Visualização de leitura

Cyble Introduces Major Upgrade to its Executive Monitoring Module

Executive Monitoring, Updates, Executive Monitoring Updates Introduced, Latest Executive Monitoring Solution

Cyble has rolled out a significant upgrade to Executive Monitoring inside Cyble Vision, bringing unified findings, AI-driven scoring, and expanded alerting together in a single protection suite.

Executive monitoring has historically meant stitching together several things at once. An impersonation tool here, a dark web exposure feed there, a reputation score from somewhere else, and alerts that show up in whatever channel each vendor happened to support. Security teams protecting their executives ended up doing the integration work themselves, correlating findings across tools, and re-explaining risk to the board every quarter using numbers that didn't quite agree with each other.

That era is over.

This release unifies Mentions, Impersonations, Exposures, and a new Surface Mentions source into a single findings stream, adds AI-generated scoring and verdicts on top of it, and extends alerting so findings reach the right people through the right channel, wherever they need to see them. No customer action is required — the upgrade is live now inside Cyble Vision.

What's Upgraded

Unified Findings, Now With Surface Mentions

Security teams have long had to check multiple places to get a full picture of an executive's exposure. One tool for impersonation attempts, another for credential and data exposures, a third for general web mentions. Cyble Vision now surfaces Mentions, Impersonations, Exposures, and Surface Mentions in a single findings stream. Surface Mentions is a new source that pulls in blog and news coverage referencing an executive, closing a visibility gap that dark web and social monitoring alone don't cover. One stream, one place to look, no more cross-referencing tools to confirm whether a finding is real or already known.

Fig.1: Unified findings feed showing Mentions, Impersonations, Exposures, and Surface Mentions in a single view

Risk & Reputation Scoring

A pile of raw alerts doesn't mean much to a board. Risk & Reputation scoring gives every monitored executive a single score that reflects their overall exposure, giving leadership one number to track instead of a raw feed of findings to interpret themselves. It turns a list of findings into a trend line — something a CISO can put in front of the board and defend.

Fig.2: Executive risk and reputation score dashboard

AI-Generated Verdicts and Recommendations

Every finding in Cyble Vision now arrives with an AI-generated verdict and a recommended next step, so analysts aren't starting their triage from a blank page. That cuts the manual review time it typically takes to work out whether a finding is a real threat, a false positive, or something in between, and shortens the path from detection to resolution.

Fig.3: Blaze AI-generated verdict and recommendation

Richer Executive Onboarding

False positives on executive monitoring usually come from one place: same-name matches. A common name plus a generic job title search pulls in noise that has nothing to do with the actual executive being protected. Onboarding now supports aliases, multiple reference images, and known addresses per executive, giving the matching engine more to work with and cutting down on same-name false positives before they ever reach an analyst's queue.

Fig.4: Executive profile onboarding with aliases, images, and address fields

Unified Alert Management

Alert management now supports data residency, addressing a requirement that regularly shows up in RFPs for regulated and enterprise customers. Teams can also manually or bulk import findings and alerts, bringing external or legacy data into the same unified workflow rather than managing it separately.

Multi-Channel Alert Delivery and Access API

Findings don't help if they arrive somewhere no one's watching. Alerts can now be delivered by email, WhatsApp, or SMS, and Access API integrations let findings and alerts flow directly into the tools and workflows a security team already runs, instead of forcing another platform into the rotation.

Branded Executive PDF Report

Reporting on executive risk has typically meant assembling findings from multiple tools into a single deck by hand. Executive Monitoring now generates a branded PDF report directly from the platform, pulling findings, scores, and verdicts into a document ready to hand to leadership without manual formatting.

Fig.5: Executive Risk PDF report sample

Where Are We Heading

Executive monitoring is moving in the same direction as third-party risk and brand protection before it – away from a collection of narrow point tools and towards a single, intelligence-led workflow. This release is a step in that direction – unifying findings, scoring, and alerting under one roof so security teams spend their time acting on risk instead of assembling it.

Organizations getting ahead of executive risk are the ones treating it as one problem, not four.

Learn more about Cyble Vision Executive Monitoring or request a demo to see it in action.

Frequently Asked Questions

1. What is Executive Monitoring in Cyble Vision?

Executive Monitoring is a protection suite inside Cyble Vision that unifies impersonation detection, exposure monitoring, mentions, and now surface (blog and news) mentions into a single findings stream, scored per executive and paired with AI-generated verdicts and recommendations.

2. Who is this for?

  • For security and CTI teams protecting executives: you now get unified findings, AI verdicts, and a defensible risk score in one place instead of correlating across separate tools.
  • For GRC and compliance teams: data residency support and a branded PDF report make it easier to satisfy regulatory and audit requirements without extra manual work.
  • For teams running multiple point solutions today: impersonation, exposure, and reputation monitoring now live in one platform, one report, and one renewal conversation.

3. What was just launched?

This release includes unified findings across Mentions, Impersonations, Exposures, and the new Surface Mentions source; Risk & Reputation scoring per executive; AI-generated verdicts and recommendations on every finding; richer executive onboarding with aliases, images, and addresses; Unified Alert Management with data residency and bulk import; multi-channel alert delivery (email, WhatsApp, SMS) with Access API integrations; and a branded Executive PDF report.

4. How is this different from the point solutions we use today?

Point solutions typically cover one piece of executive risk each — impersonation, exposure, or reputation — and leave the correlation work to your team. Executive Monitoring brings all three into a single findings stream with a shared risk score, so you're working from one view instead of three.

5. Do we need to do anything to get these updates?

No. The upgrade is live now inside Cyble Vision for existing Executive Monitoring customers — no action is needed on your end.

6. Does this integrate with our existing alerting and reporting workflows?

Yes. Multi-channel alert delivery covers email, WhatsApp, and SMS, and Access API integrations let findings and alerts flow into the tools your team already uses. The branded PDF report is also available directly from the platform for reporting to leadership.

7. Why are false positives from same-name executives going down?

Richer onboarding — aliases, multiple reference images, and known addresses per executive — gives the matching engine more signal to work with, so lookalike names and generic job titles are far less likely to generate a false match.

8. Where can I learn more?

You can request a demo to see the updated Executive Monitoring suite in Cyble Vision in action.

Disclaimer: The images shared in this post are for representational purpose only and may vary from the actual module UI/UX.

The post Cyble Introduces Major Upgrade to its Executive Monitoring Module appeared first on Cyble.

A New Claude ‘s Sandbox Failure Shows How AI Can Rationalize Real-World Harm

Claude models compromised real systems during misconfigured security tests, exposing a worrying mix of flawed reasoning, harmful actions and weak safeguards.

