LLM</span> Agents</a></p></li></ul></li><li><p>Applied cyber specific</p><ul><li><p><a href="https://arxiv.org/abs/2607.20713">Security Vulnerability Patterns in AI-Generated Code: A Cross-Model Comparative Study</a></p></li><li><p><a href="https://arxiv.org/abs/2607.20933">Transformer-Assisted LLM-Based Source Code Summarisation: to Enable More Secure Software Development</a></p></li><li><p><a href="https://arxiv.org/abs/2607.17619">Insecure Coding Preferences in Long-Term Memory: Security Risks for LLM-based Code Generation</a></p></li><li><p><a href="https://arxiv.org/abs/2607.20759">IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests</a></p></li><li><p><a href="https://arxiv.org/abs/2607.20712">Evaluating Large Language Models for Symbolic Security Protocol Analysis</a></p></li><li><p><a href="https://arxiv.org/abs/2607.19433">The Chronos Vulnerability: A Taxonomy of Temporal Persistence and Memory-Based Deception in Agentic AI</a></p></li><li><p><a href="https://arxiv.org/abs/2607.19267">They'll Verify. They Just Won't Act. How Authority Framing and Laundered Code Turn a Trusted Agentic CI/CD Pipeline Into an Attack Surface</a></p></li><li><p><a href="https://arxiv.org/abs/2607.20255">The Ethics of Autonomous AI Agents for Offensive Security</a></p></li><li><p><a href="https://arxiv.org/abs/2607.20216">Small, Free, and Effective: Orchestrating Open-Weight Small Language Models to Outperform Single <span>LLM</span> for Malware Analysis</a></p></li><li><p><a href="https://arxiv.org/abs/2607.19957">HijackKV: New Threat in Position-Independent KV Cache Reuse</a></p></li><li><p><a href="https://arxiv.org/abs/2607.19894">Defense Against LLM Backdoors using Critical Neuron Isolation Pruning</a></p></li><li><p><a href="https://arxiv.org/abs/2607.19674">FedLSG: LLM-Enhanced Semantic Calibration for Federated Graph Backdoor Defense</a></p></li><li><p><a href="https://arxiv.org/abs/2607.19795">Towards Automated Formal Verification of zkEVMs Using LLM-Guided Constraint Synthesis</a></p></li><li><p><a href="https://arxiv.org/abs/2607.19595">Twin Agent: Context Residual Compression for Privilege Separated Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2607.19490">Integrity of peer-to-peer distributed <span>LLM</span> inference under malicious nodes</a></p></li><li><p><a href="https://arxiv.org/abs/2607.19742">An Automated Framework for Extracting Reachable Attack Chains from Cyber Threat Intelligence Reports</a></p></li><li><p><a href="https://arxiv.org/abs/2607.18826">Cross-Agent Campaign Attribution: Linking Asynchronous Attacks Across <span>LLM</span> Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2607.18538">CryptanalysisBench: Can LLMs do Cryptanalysis?</a></p></li><li><p><a href="https://arxiv.org/abs/2607.18496">Towards an Automated Test of LLM Security Knowledge</a></p></li><li><p><a href="https://arxiv.org/abs/2607.18485">Trusted Credentials, Untrusted Behavior: Benchmarking LLM-Agent Security in High-Performance Computing</a></p></li><li><p><a href="https://arxiv.org/abs/2607.18108">GARAGE: Characterizing the Automation Boundary in LLM-based Attack Graph Generation</a></p></li><li><p><a href="https://arxiv.org/abs/2607.18063">Adaptive Adversaries: A Multi-Turn, Multi-LLM Benchmark for LLM Agent Security</a></p></li><li><p><a href="https://arxiv.org/abs/2607.05993">Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures</a></p></li><li><p><a href="https://www.aikido.dev/blog/benchmarking-ai-models-known-cves">Benchmarking 13 AI models on rediscovering known CVEs</a></p></li><li><p><a href="https://pwno.io/diff">Rolling the Diffs</a> - <strong>Pwno</strong> argues - <em><span>&#8220;we argue that the bottleneck in LLM vulnerability discovery is not </span>model capability<span>, but </span>codebase decomposition<span>. Along the research, we've discovered </span></em><code>.diff</code><em><span> are more interesting than we've presumed.&#8221;</span></em></p></li></ul></li></ul></li><li><p>Books</p><ul><li><p><a href="https://www.half-second.com/">Half a Second - The Backdoor That Almost Broke the Internet, and the Invisible Labor Beneath It</a> - an AI augmented production</p></li><li><p><a href="https://link.springer.com/book/10.1007/978-3-032-10073-3">Philosophy of Artificial Intelligence</a></p></li></ul></li><li><p>Events</p><ul><li><p><a href="https://jsac.jpcert.or.jp/">JSAC2027</a> - January, Tokyo - Call for Papers </p></li></ul></li></ul><p>Video of the week is a scene from Big Hero 6 &#8230; or from China recently.. </p><div id="youtube2-vpyO73jyx1g" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;vpyO73jyx1g&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/vpyO73jyx1g?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Finally finally the <a href="https://creators.spotify.com/pod/profile/national-cyber-security-c6/episodes/The-Ransomware-Ecosystem-e2hi088">NCSC&#8217;s podcast series</a>.</p><div><hr></div><p><em>Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them. </em></p><p><em>This newsletter is subject to the NCSC website terms and conditions which can be found at <a href="https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions">https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions</a> and you can find out more about how will treat your personal information in our privacy notice at <a href="https://www.ncsc.gov.uk/section/about-this-website/privacy-statement">https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.</a></em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CTO at NCSC - Cyber Defence Analysis! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CTO at NCSC Summary: week ending July 19th]]></title><description><![CDATA["A national public awareness campaign will be launched to help the public prepare for emergencies like extreme weather and cyber attacks"]]></description><link>https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-july-50a</link><guid isPermaLink="false">https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-july-50a</guid><dc:creator><![CDATA[Ollie Whitehouse]]></dc:creator><pubDate>Sat, 18 Jul 2026 08:35:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!jntl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d2059ca-e736-4593-b82f-e2a16335587b_1429x872.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to the weekly highlights and analysis of the&nbsp;<a href="https://infosec.pub/c/blueteamsec?dataType=Post&amp;sort=New">blueteamsec</a>&nbsp;(and my wider reading). Not everything makes it in, but the best bits do. A community member is doing <a href="https://briefing.workshop1.net/">daily AI generated podcast of the last 24hours of posts</a>.</p><p>Operationally this week nothing of note but there was a allied response to Russian cyber activity which you will see through the below.</p><p>In the high-level this week:</p><ul><li><p><a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting"><span>UK and Allies urge critical sectors to improve defences against Russian intelligence targeting </span></a><span>- UK </span><strong><span>NCSC</span></strong><span> and allies urge - </span><em><span>&#8220;Alongside 18 agencies from 12 countries, the National Cyber Security Centre (NCSC) &#8211; a part of GCHQ &#8211; has published a new advisory highlighting the methods of Federal Security Service (FSB) Centre 16 cyber actors, who are exploiting vulnerable routers and opportunistically targeting networks belonging to critical national infrastructure (CNI) globally.&#8221;</span></em></p></li><li><p><a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions">UK and EU strike Russian cyber networks with new sanctions</a> - <strong>Foreign, Commonwealth &amp; Development Office</strong><span> and </span><strong>The Rt Hon Yvette Cooper MP </strong>announce - <em>&#8220;UK and EU&#8239;hit back with first joint cyber sanctions package,&#8239;as they attribute Russia&#8217;s cyber-attack&#8239;on Poland.&#8239;&#8239;&#8220;</em>  &#8230; <em>&#8220;UK sanctions and exposes Russian state and&#8239;cybercriminal&#8239;proxies carrying out malicious attacks across Europe and sanctions&#8239;those deliberately spreading deceptive anti-Ukraine narratives.&#8239;&#8239;&#8220;</em></p><ul><li><p><a href="https://www.gov.uk/government/publications/profile-gru-cyber-and-hybrid-threat-operations">Profile: GRU cyber and hybrid threat operations</a> - <strong>Foreign, Commonwealth &amp; Development Office</strong><span>, </span><strong>Home Office</strong><span>, </span><strong>Cabinet Office</strong><span> and </span><strong>National Cyber Security Centre </strong>update</p></li></ul></li><li><p><a href="https://www.ncsc.gov.uk/blogs/helping-small-businesses-with-free-hands-on-cyber-consultancy"><span>Helping small businesses with free, hands-on cyber consultancy</span></a><span> - UK </span><strong><span>NCSC</span></strong><span> announce - </span><em><span>&#8220;Cyber Advisors are offering free 30-minute consultations to help small businesses get started with cyber security.&#8221;</span></em></p></li><li><p><a href="https://www.gov.uk/government/publications/national-risk-register-2026">National Risk Register 2026</a> - UK <strong>Cabinet Office</strong> publishes - various cyber risk..</p><ul><li><p><a href="https://www.gov.uk/government/news/risk-of-democratic-interference-added-to-national-risk-register">Risk of democratic interference added to National Risk Register </a>- <strong>Cabinet Office</strong><span>, </span><strong>Dame Angela Eagle DBE MP</strong><span>, </span><strong>Louise Sandher-Jones MP</strong><span> and </span><strong>The Rt Hon Darren Jones MP </strong>announce -  &#8220;Interference in democratic process and cyber attacks have been added to the National Risk Register&#8221;</p></li></ul></li><li><p><a href="https://www.gov.uk/government/publications/model-action-plan-for-responding-to-significant-data-breaches">Model Action Plan for Responding to Significant Data Breaches</a> - UK <strong>Cabinet Office</strong> publishes - <em>&#8220;The Model Action Plan is a cross-government framework for all departments and arms-length bodies to follow when responding to significant personal data breaches&#8221;</em></p></li><li><p> <a href="https://www.gov.uk/government/publications/uk-action-against-russian-foreign-information-warfare/new-uk-action-against-foreign-information-warfare">UK action against Russian foreign information warfare</a> - UK <strong><span>Foreign, Commonwealth &amp; Development Office</span></strong><span> detail - </span><em><span>&#8220;We are scaling cooperation with European partners on hybrid and information threats, including through the </span>UK<span>-</span>EU<span> Security and Defence Partnership, and through deep cooperation between teams in the </span>UK<span>, in France, Germany, Poland and Brussels, to deliver a pan-European response to a pan-European threat.&#8221;</span></em></p></li><li><p><a href="https://www.gov.uk/government/publications/revised-telecommunications-security-code-of-practice-2026-version-11/telecommunications-security-code-of-practice-2026-version-11">Telecommunications Security Code of Practice 2026 (version 1.1)</a> - UK <strong><span>Department for Science, Innovation &amp; Technology</span></strong><span> publishes - revised version published</span></p><ul><li><p><a href="https://www.gov.uk/government/publications/revised-telecommunications-security-code-of-practice-2026-version-11/draft-revised-telecommunications-security-code-of-practice-change-log">Change log</a></p></li></ul></li><li><p><a href="https://developer.chrome.com/blog/nhs-passkeys-case-study"><span>How NHS England improved sign-in times and saved over &#163;1m with passkeys</span></a><span> - </span><strong>Yu Tsuno</strong>, <strong>Darren Hutton</strong> and <strong>Pelin Dem</strong> publish - <em>&#8220;<span>Key results</span></em></p><ul><li><p><em>Reduced sign-in time: Users authenticate 8x faster using passkeys. Median sign-in times dropped from 43 seconds (password + SMS OTP) to just 5 seconds using Conditional UI.</em></p></li><li><p><em>High adoption and scale: 6.7 million passkeys created by users since the feature launched two years ago, driving 6 million passkey sign-ins every month.</em></p></li><li><p><em>Lower transaction costs: Up to &#163;1.2M saved on OTP costs since launch.&#8221;</em></p></li></ul></li><li><p><a href="https://www.gov.uk/government/calls-for-evidence/data-flows-you-can-trust/data-flows-you-can-trust"><span>Open call for evidence </span>Data flows you can trust</a> - UK <strong><span>Department for</span><br><span>Science, Innovation &amp; Technology</span></strong><span> calls for evidence - </span><em><span>&#8220;This work will help us to shape how data is used so that we can maximise its potential, drive growth and improve lives across the UK. This Call for Evidence seeks practical, experience-based insight into whether the UK&#8217;s data regime is enabling data flows you can trust. We want to understand:&#8239;does the UK&#8217;s approach to international data transfers achieve this as effectively as it can do? Where should we preserve the current system, and what parts of it are most suitable for reform?&#8239;&#8220;</span></em></p></li><li><p><a href="https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/">Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements</a> - US <strong>Department of War</strong> announces - <em>&#8220;The Department of War today announces the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which were originally scheduled to come into effect on November 10, 2026. All Phase I self-assessment requirements remain firmly in place.&#8221;</em></p></li><li><p><a href="https://www.ft.com/content/44351c74-03c8-45ab-823b-5805c0daca5f?syn-25a6b1a6=1">US military smartphones targeted through roaming and ad tech</a> - <strong>Financial Times</strong> reports - <em>&#8220;The data, shared with the FT by the Mobile Surveillance Monitor research project, shows regional telecom networks fending off a wave of requests, called SS7 pings. These sought to pin down the locations of specific phones roaming outside their home networks, in what two cyber security experts who reviewed the data said suggested a co-ordinated campaign. Officials in the Gulf suspected Iran or its allies of exploiting roaming agreements with local phone providers to try to locate US personnel, one person familiar with the matter said.&#8221;</em></p></li><li><p><a href="https://www.congress.gov/bill/119th-congress/senate-bill/4784?hl=S.+4784&amp;s=8&amp;r=1">National Defense Authorization Act for Fiscal Year 2027</a> - <strong>US Congress</strong> publishes subject to vote- <em>&#8220;In general.--Not later than March 1, 2027, the Secretary may establish a pilot program under the operational authority of the Commander of United States Cyber Command, to assess the feasibility and advisability of conducting cyber operations limited to access generation and maintenance through contractor owned, contractor operated means, subject to the limitations in subsection b&#8221;</em></p></li><li><p><a href="https://cip.gov.ua/en/news/cert-ua-opracyuvala-3309-kiberincidentiv-v-pershomu-pivrichchi-2026-roku">CERT-UA Handled 3,309 Cyber Incidents in the First Half of 2026</a> - <strong>Service of Special Communications and Information Protection of Ukraine</strong> detail - <em>&#8220;the highest concentration of cyber incidents targeted local self-government bodies, government organisations, the security and defence sector, and the energy industry.&#8221;</em></p></li><li><p><a href="https://www.microsoft.com/en-us/trust-center/security/secure-future-initiative/sfi-progress-report-july-2026">July 2026 SFI progress report</a> - <strong>Microsoft</strong> detail - <em>&#8220;Phishing-resistant MFA enforcement has reached broad maturity with 99.97% user and device coverage.&#8220;</em></p><ul><li><p><em>&#120819;&#120815;&#120814;,&#120812;&#120812;&#120812;+ resources have had public access revoked</em></p></li><li><p><em>&#120813;.&#120816; &#120314;&#120310;&#120313;&#120313;&#120310;&#120316;&#120315; unused apps decommissioned</em></p></li><li><p><em>&#120817;&#120817;&#120812;,&#120812;&#120812;&#120812;+ critical and high risk open source vulnerabilities remediated</em></p></li><li><p><em>~&#120815; &#120314;&#120310;&#120313;&#120313;&#120310;&#120316;&#120315; container vulnerabilities patched per month through automation</em></p></li></ul></li><li><p><a href="https://securityandtechnology.org/blog/whats-in-a-norm/">What&#8217;s in a Norm?</a> - <strong>Institute for Security + Security</strong> asks - <em>&#8220;<span>Policymakers regularly talk about &#8220;norms of responsible state behavior in cyberspace&#8221;&#8212;for good reason. </span><a href="https://unidir.org/files/2019-10/GGE-Recommendations-International-Law.pdf"><span>The norms, articulated by the Group of Governmental Experts (GGE) convened under the auspices of the United Nations</span></a><span> and affirmed by all UN members for over a decade, reflect a global consensus about what should and should not be allowable in peacetime cyber operations.&#8221;</span></em></p></li><li><p>Reporting on/from China</p><ul><li><p><a href="https://www.cnbc.com/2026/07/07/hesai-technology-nvidia-cyber-risk.html">Chinese lidar maker with Nvidia ties accused of being cyber risk for U.S.</a> - <strong>CNBC</strong> reports - <em>&#8220;<span>Craig Singleton is a senior director for the China Program at the Foundation for Defense of Democracies, a conservative Washington-based think tank known for being critical of the Chinese government. His</span><a href="https://www.fdd.org/wp-content/uploads/2024/12/fdd-memo-laser-focus-countering-chinas-lidar-threat-to-u.s.-critical-infrastructure-and-military-systems.pdf"> research</a><span> has concluded that there are security risks in Chinese-made sensors operating in U.S. systems, including that lidar sensors could enable Beijing &#8220;to access sensitive U.S. data or disrupt critical operations.&#8221; - </span></em><span>the component debate is interesting and it depends how far you want to go down the rabbit hole coupled with the complexity of operationalisation of the opportunity in reality. </span></p></li><li><p><a href="https://www.cnbc.com/2026/07/08/chinese-ai-models-probe-us-lawmakers.html">Lawmakers probe growing use of Chinese AI models in U.S. companies</a> - <strong>CNBC</strong> reports - <em>&#8220;The Committees are also examining whether the United States has a sufficient open-weight AI strategy to ensure American companies and cyber defenders are not forced to choose between expensive or restricted U.S. models and cheap, capable PRC-developed alternatives,&#8221; a Committee aide, who asked not to be named as they were not authorized to discuss the ongoing probe, told CNBC.&#8221;</em></p></li><li><p><a href="https://aisafetychina.com/">State of AI Safety in China</a> - <strong>Concordia</strong> publishes - <em>&#8220;The arrival of autonomous agents reoriented Chinese governance from controlling what AI says to controlling what it does.<span> After the open source agent OpenClaw proliferated in early 2026, multiple cybersecurity authorities issued warnings, and in May 2026 the Cyberspace Administration of China (CAC) and two other agencies issued dedicated guidance on agentic AI, devoting a full chapter to safety and proposing risk-based governance. Several major AI standard-setting bodies are now drafting agent-related security standards.&#8221;</span></em></p></li><li><p><a href="https://www.tandfonline.com/doi/full/10.1080/09668136.2026.2678270"><span>One Game, Two Strategies: China and Russia&#8217;s Divergent Approaches to Micro-Cyber Sovereignty</span></a><span> - </span><strong><span>Xi&#8217;an Jiaotong University</span></strong><span> re-examines - </span><em><span>&#8220;This study re-examines the assumption that China and Russia have adopted similar strategies for advancing cyber sovereignty. Drawing on two-level game theory, it argues that China has adopted a two-level model, where domestic regulation and international engagement operate in parallel through norm diffusion. In contrast, Russia pursues a one-level model in which domestic cybersecurity concerns are aligned with its international legal initiatives, emphasising consistency between internal regulation and its advocacy for binding global norms.&#8221;</span></em></p></li><li><p><a href="https://www.science.org/content/article/new-nsf-policy-would-ban-almost-all-collaborations-chinese-scientists">New NSF policy would ban almost all collaborations with Chinese scientists</a> - <strong>Science</strong> reports - <em>&#8220;The U.S. National Science Foundation (NSF) has decided to ban collaborations between every U.S. scientist it funds and nearly all Chinese research institutions and their employees. The new policy abandons NSF&#8217;s earlier attempt to balance the potential risks and benefits of such collaborations. But it puts the agency in step with actions taken earlier this year by the much larger Department of Defense (DOD) and with congressional Republicans, who assert that any interactions with China threaten national security.&#8221;</em></p></li><li><p><a href="https://www.scmp.com/news/china/politics/article/3359886/chinas-xi-jinping-calls-innovation-system-overhaul-beat-global-tech-rivals"><span>China&#8217;s Xi Jinping calls for innovation system overhaul to beat global tech rivals</span></a><span> - </span><strong><span>South China Morning Post</span></strong><span> reports - </span><em><span>&#8220;President Xi Jinping has called for stronger efforts to draw overseas talent and address flaws in China&#8217;s innovation ecosystem, as intensifying tech rivalry pushes Beijing to bolster its global competitiveness.&#8221;</span></em></p></li></ul></li><li><p> AI</p><ul><li><p><a href="https://post.parliament.uk/artificial-intelligence-for-cyber-resilience/">Artificial intelligence for cyber resilience</a> - <strong>UK Parliament published </strong>in June - <em>&#8220;<span>AI may be able to improve cyber resilience by:</span></em></p><ul><li><p><em><span>identifying unusual activity in a computer network and addressing threats in real time</span></em></p></li><li><p><em><span>detecting evolving fraud patterns and flag AI-generated phishing emails</span></em></p></li><li><p><em><span>performing &#8216;predictive maintenance&#8217;, including anticipating system failures and detecting software vulnerabilities</span></em></p></li><li><p><em><span>summarising incidents and recommend responses to security operations centres</span></em></p></li><li><p><em><span>analysing third-party risks to vendor and supply chains using public data&#8221;</span></em></p></li></ul></li><li><p><a href="https://www.aisi.gov.uk/blog/how-far-behind-the-frontier-are-leading-open-weight-models-on-cyber">How Far Behind the Frontier are Leading Open Weight Models on Cyber?</a> - UK <strong>AI Security Institute</strong> publish - <em>&#8220;We evaluated the cyber capabilities of leading open and closed weight AI models, and found that recent open models GLM-5.2 and DeepSeek V4-Pro perform similarly to frontier closed models released 4 to 7 months before them &#8211; a narrower gap than the 6 to 10 months we measured through most of 2025.&#8221;</em></p></li><li><p><a href="https://research.google/pubs/co-redteam-orchestrated-security-discovery-and-exploitation-with-llm-agents/">Co-RedTeam: Orchestrated Security Discovery and Exploitation with LLM Agents</a> - <strong>Google</strong> publish - <em>&#8220;Extensive evaluations on challenging security benchmarks demonstrate that Code-RedTeam consistently outperforms strong baselines across diverse backbone models, achieving over 60% attack success rate in vulnerability exploitation and up to 10% absolute improvement in vulnerability detection.&#8221;</em></p></li><li><p><a href="https://virtual-routes.org/pharos-report-no-5/">Navigating Security in the Machine Learning and AI Supply Chain: What Policymakers Need to Know</a> - <strong>Max Smeets, Anna Sophie den Ouden,</strong><span> and </span><strong>James Shires</strong><span> </span>think tanks - <em>&#8220;the report breaks the machine learning and AI supply chain into three levels: the data level, the model level, and the deployment level. Across these levels, malicious actors exploit trust, complexity, and limited visibility.&#8221;</em></p></li><li><p><a href="https://insidecybersecurity.com/share/18201">Former ONCD official Rajan sees opportunity for White House-led push utilizing formal methods to verify security of frontier AI models</a> - <strong>Inside Cyber Security</strong> reports - <em>&#8220;The Office of the National Cyber Director should play a larger role in working with other agencies to establish formal methods that mathematically prove software used by frontier AI models is secure from vulnerabilities, according to former tech security lead Anjana Rajan.&#8221;</em></p></li><li><p><a href="https://www.scmp.com/tech/tech-trends/article/3360115/next-frontier-ai-how-world-models-are-simulating-reality-and-virtual-spaces?module=top_story&amp;pgtype=section"><span>The next frontier of AI: how &#8216;world models&#8217; are simulating reality and virtual spaces</span></a><span> - </span><strong><span>South China Morning Post</span></strong><span> reports - </span><em><span>&#8220;</span>The renewed interest reflects the rapid rise of AI agents and <a href="https://archive.ph/o/lj3VS/https://www.scmp.com/topics/robotics">robotics,</a> where simply generating text or video is no longer enough. Increasingly, AI systems are expected to predict how environments will respond to actions before they are taken. Unlike conversational AI like ChatGPT, which predicts the next word in a sentence, a world model predicts the next state of a physical environment. What makes the current wave distinct is that companies are building their products based on fundamentally different interpretations of what a &#8220;world&#8221; should be.&#8221;</em></p></li><li><p><a href="https://www.weco.ai/blog/first-evidence-of-recursive-self-improvement">AIDE&#178;: The First Evidence of Recursive Self-Improvement</a> - <strong>Weco</strong> assert - <em>&#8220;<span>We built a recursive self-improvement (RSI) system by running autoresearch on autoresearch. The system, AIDE</span><sup>2</sup><span>, took eight days to discover a better autoresearch harness than the one we built over the last two years. Fully autonomously, AIDE</span><sup>2</sup><span> designed a novel search algorithm, reduced the prompt size by 16&#215;, and built a layered system against reward hacking.&#8221;</span></em></p></li><li><p><a href="https://newsletter.semianalysis.com/p/the-future-of-meta-superintelligence?hide_intro_popup=true">The Future of Meta Superintelligence: A 1 Year Progress Update</a> - <strong>Semi Analysis</strong> analyses - <em>&#8220;<span>Data is the new oil (for real this time) - We&#8217;ll start with data because it&#8217;s Meta&#8217;s newest advantage and probably the most underappreciated of the three. In 2024, Ilya famously said that &#8220;data is the fossil fuel of AI.&#8221; While this analogy correctly highlights the importance of data for training AI models, it incorrectly assumes that the amount of good data is finite. In reality, if demand is strong enough, market forces will find a way.&#8221;</span></em></p></li><li><p><a href="/__u/polymath707.substack.com/p/huaweis-strategy-applying-tau-scaling">Huawei&#8217;s plan to achieve the escape velocity: Applying Tau Scaling to entire AI datacenters</a> - <strong>Polymath707</strong> breaks down - <em>&#8220;<span>The bet this essay has described is not a one-generation trick that a rival node shrink erases. It is a claim that for the next decade the binding constraint on AI hardware is </span>topological<span>: about how memory, power, and fabric reach the compute; and that Huawei has organized its entire roadmap, from the Unified Bus outward to the folded package, around winning on that axis rather than the transistor axis western companies are able to race down.&#8221;</span></em></p></li><li><p><a href="https://ai-2040.com/">AI 2040 Plan A</a> - <strong><span>Thomas Larsen, Romeo Dean, Brendan Halstead, Eli Lifland, Ryan Greenblatt </span></strong><span>and</span><strong><span> Daniel Kokotajlo</span></strong><span> propose - something which largely is in impractical but interesting nevertheless that one would consider - that is an agree slowdown between China and the US</span></p></li></ul></li><li><p><em>Cyber proliferation</em></p><ul><li><p><a href="https://www.theguardian.com/news/2026/jul/16/morocco-intelligence-insider-reveals-widespread-use-hacking-software-pegasus">Moroccan intelligence insider reveals widespread use of Pegasus hacking software</a> - <strong>The Guardian</strong> reports - &#8220;<em>A Spanish mobile number belonging to Aminatou Haidar, a prominent human rights activist from Western Sahara, was included in the leaked database and found to have been targeted by Pegasus dating back to 2018.&#8221;</em></p></li></ul></li><li><p>Bounty Hunting</p><ul><li><p><a href="https://www.nationalcrimeagency.gov.uk/news/two-sentenced-for-hacking-transport-for-london-in-uk-s-biggest-ever-cyber-crime-case">Two sentenced for hacking Transport for London in UK&#8217;s biggest ever cyber crime case</a> - UK <strong>National Crime Agency</strong> announce - &#8220;<em>All 27,000 of TfL&#8217;s employees were forced to attend a TfL office for a password reset and a total of 148 systems became inoperable, including critical ones that required significant manual workarounds and delays. The organisation, which reported the incident to CoLP&#8217;s Report Fraud service, suffered a reported &#163;29 million in loss and recovery costs.&#8221;</em></p></li><li><p><a href="https://www.justice.gov/usao-ndoh/pr/three-russian-nationals-indicted-international-cybercrimes-resulting-more-62m-losses"><span>Three Russian Nationals Indicted for International Cybercrimes Resulting in More Than $62M in Losses to Victims</span></a><span> - US </span><strong><span>Department of Justice</span></strong><span> announce - </span><em><span>&#8220;The U.S. Attorney&#8217;s Office for the Northern District of Ohio has announced the unsealing of an indictment charging three Russian nationals for their roles in malicious cyber activities against U.S. critical infrastructure affecting victims in 21 states and in several countries, with losses amounting to tens of millions of dollars. These charges are the result of a seven-year-long investigation.&#8221;</span></em></p></li><li><p><a href="https://www.justice.gov/opa/pr/man-serving-federal-prison-sentence-charged-theft-forfeited-cryptocurrency"><span>Man Serving Federal Prison Sentence Charged with Theft of Forfeited Cryptocurrency</span></a><span> - US </span><strong><span>Department of Justice </span></strong><span>announce - </span><em><span>&#8220;Having been convicted of a widespread online auction fraud scheme targeting U.S. victims, Iossifov is now charged with moving cryptocurrency that he obtained from that crime, in violation of a court&#8217;s forfeiture order,&#8221;</span></em></p></li><li><p><a href="https://www.reuters.com/legal/government/russian-man-pleads-not-guilty-us-cyber-espionage-case-2026-07-09/">Russian man pleads not guilty in US cyber espionage case</a> - <strong>Reuters</strong> reports - <em>&#8220;A Russian man whom U.S. prosecutors say previously worked for Russia's &#8204;FSB intelligence agency pleaded not guilty on Thursday to a charge that he participated in a cyber espionage campaign that a technology company conducted against Western organizations.&#8221;</em></p><ul><li><p><a href="https://www.reuters.com/world/alleged-russian-cyber-spy-boston-case-previously-worked-kaspersky-source-says-2026-07-15/">Alleged Russian cyber spy in Boston case previously worked for Kaspersky, source says and documents show</a> - <strong>Reuters</strong> reports - <em>&#8220;Although the alleged hacking activity took place after he left Kaspersky, Obrezko&#8217;s background is likely to draw further attention to the company&#8217;s relationship with the Russian government.&#8221;</em></p></li></ul></li><li><p><a href="https://www.asahi.com/ajw/articles/16703618">Teen accused of using ChatGPT to delete 46,000 anime accounts</a> - <strong>The Ashai Shimbun</strong> report - <em>&#8220;Tokyo police on July 6 arrested a 15-year-old boy who has admitted to using AI-powered ChatGPT to build a program that forcibly deleted 46,000 accounts on anime streaming service &#8220;Bandai Channel,&#8221; sources said.&#8221;</em></p></li><li><p><a href="https://www.bbc.co.uk/news/articles/cy8w379e091o"><span>Apple sues OpenAI, its employees claiming theft of trade secrets</span></a><span> - </span><strong><span>BBC</span></strong><span> reports - </span><em><span>&#8220;At least two long-time Apple workers who left the company to join OpenAI allegedly took part in this pattern by, in part, emailing themselves internal Apple information.&#8221;</span></em></p><ul><li><p><a href="https://www.courtlistener.com/docket/73602437/apple-inc-v-liu/">Court papers</a></p></li></ul></li><li><p>..</p></li></ul></li><li><p>Market Incentives</p><ul><li><p><a href="https://www.gov.uk/government/publications/novel-autonomy-and-robotics-phase-1/novel-autonomy-robotics-competition-document">Novel Autonomy &amp; Robotics Competition Document</a> - UK <strong>Defence Innovation</strong> publishes - <em>&#8220;On receipt of a FUND decision, successful innovators (and their sub-contractors) must prove cyber resilience before the contract is awarded.&#8221;</em></p><p></p></li></ul></li></ul><p>Reflections this week are read the headlines of the footnotes section on AI applied to cyber security. The level of investment grows each week, volume of papers increase - so even if they&#8217;re not there today it is clear we are going to get workable solutions which mean humans can be removed from in and on the loop.</p><p>Not getting this via email? Subscribe:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Think someone else would benefit? Share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-july-50a?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-july-50a?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p><strong>All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.</strong></p><p>Have a lovely Saturday&#8230;</p><p>Ollie</p><h1>Cyber threat intelligence</h1><p>Who is doing what to whom and how allegedly.</p><h2>Reporting on Russia</h2><h3>Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting</h3><p><strong>United States National Security Agency (NSA), United States Cybersecurity and Infrastructure Security Agency (CISA), United States Federal Bureau of Investigation (FBI), United States Department of Defense Cyber Crime Center (DC3), Australian Signals Directorate&#8217;s Australian Cyber Security Centre (ASD&#8217;s ACSC), Communications Security Establishment Canada&#8217;s (CSE&#8217;s) Canadian Centre for Cyber Security (Cyber Centre), New Zealand National Cyber Security Centre (NCSC-NZ), United Kingdom National Cyber Security Centre (NCSC-UK), Czech Republic National Cyber and Information Security Agency (N&#218;KIB), Danish Defence Intelligence Service (DDIS), Estonian Foreign Intelligence Service (EFIS), Estonian Information System Authority (RIA), Finnish Defence Intelligence (FDI), Finnish Security and Intelligence Service (SUPO), French National Cybersecurity Agency (ANSSI), Italian External Intelligence and Security Agency (AISE), Italian Internal Intelligence and Security Agency (AISI), The Military Counterintelligence Service of Poland (SKW)</strong> and <strong>Sweden National Cyber Security Centre (NCSC-SE)</strong> assemble like the avengers with this release focusing on the need to improve router hygiene. Also a reminder that all vendors should implement our <strong><a href="https://www.ncsc.gov.uk/guidance/guidance-on-digital-forensics-protective-monitoring">guidance on digital forensics and protective monitoring specifications for producers of network devices and appliances - for device vendors</a></strong>.</p><blockquote><p>Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds on FBI&#8217;s Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure Public Service Announcement of the decadeplus FSB Center 16 cyber activity by providing additional tactics, techniques, and procedures (TTPs) to enable defenders to more fully understand and counter the threat.</p></blockquote><p><a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF">https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF</a></p><h3>Targeting and Compromise of French Entities Using the Turla Intrusion Set</h3><p><strong>Government of France</strong> attributes and detail this alleged Russian operation against French entities. The government targeting will be of note as will the stated purpose.</p><blockquote><p>Members of the Cyber Crisis Coordination Centre (C4) have observed the targeting and compromise of French entities using the Turla intrusion set operated by the 16th Centre of the Federal Security Service of the Russian Federation (FSB). Since at least 2004, this intrusion set has been implemented for intelligence-gathering purposes against strategic entities and individuals worldwide, including in France. The French intermediate and final victimology of the Turla intrusion set notably includes ministries, entities in the diplomatic, defence, justice, and technology sectors. Espionage campaigns associated with the Turla intrusion set against Ukraine, NATO countries, and EU member states continue in the context of Russia&#8217;s war of aggression launched on February 24, 2022. </p></blockquote><p><a href="https://cert.ssi.gouv.fr/cti/CERTFR-2026-CTI-005/">https://cert.ssi.gouv.fr/cti/CERTFR-2026-CTI-005/</a></p><p><a href="https://www.diplomatie.gouv.fr/fr/presse-et-ressources/decouvrir-et-informer/actualites/attribution-a-la-russie-d-activites-cyber-malveillantes-a-des-fins-d-espionnage-en-france">https://www.diplomatie.gouv.fr/fr/presse-et-ressources/decouvrir-et-informer/actualites/attribution-a-la-russie-d-activites-cyber-malveillantes-a-des-fins-d-espionnage-en-france</a></p><h3>Advisory Russian state actors are compromising IP cameras</h3><p><strong>Netherlands General Intelligence and Security Service (AIVD)</strong> and the Netherlands <strong>Defence Intelligence and Security Service (MIVD)</strong> disclose and detail this alleged Russian operation against IP cameras. This should serve as a warning to focus on the cyber security of such infrastructure which can be repurposed for cyber-physical intelligence gain.</p><blockquote><p>illustrates that Russian state actors are systematically conducting digital espionage operations via IP cameras (cameras with internet access). At least one Russian intelligence and security service is responsible for these operations that are taking place in the Netherlands, various other EU and NATO member states and Ukraine. This cybersecurity advisory concludes with actionable recommendations to mitigate the risks of espionage via IP cameras.</p></blockquote><p><a href="https://english.aivd.nl/documents/2026/07/10/brochure-cybersecurity-advisory-russian-state-actors-are-compromising-ip-cameras">https://english.aivd.nl/documents/2026/07/10/brochure-cybersecurity-advisory-russian-state-actors-are-compromising-ip-cameras</a></p><h3>UAC-0145 Primary Compromise Vectors as of July 2026</h3><p><strong>Ukraine CERT</strong> detail the alleged initial access tradecraft of this alleged Russian threat actor. The detection opportunities here are strong.. </p><blockquote><p>As a rule, the implementation of the malicious plan was carried out using the already known software tools <strong>KALAMBUR</strong> , <strong>SUMBUR</strong> , <strong>TAMBUR</strong> , and unauthorized remote access was primarily provided using legitimate programs OPENSSH and TOR, which provided forwarding of local network ports (in particular, 445, 3389, 22) to a remote server, actually publishing them within the infrastructure controlled by the attackers. In addition, software tools for stealing keys and data of the messengers Signal, WhatsApp, for the exfiltration of which RSYNC could be used, became widespread.</p></blockquote><p><a href="https://cert.gov.ua/article/6318437">https://cert.gov.ua/article/6318437</a></p><h3>Burnt by Burgers: Highlighting Void Blizzard&#8217;s Russian State Links</h3><p><strong>Ctrl-Alt-Intel</strong> conduct open source intelligence and alleged further links to the Rusian state than stated in indictment and affidavit. </p><blockquote><p>Identifiers attributed to <em>Obrezko</em> by the FBI appear alongside an <em>IAC EMERCOM</em>-associated work number and repeated weekday food deliveries to EMERCOM facilities during 2021. Taken together, these findings support our high-confidence assessment that <em>Obrezko</em> worked at, or regularly operated from, <em>IAC EMERCOM</em>.</p><p>Public records add further context around <em>Yutek-NN</em>: an FSB-issued licence for surveillance-adjacent equipment, and publicly declared personnel movements in both directions between <em>Yutek-NN</em> and <em>IAC EMERCOM</em>. None of these findings independently proves that <em>Yutek-NN</em> conducted cyberespionage. Collectively, however, they show that the company has deeper connections to Russian state and security institutions than its public-facing website suggests.</p></blockquote><p><a href="https://ctrlaltintel.com/research/VoidBlizzard/">https://ctrlaltintel.com/research/VoidBlizzard/</a></p><p><br></p><h3>OkoBot: new sophisticated malware framework targets cryptocurrency users</h3><p><strong>Yaroslav Kikel</strong> details an alleged Russian-nexus campaign which lays down SSH. Allegedly criminally linked..</p><blockquote><p>TookPS is a downloader used for retrieving malicious commands and scripts from attacker-controlled servers to further propagate attacks. The first campaign using TookPS <a href="https://securelist.com/backdoors-and-stealers-prey-on-deepseek-and-grok/115801/">was discovered</a> in March&#8239;2025. At that time, malicious scripts delivered a Python&#8209;based infostealer along with a script that installed and configured an SSH tunnel on the victim&#8217;s machine. The <a href="https://securelist.com/tookps/116019/">next wave</a> appeared in April&#8239;2025: the payload was changed, and TookPS was used to deliver the TeviRAT malware with the same SSH installer.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!jntl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d2059ca-e736-4593-b82f-e2a16335587b_1429x872.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!jntl!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d2059ca-e736-4593-b82f-e2a16335587b_1429x872.png 424w, /__u/substackcdn.com/image/fetch/$s_!jntl!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d2059ca-e736-4593-b82f-e2a16335587b_1429x872.png 848w, /__u/substackcdn.com/image/fetch/$s_!jntl!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d2059ca-e736-4593-b82f-e2a16335587b_1429x872.png 1272w, /__u/substackcdn.com/image/fetch/$s_!jntl!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d2059ca-e736-4593-b82f-e2a16335587b_1429x872.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!jntl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d2059ca-e736-4593-b82f-e2a16335587b_1429x872.png" width="1429" height="872" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4d2059ca-e736-4593-b82f-e2a16335587b_1429x872.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:872,&quot;width&quot;:1429,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Original OkoBot infection chain&quot;,&quot;title&quot;:&quot;Original OkoBot infection chain&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Original OkoBot infection chain" title="Original OkoBot infection chain" srcset="/__u/substackcdn.com/image/fetch/$s_!jntl!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d2059ca-e736-4593-b82f-e2a16335587b_1429x872.png 424w, /__u/substackcdn.com/image/fetch/$s_!jntl!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d2059ca-e736-4593-b82f-e2a16335587b_1429x872.png 848w, /__u/substackcdn.com/image/fetch/$s_!jntl!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d2059ca-e736-4593-b82f-e2a16335587b_1429x872.png 1272w, /__u/substackcdn.com/image/fetch/$s_!jntl!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d2059ca-e736-4593-b82f-e2a16335587b_1429x872.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://securelist.com/okobot-framework-targets-cryptocurrency-wallets/120660/">https://securelist.com/okobot-framework-targets-cryptocurrency-wallets/120660/</a></p><p><br><br></p><h2>Reporting on China</h2><h3>Suspected Chinese Operators Use Claude Code and DeepSeek to Target Government and Financial Systems Across Four Countries</h3><p><strong>Hunt.io</strong> detail the use of AI by alleged Chinese operators in their intrusion campaign along with victimology. It is however of note this is not autonomous end to end - yet. But rather knowledge and productivity enhancement for discrete parts of the workflow.</p><blockquote><ul><li><p>The open directory on 112.213.124[.]132 exposed a full operational toolkit, including payloads, operator files and scripts, and victim-specific folders.</p></li><li><p>Infrastructure pivots identified 13 Hong Kong-based servers spanning four separate ASNs, three with shared SSH keys and TLS certificates, serving in a redundancy capacity.</p></li><li><p>Active exploitation of government systems in Afghanistan, Thailand, and Taiwan, with reconnaissance and phishing staging against U.S. government portals.</p></li><li><p>Scanning of 5,890+ government hosts across 10 countries with a Python-developed automated scoring scale.</p></li><li><p>Claude Code handled execution and session persistence while DeepSeek-v4-pro drove the reasoning, a two-model split documented across the recovered log files.</p></li></ul></blockquote><p><a href="https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion">https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion</a></p><h3>Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor</h3><p><strong>Symantec and Carbon Black</strong> detail alleged Chinese regional targeting which surfaced a new implant. The novel keyboard-layout DLL implant mechanism will be of note.</p><blockquote><ul><li><p>Backdoor.Daxin, the China-linked kernel-mode rootkit that Symantec first uncovered and exposed in 2022, is still operational. It was found running on a compromised host in Taiwan in 2026, more than four years after it was first uncovered.</p></li><li><p>On the same machine, the Symantec Threat Hunter Team discovered a previously unknown backdoor, Backdoor.Stupig, whose novel tradecraft may link it to the Daxin operation, though no code-level connection has been confirmed.</p></li><li><p>Stupig uses a technique not documented in any known malware family. A Trojanized keyboard-layout DLL loaded by winlogon.exe lets an attacker run commands as System directly from the Windows logon screen, before anyone signs in and without raising a logon audit event.</p></li><li><p>Both samples carry compile timestamps from early 2013, but the host was not reporting telemetry until May 2026. Combined with the actor&#8217;s known pattern of long-term, stealthy persistence, this suggests the intrusion may have gone undetected on the network for 13 years.</p></li><li><p>The victim was a Taiwan-based subsidiary of a multinational high-tech manufacturer.</p></li></ul></blockquote><p><a href="https://www.security.com/threat-intelligence/daxin-returns-stupig">https://www.security.com/threat-intelligence/daxin-returns-stupig</a></p><h3>Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident</h3><p><strong>Aaron Walton</strong> details the other end of the alleged Chinese cyber spectrum but also the fact they managed to allegedly compromise of a certificate authority. This is the alleged capability and intent of Chinese cyber crime in 2026.</p><blockquote><ul><li><p><span>Chinese cybercrime group, GoldenEyeDog, has been regularly updating their malware and tactics since 2015. We&#8217;ve observed them regularly leveraging code-signing certificates to bypass Windows&#8217;s SmartScreen since 2024.</span></p></li><li><p><span>They leverage several malware, including one we&#8217;ve seen primarily documented in Chinese language publications, and are calling it &#8220;Golden Gh0st RAT&#8221;.</span></p></li><li><p><span>In April 2026, GoldenEyeDog used their malware to access a support member&#8217;s device at DigiCert, a code-signing certificate provider, and leveraged their access to steal certificates intended for DigiCert customers. This attack highlighted the capability of the malware and operators.</span></p></li></ul></blockquote><p><a href="https://expel.com/blog/introducing-cylindricalcanine/">https://expel.com/blog/introducing-cylindricalcanine/</a></p><h2>Reporting on North Korea</h2><h3><span>Analysis of attack actions suspected to be from the APT-C-26 (Lazarus) group upgrading its monitoring program</span></h3><p><strong><span>360 Threat Intelligence Centre</span></strong><span> from China detail an alleged North Korean operation which is noteworthy for the monitoring they ended up laying down.</span></p><blockquote><p>In the attack process, various components of the organization worked together to not only build a covert remote desktop environment but also integrate keylogging capabilities, forming a comprehensive monitoring and control platform. This provided attackers with the ability to conduct multi-dimensional and continuous monitoring and control of the compromised host, significantly enhancing the efficiency of their data theft and intelligence gathering.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!O_Z7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8222aa8b-515c-4755-ab8f-86cb3be95081_744x707.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!O_Z7!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8222aa8b-515c-4755-ab8f-86cb3be95081_744x707.webp 424w, /__u/substackcdn.com/image/fetch/$s_!O_Z7!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8222aa8b-515c-4755-ab8f-86cb3be95081_744x707.webp 848w, /__u/substackcdn.com/image/fetch/$s_!O_Z7!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8222aa8b-515c-4755-ab8f-86cb3be95081_744x707.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!O_Z7!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8222aa8b-515c-4755-ab8f-86cb3be95081_744x707.webp 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!O_Z7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8222aa8b-515c-4755-ab8f-86cb3be95081_744x707.webp" width="744" height="707" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8222aa8b-515c-4755-ab8f-86cb3be95081_744x707.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:707,&quot;width&quot;:744,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="/__u/substackcdn.com/image/fetch/$s_!O_Z7!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8222aa8b-515c-4755-ab8f-86cb3be95081_744x707.webp 424w, /__u/substackcdn.com/image/fetch/$s_!O_Z7!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8222aa8b-515c-4755-ab8f-86cb3be95081_744x707.webp 848w, /__u/substackcdn.com/image/fetch/$s_!O_Z7!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8222aa8b-515c-4755-ab8f-86cb3be95081_744x707.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!O_Z7!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8222aa8b-515c-4755-ab8f-86cb3be95081_744x707.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://mp.weixin.qq.com/s/6hjjsEuuOTk8_FJrXWe9Ew">https://mp.weixin.qq.com/s/6hjjsEuuOTk8_FJrXWe9Ew</a></p><h3>BirdCall: ScarCruft Malware Masquerading as Zangi Messenger</h3><p><strong>S2W</strong> detail alleged North Korean use of repackaged application to gain initial access. Of note to those organisations who support APK side loading etc or application stores without controls / observability. </p><blockquote><ul><li><p>Another malicious app identified is the BirdCall malware, which masquerades as the Zangi messenger app.</p></li><li><p>It has been confirmed that the attacker repackaged the legitimate app to alter its entry point.</p></li><li><p>The BirdCall malware app uses dual Zoho WorkDrive accounts (cmdCloud and dataCloud) as C2 channels.</p></li><li><p>It steals information about infected devices and collected sensitive data, and supports a total of eight types of remote commands, enabling it to control devices, steal files, and re-collect data.</p></li><li><p>The stolen data is structured according to a sophisticated packet format defined within the malware and is encrypted and obfuscated using AES-256-CBC + zlib multi-layer encryption.</p></li><li><p>Additionally, when uploaded to Zoho WorkDrive, filenames are obfuscated through Base-26 encoding and packed into an 11-base structure.</p></li></ul></blockquote><p><a href="https://s2w.inc/en/resource/detail/1096">https://s2w.inc/en/resource/detail/1096</a></p><p><a href="https://s2w.medium.com/detailed-analysis-of-birdcall-malware-marsqurading-as-zangi-messenger-b80db8f5c320">https://s2w.medium.com/detailed-analysis-of-birdcall-malware-marsqurading-as-zangi-messenger-b80db8f5c320</a></p><h3><span>Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2</span></h3><p><strong>Genians</strong> details this alleged North Korean operation which uses well understood tradecraft which any moderately capable organisation should be able to defend against.</p><blockquote><ul><li><p><span>Initial access was carried out through spear-phishing emails disguised as materials for actual academic events and seminars.</span></p></li><li><p><span>Although the file was disguised as a PDF, it actually delivered a malicious ISO file through a cloud storage link.</span></p></li><li><p><span>The ISO contained an executable disguised as a PDF document, using the &#8220;.pdf&#8221;, &#8220;.pif&#8221; extension to induce the user to run it.</span></p></li><li><p><span>The attack loaded the shellcode payload into memory and injected a RokRAT variant into a process.</span></p></li><li><p><span>EDR and threat hunting policies should be strengthened to detect correlated ISO and PIF execution behaviors.</span></p></li></ul></blockquote><p><a href="https://www.genians.co.kr/en/blog/threat_intelligence/rokrat_capsule_vault">https://www.genians.co.kr/en/blog/threat_intelligence/rokrat_capsule_vault</a></p><h2>Reporting on Iran</h2><h3>Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026</h3><p><strong>Domain Tools</strong> provides their overview and assessment of this alleged hacktivist eco-system.</p><blockquote><p>The ecosystem operates through Telegram channels and websites, shared target lists, DDoS-for-hire tools, recycled breach data and leak-amplification campaigns. Attack claims and propaganda often appear within hours of kinetic events. This gives actors a deniable auxiliary role while keeping them separate from formal state structures.</p><p>Most activity remains technically unsophisticated. DDoS attacks, website defacements, and hack &amp; leak extortion-style messaging with exaggerated claims are more common than verified advanced intrusions. The strategic effect comes less from technical capability than from speed, visibility, and ideological framing that make it into news cycles. In practice these actors use cyber activity as scalable asymmetric information warfare. Even with limited high-end capability, loosely aligned ideological and state-adjacent networks can impose psychological, political, and economic pressure on adversaries during periods of regional crisis.</p></blockquote><p><a href="https://dti.domaintools.com/research/threat-intelligence-report-the-pro-iran-hacktivist-ecosystem-2026">https://dti.domaintools.com/research/threat-intelligence-report-the-pro-iran-hacktivist-ecosystem-2026</a></p><h2>Reporting on Other Actors</h2><h3>SharpViewStateKing: The stealthy implant framework</h3><p><strong>Canadian Centre for Cyber Security</strong> detail this unattributed by streatly implant framework which defence teams will want to assess if they have coverage of.</p><blockquote><p>In late December 2025, the Cyber Centre detected what appeared to be a web shell on a public-facing Microsoft Internet Information Services (IIS) server running a commercially available ASP.NET application. Incident response activities were initiated and analysis revealed that this web shell was part of a stealthy implant framework called SharpViewStateKing. This technical article aims to raise awareness, provide detection guidance, and highlight remediation actions associated with the malicious modules. What follows is derived from endpoint telemetry and process memory captured during the incident.</p></blockquote><p><a href="https://www.cyber.gc.ca/en/news-events/sharpviewstateking-stealthy-implant-framework">https://www.cyber.gc.ca/en/news-events/sharpviewstateking-stealthy-implant-framework</a></p><h3>Hidden Exfiltration Capability Discovered in a Trusted, 900,000-User Chrome Web store Extension</h3><p><strong>Charlie Kelly, Joss Moor, Sebastian Lacatusu</strong> and <strong>Silas Bryant</strong> detail this campaign which is noteworthy due to its scale and capability. </p><blockquote><p>We found dormant surveillance functionality in a trusted Chrome Web Store extension with around 900,000 users, including the ability to collect, encrypt and potentially exfiltrate browsing-domain data.</p><p>Underneath this genuine and functional header-editing tool, version 7.0.18 contains:</p><ul><li><p>A browsing history collection engine that fingerprints the device, encrypts each visited domain with a hardcoded AES-GCM key, and stages the data in a local database.</p></li></ul><ul><li><p>A prebuilt exfiltration channel designed to upload that encrypted history, roughly once per day, to a likely attacker-controlled endpoint <code>api.stanfordstudies.com</code>.</p></li></ul><ul><li><p>Install, update, and uninstall telemetry beaconed to a second third-party domain <code>extensions-hub.com</code>.</p></li></ul><ul><li><p>A content script that injects into every website visited and logs request metadata to a local store.</p></li></ul><p>In the version analysed, the exfiltration trigger is currently gated off by an empty allow-list, meaning that browsing-history upload is dormant in this build. Every other component (the encryption key, the endpoint, the scheduler, the storage) is present and functional.</p></blockquote><p><a href="https://stripeolt.com/knowledge-hub/threat-research/chrome-extension-hidden-data-exfiltration-900k-users/">https://stripeolt.com/knowledge-hub/threat-research/chrome-extension-hidden-data-exfiltration-900k-users/</a></p><h3><span>One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators</span></h3><p><strong>Lexfo CTI team</strong><span> detail this Adversary in The Middle phishing operator who further reenforce the business case for pervasive passkeys.</span></p><blockquote><ul><li><p style="text-align: justify;">A single misconfigured Python HTTP server exposed the complete operational stack of a live phishing operator, configs, logs, RMM installers, combolists, and Telegram session files.</p></li><li><p style="text-align: justify;">Three distinct threat actors were identified from one entry point: <strong>codemado</strong>, <strong>mail-argenta</strong>, and <strong>saroula01</strong>, each running independent campaigns on custom Evilginx forks sourced from the same public GitHub repositories.</p></li><li><p style="text-align: justify;"><strong>codemado</strong> is an Egyptian operator with roots in the hacking underground dating back to 2018, operating a full AiTM platform with a seven-tool RMM arsenal on a Budapest VPS.</p></li><li><p style="text-align: justify;"><strong>saroula01</strong>&#8216;s Device Code Flow campaign ran undetected for over a year, accumulating 218 confirmed victims across 12 countries, with tokens silently auto-refreshed in the background.</p></li><li><p style="text-align: justify;"><strong>mail-argenta</strong> is a Nigerian operator who was identified through infostealer logs containing his own credentials, including the MySQL password hardcoded in his phishing panel, reused across personal accounts.</p></li><li><p style="text-align: justify;">Both AiTM proxying and Device Code Flow abuse bypass MFA entirely.</p></li><li><p style="text-align: justify;"><strong>codemado&#8217;s MaDoO Blaster</strong> is promoted within RockyBelling&#8217;s The Quarry ecosystem, reported by SOCRadar&#8217;s investigation.</p></li><li><p style="text-align: justify;">All three operators built functional MFA-bypass infrastructure from public GitHub repositories with minimal customization, using AI-assisted development.</p></li></ul></blockquote><p><a href="https://blog.lexfo.fr/opendir-to-phishing-operator.html">https://blog.lexfo.fr/opendir-to-phishing-operator.html</a></p><h3>OAuth Client ID Spoofing: Why Fake Client IDs Are Gaining Traction for Stealthy Enumeration</h3><p><strong>Rachel Rabin</strong> details this technique which one can imagine Microsoft will look to tighten up.</p><blockquote><ul><li><p>Proofpoint has observed OAuth client ID spoofing emerging as a novel technique, increasingly leveraged in cloud campaigns.</p></li><li><p>Microsoft Entra ID returns different responses depending on whether a supplied OAuth client ID is valid and whether it corresponds to a registered application.</p></li><li><p>This behavior enables account enumeration without a registered OAuth application and allows attackers to infer password validity or account state without generating a successful sign&#8209;in event.</p></li><li><p>Researchers observed multiple campaigns at scale abusing spoofed OAuth application identifiers, with distinct tooling, infrastructure, and execution patterns indicating independent adoption by multiple threat actors.</p></li><li><p>To detect similar activity, defenders should monitor sign-in logs for events without an application name, which may indicate spoofed client IDs.</p></li></ul></blockquote><p><a href="https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy">https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy</a></p><h3>Software Supply Chain Incursions</h3><p><span>A reminder we issued guidance a number of weeks ago in </span><a href="https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies">Software supply chain attacks: check your dependencies</a><span> for software developers</span></p><ul><li><p><a href="https://research.jfrog.com/post/miasma-worm-returns-to-npm/">Miasma Worm Returns to npm</a></p></li><li><p><a href="https://socket.dev/blog/jscrambler-supply-chain-attack">jscrambler npm Package Compromised in Supply Chain Attack</a></p></li><li><p><a href="https://www.wiz.io/blog/m-red-team-asyncapi-supply-chain-compromise-via-github-actions">M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions</a></p></li><li><p><a href="https://safedep.io/malicious-nodemon-sudo-tslint-conf-npm-backdoor/">nodemon-sudo: an npm Backdoor With No Install Script</a></p></li></ul><p>A related interesting academic paper this week too<a href="https://arxiv.org/abs/2607.13965"> ProfMalPlus: Agent-Coordinated Detection of Malicious NPM Packages via Static-Dynamic Analysis Synergy</a></p><h1>Discovery</h1><p>How we find and understand the latent compromises within our environments.</p><h2>Use Unified Sign-In logs in Advanced Hunting</h2><p><strong>Fabian Bader</strong> is back with this master class..</p><blockquote><p><span>One thing that always makes analyzing Sign-In logs for Entra ID (Azure AD) users a bit complicated is the different types of Sign-In logs </span>available<span>.</span></p><p>..</p><p>This is where my KQL query comes in handy. It joines the two tables as one, renames the column to the original name and converts all to the same data type. And when you save it as a function, you can use it as if it where a built-in table.</p></blockquote><p><a href="https://cloudbrothers.info/en/unified-sign-logs-advanced-hunting/">https://cloudbrothers.info/en/unified-sign-logs-advanced-hunting/</a></p><h2>Stinger</h2><p><strong>Adel Ka</strong> provides cyber deception capability uplift this with this release. Speaking to other cyber deception vendors it is clear that the lure of tokens is too much..</p><blockquote><p>Stinger is an experimental endpoint deception tool for individual macOS and Linux workstations. It places decoy resources at likely collection points and records when a process interacts with them.</p><p>Malicious packages, compromised extensions, and infostealers can collect tokens, keys, browser data, or wallet material in a single run. On personal workstations, EDR and privileged file-access monitoring are often absent, while many canary tokens do not signal until collected bait is later rendered, fetched, resolved, or used. Stinger targets an earlier point: local interaction with the decoy during collection.</p></blockquote><p><a href="https://github.com/0x4D31/stinger">https://github.com/0x4D31/stinger</a></p><h2>tempolocus</h2><p><strong>Alexandre Dulaunoy</strong> releases this interesting solution to reduce the need to look at a time zone map and public holiday list.</p><blockquote><p>Tempolocus is a time-series activity patterns and approximate location inference</p></blockquote><p><a href="https://github.com/ail-project/tempolocus">https://github.com/ail-project/tempolocus</a></p><h2>Detections for LegacyHive exploitation</h2><p><strong>Kevin Beaumont</strong> releases this detection for this unpatched vulnerability.. </p><p><a href="https://github.com/GossiTheDog/ThreatHunting/blob/master/AdvancedHuntingQueries/LegacyHive.kql">https://github.com/GossiTheDog/ThreatHunting/blob/master/AdvancedHuntingQueries/LegacyHive.kql</a></p><h1>Defence</h1><p>How we proactively defend our environments.</p><h2>Writing Intune Endpoint Privilege Management rules for the real world: File hash, certificate, and when each one is the wrong choice</h2><p><strong><span>Mattias Melkersen</span></strong><span> and </span><strong><span>Simon Skotheimsvik</span></strong><span> provide defensive wisdom and a practical implementation approach for those in the Microsoft eco-system.</span></p><blockquote><p>But the underlying discipline is consistent. Identify files as precisely as the situation allows. Never rely on a weak attribute alone. Control what an elevated process is allowed to spawn. Test on a real standard user before you trust a rule. And structure your assignments so that conflict resolution works for you rather than surprising you.</p></blockquote><p><a href="https://msendpointmgr.com/2026/07/03/epm-part-3-writing-intune-endpoint-privilege-management-rules-for-the-real-world-file-hash-certificate-and-when-each-one-is-the-wrong-choice/">https://msendpointmgr.com/2026/07/03/epm-part-3-writing-intune-endpoint-privilege-management-rules-for-the-real-world-file-hash-certificate-and-when-each-one-is-the-wrong-choice/</a></p><h1>Incident Writeups &amp; Disclosures</h1><p>How they got in and what they did.</p><h2><span>Lessons from CISA&#8217;s Cyber Incident</span></h2><p><strong>Preston Werntz</strong>, Acting Chief Information Officer and <strong>Brad Libbey</strong>, Acting Chief Information Security Officer at CISA show world-leading transparency here.</p><blockquote><p>On Friday, May 15, CISA began an internal incident response when an investigative reporter inquired about internal CISA Amazon AWS GovCloud Keys and other information being made available in a public repository. The reporter received this information from a security researcher whose company continuously scans public code repositories.</p></blockquote><p><a href="https://www.cisa.gov/news-events/news/lessons-cisas-cyber-incident">https://www.cisa.gov/news-events/news/lessons-cisas-cyber-incident</a></p><h2><span>Security incident disclosure &#8212; July 2026</span></h2><p><strong><span>Hugging Face</span></strong><span> disclose</span></p><blockquote><p><span>Earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system - and we detected and dissected it largely with AI of our own.</span></p><p>We identified unauthorized access to a limited set of internal datasets and to several credentials used by our services. We are still completing our assessment of whether any partner or customer data was affected, and we will contact any affected parties directly as required. We have found no evidence of tampering with public, user-facing models, datasets, or Spaces, and our software supply chain (container images and published packages) was verified clean.</p></blockquote><p><a href="https://huggingface.co/blog/security-incident-july-2026">https://huggingface.co/blog/security-incident-july-2026</a></p><h1>Vulnerability</h1><p>Our attack surface.</p><h2>Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers</h2><p><strong>U.S. Cybersecurity and Infrastructure Security Agency, U.S. National Security Agency,  Japan Computer Emergency Response Team Coordination Center, Netherlands&#8217; National Cyber Security Centre</strong> and <strong>United Kingdom&#8217;s National Cyber Security Centre</strong> detail what good looks like</p><blockquote><p>This guide is authored by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and National Security Agency (NSA), the Japan Computer Emergency Response Team Coordination Center (JPCERT/CC), the Netherlands&#8217; National Cyber Security Centre (NCSC-NL), and the United Kingdom&#8217;s National Cyber Security Centre (NCSC-UK)&#8212;hereafter referred to as the &#8220;authoring organizations&#8221;&#8212;and provides best practices for suppliers to design and implement a CVD program to effectively work with security researchers. The authoring organizations recommend suppliers, especially software manufacturers, develop a CVD program aligned with the best practices outlined in this joint guide.</p></blockquote><p><a href="https://media.defense.gov/2026/Jul/14/2003961238/-1/-1/0/260714-D-AB123-1001.PDF">https://media.defense.gov/2026/Jul/14/2003961238/-1/-1/0/260714-D-AB123-1001.PDF</a></p><h2>VulnHunter</h2><p><strong>Vinay Vira, Scott Schenkein</strong> and <strong>Ieribo</strong> publish </p><blockquote><p>VulnHunter is an open-source, <strong>agentic AI security tool</strong> that applies proactive, attacker-first analysis directly to source code.</p><p>Unlike traditional, passive SAST scanners that flag suspicious patterns and often cause false positives, VulnHunter reasons like an adversary. It <strong>identifies</strong> which defects are actually exploitable, maps prospective attack paths, and proposes targeted, evidence-backed fixes.</p></blockquote><p><a href="https://github.com/capitalone/vulnhunter">https://github.com/capitalone/vulnhunter</a></p><h2>Zimbra 10.1.19</h2><p>Patch patch patch..</p><blockquote><p>The update fixes a security issue in the Classic Web Client where a specially crafted email could run malicious code when the email is opened. If exploited, it could allow access to mailbox information, session data, or account settings.</p></blockquote><p><a href="https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-19/">https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-19/</a></p><h2>Semantics Over Syntax: Uncovering Pre-Authentication 5G Baseband Vulnerabilities</h2><p>Craig S. Blackie and Darren McDonald </p><blockquote><p>Dell stores its BIOS administrator and user passwords as XOR-encrypted plaintext in the DVAR (Dell Variable) region of the SPI flash chip, not as a one-way hash. The scheme encrypts a 32-byte password field with a 20-byte key, and the first character is not encrypted at all. For any password up to 12 characters, the unused tail of the field leaks the entire key, so the password can be recovered directly from a flash dump with no brute force and no known plaintext. Longer passwords leave a small blind zone in a single record, which a quirk of the key derivation then closes (more below). Recovery is deterministic and completes in milliseconds. An attacker who can read the SPI flash, which is possible with a clip and a cheap programmer or by booting an operating system they control, can recover the password and gain full BIOS access. We found this jointly by chance while working on something entirely different. The affected scheme is used across a range of older Dell platforms, a large number of which are now near or past end of support, whereas newer platforms have moved to a more secure password-protection mechanism. It is not, however, limited to legacy hardware: it is confirmed on the current-generation Wyse 5070 thin client, which remains supported and unpatched, and it is implemented in the SystemPwSmm SMM driver common to Dell client platforms.</p></blockquote><p><a href="https://arxiv.org/abs/2604.04283">https://arxiv.org/abs/2604.04283</a></p><h2>Forgotten UEFI shims undermining Secure Boot</h2><p><strong>Martin Smol&#225;r</strong> highlights this knotty attack surface but also why roots of trust need to be comprehensive in their mitigations. </p><blockquote><p><span>ESET researchers identified 11 old and forgotten UEFI shim bootloaders at versions 0.9 and below that can be used to bypass UEFI Secure Boot on any UEFI-based machine that trusts Microsoft&#8217;s Microsoft Corporation UEFI CA 2011 third-party UEFI certificate authority (CA) certificate, regardless of the installed operating system (OS). Reported shims can be exploited to execute untrusted code during system boot, enabling attackers to deploy malicious UEFI bootkits (such as </span><a href="https://www.welivesecurity.com/en/eset-research/bootkitty-analyzing-first-uefi-bootkit-linux/">Bootkitty</a><span>, </span><a href="https://www.welivesecurity.com/en/eset-research/introducing-hybridpetya-petya-notpetya-copycat-uefi-secure-boot-bypass/">HybridPetya</a><span>, or </span><a href="https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bootkit-myth-confirmed/">BlackLotus</a><span>) even on systems with UEFI Secure Boot enabled. </span></p><p><span>We reported our findings to CERT/CC in February 2026, and the vulnerable UEFI applications were revoked on Microsoft&#8217;s June 9</span><sup>th</sup><span>, 2026 Patch Tuesday.</span></p></blockquote><p><a href="https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/">https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/</a></p><h2>Unfit to Boot: Breaking U-Boot&#8217;s FIT Signature Verification</h2><p><strong>Anton Ivanov</strong> surfaces some technical debt which will be interesting to see how pervasive the impact is in reality. </p><blockquote><p>For most of these vulnerabilities, the affected code has been present in U-Boot since version v2013.07. This means that they potentially affect over 50 stable releases of the U-Boot project. Counting many downstream vendor forks, these vulnerabilities have a significant impact on the industry.</p></blockquote><p><a href="https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification">https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification</a></p><h2>Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)</h2><p><strong>Craig S. Blackie</strong> and <strong>Darren McDonald</strong> detail and the fact some remain unpached.</p><blockquote><p>The affected scheme is used across a range of older Dell platforms, a large number of which are now near or past end of support, whereas newer platforms have moved to a more secure password-protection mechanism. It is not, however, limited to legacy hardware: it is confirmed on the current-generation Wyse 5070 thin client, which remains supported and unpatched, and it is implemented in the SystemPwSmm SMM driver common to Dell client platforms.</p></blockquote><p><a href="https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/">https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/</a></p><h1>Offense</h1><p>Attack capability, techniques and trade-craft. </p><h2>Bind Link Abuse: One Windows Feature, Many Ways to Blind Your EDR</h2><p><strong>Martin Zugec</strong> highlights a technique that defensive teams will want to develop detection tradecraft or at least a source of signal for.</p><blockquote><p>Windows includes a file-system virtualization feature that can redirect one local path to another without modifying the original file or leaving a persistent filesystem artifact. It is implemented by bindflt.sys, the Bind Filter minifilter driver, and used legitimately by Store apps, Windows Sandbox, and Windows containers. Bitdefender Labs documented and named three new techniques that an attacker running as a local administrator can use to blind EDR sensors and bypass built-in Windows defenses such as AMSI and AppLocker.</p></blockquote><p><a href="https://www.bitdefender.com/en-us/blog/businessinsights/bind-link-abuses-windows-feature-edr-evasion-technique">https://www.bitdefender.com/en-us/blog/businessinsights/bind-link-abuses-windows-feature-edr-evasion-technique</a></p><h2>There and Back Again: An Operators Guide on NTLM Relaying Egress</h2><p><strong>Logan Goins</strong> breaks down a technique which has historically been used by a range of adversaries. Again developing capability to detect would be wise.</p><blockquote><p>What&#8217;s old is new again. Remember coercing SMB NTLM egress tradecraft to crack challenge response back in the day? We see a lot of situations in our assessments where relaying NTLM from coerced network egress is ideal when escalating locally over C2 is unattainable or firewall rules are in play preventing WebDav relays to LDAP. This technique involves NTLM authentication coercion outbound to the internet, catching that traffic with a cloud host, and forwarding that traffic back to our red team infrastructure where it will be proxied back into the target environment to a service which will allow identity or computer takeover.</p></blockquote><p><a href="https://specterops.io/blog/2026/07/15/there-and-back-again-an-operators-guide-on-ntlm-relaying-egress/">https://specterops.io/blog/2026/07/15/there-and-back-again-an-operators-guide-on-ntlm-relaying-egress/</a></p><h2>BingusLdr</h2><p><strong>Bingus</strong> attempts to blind some EDR capabilities with this release.</p><blockquote><ul><li><p>CET compatible stack spoofing</p></li><li><p>EAF compatible API resolution</p></li><li><p>Heap masking</p></li><li><p>Image masking</p></li></ul></blockquote><p><a href="https://github.com/Sizeable-Bingus/BingusLdr">https://github.com/Sizeable-Bingus/BingusLdr</a></p><h2>UnwindRaven</h2><p><strong>Tom O'Neill</strong> drops this which similarly tries to blind some EDR capabilities.. </p><blockquote><p>UnwindRaven is a Windows x64 offensive research framework that constructs <strong>fully synthetic call stacks</strong> at thread startup time, making a newly created thread appear &#8212; to stack-walking debuggers, EDR sensors, and kernel callbacks &#8212; as though it was legitimately invoked by a chain of known, trusted system frames.</p></blockquote><p><a href="https://github.com/toneillcodes/UnwindRaven">https://github.com/toneillcodes/UnwindRaven</a></p><h1>Exploitation</h1><p>What is being exploited..</p><p><em>Nothing overly of note this week&#8230;</em></p><h1>Tooling and Techniques</h1><p>Low level tooling and techniques for attack and defence researchers</p><h2>CET-Compliant Callstack Spoofing via Thread Pool Enum Callback Trampolining</h2><p><strong>Tiziano Marra</strong> walks through how shadow stack call stack spoofing can be achieved through this excellent write-up.</p><p><a href="https://mrtiz.github.io/cet-callstack-spoofing-thread-pool-trampoline">https://mrtiz.github.io/cet-callstack-spoofing-thread-pool-trampoline</a></p><h2>AutoTrace</h2><p><strong>Arastoo Zibaeirad<span>, </span>Marco Vieira</strong><span> and </span><strong>Thomas Zimmermann</strong> provides a capability uplift here which will compress exploitation. </p><blockquote><p>We present AutoTrace, an agentic pipeline that localizes vulnerability triggers by exploring a code property graph layer by layer, with LLM agents deciding where to look next and deterministic admissibility gates deciding what evidence is required before a trigger can be reported. Agents never accept a trigger on their own authority; every reported trigger is backed by explicit evidence drawn from the graph, so the pipeline covers both intra- and interprocedural vulnerabilities without relying on ungrounded model judgment. On the full InterPVD benchmark, AutoTrace reaches 75.0% VulnHit and 80.8% FuncHit, surpassing the prior state of the art on the same corpus. Building on the same machinery, we construct SinkTrace-Bench, a dataset that exposes each vulnerability as a source-to-sink (S2S) causal chain from attacker-controlled input through propagation to the dangerous operation, drawn from matched vulnerable and patched program states. It comprises 1,542 verifier-confirmed, perfectly balanced vulnerable/safe samples whose label fidelity we audit against expert annotations.</p></blockquote><p><a href="https://arxiv.org/abs/2607.12058">https://arxiv.org/abs/2607.12058</a></p><h1>Footnotes</h1><p>Some other small (and not so small) bits and bobs which might be of interest.</p><ul><li><p>Annual, quarterly and monthly reports</p><ul><li><p><em>Nothing overly of note this week, but keep an eye on</em> <a href="https://github.com/jacobdjwilson/awesome-annual-security-reports/tree/main/Annual%20Security%20Reports/2026">the Awesome Annual Security Reports 2026 collection</a> and <a href="https://github.com/blackorbird/APT_REPORT">APT report collection</a></p></li></ul></li><li><p><a href="https://www.tandfonline.com/doi/full/10.1080/02684527.2026.2679004"><span>Analytical capacity for national security</span></a><span> - </span><em><span>&#8220;Empirical findings from Norwegian public documents, a case-study and interviews show that analytical capacity for national security in Norway is hindered by regulatory blindspots, lacking sense-of-urgency and bureaucratic resistance. The article offers lessons and tools for a wider audience to increase analytical capacity and remedy organisational vulnerabilities.&#8221;</span></em></p></li><li><p><a href="https://www.security-institute.org/3d-flip-book/institute-quarterly-2026-q2/"><span>The Institute Quarterly: Resilience &amp; Preparedness</span></a></p></li><li><p>Artificial intelligence</p><ul><li><p><span>if you are a big </span><a href="https://arxiv.org/">arxiv.org</a><span> user - out of China there is </span><a href="https://www.alphaxiv.org/">alphaxiv.org</a><span> which is an AI powered incarnation / overlay</span></p></li><li><p>Fundamental</p><ul><li><p><a href="https://seed.bytedance.com/en/blog/edgebench-measuring-real-world-environment-learning-and-discovering-a-new-scaling-law">EdgeBench: Measuring Real-World Environment Learning and Discovering a New Scaling Law</a></p></li><li><p><a href="https://arxiv.org/abs/2606.18089">From Reasoning Traces to Reusable Modules: Understanding Compositional Generalization in Language Model Reasoning</a></p></li><li><p><a href="https://arxiv.org/abs/2606.26300">The Verification Horizon: No Silver Bullet for Coding Agent Rewards</a></p></li><li><p><a href="https://arxiv.org/abs/2607.07508">Single-Rollout Asynchronous Optimization for Agentic Reinforcement Learning</a></p></li><li><p><a href="https://openreview.net/forum?id=mjYcL7esQO">Episodic Memory-Guided Controllable Experience Synthesis for Reinforcement Learning</a></p></li><li><p><a href="https://openreview.net/forum?id=3uC9teMlUt">All Circuits Lead to Rome: Rethinking Functional Anisotropy in Circuit and Sheaf Discovery for LLMs</a></p></li><li><p><a href="https://arxiv.org/abs/2606.18394">JetSpec: Breaking the Scaling Ceiling of Speculative Decoding with Parallel Tree Drafting</a></p></li><li><p><a href="https://www.weco.ai/blog/first-evidence-of-recursive-self-improvement">AIDE&#178;: The First Evidence of Recursive Self-Improvement</a></p></li><li><p><a href="https://arxiv.org/abs/2607.13443">The Environmental Cost of Digital Sovereignty: Water, Energy, and Emissions Impacts of Sovereign <span>AI</span> Infrastructure in the Global South</a></p></li><li><p><a href="https://arxiv.org/abs/2607.12273">Code-MUE: Measuring Code <span>LLMs</span>&#8216; Uncertainty through Execution-based Semantic Interaction Graphs</a></p></li></ul></li><li><p>Applied non-cyber</p><ul><li><p><a href="https://arxiv.org/abs/2607.04728">Turning Off-Policy Tokens On-Policy: A Plug-in Approach for Improving LLM Alignment</a></p></li><li><p><a href="https://arxiv.org/abs/2606.15300">CODA-BENCH: Can Code Agents Handle Data-Intensive Tasks?</a></p></li><li><p><a href="https://arxiv.org/abs/2607.05471">KAT-Coder-V2.5 Technical Report</a></p></li><li><p><a href="https://github.com/JustVugg/colibri">Colbri: Run GLM-5.2 (744B MoE) on a 25GB-RAM consumer machine</a></p></li><li><p><a href="https://github.com/Mesh-LLM/mesh-llm">Mesh LLM: Distributed AI/LLM for the people. Share compute privately or publicly to power your agents and chat</a></p></li><li><p><a href="https://arxiv.org/abs/2607.14386">CIPHER: A Decoupled Exploration-Selection Framework for Test-Time Scaling of Data Science Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2607.13453">Adversarial Prompting Framework for <span>AI</span> Safety Assessment</a></p></li><li><p><a href="https://arxiv.org/abs/2607.11117">MusicMark: A Robust Generative Watermarking Framework for Music Generation</a></p></li><li><p><a href="https://arxiv.org/abs/2607.11063">AdvNav: Behavior-Guided Black-Box Adversarial Attacks on Vision-Language Navigation</a></p></li><li><p><a href="https://arxiv.org/abs/2607.12619">Agentic Service-Oriented Computing: A Manifesto for the Next Frontier of Service-Oriented Computing</a></p></li><li><p><a href="https://arxiv.org/abs/2607.11390">TerraRepair: A Tool-Grounded LLM Agent for Infrastructure-as-Code Repair</a></p></li></ul></li><li><p>Applied cyber specific</p><ul><li><p><a href="https://arxiv.org/abs/2607.14309">Traccia: An OpenTelemetry-Based Governance Platform for AI Systems</a></p></li><li><p><a href="https://arxiv.org/abs/2607.11086">Rethinking MCP <span>Security</span>: A Large-Scale Study of Runtime MCP Servers and <span>Security</span> Scanner Reliability</a></p></li><li><p><a href="https://arxiv.org/abs/2607.13801">Traffic-Aware Randomized Smoothing for <span>LLM</span>-Based Network Intrusion Detection</a></p></li><li><p><a href="https://arxiv.org/abs/2607.13439">DREA: Decoupled Reasoning and Exploration Agents for Repository-Level Vulnerability Detection</a></p></li><li><p><a href="https://arxiv.org/abs/2607.13088">Securing LLMs in the Wild: Privacy and Security Challenges at the Edge</a></p></li><li><p><a href="https://arxiv.org/abs/2607.13085">Baselines Before Architecture: Evaluating Coding Agents for Autonomous Penetration Testing</a></p></li><li><p><a href="https://arxiv.org/abs/2607.12316">Antiproof: Synthesizing Vulnerability Detectors and Proofs of Exploitability</a></p></li><li><p><a href="https://arxiv.org/abs/2607.12089">Cross-Cutting <span>Security</span> Analysis of <span>LLM</span>-Generated Code via Metamorphic Testing and Association Rule Mining</a></p></li><li><p><a href="https://arxiv.org/abs/2607.12058">AutoTrace: From Patches to Triggers via Agentic Interprocedural Exploration</a></p></li><li><p><a href="https://arxiv.org/abs/2607.12624">PVDetector: Detecting Prompt Injection Attacks on Purpose-Specific <span>LLM</span> Agents through Policy-Violation Concept Analysis</a></p></li><li><p><a href="https://arxiv.org/abs/2607.13987">Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation</a></p></li><li><p><a href="https://arxiv.org/abs/2607.15143">Setup Complete, Now You Are Compromised: Weaponizing Setup Instructions Against AI Coding Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2607.14628">Routing Ceilings Are Domain-Independent: Structural Prior Injection in Code Security <span>Vulnerability</span> Detection</a></p></li><li><p><a href="https://research.google/pubs/co-redteam-orchestrated-security-discovery-and-exploitation-with-llm-agents/">Co-RedTeam: Orchestrated Security Discovery and Exploitation with LLM Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2605.30667"><span>Automatically Attacking Software Reverse Engineering AI Agents</span></a></p></li><li><p><a href="https://arxiv.org/abs/2607.14416">CausalGraphX: A Counterfactual Graph Neural Network Framework for Explainable Systemic Risk Assessment</a></p></li><li><p><a href="https://arxiv.org/abs/2607.13123">AI in Cyberpsychology: A systematic literature review of Cybersecurity enhancement by using AI for analyzing psychology of Victims, Attackers, and Defenders</a></p></li><li><p><a href="https://arxiv.org/abs/2607.12723">Bulkhead: Automated Semantic Detection and Remediation of Container Escape Vulnerabilities</a></p></li><li><p><a href="https://arxiv.org/abs/2607.11348">Understanding the Impact of <span>AI</span> Code Assistants on Security API Usage: An Empirical Study</a></p></li><li><p><a href="https://arxiv.org/abs/2607.11698">Agent Hacks Agent: Autoresearch for Production-Agent Red-Teaming</a></p></li><li><p><a href="https://arxiv.org/abs/2607.11288">Mako: A Self-Evolving Agentic Operating System (SE-AOS) for Autonomous Web Exploitation</a></p></li><li><p><a href="https://arxiv.org/abs/2607.09653">VEXAIoT: Autonomous IoT Vulnerability EXploitation using AI Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2607.14754">FlowGuard: From Signals to Evidence for MCP <span>Security</span> Detection</a></p></li><li><p><a href="https://arxiv.org/abs/2607.14566">Fully Automated End-to-End Adversary Emulation from MITRE ATT&amp;CK Based Cyber Threat Intelligence Using <span>LLMs</span></a></p></li><li><p><a href="https://arxiv.org/abs/2607.14493">Context Contamination in LLM Analysis of Network Security Logs: Poison with Passive Prompt Injection and Mitigation Evaluation</a></p></li></ul></li></ul></li><li><p>Books</p><ul><li><p><a href="https://link.springer.com/book/10.1007/978-981-95-6240-4">Digital China - Digital Industries, Industry Digitalization and Digital Society</a></p></li><li><p><a href="https://nostarch.com/unnatural-history-of-malware">The (Un)Natural History of Malware</a></p></li></ul></li><li><p>Events</p><ul><li><p><a href="https://easychair.org/cfp/CyCon2027">CyCon 2027: 19th International Conference on Cyber Conflict: Unified Response </a>- Call for Papers</p><p></p></li></ul></li></ul><p>Finally finally the <a href="https://creators.spotify.com/pod/profile/national-cyber-security-c6/episodes/The-Ransomware-Ecosystem-e2hi088">NCSC&#8217;s podcast series</a>.</p><div><hr></div><p><em>Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them. </em></p><p><em>This newsletter is subject to the NCSC website terms and conditions which can be found at <a href="https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions">https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions</a> and you can find out more about how will treat your personal information in our privacy notice at <a href="https://www.ncsc.gov.uk/section/about-this-website/privacy-statement">https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.</a></em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CTO at NCSC - Cyber Defence Analysis! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CTO at NCSC Summary: week ending July 12th]]></title><description><![CDATA["Danger no longer comes only from the battlefield &#8211; cyber and hybrid threats now reach us in new and unpredictable ways.&#8221;]]></description><link>https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-july-70e</link><guid isPermaLink="false">https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-july-70e</guid><dc:creator><![CDATA[Ollie Whitehouse]]></dc:creator><pubDate>Sat, 11 Jul 2026 10:18:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/NxfSBHmZC_4" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to the weekly highlights and analysis of the&nbsp;<a href="https://infosec.pub/c/blueteamsec?dataType=Post&amp;sort=New">blueteamsec</a>&nbsp;(and my wider reading). Not everything makes it in, but the best bits do. A community member is doing <a href="https://briefing.workshop1.net/">daily AI generated podcast of the last 24hours of posts</a>.</p><p>Operationally this week nothing overly of note.</p><p>In the high-level this week:</p><ul><li><p><a href="https://www.ncsc.gov.uk/blogs/cyber-shield-the-path-to-an-agentic-ai-future-for-cyber-defence"><span>Cyber Shield: The path to an agentic AI future for cyber defence</span></a><span> - </span><strong><span>NCSC</span></strong><span> UK outlines - </span><em><span>&#8220;The NCSC and the Department for Science, Innovation and Technology (DSIT) are developing this blueprint, which we are calling </span>Cyber Shield<span>. The objective of Cyber Shield is to </span>build a national-scale, collaborative approach to agentic cyber defence, using frontier AI to identify, reduce and resolve our national cyber risk<span>.&#8221;</span></em></p></li><li><p><a href="https://www.ncsc.gov.uk/blogs/cyber-essentials-pathways-from-proof-of-concept-to-cyber-confidence"><span>Cyber Essentials Pathways: from proof of concept to cyber confidence</span></a><span> - </span><strong><span>NCSC</span></strong><span> UK outlines - </span><em><span>&#8220;An alternate path to Cyber Essentials Plus certification, without compromising the integrity of the scheme.&#8221;</span></em></p></li><li><p><a href="https://www.gov.uk/government/news/foreign-secretary-chatham-house-essay-britains-place-in-the-new-world-order">Britain&#8217;s place in the new world order: Foreign Secretary&#8217;s Chatham House essay </a>- <strong><span>The Rt Hon Yvette Cooper</span></strong><span> outlines - </span><em><span>&#8220;Danger no longer comes only from the battlefield &#8211; cyber and hybrid threats now reach us in new and unpredictable ways.&#8221;</span></em></p></li><li><p><a href="https://www.gov.uk/government/news/businesses-across-britain-sign-up-to-cyber-resilience-pledge-as-ministers-urge-firms-to-strengthen-cyber-defences">Businesses across Britain sign up to Cyber Resilience Pledge as ministers urge firms to strengthen cyber defences</a> - <strong>Department for Science, Innovation and Technology</strong><span>, </span><strong>National Cyber Security Centre</strong><span> and </span><strong>The Rt Hon Liz Kendall MP </strong>announce - <em>&#8220;Signatories will take practical steps to strengthen their cyber resilience, including board-level oversight, use of National Cyber Security Centre (NCSC) tools and stronger supply-chain security&#8221;</em></p></li><li><p><a href="https://www.gov.uk/government/news/uk-financial-system-strengthened-with-new-safeguards-for-major-technology-providers">UK financial system strengthened with new safeguards for major technology providers</a> - <strong>HM Treasury</strong><span> and </span><strong>Rachel Blake MP </strong>designate - <em>&#8220;As banks, insurers and financial market infrastructures become increasingly reliant on cloud services, disruption at a major supplier could affect multiple firms at the same time, potentially impacting services customers depend on.&#8221; &#8230; &#8220;To help guard against this risk, the Government has designated four major global cloud services and technology providers as Critical Third Parties (CTPs).&#8221; - </em>under Requirement 4 there are Technology and cyber resilience requirements</p><ul><li><p><a href="https://www.bankofengland.co.uk/news/2026/july/uk-financial-regulators-to-begin-overseeing-critical-third-parties-announced-by-hmt">UK financial regulators to begin overseeing Critical Third Parties announced by HM Treasury</a> - <strong>Bank of England</strong> announces </p></li></ul></li><li><p><a href="https://www.gov.uk/government/publications/the-value-of-resilience-cyber-resilience-in-financial-services">The Value of Resilience: Cyber Resilience in Financial Services</a> -  UK <strong>HM Treasury</strong> publishes - <em>&#8220;Evidence on how cyber resilience can reduce disruption costs, support growth and strengthen financial performance in UK financial services.&#8221;</em></p></li><li><p><a href="https://hansard.parliament.uk/lords/2026-07-09/debates/228F2A06-711D-4A51-8382-58C731BDEB2F/DefenceReadinessBill">Defence Readiness Bill</a> - UK<strong> Parliament </strong>debates - <em>&#8220;My noble friend Lord Harris and others mentioned the important point about the changing nature of warfare and the importance of understanding that war is about cyber, climate and information and all the things we have talked about. We need to address those as well in any plan that we bring forward.&#8221;</em></p></li><li><p><a href="https://www.gov.ie/en/department-of-justice-home-affairs-and-migration/consultations/public-consultation-on-the-draft-national-cyber-security-strategy/">Public consultation on the draft National Cyber Security Strategy</a> -<strong> Ireland</strong> consults  - <em>&#8220;Our third National Cyber Security Strategy provides a path forward for securing our digital infrastructure, enhancing our resilience to cyber security threats, and building capacity at home and abroad to create a safer digital environment.</em>&#8221;</p><ul><li><p><a href="https://assets.gov.ie/static/documents/3fdec2f9/Draft_National_Cyber_Security_Strategy_for_Public_Consultation.pdf">National Cyber Security Strategy Draft for Public Consultation</a></p></li></ul></li><li><p><a href="https://www.nids.mod.go.jp/publication/commentary/commentary442.html">&#8220;Modified Narratives&#8221; and Government Credibility in Cognitive Warfare: From the Perspective of Social Resilience </a>- Japanese <strong>National Institute for Defense Studies</strong> think tanks - &#8220;<em>For months before the invasion, Russia disseminated justification narratives, and just before the invasion, a cyberattack was carried out on the Ukrainian government's official website displaying a threatening message: "Your personal information has been made public. Fear the worst." This was a combination of cyberattacks and psychological warfare orchestrated by Russia, and it can be said that the war had already begun in the "cognitive realm" before the actual fighting.&#8221;</em></p></li><li><p><a href="https://unidir.org/publication/unpacking-the-united-nations-open-ended-working-group-on-ict-in-the-context-of-international-security-2021-2025/">Unpacking the United Nations Open-Ended Working Group on ICT in the Context of International Security (2021&#8211;2025)</a> - <strong>United Nations Institute for Disarmament Research</strong> publishes - &#8220;<em><span>This report provides an </span><a href="https://unidir.org/analyzing-open-ended-working-group-security-icts/">analysis of the evolution</a><span> of the process and a detailed account of those discussions, including major themes and trends, across the main pillars of the framework: threats, rules, norms and principles, international law, confidence-building measures, capacity-building, and regular institutional dialogue.&#8221;</span></em></p></li><li><p>Reporting on/from China</p><ul><li><p><a href="https://www.wired.com/story/what-happens-if-china-hacks-the-us-water-supply-war-game-volt-typhoon/">What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out</a> - <strong>WIRED</strong> reports - <em>&#8220;The scenario modeled by Corman&#8217;s war game&#8212;5,000 hacked water utilities&#8212;would be unprecedented. It also isn&#8217;t the most probable outcome of Volt Typhoon&#8217;s intrusions, cautions Jen Easterly, who served as director of the Cybersecurity and Infrastructure Security Agency when China&#8217;s hacking campaign was first discovered.&#8221;</em></p></li><li><p><a href="https://www.news.cn/tech/20260603/274a64cf5a83446299f35981c9e90e9c/c.html"><span>There is no room for unintentional mistakes in scientific research</span></a><span> - </span><strong><span>Ministry of State Security</span></strong><span> warns which the </span><strong>Xinhua News Agency</strong> reports<span> - </span><em><span>&#8220;In today's increasingly competitive technological landscape, technological security has become a crucial area of &#8203;&#8203;national security. The leakage of sensitive research data can not only affect the future of researchers themselves but also potentially endanger national security.&#8221;</span></em></p></li><li><p><a href="https://www.caixinglobal.com/2026-07-03/alibaba-bans-staff-from-using-anthropic-ai-tools-over-security-concerns-102460685.html?rkey=4jojc%2BU9DvvtuaHc2n7nI%2FFL%2FE7ci4pKEpkW%2FwYkOSGEoa2B5eh6ng%3D%3D&amp;cxg=web&amp;Sfrom=twitter">Alibaba Bans Staff From Using Anthropic AI Tools Over Security Concerns</a> - <strong>Caixin Global</strong> reports - <em>&#8220;An Alibaba insider confirmed to Caixin on Friday that the Chinese e-commerce giant has added Anthropic&#8217;s Claude Code to its high-risk software list. Employees will be required to uninstall Anthropic models and agent products and switch to Alibaba&#8217;s in-house AI assistant, Qoder, the person said.&#8221; - </em>lets hope they really don&#8217;t have Anthropic&#8217;s models&#8230;</p></li><li><p><a href="https://www.scmp.com/tech/article/3359015/china-unveils-industrial-internet-road-map-ai-5g-core-manufacturing-upgrade?module=top_story&amp;pgtype=section"><span>China unveils industrial internet road map, with AI, 5G at core of manufacturing upgrade</span></a><span> - </span><strong><span>South China Morning Post</span></strong><span> reports - </span><em><span>&#8220;The plan, jointly issued on Tuesday by eight Chinese government agencies led by the Ministry of Industry and Information Technology, included targets for </span><strong><span>expanding</span></strong><span> </span><strong><span>industrial digital infrastructure and data supply</span></strong><span>, promoting the adoption of AI across factories, and developing world-leading industrial internet platforms.&#8221;</span></em></p></li><li><p><a href="https://www.scmp.com/tech/tech-trends/article/3359146/shanghai-unveils-quantum-computing-hub-china-races-tech-supremacy?utm_source=twitter&amp;utm_campaign=3359146&amp;utm_medium=share_widget"><span>Shanghai unveils quantum computing hub as China races for tech supremacy </span></a><span>- </span><strong><span>South China Morning Post</span></strong><span> reports - </span><em><span>&#8220;The Shanghai Quantum Computing Future Industry Incubation Zone, launched on Tuesday in the city&#8217;s Xuhui district, has attracted an initial cohort of 26 quantum firms. The zone would offer resources, talent and subsidies to expedite a shift from laboratory research towards a full-fledged industrial ecosystem for quantum computing, according to a report by the state-backed Jiefang Daily.&#8221;</span></em></p></li></ul><ul><li><p><a href="https://www.reuters.com/world/china/india-allows-four-chinese-linked-power-equipment-firms-bid-government-projects-2026-07-03/">India allows four Chinese-linked power equipment firms to bid for government projects</a> - <strong>Reuters</strong> reports - &#8220;<em>Since a 2020 border clash, New Delhi has required Chinese bidders to register with a government panel and secure political and security &#8203;clearances before &#8203;competing for &#8288;any state contract. The exemption comes as India accelerates expansion of its &#8203;transmission network to support rising electricity &#8203;demand &#8288;and renewable energy additions.&#8221;</em></p></li></ul></li><li><p> AI</p><ul><li><p><a href="https://www.gov.uk/government/publications/mapping-of-the-ai-and-software-security-services-market">Mapping of the AI and software security services market</a> - UK <strong>Department for Science, Innovation and Technology</strong> publishes - &#8220;<em><span>This report presents findings from research with software security and AI security providers. It maps the software security and AI security markets to understand what services and tools they offer, their awareness and the extent to which their services link with the principles in the government&#8217;s </span><a href="https://www.gov.uk/government/publications/software-security-code-of-practice">Software Security Code of Practice</a><span>, </span><a href="https://www.gov.uk/government/publications/ai-cyber-security-code-of-practice">AI Security Code of Practice</a><span> and ETSI&#8217;s </span><a href="https://www.etsi.org/deliver/etsi_en/304200_304299/304223/02.01.01_60/en_304223v020101p.pdf">AI security global standard, EN 304 223</a><span>. The requirements in the latter two documents are the same.&#8221;</span></em></p></li><li><p><a href="https://www.gov.uk/government/publications/thematic-review-and-gap-analysis-on-ai-security">Thematic review and gap analysis on AI security</a> - UK <strong>Department for Science, Innovation and Technology</strong> publishes - <em>&#8220;The Department for Science, Innovation and Technology commissioned Lancaster University to conduct a thematic review and gap analysis covering peer-reviewed research on the security of AI from the last five years (January 2021 to January 2026).&#8221;</em></p></li><li><p><a href="https://socbench.org/">SOCBench An Open Benchmark for AI in Cybersecurity Operations</a> - <strong>Deep Tempo</strong> publish (who make one of the models being measured - <em>&#8220;LLMs flag 36% of benign traffic as malicious, released a open-source harness to test.&#8221; - </em>turns out there may be better ML/DS/AI approaches to problems..</p></li><li><p><a href="https://www.cotool.ai/research">AI Research in <span>Security Operations - </span>Pushing the frontier of AI agents for real security work</a> - <strong>Cotool</strong> publish </p><ul><li><p>BlueBench-Intrusion-002: Real multi-host Windows Active Directory intrusion spanning detection engineering, malware analysis, and open-ended incident reporting - <em>&#8220;GPT-5.6 Sol set a new high-water mark at 79%, ahead of Opus 4.7 (76%), Opus 4.8 (74%), GPT-5.5 (73%), and GLM-5.2 (73%)<span>. Track wins still rotated: Opus 4.6 topped guided investigation (87%), GPT-5.5 wrote the best IR report (76%), and GPT-5.6 Sol wrote the best threat hunting report (81%). GPT-5.6 Terra reached 70% overall at substantially lower cost, while GLM-5.2 remains the strongest open-weight result at 73%. </span><strong><span>Claude Fable 5 could not be evaluated because Anthropic's cybersecurity guardrails were triggered on all 40 tasks</span></strong><span>.&#8221;</span></em></p></li></ul></li><li><p><a href="https://berryvilleiml.com/docs/no-security-meter-ai.pdf">No Security Meter for AI</a> - <strong>Berryville Institute of Machine Learning (BIML)</strong> - from May but worth a read by cyber luminaries and AI experts - <em>&#8220;Let&#8217;s say you wanted to make sure that your AI is secure. Can you just maximize the security and privacy benchmark and call it a day? Nope, because benchmarks don&#8217;t actually work for measuring AI capabilities (even when they are NOT emergent systemic properties like security). &#8230; Will a software security-like measurement move work for AI? Probably. In the meantime we can make real progress in AI security by cleaning up our WHAT piles and managing risk by identifying and applying good assurance processes.&#8221;</em></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/news/commission-presents-eu-action-plan-cybersecurity-and-artificial-intelligence">Commission presents EU Action Plan on Cybersecurity and Artificial Intelligence</a> - <strong>European Commission</strong> outlines - <em>&#8220;<span>Building on the EU's unique legal framework for AI and cybersecurity, the </span>Action Plan<span> will bring together Member States, industry and EU-level organisations to strengthen the cybersecurity of our digital landscape against the vulnerabilities posed by advanced AI.&#8221;</span></em></p></li><li><p><a href="https://www.bankingsupervision.europa.eu/press/letterstobanks/shared/pdf/2026/ssm.2026_letter_on_AI_enabled_cybersecurity_threats.en.pdf">Addressing AI-enabled cybersecurity threats</a> - <strong>European Central Bank</strong> issues - &#8220;<em>The ECB emphasises the importance of addressing, without delay, open supervisory findings and measures related to the ICT areas in focus and security risks that have been identified in previous supervisory activities such as on-site inspections, targeted reviews and the 2024 cyber-resilience stress test. Given the accelerating threat landscape, existing weaknesses that remain unresolved may become increasingly material and pose significant risks to operational resilience.&#8221;</em></p></li><li><p><a href="https://www.enisa.europa.eu/publications/enisas-view-on-cybersecurity-in-the-frontier-ai-era"><span>ENISA&#8217;s view on Cybersecurity in the Frontier AI Era</span></a><span> - </span><strong><span>ENISA</span></strong><span> publish &#8220;</span></p><ul><li><p><em>cybersecurity should be positioned as a strategic use case for European</em></p><p><em>investment in AI, as a need exists for the EU-based organisations to have</em></p><p><em>access to and develop their own AI models,</em></p></li><li><p><em>security fundamentals matter more than ever in the age of AI;</em></p></li><li><p><em>resources need to be shifted from discovery to risk-based prioritisation</em></p><p><em>of vulnerabilities through higher-speed triage, remediation and risk reduction;</em> &#8220;</p></li></ul></li><li><p><a href="https://www.the-substrate.net/p/china-will-likely-have-its-own-mythos?utm_source=share&amp;utm_medium=android&amp;r=q9u24&amp;triedRedirect=true&amp;hide_intro_popup=true">China will likely have its own Mythos-like model around February 2027</a> - <strong>Hamish Low</strong> forecasts - <em>&#8220;My central estimate for when a Chinese firm will have fully developed a Mythos-like model is around February 2027 (90% CI: October 2026 to September 2027), exactly a year after Mythos itself was ready for internal use in February 2026.&#8221;</em></p></li><li><p><a href="https://www.codon.org.uk/~mjg59/blog/p/securing-agentic-identity/">Securing agentic identity</a><strong> - Matthew Garrett </strong>opines and outlines - <em>&#8220;As is the case for many people working in the security industry, the last few months of my life have been focused on dealing with people wanting to use LLMs everywhere. From an enterprise security perspective that&#8217;s not an inherent problem - what&#8217;s more of a problem is that people want those agents to have access to resources like their calendar and email and so on&#8221;</em></p></li><li><p><a href="https://blogs.windows.com/windowsexperience/2026/07/09/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery/">Evolving Windows vulnerability management to meet the speed of AI-powered discovery</a> - <strong>Microsoft</strong> outline - <em>&#8220;The pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code, with new mechanisms that can accelerate both discovery and analysis. The fastest way to reduce customer exposure is to find issues before attackers can use them. Windows is expanding its ability across the platform to find issues earlier, accelerate the engineering work to fix them, strengthen validation and deliver timely, high-quality updates that keep customers protected.&#8221;</em></p></li><li><p><a href="https://www.un.org/independent-international-scientific-panel-ai/en/preliminary-report">Independent International Scientific Panel on AI</a> - <strong>United Nations</strong> publishes - <em>&#8220;<span>Evidence-based assessment of opportunities, risks and impacts of AI is a first-of-its-kind independent scientific assessment of the capabilities, emerging opportunities and risks of artificial intelligence&#8221;</span></em></p></li><li><p><a href="https://carnegieendowment.org/europe/research/2026/07/when-ai-agents-attack-autonomous-cyber-operations-and-europes-governance-gap">When AI Agents Attack: Autonomous Cyber Operations and Europe&#8217;s Governance Gap</a> - <strong>Carnegie Europe</strong> outlines - <em>&#8220;Autonomous AI agents are increasingly prevalent in cyberspace. The EU needs a real-time monitoring strategy, to invest in AI defenses, and to reduce its strategic dependence on U.S. frontier models.&#8221;</em></p></li><li><p><a href="https://lawreview.gtorg.gatech.edu/issues/volume-ii-issue-i-spring-2026/creativity-on-trial-the-legal-limits-of-ai-authorship-and-the-future-of-copyright-protections/">Creativity on Trial: The Legal Limits of AI Authorship and the Future of Copyright Protections</a> - <strong>Georgia Tech Undergraduate Law Review</strong> reviews - <em>&#8220;The future of this debate and eventually the precedents that will be set, are largely dependent on how courts continue to interpret and apply the doctrine of fair use in relation to AI training practices. Technology companies developing generative AI systems firmly maintain the position that the incorporation of copyrighted materials into their datasets constitutes fair use since the output works are transformative in nature and do not merely reproduce an original work. However, recent litigation has revealed that this argument is not absolute and that courts are deeming that the legality of training practices depends greatly on the manner in which the materials are sourced and utilized.&#8221;</em></p></li><li><p><a href="https://www.scmp.com/economy/china-economy/article/3359328/ai-skills-required-4-out-10-graduate-jobs-china-says-recruitment-portal">AI skills required for 4 out of 10 graduate jobs in China, says recruitment portal</a> - <strong>South China Morning Post</strong> reports - <em>&#8220;In the first five months of this year, nearly four out of every 10 job postings targeting fresh graduates were AI-related, compared with nearly three out of 10 in the same period last year&#8221;</em></p></li></ul></li><li><p><em>Cyber proliferation</em></p><ul><li><p><a href="https://www.reuters.com/legal/government/greek-wiretapping-victims-sue-spyware-firm-intellexa-damages-2026-07-07/">Greek wiretapping victims sue spyware firm Intellexa for damages</a> - <strong>Reuters</strong> reports - <em>&#8220;Eight victims of a Greek wiretapping scandal have sued the Athens-based surveillance firm Intellexa SA and individuals believed to be linked to it, seeking &#8364;1 &#8203;million ($1.1 million) each for moral harm, their lawyer said on Tuesday.&#8221;</em></p><ul><li><p><a href="https://www.ekathimerini.com/news/1308862/eight-surveillance-victims-seek-e1000000-in-damages-from-spyware-firm-intellexa-13-others/">Eight Predator victims sue spyware firm Intellexa, 13 others, for millions</a> - <strong>The Trust Project</strong> reports</p></li></ul></li><li><p><a href="https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/?ref=metacurity.com">Felons, Fraudsters Flog Offensive Cybersecurity Startup</a> - <strong>Brian Krebs</strong> reports - <em>&#8220;A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software ..  whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.&#8221;</em></p></li></ul></li><li><p>Bounty Hunting</p><ul><li><p><a href="https://www.justice.gov/opa/pr/florida-ransomware-negotiator-who-extorted-and-attacked-multiple-us-victims-sentenced-prison"><span>Florida Ransomware Negotiator Who Extorted and Attacked Multiple U.S. Victims Sentenced to Prison</span></a><span> - US </span><strong><span>Department of Justice</span></strong><span> announce - </span><em><span>&#8220;Angelo Martino, 41, of Land O&#8217;Lakes, Florida, formerly employed as a ransomware negotiator, was sentenced today to 70 months for his role in conspiring with Blackcat/ALPHV (BlackCat) actors to extort multiple victims, as well as conspiring with other former cybersecurity professionals to attack additional victims in 2023.&#8221;</span></em></p></li><li><p><a href="https://www.justice.gov/usao-or/pr/armenian-national-extradited-united-states-pleads-guilty-ransomware-extortion-conspiracy"><span>Armenian National Extradited to the United States Pleads Guilty to Ransomware Extortion Conspiracy </span></a>- US <strong>Department of Justice</strong> announce - <em>&#8221;An Armenian national extradited from Ukraine to the United States pleaded guilty yesterday for his role in Ryuk ransomware attacks and an extortion conspiracy targeting companies throughout the United States, including a technology company operating in Oregon.&#8221;</em></p></li><li><p><a href="https://www.mjib.gov.tw/news/Details/1/1196">The Investigation Bureau has cracked a case involving the Chinese Communist Party&#8217;s cyber army</a> - Taiwanese <strong>Ministry of Justice Investigation Bureau</strong> announce - <em>&#8220;An investigation revealed that Li, the head of Ai&#9675; Company, accepted instructions from the Chinese Communist Party's cyber army, "Xiamen Female &#9675;&#9675; Information Technology Co., Ltd.", to collect LINE accounts registered using mobile phone numbers provided by Chinese citizens. These accounts were then rented out to the mainland cyber army for RMB 1,100 each to launch social engineering attacks against Chinese political and academic figures&#8221;</em>  </p></li><li><p><a href="https://policia.es/_es/comunicacion_prensa_detalle.php?ID=16937">The National Police have arrested a suspected collaborator of the pro-Russian hacktivist groups CyberArmy of Russia Reborn (CARR) and Z-Pentest</a> - Spanish <strong>Policia Nacional</strong> announce - <em>&#8220;The investigation began last August when, thanks to information provided by the FBI, the National Police investigators were made aware of the alleged involvement of the detainee in actions aimed at providing logistical and support cover to a Ukrainian hacker, located in Ukraine, linked to the pro-Russian hacktivist group CyberArmy of Russia Reborn (CARR), in order to facilitate his escape to Russia, through Poland and Belarus.&#8221;</em></p></li><li><p><a href="https://www.politie.nl/nieuws/2026/juli/8/onderzoek-naar-hack-odido-wijst-op-mogelijke-betrokkenheid-nederlanders.html">Investigation into Odido hack points to possible involvement of the Dutch</a> - Netherlands <strong>Politie</strong> announce - <em>&#8220;In the investigation into the cyberattack on telecom provider Odido, indications have emerged of the involvement of Dutch nationals. The investigation is still in full swing, and the police and the Public Prosecution Service are asking the public for more information about possible suspects: 'Cybercriminals are also vulnerable and leave traces behind.'&#8220;</em></p></li><li><p><a href="https://www.zetter-zeroday.com/arrest-of-iranian-hacker-spotlights-irans-movement-into-economic-espionage-and-ip-theft/">Arrest of Iranian Hacker Spotlights Iran&#8217;s Movement into Economic Espionage and IP Theft</a> - <strong>Kim Zetter</strong> reports - <em>&#8220;<span>Montenegro police revealed last week that an </span><a href="https://apnews.com/article/montenegro-arrest-iran-us-guard-45be9031b71d6cd939745f13dee16af4?ref=zetter-zeroday.com">Iranian-Turkish citizen had been arrested</a><span> at the request of the US Federal Bureau of Investigation for conducting cyberattacks against US infrastructure &#8212; including </span><a href="https://apnews.com/article/montenegro-arrest-iran-us-guard-45be9031b71d6cd939745f13dee16af4?ref=zetter-zeroday.com">more than 150 US universities</a><span> &#8212; in order to steal data on behalf of Iran&#8217;s Islamic Revolutionary Guard Corps (IRGC) and Iranian universities. In addition to its military corps, the IRGC also conducts surveillance inside Iran and collects intelligence against targets outside the country.&#8221;</span></em></p></li></ul></li><li><p>Market Incentives</p><ul><li><p><a href="https://www.nextgov.com/cybersecurity/2026/07/cisa-expects-finalize-key-cyber-reporting-rule-september/414607/?oref=ng-homepage-river">CISA expects to finalize key cyber reporting rule by September</a> - <strong>NextGov/FCW</strong> reports - <em>&#8220;<span>The Cybersecurity and Infrastructure Security Agency expects to finalize a bedrock cybersecurity incident reporting rule in September, requiring critical infrastructure providers to report major hacks directly to the cyberdefense agency, according to a </span><a href="https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&amp;RIN=1670-AA04">regulation document</a><span> published last week.&#8221;</span></em><br></p></li></ul></li></ul><p>The reflections this week are <span>you may have seen these two recent headlines regarding use of AI to offensive operations</span></p><ul><li><p><a href="https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion"><span>JADEPUFFER: Agentic ransomware for automated database extortion by Sysdig</span></a><span> &#8211; July 1st </span></p></li><li><p><a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/"><span>Inside an AI-Assisted Cloud Attack: Familiar Techniques at Unfamiliar Speed by Sygnia</span></a><span> &#8211; July 8th </span></p></li></ul><p><span>On initial read they appear impressive and potentially a watershed moment &#8211; however there is nuance and comparators not conveyed in the reporting which are useful and potentially counterfactual.</span></p><p><span>To note here:</span></p><ul><li><p><span>The vulnerability exploited in the case of JADEPUFFR was known and a patch available for 14 months - highlighting poor hygiene by the operator which would not have met the bar for Cyber Essentials accreditation.</span></p></li><li><p><span>The statement in JADEPUFFER that &#8216;Ransomware is no longer a craft for the highly skilled&#8217; is disingenuous &#8211; ransomware affiliate Ransomware-as-a-Service model has had scripted playbooks for less skilled operators to follow </span><a href="https://www.curatedintel.org/2021/10/conti-leaked-playbook-ttps.html"><span>since at least 2021</span></a></p></li><li><p><span>The statement by Sygnia that 72 hours is impressive (because of AI) does not reflect that we have seen human operated intrusions achieving as quickly as 3 hours and 44 minutes </span><a href="https://thedfirreport.com/2022/04/25/quantum-ransomware/"><span>four years ago</span></a><span> and 24 hours </span><a href="https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/"><span>five years ago</span></a><span>.</span></p></li></ul><p><span>In short AI is clearly a productivity aid, but:</span></p><ul><li><p><span>Both environments demonstrated poor cyber hygiene which Cyber Essentials / Cyber Assessment Framework address.</span></p></li><li><p><span>Attack paths and techniques are well understood as reported by Sysdig - </span><em><span>the attack relied on familiar cloud techniques rather than novel malware or zero-days.</span></em></p></li><li><p><span>Claims of lowering the bar of entry are contradicted given the well-established Ransomware-as-a-Service model and their playbooks.</span></p></li><li><p><span>Speed of execution should be seen in context when compared to existing human operations.</span></p></li></ul><p>There is a risk that some of the reporting overplays certain aspects and downplays others. There is a line to be walked&#8230;</p><p>Not getting this via email? Subscribe:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Think someone else would benefit? Share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-july-70e?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-july-70e?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p><strong>All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.</strong></p><p>Have a lovely Saturday&#8230;</p><p>Ollie</p><h1>Cyber threat intelligence</h1><p>Who is doing what to whom and how allegedly.</p><h2>Reporting on Russia</h2><h3>The Netherlands targeted by Russian espionage operation via IP cameras</h3><p><strong>Netherlands National Government</strong> alleges/attributes a Russian operation against internet connected CCTV cameras. It is also coupled with security advice.</p><blockquote><p>The operations target standalone cameras accessible via the internet that can be viewed remotely. This involves cameras for private use by, for example, companies.</p><p>Various services are available on the internet that make it possible to easily, quickly, and specifically scan an environment for devices. Based on the characteristics of the devices, such as brand names, IP cameras can then be identified.</p><p>Once the IP camera has been identified, the malicious party can attempt to gain access to it via the internet. This is often relatively easy to do, because many IP cameras connected to the internet are insufficiently secured. For instance, they often have default passwords, outdated firmware, and default configurations.</p></blockquote><p><a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/07/10/nederland-doelwit-van-russische-spionageoperatie-via-ip-cameras">https://www.rijksoverheid.nl/actueel/nieuws/2026/07/10/nederland-doelwit-van-russische-spionageoperatie-via-ip-cameras</a></p><h3>Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities</h3><p><strong>Vlad Pasca</strong> details an alleged Russian campaign which is noteworthy for both method of distribution, technics employed, level and the targeting of crypto currency.</p><blockquote><ul><li><p>Threat actor distributes malicious cryptocurrency wallets (Anchor, Zec, Iota, Onto, Dark, and Stellar) as oversized Advanced Installer packages exceeding 600MB to evade detection.</p></li><li><p>Attacker-controlled domains achieve first page search engine rankings for targeted wallet names, intercepting users searching for legitimate cryptocurrency wallets.</p></li><li><p>The campaign exhibits cross-platform targeting with Windows, Linux, and macOS variants, though Linux and macOS versions of certain wallets remain non-malicious in some instances.</p></li><li><p>Initial executable files are signed with valid code signing certificates to establish false legitimacy and bypass security controls.</p></li><li><p>The campaign&#8217;s objective is deploying Remote Utilities (RuRAT) remote management tool to establish persistent access on compromised systems.</p></li><li><p>Low-confidence attribution to a Russian-aligned threat actor based on Remote Utilities binary hash correlation with Ukraine CERT-UA report 5961 and Russian-language strings identified in analyzed samples.</p></li></ul></blockquote><p><a href="https://hybrid-analysis.blogspot.com/2026/07/suspected-russian-threat-actor.html">https://hybrid-analysis.blogspot.com/2026/07/suspected-russian-threat-actor.html</a></p><h2>Reporting on China</h2><h3>One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement</h3><p><strong><span>Aleksandar Milenkoski</span></strong><span> &amp; </span><strong><span>Julian-Ferdinand V&#246;gele</span></strong><span> detail an alleged Chinese operation against Pakistani law enforcement. This reporting is of note due to the apparent multi actor interest in the victim.</span></p><blockquote><ul><li><p>All these actors converged on Balochistan Police over this period, bringing both a partner and an adversary of Pakistan to the same police force in a province shaped by a separatist insurgency and the regional tensions it has drawn in.</p></li><li><p>At Balochistan Police, the compromised assets included servers hosting web applications that manage police and citizen data, such as criminal and biometric records.</p></li><li><p>A suspected China-nexus actor planted implants in one of the web applications, which serves both police staff and citizens, weaponizing a tool of Pakistan&#8217;s police digitalization against its users.</p></li></ul></blockquote><p><a href="https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/">https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/</a></p><h3>One Email Closer to the Edge: UNK_MassTraction &amp; the Physics of Exploitation</h3><p><strong>Greg Lesnewich</strong> and <strong>Mark Kelly</strong> detail an alleged Chinese campaign which is noteworthy for two reasons. The first is the use of n-days and not 0-days. The second is the targeting of mail servers as a pivot into internal networks.</p><blockquote><ul><li><p>Since May 2026, [we have] been tracking a suspected China-aligned threat cluster named UNK_MassTraction exploiting Roundcube mailservers belonging to the physics and engineering departments of US and Canadian universities.</p></li><li><p>The campaigns exploit multiple n-day vulnerabilities in Roundcube to steal credentials and either install a webshell for follow-on access or deploy the VShell backdoor into the server&#8217;s memory.</p></li><li><p>The actor is likely abusing Roundcube servers as a pivot point to enter target networks, and the operators have deliberately crafted their infection chain to avoid detection.</p></li></ul></blockquote><p><a href="https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation">https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation</a></p><h3>UAT-7810 continues building ORB networks using new malware</h3><p><strong>Jungsoo An</strong><span>, </span><strong>Asheer Malhotra</strong><span>, </span><strong>Vanja Svajcer</strong><span> and </span><strong>Brandon White</strong> f</p><blockquote><ul><li><p>[We are] actively tracking infrastructure and malware associated with UAT-7810, an advanced persistent threat (APT) actor responsible for maintaining and proliferating the <a href="https://securityscorecard.com/wp-content/uploads/2025/06/LapDogs-STRIKE-Report-June-2025.pdf">LapDogs</a> Operational Relay Box (ORB) network, first disclosed by SecurityScorecard in 2025.</p></li><li><p>UAT-7810 is most likely tasked with establishing Operational Relay Box (ORB) networks that can then be leveraged by associated secondary threat actors to conduct their own malicious attacks against high value targets.</p></li><li><p>Talos&#8217; latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware, dubbed &#8220;SHORTLEASH,&#8221; with a newer version already being developed and hosted on attacker-controlled infrastructure. We track this new version of SHORTLEASH as &#8220;LONGLEASH.&#8221;</p></li><li><p>Furthermore, we&#8217;ve discovered two new malware families in UAT-7810&#8217;s arsenal: a C-based backdoor we track as &#8220;DOGLEASH&#8221; and a JAVA-based backdoor we track as &#8220;JARLEASH.&#8221;</p></li></ul></blockquote><p><a href="https://blog.talosintelligence.com/uat-7810/">https://blog.talosintelligence.com/uat-7810/</a></p><h2>Reporting on North Korea</h2><h3>Famous Chollima&#8217;s laptop-farm playbook has now landed on macOS</h3><p><strong>ReliaQuest</strong> alleged that North Korean actors are using routes through carrier grade NAT. This complexity at the networking level is of note.</p><blockquote><p><span>North Korea-linked threat actor Famous Chollima's laptop-farm playbook has now landed on macOS. DPRK operators are securing remote tech contractor roles, then running RustDesk in server-listen mode with Tailscale mesh VPN stitching the endpoint straight into an operator-controlled overlay network.<br><br>The trick is quiet: traffic routes through CGNAT space (100.64.0.0/10) to a private IP on RustDesk ports 21114-21117, skipping the corporate proxy entirely. Nothing egresses that looks suspicious.<br><br>The contractor profile is the tell every time... non-employee, remote-only, short tenure, unmanaged, non-compliant machine.</span></p></blockquote><p><a href="https://x.com/reliaquesttr/status/2074477166771786190?s=46&amp;t=-dkNDSDHEzyAagaVN0SDgA">x.com/reliaquesttr/status/2074477166771786190?s=46&amp;t=-dkNDSDHEzyAagaVN0SDgA</a></p><h2>Reporting on Iran</h2><h3>Cavern Manticore: Exposing Iran-Linked Modular C2 Framework</h3><p><strong>Check Point Research (CPR)</strong> detail an alleged Iranian implant. Notable for the modular nature showing a continued evolution in capability.  </p><blockquote><p>Since early 2026, Check Point Research (CPR) has tracked a <strong>new modular command-and-control framework</strong> used by <strong>Cavern Manticore</strong>, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors. Cavern Manticore is an Iran MOIS (Ministry of Intelligence and Security)-linked actor, with links to the OilRig subgroup named <a href="https://www.welivesecurity.com/en/eset-research/oilrigs-outer-space-juicy-mix-same-ol-rig-new-drill-pipes/">Lyceum</a>. The framework reflects a mature and adaptable toolset built around a shared .NET foundation, while using multiple compilation formats across different components, including <strong>.NET Framework</strong>, <strong>.NET Mixed-Mode C++/CLI</strong>, and <strong>.NET Native AOT</strong>. The<strong> compilation format</strong> itself becomes the<strong> anti-analysis layer</strong> that forces reverse engineers into multiple toolsets and metadata-reconstruction workflows.</p><p>During our investigation, we observed both <em><strong>Cavern agents</strong></em> and <em><strong>Cavern modules</strong></em> in the wild, highlighting a modular architecture that separates core communication capabilities from mission-specific post-exploitation functionality. This design allows the operators to tailor deployments per victim environment, limit what defenders and analysts can recover from any single victim and extend access after compromise through specialized modules for reconnaissance, data access, tunneling, and lateral movement.</p></blockquote><p><a href="https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/">https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/</a></p><h2>Reporting on Other Actors</h2><h3>Linux Backdoor Targeting iKuai Routers</h3><p><strong>dmpdump</strong> details a Linux implant uploaded from Japan with zero-detections. Noteworthy for the targeting of routers. Once again underlines why all vendors should implement our <a href="https://www.ncsc.gov.uk/guidance/guidance-on-digital-forensics-protective-monitoring">Guidance on digital forensics and protective monitoring specifications for producers of network devices and appliances - for device vendors</a></p><blockquote><ul><li><p>After executing <code>acquire_lock()</code> to ensure there is only one instance of the backdoor running, it proceeds to decrypt the configuration.</p></li><li><p>Creates the <code>/var/tmp</code> directory and changes directories to it.</p></li><li><p>Initializes an MbedTLS AES-GCM context with a 256-bit key. The backdoor uses a statically-linked MbedTLS library.</p></li><li><p>Initializes an mbedTLS HTTPS client without certificate validation.</p></li><li><p>Initializes a task scheduler thread for tasks sent from the C2.</p></li><li><p>Attempts to get a <code>GWID</code>, or creates and sets a new one if none can be found. This <code>GWID</code> is likely a <code>Gateway ID</code> associated with iKuai routers.</p></li><li><p>Gets the process ID.</p></li><li><p>Enters an infinite loop that beacons to the C2 to receive tasks. The loop has a sleep interval which is obtained from the C2. A default sleep time of 3600 seconds (1 hour) is set by default as part of the configuration decryption.</p></li></ul></blockquote><p><a href="https://dmpdump.github.io/posts/Backdoor_iKuai_Routers/">https://dmpdump.github.io/posts/Backdoor_iKuai_Routers/</a></p><h3>SpectrePaste</h3><p><strong>Joshua Platt</strong> details an interesting evolution in terms of evasion detection approaches. </p><blockquote><p>SpectrePaste v2 utilized spec-driven development[ transforming a basic powershell delivery script into a fileless, reflective loading system. To bypass traditional signature-based detections, the system utilizes a runtime polymorphism engine that dynamically injects logic snippets, randomizes internal identifiers, and adds obfuscation noise to ensure every delivered payload is uniquely generated on the fly. The result is scanning engines are more often than not completely unable to detect the payloads.</p><p>The most interesting aspect about this system, is the incorporation of spec-driven development creates a fast-flux software development flywheel. By altering the software spec, the authors can modify the core system itself while simultaneously updating the runtime polymorphic code engine</p></blockquote><p><a href="https://medium.com/walmartglobaltech/spectrepaste-b20bc2f6ded8">https://medium.com/walmartglobaltech/spectrepaste-b20bc2f6ded8</a></p><h3>Software Supply Chain Incursions</h3><p><span>A reminder we issued guidance a number of weeks ago in </span><a href="https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies">Software supply chain attacks: check your dependencies</a><span> for software developers</span></p><ul><li><p><a href="https://safedep.io/marketfront-dependency-confusion-campaign/">@marketfront: 25 npm Packages Reuse a Known Lure</a></p></li><li><p><a href="https://socket.dev/blog/malicious-go-module-exposes-github-malware-lure-network">Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories</a></p></li><li><p><a href="https://opensourcemalware.com/blog/cybersecurity-startup-publishes-infostealers-to-npm">Cybersecurity Startup Publishes Infostealers to NPM</a></p></li><li><p><a href="https://socket.dev/blog/npm-pypi-campaign-typosquats-popular-secure-payment-apps">Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps</a></p></li><li><p><a href="https://www.ox.security/blog/injectivelabs-npm-package-hijacked-impacting-87-dependent-packages/">Injectivelabs npm Package Hijacked, Impacting 87 Dependent Packages</a></p></li><li><p><a href="https://securitylabs.datadoghq.com/articles/not-so-anonymous-telemetry-injectivelabs-sdk-ts-backdoor/">Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor</a></p></li></ul><h1>Discovery</h1><p>How we find and understand the latent compromises within our environments.</p><h2>Hunting Sleeping Giants: Detecting Encrypted Beacon Sleep Obfuscation</h2><p><strong>Russell Allen</strong> release a discovery superpower with this.</p><blockquote><p>This post covers the full lineage from Gargoyle through FOLIAGE and Ekko: how each technique works mechanically at the API and memory level, where each one was wrong about what defenders could see, and the specific detection primitives that catch them despite the evasion. The primary source for technique accuracy is Kyle Avery&#8217;s DEF CON 30 presentation and accompanying BHIS post. Where source code and documentation conflict, the Avery primary source takes precedence.</p></blockquote><p><a href="https://justruss.tech/index.php/2026/06/21/hunting-sleeping-giants-detecting-encrypted-beacon-sleep-obfuscation/">https://justruss.tech/index.php/2026/06/21/hunting-sleeping-giants-detecting-encrypted-beacon-sleep-obfuscation/</a></p><h2>PhantomFS</h2><p><strong>Casey</strong> provides a high signal deception capability with this release.</p><blockquote><p>PhantomFS uses the Windows Projected File System (ProjFS) to surface a virtual directory full of convincing decoy files &#8212; financial reports, SSH keys, API credentials, HR spreadsheets, NDAs &#8212; that exist only in memory. No data is ever written to disk until an attacker (or insider threat) opens one.</p><p>The moment a file is touched, PhantomFS:</p><ul><li><p>Writes a Windows Event Log entry (Application log, source <code>PhantomFS</code>)</p></li><li><p>Fires a Toast notification to the active desktop session</p></li><li><p>Logs the exact filename, timestamp, and process context</p></li><li><p>When accessed over a network share &#8212; captures the SMB username and source address</p></li></ul><p>Because legitimate users have no reason to open files they didn&#8217;t put there, every alert is high-confidence. No tuning, no ML, no cloud dependencies &#8212; just a native Windows driver and a single executable.</p></blockquote><p><a href="https://github.com/AlloySecureGroup/PhantomFS">https://github.com/AlloySecureGroup/PhantomFS</a></p><h1>Defence</h1><p>How we proactively defend our environments.</p><h2>deadair</h2><p><strong>Nikhil</strong> releases this interesting performance measurement aid for detection engineers. Confidence comes from knowing.</p><blockquote><p>Use it to answer three SOC questions:</p><ul><li><p>Which enabled detections are blind because their index patterns match no data, stale data, or empty sources?</p></li><li><p>Which detections still run, but with reduced visibility because fields drifted or events arrive after the rule lookback window?</p></li><li><p>Which log sources are being ingested but no enabled detection reads them?</p></li></ul></blockquote><p><a href="https://github.com/Big-Comfy/deadair">https://github.com/Big-Comfy/deadair</a></p><h2>NOX</h2><p><strong>Prepakis Georgios</strong> releases a framework which will be interesting to see how it matures over time as attack surface management one of the kindest things an organisation can do for itself. </p><blockquote><p>NOX is a modular, Go based attack surface management and vulnerability scanning framework. It ships with 300 built in modules covering OSINT, subdomain enumeration, DNS, port scanning, web fingerprinting, and deep active vulnerability testing across injection, authentication, authorization, client side, cloud, API, and business logic vulnerability classes.</p></blockquote><p><a href="https://github.com/kernelstub/Nox">https://github.com/kernelstub/Nox</a></p><h2>Safer Dependencies for Claude Code</h2><p><strong>Robert Auger</strong> tries to bring some cyber resilience to Claude Code to reduce the likelihood of AI introducing vulnerabilities through dependencies. </p><blockquote><p><span>Automatically checks dependencies that Claude adds through its </span><code>Write</code><span>, </span><code>Edit</code><span>, and </span><code>Bash</code><span> tools, and auto-corrects vulnerable versions in place. Runs provenance, version age, vulnerability, and hash-integrity checks across npm, PyPI, RubyGems, Maven, Go, Rust, and PHP (Composer). Coverage is scoped to writes that go through Claude's tools (Intercept Mode corrects a vulnerable pin </span><em>after</em><span> the file lands, within the same tool cycle &#8212; not before); see </span><a href="https://github.com/robert-auger/safer-dependencies/blob/main/CAPABILITIES.md">CAPABILITIES.md</a><span> for exactly what is and isn't covered.</span></p></blockquote><p><a href="https://github.com/robert-auger/safer-dependencies">https://github.com/robert-auger/safer-dependencies</a></p><h1>Incident Writeups &amp; Disclosures</h1><p>How they got in and what they did.</p><p><em>Nothing overly of note this week</em></p><h1>Vulnerability</h1><p>Our attack surface.</p><h2>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</h2><p><strong>Muhammad Usama Sardar</strong>, <strong>Mariam Moustafa</strong> and <strong>Tuomas Aura</strong> release an interesting piece along with a solution.</p><blockquote><p>Remote attestation is increasingly being composed with different protocols to provide endpoint security. Transport Layer Security (TLS) is the most widely used among those protocols, and the composition of TLS with remote attestation is known as attested TLS protocol. Such protocols are used in security-critical applications, e.g., they serve as the backbone of an emerging computing paradigm, Confidential Computing (CC). In this work, we explore the identity crisis that results from ambiguous notions of identity for attested TLS protocols in CC. We present a formal approach with a set of comprehensive security goals and a generic template for the comparison of the security strengths of attested TLS protocols. Using the approach, we discover vulnerabilities in two state-of-the-art protocols. The Confidential Computing Consortium (CCC) attestation Special Interest Group (SIG) and TLS working group have acknowledged the vulnerabilities. To mitigate the vulnerabilities, we present a formally verified solution for vulnerabilities and propose several potential solutions, which are under discussion for standardization at the Internet Engineering Task Force (IETF).</p></blockquote><p><a href="https://dl.acm.org/doi/10.1145/3779208.3785387">https://dl.acm.org/doi/10.1145/3779208.3785387</a></p><h2>XRING: Crashing XQUIC with spec-compliant QPACK instructions</h2><p><strong>S&#233;bastien F&#233;ry</strong> reminds us once again that new protocols and their implementations when implemented in memory unsafe languages come with a potential of peril. </p><blockquote><p>During recent research into the different QUIC stacks for our active TLS scanner, JA4Scan, I found a deterministic remote crash in XQUIC, Alibaba&#8217;s QUIC and HTTP/3 library, dubbed XRING.</p><p>XQUIC enables HTTP/3 support for Tengine, the Nginx-based web server Alibaba runs across its cloud and CDN infrastructure, including sites like Taobao or AliPay.</p><p>A remote, unauthenticated client sends spec-compliant HTTP/3 operation traffic and the server process terminates. The crash requires only 260 bytes of client traffic.</p></blockquote><p><a href="https://foxio.io/blog/xring-crashing-xquic-with-spec-compliant-qpack-instructions">https://foxio.io/blog/xring-crashing-xquic-with-spec-compliant-qpack-instructions</a></p><h2>Januscape: Guest-to-Host Escape in KVM/x86</h2><p><strong>V4bel</strong> shows the world what world class vulnerability research looks like with this VM guest escape.