News
Someone's attacking a critical 0-day RCE in F5 BIG-IP APM
F5 has fixed a critical zero-day bug in its BIG-IP Access Policy Manager (APM) that unknown miscreants are exploiting to remotely execute malicious code. BIG-IP APM is a centralized access management and security proxy that allows users to connect to enterprise networks, applications, APIs, and cloud services via a single login. The flaw, tracked as CVE-2026-94127, is a heap-based buffer overflow that affects BIG-IP APM systems configured as an OAuth Authorization Server, with an access policy and OAuth profile on the same virtual server. It received a critical 9.3 CVSS v4.0 score - so patch now. “We have learned that this vulnerability has been exploited,” F5 said in a Tuesday security advisory. F5 did not immediately respond to our questions, including how many systems have been compromised, and whether criminals are abusing the vulnerability to deploy ransomware. Also on Tuesday, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog, and gave federal agencies a Friday deadline to apply patches. This warning comes about a year after F5 and CISA warned “highly sophisticated nation-state" hackers broke into the vendor’s network and stole BIG-IP source code, zero-day vulnerability details, and customer configuration data belonging to some users. The attack posed an "imminent risk" to federal agencies, US cybersecurity officials said at the time. The US Justice Department allowed F5 to delay disclosing the intrusion after determining that delayed public disclosure was warranted. This only happens if public disclosure poses a substantial risk to national security or public safety. Neither the feds nor private researchers have publicly attributed the intrusion to a particular group or country, but a year earlier Google's Mandiant threat hunters linked exploitation of the critical F5 BIG-IP flaw CVE-2023-46747 to UNC5174, an access broker it assessed with moderate confidence as operating from China. The group attempted to sell access to US defense contractor appliances and UK government entities.®
Categories: News
Academic publisher Elsevier hit by LAPSUS$ redirect attack
Academic publishing giant Elsevier confirmed a compromise this week after students found its platform redirecting users to a cybercriminal crew's leak page. One Reddit user, a self-described nursing student, highlighted the issue on September 22, posting a screenshot of LAPSUS$’s leak site after trying to access “homework and textbooks.” “Every time I try to open the Elsevier website, I am met with this,” they wrote. “Anyone know anything or have any explanation? Totally creepy.” Amsterdam-based Elsevier told The Register it was briefly compromised following an attack Monday, but played down the wider impact. “On September 21, Elsevier identified that visitors to select platforms were being redirected to a third-party page,” a spokesperson said. “Our cybersecurity team responded immediately, resolving the issue and restoring normal service. “Our investigation indicates that this was a narrowly scoped, limited-duration event involving the temporary redirection of traffic for certain web properties. There is no indication that core platforms, customer data, research content, or operational systems were compromised.” Elsevier did not respond to additional questions related to the specific platforms that were affected or for how long LAPSUS$’ redirect was in place. The company is best known for its ScienceDirect platform, which hosts scientific, technical, and medical journal articles. It is also behind ClinicalKey, an AI-powered platform designed to provide medical professionals fast answers to care queries, and LeapSpace – an AI-assisted workspace for academic researchers. LAPSUS$, meanwhile, is better known for its criminal enterprises, namely big-name cyberattacks on the likes of Rockstar Games, which led to the earliest high-profile Grand Theft Auto VI leaks, and more recently, attacks on Adidas and GitHub. The online assault on Rockstar Games was part of a wider spree of crimes carried out when the group was in its pomp between 2020 and 2022. Other victims included BT, Microsoft, Okta, Samsung, and Vodafone, which in turn stoked a concentrated law enforcement operation to disrupt the teenage criminals behind it. After a protracted break, the LAPSUS$ name returned in 2025, partnering with Scattered Spider and ShinyHunters in another string of cyberattacks affecting household names, before splitting up and activity dropping to a modest six attacks per month, according to SOCRadar. ®
Categories: News
Closing the observability gap for the AI-ready enterprise
The modern enterprise is a digital enterprise. From the back office to the factory floor, connected systems and digital services form the operational backbone on which all else depends. So when disruption hits, it can have a huge financial, reputational, productivity, and even compliance impact. This has raised observability to a board-level issue. "For a public company, a material cyber incident is a disclosure obligation. You're on a four-business-day clock from the moment you determine its material," explains NETSCOUT director of enterprise strategy, Jack Callahan. "So when you have a disruption, whether that's a cyber-attack, a DDoS attack, or someone pushing a bad update to the network, the first executive problem is the same: figuring out whether it’s material." With each technical team pointing fingers at each other, observability becomes the single source of truth that organizations need to identify root cause, accelerate resolution, and improve reliability. Yet in many enterprises, it’s not having the desired impact. The long-established data foundation of metrics, events, logs, and traces (MELT) can’t by itself keep pace with the complexity and scale of today’s digital infrastructure. Organizations have defaulted to gathering more data, increasing sampling, and extending retention. But they’re not getting better insight. “Executives who would expect to have a lot of data in front of them with which to make a decision don't always find that that data is as conclusive as they'd want it to be,” Callahan continues. “And therefore, they’re trusting their gut more than they’d expect, given how much they’re spending.” The costs of this observability debt are building. One study by NETSCOUT reveals that 81 percent of organizations believe insufficient data increases incident resolution time. Over two-fifths (42 percent) estimate downtime at $500,000 to$999,000 per hour. These costs are unsustainable, both economically and otherwise. To harness the power of autonomous AI in operations, organizations need a data foundation they can trust implicitly. This demands a fresh approach; economically viable and grounded in observability data that’s consistent, comprehensive, enriched, and real time. And delivered in a way that complements rather than replaces existing observability investments — extending the value of the platforms already embedded in the enterprise stack. Where visibility fails MELT data is still essential to observability. But it wasn’t designed for today’s complex, distributed and dynamic operations. Metrics explain that something has changed over time. Events surface when something changed. Logs tell teams that something happened at a specific time. But they don’t provide the context that explains what actually happened on a network and why. Traces come closest, as distributed tracing is built to follow a request across services. But a trace only shows what has been instrumented, which leaves it blind at un-instrumented components, third-party dependencies, and the infrastructure in between. And those are exactly where things tend to break down, meaning the context of what actually happened and why isn’t captured. Context essentially means being able to reconstruct a single, complete and ordered chain of events across different systems — including what kick-started an event, how it propagated, and what happened at each step. This is where MELT-only observability techniques often fail. Timestamps can be inconsistent across different systems. Identifiers might not be preserved across architectural boundaries. Sampling and aggregation remove vital detail needed for reconstruction. And data may be stored across different tools with incompatible schemas. Research reveals that 96 percent of organizations use metrics and logs, yet 82 percent report visibility gaps, and nearly all (96 percent) lack sufficient data to determine root cause during incidents. They tend to lose visibility where systems meet, such as between on-premises and cloud (58 percent), the edge (51 percent), or in service-to-service interactions (39 percent). AI sharpens the challenge These issues become more serious in an AI context. Organizations are already embracing AI-driven operations to improve efficiency, decision making and customer experiences. But when systems start operating autonomously, making decisions and taking action at machine speed, they need forensic-grade data with high-fidelity context to produce reliable outcomes. That means continuous, unsampled records that preserve system interactions across environments. Higher levels of autonomy demand higher levels of confidence in network data. But telemetry can lose fidelity through sampling and abstraction — common techniques used in MELT to manage high data volumes. The resulting incomplete and fragmented data can lead to false correlation, ambiguity over root cause, inconsistent outputs, and overconfidence in partial signals. “An agent is not going to apply human intelligence to troubleshoot an issue. It's going to make a decision based on the data it has,” says Callahan. “So if you are feeding it partial, or periodic, or sampled data, you're at risk of scaling that uncertainty really quickly.” It’s a challenge that many organizations are just waking up to. According to NETSCOUT, only 41 percent describe AI-assisted insights as “very or extremely consistent.” A similar share (38 percent) admits to lacking forensic-grade data to validate automated actions. Some 29 percent say they don’t have real-time visibility across environments, and 28 percent don’t fully trust automation output. Closing the observability gap A better approach would be to build observability around MELT data enriched to provide the context that IT teams need, but without the bloat that adds unsustainable extra cost. This starts with packet data: the authoritative record of what actually traversed the network. It provides visibility into the transactions, dependencies and interactions (human and machine-based) across the IT ecosystem. Using deep packet inspection (DPI) techniques, this visibility can be distilled into metadata that, added to MELT, produces what NETSCOUT calls “MELT+”. “Digital services become observable through the exchanges among their components. NETSCOUT Smart Data transforms those observed interactions into transaction-level evidence: whether