<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:media="http://search.yahoo.com/mrss/"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyber Security News</title>
	<atom:link href="https://cybersecuritynews.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://cybersecuritynews.com/</link>
	<description>World&#039;s #1 Premier Cybersecurity and Hacking News Portal</description>
	<lastBuildDate>Tue, 08 Sep 2026 14:02:42 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://cybersecuritynews.com/wp-content/uploads/2025/12/cropped-CSN-Favico-32x32.webp</url>
	<title>Cyber Security News</title>
	<link>https://cybersecuritynews.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">192061645</site>	<item>
		<title>Reflectiz Launches Agentic Pentesting for Websites: Up to 10x Coverage vs Conventional Pentests</title>
		<link>https://cybersecuritynews.com/reflectiz-launches-agentic-pentesting-for-websites-up-to-10x-coverage-vs-conventional-pentests/</link>
		
		<dc:creator><![CDATA[Cybernewswire]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 14:02:40 +0000</pubDate>
				<category><![CDATA[Press Release]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=162576</guid>

					<description><![CDATA[<p>Boston, MA, USA, September 8th, 2026, CyberNewswire Specialized team of AI agents that discover, attack, and validate web vulnerabilities, leveraging pre-existing site context to eliminate noise and speed remediation.&#160; Reflectiz, the continuous web exposure management company, today launched a multi-agent penetration testing platform for websites. Multiple specialized AI agents discover, attack, and validate vulnerabilities across [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/reflectiz-launches-agentic-pentesting-for-websites-up-to-10x-coverage-vs-conventional-pentests/">Reflectiz Launches Agentic Pentesting for Websites: Up to 10x Coverage vs Conventional Pentests</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>Boston, MA, USA, September 8th, 2026, CyberNewswire</strong></p>



<p class="wp-block-paragraph"><strong>Specialized team of AI agents that discover, attack, and validate web vulnerabilities, leveraging pre-existing site context to eliminate noise and speed remediation.&nbsp;</strong></p>



<p class="wp-block-paragraph">Reflectiz, the continuous web exposure management company, today launched a multi-agent penetration testing platform for websites. </p>



<p class="wp-block-paragraph">Multiple specialized AI agents discover, attack, and validate vulnerabilities across complex web environments, and because they start from an existing model of each site, they cover up to ten times more than conventional pentesting tools.</p>



<p class="wp-block-paragraph">A pentest used to be an event. An engagement, a report, done. The report described a moment. The website kept going: login, checkout, payments, dozens of third-party scripts, all probed by attackers daily.&nbsp;</p>



<p class="wp-block-paragraph">&#8220;Websites change every week and get pentested once or twice a year. That gap is where exposure builds up,&#8221; said Idan Cohen, CEO and co-founder of Reflectiz. &#8220;Teams need testing that keeps up with releases at a cost they can sustain, and trusted coverage of what was tested.&#8221;</p>



<h2 id="h-while-others-start-every-test-blind-reflectiz-already-knows-the-website" class="wp-block-heading"><strong>While others start every test blind, Reflectiz already knows the website.</strong></h2>



<p class="wp-block-paragraph">Reflectiz has spent a decade scanning thousands of production websites and holds a live model of each one: pages, scripts, third parties, domains, sensitive inputs, and behaviors. </p>



<p class="wp-block-paragraph">The pentesting agents add the attacker&#8217;s perspective to that same model.</p>



<p class="wp-block-paragraph">A finding does not arrive as a line item. It arrives with the script involved, the data it can reach, and whether real users are exposed right now, allowing teams to skip the investigation and go straight to the fix.</p>



<p class="wp-block-paragraph">&#8220;The hard part of web pentesting was never the payload. It was understanding what the application actually does,&#8221; said Ysrael Gurt, CTO and co-founder of Reflectiz. </p>



<p class="wp-block-paragraph">&#8220;Our engine has been reading live websites for years, so our agents start with a map of the site that other tools never build.&#8221;</p>



<h2 id="h-a-team-of-specialized-agents-not-another-scanner" class="wp-block-heading"><strong>A team of specialized agents, not another scanner</strong></h2>



<p class="wp-block-paragraph">The agentic pentesting runs as a coordinated team of AI agents, each with a defined role:</p>



<ul class="wp-block-list">
<li>One agent crawls the site the way a real user does, through logins, one-time codes, and 2FA, mapping what is actually there.</li>



<li>A second fingerprints the stack and works out which attacks apply where.</li>



<li>A third runs those attacks and chains what it finds.</li>



<li>The fourth matters most: an independent validator reproduces every finding before it reaches the report. False positives are removed by design.</li>
</ul>



<p class="wp-block-paragraph"><strong>The result:</strong> findings with reproduction steps and evidence, plus a coverage map of what was tested and cleared.&nbsp;</p>



<p class="wp-block-paragraph">Testing spans the full <a href="https://www.reflectiz.com/blog/owasp-top-ten-2026/" target="_blank" rel="noreferrer noopener nofollow">OWASP Top 10</a>, and teams set depth per flow, from fast predefined checks to expert-level attack chains on critical assets. </p>



<h2 id="h-completing-the-360-map-of-web-risk" class="wp-block-heading"><strong>Completing the 360° map of web risk</strong></h2>



<p class="wp-block-paragraph">The agentic pentesting, part of the new Offensive Hub, joins Security Hub and Privacy Hub on the Reflectiz platform, completing a 360° map of web risk: what runs on the website, what data it touches, and how it can be attacked.</p>



<ul class="wp-block-list">
<li><strong>One exposure picture.</strong> Findings from all three hubs cross-reference automatically, no dashboards reconciled by hand.</li>



<li><strong>Guided fixes.</strong> Atlas, the Reflectiz AI remediation agent, explains each risk and walks the team through the fix.</li>



<li><strong>Existing workflows.</strong> Results route into current operations through a REST API, CI/CD triggers, and Slack alerts.</li>
</ul>



<h2 id="h-see-it-live" class="wp-block-heading"><strong>See it live</strong></h2>



<p class="wp-block-paragraph">Reflectiz founders Idan Cohen and Ysrael Gurt will demonstrate the agentic pentesting in a live webinar on September 15 at 11 AM ET / 6 PM CET.</p>



<p class="wp-block-paragraph">Registration: <a href="https://www.reflectiz.com/lp/founders-case-study-webinar/" target="_blank" rel="noreferrer noopener nofollow">https://www.reflectiz.com/lp/founders-case-study-webinar/</a></p>



<p class="wp-block-paragraph">Product information: <a href="https://www.reflectiz.com/offensive-hub/" target="_blank" rel="noreferrer noopener nofollow">Reflectiz Offensive Hub</a> | <a href="https://www.youtube.com/watch?v=Vn2W2RxSnSo" target="_blank" rel="noreferrer noopener nofollow">Walkthrough Video</a></p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhrsA7-MvDbsUuYjT1N7uPYFLmwYQO0AC8SQGKXUWKqbuabjtjExshKzpoTAJZoD6bgZXooV6bC3ZtkevRIJ-sCMMHN61bC7PfGhGnWLW7Se9kiKc4uzRtrE8VXLzyt-no3vUIgFRfTdv7Hn9lWyGNOdDe2gTGmWNYScmaBlq0DKJ5kzy8uUK8DN89hq7U/s1600/bfb547d0-1fbb-47ef-8c78-05b790fcfe3e.webp" alt=""/></figure>



<h2 id="h-about-reflectiz" class="wp-block-heading"><strong>About Reflectiz</strong></h2>



<p class="wp-block-paragraph">Reflectiz is the continuous web exposure management company. Its agentless, outside-in platform monitors, tests, and secures the entire web layer, from third-party scripts and web privacy risk to agentic penetration testing of the live site. </p>



<p class="wp-block-paragraph">Reflectiz helps enterprises in retail, finance, travel, insurance, healthcare, and gaming meet PCI DSS, DORA, NIS2, and global privacy requirements without touching a line of code. Learn more at <a href="https://www.reflectiz.com" target="_blank" rel="noreferrer noopener nofollow">https://www.reflectiz.com</a>.</p>



<h2 id="h-contact" class="wp-block-heading"><strong>Contact</strong></h2>



<p class="wp-block-paragraph"><strong>Marketing Manager</strong></p>



<p class="wp-block-paragraph"><strong>Oran Frenkel</strong></p>



<p class="wp-block-paragraph"><strong>Reflectiz</strong></p>



<p class="wp-block-paragraph"><strong>oran.f@reflectiz.com</strong></p>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://cybersecuritynews.com/reflectiz-launches-agentic-pentesting-for-websites-up-to-10x-coverage-vs-conventional-pentests/">Reflectiz Launches Agentic Pentesting for Websites: Up to 10x Coverage vs Conventional Pentests</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjt9FuSZY2wO98OtLQ6-GeLD_UiBWr5lY_UJo47Uey6Haen5vbZ_5LR8ogflsR7hpPp9di2IHddNORhZjhBIYD5DU0FXsGDHQWygw1gvpnWqpF1DRNkRqZ9aptbMyOCq21FuDN2E1W6BS5x-sY2kFXAmyoeNDaIjf7fHM2aCYpaMR1HTsqg-ngQnohy6mA/s1600/Insignary%20Launches%20Clarity%20On-Demand%20SBOMs,%20No%20Annual%20Commitment%20Required%20Toronto,%20Canada,%20July%2015th,%202026,%20CyberNewswire%20Enterprise-grade%20binary%20software%20verification%20for%20one%20proj%20-%202026-09-08T185728.44.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">162576</post-id>	</item>
		<item>
		<title>Mars Security Launches Real-Time Intel-to-Detection Engine That Turns Live Threat Intelligence Into Backtested Detections in Minutes</title>
		<link>https://cybersecuritynews.com/mars-security-launches-real-time-intel-to-detection-engine-that-turns-live-threat-intelligence-into-backtested-detections-in-minutes/</link>
		
		<dc:creator><![CDATA[Cybernewswire]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 13:20:42 +0000</pubDate>
				<category><![CDATA[Press Release]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=162565</guid>

					<description><![CDATA[<p>New York, NY, United States, September 8th, 2026, CyberNewswire Mars Security, the autonomous threat hunting and detection engineering platform founded by offensive security veterans, today announced Real-Time Intel-Based Detection, a capability that turns newly published threat intelligence into validated, ready-to-deploy detection rules within minutes of release. Built by former offensive operators, the new capability converts [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/mars-security-launches-real-time-intel-to-detection-engine-that-turns-live-threat-intelligence-into-backtested-detections-in-minutes/">Mars Security Launches Real-Time Intel-to-Detection Engine That Turns Live Threat Intelligence Into Backtested Detections in Minutes</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>New York, NY, United States, September 8th, 2026, CyberNewswire</strong></p>



<p class="wp-block-paragraph"><a href="https://marssec.ai/" target="_blank" rel="noreferrer noopener nofollow">Mars Security,</a> the autonomous threat hunting and detection engineering platform founded by offensive security veterans, today announced Real-Time Intel-Based Detection, a capability that turns newly published threat intelligence into validated, ready-to-deploy detection rules within minutes of release.</p>



<p class="wp-block-paragraph">Built by former offensive operators, the new capability converts advisories from CISA, Mandiant, and other intelligence sources into MITRE ATT&amp;CK-mapped detection rules across CrowdStrike, Wiz, Splunk, and cloud telemetry, each one tested against 30 days of the customer’s own data before it goes live.</p>



<p class="wp-block-paragraph">Mars believes it is the first platform to automate the complete path from threat advisory to production detection, including backtesting against the customer’s own environment, with no data ingestion and no changes to the existing security stack.</p>



<p class="wp-block-paragraph">Every security team already pays for threat intelligence. Very little of it becomes a working detection. When CISA, Mandiant, Unit 42 or Microsoft Threat Intelligence publishes a report on a new campaign, malware family or APT group, a detection engineer still has to read it, pull the indicators and techniques, work out which log source can see them, write the query, test it, tune it and deploy it. Across most SOCs that cycle takes days to weeks. </p>



<p class="wp-block-paragraph">Attackers rotate infrastructure in hours. That delay, <a href="https://marssec.ai/blog/threat-intelligence-useless-if-never-becomes-detection" target="_blank" rel="noreferrer noopener nofollow">the gap between knowing about a threat and being able to detect it</a>, is where most successful intrusions sit.</p>



<p class="wp-block-paragraph">Mars now closes that gap automatically.</p>



<h2 id="h-how-it-works" class="wp-block-heading"><strong>How it works</strong></h2>



<p class="wp-block-paragraph">As new intelligence becomes available, Mars extracts the relevant indicators, techniques and infrastructure, maps them to MITRE ATT&amp;CK, and writes the detection in the native query language of whichever telemetry can actually see the threat: CrowdStrike Falcon, Wiz, Splunk, firewall logs, Linux Sysmon, identity providers, AWS telemetry, or data lakes such as Snowflake and Databricks. </p>



<p class="wp-block-paragraph">Each rule carries a severity rating and lands in the team’s queue for review. <strong>Accept Rule</strong> pushes it live. <strong>Dismiss</strong> clears it.</p>



<p class="wp-block-paragraph">Nothing ships untested. Before a rule is offered, Mars runs the exact query against the customer’s previous 30 days of data and shows how many events it would have matched and how many of those would have been false positives. </p>



<p class="wp-block-paragraph">Teams can rerun the backtest over any window they choose. The same scrutiny applies to the underlying indicators: domains, IP addresses and hashes are scored against their false-positive history, and anything too broad, too old or historically noisy is dropped before it ever reaches a rule.</p>



<p class="wp-block-paragraph">“We spent years on the offensive side, and the thing that surprised us most was how rarely anyone saw us, even when the intel on our tradecraft was already public. </p>



<p class="wp-block-paragraph">Threat intelligence has always told security teams what is happening in the world. It never handed them the detection to find it in their own environment. Mars does that now, and it tests the detection against your data before it goes anywhere near production.” <strong>– Shahaf Galili, Co-Founder and CEO, Mars Security.</strong></p>



<h2 id="h-coverage-not-just-alerts" class="wp-block-heading"><strong>Coverage, not just alerts</strong></h2>



<p class="wp-block-paragraph">The engine also works in the other direction. Mars continuously maps the customer’s existing detection coverage against the telemetry already connected and flags the gaps that matter. </p>



<p class="wp-block-paragraph">Recent recommendations include AWS CloudTrail logging tampering, Route 53 domain transfer abuse, pass-the-hash lateral movement and suspicious Microsoft Graph API activity. </p>



<p class="wp-block-paragraph">For teams running detection-as-code, select recommendations arrive as an open pull request, ready to review and merge.</p>



<p class="wp-block-paragraph">That matters because static rules break the moment attacker tradecraft shifts. Mars was built by people who spent years watching detections fail from the other side, and its hunt library targets behavior rather than signatures so coverage holds as adversaries change tools. </p>



<p class="wp-block-paragraph">The same engine now extends to newer attack surfaces, including monitoring AI coding agents and the credentials they leak into logs, without buying another tool to watch them.</p>



<p class="wp-block-paragraph">“A SOC should not need a two-week backlog to act on a report that took an attacker two hours to make obsolete. When the intel lands, the detection should already be written, already tested against your data, and waiting for a click.” <strong>– Ran Lerer, Co-Founder and CTO, Mars Security.</strong></p>



<p class="wp-block-paragraph">&#8220;A campaign advisory used to sit in a queue for days before it became a rule anyone trusted. With Mars, it shows up already mapped, already tested against the environment it&#8217;s meant to protect, and it actually holds up. That is the first time detection has felt ahead of the threat instead of behind it.&#8221; – <strong>Andy Ellis, Former CISO, Akamai Technologies.</strong></p>



<h2 id="h-availability" class="wp-block-heading"><strong>Availability</strong></h2>



<p class="wp-block-paragraph">Real-Time Intel-Based Detection is available now to all Mars Security customers at no additional cost. Mars deploys in hours, requires no data ingestion, no tool replacement and no additional detection engineering headcount, and is available on AWS Marketplace.</p>



<p class="wp-block-paragraph">Security teams can request a demo or read the technical documentation on the <a href="https://marssec.ai/" target="_blank" rel="noreferrer noopener nofollow">Mars website</a>.</p>



<h2 id="h-about-mars-security" class="wp-block-heading"><strong>About Mars Security</strong></h2>



<p class="wp-block-paragraph">Mars Security is the autonomous threat hunting and detection engineering platform that continuously converts threat intelligence into validated detections across an organization’s existing security stack. </p>



<p class="wp-block-paragraph">Founded by offensive security veterans <strong>Shahaf Galili, Ran Lerer and Matan Caspi</strong>, who bring more than 50 years of combined hands-on cyber offense experience, Mars queries SIEM, EDR, identity, cloud and data lake telemetry in place, with no ingestion and no rip-and-replace, and turns advisories into MITRE ATT&amp;CK-mapped, backtested detection rules in minutes. </p>



<p class="wp-block-paragraph">Mars maps detection coverage gaps, delivers a behavior-based threat hunting library built from years of offensive operations, and replaces the patch treadmill with continuous detection engineering. </p>



<p class="wp-block-paragraph">Mars is SOC 2 compliant, available on AWS Marketplace, and backed by <strong>TLV Ventures, Jibe Ventures, Bullet Ventures, CCL and XPS</strong>.</p>



<p class="wp-block-paragraph">Learn more at <a href="https://marssec.ai/" target="_blank" rel="noreferrer noopener nofollow">marssec.ai</a>, download the <a href="https://marssec.ai/onepager" target="_blank" rel="noreferrer noopener nofollow">Mars one-pager</a>, read the Mars blog or follow Mars Security on <a href="https://www.linkedin.com/company/marssec/" target="_blank" rel="noreferrer noopener nofollow">LinkedIn</a>.</p>



<h2 id="h-contact" class="wp-block-heading"><strong>Contact</strong></h2>



<p class="wp-block-paragraph"><strong>Nir Lerer</strong></p>



<p class="wp-block-paragraph"><strong>Mars Security</strong></p>



<p class="wp-block-paragraph"><strong>Nir@Marssec.ai</strong></p>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://cybersecuritynews.com/mars-security-launches-real-time-intel-to-detection-engine-that-turns-live-threat-intelligence-into-backtested-detections-in-minutes/">Mars Security Launches Real-Time Intel-to-Detection Engine That Turns Live Threat Intelligence Into Backtested Detections in Minutes</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_cLZdSy0uwelZwIVsX3O8ev7dtW6DMFqxpHQZWohP0u5jcO9Cy-bwDiO_EYgmw8sM_-C-sTLdvxSexVdOcLOH4zWlUHv_Th4e3lu6m9hz9lYyg8J7Ox-fUlvP-54VS_RlroF1UIp3pWS5SRZ0wGJXaA60mdWrmTf4G5ZS3d_2KDZ6aIaqcWPHtJC0Mf8/s1600/Insignary%20Launches%20Clarity%20On-Demand%20SBOMs,%20No%20Annual%20Commitment%20Required%20Toronto,%20Canada,%20July%2015th,%202026,%20CyberNewswire%20Enterprise-grade%20binary%20software%20verification%20for%20one%20proj%20-%202026-09-08T183314.13.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">162565</post-id>	</item>
		<item>
		<title>Claude Mythos AI Autonomously Executes Full Cyber Kill Chain Without Human Guidance</title>
		<link>https://cybersecuritynews.com/claude-mythos-ai/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 12:50:47 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=162561</guid>

					<description><![CDATA[<p>Claude Mythos is the first model reported to complete a cyber kill chain without step-by-step human direction. The finding does not describe malware or a confirmed victim breach. It is a controlled test, but shows how quickly autonomous attack capability is advancing. The concern is speed. The model found weaknesses, entered a defended enterprise network, [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/claude-mythos-ai/">Claude Mythos AI Autonomously Executes Full Cyber Kill Chain Without Human Guidance</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Claude Mythos is the first model reported to complete a cyber kill chain without step-by-step human direction. The finding does not describe malware or a confirmed victim breach. It is a controlled test, but shows how quickly autonomous attack capability is advancing.<a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58939690-1282-4a9e-83b8-3b82cdfb252f/The-Offensive-Frontier-AI-as-The-Attacker.pdf?AWSAccessKeyId=ASIA2F3EMEYEZXNPCLW4&amp;Signature=gVewioyNOYwLX8T%2Bx%2BxWkV355C4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCNxLTgVCrgVhjkz%2BQERTtpqxNOX8xgmMvlnm0YnMW%2BLgIgIreZx7qPYRZTcebez9rA%2BbpgH2QTdNasReKR7xeJvTgq8wQIVRABGgw2OTk3NTMzMDk3MDUiDPoI5WNiL8xKQV6TmirQBPnP%2BJYRugGohMojA6rebEnXl9G8xCnTAgUoh%2BahpbAX3lr0TmJ9O4TfpZw4wsHwVBpKOcFPtVq6mBj0Wgqn1mqaCV1hIRN3D0c4oW%2BKEwwQAZyVcSNs%2BtAy5r2rUKs9F9VhehVpEttDTQTNxu6NXbJud1np7QJvAKF8x%2BoZli%2FkK1CHLfHIBUkj0lbazy064xArx2Xcx7i9BW5vReTQRx%2BiUpcSXfrxTfiUvwx87SCcgqFZOIwulBOs3slrwWKE16s9%2FEmJtmwuwqNfy3a6NCFkl5tZa834alI1arvcqt0SQY7v34BBHCJRzTU6GeVB%2BUtbTcJ4nkTfZC9fKLHYwsJO1pl4aGvmoaJ4H9cLF7nHyC0vlsnELZVv8r9PkTcwo0KRNV%2Bf%2BeCorbF%2BUqAzU6eqQpIpe1xCkCLTHYtkvwnXed4ZDFXXQRIH19953EiSm0r5I0ltryGz8vId%2FRq%2FgLC9cBy1A4Brozj0Z1XH3Vpb4pUWk1ZAbFHNl4lSI4loQz3FzfKiJn37%2F%2F2KjxMfHUj1XiMj%2BCBc0oeyx%2FmkSy8SsjYRx09OvAzLC4gSGPehGSSxvZMs4X7gTf5rT98SwKMba%2BXEbthoBEAaRbAFKx7KGNqgC%2FV7UYrMcZk3%2BqkyK174jYAhAkExZQ7Sl2kWvhbfxa8TEoLgo8H3aySqgb8lCVwwHRA%2Fm6Cm7TnSRz2gHu0Eat55sC5nWtydIQqCCp4mUdYMMLJzhvnDEQH5UYS%2BUdZQtOlH2nunFufPMZ9HAUKGAR6p4py%2BMrrsL9aeQFYwwPD%2F1AY6mAF36wgDeCTrB6hln6qv4luoaOT6ItC2%2B5DJzfw%2BGqTp%2FbcH0sDMPqqCgRqSifEdv70pqQl6xXsm8CJ8LHk3iljIunBLn7%2Bf8sR3E%2FjTQME2C%2B25DKzPgwCIvJFHIjD0yU3%2FfkwlfKbDYvuNofAsuAWftavy%2Ft9gBDkVmh%2Fu%2F7bFhQTH8Sq3w0OjDmU6LDy7AONPJ1wUrv7ecg%3D%3D&amp;Expires=1788872211"></a><a rel="noopener" target="_blank" href="https://www.boozallen.com/insights/cyber/cyber-weapon-index.html"></a></p>



<p class="wp-block-paragraph">The concern is speed. The model found weaknesses, entered a defended enterprise network, collected credentials, raised privileges, moved between systems and reached domain administrator control. </p>



<p class="wp-block-paragraph">Those are stages defenders try to interrupt during an intrusion. <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58939690-1282-4a9e-83b8-3b82cdfb252f/The-Offensive-Frontier-AI-as-The-Attacker.pdf?AWSAccessKeyId=ASIA2F3EMEYEZXNPCLW4&amp;Signature=gVewioyNOYwLX8T%2Bx%2BxWkV355C4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCNxLTgVCrgVhjkz%2BQERTtpqxNOX8xgmMvlnm0YnMW%2BLgIgIreZx7qPYRZTcebez9rA%2BbpgH2QTdNasReKR7xeJvTgq8wQIVRABGgw2OTk3NTMzMDk3MDUiDPoI5WNiL8xKQV6TmirQBPnP%2BJYRugGohMojA6rebEnXl9G8xCnTAgUoh%2BahpbAX3lr0TmJ9O4TfpZw4wsHwVBpKOcFPtVq6mBj0Wgqn1mqaCV1hIRN3D0c4oW%2BKEwwQAZyVcSNs%2BtAy5r2rUKs9F9VhehVpEttDTQTNxu6NXbJud1np7QJvAKF8x%2BoZli%2FkK1CHLfHIBUkj0lbazy064xArx2Xcx7i9BW5vReTQRx%2BiUpcSXfrxTfiUvwx87SCcgqFZOIwulBOs3slrwWKE16s9%2FEmJtmwuwqNfy3a6NCFkl5tZa834alI1arvcqt0SQY7v34BBHCJRzTU6GeVB%2BUtbTcJ4nkTfZC9fKLHYwsJO1pl4aGvmoaJ4H9cLF7nHyC0vlsnELZVv8r9PkTcwo0KRNV%2Bf%2BeCorbF%2BUqAzU6eqQpIpe1xCkCLTHYtkvwnXed4ZDFXXQRIH19953EiSm0r5I0ltryGz8vId%2FRq%2FgLC9cBy1A4Brozj0Z1XH3Vpb4pUWk1ZAbFHNl4lSI4loQz3FzfKiJn37%2F%2F2KjxMfHUj1XiMj%2BCBc0oeyx%2FmkSy8SsjYRx09OvAzLC4gSGPehGSSxvZMs4X7gTf5rT98SwKMba%2BXEbthoBEAaRbAFKx7KGNqgC%2FV7UYrMcZk3%2BqkyK174jYAhAkExZQ7Sl2kWvhbfxa8TEoLgo8H3aySqgb8lCVwwHRA%2Fm6Cm7TnSRz2gHu0Eat55sC5nWtydIQqCCp4mUdYMMLJzhvnDEQH5UYS%2BUdZQtOlH2nunFufPMZ9HAUKGAR6p4py%2BMrrsL9aeQFYwwPD%2F1AY6mAF36wgDeCTrB6hln6qv4luoaOT6ItC2%2B5DJzfw%2BGqTp%2FbcH0sDMPqqCgRqSifEdv70pqQl6xXsm8CJ8LHk3iljIunBLn7%2Bf8sR3E%2FjTQME2C%2B25DKzPgwCIvJFHIjD0yU3%2FfkwlfKbDYvuNofAsuAWftavy%2Ft9gBDkVmh%2Fu%2F7bFhQTH8Sq3w0OjDmU6LDy7AONPJ1wUrv7ecg%3D%3D&amp;Expires=1788872211" target="_blank" rel="noopener"></a>GitHub hosts projects and discussions using the Claude Mythos name, but did not identify a malware campaign. </p>