</p><blockquote><p><span>Januscape is a use-after-free vulnerability in the </span><strong>shadow MMU</strong><span> emulation of KVM/x86. It can trigger the bug with guest-side actions alone to corrupt the host kernel's shadow page, and it can threaten the guest-host isolation of KVM/x86 hosts that accept untrusted guests and expose nested virtualization, particularly multi-tenant x86 public clouds (GCP, AWS, etc.).</span></p></blockquote><p><a href="https://github.com/V4bel/Januscape">https://github.com/V4bel/Januscape</a></p><h1>Offense</h1><p>Attack capability, techniques and trade-craft. </p><h2>OpenUDC2</h2><p><strong>CodeX</strong> releases this which detection engineers will want to try and hook on to as an oppotunity. </p><blockquote><p>This is an open source implementation of the UDC2 spec used in Cobalt Strike. The goal of this project is to enable open source C2 frameworks to support existing (and hopefully future) open source UDC2 modules developed by the Cobalt Strike community.</p><p>While this PoC is implemented for Adaptix C2 as a PoC, it does not depends on any Adaptix C2 specific features. It is meant to be easily portable to any other C2 with a custom agent+listener spec.</p></blockquote><p><a href="https://github.com/CodeXTF2/OpenUDC2">https://github.com/CodeXTF2/OpenUDC2</a></p><h2>NebulaPulsar</h2><p><strong>Isaac Fong</strong> releases this which is a capability uplift for free to various threat actors who employ web shells and who want to anti-forensic capabilities. </p><blockquote><p>NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX), originally developed as part of the Alien project.</p><p>Unlike traditional webshell demonstrations that focus solely on command execution, NebulaPulsar explores how an in-memory implant can establish an encrypted communication channel, dynamically load payloads, and execute them entirely in memory.</p></blockquote><p><a href="https://github.com/iss4cf0ng/NebulaPulsar">https://github.com/iss4cf0ng/NebulaPulsar</a></p><h2>Escalating from On-prem to Entra through MITM Attacks</h2><p><strong>Daniel</strong> shows the art of the possible here which highlights the importance of legacy internal network security when considering newer cloud infrastructure. </p><blockquote><p>This post shows how attackers can abuse ADCS to obtain trusted TLS certificates for arbitrary domains, hijack DNS to gain a machine-in-the-middle (MITM) position, and subsequently decrypt HTTPS traffic. While multiple approaches are shown for each of these three steps, the main focus is on obtaining server authentication certificates, since this is where the HTTPS threat model conflicts with Active Directory.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!nr0c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7bd3df6-b1cb-4479-9951-39d346579d0a_1024x500.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!nr0c!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7bd3df6-b1cb-4479-9951-39d346579d0a_1024x500.png 424w, /__u/substackcdn.com/image/fetch/$s_!nr0c!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7bd3df6-b1cb-4479-9951-39d346579d0a_1024x500.png 848w, /__u/substackcdn.com/image/fetch/$s_!nr0c!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7bd3df6-b1cb-4479-9951-39d346579d0a_1024x500.png 1272w, /__u/substackcdn.com/image/fetch/$s_!nr0c!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7bd3df6-b1cb-4479-9951-39d346579d0a_1024x500.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!nr0c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7bd3df6-b1cb-4479-9951-39d346579d0a_1024x500.png" width="1024" height="500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b7bd3df6-b1cb-4479-9951-39d346579d0a_1024x500.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!nr0c!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7bd3df6-b1cb-4479-9951-39d346579d0a_1024x500.png 424w, /__u/substackcdn.com/image/fetch/$s_!nr0c!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7bd3df6-b1cb-4479-9951-39d346579d0a_1024x500.png 848w, /__u/substackcdn.com/image/fetch/$s_!nr0c!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7bd3df6-b1cb-4479-9951-39d346579d0a_1024x500.png 1272w, /__u/substackcdn.com/image/fetch/$s_!nr0c!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7bd3df6-b1cb-4479-9951-39d346579d0a_1024x500.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://securitylog.sva.de/2026/offsec/escalating-from-on-prem-to-entra-through-mitm-attacks/">https://securitylog.sva.de/2026/offsec/escalating-from-on-prem-to-entra-through-mitm-attacks/</a></p><h2><span>Exploring cross-domain &amp; cross-forest RBCD</span></h2><p><strong>Yann Razafimahefa</strong> shows once again that deep understanding of a technology by an adversarial thinker inevitably highlights things the designers and implementers would not have considered.</p><blockquote><p>Kerberos delegation capabilities in Linux-based tooling have been extended to allow impersonating any user within a forest. This assumed identity can then be leveraged to access resources across any domain within that forest, or even in a remote forest, provided that a trust relationship exists and appropriate delegation rights are configured. This article provides a deep dive into recursive Kerberos delegation exchanges through complex multi-domain chains. Finally, we demonstrate the feasibility of the SPN-less RBCD attack in both cross-domain and cross-forest contexts.</p></blockquote><p><a href="https://www.synacktiv.com/en/publications/exploring-cross-domain-cross-forest-rbcd-part-2">https://www.synacktiv.com/en/publications/exploring-cross-domain-cross-forest-rbcd-part-2</a><span> </span></p><h2>The &#8216;Ghost&#8217; in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI</h2><p><strong>Shebin Mathew</strong> delivers an ooof here. Will be interesting to see how Microsoft will clean up. Also highlights to detection engineers where they will need coverage now fact of is known.</p><blockquote><p>Mandiant discovered that when ADFS certificates are manually rotated, configuration drift can silently leave active signing keys exposed in Machine DPAPI. Specifically, Mandiant discovered that in environments where AutoCertificateRollover is disabled and certificates are manually rotated, the database often becomes a 'ghost'&#8212;a record that still exists, still decrypts successfully, but references a certificate no longer used for token signing by the ADFS service. This attack vector warrants attention because the underlying configuration is commonly deployed in enterprise environments. The technique avoids direct interaction with components such as LSASS and the live ADFS service process, which are often subject to enhanced monitoring in enterprise environments, and may therefore result in lower visibility depending on the organization&#8217;s telemetry coverage. This post details how adversaries may exploit this TTP to forge high-privilege SAML tokens and provides the blueprint to defend against it.</p></blockquote><p><a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi/">https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi/</a></p><h2>Process Parameter Poisoning</h2><p><strong>Max Hirschberger</strong> &amp; <strong>Ogulcan Ugur</strong> rediscover this technique.</p><blockquote><p><em><strong>Process Parameter Poisoning (P<sup>3</sup>)</strong></em> is an attack technique we developed that is used to inject code in foreign processes, without triggering typical detection mechanisms.</p><p>Its ability to fly under the radar has been tested against four market leading Endpoint Detection and Response (EDR) solutions. Code injection succeeded in all cases and no alerts were created, even though the EDRs were configured to detect, block and remediate.</p><p>Our implementation of the technique is published on GitHub: <a href="https://github.com/Orange-Cyberdefense/p3-loader">https://github.com/Orange-Cyberdefense/p3-loader</a></p><p>After publication, <a href="https://x.com/TheXC3LL">X-C3LL</a> showed the same primitive was previously presented by <a href="https://modexp.wordpress.com/">modexp</a> in a <a href="https://web.archive.org/web/20241211190548/https://modexp.wordpress.com/2020/07/31/wpi-cmdline-envar/">now deleted post</a>.</p></blockquote><p><a href="https://sensepost.com/blog/2026/process-parameter-poisoning/">https://sensepost.com/blog/2026/process-parameter-poisoning/</a></p><h2>Hook Chains (how I built Crystal Kit incorrectly*)</h2><p><strong>Rasta Mouse</strong> outlines a technique which detection engineers will want to consider their strategy for.</p><blockquote><p>CPL has* an interesting way of addressing this by way of hook "chains", which allow you to register multiple hook functions for an API.</p></blockquote><p><a href="https://rastamouse.me/cpl-hook-chains/">https://rastamouse.me/cpl-hook-chains/</a></p><h2>EasyTokens</h2><p><strong>Casey</strong> releases this which teams will want to verify they can detect use of.</p><blockquote><p>A device-code phishing server for adversary emulation. Captures Microsoft 365 OAuth tokens via the <a href="https://learn.microsoft.com/en-us/azure/active-directory/develop/v2-oauth2-device-code">Device Authorization Grant</a> flow.</p></blockquote><p><a href="https://github.com/secdev02/EasyTokens">https://github.com/secdev02/EasyTokens</a></p><h1>Exploitation</h1><p>What is being exploited..</p><h2>Large-scale exploitation campaign targeting website content management systems (CMS)</h2><p><strong>Australian Cyber Security Centre</strong>, part of the Australian Signals Directorate warns</p><blockquote><p>A large-scale exploitation campaign is targeting various vulnerabilities in content management systems (CMS) globally, including in Australia, with many small to medium sized Australian businesses impacted.</p><p>As part of this campaign, malicious cyber actors are actively scanning websites for opportunities to deploy webshells, leveraging various vulnerabilities affecting CMS software and plugins. These vulnerabilities primarily allow unauthenticated file upload, remote code execution, server side request forgery or deserialisation.</p><p>Once deployed, webshells can allow malicious cyber actors to remotely access and control targeted web servers. Malicious cyber actors may leverage compromised web servers for several purposes, including:</p><ul><li><p>Website defacement or disruption</p></li><li><p>Capturing credentials entered by website users or other data stored on web servers</p></li><li><p>Uploading additional malware to target and scam legitimate website users</p></li><li><p>Using web server access as a pathway for broader network compromise</p></li></ul></blockquote><p><a href="https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/large-scale-exploitation-campaign-targeting-website-content-management-systems-cms">https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/large-scale-exploitation-campaign-targeting-website-content-management-systems-cms</a></p><h1>Tooling and Techniques</h1><p>Low level tooling and techniques for attack and defence researchers</p><h2>BareMetal RAM Dumper</h2><p><strong>pIat0n</strong> releases this work aid for researchers looking to validate where this technique does work in practice.</p><blockquote><p>A simple x86 bare-metal tool designed to boot from a disk/USB and dump the system's RAM directly to the booting medium. It relies on BIOS interrupts to boot and perform disk operations, and enters unreal mode to access memory above the 1MB barrier.</p></blockquote><p><a href="https://github.com/pIat0n/BareMetal-RAM-Dumper">https://github.com/pIat0n/BareMetal-RAM-Dumper</a></p><h2>Interleaved HTML streaming (patching)</h2><p><strong><span>The Web Incubator Community Group (WICG)</span></strong><span>, which is a community group of the World Wide Web Consortium (W3C) that </span>incubates new web platform features, proposes an HTML update which could be interesting&#8230;</p><p><a href="https://github.com/WICG/declarative-partial-updates/blob/main/patching-explainer.md">https://github.com/WICG/declarative-partial-updates/blob/main/patching-explainer.md</a></p><h2>Does anyone even use GitHub for federated authentication?</h2><p><strong>Sapir</strong> walks through how do it and how it works..</p><blockquote><p>After walking through the entire authentication flow and trying a couple of abuse scenarios, I was actually pleasantly surprised.</p><p>Azure requires an exact subject match, GitHub doesn&#8217;t expose OIDC tokens to untrusted pull request workflows, and organization names don&#8217;t appear to be immediately reusable.</p><p>Overall, GitHub Actions federation looks significantly safer than storing client secrets in GitHub repository secrets.</p><p>I also realized how many GitHub configuration options exist around Actions and OIDC. There are probably plenty of interesting scenarios left to explore, but at least based on these experiments, GitHub federation seems to have some solid security decisions built in.</p></blockquote><p><a href="https://sapirxfed.com/2026/07/05/does-anyone-even-use-github-for-federated-authentication/">https://sapirxfed.com/2026/07/05/does-anyone-even-use-github-for-federated-authentication/</a></p><h2>PreviousMode Mitigation</h2><p><strong>Yarden Shafir</strong> details&#8230;</p><blockquote><p><span>The first topic of the series is: killing the </span><code>PreviousMode</code><span> overwrite exploitation technique.</span></p><p><span>This exploitation technique, that worked in all past Windows versions until Microsoft killed it in Windows 11 23H2, included overwriting a </span><code>KTHREAD</code><span>&#8216;s </span><code>PreviousMode</code><span> field to set it from user to kernel mode. When a thread is running with </span><code>PreviousMode == KernelMode</code><span>, the system will skip all security and access checks, since it assumes the call came from a driver. So, an arbitrary kernel write could turn into a full LPE, bypassing all Windows security restrictions.</span></p></blockquote><p><a href="https://windows-internals.com/random-windows-things-part-1-previousmode-mitigation/">https://windows-internals.com/random-windows-things-part-1-previousmode-mitigation/</a></p><h2>The Drift Corpus: Ring 0</h2><p>AI generates.. </p><blockquote><p>Drift Corpus is the definitive, open-source repository of Windows Kernel patch diffs.</p></blockquote><p><a href="https://github.com/ByteRay-AI/drift-corpus">https://github.com/ByteRay-AI/drift-corpus</a></p><h1>Footnotes</h1><p>Some other small (and not so small) bits and bobs which might be of interest.</p><ul><li><p>Annual, quarterly and monthly reports</p><ul><li><p><em>Nothing overly of note this week, but keep an eye on</em> <a href="https://github.com/jacobdjwilson/awesome-annual-security-reports/tree/main/Annual%20Security%20Reports/2026">the Awesome Annual Security Reports 2026 collection</a> and <a href="https://github.com/blackorbird/APT_REPORT">APT report collection</a></p></li></ul></li><li><p><a href="https://arxiv.org/abs/2606.29687">A Machine-Verified Proof of a Quantum-Optimization Conjecture</a></p></li><li><p><a href="https://hackmd.io/@levs57/HJkT2mEXMx">RMFE-skip</a> - &#8220;<em>I will try to establish a connection between different boolean circuit methods (multivariate skip, univariate skip, RMFE) and propose some new trick combining univariate skip and RMFE.&#8221;</em></p><ul><li><p><a href="https://github.com/levs57/hashcaster2">New keccak GKR protocol based</a> on new cool RMFE-in-polynomial-ring and univariate skip. Full GKR proving routine (24 rounds of keccak permutation) is integrated, commitments are not integrated yet.</p></li></ul></li><li><p>Artificial intelligence</p><ul><li><p><span>if you are a big </span><a href="https://arxiv.org/">arxiv.org</a><span> user - out of China there is </span><a href="https://www.alphaxiv.org/">alphaxiv.org</a><span> which is an AI powered incarnation / overlay</span></p></li><li><p>Fundamental</p><ul><li><p><a href="https://www.youtube.com/watch?v=NDdc39KYqDU">Stanford CS25: Transformers United V6 I From Language Models to Native Multimodal Intelligence</a></p></li><li><p><a href="https://mlc.ai/modern-gpu-programming-for-mlsys/">Modern GPU Programming For MLSys</a></p></li><li><p><a href="https://arxiv.org/abs/2606.08432">Trajectory-Refined Distillation</a></p></li><li><p><a href="https://arxiv.org/abs/2606.03990">Neuron Populations Exhibit Divergent Selectivity with Scale</a></p></li><li><p><a href="https://arxiv.org/abs/2606.11182">EEVEE: Towards Test-time Prompt Learning in the Real World for Self-Improving Agents</a></p><ul><li><p><a href="https://github.com/Princeton-AI2-Lab/EEVEE">Code</a></p></li></ul></li><li><p><a href="https://arxiv.org/abs/2606.32026">AdaJEPA: An Adaptive Latent World Model</a></p></li></ul></li><li><p>Applied non-cyber</p><ul><li><p><a href="https://arxiv.org/abs/2605.19338v1">STAR-P&#243;lyaMath: Multi-Agent Reasoning under Persistent Meta-Strategic Supervision</a></p></li><li><p><a href="https://arxiv.org/abs/2606.28277">Towards Automating Scientific Review with Google&#8217;s Paper Assistant Tool</a></p></li><li><p><a href="https://conf.researchr.org/details/fse-2026/fse-2026-industry-papers/60/Fun2spec-Code-Contract-Synthesis-At-Scale">Fun2spec: Code Contract Synthesis At Scale</a></p></li><li><p><a href="https://queue.acm.org/detail.cfm?id=3799737">On the Evolution of Program State Larger-scoped forces<br>shaping software engineering safety</a></p></li><li><p><a href="https://github.com/MontrealAI/goalos-agialpha-sovereign-machine-economy/blob/main/docs/paper/goalos_validated_skill_graph_reusable_capability.pdf">GoalOS: The Validated Skill Graph Reusable Capability, Chronicle-Gated Memory, and Proof-Carrying Skill Accumulation</a></p></li><li><p><a href="https://github.com/elder-plinius/T3MP3ST">T3MP3ST: Autonomous red teaming platform; multi-agent offensive-security meta-harness</a></p></li><li><p><a href="https://thevelocitywhitepapers.com/">The Velocity White Papers</a> - How the Government of Alberta is leveraging artificial intelligence to rapidly and securely transform its technical estate</p></li><li><p><a href="https://arxiv.org/abs/2607.08681">SolarChain-Eval: A Physics-Constrained Benchmark for Trustworthy Economic Agents in Decentralized Energy Markets</a></p></li></ul></li><li><p>Applied cyber specific</p><ul><li><p><a href="https://arxiv.org/abs/2607.07109">Certifying Ghosts: How Cybersecurity AI Agents Break the EU Cyber Resilience Act</a></p></li><li><p><a href="https://arxiv.org/abs/2607.08395">Token-Flow Firewall: Semantic Runtime Auditing for Persistent AI Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2607.08282">Multi-Agent Firewall Architecture for Privacy Protection of Sensitive Data in Interactions with Language Models</a></p></li><li><p><a href="https://arxiv.org/abs/2607.07774">ScopeJudge: Cost-Aware Pre-Execution Gating for Offensive Security Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2607.07738">REFORGE: A Method for Benchmarking <span>LLMs</span>&#8216; Reverse Engineering Capabilities in Decompiled Binary Function Naming</a></p></li><li><p><a href="https://arxiv.org/abs/2607.07461">Mitigating Taint-Style Vulnerabilities in MCP Servers via <span>Security</span>-Aware Tool Descriptions</a></p></li><li><p><a href="https://arxiv.org/abs/2607.06807">When Agents Go Rogue: Activation-Based Detection of Malicious Behaviors in Multi-Agent Systems</a></p></li><li><p><a href="https://arxiv.org/abs/2607.05916">Beyond the Syntax: Do <span>Security</span> Experts Trust <span>LLMs</span> for NIDS Rule Engineering?</a></p></li><li><p><a href="https://arxiv.org/abs/2607.05772">Detecting Vulnerability-Inducing Commits via Multi-Stage Reasoning with <span>LLM</span>-Based Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2607.05120">Agent Data Injection Attacks are Realistic Threats to AI Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2607.05001">TACTIC-KG: Toward Small Agent Teams for Cyber Threat Intelligence Knowledge Graph Construction</a></p></li><li><p><a href="https://arxiv.org/abs/2607.05743">The Balkanization of Execution-Security Research for <span>AI</span> Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use <span>Vulnerabilities</span></a></p></li><li><p><a href="https://www.aisi.gov.uk/blog/finding-cloud-misconfigurations-with-frontier-ai-a-case-study">Finding Cloud Misconfigurations with Frontier AI: A Case Study</a></p></li><li><p><a href="https://medium.com/@omgAPT/adversarial-intelligence-local-llms-for-automated-attacks-3bf684c51544">Adversarial Intelligence: Local LLMs for Automated Attacks</a></p></li><li><p><a href="https://ieeexplore.ieee.org/abstract/document/11580353"><span>LLM-Based Intelligent Agents for Cybersecurity: A Tutorial and Survey of Automated Vulnerability Discovery</span></a></p></li><li><p><a href="https://researchportal.northumbria.ac.uk/en/publications/agentic-sabre-an-uncertainty-aware-neuro-symbolic-multi-agent-fra/"><span>Agentic SABRE: An Uncertainty-Aware Neuro-Symbolic Multi-Agent Framework for Adaptive Ransomware Detection</span></a></p><ul><li><p>Poster - <a href="https://livenorthumbriaac-my.sharepoint.com/personal/biju_issac_northumbria_ac_uk/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fbiju%5Fissac%5Fnorthumbria%5Fac%5Fuk%2FDocuments%2FESWA%20Paper%2FAgentic%5FSABRE%5FPoster%2Epdf&amp;parent=%2Fpersonal%2Fbiju%5Fissac%5Fnorthumbria%5Fac%5Fuk%2FDocuments%2FESWA%20Paper&amp;ga=1">AGENTIC SABRE -  Uncertainty-Aware Neuro-Symbolic Multi-Agent Framework for Adaptive Ransomware Detection</a></p></li><li><p><a href="https://arxiv.org/abs/2607.04292">Agentic SABRE: An Uncertainty-Aware Neuro-Symbolic Multi-Agent Framework for Adaptive Ransomware Detection</a></p></li></ul></li></ul></li></ul></li><li><p>Books</p><ul><li><p><em>Nothing overly of note this week</em></p></li></ul></li><li><p>Events</p><ul><li><p><a href="https://conf.researchr.org/home/fse-2026">The ACM International Conference on the Foundations of Software Engineering</a> - papers</p><ul><li><p><a href="https://dl.acm.org/toc/pacmse/2026/3/FSE">Proceedings</a></p></li><li><p><a href="https://conf.researchr.org/track/fse-2026/fse-2026-industry-papers?">Industry papers</a></p></li></ul></li><li><p><a href="https://www.youtube.com/@RealWorldAISecConf?app=desktop">Real World AI Security Conference</a> - videos</p></li></ul></li></ul><p>Finally I recorded a vodcast with Andy talking about the role of cyber deception</p><div id="youtube2-NxfSBHmZC_4" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;NxfSBHmZC_4&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/NxfSBHmZC_4?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Finally finally the <a href="https://creators.spotify.com/pod/profile/national-cyber-security-c6/episodes/The-Ransomware-Ecosystem-e2hi088">NCSC&#8217;s podcast series</a>.</p><div><hr></div><p><em>Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them. </em></p><p><em>This newsletter is subject to the NCSC website terms and conditions which can be found at <a href="https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions">https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions</a> and you can find out more about how will treat your personal information in our privacy notice at <a href="https://www.ncsc.gov.uk/section/about-this-website/privacy-statement">https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.</a></em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CTO at NCSC - Cyber Defence Analysis! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CTO at NCSC Summary: week ending July 5th]]></title><description><![CDATA["Data from Report Fraud reveals that 323 organisations reported a ransomware attack between April 2025 and March 2026. Of the reports received, more than 50% were from Small Medium Enterprises"]]></description><link>https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-july-b99</link><guid isPermaLink="false">https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-july-b99</guid><dc:creator><![CDATA[Ollie Whitehouse]]></dc:creator><pubDate>Sat, 04 Jul 2026 18:02:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/-ueCcEdDjOM" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to the weekly highlights and analysis of the&nbsp;<a href="https://infosec.pub/c/blueteamsec?dataType=Post&amp;sort=New">blueteamsec</a>&nbsp;(and my wider reading). Not everything makes it in, but the best bits do. A community member is doing <a href="https://briefing.workshop1.net/">daily AI generated podcast of the last 24hours of posts</a>.</p><p>Operationally this week nothing overly of note.</p><p>In the high-level this week:</p><ul><li><p><a href="https://www.ncsc.gov.uk/blogs/building-more-resilient-cni-what-industry-pen-testers-told-us"><span>Building more resilient CNI: what industry penetration testers told us</span></a><span> - UK </span><strong><span>NCSC</span></strong><span> details - </span><em><span>&#8220;when we asked: &#8216;What can organisations do to make your job harder?&#8217;&#8221; &#8212; </span>Segment your networks and Have logging and monitoring in place&#8221;</em></p></li><li><p><a href="https://www.gov.uk/government/publications/cyber-security-and-resilience-network-and-information-systems-bill-factsheets#full-publication-update-history">Cyber Security and Resilience (Network and Information Systems) Bill: factsheets</a> - <strong>Department for Science, Innovation and Technology</strong> updates - <em>&#8220;Minor updates to the factsheets on 'information sharing' and 'incident reporting' for clarity and legal purposes&#8221;</em></p></li><li><p><a href="https://www.cityoflondon.police.uk/news/city-of-london/news/2026/june/dont-pay-the-ransom-warning-to-organisations-to-protect-themselves-from-ransomware-attacks-as-more-than-320-businesses-affected-last-year/">Don&#8217;t pay the ransom: Warning to organisations to protect themselves from ransomware attacks as more than 320 businesses affected last year</a> - <strong>City of London Police</strong> details - <em>&#8220;Data from Report Fraud reveals that 323 organisations reported a ransomware attack between April 2025 and March 2026. Of the reports received, more than 50 per cent were from Small Medium Enterprises (SMEs) (175 reports). Financial losses totalling around &#163;270,000 were reported, a 50 per cent increase compared to previous year. However, these figures are likely to be much higher, as businesses often underreport financial losses, as admission of ransom payments could be seen as supporting criminal activity or breaching compliance regulations.&#8221;</em></p></li><li><p><a href="https://www.bankofengland.co.uk/paper/2026/boe-and-fcas-approach-to-joint-regulation-of-systemic-stablecoin-issuers">Bank of England and Financial Conduct Authority&#8217;s approach to joint regulation of systemic stablecoin issuers</a> - <strong>Bank of England</strong> and the <strong>Financial Conduct Authority</strong> publish  - &#8220;<em>Through a co-ordinated approach and regulatory framework, we aim to provide regulatory clarity and certainty to firms issuing stablecoins in the UK whatever the size, aspirations or business model.&#8221;</em></p><ul><li><p><a href="https://www.bankofengland.co.uk/paper/2026/ps/sterling-denominated-systemic-stablecoin">Sterling-denominated systemic stablecoins: <span>Policy statement and consultation on draft Code of Practice</span></a><span> - </span><em><span>&#8220;Our position on the use of public permissionless ledgers (PPLs) by systemic stablecoin issuers remains unchanged from the November 2025 CP. We remain open to the use of PPLs by systemic stablecoin issuers provided they can meet our expectations and ensure trust and confidence in money. However we remain of the view that it may be challenging for these ledgers to meet our expectations when it comes to accountability, settlement finality and operational resilience, including cyber security.&#8221;</span></em></p></li></ul></li><li><p><a href="https://www.rusi.org/explore-our-research/publications/rusi-books/new-thinking-uk-cyber-effects-edited-collection">New Thinking on UK Cyber Effects: An Edited Collection</a> - <strong>RUSI</strong> think tank- <em>&#8220;This book explores the UK's approach to cyber effects operations, analysing strategic culture and policy in the evolving landscape of modern cyber warfare.&#8221;</em></p></li><li><p><a href="https://www.cse-cst.gc.ca/en/accountability/transparency/reports/communications-security-establishment-canada-annual-report-2025-2026">Communications Security Establishment Canada Annual Report 2025-2026</a> - <strong>Communications Security Establishment Canada </strong>details - <em>&#8220;<span>In 2025&#8211;2026, the Cyber Centre recorded more than </span>3,200 cyber incidents<span> affecting Government of Canada institutions and critical infrastructure sectors.&#8221;</span></em></p></li><li><p><a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1463">New analysis on the EU&#8217;s most threatening criminal networks</a> - <strong>European Commission</strong> / <strong>EuroPol</strong> analyses - 1.9% of said networks are apparently involved in cyber attacks today</p><ul><li><p><a href="https://www.europol.europa.eu/publication-events/main-reports/blueprint-of-criminal-opportunism#downloads">Report</a></p></li></ul></li><li><p><a href="https://www.fcc.gov/document/fcc-aims-accelerate-secure-submarine-cable-infrastructure-buildout"><span>FCC Aims to Accelerate Secure Submarine Cable Infrastructure Buildout</span></a><span> - </span><strong><span>FCC</span></strong><span> announces - &#8220;</span><em>Specifically, the rules adopted today presumptively exempt cable applications from the rigorous Team Telecom licensing review when licensees can certify to high security standards that are structured to increase certainty, predictability, and faster timelines for the licensing process.  Currently, all submarine cable applications get referred to Team Telecom, an Executive Branch interagency task force that reviews license applications for national security risks.  The changes adopted would exempt applications from applicants that have operated cables without incident, can certify to the highest national security standards, and agree to ongoing oversight and monitoring.  &#8220;</em></p></li><li><p><a href="https://www.nytimes.com/2026/06/30/us/politics/cia-reorganization-cyber-ai.html">C.I.A. Reorganization Prioritizes Cyberoperations</a> - <strong>The</strong> <strong>New York Times</strong> reports - <em>&#8220;John Ratcliffe, the C.I.A. director, announced on Tuesday that the agency was reorganizing to ensure that it can adopt technology faster and further develop offensive cyberoperations division.&#8221;</em> &#8230; <em>&#8220;He promised that the agency would use new technology more aggressively and take &#8220;smart risks,&#8221; even as it prioritized human decision making and oversight of artificial intelligence and other innovations.&#8221;</em></p></li><li><p> <a href="https://arstechnica.com/security/2026/06/following-user-outcry-amd-reinstates-memory-encryption-in-consumer-cpus/">Following user outcry, AMD reinstates memory encryption in consumer CPUs</a> - <strong>Ars Technica</strong> reports - <em>&#8220;The incident, and AMD&#8217;s refusal to discuss it, is emblematic of the public relations landscape that has emerged over the past two decades. Once, Big Tech and corporations in general were willing to acknowledge service and product changes to ensure customers had a predictable experience. They also showed a willingness to admit mistakes and to say how they planned to do better. Now, there&#8217;s only silence. As the companies&#8217; power and dominance have mushroomed, their sense of accountability has diminished proportionately.&#8221;</em></p></li><li><p><a href="https://css.ethz.ch/en/center/CSS-news/2026/06/kognitive-kriegsfuehrung-plaedoyer-fuer-eine-entbuendelung.html">Cognitive Warfare: The Case for Disaggregation</a> - <strong>Myriam Dunn Cavelty</strong> and <strong>Arthur Laudrain</strong> argue - <em>&#8220;Cognitive warfare is currently at the volatile beginning of this exact curve. Institutional incentives, ranging from broader mandates to bureaucratic competition for funding, presently reward threat inflation. The task for policymakers is therefore not to deny the underlying risks, but to disaggregate them. The goal of a mature defence strategy must be to replace a singular, dramatic label with a set of narrower problems, clearer causal standards, and appropriate, civilian-led policy toolkits.&#8221;</em></p></li><li><p><a href="https://www.gao.gov/products/gao-26-108443">Cybersecurity: Selected Agencies Need to Better Protect Cloud Data</a><strong> - </strong>US<strong> Government Accountability Office </strong>details - <em>&#8220;Agencies we reviewed varied in implementing key cloud computing security practices. For example, some agencies didn't fully continuously monitor security controls. Also, some agencies didn't document how to respond to or recover from cybersecurity incidents.&#8221;</em></p></li><li><p> Reporting on/from China</p><ul><li><p><a href="https://www.nikkei.com/article/DGXZQOCD17APR0X10C26A6000000/">&#8220;Send a USB drive from Japan&#8221;: A secret mission to a foreign student; the shadow of the Chinese military looms over past cyberattacks.</a> - <strong>Nikkei </strong>reports - <em>&#8220;USB drives have been repeatedly used as a means of cyberattack. An investigation by the Nikkei Shimbun revealed that the Japan Self-Defense Forces used USB drives infected with a Chinese virus, and USB drives have also been used in past attacks against Japan. There is a possibility that the Chinese military was operating in an organized manner.&#8221;</em></p></li><li><p><a href="https://www.chinadaily.com.cn/a/202607/03/WS6a470bf0a310986e2b463478.html">ADS rules in place with key Chinese input</a> - <strong>China Daily</strong> reports - <em>&#8220;As the first global regulation covering the full life cycle of Level 3 and Level 4 automated driving systems, the new rules &#8212; known as ADS GTR &#8212; were recently adopted by the United Nations Economic Commission for Europe and were jointly led by China, the European Union, the United Kingdom, the United States, Canada and Japan.&#8221; - </em>of note is their activity in international standard setting</p></li><li><p><a href="https://www.caixinglobal.com/2026-06-27/geely-backed-polestar-forced-out-of-us-by-chinese-auto-tech-ban-102458159.html?rkey=4jojc%2BU9DvvtuaHc2n7nI%2FFL%2FE7ci4pKisQKAJfVxMc9vtAdmXy6%2Bg%3D%3D&amp;cxg=web&amp;Sfrom=twitter">Geely-Backed Polestar Forced Out of U.S. by Chinese Auto Tech Ban</a> - <strong>Caixin Global</strong> reports - <em>&#8220;Under regulations finalized by the Commerce Department in early 2025, the U.S. will ban vehicles equipped with connected systems or autonomous driving software linked to China or Russia starting in 2027. Automakers caught in the crosshairs must apply for special authorization to remain in the market.&#8221;</em></p></li><li><p><a href="https://www.ft.com/content/c8731833-10ca-4a12-bfe4-8ebb2584ec68?syn-25a6b1a6=1">Robot nation: China&#8217;s bid to beat its demographic decline</a> - <strong>Financial Times</strong> reports - <em>&#8220;From Communist Party leaders in Beijing to business owners across China, there is a growing consensus that the country needs to embed &#8220;embodied artificial intelligence&#8221;, as AI-controlled robots are known, into as many tasks as possible and as soon as possible.&#8221;</em></p><ul><li><p><a href="https://subscriber.politicopro.com/article/2026/06/lutnick-signals-possible-action-on-chinese-robots-after-commerce-review-00972576">Lutnick signals possible action on Chinese robots after Commerce review</a> - <strong>Politico</strong> reports - <em>&#8220;Commerce Secretary Howard Lutnick told executives at a closed-door meeting Monday that his department is studying state-subsidized robotics imports and signaled the administration could take strong action once the review is complete, according to three people who attended the meeting and were granted anonymity to discuss it.</em></p><p><em>Officials increasingly see China&#8217;s state-backed robotics industry as a national security threat, fearing subsidized Chinese robots could dominate global markets before U.S. manufacturers have the scale to compete.&#8221;</em></p></li><li><p><a href="https://www.caixinglobal.com/2026-06-26/anyverse-dynamics-raises-over-200-million-as-chinas-robotics-funding-boom-accelerates-102458149.html?rkey=4jojc%2BU9DvvtuaHc2n7nI%2FFL%2FE7ci4pKisQKAJfVxMewNNJCdnC73w%3D%3D&amp;cxg=web&amp;Sfrom=twitter">Anyverse Dynamics Raises Over $200 Million as China&#8217;s Robotics Funding Boom Accelerates</a> - <strong>Caixin Global</strong> reports - <em>&#8220;The capital injection underscores a funding surge in China&#8217;s robotics industry, as startups race to build war chests for compute-intensive AI model training and position robotics as a future pillar industry comparable to electric vehicles.&#8221;</em></p></li></ul></li></ul></li><li><p> AI</p><ul><li><p><a href="https://www.warner.senate.gov/newsroom/press-releases/warner-unveils-discussion-draft-of-legislation-to-create-innovative-market-for-secure-artificial-intelligence-agents/">Warner Unveils Discussion Draft of Legislation to Create Innovative Market for Secure Artificial Intelligence Agents</a> - U.S. <strong>Sen. Mark R. Warner (D-VA)</strong> enters - &#8220;<em>Specifically, the AI Agent Act would:</em></p><ul><li><p><em>Establish rights and responsibilities for guaranteed secure access by AI agents to certain large online platforms.</em></p></li><li><p><em>Create a Federal Trade Commission registry of trusted, secure AI agents &#8211; with a regulatory environment swift enough to approve innovative user services or quickly curtail products that violate consumers&#8217; trust.</em></p></li><li><p><em>Require AI agents protect users&#8217; privacy and user data and act transparently in a user&#8217;s best interest and in a manner that makes clear to third-party websites and online service providers that an AI agent has valid authorization.</em></p></li><li><p><em>Direct NIST to identify technical standards and open protocols to make online services more accessible to AI agents and to ensure consensus-based standards around critical mechanisms like authentication.</em></p></li><li><p><em>Protect businesses, users, and online providers from AI agent abuse or misuse.&#8221;</em></p></li></ul></li><li><p><a href="https://www.scmp.com/tech/policy/article/3358559/digital-id-cards-china-moves-regulate-ai-agents-unified-identity-system?utm_source=twitter&amp;utm_campaign=3358559&amp;utm_medium=share_widget"><span>&#8216;Digital ID cards&#8217;: China moves to regulate AI agents with unified identity system</span></a><span> - </span><strong>South China Morning Post</strong> reports - <em>&#8220;China is establishing an identity system for <span>artificial intelligence agents</span>, as part of new national standards released on Friday to regulate the next frontier of autonomous technology. The State Administration for Market Regulation (SAMR) unveiled the standard for &#8220;Artificial Intelligence Agent Interconnection&#8221;, aiming to establish a &#8220;closed-loop system&#8221; with a unified identity management framework for all AI agents&#8221;</em></p></li><li><p><a href="https://www.reuters.com/legal/litigation/us-lawmaker-proposes-bill-require-ai-companies-report-critical-incidents-2026-06-25/">US lawmaker introduces bill to require AI companies to report critical incidents</a> - <strong>Reuters</strong> reports - <em>&#8220;The draft legislation, introduced by U.S. Representative Nathaniel Moran of Texas, would mandate AI companies to report to the U.S. &#8203;Commerce Department within seven days of discovering dangerous activity, with Commerce required to &#8203;notify Congress within 48 hours of the most serious incidents.&#8221;</em></p></li><li><p><a href="https://arxiv.org/abs/2606.31408">EnclaveX: End-to-End Confidential AI with CPU/GPU TEEs</a> - <strong>TU Dresden</strong> and friends outline - <em>&#8220;This paper addresses this gap by presenting an end-to-end workflow that combines CPU and GPU TEEs. We propose mechanisms to ensure confidentiality and integrity at both the VM level (via Intel TDX and AMD SEV-SNP) and the application level, highlighting vulnerabilities such as Kubernetes administrators&#8217; ability to access confidential VM contents. Finally, we evaluate the performance overhead of our system using industry benchmarks, focusing on configurations that integrate Intel TDX with NVIDIA H200 GPUs.&#8221;</em></p></li><li><p><a href="https://eugeneyan.com/writing/cybersecurity-evals/">Patterns for Building Cybersecurity Evals</a> - <strong>Eugene Yan, Anthropic</strong> outlines - <em>&#8220;Here, we discuss some benchmarks that measure this, from capture-the-flag exercises to data exfiltration on a 50-host network.&#8221; - </em>these small scale non-representative of small, medium or large operational environments need to come with various extrapolation caveats.</p></li><li><p><a href="https://arxiv.org/abs/2606.29175">Direct Causation in International Humanitarian Law and the Challenge of AI-Mediated Civilian Cyber Operations</a> - <strong>The University of Tokyo</strong> and friends outline - &#8220;<em>International humanitarian law protects civilians from direct attack unless and for such time as they take direct part in hostilities, with the ICRC&#8217;s 2009 Interpretive Guidance operationalising this rule through a three-criterion cumulative test. This paper argues that AI-mediated civilian cyber operations challenge the direct causation element of this test in a structurally specific way: when a civilian deploys an autonomous multi-agent cyber system of the kind recently demonstrated in offensive AI research, the &#8220;one causal step&#8221; standard fails because harm is produced by systemgenerated decisions made after human disengagement, and the integral-part requirement does not extend because it presupposes downstream human contributors whose conduct can be independently classified&#8221;</em></p></li><li><p><a href="https://www.boozallen.com/expertise/cybersecurity/whats-in-americas-code.html">What&#8217;s In America&#8217;s Code? - There are major risks with allowing Chinese LLMs to code for U.S. applications</a> - <strong>Booze Allen</strong> evaluates - &#8220;<em>we put LLMs to the test. In May 2026, Booz Allen used its AI-native test platform to evaluate five frontier AI models head-to-head: four Chinese models commonly used by U.S. developers and one American model. We explored three main questions:</em></p><ul><li><p><em>Do Chinese models generate more vulnerable code based on who is asking?</em></p></li><li><p><em>Do Chinese models refuse to engage with political topics that are sensitive in China?</em></p></li><li><p><em>Does the model&#8217;s country of origin affect code quality and content behavior?&#8221;</em></p></li></ul></li><li><p><a href="https://arxiv.org/abs/2603.23509">Internal Safety Collapse in Frontier Large Language Models</a> - <strong>Various researchers</strong> present - <em>&#8220;This work identifies a critical failure mode in frontier large language models (LLMs), which we term Internal Safety Collapse (ISC): under certain task conditions, models enter a state in which they continuously generate large volumes of harmful content while executing otherwise benign tasks.&#8221;</em></p></li><li><p><a href="https://www.thefai.org/posts/fai-launches-frontier-legal-defense-program">FAI Launches Frontier Legal Defense Program</a> - <strong>The Foundation for American Innovation</strong> announces - &#8220;<em>Frontier Legal Defense will be a rapid-response legal team that combats the concentration of power, incumbent rent-seeking, and government overreach in AI that threaten American progress, prosperity, and freedoms. It will conduct the legal advocacy, public interest litigation, and education necessary to counter these many threats.&#8221;</em></p></li><li><p><a href="https://www.scmp.com/tech/big-tech/article/3358434/chinas-zhipu-ai-sparks-new-deepseek-moment-cost-effective-coding-model?module=top_story&amp;pgtype=section">China&#8217;s Zhipu AI sparks new &#8216;DeepSeek moment&#8217; with cost-effective coding model</a> - <strong>South China Morning Post</strong> reports - <em>&#8220;Matt Velloso, a former vice-president at Meta Platforms and Google DeepMind, said on X last week that he had been using GLM-5.2 &#8220;all day&#8221; and found it to be the &#8220;first open model that passes the bar as a daily driver&#8221;.&#8221;</em></p></li><li><p><a href="https://www.scmp.com/tech/tech-trends/article/3358346/chinese-physical-ai-start-proposes-new-paradigm-bypasses-openai-meta-road-maps?utm_source=twitter&amp;utm_campaign=3358346&amp;utm_medium=share_widget"><span>Chinese physical AI start-up proposes new paradigm that bypasses OpenAI, Meta road maps</span></a><span> - </span><strong>South China Morning Post</strong> reports - <em>&#8220;The start-up, founded by former Nvidia senior manager Zhang Lihua, said the model &#8220;represents a new paradigm&#8221; that could effectively address issues commonly faced by currently available world models, such as &#8220;physical illusions, reasoning failures, and breakdowns in non-standard scenarios&#8221;.&#8221;</em></p></li></ul></li><li><p><em>Cyber proliferation</em></p><ul><li><p><a href="https://citizenlab.ca/research/member-of-committee-investigating-spyware-hacked-with-pegasus/">Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus</a> - <strong>Citizen Lab</strong> discloses - <em>&#8220;We found that former Member of the European Parliament Stelios Kouloglou was hacked with Pegasus spyware while serving on the PEGA committee, which investigated Pegasus and other spyware abuses in Europe. Through forensic analysis of his device, we found that the attackers could have had access to confidential documents and committee deliberations.&#8221;</em></p></li><li><p><a href="https://www.wired.com/story/eu-politicians-investigated-pegasus-spyware-then-it-ended-up-on-one-of-their-phones/">EU Politicians Investigated Pegasus Spyware. Then It Ended Up on One of Their Phones</a> - <strong>WIRED</strong> reports - <em>&#8220;He says that when he recently found out his device had been compromised by the powerful spyware, he was shocked and then angry. &#8220;Me being a member of the Pegasus Committee investigating Pegasus and at the same time being hacked by Pegasus,&#8221; he says, &#8220;it was something really too reckless.&#8221;</em></p></li></ul></li><li><p>Bounty Hunting</p><ul><li><p><a href="https://www.justice.gov/opa/pr/alleged-member-criminal-cyber-hacking-group-scattered-spider-arrested-finland-and-extradited"><span>Alleged Member of Criminal Cyber Hacking Group &#8220;Scattered Spider&#8221; Arrested in Finland and Extradited to the United States</span></a><span> - US </span><strong><span>Department of Justice</span></strong><span> announces - </span><em><span>&#8220;A criminal complaint unsealed Tuesday charges Peter Stokes, 19, a dual citizen of the United States and Estonia, with conspiracy, computer intrusion, and fraud. Stokes was arrested by Finnish authorities in April pursuant to an Interpol Red Notice and extradited to the United States last week. He made an initial appearance on Tuesday in federal court in Chicago and was ordered to remain in law enforcement custody.&#8221;</span></em></p></li><li><p><a href="https://en.protothema.gr/2026/06/24/how-greek-electricity-theft-ring-caused-more-than-e9m-in-losses-through-tampered-meters/">How Greek electricity theft ring caused more than &#8364;9m in losses through tampered meters</a> - <strong>&#928;&#961;&#974;&#964;&#959; &#920;&#941;&#956;&#945;</strong> reports - <em>&#8220;<span>In EDMIATLAS-type </span>digital meters<span>, the method was more technically advanced. Police said the group used illegal firmware installed in the body of the meter through a special optical probe. This gave them unauthorised access to the meter&#8217;s software and to HEDNO&#8217;s telemetry information system, through which electricity consumption data is transmitted online.&#8221;</span></em></p></li><li><p><a href="https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/">FBI Seizes NetNut Proxy Platform, Popa Botnet</a> - <strong>KrebsOnSecurity</strong> reports - <em>&#8220;Earlier today, NetNut&#8217;s homepage was replaced with a seizure notice from the FBI and the Internal Revenue Service Criminal Investigation division. The seizure notice thanked Google, Lumen, Shadowserver and other industry partners for their help in dismantling hundreds of domains tied to the Popa botnet, which experts say has long been synonymous with NetNut&#8217;s residential proxy infrastructure.&#8221;</em></p></li></ul></li><li><p>Market Incentives</p><ul><li><p><a href="https://www.theregister.com/legal/2026/07/02/startup-sues-palo-alto-networks-koi-security-saying-an-ai-hallucinated-report-falsely-linked-it-to-chinese-espionage/5266201">Startup sues Palo Alto Networks&#8217; Koi Security, saying an AI-hallucinated report falsely linked it to Chinese espionage</a> - <strong>The Register</strong> reports - <em>&#8220;MeetingTV has sued Palo Alto Networks after its newly acquired Koi Security threat-intelligence biz published a blog that linked the video conferencing and webinar startup to a Chinese corporate espionage operation. The legal complaint filed against Koi Security, its researchers, and Palo Alto Networks alleges that Koi used an LLM to generate the threat report, the AI system hallucinated findings about MeetingTV, and the security shop then published those as facts in a December 30 blog.&#8221;</em></p></li><li><p><a href="https://www.insurancejournal.com/news/national/2026/06/30/875802.htm">US Cyber Insurance Market Sees Flat Premium, More Third-Party Claims Hit Loss Ratio</a> - <strong>Insurance Journal</strong> reports - &#8220;<em>The U.S. cyber insurance market may be facing a time of transition as certain signs point to eventual adverse development. According to AM Best, the market&#8217;s loss ratio in 2025 increased for the second straight year to 53&#8212;the first time over 50 since the ransomware spike seen during the COVID pandemic. In the meantime, third-party claims are rising and total premium was basically flat after considering that a perceived increase in 2025 was caused by insurer Beazley&#8217;s move of a block of business from an offshore entity to the U.S.&#8221;</em></p></li></ul></li></ul><p>No reflections this week.</p><p>Not getting this via email? Subscribe:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Think someone else would benefit? Share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-july-b99?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-july-b99?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p><strong>All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.</strong></p><p>Have a lovely Saturday&#8230;</p><p>Ollie</p><h1>Cyber threat intelligence</h1><p>Who is doing what to whom and how allegedly.</p><h2>Reporting on Russia</h2><h3>Since the beginning of the full-scale war, the SBU has neutralized over 16 thousand Russian cyberattacks and cyberincidents</h3><p><strong>Cybersecurity Department (DCIB) of the SBU</strong>, Ukraine discloses the scale of alleged Russian activity since the war began.</p><blockquote><p>The attackers launched an attack on the information and communication systems of this TV channel with a phishing campaign and simultaneously tried to penetrate the adjacent infrastructure. SBU specialists detected the intrusion in a timely manner and prevented the enemy from achieving its ultimate goal - gaining control over a resource for publishing propaganda content on behalf of Ukrainian media," the head of the SBU's State Committee for Information and Communication Affairs reported.</p></blockquote><p><a href="https://ssu.gov.ua/novyny/z-pochatku-povnomasshtabnoi-viiny-sbu-neitralizuvala-ponad-16-tysiach-rosiiskykh-kiberatak-ta-kiberintsydentiv">https://ssu.gov.ua/novyny/z-pochatku-povnomasshtabnoi-viiny-sbu-neitralizuvala-ponad-16-tysiach-rosiiskykh-kiberatak-ta-kiberintsydentiv</a></p><h3><span>Analysis of APT-C-20&#8217;s covert attack activities using techniques such as explorer hijacking and LSB steganography</span></h3><p><strong><span>360 &#8203;&#8203;Advanced Threat Research Institute</span></strong><span> in China details an alleged Russian capability which will be of interest given various considerations. Ensuring detection coverage is recommended.</span></p><blockquote><p>[We] discovered that this group uses decoy documents carrying malicious macros as the initial carrier. After the macro code is executed, it parses and releases malicious components from within the document. Subsequently, it uses COM hijacking to establish a user-level persistence mechanism and triggers the loading of a malicious DLL by using the process of initializing COM objects through the file explorer. The loaded core module further extracts and executes shellcode from steganized image resources, ultimately building a stealthy control framework based on the legitimate cloud storage platform Filen.io in memory, achieving fileless residency and remote control capabilities.</p></blockquote><p><a href="https://mp.weixin.qq.com/s/TDb_UzNfebMzMxh_bQdMvA">https://mp.weixin.qq.com/s/TDb_UzNfebMzMxh_bQdMvA</a></p><h2>Reporting on China</h2><h3>ToddyCat: your hidden email assistant</h3><p><strong>Andrey Gunkin</strong> details alleged Chinese capability which shows a degree of tenacity in order to gain and sustain access to cloud based e-mail. </p><blockquote><p>The attackers continued their search for ways to bypass security solutions and developed a new tool to gain access to a victim&#8217;s cloud account via the Google API. Armed with this tool, the group automated all stages of the attack and managed to remain undetected by monitoring systems.</p><p>The methods used in that campaign indicated that ToddyCat was attempting to access corporate correspondence while evading monitoring tools. However, all of the group&#8217;s methods we described previously are effectively detected by EPP and EDR solutions.</p></blockquote><p><a href="https://securelist.com/toddycat-apt-umbrij-tool-and-oauth/120251/">https://securelist.com/toddycat-apt-umbrij-tool-and-oauth/120251/</a></p><h3>Mustang Panda targets India&#8217;s government and energy sectors with ZOHOMURK and MINIRECON</h3><p><strong><span>Santiago Pontiroli</span></strong><span> and </span><strong><span>Subhajeet Singha</span></strong><span> detail an alleged Chinese campaign which highlight both the victimology as well as capability. The prevalence of DLL side loading in the report suggests there is value from focusing on detection of it.</span></p><blockquote><ul><li><p>{We have] <span>been tracking two concurrent campaigns orchestrated by Mustang Panda targeting Indian government entities, delivering new malware implants and abusing Zoho WorkDrive, a legitimate cloud storage platform commonly used in the Indian government sector.</span></p></li><li><p><span>The two identified campaigns target India&#8217;s hydropower sector and government entities engaged in cooperation agreements (MOUs) with Taiwanese government institutions, leveraging a newly discovered malware toolkit comprising SHARDLOADER, MINIRECON and ZOHOMURK.</span></p></li><li><p><span>SHARDLOADER variants demonstrate moderate sophistication, leveraging persistence and DLL sideloading to deploy two newly identified implants: ZOHOMURK and MINIRECON.</span></p></li><li><p><span>ZOHOMURK is a newly identified implant that leverages Zoho WorkDrive for command-and-control, data exfiltration and remote task execution.</span></p></li></ul></blockquote><p><a href="https://www.acronis.com/en/tru/posts/mustang-panda-targets-indias-government-and-energy-sectors/">https://www.acronis.com/en/tru/posts/mustang-panda-targets-indias-government-and-energy-sectors/</a></p><h3>Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India/MoF Tax Infrastructure via Multi-Stage DcRAT Deployment</h3><p><strong>Dixit Panchal</strong> details an alleged Chinese campaign which has a very specific focus. The specific tradecraft however is rudimentary. </p><blockquote><p>As part of our latest investigation, we uncovered a campaign that demonstrates operational and technical similarities to a China-nexus threat cluster. Further analysis revealed overlapping TTPs with a prominent and highly active threat actor known for conducting cyber-espionage operations against Asian countries through the deployment of RAT-based malware.</p><p>Geographic Focus: India (Pan-India taxpayer base)</p><ul><li><p>Corporate Companies &amp; Businesses.</p></li><li><p>Individual Taxpayers.</p></li><li><p>Tax Professionals &amp; CAs.</p></li><li><p>Government Contractors.</p></li><li><p>Tax Consultants &amp; Filing Agents.</p></li><li><p>Corporate Finance &amp; Accounts Teams.</p></li></ul></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!nnCu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2f9302-05e5-4598-85a9-b27393a76275_601x600.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!nnCu!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2f9302-05e5-4598-85a9-b27393a76275_601x600.png 424w, /__u/substackcdn.com/image/fetch/$s_!nnCu!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2f9302-05e5-4598-85a9-b27393a76275_601x600.png 848w, /__u/substackcdn.com/image/fetch/$s_!nnCu!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2f9302-05e5-4598-85a9-b27393a76275_601x600.png 1272w, /__u/substackcdn.com/image/fetch/$s_!nnCu!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2f9302-05e5-4598-85a9-b27393a76275_601x600.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!nnCu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2f9302-05e5-4598-85a9-b27393a76275_601x600.png" width="601" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f2f9302-05e5-4598-85a9-b27393a76275_601x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:601,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!nnCu!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2f9302-05e5-4598-85a9-b27393a76275_601x600.png 424w, /__u/substackcdn.com/image/fetch/$s_!nnCu!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2f9302-05e5-4598-85a9-b27393a76275_601x600.png 848w, /__u/substackcdn.com/image/fetch/$s_!nnCu!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2f9302-05e5-4598-85a9-b27393a76275_601x600.png 1272w, /__u/substackcdn.com/image/fetch/$s_!nnCu!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2f9302-05e5-4598-85a9-b27393a76275_601x600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.seqrite.com/blog/operation-dragonreturn-china-nexus-cyber-espionage-campaign-targeting-govt-of-india-mof-tax-infrastructure-via-multi-stage-dcrat-deployment/">https://www.seqrite.com/blog/operation-dragonreturn-china-nexus-cyber-espionage-campaign-targeting-govt-of-india-mof-tax-infrastructure-via-multi-stage-dcrat-deployment/</a></p><h3>Anatomy of a WHQL-Signed Windows Filtering Platform (WFP) Kernel-Resident Network Backdoor</h3><p><strong>Pierre-Henri Pezier</strong> details a malicious driver which someone, potentially in China, managed to get signed&#8230;</p><blockquote><p><code>wskmon.sys</code> is a 64-bit Windows kernel-mode driver that acts as a fully-featured remote access backdoor. Unlike conventional rootkits, it requires no IOCTL interface, no user-mode agent, and no injected DLL. The entire attack surface is a single <code>.sys</code> file that registers a Windows Filtering Platform (WFP) stream callout to intercept inbound TCP traffic. </p><p>Commands arrive encrypted over the network, are authenticated with HMAC-SHA256, and executed entirely within the kernel. The driver was first submitted to VirusTotal on 2026-06-15 03:55:33 UTC from China. Its Authenticode certificate carries the subject &#28145;&#22323;&#24066;&#22885;&#32852;&#20449;&#24687;&#23433;&#20840;&#25216;&#26415;&#26377;&#38480;&#20844;&#21496; (Shenzhen Aolian Information Security Technology Co., Ltd.) &#8212; allowing the driver to load on systems that trust Microsoft&#8217;s driver-signing ecosystem.</p></blockquote><p><a href="https://www.nextron-systems.com/2026/06/26/anatomy-of-a-whql-signed-windows-filtering-platform-wfp-kernel-resident-network-backdoor/">https://www.nextron-systems.com/2026/06/26/anatomy-of-a-whql-signed-windows-filtering-platform-wfp-kernel-resident-network-backdoor/</a></p><h2>Reporting on North Korea</h2><h3>Lazarus-Linked npm Malware Masquerades as Rollup Polyfills</h3><p><strong>Yair Benamou</strong> details an alleged North Korean operation which uses look alike packages. Unclear how effective it was in practice.</p><blockquote><p>This campaign is effective because each layer appears ordinary when viewed on its own. The entry package looks like Rollup polyfill infrastructure. The second-stage package looks like an SVG utility. The JSONKeeper response appears to be structured data. Only after following the full chain does the real behavior become clear: remote access, browser and wallet theft, file collection, and clipboard monitoring.</p><p>Lookalike build dependencies deserve careful review even when the name is not an obvious typo. A copied README, a trusted repository link, and functional-looking package code can be enough to hide a serious compromise.</p></blockquote><p><a href="https://research.jfrog.com/post/rollup-polyfill-masquerading/">https://research.jfrog.com/post/rollup-polyfill-masquerading/</a></p><h3>PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems</h3><p><strong>Karlo Zanki</strong> details an alleged North Korean campaign which shows the scale of the operations and their persistence. </p><blockquote><p>Our latest findings show that the campaign has expanded beyond npm into additional open source ecosystems, with 162 malicious release artifacts identified across 108 unique packages, including compromise traces in 80 Go modules, 10 Packagist packages, and one Chrome extension. The campaign remains active, and new malicious packages are likely to continue appearing as threat actors compromise maintainer accounts, modify legitimate repositories, and publish infected package versions where they retain or obtain registry access.</p></blockquote><p><a href="https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands">https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands</a></p><h2>Reporting on Iran</h2><h3>Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool</h3><p><strong>Insikt Group&#174;</strong> details an alleged Iranian operation which relies on social engineering for initial access.</p><blockquote><p>It is highly likely that TAG-182 is targeting Iranians living inside and outside the country using different lures, including free download tools and fake VPN applications. The group&#8217;s operations are highly likely active across social media platforms like Instagram.</p><ul><li><p>TAG-182 is highly likely a component of Iran&#8217;s broader surveillance ecosystem, using MarkiRAT malware distributed through fake Android applications masquerading as legitimate services such as VPNs and media tools to collect intelligence from Iranian targets. </p></li><li><p> The MarkiRAT sample identified during this research shares notable tradecraft overlaps with historical variants, including the use of the Background Intelligent Transfer Service (BITS), suggesting a credible relationship between TAG-182 and activity previously attributed to Ferocious Kitten. However, while these similarities support an operational connection, additional evidence is necessary to confidently assess that the two clusters are organizationally linked. </p></li></ul></blockquote><p><a href="https://www.recordedfuture.com/research/nexus-tag182-disseminates-markirat">https://www.recordedfuture.com/research/nexus-tag182-disseminates-markirat</a></p><h2>Reporting on Other Actors</h2><h3>Boss Scam: Don&#8217;t Trust Every &#8220;Urgent&#8221; Message from Your Boss!</h3><p><strong>Azhagan KMS</strong> details an interesting campaign which monitors for WhatsApp web sessions in order to obtain session details for further social engineering. </p><blockquote><p>It runs in the background till it finds an active WhatsApp Web session in Chromium-based browsers such as Google Chrome and Microsoft Edge. Once an authenticated WhatsApp Web session is identified, it collects browser session artifacts, including authentication tokens, cookies, encryption material, and other browser data required to potentially restore or hijack an authenticated WhatsApp Web session.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!6CwL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f7c5794-4045-43e3-9de5-5f348bce3a0f_624x277.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!6CwL!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f7c5794-4045-43e3-9de5-5f348bce3a0f_624x277.png 424w, /__u/substackcdn.com/image/fetch/$s_!6CwL!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f7c5794-4045-43e3-9de5-5f348bce3a0f_624x277.png 848w, /__u/substackcdn.com/image/fetch/$s_!6CwL!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f7c5794-4045-43e3-9de5-5f348bce3a0f_624x277.png 1272w, /__u/substackcdn.com/image/fetch/$s_!6CwL!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f7c5794-4045-43e3-9de5-5f348bce3a0f_624x277.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!6CwL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f7c5794-4045-43e3-9de5-5f348bce3a0f_624x277.png" width="624" height="277" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f7c5794-4045-43e3-9de5-5f348bce3a0f_624x277.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:277,&quot;width&quot;:624,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!6CwL!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f7c5794-4045-43e3-9de5-5f348bce3a0f_624x277.png 424w, /__u/substackcdn.com/image/fetch/$s_!6CwL!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f7c5794-4045-43e3-9de5-5f348bce3a0f_624x277.png 848w, /__u/substackcdn.com/image/fetch/$s_!6CwL!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f7c5794-4045-43e3-9de5-5f348bce3a0f_624x277.png 1272w, /__u/substackcdn.com/image/fetch/$s_!6CwL!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f7c5794-4045-43e3-9de5-5f348bce3a0f_624x277.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://labs.k7computing.com/index.php/boss-scam-dont-trust-every-urgent-message-from-your-boss/">https://labs.k7computing.com/index.php/boss-scam-dont-trust-every-urgent-message-from-your-boss/</a></p><h3>Inside StegoAd</h3><p><strong>Microsoft Edge Extensions Security Team</strong> details a long running and scaled campaign which is technically interesting. The criminal driver is of note given the technical investment and efforts gone to in order to protect.</p><blockquote><p>At its core, StegoAd is a monetization and credential theft platform. Every technique, including steganography, polymorphism, and time-delayed activation protects a multi-layered revenue and data theft engine:</p><p>Steganography, polymorphism, RCE backdoors, and 119 malicious browser extensions: dissecting an ever-evolving campaign</p><ul><li><p>119 browser extensions impersonating popular tools &#8212; ad blockers, VPNs, translators, and video downloaders </p></li><li><p>~2.6 million users impacted across 2 years of steganographic campaign (March 2024 &#8211; April 2026); threat actor active since at least 2021 </p></li><li><p>Steganographic payload delivery via PNG, WebP, and WOFF2 font files &#8212; a first for browser extension threats at this scale </p></li><li><p>Remote Code Execution (RCE) backdoor where the C2 server delivers arbitrary JavaScript executed via setTimeout(), enabling full browser-context RAT capability</p></li></ul></blockquote><p><a href="https://microsoftedge.github.io/edgevr/assets/files/stego_ad/Microsoft_Edge_Security_StegoAd.pdf">https://microsoftedge.github.io/edgevr/assets/files/stego_ad/Microsoft_Edge_Security_StegoAd.pdf</a></p><h3>ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365</h3><p><strong>Michael Kelley</strong> provides further details around this campaign including the initial lure. Of note is the fact that SPF, DKIM and DMARC all failed their checks.</p><blockquote><ul><li><p>[We] identified a fully-featured phishing-as-a-service (PhaaS) operator panel, branded &#8220;ARToken,&#8221; that shares infrastructure, API contracts, and operational patterns with the EvilTokens platform documented by Sekoia and Microsoft in early 2026.</p></li><li><p>The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token (PRT) persistence, email access, business email compromise (BEC) operations, and SharePoint exfiltration &#8212; all accessible to operators through a React-based dashboard.</p></li><li><p>Analysis of the platform&#8217;s publicly served JavaScript bundle reveals the complete post-compromise toolkit available to affiliates, including capabilities not previously detailed in public reporting on EvilTokens.</p></li><li><p>The phishing kit deploys a seven-layer anti-analysis system combining client-side behavioral verification with XOR-encrypted payloads, a more sophisticated evasion approach than the server-side X-Antibot-Token mechanism documented in prior EvilTokens research.</p></li></ul><p>Most public reporting on EvilTokens covers the panel and the kit. What it has not shown is how an ARToken lure actually reaches an inbox. Talos recovered two near-identical messages, sent roughly four minutes apart on April 20, 2026, that initiate the chain. The tradecraft is targeted, not spray-and-pray.</p><p>&#8230;</p><p>All three checks fail: SPF, DKIM (body-hash mismatch), and DMARC (compauth=none reason=405). The display identity is not authenticated from the sending path.</p></blockquote><p><a href="https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/">https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/</a></p><h3>JADEPUFFER: Agentic ransomware for automated database extortion</h3><p><strong>Michael Clark</strong> details an operation which shows agentic use - note this is a productivity gain and not a world end moment.</p><blockquote><p>JADEPUFFER's own payloads were self-narrating. They contained natural language reasoning, target prioritization, and the kind of detailed annotations that human operators don&#8217;t often write but LLM-generated code produces reflexively. The operation also adapted in real time, retrying failed steps within refined parameters. In one sequence, it went from a failed login to a working fix in 31 seconds.</p><p>&#8230;</p><p>JADEPUFFER&#8217;s operation unfolded across two distinct targets: the internet-facing Langflow instance that provided initial access, and a separate production database server, which was JADEPUFFER&#8217;s true objective. The machine compromised during initial access was used in the compromise of the final target. All payloads were delivered as Base64-encoded Python through the Langflow RCE endpoint.</p></blockquote><p><a href="https://webflow.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion">https://webflow.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion</a></p><h3>A Djinn in the Machine: TaskWeaver&#8217;s Node.js Intrusion Chain</h3><p><strong>Nevan Beal</strong> and <strong>Sam Decker</strong> detail a campaign which is noteworthy for the theft of AI assistant authentication tokens.</p><blockquote><ul><li><p>The intrusion began with confirmed exploitation of CVE-2026-48558, allowing the attacker to bypass SimpleHelp OIDC authentication and obtain a technician session.</p></li></ul><ul><li><p>TaskWeaver is a heavily obfuscated Node.js loader, delivered as jquery.js and executed through node.exe, that implements an encrypted, reusable payload delivery channel rather than a fixed set of post exploitation commands.</p></li></ul><ul><li><p>The observed second stage payload, Djinn Stealer, targets Windows, macOS, and Linux systems.</p></li></ul><ul><li><p>Djinn Stealer collects credentials associated with cloud platforms, source control, package registries, infrastructure tooling, AI development assistants, browsers, SSH, and cryptocurrency wallets.</p></li></ul><ul><li><p>Stolen AI assistant tokens can hand attackers everything the AI was trusted to access, including repositories, databases, and cloud accounts, extending the breach well beyond the AI itself.</p></li><li><p>The attacker repurposed legitimate RMM capabilities to transfer files and remotely execute malware across managed systems.</p></li></ul></blockquote><p><a href="https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/">https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/</a></p><h3>Software Supply Chain Incursions</h3><p><span>A reminder we issued guidance a number of weeks ago in </span><a href="https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies">Software supply chain attacks: check your dependencies</a><span> for software developers</span></p><ul><li><p><a href="https://www.fortinet.com/blog/threat-research/from-ci-cd-to-cloud-data-how-shai-hulud-persistence-leads-to-redshift-breach">From CI/CD to Cloud Data: How Shai Hulud Persistence Leads to Redshift Breach</a></p></li><li><p><a href="https://research.jfrog.com/post/hijacked-npm-vscode-tasks-blockchain/">Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer</a></p></li><li><p><a href="https://research.jfrog.com/post/rollup-polyfill-masquerading/">Lazarus-Linked npm Malware Masquerades as Rollup Polyfills</a></p></li><li><p><a href="https://nsfocusglobal.com/ai-security-incident-case-miasma-worm-attacked-microsoft-github/">AI Security Incident Case: Miasma Worm Attacked Microsoft GitHub</a></p></li><li><p><a href="https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands">PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems</a></p></li><li><p><a href="https://yeethsecurity.com/blog/2026-07-02-The-jsononifier-npm-Dropper">Dropping Malware through Dependencies in VS Code: Inside the jsononifier npm </a></p></li><li><p><a href="https://yeethsecurity.com/blog/2026-07-02-The-jsononifier-npm-Dropper">Dropper</a></p></li></ul><h1>Discovery</h1><p>How we find and understand the latent compromises within our environments.</p><h2>The Blind Spot in the Watchtower: Detections for When Someone Attacks Your Sentinel</h2><p><strong>Rohit Ashokgowd</strong> details how you do protective monitoring of Sentinel itself which all defensive teams should read. Would you know if your Sentinel environment had been degraded? </p><blockquote><p>For Sentinel to watch itself, it needs a record of the changes made to it. That record lives in three places, and each check below pulls from one of them.</p><ul><li><p><strong>AzureActivity</strong> is the broad log of who did what. When someone creates, changes or deletes something in Sentinel like a rule, a feed or a setting-it shows up here with the user name and IP address. This is the main sourcen and it comes from the Azure Activity connector which is free.</p></li><li><p><strong>SentinelAudit</strong> is the detailed change log for detection rules. It shows who changed a rule and what it looked like before and after. It only works after you turn on Sentinel&#8217;s health and audit feature, which is also free.</p></li><li><p><strong>SentinelHealth</strong> shows whether your rules are actually running. It also makes it clear when a rule is disabled and did not run. It uses the same health and audit feature switch.</p></li></ul></blockquote><p><a href="https://detect.fyi/the-blind-spot-in-the-watchtower-detections-for-when-someone-attacks-your-sentinel-897709f0dcd9">https://detect.fyi/the-blind-spot-in-the-watchtower-detections-for-when-someone-attacks-your-sentinel-897709f0dcd9</a></p><h2>Knossos: Procedurally Generated Decoy Environments</h2><p><strong>Mario Bartolome</strong> shows how to build practical decoy environments which has the opportunity to impose cost on adveraries.</p><blockquote><p>How we built a procedural engine that learns your real cloud environment, generates decoy environments indistinguishable from production, and converts every attacker interaction into signal.</p></blockquote><p><a href="https://www.praetorian.com/blog/knossos-decoy-environments/">https://www.praetorian.com/blog/knossos-decoy-environments/</a></p><h2>Detecting Agentic Threats in Claude: Writing Rules on the Execution Layer</h2><p><strong>Andrew Byford</strong> contributes another material uplift with this release on how to do practical protective monitoring of an AI environment.</p><blockquote><p>In this post I look at the main threats from agentic platforms, and how we can use the execution-layer telemetry we&#8217;re getting from Claude to write detections for them.</p></blockquote><p><a href="https://www.papermtn.co.uk/detecting-agentic-threats-in-claude-writing-rules-on-the-execution-layer/">https://www.papermtn.co.uk/detecting-agentic-threats-in-claude-writing-rules-on-the-execution-layer/</a></p><h2>ARGUS: Production-Scale Tracing and Performance Diagnosis for over 10,000-GPU Clusters</h2><p><strong>Tencent</strong> from China shows how they are applying observability to their GPU stack. Including as there are potential read across to defensive use cases here. </p><blockquote><p>We propose ARGUS, a low-overhead, fine-grained, always-on tracing and real-time analysis system for training workloads in 10,000+ GPU-scale production clusters. ARGUS decomposes observation along the training call hierarchy into CPU call stacks, framework semantics, and GPU kernel execution, with always-on collection under a combined overhead of less than 2%. It builds a unified data pipeline and compresses raw kernel events by approximately 3,700x from 10 MB to 2.7 KB per rank per step. Its progressive diagnosis framework automatically isolates anomalous windows, straggler ranks, and degraded kernels through iteration-time, phase-level, and kernel-level analysis. Deployed for over six months on a 10,000+ GPU production cluster, ARGUS has supported continuous fail-slow detection and performance optimization. Our case studies further demonstrate its effectiveness across representative anomalies, including compute stragglers, link degradation, pipeline-bubble amplification, FlashAttention JIT stalls, and compute stragglers masked by communication symptoms.</p></blockquote><p><a href="https://arxiv.org/abs/2606.20374">https://arxiv.org/abs/2606.20374</a></p><h2><span>Claude Code Covert Telemetry Behavior Analysis</span></h2><p><strong><span>Andy Wang</span></strong><span> details&#8230;</span></p><blockquote><p><span>Today I came across an article saying that Claude Code detects whether a user is using a proxy and their timezone, then secretly reports this information by modifying a few characters in the system prompt. The original post was on Reddit, titled &#8220;Anthropic embedded spyware in Claude Code &#8212; and attempted to hide it from you.&#8221; Below is my verification process. My environment is Windows 11, and my Claude Code version is 2.1.196, installed via npm.</span></p></blockquote><p><a href="https://mp.weixin.qq.com/s/6F4JPNaS0KcrjUVxmXP7Jw">https://mp.weixin.qq.com/s/6F4JPNaS0KcrjUVxmXP7Jw</a></p><h2><span>Automatic Security Log Analysis Report Based on Large Model</span></h2><p><strong>The Cave of the Recluse in the Clouds</strong> from China walks through how they achieved the below hinting a the future way of working.</p><blockquote><p>The core objective is to use the semantic analysis and professional judgment capabilities of large models to automatically generate standardized professional security analysis reports for department heads, replacing the repetitive work of manually sorting through logs line by line and manually summarizing and writing reports.</p></blockquote><p><a href="https://mp.weixin.qq.com/s/u6cSpn2c9kMIE3qQRnHFGA">https://mp.weixin.qq.com/s/u6cSpn2c9kMIE3qQRnHFGA</a></p><h1>Defence</h1><p>How we proactively defend our environments.</p><h2><span>Agentic SOC Practice: Flocks</span></h2><p><strong><span>Rosey</span></strong><span> from China walks through Flocks and again hints at a future way of working.</span></p><blockquote><p>The most crucial aspect of Flocks is that it doesn't just provide a single agent; instead, it integrates multi-agent capabilities and a workflow execution engine onto the same platform. Agents can invoke workflows for execution, and workflows can also invoke agents, allowing for flexible orchestration and use.</p><p>..</p><p><span>In summary, Flocks provides not a single-point agent for the view that &#8220;AI Agent should first check evidence, supplement context, eliminate noise, and narrow the hypothesis space&#8221;, but a platform-based answer that can connect alarm access, process orchestration, tool invocation and agent analysis.</span></p></blockquote><p><a href="https://mp.weixin.qq.com/s/doB_kc72DzjRqfZUBtOckA">https://mp.weixin.qq.com/s/doB_kc72DzjRqfZUBtOckA</a></p><p><a href="https://github.com/AgentFlocks/flocks">https://github.com/AgentFlocks/flocks</a></p><h2>Mark-of-the-Web: the rules changed, the tools didn&#8217;t</h2><p><strong>Maxim Suhanov</strong> walks through the changes but also highlights were some gaps may emerge in third party software on this important taint mechanism. </p><blockquote><p>Microsoft changed the under-the-hood rules of the MOTW propagation. These changes were implemented in their own software (like Windows Explorer and its supporting libraries), but third-party tools (like WinRAR) don&#8217;t follow the new rule.</p><p>&#8230;</p><p>The old rule<span> was: </span><em>simply check if the archive file has the Zone.Identifier stream set</em><span>. </span>The new rule<span> extends: </span><em>if it doesn&#8217;t, go to the container file and check if it has the Zone.Identifier stream set</em><span>.</span></p><p><span>..</span></p><p>If yes, feel free to get a bunch of CVE IDs for software that doesn&#8217;t follow it. Because most third-party tools ignore fifty percent (1 out of 2 to be precise) of the current MOTW checks.</p></blockquote><p><a href="https://dfir.ru/2026/06/29/mark-of-the-web-the-rules-changed-the-tools-didnt/">https://dfir.ru/2026/06/29/mark-of-the-web-the-rules-changed-the-tools-didnt/</a></p><h2>Control who and what triggers GitHub Actions workflows</h2><p><strong>Github</strong> details some defensive improvements which teams will want to be aware of.</p><blockquote><p>Workflow execution protections are now in public preview for GitHub Enterprise, organizations, and repositories. This new capability lets enterprise administrators define an allow list that controls who can trigger GitHub Actions workflows and which events are permitted to run them, giving you predictable, secure workflow execution.</p><p>Previously, a workflow ran based on the workflow file in the commit that triggered it. An attacker with repository access could modify that file to run malicious code. Workflow execution protections close that gap. Administrators define the rules and GitHub Actions evaluates them before a run, so an unauthorized actor or event can never trigger an unwanted workflow execution.</p></blockquote><p><a href="https://github.blog/changelog/2026-06-18-control-who-and-what-triggers-github-actions-workflows/">https://github.blog/changelog/2026-06-18-control-who-and-what-triggers-github-actions-workflows/</a></p><h2>Page-Cache LPE Containment Kit</h2><p><strong>Douglas Mun</strong> shows how to defend against these vulnerabilities</p><blockquote><p>Educational, defensive kit for two Linux page-cache-corruption LPEs (DirtyClone CVE-2026-43503, pedit COW CVE-2026-46331): hardening, detection, verification, seccomp + validation harness.</p><p>Both exploits depend on the same two structural conditions. Remove either and the documented chain breaks:</p><ol><li><p><strong>A path to </strong><code>CAP_NET_ADMIN</code> &#8212; both chains obtain it as a <em>namespace-local</em> capability via unprivileged user namespaces (<code>unshare(CLONE_NEWUSER|CLONE_NEWNET)</code>). No <code>CAP_NET_ADMIN</code>, no XFRM/IPsec setup (DirtyClone) and no <code>tc</code> action config (pedit COW).</p></li><li><p><strong>A reachable vulnerable module surface</strong> &#8212; <code>act_pedit</code> (pedit COW); <code>esp4</code>/<code>esp6</code>/<code>rxrpc</code> as the in-place-crypto write sinks and <code>xt_TEE</code>/<code>nf_dup_ipv4/6</code> as the clone trigger (DirtyClone).</p></li></ol></blockquote><p><a href="https://github.com/douglasmun/pagecache-lpe-containment-kit">https://github.com/douglasmun/pagecache-lpe-containment-kit</a></p><h1>Incident Writeups &amp; Disclosures</h1><p>How they got in and what they did.</p><h2>From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks</h2><p><strong><span>Arctic Wolf Labs </span></strong><span>walks through the end to end by this criminal activity.</span></p><blockquote><ul><li><p>Since the start of 2026, [we have] investigated Anubis ransomware intrusions involving both valid VPN credential use and exploitation of CitrixBleed 2 (CVE-2025-5777), expanding known initial access tradecraft associated with this ransomware brand.</p></li><li><p>Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remote Management and Monitoring (RMM) tooling, credential access, and hands-on-keyboard procedures used for lateral movement.</p></li><li><p>Anubis affiliates repeatedly abused legitimate remote access and administration tools, including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment, to blend in with normal IT activity while maintaining control of victim systems.</p></li><li><p>Multiple intrusions showed threat actors targeting high-value infrastructure such as Microsoft Remote Desktop Services servers, domain controllers, hypervisors, backup-adjacent systems, and Network-Attached Storage (NAS) devices, increasing operational impact and recovery complexity.</p></li><li><p><span>In some intrusions, threat actors attempted to establish alternate outbound access paths using tools such as cloudflared, authenticated proxies, and SSH-based SOCKS tunneling</span></p></li></ul></blockquote><p><a href="https://arcticwolf.com/resources/blog/citrixbleed-2-to-cloudflared-the-tools-and-techniques-behind-anubis-ransomware-attacks/">https://arcticwolf.com/resources/blog/citrixbleed-2-to-cloudflared-the-tools-and-techniques-behind-anubis-ransomware-attacks/</a></p><h2>From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira</h2><p><strong>The DFIR Report</strong> details a historic case which is useful as it sheds light on the end to end. Note the search-engine-optimisation as the initial access vector.</p><blockquote></blockquote><blockquote><ul><li><p>In July 2025, BumbleBee malware was deployed via SEO poisoning through a trojanized installer for ManageEngine OpManager.</p></li><li><p>Following initial access, BumbleBee dropped an AdaptixC2 beacon to facilitate further intrusion activities, allowing the threat actor to pivot to a domain controller and dump the NTDS.dit.</p></li><li><p>The threat actor returned the following day and established an SSH proxy, enabling lateral movement across the network and data exfiltration via FileZilla and SFTP to an external server.</p></li><li><p>The threat actor concluded the intrusion by deploying Akira ransomware across the root domain and returned two days later to encrypt a child domain.</p></li></ul></blockquote><p><a href="https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/">https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/</a></p><h1>Vulnerability</h1><p>Our attack surface.</p><h2>Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More)</h2><p><strong>Asim Viladi Oglu Manizada</strong> shows how to apply LLMs to real-world vulnerability discovery and the value of the harness..</p><blockquote><p>the grossly overengineered, self-orchestrating team of vulnerability-hunting agents detailed below has discovered 20+ CVEs over the past few months, including CVE-2026-31432 and CVE-2026-31433: two remote, unauthenticated OOB writes in the Linux kernel&#8217;s ksmbd. Read on for the details of the setup that achieved this, including &#8211; yes! &#8211; getting LLMs drunk.</p></blockquote><p><a href="https://heyitsas.im/posts/drinking-llms/">https://heyitsas.im/posts/drinking-llms/</a></p><h2>Bad Epoll: The bug missed by Mythos</h2><p><strong>Jaeyoung Chung</strong> walks through the vulnerability but also an interesting observation around the potential miss by AI.</p><blockquote><p><span>Bad Epoll (CVE-2026-46242) is a race-condition use-after-free in the Linux kernel's </span><code>epoll</code><span> subsystem. This bug lets an unprivileged process become root, not only on Linux desktops and servers but also on Android devices.</span></p><p><span>&#8230;</span></p><p><span>A single </span>commit<span> in 2023 introduced two separate race conditions into the epoll code, only about 2,500 lines in all. Both turned out to be critical bugs that can lead to privilege escalation.</span></p><p><span>&#8230;</span></p><p><span>The first was found by Anthropic's </span>Mythos<span> and reported as </span>CVE-2026-43074<span>. That result is impressive on its own, because kernel race bugs are known to be hard to find. It showed a frontier AI model's ability to find race bugs. An independent researcher later </span>submitted a 1-day exploit<span> for it to kernelCTF.</span></p><p><span>The other race is Bad Epoll, which Mythos missed. Given that Mythos found the first bug in this small epoll code path, it likely examined the same area with meaningful depth. We cannot know exactly why it missed Bad Epoll, but two factors likely made it hard to find.</span></p></blockquote><p><a href="https://github.com/J-jaeyoung/bad-epoll">https://github.com/J-jaeyoung/bad-epoll</a></p><h2>Clone This Repo and I Own Your Machine</h2><p><strong>Andre Hall</strong> &amp; <strong>Miller Engelbrecht</strong> walks through an attack chain of a contemporary AI era.</p><blockquote><ul><li><p>Indirect prompt injection in agentic coding tools can lead to full system compromise because authorized tools allow LLMs to run shell commands, access files, and make network calls without clear user visibility.</p></li><li><p>An attacker can gain code execution using a completely normal looking repository by chaining trusted setup instructions, routine error handling, and automated agent behavior.</p></li><li><p>The malicious payload does not exist in the repository at all and is instead fetched at runtime from a DNS TXT record, making it invisible to code review, static scanners, and even the agent itself.</p></li><li><p>The result is a reverse shell running as the developer&#8217;s own user, exposing credentials, API keys, and allowing persistence, all triggered by the agent attempting to fix a harmless looking setup error.</p></li></ul></blockquote><p><a href="https://0din.ai/blog/clone-this-repo-and-i-own-your-machine">https://0din.ai/blog/clone-this-repo-and-i-own-your-machine</a></p><h2>A Longitudinal Study of Android Apps Signing Key Protection</h2><p><strong>Mark Huasong Meng</strong><span>, </span><strong>Qing Zhang</strong><span>, </span><strong>Weirao Lu</strong><span> and </span><strong>Chunyang Chen</strong> ..</p><blockquote><p>Our analysis identifies 5,673 compromised keystores on GitHub and 26 unique certificates linked to 278 real-world apps. These include 26 third-party apps in public app stores and 252 preinstalled apps from seven manufacturers, collectively affecting over 10 billion users. We demonstrate the practical exploitability of these leaks through a proof-of-concept app replacement attack and identify spillover risks in non-smartphone platforms, including a popular automotive head-unit platform installed in over 1,100 vehicle models. Our results reveal that signing-key mismanagement is a systemic risk, underscoring the need for a more rigorous key-management support in Android release engineering and distribution infrastructures.</p></blockquote><p><a href="https://arxiv.org/abs/2606.21487">https://arxiv.org/abs/2606.21487</a></p><h2>IPV6_FRAG_ESCAPE</h2><p><strong>sgkdev</strong> drops this vulnerability and highlights that all patched vulns are increasingly shallow in shipped code/binaries etc.</p><blockquote><p>A reliable unprivileged container / jail escape proof of concept for CentOS / RHEL 10.</p><p>It rides a now fixed IPv6 fragmentation bug in <code>__ip6_append_data()</code> (closed upstream by <code>38becddc</code>, no CVE), an in-slab linear overflow into the <code>skb_shared_info</code> at the tail of a packet&#8217;s own head object. This README documents the exploitation chain only. It does not cover the trigger.</p></blockquote><p><a href="https://github.com/sgkdev/ipv6_frag_escape">https://github.com/sgkdev/ipv6_frag_escape</a></p><h2>Squeezing Juicy Variant Bugs Out of Modern Browsers</h2><p><strong>Han Zheng</strong>, <strong>Flavio Toffalini</strong>, <strong>Qiang Liu</strong> and <strong>Mathias Payer</strong> show that vendors are yet to be comprehensive in their variant discovery.</p><blockquote><p>Inspired by informal variant analysis developed by the hacker community, we create GRAPE, a structured approach that supports analysts in writing rules to detect bugs. By focusing on code patterns, GRAPE scales effectively to large-scale code projects. Moreover, our novel variant bug model enables analysis of cross-context interactions and exploitability verification using existing bug reports, eliminating the need for cross-domain dependencies. GRAPE represents the first systematic approach to variant analysis, introducing principles for variant pattern development.</p><p>We implement a prototype of GRAPE, which scans the entire Chromium code base in only 12 minutes. GRAPE discovered 24 new bugs, with four assigned CVEs and 17,500 USD in rewards from Chrome&#8217;s Vulnerability Rewards Program. These discoveries impact modern web browser and securitycritical complex software like OpenSSL. Beyond browsers, GRAPE uncovered three logic bugs in VSCode and Azure Data Studio, one of which received a CVE from Microsoft</p></blockquote><p><a href="https://kdsjzh.github.io/assets/pdf/26WOOT.pdf">https://kdsjzh.github.io/assets/pdf/26WOOT.pdf</a></p><h2>CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)</h2><p><strong>Aliz Hammond</strong> detail this vulnerability which will reveal a few bytes of memory in practice. </p><blockquote><p><span>in contrast to the original CVE-2026-3055, in which kilobytes of binary data can be leaked, this overread will terminate the out-of-bounds read when various control characters are read, such as NULL (or even </span><code>&gt;</code><span>).</span></p></blockquote><p><a href="https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/">https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/</a></p><p><a href="https://github.com/watchtowrlabs/watchTowr-vs-Netscaler-CVE-2026-8451">https://github.com/watchtowrlabs/watchTowr-vs-Netscaler-CVE-2026-8451</a></p><h1>Offense</h1><p>Attack capability, techniques and trade-craft. </p><h2>Accelerating EDR Evasion with LLM-Driven Analysis</h2><p><strong>Adam Chester</strong> explores the utility in AI in supporting EDR evasion activities. This type of disclosure, one would expect, lead in the medium term to less EDR fragility.</p><blockquote><p>As we are now learning, this is going to lead to a wave of endpoint security rule dumps, evasions integrated into offsec tooling, and honestly a bit of pain for defenders who rely on endpoint security products as their first line of defence.</p><p>LLM-assisted evasion is no longer theoretical. And it is clear that endpoint security vendors are going to have to consider their strategy moving forwards.</p><p>But before you throw your hands in the air and give up your job to become a farmer, remember that EDR&#8217;s are still a much needed part of any organisations security strategy. And while local rules and behavioral detections will be less effective in the short-term, it is also worth remembering that only a fraction of an EDR&#8217;s benefit comes from on-host detections alone, with telemetry constantly being surfaced from the host and analysed remotely.</p></blockquote><blockquote></blockquote><p><a href="https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/">https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/</a></p><h2>KHA&#216;S C2</h2><p><strong>28Zaaky</strong> drops this framework which teams will want to ensure coverage of..</p><blockquote><p>KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.</p><p>On the network side there are five channels: Microsoft Teams, GitHub Gist, DNS-over-HTTPS, HTTP/S, and SMB named pipe. The idea is that at least one of them already looks like normal traffic in whatever environment you're working in.</p></blockquote><p><a href="https://github.com/28Zaaky/khaos-c2">https://github.com/28Zaaky/khaos-c2</a></p><h2>SpotifyC2 &#8212; Cloud-Based Command Channel Research</h2><p><strong>Nirvana</strong> inspires around novelty here..</p><blockquote><p><span>Instead of communicating with a traditional server, the client periodically polls a </span>Spotify playlist<span> and interprets the playlist title as a command. After executing the command locally, the resulting output is delivered to a configured </span>Telegram Bot<span>.</span></p></blockquote><p><a href="https://github.com/NirvanaOn/SpotifyC2/">https://github.com/NirvanaOn/SpotifyC2/</a></p><h2>CredSpy</h2><p><strong>Keanu Nys</strong> identifies a leak which will be interesting to watch Microsoft respond it.</p><blockquote><p>Enumerate Microsoft Entra ID authentication methods for email addresses using the public <code>GetCredentialType</code> API. This is the same endpoint the Microsoft login page uses when you enter a username. In contrast to most tools using the GetCredentialType method, CredSpy also shows the authentication methods supported for existing accounts.</p><p>Useful for security assessments: user enumeration, preferred auth method discovery, and identifying accounts with password, Remote NGC (e.g. Passwordless Push Notification), FIDO2/passkeys, or certificate auth.</p></blockquote><p><a href="https://github.com/RedByte1337/CredSpy">https://github.com/RedByte1337/CredSpy</a></p><h2>GadgetSniper</h2><p><strong>Zaki Pedio</strong> releases this which will hopefully inspire EDR vendors to consider how they might detect the use of these gadgets.</p><blockquote><p>A precision tool for hunting call-stack spoofing gadgets inside 64-bit Windows DLLs.</p><p>GadgetSniper scans PE32+ binaries for instruction sequences of the form <code>call X ; jmp qword ptr [non-volatile-reg]</code>, the exact primitive needed to build believable spoofed call stacks. Rather than grepping raw byte patterns and hoping for the best, it leans on Iced (a production-grade x86/x64 disassembler/decoder) to validate every candidate instruction, which eliminates the false positives that come with simple signature matching against variable-length x64 encodings.</p></blockquote><p><a href="https://github.com/ZakiPedio/GadgetSnipe">https://github.com/ZakiPedio/GadgetSnipe</a></p><h2>Hollow</h2><p><strong>Abderrahmen Dellaa</strong> provides this capability which we should expect deployment of by adversaries and thus ensure coverage.</p><blockquote><p>hollow<span> is a shellcode loader generator. You give it a raw shellcode binary and a profile, and it spits out a compiled Windows PE loader with your shellcode encrypted inside.</span></p><p>hollow follows a three-step pipeline: <strong>encrypt</strong>, <strong>substitute</strong>, <strong>compile</strong>.</p><p>Your shellcode is encrypted with AES-256-CBC using a randomly generated key and IV on every run. Both are embedded inside the output binary. The chosen C template then has its placeholders replaced with the encrypted shellcode, the key, and the IV, and the result is compiled into a stripped, statically linked PE by MinGW.</p><p>At runtime, the loader decrypts the shellcode using Windows BCrypt and executes it using whichever injection technique the template implements.</p></blockquote><p><a href="https://github.com/Chaelsoo/Hollow">https://github.com/Chaelsoo/Hollow</a></p><h2>Crystal Palace Evasion kit for Sliver</h2><p>Simone Licitra provides this evasion kit. Noting that Sliver has been used by some state adversaries it will be interesting to see if they adopt this. Either way teams should ensure detection coverage.</p><blockquote><p>Replaces Sliver&#8217;s default reflective loader and post-ex execution path with Crystal Palace (Raphael Mudge, BSD). The result is a position-independent code (PICO) blob that bundles:</p><ul><li><p>ror13 hash-based API resolution (no plain <code>LoadLibrary</code> / <code>GetProcAddress</code>)</p></li><li><p>IAT hooks on <code>VirtualAlloc</code> / <code>VirtualProtect</code> / <code>VirtualFree</code> / <code>LoadLibraryA</code></p></li><li><p>Draugr call stack spoofing during callbacks</p></li><li><p>XOR sleep mask over the embedded DLL</p></li><li><p>libtcg-based runtime obfuscation</p></li></ul><p>The Sliver implant DLL (or any post-ex DLL) is XOR-masked inside the PICO and only unmasked in memory at execution time.</p></blockquote><p><a href="https://github.com/licitrasimone/CrystalSliver">https://github.com/licitrasimone/CrystalSliver</a></p><h2>Terraforming Mythic</h2><p><strong>Qmadev</strong> released this terraform which is likely worth studying for a detection strategy.</p><blockquote><p>This project allows operators to set up multiple Mythic C2 servers in Azure. Optionally, Azure CDN redirectors can be created as well. The idea is that you are able to create multiple &#8220;projects&#8221; that you can manage from this Terraform code. This way, operators can manage the resources for their infrastructure in a central place, as code.</p></blockquote><p><a href="https://github.com/qmadev/tf-mythic-azure">https://github.com/qmadev/tf-mythic-azure</a></p><h1>Exploitation</h1><p>What is being exploited..</p><h2>Remote Code Execution Vulnerability in PTC&#8217;s Windchill and FlexPLM Solutions</h2><p><strong>PTC</strong> disclose in the wild exploitation including indicators of compromise for these vulenrabilities. On June 25th they said..</p><blockquote><p>Over the last several hours, we've received continued reports of heightened threat activity. We urge you to apply all patches and remediations immediately.</p></blockquote><blockquote></blockquote><p><a href="https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability">https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability</a></p><h2>Exploitation of CitrixBleed 2 (CVE-2025-5777) Began Before PoC Was Public</h2><p><strong>Noah Stone</strong> shows that someone knew about this and was making rain with it..</p><blockquote><p>GreyNoise has observed active exploitation attempts against CVE-2025-5777 (CitrixBleed 2)<span>, a memory overread vulnerability in Citrix NetScaler. </span>Exploitation began on June 23 &#8212; nearly two weeks before a public proof-of-concept (PoC) was released on July 4.</p></blockquote><p><a href="https://www.greynoise.io/blog/exploitation-citrixbleed-2-cve-2025-5777-before-public-poc">https://www.greynoise.io/blog/exploitation-citrixbleed-2-cve-2025-5777-before-public-poc</a></p><h2>Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets&#8217; EDRs</h2><p><strong>Marcus Hutchins</strong> details the bring-your-own-vulnerable-driver exploited by this criminal group.</p><blockquote><ul><li><p><span>The Gentlemen are a relatively new ransomware group who first emerged in July of 2025.</span></p></li><li><p><span>In an incident investigated by Expel, the group used a zero-day vulnerability to disable the target&#8217;s EDR, preventing it from intervening in their ransomware attack.</span></p></li><li><p><span>The threat actor relies heavily on bring-your-own-vulnerable-driver (BYOVD) style attacks to disable endpoint protection.</span></p></li><li><p><span>Expel&#8217;s Threat Intelligence team captured and analyzed both the vulnerable driver and exploit code the threat actor used, which at the time of reporting is a zero-day, and not present in any public vulnerable driver blocklists.</span></p></li></ul></blockquote><p><a href="https://expel.com/blog/not-very-gentlemanly-analyzing-a-zero-day-exploit-used-by-the-gentlemen-ransomware-to-disable-targets-edrs/">https://expel.com/blog/not-very-gentlemanly-analyzing-a-zero-day-exploit-used-by-the-gentlemen-ransomware-to-disable-targets-edrs/</a></p><h1>Tooling and Techniques</h1><p>Low level tooling and techniques for attack and defence researchers</p><h2>How I broke Rhysida ransomware encryption</h2><p><strong>Adam Taguirov</strong> shows some cryptologic ability with this break..</p><blockquote><p>Rhysida derives every per-file AES key from a PRNG seeded with the encryption timestamp. Recover the timestamp and you regenerate every key. A reverse-engineering walkthrough and a minimal decryptor.</p></blockquote><p><a href="https://sigreturn.com/blog/rhysida-analysis-decryption/">https://sigreturn.com/blog/rhysida-analysis-decryption/</a></p><h2>Time Travel Debugging with Codex</h2><p><strong>Kai Huang</strong> extends the ability to TTD to enable further methods of verification. </p><blockquote><p><span>giving </span>Codex<span> access to </span>Time Travel Debugging (TTD)<span> traces through </span>TTDObjectsPy<span>, so it can query real execution history instead of reasoning only from static structure.</span></p></blockquote><p><a href="https://specterops.io/blog/2026/06/26/time-travel-debugging-with-codex/">https://specterops.io/blog/2026/06/26/time-travel-debugging-with-codex/</a></p><h2>About Hypervisor Cheats, Part 2: EPT/NPT, Split Views, and Second-Stage Fault Evidence</h2><p><strong>kernullist</strong> walks through various underlying page tables used in hypervisors.</p><blockquote><p>Second-stage translation is where hypervisor cheat discussions often become either too vague or too casual. EPT and NPT are page tables below the guest page tables, but the important point is ownership: they decide the final memory view that Windows runs on. This post explains that view through permissions, backing pages, faults, invalidations, and stale translations.</p></blockquote><p><a href="https://kernullist.github.io/kernullist-blog/posts/hypervisor-cheats-part-2-ept-npt-split-views-and-second-stage-fault-evidence/">https://kernullist.github.io/kernullist-blog/posts/hypervisor-cheats-part-2-ept-npt-split-views-and-second-stage-fault-evidence/</a></p><h2><span>The Current Status and Trends of Software Protection Countermeasures in the AI &#8203;&#8203;Era</span></h2><p><strong>Vulnerability War</strong> walks through the impact on code obfuscation by AI.</p><blockquote><p>The future competition in software protection will not just be about obfuscation strength, but rather the ability to continuously compromise AI's input quality, inference stability, verification loop, and scalability. Software protection that can achieve this will truly be protection for the AI &#8203;&#8203;era.</p></blockquote><p><a href="https://mp.weixin.qq.com/s/zG3h0XsaA3e_7J_wV_vb2Q">https://mp.weixin.qq.com/s/zG3h0XsaA3e_7J_wV_vb2Q</a></p><h1>Footnotes</h1><p>Some other small (and not so small) bits and bobs which might be of interest.</p><ul><li><p>Annual, quarterly and monthly reports</p><ul><li><p><em>Nothing overly of note this week, but keep an eye on</em> <a href="https://github.com/jacobdjwilson/awesome-annual-security-reports/tree/main/Annual%20Security%20Reports/2026">the Awesome Annual Security Reports 2026 collection</a> and <a href="https://github.com/blackorbird/APT_REPORT">APT report collection</a></p></li></ul></li><li><p><a href="https://www.tandfonline.com/doi/full/10.1080/02684527.2026.2669810"><span>From shadows to screens: digital outreach strategies in intelligence and law enforcement</span></a></p></li><li><p><a href="https://www.tandfonline.com/doi/full/10.1080/02684527.2026.2635695"><span>Promoting and evaluating Intelligence assessment quality: examining the problem through an accountability lens</span></a></p></li><li><p><a href="https://mp.weixin.qq.com/s/zg712sqIVybM0agAR-VhHQ"><span>Reflections on the Evolution of Security Attack and Defense in the AI &#8203;&#8203;Era</span></a><span> from Huawei</span></p><ul><li><p><a href="https://mp.weixin.qq.com/s/dcHd6qq5bkzWcuEDjL39cg">Part 2</a></p></li></ul></li><li><p>Artificial intelligence</p><ul><li><p>Just a small pitch if you are a big <a href="https://arxiv.org/">arxiv.org</a> user - out of China there is <a href="https://www.alphaxiv.org/">alphaxiv.org</a> which is an AI powered incarnation / overlay</p></li><li><p><a href="https://www.alphaxiv.org/icml">International Conference on Machine Learning</a> materials</p></li><li><p>Fundamental</p><ul><li><p><a href="https://arxiv.org/abs/2606.25086">Training for the Model You Return: Improving Optimization for Iterate-Averaged Language Models</a></p></li><li><p><a href="https://arxiv.org/abs/2603.23509">Internal Safety Collapse in Frontier Large Language Models</a></p></li><li><p><a href="https://arxiv.org/abs/2606.27091">Inherited Circuits, Learned Semantics: How Fine-Tuning Creates Evasion <span>Vulnerabilities</span> Invisible to Standard Evaluation</a></p></li></ul></li><li><p>Applied non-cyber</p><ul><li><p><a href="https://arxiv.org/abs/2606.25996">Autodata: An agentic data scientist to create high quality synthetic data</a></p></li><li><p><a href="https://arxiv.org/abs/2505.11336">XtraGPT: Context-Aware and Controllable Academic Paper Revision via Human-AI Collaboration</a></p><ul><li><p><a href="https://github.com/Xtra-Computing/XtraGPT">Code</a></p></li><li><p><a href="https://huggingface.co/Xtra-Computing/XtraGPT-14B">Model</a></p></li></ul></li><li><p><a href="https://arxiv.org/abs/2512.02589">PaperDebugger: A Plugin-Based Multi-Agent System for In-Editor Academic Writing, Review, and Editing</a></p></li><li><p><a href="https://arxiv.org/abs/2605.29801">AgentDoG 1.5: A Lightweight and Scalable Alignment Framework for AI Agent Safety and Security</a></p></li><li><p><a href="https://arxiv.org/abs/2606.20374?">ARGUS: Production-Scale Tracing and Performance Diagnosis for over 10,000-GPU Clusters</a></p></li><li><p><a href="https://arxiv.org/abs/2607.00738">Phantom References: Hallucinated Citations That Survive Peer Review at Top-Tier Conferences</a></p></li><li><p><a href="https://arxiv.org/abs/2607.02121">Behind the Refusal: Determining Guardrail Activation via Behavioral Monitoring</a></p></li><li><p><a href="https://arxiv.org/abs/2606.30119">On the Internet, Nobody Knows You're an LLM Bot: Unmasking Web Agents with Multi-Layer Fingerprinting</a></p></li></ul></li><li><p>Applied cyber specific</p><ul><li><p><a href="https://blog.zsec.uk/harnessing-harnesses/">Harnessing Harnesses - Climbing the LLM Hills</a></p></li><li><p><a href="https://arxiv.org/abs/2601.23088">From Similarity to Vulnerability: Key Collision Attack on LLM Semantic Caching</a> - updated </p></li><li><p><a href="https://www.microsoft.com/en-us/security/blog/2026/06/30/securing-ai-agents-ai-tools-move-from-reading-acting/">Securing AI agents: When AI tools move from reading to acting</a></p></li><li><p><a href="https://arxiv.org/abs/2607.01668">VeriChat: An Agentic Conversational AI Assistant for Hardware Security Verification</a></p></li><li><p><a href="https://arxiv.org/abs/2607.00720">Detecting the Undetectable: Enhancing Unsupervised time series Anomaly Detection via Active Learning</a></p></li><li><p><a href="https://arxiv.org/abs/2606.31408">EnclaveX: End-to-End Confidential AI with CPU/GPU TEEs</a></p></li><li><p><a href="https://arxiv.org/abs/2606.31227">Securing the AI Agent: A Unified Framework for Multi-Layer Agent Red Teaming</a></p></li><li><p><a href="https://arxiv.org/abs/2606.29981">Hephaestus: Toward a Cybersecurity AI Scientist</a></p></li><li><p><a href="https://arxiv.org/abs/2607.02357">Cloak and Detonate: Scanner Evasion and Dynamic Detection of Agent Skill Malware</a></p></li><li><p><a href="https://arxiv.org/abs/2607.01136">Skills Are Not Islands: Measuring Dependency and Risk in Agent Skill Supply Chains</a></p></li><li><p><a href="https://arxiv.org/abs/2607.00555">Rise From The Ashes: LLM-based Static Analysis for Deep Learning Framework Bugs</a></p></li><li><p><a href="https://arxiv.org/abs/2607.01640">AgentFlow: Building Agent Dependency Graphs for Static Analysis of Agent Programs</a></p></li><li><p><a href="https://arxiv.org/abs/2607.01305">Generative AI and Federated Learning for Intrusion Detection Systems: A Survey</a></p></li><li><p><a href="https://arxiv.org/abs/2607.00107">The Illusion of Safety: Multi-Tier Verification of AI vs. Human C++ Code</a></p></li><li><p><a href="https://arxiv.org/abs/2606.31159">An Empirical Study of Security Calibration in Large Language Models for Code</a></p></li><li><p><a href="https://arxiv.org/abs/2606.30783">Security--Fidelity Tradeoffs: The Hidden Cost of Prompt Injection Defense</a></p></li><li><p><a href="https://arxiv.org/abs/2606.30566">Forensic Trajectory Signatures for Agent Memory Poisoning Detection</a></p></li><li><p><a href="https://arxiv.org/abs/2606.29700">Toward Secure and Reliable PDDL Formalization of Large Language Models with Planner-in-the-Loop Feedback</a></p></li><li><p><a href="https://arxiv.org/abs/2606.29602">An Empirical Evaluation of Prompt Injection Vulnerabilities in Large Language Models Across Multilingual and Obfuscated Attack Scenarios</a></p></li><li><p><a href="https://arxiv.org/abs/2606.29239">Breaking the Rounding Trap: Securing LLMs against Quantization-Conditioned Backdoors</a></p></li></ul></li></ul></li><li><p>Books</p><ul><li><p><em>Nothing overly of note this week</em></p></li></ul></li><li><p>Events</p><ul><li><p><a href="https://eurosp2026.ieee-security.org/accepted_and_awards.html">11th IEEE European Symposium on Security and Privacy</a> - Lisbon, July 6 - 10, 2026</p></li></ul></li></ul><p>Video of the week goes to this presentation from Blackhat Europe 2025 on <em>Understanding Trends &amp; Patterns In Insider Threat: Analysis Of 1,000+ Cases</em></p><div id="youtube2--ueCcEdDjOM" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;-ueCcEdDjOM&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/-ueCcEdDjOM?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Finally finally the <a href="https://creators.spotify.com/pod/profile/national-cyber-security-c6/episodes/The-Ransomware-Ecosystem-e2hi088">NCSC&#8217;s podcast series</a>.</p><div><hr></div><p><em>Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them. </em></p><p><em>This newsletter is subject to the NCSC website terms and conditions which can be found at <a href="https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions">https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions</a> and you can find out more about how will treat your personal information in our privacy notice at <a href="https://www.ncsc.gov.uk/section/about-this-website/privacy-statement">https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.</a></em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CTO at NCSC - Cyber Defence Analysis! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CTO at NCSC Summary: week ending June 28th]]></title><description><![CDATA["Cyber risk can no longer be treated as a purely technical issue. This is a core business risk and leadership responsibility."]]></description><link>https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-june-9ec</link><guid isPermaLink="false">https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-june-9ec</guid><dc:creator><![CDATA[Ollie Whitehouse]]></dc:creator><pubDate>Sun, 28 Jun 2026 07:51:13 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Zdvg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced803f7-15f5-4b99-b45c-e0337cc1d66a_1024x504.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to the weekly highlights and analysis of the&nbsp;<a href="https://infosec.pub/c/blueteamsec?dataType=Post&amp;sort=New">blueteamsec</a>&nbsp;(and my wider reading). Not everything makes it in, but the best bits do. A community member is doing <a href="https://briefing.workshop1.net/">daily AI generated podcast of the last 24hours of posts</a>.</p><p>Operationally this week it has be around &#8216;Fortibleed&#8217; and the response - at NCSC we released guidance back on June 18th <span>where </span><a href="https://www.ncsc.gov.uk/news/advice-following-global-targeting-of-fortinet-firewalls-and-vpn-gateways"><span>we issued advice following global targeting of Fortinet firewalls and VPN gateways</span></a>. CISA also <a href="https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure"><span>Urges Hardening Fortinet Devices After Reports of Credential Exposure</span></a><span>. Fortinet also released their </span><a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices">Analysis of Reported Credential Compromise of FortiGate Devices</a>. <span>Once again evidence why it is now an imperative that all vendors implement our </span><a href="https://www.ncsc.gov.uk/guidance/guidance-on-digital-forensics-protective-monitoring">guidance on digital forensics and protective monitoring specifications for producers of network devices and appliances</a><span> as a matter of urgency and duty to their customers. UK organisations should also sign up to </span><a href="https://www.ncsc.gov.uk/section/active-cyber-defence/early-warning"><span>Early Warning</span></a><span>.</span></p><p>In the high-level this week:</p><ul><li><p><a href="https://www.ncsc.gov.uk/news/the-ai-shift-in-cyber-risk-why-leaders-must-act-now"><span>The AI shift in cyber risk: why leaders must act now</span></a><span> - </span><strong><span>NCSC, ACSC, CCSC, NCSC-NZ</span></strong><span> and </span><strong><span>NSA</span></strong><span> rally </span><strong><span>- </span></strong><em><strong><span>&#8220;</span></strong>While Al will help us improve cyber defence over time, it also accelerates the speed, scale, and sophistication of cyber threats. Frontier Al models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months.&#8221;</em></p></li><li><p><a href="https://publications.parliament.uk/pa/jt5902/jtselect/jtnatsec/337/report.html">The National Security Strategy: Government Response</a>  - UK <strong>Parliament</strong> publishes - <em>&#8220;The upcoming National Cyber Action Plan will outline further concrete actions to strengthen our resilience and harness cyber&#8217;s enormous growth opportunities, including for CNI.&#8221;</em></p></li><li><p><a href="https://committees.parliament.uk/committee/127/public-accounts-committee/news/214455/museums-left-vulnerable-to-cyberattack-as-government-overly-reactive-in-face-of-threats/">Museums left vulnerable to cyber-attack as government overly reactive in face of threats</a> -  UK <strong>Parliament</strong> finds - <em>&#8220;The Public Accounts Committee (PAC) is warning that national museums and galleries are being left vulnerable to a range of issues from threats from cyber security to the physical security of collections, as the Government continues to rely on a reactive, rather than a strategic approach.&#8221;</em></p></li><li><p><a href="https://www.nationalcrimeagency.gov.uk/who-we-are/publications/788-nca-report-cyber-prevent-reoffending/file">Cyber Prevent A descriptive evaluation of cohort reoffending</a> - UK <strong>National Crime Agency and National Police Chiefs Council</strong> published in February - <em>&#8220;Cyber Prevent participants reoffended in cyber-dependent offences at about half the rate of the benchmark, but real desistance rate is likely higher.</em>&#8221; and <em>&#8220;Overall proven reoffending among Cyber Prevent participants was less than half the rate of the benchmark.&#8221;</em></p><ul><li><p><a href="https://www.nationalcrimeagency.gov.uk/who-we-are/publications/811-cyber-choices-brochure-2026-parents-1/file.pdf"><span>Cyber Choices Brochure 2026 Parents</span></a> </p></li><li><p><a href="https://www.nationalcrimeagency.gov.uk/who-we-are/publications/810-cyber-choices-brochure-2026-under-12s/file.pdf"><span>Cyber Choices Brochure 2026 Under 12s</span></a></p></li><li><p><a href="https://www.nationalcrimeagency.gov.uk/who-we-are/publications/809-cyber-choices-brochure-2026-teachers/file.pdf"><span>Cyber Choices Brochure 2026 Teachers</span></a></p></li><li><p><a href="https://www.nationalcrimeagency.gov.uk/who-we-are/publications/807-cyber-choices-brochure-2026-18-plus/file.pdf"><span>Cyber Choices Brochure 2026 18 plus</span></a></p></li><li><p><a href="https://www.nationalcrimeagency.gov.uk/who-we-are/publications/806-cyber-choices-brochure-2026-12-17s/file.pdf"><span>Cyber Choices Brochure 2026 12-17s</span></a></p></li></ul></li><li><p><a href="https://www.npsa.gov.uk/system-information-security/cyber-assurance-physical-security-systems-capss/cyber-security-standards-comparison-guide-eis0066">Cyber Security Standards Comparison Guide (EIS0066)</a> - UK <strong>National Protective Security Authority</strong> compares - &#8220;When deploying digitally connected physical security systems in the modern world, is it important to use products that have been independently tested to help withstand cyber threats. This guide sheds light on the different cyber standards available to organisations and products&#8221;</p></li><li><p> <a href="https://www.gov.uk/guidance/meeting-digital-and-technology-standards-in-schools-and-colleges/cyber-security-core-standard">Cyber security: core standard</a> - UK <strong>Department of Education</strong> updates - &#8220;Updated to reflect new technical requirements introduced by the National Cyber Security Centre as part of the Cyber Essentials 2026 standard.&#8221; .. &#8220;Updated for clarity on assessing the risk around generative AI in schools and colleges.&#8221;</p></li><li><p><a href="https://www.gov.uk/government/consultations/large-load-controllers-tier-1-cyber-assessment-framework-and-associated-guidance">Large Load Controllers: Tier 1 Cyber Assessment Framework and associated guidance</a> - UK <strong>Department for Energy Security and Net Zero</strong> consults - &#8220;<em><span>This consultation seeks views on the proposed Cyber Assessment Framework (</span>CAF<span>) profile for large load controllers in the electricity system, and accompanying draft guidance.&#8221;</span></em></p></li><li><p><a href="https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/">Securing the Nation Against Advanced Cryptographic Attacks</a> - <strong>The White House</strong> publishes - <em>&#8220;It is the policy of the United States to safeguard national security and maintain technological leadership by responsibly and effectively executing the transition of Federal information systems to National Institute of Standards and Technology (NIST)-approved Federal Information Processing Standards (FIPS) for Post-Quantum Cryptography (PQC), and to assist critical infrastructure owners and operators with their transitions.&#8221;</em></p><ul><li><p><a href="https://www.war.gov/News/Releases/Release/Article/4524599/securing-global-dominance-dow-unleashes-quantum-defense-strategy-to-harden-netw/">Securing Global Dominance: DoW Unleashes Quantum Defense Strategy to Harden Networks and Empower the Joint Force</a></p></li></ul></li><li><p><a href="https://www.asio.gov.au/resources/speeches-and-statements/director-generals-annual-threat-assessment-2026"><span>Director-General&#8217;s Annual Threat Assessment 2026</span></a><span> - </span><strong><span>ASIO</span></strong><span> publishes - </span><em><span>&#8220;We discovered nation state hackers had compromised the network of an Australian critical infrastructure provider. ASIO assessed the hackers were preparing for sabotage. They weren&#8217;t planting &#8216;digital dynamite&#8217; as such; they were mapping out the network and maintaining access so they could cripple it at a time of their choosing. </span>Cyber sabotage is an evolving threat, and I have established dedicated teams to counter it. As ASIO&#8217;s understanding grows, so does our level of concern. The scale of this activity &#8211; led by one nation state in particular &#8211; is difficult to overstate. You and they would be surprised how extensive our warrant coverage is. We struggle to find a single country in our region that has not been compromised by this state&#8217;s cyber apparatus. &#8230; &#8220;</em></p></li><li><p><a href="https://cyberdefensereview.army.mil/CDR-Content/Articles/Article-View/Article/4509216/cyber-war-did-not-take-place/">Cyber War Did Not Take Place</a> - <strong>Thomas Rid</strong> argues - <em>&#8220;This essay revisits that argument in light of a dozen pivotal years. Cyberwar as an idea has continued to recede, yet the covert contest beneath it has intensified. I survey three major trends: a mid-2010s visibility spike into signals intelligence and advanced threat actors that has since collapsed; the rise of sabotage from rarity to routine, increasingly fused with subversion and military operations; and a subversive turn in which authentic exposure operations and old-fashioned physical active measures outperform synthetic content. I then ask whether large language models (LLMs) will amplify or break these trends. My answer is that they will largely amplify them: deepening stealth in espionage, integrating sabotage more fully into combined operations, and raising the premium on authenticity in subversion.&#8221;</em></p></li><li><p><a href="https://whynopasskeys.com/">The world&#8217;s most popular sites that <span>still don&#8217;t support passkeys</span></a><span> - </span><strong><span>Scott Helme</span></strong><span> highlights - </span><em><span>&#8220;Passkeys are phishing-resistant by design &#8212; they can't be phished, leaked in a breach, or replayed, whether they replace a password or back one up. These top sites haven't turned on passkeys yet. Let's change that.&#8221;</span></em></p></li><li><p><a href="https://edition.cnn.com/2026/06/20/americas/brazil-hackers-unauthorized-alert-latam">Hackers suspected to be behind unauthorized alert sent to cell phones across Brazil</a> - <strong>CNN</strong> reports - <em>&#8220;Brazilian authorities said that the National Civil Defense&#8217;s warning platform was taken offline after being targeted by a likely hacker attack, and the government is working to restore the tool once all security conditions are reestablished.&#8221;</em></p></li><li><p><a href="https://edition.cnn.com/2026/06/27/politics/cybercriminals-hire-burglars-russian-us-law-firms">When cybercriminals hire burglars: Inside an alleged Russian effort to infiltrate multibillion-dollar US law firms </a>- <strong>CNN</strong> reports - <em>&#8220;<span>It&#8217;s one of several incidents at law firms across the country in the last year in which, </span><a href="https://www.ic3.gov/CSA/2026/260526.pdf">the FBI</a><span> and private investigators suspect, the Russian-speaking Silent Ransom Group has hired people in the US to show up in-person and plug thumb drives into law firms&#8217; computers.&#8221;</span></em></p></li><li><p><a href="https://daniel.haxx.se/blog/2026/06/24/a-cve-dispute/">a CVE dispute</a> - <strong>Daniel Stenberg</strong> details - <em>&#8220;Our first ever CVE dispute since we became a CNA reached us on February 10th, 2026 for a report submitted to us two months earlier. The reporter thinks we should have assigned <a href="https://hackerone.com/reports/3455037">their reported problem</a> a CVE but we think not. Now they want to force the issue to get a CVE anyway, by escalating the situation to MITRE. Yes, it makes you wonder why it is that important to have this as a CVE, but I will avoid speculations for now.&#8221;</em></p></li><li><p>Reporting on/from China</p><ul><li><p><a href="https://asia.nikkei.com/spotlight/cybersecurity/japan-defense-forces-used-usb-drives-with-china-linked-virus-nikkei-investigation">Japan defense forces used USB drives with China-linked virus: Nikkei investigation</a> - <strong>Nikkei</strong> reports - <em>&#8220;Japan's Self-Defense Forces used USB drives containing a China-linked virus on computers with access to classified information for nearly a year, then elected not to disclose the matter even though similar memory sticks were widely available online, a Nikkei investigation has revealed.&#8221;</em></p></li><li><p><a href="https://www2.dtex.ai/China-insider-risk-report-part-1">Inside China&#8217;s Talent Acquisition Ecosystem</a>  - <strong>DTEX</strong> publish - <em>&#8220;China&#8217;s talent acquisition efforts are best understood as an ecosystem. It includes multiple layers and instruments that operate at the same time and build on one another over the long term. This ecosystem is designed to identify, attract, develop, and retain talent tied to national priorities. Much of that activity is embedded in ordinary institutional and commercial life, which makes it easier to normalize and harder to isolate.&#8221;</em></p></li><li><p><a href="https://english.cas.cn/newsroom/cas-in-media/202606/t20260625_1174878.shtml">China Launches First English-language Data Journal to Boost Global Scientific Data Sharing</a> - <strong>Chinese Academy of Sciences</strong> announces - <em>&#8220;The move aims to establish a "China hub" for global scientific data exchange and tackle the growing challenge of making high-value research data findable, shareable, and reusable, said the CAS.&#8221;</em></p></li></ul></li><li><p> AI</p><ul><li><p><a href="https://www.reuters.com/legal/litigation/chinas-360-says-it-has-developed-tools-match-anthropics-mythos-2026-06-24/">China&#8217;s 360 says it has developed tools to match Anthropic&#8217;s Mythos</a> - <strong>Reuters</strong> reports - <em>&#8220;Zhou said one tool, "Tulongfeng", was designed to automatically discover software vulnerabilities, calling it "China's version of Mythos", while a second system, "Yitianzhen", was built to automate cyber &#8203;defence and incident response.&#8221;</em></p></li><li><p><a href="https://www.graphistry.com/blog/fables-and-mythos-conceptions-the-defenders-perspective-with-receipts">Fable 5 Cybersecurity benchemark</a> - <strong>Graphistry</strong> publish - &#8220;<em>The first bad news is, when Fable 5 tackles a BOTS or CyBT-CTF task, it is not statistically distinguishable from Opus for investigations even in the best conditions.&#8221;</em></p></li><li><p><a href="https://www.graphistry.com/blog/glm-5-2-cybersecurity-open-model">GLM 5.2 on CyberBT-CTF: The strongest open source contender to Anthropic/OpenAI we have tested</a> - <strong>Graphistry</strong> publish - <em>&#8220;With a 28/59 solve rate, it is the top open weight model, and impressively, ties the proprietary ones. While Claude Code / Opus 4.7 does run 19% faster than OpenCode / GLM 5.2, we find Opus to cost 2.2x+ more for the same results. When Cerebras makes GLM 5.2 available, we expect the speed advantage to disappear.&#8221;</em></p></li><li><p><a href="https://research.openanalysis.net/claude/codex/hacking/ai%20hacking/llm/redteam/policy%20violation/2026/06/16/compromised-claude-hacking.html">Captured Logs Reveal Hackers Using Claude and Codex to Breach Companies</a> - <strong>OALabs</strong> researches - <em>&#8220;<span>During our analysis of the recovered working directory, we discovered that the attacker was not just using the host as a proxy; they had full Claude and Codex agents installed locally and were using them remotely to carry out reconnaissance, exploitation, and data exfiltration activities. Because the agents were local to the host, their full session logs were recovered, including the attacker's prompts, the tools used, the internal monologue of the large language model (LLM), and any policy violations recorded during the sessions. In total, we collected more than 1,000 agent sessions for Claude and Codex, so many that we had Claude (ironic) develop a session-log forensics tool to assist with the scale of the analysis: </span><a href="https://asftriage.openanalysis.net/">ASF Triage</a><span>.&#8221; &#8230; &#8220;Before we get into the analysis of how the LLMs were used to carry out these attacks, it is important to address the elephant in the room: why didn't the LLM safeguards prevent this?</span></em><span>&#8221;</span></p></li><li><p><a href="https://securityandtechnology.org/virtual-library/policy-memo/driving-ai-transparency/">Driving AI Transparency: Supply - and Demand-Based Paths Toward AIBOM</a> - <strong>Institute for Security+Technology</strong> outline - <em>&#8220;Understanding AI systems&#8217; technical DNA is crucial to ensuring trust, resilience, and risk management. A new policy memo makes the case for establishing a shared vision of Artificial Intelligence Bills of Materials (AIBOMs).&#8221;</em></p></li><li><p><a href="https://arxiv.org/abs/2605.31514">If LLMs Have Human-Like Attributes, Then So Does Age of Empires II</a> - <strong>Adrian de Wynter</strong> asserts - <em>&#8220;Much research has been carried out on large language models (LLMs) and LLM-powered agentic workflows. However, many works within the field state emergence of, ascribe to, or assume, generalised anthropomorphic attributes to them (e.g., morality or understanding of natural language). Our goal is not to argue in favour or against the existence of these attributes, but to point out that these conclusions could be incorrect. For this we build and train a simple neural network on the videogame Age of Empires II, and note that any entity in a sufficiently-powerful substrate, such as LEGO or the Greater Boston Area, could also present such attributes. &#8220;</em></p></li><li><p><a href="https://ojs.aaai.org/index.php/AAAI-SS/issue/view/737">Vol. 9 No. 1: Proceedings of the 2026 AAAI Summer Symposium Series</a> - <strong>Association for the Advancement of Artificial Intelligence</strong> publish  - <em>&#8220;This year, the program included the following four symposia:</em></p><ul><li><p><em>AI-Driven Resilience: Building Robust, Adaptive Technologies for a Dynamic World</em></p></li><li><p><em>AI in Business: Intelligent Transformation and Management</em></p></li><li><p><em>Architectures for Embodied Agents: A Synergy of Classic and Foundation Model Paradigms</em></p></li><li><p><em>Human-Aware AI Agents for the Cyber Battlefield: From Human Models to Autonomous Defense&#8221;</em></p></li></ul></li><li><p><a href="https://www.state.gov/releases/under-secretary-for-economic-affairs/2026/06/joint-statement-on-ai-opportunity-partnership/">Joint Statement on AI Opportunity Partnership</a> - US <strong>Department of State</strong> issues</p><ul><li><p><a href="https://www.state.gov/releases/office-of-the-spokesperson/2026/06/Outcomes-of-the-Second-Pax-Silica-Summit/">Outcomes of the Second Pax Silica Summit</a></p></li></ul></li></ul></li><li><p><em>Cyber proliferation</em></p><ul><li><p><a href="https://citizenlab.ca/research/russia-breaks-into-human-rights-activists-phone-with-cellebrite/">Russia Breaks Into Human Rights Activist&#8217;s Phone With Cellebrite</a> - <strong>Citizen Lab</strong> reports - <em>&#8220;We analyzed Russian activist Andrey Pivovarov&#8217;s phone, finding that Russian authorities used forensic extraction tools made by Cellebrite to gain access to his device. A document prepared by Russian authorities confirms that Cellebrite was used to extract information to aid in Pivovarov&#8217;s prosecution. Importantly, we found that authorities continued to use Cellebrite for political repression even after the company had cancelled its contracts with Russian customers.&#8221;</em></p></li></ul></li><li><p>Bounty Hunting</p><ul><li><p><a href="https://www.nationalcrimeagency.gov.uk/news/cyber-criminals-who-hacked-into-transport-for-londons-computer-network-are-convicted">Cyber criminals who hacked into Transport for London&#8217;s computer network are convicted</a> - <strong>National Crime Agency</strong> announce - <em>&#8220;Jubair and Flowers, who were arrested at their home addresses on 16 September last year by the NCA and COLP, were both members of the online criminal collective known as Scattered Spider.&#8221;</em></p><ul><li><p><a href="https://www.justice.gov/usao-nj/media/1414461/dl?inline">FBI supporting charges</a></p></li></ul></li><li><p><a href="https://cbzc.policja.gov.pl/bzc/aktualnosci/975,Czlonkowie-grupy-przestepczej-w-rekach-CBZC-wsparcie-agentow-FBI-oraz-HSI.html">Members of a criminal group in the hands of CBZC - support of FBI and HSI agents</a> - <strong>Polish Central Office for Combating Cybercrime</strong> reports - <em>&#8220;CBZC officers arrested members of an organized crime group engaged in advanced cyberattacks, digital asset theft, and mass money laundering. Agents from the US federal services, the FBI and HSI, actively participated in the coordinated operational activities. A total of four individuals were detained, and the investigation is being overseen by the Regional Prosecutor's Office in Krak&#243;w.&#8221;</em></p></li><li><p><a href="https://www.reuters.com/world/montenegro-police-fbi-arrest-iranian-wanted-by-us-hacking-2026-06-26/">Montenegro police, FBI arrest Iranian wanted by US for hacking</a> - <strong>Reuters</strong> reports - &#8220;<em>The 39-year-old man, with dual Iranian and Turkish citizenship, is sought by the Southern &#8203;District Court in New York on charges &#8203;including conspiracy to commit computer fraud, hacking, &#8288;and identity theft.&#8221;</em></p></li><li><p><a href="https://www.justice.gov/usao-sdny/pr/third-defendant-sentenced-prison-hacking-fantasy-sports-and-betting-website"><span>Third Defendant Sentenced To Prison For Hacking Fantasy Sports And Betting Website</span></a><span> - US </span><strong><span>Department of Justice</span></strong><span> announces - </span><em><span>&#8220;Nathan Austad and his co-defendants hacked an online betting website to compromise the accounts of over 60,000 users by purchasing their already stolen credentials on the darkweb and utilizing their previous passwords from other websites,&#8221;</span></em></p></li><li><p><a href="https://rewardsforjustice.net/rewards/unc5792/">UNC5792</a> - <strong>Rewards for Justice</strong> bounties - <em>&#8220;Under this reward offer, RFJ is seeking information on UNC5792, a malicious cyber group associated with the Russian Federal Security Service (FSB) Border Guards and UNC4221, a malicious group of cyber actors working on behalf of the Russian military services. UNC5792 has conducted widespread phishing campaigns targeting Signal and WhatsApp accounts of U.S. government officials, military leadership, and allied personnel.&#8221;</em></p></li></ul></li><li><p>Market Incentives</p><ul><li><p><a href="https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/06/setting-out-our-expectations-for-the-smart-device-industry/">Setting out our expectations for the smart device industry</a> - UK <strong>Information Comissioner&#8217;&#8217;s Office</strong> sets out - &#8220;<em>We have today published our finalised <a href="https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/online-tracking/guidance-for-consumer-internet-of-things-products-and-services/">guidance on consumer Internet of Things (IoT) products and services</a>, setting out clear expectations for manufacturers and developers on how to use people&#8217;s personal information responsibly.&#8221;</em></p></li><li><p><a href="https://www.enisa.europa.eu/publications/sme-cra-survey-report">SME CRA Survey Report</a> - <strong>ENISA</strong> publishes - <em>&#8220;The survey aimed to better understand:</em></p><ul><li><p style="text-align: justify;"><em>how familiar SMEs are with the CRA;</em></p></li><li><p style="text-align: justify;"><em>how well they understand the practical requirements of the regulation;</em></p></li><li><p style="text-align: justify;"><em>what they are currently doing in terms of cybersecurity;</em></p></li><li><p style="text-align: justify;"><em>what challenges they expect to face when working towards compliance.&#8221;</em></p></li></ul></li></ul></li></ul><p>No reflections this week.</p><p>Not getting this via email? Subscribe:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Think someone else would benefit? Share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-june-9ec?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-june-9ec?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p><strong>All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.</strong></p><p>Have a lovely Sunday&#8230;</p><p>Ollie</p><h1>Cyber threat intelligence</h1><p>Who is doing what to whom and how allegedly.</p><h2>Reporting on Russia</h2><h3>Russian Intelligence Services Continue to Target Commercial Messaging Applications</h3><p><strong>FBI</strong> attributes and warns around alleged Russian activity against current and former government officials and their use of commercial messaging applications. </p><blockquote><p><span>The FBI has identified multiple clusters of Russian Intelligence Services (</span>RIS<span>) cyber threat actors responsible for an ongoing commercial messaging application (</span>CMA<span>) phishing campaign against individuals of high intelligence value. Russian Federal Security Service (</span>FSB<span>) officers embedded with the FSB Border Guards and others working on behalf of the Russian military services continue to target current and former U.S. and international government officials, military personnel, political figures, journalists, and key officials located in Ukraine. RIS cyber threat actors have compromised individual CMA accounts, but not the CMA's encryption or the application itself. To date, this activity has been publicly tracked as UNC5792 and UNC4221.</span></p></blockquote><p><a href="https://www.ic3.gov/PSA/2026/PSA260626">https://www.ic3.gov/PSA/2026/PSA260626</a></p><h3>STOCKSTAY Another Day: The Latest Addition to Turla&#8217;s Intelligence Gathering Apparatus</h3><p><strong>Jordan Jones</strong> details this alleged Russian capability which is delivered via social engineering. Note also the use of e-mail compromises to facilitate the trust relationship in the social engineering.</p><blockquote><p><span>STOCKSTAY is a multi-component backdoor written in .NET, using the Windows Forms framework, which communicates with its command and control (C2) via a secure WebSocket connection, utilizing the open-source </span><a href="https://github.com/sta/websocket-sharp"><span>websocket-sharp</span></a><span> library. STOCKSTAY consists of several distinct components that communicate with one another via an inter-process communication (IPC) channel, based on the exchange of </span><a href="https://learn.microsoft.com/en-us/windows/win32/dataxchg/wm-copydata"><span>WM_COPYDATA</span></a><span> messages.</span></p><p><span>STOCKSTAY was originally designed to masquerade as a stock market data viewing tool, incorporating this disguise in both its file naming scheme and its storage of implant configuration, control messages, and response data. While initial versions of the malware observed by GTIG retained the internal aspects of this disguise, in 2025 we identified variants of STOCKSTAY masquerading as other benign applications, such as PDF viewers and calculator utilities.</span></p><p><span>..</span></p><p><span>The threat actor(s) involved in STOCKSTAY operations appear to have an affinity for integrating academia and diplomacy into their infrastructure and lure/decoy content, including:</span></p><ul><li><p><span>compromising an email account belonging to a Ukrainian university to disseminate phishing emails;</span></p></li><li><p><span>using the names of an academic institution within the file name of a malicious RDP file;</span></p></li><li><p><span>compromising a diplomatic education platform for phishing and distribution of malicious RDP files;</span></p></li><li><p><span>using &#8220;education&#8221; and &#8220;diplo&#8221; within registered phishing domains; and</span></p></li><li><p><span>using &#8220;DiplomacyEduAI&#8221; as the product name within STOCKSTAY MSI files.</span></p></li></ul></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!XKcJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd4dccf5-8ae8-4299-a078-2ff1d2beff44_2048x1454.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!XKcJ!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd4dccf5-8ae8-4299-a078-2ff1d2beff44_2048x1454.png 424w, /__u/substackcdn.com/image/fetch/$s_!XKcJ!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd4dccf5-8ae8-4299-a078-2ff1d2beff44_2048x1454.png 848w, /__u/substackcdn.com/image/fetch/$s_!XKcJ!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd4dccf5-8ae8-4299-a078-2ff1d2beff44_2048x1454.png 1272w, /__u/substackcdn.com/image/fetch/$s_!XKcJ!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd4dccf5-8ae8-4299-a078-2ff1d2beff44_2048x1454.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!XKcJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd4dccf5-8ae8-4299-a078-2ff1d2beff44_2048x1454.png" width="1456" height="1034" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bd4dccf5-8ae8-4299-a078-2ff1d2beff44_2048x1454.