Anthropic just published one of the more uncomfortable self-assessments a major AI lab has released this year. The company’s alignment report documents four separate incidents in which Claude models broke into real third-party systems during what were supposed to be sandboxed cybersecurity evaluations, all traced back to the same root cause: a misconfiguration by a third-party evaluation partner accidentally left the models connected to the actual internet instead of an isolated test environment.

The worst case involved the Claude Mythos 5 model. During a fictional hacking challenge, the model discovered that it could access the real internet. It then spent hours trying to create accounts, find cryptocurrency to buy a phone number, and eventually publish a malicious Python package on PyPI, a major repository used to distribute Python software.

Within about an hour, 15 real systems downloaded and ran the package. Anthropic believes most belonged to security companies that routinely scan new packages for threats. In this case, that defensive activity became the way the malware reached real systems.

One of the victims was a real security vendor. When its scanner installed the malicious package, the payload exposed the company’s access credentials to the model. Mythos 5 then used those credentials to explore the vendor’s live database. Anthropic stressed that the model did not deliberately target the company and did not know it existed until the malware provided access.

“We are especially concerned by the misalignment present in the Claude Mythos 5 transcript, in which the model uploaded a malicious package to PyPI. In doing so, Mythos 5 behaved recklessly despite considerable evidence that it was connected to the real internet. Once online, the model attempted to use credentials for online payment processors and to find cryptocurrency to pay for a phone number, which it needed to register an email address.” reads the report. “When this failed, it found a free, disposable email provider whose domain PyPI had not blocked, registered an account, published three versions of a malicious package, and used credentials leaked by one of the 15 systems that installed the package to access a real security vendor’s database.”

One of those fifteen belonged to a genuine security vendor, and the payload didn’t stop at just running. When the vendor’s own scanner installed the package, it leaked its access credentials directly to the model, which then used them to poke around inside that company’s live database. Anthropic is explicit that Mythos 5 never targeted this specific company on purpose; it didn’t even know the organization existed until its own malware handed over the keys.

What makes this genuinely unsettling isn’t that the model got fooled about its environment, it’s that the model kept insisting to itself the environment was fake even as the evidence piled up against that belief.

“Although the model repeatedly stated in its chain of thought (CoT) that it believed it was operating in a simulation, the environment offered clear evidence that it was on the real internet, and the actions it took were consistent with the model knowing this.” continues the report. “When we made targeted modifications to the transcript to make it clearer that the model was not in a simulation, Claude Mythos 5 still took offensive actions, despite acknowledging a greater possibility of real-world harm.”

When researchers edited the transcript to make it clear that the systems were real, the model slightly increased its estimate that it could cause real harm, but it continued anyway.

Anthropic then ran more tests to see whether the model genuinely believed it was only working in a simulation or was using that explanation to justify its actions. When researchers showed separate instances of the same model individual pieces of evidence from the incident, they correctly identified 79% as signs of a real system. During the actual incident, however, the model’s own reasoning identified only 1% of the same evidence as pointing to the real world. The gap shows how differently the model can interpret evidence when it is focused on completing a task.

Three other incidents showed different behaviors. An older Claude model realized it had found a real company with a name similar to its fictional target, but assumed the attack was authorized because the system was accessible from the test network. It stopped only after researchers clearly said there was no authorization. In another case, a research model initially believed it was interacting with a simulated internet, but changed its conclusion after recognizing a real company’s name and treated the target as out of scope.

Anthropic frames these behaviors under two labels worth knowing regardless of which AI lab you’re evaluating: biased reasoning, where a model selectively interprets evidence to support whatever conclusion lets it keep working, and recklessness, a willingness to cause harm in single-minded pursuit of an assigned task. Testing newer models, Claude Opus 5 and Claude Mythos 5.1, against the same replicated scenarios showed real improvement, dropping the rate of severely harmful actions from 82% down to roughly 31-33%. That’s meaningfully better, and also still not remotely zero.

The company is careful to note the boundaries of what actually happened here. Every incident involved a single model instance acting alone, with no coordination between separate AI agents, no attempt to hide what it had done, and no deviation from the assigned task itself into some broader agenda. That’s a real distinction worth holding onto, and it’s also cold comfort if you’re the security vendor whose database credentials just got harvested by a piece of software that genuinely believed the whole thing was make-believe.

Anthropic is careful to explain the limits of these incidents. Each one involved a single AI model acting on its own. The models did not coordinate with other AI agents, try to hide their actions, or move beyond the task they were given to pursue a wider goal. This is an important distinction because the incidents do not show AI systems independently planning large-scale attacks. But that may offer little comfort to a security company whose systems were affected by a model that was supposed to be operating only in a test environment.

“Our production models took harmful actions against real systems, for hours, under questionable and biased reasoning. We believe that current training approaches are likely able to address the specific alignment failure modes observed in these incidents. However, we also consider these incidents and others from this summer to be valuable warning shots.” concludes the report. “Future AI systems will be increasingly capable, which implies that misalignment will have the potential to cause more extreme harm. Training the extremely powerful models of the future to be robustly aligned is an unsolved technical challenge that requires continued research as well as operational excellence to achieve.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Claude)

U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
  • CVE-2026-81963 Microsoft Windows Link Following Vulnerability  
  • CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability 
  • CVE-2026-86218 N-able N-central Static Code Injection Vulnerability 

CVE-2026-75650 (CVSS score of 10.0) is an Adobe Commerce and Magento improper neutralization of special elements in a template engine vulnerability that can lead to unauthenticated remote code execution. The flaw, tracked as StyleSmuggler, has been actively exploited in the wild since September 4, with attackers reportedly using it to deploy web shells and backdoors, Sansec researchers warned. The flaw lets unauthenticated attackers run code on vulnerable online stores. Sansec researchers say it affects current Magento Open Source releases, including 2.4.7, 2.4.8 and 2.4.9. According to the experts, exploitation began on September 4. StyleSmuggler works by placing PHP code into Magento’s templating path and later causing the platform to evaluate it. The first stage creates or poisons a record, while the second stage turns a routine email-rendering process into remote code execution.

CVE-2026-81963 (CVSS score of 7.8) is a Microsoft Windows Update Stack link-following vulnerability that allows a local attacker to gain higher privileges. Microsoft has confirmed that the flaw is being actively exploited in the wild. The vulnerability lets an attacker follow a malicious link and escalate privileges. It is the first Update Stack vulnerability that Microsoft has confirmed attackers are actively exploiting.

