News

High-severity Nvidia bug could crash GPU monitoring on exposed servers

The Register - 3 hours 35 min ago
Researchers found thousands of GPU servers exposing Nvidia's DCGM Exporter to the internet, with hundreds potentially vulnerable to a high-severity flaw that could let unauthenticated attackers crash the GPU monitoring service and disrupt AI workloads. DCGM Exporters read telemetry from the GPUs on a host, including its hardware, utilization, memory usage, power consumption, and error events. Each GPU has its own unique ID, or UUID, and all of these metrics are exposed in plaintext over HTTP. This exposure provides would-be attackers with detailed information useful for reconnaissance, including mapping GPU infrastructure, identifying potentially vulnerable systems, and monitoring workload activity. Michael Katchinskiy, a researcher at datacenter security startup Lava, found and reported the bug in the GPU health and performance monitoring service. In September, the GPU giant Nvidia released a fix for the flaw, tracked as CVE-2026-47483, and gave it an 8.2 CVSS high-severity rating. “Once we realized how much these endpoints revealed, the next question was: How many of them are exposed to the internet?” Katchinskiy said in a Thursday blog. So the researchers started scanning the internet for exposed DCGM Exporters. And the scale of exposure proved “especially significant,” he wrote. Over the course of four scans between March and May, the threat hunters found about 2,100 GPU servers exposing DCGM Exporter metrics to the open internet. These included 12,000 GPU UUIDs. None of these required authentication. The hosts belonged to about 300 organizations, according to Katchinskiy, and nearly half - 5,274 of the exposed GPUs, or 44 percent of the total - were located in the US. These GPUs represented about $100 million in hardware, and included Nvidia Blackwell Ultra B300 GPUs, H200s, and H100s - used to run large-scale AI workloads - plus consumer RTX 5090 and 4090 systems. While investigating the exposed systems, the Lava team found that about 25 percent of the exposed DCGM hosts also revealed data from Go’s /debug/pprof/ built-in profiling tool. The profiler collects and exposes runtime performance data such as CPU and memory usage for running Go applications. This includes CPU usage, memory allocations, goroutine states, and blocking events. “With enough concurrent unauthenticated requests, the exporter could run out of memory and crash, cutting off visibility into GPU health and activity,” Katchinskiy wrote. The CPU and memory pressure could also affect AI training or inference workloads. Nvidia fixed the issue in version 4.8.2, and operators should upgrade to that version or later. In addition to GPU telemetry, Lava looked into Prometheus Node Exporter, which monitors server hardware and operating systems, and also exposes metrics over HTTP. The team found 12,096 public Node Exporter hosts exposing data on server models, operating systems, firmware versions, hostnames, storage paths and networking hardware commonly used in GPU clusters. This information reveals how environments are built and configured, which could also be used by attackers for reconnaissance, matching the system to known vulnerabilities. The publicly exposed monitoring services affected customer infrastructure across neocloud and GPU cloud providers including Nebius, Voltage Park, Lambda, Northern Data, and DigitalOcean. Lava reported all of this to the affected providers, and Katchinskiy says that these providers worked with customers to address the exposures. For operators: the security shop says Nvidia DCGM Exporter, Node Exporter and Prometheus services should not be directly reachable from the public internet and recommends restricting them to authorized monitoring infrastructure. “The findings highlight a growing security gap in AI infrastructure: companies are spending millions on GPUs while leaving critical systems exposed,” Katchinskiy wrote. “Those exposures can reveal how AI environments are built and, in some cases, allow attackers to disrupt them.” ®
Categories: News

Shai-Hulud worm makes jump to AI infrastructure with Tensorlake compromise

The Register - 4 hours 58 min ago
The credential-hijacking Shai-Hulud worm has struck again, this time burrowing its way into a popular AI agent platform SDK. Multiple security researchers reported Thursday that they had detected Shai-Hulud infection in a recent release of the npm package for version 0.5.144 of Tensorlake’s SDK. That package has somewhere in the neighborhood of 12,000 downloads per week, while its GitHub repository has more than a thousand stars, suggesting it’s quite popular and that the infection could pose a serious risk to anyone who installed the malicious version. Analysis of the malicious release suggests it shares code and techniques with the Shai-Hulud variant dubbed ChainDrop by researchers, which was used in August to compromise npm dependencies including keyv and flat-cache. Like other variants of Shai-Hulud, the worm is designed to steal credentials and self-propagate. This particular version, according to supply chain security firm SafeDep, is designed to steal everything from crypto wallets to browser passwords, GitHub Actions secrets, cloud credentials, service-account tokens, and whatever else it can get its hands on. It exfiltrates that data and keeps an open line to its C2 infrastructure to await further instructions. To make matters worse, this Shai-Hulud variant monitors certain stolen GitHub tokens and, if one is revoked, can trigger the deletion of the infected user's home directory under specific conditions, making removal tricky. Socket recommends rebuilding compromised systems from a trusted source before restoring access to secrets, while researchers warn that the malicious token monitor should be disabled before revoking affected credentials. Tensorlake, for those unfamiliar, is a cloud-native platform for running isolated AI agents and untrusted AI-authored code. The infected npm SDK is used to create and manage Tensorlake environments. Socket warns that the malicious SDK's installation script can execute on the developer's machine or build server, outside Tensorlake's sandbox protections, potentially compromising the host before any AI-generated code is run. “Teams may isolate an agent’s generated code while installing its SDK on a developer workstation, application server, or build runner with access to deployment credentials and other secrets,” Socket noted. “Code executed during that installation inherits the permissions of the installing process.” That may sound bad, but it’s worth noting the malicious version wasn’t up for long - according to security firm Socket, the infected version was published to npm earlier this morning, UTC, and was flagged by its engine 11 minutes after publication. Npm removed the version, and Tensorlake has pulled the package as well, updating the version to 0.5.145. Best check to be sure you haven't installed the malicious version if you're a Tensorlake user. ®
Categories: News