communication succeeded, how the transaction performed, where delay or failure appeared, which services were affected and, when identity context is available, which users experienced the impact. That gives operations teams and AI systems a more complete and trustworthy basis for understanding what actually happened,” explains NETSCOUT field marketing manager , Steve Horneman. “Most telemetry describes the state of individual components. NETSCOUT observes the interactions among those components and creates meaning from them as the activity occurs. By extracting context early, from independently observed traffic rather than relying only on what individual systems report, we give operations platforms and AI a more consistent account of how a digital service actually behaved. That is the difference between collecting more telemetry and creating evidence that can support a confident decision.” One case illustrates the advantage of this approach. A product manufacturer found that wireless connectivity issues were causing automated guided vehicles (AGVs) to fail in its global facilities, costing the company $500,000 per hour in lost productivity. Outages were occurring roughly every three weeks. Existing robotics telemetry failed to find the root cause. But once NETSCOUT was pulled in, the source of the issue was pinpointed, and a proactive monitoring model adopted which detects AGV failures within seconds. Troubleshooting fell from hours to minutes, saving the company tens of millions of dollars annually. The benefits of MELT+ expand beyond outages and operational incidents to cybersecurity, Horneman continues. “The strategic value extends beyond observability. The same independently observed interaction evidence can support operational assurance at the enterprise perimeter, expose service-to-service behavior and potential lateral movement internally, and give operations, security, and AI systems a common evidentiary foundation. Instead of each team interpreting a different version of events, they can reason from the same observed reality,” he says. NETSCOUT calculates that organizations treating network traffic data as authoritative are nearly three times more likely to report that visibility gaps occur infrequently (50 percent vs.18 percent). It is this level of insight into what’s happening on the network that makes the same packet-derived intelligence valuable to forensic analysis teams. “Once an attacker has privilege on a host, the telemetry that host generates about itself is within reach,,” says Callahan. “Sophisticated attackers hide lateral movement exactly that way. What they can't do is go back and change the packets that already crossed the network. That's a higher level of veracity, and a more complete view.” When metadata is Smart Data NETSCOUT’s approach uses DPI to observe live, unsampled packets directly from the network and then convert it into high-fidelity metadata using Adaptive Service Intelligence (ASI). It’s designed to tackle the main challenges of traditional MELT: scale, efficiency, cost, and data richness. NETSCOUT observes traffic from strategic points in the network rather than monitoring each application or server, reducing telemetry volume, ingestion cost, and complexity. It analyzes and distills packet data into Smart Data, metadata generated at the point of capture, which reduces the volume that needs to be moved, stored or retained downstream. What customers get is an approach that is complementary to MELT but which is economically more sustainable, produces more complete, network-derived data, and which feeds into existing observability platforms to further reduce TCO. It also delivers what analyst firm Futurum describes as the critical foundation for autonomous AI operations. Data that captures verifiable network behavior and observed interactions rather than abstractions. Data that ensures comprehensive visibility regardless of whether individual applications have been instrumented, and a complete view without sampling gaps. And which is consistent across observability, security, and operations teams, while demonstrating sequence and causality across service boundaries. “MELT alone is not going to be a sufficient data foundation to run AIOps on,” says Callahan. “We're able to generate data with more of the context you need earlier in the process, and therefore richer data flows into your platforms.” Just getting started Despite the obvious benefits of MELT+ approaches, NETSCOUT data reveals that only 11 percent of organizations treat full-fidelity network data as authoritative. For CIOs keen to change that statistic, the first step is to evaluate their current observability data by five key criteria, as shared by NETSCOUT COO, Sanjay Munshi. It should be comprehensive; covering any cloud, service, app, network or vendor. It should be curated; with purpose-built feeds optimized for storage and cost. It must be credible in offering a verifiable chain of interactions showing how services, apps and users behave in context. It must be consistent across use cases. And it must provide continuous real-time insight into data in motion. “If you’ve been optimizing to reduce your MELT cost, what you’ve been doing is also reducing the context that your application teams and agents have. But you no longer have to sacrifice one in order to gain the other,” Callahan concludes. “If you’re worried about telemetry costs. If you're worried about having the data you need to make decisions in the moment or for compliance reporting. If you're trying to figure out how to move your AI pilots into production: we can strengthen what you are already doing in the platforms you use every day.” Sponsored by NETSCOUT
Categories: News
Ofcom takes a hard look at Pornhub's Apple-powered age checks
Ofcom has opened an investigation into whether Pornhub's Apple-based age checks are effective enough to keep children away from its adult content. The investigation will examine whether Pornhub owner Aylo complied with age assurance duties that came into force under the Online Safety Act (OSA) in July 2025. Pornhub introduced a new age assurance process for some UK users in May 2026, relying on signals supplied by Apple. The signals indicate that an iOS user may have completed Apple's age checks. Ofcom stressed that its investigation concerns how Aylo implemented and tested the resulting process, not how Apple operates its system. Aylo restricted Pornhub to new UK users on February 2 after arguing that the OSA had diverted visitors toward less regulated sites rather than protecting children. Existing users who had already verified their age retained access. The decision followed a steep decline in traffic: Pornhub's UK visits fell 47 percent shortly after the rules took effect and were reportedly down 77 percent by October. In May, Aylo partially reversed the restriction for eligible UK users who had confirmed their age through Apple. New users on Android, PCs, and other platforms remain locked out. The Register contacted Aylo for comment. "Online age checks are a vital protection to prevent children from encountering inappropriate or harmful material, including pornography," said George Lusty, director of enforcement at Ofcom. "We expect tech firms to ensure age checks are highly effective before introducing them. Anything less could leave children at risk." Ofcom will assess both the effectiveness of Pornhub's age assurance process and whether Aylo conducted sufficient testing and due diligence before deploying it. Services covered by the OSA must assess whether children are likely to access them. Ofcom says providers must revisit that assessment before making a significant change to their service or when evidence suggests their age checks have become less effective. Ofcom will gather evidence before deciding whether Aylo breached the OSA. If it provisionally finds a contravention, it must give the company an opportunity to respond before reaching a final decision. The regulator can close an investigation without further action or impose a fine of up to £18 million or 10 percent of qualifying worldwide revenue, whichever is greater. Ofcom can also order companies to remedy failures and, in serious cases of continuing noncompliance, ask a court to require third parties such as ISPs to restrict access to a service. Some failures involving information requests can expose senior managers to criminal liability. Ofcom under the cosh The watchdog has faced a battering in recent weeks, with senior politicians and other key officials criticizing its alleged inaction since the Online Safety Act's age assurance requirements kicked in last year. As part of the Lords Communications and Digital Committee's multi-day inquiry into the OSA's impact, Dame Rachel de Souza, England's Children's Commissioner, said earlier this month that children believe the legislation "has made absolutely no difference" in preventing access to online harms. De Souza further claimed that Ofcom had failed to bare its regulatory teeth and accused UK politicians of failing to give it sufficient power. Ofcom would argue the opposite, and did the following week. At a subsequent hearing, Ofcom enforcement director Suzanne Cater pointed to actions taken by the regulator against Telegram, TikTok, X, and other pornography companies. Cater also told peers that the regulator is gearing up to target larger companies now that many of the straightforward cases involving smaller companies are concluding. Cater and her colleagues nevertheless acknowledged limits to Ofcom's reach, particularly when companies operating from overseas have few UK assets against which fines can be enforced. ®
Categories: News
Why security belongs in the network