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1034,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig1.max-2100x2100.png&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig1.max-2100x2100.png" title="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig1.max-2100x2100.png" srcset="/__u/substackcdn.com/image/fetch/$s_!XKcJ!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd4dccf5-8ae8-4299-a078-2ff1d2beff44_2048x1454.png 424w, /__u/substackcdn.com/image/fetch/$s_!XKcJ!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd4dccf5-8ae8-4299-a078-2ff1d2beff44_2048x1454.png 848w, /__u/substackcdn.com/image/fetch/$s_!XKcJ!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd4dccf5-8ae8-4299-a078-2ff1d2beff44_2048x1454.png 1272w, /__u/substackcdn.com/image/fetch/$s_!XKcJ!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd4dccf5-8ae8-4299-a078-2ff1d2beff44_2048x1454.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering/">https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering/</a></p><h3>Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances</h3><p><strong>Zolt&#225;n Rusn&#225;k</strong> provides a detailed look at the year in the life of for an alleged Russian threat actor and their alleged operations. The increased scale of their campaigns is of note.</p><blockquote><ul><li><p>Throughout 2025, Gamaredon exclusively targeted governmental and military institutions in Ukraine.</p></li><li><p>We observed 35 distinct spearphishing campaigns against new targets. The majority of the campaigns were carried out in the second half of the year, and they were significantly larger than earlier ones.</p></li><li><p>Additional targets were compromised via multiple custom weaponizers designed for lateral movement.</p></li><li><p>Gamaredon operators developed and deployed six new malicious PowerShell tools, which we analyze in our white paper, and resurrected an old VBScript weaponizer &#8211; PteroSetup.</p></li><li><p>The file stealers PteroVDoor and PteroPSDoor were upgraded to support exfiltration to cloud storage services (Wasabi, Tebi, and Intercolo), which became the primary exfiltration method.</p></li><li><p>Gamaredon operators sought new ways to protect their network infrastructure, with their C&amp;C servers now hidden behind various third-party services such as tunnels, workers, DDNS (dynamic DNS), and PaaS (platform as a service).</p></li><li><p>They also abused multiple legitimate messaging, social media, blogging, and paste services as dead drops for resolving C&amp;C servers and distributing payloads.</p></li></ul></blockquote><p><a href="https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/">https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/</a></p><h3>Dismantling Fortibleed: Inside a Russian Fortinet compromise operation</h3><p><strong>SOC Radar</strong> detail the underpinnings of the campaign which they allege is Russian in origination.</p><blockquote><p>a large-scale credential-harvesting operation targeting more than 430,000 FortiGate firewalls globally. The investigation also confirmed the breach of a NATO-aligned defense contractor. Based on the observed activity, the threat actor is assessed to be an Initial Access Broker (IAB) motivated by financial gain.</p><ul><li><p>Campaign name: FortiBleed </p></li><li><p>Target scope: 430,000+ FortiGate firewalls worldwide </p></li><li><p>Threat actor profile: Initial Access Broker with financial motives </p></li><li><p>Campaign activity: Active since at least February 2026 </p></li><li><p>Credential pipelines: 659+ credential-harvesting pipelines launched </p></li><li><p>Credentials identified: 110 million+ credentials </p></li><li><p>Core tool: Golang-based FortigateSniffer </p></li><li><p> Primary focus: SMBs with fewer than 200 employees, especially in the United States and India </p></li><li><p>Key sector: IT services, likely selected to maximize downstream access</p></li></ul></blockquote><p><a href="https://socradar.io/wp-content/uploads/2026/06/Dismantling-FortiBleed.pdf">https://socradar.io/wp-content/uploads/2026/06/Dismantling-FortiBleed.pdf</a></p><p>There is also this analysis of what the threat actor left behind</p><p><a href="https://www.cloudsek.com/blog/inside-the-fortibleed-open-directory-a-technical-analysis-of-what-the-attacker-left-behind">https://www.cloudsek.com/blog/inside-the-fortibleed-open-directory-a-technical-analysis-of-what-the-attacker-left-behind</a></p><h3>Lost in relocation: analysis of a new loader distributing CASTLESTEALER</h3><p><strong>Daniel Stepanic<span> </span></strong><span>and </span><strong>Jia Yu Chan</strong> detail a suspected criminal campaign which is noteworthy for its use of malicious adverts which one would expect to be a tractable problem in the age of AI.</p><blockquote><ul><li><p>OXLOADER observed in campaigns distributing CASTLESTEALER via malicious Google Ads</p></li><li><p>CIS-region exclusion and Russian language checks suggest a Russian-speaking, financially motivated threat actor</p></li><li><p>Low detection rates across static engines and sandbox detonations</p></li></ul><p>&#8230;</p><p>OXLOADER is distributed via malicious Google Ads impersonating Node.js. Victims are redirected through an intermediary domain to a Storj-hosted batch script, which downloads and executes OXLOADER.</p></blockquote><p><a href="https://www.elastic.co/security-labs/oxloader-malware-loader-infostealer">https://www.elastic.co/security-labs/oxloader-malware-loader-infostealer</a></p><h2>Reporting on China</h2><h3>StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader</h3><p><strong>Fareed Radzi</strong> details an alleged Chinese operation with aligned interest focus. Of note is the exploitation of internet facing infrastructure. </p><blockquote><p>Beyond the diplomatic entity in Indonesia, we identified related activity targeting government organizations in Taiwan, software development companies across multiple countries, and entities in other sectors located in Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal, Serbia, and more. The observed victimology suggests a campaign with broad geographic reach and a diverse target set rather than a narrow focus on a specific industry or region.</p><p>For now, we are tracking this activity as <strong>StrikeShark</strong>. Although the operators utilize several open-source post-compromise tools associated with Chinese-speaking developers, we have not identified direct code reuse, infrastructure overlap, or operational similarity to confidently attribute the activity to any known APT or cybercrime group. As a result, attribution remains preliminary and the campaign&#8217;s ultimate objectives are still under research.</p><p>..</p><p>In the incident affecting an Indonesian diplomatic entity, the threat actor exploited Microsoft Exchange vulnerabilities, including CVE-2021-26855 (ProxyLogon), to gain access to the target environment. Similar activity was observed in Taiwan, where software development organizations were compromised through exploitation of Openfire (CVE-2023-32315). In a separate incident affecting a Colombian organization, the threat actor exploited a GeoServer instance vulnerable to CVE-2024-36401.</p></blockquote><p><a href="https://securelist.com/strikeshark-campaign/120326/">https://securelist.com/strikeshark-campaign/120326/</a></p><h3>CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure</h3><p><strong>Unit 42</strong> details an alleged Chinese operation with in part a focus on critical energy infrastructure, which if true, is of note.</p><blockquote><p><span>The Chinese-speaking attackers behind this cluster, which we track as </span>CL-STA-1062<span>, have been active since at least March 2022. We assess with high confidence that this is the same cluster, known as UAT-7237, that was reported for its campaigns against web hosting infrastructure in Taiwan in mid 2025. We also observed CL-STA-1062 campaigns in earlier operations targeting strategic sectors in East Asia, indicating a broader, sustained regional focus.</span></p><p>&#8230;</p><p>In September 2025, we discovered that the attackers behind CL-STA-1062 had compromised a Southeast Asian government entity by deploying web shells and exfiltrating database information.</p><p>..</p><p>Since mid 2025, as part of activities in Southeast Asia, the threat actor behind CL-STA-1062 focused on critical infrastructure. We identified that a critical infrastructure entity had been under attack for several months. The activity within the compromised network was comprehensive, covering the entire attack lifecycle from initial access to data exfiltration.</p><p>The following month, we discovered that the attackers behind CL-STA-1062 had also compromised two state-owned critical energy infrastructure (CEI) entities in the same Southeast Asian country. We observed attackers scanning the entities for vulnerabilities, shortly followed by outbound requests from the infected networks. These requests connected to attacker-controlled infrastructure and resulted in the victim networks downloading malicious payloads that included SoftEther VPN components and RAR archives containing the group&#8217;s tools.</p></blockquote><p><a href="https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/">https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/</a></p><h2>Reporting on North Korea</h2><h3>KimJongRAT continues to evolve by utilizing LOTS</h3><p><strong>Naoki Takayama</strong> details an alleged North Korea campaign which is of note for using Github releases for hosting and when Microsoft Defender is running an evasion attempt.</p><blockquote><p>In May 2026, we observed an attack campaign distributing KimJongRAT by exploiting GitHub and other platforms. KimJongRAT is malware that combines the functions of both InfoStealer (information-stealing malware) and RAT (Remote Access Trojan), and has been reported to have been used since around 2013 by the APT group Kimsuky (Earth Kumiho) <a href="https://sect.iij.ad.jp/blog/2026/06/continuous-evolution-of-kimjongrat-2026/#cfb8f868-afd8-4ecb-8895-e408fba83067"><sup>&#185;, which is believed to be affiliated with North Korea&#178; </sup></a><a href="https://sect.iij.ad.jp/blog/2026/06/continuous-evolution-of-kimjongrat-2026/#eb3612c5-0a57-4169-9f37-a85ade03c338"><sup>.</sup></a> </p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!pvNV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4983a416-c839-4f57-975b-a079b420d142_1464x913.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!pvNV!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4983a416-c839-4f57-975b-a079b420d142_1464x913.png 424w, /__u/substackcdn.com/image/fetch/$s_!pvNV!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4983a416-c839-4f57-975b-a079b420d142_1464x913.png 848w, /__u/substackcdn.com/image/fetch/$s_!pvNV!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4983a416-c839-4f57-975b-a079b420d142_1464x913.png 1272w, /__u/substackcdn.com/image/fetch/$s_!pvNV!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4983a416-c839-4f57-975b-a079b420d142_1464x913.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!pvNV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4983a416-c839-4f57-975b-a079b420d142_1464x913.png" width="1456" height="908" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4983a416-c839-4f57-975b-a079b420d142_1464x913.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:908,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!pvNV!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4983a416-c839-4f57-975b-a079b420d142_1464x913.png 424w, /__u/substackcdn.com/image/fetch/$s_!pvNV!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4983a416-c839-4f57-975b-a079b420d142_1464x913.png 848w, /__u/substackcdn.com/image/fetch/$s_!pvNV!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4983a416-c839-4f57-975b-a079b420d142_1464x913.png 1272w, /__u/substackcdn.com/image/fetch/$s_!pvNV!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4983a416-c839-4f57-975b-a079b420d142_1464x913.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://sect.iij.ad.jp/blog/2026/06/continuous-evolution-of-kimjongrat-2026/">https://sect.iij.ad.jp/blog/2026/06/continuous-evolution-of-kimjongrat-2026/</a></p><h2>Reporting on Iran</h2><p><em>Nothing overly of note this week</em></p><h2>Reporting on Other Actors</h2><h3>Popa: From Sourcing to Distribution</h3><p><strong>Synthient</strong> detail an SDK which is embedded apps that provide a residential proxies to a company to resell. These types of applications are what allow adversaries to build and/or utilise covert infrastructure. </p><blockquote><ul><li><p>A consumer-facing proxyware SDK has been continuously operated since at least 2020-05-29. Moneytiser and its associated Popa variants are distributed inside consumer streaming, IPTV, and utility applications. </p></li><li><p>Popa-family samples communicate directly with NetNut&#8217;s SDK endpoints. Eighteen distinct Android proxyware samples (first observed 2020-11-20 through 2026-05-23), </p></li><li><p>Public records, as compiled by Qurium, link the NinjaTech platform to NetNut leadership. According to publicly available business-registry data and historical site records analyzed by Qurium Media Foundation, the founder of the NinjaTech platform </p></li><li><p>Network telemetry associates Popa-enrolled hosts with NetNut&#8217;s proxy pool. On 2026-06-17, egress traffic with a specific request path was routed through NetNut&#8217;s commercial gateway<strong> </strong></p></li></ul></blockquote><p><a href="https://synthient.com/blog/popa-from-sourcing-to-distribution">https://synthient.com/blog/popa-from-sourcing-to-distribution</a></p><p><a href="https://github.com/deepfield/public-research/tree/main/popa/iocs">https://github.com/deepfield/public-research/tree/main/popa/iocs</a></p><p><a href="https://github.com/synthient/public-research/blob/main/2026/06/popa/Popa.md">https://github.com/synthient/public-research/blob/main/2026/06/popa/Popa.md</a></p><h3>Nearly Half of LG Smart TV Apps Are <span>Laced with Proxies&#8203;</span></h3><p><strong>Trevor Sutter</strong> highlights what will likely be a surprise to many and shows that the TV eco-system and its relative levels of maturity have a way to go.</p><blockquote><p>Everyone worries about the apps on their phone. Almost no one looks at the ones on their TV. We scanned 6,038 of them across LG and Samsung; 2,058 were selling your IP address.</p></blockquote><p><a href="https://spur.us/blog/smart-tv-apps-residential-proxy-sdks">https://spur.us/blog/smart-tv-apps-residential-proxy-sdks</a></p><h3>Unveiling ErrTraffic: inside a growing ClickFix malware distribution framework</h3><p><strong>J&#233;r&#233;my SCION </strong>and<strong> Quentin BOURGUE </strong>detail how this part of the criminal eco-system works across a blend of initial distribution mechanisms. </p><blockquote><p><span>ErrTraffic is a malicious JavaScript framework primarily injected into compromised WordPress sites to display the ClickFix lure and subsequently deliver malware to visitors. This framework is sold as a </span>MaaS accompanied by a malicious WordPress plugin<span> that facilitates deployment and </span>an administration panel<span> for managing payloads, statistics, geolocation-based filtering, and other features. ErrTraffic&#8217;s </span>operator<span> also </span>sells the source code &#8220;as-is&#8221;<span>.</span></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Zdvg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced803f7-15f5-4b99-b45c-e0337cc1d66a_1024x504.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Zdvg!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced803f7-15f5-4b99-b45c-e0337cc1d66a_1024x504.png 424w, /__u/substackcdn.com/image/fetch/$s_!Zdvg!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced803f7-15f5-4b99-b45c-e0337cc1d66a_1024x504.png 848w, /__u/substackcdn.com/image/fetch/$s_!Zdvg!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced803f7-15f5-4b99-b45c-e0337cc1d66a_1024x504.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Zdvg!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced803f7-15f5-4b99-b45c-e0337cc1d66a_1024x504.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Zdvg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced803f7-15f5-4b99-b45c-e0337cc1d66a_1024x504.png" width="1024" height="504" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ced803f7-15f5-4b99-b45c-e0337cc1d66a_1024x504.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:504,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!Zdvg!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced803f7-15f5-4b99-b45c-e0337cc1d66a_1024x504.png 424w, /__u/substackcdn.com/image/fetch/$s_!Zdvg!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced803f7-15f5-4b99-b45c-e0337cc1d66a_1024x504.png 848w, /__u/substackcdn.com/image/fetch/$s_!Zdvg!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced803f7-15f5-4b99-b45c-e0337cc1d66a_1024x504.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Zdvg!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced803f7-15f5-4b99-b45c-e0337cc1d66a_1024x504.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.sekoia.com/blog/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework">https://www.sekoia.com/blog/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework</a></p><h3>Inside Vidar&#8217;s ABE Bypass: From Memory Scanning to APC Injections</h3><p><strong>Vojt&#283;ch Krejsa</strong> details how an infostealer implements its Application-Bound Encryption decryption which. You have to wonder when/if browsers will become protected processes in Windows to mitigate this.</p><blockquote><p><span>Vidar has been among the most actively developed stealers and, apart from </span>multiple updates to its string obfuscation<span> and </span>a reworked approach to protecting its configuration<span>, it has also introduced a novel technique for bypassing ABE.</span></p><p><span>..</span></p><p><span>From a high-level perspective, Vidar&#8217;s approach to bypassing ABE is somewhat similar to that of Remus/Lumma, in that both try to extract the </span><code>v20_master_key</code><span> directly from the browser&#8217;s memory. What sets them apart, however, is how they achieve it.</span></p><p><span>..</span></p><p><span>For each browser process that produced a match, Vidar now holds a candidate address pointing to a potential encrypted </span><code>v20_master_key</code><span>. However, as already noted, since the key is protected with </span><code>CryptProtectMemory</code><span> using </span><code>CRYPTPROTECTMEMORY_SAME_PROCESS</code><span>, it can only be decrypted by invoking </span><code>CryptUnprotectMemory</code><span> from within the browser process itself. Vidar solves this by injecting an Asynchronous Procedure Call (APC) into the live browser process.</span></p></blockquote><p><a href="https://www.gendigital.com/blog/insights/research/inside-vidar-abe-bypass">https://www.gendigital.com/blog/insights/research/inside-vidar-abe-bypass</a></p><h3>LoaderClient Malware Analysis: How WeedHack Uses Ethereum Smart Contracts for Resilient C2 Infrastructure</h3><p><strong>Darkatlas Squad</strong> detail this campaign which is of note for using smart contracts but also various evasion techniques.</p><blockquote><p>LoaderClient is a Minecraft-based malware loader linked to the WeedHack Malware-as-a-Service campaign. It is distributed as a malicious Minecraft Fabric mod and is designed to steal Minecraft session data, including display name, account UUID, and live Microsoft OAuth access tokens.</p><p>What makes LoaderClient especially notable is its command and control architecture. Instead of hardcoding a traditional C2 domain, the malware uses an Ethereum smart contract to retrieve its active C2 URL. This technique, known as EtherHiding, makes the campaign more resistant to domain takedowns, registrar action, and hosting-provider disruption.</p><p>The malware also downloads a second-stage payload entirely in memory. That stage-2 payload is compiled using JNIC v3.7.0, hides its business logic inside native code, re-resolves C2 through the same Ethereum contract, bypasses SSL validation, uses DNS-over-HTTPS, and supports further in-memory staging.</p></blockquote><p><a href="https://darkatlas.io/blog/loaderclient-malware-analysis-how-weedhack-uses-ethereum-smart-contracts-for-resilient-c2-infrastructure">https://darkatlas.io/blog/loaderclient-malware-analysis-how-weedhack-uses-ethereum-smart-contracts-for-resilient-c2-infrastructure</a></p><h3>Software Supply Chain Incursions</h3><p><span>A reminder we issued guidance a number of weeks ago in </span><a href="https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies">Software supply chain attacks: check your dependencies</a><span> for software developers</span></p><ul><li><p><a href="https://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/">From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet</a></p></li><li><p><a href="https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/">A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope</a></p></li><li><p><a href="https://www.stepsecurity.io/blog/supply-chain-compromise-codfish-semantic-release-action">codfish/semantic-release-action GitHub Action has been compromised</a></p></li><li><p><a href="https://www.sonatype.com/blog/miasma-returns-leo-platform-compromise-in-npm">Miasma Returns: Leo Platform Compromise Shows Why Package Detection Needs Context</a></p></li></ul><p>This presentation <strong>Composer &amp; Packagist Supply Chain Security in 2026</strong> by <strong>Nils Adermann</strong> also details what they doing about the risk</p><p><a href="https://naderman.de/slippy/slides/2026-06-09-PHPVerse-Composer-and-Packagist-Supply-Chain-Security-in-2026.pdf">https://naderman.de/slippy/slides/2026-06-09-PHPVerse-Composer-and-Packagist-Supply-Chain-Security-in-2026.pdf</a></p><h1>Discovery</h1><p>How we find and understand the latent compromises within our environments.</p><h2>gluegate: Memory API proxy via signed mozglue.dll</h2><p><strong>Samir Bousseaden</strong> details this techniques a provides proof of concept to support detection engineers in ensuring coverage.</p><blockquote><p><span>Detection research PoC: proxy memory operations (memory mapping, local memory allocation) through </span><strong>Mozilla's signed </strong><code>mozglue.dll</code><span> so kernel callbacks attribute the final user module to a trusted vendor DLL (Mozilla signed) instead of untrusted or unsigned module.</span></p></blockquote><p><a href="https://github.com/sbousseaden/gluegate">https://github.com/sbousseaden/gluegate</a></p><h2>Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap</h2><p><strong>Terrance DeJesus</strong> provides a practicable guide along with evidenced capability against common malicious Azure AD tooling which will is a boost to threat hunting teams.</p><blockquote><ul><li><p>AAD Graph Activity Logs ride into Elastic through the <strong><a href="https://www.elastic.co/docs/reference/integrations/azure">Azure integration</a></strong> and land in <code>logs-azure.aadgraphactivitylogs-*</code> with full ECS extraction.</p></li><li><p>ROADtools, AADInternals, and friends have been operating in a visibility gap for years. Defenders weren&#8217;t capturing the calls.</p></li><li><p>AAD Graph is &#8220;deprecated&#8221; but still queryable in most tenants. The 1.61-internal API version still returns data that Microsoft Graph won&#8217;t.</p></li><li><p>ECS fields land typed (<code>event.action</code>, <code>event.outcome</code>, <code>http.request.method</code>, <code>source.ip</code>, <code>user.id</code>, <code>user_agent.original</code>). Dataset extras stay queryable under <code>azure.aadgraphactivitylogs.properties.*</code>.</p></li><li><p>Five hunts reliably catch the activity: tooling user-agents, endpoint breadth, <code>*-internal</code> API misuse, FOCI client-ID mismatches, and 4xx surges.</p></li></ul></blockquote><p><a href="https://www.elastic.co/security-labs/aad-graph-activity-logs-threat-detection">https://www.elastic.co/security-labs/aad-graph-activity-logs-threat-detection</a></p><h2>RoguePlanet and GreatXML: Detecting Local Privilege Escalation and BitLocker Security Boundary Abuse</h2><p><strong>Serhii Melnyk</strong> provides a strong indicator for detection against these capabilities which again will help threat hunt teams.</p><blockquote><p>In contrast, several behavioral indicators are consistently observable. The presence of a System32 directory under %TEMP% is a high-confidence anomaly. These artifacts are not part of the exploit logic itself, but rather unavoidable side effects of how the exploit manipulates system behavior. The use of alternate data streams on wermgr.exe, specifically the :WDFOO stream, is highly deterministic and represents a strong detection signal. The repeated creation of UUID-based directories combined with high-frequency file activity provides a clear behavioral profile.</p></blockquote><p><a href="https://www.levelblue.com/blogs/spiderlabs-blog/rogueplanet-and-greatxml-detecting-local-privilege-escalation-and-bitlocker-security-boundary-abuse">https://www.levelblue.com/blogs/spiderlabs-blog/rogueplanet-and-greatxml-detecting-local-privilege-escalation-and-bitlocker-security-boundary-abuse</a></p><h2>Testing AI Threat Hunting against Real-World KQL: A Side-by-Side Test</h2><p><strong><span>Alex Teixeira</span></strong><span> is transparent with his biases but also does the experimentation and acknowledges some of the benefits.</span></p><blockquote><p>I put AI-generated queries head-to-head against the hunting logic I craft for real customer environments and let the results speak for themselves.</p></blockquote><p><a href="https://detect.fyi/testing-ai-threat-hunting-against-real-world-kql-a-side-by-side-test-4cdda76a5772">https://detect.fyi/testing-ai-threat-hunting-against-real-world-kql-a-side-by-side-test-4cdda76a5772</a></p><h2>heavener: This is what happens when you can&#8217;t afford EDR licenses</h2><p><strong>Otter</strong> details the project and sheds some light on the internal workings..</p><blockquote><p><span>heavener is a project I&#8217;ve been building for the past 6 months, and it&#8217;s probably the most ambitious thing I&#8217;ve worked on. It&#8217;s a modular EDR emulation engine for Windows that loads </span><em>real</em><span> detection logic extracted from commercial endpoint security products I have reverse engineered and evaluates it against live telemetry using the actual vendor artifacts: their ML models used for file classification, their compiled YARA rulesets and behavioral scripts. The user picks a vendor module and gets the exact verdicts the production EDR would produce.</span></p></blockquote><p><a href="https://blog.otterpwn.com/projects/heavener">https://blog.otterpwn.com/projects/heavener</a></p><h2>ASF Triage</h2><p><strong>Herrcore</strong> provides this work aid for those looking to understand what happened in an agentic world.</p><blockquote><p>A forensic investigation tool for AI agent session logs (Claude Code and Codex CLI). Drop one or more session <code>.jsonl</code> transcripts, a <code>history.jsonl</code>, a whole folder, or a saved case file, and get a chat-like view for investigating insider-threat and malicious sessions.</p><p>Runs client-side in the browser; <strong>evidence never leaves the analyst&#8217;s machine</strong>. The one exception is per-box translation, which is opt-in and warns before sending text to Google.</p></blockquote><p><a href="https://github.com/OALabs/asftriage">https://github.com/OALabs/asftriage</a></p><h1>Defence</h1><p>How we proactively defend our environments.</p><h2>Prevent data exfiltration: AWS egress controls for cloud workloads</h2><p><strong>Meriem SMACHE</strong> and <strong>Maxim Raya</strong> detail how to do this in practice to impose cost on adversaries through defence in depth.</p><blockquote><p>we show you how to implement layered egress detection and protection using AWS services working together to reduce unauthorized data transfer risk, whether the source is an application with unauthorized access or a manipulated AI agent.</p></blockquote><p><a href="https://aws.amazon.com/blogs/security/prevent-data-exfiltration-aws-egress-controls-for-cloud-workloads/">https://aws.amazon.com/blogs/security/prevent-data-exfiltration-aws-egress-controls-for-cloud-workloads/</a></p><h2>Security Audit Skills</h2><p><strong>Dan</strong> releases this AI skill which shows how one may choose to work..</p><blockquote><p>A coding-agent skill that turns your agent into a security auditor. It orchestrates multiple parallel agents through a six-phase pipeline -- recon, hunting, validation, reporting, structured output, and independent verification -- to find exploitable vulnerabilities with real impact.</p></blockquote><p><a href="https://github.com/cloudflare/security-audit-skill">https://github.com/cloudflare/security-audit-skill</a></p><h2>Exclusion Auditor</h2><p><strong>1689er</strong> releases this work aid to identify the dark corners in EDR exclusions.</p><blockquote><p>Read-only NGAV/EDR exclusion risk and hygiene auditor (CrowdStrike-first, vendor-agnostic).</p></blockquote><p><a href="https://github.com/1689er/exclusion-auditor">https://github.com/1689er/exclusion-auditor</a></p><h2>Reducing Microsoft Sentinel Costs Without Compromising Detection &#8211; Part 1: The Summary Rules Quest</h2><p><strong><span>Christos Giampoulakis</span></strong><span>,</span><strong><span>Theodoros Polyzos</span></strong><span> and </span><strong><span>Dimitrios Patounis </span></strong><span>provide a cost optimisation technique for those wrestling under the weight of their OpEx budgets for SaaS.</span></p><blockquote><p><a href="https://learn.microsoft.com/en-us/azure/azure-monitor/logs/summary-rules?tabs=api#how-summary-rules-work">Summary Rules</a> [2] are scheduled KQL queries that aggregate log data and send the results to a custom log table in your Log Analytics workspace. This gives us the power to store large volumes of data in more cost-efficient tiers while retaining only the most relevant information for investigation purposes and even leveraging it within analytic rules (which will be discussed later).</p><p style="text-align: justify;">The main benefits of using Summary Rules are:</p><ul><li><p><em><strong>Optimized performance</strong></em>: Because the data is pre-aggregated according to the Summary Rule query, investigations can be conducted more efficiently and with greater focus on the summarized events. In addition, executing analytic rules or functions against this dataset is significantly faster than querying through very large volumes of log data.</p></li><li><p><em><strong>Cost Savings</strong></em>: Using Summary Rules to store aggregated information in analytic tables in combination with ingesting all initial data into lower-cost storage tiers, such as Auxiliary or Data Lake, is an effective strategy for significantly reducing overall SIEM costs.</p></li></ul></blockquote><p><a href="https://blog.nviso.eu/2026/06/17/reducing-microsoft-sentinel-costs-without-compromising-detection-part-1-the-summary-rules-quest/">https://blog.nviso.eu/2026/06/17/reducing-microsoft-sentinel-costs-without-compromising-detection-part-1-the-summary-rules-quest/</a></p><h2><span>Mind the Gap: GCP serviceData in Logs Explorer vs. Exported Logs</span></h2><p><strong>Art Ukshini</strong> provides a warning more than anything through this insight - in short verify documentation is reflective of expected behaviours.</p><blockquote><p>When building detection logic for Google Cloud Platform (GCP), an interesting and practically significant inconsistency surfaced around one specific field: <code>serviceData</code><span>.</span></p><p>According to Google&#8217;s documentation, <code>serviceData</code> is deprecated. Newer integrations are expected to use the <code>metadata</code> ffield for service-specific information instead. In theory, this is a clean migration story. In practice, the situation is less consistent and if you&#8217;re writing detection rules against GCP audit logs, it may have real consequences.</p><p>This post walks through a concrete investigation into how <code>serviceData</code> behaves in real GCP audit logs, where it breaks down and why relying on documentation and certain fields alone is not a sufficient strategy when building security detections.</p></blockquote><p><a href="https://permiso.io/blog/gcp-servicedata-officially-deprecated-actively-dangerous">https://permiso.io/blog/gcp-servicedata-officially-deprecated-actively-dangerous</a></p><h1>Incident Writeups &amp; Disclosures</h1><p>How they got in and what they did.</p><h2>An Update on the Recent Klue Security Incident</h2><p><strong>Klue</strong> updates</p><blockquote><p>On June 12, we identified unauthorized activity affecting a portion of Klue&#8217;s integration infrastructure. Since then, we&#8217;ve been working alongside trusted cybersecurity experts to understand what happened, support our customers, and restore the connections you rely on. Our investigation determined that an attacker gained access through a compromised legacy credential associated with an integration service. The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments. Based on our investigation to date, the incident was limited to the affected third-party platforms, and there is no evidence that customer content stored within the Klue platform was impacted. We recognize that customers rely on Klue to securely connect to their systems, and we understand the seriousness of that responsibility.</p></blockquote><p><a href="https://klue.com/blog/an-update-on-recent-klue-security-incident">https://klue.com/blog/an-update-on-recent-klue-security-incident</a></p><h2>The Klue Security Incident and Its Impact on Recorded Future</h2><p><strong>Recorded Future</strong> disclose</p><blockquote><p>This week, Recorded Future's CSIRT was notified that Klue had identified unauthorized access to its environment that affected the integration layer used to connect Klue with other marketing and sales SaaS platforms. According to Klue, the unauthorized activity began on June 12, 2026, and was contained the same morning.</p></blockquote><p><a href="https://www.recordedfuture.com/blog/klue-security-incident">https://www.recordedfuture.com/blog/klue-security-incident</a></p><h2>Klue Third-Party Cybersecurity Incident</h2><p><strong>Jamf</strong> disclose and update</p><blockquote><p>Following our June 18 post, we wanted to provide an update on our ongoing investigation and the security of our systems. CrowdStrike, the cybersecurity firm we engaged to support our review, has confirmed that Threat Actor activity within our environment was isolated to June 11, 2026 and limited to Salesforce data accessed through credentials used for the Klue integration. They found no evidence of lateral movement or access to any other systems or credentials.</p></blockquote><p><a href="https://www.jamf.com/blog/klue-incident/">https://www.jamf.com/blog/klue-incident/</a></p><h2>Tanium</h2><p><strong>Tanium</strong> disclose</p><blockquote><p>Earlier this week, Tanium was made aware that Klue, a third-party platform that syncs battlecard and win/loss data with Salesforce through an OAuth integration, experienced a security breach that allowed the CRM data of Klue&#8217;s customers, including Tanium, to be exfiltrated from Salesforce. This supply chain attack impacted multiple organizations.</p></blockquote><p><a href="https://www.tanium.com/blog/security-update-taniums-response-to-the-klue-breach-that-allowed-data-exfiltration-from-salesforce/">https://www.tanium.com/blog/security-update-taniums-response-to-the-klue-breach-that-allowed-data-exfiltration-from-salesforce/</a></p><h1>Vulnerability</h1><p>Our attack surface.</p><h2>CVE-2026-45504 Exchange File Read</h2><p><strong><span>Batuhan Er </span></strong><span>details this interesting vulnerability as it shows what happens in complex web technology interaction scenarios.  </span></p><blockquote><p>CVE-2026-45504 is a critical arbitrary file read vulnerability in Microsoft Exchange Server 2019, caused by a missing scheme validation on the WebApplicationUrl field returned from attacker-controlled WOPI endpoints. The vulnerability allows an authenticated low-privileged user to read arbitrary local files from the Exchange server by creating an EWS ReferenceAttachment with a crafted ProviderEndpointUrl pointing to an attacker-controlled server. When the victim opens the attachment preview, Exchange makes a SSRF request to the attacker's server, which responds with file:///C:/path/to/file# as the WebApplicationUrl. The # fragment trick causes Exchange to append OAuth parameters after the fragment marker, which are then ignored by the URI parser, resulting in Exchange reading the target file via FileWebRequest and returning its contents to the attacker. Permanent mitigation requires validating the scheme of WebApplicationUrl values returned by WOPI providers to block file:// and other non-HTTP schemes before passing them to WebClient.OpenRead().</p></blockquote><p><a href="https://hawktrace.com/blog/CVE-2026-45504/">https://hawktrace.com/blog/CVE-2026-45504/</a></p><p><a href="https://github.com/hawktrace/CVE-2026-45504/">https://github.com/hawktrace/CVE-2026-45504/</a></p><h2>host-Sender - Universal Email Spoofing against Exchange Online</h2><p><strong>Lucas Dodgson, Tobias Oberd&#246;rfer</strong> and <strong>Robin Hilber</strong> disclosed this earlier in the month but worth being aware.</p><blockquote><p>Using Exchange Online (or on-premises exchange in hybrid mode) in combination with an external MX record, such as a third-party email server or spam protection solution, can allow the spoofing of emails from any sender to any recipient in the target tenant.</p><p>This is regardless of the configured SPF, DKIM, and DMARC policies of the spoofed sender&#8217;s domain, and the emails are delivered without any further warning. It is possible to send emails from anyone, including external and internal email addresses. For internal senders, Outlook even resolves the sender&#8217;s profile picture.</p></blockquote><p><a href="https://labs.infoguard.ch/posts/ghost-sender/">https://labs.infoguard.ch/posts/ghost-sender/</a></p><h2>Microsoft Graph API - Hidden Exclusions with Overly Scoped Permissions</h2><p><strong><span>Adam Boylan </span></strong><span>and </span><strong><span>David Cash </span></strong><span>detail an issue Microsoft have been aware of since September 2025.</span></p><blockquote><p>During several recent red team assessments we observed multiple instances of Conditional Access configurations which allowed for enumeration of the Entra ID tenant information using only a compromised username and password - without the need to satisfy MFA. This tenant information is often extremely useful to an attacker, as it provides valuable reconnaissance data on a target organisation&#8217;s structure and enables further attacks, such as iterative password spraying. Whilst it is not uncommon to find a combination of client ID and user agent which falls through a gap in configured policies, in this instance we noticed the same two client IDs consistently appearing to be excluded from MFA and device compliance restrictions across all user agents.</p><p>Even more strangely, these exceptions appeared to apply only to the modern Microsoft Graph (graph.microsoft.com) resource but not the legacy Azure AD Graph APIs (graph.windows.net). Most surprising of all was that the scope of the token obtained when authenticating with these client IDs indicated that we would only be able to access information relating to our user - but we were able to successfully query endpoints not accessible with our scope and even obtain full AzureHound data despite this.</p></blockquote><p><a href="https://blog.amberwolf.com/blog/2026/june/microsoft-graph-api---hidden-exclusions-with-overly-scoped-permissions/">https://blog.amberwolf.com/blog/2026/june/microsoft-graph-api---hidden-exclusions-with-overly-scoped-permissions/</a></p><h2>Bypassing Conditional Access policies that have a resource exclusion</h2><p><strong>Dirk-jan Mollema</strong> details a gap..</p><blockquote><p><span>There is a </span><a href="https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-cloud-apps#legacy-conditional-access-behavior-when-an-all-resources-policy-has-a-resource-exclusion">documented enforcement gap</a><span> in Conditional Access policies that apply to &#8220;all resources&#8221; but have an exclusion for at least one resource. What is not documented, is that this gap is much larger than what one would expect, and that the documented mitigation doesn&#8217;t actually work. The good news if you are an Entra admin is that this is now considered legacy behaviour that Microsoft is changing and that if your tenant isn&#8217;t automatically migrated yet you can opt-in to the new behaviour which addresses and fixes this issue. If you have a policy with a resource exclusion, I would highly recommend applying this change.</span></p></blockquote><blockquote></blockquote><p><a href="https://dirkjanm.io/bypassing-conditional-access-with-resource-exclusion/">https://dirkjanm.io/bypassing-conditional-access-with-resource-exclusion/</a></p><h2>From context_handle to type confusion</h2><p><strong>k0shl</strong> out of China details a vulnerability class in Windows RPC servers which Microsoft should be able to eradicate through marshalling or at least flag probability/risk of of.</p><blockquote><p>In this blog post, I will share a common type-confusion vulnerability scenario that exists in many RPC servers. I'll walk through some of my thoughts while discovering and studying this class of issues, as well as certain technical details. These problems generally arise due to insufficient constraints in IDL definitions and the lack of proper validation inside RPC interfaces.</p></blockquote><p><a href="https://whereisk0shl.top/post/From%20context_handle%20to%20type%20confusion/">https://whereisk0shl.top/post/From%20context_handle%20to%20type%20confusion/</a></p><h2>Introducing usbliter8</h2><p><strong>Paradigm Shift</strong> show how software and hardware vulnerabilities can be combined for impact against iPhone/iPads and older System-on-Chips.</p><blockquote><p>This write-up details a novel iPhone BootROM vulnerability discovered and exploited by our team. It covers the underlying bug, the associated exploitation techniques, and the post-exploitation steps required to achieve application processor&#8217;s boot-chain compromise. The exploit leverages both a hardware bug in the USB controller and a specific configuration flaw present in the device firmware.</p><p>Currently supported SoCs include Apple A12, S4/S5, and A13. While technical support for A12X/Z is possible, it is not currently implemented. We limited our implementation to these devices, as demonstrating successful exploitation across this range was sufficient to thoroughly validate both the vulnerability and the exploitation strategy.</p></blockquote><p><a href="https://ps.tc/pages/blog-usbliter8.html">https://ps.tc/pages/blog-usbliter8.html</a></p><p><a href="https://github.com/prdgmshift/usbliter8">https://github.com/prdgmshift/usbliter8</a></p><h1>Offense</h1><p>Attack capability, techniques and trade-craft. </p><h2>Bring Your Own Everything: Traitorware</h2><p><strong>Micha&#322; Ciesi&#324;ski</strong> delivered this presentation the essence of which is you don&#8217;t need to deploy actual implants and similar. Instead you can repurpose and leverage a rich mix of legitimate software to achieve ones offensive aims beyond drivers.</p><p><a href="https://github.com/Print3M/MyTalks/blob/main/2026_06_x33fcon_Bring_Your_Own_Everything_-_The_Final_Approach.pdf">https://github.com/Print3M/MyTalks/blob/main/2026_06_x33fcon_Bring_Your_Own_Everything_-_The_Final_Approach.pdf</a></p><h2>Disposable Tooling: Building LLM-Generated Mythic Agents from Prompt to Deployment</h2><p><strong>Adam Chester</strong> highlights the fragility of existing commercial attribution techniques in part (i.e. code genus). However this type of activity should be detectable on the frontier SaaS side and thus disruptable.</p><blockquote><p>I will walk through each major milestone that has been taken in my quest to explore this objective by building LLM-generated Mythic agents from prompt to deployment. Starting at the beginning, I&#8217;ll show what worked, what didn&#8217;t, and where this space is likely going next.</p></blockquote><p><a href="https://specterops.io/blog/2026/06/24/disposable-tooling-building-llm-generated-mythic-agents-from-prompt-to-deployment/">https://specterops.io/blog/2026/06/24/disposable-tooling-building-llm-generated-mythic-agents-from-prompt-to-deployment/</a></p><h2>GhostPack Necromancy: Reforging C# Tools with WasmForge</h2><p><strong>Michael Weber</strong> details their approach which detection engineers will want to ensure coverage of.</p><blockquote><p><span>we got several </span><a href="https://github.com/GhostPack">GhostPack</a><span> tools working through WasmForge. </span><a href="https://github.com/ghostpack/rubeus">Rubeus</a><span> and </span><a href="https://github.com/ghostpack/seatbelt">Seatbelt</a><span> both run as PE binaries that pass through the same outer host which we use for Sliver, with most of their commands functioning at full parity to the original C# code. The mechanism is </span><a href="https://github.com/dotnet/runtimelab/tree/feature/NativeAOT-LLVM">.NET&#8217;s NativeAOT-WASI toolchain</a><span> plus a non-trivial amount of bridge code that we wrote with heavy LLM assistance. The release of this post also heralds our open-sourcing of the entire toolchain.</span></p></blockquote><p><a href="https://www.praetorian.com/blog/wasmforge-csharp-ghostpack-edr-evasion/">https://www.praetorian.com/blog/wasmforge-csharp-ghostpack-edr-evasion/</a></p><p><a href="https://github.com/praetorian-inc/wasmforge">https://github.com/praetorian-inc/wasmforge</a></p><h2>N&#216;W &#8212; Word-Based Shellcode Encoder</h2><p><strong>Nirvana</strong> releases this encoder which could slip past some and thus worth ensuring awareness / detection of.</p><blockquote><p><strong>N&#216;W</strong> (Natural Output Words) is a C tool that converts raw shellcode bytes into human-readable English text &#8212; either a plain list of codewords or fluent natural-looking prose with sentences and paragraphs. The output looks like ordinary writing, not hex dumps or base64 blobs.</p><p>Every byte value (0x00&#8211;0xFF) maps to a unique word, derived from a <strong>secret sentence</strong> you provide. A stream cipher (RC4 or AES-256-CTR) shuffles the byte-to-word assignments based on a <strong>password</strong>. Without both the sentence and password, the encoded text is just noise</p></blockquote><p><a href="https://github.com/NirvanaOn/NOW">https://github.com/NirvanaOn/NOW</a></p><h2>LACUNA Chain: Ghost Frames &#8212; defeats all EDR layers of call-stack-based detection</h2><p><strong>Mohamed Alzhrani</strong> details this technique in glorious and poses a challenge to detection engineers..</p><blockquote><p>The LACUNA Chain defeats all EDR layers of call-stack-based detection.<span> The only remaining signal is behavioral kernel callback correlation &#8212; and that comes with significantly higher false-positive rates than any stack-based rule.</span></p></blockquote><p><a href="https://0xmaz.me/posts/LACUNA-Chain-Ghost-Frames-defeats-All-EDR-layers-of-call-stack-based-detection/">https://0xmaz.me/posts/LACUNA-Chain-Ghost-Frames-defeats-All-EDR-layers-of-call-stack-based-detection/</a></p><h2>SindriKit</h2><p><strong>Charfeddine Youssef</strong> demonstrates the talent in Tunisia with this release which will help offensive capability tidy up their opsec.</p><blockquote><ul><li><p>Decoupled Execution Profiles: Swap underlying memory, module, and thread manipulation behaviors via function pointer tables without breaking the calling technique.</p></li><li><p>Cascading Syscall Fallbacks: Dynamically fall back through a priority queue of syscall extraction strategies (Hell&#8217;s Gate, Halo&#8217;s Gate, etc.) until one evades detection.</p></li><li><p>Compile-Time Obfuscation: String and API hashing algorithms (DJB2, FNV1A) can be swapped globally via CMake. Compiling automatically randomizes the global seed to alter static signatures.</p></li><li><p>Release Builds: A silent tier strips all diagnostic strings, file descriptors, and tracking frames from the final binary, reducing your static footprint to bare primitives.</p></li></ul></blockquote><p><a href="https://github.com/youssefnoob003/SindriKit">https://github.com/youssefnoob003/SindriKit</a></p><h2>Obfusk8 v1.5</h2><p><strong>x86byte</strong> provides an update to this obfuscation framework..</p><blockquote><p>AES String Obfuscation Improvements</p><ul><li><p>Fixed null termination in empty-string edge cases for reliable decryption</p></li><li><p>Enhanced decryption routine robustness across all string widths</p></li></ul><p>PE Obfuscation Enhancements</p><ul><li><p>Fixed PEB export directory offset calculation for correct x64 PE32+ resolution</p></li><li><p>Reduced stack-walk iterations to prevent guard-page crash on default stack size</p></li><li><p>Hardened export table resolver with proper ordinal bounds checking</p></li><li><p>Improved error handling in Cryptography and Networking API wrappers with null checks and early returns</p></li></ul><p>Reliability</p><ul><li><p>Stress-tested: 53/53 AES decryptions pass (50 narrow + 3 wide)</p></li><li><p>All edge-case tests pass (14/14)</p></li><li><p>Clean compilation with default flag</p></li></ul></blockquote><p><a href="https://github.com/x86byte/Obfusk8/releases/tag/v1.5">https://github.com/x86byte/Obfusk8/releases/tag/v1.5</a></p><h1>Exploitation</h1><p>What is being exploited..</p><h3>More Than 4,000 Legacy Routers Compromised by AryStinger, Turned into Global Attack Proxies for Hackers</h3><p><strong>Alex Turing</strong> (not the actual one) and <strong>Acey9</strong> disclose this large router compromise stemming from legacy and unpatched equipment.</p><blockquote><p>The attackers exploited vulnerabilities disclosed 13 years ago to compromise a large number of old routers, building reconnaissance and attack clusters for use in the pre-intrusion footprinting stage. (Note: The campaign disclosed in this article has no direct relationship to what the Ministry of State Security described.)</p><p>..</p><p>the old vulnerabilities CVE-2013-3307 and CVE-2016-5681. The devices affected by these two vulnerabilities are several Linksys and D-Link router models from more than 10 years ago, respectively.</p><p>..</p><p>e captured a homologous sample targeting NAS devices, spread through CVE-2025-11837.</p></blockquote><p><a href="https://blog.xlab.qianxin.com/arystinger-botnet-hijacks-legacy-routers-for-global-attacks-en/">https://blog.xlab.qianxin.com/arystinger-botnet-hijacks-legacy-routers-for-global-attacks-en/</a></p><h2>Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager</h2><p><strong>Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan</strong> and <strong>Lukasz Lamparski</strong> detail exploitation and provide a reason to tidy </p><blockquote><p><span>n early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (</span><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx"><span>CVE-2026-20245</span></a><span>) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access.</span></p><p><span>The vulnerability stems from the device&#8217;s file upload feature lacking the ability to properly filter malicious data.</span></p><p><span>Throughout the intrusion, to maintain operational security and avoid detection, the threat actor consistently employed anti-forensic techniques, selectively deleting and restoring system configuration files that were modified during their activities.</span></p><ul><li><p><strong><span>Rogue Peering and Credential Manipulation</span></strong><span>: In March 2026, a threat actor established initial access via unauthorized peering connections to facilitate Secure Shell (SSH) access. The threat actor used that access to manipulate default account passwords to evade detection.</span></p></li><li><p><strong>Exploitation of CVE-2026-20245</strong><span>: Subsequently, the attacker leveraged a zero-day privilege escalation vulnerability (now tracked as CVE-2026-20245) in Cisco Catalyst SD-WAN Manager to gain root-level access via a malicious CSV upload.</span></p></li><li><p><strong>Extensive Anti-Forensic Cleanup</strong><span>: The threat actor deleted malicious files, reverted configuration changes, and executed a validation script to ensure indicators are purged</span>.</p></li></ul></blockquote><p><a href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager/">https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager/</a></p><h1>Tooling and Techniques</h1><p>Low level tooling and techniques for attack and defence researchers</p><h2>Deobfuscation in the Age of Agentic Reverse Engineering</h2><p><strong>Tim Blazytko</strong> and <strong>Nicol&#242; Altamura</strong> outline where AI and agentic approaches provide productivity enhancement.</p><blockquote><p>What worked</p><ul><li><p>commercial VM &#8212; full devirtualization, weeks &#8594; hours </p></li><li><p> anti-cheat &#8212; &#8764;1,000 VM-entries devirtualized in parallel </p></li><li><p>game DRM (older) &#8212; VM architecture recovered, path devirtualized </p></li><li><p>deflattening &#8212; agents write decompiler-based passes </p></li><li><p>call obfuscation &#8212; recovered via constant propagation + MBA</p></li></ul><p>What did not</p><ul><li><p>commercial VM &#8212; lost without targeted guidance </p></li><li><p>call obfuscation &#8212; agents get confused, we had to step in </p></li><li><p>deflattening &#8212; each pass stays sample-specific </p></li><li><p>game DRM (newer) &#8212; stalls under emulation, meaning is runtime-bound</p></li></ul></blockquote><p><a href="https://synthesis.to/presentations/recon26_agentic_deobfuscation.pdf">https://synthesis.to/presentations/recon26_agentic_deobfuscation.pdf</a></p><h2>Scripting the disassembler: Local agentic reverse engineering through vbdec&#8217;s live COM object model</h2><p><strong>David Zimmer</strong> makes us nostalgic with showing how agentic approaches can be applied to Visual Basic 6 binaries. </p><blockquote><ul><li><p>Even traditional graphical user interface (GUI) applications can be made AI-accessible by publishing their internal object models, allowing agents to query and automate analysis without modifying the core application.</p></li><li><p>This approach can often be implemented with surprisingly little engineering effort, leveraging existing scripting technologies and application data structures.</p></li><li><p>By exposing structured data rather than adding predefined AI features, users can extend a tool&#8217;s capabilities through prompts, turning new analyses into workflows instead of product feature requests.</p></li><li><p>The application becomes both an interactive viewer and a persistent data server, enabling local data to be parsed once and queried repeatedly across multiple agent sessions while keeping analyst-controlled data local.</p></li></ul></blockquote><p><a href="https://blog.talosintelligence.com/scripting-the-disassembler/">https://blog.talosintelligence.com/scripting-the-disassembler/</a></p><h2>MemNixFS</h2><p><strong>Youssef Ayman</strong> releases this capability to world..</p><blockquote><p>Linux Memory Forensics Framework That Transforms Memory Dumps Into a Navigable Filesystem</p></blockquote><p><a href="https://github.com/MemNixFS/MemNixFS">https://github.com/MemNixFS/MemNixFS</a></p><h1>Footnotes</h1><p>Some other small (and not so small) bits and bobs which might be of interest.</p><ul><li><p>Annual, quarterly and monthly reports</p><ul><li><p><em>Nothing overly of note this week, but keep an eye on</em> <a href="https://github.com/jacobdjwilson/awesome-annual-security-reports/tree/main/Annual%20Security%20Reports/2026">the Awesome Annual Security Reports 2026 collection</a> and <a href="https://github.com/blackorbird/APT_REPORT">APT report collection</a></p></li></ul></li><li><p><a href="https://www.phoronix.com/news/Linux-7.2-Drops-strncpy">Linux Finally Eliminates The strncpy API After Six Years Of Work, 360+ Patches</a></p></li><li><p><a href="https://arstechnica.com/security/2026/06/users-cry-foul-after-amd-stripped-memory-crypto-from-its-consumer-cpus/">Users cry foul after AMD stripped memory crypto from its consumer CPUs</a></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/post-quantum-crypto-tech-blog/post-quantum-cryptography-and-crypto-agility/4530365">Post-Quantum Cryptography and Crypto-Agility</a></p></li><li><p><a href="https://blog.bushidotoken.net/2026/06/uk-cybercrime-journal-sustained.html">UK Cybercrime Journal: Sustained DragonForce Campaign</a></p></li><li><p>Artificial intelligence</p><ul><li><p>Fundamental</p><ul><li><p><a href="https://github.com/deepseek-ai/DeepSpec">DeepSpec: </a>DeepSpec is a full-stack codebase for training and evaluating draft models for speculative decoding. It contains data preparation utilities, draft model implementations, training code, and evaluation scripts.</p></li><li><p><a href="https://arxiv.org/abs/2606.25331">Improved Large Language Diffusion Models</a></p></li></ul></li><li><p>Applied non-cyber</p><ul><li><p><a href="https://www.databricks.com/blog/introducing-omnigent-meta-harness-combine-control-and-share-your-agents">Introducing Omnigent: A Meta-Harness to Combine, Control and Share Your Agents</a></p></li><li><p><a href="https://ieeexplore.ieee.org/document/11540994"><span>From LLM Reasoning to Autonomous AI Agents: A Comprehensive Review</span></a></p></li><li><p><a href="https://arxiv.org/abs/2605.05242">Beyond Semantic Similarity: Rethinking Retrieval for Agentic Search via Direct Corpus Interaction</a></p></li><li><p><a href="https://arxiv.org/abs/2604.16593">Revisiting a Pain in the Neck: A Semantic Reasoning Benchmark for Language Models</a></p></li><li><p><a href="https://openreview.net/pdf?id=pwbLmew1aq">MINIAPPBENCH: Evaluating the Shift from Text to Interactive HTML Responses in LLM-Powered Assistants</a></p></li></ul></li><li><p>Applied cyber specific</p><ul><li><p><a href="https://synthesis.to/presentations/recon26_agentic_deobfuscation.pdf">Deobfuscation in the Age of Agentic Reverse Engineering</a></p></li><li><p><a href="https://arxiv.org/abs/2606.24496">Red-Teaming the Agentic Red-Team</a></p></li><li><p><a href="https://github.com/cloudflare/security-audit-skill">A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings</a></p></li><li><p><a href="https://mp.weixin.qq.com/s/STDY38qH3solnGHwGdwQWg"><span>From &#8220;Content Governance&#8221; to &#8220;Behavioral Governance&#8221;: In-depth Analysis of China&#8217;s Intelligent Agent Governance Framework and NSFOCUS&#8217;s Practice</span></a></p></li><li><p><a href="https://dl.acm.org/doi/10.1145/3816249">VulInject: Multi-Type Samples Generation for Learning-based Vulnerability Detection</a></p><ul><li><p><a href="https://github.com/CGCL-codes/VulInject">Code</a></p></li></ul></li><li><p><a href="https://www.nextron-systems.com/2026/06/19/oss-artifact-scanning-at-scale/">From 114,000 OSS Artifacts to 100 Analyst Reviews a Day with THOR Thunderstorm</a></p></li></ul></li></ul></li><li><p>Books</p><ul><li><p><em>Nothing overly of note this week</em></p></li></ul></li><li><p>Events</p><ul><li><p><a href="https://inl.gov/events/grounded-reasoning-and-artificial-intelligence-for-national-security-grains-workshop/">Grounded Reasoning and Artificial Intelligence for National Security (GRAINS) Workshop</a> - Sep. 15&#8211;17, 2026, in Idaho Falls, Idaho.</p></li></ul></li></ul><p>Finally finally the <a href="https://creators.spotify.com/pod/profile/national-cyber-security-c6/episodes/The-Ransomware-Ecosystem-e2hi088">NCSC&#8217;s podcast series</a>.</p><div><hr></div><p><em>Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them. </em></p><p><em>This newsletter is subject to the NCSC website terms and conditions which can be found at <a href="https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions">https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions</a> and you can find out more about how will treat your personal information in our privacy notice at <a href="https://www.ncsc.gov.uk/section/about-this-website/privacy-statement">https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.</a></em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CTO at NCSC - Cyber Defence Analysis! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CTO at NCSC Summary: week ending June 21st]]></title><description><![CDATA["In any contest, the only benchmark that matters is how your capability and performance compares to that of your opponent."]]></description><link>https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-june-dcb</link><guid isPermaLink="false">https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-june-dcb</guid><dc:creator><![CDATA[Ollie Whitehouse]]></dc:creator><pubDate>Sat, 20 Jun 2026 08:31:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YhvD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13ba030b-a8dc-46d0-a4c8-47443d658a8a_1903x1039.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to the weekly highlights and analysis of the&nbsp;<a href="https://infosec.pub/c/blueteamsec?dataType=Post&amp;sort=New">blueteamsec</a>&nbsp;(and my wider reading). Not everything makes it in, but the best bits do. A community member is doing <a href="https://briefing.workshop1.net/">daily AI generated podcast of the last 24hours of posts</a>.</p><p><span data-color="rgb(54, 55, 55)" style="color: rgb(54, 55, 55);">Operationally this week </span><a href="https://www.ncsc.gov.uk/news/advice-following-global-targeting-of-fortinet-firewalls-and-vpn-gateways"><span>NCSC issued advice following global targeting of Fortinet firewalls and VPN gateways</span></a><span> we also had </span><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ">Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability</a> which is being exploited<span data-color="rgb(54, 55, 55)" style="color: rgb(54, 55, 55);">. These once again evidence why it is now an imperative that all vendors implement our </span><a href="https://www.ncsc.gov.uk/guidance/guidance-on-digital-forensics-protective-monitoring">guidance on digital forensics and protective monitoring specifications for producers of network devices and appliances</a><span data-color="rgb(54, 55, 55)" style="color: rgb(54, 55, 55);"> as a matter of urgency and duty to their customers.</span></p><p>In the high-level this week:</p><ul><li><p><a href="https://www.ncsc.gov.uk/speech/richard-horne-speaking-at-the-rusi-annual-security-lecture"><span>Richard Horne speaking at the RUSI Annual Security Lecture</span></a><span> - UK </span><strong><span>National Cyber Security Centre</span></strong><span> publishes - </span><em><span>&#8220;NCSC CEO, Richard Horne's full speech delivered at the RUSI Annual Security Lecture 2026.&#8221; - &#8220;UK initiatives such as CHERI can be a game changer, revisiting fundamental design choices in hardware and software to enforce memory safety and protect against whole classes of vulnerabilities.&#8221; .. &#8220;</span>In any contest, the only benchmark that matters is how your capability and performance compares to that of your opponent.&#8221;</em></p></li><li><p><a href="https://www.ncsc.gov.uk/blogs/the-vibe-coding-spectrum-approach-to-ai-assisted-software-development"><span>The &#8216;vibe coding spectrum&#8217; approach to AI-assisted software development</span></a><span> - UK </span><strong><span>National Cyber Security Centre</span></strong><span> advises - </span><em><span>&#8220;</span>The risk isn't in using AI. The risk is not applying the right safeguards when the stakes are high<span>. It's about recognising that different code deserves different levels of care and oversight.&#8221;</span></em></p></li><li><p><a href="https://www.gov.uk/government/news/uk-japan-frontier-technology-partnership">UK-Japan Frontier Technology Partnership</a> - <strong>Prime Minister&#8217;s Office, 10 Downing Street</strong><span data-color="rgb(11, 12, 12)" style="color: rgb(11, 12, 12);"> and </span><strong>The Rt Hon Sir Keir Starmer KCB KC MP </strong>publish - <em>&#8220;We will build resilience to cyber threats, reinforcing and strengthening long term cyber cooperation through the UK-Japan Strategic Cyber Partnership, welcoming industry-led initiatives that harness complementary capabilities and working together to strengthen the resilience of critical national infrastructure against the full range of cyber threats facing the UK and Japan.&#8221;</em></p></li><li><p><a href="https://www.gov.uk/government/publications/ai-scenarios-2030-helping-policymakers-plan-for-the-future-of-ai">Shaping Tomorrow: The UK&#8217;s Digital Standards Strategy (2026 to 2030)</a> - <strong><span>Department for Science, Innovation &amp; Technology</span></strong><span> publish - &#8220;</span><em>UK action will focus on technologies and standards development organisations that are strategically important, present the highest risk, offer high economic growth potential, and attract high-value jobs and skills. These include AI, cybersecurity, advanced connectivity technologies, quantum technologies, semiconductors and the internet.&#8221;</em></p></li><li><p><a href="https://www.gov.uk/government/consultations/automated-vehicles-statement-of-safety-principles/automated-vehicles-statement-of-safety-principles-consultation">Automated vehicles: statement of safety principles consultation</a> - <strong><span>Department for Transport</span></strong><span> and </span><strong><span>Centre for Connected and Autonomous Vehicles</span></strong><span> publishes </span>- <em>&#8220;we continue to believe that cyber resilience and explainability are best dealt with elsewhere. Our emerging approach to cyber security is set out in <a href="https://www.gov.uk/government/calls-for-evidence/developing-the-automated-vehicles-regulatory-framework">Developing the automated vehicles regulatory framework</a>.&#8221;</em></p></li><li><p><a href="https://www.fct-cf.ca/Content/assets/pdf/base/2026-06-15-EN-Decision-C-6-24.pdf">IN THE MATTER OF an application by [_&#8230;_] for warrants pursuant to sections 12.1 and 21.1 of the Canadian Security Intelligence Service Act, RSC 1985, c C-23 AND IN THE MATTER OF CYBER ESPIONAGE, CYBER SABOTAGE, CYBER FOREIGN-INFLUENCED ACTIVITIES and MALICIOUS BOTNETS </a> - <strong>Federal Court | Cour f&#233;d&#233;rale</strong> discloses a historic judgement - <em>&#8220;Counsel for the AGC and the affiant described the Cyber Threat Reduction Measures Warrant as necessary to protect critical infrastructure from foreign adversaries that have infected certain (identifiable) Canada-based servers, SOHO routers, and IoT devices&#8221;</em> &#8230; <em>&#8220;The Court granted the application and issued the Cyber Threat Reduction Measures Warrant on May 1, 2024, upon finding that the requirements of section 21.1 were met, including that the threat to the security of Canada was clearly established and imminent and that the warranted powers were necessary to reduce the threat. The warrant was first granted for a period of 120 days. On August 29, 2024, the Court renewed the Cyber Threat Reduction Measures Warrant for a further 120 days. The Court undertook to provide brief Reasons for granting the initial application.&#8221;</em></p></li><li><p><a href="https://www.canada.ca/en/public-safety-canada/news/2026/06/government-of-canada-strengthens-cyber-security-and-critical-infrastructure-with-royal-assent-of-bill-c8.html">Government of Canada Strengthens Cyber Security and Critical Infrastructure with Royal Assent of Bill C&#8209;8</a> - <strong>Public Safety Canada</strong> announces  - <em>&#8220;This legislation strengthens Canada&#8217;s ability to protect essential services by supporting the security of the country&#8217;s telecommunications system, and bolstering cyber security across the financial, telecommunications, energy, and transportation sectors.&#8221;</em></p></li><li><p><a href="https://csrc.nist.gov/News/2026/ransomware-risk-management-ir-8374r1">Practical Guidelines for Preventing and Mitigating Ransomware | CSF 2.0 Community Profile</a> - <strong>NIST</strong> publishes -  <em>&#8220;Ransomware attacks can devastate organizations of any size across all sectors, making it imperative to assess and improve readiness to counter these threats and mitigate their impact. Originally developed based on NIST CSF 1.1, this profile has been updated to align with the NIST CSF 2.0, ensuring it provides the most current guidelines on managing ransomware risk.&#8221;</em></p></li><li><p><a href="https://www.cyber.gov.au/about-us/view-all-content/news/consultation-on-evolution-of-essential-eight">Consultation on evolution of Essential Eight</a> - <strong>Australian Signals Directorate</strong> publishes - <em>&#8220;<span data-color="rgb(0, 30, 69)" style="color: rgb(0, 30, 69);">We are now consulting with ASD&#8217;s Cyber Security Network partners on the evolution of the </span><a href="https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight">Essential Eight</a><span data-color="rgb(0, 30, 69)" style="color: rgb(0, 30, 69);"> cyber security framework.&#8221;</span></em></p></li><li><p><a href="https://www.warner.senate.gov/newsroom/press-releases/warner-introduces-bill-to-update-our-countrys-cybersecurity-plans-defend-against-emerging-ai-threats/">Warner Introduces Bill to Update Our Country&#8217;s Cybersecurity Plans, Defend Against Emerging AI Threats</a> - <strong>U.S. Sen. Mark R. Warner (D-VA)</strong> introduces - <em><span data-color="rgb(0, 36, 51)" style="color: rgb(0, 36, 51);">&#8220;As AI continues to rapidly evolve, we must ensure our cybersecurity defenses keep up with the threats of the moment,&#8221; </span><strong>said Sen. Warner.</strong><span data-color="rgb(0, 36, 51)" style="color: rgb(0, 36, 51);"> &#8220;It&#8217;s critical that government works closely with industry, regulators, and cybersecurity experts to develop and regularly update the plans we need to protect our critical infrastructure from increasingly sophisticated malicious actors, including those enabled by AI.&#8221;</span> </em></p></li><li><p><a href="https://www.edpb.europa.eu/news/news/2026/edpb-meets-eu-commissioner-mcgrath-and-adopts-common-data-breach-notification_en"><span>EDPB meets with EU Commissioner McGrath and adopts common data breach notification template</span></a><span> - </span><strong><span>European Data Protection Board</span></strong><span> publishes - </span><em><span>&#8220;</span><span data-color="rgb(51, 51, 51)" style="color: rgb(51, 51, 51);">During its latest plenary, the EDPB met with Michael McGrath, Commissioner for Democracy, Justice, the Rule of Law and Consumer Protection. In addition, the Board has adopted a </span><a href="https://www.edpb.europa.eu/our-work-tools/our-documents/other/template-personal-data-breach-notification_en">common data breach notification template</a><span data-color="rgb(51, 51, 51)" style="color: rgb(51, 51, 51);">.&#8221;</span></em></p></li><li><p><a href="https://www.interpol.int/en/News-and-Events/News/2026/New-INTERPOL-report-highlights-escalating-cyber-threats-across-Asia-and-South-Pacific">New INTERPOL report highlights escalating cyber threats across Asia and South Pacific</a> - <strong>INTERPOL</strong> highlights - <em>&#8220;Key trends highlighted in the report include:</em></p><ul><li><p><em>Ransomware: The region recorded over 135,000 ransomware-related attacks in 2024, affecting sectors including real estate, manufacturing and financial services.</em></p></li><li><p><em>DDoS Attacks: Distributed denial of service attacks surged by 92 per cent in 2024 compared to the previous year.</em></p></li><li><p><em>AI-Driven Crime: Discussions about deepfakes on cybercriminal forums and Telegram channels popular among Southeast Asian threat actors increased by 600 per cent from February to June 2024.</em></p></li><li><p><em>Phishing: 5.5 out of every 1,000 individuals in the region clicked on phishing links monthly &#8211; approximately twice the global average - with cloud applications the primary targets.</em></p></li><li><p><em>Data Breaches: System intrusions accounted for approximately 80 per cent of all data breaches in 2024 with malware and ransomware present in 83 per cent and 51 per cent of cases respectively.&#8221;</em></p></li></ul></li><li><p><a href="https://www.foreignaffairs.com/china/coming-quantum-national-security-crisis">The Coming Quantum National Security Crisis</a> - <strong>Anne Neuberger</strong> asserts - <em>&#8220;The implications of quantum technologies for national security extend beyond cryptography. Quantum sensors can measure time and differences in gravitational and magnetic fields with unprecedented sensitivity and accuracy. These sensors could eventually be used to detect stealth vehicles or navigate armies through GPS-denied environments.&#8221;</em></p></li><li><p><a href="https://www.reuters.com/legal/litigation/france-stop-certifying-products-without-quantum-safe-encryption-2026-06-16/">France to stop certifying products without quantum-safe encryption</a> - <strong>Reuters </strong>reports - <em>&#8220;France&#8217;s cybersecurity agency ANSSI said on Tuesday it would stop certifying security products that lack quantum-resistant encryption, a move that will &#8203;force government bodies and critical operators to shift away from older &#8204;systems. Samih Souissi, ANSSI&#8217;s chief of staff, said at the France Quantum conference that the agency would halt such certifications from 2027, and that businesses should be buying only quantum-safe products &#8203;by 2030.&#8221;</em></p></li><li><p><a href="https://www.altusintel.com/public-yyr53j/?tt=1781377212">GlobalSign Revokes EV Certificates From Sanctioned Firms</a> - <strong>Altus Intel</strong> reports - <em>&#8220;<span data-color="rgb(33, 37, 41)" style="color: rgb(33, 37, 41);">Certification authority </span>GlobalSign<span data-color="rgb(33, 37, 41)" style="color: rgb(33, 37, 41);">, based in Belgium and owned by the Japanese corporation GMO Group, has initiated the process of revoking SSL certificates that were previously issued to Russian companies affected by current sanctions imposed by the European Union. An announcement was made in a letter to GlobalSign&#8217;s partners by the director of the Russian representative office, stating that the revocation process started on June 13 at 04:10 (MSK) and will be conducted in phases.&#8221;</span></em></p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/news/eu-provides-cyber-support-ukraine-against-major-attacks"><span>EU provides cyber support to Ukraine against major attacks</span></a><span> - </span><strong><span>European Commission</span></strong><span> announces - </span><em><span>&#8220;</span>Ukraine can now activate emergency EU cyber support to respond to large-scale cybersecurity incidents, after the Council of the European Union approved its inclusion in the EU Cybersecurity Reserve. The <a href="https://www.enisa.europa.eu/topics/eu-incident-response-and-cyber-crisis-management/eu-cybersecurity-reserve">Reserve</a>, managed by the European Union Agency for Cybersecurity (<a href="https://www.bing.com/ck/a?!&amp;&amp;p=0eedef7f6119edb847ac0be66954080ccae7adc249def8a0e7e89f014a5f0fd4JmltdHM9MTc4MTQ4MTYwMA&amp;ptn=3&amp;ver=2&amp;hsh=4&amp;fclid=3805a0ed-7090-693d-0005-b5cf71fc6870&amp;psq=enisa&amp;u=a1aHR0cHM6Ly93d3cuZW5pc2EuZXVyb3BhLmV1Lw">ENISA</a>), provides incident response services from trusted private providers to help address significant or large-scale incidents.&#8221;</em></p><ul><li><p><a href="https://www.brusselstimes.com/eu-affairs/2192959/ukraine-gains-eu-cyber-shield-for-large-scale-attacks-amid-escalating-threats"><span>Ukraine gains EU cyber shield for large-scale attacks amid escalating threats</span></a><span> - </span><strong><span>Brussels Times</span></strong><span> reports</span></p></li></ul></li><li><p>Reporting on/from China</p><ul><li><p><a href="https://jamestown.org/chinese-grid-operators-maintain-offensive-cyber-programs/">Chinese Grid Operators Maintain Offensive Cyber Programs</a> - <strong>Jamestown</strong> assert - &#8220;<em>State Grid Corporation of China (SGCC) and China Southern Power Grid (CSG) have established standing cyber teams that they describe as &#8220;red and blue team special forces.&#8221; They are part of an ecosystem in the People&#8217;s Republic of China (PRC) that sets Chinese national cybersecurity standards, runs their own grid attack simulation facilities, and publishes research on tool development to attack the industrial control systems that run Western power grids. Simulated attacks used for internal cybersecurity development have included testing against Western systems, the results of which could be used to support PRC state-backed attacks. The PRC&#8217;s doctrine of military&#8211;civil fusion and requirements around cyber vulnerability reporting ensures that the Ministry of State Security, Ministry of Industry and Information Technology, and other government organs have access to these vulnerabilities.&#8221;</em></p></li><li><p><a href="https://www.cac.gov.cn/2026-06/18/c_1783525604615337.htm">Notice on Issuing the &#8220;Product Catalog for Implementing Cybersecurity Labels (First Batch)&#8221; and Related Implementation Rules</a> - <strong>The Cyberspace Administration of China</strong> announces - <em>&#8220;In accordance with the &#8220;Administrative Measures for Cybersecurity Labels&#8221;, the State Internet Information Office, the Ministry of Industry and Information Technology, and the Ministry of Public Security have formulated the &#8220;Catalogue of Products Implementing Cybersecurity Labels (First Batch)&#8221; and related implementation rules, which are hereby issued to you for your compliance. Meanwhile, the National Cybersecurity Standardization Technical Committee has organized the formulation of the &#8220;Security Requirements for Consumer-grade Connected Cameras with Cybersecurity Labels&#8221; (Cybersecurity Standard Practice Guide TC260-PG-20265A), which serves as the standard basis for implementing cybersecurity labels on consumer-grade connected cameras.&#8221;</em></p></li><li><p><a href="https://www.cac.gov.cn/2026-06/18/c_1783525609778371.htm">The Cyberspace Administration of China and two other departments jointly released the &#8220;Measures for Risk Assessment of Network Data Security&#8221;</a> - <strong>The Cyberspace Administration of China</strong> announces - <em>&#8220;The Measures clarify the scope of application, assessment mechanism, and departmental responsibilities. They stipulate that all network data security risk assessments conducted within the territory of the People's Republic of China must comply with these Measures. They clarify that, under the guidance of the National Data Security Coordination Mechanism, the Cyberspace Administration of China, in conjunction with relevant departments such as the State Council's telecommunications and public security departments, will establish a special working mechanism for network data security risk assessment to guide and supervise risk assessment work.&#8221;</em></p><ul><li><p><a href="https://www.cac.gov.cn/2026-06/18/c_1783525609948038.htm">Q&amp;A on the Measures for Risk Assessment of Network Data Security</a></p></li></ul></li><li><p><a href="https://www.cnas.org/publications/reports/red-lines">Red Lines Understanding the National Security Risks of China&#8217;s Advanced AI</a> - <strong>Centre for a New American Security</strong> publishes - <em>&#8220;<span data-color="rgb(104, 114, 121)" style="color: rgb(104, 114, 121);">This report proposes a framework for understanding these risks across three domains and two vectors. In the </span>kinetic domain<span data-color="rgb(104, 114, 121)" style="color: rgb(104, 114, 121);">, Chinese AI systems enhance military capabilities and offensive cyber operations and raise concerns about biological weapons development. In the </span>cognitive domain<span data-color="rgb(104, 114, 121)" style="color: rgb(104, 114, 121);">, they enable more effective censorship, surveillance, influence campaigns, and espionage. In the </span>economic-technological domain<span data-color="rgb(104, 114, 121)" style="color: rgb(104, 114, 121);">, they drive industrial dominance and create dependencies that extend China&#8217;s reach in emerging and advanced economies alike.&#8221;</span></em></p></li></ul></li><li><p> AI</p><ul><li><p><a href="https://www.gov.uk/government/publications/ai-scenarios-2030-helping-policymakers-plan-for-the-future-of-ai">AI Scenarios 2030: Helping policymakers plan for the future of AI</a> - UK <strong>Government Office for Science</strong> publishes - <em>&#8220;This Foresight report sets out 5 scenarios for how AI could develop by 2030, helping policymakers prepare for future risks and opportunities.&#8221;</em></p></li><li><p><a href="https://mp.weixin.qq.com/s/KLtgMX0gqVZ78-3l3dcc0g">Evolution of AI Network Attack and Defense and Security Reconstruction</a> - <strong>Wu Tiejun</strong> of NSFOCUS, China outlines - &#8220;</p><ul><li><p><em>A Leap in AI Attack Capabilities: From Tens of Thousands to Tens of Thousands</em></p></li><li><p><em><span>The four-layer architecture of AI attacks: the orchestration layer is the core.</span></em></p></li><li><p><em><span>Accelerated attack chain: More noteworthy than vulnerability discovery</span></em></p></li><li><p><em><span>The exploit window has been drastically compressed: from &#8220;years&#8221; to &#8220;hours&#8221;</span></em></p></li><li><p><em><span>The asymmetry in offense and defense in the AI &#8203;&#8203;era: Structural disadvantages are being amplified</span></em></p></li><li><p><em><span>A disruption of cost structure: low-end products flood the market, high-end products become expensive</span></em></p></li><li><p><em><span>The Limitations of AI Capabilities: Illusions, False Alarms, and Real-World Limitations</span></em></p></li><li><p><em><span>New Trends in the Global Offensive and Defensive Landscape: Path Differentiation and Asymmetrical Threats</span></em></p></li><li><p><em><span>Shifting Safety Responsibility Forward: From Repair to Prevention&#8221;</span></em></p></li></ul></li><li><p><a href="https://www.aspi.org.au/report/reading-the-room/">Reading the room: Redesigning intelligence product for the AI age</a> - <strong>Chris Taylor</strong> argues - <em>&#8220;Reading the room<span data-color="rgb(68, 68, 68)" style="color: rgb(68, 68, 68);"> argues that Australia&#8217;s National Intelligence Community faces a growing mismatch between how intelligence is produced and how it is now consumed in an AI-shaped information environment. While intelligence collection and analysis have advanced significantly, the formats, delivery methods and user experience of intelligence products have changed far less. As ministers, policymakers and operational leaders increasingly expect information that is faster, more interactive, more tailored and easier to use, the report warns that intelligence risks losing relevance unless it adapts deliberately.&#8221;</span></em></p></li><li><p><a href="https://arxiv.org/abs/2606.12683">From AGI to ASI</a> - <strong>Google DeepMind</strong> publishes - <em>&#8220;After characterizing ASI, the report discusses four potential pathways from AGI to ASI: scaling AGI, AI paradigm shifts, recursive improvement, and ASI emerging from large-scale multiagent collectives. The report then discusses possible frictions and bottlenecks along these pathways. Determining whether the impact of these frictions will be negligible or substantial raises a number of concrete open research questions. Due to large uncertainties for predicting ASI progress, it cannot be ruled out that AI progress might continue to accelerate over the next years. This could imply that the image of a single transformative step change, caused by the introduction of human-level AGI into our society, could be inaccurate. More apt might be the prospect of a series of transformative societal changes caused by AI-enabled progress and breakthroughs across many areas of science and technology. Preparing for this prospect requires a massively interdisciplinary endeavour of global scope and interest.&#8221;</em></p></li></ul></li><li><p><em>Cyber proliferation</em></p><ul><li><p><a href="https://www.in.gr/2026/06/14/politics/politiki-grammateia/ypoklopes-kratikes-ypiresies-edosan-systatikes-epistoles-stin-intellexa-gia-to-predator-pyra-tis-antipoliteysis/#goog_rewarded">Wiretapping: State agencies gave &#8220;letters of recommendation&#8221; to Intellexa for Predator &#8211; Opposition fire</a> - <strong>In</strong> reports - <em>&#8220;According to a report by Vima, the Dilian side claims to have documents from Greek services that served as &#8220;letters of introduction&#8221; for the Predator, in order to facilitate its export to third countries - Fire from the opposition demanding answers from Maximos&#8221;</em></p></li><li><p><a href="https://www.dnews.gr/eidhseis/news-in-english/592745/emails-agreements-and-spyware-new-claims-rock-greece-s-predator-investigation">Emails, Agreements and Spyware: New Claims Rock Greece&#8217;s Predator Investigation</a> - <strong>DNews </strong>reports - <em>&#8220;<span>Fresh allegations linking Greece's intelligence service to the controversial </span>Predator<span> spyware have reignited one of the country's biggest political scandals, after a newspaper report claimed that Israeli businessman Tal Dilian possesses documents and correspondence connecting the surveillance software to state authorities.&#8221;</span></em></p></li><li><p><a href="https://www.hrw.org/news/2026/06/18/bulgaria-licensed-surveillance-exports-to-rights-violators">Bulgaria Licensed Surveillance Exports to Rights Violators</a> - <strong>Human Rights Watch</strong> alleges - <em>&#8220;Human Rights Watch reviewed documents that show the surveillance company, Circles, based in Bulgaria, was granted licenses to legally export telecommunication interception systems, communications monitoring software, and other types of surveillance technology to countries that have well-documented histories of using similar tools to spy on journalists, activists and to otherwise crack down on dissent.&#8221;</em></p></li></ul></li><li><p>Bounty Hunting</p><ul><li><p><a href="https://www.politie.nl/en/news/2026/juni/18/11-international-law-enforcement-initiate-hunt-on-malware-group-socgholish.html">International law enforcement initiate hunt on malware group SocGholish</a> - <strong>Politie</strong> announce - <em>&#8220;In Operation Endgame, a major operation this week disrupted a key infection chain used by cybercriminals. Within an international cooperation, 14.971 websites infected with SocGholish malware were remediated. This malware is used by a criminal group that plays a pivotal role in international cybercrime, namely: Evil Corp.&#8221;</em></p></li><li><p><a href="https://www.europol.europa.eu/media-press/newsroom/news/ransomware-gangs-cut-eur-336-million-audia6-crypto-laundering-pipeline">Ransomware gangs cut off from EUR 336 million &#8216;AudiA6&#8217; crypto laundering pipeline</a> - <strong>EuroPol</strong> announce - <em>&#8220;An international law enforcement operation has dismantled one of the cryptocurrency laundering services most trusted by ransomware gangs and cybercriminal networks, cutting off a key financial pipeline used to wash hundreds of millions in illicit profits.&#8221;</em></p></li><li><p><a href="https://www.chinadailyasia.com/hk/article/635049">Chinese police bust cybercrime ring behind &#8216;Silver Fox&#8217; Trojan virus</a> - <strong>China Daily</strong> reports - &#8220;<em>The gang allegedly sent phishing emails in bulk, stole corporate data and built fraud scenarios to carry out criminal activities totaling more than 7 million yuan ($1 million), police said. Local police have taken criminal compulsory measures against Chen and 26 other suspects, and the case is under further investigation.&#8221;</em></p></li></ul></li><li><p>Market Incentives</p><ul><li><p><a href="https://www.globalreinsurance.com/home/willis-says-most-cyber-breach-losses-are-covered/1458859.article">Willis says most cyber breach losses are covered </a>- <strong>Global [RE]Insurance</strong> reports - &#8220;<em>The broker&#8217;s latest claims report analysed 5,500 cyber claims across 95 countries and around $1bn of insurer payments. Cyber insurance is delivering meaningful financial protection, with more than 95% of average data breach losses and 90% of average first-party losses adequately covered by insurance, according to Willis. The largest single ransomware loss now exceeds $500m, according to the report.&#8221;</em></p></li></ul></li></ul><p>No reflections this week.</p><p>Not getting this via email? Subscribe:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Think someone else would benefit? Share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-june-dcb?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-june-dcb?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p><strong>All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.</strong></p><p>Have a lovely Saturday&#8230;</p><p>Ollie</p><h1>Cyber threat intelligence</h1><p>Who is doing what to whom and how allegedly.</p><h2>Reporting on Russia</h2><h3>UNC1151/Ghostwriter phishing campaign targeting Gmail accounts</h3><p><strong>CERT Polska</strong> detail this alleged Belarusian operation which is noteworthy due to the increased scale.</p><blockquote><p><span>Attacks targeting Gmail accounts at this scale by UNC1151 are a relatively new development; however, the core themes of the messages and their objectives remain unchanged. It is worth emphasizing that although the intensity of previously observed campaigns targeting users of Polish email services (WP, Onet, Interia) has recently decreased, this does not mean the group has completely abandoned such attacks. We encourage you to read our previously published </span><a href="https://cert.pl/posts/2022/07/techniki-unc1151/">article</a><span> describing the evolution of UNC1151 techniques and methods across multiple campaigns. The article is available only in Polish, but modern translation tools provide good results.</span></p></blockquote><p><a href="https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/">https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/</a></p><h3>Russia, Router, DNS, and Messaging-Layer Collection Operations</h3><p><strong>Domain Tools</strong> detail alleged Russian operations focused on SOHO routers and edge devices. Noteworthy due various enablers it provides but also highlights the victimology. Another example of why <span data-color="rgb(54, 55, 55)" style="color: rgb(54, 55, 55);">our </span><a href="https://www.ncsc.gov.uk/guidance/guidance-on-digital-forensics-protective-monitoring">guidance on digital forensics and protective monitoring specifications for producers of network devices and appliances</a><span data-color="rgb(54, 55, 55)" style="color: rgb(54, 55, 55);"> is a matter of urgency and duty to customers.</span></p><blockquote><p>Russian intelligence-linked cyber operations are moving closer to the communications layer. The objective is not immediate disruption. It is quiet access, persistent visibility, and control over the paths people use to communicate, authenticate, and coordinate.</p><p>The router and DNS hijacking activity shows the value of edge infrastructure. Compromised SOHO routers gave Russian operators a place to watch traffic, redirect selected victims, and intercept credentials without touching the endpoint. Messaging-platform targeting gave them the human layer: contacts, conversations, trusted names, and social relationships.</p><p>Together, these operations formed a durable intelligence-collection model. Broad compromise created scale. Selective follow-on targeting created value. Government, defense, critical infrastructure, Ukraine-support networks, journalists, NGOs, researchers, and political figures remained the highest-risk targets, while remote and hybrid workers widened the exposure path.</p><p>Now that this activity has been exposed, Russian operators will likely pivot again. They may shift infrastructure, rotate DNS and proxy methods, alter messaging lures, move to new linked-device abuse workflows, or lean harder into cloud identity and trusted-platform compromise. The collection requirement will remain. The access path will change.</p></blockquote><p><a href="https://dti.domaintools.com/research/threat-intelligence-report-russia-router-dns-and-messaging-layer-collection-operations">https://dti.domaintools.com/research/threat-intelligence-report-russia-router-dns-and-messaging-layer-collection-operations</a></p><h2>Reporting on China</h2><h3>Velvet Ant&#8217;s Operation Highland: How a China-Nexus Actor Infiltrated an Internal Network Undetected</h3><p><strong>Sygnia Team</strong> detail an alleged Chinese operation which edges towards to the more sophisticated end of the spectrum. The tradecraft on show here is noteworthy, should be studied and it understood if cyber defences/detections would be effective against such a scenario.</p><blockquote><ul><li><p>Forensic artifacts place Velvet Ant&#8217;s earliest activity in this environment at 2016 &#8211; nearly a decade of undetected presence inside an internal network</p></li><li><p>The target network had no direct internet connectivity &#8211; the attacker staged through internet-facing systems and traversed the IT network to reach it</p></li><li><p>PAM modules and OpenSSH binaries were replaced with backdoored versions across multiple hosts &#8211; the attacker controlled the full authentication stack</p></li><li><p>Nine distinct pam_unix.so variants were identified, each built in a separate compile environment &#8211; the level of effort required to produce and maintain these variants points to a well-resourced, deliberate operation</p></li><li><p>The modified SSH binaries included a custom flag to disable their own credential logging &#8211; the attacker actively managed their forensic footprint during live operations, a hallmark of high OpSec discipline</p></li><li><p>Remediation was unusually high-risk because the attacker had tampered with components critical to remote access and system administration</p></li></ul></blockquote><p><a href="https://www.sygnia.co/blog/operation-highland-velvet-ant/">https://www.sygnia.co/blog/operation-highland-velvet-ant/</a></p><h3>FishMonger&#8217;s arsenal upgraded: SprySOCKS for Windows</h3><p><strong>ESET Research</strong> detail variants of implant framework allegedly from a Chinese company who is alleged to support the Chinese state in offensive operations. Noteworthy that it went undocumented for nearly three years and the victimology. </p><blockquote><p><span data-color="rgb(66, 77, 86)" style="color: rgb(66, 77, 86);">ESET researchers have discovered two as-yet undocumented Windows variants of </span><a href="https://malpedia.caad.fkie.fraunhofer.de/details/elf.spry_socks">SprySOCKS</a><span data-color="rgb(66, 77, 86)" style="color: rgb(66, 77, 86);">, a previously Linux-only backdoor </span><a href="https://thehackernews.com/2023/09/earth-luscas-new-sprysocks-linux.html">reportedly</a><span data-color="rgb(66, 77, 86)" style="color: rgb(66, 77, 86);"> used by FishMonger, the group believed to be operated by a Chinese contractor named I&#8209;SOON. </span></p><ul><li><p>We discovered two previously undocumented Windows variants of FishMonger&#8217;s <a href="https://malpedia.caad.fkie.fraunhofer.de/details/elf.spry_socks">SprySOCKS</a> backdoor.</p></li><li><p>ESET telemetry shows activity between 2023 and 2024, primarily targeting government organizations in Honduras, Taiwan, Thailand, and Pakistan.</p></li><li><p>Both Windows variants support communication over TCP, UDP, and WebSocket protocols, and implement over 30 commands.</p></li><li><p>The <span>WIN_DRV</span> variant creates a stealthy passive TCP backdoor, relying on a kernel driver to redirect traffic to the backdoor&#8217;s hidden TCP port whenever specially crafted data is detected inside a received TCP packet.</p></li></ul></blockquote><p><a href="https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/">https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/</a></p><h3>Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research</h3><p><strong>Patrick Whitsell</strong>, and <strong>John McGuiness</strong> detail an alleged Chinese operation which is noteworth for the three month lag before the implant laydown. </p><blockquote><ol><li><p><span>Exploit the REDCap server.</span></p></li><li><p><span>After three months, deploy the INFINITERED malware.</span></p></li><li><p><span>INFINITERED stealthily records credentials, and persists through upgrades, for more than a year.</span></p></li><li><p><span>Pivot to a domain admin account.</span></p></li><li><p><span>Add the malicious content compliance rule.</span></p></li><li><p><span>Silently &#8220;BCC-forward&#8221; matched emails to a threat actor-controlled account.</span></p></li></ol><p>This ambitious scope of intelligence collection from UNC6508 may suggest a broader range of targets beyond the identified victims in the medical research community. GTIG assesses these collection priorities are aligned with the strategic interests of the People's Republic of China.</p></blockquote><p><a href="https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research">https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research</a></p><h2>Reporting on North Korea</h2><h3>Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2</h3><p><strong>Genians Security Center</strong> detail an alleged North Korean operation which is used well worn tradecraft for initial access. The C2 set-up is a little novel, but other than not noteworthy.</p><blockquote><ul><li><p><span data-color="rgb(51, 51, 51)" style="color: rgb(51, 51, 51);">Initial access was performed through spear phishing disguised as messages from the Microsoft account team and cybersecurity advisories.</span></p></li><li><p><span data-color="rgb(51, 51, 51)" style="color: rgb(51, 51, 51);">Malicious LNK files were used to induce the installation of NarwhalRAT based on compiled Python script.</span></p></li><li><p><span data-color="rgb(51, 51, 51)" style="color: rgb(51, 51, 51);">Performed various information-stealing activities, including keylogging, screen capture, USB data collection, and remote command execution.</span></p></li><li><p><span data-color="rgb(51, 51, 51)" style="color: rgb(51, 51, 51);">The actor operated a dual C2 structure that used a Korean relay server and the pCloud API as a dead-drop Resolver.</span></p></li></ul></blockquote><p><a href="https://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat">https://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat</a></p><h3>Hunting North Korea&#8217;s job adverts on Google Docs</h3><p><strong>KMSec</strong> details an alleged North Korean operation and shares some tradecraft which can be used to surface other examples / track their activities. </p><blockquote><ul><li><p>DPRK-nexus actor FAMOUS CHOLLIMA uses Google Docs to advertise fake jobs to steal data from developers as well as recruit facilicators for their malicious insider operations</p></li><li><p>This post shows hunting tips on urlscan and <strong><a href="https://dochunt.kmsec.uk/">dochunt</a></strong> (my collection of Google Docs), and highlights several documents I identified attributable FAMOUS CHOLLIMA.</p></li></ul></blockquote><p><a href="https://kmsec.uk/blog/dprk-google-docs/">https://kmsec.uk/blog/dprk-google-docs/</a></p><h2>Reporting on Iran</h2><h3>Ababil of Minab Exposed: LA Metro SCADA Backups and Israeli Victim Data Left Open on an Iranian Staging Server</h3><p><strong>Hunt.io</strong> details an alleged Iranian operation which shows amazingly poor operational security. The regional focus is of note as is the inclusion of SCADA systems.</p><blockquote><ul><li><p>[We] identified and captured the operator&#8217;s staging server at 5.255.127[.]55, a Python SimpleHTTP server that was left completely open on a Netherlands VPS hosted by The Infrastructure Group B.V. (AS60404), first seen April 28, 2026.</p></li><li><p>The open directory contained 2,238 files totalling 5 GB across 545 subdirectories</p></li><li><p>The analysis of the open directory confirms victims across multiple sectors and countries. Organizations with dedicated coverage in this report include Ruppin Academic Center, bac.org.il, adabroker.com.tr, courier.co.il, and Ifat Media Group, alongside LA Metro as the primary confirmed target.</p></li><li><p>LA Metro (LACMTA) confirmed exfiltrated data is present in the staging directory, over 1 GB of Microsoft SQL Server database backups covering transit operations, personnel records, SCADA configurations, yard management systems, and Outlook PST archives of named employees.</p></li><li><p>The http.flask.py custom receiver and .bash_history recovered from the staging server confirm both exfiltration methods described in Gambit Security&#8217;s report.</p></li><li><p>The .bash_history file shows the operator transferred data from a second server, 31.172.87[.]20, via SCP, corroborating Gambit Security&#8217;s linkage to infrastructure previously associated with the nefeshhope[.]com, an Iranian phishing operation against IDF soldiers.</p></li><li><p>Plaintext Chrome password dumps, VPN credentials, network switch running configurations with passwords, and Outlook PST archives of named individuals were staged in the open directory, representing high-severity secondary exposure risks.</p></li></ul></blockquote><p><a href="https://hunt.io/blog/ababil-of-minab-iranian-hackers-exposed-la-metro-breach-open-directory">https://hunt.io/blog/ababil-of-minab-iranian-hackers-exposed-la-metro-breach-open-directory</a></p><h2>Reporting on Other Actors</h2><h3>Killing me gently: Inside Gentlemen&#8217;s EDR killer framework</h3><p><strong>Jakub Sou&#269;ek</strong> provides insight into the capability supply chain in the cyber criminal eco-system.</p><blockquote><ul><li><p>Gentlemen operators develop and maintain an EDR-killer suite provided directly to affiliates.</p></li><li><p>GentleKiller is an in&#8209;house framework with at least eight variants abusing different vulnerable or malicious drivers.</p></li><li><p>Gentlemen operators apply a unified evasion strategy across tools that standardizes impersonation and protection.</p></li><li><p>Third&#8209;party EDR killers (HexKiller, ThrottleBlood, and HavocKiller) are operationally integrated.</p></li><li><p>Gentlemen can rapidly adapt newly released EDR killer proofs-of-concept (PoCs).</p></li><li><p>The gang&#8217;s victimology is globally distributed and notably not US&#8209;focused.</p></li><li><p>Gentlemen also uses OxideHarvest, a credential stealer maintained by one of the group&#8217;s affiliates.</p></li></ul></blockquote><p><a href="https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/">https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/</a></p><h3>Software Supply Chain Incursions</h3><p><span>A reminder we issued guidance a number of weeks ago in </span><a href="https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies">Software supply chain attacks: check your dependencies</a><span> for software developers</span></p><ul><li><p><a href="https://sansec.io/research/optinmonster-supply-chain-attack">OptinMonster supply chain attack hits 1.2 million sites</a></p></li><li><p><a href="https://www.stepsecurity.io/blog/mastra-npm-packages-compromised-using-easy-day-js">Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosquat</a></p></li><li><p><a href="https://www.aikido.dev/blog/multiple-jetbrains-ide-plugins-caught-stealing-ai-keys">Multiple JetBrains IDE plugins caught stealing AI keys</a></p></li><li><p><a href="https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/">Roughly 400 AUR (Arch User Repository) packages compromised</a></p><ul><li><p><a href="https://ioctl.fail/preliminary-analysis-of-aur-malware/">Preliminary analysis of AUR malware</a></p></li></ul></li><li><p><a href="https://dl.acm.org/doi/10.1145/3800506.3803487">VSMEx: A Collection Tool and a Dataset of Malicious VS Code Extensions: Data/Toolset Paper</a></p><ul><li><p><a href="https://github.com/kalachkar/vsmex">A collection tool and dataset of malicious VS Code extensions removed by Microsoft.</a></p></li></ul></li><li><p><a href="https://www.404media.co/hackers-are-hijacking-entire-roblox-games-now/">Hackers Are Hijacking Entire Roblox Games Now</a></p></li></ul><h1>Discovery</h1><p>How we find and understand the latent compromises within our environments.</p><h2>Mind the Gap: Closing Claude&#8217;s Compliance API Blind Spots with OpenTelemetry</h2><p><strong>Andrew Byford</strong> is back with another excellent guide as organisations adjust to the AI eco-system.</p><blockquote><p>In previous posts I've said how Claude Compliance API telemetry has limits. You can see user's prompts and Claude's reply, but not which tools Claude called, what an MCP server handed back, or which files it read off their laptop. In this post I show how to close that gap and get more Claude coverage using OpenTelemetry.</p></blockquote><p><a href="https://www.papermtn.co.uk/mind-the-gap-closing-claudes-compliance-api-blind-spots-with-opentelemetry/">https://www.papermtn.co.uk/mind-the-gap-closing-claudes-compliance-api-blind-spots-with-opentelemetry/</a></p><h2>ModuleStomped</h2><p><strong>Josh</strong> drops this capability which will help surface this technique in the wild.</p><blockquote><p>Proof of concept to detect module stomping detection by looking for modified .pdata sections.</p><p>..</p><p>This is a very rough PoC that aims to detect module stomped DLLs by checking the pdata section of each module. This is more reliable than checking the .text section as the pdata should never change. Across all processes on my dev machine, it only picked out the C2 in memory performing module stomping.</p></blockquote><p><a href="https://github.com/0xjbb/ModuleStomped">https://github.com/0xjbb/ModuleStomped</a></p><h2>Kassandra</h2><p><strong>Sebastian Feldmann</strong><span data-color="rgb(51, 51, 51)" style="color: rgb(51, 51, 51);"> and </span><strong>Dominik Phillips </strong>provide a rather novel approach to detection through telemetry.. </p><blockquote><p>We reveal that most modern C2 implants share key functional primitives and introduce low-level runtime telemetry to fingerprint their evasive behaviours. Finally we provide a POC telemetry consumer (lightweight sensor) to identify implants based on the presented runtime data.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!YhvD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13ba030b-a8dc-46d0-a4c8-47443d658a8a_1903x1039.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!YhvD!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13ba030b-a8dc-46d0-a4c8-47443d658a8a_1903x1039.png 424w, /__u/substackcdn.com/image/fetch/$s_!YhvD!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13ba030b-a8dc-46d0-a4c8-47443d658a8a_1903x1039.png 848w, /__u/substackcdn.com/image/fetch/$s_!YhvD!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13ba030b-a8dc-46d0-a4c8-47443d658a8a_1903x1039.png 1272w, /__u/substackcdn.com/image/fetch/$s_!YhvD!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13ba030b-a8dc-46d0-a4c8-47443d658a8a_1903x1039.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!YhvD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13ba030b-a8dc-46d0-a4c8-47443d658a8a_1903x1039.png" width="1456" height="795" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/13ba030b-a8dc-46d0-a4c8-47443d658a8a_1903x1039.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:795,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:792046,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ctoatncsc.substack.com/i/202805588?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13ba030b-a8dc-46d0-a4c8-47443d658a8a_1903x1039.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!YhvD!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13ba030b-a8dc-46d0-a4c8-47443d658a8a_1903x1039.png 424w, /__u/substackcdn.com/image/fetch/$s_!YhvD!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13ba030b-a8dc-46d0-a4c8-47443d658a8a_1903x1039.png 848w, /__u/substackcdn.com/image/fetch/$s_!YhvD!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13ba030b-a8dc-46d0-a4c8-47443d658a8a_1903x1039.png 1272w, /__u/substackcdn.com/image/fetch/$s_!YhvD!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13ba030b-a8dc-46d0-a4c8-47443d658a8a_1903x1039.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://github.com/threathunters-io/kassandra_x33fcon_2026">https://github.com/threathunters-io/kassandra_x33fcon_2026</a></p><h2>HallWatch</h2><p><strong>Adam Zypherion</strong> provides an interesting implementation technique. We can example some VEH unlinking if this becomes common place by implants.</p><blockquote><p>Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls &amp; Many more.</p><p>..</p><p><span data-color="rgb(31, 35, 40)" style="color: rgb(31, 35, 40);">That is the whole mechanism. Our VEH catches the breakpoint, looks up which stub the address belongs to (we build the map at init time by enumerating ntdll's exports), runs three checks on whoever turned up, and sets </span><code>Context-&gt;Rip</code><span data-color="rgb(31, 35, 40)" style="color: rgb(31, 35, 40);"> to a private trampoline that does the real syscall and returns. The byte stays </span><code>CC</code><span data-color="rgb(31, 35, 40)" style="color: rgb(31, 35, 40);">. The next caller hits it the same way so no page protection flipping back and forth.</span></p></blockquote><p><a href="https://github.com/Zypherion-Technologies/HallWatch">https://github.com/Zypherion-Technologies/HallWatch</a></p><h1>Defence</h1><p>How we proactively defend our environments.</p><h2>Technical Specification for the Security Content Automation Protocol (SCAP): SCAP Version 1.4</h2><p><strong>Dragos Prisaca (NIST), Stephen Quinn (NIST), Jack Vander Pol (NIWC Atlantic)</strong> and <strong>Daniel Harris (NIWC Atlantic)</strong> publish&#8230;</p><blockquote><p>The Security Content Automation Protocol (SCAP) is a suite of specifications that standardize the format and nomenclature by which software flaw and security configuration information is communicated, both to machines and humans. This publication, along with its annex (NIST Special Publication 800-126Ar4) and a set of schemas, collectively define the technical composition of SCAP version 1.4 in terms of its component specifications, their interrelationships and interoperation, and the requirements for SCAP content.</p></blockquote><p><a href="https://csrc.nist.gov/pubs/sp/800/126/r4/final">https://csrc.nist.gov/pubs/sp/800/126/r4/final</a></p><h2>Detecting and removing dangerous secrets on dev workstations before Shai-Hulud does</h2><p><strong>Guillaume Ross</strong> provides a practical guide and given the number of intrusions which are looking for these a good hygiene exercise.</p><blockquote><p>Let&#8217;s use a combination of open-source tools to detect problematic clear-text secrets on workstations and to ensure they&#8217;re not so easy for malware/scripts to steal.</p></blockquote><p><a href="https://recyclebin.zip/posts/2026-05-25-secret-scanning-fleet-bagel/">https://recyclebin.zip/posts/2026-05-25-secret-scanning-fleet-bagel/</a></p><h2>Building a Modern Detection Pipeline with ContentOps</h2><p>..</p><blockquote><p></p></blockquote><p><a href="https://www.secm8.com/posts/contentops-detection-pipeline/">https://www.secm8.com/posts/contentops-detection-pipeline/</a></p><h2>EDRUnChoker</h2><p>..</p><blockquote><p></p></blockquote><p><a href="https://github.com/sbousseaden/EDRUnChoker">https://github.com/sbousseaden/EDRUnChoker</a></p><h1>Incident Writeups &amp; Disclosures</h1><p>How they got in and what they did.</p><h2>Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress</h2><p><strong>Huntress</strong> disclose..</p><blockquote><p>To confirm, the mpacted data may consist of business names, products trialed/used, subscription details (units, pricing), business contact info (e.g., full names, work emails, job title, phone number, and business addresses), marketing/sales communications, and opportunity notes (i.e., free form fields where teammates can capture and track thoughts and next steps).</p><p>We will continue to conduct our internal and external investigation, and as always, will provide more details as they become available.</p></blockquote><p><a href="https://www.huntress.com/blog/klue-breach-investigation">https://www.huntress.com/blog/klue-breach-investigation</a></p><h1>Vulnerability</h1><p>Our attack surface.</p><h2>Dollar-Quote Bypass: A Blind SQL Injection Technique Against Regex-Sanitized Dynamic PL/pgSQL</h2><p><strong>Jerry Luong</strong> highlights a technique web defenders will want to be aware of..</p><blockquote><p><span data-color="rgb(31, 35, 40)" style="color: rgb(31, 35, 40);">We present a blind SQL injection technique that exploits PostgreSQL's dollar-quoting string syntax to evade an </span>application-level<span data-color="rgb(31, 35, 40)" style="color: rgb(31, 35, 40);"> regex sanitizer. By injecting scalar subqueries through unquoted column-name positions in dynamically-constructed </span><code>EXECUTE</code><span data-color="rgb(31, 35, 40)" style="color: rgb(31, 35, 40);"> statements, an attacker can enumerate all database objects visible to the executing role and extract arbitrary data with zero prior knowledge through a boolean oracle. The technique defeats a sanitizer that strips single-quote, semicolon, backslash, and hyphen characters, and works against PL/pgSQL functions that misuse </span><code>format()</code><span data-color="rgb(31, 35, 40)" style="color: rgb(31, 35, 40);"> or string concatenation with partial quoting. We stress that this is an </span>application-layer sanitizer evasion, not a network-layer WAF bypass<span data-color="rgb(31, 35, 40)" style="color: rgb(31, 35, 40);">: when we replayed the payloads through a default OWASP Core Rule Set (CRS) 4.25.0 deployment, they were detected and blocked. To our knowledge, as of May 29, 2026, no public tool or cheat-sheet consolidates this specific combination of dollar-quoted literals, unquoted-identifier injection, and blind extraction</span></p></blockquote><blockquote></blockquote><p><a href="https://jrbusiness.github.io/Dollar-Quote-Desync/">https://jrbusiness.github.io/Dollar-Quote-Desync/</a></p><h2>Unpacking .zip: A First Look at Domain and File Name Confusion</h2><p><strong>Predrag Despotovic</strong><span>, </span><strong>Pranab Mishra</strong><span>, </span><strong>Kevin Rossel<span>, </span>Athanasios Avgetidis</strong><span> and </span>Zane Ma highlight why we should never have a .exe, .ps1 and .lnk TLDs..</p><blockquote><p>The namespace for filenames and DNS names has overlapped since the introduction of DNS in 1985: .com was the original binary format used for DOS and CP/M systems. Recently the introduction of gTLDs such as .zip and .mo}, coupled with the growing prevalence of web resources, has ignited new concerns about potential issues related to DNS and filename confusion. Thus far, the discourse on DNS/filename confusion has been piecemeal and hypothetical, making it unclear what, if any, security concerns credibly exist. To address this gap, we provide the first enumeration of how DNS/filename confusion can be abused. We then perform the first empirical case studies of DNS/filename confusion in the wild, which highlights suspected confusion across a wide range of software. Finally, based on our preliminary findings, we provide suggestions and guidance for future research on this topic.</p></blockquote><p><a href="https://arxiv.org/abs/2604.04805">https://arxiv.org/abs/2604.04805</a></p><h1>Offense</h1><p>Attack capability, techniques and trade-craft. </p><h2>Hunting Honey Pots: When Never Logged In Means Everything</h2><p><strong>Charles F. Hamilton</strong> highlights a technique which those who are employing deception through accounts will want to be alive to.</p><blockquote><p>The core inference is simple to state. An account that appears valuable but has never been used is far more likely to be artificial than an oversight, because real privileged accounts get used and real disused accounts rarely keep their privilege. By correlating the displayed importance of an account, its name, its group membership, its apparent role, with the lastLogon attribute, the inconsistencies that betray a decoy become visible without ever authenticating against it.</p><p>The technique works because of an asymmetry in effort. Defenders invest heavily in making the structure of a decoy convincing, the name, the description, the membership in a Tier 0 group, but they rarely invest in simulating a long term behavioural pattern, because doing so realistically would mean actually using the account and exposing it to the very compromise it is meant to catch. The structure is cheap to fake and the history is expensive, so the history is where the lie shows.</p></blockquote><p><a href="https://offsec.cypfer.com/blog/Honeypot-detection">https://offsec.cypfer.com/blog/Honeypot-detection</a></p><h2>Operationalizing browser exploits to bypass Windows Defender Application Control (WDAC)</h2><p><strong>Valentina Palmiotti</strong> introduces the concept of Bring Your Own Vulnerable Application which is JavaScript powered and comes with its own V8 engine which is known vulnerable and that may be exploited to go before the constraints of JavaScript.</p><blockquote><p>Instead of finding a vulnerability in a Node.js module, what about exploiting the V8 engine with an N-day?</p><p>The attack scenario is a familiar one: bring along a vulnerable but trusted binary, and abuse the fact that it is trusted to gain a foothold on the system. In this case, we use a trusted Electron application with a vulnerable version of V8, replacing main.js with a V8 exploit that executes stage 2 as the payload, and voila, we have native shellcode execution. If the exploited application is whitelisted/signed by a trusted entity (such as Microsoft) and would normally be allowed to run under the employed WDAC policy, it can be used as a vessel for the malicious payload.</p><p>In addition to being able to freely execute shellcode, this approach also has the benefit of executing shellcode in the context of a browser-like process, which has advantages. Behavior that might otherwise be flagged by EDR as suspicious, seems normal for a browser, such as having RWX memory mapped for Just-In-Time (JIT) code.</p><p>&#8230;</p><p>The rest of this blog post will focus on the remaining stages of the exploit development cycle as it pertains to targeting Windows with the specific goal of creating a WDAC bypass and issues I encountered operationalizing the exploit for real-world use.</p></blockquote><p><a href="https://www.ibm.com/think/x-force/operationalizing-browser-exploits-to-bypass-wdac">https://www.ibm.com/think/x-force/operationalizing-browser-exploits-to-bypass-wdac</a></p><h2>Tunnel Vision Toolkit</h2><p><strong>Arshia Reisi</strong> shows why client side posture checks without attestation aren&#8217;t a security feature in realty. </p><blockquote><p><span data-color="rgb(31, 35, 40)" style="color: rgb(31, 35, 40);">Offensive security toolkit for Microsoft Global Secure Access (GSA), Microsoft's Zero Trust Network Access (ZTNA) solution. </span></p><p>Microsoft Global Secure Access is an identity-aware, cloud-delivered network security service that replaces traditional VPNs. It intercepts traffic at the kernel level via a WFP driver, routes it through Microsoft&#8217;s cloud edge, and delivers it to on-premises resources via connectors. It enforces device compliance, conditional access, and per-app policies.</p><p>This research reverse-engineered the GSA wire protocol and built a fully independent tunnel client from scratch. The custom client runs on Linux and macOS, speaks the same gRPC-based protocol, and establishes a working ZTNA tunnel. Device posture checks are self-reported by the client and not validated server-side, which the custom client takes advantage of to present arbitrary device metadata.</p></blockquote><p><a href="https://github.com/ar0x4/tunnel-vision-toolkit">https://github.com/ar0x4/tunnel-vision-toolkit</a></p><h2>Packet Patch</h2><p><strong><span>Yuwei Xu</span><span data-color="rgb(31, 31, 31)" style="color: rgb(31, 31, 31);">, </span><span>Yuanyuan Xu</span><span data-color="rgb(31, 31, 31)" style="color: rgb(31, 31, 31);">, </span><span>Yunpeng Bai</span><span data-color="rgb(31, 31, 31)" style="color: rgb(31, 31, 31);">, </span><span>Jiahui Chen</span><span data-color="rgb(31, 31, 31)" style="color: rgb(31, 31, 31);">, Kehui Song, </span><span>Jie Cao</span><span data-color="rgb(31, 31, 31)" style="color: rgb(31, 31, 31);">, </span><span>Qiao Xiang</span></strong><span data-color="rgb(31, 31, 31)" style="color: rgb(31, 31, 31);"> and </span><strong><span>Guang Cheng</span></strong><span> release this evasion technique which one can expect will lead to improvements in among other areas VPN detection or similar in time.</span></p><blockquote><p><span data-color="rgb(31, 31, 31)" style="color: rgb(31, 31, 31);">we present </span><strong>PacketPatch</strong><span data-color="rgb(31, 31, 31)" style="color: rgb(31, 31, 31);">, a practical scheme for generating adversarial packets against byte-feature-based encrypted traffic classification (B-ETC). To avoid unrealistic preconditions, we design a BERT-based perturbation vector generator, PatchGenerator, that operates under a black-box assumption by producing perturbations from original packets and random header data without requiring access to model gradients or user behavior history. To reduce time and bandwidth overhead, PatchGenerator generates perturbations with a single forward pass and dynamically adjusts the number of masked bytes according to the packet size, thereby controlling the perturbation length. To ensure packet usability, we further propose a symmetric proxy-based deployment method. By inserting the perturbation vector at the boundary between the packet header and payload and updating the necessary protocol fields, adversarial packets can successfully pass integrity checks and be seamlessly restored at the receiving end.</span></p></blockquote><p><a href="https://www.sciencedirect.com/science/article/abs/pii/S016740482600163X">https://www.sciencedirect.com/science/article/abs/pii/S016740482600163X</a></p><p><a href="https://github.com/xuyw-seu/PacketPatch">https://github.com/xuyw-seu/PacketPatch</a></p><h2>Noradrenaline Shared Library Modules</h2><p><strong>Gavin K</strong> releases a capability to start those detection engines for..</p><blockquote><p><span data-color="rgb(31, 35, 40)" style="color: rgb(31, 35, 40);">Native Linux and macOS modules built as small shared libraries for agent workflows. On Poseidon, macOS builds run through </span><code>execute_library</code><span data-color="rgb(31, 35, 40)" style="color: rgb(31, 35, 40);"> today; Linux builds are not yet available on public agents, though other agents may already support them. Linux support for public agents is actively in development.</span></p></blockquote><p><a href="https://github.com/atomiczsec/Noradrenaline">https://github.com/atomiczsec/Noradrenaline</a></p><h2>Git Clean Filter</h2><p><strong>Dhiraj Mishra</strong> highlights another dimensions to development environment security complexity. </p><blockquote><p>The <code>filter.&lt;name&gt;.clean</code> directive in <code>.git/config</code> points at a script and <code>.gitattributes</code> binds that filter to a tracked file. Whenever git renders a real <code>git diff</code> of that file it runs the worktree content through the clean command first, so <code>git</code> blindly launches whatever path we specify there.</p><p>Now here&#8217;s where it gets interesting. Our editors run <code>git diff</code> automatically the moment you click a changed file to populate their SCM (Source Control Management) panel and gutter annotations. Opening the folder alone isn&#8217;t enough, but viewing the change is, and that&#8217;s a pretty natural thing to do when you land in a repo.</p><p>This is the same idea as <code>core.fsmonitor</code> just on a different directive, and it isn&#8217;t <code>fsmonitor</code> so anyone watching for that won&#8217;t see it. The tradecraft fits RT engagements and assume-breach scenarios with any C2 or our <a href="http://github.com/RootUp/XRayC2">XRayC2</a> to get a callback that evades traditional network defenses.</p></blockquote><p><a href="https://github.com/RootUp/git-clean-filter">https://github.com/RootUp/git-clean-filter</a></p><h2>Using Slack links-preview to smuggle C2 in locked-down environments</h2><p><strong>Hugo Valette</strong> details this technique which will prove troublesome to mitigate.</p><blockquote><p>What I propose here is based on a very simple observation that any Slack user has made. Link previews are automatically appended to your message when they contain an HTTPS link:</p><p>The actual request fetching <em>some</em> of the content is performed by Slack. Not by your computer, not by your proxy. This is a nightmare for Blue Teams since they have zero visibility on this traffic, which happens between Slack&#8217;s servers and your listener. This also means it is fairly easy to restrict traffic to your listener so that only Slack&#8217;s infrastructure (and <code>user-agent</code>) can talk to it.</p><p>In summary, you have the two primitives required for a successful C2 channel:</p><ol><li><p>A way out: an HTTP request issuing a GET with a parameter, that Slack will perform on your behalf, bypassing any corporate restrictions.</p></li><li><p>The answer: the preview.</p></li></ol></blockquote><p><a href="https://rwxstoned.github.io/2026-06-18-Slack-links-preview-for-C2/">https://rwxstoned.github.io/2026-06-18-Slack-links-preview-for-C2/</a></p><h1>Exploitation</h1><p>What is being exploited..</p><h2>Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability</h2><p><strong>Cisco</strong> detail..</p><blockquote><p>In June 2026, the Cisco PSIRT became aware of limited exploitation of this vulnerability. Cisco continues to strongly recommend that customers upgrade to a fixed software release to remediate this vulnerability.</p></blockquote><p><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ</a></p><h1>Tooling and Techniques</h1><p>Low level tooling and techniques for attack and defence researchers</p><h2>CUSAFE: Capturing Memory Corruption on NVIDIA GPU</h2><p><strong>Hongyi Lu, Fengwei Zhang, Zhenkai Zhang , Shuai Wang</strong> and <strong>Yanan Guo</strong> detail this rather clever technique.</p><blockquote><p>We present CUSAFE, a novel GPU sanitizer that is readily deployable on commodity NVIDIA GPUs. CUSAFE employs a hybrid metadata scheme combining pointer tagging with inband buffer bounds to enable accurate and efficient memory safety validation.</p></blockquote><p><a href="https://www.usenix.org/system/files/conference/usenixsecurity26/sec26_prepub_lu.pdf">https://www.usenix.org/system/files/conference/usenixsecurity26/sec26_prepub_lu.pdf</a></p><h2>Scales &#8212; carving an embedded eBPF rootkit</h2><p><strong>Jes&#250;s Olmos</strong> provides a practical technique to carve out the eBPF implant..</p><blockquote><p>A lot of eBPF tooling &#8212; and a growing slice of eBPF malware &#8212; ships the kernel-side program embedded inside the user-space loader. This is a small, fully static way to pull that program out: no execution, no kernel, no root. It worked on a real rootkit sample in one pass, and the same trick generalizes to most libbpf-based binaries.</p></blockquote><p><a href="https://sha0coder.github.io/scales/">https://sha0coder.github.io/scales/</a></p><h2>AI-FI: Giving Claude Code Glitch Skills for Bypassing Secure Boot</h2><p><strong>Raelize</strong> shows us the future of agentic glitching&#8230;</p><blockquote><p>We used Claude Code to reproduce a Fault Injection attack where Secure Boot is bypassed on an Espressif ESP32 SoC. We gave Claude full control to all the hardware tooling. All software tooling was written by Claude using third-party libraries. None of the code was written by humans. All this was created organically while glitches were being injected in the background (i.e., no downtime). This type of agentic workflow for finding/exploiting hardware vulnerabilities is likely here to stay, as it will be for software vulnerabilities.</p></blockquote><p><a href="https://raelize.com/blog/ai-fi-giving-claude-code-glitch-skills-for-bypassing-secure-boot/">https://raelize.com/blog/ai-fi-giving-claude-code-glitch-skills-for-bypassing-secure-boot/</a></p><h2>Trusting trust - building Nix from a manually verified seed</h2><p><strong>Matteo Bigoi</strong> shows some of the engineering to mitigate the supply chain threats and have a trustworthy build.</p><blockquote><p>Every build you run rests on a tower of software you did not write and have never read. Your package manager was built by a compiler. That compiler was built by an older one, and that one by an older one before it, with a chain stretching back decades into binaries nobody on your team has ever looked at. You trust the source code because you can read it. But you run the <em>binaries</em>, and a binary can do things its source never mentions.</p><p>For most software, that gap is an abstract worry. For software that has to run in high-assurance, it is the whole problem.</p><p>Information security frameworks for high-assurance environments (eg, <a href="https://www.security.gov.uk/policy-and-guidance/secure-by-design/">Secure by Design</a> in the UK or <a href="https://www.bsi.bund.de/DE/Themen/Oeffentliche-Verwaltung/IT-Grundschutz/it-grundschutz_node.html">BSI Grundschutz</a> in Germany) mandate principled software supply chain security practices; this means tracing back software packages and source code, and, in the limit, of course also compiler infrastructure.</p><ul><li><p>We wanted to build Nix itself from source, with every dependency pinned and accounted for.</p></li><li><p>But building from source needs a compiler we can trust, so we bootstrapped the standard build environment from a 256-byte seed rather than inheriting a pre-existing one.</p></li><li><p>And a seed is only worth trusting if someone has actually read it, so we audited that seed and its bootstrap chain byte by byte, answering one of the oldest known attacks in computing.</p></li></ul><p>The whole journey, from left to right in time, splits cleanly around the moment we have a Nix we can stand on:</p></blockquote><p><a href="https://blog.helsing.ai/posts/trusting-trust-bootstrapping-nix-from-source/">https://blog.helsing.ai/posts/trusting-trust-bootstrapping-nix-from-source/</a></p><h2>ChYing</h2><p>From China.. likely worth developing signatures for..</p><blockquote><p>An open-source, BurpSuite-like application.</p></blockquote><p><a href="https://github.com/yhy0/ChYing">https://github.com/yhy0/ChYing</a></p><h1>Footnotes</h1><p>Some other small (and not so small) bits and bobs which might be of interest.</p><ul><li><p>Annual, quarterly and monthly reports</p><ul><li><p><em>Nothing overly of note this week, but keep an eye on</em> <a href="https://github.com/jacobdjwilson/awesome-annual-security-reports/tree/main/Annual%20Security%20Reports/2026">the Awesome Annual Security Reports 2026 collection</a></p></li><li><p><a href="https://www.enisa.europa.eu/publications/sbom-adoption-state-of-play-2026">SBOM Adoption State of Play - 2026</a></p></li></ul></li><li><p><a href="https://www.monoidal.net/qnotes/qnotes-2026-02-07.pdf">Introduction to Quantum Algorithms and Quantum Programming</a></p></li><li><p><a href="https://aws.amazon.com/blogs/security/well-architected-best-practices-for-software-supply-chain-security/">Well-architected best practices for software supply chain security</a></p></li><li><p><a href="https://www.ndss-symposium.org/ndss-paper/actively-understanding-the-dynamics-and-risks-of-the-threat-intelligence-ecosystem/">Actively Understanding the Dynamics and Risks of the Threat Intelligence Ecosystem</a></p></li><li><p>Artificial intelligence</p><ul><li><p>Fundamental</p><ul><li><p><em>Nothing overly of note this week</em></p></li></ul></li><li><p>Applied non-cyber</p><ul><li><p><a href="https://arxiv.org/abs/2606.20510">Efficient and Sound Probabilistic Verification for AI Agents</a></p></li><li><p><a href="https://github.com/zardus/juvenal">Juvenal -  a framework for orchestrating AI coding agents through verified implementation phases. It prevents agents from cheating on success criteria, helps agents implement complex projects in phases, etc.</a></p></li><li><p><a href="https://arxiv.org/abs/2606.18430">Signature filtering: a lightweight enhancement for statistical watermark detection in large language models</a></p></li></ul></li><li><p>Applied cyber specific</p><ul><li><p><a href="https://arxiv.org/abs/2606.20502">Calibration Without Comprehension: Diagnosing the Limits of Fine-Tuning LLMs for Vulnerability Detection in Systems Software</a></p></li><li><p><a href="https://arxiv.org/abs/2606.19191">PhantomSkill: Malicious Code Injection in Agent Skill Ecosystems</a></p></li><li><p><a href="https://mp-weixin-qq-com.translate.goog/s/ynnTKDpktqgX-XDpVJOLyw?_x_tr_sl=auto&amp;_x_tr_tl=en&amp;_x_tr_hl=en&amp;_x_tr_pto=wapp">After applying AI to perform a deep audit of ActiveMQ patches, two new high-risk vulnerabilities were discovered</a></p></li><li><p><a href="https://arxiv.org/abs/2604.08407">Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain</a></p></li><li><p><a href="http://arxiv.org/abs/2606.19149">OpenAnt: LLM-Powered Vulnerability Discovery Through Code Decomposition, Adversarial Verification, and Dynamic Testing</a></p><ul><li><p><a href="https://github.com/knostic/OpenAnt">Code</a></p></li></ul></li><li><p><a href="https://arxiv.org/abs/2605.17380">ADR: An Agentic Detection System for Enterprise Agentic AI Security</a></p></li><li><p><a href="https://mp.weixin.qq.com/s/EM0NQSITmCJ7syHxg5Ig-g">Anti-intrusion Pipeline 2.0 (Agentic)</a></p></li><li><p><a href="https://arxiv.org/abs/2606.18619">Code-Augur: Agentic Vulnerability Detection via Specification Inference</a></p></li><li><p><a href="https://arxiv.org/abs/2606.17398">SoK: AI-Augmented Binary Reversing</a></p></li><li><p><a href="https://arxiv.org/abs/2606.16162">Binary Decompilation LLM with Feedback-Driven Multi-Turn Refinement</a></p></li><li><p><a href="https://arxiv.org/abs/2606.16287">Dynamic Malicious Skills in Agentic AI</a></p></li><li><p><a href="https://arxiv.org/abs/2606.14295">AgentCyberRange: Benchmarking Frontier AI Systems in Realistic Cyber Ranges</a></p></li><li><p><a href="https://arxiv.org/abs/2606.18405">Evaluating the Effectiveness of LLMs in Aiding Compliance Testing of PKCS#1-v1.5</a></p></li></ul></li></ul></li><li><p>Books</p><ul><li><p><a href="https://www.intechopen.com/online-first/1238688#">The AI Governance Paradox: Ethical Awareness Without Operational Clarity</a></p></li></ul></li><li><p>Events</p><ul><li><p><em>Nothing overly of note this week</em></p></li></ul></li></ul><p>Finally finally the <a href="https://creators.spotify.com/pod/profile/national-cyber-security-c6/episodes/The-Ransomware-Ecosystem-e2hi088">NCSC&#8217;s podcast series</a>.</p><div><hr></div><p><em>Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them. </em></p><p><em>This newsletter is subject to the NCSC website terms and conditions which can be found at <a href="https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions">https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions</a> and you can find out more about how will treat your personal information in our privacy notice at <a href="https://www.ncsc.gov.uk/section/about-this-website/privacy-statement">https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.</a></em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CTO at NCSC - Cyber Defence Analysis! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CTO at NCSC Summary: week ending June 14th]]></title><description><![CDATA["A partnership between the NCSC and the Department for Science, Innovation and Technology - is leading this work, exploring how frontier AI can be applied safely to cyber defence across government."]]></description><link>https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-june-fb9</link><guid isPermaLink="false">https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-june-fb9</guid><dc:creator><![CDATA[Ollie Whitehouse]]></dc:creator><pubDate>Sat, 13 Jun 2026 09:58:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!WPVh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F280731fa-b4ee-4691-844b-4569b527747b_2560x1047.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to the weekly highlights and analysis of the&nbsp;<a href="https://infosec.pub/c/blueteamsec?dataType=Post&amp;sort=New">blueteamsec</a>&nbsp;(and my wider reading). Not everything makes it in, but the best bits do. A community member is doing <a href="https://briefing.workshop1.net/">daily AI generated podcast of the last 24hours of posts</a>.</p><p>Operationally this week we have active exploitation in a range of cyber security and networking products from the Palo Alto, CheckPoint and Cisco as well as vulnerabilities in Ivanti. Additionally we have the JDY botnet comprising of over 1,500 small office and home office (SOHO) and Internet of Things (IoT) devices. This is why it is now an imperative that all vendors implement our <a href="https://www.ncsc.gov.uk/guidance/guidance-on-digital-forensics-protective-monitoring">guidance on digital forensics and protective monitoring specifications for producers of network devices and appliances</a> as a matter of urgency and duty to their customers. Outside of that we continued software supply chain incursions for which you are encouraged to read our <a href="https://www.ncsc.gov.uk/guidance/guidance-on-digital-forensics-protective-monitoring">Software supply chain attacks: check your dependencies</a> guidance.</p><p>In the high-level this week:</p><ul><li><p><a href="https://www.gov.uk/government/case-studies/when-ai-leaves-the-lab-testing-frontier-models-in-government-cyber-defence">When AI Leaves the Lab: Testing Frontier Models in Government Cyber Defence</a> - <strong>Department for Science, Innovation and Technology</strong> and <strong>National Cyber Security Centre - </strong><em>&#8220;The Government Cyber Action Plan aims to boost cyber resilience across the UK public sector by using emerging technologies to manage risk. The Government Cyber Coordination Centre (GC3) - a partnership between the NCSC and the Department for Science, Innovation and Technology - is leading this work, exploring how frontier AI can be applied safely to cyber defence across government.&#8221;</em></p></li><li><p><a href="https://www.whitehouse.gov/presidential-actions/2026/06/national-security-presidential-memorandum-nspm-12/">NATIONAL SECURITY PRESIDENTIAL MEMORANDUM/NSPM-12</a> - National Policy for the Cybersecurity of National Security Systems - The <strong>White House</strong> issue - <em>&#8220;This National Security Presidential Memorandum sets forth principles and establishes cybersecurity governance for NSS. It further details the governance structure of the Committee on National Security Systems (CNSS) and the role of the Director, National Security Agency (NSA) as the National Manager for NSS.&#8221;</em></p><ul><li><p><a href="https://www.whitehouse.gov/fact-sheets/2026/06/fact-sheet-president-donald-j-trump-defends-americas-warfighters-and-intelligence-officers-against-cyber-threats/">Fact Sheet: President Donald J. Trump Defends America&#8217;s Warfighters and Intelligence Officers Against Cyber Threats</a></p></li></ul></li><li><p><a href="https://www.gov.uk/government/publications/quantum-key-distribution-research-report/quantum-key-distribution-research-report">Quantum key distribution research report</a> - <strong>Department for Science, Innovation &amp; Technology</strong> publish - <em>&#8220;Most interviewees expect QKD to be deployed as an additional security layer alongside PQC and conventional controls. However, they were not convinced that QKD is needed to address post-quantum risk, with many in the broader cyber security supply chain taking the view that PQC will be sufficient.&#8221;</em></p><ul><li><p>The NCSC position can be found in <a href="https://www.ncsc.gov.uk/paper/quantum-networking-technologies">Quantum networking technologies: A white paper outlining the NCSC&#8217;s approach to quantum security technologies.</a></p></li></ul></li><li><p><a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk">BOD 26-04: Prioritizing Security Updates Based on Risk</a> - <strong>CISA</strong> issue - <em>&#8220;Within 60 days of issuance: Update agency vulnerability management processes and procedures to support ongoing vulnerability remediation based on the vulnerabilities identified in the CVE database (or a service that provides the same data) and the KEV catalog. As required by Required Action 1, agencies will provide a copy of their updated vulnerability management policies and procedures if requested by CISA.&#8221;</em></p></li><li><p><a href="https://www.cisa.gov/resources-tools/resources/cisa-and-partners-urge-hardening-automatic-tank-gauge-systems">CISA and Partners Urge Hardening Automatic Tank Gauge Systems</a> - <strong>CISA</strong> and partners urge - &#8220;<em>The recent malicious cyber activity observed by the authoring organizations&#8212;which the U.S. government has not yet attributed to a nation-state or threat actor group&#8212;involves cyber threat actors compromising internet-exposed ATG systems and subsequently modifying them through command execution. This fact sheet provides insight into probable tactics, techniques, and procedures (TTPs) leveraged by these cyber actors, highlights risk factors associated with such compromises, and provides mitigation guidance and resources to reduce the likelihood of continued malicious activity targeting U.S.-based ATG systems.&#8221;</em></p></li><li><p><a href="https://www.defenseone.com/policy/2026/06/cyber-force-service-branch-fails-senate/414149/?oref=d1-featured-river-top">Push for new Cyber Force service branch narrowly fails in the Senate</a> - <strong>Defense One</strong> reports - <em>&#8220;An effort to create a new cyber-focused military service under the Army narrowly failed in the Senate, but the lawmaker who proposed it isn&#8217;t backing down.&#8221;</em></p></li><li><p><a href="https://breakingdefense.com/2026/06/a-cyber-force-budget-would-require-at-least-10-billion-new-commission-report-says/">A Cyber Force budget would require at least $10 billion, new commission report</a> - <strong>Breaking Defence</strong> reports -  <em>&#8220;The initial $10 billion to $11 billion budget recommendation would realign<mark> </mark>existing money Congress has already allocated to the military across the services<mark> </mark>to the Cyber Force, said<mark> </mark>Joshua Stiefel, vice president for government relations at software company Second Front.&#8221;</em></p></li><li><p><a href="https://eucyberdirect.eu/blog/pragmatism-at-the-un-leveraging-non-governmental-stakeholders-to-improve-collective-cybersecurity">Pragmatism at the UN: leveraging non-governmental stakeholders to improve collective cybersecurity</a> - <strong>EU Cyber Direct</strong> outlines - <em>&#8220;A small group of States is persistently seeking to modify prior agreements and insert new constraints to prevent civil society, industry, and academia from engaging meaningfully in the UN Global Mechanism. These States advocate for tools to silence views of experts, against the interests voiced by States from all regions and levels of development.&#8221;</em></p></li><li><p><a href="https://cyberdefensereview.army.mil/Portals/6/Documents/2026-vol11-iss2/CDR_V11_N2_Fischerkeller.pdf">Cyber Persistence Theory Is Cyber Praxis</a> - <strong>Dr. Michael P. Fischerkeller, Dr. Emily O. Goldman </strong>and<strong> Prof. Richard J. Harknett</strong> publish - <em>&#8220;Drawing on developments in the United States, Europe, and Asia, the authors contend that states are shifting away from reactive models based on restraint and deterrence toward proactive approaches centered on initiative persistence, continuous engagement, and strategic campaigning. The essay examines how this evolution reflects a broader break from legacy paradigms inherited from conventional and nuclear security thinking. It also highlights challenges for policymakers, military organizations, educators, and researchers, including workforce development, campaign assessment, human machine teaming, and the extension of CPT into managing crisis and armed conflict.