<p class="wp-block-paragraph">The finding comes from Booz Allen’s assessment of autonomous models. It is a benchmark result, not evidence of a named program independently attacking organizations.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58939690-1282-4a9e-83b8-3b82cdfb252f/The-Offensive-Frontier-AI-as-The-Attacker.pdf?AWSAccessKeyId=ASIA2F3EMEYEZXNPCLW4&amp;Signature=gVewioyNOYwLX8T%2Bx%2BxWkV355C4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCNxLTgVCrgVhjkz%2BQERTtpqxNOX8xgmMvlnm0YnMW%2BLgIgIreZx7qPYRZTcebez9rA%2BbpgH2QTdNasReKR7xeJvTgq8wQIVRABGgw2OTk3NTMzMDk3MDUiDPoI5WNiL8xKQV6TmirQBPnP%2BJYRugGohMojA6rebEnXl9G8xCnTAgUoh%2BahpbAX3lr0TmJ9O4TfpZw4wsHwVBpKOcFPtVq6mBj0Wgqn1mqaCV1hIRN3D0c4oW%2BKEwwQAZyVcSNs%2BtAy5r2rUKs9F9VhehVpEttDTQTNxu6NXbJud1np7QJvAKF8x%2BoZli%2FkK1CHLfHIBUkj0lbazy064xArx2Xcx7i9BW5vReTQRx%2BiUpcSXfrxTfiUvwx87SCcgqFZOIwulBOs3slrwWKE16s9%2FEmJtmwuwqNfy3a6NCFkl5tZa834alI1arvcqt0SQY7v34BBHCJRzTU6GeVB%2BUtbTcJ4nkTfZC9fKLHYwsJO1pl4aGvmoaJ4H9cLF7nHyC0vlsnELZVv8r9PkTcwo0KRNV%2Bf%2BeCorbF%2BUqAzU6eqQpIpe1xCkCLTHYtkvwnXed4ZDFXXQRIH19953EiSm0r5I0ltryGz8vId%2FRq%2FgLC9cBy1A4Brozj0Z1XH3Vpb4pUWk1ZAbFHNl4lSI4loQz3FzfKiJn37%2F%2F2KjxMfHUj1XiMj%2BCBc0oeyx%2FmkSy8SsjYRx09OvAzLC4gSGPehGSSxvZMs4X7gTf5rT98SwKMba%2BXEbthoBEAaRbAFKx7KGNqgC%2FV7UYrMcZk3%2BqkyK174jYAhAkExZQ7Sl2kWvhbfxa8TEoLgo8H3aySqgb8lCVwwHRA%2Fm6Cm7TnSRz2gHu0Eat55sC5nWtydIQqCCp4mUdYMMLJzhvnDEQH5UYS%2BUdZQtOlH2nunFufPMZ9HAUKGAR6p4py%2BMrrsL9aeQFYwwPD%2F1AY6mAF36wgDeCTrB6hln6qv4luoaOT6ItC2%2B5DJzfw%2BGqTp%2FbcH0sDMPqqCgRqSifEdv70pqQl6xXsm8CJ8LHk3iljIunBLn7%2Bf8sR3E%2FjTQME2C%2B25DKzPgwCIvJFHIjD0yU3%2FfkwlfKbDYvuNofAsuAWftavy%2Ft9gBDkVmh%2Fu%2F7bFhQTH8Sq3w0OjDmU6LDy7AONPJ1wUrv7ecg%3D%3D&amp;Expires=1788872211" target="_blank" rel="noopener"></a><a href="https://github.com/topics/claude-mythos?o=desc&amp;s=forks" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph"><a href="https://www.boozallen.com/insights/cyber/cyber-weapon-index.html" data-type="link" data-id="https://www.boozallen.com/insights/cyber/cyber-weapon-index.html" target="_blank" rel="noreferrer noopener nofollow">Booz Allen said in a report</a> shared with Cyber Security News (CSN) that it tested 18 U.S. and Chinese models as autonomous attackers against a production-grade enterprise network. Researchers used network and host telemetry to measure actions, rather than accept model claims.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58939690-1282-4a9e-83b8-3b82cdfb252f/The-Offensive-Frontier-AI-as-The-Attacker.pdf?AWSAccessKeyId=ASIA2F3EMEYEZXNPCLW4&amp;Signature=gVewioyNOYwLX8T%2Bx%2BxWkV355C4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCNxLTgVCrgVhjkz%2BQERTtpqxNOX8xgmMvlnm0YnMW%2BLgIgIreZx7qPYRZTcebez9rA%2BbpgH2QTdNasReKR7xeJvTgq8wQIVRABGgw2OTk3NTMzMDk3MDUiDPoI5WNiL8xKQV6TmirQBPnP%2BJYRugGohMojA6rebEnXl9G8xCnTAgUoh%2BahpbAX3lr0TmJ9O4TfpZw4wsHwVBpKOcFPtVq6mBj0Wgqn1mqaCV1hIRN3D0c4oW%2BKEwwQAZyVcSNs%2BtAy5r2rUKs9F9VhehVpEttDTQTNxu6NXbJud1np7QJvAKF8x%2BoZli%2FkK1CHLfHIBUkj0lbazy064xArx2Xcx7i9BW5vReTQRx%2BiUpcSXfrxTfiUvwx87SCcgqFZOIwulBOs3slrwWKE16s9%2FEmJtmwuwqNfy3a6NCFkl5tZa834alI1arvcqt0SQY7v34BBHCJRzTU6GeVB%2BUtbTcJ4nkTfZC9fKLHYwsJO1pl4aGvmoaJ4H9cLF7nHyC0vlsnELZVv8r9PkTcwo0KRNV%2Bf%2BeCorbF%2BUqAzU6eqQpIpe1xCkCLTHYtkvwnXed4ZDFXXQRIH19953EiSm0r5I0ltryGz8vId%2FRq%2FgLC9cBy1A4Brozj0Z1XH3Vpb4pUWk1ZAbFHNl4lSI4loQz3FzfKiJn37%2F%2F2KjxMfHUj1XiMj%2BCBc0oeyx%2FmkSy8SsjYRx09OvAzLC4gSGPehGSSxvZMs4X7gTf5rT98SwKMba%2BXEbthoBEAaRbAFKx7KGNqgC%2FV7UYrMcZk3%2BqkyK174jYAhAkExZQ7Sl2kWvhbfxa8TEoLgo8H3aySqgb8lCVwwHRA%2Fm6Cm7TnSRz2gHu0Eat55sC5nWtydIQqCCp4mUdYMMLJzhvnDEQH5UYS%2BUdZQtOlH2nunFufPMZ9HAUKGAR6p4py%2BMrrsL9aeQFYwwPD%2F1AY6mAF36wgDeCTrB6hln6qv4luoaOT6ItC2%2B5DJzfw%2BGqTp%2FbcH0sDMPqqCgRqSifEdv70pqQl6xXsm8CJ8LHk3iljIunBLn7%2Bf8sR3E%2FjTQME2C%2B25DKzPgwCIvJFHIjD0yU3%2FfkwlfKbDYvuNofAsuAWftavy%2Ft9gBDkVmh%2Fu%2F7bFhQTH8Sq3w0OjDmU6LDy7AONPJ1wUrv7ecg%3D%3D&amp;Expires=1788872211" target="_blank" rel="noopener"></a><a href="https://www.boozallen.com/insights/cyber/cyber-weapon-index.html" target="_blank" rel="noopener"></a></p>



<h2 id="h-claude-mythos-ai-autonomously-executes-full-cyber-kill-chain" class="wp-block-heading"><strong>Claude Mythos AI Autonomously Executes Full Cyber Kill Chain</strong></h2>



<p class="wp-block-paragraph">The Cyber Weapon Index gave Claude Mythos an 80 score, combining 74 for vulnerability research and 86 for kill-chain attainment. </p>



<p class="wp-block-paragraph">It was the only model assessed as reaching the final objective. Researchers said it moved from a stolen employee credential to administrator-level control in every credentialed attempt.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58939690-1282-4a9e-83b8-3b82cdfb252f/The-Offensive-Frontier-AI-as-The-Attacker.pdf?AWSAccessKeyId=ASIA2F3EMEYEZXNPCLW4&amp;Signature=gVewioyNOYwLX8T%2Bx%2BxWkV355C4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCNxLTgVCrgVhjkz%2BQERTtpqxNOX8xgmMvlnm0YnMW%2BLgIgIreZx7qPYRZTcebez9rA%2BbpgH2QTdNasReKR7xeJvTgq8wQIVRABGgw2OTk3NTMzMDk3MDUiDPoI5WNiL8xKQV6TmirQBPnP%2BJYRugGohMojA6rebEnXl9G8xCnTAgUoh%2BahpbAX3lr0TmJ9O4TfpZw4wsHwVBpKOcFPtVq6mBj0Wgqn1mqaCV1hIRN3D0c4oW%2BKEwwQAZyVcSNs%2BtAy5r2rUKs9F9VhehVpEttDTQTNxu6NXbJud1np7QJvAKF8x%2BoZli%2FkK1CHLfHIBUkj0lbazy064xArx2Xcx7i9BW5vReTQRx%2BiUpcSXfrxTfiUvwx87SCcgqFZOIwulBOs3slrwWKE16s9%2FEmJtmwuwqNfy3a6NCFkl5tZa834alI1arvcqt0SQY7v34BBHCJRzTU6GeVB%2BUtbTcJ4nkTfZC9fKLHYwsJO1pl4aGvmoaJ4H9cLF7nHyC0vlsnELZVv8r9PkTcwo0KRNV%2Bf%2BeCorbF%2BUqAzU6eqQpIpe1xCkCLTHYtkvwnXed4ZDFXXQRIH19953EiSm0r5I0ltryGz8vId%2FRq%2FgLC9cBy1A4Brozj0Z1XH3Vpb4pUWk1ZAbFHNl4lSI4loQz3FzfKiJn37%2F%2F2KjxMfHUj1XiMj%2BCBc0oeyx%2FmkSy8SsjYRx09OvAzLC4gSGPehGSSxvZMs4X7gTf5rT98SwKMba%2BXEbthoBEAaRbAFKx7KGNqgC%2FV7UYrMcZk3%2BqkyK174jYAhAkExZQ7Sl2kWvhbfxa8TEoLgo8H3aySqgb8lCVwwHRA%2Fm6Cm7TnSRz2gHu0Eat55sC5nWtydIQqCCp4mUdYMMLJzhvnDEQH5UYS%2BUdZQtOlH2nunFufPMZ9HAUKGAR6p4py%2BMrrsL9aeQFYwwPD%2F1AY6mAF36wgDeCTrB6hln6qv4luoaOT6ItC2%2B5DJzfw%2BGqTp%2FbcH0sDMPqqCgRqSifEdv70pqQl6xXsm8CJ8LHk3iljIunBLn7%2Bf8sR3E%2FjTQME2C%2B25DKzPgwCIvJFHIjD0yU3%2FfkwlfKbDYvuNofAsuAWftavy%2Ft9gBDkVmh%2Fu%2F7bFhQTH8Sq3w0OjDmU6LDy7AONPJ1wUrv7ecg%3D%3D&amp;Expires=1788872211" target="_blank" rel="noopener"></a><a href="https://www.boozallen.com/insights/cyber/cyber-weapon-index.html" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">The harder scenario began with no credentials. The report says Claude Mythos penetrated from outside and worked out how to raise its access, instead of following a fixed plan. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_MzPEpgErU1INO6hK5RSGIG4P0mfNm3YxyrR6hhGo2C2jHWXnaNxoLSIqv-f84d1iHfzeudchlVaYgIQAVVZfOvt4d3btWVHlDPrKShorafJHc05juXK3-9zXVOfemNLVLul8kOp_Au2QoMLOobKernf7ozyLw_nCfdGMjrBsiWuoch3tF8EGIOF0PUs/s1600/Attack%20lifecycle%20(Source%20-%20GitHub).webp" alt="" /><figcaption class="wp-element-caption">Attack lifecycle (Source &#8211; GitHub)</figcaption></figure>
</div>


<p class="wp-block-paragraph">The reported <a href="https://cybersecuritynews.com/first-ever-ai-agent-cyberattack/" target="_blank" rel="noopener">autonomous AI agent breach</a> illustrates why this development has drawn attention. <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58939690-1282-4a9e-83b8-3b82cdfb252f/The-Offensive-Frontier-AI-as-The-Attacker.pdf?AWSAccessKeyId=ASIA2F3EMEYEZXNPCLW4&amp;Signature=gVewioyNOYwLX8T%2Bx%2BxWkV355C4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCNxLTgVCrgVhjkz%2BQERTtpqxNOX8xgmMvlnm0YnMW%2BLgIgIreZx7qPYRZTcebez9rA%2BbpgH2QTdNasReKR7xeJvTgq8wQIVRABGgw2OTk3NTMzMDk3MDUiDPoI5WNiL8xKQV6TmirQBPnP%2BJYRugGohMojA6rebEnXl9G8xCnTAgUoh%2BahpbAX3lr0TmJ9O4TfpZw4wsHwVBpKOcFPtVq6mBj0Wgqn1mqaCV1hIRN3D0c4oW%2BKEwwQAZyVcSNs%2BtAy5r2rUKs9F9VhehVpEttDTQTNxu6NXbJud1np7QJvAKF8x%2BoZli%2FkK1CHLfHIBUkj0lbazy064xArx2Xcx7i9BW5vReTQRx%2BiUpcSXfrxTfiUvwx87SCcgqFZOIwulBOs3slrwWKE16s9%2FEmJtmwuwqNfy3a6NCFkl5tZa834alI1arvcqt0SQY7v34BBHCJRzTU6GeVB%2BUtbTcJ4nkTfZC9fKLHYwsJO1pl4aGvmoaJ4H9cLF7nHyC0vlsnELZVv8r9PkTcwo0KRNV%2Bf%2BeCorbF%2BUqAzU6eqQpIpe1xCkCLTHYtkvwnXed4ZDFXXQRIH19953EiSm0r5I0ltryGz8vId%2FRq%2FgLC9cBy1A4Brozj0Z1XH3Vpb4pUWk1ZAbFHNl4lSI4loQz3FzfKiJn37%2F%2F2KjxMfHUj1XiMj%2BCBc0oeyx%2FmkSy8SsjYRx09OvAzLC4gSGPehGSSxvZMs4X7gTf5rT98SwKMba%2BXEbthoBEAaRbAFKx7KGNqgC%2FV7UYrMcZk3%2BqkyK174jYAhAkExZQ7Sl2kWvhbfxa8TEoLgo8H3aySqgb8lCVwwHRA%2Fm6Cm7TnSRz2gHu0Eat55sC5nWtydIQqCCp4mUdYMMLJzhvnDEQH5UYS%2BUdZQtOlH2nunFufPMZ9HAUKGAR6p4py%2BMrrsL9aeQFYwwPD%2F1AY6mAF36wgDeCTrB6hln6qv4luoaOT6ItC2%2B5DJzfw%2BGqTp%2FbcH0sDMPqqCgRqSifEdv70pqQl6xXsm8CJ8LHk3iljIunBLn7%2Bf8sR3E%2FjTQME2C%2B25DKzPgwCIvJFHIjD0yU3%2FfkwlfKbDYvuNofAsuAWftavy%2Ft9gBDkVmh%2Fu%2F7bFhQTH8Sq3w0OjDmU6LDy7AONPJ1wUrv7ecg%3D%3D&amp;Expires=1788872211" target="_blank" rel="noopener"></a><a href="https://cybersecuritynews.com/first-ever-ai-agent-cyberattack/" target="_blank" rel="noopener"></a>The test examined whether models could spot weaknesses in compiled software without source code. </p>



<p class="wp-block-paragraph">Only frontier Anthropic models identified the previously unseen flaw used in testing, and only Claude Mythos reportedly exploited it. The result is from a defined setting, not proof of universal performance.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58939690-1282-4a9e-83b8-3b82cdfb252f/The-Offensive-Frontier-AI-as-The-Attacker.pdf?AWSAccessKeyId=ASIA2F3EMEYEZXNPCLW4&amp;Signature=gVewioyNOYwLX8T%2Bx%2BxWkV355C4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCNxLTgVCrgVhjkz%2BQERTtpqxNOX8xgmMvlnm0YnMW%2BLgIgIreZx7qPYRZTcebez9rA%2BbpgH2QTdNasReKR7xeJvTgq8wQIVRABGgw2OTk3NTMzMDk3MDUiDPoI5WNiL8xKQV6TmirQBPnP%2BJYRugGohMojA6rebEnXl9G8xCnTAgUoh%2BahpbAX3lr0TmJ9O4TfpZw4wsHwVBpKOcFPtVq6mBj0Wgqn1mqaCV1hIRN3D0c4oW%2BKEwwQAZyVcSNs%2BtAy5r2rUKs9F9VhehVpEttDTQTNxu6NXbJud1np7QJvAKF8x%2BoZli%2FkK1CHLfHIBUkj0lbazy064xArx2Xcx7i9BW5vReTQRx%2BiUpcSXfrxTfiUvwx87SCcgqFZOIwulBOs3slrwWKE16s9%2FEmJtmwuwqNfy3a6NCFkl5tZa834alI1arvcqt0SQY7v34BBHCJRzTU6GeVB%2BUtbTcJ4nkTfZC9fKLHYwsJO1pl4aGvmoaJ4H9cLF7nHyC0vlsnELZVv8r9PkTcwo0KRNV%2Bf%2BeCorbF%2BUqAzU6eqQpIpe1xCkCLTHYtkvwnXed4ZDFXXQRIH19953EiSm0r5I0ltryGz8vId%2FRq%2FgLC9cBy1A4Brozj0Z1XH3Vpb4pUWk1ZAbFHNl4lSI4loQz3FzfKiJn37%2F%2F2KjxMfHUj1XiMj%2BCBc0oeyx%2FmkSy8SsjYRx09OvAzLC4gSGPehGSSxvZMs4X7gTf5rT98SwKMba%2BXEbthoBEAaRbAFKx7KGNqgC%2FV7UYrMcZk3%2BqkyK174jYAhAkExZQ7Sl2kWvhbfxa8TEoLgo8H3aySqgb8lCVwwHRA%2Fm6Cm7TnSRz2gHu0Eat55sC5nWtydIQqCCp4mUdYMMLJzhvnDEQH5UYS%2BUdZQtOlH2nunFufPMZ9HAUKGAR6p4py%2BMrrsL9aeQFYwwPD%2F1AY6mAF36wgDeCTrB6hln6qv4luoaOT6ItC2%2B5DJzfw%2BGqTp%2FbcH0sDMPqqCgRqSifEdv70pqQl6xXsm8CJ8LHk3iljIunBLn7%2Bf8sR3E%2FjTQME2C%2B25DKzPgwCIvJFHIjD0yU3%2FfkwlfKbDYvuNofAsuAWftavy%2Ft9gBDkVmh%2Fu%2F7bFhQTH8Sq3w0OjDmU6LDy7AONPJ1wUrv7ecg%3D%3D&amp;Expires=1788872211" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">Other models showed progress without matching the full outcome. Four reached domain access and control, four achieved lateral movement, and two reached credential access. </p>



<p class="wp-block-paragraph">All but one penetrated the network autonomously. An attacker need not finish every stage alone to cause disruption or give a human operator a head start.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58939690-1282-4a9e-83b8-3b82cdfb252f/The-Offensive-Frontier-AI-as-The-Attacker.pdf?AWSAccessKeyId=ASIA2F3EMEYEZXNPCLW4&amp;Signature=gVewioyNOYwLX8T%2Bx%2BxWkV355C4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCNxLTgVCrgVhjkz%2BQERTtpqxNOX8xgmMvlnm0YnMW%2BLgIgIreZx7qPYRZTcebez9rA%2BbpgH2QTdNasReKR7xeJvTgq8wQIVRABGgw2OTk3NTMzMDk3MDUiDPoI5WNiL8xKQV6TmirQBPnP%2BJYRugGohMojA6rebEnXl9G8xCnTAgUoh%2BahpbAX3lr0TmJ9O4TfpZw4wsHwVBpKOcFPtVq6mBj0Wgqn1mqaCV1hIRN3D0c4oW%2BKEwwQAZyVcSNs%2BtAy5r2rUKs9F9VhehVpEttDTQTNxu6NXbJud1np7QJvAKF8x%2BoZli%2FkK1CHLfHIBUkj0lbazy064xArx2Xcx7i9BW5vReTQRx%2BiUpcSXfrxTfiUvwx87SCcgqFZOIwulBOs3slrwWKE16s9%2FEmJtmwuwqNfy3a6NCFkl5tZa834alI1arvcqt0SQY7v34BBHCJRzTU6GeVB%2BUtbTcJ4nkTfZC9fKLHYwsJO1pl4aGvmoaJ4H9cLF7nHyC0vlsnELZVv8r9PkTcwo0KRNV%2Bf%2BeCorbF%2BUqAzU6eqQpIpe1xCkCLTHYtkvwnXed4ZDFXXQRIH19953EiSm0r5I0ltryGz8vId%2FRq%2FgLC9cBy1A4Brozj0Z1XH3Vpb4pUWk1ZAbFHNl4lSI4loQz3FzfKiJn37%2F%2F2KjxMfHUj1XiMj%2BCBc0oeyx%2FmkSy8SsjYRx09OvAzLC4gSGPehGSSxvZMs4X7gTf5rT98SwKMba%2BXEbthoBEAaRbAFKx7KGNqgC%2FV7UYrMcZk3%2BqkyK174jYAhAkExZQ7Sl2kWvhbfxa8TEoLgo8H3aySqgb8lCVwwHRA%2Fm6Cm7TnSRz2gHu0Eat55sC5nWtydIQqCCp4mUdYMMLJzhvnDEQH5UYS%2BUdZQtOlH2nunFufPMZ9HAUKGAR6p4py%2BMrrsL9aeQFYwwPD%2F1AY6mAF36wgDeCTrB6hln6qv4luoaOT6ItC2%2B5DJzfw%2BGqTp%2FbcH0sDMPqqCgRqSifEdv70pqQl6xXsm8CJ8LHk3iljIunBLn7%2Bf8sR3E%2FjTQME2C%2B25DKzPgwCIvJFHIjD0yU3%2FfkwlfKbDYvuNofAsuAWftavy%2Ft9gBDkVmh%2Fu%2F7bFhQTH8Sq3w0OjDmU6LDy7AONPJ1wUrv7ecg%3D%3D&amp;Expires=1788872211" target="_blank" rel="noopener"></a><a href="https://www.boozallen.com/insights/cyber/cyber-weapon-index.html" target="_blank" rel="noopener"></a></p>



<h2 id="h-defenders-face-a-speed-problem" class="wp-block-heading"><strong>Defenders face a speed problem</strong></h2>



<p class="wp-block-paragraph">The report argues that risk lies in the entire AI system, not only its model. An attack harness can link a model with tools, memory, feedback and an execution environment. </p>