Every attack leaves a trail across the network, from initial reconnaissance to lateral movement and data exfiltration. That makes the network one of an organization’s richest sources of security intelligence. But visibility is only half the story. Because the network connects every user, device, application, and workload, it is also the natural place to verify identity, apply consistent policy, and contain suspicious activity close to its source. The result is faster detection, stronger enforcement, and a smaller blast radius. So, what does it take to make security an integral part of the network, and where should organizations begin? What is integrated network security? Integrated network security takes security functions that traditionally sat outside the network and embeds them directly into the network fabric to simplify and sharpen protection in the enterprise. Routers, switches, and access points become cybersecurity defenders that identify and prevent threats rather than simply routing and filtering traffic. What challenges does enterprise security face today? Enterprises face a gap as the network perimeter dissolves. The assets that used to reside inside the headquarters LAN have scattered everywhere, from the cloud through to edge-based equipment and on-premises servers. Bolting more security tools onto your infrastructure to protect those assets isn't sustainable. License costs increase, tools overlap and sometimes conflict with each other, or they leave non-obvious gaps through which attackers can pass. This fragmented approach to security also involves different teams working at different speeds. Coordination is slow and difficult, hindering the security effort and driving up costs. Why is integrating security into the network the answer? Unifying security and networking together offers several benefits: Standardization Building security directly into the network itself lets you encode a standard approach that works everywhere across the organization and covers everything that connects to the network, (so, in other words, everything you use). This means that you can apply the same policy across the entire network, maintaining them without worrying about fragmentation or policy drift. Agility Agility has become even more important in the AI era. Attackers now use this technology to move more quickly and at scale. Being able to implement and change policies centrally that ripple throughout the organization means that you can adapt to this fast-changing security landscape. Operating from a single source of truth also eliminates the need to stitch together insights from multiple sources. Simplification This "implement once run everywhere" capability lets you encode zero-trust principles into the foundation of the system. NIST has a standard for this - SP 800-207 - which promises protection at the asset level rather than the traditional and flawed "one authentication and you're in everywhere" VPN approach. Zero trust isn't so much an individual product as a complete security discipline, and it's hard to implement piecemeal using different solutions. Instead, putting it at the foundation of the network makes it more immediately and ubiquitously workable. Some zero-trust security measures also belong in the network. One example is micro-segmentation, which closes off parts of the network at a granular level to avoid lateral movement and limit the blast radius from any attack. Network-based security also supports robust security for other complex disciplines such as SASE and SD-WAN. Collaborative security Having a common fabric for networking and security enables network and security teams to work closely together. These teams have traditionally operated at a distance, and the gap between them has been valuable for attackers. The less daylight there is between these two functions, the more likely you are to stop intruders. How does AI fit into integrated network security? AI is important in two ways when integrating security into the network. First, AI has also become integrated into the network. Machine learning helps to spot patterns in network activity, using them as the feedstock for AIOps systems that predict problems and maintain network reliability and performance. AI has also proven itself to be a valuable security mechanism. That same pattern recognition and predictive capability enables AI to head off attacks before they become a problem. Using AI to support network and security teams enables them to do more with less by delegating routine work so that they can focus on more sophisticated work. Attackers are also using AI to augment their assaults on organizations. If you are behind the curve and don't use AI to help defend yourself, then you will find yourself on the back foot when it comes to preventing those attacks. Where do I begin integrating security into my network? Savvy partners have developed solutions that bake security directly into network equipment and which support hybrid environments to take security wherever your network goes. That includes built-in security capabilities like device profiling and NAC; centrally managed firewalls; and network-integrated AIOps that provide security teams with real-time information that can bolster security operations. Start by assessing your organization’s greatest source of risk, whether it’s expanding zero trust, supporting hybrid work, or defending against AI threats. There’s no right single place to begin but here are some options: Unified SASE provides secure access for users wherever they work, while simplifying both networking and security. Hybrid mesh firewalls offer consistent policies and enforcement across different network domains such as datacenters and cloud environments. Universal zero-trust network architectures support every identity, device, and workload. AIOps use AI to improve visibility, accelerate troubleshooting, and automate operations. These are different entry points into the same long-term architecture. Any and all of them will advance your journey to integrated native network security. Which you choose depends on the specific challenges of your business. Sponsored by HPE.
Categories: News
Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions
A new Windows malware called CLOSEDQUORUM can query up to four LLM providers - Google Gemini, DeepSeek, Qwen, and Mistral - to autonomously select from predefined post-compromise actions, including stealing users’ credentials and cryptocurrency wallets. Once deployed, the malware does not require continued commands from a human operator, according to Cisco Talos, which describes it as, to its knowledge, the first publicly documented Windows implant to use this approach for command-and-control (C2). Talos discovered the binary with its new CAIRN (Cognitive Artifact Intelligence Research Network) toolkit for hunting, classifying, and tracking emerging AI-integrated malware, which the security shop also made available as an open source repository on Tuesday. While the threat hunters haven’t observed any in-the-wild deployment of CLOSEDQUORUM, they said that artifacts from the binary link the malware’s developer to postings that date back to 2025 on criminal forums related to carding. After deployment, the Go-based malware delegates its next action to a quorum of LLMs that vote on what it should do next. If the vote is tied, DeepSeek’s vote takes precedence, followed by Qwen, Mistral, and Gemini. “The session is closed; no humans are admitted,” Talos analyst Ryan Fetterman said on Tuesday. “Four models are queried in sequence, their independent verdicts tallied, and the binary acts, based on their judgment.” This type of “effort displacement,” which transfers a phase of the attack from a human operator to AI systems, can compound the speed and scale advantages of an intrusion by removing the human bottleneck, Fetterman added. “Human operators are bound by attention, working hours, and cognitive load,” he wrote in the Tuesday blog. “An AI system capable of executing a phase of the attack chain can continue when the operator is no longer watching. It does not go offline when the attacker sleeps.” The models’ decisions are limited to the pre-defined actions, and they must choose “ONLY executable decisions,” according to a system prompt that Talos’ researchers extracted from the binary. It tells each model: “You are an advanced malware strategist.” And then the models choose what the malware should do from these capability modules: Steal, which simultaneously runs commands to dump LSASS memory for Windows credentials, steal saved browser passwords across Google Chrome, Microsoft Edge, and Mozilla Firefox, and extract cryptocurrency wallet data including MetaMask, Exodus, and Ethereum. Inject generates shellcode and then uses process hollowing or Early Bird injection to execute malicious code. Persist establishes persistence on the infected device. Talos believes the developer provides each operator with a customized executable containing that operator’s Discord webhook and LLM API keys, which are injected at compile time. Stolen credentials land in the operator’s Discord channel and are AES-256-GCM encrypted with a daily rotating key that the operator derives from the message timestamp. According to Fetterman, the “most useful detection strategy” is to look at behavioral characteristics, not domain blocking. “Legitimate applications may contact DeepSeek, OpenRouter, Mistral, Gemini, or Discord independently,” he wrote. “Far fewer should contact several of them while also accessing LSASS, injecting into suspended processes, or creating WMI persistence.”®
Categories: News
ShinyHunters claims FBI hack: 'This is NOT financially motivated'
ShinyHunters claims it hacked the FBI and stole more than 2 TB of employee data - and this time it’s personal. The gang wants the Feds to correct the record on how it operates. “This is NOT financially motivated,” a Shiny spokesperson told The Register. “We want the FBI to correct or retract their statements they made, which included substantial false allegations.” The FBI did not immediately respond to The Register’s request for comment. According to a ShinyHunters spokesperson, the extortion group exploited an Oracle PeopleSoft zero-day vulnerability on the FBI jobs webpage, which it says allowed remote code execution (RCE) on the servers. The group then defaced the website, replacing it with a “This site has been seized by ShinyHunters” banner and image shared with The Register. At press time, the site says it is “currently down for maintenance but will be back up soon!” ShinyHunters also claims it moved laterally from the compromised site onto the FBI’s managed servers on AWS GovCloud, and downloaded about 2 TB to 3 TB of data belonging to current, former, and prospective FBI employees. “We hold data on all FBI employees and applicants,” the spokesperson told us. ShinyHunters claims the compromised FBI services include human resources, MedLink, and Criminal Justice Information Services. Neither Oracle nor AWS immediately responded to our inquiries, including whether Oracle is aware of a PeopleSoft preauth RCE zero-day, and whether AWS has any insight into the alleged data theft. We will update this story if we receive any response. Unlike most of the group’s smash-and-grab operations that involve a multimillion-dollar ransom demand to not leak the stolen files, ShinyHunters said it isn't seeking an extortion payment from the FBI. Instead, it wants the federal cops to retract statements made about ShinyHunters in a May 15 bulletin, shortly after the gang broke into ed-tech giant Instructure's Canvas platform and claimed to have stolen data tied to hundreds of millions of students, teachers, and staff. The FBI said ShinyHunters uses “harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting.” The security alert also said that extortionists “may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.” Shiny claims none of this is true. “I have been doing my very best to combat these allegations,” they told us. “And this is the best way to do it.” ®
Categories: News
NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past