Fighting GenAI with GenAI: The New Email Security Landscape

The Register - 6 hours 52 min ago
The use of phishing emails as a means of stealing information or implanting damaging malware dates back to the mid-1990s. Although almost as old as the Internet, it remains the instrument of choice for threat actors wanting to pose as trusted organizations or individuals for the purposes of corporate infiltration. In fact its use is on the rise: according to the most recent figures from the Federal Bureau of Investigation (FBI), some 26 percent of all cybercrime complaints filed with them are now phishing-related. The bad news doesn’t stop there. Phishing is mutating in alarming new ways, raising all sorts of difficult questions for defenders and placing email security at a tricky inflection point. AI has for years been a useful tool in the hands of the cybercriminal. But the advent of Generative AI (GenAI) is proving a cyber game changer, transforming phishing from a widespread but easily identifiable nuisance into a lethal precision instrument. Aspiring phishers have historically been hindered by various constraints. Their attempts at chummy authenticity have often been undermined by easy-to-spot mistakes and amateurish formatting – blemishes that traditional email security is good at picking up. Personalised attacks have also been hard to launch at any kind of scale. GenAI sweeps all technical, linguistic, and operational restrictions aside by automating sophistication. Attackers no longer have to choose between individually targeted “spear phishing” which takes much effort to coordinate, and large-scale attacks that lack finesse. Now, with minimal expertise and at low cost, they can hit thousands of victims with minutely tailored phishes at the press of a button. Today’s Large Language Models (LLMs) generate polished and contextual text in any language, backing it with realistic brand graphics and convincing web addresses. At a stroke, Gen AI has democratized this type of crime, putting it in reach of anyone capable of the most elementary research. “Thanks to AI, the historic signals that exposed a phishing email – poor grammar, misspelt words – are now ironed out and replaced with perfect language,” notes Dave Baggett, SVP Cybersecurity with software developer Kaseya. “These emails can be highly targeted with the help of AI. You can create an email that pinpoints, say, a pharma company by using authentic terminology. It’s an incredibly powerful tool for the bad guys.” And let’s not forget that where this new AI-enabled phishing is successful, it is not just a single unwary employee whose data is at risk. Once past the perimeter, a bad actor can get to work burrowing into the cloud and SaaS platforms that now underpin global commerce and communications. All in all, it’s easy to understand how losses from phishing attacks have gone up 274 percent in the last couple of years, according to the FBI. This new email security landscape is an alarming development for corporate IT bosses, and also for MSPs who must be super wary on behalf of customers who don’t have the expertise to pick up attacks at this pitch of sophistication on their own. AI is for the good guys too It’s not all bad news on the email security front line. As threat actors have been perfecting their use of GenAI, defenders have been developing AI-driven counter solutions in parallel. Where old school protection relied on spotting the kind of anomalies that GenAI has now ironed out, newer solutions are geared more towards contextual analysis. They are not so much trying to spot clumsy typos and dodgy attachments as model an attacker’s intent before damage is done. Today defenders can use AI to analyze subtle patterns that are in tune with the layered structure of modern phishing campaigns. The aim is to determine whether a message aligns with expected behavioral patterns. This level of finesse is made necessary by the insidious nature of modern phishing which means that technically clean email messages, in other words ones that are free of malware-loaded attachments or booby-trapped links, can still contain malicious potential. Modern cybercriminals often bypass automated security filters by the simple means of exploiting human psychology and trusted infrastructure. Social engineering, supercharged by GenAI, can be a sharper sword than a malware payload. A phish will often seek to impersonate a boss or a colleague using a plain text email. Attackers can set GenAI to scour LinkedIn, looking for people who have just started new jobs. Green employees are more vulnerable to a phish that looks like an email from a new superior they haven’t got to know yet. Once trust is established, what will typically follow is a demand for, say, an urgent wire transfer, or a casual request for payroll details or passwords. Attackers can develop a relationship over multiple emails to “groom” the victim before striking. Traditional filters see nothing suspicious. Spotting this sort of attack demands a smarter grade of tool. “Since attackers are relying on manipulation of fallible individuals, security must now support them at the moment where wrong decisions can be made,” says Baggett. “Good email security will replace generic warnings with easily digestible context about why a message might be risky and advice about the need for further verification.” Where once an inbox was a passive delivery channel, says Baggett, it is now an active layer of risk mitigation, tooled up to stamp out a phishing attempt before it escalates into account compromise and devastating financial loss. A huge asymmetry The good guys are fighting back. But as Baggett points out, there remains a huge asymmetry between bad actor and defender: “Attackers can use LLMs, basically for free, to create perfect phishing templates,” he says. “On the other hand, if defenders took every inbound email and put it through a frontier LLM model, that’s about 100x too expensive. We just can’t use the same tools at the criminals.” One option for defenders is to use smaller, more specialized models, distilled from larger ones. A compact model could be tuned, for example, to the sentiment or meaning of each phrase in an email, and set to pick up a threatening tone or a favor being asked. Where chunky LLMs just cost too much, another choice might be to run a subset of the overall inbound mail through a big model: “Admins can be given a way to run particular mails through a frontier LLM,” says Baggett. “That model will have been trained to understand certain critical aspects of email security.” Better use could be made of pre-LLM tools such as computer vision, which can help process, analyze and understand visual data like digital images and videos. Other ancillary tools that could enrich the defensive mix include sender analysis to look into the origin and authenticity of an email message, and linked-content inspection that can examine an email in depth without triggering any embedded threats. There are some reasons to hope for a safer future as AI technology evolves. As inference becomes smarter and models get better, it should become possible to run a higher percentage of emails through a large scale LLM, believes Baggett. This, however, may not be achievable for some years. There’s also the possibility of using LLMs not just to spot potentially malicious emails but also to analyze the settings and admin controls of existing security tools. In this way, the knowledge required to use the tools to best effect becomes much less. “Security tools can be complex and feature hundreds of settings,” points out Baggett. “Some require expertise that our customers don’t have. There are a number of things we believe tools should be doing to help defenders, for example reduce alert fatigue.” The criminal fraternity may, of course, also find ways to harness better tools for new purposes. At the moment, most attacks are conceived and designed by humans. But ultimately, this job may be taken over by agentic models able to figure out new tactics for themselves. Machines may soon be able to plan and supervise attacks at scale. Great tools, available now Luckily defenders don’t have to sit back and be at the mercy of future developments. There are some great tools available today that help them even up the odds and cut the complexity from checking email. INKY Smart Insights, for example, uses GenAI to reduce a lengthy manual email investigation to a few seconds of automated triage. For the purposes of hard-pressed administrators it can turn a mess of technical email evidence into a plain-language verdict and enable the creation of cogent reports. Along with Kaseya Intelligence it can support decision-making across the broader security environment. “Smart Insights will identify problems and give a narrative explanation of its reasoning,” enthuses Baggett. “It will do that in a way that’s not overly technical, making the tool valuable to someone who doesn’t have expertise in email security.” The hard-pressed MSP, for example, can leverage Smart Insights to provide key information for their customers in an abbreviated and digestible format. In short, it allows them to enjoy the sophistication of LLMs but without adding hugely to their overheads. The war on GenAI-powered phishing is far from won. But so long as defenders can understand the potential of the smart tools at their disposal, they have a fighting chance of keeping the bad guys at bay and essential channels of communication safe. Find out more at Kaseya’s Cybersecurity Summit – details here Sponsored by Kaseya
Categories: News

UK and Germany team up against Russian cyberattacks as Brexit rethink looms

The Register - 10 hours 30 min ago
Britain and Germany have announced a partnership to counter cyberattacks and sabotage, particularly from Russia, as Prime Minister Andy Burnham heads to Berlin for talks. Under the arrangement announced Thursday, the countries will share information and coordinate efforts to monitor, deter, and disrupt hostile activity, including threats to critical infrastructure. The announcement comes ahead of Burnham's first face-to-face meeting with German Chancellor Friedrich Merz, where security won't be the only item on the agenda. The PM is also expected to raise Britain's relationship with the EU, including the possibility of rejoining the bloc. Burnham has floated several options for undoing parts of Brexit, from rejoining the customs union or single market to returning to the EU outright. According to the Financial Times, he wants Germany's backing for closer economic ties before a UK-EU summit on November 20. On the security front, both governments worry about Russia's appetite for cyberattacks, sabotage, and other operations that fall short of outright military confrontation. "Attacks on our infrastructure, our businesses and our democracies are not a distant threat," Burnham said ahead of the meeting. "They reach into people's homes and workplaces, and they are designed to make us weaker and more divided." He added: "Britain and Germany are joining forces to find, expose and disrupt this activity." The partnership builds on the Kensington Treaty, signed in July 2025 and ratified on Thursday, which already committed the two countries to working more closely on defense, cybersecurity, technology, and economic security. The announcement offers little operational detail. It names no agencies, specifies no additional funding, and does not explain how the countries will disrupt hostile operations. The deal lands amid increasingly stark warnings from European intelligence agencies about Moscow's activities. Germany's foreign intelligence chief, Martin Jaeger, warned this week that the confrontation with Russia had entered a more dangerous phase, while German authorities have blamed Moscow for an attempted drone attack at Leipzig airport in August. Britain has been dusting off its own tools for dealing with hostile states. The government has fast-tracked legislation giving the Home Secretary new powers to designate state-backed organizations and proxy groups, while Burnham has asked security chiefs to establish a National Centre for Information Defence to tackle foreign disinformation campaigns. ®
Categories: News