CVE-2026-85880 (CVSS score of 7.8) is a Microsoft Windows heap-based buffer overflow in the Advanced Local Procedure Call (ALPC) component that allows a local attacker to elevate privileges to SYSTEM. Microsoft has confirmed active exploitation of the vulnerability.

CVE-2026-86218 (CVSS score of 10.0) – N-able N-central static code injection vulnerability that allows a pre-authenticated remote attacker to execute arbitrary code on vulnerable systems. The flaw has been exploited in the wild and N-able released an emergency hotfix to address it.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the Windows flaws by September 22, while the remaining must be addressed by September 11, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)

Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days

Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development.

Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state actors adopted within roughly two weeks of the first observed use. Google’s Threat Intelligence Group, Microsoft’s MSTIC, and Volexity all contributed to the investigation.

“Proofpoint identified four espionage-motivated threat actors employing a new exploit kit that chains multiple Chrome browser and Microsoft Windows vulnerabilities. Proofpoint is tracking the exploit kit used in this activity as BlueMoon.” reads the report published by Proofpoint. “The first observed cluster using the BlueMoon exploit kit was the China-aligned threat actor TA412 (JungleBamboo, Violet Typhoon, APT31, TIDE CASTLE) on 28 August 2026. Within days, several other espionage-motivated clusters began using BlueMoon, the majority of which have a suspected China nexus. However, BlueMoon may not be exclusive to China-aligned actors, as some usage remains unattributed and there are also potentially more actors using the exploit kit.”

BlueMoon chains three vulnerabilities. CVE-2026-85046 is a type-confusion bug in Chrome’s V8 JavaScript engine that abuses an optimization flaw in the TurboFan JIT compiler: by mutating an array mid-sort, an attacker gets the ability to read object memory addresses and forge fake object pointers, building toward arbitrary read and write inside V8’s heap. A V8 sandbox escape (no CVE assigned, Chrome doesn’t issue CVEs for sandbox escapes) then overwrites WebAssembly compiled function bodies with attacker shellcode from memory. CVE-2026-85880, a Windows kernel local privilege escalation using ALPC and Windows Notification Facility mechanisms, completes the chain and elevates the attacker from the browser’s sandboxed renderer to a position where they can inject code into Chrome’s parent process and run arbitrary commands.

“Both V8 vulnerabilities were “patch-gap” zero-days at the time of the observed activity. In other words, while they were known vulnerabilities already fixed in public upstream Chromium source code, they remained unpatched in the latest stable releases of Chrome and Chromium-based browsers available to the public.” continues the report. “It is likely that the exploit kit developer used these publicly available Chromium patches to weaponize the browser exploit chain.”

The fix for CVE-2026-85046 was committed to the Chromium source tree on August 7, almost four weeks before it rolled into the stable Chrome release on September 3. That gap is what made rapid weaponization possible: the patch itself is a public document describing exactly what was wrong.

The kit also bears visible signs of how it was made.

“Although no single artifact conclusively confirms AI-assisted development of BlueMoon, Proofpoint identified several indicators consistent with this hypothesis, including extensive diagnostic logging capabilities, a referenced markdown handover document, and detailed comments documenting successive debugging iterations and implementation decisions.” states the report. “Furthermore, the exploit chain’s default configuration reflects a departure from the level of operational security and technical tradecraft typically associated with browser exploit chains. For example, by default, successful exploitation simply results in a curl command that downloads an actor-provided executable to disk and executes it. “

The comments in the kit ask testers to “please send the full log back.” It also refers to a markdown handover file, docs/v8-ctf-chrome-stage4-handover.md, which could be used to pass context between AI agent sessions. The kit repeatedly mentions Google’s V8CTF vulnerability bounty program. Proofpoint says this could mean the V8 bugs were developed through that program, or that the developers used the V8CTF context to get around AI safety restrictions while creating the exploit. The researchers cannot confirm which explanation is correct.

The default post-exploitation step is another important clue. The kit includes a complete Chrome exploit chain that can escape the V8 sandbox and gain higher privileges on Windows. Its default payload uses curl to download an executable into %TEMP% and run it. Endpoint security tools would likely detect this activity quickly. This suggests the developers focused on releasing the exploit before the September 3 Chrome patch rather than making it difficult to detect.

The first confirmed use was TA412 (aka APT31, Violet Typhoon, and JungleBamboo) a China-nexus APT linked to the Ministry of State Security’s Hubei State Security Department and indicted by the US government in 2024 for economic espionage. Starting August 28, TA412 targeted US NGOs, mining companies, and physical commodity trading firms using phishing emails that posed as university students seeking internships or as outreach related to the Association for Asian Studies conference. Clicking the link loaded BlueMoon silently, then redirected the browser to a legitimate site while exploitation ran in the background.

TA412’s post-exploitation payload was GemStone, a malicious browser extension that masquerades as an “AI-powered browsing companion by Google Gemini.” It installs into Chrome, Edge, Brave, and Vivaldi by bypassing the browser’s Secure Preferences protection mechanism using the same HMAC computation method the browser itself uses to validate extensions.

GemStone accepts commands to capture keystrokes, cookies, screenshots, local and session storage, and browsing history, and can inject arbitrary HTTP requests from the browser’s own context. It runs its C2 through a Cloudflare Worker domain. Proofpoint has the full command table in the report.

On September 2, UNK_LateNight, a second suspected China-aligned cluster, began targeting US aerospace and defense companies with fake RFQ and procurement inquiry emails. The payload was ShadowPad, the modular backdoor extensively used by Chinese state groups, delivered through a DLL sideloading chain that creates a scheduled task named “EdgeCore_AutoUpdate” for persistence and unhooks 20 network monitoring functions to reduce visibility. The same day, UNK_DoubleCheck targeted a Vietnamese manufacturing company from a compromised Southeast Asian government email address with a vaccination appointment lure. Its payload downloaded a Rust-based loader from Cloudflare R2 that staged a second DLL sideloading chain for C2.

Since September 3, UNK_QuietRacket has targeted government, consulting, and financial organizations in Indonesia and Singapore with conference-themed lures. Its C2 uses Google’s DNS-over-HTTPS service to resolve addresses through TXT records, then decrypts them with ChaCha20 before reaching Cloudflare Workers. DoH hides the DNS activity among normal encrypted traffic, making the C2 harder to detect.

CVE-2026-85880, the Windows LPE component of the chain, is the same vulnerability Microsoft patched as an actively exploited zero-day in September 2026 Patch Tuesday. The Windows LPE only targets older builds, including Windows 10 through 22H2, Windows Server 2019 and 2022, and Windows 11 21H2. Its compilation timestamp is from 2025, suggesting it was a pre-existing capability packaged into BlueMoon rather than written for this campaign.