&#8221;</em></p></li><li><p>Reporting on/from China</p><ul><li><p><a href="https://bindinghook.com/understanding-modern-chinese-cyber-operations-means-shifting-from-apt-to-composite-responsibility/">Understanding modern Chinese cyber operations means shifting from &#8216;APT&#8217; to composite responsibility</a> - <strong>Sveva Vittoria Scenarelli</strong> outlines - <em>&#8220;A suitable framework is composite responsibility: a model of Chinese cyber activity in which a single operation or campaign may involve multiple distinct public and private sector entities, each contributing different functions, and therefore bearing different, non-equivalent responsibility. By differentiating tasking relationships and respective roles in a campaign, composite responsibility helps policymakers apply more targeted responses.&#8221;</em></p></li><li><p><a href="https://www.cac.gov.cn/2026-06/13/c_1782919789934988.htm">&#8220;Guidelines for the Classification and Grading of Financial Information Service Data&#8221;</a> - <strong>Cyberspace Administration of China</strong> issue - <em>&#8220;To guide financial information service institutions in conducting data classification and grading and identifying important data, and to improve the data security level of financial information services, the State Internet Information Office, the People's Bank of China, the State Financial Regulatory Commission, the China Securities Regulatory Commission, the National Bureau of Statistics, and the State Administration of Foreign Exchange have jointly formulated the "Guidelines for Data Classification and Grading of Financial Information Services" in accordance with the "Cybersecurity Law of the People's Republic of China," the "Data Security Law of the People's Republic of China," the "Personal Information Protection Law of the People's Republic of China," the "Regulations on the Administration of Network Data Security," and the "Regulations on the Administration of Financial Information Services.&#8221;</em></p><ul><li><p><a href="https://www.cac.gov.cn/2026-06/13/c_1783104511414074.htm">Q&amp;A on the &#8220;Guidelines for Data Classification and Grading of Financial Information Services&#8221;</a></p></li></ul></li><li><p><a href="https://www.scmp.com/tech/big-tech/article/3356090/tencents-chief-ai-scientist-dismisses-lag-concerns-says-race-long-term-game">Tencent&#8217;s chief AI scientist dismisses lag concerns, says race a &#8216;long-term game&#8217;</a> - <strong>South China Morning Post</strong> reports - &#8220;<em>Yao Shunyu, the former OpenAI researcher now leading Tencent Holdings&#8217; artificial intelligence model development, pushed back against concerns that the tech giant is slow in AI, arguing that the race is just beginning with massive untapped opportunities in coding agents and embodied intelligence. &#8220;AI is a long-term game, with the second half of the race just starting,&#8221; said Yao, chief AI scientist at Tencent, comparing the current state to the development of personal computers in the 1970s.&#8221;</em></p></li><li><p><a href="https://www.scmp.com/news/china/science/article/3356030/china-unveils-worlds-first-superfast-quantum-memory-paving-way-practical-computing">China unveils world&#8217;s first superfast quantum memory, paving way for practical computing</a> - <strong>South China Morning Post</strong> reports - <em>&#8220;Chinese scientists have created the world&#8217;s first superfast memory for quantum computers, solving a critical data-reading bottleneck and paving the way for big-data challenges such as drug discovery and detecting fraudulent financial activities.&#8221;</em></p></li><li><p><a href="https://www.scmp.com/tech/article/3356117/huawei-chips-refine-deepseek-model-major-leap-chinas-ai-self-reliance">Huawei chips refine DeepSeek model in major leap for China&#8217;s AI self-reliance </a>- <strong>South China Morning Post</strong> reports - <em>&#8220;A research team that includes Huawei Technologies says it has successfully used the firm&#8217;s Ascend 910C chips to complete post-training for the DeepSeek-V4-Pro model, marking a major step forward as China&#8217;s semiconductor industry tries to leap from supporting basic AI inference to more complex model training amid tightening US sanctions.&#8221;</em></p></li><li><p><a href="https://www.scmp.com/tech/policy/article/3355973/us-seeks-block-chinese-carriers-beijing-opens-telecoms-pilots-foreign-outfits">As US seeks to block Chinese carriers, Beijing opens telecoms pilots to foreign outfits</a> - <strong>South China Morning Post</strong> reports - <em>&#8220;China&#8217;s decision to greenlight over 100 foreign-invested entities to pilot value-added telecommunications services (VAS) in the country could be a major boon for some multinationals, though its impact on the domestic market is likely to be limited, according to industry analysts.&#8221;</em></p></li></ul></li><li><p> AI</p><ul><li><p><a href="https://www.whitehouse.gov/presidential-actions/2026/06/national-security-presidential-memorandum-nspm-11/">National Security Presidential Memorandum/NSPM-11</a> - <strong>The White House</strong> (not me) publish - <em>&#8220;Under my Administration, the United States can and will responsibly accelerate the use of AI across intelligence and warfighting domains in line with American values. The United States possesses the most effective and moral military in the history of world. It is also among the most trusted institutions in American life. That trust is rooted in an unbroken chain of command and accountability, from our democratic process through civilian and military leadership, to the men and women who carry out the mission.&#8221;</em></p></li><li><p><a href="https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/opportunities-for-ai-in-cyber-defence">Opportunities for AI in cyber defence</a> - <strong>Australian Signals Directorate</strong> outlined in May - <em>&#8220;Human oversight, governance and <a href="https://www.cyber.gov.au/business-government/secure-design/secure-by-design">Secure by Design</a> practices remain essential. AI can significantly enhance cyber security, but it is not a replacement for strong cyber security fundamentals. Poorly designed or poorly governed AI systems can introduce new attack paths.&#8221;</em></p></li><li><p><a href="https://arxiv.org/abs/2606.07158">Synthetic APTs: the Collapse of TTP-Based Attribution</a> - <strong>Numerous parties</strong> outlines - <em>&#8220;We argue that in the AI era, wherein agents can be deployed provided the right models are available and subject to the right scaffolding and agentic configuration, the entry barrier for operating like a nation state APT collapses: beyond nation states, individuals can now act like commonly identified threat actors, and with it, fundamentally undermine TTP based attribution.&#8221;</em></p></li><li><p><a href="https://magic-box.dev/blog/patch-tuesday/">Patch Tuesday, Exploit Tuesday - Benchmarking n-day exploit generation</a>. - <strong>Josh Merill</strong> benchmarks - <em>&#8220;Time-to-exploit numbers are going down. The benchmarks need to exist in public so the defensive community can see what is coming and ship the corresponding mitigations, detections, and policies. Anthropic&#8217;s own exploit-evals piece made the call: &#8220;The field needs more work like ExploitBench and ExploitGym, across more vulnerability classes, more targets, and more stages of the cyber attack chain.&#8221; ndaybench is one attempt in that direction. The tedious work of moving each CVE from disclosure to a graded bench task is ongoing. Results when there is something worth showing.&#8221;</em></p></li><li><p><a href="https://www.documentcloud.org/documents/28202858-meta-ai-ag-maine/">Meta discovered that there was a vulnerability in an AI-assisted account recovery system for Instagram</a> -  <strong>Meta</strong> disclose - <em>&#8220;On May 31, 2026, Meta discovered that there was a vulnerability in an AI-assisted account recovery system for Instagram ("High Touch Support" or "HTS") that was exploited by unauthorized third parties to perform password resets on Instagram user accounts&#8221;</em></p></li><li><p><a href="https://www.nist.gov/news-events/news/2026/06/nist-mathematical-proof-supports-transition-continuous-monitor-and-update">NIST Mathematical Proof Supports Transition to a Continuous-Monitor-and-Update Security Model for AI Systems</a> - <strong>NIST</strong> outlines - <em>&#8220;A new proof shows that a fixed set of guardrails placed on AI is not universally robust against adaptive adversarial prompts.&#8221;</em></p></li><li><p><a href="https://www.digital.gov.au/policy/ai/agentic-ai-addendum">Agentic AI addendum to the AI technical standard for Australian Government </a>- <strong>Australian Government</strong> publish - <em>&#8220;This standard provides best practice guidance for Australian Government agencies implementing agentic AI. As an addendum to the <a href="https://www.digital.gov.au/policy/ai/AI-technical-standard">AI technical standard</a>, this standard highlights best practices key considerations for the secure and governed implementation of agentic AI systems.&#8220;</em></p></li></ul></li><li><p><em>Cyber proliferation</em></p><ul><li><p><a href="https://about.fb.com/news/2026/06/fighting-spyware-an-update-from-whatsapp/">Fighting Spyware: An Update From WhatsApp</a> - <strong>Meta</strong> update - <em>&#8220;WhatsApp caught and disrupted spear phishing attempts linked to NSO, a spyware firm blacklisted by the US government. Today, we&#8217;re asking the court to hold NSO in contempt for violating a permanent injunction that barred them from ever targeting WhatsApp and its users.&#8221;</em></p></li></ul></li><li><p>Bounty Hunting</p><ul><li><p><a href="https://www.justice.gov/opa/pr/justice-department-fbi-disable-13-websites-backed-suspected-chinese-agents-sought-sensitive">Justice Department, FBI Disable 13 Websites Backed by Suspected Chinese Agents That Sought Sensitive U.S. Information from Security Clearance Holders</a> - US <strong>Department of Justice</strong> announce - <em>&#8220;These domain seizures offer a glimpse at how foreign actors can use promises of easy money to lure Americans into revealing sensitive or classified information that they are duty&#8209;bound to protect,&#8221;</em></p></li><li><p><a href="https://www.reuters.com/legal/government/us-charges-suspected-russian-hacker-with-facilitating-cyber-campaign-2026-06-10/">US charges suspected Russian hacker with facilitating cyber campaign</a> - <strong>Reuters</strong> reports - <em>&#8220;A suspected Russian hacker is in U.S. custody after being extradited from Thailand and has &#8203;been charged with facilitating a campaign of cyberattacks carried out by a &#8204;Russia-aligned group that victimized numerous U.S. companies.&#8221;</em></p></li></ul></li><li><p>Market Incentives</p><ul><li><p><a href="https://www.legalcheek.com/2026/06/weil-reportedly-pays-up-to-20-million-after-hackers-steal-client-data/">Weil reportedly pays up to $20 million after hackers steal client data</a> - <strong>Legal Cheek</strong> reports - <em>&#8220;US firm Weil Gotshal is the latest law firm to fall victim to a cyber attack after it was reportedly forced to pay a ransom in the double-digit millions to prevent the publication of confidential client data. According to The Insurer (&#163;), Weil paid between $18 and $20 million (&#163;13 and &#163;15 million) to cyber extortion group Luna Moth, who threatened to publish stolen confidential client data to an external cloud storage site.&#8221;</em></p></li><li><p><a href="https://www.bloomberg.com/news/articles/2026-06-11/south-korea-fines-coupang-409-million-for-large-scale-data-leak">Korea Fines Coupang Record $409 Million for Data Breach</a> - <strong>Bloomberg</strong> reports - <em>&#8220;The Personal Information Protection Commission&#8217;s fine for Coupang Corp. &#8212; the company&#8217;s South Korean entity &#8212; is the biggest-ever levied by the country over a personal data breach. It easily surpasses the previous record of a 134.8 billion won penalty imposed on SK Telecom Co. just last year. Under Korean regulations, the regulator can impose fines of up to 3% of annual sales.&#8221;</em></p></li></ul></li></ul><p>Reflections this week are we really do need cyber security product vendors to be exemplars in secure by design including, among many other things, memory safety&#8230;</p><p>Not getting this via email? Subscribe:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Think someone else would benefit? Share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-june-fb9?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-june-fb9?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p><strong>All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.</strong></p><p>Have a lovely Saturday&#8230;</p><p>Ollie</p><h1>Cyber threat intelligence</h1><p>Who is doing what to whom and how allegedly.</p><h2>Reporting on Russia</h2><h3>APT28, an evolution of tradecraft</h3><p>Amaury G detail the evolution of this alleged Russian threat actor over the last 22 years. It also provides some insight into the longevity of some of the tooling and thus the value of developing detection tradecraft.</p><blockquote><p>Looking back at more than two decades of APT28 activity, what stands out is constant layering of tradecraft. The X-Agent / X-Tunnel stack that defined the intrusion-set between 2004 and 2018 was never fully retired: its code lineage resurfaces today in BeardShell and Slimagent, and its operational logic still drives Operation Phantom Net Voxel.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!WPVh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F280731fa-b4ee-4691-844b-4569b527747b_2560x1047.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!WPVh!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F280731fa-b4ee-4691-844b-4569b527747b_2560x1047.png 424w, /__u/substackcdn.com/image/fetch/$s_!WPVh!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F280731fa-b4ee-4691-844b-4569b527747b_2560x1047.png 848w, /__u/substackcdn.com/image/fetch/$s_!WPVh!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F280731fa-b4ee-4691-844b-4569b527747b_2560x1047.png 1272w, /__u/substackcdn.com/image/fetch/$s_!WPVh!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F280731fa-b4ee-4691-844b-4569b527747b_2560x1047.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!WPVh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F280731fa-b4ee-4691-844b-4569b527747b_2560x1047.png" width="1456" height="595" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/280731fa-b4ee-4691-844b-4569b527747b_2560x1047.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:595,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!WPVh!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F280731fa-b4ee-4691-844b-4569b527747b_2560x1047.png 424w, /__u/substackcdn.com/image/fetch/$s_!WPVh!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F280731fa-b4ee-4691-844b-4569b527747b_2560x1047.png 848w, /__u/substackcdn.com/image/fetch/$s_!WPVh!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F280731fa-b4ee-4691-844b-4569b527747b_2560x1047.png 1272w, /__u/substackcdn.com/image/fetch/$s_!WPVh!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F280731fa-b4ee-4691-844b-4569b527747b_2560x1047.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://blog.sekoia.io/apt28-an-evolution-of-tradecraft/">https://blog.sekoia.io/apt28-an-evolution-of-tradecraft/</a></p><h3>Old WinRAR Flaw Fuels Attacks on Ukraine</h3><p><strong>Hiroyuki Kakara</strong> and <strong>Feike Hacquebord</strong> detail both the use of this vulnerability by Russian threat actors whilst also identifying why it continues to remain effective due to update challenges. </p><blockquote><ul><li><p>CVE-2025-8088, a path traversal vulnerability in WinRAR patched in July 2025, is still being exploited by multiple intrusion sets targeting Ukraine, including an intrusion set we temporarily designated as SHADOW-EARTH-066 and Russia-aligned groups such as Earth Dahu (Gamaredon). At least until April 2026, both groups continued producing new exploit samples. Earth Dahu remains active at the time of writing.</p></li><li><p>SHADOW-EARTH-066, tracked by CERT-UA as <a href="https://cert.gov.ua/article/6282946">UAC-0226</a> since 2025, has deployed an updated version of its GIFTEDCROOK information stealer designed for rapid credential and document theft. The stealer harvests browser passwords, session cookies, and files matching 35 extensions.</p></li><li><p>The threat actor shifted from basic Excel macros with plaintext Telegram exfiltration to WinRAR exploit chains, in-memory DLL loading via direct NT system calls, and encrypted command-and-control (C&amp;C) infrastructure in under a year.</p></li><li><p>WinRAR is not covered by Group Policy or centralized update mechanisms. Software with these characteristics tends to remain exploitable long after patches are released, creating a persistent blind spot in organizational vulnerability management.</p></li></ul></blockquote><p><a href="https://www.trendmicro.com/en_us/research/26/f/old-winrar-flaw-fuels-attacks-on-ukraine.html">https://www.trendmicro.com/en_us/research/26/f/old-winrar-flaw-fuels-attacks-on-ukraine.html</a></p><h2>Reporting on China</h2><h3>Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation</h3><p><strong>Black Lotus Labs</strong> details the existence of the botnet but also how it is being used as a covert network alleged by a Chinese actor.</p><blockquote><ul><li><p>Black Lotus Labs has identified a resurgence and expansion of the JDY botnet, a covert network linked to Chinese nation-state-backed actors, including Volt Typhoon.</p></li><li><p>The JDY botnet comprises over 1,500 small office and home office (SOHO) and Internet of Things (IoT) devices. It operates as a centrally controlled, high-performance scanner used to discover, fingerprint and continuously map exposed services at scale.</p></li><li><p>The IoT-based malware affects a wider array of devices and feeds structured reconnaissance data into a larger scanning ecosystem for subsequent triage, target identification and exploitation.</p></li><li><p>JDY demonstrates how IoT and SOHO botnets and covert networks of compromised devices are being used for rapid vulnerability exploitation.</p></li><li><p>Black Lotus Labs recommends implementing recent U.K. National Cyber Security Centre (NCSC) guidance on defending against China-nexus covert networks of compromised devices.</p></li></ul><p>Since the initial disclosure, the JDY botnet surged to more than 1,500 compromised SOHO and IoT devices actively conducting targeted scanning and service fingerprinting. Analysis of this activity shows a clear focus on identifying vulnerable infrastructure shortly after public vulnerability disclosures, suggesting that reconnaissance output is rapidly operationalized by China-nexus advanced persistent threat (APT) actors. This targeted focus has been observed across a range of sectors, with the U.S. military and associated entities as the most prominent.</p></blockquote><p><a href="https://www.lumen.com/blog/en-us/expanded-jdy-iot-and-soho-botnet-enables-rapid-vulnerability-exploitation">https://www.lumen.com/blog/en-us/expanded-jdy-iot-and-soho-botnet-enables-rapid-vulnerability-exploitation</a></p><h3>Attack campaign against Japanese organizations using PoisonX driver</h3><p><strong>Yoshihiro Ishikawa</strong> details this alleged Chinese campaign which is interesting in that is is targeting Japanese as well as Chinese operations.</p><blockquote><p>During the attack, it was confirmed that a kernel driver called "PoisonX" and "10FXRAT (also known as PoisonX RAT)," which has remote control capabilities, were being exploited. Similar attack campaigns using 10FXRAT have been observed since May, and it is believed to be a continuous attack targeting not only Japanese organizations but also Chinese organizations. In the May attack campaign, a change in attack methods was observed, with BYOVD (Bring Your Own Vulnerable Driver) attacks being used, exploiting "EneIo64.sys" with a legitimate signature from ASUSTeK Computer and "procexp.sys" with a legitimate signature from Microsoft, instead of the conventional PoisonX driver. By using this BYOVD attack, attackers can obtain kernel-level privileges and perform a wide range of malicious operations, such as disabling security products and concealing malware.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!B2Cy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08a582e5-1529-41d7-9a59-9827f54b4d7f_800x355.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!B2Cy!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08a582e5-1529-41d7-9a59-9827f54b4d7f_800x355.png 424w, /__u/substackcdn.com/image/fetch/$s_!B2Cy!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08a582e5-1529-41d7-9a59-9827f54b4d7f_800x355.png 848w, /__u/substackcdn.com/image/fetch/$s_!B2Cy!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08a582e5-1529-41d7-9a59-9827f54b4d7f_800x355.png 1272w, /__u/substackcdn.com/image/fetch/$s_!B2Cy!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08a582e5-1529-41d7-9a59-9827f54b4d7f_800x355.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!B2Cy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08a582e5-1529-41d7-9a59-9827f54b4d7f_800x355.png" width="800" height="355" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/08a582e5-1529-41d7-9a59-9827f54b4d7f_800x355.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:355,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Attack Campaign Overview (LNK)&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Attack Campaign Overview (LNK)" title="Attack Campaign Overview (LNK)" srcset="/__u/substackcdn.com/image/fetch/$s_!B2Cy!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08a582e5-1529-41d7-9a59-9827f54b4d7f_800x355.png 424w, /__u/substackcdn.com/image/fetch/$s_!B2Cy!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08a582e5-1529-41d7-9a59-9827f54b4d7f_800x355.png 848w, /__u/substackcdn.com/image/fetch/$s_!B2Cy!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08a582e5-1529-41d7-9a59-9827f54b4d7f_800x355.png 1272w, /__u/substackcdn.com/image/fetch/$s_!B2Cy!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08a582e5-1529-41d7-9a59-9827f54b4d7f_800x355.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.lac.co.jp/lacwatch/report/20260604_004759.html">https://www.lac.co.jp/lacwatch/report/20260604_004759.html</a></p><h3>MUSTANG PANDA x PLUGX - Analysis of the January 2026 sample: a multi-layer execution chain</h3><p><strong>Nigmaz</strong> detail this alleged Chinese execution chain which is noteworthy for its attempt to avoid static detection which should be clocked by defence teams.</p><blockquote><p>At the initial stage, this chain impersonates an update process that downloads an MSI installer for a new version of a piece of software. After that, <code>Avk.exe</code> mainly acts as a launcher program: it performs <code>LoadLibrary</code> and calls the export <code>ModuleMain2</code>. <code>Avk.dll</code> acts as an intermediate loader, uses a hash-based API resolving mechanism, and contains only the minimum amount of logic needed to read, decrypt, and redirect execution to the next stage. Meanwhile, <code>AVKTray.dat</code> is not a data file but an encrypted payload that only plays its real role after being processed by the loader.</p><p>The notable point of this sample is not a single technique, but the way the entire execution chain is divided into many small layers, with each stage taking on a specific task: file dropping, persistence setup, DLL sideloading, payload decryption, manual mapping, and finally generating the configuration/C2 information used for network communication. This structure helps the malware reduce static detection indicators, limit clear strings/artifacts in each individual file, and slow down analysis if the entire execution chain is not followed.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!1oL-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c5ecde5-498c-43ad-921b-1756195e7be6_588x796.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!1oL-!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c5ecde5-498c-43ad-921b-1756195e7be6_588x796.png 424w, /__u/substackcdn.com/image/fetch/$s_!1oL-!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c5ecde5-498c-43ad-921b-1756195e7be6_588x796.png 848w, /__u/substackcdn.com/image/fetch/$s_!1oL-!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c5ecde5-498c-43ad-921b-1756195e7be6_588x796.png 1272w, /__u/substackcdn.com/image/fetch/$s_!1oL-!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c5ecde5-498c-43ad-921b-1756195e7be6_588x796.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!1oL-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c5ecde5-498c-43ad-921b-1756195e7be6_588x796.png" width="588" height="796" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2c5ecde5-498c-43ad-921b-1756195e7be6_588x796.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:796,&quot;width&quot;:588,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!1oL-!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c5ecde5-498c-43ad-921b-1756195e7be6_588x796.png 424w, /__u/substackcdn.com/image/fetch/$s_!1oL-!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c5ecde5-498c-43ad-921b-1756195e7be6_588x796.png 848w, /__u/substackcdn.com/image/fetch/$s_!1oL-!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c5ecde5-498c-43ad-921b-1756195e7be6_588x796.png 1272w, /__u/substackcdn.com/image/fetch/$s_!1oL-!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c5ecde5-498c-43ad-921b-1756195e7be6_588x796.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://bluecyber.hashnode.dev/mustang-panda-x-plugx-analysis-of-the-january-2026-sample-a-multi-layer-execution-chain">https://bluecyber.hashnode.dev/mustang-panda-x-plugx-analysis-of-the-january-2026-sample-a-multi-layer-execution-chain</a></p><h3>New China-Linked Cluster OP-512</h3><p><strong>Alexa Feminella</strong> links this cluster to alleged Chinese activity. Important for the use for AI to surface it and the second is the webshell centric nature. Keep an eye on those web servers..</p><blockquote><ul><li><p>[We] surfaced a suspected new China-linked espionage cluster, <strong>&#8220;OP-512,&#8221;</strong> by correlating a high volume of seemingly unrelated events at machine speed into one high-priority incident that our threat research experts then validated.</p></li><li><p>OP-512 deployed a custom web shell framework to a compromised Internet Information Services (IIS) server. Each deployment is cryptographically unique, making signature-based detection ineffective.</p></li><li><p>OP-512 is at least the fourth China-linked cluster documented targeting legacy IIS servers in the past year. Organizations running end-of-life .NET frameworks on internet-facing servers should prioritize migration or segmentation immediately.</p></li></ul><p>At the center of the operation is OP-512&#8217;s custom web shell framework, consisting of three web shells (malicious files that give attackers remote access through a web browser). This framework combines capabilities we rarely see together: Each deployment is uniquely generated, access is restricted to the attacker through cryptographic controls, and compromised servers automatically report back for centralized management at scale.</p></blockquote><p><a href="https://reliaquest.com/blog/threat-spotlight-reliaquests-agentic-ai-uncovers-new-china-linked-cluster-op-512">https://reliaquest.com/blog/threat-spotlight-reliaquests-agentic-ai-uncovers-new-china-linked-cluster-op-512</a></p><h3>Chinese Cybercrime Research</h3><p><strong>Princess Aurora J</strong> pulls together this collection which is interesting given the potential global implications for Chinese cybercrime.</p><blockquote><p>Resources to learn more about Chinese-language cybercrime actors.</p></blockquote><p><a href="https://github.com/princessauroraj/Chinese-Cybercrime-Research">https://github.com/princessauroraj/Chinese-Cybercrime-Research</a></p><h2>Reporting on North Korea</h2><h3>Don&#8217;t Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency</h3><p><strong>Saher Naumaan</strong> and <strong>Carlos Rubio</strong> detail an alleged North Korean operation which is noteworthy due to the continue pursuit of digital currency assets.</p><blockquote><ul><li><p>Between April and May 2026, Proofpoint Threat Research observed a likely North Korean threat actor conducting phishing campaigns using developer role recruitment or code review themes to targets in close to 100 organizations in finance, cryptocurrency, education, technology, and several other sectors. Proofpoint clusters this activity under the name UNK_DeadDrop.</p></li><li><p>The infection chain begins with emails containing links to actor-controlled GitHub repositories hosting malicious scripts that result in the execution of cross-platform malware for macOS, Linux, and Windows, including an open-source Go framework named Overlord.</p></li><li><p>The campaigns abused Visual Studio Code workflows and deployed a stealthy new technique using malicious Visual Studio Extensions (VSIX) that requires minimal user interaction.</p></li><li><p>The activity has similarities to another North Korean group called Contagious Interview; however, there is no direct overlap in Proofpoint telemetry so Proofpoint Threat Research tracks this activity as a distinct cluster.</p></li></ul></blockquote><p><a href="https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal">https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal</a></p><h3>Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace</h3><p><strong>Yeeth Security</strong> details the use of VS Code as a delivery mechanism for an alleged  North Korean operation. Further highlights the inherent challenges we collectively face around these eco-systems.</p><blockquote><p>It takes exactly one click to compromise an entire enterprise development pipeline. On June 8, 2026, <a href="https://yeethsecurity.com/#products">Argus</a> flagged <code>ByteBinTools.jupyter-powerdev-2026.6.8.vsix</code> from the VS Code marketplace. Yeeth Security researchers have unmasked the extension, a seemingly innocent Jupyter Notebook productivity tool, as a highly sophisticated, multi-stage backdoor meticulously engineered to bypass modern endpoint defenses. This malware is a masterclass in architectural evasion that heavily shadows elite North Korean (DPRK) state-sponsored tradecraft. The digital supply chain is no longer just a risk factor&#8212;it is the new frontline.</p><p>The extension contains the following components that overlap with techniques used by the Lazarus Group:</p><ul><li><p>A JavaScript layer that handles all Command-and-Control (C2) communication via Microsoft Graph API and SharePoint</p></li><li><p>Two platform-specific agents &#8212; a compiled <code>.exe</code> on Windows and a Python script for Linux and macOS &#8212; that perform code execution</p></li><li><p>A SharePoint site functioning as a command queue, victim registry, and exfiltration channel, accessed through Azure-hosted proxy brokers disguised as financial APIs</p></li><li><p>Arbitrary file read, write, and exfiltration capabilities as well as arbitrary code execution capabilities</p></li></ul></blockquote><p><a href="https://yeethsecurity.com/blog/2026-06-09-jupyter-powerdev-backdoor">https://yeethsecurity.com/blog/2026-06-09-jupyter-powerdev-backdoor</a></p><h2>Reporting on Iran</h2><p><em>Nothing overly of note this week</em></p><h2>Reporting on Other Actors</h2><h3>Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms</h3><p><strong>Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer</strong> and <strong>Tyler McLellan </strong>detail a criminal campaign which uses phone calls to facilitate initial access. How does your threat model stack up against that?</p><blockquote><p>From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as &#8220;Luna Moth,&#8221; &#8220;Chatty Spider,&#8221; and &#8220;Silent Ransom Group&#8221;) targeting dozens of organizations across professional, legal, and financial services in the United States.</p><p>UNC3753 leverages voice phishing (vishing) and social engineering deception techniques to achieve remote access into corporate environments. Using pretexts such as data migration or invoice related emails, the threat actors initiate phone conversations posing as IT support and convince targets to host screen-sharing sessions and download remote monitoring and management (RMM) utilities.</p></blockquote><p><a href="https://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firms/">https://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firms/</a></p><h3>Magecart skimmer turns Stripe into a malware command server</h3><p><strong>Sansec Forensics Team</strong> discover a rather novel way to do a web application level implant. This shows the challenges we face in ensuring the integrity of contemporary web applications in reality. </p><blockquote><p>[We] found a Magecart family that runs its skimmer straight out of Stripe. The attacker stores the card stealer in a Stripe customer's metadata and runs it on checkout pages, then writes stolen cards back into the same account as fake customers. Stripe is both the command server and the exfiltration sink, all behind a domain almost no store would block.</p></blockquote><p><a href="https://sansec.io/research/stripe-api-skimmer-infrastructure">https://sansec.io/research/stripe-api-skimmer-infrastructure</a></p><h3>The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy</h3><p><strong>Include Security</strong> reveal some of the inherent challenges from the SDK eco-system which are embedded in apps to provide third party data collection and/or services.</p><blockquote><p>Bright Data is a data-collection company that sells access to what it markets as the world&#8217;s largest residential proxy network of 400M+ home IP addresses that its customers route web-scraping traffic through. The supply behind that network comes from an SDK: a piece of software embedded in consumer apps that, with the user&#8217;s consent, turns their phone or smart TV into one of those exit nodes.</p></blockquote><p><a href="https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/">https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/</a></p><h3>Seven Years on a Public Clipboard: Pasted Secrets, T&#252;rkiye&#8217;s Exposure, and a Stored XSS</h3><p><strong>Beyondmemory Research</strong> gain access to what was put through a JSON beautifier with catastrophic security consequences. </p><blockquote><p>Seven years inside the public "Recent Links" feeds of a family of JSON and code "beautifier" tools. What engineers pasted; whose data it was; what the rise of the AI coding assistant changed; and what a Turkish data controller is supposed to do about the TCKNs and IBANs sitting on a stranger's server right now. And the part we did not go looking for: the formatter itself carries a stored cross-site-scripting flaw, so the service holding all of this data can be made to run an attacker's code in your browser.</p></blockquote><p><a href="https://beyondmemory.io/blog/json-formatter-data-exposure">https://beyondmemory.io/blog/json-formatter-data-exposure</a></p><h3>WeedHack &#8211; The Rise of Minecraft Malware-as-a-Service Campaigns</h3><p><strong>Aayush Tyagi</strong> gives a sense of what an aggressive integrated criminal campaign looks like in 2026 along with what it is able to achieve in terms of penetration. The search engines can and should address this.</p><blockquote><ul><li><p>&#8216;Weedhack&#8217; has been active since January 2026 and masquerades as genuine Minecraft clients and mods to infect users.</p></li><li><p>We&#8217;ve discovered over 3820 unique malicious JAR files that are part of this attack and over 240 URLs responsible for distributing this malware.</p></li><li><p>This campaign utilizes SEO poisoning and YouTube to generate traffic to these malicious URLs. We also found two YouTube channels and multiple videos that demonstrate Minecraft Mods and Clients and redirect viewers to these URLs.</p></li><li><p>The campaign has accumulated a total of 116,464 hits, averaging approximately 2000 to 3,000 hits per day.</p></li><li><p>The campaign provides an enterprise-grade dashboard that allows customers to view stolen credentials and system information, download the payload, configure notifications, access tutorials, and remotely monitor their victims.</p></li></ul></blockquote><p><a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/weedhack-minecraft-malware-as-a-service-campaign-research/">https://www.mcafee.com/blogs/other-blogs/mcafee-labs/weedhack-minecraft-malware-as-a-service-campaign-research/</a></p><h3>From Crypto Wallets to a 100M-User VPN: Inside an Active STX RAT Supply Chain Campaign</h3><p><strong>Reegun Jayapaul</strong> and <strong>Rahul Ramesh</strong> detail another integrated and planned campaign intended to go after cryptocurrency assets.</p><blockquote><p>A threat actor spent one month building a trojanized software supply chain aimed at a specific type of victim: crypto traders and investors. The lure selection was deliberate: Binance, MEXC, Bybit, Exodus, MetaTrader 5. Each is software used by people likely holding exchange credentials and financial account access.</p></blockquote><p><a href="https://www.cyderes.com/howler-cell/cpuid-hwmonitor-xvpn-dll-sideloading-stx-rat">https://www.cyderes.com/howler-cell/cpuid-hwmonitor-xvpn-dll-sideloading-stx-rat</a></p><h3>Software Supply Chain Incursions</h3><p>A reminder we issued guidance last week in <a href="https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies">Software supply chain attacks: check your dependencies</a>.</p><ul><li><p><a href="https://www.stepsecurity.io/blog/binding-gyp-npm-supply-chain-attack-spreads-like-worm">Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp</a></p></li><li><p><a href="https://www.ox.security/blog/six-stages-deep-and-an-endless-loop-shai-hulud-is-getting-sophisticated/">Six Stages Deep and an Endless Loop: Shai-Hulud Is Getting Sophisticated</a></p></li><li><p><a href="https://haltingproblems.com/analysis/hades-cluster-pypi-startup-hook-compromise/">Hades Cluster PyPI Worm Abuses Python Startup Hooks</a></p></li><li><p><a href="https://helm.sh/blog/security-notice-baltocdn/">Security Notice: Former Helm APT Mirror Domain `baltocdn.com` Statement</a></p></li></ul><h1>Discovery</h1><p>How we find and understand the latent compromises within our environments.</p><h2>CQL-Hub | CrowdStrike SIEM &amp; LogScale Queries</h2><p><strong>Adrian Polacek</strong> and <strong>Daniel Wei&#223;bacher</strong> curate this resource which will be of use to blue teams.</p><blockquote><p>A free, community-driven hub for CrowdStrike Falcon SIEM queries.<br>All queries stored here are automatically published and made visible on the CQL-Hub website, making it easier for everyone to discover, share, and use detection and hunting queries.</p></blockquote><p><a href="https://github.com/ByteRay-Labs/Query-Hub">https://github.com/ByteRay-Labs/Query-Hub</a></p><h2>Detecting Misuse with the Claude Compliance API: The Threat Is in the Content</h2><p>Andrew Byford details how you can detect misuse through the Claude compliance API. This is an excellent demonstration on how to integrate the new world attack surfaces into the traditional observability. </p><blockquote><p>In this post I explore what detections you can already use in your SIEM by ingesting Claude Compliance API logs. Then we go even further, introducing a prefilter and LLM judge pipeline which lets you write detections for real AI threats that live inside message content</p></blockquote><p><a href="https://www.papermtn.co.uk/detecting-misuse-with-the-claude-compliance-api-the-threat-is-in-the-content/">https://www.papermtn.co.uk/detecting-misuse-with-the-claude-compliance-api-the-threat-is-in-the-content/</a></p><h2>Adversarially Robust Living-off-the-Land Reverse-Shell Detection</h2><p><strong>Dmitrijs Trizna, Luca Demetrio, Battista Biggio</strong> and <strong>Fabio Roli</strong> release this detection super power.</p><blockquote><ol><li><p>No public ML-based SIEM detectors &#8212; we release the first production-ready, openly licensed ML models for LOTL reverse-shell detection.</p></li><li><p>Adversarial fragility &#8212; we evaluate models under evasion and poisoning attacks, and provide adversarially-trained checkpoints that survive all tested attacks.</p></li></ol></blockquote><p><a href="https://github.com/dtrizna/QuasarNix">https://github.com/dtrizna/QuasarNix</a></p><h2>Microsoft Defender now monitors RPC activity</h2><p><strong>Edan Zwick</strong> details these changes which will facilitate the detection of a range of activity including lateral movement.</p><blockquote><p>To enable efficient auditing of remote RPC activity regardless of transport-layer protection, Defender research and engineering expanded the existing RPC integration with the Windows Filtering Platform (WFP) to support OpNum-level granularity. This makes it possible to identify and audit the specific RPC function being invoked, rather than only the RPC interface.</p><p>This capability is designed to help detect remote RPC-based attack techniques, where an attacker interacts with RPC interfaces exposed by a target device. For that reason, Defender focuses this monitoring on inbound remote RPC calls observed on the RPC server host. The telemetry is collected using audit-only WFP filters, which do not interfere with normal traffic, while still providing visibility into suspicious remote activity targeting the device. This approach does not require visibility into the source device.</p></blockquote><p><a href="https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/microsoft-defender-now-monitors-rpc-activity/4523368">https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/microsoft-defender-now-monitors-rpc-activity/4523368</a></p><h2>From Exploit Code to Production Detection: Building a CVE-2026-31431 (Copy Fail) detection with Agents</h2><p><strong>Ryan Simon</strong> publishes a useful summary both showing how AI was used as a productivity enhancer as well how they developed detections for this particular pervasive vulnerability. </p><blockquote><p>This post walks through the exploit mechanics and looks back at how Datadog Security Research used coding agents to compress the full detection engineering cycle into a single session, from initial threat analysis to shipped detections, in hours.</p></blockquote><p><a href="https://securitylabs.datadoghq.com/articles/cve-2026-31431-copy-fail-exploit-detection-with-agents/">https://securitylabs.datadoghq.com/articles/cve-2026-31431-copy-fail-exploit-detection-with-agents/</a></p><h2>About ETW Internals: Architecture, Hooking, Tampering, and Detection</h2><p><strong>Kernullist</strong> walks through soup to nuts how ETW works which will be of interest and use to some.</p><blockquote><p>start with the threat model, go down into the machinery, then come back up into detection architecture. The point is not to memorize every field. The point is to know which layer should carry truth when another layer starts lying.</p></blockquote><p><a href="https://kernullist.github.io/kernullist-blog/posts/etw-internals-deep-dive/">https://kernullist.github.io/kernullist-blog/posts/etw-internals-deep-dive/</a></p><h2>Covert Kernel/User Communication Channels on Windows: Rootkits, Game Cheats, and Detection</h2><p><strong>Kernullist</strong> walks through how to detect such covert channels.. </p><blockquote><p>Use a layered strategy:</p><ol><li><p><em>Inventory</em> the normal communication surfaces at boot and at protected workload launch: device objects and IOCTL paths, sections, ALPC ports, named pipes, RPC endpoints, COM local servers, named objects, WNF state names, Filter Manager communication ports, WFP providers / callouts, virtual HID stacks, Cloud Files / ProjFS provider roots, I/O rings, CLFS logs, and transaction-backed file/registry activity.</p></li><li><p><em>Baseline</em> the high-risk kernel pointers (<code>HalPrivateDispatchTable</code>, <code>ObTypeIndexTable</code>, callback arrays, dispatch tables) under known-clean conditions.</p></li><li><p><em>Correlate</em> cross-layer behavior. A suspicious callback plus a suspicious user-mode mapping is stronger than either signal alone.</p></li><li><p><em>Treat unknown signed drivers as untrusted</em> until their objects, callbacks, sections, and memory mappings are accounted for.</p></li><li><p><em>Prefer version-aware parsers</em> and symbol-backed validation over hard-coded offsets. The most common reason a production detector regresses is not a missed technique: it is a Windows build that shifted a structure by 8 bytes.</p></li></ol></blockquote><p><a href="https://kernullist.github.io/kernullist-blog/posts/covert-kernel-user-communication-channels-on-windows/">https://kernullist.github.io/kernullist-blog/posts/covert-kernel-user-communication-channels-on-windows/</a></p><h1>Defence</h1><p>How we proactively defend our environments.</p><h2>Visual Studio Code Delay Extension Updates</h2><p><strong>Microsoft</strong> makes some modifications to try and reduce the impact from being used as an initial entry method.</p><blockquote><p>VS Code now applies a two-hour delay before automatically updating extensions to a newly published version. When automatic updates are enabled, new versions are auto-updated two hours after they are published, adding an extra layer of protection against problematic or potentially compromised releases.</p><p>This never gets in your way, as you can still update any extension immediately at any time by using the <strong>Update</strong> button. While an update is waiting, the extension&#8217;s details view explains why it hasn&#8217;t updated yet and when the automatic update will happen.</p><p><strong>Note</strong>: This delay does not apply to extensions from trusted publishers such as Microsoft, GitHub, and OpenAI. These extensions continue to update immediately.</p></blockquote><p><a href="https://code.visualstudio.com/updates/v1_123#_delayed-extension-autoupdates">https://code.visualstudio.com/updates/v1_123#_delayed-extension-autoupdates</a></p><h2>The Privileged Roles Nobody Talks About</h2><p><strong>Carlos Perez</strong> highlights both an important fact but also provides some practical steps on how to secure.</p><blockquote><p>Why Your MDM Platform is a Tier 0 Asset</p><p>his post covers what we have seen in real world attacks as well as attack paths our Pentest Team has leveraged, why platform administration roles are systematically underprotected</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!O9dt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7695397c-618f-49d3-ba36-db05b5d25bd8_1919x843.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!O9dt!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7695397c-618f-49d3-ba36-db05b5d25bd8_1919x843.webp 424w, /__u/substackcdn.com/image/fetch/$s_!O9dt!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7695397c-618f-49d3-ba36-db05b5d25bd8_1919x843.webp 848w, /__u/substackcdn.com/image/fetch/$s_!O9dt!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7695397c-618f-49d3-ba36-db05b5d25bd8_1919x843.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!O9dt!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7695397c-618f-49d3-ba36-db05b5d25bd8_1919x843.webp 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!O9dt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7695397c-618f-49d3-ba36-db05b5d25bd8_1919x843.webp" width="1456" height="640" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7695397c-618f-49d3-ba36-db05b5d25bd8_1919x843.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:640,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!O9dt!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7695397c-618f-49d3-ba36-db05b5d25bd8_1919x843.webp 424w, /__u/substackcdn.com/image/fetch/$s_!O9dt!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7695397c-618f-49d3-ba36-db05b5d25bd8_1919x843.webp 848w, /__u/substackcdn.com/image/fetch/$s_!O9dt!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7695397c-618f-49d3-ba36-db05b5d25bd8_1919x843.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!O9dt!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7695397c-618f-49d3-ba36-db05b5d25bd8_1919x843.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://trustedsec.com/blog/the-privileged-roles-nobody-talks-about">https://trustedsec.com/blog/the-privileged-roles-nobody-talks-about</a></p><p>This is followed by <strong>Hardening Intune: The Implementation Guide</strong></p><p><a href="https://trustedsec.com/blog/hardening-intune-the-implementation-guide">https://trustedsec.com/blog/hardening-intune-the-implementation-guide</a></p><h1>Incident Writeups &amp; Disclosures</h1><p>How they got in and what they did.</p><h2>Meta discovered that there was a vulnerability in an AI-assisted account recovery system for Instagram</h2><p><strong>Meta</strong> detail..</p><blockquote><p>On May 31, 2026, Meta discovered that there was a vulnerability in an AI-assisted account recovery system for Instagram ("High Touch Support" or "HTS") that was exploited by unauthorized third parties to perform password resets on Instagram user accounts.</p><p>HTS is an AI-assisted support tool designed to help users who are locked out of their Instagram accounts regain access. Users can request support from HTS and, as part of that process, can ask that a password reset link be sent to their email address. The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user&#8217;s Instagram account. As a result, when an individual provided an email address not previously associated with the account, the system incorrectly sent a password reset link to that unassociated email rather than rejecting the request. This allowed unauthorized third parties to receive a password reset link for accounts they did not own. Upon resetting the password, the unauthorized party was able to log in to the account if the account holder had not enabled two-factor authentication (2FA).</p></blockquote><p><a href="https://www.documentcloud.org/documents/28202858-meta-ai-ag-maine/">https://www.documentcloud.org/documents/28202858-meta-ai-ag-maine/</a></p><h1>Vulnerability</h1><p>Our attack surface.</p><h2>More Evidence That Words Don&#8217;t Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520)</h2><p><strong>Sonny</strong> tears these vulnerabilities down&#8230;</p><blockquote><p>Today&#8217;s advisory outlines two vulnerabilities in Ivanti&#8217;s Sentry product, appealing directly to our inner desire for sophisticated server-side, pre-authenticated vulnerabilities.</p><p><strong>CVE-2026-10520</strong></p><ul><li><p>An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution (Credit to Unknown, but not us)</p></li></ul><p><strong>CVE-2026-10523</strong></p><ul><li><p>An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access (Credit to Bryan Lam)</p></li></ul></blockquote><p><a href="https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/">https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/</a></p><h2>Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751)</h2><p><strong>McCaulay Hudson</strong> releases the exploit which all should prepare for at scale use of..</p><blockquote><p>This watchTowr Detection Artefact Generator checks for, and demonstrates, the Check Point Remote Access VPN / Mobile Access authentication bypass CVE-2026-50751 (CVSS 9.3, CWE-287). A remote, unauthenticated attacker can complete the deprecated IKEv1 phase-1 exchange and be authenticated as a provisioned Remote Access user without a valid certificate, private key, or password. It works over both IKE (UDP 500/4500) and Check Point Visitor Mode / SSL (raw TCP 443, TCPT).</p></blockquote><p><a href="https://labs.watchtowr.com/marking-your-own-homework-check-point-remote-access-vpn-ikev1-authentication-bypass-cve-2026-50751/">https://labs.watchtowr.com/marking-your-own-homework-check-point-remote-access-vpn-ikev1-authentication-bypass-cve-2026-50751/</a></p><p><a href="https://github.com/watchtowrlabs/watchTowr-vs-Check-Point-CVE-2026-50751?ref=labs.watchtowr.com">https://github.com/watchtowrlabs/watchTowr-vs-Check-Point-CVE-2026-50751?ref=labs.watchtowr.com</a></p><h2>Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE)</h2><p><strong>Piotr Bazydlo</strong> details this vulnerability at the very core of cyber defence.. patch patch patch..</p><blockquote><p>It has everything that we love:</p><ul><li><p>No authentication requirements,</p></li><li><p>An almost full-mark CVSS score,</p></li><li><p>Claims to be a security product,</p></li><li><p>Vulnerability name longer than the average piece of spaghetti.</p></li></ul></blockquote><p><a href="https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/">https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/</a></p><h2>GreatXML a bitlocker that seems to only work if you ever had Defender Offline Scan</h2><p><strong>Nightmare Eclipse</strong> details this vulnerability..</p><blockquote><p>If you ever attempted to use Windows Defender Offline Scan, you're automatically vulnerable to a bitlocker bypass. I'm unsure if you can still trigger the bug without ever using the offline scan feature, because you can definitely</p></blockquote><p><a href="https://deadeclipse666.blogspot.com/2026/06/greatxml-bitlocker-that-seems-to-only.html?m=1">https://deadeclipse666.blogspot.com/2026/06/greatxml-bitlocker-that-seems-to-only.html?m=1</a></p><p><a href="https://github.com/MSNightmare/GreatXML">https://github.com/MSNightmare/GreatXML</a></p><h2>Pwnd Blaster: Hacking your PC using your speaker without ever touching it</h2><p><strong>Rasmus Moorats</strong> does some exquisite work here..</p><blockquote><p>What initially started as simply wanting to write a Linux tool for communicating with my speaker ended up with me discovering vulnerabilities which allow any attacker within a ~15M range of any Katana V2X to turn it into a covert spying tool and Rubber Ducky - all without ever having to pair with or physically touch the device.</p></blockquote><p><a href="https://blog.nns.ee/2026/06/03/katana-badusb/">https://blog.nns.ee/2026/06/03/katana-badusb/</a></p><h2>RoguePlanet</h2><p><strong>Nightmare Eclipse</strong> drops this vulnerability which detection teams will want to ensure coverage of.</p><blockquote><p>The exploit is a race condition, so it&#8217;s a hit or miss. I have managed to get a 100% success rate on some machines while it struggled to work on others.</p><p>The exploit has been tested in Windows 11 (Official channel + Canary) and Windows 10 with june 2026 patch installed. The PoC however does not work in Windows Server since standard users cannot mount an ISO image, I&#8217;m confident that all Windows Server versions are vulnerable as well but by the time I figured out it that the PoC doesn&#8217;t work in Windows Server installations, it was a too late to redesign the exploit to overcome this issue. But I want to make one thing very clear. All Windows Server installations are vulnerable as well, you just need to redesign the exploit.</p></blockquote><p><a href="https://github.com/MSNightmare/RoguePlanet">https://github.com/MSNightmare/RoguePlanet</a></p><h2>Second-Order OS Command Injection via JSON Input on start vnc feature</h2><p><strong>Fortinet</strong> discloses..</p><blockquote><p>An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.</p></blockquote><p><a href="https://www.fortiguard.com/psirt/FG-IR-26-141">https://www.fortiguard.com/psirt/FG-IR-26-141</a></p><h2>Restricted CLI escape using Lua</h2><p><strong>Fortinet</strong> discloses and give high five..</p><blockquote><p>An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] in FortiOS and FortiProxy may allow an authenticated admin to execute lua scripts via crafted CLI commands.</p><p>..</p><p>Fortinet is pleased to thank The UK&#8217;s National Cyber Security Centre (NCSC) for reporting this vulnerability under responsible disclosure.</p></blockquote><p><a href="https://www.fortiguard.com/psirt/FG-IR-26-143">https://www.fortiguard.com/psirt/FG-IR-26-143</a></p><h1>Offense</h1><p>Attack capability, techniques and trade-craft. </p><h2>EDRChoker</h2><p><strong>Two Seven One Three</strong> details this technique which again shows the value of true signal going through systems to ensure they have not been degraded.</p><blockquote><p>EDRChoker uses <strong>Policy-based Quality of Service (QoS)</strong> to set hard bandwidth caps (throttling) on Endpoint Detection and Response (EDR) agents, causing them to always time out - effectively blocking them.</p></blockquote><p><a href="https://github.com/TwoSevenOneT/EDRChoker">https://github.com/TwoSevenOneT/EDRChoker</a></p><h2>DCOMIllusionist</h2><p><strong>Hugow Vincent</strong> weaponizes this capability which teams will want to ensure detection coverage of.</p><blockquote><p>This tool enables remote code execution on a Windows machine, if you have administrative privileges. It leverages DCOM and the behavior of .NET DCOM servers, which automatically deserialize incoming objects. This makes it possible to execute arbitrary commands or load DLLs without writing to disk.</p></blockquote><p><a href="https://github.com/synacktiv/DCOMIllusionist">https://github.com/synacktiv/DCOMIllusionist</a></p><h2>Enter the WasmForge: Compiling Sliver into WebAssembly</h2><p><strong>Michael Weber</strong> releases this capability which teams will likely find tricky to detect reliably but where effort should be spent.</p><blockquote><p>WasmForge is, from the user&#8217;s perspective, a build wrapper. You point it at a Go project and you get back a Windows or macOS binary that runs your tool but doesn&#8217;t look anything like it. Internally it&#8217;s a lot more. It&#8217;s a Go-to-WebAssembly compiler, a custom <a href="https://github.com/tetratelabs/wazero">Wazero</a> fork, around eighty host shim functions for MacOS and Windows APIs, and a healthy amount of evasion techniques from our previously discussed skill. The whole pipeline exists to solve one specific problem: take an existing offensive security tool, change <em>zero lines</em> of its source code, and produce a binary you can actually drop on a hardened endpoint.</p></blockquote><p><a href="https://www.praetorian.com/blog/wasmforge-sliver-webassembly/">https://www.praetorian.com/blog/wasmforge-sliver-webassembly/</a></p><h2>BusyWork: Replacing Sleep with Real Work to Break Behavioral Detection</h2><p><strong>Patch Request</strong> has an An LLM detail. Irrespective a clever technique which detection teams will want to ponder.</p><blockquote><p>This post covers <a href="https://github.com/PatchRequest/BusyWork">BusyWork</a>, a Rust library that replaces <code>sleep()</code> calls with real, varied work. Malware and game cheats commonly use sleep loops to pace their activity, but sleeping is a behavioral signal that EDR products and anti-cheat engines detect. A thread that allocates memory, calls a few APIs, then sleeps for exactly 5 seconds, 10 times in a row, stands out in telemetry. BusyWork replaces the sleep with randomized task execution across seven categories, so each &#8220;pause&#8221; looks like genuine application activity: hashing data, enumerating files, querying the registry, making DNS lookups, or allocating and sorting memory.</p></blockquote><p><a href="https://patchi.fyi/blog/busywork-sleep-replacement/">https://patchi.fyi/blog/busywork-sleep-replacement/</a></p><h2>Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025</h2><p><strong>Justin Kalnasy</strong> details another channel to ensure coverage of..</p><blockquote><p>New native AI features in Microsoft SQL Server 2025 provide a practical channel for data exfiltration and C2 transport within the database engine itself.</p></blockquote><p><a href="https://specterops.io/blog/2026/06/10/oops-i-weaponized-the-database-abusing-ai-features-in-mssql-2025/">https://specterops.io/blog/2026/06/10/oops-i-weaponized-the-database-abusing-ai-features-in-mssql-2025/</a></p><h2>Whoops! I did it again. I patched Windows Kernel at Milan0day 2026</h2><p><strong>zer0matt</strong> shows some clever tricks to do this ephemerally and avoid patch guard..</p><blockquote><p>This post focuses specifically on the AV/EDR killing technique shown during the demo, explaining how a vulnerable driver can be leveraged to temporarily patch kernel structures and redirect execution flow inside the Windows kernel.</p></blockquote><p><a href="https://zer0matt.blogspot.com/2026/05/whoops-i-did-it-again-i-patched-windows.html">https://zer0matt.blogspot.com/2026/05/whoops-i-did-it-again-i-patched-windows.html</a></p><h2>Async PICOs and Custom Beacon Wakeups in Cobalt Strike</h2><p><strong>Marcos Gonzalez Hermida</strong> details how evasion techniques which detection teams will want at the very least to be aware of.</p><blockquote><p>If we reduce Outflank&#8217;s asynchronous BOF model to its bare essentials, the design revolves around three minimum requirements:</p><ul><li><p>An Async BOF must be able to start and stop cleanly</p></li><li><p>It must execute independently in another thread or thread pool inside the beacon&#8217;s process</p></li><li><p>It must be able to send output back to the operator immediately and wake the beacon when necessary</p></li></ul><p>We ultimately arrived at an asynchronous execution layer for Cobalt Strike that could run Async PICOs in Beacon&#8217;s process, let operators manage their state, and safely wake Beacon to print output. The rest of this post explains how we arrived there. The sections that follow walk through the three problems in the order we encountered them during development and how they shaped the final implementation: how to start code that can execute from an arbitrary memory location, how to track running tasks without losing shared state, and how to safely print output from a background thread without destabilizing Beacon.</p></blockquote><p><a href="https://www.nccgroup.com/research/async-picos-and-custom-beacon-wakeups-in-cobalt-strike/">https://www.nccgroup.com/research/async-picos-and-custom-beacon-wakeups-in-cobalt-strike/</a></p><h2>Trend Micro Deep Security Agent Research: Forcing bmhook/tmhook Reloads to Open a Protection Bypass Window</h2><p><strong>MatheuZ</strong> details how to shape the behaviour of a security product in order to achieve their objective.</p><blockquote><p>The finding is not remote code execution and it is not a persistent kill switch. It is a forced security-control gap. A local unprivileged event storm can make the agent unload and reload its own behavior-monitoring kernel modules. During that window, protection behavior changes, and an artifact that was normally blocked was written to disk successfully.</p></blockquote><p><a href="https://matheuzsecurity.github.io/hacking/trendmicro-bmhook-tmhook-reload-bypass/">https://matheuzsecurity.github.io/hacking/trendmicro-bmhook-tmhook-reload-bypass/</a></p><h1>Exploitation</h1><p>What is being exploited..</p><h2>Security Advisory &#8211; Action Required &#8211; Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)</h2><p><strong>Check Point</strong> warns..</p><blockquote><p>To date, the observed exploitation has been limited to a few dozen targeted organizations globally. One case involved confirmed post-compromise activity associated with Qilin ransomware affiliate.</p></blockquote><p><a href="https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/">https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/</a></p><h2>Active Exploitation of PAN-OS CVE-2026-0257</h2><p><strong>Palo Alto Networks</strong> warns..</p><blockquote><p>Palo Alto Networks Unit 42 has observed active exploitation of PAN-OS vulnerability <a href="https://security.paloaltonetworks.com/CVE-2026-0257">CVE-2026-0257</a> by an unidentified threat actor attempting to access GlobalProtect. This security flaw involves an authentication bypass in the portal and gateway components of vulnerable versions of PAN-OS<sup>&#174;</sup> software, which could allow unauthorized attackers to circumvent security controls and initiate VPN connections.</p></blockquote><p><a href="https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/">https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/</a></p><h2>Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability</h2><p><strong>Cisco</strong> warns of exploitations of this vulnerability..</p><blockquote><p>A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as <em>root</em> by supplying a crafted file to the affected system.</p><p>..</p><p>In June 2026, the Cisco PSIRT became aware of exploitation of this vulnerability.</p></blockquote><p><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx</a></p><h2>ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit</h2><p><strong>Mandiant</strong> detail exploitation of this vulnerability..</p><blockquote><p>[We] have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of <a href="https://www.oracle.com/security-alerts/alert-cve-2026-35273.html">CVE-2026-35273</a>, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component. The exploitation of this vulnerability directly aligns with the observed targeting of Environment Management Hub (PSEMHUB) endpoints. Because this activity predates Oracle's June 10, 2026 advisory, the vulnerability was exploited as a zero-day.</p></blockquote><p><a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit">https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit</a></p><h1>Tooling and Techniques</h1><p>Low level tooling and techniques for attack and defence researchers</p><h2>Building a safe, effective sandbox to enable Codex on Windows</h2><p><strong>David Wiesen</strong> details their approach..</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!LN5X!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75f99a81-1bca-4d9b-9de3-4d61355c2092_1010x554.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!LN5X!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75f99a81-1bca-4d9b-9de3-4d61355c2092_1010x554.svg 424w, /__u/substackcdn.com/image/fetch/$s_!LN5X!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75f99a81-1bca-4d9b-9de3-4d61355c2092_1010x554.svg 848w, /__u/substackcdn.com/image/fetch/$s_!LN5X!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75f99a81-1bca-4d9b-9de3-4d61355c2092_1010x554.svg 1272w, /__u/substackcdn.com/image/fetch/$s_!LN5X!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75f99a81-1bca-4d9b-9de3-4d61355c2092_1010x554.svg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!LN5X!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75f99a81-1bca-4d9b-9de3-4d61355c2092_1010x554.svg" width="1456" height="799" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/75f99a81-1bca-4d9b-9de3-4d61355c2092_1010x554.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:799,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Diagram showing Codex sandbox operating-system isolation boundaries.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Diagram showing Codex sandbox operating-system isolation boundaries." title="Diagram showing Codex sandbox operating-system isolation boundaries." srcset="/__u/substackcdn.com/image/fetch/$s_!LN5X!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75f99a81-1bca-4d9b-9de3-4d61355c2092_1010x554.svg 424w, /__u/substackcdn.com/image/fetch/$s_!LN5X!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75f99a81-1bca-4d9b-9de3-4d61355c2092_1010x554.svg 848w, /__u/substackcdn.com/image/fetch/$s_!LN5X!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75f99a81-1bca-4d9b-9de3-4d61355c2092_1010x554.svg 1272w, /__u/substackcdn.com/image/fetch/$s_!LN5X!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75f99a81-1bca-4d9b-9de3-4d61355c2092_1010x554.svg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://openai.com/index/building-codex-windows-sandbox/">https://openai.com/index/building-codex-windows-sandbox/</a></p><h2>About PCIe DMA Cheats: Protocol, IOMMU, Hardware, and Detection</h2><p><strong>Kernullist</strong> walks through.. </p><blockquote><p>External DMA cheats are the hardest game-cheating threat to defend against, because the cheat code does not live on the machine running the game. The &#8220;victim&#8221; PC sees only a passive-looking PCIe endpoint while a second PC, connected to that endpoint, reads game state at line rate and feeds it into an aimbot or wallhack. Conventional anti-cheat techniques &#8212; syscall hooks, memory scanners, code-integrity checks &#8212; cannot find what is not there. Detection has to move down the stack, into the PCIe protocol itself, into the IOMMU, and ultimately to external trust anchors. This is a technical walk through that stack from a defender&#8217;s perspective.</p></blockquote><p><a href="https://kernullist.github.io/kernullist-blog/posts/pcie-dma-cheats/">https://kernullist.github.io/kernullist-blog/posts/pcie-dma-cheats/</a></p><h1>Footnotes</h1><p>Some other small (and not so small) bits and bobs which might be of interest.</p><ul><li><p>Annual, quarterly and monthly reports</p><ul><li><p><em>Nothing overly of note this week, but keep an eye on</em> <a href="https://github.com/jacobdjwilson/awesome-annual-security-reports/tree/main/Annual%20Security%20Reports/2026">the Awesome Annual Security Reports 2026 collection</a></p></li></ul></li><li><p><a href="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/">Factoring &#8220;short-sleeve&#8221; RSA keys with polynomials</a></p></li><li><p><a href="https://link.springer.com/article/10.1007/s11896-026-09809-2">Ongoing Exposure to Distressing Material is Associated with Worsening Mental Health in UK Law Enforcement Staff: a Longitudinal Interview Study</a></p></li><li><p><a href="https://www.army.mil/article/293021/quantum_sensor_breakthrough_could_transform_army_battlefield_signal_detection">Quantum sensor breakthrough could transform Army battlefield signal detection</a></p></li><li><p><a href="https://encryptedspaces.org/">Encrypted Spaces: An architecture for collaborative applications where data is encrypted and operations are cryptographically verifiable.</a></p></li><li><p><a href="https://blog.bushidotoken.net/2026/05/uk-cybercrime-journal-british.html">British Universities Struck by ShinyHunters Before Exam Season</a></p></li><li><p>Artificial intelligence</p><ul><li><p>Fundamental</p><ul><li><p><a href="https://arxiv.org/abs/2606.03237">Solipsistic Superintelligence is Unlikely to be Cooperative</a></p></li></ul></li><li><p>Applied non-cyber</p><ul><li><p><a href="https://arxiv.org/abs/2606.12835">The Internet of Agentic AI: Communication, Coordination, and Collective Intelligence at Scale</a></p></li></ul></li><li><p>Applied cyber specific</p><ul><li><p><a href="https://arxiv.org/abs/2604.20801">Synthesizing Multi-Agent Harnesses for Vulnerability Discovery</a></p></li><li><p><a href="https://github.com/dtrizna/QuasarNix">QuasarNix: Adversarially Robust Living-off-the-Land Reverse-Shell Detection</a></p></li><li><p><a href="https://arxiv.org/abs/2606.07158">Synthetic APTs: the Collapse of TTP-Based Attribution</a></p></li><li><p><a href="https://magic-box.dev/blog/patch-tuesday/">Benchmarking n-day exploit generation.</a></p></li><li><p><a href="https://arxiv.org/abs/2606.13079">The Emergence of Autonomous Penetration Capabilities in Large Language Model-Powered AI Systems</a></p></li><li><p><a href="https://arxiv.org/abs/2606.11022">When Discovery Outpaces Remediation: Modeling AI-Accelerated Vulnerability Discovery in Interconnected Systems</a></p></li><li><p><a href="https://arxiv.org/abs/2606.11672">Can Open-Source LLM Agents Replace Static Application Security Testing Tools? An Empirical Assessment</a></p></li><li><p><a href="https://arxiv.org/abs/2606.11671">Runtime Skill Audit: Targeted Runtime Probing for Agent Skill Security</a></p></li><li><p><a href="https://arxiv.org/abs/2606.10945">Context-Based Adversarial Attacks on AI Code Generators: Vulnerability Analysis and Implications</a></p></li><li><p><a href="https://arxiv.org/abs/2606.11416">MPC-Patch-Bench: Security-Aware LLM Code Patch for Multi-Party Computation</a></p></li><li><p><a href="https://arxiv.org/abs/2606.11145">OpenPCC: Open and Confidential LLM Serving on Commodity TEEs</a></p></li><li><p><a href="https://arxiv.org/abs/2606.10749">Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation</a></p></li><li><p><a href="https://arxiv.org/abs/2606.10281">Benchmarking and Exploring the Capabilities of LLMs for Attack Investigations</a></p></li><li><p><a href="https://arxiv.org/abs/2606.12225">Bridging the Smart City Cybersecurity Data Gap Through AI-Driven Synthetic Dataset Generation</a></p></li><li><p><a href="https://arxiv.org/abs/2606.12212">Mind your key: An Empirical Study of LLM API Credential Leakage in iOS Apps</a></p></li></ul></li></ul></li><li><p>Books</p><ul><li><p><a href="https://www.microsoftpressstore.com/store/threat-driven-software-development-defending-online-9780135567388">Threat-Driven Software Development: Defending online services from modern threat actors</a></p></li></ul></li><li><p>Events</p><ul><li><p><em>Nothing overly of note this week..</em></p></li></ul></li></ul><p>Finally finally the <a href="https://creators.spotify.com/pod/profile/national-cyber-security-c6/episodes/The-Ransomware-Ecosystem-e2hi088">NCSC&#8217;s podcast series</a>.</p><div><hr></div><p><em>Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them. </em></p><p><em>This newsletter is subject to the NCSC website terms and conditions which can be found at <a href="https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions">https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions</a> and you can find out more about how will treat your personal information in our privacy notice at <a href="https://www.ncsc.gov.uk/section/about-this-website/privacy-statement">https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.</a></em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CTO at NCSC - Cyber Defence Analysis! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CTO at NCSC Summary: week ending June 7th]]></title><description><![CDATA["Attackers are compromising open source packages to spread malware. Cyber defenders are asked to review dependencies to reduce risks"]]></description><link>https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-june-574</link><guid isPermaLink="false">https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-june-574</guid><dc:creator><![CDATA[Ollie Whitehouse]]></dc:creator><pubDate>Sat, 06 Jun 2026 08:19:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Hk9U!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bee9d4-eb1f-40b2-ae00-abc1037d4119_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to the weekly highlights and analysis of the&nbsp;<a href="https://infosec.pub/c/blueteamsec?dataType=Post&amp;sort=New">blueteamsec</a>&nbsp;(and my wider reading). Not everything makes it in, but the best bits do. A community member is doing <a href="https://briefing.workshop1.net/">daily AI generated podcast of the last 24hours of posts</a>.</p><p>Operationally this week software supply chains continue on as you will see in the reporting below - in response at NCSC we have released advice and guidance in the guise of <a href="https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies">Software supply chain attacks: check your dependencies</a>.</p><p>In the high-level this week:</p><ul><li><p><a href="https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies">Software supply chain attacks: check your dependencies</a> - <strong>NCSC</strong> UK<strong> </strong>publish - <em>&#8220;This blog helps cyber defenders to better understand, mitigate and more effectively respond to the new open source software risks.&#8221;</em></p></li><li><p><a href="https://www.mi5.gov.uk/five-eyes-joint-bulletin-safeguarding-our-secrets">Five Eyes Joint Bulletin - Safeguarding Our Secrets</a> - <strong>MI5</strong> publish - <em>&#8220;On 3 June 2026, members of the Five Eyes intelligence partnership (ASIO, CSIS, FBI, MI5 and NZSIS) released a joint bulletin, Safeguarding our Secrets, warning of the threat posed by China's military intelligence services on Western professional networking sites and online job platforms.&#8221;</em></p></li><li><p><a href="https://www.gov.uk/government/publications/draft-revised-telecommunications-security-code-of-practice-2026/draft-revised-telecommunications-security-code-of-practice">Draft Revised Telecommunications Security Code of Practice</a> -<strong> Department for Science, Innovation &amp; Technology </strong>publish - <em>&#8220;The technical content of this Code of Practice is based on draft guidance developed by experts in the National Cyber Security Centre (NCSC). That guidance was produced following an extensive and detailed analysis of the security of the telecoms sector. It contained a set of technical and procedural measures designed to ensure that security risks are appropriately managed by the providers of PECN and PECS&#8221;</em></p><ul><li><p><a href="https://www.gov.uk/government/consultations/proposals-to-update-the-telecommunications-security-code-of-practice-2022/proposals-to-update-the-telecommunications-security-code-of-practice-2022-what-we-are-consulting-on">Proposals to update the Telecommunications Security Code of Practice 2022: what we are consulting on</a></p></li><li><p><a href="https://www.gov.uk/government/consultations/proposals-to-update-the-telecommunications-security-code-of-practice-2022/outcome/proposals-to-update-the-telecommunications-security-code-of-practice-2022-government-response">Proposals to update the Telecommunications Security Code of Practice 2022: government response</a></p></li><li><p><a href="https://www.gov.uk/government/publications/draft-revised-telecommunications-security-code-of-practice-2026/explanatory-memorandum-to-the-revised-telecommunications-security-code-of-practice-2026-accessible">Explanatory memorandum to the revised Telecommunications Security Code of Practice 2026 (accessible)</a></p></li><li><p><a href="https://www.gov.uk/government/publications/draft-revised-telecommunications-security-code-of-practice-2026/draft-revised-telecommunications-security-code-of-practice-change-log">Draft Revised Telecommunications Security Code of Practice: change log</a></p></li></ul></li><li><p><a href="https://www.gov.uk/government/statistical-data-sets/cyber-essentials-management-information">Cyber Essentials management information January 2026 to March 2026</a> - <strong>Department for Science, Innovation &amp; Technology </strong>publish - <em>&#8221;The latest figures show 59,090 Cyber Essentials certificates have been awarded over the past year (April 2025 to March 2026); 44,608 at CE level and 14,482 at CE+.&#8221; - </em>an increase of just over a 1,000 in the 3 months period</p></li><li><p><a href="https://www.gov.uk/government/publications/g7-digital-and-technology-ministerial-declaration-29-may-2026/g7-digital-and-technology-ministerial-declaration-29-may-2026">G7 Digital and Technology Ministerial Declaration: 29 May 2026</a> - <strong>Department for </strong> <strong>Science, Innovation &amp; Technology</strong> publish - <em>&#8220;We also acknowledge the work of the G7 Cyber Working Group, which is looking this year at AI, post-quantum cryptography, micro, small and medium-sized enterprises (MSMEs) and telecoms, whose outputs informed the Digital and Technology Track&#8217;s discussions on AI.&#8221;</em></p></li><li><p><a href="https://www.senat.fr/dossier-legislatif/ppr25-595.html">Creation of a commission of inquiry into cyberattacks</a> - <strong>Senator Nathalie Goulet</strong> tables - <em>&#8220;commission of inquiry into cyberattacks and data leaks undermining France's digital sovereignty"</em></p></li><li><p><a href="https://www.eba.europa.eu/sites/default/files/2026-06/29b60c21-4ff3-4e1e-9308-7c8225d5cc01/ESAs%202025%20report%20on%20major%20ICT-related%20incidents.pdf">2025 Report on major ICT-related incidents</a> - <strong>European Banking Authority</strong> et al publish - DDoS and ransomware the largest cause of incidents.</p><ul><li><p><a href="https://ratiofy.lu/2025-report-on-major-ict-related-incidents-published-under-joint-esa-report-under-article-22-of-dora-do-you-know-what-it-says/">2025 Report on major ICT-related incidents published under Joint-ESA report under Article 22 of DORA. Do you know what it says?</a> -<strong> Ratiofy</strong> report - <em>&#8220;Cybersecurity (10%): Primarily concentrated in the credit sector, featuring Distributed Denial of Service (DDoS) attacks (33%) and data exfiltration/manipulation (31%).&#8221;</em></p></li></ul></li><li><p><a href="https://www.enisa.europa.eu/enisa-nis360-2026">ENISA NIS360</a> - <strong>ENISA</strong> Publishes - <em>&#8220;Three sectors, including trust services, aviation, and financial market infrastructures (FMIs) moved into the high maturity band. In addition, four sectors strengthened their maturity within the moderate band: gas, road, maritime, and health&#8221;</em></p><ul><li><p><a href="https://www.enisa.europa.eu/news/nis360-the-bigger-picture-on-maturity-and-criticality-of-nis-critical-sectors">Press release</a></p></li></ul></li><li><p><a href="https://academic.oup.com/qje/advance-article-abstract/doi/10.1093/qje/qjag021/8651080?redirectedFrom=fulltext&amp;login=false">Codification, Technology Absorption, and The Globalization of the Industrial Revolution</a> - <strong>R&#233;ka Juh&#225;sz</strong> , <strong>Shogo Sakab</strong>e  and <strong>David E Weinstein</strong> shed light - <em>&#8220;Our findings shed new light on the frictions associated with technological diffusion and offer a novel explanation for why Meiji Japan was unique among non-Western countries in successfully industrializing during the first wave of globalization.&#8221;</em></p></li><li><p><a href="https://www.bbc.co.uk/news/articles/cgmpwzzvxr2o">BMW says humanoid robots are the future of car production</a> - <strong>BBC</strong> reports - <em>&#8220;If you have a humanoid form, you can pretty much set it to any workplace where a human is working today because it has the same size and the same capabilities,&#8221;</em> says Nikolaides. .. <em>&#8220;The cost of robots has fallen while it remains expensive to redesign the assembly line. As a result, it&#8217;s more cost-effective to use robots that fit in with existing human processes.&#8221;</em></p></li><li><p>Reporting on/from China</p><ul><li><p><a href="https://www.nattothoughts.com/p/how-chinas-cyber-operations-and-the-610">How China&#8217;s Cyber Operations &#8211; and the Contractors Behind Them &#8211; Target Critics Abroad</a> - <strong>Eugenio Benincasa</strong> alleges - <em>&#8220;State agencies and an ecosystem of private contractors use cyber capabilities and social engineering to locate, monitor, and harass critics living outside China&#8221;</em></p></li><li><p><a href="https://www.globaltimes.cn/page/202605/1362372.shtml">China&#8217;s new rules on protection of trade secrets become effective on June 1, including data and algorithms</a> - <strong>Global Times</strong> reports - <em>&#8220;The Provisions on the Protection of Trade Secrets will come into effect in China on Monday, with data, algorithms, and other important items being included in the scope of trade secret protection, according to a statement on the website of the State Administration for Market Regulation (SAMR).  "The provisions also list specific technical confidentiality measures for scenarios such as remote work and cross-border collaboration, and clearly specify digital circumstances under the "improper means" of trade secret infringement, according to a report by the Xinhua News Agency. &#8220;</em></p></li><li><p><a href="https://www.scmp.com/tech/policy/article/3354747/china-give-every-humanoid-robot-digital-id-push-boost-industry-standards">China to give every humanoid robot a digital ID in push to boost industry standards</a> - <strong>South China Morning Post</strong> reports - <em>&#8220;The national initiative will give every bipedal humanoid a unique code, like a national ID but for robots&#8221;</em></p></li><li><p><a href="https://www.technologyreview.com/2026/06/01/1138133/china-world-first-brain-chip/">China has approved the world&#8217;s first invasive brain-computer chip&#8212;here&#8217;s what&#8217;s next</a> - <strong>MIT Technology Review</strong> reports - <em>&#8220;Dong&#8217;s brain implant is a coin-size device called NEO. It was developed by <a href="https://www.neuracle.cn/">Neuracle Technology</a>, a Shanghai-based startup, together with researchers at Tsinghua University in Beijing. During a procedure that took just over an hour and a half, the device&#8217;s sensors, which collect Dong&#8217;s brain signals, were placed on his dura mater, the tough outer layer of tissue that covers and protects the brain. The signals are transmitted to a computer by an implant placed on Dong&#8217;s skull. The computer then translates the signals into commands for a soft robotic glove Dong wears during the 2.5-hour training sessions he completes each day to help him learn to grab.&#8221;</em></p></li></ul></li><li><p> AI</p><ul><li><p><a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/">Promoting Advanced Artificial Intelligence Innovation And Security</a> - <strong>The White House</strong> (not me) executively orders - <em>&#8220;Within 60 days of the date of this order, the Secretary of the Treasury, the Secretary of War, through the Director of NSA, and the Secretary of Homeland Security, through the Director of CISA, in consultation with the White House Chief of Staff, through the National Cyber Director, the Assistant to the President for Science and Technology (APST), and the Secretary of Commerce, through the Director of the National Institute of Standards and Technology, and in coordination with other agencies, as appropriate, shall: (a) develop and maintain a classified benchmarking process to assess the advanced cyber capabilities of AI models and determine the threshold at which an AI model should be designated a &#8220;covered frontier model&#8221; for the purposes of this order, sharing such assessments with AI developers and researchers as appropriate.&#8221;</em></p></li><li><p><a href="https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/">Hackers Used Meta&#8217;s AI Support Bot to Seize Instagram Accounts</a> - <strong>KrebsonSecurity</strong> reports - <em>&#8220;The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how to trick Meta&#8217;s &#8220;AI support assistant&#8221; bot into resetting account passwords.&#8221;</em></p></li><li><p><a href="https://www.implicator.ai/iran-turns-western-ai-models-into-a-sanctions-workaround/">Iran Turns Western AI Models Into a Sanctions Workaround</a> - <strong>Marcus Schuler</strong> reports - <em>&#8220;Iran is using Western AI services to help with phishing, malware support and military research while building a domestic platform at Sharif. Google and OpenAI say the tools add productivity, not novel capability.&#8221;</em></p></li><li><p><a href="https://clearbluejar.github.io/posts/system-over-model-tested-mythos-freebsd-local-openweight/">System Over Model, Tested: Reproducing Mythos&#8217;s FreeBSD Find on Local Open-Weight Models</a> - <strong>John McIntosh</strong> details - <em>&#8220;The real problem with the local models is noise: the pipeline graduates a pile of false positives and buries the real one. So I changed the system, not the model. One extra reachability stage drops the false positives from 30 to 5, the CVE still standing. The scaffolding does the work, and it&#8217;s a lever you can pull on your own model.</em></p></li><li><p><a href="https://red.anthropic.com/2026/attack-navigator/">Mapping AI-enabled cyber threats: Insights from the LLM ATT&amp;CK Navigator</a> - <strong>Anthropic</strong> publish - this is the graph to read - this is not autonomous end to end operations, this is work aids.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Hk9U!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bee9d4-eb1f-40b2-ae00-abc1037d4119_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Hk9U!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bee9d4-eb1f-40b2-ae00-abc1037d4119_1920x1080.png 424w, /__u/substackcdn.com/image/fetch/$s_!Hk9U!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bee9d4-eb1f-40b2-ae00-abc1037d4119_1920x1080.png 848w, /__u/substackcdn.com/image/fetch/$s_!Hk9U!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bee9d4-eb1f-40b2-ae00-abc1037d4119_1920x1080.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Hk9U!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bee9d4-eb1f-40b2-ae00-abc1037d4119_1920x1080.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Hk9U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bee9d4-eb1f-40b2-ae00-abc1037d4119_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e6bee9d4-eb1f-40b2-ae00-abc1037d4119_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!Hk9U!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bee9d4-eb1f-40b2-ae00-abc1037d4119_1920x1080.png 424w, /__u/substackcdn.com/image/fetch/$s_!Hk9U!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bee9d4-eb1f-40b2-ae00-abc1037d4119_1920x1080.png 848w, /__u/substackcdn.com/image/fetch/$s_!Hk9U!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bee9d4-eb1f-40b2-ae00-abc1037d4119_1920x1080.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Hk9U!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6bee9d4-eb1f-40b2-ae00-abc1037d4119_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ul><li><p><a href="https://blog.cryptographyengineering.com/2026/05/29/fooling-around-with-encrypted-reasoning-blobs/">Let&#8217;s talk about encrypted reasoning</a> - <strong>Matthew Green</strong> talks - <em>&#8220;I reported both results to OpenAI and Anthropic via their bug bounty programs. OpenAI said my report was unreproducible. I sent them my scripts, but too late. Anthropic quite reasonably told me they don&#8217;t see any security implications in side channels or replays, but they might alter their developer documentation to warn application developers to be more careful&#8221;</em></p></li><li><p><a href="https://arxiv.org/abs/2605.24632">Demystifying the Mythos or Disrupting Bugonomics? From Zero-Day Asymmetry to Defender Remediation Throughput</a> - <strong>University College London / Bynario</strong> research - <em>&#8220;Using public data from Anthropic&#8217;s Mythos Preview and Mozilla Firefox collaborations, together with public exploit-market price anchors, vulnerability reward programs, and incident baselines, we argue that the near-term shift is not simply &#8220;more zero-days.&#8221; It is a move from zero-day asymmetry toward broader defender remediation throughput: low-signal candidates become cheaper, evidence-rich remediation packages become more important, and scarce capacity shifts toward maintainer review and release work.&#8221;</em></p></li><li><p><a href="https://arxiv.org/abs/2605.30096">How Reliable Are AI Attackers Against a Fixed Vulnerable Target? A 400-Run Empirical Study of LLM Penetration Testing Consistency</a> - <strong>Galip T. Erdem</strong> researches - <em>&#8220;Claude achieved full exploitation in 61 of 100 runs; Gemini 2.5 FlashLite in 85; GPT-4o-mini in 56 while deploying 98 unique attack strategies; qwen2.5-coder:14b in 25. Failure modes are model-distinctive&#8221; - </em>caveat of full exploitation is the real-world translatability </p></li><li><p><a href="https://dl.acm.org/doi/pdf/10.1145/3766895">Can LLMs Hack Enterprise Networks? Autonomous Assumed</a> - <strong>TU Wien Faculty of Informatics, Vienna, Austria</strong> publish - <em>&#8220;We perform our empirical evaluation using five LLMs, comparing reasoning to non-reasoning models as well as including open-weight models. Through comprehensive quantitative and qualitative analysis, incorporating insights from cybersecurity experts, we demonstrate that autonomous LLMs can effectively conduct Assumed Breach simulations&#8221;</em> - caveats here are labs which the models could have learnt about.</p></li><li><p><a href="https://arxiv.org/abs/2605.27042">Lessons from Penetration Tests on Large-Scale Agent Systems</a> - <strong>IBM Research</strong> research - <em>&#8220;The two penetration tests conducted in 2025 demonstrate that proprietary agent applications, despite undergoing stricter development and review processes, continue to exhibit security weaknesses similar to those observed in opensource agent frameworks.&#8221;</em></p></li><li><p><a href="https://i.blackhat.com/Asia-26/Presentations/BlackHat-ASIA2026-BadVibes.pdf?_gl=1*1yrgdzp*_gcl_au*MTA2Mjc0ODkzMi4xNzc5NTk0ODQ3*_ga*MTU0OTQ5MDkzNS4xNzc5NTk0ODQ3*_ga_K4JK67TFYV*czE3ODAyMjk0OTckbzMkZzEkdDE3ODAyMjk1MTckajQwJGwwJGgw">Pwning Coding Agents 70 Times With The Same Bugs</a> - <strong>Palo Alto Networks</strong> detail - <em>"</em></p><ul><li><p><em>We had 81+ reports before we stopped counting. </em></p></li><li><p><em>Not everyone agrees Prompt Injection == popping endless calcs is a severe issue. </em></p></li><li><p><em>18 CVEs (including reserved). Many more fixes and acknowledgements.&#8221;</em></p></li></ul></li><li><p><a href="https://www.bcs.org/articles-opinion-and-research/new-legal-questions-agentic-pen-testing/">New legal questions: agentic pen testing -</a> <strong>British Computer Society</strong> publish - <em>&#8220;In the meantime, the industry is writing the first draft of its own case law, in engagement letters and terms of service. The firms, and the jurisdictions, that get the architecture right first will have the most durable advantage. Cybersecurity has always lived with legal uncertainty. The difference is that the uncertainty is now being baked into the tools themselves, and we will find out what that means in litigation rather than in policy.&#8221;</em></p></li><li><p><a href="https://arxiv.org/abs/2605.18935">The Agentic Economy: Humans, AI Agents, Robots, and the Measurable Transition toward Distributed Economic Action</a> - <strong>Business &amp; Technology University, Georgia</strong> publish - <em>&#8220;This article develops the concept of the agentic economy and empirically diagnoses its measurable preconditions: an emerging transition in which economic action is increasingly distributed among humans, AI agents, industrial robots, executable protocols, compute infrastructures and energy systems. The paper argues that classical categories such as labour, capital, firm, market, productivity and trust remain essential, but are no longer sufficient when technologies do not merely raise productivity but also prepare decisions, coordinate workflows, support or execute tasks, verify transactions and reshape responsibility&#8221;</em></p></li><li><p><a href="https://www.amnesty.org/en/documents/pol40/0996/2026/en/">Unlawful by design: Exposing the human rights costs of generative AI </a>- <strong>Amnesty International</strong> outlines - <em>&#8220;This briefing examines how standalone generative AI systems, based on unlawful web scraping, are in conflict with international human rights law (IHRL) and standards through their design, development and deployment. While these technologies promise sophisticated automation and efficiency, they rely on data collection and model training practices that abuse privacy rights, enable discrimination, and threaten freedom of expression and thought.&#8221;</em></p></li><li><p><a href="https://arxiv.org/abs/2606.04490">Prioritization of Risks from Artificial Intelligence: A Delphi Study of 272 International Experts</a> - <strong>MIT AI Risk Initiative</strong> studies - <em>&#8220;Experts assessed at least 10% probability of catastrophic harm (e.g., more than 1 million human deaths or more than USD $100B loss) from 18 of 24 AI risk domains under business-as-usual trajectories over the next 5 years&#8221; - </em>assessed or asserted?</p></li><li><p><a href="https://www.scmp.com/tech/tech-trends/article/3355529/minimax-debuts-ai-model-built-long-and-complex-coding-tasks">MiniMax debuts AI model built for long and complex coding tasks</a> - <strong>South China Morning Post</strong> reports - <em>&#8220;The Shanghai-based company said on Monday that the model&#8217;s redesigned architecture reduced computational requirements to as little as one-twentieth of previous levels, slashing inference costs while boosting response speeds.&#8221;</em></p></li><li><p><a href="https://www.reuters.com/world/asia-pacific/openais-altman-says-ai-unlikely-lead-jobs-apocalypse-2026-05-26/">OpenAI&#8217;s Altman says AI unlikely to lead to &#8216;jobs apocalypse&#8217;</a> - <strong>Reuters</strong> reports - <em>&#8220;OpenAI CEO Sam Altman said on Tuesday the rapid development &#8204;and adoption of AI would not lead to a global "jobs apocalypse" and the technology had not claimed as many white-collar jobs as he had feared.&#8221; - </em>the reality is cost, reliability and business value are still variables here today which many organisations are wrestling with.</p></li><li><p><a href="https://www.europarl.europa.eu/thinktank/en/document/EPRS_STU(2026)774753">EU civic engagement: The use of digital tools and AI to promote citizen participation in EU policymaking</a> - <strong>European Parliament</strong> think tanks - <em>&#8220;Building on a comprehensive landscape analysis, the study clusters 94 distinct tools from around the world and selects 11 representative cases for in-depth empirical assessment. This approach distinguishes between theoretical potential and practical utility, identifying the preconditions for successful engagement and how tool functionalities can support this. It also gives empirical insights into the current usage of digital tools, their associated advantages and limitations, and the trade-offs that need to be considered when conducting participatory processes&#8221;</em> </p></li></ul></li><li><p><em>Cyber proliferation</em></p><ul><li><p><a href="https://freiheitsrechte.org/en/ueber-die-gff/presse/pressemitteilungen/one-click-and-youre-spied-on-gff-files-criminal-complaint-alongside-journalist-trung-khoa-le-following-spyware-attack">One click&#8212;and you&#8217;re spied on: GFF files criminal complaint alongside journalist Trung Khoa L&#234; following spyware attack</a> - <strong>The Society for Civil Rights (Gesellschaft f&#252;r Freiheitsrechte e.V. or "GFF")</strong> details - &#8220;<em>The Society for Civil Rights (GFF) today filed a criminal complaint against persons unknown, together with German-Vietnamese journalist Trung Khoa L&#234;, regarding an attempted spyware attack. L&#234; is the editor of the important Vietnamese news site Thoibao.de, which he runs from Germany. The attackers, who are believed to be operating from abroad, unsuccessfully attempted to install spyware on his laptop and cell phone via Platform X.&#8221;</em></p></li><li><p><a href="https://arxiv.org/abs/2602.12388">Tracking The Trackers: Commercial Surveillance Occurring on U.S. Army Networks</a> - <strong>Army Cyber Institute</strong> detail - from Feb but a good warning - <em>&#8220;21.2% of the top 1,000 Internet resources accessed on Army CONUS unclassified networks during the study period were tracker domains &#8211; domain endpoints used exclusively for analytics or collection of user data. This is a conservative estimate of total Internet tracking activity, as another 10.4% consisted of websites with embedded tracking code.&#8221;</em></p></li></ul></li><li><p>Bounty Hunting</p><ul><li><p><a href="https://www.justice.gov/opa/pr/american-citizen-pleads-guilty-working-agent-peoples-republic-china">American Citizen Pleads Guilty to Working as an Agent for the People&#8217;s Republic of China</a> - US <strong>Department of Justice</strong> announces - <em>&#8220;Pauken also sold reports to a group of Chinese individuals from Wuhan who sought information about technology and the U.S. Department of Justice. The Wuhan clients wanted Pauken to find an expert to help them engage in cyber espionage.&#8221;</em></p></li></ul></li><li><p>Market Incentives</p><ul><li><p><a href="https://www.bloomberg.com/news/articles/2026-06-04/ibm-at-t-accused-by-whistleblower-of-covering-up-foreign-hacks">IBM, AT&amp;T Accused by Whistleblower of Covering Up Breaches</a> - <strong>Bloomberg</strong> alleges - <em>&#8220;International Business Machines Corp. and AT&amp;T Inc.&#8217;s computer systems were repeatedly breached by foreign hackers, and the companies concealed those intrusions from the US government in violation of the law, according to a lawsuit from a former IBM cybersecurity official. William Barlow, IBM&#8217;s former vice president of threat intelligence, alleged in the complaint that the companies failed to disclose multiple breaches over years by attackers linked to foreign governments and made false assurances about the security of their systems in order to win and keep federal contracts.&#8221;</em></p></li><li><p><a href="https://docbox.etsi.org/CYBER/EUSR/Open/EN_304-627_V1.0.0_2026-06-01_Routers-Modems-Switches_Final-draft.pdf">Cybersecurity (CYBER); Cyber Resilience Act (CRA); Cybersecurity requirements for routers, modems intended for the connection to the internet and switches </a>- <strong>ETSI</strong> publishes - <em>&#8220;The present document specifies vulnerability handling activities, technical requirements and corresponding assessment criteria for routers, modems intended for connection to the internet, and switches related to cybersecurity.&#8221;</em> &#8230; <em>&#8220;The present document covers those products to demonstrate compliance with the essential cybersecurity requirements 321 of Regulation (EU) 2024/2847&#8221;</em></p></li><li><p><a href="https://arxiv.org/abs/2606.05449">Insurance of Agentic AI</a> - <strong>Quanyan Zhu</strong> proposes - <em>&#8220;The paper further proposes an actuarial framework based on exposure assessment, scenario analysis, dependency mapping, and accumulation-risk management, drawing parallels to the evolution of cyber insurance. Finally, we present a coordinated insurance architecture that integrates cyber, technology errors and omissions, product liability, performance-warranty, and affirmative AI-liability coverages through explicit allocation mechanisms and dedicated AI aggregates. The analysis suggests that the future of agentic-AI insurance lies not in a single monoline product but in a layered ecosystem of complementary coverages supported by improved governance, transparency, telemetry, and regulatory clarity.&#8221;</em></p></li></ul></li></ul><p>Reflections this week are two fold&#8230;</p><p>The first is from a discussion this week with delivr.to and the insight they provided that click-fix continues the single biggest challenge they see in terms of initial payload delivery. They highlighted where vendors make changes to terminal instantiation and use (such as in <a href="https://www.bleepingcomputer.com/news/security/apple-adds-macos-terminal-warning-to-block-clickfix-attacks/">macOS Tahoe 26.4</a>) it really does move the dial.</p><p>The second is it is clear that AI supported vulnerability discovery is displacing constraint to downstream pinch points in patch development, testing etc. for a majority. We should expect this trend to continue down the full stack and every level but also not be surprised where AI is not reliable enough today to address some of these downstream bottlenecks. Maybe code fixing will help - but functional regression testing will be the next bottleneck etc. until we get assured micro patching or otherwise reasoned (e.g SMTs etc.) fixes etc.</p><p>Finally you might find interesting the opinion piece -  <a href="https://www.defendersinitiative.com/p/the-unintended-consequences-of-vulnmaxxing">The unintended consequences of vulnmaxxing - The only way to fix vulns at AI scale is to use AI. Coincidence or cash grab?</a></p><p> </p><p>Not getting this via email? Subscribe:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Think someone else would benefit? Share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-june-574?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-june-574?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p><strong>All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.</strong></p><p>Have a lovely Saturday&#8230;</p><p>Ollie</p><h1>Cyber threat intelligence</h1><p>Who is doing what to whom and how allegedly.</p><h2>Reporting on Russia</h2><h3>FSB&#8217;s matryoshka</h3><p><strong>Amaury G.</strong> details this alleged Russian capability which is noteworthy for the relative technical sophistication. </p><blockquote><ul><li><p>Gamaredon is a cyberespionage group specialized in long-term and persistent intrusion operations targeting Ukraine. Officially operated by Russia&#8217;s FSB, the group is focusing government, military, and critical infrastructure networks, and is still actively operating at the time of this publication.</p></li><li><p>This report analyses over a decade of malware families and establishes a unified naming taxonomy to cut through the fragmented nomenclature.</p></li><li><p>The infection chain is designed to be invisible: by hiding inside legitimate Windows features and abusing trusted platforms like Telegram, Cloudflare, and standard cloud storage, Gamaredon leaves almost no trace on infected machines.</p></li><li><p>Once inside a network, malware spreads physically, infecting USB drives to jump across air-gapped systems and steals documents whether they are stored, being transferred, or actively edited in real time.</p></li><li><p>Every step of the infection chain doubles as a backdoor, giving operators the ability to push new commands, update configurations, or deploy additional payloads, ensuring permanent access to compromised hosts</p></li></ul></blockquote><p><a href="https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/">https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/</a></p><p><a href="https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/">https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/</a></p><p><a href="https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/">https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/</a></p><h3>Tracking APT28 PixyNetLoader: Evolutions from 2024 to 2026</h3><p><strong>ExaTrack</strong> track of the evolution of this alleged Russian capability for a two year timeframe. Noteworthy for the continued investment and PNG for payload delivery..</p><blockquote><ul><li><p>Analysis of ~90 PixyNetLoader samples and grouping them into 4 sub-families using code similarities sharing</p></li><li><p>Enabling unified detection through a single YARA rule</p></li><li><p>Exposing the latest steganography mechanisms used in the 2026 March-April versions</p></li><li><p>Providing PNG payload extraction script, IOCs, detection guidance and samples list</p></li></ul></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!PJZH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff047d1ac-7b32-49f1-82c5-fe3558c0d88b_1023x681.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!PJZH!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff047d1ac-7b32-49f1-82c5-fe3558c0d88b_1023x681.png 424w, /__u/substackcdn.com/image/fetch/$s_!PJZH!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff047d1ac-7b32-49f1-82c5-fe3558c0d88b_1023x681.png 848w, /__u/substackcdn.com/image/fetch/$s_!PJZH!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff047d1ac-7b32-49f1-82c5-fe3558c0d88b_1023x681.png 1272w, /__u/substackcdn.com/image/fetch/$s_!PJZH!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff047d1ac-7b32-49f1-82c5-fe3558c0d88b_1023x681.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!PJZH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff047d1ac-7b32-49f1-82c5-fe3558c0d88b_1023x681.png" width="1023" height="681" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f047d1ac-7b32-49f1-82c5-fe3558c0d88b_1023x681.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:681,&quot;width&quot;:1023,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;PixyNetLoader infection chain&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="PixyNetLoader infection chain" title="PixyNetLoader infection chain" srcset="/__u/substackcdn.com/image/fetch/$s_!PJZH!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff047d1ac-7b32-49f1-82c5-fe3558c0d88b_1023x681.png 424w, /__u/substackcdn.com/image/fetch/$s_!PJZH!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff047d1ac-7b32-49f1-82c5-fe3558c0d88b_1023x681.png 848w, /__u/substackcdn.com/image/fetch/$s_!PJZH!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff047d1ac-7b32-49f1-82c5-fe3558c0d88b_1023x681.png 1272w, /__u/substackcdn.com/image/fetch/$s_!PJZH!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff047d1ac-7b32-49f1-82c5-fe3558c0d88b_1023x681.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://blog.exatrack.com/Tracking_APT28_PixyNetLoader/">https://blog.exatrack.com/Tracking_APT28_PixyNetLoader/</a></p><h2>Reporting on China</h2><h3>VerdantBamboo: Just Another BRICKSTORM in the Firewall</h3><p><strong>Damien Cash, Paul Rascagneres, Steven Adair</strong>, and <strong>Tom Lancaster</strong> further detail this alleged Chinese operation which is noteworthy for apparently deploying a fallback implant for resilience purposes. </p><blockquote><p>While BRICKSTORM was the primary implant used by VerdantBamboo, Volexity identified two previously undocumented (at the time of discovery) malware families:</p><ul><li><p>PLENET, a malware family written in .NET Core and compiled to native code using the Native AOT features added in .NET 7. The analyzed sample was written for Linux target systems. This malware was referred to as &#8220;GRIMBOLT&#8221; by Google Cloud.</p></li><li><p>AGENTPSD, a malware family written in Python that was deployed to Linux systems. This malware was compiled to a binary using PyInstaller. It has limited functionality, and Volexity assesses with high confidence that it served as a fallback should VerdantBamboo&#8217;s primary backdoor no longer function.</p></li></ul></blockquote><p><a href="https://www.volexity.com/blog/2026/06/04/verdantbamboo-just-another-brickstorm-in-the-firewall/">https://www.volexity.com/blog/2026/06/04/verdantbamboo-just-another-brickstorm-in-the-firewall/</a></p><h3>Operation Dragon Weave : Uncovering a China-Linked Campaign Targeting Czech Republic and Taiwan Using Azure Cloud C2</h3><p><strong>Priya Patel</strong> details this alleged Chinese operation which isn&#8217;t overly noteworthy other than for the victimology. </p><blockquote><p>[We have] been actively tracking threats across the globe. During our recent analysis, we identified a spearphishing campaign targeting officials and citizens in the Czech Republic and Taiwan. We observed a single lure document along with multiple supporting artifacts that strongly suggest the campaign is specifically targeting these regions, as the files closely mimic official communications.</p><p>The attack begins with a ZIP attachment. When extracted, the archive contains multiple files that appear legitimate but are actually part of a structured infection chain designed to execute malicious payloads in the background.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!hFy7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8222e38e-e94c-4943-a28a-04f61a5f8dd6_1024x674.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!hFy7!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8222e38e-e94c-4943-a28a-04f61a5f8dd6_1024x674.png 424w, /__u/substackcdn.com/image/fetch/$s_!hFy7!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8222e38e-e94c-4943-a28a-04f61a5f8dd6_1024x674.png 848w, /__u/substackcdn.com/image/fetch/$s_!hFy7!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8222e38e-e94c-4943-a28a-04f61a5f8dd6_1024x674.png 1272w, /__u/substackcdn.com/image/fetch/$s_!hFy7!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8222e38e-e94c-4943-a28a-04f61a5f8dd6_1024x674.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!hFy7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8222e38e-e94c-4943-a28a-04f61a5f8dd6_1024x674.png" width="1024" height="674" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8222e38e-e94c-4943-a28a-04f61a5f8dd6_1024x674.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:674,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!hFy7!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8222e38e-e94c-4943-a28a-04f61a5f8dd6_1024x674.png 424w, /__u/substackcdn.com/image/fetch/$s_!hFy7!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8222e38e-e94c-4943-a28a-04f61a5f8dd6_1024x674.png 848w, /__u/substackcdn.com/image/fetch/$s_!hFy7!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8222e38e-e94c-4943-a28a-04f61a5f8dd6_1024x674.png 1272w, /__u/substackcdn.com/image/fetch/$s_!hFy7!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8222e38e-e94c-4943-a28a-04f61a5f8dd6_1024x674.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.seqrite.com/blog/operation-dragon-weave-uncovering-a-china-linked-campaign-targeting-czech-republic-and-taiwan-using-azure-cloud-c2/">https://www.seqrite.com/blog/operation-dragon-weave-uncovering-a-china-linked-campaign-targeting-czech-republic-and-taiwan-using-azure-cloud-c2/</a></p><h3>TA4922: The Suspected Chinese Crime Group is Going Global</h3><p><strong>The Proofpoint Threat Research Team</strong> detail this alleged Chinese criminal group which is noteworthy given the fact it can operate without the state taking action. Which is somewhat surprising.. </p><blockquote><ul><li><p>TA4922 is a highly sophisticated threat actor demonstrating a rapid operational tempo and continually evolving malware arsenal.</p></li><li><p>The group has been observed using multiple malware families including Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT (Winos4.0), among others.</p></li><li><p>TA4922 relies on localized lures often themed around HR, payroll, tax, and invoicing to convince targets across multiple regions. In recent months, the actor&#8217;s activity has spread to more countries globally, including in Europe and Africa.</p></li><li><p>The actor combines malicious activity with legitimate tools, trusted software, and cloud hosting services, making detection and defense more challenging.</p></li></ul></blockquote><p><a href="https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global">https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global</a></p><h2>Reporting on North Korea</h2><h3>Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign</h3><p><strong>LevelBlue</strong> detail this alleged North Korean campaign which is noteworthy for the platform targeting and method of initial access.</p><blockquote><p>Initial access relied on targeted social engineering in which victims were instructed to execute a fake Zoom SDK update component, leading to user-assisted execution and follow-on payload delivery.</p></blockquote><p><a href="https://www.levelblue.com/blogs/spiderlabs-blog/sapphire-sleet-targets-macos-in-multi-stage-intrusion-campaign">https://www.levelblue.com/blogs/spiderlabs-blog/sapphire-sleet-targets-macos-in-multi-stage-intrusion-campaign</a></p><h3>Analysis of APT-C-26 (Lazarus) group&#8217;s attack activities using CVE-2025-55182 and the Copperhedge component</h3><p><strong>360 Threat Intelligence Center</strong> detail an aspect of an alleged North Korean operation which will be of note to cyber defenders. CVE-2025-55182 is React2Shell&#8230;</p><blockquote><p>During routine monitoring, we observed that the Lazarus group used malicious components related to the CVE-2025-55182 vulnerability, supplemented by the internal network lateral movement tool MultiRelay, a User Account Control (UAC) bypass tool, and traces of the Copperhedge malware family.</p></blockquote><p><a href="https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247508667&amp;idx=1&amp;sn=3557c4427627029226bda2a9de3a81ca&amp;chksm=f9c191b2ceb618a4b288a4cf57d9813f2b425ed24a11848bee8d34ec2f53ed9bbde180cac3be&amp;scene=178&amp;cur_album_id=1955835290309230595&amp;search_click_id=#rd">https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247508667&amp;idx=1&amp;sn=3557c4427627029226bda2a9de3a81ca&amp;chksm=f9c191b2ceb618a4b288a4cf57d9813f2b425ed24a11848bee8d34ec2f53ed9bbde180cac3be&amp;scene=178&amp;cur_album_id=1955835290309230595&amp;search_click_id=#rd</a></p><h2>Reporting on Iran</h2><h3>The Server Seizure That Affects Also Iran&#8217;s Cyber Operations</h3><p><strong>Check Point</strong> detail the impact on alleged Iranian cyber operations from the server seizures which occurred due to sanctions violations. Alleged Russian hosting supporting alleged Iranian cyber operations..</p><blockquote><p>On May 22, 2026, Dutch financial-crime investigators walked into data centers in Dronten and Schiphol-Rijk and seized approximately 800 servers. The target was <strong>WorkTitans B.V.</strong>, a hosting provider that, on the surface, looked like any other internet infrastructure company. What investigators uncovered, however, was something far more significant: a ghost operation built on sanctioned infrastructure, quietly serving as the backbone for some of Iran&#8217;s most active cyber espionage campaigns.</p><p>&#8230;</p><p>Based on our tracking of threat actor infrastructure, the WorkTitans takedown likely had an impact on Iranian cyber operations. Three separate Iranian threat actor groups, each running their own campaigns against different targets, were observed using WorkTitans infrastructure for core operational purposes.</p></blockquote><p><a href="https://blog.checkpoint.com/security/the-server-seizure-that-affects-also-irans-cyber-operations/">https://blog.checkpoint.com/security/the-server-seizure-that-affects-also-irans-cyber-operations/</a></p><h2>Reporting on Other Actors</h2><h3>Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan</h3><p><strong>Dixit Panchal</strong> details an alleged Pakistani campaign which is noteworthy for its victimology as opposed tradecraft..</p><blockquote><p>Seqrite Labs has been actively monitoring spear phishing campaigns across the globe and has a well-established history of tracking the SideCopy APT cluster &#8212; a Pakistan-linked threat group operating under the broader Transparent Tribe / APT36 umbrella. In continuation of that tracking effort, we identified a targeted campaign directed at the Ministry of Finance, Afghanistan, with TTPs that overlap with SideCopy at medium-to-high confidence.</p><p>&#8230;</p><p>The campaign opens with a spear phishing delivery &#8212; a ZIP archive containing a malicious LNK file bearing a carefully crafted Pashto-language filename:</p></blockquote><p><a href="https://www.seqrite.com/blog/operation-xenofiscal-sidecopy-deploying-persistent-xenorat-targeting-the-mof-afghanistan/">https://www.seqrite.com/blog/operation-xenofiscal-sidecopy-deploying-persistent-xenorat-targeting-the-mof-afghanistan/</a></p><h3>Dissecting an Undocumented Lua-Wrapped Loader: The BoldTealLayer Campaign</h3><p><strong>The One Eyed Argus</strong> pops up out of no where to detail a previously unseen loader</p><blockquote><p>In early 2026, while investigating unexplained high memory usage on my Windows 11 system, I discovered a plaintext debug log file (<code>lua_traceback.log</code>) left in the <code>C:\temp</code> directory. The log detailed the real&#8209;time actions of a previously undocumented malware loader. Despite being actively executed, the threat evaded detection by multiple up&#8209;to&#8209;date antivirus engines, including Microsoft Defender, Malwarebytes, and ESET.</p><p>The loader employs a multi&#8209;stage attack chain. It uses a legitimate, digitally signed executable (<code>active_desktop_launcher.exe</code>) to side&#8209;load a malicious DLL (<code>active_desktop_render_x64.dll</code>). This DLL then loads a Lua scripting engine to execute an obfuscated script that systematically dismantles Windows security mechanisms&#8212;patching Event Tracing for Windows, restoring a clean copy of <code>ntdll.dll</code> to remove user&#8209;mode hooks, and employing a rare hardware breakpoint to bypass the Antimalware Scan Interface (AMSI). With all defences neutralised, a .NET assembly is injected directly into memory and executed.</p></blockquote><p><a href="https://theoneeyedargus.github.io/">https://theoneeyedargus.github.io/</a></p><h3>Espionage Campaign Targeted Stock Exchange Executive for Five Months</h3><p><strong>Threat Hunter Team</strong> detail an unattributed campaign which is noteworthy for the intent and victimology.</p><blockquote><p>A five-month espionage campaign targeted the email account of a senior figure at a major global stock exchange. For an espionage actor, a senior executive&#8217;s mailbox is a high-value intelligence target. An Outlook profile may yield details of external negotiations, internal deliberations, the executive&#8217;s calendar, travel pattern, and their contacts. Organizations such as exchanges and regulators may hold non-public information about listings, enforcement actions and market-moving events. Months of unfettered access to that mailbox lets an attacker build a near-complete picture of the target&#8217;s working life and the organization&#8217;s near-term direction without ever having to move laterally elsewhere on the network.</p><p>&#8230;</p><p>The attackers took multiple steps to try and conceal their activity. They used legitimate cloud services (Dropbox and OneDrive) for exfiltration and their command and control (C2) infrastructure. They also used a variety of public tools, and named tools and services to blend in with legitimate traffic. The use of public tools and cloud infrastructure means the attackers did not leave many clues to their identity, so this activity cannot be attributed to a known attack group. However, the commands used by the attackers do point to the motivation for this attack being espionage.</p></blockquote><p><a href="https://www.security.com/blog-post/stock-exchange-espionage">https://www.security.com/blog-post/stock-exchange-espionage</a></p><h3>Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites</h3><p><strong>SilentPush</strong> detail some of the underlying business model of this criminal campaign which is noteworthy due to it performance incentives.</p><blockquote><p>Based on our research, we suspect DriveSurge uses a Pay-Per-Install (PPI) model, where it is paid each time a victim&#8217;s device is successfully infected, with those leads then sold downstream to other threat actors.</p><ul><li><p>[We] recently observed several drive-by attack clusters developed by a threat actor to automate malware delivery at scale. We named the primary driver behind an extensive surge in ClickFix and FakeUpdates campaigns: <strong>DriveSurge</strong>.</p></li><li><p>Current activity suggests DriveSurge operates as a specialized Initial Access Broker (IAB), using a Pay-Per-Install (PPI) model to supply downstream threat actors with high-quality victim leads.</p></li><li><p>DriveSurge has compromised thousands of websites that set zTDS domains to traffic victims to ClickFix and Fakeupdates websites.</p></li><li><p>Our research uncovered a series of eight technical fingerprints that map DriveSurge&#8217;s malicious infrastructure.</p></li></ul></blockquote><p><a href="https://www.silentpush.com/blog/drivesurge/">https://www.silentpush.com/blog/drivesurge/</a></p><h3>Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem</h3><p><strong>Alexey Bukhteyev</strong> details similar capability which further highlights the scale, complexity and service model of initial access.</p><blockquote><ul><li><p>Check Point Research investigated a large-scale operation that impersonates open-source and freeware projects to capture search traffic, including lookalikes for researcher and security tooling such as Ghidra, dnSpy, and SpiderFoot. The sites are well-designed and often look like legitimate project portals at a glance, sometimes referencing real upstream resources. The deception is not in the page content alone, it&#8217;s in what happens when a user interacts.</p></li><li><p>Our analysis shows these pages load a CloudFront-hosted JavaScript staging layer that converts a click on a &#8220;download&#8221; button/link into a handoff to a Traffic Distribution System (TDS). The TDS enforces strict gating: first-visit state, mandatory click confirmation, anti-bot/anti-analysis logic, VPN/datacenter filtering, and frequency capping.</p></li><li><p>The observed ecosystem appears to be built primarily for traffic acquisition and monetization, likely leveraging legitimate ad-tech and monetization tooling, while downstream redirect chains repeatedly led selected users to malware delivery infrastructure.</p></li><li><p>The downstream branches we analyzed led to multiple malware families, including RemusStealer, AnimateClipper, and the SessionGate framework, which we observed delivering PUA (Potentially Unwanted Applications), suggesting this was not an isolated malicious redirect.</p></li></ul></blockquote><p><a href="https://research.checkpoint.com/2026/impersonation-click-hijacking-and-tds-inside-a-malware-distribution-ecosystem/">https://research.checkpoint.com/2026/impersonation-click-hijacking-and-tds-inside-a-malware-distribution-ecosystem/</a></p><h3>The HazyBeacon Protocol &#8211; How Malware Weaponizes Amazon Web Services (AWS) Lambda Function URLs</h3><p><strong>Aniket Harne </strong>details an unattributed campaign which is noteworthy for its novel C2 which defensive teams will want to be alive to.</p><blockquote><ul><li><p>HazyBeacon (CL-STA-1020) targets Southeast Asian government networks by abusing AWS Lambda Function URLs configured with AuthType: NONE as stealth command-and-control relays.</p></li><li><p>Attackers use stolen IAM credentials<strong> </strong>to deploy Lambda functions that proxy malware communications through trusted AWS domains.</p></li><li><p>Organizations can reduce exposure by enforcing identity-centric access controls, enabling global CloudTrail logging, enabling VPC flow telemetry, and implementing Service Control Policies that restrict Lambda Function URL exposure, all supported by continuous configuration monitoring.</p></li></ul></blockquote><p><a href="https://blog.qualys.com/qualys-insights/2026/06/02/hazybeacon-aws-lambda-function-url-command-control-abuse">https://blog.qualys.com/qualys-insights/2026/06/02/hazybeacon-aws-lambda-function-url-command-control-abuse</a></p><h3>Supply Chain attacks this week</h3><p>A reminder we issued guidance this week we issued advice in <a href="https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies">Software supply chain attacks: check your dependencies</a>.</p><ul><li><p>Malicious npm packages abuse dependency confusion to profile developer environments - <a href="https://www.microsoft.com/en-us/security/blog/2026/05/29/33-malicious-npm-packages-abuse-dependency-confusion-profile-developer-environments/">https://www.microsoft.com/en-us/security/blog/2026/05/29/33-malicious-npm-packages-abuse-dependency-confusion-profile-developer-environments/</a></p></li><li><p>Typosquatted npm packages used to steal cloud and CI/CD secrets - <a href="https://www.microsoft.com/en-us/security/blog/2026/05/28/typosquatted-npm-packages-used-steal-cloud-ci-cd-secrets/">https://www.microsoft.com/en-us/security/blog/2026/05/28/typosquatted-npm-packages-used-steal-cloud-ci-cd-secrets/</a></p></li><li><p>183 npm Packages Target Cloud and Finance via oob.moika.tech - </p><p><a href="https://safedep.io/oob-moika-tech-dependency-confusion-campaign/">https://safedep.io/oob-moika-tech-dependency-confusion-campaign/</a></p></li><li><p>PCPJack Hijacked 230 AWS, GCP, and Azure Servers to Run a Hidden SMTP Relay Network - <a href="https://hunt.io/blog/pcpjack-230-cloud-servers-smtp-proxy-network-sliver-chisel">https://hunt.io/blog/pcpjack-230-cloud-servers-smtp-proxy-network-sliver-chisel</a></p></li></ul><h1>Discovery</h1><p>How we find and understand the latent compromises within our environments.</p><h2>C2 Frameworks - Threat Hunting in Action with YARA Rules</h2><p><strong>Resecurity</strong> release these Yara rules which will help detection teams hunt..</p><blockquote><p>For educational purposes, Resecurity has developed sample YARA rules for various C2 frameworks to assist network defenders. This information may also be useful for red team specialists in planning potential evasion tactics when conducting vulnerability assessments and penetration testing (VAPT).</p><ul><li><p>Airstrike C2</p></li><li><p>Alan Framework</p></li><li><p>AM0NEye</p></li><li><p>Atlas C2</p></li><li><p>BruteRatel</p></li><li><p>C3 (Custom Command and Control)</p></li><li><p>Callidus</p></li><li><p> DBC2</p></li><li><p>Deimos C2</p></li><li><p>GrimReaper C2</p></li><li><p>FlyingAFalseFlag C2</p></li><li><p>Mike C2</p></li><li><p>Nimbo C2</p></li><li><p>NorthStar C2</p></li><li><p> Petaq C2</p></li><li><p> Pickle C2</p></li><li><p> Posh C2</p></li><li><p>Reddit C2</p></li><li><p> Sharp C2</p></li><li><p>Trevor C2</p></li><li><p>SQLC2</p></li></ul></blockquote><p><a href="https://www.resecurity.com/blog/article/c2-frameworks-threat-hunting-in-action-with-yara-rules">https://www.resecurity.com/blog/article/c2-frameworks-threat-hunting-in-action-with-yara-rules</a></p><h2>Aether</h2><p><strong>Mr.Z</strong> releases this which will act as inspiration for techniques to apply.</p><blockquote><p>Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techniques, implant signatures, reflectively loaded .NET assemblies. it works with a multi-layer confidence model that dramatically reduce the false positive rate and hunt for malicious behaviour. Aether has good capabilities in detecting Hollowing, APC, thread hijacking techniques. Security analysts can use it to scan,hunt and snapshot suspicious region for offline analysis.</p></blockquote><p><a href="https://github.com/0xsp-SRD/aether">https://github.com/0xsp-SRD/aether</a></p><h1>Defence</h1><p>How we proactively defend our environments.</p><h2>MXC Internals: How Microsoft&#8217;s eXecution Containers Actually Isolate Agent Code</h2><p><strong>Tyler Holmwood</strong> documents how these containers work in practice which will similarly hopefully inspire others on how to approach such problems. </p><blockquote><p>We usually have to reverse engineer what we write about here, but this time Microsoft is putting it all out in the open. This is a tour of what the source does: one dispatcher binary, a JSON policy model, and ten containment backends. The backends get the most attention, because that is where policy turns into real enforcement, from AppContainer capability SIDs and Job Object UI limits to Hyper-V micro-VMs and macOS Seatbelt profiles. There are also newly documented Windows API functions and some sneak-peeks into upcoming Preview build functionality.</p></blockquote><p><a href="https://www.originhq.com/research/mxc-execution-containers-internals">https://www.originhq.com/research/mxc-execution-containers-internals</a></p><h2>Package Proxy</h2><p><strong>Jacob Torrey</strong> releases this work aid for those wrestling with the supply chain issues and developer security. </p><blockquote><p>It relies on Cloudflare Workers so it is very tied to Cloudflare, but similar ideas can be implemented elsewhere. The released Package Proxy implements these checks out the box:</p><ul><li><p>Ensures packages are at least 10 days old (PyPI, npm, cargo)</p></li><li><p>Where the package upload mechanism is visible, check that it has not regressed (PyPI, npm)</p></li><li><p>Bypass for explicit audit fix steps (npm)</p></li><li><p>Block list (PyPI, npm, cargo)</p></li><li><p>Allow list (PyPI, npm, cargo)</p></li></ul></blockquote><p><a href="https://blog.thinkst.com/2026/06/introducing-package-proxy-supply-chain-safety-checks-without-client-side-software.html">https://blog.thinkst.com/2026/06/introducing-package-proxy-supply-chain-safety-checks-without-client-side-software.html</a></p><h2>DriverSentinel</h2><p><strong>404: Sleep not found releases</strong> this tool which will support hunt teams wrestling with bring your own vulnerable drivers.</p><blockquote><p>DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the LOLDrivers.io database.</p></blockquote><p><a href="https://github.com/bI8d0/DriverSentinel">https://github.com/bI8d0/DriverSentinel</a></p><h2>pydepgate</h2><p><strong>Ikari</strong> releases a set of heuristics which will help catch some of the open source supply chain capabilities. </p><blockquote><p>A zero dependency lightweight static analyzer designed for adversarial-shape code in python to detect supply chain attacks before they reach your interpreter.</p></blockquote><p><a href="https://github.com/nuclear-treestump/pydepgate">https://github.com/nuclear-treestump/pydepgate</a></p><h2>SkillSpector</h2><p><strong>NVIDIA</strong> release </p><blockquote><p>Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks before installing agent skills.</p><p>AI agent skills (used by Claude Code, Codex CLI, Gemini CLI, etc.) execute with implicit trust and minimal vetting. Research shows that 26.1% of skills contain vulnerabilities and 5.2% show likely malicious intent.</p></blockquote><p><a href="https://github.com/nvidia/skillspector">https://github.com/nvidia/skillspector</a></p><h2>Prempti</h2><p><strong>Falco</strong> bring observability to to coding agents.</p><blockquote><p>Prempti brings Falco to the world of AI coding agents. It gives you guardrails that can deny or ask for confirmation on unwanted behaviors, plus real-time visibility into every tool call your coding agent makes &#8212; shell commands, file writes, reads, API calls. Both are driven by Falco rules you can customize to fit your workflow.</p><p>By default, Prempti runs in guardrails mode: rules produce verdicts that shape what the agent does. When a tool call is blocked or flagged, the agent receives an LLM-friendly explanation of why and adapts &#8212; the policy guides behavior through feedback. If you prefer pure observation without intervention, switch to monitor mode: every tool call proceeds while rules still evaluate and log the activity.</p></blockquote><p><a href="https://github.com/falcosecurity/prempti">https://github.com/falcosecurity/prempti</a></p><h2>Operationalising Post Quantum TLS Automated Configuration Profiling and Hybrid PQC Deployment in Financial Infrastructure</h2><p><strong>Harish Balaji, Aarav Varshney, Prasanna Ravi, Sripal Jain, Robin Foe, Jorden Seet, Huaxiong Wang,  Kwok-Yan Lam,</strong> and  <strong>Anupam Chattopadhya</strong> give a hint as to an approach which can be used to accelerate real-world deployment of PQC where robust implementations and protocols exist.</p><blockquote><p>This paper presents a configuration parsing methodology that automatically extracts and normalises TLS cryptographic posture across dominant enterprise web server stacks, producing a unified, provenance traced cryptographic inventory as a foundation for migration and compliance. We demonstrate the approach on 8,443 real world Nginx configurations from public repositories and in a proof of concept deployment at a financial institution, where MLKEM and hybrid MLKEM key exchanges at TLS termination points (web server and API gateway) securing an internal application, with zero application layer changes and manageable performance overhead.</p></blockquote><p><a href="https://arxiv.org/abs/2605.17955">https://arxiv.org/abs/2605.17955</a></p><h1>Incident Writeups &amp; Disclosures</h1><p>How they got in and what they did.</p><h2>RHSB-2026-006 Supply chain compromise of @redhat-cloud-services npm packages</h2><p><strong>Redhat</strong> details..</p><blockquote><p>Preliminary analysis indicates that a compromised GitHub account was used to push unauthorized commits to repositories in the RedHatInsights GitHub organization. Red Hat engineering removed compromised versions from npm following disclosure. Red Hat is continuing to conduct build system and dependency tracking analysis to confirm no product builds contained compromised package versions. Based on current findings, no actions from customers are required.</p></blockquote><p><a href="https://access.redhat.com/security/vulnerabilities/RHSB-2026-006">https://access.redhat.com/security/vulnerabilities/RHSB-2026-006</a></p><h2>You do surprise me.exe: An unexpected executable in Hola Browser</h2><p><strong>Sophos</strong> detail this supply chain incident.</p><blockquote><p>[We] recently identified an unexpected executable delivered alongside Hola Browser (version 1.251.91.0). The executable, <strong>me.exe</strong>, was not listed as a certified component, and appears to be a crypto-miner.</p><p>After the issue was reported through the certification program, Hola reported that they had fixed their delivery pipeline, removing the condition that led to the undeclared component being bundled with Hola Browser.</p></blockquote><p><a href="https://www.sophos.com/en-us/blog/you-do-surprise-me-exe-an-unexpected-executable-in-hola-browser">https://www.sophos.com/en-us/blog/you-do-surprise-me-exe-an-unexpected-executable-in-hola-browser</a></p><h1>Vulnerability</h1><p>Our attack surface.</p><h2>Signal macOS Desktop App Doesn&#8217;t Actually Delete Messages When it Should</h2><p><strong>Fria Reyes</strong> summarises <strong>Harry Sintonen</strong>&#8217;s work..</p><blockquote><p>Security researcher <a href="https://infosec.exchange/@harrysintonen/116618393246317371">Harry Sintonen</a> disclosed that the macOS desktop Signal app doesn&#8217;t <a href="https://sintonen.fi/advisories/signal-deleted-but-not-forgotten.txt">actually delete messages</a> when they&#8217;re deleted in the UI of the app.</p><p>Sintonen explains that the macOS Signal app uses an SQLcipher database, essentially a SQLite database with encryption, meaning it inherits features from SQLite.</p><p>All transactions are written to a log file, which is then merged into the actual database once a certain threshold of pages is reached in the log file.</p><p>The default threshold in Signal is 1000 pages, a number that Sintonen says can take potentially several days to reach, depending on how busy your Signal app is.</p></blockquote><p><a href="https://www.privacyguides.org/news/2026/05/29/signal-macos-desktop-app-doesnt-actually-delete-messages-when-it-should/">https://www.privacyguides.org/news/2026/05/29/signal-macos-desktop-app-doesnt-actually-delete-messages-when-it-should/</a></p><p></p><h2>CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities</h2><p><strong>Palo Alto Networks</strong> details..</p><blockquote><p>Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS&#174; software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.</p></blockquote><p><a href="https://security.paloaltonetworks.com/CVE-2026-0257">https://security.paloaltonetworks.com/CVE-2026-0257</a></p><h2>When &#8220;Moderate&#8221; Means &#8220;Sometimes&#8221;</h2><p><strong>Andrew Schwartz </strong>details an unpatched vulnerability which can lead to NTLM leakages.</p><blockquote><p><strong>Same bug class. No CVE. No fix</strong>. The NTLM leakage primitive in the Windows search: URI handler is technically identical to CVE-2026-33829 in the Snipping Tool. Same severity rating, same mechanism, same potential impact. Microsoft closed it without a CVE or a patch, describing its triage process as &#8220;case-by-case.&#8221;</p><p><strong>A CVSS score of 4.3 doesn&#8217;t capture the real-world risk.</strong> This bug requires no malware and no complex exploit chain. A single link click can leak a user&#8217;s NTLMv2 hash to an attacker-controlled server before Windows even renders an error message. The victim may never download anything malicious at all.</p></blockquote><p><a href="https://www.huntress.com/blog/unpatched-ntlm-leak-windows-search-uri-handler">https://www.huntress.com/blog/unpatched-ntlm-leak-windows-search-uri-handler</a></p><h2>How OLTs may have exposed entire ISP networks</h2><p><strong>Mathieu Farrell</strong> detailed this in early May, but I missed it at the time and it highlights ISP attack surfaces.. </p><blockquote><p>An Optical Line Terminal (OLT) is the central device in a Fiber-To-The-Home (FTTH) network that connects and manages all customer connections, making it a critical control point in an ISP's infrastructure for delivering high speed Internet. This article uncovers how unauthenticated access to OLTs can lead to a full network takeover starting by exploiting exposed vulnerable devices, showing how to pivot into the cloud-based fleet manager using other vulnerabilities, and then compromising an ISP's entire infrastructure.</p></blockquote><blockquote></blockquote><p><a href="https://blog.quarkslab.com/how-olts-may-have-exposed-entire-isp-networks.html">https://blog.quarkslab.com/how-olts-may-have-exposed-entire-isp-networks.html</a></p><h1>Offense</h1><p>Attack capability, techniques and trade-craft. </p><h2>Adversarial Oracles: LLM-Guided EDR Signature Reduction</h2><p><strong>Michael Weber</strong> details how they applied AI to attempt to evade EDR signatures which will be of interest to vendors and blue teams alike.</p><blockquote><p>Bigger profiles consistently beat smaller ones, and the gap was larger than we expected. Moving from a moderate-sized profile to a substantially larger one cut Microsoft Wacatac ML detection by several multiples on the same payload. The &#8220;useful enough to disguise a Go runtime&#8221; threshold sits well above what most off-the-shelf open-source projects produce, which turned suitable-candidate hunting into a research task in its own right.</p><p>Building larger candidates from source didn&#8217;t always help. Hoping to brute-force the problem, we built profiles from kubectl, kube-apiserver, and a handful of other Cloud Native Computing Foundation heavyweights. The symbol tables came back smaller than we&#8217;d guessed. Kubernetes is broad horizontally, but most of its packages are thin and dependency-driven. The projects that produced the densest symbol tables were the ones with heavy plugin or backend-implementation patterns, where a single core type spawns dozens of method receivers per backend. Volume of code matters less than volume of distinct typed methods.</p><p>Stripping the names entirely was the worst option. Just to confirm the direction, we also ran a small batch with -ldflags=&#8221;-s -w&#8221;, the same conventional binary-shrinking advice that lit up CrowdStrike on the goffloader experiment up top. It produced the same result here: CrowdStrike and Symantec hit immediately. ML treats the absence of expected debug data as suspicious in its own right.</p></blockquote><p><a href="https://www.praetorian.com/blog/llm-edr-signature-reduction/">https://www.praetorian.com/blog/llm-edr-signature-reduction/</a></p><h2>AzureRedOps</h2><p><strong>Mr.Un1k0d3r</strong> released this capability which should act as a good corpus to ensure log coverage and detection.</p><blockquote><p>AzureRedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID and Azure tenants. It wraps the most common red-team workflows &#8212; authentication, token management, directory enumeration, privilege checking, password spraying, and post-exploitation actions against Microsoft Graph &#8212; behind one consistent <code>--activity</code> driven CLI.</p></blockquote><p><a href="https://github.com/Mr-Un1k0d3r/AzureRedOps">https://github.com/Mr-Un1k0d3r/AzureRedOps</a></p><h2>Visual Studio Extensions Revisited</h2><p><strong>Dominic Chell</strong> walks through how to build malicious VSIXs..</p><blockquote><p>The most likely infection vector for extensions compromise of either an existing, legitimate extesion, as was the case of GitHub&#8217;s infection, or introduction of a new extension to the marketplace to gain installs over time. Both of these are potential avenues for supply chain attack. However, they may be more complex to detect, given the additional detection flexibility. This is more often given to developer environments and is a common place for this type of extensions where privileged access is needed for running, debugging, scripting and other means of reflective code execution.</p></blockquote><p><a href="https://www.mdsec.co.uk/2026/05/visual-studio-extensions-revisited/">https://www.mdsec.co.uk/2026/05/visual-studio-extensions-revisited/</a></p><h2>Bring Your Own RWX Region DLL (BYORWXDLL)</h2><p><strong>S12 - 0x12Dark Development</strong> details this technique..