Cheapskates wouldn't pay for security help, got hit by ransomware, and went bust months later

The Register - 13 hours 37 min ago
Welcome back to PWNED, the weekly column where we highlight some of the lowlights in corporate security. This week, we’ll talk about two scenarios, one that ended in tragedy and another that shows the power of a good defense over dedicated phishing attacks. Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request. Both stories come courtesy of Dave Hatter, a cybersecurity and compliance consultant with Intrust IT. In his many years of experience with the company, Hatter has had to work for a variety of small companies that needed help with their security, whether they knew it or not. One time several years ago, the new CFO at a small construction company phoned Intrust and expressed interest in hiring them. However, the proposal was vetoed by the owner of the company, an older gentleman who thought his business was too small to interest hackers and that his existing, one-person IT staff was all he could afford. “We got a guy, my brother’s uncle’s cousin does my IT, don’t need you guys,” Hatter quotes the owner as saying. “We hear this all the time. Thanks for shopping. You’re too expensive.” Three weeks later, Hatter got a call from a local accountant friend who begged him to help a client who'd been hit with a ransomware attack. Hatter said he couldn’t really give more than general guidance, but would talk to the victim anyway. As soon as he called the number, Hatter realized that the ransomware victim was actually the same construction company that had turned down his services a few weeks earlier. The business had an old unpatched Windows server that contained all its most important data. There was a backup drive, but it was connected to the same server, so both devices were encrypted by the ransomware. “Their entire backup is this external drive, which, of course, is now encrypted,” Hatter said. “So, literally, they can't pay their employees. They don't know who owes them money.” Hatter could not help the company, and he never found out whether it paid the ransom. However, the org, which had been around for years, went out of business within months. This sad story shows the importance of having real backups that are off-site or in the cloud and patching whatever servers you have. You can never assume that your company is too small to be attacked because ransomware gangs want your money and they are just as happy to take on small businesses as large ones, which are likely to be harder targets. The other incident involved two companies in the landscaping and construction business. Somebody broke into an executive’s email account at company one and started sending phishing emails to company number two. The miscreants had also set up email filtering rules in the first company’s account so that the messages from the phishing campaign were routed to buried folders where the real-life account holder would never see them. The phishing mails took the form of RFPs (requests for proposal) – a perfect lure, because who wouldn't want new business? They were perfectly crafted, with no grammar errors or obvious tells, and the return address matched company one's. However, instead of attaching the RFP as a PDF or PowerPoint file, it had a button for the user to click to download it. “If I can get in your email and send out emails as you, the recipients, especially if they've interacted with me before, aren't going to have any guard up,” Hatter said. “Especially if there's no crazy language or crazy requests in there because they've got an email from me before.” Upon clicking the download button, the user was transported to a Microsoft 365 login screen that looked identical to the real one but was not on the microsoft.com domain. The user was then invited to put in their email address and password to gain access to the desired file. Because the user had 2FA, this fake page also asked them for their limited-time 2FA code. Behind the scenes, the threat actors were transmitting the login to Microsoft so that Microsoft itself would send an SMS message to the victim at company number two. Then the victim would pass along the one-time passcode via the fake login site. A classic man-in-the-middle attack. It worked, and the threat actors now had access to the Microsoft 365 account and email for the victim at company number two. This could've allowed them to do almost anything using that person’s email. If the victim had access to bank accounts or customer data, the attackers could have initiated password resets from the account, then conducted fraudulent money transfers, or stolen personal information. At the very least, they could've used the victim's account to phish other contacts. Fortunately, Hatter's client had installed a piece of software his company made called TarBot, which runs in the Microsoft 365 environment and uses Entra ID P2 to help customers identify suspicious logins. “It throws off a bunch of telemetry, statistics, metrics, whatever you want to call it, that allows our software to say, this is an anomalous login, revoke the token, and make the user log in again,” Hatter said. He said his company is not the only one to make apps like TarBot that detect suspicious logins. So the bad guys were kicked out after just a few minutes. But Hatter says the better way to stop these attacks is to use phishing-resistant MFA, such as hardware keys (like the YubiKey line) or passkeys. With today’s AI-assisted phishing, telltale signs such as bad grammar or obviously fake login pages are becoming few and far between. ®
Categories: News

Ransomware fixer claimed he could decrypt files, allegedly defrauded clients instead

The Register - 19 hours 22 min ago
The United States Department of Justice has charged a man with fraud after he allegedly told clients he could decrypt files locked up by ransomware but actually paid ransoms – and seemingly got away with it for years. The Feds allege that Zohar Pinhasi – aka “Zack Silver” and “Zack Green” – ran a Florida company called “MonsterCloud” that advised ransomware victims not to pay because it had a way to recover encrypted data. “The charges relate to Pinhasi’s claimed ability to decrypt ransomware without paying cybercriminals, purportedly using ‘proprietary tools’ and ‘advanced decryption techniques' on behalf of distressed business owners who came to his company,” according to a DoJ press release. “In fact, Pinhasi allegedly used a portion of his clients’ fees to pay off the ransomware attackers, and then kept the rest, often extracting a substantial markup.” In one case, Pinhasi allegedly charged his client $150,000, paid the $8,200 ransom, and pocketed the rest – but didn’t admit he had paid the ransom. That scheme allegedly worked so well that Pinhasi charged clients more than $19 million and paid more than $8 million in ransom payments. The DOJ’s indictment [PDF] says MonsterCloud’s website mentions its use of “advanced decryption techniques and cutting-edge technology” – the same language found on this monstercloud.com page. The site also contains this claim: “At MonsterCloud, we are not a team of IT Experts. We are the most sophisticated Counter Cyber Terrorism team in the world.” The indictment suggests MonsterCloud was nothing of the sort, and that its claims rang hollow for years. “MonsterCloud's website included ‘testimonials’ and other promotional content, including from at least one compensated spokesperson,” the indictment states. “In May 2019, one such spokesperson – an individual who had provided a paid testimonial for the MonsterCloud website – contacted the defendant Zohar Pinhasi with questions about Pinhasi’s business practices and truthfulness.” “Among other things, the spokesperson asked Pinhasi whether MonsterCloud actually had any proprietary software that would allow MonsterCloud to decrypt encrypted data. Pinhasi responded: ‘MonsterCloud doesn't hold any proprietary technology [to] decrypt the ransomware data.’” Pinhasi faces two counts of wire fraud, and one of wire fraud conspiracy. He could do twenty years on each count, if convicted. The FBI is investigating this case, and it appears further charges could follow as the indictment states Pinhasi had “multiple co-conspirators, individuals whose identities are both known and unknown to the Grand Jury, including MonsterCloud employees and contractors.” ®
Categories: News