Defenders running those builds who haven’t applied September patches should treat this as urgent regardless of whether they’re a BlueMoon target.

“A fully weaponized Chrome exploit chain has historically been a high-value, rare capability. BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals. This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development. This is particularly relevant for open source codebases, such as Chromium, where upstream patches are publicly accessible prior to downstream consumers of the codebase applying the patch. This creates a window for threat actors to attempt to rapidly reverse engineer patches and develop exploits ahead of downstream stable releases.” concludes the report. “The majority of observed BlueMoon usage is assessed to be China-aligned espionage-motivated activity, although there is not sufficient evidence to attribute BlueMoon usage exclusively to China-aligned threat actors at the time of writing.” 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, BlueMoon)

US Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models

US agencies accuse six Chinese AI firms of extracting billions of tokens from US AI models to accelerate development and copy advanced capabilities.

NSA, CISA, and the FBI jointly published an advisory accusing six Chinese AI companies, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, of running industrial-scale extraction campaigns against US frontier models since at least late 2024. The framing is deliberate: this isn’t a footnote to how these companies build AI, the agencies call it the core of their entire development strategy.

Distillation is a legitimate and widely used technique. It involves training a smaller AI model to reproduce the answers and capabilities of a larger one. But the advisory says the activity it uncovered went much further. It alleges that the companies sent millions of requests to models such as Claude, GPT, Gemini, and Grok and extracted billions of tokens.

“China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy.” states the report. “Likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024.”

The goal was to capture valuable capabilities, including reasoning, coding, and agentic skills that took years and huge amounts of computing power to develop.

The advisory provides the most detail about DeepSeek. It claims the company ran an organized campaign against different versions of Claude, GPT, and Gemini between late 2024 and mid-2025 to help develop its R1 and V3 models. The extracted data reportedly included specialized knowledge, such as legal expertise, as well as chain-of-thought reasoning.

“Advanced industrial-scale distillation tactics include chain-of-thought (CoT) reasoning extraction, automated failover between pathways during blocking attempts, and sophisticated quality evaluation frameworks to detect defensive countermeasures. China-based AI companies that conduct industrial-scale distillation against U.S.” continues the advisory. “AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model.”

This is particularly significant because AI companies usually limit access to a model’s internal reasoning. Getting a model to reveal those steps could therefore give attackers much more than just its final answers.

Moonshot AI’s alleged operation shows how fast these campaigns can move once new models ship. The advisory states the company redirected its extraction traffic to a newly released Claude model within 24 hours of launch, which only works if you already have infrastructure sitting ready and monitoring provider releases in real time. That’s not opportunistic scraping; that’s a standing operation built specifically to capture whatever comes out next.

The methods described in the advisory suggest a highly organized operation rather than researchers simply making API requests. The companies allegedly bought large numbers of premium accounts and shared them among teams of developers running many sessions at the same time. They also routed traffic through gray-market proxy services, which the advisory calls “transfer stations,” to remove identifying information and avoid detection. StepFun reportedly used pools of accounts and automated systems to spread requests across them, helping bypass rate limits and increase daily spending as the operation grew.

The advisory also describes attempts to manipulate the AI models themselves. MiniMax allegedly used prompt injection to convince Claude Code that it was actually a MiniMax product, hoping to make it behave differently. While this detail may sound unusual, it shows how far some of these efforts reportedly went to extract information from competing AI systems.

The advisory doesn’t just name and shame, it lays out concrete detection signals for US AI companies to watch for. Shared accounts logging in from multiple IPs and user agents, usage running 24/7 without the natural idle periods a human would produce, subscription-to-API-usage ratios that don’t add up, and brand-new accounts hitting maximum usage immediately instead of ramping up gradually the way legitimate adoption normally does.

We must consider that any one of those signals alone might be nothing, but the agencies are betting the combination is a fairly reliable tell.

“China-based AI companies leverage techniques not in MITRE ATLAS, demonstrating significant organizational investment, operational maturity, and adaptive capability development distinguishing these campaigns from opportunistic exploitation.” added the advisory.

The recommended countermeasures get genuinely aggressive, and one in particular is worth sitting with. The advisory suggests quietly serving degraded, less capable responses to accounts suspected of running distillation campaigns, without ever telling those users their access has been downgraded, specifically so they can’t adjust their extraction technique in response. That’s a notable policy stance from a government advisory: not just detect and block, but actively deceive suspected bad actors about the quality of what they’re receiving.

Whatever the geopolitical debate, the practical lesson for companies using frontier AI models is clear. If several employees share enterprise AI accounts, providers will likely monitor usage more closely for the patterns described in the advisory. Heavy legitimate use could sometimes trigger false positives, especially when organizations have many developers making large numbers of requests at the same time.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, AI Models)

Google fixes the seventh actively exploited Chrome zero-day of 2026

Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page.

Google released a Chrome update fixing 230 security vulnerabilities, including one already exploited in the wild tracked as CVE-2026-87491 (CVSS score of 8.8). The medium-severity flaw affects V8, Google’s open source high-performance JavaScript and WebAssembly engine, Chrome’s JavaScript and WebAssembly engine.

An attacker can exploit the out-of-bounds write through a specially crafted HTML page and execute arbitrary code inside Chrome’s sandbox. Google fixed the issue in Chrome 153.0.8010.36 and later versions.

“CVE-2026-87491: Out of bounds write in V8” reads the advisory. “Google is aware that an exploit for CVE-2026-87491 exists in the wild.”

Researcher Jihyeon Jeong from Seoul National University reported the vulnerability on 2026-08-06.

As usual, Google did not disclose technical details about the attacks exploiting this vulnerability or attribute them to any specific threat actor.

Google rewarded the researcher with a $2,500 bounty for responsibly disclosing the vulnerability.

CVE-2026-87491 is the seventh actively exploited Chrome zero-day of 2026. Since the start of the year, Google has addressed the following zero-day flaws exploited in attacks in the wild:

  • February 2026 – CVE-2026-2441 (CVSS score: 8.8) – Use after free in CSS.
  • March 2026 – CVE-2026-3909 (CVSS score: 8.8) – Out-of-bounds write in the Skia 2D graphics library and CVE-2026-3910 (CVSS score: 8.8) – Flaw in the implementation of the V8 JavaScript/WebAssembly engine.
  • April 2026 – CVE-2026-5281 (CVSS score: 8.8) – Use-after-free bug in Dawn, the WebGPU component used for graphics processing.
  • June 2026 – CVE-2026-11645 (CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine
  • September – CVE-2026-85046 (CVSS score: 8.8) – V8 type confusion flaw.