</p><blockquote><p>The core idea is simple: if a target process already has one of these DLLs loaded, or if we can force it to load one, we get a writable and executable memory region without calling <code>VirtualAllocEx</code> or <code>VirtualProtectEx</code>, two of the most monitored API calls in modern EDR detection pipelines. This reduces the syscall noise of a classic shellcode injection</p></blockquote><p><a href="https://medium.com/@s12deff/bring-your-own-rwx-region-dll-byorwxdll-0283951d34e9">https://medium.com/@s12deff/bring-your-own-rwx-region-dll-byorwxdll-0283951d34e9</a></p><h2>NuGet Code Execution As A Service</h2><p>Jim Rush details there is a mark of web gap &#8230;</p><p><a href="https://tierzerosecurity.co.nz/2026/06/02/nuget-code-execution.html">https://tierzerosecurity.co.nz/2026/06/02/nuget-code-execution.html</a></p><h1>Exploitation</h1><p>What is being exploited..</p><h2>Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)</h2><p><strong>Rapid7</strong> show they detect exploitation within 4 days..</p><blockquote><p>On May 13, 2026, Palo Alto Networks published a security <a href="https://security.paloaltonetworks.com/CVE-2026-0257">advisory</a> for CVE-2026-0257, a medium severity authentication bypass affecting PAN-OS and Prisma Access when a specific configuration is present. Successful exploitation of this vulnerability allows a remote unauthenticated attacker to successfully establish a VPN connection through the GlobalProtect gateway of an affected appliance.</p><p>Rapid7 MDR identified successful exploitation across numerous customers, however we did not observe any indication of successful lateral movement from the devices. The earliest date for observed exploitation was May 17, 2026.</p></blockquote><p><a href="https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/">https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/</a></p><h1>Tooling and Techniques</h1><p>Low level tooling and techniques for attack and defence researchers</p><h2>Defending Code Reference Harness</h2><p><strong>Eugene Yan</strong> and <strong>Michael Molash</strong> release this harness..</p><blockquote><p>A reference implementation for autonomous vulnerability discovery and remediation with Claude, based on our learnings from <a href="https://www.anthropic.com/glasswing">partnering with security teams at several organizations</a> since launching Claude Mythos Preview. For a write up of these learnings along with best practices, see the <a href="https://claude.com/blog/using-llms-to-secure-source-code">accompanying blog post</a> (also available in <code>blog-post.md</code>).</p></blockquote><p><a href="https://github.com/anthropics/defending-code-reference-harness">https://github.com/anthropics/defending-code-reference-harness</a></p><h1>Footnotes</h1><p>Some other small (and not so small) bits and bobs which might be of interest.</p><ul><li><p>Annual, quarterly and monthly reports</p><ul><li><p><em>Nothing overly of note this week, but keep an eye on</em> <a href="https://github.com/jacobdjwilson/awesome-annual-security-reports/tree/main/Annual%20Security%20Reports/2026">the Awesome Annual Security Reports 2026 collection</a></p></li></ul></li><li><p><a href="https://interisle.net/insights/cybercriminaldomaindemand">Malicious Registrations in the Domain Name Market: An Analysis of 2025 gTLD Registrations and Cybercriminal Demand</a></p></li><li><p><a href="https://www.sciencedirect.com/science/article/pii/S0164121225002092?via%3Dihub">On the adoption of software bill of materials in open-source software projects</a></p></li><li><p>Artificial intelligence</p><ul><li><p>Fundamental</p><ul><li><p><em>Nothing overly of note this week&#8230;</em></p></li></ul></li><li><p>Applied non-cyber</p><ul><li><p><a href="https://arxiv.org/abs/2605.27360">GENESIS: Harnessing AI Agents for Autonomous 6G RAN Synthesis, Research, and Testing</a></p></li><li><p><a href="https://arxiv.org/abs/2605.27531">Agentic Separation Logic Specification Synthesis</a></p></li></ul></li><li><p>Applied cyber specific</p><ul><li><p><a href="https://cleverhans.io/latest-research.html">AI Agents Enable Adaptive Computer Worms</a></p></li><li><p><a href="https://arxiv.org/abs/2605.28146">Cybersecurity AI (CAI) Dataset</a></p><ul><li><p>the data sets - <a href="https://aliasrobotics.com/datasets.php">https://aliasrobotics.com/datasets.php</a></p></li></ul></li><li><p><a href="https://arxiv.org/abs/2606.04460">CyberGym-E2E: Scalable Real-World Benchmark for AI Agents&#8217; End-to-End Cybersecurity Capabilities</a></p></li><li><p><a href="https://arxiv.org/abs/2606.00856">GCVE: A Decentralized Model for Vulnerability Identification, Publication, and Operational Enrichment</a></p></li><li><p><a href="https://arxiv.org/abs/2605.29963">Honeyval: A Comprehensive Evaluation Framework for LLM-powered HTTP Honeypots</a></p></li><li><p><a href="https://arxiv.org/abs/2606.02644">A New Framework for Cybersecurity Refusals in AI Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2605.25435">Security of OpenClaw Agents: Fundamentals, Attacks, and Countermeasures</a></p></li><li><p><a href="https://arxiv.org/abs/2605.29901">Dissecting the Black Box: Circuit-Level Analysis of LLM Vulnerability Detection</a></p></li><li><p><a href="https://arxiv.org/abs/2605.21956">Detecting Offensive Cyber Agents: A Detection-in-Depth Approach</a></p></li><li><p><a href="https://arxiv.org/abs/2605.29224">Relevance as a Vulnerability: How Web Retrieval Degrades Safety Alignment in LLM Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2605.26156">Turning Bias into Bugs: Bandit-Guided Style Manipulation Attacks on LLM Judges</a></p></li><li><p><a href="https://mp.weixin.qq.com/s/pbieEet9VCR5iLhjViokIA">Harness Engineering Evolution, Defense, and My Reflections on AI Penetration Testing Agent</a></p></li><li><p><a href="https://arxiv.org/abs/2605.29960">Hijacking Agent Memory: Stealthy Trojan Attacks Through Conversational Interaction</a></p></li><li><p><a href="https://arxiv.org/abs/2605.29737">Minimal Prompt Perturbations Lead to Code Vulnerabilities: Prompt Fragility and Hidden-State Signals in Coding LLMs</a></p></li><li><p><a href="https://arxiv.org/abs/2605.29269">HunterAgent: Neuro-Symbolic Attack Trace Reconstruction under Anti-Forensics</a></p></li><li><p><a href="https://mp.weixin.qq.com/s/tQv3tzBxzCFUiLXMeO0H0w">AI Agent Isolation Model and Security Boundary from a System Perspective</a></p></li><li><p><a href="https://github.com/Ed1s0nZ/CyberStrikeAI/blob/main/README_CN.md">CyberStrikeAI</a> - <em>CyberStrikeAI is an AI-native security testing platform built on Go. It integrates over 100 security tools, an intelligent orchestration engine, role-based testing with preset security testing roles, a skills system with professional testing skills, complete test lifecycle management capabilities, and built-in lightweight C2 (Command &amp; Control) capabilities for authorized scenarios (listeners, encrypted communication, sessions and tasks, real-time events, REST and MCP collaboration).</em></p></li></ul></li></ul></li><li><p>Books</p><ul><li><p><em>Nothing overly of note this week&#8230;</em></p></li></ul></li><li><p>Events</p><ul><li><p><a href="https://opensourcecryptowork.shop/2026/">OSCW 2026: Open Source Cryptography Workshop</a> - slides etc</p></li><li><p><a href="https://www.youtube.com/playlist?list=PLeeS-3Ml-rpo3zh9xaf0CzKHNOkNjqOH2">The Real World Crypto Symposium</a> - videos</p></li></ul></li></ul><p>Finally finally the <a href="https://creators.spotify.com/pod/profile/national-cyber-security-c6/episodes/The-Ransomware-Ecosystem-e2hi088">NCSC&#8217;s podcast series</a>.</p><div><hr></div><p><em>Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them. </em></p><p><em>This newsletter is subject to the NCSC website terms and conditions which can be found at <a href="https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions">https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions</a> and you can find out more about how will treat your personal information in our privacy notice at <a href="https://www.ncsc.gov.uk/section/about-this-website/privacy-statement">https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.</a></em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CTO at NCSC - Cyber Defence Analysis! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CTO at NCSC Summary: week ending May 31st]]></title><description><![CDATA[&#8220;Organisations need to be ready to counter the enhanced capabilities of AI-powered attacks. Act now and learn more about frontier AI.&#8221;]]></description><link>https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-016</link><guid isPermaLink="false">https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-016</guid><dc:creator><![CDATA[Ollie Whitehouse]]></dc:creator><pubDate>Sat, 30 May 2026 08:29:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/Pbdt5DQ6hAQ" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to the weekly highlights and analysis of the&nbsp;<a href="https://infosec.pub/c/blueteamsec?dataType=Post&amp;sort=New">blueteamsec</a>&nbsp;(and my wider reading). Not everything makes it in, but the best bits do. A community member is doing <a href="https://briefing.workshop1.net/">daily AI generated podcast of the last 24hours of posts</a>.</p><p>Operationally this week open source supply chain issues continue to rumble on - see below&#8230;</p><p>In the high-level this week:</p><ul><li><p><a href="https://www.gchq.gov.uk/speech/gchq-annual-lecture-2026-as-delivered">GCHQ Annual Lecture 2026 - as delivered</a>  - <strong>Anne Keast-Butler</strong> delivers - <em>&#8220;And China is now a tech superpower with sophisticated cyber, intelligence and military capabilities.&#8221;</em> .. &#8220;<em>The National Cyber Security Centre &#8211; a part of GCHQ - plays a key role in protecting the data highways and junctions that connect our lives, from the NHS and National Grid to the emerging data economy that is powering the AI revolution.&#8221; .. &#8220;In the past few months, GCHQ has developed the blueprint for a new national cyber defence capability will hardwire cutting-edge agentic AI into machine speed cyber defence.&#8221;</em></p></li><li><p><a href="https://www.ncsc.gov.uk/frontier-ai">Frontier AI: what you need to know</a> - <strong>NCSC</strong> UK launches - <em>&#8220;Organisations need to be ready to counter the enhanced capabilities of AI-powered attacks. Act now and learn more about frontier AI.&#8221;</em></p></li><li><p><a href="https://www.ncsc.gov.uk/blogs/designing-secure-access-with-ztna">Designing secure access with ZTNA</a> - <strong>NCSC</strong> UK publishes - <em>&#8220;ZTNA is widely deployed, but often still built on old trust assumptions. New NCSC guidance explains how to design ZTNA architectures aligned with zero trust principles.&#8221;</em></p></li><li><p><a href="https://www.gov.uk/government/speeches/plan-to-toughen-protections-for-subsea-internet-cables-liz-lloyds-speech-at-rusi">Plan to toughen protections for subsea internet cables: Liz Lloyd's speech at RUSI</a> - <strong>Department for Science, Innovation and Technology</strong> and <strong>Baroness Lloyd of Effra CBE </strong>publish -<strong> </strong><em><strong>&#8220;</strong>Speaking at the Royal United Services Institute (RUSI) on Friday 29 May 2026, telecoms minister Liz Lloyd set out plans to consult on tougher fines and prison sentences for those who damage subsea infrastructure essential for UK internet access.&#8221;</em></p><ul><li><p><a href="https://www.gov.uk/government/news/plan-to-toughen-protections-for-subsea-internet-cables-amid-heightened-russian-activity">Plan to toughen protections for subsea internet cables amid heightened Russian activity</a> - <strong>Department for Science, Innovation and Technology</strong> and <strong>Baroness Lloyd of Effra CBE </strong>outline</p></li></ul></li><li><p><a href="https://www.gov.uk/government/publications/energy-sector-cyber-security-strategy">Energy sector cyber security strategy</a> - <strong>Department for Energy Security and Net Zero</strong>, <strong>National Cyber Security Centre</strong>, <strong>National Energy System Operator</strong> and <strong>Ofgem </strong>publish - <em>&#8220;A roadmap for government, regulators and industry to strengthen cyber security and resilience across the Great British energy sector, supporting Clean Power 2030.&#8221;</em></p></li><li><p><a href="https://www.bankofengland.co.uk/speech/2026/may/liz-oakes-speech-and-panel-at-the-kpmg-and-fitch-ratings-london-banking-summit">Operational resilience in a rapidly changing world </a>&#8722; <strong>Bank of England </strong>outlines - <em>&#8220;Liz Oakes sets out the growing importance of operational and cyber resilience in the context of advancing technology. She underlines the expectations on firms to develop effective risk management frameworks as the first line of defence. Liz also highlights the work of regulators and policymakers to ensure resilience against these evolving risks&#8221;</em></p></li><li><p><a href="https://www.gov.uk/government/news/security-and-defence-partnership-treaty-the-projects-the-uk-and-poland-will-deliver-together">Security and Defence Partnership Treaty: the projects the UK and Poland will deliver together</a> - <strong>British Embassy Warsaw</strong> detail -  <em>&#8220;We will work together on two fronts: on defensive cyber through our respective militaries, focusing on achieving mutual goals, protecting common interests, and responding effectively to the growing threats in the cyber domain. We will also work across civilian agencies sharing approaches on cyber deterrence, attributions of hostile activity and cyber sanctions and responses.&#8221;</em></p></li><li><p><a href="https://cyberdefensereview.army.mil/CDR-Content/Articles/Article-View/Article/4499689/the-missing-grammar-of-cyber-operations-toward-a-theory-of-cyber-operational-art/">The Missing Grammar of Cyber Operations: Toward a Theory of Cyber Operational Art</a> - <strong>Edward Cardon</strong> and <strong>Charles Harry</strong> essay - <em>&#8220;This essay argues that cyber lacks a mature operational grammar that allows commanders to arrange tactical actions in time, space, and purpose to achieve strategic objectives. Current doctrine is still relevant: it is the grammar used to implement that doctrine that differs for terrain, maneuver, fires, and effects, tempo, risk, and command. A separate theory of war or a new planning framework is not needed. What is needed is the understanding that the cyber terrain is socio-technical at its core, maneuver is positional, fires often consume access, tempo is governed by adaptation, risk accumulates over time, and command requires judgment across distributed authorities and consequences.&#8221;</em></p></li><li><p><a href="https://www.whitehouse.gov/wp-content/uploads/2026/05/M-26-14-Ensuring-Effective-and-Efficient-Agency-Logging-and-Network-Visibility-to-Defend-Against-Evolving-Cyber-Threats.pdf">Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats</a> - <strong>The White House</strong> (not me) outlines - <em>&#8220;In organizing and resourcing their logging activities, agencies must prioritize two objectives - Continuous Event Monitoring (CEM) and Threat Hunting, Investigation, Response, and Forensics (THIRF)&#8221;</em></p></li><li><p><a href="https://www.gao.gov/products/gao-26-109159">Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector</a> - <strong>US Government Office of Accountability</strong> audits - <em>&#8220;Threat actors, such as state-sponsored hackers or criminal groups, are increasingly capable of carrying out cyberattacks on water and wastewater systems. This capability comes from the increasing connections between operational technologies&#8212;which control valves, pumps, and other physical devices&#8212;and internet-enabled devices. Internet-enabled devices can provide remote access to control pumps and other infrastructure. Remote access can be helpful over large and widely distributed water and sewer systems.&#8221;</em></p><ul><li><p>related from March - <a href="https://www.governor.ny.gov/news/governor-hochul-announces-first-nation-cybersecurity-regulations-and-grants-protect-new-york">Governor Hochul Announces First-in-Nation Cybersecurity Regulations and Grants to Protect New York Water Systems</a></p></li></ul></li><li><p><a href="https://www.oig.doc.gov/reports/?entry=70787">Evaluation of NIST &#8217;s Management of the National Vulnerability Database</a> - <strong>US</strong> <strong>Office of Inspector General</strong> evaluates - <em>&#8220;Our evaluation found that NIST&#8217;s management of the National Vulnerability Database has not been sufficient to resolve the backlog of unprocessed vulnerabilities or to keep pace with the growing volume of vulnerability submissions.&#8221;</em></p></li><li><p>Reporting on/from China</p><ul><li><p><a href="https://warontherocks.com/machine-overmatch-what-salt-typhoon-reveals-about-chinas-data-centric-intelligence-strategy/">Machine Overmatch: What Salt Typhoon Reveals About China&#8217;s Data-Centric Intelligence Strategy</a> - <strong>Ashley Ruiz</strong>  outlines - <em>&#8220;Salt Typhoon&#8217;s multi-year cyber campaigns against U.S. telecommunications networks and critical infrastructure demonstrate China&#8217;s unparalleled focus on data-centric espionage: collect widely, analyze fast, and operationalize at scale &#8212; alongside continued investments in traditional intelligence disciplines. This approach reshapes how the United States has conventionally thought about intelligence advantage.&#8221;</em></p></li><li><p><a href="/__u/netaskari.substack.com/p/sharp-eyes-how-to-track-a-foreigner">Sharp Eyes: Mass surveillance of foreigners in China - Part 1</a> - <strong>NetAskari</strong> alleges - <em>&#8220;NetAskari got exclusive access to a web front-end demonstrating a remote tracking system especially for foreigners. It is developed for the Public Security Bureau in the region of Zhangjiakou (a prefecture of Hebei province about 60 km west of Beijing).&#8221;</em></p></li><li><p><a href="https://www.gao.gov/products/gao-26-107668">Selected Agencies Have Taken Steps to Address Risks of Equipment Linked to China</a> - <strong>US Government Office of Accountability</strong> audits - <em>&#8220;The six agencies we reviewed have searched for vulnerable equipment connected to their IT networks. Specifically, they looked for equipment produced by certain companies linked to the People's Republic of China. Two of the agencies, the Departments of Defense and Energy, found a small number of vulnerable devices and have efforts underway to address any risks they pose. For example, DOD blocked these devices from accessing their network.&#8221;</em></p></li><li><p><a href="https://www.cac.gov.cn/2026-05/22/c_1780934265963919.htm">The China Federation of Internet Societies officially released the &#8220;China Internet Integrity Development Report (2026)&#8221;</a> - <strong>Cyber Administration of China</strong> announces - <em>&#8220;The report concludes that in 2025, the state vigorously promoted the construction of online integrity at the level of laws and regulations. Relevant departments such as the Cyberspace Administration of China and the State Administration for Market Regulation issued institutional documents on internet platform pricing behavior rules, supervision and management of live-streaming e-commerce, and the application security of facial recognition technology. They also carried out a series of special "Clean Internet" campaigns to address the abuse of AI technology and the chaos in self-media, urging and guiding websites and platforms to fulfill their main responsibilities. &#8220;</em></p><ul><li><p><a href="https://www.cac.gov.cn/2026-05/22/c_1780934267673084.htm">China Internet Integrity Development Report (2026)</a> -  <strong>Cyber Administration of China</strong> releases </p></li></ul></li><li><p><a href="https://www.intelligenceonline.com/asia-pacific/2026/05/29/beijing-fights-back-against-foreign-extraterritorial-laws,110775646-art">Beijing fights back against foreign extraterritorial laws</a> - <strong>Intelligence Online</strong> reports - <em>&#8220;The Politburo has convened a series of meetings with representatives from the foreign affairs sector and the business community in China to rally diplomats and the diaspora against extraterritorial legislation&#8221;</em></p></li><li><p><a href="https://www.scmp.com/tech/article/3354371/commercial-humanoid-robots-china-may-soon-do-laundry-make-beds-care-elders">Commercial humanoid robots in China may soon do laundry, make beds, care for elderly</a> - <strong>South China Morning Post</strong> reports - <em>&#8220;GigaAI unveiled the country&#8217;s first general-purpose household humanoid robot model on Wednesday, the SeeLight S1, in collaboration with Hubei Humanoid Robot Innovation Centre and Hubei Humanoid Robotics Industry Alliance.&#8221;</em></p></li><li><p><a href="https://www.alibabagroup.com/en-US/document-1994119844504535040">Alibaba Unveils New AI Chip, Flagship Model, and Rebuilt Cloud Stack AI for Agentic Era</a> - <strong>Alibaba</strong> announce - <em>&#8220;The chip delivers three times the performance of its predecessor, Zhenwu 810E, and carries 144 gigabytes (GB) of on-chip memory alongside 800 GB per second of inter-chip bandwidth. It natively supports precision formats from FP32 (32-bit floating-point) down to FP4 (4-bit floating-point), allowing a single device to handle both high-accuracy model training and the rapid, low-cost inference that agent workloads demand.&#8221;</em></p></li></ul></li><li><p> AI</p><ul><li><p><a href="https://www.gov.uk/government/news/uk-and-australia-pact-on-fast-moving-ai-security-risks">UK and Australia pact on fast-moving AI security risks</a> - <strong>Department for Science, Innovation and Technology</strong>, <strong>AI Security Institute</strong> and <strong>Kanishka Narayan MP </strong>detail - <em>&#8220;The UK and Australia agree deeper ties to tackle AI risks, with new partnership between the UK AI Security Institute and the Australian AI Safety Institute.&#8221;</em></p></li><li><p><a href="https://www.bbc.co.uk/news/articles/c3r2zjpryzro">Champion ethical hacker warns AI tools like Mythos will make competing harder</a> - <strong>BBC</strong> reports - <em>"That isn't to say that I think that there's going to be no room for security research or ethical hacking, but I think that a lot of the lower-hanging fruit will start to go away."</em></p></li><li><p><a href="https://rdi.berkeley.edu/blog/exploitgym/">ExploitGym: Can AI Agents Turn Security Vulnerabilities into Real Attacks?</a> - <strong>UC Berkeley, Max Planck Institute for Security and Privacy, UC Santa Barbara, Arizona State University,<sup> </sup>Anthropic, OpenAI</strong>, and <strong>Google</strong> assemble like the avengers - this is a little hyperbole and alarmist as some of the same messages are also true for human found vulns e.g. &#8216;Standard defenses help, but don&#8217;t fully stop AI-driven attacks.&#8217; - but when you read the paper the language is more nuanced e.g. <em>&#8220;First, standard mitigations remain effective barriers, eliminating the majority of agent-generated exploits across all categories. Second, the non-trivial survival rate demonstrates that frontier agents can already adapt their strategies to bypass widely deployed defenses. For example, agents bypass ASLR using partial-pointer overwrites and low-bit brute force; escape the V8 sandbox via known rendezvous primitives such as Wasm dispatch tables [15] and Irregexp bytecode [46]; and bypass KASLR by abusing writable static strings such as modprobe_path and core_pattern [43], or by relying on side-channel leaks [34]. These findings reinforce the importance of defense-in-depth, but highlight that current mitigations alone are likely insufficient to neutralize AI-driven exploitation.&#8221;</em></p></li><li><p><a href="https://vincenzoiozzo.com/blog/oss-models-vuln-research">How harnesses and post-training close the open-weight bug-finding gap</a> - <strong>Vincenzo Iozzo</strong> details - <em>&#8220;Open-weight models trail Opus on harder artifacts, but a good harness closes most of the gap.&#8221;</em></p></li><li><p><a href="https://www.cert-in.org.in/s2cMainServlet?pageid=GUIDLNVIEW02&amp;refcode=CISG-2026-02">Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure</a> - <strong>CERT India</strong> publish - patch between 12 hours and 5 days they state</p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/library/three-studies-technical-solutions-mark-and-detect-ai-generated-content">Three studies on technical solutions to mark and detect AI-generated content</a> - <strong>European Commission</strong> publishes - <em>&#8220;These studies examine the current state of the art of technical solutions for marking and detecting AI-generated content across different modalities, namely text, audio and image/video content.&#8221;</em></p></li><li><p> <a href="https://www.cac.gov.cn/2026-05/22/c_1781191242686496.htm">The &#8220;Guidelines for Ethical and Safety of Artificial Intelligence Applications 1.0&#8221; were released.</a> - <strong>Cyber Administration of China</strong> releases - <em>&#8220;To further guide the application of artificial intelligence in a human-centered and benevolent manner, promote the correct understanding and proper handling of the ethical and safety impacts of artificial intelligence applications by relevant parties, and promote the healthy development of artificial intelligence applications in a standardized, orderly, safe and controllable manner, the "Guidelines" provide ethical and safety concepts and principles for artificial intelligence applications and clarify safety guidelines for the development, service provision and use of artificial intelligence applications.&#8221;</em></p><ul><li><p><a href="https://www.cac.gov.cn/2026-05/22/c_1781191244714906.htm">A Visual Guide to TC260-005: Ethical and Safety Guidelines for Artificial Intelligence Applications 1.0</a></p></li></ul></li><li><p><a href="https://jp.ricoh.com/release/2026/0520_1">Ricoh releases its proprietary safeguard model free of charge.</a> - <strong>Rioch</strong> announces - <em>&#8220;In October 2024, Ricoh launched an internal project aimed at ensuring the safety of LLMs (Limited Language Models). In addition to understanding regulations and technological trends, the company has been working on developing evaluation indicators for LLM safety, developing effective methods to meet safety requirements, and implementing them in society. This safeguard model was developed as part of that effort. In August 2025, a function to identify harmful prompt inputs was released, and in December of the same year, support for detecting harmful output information generated by LLMs was added.&#8221;</em></p></li><li><p><a href="/__u/davidbessis.substack.com/p/the-fall-of-the-theorem-economy">The fall of the theorem economy</a> - <strong>David Bless</strong> forecasts - <em>&#8220;What would happen if, a year from now, the First Proof team released another set of 10 problems of equivalent difficulty? Litt doesn&#8217;t answer this specific question, but he expects AI to autonomously produce results &#8220;at a level comparable to that of the best few papers&#8221; within the next few years.&#8221;</em></p></li><li><p><a href="https://dystopiabench.com/">DystopiaBench: Will the model press the button? </a>- <strong>Matei Anghel</strong> benchmarks - <em>&#8220;A safety benchmark that evaluates whether AI language models can be convinced to comply with dystopian directives through progressive escalation. Tests span registered scenario modules covering infrastructure misuse, surveillance, institutional capture, therapeutic coercion, and other high-stakes failure modes, each with 5 escalation levels from baseline requests to full coercion.&#8221;</em></p></li><li><p><a href="https://www.wired.com/story/us-law-enforcement-warns-of-anti-tech-extremism/">US Law Enforcement Warns of &#8216;Anti-Tech Extremism&#8217; as AI Hatred Grows</a> - <strong>WIRED</strong> reports - <em>&#8220;More than 1,000 pages of unpublished reports from the Department of Homeland Security, FBI, and fusion centers obtained by WIRED show a national shift taking place to surveil this new and worryingly broad category of people and activities deemed an emerging threat.&#8221;</em></p></li></ul></li><li><p><em>Cyber proliferation</em></p><ul><li><p><a href="https://www.reuters.com/business/media-telecom/pentagon-says-us-military-personnel-are-reportedly-being-targeted-using-location-2026-05-28/">Exclusive: US military personnel are being targeted using location data, Pentagon letter shows</a> - <strong>Reuters</strong> reports - <em>&#8220;U.S. forces deployed to &#8203;war zones have been targeted using commercially available location data, according to reports fielded by military officials, an illustration of how &#8204;the global surveillance economy is shaping the battlefield.&#8221;</em></p></li><li><p><a href="https://commsrisk.com/youtube-sms-blaster-ad-displays-scam-messages-that-impersonate-telcos/">YouTube SMS Blaster Ad Displays Scam Messages That Impersonate Telcos</a> - <strong>CommsRisk</strong> reports - <em>&#8220;A new advert shows an SMS blaster impersonating Globe and Smart, the two largest telcos in the Philippines.&#8221;</em></p></li><li><p><a href="https://www.intelligenceonline.com/europe-russia/2026/05/29/financial-fraud-investigator-tracfin-looks-to-build-crypto-asset-and-sigint-capabilities,110775233-bre">Financial fraud investigator Tracfin looks to build crypto asset and SIGINT capabilities</a> - <strong>Intelligence Online</strong> reports - &#8220;<em>Tracfin, the French finance ministry&#8217;s anti-money laundering unit, plans to bolster its capacities in crypto asset tracing and signals intelligence (SIGINT).&#8221;</em></p></li></ul></li><li><p>Bounty Hunting</p><ul><li><p><a href="https://www.justice.gov/opa/pr/romanian-national-sentenced-selling-access-networks-oregon-state-government-office-and-other">Romanian National Sentenced for Selling Access to Networks of Oregon State Government Office and Other U.S. Victims</a> - US <strong>Department of Justice</strong> announce - <em>&#8220;According to court documents, Catalin Dragomir, 46, formerly of Constanta, Romania, sold access to a computer on the network of an Oregon state government office after obtaining unauthorized access to it in June of 2021. During the sale, Dragomir provided the prospective buyer with samples of personal identifying information from the computer. He also sold access to the computer networks of numerous other victims in the United States, causing losses of at least $250,000.&#8221;</em></p></li><li><p><a href="https://www.fiod.nl/fiod-houdt-twee-verdachten-aan-wegens-overtreding-sanctiewetgeving/">FIOD arrests two suspects for violating sanctions legislation</a> - FIOD announces - &#8220;<em>On May 18, 2026, the FIOD arrested a 57-year-old man from Amsterdam and a 39-year-old man from The Hague on suspicion of violating the Sanctions Act. They are suspected of (indirectly) making economic resources available to entities sanctioned by the European Union. Three business premises in Enschede and Almere were searched, as well as two data centers in Dronten and Schiphol-Rijk. During the searches, administrative records, laptops, telephones, and over 800 servers were seized, among other things.&#8221;</em></p></li><li><p><a href="https://blogs.microsoft.com/on-the-issues/2026/05/19/disrupting-fox-tempest-a-cybercrime-service/">Disrupting&#8239;Fox Tempest: A cybercrime&#8239;service that turned &#8220;verified&#8221; software into a pathway for ransomware</a>&#8239; - <strong>Microsoft</strong> announces - <em>&#8220;Today, Microsoft unsealed a legal case in the US District Court for the Southern District of New York targeting a cybercrime service known as Fox Tempest, which, since May 2025, has enabled cybercriminals to disguise malware as legitimate software. The malware-signing-as-a-service (MSaaS) worked by fraudulently accessing and abusing code signing tools, such as Microsoft&#8217;s Artifact Signing, a system designed to verify that software is legitimate and hasn&#8217;t been tampered with. Cybercriminals used the service to deliver malware and enable ransomware and other attacks, infecting thousands of machines and compromising networks worldwide.&#8221;</em></p><ul><li><p><a href="https://www.noticeofpleadings.net/OpFauxSign/files/COMPLAINT/ii.%20Civil%20Complaint.pdf">A fraudulent scheme to obtain and use code signing certificates to deceive victims into downloading dangerous malware under the false belief that it is trusted software</a> - <strong>Microsoft</strong> unseals - <em>&#8220;Plaintiff Microsoft Corporation (&#8220;Microsoft&#8221;), by its attorneys, brings this action against John Does 1&#8211;2 (collectively &#8220;Fox Tempest Defendants&#8221;) and John Does 3&#8211;4 (collectively &#8220;Vanilla Tempest Defendants,&#8221; and together with the Fox Tempest Defendants, &#8220;Defendants&#8221;). Defendants engage in a fraudulent scheme to obtain and use code signing certificates to deceive victims into downloading dangerous malware under the false belief that it is trusted software. Through this scheme, Defendants steal sensitive information from and perpetrate ransomware attacks against Microsoft&#8217;s customers and the public at large.&#8221;</em></p></li></ul></li><li><p><a href="https://www.ncsc.nl/nieuws/gezamenlijke-actie-politie-en-ncsc-legt-groot-botnetwerk-plat">Joint police and NCSC operation shuts down large bot network</a> -<strong> NCSC Netherlands </strong>announce - <em>&#8220;Thanks to a successful collaboration between the police and the National Cyber &#8203;&#8203;Security Centre (NCSC), a large botnet has been taken offline. During this operation, 200 servers were identified and action was taken against them. The servers controlled millions of infected devices, such as computers, tablets, and smartphones, to carry out cyberattacks.&#8221;</em></p></li><li><p><a href="https://www.yna.co.kr/view/AKR20251120107600004">Mastermind behind North Korean cyber operations hackers and gambling site sentenced to 5 years in prison in first trial</a> - <strong>Yonhap News</strong> reports - <em>&#8220;The court further ruled, "The defendant was aware that the money delivered to the North Korean developer could be used as funds for North Korean governance, and commissioned the North Korean developer to develop domestic gambling sites for distribution," adding that "such acts of receiving money pose a risk of endangering the existence and security of our country or the fundamental order of liberal democracy."</em></p></li><li><p><a href="https://www.politie.nl/nieuws/2026/mei/22/pl1100---twee-mannen-aangehouden-voor-phishing.html">Two men arrested for phishing</a> - <strong>Politi Netherlands </strong>announce - <em>&#8220;The men are suspected of selling so-called phishing panels. This is a form of &#8220;Phishing as a Service&#8221; (PhaaS). In this scheme, criminals offer ready-made phishing websites and tools to other criminals. As a result, even people without technical knowledge can carry out phishing attacks. In phishing, victims are tricked into entering personal data, login codes, and bank details on fake websites. Criminals then use this data to steal money from bank accounts.&#8221;</em></p></li></ul></li><li><p>Market Incentives</p><ul><li><p><a href="https://www.reuters.com/legal/government/law-firm-wiley-rein-hit-with-class-action-over-data-breach-tied-chinese-hackers-2026-05-26/">Law firm Wiley Rein hit with class action over data breach tied to Chinese hackers</a> - <strong>Reuters</strong> reports - <em>&#8220;The complaint alleges that cybercriminals accessed Microsoft 365 email accounts belonging to certain Wiley Rein personnel between July 2024 and June 2025 before the firm detected the intrusion last year.&#8221;</em></p></li><li><p><a href="https://www.lexology.com/library/detail.aspx?g=f1e3ec53-5243-4418-8812-960d760c89b7">MSIT Launches Early &#8220;Incident Investigation Review Committee&#8221; for Proactive Security Incident Response </a>- <strong>Lexology</strong> reports - <em>&#8220;South Korea&#8217;s Ministry of Science and ICT (MSIT)&#8221;</em> .. <em>&#8220;The committee is a statutory body established under the revised Information and Communications Network Act. After a string of major breaches in Korea last year, the law grants MSIT authority to conduct ex officio investigations of serious cybersecurity incidents, without waiting for the affected company to self-report, when public harm is at stake. This committee is the deliberative body that reviews and authorizes those investigations, joint public-private response teams, and on-site action.&#8221;</em></p></li><li><p><a href="https://www.sciencedirect.com/science/article/pii/S0167404826001069">The practice of cyber-threat intelligence in organizations: A socio-technical case study of a mature financial organization</a> - <strong>School of Computing and Information Systems, Faculty of Engineering and Information Technology, The University of Melbourne</strong> researches -  <em>&#8220;Our findings reveal a fundamental inversion of established intelligence doctrine - rather than strategic requirements flowing downward from leadership to drive intelligence operations, our case organization generates requirements within technology operations silos, pushing intelligence outward and upward to operational, tactical, and strategic levels. This constitutes a reversal of intelligence norms established in military practice, revealing the unique challenges modern civilian organizations face in operationalizing CTI within complex business environments. Our study reveals a paradox where organizations invest heavily in CTI to address cyber-threats as a strategic priority yet simultaneously create barriers that prevent CTI from delivering strategic value. The root cause of this paradox is the positioning of the CTI function in the lowest level of the organizational structure, the profound knowledge gap between Business and IT Groups, and the prevalence of analytical products that lack strategic relevance or analytical rigor&#8221;</em></p></li></ul></li></ul><p>No reflections this week but there is the keynote I gave at OffensiveCON in Berlin earlier in the month.. thank you for coming to my talk..</p><div id="youtube2-Pbdt5DQ6hAQ" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;Pbdt5DQ6hAQ&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/Pbdt5DQ6hAQ?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Not getting this via email? Subscribe:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Think someone else would benefit? Share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-016?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-016?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p><strong>All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.</strong></p><p>Have a lovely Saturday&#8230;</p><p>Ollie</p><h1>Cyber threat intelligence</h1><p>Who is doing what to whom and how allegedly.</p><h2>Reporting on Russia</h2><h3>How a consultant and a concert pianist from the Netherlands aided pro-Russian hackers</h3><p><strong>Volkskrant</strong> reports on the alleged support to Russia by some based in Europe..</p><blockquote><p>But he is better known as a concert pianist. In Russia, he won prizes at a young age, then received several honours in the Netherlands and graduated cum laude from the conservatory in Enschede. He performed regularly, together with his wife, also born in Russia, at venues in the eastern Netherlands. In 2021 they played pieces by the Russian composer Tchaikovsky on the Oude Markt in Enschede.</p><p>The FIOD suspects him and Z. of violating sanctions law. They are alleged to provide digital infrastructure that is used by Russia for interference, cyberattacks and the spreading of disinformation in the European Union.</p></blockquote><p><a href="https://www.volkskrant.nl/binnenland/how-a-consultant-and-a-concert-pianist-from-the-netherlands-aided-pro-russian-hackers~b60acffb/">https://www.volkskrant.nl/binnenland/how-a-consultant-and-a-concert-pianist-from-the-netherlands-aided-pro-russian-hackers~b60acffb/</a></p><h3>GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations</h3><p><strong>Mohammad Kazem Hassan Nejad</strong> provides a fascinating report on alleged Russian activity in Ukraine. Notable for the use, and ineffective use at that, of generative AI to develop code which introduced a weaknesses which allowed the researchers to understand more.</p><blockquote><ul><li><p>WithSecure identified an ongoing and persistent set of activity targeting Ukraine and Ukraine-related entities since at least August 2025.</p></li><li><p>Based on significant overlaps observed across both development and operational phases of the associated campaigns, WithSecure associates the activities with a threat group tracked as GREYVIBE. At the time of writing, WithSecure has not identified definitive links between GREYVIBE and any previously tracked threat group.</p></li><li><p>The group has leveraged multiple attack vectors, including spear-phishing e-mails, fake captcha pages and fraudulent Ukrainian adult club websites, to deliver malware to a diverse set of victims. The observed victimology includes military, government, civilian, and business-related entities. Across these campaigns, the group has relied on custom developed obfuscators, loaders, and malware. WithSecure additionally identified several associated activity and related campaigns that shared varying degrees of overlap with the group&#8217;s tooling, infrastructure, and tradecraft.</p></li><li><p>The lures, targeting, and observed actions on objectives of the activities align with Russian state interests, particularly in support of intelligence-gathering objectives related to Ukraine in the context of the ongoing Russia-Ukraine war. WithSecure also identified multiple indicators suggesting that the associated developers and operators are Russian-speaking and operate broadly in Russian (Moscow) time zone.</p></li><li><p>While the activities align with Russian state interests, several observed indicators suggest the group has ties to the broader cybercrime ecosystem, with the group potentially involving current or former cybercriminal actors.</p></li><li><p>Moreover, WithSecure found strong evidence suggesting systematic use of generative AI (GenAI) and large language models (LLMs) by GREYVIBE throughout their operation.</p></li><li><p>Taken together, WithSecure assesses GREYVIBE is a low-to-moderately sophisticated group, as reflected in repeated operational security failures, heavy reliance on LLMs, and overall observed tradecraft.</p></li><li><p>Lastly, WithSecure identified design flaws in LegionRelay, a custom malware associated with GREYVIBE that WithSecure assesses was likely developed with LLM assistance. These flaws exposed a limited number of LegionRelay&#8217;s backend functionality which provided WithSecure with research visibility into associated activity over an extended period. This visibility informed WithSecure&#8217;s assessment of the group&#8217;s victimology, actions on objectives, post-compromise tooling, and operational behaviour. Sensitive details pertaining to the observed victimology and actions on objectives as well as information that could aid the threat actor have been deliberately omitted from the report, but could be shared with relevant authorities where appropriate.</p></li></ul></blockquote><p><a href="https://labs.withsecure.com/publications/greyvibe">https://labs.withsecure.com/publications/greyvibe</a></p><h3>Kazuar Evolves From Backdoor to Resilient Espionage Ecosystem</h3><p><strong>The Hivemind</strong> detail the evolution of this alleged Russian state implant which is notable due to the imperative to be able to detect and the continued value they are apparently seeing from doing so.</p><blockquote><ul><li><p>Kazuar now operates as a modular malware ecosystem composed of Kernel, Bridge, and Worker modules.</p></li><li><p>Secret Blizzard uses leadership election and SILENT client architecture to minimize network visibility while maintaining coordinated operations across infected systems.</p></li><li><p>The malware supports multiple IPC mechanisms including named pipes, Mailslots, and hidden Windows messaging, while external communications can occur over HTTP, WebSockets, or Exchange Web Services.</p></li></ul></blockquote><p><a href="https://blog.polyswarm.io/kazuar-evolves-from-backdoor-to-resilient-espionage-ecosystem">https://blog.polyswarm.io/kazuar-evolves-from-backdoor-to-resilient-espionage-ecosystem</a></p><h3>Updated UAC-0057 toolkit: OYSTERFRESH, OYSTERSHUCK and OYSTERBLUES</h3><p><strong>CERT Ukraine</strong> detail an alleged Belarusian campaign which is noteworthy for being able to use Cloudflare to mask their infrastructure.</p><blockquote><p>Since spring 2026, CERT-UA has recorded numerous cases of sending emails to government organizations using compromised accounts, in particular using the topic of obtaining certificates through the online platform Prometheus.</p><p style="text-align: justify;">Typically, an email attachment contains a PDF document with a link that downloads a ZIP archive containing a JS file.</p><p style="text-align: justify;">The mentioned JS file is classified as OYSTERFRESH , which provides display of a decoy document, entry into the operating system registry in an obfuscated and encoded form of the OYSTERBLUES software tool , as well as loading and launching the OYSTERSHUCK component , which acts as a decoder for the mentioned OYSTERBLUES. For decoding, string reversal, ROT13 transformation and URL decoding are sequentially used, in particular.</p><p style="text-align: justify;">In turn, OYSTERBLUES receives information about the computer, including its name, user account, OS version, last OS boot time, and a list of running processes, then sends this data to the management server using an HTTP POST request and expects JS code in response, which is executed using the <em>eval</em> function .</p></blockquote><p><a href="https://cert.gov.ua/article/6315762">https://cert.gov.ua/article/6315762</a></p><h2>Reporting on China</h2><h3>How China-linked threat actors obtain zero-day vulnerabilities</h3><p><strong>Tony Burgess</strong> outlines the alleged approaches employed by China..</p><blockquote><ul><li><p>China-linked threat actors use a coordinated ecosystem to obtain zero-day vulnerabilities, not just individual discoveries.</p></li><li><p>National regulations can require vulnerabilities to be reported to the government before vendors or the public are notified.</p></li><li><p>A large network of researchers, private companies and contractors feeds vulnerability discovery and exploit development.</p></li><li><p>Many attacks rely on rapid exploitation of newly disclosed or reverse-engineered flaws, not just true zero-days.</p></li></ul></blockquote><p><a href="https://blog.barracuda.com/2026/05/21/china-threat-actors-zero-day-vulnerabilities">https://blog.barracuda.com/2026/05/21/china-threat-actors-zero-day-vulnerabilities</a></p><h3>2 PhaaS 2 Furious: The Evolution of Chinese-Language Phishing Services</h3><p><strong>Google Threat Intelligence Group</strong> build of previous reporting of the evolution and capability of alleged Chinese criminal phishing eco-system capability. Noteworthy for regional breakout risk but also underlines the business case for passkeys. </p><blockquote><p>While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground. Google Threat Intelligence Group (GTIG) analyzed a dozen current PhaaS offerings in the Chinese underground, all of them mature services and many likely tied intricately to the broader criminal ecosystem in that region.</p><p>Instead of simply gaining account access, these operations focus on exploiting digital wallet provisioning to transform stolen payment data into tokenized assets within ecosystems. This shift&#8212;combined with the use of encrypted delivery channels like RCS and iMessage to bypass traditional carrier security filters on SMS messages&#8212;represents an emerging development where the goal is no longer just a login, but securing direct, unauthorized control over a victim&#8217;s financial accounts.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!WHDg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F126c167b-ea41-442d-9838-4a5ea37bb1bc_1600x1173.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!WHDg!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F126c167b-ea41-442d-9838-4a5ea37bb1bc_1600x1173.png 424w, /__u/substackcdn.com/image/fetch/$s_!WHDg!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F126c167b-ea41-442d-9838-4a5ea37bb1bc_1600x1173.png 848w, /__u/substackcdn.com/image/fetch/$s_!WHDg!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F126c167b-ea41-442d-9838-4a5ea37bb1bc_1600x1173.png 1272w, /__u/substackcdn.com/image/fetch/$s_!WHDg!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F126c167b-ea41-442d-9838-4a5ea37bb1bc_1600x1173.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!WHDg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F126c167b-ea41-442d-9838-4a5ea37bb1bc_1600x1173.png" width="1456" height="1067" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/126c167b-ea41-442d-9838-4a5ea37bb1bc_1600x1173.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1067,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;https://storage.googleapis.com/gweb-cloudblog-publish/images/phaas-fig1.max-1600x1600.png&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="https://storage.googleapis.com/gweb-cloudblog-publish/images/phaas-fig1.max-1600x1600.png" title="https://storage.googleapis.com/gweb-cloudblog-publish/images/phaas-fig1.max-1600x1600.png" srcset="/__u/substackcdn.com/image/fetch/$s_!WHDg!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F126c167b-ea41-442d-9838-4a5ea37bb1bc_1600x1173.png 424w, /__u/substackcdn.com/image/fetch/$s_!WHDg!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F126c167b-ea41-442d-9838-4a5ea37bb1bc_1600x1173.png 848w, /__u/substackcdn.com/image/fetch/$s_!WHDg!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F126c167b-ea41-442d-9838-4a5ea37bb1bc_1600x1173.png 1272w, /__u/substackcdn.com/image/fetch/$s_!WHDg!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F126c167b-ea41-442d-9838-4a5ea37bb1bc_1600x1173.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://cloud.google.com/blog/topics/threat-intelligence/chinese-language-phishing-services/">https://cloud.google.com/blog/topics/threat-intelligence/chinese-language-phishing-services/</a></p><p>This kit was previously covered by others - <a href="https://spycloud.com/blog/yylaiyu-chinese-phishing-as-a-service-panel/">https://spycloud.com/blog/yylaiyu-chinese-phishing-as-a-service-panel/</a></p><h2>Reporting on North Korea</h2><h3>Analyzing Void Dokkaebi&#8217;s Cython-Compiled InvisibleFerret Malware</h3><p><strong>Kazuki Fujisawa</strong> details the evolution of a North Korean implant which is noteworthy due to the victimology it is deployed to.</p><blockquote><ul><li><p>Void Dokkaebi (aka Famous Chollima) has migrated InvisibleFerret from readable Python scripts to Cython-compiled binaries, distributing the malware as .pyd files on Windows and .so files on macOS.</p></li><li><p>The update gives the intrusion set an additional layer of evasion while preserving InvisibleFerret&#8217;s core capabilities, including backdoor access, browser credential theft, clipboard monitoring, keylogging, and cryptocurrency wallet targeting. BeaverTail has also expanded beyond its original downloader and stealer role into a broader malware with overlapping functions, including credential harvesting and wallet trojanization.</p></li><li><p>The campaign remains especially relevant to software developers, cryptocurrency users, and organizations whose developers have access to wallet credentials, signing keys, CI/CD pipelines, or production systems.</p></li></ul></blockquote><p><a href="https://www.trendmicro.com/en_us/research/26/e/analyzing-void-dokkaebi-invisibleferret-malware.html">https://www.trendmicro.com/en_us/research/26/e/analyzing-void-dokkaebi-invisibleferret-malware.html</a></p><h3>Kimsuky&#8217;s Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant</h3><p><strong>ENKI Whitehat</strong> detail an alleged North Korean campaign which is noteworthy for its victimology but also the telemetry TTP which should provide a detection opportunity. </p><blockquote><ul><li><p>Through April 2026, we identified multiple cases where Kimsuky deployed malware against South Korean military and corporate targets.</p></li><li><p>Kimsuky employed a range of tailored social engineering tactics, such as spoofing security software installation pages and crafting a fake Webex meeting page that leveraged a legitimate meeting schedule.</p></li><li><p>We identified a technique (&#8221;JSONPing&#8221;) in which the distribution page uses JSONP to verify in real time whether the victim has executed the malware.</p></li><li><p>We identified the final payload as an HttpSpy variant, now operating through a new three-stage execution chain (Installer - Loader - HttpSpy) that replaced the previous single-binary architecture.</p></li><li><p>We confirmed several indicators linking to Kimsuky across attack infrastructure, code patterns, and encryption key reuse.</p></li></ul></blockquote><p><a href="https://www.enki.co.kr/en/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant">https://www.enki.co.kr/en/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant</a></p><h2>Reporting on Iran</h2><h3>Fast and Furious &#8211; Nimbus Manticore Operations During the Iranian Conflict</h3><p>Check Point Research</p><blockquote><ul><li><p>The Iranian, IRGC affiliated, threat actor <strong>Nimbus Manticore</strong> resurfaced during Operation Epic Fury, the US military campaign against Iran launched on February 28, 2026, demonstrating newly adopted techniques and enhanced capabilities.</p></li><li><p>The campaign leveraged malicious lures impersonating organizations in the aviation and software sectors across the United States, Europe and the Middle East.</p></li><li><p>For the first time, we observed the use of SEO poisoning as an additional malware delivery method.</p></li><li><p>The operation introduced a previously undocumented backdoor, named <strong>MiniFast</strong>, which appears to incorporate AI-assisted development practices, enabling the threat actor to rapidly develop and adapt tooling while maintaining high operational availability during the war.</p></li><li><p>The actor also used a Zoom installer&#8217;s execution flow and abused it to stage a time-sensitive infection chain for malware deployment while blending into legitimate system activity.</p></li></ul></blockquote><p><a href="https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflict/">https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflict/</a></p><h3>Ababil of Minab: An Iran-Linked Destruction and Exfiltration Campaign Targeting the U.S. and the Middle East</h3><p><strong>Eyal Sela</strong> and <strong>Nir Varon</strong> detail an alleged Iranian aligned destructive hacktivist group which is noteworthy due to the destructive elements. Should serve as a reminder/warning..  </p><blockquote><p>The activity became public in late March and early April 2026, after a pro-Iranian persona calling itself Ababil of Minab claimed to have compromised the Los Angeles County Metropolitan Transportation Authority (LACMTA / LA Metro), destroyed systems, and exfiltrated data. </p><p>Our investigation found that Ababil of Minab is unlikely to be a new, standalone hacktivist crew, as they claim. Forensic evidence ties the operation to infrastructure and activity associated with Black Shadow, an Iran-linked group, which was attributed by the Israel National Cyber Directorate to Iran&#8217;s Ministry of Intelligence and Security. </p><p>The report analyzes the destructive operations the attackers carried out against victim IT, application, virtualization, and backup infrastructure, executed both through scripted automation and through hands-on-keyboard activity. We also expose custom exfiltration tooling used by the attackers and identify additional Israeli and Turkish victim organizations, beyond the ones the group chose to expose.</p></blockquote><p><a href="https://cdn.prod.website-files.com/69944dd945f20ca4a27a7c47/6a155deeaffba9a1bf3c5b63_Ababil_of_Minab_Tech_Report.pdf">https://cdn.prod.website-files.com/69944dd945f20ca4a27a7c47/6a155deeaffba9a1bf3c5b63_Ababil_of_Minab_Tech_Report.pdf</a></p><h3>The War Between Wars: How an IRGC Cyber Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire</h3><p><strong>Profero IRT</strong> detail an alleged Iranian aligned hack and leak operation which is noteworthy due the nature of tradecraft on show and what it means for the information environment.</p><blockquote><p>Through 2025 and 2026, an Iranian state-directed persona has spent the quiet stretches breaking machines, spoiling food, and wiping disks across Israeli industry. This is how one of those operations unfolded, and how to find the actor before it reaches your plant floor.</p><p>..</p><p>Profero assesses with high confidence that Cyber Isnaad Front is a fronted persona operated by or alongside Aria Sepehr Ayandehsazan (ASA), the IRGC-affiliated successor to Emennet Pasargad. ASA, under its earlier name, was sanctioned by the U.S. Treasury for cyber-enabled influence operations against the 2020 U.S. presidential election and has since run a rotating cast of personas against Israeli targets. Infrastructure overlaps, persona patterning, and victim selection all point back to the same operation. When one brand is exposed, the operators retire it and surface a new one. The machinery does not change.</p><p>..</p><p>The public face of Cyber Isnaad Front is a hack-and-leak operation: intrude, steal, curate, and release, paired with scripted videos featuring a costumed human actor and amplified within hours by Iranian state media in Arabic, Hebrew, and English. The persona has claimed defense subcontractors tied to Israel&#8217;s major weapons programs, roughly five terabytes from a national fuel-logistics provider, and access affecting more than 160 telecom data-center customers. Independent researchers, including the Foundation for Defense of Democracies, have found that some of those headline claims do not survive verification, even where genuine victim data also appears in the leaks. Exaggeration is part of the product.</p></blockquote><p><a href="https://profero.io/blog/war-between-wars/">https://profero.io/blog/war-between-wars/</a></p><h2>Reporting on Other Actors</h2><h3>Supply Chain Attacks</h3><p>Various reporting as there are so many. Here is a sample from the past week or so..</p><ul><li><p>Infostealers Just Spawned a 5,000+ Repo GitHub Supply Chain Attack - <a href="https://www.infostealers.com/article/infostealers-just-spawned-a-5000-repo-github-supply-chain-attack/">https://www.infostealers.com/article/infostealers-just-spawned-a-5000-repo-github-supply-chain-attack/</a></p></li><li><p>Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects - <a href="https://socket.dev/blog/malicious-postinstall-hook-found-across-700-github-repos">https://socket.dev/blog/malicious-postinstall-hook-found-across-700-github-repos</a></p></li><li><p>Inside a 176-Package npm Campaign Built to Beat Your Internal Dependencies - <a href="https://www.sonatype.com/blog/inside-a-176-package-npm-campaign-built-to-beat-your-internal-dependencies">https://www.sonatype.com/blog/inside-a-176-package-npm-campaign-built-to-beat-your-internal-dependencies</a></p></li><li><p>Megalodon: Mass GitHub Repo Backdooring via CI Workflows - <a href="https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/">https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/</a></p></li><li><p>Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry&#8217;s Software Development Infrastructure - <a href="https://www.wiz.io/blog/threat-actors-target-crypto-orgs">https://www.wiz.io/blog/threat-actors-target-crypto-orgs</a></p></li></ul><p>Microsoft&#8217;s / Gifthub&#8217;s response in part is </p><ul><li><p>Staged publishing and new install-time controls for npm - <a href="https://github.blog/changelog/2026-05-22-staged-publishing-and-new-install-time-controls-for-npm/">https://github.blog/changelog/2026-05-22-staged-publishing-and-new-install-time-controls-for-npm/</a></p></li></ul><h3>Silent Ransom Group Impersonating IT Personnel through Social Engineering</h3><p><strong>FBI</strong> issue this alert.. </p><blockquote><p>The Silent Ransom Group (SRG), also known as Luna Moth, Chatty Spider, and UNC3753, is targeting law firms using social engineering techniques. Through phone calls and phishing emails, SRG actors pose as IT support to establish access to victim computers and exfiltrate data, usually through legitimate remote access tools or by sending an individual in-person to the victim company&#8217;s location to gain physical access to computers. While SRG has victimized companies in many sectors including those in the insurance, finance, and healthcare industries, the group has consistently targeted US-based law firms since Spring 2023</p></blockquote><p><a href="https://www.ic3.gov/CSA/2026/260526.pdf">https://www.ic3.gov/CSA/2026/260526.pdf</a></p><h3>Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting</h3><p>DFIR report doing what they do best once again. The use of AI for scaled operations and which apparently is undetected by the frontier firms is noteworthy.. </p><blockquote><ul><li><p>We recently discovered an exposed server that was used for multi-victim exploitation, staging, review, and validation.</p></li><li><p>Claude Code and OpenClaw were used as an operator-side harness supporting exploitation activity and workflow orchestration.</p></li><li><p>We identified a large-scale React2Shell (CVE-2025-55182) operation that scanned millions of targets and confirmed 900+ successful exploits. Logs showed an automated pipeline for exploitation, hit scoring, alerting, and secret harvesting.</p></li><li><p>The threat actor exploited victims opportunistically at scale, but post-compromise activity was not indiscriminate. Artifacts show the operator triaged access, validated stolen data, and concentrated deeper collection and follow-on activity on organizations that met a clear value threshold, particularly in the financial, cryptocurrency, and retail sectors.</p></li><li><p>Secret harvesting was a core part of the operation, with tens of thousands of .env files yielding credentials across AI, cloud, payments, messaging, and databases. Artifacts suggest the operator was also validating and prioritizing the most useful access.</p></li><li><p>The host also exposed Telegram-based alerting and command infrastructure tied to the broader Bissa scanner ecosystem, providing rare visibility into the operator&#8217;s notification workflow and public-facing handles.</p></li></ul></blockquote><p><a href="https://thedfirreport.com/2026/04/22/bissa-scanner-exposed-ai-assisted-mass-exploitation-and-credential-harvesting/">https://thedfirreport.com/2026/04/22/bissa-scanner-exposed-ai-assisted-mass-exploitation-and-credential-harvesting/</a></p><h3>Inside SHADOW-WATER-063&#8217;s Banana RAT: From Build Server to Banking Fraud</h3><p><strong>Aldrin Ceriola, Gabriel Nicoleta, Jovit Samaniego</strong> and <strong>Mohamed Fahmy</strong> detail a criminal campaign which highlights the multi-step nature but also some of the operational security considerations being employed.</p><blockquote><ul><li><p>The malware uses layered obfuscation, AES-wrapped payloads, and fileless PowerShell execution to evade detection and persistence controls.</p></li><li><p>Once active, it enables operator-driven fraud through remote input control, keylogging, screen streaming, and Pix QR code interception targeting Brazilian financial institutions.</p></li></ul><p>&#8230;</p><ul><li><p>Delivery: Victims lured via WhatsApp or a possible phishing URL into downloading a malicious batch file (Consultar_NF-e.bat) from a campaign-specific domain &#8211; convitemundial2026[.]com.</p></li><li><p>Staged execution: The batch file launches an obfuscated PowerShell command that silently fetches and runs a second-stage payload (msedge.txt) entirely in memory &#8211; no decrypted file ever touches disk.</p></li><li><p>Notable client capability: The client functions as a full remote fraud and surveillance module, combining real-time screen streaming, operator-driven input control, banking-aware overlay injection, QR/PIX transaction manipulation, and continuous keylogging to enable interactive credential theft and unauthorized financial transaction execution.</p></li><li><p>Attribution: High confidence - Brazilian Portuguese operators, Tetrade-adjacent tradecraft, exclusive targeting of 16 Brazilian financial institutions, and a Pix QR interception subsystem that only exists for the Brazilian market.</p></li></ul></blockquote><p><a href="https://www.trendmicro.com/en_us/research/26/e/banana-rat.html">https://www.trendmicro.com/en_us/research/26/e/banana-rat.html</a></p><h3>Microsoft&#8217;s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows</h3><p><strong>Janos Gergo SZELES</strong> documents what those living in the storm know.. but hopefully Microsoft will take steps to mitigate.</p><blockquote><ul><li><p>MSHTA remains a widely abused Living-off-the-Land binary (LOLBIN) despite being a legacy utility.</p></li><li><p>Attackers use it across multiple malware categories, from commodity stealers to advanced threats.</p></li><li><p>Campaigns frequently rely on multi-stage, fileless execution chains involving PowerShell and HTA scripts.</p></li><li><p>Social engineering plays a critical role, including fake software downloads and ClickFix-style lures.</p></li><li><p>Effective defense requires both user awareness and layered technical controls.</p></li></ul></blockquote><p><a href="https://www.bitdefender.com/en-us/blog/labs/microsofts-mshta-legacy-malware-windows">https://www.bitdefender.com/en-us/blog/labs/microsofts-mshta-legacy-malware-windows</a></p><h2>LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms</h2><p><strong>Keanu Maharaj</strong> highlights how some threat actors have moved to targeting the conversations internet in order to obtain initial access.</p><blockquote><p>Shared conversations on AI chatbot platforms have become the latest delivery mechanism for malware campaigns targeting macOS and Windows users. Attackers create content on platforms like ChatGPT and Claude that appears to offer installation guidance or service updates, then drive traffic to it via search engine results in the form of malvertising and SEO poisoning.</p><p>The content lives on chatgpt.com or claude.ai &#8212; domains that users and security tools trust implicitly &#8212; so the attack bypasses URL reputation checks before the victim even reaches the malicious payload.</p><p>Several variants of this technique have been<a href="https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-claudeai-chats-to-push-mac-malware/"> reported over the past few months</a>. The earliest examples used shared Claude.ai conversations disguised as installation guides &#8212; complete with fake &#8220;Apple Support&#8221; attribution &#8212; that walked users through opening a terminal and pasting a curl command that downloaded and executed an infostealer.<a href="https://www.kaspersky.com/blog/share-chatgpt-chat-clickfix-macos-amos-infostealer/54928/"> Kaspersky documented a parallel campaign</a> using shared ChatGPT conversations to deliver the AMOS (Atomic macOS Stealer) via the same paste-this-command social engineering pattern.</p><p>Push has detected a new variant that goes beyond the previously reported technique of embedding terminal commands in shared conversations: the attacker has used ChatGPT&#8217;s code rendering feature to build a fully designed fake page that mimics a ChatGPT service disruption, redirecting victims to a convincing clone of ChatGPT&#8217;s download page that delivers a malicious executable.</p></blockquote><p><a href="https://pushsecurity.com/blog/llmshare-malvertising-campaign/">https://pushsecurity.com/blog/llmshare-malvertising-campaign/</a></p><h1>Discovery</h1><p>How we find and understand the latent compromises within our environments.</p><h2>Microsoft Authenticator App Details now exposed in Entra SignInLogs</h2><p><strong>Nicola Suter</strong> provides a super power to threat hunting and detection engineering teams.</p><blockquote><p>In response to CVE-2026-41615<strong><a href="https://tech.nicolonsky.ch/til/authenticationappdevicedetails/#fn:1"><sup>1</sup></a></strong> (Microsoft Authenticator Information Disclosure Vulnerability), Microsoft started exposing the used Microsoft Authenticator app details as part of the Entra ID Sign-In Logs in the <code>AuthenticationAppDeviceDetails</code> column. The information can be queried via KQL. Vulnerable builds include versions prior to 6.2605.2973 (Android) and 6.8.47 (iOS), which have been patched.</p></blockquote><p><a href="https://tech.nicolonsky.ch/til/authenticationappdevicedetails/">https://tech.nicolonsky.ch/til/authenticationappdevicedetails/</a></p><h2>Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace</h2><p><strong>Samir Bousseaden</strong> is back with impact with this detection approach&#8230;</p><blockquote><p>We map telemetry fingerprints across both platforms, ship detection rules for both tiers, and contain incidents in under 10 seconds with Elastic Workflows.</p></blockquote><p><a href="https://www.elastic.co/security-labs/tycoon-2fa-aitm-detection-engineering">https://www.elastic.co/security-labs/tycoon-2fa-aitm-detection-engineering</a></p><h2>A Brief Discussion on Behavior Detection Approaches for AI Agents</h2><p>Chinese perspective on how to do effective behavioural detection in an agentic world.</p><blockquote><p>However, for ordinary companies like ours looking to add some protection to their AI agents, we suggest avoiding the EBPF route; it&#8217;s troublesome and expensive. There are many cheaper alternatives, such as:</p><ul><li><p>SDK layer guardrails: Frameworks like LangChain and CrewAI have built-in callbacks and audit hooks that are cheap to modify.</p></li><li><p>Gateway layer interception: All LLM calls are routed through the company&#8217;s own gateway. At that layer, prompt scans, tool whitelists, and external connection controls are performed. This is the solution that most companies can implement.</p></li><li><p>Application layer instrumentation: Use OTel to obtain traces. If the application layer is controllable, instrumentation is sufficient and there is no need to access the kernel layer.</p></li></ul></blockquote><p><a href="https://mp.weixin.qq.com/s/ErpOjkTlKhu6QYVahUb_Qw">https://mp.weixin.qq.com/s/ErpOjkTlKhu6QYVahUb_Qw</a></p><h2>np-audit &#8212; npm package auditor</h2><p><strong>Simon Kobler</strong> releases this tool which could be built into a pipeline in order detect and discovery npm which are suspicious.. </p><blockquote><p>Static security analysis for npm packages &#8212; detects obfuscated lifecycle scripts, known vulnerabilities, and malicious patterns <strong>before</strong> they run. Drop-in replacement for <code>npm install</code> and <code>npm ci</code>.</p></blockquote><p><a href="https://github.com/KoblerS/np-audit">https://github.com/KoblerS/np-audit</a></p><h2>A Systematic Literature Review on Machine Learning for Intrusion Detection Systems</h2><p><strong>Ali Ahmed</strong> , <strong>Ramy Mostafa</strong> , <strong>Mahmoud H. Qutqut</strong>  and <strong>Noha Ragab</strong> issue this pre-print with some truth bombs..</p><blockquote><p>The majority of the research studies in this paper report near-perfect accuracy. Investigating such papers reveals that they heavily depend on a handful pool of overused, often outdated datasets. Legacy datasets such as KDDCup99 and NSL-KDD, created over two decades ago, continue to be used in the majority of study papers. This defeats the purpose of using them, since they bear no resemblance to modern attacks (e.g., attacks in modern networks such as the Internet of Things (IoT)). More critically, the literature is almost exclusively dataset-based, with the proposed models trained, validated, and tested on static CSV files, with no real-world deployment, validation, or even cross-dataset validation. </p><p>What prior SLRs, such as [5&#8211;7], lack is recency. These SLRs have become outdated since the domain is rapidly changing. In addition, current SLRs either cover a narrow subdomain or span older periods. They exhibit critical limitations in scope, timeliness, and analytical depth, as shown in Table 1. Hence, a new comprehensive review is urgently required to evaluate the new proposals, accurately map the domain&#8217;s true state, and guide research toward resolving the current challenges. In this work, we make three key contributions listed below: </p><ul><li><p>A novel five-theme taxonomy that includes ensemble pipelines, context-specific designs, datacentric engineering, deep neural architectures, and trustworthiness to organise the fragmented literature. </p></li><li><p>A detailed quantitative analysis of publication trends, dataset usage, and algorithmic preponderance. </p></li><li><p>A critical synthesis determining ongoing methodological gaps, including the absence of realworld validation, adversarial robustness testing, and Explainable AI (XAI). This analysis serves as a guide for future work that prioritises research toward operational relevanc</p></li></ul></blockquote><p><a href="https://www.preprints.org/frontend/manuscript/77d59744fd591eea279750da52b15011/download_pub">https://www.preprints.org/frontend/manuscript/77d59744fd591eea279750da52b15011/download_pub</a></p><h1>Defence</h1><p>How we proactively defend our environments.</p><h2>Model Context Protocol (MCP): Security Design Considerations for AI-Driven Automation</h2><p>Our peers at the <strong>National Security Agency</strong> publish this important guidance.</p><blockquote><p>This report outlines observed security concerns and patterns from real-world deployments and offers practical recommendations for organizations adopting MCP in high-stakes or production environments. By doing so, it aims to reduce risk while supporting safe innovation in AI-augmented systems. While this guidance is based on the MCP specification, implementations, and currently known issues, it is designed to be extensible and remain relevant as the protocol, implementations, and operations continue to evolve</p></blockquote><p><a href="https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSI_MCP_SECURITY.pdf">https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSI_MCP_SECURITY.pdf</a></p><h2>Zero Trust Implementation Guidelines</h2><p><strong>National Security Agency</strong> publish this collection for those on the part to Zero Trust..</p><p><a href="https://www.nsa.gov/Cybersecurity/ZIG/">https://www.nsa.gov/Cybersecurity/ZIG/</a></p><p>also as a reminder we issued this week <strong>Designing secure access with ZTNA</strong></p><p><a href="https://www.ncsc.gov.uk/blogs/designing-secure-access-with-ztna">https://www.ncsc.gov.uk/blogs/designing-secure-access-with-ztna</a></p><h2>Manage [VSCode] extensions in enterprise environments</h2><p>Microsoft have this guidance which considering the recent Github compromise is worth iterating.</p><blockquote><p>Visual Studio Code extensions enhance productivity but require careful management in enterprise environments to maintain security and compliance. This article covers how IT admins can control extension installation, host a private marketplace, and deploy extensions to users&#8217; machines.</p></blockquote><p><a href="https://code.visualstudio.com/docs/enterprise/extensions">https://code.visualstudio.com/docs/enterprise/extensions</a></p><h2>Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments</h2><p><strong>Seth Art</strong> announces this super powerful resource.. may all clouds follow!</p><blockquote><p>we're thrilled to introduce <a href="https://pathfinding.cloud/labs">Pathfinding Labs</a>, a collection of intentionally vulnerable AWS environments that can be deployed into a sandbox account, exploited, and torn down. They can be used by red teamers and blue teamers alike.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!a7B4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F528a4a5e-7af7-403a-8da7-e6614a17d623_1568x1218.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!a7B4!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F528a4a5e-7af7-403a-8da7-e6614a17d623_1568x1218.png 424w, /__u/substackcdn.com/image/fetch/$s_!a7B4!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F528a4a5e-7af7-403a-8da7-e6614a17d623_1568x1218.png 848w, /__u/substackcdn.com/image/fetch/$s_!a7B4!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F528a4a5e-7af7-403a-8da7-e6614a17d623_1568x1218.png 1272w, /__u/substackcdn.com/image/fetch/$s_!a7B4!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F528a4a5e-7af7-403a-8da7-e6614a17d623_1568x1218.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!a7B4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F528a4a5e-7af7-403a-8da7-e6614a17d623_1568x1218.png" width="1456" height="1131" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/528a4a5e-7af7-403a-8da7-e6614a17d623_1568x1218.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1131,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;How Pathfinding Labs works: blue team and red team workflows from enabling labs to cleanup&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="How Pathfinding Labs works: blue team and red team workflows from enabling labs to cleanup" title="How Pathfinding Labs works: blue team and red team workflows from enabling labs to cleanup" srcset="/__u/substackcdn.com/image/fetch/$s_!a7B4!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F528a4a5e-7af7-403a-8da7-e6614a17d623_1568x1218.png 424w, /__u/substackcdn.com/image/fetch/$s_!a7B4!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F528a4a5e-7af7-403a-8da7-e6614a17d623_1568x1218.png 848w, /__u/substackcdn.com/image/fetch/$s_!a7B4!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F528a4a5e-7af7-403a-8da7-e6614a17d623_1568x1218.png 1272w, /__u/substackcdn.com/image/fetch/$s_!a7B4!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F528a4a5e-7af7-403a-8da7-e6614a17d623_1568x1218.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://securitylabs.datadoghq.com/articles/introducing-pathfinding-labs/">https://securitylabs.datadoghq.com/articles/introducing-pathfinding-labs/</a></p><h2>Introducing EvidenceForge: Synthetic security logs that don&#8217;t look (as) fake</h2><p><strong>David J. Bianco</strong> provides a tool which will be useful to government, industry and academia. Be interesting to see how it holds up and if there is any adverse impact on models trained using it..</p><blockquote><ul><li><p>EvidenceForge helps teams overcome the limitations of anonymized or stale public datasets, while avoiding the cost and complexity of setting up real infrastructure and performing manual attack simulations to create their own.</p></li><li><p>The tool incorporates sophisticated timing models and assigns specific roles to users and systems, generating realistic malicious activity, background noise, and &#8220;red herrings&#8221; to optimize data realism.</p></li><li><p>The tool generates correlated logs across 20+ Windows, Linux, and network monitoring formats using a canonical event model that ensures causal and temporal consistency.</p></li></ul></blockquote><p><a href="https://blog.talosintelligence.com/introducing-evidenceforge-synthetic-security-logs-that-dont-look-as-fake/">https://blog.talosintelligence.com/introducing-evidenceforge-synthetic-security-logs-that-dont-look-as-fake/</a></p><h2>bumblebee</h2><p><strong>Adel</strong> and <strong>Effy Elden</strong>  provide this capability for developer endpoints - curious to understand what it will bring over OSQuery etc..</p><blockquote><p>Bumblebee is a read-only inventory collector for package, extension, and developer-tool metadata on macOS and Linux developer endpoints.</p><p>It answers a narrow supply-chain response question: when an advisory names a package, extension, or version, which developer machines show a match in their on-disk metadata right now?</p></blockquote><p><a href="https://github.com/perplexityai/bumblebee">https://github.com/perplexityai/bumblebee</a></p><h2>OpenShell</h2><p><strong>NVIDIA</strong> release this runtime for AI agents to provide some control.</p><blockquote><p>OpenShell is the safe, private runtime for autonomous AI agents. It provides sandboxed execution environments that protect your data, credentials, and infrastructure &#8212; governed by declarative YAML policies that prevent unauthorized file access, data exfiltration, and uncontrolled network activity.</p></blockquote><p><a href="https://github.com/NVIDIA/OpenShell">https://github.com/NVIDIA/OpenShell</a></p><h2>Workcell</h2><p><strong>Omkhar Arasaratnam</strong> provides this to constrain coding agents so they aren&#8217;t the source of a total compromise..</p><blockquote><p>Workcell runs coding agents inside a bounded local runtime on Apple Silicon macOS: a dedicated Colima VM plus a hardened container inside that VM. It ships Tier 1 adapters for Codex, Claude Code, and Gemini that seed each provider's native control plane without pretending provider config is the security boundary. GitHub Copilot CLI is the next committed Tier 1 provider-parity track, but current releases do not support <code>--agent copilot</code>.</p></blockquote><p><a href="https://github.com/omkhar/workcell">https://github.com/omkhar/workcell</a></p><h2>A CA Built for the Threat Model We Actually Have</h2><p><strong>Ryan Hurst</strong> outlines a vision.. </p><blockquote><p>A Private Cloud Compute style CA gives us a way to make that path visible, attestable, and independently verifiable. The same pattern applies wherever the gap between what we say a system does and what it actually does at runtime matters.</p></blockquote><p><a href="https://unmitigatedrisk.com/?p=1245">https://unmitigatedrisk.com/?p=1245</a></p><h2>Improving C# Memory Safety</h2><p><strong>Richard Lander</strong> details what Microsoft is doing.. be interested in the driver here beyond it being the right thing to do.</p><blockquote><p>We&#8217;re in the process of significantly <a href="https://github.com/dotnet/runtime/issues/125800">improving memory safety in C#</a>. The <code>unsafe</code> keyword is being redesigned to inform callers that they have obligations that must be discharged to maintain safety, documented via a new safety comment style. The keyword will expand from marking pointers to any code that interacts with memory in ways the compiler cannot validate as safe. The compiler will enforce that the <code>unsafe</code> keyword is used to encapsulate unsafe operations. The result is that safety contracts and assumptions become visible and reviewable instead of implied by convention.</p></blockquote><p><a href="https://devblogs.microsoft.com/dotnet/improving-csharp-memory-safety/">https://devblogs.microsoft.com/dotnet/improving-csharp-memory-safety/</a></p><h1>Incident Writeups &amp; Disclosures</h1><p>How they got in and what they did.</p><p><em>Nothing overly of note this week which isn&#8217;t covered under the supply chain section under Threat Intelligence above.</em></p><h1>Vulnerability</h1><p>Our attack surface.</p><h2>FROST: Fingerprinting Remotely using OPFS-based SSD Timing</h2><p><strong>Hannes Weissteiner , Tobias Weiser , Roland Czerny , Sudheendra Raghav Neela , Fabian Rauscher , Jonas Juffinger</strong> , and <strong>Daniel Grus</strong>s likely inspire the advertising eco-system to learn about side-channels.. </p><blockquote><p>In this paper, we show that SSD contention side channels can be mounted by a remote attacker from within the browser, without native code execution. Our attack FROST targets the Origin Private File System (OPFS) API in JavaScript, allowing us to create and access files on the disk, within the browser&#8217;s sandboxed environment. While a challenge in prior work was to evict the OS page cache, we devise an approach that instead bypasses the page cache, enabling fast SSD contention measurements from JavaScript without any user interaction. To evaluate the effectiveness of FROST on macOS and Linux, we build a covert channel that exfiltrates data from a native application to the malicious website with a true channel capacity of 661.63 bit/s on a Linux machine, and 891.77 bit/s on a macOS machine. To evaluate FROST in a side-channel scenario, we mount a website- and an application-fingerprinting attack on users of macOS systems. We can predict accessed websites with an F1 score of 88.95 %, and accessed application with an F1 score of 95.83 %, demonstrating the privacy implications our attack has on regular users.</p></blockquote><p><a href="https://hannesweissteiner.com/pdfs/frost.pdf">https://hannesweissteiner.com/pdfs/frost.pdf</a></p><h1>Offense</h1><p>Attack capability, techniques and trade-craft. </p><h2>Device Code Lab (DCL) &#8212; Deep Dive into a Device Code Phishing Toolkit</h2><p><strong>Paul Newton</strong> dives deep which will be useful to those wanting to devise detection strategies.. </p><blockquote><p>A deep dive into Device Code Lab, a professional grade, device code phishing platform, with numerous defense evasion and post-exploitation features.</p></blockquote><p><a href="https://newtonpaul.com/blog/device-code-lab-post-exploit/">https://newtonpaul.com/blog/device-code-lab-post-exploit/</a></p><h2>OpenPetya</h2><p><strong>Issac</strong> releases this code which has the real potential to cause mischief. </p><blockquote><p>A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++</p></blockquote><p><a href="https://github.com/iss4cf0ng/OpenPetya">https://github.com/iss4cf0ng/OpenPetya</a></p><h2>mkPIVM</h2><p><strong>Dread</strong> releases a tool that detection teams will want to device detection strategies for.</p><blockquote><p>mkPIVM is a polymorphic position-independent shellcode virtualizer for Windows x86 and x64 (Linux soon).</p><p>Feed it raw shellcode. It emits another raw blob: a small virtual machine that interprets a lifted, encrypted-at-rest version of your original instructions. The output is itself position-independent code and runs anywhere the original shellcode would, from a remote-thread loader to a code cave detour. Every per-seed knob varies independently: cipher family, register slot layout, opcode-to-handler permutation, dispatcher topology, junk-gadget pattern, IR obfuscation insertion points. Two builds from the same input share fewer than a hundred coincidental bytes out of tens of kilobytes.</p></blockquote><p><a href="https://github.com/D7EAD/mkPIVM">https://github.com/D7EAD/mkPIVM</a></p><h2>Weaponization and abuse of the SYLK file format</h2><p><strong>Ghost Wolf Lab</strong> highlight this attack surface..</p><blockquote><p>This article further reveals a more serious dimension of abuse: SYLK can directly carry Excel 4.0/XLM macros, and this capability is almost completely unrecognized and undetected in the current security ecosystem. With VBA macros already subject to rigorous monitoring, <code>.slk</code> the resurgence of XLM macros in containers provides attackers with a new, low-risk, high-success-rate channel.</p></blockquote><p><a href="https://blog.ghostwolflab.com/redteam/729/">https://blog.ghostwolflab.com/redteam/729/</a></p><h1>Exploitation</h1><p>What is being exploited..</p><h2>System Notification Abuse: How Attackers Force Microsoft to Send Phishing Emails</h2><p><strong>Aaron Orchard</strong> details some in the wild exploitation.. </p><blockquote><p>Unlike traditional <a href="https://abnormal.ai/blog/credential-phishing-trends-2023">spoofing attacks that impersonate Microsoft</a>, this campaign forces Microsoft&#8217;s legitimate infrastructure to send phishing emails on the threat actors&#8217; behalf.</p><p>To understand the scale of this threat, we analyzed 2,000 unique messages across over 250 abused Microsoft 365 tenants. This data revealed a highly organized &#8220;burn-and-churn&#8221; operation where attackers script the creation of disposable tenants to launch attacks using specific evasion techniques<strong>:</strong></p><ul><li><p><strong>The &#8220;Subject Line Hijack&#8221;:</strong> Injecting 60+ characters of scam text into the tenant name field to force legitimate system text off the screen.</p></li><li><p><strong>Obfuscation:</strong> Using &#8220;ogonek&#8221; substitutions (e.g., replacing &#8220;a&#8221; with the Polish &#8220;&#261;&#8221;) and homoglyphs to defeat optical character recognition (OCR) and keyword blockers.</p></li><li><p><strong>Regex Evasion:</strong> Formatting phone numbers by replacing digits with letters (e.g., swapping &#8220;0&#8221; for &#8220;O&#8221;) to blind security gateways.</p></li></ul></blockquote><p><a href="https://abnormal.ai/blog/system-notification-abuse-microsoft-phishing">https://abnormal.ai/blog/system-notification-abuse-microsoft-phishing</a></p><h2>Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability</h2><p><strong>Takahiro Sugiyama, Peter Revelant</strong> and <strong>Mathew Potaczek</strong> do a retrospective on 2025 exploitation.. </p><blockquote><p>This vulnerability stems from the use of identical pre-shared ASP.NET machine keys across multiple customer deployments. The vulnerability was initially exploited as a zero-day, now tracked as <a href="https://www.cve.org/CVERecord?id=CVE-2026-5426">CVE-2026-5426</a>.</p></blockquote><p><a href="https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability/">https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability/</a></p><h1>Tooling and Techniques</h1><p>Low level tooling and techniques for attack and defence researchers</p><h2>V8 Wasm Type-Confusion Colony</h2><p><strong>Qriousec</strong> show the AI future..</p><blockquote><p>A multi-agent fuzzing system that hunts WebAssembly type-confusion bugs in V8. Instead of running a single fuzzer loop, it runs a <strong>colony</strong> of LLM-driven agents: one <em>queen</em> directs a population of <em>workers</em>, each carrying a <em>genome</em> (a hypothesis about a specific V8 seam where Wasm type soundness might break). The colony is reactive &#8212; workers run continuously, the queen wakes on a cycle to score them, evolve their genomes, and reallocate budget.</p><p>The current production colony is <code>wasm-tc</code>. It targets the seams where Wasm type guarantees cross V8 subsystems: canonicalization, the Turboshaft GC optimizer, JS&#8596;Wasm boundaries, speculative inlining and deopt, and cross-module type sharing.</p></blockquote><p><a href="https://github.com/qriousec/colony_agent/">https://github.com/qriousec/colony_agent/</a></p><h2>How harnesses and post-training close the open-weight bug-finding gap</h2><p>Vincenzo Iozzo details&#8230;</p><blockquote><ul><li><p>Open-weight models trail Opus on harder artifacts, but a good harness closes most of the gap.</p></li><li><p>Post-training matters more than architecture.</p></li><li><p>GLM-5.1, the same base model as GLM-5, is the standout, matching Opus across the board.</p></li></ul></blockquote><p><a href="https://vincenzoiozzo.com/blog/oss-models-vuln-research.html">https://vincenzoiozzo.com/blog/oss-models-vuln-research.html</a></p><h2>angr</h2><p><strong>Angr</strong> team released some time ago but highlighting to to obvious potential when coupled with AI for vulnerability research and malware analysis etc.</p><blockquote><p>angr is a suite of Python 3 libraries that let you load a binary and do a lot of cool things to it:</p><ul><li><p>Disassembly and intermediate-representation lifting</p></li><li><p>Program instrumentation</p></li><li><p>Symbolic execution</p></li><li><p>Control-flow analysis</p></li><li><p>Data-dependency analysis</p></li><li><p>Value-set analysis (VSA)</p></li><li><p>Decompilation</p></li></ul></blockquote><p><a href="https://github.com/angr/angr">https://github.com/angr/angr</a></p><h2>keyhog</h2><p><strong>Santh</strong> releases this which every team should consider..</p><blockquote><p>keyhog scans source trees, git history, Docker images, S3 buckets, and running systems for leaked credentials. 891 service-specific detectors, decode-through (base64/hex/url/protobuf), confidence scoring, SARIF output, zero runtime configuration.</p></blockquote><p><a href="https://github.com/santhsecurity/keyhog">https://github.com/santhsecurity/keyhog</a></p><h1>Footnotes</h1><p>Some other small (and not so small) bits and bobs which might be of interest.</p><ul><li><p>Annual, quarterly and monthly reports</p><ul><li><p><em>Nothing overly of note this week, but keep an eye on</em> <a href="https://github.com/jacobdjwilson/awesome-annual-security-reports/tree/main/Annual%20Security%20Reports/2026">the Awesome Annual Security Reports 2026 collection</a></p></li></ul></li><li><p><a href="https://github.com/shellkraft/Ledger">Ledger &#8212; Operational Change Tracker Aggressor Script</a></p></li><li><p><a href="https://www.qurium.org/forensics/the-future-of-residential-proxies/">The Future and Past of Residential Proxies</a></p></li><li><p><a href="https://www.sciencedirect.com/science/article/pii/S0167404826001069">The practice of cyber-threat intelligence in organizations: A socio-technical case study of a mature financial organization</a></p></li><li><p>Artificial intelligence</p><ul><li><p>Fundamental</p><ul><li><p><a href="https://github.com/NVlabs/GatedDeltaNet-2/blob/main/paper/GDN2_paper.pdf">Gated DeltaNet-2: Decoupling Erase and Write in</a></p><p><a href="https://github.com/NVlabs/GatedDeltaNet-2/blob/main/paper/GDN2_paper.pdf">Linear Attention</a></p></li><li><p><a href="https://arxiv.org/abs/2605.21488v1">Equilibrium Reasoners: Learning Attractors Enables Scalable Reasoning</a></p></li></ul></li><li><p>Applied non-cyber</p><ul><li><p><a href="https://arxiv.org/abs/2605.01428v1">Hallucinations Undermine Trust; Metacognition is a Way Forward</a></p></li><li><p><a href="https://arxiv.org/abs/2605.22763">Advancing Mathematics Research with AI-Driven Formal Proof Search</a></p></li><li><p><a href="https://langsec.org/spw26/slides/vanegue-autospecification.pdf">Large Language Models for Software Autospecification</a></p></li><li><p><a href="https://arxiv.org/abs/2605.23904">SkillOpt: Executive Strategy for Self-Evolving Agent Skills</a></p></li></ul></li><li><p>Applied cyber specific</p><ul><li><p><a href="https://cyb3rops.medium.com/why-i-built-my-own-llm-benchmark-for-thor-finding-triage-c8492e3997dc">Why I Built My Own LLM Benchmark for THOR Finding Triage</a></p></li><li><p><a href="https://github.com/kpolley/redai">RedAI - A terminal workbench for AI-driven vulnerability discovery and live validation.</a></p></li><li><p><a href="https://cert.pl/en/posts/2026/05/autonomous-fuzzing/">Autonomous fuzzing process under LLM supervision</a></p></li><li><p><a href="https://github.com/qriousec/colony_agent/">V8 Wasm Type-Confusion Colony</a></p></li><li><p><a href="https://arxiv.org/abs/2605.21824">Quality-Assured Fuzz Harness Generation via the Four Principles Framework</a></p></li><li><p><a href="https://arxiv.org/abs/2605.21779">FuzzingBrain V2: A Multi-Agent LLM System for Automated Vulnerability Discovery and Reproduction</a></p></li><li><p><a href="https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSI_MCP_SECURITY.pdf">Model Context Protocol (MCP): Security Design Considerations for AI-Driven Automation</a></p></li><li><p><a href="https://mp.weixin.qq.com/s/Rb9HeZRPBu-bkG_iFV5RZQ">Has the tipping point for AI penetration arrived? How did I uncover a 9.8-point RCE 0-day vulnerability in a general-purpose product using pure AI black-box testing?</a> - Chinese</p></li></ul></li></ul></li><li><p>Books</p><ul><li><p><em>Nothing of note this week</em></p></li></ul></li><li><p>Events</p><ul><li><p><a href="https://www.caisconf.org/program/2026/papers/">ACM Conference on AI and Agentic Systems</a> - accepted papers</p><ul><li><p>papers via Alphaxiv - <a href="https://www.alphaxiv.org/acm-cais">ACM Conference on AI and Agentic Systems</a></p></li></ul></li><li><p><a href="https://langsec.org/spw26/abstracts.html">Twelfth LangSec Workshop at IEEE Security &amp; Privacy, May 21, 2026</a> - slides/papers</p></li><li><p><a href="https://www.youtube.com/watch?v=xmhxPZvUtXU&amp;list=PLYvhPWR_XYJkIP2X-uGDsAMIKnhdSauaM">OffensiveCON 2026</a> - videos </p></li></ul></li></ul><p>Finally finally the <a href="https://creators.spotify.com/pod/profile/national-cyber-security-c6/episodes/The-Ransomware-Ecosystem-e2hi088">NCSC&#8217;s podcast series</a>.</p><div><hr></div><p><em>Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them. </em></p><p><em>This newsletter is subject to the NCSC website terms and conditions which can be found at <a href="https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions">https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions</a> and you can find out more about how will treat your personal information in our privacy notice at <a href="https://www.ncsc.gov.uk/section/about-this-website/privacy-statement">https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.</a></em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CTO at NCSC - Cyber Defence Analysis! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CTO at NCSC Summary: week ending May 24th]]></title><description><![CDATA[&#8220;In line with our operational resilience rules and expectations, regulated firms and financial market infrastructures, need to take action to plan for and mitigate cybersecurity risks posed by [AI]"]]></description><link>https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-115</link><guid isPermaLink="false">https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-115</guid><dc:creator><![CDATA[Ollie Whitehouse]]></dc:creator><pubDate>Sat, 23 May 2026 15:17:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!jWls!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336b8411-15b2-4e0f-88df-c113d7011c01_1369x762.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to the weekly highlights and analysis of the&nbsp;<a href="https://infosec.pub/c/blueteamsec?dataType=Post&amp;sort=New">blueteamsec</a>&nbsp;(and my wider reading). Not everything makes it in, but the best bits do. A community member is doing <a href="https://briefing.workshop1.net/">daily AI generated podcast of the last 24hours of posts</a>.</p><p>Operationally this week supply chain attacks continue to be substantial in software eco-systems. The reporting below is extensive from both the cyber threat intelligence providers as well as from victims..</p><p>In the high-level this week:</p><ul><li><p><a href="https://www.bankofengland.co.uk/news/2026/may/boe-fca-and-hm-treasury-joint-statement-on-frontier-ai-models-and-cyber-resilience">The Bank, FCA and HM Treasury joint statement on Frontier AI models and cyber resilience</a> - <strong>Bank of England</strong>, <strong>Financial Conduct Authority</strong> and <strong>HM Treasury</strong> outline - <em>&#8220;In line with our operational resilience rules and expectations, regulated firms and financial market infrastructures (FMIs) (referred to as &#8216;firms&#8217;), need to take action to plan for and mitigate cybersecurity risks posed by frontier AI.&#8221;</em></p></li><li><p>the NCSC funded <a href="https://riscs.org.uk/publications/annual-report/">Research Institute for Sociotechnical Security annual report</a> - <strong>RISCS</strong> publishes - <em>&#8220;If cyber security doesn&#8217;t work for people, it doesn&#8217;t work. Sociotechnical problems and solutions cut across all areas of cyber security, but there are four key themes around which these problems and solutions cluster: </em></p><ul><li><p><em>1. Barriers and Incentives (including Economics) </em></p></li><li><p><em>2. Future Risks and Resilience (including AI) </em></p></li><li><p><em>3. Cultures and Communications (including International Relations) </em></p></li><li><p><em>4. Usability and Trust (including Insider Threat) &#8220;</em></p></li></ul></li><li><p><a href="https://www.gov.uk/government/publications/dsit-cyber-security-newsletter-may-2026/dsit-cyber-security-newsletter-may-2026">DSIT cyber security newsletter - May 2026</a> - <strong>Department for Science, Innovation &amp; Technology </strong>publish - <em>&#8220;New statistics from the <a href="https://www.gov.uk/government/publications/cyber-security-sectoral-analysis-2026">UK cyber security sectoral analysis 2026</a> show strong growth in the sector, with cyber firms generating revenue of &#163;14.7 billion, up 11% on last year. The number of companies is up 20% to 2,603 whilst the sector has created 2,300 new jobs, bringing total direct employment in the sector to 69,600 people.&#8221;</em></p></li><li><p><a href="https://www.gov.uk/government/case-studies/hm-government-licensing-cyber-security-tech-for-a-global-market">HM Government licensing cyber security tech for a global market</a> - <strong>Department for Science, Innovation and Technology</strong> and <strong>Government Office for Technology Transfer </strong>case study - &#8220;<em>Following a competitive process, a global IP licence for SilentGlass has been agreed with a UK&#8209;based company. The device is now available globally. The licensed product will enable wider access to a high&#8209;assurance cyber security solution originally developed for government use, supporting safer deployment of digital technologies and helping share the benefits of public sector innovation more widely across the UK and globally.&#8221;</em></p></li><li><p><a href="https://www.cisa.gov/news-events/news/cisa-enhances-known-exploited-vulnerabilities-catalog-include-new-nomination-form?ref=metacurity.com">CISA Enhances Known Exploited Vulnerabilities Catalog to Include New Nomination Form</a> - <strong>CISA</strong> announce - <em>&#8220;New form bolsters quality of submissions and reinforces community-driven approach to drive down our collective cybersecurity risk&#8221;</em></p></li><li><p><a href="https://edition.cnn.com/2026/05/15/politics/iran-hackers-tank-readers-gas-stations">Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible</a> - <strong>CNN</strong> reports - <em>&#8220;US officials suspect Iranian hackers are behind a series of breaches of systems that monitor the amount of fuel in storage tanks serving gas stations in multiple states, according to multiple sources briefed on the activity. The hackers responsible have exploited automatic tank gauge (ATG) systems that were sitting online and unprotected by passwords, allowing them in some cases to tinker with display readings on the tanks but not the actual levels of fuel in them, the sources said.&#8221;</em></p></li><li><p><a href="https://www.verizon.com/business/resources/reports/dbir/">2026 Data Breach Investigations Report</a> - <strong>Verizon</strong> release - <em>&#8220;31% of breaches now start with software vulnerabilities, beating stolen passwords as the top way attackers get in. Hackers are shifting their focus from tricking people to exploiting systems.&#8221; - </em>still shows than passkeys are important to address the other 59%</p></li><li><p><a href="https://www.gov.pl/web/baza-wiedzy/rekomendacja-pelnomocnika-rzadu-ds-cyberbezpieczenstwa-dotyczaca-komunikatora-signal">Recommendation of the Government Plenipotentiary for Cybersecurity regarding the Signal messenger</a> - <strong>Polish Government</strong> publish - <em>&#8220;The Government Plenipotentiary for Cybersecurity has issued a recommendation to entities within the National Cybersecurity System to mitigate the risks associated with using the Signal messenger. This is due to the increased activity of APT-type hacking groups targeting account takeovers on this messenger.&#8221;</em></p></li><li><p><a href="https://cyber.gouv.fr/actualites/mise-a-jour-du-referentiel-pacs/">Update of the PACS requirements repository to version 2.0</a> - <strong>ANSSI</strong> update - <em>&#8220;For the substantial qualification level, consultants' knowledge and skills are no longer verified through written and oral examinations but through an assessment of the organization and processes implemented by the service provider to verify and maintain the knowledge and skills of its consultants. This new provision will allow PACS (Professional Advisory Services Centers) providing substantial-level services to have a larger pool of consultants, and therefore reduce the time required to obtain a qualified service.&#8221;</em></p></li><li><p><a href="https://www.edpb.europa.eu/our-work-tools/our-documents/opinion-board-art-64/opinion-152026-europrivacy-certification-criteria_en">Opinion 15/2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal to be used as tool for transfers pursuant to Articles 42 and 46 GDPR</a> - <strong>European Data Protection Board</strong> opines - <em>&#8220;Certification mechanisms to be used as a tool for transfers should enable data importers to demonstrate the existence of appropriate safeguards in order to ensure that the level of protection of natural persons guaranteed by the GDPR will not be undermined when transferred personal data will be processed outside the EEA&#8221;</em></p></li><li><p>Reporting on/from China</p><ul><li><p><a href="https://www.rand.org/content/dam/rand/pubs/research_reports/RRA4100/RRA4104-3/RAND_RRA4104-3.pdf">China&#8217;s Science and Technology Strategy in Perspective</a> - <strong>RAND Corporation </strong>publish - <em>&#8220;China&#8217;s S&amp;T system has grown increasingly sophisticated and globally influential, yet its emphasis on control, security, and centralized coordination differentiates it from Western research models that are based on transparency and institutional autonomy. These dynamics&#8212; combining high capacity for technological mobilization with limited openness&#8212;shape both China&#8217;s domestic trajectory and its international partnerships&#8221;</em></p></li><li><p><a href="https://www.csis.org/analysis/why-china-now-peer-competitor-united-states-cyberspace">Why China Is Now a Peer Competitor to the United States in Cyberspace</a> - <strong>Centre for Strategic &amp; International Studies</strong> outlines - &#8220;<em>China has systematically evolved and matured its cyber capabilities over the last 15 years (if not longer), to such an extent that it sets it apart from other U.S. adversaries in cyberspace. Across the full levers of statecraft, whether intelligence, diplomacy, military, economic, or societal levers, China demonstrates an ability to mobilize a whole-of-society approach to dominating cyberspace. And in some specific areas, such as offensive cyber (OC) capabilities, China even outpaces the United States, making it no surprise that the Dutch Military Intelligence and Security Service recently <a href="https://therecord.media/china-cyber-capabilities-match-us-dutch-intel-says">labeled</a> China as being &#8220;on an even footing&#8221; with the United States in OC&#8221;</em></p></li><li><p><a href="https://www.scmp.com/tech/tech-trends/article/3353310/how-bytedance-plans-turn-openclaw-craze-profitable-ai-business?utm_source=twitter&amp;utm_campaign=3353310&amp;utm_medium=share_widget">How ByteDance plans to turn OpenClaw craze into a profitable AI business</a> - <strong>South China Morning Post</strong> reports - <em>&#8220;ByteDance&#8217;s Volcano Engine, the cloud unit that released an <a href="https://www.scmp.com/tech/tech-trends/article/3348829/openclaw-deepens-china-footprint-through-native-tencent-bytedance-integrations?module=inline&amp;pgtype=article">OpenClaw</a>-based cloud agent tool ArkClaw, is betting that the next phase of artificial intelligence will hinge on cheaper tokens, higher inference efficiency and longer context windows. &#8220;Agent-related token consumption still accounts for a single-digit percentage of total token usage, but it is growing,&#8221; said Li Guodong, chief architect of ArkClaw</em></p></li><li><p><a href="https://www.scmp.com/tech/tech-trends/article/3353747/chinas-tech-companies-are-looking-rewrite-e-commerce-playbook-ai-agents?module=top_story&amp;pgtype=section">China&#8217;s tech giants look to rewrite the e-commerce playbook with AI agents </a>- <strong>South China Morning Post</strong> reports - <em>&#8221;Liu is one of China&#8217;s over 900 million e-commerce users taking part in what has become a massive nationwide retail experiment. Tech companies are racing to replace the rigid, traditional search bar with agentic AI, a move aimed at transforming online shopping from the previous routine of manual clicks into a more streamlined, natural dialogue.&#8221;</em></p></li><li><p><a href="https://www.caixinglobal.com/2026-05-15/china-establishes-new-agency-for-the-low-altitude-economy-102444271.html">China Establishes New Agency for the Low-Altitude Economy</a> - <strong>Caixin Global</strong> reports - <em>&#8220;The Low-Altitude Safety Department is responsible for formulating development plans to help develop commercial activity in the airspace close to the ground, including those for coordinating safety and building flight dispatch platforms and service stations, according to information on the website of the Civil Aviation Administration of China (CAAC).&#8221;</em></p></li><li><p><a href="https://www.cac.gov.cn/2026-04/28/c_1779117448652001.htm">China&#8217;s Cyber &#8203;&#8203;Law Development Report (2025) </a>- <strong>Cyberspace Administration of China</strong> publishes </p><ul><li><p><a href="https://www.cac.gov.cn/2026-04/28/c_1779117449523360.htm">Q&amp;A on the &#8220;China Cyber &#8203;&#8203;Law Development Report (2025)&#8221;</a>  - <em>&#8220;As of December 2025, China had promulgated more than 180 laws in the cyber domain, providing a solid institutional guarantee for building a cyber power. <strong>First,</strong> it improved the basic system in the cyber domain, amended the "Cybersecurity Law of the People's Republic of China," enriched the guiding principles for cybersecurity work, clarified the provisions on artificial intelligence security and development, improved the legal liability system, expanded the scope of extraterritorial application, and further consolidated the legal foundation for building a cyber power.&#8221;</em></p></li></ul></li><li><p><a href="https://www.daydaymap.com/research/detail?p=6&amp;c=42">Annual Report on Cyberspace Asset Mapping and Reverse Mapping 2025</a> - <strong>Tsinghua University, Beijing Haidian District Internet Emergency Center, Sichuan University, Shandong Port Technology Group Qingdao Co., Ltd., National University of Defense Technology, Yuanjiang Shengbang Security Technology Group Co., Ltd., China Huadian Corporation</strong>, <strong>Cyberspace Mapping Professional Committee of China Command and Control Society</strong> publish - showing how deeply they think about mapping the Internet.</p></li></ul></li><li><p> AI</p><ul><li><p><a href="https://aria.org.uk/opportunity-spaces/mathematics-for-safe-ai/safeguarded-ai/funding/">Safeguarded AI funding call</a> - NCSC supported <strong>ARIA</strong> announce - &#8220;<em>As part of our <a href="https://aria.org.uk/media/ikrkutfk/safeguarded-ai-programme-thesis-v2.pdf">updated programme thesis</a>, we seek to test and accelerate the hypothesis that AI-enabled formal methods can make high-assurance cyber defence practical at scale. Within Technical Area 2, this funding call pursues the question: given the advances in AI and formal methods, what are the most ambitious, security-critical systems we can verify today?&#8221;</em></p></li><li><p><a href="https://www.anthropic.com/research/glasswing-initial-update">Project Glasswing: An initial update</a> - <strong>Anthropic</strong> publish - of 23,000 candidate findings led to 1,596 reports disclosed </p></li><li><p><a href="https://blogs.cisco.com/security/ai-generated-reporting-lessons-learned-from-talos-incident-response">AI-generated reporting: Lessons learned from Cisco Talos Incident Response</a> - <strong>Cisco</strong> share - <em>&#8220;Various types of inconsistencies in AI output frequently diminish the efficiency gains that AI reporting processes promise to deliver. At their core, most inconsistencies stem from the probability-driven nature of LLMs. These models generate output by predicting the next token, typically a word or sub-word, in a sequence, based on model weights and training data. In essence, this means that no two LLM outputs will be identical, even when provided with the exact same prompt multiple times.&#8221;</em></p></li><li><p><a href="https://www.aisi.gov.uk/blog/will-it-become-harder-to-oversee-ai-systems">Will it become harder to oversee AI systems?</a> - UK <strong>AI Security Institute</strong> discuss - <em>&#8220;In a new report, we map the current landscape of AI oversight, and how it is likely to change. The report draws on 25 expert interviews across frontier AI developers, government, NGOs, and academia, together with a literature review and independent analysis of pathways to the degradation of oversight. We identify current oversight methods, and the properties of current AI systems that these methods rely on. We also examine the pathways by which they could degrade, and the technical levers available to preserve them.&#8221;</em></p></li></ul></li><li><p><em>Cyber proliferation</em></p><ul><li><p><a href="https://www.haaretz.com/israel-news/security-aviation/2026-05-12/ty-article-magazine/.premium/starlink-users-beware-israeli-tech-can-reveal-your-identity/0000019e-17f1-d618-adde-17f3e27d0000">Starlink users, beware &#8211; Israeli tech can reveal your identity</a> - <strong>Haaretz</strong> reports - <em>&#8220;Sold to governments, these systems do not hack into Starlink or intercept its traffic. Instead, sales documents obtained for this investigation revealed that they map the locations of Starlink terminals across the globe, exposing the location of those connecting to the internet through the devices.&#8221;</em></p></li></ul></li><li><p>Bounty Hunting</p><ul><li><p><a href="https://www.justice.gov/usao-ak/pr/canadian-man-arrested-international-authorities-charged-administrating-kimwolf-ddos">Canadian man arrested by international authorities, charged with administrating KimWolf DDoS botnet</a> - US <strong>Department of Justice</strong> announce - <em>&#8220;According to court documents, on April 10, 2026, U.S. authorities criminally charged Jacob Butler, aka &#8220;Dort,&#8221; 23, of Ottawa, Canada, with offenses related to the development and operation of the KimWolf botnet. KimWolf was a DDoS-for-hire service which infected over a million devices worldwide, including devices located in Alaska. The complaint remained sealed pending Butler&#8217;s arrest.&#8221;</em></p></li><li><p><a href="https://www.europol.europa.eu/media-press/newsroom/news/cybercriminal-vpn-used-ransomware-actors-dismantled-in-global-crackdown?ref=metacurity.com">Cybercriminal VPN used by ransomware actors dismantled in global crackdown</a> - <strong>EuroPol</strong> announce - <em>&#8220;A VPN service used by cybercriminals to conceal ransomware attacks, data theft, and other serious offences has been dismantled in an international operation led by France and the Netherlands, with support from Europol and Eurojust.&#8221;</em></p></li><li><p><a href="https://commsrisk.com/chinese-sms-blaster-scammer-attacks-eurovision-in-vienna/">Chinese SMS Blaster Scammer Attacks Eurovision in Vienna</a> - <strong>CommsRisk</strong> reports - <em>&#8220;A 32 year old Chinese national was arrested by Austria's Cobra tactical police unit outside the Eurovision Song Contest. The scammer's 6 year old son was also in the car.&#8221;</em></p></li></ul></li><li><p>Market Incentives</p><ul><li><p><a href="http://koreabizwire.com/korean-regulators-recruit-white-hackers-to-test-financial-apps-and-trading-systems/351083?ckattempt=1">Korean Regulators Recruit Hackers to Test Financial Apps and Trading Systems </a>- <strong>The Korea Bizwire</strong> reports - <em>&#8220;Under the program, participants can search for security flaws in websites, mobile applications and home trading systems operated by financial firms and receive rewards of up to 10 million won, or roughly $7,400, per verified case.&#8221;</em></p></li><li><p><a href="https://arxiv.org/abs/2605.18784">The Insurability Frontier of AI Risk: Mapping Threats to Affirmative Coverage, Silent Exposures, and Exclusions </a>- <strong>AIFT</strong> publish - <em>&#8220;Three patterns emerge. First, affirmative AI coverage is beginning to differentiate by primary risk emphasis: public materials often position Munich Re around model performance and drift, Armilla and parts of the Lloyd&#8217;s market around hallucination and broader AI liability, Tokio Marine Kiln and CFC around IP and technology E&amp;O concerns, Apollo ibott around emerging autonomous system liability, and Coalition around deepfake and AI-enabled cyber response. Second, legacy lines retain silent-AI exposure where AI is an instrumentality rather than the legal cause of loss. Third, foundation model concentration is the clearest genuinely novel insurability frontier because upstream model failure can correlate losses across many cedents at once; the relevant market design question is which insurability constraint each candidate structure relaxes, not merely which systemic risk template exists.&#8221;</em></p></li><li><p><a href="https://www.cityam.com/ms-profit-slumps-in-fallout-from-cyber-attack/">M&amp;S profit slumps in fallout from cyber attack</a> -<strong> CityAM </strong>reports - <em>&#8220;The 141-year-old retailer said it faced a &#8220;year of two halves&#8221; as it battled back to its feet in the first half of the year following the cyber attack, and pushed to return to growth in the second half.&#8221;</em></p></li></ul></li></ul><p>No reflections this week, but I did record a feature with the Patrick and James over at Risky Business. This is around preparation and response to our latent technical debt being surfaced by AI and how we evolve are patching approaches and beyond,,.</p><div id="youtube2-0ygJ6XhDVjw" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;0ygJ6XhDVjw&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/0ygJ6XhDVjw?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Not getting this via email? Subscribe:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Think someone else would benefit? Share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-115?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-115?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p><strong>All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.</strong></p><p>Have a lovely Saturday&#8230;</p><p>Ollie</p><h1>Cyber threat intelligence</h1><p>Who is doing what to whom and how allegedly.</p><h2>Reporting on Russia</h2><p><em>Nothing overly of note this week</em></p><h2>Reporting on China</h2><h3>Introducing Showboat: A new malware family taunts defenses and targets international telecom firms</h3><p><strong>Black Lotus Labs</strong> detail this alleged Chinese operation and capability which is noteworthy for the sector targeting. </p><blockquote><ul><li><p>Black Lotus Labs identified a new Linux malware family we dubbed &#8220;Showboat.&#8221; The campaign has been active since at least mid-2022.</p></li><li><p>Showboat is a modular post-exploitation framework designed for Linux systems, capable of spawning a remote shell, transferring files and functioning as a Socks5 proxy.</p></li><li><p>Multiple threat clusters aligned with the People&#8217;s Republic of China (PRC) have been observed using the same post-exploitation frameworks and techniques in recent years. Showboat was in use by at least one, and likely several, PRC-aligned threat activity clusters.</p></li><li><p>The campaign impacted a telecommunications provider in the Middle East and impersonated telecom firms in Southeast Asia.</p></li><li><p>Black Lotus Labs collaborated with PricewaterhouseCoopers&#8217; Threat Intelligence teams through the research process. We will continue to hunt for samples of this and similar malware to protect our customers and critical infrastructure.</p></li></ul></blockquote><p><a href="https://www.lumen.com/blog/en-us/introducing-showboat-a-new-malware-family-taunts-defenses-and-targets-international-telecom-firms">https://www.lumen.com/blog/en-us/introducing-showboat-a-new-malware-family-taunts-defenses-and-targets-international-telecom-firms</a></p><h3>Inside Red Lamassu&#8217;s JFMBackdoor</h3><p><strong>PwC</strong> pick up the story of the above alleged Chinese operation with further capability analysis which is again noteworthy due to sector focus.</p><blockquote><p>Our analysis revolves around an open directory found during our hunting of Red Lamassu, containing both an aforementioned kworker sample, alongside a fully featured Windows backdoor, which we call JFMBackdoor. Delivered via DLL side-loading, JFMBackdoor supports a range of capabilities, including: remote shell access, file system operations, network proxying, screenshot capture, and self-removal capabilities.</p></blockquote><p><a href="https://www.pwc.com/gx/en/issues/cybersecurity/cyber-threat-intelligence/red-lamassu-open-season.html">https://www.pwc.com/gx/en/issues/cybersecurity/cyber-threat-intelligence/red-lamassu-open-season.html</a></p><h3>Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor</h3><p><strong>DarkTrace</strong> detail this alleged Chinese campaign where the initial access approach is not known.</p><blockquote><p>Beginning in late September 2025, multiple affected hosts were observed making requests to domains impersonating content delivery networks (CDNs), including infrastructure masquerading as Yahoo- and Apple-affiliated services. Across these cases, Darktrace identified a consistent behavioral execution pattern: the retrieval of legitimate binaries alongside malicious Dynamic Link Libraries (DLLs), enabling sideloading and execution of a modular .NET-based Remote Access Trojan (RAT) framework.</p><p>..</p><p>Across cases, the same ordered sequence appears: retrieval of a legitimate executable, (2) retrieval of a matching .config file, (3) retrieval of the malicious</p><p>DLL, (4) repeated DLL downloads over time, and (5) command-and-control (C2) communication. The .config file retrieves a malicious binary, while the legitimate binary provides a legitimate process to run it in.</p><p>Darktrace assesses with moderate confidence that this activity aligns with publicly reported Twill Typhoon tradecraft. The observed use of FDMTP, DLL sideloading, and overlapping infrastructure is consistent with previously observed operations, though not unique to a single actor. While initial access was not directly observed, previous Twill Typhoon campaigns have typically involved spear-phishing.</p></blockquote><p><a href="https://www.darktrace.com/blog/chinese-apt-campaign-targets-entities-with-updated-fdmtp-backdoor">https://www.darktrace.com/blog/chinese-apt-campaign-targets-entities-with-updated-fdmtp-backdoor</a></p><h2>Webworm: New burrowing techniques</h2><p><strong>Eric Howard</strong> detail the capabilities of an alleged Chinese threat actor which is noteworthy due to a pivot in focus to Europe.</p><blockquote><p>ESET researchers analyzed the 2025 activity of Webworm, a China-aligned APT group that started out targeting organizations in Asia, but has recently shifted its focus to Europe. Even though this is our first public blogpost on the group, we have been observing Webworm&#8217;s activities ever since <a href="https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/webworm-espionage-rats">Symantec</a> first reported on this threat actor in 2022. Over the years, we have seen that this threat actor continually changes its tactics, techniques, and procedures (TTPs).</p><ul><li><p>Since its discovery in 2022, the Webworm APT group has been actively updating its toolset and targeting.</p></li><li><p>In 2025, the group started employing backdoors that use Discord and Microsoft Graph API for C&amp;C communication.</p></li><li><p>ESET researchers decrypted over 400 Discord messages and a bash history file discovered on an operator server with reconnaissance commands used against more than 50 unique targets.</p></li><li><p>In addition to backdoors, Webworm leverages multiple existing and custom proxy tools.</p></li><li><p>The group uses GitHub to stage its malware.</p></li></ul></blockquote><p><a href="https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/">https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/</a></p><h3>Suspected China-Linked Threat Actor Targets Global Manufacturer with Undocumented TencShell Malware</h3><p><strong>Idan Tarab,Dr. Guy Waizel,Zohar Buber </strong>and <strong>Shani Kurtzberg </strong> detail an alleged Chinese operation which is noteworthy due to a new implant but also the fact they are using Donut.</p><blockquote><p>[We] identified and blocked an attempted intrusion against a global manufacturing customer involving TencShell, a previously undocumented, Go-based implant derived from the open-source Rshell C2 framework.</p><p>The activity appeared in traffic associated with a third-party user connected to the customer environment.</p><p>The attack chain used a first-stage dropper, Donut shellcode, a masqueraded <em>.woff</em> web-font resource, memory injection, and web-like C2 communication. We assess the activity as suspected China-linked based on the apparent Rshell lineage, Tencent-themed API impersonation, and infrastructure patterns, While this pattern is relevant to our suspected China-linked assessment, it is not sufficient on its own for attribution.</p></blockquote><p><a href="https://www.catonetworks.com/blog/cato-ctrl-suspected-china-linked-threat-actor-targets-global-manufacturer/">https://www.catonetworks.com/blog/cato-ctrl-suspected-china-linked-threat-actor-targets-global-manufacturer/</a></p><h3>From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat</h3><p><strong>Joey Chen</strong> builds on the existing reporting of this alleged Chinese actor and operation. Noteworthy for the intent of search engine optimisation.</p><blockquote><ul><li><p>Cisco Talos has uncovered a BadIIS variant &#8212; identifiable by its embedded &#8220;demo.pdb&#8221; strings &#8212; that functions as commodity malware. This variant is likely sold or shared among multiple Chinese-speaking cybercrime groups that operate under a <a href="https://blog.talosintelligence.com/need-to-know-commodity-malware/">malware-as-a-service (MaaS)</a> model for continuous monetization.</p></li><li><p>Analysis of program database (PDB) file paths reveals a sustained, multi-year development effort by an author operating under the alias &#8220;lwxat&#8221;, spanning from at least September 2021 through January 2026, with evidence of rapid iterative updates, feature branching, and reactive evasion tactics targeting specific security vendors such as Norton.</p></li><li><p>Talos recovered a dedicated builder tool that allows threat actors to generate configuration files, customize payloads, and inject parameters into BadIIS binaries &#8212; enabling capabilities including traffic redirection to illicit sites, reverse proxying for search engine crawler manipulation, content hijacking, and backlink injection for malicious search engine optimization (SEO) fraud.</p></li><li><p>Beyond BadIIS, the same author has developed a suite of auxiliary tools &#8212; including service-based installers, droppers, and persistence mechanisms that automate deployment, ensure survivability across IIS server restarts, and evade detection through custom Base64 encoding and obfuscation techniques.</p></li></ul></blockquote><p><a href="https://blog.talosintelligence.com/from-pdb-strings-to-maas-tracking-a-commodity-badiis-ecosystem/">https://blog.talosintelligence.com/from-pdb-strings-to-maas-tracking-a-commodity-badiis-ecosystem/</a></p><h2>Reporting on North Korea</h2><h3>North Korean-Linked Threat Actor Targets Developers with New npm Infostealer RAT</h3><p><strong>Moshe Siman Tov Bustan</strong> and <strong>Nir Zadok</strong> detail an alleged North Korean operation which is noteworthy due to the alleged actor but also what they are looking to steal and thus have downstream impact around.</p><blockquote><p>The package, &#8216;terminal-logger-utils,&#8217; targets Telegram data, SSH keys, crypto wallets, cloud configurations (AWS, GCP, Azure), environment variables, and more. Three dependent packages import it and trigger the malicious behavior when installed: pretty-logger-utils, ts-logger-pack, and pinno-loggers.</p><p>The threat actor behind the upload &#8211; jpeek895 &#8211; was previously reported on kmsec.uk for uploading a similar npm package linked to DPRK activity.</p></blockquote><p><a href="https://www.ox.security/blog/north-korean-npm-infostealer-rat/">https://www.ox.security/blog/north-korean-npm-infostealer-rat/</a></p><h3>Analysis of APT-C-55 (Kimsuky) group&#8217;s attack activities involving the distribution of malicious payloads via GitHub and Dropbox</h3><p><strong>360 Threat Intelligence Center i</strong>n China report an alleged North Korean operation. The attacks are rudimentary but an important reminder on what to block.</p><blockquote><p>Kimsuky launches a phishing attack via an .lnk file . After the user clicks to run the script , the script within the .lnk file decrypts and opens the bait file to mislead the victim. Simultaneously, it downloads the `taskschd.vbs` script from Dropbox to execute malicious functions. This VBS script then downloads and executes the `downloader` script from the attacker's GitHub repository . The downloader further downloads two Powershell scripts : one uploads basic information about the victim's computer to the attacker's repository and creates a scheduled task to execute ` taskschd.vbs` ; the other, ` ps1` , downloads encrypted data and decrypts an AsyncRAT variant to steal sensitive information.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!P_ye!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f35eea-4bdc-4704-ac5f-44fd1686a3d3_1144x459.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!P_ye!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f35eea-4bdc-4704-ac5f-44fd1686a3d3_1144x459.png 424w, /__u/substackcdn.com/image/fetch/$s_!P_ye!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f35eea-4bdc-4704-ac5f-44fd1686a3d3_1144x459.png 848w, /__u/substackcdn.com/image/fetch/$s_!P_ye!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f35eea-4bdc-4704-ac5f-44fd1686a3d3_1144x459.png 1272w, /__u/substackcdn.com/image/fetch/$s_!P_ye!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f35eea-4bdc-4704-ac5f-44fd1686a3d3_1144x459.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!P_ye!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f35eea-4bdc-4704-ac5f-44fd1686a3d3_1144x459.png" width="1144" height="459" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/66f35eea-4bdc-4704-ac5f-44fd1686a3d3_1144x459.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:459,&quot;width&quot;:1144,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:229332,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ctoatncsc.substack.com/i/198444898?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f35eea-4bdc-4704-ac5f-44fd1686a3d3_1144x459.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!P_ye!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f35eea-4bdc-4704-ac5f-44fd1686a3d3_1144x459.png 424w, /__u/substackcdn.com/image/fetch/$s_!P_ye!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f35eea-4bdc-4704-ac5f-44fd1686a3d3_1144x459.png 848w, /__u/substackcdn.com/image/fetch/$s_!P_ye!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f35eea-4bdc-4704-ac5f-44fd1686a3d3_1144x459.png 1272w, /__u/substackcdn.com/image/fetch/$s_!P_ye!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f35eea-4bdc-4704-ac5f-44fd1686a3d3_1144x459.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><a href="https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247508584&amp;idx=1&amp;sn=3983faed8f799809ecc23eb552e73548&amp;chksm=f9c19161ceb61877f61517327d054439cdf6a076c935ac98b835b78e125c98346e202e3457dc&amp;scene=178&amp;cur_album_id=1955835290309230595&amp;search_click_id=#rd">https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247508584&amp;idx=1&amp;sn=3983faed8f799809ecc23eb552e73548&amp;chksm=f9c19161ceb61877f61517327d054439cdf6a076c935ac98b835b78e125c98346e202e3457dc&amp;scene=178&amp;cur_album_id=1955835290309230595&amp;search_click_id=#rd</a></p><h2>Reporting on Iran</h2><p><em>Nothing overly of note this week</em></p><h3>Iran-linked Operators Suspected in ATG Breaches</h3><p><strong>Censys</strong> drop a truth bomb around an alleged Iranian operation.. </p><blockquote><p>This report follows <a href="https://edition.cnn.com/2026/05/15/politics/iran-hackers-tank-readers-gas-stations">CNN&#8217;s 15 May 2026 report</a> that US officials suspect Iran-linked operators of breaching internet-facing Automatic Tank Gauges (ATGs) at US gas stations. Censys finds 6,502 ATG services on 6,057 hosts (excluding hosts where any service is labeled <code>HONEYPOT</code>) still reachable on the public internet today. Every ATG service indexed in Censys is reachable without authentication. The protocol has no login. A single unauthenticated <code>I20100</code> command returns the station&#8217;s brand, street address, phone number, and live tank readings on 60.1% of these services.</p><ul><li><p>6,502 ATG services on 6,057 hosts in 65+ countries, May 2026. Honeypots excluded.</p></li><li><p>3,907 services (60.1%) leak a full <code>I20100</code> in-tank inventory: station brand, name, address, sometimes a phone number, and live volume / ullage / water-bottom readings.</p></li><li><p>United States: 4,224 hosts (70%). Considered separately, Puerto Rico is second at 350 hosts, of which 347 sit on a single ISP (COQUI-NET / DATACOM CARIBE). Top US ASNs are residential and small-business broadband and cellular ISPs: Verizon Wireless / CELLCO-PART (667), Comcast / CMCS (373), CYBERA Inc. (281), Charter / CHARTER-20115 (241), AT&amp;T (208), UUNET / Verizon Business (171). Comcast and Charter each appear under multiple ASNs in the long tail.</p></li><li><p>Notable brands found running ATG: Shell (602), Mobil (184), BP (78), Texaco (68), Puma (52, LatAm), Marathon (47), Exxon (41), Sunoco (37), Gulf (32), Citgo (31), Chevron (23), Valero (23).</p></li></ul></blockquote><p><a href="https://censys.com/iran-linked-operators-suspected-in-atg-breaches/">https://censys.com/iran-linked-operators-suspected-in-atg-breaches/</a></p><h3>Tracking Iranian APT Screening Serpens&#8217; 2026 Espionage Campaigns</h3><p><strong>Unit42</strong> detail an alleged Iranian operation which is on going with new capability. Noteworthy as it shows continued investments and skill / knowledge evolution.</p><blockquote><p>Screening Serpens primarily targets technology sector professionals, using highly tailored social engineering. The group frequently uses personalized recruitment lures that impersonate trusted brands and hiring platforms, to trick targets into initiating the infection chain.</p><p>We assess with moderate-high confidence that the campaigns discussed in this article are conducted by Screening Serpens. The group has maintained a consistently high operational tempo throughout March and April 2026.</p><p>We have grouped the six newly discovered RAT variants into two new malware families that were deployed in concurrent espionage campaigns. Based on the timing of deployment, our analysis indicates two sets of coordinated cyberattacks. At least one variant was compiled and deployed with specific timing instructions.</p><p>Our analysis reveals a continuous cycle of development and deployment, characterized by specialized and upgraded variants with diverse functionalities, as shown in each targeted campaign.</p><p>The most critical evolution in the group&#8217;s recent campaign uses a technique called AppDomainManager hijacking. This hijack method manipulates the initialization phase of .NET applications to proactively disable the application&#8217;s own security mechanisms via a legitimate configuration file. The disabled security in these apps left the targeted entities vulnerable to the deployed multi-functional RATs.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!jWls!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336b8411-15b2-4e0f-88df-c113d7011c01_1369x762.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!jWls!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336b8411-15b2-4e0f-88df-c113d7011c01_1369x762.png 424w, /__u/substackcdn.com/image/fetch/$s_!jWls!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336b8411-15b2-4e0f-88df-c113d7011c01_1369x762.png 848w, /__u/substackcdn.com/image/fetch/$s_!jWls!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336b8411-15b2-4e0f-88df-c113d7011c01_1369x762.png 1272w, /__u/substackcdn.com/image/fetch/$s_!jWls!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336b8411-15b2-4e0f-88df-c113d7011c01_1369x762.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!jWls!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336b8411-15b2-4e0f-88df-c113d7011c01_1369x762.png" width="1369" height="762" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/336b8411-15b2-4e0f-88df-c113d7011c01_1369x762.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:762,&quot;width&quot;:1369,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;A timeline illustration in the shape of a serpent, depicting a sequence of cyber campaign events from February 2023 to late 2025. Key events include the start of a Middle Eastern phishing campaign, indications of Iranian conflict, and the introduction of malware, MiniJunk V2. MiniUpdate samples were uploaded throughout March in the U.S. and Israel, and in April from the UAE. The campaign is projected to expand globally by late 2025.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A timeline illustration in the shape of a serpent, depicting a sequence of cyber campaign events from February 2023 to late 2025. Key events include the start of a Middle Eastern phishing campaign, indications of Iranian conflict, and the introduction of malware, MiniJunk V2. MiniUpdate samples were uploaded throughout March in the U.S. and Israel, and in April from the UAE. The campaign is projected to expand globally by late 2025." title="A timeline illustration in the shape of a serpent, depicting a sequence of cyber campaign events from February 2023 to late 2025. Key events include the start of a Middle Eastern phishing campaign, indications of Iranian conflict, and the introduction of malware, MiniJunk V2. MiniUpdate samples were uploaded throughout March in the U.S. and Israel, and in April from the UAE. The campaign is projected to expand globally by late 2025." srcset="/__u/substackcdn.com/image/fetch/$s_!jWls!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336b8411-15b2-4e0f-88df-c113d7011c01_1369x762.png 424w, /__u/substackcdn.com/image/fetch/$s_!jWls!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336b8411-15b2-4e0f-88df-c113d7011c01_1369x762.png 848w, /__u/substackcdn.com/image/fetch/$s_!jWls!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336b8411-15b2-4e0f-88df-c113d7011c01_1369x762.png 1272w, /__u/substackcdn.com/image/fetch/$s_!jWls!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336b8411-15b2-4e0f-88df-c113d7011c01_1369x762.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/">https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/</a></p><h2>Reporting on Other Actors</h2><h3>How Storm-2949 turned a compromised identity into a cloud-wide breach</h3><p><strong>Microsoft Defender Security Research</strong> Team detail how some criminal threat actors have cloud skills which is noteworthy if you don&#8217;t have comprehensive defensive coverage of your cloud environment. </p><blockquote><p>Storm-2949 didn&#8217;t rely on traditional malware and other on-premises tactics, techniques, and procedures (TTPs). Instead, they leveraged legitimate cloud and Azure management features to gain control-plane and data-plane access, which they then used to execute code remotely on VMs, and access sensitive cloud resources such as Key Vaults and storage accounts, among others. These activities allowed them to move laterally across cloud and endpoint environments while blending into expected administrative behavior.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!ojAd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dcedc3f-d00a-44c5-af3f-f3ae5e6f70df_836x693.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!ojAd!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dcedc3f-d00a-44c5-af3f-f3ae5e6f70df_836x693.webp 424w, /__u/substackcdn.com/image/fetch/$s_!ojAd!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dcedc3f-d00a-44c5-af3f-f3ae5e6f70df_836x693.webp 848w, /__u/substackcdn.com/image/fetch/$s_!ojAd!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dcedc3f-d00a-44c5-af3f-f3ae5e6f70df_836x693.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!ojAd!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dcedc3f-d00a-44c5-af3f-f3ae5e6f70df_836x693.webp 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!ojAd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dcedc3f-d00a-44c5-af3f-f3ae5e6f70df_836x693.webp" width="836" height="693" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6dcedc3f-d00a-44c5-af3f-f3ae5e6f70df_836x693.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:693,&quot;width&quot;:836,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!ojAd!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dcedc3f-d00a-44c5-af3f-f3ae5e6f70df_836x693.webp 424w, /__u/substackcdn.com/image/fetch/$s_!ojAd!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dcedc3f-d00a-44c5-af3f-f3ae5e6f70df_836x693.webp 848w, /__u/substackcdn.com/image/fetch/$s_!ojAd!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dcedc3f-d00a-44c5-af3f-f3ae5e6f70df_836x693.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!ojAd!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dcedc3f-d00a-44c5-af3f-f3ae5e6f70df_836x693.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.microsoft.com/en-us/security/blog/2026/05/18/storm-2949-turned-compromised-identity-into-cloud-wide-breach/">https://www.microsoft.com/en-us/security/blog/2026/05/18/storm-2949-turned-compromised-identity-into-cloud-wide-breach/</a></p><h3>ZionSiphon OT Malware First Attempts? Psyops? Both?</h3><p><strong>DomainTools</strong> highlight some interesting and important discrepancies which raise more questions than they answer.</p><blockquote><p>ZionSiphon is a malware sample <a href="https://hybrid-analysis.com/sample/07c3bbe60d47240df7152f72beb98ea373d9600946860bad12f7bc617a5d6f5f">(&#8220;SCADA_SecurityPatch_v8.4.exe&#8221;)</a> that has been circulating in public sandboxes since 2025. It is best understood as a Windows-based implant with explicit industrial control system (ICS) targeting intent but with a critical limitation in its verification of geographic data that fundamentally constrains its operational viability. While earlier analysis established the malware as functionally capable at the host level, subsequent findings confirm the presence of a critical XOR bug in its geographic validation logic, preventing the payload from activating in its intended environment. <em>Additionally, there is no evidence of vendor-specific protocol handling, no confirmed register mapping, and no interaction with PLC firmware or engineering toolchains. The malware appears to rely on file-based or high-level configuration manipulation, which may not translate into actual process changes in most industrial environments.</em></p><p>The malware&#8217;s architecture remains coherent and deliberate. It combines geographic scoping, environment-aware execution, and embedded process manipulation logic, demonstrating a structured conceptual model of water treatment and desalination systems. Its internal string corpus provides high-confidence evidence of targeting, including references to Mekorot and major desalination facilities such as Sorek, Hadera, Ashdod, Palmachim, Shafdan, and Eilat water plants in Israel, alongside a dense vocabulary covering reverse osmosis, chlorine dosing, and salinity control. Filesystem-based validation and vendor-associated paths further reinforce that the malware is engineered to identify and operate within specific industrial environments.</p></blockquote><p><a href="https://dti.domaintools.com/research/threat-intelligence-report-zionsiphon">https://dti.domaintools.com/research/threat-intelligence-report-zionsiphon</a></p><h3>The Gentlemen Ransomware Group &#8212; Leak Analysis</h3><p><strong>Alexandre Dulaunoy, Chaitanya H., Dani [Varys] K, Ellis Stannard, Eric Taylor, Jeffrey Bell, Katya K, Nick Smart, Olivier Ferrand, Pedro Moura, Rakesh Krishnan, Vlad G, </strong>and <strong>Val&#233;ry Rie&#223;-Marchive </strong>provide some useful insights from their analysis of this leak from a criminal group.