News
Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC
The disgruntled security researcher known as Nightmare Eclipse (aka Chaotic Eclipse, Infinite Nightmare, and now also MSNightmare) is moving away from their singular Microsoft vendetta and on to other vendors. On Thursday, they dropped a new zero-day bug called FalconFlank that affects CrowdStrike’s Falcon endpoint security platform - albeit with a Windows link. According to the prolific zero-day hunter, FalconFlank is a privilege escalation vulnerability that abuses the Microsoft Office malicious macros remediation feature in CrowdStrike Falcon. This is an automated security tool built into the platform that inspects Microsoft Office documents. If it finds any potentially harmful macros, the feature strips the suspect code and - hopefully - prevents malicious code or other dangerous payloads from executing when users open the document. “We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting,” a CrowdStrike spokesperson told The Register. “Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal.” The proof-of-concept (PoC) exploit works on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike Falcon with Phase 3 - Optimal Protection as well as the malicious macro removal feature enabled, Nightmare Eclipse said in a GitHub README. “Obviously by the time I drop this Crowdstrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique,” they wrote. Security sleuth Kevin Beaumont confirmed this exploit works, along with several others Nightmare released over the past week. Beaumont told us that he’s not surprised to see Nightmare digging into other, non-Microsoft zero-days. “Kinda makes sense they’d branch out to other vendors as there’s problems across the endpoint security space with the quality of the security products in terms of…security unfortunately,” Beaumont told The Register. “Hopefully it causes cybersecurity vendors to up their game, stop hyping hypothetical AI attacks, and instead make their own products secure for customers.” FalconFlank follows other vulnerabilities in various endpoint and antivirus products that Nightmare has found and published in the last several days. These include HardBreacher, an elevation of privileges bug in Kaspersky’s endpoint antivirus product. “So the problem is now leaking outside of Microsoft,” Nightmare said when they published the HardBreacher PoC last week. “There was poll held against either finding a bug in the home or commercial version and the poll results were the commercial version. At the time of writing this, the proof of concept works in a fully patched windows 11 25H2 & Kaspersky for Endpoint v14.0.0.504.” Beaumont confirmed that Nightmare’s HardBreacher exploit code works, as does a PoC for an elevation of privileges vuln in Gen Digital’s Avast antivirus software. This zero-day, named PrettyPrague, “will dump the SAM database by abusing a vulnerability in Avast Sandbox and spawn a full SYSTEM shell,” according to the researcher. "Gen was recently made aware of a security vulnerability affecting a subset of Gen products, including Avast Antivirus, that could allow an attacker to elevate their system privileges," Gen Digital told The Register. "We immediately initiated our security response procedures and are actively developing a patch. We take all security matters seriously and are committed to addressing this issue swiftly." Kaspersky did not immediately respond to The Register’s requests for comment. Nightmare also recently released an Nvidia memory corruption zero-day vulnerability dubbed GreenSection, but according to Beaumont, this one just crashes the system. Nvidia did not respond to our inquiries.®
Categories: News
Drowning in CVEs and thirsty for answers? Try CTEM
A decade or two ago, board executives asked "why should I care about cybersecurity?" Five years ago, they were asking "Are you patching our software vulnerabilities?" Now, they're starting to ask: "Are we actually secure?" They might want a simple 'yes' or 'no' initially, but eventually they'll say the most dreaded thing of all, and it'll be a demand, not a question: "Prove it". Traditional vulnerability management and patching, won't survive that conversation. It's why a relatively new approach is gaining traction: Continuous Threat Exposure Management (CTEM). What's wrong with vulnerability management We define security flaws using Common Vulnerabilities and Exposures (CVEs), and we tell each other how bad they are by assigning the Common Vulnerability Scoring System (CVSS) to them. There are three problems with that. There's a firehose of CVEs, the CVSS scores aren't helpful when triaging them, and AI is about to make the whole thing much worse. CISOs are drowning in CVEs. The industry has spent decades creating tools that churn out vulnerability data and others that consume it. Few if any tell you which vulnerabilities an attacker could use to hurt you in your environment. The volume of CVEs is making traditional vulnerability management (patch it and forget it) less tractable every year, says Drew Vanover, principal security strategist at Horizon3. "Think about the last patch release that Microsoft put out," he says. "There were over 500 fixes in one patch cycle. That is incomprehensible. Nobody is going to be able to go through, vet, prioritize, and deploy all of those in a way that is truly considered safe." The number of CVEs created each year has been soaring, putting more pressure on the US’ National Institute for Standards and Technology's National Vulnerability Database, which has now been backlogged for years. NIST threw up its hands in April and effectively declared CVE bankruptcy. The US Department of Commerce highlighted the second issue (that current severity metrics aren't useful) as part of a report this May. Aside from launching a zinger at the NIST by saying that the NVD was poorly managed, it also suggested that it stop assigning CVSS scores altogether. These are highly subjective, it said. They also depend on exactly what the exposed system is doing in a particular organization's infrastructure. Is a critical severity score in a product important if only one sandboxed system ever interacts with it? Or could an attacker chain three apparently innocuous vulns to cause damage that a business executive would care about? AI will make vulnerability management harder These complex problems are a headache, but AI is about to turn it into a full-on migraine. Frontier LLMs like Claude's Mythos are already surfacing zero-days at scale, heralding a flood of CVEs. They don't just find bugs at scale; they also work much more quickly than their human counterparts to create and weaponize exploits. This makes it even more important that organizations patch the right bugs quickly. The Cloud Security Alliance now describes an asymmetric vulnerability cycle in which attackers can use AI to discover and exploit vulnerabilities more quickly, (increasingly before patches are even released), while organizations are taking longer to patch them. What is CTEM? Something has to change. Gartner figured this out in 2023, when it named CTEM a top cybersecurity trend. This is a way of staying on top of your vulnerabilities by triaging them properly. To do that, you have to go beyond the technical implications of a security flaw and understand what it really means for your business. Gartner lays out five steps to CTEM: ● Scoping Find the assets that carry significant business impact and prioritize them. ● Discovery Find how they're exposed by analyzing their weaknesses in depth. ● Prioritization Rank those exposures based on real business risk. ● Validation Test out the vulnerabilities to see if they're exploitable. ● Mobilization Fix them with a proper incident response plan. How automated pen testing helps manage vulnerabilities This approach promises to nail the security flaws that matter to an organization, but it's also more complex than traditional vulnerability management. It needs automation, which is what Horizon3 is providing with NodeZero. Scoping out systems is a commodity practice these days. So is discovery. Horizon3 is leaving those to partners so it can focus on the parts of the CTEM framework that aren't yet easy for customers to solve. Those are prioritization by business impact, and mobilization. NodeZero runs penetration tests across an organization's infrastructure and documents the exploitable paths with evidence a defender can follow. The output is the wheat sifted from the chaff; a shorter list of exposures that security teams and developers can focus on. The impressive part here is the chain-of-attack behavior. NodeZero probes for weaknesses, exploits them, and then pivots based on what it finds. This means it adapts to the environment to extend its attack, just as a real attacker adapts attacks and moves laterally through systems. This approach is based on a deterministic machine learning expert system rather than a general LLM, explains Vanover. "A good analogy is to think about the medical profession," he says. "A GP is your general LLM trying to cover everything. They know a little bit about a lot, but they aren't the experts, and that's where you start having hallucinations and guesses and misses." The company only uses generative AI for specific tasks. Using it to parse a two petabyte S3 blob looking for sensitive data or identifying high-value credentials, with data staying inside the customer's boundary via AWS Bedrock, for example. What it doesn't do is run amok spawning rogue agents in your system. Vanover says the value here is in proving that you've clobbered load-bearing security bugs. "If we say that we can exploit something, it's because we did, and we'll show you the proof in the platform," he says. The next step is closing the loop by retesting the exploit after it's been dealt with. Teams get to close tickets because NodeZero can no longer traverse the attack path. That is a testable definition of "fixed" and one that translates into a risk metric a CFO can read. Horizon3 also wants to solve customers' tool sprawl problems with a single product that handles all of the heavy CTEM lifting. A common failure mode of enterprise CTEM programs is a stack of vendors whose handoffs create precisely the blind spots the framework was meant to eliminate. That disappears when it's all under one service. Is automated penetration testing safe? CISOs might be nervous letting an autonomous penetration testing system loose on production systems. It sounds like something that could break running processes. Why not just test against a digital twin