<p class="wp-block-paragraph">This helps an agent retain context, recover from errors and connect tasks, as seen in <a href="https://cybersecuritynews.com/ai-agents-breach-company-network/" target="_blank" rel="noopener">agents breaching company networks</a>.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58939690-1282-4a9e-83b8-3b82cdfb252f/The-Offensive-Frontier-AI-as-The-Attacker.pdf?AWSAccessKeyId=ASIA2F3EMEYEZXNPCLW4&amp;Signature=gVewioyNOYwLX8T%2Bx%2BxWkV355C4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCNxLTgVCrgVhjkz%2BQERTtpqxNOX8xgmMvlnm0YnMW%2BLgIgIreZx7qPYRZTcebez9rA%2BbpgH2QTdNasReKR7xeJvTgq8wQIVRABGgw2OTk3NTMzMDk3MDUiDPoI5WNiL8xKQV6TmirQBPnP%2BJYRugGohMojA6rebEnXl9G8xCnTAgUoh%2BahpbAX3lr0TmJ9O4TfpZw4wsHwVBpKOcFPtVq6mBj0Wgqn1mqaCV1hIRN3D0c4oW%2BKEwwQAZyVcSNs%2BtAy5r2rUKs9F9VhehVpEttDTQTNxu6NXbJud1np7QJvAKF8x%2BoZli%2FkK1CHLfHIBUkj0lbazy064xArx2Xcx7i9BW5vReTQRx%2BiUpcSXfrxTfiUvwx87SCcgqFZOIwulBOs3slrwWKE16s9%2FEmJtmwuwqNfy3a6NCFkl5tZa834alI1arvcqt0SQY7v34BBHCJRzTU6GeVB%2BUtbTcJ4nkTfZC9fKLHYwsJO1pl4aGvmoaJ4H9cLF7nHyC0vlsnELZVv8r9PkTcwo0KRNV%2Bf%2BeCorbF%2BUqAzU6eqQpIpe1xCkCLTHYtkvwnXed4ZDFXXQRIH19953EiSm0r5I0ltryGz8vId%2FRq%2FgLC9cBy1A4Brozj0Z1XH3Vpb4pUWk1ZAbFHNl4lSI4loQz3FzfKiJn37%2F%2F2KjxMfHUj1XiMj%2BCBc0oeyx%2FmkSy8SsjYRx09OvAzLC4gSGPehGSSxvZMs4X7gTf5rT98SwKMba%2BXEbthoBEAaRbAFKx7KGNqgC%2FV7UYrMcZk3%2BqkyK174jYAhAkExZQ7Sl2kWvhbfxa8TEoLgo8H3aySqgb8lCVwwHRA%2Fm6Cm7TnSRz2gHu0Eat55sC5nWtydIQqCCp4mUdYMMLJzhvnDEQH5UYS%2BUdZQtOlH2nunFufPMZ9HAUKGAR6p4py%2BMrrsL9aeQFYwwPD%2F1AY6mAF36wgDeCTrB6hln6qv4luoaOT6ItC2%2B5DJzfw%2BGqTp%2FbcH0sDMPqqCgRqSifEdv70pqQl6xXsm8CJ8LHk3iljIunBLn7%2Bf8sR3E%2FjTQME2C%2B25DKzPgwCIvJFHIjD0yU3%2FfkwlfKbDYvuNofAsuAWftavy%2Ft9gBDkVmh%2Fu%2F7bFhQTH8Sq3w0OjDmU6LDy7AONPJ1wUrv7ecg%3D%3D&amp;Expires=1788872211" target="_blank" rel="noopener"></a><a href="https://cybersecuritynews.com/ai-agents-breach-company-network/" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">A model that stops short alone can become more effective with automation, tailored prompts and operational tools. The report found that a harness paired with Claude Sonnet could rival Claude Mythos. A public model score, therefore, can leave serious blind spots.<a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58939690-1282-4a9e-83b8-3b82cdfb252f/The-Offensive-Frontier-AI-as-The-Attacker.pdf?AWSAccessKeyId=ASIA2F3EMEYEZXNPCLW4&amp;Signature=gVewioyNOYwLX8T%2Bx%2BxWkV355C4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCNxLTgVCrgVhjkz%2BQERTtpqxNOX8xgmMvlnm0YnMW%2BLgIgIreZx7qPYRZTcebez9rA%2BbpgH2QTdNasReKR7xeJvTgq8wQIVRABGgw2OTk3NTMzMDk3MDUiDPoI5WNiL8xKQV6TmirQBPnP%2BJYRugGohMojA6rebEnXl9G8xCnTAgUoh%2BahpbAX3lr0TmJ9O4TfpZw4wsHwVBpKOcFPtVq6mBj0Wgqn1mqaCV1hIRN3D0c4oW%2BKEwwQAZyVcSNs%2BtAy5r2rUKs9F9VhehVpEttDTQTNxu6NXbJud1np7QJvAKF8x%2BoZli%2FkK1CHLfHIBUkj0lbazy064xArx2Xcx7i9BW5vReTQRx%2BiUpcSXfrxTfiUvwx87SCcgqFZOIwulBOs3slrwWKE16s9%2FEmJtmwuwqNfy3a6NCFkl5tZa834alI1arvcqt0SQY7v34BBHCJRzTU6GeVB%2BUtbTcJ4nkTfZC9fKLHYwsJO1pl4aGvmoaJ4H9cLF7nHyC0vlsnELZVv8r9PkTcwo0KRNV%2Bf%2BeCorbF%2BUqAzU6eqQpIpe1xCkCLTHYtkvwnXed4ZDFXXQRIH19953EiSm0r5I0ltryGz8vId%2FRq%2FgLC9cBy1A4Brozj0Z1XH3Vpb4pUWk1ZAbFHNl4lSI4loQz3FzfKiJn37%2F%2F2KjxMfHUj1XiMj%2BCBc0oeyx%2FmkSy8SsjYRx09OvAzLC4gSGPehGSSxvZMs4X7gTf5rT98SwKMba%2BXEbthoBEAaRbAFKx7KGNqgC%2FV7UYrMcZk3%2BqkyK174jYAhAkExZQ7Sl2kWvhbfxa8TEoLgo8H3aySqgb8lCVwwHRA%2Fm6Cm7TnSRz2gHu0Eat55sC5nWtydIQqCCp4mUdYMMLJzhvnDEQH5UYS%2BUdZQtOlH2nunFufPMZ9HAUKGAR6p4py%2BMrrsL9aeQFYwwPD%2F1AY6mAF36wgDeCTrB6hln6qv4luoaOT6ItC2%2B5DJzfw%2BGqTp%2FbcH0sDMPqqCgRqSifEdv70pqQl6xXsm8CJ8LHk3iljIunBLn7%2Bf8sR3E%2FjTQME2C%2B25DKzPgwCIvJFHIjD0yU3%2FfkwlfKbDYvuNofAsuAWftavy%2Ft9gBDkVmh%2Fu%2F7bFhQTH8Sq3w0OjDmU6LDy7AONPJ1wUrv7ecg%3D%3D&amp;Expires=1788872211"></a></p>



<p class="wp-block-paragraph">The likely entry routes are familiar: exposed services, unpatched flaws, stolen credentials and weak access controls. </p>



<p class="wp-block-paragraph">AI reduces the time and expertise needed to test options, analyze results and adapt. <a href="https://cybersecuritynews.com/ai-agents/" target="_blank" rel="noopener">AI agents rebuilding attack tools</a> illustrate how persistence after failure can amplify this advantage. <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58939690-1282-4a9e-83b8-3b82cdfb252f/The-Offensive-Frontier-AI-as-The-Attacker.pdf?AWSAccessKeyId=ASIA2F3EMEYEZXNPCLW4&amp;Signature=gVewioyNOYwLX8T%2Bx%2BxWkV355C4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCNxLTgVCrgVhjkz%2BQERTtpqxNOX8xgmMvlnm0YnMW%2BLgIgIreZx7qPYRZTcebez9rA%2BbpgH2QTdNasReKR7xeJvTgq8wQIVRABGgw2OTk3NTMzMDk3MDUiDPoI5WNiL8xKQV6TmirQBPnP%2BJYRugGohMojA6rebEnXl9G8xCnTAgUoh%2BahpbAX3lr0TmJ9O4TfpZw4wsHwVBpKOcFPtVq6mBj0Wgqn1mqaCV1hIRN3D0c4oW%2BKEwwQAZyVcSNs%2BtAy5r2rUKs9F9VhehVpEttDTQTNxu6NXbJud1np7QJvAKF8x%2BoZli%2FkK1CHLfHIBUkj0lbazy064xArx2Xcx7i9BW5vReTQRx%2BiUpcSXfrxTfiUvwx87SCcgqFZOIwulBOs3slrwWKE16s9%2FEmJtmwuwqNfy3a6NCFkl5tZa834alI1arvcqt0SQY7v34BBHCJRzTU6GeVB%2BUtbTcJ4nkTfZC9fKLHYwsJO1pl4aGvmoaJ4H9cLF7nHyC0vlsnELZVv8r9PkTcwo0KRNV%2Bf%2BeCorbF%2BUqAzU6eqQpIpe1xCkCLTHYtkvwnXed4ZDFXXQRIH19953EiSm0r5I0ltryGz8vId%2FRq%2FgLC9cBy1A4Brozj0Z1XH3Vpb4pUWk1ZAbFHNl4lSI4loQz3FzfKiJn37%2F%2F2KjxMfHUj1XiMj%2BCBc0oeyx%2FmkSy8SsjYRx09OvAzLC4gSGPehGSSxvZMs4X7gTf5rT98SwKMba%2BXEbthoBEAaRbAFKx7KGNqgC%2FV7UYrMcZk3%2BqkyK174jYAhAkExZQ7Sl2kWvhbfxa8TEoLgo8H3aySqgb8lCVwwHRA%2Fm6Cm7TnSRz2gHu0Eat55sC5nWtydIQqCCp4mUdYMMLJzhvnDEQH5UYS%2BUdZQtOlH2nunFufPMZ9HAUKGAR6p4py%2BMrrsL9aeQFYwwPD%2F1AY6mAF36wgDeCTrB6hln6qv4luoaOT6ItC2%2B5DJzfw%2BGqTp%2FbcH0sDMPqqCgRqSifEdv70pqQl6xXsm8CJ8LHk3iljIunBLn7%2Bf8sR3E%2FjTQME2C%2B25DKzPgwCIvJFHIjD0yU3%2FfkwlfKbDYvuNofAsuAWftavy%2Ft9gBDkVmh%2Fu%2F7bFhQTH8Sq3w0OjDmU6LDy7AONPJ1wUrv7ecg%3D%3D&amp;Expires=1788872211" target="_blank" rel="noopener"></a><a href="https://cybersecuritynews.com/ai-agents/" target="_blank" rel="noopener"></a>The recommended response is to assume an initial foothold and restrict what happens next. </p>



<p class="wp-block-paragraph">Organizations should connect vulnerability management, detection, containment and response; enforce least privilege, strong identity checks, segmentation and isolation of high-value systems; and test containment while keeping services running.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58939690-1282-4a9e-83b8-3b82cdfb252f/The-Offensive-Frontier-AI-as-The-Attacker.pdf?AWSAccessKeyId=ASIA2F3EMEYEZXNPCLW4&amp;Signature=gVewioyNOYwLX8T%2Bx%2BxWkV355C4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCNxLTgVCrgVhjkz%2BQERTtpqxNOX8xgmMvlnm0YnMW%2BLgIgIreZx7qPYRZTcebez9rA%2BbpgH2QTdNasReKR7xeJvTgq8wQIVRABGgw2OTk3NTMzMDk3MDUiDPoI5WNiL8xKQV6TmirQBPnP%2BJYRugGohMojA6rebEnXl9G8xCnTAgUoh%2BahpbAX3lr0TmJ9O4TfpZw4wsHwVBpKOcFPtVq6mBj0Wgqn1mqaCV1hIRN3D0c4oW%2BKEwwQAZyVcSNs%2BtAy5r2rUKs9F9VhehVpEttDTQTNxu6NXbJud1np7QJvAKF8x%2BoZli%2FkK1CHLfHIBUkj0lbazy064xArx2Xcx7i9BW5vReTQRx%2BiUpcSXfrxTfiUvwx87SCcgqFZOIwulBOs3slrwWKE16s9%2FEmJtmwuwqNfy3a6NCFkl5tZa834alI1arvcqt0SQY7v34BBHCJRzTU6GeVB%2BUtbTcJ4nkTfZC9fKLHYwsJO1pl4aGvmoaJ4H9cLF7nHyC0vlsnELZVv8r9PkTcwo0KRNV%2Bf%2BeCorbF%2BUqAzU6eqQpIpe1xCkCLTHYtkvwnXed4ZDFXXQRIH19953EiSm0r5I0ltryGz8vId%2FRq%2FgLC9cBy1A4Brozj0Z1XH3Vpb4pUWk1ZAbFHNl4lSI4loQz3FzfKiJn37%2F%2F2KjxMfHUj1XiMj%2BCBc0oeyx%2FmkSy8SsjYRx09OvAzLC4gSGPehGSSxvZMs4X7gTf5rT98SwKMba%2BXEbthoBEAaRbAFKx7KGNqgC%2FV7UYrMcZk3%2BqkyK174jYAhAkExZQ7Sl2kWvhbfxa8TEoLgo8H3aySqgb8lCVwwHRA%2Fm6Cm7TnSRz2gHu0Eat55sC5nWtydIQqCCp4mUdYMMLJzhvnDEQH5UYS%2BUdZQtOlH2nunFufPMZ9HAUKGAR6p4py%2BMrrsL9aeQFYwwPD%2F1AY6mAF36wgDeCTrB6hln6qv4luoaOT6ItC2%2B5DJzfw%2BGqTp%2FbcH0sDMPqqCgRqSifEdv70pqQl6xXsm8CJ8LHk3iljIunBLn7%2Bf8sR3E%2FjTQME2C%2B25DKzPgwCIvJFHIjD0yU3%2FfkwlfKbDYvuNofAsuAWftavy%2Ft9gBDkVmh%2Fu%2F7bFhQTH8Sq3w0OjDmU6LDy7AONPJ1wUrv7ecg%3D%3D&amp;Expires=1788872211" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">Teams should test safeguards in deployed configurations, including tool permissions and autonomy levels. The report recommends continuous measurement of models and surrounding systems, plus controlled access for vetted defenders to reproduce threatening behavior. </p>



<p class="wp-block-paragraph">This exceeds paper compliance when attack methods change quickly. <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58939690-1282-4a9e-83b8-3b82cdfb252f/The-Offensive-Frontier-AI-as-The-Attacker.pdf?AWSAccessKeyId=ASIA2F3EMEYEZXNPCLW4&amp;Signature=gVewioyNOYwLX8T%2Bx%2BxWkV355C4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCNxLTgVCrgVhjkz%2BQERTtpqxNOX8xgmMvlnm0YnMW%2BLgIgIreZx7qPYRZTcebez9rA%2BbpgH2QTdNasReKR7xeJvTgq8wQIVRABGgw2OTk3NTMzMDk3MDUiDPoI5WNiL8xKQV6TmirQBPnP%2BJYRugGohMojA6rebEnXl9G8xCnTAgUoh%2BahpbAX3lr0TmJ9O4TfpZw4wsHwVBpKOcFPtVq6mBj0Wgqn1mqaCV1hIRN3D0c4oW%2BKEwwQAZyVcSNs%2BtAy5r2rUKs9F9VhehVpEttDTQTNxu6NXbJud1np7QJvAKF8x%2BoZli%2FkK1CHLfHIBUkj0lbazy064xArx2Xcx7i9BW5vReTQRx%2BiUpcSXfrxTfiUvwx87SCcgqFZOIwulBOs3slrwWKE16s9%2FEmJtmwuwqNfy3a6NCFkl5tZa834alI1arvcqt0SQY7v34BBHCJRzTU6GeVB%2BUtbTcJ4nkTfZC9fKLHYwsJO1pl4aGvmoaJ4H9cLF7nHyC0vlsnELZVv8r9PkTcwo0KRNV%2Bf%2BeCorbF%2BUqAzU6eqQpIpe1xCkCLTHYtkvwnXed4ZDFXXQRIH19953EiSm0r5I0ltryGz8vId%2FRq%2FgLC9cBy1A4Brozj0Z1XH3Vpb4pUWk1ZAbFHNl4lSI4loQz3FzfKiJn37%2F%2F2KjxMfHUj1XiMj%2BCBc0oeyx%2FmkSy8SsjYRx09OvAzLC4gSGPehGSSxvZMs4X7gTf5rT98SwKMba%2BXEbthoBEAaRbAFKx7KGNqgC%2FV7UYrMcZk3%2BqkyK174jYAhAkExZQ7Sl2kWvhbfxa8TEoLgo8H3aySqgb8lCVwwHRA%2Fm6Cm7TnSRz2gHu0Eat55sC5nWtydIQqCCp4mUdYMMLJzhvnDEQH5UYS%2BUdZQtOlH2nunFufPMZ9HAUKGAR6p4py%2BMrrsL9aeQFYwwPD%2F1AY6mAF36wgDeCTrB6hln6qv4luoaOT6ItC2%2B5DJzfw%2BGqTp%2FbcH0sDMPqqCgRqSifEdv70pqQl6xXsm8CJ8LHk3iljIunBLn7%2Bf8sR3E%2FjTQME2C%2B25DKzPgwCIvJFHIjD0yU3%2FfkwlfKbDYvuNofAsuAWftavy%2Ft9gBDkVmh%2Fu%2F7bFhQTH8Sq3w0OjDmU6LDy7AONPJ1wUrv7ecg%3D%3D&amp;Expires=1788872211" target="_blank" rel="noopener"></a>The headline is not that an AI model has become a criminal actor. A controlled assessment found one system capable of completing a realistic sequence of offensive tasks. </p>



<p class="wp-block-paragraph">The gap between early access and full compromise may be narrowing, making patching, identity protection and segmentation urgent. Related <a href="https://cybersecuritynews.com/eight-ai-agents-breach-government-systems/" target="_blank" rel="noopener">AI-driven government system breaches</a> show why coordinated automation needs preparation.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/58939690-1282-4a9e-83b8-3b82cdfb252f/The-Offensive-Frontier-AI-as-The-Attacker.pdf?AWSAccessKeyId=ASIA2F3EMEYEZXNPCLW4&amp;Signature=gVewioyNOYwLX8T%2Bx%2BxWkV355C4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCNxLTgVCrgVhjkz%2BQERTtpqxNOX8xgmMvlnm0YnMW%2BLgIgIreZx7qPYRZTcebez9rA%2BbpgH2QTdNasReKR7xeJvTgq8wQIVRABGgw2OTk3NTMzMDk3MDUiDPoI5WNiL8xKQV6TmirQBPnP%2BJYRugGohMojA6rebEnXl9G8xCnTAgUoh%2BahpbAX3lr0TmJ9O4TfpZw4wsHwVBpKOcFPtVq6mBj0Wgqn1mqaCV1hIRN3D0c4oW%2BKEwwQAZyVcSNs%2BtAy5r2rUKs9F9VhehVpEttDTQTNxu6NXbJud1np7QJvAKF8x%2BoZli%2FkK1CHLfHIBUkj0lbazy064xArx2Xcx7i9BW5vReTQRx%2BiUpcSXfrxTfiUvwx87SCcgqFZOIwulBOs3slrwWKE16s9%2FEmJtmwuwqNfy3a6NCFkl5tZa834alI1arvcqt0SQY7v34BBHCJRzTU6GeVB%2BUtbTcJ4nkTfZC9fKLHYwsJO1pl4aGvmoaJ4H9cLF7nHyC0vlsnELZVv8r9PkTcwo0KRNV%2Bf%2BeCorbF%2BUqAzU6eqQpIpe1xCkCLTHYtkvwnXed4ZDFXXQRIH19953EiSm0r5I0ltryGz8vId%2FRq%2FgLC9cBy1A4Brozj0Z1XH3Vpb4pUWk1ZAbFHNl4lSI4loQz3FzfKiJn37%2F%2F2KjxMfHUj1XiMj%2BCBc0oeyx%2FmkSy8SsjYRx09OvAzLC4gSGPehGSSxvZMs4X7gTf5rT98SwKMba%2BXEbthoBEAaRbAFKx7KGNqgC%2FV7UYrMcZk3%2BqkyK174jYAhAkExZQ7Sl2kWvhbfxa8TEoLgo8H3aySqgb8lCVwwHRA%2Fm6Cm7TnSRz2gHu0Eat55sC5nWtydIQqCCp4mUdYMMLJzhvnDEQH5UYS%2BUdZQtOlH2nunFufPMZ9HAUKGAR6p4py%2BMrrsL9aeQFYwwPD%2F1AY6mAF36wgDeCTrB6hln6qv4luoaOT6ItC2%2B5DJzfw%2BGqTp%2FbcH0sDMPqqCgRqSifEdv70pqQl6xXsm8CJ8LHk3iljIunBLn7%2Bf8sR3E%2FjTQME2C%2B25DKzPgwCIvJFHIjD0yU3%2FfkwlfKbDYvuNofAsuAWftavy%2Ft9gBDkVmh%2Fu%2F7bFhQTH8Sq3w0OjDmU6LDy7AONPJ1wUrv7ecg%3D%3D&amp;Expires=1788872211" target="_blank" rel="noopener"></a><a href="https://cybersecuritynews.com/eight-ai-agents-breach-government-systems/" target="_blank" rel="noopener"></a></p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong>Keep your SOC&nbsp;up to date on active malware &amp; phishing within 24h of their emergence.&nbsp;<a href="https://any.run/threat-intelligence-feeds/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=cta_links&amp;utm_content=landing_feeds&amp;utm_term=sep_26#contact-sales" target="_blank" rel="noreferrer noopener nofollow">Try ANYRUN to prevent incidents with early detection</a></strong></strong>.</p>
<p>The post <a href="https://cybersecuritynews.com/claude-mythos-ai/">Claude Mythos AI Autonomously Executes Full Cyber Kill Chain Without Human Guidance</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/09/Claude-Mythos-AI-Autonomously-Executes-Full-Cyber-Kill-Chain-Without-Human-Guidance.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">162561</post-id>	</item>
		<item>
		<title>Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain</title>
		<link>https://cybersecuritynews.com/hackers-disable-endpoint-protection/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 12:10:57 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=162518</guid>

					<description><![CDATA[<p>A new intrusion campaign shows how quickly a Windows domain can be turned into a launchpad for deeper compromise. The operators used a Sliver command-and-control beacon, account creation, credential theft and remote administration to establish control after gaining an initial foothold. The activity was staged from an exposed server and aimed at one unnamed US [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/hackers-disable-endpoint-protection/">Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A new intrusion campaign shows how quickly a Windows domain can be turned into a launchpad for deeper compromise. The operators used a Sliver command-and-control beacon, account creation, credential theft and remote administration to establish control after gaining an initial foothold.<a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/9fb6ab04-f4fb-4358-ac12-8d4b5bbba988/Hackers-Disable-Endpoint-Protection-and-Deploy-Sliver-Across-Compromised-Windows-Domain.pdf?AWSAccessKeyId=ASIA2F3EMEYE64QQ5OGM&amp;Signature=D9O%2BcoFeSHzSbFkE7VDmDm8R5Zw%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCb5s%2BdXOODjaRFD%2B99da7s%2FATJHzDW%2F6ZcJbarp8UuXgIhANAGF7meBIMrftCfH7XfQh9Srl6b%2Fh7sreidHb3BxgBJKvMECFQQARoMNjk5NzUzMzA5NzA1IgyBsexw2u592pGIWNQq0AT9ZnCGcnsELBIIBQMK8PqKvJ48ctmkVEoRqNPzBp4SfMpU66DF%2Flu4NHAbGL0P%2BCk4%2F61FV0Ozbh4pfF%2Fz2Nh4OvfyzV3Bwc%2FkUwWv5%2F52Jhcv7kxnhxj1cMHtMlt9ec1DFoBndT3Swhh3OIKOxE2yIfpndRFkXX95XushRH2O08J6Xezwa3j9xpzSQQjDCaCJo6JO7pgKOhK3Zx36Va5pev4bLY83XgZmKxKkTJ2S69kPSI8eVgbwpuyCnia4XW2P1s7mEQJvOaBl1iQe6VcX%2BPzzRriMqKrxqoeYU9lhRC5AZRGlLLaoHCyJpy9nCeWRwkZtp3iodlmEMitDUPmTVx95WhMJegQ%2FkYZ6H7iXwzXz4t%2FUu4s16pUF3Y9NYJlUla9MS3dZZIeECeWFtgmw3cM4Sd94rAHVMCZbC94r6nAh7bFSVy3eznE4JKEihz8dGpHWpVeGq0etU3NDpc2Z5toyRo5GB%2F9A%2FeXJ9GhyCAlgVXjLLZRSJkQXfitj5JkJPMAONG2Vw0%2FK0jcaXxCuFA7aZ6XanOKBM6EPR1IQwVDz2Tty17BPj8zOeHuLooZI%2FCJ7%2BGUUbrbiovioXxzYsKZmYRM7DWo3kgCYa36ve2L2eRY4e%2FH5xAk593lMdEGKf6RiesbqZOCVmlQDgH5jLxH0KEgS%2FjSLCHZ9GBKfXbYJn%2Bg2CKOEZni0o9IPb4kSEkOXqXGkLf1pxGNrOidiE%2Fx0XkGhgAJD9U00ryxOpMc0hLFeZLXcgOQqoolks5AwLM%2F9ieAAAEuHXoYd%2BNYRMJXV%2F9QGOpcBzauM8N9EXQ1yCPdjtDZX1RMaXar%2B2fPxqCUJAYf6JqYgIo04DEJPI38RIVNBP%2BxuZEM3KgPV9JqS0uZBV4pZ29EsLvAukQti8IBOtqu0qcvIaS97FFbe5SkLzj2fx04MDGbWf%2BxWzNxSTJfQHHXJmpz2iPLWtot11KcQzhjM1oeW99QNvczYSb0lyN%2F2%2BOPSe7KjGioWZA%3D%3D&amp;Expires=1788868712"></a><a rel="noopener" target="_blank" href="https://the-hunters-ledger.com/reports/sliver-c2-windows-postex-staging-193-233-202-17/"></a></p>