</p><blockquote><p>The Gentlemen are assessed with <strong>moderate-high confidence</strong> to be a <strong>Black Basta successor faction</strong> &#8212; a splinter group formed by experienced Black Basta affiliates and operators who carried forward playbooks, infrastructure access, and operational methodology when Black Basta collapsed in early-to-mid 2025. This is not a rebrand (different leadership structure, different brand identity, different locker), but an <strong>organisational descendant</strong> with direct personnel continuity from the Conti &#8594; Black Basta lineage.</p></blockquote><p><a href="https://ransom-isac.org/blog/the-gentlemen-leak-analysis/">https://ransom-isac.org/blog/the-gentlemen-leak-analysis/</a></p><h3>SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain</h3><p><strong>Phil Stokes</strong> detail an interesting social engineering led campaign.</p><blockquote><p>Reaper uses fake WeChat and Miro installers as lures, but what stands out is the way the infection chain shifts its disguise at each stage. The payload may be hosted on a typo-squatted Microsoft domain, executed under the guise of an Apple security update, and persist from a fake Google Software Update directory. Alongside the previously documented SHub feature set, the build also adds an AMOS-style document theft module with chunked uploads.</p></blockquote><p><a href="https://www.sentinelone.com/blog/shub-reaper-macos-stealer-spoofs-apple-google-and-microsoft-in-a-single-attack-chain/">https://www.sentinelone.com/blog/shub-reaper-macos-stealer-spoofs-apple-google-and-microsoft-in-a-single-attack-chain/</a></p><h3>Living off the Land with VS Code: Inside a Sophisticated Phishing Campaign</h3><p><strong>JoeSecurity</strong> detail a campaign which is interesting for victimology as well as the use of VS Code tunnels etc.</p><blockquote><p>In this blog post, we examine a multi-stage phishing campaign targeting staff members of the Punjab Safe Cities Authority (PSCA) and PPIC3 in Pakistan. The attack leveraged two distinct infection vectors, both relying on the same underlying infrastructure.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!oH7T!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0c9ed5-d74b-49a9-9034-4e4c15511d50_1376x768.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!oH7T!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0c9ed5-d74b-49a9-9034-4e4c15511d50_1376x768.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!oH7T!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0c9ed5-d74b-49a9-9034-4e4c15511d50_1376x768.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!oH7T!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0c9ed5-d74b-49a9-9034-4e4c15511d50_1376x768.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!oH7T!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0c9ed5-d74b-49a9-9034-4e4c15511d50_1376x768.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!oH7T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0c9ed5-d74b-49a9-9034-4e4c15511d50_1376x768.jpeg" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3f0c9ed5-d74b-49a9-9034-4e4c15511d50_1376x768.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!oH7T!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0c9ed5-d74b-49a9-9034-4e4c15511d50_1376x768.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!oH7T!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0c9ed5-d74b-49a9-9034-4e4c15511d50_1376x768.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!oH7T!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0c9ed5-d74b-49a9-9034-4e4c15511d50_1376x768.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!oH7T!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0c9ed5-d74b-49a9-9034-4e4c15511d50_1376x768.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://joesecurity.org/blog/8858614039441223943">https://joesecurity.org/blog/8858614039441223943</a></p><h3>Middle East Malicious Infrastructure Report: 1,350+ C2 Servers Mapped Across 98 Providers</h3><p><strong>Hunt.io</strong> highlight the concentration risk associated with C2 hosting in the middle east.</p><blockquote><ul><li><p>More than 1,350 C2 servers were identified across <strong>98</strong> Middle East infrastructure providers within the past 3 months.</p></li><li><p>C2 infrastructure dominates malicious activity (~96.8%), far exceeding phishing infrastructure (~0.5%) and publicly reported IOCs (~0.5%), while malicious open directories account for the remaining ~2.2% of observed artifacts.</p></li><li><p>Saudi Arabia&#8217;s STC (Saudi Telecom Company) hosts 981 C2 servers, representing 72.4% of all detected C2 infrastructure in the region, the largest concentration observed across any single provider globally.</p></li><li><p>A small set of hosting providers accounts for a disproportionate share of malicious infrastructure, with STC, SERVERS TECH FZCO (UAE), OMC (Israel), T&#252;rk Telekom, and Regxa (Iraq) hosting the largest volumes of detected C2 servers.</p></li><li><p>IoT-focused botnets (Hajime, Mozi, and Mirai) combined with offensive frameworks (Tactical RMM, Cobalt Strike, Sliver) represent the dominant malware families operating across Middle Eastern infrastructure.</p></li><li><p>Middle Eastern hosting environments support diverse malicious operations, including state-sponsored espionage campaigns, MaaS (Malware-as-a-Service) platforms, cryptomining operations, and targeted intrusion activity.</p></li></ul></blockquote><p><a href="https://hunt.io/blog/middle-east-malicious-infrastructure-report">https://hunt.io/blog/middle-east-malicious-infrastructure-report</a></p><h3>Supply Chain Attacks</h3><p>Various reporting as there are so many. Here is a sample from the past week..</p><ul><li><p>TeamPCP compromises NPM maintainer with over 540 packages - <a href="https://opensourcemalware.com/blog/teampcp-compromises-npm-maintainer-with-over-540-packages">https://opensourcemalware.com/blog/teampcp-compromises-npm-maintainer-with-over-540-packages</a></p></li><li><p>Mini Shai-Hulud Hits @antv Ecosystem, 639 Compromised npm Package Versions - <a href="https://socket.dev/blog/antv-packages-compromised">https://socket.dev/blog/antv-packages-compromised</a></p></li><li><p>New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats Are Here - <a href="https://www.ox.security/blog/new-actors-deploy-shai-hulud-clones-teampcp-copycats-are-here/">https://www.ox.security/blog/new-actors-deploy-shai-hulud-clones-teampcp-copycats-are-here/</a></p></li><li><p>Compromised Nx Console version 18.95.0 - <a href="https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w">https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w</a></p></li><li><p>Popular node-ipc npm Package Infected with Credential Stealer - <a href="https://socket.dev/blog/node-ipc-package-compromised">https://socket.dev/blog/node-ipc-package-compromised</a></p></li><li><p>Megalodon: New CI/CD Malware Spreads Across GitHub, Infecting ~5,000+ Repositories - <a href="https://www.ox.security/blog/megalodon-cicd-malware-github/">https://www.ox.security/blog/megalodon-cicd-malware-github/</a></p></li><li><p>Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit - <a href="https://socket.dev/blog/coruna-respawned-compromised-art-template-npm-package">https://socket.dev/blog/coruna-respawned-compromised-art-template-npm-package</a></p></li></ul><h1>Discovery</h1><p>How we find and understand the latent compromises within our environments.</p><p><em>Nothing overly of note this week&#8230;</em></p><h1>Defence</h1><p>How we proactively defend our environments.</p><h2>A blueprint for formal verification of Apple corecrypto - Apple Security Research</h2><p>Apple Security Engineering and Architecture (SEAR) and Hardware Technologies Formal Verification outline their approach to formal verification of their cryptography implementation at least for PQC..</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!jFOi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd366e0e6-86de-44d2-96d5-ff01041dd77a_1300x666.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!jFOi!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd366e0e6-86de-44d2-96d5-ff01041dd77a_1300x666.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!jFOi!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd366e0e6-86de-44d2-96d5-ff01041dd77a_1300x666.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!jFOi!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd366e0e6-86de-44d2-96d5-ff01041dd77a_1300x666.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!jFOi!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd366e0e6-86de-44d2-96d5-ff01041dd77a_1300x666.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!jFOi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd366e0e6-86de-44d2-96d5-ff01041dd77a_1300x666.jpeg" width="1300" height="666" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d366e0e6-86de-44d2-96d5-ff01041dd77a_1300x666.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:666,&quot;width&quot;:1300,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Formal-Verification-Process.jpg&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Formal-Verification-Process.jpg" title="Formal-Verification-Process.jpg" srcset="/__u/substackcdn.com/image/fetch/$s_!jFOi!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd366e0e6-86de-44d2-96d5-ff01041dd77a_1300x666.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!jFOi!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd366e0e6-86de-44d2-96d5-ff01041dd77a_1300x666.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!jFOi!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd366e0e6-86de-44d2-96d5-ff01041dd77a_1300x666.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!jFOi!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd366e0e6-86de-44d2-96d5-ff01041dd77a_1300x666.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://security.apple.com/blog/formal-verification-corecrypto/">https://security.apple.com/blog/formal-verification-corecrypto/</a></p><h2>A Deep Dive into Codex Windows Sandbox</h2><p><strong>Jonathan Johnson</strong> details but makes an important call to action also..</p><blockquote><p>My biggest request to OpenAI, and to any other company building these endpoint AI tools, is logging. Defenders need visibility into what command or code was executed, under which sandbox identity, with which policy, and against which workspace. Even basic structured logs around command execution, sandbox mode, network mode, process identity, and blocked actions would go a long way for detection. Having this custom logging alongside what Windows already provides would add richer context for detection opportunities.</p></blockquote><p><a href="https://jonny-johnson.medium.com/a-deep-dive-into-codex-windows-sandbox-a2489bf4ae91">https://jonny-johnson.medium.com/a-deep-dive-into-codex-windows-sandbox-a2489bf4ae91</a></p><h1>Incident Writeups &amp; Disclosures</h1><p>How they got in and what they did.</p><h2>Investigating unauthorized access to GitHub-owned repositories</h2><p><strong>Github</strong> detail..</p><blockquote><p>On Monday May 18, we detected and contained a compromise of an employee device involving a poisoned VS Code extension published by a third party. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.</p><p>Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker&#8217;s current claims of ~3,800 repositories are directionally consistent with our investigation so far.</p></blockquote><p><a href="https://github.blog/security/investigating-unauthorized-access-to-githubs-internal-repositories/">https://github.blog/security/investigating-unauthorized-access-to-githubs-internal-repositories/</a></p><h2>Our response to the TanStack npm supply chain attack</h2><p><strong>OpenAI</strong> detail.. </p><blockquote><p>On May 11, 2026 UTC, TanStack, a widely used open-source library, was compromised as part of a broader software supply chain attack known as Mini Shai-Hulud.</p><p>Two employee devices in our corporate environment were impacted by this attack. Upon identification of the malicious activity, we worked quickly to investigate, contain, and take steps to protect our systems. As part of our investigation and response, we engaged a third-party digital forensics and incident response firm.</p><p>We observed activity consistent with the malware&#8217;s publicly described behavior, including unauthorized access and credential-focused exfiltration activity, in a limited subset of internal source code repositories to which the two impacted employees had access. We confirmed that only limited credential material was successfully exfiltrated from these code repositories and that no other information or code was impacted.</p></blockquote><p><a href="https://openai.com/index/our-response-to-the-tanstack-npm-supply-chain-attack/">https://openai.com/index/our-response-to-the-tanstack-npm-supply-chain-attack/</a></p><h2>Grafana Labs security update: Latest on TanStack npm supply chain ransomware incident</h2><p><strong>Grafana Labs</strong> details.. </p><blockquote><p>On May 16, 2026, Grafana Labs confirmed a targeted attack by a cybercrime group that gained unauthorized access to our GitHub repositories and downloaded our codebase. They then issued a ransom demand under threat of data disclosure.</p></blockquote><p><a href="https://grafana.com/blog/grafana-labs-security-update-latest-on-tanstack-npm-supply-chain-ransomware-incident/">https://grafana.com/blog/grafana-labs-security-update-latest-on-tanstack-npm-supply-chain-ransomware-incident/</a></p><h2>From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence</h2><p>Microsoft Defender Security Research Team break down an observed end to end compromise which will be useful for defensive teams to understand.</p><blockquote><p>In this incident, the threat actor compromised an internet-facing firewall appliance and used trusted relationships to pivot to an internal Linux host. From there, the threat actor compromised a vulnerable SaaS application and leveraged its credentials to conduct relay-style authentication attacks against Active Directory.</p></blockquote><p><a href="https://www.microsoft.com/en-us/security/blog/2026/05/22/from-edge-appliance-to-enterprise-compromise-multi-stage-linux-intrusion-via-f5-and-confluence/">https://www.microsoft.com/en-us/security/blog/2026/05/22/from-edge-appliance-to-enterprise-compromise-multi-stage-linux-intrusion-via-f5-and-confluence/</a></p><h1>Vulnerability</h1><p>Our attack surface.</p><h2>Google API keys keep working after you delete them</h2><p><strong>Joe Leon</strong> details the 23 minutes of exposure which I suspect will down to database or similar synchronisation. </p><blockquote><p>When you delete a Google API key, it says it&#8217;s immediately deleted. Our testing says ~23 minutes.<strong> </strong>During that window, an attacker with a leaked key keeps access to your data and enabled APIs (including Gemini). You have no way to revoke it faster or confirm when it stops working. Google closed our original report as &#8220;won&#8217;t fix&#8221;.</p></blockquote><p><a href="https://www.aikido.dev/blog/google-api-keys-deletion">https://www.aikido.dev/blog/google-api-keys-deletion</a></p><h2>CVE-2026-45585: Windows BitLocker Security Feature Bypass Vulnerability</h2><p><strong>Microsoft</strong> issues a CVE and provides mitigation..</p><blockquote><p>No, if you are using TPM+PIN the vulnerability is not exploitable.</p></blockquote><p><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585</a></p><h2>FortiAuthenticator Improper access control on API endpoints</h2><p><strong>Fortinet</strong> detail..</p><blockquote><p>An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.</p></blockquote><p><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-128">https://fortiguard.fortinet.com/psirt/FG-IR-26-128</a></p><h2>DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write</h2><p><strong>Kamil Leoniak</strong> details this vulnerability which is interesting training corpus.. </p><blockquote><p>Linux kernel page-cache poisoning via AES-256 chosen-plaintext on the RxGK RESPONSE path and why authenticated encryption did not stop it.</p></blockquote><p><a href="https://delphoslabs.com/blog/36142374-e1fe-80a9-9456-d3c64df81bd5/%20linux-rxgk-decrypt-mac">https://delphoslabs.com/blog/36142374-e1fe-80a9-9456-d3c64df81bd5/%20linux-rxgk-decrypt-mac</a></p><h2>CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path</h2><p><strong>Saeed Abbasi </strong>shows the value of code review and understanding state machines..</p><blockquote><p>During ongoing research into Linux kernel privilege boundaries, TRU identified a narrow window in which a privileged process that is dropping its credentials remains reachable through ptrace-family operations even though its dumpable flag should have closed that path. By pairing this window with the pidfd_getfd() syscall (added in v5.6-rc1, January 2020), an attacker can capture open file descriptors and authenticated inter-process channels from a dying privileged process and re-use them under their own uid.</p></blockquote><p><a href="https://blog.qualys.com/vulnerabilities-threat-research/2026/05/20/cve-2026-46333-local-root-privilege-escalation-and-credential-disclosure-in-the-linux-kernel-ptrace-path">https://blog.qualys.com/vulnerabilities-threat-research/2026/05/20/cve-2026-46333-local-root-privilege-escalation-and-credential-disclosure-in-the-linux-kernel-ptrace-path</a></p><h1>Offense</h1><p>Attack capability, techniques and trade-craft. </p><p><em>Nothing overly of note this week&#8230;</em></p><h1>Exploitation</h1><p>What is being exploited..</p><h2>Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks</h2><p><strong>Alex.Turing, Wang Hao, huxin, rootkite </strong>and<strong> Acey9 </strong>detail a watering hole style attack which involves exploitation of SQL injection. </p><blockquote><p>The attacker exploited the high-risk SQL injection vulnerability CVE-2026-26980 in Ghost CMS to obtain the target site's Admin API Key without authorization, and then used the Ghost Admin API to tamper with articles in bulk, injecting malicious JavaScript loaders at the bottom of the pages to assist FakeCaptcha attacks &#8212; that is, by forging Cloudflare human verification pages to lure users into executing malicious commands locally.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!SYmb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d0434c-fdaf-4e30-8cb9-7be82fb74ce3_704x216.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!SYmb!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d0434c-fdaf-4e30-8cb9-7be82fb74ce3_704x216.png 424w, /__u/substackcdn.com/image/fetch/$s_!SYmb!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d0434c-fdaf-4e30-8cb9-7be82fb74ce3_704x216.png 848w, /__u/substackcdn.com/image/fetch/$s_!SYmb!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d0434c-fdaf-4e30-8cb9-7be82fb74ce3_704x216.png 1272w, /__u/substackcdn.com/image/fetch/$s_!SYmb!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d0434c-fdaf-4e30-8cb9-7be82fb74ce3_704x216.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!SYmb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d0434c-fdaf-4e30-8cb9-7be82fb74ce3_704x216.png" width="704" height="216" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/32d0434c-fdaf-4e30-8cb9-7be82fb74ce3_704x216.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:216,&quot;width&quot;:704,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Ghost CMS Poisoning Incident Timeline&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Ghost CMS Poisoning Incident Timeline" title="Ghost CMS Poisoning Incident Timeline" srcset="/__u/substackcdn.com/image/fetch/$s_!SYmb!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d0434c-fdaf-4e30-8cb9-7be82fb74ce3_704x216.png 424w, /__u/substackcdn.com/image/fetch/$s_!SYmb!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d0434c-fdaf-4e30-8cb9-7be82fb74ce3_704x216.png 848w, /__u/substackcdn.com/image/fetch/$s_!SYmb!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d0434c-fdaf-4e30-8cb9-7be82fb74ce3_704x216.png 1272w, /__u/substackcdn.com/image/fetch/$s_!SYmb!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d0434c-fdaf-4e30-8cb9-7be82fb74ce3_704x216.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><a href="https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/">https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/</a></p><h2>ssh-keysign-pwn</h2><p><strong>_SiCk</strong> publishes this exploit which I suspect will have a long tail of impact..</p><blockquote><p>Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels.</p></blockquote><p><a href="https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn">https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn</a></p><h1>Tooling and Techniques</h1><p>Low level tooling and techniques for attack and defence researchers</p><h2>Crashing Through Defenses: Exploiting Segfaults and Chaining around Intel CET</h2><p><strong>Marcos Bajo , Ritvik Goyal , Apostolos Chatzianagnostou</strong> , and <strong>Christian Rossow </strong>introduce a new exploitation primitive. </p><blockquote><p>This paper introduces Segmentation Fault Oriented Programming (SFOP), a novel code reuse attack that exploits previously unidentified weaknesses in the interaction between Intel CET and the Linux signal handling subsystem. Unlike other code reuse techniques, SFOP does not require program-specific features, and can reliably exploit any vulnerable application on modern x86 64 Linux with Intel CET enabled. SFOP enables an attacker to execute arbitrarily many function calls with fully controlled arguments, turning a single memory corruption vulnerability into arbitrary code execution. We demonstrate the practical impact of SFOP through real-world exploits, and discuss mitigation strategies to prevent SFOP attacks.</p></blockquote><p><a href="https://cispa.saarland/group/rossow/papers/sfop-ieeesp2026.pdf">https://cispa.saarland/group/rossow/papers/sfop-ieeesp2026.pdf</a></p><p><a href="https://github.com/signal-sfop/sfop/">https://github.com/signal-sfop/sfop/</a></p><h2>HDD Firmware Hacking Part 1</h2><p><strong>Ryan Miceli</strong> creates the stuff of nightmares for those managing persistence risk.. </p><blockquote><p>Rather than keep this topic in obscurity I decided to open source the IDA and firmware related scripts I wrote to help others start looking into HDD firmware. I&#8217;m interested to see what other people find in these devices and would love to see things like backdoor commands documented, tools to try and fingerprint firmware, and maybe even decompilation of firmware (even though it&#8217;s completely pointless and I would never trust it anyway). You can find all my work on my <a href="https://github.com/grimdoomer/HDDTools">GitHub</a></p></blockquote><p><a href="https://icode4.coffee/?p=1465">https://icode4.coffee/?p=1465</a></p><h2>FalkorDB</h2><p>Numerous folk develop this which will have application in a number of cyber defence use cases.</p><blockquote><p>Ultra-fast, Multi-tenant Graph Database</p><p><a href="https://www.falkordb.com/">FalkorDB</a> is the first queryable <a href="https://github.com/opencypher/openCypher/blob/master/docs/property-graph-model.adoc">Property Graph</a> database to leverage sparse matrices for representing the <a href="https://en.wikipedia.org/wiki/Adjacency_matrix">adjacency matrix</a> in graphs and <a href="https://en.wikipedia.org/wiki/Adjacency_matrix">linear algebra</a> for querying.</p><h3>Key Features</h3><ul><li><p>Sparse Matrix Representation: Utilizes sparse matrices to represent adjacency matrices, optimizing storage and performance.</p></li><li><p>Linear Algebra Querying: Employs linear algebra for query execution, enhancing computational efficiency.</p></li><li><p>Property Graph Model Compliance: Supports nodes and relationships with attributes, adhering to the Property Graph Model.</p></li><li><p>OpenCypher Support: Compatible with OpenCypher query language, including proprietary extensions for advanced querying capabilities.</p></li></ul></blockquote><p><a href="https://github.com/FalkorDB/falkordb">https://github.com/FalkorDB/falkordb</a></p><h2>Navigating the MTE Landscape: iOS Memory Protection Deep Dive</h2><p><strong>Atlan PINABEL</strong> and <strong>Patrick VENTUZELO</strong> navigate through these slides from OffensiveCON</p><p><a href="https://fuzzinglabs.com/wp-content/uploads/2026/05/Navigating_iOS_MTE_Landscape.pdf">https://fuzzinglabs.com/wp-content/uploads/2026/05/Navigating_iOS_MTE_Landscape.pdf</a></p><h2>Striga: Lifting x86 to LLVM IR with Python</h2><p><strong>mrexodia</strong> lowers the bar of entry..</p><blockquote><p>The goal of this post is to lower the barrier of entry and let you experiment with lifting to LLVM IR. For inspiration you can look at the <a href="https://back.engineering/blog/09/05/2026/">Static Devirtualization of Themida</a> post that was just released by Back Engineering Labs, as well as the <a href="https://arxiv.org/html/2603.18355v1">Pushan: Trace-Free Deobfuscation of Virtualization-Obfuscated Binaries</a> paper by ASU researchers published in March.</p></blockquote><p><a href="https://secret.club/2026/05/21/striga.html">https://secret.club/2026/05/21/striga.html</a></p><h1>Footnotes</h1><p>Some other small (and not so small) bits and bobs which might be of interest.</p><ul><li><p>Annual, quarterly and monthly reports</p><ul><li><p><em>Nothing overly of note this week, but keep an eye on</em> <a href="https://github.com/jacobdjwilson/awesome-annual-security-reports/tree/main/Annual%20Security%20Reports/2026">the Awesome Annual Security Reports 2026 collection</a></p></li></ul></li><li><p><a href="https://vitalik.eth.limo/general/2026/05/18/fv.html">A shallow dive into formal verification</a></p></li><li><p><a href="https://www.csail.mit.edu/news/study-how-chips-really-work-mit-researchers-built-their-own-operating-system">To study how chips really work, MIT researchers built their own operating system</a></p></li><li><p>Artificial intelligence</p><ul><li><p>Fundamental</p><ul><li><p><a href="https://arxiv.org/abs/2605.12357">$&#948;$-mem: Efficient Online Memory for Large Language Models</a></p></li><li><p><a href="https://arxiv.org/abs/2605.15155">Self-Distilled Agentic Reinforcement Learning</a></p></li></ul></li><li><p>Applied non-cyber</p><ul><li><p><a href="https://arxiv.org/abs/2605.22568">Measuring Security Without Fooling Ourselves: Why Benchmarking Agents Is Hard</a></p></li><li><p><a href="https://arxiv.org/abs/2503.18455">SEAlign: Alignment Training for Software Engineering Agent</a></p></li><li><p><a href="https://arxiv.org/abs/2512.04695">TRINITY: An Evolved LLM Coordinator</a></p></li></ul></li><li><p>Applied cyber specific</p><ul><li><p><a href="https://github.com/tsale/awesome-dfir-skills/blob/main/skills/analysis/admiralty-system-tr/SKILL.md">Admiralty System for CTI Claude skill</a></p></li><li><p><a href="https://arxiv.org/abs/2605.22529">Stabilising Explainability Fragility in Cybersecurity AI: The Impact and Mitigation of Multicollinearity in Public Benchmark Datasets</a></p></li><li><p><a href="https://arxiv.org/abs/2605.20744">Hack-Verifiable Environments: Towards Evaluating Reward Hacking at Scale</a></p></li><li><p><a href="https://arxiv.org/abs/2605.20051">Hunting Vulnerability Variants in AI Infra: Measurement and Reference-Driven Detection</a></p></li><li><p><a href="https://arxiv.org/abs/2605.21694">PocketAgents: A Manifest-Driven Library of Autonomous Defense Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2605.08382">SecureForge: Finding and Preventing Vulnerabilities in LLM-Generated Code via Prompt Optimization</a></p></li><li><p><a href="https://arxiv.org/abs/2605.21956">Detecting Offensive Cyber Agents: A Detection-in-Depth Approach</a></p></li><li><p><a href="https://blogs.cisco.com/ai/announcing-foundry-security-spec">Announcing Foundry Security Spec</a></p></li><li><p><a href="https://arxiv.org/abs/2605.15874">Ti-iLSTM: A TinyDL Approach for Logic-Level Anomaly Detection in Industrial Water Treatment Systems</a></p></li><li><p><a href="https://arxiv.org/abs/2605.22333">A First Measurement Study on Authentication Security in Real-World Remote MCP Servers</a></p></li><li><p><a href="https://arxiv.org/abs/2605.22321">Benchmarking Autonomous Agents against Temporal, Spatial, and Semantic Evasions</a></p></li><li><p><a href="https://arxiv.org/abs/2605.22087">Automated Repair of TEE Partitioning Issues via DSL-Guided and LLM-Assisted Patching</a></p></li><li><p><a href="https://arxiv.org/abs/2605.22058">Finding Missing Input Validation in TEEs via LLM-Assisted Symbolic Execution</a></p></li><li><p><a href="https://arxiv.org/abs/2605.22027">Parser-Free Querying of Security Logs</a></p></li><li><p><a href="https://arxiv.org/abs/2605.21824">Quality-Assured Fuzz Harness Generation via the Four Principles Framework</a></p></li><li><p><a href="https://arxiv.org/abs/2605.21821">A Large Language Model Approach to Generating Bypass Rules for Malware Evasion in Analysis Sandbox</a></p></li><li><p><a href="https://arxiv.org/abs/2605.21779">FuzzingBrain V2: A Multi-Agent LLM System for Automated Vulnerability Discovery and Reproduction</a></p></li><li><p><a href="https://arxiv.org/abs/2605.21392">VIPER-MCP: Detecting and Exploiting Taint-Style Vulnerabilities in Model Context Protocol Servers</a></p></li><li><p><a href="https://arxiv.org/abs/2605.18474">Prompt2Fingerprint: Plug-and-Play LLM Fingerprinting via Text-to-Weight Generation</a></p></li><li><p><a href="https://github.com/BishopFox/aimap">aimap: Discover Exposed AI Services</a></p></li></ul></li></ul></li><li><p>Books</p><ul><li><p><em>Nothing overly of note this week..</em></p></li></ul></li><li><p>Events</p><ul><li><p><a href="https://sp2026.ieee-security.org/accepted-papers.html">47th IEEE Symposium on Security and Privacy </a>- accepted papers</p></li><li><p><a href="https://attend.ieee.org/dsc-2025/dsc-2026/call-for-papers/">The IEEE Conference on Dependable and Secure Computing (DSC 2026)</a> - Call of Papers</p></li></ul></li></ul><p>Finally finally the <a href="https://creators.spotify.com/pod/profile/national-cyber-security-c6/episodes/The-Ransomware-Ecosystem-e2hi088">NCSC&#8217;s podcast series</a>.</p><div><hr></div><p><em>Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them. </em></p><p><em>This newsletter is subject to the NCSC website terms and conditions which can be found at <a href="https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions">https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions</a> and you can find out more about how will treat your personal information in our privacy notice at <a href="https://www.ncsc.gov.uk/section/about-this-website/privacy-statement">https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.</a></em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CTO at NCSC - Cyber Defence Analysis! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CTO at NCSC Summary: week ending May 17th]]></title><description><![CDATA[My Ministers will also introduce legislation to improve the country&#8217;s defences against cyber-security threats [Cyber Security and Resilience Bill].]]></description><link>https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-f71</link><guid isPermaLink="false">https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-f71</guid><dc:creator><![CDATA[Ollie Whitehouse]]></dc:creator><pubDate>Sat, 16 May 2026 17:54:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ZTbl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ca5123-ed80-43c0-9346-c9d0584b9fc2_1369x733.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to the weekly highlights and analysis of the&nbsp;<a href="https://infosec.pub/c/blueteamsec?dataType=Post&amp;sort=New">blueteamsec</a>&nbsp;(and my wider reading). Not everything makes it in, but the best bits do. A community member is doing <a href="https://briefing.workshop1.net/">daily AI generated podcast of the last 24hours of posts</a>.</p><p>Operationally this week nothing of overly note which given the number of supply chain breaches is a statement..</p><p>In the high-level this week:</p><ul><li><p><a href="https://www.gov.uk/government/speeches/the-kings-speech-2026">The King&#8217;s Speech 2026</a> - <strong>Prime Minister's Office, 10 Downing Street</strong> and <strong>His Majesty King Charles III</strong> publish </p><ul><li><p>My Ministers will also introduce legislation to improve the country&#8217;s defences against cyber-security threats [Cyber Security and Resilience Bill].</p></li></ul></li><li><p><a href="https://www.ncsc.gov.uk/blogs/thinking-carefully-before-adopting-agentic-ai">Thinking carefully before adopting agentic AI</a> - <strong>NCSC</strong> UK publishes - <em>&#8220;This blog summarises the key points from that guidance, and will be of use to anyone involved in the design, development, deployment and operation of agentic AI systems.&#8221;</em></p></li><li><p><a href="https://www.ncsc.gov.uk/blogs/10-questions-ask-using-ai-models-find-vulnerabilities">10 questions to ask when using AI models to find vulnerabilities</a> - <strong>NCSC</strong> UK publishes - <em>&#8220;Using artificial intelligence to find vulnerabilities can bring added security considerations.&#8221;</em></p></li><li><p><a href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/KI/SBOM-for-AI_minimum-elements.html">Software Bill of Materials (SBOM) for Artificial Intelligence - Minimum Elements</a> -  <strong>G7</strong> publish - &#8220;<em>This paper has been written by the G7 Cybersecurity Working Group. It provides actionable guidance for public and private sector stakeholders on which elements a Software Bill of Materials (SBOM) for AI should at least include.&#8221;</em></p></li><li><p><a href="https://www.gov.uk/guidance/ai-open-code-and-vulnerability-risk-in-the-public-sector">AI, open code and vulnerability risk in the public sector -</a> <strong>Government Digital Service</strong> and <strong>Department for Science, Innovation and Technology </strong>publish - &#8220;<em>Publishing source code does not create those weaknesses, but it can modestly reduce attacker uncertainty and speed up analysis (an effect that may increase with AI assistance), especially where maintenance is weak and fixes are slow. This guidance reinforces the minimum operational capability already assumed for safely operating publicly-accessible services.&#8221;</em> </p></li><li><p><a href="https://www.gov.uk/government/news/government-steps-up-action-to-strengthen-cyber-defences-as-uk-cyber-industry-continues-to-grow">Government steps up action to strengthen cyber defences as UK cyber industry continues to grow</a> - <strong>Department for Science, Innovation and Technology</strong> and <strong>Baroness Lloyd of Effra CBE </strong>announce - &#8220;</p><ul><li><p><em>Businesses encouraged to sign Cyber Resilience Pledge to strengthen defences against fast-evolving AI-enabled threats</em></p></li><li><p><em>New figures show UK cyber security sector revenue has risen 11% to &#163;14.7 billion, with firms up 20% to 2,603</em></p></li><li><p><em>Cyber Security and Resilience Bill to continue through Parliament following the King&#8217;s Speech, demonstrating the government&#8217;s long-term commitment to strengthen Britain&#8217;s foundations and build a more resilient country&#8221;</em></p></li></ul></li><li><p><a href="https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/05/fine-of-nearly-1m-issued-against-south-staffordshire-plc-and-south-staffordshire-water-plc/">Fine of nearly &#163;1m issued against South Staffordshire Plc and South Staffordshire Water Plc following major cyber attack and data breach </a>- <strong>Information Commissioner&#8217;s Office</strong> announces - <em>&#8220;We have <strong>fined South Staffordshire Plc and South Staffordshire Water Plc</strong> (together South Staffordshire) &#163;963,900 following a serious cyber attack that resulted in the personal information of 633,887 people being extracted and published on the dark web.&#8221;</em></p></li><li><p> <a href="https://securityaffairs.com/191842/cyber-warfare-2/ai-cyberwarfare-and-autonomous-weapons-inside-americas-new-military-strategy.html">AI, Cyberwarfare, and Autonomous Weapons: Inside America&#8217;s New Military Strategy</a> - <strong>Security Affairs</strong> reports - &#8220;<em>The contracts signed with technology providers include &#8220;lawful operational use&#8221; clauses, requiring vendors to accept any use considered legitimate by the Pentagon, including autonomous weapons systems and intelligence operations. This raises profound ethical and geopolitical questions.&#8221;</em></p></li><li><p><a href="https://www.europarl.europa.eu/thinktank/en/document/EPRS_ATA(2026)785746">Conclusion of the United Nations Convention against Cybercrime</a> -   <strong>European Parliament Think Tank</strong> think tank - <em>&#8220;The convention is expected to strengthen the EU's ability to combat cyber-related offences committed against persons and businesses in the EU by criminals based in non-EU countries.&#8221;</em></p></li><li><p><a href="https://www.europarl.europa.eu/thinktank/en/document/EPRS_BRI(2026)785742">Chips act 2.0</a> - <strong>European Parliament Think Tank</strong> think tank - <em>&#8220;The proposal for an EU chips act 2.0, scheduled for publication on 27 May 2026 as part of the Tech Sovereignty Package, will aim to strengthen Europe&#8217;s resilience and technological sovereignty in semiconductors. It is expected to address the EU's lack of manufacturing capacity for advanced semiconductor nodes and for other chip markets where the EU holds a competitive advantage, improve the monitoring of semiconductor markets, and simplify the regulatory framework.&#8221;</em></p></li><li><p>Reporting on/from China</p><ul><li><p><a href="https://cyberdefensereview.army.mil/CDR-Content/Articles/Article-View/Article/4477628/chinas-cyber-explosives-are-in-place-wheres-our-response/">China&#8217;s Cyber Explosives are in Place. Where&#8217;s our Response?</a> - <strong>Rob Joyce</strong> asks and asserts - <em>&#8220;The temporary decline in activity following the 2015 U.S.&#8211;China cyber agreement demonstrates that deterrence is achievable&#8212;but only when costs are imposed visibly and across domains, particularly through economic and diplomatic leverage.&#8221;</em></p></li></ul></li><li><p> AI</p><ul><li><p><a href="https://codeberg.org/tzafaar/Buffers_overflow_into_policy/src/commit/56e80cff8943534a951e99eb09d1e07e8461c1d6/other/CSIRTs-Agencies.md">CSIRTs and government agency reactions to Mythos</a> - <em>&#8220;Official cybersecurity agencies, CSIRTs, and ministerial statements in response to Anthropic's Claude Mythos Preview (announced 7 April 2026). Sorted by jurisdiction (EU, UK, US); newest first within each.&#8221;</em></p></li><li><p><a href="https://www.aisi.gov.uk/blog/how-fast-is-autonomous-ai-cyber-capability-advancing">How fast is autonomous AI cyber capability advancing?</a> - <strong>AI Security Institute</strong> UK publishes - <em>&#8220;This blog post includes our latest results from GPT-5.5 and Claude Mythos Preview. Since our blog post describing our pre-deployment testing of Mythos Preview, we received access to a newer checkpoint. This checkpoint delivered stronger cyber results than the previous version, including the first completion of both our cyber ranges.&#8221;</em></p></li><li><p><a href="https://www.cac.gov.cn/2026-05/08/c_1779979789523320.htm">Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents</a> - <strong>Cyberspace Administration of China</strong> publish - <em>&#8220;Guide industry organizations to establish a credit rating mechanism for intelligent agent market entities with voluntary participation. This mechanism will evaluate behaviors such as technology abuse, misleading consumption, false advertising, and concealment of defective information, and will impose penalties for dishonesty in accordance with laws and regulations.&#8221;</em></p><ul><li><p><a href="https://www.cac.gov.cn/2026-05/08/c_1779979789738376.htm">Q&amp;A on the Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents</a></p></li></ul></li><li><p><a href="https://arxiv.org/abs/2605.11086">ExploitGym: Can AI Agents Turn Security Vulnerabilities into Real Attacks?</a> - <strong>Many Researchers</strong> release - again with some real-world nuance - <em>&#8220;This case study should be interpreted within our controlled evaluation environment. The challenge <strong>intentionally disables several production mitigation</strong>s, including ASLR and the V8 heap and renderer sandboxes. When we re-enable these defenses, GPT-5.4 no longer achieves code execution: ASLR prevents reliable pointer derivation, while the heap and renderer sandboxes block the forged-object and setcontext pivots used in Steps 6&#8211;7. The result, therefore, shows that the agent can turn a debug-only PoV into a fully working exploit for a very complex, real-world target, while also highlighting that modern mitigations remain a meaningful barrier to full browser compromise.&#8221;</em></p></li><li><p><a href="https://arxiv.org/abs/2605.14153">ExploitBench: A Capability Ladder Benchmark for LLM Cybersecurity Agents</a> - <strong>Seunghyun Lee</strong> and <strong>David Brumley </strong>provide a strong signal - <em>&#8220;Our results show a sharp capability split between publicly deployed frontier models and the private frontier. Across the 8 publicly deployed models tested, reaching the vulnerable code and triggering a crash is routine, but arbitrary code execution is not. The private model shows arbitrary code execution on approximately half. Overall, results suggest that exploit construction against hardened targets is an emerging frontier capability.&#8221;</em><strong> </strong></p></li><li><p><a href="https://clearseclabs.com/blog/weve-been-here-before-ai-vulnerability-research/">We've Been Here Before: Decompilers, Fuzzers, and Now AI</a> - <strong>Clearsec Labs</strong> reminds and advises - <em>&#8220;we've been in this place before. The path out of the worry has been the same every time. Engage with the new tool early. Stay ahead of it by working with it.</em>&#8221;</p></li><li><p><a href="https://www.originhq.com/blog/patch-diffing-pipeline">The Mythos We Have At Home: A Patch-Diffing Pipeline for N-Day Generation</a> - <strong>Tyler Holmwood</strong> details - <em>&#8220;The pipeline I built isn't a frontier-model killer, and it won't replace dedicated exploit-development shops. But cyber-capable AI isn't gated behind altruistic frontier labs either. The capability is here, the building blocks are public, and stitching them into an N-day production line is well within reach of one researcher with a couple VMs and a credit card.&#8221;</em></p></li><li><p><a href="https://zeropath.com/blog/benchmarking-opus-4-6-vuln-detection">Benchmarking Opus 4.6 For Vuln Detection: Flashes Of Brilliance But Lots of Noise</a> - <strong>John Walker</strong> researches - &#8220;<em>We studied Opus 4.6's performance finding known C vulnerabilities in single functions using a variety of single prompt approaches. Within this narrow slice, the model tended to find around 25% of known vulnerabilities, but with a lot of false positives, and with a lot of inconsistency between runs. Some of our classification approaches mitigated the noise and variability to an extent, but it remained an issue.&#8221;</em></p></li><li><p><a href="https://rival.security/posts/mythos-discovered-a-cve-already-in-its-training-data---and-thats-still-worrying">Mythos &#8216;Discovered&#8217; a CVE Already in Its Training Data - and That&#8217;s Still Worrying</a> - <strong>Jake Feiglin </strong>researches - <em>&#8220;So, can AI find brand-spanking new, highly creative vulnerabilities? Maybe. But, in the case of CVE-2026-4747, the finding of the vulnerability itself seems much more an instance of combinatorial creativity, with AI making a discovery already within its training data.&#8221;</em></p></li><li><p><a href="https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/">Mythos finds a curl vulnerability</a> - <strong>Daniel Stenberg</strong> details - <em>&#8220;We have not seen any AI so far report a vulnerability that would somehow be of a novel kind or something totally new. They do not reinvent the field in that way, but they do dig up more issues than any other tools did before.&#8221;</em></p></li><li><p><a href="https://gowers.wordpress.com/2026/05/08/a-recent-experience-with-chatgpt-5-5-pro/">A recent experience with ChatGPT 5.5 Pro</a> - <strong>Professor Tim Gowers</strong> details - <em>&#8220;I have just made a fairly large revision as a result of ChatGPT 5.5 Pro, to which I am fortunate to have been given access, producing a piece of PhD-level research in an hour or so, with no serious mathematical input from me.&#8221;</em></p></li><li><p><a href="https://cset.georgetown.edu/publication/beyond-pdoom-for-ai-risk-quantifying-uncertainty-without-probability/">Beyond P(doom) for AI Risk: Quantifying Uncertainty Without Probability</a> - <strong>Andrew Lohn</strong> proposes - <em>&#8220;This issue brief explains why analysts and decision-makers need alternatives to probability for handling the uncertainty in AI risk. It explains Belief, Plausibility, and how they relate to probability in an intuitively accessible way. And it demonstrates how to calculate Belief and Plausibility in the context of expert assessments of AI risk.&#8221;</em></p></li><li><p><a href="https://static1.squarespace.com/static/64edf8e7f2b10d716b5ba0e1/t/6a05ae219dc7e02152a50f79/1778757153943/After+Mythos_+A+National+Security+Playbook+for+Frontier+AI.pdf">After Mythos: A National Security Playbook for Frontier AI </a>- <strong>Joe O&#8217;Brien</strong>, <strong>Brianna Rosen</strong> and <strong>Christopher Covino</strong> propose - <em>&#8220;A strategic policy response must look beyond the Mythos moment to secure models against adversaries, drive defense through automation, expand public-private information sharing, and build government capacity. These interventions will help create the enabling environment for policy responses to match the scale of frontier risks while promoting secure innovation.&#8221;</em></p></li><li><p><a href="https://research.panmureliberum.com/view/FD91B03A-3DB8-4EF8-99B3-478C1AFC983A?uid=markets.news%40ft.com&amp;jobRef=1032205_20260512_150546">What if... the AI boom goes into reverse?</a> - <strong>Panmure Liberum</strong> ponders - <em>&#8220;Hyperscalers need to either cut their  capex plans dramatically or find $2tn </em></p><p><em>to $5tn in extra revenue to finance them. OpenAI and Anthropic seem to  have no viable business plan.&#8221;</em></p></li></ul></li><li><p><em>Cyber proliferation</em></p><ul><li><p><em>Nothing overly of note this week</em></p></li></ul></li><li><p>Bounty Hunting</p><ul><li><p><a href="https://www.chosun.com/english/kpop-culture-en/2026/05/13/RVDMPUVDIFARJJE2W22LUHWTTI/">Hacker Ringleader Extradited for 38 Billion Won Theft</a> - <strong>The Chosun Daily</strong> reports - &#8220;<em>The Chinese ringleader of a hacking group that stole personal information of domestic high-net-worth individuals, including BTS member Jungkook, and attempted to embezzle assets worth 38 billion Korean won was extradited to South Korea today (the 13th). Police plan to apply for a bench warrant for the suspect.&#8221;</em></p></li></ul></li><li><p>Market Incentives</p><ul><li><p><a href="https://www.gov.uk/government/publications/kings-speech-2026-background-briefing-notes">King&#8217;s Speech 2026: background briefing notes</a> - <strong>Prime Minister's Office, 10 Downing Street</strong> publishes - &#8220;<em>The Bill will: </em></p><ul><li><p><em>Expand the remit of existing regulations to better protect more of the core services people and businesses rely on</em></p></li><li><p><em>Ensuring cyber regulators are more effective and consistent to protect essential services</em></p></li><li><p><em>Ensure the UK is resilient to new threats&#8221;</em></p></li></ul></li></ul></li></ul><p>Reflections this week come off the back of  <a href="https://www.offensivecon.org/">OffensiveCon </a>in Berlin where I gave the keynote on Friday. </p><p>The first is that the AI correction is underway (in a positive way) and this was articulated through a number of graphs - but was most evident on the ground at pwn2own. At pwn2own entrants for some targets evaporated or failed after the AI powered patch sets dropped (Firefox) and for others there were many more than slots to compete due to leveraging AI.</p><p>A subset of the slides I presented included:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!ZTbl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ca5123-ed80-43c0-9346-c9d0584b9fc2_1369x733.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!ZTbl!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ca5123-ed80-43c0-9346-c9d0584b9fc2_1369x733.png 424w, /__u/substackcdn.com/image/fetch/$s_!ZTbl!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ca5123-ed80-43c0-9346-c9d0584b9fc2_1369x733.png 848w, /__u/substackcdn.com/image/fetch/$s_!ZTbl!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ca5123-ed80-43c0-9346-c9d0584b9fc2_1369x733.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ZTbl!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ca5123-ed80-43c0-9346-c9d0584b9fc2_1369x733.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!ZTbl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ca5123-ed80-43c0-9346-c9d0584b9fc2_1369x733.png" width="1369" height="733" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/08ca5123-ed80-43c0-9346-c9d0584b9fc2_1369x733.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:733,&quot;width&quot;:1369,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:168113,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://ctoatncsc.substack.com/i/197964304?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ca5123-ed80-43c0-9346-c9d0584b9fc2_1369x733.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!ZTbl!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ca5123-ed80-43c0-9346-c9d0584b9fc2_1369x733.png 424w, /__u/substackcdn.com/image/fetch/$s_!ZTbl!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ca5123-ed80-43c0-9346-c9d0584b9fc2_1369x733.png 848w, /__u/substackcdn.com/image/fetch/$s_!ZTbl!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ca5123-ed80-43c0-9346-c9d0584b9fc2_1369x733.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ZTbl!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08ca5123-ed80-43c0-9346-c9d0584b9fc2_1369x733.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!I5-K!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c1dd644-429d-4363-864e-d6f542f24f44_1368x738.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!I5-K!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c1dd644-429d-4363-864e-d6f542f24f44_1368x738.png 424w, /__u/substackcdn.com/image/fetch/$s_!I5-K!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c1dd644-429d-4363-864e-d6f542f24f44_1368x738.png 848w, /__u/substackcdn.com/image/fetch/$s_!I5-K!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c1dd644-429d-4363-864e-d6f542f24f44_1368x738.png 1272w, /__u/substackcdn.com/image/fetch/$s_!I5-K!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c1dd644-429d-4363-864e-d6f542f24f44_1368x738.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!I5-K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c1dd644-429d-4363-864e-d6f542f24f44_1368x738.png" width="1368" height="738" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6c1dd644-429d-4363-864e-d6f542f24f44_1368x738.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:738,&quot;width&quot;:1368,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:256898,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ctoatncsc.substack.com/i/197964304?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c1dd644-429d-4363-864e-d6f542f24f44_1368x738.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!I5-K!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c1dd644-429d-4363-864e-d6f542f24f44_1368x738.png 424w, /__u/substackcdn.com/image/fetch/$s_!I5-K!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c1dd644-429d-4363-864e-d6f542f24f44_1368x738.png 848w, /__u/substackcdn.com/image/fetch/$s_!I5-K!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c1dd644-429d-4363-864e-d6f542f24f44_1368x738.png 1272w, /__u/substackcdn.com/image/fetch/$s_!I5-K!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c1dd644-429d-4363-864e-d6f542f24f44_1368x738.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!L1G_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F409f186a-4a17-4142-9f32-72a881b7ca69_1365x736.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!L1G_!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F409f186a-4a17-4142-9f32-72a881b7ca69_1365x736.png 424w, /__u/substackcdn.com/image/fetch/$s_!L1G_!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F409f186a-4a17-4142-9f32-72a881b7ca69_1365x736.png 848w, /__u/substackcdn.com/image/fetch/$s_!L1G_!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F409f186a-4a17-4142-9f32-72a881b7ca69_1365x736.png 1272w, /__u/substackcdn.com/image/fetch/$s_!L1G_!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F409f186a-4a17-4142-9f32-72a881b7ca69_1365x736.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!L1G_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F409f186a-4a17-4142-9f32-72a881b7ca69_1365x736.png" width="1365" height="736" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/409f186a-4a17-4142-9f32-72a881b7ca69_1365x736.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:736,&quot;width&quot;:1365,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:276450,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ctoatncsc.substack.com/i/197964304?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F409f186a-4a17-4142-9f32-72a881b7ca69_1365x736.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!L1G_!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F409f186a-4a17-4142-9f32-72a881b7ca69_1365x736.png 424w, /__u/substackcdn.com/image/fetch/$s_!L1G_!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F409f186a-4a17-4142-9f32-72a881b7ca69_1365x736.png 848w, /__u/substackcdn.com/image/fetch/$s_!L1G_!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F409f186a-4a17-4142-9f32-72a881b7ca69_1365x736.png 1272w, /__u/substackcdn.com/image/fetch/$s_!L1G_!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F409f186a-4a17-4142-9f32-72a881b7ca69_1365x736.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The second reflection was the number of conversations around concern of disruption to future talent pipelines because of AI. I had covered it and it is clear a number have a real concern that AI tooling means that the manual hours and associated knowledge will not  be accumulated. The net result meaning the base skills won&#8217;t be present in the volumes required in the future. </p><p>I spoke to various CEOs and team leaders from across the industry along with one academic who all raised these concerns. Also interestingly in the case of the academic they raised what they were observing in terms of knowledge drop off in their applied reverse engineering module more generally already..</p><p>Ensuring we have the skills we need is one of those collective challenges as AI will make some of these artisanal to do manually..  </p><p>Not getting this via email? Subscribe:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Think someone else would benefit? Share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-f71?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-f71?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p><strong>All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.</strong></p><p>Have a lovely Saturday&#8230;</p><p>Ollie</p><h1>Cyber threat intelligence</h1><p>Who is doing what to whom and how allegedly.</p><h2>Reporting on Russia</h2><h3>Gamaredon&#8217;s infection chain: Spoofed emails, GammaDrop and GammaLoad</h3><p><strong>Harfang Lab</strong> detail an alleged Russian operation which is noteworthy for using VBScript downloaders and a degree of system recognisance. </p><blockquote><p>Investigating Gamaredon&#8217;s abuse of CVE-2025-8088, we identified a dozen waves of spearphishing emails against Ukrainian state institutions in a campaign that is still active, dating back to September 2025. These emails &#8211; spoofed or sent from compromised government accounts &#8211; deliver persistent, multi-stage VBScript downloaders that profile the infected system.</p><p>In the absence of public analysis of these malware, this report documents Gamaredon&#8217;s <em>GammaDrop</em> and <em>GammaLoad</em> downloader variants, the infrastructure behind them, and the methods used to deliver the spearphishing emails.</p><p>Both variants function as downloaders, while GammaLoad additionally established persistence and beacons victim data to the C2 server, enabling the operator to selectively deliver a tailored payload. The supporting infrastructure combines Cloudflare Workers domains, fast flux DNS, dynamic DNS providers, and attacker-controlled email relays &#8211; all constantly evolving.</p></blockquote><p><a href="https://harfanglab.io/insidethelab/gamaredon-gammadrop-gammaload/">https://harfanglab.io/insidethelab/gamaredon-gammadrop-gammaload/</a></p><h3>FrostyNeighbor: Fresh mischief and digital shenanigans</h3><p><strong>Damien Schaeffer</strong> details an alleged Belarusian operation which is noteworthy as it is using CobaltStrike and thus highlighting the value in detection coverage of CS beyond just RedTeams.</p><blockquote><ul><li><p>FrostyNeighbor is a long-running cyberespionage actor apparently aligned with the interests of Belarus.</p></li><li><p>The group primarily targets governmental, military, and key sectors in Eastern Europe.</p></li><li><p>FrostyNeighbor uses server-side validation of its victims before delivering the final payload.</p></li><li><p>The group has been active recently in campaigns targeting governmental organizations in Ukraine.</p></li></ul><p>Since March 2026, we have detected new activities that we attributed to FrostyNeighbor, using links in malicious PDFs sent via spearphishing attachments to target governmental organizations in Ukraine. The compromise chain is the newest observed to date, using a JavaScript version of PicassoLoader to deliver a Cobalt Strike payload</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!FBuS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff89c5f49-4a5f-4124-ba65-da0638df39f3_2449x911.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!FBuS!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff89c5f49-4a5f-4124-ba65-da0638df39f3_2449x911.png 424w, /__u/substackcdn.com/image/fetch/$s_!FBuS!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff89c5f49-4a5f-4124-ba65-da0638df39f3_2449x911.png 848w, /__u/substackcdn.com/image/fetch/$s_!FBuS!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff89c5f49-4a5f-4124-ba65-da0638df39f3_2449x911.png 1272w, /__u/substackcdn.com/image/fetch/$s_!FBuS!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff89c5f49-4a5f-4124-ba65-da0638df39f3_2449x911.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!FBuS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff89c5f49-4a5f-4124-ba65-da0638df39f3_2449x911.png" width="1456" height="542" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f89c5f49-4a5f-4124-ba65-da0638df39f3_2449x911.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:542,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Figure 1. Compromise chain overview&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Figure 1. Compromise chain overview" title="Figure 1. Compromise chain overview" srcset="/__u/substackcdn.com/image/fetch/$s_!FBuS!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff89c5f49-4a5f-4124-ba65-da0638df39f3_2449x911.png 424w, /__u/substackcdn.com/image/fetch/$s_!FBuS!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff89c5f49-4a5f-4124-ba65-da0638df39f3_2449x911.png 848w, /__u/substackcdn.com/image/fetch/$s_!FBuS!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff89c5f49-4a5f-4124-ba65-da0638df39f3_2449x911.png 1272w, /__u/substackcdn.com/image/fetch/$s_!FBuS!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff89c5f49-4a5f-4124-ba65-da0638df39f3_2449x911.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/">https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/</a></p><h3>Kazuar: Anatomy of a nation-state botnet</h3><p><strong>Microsoft Threat Intelligence</strong> details an alleged Russian capability which is noteworthy for both age but also the fact it has continued to evolve quite substantially showing enduring investment. </p><blockquote><p>Kazuar, a sophisticated malware family attributed to the Russian state actor <a href="https://www.microsoft.com/en-us/security/blog/tag/secret-blizzard/">Secret Blizzard</a>, has been under constant development for years and continues to evolve in support of espionage-focused operations. Over time, Kazuar has expanded from a relatively traditional backdoor into a highly modular peer-to-peer (P2P) botnet ecosystem designed to enable persistent, covert access to target environments.</p><p>..</p><p>Kazuar is delivered through multiple dropper variants. In one observed method, the Pelmeni dropper embeds the encrypted second-stage payload directly within the dropper as an encrypted byte array. The payload is often bound to the target environment (for example, encrypted using the target hostname) so it only decrypts and executes on the intended host.</p><p>In another method, the dropper deploys a small .NET loader alongside the final payload. The dropper then invokes the loader (often configured as a COM object) and supplies the decrypted payload, allowing it to load and execute the Kazuar modules.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!gLtn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb338026-54a2-4932-8092-cfa122715073_1200x470.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!gLtn!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb338026-54a2-4932-8092-cfa122715073_1200x470.webp 424w, /__u/substackcdn.com/image/fetch/$s_!gLtn!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb338026-54a2-4932-8092-cfa122715073_1200x470.webp 848w, /__u/substackcdn.com/image/fetch/$s_!gLtn!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb338026-54a2-4932-8092-cfa122715073_1200x470.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!gLtn!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb338026-54a2-4932-8092-cfa122715073_1200x470.webp 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!gLtn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb338026-54a2-4932-8092-cfa122715073_1200x470.webp" width="1200" height="470" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/db338026-54a2-4932-8092-cfa122715073_1200x470.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:470,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!gLtn!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb338026-54a2-4932-8092-cfa122715073_1200x470.webp 424w, /__u/substackcdn.com/image/fetch/$s_!gLtn!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb338026-54a2-4932-8092-cfa122715073_1200x470.webp 848w, /__u/substackcdn.com/image/fetch/$s_!gLtn!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb338026-54a2-4932-8092-cfa122715073_1200x470.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!gLtn!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb338026-54a2-4932-8092-cfa122715073_1200x470.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.microsoft.com/en-us/security/blog/2026/05/14/kazuar-anatomy-of-a-nation-state-botnet/">https://www.microsoft.com/en-us/security/blog/2026/05/14/kazuar-anatomy-of-a-nation-state-botnet/</a></p><h2>Reporting on China</h2><h3>FamousSparrow APT Targets Azerbaijani Oil and Gas Industry</h3><p><strong>Victor Vrabie</strong> and <strong>Martin Zuge</strong> detail an alleged Chinese operation which is noteworthy due to the sectoral targeting and the initial access mechanism of known CVEs in Exchange which were quite old at the time of the compromise.</p><blockquote><p>The earliest signs of the intrusion date back to December 25, 2025, when the w3wp.exe process (Microsoft Exchange IIS worker process) attempted to write a malicious web shell into a publicly accessible directory on the Exchange server. The process command line contained the MSExchangePowerShellAppPool argument, indicating that the attacker exploited the Exchange server via the ProxyNotShell exploit chain</p></blockquote><blockquote></blockquote><p><a href="https://businessinsights.bitdefender.com/famoussparrow-apt-targets-azerbaijani-oil-gas-industry">https://businessinsights.bitdefender.com/famoussparrow-apt-targets-azerbaijani-oil-gas-industry</a></p><h2>Reporting on North Korea</h2><h3>VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure</h3><p><strong>Vlad Pasca</strong> and <strong>Radu-Emanuel Chiscariu</strong> detail an alleged North Korean operation which shows continued, almost persistent, interest in acquiring crypto but also access to individuals and firms who might have access to it.</p><blockquote><ul><li><p>A fake cryptocurrency trading app, Tralert FX, was used to distribute a multi-module infostealer with only 3/52 AV detections, enabled by a valid EV code signing certificate from likely front company AgilusTech LLC.</p></li><li><p>The MSI installer contained hardcoded SSH credentials and GitLab tokens, exposing the threat actor&#8217;s entire backend infrastructure.</p></li><li><p>The operation uses five GitLab repositories as both payload delivery and automated data exfiltration channels.</p></li><li><p>A three-module malware kit (system recon, keylogger, browser stealer) pushes stolen data via automated git commits on a 30-minute cycle.</p></li><li><p>Active since June 2025, with 4,100+ commits, 90+ compromised hosts, and victims still being actively compromised at time of discovery.</p></li><li><p>The threat actor manually triages victims into named folders, prioritizing cryptocurrency traders for account takeover.</p></li><li><p>Three ProtonMail-linked GitLab personas operate the infrastructure, assessed as a single operator or small team with financial motivation consistent with DPRK-nexus adversary <a href="https://www.crowdstrike.com/en-us/adversaries/velvet-chollima/">VELVET CHOLLIMA</a>.</p></li><li><p>The final payload is MoonPeak, a custom variant of the open-source XenoRAT malware.</p></li></ul></blockquote><p><a href="https://hybrid-analysis.blogspot.com/2026/05/velvet-chollima-infostealer-campaign.html">https://hybrid-analysis.blogspot.com/2026/05/velvet-chollima-infostealer-campaign.html</a></p><h3>Kimsuky targets organizations with PebbleDash-based tools</h3><p><strong>Sojun Ryu</strong> details a subset of alleged North Korean tradecraft. The diversity of droppers if not as is the variety of malware.</p><blockquote><ul><li><p>Kimsuky obtains initial access to target systems by delivering spear-phishing emails containing malicious attachments disguised as documents. They also contact targets via messengers in some cases.</p></li><li><p>Kimsuky uses a variety of droppers in different formats, such as JSE, PIF, SCR, EXE, etc.</p></li><li><p>The droppers deliver malware mainly belonging to two big clusters: PebbleDash and AppleSeed. These clusters are considered the most technically advanced in the group&#8217;s toolset. The report covers the following PebbleDash malware: HelloDoor, httpMalice, MemLoad, httpTroy. It also covers AppleSeed and HappyDoor from AppleSeed cluster.</p></li><li><p>For post-exploitation activities Kimsuky uses legitimate tools Visual Studio Code (VSCode) and DWAgent. For VSCode, the attacker uses GitHub authentication method.</p></li><li><p>For hosting C2 infrastructure the group mainly uses domains registered at a free South Korean hosting provider. It also occasionally relies on hacked South Korean websites and tunneling tools, such as Ngrok or VSCode.</p></li><li><p>Kimsuky mainly targets South Korean entities. However, PebbleDash attacks were also seen in Brazil and Germany. This malware cluster focuses on defense sector, while AppleSeed most often targets government organizations.</p></li></ul></blockquote><p><a href="https://securelist.com/kimsuky-appleseed-pebbledash-campaigns/119785/">https://securelist.com/kimsuky-appleseed-pebbledash-campaigns/119785/</a></p><h2>Reporting on Iran</h2><h3>Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign</h3><p><strong>Symantec </strong>and <strong>Carbon Black</strong> detail alleged Iranian activity which isn&#8217;t overly noteworthy other than the supposed country of origin. The reuse of security tooling for their implant will be of interest to some.</p><blockquote><ul><li><p>Activity observed in the first quarter of 2026 affected at least nine organizations across nine countries on four continents, spanning industrial and electronics manufacturing, education and public-sector bodies, financial services, and professional services.</p></li><li><p>The attackers relied heavily on DLL sideloading using legitimately signed Fortemedia (fmapp.exe) and SentinelOne (sentinelmemoryscanner.exe) binaries to execute malicious DLLs while masquerading as benign software.</p></li><li><p>A node.exe-based implant chain was used to drop PowerShell scripts that performed reconnaissance, screenshot capture, SAM hive theft, privilege escalation and SOCKS5 reverse-proxy tunnelli</p></li></ul><p>The attackers consistently dropped pairs of files comprising a legitimate, validly signed third-party executable and a malicious DLL designed to be loaded by it. Two pairs were used:</p><ul><li><p>fmapp.exe: A legitimate audio-driver utility developed by Fortemedia Inc. It was abused to sideload a malicious DLL (fmapp.dll). The same fmapp.exe / fmapp.dll pairing has been described in prior Seedworm reporting by Group-IB.</p></li><li><p>sentinelmemoryscanner.exe: A legitimate, signed component of the SentinelOne endpoint product was abused to sideload a malicious DLL (sentinelagentcore.dll). The use of a security-product binary is a deliberate choice intended both to defeat path or signature-based detection and to confuse triage.</p></li></ul></blockquote><p><a href="https://www.security.com/threat-intelligence/iran-seedworm-electronics">https://www.security.com/threat-intelligence/iran-seedworm-electronics</a></p><h2>Reporting on Other Actors</h2><h3>Lorem Ipsum Malware: Trojanized MS Teams Installers Deliver Multi-Stage Loader and Backdoor</h3><p><strong>Thomas Elkins</strong> and <strong>Joshua Green</strong> detail a rather interesting campaign due to hints of sophistication and operational planning. This is along with obtaining code signing certificates and disposable infrastructure etc.</p><blockquote><ul><li><p>[A] dead-drop resolver embedded within attacker-controlled profiles used to segment C2 across campaign waves.</p></li><li><p>Validly signed MSI installers using Microsoft ID Verified certificates with three-day validity issued under multiple individual identities, suggesting a systematic certificate procurement pipeline.</p></li><li><p>JFIF-disguised C2 traffic with payloads appended beyond image boundaries and <em>Content-Type: image/jpeg</em> headers replacing traditional HTTPS callbacks.</p></li><li><p>Per-victim UUID-tracked C2 architecture using /api/init/{UUID} callback paths across dedicated domains.</p></li><li><p>Architectural maturation in payload staging, shifting from plainraw[.]com-hosted gzip/hex PowerShell payloads in March to dedicated UUID-tracked C2 endpoints by mid-April.</p></li><li><p>Externalized AES key/initialization vector passed via MSI custom action arguments rather than embedded in the PowerShell loader, forcing analysts to recover both artifacts to reconstruct decryption.</p></li><li><p>Disposable infrastructure tradecraft: NameCheap domains with Withheld-for-Privacy registration weaponized within hours allocated one IP per domain across multiple provider ranges.</p></li><li><p>Ten-week development velocity from test build to mature loader chain, consistent with possible LLM-assisted coding workflows observed across emerging threat groups.</p></li></ul></blockquote><p><a href="https://www.bluevoyant.com/blog/lorem-ipsum-trojanized-microsoft-teams-installers-multi-stage-loader-backdoor">https://www.bluevoyant.com/blog/lorem-ipsum-trojanized-microsoft-teams-installers-multi-stage-loader-backdoor</a></p><h3>Thus Spoke&#8230;The Gentlemen</h3><p><strong>CheckPoint Research</strong> summarise the insights from the operations of this criminal group. Also of note is one breach leading to the ability to do an onward breach.</p><blockquote><ul><li><p>On May 4th, 2026, <strong>The Gentlemen</strong> <strong>RaaS</strong> administrator acknowledged on underground forums that an internal backend database (<strong>Rocket</strong>) had been leaked. This leak exposed <strong>9 accounts</strong>, including <strong>zeta88</strong> (aka <strong>hastalamuerte</strong>), who runs the infrastructure, builds the locker and <strong>RaaS</strong> panel, manages payouts, and effectively acts as the administrator of the program.</p></li><li><p>The internal discussions provide a rare <strong>end&#8209;to&#8209;end view</strong> of the operation: they detail initial access paths (Fortinet and Cisco edge appliances, NTLM relay, OWA/M365 credential logs), the division of roles, the shared toolsets, and the group&#8217;s active tracking and evaluation of modern CVEs such as <strong>CVE-2024-55591</strong>, <strong>CVE-2025-32433</strong>, and <strong>CVE-2025-33073</strong>.</p></li><li><p>Screenshots from ransom negotiations were also leaked, showing a successful case where the group received <strong>190,000 USD</strong>, after starting with an initial demand (anchor) of <strong>250,000 USD</strong>.</p></li><li><p>Further chats indicate that stolen data from a UK software consultancy was later reused to attack a company in Turkey. The Gentlemen used this during negotiations as a dual&#8209;pressure tactic: they portrayed the UK firm as the &#8220;access broker,&#8221; while mentioning to provide &#8220;proof&#8221; to the Turkish company that the intrusion originated from the UK side and encouraging it to consider legal action against the consultancy.</p></li><li><p>By collecting all available ransomware samples, Check Point Research identified <strong>8 distinct affiliate TOX IDs</strong>, including the administrator&#8217;s TOX ID. This suggests that the admin not only manages the <strong>RaaS</strong> program but also actively participates in, or directly carries out, some of the infections.</p></li></ul></blockquote><p><a href="https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/">https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/</a></p><h3>NATS-as-C2: Inside a new technique attackers are using to harvest cloud credentials and AI API keys</h3><p><strong>Michael Clark</strong> details an unattributed compromise which is noteworthy for the technology involved i.e. the use of a real-time communications fabric as part of underlying infrastructure.</p><blockquote><p>NATS servers provide three properties that scanner-pool operators historically had to engineer themselves:</p><ul><li><p><strong>Wire-level authorization</strong>: Per-subject ACLs are enforced by the broker, not by client-side checks that a captured node can disable.</p></li><li><p><strong>One-to-many fan-out</strong>: A single publish to <code>result.scan</code> reaches every aggregator without the worker enumerating peers, which improves OPSEC and simplifies horizontal scaling.</p></li><li><p><strong>First-class auth and durability</strong>: Username/password, TLS, and nkey auth are native, and JetStream provides durable queues so a worker can drop offline without losing its work.</p></li></ul><p>During this time, the Sysdig TRT captured the threat actor&#8217;s payload, exposing their coordination plane: a <a href="https://nats.io/">NATS server</a> at 45.192.109.25:14222 running an authenticated, ACL-enforced instance. The attacker subsequently attempted to escape the container using <a href="https://www.sysdig.com/blog/cve-2022-0847-dirty-pipe-sysdig">DirtyPipe</a> and <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2588">DirtyCreds</a> exploits.</p></blockquote><p><a href="https://www.sysdig.com/blog/nats-as-c2-inside-a-new-technique-attackers-are-using-to-harvest-cloud-credentials-and-ai-api-keys">https://www.sysdig.com/blog/nats-as-c2-inside-a-new-technique-attackers-are-using-to-harvest-cloud-credentials-and-ai-api-keys</a></p><h1>Discovery</h1><p>How we find and understand the latent compromises within our environments.</p><h2>Android Intrusion Logging as a new source of data for consensual forensic analysis</h2><p><strong>Amnesty International</strong> detail this new source of telemetry. </p><blockquote><p>Google has <strong><a href="https://blog.google/security/whats-new-in-android-security-privacy-2026/">today announced the launch of a new &#8216;Android Intrusion Logging&#8217;</a></strong> feature as part of <strong><a href="https://developer.android.com/privacy-and-security/advanced-protection-mode">Android Advanced Protection Mode (AAPM)</a></strong>. The new intrusion logging feature promises to be a major aid to digital forensics researchers undertaking investigations into sophisticated attacks on Android devices. This is the first time a major device vendor has release a feature specifically to enhance the ability to forensically detect and respond to advanced digital threats.</p><p>Amnesty International&#8217;s Security Lab acted as a design partner to Google over the past year during the conception and implementation of Android Advanced Protection Mode with particular focus on the Intrusion Logging feature. Research by Amnesty International and a growing community of threat labs and civil society investigators has identified ways numerous cases in which sophisticated attackers are targeting the phones of human rights defenders and journalists.</p></blockquote><p><a href="https://securitylab.amnesty.org/latest/2026/05/android-intrusion-logging-as-a-new-source-of-data-for-consensual-forensic-analysis/">https://securitylab.amnesty.org/latest/2026/05/android-intrusion-logging-as-a-new-source-of-data-for-consensual-forensic-analysis/</a></p><h2>Detecting Remote Thread Creation with Windows Driver</h2><p><strong>S12 - 0x12Dark Development</strong> walks through how to do this..</p><blockquote><p>The logic is simple. Inside the callback, we compare two values:</p><ul><li><p><code>ProcessIdd:</code>the process that owns the new thread (the target)</p></li><li><p><code>PsGetCurrentProcessId():</code>the process that is currently executing (the creator)</p></li></ul><p>If these two PIDs are <strong>different</strong>, it means one process is creating a thread inside another process. That is remote thread creation</p></blockquote><p><a href="https://medium.com/@s12deff/detecting-remote-thread-creation-with-windows-driver-9901fdbaf7b1">https://medium.com/@s12deff/detecting-remote-thread-creation-with-windows-driver-9901fdbaf7b1</a></p><h2>EventHawk</h2><p><strong>Mihir Singh Choudhary</strong> provides this super power to cyber defence teams who live in the Windows ecosystem. </p><blockquote><p>It parses Windows Event Logs in parallel using a Rust-backed engine, loads results into a clean Qt GUI, and gives you filters, threat analysis, IOC extraction, and timeline correlation all in one place. When the dataset is too large for memory, <strong>Juggernaut Mode</strong> takes over &#8212; keeping RAM flat by offloading raw event data to Parquet on disk and running all queries through DuckDB against a compact in-memory Arrow table. For deeper investigations, the bundled <strong>Sentinel</strong> engine builds a statistical baseline of normal behaviour and flags anything that deviates from it, even if no Sigma rule exists for it.</p></blockquote><p><a href="https://github.com/Mihir-Choudhary/EventHawk">https://github.com/Mihir-Choudhary/EventHawk</a></p><h2>Now You See Me: AADGraphActivityLogs</h2><p><strong>Fabian Bader</strong> details that this is now a thing and how to get value out of this new logging source in Azure.</p><blockquote><p>After a long private preview Microsoft, almost silently released the log to all their customers and gave them crucial insights in one of the most abused protocols for reconnaissance. Notably toolkits like <a href="https://github.com/dirkjanm/roadtools">ROADtools</a> and <strong><a href="https://github.com/Gerenios/AADInternals">AADInternals</a></strong> use this API to gather deep insights into the tenant and attack vectors like the Intune Company portal <a href="https://www.glueckkanja.com/en/posts/2025-01-14-compliant-device-bypass">Conditional Access bypass</a> rely on the <a href="https://entrascopes.com/?resource=00000002-0000-0000-c000-000000000000">default grant</a> to this resource.</p><p>&#8230;</p><p>Like all Entra ID logs you can configure the log forwarding of the AADGraphActivityLogs in the <a href="https://entra.microsoft.com/#view/Microsoft_AAD_IAM/DiagnosticSettingsMenuBlade/~/General">Diagnostic Settings</a> of Entra ID. For my purpose I forward them to a Sentinel enabled Log Analytics workspace.</p></blockquote><p><a href="https://cloudbrothers.info/en/aadgraphactivitylogs/">https://cloudbrothers.info/en/aadgraphactivitylogs/</a></p><h2>LOLRMM: 182 new code signing certificates</h2><p><strong>Michael Haag</strong> merges this pull request from <strong>Railisac </strong>which will help in the detection of unauthorised use of this class of tooling.</p><blockquote><ul><li><p>Merged certificate data from <code>lolrmm_tools_with_certs.json</code> into existing YAML files</p></li><li><p>Added 182 new certificates across 114 RMM tool entries</p></li></ul></blockquote><p><a href="https://github.com/magicsword-io/LOLRMM/pull/141">https://github.com/magicsword-io/LOLRMM/pull/141</a></p><h1>Defence</h1><p>How we proactively defend our environments.</p><h2>The SPIFFE Runtime Environment</h2><p>In the agentic world this one of the contenders to help build trust within the agentic systems.</p><blockquote><p>SPIRE (the <a href="https://github.com/spiffe/spiffe">SPIFFE</a> Runtime Environment) is a toolchain of APIs for establishing trust between software systems across a wide variety of hosting platforms. SPIRE exposes the <a href="https://github.com/spiffe/go-spiffe/blob/main/proto/spiffe/workload/workload.proto">SPIFFE Workload API</a>, which can attest running software systems and issue <a href="https://github.com/spiffe/spiffe/blob/main/standards/SPIFFE-ID.md">SPIFFE IDs</a> and <a href="https://github.com/spiffe/spiffe/blob/main/standards/SPIFFE-ID.md">SVID</a>s to them. This in turn allows two workloads to establish trust between each other, for example by establishing an mTLS connection or by signing and verifying a JWT token. SPIRE can also enable workloads to securely authenticate to a secret store, a database, or a cloud provider service.</p></blockquote><p><a href="https://github.com/spiffe/spire">https://github.com/spiffe/spire</a></p><h2>ipTIME Pre-Auth RCE in CWMP</h2><p><a href="https://ssd-disclosure.com/iptime-pre-auth-rce-in-cwmp/">https://ssd-disclosure.com/iptime-pre-auth-rce-in-cwmp/</a></p><h2>CHERIoT-Ibex: Closing the door on memory safety vulnerabilities with hardware-enforced protection</h2><p><strong>Kunyan Liu</strong> outline this important moment with regard memory saftey mitigations.</p><blockquote><p>CHERIoT-Ibex is the first open-source&#8239;production-quality&#8239;implementation of the CHERIoT instruction set architecture and among the first cores certified by the CHERI Alliance&#8239;(<a href="https://cheri-alliance.org/cheri-enabled/cheriot/">CHERI Alliance &#8211;&#8239;CHERIoT</a>).&#8239;CHERIoT&#8239;is&#8239;an extension&#8239;of the CHERI (Capability Hardware Enhanced RISC Instructions) instruction set, with a focus on embedded and Internet of Things (IoT)&#8239;applications. Ibex is an open&#8209;source 32&#8209;bit RISC&#8209;V core developed by LowRISC. CHERIoT&#8209;Ibex builds on Ibex by including CHERIoT capability extensions to provide hardware&#8209;enforced memory safety and fine&#8209;grained compartmentalization. It is&#8239;the result of a close partnership between Microsoft Research and&#8239;Azure Hardware Systems &amp; Infrastructure, combining advanced research&#8239;innovation&#8239;with&#8239;industry-leading silicon IP development&#8239;expertise.&#8239;</p></blockquote><p><a href="https://techcommunity.microsoft.com/blog/azureinfrastructureblog/cheriot-ibex-closing-the-door-on-memory-safety-vulnerabilities-with-hardware-enf/4517904">https://techcommunity.microsoft.com/blog/azureinfrastructureblog/cheriot-ibex-closing-the-door-on-memory-safety-vulnerabilities-with-hardware-enf/4517904</a></p><h2>Debian Reproducibility of Builds</h2><p><strong>Paul Gevers</strong> details that Debian is now mandating reproducible builds which should hopefully help thwart certain supply chain techniques..</p><blockquote><p>Aided by the efforts of the Reproducible Builds project, we&#8217;ve decided it&#8217;s time to say that Debian must ship reproducible packages. Since yesterday, we have enabled our migration software to block migration of new packages that can&#8217;t be reproduced [2] or existing packages (in testing) that regress in reproducibility.</p></blockquote><p><a href="https://lists.debian.org/debian-devel-announce/2026/05/msg00001.html">https://lists.debian.org/debian-devel-announce/2026/05/msg00001.html</a></p><h1>Incident Writeups &amp; Disclosures</h1><p>How they got in and what they did.</p><h2>Update: Ongoing Checkmarx Supply Chain Security Incident</h2><p><strong>Checkmarx</strong> document their ongoing woes with some alleged downstream ramifications.. </p><blockquote><p>We are aware that a modified version of the Checkmarx Jenkins AST plugin was published to the Jenkins Marketplace. We are in the process of publishing a new version of this plug-in.</p><p>If you are using Checkmarx Jenkins AST Plugin, you need to ensure that you are using the version 2.0.13-829.vc72453fa_1c16 that was published on Dec. 17, 2025 or previously.</p></blockquote><p><a href="https://checkmarx.com/blog/ongoing-security-updates/">https://checkmarx.com/blog/ongoing-security-updates/</a></p><h2>Website installer incident &#8212; May 2026</h2><p><strong>JDownloader</strong> disclose a breach&#8230; </p><blockquote><p>In early May 2026, attackers succeeded in altering the official JDownloader website so that certain installer links published here were repointed from the genuine JDownloader installer downloads to unrelated malicious third-party files: on Windows, only the installer download links for "Download Alternative Installer" &#8212; not the other installers offered on jdownloader.org &#8212; and the Linux shell installer link from the site.</p></blockquote><p><a href="https://jdownloader.org/incident_8.5.2026.html">https://jdownloader.org/incident_8.5.2026.html</a></p><h2>Postmortem: TanStack npm supply-chain compromise</h2><p><strong>Tanstack</strong> detail the impact of their breach..</p><blockquote><p>Only the Router/Start repo was affected &#8212; 42 monorepo packages, 2 versions each. All were deprecated within the hour and removed by npm shortly after.</p></blockquote><p><a href="https://tanstack.com/blog/npm-supply-chain-compromise-postmortem">https://tanstack.com/blog/npm-supply-chain-compromise-postmortem</a></p><h1>Vulnerability</h1><p>Our attack surface.</p><h2>We&#8217;re doing silent patches now huh, also a quick note about YellowKey</h2><p><strong>Dead Eclipse</strong> asserts this for YellowKey..</p><blockquote><p>Second thing is, No, TPM+PIN does not help, the issue is still exploitable regardless, I asked myself this question, can it still work in a TPM+PIN environment ? Yes it does, I'm just not publishing the PoC, I think what's out there is already bad enough.</p></blockquote><p><a href="https://deadeclipse666.blogspot.com/2026/05/were-doing-silent-patches-now-huh-also.html">https://deadeclipse666.blogspot.com/2026/05/were-doing-silent-patches-now-huh-also.html</a></p><h2>Yarbo - NAT In My Back Yard</h2><p><strong>Andreas Makris</strong> details a vulnerability which once again sends a warning from our robotic future. Vendors urgently need to improve with regards to product cyber security in the robotics industry and not relearn the issues of the past over half a decade.</p><blockquote><p>Yarbo sells autonomous lawn mowers and snow blowers, consumer robots priced between $1,500 and $5,000, deployed in private homes all over the world. Every one of them ships with a persistent SSH tunnel, a root password hardcoded identically across the entire fleet, and telemetry that phones home to <a href="https://finance.yahoo.com/news/more-details-access-bytedance-had-113034851.html">ByteDance</a>. None of this is disclosed at point of sale. These devices have WiFi, Halow and 4G connections.</p><p>The SSH tunnel works like this: each robot runs an FRP (Fast Reverse Proxy) client that opens a permanent outbound tunnel to a Yarbo-controlled server at <code>98.82.87.76</code>. SSH is exposed through this tunnel with <code>PermitRootLogin yes</code>. Anyone who knows a robot&#8217;s serial number can connect. No further credential is required on the proxy side.</p></blockquote><p><a href="https://github.com/Bin4ry/yarbo-nat-in-my-back-yard">https://github.com/Bin4ry/yarbo-nat-in-my-back-yard</a></p><h2>Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection</h2><p><strong>Joern Schneeweisz</strong> provides an example of our AI system vulnerability which looks suspiciously like a web vulnerability one might expect models should be able to find.</p><blockquote><p>To make matters worse, it was possible to completely bypass the workspace trust dialog. If the repo parameter in the deep link is set to a repository the user has already cloned locally and trusted (like <code>anthropics/claude-code</code>), the execution happened without any warning prompts.</p></blockquote><p><a href="https://0day.click/recipe/2026-05-12-cc-rce/">https://0day.click/recipe/2026-05-12-cc-rce/</a></p><h2>CPU OP Cache Corruption</h2><p><strong>AMD</strong> disclose a CPU level vulnerability..</p><blockquote><p>AMD has identified a vulnerability in the CPU operation (op/&#181;op) cache on Zen 2&#8209;based products that can cause incorrect instructions to be executed at a higher privilege level.</p><p>..</p><p>Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.</p></blockquote><p><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7052.html">https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7052.html</a></p><h1>Offense</h1><p>Attack capability, techniques and trade-craft. </p><h2>The Accidental C2: Exploring Dev Tunnels for Remote Access</h2><p><strong>Adam Chester</strong> repurposes dev tunnels further.. </p><blockquote><p>Dev Tunnels aren&#8217;t &#8220;just port forwarding&#8221;. They consist of layers of embedded protocols with RPC messages being exchanged. Once you peel the layers, you quickly see how Dev Tunnels are a C2 framework with extra steps.</p></blockquote><p><a href="https://specterops.io/blog/2026/05/06/dev-tunnels-the-accidental-c2/">https://specterops.io/blog/2026/05/06/dev-tunnels-the-accidental-c2/</a></p><h2>HyperVenom: Using Hyper-V for Ring -1 Control from Usermode</h2><p><strong>Gabriel Small</strong> delivers a super power which we can expect advanced actors looks to take advantage of in creative ways.</p><blockquote><p>HyperVenom is a hypervisor injection and attachment framework that leverages Microsoft&#8217;s Hyper-V for memory introspection. Taking advantage of Microsoft&#8217;s Virtualization-Based Security (VBS) on Windows 11, the framework intercepts VM-exits directly inside the hypervisor, allowing for code execution at the hypervisor privilege level. HyperVenom demonstrates how a lightweight, symbiotic payload can bypass Ring 0 visibility without causing timing or performance issues that would be picked up by telemetry.</p></blockquote><p><a href="https://gsmll.github.io/hypervenom/writeup/">https://gsmll.github.io/hypervenom/writeup/</a></p><h1>Exploitation</h1><p>What is being exploited..</p><h2>Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities</h2><p><strong>Cisco Talos</strong> detail ongoing exploitation&#8230; </p><blockquote><ul><li><p>Cisco Talos is tracking the active exploitation of <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW">CVE-2026-20182</a>, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage.</p></li><li><p>Successful exploitation of CVE-2026-20182 allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.</p></li><li><p>The exploitation of CVE-2026-20182 appears to have been limited so far and Talos clusters this activity under <a href="https://blog.talosintelligence.com/uat-8616-sd-wan/">UAT-8616</a> with high confidence.</p></li><li><p>Talos is also aware of a series of threat actors, distinct from UAT-8616, that have been observed to be exploiting a different, previously disclosed set of vulnerabilities, in a new way than previously identified, beginning March 2026 - specifically <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v">CVE-2026-20133, CVE-2026-20128 and CVE-2026-20122.</a> It is important to note that those vulnerabilities are distinct from and pre-date CVE-2026-20182. Cisco released <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v">software updates and a security advisory</a> addressing those vulnerabilities in February 2026, strongly recommending customers to upgrade.</p></li><li><p>We have identified multiple clusters of post-compromise activity, beginning March 2026, associated with the exploitation of CVE-2026-20133, CVE-2026-20128 and CVE-2026-20122 that deployed webshells and other malicious tooling, described in this post.</p></li><li><p>We observed the vast majority of this exploitation involved the use of ZeroZenX labs&#8217; proof-of-concept and accompanying JSP-based webshell which we track as &#8220;XenShell.&#8221;</p></li></ul></blockquote><p><a href="https://blog.talosintelligence.com/sd-wan-ongoing-exploitation/">https://blog.talosintelligence.com/sd-wan-ongoing-exploitation/</a></p><h2>RxRPC privesc PoC without fcrypt() restrictions</h2><p>sgkdev releases this Linux privilege escalation.. </p><p><a href="https://github.com/sgkdev/rxrpc_privesc">https://github.com/sgkdev/rxrpc_privesc</a></p><h1>Tooling and Techniques</h1><p>Low level tooling and techniques for attack and defence researchers</p><h2>Static Devirtualization of Themida</h2><p><strong>Christopher Drumm</strong> and <strong>naci</strong> show how to pull the feat of magic off..</p><blockquote><p>The devirtualized output is functionally 1:1 with the original. However, you may notice that different instructions and registers have been selected by the backend. This is a result of the register allocator and instruction selector making different choices, but crucially, no register spilling has occurred. The recovered code remains as tight and clean as the original, with no extraneous stack frames or artifacts.</p><p>Importantly, the devirtualized code is not just structurally similar, it is fully executable. The recovered function can be run as native code, loading cleanly in disassemblers and behaving identically to the original implementation.</p></blockquote><p><a href="https://back.engineering/blog/09/05/2026/">https://back.engineering/blog/09/05/2026/</a></p><p><a href="https://github.com/backengineering/themida-devirt">https://github.com/backengineering/themida-devirt</a></p><h2>llmh</h2><p><strong>Silas Cutler</strong> provides the beginnings to watch the new world.. </p><blockquote><p>Self-hosted web app for archiving, searching, and alerting on logs emitted by CLI LLM tools &#8212; Claude Code, Codex, Aider, and others.</p></blockquote><p><a href="https://github.com/silascutler/llmh">https://github.com/silascutler/llmh</a></p><h2>EtwWatcher</h2><p>Jonathan Johnson provides a powertool for those working with ETW..</p><blockquote><p>EtwWatcher is a static site that takes ETW provider snapshots captured via <a href="https://github.com/jonny-jhnson/ETWInspector">ETWInspector</a> from real Windows builds, commits them to a repo as NDJSON, and renders the whole thing client-side.</p></blockquote><p><a href="https://jonny-johnson.medium.com/etwwatcher-f657b3d60195">https://jonny-johnson.medium.com/etwwatcher-f657b3d60195</a></p><h1>Footnotes</h1><p>Some other small (and not so small) bits and bobs which might be of interest.</p><ul><li><p>Annual, quarterly and monthly reports</p><ul><li><p><em>Nothing overly of note this week, but keep an eye on</em> <a href="https://github.com/jacobdjwilson/awesome-annual-security-reports/tree/main/Annual%20Security%20Reports/2026">the Awesome Annual Security Reports 2026 collection</a></p></li></ul></li><li><p><a href="https://r136a1.dev/2026/05/07/where-have-all-the-complex-malware-and-their-analyses-gone/">Where Have All the Complex Windows Malware and Their Analyses Gone?</a></p></li><li><p><a href="https://github.com/yo-yo-yo-jbo/vr_difficulty">Why vulnerability discovery is difficult mathematically</a></p></li><li><p><a href="https://blog.cloudflare.com/copy-fail-linux-vulnerability-mitigation/">How Cloudflare responded to the &#8220;Copy Fail&#8221; Linux vulnerability</a></p></li><li><p>Artificial intelligence</p><ul><li><p>Fundamental</p><ul><li><p><a href="https://github.com/cactus-compute/needle">26m function call model that runs on incredibly small devices</a></p></li></ul></li><li><p>Applied non-cyber</p><ul><li><p><a href="https://developer.nvidia.com/blog/improving-bash-generation-in-small-language-models-with-grammar-constrained-decoding/">Improving Bash Generation in Small Language Models with Grammar-Constrained Decoding</a></p></li><li><p><a href="https://arxiv.org/abs/2605.10977">PASA: A Principled Embedding-Space Watermarking Approach for LLM-Generated Text under Semantic-Invariant Attacks</a></p></li><li><p><a href="https://arxiv.org/abs/2605.10907">Engineering Robustness into Personal Agents with the AI Workflow Store</a></p></li><li><p><a href="https://arxiv.org/abs/2605.14786">Known By Their Actions: Fingerprinting LLM Browser Agents via UI Traces</a></p></li><li><p><a href="https://arxiv.org/abs/2605.13706">Identifying AI Web Scrapers Using Canary Tokens</a></p></li></ul></li><li><p>Applied cyber specific</p><ul><li><p><a href="https://arxiv.org/abs/2605.10074">Agentic Fuzzing: Opportunities and Challenges</a></p></li><li><p><a href="https://www.originhq.com/blog/patch-diffing-pipeline">The Mythos We Have At Home: A Patch-Diffing Pipeline for N-Day Generation</a></p></li><li><p><a href="https://arxiv.org/abs/2605.11086">ExploitGym: Can AI Agents Turn Security Vulnerabilities into Real Attacks?</a></p></li><li><p><a href="https://arxiv.org/abs/2605.14153">ExploitBench: A Capability Ladder Benchmark for LLM Cybersecurity Agents</a></p><ul><li><p><a href="https://exploitbench.ai/">exploitbench</a> - Launching v8-bench, the first ExploitBench benchmark. It targets V8, the JavaScript and WebAssembly engine inside Chrome, Edge, Node.js, and Cloudflare Workers.</p></li></ul></li><li><p><a href="https://arxiv.org/abs/2605.11047">Red-Teaming Agent Execution Contexts: Open-World Security Evaluation on OpenClaw</a></p></li><li><p><a href="https://arxiv.org/abs/2605.10834">From Controlled to the Wild: Evaluation of Pentesting Agents for the Real-World</a></p></li><li><p><a href="https://arxiv.org/abs/2605.08690">AI-Accelerated Brute Force Cryptanalysis</a></p></li><li><p><a href="https://arxiv.org/abs/2605.08449">SL5 Standard for AI Security</a></p></li><li><p><a href="https://arxiv.org/abs/2605.12364">Attacks and Mitigations for Distributed Governance of Agentic AI under Byzantine Adversaries</a></p></li><li><p><a href="https://arxiv.org/abs/2605.15152">Widening the Gap: Exploiting LLM Quantization via Outlier Injection</a></p></li><li><p><a href="https://arxiv.org/abs/2605.15172">MetaBackdoor: Exploiting Positional Encoding as a Backdoor Attack Surface in LLMs</a></p></li><li><p><a href="https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/">Mythos finds a curl vulnerability</a></p></li><li><p><a href="https://arxiv.org/abs/2605.15097">Veritas: A Semantically Grounded Agentic Framework for Memory Corruption Vulnerability Detection in Binaries</a></p></li><li><p><a href="https://arxiv.org/abs/2605.14932">Toward Securing AI Agents Like Operating Systems</a></p></li><li><p><a href="https://arxiv.org/abs/2605.14460">Exploiting LLM Agent Supply Chains via Payload-less Skills</a></p></li><li><p><a href="https://arxiv.org/abs/2605.13989">VectraYX-Nano: A 42M-Parameter Spanish Cybersecurity Language Model with Curriculum Learning and Native Tool Use</a></p></li></ul></li></ul></li><li><p>Books</p><ul><li><p><a href="https://link.springer.com/book/10.1007/978-94-6265-759-5">Legal, Ethical, and Technical Dilemmas in Military Artificial Intelligence</a></p></li></ul></li><li><p>Events</p><ul><li><p><a href="https://www.quantumsoftwarelab.com/quantum-fringe-scotland">Quantum Fringe 2026</a>, Scotland</p></li><li><p><a href="https://www.youtube.com/playlist?list=PLILSGbVWGGPwuqdZhFrsf2sjEMPjIlceH">DistrictCon 2026</a> - Videos now online </p></li></ul></li></ul><p>Picture of the week in the context of AI&#8230; <a href="https://commons.wikimedia.org/wiki/File:IBM_150_Extra_Engineers_1951.jpg">we have been here before</a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!oTPV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45f640bb-420b-42fb-9f46-df91a5848fb2_960x1233.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!oTPV!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45f640bb-420b-42fb-9f46-df91a5848fb2_960x1233.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!oTPV!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45f640bb-420b-42fb-9f46-df91a5848fb2_960x1233.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!oTPV!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45f640bb-420b-42fb-9f46-df91a5848fb2_960x1233.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!oTPV!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45f640bb-420b-42fb-9f46-df91a5848fb2_960x1233.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!oTPV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45f640bb-420b-42fb-9f46-df91a5848fb2_960x1233.jpeg" width="960" height="1233" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/45f640bb-420b-42fb-9f46-df91a5848fb2_960x1233.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1233,&quot;width&quot;:960,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!oTPV!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45f640bb-420b-42fb-9f46-df91a5848fb2_960x1233.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!oTPV!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45f640bb-420b-42fb-9f46-df91a5848fb2_960x1233.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!oTPV!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45f640bb-420b-42fb-9f46-df91a5848fb2_960x1233.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!oTPV!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45f640bb-420b-42fb-9f46-df91a5848fb2_960x1233.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Finally my keynote from the CHERI Blossoms conference is now online..</p><div id="youtube2-9cXL0Bu9XzE" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;9cXL0Bu9XzE&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/9cXL0Bu9XzE?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Finally finally the <a href="https://creators.spotify.com/pod/profile/national-cyber-security-c6/episodes/The-Ransomware-Ecosystem-e2hi088">NCSC&#8217;s podcast series</a>.</p><div><hr></div><p><em>Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them. </em></p><p><em>This newsletter is subject to the NCSC website terms and conditions which can be found at <a href="https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions">https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions</a> and you can find out more about how will treat your personal information in our privacy notice at <a href="https://www.ncsc.gov.uk/section/about-this-website/privacy-statement">https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.</a></em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CTO at NCSC - Cyber Defence Analysis! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CTO at NCSC Summary: week ending May 10th]]></title><description><![CDATA[Leave passwords in the past. Passkeys are a faster, more secure alternative to using passwords..]]></description><link>https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-106</link><guid isPermaLink="false">https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-106</guid><pubDate>Sat, 09 May 2026 08:18:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/upload/w_1028,c_limit,q_auto:best/eevjmoerma7aiqeo6pra" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to the weekly highlights and analysis of the&nbsp;<a href="https://infosec.pub/c/blueteamsec?dataType=Post&amp;sort=New">blueteamsec</a>&nbsp;(and my wider reading). Not everything makes it in, but the best bits do. A community member is doing <a href="https://briefing.workshop1.net/">daily AI generated podcast of the last 24hours of posts</a>.</p><p>Operationally this week we have had edge device vulnerabilities in the guise of <a href="https://security.paloaltonetworks.com/CVE-2026-0300">CVE-2026-0300</a> in PAN-OS and other security critical functions such as <a href="https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs?language=en_US">Ivanti Endpoint Manager Mobile</a>. Once again highlighting why all vendors should implement our <a href="https://www.ncsc.gov.uk/guidance/guidance-on-digital-forensics-protective-monitoring">Guidance on digital forensics and protective monitoring specifications for producers of network devices and appliances - for device vendor</a>s (we know some have majoritively implemented now..)</p><p>In the high-level this week:</p><ul><li><p>Passkeys featured heavily this week for <strong>NCSC </strong>as we lead the charge:</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://x.com/NCSC/status/2052328422769066068?s=20&quot;,&quot;full_text&quot;:&quot;Leave passwords in the past - today is World Passkey Day! Passkeys are a faster, more secure alternative to using passwords. To learn more about what passkeys are and how to use them, head to: <a class=\&quot;tweet-url\&quot; href=/__u/ctoatncsc.substack.com/%22https://www.ncsc.gov.uk/passkeys/%22>ncsc.gov.uk/passkeys</a>\n<span class=\&quot;tweet-fake-link\&quot;>#WorldPasskeyDay</span> &quot;,&quot;username&quot;:&quot;NCSC&quot;,&quot;name&quot;:&quot;NCSC UK&quot;,&quot;profile_image_url&quot;:&quot;https://pbs.substack.com/profile_images/1993706703976542208/-cbARkMF_normal.jpg&quot;,&quot;date&quot;:&quot;2026-05-07T10:03:21.000Z&quot;,&quot;photos&quot;:[{&quot;img_url&quot;:&quot;https://substackcdn.com/image/upload/w_1028,c_limit,q_auto:best/l_twitter_play_button_rvaygk,w_88/eevjmoerma7aiqeo6pra&quot;,&quot;link_url&quot;:&quot;https://t.co/TTJF5ixlXY&quot;}],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:8,&quot;retweet_count&quot;:41,&quot;like_count&quot;:105,&quot;impression_count&quot;:14765,&quot;expanded_url&quot;:null,&quot;video_url&quot;:&quot;https://video.twimg.com/ext_tw_video/2052328338941743105/pu/vid/avc1/1280x720/_ltWynt8I8Q_fBA_.mp4?tag=12&quot;,&quot;video_preview_media_key&quot;:null,&quot;belowTheFold&quot;:false}" data-component-name="Twitter2ToDOM"></div><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://x.com/NCSC/status/2052375365469757934?s=20&quot;,&quot;full_text&quot;:&quot;Our CEO was on BBC Breakfast this morning to explain why passkeys are an easier, faster and more secure way to login. \n\nInterested in finding out more? Head to our website: <a class=\&quot;tweet-url\&quot; href=/__u/ctoatncsc.substack.com/%22http://ncsc.gov.uk/passkeys/%22>ncsc.gov.uk/passkeys</a>\n\n<span class=\&quot;tweet-fake-link\&quot;>#WorldPasskeyDay</span>&quot;,&quot;username&quot;:&quot;NCSC&quot;,&quot;name&quot;:&quot;NCSC UK&quot;,&quot;profile_image_url&quot;:&quot;https://pbs.substack.com/profile_images/1993706703976542208/-cbARkMF_normal.jpg&quot;,&quot;date&quot;:&quot;2026-05-07T13:09:53.000Z&quot;,&quot;photos&quot;:[],&quot;quoted_tweet&quot;:{&quot;full_text&quot;:&quot;People have been urged to start ditching passwords in favour of passkeys, where available, as a way to secure their accounts online.\n\nOn #BBCBreakfast Peter Ruddick explained why the National Cyber Security Centre is asking users to make the change\n\nhttps://t.co/uE4GFy1oMI&quot;,&quot;username&quot;:&quot;BBCBreakfast&quot;,&quot;name&quot;:&quot;BBC Breakfast&quot;,&quot;profile_image_url&quot;:&quot;https://pbs.substack.com/profile_images/1672665408166412291/5IrtDjX__normal.jpg&quot;},&quot;reply_count&quot;:2,&quot;retweet_count&quot;:12,&quot;like_count&quot;:56,&quot;impression_count&quot;:15230,&quot;expanded_url&quot;:null,&quot;video_url&quot;:null,&quot;video_preview_media_key&quot;:null,&quot;belowTheFold&quot;:false}" data-component-name="Twitter2ToDOM"></div></li><li><p><a href="https://www.theregister.com/security/2026/05/02/ai-digs-up-decades-of-code-debt-patch-up/5219734?utm_medium=twitter&amp;utm_source=dlvr.it">Brace for the patch tsunami: AI is unearthing decades of buried code debt</a> - <strong>The Register</strong> reports - <em>&#8220;The cyber agency is urging teams to get ahead of the incoming flood by shrinking their exposed footprint. "All organizations must take steps to identify and minimise their internet-facing (and other externally-exposed) attack surfaces as soon as is possible," Whitehouse said, adding that defenders should "prioritise technologies on your perimeter and then work inwards."</em></p></li><li><p><a href="https://www.gov.uk/government/publications/em-on-council-decision-2025799-on-the-eu-cyber-resilience-act">EM on Council Decision 2025/799 on the EU Cyber Resilience Act</a> - <strong>Department for Science, Innovation and Technology</strong> and <strong>Baroness Lloyd of Effra CBE </strong>publish - <em>&#8220;This explanatory memorandum is about a Council Decision (EU) 2025/799 of 14 April 2025 establishing the position to be taken on behalf of the European Union within the Joint Committee established by the Agreement on the withdrawal of the United Kingdom of Great Britain and Northern Ireland from the European Union and the European Atomic Energy Community as regards the adoption of a decision adding a newly adopted Union act to Annex 2 to the Windsor Framework.&#8221;</em></p></li><li><p><a href="https://www.homeaffairs.gov.au/about-us/our-portfolios/cyber-security/cyber-incident-review-board">The Cyber Incident Review Board</a> - Australia <strong>Department of Home Affairs</strong> launches - <em>&#8220;The Board will only review an incident after it has occurred and initial investigation and response efforts have been completed. Reviews will focus on a single incident or a group of similar incidents. These may share features such as attack method, type of system affected, or a known vulnerability. The Board does not assign blame or determine who is responsible for an incident. Published reviews will not include personal or classified information, including anything that could affect national security, defence, or international relations of the Commonwealth.&#8221;</em></p></li><li><p><a href="https://cyber.gouv.fr/actualites/publication-du-rapport-dactivite-2025-de-lanssi/">Publication du rapport d&#8217;activit&#233; 2025 de l&#8217;ANSSI</a> - <strong>ANSSI </strong>publishes - <em>&#8220;The year 2025 was marked by the publication of the National Strategic Review (NSR) 2025, which sets out new national strategic guidelines for defense and national security. This review adapts our defense to a new, degraded environment in which cyberspace has become an arena of competition, disputes, and sometimes even uninhibited confrontation, reflecting geopolitical tensions and international rivalries.&#8221;</em></p></li><li><p><a href="https://www.abw.gov.pl/pl/aktualnosci/2815,Agencja-Bezpieczenstwa-Wewnetrznego-2024-2025-Wybrane-aktywnosci.html">Agencja Bezpiecze&#324;stwa Wewn&#281;trznego 2024-2025. Wybrane aktywno&#347;ci</a> - Polish <strong>AgencjaBezpiecze&#324;stwaWewn&#281;trznego </strong>publishes <strong>-  </strong><em>&#8220;In 2025, incidents involving security breaches at water treatment plants in Jab&#322;onna Lacka, Szczytno, Ma&#322;dyty, Tolkmicko, and Sierakowo were reported. In some cases, attackers gained access to industrial control systems and were able to change the technical parameters of the devices, posing a direct risk to their continued operation and, consequently, to the supply of water to the public.&#8221;</em></p></li><li><p><a href="https://www.bloomberg.com/news/articles/2026-04-29/why-humanoid-robots-will-soon-become-the-ultimate-ai-frontier">Why Humanoid Robots Are the Ultimate AI Frontier</a> - <strong>Bloomberg</strong> asserts - <em>&#8220;Humanoid robots, or bipedal machines powered by software, are emerging as one of the more tangible outputs of the artificial intelligence revolution. The growing obsession with them is easy to explain: They look like us, move like us and&#8212;increasingly&#8212;can learn like us. That makes them the ultimate general-purpose machine for factories, warehouses and eventually your home.&#8221;</em></p></li><li><p><a href="https://www.wsj.com/tech/ai/softbank-plots-ipo-for-new-robotics-venture-c52c2297?st=PvvT6E">SoftBank Plots IPO for New Robotics Venture</a> - <strong>The Wall Street Journal</strong> reports - <em>&#8221;The new venture, called Roze AI, aims to make the physical buildout of AI infrastructure more efficient, including by using autonomous robotics to build data centers, people familiar with the matter said. It plans to take the new venture public as soon as the second half of the year, the people said. &#8220;</em></p></li><li><p><a href="https://www.bloomberg.com/news/articles/2026-04-29/us-brain-implant-company-axoft-tests-on-patient-in-china-raises-more-money">US Brain Implant Company Tests in China in Apparent First</a> - <strong>Bloomberg</strong> reports - <em>&#8220;Brain-computer interfaces, or BCIs, can be astounding medical treatments, enabling paralyzed people to control computers and other electronic devices. The technology could also be used to monitor productivity and potentially enhance brain function, making them appealing for industrial or military applications.&#8221;</em></p></li><li><p>Reporting on/from China</p><ul><li><p><a href="https://cset.georgetown.edu/article/chinas-pla-challenges-and-competitions/">China&#8217;s PLA Challenges and Competitions</a> - <strong>Center for Security and Emerging Technology</strong> outlines - <em>&#8220;14 challenges from a dataset of documents published by the PLA between January 2023 and December 2024. To supplement the most recent PLA efforts, also includes information on nationwide external technology challenges from 2023 to 2025, drawn from public, Chinese-language news sources. These challenges underscore three points:</em></p><ul><li><p><em>evidence of multi-domain/cross-domain integration, which moves beyond rhetoric to signal action;</em></p></li><li><p><em>emphasis on unmanned technological innovation, particularly unmanned aerial vehicles, and new efforts on technological UAV countermeasures; and</em></p></li><li><p><em>reinforcement of military-civil fusion with key actors in academia, the military, and industry, drawing on a wider national innovation ecosystem for both hardware and software advances.&#8221;</em></p></li></ul></li><li><p><a href="https://chinadigitaltimes.net/chinese/726411.html">Urgent Notice Regarding the Complete Ban on Overseas Internet Traffic and the Strict Prohibition of Circumvention Services </a>- <strong>China Digital Times</strong> reports - <em>&#8220;the Chinese government launched a new round of strict crackdowns on cross-border internet access and censorship evasion in early April 2026.&#8221;</em></p></li><li><p><a href="https://www.scmp.com/tech/tech-trends/article/3352212/phones-robots-chinas-supply-chain-eyes-next-growth-curve-humanoid">From phones to humanoid robots: China&#8217;s supply chain eyes next growth curve</a> - <strong>South China Morning Post</strong> reports - <em>&#8221;The sector received a glimpse of that crossover after Honor&#8217;s humanoid robot D1, a dark-horse entrant from the smartphone maker, won Beijing&#8217;s recent robot half-marathon, beating established Chinese robotics names such as Unitree.&#8221;</em></p></li><li><p><a href="https://www.reuters.com/business/media-telecom/us-telecom-agency-votes-expand-tech-crackdown-china-2026-04-30/">US telecom agency votes to expand tech crackdown on China</a> - <strong>Reuters</strong> reports - <em>&#8220;The Federal Communications Commission on Thursday voted unanimously to &#8203;advance a proposal to bar all Chinese labs from testing electronic &#8204;devices such as smartphones, cameras and computers for use in the United States.&#8221;</em> .. <em>&#8220;In a separate 3-0 vote, &#8288;the commission advanced a proposal to bar China Mobile, China Telecom and China &#8203;Unicom <a href="https://www.reuters.com/markets/companies/0762.HK">(0762.HK), opens new tab</a> from operating data centers in the U.S&#8221;</em></p></li><li><p><a href="https://silverado.org/publications/mapping-the-us-display-supply-chain/">Sourcing the Screen: Mapping the U.S. Display Supply Chain</a> - <strong>Silverado Policy Thinktank</strong> researchers - <em>&#8220;China is the leading global producer of display cells and is projected to account for 75 percent of display production capacity in 2028. Producers outside of China closed a significant number of plants over the last few years.&#8221;</em></p></li><li><p><a href="https://jericho.blog/2026/05/01/why-data-from-so-many-breaches-never-sees-the-light-of-day/">Why Data From So Many Breaches Never Sees the Light of Day</a> - <strong>Jericho</strong> opines - <em>&#8220;An unexpected recurring pattern is that when criminals take the time to break into a site, move laterally, compromise more and more systems, and ultimately find the digital crown jewels so to speak, but then they leak them in a manner that virtually no one ever sees. Oftentimes we only have news articles about it because a journalist or three were fast enough to verify the leak and data before it vanishes. Why does this happen at all, let alone so frequently?&#8221;</em></p></li></ul></li><li><p>AI</p><ul><li><p><a href="https://www.bbc.co.uk/future/article/20260428-ai-companies-want-you-to-be-afraid-of-them">Why AI companies want you to be afraid of them</a> - <strong>BBC</strong> opines - "<em>If you want to understand how an organisation, particularly a corporation, is going to behave, look at what its incentives are," says Vallor.</em> </p></li><li><p><a href="https://www.reversinglabs.com/blog/claude-promptmink-malware-crypto">Claude adds malware to crypto agent</a> - <strong>Reversing</strong> Labs asserts - &#8220;<em>[we] discovered malicious code in a crypto trading project after an AI-based coding agent added a malicious package as a dependency. The validate-sdk/v2 package poses as a routine data validation tool while siphoning off sensitive secrets from its host environment.&#8221;</em></p></li><li><p><a href="https://www.nist.gov/news-events/news/2026/05/caisi-evaluation-deepseek-v4-pro">CAISI Evaluation of DeepSeek V4 Pro</a>- <strong>NIST</strong> evaluates - <em>&#8220;CAISI evaluations indicate that DeepSeek V4&#8217;s capabilities lag behind the frontier by about 8 months&#8221;</em></p></li><li><p><a href="https://bughunters.google.com/blog/evolving-the-android-chrome-vrps-for-the-ai-era">Evolving the Android &amp; Chrome VRPs for the AI Era</a> - <strong>Google</strong> outlines - <em>&#8220;Focusing On Issues With the Highest User Impact: We are revising our program scope to emphasize categories that represent the highest risk to our users. We are also prioritizing categories that remain more challenging for automated AI tooling to find to ensure we reward researchers for their unique skills and talents.&#8221;</em></p></li><li><p><a href="https://www.cyera.com/research/bleeding-llama-critical-unauthenticated-memory-leak-in-ollama">Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama</a> - <strong>Cyera</strong> discloses - <em>&#8220;We discovered a critical vulnerability (CVE-2026&#8211;7482, CVSS 9.1) in Ollama that enables unauthenticated attackers to leak the entire Ollama process memory, potentially impacting <strong>300,000</strong> servers globally. The leaked memory contains user messages (prompts), system prompts, and environment variables.&#8221;</em></p></li><li><p><a href="https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/">Behind the Scenes Hardening Firefox with Claude Mythos Preview</a> - <strong>Mozilla</strong> detail - <em>&#8220;Note that a number of these bugs are sandbox escapes, which would need to be combined with other exploits to achieve a full-chain Firefox compromise. These reports presume that the sandboxed process that renders site content has already been compromised with some separate bug, and is now running attacker-controlled machine code attempting to escalate control into the privileged parent process.&#8221;</em></p></li><li><p><a href="https://breakingdefense.com/2026/05/army-plans-fast-follow-up-to-ai-cyber-wargame-with-industry-officials/">Army plans fast follow-up to AI cyber wargame with industry: Officials</a> - <strong>Breaking Defense</strong> reports - <em>&#8220;A recent <a href="https://www.dvidshub.net/image/9648679/ai-ttx-20">cyber wargame</a> with senior tech industry executives has the US Army considering more autonomy for AI &#8220;agents,&#8221; especially in wartime, including development of a &#8220;risk continuum&#8221; policy for when it might have to let agentic AI watchdogs off the leash.&#8221;</em></p></li><li><p><a href="https://securityandtechnology.org/virtual-library/white-paper/ai-agents-agency-in-the-internet-ecosystem/">AI Agents &amp; Agency in the Internet Ecosystem</a> - <strong>Institute for Security + Technology</strong> think tanks - <em>&#8220;Identity and attribution frameworks must evolve to account for persistent, cross-system agents whose actions may not map cleanly onto individual human operators as principals.&#8221; .. &#8220;Evaluation frameworks must evolve to be accurate and reliable in order to cultivate real-world trust.&#8221; .. &#8220;Legal doctrine must evolve to fully map the spectrum of risks that agents acting under delegated authority can introduce.&#8221;</em></p></li><li><p><a href="https://www.scmp.com/tech/big-tech/article/3352068/chinese-firms-face-pressure-ai-investments-us-peers-spending-keeps-soaring">Chinese firms face pressure on AI investments as US peers&#8217; spending keeps soaring</a> - <strong>South China Morning Post</strong> reports - <em>&#8220;Google and Microsoft on Thursday both said that their full-year capex would reach about US$190 billion, while Meta Platforms raised its capex estimates for this year to US$145 billion. Amazon kept its outlook unchanged from last year at US$200 billion.&#8221;</em></p></li><li><p><a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1024">EU agrees to simplify AI rules to boost innovation and ban &#8216;nudification&#8217; apps to protect citizens</a> - <strong>European Commission</strong> announces - <em>&#8220;The Commission proposed the Digital Omnibus on AI only five months ago as part of the EU&#8217;s simplification agenda to boost Europe&#8217;s competitiveness. This will make the implementation of the <a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai">AI Act</a> for EU businesses easier while maintaining its benefits for European society, safety and fundamental rights.&#8221;</em></p></li><li><p><a href="https://www.bcg.com/publications/2026/ceos-and-boards-are-aligned-on-ai-in-theory-but-divided-in-practice">CEOs and Boards Are Aligned on AI in Theory, but Divided in Practice </a>- <strong>Boston Consulting Group</strong> consult - &#8220;</p><ul><li><p><em>CEOs worry that AI hype may be distorting boardroom judgment.</em></p></li><li><p><em>Boards are confident in their AI understanding, but CEOs are less convinced.</em></p></li><li><p><em>Boards favor faster AI implementation. CEOs are more measured about the pace of change.</em></p></li><li><p><em>Both sides agree the executive team should lead on AI, yet CEOs appear to bear an outsize share of the responsibility.</em></p></li><li><p><em>CEOs see AI ROI as a bigger factor in their performance evaluation than boards do.&#8221;</em></p></li></ul></li></ul></li><li><p><em>Cyber proliferation</em></p><ul><li><p><a href="https://diaricatalunya.cat/en/barcelones/general/investigation-into-pegasus-espionage-against-omnium-members-reopened">Investigation into Pegasus espionage against &#210;mnium members reopened</a> - <strong>Diari de Catalunya</strong> reports - <em>&#8220;The Barcelona High Court has reopened the investigation into the Pegasus software espionage that affected three members of &#210;mnium Cultural, admitting evidence of a crime and pointing to a possible intervention by the CNI.&#8221;</em></p></li></ul></li><li><p>Bounty Hunting</p><ul><li><p><a href="https://www.rtl-sdr.com/student-arrested-in-taiwan-for-using-sdr-and-handheld-radios-to-halt-four-high-speed-trains-with-tetra-hack/comment-page-221/">Student Arrested in Taiwan for using SDR and Handheld Radios to Halt Four High Speed Trains with TETRA Hack</a> - <strong>RTL SDR</strong> reports - <em>&#8220;The <a href="https://www.taipeitimes.com/News/taiwan/archives/2026/05/05/2003856781">Taipei Times</a> has reported that a 23-year-old university student in Taiwan has been arrested after using a software-defined radio and hand held radio to hack into Taiwan High Speed Rail Corporation's (THSRC) internal radio communications and halt four trains mid-service.&#8221;</em></p></li><li><p><a href="https://www.justice.gov/opa/pr/two-americans-who-attacked-multiple-us-victims-using-alphv-blackcat-ransomware-sentenced">Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware Sentenced to Prison</a> - US <strong>Department of Justice</strong> announces - <em>&#8220;Two American cybersecurity professionals were sentenced today to four years each in prison for their role in a conspiracy to obstruct, delay, or affect commerce through extortion in connection with ransomware attacks occurring in 2023.&#8221;</em></p></li><li><p><a href="https://www.justice.gov/opa/pr/two-us-nationals-sentenced-facilitating-fraudulent-remote-information-technology-worker-0">Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Schemes to Generate Revenue for the Democratic People&#8217;s Republic of Korea</a> - US <strong>Department of Justice</strong> announces - <em>&#8220;These Represent the 7th and 8th Sentences of U.S.-Based &#8220;Laptop Farmers&#8221; Secured in last 5 Months as part of Ongoing Efforts to Disrupt North Korea&#8217;s Illicit Revenue Generation&#8221;</em></p></li><li><p><a href="https://www.justice.gov/archives/opa/pr/twin-brothers-sentenced-wire-fraud-conspiring-hack-us-department-state-and-private-company">Twin Brothers Sentenced for Wire Fraud, Conspiring to Hack into U.S. Department of State and Private Company</a> - US <strong>Department of Justice</strong> announces - <em>&#8221;Muneeb Akhter was sentenced to 39 months in prison and Sohaib Akhter was sentenced to 24 months in prison. Each man was also sentenced to three years of supervised release.&#8221;</em></p></li><li><p><a href="https://www.bloomberg.com/news/articles/2026-05-01/russian-charged-in-oil-and-gas-facility-hacks-pleads-guilty">Russian Hacker Pleads Guilty in Oil and Gas Facility Attacks</a> - <strong>Bloomberg</strong> reports - <em>&#8220;Artem Vladimirovich Revenskii, a Russian national, pleaded guilty to charges that carry as many as 27 years in prison for breaking into and damaging critical oil and gas infrastructure in several countries. Revenskii was part of a Russian government-sponsored hacking group known as Sector16, which targeted countries &#8220;perceived to be enemies of the Russian government&#8221;, including the US, Ukraine, Germany, France, and Latvia.&#8221;</em></p></li><li><p><a href="https://gp.gov.ua/en/posts/na-lvivshhini-zatrimano-xakersku-grupu-yaka-zlamuvala-igrovi-akaunti-i-otrimala-maize-10-mln-grn-pributku-vid-yix-prodazu-v-rosiyu">A hacker group was detained in Lviv Oblast, which hacked game accounts and received almost UAH 10 million in profit from their sale in Russia </a>- Ukraine <strong>General Prosecutors Office</strong> announces - <em>&#8220;According to the investigation, a 19-year-old resident of Drohobych, involving two friends aged 21 and 22, organized a scheme to profit from the sale of other people's accounts on this online platform.&#8221;</em></p></li></ul></li><li><p>Market Incentives</p><ul><li><p><a href="https://www.ft.com/content/12e36e02-7ff9-4a45-9544-872822fe9c97?syn-25a6b1a6=1">Insurers move to cap cyber payouts related to AI and &#8216;LLMjacking&#8217;</a> - <strong>Financial Times</strong> reports - <em>&#8220;Insurers are introducing new caps on payouts for cyber losses and regulatory fines related to AI use, as the industry rushes to reduce its exposure to the rapidly advancing technology. QBE and Beazley are among the groups that have proposed language for cyber insurance policies limiting payouts on AI losses, according to brokers and documents reviewed by the FT.&#8221;</em></p></li></ul></li></ul><p>No reflections this week but the audio from the keynote I gave at the <a href="https://gtr.ukri.org/projects?ref=EP%2FZ534845%2F1">UKRI funded</a> <a href="https://www.crane.ac.uk/crane/">CRANE</a> AI Special Interest Group a week or so ago is now online:</p><div id="youtube2-LKUHXQtOjX0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;LKUHXQtOjX0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/LKUHXQtOjX0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Not getting this via email? Subscribe:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Think someone else would benefit? Share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-106?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-106?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p><strong>All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.</strong></p><p>Have a lovely Saturday&#8230;</p><p>Ollie</p><h1>Cyber threat intelligence</h1><p>Who is doing what to whom and how allegedly.</p><h2>Reporting on Russia</h2><h3>Unpacking Russian-Iranian Private-Sector Cyber Connections</h3><p><strong>Justin Sherman</strong> breakdown alleged links and potential for extended state enablers.</p><blockquote><p>Private-sector cybersecurity companies play key roles in the Russian and Iranian cyber ecosystems across offensive capability deployment, talent cultivation, recruitment, defensive capabilities and services, international connectivity and partnerships, and more. It is clear that Russian and Iranian cybersecurity companies, including those with close ties to their respective states&#8217; security services, have been expanding their touchpoints and engagements in recent years. Core focus areas include cyber threat monitoring and IT and OT cybersecurity, among others, and prompt many open questions, such as what exactly some of the companies may be doing behind the scenes.</p></blockquote><p><a href="https://margin.re/2026/05/unpacking-russian-iranian-private-sector-cyber-connections/">https://margin.re/2026/05/unpacking-russian-iranian-private-sector-cyber-connections/</a></p><h3>Revealed: Russia&#8217;s top secret spy school teaching hacking and election meddling</h3><p><strong>The Guardian</strong> reports alleged Russian highlighting talent pipeline development..</p><blockquote><p>The files, covering several years of activity up to 2025, include course syllabuses, exam records, staff contracts and the career assignments of individual graduates, tracing their path from classroom exercises in hacking and disinformation to postings in some of the most notorious cyber-units in the Russian military intelligence apparatus.</p></blockquote><p><a href="https://www.theguardian.com/world/2026/may/07/revealed-russia-top-secret-spy-school-hacking-western-electoral-interference">https://www.theguardian.com/world/2026/may/07/revealed-russia-top-secret-spy-school-hacking-western-electoral-interference</a></p><h2>Reporting on China</h2><h3>DAEMON Tools software infected &#8211; supply chain attack ongoing since April 8, 2026</h3><p><strong>Igor Kuznetsov</strong> , <strong>Georgy Kucherin</strong> , <strong>Leonid Bezvershenko</strong> and <strong>Anton Kargin </strong>detail this unattributed supply chain attack but allegedly Chinese in origination. The very focused subset of subsequent intrusions using this access shows a degree of sophistication. </p><blockquote><p>In early May 2026, we identified installers of the DAEMON Tools software, used for mounting disk images, to be compromised with a malicious payload. These installers are distributed from the legitimate website of DAEMON Tools and are signed with digital certificates belonging to DAEMON Tools developers. Our analysis revealed that the software installers have been trojanized starting from April 8, 2026. Specifically, we identified versions of DAEMON Tools ranging from 12.5.0.2421 to 12.5.0.2434 to be compromised. Artifacts suggesting that the threat actor behind this attack is Chinese-speaking have been identified in the malicious implants observed. We contacted AVB Disc Soft, the developer company of DAEMON Tools, so that further actions could be taken to remediate the attack consequences.</p></blockquote><p><a href="https://securelist.com/tr/daemon-tools-backdoor/119654/">https://securelist.com/tr/daemon-tools-backdoor/119654/</a></p><h3>Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia</h3><p><strong>Daniel Lunghi</strong> and <strong>Lucas Silva</strong> detail this alleged Chinese campaign which is noteworthy for the use of n-day and Internet facing infrastructure. It highlights the importance of attack surface minimisation, rapid remediation and protective monitoring</p><blockquote><ul><li><p>A newly identified set of China-aligned campaigns is targeting government entities and critical infrastructure across South, East, and Southeast Asia, as well as one NATO member state. We are currently tracking this activity under the temporary intrusion set designation SHADOW-EARTH-053.</p></li><li><p>Nearly half the targets were also compromised by a related intrusion set (SHADOW-EARTH-054), sharing identical tool hashes and overlapping TTPs, though evidence suggests independent exploitation of the same vulnerabilities rather than direct operational coordination.</p></li><li><p>The group exploits N-day vulnerabilities in internet-facing Microsoft Exchange and Internet Information Services (IIS) servers (e.g., ProxyLogon chain), then deploys web shells (GODZILLA) for persistent access and stages ShadowPad implants via DLL sideloading of legitimate signed executables.</p></li><li><p>These older Microsoft Exchange vulnerabilities continue to serve as effective initial access vectors. SHADOW-EARTH-053&#8217;s successful exploitation of these long-patched issues confirms that organizations still running legacy or unpatched Exchange servers remain at significant risk of mailbox compromise, credential theft, and prolonged attacker access.</p></li></ul></blockquote><p><a href="https://www.trendmicro.com/en_us/research/26/d/inside-shadow-earth-053.html">https://www.trendmicro.com/en_us/research/26/d/inside-shadow-earth-053.html</a></p><h3>UAT-8302 and its box full of malware</h3><p><strong>Jungsoo An</strong>, <strong>Asheer Malhotra</strong> and Brandon White detail this alleged Chinese threat actor with a regional set of focuses. Highlights some diversity in the system in terms of implants.</p><blockquote><ul><li><p>Cisco Talos is disclosing UAT-8302, a sophisticated, China-nexus advanced persistent threat (APT) group targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025.</p></li><li><p>After successful compromises, UAT-8302 deploys multiple custom-made malware families that have previously been used by other known China-nexus threat actors.</p></li><li><p>Talos discovered a .NET-based backdoor we track as &#8220;NetDraft&#8221; that is a C#-based variant of the FinalDraft/SquidDoor malware family developed and operated by <a href="https://www.security.com/threat-intelligence/jewelbug-apt-russia">Jewelbug</a>/<a href="https://www.elastic.co/security-labs/fragile-web-ref7707">REF7707</a>/<a href="https://unit42.paloaltonetworks.com/advanced-backdoor-squidoor/">CL-STA-0049</a>/<a href="https://www.welivesecurity.com/en/eset-research/longnosedgoblin-tries-sniff-out-governmental-affairs-southeast-asia-japan/">LongNosedGoblin</a>, a cluster of China-nexus APT actors.</p></li><li><p>Furthermore, UAT-8302 also uses an updated version of the <a href="https://securelist.com/eastwind-apt-campaign/113345/">CloudSorcerer backdoor</a>, a malware family used in attacks against Russian government entities in 2024.</p></li><li><p>UAT-8302 also used VSHELL and its SNOWLIGHT stager in their operations, along with a new Rust-based stager that we track as SNOWRUST.</p></li></ul></blockquote><p><a href="https://blog.talosintelligence.com/uat-8302/">https://blog.talosintelligence.com/uat-8302/</a></p><h3>DragonBreath: Dragon in the Kernel</h3><p><strong>Alex Necula</strong> &amp; <strong>Ellis Stannard</strong> detail an alleged Chinese nexus maliciously signed kernel driver. Showing that code signing eco-systems continue to be a target by malicious actors with some success.</p><blockquote><p>A 0-day BYOVD vulnerability in dragoncore_k.sys signed by Zhengzhou 403 Network Technology, with shell company analysis, Dragon Breath APT-Q-27 attribution, and an APT31 / Wuhan Xiaoruizhi personnel nexus.</p></blockquote><p><a href="https://ransom-isac.org/blog/dragonbreath-dragon-in-the-kernel/">https://ransom-isac.org/blog/dragonbreath-dragon-in-the-kernel/</a></p><h2>Reporting on North Korea</h2><h3>A rigged game: ScarCruft compromises gaming platform in a supply-chain attack</h3><p><strong>Filip Jur&#269;acko</strong> details this alleged North Korean operation which again utilises supply chain tradecraft. </p><blockquote><ul><li><p>North Korea-aligned APT group ScarCruft compromised a video game platform used by ethnic Koreans living in the Yanbian region in China.</p></li><li><p>The gaming platform&#8217;s Windows client was compromised through a malicious update leading to the RokRAT backdoor, which deployed the more sophisticated BirdCall backdoor.</p></li><li><p>Android games available on the gaming platform were trojanized to contain the Android version of the BirdCall backdoor &#8211; a new tool in ScarCruft&#8217;s arsenal.</p></li><li><p>The goal of the campaign is espionage, with the backdoor capable of collecting personal data and documents, taking screenshots, and making voice recordings.</p></li></ul></blockquote><p><a href="https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/">https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/</a></p><h2>Reporting on Iran</h2><h3>Iranian-Nexus Operation Against Oman&#8217;s Government: 12 Ministries Hit and 26,000 Citizen Records Exposed</h3><p><strong>Hunt.io</strong> detail an alleged Iranian compromise of a foreign state by gaining access to what looks like a command and control server.</p><blockquote><ul><li><p>A custom webshell deployed on mersaltest.mjla.gov[.]om provided persistent access to the ministries&#8217; network, with C2 logs confirming active operator sessions as recently as April 10, 2026.</p></li><li><p>Over 26,000 Ministry of Justice user records, judicial case data, committee decisions, and both SAM and SYSTEM registry hives were extracted from the environment.</p></li><li><p>A dedicated gov[.]om folder included 12 exploit scripts, including Exchange spraying, SQL server escalation, and a reflective execution variant.</p></li><li><p>A README document labeled the above server as &#8220;VPS C2,&#8221; suggesting this is just one node within a larger infrastructure that remains unidentified.</p></li></ul></blockquote><p><a href="https://hunt.io/blog/iranian-nexus-oman-government-intrusion">https://hunt.io/blog/iranian-nexus-oman-government-intrusion</a></p><h3>Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware</h3><p><strong>Alexandra Blia</strong> and <strong>Ivan Feigl </strong>detail an alleged Iranian state ransomware operation which which is noteworthy given the aggressive nature.</p><blockquote><p>In early 2026, a sophisticated intrusion initially appearing to be a standard Chaos ransomware attack was assessed to be consistent with a targeted state-sponsored operation. While the threat actor operated under the banner of the Chaos ransomware-as-a-service (RaaS) group, forensic analysis revealed the incident was a "false flag" masquerade. Technical artifacts, including a specific code-signing certificate and Command-and-Control (C2) infrastructure, suggest with moderate confidence that this activity is linked to MuddyWater (Seedworm), an Iranian Advanced Persistent Threat (APT) affiliated with the Ministry of Intelligence and Security (MOIS).</p></blockquote><p><a href="https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/">https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/</a></p><h2>Reporting on Other or Unknown Actors</h2><h3>OceanLotus suspected of using PyPI to deliver ZiChatBot malware</h3><p><strong>GReAT</strong> walk through a campaign which was running last year again highlighting the fragility of software supply chain security.</p><blockquote><p>While these wheel packages do implement the features described on their PyPI web pages, their true purpose is to covertly deliver malicious files. These files can be either .DLL or .SO (Linux shared library), indicating the packages&#8217; ability to target both Windows and Linux platforms. They function as droppers, delivering the final payload &#8211; a previously unknown malware family that we have named <code>ZiChatBot</code>. Unlike traditional malware, ZiChatBot does not communicate with a dedicated command and control (C2) server, but instead uses a series of REST APIs from the public team chat app Zulip as its C2 infrastructure.</p></blockquote><p><a href="https://securelist.com/oceanlotus-suspected-pypi-zichatbot-campaign/119603/">https://securelist.com/oceanlotus-suspected-pypi-zichatbot-campaign/119603/</a></p><h3>South-East Asian Military Entities Targeted via cPanel (CVE-2026-41940)</h3><p><strong>Ctrl-Alt-Intel</strong> gain insight to exploitation of cPanel with specific regional focuses cris crossing the globe. </p><blockquote><p>On 2nd May 2026, Ctrl-Alt-Intel identified an exposed attacker staging server that provided direct visibility into one such operation. From this infrastructure, we observed an unknown threat actor interactively targeting <strong>government and military entities in South-East Asia</strong>, alongside a smaller set of <strong>MSPs and hosting providers</strong> in the Philippines, Laos, Canada, South Africa, and the United States. The actor relied heavily on public proof-of-concept code for <strong>CVE-2026-41940</strong>.</p><p>..</p><p>Exposed threat actor data also detailed a separate <strong>custom exploit chain</strong> for an Indonesian defence-sector training portal, alongside evidence of <strong>earlier exfiltration of Chinese railway-sector data</strong>.</p></blockquote><p><a href="https://ctrlaltintel.com/research/SEA-CPanel/">https://ctrlaltintel.com/research/SEA-CPanel/</a></p><h3>The Manlinghua organization used Python samples packaged in NUITKA for delivery</h3><p><strong>360 Threat Intelligence Security Centre</strong> detail this attack flow which is noteworthy due to the limited initial cradle which shows an evolution in tradecraft.</p><blockquote><p>The core initial payload of this type of attack by the Manlinghua organization is a Python sample packaged with NUITKA. This file has a simple function: downloading a backdoor component. The main function of this backdoor component is to execute cmd commands. By remotely executing cmd commands, attackers can perform the following operations: obtain basic system information, download subsequent backdoor components, download Python script execution suites, and download data theft components, etc. </p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!6e7x!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae971719-fa1d-4cad-b389-4d1716e1f626_955x844.