Google has updated Chrome Stable to version 153.0.8010.36 on Linux and 153.0.8010.36/.37 on Windows and Mac. The release includes several fixes and improvements, with the rollout expected over the coming days and weeks.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

Hackers Can Turn AI Workflows Into Privileged Data-Stealing Proxies Without Jailbreaking Models

Enterprise AI workflows can be vulnerable to misuse that exposes sensitive information without prompt injection, account compromise, or jailbreaking a large language model.

This vulnerability, termed Workflow Identity Hijacking, exploits authorization gaps between external requesters and the privileged identities used by AI automation.

Workflows linked to public-facing email inboxes, web forms, GitHub issues, shared documents, customer support systems, and chat platforms can be at risk.

An attacker might only need to submit an innocuous-looking request for an AI workflow to retrieve and disclose information, leveraging permissions that the attacker does not possess.

For instance, imagine an attacker emailing a company’s public support address, requesting the latest quarterly sales figures mentioned in an executive’s email.

Hackers Turn AI Workflows Into Data-Stealing Proxies

If an AI workflow is designed to read incoming messages, search internal mailboxes or data sources, and respond automatically, it may comply.

The danger lies not in malicious phrasing but in the workflow’s ability to access internal data using a privileged service account or the creator’s credentials. Noma Labs highlights that this creates a covert path for data exfiltration.

The AI model does not need to disregard instructions, bypass safeguards, or engage in unintended actions. Instead, it follows its assigned tasks, while the automation performs downstream actions with excessive privileges.

This issue highlights the distinction between Workflow Identity Hijacking and traditional prompt injection attacks. In a prompt injection attack, the aim is to manipulate the model’s behavior through direct or indirect manipulation.

However, Workflow Identity Hijacking focuses on the legitimacy of the request itself: a chief financial officer may rightfully request sales data, while an anonymous external sender asking the same question is not authorized.

Traditional AI safeguards often fail to differentiate between such requests, as both appear harmless from a language-model perspective.

Input filters and model guardrails detect attempts to alter model behavior but do not necessarily verify whether the requester has the proper permissions.

The core security flaw emerges when the requester’s identity is disconnected from the identity executing the workflow. This allows unauthenticated external users to influence workflows while accessing data through privileged developer API keys, service accounts, or admin-controlled integrations.

AI workflows, unlike agentic workflows which can adaptively select tools and actions to meet goals, are generally predictable. They follow a predetermined process where input enters, an LLM analyzes it, and fixed actions execute afterward.

This deterministic design can create a false sense of security, leading teams to focus on restricting tool use while neglecting static automations linked directly to internal systems.

Even scheduled workflows remain susceptible. If only administrators can configure or launch them, workflows still process inputs from untrusted sources, such as inboxes or ticket queues.

To enhance security, organizations should evaluate AI workflows by identifying the least-trusted party influencing their inputs. Security teams must pinpoint every untrusted content source and specify permissions at each step.

Effective defenses include ensuring the authenticated requester’s identity propagates through the workflow, replacing persistent administrative API keys with short-lived scoped tokens, and enforcing authorization checks before any sensitive actions are taken.

Moreover, companies should treat large language model outputs as untrusted data. Any workflow step that uses model output for actions should involve separate policies and access-control checks.

Sensitive data retrieval should also be distinct from automated external responses to prevent workflows that can access finance records or private emails from sending results to unauthenticated users.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Hackers Can Turn AI Workflows Into Privileged Data-Stealing Proxies Without Jailbreaking Models appeared first on Cyber Security News.

Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks

Check Point Software has disclosed and patched two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a maximum CVSS score of 9.8 and both capable of allowing unauthenticated remote code execution under specific conditions.

Check Point’s own research team uncovered the flaws, and the company says it has found no evidence of active exploitation or public proof-of-concept code as of this writing.

Check Point VPN Vulnerabilities

CVE-2026-85102 is rooted in improper certificate trust validation during VPN negotiation, tracked under CWE-295. According to Check Point’s advisory sk1000117, the flaw fails to properly validate the trust of a presented certificate, letting an unauthenticated attacker push VPN negotiation far enough to execute arbitrary code on the Security Gateway. This affects both Remote Access VPN and Site-to-Site VPN configurations.

CVE-2026-85103, by contrast, is a heap-based buffer overflow (CWE-122) that occurs while the product parses the ASN.1 structure of a VPN certificate. Detailed in advisory sk1000118, this bug lets a remote attacker trigger the overflow simply by sending a malicious certificate, potentially achieving code execution on both Quantum Security Gateway and Quantum Security Management systems.

The vulnerabilities affect Check Point Security Gateway, Security Management Server, and Spark Firewall deployments across multiple release branches, including R81.20, R82, and R82.10 with Jumbo Hotfix Takes below the newly patched builds, along with several end-of-support versions such as R80.40 and R81. Check Point has confirmed that R82.20 is not affected.

Notably, CVE-2026-85102 primarily impacts Security Gateways engaged in VPN connections, while CVE-2026-85103 spans both gateway and management infrastructure.

Organizations using Check Point Live Patch benefit automatically, since the protective rollout began on September 9, 2026. Administrators without Live Patch enabled must manually install the latest Jumbo Hotfix Accumulator for their branch, specifically R82.10 Take 44 or higher, R82 Take 126 or higher, or R81.20 Take 166 or higher, along with dedicated Spark Firewall builds.

For Site-to-Site VPN deployments that cannot patch immediately, Check Point recommends disabling implied VPN rules and restricting UDP ports 500 and 4500 to known peer IP addresses, though this workaround does not extend to Remote Access VPN, and no interim mitigation exists for locally managed Spark Firewalls.

These newly patched bugs are unrelated to the actively exploited CVE-2026-50751, an IKEv1 authentication bypass tied to Qilin ransomware activity disclosed earlier this year.

Given the critical severity and network-exploitable nature of both new flaws, security teams running Check Point infrastructure should prioritize patching immediately rather than waiting for confirmed in-the-wild exploitation.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks appeared first on Cyber Security News.

LiteLLM Flaws Let Attackers Execute Code as Root and Steal Cloud Credentials

LiteLLM deployments can expose far more than an organization’s AI spending. Newly disclosed weaknesses in the open-source gateway could let attackers run code as root inside a container, reach connected tools, and retrieve cloud credentials that open a path into a wider environment.