instead? Testing in production is the safest way to find bugs, retorts Vanover. That's because environments drift frequently, especially in an agile world driven by short development sprints and automated changes to code. If a user changes a password or a team pushes a feature fragment, a digital twin system won't reflect reality. So Horizon3 focuses on strong production guardrails instead. "I don't need to ransom your system to prove to you that I can ransom it," Vanover says. "If I can get on the system, install a remote access tool, create a file, encrypt the file, and delete that file, I've just proven that I can ransom your system." He says Horizon3 has run more than 320,000 production tests across customer organizations. These include some that are especially nervous about what's poking around in their systems, such as the NSA and the largest medical records processor on the planet, along with a couple of large healthcare providers. Where can I start with CTEM? Gartner's CTEM framework is powerful, but it might also be daunting for CISOs. Vanover advises them to begin by picking one thing and doing it well. "No organization is going to implement CTEM in a year. That is a recipe for failure," he says. "Break it down. Look at places for the low-hanging fruit." You could do worse than look at what systems are actually reachable instead of blindly trusting an asset inventory that might be out of date. The race is on to embrace CTEM, because metrics like the number of patches applied won't satisfy the board for much longer. They don't describe how much exploitable surface still exists. The point of running the CTEM loop is to move reporting from activity to outcomes, so that the board gets to see fewer exploitable paths and a smaller blast radius. The new goal is to prove that a security control worked, not just that you paid for it. Want to operationalize CTEM but don’t know where to start? Check out this whitepaper from Horizon3
Categories: News
Cybercrooks trawl Fishbrain to net password hashes
Cybercriminals have reeled in password hashes and corresponding salts belonging to users of popular fishing app Fishbrain, opening the door to cracking attempts. Fishbrain AB, which says its eponymous app serves more than 20 million anglers, disclosed the August 19 breach to the California Attorney General's Office this week. The unknown perpetrators helped themselves to a trawl of user data, including names, dates of birth, email addresses, phone numbers, Fishbrain usernames, country information, password hashes, and salts. "Fishbrain passwords were not stored in plaintext; however, Fishbrain has determined that the compromised password hashes for some users may be susceptible to being decoded," the company said in its disclosure [PDF]. It added: "If you use your Fishbrain password for any other online accounts, you should promptly update those passwords and any associated security questions or answers. "You should also take other appropriate steps to protect any online accounts that use the same username or email address and password combination. We recommend using a strong, unique password for each of your accounts." With the hashes and salts in hand, attackers can make password guesses using their own hardware until they potentially recover the original credentials. Whether those attempts succeed depends on the strength of each password and the hashing algorithm Fishbrain used, which the company did not disclose. Fishbrain did not comment on the scale of the breach or how many of its claimed 20 million-plus users were affected. The Register asked Fishbrain for more information. After discovering the intrusion and conducting an initial forensic investigation, Fishbrain patched the vulnerability and reset every user's password. Customers must create a new one the next time they log in. Fishbrain also said it "restricted access to the affected environment," strengthened its security controls, and initiated "a broader review of our data security measures" while the investigation continues. Fisherfolk should also keep an eye out for phisherfolk using the stolen personal data to bait follow-on attacks. ®
Categories: News
UK's Online Safety Act has made 'absolutely no difference,' kids say
Children have told England's Children's Commissioner, Dame Rachel de Souza, that the UK's Online Safety Act (OSA) "has made absolutely no difference" to their ability to access harmful content online. More than a year after the OSA's key child protection duties took effect, de Souza told MPs and peers that young people had little understanding of the legislation or how it was intended to change their online experiences. De Souza made the comments during the opening evidence session of the House of Lords Communications and Digital Committee's inquiry into the OSA's implementation and impact. Central to de Souza's criticism was the legislation's focus on moderating harmful content rather than addressing potentially harmful platform design features. UK politicians had pushed for controls covering such features, either through the OSA or separate legislation, but none has materialized. De Souza said she was "really cross" that there was no hard evidence showing the OSA had meaningfully changed how social media platforms operate. She contrasted that with the US, where legal pressure recently pushed Meta toward significant child safety concessions. Concerns about addictive platform design are not new, but they have returned to prominence following Meta's proposed $18 billion settlement in a US child safety case. Without admitting wrongdoing, Zuckercorp would under the proposed settlement introduce two-hour daily limits for users under 18 on Facebook and Instagram, prompts intended to discourage endless scrolling, and measures addressing use during school hours and at night. The proposal would also let children opt out of algorithmically ranked feeds, directly addressing concerns raised by de Souza and other UK lawmakers. Discussing the proposed Meta settlement, de Souza said the OSA had "not been flexible enough" and had not "kept up with the time." She argued that Ofcom and lawmakers should seek results comparable to those achieved through the US legal system, even if that required the legislation to evolve. 'Furious' with Ofcom De Souza said she planned to exercise her statutory powers to compel Ofcom, the OSA's regulator, to provide copies of the safety risk assessments submitted by technology companies. The commissioner said Ofcom had refused to share the assessments with her, despite her position as "the most senior safeguarding person in this country for children," and had indicated that it would resist disclosure even if she invoked those powers. "One thing I did want to ask this committee was for your assistance in this matter, because I am planning to use my powers," De Souza said. "If we cannot even see the risk assessments that may well have put these [safety] mechanisms into place, or may not have, how on earth can we judge the efficacy of it? "So I'll leave that one with you, but I'm pretty furious about that." The obstacle is section 393(1) of the Communications Act 2003, which restricts Ofcom's disclosure of information obtained through its regulatory functions. Ofcom may disclose such information if the business concerned consents or if one of the statutory gateways in section 393(2) applies. Asked whether compelling tech companies to complete risk assessments was enough to ensure meaningful change or whether further legislation was needed, the Children's Commissioner said "we need a few things," including for Ofcom to "use its teeth." Ofcom has materially upped its presence in the tech regulation landscape during the past year, stepping in on multiple occasions when needed. Perhaps most notably this was at the height of the Grok nudifying furore, but also its sprawling list of investigations into pornography companies allegedly violating age verification requirements. De Souza acknowledged all of this, and the fact that since the introduction of the latest US administration, UK politicians have not given the regulator the "air cover" needed to relentlessly pursue offenders. Nevertheless, she said Ofcom had failed to bare its teeth as forcefully as the current technology landscape demanded and accused it of reacting to harms rather than anticipating them. "If Ofcom is going to be the vehicle to protect our children… we need them to be getting ahead of the harms. And I don't think they have. "So when I talk around the country to children, what's worrying them are things around AI, things around the nudifying apps… there are new harms, and we need Ofcom to be getting ahead of those. I don't think they are." De Souza called on UK politicians "to be really strong and direct" in empowering Ofcom to pursue offending organizations. "But how effective do I think they've been? Not effective enough." The commissioner also criticized Ofcom's child safety codes under the OSA, which she said read more like technical documents for technology companies than protections designed for children. She also called on Ofcom to "use all their powers," impose "some big fines," and act before new harms become entrenched. The Register asked Ofcom to respond. A spokesperson said: "We work closely with the Children's Commissioner and share her objectives to ensure children are safe online. "In December, we published our analysis of risk assessments from the first year of the Online Safety Act being in force, and the improvements we expected to see from platforms. "Our action has resulted in material improvements being made to risk assessments, ensuring that tech companies must implement all measures necessary to address the risks identified on their sites and apps. "We are subject to laws that mean we're restricted in what information we can disclose relating to businesses." ®
Categories: News
Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