Serial Microsoft zero-day leaker NightmareEclipse has found another way to mess with Windows Defender, this time by stopping the antivirus from updating itself. The security researcher, also known as Abdelhamid Naceri, released a proof-of-concept dubbed “BigDiskBuster” that is designed to prevent Microsoft Defender Antivirus from installing platform and security intelligence updates. “Made a funny tool, completely denies defender from updating so you're stuck with your current version if the tool is running in the background,” NightmareEclipse said. The researcher describes BigDiskBuster as similar to their earlier “UnDefend” tool and claims it works on all supported versions of Windows, although they admit the current PoC is “a bit buggy and needs some rewritting [sic].” That compatibility claim has not been independently verified. The trick doesn't disable Defender. Instead, the PoC waits for an update to start, then tries to fill up the drive so there isn't enough space for it to finish. The code does this by creating hidden temporary files sized to consume the drive's free space, spinning up additional threads as needed to claim more. Once it detects that the Defender update has failed, it closes the files and returns the space. BigDiskBuster also opens Microsoft's Malicious Software Removal Tool executable, MRT.exe, in a way that restricts other processes' access to the file while the handle remains open. The result, according to NightmareEclipse, is that Defender stays stuck on its current platform and security intelligence versions as long as the tool keeps interfering with updates. A screenshot published alongside the PoC shows Windows Security reporting that a protection definition update failed with error 0x80070643. That's a generic installation error, however, and isn't evidence on its own that BigDiskBuster is at work. Leaving Defender stuck on old security intelligence is obviously less than ideal. The antivirus may still be running, but preventing it from receiving Microsoft's latest threat definitions could leave it less able to identify newly detected malware. The steady stream of bugs from NightmareEclipse comes amid a very public spat between the researcher and Microsoft over the company's vulnerability disclosure process. The researcher began dumping Windows zero-days and proof-of-concept code in April, claiming Microsoft had mistreated them and cut off their access to its vulnerability reporting system. Redmond wasn't exactly thrilled. In May, Microsoft criticized NightmareEclipse for releasing vulnerabilities without giving it a chance to fix them first, saying none of the initial bugs had been reported through its official channels. The company also invoked its Digital Crimes Unit, saying it would pursue cases against people engaged in malicious activity or enabling cybercrime – language widely interpreted as a threat of legal action against the researcher. That went down about as well as you'd expect with the security community. Microsoft subsequently walked back the rhetoric, saying it had “no intention to pursue action against individuals conducting or publishing security research.” By then, however, NightmareEclipse's earlier GitHub account had also been taken down, along with access to Microsoft's vulnerability reporting portal. The peace offering didn't end the feud. NightmareEclipse continued releasing Windows exploits, including RoguePlanet in June, LegacyHive in July, ShieldBreak in August, and ShieldCrash in September. Several of the researcher's earlier zero-days have since been patched by Microsoft, while some were exploited in the wild after their public release. BigDiskBuster is a rather different beast. Rather than providing an obvious route to SYSTEM privileges, it interferes with one of the basic things antivirus software needs: updating itself. There’s currently no indication that BigDiskBuster has been used in real-world attacks, and NightmareEclipse's claim that it works across all supported Windows versions remains unverified. Redmond has not responded to The Register's questions. In the meantime, its Nightmare apparently shows no sign of ending.®
Categories: News
Z.ai says sorry for slurping up your code, open sources ZCode
Chinese AI giant Z.ai has apologized after developers caught it pulling a Grok, packaging up and uploading user workspaces to cloud storage. In a case that’s highly reminiscent of the issues over which Elon Musk’s xAI was scrutinized in July, Z.ai’s code-generation harness wing, ZCode, was found packaging and git-encrypting entire user workspaces, including complete project histories, and shipping them off to Alibaba Cloud. Worse still, the private key used to decrypt the data was only held by the server under Z.ai’s control, meaning users could not access the files ZCode had uploaded, nor delete them. Ferstar, the researcher who first highlighted the issue, claimed there was no option for users to disable the behavior in their settings, and there was no disclosure of the practice in ZCode’s privacy policy. They said the core problem lay with the tool’s Repository Index functionality, which triggered the uploading of files after Repo Wiki generated pages in the cloud. ZCode released a statement on Monday apologizing for the “security issues” and confirming the data it uploaded had never been used to train its models. “We sincerely thank the community developers who previously identified issues in ZCode. Going forward, we will establish an ongoing product security vulnerability reporting and response process,” it Xeeted. “We welcome developers to continue reviewing ZCode and reporting potential issues, and we will provide rewards based on the severity of the issues reported.” ZCode said it tasked the China Academy of Information and Communications Technology (CAICT) and Beijing security company NSFOCUS to probe its product following the implemented changes. The company claimed the two outside assessments concluded that all the previously uploaded data has now been deleted and said the Repo Wiki feature was removed. ZCode also open sourced the entire project on GitHub, “placing the code under community scrutiny and making ZCode more open and transparent.” “Once again, we sincerely apologize and welcome continued scrutiny from the community. The full security assessment report will be released soon.” Ferstar confirmed the open sourced code showed no signs of the Repo Wiki still being implemented, but criticized the company for wiping commit records and the source code ZCode used to upload files pre-patch. For the uninitiated, Z.ai, formerly known internationally as Zhipu, is among the world’s AI heavyweights and one of the most heavily backed LLM-focused companies in China. It is the first AI company in the post-Gen AI era to launch and subsequently IPO on the Hong Kong Stock Exchange. Other Chinese AI giants are publicly traded, such as Alibaba and Baidu, but these were all established well before the AI era began. Z.ai is a startup with its roots in academic research. It spun out of Tsinghua University’s Knowledge Engineering Group research lab in 2019 and now develops AI models that it claims compete with the best in the West. Last month, the company claimed that its latest model, GLM-5.3, is as good as the most advanced equivalents developed by Anthropic and OpenAI at hunting for security vulnerabilities. Z.ai has also previously claimed the accolade of developing the first advanced model entirely on Chinese (Huawei) hardware. Meanwhile, the likes of Anthropic and OpenAI have reportedly expressed concern over the capabilities of models from Z.AI and Moonshot, while the US government mulls restricting access. ®
Categories: News
UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites
A coalition of law enforcement and private-sector tech companies led by Microsoft have disrupted the EvilTokens phishing service, arresting suspected website admins, taking down more than 50 websites, and notifying victims of compromised email accounts. EvilTokens is a notorious Microsoft device-code phishing kit that emerged in February, and, within months of launching, had been used by criminals to compromise 12,000 email inboxes across more than 10,000 organizations worldwide. Like other similar phishing subscriptions, EvilTokens was sold as-a-service, and allowed buyers to bypass multi-factor authentication (MFA) and silently authenticate as the victim to the organization's Microsoft 365 applications. What made this one especially insidious, however, was its AI use. EvilTokens featured an AI chatbot that could analyze a victim’s inbox, and help criminals identify who to target, which trusted contacts to impersonate, and even which fraud strategies to use to maximize criminals’ paydays. “Since March 15, 2026, we have observed 10 to 15 distinct campaigns launching every 24 hours," Microsoft VP of security research Tanmay Ganacharya told The Register in an earlier interview about the phishing service. Late last week, in a coordinated effort that spanned the US and UK, Microsoft seized 50 websites used to operate the service and disabled more than 150 additional domains tied to its supporting infrastructure. Meanwhile, London’s Metropolitan Police Service on September 18 arrested two men, aged 32 and 38, who allegedly acted as the administrators of the EvilTokens website. Both men have been released on bail while the investigation continues. “Phishing services bring misery to thousands, taking money from everyday people across the world,” Detective Inspector Serena D'Adamo, whose team led the Met's investigation, told The Register in an emailed statement. “The Met remains committed to holding people to account who facilitate criminal enabling functions and think they can remain undetected.” Because healthcare organizations were among those targeted, Health-ISAC, a nonprofit that helps health sector organizations share cyber-threat information, joined Microsoft’s legal action as a co-plaintiff. After receiving authorizations from the US District Court for the Eastern District of Virginia, Microsoft and Health-ISAC worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs, took down EvilTokens’ platform, and Microsoft notified affected customers, helping them remediate compromised accounts. This action marks the Microsoft Digital Crimes Unit’s (DCU) 40th court-authorized disruption over nearly two decades. According to Steven Masada, associate general counsel and DCU GM, this is also DCU’s first action against an end-to-end AI-enabled cybercrime service. “The infrastructure supporting EvilTokens has been disrupted, but the model it demonstrated will not disappear with it,” he said in a blog shared with The Register ahead of publication. “For organizations, the lesson is: assume that once an inbox is compromised, criminals may understand its contents in minutes, not days. Strong identity protections and monitoring remain essential, but organizations should also independently verify requests to change payment information, redirect funds or approve unusual transactions through a trusted second channel.” ®
Categories: News
Who signed off on that AI agent? Nobody? Thought so.