<p class="wp-block-paragraph">The activity was staged from an exposed server and aimed at one unnamed US organisation. Its scripts were built for a real Active Directory environment, including a planned rollout across 18 hosts, while the recovered material contained no proof that ransomware was deployed in this specific incident.<a rel="noopener" target="_blank" href="https://the-hunters-ledger.com/reports/sliver-c2-windows-postex-staging-193-233-202-17/"></a><a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/9fb6ab04-f4fb-4358-ac12-8d4b5bbba988/Hackers-Disable-Endpoint-Protection-and-Deploy-Sliver-Across-Compromised-Windows-Domain.pdf?AWSAccessKeyId=ASIA2F3EMEYE64QQ5OGM&amp;Signature=D9O%2BcoFeSHzSbFkE7VDmDm8R5Zw%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCb5s%2BdXOODjaRFD%2B99da7s%2FATJHzDW%2F6ZcJbarp8UuXgIhANAGF7meBIMrftCfH7XfQh9Srl6b%2Fh7sreidHb3BxgBJKvMECFQQARoMNjk5NzUzMzA5NzA1IgyBsexw2u592pGIWNQq0AT9ZnCGcnsELBIIBQMK8PqKvJ48ctmkVEoRqNPzBp4SfMpU66DF%2Flu4NHAbGL0P%2BCk4%2F61FV0Ozbh4pfF%2Fz2Nh4OvfyzV3Bwc%2FkUwWv5%2F52Jhcv7kxnhxj1cMHtMlt9ec1DFoBndT3Swhh3OIKOxE2yIfpndRFkXX95XushRH2O08J6Xezwa3j9xpzSQQjDCaCJo6JO7pgKOhK3Zx36Va5pev4bLY83XgZmKxKkTJ2S69kPSI8eVgbwpuyCnia4XW2P1s7mEQJvOaBl1iQe6VcX%2BPzzRriMqKrxqoeYU9lhRC5AZRGlLLaoHCyJpy9nCeWRwkZtp3iodlmEMitDUPmTVx95WhMJegQ%2FkYZ6H7iXwzXz4t%2FUu4s16pUF3Y9NYJlUla9MS3dZZIeECeWFtgmw3cM4Sd94rAHVMCZbC94r6nAh7bFSVy3eznE4JKEihz8dGpHWpVeGq0etU3NDpc2Z5toyRo5GB%2F9A%2FeXJ9GhyCAlgVXjLLZRSJkQXfitj5JkJPMAONG2Vw0%2FK0jcaXxCuFA7aZ6XanOKBM6EPR1IQwVDz2Tty17BPj8zOeHuLooZI%2FCJ7%2BGUUbrbiovioXxzYsKZmYRM7DWo3kgCYa36ve2L2eRY4e%2FH5xAk593lMdEGKf6RiesbqZOCVmlQDgH5jLxH0KEgS%2FjSLCHZ9GBKfXbYJn%2Bg2CKOEZni0o9IPb4kSEkOXqXGkLf1pxGNrOidiE%2Fx0XkGhgAJD9U00ryxOpMc0hLFeZLXcgOQqoolks5AwLM%2F9ieAAAEuHXoYd%2BNYRMJXV%2F9QGOpcBzauM8N9EXQ1yCPdjtDZX1RMaXar%2B2fPxqCUJAYf6JqYgIo04DEJPI38RIVNBP%2BxuZEM3KgPV9JqS0uZBV4pZ29EsLvAukQti8IBOtqu0qcvIaS97FFbe5SkLzj2fx04MDGbWf%2BxWzNxSTJfQHHXJmpz2iPLWtot11KcQzhjM1oeW99QNvczYSb0lyN%2F2%2BOPSe7KjGioWZA%3D%3D&amp;Expires=1788868712"></a></p>



<p class="wp-block-paragraph">Analysts at The Hunter’s Ledger identified the operation as a high-risk post-exploitation toolkit and tracked it as UTA-2026-024. </p>



<p class="wp-block-paragraph">The research ties the infrastructure to a confirmed ransomware incident, but does not name the people behind this intrusion or conclude that they deployed an encryptor.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/9fb6ab04-f4fb-4358-ac12-8d4b5bbba988/Hackers-Disable-Endpoint-Protection-and-Deploy-Sliver-Across-Compromised-Windows-Domain.pdf?AWSAccessKeyId=ASIA2F3EMEYE64QQ5OGM&amp;Signature=D9O%2BcoFeSHzSbFkE7VDmDm8R5Zw%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCb5s%2BdXOODjaRFD%2B99da7s%2FATJHzDW%2F6ZcJbarp8UuXgIhANAGF7meBIMrftCfH7XfQh9Srl6b%2Fh7sreidHb3BxgBJKvMECFQQARoMNjk5NzUzMzA5NzA1IgyBsexw2u592pGIWNQq0AT9ZnCGcnsELBIIBQMK8PqKvJ48ctmkVEoRqNPzBp4SfMpU66DF%2Flu4NHAbGL0P%2BCk4%2F61FV0Ozbh4pfF%2Fz2Nh4OvfyzV3Bwc%2FkUwWv5%2F52Jhcv7kxnhxj1cMHtMlt9ec1DFoBndT3Swhh3OIKOxE2yIfpndRFkXX95XushRH2O08J6Xezwa3j9xpzSQQjDCaCJo6JO7pgKOhK3Zx36Va5pev4bLY83XgZmKxKkTJ2S69kPSI8eVgbwpuyCnia4XW2P1s7mEQJvOaBl1iQe6VcX%2BPzzRriMqKrxqoeYU9lhRC5AZRGlLLaoHCyJpy9nCeWRwkZtp3iodlmEMitDUPmTVx95WhMJegQ%2FkYZ6H7iXwzXz4t%2FUu4s16pUF3Y9NYJlUla9MS3dZZIeECeWFtgmw3cM4Sd94rAHVMCZbC94r6nAh7bFSVy3eznE4JKEihz8dGpHWpVeGq0etU3NDpc2Z5toyRo5GB%2F9A%2FeXJ9GhyCAlgVXjLLZRSJkQXfitj5JkJPMAONG2Vw0%2FK0jcaXxCuFA7aZ6XanOKBM6EPR1IQwVDz2Tty17BPj8zOeHuLooZI%2FCJ7%2BGUUbrbiovioXxzYsKZmYRM7DWo3kgCYa36ve2L2eRY4e%2FH5xAk593lMdEGKf6RiesbqZOCVmlQDgH5jLxH0KEgS%2FjSLCHZ9GBKfXbYJn%2Bg2CKOEZni0o9IPb4kSEkOXqXGkLf1pxGNrOidiE%2Fx0XkGhgAJD9U00ryxOpMc0hLFeZLXcgOQqoolks5AwLM%2F9ieAAAEuHXoYd%2BNYRMJXV%2F9QGOpcBzauM8N9EXQ1yCPdjtDZX1RMaXar%2B2fPxqCUJAYf6JqYgIo04DEJPI38RIVNBP%2BxuZEM3KgPV9JqS0uZBV4pZ29EsLvAukQti8IBOtqu0qcvIaS97FFbe5SkLzj2fx04MDGbWf%2BxWzNxSTJfQHHXJmpz2iPLWtot11KcQzhjM1oeW99QNvczYSb0lyN%2F2%2BOPSe7KjGioWZA%3D%3D&amp;Expires=1788868712" target="_blank" rel="noopener"></a><a href="https://the-hunters-ledger.com/reports/sliver-c2-windows-postex-staging-193-233-202-17/" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph"><a href="https://the-hunters-ledger.com/reports/sliver-c2-windows-postex-staging-193-233-202-17/" data-type="link" data-id="https://the-hunters-ledger.com/reports/sliver-c2-windows-postex-staging-193-233-202-17/" target="_blank" rel="noreferrer noopener nofollow">The Hunter’s Ledger said in a report</a> shared with Cyber Security News (CSN) that the operators combined ordinary public tools with unusually detailed knowledge of the victim’s network. </p>



<p class="wp-block-paragraph">The result was a durable access package designed to disable safeguards, steal credentials and keep its control channels available.<a href="https://the-hunters-ledger.com/reports/sliver-c2-windows-postex-staging-193-233-202-17/" target="_blank" rel="noopener"></a><a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/9fb6ab04-f4fb-4358-ac12-8d4b5bbba988/Hackers-Disable-Endpoint-Protection-and-Deploy-Sliver-Across-Compromised-Windows-Domain.pdf?AWSAccessKeyId=ASIA2F3EMEYE64QQ5OGM&amp;Signature=D9O%2BcoFeSHzSbFkE7VDmDm8R5Zw%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCb5s%2BdXOODjaRFD%2B99da7s%2FATJHzDW%2F6ZcJbarp8UuXgIhANAGF7meBIMrftCfH7XfQh9Srl6b%2Fh7sreidHb3BxgBJKvMECFQQARoMNjk5NzUzMzA5NzA1IgyBsexw2u592pGIWNQq0AT9ZnCGcnsELBIIBQMK8PqKvJ48ctmkVEoRqNPzBp4SfMpU66DF%2Flu4NHAbGL0P%2BCk4%2F61FV0Ozbh4pfF%2Fz2Nh4OvfyzV3Bwc%2FkUwWv5%2F52Jhcv7kxnhxj1cMHtMlt9ec1DFoBndT3Swhh3OIKOxE2yIfpndRFkXX95XushRH2O08J6Xezwa3j9xpzSQQjDCaCJo6JO7pgKOhK3Zx36Va5pev4bLY83XgZmKxKkTJ2S69kPSI8eVgbwpuyCnia4XW2P1s7mEQJvOaBl1iQe6VcX%2BPzzRriMqKrxqoeYU9lhRC5AZRGlLLaoHCyJpy9nCeWRwkZtp3iodlmEMitDUPmTVx95WhMJegQ%2FkYZ6H7iXwzXz4t%2FUu4s16pUF3Y9NYJlUla9MS3dZZIeECeWFtgmw3cM4Sd94rAHVMCZbC94r6nAh7bFSVy3eznE4JKEihz8dGpHWpVeGq0etU3NDpc2Z5toyRo5GB%2F9A%2FeXJ9GhyCAlgVXjLLZRSJkQXfitj5JkJPMAONG2Vw0%2FK0jcaXxCuFA7aZ6XanOKBM6EPR1IQwVDz2Tty17BPj8zOeHuLooZI%2FCJ7%2BGUUbrbiovioXxzYsKZmYRM7DWo3kgCYa36ve2L2eRY4e%2FH5xAk593lMdEGKf6RiesbqZOCVmlQDgH5jLxH0KEgS%2FjSLCHZ9GBKfXbYJn%2Bg2CKOEZni0o9IPb4kSEkOXqXGkLf1pxGNrOidiE%2Fx0XkGhgAJD9U00ryxOpMc0hLFeZLXcgOQqoolks5AwLM%2F9ieAAAEuHXoYd%2BNYRMJXV%2F9QGOpcBzauM8N9EXQ1yCPdjtDZX1RMaXar%2B2fPxqCUJAYf6JqYgIo04DEJPI38RIVNBP%2BxuZEM3KgPV9JqS0uZBV4pZ29EsLvAukQti8IBOtqu0qcvIaS97FFbe5SkLzj2fx04MDGbWf%2BxWzNxSTJfQHHXJmpz2iPLWtot11KcQzhjM1oeW99QNvczYSb0lyN%2F2%2BOPSe7KjGioWZA%3D%3D&amp;Expires=1788868712" target="_blank" rel="noopener"></a></p>



<h2 id="h-hackers-disable-endpoint-protection" class="wp-block-heading"><strong>Hackers Disable Endpoint Protection</strong></h2>



<p class="wp-block-paragraph">After entering the domain, the operators scripted the creation of an Active Directory account with a non-expiring password and added it directly to Domain Admins. </p>



<p class="wp-block-paragraph">They also created a local administrator, enabled Remote Desktop Protocol access, and turned off Network Level Authentication, expanding the paths available for later movement.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/9fb6ab04-f4fb-4358-ac12-8d4b5bbba988/Hackers-Disable-Endpoint-Protection-and-Deploy-Sliver-Across-Compromised-Windows-Domain.pdf?AWSAccessKeyId=ASIA2F3EMEYE64QQ5OGM&amp;Signature=D9O%2BcoFeSHzSbFkE7VDmDm8R5Zw%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCb5s%2BdXOODjaRFD%2B99da7s%2FATJHzDW%2F6ZcJbarp8UuXgIhANAGF7meBIMrftCfH7XfQh9Srl6b%2Fh7sreidHb3BxgBJKvMECFQQARoMNjk5NzUzMzA5NzA1IgyBsexw2u592pGIWNQq0AT9ZnCGcnsELBIIBQMK8PqKvJ48ctmkVEoRqNPzBp4SfMpU66DF%2Flu4NHAbGL0P%2BCk4%2F61FV0Ozbh4pfF%2Fz2Nh4OvfyzV3Bwc%2FkUwWv5%2F52Jhcv7kxnhxj1cMHtMlt9ec1DFoBndT3Swhh3OIKOxE2yIfpndRFkXX95XushRH2O08J6Xezwa3j9xpzSQQjDCaCJo6JO7pgKOhK3Zx36Va5pev4bLY83XgZmKxKkTJ2S69kPSI8eVgbwpuyCnia4XW2P1s7mEQJvOaBl1iQe6VcX%2BPzzRriMqKrxqoeYU9lhRC5AZRGlLLaoHCyJpy9nCeWRwkZtp3iodlmEMitDUPmTVx95WhMJegQ%2FkYZ6H7iXwzXz4t%2FUu4s16pUF3Y9NYJlUla9MS3dZZIeECeWFtgmw3cM4Sd94rAHVMCZbC94r6nAh7bFSVy3eznE4JKEihz8dGpHWpVeGq0etU3NDpc2Z5toyRo5GB%2F9A%2FeXJ9GhyCAlgVXjLLZRSJkQXfitj5JkJPMAONG2Vw0%2FK0jcaXxCuFA7aZ6XanOKBM6EPR1IQwVDz2Tty17BPj8zOeHuLooZI%2FCJ7%2BGUUbrbiovioXxzYsKZmYRM7DWo3kgCYa36ve2L2eRY4e%2FH5xAk593lMdEGKf6RiesbqZOCVmlQDgH5jLxH0KEgS%2FjSLCHZ9GBKfXbYJn%2Bg2CKOEZni0o9IPb4kSEkOXqXGkLf1pxGNrOidiE%2Fx0XkGhgAJD9U00ryxOpMc0hLFeZLXcgOQqoolks5AwLM%2F9ieAAAEuHXoYd%2BNYRMJXV%2F9QGOpcBzauM8N9EXQ1yCPdjtDZX1RMaXar%2B2fPxqCUJAYf6JqYgIo04DEJPI38RIVNBP%2BxuZEM3KgPV9JqS0uZBV4pZ29EsLvAukQti8IBOtqu0qcvIaS97FFbe5SkLzj2fx04MDGbWf%2BxWzNxSTJfQHHXJmpz2iPLWtot11KcQzhjM1oeW99QNvczYSb0lyN%2F2%2BOPSe7KjGioWZA%3D%3D&amp;Expires=1788868712" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">The scripts stopped and disabled eight services associated with the victim’s endpoint protection product, then checked each service state. </p>



<p class="wp-block-paragraph">They also collected the SAM, SYSTEM and SECURITY registry hives for offline password cracking, while a separate LSASS memory dump and Mimikatz supplied additional routes to credentials.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/9fb6ab04-f4fb-4358-ac12-8d4b5bbba988/Hackers-Disable-Endpoint-Protection-and-Deploy-Sliver-Across-Compromised-Windows-Domain.pdf?AWSAccessKeyId=ASIA2F3EMEYE64QQ5OGM&amp;Signature=D9O%2BcoFeSHzSbFkE7VDmDm8R5Zw%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCb5s%2BdXOODjaRFD%2B99da7s%2FATJHzDW%2F6ZcJbarp8UuXgIhANAGF7meBIMrftCfH7XfQh9Srl6b%2Fh7sreidHb3BxgBJKvMECFQQARoMNjk5NzUzMzA5NzA1IgyBsexw2u592pGIWNQq0AT9ZnCGcnsELBIIBQMK8PqKvJ48ctmkVEoRqNPzBp4SfMpU66DF%2Flu4NHAbGL0P%2BCk4%2F61FV0Ozbh4pfF%2Fz2Nh4OvfyzV3Bwc%2FkUwWv5%2F52Jhcv7kxnhxj1cMHtMlt9ec1DFoBndT3Swhh3OIKOxE2yIfpndRFkXX95XushRH2O08J6Xezwa3j9xpzSQQjDCaCJo6JO7pgKOhK3Zx36Va5pev4bLY83XgZmKxKkTJ2S69kPSI8eVgbwpuyCnia4XW2P1s7mEQJvOaBl1iQe6VcX%2BPzzRriMqKrxqoeYU9lhRC5AZRGlLLaoHCyJpy9nCeWRwkZtp3iodlmEMitDUPmTVx95WhMJegQ%2FkYZ6H7iXwzXz4t%2FUu4s16pUF3Y9NYJlUla9MS3dZZIeECeWFtgmw3cM4Sd94rAHVMCZbC94r6nAh7bFSVy3eznE4JKEihz8dGpHWpVeGq0etU3NDpc2Z5toyRo5GB%2F9A%2FeXJ9GhyCAlgVXjLLZRSJkQXfitj5JkJPMAONG2Vw0%2FK0jcaXxCuFA7aZ6XanOKBM6EPR1IQwVDz2Tty17BPj8zOeHuLooZI%2FCJ7%2BGUUbrbiovioXxzYsKZmYRM7DWo3kgCYa36ve2L2eRY4e%2FH5xAk593lMdEGKf6RiesbqZOCVmlQDgH5jLxH0KEgS%2FjSLCHZ9GBKfXbYJn%2Bg2CKOEZni0o9IPb4kSEkOXqXGkLf1pxGNrOidiE%2Fx0XkGhgAJD9U00ryxOpMc0hLFeZLXcgOQqoolks5AwLM%2F9ieAAAEuHXoYd%2BNYRMJXV%2F9QGOpcBzauM8N9EXQ1yCPdjtDZX1RMaXar%2B2fPxqCUJAYf6JqYgIo04DEJPI38RIVNBP%2BxuZEM3KgPV9JqS0uZBV4pZ29EsLvAukQti8IBOtqu0qcvIaS97FFbe5SkLzj2fx04MDGbWf%2BxWzNxSTJfQHHXJmpz2iPLWtot11KcQzhjM1oeW99QNvczYSb0lyN%2F2%2BOPSe7KjGioWZA%3D%3D&amp;Expires=1788868712" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">A central concern is the campaign’s persistence. Scheduled tasks ran as SYSTEM, used forged author details and included backdated registration dates. </p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjf2ODrdgFLf_IytHIsWiFIvPRSYmf9ff6RdhKxV0z8urOlquQNI41O6xqUn-rs0n4V2J1Opxa_IrHhFWMtxcz76iJ6vi1t5SbK9sWNhlATQQvcput5zADTzGlBhu5teBYMAb1yCfBQyI_XzYcVJVYfwmiTVj3B0IC6bhOeCPXrAijIsT4izhTjoUUaMvw/s1600/Kill%20Chain%20(Source%20-%20THE%20HUNTER%E2%80%99S%20LEDGER).webp" alt="Kill Chain (Source - THE HUNTER’S LEDGER)" /><figcaption class="wp-element-caption">Kill Chain (Source &#8211; THE HUNTER’S LEDGER)</figcaption></figure>
</div>


<p class="wp-block-paragraph">One weekly task downloaded the latest attack chain without saving a fixed payload, a tactic similar to <a href="https://cybersecuritynews.com/remote-scheduled-tasks-etherrat/" target="_blank" rel="noopener">remote scheduled task delivery</a> in EtherRAT attacks.<a href="https://cybersecuritynews.com/remote-scheduled-tasks-etherrat/" target="_blank" rel="noopener"></a><a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/9fb6ab04-f4fb-4358-ac12-8d4b5bbba988/Hackers-Disable-Endpoint-Protection-and-Deploy-Sliver-Across-Compromised-Windows-Domain.pdf?AWSAccessKeyId=ASIA2F3EMEYE64QQ5OGM&amp;Signature=D9O%2BcoFeSHzSbFkE7VDmDm8R5Zw%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCb5s%2BdXOODjaRFD%2B99da7s%2FATJHzDW%2F6ZcJbarp8UuXgIhANAGF7meBIMrftCfH7XfQh9Srl6b%2Fh7sreidHb3BxgBJKvMECFQQARoMNjk5NzUzMzA5NzA1IgyBsexw2u592pGIWNQq0AT9ZnCGcnsELBIIBQMK8PqKvJ48ctmkVEoRqNPzBp4SfMpU66DF%2Flu4NHAbGL0P%2BCk4%2F61FV0Ozbh4pfF%2Fz2Nh4OvfyzV3Bwc%2FkUwWv5%2F52Jhcv7kxnhxj1cMHtMlt9ec1DFoBndT3Swhh3OIKOxE2yIfpndRFkXX95XushRH2O08J6Xezwa3j9xpzSQQjDCaCJo6JO7pgKOhK3Zx36Va5pev4bLY83XgZmKxKkTJ2S69kPSI8eVgbwpuyCnia4XW2P1s7mEQJvOaBl1iQe6VcX%2BPzzRriMqKrxqoeYU9lhRC5AZRGlLLaoHCyJpy9nCeWRwkZtp3iodlmEMitDUPmTVx95WhMJegQ%2FkYZ6H7iXwzXz4t%2FUu4s16pUF3Y9NYJlUla9MS3dZZIeECeWFtgmw3cM4Sd94rAHVMCZbC94r6nAh7bFSVy3eznE4JKEihz8dGpHWpVeGq0etU3NDpc2Z5toyRo5GB%2F9A%2FeXJ9GhyCAlgVXjLLZRSJkQXfitj5JkJPMAONG2Vw0%2FK0jcaXxCuFA7aZ6XanOKBM6EPR1IQwVDz2Tty17BPj8zOeHuLooZI%2FCJ7%2BGUUbrbiovioXxzYsKZmYRM7DWo3kgCYa36ve2L2eRY4e%2FH5xAk593lMdEGKf6RiesbqZOCVmlQDgH5jLxH0KEgS%2FjSLCHZ9GBKfXbYJn%2Bg2CKOEZni0o9IPb4kSEkOXqXGkLf1pxGNrOidiE%2Fx0XkGhgAJD9U00ryxOpMc0hLFeZLXcgOQqoolks5AwLM%2F9ieAAAEuHXoYd%2BNYRMJXV%2F9QGOpcBzauM8N9EXQ1yCPdjtDZX1RMaXar%2B2fPxqCUJAYf6JqYgIo04DEJPI38RIVNBP%2BxuZEM3KgPV9JqS0uZBV4pZ29EsLvAukQti8IBOtqu0qcvIaS97FFbe5SkLzj2fx04MDGbWf%2BxWzNxSTJfQHHXJmpz2iPLWtot11KcQzhjM1oeW99QNvczYSb0lyN%2F2%2BOPSe7KjGioWZA%3D%3D&amp;Expires=1788868712" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">The team also manipulated the victim’s DNS content filter through its administrative interface. It added the attackers’ domain to an allowlist and placed a matching record in internal DNS, making the domain resolve internally and pass the same security control intended to block it.<a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/9fb6ab04-f4fb-4358-ac12-8d4b5bbba988/Hackers-Disable-Endpoint-Protection-and-Deploy-Sliver-Across-Compromised-Windows-Domain.pdf?AWSAccessKeyId=ASIA2F3EMEYE64QQ5OGM&amp;Signature=D9O%2BcoFeSHzSbFkE7VDmDm8R5Zw%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCb5s%2BdXOODjaRFD%2B99da7s%2FATJHzDW%2F6ZcJbarp8UuXgIhANAGF7meBIMrftCfH7XfQh9Srl6b%2Fh7sreidHb3BxgBJKvMECFQQARoMNjk5NzUzMzA5NzA1IgyBsexw2u592pGIWNQq0AT9ZnCGcnsELBIIBQMK8PqKvJ48ctmkVEoRqNPzBp4SfMpU66DF%2Flu4NHAbGL0P%2BCk4%2F61FV0Ozbh4pfF%2Fz2Nh4OvfyzV3Bwc%2FkUwWv5%2F52Jhcv7kxnhxj1cMHtMlt9ec1DFoBndT3Swhh3OIKOxE2yIfpndRFkXX95XushRH2O08J6Xezwa3j9xpzSQQjDCaCJo6JO7pgKOhK3Zx36Va5pev4bLY83XgZmKxKkTJ2S69kPSI8eVgbwpuyCnia4XW2P1s7mEQJvOaBl1iQe6VcX%2BPzzRriMqKrxqoeYU9lhRC5AZRGlLLaoHCyJpy9nCeWRwkZtp3iodlmEMitDUPmTVx95WhMJegQ%2FkYZ6H7iXwzXz4t%2FUu4s16pUF3Y9NYJlUla9MS3dZZIeECeWFtgmw3cM4Sd94rAHVMCZbC94r6nAh7bFSVy3eznE4JKEihz8dGpHWpVeGq0etU3NDpc2Z5toyRo5GB%2F9A%2FeXJ9GhyCAlgVXjLLZRSJkQXfitj5JkJPMAONG2Vw0%2FK0jcaXxCuFA7aZ6XanOKBM6EPR1IQwVDz2Tty17BPj8zOeHuLooZI%2FCJ7%2BGUUbrbiovioXxzYsKZmYRM7DWo3kgCYa36ve2L2eRY4e%2FH5xAk593lMdEGKf6RiesbqZOCVmlQDgH5jLxH0KEgS%2FjSLCHZ9GBKfXbYJn%2Bg2CKOEZni0o9IPb4kSEkOXqXGkLf1pxGNrOidiE%2Fx0XkGhgAJD9U00ryxOpMc0hLFeZLXcgOQqoolks5AwLM%2F9ieAAAEuHXoYd%2BNYRMJXV%2F9QGOpcBzauM8N9EXQ1yCPdjtDZX1RMaXar%2B2fPxqCUJAYf6JqYgIo04DEJPI38RIVNBP%2BxuZEM3KgPV9JqS0uZBV4pZ29EsLvAukQti8IBOtqu0qcvIaS97FFbe5SkLzj2fx04MDGbWf%2BxWzNxSTJfQHHXJmpz2iPLWtot11KcQzhjM1oeW99QNvczYSb0lyN%2F2%2BOPSe7KjGioWZA%3D%3D&amp;Expires=1788868712"></a></p>