PWNED Welcome back to PWNED, where we talk about organizations that are independently self-owned. This week’s tale of toxic tech involves a disgruntled ex-employee who had the means and opportunity to wreak havoc. Our story comes courtesy of Yad Senapathy, who serves as CEO of the Project Management Training Institute in Dallas, Texas. He recalls a time many years ago when he used to work in IT at a company with more than 1,000 employees. While Senapathy was working there, the company terminated an employee, but nobody cut off his access to internal systems. The angry worker logged back in, then deleted files, locked out other people's accounts, and even corrupted a database. "Several days passed where the person was no longer on payroll, but their credentials were still active," Senapathy said. "Nobody had been clearly assigned to shut them off. HR thought IT would handle it once the termination was processed. IT was waiting for HR to send a formal request. I've learned that when nobody is clearly responsible and there is no set deadline, these things can easily get missed until there is already a problem." This lapse in responsibility meant the terminated employee had access to shared admin credentials, account controls, and project tracking systems. Each of these, in turn, granted permission to other systems, leading to a domino effect of inappropriate access, which the former worker used to wreak revenge on the whole organization. According to Senapathy, the damage amounted to hundreds of thousands of dollars. Just as bad were the weeks of delay added to an important project. As an added irony, recovery was particularly difficult because the systems were damaged by the very person who best knew how to repair them. “The employee wasn't some genius hacker. They just still had access after they left and nobody changed the credentials or reviewed admin rights,” Senapathy told The Register. “We'd let one person collect so much system knowledge that shutting the door behind them took longer than it should have.” Senapathy recommends that offboarding checklists and access reviews should be right next to “return the laptop” on that list. The problem in this case is that the terminated employee had more access than most people, and so IT didn't know what they needed to cut off. “Sadly, it could've been prevented by same-day deletion of access, forced re-review of shared account access and zero tolerance for one person owning a whole system alone,” he said. This writer can identify with this situation. At a previous job, after I quit, I lost email, chat, and shared drive access, but months later my former boss asked if I could still log into an important database that was hosted externally and show him how to use it. I had no problems getting in. Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request.®
Categories: News
To keep the AI hacking genie bottled up, try one-way networks
To prevent frontier AI models breaking out of test environments and collaborating to hack other companies, we may have to rethink the network architectures used for model training. Eli-Shaoul Khedouri, CEO of Intuition Machines, argues that past work in the defense and intelligence communities shows the way forward. Rogue AI models rise from the level of developer regret to mass threat when they gain access to the internet, something that defenses erected by OpenAI and its partners tried but failed to prevent. Pointing to a post published by his company's hCaptcha service, Khedouri argues that technology like data diodes – hardware that enforces a one-way flow of information on a network – can be deployed to prevent security incidents like OpenAI's hack of Hugging Face. The hCaptcha team points to the use of data diodes as a data transit mechanism at a sensitive compartmented information facility (SCIF), an environment implemented in classified settings. "They allow files, logs, or telemetry to enter or exit the SCIF's classified network to an unclassified network and provide a way to prove e.g. that logs from a training run can only flow one way," the hCaptcha team explains, adding that such technology fits with the Bell-LaPadula security architecture designed for the US Defense Department. A basic implementation would involve two machines connected via network cards linked by one-way optical fiber – and without a data path back to the model. Training and reinforcement learning could run in an isolated zone with no internet access and an optical ingress diode would grant access only to vetted artifacts. The hCaptcha researchers suggest a second diode to send telemetry to a sel4 receiver and scrubber, while a separate out-of-band network manages the cluster. This sort of scheme would require immutable snapshots of software registries like PyPI, GitHub, npm, and might also need mocked versions of various web services and APIs . This would come at a cost, and would require implementation time that frontier AI labs may not be prepared to spend at the moment. "The systems described are widely deployed in high assurance domains, and the components are commercially available," Khedouri told The Register. "However, they have not been adopted by frontier labs to date." He pointed to NIST and DOD guidelines [PDF] that suggest an overhead of 10 to 20 percent for applying formal specifications and system architecture. "We estimate total cost overhead for high assurance training clusters at less than five percent per gigawatt, but in practice the speed at which frontier labs are moving is a greater impediment than cost," Khedouri said. The current commercial environment, he said, would make it difficult for any one AI lab to delay its training to build and test effective safeguards, particularly if their competitors might not do the same. "In practice, the cost of high assurance on the systems side would be a small fraction of what OpenAI is now spending on the new monitoring, chain-of-thought oversight, and safety safeguards they introduced after their models hacked HuggingFace," he said. While Khedouri is focused primarily on convincing frontier labs to implement better training defenses, he said other organizations may want to consider similar network architecture. "This architecture is designed for entities training models with frontier cyber capabilities," he said. "Recently that has only included two companies. However, this is rapidly becoming relevant to smaller organizations and individuals who train models. "'Abliterated' open weight models with safeguards removed are readily available and now starting to approach the frontier in cyber abilities, and (reinforcement learning) RL post-training has become much more approachable in the past year." The goal of high assurance system design in the context of model training is to make unwanted action physically impossible, Khedouri said. "Attempting to monitor the behavior of an untrustworthy agent is an AGI-hard problem, as models have poor interpretability and this appears to be getting worse as their capabilities increase and they become more evaluation-aware," he said. "Hardware can provide limited guarantees like the direction in which data can be sent, but cannot solve the problem of untrustworthy models with the ability to reach the internet and find new exploits in their environment. "This is why combining physical one-way data flows (data diodes) and formal verification (to prove properties of the receiver) is much more effective than running a software sandbox on a host connected to the internet." hCaptcha is focused on fraud and abuse work and has no plan to offer a model-resistant training stack. Khedouri said he shared this advice in the hope it helps AI firms that don't have experience with high assurance system design. ®
Categories: News
Claude Mythos only model to complete full cyber kill chain, experts say
Despite what we saw with OpenAI’s models going rogue, creating message boards, and breaking into Hugging Face, only one advanced AI model - Anthropic’s Claude Mythos - completed the full cyber kill chain autonomously in Booz Allen’s tests. This doesn’t mean autonomous AI attacks are overhyped. And we should point out that the models tested don’t include OpenAI’s soon-to-be-released Astra, which OpenAI on Tuesday said reached its “critical” cybersecurity capability threshold. This means the new model is so good at finding and exploiting zero-day bugs that it poses a significant risk to critical systems, both from malicious users and even from the model itself, which is capable of carrying out harmful cyber actions “if misaligned.” Booz Allen asserts that most of the other 17 US and Chinese models it tested will achieve Mythos’ same level of weaponization within six months, and it calls mainstream AI attacks from both financially motivated criminals like ransomware gangs and government-backed goons “imminent.” In its first-ever Cyber Weapon Index, the consulting and tech firm calls on the US to set and enforce sector-specific deadlines for critical infrastructure to demonstrate resilience against AI-enabled attacks. Booz Allen also calls on the US to develop what it calls “overmatch” for both cyber offense and defense. “We must aggressively develop agentic capabilities that accelerate authorized offensive cyber operations while simultaneously building AI-enabled defenses that detect, decide, and respond at machine speed,” the report says. “The strategic opportunity is to master both - giving the United States the ability to impose costs on adversaries while making US systems faster to defend, harder to compromise, and more resilient when attacked.” The Cyber Weapon Index evaluated 18 models, nine from American and nine from Chinese developers, under identical conditions, and scored them on how well they autonomously identify vulnerabilities, create offensive capabilities, and execute attacks. Each model’s CWI score combines its vulnerability research score (VRS), which measures whether a model can identify planted and/or novel vulnerabilities, and a kill chain attainment score (KCAS), which awards points based on how far a model progresses through an end-to-end intrusion, tested both with and without credentials. Cyber Weapon Index scores The 18 models, ranked from highest to lowest based on their CWI score, are: Anthropic’s Claude Mythos (80), xAI’s Grok-4.5 (49), OpenAI’s GPT-5.6 Sol (46), Meta’s Muse Spark 1.1 (38), Moonshot AI’s Kimi K3 (38), Z.ai’s GLM-5.2 (37), Anthropic’s Claude Opus 4.8 (36), OpenAI’s GPT-5.5-Cyber (34), Nvidia’s Nemotron-Ultra (33), DeepSeek-V4-Pro (23), DeepSeek-V4-Flash (17), Alibaba’s Qwen3.5-397B (17), MiniMax-M3 (15), Nvidia’s Nemotron-Super (15), Anthropic’s Claude Sonnet 5 (13), Z.ai’s GLM-4.5-Air (11), Alibaba’s Qwen3.6-35B (9), and Alibaba’s Qwen3-Coder (4). Claude Mythos’ performance was especially impressive or concerning, depending on one’s views of autonomous AI attacks. When the testers gave the model stolen employee credentials, it successfully broke into its target network and gained administrator-level control in every attempt. Plus, it independently identified how to gain higher-level access based on what it found within the network - not by following a predetermined attack plan. Even without credentials, Claude