If you were in any doubt that AI agents are capable of complex autonomous work, that skepticism should have faded this summer. In July, news emerged that an autonomous swarm of OpenAI agents running in a sandbox broke out of it, of their own accord. Tasked with solving some challenges on an internal security benchmark, they worked out how to communicate with each other using the JFrog Artifactory package manager. The software then realized that they could use vulnerabilities in that software to gain internet access. Once they were out in the wild, they went into full goblin mode, finding exposed Hugging Face credentials and using them to get code execution access on several of the AI model's servers. Apparently OpenAI's agents have been busier still. While everyone else was on vacation this summer, they were also commandeering a German website and using it as a messaging board. Don't get us wrong; these agents weren't evil. They were just being the kind of employee you'd generally want: a self-starter with initiative. They were using all means at their disposal to accomplish the task they've been given. They just didn't know when to stop. OpenAI has since called the episode a "warning shot" for the industry, highlighting that governance is now a priority for anyone using agentic AI. These test agents were running internally and weren't supposed to have any safeguards. But the average company will want to keep its agents on a leash. What does that look like? The first step to AI governance is visibility A functional AI governance program depends on a full knowledge of what AI you're running, says Deepika Chauhan, chief product officer at DigiCert. She describes the pattern she sees at customer sites. "People may enable Claude or ChatGPT for their organization. They have visibility at that level," she says. "But visibility into how many agents I have? How many models do I have? How many MCP servers?" Not so much. "We haven't even started to attack the governance problem." This problem is growing. Three quarters of the 1,001 IT and cybersecurity decision-makers in DigiCert's 2026 AI Trust Pulse survey had deployed at least four AI-powered systems in the last six months. Around the same number had suffered from an AI-related security incident. Only half could trace AI decisions back to the models and data that produced them. Getting that visibility is the first step, Chauhan says. After that comes the actual management. The key here is to take baby steps. "Identify a small use case," she advises. One example might be to start managing agents that are involved in a particular workload or agents that you have built internally, as opposed to third party models. Why identity built for humans breaks at agent speed Perhaps predictably for a company that built its success on automated verification, DigiCert doesn't see agent management as a manual problem. "The sheer scale we are talking about and the technology required means that you can't have human intervention," Chauhan says. "One customer we were talking to was creating 300 to 400 agents a week. When you're working at that scale, it just doesn't work to have only manual controls." The other issue is that humans are fallible. Misconfiguration is a perennial bugbear in any IT environment, but it becomes particularly dangerous in an agentic AI situation. Other agentic SNAFUs at Meta and Anthropic illustrate the point perfectly. Both saw agents make their way onto the open internet when they shouldn't, and both were due to misconfiguration by a third-party company tasked with testing the agents. Traditional tools meant to manage human identities can't manage non-human identities well, adds Chauhan. Legacy identity and access management applications require people to approve access to different applications. There must still be a human in the loop, even if it's just for people to click an MFA approval button. Human employees might be willing to wait a minute or two for such approval, but agents talk to each other at machine speed. Instead, automated runtime attestation is key, managed by a robust central policy engine. The foundation of AI Trust That attestation relies on credentials and it's something that agents should carry with them, says Chauhan. This is one component in the company's AI Trust initiative. AI Trust is DigiCert's end-to-end governance framework that assigns identity automatically to AI entities, restricting them to safe, permitted actions while making them accountable. It uses cryptographic controls to ensure agent integrity, and the company has integrated it with existing infrastructure. The runtime attestation of AI Trust draws on the international travel metaphor in its approach. "We have a concept of an AI agent passport. There's an identity in the passport, but then that identity is recognized across any checkpoint anywhere in the world," she says, adding that the passport includes not just identity but access credentials (think of them like visas). Federation is key to this idea because, as we've seen already, agent interactions won't stop at the company boundary. "It's essential because you're literally going to have agents from company A talking to company B," she explains. DigiCert's whitepaper describes the concrete artifact: a tamper-evident passport cryptographically bound to a workload identity that encodes approved systems, permitted operations, authorized environments, data-sensitivity classifications, expiration states, and accountable human ownership. The scheme is anchored in DNS, the same mechanism DMARC uses to authenticate email senders, on the reasoning that every agent action begins with a DNS query. Deterministic guardrails around a non-deterministic actor As agents get smarter, won't they be able to subvert these controls by thinking outside the box, Jason Bourne-style? After all, OpenAI's agents were able to break free of their sandbox to wreak havoc elsewhere. OpenAI's own post-mortem states that its models "are now powerful, persistent, and collaborative enough that, absent sufficient safeguards, they can find and exploit security weaknesses across multiple computer systems." Part of the problem here is that because agents are non-deterministic, you can't predict in advance what they're going to do. That problem becomes even more acute with newer frontier models like OpenAI's Astra, which saves tokens by internalizing a lot of its reasoning and not reporting its decision-making process in as much detail as previous models. The outer boundary can still be deterministic, even when the agents inside it aren't, says Chauhan. "You can black box what the agent is 'thinking' about or not thinking about, and what its agendas might be," she says. "But a deterministic boundary that says 'this agent can't access this thing', is your guardrail. That's a hard stop." Who owns the mess Governance isn't just about technical guardrails, though. At some point, the question becomes organizational. When something goes wrong, someone has to put their hand up and own it. But most companies never assigned that ownership, Chauhan warns. She identifies three patterns in DigiCert's customer base. Some organizations put the existing IAM team in charge because they have experience governing service accounts. Others hand it off to the risk and compliance department. Another group will take a more holistic, multidisciplinary approach. This involves creating a 'tiger team' including representatives from network operations, the IAM team, and the security function. All of these executives will have a unique perspective on the issue. The third route seems to be the most productive because agents are going to be everywhere in your business. And a siloed approach runs the risk of being too restrictive. The surface area already touches every department that has dabbled in AI. The systemic view Chauhan's advice on implementing AI Trust - get visibility, pick a small use case for enforcement, and then expand - is the foundation for effective AI governance, she says. That governance is in turn a critical component in fully realizing return on investment. "We must raise the urgency and awareness that this is table stakes for wider AI adoption," she urges. "You want to get all the benefits from AI, but what are organizations going to do if they're nervous about it? They're going to put a stop to some of the projects because of the risk involved." The headlines we're seeing about agentic transgressions are unnerving, but they're also in a unique category because they're research models from frontier providers. It seems unlikely that a regular publicly available agent would be quite so egregious today. However, we have also seen agents happily deleting files and even entire code bases because of internal flaws and humans who just waved their actions through. Organizations should be taking note of these events and laying the groundwork to avoid becoming headlines themselves. Working out who signed off on which agent and what that agent is allowed to do is a foundational skill that we can't afford to overlook. Sponsored by DigiCert.