<p class="wp-block-paragraph">This approach mirrors a broader pattern in Windows intrusions, where trusted administrative features become the delivery system after access is obtained. </p>



<p class="wp-block-paragraph">Recent reporting on <a href="https://cybersecuritynews.com/silver-fox-linked-hackers/" target="_blank" rel="noopener">fake installer campaigns disabling Defender</a> also showed attackers using installer workflows and scheduled tasks to weaken controls before maintaining access. In both cases, the danger is not a single tool but the sequence of actions surrounding it.<a href="https://cybersecuritynews.com/silver-fox-linked-hackers/" target="_blank" rel="noopener"></a></p>



<h2 id="h-blockchain-c2-complicates-response" class="wp-block-heading"><strong>Blockchain C2 Complicates Response</strong></h2>



<p class="wp-block-paragraph">Alongside Sliver, the toolkit used a Node.js implant that obtained its command server from an Ethereum smart contract. </p>



<p class="wp-block-paragraph">The first domain recorded in that contract was the same one inserted into the victim’s DNS configuration, directly connecting the two seemingly different parts of the operation.<a href="https://the-hunters-ledger.com/reports/sliver-c2-windows-postex-staging-193-233-202-17/" target="_blank" rel="noopener"></a><a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/9fb6ab04-f4fb-4358-ac12-8d4b5bbba988/Hackers-Disable-Endpoint-Protection-and-Deploy-Sliver-Across-Compromised-Windows-Domain.pdf?AWSAccessKeyId=ASIA2F3EMEYE64QQ5OGM&amp;Signature=D9O%2BcoFeSHzSbFkE7VDmDm8R5Zw%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCb5s%2BdXOODjaRFD%2B99da7s%2FATJHzDW%2F6ZcJbarp8UuXgIhANAGF7meBIMrftCfH7XfQh9Srl6b%2Fh7sreidHb3BxgBJKvMECFQQARoMNjk5NzUzMzA5NzA1IgyBsexw2u592pGIWNQq0AT9ZnCGcnsELBIIBQMK8PqKvJ48ctmkVEoRqNPzBp4SfMpU66DF%2Flu4NHAbGL0P%2BCk4%2F61FV0Ozbh4pfF%2Fz2Nh4OvfyzV3Bwc%2FkUwWv5%2F52Jhcv7kxnhxj1cMHtMlt9ec1DFoBndT3Swhh3OIKOxE2yIfpndRFkXX95XushRH2O08J6Xezwa3j9xpzSQQjDCaCJo6JO7pgKOhK3Zx36Va5pev4bLY83XgZmKxKkTJ2S69kPSI8eVgbwpuyCnia4XW2P1s7mEQJvOaBl1iQe6VcX%2BPzzRriMqKrxqoeYU9lhRC5AZRGlLLaoHCyJpy9nCeWRwkZtp3iodlmEMitDUPmTVx95WhMJegQ%2FkYZ6H7iXwzXz4t%2FUu4s16pUF3Y9NYJlUla9MS3dZZIeECeWFtgmw3cM4Sd94rAHVMCZbC94r6nAh7bFSVy3eznE4JKEihz8dGpHWpVeGq0etU3NDpc2Z5toyRo5GB%2F9A%2FeXJ9GhyCAlgVXjLLZRSJkQXfitj5JkJPMAONG2Vw0%2FK0jcaXxCuFA7aZ6XanOKBM6EPR1IQwVDz2Tty17BPj8zOeHuLooZI%2FCJ7%2BGUUbrbiovioXxzYsKZmYRM7DWo3kgCYa36ve2L2eRY4e%2FH5xAk593lMdEGKf6RiesbqZOCVmlQDgH5jLxH0KEgS%2FjSLCHZ9GBKfXbYJn%2Bg2CKOEZni0o9IPb4kSEkOXqXGkLf1pxGNrOidiE%2Fx0XkGhgAJD9U00ryxOpMc0hLFeZLXcgOQqoolks5AwLM%2F9ieAAAEuHXoYd%2BNYRMJXV%2F9QGOpcBzauM8N9EXQ1yCPdjtDZX1RMaXar%2B2fPxqCUJAYf6JqYgIo04DEJPI38RIVNBP%2BxuZEM3KgPV9JqS0uZBV4pZ29EsLvAukQti8IBOtqu0qcvIaS97FFbe5SkLzj2fx04MDGbWf%2BxWzNxSTJfQHHXJmpz2iPLWtot11KcQzhjM1oeW99QNvczYSb0lyN%2F2%2BOPSe7KjGioWZA%3D%3D&amp;Expires=1788868712" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">The contract changed domains five times over five months, making simple domain blocks short-lived. Yet the contract itself stayed unchanged and publicly readable, giving defenders a better tracking point. </p>



<p class="wp-block-paragraph">The related beacon also contacted its main server every 60 seconds with no measured timing variation, a useful signal for network hunting.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/9fb6ab04-f4fb-4358-ac12-8d4b5bbba988/Hackers-Disable-Endpoint-Protection-and-Deploy-Sliver-Across-Compromised-Windows-Domain.pdf?AWSAccessKeyId=ASIA2F3EMEYE64QQ5OGM&amp;Signature=D9O%2BcoFeSHzSbFkE7VDmDm8R5Zw%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCb5s%2BdXOODjaRFD%2B99da7s%2FATJHzDW%2F6ZcJbarp8UuXgIhANAGF7meBIMrftCfH7XfQh9Srl6b%2Fh7sreidHb3BxgBJKvMECFQQARoMNjk5NzUzMzA5NzA1IgyBsexw2u592pGIWNQq0AT9ZnCGcnsELBIIBQMK8PqKvJ48ctmkVEoRqNPzBp4SfMpU66DF%2Flu4NHAbGL0P%2BCk4%2F61FV0Ozbh4pfF%2Fz2Nh4OvfyzV3Bwc%2FkUwWv5%2F52Jhcv7kxnhxj1cMHtMlt9ec1DFoBndT3Swhh3OIKOxE2yIfpndRFkXX95XushRH2O08J6Xezwa3j9xpzSQQjDCaCJo6JO7pgKOhK3Zx36Va5pev4bLY83XgZmKxKkTJ2S69kPSI8eVgbwpuyCnia4XW2P1s7mEQJvOaBl1iQe6VcX%2BPzzRriMqKrxqoeYU9lhRC5AZRGlLLaoHCyJpy9nCeWRwkZtp3iodlmEMitDUPmTVx95WhMJegQ%2FkYZ6H7iXwzXz4t%2FUu4s16pUF3Y9NYJlUla9MS3dZZIeECeWFtgmw3cM4Sd94rAHVMCZbC94r6nAh7bFSVy3eznE4JKEihz8dGpHWpVeGq0etU3NDpc2Z5toyRo5GB%2F9A%2FeXJ9GhyCAlgVXjLLZRSJkQXfitj5JkJPMAONG2Vw0%2FK0jcaXxCuFA7aZ6XanOKBM6EPR1IQwVDz2Tty17BPj8zOeHuLooZI%2FCJ7%2BGUUbrbiovioXxzYsKZmYRM7DWo3kgCYa36ve2L2eRY4e%2FH5xAk593lMdEGKf6RiesbqZOCVmlQDgH5jLxH0KEgS%2FjSLCHZ9GBKfXbYJn%2Bg2CKOEZni0o9IPb4kSEkOXqXGkLf1pxGNrOidiE%2Fx0XkGhgAJD9U00ryxOpMc0hLFeZLXcgOQqoolks5AwLM%2F9ieAAAEuHXoYd%2BNYRMJXV%2F9QGOpcBzauM8N9EXQ1yCPdjtDZX1RMaXar%2B2fPxqCUJAYf6JqYgIo04DEJPI38RIVNBP%2BxuZEM3KgPV9JqS0uZBV4pZ29EsLvAukQti8IBOtqu0qcvIaS97FFbe5SkLzj2fx04MDGbWf%2BxWzNxSTJfQHHXJmpz2iPLWtot11KcQzhjM1oeW99QNvczYSb0lyN%2F2%2BOPSe7KjGioWZA%3D%3D&amp;Expires=1788868712" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">The recommended response is to reset credentials across the affected domain, not solely for known accounts; review privileged-group additions and SYSTEM tasks; restore the DNS allowlist; rotate the filter administrator password; and remove planted internal DNS entries. </p>



<p class="wp-block-paragraph">Teams should also look for RDP enabled with Network Level Authentication disabled and monitor the contract for later C2 changes. <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/9fb6ab04-f4fb-4358-ac12-8d4b5bbba988/Hackers-Disable-Endpoint-Protection-and-Deploy-Sliver-Across-Compromised-Windows-Domain.pdf?AWSAccessKeyId=ASIA2F3EMEYE64QQ5OGM&amp;Signature=D9O%2BcoFeSHzSbFkE7VDmDm8R5Zw%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCb5s%2BdXOODjaRFD%2B99da7s%2FATJHzDW%2F6ZcJbarp8UuXgIhANAGF7meBIMrftCfH7XfQh9Srl6b%2Fh7sreidHb3BxgBJKvMECFQQARoMNjk5NzUzMzA5NzA1IgyBsexw2u592pGIWNQq0AT9ZnCGcnsELBIIBQMK8PqKvJ48ctmkVEoRqNPzBp4SfMpU66DF%2Flu4NHAbGL0P%2BCk4%2F61FV0Ozbh4pfF%2Fz2Nh4OvfyzV3Bwc%2FkUwWv5%2F52Jhcv7kxnhxj1cMHtMlt9ec1DFoBndT3Swhh3OIKOxE2yIfpndRFkXX95XushRH2O08J6Xezwa3j9xpzSQQjDCaCJo6JO7pgKOhK3Zx36Va5pev4bLY83XgZmKxKkTJ2S69kPSI8eVgbwpuyCnia4XW2P1s7mEQJvOaBl1iQe6VcX%2BPzzRriMqKrxqoeYU9lhRC5AZRGlLLaoHCyJpy9nCeWRwkZtp3iodlmEMitDUPmTVx95WhMJegQ%2FkYZ6H7iXwzXz4t%2FUu4s16pUF3Y9NYJlUla9MS3dZZIeECeWFtgmw3cM4Sd94rAHVMCZbC94r6nAh7bFSVy3eznE4JKEihz8dGpHWpVeGq0etU3NDpc2Z5toyRo5GB%2F9A%2FeXJ9GhyCAlgVXjLLZRSJkQXfitj5JkJPMAONG2Vw0%2FK0jcaXxCuFA7aZ6XanOKBM6EPR1IQwVDz2Tty17BPj8zOeHuLooZI%2FCJ7%2BGUUbrbiovioXxzYsKZmYRM7DWo3kgCYa36ve2L2eRY4e%2FH5xAk593lMdEGKf6RiesbqZOCVmlQDgH5jLxH0KEgS%2FjSLCHZ9GBKfXbYJn%2Bg2CKOEZni0o9IPb4kSEkOXqXGkLf1pxGNrOidiE%2Fx0XkGhgAJD9U00ryxOpMc0hLFeZLXcgOQqoolks5AwLM%2F9ieAAAEuHXoYd%2BNYRMJXV%2F9QGOpcBzauM8N9EXQ1yCPdjtDZX1RMaXar%2B2fPxqCUJAYf6JqYgIo04DEJPI38RIVNBP%2BxuZEM3KgPV9JqS0uZBV4pZ29EsLvAukQti8IBOtqu0qcvIaS97FFbe5SkLzj2fx04MDGbWf%2BxWzNxSTJfQHHXJmpz2iPLWtot11KcQzhjM1oeW99QNvczYSb0lyN%2F2%2BOPSe7KjGioWZA%3D%3D&amp;Expires=1788868712" target="_blank" rel="noopener"></a>Security teams should favor behavior over broad signatures for public tools. </p>



<p class="wp-block-paragraph">Baseline scheduled tasks, alert on fileless download commands running as SYSTEM and review sudden endpoint-protection service changes. </p>



<p class="wp-block-paragraph">Readers examining related Windows tradecraft can compare <a href="https://cybersecuritynews.com/sliver-implant-attacking-german-entities/amp/" target="_blank" rel="noopener">Sliver implant activity targeting Germany</a> and <a href="https://cybersecuritynews.com/ransomware-uses-system-scheduled-task/" target="_blank" rel="noopener">ransomware SYSTEM task abuse</a>, which show how familiar components can be chained into an enterprise-wide incident. The pattern deserves sustained, careful attention.</p>



<p class="wp-block-paragraph"><strong>Indicators of compromise (IoCs):-</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>IPv4 address</td><td><code>193.233.202.17</code></td><td>Primary Sliver command-and-control and staging-server address</td></tr><tr><td>IPv4 address</td><td><code>77.110.126.46</code></td><td>Hardcoded third-tier fallback address, designated hunt-only</td></tr><tr><td>IPv4 address</td><td><code>146.103.127.44</code></td><td>Historical operator-used address from April 2026, designated monitor-only</td></tr><tr><td>Domain</td><td><code>publisherresolution.com</code></td><td>First C2 domain written to the Ethereum resolver contract</td></tr><tr><td>Domain</td><td><code>resumeacceptable.com</code></td><td>Historical Ethereum resolver C2 domain</td></tr><tr><td>Domain</td><td><code>simultaneouslypower.com</code></td><td>Historical Ethereum resolver C2 domain</td></tr><tr><td>Domain</td><td><code>wiselystarting.com</code></td><td>Historical Ethereum resolver C2 domain</td></tr><tr><td>Domain</td><td><code>itemrange.com</code></td><td>Most recently recorded Ethereum resolver C2 domain</td></tr><tr><td>URL</td><td><code>https://publisherresolution.com</code></td><td>Ethereum resolver contract value</td></tr><tr><td>URL</td><td><code>https://resumeacceptable.com</code></td><td>Ethereum resolver contract value</td></tr><tr><td>URL</td><td><code>https://simultaneouslypower.com</code></td><td>Ethereum resolver contract value</td></tr><tr><td>URL</td><td><code>https://wiselystarting.com</code></td><td>Ethereum resolver contract value</td></tr><tr><td>URL</td><td><code>https://itemrange.com</code></td><td>Ethereum resolver contract value</td></tr><tr><td>URL</td><td><code>http://193.233.202.17:42718/task_39.ps1</code></td><td>Fileless PowerShell download location used by the persistence task</td></tr><tr><td>File name</td><td><code>svcload.exe</code></td><td>Modified PrintSpoofer derivative</td></tr><tr><td>File name</td><td><code>ws35.exe</code></td><td>Reverse-shell sample containing the fallback address</td></tr><tr><td>File name</td><td><code>ws36.exe</code></td><td>Reverse-shell sample containing the fallback address</td></tr><tr><td>File name</td><td><code>ws37.exe</code></td><td>Reverse-shell sample containing the fallback address</td></tr><tr><td>File name</td><td><code>ws_3srv.exe</code></td><td>Reverse-shell sample containing the fallback address</td></tr><tr><td>File name</td><td><code>task_39.ps1</code></td><td>PowerShell payload retrieved by the scheduled task</td></tr><tr><td>File name</td><td><code>slv_beacon_sc.bin</code></td><td>Sliver beacon shellcode payload</td></tr><tr><td>Smart contract</td><td><code>0xb3f2897f2bc797e5b9033faef8c81e92b01cb831</code></td><td>Ethereum contract used to resolve the Node.js implant’s C2 location</td></tr><tr><td>MSI UpgradeCode</td><td><code>{B3D67F25-0E3A-4B6B-965C-2C7610958983}</code></td><td>Stable installer identifier observed in the MSI package</td></tr><tr><td>User-Agent</td><td><code>Chrome/108.0.6602.492</code></td><td>Hardcoded malformed User-Agent associated with the campaign’s request profile</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong>Keep your SOC&nbsp;up to date on active malware &amp; phishing within 24h of their emergence.&nbsp;<a href="https://any.run/threat-intelligence-feeds/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=cta_links&amp;utm_content=landing_feeds&amp;utm_term=sep_26#contact-sales" target="_blank" rel="noreferrer noopener nofollow">Try ANYRUN to prevent incidents with early detection</a></strong></strong>.</p>
<p>The post <a href="https://cybersecuritynews.com/hackers-disable-endpoint-protection/">Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/09/Hackers-Disable-Endpoint-Protection-and-Deploy-Sliver-Across-Compromised-Windows-Domain.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">162518</post-id>	</item>
		<item>
		<title>WeWorm &#8211; First 0-Click Worm Spreading Through WeChat Calls Across iOS and Android</title>
		<link>https://cybersecuritynews.com/weworm-first-0-click-worm/</link>
		
		<dc:creator><![CDATA[Guru Baran]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 12:09:47 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=162555</guid>

					<description><![CDATA[<p>A proof-of-concept zero-click worm dubbed “WeWorm” that it says can spread through WeChat voice calls on both iOS and Android, compromising a target’s WeChat account in seconds without the victim answering the call. Calif says the bug was reported to Tencent in July and that Tencent has since mitigated the exploit for users, but the [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/weworm-first-0-click-worm/">WeWorm &#8211; First 0-Click Worm Spreading Through WeChat Calls Across iOS and Android</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A proof-of-concept zero-click worm dubbed “WeWorm” that it says can spread through WeChat voice calls on both iOS and Android, compromising a target’s WeChat account in seconds without the victim answering the call.</p>



<p class="wp-block-paragraph">Calif says the bug was reported to Tencent in July and that Tencent has since mitigated the exploit for users, but the research still serves as a stark warning about how mobile messaging apps can become wormable attack surfaces at planetary scale.</p>



<p class="wp-block-paragraph">WeChat is not a niche target. Tencent says Weixin and WeChat together exceeded 1.4 billion monthly active users as of the end of Q1 2026, while WeChat’s own site describes the platform as serving over 1 billion users with chats and calls across major mobile and desktop platforms.</p>



<p class="wp-block-paragraph">That sheer reach is what makes Calif’s demonstration so alarming: a memory-corruption flaw in the app’s <a href="https://cybersecuritynews.com/grandstream-gxp1600-voip-phones-rce-vulnerability/" target="_blank" rel="noreferrer noopener">VoIP stack</a> is not just another messaging bug, but a potential entry point into one of the world’s most deeply embedded communications ecosystems.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe title="WeWorm: the first zero-click worm to spread through WeChat calls across iOS and Android" width="696" height="522" src="https://www.youtube.com/embed/OQdagtqKoXg?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
</div></figure>



<p class="wp-block-paragraph">According to<a href="https://calif.io/research/weworm" target="_blank" rel="noreferrer noopener nofollow"> Calif’s public research listing</a>, WeWorm is described as “the first zero-click worm to spread through WeChat calls across iOS and Android,” and it was published on September 8, 2026, as part of the company’s Android-tagged research work.</p>



<p class="wp-block-paragraph">Calif frames the finding not as a theoretical edge case but as a live demonstration of how a trusted messaging relationship can be weaponized, with one compromised contact becoming the launch point for attacks against everyone in that person’s social graph.</p>



<p class="wp-block-paragraph">The company’s demo chain reportedly used three phones to prove cross-platform propagation. A Pixel 10a was used as the initial attacker device, which then called an iPhone 17e and exploited the flaw while the call was still ringing; the compromised iPhone was then used to call another Pixel 10a, which was reportedly taken over in the same way.</p>



<p class="wp-block-paragraph">In practical terms, that is the textbook definition of a wormable condition in a communications app: the attacker calls the victim, the victim becomes the attacker, and the infection path continues with almost no friction.</p>



<p class="wp-block-paragraph">What makes the scenario especially dangerous is the “zero-click” aspect. Calif says the victim does not need to answer the call or interact with the phone at all for exploitation to succeed, and even if the person does answer, they hear nothing while the compromise still goes through.</p>



<p class="wp-block-paragraph">That claim places WeWorm in the most feared class of mobile exploits, where normal user caution offers little protection because there is no malicious link to avoid and no attachment to reject.</p>



<p class="wp-block-paragraph">Calif also says exploitation yields full control of the victim’s <a href="https://cybersecuritynews.com/north-korean-it-worker-allegedly-used-stolen-identity/" target="_blank" rel="noreferrer noopener">WeChat account</a>, including the ability to read and send messages, place calls, and act on the user’s behalf inside the app.</p>



<p class="wp-block-paragraph">On its own, account takeover at that level would already be severe for identity abuse, surveillance, fraud, and lateral targeting; chained with additional device-level bugs, Calif says the same access could be extended to full control of the underlying Android or iOS device.</p>



<p class="wp-block-paragraph">The company specifically links that possibility to its broader AI-assisted exploit research, including Android work such as OEMpocalypse, which it has presented as a path from app-level access to root on several vendor ecosystems.</p>



<p class="wp-block-paragraph">One condition slightly narrows the attack surface: the attacker must already be on the victim’s friend list. But Calif argues that this is a weak barrier in real-world conditions because once a single trusted contact is compromised, that person’s account can be used to reach additional friends, turning the victim’s social trust network into the worm’s propagation layer.</p>



<p class="wp-block-paragraph">That is a familiar and troubling pattern in modern communications security, where safety features and trust assumptions designed for convenience can become force multipliers once an adversary gets an initial foothold.</p>



<p class="wp-block-paragraph">The technical root cause, Calif says, is a memory-corruption bug in WeChat’s VoIP stack, though the company is withholding full exploit details until a later conference presentation.</p>



<p class="wp-block-paragraph">That restraint matters because memory-corruption flaws in real-time communications code are among the most sensitive bug classes in mobile security, especially when they sit inside call-handling paths that process network data before a user takes any action.</p>



<p class="wp-block-paragraph">Calif further suggests that this bug is only one example of a broader class of “unconventional attack surfaces” spread across messaging apps, hinting that similar issues may exist in other platforms with rich calling and media features.</p>



<p class="wp-block-paragraph">WeWorm may be a demo, but its significance is real. Calif has effectively shown that mobile messaging worms are no longer a distant nightmare or a plot device for conference talks; they are a practical research outcome in 2026, built against one of the world’s largest communications platforms and developed at AI speed.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)"><strong><strong>Learn 7 Metric-Gated AI SOC Deployment Phases &#8211; <strong><strong><a href="https://underdefense.com/ai-soc-deployment-playbook-from-assessment-to-autonomy/?utm_source=cybersecuritynews.com&amp;utm_medium=online_media&amp;utm_campaign=csn_linkedin_newsletter_ai_soc_deployment_playbook_september_2026" target="_blank" rel="noreferrer noopener nofollow">Download Free AI SOC Deployment Playbook 2026</a></strong></strong>.</strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/weworm-first-0-click-worm/">WeWorm &#8211; First 0-Click Worm Spreading Through WeChat Calls Across iOS and Android</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/09/WeWorm-First-0-Click-Worm.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">162555</post-id>	</item>
		<item>
		<title>SAP Security Updates September 2026 &#8211; Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport</title>
		<link>https://cybersecuritynews.com/sap-security-updates-september-2026/</link>
		
		<dc:creator><![CDATA[Abinaya]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 11:19:03 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[Vulnerability News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=162531</guid>

					<description><![CDATA[<p>SAP has released its September 2026 Security Patch Day updates, delivering 19 new security notes and one update to a previously issued note. The patches address vulnerabilities across SAP NetWeaver, SAP Extended Passport Processing, SAP Cloud Application Programming Model, SAP S/4HANA, SAP Integration Suite, SAP Commerce Cloud, and other enterprise products. The most severe issue [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/sap-security-updates-september-2026/">SAP Security Updates September 2026 &#8211; Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">SAP has released its September 2026<a href="https://cybersecuritynews.com/sap-security-update-july-2026/" target="_blank" rel="noreferrer noopener"> Security Patch Day updates</a>, delivering 19 new security notes and one update to a previously issued note.</p>



<p class="wp-block-paragraph">The patches address vulnerabilities across SAP NetWeaver, SAP Extended Passport Processing, SAP Cloud Application Programming Model, SAP S/4HANA, SAP Integration Suite, SAP Commerce Cloud, and other enterprise products.</p>