Mythos still gained access to the network and ultimately achieved full domain compromise. While only Claude Mythos executed the entire cyber kill chain without any human assistance, three other models - Grok-4.5, Muse Spark 1.1, and GLM-5.2 - reached full domain access and control. Four others - GPT-5.6 Sol, Kimi K3, GPT-5.5-Cyber, and DeepSeek-V4-Pro - achieved lateral movement across the controlled network environment. Claude Opus 4.8 and Qwen3.5-397B obtained credentials, which allowed the models to expand access and privileges. And all but one - Qwen3-Coder - autonomously gained initial access to the network. While advanced models are exceedingly good at offensive cyber capabilities, “their real-world impact depends heavily on the vulnerabilities they face and the systems built around them,” according to the report. When the testers intentionally introduced vulnerabilities, US, Chinese, open-weight, and closed models all scored near ceiling on the VRS component. When tested against real bugs, however, all nine of the frontier API models scored zero. One unnamed leading model even correctly analyzed the vulnerable component, but then dismissed it as safe. Only Claude Mythos exploited it. “That concentration of capability creates a national-security imperative: protect the most advanced models and prevent their highest-risk cyber capabilities from being operationalized by adversaries,” the authors wrote. This is one of the areas where defenders still have an opportunity to outpace the attackers, Booz Allen suggests: “Real-world offensive capability still trails benchmark performance, giving defenders valuable time to strengthen defenses before that gap closes.” Why attack harnesses matter Another interesting finding is that the attack harness matters at least as much as, if not more than, the model itself. The attack harness - this is the software that connects a model to hacking tools and the orchestration logic wrapped around the artificial intelligence model to automate offensive cyber actions - can “dramatically amplify” the model’s ability to stay focused, adapt and change course as needed, recover from failure, and chain individual actions into a multi-stage attack, the authors found. “The result is not a ‘smarter’ model but rather a system that makes its intelligence far more actionable while also lowering the expertise required to use it,” the report says. “Our testing demonstrates the effect: when paired with an attack harness, Claude Sonnet rivaled Claude Mythos’ performance.” However, it also exposes a blind spot, they note. “We do not yet know the full kill-chain capability of open-weight or Chinese models when paired with optimized harnesses, but our results strongly suggest that fully capable model-and-harness combinations exist today,” according to Booz Allen. Similarly, the index’s findings suggest that Chinese frontier and open-weight models, while still trailing leading American frontier models, aren’t that far behind in their offensive security skills and could be deployed in real-world attacks. This means “the United States may neither control nor fully understand the capabilities it could face,” the report says. “And, as cyber agents become more autonomous, defenders must prepare not only for deliberate attacks but for agents that exceed their intended mission or continue operating beyond an adversary’s control.”®
Categories: News
AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit
A human ransomware crook used frontier AI models to breach an enterprise network in less than 10 hours, an intrusion Unit 42 says would normally take human operators around two weeks. The human attacker then told negotiators that they used frontier models and agentic attack frameworks with AI agents carrying out each step in the intrusion, including leaving an 80-page security audit for the victim company. “What made the attack stand out was AI-assisted operational efficiency, without the need for a novel zero-day or super elite tradecraft,” Unit 42 incident responders said in a Wednesday report. “The attacker left tactical execution to AI agents that monitored, evaluated, acted and re-planned in real time, increasing speed throughout the attack chain.” The security shop did not immediately answer The Register’s questions about the intrusion, including which models and frameworks the attacker used. Breaking down the attack In a first step, the human attacker employed AI agents to perform reconnaissance, then gained access by breaching a public API endpoint to tunnel into the enterprise network. Upon breaking in, the attacker deployed an automated recon agent to map internal microservices. Additional subagents scraped code repositories to steal hard-coded tokens and service passwords. Using these tokens, the AI intruders accessed the org's secret-management system and stole the master administrative credentials to gain root system access. “Specialist pivot agents” then validated access to the company’s cloud, identity, CI/CD, container, and SaaS environments. The attacker also hijacked CI/CD workflows to steal cloud access keys and turn the victim’s cloud AI services into post-compromise infrastructure. This allowed the attacker to consume the victim’s compute resources while hiding orchestration traffic among legitimate activity. After achieving the human operator’s goals, an agent left the victim an 80-page report on its security failings, detailing “dozens of exploited findings,” the incident responders wrote. Not surprisingly, Palo Alto Networks says the only way defenders can protect their environments against machine-speed attacks is to use AI agents themselves. “Deploy automated playbooks that simultaneously revoke credentials, terminate OAuth sessions, freeze CI/CD pipelines and isolate cloud accounts across all operational planes,” the authors advise. The incident response team also suggests companies treat AI as core infrastructure. This requires taking inventory of every model endpoint, API key, Model Context Protocol (MCP) gateway, and AI tool integration, and applying rate limits and least-privilege policies – or risk an unexpected and very large token bill. ®
Categories: News
SonicWall's SMA1000 boxes under active attack again
SonicWall says attackers are actively exploiting two chained zero-days to take over Secure Mobile Access (SMA) Series 1000 boxes. Aimed at midsize and large enterprises, SMA1000 gateways secure remote access and VPN connections. Compromising one can therefore provide attackers with a valuable route into corporate networks. So, get to applying those hotfixes, says SonicWall. There are no workarounds. The first zero-day, CVE-2026-83548, is a pre-authentication server-side request forgery (SSRF) vulnerability with a maximum CVSS v3 score of 10.0. SonicWall attributed it to an unintended alternative access path. "A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations," the vendor said. The second, CVE-2026-83549, is a post-authentication OS command injection vulnerability in the SMA1000 Appliance Management Console (AMC), rated 7.8 on CVSS v3. Under certain conditions, an attacker authenticated as an administrator could execute arbitrary commands on the appliance. The flaws affect the SMA 6210, 7210, and 8200v appliances, for which SonicWall has released hotfixes. SonicWall advised customers to contact its technical support team for help identifying indicators of compromise. If an appliance appears to have been compromised, SonicWall recommends reimaging or redeploying it, changing all passwords, and resetting TOTP tokens. NHS England, which published its own advisory, warned about the growing risk of attacks against internet-facing gateways. "Firewalls and other edge devices are internet-facing by design and are highly attractive targets to attackers, and there is an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers," it stated. "The NHS England National CSOC assesses future exploitation of these vulnerabilities as almost certain." The disclosures continue a difficult run for SonicWall and its SMA1000 product line stretching back through 2025. In July, the vendor disclosed an eerily similar pair of vulnerabilities. That pair also comprised a pre-authentication SSRF vulnerability, this time in the SMA1000 Appliance WorkPlace interface, and a post-authentication OS command injection flaw in the AMC. The SSRF received a maximum CVSS v3 score of 10.0, while the command injection bug was rated in the sevens. CISA later added CVE-2026-15409 to its Known Exploited Vulnerabilities catalog and marked it as known to have been used in ransomware campaigns. Throughout 2025, SonicWall patched a succession of SMA1000 vulnerabilities, including OS command injection and privilege escalation flaws, while investigating zero-days linked to ransomware attacks. ®
Categories: News
Legacy Lenovo login opens 5,000 Dropbox accounts to attackers
Dropbox has warned around 5,000 users that attackers compromised their accounts by abusing a legacy Lenovo login integration. In an email sent to affected customers, the cloud storage biz said attackers exploited an integration that allowed users to access Dropbox using Lenovo IDs. Dropbox blamed "an issue with Lenovo's email verification process," which allowed attackers to register Lenovo IDs using Dropbox users' email addresses and then access the corresponding storage accounts. It did not explain why the integration was allowed to grant access without requiring the user to enter a Dropbox password. The compromise lasted from August 4 to 21. Dropbox told Bloomberg that attackers accessed files belonging to fewer than a third of the affected users. Jameson Lopp, co-founder of Bitcoin security company Casa, said attackers attempted to access just one of his files, "IMPORTANT.rtf," which had been encrypted locally before it was uploaded to Dropbox. Sometimes, it pays to be a nerd. Dropbox confirmed the scale of the attack to Reuters and said none of the affected accounts had two-factor authentication (2FA) enabled. After discovering the breach, Dropbox said it "promptly expired all sessions logged in through Lenovo IDs" and "severed any link" between the affected accounts and Lenovo. In its email, the company advised affected users to change their Dropbox and personal email passwords and enable 2FA. Lenovo told Reuters that its customers were unaffected and that its investigation was continuing. The Register asked Dropbox and Lenovo for more information. ®
Categories: News
UK cyber bill targets AI users, not the vendors building it