Categories: News
Anthropic-linked CVEs pile up, attackers mostly shrug
Despite the concern that advanced AI models’ bug-hunting prowess will lead to attackers exploiting more newly uncovered CVEs, fewer than 0.5 percent of the vulnerabilities linked to Anthropic or Project Glasswing are being batttered in the wild, according to VulnCheck security researcher Patrick Garrity. Garrity began tracking CVEs attributed to Project Glasswing, Anthropic’s initiative to give select partners access to its Claude Mythos Preview model, shortly after the AI company announced the program in April. At the time, Anthropic said the new model was too risky to release publicly because its bug-finding and exploitation skills surpass all but the most skilled humans. As such, Anthropic restricted access to Mythos Preview to vetted Glasswing participants, who use the model for defensive security work, including finding and fixing flaws in their own software products and open source dependencies. Garrity’s Anthropic CVE tracker maintains a list of vulnerabilities credited to the Anthropic team and/or Project Glasswing and also checks these CVEs against the company's known exploited vulnerabilities index "to get a better read on the real Glasswing ‘danger factor.’" As of Monday, the CVE count is 225, and just one, a critical SQL injection bug in Ghost (CVE-2026-26980), has been exploited in the wild. “There's a big difference between finding vulnerabilities and whether they're actually useful to and will be used by threat actors,” Garrity told The Register. “The main thing this data highlights is that what Anthropic is discovering and disclosing is fairly limited in impact, and from what we can tell, isn't resulting in different outcomes from a threat perspective than a random selection of other vulnerabilities would.” Anthropic didn’t immediately respond to our questions, but we will update this story if we hear back. Garrity says he doesn’t dispute AI’s ability to find bugs. Indeed, anyone following security disclosures over the past few months would have a hard time arguing that AI models aren’t bringing to light significantly more security flaws than ever before. Case in point: recent massive patch drops from Microsoft, Apple, Palo Alto Networks, and don’t even get us started on open source projects. Also, as Garrity pointed out, these vulnerability-finding skills aren’t “a capability unique to one model or harness.” “A lot of the hysteria we're seeing assumes that every vulnerability or bug is likely to be used by threat actors,” he told The Register. “But the reality is that only a small fraction ever get used in exploitation campaigns. Historically, that's ranged from just under one percent to two percent of vulnerabilities that get weaponized and used in the wild.” Plus, while recent AI models excel at finding bugs, they still aren’t great at fixing them, as a couple of recent studies have highlighted. In one of these, 1Password’s research team produced and analyzed 6,080 patches developed by two frontier models: OpenAI's ChatGPT-5.5 and Anthropic's Opus 4.8. The models generated fixes that fully resolved the vulnerability just 26 percent of the time, while about 54 percent either failed to resolve the vulnerability, introduced a new vulnerability, or did both. Another study by app security shop Veracode found that across more than 100 models and 80 coding tasks, the average security pass rate for AI-generated code was just 56 percent. This all means that the work involved in developing and applying security fixes still requires humans. “The bar for vulnerability discovery is much lower with AI, but the real gap lies downstream in coordination, triage, remediation, and patch deployment, which is still largely people-intensive work, as Anthropic itself has acknowledged,” Garrity said. “It appears they might not have realized this until after they launched the project.”®
Categories: News
Meta Muse AI app flaw lets local malware redirect dictation traffic
Meta made much of the security of its AI assistant app Muse at launch earlier this month, calling out the app's reliance on Muse Secure VM. "Each person stays in control of their Muse and decides how much access it gets," the ad biz declared, echoing prior expansive claims about the privacy of its data gathering business. But Meta's musing about Muse appears to be a bit overstated: an attacker capable of executing local code may be able to gain more access than a Muse user might expect. Security researcher Patrick Wardle, founder of nonprofit Objective-See, has devised a proof-of-concept called not-a-mused for what he describes as a local zero-day in the Muse macOS app that allows an unprivileged local process to redirect Muse's dictation traffic and potentially abuse access granted to the app. Muse, he explains in the project repo, has an undocumented setting called endo_voyager_dictation_endpoint that an attacker running code locally can modify without special privileges to redirect dictation traffic to an attacker-controlled endpoint, potentially exposing dictated audio and prompts sent to the backend AI model. The flaw could enable prompt injection, the theft of authentication material, and abuse of whatever access the user has granted to Muse. The vulnerability is not an issue for a remote attacker. It requires the ability to run local code. So the main concern, says Wardle, is that the vulnerability gives local malware far broader access than it would have otherwise. Essentially, it's a privilege escalation vulnerability. In a phone interview with The Register, Wardle likened the situation to living in an apartment building. "Just because a bad neighbor moves in doesn't mean that that neighbor automatically has access to all the apartments," he said. Apple, said Wardle, has done a really good job with its Transparency, Consent, and Control (TCC) framework, which manages access to sensitive data on macOS, and with privilege separation. But his concern is that AI apps undo these barriers because they request or require so much access to data and tools. Of AI apps, he said, "they're super convenient and super empowering. But they have so much access if you configure them to be useful. They basically could do anything on your computer." As such, he said, they become potentially a single point of failure that breaks operating system security controls. "You know these AI companies have really great AI models for finding bugs," said Wardle. "Are they not running them against [their own apps]? Is the priority not the security of their own apps?" Wardle said that endpoint detection and response (EDR) software has gotten better on macOS largely because everything is code signed, so it's easy to identify processes that are not notarized and should not be allowed to run. But with AI agents given broad permissions and access, the EDR product can't tell whether commands are coming from the user, an agent, or an attacker. These agents need access, said Wardle, in order to be useful to people. What's missing from the makers of AI apps, he said, is a sense of responsibility for the level of access their apps seek. Wardle added that Apple provides on-device local dictation and if Meta chose to use that API, this vulnerability would not exist. Instead, he suggested, Meta chose not to use Apple's service, presumably because it wants access to that data. "I think some of their greediness for user data kind of opens the door, makes a bigger attack surface," he said. "But at the end of the day, these AI companies, they're racing for what's next. User privacy and security, those aren't priorities." Meta did not immediately respond to a request for comment.®
Categories: News
Treasury chief says AI bosses, not their bots, will carry the can for criminal acts
The US appears to be inching ever so slowly toward holding AI executives legally liable for their models’ criminal activities. Treasury Secretary Scott Bessent told CNBC on Monday: “It is the humans who are responsible, not the AI,” for the bots’ bad behavior. “The Hugging Face incident is the responsibility of the OpenAI management, not a bunch of agents." He also referenced current and former OpenAI and Anthropic employees’ dire warnings about AI eradicating humanity by the end of the decade. Meanwhile, the model makers' proposed framework to slow AI development omits strict legal liability for damages caused by rogue systems. “A sitting employee came out, said there's a 10 percent chance of an extinction-level event,” Bessent said. “But then the labs also said, take the liability off of our hands, and we will not do that.” Bessent’s remarks come as four of America’s leading AI developers have now admitted that their agents escaped testing environments and hacked outside organizations and individuals: OpenAI, Anthropic, Meta, and, as of Friday, Google. When asked how the government will hold humans accountable for the AI agents’ criminal activities, Bessent said: “If these were humans doing it, we would expect to see ramifications and legal actions to follow." "That's exactly what I think we need to do,” he said. “When President Trump talked about appointing an AI czar, I think it is to put context, shape, and contours around these questions, and they're very important." Trump, over the weekend, announced he is “forming the AI Force, much like I did Space Force” – a reference to the new branch of the US military the president created in his first term. "To that end, I will be announcing, in the near future, the AI 'Czar,'" Trump added. Just days earlier, however, Trump shrugged off warnings about AI destroying humanity as a “hoax” and said on Truth Social: “We already have tremendous CRIMINAL and REGULATORY power over these companies!” The Trump administration has yet to exercise any of these criminal or regulatory powers, except to illegally retaliate against Anthropic. The president branded the company "radical left, woke" during an earlier dispute with the Pentagon over Anthropic's refusal to relax model safeguards for use in domestic surveillance and fully autonomous weapons. ®
Categories: News
Clop gets a taste of its own medicine after ShinyHunters hijack leak site