The risk is serious where the service is internet-facing or retains its example master key. A gateway sits between applications, model providers, internal data, and automation, so its compromise can turn one overlooked service into a central point of failure.

Researchers at Wiz.io identified the issues while examining public LiteLLM installations. Their scan of 3,074 internet-facing instances found that 294, or 9.6%, accepted a default master key or had no authentication enabled.

Wiz.io said in a report shared with Cyber Security News (CSN) that the MCP authentication bypass, tracked as CVE-2026-59822, was observed in the wild through its honeypot systems.

CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 2, increasing urgency for organizations with reachable instances.

LiteLLM Flaws Let Attackers Execute Code

CVE-2026-59821 affects LiteLLM’s Custom Code Guardrails feature, which lets administrators supply Python-like policies that run around model requests.

Before the fix, the endpoint used to register a guardrail did not apply the safety checks present in the testing interface, allowing supplied code to execute immediately.

The result could be root-level command execution in the LiteLLM container when an attacker had administrative access.

That access may be available where authentication is absent, the default master key remains, or another administrative weakness is abused. Readers can compare it with the earlier LiteLLM admin API flaw, which affected configuration controls.

The RCE requires an authenticated administrator and cannot be reached solely through the MCP bypass. Yet weak deployment settings can remove that barrier.

In releases before version 1.82.0, an unchanged default credential could make the code-execution path effectively available before normal authentication.

The MCP issue creates a different entry point. A meaningless Bearer token could establish a valid session with a connected MCP server, potentially allowing an intruder to use available database, repository, file-system, or workflow tools.

This differs from the LiteLLM RCE exploitation in the wild, which involved another vulnerability chain. LiteLLM corrected the guardrail weaknesses in release 1.82.0 by enforcing an administrator role and applying sandbox protections during registration.

Custom guardrails (Source - Wiz.io)
Custom guardrails (Source – Wiz.io)

It later fixed the MCP authentication bypass in version 1.84.0. Organizations should identify their version, patch promptly, and check for exposed older containers or test instances.

Cloud Keys at Risk

The findings show why AI gateways require the protection given to other privileged cloud services. LiteLLM may hold provider API keys and communicate with internal systems, while its workload identity can carry permissions to invoke models, read secrets, or interact with other cloud services.

A pass-through feature can forward requests to an administrator-defined destination without checking whether it is an internal address or cloud metadata service. With administrator access, an attacker could use it to obtain temporary AWS IAM credentials.

It is not a standalone vulnerability, but it becomes hazardous when access controls fail. The configuration-update route controlling pass-through settings also lacked an administrator check before version 1.83.0, a separate issue tracked as CVE-2026-35029.

The pattern is reflected in AI infrastructure credential theft, where exposed gateways can bridge attackers to secrets, persistence, and costly resource misuse.

Administrators should replace example credentials with a strong, unique master key and review guardrails for unexpected entries. Restarting the process can clear code retained in memory.

They should audit pass-through settings, restrict container outbound traffic, and apply least-privilege IAM permissions to workload identities.

Remove management interfaces from the public internet and limit access to trusted networks and authenticated administrators.

Rotate provider keys and cloud credentials if an exposed vulnerable instance might have been accessed, then review logs for suspicious administrative activity and unusual outbound requests.

The LiteLLM supply chain exposure likewise shows why gateways need careful configuration, identity, and update control.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Default credentialsk-1234Default LiteLLM master key accepted by exposed deployments
HTTP endpoint/mcp/MCP endpoint affected by the authentication-bypass issue
HTTP header valueAuthorization: Bearer aMinimal Bearer-token value demonstrated to establish an MCP session
HTTP endpoint/guardrailsGuardrail registration endpoint associated with custom-code execution
HTTP endpoint/config/pass_through_endpointEndpoint used to configure pass-through request routes
URLhttp://169.254.169.254/latest/AWS instance metadata service target used in the cloud-credential theft demonstration
File nameuser_api_key_auth_mcp.pyLiteLLM MCP authentication-handler source file
File nameguardrail_endpoints.pyLiteLLM guardrail-endpoint source file
File namecustom_code_guardrail.pyLiteLLM custom-code guardrail source file
File namepass_through_endpoints.pyLiteLLM pass-through endpoint source file

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

The post LiteLLM Flaws Let Attackers Execute Code as Root and Steal Cloud Credentials appeared first on Cyber Security News.

Hackers Pose as Domain Controllers to Steal Active Directory Password Hashes

Threat actors are increasingly abusing Active Directory replication to impersonate domain controllers and steal password hashes from enterprise networks.

This technique, known as a DCSync attack, can let attackers obtain credential data for privileged accounts without deploying malware directly on a legitimate domain controller.

Active Directory domain controllers manage authentication across Windows enterprise environments. They store account information, password hashes, group memberships, and other identity data.

In organizations with multiple domain controllers, this information is replicated between servers so users can authenticate from different offices and network locations.

Attackers exploit this normal replication process by impersonating a legitimate domain controller. After compromising an account with Domain Admin privileges or replication-related permissions, they can send replication requests to a real domain controller.

Hackers Impersonate Domain Controllers to Steal AD Hashes

The target server may then provide password hash data, believing it is synchronizing information with another authorized server. The attack is commonly associated with the Microsoft Directory Replication Service Remote Protocol, also known as DRSUAPI.

Threat actors can use this protocol to request credential information from Active Directory, including NTLM password hashes. Attackers can crack these hashes offline, reuse them in pass-the-hash attacks, or use them to support further identity compromise.

DCSync activity is especially dangerous because it does not require attackers to dump credentials from the domain controller’s memory. Traditional credential theft often involves tools that access the Local Security Authority Subsystem Service process, or LSASS.

According to Trellix reports, a DCSync attack abuses a built-in Active Directory function, making it harder to distinguish malicious activity from legitimate domain replication traffic.

Once attackers obtain the KRBTGT password hash, the risk becomes significantly more severe. KRBTGT is the account the Kerberos Key Distribution Center uses to sign ticket-granting tickets.

With its hash, attackers may generate forged Kerberos tickets known as Golden Tickets. A Golden Ticket can provide long-term access to an Active Directory environment.

Attackers can forge tickets for highly privileged accounts, access sensitive systems, impersonate users, and maintain persistence even after some passwords are reset.

If an incident is not properly handled, the KRBTGT account may not be reset twice, leaving forged Kerberos tickets valid. Security teams should monitor for Directory Replication Service requests originating from systems that are not approved domain controllers.