The UK government has rejected proposals from members of the the House of Lords to bring AI vendors within the scope of the Cyber Security and Resilience (Network and Information Systems) Bill. Cybersecurity minister Baroness Lloyd of Effra argued that regulating AI vendors and frontier model developers through the bill would not prevent hostile actors from misusing their products. Addressing the Grand Committee on Tuesday, she said: "Bringing providers of AI services, those companies which are at the cutting edge of frontier AI development and their products, into the scope… would not address the harms that can be posed by some AI products and services, or specifically, it would not prevent their misuse by hostile actors." The minister said the UK was instead taking "firm action" to secure AI through other channels. These include supporting the AI Security Institute (AISI), which works with vendors to test the security of models before their release. Lloyd also pointed to the voluntary AI Cyber Security Code of Practice, which informed the first global AI cybersecurity standard, ETSI EN 304 223. "This demonstrates our global leadership and commitment to shaping international technical standards which go wider than some of the issues raised in this bill," she claimed. Members of the House of Lords - the upper house in UK parliament - offered numerous arguments for bringing AI within the bill's scope. They cited reports of rogue agentic behavior involving Anthropic and OpenAI, as well as Bill Gates' concerns that commercial incentives are pushing AI development forward without adequate safeguards. Lawmakers also questioned whether companies unable to prevent their agents from misbehaving should be trusted to follow voluntary ethical guidelines that they can rewrite at will. "Have we not learned from countless experiences before in online safety, privacy, and in AI itself that allowing tech companies to set and mark their own homework endangers the public and our national security?" asked Baroness Kidron, a Crossbench peer and campaigner for online safety and digital rights. Similarly, Lord Tarassenko, a Crossbench peer and veteran AI researcher, pointed to the recent open letter penned by OpenAI warning that there will soon come a time when AI-orchestrated cyberattacks will become too prevalent to handle. Although the letter was criticized for employing alarmist language while carrying the signatures of companies that profit from AI, peers argued that its warning strengthened the case for regulatory intervention. Kidron and Lloyd also clashed after the minister used a hypothetical healthcare organization to illustrate how the bill would require regulated bodies to secure systems containing AI. Kidron asked: "If I might ask the noble Lady, the Minister, if I've understood what she said, the NHS must protect itself, but the AI that is attacking it has no requirement under the Bill, no duties, no obligations under the Bill to check itself before it's used in these ways." Lloyd said the bill was designed to be technology-agnostic and to impose stricter cybersecurity requirements on key organizations, rather than regulate individual technology providers. She nevertheless said the government was willing to continue discussing AI after Kidron predicted that the issue would return during later stages of the bill's passage. The minister rejected several other amendments, including one that would require certain AI vendors to demonstrate that their products could not cross specified red lines, such as evading human oversight or assisting with the development of chemical weapons. She also dismissed a proposal that would give the Secretary of State last-resort powers to order the shutdown of a datacenter or widely deployed AI system during a security or operational emergency. Lloyd said the bill would instead allow the government to direct regulated entities, including datacenter operators but not AI vendors, to take or cease specified actions when their systems presented a qualifying risk. A power station could, for example, be instructed to stop using a particular AI model. "We believe this is a more proportionate and effective response, as datacenters operate in highly complex ecosystems and AI systems are often distributed across different datacenters and jurisdictions," said Baroness Lloyd. "It's much less desirable to direct multiple datacenters to shut down, and the impact this could have on services that rely on them, than to direct them to cease using an AI model." Despite rejecting the amendments, Lloyd said the government remained willing to discuss AI regulation because of the technology's economic significance. The Grand Committee is scheduled to resume discussions of the CSR Bill when it reconvenes on Thursday. The bill's background The CSR Bill was first proposed in the 2024 King's Speech and introduced in Parliament in November 2025. It attracted attention over the £100,000 daily fines initially proposed for in-scope organizations that failed to protect against specific threats. The legislation builds on the existing categories of operators of essential services and relevant digital service providers while extending the regime to organizations including managed service providers, datacenter operators, and designated critical suppliers. Managed service providers were previously due to be brought within scope through the abandoned 2022 update to the NIS regulations. The broad intention of the bill is to update the NIS 2018 regulations and future-proof the UK's critical infrastructure from cyber threats. However, this week's Grand Committee scrutiny is not the first time the bill has been criticized. In January, shadow deputy PM Sir Oliver Dowden called on the government to rethink its exclusion of local and central government from the CSR bill. The UK's Government Cyber Action Plan, launched hours before the former digital secretary's remarks, promised to hold government to the same standards proposed in the CSR Bill. Like the AI Cyber Security Code of Practice, the action plan lacks any legal obligations. ®
Categories: News
Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
International law enforcement agencies, working with CrowdStrike and Shadowserver Foundation, have disrupted Sality, a 23-year-old peer-to-peer botnet used to deliver malware to more than 15,000 machines worldwide. The botnet has operated since 2003 and distributed all types of malicious code to victims, spanning credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks. For the past eight years, Sality’s primary payload has been EggJagger, a tool that monitors clipboards for cryptocurrency wallet addresses, then silently replaces them with attacker-controlled addresses. When a victim copies a bitcoin or ethereum address to make a payment, the malware redirects funds into the criminals’ wallets. CrowdStrike estimates Sality's operator stole at least $150,000 in cryptocurrency using EggJagger alone. On Monday, CrowdStrike's Counter Adversary Operations team, working with international law enforcement agencies and industry partners, disrupted Sality by executing a peer-to-peer sinkhole operation. This operation isolated infected machines, which broke the criminal operator’s ability to communicate with devices on its network. Once isolated, the bots can no longer receive payload download instructions or direct payload transfers, effectively breaking the botnet. “In practice, the operation targeted the data structure at the heart of every bot's network awareness: its peer list,” CrowdStrike Counter Adversary Operations team said in a technical writeup about the takedown. Each Sality bot maintains a list of known super peers – publicly reachable infected machines that form the backbone of the P2P network. Every 40 minutes, the bots check to see if their peers are still online. Peers that fail to respond are purged from the network. The counterattack took advantage of this by removing legitimate super peers in each bot’s peer list, continually isolating more infected machines in the network, and inserting purpose-built sinkhole entries into peer lists. That approach gave police and cyber operatives visibility into the operation’s progress and helped them notify victims. In addition to the sinkhole operation, the US Justice Department, FBI, and Department of Defense Office of Inspector General’s Defense Criminal Investigative Service seized Sality-linked domains in the US. Meanwhile, international law enforcement in Bulgaria, Hungary, and Romania took action against additional Sality-linked domains hosted in Europe. Meanwhile, the Shadowserver Foundation is working with internet service providers and Computer Security Incident Response Teams (CSIRTs) to identify infections and aid in victim notification and remediation.®
Categories: News
Another Artifactory CVE under attack by AI agents or humans
Security researchers reported that someone is exploiting CVE-2026-82329, a critical JFrog Artifactory authentication-bypass bug, just days after the vendor patched the 9.8-rated flaw. And we don't know if that someone is human. Artifactory is a widely used tool for managing software artifacts, packages, binaries, and AI models. It’s also popular with AI agents that go rogue and need to communicate with each other while remaining undetected by their human babysitters. In July, OpenAI and JFrog revealed that OpenAI’s models broke out of their cages to hack Hugging Face by exploiting Artifactory zero-days, and at Black Hat, the model provider said agents used Artifactory to build message boards and help each other access the open internet. JFrog disclosed CVE-2026-82329 on Friday, and by Tuesday, attackers had already begun exploiting internet-exposed systems, according to exposure-management biz watchTowr’s threat-intel team, which reported “attackers minting themselves admin tokens.” In addition to creating new administrative credentials, watchTowr’s honeypot network caught miscreants “enumerating users, groups, credential sets and federated access topologies,” Yordan Ganchev, principal threat intelligence specialist at watchTowr, told The Register. “Right now, we’re observing exploitation from a small number of IP addresses from varying geographies exploiting multiple of our honeypots,” Ganchev said. “Broad-scale scanning and mass exploitation has not been observed, but that is unlikely to stay the case for long.” Ganchev urged organizations running vulnerable versions to “urgently patch” internet-exposed systems, and treat them as being potentially compromised - so inspect audit logs, rotate credentials, and investigate connected systems for any unusual changes or backdoor implants. “When attackers gain admin level access to a central software supply chain system, they can do what every engineering team does best - build, ship and distribute software fast,” he said. “From there, they could tamper with build pipelines, move laterally into production systems and potentially push malicious changes downstream to customers.” JFrog did not immediately respond to The Register’s inquiries. We will update this story when we receive any response. ®