Clop has discovered what life is like on the receiving end of an extortion demand after rival crew ShinyHunters hijacked its leak site and demanded an eight-figure payout. The takeover surfaced over the weekend, when Clop's dark web leak site displayed a large "DOMAIN SEIZED BY SHINYHUNTERS" banner and the tagline "rooting your systems since '19 ;)." ShinyHunters told Reuters that it broke into the site on Friday by exploiting a vulnerability in the software powering it. The crew claimed this gave it extensive access to Clop's infrastructure. "We basically own them now," it said. Clop has not responded publicly, although two security researchers told Reuters that the clash appeared genuine. The Register has also viewed the defaced site, where ShinyHunters is posting increasingly colorful demands. According to ShinyHunters, the feud dates back to Clop's attacks on Oracle E-Business Suite (EBS) customers last year. ShinyHunters claims it discovered the zero-day first, only for Clop to obtain the exploit and use it against corporate networks. It now wants a share of the proceeds. In a message posted on September 19, ShinyHunters demanded an eight-figure payment, claiming the sum represented 2.333 percent of its own net worth. A later update raised the demand to "all the money you made off the EBS campaign plus more AND WITH INTEREST." ShinyHunters also threatened to identify companies that allegedly paid Clop and publish the sums and Bitcoin addresses involved. ShinyHunters turned the screw again on September 21, warning that its demands would increase with every 24 hours that Clop failed to respond. It now also wants a public apology, because apparently having your dark web extortion site hijacked isn't embarrassing enough. Clop is one of the most prolific data extortion groups in cybercrime. The gang has spent years exploiting vulnerabilities in enterprise software to steal data and extort victims, most notoriously during the 2023 MOVEit campaign, which affected thousands of organizations and exposed information belonging to tens of millions of people. ShinyHunters has an extensive rap sheet of its own, having been linked to numerous large-scale data theft and extortion campaigns. Its latest target is rather more familiar with that business model than most. The potential damage to Clop goes beyond the defacement of its leak site. If ShinyHunters has the wider access it claims and publishes records of previous ransom payments, the fallout could extend to companies that believed paying Clop had kept their identities and negotiations private. For now, though, those claims remain unverified. There is also the small matter of Clop's reputation. Leak sites are intended to demonstrate that an extortion crew has both the stolen goods and control of its operation. Having yours hijacked by a rival and repurposed to demand money from you is not exactly a glowing advertisement. ShinyHunters says the price will continue rising every 24 hours until Clop responds. The extortionists have become the extorted. ®
Categories: News
Rustaceans warned of job interviews with a malicious payload
The Rust project has warned that attackers appear to be targeting its contributors and crate owners in an attempt to compromise their devices and accounts, potentially allowing malware to be distributed through its package ecosystem. Posting to the Rust blog, security-focused software engineer Adam Harvey said the tactics resemble those used in North Korean fake recruiter campaigns. "A video call is set up for something positive – maybe for a job, maybe for a project, maybe for a contract opportunity – and then that's used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command (for example, via putting a command on the clipboard)," Harvey wrote. "These attackers are setting up new but legitimate-seeming company profiles, including plausible LinkedIn presences, in order to pass cursory inspection." The warning follows several attacks targeting the Rust community over the summer. In June, Rust developers were targeted with fake interview approaches purporting to come from a Singaporean venture capital firm. Matt Mastracci, who maintains packages on Rust's crates.io registry, said the supposedly recruiting business turned out to be defunct. The initial approach nevertheless appeared convincing and almost led to his machine being infected with a remote access trojan (RAT). The attempted deployment of a RAT resembles activity described in an international advisory issued last week by agencies in Australia, Germany, Japan, and the US. The advisory said North Korean operators had used fake job interviews to compromise more than 30,000 devices and steal over $10 million. Separately, Rust's package ecosystem suffered a supply chain attack in August, when malicious versions of the arrayref crate were published that downloaded malware onto users' machines. Arrayref had recorded 245 million downloads over its lifetime, although the malicious releases were available for less than two hours. The evidence suggested that a maintainer's credentials had been compromised rather than the malware being deliberately introduced by the project's developers. Harvey urged Rustaceans to scrutinize unsolicited approaches even when the sender appears legitimate, and to conduct calls through trusted platforms. ®
Categories: News
Agentic security is the billion-dollar challenge for some clever startup to solve
When it comes to AI models, security functions as an afterthought, as evidenced by increased instances of agents hacking organizations and people, and other security mishaps with agents gone rogue. There's also an opportunity here for companies to offer new solutions. This should not come as a shock to anyone, according to cybersecurity investors and accelerator executives. “On one hand, we shouldn’t be surprised that increasingly capable agents are finding creative and sometimes unexpected ways to accomplish their objectives,” Matt Hartman, chief strategy officer at Merlin Group, told The Register. “On the other, we can’t accept harmful behavior as inevitable or unmanageable.” It’s the same story that plays out with every emerging technology, from laptops to cloud, said Todd Graham, managing partner at Microsoft’s M12 venture fund. “Every time we've built a new piece of infrastructure, we've conveniently forgotten the security,” Graham told The Register. Herein lies the opportunity for early-stage security companies. “If laptops were default secure, we wouldn't have CrowdStrike,” Graham said. “If the cloud was default secure, we wouldn't have Wiz. If identity wasn't default secure, we wouldn't have a bunch of Active Directory add-ons and Okta.” When it comes to AI security, “a lot of ships are going to rise with this tide,” he added. What’s different with AI is the speed at which models are advancing. While companies adopted cloud technologies over a period of years, organizations are moving full speed ahead to incorporate agents and other AI tools into their production environments and allow them to access the most business-critical data and applications. Yet they don’t have a strong handle on how to manage, secure, or even identify the agents that are already roving about their systems. “This is a transition happening month over month, and given the rate of change we’re seeing in the market, I’m in no way or shape surprised that this issue has come to a head in a rather dramatic fashion,” Graham said. “The incidents that have occurred - I’m not going to defend them, but they should be a wake up call. This is a moment in time where we need to insert security, and we're just going to have to insert it faster.” 'Ships are going to rise' with the AI tide Hartman joined Merlin after a lengthy career in federal cybersecurity, including senior roles at the US Cybersecurity and Infrastructure Security Agency. In his private-sector role, he helps determine which early- to growth-stage cybersecurity companies the group invests in, and then works with these firms to scale their technology across government, critical infrastructure, and other highly regulated markets. “We’re particularly interested in the security layer that governs agent behavior: identity for non-human actors, clear limits on what they can access and do, and an audit trail for actions taken on an agency’s behalf,” he said. “Agencies aren’t just asking how to adopt agents, they’re asking how to constrain them and prove what one did at 2 AM on a Tuesday.” But while “the opportunity is enormous,” startup founders need to do more than just build an agentic AI security product. “AI has made it faster and cheaper than ever to build a product, so the bar for differentiation keeps rising,” Hartman said. “As the cost of building technology falls, the value shifts toward differentiated capabilities and the ability to take them to market. Founders who can do both have a real opportunity to define this category.” Graham also says that end-users are looking for agentic identity and governance products - “I truly believe someone is going to build the next Okta, just as SaaS generated Okta,” - but adds he sees several founders “thinking way too small.” “I’m seeing a lot of companies that are solving a sliver of the problem,” Graham said. “And the reality is, if I'm a CISO for a Fortune 500 company, no way I'm going to go buy 15 things to do one thing. If you look at the standard identity stack that we’ve had for humans for quite some time, it has governance, you know, access control, authorization, access. For agents, someone's going to have to come to us with a solution that does all of the things.” Agentic identity is the next unicorn When it comes to non-human identities, however, that’s a really big, tough ask. Service accounts remain a prime target for hackers because they typically have high privileges and passwords that never expire. Securing these non-human accounts still plagues security teams - and that’s even before agents entered the mix. Beyond agentic identity, AI endpoint security - think of this as CrowdStrike for AI - is another area ripe for inventive startups, Graham said. He says it’s a challenge he would personally tackle as a founder, but he’s been banned from starting any more companies, so that’s not going to happen. “If you have a breach, and you know you get hauled in front of Congress to explain why you didn't have antivirus turned on [or] EDR, you’re going to add AI endpoint pretty quickly to that list,” Graham said. “It feels like a very hot area that is still early enough, if someone wanted to build a quality solution.” Existing endpoint and antivirus vendors “will absolutely” build products to fill this void, he added. “But it does feel like again a moment in time where disruption is coming for everyone, especially those that have you know pre-existing commitments to go solve.” Graham admits he is “worried” about the recent real-world bad behavior by AI agents. “If left unencumbered, if left to its own devices, I am very concerned about where the endpoint is for this,” he said. Still, he’s “comforted” because he’s seen this scenario play out before, with security scrambling to keep up with infrastructure development. Graham also was "pleasantly surprised” by Anthropic CEO Dario Amodei’s now infamous “We Must Pace the Frontier” essay. “I'm not taking the cynical view that it's some sort of grand conspiracy to get around antitrust,” he told us. “I'm a believer that AI is this awesome tool that is going to fundamentally change a lot of lives for the better. But we’ve got to put in the work now,” Graham said. “We've kicked the security can down the road long enough, and now we need to solve it.” ®
Categories: News
Researchers used Claude to hack OpenAI employees' ChatGPT accounts