Attackers hijacked top-level domains, minted fake security certs for Google and other orgs

The Register - Wed, 07/10/2026 - 20:38
Imagine going to a Google website at its correct URL, only to be redirected to a crim's illegitimate copy. Attackers hijacked top-level domains, allowing them to alter DNS records and mint fraudulent HTTPS certificates for several Google domains, and those belonging to other organizations. Google said it became aware of the series of attacks last week in the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code top-level namespaces (ccTLDs). “During these hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations,” Google security warned on Tuesday. Google did not say which specific domains or organizations were affected. The attacks did not compromise Google’s systems, and Chrome quickly blocked suspected counterfeit certificates across the affected ccTLDs - meaning Chrome browser users are already protected - according to the Chocolate Factory. “Due to the nature of the attacks, we have no reason to believe the Certification Authorities (CAs) that issued the impacted certificates did anything wrong,” the alert said. These types of attacks allow criminals to impersonate legitimate organizations and websites without triggering any browser security alerts. The attacker controls the traffic routing (via DNS) and the private key associated with the unauthorized certificate, which means they can potentially intercept or modify data sent by users to the impersonated site - and abuse the trusted organization's brand to distribute malware or conduct phishing attacks. “While Chrome took steps during these incidents to identify and block suspected unauthorized certificates across the affected ccTLDs, browser-side intervention should not be relied on to protect your users,” Google warned domain owners. “Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users.” To ensure that their domains and users are protected, Google recommends ongoing monitoring of Certificate Transparency (CT) logs across all of an organization’s domains, including parked or regional ccTLD properties. This provides near real-time alerts whenever someone obtains a certificate for one of your domains. And if you operate a domain in .gh, .sl, or .as, definitely review recent CT log entries for unexpected certificates. Organizations can also publish restrictive Certification Authority Authorization (CAA) DNS records, which allow domain owners to specify which CAs are permitted to issue certificates for their domains. While this won’t stop certificates from being issued during a DNS hijacking attack, it helps safeguard domains after DNS control is restored. Google recommends CAA policies that restrict issuance to specific authorized accounts and validation methods and prevent attackers from using cached validation state to mint new certificates after a hijacking ends.®
Categories: News

AWS launches open-source AI agent sandbox to prevent YOLO mode disasters

The Register - Wed, 07/10/2026 - 18:42
AWS has offered multiple open-source strategies for holding AI agents accountable, and now it’s adding a full-on sandbox to this stack. Dubbed Strands Box, the new solution uses OS-level isolation and some of AWS’ other recent open-source AI control tools to, ostensibly, retain greater control over autonomous AI agents’ behavior. “Agents increasingly run in ‘YOLO mode,’ approving every action without human review,” the AWS team explained in its announcement. “The usual solution to this problem is a sandbox … but access is only part of what we want to control.” The problem with containers and microVMs typically used to isolate AI agents, as AWS explains it, is that their strong isolation doesn’t come with contextual rule enforcement. In other words, when a containerized or virtualized agent gets hold of a tool, there may be no stopping it from doing whatever it wants - like deleting a production database, or gaining access to the internet and doing dog knows what. That’s where the other open-source tools inside Strands Box come in: It uses the Dogwood Local Engine to give the policy engine in Box temporal awareness, so tool calls can be checked against not only what the agent wants to do, but what it’s already done. As one example, AWS noted that an agent could be allowed to post status updates to Slack, but no more than three times every ten minutes to prevent it from spamming its human operators. An AWS spokesperson further explained that Box could be used to control when an agent can perform a Git push, or it could be used to put a cap on API calls that could end up costing a small fortune. Additionally, Strands Box includes Strands Shell and Monty for Python, which expose shell and Python operations to the same Dogwood policy engine and event history, making agentic actions clearer to developers and allowing policies to account for what an agent is trying to do. AWS VP and distinguished engineer Marc Brooker, one of the folks behind Dogwood and Strands Box, explained to The Register that the interpreters are a key part of making agentic behavior more intelligible, which allows for devs to write more precise policies to prevent agents from taking bad actions. “Box’s Shell and Python interpreters expose operations such as file deletions, while its gateways expose API requests and tool calls,” Brooker told us in an email. “Policies can then account for the action being attempted and earlier activity.” Box, Brooker added, enforces those rules without trusting or relying on agents to actually follow instructions, which should ideally prevent them from running roughshod over their operators’ wishes. As for the reason behind AWS’ push to develop open-source tools like Dogwood, the Dogwood Local Engine, and Strands Box, Brooker said that AWS wants to find the right balance between boundaries and policies that prevent agentic AI disasters of the kind we regularly report. “Box enforces the policies developers configure, deterministically, and the agent can't talk its way around these rules,” Brooker explained, though he added that, even with properly configured permissions, an agentic action can still produce an unwanted result. “Developers remain responsible for deciding what access to grant and where human review is needed,” Brooker added - in other words, don’t let your YOLO mode go too YOLO. A bit of human oversight is still necessary. “Agent safety is an area where the industry still has significant work to do, and we're committed to continuing to invest in it, both inside the AWS cloud and in open source,” Brooker said. Strands Box supports any agent or harness one wants to confine within its walls and is available on GitHub now, though only for macOS for the time being. Linux support is in development, and AWS told us a Windows client is “on our radar,” but neither has a planned release date. Deployment to platforms like AgentCore, ECS, and Kubernetes is also planned. ®
Categories: News