<p class="wp-block-paragraph">The most severe issue is CVE-2026-44756, a critical <a href="https://cybersecuritynews.com/sap-vulnerabilities-malicious-code-injection/" target="_blank" rel="noreferrer noopener">memory corruption vulnerability in SAP </a>Extended Passport Processing, tracked under SAP Note 3747649. It carries a CVSS score of 10.0, the highest possible severity rating.</p>



<p class="wp-block-paragraph">The flaw affects multiple SAP kernel and Web Dispatcher versions, including KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, and 9.16 through 9.20.</p>



<p class="wp-block-paragraph">An unauthenticated remote attacker could potentially exploit the memory corruption flaw to compromise confidentiality, integrity, and availability. Organizations using affected SAP kernel components should treat this update as an emergency patching priority.</p>



<p class="wp-block-paragraph">Another critical vulnerability, CVE-2026-58240, affects SAP NetWeaver Message Server. SAP Note 3759472 addresses a <a href="https://cybersecuritynews.com/check-point-zero-day-poc-released/" target="_blank" rel="noreferrer noopener">missing authentication check</a> with a CVSS score of 9.8. The issue affects KERNEL versions 9.16, 9.18, 9.19, and 9.20.</p>



<p class="wp-block-paragraph">Successful exploitation could allow an attacker without valid credentials to access or interact with exposed services, creating a serious risk to SAP environments.</p>



<h2 id="h-sap-security-updates-september-2026" class="wp-block-heading"><strong>SAP Security Updates September 2026</strong></h2>



<p class="wp-block-paragraph">SAP also fixed CVE-2026-76969, a critical credential disclosure vulnerability in multitenant applications using the SAP Cloud Application Programming Model library sap/cds-mtxs.</p>



<p class="wp-block-paragraph">The flaw has a CVSS score of 9.4 and affects versions up to 1.18.3, 2.7.6, 3.9.6, and 4.0.2. Developers and cloud administrators should update affected dependencies quickly, especially where they handle tenant data and application credentials.</p>



<p class="wp-block-paragraph">A fourth critical issue, CVE-2026-66768, impacts SAP GUI for Java in SAP NetWeaver. The improper access control vulnerability, fixed by SAP Note 3781729, has a CVSS score of 9.0. It affects BC-FES-JAV 8.10 and could allow a low-privileged attacker to gain unauthorized access after user interaction.</p>



<p class="wp-block-paragraph">The <a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2026.html?isu_page=1" target="_blank" rel="noreferrer noopener nofollow">September release also includes high-severity fixes</a>, including CVE-2026-76958, an 8.5-rated XXE flaw in SAP Integration Suite Trading Partner Management that could expose sensitive files, enable server-side requests, or disrupt XML processing.</p>



<p class="wp-block-paragraph">SAP patched insecure deserialization in SAP NetWeaver Business Client, memory corruption in SAP NetWeaver Application Server for ABAP and ABAP Platform, and CRLF injection in SAP Commerce Cloud Search and Navigation.</p>



<p class="wp-block-paragraph">The company also released an update for CVE-2026-58243, a high-severity privilege escalation flaw in SAP ABAP Developer Tools originally addressed during the August 2026 Patch Day.</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">SAP Note</th><th class="has-text-align-left" data-align="left">CVE</th><th class="has-text-align-left" data-align="left">Vulnerability</th><th class="has-text-align-left" data-align="left">Affected product/versions</th><th class="has-text-align-left" data-align="left">Priority</th></tr></thead><tbody><tr><td class="has-text-align-left" data-align="left">3747649</td><td class="has-text-align-left" data-align="left">CVE-2026-44756</td><td class="has-text-align-left" data-align="left">Memory corruption</td><td class="has-text-align-left" data-align="left">SAP Extended Passport (EPP) Processing<br>KRNL64NUC: 7.22, 7.22EXT; KRNL64UC: 7.22, 7.22EXT, 7.53, 8.04; WEBDISP: 9.16, 9.18, 9.19, 9.20; KERNEL: 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20</td><td class="has-text-align-left" data-align="left">Critical</td></tr><tr><td class="has-text-align-left" data-align="left">3759472</td><td class="has-text-align-left" data-align="left">CVE-2026-58240</td><td class="has-text-align-left" data-align="left">Missing authentication check</td><td class="has-text-align-left" data-align="left">SAP NetWeaver Message Server<br>KERNEL: 9.16, 9.18, 9.19, 9.20</td><td class="has-text-align-left" data-align="left">Critical</td></tr><tr><td class="has-text-align-left" data-align="left">3798315</td><td class="has-text-align-left" data-align="left">CVE-2026-76969</td><td class="has-text-align-left" data-align="left">Credential disclosure in multitenant CAP applications</td><td class="has-text-align-left" data-align="left">SAP CAP library <code>sap/cds-mtxs</code><br>Versions: ≤1.18.3, ≤2.7.6, ≤3.9.6, ≤4.0.2</td><td class="has-text-align-left" data-align="left">Critical</td></tr><tr><td class="has-text-align-left" data-align="left">3781729</td><td class="has-text-align-left" data-align="left">CVE-2026-66768</td><td class="has-text-align-left" data-align="left">Improper access control</td><td class="has-text-align-left" data-align="left">SAP NetWeaver SAP GUI for Java<br>BC-FES-JAV: 8.10</td><td class="has-text-align-left" data-align="left">Critical</td></tr><tr><td class="has-text-align-left" data-align="left">3772411</td><td class="has-text-align-left" data-align="left">CVE-2026-58243</td><td class="has-text-align-left" data-align="left">Privilege escalation — <strong>updated August note</strong></td><td class="has-text-align-left" data-align="left">SAP ABAP Developer Tools<br>SAP_BASIS: 750, 751, 752, 753, 754, 755, 756, 757, 758, 816, 918, 920</td><td class="has-text-align-left" data-align="left">High</td></tr><tr><td class="has-text-align-left" data-align="left">3792978</td><td class="has-text-align-left" data-align="left">CVE-2026-76958</td><td class="has-text-align-left" data-align="left">XML External Entity (XXE)</td><td class="has-text-align-left" data-align="left">SAP Integration Suite<br>Cloud Integration – Trading Partner Management V2: 2.9.2; B2B Integration Factory – Cloud Integration – Trading Partner Management: 1.10.0</td><td class="has-text-align-left" data-align="left">High</td></tr><tr><td class="has-text-align-left" data-align="left">3784138</td><td class="has-text-align-left" data-align="left">CVE-2026-76967</td><td class="has-text-align-left" data-align="left">Insecure deserialization</td><td class="has-text-align-left" data-align="left">SAP NetWeaver Business Client<br>BC-WD-CLT-BUS: 8.00, 8.10</td><td class="has-text-align-left" data-align="left">High</td></tr><tr><td class="has-text-align-left" data-align="left">3757002</td><td class="has-text-align-left" data-align="left">CVE-2026-66767</td><td class="has-text-align-left" data-align="left">Memory corruption</td><td class="has-text-align-left" data-align="left">SAP NetWeaver AS for ABAP and ABAP Platform<br>KRNL64NUC: 7.22, 7.22EXT; KRNL64UC: 7.22, 7.22EXT, 7.53, 8.04; KERNEL: 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20</td><td class="has-text-align-left" data-align="left">High</td></tr><tr><td class="has-text-align-left" data-align="left">3791068</td><td class="has-text-align-left" data-align="left">CVE-2026-2332</td><td class="has-text-align-left" data-align="left">CRLF injection through Jetty components</td><td class="has-text-align-left" data-align="left">SAP Commerce Cloud Search and Navigation<br>COM_CLOUD: 2211, 2211-JDK21</td><td class="has-text-align-left" data-align="left">High</td></tr><tr><td class="has-text-align-left" data-align="left">3750721</td><td class="has-text-align-left" data-align="left">CVE-2026-76968</td><td class="has-text-align-left" data-align="left">Information disclosure</td><td class="has-text-align-left" data-align="left">SAP Web Dispatcher, Internet Communication Manager, and SAP Content Server<br>KRNL64NUC: 7.22, 7.22EXT; KRNL64UC: 7.22, 7.22EXT, 7.53; WEBDISP: 7.22_EXT, 7.53, 7.54, 7.77, 7.93, 9.16; CONTSERV: 7.53, 7.54; KERNEL: 7.22, 7.53, 7.54, 7.77, 7.93, 9.16, 9.18, 9.19, 9.20</td><td class="has-text-align-left" data-align="left">Medium</td></tr><tr><td class="has-text-align-left" data-align="left">3756450</td><td class="has-text-align-left" data-align="left">CVE-2026-44766</td><td class="has-text-align-left" data-align="left">SQL injection</td><td class="has-text-align-left" data-align="left">SAP S/4HANA Intercompany Matching and Reconciliation<br>SAPSCORE: 136; S4CORE: 104, 105, 106, 107, 108, 109</td><td class="has-text-align-left" data-align="left">Medium</td></tr><tr><td class="has-text-align-left" data-align="left">3786489</td><td class="has-text-align-left" data-align="left">CVE-2026-76971</td><td class="has-text-align-left" data-align="left">Server-Side Request Forgery (SSRF)</td><td class="has-text-align-left" data-align="left">SAP Manufacturing Integration and Intelligence<br>XMII: 15.4, 15.5</td><td class="has-text-align-left" data-align="left">Medium</td></tr><tr><td class="has-text-align-left" data-align="left">3787345</td><td class="has-text-align-left" data-align="left">CVE-2026-34477</td><td class="has-text-align-left" data-align="left">Security misconfiguration due to Apache Log4j</td><td class="has-text-align-left" data-align="left">SAP Commerce Cloud Search and Navigation<br>COM_CLOUD: 2211, 2211-JDK21</td><td class="has-text-align-left" data-align="left">Medium</td></tr><tr><td class="has-text-align-left" data-align="left">3783189</td><td class="has-text-align-left" data-align="left">CVE-2026-76977</td><td class="has-text-align-left" data-align="left">Clickjacking</td><td class="has-text-align-left" data-align="left">SAPUI5 Frame Options Allowlist<br>SAP_UI: 750, 754, 755, 756, 757, 758, 816; UI_700: 200</td><td class="has-text-align-left" data-align="left">Medium</td></tr><tr><td class="has-text-align-left" data-align="left">3365276</td><td class="has-text-align-left" data-align="left">CVE-2026-76960</td><td class="has-text-align-left" data-align="left">Cross-Site Request Forgery (CSRF)</td><td class="has-text-align-left" data-align="left">SAP S/4HANA Finance for Advanced Payment Management<br>S4CORE: 105, 106, 107</td><td class="has-text-align-left" data-align="left">Medium</td></tr><tr><td class="has-text-align-left" data-align="left">3371336</td><td class="has-text-align-left" data-align="left">CVE-2026-76961</td><td class="has-text-align-left" data-align="left">Cross-Site Request Forgery (CSRF)</td><td class="has-text-align-left" data-align="left">SAP S/4HANA Finance for Advanced Payment Management<br>S4CORE: 108</td><td class="has-text-align-left" data-align="left">Medium</td></tr><tr><td class="has-text-align-left" data-align="left">3365311</td><td class="has-text-align-left" data-align="left">CVE-2026-76959</td><td class="has-text-align-left" data-align="left">Cross-Site Request Forgery (CSRF)</td><td class="has-text-align-left" data-align="left">SAP S/4HANA Finance for Advanced Payment Management<br>UIAPFI70: 800, 900, 901, 902</td><td class="has-text-align-left" data-align="left">Medium</td></tr><tr><td class="has-text-align-left" data-align="left">3657599</td><td class="has-text-align-left" data-align="left">CVE-2026-76962</td><td class="has-text-align-left" data-align="left">Missing authorization check</td><td class="has-text-align-left" data-align="left">SAP S/4HANA Manage Bank Chains app<br>S4CORE: 107, 108, 109</td><td class="has-text-align-left" data-align="left">Medium</td></tr><tr><td class="has-text-align-left" data-align="left">3772838</td><td class="has-text-align-left" data-align="left">CVE-2026-76963</td><td class="has-text-align-left" data-align="left">Missing authorization check</td><td class="has-text-align-left" data-align="left">SAP NetWeaver and ABAP Platform<br>SAP_BASIS: 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758</td><td class="has-text-align-left" data-align="left">Medium</td></tr><tr><td class="has-text-align-left" data-align="left">3736494</td><td class="has-text-align-left" data-align="left">CVE-2026-58234</td><td class="has-text-align-left" data-align="left">Denial of service</td><td class="has-text-align-left" data-align="left">SAP Process Integration SOAP Adapter<br>MESSAGING: 7.50; SAP_XIAF: 7.50</td><td class="has-text-align-left" data-align="left">Low</td></tr></tbody></table></figure>



<p class="wp-block-paragraph">Medium-severity fixes cover SQL injection, server-side request forgery,<a href="https://cybersecuritynews.com/0-day-clickjacking-vulnerabilities/" target="_blank" rel="noreferrer noopener"> clickjacking</a>, cross-site request forgery, information disclosure, authorization bypass, and Apache Log4j-related security misconfiguration issues. SAP also patched a low-severity denial-of-service flaw in the SAP Process Integration SOAP Adapter.</p>



<p class="wp-block-paragraph">SAP administrators should review all relevant security notes in the SAP Support Portal, map them to deployed product versions, test patches under change-control procedures, and apply the fixes as soon as possible.</p>



<p class="wp-block-paragraph">Internet-facing SAP services, NetWeaver Message Server instances, cloud application dependencies, and systems processing sensitive business data should receive priority attention.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)"><strong><strong>Learn 7 Metric-Gated AI SOC Deployment Phases &#8211; <strong><strong><a href="https://underdefense.com/ai-soc-deployment-playbook-from-assessment-to-autonomy/?utm_source=cybersecuritynews.com&amp;utm_medium=online_media&amp;utm_campaign=csn_linkedin_newsletter_ai_soc_deployment_playbook_september_2026" target="_blank" rel="noreferrer noopener nofollow">Download Free AI SOC Deployment Playbook 2026</a></strong></strong>.</strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/sap-security-updates-september-2026/">SAP Security Updates September 2026 &#8211; Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/09/SAP-Security-Updates-September-2026-Critical-Vulnerabilities-patched-in-SAP-NetWeaver-Cloud-and-Extended-Passport.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">162531</post-id>	</item>
		<item>
		<title>U.S. Offers $10 Million Reward for Iranian IRGC Cyber Chief Linked to Critical Infrastructure Attacks</title>
		<link>https://cybersecuritynews.com/u-s-offers-10-million-reward-for-iranian-irgc-cyber-chief/</link>
		
		<dc:creator><![CDATA[Abinaya]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 09:14:03 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=162488</guid>

					<description><![CDATA[<p>The U.S. Department of State’s Rewards for Justice program has announced a reward of up to $10 million for information leading to the identification or whereabouts of Amir Yaryab, a senior figure in Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC). U.S. officials allege that Yaryab oversees the command’s Cyber Operations Command, managing cyber units [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/u-s-offers-10-million-reward-for-iranian-irgc-cyber-chief/">U.S. Offers $10 Million Reward for Iranian IRGC Cyber Chief Linked to Critical Infrastructure Attacks</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">The U.S. Department of State’s Rewards for Justice program has announced a reward of up to $10 million for information leading to the identification or whereabouts of Amir Yaryab, a senior figure in Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC).</p>



<p class="wp-block-paragraph">U.S. officials allege that Yaryab oversees the command’s Cyber Operations Command, managing cyber units responsible for attacks on critical infrastructure across the U.S., Europe, and the Middle East.</p>



<p class="wp-block-paragraph">This reward is part of broader efforts to combat <a href="https://cybersecuritynews.com/hackers-attacking-siemens-s7-plcs/" target="_blank" rel="noreferrer noopener">malicious cyber activities</a> targeting U.S. critical infrastructure, as outlined under the Computer Fraud and Abuse Act.</p>



<h2 id="h-u-s-offers-10-million-reward" class="wp-block-heading"><strong>U.S. Offers $10 Million Reward</strong></h2>



<p class="wp-block-paragraph">Yaryab is said to lead various components within the IRGC-CEC known as Shahid Hemmat and Shahid Shushtari, both involved in cyber and cyber-enabled information campaigns against multiple sectors, including defense, telecommunications, energy, and finance.</p>



<p class="wp-block-paragraph">U.S. authorities have linked Yaryab to several IRGC-affiliated groups, including CyberAv3ngers and Dadeh Afzar Arman (DAA), which have been implicated in malware incidents and assaults on civilian infrastructure worldwide.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://rewardsforjustice.net/wp-content/uploads/2026/09/Graphic_Yaryab-514_ENG-1.jpg" alt=""/></figure>



<p class="wp-block-paragraph"><a href="https://rewardsforjustice.net/rewards/amir-yaryab/" target="_blank" rel="noreferrer noopener nofollow">This recent announcement</a> has intensified scrutiny on the Iranian cyber command, especially as operational technology systems remain vulnerable to internet-based threats. The alert correlates with past warnings about CyberAv3ngers targeting industrial control systems.</p>



<p class="wp-block-paragraph">A joint advisory issued by CISA, the FBI, NSA, EPA, and international collaborators revealed that IRGC-connected actors began compromising Israeli-made Unitronics Vision Series <a href="https://cybersecuritynews.com/iran-linked-cyberav3ngers-sets-sights/" target="_blank" rel="noreferrer noopener">programmable logic controllers (PLCs) in late 2023</a>. These devices are essential in various sectors, including water treatment, energy, transportation, and healthcare.</p>



<p class="wp-block-paragraph">Reports indicate that between November 2023 and January 2024, CyberAv3ngers initiated multiple waves of attacks against U.S. based Unitronics PLCs, compromising at least 75 devices, 34 of which were in the U.S. water and wastewater sector.</p>



<p class="wp-block-paragraph">The attackers primarily targeted internet-exposed devices that used default passwords or lacked password protection. The cyber offensive was not merely a matter of defacement; it involved altering the ladder logic within PLCs, which directly manage the operations of physical devices such as pumps and valves.</p>



<p class="wp-block-paragraph">Unauthorized changes could disrupt essential functions, and attackers also tampered with device names, software versions, and remote access credentials, complicating recovery efforts.</p>



<p class="wp-block-paragraph">Moreover, in some incidents, individuals responsible for these attacks replaced human-machine interface (HMI) displays with messages asserting responsibility and threatening Israeli-made equipment. This interference can obstruct plant operators from accessing crucial operational data.</p>



<p class="wp-block-paragraph">CyberAv3ngers&#8217; activities highlight the significant risks to critical infrastructure posed by weak operational technology security. When attackers compromise PLCs, they can take control of critical industrial processes, leading to potentially disastrous consequences.</p>



<p class="wp-block-paragraph">In response, organizations operating PLCs and HMIs are urged to mitigate risks by identifying and eliminating devices directly exposed to the public internet. Strong password policies, multifactor authentication, and other security measures should be enforced.</p>



<p class="wp-block-paragraph">For those using Unitronics Vision Series PLCs, <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a" target="_blank" rel="noreferrer noopener nofollow">CISA recommends</a> updating engineering workstations and firmware to the latest versions and securing remote access through VPNs and firewalls.</p>



<p class="wp-block-paragraph">Additionally, maintaining updated asset inventories and monitoring for unusual activities can help prevent such cyber threats. The ongoing activities of CyberAv3ngers underscore the urgent need for robust cybersecurity measures in industrial systems to defend against state-aligned adversaries seeking to disrupt critical services.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)"><strong><strong>Learn 7 Metric-Gated AI SOC Deployment Phases &#8211; <strong><strong><a href="https://underdefense.com/ai-soc-deployment-playbook-from-assessment-to-autonomy/?utm_source=cybersecuritynews.com&amp;utm_medium=online_media&amp;utm_campaign=csn_linkedin_newsletter_ai_soc_deployment_playbook_september_2026" target="_blank" rel="noreferrer noopener nofollow">Download Free AI SOC Deployment Playbook 2026</a></strong></strong>.</strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/u-s-offers-10-million-reward-for-iranian-irgc-cyber-chief/">U.S. Offers $10 Million Reward for Iranian IRGC Cyber Chief Linked to Critical Infrastructure Attacks</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/09/U.S.-Offers-10-Million-Reward-for-Iranian-IRGC-Cyber-Chief-Linked-to-Critical-Infrastructure-Attacks.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">162488</post-id>	</item>
		<item>
		<title>Panzer Ransomware Targets Italian Manufacturers and Telecom Firms With ESXi-Ready RaaS</title>
		<link>https://cybersecuritynews.com/panzer-ransomware-targets/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 09:10:50 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=162500</guid>

					<description><![CDATA[<p>Panzer ransomware has entered Italy amid a sharp rise in attacks. The ransomware-as-a-service, or RaaS, operation surfaced on August 5 and listed a kitchen manufacturer in Treviso and a telecommunications engineering firm in Catanzaro among its alleged victims. The group advertises tools for Windows, Linux, FreeBSD, and VMware ESXi systems. An attack on a virtualization [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/panzer-ransomware-targets/">Panzer Ransomware Targets Italian Manufacturers and Telecom Firms With ESXi-Ready RaaS</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Panzer ransomware has entered Italy amid a sharp rise in attacks. The ransomware-as-a-service, or RaaS, operation surfaced on August 5 and listed a kitchen manufacturer in Treviso and a telecommunications engineering firm in Catanzaro among its alleged victims.</p>



<p class="wp-block-paragraph">The group advertises tools for Windows, Linux, FreeBSD, and VMware ESXi systems. An attack on a virtualization host can disrupt many business applications at once, turning one compromised server into a wider outage.</p>



<p class="wp-block-paragraph">Panzer posted victims across 11 countries and the campaign arrived as claimed ransomware incidents in Italy reached 212 by September 6, above the 169 recorded during all of 2025.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/a47c4dab-53a8-425d-9418-f897713877cd/Panzer-Ransomware-Targets-Italian-Manufacturers-and-Telecom-Firms-With-ESXi-Ready-RaaS.pdf?AWSAccessKeyId=ASIA2F3EMEYE2IOQLHWM&amp;Signature=MWnkD4LQGbBC13yAnS1C1JAy%2Bso%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIn%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDF3ZBYB2gC0oy%2B8D%2BxeB88Zj0doEqg%2BOQMFbxWUUAm2gIhAIgeU%2Bri0QUAvmdy2JENKTeslBRzvO0rEcC7noNfF3nZKvMECFEQARoMNjk5NzUzMzA5NzA1IgzI4mWkyWUxQb7DpcUq0AQfHILakiZxgbvx67lQnEaEiEuKKYpjcuYCGdftcjiiBI5WOfl%2FLgOMRp%2B25s8dKCje7RyZ097rWEhHnAjnFQuvSOkCHAzrz8nE6HTca3Ltm40MuGXM3R2gEDihYXrLhMlDpjbMbaWduBhgOfbFkxOpRe7kg%2FroKMKKoBunCy5BVpuRSHwJxkbrHWopuvMrhQYfLTOCxhnfsyVgk%2B3kmk144QoVzKdx2e1aL4NlqoJNWK%2FQ2rMnmFmKc1hvOUYTmF2XDIGaZF9%2Fq2Ka32swmkoHeUxtVGYOBXuE3U2AGaYDVz4AJht1Z6ERSzq015usVXjAWqN5UK11kQSIp2rtg7rJeWjrWhaLKrrUs%2BHwSuPlljzk6KWkThL8TFuUswb1Lh4dh49j68B4B0BCAwhIvJ0d05tsxejWuVHRrd9RtElPFmimveQG3di6BZ%2BP4uZkIiwE%2BQPPraITtrUo050jFFVIT2aQAovsmTs6Y2JAwFzvzp0OrezGxmR7oRUGOW0z3iUpVJamAc3ingTNsFIBfVbe%2Ba0D6V0f9rz8MkNGhdKso69Qeh%2BPm8gIey09GQJpLdzX2znclTYfUqfINp%2BsdKw1jGWE2QZLreKiexLTC1n7Ajt3E91gIg71M%2FrKolfKKBUvNTazfs%2B%2BmYD%2FCw%2Bcas5h8N2Z%2B3fNwT431u1H1o0SUKr9nhrfcR9zarY8mNvQKoR3lBbeeSL51fS6Dd6DdQD9r4J1EU1KFqjWzCbCdpMLPRcdSMqZiYIw2H4FjpCnVx%2B7B%2Fi9S759fJG5dLyaWPa3MJ2V%2F9QGOpcBqpau7qvPCOqz3m01i9F0VqB0WXOuMqegfB2eGLYm5awF5yymDZlbX4nMvII2LRsC0XPVyMUNIsV%2Bst%2B583e4lfMmqmyqq7G%2F8S8fU574Z7BnIrITQa6TiaeyAk0TAIuiY9OwLMRKxdY84hFoeq0TvEqlgQshx5QHJAu0ozBDSr93ucJHOfKDYzwsTCHbouq7dUjz40JqdA%3D%3D&amp;Expires=1788860528" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph"><a href="https://andreafortuna.org/2026/09/07/panzer-ransomware-italian-victims/" data-type="link" data-id="https://andreafortuna.org/2026/09/07/panzer-ransomware-italian-victims/" target="_blank" rel="noreferrer noopener nofollow">Researcher&nbsp;Andrea Fortuna&nbsp;said in a report</a> shared with Cyber Security News (CSN) that the Panzer&#8217;s victim posts should still be treated carefully. </p>