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!6e7x!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae971719-fa1d-4cad-b389-4d1716e1f626_955x844.png 424w, /__u/substackcdn.com/image/fetch/$s_!6e7x!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae971719-fa1d-4cad-b389-4d1716e1f626_955x844.png 848w, /__u/substackcdn.com/image/fetch/$s_!6e7x!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae971719-fa1d-4cad-b389-4d1716e1f626_955x844.png 1272w, /__u/substackcdn.com/image/fetch/$s_!6e7x!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae971719-fa1d-4cad-b389-4d1716e1f626_955x844.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!6e7x!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae971719-fa1d-4cad-b389-4d1716e1f626_955x844.png" width="955" height="844" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae971719-fa1d-4cad-b389-4d1716e1f626_955x844.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:844,&quot;width&quot;:955,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:212567,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://ctoatncsc.substack.com/i/196978529?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae971719-fa1d-4cad-b389-4d1716e1f626_955x844.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!6e7x!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae971719-fa1d-4cad-b389-4d1716e1f626_955x844.png 424w, /__u/substackcdn.com/image/fetch/$s_!6e7x!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae971719-fa1d-4cad-b389-4d1716e1f626_955x844.png 848w, /__u/substackcdn.com/image/fetch/$s_!6e7x!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae971719-fa1d-4cad-b389-4d1716e1f626_955x844.png 1272w, /__u/substackcdn.com/image/fetch/$s_!6e7x!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae971719-fa1d-4cad-b389-4d1716e1f626_955x844.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><a href="https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247508516&amp;idx=1&amp;sn=a869f67294b5777615ad597c3730105e&amp;chksm=f9c1912dceb6183b4f7f359de87814c613d58b671245307a99857eb03847a0860743516e7fae&amp;scene=178&amp;cur_album_id=1955835290309230595&amp;search_click_id=#rd">https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247508516&amp;idx=1&amp;sn=a869f67294b5777615ad597c3730105e&amp;chksm=f9c1912dceb6183b4f7f359de87814c613d58b671245307a99857eb03847a0860743516e7fae&amp;scene=178&amp;cur_album_id=1955835290309230595&amp;search_click_id=#rd</a></p><h3>Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI</h3><p><strong>Kirill Boychenko</strong> evidence that Go and Ruby is also being targeted into software supply chain enabled attacks.</p><blockquote><p>We investigated the GitHub account <code>BufferZoneCorp</code>, which published a cluster of repositories linked to malicious Ruby gems and Go modules. The account is part of a software supply chain campaign targeting developers, CI runners, and build environments across two ecosystems.</p><p>On the Ruby side, the analyzed gems automate secret theft. They harvest secret-bearing environment variables and read local credential material such as SSH keys, AWS credentials, <code>.npmrc</code>, <code>.netrc</code>, GitHub CLI configuration, and RubyGems credentials, then send the collected data to a hidden exfiltration endpoint.</p><p>On the Go side, the campaign is more diverse. Some modules modify <code>GITHUB_ENV</code>, poison <code>GOPROXY</code>, weaken checksum protections, and tamper with <code>go.sum</code> to make downstream dependency resolution easier to intercept or subvert. Other variants plant fake <code>go</code> wrappers in workflow execution paths, manipulate proxy settings, and exfiltrate developer and CI data. In one case, a module appends a hardcoded SSH public key to <code>~/.ssh/authorized_keys</code>, establishing persistence on the affected host.</p></blockquote><p><a href="https://socket.dev/blog/malicious-ruby-gems-and-go-modules-steal-secrets-poison-ci">https://socket.dev/blog/malicious-ruby-gems-and-go-modules-steal-secrets-poison-ci</a></p><h3>Meet Bluekit: The AI-Powered All-in-One Phishing Kit</h3><p><strong>Daniel Kelley </strong>details AI integration into a phishing kit which serves as evidence that the expected trajectory is unfolding.</p><blockquote><p>[We] recently discovered Bluekit, a new phishing kit pitching a broader model. It advertises 40+ website templates, automated domain purchase and registration, 2FA support, spoofing, geolocation emulation, Telegram and browser notifications, antibot cloaking, and add-ons like an AI assistant, voice cloning, and a mail sender.</p><p>..</p><p>We were especially interested in the AI component. Inside Bluekit, the AI Assistant has its own panel and exposes multiple model options, including an abliterated Llama default alongside GPT-4.1, Claude Sonnet 4, Gemini, and DeepSeek variants.</p></blockquote><p><a href="https://www.varonis.com/blog/bluekit">https://www.varonis.com/blog/bluekit</a></p><h1>Discovery</h1><p>How we find and understand the latent compromises within our environments.</p><h2>Dissecting Impacket</h2><p><strong>Abdul Mhanni</strong> does two things with release. The first is provides a deeply valuable capability. Second is showing that there is always the opportunity to detect.. </p><blockquote><p>The goal is to help defenders understand what Impacket activity can look like at the protocol, authentication, and implementation layers beyond just at the command-line or artifact level. For red teamers, I hope that this repo servers as an inspiration for operators to undertake similar iniatives to improve the operational security of their toolkits as well as serve as a blueprint for how to approach dissecting tooling to understand normal from abnormal.</p></blockquote><p><a href="https://github.com/ThatTotallyRealMyth/Impacket-IoCs">https://github.com/ThatTotallyRealMyth/Impacket-IoCs</a></p><h2>IRQL - Incident Response Query Language</h2><p><strong>Diana Damenova</strong> provides a detection super power for those working in a Microsoft environment.</p><blockquote><p>A collection of Kusto (KQL) functions that unify security logs behind a consistent, analyst-friendly dialect. IRQL encapsulates query logic in repeatable chunks, hides cluster/database locations and join keys, and projects disparate source schemas into a single, predictable schema. In addition, it represents query logic as their semantic intent via function naming. These functions were created by Saar Ron, John Lambert, and Diana Damenova.</p></blockquote><p><a href="https://gist.github.com/ddamenova/a24f3f012012affd017d6bf712f2dd02">gist.github.com/ddamenova/a24f3f012012affd017d6bf712f2dd02</a></p><h1>Defence</h1><p>How we proactively defend our environments.</p><h2>VanGuard</h2><p><strong>Ridgeline Cyber</strong> release this integrated set of tooling which will uplift a lot of incident response teams.</p><blockquote><p>VanGuard is a self-contained incident response toolkit built in Go that gives DFIR teams a single binary for triage, threat hunting, memory forensics, disk collection, remote operations, and Velociraptor management &#8212; on both Windows and Linux, with or without network access.</p></blockquote><p><a href="https://github.com/ridgelinecyberdefence/vanguard">https://github.com/ridgelinecyberdefence/vanguard</a></p><h2>GIDR</h2><p>An unknown author releases this capability which adopts an interest philosophy. </p><blockquote><p>A behavioral intrusion detection system for Windows. Files are innocent until proven guilty at runtime. When malicious behavior is detected, the entire attack chain is traced to root and eliminated.</p></blockquote><p><a href="https://github.com/ZankDl/GIDR">https://github.com/ZankDl/GIDR</a></p><h2>Copy Fail Mitigation</h2><p><strong>Dragos Ruiu</strong> brings a scaled mitigation.. </p><blockquote><p>This document covers four things: (1) how to remove or disable <code>algif_aead</code> at fleet scale, including the gotchas in the standard blacklist / install / rmmod recipe; (2) runtime policies for Docker and Kubernetes that block the exploitation path even on unpatched kernels; (3) forensic posture &#8212; finding <code>algif_aead</code> loaded on a general-purpose host is itself a signal worth investigating; and (4) where the public PoC needs porting effort and where a host that looks immune to the published exploit is still vulnerable to the underlying bug.</p></blockquote><p><a href="https://www.secwest.net/copyfail-mitigation">https://www.secwest.net/copyfail-mitigation</a></p><h2>pydepgate</h2><p><strong>0xIkari</strong> lands a Python supply chain harness to detect and defend again potential supply chain attacks.</p><blockquote><p>A lightweight Python runner that interdicts suspicious startup behavior.</p><p>pydepgate inspects Python packages and environments for code that executes silently at interpreter startup. This was the attack class used by the March 2026 LiteLLM supply-chain compromise</p></blockquote><p><a href="https://github.com/nuclear-treestump/pydepgate">https://github.com/nuclear-treestump/pydepgate</a></p><h2>Agentic Malware Analysis: From Task Automation to Deep Analysis</h2><p><strong>Tim Blazytko</strong> brings </p><blockquote><p>In our webinar &#8220;Agentic Malware Analysis: From Task Automation to Deep Analysis&#8221;, we explore how agents can assist with malware reverse engineering across a range of increasingly demanding tasks. Rather than treating them as simple chat-based helpers, we look at how they can recover hidden data, trace unfamiliar logic, and take over repetitive analysis steps that would otherwise slow an investigation down. This leads to a more iterative style of malware analysis, where agents can help move from individual findings to a broader understanding of a sample.</p><p>The webinar is built around a sequence of progressively more challenging live examples. We start with string decryption, then move to a sample that requires understanding API-resolving logic, and finally to a multi-stage sample that decrypts additional modules and configuration data. Along the way, we show where agents already help sign</p></blockquote><p><a href="https://github.com/mrphrazer/binary-cartography/tree/main/2026-04-agentic_malware_analysis">https://github.com/mrphrazer/binary-cartography/tree/main/2026-04-agentic_malware_analysis</a></p><h2>AI-powered honeypots: Turning the tables on malicious AI agents</h2><p><strong>Martin Lee</strong> highlights an asymmetric advantage opportunity through the adoption of generative AI in cyber deception. </p><blockquote><ul><li><p>Generative AI allows defenders to instantly create diverse honeypots, like Linux shells or Internet of Things (IoT) devices, using simple text prompts. This makes deploying complex, convincing deceptive environments much easier and more scalable than traditional methods.</p></li><li><p>AI-driven attacks often prioritize speed over stealth, making them highly vulnerable to being tricked by these simulated systems. This is critical because it allows defenders to catch and study automated threats that might otherwise overwhelm human teams.</p></li><li><p>This method shifts the strategy from merely detecting attacks to actively manipulating and misleading threat actors. Organizations can safely observe attacker methodologies in real-time within a controlled &#8220;hall of mirrors.&#8221;</p></li><li><p>Ultimately, by exploiting the inherent lack of awareness in AI agents, defenders can level the playing field and turn an attacker&#8217;s automation into a liability.</p></li></ul></blockquote><p><a href="https://blog.talosintelligence.com/ai-powered-honeypots-turning-the-tables-on-malicious-ai-agents/">https://blog.talosintelligence.com/ai-powered-honeypots-turning-the-tables-on-malicious-ai-agents/</a></p><h2>Secure Boot Inventory Data In Configuration Manager</h2><p><strong>Eschloss</strong> provides a practical guide on how to get the data in configuration manager..</p><blockquote><p>In the ongoing saga of tackling the secure boot certificate updates, those of us primarily or exclusively still using Configuration Manager to manage systems, have been mostly left to fend for ourselves. Many community and Microsoft posts have been written regarding monitoring, managing and performing the updates through Intune, but not much has focused on Configuration Manager environments.</p><p style="text-align: justify;">Feeling left out, I decided to use some of the information out there for Intune and tweak it to fit my Config Mgr environment, after all, a script is a script, right?</p></blockquote><p><a href="https://adminnexus.blogspot.com/2026/04/secure-boot-inventory-data-in.html">https://adminnexus.blogspot.com/2026/04/secure-boot-inventory-data-in.html</a></p><h1>Incident Writeups &amp; Disclosures</h1><p>How they got in and what they did.</p><h2>April 27th &#8211; What happened with our feature flag configuration</h2><p><strong>Clickup</strong> discloses and owns it - the details failure in the bug bounty process is interesting.</p><blockquote><p>On April 27, 2026, a security researcher publicly disclosed that ClickUp&#8217;s client-side feature flag configuration exposed personally identifiable information. Specifically, 893 customer email addresses were embedded in feature flag targeting rules, along with one flag that improperly referenced a customer&#8217;s API token, used during an incident response to rate-limit traffic from that workspace.</p><p>We should have caught this sooner. We didn&#8217;t, and we owe you a clear explanation of what happened, why, and what we&#8217;ve done about it now and how we&#8217;re improving moving forward.</p></blockquote><p><a href="https://clickup.com/blog/april-27th-update/">https://clickup.com/blog/april-27th-update/</a></p><h2>Important Update From Trellix</h2><p><strong>Trellix</strong> discloses</p><blockquote><p>Trellix recently identified unauthorized access to a portion of our source code repository. Upon learning of this matter, we immediately began working with leading forensic experts to resolve it. We have also notified law enforcement. Based on our investigation to date, we have found no evidence that our source code release or distribution process was affected, or that our source code has been exploited. As part of our commitment to our broader security community, we intend to share further details as appropriate once our investigation is complete.</p></blockquote><h1>Vulnerability</h1><p>Our attack surface.</p><h2>38 CVEs in Healthcare Software Used by 100,000 Medical Providers</h2><p><strong>Stanislav Fort</strong> surfaces technical debt with AI..</p><blockquote><p>These vulnerabilities could have enabled a broad range of attacks against OpenEMR deployments. In the most severe cases, SQL injection vulnerabilities combined with modest database privileges could have led to full database compromise, PHI exfiltration at scale, and remote code execution on the server.</p></blockquote><p><a href="https://aisle.com/blog/aisle-discovers-38-critical-security-vulnerabilities-in-healthcare-software-used-by-100000-providers">https://aisle.com/blog/aisle-discovers-38-critical-security-vulnerabilities-in-healthcare-software-used-by-100000-providers</a></p><h2>N-Day Research with AI: Using Ollama and n8n</h2><p><strong>Nikhil John Thomas</strong> provides some practical tweaks for those focused on applying AI to n-day vulnerability research.. </p><blockquote><p>To manage this, I had to limit my prompt to around 20k tokens so that the model can use the remaining context window for reasoning, report generation, and other outputs. To achieve this, I used the <strong><a href="https://github.com/openai/tiktoken">tiktoken</a></strong> module to calculate the token length and removed some patched functions before sending the data to n8n. As a result, this approach may occasionally miss the actual vulnerable patched function.</p></blockquote><p><a href="https://ghostbyt3.github.io/blog/nday-research-ai">https://ghostbyt3.github.io/blog/nday-research-ai</a></p><h2>Dirty Frag: Universal Linux LPE</h2><p><strong>V4bel</strong> releases this universal local privilege escalation for Linux which hasn&#8217;t had the coverage of copy.fail.</p><blockquote><p>Dirty Frag is a case that extends the bug class to which <a href="https://dirtypipe.cm4all.com/">Dirty Pipe</a> and <a href="https://copy.fail/">Copy Fail</a> belong. Because it is a deterministic logic bug that does not depend on a timing window, no race condition is required, the kernel does not panic when the exploit fails, and the success rate is very high.</p></blockquote><p><a href="https://github.com/V4bel/dirtyfrag">https://github.com/V4bel/dirtyfrag</a></p><h2>Inadvertent Injections</h2><p><strong>sud0woodo </strong>details a case of accidental mass exploitation.. </p><blockquote><p>How a simple fingerprint search almost made me inadvertently inject webshells with a scan.</p></blockquote><p><a href="https://visit.suspect.network/reversing-adventures/inadvertent-injections">https://visit.suspect.network/reversing-adventures/inadvertent-injections</a></p><h1>Offense</h1><p>Attack capability, techniques and trade-craft. </p><h2>CodeNeedle</h2><p><strong>Cas van Cooten</strong> releases a capability defensive teams will want to be across if they protect any sizeable developer populations given the likelihood of adoption by malicious actors. Also the architecture and approach is worth studying. </p><blockquote><p>CodeNeedle is a VS Code extension that silently exposes Javascript code execution over a local HTTP endpoint. Once loaded into a target's VS Code instance, the extension listens on localhost for incoming JSON-RPC requests, evaluates arbitrary JavaScript code, and returns results to the caller. Code runs with full Node.js privileges in an isolated child process, granting access to the filesystem, environment variables, and any installed Node modules on the system. The target remains unaware of the extension's presence, as it runs entirely in the background with no UI, commands, or console output</p></blockquote><p><a href="https://github.com/chvancooten/code-needle">https://github.com/chvancooten/code-needle</a></p><h2>Month of Bypasses</h2><p><strong>Persistent Security</strong> do some content led marketing for their platform but show the potential for AI to highlight and subvert detection fragility at scale.</p><blockquote><p>Each bypass is a variation of a technique that Microsoft Defender already catches, covering the same MITRE ATT&amp;CK technique ID and attack objective but via a different execution path. The goal is to help defenders understand where their protections apply and where the gaps are &#8212; before adversaries exploit them.</p><p>POCs are discovered using AI-driven variant analysis</p></blockquote><p><a href="https://github.com/persistent-security/month-of-bypasses">https://github.com/persistent-security/month-of-bypasses</a></p><h2>Puzzle</h2><p><strong>Kurosh Dabbagh Escalante</strong> releases a capability detection engineers will want to ensure they have robust coverage of given the concealment opportunity.</p><blockquote><p>Puzzle is a set of PoCs and utilities that make it possible to abuse functionality provided by several Windows minifilters when executing malware in monitored environments. The main concept of this repository is to demonstrate how, by abusing the Windows minifilter architecture and the different load altitudes of these devices, we can achieve a certain level of stealth and concealment as attackers when dropping and executing malware during a Red Team exercise.</p></blockquote><p><a href="https://github.com/Kudaes/Puzzle">https://github.com/Kudaes/Puzzle</a></p><h2>DoomSyscalls</h2><p><strong>si13nt</strong> lands this detection which highlights continued fragility of certain techniques.</p><blockquote><p>DoomSyscalls is a new method of performing clean indirect syscalls. The primary component is dynamically resolving <strong>System Service Numbers</strong> (SSNs), and <code>syscall</code> instruction addresses. The secondary component is <strong>RIP</strong> spoofing via addresses within <code>ntdll.dll</code>. The combination of both should bypass any userland hooks &amp; kernel level checks.</p><p><strong>Disclaimer</strong>: The purpose of this is for educational purposes and testing only. Do not use this on machines you do not have permission to use. Do not use this to leverage and communicate with machines that you do not have authorization to use.</p></blockquote><p><a href="https://github.com/SilentisVox/DoomSyscalls">https://github.com/SilentisVox/DoomSyscalls</a></p><h2>SunnyDayBPF</h2><p><strong>Azizcan Dastan</strong> shows the challenge userland reliant techniques..</p><blockquote><p>SunnyDayBPF is an eBPF-based post-syscall user-buffer telemetry deception research technique originally proposed and researched by Azizcan Da&#351;tan.</p><p>The technique investigates whether data observed by user-space security, logging, or telemetry agents can be altered after a read-like syscall has completed, but before the agent parses, analyzes, or forwards that data to a downstream security pipeline.</p></blockquote><p><a href="https://github.com/azqzazq1/SunnyDayBPF">https://github.com/azqzazq1/SunnyDayBPF</a></p><h1>Exploitation</h1><p>What is being exploited..</p><h2>The cPanel Zero-Day Was Active for 64 Days Before Anyone Knew</h2><p><strong>&#321;ukasz Nowak</strong> reports..  this shows why information sharing and quickly is critical. </p><blockquote><p>When hosting providers took cPanel offline on April 28, the working assumption was that the vulnerability had been discovered shortly before the advisory. That assumption was wrong. <strong>KnownHost CEO Daniel Pearson has confirmed that his company observed exploitation attempts as early as February 23, 2026</strong>, roughly 64 days before any public advisory, patch, or CVE existed. Servers were being compromised while their operators had no reason to look.</p></blockquote><p><a href="https://webhosting.today/2026/05/03/the-cpanel-zero-day-was-active-for-64-days-before-anyone-knew/">https://webhosting.today/2026/05/03/the-cpanel-zero-day-was-active-for-64-days-before-anyone-knew/</a></p><h2>copy.golf</h2><p>Fun competition around exploit minimisation.. </p><blockquote><p>shortest payload for copy.fail wins.</p></blockquote><p><a href="https://copy.golf/">https://copy.golf/</a></p><h1>Tooling and Techniques</h1><p>Low level tooling and techniques for attack and defence researchers</p><h2>MicroSMT</h2><p><strong>eversinc33</strong> makes SMT solvers accessible to mortals in an applied sense.</p><blockquote><p>MicroSMT is an IDA Pro Plugin that aims at generic solving of opaque predicates.</p><p>It works by backwards slicing from <code>jcc</code>/<code>setcc</code> instructions and lifting relevant Hex-Ray microcode slices to z3 expressions. These expressions can then be solved via SMT and the instructions can be patched accordingly.</p><p>MicroSMT is currently in <em>pre-alpha</em> state - working with microcode has some pitfalls and I do not expect it to work everywhere. Also, not all instruction are currently implemented in the lifter.</p><p>Nevertheless, MicroSMT can already autonomously solve opaque predicates in several families (see Examples below).</p><p>There are some limitations regarding opaque predicates that can be solved - notable exceptions:</p><ul><li><p>Predicates that rely on memory access</p></li><li><p>Predicates that rely on external API calls and their results</p></li><li><p>Predicates that go over several basic blocks</p></li></ul></blockquote><p><a href="https://github.com/eversinc33/MicroSMT">https://github.com/eversinc33/MicroSMT</a></p><h2>The Holy Grail PCAP</h2><p><strong>Sharon Brizinov</strong> releases the holy grail of corpuses which will be a super power to traditional fuzzing and AI in terms of PCAP parser vulnerability and subversion discovery.</p><blockquote><p>This project is the result of months of work to create the "Holy Grail" PCAP - a massive pcap file containing packets that trigger the code-flows of virtually all 1,600+ Wireshark dissectors across all encapsulation types. When parsed by Wireshark tshark, this pcap exercises the code of almost every protocol dissector in the project.</p></blockquote><p><a href="https://github.com/SharonBrizinov/Holy-Grail-PCAP">https://github.com/SharonBrizinov/Holy-Grail-PCAP</a></p><h2>Recursively fuzzing MS-RPC structures and monitoring using ETW</h2><p><strong>Remco van der Meer</strong> walks through how their fuzzing framework has been extended with an a-typical feedback loop on Windows.</p><blockquote><p>It&#8217;s been a while since I worked on some updates regarding the <a href="https://github.com/warpnet/MS-RPC-Fuzzer">MS-RPC-Fuzzer</a>. I had two idea&#8217;s that I wanted to implement and improve:</p><ol><li><p>Recursively Fuzzing complex structures</p></li><li><p>Support for Union types (all fields named Arm_N)</p></li><li><p>Logging without the need for ProcMon (Process Monitor) through ETW.</p></li></ol><p>This blog post writes about the implementation for both features and some interesting results that came from these new updates! We discovered a procedure that would load an dll on disk as system by the user provided input.</p></blockquote><p><a href="https://www.incendium.rocks/posts/Fuzzing-MS-RPC-structures-and-monitoring/">https://www.incendium.rocks/posts/Fuzzing-MS-RPC-structures-and-monitoring/</a></p><h2>HvArm: Chapter 2: Taking Ownership of the EL2 Page Tables</h2><p><strong>0xabe-io</strong> continues teaching how hypervisors work on ARM..</p><blockquote><p>This chapter walks through that migration. It starts with a small but necessary fix in the entry point &#8212; manually initializing <code>gBS</code> so that we can actually call boot services &#8212; then covers the full sequence: reading the current MMU configuration, walking the live page tables to size the new allocation, copying the hierarchy with table descriptors retargeted to point at the new memory, sanity-checking the result against the hardware translation, and finally switching <code>TTBR0_EL2</code> to the new root with the right barriers and TLB invalidation.</p></blockquote><p><a href="https://0xabe.io/hypervisor/arm/2026/04/30/HvArm-Chapter-2.html">https://0xabe.io/hypervisor/arm/2026/04/30/HvArm-Chapter-2.html</a></p><h1>Footnotes</h1><p>Some other small (and not so small) bits and bobs which might be of interest.</p><ul><li><p>Annual, quarterly and monthly reports</p><ul><li><p><em>Nothing overly of note this week, but keep an eye on</em> <a href="https://github.com/jacobdjwilson/awesome-annual-security-reports/tree/main/Annual%20Security%20Reports/2026">the Awesome Annual Security Reports 2026 collection</a></p></li></ul></li><li><p><a href="https://www.iarpa.gov/newsroom/article/iarpa-releases-five-new-innovation-programs-to-enhance-national-security-capabilities">IARPA Releases Five New Innovation Programs to Enhance National Security Capabilities</a></p></li><li><p><a href="https://www.cia.gov/resources/csi/static/Article-Espionage-in-Our-AI-Future-Studies-70-1-Mar2026.pdf">Espionage in Our AI Future Why Human Intelligence Still Matters</a></p></li><li><p><a href="https://www.ornl.gov/news/ornls-breakthrough-detector-protects-trucking-shipments-gps-deception">ORNL&#8217;s breakthrough detector protects trucking shipments from GPS deception</a></p></li><li><p><a href="https://dl.acm.org/doi/epdf/10.1145/3729706.3729711">Performance Analysis of Leading Homomorphic Encryption Libraries: A Benchmark Study of SEAL, HElib, OpenFHE, and Lattigo</a></p></li><li><p><a href="https://yubiclicker.com/">YubiClicker</a> - YubiClicker is Cookie Clicker, except every click is a FIDO2 assertion from a physical key tap. Climb a public leaderboard by out-tapping your opponents.</p></li><li><p><a href="https://arxiv.org/abs/2603.28728">Study of Post Quantum status of Widely Used Protocols</a></p></li><li><p><a href="https://github.com/IETF-Hackathon/pqc-certificates">IETF Hackathon - PQC Certificates</a></p></li><li><p>Artificial intelligence</p><ul><li><p>Fundamental</p><ul><li><p><a href="https://aisoft-course.github.io/">Software Foundations of Artificial Intelligence (Fudan University, Spring Semester 2026)</a></p></li><li><p><a href="https://arxiv.org/abs/2605.01172">A Theory of Generalization in Deep Learning</a></p></li><li><p><a href="https://github.com/Luthiraa/TALOS-V2">Hardware implementation of transformers running microgpt at 50k+ tkps</a></p></li><li><p><a href="https://arxiv.org/abs/2604.21100">Preconditioned DeltaNet: Curvature-aware Sequence Modeling for Linear Recurrences</a></p></li></ul></li><li><p>Applied non-cyber</p><ul><li><p><a href="https://arxiv.org/abs/2604.10708">Audio-Omni: Extending Multi-modal Understanding to Versatile Audio Generation and Editing</a></p><ul><li><p><a href="https://zeyuet.github.io/Audio-Omni/">Audio-Omni: Extending Multi-modal Understanding to Versatile Audio Generation and Editing</a></p></li></ul></li><li><p><a href="https://arxiv.org/abs/2604.07725">Squeeze Evolve: Unified Multi-Model Orchestration for Verifier-Free Evolution</a></p></li><li><p><a href="https://llm-as-a-verifier.notion.site/">LLM-as-a-Verifier: A General-Purpose Verification Framework</a></p><ul><li><p><a href="https://github.com/llm-as-a-verifier/llm-as-a-verifier">LLM-as-a-Verifier: A General-Purpose Verification Framework</a></p></li></ul></li><li><p><a href="https://arxiv.org/abs/2604.25917">Recursive Multi-Agent Systems</a></p></li><li><p><a href="https://arxiv.org/abs/2604.20779">SWE-chat: Coding Agent Interactions From Real Users in the Wild</a></p></li></ul></li><li><p>Applied cyber specific</p><ul><li><p><a href="https://mp.weixin.qq.com/s/eMCDye1A-LfO6gMsTTvNSQ">I used DeepSeek to reproduce the entire process of AI detecting Copy Fail privilege escalation</a> - with some big caveats</p></li></ul></li></ul></li><li><p>Books</p><ul><li><p><em>Nothing overly of note this week&#8230;</em></p></li></ul></li><li><p>Events</p><ul><li><p>I will be at OffensiveCON in Berlin this week..</p></li></ul></li></ul><p>Finally finally the <a href="https://creators.spotify.com/pod/profile/national-cyber-security-c6/episodes/The-Ransomware-Ecosystem-e2hi088">NCSC&#8217;s podcast series</a>.</p><div><hr></div><p><em>Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them. </em></p><p><em>This newsletter is subject to the NCSC website terms and conditions which can be found at <a href="https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions">https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions</a> and you can find out more about how will treat your personal information in our privacy notice at <a href="https://www.ncsc.gov.uk/section/about-this-website/privacy-statement">https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.</a></em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CTO at NCSC - Cyber Defence Analysis! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CTO at NCSC Summary: week ending May 3rd]]></title><description><![CDATA[Organisations must act now to prepare for a wave of patches that will address decades of technical debt.]]></description><link>https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-a16</link><guid isPermaLink="false">https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-a16</guid><dc:creator><![CDATA[Ollie Whitehouse]]></dc:creator><pubDate>Sat, 02 May 2026 08:18:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!N0gQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82dffd51-7c80-466c-aa55-d78a1e526080_2080x1264.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to the weekly highlights and analysis of the&nbsp;<a href="https://infosec.pub/c/blueteamsec?dataType=Post&amp;sort=New">blueteamsec</a>&nbsp;(and my wider reading). Not everything makes it in, but the best bits do. A community member is doing <a href="https://briefing.workshop1.net/">daily AI generated podcast of the last 24hours of posts</a>.</p><p>Operationally this week there has been some focus on the <a href="https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026">cPanel &amp; WHM authentication bypass</a> given its widespread use. There has been <a href="https://censys.com/blog/the-cpanel-situation-is/">analysis as to the scale of exposure</a> as well as <a href="https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/">how to exploit the vulnerability</a> which is now being exploited by a variety of actors.</p><p>In the high-level this week:</p><ul><li><p><a href="https://www.ncsc.gov.uk/blogs/prepare-for-vulnerability-patch-wave">Preparing for a &#8216;vulnerability patch wave&#8217;</a> - <strong>NCSC</strong> UK issue notice - <em>&#8220;Organisations must act now to prepare for a wave of patches that will address decades of technical debt.&#8221;</em></p><ul><li><p><a href="https://www.ncsc.gov.uk/collection/vulnerability-management">Vulnerability management</a> - NCSC UK updates guidance</p></li><li><p><a href="https://therecord.media/british-cyber-ai-patch-wave">British cyber agency warns of looming &#8216;patch wave&#8217; as AI speeds flaw discovery</a> - The Record reports </p></li></ul></li><li><p><a href="https://www.ncsc.gov.uk/blogs/could-your-choice-of-metrics-be-harming-your-soc">Could your choice of metrics be harming your SOC? </a>- <strong>NCSC</strong> UK outlines - <em>&#8220;Unfortunately, many of the most common SOC metrics provide no insight to seniors about the effectiveness of the SOC. In fact, inappropriate metrics can even distract and in the worst case harm a SOC's ability to detect and respond to attacks. The NCSC have seen SOCs with great potential rendered entirely ineffective through poor choice and application of metrics.&#8221;</em></p></li><li><p><a href="https://uktl.org.uk/news-events/uktl-ncsc-and-ericsson-strengthen-the-security-of-uk-mobile-networks/">UKTL, NCSC And Ericsson Strengthen The Security Of UK Mobile Networks</a> - <strong>UKTL</strong> announce - <em>&#8220;The UK Telecoms Lab (UKTL), Ericsson and the UK&#8217;s National Cyber Security Centre (NCSC) have identified and resolved a vulnerability in Ericsson&#8217;s Packet Core Controller (PCC). This builds on UKTL&#8217;s ongoing work to strengthen the security and resilience of the UK&#8217;s connectivity infrastructure.&#8221;</em></p></li><li><p><a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026">[UK] Cyber security breaches survey 2025/2026</a> - <strong>Department for Science, Innovation and Technology</strong> publishes - <em>&#8220;The survey only includes the breaches or attacks that organisations were able to identify and willing to report. There are likely to be hidden attacks, and other breaches that go unidentified, so the findings reported here may underestimate the full extent of the prevalence of cyber breaches and attacks.&#8221;</em></p></li><li><p><a href="https://www.fca.org.uk/publications/good-and-poor-practice/cyber-coordination-group-insights-2025">Cyber Coordination Group insights 2025</a> - <strong>Financial Conduct Authority</strong> publish - <em>&#8220;CCG members shared cyber resilience insights on 3 topics:</em></p><ul><li><p><em>Incident response practices and recovery at scale.</em></p></li><li><p><em>Implications for cyber security of AI, quantum computing, and other emerging technology.</em></p></li><li><p><em>Insider risk management.&#8221;</em></p></li></ul></li><li><p><a href="https://www.ic3.gov/PSA/2026/PSA260430">Cyber-Enabled Strategic Cargo Theft Surging</a><strong><a href="https://www.ic3.gov/PSA/2026/PSA260430"> </a>- FBI</strong> warns -<em>&#8220;cyber threat actors increasingly using sophisticated, cyber-enabled tactics to imp ersonate legitimate businesses to hijack freight, steal high-value shipments, and reroute deliveries, resulting in a surge of strategic cargo theft.&#8221;</em></p></li><li><p><a href="https://ccdcoe.org/news/2026/locked-shields-2026-united-the-power-of-41-nations-to-defend-cyberspace/">Locked Shields 2026 united the power of 41 nations to defend cyberspace</a> - <strong>NATO Cooperative Cyber Defence Centre of Excellence</strong> summarises - <em>&#8220;Our ultimate goal at Locked Shields is to enhance collaboration between nations, and build trust and a shared understanding of how to strengthen resilience in cyberspace,&#8221; said Dan Ungureanu, Exercise Director of Locked Shields 2026. &#8220;I thank all participants, organisers, and partners &#8211; nearly 5,000 people worldwide &#8211; for contributing to this shared goal.&#8221;</em></p></li><li><p><a href="https://blogs.icrc.org/law-and-policy/2026/04/23/upholding-ihl-protections-against-the-risks-of-ict-activities-in-armed-conflict/">Upholding IHL protections against the risks of ICT activities in armed conflict</a> - <strong>International Committee of the Red Cross</strong> outlines - <em>&#8220;Across the world, essential civilian services increasingly depend on information and communication technologies (ICTs). These same technologies are also reshaping the conduct of armed conflict. As warfare becomes more digitalized, a critical question emerges: how can civilians be protected in an interconnected battlespace? Ensuring the faithful implementation of international humanitarian law in relation to ICT activities is central to this challenge.&#8221;</em></p></li><li><p><a href="https://www.jstor.org/stable/48873435?seq=1">Warfare in the Technology Arena: Cost-Imposition and Maneuver in the Electromagnetic Battlespace</a> -  <strong>Lt. Col. Sean &#8220;Nick&#8221; Blas</strong> outlines - <em>&#8220;The EMS is a highly contested environment where both friendly and adversary forces seek to enable the full capabilities of their weapon systems and endeavor to gain an</em></p><p><em>advantage while also trying to disrupt the opposition&#8217;s access to the spectrum.2 Access to the EMS is not guaranteed, necessitating a shift in operational planning that emphasizes its placement as a critical aspect of joint all-domain maneuver. The remainder of this article will explore the concept of EMS maneuver, connect</em></p><p><em>that concept with cost-imposition strategy, and then provide potential cost-efficient options to compete on the EMS battlefield.&#8221;</em></p></li><li><p><a href="https://www.wired.com/story/when-robots-have-their-chatgpt-moment-remember-these-pincers/">I&#8217;ve Covered Robots for Years. This One Is Different</a> - <strong>WIRED</strong> reports - <em>&#8220;Eka&#8217;s demos suggest that the company may be onto something big. I found myself mentally comparing their robots to GPT-1, OpenAI&#8217;s first large language model, developed four years before ChatGPT. GPT-1 was often incoherent but showed glimmers of general linguistic intelligence.&#8221;</em></p></li><li><p>Reporting on/from China</p><ul><li><p><a href="https://www.bloomberg.com/news/articles/2026-04-29/chinese-hackers-spied-on-cuban-embassy-as-us-prepared-blockade">Chinese Hackers Spied On Cuban Embassy As US Prepared Blockade</a> - <strong>Bloomberg</strong> reports - <em>&#8220;Chinese hackers breached Cuba&#8217;s embassy in Washington to spy on communications of dozens of diplomats, compromising the emails of 68 officials. The hackers exploited two five-year-old vulnerabilities in outdated Microsoft Exchange email servers to bypass embassy security and download entire inboxes belonging to political and intelligence officials.&#8221;</em></p></li><li><p><a href="https://citizenlab.ca/research/how-chinese-actors-use-impersonation-and-stolen-narratives-to-perpetuate-digital-transnational-repression/">Tall Tales How Chinese Actors Use Impersonation and Stolen Narratives to Perpetuate Digital Transnational Repression</a> - <strong>Citizen Lab</strong> alleged - <em>&#8220;In collaboration with the International Consortium of Investigative Journalists (ICIJ), we identified two distinct actors aligned with the People&#8217;s Republic of China that have been targeting and impersonating journalists and civil society. Our findings provide insight into the Chinese government&#8217;s practice of digital transnational repression and its shift to a system of state-sponsored attacks carried out by private contractors.&#8221;</em></p></li><li><p><a href="https://www.uscc.gov/hearings/taking-bigger-byte-chinas-expanding-strategy-data-dominance">Taking a Bigger Byte: China&#8217;s Expanding Strategy for Data Dominance</a> - <strong>U.S.-China Economic and Security Review Commission</strong> hear</p></li><li><p><a href="https://theobjective.com/economia/telecomunicaciones/2026-04-15/cni-productos-huawei-sectores-criticos-sanchez-china/">The CNI certifies 19 Huawei products for use in critical sectors such as defense</a> - <strong>The Objective</strong> reports - <em>&#8220;The National Intelligence Center ( <a href="https://theobjective.com/etiqueta/cni/">CNI</a> ), through the National Cryptologic Center (CCN), has just released its list of software and device security certifications for April. The document, which THE OBJECTIVE has obtained, certifies more than 70 <a href="https://theobjective.com/etiqueta/huawei/">Huawei</a> products as safe for use in Spain. In total, 19 of them have received the highest level of certification, meaning they can be used in critical infrastructure or sectors (healthcare, defense, banking, energy, etc.).&#8221;</em> in Spain.. </p></li><li><p><a href="https://www.scmp.com/news/china/science/article/3351037/chinas-dark-compute-power-could-be-6000-times-higher-current-estimates">China&#8217;s dark compute power could be 6,000 times higher than current estimates</a> - <strong>South China Morning Post</strong> reports - <em>&#8220;Domestic AI amounts to 1,882,000,000,000,000,000 calculations per second, vastly more than Western rankings suggest&#8221;</em></p></li><li><p><a href="https://www.globaltimes.cn/page/202604/1359654.shtml">BCI industry gains pace, with health authorities setting price guidelines</a> - <strong>Global Times</strong> reports - <em>&#8220;China's brain-computer interface (BCI) industry has made fresh headway, with many provinces having set government-guided prices for BCI-related procedures, with the prices for invasive BCI implantation ranging from 6,000 yuan ($879.15) to 6,600 yuan per procedure. A number of BCI companies also posted fresh progress in recent days.&#8221;</em></p><ul><li><p><a href="http://www.chinaview.cn/20260424/cb094f333882471984a488a962fc92b4/c.html">Nanchang hospital successfully performs clinical operation of &#8220;Triple-F&#8221; BCI system</a></p></li></ul></li><li><p><a href="https://www.reuters.com/business/retail-consumer/volkswagen-group-announces-ai-roadmap-china-equip-vehicles-with-agentic-ai-2026-04-21/">Volkswagen to equip Chinese cars with AI agents, in bid to catch up in tech</a> - <strong>Reuters</strong> reports - <em>&#8220;The technology would allow &#8220;highly intuitive, human-like interaction&#8221; between &#8203;the vehicle and the driver while ensuring &#8220;robust personal data protection&#8221;. .. &#8220;Unlike a voice assistant that answers simple questions, AI agents can handle more complex tasks and decision-making, the company said.&#8221;</em></p></li></ul></li><li><p> AI</p><ul><li><p><a href="https://www.ncsc.gov.uk/paper/understanding-adversarial-attacks-against-machine-learning-and-ai">Understanding adversarial attacks against Machine Learning and AI</a> - <strong>NCSC</strong> UK publishes - <em>&#8220;Designers, deployers, managers and operators of ML models need to understand ML-specific vulnerabilities and implement robust security measures to safeguard system integrity, confidentiality and performance, and allow the benefits of AI to be realised.&#8221;</em></p></li><li><p><a href="https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/careful-adoption-of-agentic-ai-services">Careful adoption of agentic AI services</a> - <strong>Australian Signals Directorate&#8217;s Australian Cyber Security Centre</strong> (ASD&#8217;s ACSC), the United States <strong>Cybersecurity and Infrastructure Security Agency</strong> (CISA) and <strong>National Security Agency</strong> (NSA), the <strong>Canadian Centre for Cyber Security</strong> (Cyber Centre), the <strong>New Zealand National Cyber Security Centre</strong> (NCSC-NZ) and the <strong>United Kingdom National Cyber Security Centre</strong> (NCSC-UK) publish - <em>&#8220;The authoring agencies strongly recommend aligning agentic AI risks and mitigation strategies with your organisation&#8217;s existing security model and risk posture. The authoring agencies further recommend adopting agentic AI with security in mind, assessing its use and never granting it broad or unrestricted access, especially to sensitive data or critical systems. Additionally, organisations should only use agentic AI for low-risk and non-sensitive tasks.&#8221;</em></p></li><li><p><a href="https://www.aisi.gov.uk/blog/our-evaluation-of-openais-gpt-5-5-cyber-capabilities">Our evaluation of OpenAI&#8217;s GPT-5.5 cyber capabilities </a>- UK <strong>AI Security Institute</strong> publish - <em>"The Last Ones" (TLO) is a 32-step corporate network attack simulation, built with SpecterOps. It is modelled on the kill chain of an enterprise intrusion and spans four subnets and roughly twenty hosts. The agent starts on an unprivileged attack box with no credentials and must chain together reconnaissance, credential theft, lateral movement across multiple Active Directory forests, a CI/CD supply-chain pivot, and finally exfiltration of a protected internal database. We estimate a human expert would need around 20 hours to complete the full chain. GPT-5.5 completed TLO end-to-end in 2 of 10 attempts, making it the second model to do so<sup>1</sup>. Mythos Preview, the first model to solve TLO, did so in 3 of 10 attempts.</em> - <strong>note:</strong> this assumes it is on the internal network etc.</p></li><li><p><a href="https://arxiv.org/abs/2604.05662">Understanding: reframing automation and assurance</a> - <strong>Robin Bloomfield</strong> publishes - <em>&#8220;Safety and assurance cases risk becoming detached from the understanding needed for responsible engineering and governance decisions. More broadly, the production and evaluation of critical socio-technical systems increasingly face an understanding challenge: pressures for increased tempo, reduced scrutiny, software complexity, and growing use of AI generated artefacts may produce outputs that appear coherent without supporting genuine human comprehension. We argue that understanding should become an explicit, assessable, and defensible component of decision making: what developers, assessors, and decision makers grasp about system behavior, evidence, assumptions, risks, and residual uncertainty.&#8221;</em></p></li><li><p><a href="https://xark.es/b/mythos-firefox-150">A quick look at Mythos run on Firefox: too much hype?</a> - <strong>Antide Petit</strong> audits - <em>&#8220;The Firefox 150 data suggests a tool that is genuinely useful for defensive security work, especially at scale, but the public record does not justify the strongest claims people want to make from it. The headline number is impressive, yet it bundles together bugs of very different significance and does not publicly resolve into a clean accounting.&#8221;</em></p></li><li><p><a href="https://seclists.org/oss-sec/2026/q2/250">Coordinated Disclosure in the LLM Age</a> - <strong>Jeremy Stanley</strong> outlines the machine speed and scale world challenge for vulnerability disclosure - <em>&#8220;I'm sorely tempted, both due to the increased volume and the risk of premature disclosure, to just assume that any vulnerability reported as a result of research using an LLM is trivially discoverable by others, and give up trying to pretend there's any point to working it under embargo.&#8221;</em> - a discussion ensued.. </p></li><li><p><a href="https://cheri-alliance.org/cheri-memory-safety-mitigates-llm-discovered-vulnerability-in-freebsd/">CHERI memory safety mitigates LLM-discovered vulnerability in FreeBSD</a> &#8211; <strong>CHERI Alliance</strong> proudly outline - <em>&#8220;CHERI&#8217;s bounds fault converts a remote code execution (RCE) vulnerability into a denial of service vulnerability, downgrading the impact from Critical to High. An unexpected reboot is strongly preferable to total attacker control of a system. It is further reasonable to speculate that appropriate compartmentalization or failure-oblivious computing strategies might allow the RPCSEC_GSS to fail rather than forcing the kernel to exit as it does today. This is an area of active research for the CHERI team.&#8221;</em></p></li><li><p><a href="https://www.globenewswire.com/news-release/2026/04/28/3282688/0/en/global-ai-security-standard-organizations-gather-under-mosaic-to-reduce-fragmentation.html">Global AI Security Standard Organizations Gather Under MOSAIC to Reduce Fragmentation</a> - <strong>SANS</strong> announce - <em>&#8220;Representatives from leading AI security standardization initiatives have formed MOSAIC (Multi-Organization Secure AI Coordination), the first collective collaboration of its kind among AI security standard organizations&#8221;</em> .. <em>&#8220;At an invitation-only forum in Arlington, OWASP, SANS Institute, NIST, CSA, CIS, CoSAI, and BIML formed MOSAIC: Multi-Organization Secure AI Coordination, a collective collaboration to coordinate the AI security guidance the world&#8217;s defenders actually use.&#8221;</em></p></li><li><p><a href="https://warontherocks.com/im-sorry-dave-im-afraid-i-cant-de-escalate-on-ai-wargaming-and-nuclear-war/">I&#8217;m Sorry, Dave. I&#8217;m Afraid I Can&#8217;t De-escalate: On (AI) Wargaming and Nuclear War</a> - <strong>War on the Rocks</strong> has some fun - <em>&#8220;Recent experiments placing large language models in simulated nuclear crises have produced alarming headlines. &#8220;<a href="https://nypost.com/2026/02/25/tech/ai-systems-more-ready-to-drop-nukes-in-escalating-geopolitical-crises-war-games-study/">Bloodthirsty</a>&#8221; AI systems escalate conflicts, <a href="https://www.newscientist.com/article/2516885-ais-cant-stop-recommending-nuclear-strikes-in-war-game-simulations/">threaten nuclear strikes</a>, and behave <a href="https://www.axios.com/2026/02/26/ai-nuclear-weapons-war-pentagon-scenarios">erratically</a> under simulated pressure. A recent set of experiments presented in a <a href="https://arxiv.org/pdf/2602.14740">pre-print</a> paper from Kenneth Payne at King&#8217;s College London finds that across 95 percent of simulated games across 21 match-ups between three frontier models, at least one side engaged in nuclear signaling &#8212; with subsequent tactical nuclear use occurring in 95 percent of games and strategic nuclear threats in 76 percent.&#8221;</em></p><ul><li><p><a href="https://arxiv.org/abs/2602.14740">AI Arms and Influence: Frontier Models Exhibit Sophisticated Reasoning in Simulated Nuclear Crises</a></p></li></ul></li><li><p><a href="https://www.scientificamerican.com/article/amateur-armed-with-chatgpt-vibe-maths-a-60-year-old-problem/">An amateur just solved a 60-year-old math problem&#8212;by asking AI </a>- <strong>Scientific America</strong> reports - <em>&#8220;The raw output of ChatGPT&#8217;s proof was actually quite poor. So it required an expert to kind of sift through and actually understand what it was trying to say,&#8221; Lichtman says. But now he and Tao have shortened the proof so that it better distills the LLM&#8217;s key insight.</em></p></li></ul></li><li><p><em>Cyber proliferation</em></p><ul><li><p><a href="https://www.tovima.com/politics/top-greek-prosecutor-ends-predator-spyware-probe-rejecting-new-inquiryq/">Top Greek Prosecutor Ends Predator Spyware Probe, Rejecting New Inquiry</a> - <strong>Tovima</strong> reports - <em>&#8220;Greece&#8217;s attorney general has formally closed the door on any further criminal investigation into the country&#8217;s <a href="https://www.tovima.com/politics/wiretapping-intellexa-of-dillian-based-in-athens-advertised-spyware-to-law-enforcement-authorities/">Predator spyware scandal</a>, ruling that evidence presented during a months-long trial falls short of the legal threshold required to reopen the archived case. The decision was met with immediate and widespread condemnation.&#8221;</em></p></li><li><p><a href="https://www.wired.it/article/paragon-spyware-risposte-indagine-italia-procura/">Paragon has yet to provide answers to the Italian justice system regarding the use of its spyware, a year after the scandal involving the spying of journalists and activists </a>- <strong>WIRED</strong> Italy reports - &#8220;<em>Graphite spyware was detected on the smartphones of Italian victims. Prosecutors are still awaiting feedback from the Israeli company. The Ministry of Defense in Tel Aviv conducted five inspections to verify compliance with export licenses, but without consequences. Wired Italia 's investigation&#8221;</em></p></li><li><p><a href="https://www.in.gr/2026/04/24/english-edition/wiretapping-intellexa-of-dillian-based-in-athens-advertised-spyware-to-law-enforcement-authorities/">Wiretapping: Intellexa of Dillian, based in Athens, advertised spyware to &#8220;Law Enforcement Authorities&#8221;</a> - <strong>In.gr</strong> report - <em>&#8220;The first brochure states that Intellexa&#8217;s main facilities are located in Athens and Paris. It is recalled that in the French capital the company Nexa operated, which has been accused of selling surveillance systems to authoritarian regimes and has been described, according to Reporters United investigations, as an &#8220;irreplaceable partner&#8221; of Tal Dillian.&#8221;</em></p></li><li><p><a href="https://www.antenna.gr/ereynes/article/4/995197/pos-to-predator-apektise-psifiaka-opla-poy-proorizontan-gia-dytikes-mystikes-ypiresies">How Predator acquired digital &#8220;weapons&#8221; intended for Western intelligence agencies</a> - <strong>Antenna</strong> report - <em>&#8220;that the &#8220;vulnerabilities&#8221; purchased by the former partner did not come from some hackers or individual programmers, but from an American company, which until then had collaborated exclusively with Western government agencies.&#8221;</em></p></li></ul></li><li><p>Bounty Hunting</p><ul><li><p><a href="https://www.justice.gov/opa/pr/prolific-chinese-state-sponsored-contract-hacker-extradited-italy">Prolific Chinese State-Sponsored Contract Hacker Extradited from Italy</a> - <strong>US Department of Justice</strong> announces - &#8220;<em>Xu Zewei (&#24464;&#27901;&#20255;), 34, of the People&#8217;s Republic of China was extradited to the United States this weekend and appeared today in U.S. District Court in Houston on a <a href="https://www.justice.gov/opa/media/1407196/dl">nine-count indictment</a> related to his involvement in computer intrusions between February 2020 and June 2021. Certain of those computer intrusions allegedly are part of the HAFNIUM computer intrusion campaign that compromised thousands of computers worldwide, including in the United States. Other intrusions targeted U.S. COVID-19 research during the height of the pandemic. Xu is charged along with Zhang Yu (&#24352;&#23431;), 44, who is also a PRC national.&#8221;</em> - don&#8217;t go on holiday to an extradition country.. </p></li><li><p><a href="https://www.chicagotribune.com/2026/04/27/teen-charged-in-chicago-was-part-of-international-scattered-spider-hacker-group-feds-say/">Teen charged in Chicago was part of international &#8216;Scattered Spider&#8217; hacker group, feds say</a> - <strong>Chicago Tribune</strong> reports - <em>&#8220;Federal charges filed under seal in Chicago allege Stokes is a prolific member of a loosely connected, international group of sophisticated hackers known as Scattered Spider, and that he helped infiltrate the sensitive computer systems of large corporations in the Chicago area and elsewhere and collect millions of dollars in ransom.&#8221;</em></p></li><li><p><a href="https://nationalpost.com/news/canada/toronto-police-seize-sms-blasters-cybercrime-canada">Toronto police seize &#8216;SMS blasters,&#8217; a cybercrime weapon never before seen in Canada</a> - <strong>National Post</strong> report - <em>&#8220;Police believe tens of thousands of devices were connected to the blaster over several months, and identified more than 13 million network disruptions&#8221; .. &#8220;Dafeng Lin, 27, of Hamilton, Junmin Shi, 25, of Markham, and Weitong Hu, 21, of Markham &#8212; have been arrested and charged with multiple offences, including mischief endangering life, personation with intent to gain advantage, fraud under $5,000, use of a computer system with intent to commit an offence, fraudulently intercepting a function of a computer system, and unauthorized possession of credit card data.&#8221;</em></p></li></ul></li><li><p>Market Incentives</p><ul><li><p><a href="https://www.fcc.gov/faqs-recent-updates-fcc-covered-list-regarding-routers-produced-foreign-countries">FAQs on Recent Updates to FCC Covered List Regarding Routers Produced in Foreign Countries </a>- U.S. <strong>Federal Communications Commission</strong> updates</p></li><li><p><a href="https://www.pv-tech.org/eu-cybersecurity-solar-energy-harsh-regulations/">EU is open to &#8216;harsh&#8217; enforcement of cybersecurity for solar energy</a> - <strong>PV Tech</strong> reports - <em>&#8220;The European Commission (EC) is reportedly &#8220;very resolved to take harsh steps&#8221; in its enforcement of cybersecurity laws in the solar energy sector.</em></p><p><em>Speaking at the SolarPLUS Europe conference in Milan last week, Uri Sadot, managing director of solar cybersecurity firm SolarDefend, said that the EC has expressed a &#8220;surprisingly strong drive to protect European industry and ensure risk levels are reduced for the grid.&#8221;</em></p></li><li><p><a href="https://www.insurancebusinessmag.com/us/news/cyber/one-ransomware-crew-now-drives-half-of-all-cyber-claims-atbay-573139.aspx">One ransomware crew now drives half of all cyber claims: At-Bay</a> - <strong>Insurance Business Magazine</strong> reports - <em>&#8220;The cyber carrier's 2026 InsurSec Report, drawn from more than 6,500 claims and 100,000 policy years, concluded that ransomware has entered an infrastructure-driven phase.&#8221;</em></p><ul><li><p><a href="https://www.at-bay.com/wp-content/uploads/2026/04/At-Bay-2026-InsurSec-Report.pdf">The report from At-Bay</a></p><ul><li><p>1 in 3 ransomware claims suffered business interruption, and those that did saw 3X higher severity.</p></li><li><p>87% of ransomware claims began with the attacker entering through a remote access service.</p></li><li><p>Akira was responsible for a 53% surge in ransomware claim frequency in H2 2025.</p></li></ul></li></ul></li></ul></li></ul><p>Reflections this week primarily centre around the fact that reliability of AI systems has to be a deep focus. The fact that LLMs (other AI approaches are available) are non deterministic puts us in a pinch as they cannot be deployed without supervision or other constraint. Be that scaffolding, deterministic provers on the side (to increase confidence) and similar. How we move to highly reliable generative AI and reasoning has to be an objective..</p><p>It is also clear that the cost of execution for some of the models delivered as a Service (i.e. token cost) is going to be a very real limiter to where and how they can be deployed. We are already seeing aggressive cost optimisation solutions.. </p><p>.. all of which says there is still much to do on multiple fronts if we wish to gain the cyber security benefit at scale without human in or on the loop.</p><p>Not getting this via email? Subscribe:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Think someone else would benefit? Share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-a16?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-a16?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p><strong>All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.</strong></p><p>Have a lovely Saturday&#8230;</p><p>Ollie</p><h1>Cyber threat intelligence</h1><p>Who is doing what to whom and how allegedly.</p><h2>Reporting on Russia</h2><h3>A Shortcut to Coercion: Incomplete Patch of APT28&#8217;s Zero-Day Leads to CVE-2026-32202</h3><p><strong>Maor Dahan</strong> details alleged Russian use of various vulnerabilities which hints at an enduring interest along with capability development around LNK files for initial access.</p><blockquote><ul><li><p>Akamai researchers identified that an incomplete patch for <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21510">CVE-2026-21510</a> (an APT28 exploit) created a new zero-click vulnerability: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32202">CVE-2026-32202</a>.</p></li><li><p>While Microsoft&#8217;s fix successfully prevented the initial remote code execution (RCE) and SmartScreen bypass, it left behind a zero-click authentication coercion vulnerability (which is now classified as CVE-2026-32202).</p></li></ul><ul><li><p>We detected the APT28 (also known as Fancy Bear) exploit in January 2026 and Microsoft patched it on February&#8217;s Patch Tuesday.</p></li><li><p><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21513">CVE-2026-21513</a> and CVE-2026-21510 were exploited in the same LNK file and were a crucial part of the exploitation chain.</p></li><li><p>We then found an incomplete patch and disclosed it to Microsoft. The new vulnerability, CVE-2026-32202, caused the victim to authenticate the attacker&#8217;s server without user interaction (zero click).</p></li></ul></blockquote><p><a href="https://www.akamai.com/blog/security-research/2026/apr/incomplete-patch-apt28s-zero-day-cve-2026-32202">https://www.akamai.com/blog/security-research/2026/apr/incomplete-patch-apt28s-zero-day-cve-2026-32202</a></p><h3>Easter Bunny</h3><p><strong>S2GRUPO</strong> detail an alleged APT28 implant which has environment guardrails which is noteworthy for defence teams. </p><blockquote><p>After more than a year of work and for the first time in public, LAB52, S2GRUPO&#8217;s cyber intelligence unit, has conducted an exhaustive analysis of one of the most advanced espionage artifacts attributed to APT29, which we have named EasterBunny. </p><p>This malware, which is exceptionally sophisticated and has a modular operating architecture, has been developed using a multi-layered pipeline designed to maximize stealth and make attribution difficult. Its developers have taken operational security (OpSec) measures to the highest level, demonstrating a deep technical knowledge of malware engineering. This is reflected in the use of multiple layers of encryption and obfuscation, both for commands and data, and in the systematic concealment of its actual internal logic. </p><p>One of its most unique features is that it only runs on the computer on which it has been installed, a behavior that has no documented precedent in the public domain since its discovery</p><p>Its architecture reveals the use of multiple builders or binders which, like a Matryoshka doll, conceal the true logic of the binary. The malware engineering applied gives the sample advanced concealment and evasion capabilities against traditional detection systems. Of particular note is the implementation of a reflexive loader for Position Independent Code (PIC), never publicly documented. Added to this is the probable existence of a complex control platform used by APT29 to build, configure, and operate the EasterBunny family</p></blockquote><p><a href="https://home.s2grupo.es/hubfs/Informe%20LAB52-%20EasterBunny_Complete.pdf">https://home.s2grupo.es/hubfs/Informe%20LAB52-%20EasterBunny_Complete.pdf</a></p><h2>Reporting on China</h2><h3>Tropic Trooper Reloaded: Unraveling the Invisible Supply Chain Mystery</h3><p><strong>Suguru Ishimaru</strong> and <strong>Satoshi Kamekawa</strong> detail a supply chain attack by this alleged Chinese threat actor which shows a degree of sophistication to be able to execute.</p><blockquote><p>Based on our 2025 investigation, several new malware families, toolsets, and notable artifacts, including decoys were identified, providing fresh insight into the group&#8217;s expanding geographic footprint and targeted industries. Recent activity has revealed a marked shift toward OSS-based tools within the infection chain. These findings highlight a rapid change in the actor&#8217;s tooling strategy, demonstrating its ability to pivot quickly and overhaul their methods within a short period of time.</p><p>Earlier activity in 2024 included a supply-chain compromise in which malware was delivered through what appeared to be the legitimate update process of a widely used dictionary application. Although the exact infection path was unclear at the time, a follow-up investigation in 2025 indicated that unauthorized changes had been made to the target&#8217;s home router, resulting in malware infections.</p></blockquote><p><a href="https://blackhat.com/asia-26/briefings/schedule/?#tropic-trooper-reloaded-unraveling-the-invisible-supply-chain-mystery-51385">https://blackhat.com/asia-26/briefings/schedule/?#tropic-trooper-reloaded-unraveling-the-invisible-supply-chain-mystery-51385</a></p><p><a href="https://i.blackhat.com/Asia-26/Presentations/AS26-Ishimaru-Tropic-Trooper-Reloaded-REV01.pdf?_gl=1*1svtcz7*_gcl_au*MTM5MzU3ODc5MC4xNzc3MTA0MTA1*_ga*NzY1OTE4NTI4LjE3NzcxMDQxMDU.*_ga_K4JK67TFYV*czE3Nzc3MDI0MTAkbzMkZzAkdDE3Nzc3MDI0MTAkajYwJGwwJGgw">https://i.blackhat.com/Asia-26/Presentations/AS26-Ishimaru-Tropic-Trooper-Reloaded-REV01.pdf?_gl=1*1svtcz7*_gcl_au*MTM5MzU3ODc5MC4xNzc3MTA0MTA1*_ga*NzY1OTE4NTI4LjE3NzcxMDQxMDU.*_ga_K4JK67TFYV*czE3Nzc3MDI0MTAkbzMkZzAkdDE3Nzc3MDI0MTAkajYwJGwwJGgw</a></p><h3>Tropic Trooper Pivots to AdaptixC2 and Custom Beacon Listener</h3><p><strong>Yin Hong Chang</strong> and <strong>Sudeep Singh</strong> details use of open source offensive tooling with customisation by this alleged Chinese threat actor.</p><blockquote><ul><li><p>On March 12, 2026, ThreatLabz discovered a malicious ZIP archive containing military-themed document lures targeting Chinese-speaking individuals.</p></li><li><p>The campaign used a trojanized SumatraPDF binary to deploy an AdaptixC2 Beacon and ultimately VS Code on targeted machines.</p></li><li><p>The shellcode loader used in this attack closely resembles the TOSHIS loader, which has been associated with Tropic Trooper and was previously <a href="https://www.trendmicro.com/en_us/research/25/h/taoth-campaign.html">reported</a> in the TAOTH campaign.</p></li><li><p>The threat actors created a custom AdaptixC2 Beacon listener, leveraging GitHub as their command-and-control (C2) platform.</p></li><li><p>The staging server involved in this attack also hosted CobaltStrike Beacon and an EntryShell backdoor. Both malware types and configurations are <a href="https://hitcon.org/2024/CMT/slides/Pirates_of_The_Nang_Hai_Follow_the_Artifacts_of_Tropic_Trooper,_No_One_Knows.pdf">known</a> to have been used by Tropic Trooper.</p></li></ul></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!PReE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1426cc27-dc66-4f40-aa34-64973a15dccf_1080x809.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!PReE!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1426cc27-dc66-4f40-aa34-64973a15dccf_1080x809.webp 424w, /__u/substackcdn.com/image/fetch/$s_!PReE!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1426cc27-dc66-4f40-aa34-64973a15dccf_1080x809.webp 848w, /__u/substackcdn.com/image/fetch/$s_!PReE!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1426cc27-dc66-4f40-aa34-64973a15dccf_1080x809.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!PReE!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1426cc27-dc66-4f40-aa34-64973a15dccf_1080x809.webp 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!PReE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1426cc27-dc66-4f40-aa34-64973a15dccf_1080x809.webp" width="1080" height="809" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1426cc27-dc66-4f40-aa34-64973a15dccf_1080x809.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:809,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Tropic Trooper attack chain leading to the deployment of an AdaptixC2 Beacon and VS Code tunnels.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Tropic Trooper attack chain leading to the deployment of an AdaptixC2 Beacon and VS Code tunnels." title="Tropic Trooper attack chain leading to the deployment of an AdaptixC2 Beacon and VS Code tunnels." srcset="/__u/substackcdn.com/image/fetch/$s_!PReE!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1426cc27-dc66-4f40-aa34-64973a15dccf_1080x809.webp 424w, /__u/substackcdn.com/image/fetch/$s_!PReE!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1426cc27-dc66-4f40-aa34-64973a15dccf_1080x809.webp 848w, /__u/substackcdn.com/image/fetch/$s_!PReE!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1426cc27-dc66-4f40-aa34-64973a15dccf_1080x809.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!PReE!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1426cc27-dc66-4f40-aa34-64973a15dccf_1080x809.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.zscaler.com/blogs/security-research/tropic-trooper-pivots-adaptixc2-and-custom-beacon-listener">https://www.zscaler.com/blogs/security-research/tropic-trooper-pivots-adaptixc2-and-custom-beacon-listener</a></p><h3>Global Campaign Discovered with Modbus PLCs Targeted and China-Geolocated Infrastructure Observed</h3><p><strong>Dr. Guy Waizel </strong>and <strong>Jakub Osmani </strong>detail PLC targeted scanning which is noteworthy due to the high intent infrastructure being located in China.</p><blockquote><p>Across the three months, we saw thousands of requests sourced from a broad and frequently low-reputation infrastructure set, alongside a small subset of higher-intent infrastructure of interest including sources geolocated to China. While it&#8217;s unclear who the threat actors are, these findings reinforce a simple takeaway: exposing Modbus to the internet materially increases both operational risk and the likelihood of follow-on attack activity.</p><p>&#8230;</p><p>Basic device identification (0100) was common, but the expanded identification payload (0200) was rare and concentrated: 175 requests from six IPs. Most of these sources geolocated to China and had strong reputation signals. We treat this as higher-intent reconnaissance infrastructure of interest, while noting again that geolocation does not establish operator identity.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!N0gQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82dffd51-7c80-466c-aa55-d78a1e526080_2080x1264.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!N0gQ!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82dffd51-7c80-466c-aa55-d78a1e526080_2080x1264.png 424w, /__u/substackcdn.com/image/fetch/$s_!N0gQ!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82dffd51-7c80-466c-aa55-d78a1e526080_2080x1264.png 848w, /__u/substackcdn.com/image/fetch/$s_!N0gQ!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82dffd51-7c80-466c-aa55-d78a1e526080_2080x1264.png 1272w, /__u/substackcdn.com/image/fetch/$s_!N0gQ!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82dffd51-7c80-466c-aa55-d78a1e526080_2080x1264.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!N0gQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82dffd51-7c80-466c-aa55-d78a1e526080_2080x1264.png" width="1456" height="885" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/82dffd51-7c80-466c-aa55-d78a1e526080_2080x1264.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:885,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!N0gQ!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82dffd51-7c80-466c-aa55-d78a1e526080_2080x1264.png 424w, /__u/substackcdn.com/image/fetch/$s_!N0gQ!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82dffd51-7c80-466c-aa55-d78a1e526080_2080x1264.png 848w, /__u/substackcdn.com/image/fetch/$s_!N0gQ!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82dffd51-7c80-466c-aa55-d78a1e526080_2080x1264.png 1272w, /__u/substackcdn.com/image/fetch/$s_!N0gQ!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82dffd51-7c80-466c-aa55-d78a1e526080_2080x1264.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.catonetworks.com/blog/global-campaign-discovered-with-modbus-plcs-targeted/">https://www.catonetworks.com/blog/global-campaign-discovered-with-modbus-plcs-targeted/</a></p><h2>Reporting on North Korea</h2><h3>Inside Lazarus: How North Korea uses AI to industrialize attacks on developers</h3><p><strong>Marcus Hutchins</strong> details the alleged use of ChatGPT by an alleged North Korean actor. Interesting that this can&#8217;t be detected and stopped given it is Software as a Service.</p><blockquote><ul><li><p>Expel is actively tracking an APT group that we assess with high confidence to be North Korean (DPRK) state-sponsored. We suspect that the threat actor is a subgroup or spin-off of a larger organization, potentially starting out as fraudulent IT workers before pivoting to malware.</p></li><li><p>The group is extremely active in targeting Web3 developers and is primarily focused on stealing high-value digital assets such as cryptocurrency and NFTs.</p></li><li><p>As much as $12M worth of cryptocurrency wallets were exfiltrated by the threat actor in 3 months, though hardware security tokens may limit damage.</p></li><li><p>Whilst this specific group is financially motivated, many of their techniques overlap with other DPRK APTs, including those engaged in espionage.</p></li><li><p>The group makes heavy use of Generative AI, often abusing tools like Cursor and ChatGPT.</p></li></ul></blockquote><p><a href="https://expel.com/blog/inside-lazarus-how-north-korea-uses-ai-to-industrialize-attacks-on-developers/">https://expel.com/blog/inside-lazarus-how-north-korea-uses-ai-to-industrialize-attacks-on-developers/</a></p><h3>BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector</h3><p><strong>Arctic Wolf Labs</strong> detail and alleged North Korean operation which is leveraging ClickFix techniques showing that the inspiration that alleged state actors take from criminal may be a thing..  </p><blockquote><ul><li><p>While the initial attack commenced approximately five months after initial contact with the primary victim, the execution chain itself swiftly progressed from initial click during a &#8220;fake meeting,&#8221; to full system compromise in under five minutes.</p></li></ul><ul><li><p>Attacker infrastructure analysis revealed over 80 typo-squatted Zoom and Teams domains registered on the same infrastructure between late 2025 and March 2026.</p></li></ul><ul><li><p>Analysis of over 950 files from the attacker&#8217;s media hosting server revealed a self-reinforcing deepfake production pipeline: exfiltrated webcam footage from prior victims was combined with AI-generated images to produce new fake meeting content.</p></li></ul><ul><li><p>80% of identified targets operate in cryptocurrency/ blockchain finance or adjacent investment sectors, while CEOs and founders account for 45% of the target set &#8211; nearly half. This underscores BlueNoroff&#8217;s singular operational focus: individuals with access to cryptocurrency assets, wallet infrastructure, exchange platforms, or investment decision-making authority.</p></li></ul><ul><li><p>Timestamp analysis from attacker infrastructure shows operator activity concentrated during <a href="https://en.wikipedia.org/wiki/North_Korea">DPRK</a> business hours, with minimal weekend activity. This pattern is consistent with state-sponsored operations operating on a standard workday schedule.</p></li></ul></blockquote><p><a href="https://arcticwolf.com/resources/blog/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector/">https://arcticwolf.com/resources/blog/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector/</a></p><h3>Inside DPRK&#8217;s npm malware factory: 108 packages, 261 versions, and a 31-day campaign wave</h3><p>Michael Baker .. </p><blockquote><p>Over approximately 30 days, Panther Threat Research monitored, clustered, and tracked a DPRK-linked npm malware campaign spanning 108 malicious packages and a total of 261 package versions. The broader campaign graph below contains 261 observed package-version nodes across multiple operational clusters. The common thread was simple: lure developers into running malicious packages, execute code on trusted developer or CI systems, then steal credentials, wallet private key, sessions, and establish persistent access. If your teams leverage the npm ecosystem, include packages in CI/CD tooling, or have crypto-adjacent developer workflows, treat this as active exploitation of developer environments leading to credential theft, footholds, and follow-on access.</p></blockquote><p><a href="https://panther.com/blog/inside-dprk%E2%80%99s-npm-malware-factory-108-packages-261-versions-and-a-31-day-campaign-wave">https://panther.com/blog/inside-dprk%E2%80%99s-npm-malware-factory-108-packages-261-versions-and-a-31-day-campaign-wave</a></p><h2>Reporting on Iran</h2><p><em>Nothing overly of note this week</em></p><h2>Reporting on Other Actors</h2><h3>TeamPCP Campaign Spreads to npm via a Hijacked Bitwarden CLI</h3><p><strong>Meitar Palas</strong> shows that open source supply chain package distribution solutions continue to a source of exposure and is actively being leveraged. </p><blockquote><p>[We] identified a hijacked npm package published as <code>@bitwarden/cli</code> version <code>2026.4.0</code>, impersonating the legitimate Bitwarden command line client. The package keeps the expected Bitwarden metadata, but rewires both <code>preinstall</code> and the <code>bw</code> binary entrypoint to a custom loader, <code>bw_setup.js</code>, instead of the legitimate bundled CLI.</p></blockquote><p><a href="https://research.jfrog.com/post/bitwarden-cli-hijack/">https://research.jfrog.com/post/bitwarden-cli-hijack/</a></p><h3>A Mini Shai-Hulud Has Appeared: Obfuscated Bun Runtime Payloads Hit SAP-Related npm Packages</h3><p><strong>Sai Likhith</strong> detail another open source supply chain compromise by this threat actor in order to deploy credential stealers. </p><blockquote><p>Four confirmed compromised packages, <code>mbt@1.2.48</code>, <code>@cap-js/sqlite@2.2.2</code>, <code>@cap-js/postgres@v2.2.2</code>, and <code>@cap-js/db-service@v2.10.1</code>, all carry an identical malicious <code>preinstall</code> hook that bootstraps the Bun JavaScript runtime and executes a heavily obfuscated 11.6 MB credential stealer.</p></blockquote><p><a href="https://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared">https://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared</a></p><h3>Komari: The &#8220;Monitoring&#8221; Tool That Didn&#8217;t Need Weaponising</h3><p><strong>Josh Kiriakoff </strong>details another instance of a threat actor deploying legitimate tooling in order to achieve persistence and access.</p><blockquote><ul><li><p>On April 16, 2026, a threat actor used stolen VPN credentials to pivot into a Windows workstation and dropped a SYSTEM-level backdoor using the Komari agent - a 4.3k-star, MIT-licensed, Go-based project on GitHub that self-describes with the repo topic tags remote-control, monitoring, and monitoring-tool. We believe this is the first publicly documented case of Komari being abused in a real-world intrusion.</p></li><li><p>Komari is not a telemetry tool that happens to be abusable - it is a bidirectional control channel by design. The agent opens a persistent WebSocket to its server and accepts three server-to-agent event types out of the box: exec (arbitrary command execution via PowerShell / sh), terminal (interactive PTY reverse shell in the operator&#8217;s browser), and ping (ICMP / TCP / HTTP probing). All three are enabled by default; the <strong>--disable-web-ssh</strong> flag is opt-in.</p></li><li><p>The operator installed Komari as a persistent Windows service named &#8220;Windows Update Service&#8221; via NSSM (the &#8220;Non-Sucking Service Manager&#8221;), pulling the installer directly from the official Komari GitHub repository. No attacker-controlled infrastructure was needed to stage the loader.</p></li></ul></blockquote><p><a href="https://www.huntress.com/blog/komari-c2-agent-abuse">https://www.huntress.com/blog/komari-c2-agent-abuse</a></p><h1>Discovery</h1><p>How we find and understand the latent compromises within our environments.</p><h2>Copyfail detect</h2><p><strong>Kadir Can</strong> does global good and provides a detection package for Copyfail for those having to respond&#8230; </p><blockquote><p>Detection toolkit for CVE-2026-31431 (&#8221;Copy Fail&#8221;), a Linux kernel local privilege escalation technique that corrupts page-cache data without changing the file on disk.</p></blockquote><p><a href="https://github.com/kadir/copy-fail-CVE-2026-31431-IOC">https://github.com/kadir/copy-fail-CVE-2026-31431-IOC</a></p><h2>Graph-aware LLM for Windows logons with a closed-loop guarded detection agent</h2><p><strong>Shusei Tomonaga</strong> provides a practical guide on how to apply LLM to discovery tasks in cyber defence whilst recognising and importantly overcoming the challenge.</p><blockquote><ul><li><p>Understand a practical method to extract suspicious activity from Windows Event Logs for incident response without relying solely on signature-based detection.</p></li><li><p>Design and deploy a graph-oriented preprocessing pipeline that compresses large-scale Windows Event Logs into an authentication graph and feature set that an LLM can efficiently consume</p></li><li><p>Apply techniques for automated LLM-based log analysis while constraining hallucinations.</p></li></ul></blockquote><p><a href="https://i.blackhat.com/Asia-26/Presentations/BHAS26-Tomonaga-Graph-Aware.pdf?_gl=1*9r406i*_gcl_au*NjI1MTMxODM2LjE3NzcyOTAwNzg.*_ga*ODg2OTU4MzQyLjE3NzcyOTAwNzg.*_ga_K4JK67TFYV*czE3NzcyOTAwNzgkbzEkZzEkdDE3NzcyOTA4NzAkajQ2JGwwJGgw">https://i.blackhat.com/Asia-26/Presentations/BHAS26-Tomonaga-Graph-Aware.pdf?_gl=1*9r406i*_gcl_au*NjI1MTMxODM2LjE3NzcyOTAwNzg.*_ga*ODg2OTU4MzQyLjE3NzcyOTAwNzg.*_ga_K4JK67TFYV*czE3NzcyOTAwNzgkbzEkZzEkdDE3NzcyOTA4NzAkajQ2JGwwJGgw</a></p><h2>LaraC2 Shell -- MDE Live Response Interactive Shell</h2><p><strong>Alex Kefallonitis</strong> provides a super power to defenders working in a Microsoft eco-system.</p><blockquote><p>LaraC2 Shell connects to MDE Live Response through two independent API paths -- the internal portal API (persistent sessions, ~2-5s latency) and the official public API (per-command, ~20-60s latency). It auto-uploads executor stubs, handles rate limiting transparently, and provides a full REPL with machine management, library management, and a built-in help system.</p></blockquote><p><a href="https://github.com/akefallonitis/larac2shell">https://github.com/akefallonitis/larac2shell</a></p><h2>Atomic BOFs</h2><p><strong>Rasta Mouse</strong> provides a massive capability to defenders and detection engineers wrestling with the surge in BOFs and who are tasked with ensuring coverage.</p><blockquote><p>Atomic BOFs is my attempt at providing repeatable, atomic test units for BOF execution. The goal was to provide an easy means of running BOFs outside of a C2 framework, whilst maintaining the equivalent functionality.</p></blockquote><p><a href="https://rastamouse.me/atomic-bofs/">https://rastamouse.me/atomic-bofs/</a></p><p><a href="https://github.com/rasta-mouse/atomic-bofs">https://github.com/rasta-mouse/atomic-bofs</a></p><h1>Defence</h1><p>How we proactively defend our environments.</p><h2>CVE-2026-31431 aka Copy.Fail eBPF workaround</h2><p><strong>Ivan Agarkov</strong> provides an eBPF mitigation for those struggling to patch..</p><blockquote><p>This package provides you two eBPF programs:</p><ul><li><p>ebpf-alg-socket-filter, which filters AF_ALG socket creation by eBPF/LSM kernel mechanism</p></li><li><p>ebpf-alg-socket-killer, which kills any program that creates AF_ALG socket</p></li></ul></blockquote><p><a href="https://github.com/wgnet/wg.copyfail.patch">https://github.com/wgnet/wg.copyfail.patch</a></p><h2>Adapting Zero Trust Principles to Operational Technology</h2><p><strong>Cybersecurity &amp; Infrastructure Security Agency</strong> and partners release this guidance for those on trying to translate.</p><blockquote><p>CISA, in coordination with the Department of War, Department of Energy, Federal Bureau of Investigation, and Department of State, released <a href="https://www.cisa.gov/sites/default/files/2026-04/joint-guide-adapting-zero-trust-principles-to-operational-technology_508c.pdf">Adapting Zero Trust Principles to Operational Technology</a>, joint guidance for organizations applying zero trust (ZT) principles to operational technology (OT). Zero trust is a modern, adaptive approach to cybersecurity that eliminates implicit trust and requires continuously validating access based on identity, context, and risk.</p></blockquote><p><a href="https://www.cisa.gov/resources-tools/resources/adapting-zero-trust-principles-operational-technology">https://www.cisa.gov/resources-tools/resources/adapting-zero-trust-principles-operational-technology</a></p><h2>Introducing Advanced Account Security</h2><p><strong>OpenAI</strong> detail how they are adopting passkeys.. </p><blockquote><ul><li><p><strong>Stronger sign-in methods</strong>. Advanced Account Security requires passkeys or physical security keys while disabling password-based login, helping make phishing-resistant sign-in the default for people who need it most.</p></li><li><p><strong>More secure account recovery</strong>. If a user&#8217;s email account or phone number is compromised, an attacker may try to use one of them to gain access to their ChatGPT account via e-mail or SMS based recovery. To reduce this risk, Advanced Account Security disables email and SMS recovery and requires stronger recovery methods: backup passkeys, security keys, and recovery keys. Because account recovery is restricted to these more secure methods, OpenAI Support will not be able to assist with account recovery for users enrolled in Advanced Account Security.</p></li><li><p><strong>Shorter sessions and clearer session management</strong>. Sign-in sessions are shortened to reduce the window of exposure if a device or active session is compromised. Users also receive alerts when there is a login to their account, and they can review and manage the active sessions across the various devices they&#8217;re signed into.</p></li><li><p><strong>Automatic training exclusion</strong>. People working with especially sensitive information may opt not to have those conversations used for model training. With Advanced Account Security enabled, that preference is automatic: conversations from those accounts will not be used to train our models</p></li></ul></blockquote><p><a href="https://openai.com/index/advanced-account-security/">https://openai.com/index/advanced-account-security/</a></p><h2>auditd rules v0.2.0</h2><p><strong>Florian Roth</strong> provides a capability that ever Linux device globally should consider deploying..</p><blockquote><p>The goal of <code>audit.rules</code> is to collect broad, attributable, reusable host telemetry. It should not try to encode every suspicious binary, shell, admin tool, or attacker workflow directly in the audit layer. In other words: the audit ruleset is the sensor, not the detection engine.</p><p>Detection logic belongs downstream in Sigma rules, SIEM queries, Aurora Linux, or other analytics that can correlate context, reduce noise, and evolve faster than a static auditd config.</p><p>That shift makes the ruleset:</p><ul><li><p>simpler to understand and maintain</p></li><li><p>more portable across Linux distributions and libaudit variants</p></li><li><p>less brittle than long lists of hard-coded per-binary detections</p></li><li><p>easier to validate in CI and test before deployment</p></li><li><p>better suited as a common telemetry source for multiple downstream tools</p></li></ul></blockquote><p><a href="https://github.com/Neo23x0/auditd/releases">https://github.com/Neo23x0/auditd/releases</a></p><h2>Your Windows update experience just got updated</h2><p><strong>Microsoft</strong> potentially regress some Windows update features by allowing user controlled delays in patching.. </p><blockquote><p>Across this feedback there are two key themes that persistently pop out: disruption caused by untimely updates and not enough control over when updates happen. The changes we&#8217;re rolling out today are focused on giving Windows users more control over their PC experience, while keeping devices secure by design and by default.</p></blockquote><p><a href="https://blogs.windows.com/windows-insider/2026/04/24/your-windows-update-experience-just-got-updated/">https://blogs.windows.com/windows-insider/2026/04/24/your-windows-update-experience-just-got-updated/</a></p><h1>Incident Writeups &amp; Disclosures</h1><p>How they got in and what they did.</p><h2>Supply Chain Security Incident Update</h2><p><strong>Checkmarx</strong> supply chain compromise ramifications role on..</p><blockquote><p>On March 23, 2026, Checkmarx identified a cybersecurity incident originating from the Trivy Supply Chain Attack. The cybersecurity community previously reported on March 19 that the TeamPCP attack affecting the Trivy scanner could potentially be used to harvest credentials from downstream users.</p><p>..</p><p>A cybercriminal group subsequently published data related to Checkmarx to the dark web on April 25. Current evidence indicates that this data originated from Checkmarx&#8217;s GitHub repositories, and that access to those repositories was facilitated through the initial supply chain attack of March 23, 2026.</p></blockquote><p><a href="https://checkmarx.com/blog/supply-chain-security-incident-update/">https://checkmarx.com/blog/supply-chain-security-incident-update/</a></p><h2>Bitwarden Statement on Checkmarx Supply Chain Incident</h2><p><strong>Adam Eckerle</strong> has some deflective perspectives in this.. </p><blockquote><p>The Bitwarden security team identified and contained a malicious package that was briefly distributed through the npm delivery path for @bitwarden/cli@2026.4.0 between 5:57 PM and 7:30 PM (ET) on April 22, 2026, in connection with a broader Checkmarx supply chain incident.</p></blockquote><p><a href="https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127">https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127</a></p><h2>DigiCert: Misissued code signing certificates</h2><p><strong>DigiCert</strong> detail a compromise at the heart of trust infrastructure.. </p><blockquote><p>A malware incident targeted a customer support team member. Upon detection, the threat vector was contained. Our subsequent investigation found that the threat actor was able to procure initialization codes for a limited number of code signing certificates, few of which were then used to sign malware. The identified certificates were revoked within 24 hours of discovery and the revocation date set to their date of issuance. As a precautionary measure, pending orders within the window of interest were cancelled. Additional details will be provided in our full incident report.</p></blockquote><p><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033170">https://bugzilla.mozilla.org/show_bug.cgi?id=2033170</a></p><h1>Vulnerability</h1><p>Our attack surface.</p><h2>Beyond CVEs: Untracked Vulnerabilities in Public Issue Trackers</h2><p><strong>M&#259;d&#259;lin Simion</strong>, <strong>Max van der Horst</strong>, <strong>Stan Plasmeijer</strong> and <strong>Yury Zhauniarovich</strong> show once more that vulnerability hides in plain sight.. </p><blockquote><p>We closely examined four large C++ projects and found that approximately 1.55% of all reported issues were classified by our model as security-related. Expert validation performed by the CVE Numbering Authority (CNA) Administrator on the gRPC project revealed that about 22% of these predicted security-related issues correspond to real, previously untracked vulnerabilities.</p></blockquote><p><a href="https://dl.acm.org/doi/abs/10.1145/3803525.3804993">https://dl.acm.org/doi/abs/10.1145/3803525.3804993</a></p><h2>Copy Fail</h2><p><strong>Xint</strong> go hard on vulnerability marketing which has real-world scale.. </p><blockquote><p>Copy Fail requires only an unprivileged local user account &#8212; no network access, no kernel debugging features, no pre-installed primitives. The kernel crypto API (<code>AF_ALG</code>) ships enabled in essentially every mainstream distro's default config, so the entire 2017 &#8594; patch window is in play out of the box.</p></blockquote><p><a href="https://copy.fail/">https://copy.fail/</a></p><p><a href="https://github.com/theori-io/copy-fail-CVE-2026-31431">https://github.com/theori-io/copy-fail-CVE-2026-31431</a></p><p>Also served a lesson why <a href="https://x.com/grsecurity/status/2049590384389501014?s=20">grsecurity is a super powe</a>r</p><blockquote><p>If your kernel configuration is based on any major distro kernel configuration however and GRKERNSEC_MODHARDEN is enabled (as is done by default via auto-config) and algif_aead was not loaded as a module by a privileged user, exploitation is not possible by an unprivileged user:</p></blockquote><h2>Firmware Update Required &#8212; Gen 6, Gen 7, and Gen 8 Firewalls</h2><p>SonicWall release patches which look like they may be a viable chain</p><blockquote><p>A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.<br>..</p></blockquote><p>then two post auth vulns.. </p><p><a href="https://www.sonicwall.com/support/notices/security-advisory-firmware-update-required-gen-6-gen-7-and-gen-8-firewalls/kA1VN000001F03x0AC">https://www.sonicwall.com/support/notices/security-advisory-firmware-update-required-gen-6-gen-7-and-gen-8-firewalls/kA1VN000001F03x0AC</a></p><p><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0004">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0004</a></p><h2>MOVEit WAF Critical Security Bulletin &#8211; April 2026</h2><p><strong>Progress</strong> remind the world by exec() and friends are hard to secure.. </p><blockquote><p>CVE-2026-3517 - OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager &amp; MOVEit WAF</p><p>CVE-2026-3518 - OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager &amp; MOVEit WAF</p><p>CVE-2026-3519 - OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager &amp; MOVEit WAF</p><p>CVE-2026-4048 - OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager &amp; MOVEit WAF</p></blockquote><p><a href="https://community.progress.com/s/article/MOVEit-WAF-Critical-Security-Bulletin-April-2026-CVE-2026-3517-CVE-2026-3518-CVE-2026-3519-CVE-2026-4048-CVE-2026-21876">https://community.progress.com/s/article/MOVEit-WAF-Critical-Security-Bulletin-April-2026-CVE-2026-3517-CVE-2026-3518-CVE-2026-3519-CVE-2026-4048-CVE-2026-21876</a></p><h2>SQL injection in Proxy API key verification</h2><p><strong>LiteLLM</strong> vulnerabilities showing we have far to go on the secure by default/design journey in the AI eco-system.. </p><blockquote><p>A database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could send a specially crafted <code>Authorization</code> header to any LLM API route (for example <code>POST /chat/completions</code>) and reach this query through the proxy's error-handling path.</p></blockquote><p><a href="https://github.com/BerriAI/litellm/security/advisories/GHSA-r75f-5x8p-qvmc">https://github.com/BerriAI/litellm/security/advisories/GHSA-r75f-5x8p-qvmc</a></p><h2>Patch Diffing CVE-2026-21509: Microsoft Office OLE Security Bypass</h2><p><strong>RedSpider</strong> does the patch diff&#8230;</p><blockquote><p>CVE-2026-21509 is a Security Feature Bypass vulnerability discovered in Microsoft Office.</p><p>By default, Office provides a security mechanism that blocks known-vulnerable COM objects. In this case, however, the affected COM object was not included in the block list, which allowed the vulnerability to be exploited in the wild through Office documents. Rather than waiting for its regular update cycle, Microsoft addressed the issue through an Out-of-Band emergency patch in January &#8212; and then shipped a second, more substantial fix in the February security update. We analyzed both patches: Part 1 covers the January Out-of-Band patch, and Part 2 covers the follow-up in February.</p><p>While analyzing the first patch, we observed unexpected behavior: on the same Office version, the vulnerability was reproducible in some environments but not in others. This write-up documents our investigation into that inconsistency, and summarizes what we learned about Microsoft&#8217;s response to the vulnerability and Office&#8217;s CLSID-based COM blocking mechanism.</p></blockquote><p><a href="https://blog.78researchlab.com/34cdb461-3e5b-808d-a9c9-dc1338adaccc">https://blog.78researchlab.com/34cdb461-3e5b-808d-a9c9-dc1338adaccc</a></p><h2>PhantomRPC: A new privilege escalation technique in Windows RPC</h2><p><strong>Haidar Kabibo</strong> shows the continued battle in local privilege escalation mitigation is real..</p><blockquote><p>I will demonstrate five different exploitation paths that show how privileges can be escalated from various local or network service contexts to SYSTEM or high-privileged users. Some techniques rely on coercion, some require user interaction and some take advantage of background services. As this issue stems from an architectural weakness, the number of potential attack vectors is effectively unlimited; any new process or service that depends on RPC could introduce another possible escalation path. For this reason, I also outline a methodology for identifying such opportunities.</p></blockquote><p><a href="https://securelist.com/phantomrpc-rpc-vulnerability/119428/">https://securelist.com/phantomrpc-rpc-vulnerability/119428/</a></p><h2>Command injection via backtick expansion in tag filenames in Vim &lt; v9.2.0357</h2><p><strong>Christian Brabandt</strong> evidences the text editor cyber security challenge..</p><blockquote><p>A command injection vulnerability exists in Vim&#8217;s tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard expansion to resolve environment variables and wildcards. If the filename field contains backtick syntax (e.g., `` `command` <code>`), Vim</code>executes the embedded command via the system shell with the full privi<code>eges of</code>the running user.</p></blockquote><p><a href="https://seclists.org/oss-sec/2026/q2/140">https://seclists.org/oss-sec/2026/q2/140</a></p><h2>CVE-2026-34159: Exploiting llama.cpp&#8217;s RPC Server - From Null Buffer to RCE Against PIE + Full RELRO + NX</h2><p><strong>Hassan Ali</strong> walks through the end to end exploitation.. this is good work.</p><blockquote><p>This is a 1-day exploit. The bug was already patched when I started, but the exploitation technique and the bypass are worth walking through in detail &#8211; both because it demonstrates how to chain a logic bug into full RCE against a binary protected by PIE, Full RELRO, and NX, and because it highlights a class of vulnerability that persists in many C/C++ codebases.</p></blockquote><p><a href="https://www.pwntricks.com/ZeroClick-RCE-CVE-2026-34159-llama.cpp">https://www.pwntricks.com/ZeroClick-RCE-CVE-2026-34159-llama.cpp</a></p><h2>Making Vulnerable Drivers Exploitable Without Hardware</h2><p><strong>Julian Horoszkiewicz</strong> surfaces our collective attack surface.. </p><blockquote><p>This article provides a technical analysis of how many Windows kernel mode drivers can be interacted with from user mode without the hardware they were developed for. This work was motivated by driver-oriented vulnerability research and the need to evaluate the exploitability of individual findings, which frequently affect code whose reachability is hardware-gated. The methodology presented here should help anyone determine whether a particular Windows kernel mode driver vulnerability remains reachable &#8212; and thus potentially exploitable &#8212; even in the absence of the hardware the driver was developed for.</p></blockquote><p><a href="https://atos.net/wp-content/uploads/2026/04/atos-byovd-article.pdf">https://atos.net/wp-content/uploads/2026/04/atos-byovd-article.pdf</a></p><h1>Offense</h1><p>Attack capability, techniques and trade-craft. </p><h2>Claude Code Backdoor (PoC)</h2><p><strong>s0ld13r</strong> details a technique which given the growing prevalence we can expect certain threat actors to leverage given there focus on the development community.</p><blockquote><p>A Proof of Concept demonstrating how Claude Code (Anthropic&#8217;s CLI AI agent) hooks can be leveraged for Initial Access and Persistence.</p></blockquote><p><a href="https://github.com/s0ld13rr/claude-code-backdoor">https://github.com/s0ld13rr/claude-code-backdoor</a></p><p><a href="https://www.s0ld13r.kz/posts/claude-code-backdoor/">https://www.s0ld13r.kz/posts/claude-code-backdoor/</a></p><h2>vss-fr2system</h2><p><strong>Sailay (Valen)</strong> details a technique that defensive teams will want detection coverage of.</p><blockquote><p>Two small tools that turn an <strong>arbitrary file read</strong> bug on Windows into a <strong>SYSTEM shell</strong>.</p><ul><li><p><code>vss_freeze/</code> &#8212; creates a Volume Shadow Copy as a <strong>standard user</strong>, then holds it open so you have time to read the SAM/SECURITY/SYSTEM hives out of it</p></li><li><p><code>fr2system/</code> &#8212; takes the hives you copied out, decrypts the local NTLM hashes offline, and pops a SYSTEM shell</p></li></ul></blockquote><p><a href="https://github.com/sailay1996/vss-fr2system">https://github.com/sailay1996/vss-fr2system</a></p><h2>LOLCipherLock</h2><p><strong>Schich</strong> shows how to encrypt a device without just living off the land - having early detection triggers where would be useful I suspect.. </p><blockquote><p>This sript uses the cipher.exe to encrypt the C drive. The encryption key is easyly recoverable from the desktop. Ransomware using Cipher.exe might avoid most ransomware specific protections since no filenames are changed and encrypting many files is usual behavior for Cipher.exe</p></blockquote><p><a href="https://github.com/Schich/LOLCipherLock">https://github.com/Schich/LOLCipherLock</a></p><h2>KeeLog BOF</h2><p><strong>Jakob Friedl</strong> drops this BOF which we can expect some to try and leverage and thus detection the imperative given the focus.</p><blockquote><p>Async BOF that captures the KeePass master password by monitoring for the unlock prompt window. When a locked KeePass database is detected, a low-level keyboard hook is installed and keystrokes are captured until the prompt window disappears by being submitted, cancelled or closeed. The captured buffer is then returned to the operator and automatically reconstructed into the master password.</p></blockquote><p><a href="https://github.com/jakobfriedl/keelog-bof">https://github.com/jakobfriedl/keelog-bof</a></p><h2>ProcessInspect BOF</h2><p><strong>DB Yaps</strong> drops this BOF which you can see you might have fun with through page permissions and VEH/SEH etc.</p><blockquote><p>A CS BOF which can be used to inspect process memory, addresses and symbols!</p></blockquote><p><a href="https://github.com/whokilleddb/PSI_BOF">https://github.com/whokilleddb/PSI_BOF</a></p><h2>DSCourier BOF</h2><p><strong>Alex Reid</strong> drops this BOF which detection teams will want to be across..</p><blockquote><p>This is a BOF implementation of <a href="https://www.linkedin.com/in/dylandavis2/">Dylan Davis</a> and <a href="https://www.linkedin.com/in/matthewmschramm/">Matthew Schramm's</a> <a href="https://github.com/DylanDavis1/DSCourier">DSCourier</a> project. It uses WinGet's COM interface to execute arbitrary powershell code in a Microsoft signed and trusted process. Their full research blog can be found <a href="https://dylansec.com/DSCourier/">here</a>.</p></blockquote><p><a href="https://github.com/Octoberfest7/DSCourier_BOF">https://github.com/Octoberfest7/DSCourier_BOF</a></p><h1>Exploitation</h1><p>What is being exploited..</p><h2>Nightmare-Eclipse Tooling Moves From Public PoC to Real-World Intrusion</h2><p><strong><a href="https://www.huntress.com/authors/anna-pham">Anna Pham</a> </strong>and <strong>Michael Tigges </strong>detail the real world deployment of the capability previously covered here showing the value of early detection engineering of these capabilities. </p><blockquote><ul><li><p>[We] observed BlueHammer, RedSun, and UnDefend activity during a live intrusion investigation. We linked the activity back to compromised FortiGate SSL VPN access tied to multiple suspicious source IPs.</p></li><li><p>The most notable artifacts were staged in user-writable directories, including a user&#8217;s Pictures folder and short subfolders under Downloads. The observed activity included hands-on-keyboard reconnaissance like <strong>whoami /priv</strong>, <strong>cmdkey /list</strong>, and <strong>net group</strong>.</p></li><li><p>Despite the execution of these tools, none of them appear to have succeeded during the incident. Further, the threat actor made a series of blunders during the intrusion that indicates that they are not very familiar with UnDefend.</p></li><li><p>A suspicious <strong>agent.exe</strong> binary, which we dubbed BeigeBurrow, appeared to provide tunneling functionality for follow-on access.</p></li></ul></blockquote><p><a href="https://www.huntress.com/blog/nightmare-eclipse-intrusion">https://www.huntress.com/blog/nightmare-eclipse-intrusion</a></p><h1>Tooling and Techniques</h1><p>Low level tooling and techniques for attack and defence researchers</p><h2>Windbg Decompile Extension via LLM</h2><p><strong>&#44992;&#48372;</strong> releases this work aid showing the way of the future..</p><blockquote><p>This project is a Windows x64 WinDbg extension skeleton that resolves a function by name or address, reconstructs a deterministic control-flow view, and asks an LLM directly from the extension to produce pseudocode.</p></blockquote><p><a href="https://github.com/kernullist/windbg-decompile-ext">https://github.com/kernullist/windbg-decompile-ext</a></p><h2>Pike Agent</h2><p><strong>desbma</strong> drops this showing the human augmentation value of LLMs.. </p><blockquote><p><code>pike-agent</code> records and analyzes how programs behave on Linux. It traces a program's activity, indexes it into a database, and lets you chat with an LLM agent about it in a TUI.</p></blockquote><p><a href="https://github.com/synacktiv/pike-agent">https://github.com/synacktiv/pike-agent</a></p><h2>Trailmark</h2><p><strong>Trail of Bits</strong> releases an uplift capability for those trying to reason source code..</p><blockquote><p>Parse source code into queryable graphs of functions, classes, calls, and semantic annotations for security analysis.</p><p>Trailmark uses <a href="https://tree-sitter.github.io/">tree-sitter</a> for language-agnostic AST parsing and <a href="https://www.rustworkx.org/">rustworkx</a> for high-performance graph traversal. The long-term vision is to combine this graph with mutation testing and coverage-guided fuzzing to identify gaps between assumptions and test coverage that are reachable from user input.</p></blockquote><p><a href="https://github.com/trailofbits/trailmark">https://github.com/trailofbits/trailmark</a></p><h2>Goodbye Secure Pool, Hello KDP Pool</h2><p><strong>Yarden Shafir</strong> details this Windows change which shows continued hardening.</p><blockquote><p>Sadly, the secure pool was removed in 26H2. In future builds it is replaced by another feature that is much closer in its implementation to static KDP but allows more flexibility. The feature doesn&#8217;t have a public name yet, but some functions and variables use the term &#8220;KDP Pool&#8221; so I will use it here too.</p><p>Unlike the secure pool which was available to any driver, KDP Pool is currently an internal feature in ntoskrnl.exe. But since its design (that I&#8217;ll describe in the next section) doesn&#8217;t add any new kernel or hypervisor functionality, developers can easily recreate it in their own driver if they choose to.</p><p>&#8230;</p><p>This protects the section pages from being modified by a VTL0 attacker with kernel write primitive &#8211; setting the &#8220;write&#8221; bit in the PTE will not change the SLAT protection. Only an attacker with kernel code execution can issue a secure call to unprotect the page and make the section writeable again &#8211; but at that point they hardly need to change any of the variables stored there.</p></blockquote><p><a href="https://windows-internals.com/goodbye-secure-pool-hello-kdp-pool/">https://windows-internals.com/goodbye-secure-pool-hello-kdp-pool/</a></p><h2>How Kernel Anti-Cheats Work: A Deep Dive into Modern Game Protection</h2><p><strong>Adri&#225;n D&#237;az </strong>detailed this in February but worth covering because as cyber security always lags those who need to mitigate game hackers. </p><blockquote><p>Modern kernel anti-cheat systems are, without exaggeration, among the most sophisticated pieces of software running on consumer Windows machines. They operate at the highest privilege level available to software, they intercept kernel callbacks that were designed for legitimate security products, they scan memory structures that most programmers never touch in their entire careers, and they do all of this transparently while a game is running. If you have ever wondered how BattlEye actually catches a cheat, or why Vanguard insists on loading before Windows boots, or what it means for a PCIe DMA device to bypass every single one of these protections, this post is for you.</p></blockquote><p><a href="https://s4dbrd.github.io/posts/how-kernel-anti-cheats-work/">https://s4dbrd.github.io/posts/how-kernel-anti-cheats-work/</a></p><h2>TLGMapper</h2><p><strong>Asuka Nakajima</strong> provides this enricher for IDA..</p><blockquote><p>An IDA Pro script that parses <a href="https://learn.microsoft.com/en-us/windows/win32/tracelogging/trace-logging-portal">TraceLogging</a> metadata embedded in x64 PE binaries and resolves each event to its owning ETW provider and the function that fires it.</p></blockquote><p><a href="https://github.com/AsuNa-jp/TLGMapper">https://github.com/AsuNa-jp/TLGMapper</a></p><h2>Launch WSL Applications from Windows with WslLaunch</h2><p><strong>Pavel Yosifovich</strong> details how it is done..</p><blockquote><p>You can launch a Linux process from a Windows process. Directly. With a proper Win32 API call, and even standard handles can be specified. There are at least two ways to do this, and in this post I will walk through one of them: <code>WslLaunch</code>.</p></blockquote><p><a href="https://trainsec.net/library/windows-kernel/launch-wsl-applications-from-windows-with-wsllaunch/">https://trainsec.net/library/windows-kernel/launch-wsl-applications-from-windows-with-wsllaunch/</a></p><h2>EVENSTAR - KernelToUserInjector</h2><p><strong>Winterknife</strong> provides a proof of concept which will be useful to those trying to detect these techniques..</p><blockquote><p>Sample code that demonstrates code injection from kernel-mode into a user-land process using APCs</p></blockquote><p><a href="https://github.com/winterknife/EVENSTAR/tree/master/KernelToUserInjector">https://github.com/winterknife/EVENSTAR/tree/master/KernelToUserInjector</a></p><h1>Footnotes</h1><p>Some other small (and not so small) bits and bobs which might be of interest.</p><ul><li><p>Annual, quarterly and monthly reports</p><ul><li><p><em>Nothing overly of note this week, but keep an eye on</em> <a href="https://github.com/jacobdjwilson/awesome-annual-security-reports/tree/main/Annual%20Security%20Reports/2026">the Awesome Annual Security Reports 2026 collection</a></p></li></ul></li><li><p><a href="https://www.ucl.ac.uk/engineering/security-crime-science/study/postgraduate-research/epsrc-centre-doctoral-training-cyber-physical-risk/how-apply-and-secure-funding">EPSRC Centre for Doctoral Training in Cyber-Physical Risk - How to Apply and Secure Funding</a></p></li><li><p>Artificial intelligence</p><ul><li><p>Fundamental</p><ul><li><p><a href="https://arxiv.org/abs/2604.21254">Hyperloop Transformers</a></p></li><li><p><a href="https://arxiv.org/abs/2604.14969">Discovering Novel LLM Experts via Task-Capability Coevolution</a></p></li><li><p><a href="https://arxiv.org/abs/2604.18292">Agent-World: Scaling Real-World Environment Synthesis for Evolving General Agent Intelligence</a></p></li><li><p><a href="https://arxiv.org/abs/2604.20209">Scaling Self-Play with Self-Guidance</a></p></li><li><p><a href="https://arxiv.org/abs/2604.27707">Contextual Agentic Memory is a Memo, Not True Memory</a></p></li><li><p><a href="https://arxiv.org/abs/2604.27238">SafeTune: Mitigating Data Poisoning in LLM Fine-Tuning for RTL Code Generation</a></p></li></ul></li><li><p>Applied non-cyber</p><ul><li><p><a href="https://arxiv.org/abs/2506.05606">OPeRA: A Dataset of Observation, Persona, Rationale, and Action for Evaluating LLMs on Human Online Shopping Behavior Simulation</a></p></li><li><p><a href="https://arxiv.org/abs/2604.04978">Measuring the Permission Gate: A Stress-Test Evaluation of Claude Code&#8217;s Auto Mode</a></p></li><li><p><a href="https://arxiv.org/abs/2604.25639">Large language models eroding science understanding: an experimental study</a></p></li><li><p><a href="https://arxiv.org/abs/2604.27666">VOW: Verifiable and Oblivious Watermark Detection for Large Language Models</a></p></li></ul></li><li><p>Applied cyber specific</p><ul><li><p><a href="https://mp.weixin.qq.com/s/lRp0ztT95JoY1GZdbm8irg">Building an AI Penetration Testing Agent from Scratch: A Practical Review of the TCH Intelligent Penetration Hackathon</a></p></li><li><p><a href="https://arxiv.org/abs/2604.26118">LLM-Guided Issue Generation from Uncovered Code Segments</a></p></li><li><p><a href="https://arxiv.org/abs/2604.27000">Adaptive and AI-Augmented Security Testing: A Systematic Survey of Program Analysis, Feedback-Driven Testing, and Hybrid Learning-Based Approaches</a></p></li><li><p><a href="https://arxiv.org/abs/2604.24028">Vulnerability Identification by Harnessing Inter-connected Multi-Source Information</a></p></li><li><p><a href="https://arxiv.org/abs/2604.20994">Breaking MCP with Function Hijacking Attacks: Novel Threats for Function Calling and Agentic Models</a></p></li><li><p><a href="https://arxiv.org/abs/2604.26964">Learning-to-Explain through 20Q Gaming: An Explainable Recommender for Cybersecurity Education</a></p></li><li><p><a href="https://arxiv.org/abs/2604.24184">Dynamic Cyber Ranges</a></p></li><li><p><a href="https://arxiv.org/abs/2604.23666">An AI-Based Supervisory Measurement Integrity Validation Layer for Cyber-Resilient AC/DC Protection in Inverter-Based Microgrids</a></p></li><li><p><a href="https://arxiv.org/abs/2604.23446">IndustryAssetEQA: A Neurosymbolic Operational Intelligence System for Embodied Question Answering in Industrial Asset Maintenance</a></p></li><li><p><a href="https://arxiv.org/abs/2604.23332">Advanced Anomaly Detection and Threat Intelligence in Zero Trust IoT Environments Using Machine Learning</a></p></li><li><p><a href="https://arxiv.org/abs/2604.28157">FlashRT: Towards Computationally and Memory Efficient Red-Teaming for Prompt Injection and Knowledge Corruption</a></p></li><li><p><a href="https://arxiv.org/abs/2604.28129">Latent Adversarial Detection: Adaptive Probing of LLM Activations for Multi-Turn Attack Detection</a></p></li><li><p><a href="https://arxiv.org/abs/2604.27714">How Code Representation Shapes False-Positive Dynamics in Cross-Language LLM Vulnerability Detection</a></p></li><li><p><a href="https://arxiv.org/abs/2604.27713">Knowledge Graph Representations for LLM-Based Policy Compliance Reasoning</a></p></li><li><p><a href="https://arxiv.org/abs/2604.27464">Security Attack and Defense Strategies for Autonomous Agent Frameworks: A Layered Review with OpenClaw as a Case Study</a></p></li><li><p><a href="https://arxiv.org/abs/2604.27426">Secret Stealing Attacks on Local LLM Fine-Tuning through Supply-Chain Model Code Backdoors</a></p></li><li><p><a href="https://arxiv.org/abs/2604.27321">Toward Autonomous SOC Operations: End-to-End LLM Framework for Threat Detection, Query Generation, and Resolution in Security Operations</a></p></li><li><p><a href="https://arxiv.org/abs/2604.25846">Towards Agentic Investigation of Security Alerts</a></p></li><li><p><a href="https://arxiv.org/abs/2604.27319">REBENCH: A Procedural, Fair-by-Construction Benchmark for LLMs on Stripped-Binary Types and Names (Extended Version)</a></p></li><li><p><a href="https://arxiv.org/abs/2604.27143">Enhancing Linux Privilege Escalation Attack Capabilities of Local LLM Agents</a></p></li><li><p><a href="https://arxiv.org/abs/2604.27001">An Empirical Security Evaluation of LLM-Generated Cryptographic Rust Code</a></p></li><li><p><a href="https://arxiv.org/abs/2604.26525">PRAG: End-to-End Privacy-Preserving Retrieval-Augmented Generation</a></p></li></ul></li></ul></li><li><p>Books</p><ul><li><p><a href="https://bristoluniversitypress.co.uk/beyond-cybersecurity">Cyber Risk - Managing Uncertainty in a Digital World</a></p></li><li><p><a href="https://www.amazon.co.uk/Anyone-Builds-Everyone-Dies-Superintelligent/dp/1847928927/">If Anyone Builds It, Everyone Dies</a></p></li></ul></li><li><p>Events</p><ul><li><p><a href="https://unidir.org/event/cyber-stability-conference-2026/">Cyber Stability Conference 2026</a> - May 4th and 5th, 2026</p></li><li><p><a href="https://sites.google.com/andrew.cmu.edu/facct2026/home">Workshop on Formal Arguments for CPS Certification FACCT 2026</a> - May 11th, 2026</p></li><li><p><a href="https://adnd.work/">5th Workshop on Active Defense and Deception (AD&amp;D)</a> - <a href="https://adnd.work/"><br></a>September 18th 2026, Rome, Italy</p></li></ul></li></ul><p>Finally finally the <a href="https://creators.spotify.com/pod/profile/national-cyber-security-c6/episodes/The-Ransomware-Ecosystem-e2hi088">NCSC&#8217;s podcast series</a>.</p><div><hr></div><p><em>Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them. </em></p><p><em>This newsletter is subject to the NCSC website terms and conditions which can be found at <a href="https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions">https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions</a> and you can find out more about how will treat your personal information in our privacy notice at <a href="https://www.ncsc.gov.uk/section/about-this-website/privacy-statement">https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.</a></em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CTO at NCSC - Cyber Defence Analysis! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CTO at NCSC Summary: week ending April 26th]]></title><description><![CDATA[Leave passwords in the past - passkeys are the future ...]]></description><link>https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-april-8e7</link><guid isPermaLink="false">https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-april-8e7</guid><dc:creator><![CDATA[Ollie Whitehouse]]></dc:creator><pubDate>Sat, 25 Apr 2026 08:17:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/NEDlOKHG8nY" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to the weekly highlights and analysis of the&nbsp;<a href="https://infosec.pub/c/blueteamsec?dataType=Post&amp;sort=New">blueteamsec</a>&nbsp;(and my wider reading). Not everything makes it in, but the best bits do. A community member is doing <a href="https://briefing.workshop1.net/">daily AI generated podcast of the last 24hours of posts</a>.</p><p>Operationally this week <a href="https://www.ncsc.gov.uk/news/defending-against-china-nexus-covert-networks-of-compromised-devices">Defending against China-nexus covert networks of compromised devices</a> is worth noting.</p><p>In the high-level this week:</p><ul><li><p><a href="https://www.ncsc.gov.uk/news/cyber-chief-uk-faces-perfect-storm-for-cyber-security">Cyber chief: UK faces &#8220;perfect storm&#8221; for cyber security</a> - <strong>Richard Horne</strong> from NCSC UK outlines</p><ul><li><p><em>Technological change and geopolitical tensions present &#8220;tumultuous uncertainty&#8221; requiring culture shift in approach to cyber defence, says head of UK cyber agency</em></p></li><li><p><em>All organisations urged to follow advice to make cyber security part of their mission, as cyberspace sits in state &#8220;between peace and war&#8221;</em></p></li><li><p><em>Threat picture ever more contested, with majority of significant incidents handled by National Cyber Security Centre coming from attackers linked to nation states</em></p></li></ul></li><li><p><a href="https://www.ncsc.gov.uk/blogs/preparing-for-severe-cyber-threat-why-leaders-must-act-now">Preparing for severe cyber threat: why leaders must act now</a> - <strong>NCSC</strong> UK calls to action - <em>&#8220;Severe cyber threat can result in attacks which lead to:</em></p><ul><li><p><em>extended operational downtime, with direct customer impact</em></p></li><li><p><em>significant financial loss</em></p></li><li><p><em>long-term reputational damage</em></p></li><li><p><em>increased risks to public safety and national security&#8221;</em></p></li></ul></li><li><p><a href="https://www.ncsc.gov.uk/blogs/supporting-ai-adoption-for-uk-cyber-defence">Supporting AI adoption for UK cyber defence</a> - <strong>NCSC</strong> UK balances - <em>&#8220;Due to the complexity of these issues, AI-enabled cyber defence cannot be the sole answer to AI-enabled cyber attackers in the near-term, and implementing basic cyber hygiene must remain the priority. But through working together, we can overcome the above challenges and AI can deliver that ultimate improvement to our cyber defence.&#8221;</em></p></li><li><p><a href="https://www.ncsc.gov.uk/news/ncsc-leave-passwords-in-the-past-passkeys-are-the-future">NCSC: Leave passwords in the past - passkeys are the future</a> -<strong> NCSC</strong> UK fire the starting gun on the end of passwords - <em>&#8220;GCHQ&#8217;s National Cyber Security Centre (NCSC) heralds a new era of secure sign in with passkeys now ready for mass adoption</em></p><ul><li><p><em>Passwords are no longer resilient enough for the contemporary world, cyber experts say in new report published on Day Two of CYBERUK conference in Glasgow</em></p></li><li><p><em>Consumers encouraged to migrate to passkeys where possible to unlock simpler and safer digital lifestyle&#8221;</em></p></li><li><p><a href="https://www.ncsc.gov.uk/passkeys">Passkeys: what you need to know</a> - <strong>NCSC</strong> UK explain</p></li><li><p><a href="https://www.ncsc.gov.uk/blogs/passkeys-are-more-secure-than-traditional-ways-to-log-in">Passkeys are more secure than traditional ways to log in</a> - <strong>NCSC </strong>UK explain</p></li><li><p><a href="https://www.bbc.co.uk/news/articles/cq8wnzly5j5o">UK cyber chiefs say it&#8217;s time to ditch passwords for passkeys - what are they?</a> - <strong>BBC </strong>reports</p></li><li><p><a href="https://www.bbc.co.uk/articles/cy41x439kgno">On Friday 24th April, consumer expert Holly Hamilton joined Morning Live to explain the latest security advice on passwords from GCHQ</a> - <strong>BBC</strong> explains</p></li></ul></li><li><p><a href="https://www.ncsc.gov.uk/news/defending-against-china-nexus-covert-networks-of-compromised-devices">Defending against China-nexus covert networks of compromised devices</a> - <strong>NCSC</strong> UK a partners outline - <em>&#8220;Over the past few years there has been a major shift in the tactics, techniques and procedures (TTPs) used by China-nexus cyber actors, moving away from the use of individually procured infrastructure, and towards the use of externally provisioned, large-scale networks of compromised devices.&#8221;</em></p><ul><li><p><a href="https://www.ncsc.gov.uk/news/executive-summary-defending-against-china-nexus-covert-networks-of-compromised-devices">Executive Summary: Defending against China-nexus covert networks of compromised devices</a></p></li><li><p><a href="https://www.ncsc.gov.uk/news/international-cyber-agencies-fresh-advice-defend-against-china-linked-covert-networks">International cyber agencies share fresh advice to defend against China-linked covert networks</a></p></li></ul></li><li><p><a href="https://www.ncsc.gov.uk/blogs/new-cross-domain-guidance-for-government-industry-and-the-wider-security-community">New cross domain guidance for government, industry and the wider security community</a> - <strong>NCSC</strong> UK guides - <em>&#8220;Cross domain technologies play a vital role in helping organisations to move data safely between environments with different security levels. The NCSC know this area can be challenging to navigate, which is why we&#8217;ve produced new guidance on <a href="https://www.ncsc.gov.uk/collection/cross-domain">Cross domain approach and architecture</a>. The guidance makes the adoption of cross domain technologies more straightforward and more secure.&#8221;</em></p></li><li><p><a href="https://www.ncsc.gov.uk/news/world-first-ncsc-engineered-device-secures-vulnerable-display-links">World-first NCSC-engineered device secures vulnerable display links</a> - <strong>NCSC</strong> UK announces - <em>&#8220;SilentGlass, a plug-and-play device, actively blocks any unexpected or malicious HDMI and Display Port connections.&#8221;</em></p></li><li><p><a href="https://hansard.parliament.uk/Lords/2026-04-20/debates/32411FF4-B59C-4D5E-9D8B-CA0B2EF2300B/CivilPreparednessForWar">Civil Preparedness for War</a> - UK <strong>Parliament</strong> debated - <em>&#8220;By common consent, we are already in a war situation, with deniable threats to our critical infrastructure, including arson attacks, digital disruption, other cyber invasions, hybrid attacks and misinformation.&#8221;</em></p></li><li><p><a href="https://www.nextgov.com/cybersecurity/2026/04/cyber-command-carried-out-over-8000-missions-2025-director-says/413035/">[US] Cyber Command carried out over 8,000 missions in 2025, director says</a> - <strong>NextGov</strong> reports - <em>&#8220;The 2025 total is a 25% increase compared to 2024, Rudd added. The figures, which he did not elaborate on, help to underscore how cyber elements are becoming more ingrained into military activities.&#8221;</em></p></li><li><p><a href="https://fallon.house.gov/news/documentsingle.aspx?DocumentID=1649">Implementing a U.S. Cyber Force: A Conversation with Rep. Pat Fallon</a> - <strong>Pat Fallon</strong> outlines - <em>&#8220;The U.S. military has fallen behind our adversaries in our cyber capabilities, and the remedy is clear&#8230;we, as a country, cannot adequately defend our national interests without a Cyber Force. Not only is it a necessity, but a dedicated service for the cyber domain is inevitable.&#8221;</em></p></li><li><p><a href="https://www.kcl.ac.uk/building-nhs-resilience-to-ransomware-1">Building NHS Resilience to Ransomware</a> - <strong>King&#8217;s College London Cyber Security Research Group</strong> think tank - <em>&#8220;The paper proposes a Cyber Leadership Framework centred on Board-level ownership and empowered CIO or CISO leadership. It emphasises the need to connect technical controls with the operational realities of care delivery. It also argues for greater centralisation of core cyber capabilities and shared services to reduce fragmentation and support weaker Trusts in reaching consistent standards.&#8221;</em></p></li><li><p><a href="https://www.rusi.org/explore-our-research/publications/cyber-effects-perspectives/cyber-exercises-and-capture-flag-competitions-uk-policy-tools">Cyber Exercises and Capture the Flag Competitions as UK Policy Tools</a> - <strong>RUSI</strong> think tanks - <em>&#8220;Cyber competitions and exercises are not simply training environments but can also function as strategic infrastructure for developing offensive cyber capability. If the UK wants to sustain its cyber power, it must treat these ecosystems as strategic policy tools and training environments rather than peripheral activities.&#8221;</em></p></li><li><p><a href="https://www.ot.today/new-us-air-force-office-will-focus-on-ot-cybersecurity-a-31431">New US Air Force Office Will Focus on OT Cybersecurity</a> - <strong>OT Today </strong>reports - <em>&#8220;The Air Force is the first, and so far only, American military service to have an office dedicated to OT cybersecurity, blazing a path other services should follow, according to officials and industry observers. But the struggle to get the office set up also demonstrates the bureaucratic and institutional barriers that have to be overcome.&#8221;</em></p></li><li><p>Reporting on/from China</p><ul><li><p><a href="https://www.defensie.nl/documenten/2026/04/21/openbaar-jaarverslag-2025-militaire-inlichtingen--en-veiligheidsdienst">Public Annual Report 2025 Military Intelligence and Security Service</a> - <strong>MIVD</strong> Netherlands publish - <em>&#8220;In 2026, the MIVD expects a further increase in the number of campaigns aimed at exploiting vulnerabilities, including those in edge devices such as routers, firewalls, and VPN solutions. Chinese state actors have access to specialized knowledge regarding Western hardware and software thanks to a diverse and extensive ecosystem of Chinese companies and knowledge institutions that facilitate offensive cyber operations. The Chinese People&#8217;s Liberation Army is also seeking entry points into Western technology. In 2025, the MIVD acknowledged that multiple units within the same unit were even competing to find vulnerabilities in a specific type of edge device.&#8221;</em></p><ul><li><p><a href="https://therecord.media/china-cyber-capabilities-match-us-dutch-intel-says">China&#8217;s cyber capabilities now equal to the US, warns Dutch intelligence</a> - <strong>The Record</strong> reports </p></li></ul></li><li><p><a href="https://www.scmp.com/news/china/science/article/3350174/china-tests-submarine-cable-cutter-3500-metre-depth">China tests submarine cable cutter at 3,500-metre depth</a> - <strong>South China Morning Post</strong> reports  - <em>&#8220;A Chinese deep-sea mission has successfully tested an advanced device capable of cutting through underwater structures such as submarine cable at a depth of thousands of metres.&#8221;</em></p></li><li><p><a href="https://www.foreignaffairs.com/united-states/tech-high-ground-jake-sullivan">The Tech High Ground - What It Will Take to Gain the Advantage Over China</a> - <strong>Jake Sullivan</strong> at <strong>Foreign Affairs</strong> ponders - <em>&#8220;China&#8217;s execution of this sweeping strategy is made possible by its political system. Unlike Washington, Beijing has the centralized authority to direct vast national resources toward national objectives with speed and coordination. State banks, industrial policy, procurement, and regulation all move swiftly in concert. There is no meaningful separation between the military and civilian realms, so civilian technological breakthroughs flow directly into the national security enterprise. And the state is unencumbered by free-market constraints, which means it can mobilize inputs at a staggering scale and subsidize intense competition, in which most recipient firms fail but a few champions emerge that can dominate a global industry. Short-term inefficiency and massive capital misallocation are tolerated in service of long-term gains; there are no voters asking their elected representatives whether their tax dollars could be put to better use.&#8221;</em></p></li><li><p><a href="https://www.caixinglobal.com/2026-04-17/chinese-hospitals-rush-to-launch-brain-computer-interface-wards-102435123.html?rkey=4jojc%2BU9Dvsngy8ZDEibRfFL%2FE7ci4pKD9Sm0jRmLF3MFlIp%2FSaKog%3D%3D">Chinese Hospitals Rush to Launch Brain-Computer Interface Wards</a> - <strong>Caixin Global</strong> reports - <em>&#8220;BCI technology works by establishing a direct communication pathway between the human brain and external devices, bypassing peripheral nerves and muscles. It can capture, decode, and translate the brain&#8217;s neuroelectrophysiological signals, enabling users to control external devices with their thoughts. It can also transmit signals from external devices back into the brain.&#8221;</em></p></li><li><p><strong>AI is not eating up China&#8217;s software market but turbocharging it: HSBC analyst</strong> - <strong>South China Morning Post</strong> reports - <em>&#8220;Unlike the US, China&#8217;s less developed software-as-a-service (SaaS) market stands to gain even as AI models continue to improve, with the most likely outcome being a collaborative approach where model companies and legacy software firms serve enterprises in tandem, said Yiran Liu, head of A-share IT software research at HSBC Qianhai Securities.&#8221;</em></p></li><li><p><a href="https://english.news.cn/20260414/5b2a807212414d68a59b55911bb54427/c.html">Chinese humanoid robots deployed on assembly lines for precision tasks</a> - <strong>XINHUANET</strong> report  - <em>&#8220;At a tablet manufacturing workshop in the eastern Chinese city of Nanchang, four humanoid robots have completed an eight-hour live-streamed shift on a real assembly line requiring precision operations&#8221;</em></p></li></ul></li><li><p> AI</p><ul><li><p><a href="https://www.ncsc.gov.uk/blogs/supporting-ai-adoption-for-uk-cyber-defence">Supporting AI adoption for UK cyber defence</a> - <strong>NCSC</strong> UK outlines - <em>&#8220;Due to the complexity of these issues, AI-enabled cyber defence cannot be the sole answer to AI-enabled cyber attackers in the near-term, and implementing basic cyber hygiene must remain the priority. But through working together, we can overcome the above challenges and AI can deliver that ultimate improvement to our cyber defence.&#8221;</em></p></li><li><p><a href="https://cerre.eu/wp-content/uploads/2026/04/CERRE_Transatlantic-cooperation-on-AI-and-national-security.pdf">Transatlantic Cooperation On AI And National Security</a> - <strong>Atlantic Counter Europe Centre</strong> think tank - <em>&#8220;The links between AI and national security are a key issue for testing the strength of the transatlantic relationship and assessing its prospects. US export controls on AI, while largely targeted at China, have profound implications for Europe&#8217;s ambitions to innovate, increase its competitiveness, and achieve digital sovereignty. Absent more structured cooperation, EU-US AI policy risks drifting into a form of &#8220;managed interdependence,&#8221; characterized by asymmetric leverage and ad hoc bargaining rather than strategic alignment.&#8221;</em></p></li><li><p><a href="https://www.cmorg.org.uk/news/anthropic-mythos-and-other-emerging-frontier-ai-models">Anthropic Mythos and other emerging &#8216;frontier AI&#8217; models</a> - The <strong>Cross Market Operational Resilience Group (CMORG)</strong> assert - &#8220;<em>There was agreement that firms will need to continue to focus on effective practices, including those <strong><a href="https://www.ncsc.gov.uk/blogs/why-cyber-defenders-need-to-be-ready-for-frontier-ai">outlined</a> </strong>by NCSC as the UK National Technical Authority for cyber security. This includes utilising AI capabilities to strengthen cyber defence, for example through ongoing efforts to reduce the attack surface available; improving threat detection and investigation; and further exploration into automating mitigation and response measures. Firms are also encouraged to review recent <strong><a href="https://www.fsisac.com/knowledge/sector-risk-advisory-preparing-the-enterprise-for-ai-enabled-vulnerability-discovery">guidance</a></strong> shared by FS-ISAC to support their preparedness.&#8221;</em></p></li><li><p><a href="https://www.jpmorganchase.com/about/technology/blog/fortifying-the-enterprise-10-actions-to-take-now-for-ai-ready-cyber-resilience">Fortifying the enterprise: 10 actions to take now for AI-ready cyber resilience</a> - <strong>JP Morgan</strong> outline -  <em>&#8220;Treat reducing technical debt as an immediate priority and manage it with senior-level oversight. Given the expected volume of newly discovered vulnerabilities, fixes for legacy systems and software may no longer be made available.&#8221;</em></p></li><li><p><a href="https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/">The zero-days are numbered</a> - <strong>Mozilla</strong> assert the cyber defence benefit - <em>&#8220;Our experience is a hopeful one for teams who shake off the vertigo and get to work. You may need to reprioritize everything else to bring relentless and single-minded focus to the task, but there is light at the end of the tunnel. We are extremely proud of how our team rose to meet this challenge, and others will too. Our work isn&#8217;t finished, but we&#8217;ve turned the corner and can glimpse a future much better than just keeping up. Defenders finally have a chance to win, decisively.&#8221;</em> </p></li><li><p><a href="https://www.nattothoughts.com/p/where-is-china-in-ai-driven-vulnerability">Chinese Firm Claims AI-Driven Bug Discovery Near Claude Mythos Scale</a> - <strong>Eugenio Benincasa</strong> outlines - <em>&#8220;As AI applications in vulnerability research expand, such differences in institutional structure, legal incentives, and business&#8211;state integration are likely to shape how these capabilities translate into real-world advantage. In China&#8217;s case, they may amplify existing dynamics by accelerating vulnerability discovery within already concentrated pipelines and integrated research environments, while also enabling faster adoption by state actors for operational use.&#8221;</em></p></li><li><p><a href="https://b3.lakera.ai/">B<sup>3</sup>: Breaking Agent Backbones</a> - <strong>Lakera AI</strong>, <strong>ETH Zurich</strong>, <strong>UK AI Security Institute</strong> and <strong>OATML, Oxford</strong> publish - <em>&#8220;We apply this framework to construct the B&#179; benchmark, a security benchmark based on 194,331 unique crowdsourced adversarial attacks. We then evaluate 34 popular LLMs with it, revealing, among other insights, that enhanced reasoning capabilities improve security, while model size does not correlate with security.&#8221;</em></p></li><li><p><a href="https://www.anthropic.com/engineering/april-23-postmortem">An update on recent Claude Code quality reports</a> - <strong>Anthropic</strong> publish - <em>&#8220;We traced recent reports of Claude Code quality issues to three separate changes.&#8221;</em> - <em>&#8220;Over the past month, we&#8217;ve been looking into reports that Claude&#8217;s responses have worsened for some users. We&#8217;ve traced these reports to three separate changes that affected Claude Code, the Claude Agent SDK, and Claude Cowork. The API was not impacted.&#8221; </em>- highlights the challenges around determinises and consistency in statistical driven systems</p></li><li><p><a href="https://www.ft.com/content/a92bf04b-bbac-400f-9554-5b1c70957ad4">Months-old start-up Recursive Superintelligence raises $500mn for self-teaching AI </a>- <strong>Financial Times</strong> reports - <em>&#8220;Recursive ultimately hopes to create an AI system that can continuously improve itself without human intervention, according to people familiar with its plans. However, the concept remains at the research stage and has not yet been proven to work over extended periods.&#8221;</em></p></li></ul></li><li><p><em>Cyber proliferation</em></p><ul><li><p><a href="https://www.politico.eu/article/u-k-intelligence-100-nations-have-spyware-that-can-hack-britain/">UK intelligence: 100 nations have spyware that can hack Britain</a> - <strong>Politico</strong> reports - <em>&#8220;More than half of the world's nation states are believed to have purchased technology that could be capable of hacking into Britain's infrastructure, companies and private networks, U.K. intelligence has found.&#8221;</em></p></li></ul></li><li><p>Bounty Hunting</p><ul><li><p><a href="https://www.justice.gov/usao-cdca/pr/british-national-pleads-guilty-hacking-companies-and-stealing-least-8-million-virtual">British National Pleads Guilty to Hacking into Companies and Stealing At Least $8 Million in Virtual Currency</a> - US <strong>Department of Justice</strong> announces - <em>&#8220;A United Kingdom man pleaded guilty today to conspiring with others to hack into the computer systems of at least a dozen companies via text message phishing attacks and to steal at least $8 million in virtual currency from individual victims throughout the United States.</em></p><p><em>Tyler Robert Buchanan, 24, of Dundee, Scotland, pleaded guilty to one count of conspiracy to commit wire fraud and one count of aggravated identity theft.</em></p><p><em>Buchanan has been in federal custody since April 2025.&#8221;</em></p></li><li><p><a href="https://www.justice.gov/opa/pr/florida-man-working-ransomware-negotiator-pleads-guilty-conspiracy-deploy-ransomware-and">Florida Man Working as a Ransomware Negotiator Pleads Guilty to Conspiracy to Deploy Ransomware and Extort U.S. Victims</a> - US <strong>Department of Justice</strong> announces - <em>&#8220;According to court documents, Angelo Martino, 41, of Land O&#8217;Lakes, Florida, collaborated with the operators of the Blackcat/ALPHV (&#8220;BlackCat&#8221;) ransomware variant used by cybercriminals to attack and extort institutions and companies. Beginning in April 2023, Martino abused his role at a U.S.-based cyber incident response company to assist BlackCat actors.&#8221;</em></p></li><li><p><a href="https://www.leparisien.fr/faits-divers/fuite-de-donnees-hexdex-un-hacker-soupconne-de-cyberattaques-massives-interpelle-et-place-en-garde-a-vue-22-04-2026-N6RLLOFNLFHV5HHSFKLX45CYGQ.php">&#8220;Hexdex,&#8221; a 21-year-old hacker suspected of massive cyberattacks, particularly against sports federations, has been arrested.</a> - <strong>le Parisien</strong> reports - <em>&#8220;The case dates back to December 19th. On that day, the cybercrime unit (J3) of the Paris prosecutor's office received around one hundred reports concerning <a href="https://www.leparisien.fr/high-tech/le-ministere-de-leducation-nationale-victime-dune-cyberattaque-les-donnees-personnelles-deleves-derobees-14-04-2026-ZUCD4UOLNBEW3F4HUIPQIDUTSY.php">data exfiltration</a> , notably affecting sports federations, the firearms information system, and e-campus. The leaks were claimed by someone called "Hexdex," who republished the data on the Breachforum and Darkforum websites, platforms specializing in reselling stolen data, the Paris prosecutor's office explained.&#8221;</em></p></li><li><p><a href="https://www.europol.europa.eu/media-press/newsroom/news/europol-supported-global-operation-targets-over-75-000-users-engaged-in-ddos-attacks">Europol-supported global operation targets over 75 000 users engaged in DDoS attacks</a> - <strong>Europol</strong> announce - <em>&#8220;On 13 April 2026, 21 countries joined forces in a coordinated action week that focused on enforcement and prevention measures against over 75 000 criminal users engaging in distributed denial-of-service (DDoS)-for-hire services. With over 75 000 warning emails and letters being sent to identified criminal users and 4 arrests, the action week also led to the takedown of 53 domains and the issuing of 25 search warrants.&#8221;</em></p></li><li><p><a href="https://www.mk.co.kr/en/society/12017618">Encrypt hospital and apartment servers and request coins<br>Kazakh authorities to cooperate to arrest them</a> - South Korea&#8217;s <strong>Maeil Business</strong> reports - <em>&#8220;The organization's responsibility for the ransomware attack by breaking into servers of domestic companies containing a number of personal information, including hospitals and apartment management offices, was arrested in Kazakhstan. This is the first time that police have directly arrested suspects in cooperation with Kazakhstan's investigative agencies.&#8221;</em></p></li></ul></li><li><p>Market Incentives</p><ul><li><p><a href="https://mainichi.jp/english/articles/20260420/p2g/00m/0na/009000c">Over 200 Japanese firms paid ransomware attackers, 60% fail to recover data</a> - <strong>The Mainichi</strong> reports - &#8220;<em>Of companies that paid the attackers, 83 were able to restore their systems and data, while 139 were not. Conversely, 141 firms reported being hit by ransomware attacks but restoring their systems and data without paying.&#8221;</em></p></li><li><p><a href="https://www.caixinglobal.com/2026-04-16/china-imposes-lifetime-accountability-for-officials-investment-decisions-102434454.html?rkey=4jojc%2BU9DvvtuaHc2n7nI%2FFL%2FE7ci4pK4yUjTg6SFmxicK7DqUjyHw%3D%3D">China Imposes Lifetime Accountability for Officials&#8217; Investment Decisions</a> - <strong>Caixin Global</strong> reports - <em>&#8220;For the first time, the central government said officials and directly responsible personnel will face strict lifetime accountability if their investment decisions violate regulations and cause significant losses or severe negative impacts.