US states sue popular kitmaker TP-Link over China risks

The Register - Wed, 07/10/2026 - 18:30
The attorneys general of Florida, Iowa, Montana, and Nebraska have sued ubiquitous networking and smart home tech maker TP-Link, alleging its security claims were misleading and it hadn't properly disclosed ties to China. The company has a large presence in US retail and the tech channel, especially in consumer routers, with stats from Circana asserting it had around 36.6 percent US market share by units and 31 percent by dollars in 2024. The complaint [PDF] accuses California-based TP-Link Systems, whose brand originated in Shenzhen, of deceptive and unfair marketing practices concerning its routers' security and its connections to China. It cites exploitation of TP-Link devices by Chinese and Russian state-backed hackers. The suit also claims TP-Link allegedly concealed facts about its "past and ongoing ties to the People's Republic of China," accuses it of having a supply chain that's reliant on PRC players, repeated firmware vulnerabilities, and being subject to Chinese laws that force companies to cooperate with state intelligence. According to the states' attorneys general, the hardware vendor still relies on Chinese companies for research and development and manufacturing operations, despite previously claiming to have moved into Vietnam after severing ties with China. The complaint alleges that only 0.5 percent of components used at TP-Link's Vietnamese plant, measured by value, are bought in Vietnam, with "all other inputs" imported "from or through China." The complaint also claims that a US-designated Chinese military company carried out construction work at the Vietnamese factory, challenging TP-Link's assurances about its supply chain's security. The complaint cites 2025 testimony [PDF] from former NSA cybersecurity director Rob Joyce that TP-Link's share of the US retail market for Wi-Fi systems and small-office/home-office (SoHo) routers at at least 60 percent. Lawyers pointed to various snippets from TP-Link's marketing materials. These included claims that its HomeShield product "covers all security scenarios" and, on a version of its website available in November 2025, provides a "100 percent safeguard" for network security. The complaint argues that TP-Link's security assurances were misleading because its routers contained critical vulnerabilities. It further cites Joyce's that TP-Link routers were among the brands exploited in the China-linked Volt Typhoon and Flax Typhoon campaigns. The complaint also alleges that TP-Link's privacy policies permit it to collect customer data and share it with affiliates without disclosing how its Chinese connections and China's intelligence laws could expose that information to Chinese intelligence agencies. "Iowans' sensitive data and our national security is at risk because of TP-Link and their connection to the communist Chinese government," said Iowa Attorney General Brenna Bird. "TP-Link tells Iowans its routers are safe, our personal data is secure, and that they have no ties to China. They are not telling the truth. It's time to hold China and China-backed companies accountable." "TP-Link's false statements and deceptive advertising are a violation of Montana law," said Attorney General Austin Knudsen. "As a result of their nefarious practices, millions of Americans have unknowingly invited a foreign adversary into their living rooms and put their personal information at risk. "I will do everything I can as Attorney General to hold TP-Link accountable and protect our privacy and security." Steve Kovsky, corporate affairs officer for TP-Link Systems Inc., said the lawsuits were based on false premises, did nothing to advance national security, and unfairly penalized a US company. Kovsky added that the company has spent months providing officials with clear documentation showing that it is not owned or controlled by any foreign government and that its devices sold in the US are manufactured in Vietnam. "Any claims that our products present a threat to user security or grant unauthorized network access to foreign governments are baseless," he said. "TP-Link Systems is a US company that complies with US privacy and data protection laws. We perform comprehensive security testing and rely on trusted third-party security labs for additional scrutiny to ensure our products meet the highest security standards and are recognized as among the most secure on the market. "We meet or exceed all industry best practices for monitoring and preventing vulnerabilities and actively support our customers to mitigate any issues that occur as they are identified. We do not, and will not, share customer network data with foreign governments or unauthorized third parties. "We stand fully behind the security of our products, the integrity of our company and our people, and our commitment to serving the best interests of our customers in the United States and globally. We look forward to refuting these baseless allegations in court." The allegations echo those made by Texas Attorney General Ken Paxton, whose office sued TP-Link earlier this year over its Chinese connections and router security. US officials began weighing restrictions on TP-Link router sales in 2024. In March 2026, the FCC imposed broader restrictions [PDF] on new foreign-produced router models, barring new equipment authorizations unless an exemption is granted. Previously authorized models were not automatically banned. ®
Categories: News

Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers

The Register - Wed, 07/10/2026 - 17:01
A suspected Italian attacker armed with a malware-controlling poem has infected more than 3,000 servers since April, breaking into enterprise AI infrastructure to mine cryptocurrency and add compromised systems to its growing botnet. This is the first case of “adversarial poetry” - an AI jailbreak technique that turns harmful prompts into poems to trick LLMs into bypassing safety guardrails - that Lumen’s Black Lotus Labs, which has been tracking the PoeLLM malware, has seen in real-world attacks. “This is a first for us,” the researchers told The Register via email. “While we can't get inside the threat actor's head, we think the attacker might have used a poem because it serves as a perfect vehicle for hiding an important message,” they added. “To anyone who comes across it, this is simply a poem on GitHub. It has no links, no files to download, no encrypted text that could easily be flagged as malicious, even by advanced models. There would be no reason for any security researcher to identify this poem as malicious - or know about the IP address hidden within it - unless they had access to the malware referencing it.” PoeLLM malware has been active since at least April, impacting more than 3,000 servers primarily located in the US and Western Europe, and it continues to infect new victims. At its peak, the malware infected more than 800 active servers per day. The malware abuses - and scans for - open source AI systems and services. Most of the victims were running vulnerable, internet-facing versions of LiteLLM and Ollama. Additionally, hundreds of victims were running Gotenberg, a PDF converter, and software development platform Gitea. In addition to these open source tools, the attacker may have targeted commercial software including Ivanti Sentry. The threat hunters first spotted the PoeLLM malware while investigating an Ivanti Sentry vulnerability, CVE-2026-10520. “In early June 2026, a compromised Ivanti Sentry victim contacted a dedicated server at 5.78.73[.]122,” according to a Wednesday report shared with The Register. “Shortly after contacting this C2, the Ivanti Sentry victim began scanning for other vulnerable devices.” How adversarial poetry works Black Lotus Labs attributed the PoeLLM malware to an Italian-speaking criminal, and named the financially motivated campaign Canto Incognito because it hides the malicious commands in a poem posted to a GitHub repository. “Comments within the malware and on the attacker’s GitHub pages are in Italian, and netflow analyzed by Black Lotus Labs suggests that the attacker is located in Italy,” the threat-hunters told us, adding that they believe the campaign targets AI systems and that the poem itself was written by AI. The malware deploys XMRig and Iron miners, and connects victims to Kryptex mining infrastructure. In addition to using compromised GPU hardware powering AI workloads to mine cryptocurrency, PoeLLM also turns victims' machines into vulnerability scanners and exploit servers, which allows the attacker to compromise even more vulnerable systems. The researchers’ investigation indicates that the cryptojacking miscreant - aka GitHub user “ejejejdfbbebe” - made the first GitHub commit with the adversarial poem on April 13. The repo is a fork of the nodejs.org website source code, and the file is called “dash.css.” Inside the file, there’s a poem titled “On the Nature of Connection,” which has been updated 11 times since its initial commit. Here’s the most current version, as of September: In the silent hum of driver, the machines begin to speak, Each pulse of diode threading light through copper veins. we taught the dark to carry meaning, byte by byte — A language built from lightning, cold and clean. Beyond the wall of encryption, a signal finds its way, the tick of distant servers answering back. Data moves like water through the cracks of ordered thought, and somewhere in the code, the world stays on track. Here’s the adversarial piece: the malware finds its current command-and-control (C2) server from keywords in the poem, and when the operator changes the poem, the infected systems find the new C2 location. It does this by parsing the poem, extracting certain words and phrases, and then converting them to numbers using a hard-coded dictionary in the body of the malware. Black Lotus Labs says the logic for C2 discovery works like this: The function “extract_poem_phrase_field” extracts three words/phrases from the body of the poem, case-insensitively: Word 1: text between "In the silent hum of " and "," Word 2: text between "each pulse of " and " threading" Word 3: text between "Beyond the wall of " and "," 0x44a8db–0x44a99b extracts the fourth word differently: Find " of distant servers" Walk backward to the previous whitespace Require the 4 bytes before the word to be "the " Use the word after "the " as Word 4 The four words are then matched to corresponding numbers, which combine to form the IPv4 address hosting the server. Here’s what the C2 conversion looks like with the key: Black Lotus Labs’ write-up lists all the C2 IP addresses, plus when they were first and last seen, so be sure to check that out. More AI infrastructure = larger attack surface As enterprises increasingly use AI in their operations, they also expand their attack surface. And, as we have repeatedly seen, security remains an afterthought in AI deployments. “The Canto Incognito campaign appears to be relatively unique in its targeting of multiple AI-related services,” the researchers told The Register. “Other notable campaigns this year, including the LiteLLM supply chain compromise, focused on a single service and impacted roughly 2,500 victims, according to open sources. The collection of more than 3,000 PoeLLM victims appears to exhibit multiple vulnerable services at any given time.” For comparison: The LiteLLM supply chain attack, which began with a compromised Trivy build, potentially exposed more than 2,500 companies and 434,000 CI/CD pipelines worldwide, according to CloudSEK security researchers. The PoeLLM malware developer “has been extremely successful in identifying vulnerable servers, deploying exploits, and conscripting victims to continue expanding the campaign,” Black Lotus Labs said. “If the actor had only focused on one or two vulnerabilities, the potential victim pool might have quickly dried up, but the expanding scope allowed for a bigger, more powerful (and more profitable) botnet.” They told us they expect to see more of these types of attacks in the near future. “AI makes it easier to deploy tools like LiteLLM, Ollama, or Gotenberg, but AI isn't always checking to make sure those services are patched and protected from attackers,” the researchers said. “As more AI-enabled servers come online, malware like PoeLLM will continue to spread.”®
Categories: News

FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks

The Register - Wed, 07/10/2026 - 11:52
The FBI and US Secret Service (USSS) say criminals using credentials linked to the FortiBleed campaign are locking organizations out of their Fortinet firewalls. The agencies published a joint advisory on Tuesday, citing SOCRadar's verification of more than 86,644 compromised devices across 194 countries. "Based on initial responses, some victims may get locked out of their Fortinet devices if the threat actor either deletes or changes the password for original accounts on the system," their advisory [PDF] states. "During the initial intrusion, threat actors create new accounts not previously on the device. In certain cases, threat actors delete existing accounts to block organizations from accessing affected devices and to maintain persistence on the system while attempting lateral movement within the environment." The campaign targets internet-facing FortiGate firewalls and SSL VPN gateways. Criminals use credentials from earlier breaches and infostealer logs for credential stuffing and password spraying, then extract password hashes from compromised devices and crack them offline using GPU-accelerated clusters. The agencies urged organizations to restrict internet-facing management access, terminate active administrative and VPN sessions, reset passwords, and enable phishing-resistant multi-factor authentication. The advisory also links FortiBleed to ransomware campaigns, saying initial access brokers supplied compromised-network access to ransomware affiliates. The Register previously reported on the connection, identified by SOCRadar. The current evidence points to affiliates working for the INC/Lynx and Payload ransomware groups making use of the credentials, and SOCRadar said in July that it had seen at least 12 confirmed ransomware attacks stemming from FortiBleed. The agencies encouraged victims to report incidents, while noting that organizations were not obliged to provide information in response to this advisory. The FBI and the Secret Service said victim reports could help identify indicators of compromise and warned against paying ransoms. ®
Categories: News

South Korean president calls for creation of tools that stop all cyber-attacks

The Register - Wed, 07/10/2026 - 04:56
South Korean president Lee Jae Myung has told the nation’s cabinet that it’s time to develop AI-powered defensive tools to combat AI-wielding attackers. “Recently, a series of personal information leak incidents have been occurring at financial and public institutions,” he said yesterday – likely referring to incidents like the breach at e-tailer Coupang and last week’s raid on local banks that exposed customer data. “Circumstances indicate that artificial intelligence was utilized, causing great concern and anxiety among the public,” he claimed. “I request that the relevant authorities swiftly and clearly identify the circumstances of these incidents, and rapidly deploy and concentrate the necessary personnel and resources to minimize damage,” he added, before calling for South Korea’s government to “build security capabilities that can detect attacks in advance and preemptively block them.” “I urge the relevant ministries to quickly inspect the security systems across the entire national core infrastructure, as well as the private sector, and immediately implement any necessary security measures,” he continued. “I hope we can accelerate the development and distribution of AI technologies specifically tailored for cybersecurity.” President Lee thinks South Korea needs to “completely innovate our society's security paradigm to fit the AI era.” That work will involve public and private sector players collaborating “to transform our technology, systems, and awareness.” The remarks amount to a major policy statement, and a very public one at that. South Korean ministers and tech giants now get to turn the president’s words into action, a complex task given the broad scope of the leader’s demands and the fact that nobody thinks it's possible to defeat cybercrime. Meanwhile, Down Under Also yesterday, Australian politicians had their chance to grill OpenAI Chief Strategy Officer Jason Kwon, who fronted a parliamentary committee to answer questions about how his company’s agents accessed a government medical records website. Kwon allowed that OpenAI should have done better than emailing the abuse reporting email address at the relevant Australian government agency but defended the company’s efforts to learn from the Hugging Face incident. The committee is sitting for another two days this week, with one topic of debate being how or if Australia should tweak its copyright laws to ensure AI companies pay content creators whose works they use when training their models. Australian law doesn’t include a fair use provision like those that AI companies in the USA relied on when sourcing content. Creators fear a rumored opt-in payments scheme will be too weak, but Australia’s government fears it may miss out on big datacenter investments and access to onshore frontier models if it doesn’t change copyright law to make it more AI-friendly. ®
Categories: News

Anthropic reconfigures its cool kids security program

The Register - Wed, 07/10/2026 - 00:29
Only a week after warning about the perils of competitor Z.ai's GLM-5.3 model and its advanced cybersecurity capabilities, Anthropic has expanded its Cyber Verification Program (CVP) – or rather, reconfigured it. "For the past six months, we’ve enabled trusted access through two programs: Project Glasswing and the CVP," the AI biz said. "Now, we’re integrating these programs into one expanded offering, designed to give more security organizations access to the capabilities they need to protect their systems." Project Glasswing and CVP launched in April 2026 alongside the debut of Mythos, the company's highly capable and equally hyped frontier model. Project Glasswing gave partners early access to Mythos so they could scour their systems for vulnerabilities before attackers beat them to it. VulnCheck researcher Patrick Garrity was not particularly impressed with CVEs identified by Project Glasswing, noting that fewer than 0.5 percent of the 225 Anthropic-linked vulnerabilities he tracked were being exploited in the wild. And Anthropic's own warning last month about the risks posed by GLM-5.3 somewhat undermines the idea that there's anything special about its own Mythos model. Even so, Anthropic says that its security program has allowed its partners to spot at least 129,000 verified software vulnerabilities between April and July 2026. And the biz claims that its own open source scanning efforts revealed an additional 5,500 verified vulnerabilities between April and October. "Of these verified vulnerabilities, more than 33,000 have so far been rated as critical- or high-severity," Anthropic said. "This is likely an undercount, as it is based on survey data from only a subset of Glasswing partners. As such, we expect the true impact to be at least five times higher." When these might get patched is unclear. The company's own figures indicate that of 5,674 true positive vulnerabilities, 3,014 are high severity, and 1,522 are critical severity, yet only 516 have been patched. Given industry boasting about the cybersecurity prowess of AI models, generating a fix, testing it, and deploying it ought to be nearly automatic at this point. But the gap between identification and remediation suggests there's a lot of slack in the system that needs to be ironed out. Two programs into one with three tiers Now Anthropic's two programs, one intended for organizations and one for individual security professionals, have been merged and reconfigured into three tiers. The AI biz has not explained why, but its stated intent is to tie model capabilities to specific tasks: Defense Access, Red Team Access, and Specialized Access. Depending on the tier, participants will encounter more or fewer blocks on security-related tasks. As a measure of program participation value, Anthropic said that based on five attempts at 10 CyScenarioBench challenges, those without CVP access got blocked on every attempt. Defense Access is intended for security teams at companies, nonprofits, universities, and government organizations that focus on system defense. In this tier, Claude Opus 5.5 faced refusals in 46 of 50 attempts and succeeded four times. Red Team Access is for penetration testing and offensive cyber evaluation, and participants will still face model refusals for model interactions that would cause physical harm or mass disruption. Specifically, Claude Opus 5.5 completed 34 of the 50 tasks with Red Team Access safeguards enabled, a rate similar to what would be expected from Specialized Access. Specialized Access sounds like a rebranding of Glasswing – it's "reserved for a limited set of verified organizations that are authorized to test safety systems that could impact people’s lives or disrupt markets, such as flight operating systems, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks." Those granted admission to this exclusive tier will face the fewest model refusals, not counting anyone using abliterated open-weight models that have had their guardrails suppressed. For the next month or two, program participants will need to allow their data to be retained by Anthropic as part of its AI safety requirements. But soonish, the company's Enterprise Frontier Safeguards program will offer zero data retention. Organizations already granted zero data retention while using Claude Fable 5.1 or Claude Mythos 5.1 can participate in CVP under those same terms.®
Categories: News