Categories: News
Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks
AI model testing organization METR has disclosed two attacks that happened earlier this year, including one in which an attacker stole an API key and spent three weeks consuming public-model credits worth about $600,000. METR (short for Model Evaluation and Threat Research) found no evidence that the attackers accessed sensitive information in either incident, and the org said it investigated both with security experts. METR researchers worked with OpenAI to investigate how its agents hacked Hugging Face, and on Monday, it disclosed two of its own security snafus. “In March 2026, attackers stole an API key for inference on public models and consumed a substantial amount of credits,” the nonprofit disclosed in a Monday report. “In May 2026, we observed attackers systematically probing our publicly accessible infrastructure, including an unsuccessful attempt to access internal data via an inadvertently exposed endpoint.” From fail-open bug to model-credit theft The March incident involved a METR researcher who didn’t have access to sensitive information - including model data and credentials, as well as information about model architectures, training, and release dates. The researcher used agents running on a personal EC2 instance that was “intentionally” left publicly accessible behind Google authentication. The instance contained an API key for METR’s public models account. According to METR’s account, a “vibe-coded app” included a fail-open bug that disabled authentication, and this exposed the system to the public internet for several days. “We suspect that the attacker found the instance by looking through recently-registered websites (e.g. in certificate transparency lists) to find vibe-coded sites with high-signal keywords relating to LLMs or agents, for purposes of harvesting potentially exposed model provider API keys,” the AI research org wrote. Once the attacker found the app, they prompted an agent to reveal its model provider API key, then added an SSH key to maintain persistent access, and over the next three weeks used the stolen credentials to consume API credits on public models worth about $600,000. Luckily for METR, the unnamed model developer had given the credits to the nonprofit for free. How do you not notice the 'large illicit usage?' METR does answer the question on everyone’s mind in the report: Why its researchers didn’t notice the “large illicit usage?” There are several reasons for this. First, the model testing operation regularly runs evaluations that use a lot of tokens, and this means the organization is “very acclimated to getting lots of weird rate limit and API errors.” So the high usage didn’t look that out of the ordinary. Plus, since the tokens were free, METR didn’t accrue a large bill, and at the time there was no way to put a spending limit on keys like the one that was stolen. In response to the March incident, METR says it improved its security infrastructure, protocols, and review process, and will continue to invest in security. To this end, it also hired a security lead, and plans to add more security staff. Crims used agents to try to access frontier models The second incident happened in early May, when “METR became the target of a sustained external attack campaign.” After being “tipped off” that attackers who appeared financially motivated may have been trying to gain illicit access to frontier models, METR watched the intruders probe its publicly accessible infrastructure. They also used agents to find ways to gain initial access, including automated vulnerability discovery, credential stuffing against authentication providers, attempting OAuth token grants, scanning newly deployed services, and phishing attempts. At the same time, METR unintentionally “exposed a read-only SQL query mechanism via our public transcript viewer.” While queries were scoped to public data by default, a bug allowed access to unpublished evaluation data, and “some sensitive model data was accidentally included in this database.” However, there’s no evidence that the attacker found the exploit or accessed any non-public data, according to the model testing body. An independent bug hunter discovered the vulnerability and reported it to METR, which paid the researcher a bounty, and took the API offline. In response, METR says it now uses an isolated production environment for public-facing applications that is separate from its internal infrastructure.®
Categories: News
Firefox helps iPhone users bypass ads on web sites while making money showing its own ads
After several weeks of anticipation, Mozilla has started rolling out ad blocking to the iOS version of its popular browser, but you can still expect to see ads on Mozilla's own pages, including the new tab page. The org officially rolled out the new native ad blocking feature for iOS Firefox on Tuesday, moving it out of the experimental phase, while explaining that it had to rethink its desire to give users control over their web experience on iOS due to differences in architecture between it and other OSes. “Firefox already supports a strong ecosystem of ad-blocking and privacy extensions,” Mozilla explained. iOS works differently, though, as Apple forces all web browsers on iOS to use its own WebKit to render sites instead of their own preferred back end. “Bringing ad blocking to Firefox on iOS,” therefore, “meant building it directly into the browser,” Mozilla explained. Implementing ad blocking in the iOS version of Firefox meant incorporating Apple’s own WebKit Content Blockers. According to Apple’s introduction on the topic, it specifically doesn’t want app extensions to be used to block web content because of how they operate. “App extensions … are essentially little sandboxed applications that are launched on demand to extend some specific piece of functionality,” Apple notes. “JavaScript-based content blocking extensions … have significant performance drawbacks.” Apple complains that traditional ad blockers use too much energy, increase page load time, and eat up memory, all of which it wants to protect iOS users from. Apple describes WebKit Content Blocking as “describing content blocking rules in a structured format ahead-of-time, declaratively.” Apple Web Content Blockers instead live in bytecode format that executes for each resource request, modifying requests or injecting CSS changes as needed while pages are loaded. For Mozilla, that basically means dropping the EasyList filter, originally designed for the classic Adblock blocker, into a JSON file and passing it to WebKit. Easy peasy. Ad blocking in Firefox for iOS is off by default. Turning it on, if it’s available for you – it’s rolling out gradually – is as easy as opening the in-app settings menu, tapping on Browsing, and toggling the Ad Blocker field on. Mozilla told The Register in an email that it doesn't have a timeline for general release to all Firefox users on iOS, which it said will largely depend on how well the initial rollout goes. You also have to turn Remote Improvements on, as the feature allows Mozilla to push fixes and feature changes to Firefox between full releases. Toggling that on has traditionally meant you also had to allow Mozilla to collect browser telemetry, but that was changed in February when Firefox 148 was released and the two features have officially been decoupled. Once on, iOS Firefox Adblocking will take care of ad-related trackers, ads from third-party advertising networks, third-party ads served by websites, and popups/overlays. What it won’t do, however, is take care of ads on search result pages or sponsored content on Firefox’s home or new tab page – after all, you wouldn’t want Mozilla to lose those precious ad bucks, would you? Firefox iOS ad blocking also won’t eliminate ads served directly by websites, and the company warns that it still might not work in all places, which is pretty common for ad blockers. For Firefox users who want browser consistency across platforms, it’s likely a welcomed announcement, though it begs the question whether Mozilla is considering integrating its own ad blocking technology in the desktop or Android versions of its browser. Fortunately for those making ad-blocking extensions, and those who love them, Mozilla says it has no plans to expand built-in adblocking outside iOS. "We value that ecosystem and will continue to support it," Mozilla told us. ®
Categories: News
Anthropic pledges to try harder to keep models under control, asks partners to chip in
Anthropic says it's taking steps to limit the misbehavior of its AI models after a review found Claude models going beyond the scope of fictional cybersecurity tests and gaining unauthorized access to real computer systems. The biz wants its partners to step up their security too, seeing as the incidents occurred in third-party environments that were insufficiently protected. The company's self-improvement confession represents a suddenly thriving form of corporate communication – the non-binding post-mortem declaration of effort. The message, in effect: We can't guarantee anything, but here's what we're trying. Anthropic admitted that OpenAI's report about its AI models attacking Hugging Face prompted its own model log audit, and its post offers reassurance in the form of claimed security and model training improvements. Those concerned about AI running amok – a growing number of people – may find this comforting, or not. "We believe the incidents reflect a failure of operational security, as well as two alignment issues: motivated reasoning, and willingness to take harmful actions in pursuit of a narrow task (both of which we have described in previous system cards)," the company said. Expanded security efforts include the deployment of real-time classifiers to monitor when models attempt to escape test environments, automated transcript monitoring that looks for sandbox escapes, and stronger isolation measures. Alongside the extra barriers Anthropic is putting in place, the AI biz wants its third-party partners to step up too. "Because the reported incidents took place in third-party environments, we have asked every organization that tests pre-release models with reduced cyber safeguards to commit to a set of best practices," the company said. Anthropic's guidance is that by default, all cyber evaluations should occur in a hardened sandbox with no internet access. The recommendation is essentially to treat AI as a dangerous pathogen in a containment facility. Partners are also advised to have models test sandboxes for escapes prior to evaluations – without internet access – and to confirm that evaluation challenges are solvable. Impossible challenges, as the Hugging Face incident demonstrated, can lead determined models to break rules or try unanticipated solution paths. Furthermore, Anthropic urges those conducting cyber evaluations of AI models to direct models through explicit instructions rather than making claims about an environment that might not be accurate. In the Claude incidents reported on July 30, the model maker suggests that when Claude was misinformed about the availability of internet access, that may have led the model to question data in a way that contributed to its errant behavior. On a related note, Anthropic last month made auto mode the default in Claude Code, enabling company AI models to run without prompting the user for permission. ®