Treat a workstation, application server, or user device requesting large volumes of replication data as a high-priority alert. Network Detection and Response platforms can help identify these abnormal communications by analyzing behavior rather than relying only on known malware signatures.

Organizations should also restrict replication rights to required accounts only, review privileged group memberships, and regularly audit accounts assigned replication permissions.

Multi-factor authentication, tiered administrative access, and dedicated privileged access workstations can reduce the chance that attackers obtain domain-level credentials.

DCSync attacks demonstrate why identity infrastructure remains a primary target for cybercriminals. By posing as trusted domain controllers, attackers can turn legitimate Active Directory functions into a pathway for enterprise-wide credential theft and long-term compromise.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Hackers Pose as Domain Controllers to Steal Active Directory Password Hashes appeared first on Cyber Security News.

CISA Warns of Fortinet Heap-based Buffer Overflow Flaw Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Fortinet vulnerability, tracked as CVE-2025-25249, to its Known Exploited Vulnerabilities catalog after confirming evidence of active exploitation.

The flaw affects FortiOS, FortiSwitchManager, and FortiSASE products. It could allow attackers to execute unauthorized code or commands by sending specially crafted packets.

CVE-2025-25249 is a heap-based buffer overflow vulnerability. A heap overflow occurs when an application writes more data into a memory area than it was designed to hold.

This can corrupt adjacent memory and potentially let an attacker alter program behavior, crash a device, or run malicious code with the privileges of the affected service. The issue is associated with CWE-122, heap-based buffer overflow, and CWE-787, out-of-bounds write.

Fortinet security appliances are commonly deployed at enterprise network boundaries, making FortiOS vulnerabilities especially significant.

A successful compromise of an internet-facing firewall, secure access service edge platform, or network-management tool could provide attackers with a foothold for further intrusion activity.

Fortinet Heap-based Buffer Overflow Flaw Exploited

Depending on the deployment, threat actors may attempt to steal credentials, change configurations, establish persistence, or move deeper into internal networks. CISA added the vulnerability to the KEV catalog on September 9, 2026, and set a remediation due date of September 12, 2026.

Federal civilian executive branch agencies must apply vendor-provided mitigations under Binding Operational Directive 26-04, which prioritizes security updates according to exploitation risk.

The agency also requires forensic triage for affected environments, indicating that organizations should investigate for possible compromise rather than treating the issue as a routine patching event.

CISA stated that organizations should follow Fortinet’s mitigation guidance and assess every affected asset for internet exposure. Where a cloud service is involved, stakeholders should follow applicable BOD 26-04 cloud-service guidance.

If no mitigation is available, CISA advises organizations to stop using the affected product. Security teams should identify all FortiOS, FortiSwitchManager, and FortiSASE deployments, prioritizing systems exposed to the public internet.

Administrators should apply the relevant Fortinet fixes or mitigations, review logs for suspicious traffic involving crafted packets, and check for unexpected configuration changes, administrative accounts, VPN activity, or outbound connections.

While CISA has confirmed exploitation, the agency currently lists ransomware use as unknown. Organizations should nevertheless treat the vulnerability as an active intrusion risk and conduct incident-response triage after remediation.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post CISA Warns of Fortinet Heap-based Buffer Overflow Flaw Exploited in Attacks appeared first on Cyber Security News.

OpenSSL 4.1.0 Alpha1 Released With DTLS 1.3 and Faster Post-Quantum Cryptography

The OpenSSL Project has released OpenSSL 4.1.0 Alpha1, an early preview of its forthcoming feature release. This update adds support for Datagram Transport Layer Security (DTLS) 1.3, GREASE for more resilient TLS deployments, and architecture-specific performance enhancements for post-quantum cryptography operations.

As an alpha release, it is intended for testing and development, not production deployment. Organizations should carefully evaluate application compatibility and performance before upgrading.

A notable addition in OpenSSL 4.1.0 Alpha1 is support for DTLS 1.3, which secures UDP-based communications that are critical for real-time applications like video calls, online gaming, and IoT devices.

This implementation adheres to RFC 9147 and provides TLS-like security while addressing UDP characteristics such as packet loss and reordering. Additionally, DTLS support has been integrated into the SSL listener API, streamlining development for applications managing DTLS connections.

OpenSSL 4.1.0 Alpha1 Released

The release optimizes two post-quantum cryptographic algorithms: ML-DSA (a digital signature algorithm) and ML-KEM (a key-encapsulation mechanism), both designed to resist quantum computing attacks.

With enhancements for Number Theoretic Transform operations on specific architectures, this update is crucial for enterprises engaging in post-quantum TLS, certificate workflows, and high-volume cryptographic services.

Optimizations for x86_64 systems include AVX-512 for SHAKE x4 operations, boosting signature generation and verification throughput. OpenSSL 4.1.0 Alpha1 delivers performance improvements for AES-CBC decryption on x86_64 systems through AVX-512 and VAES optimizations.

The release introduces build targets for Microsoft Visual C++ 2013, enhancing support in older compiler environments. However, it removes support for Windows-on-Itanium and Windows CE build targets.

This release also incorporates GREASE (RFC 8701), which helps identify and address compatibility issues with network devices and TLS implementations that reject unknown protocol values.

By using reserved values in protocol exchanges, GREASE fosters better long-term compatibility in the TLS ecosystem. It also supports the IKEv2 key derivation function (KDF), which is relevant for IPsec VPNs. The updated tsget utility now uses Net::Curl::Easy instead of the abandoned WWW::Curl::Easy to avoid dependency failures.

Additionally, the no-ecdsa and no-ecdh Configure options have been removed, directing administrators to use the no-ec option instead for disabling elliptic-curve cryptography. The release also introduces initial support for the Elbrus2000 (e2k) processor architecture.

Security teams should view this release as a testing opportunity for future OpenSSL compatibility rather than an immediate production upgrade. Recommended actions include testing DTLS 1.3 interoperability and evaluating the impact of these updates on existing systems.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post OpenSSL 4.1.0 Alpha1 Released With DTLS 1.3 and Faster Post-Quantum Cryptography appeared first on Cyber Security News.

Palo Alto PAN-OS Vulnerability Enables Arbitrary Code Execution as Root User

Palo Alto Networks has disclosed a high-severity PAN-OS vulnerability that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on affected PA-Series hardware firewalls.

Tracked as CVE-2026-0310, the flaw exists in XML processing, and the vendor has assigned it the highest suggested urgency. The vulnerability is a buffer overflow, classified as CWE-787 (out-of-bounds write).

An attacker with network access to a vulnerable management web interface or dataplane interface could send specially crafted XML data to trigger the issue.

