LIVE · cybersecurity feed
Live wire
CVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on HostCISA orders feds to patch actively exploited TrueConf Server flawsCVE-2026-69836 · Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
malwarehigh

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More

This week's cybersecurity landscape features several significant threats, including the abuse of legitimate signed drivers for kernel operations, a large-scale cyber espionage campaign by an Iran-based group targeting universities, and malware utilizing DLL sideloading. Additionally, advancements in AI safety are being explored by OpenAI and Google, while a new service, Kriminal AI, offers unfiltered AI responses, raising concerns about misuse. Apple is also modifying its App Tracking Transparency feature in Germany following regulatory scrutiny.

zeroday.news ·

This week's cybersecurity reporting highlights a diverse array of threats and developments, including the exploitation of legitimate signed drivers for malicious kernel operations, a significant cyber espionage campaign attributed to an Iran-based threat actor targeting academic institutions, and the proliferation of malware leveraging DLL sideloading techniques. The landscape also includes discussions around AI safety initiatives from major tech companies, the emergence of unfiltered AI services, and regulatory adjustments by Apple concerning its App Tracking Transparency feature in Germany.

The reported abuse of legitimate signed drivers for kernel operations represents a concerning trend in privilege escalation and evasion. Attackers are increasingly seeking methods to operate with high privileges while bypassing security controls designed to flag unsigned or suspicious kernel modules. By co-opting drivers that have been legitimately signed by trusted authorities, adversaries can load their own malicious code into the kernel, granting them deep system access, the ability to disable security software, and persistence mechanisms that are difficult to detect and remove. This class of attack often involves supply chain compromise or social engineering to trick users into installing the malicious driver.

Separately, an Iran-based group has reportedly launched a large-scale cyber espionage campaign specifically targeting universities. While the exact vectors and payloads were not detailed, such campaigns typically aim to exfiltrate intellectual property, research data, and sensitive personal information from faculty, staff, and students. These operations often rely on sophisticated phishing schemes, credential stuffing, or exploitation of known vulnerabilities in university IT infrastructure, which can be extensive and complex. Academic institutions are frequently targeted due to their valuable research and often more open network environments compared to highly secured corporate or government entities.

Another prevalent technique observed is the use of DLL sideloading by malware. This method exploits how Windows applications load dynamic-link libraries. If a legitimate application is designed to load a DLL from a specific path, and a malicious DLL with the same name is placed in an earlier search path or a less secure location, the operating system may load the malicious DLL instead of the legitimate one. This allows the attacker's code to execute within the context of a trusted application, often bypassing application whitelisting and other endpoint security measures.

In the realm of artificial intelligence, both OpenAI and Google are reportedly exploring advancements in AI safety. This typically involves research into preventing AI models from generating harmful content, exhibiting bias, or being exploited for malicious purposes. Concurrently, a new service named Kriminal AI has emerged, offering unfiltered AI responses, which raises significant concerns about its potential misuse. Unfiltered AI models can be leveraged to generate disinformation, facilitate cybercrime, or create other harmful content without the safeguards typically implemented by responsible AI developers.

Finally, Apple is reportedly modifying its App Tracking Transparency (ATT) feature in Germany due to regulatory scrutiny. The ATT framework requires apps to obtain user permission before tracking their activity across other companies’ apps and websites. Regulatory bodies often examine such features to ensure they comply with local data protection laws and do not unfairly disadvantage certain market participants. Adjustments in specific regions are not uncommon as global technology companies navigate diverse and evolving privacy regulations.

These reported incidents underscore the persistent and evolving threat landscape, ranging from sophisticated kernel-level attacks and state-sponsored espionage to common malware techniques and the emerging challenges posed by AI. Organizations and individuals are continuously advised to implement robust security practices, including regular patching, strong authentication, user awareness training, and careful consideration of AI tool usage, to mitigate these diverse risks.

malwareespionageaivulnerabilitydata theft
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek.

CVE-2024-3094high

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

Attackers are increasingly targeting the software development lifecycle (SDLC) supply chain by compromising developer tools, CI/CD pipelines, and open-source packages. Recent attacks like the ChainDrop npm worm demonstrate sophisticated methods to steal credentials, backdoor developer environments, and propagate malware. Securing the SDLC requires a shift from reactive code scanning to strict execution control and continuous visibility across developer endpoints, build pipelines, and cloud runtimes.

breach

AWS Security makes an inscrutable choice

Quarantining leaked credentials is not good enough

ai

Say it once: introducing Bot Preference Sync

Cloudflare's new Bot Preference Sync automatically aligns your robots.txt file with your AI bot policies for Search, Agent, and Training. Easily manage which bots access your content without maintaining static files.

cloud security

Cloudflare Launches Bot Preference Sync for AI Traffic Management

Cloudflare has introduced Bot Preference Sync, a new feature designed to simplify the management of AI bot traffic. This tool automatically updates a website's robots.txt file to align with the user's AI bot configuration settings. The goal is to prevent discrepancies between stated preferences and enforced rules, ensuring better control over how AI crawlers access and use website content.

patch

Friday Squid Blogging: Neon Flying Squid

The neon flying squid can fly in formation. The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion. They were probably neon flying squid (Ommastrephes bartramii),