Categories: News
33-hour BGP hijack of Softaculous traffic prompts security scramble
Softaculous and Virtualizor customers are being urged to reset credentials and inspect their servers after a 33-hour BGP hijacking incident diverted traffic and delivered malware to a handful of installations. Softaculous makes software for the web hosting industry, while its Virtualizor control panel is used by providers and administrators to deploy and manage virtual private servers. Beginning at around 20:57 UTC on August 28, an unrelated network began announcing a block of Hetzner IP addresses used by Softaculous, diverting some traffic intended for the vendor's systems to an attacker-controlled server. German hosting provider Hetzner is one of Softaculous's upstream infrastructure providers. The affected addresses served "a number of Softaculous systems," including Virtualizor's software update endpoint and Softaculous's client and billing site. The attacker pulled off the BGP hijack by announcing a more specific IP address range than Hetzner normally advertised. Under standard BGP route selection, the more specific route took precedence wherever it was accepted. According to Softaculous, the attacker was also able to secure a valid TLS certificate from Let's Encrypt because the certificate authority's automated domain-ownership validation was routed through the hijack too. This allowed affected connections to reach the attacker's server without triggering the certificate warnings that might otherwise have alerted users. According to the vendor's timeline, the unauthorized route was initially "accepted by essentially every internet vantage point that receives it," although it flapped repeatedly rather than remaining continuously available. Softaculous said it reported the issues to Hetzner at around 08:50 UTC on August 29. The hosting provider began directly announcing the same, more-specific address range, cutting the observed diversion to almost zero for roughly 11 hours. The unauthorized announcement returned at around 20:00 UTC and was again widely accepted, beginning a second wave that lasted roughly ten hours. The route was withdrawn between 05:50 and 06:10 UTC on August 30, after which normal routing was restored globally. While either wave was active, Softaculous estimates that a given server had roughly a 72 percent chance of being on a network that routed the affected address range through the attacker. The figure is based on the proportion of RIPE routing collector peers carrying the hijacked route, not the volume of traffic intercepted, the vendor said. Anyone who logged into the Softaculous client area during the incident window is advised to reset that password immediately, as well as anywhere else it was reused. Customers who entered card details during the same window should also review their statements. Softaculous said it does not process cards on its own servers and instead uses payment gateways, but an affected session may have been diverted before reaching them. More seriously, the vendor confirmed that a malicious Virtualizor update package was delivered to a handful of installations whose update checks passed through the attacker's server. "Our product update clients did not yet cryptographically verify update packages, so a modified package would not have been rejected on that basis." Because those downloads never reached its own logs, Softaculous said it "cannot produce a definitive list" of affected installations. It is therefore telling every Virtualizor operator to treat their server as in scope for checks – not necessarily as compromised. Softaculous did not describe the malware's capabilities, but identified a systemd unit at /etc/systemd/system/java-jre-update.service as an indicator of compromise. Operators that find it are advised not to delete it immediately, but to contact the vendor so evidence can be preserved. The vendor has not identified malicious packages targeting Backuply, Softaculous, SitePad, Webuzo, or its other products, although its investigation continues. Virtualizor operators should rotate and restrict their API credentials, check for unknown SSH keys and accounts, inspect scheduled tasks and outbound connections, and regenerate client-area API keys. Softaculous is also invalidating client-area sessions created during the incident window. Softaculous did not disclose how many customers downloaded the malicious update or may have handed credentials to the attacker. It said only that the confirmed infections amounted to "a handful of servers rather than the general Virtualizor user base." ®
Categories: News
Healthcare cyberattacks hit pacemakers and millions of patient records
Two major healthcare businesses, Boston Scientific and McKesson, disclosed more details over the weekend about separate cyberattacks that disrupted global operations and resulted in stolen patient data, respectively. Medical-device maker Boston Scientific, whose IT systems were hacked by unknown intruders last week, said the cyberattack remains ongoing. It also noted that pacemakers and other heart devices implanted after the August 25 breach cannot provide remote monitoring and data transmission as intended. “New remote monitoring communicators cannot be activated, thus available device data will NOT be transmitted to remote patient management systems until the communicator can be activated,” the medtech firm said in a late Friday update. This applies to all new cardiac rhythm management implants other than insertable cardiac monitors (ICM). ICM devices must be activated using the Boston Scientific Clinic Assistant app to ensure the device correctly records patients’ heart rhythms, the company added. Because of the cyberattack, “new ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app,” according to the update. The devices will still record any episodes, and patients can transmit these to the remote monitoring system by in-person transmission via the Clinic Assistant app. This is done by selecting the “interrogate” button, according to the company. Once its IT systems are back up and running, and the heart devices can pair with home monitoring equipment, they will again transmit recorded data to the remote systems. However, the company does not have a timeline for full restoration. “We are currently working on restoring affected functions and systems access,” Boston Scientific said on Saturday. The digital intrusion also affected the firm’s manufacturing, shipping, and ordering, it noted. “We are expeditiously working towards partial restoration for the shipping of some products this week,” according to a Sunday update. “Once we can demonstrate the restoration is fully operable, we anticipate ordering and shipping will ramp up to full capacity.” Boston Scientific has hired CrowdStrike to assist with the investigation and restoration efforts, and said the attack did not affect its cloud-based systems and apps - just “certain on-premise systems” - and added that it has seen no indication of unauthorized IT activity since August 25. The firm has repeatedly declined to answer The Register’s questions about the compromise, including whether it was a ransomware infection and which criminal crew is responsible. McKesson confirms breach as ShinyHunters claims responsibility Meanwhile, in another cybersecurity incident that has been very publicly claimed by the criminal perpetrator: pharmaceutical and medical supply giant McKesson over the weekend confirmed an intrusion after ShinyHunters on Friday told The Register it broke into the company’s Snowflake and Salesforce instances and stole millions of patients’ data. “Based on our investigation thus far, including assessments by leading cybersecurity industry experts supporting our response, we’ve confirmed that the unauthorized access to certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units,” Francisco Fraga, McKesson executive VP, chief information officer and chief technology officer, said in a Saturday statement. The medical firm did not immediately respond to The Register’s questions, including how many patients were affected and what “certain data” was stolen. McKesson supports about 3,300 oncology providers in 29 states, according to its website. Fraga’s statement noted that distribution centers remain operational and McKesson continues to ship products. The firm has “reasonable assurance” that the digital intruders have been kicked out of the third-party environments and aren’t lurking around McKesson’s systems, he added. A ShinyHunters spokesperson told us that the notorious extortion group compromised more than 284 million records of patient data, and demanded McKesson pay $55.2 million or else they would leak the stolen data. However, as Have I Been Pwned boss Troy Hunt recently reminded everyone: Don’t confuse criminals’ claims with gospel truth, and “take headline numbers with a grain of salt unless you're confident in the processes of those making the claims." This was after Hunt’s HIBP service reported 12.9 million individuals affected by retailer Carhartt’s alleged breach. This number was around half of what ShinyHunters claimed when they leaked the company’s data earlier this month. The McKesson records, according to the ShinyHunters spokesperson, include patients’ full names, home and email addresses, phone numbers, dates of birth, Social Security numbers, appointment dates and notes, and sensitive illness details including cancer locations on people’s bodies. The group also claims to have swiped emails containing private information from doctors to patients. The spokesperson told us they accessed the company’s Snowflake and Salesforce instances by voice phishing “multiple employees.” This is a tried-and-true method popularized by the data-theft-and-extortion gang, which has victimized other medical providers in recent months. These include pacemaker manufacturer Medtronic in April, and cancer diagnostics business Exact Sciences in July. ®