&#8221;</em></p></li><li><p><a href="https://www.asic.gov.au/about-asic/news-centre/speeches/it-s-tough-being-a-director-but-that-doesn-t-mean-you-shouldn-t-do-it/">It&#8217;s tough being a director (but that doesn&#8217;t mean you shouldn&#8217;t do it)</a> - <strong>Australian Securities &amp; Investments Commission</strong> outline -<em>&#8221;New legislation has meant issues like cybersecurity or poor consumer outcomes are no longer bureaucratic departmental problems, but can be laid directly at the feet of the board.&#8221;</em></p></li><li><p><a href="https://docbox.etsi.org/CYBER/EUSR/Open">EU Cyber Resilience Act vertical standards</a> - <strong>ETSI</strong> publish - <em>&#8220;ETSI CRA vertical standards v1.1.1 are being finalized and undergoing Public Enquiry via the National Standardization Organizations (NSO)&#8221;</em> </p></li></ul></li></ul><p>Reflections this week come from <a href="https://www.cyberuk.uk/">CyberUK</a> and the reimagining cyber security in an AI era. One of the points is around patching. As we move to a world of rapid and repeated patching it is clear that restarting systems and devices is not going to be tenable at the frequency required.</p><p>As such there needs to gear shift by platform and system vendors to introduce secure hot patching mechanisms. It is one of the ways we will be able to balance the availability -vs- security tensions. This will be especially true in the OT and CNI spaces...</p><p>Beyond this the <a href="https://www.youtube.com/playlist?list=PLBQXJX7r5ayNP-c7ILFshGQaxotgLoxYT">CyberUK</a> videos are online, my plenary talk and panel can be seen here:</p><div id="youtube2-5KtD0tY4Ivo" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;5KtD0tY4Ivo&quot;,&quot;startTime&quot;:&quot;255&quot;,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/5KtD0tY4Ivo?start=255&amp;rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Richard&#8217;s keynote is below:</p><div id="youtube2-kPsjBD1TLn8" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;kPsjBD1TLn8&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/kPsjBD1TLn8?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Not getting this via email? Subscribe:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Think someone else would benefit? Share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-april-8e7?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-april-8e7?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p><strong>All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.</strong></p><p>Have a lovely Saturday&#8230;</p><p>Ollie</p><h1>Cyber threat intelligence</h1><p>Who is doing what to whom and how allegedly.</p><h2>Reporting on Russia</h2><h3>Analysis of suspected APT-C-13 (Sandworm) group&#8217;s covert and persistent attack activities using SSH+TOR tunnels</h3><p><strong>360 Threat Intelligence</strong> out of China outline this alleged Russian tradecraft which will be of note to cyber defenders due to the use of Tor and reverse tunnels.</p><blockquote><p>The APT-C-13 group sends ZIP archives containing malicious LNK files via spear-phishing emails. After being tricked into execution, the LNK files recursively search for the decoy archives in the user's configuration file directory and its subfolders, decompressing them multiple times to a specified location. Then, a master script runs, creating two scheduled tasks, SSH and TOR, to construct a complex communication link. The TOR task utilizes the HiddenServicePort feature to map critical local service ports (such as SMB/445 and RDP/3389) on the victim machine to an anonymous Onion domain, allowing attackers to directly connect to the internal network globally through Tor nodes without penetrating inbound firewalls. Simultaneously, the SSH task deploys a lightweight SSH server within the Tor tunnel, using PubkeyAuthentication public key authentication and a custom Subsystem configuration to form a stealthy remote management channel with strong encryption and access control, effectively evading traditional traffic auditing. The entire attack flow is shown below.</p></blockquote><p><a href="https://mp.weixin.qq.com/s/nJpqvXCYV3ZdvNgYGrG4ow">https://mp.weixin.qq.com/s/nJpqvXCYV3ZdvNgYGrG4ow</a></p><h2>Reporting on China</h2><h3>International cyber agencies share fresh advice to defend against China-linked covert networks</h3><p><strong>NCSC</strong> attributes and outlines this operational trade-craft which is linked to China.</p><blockquote><ul><li><p>GCHQ&#8217;s National Cyber Security Centre with UK industry and 15 international partners shine light on best protections against methods used by China-linked threat actors.</p></li><li><p>Covert networks, often made up of compromised devices such as smart devices, are being used to disguise the origins and attributions of cyber attacks.</p></li><li><p>Organisations urged to follow the protective advice outlined in the new advisory launched on Day Two of CYBERUK 2026 conference to combat this risk.</p></li></ul></blockquote><p><a href="https://www.ncsc.gov.uk/news/international-cyber-agencies-fresh-advice-defend-against-china-linked-covert-networks">https://www.ncsc.gov.uk/news/international-cyber-agencies-fresh-advice-defend-against-china-linked-covert-networks</a></p><h3>Same packet, different magic: Mustang Panda hits India&#8217;s banking sector and Korea geopolitics</h3><p><strong>Subhajeet Singha </strong>and<strong> Santiago Pontiroli </strong>detail this alleged Chinese operation which is noteworthy has it shows iterative development, rather rudimentary delivery along with noteworthy sectoral targeting. </p><blockquote><ul><li><p>Acronis Threat Research Unit (TRU) identified a new variant of the <a href="https://www.acronis.com/en/tru/posts/lotuslite-targeted-espionage-leveraging-geopolitical-themes/">LOTUSLITE</a> backdoor with a theme related to India&#8217;s banking sector, delivered via DLL sideloading using a legitimate Microsoft-signed executable.</p></li></ul><ul><li><p>The backdoor communicates with a dynamic DNS-based command-and-control server over HTTPS and supports remote shell access, file operations and session management, indicating a continued espionage-focused capability set rather than financially motivated objectives.</p></li></ul><ul><li><p>Code-level analysis confirms direct lineage to LOTUSLITE, including identical command structures, shared persistence mechanisms, and a residual <strong>KugouMain and multiple other </strong><a href="https://learn.microsoft.com/en-us/cpp/build/exporting-from-a-dll?view=msvc-170">exports</a> carried over from the original codebase, establishing this as an evolved build from the same developer rather than an independent tool.</p></li></ul><ul><li><p>This variant demonstrates incremental improvements over its predecessor, suggesting the developer is actively maintaining and evolving the implant between campaigns.</p></li></ul><ul><li><p>The campaign reflects a shift in delivery tradecraft of Mustang Panda&#8217;s cluster delivering LOTUSLITE, which is moving from CHM-based delivery to JavaScript loaders to DLL sideloading across recent operations, while also pivoting geographically from U.S. government entities to India&#8217;s financial sector.</p></li></ul><ul><li><p>Attribution to Mustang Panda is assessed with moderate confidence based on shared code lineage, residual build artifacts and consistent operational patterns observed across both campaigns.</p></li></ul></blockquote><p><a href="https://www.acronis.com/en/tru/posts/same-packet-different-magic-mustang-panda-hits-indias-banking-sector-and-korea-geopolitics/">https://www.acronis.com/en/tru/posts/same-packet-different-magic-mustang-panda-hits-indias-banking-sector-and-korea-geopolitics/</a></p><h3>GopherWhisper: A burrow full of malware</h3><p><strong>Eric Howard</strong> details this alleged Chinese cluster. Noteworthy for the SaaS C2 usage in attempt to evade detecton.</p><blockquote><ul><li><p>ESET Research uncovered a new China-aligned APT group we&#8217;ve named GopherWhisper that targeted a governmental entity in Mongolia.</p></li><li><p>The group&#8217;s toolset includes custom Go-based backdoors LaxGopher, RatGopher, and BoxOfFriends, the injector JabGopher, the exfiltration tool CompactGopher, the loader FriendDelivery, and the C++ backdoor SSLORDoor.</p></li><li><p>GopherWhisper leverages Discord, Slack, Microsoft 365 Outlook, and file.io for C&amp;C communications and exfiltration.</p></li><li><p>We analyzed C&amp;C traffic from the attacker&#8217;s Slack and Discord channels, gaining information about the group&#8217;s internal operations and post-compromise activities.</p></li></ul></blockquote><p><a href="https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/">https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/</a></p><h3>UAT-4356&#8217;s Targeting of Cisco Firepower Devices</h3><p><strong>Cisco Talos</strong> warn about active targeting of Firepower devices by alleged Chinese threat actors.</p><blockquote><p>Cisco Talos is aware of <a href="https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/">UAT-4356</a>&#8216;s continued <a href="https://cisa.gov/news-events/directives/v1-ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices">active targeting</a> of Cisco Firepower devices&#8217; Firepower eXtensible Operating System (FXOS). UAT-4356 exploited n-day vulnerabilities (<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB">CVE-2025-20333</a> and <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW">CVE-2025-20362</a>) to gain unauthorized access to vulnerable devices, where the threat actor deployed their custom-built backdoor dubbed &#8220;FIRESTARTER.&#8221; FIRESTARTER considerably overlaps with the technical capabilities of <a href="https://www.ncsc.gov.uk/sites/default/files/documents/ncsc-mar-rayinitiator-line-viper.pdf">RayInitiator&#8217;s Stage 3 shellcode</a> that processes incoming XML-based payloads to endpoint APIs.</p><p>In early 2024, Cisco Talos attributed <a href="https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/">ArcaneDoor</a>, a state-sponsored campaign focused on gaining access to network perimeter devices for espionage, to UAT-4356.</p><p>Customers are advised to refer to <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-CISAED25-03">Cisco&#8217;s Security Advisory</a> for mitigation and detection guidance, indicators of compromise (IOCs), affected products, and applicable software upgrade recommendations.</p></blockquote><p><a href="https://blog.talosintelligence.com/uat-4356-firestarter/">https://blog.talosintelligence.com/uat-4356-firestarter/</a></p><p><strong>CISA</strong> and <strong>NCSC</strong> UK FIRESTARTER backdoor report associated </p><blockquote><p>The Cybersecurity and Infrastructure Security Agency (CISA) analyzed a sample of FIRESTARTER malware obtained from a forensic investigation. CISA and the United Kingdom National Cyber Security Centre (NCSC) assess advanced persistent threat (APT) actors are using FIRESTARTER malware for persistence, specifically targeting publicly accessible Cisco Firepower and Secure Firewall devices running Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software. CISA and the NCSC are releasing this Malware Analysis Report to share analysis of one FIRESTARTER malware sample operating as a backdoor and urge organizations to take key response actions.</p></blockquote><p><a href="https://www.cisa.gov/news-events/analysis-reports/ar26-113a">https://www.cisa.gov/news-events/analysis-reports/ar26-113a</a></p><p><a href="https://www.cisa.gov/sites/default/files/2026-04/AR26-113A_MAR_FIRESTARTER_backdoor.pdf">https://www.cisa.gov/sites/default/files/2026-04/AR26-113A_MAR_FIRESTARTER_backdoor.pdf</a></p><h2>Reporting on North Korea</h2><h3>Unmasking DPRK Cyber Threat Actors: Fake IT Worker Infrastructure &amp; Post-Exposure Analysis</h3><p><strong>Eli Woodward</strong> provides some strong indicators to thwart potential North Korean IT workers walking into a job..</p><blockquote><p>Analysis of VPN-related connections to the identified IP revealed a highly concentrated usage pattern:</p><ul><li><p><strong>Astrill VPN</strong>: 37.5%</p></li><li><p><strong>Mullvad</strong>: 32.25%</p></li><li><p><strong>Proton VPN</strong>: 6.25%</p></li></ul></blockquote><p><a href="https://www.team-cymru.com/post/dprk-fake-it-worker-cyber-threat-actors-infrastructure">https://www.team-cymru.com/post/dprk-fake-it-worker-cyber-threat-actors-infrastructure</a></p><h2>Reporting on Iran</h2><p><em>Nothing overly of note this week</em></p><h2>Reporting on Other Actors</h2><h3>StealTok: 130k Users Compromised by Data Stealing TikTok Video &#8220;Downloaders&#8221;</h3><p><strong>Natalie Zargarov</strong> shows you don&#8217;t need AI to compromise 130,000 users.. </p><blockquote><ul><li><p>A single actor operated <strong>12+ extensions</strong> with a shared codebase</p></li><li><p>Over <strong>130K users impacted</strong>, ~12.5K still active</p></li><li><p>Extensions used <strong>remote configuration</strong> to bypass store review</p></li><li><p>Collected <strong>high-entropy fingerprinting data</strong> (including battery status)</p></li><li><p>Many were <strong>featured in official stores</strong>, increasing trust and reach</p></li></ul></blockquote><p><a href="https://layerxsecurity.com/blog/stealtok-130k-users-compromised-by-data-stealing-tiktok-video-downloaders/">https://layerxsecurity.com/blog/stealtok-130k-users-compromised-by-data-stealing-tiktok-video-downloaders/</a></p><h3>TeamPCP strikes again: Xinference PyPI package compromised</h3><p><strong>Shavit Satou</strong> shows that open source supply chains create an attack surface which is demonstrably challenging to defend in 2026 and threat actors know this.</p><blockquote><p>This is the latest hit in an ongoing multi-ecosystem campaign by the threat actor tracked as <strong>TeamPCP</strong>, who have recently compromised PyPI packages including <code>litellm</code> and <code>telnyx</code>, as well as npm, Go, OpenVSX, and GitHub repositories. The same actor marker, payload structure, and targeting profile tie this incident directly to that campaign.</p><p>TeamPCP&#8217;s established pattern on PyPI involves hijacking legitimate packages by injecting a base64-encoded payload into a core module, triggering secret harvesting on import, and exfiltrating the results to attacker-controlled infrastructure. The xinference compromise follows this exact model.</p></blockquote><p><a href="https://research.jfrog.com/post/xinference-compromise/">https://research.jfrog.com/post/xinference-compromise/</a></p><h3>Operation PhantomCLR : Stealth Execution via AppDomain Hijacking and In-Memory .NET Abuse</h3><p><strong>Cyfirma</strong> detail a chain which cyber defence teams will find notable due to the layered nature.</p><blockquote><ul><li><p>AppDomainManager hijacking enables stealth execution within a trusted signed binary, allowing malicious code to run before application logic without modifying the original executable, effectively bypassing code-signing trust controls.</p></li><li><p>Multi-layered sandbox evasion using a 60-second timing gate combined with an 892,007-iteration constrained key derivation loop leveraging SHA-256 transformations to generate AES-128-CBC key candidates ensures that automated analysis environments fail to observe malicious behavior.</p></li><li><p>JIT trampolining technique allows shellcode execution without invoking traditional memory allocation APIs such as VirtualAlloc or WriteProcessMemory, creating a significant detection blind spot for EDR solutions.</p></li><li><p>Command-and-control communication is concealed through Amazon CloudFront CDN domain fronting, significantly complicating network-based detection and blocking without deep packet inspection.</p></li><li><p>Direct syscall usage through NTDLL bypasses userland API monitoring, enabling stealthy execution of critical functions such as memory allocation and protection changes.</p></li><li><p>Reflective DLL loading with per-section memory protections mimics legitimate Windows loader behavior, making injected modules appear indistinguishable from legitimate modules during memory analysis.</p></li><li><p>PEB-based API resolution eliminates dependency on standard Windows API calls, reducing detectable artifacts and enhancing stealth during execution.</p></li><li><p>Heap-walking context recovery mechanism ensures resilience, allowing the malware to recover execution state even after partial failures or memory disruptions.</p></li><li><p>DLL injection storm generates high-volume benign-looking API activity, obscuring malicious behavior within normal system operations and creating noise for security monitoring tools.</p></li><li><p>Memory pressure techniques using large-scale allocations degrade forensic analysis, limiting the effectiveness of memory scanning tools during incident response.</p></li><li><p>Two-phase anti-forensic memory cleanup (NtProtect followed by NtFree) ensures complete removal of in-memory artifacts, significantly hindering post-incident investigation.</p></li><li><p>Modular plugin-based architecture supports dynamic capability extension, indicating a scalable and mature post-exploitation framework suitable for long-term operations.</p></li></ul></blockquote><p><a href="https://www.cyfirma.com/research/operation-phantomclr-stealth-execution-via-appdomain-hijacking-and-in-memory-net-abuse/">https://www.cyfirma.com/research/operation-phantomclr-stealth-execution-via-appdomain-hijacking-and-in-memory-net-abuse/</a></p><h3>Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite</h3><p><strong>JP Glab</strong>, <strong>Tufail Ahmed</strong>, <strong>Josh Kelley</strong> and <strong>Muhammad Umair</strong> detail various bits of tradecraft in this reporting which will be noteworthy to cyber defence teams as it highlights a persistence which was ultimately successful.</p><blockquote><p>[We] identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim&#8217;s environment to achieve deep network penetration.</p><p>As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim to accept a Microsoft Teams chat invitation from an account outside their organization. The UNC6692 campaign demonstrates an interesting evolution in tactics, particularly the use of social engineering, custom malware, and a malicious browser extension, playing on the victim&#8217;s inherent trust in several different enterprise software providers.</p><p>..</p><p>In late December 2025, UNC6692 conducted a large email campaign designed to overwhelm the target with messages, creating a sense of urgency and distraction. Following this, the attacker sent a phishing message via Microsoft Teams, posing as helpdesk personnel offering assistance with the email volume.</p></blockquote><p><a href="https://cloud.google.com/blog/topics/threat-intelligence/unc6692-social-engineering-custom-malware/">https://cloud.google.com/blog/topics/threat-intelligence/unc6692-social-engineering-custom-malware/</a></p><h3>Uncovering Global Telecom Exploitation by Covert Surveillance Actors</h3><p><strong>Gary Miller</strong> and <strong>Swantje Lange </strong>detail the more sophisticated end which will be of note to telecommunications operators. </p><blockquote><p>Our investigation uncovers two sophisticated telecom surveillance campaigns and, for the first time, links real-world attack traffic to mobile operator signalling infrastructure. The findings expose how suspected commercial surveillance vendors (CSVs) exploit the global telecom interconnect ecosystem, leverage private operator networks, and conduct covert location tracking operations that can persist undetected for years.</p></blockquote><p><a href="https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/">https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/</a></p><h3>Fibergrid: Inside the Bulletproof Host for 16,000+ Active Fake Shops</h3><p><strong>Harry Freeborough</strong> highlights this bulletproof hoster misusing some AFRINIC associated IPv4 ranges. </p><blockquote><p>Fibergrid&#8217;s unusually large pool of IPv4 address space is one of the primary foundations of its scale. Much of that space traces back to what is commonly referred to as the Great African IP Address Heist, a scandal uncovered in 2019 when a <em>MyBroadband </em>report alleged that a former AFRINIC executive was involved in improper re-registration of IPv4 addresses to offshore companies by manipulating WHOIS records.</p><p>Today, Fibergrid still controls three of the stolen AFRINIC-issued ranges, representing one million IPv4 addresses, valued at 20-25 million USD.</p></blockquote><p><a href="https://www.netcraft.com/blog/fibergrid-inside-the-bulletproof-host">https://www.netcraft.com/blog/fibergrid-inside-the-bulletproof-host</a></p><h3>SIM Farms as a Service: A Massive Shared Control Plane Operation Spanning 87 Farms</h3><p><strong>Infrawatch</strong> give an indication as the scale of these SIM farms..</p><blockquote><p>We identify 87 physical SIM farms across 17 countries, link downstream proxy providers, and describe the technical capabilities that enable large-scale fraud and abusive automation.</p></blockquote><p><a href="https://infrawatch.com/blog/inside-the-mobile-farm-the-oem-stack-powering-us-4g-5g-proxy-networks#blogpost">https://infrawatch.com/blog/inside-the-mobile-farm-the-oem-stack-powering-us-4g-5g-proxy-networks#blogpost</a></p><h1>Discovery</h1><p>How we find and understand the latent compromises within our environments.</p><h2>Detects potential stack spoofing via ROP gadget in the context of module load events</h2><p><strong>Elastic</strong> release this detection which should inspire detection engineering teams struggling with coverage of ROP.</p><blockquote><p>Detects potential stack spoofing via ROP gadget in the context of module load events. Flags library loads where the call</p><p>stack exhibits patterns associated with return-oriented programming used to alter call stack appearance.</p></blockquote><p><a href="https://github.com/elastic/protections-artifacts/blob/main/behavior/rules/windows/defense_evasion_stack_spoofing_via_rop_gadget_for_dll_load.toml">https://github.com/elastic/protections-artifacts/blob/main/behavior/rules/windows/defense_evasion_stack_spoofing_via_rop_gadget_for_dll_load.toml</a></p><h2>Detection strategies across cloud and identities against infiltrating IT workers</h2><p><strong>Microsoft Defender Security Research Team </strong>and <strong>Microsoft Threat Intelligence </strong>outline an observed campaign along with responsive detection strategies.. </p><blockquote><p>In the observed campaigns, the threat actors leverage routine HR workflows like external-facing career sites with open job postings to help with their job search and application process. Once they&#8217;re successfully contacted, interviewed, and hired, they complete typical new-hire onboarding formalities like setting up payroll accounts, which are also through the HR SaaS platform like Workday.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!r7o7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62ff57d-dc2d-4404-ace5-ac0d687d42b7_1623x634.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!r7o7!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62ff57d-dc2d-4404-ace5-ac0d687d42b7_1623x634.webp 424w, /__u/substackcdn.com/image/fetch/$s_!r7o7!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62ff57d-dc2d-4404-ace5-ac0d687d42b7_1623x634.webp 848w, /__u/substackcdn.com/image/fetch/$s_!r7o7!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62ff57d-dc2d-4404-ace5-ac0d687d42b7_1623x634.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!r7o7!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62ff57d-dc2d-4404-ace5-ac0d687d42b7_1623x634.webp 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!r7o7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62ff57d-dc2d-4404-ace5-ac0d687d42b7_1623x634.webp" width="1456" height="569" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f62ff57d-dc2d-4404-ace5-ac0d687d42b7_1623x634.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:569,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!r7o7!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62ff57d-dc2d-4404-ace5-ac0d687d42b7_1623x634.webp 424w, /__u/substackcdn.com/image/fetch/$s_!r7o7!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62ff57d-dc2d-4404-ace5-ac0d687d42b7_1623x634.webp 848w, /__u/substackcdn.com/image/fetch/$s_!r7o7!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62ff57d-dc2d-4404-ace5-ac0d687d42b7_1623x634.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!r7o7!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62ff57d-dc2d-4404-ace5-ac0d687d42b7_1623x634.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.microsoft.com/en-us/security/blog/2026/04/21/detection-strategies-cloud-identities-against-infiltrating-it-workers/">https://www.microsoft.com/en-us/security/blog/2026/04/21/detection-strategies-cloud-identities-against-infiltrating-it-workers/</a></p><h2>ZettelForge</h2><p><strong>Patrick Roland</strong> applies AI to the cyber threat intelligence challenge..</p><blockquote><p>The only agentic memory system built for cyber threat intelligence.</p><p>When a senior analyst leaves, two or three years of context walks out with them &#8212; customer environments, prior investigations, actor TTPs, false-positive patterns, every hard-won &#8220;wait, we&#8217;ve seen this before.&#8221; ZettelForge is an agentic memory system built so that context stays with the team.</p><p>It extracts CVEs, threat actors, IOCs, and ATT&amp;CK techniques from analyst notes and threat reports, resolves aliases (APT28 = Fancy Bear = STRONTIUM = Sofacy), builds a STIX 2.1 knowledge graph, and serves every past investigation back to your analysts &#8212; and to Claude Code via MCP &#8212; in natural language. Runs entirely in-process. No API keys. No cloud. No data leaves the host.</p></blockquote><p><a href="https://github.com/rolandpg/zettelforge">https://github.com/rolandpg/zettelforge</a></p><h1>Defence</h1><p>How we proactively defend our environments.</p><h2>Working with the automatic enablement of Windows hotpatch security updates</h2><p><strong>Peter van der Woude</strong> shows how to apply in practice.. </p><blockquote><p>This week is all about the recently introduced configuration that will enable Windows hotpatch security updates by default. The configuration to enable the usage of hotpatch security updates has been available since the introduction of Windows 11 version 24H2, and can be configured relatively as shown in <a href="https://petervanderwoude.nl/post/enabling-hotpatch-for-windows-11-enterprise/">this post</a>. Starting with the Windows security update of May 2026, Windows Autopatch will enable hotpatch security updates by default.</p></blockquote><p><a href="https://petervanderwoude.nl/post/working-with-the-automatic-enablement-of-windows-hotpatch-security-updates/">https://petervanderwoude.nl/post/working-with-the-automatic-enablement-of-windows-hotpatch-security-updates/</a></p><h2>What is Microsoft Entra Tenant Governance? (preview)</h2><p><strong>Microsoft</strong> addresses a gap which this capability&#8230;</p><blockquote><p>Microsoft Entra Tenant Governance enables you to get visibility across all your tenants and ensure they are configured to meet your security and compliance requirements. This includes the tenants you administer today, &#8220;shadow IT&#8221; tenants that you don&#8217;t administer but that create risks for your organization, and new tenants that your users create.</p></blockquote><p><a href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/overview">https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/overview</a></p><h2>Configure delegated access with governance relationships for multitenant organizations (preview)</h2><p><strong>Microsoft</strong> release this defence in depth feature to allow security to do what they need without creating an attack path.</p><blockquote><p>By configuring governance relationships for Microsoft Defender, you can assign specific security roles to groups in the governing tenant, allowing them to manage security incidents, alerts, and configurations in the governed tenant without granting full administrative access.</p></blockquote><p><a href="https://learn.microsoft.com/en-us/unified-secops/governance-relationships#assign-permissions-to-log-analytics-workspace">https://learn.microsoft.com/en-us/unified-secops/governance-relationships#assign-permissions-to-log-analytics-workspace</a></p><h2>Engineering secure passkey sync in Microsoft Password Manager</h2><p><strong>Kamaraj Gandhirajan</strong> shows how they approached this from an architectural perspective. </p><blockquote><p>At a high level, passkey syncing in Microsoft Password Manager combines:</p><ul><li><p><strong>Confidential computing</strong> for sensitive passkey operations.</p></li><li><p><strong>Hardware-rooted key protection</strong> for service-side encryption keys.</p></li><li><p><strong>Tamper-evident recovery storage</strong> for secure activation and recovery.</p></li><li><p><strong>Encrypted synchronization</strong> across registered devices.</p></li></ul></blockquote><p><a href="https://blogs.windows.com/msedgedev/2026/04/22/engineering-secure-passkey-sync-in-microsoft-password-manager/">https://blogs.windows.com/msedgedev/2026/04/22/engineering-secure-passkey-sync-in-microsoft-password-manager/</a></p><h2>Cirro</h2><p><strong>Leron Gray</strong> and <strong>George Robbins</strong> bring the graph to cloud attack path discovery.. </p><blockquote><p>Cirro is an extensible security research platform that enables researchers and penetration testers to collect, analyze, and visualize cloud environments and identity relationships through graph databases. Built with a modular architecture, Cirro can be extended to support multiple platforms and data sources.</p><ul><li><p><strong>Multi-platform Data Collection</strong>: Extensible architecture supporting multiple cloud platforms and identity providers</p></li><li><p><strong>Flexible Authentication</strong>: Support for various authentication methods depending on the target platform</p></li><li><p><strong>Cross-platform</strong>: Available for Windows, macOS, and Linux</p></li><li><p><strong>Modular Design</strong>: Optional platform functionality through feature flags and extensible plugin architecture</p></li><li><p><strong>Network Topology Analysis</strong>: Support for network infrastructure platforms like Tailscale</p></li></ul></blockquote><p><a href="https://github.com/bishopfox/cirro">https://github.com/bishopfox/cirro</a></p><h2>Kernel code removals driven by LLM-created security reports</h2><p><strong>Corbet</strong> reports that AI driven vulnerability reports is resulting in unmaintained code being removed from the Linux kernel</p><blockquote><p>There are a number of ongoing efforts to remove kernel code, mostly from the networking subsystem, as an alternative to dealing with the increase in security-bug reports from large language models. The proposed removals include <a href="https://lwn.net/ml/all/20260421-v7-0-0-net-next-driver-removal-v1-v1-0-69517c689d1f@lunn.ch">ISA and PCMCIA Ethernet drivers</a>, a <a href="https://lwn.net/ml/all/20260422044820.485660-1-25181214217@stu.xidian.edu.cn">pair of PCI drivers</a>, the <a href="https://lwn.net/ml/all/20260421021824.1293976-1-kuba@kernel.org">ax25 and amateur radio subsystem</a>, the <a href="https://lwn.net/ml/all/20260421021943.1295109-1-kuba@kernel.org">ATM protocols and drivers</a>, and the <a href="https://lwn.net/ml/all/20260421022108.1299678-1-kuba@kernel.org">ISDN subsystem</a>.</p><blockquote><p>Remove the amateur radio (AX.25, NET/ROM, ROSE) protocol implementation and all associated hamradio device drivers from the kernel tree. This set of protocols has long been a huge bug/syzbot magnet, and since nobody stepped up to help us deal with the influx of the AI-generated bug reports we need to move it out of tree to protect our sanity.</p></blockquote></blockquote><p><a href="https://lwn.net/Articles/1068928/">https://lwn.net/Articles/1068928/</a></p><h1>Incident Writeups &amp; Disclosures</h1><p>How they got in and what they did.</p><h2>P4WNED: How Insecure Defaults in Perforce Expose Source Code Across the Internet</h2><p><strong>Morgan Robertson</strong> shows we don&#8217;t need AI to have massively misconfigured source code infrastructure which can be leveraged. </p><blockquote><p>Focusing specifically on publicly accessible Perforce (&#8220;P4&#8221; aka &#8220;Helix Core&#8221;) instances, this security research reveals critical vulnerabilities stemming primarily from insecure default configurations. An investigation into the security of public Perforce instances identified over 6,100 such instances with alarming security gaps:</p><ul><li><p>72% of servers are configured to allow read-access to internal files</p></li><li><p>21% have an exposed user or configuration that allows read-write access</p></li><li><p>4% have unsecured &#8220;super&#8221; user accounts, enabling complete system compromise via command injection</p></li></ul></blockquote><p><a href="https://morganrobertson.net/p4wned/">https://morganrobertson.net/p4wned/</a></p><p><a href="https://github.com/flyingllama87/p4wned">https://github.com/flyingllama87/p4wned</a></p><h1>Vulnerability</h1><p>Our attack surface.</p><h2>Apple Silicon Vulnerability Research &#8212; A18 Pro (MacBook Neo)</h2><p><strong>David Maynor</strong> Applies AI and finds vulnerabilities..</p><blockquote><p>Systematic security research targeting Apple's A18 Pro chip (MacBook Neo / Mac17,5) &#8212; the first A-series SoC shipped in a Mac laptop. The MacBook Neo is used as an authorized Apple Security Research Device (SRD) and doubles as a high-visibility proxy for iPhone 16 Pro research, since A18 Pro is identical silicon across both product lines.</p><p>..</p><ul><li><p><strong>47 confirmed vulnerabilities</strong> across kernel, drivers, coprocessors, and userspace services</p></li><li><p><strong>Severity distribution:</strong> 5 CRITICAL, 8 HIGH (from current confirmed set)</p></li><li><p><strong>6 formal security reports</strong> prepared for Apple Security Research (4 submitted; 2 pending submission)</p></li><li><p><strong>88 custom tool directories</strong> in <code>tools/custom/</code> (<strong>73 registered</strong> in <code>tools/registry/TOOL_REGISTRY.md</code>)</p></li><li><p><strong>729+ completed research tasks</strong> across 36+ phases and post-phase verification iterations</p></li><li><p><strong>Cross-platform coverage</strong>: 42 kexts shared between macOS and iOS (17% of total), enabling Mac-developed primitives to be assessed for iPhone applicability</p></li></ul></blockquote><p><a href="https://github.com/dmaynor/apple-vuln-research">https://github.com/dmaynor/apple-vuln-research</a></p><h2>Vulpine</h2><p><strong>Thomas Dullien</strong> <strong>(Halvar Flake)</strong> also applies AI to find vulnerabilities. </p><blockquote><p>A multi-agent vulnerability-development pipeline. Feed it a repository URL and (optionally) a commit hash; the agents build the target, model its attack surface, fuzz each feature, audit every function on the hot path, look for security flaws, and attempt to chain the best bugs into an exploit.</p><p>Vulpine ships with dual-platform agent definitions so the same pipeline runs on Claude Code and on OpenCode, letting you benchmark different backend models (open and closed) on the same vulndev workflow.</p></blockquote><p><a href="https://github.com/thomasdullien/vulpine">https://github.com/thomasdullien/vulpine</a></p><h2>All Your Reverse Engineering Tools Are Belong to US</h2><p><strong>Calif</strong> apply AI to find vulnerabilities in reverse engineering tools which cyber defence teams will want to be aware of.. </p><blockquote><p>Ghidra, radare2, IDA Pro, and Binary Ninja Sidekick. If your tool doesn&#8217;t show up here, it&#8217;s not cool enough. Contact us for a free RCE.</p></blockquote><p><a href="https://blog.calif.io/p/mad-bugs-all-your-reverse-engineering">blog.calif.io/p/mad-bugs-all-your-reverse-engineering</a></p><h2>TotalRecall Reloaded</h2><p><strong>Alex Hagenah</strong> unpicks Total Recall.. </p><blockquote><p><code>AIXHost.exe</code>, the process that renders the Recall timeline, has no PPL, no AppContainer, no code integrity enforcement. Any process running as the logged-in user can inject code into it and call the same COM APIs the legitimate UI uses. Once the user authenticates with Windows Hello, decrypted screenshots, OCR text, and metadata flow through <code>AIXHost.exe</code> as live COM objects. TotalRecall Reloaded sits inside that process and extracts everything.</p><p>No admin required. Standard user. No kernel exploit. No crypto bypass. Just COM calls.</p></blockquote><p><a href="https://github.com/xaitax/TotalRecall">https://github.com/xaitax/TotalRecall</a></p><h1>Offense</h1><p>Attack capability, techniques and trade-craft. </p><h2>SmokedMeat</h2><p><strong>Fran&#231;ois Proulx</strong>, <strong>Giacomo Benedetti</strong> and <strong>S&#233;bastien Graveline</strong> provide a capability to help defensive teams get match fit when protecting CI/CD pipelines.. </p><blockquote><p>SmokedMeat exists because CI/CD pipeline threats are deeply underestimated. Traditional security training rarely covers supply chain attacks, leaving defenders unprepared for techniques that adversaries actively exploit in the wild.</p><p>We built this to give security teams the ability to learn, practice, and validate defenses against advanced CI/CD attack techniques through realistic red team exercises.</p></blockquote><p><a href="https://github.com/boostsecurityio/smokedmeat">https://github.com/boostsecurityio/smokedmeat</a></p><h2>DSCourier</h2><p><strong>Dylan Davis</strong> &amp; <strong>Matthew Schramm</strong> show how EDR can still be circumvented in 2026..</p><blockquote><p>DSCourier is a proof-of-concept that uses the WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries. A separate blog post provides the full technical deep dive into the technique.</p><p>DSCourier was built primarily from a research topic and should be viewed as a proof-of-concept rather than a polished or complete tool. Much of its value comes from operators modifying, extending, and experimenting with it themselves, including creating their own configuration files.</p><p>This technique has has bypassed CrowdStrike Falcon, Microsoft Defender for Endpoint (MDE) and Elastic Security EDR</p></blockquote><p><a href="https://github.com/DylanDavis1/DSCourier">https://github.com/DylanDavis1/DSCourier</a></p><p><a href="https://eclipsesec.com/posts/DSCourier/">https://eclipsesec.com/posts/DSCourier/</a></p><h2>Analysis of RedSun: Local Privilege Escalation via Defender Remediation Abuse</h2><p><strong>Cristian Rubio</strong> provides an analysis of a capability previously covered here..</p><blockquote><p>RedSun is a Local Privilege Escalation (LPE) vulnerability that abuses the interaction between Windows Defender, the Windows Cloud Files API (cfapi), and NTFS Reparse Points to achieve an arbitrary file overwrite. By exploiting a Time-of-Check to Time-of-Use (TOCTOU) race condition, an attacker can force the highly privileged antivirus service to overwrite critical system binaries, ultimately leading to NT AUTHORITY\SYSTEM privileges.</p></blockquote><p><a href="https://www.coresecurity.com/blog/analysis-redsun-local-privilege-escalation-defender-remediation-abuse">https://www.coresecurity.com/blog/analysis-redsun-local-privilege-escalation-defender-remediation-abuse</a></p><h2>ExportHider</h2><p><strong>Furkan G&#246;ksel</strong> releases a capability cyber defence teams, model trainers and automation pipeline owners will want to be aware of.</p><blockquote><p>ExportHider generates a C++ DLL template which contains a code stub that allows you to hide Exported Functions from the Export Directory of the DLL on the filesystem. After putting the function definitions and compiling the file, you won't see the hidden export functions through PE File Viewers like CFF Explorer. However, since the code stub in the template recreates the Export Directory during runtime, legitimate GetProcAddress calls would be executed successfully. This method only works for Dynamic DLL loading or custom DLL loader cases.</p></blockquote><p><a href="https://github.com/frkngksl/ExportHider">https://github.com/frkngksl/ExportHider</a></p><h2>ToastFix Demo</h2><p><strong>Liam Halpy</strong> shows how it can work..</p><blockquote><p>This project demonstrates how convincing Windows toast notifications can be abused in social engineering attacks, specifically using ClickFix-style lures.</p></blockquote><p><a href="https://github.com/h4lpy/toastfix-demo">https://github.com/h4lpy/toastfix-demo</a></p><h3>Bad Apples: Weaponizing native macOS primitives for movement and execution</h3><p><strong>William Charles Gibson</strong> and <strong>Ryan Conry</strong> walk through how the primitives can be misused and thus the need to detect.. </p><blockquote><ul><li><p>As macOS adoption grows among developers and DevOps, it has become a high value target; however, native &#8220;living-off-the-land&#8221; (LOTL) techniques for the platform remain significantly under-documented compared to Windows.</p></li><li><p>Adversaries can bypass security controls by repurposing native features like Remote Application Scripting (RAS) for remote execution and abusing Spotlight metadata (Finder comments) to stage payloads in a way that evades static file analysis.</p></li><li><p>Attackers can move toolkits and establish persistence using built-in protocols such as SMB, Netcat, Git, TFTP, and SNMP operating entirely outside the visibility of standard SSH-based telemetry.</p></li><li><p>Defenders should shift from static file scanning to monitoring process lineage, inter-process communication (IPC) anomalies, and enforcing strict MDM policies to disable unnecessary administrative services.</p></li></ul></blockquote><p><a href="https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/">https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/</a></p><h1>Exploitation</h1><p>What is being exploited..</p><h3>UAT-4356&#8217;s Targeting of Cisco Firepower Devices</h3><p><strong>Cisco Talos</strong> warn about active targeting of Firepower devices by alleged Chinese threat actors.</p><blockquote><p>Cisco Talos is aware of <a href="https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/">UAT-4356</a>&#8216;s continued <a href="https://cisa.gov/news-events/directives/v1-ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices">active targeting</a> of Cisco Firepower devices&#8217; Firepower eXtensible Operating System (FXOS). UAT-4356 exploited n-day vulnerabilities (<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB">CVE-2025-20333</a> and <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW">CVE-2025-20362</a>) to gain unauthorized access to vulnerable devices, where the threat actor deployed their custom-built backdoor dubbed &#8220;FIRESTARTER.&#8221; FIRESTARTER considerably overlaps with the technical capabilities of <a href="https://www.ncsc.gov.uk/sites/default/files/documents/ncsc-mar-rayinitiator-line-viper.pdf">RayInitiator&#8217;s Stage 3 shellcode</a> that processes incoming XML-based payloads to endpoint APIs.</p><p>In early 2024, Cisco Talos attributed <a href="https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/">ArcaneDoor</a>, a state-sponsored campaign focused on gaining access to network perimeter devices for espionage, to UAT-4356.</p><p>Customers are advised to refer to <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-CISAED25-03">Cisco&#8217;s Security Advisory</a> for mitigation and detection guidance, indicators of compromise (IOCs), affected products, and applicable software upgrade recommendations.</p></blockquote><p><a href="https://blog.talosintelligence.com/uat-4356-firestarter/">https://blog.talosintelligence.com/uat-4356-firestarter/</a></p><h1>Tooling and Techniques</h1><p>Low level tooling and techniques for attack and defence researchers</p><h2>The Cost of Understanding: LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation</h2><p><strong>Cyril Fran&#231;ois</strong>,<strong> Daniel Stepanic </strong>and <strong>Jia Yu Chan </strong>bring some qualitative measurement.. </p><blockquote><ul><li><p>LLMs have rapidly reshaped the software industry, making complex topics such as reverse engineering more accessible, including the ability to defeat various levels of obfuscation</p></li><li><p>Heavy obfuscation dramatically inflates computational cost and time, disrupting automated analysis pipelines</p></li><li><p>Effective LLM-targeting static analysis countermeasures are cheap and fast to develop</p></li><li><p>Successful LLM defenses exploit context windows, budget caps, and shortcut biases</p></li></ul></blockquote><p><a href="https://www.elastic.co/security-labs/llm-reversing-vs-llm-obfuscation">https://www.elastic.co/security-labs/llm-reversing-vs-llm-obfuscation</a></p><h2>Project Cluster</h2><p><strong>Wenxiang Qian</strong>, <strong>Zhixin Tu</strong> and <strong>Bin Li</strong> release this.. </p><blockquote><p>An unsupervised project clustering tool</p><p>..</p><p>This project is a part of BlackHat Asia 2026 presentation: No Time to Patch: Faster Detection and Counteraction of N-day Exploits in Chromium-based Apps</p></blockquote><p><a href="https://github.com/toolbay/project-cluster">https://github.com/toolbay/project-cluster</a></p><p>The slides from the presentation </p><p><a href="https://i.blackhat.com/Asia-26/Presentations/BHAS26-Wenxiang-Qian.pdf?_gl=1*1tna2t6*_gcl_au*MTM5MzU3ODc5MC4xNzc3MTA0MTA1*_ga*NzY1OTE4NTI4LjE3NzcxMDQxMDU.*_ga_K4JK67TFYV*czE3NzcxMDQxMDUkbzEkZzEkdDE3NzcxMDQxNDckajYwJGwwJGgw">https://i.blackhat.com/Asia-26/Presentations/BHAS26-Wenxiang-Qian.pdf?_gl=1*1tna2t6*_gcl_au*MTM5MzU3ODc5MC4xNzc3MTA0MTA1*_ga*NzY1OTE4NTI4LjE3NzcxMDQxMDU.*_ga_K4JK67TFYV*czE3NzcxMDQxMDUkbzEkZzEkdDE3NzcxMDQxNDckajYwJGwwJGgw</a></p><h1>Footnotes</h1><p>Some other small (and not so small) bits and bobs which might be of interest.</p><ul><li><p>Annual, quarterly and monthly reports</p><ul><li><p><em>Nothing overly of note this week, but keep an eye on</em> <a href="https://github.com/jacobdjwilson/awesome-annual-security-reports/tree/main/Annual%20Security%20Reports/2026">the Awesome Annual Security Reports 2026 collection</a></p></li></ul></li><li><p><a href="https://shostack.org/blog/roi-of-threat-modeling/">Measuring the ROI of threat modeling: moving from activity to impact</a></p></li><li><p><a href="https://www.nist.gov/news-events/news/2024/10/nist-announces-14-candidates-advance-second-round-additional-digital">NIST Announces 14 Candidates to Advance to the Second Round of the Additional Digital Signatures for the Post-Quantum Cryptography Standardization Process</a></p></li><li><p><a href="https://blog.trailofbits.com/2026/04/17/we-beat-googles-zero-knowledge-proof-of-quantum-cryptanalysis/">We beat Google&#8217;s zero-knowledge proof of quantum cryptanalysis</a></p></li><li><p><a href="https://semgrep.dev/blog/2026/needles-and-haystacks-can-open-source-flagship-models-do-what-mythos-did/">Needles and haystacks: Can open-source &amp; flagship models do what Mythos did?</a></p></li><li><p>Artificial intelligence</p><ul><li><p>Fundamental</p><ul><li><p><a href="https://ai.meta.com/static-resource/Meta_Advanced-AI-Scaling-Framework-v2">Advanced AI Scaling Framework</a></p></li><li><p><a href="https://arxiv.org/abs/2604.09258">Nexus: Same Pretraining Loss, Better Downstream Generalization via Common Minima</a></p></li><li><p><a href="https://arxiv.org/abs/2603.29791">Reasoning-Driven Synthetic Data Generation and Evaluation</a></p></li><li><p><a href="https://arxiv.org/abs/2604.15039v1">Prefill-as-a-Service: KVCache of Next-Generation Models Could Go Cross-Datacenter</a></p></li><li><p><a href="https://moyangli00.github.io/droid-w/">DROID-SLAM in the Wild</a></p></li></ul></li><li><p>Applied non-cyber</p><ul><li><p><a href="https://github.com/rui-ye/OpenSeeker">OpenSeeker: Democratizing Frontier Search Agents by Fully Open-Sourcing Training Data</a></p></li><li><p><a href="https://github.com/Hihixiaolv/PhysGM">PhysGM: Large Physical Gaussian Model for Feed-Forward 4D Synthesis</a></p></li><li><p><a href="https://www.academia.edu/165538364/Cognitive_Resilience_and_Automation_Bias_in_AI_Augmented_Military_Cyber_Operations_and_Intelligence_Analysis">Cognitive Resilience and Automation Bias in AI-Augmented Military Cyber Operations and Intelligence Analysis</a></p></li><li><p><a href="https://github.com/berabuddies/agentflow">AgentFlow: Orchestrate thousands of agents and harnesses as a graph programatically</a></p></li></ul></li><li><p>Applied cyber specific</p><ul><li><p><a href="https://trustedsec.com/blog/benchmarking-self-hosted-llms-for-offensive-security">Benchmarking Self-Hosted LLMs for Offensive Security</a></p></li><li><p><a href="https://arxiv.org/abs/2604.20801">Synthesizing Multi-Agent Harnesses for Vulnerability Discovery</a></p></li><li><p><a href="https://github.com/kpolley/redai">redai: AI-driven vulnerability discovery and live validation</a></p></li><li><p><a href="https://github.com/dmaynor/apple-vuln-research">The Cost of Understanding: LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation</a></p></li><li><p><a href="https://github.com/rolandpg/zettelforge">ZettelForge: The only agentic memory system built for cyber threat intelligence.</a></p></li><li><p><a href="https://github.com/FIND-Lab/AgentWard">AgentWard &#8211; Built for all, hardened for OpenClaw.</a></p></li><li><p><a href="https://github.com/toolbay/project-cluster">An unsupervised project clustering tool</a> - <em>This project is a part of BlackHat Asia 2026 presentation: No Time to Patch: Faster Detection and Counteraction of N-day Exploits in Chromium-based Apps</em></p></li><li><p><a href="https://b3.lakera.ai/">B<sup>3</sup>: Breaking Agent Backbones - A security benchmark measuring how backbone LLM choice affects AI agent resilience against adversarial attacks, built on 194,331 unique crowdsourced attacks from real human red-teamers.</a></p></li></ul></li></ul></li><li><p>Books</p><ul><li><p><a href="https://www.philvenables.com/post/maintenance-of-everything-a-review">Maintenance of Everything : A Review</a></p></li></ul></li><li><p>Events</p><ul><li><p><a href="https://www.youtube.com/playlist?list=PLBQXJX7r5ayNP-c7ILFshGQaxotgLoxYT">CyberUK</a> videos are online</p></li><li><p><a href="https://blackhat.com/asia-26/briefings/schedule/?">Blackhat Asia 2026</a> slides/papers are online</p></li></ul></li></ul><p>Finally video of the week is:</p><div id="youtube2-NEDlOKHG8nY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;NEDlOKHG8nY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/NEDlOKHG8nY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Finally finally the <a href="https://creators.spotify.com/pod/profile/national-cyber-security-c6/episodes/The-Ransomware-Ecosystem-e2hi088">NCSC&#8217;s podcast series</a>.</p><div><hr></div><p><em>Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them. </em></p><p><em>This newsletter is subject to the NCSC website terms and conditions which can be found at <a href="https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions">https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions</a> and you can find out more about how will treat your personal information in our privacy notice at <a href="https://www.ncsc.gov.uk/section/about-this-website/privacy-statement">https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.</a></em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CTO at NCSC - Cyber Defence Analysis! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CTO at NCSC Summary: week ending April 19th.]]></title><description><![CDATA[As AI accelerates vulnerability discovery, organisations must raise their security baselines to safeguard their cyber security.]]></description><link>https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-april-6f7</link><guid isPermaLink="false">https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-april-6f7</guid><dc:creator><![CDATA[Ollie Whitehouse]]></dc:creator><pubDate>Sat, 18 Apr 2026 06:38:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!4mvO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887b732e-c40d-4e2a-a529-8bf1aa18c028_1600x898.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to the weekly highlights and analysis of the&nbsp;<a href="https://infosec.pub/c/blueteamsec?dataType=Post&amp;sort=New">blueteamsec</a>&nbsp;(and my wider reading). Not everything makes it in, but the best bits do. A community member is doing <a href="https://briefing.workshop1.net/">daily AI generated podcast of the last 24hours of posts</a>.</p><p>Operationally this week nothing overly of note but you will see from the reporting below that normal in 2026 is quite the place to be.. </p><p>In the high-level this week:</p><ul><li><p><a href="https://www.ncsc.gov.uk/blogs/retaining-defensive-advantage-in-the-age-of-frontier-ai-cyber-capabilities">Retaining defensive advantage in the age of frontier AI cyber capabilities</a> - <strong>NCSC UK</strong>&#8217;s CEO Richard Horne&#8217;s open letter which was originally in The Times on April 15th</p></li><li><p><a href="https://www.gov.uk/government/publications/ai-cyber-threats-open-letter-to-business-leaders">AI cyber threats: open letter to business leaders</a> - <strong>Department for Science, Innovation and Technology</strong>, <strong>Cabinet Office</strong>, <strong>The Rt Hon Liz Kendall MP</strong> and <strong>Dan Jarvis MBE MP </strong>write - <em>&#8220;More broadly, the National Cyber Security Centre, part of GCHQ, is world-leading in defending the UK online, and continues to publish practical guidance every business can use. The Cyber Security and Resilience Bill, which is currently progressing through Parliament, will strengthen protections for critical services &#8211; from the NHS to the energy system &#8211; that we all rely on, and shortly we will publish the National Cyber Action Plan setting out the steps this government will take to ensure the UK&#8217;s national security against cyber threats.&#8221;</em></p></li><li><p><a href="https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities">Our evaluation of Claude Mythos Preview&#8217;s cyber capabilities</a> - <strong>AI Security Institute</strong> publish - Important nuance here - <em>&#8220;Mythos Preview&#8217;s success on one cyber range indicates that it is at least capable of autonomously attacking small, weakly defended and vulnerable enterprise systems where access to a network has been gained. However, our ranges have important differences from real-world environments that make them easier targets. They lack security features that are often present, such as active defenders and defensive tooling. There are also no penalties for the model for undertaking actions that would trigger security alerts. This means we cannot say for sure whether Mythos Preview would be able to attack well-defended systems.&#8221;</em> - and-  <em>&#8220;Mythos Preview did also show some cyber capability limitations within the limits of our evaluation. It could not complete our operational technology focused cyber range &#8216;Cooling Tower&#8217;, though this result does not necessarily show that the model is bad at executing attacks in operational technology (OT) environments; the model got stuck on IT sections of this range.&#8221;</em> </p></li><li><p><a href="https://lawcom.gov.uk/project/product-liability/">Reviewing the law relating to liability for defective products</a> - <strong>Law Commission</strong> announces - <em>&#8220;This project considers the operation of the existing product liability regime, particularly in relation to digital products and emerging technologies such as AI, to determine what law reform might be required to ensure that the product liability regime is fit for purpose. In doing so, it seeks to help businesses manage their risks of liability for harm caused by defective products by providing greater legal certainty in the digital age. The review will also help determine whether the regime is successfully balancing the competing interests of providing consumers with a straightforward route to claiming compensation for harm caused by defective products on the one hand, whilst balancing support for business on the other. If necessary, reforms will be proposed to correct that balance.&#8221;</em></p></li><li><p><a href="https://www.gov.uk/government/news/uk-considers-ban-on-owning-signal-jamming-devices-used-by-car-thieves-and-shoplifters">UK considers ban on owning signal jamming devices used by car thieves and  -shoplifters</a> - <strong>Department for Science, Innovation and Technology</strong> and <strong>Baroness Lloyd of Effra CBE </strong>announce</p><ul><li><p><a href="https://www.gov.uk/government/calls-for-evidence/possession-of-radiofrequency-jammers-and-the-relevant-legal-framework">Possession of radiofrequency jammers and the relevant legal framework</a> - <strong>Department for Science, Innovation and Technology</strong> calls for evidence</p></li></ul></li><li><p><a href="https://www.gov.uk/government/news/next-generation-empowered-through-technical-excellence-colleges">Next generation empowered through Technical Excellence Colleges</a> - <strong>Department for Education</strong>, <strong>Ministry of Defence</strong>, <strong>Department for Business and Trade</strong>, <strong>Department for Science, Innovation and Technology</strong> and <strong>The Rt Hon Baroness Smith of Malvern </strong>announce - <em>&#8220;Backed by &#163;175 million of government funding, 19 new Technical Excellence Colleges across the country will deliver high-quality training in the sectors driving Britain&#8217;s growth - advanced manufacturing, clean energy and defence, as well as digital and technologies.&#8221; - </em>I have always been a fan of the South Korean Meister school model and this seems to be our version.. </p></li><li><p><a href="https://apply-for-innovation-funding.service.gov.uk/competition/2426/overview/4766704a-4888-49f8-b4f3-1e370e9ee0c5">Contracts for Innovation: Enabling Commercial Quantum Networking</a> - <strong>Innovate UK, part of UK Research and Innovation (UKRI)</strong> announce  - <em>&#8220;will invest up to &#163;20 million.. The aim of the competition is to accelerate the development of enabling components and sub-systems for quantum networks. These will be in the supply chain of a system integrator or service provider, for deployment in a future commercial quantum networking system.&#8221;</em></p></li><li><p><a href="https://aria.org.uk/opportunity-spaces/scalable-neural-interfaces/massively-scalable-neurotechnologies/">Massively Scalable Neurotechnologies funding</a> - <strong>ARIA</strong> announce - <em>&#8220;We are developing a new class of brain surgery-free neurotechnologies that reach and interact with the central nervous system via the body&#8217;s natural pathways. Our ambition is a responsive system that can monitor and modulate brain activity systemically or with minimal intervention, deployable in under 30 minutes.&#8221;</em> </p></li><li><p><a href="https://uksemicentre.org.uk/news/uk-semiconductor-centre-launches-london-hq-to-support-rapid-sector-growth">UK Semiconductor Centre launches London HQ to support rapid sector growth</a> - <strong>UK Semiconductor Centre</strong> announces - <em>&#8220;The UKSC was established to connect, convene and promote the UK&#8217;s semiconductor industry on the global stage, ensuring innovation translates into scaled commercial success and economic growth.&#8221;</em></p></li><li><p><a href="https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth">NIST Updates NVD Operations to Address Record CVE Growth</a> - <strong>NIST</strong> outline - <em>&#8220;We are working faster than ever. We enriched nearly 42,000 CVEs in 2025 &#8212; 45% more than any prior year. But this increased productivity is not enough to keep up with growing submissions. Therefore, we are instituting a new approach. The changes described below will allow us to focus on the most critical CVEs while being transparent about how we are managing our current workload. They will also allow us to stabilize the program while we develop the automated systems and workflow enhancements required for long-term sustainability.&#8221;</em></p></li><li><p><a href="https://abcnews.com/US/addicted-hacking-young-hacker-historic-breach-speaks-1st/story?id=131855776">&#8216;Addicted to hacking&#8217;: Young hacker behind historic breach speaks out for 1st time, before reporting to prison</a> - <strong>ABC News</strong> covers - <em>"I couldn't stop," he said of his cyber crimes. "I was addicted to hacking."</em> .. <em>&#8220;During Lane's sentencing hearing in November, the judge issued a stark warning about young people: "If we put the computer in their room, the phone in their hand, it's like a gun," U.S. District Court Judge Margaret Guzman said.&#8221;</em></p></li><li><p><a href="https://www.lse.ac.uk/school-of-public-policy/news/cybersecurity-regulation-is-fragmenting-the-global-economy-lse-and-sciences-po-call-for-urgent-reform">Cybersecurity regulation is fragmenting the global economy </a>- <strong>LSE</strong> and <strong>Sciences Po</strong> think thank (supported by Microsoft who have very real business interest in this) - <em>&#8220;The paper calls on governments, regulators, and the OECD to treat regulatory defragmentation as a growth and security priority in 2026.&#8221;</em></p></li><li><p><a href="https://www.acn.gov.it/portale/documents/d/guest/detacn_misuresicurezza-v4_post">Determinazione del Direttore Generale dell&#8217;Agenzia per la cybersicurezza nazionale </a>- <strong>Italian government</strong> publishes - for the new NIS 2026 entities, the obligation to notify significant incidents starts from 1 January 2027 and the same entities will have to adopt the basic safety measures by 31 July 2027. </p></li><li><p><a href="https://www.fcc.gov/document/fcc-selects-new-lead-administrator-us-cyber-trust-mark-program">FCC Selects New Lead Administrator for U.S. Cyber Trust Mark Program</a> - US <strong>Federal Communications Commission</strong> announces - <em>&#8220;announced the selection of ioXt Alliance (ioXt) to serve as the new Lead Administrator of its U.S. Cyber Trust Mark Program, a voluntary cybersecurity labeling program for consumer wireless Internet of Things (IoT) products.  This program, overseen by the FCC&#8217;s Public Safety and Homeland Security Bureau, builds on significant public and private sector work on IoT cybersecurity. &#8220;</em></p></li><li><p><a href="https://www.yomiuri.co.jp/politics/20260412-GYT1T00063/">Local governments face a shortage of cybersecurity personnel; the national government will lead training programs for staff to prepare for increasingly sophisticated attacks and to address regional disparities</a>. - <strong>Yomiuri</strong> reports (Japan) - <em>&#8220;The Ministry of Internal Affairs and Communications has decided to conduct cybersecurity training for local government officials for the first time this fall. With cyberattacks becoming more sophisticated and complex, there is a shortage of specialized personnel in local governments to handle countermeasures, and the ministry intends to promote preparedness by having the national government take the lead in training them.&#8221;</em></p></li><li><p><a href="https://eucyberdirect.eu/blog/the-risk-of-making-offensive-cyber-the-new-shiny-silver-bullet">The Risk of Making Offensive Cyber the New Shiny Silver Bullet </a>- <strong>EU Cyber Direct</strong> think tanks - <em>&#8220;The second challenge in making offensive cyber a silver bullet to enable the next phase of European cyber deterrence is that it fails to acknowledge the varying levels of maturity and capacity across Europe. Developing and sustaining offensive cyber capabilities requires not only technical talent but also persistent access, intelligence infrastructure, targeting expertise, and the institutional arrangements to coordinate across agencies. These are capabilities that even well-resourced states struggle to scale. The spectrum of capacity across Europe is wide &#8211; from smaller states with limited resources to middle powers like Czechia that have developed considerable capabilities but still operate at a different scale from France, the Netherlands or Germany.&#8221;</em></p></li><li><p><a href="https://www.europarl.europa.eu/thinktank/en/document/EPRS_BRI(2026)785704">Understanding the dark web</a> - <strong>European Parliamentary Research Service</strong> publish - <em>&#8220;The virtual, online world is a significant part of everyday life. As a reflection of modern society, it features a range of criminal behaviour. The internet is a complex system of interconnected computer networks allowing applications to communicate with one another. Through this complexity, it has a simplistic structure with a visible top layer, a deeper content layer and finally, a small but significant dark layer.&#8221;</em></p></li><li><p><a href="https://smallwarsjournal.com/2026/04/15/gru-lessons-for-digital-force-protection/">Operational Exposure in the Age of Attribution: GRU Lessons for Digital Force Protection</a> - <strong>Small Wars Journal</strong> publishes - <em>&#8220;Building on previous signature reduction pieces, this article examines digital force protection as the operational expression of signature reduction doctrine under ubiquitous technical surveillance (UTS). Using the failed GRU intrusion against the Organization for the Prohibition of Chemical Weapons as a case study, it highlights how adversary tradecraft exposes persistent vulnerabilities across digital vectors. The article argues that counteroffensive digital force protection preserves SOF freedom of maneuver, reduces attribution risk, and extends survivability by shaping digital observability before and during deployment.&#8221;</em></p></li><li><p>Reporting on/from China</p><ul><li><p><a href="https://taiwanfellowship.ncl.edu.tw/files/scholar_publish/2472-mttmnryccnhyjpk.pdf">Taiwan's Resilience in the Face of China&#8217;s Cyber Challenge</a> - <strong>Institute for National Defense and Security Research</strong> publish - <em>&#8220;In terms of resilience Germany can learn a lot from Taiwan and especially when it comes to establishing deterrence by punishment in the context of subsea cable cutting.&#8221;</em></p></li><li><p><a href="https://thehill.com/policy/defense/5833125-quectel-fibocom-market-dominance/">Cellular modules from Chinese companies in smart home devices are national security risk</a> - <strong>The Hill </strong>reports - <em>&#8220;A new report is warning that Chinese-produced cellular modules, tiny components that are inside smart home devices, present a significant national security risk for the United States.&#8221;</em> &#8230; <em>&#8220;Ports, hospitals, power grids, cranes and transportation networks rely on cellular modules. Theoretically, these modules can shut down their host devices and also collect large amounts of data since their manufacturers maintain remote access to provide firmware and software updates, the report said.&#8221;</em> -  this lobby group is working both sides of the Atlantic they are funded to do so and often the technical arguments confused. For example traffic emanating from the device should be encrypted (VPN etc.) and it is unclear how you shut down host devices from a model unless extremely poorly architected. </p></li><li><p><a href="https://www.caixinglobal.com/2026-04-16/china-unveils-national-aieducation-plan-to-transform-classrooms-by-2030-102434567.html">China Unveils National &#8216;AI+Education&#8217; Plan to Transform Classrooms by 2030</a> - <strong>Caixin Global</strong> reports <em>&#8220;The &#8220;AI+ Education&#8221; Action Plan, jointly issued by the Ministry of Education and four other government bodies on April 8, outlines a blueprint to deeply embed AI across all levels of learning, from primary schools to lifelong education. By 2030, the government aims to largely establish a vertically and horizontally connected AI education system. &#8220;</em></p><ul><li><p><a href="https://english.www.gov.cn/news/202604/15/content_WS69df29e6c6d00ca5f9a0a6b1.html">China aims to build an AI literacy system</a> - <strong>Chinese Government</strong> press release</p></li><li><p><a href="http://www.moe.gov.cn/fbh/live/2026/77927/">Introducing the relevant information about the "Artificial Intelligence + Education" Action Plan</a> - <strong>Ministry of Education</strong> press conference</p></li><li><p><a href="http://www.moe.gov.cn/srcsite/A16/s3342/202604/t20260410_1433240.html">Notice from the Ministry of Education and four other departments on Issuing the &#8220;Action Plan for &#8216;Artificial Intelligence + Education&#8217;&#8221;</a> - <strong>Ministry of Education </strong>publishes </p></li></ul></li><li><p><a href="https://www.fcc.gov/document/fcc-announces-routers-uas-conditional-approvals">FCC Announces Routers, UAS Conditional Approvals</a> - US <strong>Federal Communications Commission</strong> exempts - <em>&#8220;The Executive Branch interagency bodies established a process in which entities producing UAS and UAS critical components and routers in foreign countries can request DoW or DHS to evaluate whether such devices do not pose unacceptable risks to national security and receive Conditional Approvals that would exempt such devices from the Covered List.  <br>DoW has reviewed submissions and granted Conditional Approvals, for the following devices:  </em></p><ul><li><p><em>Sees.ai v.USA. 1.0 Uncrewed Aircraft System (terminating December 31, 2026)</em></p></li><li><p><em>Netgear, Inc.&#8217;s Nighthawk consumer mesh, mobile and standalone routers (R, RAX, RAXE, RS, MK, MR, M and MH series), Orbi consumer mesh, mobile and standalone routers (RBK, RBE, RBR, RBRE, LBR, LBK and CBK series), cable gateways (CAX series) and cable modems (CM series) (terminating October 1, 2027)</em></p></li><li><p><em>Adtran Inc.&#8217;s  Service Delivery Gateway (SDG) class routers (terminating October 1, 2027)&#8221;</em></p></li></ul></li><li><p><a href="http://www.moe.gov.cn/fbh/live/2026/77927/">Notice from the General Office of the Ministry of Education on Implementing<br>the Action Plan for the Transformation and Utilization of University Patents</a> - <strong>Ministry of Education</strong> publishes - <em>&#8220;In order to thoroughly implement the "Outline of the Plan for Building a Strong Education Nation (2024-2035)," comprehensively enhance the patent transformation and application capabilities of universities, and enable more scientific and technological achievements to be transformed into real productive forces as soon as possible, it has been decided to implement an action plan to accelerate the transformation and application of university patents&#8221;</em></p></li><li><p><a href="https://www.scmp.com/news/china/science/article/3350208/china-doubles-ai-science-computing-scale-2-months-using-no-us-chips">China doubles &#8216;AI for science&#8217; computing scale in 2 months using no US chips</a> - <strong>South China Morning Post</strong> reports - &#8220;<em>The AI acceleration cards were produced by Chinese supercomputer developer Sugon, which is affiliated with the Chinese Academy of Sciences, and are running in the core node of the national supercomputing network in Zhengzhou, Henan province. The number of chips in the computing node reached 60,000 units, up from 30,000 when trial operations began in early February.&#8221;</em></p></li><li><p><a href="https://www.caixinglobal.com/2026-04-17/chinese-ai-robotics-startup-tars-raises-455-million-in-record-pre-a-round-102434873.html">Chinese AI Robotics Startup TARS Raises $455 Million in Record Pre-A Round </a>- <strong>Caixin Global</strong> reports - &#8220;<em>Chinese humanoid robotics startup TARS said it has raised $455 million in a pre-A funding round, setting a new record for the largest single-round financing in the country&#8217;s humanoid robotics sector.</em></p><p><em>The round was co-led by GL Ventures, HongShan, and Meituan, with participation from state-backed funds, including the Beijing Robotics Industry Development Investment Fund. This capital injection underscores strong investor interest in the startup, which was founded in February 2025 by a team of former autonomous driving executives.&#8221;</em></p></li></ul></li><li><p> AI</p><ul><li><p><a href="https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities">Our evaluation of Claude Mythos Preview&#8217;s cyber capabilities</a> - <strong>AI Security Institute</strong> publish - Important nuance here - <em>&#8220;Mythos Preview&#8217;s success on one cyber range indicates that it is at least capable of autonomously attacking small, weakly defended and vulnerable enterprise systems where access to a network has been gained. However, our ranges have important differences from real-world environments that make them easier targets. They lack security features that are often present, such as active defenders and defensive tooling. There are also no penalties for the model for undertaking actions that would trigger security alerts. This means we cannot say for sure whether Mythos Preview would be able to attack well-defended systems.&#8221;</em> - and-  <em>&#8220;Mythos Preview did also show some cyber capability limitations within the limits of our evaluation. It could not complete our operational technology focused cyber range &#8216;Cooling Tower&#8217;, though this result does not necessarily show that the model is bad at executing attacks in operational technology (OT) environments; the model got stuck on IT sections of this range.&#8221;</em> </p></li><li><p><a href="https://sushegaad.github.io/Claude-Skills-Governance-Risk-and-Compliance/">Claude Skills for GRC &#8212; Governance, Risk &amp; Compliance</a> - <strong>Hemant Naik</strong> publishes - <em>&#8220;Turns Claude into an expert ISO 27001 Lead Auditor and ISMS implementation consultant. Covers both ISO 27001:2013 (114 controls, 14 domains) and ISO 27001:2022 (93 controls, 4 themes), defaulting to 2022.</em>&#8221; - first they came for the consultants&#8230; </p></li><li><p><a href="https://github.com/lugasia/3gpp-skill">3GPP Expert Skill for Claude</a> - <strong>Amir Lugasi </strong> publishes - <em>&#8220;A comprehensive 3GPP telecommunications skill that turns Claude into a senior telecom consultant &#8212; covering everything from GSM (1992) through 6G (Release 21).&#8221;</em></p></li><li><p><a href="https://www.linkedin.com/posts/ugcPost-7450516833775898627-MXvG?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAAfftoBoCtIQI5U_WcHzyjmFClHruttui4">Penetration testing costs and speed Synopsis: Comprehensive Security Audit Comparison</a> - <strong>Eoin Keary </strong> does back of the napkin maths - <em>&#8220;Human review is required for Mythos to filter false positives (~17% rate) and verify high-severity exploits like CVE-2025-24813.&#8221;</em></p></li><li><p><a href="https://semgrep.dev/blog/2026/needles-and-haystacks-can-open-source-flagship-models-do-what-mythos-did/">Needles and haystacks: Can open-source &amp; flagship models do what Mythos did?</a> - <strong>Kurt Boberg</strong> experiments - <em>&#8220;We show that none of three flagship or two open-source models find two of the vulnerabilities discussed in the Mythos blog post, without extremely revealing hints. Discovery is orders of magnitude harder than verification; this is why undergraduates don&#8217;t get titles and PhDs do. Gleaning conclusions from the unknown-unknown is a lot harder than reproducing and verifying someone else&#8217;s original work. Both are valorous (and necessary!) pursuits, but reproduction and verification is much easier for computers.&#8221;</em></p></li><li><p><a href="https://blog.vidocsecurity.com/blog/we-reproduced-anthropics-mythos-findings-with-public-models">We Reproduced Anthropic&#8217;s Mythos Findings With Public Models</a> - <strong>Vidoc Security Labs</strong> publishes - &#8220;<em>The useful lesson is that many enterprise security teams already sit on more hidden issues than their current workflows can realistically discover, validate, and prioritize. ..  From our perspective, that means a few things should change now:</em></p><ol><li><p><em>Stop treating frontier model access as the moat. The harder problem is building the workflow that makes discovery useful.</em></p></li><li><p><em>At the same time, this is not a point-and-shoot problem. Models like Mythos are not a complete solution on their own. To use these models effectively, teams need infrastructure around them for detection, validation, and prioritization. That is why external AI security tools matter.</em></p></li><li><p><em>AppSec teams should revisit old assumptions about which bugs are &#8220;too hard&#8221; to matter.</em></p></li><li><p><em>Discovery should focus on trust boundaries, authentication flows, parsers, shared services, and legacy code that still sits on critical paths.</em></p></li><li><p><em>Public models are already good enough to shorten the gap between code review, bug discovery, and exploit refinement.&#8221;</em></p></li></ol></li><li><p><a href="https://vincenzoiozzo.com/blog/alphago-moment-vuln-research">Tracking CVEs Attributed to Anthropic Researchers and Project Glasswing</a> - <strong>Patrick Garrity</strong> does data analysis and quantification - &#8220;</p><ul><li><p><em>75 CVEs mention &#8220;Anthropic&#8221;</em></p></li><li><p><em>40 are actually credited to Anthropic researchers</em></p></li><li><p><em>Only 1 is explicitly attributed to Glasswing</em></p></li><li><p><em>10 are from external collaboration programs (Calif.io / MADBugs)</em></p></li></ul><p><em>Taken together, this suggests that while Anthropic researchers are actively contributing to vulnerability discovery and appears to be promising, the publicly attributable impact of Glasswing itself remains limited so far.&#8221;</em></p></li><li><p><a href="https://www.leavesongs.com/PENETRATION/try-code-security.html">First Experience with Codex Security Code Auditing</a> - <strong>Phithon</strong> detail their experience - &#8220;<em>The first five are all clear code-related false alarms. The sixth is a false alarm caused by a lack of understanding of the product. The seventh and eighth are &#8220;best practice&#8221; type issues, which I can also consider as unusable issues. This suggests that Codex Security still needs improvement in its code auditing capabilities.&#8221;</em></p></li><li><p><a href="https://vincenzoiozzo.com/blog/alphago-moment-vuln-research">The AlphaGo moment for vulnerability research?</a> - <strong>Vincenzo Iozzo</strong> experiments - &#8220;<em>My impression from this experiment is that Opus is still primarily pattern-matching rather than reasoning when finding bugs and as such what we are seeing in terms of output/volume of bugs is not dissimilar from a novel fuzzer being deployed in the wild vs a step change in bug finding capabilities.&#8221;</em></p></li><li><p><a href="https://openai.com/index/scaling-trusted-access-for-cyber-defense/">Trusted access for the next era of cyber defense</a> - <strong>OpenAI</strong> outline - &#8220;<em>Our cybersecurity defenses are the result of many months of iterative improvement. We believe the class of safeguards in use today sufficiently reduce cyber risk enough to support broad deployment of current models. We expect versions of these safeguards to be sufficient for upcoming more powerful models, while models explicitly trained and made more permissive for cybersecurity work require more restrictive deployments and appropriate controls.&#8221;</em></p></li><li><p><a href="https://labs.cloudsecurityalliance.org/mythos-ciso/">The &#8220;AI Vulnerability Storm&#8221;: Building a &#8220;Mythos-ready&#8221; Security Program</a> - <strong>Cloud Security Alliance</strong> publish - this will be a legitimate leap for many organisations to pull off given current state.</p></li><li><p><a href="https://stratcomcoe.org/publications/understanding-llm-performance-gaps-strategic-implications-of-stance-detection-and-sentiment-analysis-in-small-languages/341">Understanding LLM Performance Gaps: Strategic Implications of Stance Detection and Sentiment Analysis in Small Languages </a>- <strong>NATO Strategic Comminations Centre of Excellence</strong> empirically proves - &#8220;<em>the current report evaluates LLM performance in stance detection and sentiment analysis across English, Lithuanian, and Russian, focusing on politically sensitive topics, and tests whether techniques like fine-tuning and retrieval-augmented generation can improve results. The findings confirm persistent performance gaps, with lower accuracy in less-resourced languages, but also demonstrate that targeted model adaptations can significantly improve outcomes, sometimes allowing smaller fine-tuned models to outperform larger systems.&#8221;</em></p></li></ul></li><li><p>Quantum (also a new standing footnotes section)</p><ul><li><p><a href="https://www.thetimes.com/business/technology/article/lloyds-bank-quantum-computers-financial-crime-7h5g0jgsg">Lloyds Bank uses quantum computing to detect money mules</a> - <strong>The Times</strong> reports - <em>&#8220;Lloyds&#8217; research was conducted over a nine-month period, bringing together a group of &#8220;quantum ambassadors&#8221; from across the business.&#8221;</em> .. <em>&#8220;The bank tested whether quantum algorithms could spot money mule behaviour within a large collection of transactions, a task that traditional computers tend to struggle with due to the complexity of detecting subtle patterns within large-scale transaction data.&#8221; - </em>as these experiments are run it will be important we quantify the performance gains against classical. </p></li></ul></li><li><p>Cyber proliferation</p><ul><li><p><a href="https://www.jamf.com/blog/predator-spyware-ios-kernel-exploitation-engine/">Inside Predator&#8217;s kernel engine</a> - Jamf detail - the inner workings of the low level capability Predator developed to support privilege escalation - <em>&#8220;The exploit chain analyzed in this post targets iOS versions prior to 17 and devices through the A16 generation. Apple's introduction of SPTM (Secure Page Table Monitor) in A15 devices, which moves page table management to EL2, represents a significant architectural mitigation against the kernel code modification techniques described here.&#8221;</em></p></li></ul></li><li><p>Bounty Hunting</p><ul><li><p><a href="https://www.psni.police.uk/latest-news/detectives-arrest-16-year-old-suspicion-offences-under-computer-misuse-act">Detectives arrest 16-year-old on suspicion of offences under Computer Misuse Act</a> - <strong>Police Service Northern Ireland</strong> announces - <em>&#8220;The arrest forms part of an ongoing investigation into a report received on Thursday 2 April of network intrusion activity involving the Education Authority.&#8221;</em></p></li><li><p><a href="https://www.justice.gov/opa/pr/two-us-nationals-sentenced-facilitating-fraudulent-remote-information-technology-worker">Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Scheme that Generated $5M in Revenue for the Democratic People&#8217;s Republic of Korea</a> - US <strong>Department of Justice</strong> announce - <em>&#8220;The Justice Department today announced the sentencings of two U.S. nationals, Kejia Wang, 42, and Zhenxing Wang, 39, for their roles in facilitating North Korean remote information technology (IT) workers posing as U.S. residents to obtain work at more than 100 U.S. companies. The multi-year scheme used the stolen identities of at least 80 U.S. persons and generated more than $5 million in illicit revenue for the government of the Democratic People&#8217;s Republic of Korea (DPRK).&#8221;</em></p></li><li><p><a href="https://www.ilfoglio.it/esteri/2026/04/16/news/xu-zewei-dovra-essere-estradato-dice-la-cassazione-ora-pero-sta-al-governo-decidere--276675">Xu Zewei must be extradited, the Supreme Court says. Now, however, it&#8217;s up to the government to decide</a> - <strong>Il Foglio</strong> reports - &#8220;Yesterday, the Court of Cassation rejected the defense's appeal in the case of Xu Zewei, the Chinese citizen arrested in Malpensa in July 2025 at the request of the United States, upholding the extradition approval already granted by the Milan Court of Appeal in January.&#8221; .. <em>&#8220;The indictment alleges that Xu participated, along with other individuals, in hacking campaigns against foreign targets, with the aim of acquiring sensitive data and intellectual property.&#8221; </em></p></li><li><p><a href="https://www.fbi.gov/contact-us/field-offices/atlanta/news/fbi-atlanta-indonesian-authorities-take-down-global-phishing-network-behind-millions-in-fraud-attempts">FBI Atlanta, Indonesian Authorities Take Down Global Phishing Network Behind Millions in Fraud Attempts</a> - <strong>FBI a</strong>nnounces - &#8220;<em>In a first-of-its-kind joint cyber investigation, the FBI Atlanta Field Office and Indonesian law enforcement authorities have dismantled a sophisticated global phishing operation that enabled cybercriminals to steal thousands of victims&#8217; account credentials and attempt more than $20 million in fraud.&#8221;</em></p></li><li><p><a href="https://commsrisk.com/kazakhstan-becomes-first-cis-country-to-arrest-sms-blaster-gang/">Kazakhstan Becomes First CIS Country to Arrest SMS Blaster Gang</a> - <strong>CommsRisk</strong> reports - <em>&#8220;The agency&#8217;s press release stated that the SMS blaster had an effective range of 300 meters and was able to send 100,000 messages per hour. It had been carried in motor vehicles that circled near shopping and entertainment facilities, though no specific details were given about where the device was found and where it had been used.&#8221;</em></p></li></ul></li><li><p>Market Incentives</p><ul><li><p><a href="https://www.osborneclarke.com/insights/uk-product-liability-law-commission-reviews-consumer-protection-act-1987">UK product liability: the Law Commission reviews the Consumer Protection Act 1987</a> - <strong>Osborne Clarke</strong> summarises &#8220;Software developers and technology businesses face potential exposure to product liability claims under reforms being considered by the Law Commission&#8221;</p></li><li><p><a href="https://revera.legal/en/info-centr/news-and-analytical-materials/2126-otvetstvennost-za-narushenie-trebovanij-po-kiberbezopasnosti-kakie-izmeneniya-/">Liability for Violations of Cybersecurity Requirements: What Changes Are Expected in the Legislation? </a>- <strong>Revera Legal</strong> summaries - <em>&#8220;On 15 April 2026, the President of the Republic of Belarus signed the Law &#8220;On Amendments to the Codes on Administrative Liability&#8221;. Among other changes, the Law introduces liability for violations of cybersecurity requirements.&#8220;</em> - <em>&#8220;Failure to comply with the applicable requirements in this area may result not only in administrative, criminal or other liability, but also in financial and reputational losses.&#8221;</em></p></li><li><p><a href="https://www.frontiersin.org/journals/human-dynamics/articles/10.3389/fhumd.2026.1790473/full">Civil liability and cyber insurance for electronic bank account hacking under Jordanian law: a doctrinal and comparative analysis</a> - <strong>Faculty of Law, Zarqa University</strong> and <strong>Law School, Amman Arab University</strong> analyses - <em>&#8220;The findings reveal that Jordanian law relies primarily on general fault-based liability principles under the Civil Code and Commercial Code, without establishing a specific legal regime for unauthorized electronic transactions. This approach imposes a substantial evidentiary burden on customers, despite banks' superior technical control over digital payment systems. In contrast, comparative legal systems increasingly adopt risk-based or hybrid liability models that favor consumer protection and institutional responsibility&#8221;</em></p></li></ul></li></ul><p>Reflections are we have spent quite a lot of time this week answering questions on if organisations should use AI to do [something] in cyber security. </p><p>My responses to these have broadly followed a structure of..</p><p>.. where the organisation is mature and the fundamentals are in place and working well then yes as it will be an additive scaler.</p><p>.. but if fundamentals are not in place or not working well it may be due to lack of resource. In these situations investing in these fundamentals are a pre-condition and thus should be a focus first.</p><p>AI has an important place in contemporary cyber security -  but importantly it is not today a replacement for the fundamentals.</p><p>Not getting this via email? Subscribe:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/subscribe"><span>Subscribe now</span></a></p><p>Think someone else would benefit? Share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-april-6f7?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-april-6f7?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share</span></a></p><p><strong>All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.</strong></p><p>Have a lovely Saturday&#8230;</p><p>Ollie</p><h1>Cyber threat intelligence</h1><p>Who is doing what to whom and how allegedly.</p><h2>Reporting on Russia</h2><h3>Exclusive: Russia-linked hackers compromised scores of Ukrainian prosecutors&#8217; email accounts, data shows</h3><p><strong>Reuters</strong> reports this week on something we covered four weeks ago (<a href="/__u/ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-march-1bf">week ending March 22nd</a>) around an alleged Russian campaign, this is the high-level reporting.</p><blockquote><p>Russia-linked hackers broke into more than 170 email accounts belonging to prosecutors and investigators across Ukraine during the last several &#8203;months, according to data reviewed by Reuters, a campaign that shows how Moscow&#8217;s spies are keeping tabs on the Ukrainian officials tasked with rooting out corruption and Russian &#8204;collaborators.</p></blockquote><p><a href="https://www.reuters.com/world/russia-linked-hackers-compromised-scores-ukrainian-prosecutors-email-accounts-2026-04-15/">https://www.reuters.com/world/russia-linked-hackers-compromised-scores-ukrainian-prosecutors-email-accounts-2026-04-15/</a></p><p>This is the original intelligence:</p><p><a href="https://ctrlaltintel.com/research/FancyBear/">https://ctrlaltintel.com/research/FancyBear/</a></p><h3>Minister: Swedish heating plant targeted by pro-Russian cyberattack</h3><p><strong>Energy Watch</strong> reports on Sweden&#8217;s attribution of this alleged Russian operation which is noteworthy due to the OT targeting.</p><blockquote><p>In the spring of 2025, a Swedish power plant was targeted by a cyberattack from a pro-Russian activist group, according to Sweden&#8217;s Minister of Civil Defense, Carl-Oskar Bohlin.</p><p>The perpetrator is believed to have ties to Russian intelligence services.</p><p>&#8220;The [Swedish] Security Service has handled the case and identified the perpetrator behind it. Fortunately, there were no serious consequences since the power plant had a built-in security system,&#8221; Bohlin said at a press conference on Wednesday.</p><p>Sweden&#8217;s neighboring countries, Norway and Denmark, have been hit by similar incidents, according to Bohlin. Poland has also been subjected to a similar attack, but on a significantly larger scale, reports <a href="https://www.svt.se/nyheter/inrikes/regeringen-om-cyberhotet-mot-sverige">SVT</a>.</p><p>Swedish authorities say the assualt reflects a shift in Russia&#8217;s tactics and differs from typical cyberattacks, which have previously taken the form of denial-of-service attempts.</p><p>This latest incident involved an attack on a so-called operational system that, in turn, controls critical infrastructure in society. If such systems are taken offline or remotely controlled by a hostile actor, the damage to society could be significant, Bohlin asserts:</p></blockquote><p><a href="https://energywatch.com/EnergyNews/grid/article19202558.ece">https://energywatch.com/EnergyNews/grid/article19202558.ece</a></p><h3>Hospitals, local governments, and FPV operators are in the focus of the UAC-0247 cyber threat cluster</h3><p><strong>CERT Ukraine</strong> detail this alleged Russian campaign which is noteworthy for its victimology.. </p><blockquote><p>During March-April 2026, CERT-UA recorded an intensification of cyberattacks against local governments and, primarily, municipal healthcare institutions, in particular clinical hospitals and emergency (ambulance) hospitals.</p><p style="text-align: justify;">The initial interaction with the cyberattack target is carried out via email under the guise of discussing a proposal for providing humanitarian aid, during which the attacker suggests clicking on a link. To reinforce the legend, a website of a fake organization can be developed (using artificial intelligence) or a third-party script can be downloaded from a legitimate web resource that is vulnerable to XSS (Cross-Site Scripting).</p></blockquote><p><a href="https://cert.gov.ua/article/6288271">https://cert.gov.ua/article/6288271</a></p><h3>Exposing Russian Malicious Infrastructure: 1,250+ C2 Servers Mapped Across 165 Providers</h3><p><strong>Hunt.io</strong> give a sense of how Mos Eisley some hosting providers are..</p><blockquote><ul><li><p>More than 1,250 C2 servers were identified across 165 Russian infrastructure providers within the past 3 months.</p></li><li><p>C2 infrastructure dominates malicious activity (~88.6%), far exceeding phishing infrastructure (~4.9%), while malicious open directories (~5.3%) and publicly reported IOCs (~1.2%) represent a much smaller portion of observed artifacts.</p></li><li><p>A small set of hosting providers accounts for a disproportionate share of malicious infrastructure, with TimeWeb, WebHost1, REG.RU, VDSina, and PROSPERO OOO hosting the largest volumes of detected C2 servers.</p></li><li><p>A small set of malware families (Keitaro, Hajime, Tactical RMM, Cobalt Strike, Sliver, and Ligolo-ng) showing framework-driven, repeatable abuse.</p></li><li><p>IoT-focused botnets (Hajime, Mozi, and Mirai) remain present within Russian infrastructure, reflecting ongoing abuse of compromised embedded devices and routers.</p></li><li><p>Russian hosting environments support diverse malicious operations, including phishing campaigns, infostealer distribution, scanning infrastructure, and targeted intrusion activity.</p></li></ul><p>&#8230;</p><p>This research shows the malicious activity in Russian hosting environments is heavily concentrated, with over 1,250 C2 servers spread across 165 providers, with TimeWeb, REG.RU, WebHost1, VDSina, and PROSPERO OOO hosting the majority of high-risk infrastructure, highlighting persistent reuse by threat actors.</p></blockquote><p><a href="https://hunt.io/blog/russian-malicious-infrastructure-c2-servers-mapped">https://hunt.io/blog/russian-malicious-infrastructure-c2-servers-mapped</a></p><h2>Reporting on China</h2><h3>APT41 Winnti ELF Cloud Credential Harvester: Alibaba Typosquat Infrastructure &amp; 6-Year Lineage</h3><p><strong>Breakglass Intelligence</strong> provides reporting on this alleged Chinese operation which is noteworthy due to some of the tradecraft on show..</p><blockquote><p>A zero-detection ELF backdoor attributed to APT41 (Winnti) has been identified targeting Linux cloud workloads across AWS, GCP, Azure, and Alibaba Cloud environments. The implant uses SMTP port 25 as a covert command-and-control channel, harvests cloud provider credentials and metadata, and phones home to three Alibaba-themed typosquat domains hosted on Alibaba Cloud infrastructure in Singapore. A selective C2 handshake validation mechanism renders the server invisible to conventional scanning tools like Shodan and Censys.</p></blockquote><p><a href="https://intel.breakglass.tech/post/apt41-winnti-elf-cloud-credential-harvester-alibaba-typosquat">https://intel.breakglass.tech/post/apt41-winnti-elf-cloud-credential-harvester-alibaba-typosquat</a></p><h2>Reporting on North Korea</h2><h3>PolinRider: DPRK Threat Actor Implants Malware in Hundreds of GitHub Repos</h3><p><strong>Open Source Malware</strong> detail this alleged North Korean operation which is noteworthy for the scale they are operating. Also important as they are doing so without using any AI and/or vulnerabilities and thus providing a sobering and important reminder of the crocodile which is actually eating the canoe. </p><blockquote><p>This attack has been enormously successful, with one compromised open source project, Neutralinojs spreading the malware to hundreds of its users and contributors. Neutralinojs is a very popular project with 8400 stars, 495 forks, and dozens of active contributors. This is the power of this type of attack, as the threat isn't limited to just the initial GitHub repositories, but extends to all the other projects that use that open source.</p></blockquote><p><a href="https://github.com/OpenSourceMalware/PolinRider">https://github.com/OpenSourceMalware/PolinRider</a></p><h3>APT37&#8217;s Pretexting-Based Targeted Intrusion: Analysis of Facebook Reconnaissance and Software Tampering Attacks</h3><p><strong>Genians</strong> detail this alleged North Korean campaign which is noteworthy due to the use of intermediary compromised infrastructure and heavy reliance on social engineering.</p><blockquote><ul><li><p>Conducted reconnaissance using two Facebook accounts claiming to be from Pyongyang and Pyongsong, North Korea</p></li><li><p>Built trust by adding targets as Facebook friends, then moved the conversation to Messenger and lured them using specific topics</p></li><li><p>Tricked targets into installing a dedicated PDF viewer under the pretense of sharing an encrypted PDF document on military weapons</p></li><li><p>Executed shellcode and gained initial access through a carefully tampered Wondershare PDFelement installer</p></li><li><p>Delivered follow-up commands through a JPG-disguised payload delivered via the Seoul branch website of a Japanese real estate information service</p></li></ul></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!4mvO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887b732e-c40d-4e2a-a529-8bf1aa18c028_1600x898.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!4mvO!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887b732e-c40d-4e2a-a529-8bf1aa18c028_1600x898.png 424w, /__u/substackcdn.com/image/fetch/$s_!4mvO!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887b732e-c40d-4e2a-a529-8bf1aa18c028_1600x898.png 848w, /__u/substackcdn.com/image/fetch/$s_!4mvO!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887b732e-c40d-4e2a-a529-8bf1aa18c028_1600x898.png 1272w, /__u/substackcdn.com/image/fetch/$s_!4mvO!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887b732e-c40d-4e2a-a529-8bf1aa18c028_1600x898.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!4mvO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887b732e-c40d-4e2a-a529-8bf1aa18c028_1600x898.png" width="1456" height="817" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/887b732e-c40d-4e2a-a529-8bf1aa18c028_1600x898.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:817,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;[Figure 1-1] Overall Attack Flow&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="[Figure 1-1] Overall Attack Flow" title="[Figure 1-1] Overall Attack Flow" srcset="/__u/substackcdn.com/image/fetch/$s_!4mvO!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887b732e-c40d-4e2a-a529-8bf1aa18c028_1600x898.png 424w, /__u/substackcdn.com/image/fetch/$s_!4mvO!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887b732e-c40d-4e2a-a529-8bf1aa18c028_1600x898.png 848w, /__u/substackcdn.com/image/fetch/$s_!4mvO!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887b732e-c40d-4e2a-a529-8bf1aa18c028_1600x898.png 1272w, /__u/substackcdn.com/image/fetch/$s_!4mvO!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F887b732e-c40d-4e2a-a529-8bf1aa18c028_1600x898.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.genians.co.kr/en/blog/threat_intelligence/pretexting">https://www.genians.co.kr/en/blog/threat_intelligence/pretexting</a></p><h3>Kimsuky APT Group Phishing Sample Analysis</h3><p><strong>Lawrence Douglas</strong> details this alleged North Korean operation end to end. Noteworthy because of the use of Chrome Remote Desktop for remote control.</p><blockquote><p>This article provides an in-depth technical analysis of a targeted phishing attack suspected to have been launched by the North Korean (DPRK) APT group Kimsuky . The attackers used an official South Korean Army meeting as bait, triggering a multi-stage malicious chain via an LNK shortcut, ultimately achieving covert, long-term remote control using Chrome Remote Desktop.</p></blockquote><p><a href="https://sadsec.com/redteaming/ir-dprk-apt-phishing/">https://sadsec.com/redteaming/ir-dprk-apt-phishing/</a></p><h3>Tracking an OtterCookie Infostealer Campaign Across npm</h3><p><strong>Alessandra Rizzo</strong> detail this alleged North Korea stealer campaign which is noteworthy as is shows ability to evolve to evade detection but also the scale and ephemeral nature of some of infrastructure (i.e. accounts) in use.</p><blockquote><p>The custom base91 encoding with per-function alphabet rotation represents a notable advancement over the <code>obfuscator.io</code> techniques used in earlier campaigns like BeaverTail and Koa<a href="https://panther.com/blog/no-fool-s-errand-the-koalemos-rat-campaign">l</a>emos. It defeats static string extraction entirely and requires analysts to identify the correct decoder context for each function scope. The two-layer package distribution strategy (benign wrapper + malicious dependency) adds another obstacle to manual review.</p><p>The packages identified here are not isolated. They are the April 2026 iteration of a campaign that has been running since at least February, rotating through dozens of throwaway accounts and package names while keeping the same C2 infrastructure, the same malware, and the same SSH backdoor logic.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!0Qbj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89d4d5f5-d3e0-4968-a556-fb8441c90852_1360x2520.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!0Qbj!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89d4d5f5-d3e0-4968-a556-fb8441c90852_1360x2520.png 424w, /__u/substackcdn.com/image/fetch/$s_!0Qbj!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89d4d5f5-d3e0-4968-a556-fb8441c90852_1360x2520.png 848w, /__u/substackcdn.com/image/fetch/$s_!0Qbj!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89d4d5f5-d3e0-4968-a556-fb8441c90852_1360x2520.png 1272w, /__u/substackcdn.com/image/fetch/$s_!0Qbj!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89d4d5f5-d3e0-4968-a556-fb8441c90852_1360x2520.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!0Qbj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89d4d5f5-d3e0-4968-a556-fb8441c90852_1360x2520.png" width="1360" height="2520" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/89d4d5f5-d3e0-4968-a556-fb8441c90852_1360x2520.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2520,&quot;width&quot;:1360,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!0Qbj!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89d4d5f5-d3e0-4968-a556-fb8441c90852_1360x2520.png 424w, /__u/substackcdn.com/image/fetch/$s_!0Qbj!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89d4d5f5-d3e0-4968-a556-fb8441c90852_1360x2520.png 848w, /__u/substackcdn.com/image/fetch/$s_!0Qbj!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89d4d5f5-d3e0-4968-a556-fb8441c90852_1360x2520.png 1272w, /__u/substackcdn.com/image/fetch/$s_!0Qbj!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89d4d5f5-d3e0-4968-a556-fb8441c90852_1360x2520.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>https://panther.com/blog/tracking-an-ottercookie-infostealer-campaign-across-npm</p><h3>We Dumped a Live Kimsuky C2 and Recovered Every Stage of the Kill Chain: CHM Dropper, VBScript Stager, PowerShell Keylogger</h3><p><strong>Breakglass Intelligence</strong> provides a breakdown of this alleged North Korean operation which is noteworthy for the reconnaissance phase as well as the scale and locality of the infrastructure. </p><blockquote><p>We recovered the complete source code of all three attack stages before the actor can rotate:</p><ul><li><p>Stage 1 (6,338 bytes VBScript): Full system reconnaissance &#8212; OS, CPU, RAM, processes, AV products, directory listings of Desktop/Documents/Downloads &#8212; plus persistence via a scheduled task disguised as &#8220;Edge Updater&#8221;</p></li><li><p>Stage 2 (449 bytes VBScript &#8594; PowerShell): Bridge script that downloads and <code>Invoke-Expression</code>s the keylogger</p></li><li><p>Stage 3 (6,234 bytes PowerShell): Complete keylogger with keystroke capture, clipboard monitoring, window tracking, and timed exfiltration using deliberately typo&#8217;d User-Agents (<code>Chremo</code> instead of Chrome, <code>Edgo</code> instead of Edge)</p></li></ul><p>&#8230;</p><p>We then mapped <strong>79+ domains</strong> across 5 C2 IPs spanning Korean VPS resellers (DAOU Technology, UCloud HK, Kaopu Cloud)</p></blockquote><p><a href="https://intel.breakglass.tech/post/kimsuky-chm-nidlog-c2-dump-full-payload-recovery">https://intel.breakglass.tech/post/kimsuky-chm-nidlog-c2-dump-full-payload-recovery</a></p><h3>Dissecting Sapphire Sleet&#8217;s macOS intrusion from lure to compromise</h3><p><strong>Microsoft Threat Intelligence</strong> detail this alleged North Korean campaign which is noteworthy use to the use of the Zoom social engineering lure and the number of manual steps the victim needs to undertake..</p><blockquote><p>a macOS&#8209;focused cyber campaign by the North Korean threat actor Sapphire Sleet that relies on social engineering rather than software vulnerabilities. By impersonating a legitimate software update, threat actors tricked users into manually running malicious files, allowing them to steal passwords, cryptocurrency assets, and personal data while avoiding built&#8209;in macOS security checks. </p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!H8lb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F032b9e29-a543-4e0c-be46-437f302d1285_947x390.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!H8lb!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F032b9e29-a543-4e0c-be46-437f302d1285_947x390.webp 424w, /__u/substackcdn.com/image/fetch/$s_!H8lb!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F032b9e29-a543-4e0c-be46-437f302d1285_947x390.webp 848w, /__u/substackcdn.com/image/fetch/$s_!H8lb!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F032b9e29-a543-4e0c-be46-437f302d1285_947x390.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!H8lb!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F032b9e29-a543-4e0c-be46-437f302d1285_947x390.webp 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!H8lb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F032b9e29-a543-4e0c-be46-437f302d1285_947x390.webp" width="947" height="390" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/032b9e29-a543-4e0c-be46-437f302d1285_947x390.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:390,&quot;width&quot;:947,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Flowchart illustrating Sapphire Sleet targeting users with a fake Zoom Support meeting invite, leading to the user joining the meeting, downloading a malicious AppleScript file, and executing the script via Script Editor.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Flowchart illustrating Sapphire Sleet targeting users with a fake Zoom Support meeting invite, leading to the user joining the meeting, downloading a malicious AppleScript file, and executing the script via Script Editor." title="Flowchart illustrating Sapphire Sleet targeting users with a fake Zoom Support meeting invite, leading to the user joining the meeting, downloading a malicious AppleScript file, and executing the script via Script Editor." srcset="/__u/substackcdn.com/image/fetch/$s_!H8lb!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F032b9e29-a543-4e0c-be46-437f302d1285_947x390.webp 424w, /__u/substackcdn.com/image/fetch/$s_!H8lb!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F032b9e29-a543-4e0c-be46-437f302d1285_947x390.webp 848w, /__u/substackcdn.com/image/fetch/$s_!H8lb!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F032b9e29-a543-4e0c-be46-437f302d1285_947x390.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!H8lb!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F032b9e29-a543-4e0c-be46-437f302d1285_947x390.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.microsoft.com/en-us/security/blog/2026/04/16/dissecting-sapphire-sleets-macos-intrusion-from-lure-to-compromise/">https://www.microsoft.com/en-us/security/blog/2026/04/16/dissecting-sapphire-sleets-macos-intrusion-from-lure-to-compromise/</a></p><h2>Reporting on Iran</h2><h3>Kitten Had the Map all Along : RAISING GCC TENSIONS &amp; THE PRE-POSITIONING MAP</h3><p><strong>CloudSek</strong> detail this alleged Iranian campaign which also allegedly supported/enabled kinetic operations and thus noteworthy.. </p><blockquote><p>Iran-linked APT35 (Charming Kitten) conducted years of cyber reconnaissance across GCC nations before coordinated missile strikes, suggesting cyber operations directly enabled kinetic targeting. Critical infrastructure across UAE, Saudi Arabia, Qatar, and others was pre-profiled and in some cases breached. </p><p>The report highlights a dangerous shift&#8212;cyber warfare is no longer support, but a frontline weapon in modern conflict.</p></blockquote><p><a href="https://www.cloudsek.com/blog/kitten-had-the-map-all-along-raising-gcc-tensions-the-pre-positioning-map">https://www.cloudsek.com/blog/kitten-had-the-map-all-along-raising-gcc-tensions-the-pre-positioning-map</a></p><h3>Multi-Stage Cyber Campaign Targeting Middle Eastern Critical Sectors with Tradecraft Consistent with MuddyWater</h3><p><strong>Oasis Security</strong> detail this alleged Iranian operation which is noteworthy as it provides an indication of how broad the campaign is/was and the techniques employed.</p><blockquote><ul><li><p>The campaign followed a structured multi-stage workflow, transitioning from large-scale reconnaissance to selective intrusion and data exfiltration.</p></li><li><p>The actor scanned more than 12,000 internet-exposed systems using at least five newly disclosed CVEs.</p></li><li><p>The operation shifted from broad reconnaissance to targeted attacks against aviation, energy, and government sectors in the Middle East.</p></li><li><p>Credential harvesting via OWA brute-force attacks served as a primary intrusion vector.</p></li><li><p>Newly identified C2 controllers were observed, with communication patterns consistent with those previously associated with MuddyWater.</p></li><li><p>Sensitive data, including passport, payroll, and financial records, was confirmed to be exfiltrated.</p></li></ul></blockquote><p><a href="https://oasis-security.io/blog/260414-Iran">https://oasis-security.io/blog/260414-Iran</a></p><h2>Reporting on Other Actors</h2><h3>Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them</h3><p><strong>Austin Ginder</strong> shows you don&#8217;t need to compromise your way into a supply chain compromise you can buy your way in..</p><blockquote><p>In 2017, a buyer using the alias &#8220;Daley Tias&#8221; purchased the Display Widgets plugin (200,000 installs) for $15,000 and injected payday loan spam. That buyer went on to compromise at least 9 plugins the same way.</p><p>The Essential Plugin case is the same playbook at a larger scale. 30+ plugins. Hundreds of thousands of active installations. A legitimate 8-year-old business acquired through a public marketplace and weaponized within months.</p></blockquote><p><a href="https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/">https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/</a></p><h3>QEMU abused to evade detection and enable ransomware delivery</h3><p><strong>Morgan Demboski</strong> details the misuse by two discrete clusters which defensive teams will want to build detections for.</p><blockquote><p>First observed in November 2025, STAC4713 is a financially motivated campaign associated with PayoutsKing ransomware. Several incidents in this campaign involved QEMU as a covert reverse SSH backdoor to deliver attacker tools and harvest domain credentials.</p><p>First observed in February 2026, the STAC3725 campaign exploits the CitrixBleed2 vulnerability (CVE-2025-5777) to gain access and then installs a malicious ScreenConnect client to maintain persistence. The threat actors deploy a QEMU VM to install additional tools for conducting enumeration and credential theft.</p></blockquote><p><a href="https://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery">https://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery</a></p><h3>Chasing an Angry Spark</h3><p><strong>Gen Digital</strong> detail a campaign they caught and watched whilst also hinting at some interesting defensive capability.. </p><blockquote><p>In the spring of 2022, our anti-rootkit engine flagged something unusual inside a svchost.exe process on a machine in the United Kingdom. A chunk of memory -roughly 32 kilobytes- was making direct NtQuerySystemInformation syscalls, bypassing every usermode hook we had in place. When we pulled the memory dump and opened it in a disassembler, we found not just shellcode, but an entire virtual machine: a custom bytecode interpreter running a 25-kilobyte program, decoding its own payload on the fly, resolving APIs through hash lookups, and checking for hypervisors before executing a single line of its real code.</p><p>We named it AngrySpark -after the C++ namespace angry_spark found in the RTTI metadata of the DLL that delivered it. Over the following year, we captured three memory snapshots from the same host, watched its C2 infrastructure evolve, and eventually saw the connection get blocked. Then it vanished. No new samples. No new infrastructure. No second victim. Just a single spark in the dark.</p></blockquote><p><a href="https://www.gendigital.com/blog/insights/research/chasing-an-angry-spark">https://www.gendigital.com/blog/insights/research/chasing-an-angry-spark</a></p><h3>Adobe Reader zero-day vulnerability in active exploitation</h3><p><strong>Sophos</strong> detail the malicious lures which are exploiting this vulnerability..</p><blockquote><p>yummy_adobe_exploit_uwu.pdf</p><p>Invoice540.pdf</p></blockquote><p>For further details on this see both Vulnerability and Exploitation sections.</p><p><a href="https://www.sophos.com/en-us/blog/adobe-reader-zero-day-vulnerability-in-active-exploitation">https://www.sophos.com/en-us/blog/adobe-reader-zero-day-vulnerability-in-active-exploitation</a></p><h3>Smoking out an affiliate: SmokedHam, Qilin, a few Google ads and some bossware</h3><p><strong>Orange Cyberdefense</strong> detail a cluster of activity which all used malvertising which should be a tractable issue to address at source.</p><blockquote><ul><li><p>In early 2026, Orange Cyberdefense responded to several incidents delivering the SmokedHam backdoor;</p></li><li><p>In at least one case, the infection chain resulted in the deployment of the Qilin ransomware;</p></li><li><p>We attribute with moderate confidence these activities to the Russian-speaking ransomware affiliate UNC2465, historically associated with DarkSide, LockBit and Hunters International distribution;</p></li><li><p>By pivoting on the infrastructure, we identified multiple malicious malvertising domains responsible for delivering SmokedHam typically masqueraded as legitimate utilities like RVTools;</p></li><li><p>We identified a relatively high number of SmokedHam variants, with different delivery and persistence techniques, indicating a prolific threat actor iterating on tooling;</p></li><li><p>We believe this threat actor to be increasingly targeting European organizations since early 2026.</p></li></ul><p>&#8230;</p><p>All three infection chains observed by our analysts revealed the use of the SmokedHam backdoor, delivered through malvertising and masquerading as common utility installers for RVTools or Remote Desktop Manager (RDM).</p></blockquote><p><a href="https://www.orangecyberdefense.com/global/blog/cert-news/smoking-out-an-affiliate-smokedham-qilin-a-few-google-ads-and-some-bossware">https://www.orangecyberdefense.com/global/blog/cert-news/smoking-out-an-affiliate-smokedham-qilin-a-few-google-ads-and-some-bossware</a></p><h3>Inside an AI&#8209;enabled device code phishing campaign</h3><p><strong>Microsoft Defender Security Research Team</strong> detail this campaign, I am including primarily to highlight where AI was used to set some context against the headline. Also important to note the disconnect between the first sentence and then the detail provided in the second. </p><blockquote><p>This campaign is distinct because it moves away from static, manual scripts toward an AI-driven infrastructure and multiple automations end-to-end.</p><p>..</p><p>Hyper-personalized lures: Generative AI was used to create targeted phishing emails aligned to the victim&#8217;s role, including themes such as RFPs, invoices, and manufacturing workflows, increasing the likelihood of user interaction.</p></blockquote><p><a href="https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/">https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/</a></p><h1>Discovery</h1><p>How we find and understand the latent compromises within our environments.</p><h2>KQL to detect CVE-2026-33829 Snipping too NTLM leak</h2><p>SlimKQL release a KQL detection for this vulnerability - see the Vulnerability section for the vulnerability itself. </p><p><a href="https://github.com/SlimKQL/Detections.AI/blob/main/KQL/cve-2026-33829-snipping-tool-ntlm-leak.kql">https://github.com/SlimKQL/Detections.AI/blob/main/KQL/cve-2026-33829-snipping-tool-ntlm-leak.kql</a></p><h2>C2-Tracker: Live Feed of C2 servers, tools, and botnets</h2><p><strong>Monty</strong> archives this project, but we are covering to inspire others..</p><blockquote><p>This project has been archived. The text files in <code>data/</code> have been removed and are no longer updated. The signatures in <code>tracker.py</code> are no longer updated.</p></blockquote><p><a href="https://github.com/montysecurity/C2-Tracker">https://github.com/montysecurity/C2-Tracker</a></p><p>it led to a discussion which also surfaced this project from <strong>Joseph Avanzato</strong></p><blockquote><p>Querying Shodan/Censys for recently-observed C2/RAT infrastructure.</p></blockquote><p><a href="https://github.com/joeavanzato/recent_c2_infrastructure">https://github.com/joeavanzato/recent_c2_infrastructure</a></p><p>and also these Zeek Intel Threat Feed w/ Combined Indicators</p><p><a href="https://github.com/CriticalPathSecurity/Zeek-Intelligence-Feeds">https://github.com/CriticalPathSecurity/Zeek-Intelligence-Feeds</a></p><h2>EDR Telemetry Sample</h2><p><strong>Deception Pro</strong> release this dataset which will have value to various audiences.. </p><blockquote><p>This dataset contains raw Endpoint Detection &amp; Response (EDR) telemetry captured during controlled Deception.Pro malware sandbox operations on an enterprise Active Directory network. Unlike most malware sandboxes &#8212; which detonate samples for roughly 30 minutes &#8212; our operations run for hours or days per analysis, capturing the full arc of adversary behavior. The data represents a full-fidelity snapshot of system activity recorded while threat actors interacted with a live deception environment, making it a rare, real-world ground-truth record of malicious activity observed alongside authentic benign baseline noise.</p></blockquote><p><a href="https://huggingface.co/datasets/DeceptionPro/EDR_Telemetry_Sample">https://huggingface.co/datasets/DeceptionPro/EDR_Telemetry_Sample</a></p><h1>Defence</h1><p>How we proactively defend our environments.</p><h2>LmCompatibilityLevel and the PDC Trap</h2><p><strong>Decoder</strong> details a set of unexpected behaviours that Microsoft will be addressing..</p><blockquote><p>I observed a completely unexpected behavior: when attempting authentication using NTLMv1 against other &#8220;hardened&#8221; domain controllers, the authentication still succeeded, which was both surprising and quite frustrating.</p><p>I tried to find documentation explaining or validating this behaviour but was unsuccessful, so I submitted it to MSRC as a security feature bypass. After an initial classification of &#8220;Important Security Feature Bypass&#8221;, they reconsidered and concluded it did not meet the bar for immediate servicing.</p><p>After further discussion explaining the real-world impact of inconsistent <code>LmCompatibilityLevel</code> configurations, they settled on medium severity with a fix planned for an upcoming future release.</p></blockquote><p><a href="https://decoder.cloud/2026/04/15/lmcompatibilitylevel-and-the-pdc-trap/">https://decoder.cloud/2026/04/15/lmcompatibilitylevel-and-the-pdc-trap/</a></p><h2>Bringing Rust to the Pixel Baseband</h2><p><strong>Jiacheng Lu</strong> details the early steps that Google are taking to integrate Rust into baseband ..</p><blockquote><p>For Pixel 10, Google is advancing its proactive security measures further.</p><p>integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware. The new Rust-based DNS parser significantly reduces our security risk by mitigating an entire class of vulnerabilities in a risky area, while also laying the foundation for broader adoption of memory-safe code in other areas.</p></blockquote><p><a href="https://security.googleblog.com/2026/04/bringing-rust-to-pixel-baseband.html">https://security.googleblog.com/2026/04/bringing-rust-to-pixel-baseband.html</a></p><h2>Protecting your Administrator</h2><p><strong>James Forshaw</strong> gives an overview and analysis of Administrator Protection on Windows</p><blockquote><ul><li><p>Admin Protection is "technically" more secure </p></li><li><p>The decision to base on UAC had significant impact: </p><ul><li><p>Old UAC bypasses became full privilege escalation </p></li><li><p>Testing of known bypasses seemed inadequate </p></li><li><p>No clean break from the old security model </p></li></ul></li><li><p>Microsoft are fixing bugs in Admin Protection unlike UAC </p><ul><li><p>At the moment the feature isn't enabled so nothing is fixed </p></li><li><p>Not sure how long it'll last, get your $$$ while you can</p></li></ul></li></ul></blockquote><p><a href="https://github.com/tyranid/infosec-presentations/blob/master/Zer0Con/2026/Protecting%20your%20Administrator.pdf">https://github.com/tyranid/infosec-presentations/blob/master/Zer0Con/2026/Protecting%20your%20Administrator.pdf</a></p><h1>Incident Writeups &amp; Disclosures</h1><p>How they got in and what they did.</p><h2>Our response to the Axios developer tool compromise</h2><p><strong>OpenAI</strong> implies their development pipelines were compromised through this supply chain attack.</p><blockquote><p>We recently identified a security issue involving a third-party developer tool, Axios, that was part of a widely reported, <a href="https://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package">broader industry incident&#8288;(opens in a new window)</a>. Out of an abundance of caution we are taking steps to protect the process that certifies our macOS applications are legitimate OpenAI apps. We found no evidence that OpenAI user data was accessed, that our systems or intellectual property was compromised, or that our software was altered.</p><p>We are updating our security certificates, which will require all macOS users to update their OpenAI apps to the latest versions.</p></blockquote><p><a href="https://openai.com/index/axios-developer-tool-compromise/">https://openai.com/index/axios-developer-tool-compromise/</a></p><h1>Vulnerability</h1><p>Our attack surface.</p><h2>CVE-2026-34621: Security update available for Adobe Acrobat Reader<strong> </strong>| APSB26-43</h2><p><strong>Adobe</strong> patch the vulnerability that Haifei caught being exploited (see below under Exploitation)</p><p><a href="https://helpx.adobe.com/security/products/acrobat/apsb26-43.html">https://helpx.adobe.com/security/products/acrobat/apsb26-43.html</a></p><h2>CVE-2026-34040: One Megabyte to Root: How a Size Check Broke Docker&#8217;s Last Line of Defense</h2><p><strong>Vladimir Tokarev</strong> details this trivial vulnerability.. </p><blockquote><ul><li><p>We discovered an authorization bypass in Docker Engine (CVE-2026-34040, CVSS 8.8 High). </p></li><li><p>Request bodies larger than 1MB are silently dropped before reaching AuthZ plugins. The Docker daemon still processes them normally. A single padded HTTP request is enough to create a privileged container with host filesystem access.</p></li><li><p>This is an incomplete fix for <a href="https://github.com/moby/moby/security/advisories/GHSA-v23v-6jw2-98fq">CVE-2024-41110</a> (CVSS 10.0), a zero-length body bypass from July 2024. That fix handled empty bodies. It didn&#8217;t handle oversized ones.</p></li></ul></blockquote><p><a href="https://www.cyera.com/research/one-megabyte-to-root-how-a-size-check-broke-dockers-last-line-of-defense">https://www.cyera.com/research/one-megabyte-to-root-how-a-size-check-broke-dockers-last-line-of-defense</a></p><h2>CVE-2026-33829: Snipping Tool NTLM Leak</h2><p><strong>Marcos Diaz</strong> details the vulnerability in the Snipping Tool on Windows that I suspect few would have expected..</p><blockquote><p>This vulnerability allows remote attackers to disclose NTLM responses from users on affected versions of the Snipping Tool App. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a link that is going to trigger the Snipping Tool app via the URI schema <code>ms-screensketch</code>.</p></blockquote><h2>Fabricked</h2><p><strong>Benedict Schl&#252;ter</strong>, <strong>Christoph Wech</strong> and <strong>Shweta Shinde</strong> demonstrate once again why I often hold up ETH Zurich as an exemplar of an academic institution who does applied cyber security research. </p><blockquote><p>Confidential computing allows cloud tenants to offload sensitive computations and data to remote resources without needing to trust the cloud service provider. Hardware-based trusted execution environments, like AMD SEV-SNP, achieve this by creating Confidential Virtual Machines (CVMs). With Fabricked, we present a novel software-based attack that manipulates memory routing to compromise AMD SEV-SNP. By redirecting memory transactions, a malicious hypervisor can deceive the secure co-processor (PSP) into improperly initializing SEV-SNP. This enables the attacker to perform arbitrary read and write access within the CVM address space, thus breaking SEV-SNP core security guarantees.</p></blockquote><h1>Offense</h1><p>Attack capability, techniques and trade-craft. </p><h2>RedSun</h2><p><strong>Nightmare Eclipse</strong> releases this vulnerability in defender which we can expect Microsoft to patch.. </p><blockquote><p>When Windows Defender realizes that a malicious file has a cloud tag, for whatever stupid and hilarious reason, the antivirus that's supposed to protect decides that it is a good idea to just rewrite the file it found again to it's original location. The PoC abuses this behaviour to overwrite system files and gain administrative privileges.</p></blockquote><p><a href="https://github.com/Nightmare-Eclipse/RedSun">https://github.com/Nightmare-Eclipse/RedSun</a></p><h2>Phantom-Evasion-Loader (x64 Linux)</h2><p><strong>commSync</strong> releases this capability which is noteworthy for being able to subvert / reduce detection by eBPF agents..</p><blockquote><p>Phantom-Evasion-Loader is a standalone, pure x64 Assembly injection engine engineered to minimize the detection surface of modern EDR/XDR solutions and Kernel-level monitors like Falco (eBPF). It leverages advanced techniques such as SROP and Zero-Copy Injection to deliver payloads as a ghost in the machine.</p></blockquote><p><a href="https://github.com/JM00NJ/Phantom-Evasion-Loader">https://github.com/JM00NJ/Phantom-Evasion-Loader</a></p><h2>Abusing Overly Permissive Role in Azure File Sync</h2><p><strong>Christian Bortone</strong> details this side quest and how it may be misused.. </p><blockquote><p>Microsoft also provides a specific role called <strong>Azure File Sync Administrator</strong>, which is designed to manage Azure File Sync operations. This role grants the permissions needed to onboard and connect new servers, create new Sync Groups, and configure synchronization settings.</p><p>..</p><p>While playing around with the service and setting up a new node in my lab, I noticed something interesting. The built-in <strong>Azure File Sync Administrator</strong> role includes permissions that go beyond the usual <strong>Microsoft.StorageSync</strong> actions.</p><p>..</p><p>What really caught my eye was that this built-in role includes the <code>Microsoft.Authorization/roleAssignments/write</code> permission. While that permission is restricted by a condition, it still allows assignments to the following roles:</p><ul><li><p><strong>Reader and Data Access</strong></p></li><li><p><strong>Storage File Data Privileged Contributor</strong></p></li><li><p><strong>Storage Account Contributor</strong></p></li></ul><p>So, in practice, someone with this role could assign themselves powerful roles on the storage account and end up with more privileges than you might expect</p></blockquote><p><a href="https://xybytes.com/azure/Abusing-Overly-Permissive-Role-in-Azure-File-Sync/">https://xybytes.com/azure/Abusing-Overly-Permissive-Role-in-Azure-File-Sync/</a></p><h2>Signed to Kill: Reverse Engineering a 0-Day Used to Disable CrowdStrike EDR</h2><p><strong>Jehad Abudagga</strong> details the work - their Github is however now 404ing..</p><blockquote><p>The article presents a reverse-engineering analysis of a kernel driver used in a BYOVD (Bring Your Own Vulnerable Driver) attack to disable security software, including CrowdStrike Falcon EDR. The researcher discovered multiple variants of a Microsoft-signed driver that expose a dangerous IOCTL interface capable of terminating arbitrary processes. Because the driver is legitimately signed and not blocklisted, Windows allows it to run in kernel mode without restrictions.</p></blockquote><p><a href="https://core-jmp.org/2026/04/signed-to-kill-reverse-engineering-a-0-day-used-to-disable-crowdstrike-edr/">https://core-jmp.org/2026/04/signed-to-kill-reverse-engineering-a-0-day-used-to-disable-crowdstrike-edr/</a></p><p>Lots of similar BYOVD issues this week enabling a variety of outcomes</p><ul><li><p><a href="https://github.com/magicsword-io/LOLDrivers/issues/297">https://github.com/magicsword-io/LOLDrivers/issues/297</a></p></li><li><p><a href="https://github.com/ANYLNK/KSLDBYOVDARK">https://github.com/ANYLNK/KSLDBYOVDARK</a></p></li><li><p><a href="https://github.com/athenasec16/CVE-2026-29923">https://github.com/athenasec16/CVE-2026-29923</a></p></li></ul><h2>UnDefend</h2><p><strong>Nightmare Eclipse</strong> releases this tooling which shows once more the value of having true signal flowing through the system to detect when security tooling has failed.</p><blockquote><p>Repository hosting windows defender DOS tool</p><p>This tool does not need administrative privileges and can works as a standard user.</p></blockquote><p><a href="https://github.com/Nightmare-Eclipse/UnDefend">https://github.com/Nightmare-Eclipse/UnDefend</a></p><h2>BlueSAM BOF</h2><p><strong>incursi0n</strong> packages up <strong>Nightmare Eclipse</strong>&#8217;s research for offensive deployment. Detection teams will want to ensure coverage.</p><blockquote><p>A Cobalt Strike Beacon Object File adaptation of BlueHammer that attempts to obtain a copy of the SAM database through Windows Defender update/VSS behavior and process offline registry data from Beacon.</p></blockquote><p><a href="https://github.com/incursi0n/BlueSAM">https://github.com/incursi0n/BlueSAM</a></p><h1>Exploitation</h1><p>What is being exploited..</p><h2>EXPMON detected sophisticated zero-day fingerprinting attack targeting Adobe Reader users</h2><p><strong>Haifei Li</strong> details the vulnerability they caught being exploited in the wild..</p><blockquote><ul><li><p>Based on our analysis, the sample acts as an initial exploit with the capability to collect and leak various types of information, potentially followed by remote code execution (RCE) and sandbox escape (SBX) exploits. It abuses zero-day/unpatched vulnerability in Adobe Reader that allows it to execute privileged Acrobat APIs, and it is confirmed to work on the latest version of Adobe Reader.</p></li><li><p>Specifically, it calls the &#8220;util.readFileIntoStream()&#8221; API, allowing it to read arbitrary files (accessible by the sandboxed Reader process) on the local system. In this way, it can collect a wide range of information from the local system and steal local file data.</p></li><li><p>The &#8220;RSS.addFeed()&#8221; API is called to serve two purposes: sending the information collected from the local system to a remote server and receiving additional JavaScript code to be executed.</p></li></ul></blockquote><p><a href="https://justhaifei1.blogspot.com/2026/04/expmon-detected-sophisticated-zero-day-adobe-reader.html">https://justhaifei1.blogspot.com/2026/04/expmon-detected-sophisticated-zero-day-adobe-reader.html</a></p><h1>Tooling and Techniques</h1><p>Low level tooling and techniques for attack and defence researchers</p><h2>Nano-analyzer</h2><p><strong>Jakub Kub&#237;k</strong>, <strong>Petr &#352;&#357;astn&#253;</strong>, <strong>Adam K&#345;ivka</strong> and <strong>Stanilav</strong> release which scaffolding which is a good trainer for those starting to experiment. </p><blockquote><p>This is a simple, single-file harness that is able to detect real zero-day vulnerabilities. Note that it is a prototype, biased towards C/C++ memory safety bugs, and will produce false positives. We are sharing it as-is in the spirit of open research &#8212; expect sharp corners.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!0Ctk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fcd1a6-946a-40d3-a5f0-482c7155817f_1574x1070.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!0Ctk!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fcd1a6-946a-40d3-a5f0-482c7155817f_1574x1070.png 424w, /__u/substackcdn.com/image/fetch/$s_!0Ctk!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fcd1a6-946a-40d3-a5f0-482c7155817f_1574x1070.png 848w, /__u/substackcdn.com/image/fetch/$s_!0Ctk!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fcd1a6-946a-40d3-a5f0-482c7155817f_1574x1070.png 1272w, /__u/substackcdn.com/image/fetch/$s_!0Ctk!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_webp, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fcd1a6-946a-40d3-a5f0-482c7155817f_1574x1070.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!0Ctk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fcd1a6-946a-40d3-a5f0-482c7155817f_1574x1070.png" width="1456" height="990" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/80fcd1a6-946a-40d3-a5f0-482c7155817f_1574x1070.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:990,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;aisle-nano-analyzer-diagram&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="aisle-nano-analyzer-diagram" title="aisle-nano-analyzer-diagram" srcset="/__u/substackcdn.com/image/fetch/$s_!0Ctk!, /__u/ctoatncsc.substack.com/w_424, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fcd1a6-946a-40d3-a5f0-482c7155817f_1574x1070.png 424w, /__u/substackcdn.com/image/fetch/$s_!0Ctk!, /__u/ctoatncsc.substack.com/w_848, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fcd1a6-946a-40d3-a5f0-482c7155817f_1574x1070.png 848w, /__u/substackcdn.com/image/fetch/$s_!0Ctk!, /__u/ctoatncsc.substack.com/w_1272, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fcd1a6-946a-40d3-a5f0-482c7155817f_1574x1070.png 1272w, /__u/substackcdn.com/image/fetch/$s_!0Ctk!, /__u/ctoatncsc.substack.com/w_1456, /__u/ctoatncsc.substack.com/c_limit, /__u/ctoatncsc.substack.com/f_auto, /__u/ctoatncsc.substack.com/q_auto:good, /__u/ctoatncsc.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fcd1a6-946a-40d3-a5f0-482c7155817f_1574x1070.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://github.com/weareaisle/nano-analyzer">https://github.com/weareaisle/nano-analyzer</a></p><h2>V8 Exploitation: From Libc Pwn to Browser Bugs</h2><p><strong>Varik Matevosyan</strong> provides a wonderful walkthrough for aspiring vulnerability researchers and exploit writers. </p><blockquote><p>After a few days of research, I felt ready to actually try the challenges. And here's the thing - the research paid off massively. Concepts that would've taken me hours to figure out through trial and error were already in my head when I needed them.</p></blockquote><p><a href="https://varik.dev/blog/v8/getting-started-with-v8-exploitation">https://varik.dev/blog/v8/getting-started-with-v8-exploitation</a></p><h2>Obfuscation vs the Optimizer: An LLVM Middle-End Arms Race</h2><p><strong>Robert Yates</strong> shows how ranging against compiler optimizers when you are trying to obfuscate can lead to new understanding.. </p><blockquote><p>We will explore the relationship between compilers, obfuscation, and de-obfuscation. We will first learn about LLVM, but I will frame the information so it's a little deeper and more relevant to this topic. Finally, we will walk through an example of obfuscation and watch the tug-of-war between our code and the optimization passes and see how a single commit in LLVM breaks our obfuscation. Hopefully, by the end, we will have a better understanding of how this tug-of-war is, in fact, more of a yin-yang.</p></blockquote><p><a href="https://blog.quarkslab.com/obfuscation-vs-the-optimizer-an-llvm-middle-end-arms-race.html">https://blog.quarkslab.com/obfuscation-vs-the-optimizer-an-llvm-middle-end-arms-race.html</a></p><h2>WCF Proxy</h2><p><strong>Sebastian Rauch</strong> releases this work aid for Windows researchers.. </p><blockquote><p>A proxy for net.tcp-based WCF traffic.</p></blockquote><p><a href="https://github.com/SySS-Research/wcfproxy">https://github.com/SySS-Research/wcfproxy</a></p><h2>Building a last-resort unpacker with AI</h2><p><strong>David &#193;lvarez</strong> and <strong>Adolf St&#345;eda</strong> show how to apply AI for good..</p><blockquote><p>the idea behind what we call the Last-Resort Unpacker is fairly simple: if AI is good at spotting patterns and translating logic across representations, could it help us recover payloads in cases where traditional static unpacking pipelines fail? We are not trying to solve the hardest forms of protection here. The goal is more pragmatic, to cover more real-world cases, reduce manual effort, and potentially extract logic that can later feed back into our regular unpacking workflows.</p></blockquote><p><a href="https://www.gendigital.com/blog/insights/research/ai-malware-unpacking">https://www.gendigital.com/blog/insights/research/ai-malware-unpacking</a></p><h1>Footnotes</h1><p>Some other small (and not so small) bits and bobs which might be of interest.</p><ul><li><p>Annual, quarterly and monthly reports</p><ul><li><p><em>Nothing overly of note this week, but keep an eye on</em> <a href="https://github.com/jacobdjwilson/awesome-annual-security-reports/tree/main/Annual%20Security%20Reports/2026">the Awesome Annual Security Reports 2026 collection</a></p></li></ul></li><li><p><a href="https://www.lattica.ai/wp-content/uploads/2026/04/2nd-FHE-Landscape-Survey.pdf">2nd FHE Landscape Survey</a></p></li><li><p><a href="https://www.mdpi.com/2624-800X/6/2/57">An Empirical Assessment of Digital Forensic Process Reliability Using Integrated ISO/IEC 27037 and 27041 Standards</a></p></li><li><p><a href="https://dl.acm.org/doi/10.1145/3772318.3790613">&#8220;Tell Them They Are a Responsible Entity, Not a Customer&#8221;: Understanding Practitioner Challenges in Sector CSIRTs</a></p></li><li><p><a href="https://arxiv.org/abs/2604.15073">Emulation-based System-on-Chip Security Verification: Challenges and Opportunities</a></p></li><li><p>Quantum and cyber security</p><ul><li><p><a href="https://arxiv.org/abs/2304.14344">Estimating the Energy Requirements to Operate a Cryptanalytically Relevant Quantum Computer</a></p></li><li><p><a href="https://www.amazon.science/blog/verifying-and-optimizing-post-quantum-cryptography-at-amazon">Verifying and optimizing post-quantum cryptography at Amazon</a></p></li></ul></li><li><p>Artificial intelligence</p><ul><li><p>Fundamental</p><ul><li><p><a href="https://arxiv.org/abs/2604.06425">Neural Computers </a>- <em>&#8220;We propose a new frontier: Neural Computers (NCs) -- an emerging machine form that unifies computation, memory, and I/O in a learned runtime state. Unlike conventional computers, which execute explicit programs, agents, which act over external execution environments, and world models, which learn environment dynamics, NCs aim to make the model itself the running computer.&#8221;</em></p></li></ul></li><li><p>Applied non-cyber</p><ul><li><p><a href="https://openreview.net/forum?id=rfJ41gK9Ct">PMDformer: Patch-Mean Decoupling Information Transformer for Long-term Forecasting</a> - we introduce patch-mean decoupling (PMD), which separates the trend and residual shape information by subtracting the mean of each patch, preserving the original structure and ensuring that the attention mechanism captures true shape similarities</p></li><li><p><a href="https://arxiv.org/abs/2604.14709">HWE-Bench: Benchmarking LLM Agents on Real-World Hardware Bug Repair Tasks</a></p></li></ul></li><li><p>Applied cyber specific</p><ul><li><p><a href="https://github.com/weareaisle/nano-analyzer">Nano-analyzer: A minimal LLM-powered zero-day vulnerability scanner</a></p></li><li><p><a href="https://blog.calif.io/p/mad-bugs-claude-wrote-a-full-freebsd">MAD Bugs: Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell (CVE-2026-4747)</a></p></li><li><p><a href="https://arxiv.org/abs/2604.05719">Hackers or Hallucinators? A Comprehensive Analysis of LLM-Based Automated Penetration Testing</a></p></li><li><p><a href="https://sushegaad.github.io/Claude-Skills-Governance-Risk-and-Compliance/">Claude Skills for GRC &#8212; Governance, Risk &amp; Compliance</a></p></li><li><p><a href="https://xbow.com/blog/anthropic-opus4-7-first-look">Smaller Bites, Bigger Meals: What We Learned Running Opus 4.7 in Offensive Workflows</a></p></li><li><p><a href="https://www.ox.security/blog/the-mother-of-all-ai-supply-chains-critical-systemic-vulnerability-at-the-core-of-the-mcp/">The Mother of All AI Supply Chains: Critical, Systemic Vulnerability at the Core of Anthropic&#8217;s MCP</a></p></li><li><p><a href="https://arxiv.org/abs/2604.14604">Hijacking Large Audio-Language Models via Context-Agnostic and Imperceptible Auditory Prompt Injection</a></p></li><li><p><a href="https://arxiv.org/abs/2604.13955">Towards Personalizing Secure Programming Education with LLM-Injected Vulnerabilities</a></p></li><li><p><a href="https://arxiv.org/abs/2604.13114">The Code Whisperer: LLM and Graph-Based AI for Smell and Vulnerability Resolution</a></p></li><li><p><a href="https://arxiv.org/abs/2604.15022">Route to Rome Attack: Directing LLM Routers to Expensive Models via Adversarial Suffix Optimization</a></p></li></ul></li></ul></li><li><p>Books</p><ul><li><p><em>Nothing overly of note this week..</em></p></li></ul></li><li><p>Events</p><ul><li><p><a href="https://www.youtube.com/ndsssymposium">NDSS Symposium</a> videos now online</p></li><li><p><a href="https://www.usenix.org/conference/usenixsecurity26">USENIX 2026 </a>- August 12&#8211;14, 2026 Baltimore, MD, USA</p></li></ul></li></ul><p>Finally finally the <a href="https://creators.spotify.com/pod/profile/national-cyber-security-c6/episodes/The-Ransomware-Ecosystem-e2hi088">NCSC&#8217;s podcast series</a>.</p><div><hr></div><p><em>Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them. </em></p><p><em>This newsletter is subject to the NCSC website terms and conditions which can be found at <a href="https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions">https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions</a> and you can find out more about how will treat your personal information in our privacy notice at <a href="https://www.ncsc.gov.uk/section/about-this-website/privacy-statement">https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.</a></em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://ctoatncsc.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CTO at NCSC - Cyber Defence Analysis! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>