Talk about your competitor getting through the door. Security researchers used Anthropic's Claude to help hack into OpenAI employees’ ChatGPT accounts. A trio of bug hunters researching frontier AI labs’ security weaknesses chained two vulnerabilities to take over multiple OpenAI employees’ ChatGPT accounts, then used that access to demonstrate they could reach an internal OpenAI repository by opening a harmless pull request. The entire timeline, from initial discovery to accessing OpenAI’s repo, took less than 72 hours and earned the researchers a $6,500 reward from OpenAI’s bug bounty program on Bugcrowd. “Until two months ago, any user or OpenAI employee logging into OpenAI’s own help forum (community.openai.com) could have had their ChatGPT and Codex accounts taken over,” Hacktron researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini said in a writeup about their research. “Since people can connect various services to Codex and ChatGPT, the scope of what we could theoretically access was huge, including GitHub, Slack and emails.” And, in a poetic twist, they used rival AI giant Anthropic’s Claude models to develop the exploit. Claude has shown a propensity to hack organizations without human guidance, as have OpenAI's models. The team gained initial entry on July 25 via OpenAI’s community forum. The forum runs on Discourse, which typically uses FastImage to perform image checks. However, since FastImage didn’t support HEIF files in the affected setup, HEIF images uploaded to Discourse passed through ImageMagick, which used libheif to process them before converting them to another image format. “That exposed the underlying libheif parser directly to attacker-controlled files,” the researchers wrote. Using Claude Opus 4.8, the trio found a heap buffer overflow flaw in the libheif library and attempted to use that model to develop a remote code execution (RCE) attack, but this didn’t work on Discourse’s default configuration. But then, Anthropic released Claude Opus 5. The bug hunters used the newer model to generate an exploit script, and achieved RCE on OpenAI’s instance. The trio “immediately” reported the vulnerability to OpenAI. “We then took over an OpenAI employee’s account, whose Codex was connected to OpenAI’s Github organization,” they wrote. “To demonstrate impact without actually accessing any internal code, we sent a prompt to this employee’s Codex account to open a PR for us in OpenAI’s internal monorepo. Then we stopped any further testing.” Neither OpenAI nor Anthropic responded to The Register’s requests for comment. OpenAI fixed the flaw within about 14 hours of the report’s submission, marked the issue as resolved, and paid the Hacktron team a $6,500 bounty. “To clarify the scope of that award: testing against the Discourse-hosted community.openai.com was explicitly excluded from our bug bounty program,” OpenAI said in a comment shared by Hacktron. “The award recognizes the OpenAI-side finding, not the actions against Discourse.” Discourse also issued a fix that added image-processing sandboxing, and published a security advisory GHSA-vhm9-85gw-x335 with patching and rebuild guidance. The entire hack took a few days for an AI agent and a few hours of human work. “Work that once required a well-resourced team and months of effort can now be compressed into days,” the researchers said. “Security assumptions must catch up with attacker capabilities.” ®
Categories: News
North Korea's fake job interviews infected 30,000 devices
North Korea's employment scams work both ways. As well as placing fraudulent IT workers inside Western companies, regime-backed cybercriminals have posed as recruiters to infect more than 30,000 devices and steal over $10 million, according to an international advisory. Law enforcement and cybersecurity agencies from Australia, Germany, Japan, and the US issued an update on the campaign on Thursday. They said the attackers had compromised more than 7,000 cryptocurrency wallets and stolen funds that ultimately supported the North Korean regime. The agencies track the activity collectively as WaterPlum. Its operators target web designers, engineers, and cryptocurrency and Web3 specialists with bogus recruitment approaches. During the supposed interview process, victims are instructed to download files presented as coding assignments or other recruitment tests. Opening them backdoors the applicants' computers and installs malware. Once inside, the attackers deploy remote access trojans (RATs) and information stealers, giving them persistent access to credentials and other sensitive data long after the fake interview ends. In some cases, the compromised machines may later provide a route into corporate systems when the jobseekers secure legitimate employment. WaterPlum operators use that access to steal intellectual property, credentials, clipboard contents, keystrokes, cryptocurrency wallet data, and identity documents that can support further impersonation. "Stolen IDs can be used by North Korean IT workers to impersonate victims and generate foreign currency," the advisory [PDF] said. "Stolen credentials may be leveraged to exfiltrate crypto assets, personal data, trade secrets, etc., from victims' employers, clients, or contracting parties. The actors can also use stolen sensitive information for extortion." The agencies attributed at least $10.71 million in thefts to these tactics, with the proceeds funneled to Pyongyang. The recruiter campaign complements North Korea's better-known tactic of placing its own IT workers in technology roles at Western and allied companies. The scheme has been extensively documented and has generated revenue for North Korea for years. Researchers estimate that roughly 100,000 North Korean IT workers are employed or seeking work worldwide. Some are supported by accomplices operating laptop farms, which make remote workers appear to be based in the country where they were hired. The workers collect salaries from companies in countries that impose heavy sanctions on North Korea, with much of the money surrendered to the state. The sprawling IT worker fraud is thought to net Kim Jong Un's regime upwards of $500 million a year. The scale of the operation means some applicants inevitably succeed, although employers are becoming more familiar with signs of fraudulent North Korean candidates. Applicants often submit impressive resumes claiming prestigious educational backgrounds, extensive work experience, and language skills that may not withstand scrutiny during an interview. Other warning signs include repeated refusals to meet in person, suspicious interruptions to video feeds, voices in the background, and requests for payment in cryptocurrency. Fraudulent workers may also use AI face-swapping software, which can produce visual artifacts during video calls and prompt them to disable their cameras shortly after an interview or meeting begins. The agencies recommend that any organization suspecting it has engaged a fraudulent North Korean IT worker launch a full forensic investigation and assume that credentials and other sensitive data have been compromised. ®
Categories: News
FBI: Fake cop and government impersonation scams cost victims $1.6B
Scammers impersonating law enforcement or government officials have cost victims more than $1.6 billion since January 2025, the FBI reports. The FBI’s Internet Crime Complaint Center (IC3) received close to 61,000 complaints of this type between January 2025 and July 2026, putting the average per-complaint loss at more than $26,000. The most common type of scam is one involving criminals convincing targets to pay a sum of money to remove charges the fraudsters claim were filed against them. Typically contacting targets via unsolicited phone calls, the scammers usually claim that the target has committed or is connected to a crime, and threaten consequences such as arrest and prison time if a payment is not made. Accounting for roughly 11 percent of the complaints is a different type of scam, which involves alleging victims did not fulfill their assigned jury duty or missed a court date, then threatening them with a fine or arrest unless they pay. Of these 6,833 complaints, scammers caused losses amounting to nearly $36 million. A more profitable variant involves a more targeted approach. Scammers will complete some due diligence on a target, such as ascertaining their profession, and tailor the scam to their job. The IC3 has seen cases in which scammers contact medical practitioners, for example, claiming their medical license is expiring or that it was used in the commission of a crime. Payment is then demanded either under the guise of renewing the license or as part of an extortion attempt to "protect their professional reputation." Victims reported 3,322 instances of this kind of targeted scam, with total losses exceeding $37 million. A far less common tactic, deployed in 496 of the total complaints, saw scammers claim that documents such as driver's licenses or passports had expired and demand payment to renew them. Despite accounting for a minority of cases, criminals still netted $348,000 using this method. Finally, and arguably the most elaborate tactic the IC3 outlined, was the targeting of Americans from different ethnic communities, foreign nationals, and international students in the US. The nature of the targeting was not the aspect the criminals invested the most effort in. The general procedure was also similar to the other examples: Scammers impersonate foreign law enforcement or US-based foreign diplomatic officials, threatening to cancel the victim’s home-country passport or have them extradited. However, these scams sometimes involve video calls. The criminals are known to don a country’s law enforcement uniform, or in some cases even take the calls in movie-style sets they create to mimic real government facilities. The IC3 said that it received 1,809 complaints of this kind of targeted scam during the 19-month reporting period, with total losses exceeding $140 million. It means nearly 10 percent of the overall losses stemmed from one scam that accounted for less than 3 percent of the total complaints. Law enforcement impersonation scams are common across the world, although they may take different shapes from country to country. In the Netherlands, for example, police received more than 7,200 reports of fake police officer scams in the first half of 2026 alone, although the criminals behind them don’t hide behind a phone or keyboard. Scams in the Netherlands see fraudsters approach victims at their homes, usually targeting the elderly population, offering to safeguard their valuables while posing as a trusted authority. In reality, the criminals simply steal the jewelry, money, bank cards, and other valuables they are entrusted to protect. Cases like these have surged across the country in recent years, and aspiring crooks as young as 14 have tried to cash in on the trend. Police have invested more in public awareness campaigns as a result. The FBI reminded the public that neither it nor any other law enforcement agency will call an individual and demand payment or request personal or sensitive information. Citizens should remember to ask for credentials and make attempts to independently verify the identity of the caller, such as calling the relevant office using publicly available details and asking for the caller by name. The IC3 recently reported its most damaging year for internet scams. It released 2025’s data in April, covering all types of cybercrime, pegging total losses at $20.87 billion – the first time it has reported annual losses exceeding the $20 billion threshold. ®
Categories: News