<p class="wp-block-paragraph">Doimo Cucine and NTE Italia had not publicly confirmed the incidents when the report was published, but their listing may be a credibility-building tactic.</p>



<h2 id="h-panzer-ransomware-targets-italian-manufacturers" class="wp-block-heading"><strong>Panzer Ransomware Targets Italian Manufacturers</strong></h2>



<p class="wp-block-paragraph">Panzer stands out less for a publicly examined encryptor than for the business system surrounding it. Prospective affiliates reportedly apply through Tox, face screening, and receive access to a dashboard for builds, negotiations, payment invoices, leak posts, and team accounts.</p>



<p class="wp-block-paragraph">The stated split gives affiliates 80 percent of each payment and the platform 20 percent. Operators also claim to monitor new affiliates for signs of researcher or law-enforcement access, showing a controlled recruitment process.<a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/a47c4dab-53a8-425d-9418-f897713877cd/Panzer-Ransomware-Targets-Italian-Manufacturers-and-Telecom-Firms-With-ESXi-Ready-RaaS.pdf?AWSAccessKeyId=ASIA2F3EMEYE2IOQLHWM&amp;Signature=MWnkD4LQGbBC13yAnS1C1JAy%2Bso%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIn%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDF3ZBYB2gC0oy%2B8D%2BxeB88Zj0doEqg%2BOQMFbxWUUAm2gIhAIgeU%2Bri0QUAvmdy2JENKTeslBRzvO0rEcC7noNfF3nZKvMECFEQARoMNjk5NzUzMzA5NzA1IgzI4mWkyWUxQb7DpcUq0AQfHILakiZxgbvx67lQnEaEiEuKKYpjcuYCGdftcjiiBI5WOfl%2FLgOMRp%2B25s8dKCje7RyZ097rWEhHnAjnFQuvSOkCHAzrz8nE6HTca3Ltm40MuGXM3R2gEDihYXrLhMlDpjbMbaWduBhgOfbFkxOpRe7kg%2FroKMKKoBunCy5BVpuRSHwJxkbrHWopuvMrhQYfLTOCxhnfsyVgk%2B3kmk144QoVzKdx2e1aL4NlqoJNWK%2FQ2rMnmFmKc1hvOUYTmF2XDIGaZF9%2Fq2Ka32swmkoHeUxtVGYOBXuE3U2AGaYDVz4AJht1Z6ERSzq015usVXjAWqN5UK11kQSIp2rtg7rJeWjrWhaLKrrUs%2BHwSuPlljzk6KWkThL8TFuUswb1Lh4dh49j68B4B0BCAwhIvJ0d05tsxejWuVHRrd9RtElPFmimveQG3di6BZ%2BP4uZkIiwE%2BQPPraITtrUo050jFFVIT2aQAovsmTs6Y2JAwFzvzp0OrezGxmR7oRUGOW0z3iUpVJamAc3ingTNsFIBfVbe%2Ba0D6V0f9rz8MkNGhdKso69Qeh%2BPm8gIey09GQJpLdzX2znclTYfUqfINp%2BsdKw1jGWE2QZLreKiexLTC1n7Ajt3E91gIg71M%2FrKolfKKBUvNTazfs%2B%2BmYD%2FCw%2Bcas5h8N2Z%2B3fNwT431u1H1o0SUKr9nhrfcR9zarY8mNvQKoR3lBbeeSL51fS6Dd6DdQD9r4J1EU1KFqjWzCbCdpMLPRcdSMqZiYIw2H4FjpCnVx%2B7B%2Fi9S759fJG5dLyaWPa3MJ2V%2F9QGOpcBqpau7qvPCOqz3m01i9F0VqB0WXOuMqegfB2eGLYm5awF5yymDZlbX4nMvII2LRsC0XPVyMUNIsV%2Bst%2B583e4lfMmqmyqq7G%2F8S8fU574Z7BnIrITQa6TiaeyAk0TAIuiY9OwLMRKxdY84hFoeq0TvEqlgQshx5QHJAu0ozBDSr93ucJHOfKDYzwsTCHbouq7dUjz40JqdA%3D%3D&amp;Expires=1788860528"></a></p>



<p class="wp-block-paragraph">Its ESXi option is particularly serious for manufacturers and telecom providers that run core workloads as virtual machines. </p>



<p class="wp-block-paragraph">An intruder who reaches a hypervisor could encrypt multiple virtual disks and halt dependent services, rather than affecting a single employee device. </p>



<p class="wp-block-paragraph">Reporting on&nbsp;<a href="https://cybersecuritynews.com/vmware-syslog-path-traversal/" target="_blank" rel="noopener">VMware vCenter attack techniques</a>&nbsp;illustrates how control of virtualization infrastructure can become a direct path to ransomware deployment.<a href="https://cybersecuritynews.com/vmware-syslog-path-traversal/?ref=cloud.donweb.com" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">Panzer also appears to pair encryption with data theft. The group claimed 30 GB of stolen data from Doimo Cucine and 16 GB of sensitive documents from NTE Italia. </p>



<p class="wp-block-paragraph">Backups may restore systems, but they do not remove the pressure created by a threatened data leak or potential reporting duties. Researchers have not independently confirmed Panzer&#8217;s first access method or publicly analysed payload. </p>



<p class="wp-block-paragraph">Available assessments instead associate the operation, with limited confidence, with password attacks, credential theft, remote-service movement, local data collection, security-tool tampering, and data transfers over alternative protocols.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/a47c4dab-53a8-425d-9418-f897713877cd/Panzer-Ransomware-Targets-Italian-Manufacturers-and-Telecom-Firms-With-ESXi-Ready-RaaS.pdf?AWSAccessKeyId=ASIA2F3EMEYE2IOQLHWM&amp;Signature=MWnkD4LQGbBC13yAnS1C1JAy%2Bso%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIn%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDF3ZBYB2gC0oy%2B8D%2BxeB88Zj0doEqg%2BOQMFbxWUUAm2gIhAIgeU%2Bri0QUAvmdy2JENKTeslBRzvO0rEcC7noNfF3nZKvMECFEQARoMNjk5NzUzMzA5NzA1IgzI4mWkyWUxQb7DpcUq0AQfHILakiZxgbvx67lQnEaEiEuKKYpjcuYCGdftcjiiBI5WOfl%2FLgOMRp%2B25s8dKCje7RyZ097rWEhHnAjnFQuvSOkCHAzrz8nE6HTca3Ltm40MuGXM3R2gEDihYXrLhMlDpjbMbaWduBhgOfbFkxOpRe7kg%2FroKMKKoBunCy5BVpuRSHwJxkbrHWopuvMrhQYfLTOCxhnfsyVgk%2B3kmk144QoVzKdx2e1aL4NlqoJNWK%2FQ2rMnmFmKc1hvOUYTmF2XDIGaZF9%2Fq2Ka32swmkoHeUxtVGYOBXuE3U2AGaYDVz4AJht1Z6ERSzq015usVXjAWqN5UK11kQSIp2rtg7rJeWjrWhaLKrrUs%2BHwSuPlljzk6KWkThL8TFuUswb1Lh4dh49j68B4B0BCAwhIvJ0d05tsxejWuVHRrd9RtElPFmimveQG3di6BZ%2BP4uZkIiwE%2BQPPraITtrUo050jFFVIT2aQAovsmTs6Y2JAwFzvzp0OrezGxmR7oRUGOW0z3iUpVJamAc3ingTNsFIBfVbe%2Ba0D6V0f9rz8MkNGhdKso69Qeh%2BPm8gIey09GQJpLdzX2znclTYfUqfINp%2BsdKw1jGWE2QZLreKiexLTC1n7Ajt3E91gIg71M%2FrKolfKKBUvNTazfs%2B%2BmYD%2FCw%2Bcas5h8N2Z%2B3fNwT431u1H1o0SUKr9nhrfcR9zarY8mNvQKoR3lBbeeSL51fS6Dd6DdQD9r4J1EU1KFqjWzCbCdpMLPRcdSMqZiYIw2H4FjpCnVx%2B7B%2Fi9S759fJG5dLyaWPa3MJ2V%2F9QGOpcBqpau7qvPCOqz3m01i9F0VqB0WXOuMqegfB2eGLYm5awF5yymDZlbX4nMvII2LRsC0XPVyMUNIsV%2Bst%2B583e4lfMmqmyqq7G%2F8S8fU574Z7BnIrITQa6TiaeyAk0TAIuiY9OwLMRKxdY84hFoeq0TvEqlgQshx5QHJAu0ozBDSr93ucJHOfKDYzwsTCHbouq7dUjz40JqdA%3D%3D&amp;Expires=1788860528" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">Possible entry routes include vulnerable internet-facing VPN or gateway devices, exposed Remote Desktop Protocol services, phishing messages with malicious documents, and abused remote-management software. </p>



<p class="wp-block-paragraph">The focus on exposed access points echoes reporting on&nbsp;<a href="https://cybersecuritynews.com/russian-threat-groups-use-rdp-vpn-supply-chain-attacks/" target="_blank" rel="noopener">RDP and VPN attack routes</a>, where stolen credentials and unpatched perimeter systems open a route into internal networks.<a href="https://cybersecuritynews.com/russian-threat-groups-use-rdp-vpn-supply-chain-attacks/" target="_blank" rel="noopener"></a></p>



<h2 id="h-defending-virtualized-operations" class="wp-block-heading"><strong>Defending virtualized operations</strong></h2>



<p class="wp-block-paragraph">Italian organizations should begin with remote access. Require phishing-resistant multi-factor authentication for VPN, remote administration, and privileged accounts; remove unnecessary privileges; and rotate credentials immediately when compromise is suspected. </p>



<p class="wp-block-paragraph">Internet-facing appliances and remote-management tools also need prompt patching and regular exposure reviews.</p>



<p class="wp-block-paragraph">Segmentation is equally important. Keep domain controllers, backup repositories, vCenter, and ESXi management interfaces away from everyday user networks. </p>



<p class="wp-block-paragraph">Restrict administrative protocols to monitored management segments, so a compromised workstation cannot easily reach the systems that control an entire virtual estate.</p>



<p class="wp-block-paragraph">Teams should watch for warning signs before encryption begins: unusual VPN logins, new administrator accounts, unexpected PsExec or WMI activity, unapproved remote-management tools, large archives in user or ProgramData folders, and unfamiliar cloud-transfer utilities. </p>



<p class="wp-block-paragraph">A&nbsp;<a href="https://cybersecuritynews.com/genielocker-ransomware-attack/" target="_blank" rel="noopener">new ESXi ransomware campaign</a>&nbsp;underscores why telemetry from hypervisors deserves the same attention as endpoint alerts.<a href="https://cybersecuritynews.com/genielocker-ransomware-attack/" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">Two commands deserve urgent attention when they appear unexpectedly on a server:&nbsp;<code>vssadmin delete shadows</code>&nbsp;and&nbsp;<code>bcdedit recoveryenabled no</code>. </p>



<p class="wp-block-paragraph">They can remove recovery options, and responders should isolate the affected host, preserve evidence, and begin incident-response procedures rather than waiting for encryption.</p>



<p class="wp-block-paragraph">Finally, maintain offline or immutable backups for every platform, including virtual machines, and test restorations routinely. </p>



<p class="wp-block-paragraph">Monitor large outbound transfers, prepare legal and communications plans for double extortion, and ensure that recovery testing covers the applications and dependencies that keep production and telecom services operating.</p>



<p class="wp-block-paragraph"><strong>Indicators of compromise (IoCs):-</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>Leak site (.onion)</td><td><code>pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd.onion</code></td><td>Panzer leak-site address&nbsp;<a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/a47c4dab-53a8-425d-9418-f897713877cd/Panzer-Ransomware-Targets-Italian-Manufacturers-and-Telecom-Firms-With-ESXi-Ready-RaaS.pdf?AWSAccessKeyId=ASIA2F3EMEYE2IOQLHWM&amp;Signature=MWnkD4LQGbBC13yAnS1C1JAy%2Bso%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIn%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDF3ZBYB2gC0oy%2B8D%2BxeB88Zj0doEqg%2BOQMFbxWUUAm2gIhAIgeU%2Bri0QUAvmdy2JENKTeslBRzvO0rEcC7noNfF3nZKvMECFEQARoMNjk5NzUzMzA5NzA1IgzI4mWkyWUxQb7DpcUq0AQfHILakiZxgbvx67lQnEaEiEuKKYpjcuYCGdftcjiiBI5WOfl%2FLgOMRp%2B25s8dKCje7RyZ097rWEhHnAjnFQuvSOkCHAzrz8nE6HTca3Ltm40MuGXM3R2gEDihYXrLhMlDpjbMbaWduBhgOfbFkxOpRe7kg%2FroKMKKoBunCy5BVpuRSHwJxkbrHWopuvMrhQYfLTOCxhnfsyVgk%2B3kmk144QoVzKdx2e1aL4NlqoJNWK%2FQ2rMnmFmKc1hvOUYTmF2XDIGaZF9%2Fq2Ka32swmkoHeUxtVGYOBXuE3U2AGaYDVz4AJht1Z6ERSzq015usVXjAWqN5UK11kQSIp2rtg7rJeWjrWhaLKrrUs%2BHwSuPlljzk6KWkThL8TFuUswb1Lh4dh49j68B4B0BCAwhIvJ0d05tsxejWuVHRrd9RtElPFmimveQG3di6BZ%2BP4uZkIiwE%2BQPPraITtrUo050jFFVIT2aQAovsmTs6Y2JAwFzvzp0OrezGxmR7oRUGOW0z3iUpVJamAc3ingTNsFIBfVbe%2Ba0D6V0f9rz8MkNGhdKso69Qeh%2BPm8gIey09GQJpLdzX2znclTYfUqfINp%2BsdKw1jGWE2QZLreKiexLTC1n7Ajt3E91gIg71M%2FrKolfKKBUvNTazfs%2B%2BmYD%2FCw%2Bcas5h8N2Z%2B3fNwT431u1H1o0SUKr9nhrfcR9zarY8mNvQKoR3lBbeeSL51fS6Dd6DdQD9r4J1EU1KFqjWzCbCdpMLPRcdSMqZiYIw2H4FjpCnVx%2B7B%2Fi9S759fJG5dLyaWPa3MJ2V%2F9QGOpcBqpau7qvPCOqz3m01i9F0VqB0WXOuMqegfB2eGLYm5awF5yymDZlbX4nMvII2LRsC0XPVyMUNIsV%2Bst%2B583e4lfMmqmyqq7G%2F8S8fU574Z7BnIrITQa6TiaeyAk0TAIuiY9OwLMRKxdY84hFoeq0TvEqlgQshx5QHJAu0ozBDSr93ucJHOfKDYzwsTCHbouq7dUjz40JqdA%3D%3D&amp;Expires=1788860528"></a></td></tr><tr><td>Tox ID (affiliate recruitment)</td><td><code>8C3D96497A9438794F705C055FC2FD3059F6CF11FF51060EE55ED7F0679CFC7218825BD56CB1</code></td><td>Publicly listed affiliate-recruitment contact&nbsp;<a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/a47c4dab-53a8-425d-9418-f897713877cd/Panzer-Ransomware-Targets-Italian-Manufacturers-and-Telecom-Firms-With-ESXi-Ready-RaaS.pdf?AWSAccessKeyId=ASIA2F3EMEYE2IOQLHWM&amp;Signature=MWnkD4LQGbBC13yAnS1C1JAy%2Bso%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIn%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDF3ZBYB2gC0oy%2B8D%2BxeB88Zj0doEqg%2BOQMFbxWUUAm2gIhAIgeU%2Bri0QUAvmdy2JENKTeslBRzvO0rEcC7noNfF3nZKvMECFEQARoMNjk5NzUzMzA5NzA1IgzI4mWkyWUxQb7DpcUq0AQfHILakiZxgbvx67lQnEaEiEuKKYpjcuYCGdftcjiiBI5WOfl%2FLgOMRp%2B25s8dKCje7RyZ097rWEhHnAjnFQuvSOkCHAzrz8nE6HTca3Ltm40MuGXM3R2gEDihYXrLhMlDpjbMbaWduBhgOfbFkxOpRe7kg%2FroKMKKoBunCy5BVpuRSHwJxkbrHWopuvMrhQYfLTOCxhnfsyVgk%2B3kmk144QoVzKdx2e1aL4NlqoJNWK%2FQ2rMnmFmKc1hvOUYTmF2XDIGaZF9%2Fq2Ka32swmkoHeUxtVGYOBXuE3U2AGaYDVz4AJht1Z6ERSzq015usVXjAWqN5UK11kQSIp2rtg7rJeWjrWhaLKrrUs%2BHwSuPlljzk6KWkThL8TFuUswb1Lh4dh49j68B4B0BCAwhIvJ0d05tsxejWuVHRrd9RtElPFmimveQG3di6BZ%2BP4uZkIiwE%2BQPPraITtrUo050jFFVIT2aQAovsmTs6Y2JAwFzvzp0OrezGxmR7oRUGOW0z3iUpVJamAc3ingTNsFIBfVbe%2Ba0D6V0f9rz8MkNGhdKso69Qeh%2BPm8gIey09GQJpLdzX2znclTYfUqfINp%2BsdKw1jGWE2QZLreKiexLTC1n7Ajt3E91gIg71M%2FrKolfKKBUvNTazfs%2B%2BmYD%2FCw%2Bcas5h8N2Z%2B3fNwT431u1H1o0SUKr9nhrfcR9zarY8mNvQKoR3lBbeeSL51fS6Dd6DdQD9r4J1EU1KFqjWzCbCdpMLPRcdSMqZiYIw2H4FjpCnVx%2B7B%2Fi9S759fJG5dLyaWPa3MJ2V%2F9QGOpcBqpau7qvPCOqz3m01i9F0VqB0WXOuMqegfB2eGLYm5awF5yymDZlbX4nMvII2LRsC0XPVyMUNIsV%2Bst%2B583e4lfMmqmyqq7G%2F8S8fU574Z7BnIrITQa6TiaeyAk0TAIuiY9OwLMRKxdY84hFoeq0TvEqlgQshx5QHJAu0ozBDSr93ucJHOfKDYzwsTCHbouq7dUjz40JqdA%3D%3D&amp;Expires=1788860528"></a></td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong>Keep your SOC&nbsp;up to date on active malware &amp; phishing within 24h of their emergence.&nbsp;<a href="https://any.run/threat-intelligence-feeds/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=cta_links&amp;utm_content=landing_feeds&amp;utm_term=sep_26#contact-sales" target="_blank" rel="noreferrer noopener nofollow">Try ANYRUN to prevent incidents with early detection</a></strong></strong>.</p>
<p>The post <a href="https://cybersecuritynews.com/panzer-ransomware-targets/">Panzer Ransomware Targets Italian Manufacturers and Telecom Firms With ESXi-Ready RaaS</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/09/Panzer-Ransomware-Targets-Italian-Manufacturers-and-Telecom-Firms-With-ESXi-Ready-RaaS.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">162500</post-id>	</item>
		<item>
		<title>AI Customer Service Bots Can Be Tricked Into Stealing Security Codes and Acting as Victims</title>
		<link>https://cybersecuritynews.com/ai-bots-tricked-into-stealing-security-codes/</link>
		
		<dc:creator><![CDATA[Abinaya]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 08:50:11 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=162470</guid>

					<description><![CDATA[<p>AI-powered customer service bots are being given more responsibility inside businesses, including access to customer profiles, billing data, support inboxes, account changes, and refund tools. The research showed that attackers may not need traditional vulnerability scanners or direct application exploitation. Instead, they can manipulate the data and messages an AI agent receives, causing it to [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/ai-bots-tricked-into-stealing-security-codes/">AI Customer Service Bots Can Be Tricked Into Stealing Security Codes and Acting as Victims</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">AI-powered customer service bots are being given more responsibility inside businesses, including access to customer profiles, billing data, support inboxes, account changes, and refund tools. The research showed that attackers may not need traditional <a href="https://cybersecuritynews.com/mobile-app-security-scanners/" target="_blank" rel="noreferrer noopener">vulnerability scanners </a>or direct application exploitation.</p>



<p class="wp-block-paragraph">Instead, they can manipulate the data and messages an AI agent receives, causing it to reveal sensitive information or perform actions as a legitimate customer.</p>



<p class="wp-block-paragraph">One major risk involves chatbot transcript features. Many support bots let users email a copy of a conversation. An attacker could inject malicious text into a chat session and use the transcript function to <a href="https://cybersecuritynews.com/hackers-use-invisible-unicode/" target="_blank" rel="noreferrer noopener">create a phishing email</a> that appears to come from a trusted support address.</p>



<p class="wp-block-paragraph">If a customer receives a message from support@company.com, they may be more likely to trust it than a normal phishing attempt.</p>



<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/email-spoofing/" target="_blank" rel="noreferrer noopener">Email spoofing flaws</a> can worsen the issue. Some AI agents identify users by reading the visible From header in an incoming email. However, email delivery and authentication systems may validate a different sender field.</p>



<p class="wp-block-paragraph">An attacker could send an email that passes authentication using an attacker-controlled address, prompting the AI system to associate the message with a victim’s account.</p>



<h2 id="h-ai-bots-tricked-into-stealing-security-codes" class="wp-block-heading"><strong>AI Bots Tricked Into Stealing Security Codes</strong></h2>



<p class="wp-block-paragraph">In one attack scenario, an <a href="https://cybersecuritynews.com/shipping-a-customer-facing-ai-chatbot-without-opening-a-new-attack-surface/" target="_blank" rel="noreferrer noopener">AI customer service agent</a> could receive a request that appears to come from a victim. The bot may then retrieve billing data, profile information, or account details.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiEcL4IQRrwmJEGxMtj0o77fGWFW2lozQtJPx623mMfXaWSv_ftaefTom3HcfP0TbfG8uf9iVsW0aMt9gKld2uv3OCkAjnoNhhydk0a4iwCdlpStCBas9R5GAPKe8bJwIf7qE2g7LFamu4ZjVG-AHP6tbrnq5Bplvypuaex0q9v3_D_HR6VISYNYI2xUpM/s1600/Screenshot%202026-09-08%20132018%20%281%29.webp" alt="prompt injection in LLMs  (Source : intigriti )"/><figcaption class="wp-element-caption">Prompt injection in LLMs (Source: Intigriti)</figcaption></figure>



<p class="wp-block-paragraph">If the attacker adds their own address to the CC or reply field, the bot could unintentionally send the confidential response to the attacker.</p>



<p class="wp-block-paragraph"><a href="https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents" target="_blank" rel="noreferrer noopener nofollow">Security researcher Inti De Ceukelaire warned</a> at Bug Bounty Village during DEF CON 34 that these capabilities can be abused through email tricks, prompt injection, identity confusion, and weak authentication checks.</p>



<p class="wp-block-paragraph">The research also highlighted risks around multi-factor authentication. Some bots require a one-time passcode before making sensitive changes, such as updating a phone number.</p>



<p class="wp-block-paragraph">But weak email normalization can sometimes allow attackers to reset rate limits by changing the format of an email address while still pointing to the same mailbox.</p>



<p class="wp-block-paragraph">For example, different systems may treat comments, aliases, or unusual formatting in an email address differently. One component may recognize the address as belonging to the attacker.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZb95_NEK-ga1abbcEVxjDDggoL9cKs1gmaZPmeV8md5PvJ8LaRt-smsBiLsTmLvpQEFXlStlM91hdxFA4jjZ3xVQr8JEutCUIajmD14tQG1xeg7PAuERzA6i7D2ytUFMV6t4f5xqd1yQUan5eZJ0OPAsr9wSw3XmXw7HvYoiku8ZSyXPFB06Kd53q40U/s1600/Screenshot%202026-09-08%20132028%20%281%29.webp" alt="Invoking tool calls in LLM chatbots (Source : intigriti )"/><figcaption class="wp-element-caption">Invoking tool calls in LLM chatbots (Source: Intigriti )</figcaption></figure>



<p class="wp-block-paragraph">At the same time, another backend service could parse embedded data differently and retrieve a victim’s account. This type of flaw is especially dangerous when raw user input is inserted directly into API requests.</p>



<p class="wp-block-paragraph">AI agents connected to support inboxes can also <a href="https://cybersecuritynews.com/ascension-healthcare-hacked/" target="_blank" rel="noreferrer noopener">expose third-party account codes</a>. An attacker may first send an instruction designed to influence the bot’s behavior.</p>



<p class="wp-block-paragraph">They could then trigger a legitimate password reset email from another service, such as a social media platform, to the company support inbox.</p>



<p class="wp-block-paragraph">If the AI agent reads the incoming code and follows the earlier malicious instruction, it could forward or leak the code to attacker-controlled infrastructure.</p>



<p class="wp-block-paragraph">Human approval does not always stop these attacks. A human operator and an AI agent may process different versions of the same email.</p>



<p class="wp-block-paragraph">Attackers can use multipart messages, <a href="https://cybersecuritynews.com/hackers-abuse-seo-poisoning-and-hidden-html/" target="_blank" rel="noreferrer noopener">hidden HTML</a>, CSS styling, quoted replies, or specially formatted attachments to present a harmless message to a human while exposing a malicious instruction to the AI system.</p>