Trump Mobile customers' data dumped - and some never even received their gold device

The Register - Tue, 06/10/2026 - 18:32
If you signed up for Trump Mobile, you may be part of an exclusive club of … ransomware victims. Criminals called BYOD claim to have broken into the Trump-branded mobile biz and leaked data belonging to 3,615 people, including names, email addresses, phone numbers, home addresses, and order details. BYOD is a new ransomware-as-a-service operation, and Trump Mobile is only the third organization posted on its data-leak site. According to the group’s posted claim, after telling Trump Mobile that it had been breached, the wireless provider replied: “We have no team to handle this" and “Anyone who hacks them are a terrorist.” “Well unfortunately for them, all 3615 customers and their PII, alongside telecom details are now up for grabs,” the leak site says. “Feel free to take a gander at it yourself, don't be shy, we (and them) certainly aren't stopping you.” The hackers reportedly told International Cyber Digest that they first infected a Liberty Mobile employee with an infostealer, and then accessed Trump Mobile via the MVNO. BYOD claims to still have access to Trump Mobile’s systems, and told the publication that neither wireless provider used any form of multi-factor authentication. Neither the Trump Organization nor Liberty Mobile responded to The Register’s questions about the breach. The data dump doesn’t include any details about US President Donald Trump or his family members, according to Straight Arrow News, which first reported the breach and verified some customers’ information. This could mean that the Trump family doesn’t eat its own dogfood. The leak does, however, include personal information about Eric Brunnett, vice president and chief information officer for the Trump Organization. Brunnett’s LinkedIn profile says he oversees “all Information Technology and Information Security for all aspects of the Trump Organization.” Additionally, one customer contacted by Straight Arrow said he paid a $100 pre-order deposit last year for Trump Mobile’s flagship smartphone, the T1, but never received a gold-colored device. Another criminal group, EndZone, also claimed to have breached Trump Mobile and leaked a stolen dataset a week before BYOD’s post in what “appears to be the same original breach,” according to security sleuth Dominic Alvieri. These aren’t the fledgling mobile phone company's only security snafus. Before these two apparent breaches, a security researcher in May claimed he discovered a now-plugged website vulnerability that leaked Trump Mobile customers’ details. The individual behind the discovery, who goes by "Louis" and described himself as "just a nerd between jobs with too much time on my hands," previously told The Register that the website’s data could be scooped up with a simple POST request.®
Categories: News

Microsoft extends the Outlook naughty step with two more file types

The Register - Tue, 06/10/2026 - 16:06
Microsoft is adding two extra file types to its Outlook block list to strengthen security. The file types are .msix and .msixbundle, used for Windows application packages and bundles. The change affects New Outlook for Windows and Outlook on the Web in Exchange Online. By default, users of the affected clients will no longer be able to download or open attachments with these extensions, which is no bad thing because blindly installing a malicious .msix package could compromise a device. That said, although Microsoft noted that the file types were "infrequently used," there are legitimate reasons for their presence in emails. Administrators who need to permit these attachments can add the extensions to the AllowedFileTypes property of the relevant OwaMailboxPolicy before the rollout, scheduled for early to mid-November 2026. "This update is part of our ongoing efforts to strengthen security and help protect organizations from potentially unsafe file attachments," Microsoft said. The Windows giant's application packaging system has come under fire over the years. Microsoft disabled the ms-appinstaller protocol handler by default in December 2023 after attackers abused it to distribute malware. The attachment block adds another layer of protection, unless administrators explicitly allow these file types. Other file types blocked by Outlook on the Web include .py Python files, .ps1 PowerShell files, and .cab files. It's a little surprising that it has taken until now for .msix and .msixbundle to be added to the list, considering the havoc malicious packages can wreak on a system. Renaming an attachment's extension or sending a download link may get around the attachment restriction, but neither makes the package safe. Persuading someone to download and install it remains a route for miscreants, even with Windows' other protections in place. ®
Categories: News

Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets

The Register - Tue, 06/10/2026 - 14:00
GitHub Copilot CLI may reveal developer secrets if it comes across instructions that tell it to do so, depending on the underlying model. The coding agent tool was flagged earlier this year for being susceptible to indirect prompt injection. That's when a model ingests text from a source other than the user that directs it to take some action outside the scope of its intended function. This is more of the same, with a twist. According to security researchers at Adversa AI, GitHub Copilot CLI suffers from the same vulnerability identified in Grok two months ago: Cryptographic Context Injection (CCI). Imagine a GitHub Copilot CLI user is working on a project and running the agent in autopilot mode. In other agentic coding tools like Anthropic's Claude, that's the default, but it remains optional for GitHub Copilot CLI. Given that condition, the next requirement is for the CLI tool to read a web page with a malicious set of instructions that have been encrypted with a private key published on the same site. "Static guardrails read text; they do not run it," explained Rony Utevsky in a blog post provided to The Register. "CCI ships malicious instructions as strong ciphertext, along with the key material and an instruction to decrypt, and induces the agent to run that decryption in its own code execution runtime." Active content classifiers that might be reading ingested text as a model defense would miss the encrypted code, unlike encodings like base64 or substitution ciphers that can be undone because the model learned how to decode in training. The model lottery The attack chain goes like this: The user runs Copilot CLI and asks it to fetch a specific URL. The page contains encrypted content, decryption instructions calling for use of Python, and two possible decryption keys. The first key is fake. It's a template that the agent tries to build by reading targeted files from disk (e.g., the user's .env file). Those secrets then get added to the key string. The initial decryption is attempted with this phony key but fails. So the second key is tried, the decryption works, and the agent is presented with instructions to fetch another URL for more context – but that URL contains the harvested secrets and the network request transmits them to the attacker. This doesn't work all the time, however. It depends on the model, which isn't always obvious to the user. GitHub Copilot CLI currently uses either Microsoft's own model, mai-code-1.1-flash, which executed the full attack chain on 50 percent of attempts, or one of two OpenAI GPT-5.6 models, both of which refused the attack payload. Utevsky describes the situation as a model lottery. "On the paid account we tested, the vulnerable model was not the default and had to be selected by hand," said Utevsky. "But on an account with model selection left on Auto, the router assigned the vulnerable model on some sessions and a safe one on others, with no action by the user away from defaults. The user does not choose, and does not see, which model handled the session." Adversa says it reported the vulnerability through GitHub's bug bounty program on September 17, 2026, and GitHub's triage team validated the finding but declined to treat it as a vulnerability. A GitHub spokesperson said as much to The Register, arguing that the user's actions amounted to consent for what followed: "GitHub values the contributions of our security research community and is committed to investigating reported security issues. After investigating, we determined this requires a user to intentionally direct Copilot CLI to fetch attacker-controlled or untrusted content and confirm they want to trigger the action, and thus is not a product vulnerability. While this is not a security issue with the product itself, we are always looking for opportunities to improve our products." Adversa disagrees with that call and says the attack chain presently works as described. ®
Categories: News