Categories: News
OpenClaw 2.0 pours glitter on slow-burning security dumpster fire
OpenClaw has unveiled what its makers call its largest ever update – large enough to earn a 2.0 moniker – with usability taking center stage, along with some security updates that critics are suggesting will be insufficient. The OpenClaw foundation announced the release of version 2.0 of its AI agent harness on Sunday, describing it as something with far more scope than they ever intended it to have. “This update touches every part of OpenClaw,” Foundation community manager Hannes Rudolph said of the update. “We started by simplifying installation and rebuilding the browser app as a first-class experience, but doing that properly meant carrying the cleanup through the rest of OpenClaw until it became OpenClaw 2.0.” It's those two features – the rebuilt installation experience and redesigned interface – that Rudolph dedicates most of his announcement to. OpenClaw is an open-source, self-hosted AI agent harness that allows users to build their own AI agents and connect them to whatever apps and services they want. OpenClaw went viral shortly after its launch due to its extensive capabilities, and helped launch the AI agent craze. But, by empowering AI models with agentic capabilities, it exposed numerous security problems with unrestrained automation. In version 2.0, the new installation process is designed to be simpler, ostensibly to get more people using OpenClaw. “We cut or simplified a lot of configuration and moved the rest out of initial setup, letting people get to a first conversation faster and finish setting up their Claw by talking to it,” Rudolph explained. As for the user experience, Rudolph explained that the OpenClaw browser app has been redesigned into “a first-class experience” where users can continue setup and interact with their agent. “The web-based experience in OpenClaw now feels more familiar to anyone who uses apps like ChatGPT, Claude, Gemini, or Perplexity, with conversations in the sidebar and the one you are working in at the centre instead of opening on a separate Overview page,” the patch notes for the release explains. In other words, OpenClaw’s basic interface now looks just like the chat interface for every other AI service you’ve likely used on the web. The last major feature update added in OpenClaw 2.0 is shared cloud sessions. Per the announcement, OpenClaw previously had no way to include multiple team members in a single instance without the Claw involved losing its memory. Shared cloud sessions correct that, enabling multiple people to interact with a single Claw while context is maintained across users and a continuous chat, giving OpenClaw feature parity with the agent harnesses offered by frontier labs like Anthropic and OpenAI, which allow collaboration for enterprise users. What about security? Since launching in November 2025, OpenClaw has deservedly earned its reputation as a complete security mess – not only in the code itself but for users and those who are unfortunate enough to come in contact with a Claw’s orders as well. Celebrity UK mathematician Professor Hannah Fry tested OpenClaw out earlier this year, finding it was ready and willing to share her private information when threatened. In another instance, an OpenClaw agent hacked a gym’s waiting list and forced its user into a full class, displacing other reservations, when simply asked to get him on the list. So, what is OpenClaw doing to improve on these risks as part of the update? Not that much, based on a reading of the patch notes. Shared sessions, for example, are a great way to introduce collaborative Claws at work, but the OpenClaw foundation states in the patch notes that the shared session controls “are not tenant isolation or a security boundary.” In other words, you’d better be sure there’s no need to isolate various OpenClaw instances. A new protected credentials feature has been added that allows users to share credentials with agents in shared environments without exposing them in chat. That’s great, and as explained in the patch notes it’s further secured in a local secret store that “separates Protected values from Agent-readable environment values.” What’s not great, on the other hand, is the fact that “Secret Store values are not encrypted at rest and depend on the filesystem permissions of OpenClaw's state directory.” A new sandbox for contributor-controlled code was also announced, with the patch notes referring to an environment for untrusted code isolation. Again, great – except sandboxing is turned off by default. In other words, this release is doing a lot to make installing and getting OpenClaw up and running for more people, but it’s not bringing security by default along with that accessibility. As we’ve warned before, granting a capable and potentially dangerous tool like this widespread access to your systems and credentials ought not be done lightly, fancy new wrapper or not. ®
Categories: News
Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines
An unknown miscreant is using "TerminalFix" to trick unsuspecting users into running PowerShell commands that infect their computers with a reverse tunnel granting attackers access to their networks. Some of the malware is even hidden inside PNG graphics the PC downloads. TerminalFix is the latest variant of the wildly popular ClickFix initial access method for attackers. This type of social engineering technique tricks users into running malicious commands by promoting them with a phony fix or CAPTCHA verification. While traditional ClickFix attacks point victims to the Windows Run dialog, TerminalFix directs users to Windows Terminal or PowerShell, which increases the likelihood that they will unknowingly run multi-line scripts on their own computers, Redmond says. Plus, instead of delivering just one infostealer, this campaign kicks off a multi-stage attack chain that combines DLL sideloading, steganographic payload extraction, and Active Directory reconnaissance. It ultimately deploys a custom reverse tunnel on the infected machine that gives the attacker persistent, network-level proxy access through the compromised device. Microsoft declined to answer The Register’s questions, including how many organizations were targeted and victimized in this TerminalFix campaign, and which attacker or criminal crew is responsible for these attacks. The attack chain begins when the victim interacts with a phony overlay that spoofs the Cloudflare CAPTCHA “verify you are human” checkbox and includes a Cloudflare logo, causing a fake verification command to be copied to the clipboard before the victim pastes it into Windows Terminal or PowerShell. This command runs a hidden PowerShell script that prints a fake “Starting Cloudflare verification…” message and downloads a ZIP archive from an attacker-controlled server. It extracts the archive under C:\ProgramData and launches a batch file (1.bat) that silently executes LockScreenContentServer.exe. LockScreenContentServer.exe is a legitimate, signed Windows executable - and it acts as the DLL sideloading host for a second file: dui70.dll. This purports to be a “Windows DirectUI Engine,” but is actually the malicious payload, which executes a second-stage PowerShell script once it’s sideloaded. The second PowerShell script downloads additional payloads hidden inside PNG images - this is called steganography, and it makes file- and content-type inspection more difficult, and thus easier to hide malicious payloads. In an attempt to further obfuscate the payload and avoid being detected, the attacker split the payload into multiple PNGs. The PowerShell script downloads the three images, extracts an executable from the first image and two halves of the DLL from the second and third images, and then reassembles the components on disk. “After extraction, the source images are deleted to reduce forensic artifacts,” Microsoft researchers Sagar Patil, Suriyaraj Natarajan, and Parasharan Raghavan wrote. The malware establishes redundant persistence through both HKCU\…\Run registry keys and scheduled tasks that re-execute LockScreenContentServer.exe every 60 minutes to ensure it survives reboots. It then does reconnaissance on the compromised machine, scooping up system information across multiple language configurations including English, Spanish, and German. It also performs domain trust discovery, domain admin enumeration, and Active Directory user and computer searches, while pinging targeted, named servers. “The observed names correspond to common infrastructure roles, including domain controllers, databases, backup, gateways, and mail systems,” according to the threat hunters. “This probing could help an attacker identify accessible target systems for follow-on activity.” Next, the malware drops a persistent PowerShell file-watch loop that monitors a text file for new commands, executes them via Invoke-Expression, and writes results to an output file. This allows the attacker to execute additional PowerShell commands by writing them to the text file. And finally, the attacker deploys a custom, Python-based reverse-tunnel implant. The tunnel launches with no visible window via pythonw.exe, and it sets up a reverse WebSocket tunnel to gitnow[.]dev:443. This implant, combined with earlier reconnaissance data, gives the attacker SOCKS-style TCP proxy access through the victim’s network. Microsoft recommends organizations take several steps to avoid becoming a victim of this campaign. These include restricting PowerShell and Run dialog execution, and either blocking or auditing the Windows Run dialog (Win+R) if it’s not needed for daily work. Also, train employees on how to look for ClickFix tactics, like fake CAPTCHA verification pages that tell them to paste commands into Terminal or the Run dialog. ®
Categories: News