<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLt9z0rhk7nueVtEtUTkqP9OEU_JnL5iYEoZUbGtgweBExFcSn1GFRnU06mO6b-QGZwrXZhHawF23npreZYEFJVi5nhiVP8gqgL3FrccAAVTndDeOsUcWw9mq6PiX3N5zEZYwE-HS57mYR_aNC_E6wbuighx-z2fcHVWl2amPqapRUcqlXsTJaRd22YvI/s1600/Screenshot%202026-09-08%20132045%20%281%29.webp" alt="Leaking OTP's using Google Chrome's AI (Source : intigriti )"/><figcaption class="wp-element-caption">Leaking OTP&#8217;s using Google Chrome&#8217;s AI (Source: Intigriti)</figcaption></figure>



<p class="wp-block-paragraph">Knowledge-base poisoning is another growing concern. Customer service agents often use retrieval-augmented generation to answer questions from company documentation.</p>



<p class="wp-block-paragraph">If a crawler indexes community comments, user profiles, or untrusted pages on the company domain, attackers may plant false instructions or fake discount codes that the AI treats as trusted internal information.</p>



<p class="wp-block-paragraph">Organizations deploying AI support agents should strictly separate untrusted customer content from system instructions. They should authenticate users with verified session-bound identity controls, normalize email addresses consistently, validate all tool requests server-side, and prevent bots from sending secrets to unverified recipients.</p>



<p class="wp-block-paragraph">AI agents should also have limited permissions. A chatbot that can read emails, modify accounts, issue refunds, and access third-party verification codes creates a high-value target. Businesses must treat AI agents as privileged automation systems, not just conversational interfaces.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)"><strong><strong>Learn 7 Metric-Gated AI SOC Deployment Phases &#8211; <strong><strong><a href="https://underdefense.com/ai-soc-deployment-playbook-from-assessment-to-autonomy/?utm_source=cybersecuritynews.com&amp;utm_medium=online_media&amp;utm_campaign=csn_linkedin_newsletter_ai_soc_deployment_playbook_september_2026" target="_blank" rel="noreferrer noopener nofollow">Download Free AI SOC Deployment Playbook 2026</a></strong></strong>.</strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/ai-bots-tricked-into-stealing-security-codes/">AI Customer Service Bots Can Be Tricked Into Stealing Security Codes and Acting as Victims</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/09/AI-Customer-Service-Bots-Can-Be-Tricked-Into-Stealing-Security-Codes-and-Acting-as-Victims.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">162470</post-id>	</item>
		<item>
		<title>BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft</title>
		<link>https://cybersecuritynews.com/bigbear-2-0-evilginx2/</link>
		
		<dc:creator><![CDATA[Tushar Subhra Dutta]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 08:33:39 +0000</pubDate>
				<category><![CDATA[Cyber Security News]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber security news]]></category>
		<guid isPermaLink="false">https://cybersecuritynews.com/?p=162473</guid>

					<description><![CDATA[<p>BigBear 2.0 is a phishing operation designed to steal proof that a user has already passed multi-factor authentication. It targets Microsoft 365 accounts through convincing sign-in links, then takes over the logged-in browser session rather than attempting to break the authentication factor. The operation is a rebranded Evilginx2 phishing framework that targets Microsoft 365 accounts. [&#8230;]</p>
<p>The post <a href="https://cybersecuritynews.com/bigbear-2-0-evilginx2/">BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">BigBear 2.0 is a phishing operation designed to steal proof that a user has already passed multi-factor authentication. </p>



<p class="wp-block-paragraph">It targets Microsoft 365 accounts through convincing sign-in links, then takes over the logged-in browser session rather than attempting to break the authentication factor.</p>



<p class="wp-block-paragraph">The operation is a rebranded Evilginx2 phishing framework that targets Microsoft 365 accounts. Victims are drawn in through email links that open a proxy page resembling a Microsoft sign-in page. </p>



<p class="wp-block-paragraph">It relays their traffic to the genuine service while quietly collecting credentials and the session data returned after sign-in.</p>



<p class="wp-block-paragraph">CloudSEK analysts identified BigBear 2.0 in June 2026 after gaining access to its administrative panel. The researchers linked the activity to an operator using the alias General Boss and found a network of 42 virtual private server nodes.</p>



<p class="wp-block-paragraph"><a href="https://www.cloudsek.com/blog/tracking-bigbear-2-0-evilginx2-phishing-campaign" data-type="link" data-id="https://www.cloudsek.com/blog/tracking-bigbear-2-0-evilginx2-phishing-campaign" target="_blank" rel="noreferrer noopener nofollow">CloudSEK said in a report</a> shared with Cyber Security News (CSN) that the panel held 5,137 stolen records tied to 461 organizations and 3,331 unique victim IP addresses across more than 40 countries. </p>



<p class="wp-block-paragraph">Of those records, 474 represented complete authenticated sessions, alongside 1,032 passwords and 4,148 session cookies. The records illustrate an operation that collects both immediate account access and material that may support persistent access later.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/93974ba0-e431-4c98-9f61-886aca7b12d3/BigBear-2.0-Evilginx2-Phishing-Campaign-Bypasses-Microsoft-365-MFA-With-Session-Cookie-Theft.pdf?AWSAccessKeyId=ASIA2F3EMEYEXLMKZAYH&amp;Signature=4CPrLW6aM81Ac2nMxTmJXEXmGcY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIj%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIGUWv31WrC0DDSFW8lKBl5ZPnoKzLR189MZzoMBM3G8eAiEA%2Bl1am1ks7yfQ9GgV316dJzVX7Fg68NnyAvaEHffrRm4q8wQITxABGgw2OTk3NTMzMDk3MDUiDCtfEP%2BIdpgO7Ip0WSrQBBbBfiK9K1YjGJSG4nhzmjLDmpJc0RthdPRTi%2Fp25%2BwBJb4ayJmI3fbvLr8odshL1uSt5Hr9xFveRPYb9lbDgjTZizK%2BdYQfWylxzcASSRCfwLfaCWbDVoZmAdtshfXLBzNOgEqsVOI0qffGhy23k5ydduvspDAhdG00x4yEDLDXd9d0nSABKtluOxKMXAdFFg0wBV%2FygvcMHvkSsXeoViX8qIb7tBjRN530KpkXHoGRds1XtmcIVGryuFK0ZMz88U66nwmYUyXZcj%2Bh8myduWwIw0F9SSEbLzWvt1Al7Rd1UJwzua3GIKVj%2BTUyVcHynthAukAwnvcB6JRG0ruYfOb4lBX8UuIEFVgOjgVQHlc4nIP3Y7ZhFX%2FbzK9p5QVh2ZIVW2V%2Fl0yS%2BWPGMwX2z4rHx0whc7cC4rZRld8mmj2koW2IiYF%2Bdtyp0zBBosWeluE5uAme3hRfM7h%2FPAadMLAYVDuojxoXI8XfaFCHYe0L8O%2BA5VuQ6noDquvv75dLc3rUE5Cureno2qnnJxQ6ncGDYUNFwHE0g5wCr1iRFCNhqQ%2BOZeFLM9LFlWUJaSUSqNA0cGrm8Pp1P%2B11QTM9%2BrfhRg90zwribS3G9ZHCJi46%2BfolEPK%2BIJA5WZe%2FmQ%2Bu1G40e7JbHftscza4Q32rxxaU7gpP3pSGyNKiR7vuI0E2WGJCJYhD849zspYTUFAQAHkscvmW7%2FPUDWG%2FhYVUiAAkth2odYxgb3I96ZpbRz5IHLMZWoylDh9coPY8KCCb9deki2btc%2F6%2FoVA5RWm8xfow1uz%2B1AY6mAH2aWfht00m6HIY3JRknMUZIl8a4kAfaSImnzlrnujW7peOhFla1k%2F9gOgnFrvAP1ldB6xIqDDbiBzRdb7hj0atNzuKyqJXhn4tzebg012wh2IWzz8PP5yjrlZXkpHhoMx53T2cCVMrML%2Ff5SbEwSGTbxzm3z0%2FzywwZQlh7qKPbRHCd9WJhVDYMP1Js%2FSj1bwnT%2FcmI5%2BIaw%3D%3D&amp;Expires=1788855337" target="_blank" rel="noopener"></a></p>



<h2 id="h-bigbear-2-0-evilginx2-phishing-campaign-bypasses-microsoft-365-mfa" class="wp-block-heading"><strong>BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA</strong></h2>



<p class="wp-block-paragraph">BigBear 2.0 uses an adversary-in-the-middle setup, meaning it sits between the victim and the real Microsoft login service. </p>



<p class="wp-block-paragraph">It captures the email address and password, lets Microsoft validate the request, and waits for the victim to complete their normal approval or code challenge.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgW1r0IjQhZ2onzMbT65UZiEY7VGNd2hZukIrxb5VRP8PKeSP0Z8Ajny6MLMDcRWD2cACs1AwsnJ1pVRJWM2E0-wKhqGhwu-eYPkqHJEf9evqiZr5QQnV_yVkNpQxEfgK3ajRpVeTekWcqPZbAP0EZvlWB7uAF6_aFcLmZQyKCqQzhHmjHTM_OMKelSDcA/s1600/Campaign%20Timeline%20(Source%20-%20CloudSEK).webp" alt="Campaign Timeline (Source - CloudSEK)" /><figcaption class="wp-element-caption">Campaign Timeline (Source &#8211; CloudSEK)</figcaption></figure>
</div>


<p class="wp-block-paragraph">When sign-in succeeds, Microsoft sends an authenticated session cookie to the browser. Because the proxy handled the exchange, it can copy that cookie before forwarding the response. </p>



<p class="wp-block-paragraph">The attacker can replay it in another browser and enter email, Teams, SharePoint, OneDrive, and connected single sign-on applications as the victim. <a href="https://cybersecuritynews.com/microsoft-365-session-hijacking/" target="_blank" rel="noopener">Microsoft 365 session hijacking</a> campaigns have reported the same account-takeover risk.<a href="https://cybersecuritynews.com/microsoft-365-session-hijacking/" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">This is not a weakness in a one-time password, SMS code, or push notification by itself. These methods confirm the user during the live session, but the proxy steals the resulting proof. BigBear used country-matched residential proxies and scripts that pushed users away from security-key authentication.</p>



<p class="wp-block-paragraph">The campaign particularly affected IT services and managed service providers, a concern because one compromised provider can offer attackers a route into customer environments. </p>



<p class="wp-block-paragraph">At least five affiliates were linked to the panel. <a href="https://cybersecuritynews.com/phaas-kits-targeting-us-organizations/" target="_blank" rel="noopener">Phishing kits targeting organizations</a> show this service-based model is spreading.<a href="https://cybersecuritynews.com/phaas-kits-targeting-us-organizations/" target="_blank" rel="noopener"></a></p>



<h2 id="h-containing-identity-compromise" class="wp-block-heading"><strong>Containing identity compromise</strong></h2>



<p class="wp-block-paragraph">Organizations should treat a suspected stolen cookie as an identity incident, not merely a password problem. Reset affected passwords, revoke active sessions and refresh tokens, and force a new sign-in for impacted accounts. </p>



<p class="wp-block-paragraph">Teams should examine mailbox forwarding rules, OAuth consent grants, unfamiliar application access, and sign-in activity for evidence that a hijacked session was used after authentication. This review should begin as soon as suspicious activity is reported.</p>



<p class="wp-block-paragraph">The most useful long-term control is phishing-resistant authentication, especially FIDO2 or WebAuthn security keys and passkeys where properly deployed. </p>



<p class="wp-block-paragraph">These methods bind a login cryptographically to the genuine site, making a lookalike proxy far less useful. <a href="https://cybersecuritynews.com/pass-the-passkey-attacks/" target="_blank" rel="noopener">Passkey attack techniques</a> nevertheless deserve ongoing attention.</p>


<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiM9FGZnNv9ElT5rrU8pMFiiHgaiOt4C4xcW-EKdBwULorsFPCmazA3iWeXLq_5C2SSKOC2gB3qVYUTGjSFVRFbKuoiWryIjq6UWalklSqptSMp6_n8vwZ1niQvkfNG2luaNLPR5bt64BAAVeNxeXT9J2rSGKjNGG6YXI3osEBMrIQuct27tYkSew4KQDw/s1600/Phishlet%20sample%20(Source%20-%20CloudSEK).webp" alt="Phishlet sample (Source - CloudSEK)" /><figcaption class="wp-element-caption">Phishlet sample (Source &#8211; CloudSEK)</figcaption></figure>
</div>


<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/pass-the-passkey-attacks/" target="_blank" rel="noopener"></a>Administrators should require compliant devices through Conditional Access, shorten session lifetimes where appropriate, and watch for unusual residential IP ranges or new browser sessions. </p>



<p class="wp-block-paragraph">Email filtering should inspect links that imitate sign-in pages even when they use valid certificates. Teams can monitor for the distinctive headers and cookies listed below, because infrastructure can be reassigned.</p>



<p class="wp-block-paragraph">For users, a familiar Microsoft page and successful MFA prompt do not always prove that a browser is connected directly to Microsoft. </p>



<p class="wp-block-paragraph">Verify unexpected sign-in requests through a trusted bookmark or known application, not an email link. This concern is reinforced by <a href="https://cybersecuritynews.com/hackers-using-evilginx/" target="_blank" rel="noopener">Evilginx session-cookie attacks</a>, which also depend on real-time relaying rather than stolen passwords alone.<a href="https://cybersecuritynews.com/hackers-using-evilginx/" target="_blank" rel="noopener"></a></p>



<p class="wp-block-paragraph">The campaign combined cookie theft, geographic proxy matching, and affiliate access. MFA must be paired with phishing-resistant methods, session controls, and rapid token revocation.</p>



<p class="wp-block-paragraph"><strong>Indicators of compromise (IoCs):-</strong><a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/93974ba0-e431-4c98-9f61-886aca7b12d3/BigBear-2.0-Evilginx2-Phishing-Campaign-Bypasses-Microsoft-365-MFA-With-Session-Cookie-Theft.pdf?AWSAccessKeyId=ASIA2F3EMEYEXLMKZAYH&amp;Signature=4CPrLW6aM81Ac2nMxTmJXEXmGcY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIj%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIGUWv31WrC0DDSFW8lKBl5ZPnoKzLR189MZzoMBM3G8eAiEA%2Bl1am1ks7yfQ9GgV316dJzVX7Fg68NnyAvaEHffrRm4q8wQITxABGgw2OTk3NTMzMDk3MDUiDCtfEP%2BIdpgO7Ip0WSrQBBbBfiK9K1YjGJSG4nhzmjLDmpJc0RthdPRTi%2Fp25%2BwBJb4ayJmI3fbvLr8odshL1uSt5Hr9xFveRPYb9lbDgjTZizK%2BdYQfWylxzcASSRCfwLfaCWbDVoZmAdtshfXLBzNOgEqsVOI0qffGhy23k5ydduvspDAhdG00x4yEDLDXd9d0nSABKtluOxKMXAdFFg0wBV%2FygvcMHvkSsXeoViX8qIb7tBjRN530KpkXHoGRds1XtmcIVGryuFK0ZMz88U66nwmYUyXZcj%2Bh8myduWwIw0F9SSEbLzWvt1Al7Rd1UJwzua3GIKVj%2BTUyVcHynthAukAwnvcB6JRG0ruYfOb4lBX8UuIEFVgOjgVQHlc4nIP3Y7ZhFX%2FbzK9p5QVh2ZIVW2V%2Fl0yS%2BWPGMwX2z4rHx0whc7cC4rZRld8mmj2koW2IiYF%2Bdtyp0zBBosWeluE5uAme3hRfM7h%2FPAadMLAYVDuojxoXI8XfaFCHYe0L8O%2BA5VuQ6noDquvv75dLc3rUE5Cureno2qnnJxQ6ncGDYUNFwHE0g5wCr1iRFCNhqQ%2BOZeFLM9LFlWUJaSUSqNA0cGrm8Pp1P%2B11QTM9%2BrfhRg90zwribS3G9ZHCJi46%2BfolEPK%2BIJA5WZe%2FmQ%2Bu1G40e7JbHftscza4Q32rxxaU7gpP3pSGyNKiR7vuI0E2WGJCJYhD849zspYTUFAQAHkscvmW7%2FPUDWG%2FhYVUiAAkth2odYxgb3I96ZpbRz5IHLMZWoylDh9coPY8KCCb9deki2btc%2F6%2FoVA5RWm8xfow1uz%2B1AY6mAH2aWfht00m6HIY3JRknMUZIl8a4kAfaSImnzlrnujW7peOhFla1k%2F9gOgnFrvAP1ldB6xIqDDbiBzRdb7hj0atNzuKyqJXhn4tzebg012wh2IWzz8PP5yjrlZXkpHhoMx53T2cCVMrML%2Ff5SbEwSGTbxzm3z0%2FzywwZQlh7qKPbRHCd9WJhVDYMP1Js%2FSj1bwnT%2FcmI5%2BIaw%3D%3D&amp;Expires=1788855337" target="_blank" rel="noopener"></a></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>IP address</td><td><code>38[.]60[.]250[.]157</code></td><td>BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>95[.]179[.]233[.]79</code></td><td>BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>80[.]240[.]27[.]55</code></td><td>BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>65[.]20[.]103[.]58</code></td><td>BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>38[.]54[.]124[.]88</code></td><td>BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>208[.]85[.]20[.]79</code></td><td>BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>95[.]179[.]169[.]154</code></td><td>BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>107[.]191[.]46[.]14</code></td><td>BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>130[.]94[.]82[.]180</code></td><td>BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>38[.]54[.]124[.]58</code></td><td>BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>208[.]85[.]18[.]18</code></td><td>BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>45[.]32[.]147[.]239</code></td><td>BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>208[.]76[.]222[.]214</code></td><td>BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>130[.]94[.]82[.]230</code></td><td>BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>65[.]20[.]102[.]80</code></td><td>BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>70[.]34[.]208[.]46</code></td><td>Historical BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>130[.]94[.]113[.]184</code></td><td>Historical BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>78[.]141[.]193[.]59</code></td><td>Historical BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>64[.]176[.]72[.]180</code></td><td>Historical BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>136[.]244[.]114[.]85</code></td><td>Historical BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>70[.]34[.]244[.]122</code></td><td>Historical BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>199[.]247[.]10[.]14</code></td><td>Historical BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>152[.]39[.]137[.]60</code></td><td>Historical BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>91[.]245[.]235[.]208</code></td><td>Historical BigBear 2.0 VPS node</td></tr><tr><td>IP address</td><td><code>45[.]32[.]64[.]165</code></td><td>Historical BigBear 2.0 VPS node</td></tr><tr><td>Domain</td><td><code>konceptenterprises[.]com</code></td><td>Phishing domain</td></tr><tr><td>Domain</td><td><code>ccpipharma[.]com</code></td><td>Phishing domain</td></tr><tr><td>Domain</td><td><code>annastudios-paros[.]com</code></td><td>Phishing domain</td></tr><tr><td>Domain</td><td><code>dnsforward[.]com</code></td><td>Phishing domain</td></tr><tr><td>Domain</td><td><code>hotelmidtownsurat[.]com</code></td><td>Phishing domain</td></tr><tr><td>Domain</td><td><code>dataclust[.]com</code></td><td>Phishing domain</td></tr><tr><td>Domain</td><td><code>cifutura[.]com</code></td><td>Phishing domain</td></tr><tr><td>Domain</td><td><code>hoaivt[.]com</code></td><td>Phishing domain</td></tr><tr><td>Domain</td><td><code>dronalms[.]com</code></td><td>Phishing domain</td></tr><tr><td>Domain</td><td><code>virextec[.]com</code></td><td>Phishing domain</td></tr><tr><td>Domain</td><td><code>offtic[.]com</code></td><td>Phishing domain</td></tr><tr><td>Domain</td><td><code>rootreseller[.]com</code></td><td>Phishing domain</td></tr><tr><td>Domain</td><td><code>management[.]michaelmarcotte[.]com</code></td><td>Phishing domain</td></tr><tr><td>Domain</td><td><code>kgsscans[.]com</code></td><td>Phishing domain</td></tr><tr><td>Domain</td><td><code>soil-management[.]com</code></td><td>Phishing domain</td></tr><tr><td>Domain</td><td><code>daengrentacar[.]com</code></td><td>Historical phishing domain</td></tr><tr><td>Domain</td><td><code>arrmmy[.]com</code></td><td>Historical phishing domain</td></tr><tr><td>Domain</td><td><code>captelind[.]com</code></td><td>Historical phishing domain</td></tr><tr><td>Domain</td><td><code>planisteradmin[.]com</code></td><td>Historical phishing domain</td></tr><tr><td>Domain</td><td><code>hnospascualfadon[.]com</code></td><td>Historical phishing domain</td></tr><tr><td>Domain</td><td><code>haliotisbar[.]com</code></td><td>Historical phishing domain</td></tr><tr><td>Domain</td><td><code>knowncontractor[.]com</code></td><td>Historical phishing domain</td></tr><tr><td>Domain</td><td><code>valtteri[.]net</code></td><td>Historical phishing domain</td></tr><tr><td>URL</td><td><code>management[.]daengrentacar[.]com/meetings</code></td><td>Observed live Microsoft 365 phishing page</td></tr><tr><td>Filename</td><td><code>cookie.js</code></td><td>File attachment used in the credential-processing workflow</td></tr><tr><td>Telegram bot</td><td><code>@comeandget_bot</code></td><td>Primary administrator command-and-control bot, revoked</td></tr><tr><td>Telegram bot token</td><td><code>8629902848[:]AAGEFRukqwu9QaMSDNNuVRYF3juTcg4ehO4</code></td><td>Defanged token for revoked primary administrator bot</td></tr><tr><td>Telegram bot</td><td><code>@botterxyz_bot</code></td><td>Affiliate credential-exfiltration bot</td></tr><tr><td>Telegram bot token</td><td><code>8625043408[:]AAH6G8X0aW0QhoLEB1uJiYQ5-2aLSJzg8VE</code></td><td>Defanged affiliate bot token</td></tr><tr><td>Telegram bot</td><td><code>@PackingitonG_bot</code></td><td>Affiliate credential-exfiltration bot</td></tr><tr><td>Telegram bot token</td><td><code>8783369414[:]AAGENRhb7By-0-cQFgrnOw1AW4NbOeUutVE</code></td><td>Defanged affiliate bot token</td></tr><tr><td>Telegram bot</td><td><code>@donplayer_bot</code></td><td>Affiliate credential-exfiltration bot</td></tr><tr><td>Telegram bot token</td><td><code>8807072847[:]AAEYbUaFcbeAgxTZ2Zl8pFbpjRPM9jXvvzE</code></td><td>Defanged affiliate bot token</td></tr><tr><td>Telegram bot</td><td><code>@bolywan_bot</code></td><td>Affiliate credential-exfiltration bot</td></tr><tr><td>Telegram bot token</td><td><code>8462028468[:]AAEQt7oq0c3nTHzApQtHk3RdZ7ifnkYd1XM</code></td><td>Defanged affiliate bot token</td></tr><tr><td>Telegram bot</td><td><code>@rdsxtdytguyg75d_bot</code></td><td>Affiliate credential-exfiltration bot</td></tr><tr><td>Telegram bot token</td><td><code>8794520788[:]AAERSVBlWMpzHc21CCP_-9tL_pjqH9-WuFI</code></td><td>Defanged affiliate bot token</td></tr><tr><td>HTTP header</td><td><code>x-evg-token</code></td><td>Evilginx-related application header</td></tr><tr><td>HTTP header</td><td><code>x-evg-server</code></td><td>Evilginx-related application header</td></tr><tr><td>HTTP header</td><td><code>x-evg-session</code></td><td>Evilginx-related application header</td></tr><tr><td>Cookie</td><td><code>evginx_session</code></td><td>Evilginx-related session cookie</td></tr><tr><td>Cookie</td><td><code>evginx_token</code></td><td>Evilginx-related token cookie</td></tr><tr><td>Cookie</td><td><code>evginx_admin</code></td><td>Evilginx-related administrator cookie</td></tr><tr><td>Cookie</td><td><code>bigbear_session</code></td><td>BigBear 2.0 session cookie</td></tr><tr><td>Cookie</td><td><code>bigbear_token</code></td><td>BigBear 2.0 token cookie</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Note:</strong>&nbsp;<em>IP addresses and domains are intentionally defanged (e.g.,&nbsp;</em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>



<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong>Keep your SOC&nbsp;up to date on active malware &amp; phishing within 24h of their emergence.&nbsp;<a href="https://any.run/threat-intelligence-feeds/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=cta_links&amp;utm_content=landing_feeds&amp;utm_term=sep_26#contact-sales" target="_blank" rel="noreferrer noopener nofollow">Try ANYRUN to prevent incidents with early detection</a></strong></strong>.</p>
<p>The post <a href="https://cybersecuritynews.com/bigbear-2-0-evilginx2/">BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft</a> appeared first on <a href="https://cybersecuritynews.com">Cyber Security News</a>.</p>
]]></content:encoded>
					
		
		
		<media:content url="https://cybersecuritynews.com/wp-content/uploads/2026/09/BigBear-2.0-Evilginx2-Phishing-Campaign-Bypasses-Microsoft-365-MFA-With-Session-Cookie-Theft.webp" medium="image"></media:content>
<post-id xmlns="com-wordpress:feed-additions:1">162473</post-id>	</item>
	</channel>
</rss>