Asos app delivers a data leak threat instead of fast fashion

The Register - Tue, 06/10/2026 - 12:51
Asos customers have reported receiving a rogue app notification claiming the online clothing retailer's Snowflake instance has been compromised and threatening to leak data. The notification included a link to a Telegram channel named "Xuanye Wen Gateway" and addressed Asos's data protection officer and IT team. "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it," it says. The Register has asked Asos and Snowflake to comment. The notification does not, by itself, establish that the sender accessed Asos's Snowflake instance or sensitive customer data. How the message was sent remains unclear. Asos's share price fell by around 12 percent following reports of the notification, although it has recovered slightly since. Customers of Snowflake, a cloud platform for storing and analyzing data, were targeted in a major data theft campaign in 2024, including Ticketmaster, Santander, AT&T, and dozens of others. Connor Riley Moucka, 26, of Kitchener, Ontario, later pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy charges over a hacking spree that compromised more than 165 organizations, exposed billions of customer records, and brought in about $2.5 million in ransom payments. Snowflake subsequently introduced controls allowing administrators to require multi-factor authentication. ®
Categories: News

Denmark's ID register spills more people's details than the country has residents

The Register - Tue, 06/10/2026 - 12:46
An unauthorized party abused a private Danish company's legitimate access to the country's Central Population Register (CPR), exposing names, addresses, identification numbers, and other personal information about approximately 8.8 million people. The CPR administration said in a statement [PDF] that it became aware on October 2 of irregular activity during September and established the scale of the breach over the weekend. In a TV interview last night, digitization minister Christina Egelund said it was too soon to say whether the country would issue all-new CPR numbers, one of the solutions proposed following the breach. Danish cybersecurity specialist Jan Kaastrup told TV 2 that treating CPR numbers as secrets was a "broken" approach and argued that a number alone should not be accepted as proof of identity. "We live in a digitalized society, and therefore we should have much better identification systems," he said. Egelund described the company whose access was abused as "small." Private businesses can obtain CPR data under section 38(1) of the Danish Civil Registration System Act, subject to restrictions set out in the ministry's access terms [PDF]. Eligible recipients include companies, foundations, other legal entities, and individuals conducting business. However, access concerns a defined group of people identified individually in advance, and recipients must be legally entitled to process the information under the GDPR and Danish data protection law. The Register asked the ministry why such broad access was given. CPR numbers underpin access to public services and many everyday transactions in Denmark, which has a population of around 6 million people. The database includes the information of over 55,000 people living in Greenland who also use CPR numbers for healthcare, tax services, and banking. The ministry said the register contains approximately 11 million records, including people who have died or moved abroad, which explains why the affected total exceeds Denmark's current population. The ministry also noted that names and addresses of persons who chose to register with name and address protection were not exposed. The CPR administration blocked the unnamed company's access and said it was working with specialists and relevant authorities to establish what happened. It has notified the Danish Data Protection Agency, and police are investigating. ®
Categories: News

Atlassian warns of critical file access flaw in its datacenter products

The Register - Tue, 06/10/2026 - 05:20
Atlassian has told its users to patch its datacenter products, pronto, to prevent attackers accessing their files. The Australian collaborationware company on Monday sent users an email that opens with the words “Action required” and points to a security bulletin that explains CVE-2026-21589. The 9.3-rated arbitrary file access vulnerability is present in the datacenter versions of its Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, and Fisheye products. Atlassian says the vulnerability “allows an unauthenticated attacker to access specific files within the web application root directory in affected versions.” That’s scary because Atlassian warns “In some configurations, there may be sensitive files present that increase your risk.” There’s also some good news in that attackers must know the exact filename and path to exploit the vulnerability, and the mess doesn’t allow anyone to see the contents of a directory. Another piece of good news is that Atlassian has updated its products – so users only need to find a change window in which to upgrade to a safe version of their software. Atlassian advised those who can’t patch ASAP to remove their instances from the internet, if possible. “Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can take action,” the company warned. Its advisory also includes mitigations and advice on how to determine if your instances need the fix. Users who made the move from datacenter products to the Atlassian cloud have nothing to do, as Atlassian fixed the flaws in its own SaaS. That state of affairs rather vindicates Atlassian’s 2020 decision to stop developing its low-end server products and require users to shift into its cloud, and last year’s sequel in which it decided to discontinue its datacenter software, too. Atlassian admitted it hasn’t made that migration easy, because it somehow released a lift and shift tool that was worse than an earlier version. In March 2026, Atlassian axed ten percent of staff. The company’s share price was on a year-long slide at the time, as pundits suggested it might fall victim to the SaaSPocalypse, a theory that AI would replace business software. The price of Atlassian scrip has tripled since then, suggesting investors are more confident the company’s plan to use AI to power workflows represents a moat LLMs cannot cross. ®
Categories: News

Security researcher claims to they found KVM guest-host escape flaw

The Register - Tue, 06/10/2026 - 03:06
Linux KVM, the hypervisor favoured by hyperscale clouds, apparently has a full VM escape bug. That nasty news came from security researcher Paulos Yibelo, who on X shared a screenshot of a bug bounty award he won for discovering what he described as “Full VM escape zeroday (guest>host root in industry standard hypervisors)!” The bug bounty Yibelo participated in is run by Vercel, a company that provides MicroVMs as sandboxes for AI agents to work inside. The company’s Sandbox uses Firecracker MicroVMs, a technology created by AWS, which relies on Linux KVM – the kernel level hypervisor in Linux. Vercel CEO Guillermo Rauch named KVM as the hypervisor identified by Yibelo. “We’ve confirmed a KVM 0day through our Vercel Sandbox bounty program. Affecting the industry’s gold standard solution for Linux virtualization,” he wrote. And that’s all the info that has made it into the public view at this time. The Register can find no chat on relevant mailing lists. We have asked Rauch and Yibelo for additional details. Hopefully, we don’t hear from either of them for days or weeks, for two reasons. One is that guest-host escapes are the nightmare virtualization scenario because they mean whoever runs a guest VM could take over an entire server, and perhaps gain the ability to control other guests. The other is that KVM is astoundingly prevalent: AWS and Google both use it to power their public clouds. Enterprise virtualization players Nutanix, HPE, and Proxmox also rely on KVM. And of course KVM is also in Firecracker, which is open source and could therefore be running in all sorts of places. Whatever Yibelo discovered therefore very much needs a responsible disclosure process, because if hints about the flaw emerge it could allow attackers to do a lot of damage. Once a fix is found, the next question is whether implementing it will require disruption or downtime. It’s possible to hot-patch KVM, and to migrate live VMs from vulnerable hosts to machines running a patched version of Linux. Hopefully those techniques will work. This might be the second nasty bug discovered in KVM this year, after the so-called Januscape flaw. Beyond the potential risks this bug created, observers have suggested the potential seriousness of the flaw means Yibelo’s reward should exceed the $50,000 available under Vercel’s bug bounty program. ®
Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News