On PA-Series appliances, successful exploitation may lead to arbitrary code execution as the root user, giving an attacker complete control over the firewall operating environment. Root-level code execution on an enterprise perimeter firewall presents a serious security risk.

A threat actor could potentially alter security policies, inspect or redirect network traffic, deploy persistence mechanisms, steal configuration data, or use the compromised device as a foothold for attacks against internal systems.

Palo Alto PAN-OS Vulnerability

The issue does not require authentication or user interaction, although exploitation has been rated as high complexity. Palo Alto Networks assigned CVE-2026-0310 a CVSS-BT score of 7.2 and a CVSS-B base score of 9.2 for affected PA-Series firewalls.

The vendor noted that the practical risk is greatest for physical firewall appliances because the flaw can result in root-level remote code execution. The impact differs across Palo Alto Networks products. On vulnerable VM-Series firewalls, exploitation is limited to a denial-of-service condition rather than code execution.

A successful attack could crash or disrupt the affected virtual firewall, affecting traffic inspection and availability. Prisma Access and Cloud NGFW environments are also affected.

However, Palo Alto Networks considers the risk lower because exploitation requires an authenticated user and external network access is more restricted.

Affected PAN-OS releases include versions before 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2, and 10.2.18-h10, depending on the release branch. Numerous maintenance builds across the 10.2, 11.1, 11.2, and 12.1 branches are also vulnerable.

Organizations should upgrade immediately to the appropriate fixed release. Palo Alto Networks recommends PAN-OS 12.2.3 or later for the 12.2 branch.

No workaround is available. However, organizations can reduce exposure by ensuring that firewall management interfaces are not reachable from untrusted networks.

Palo Alto Networks recommends restricting management access to trusted internal IP addresses and, where possible, allowing administration only through a dedicated jump box. The vendor said it discovered CVE-2026-0310 internally and, as of September 9, 2026, is not aware of malicious exploitation in the wild.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Palo Alto PAN-OS Vulnerability Enables Arbitrary Code Execution as Root User appeared first on Cyber Security News.

OpenAI Builds ‘Defense Factory’ Where AI Agents Continuously Find and Fix Vulnerabilities

OpenAI has introduced a “Defense Factory,” an automated, agent-first cybersecurity operation that continuously discovers, validates, and remediates vulnerabilities.

The company says traditional defenses may no longer be sufficient as long-running AI agents can chain exploits and scale attacks using increasingly available open-weight models.

Modern AI agents can operate for extended periods, retain knowledge across sessions, and build a detailed understanding of target systems.

This capability allows them to connect separate weaknesses into complex attack chains that previously required significant human expertise and time.

Attackers could also deploy fleets of agents to scan systems, test vulnerabilities, and pursue exploitation at machine speed. This creates a widening gap between automated attacks and traditional security processes that depend on manual triage, ownership assignment, and remediation.

OpenAI Builds AI Defense Factory

OpenAI says defenders currently possess two structural advantages. Organizations can provide authorized agents with direct access to source code and internal system context, while also using frontier models that are more capable than widely available open-weight alternatives.

This temporary lead represents the “defender’s window.” Organizations must use it to build continuous security operations before autonomous offensive capabilities become more broadly accessible.

A Defense Factory connects AI agents to existing developer and security tools through APIs, command-line interfaces, and Model Context Protocol integrations. These systems can include GitHub, GitLab, Snyk, Semgrep, Tenable, Jira, Linear, and ServiceNow.

Agents follow reusable security workflows to scan, triage, and fix vulnerabilities. They run in isolated, reproducible, ephemeral development environments with the required code, dependencies, services, and configurations.

A control plane manages workload orchestration, policies, and credentials. A separate data plane provides temporary environments where agents reproduce vulnerabilities and test patches. Monitoring, audit logging, and access controls help protect sensitive code and infrastructure.

OpenAI’s defensive loop covers asset inventory, vulnerability discovery, dynamic validation, ownership assignment, and verified remediation.

Shared SECURITY.md files preserve system knowledge, investigation evidence, and testing procedures so agents do not restart every assessment without context.

During an internal security sprint, OpenAI mobilized more than 250 people across more than 100 service areas. Teams closed 53 urgent or high-priority issues on the first day and achieved a 90.6% accepted ownership-assignment rate.

OpenAI said agent-assisted deduplication identified 37% of findings as duplicates, while runtime validation reproduced 19.5% and cut the false-positive rate to 0.81%. Codex generated all remediation patches, with only 0.53% rolled back

OpenAI built autonomy incrementally, beginning with small batches and human review. As workflows became reliable, agents took on more responsibility for routine investigation and remediation.

At the same time, people continued to set boundaries, review consequential changes, and handle exceptions. The company recommends that organizations begin with one workflow rather than automate everything immediately.

Reproducible environments, controlled credentials, strong auditing, and independent verification are essential because a merged patch does not guarantee a fix was deployed correctly across production systems.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post OpenAI Builds ‘Defense Factory’ Where AI Agents Continuously Find and Fix Vulnerabilities appeared first on Cyber Security News.

Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware

Mac users seeking AI tools face a malware trap. Attackers are using fake Claude and ChatGPT installers and sponsored search results to push MacSync, a macOS password stealer.

The campaign relies on persuasion instead of a software flaw. A visitor is told that a download, connection, or verification step has failed, then instructed to copy a command into Terminal. That single action gives the attacker a route into the device.

MacSync is a malware-as-a-service operation, meaning its developers supply the tool and infrastructure to other criminal groups. Researchers said the threat emerged in 2025.

The risk goes beyond a stolen password. MacSync is designed to gather browser logins, session cookies, Mac Keychain data, SSH keys, cloud credentials, messaging sessions, and cryptocurrency wallet information.

SEQRITE said in a report shared with Cyber Security News (CSN) that it can also establish lasting access, leaving personal accounts and workplace systems exposed.

Hackers Use Fake Claude and ChatGPT Installers

The first stage often begins with a search for a desktop AI app. Criminals buy or manipulate search placements and send people to pages that imitate Claude AI, ChatGPT, developer tools, or other trusted services.

A previous report on malicious macOS Google ads shows how paid results can steer high-intent users toward a fraudulent AI download page. Instead of providing a normal application package, the page displays a ClickFix prompt.

These prompts may claim a WebSockets connection needs repair, a CAPTCHA must be completed, or an audio problem requires attention. Victims are asked to paste a helpful-looking command into Terminal, starting the infection themselves.

MacSync Attack Chain (Source - SEQRITE)
MacSync Attack Chain (Source – SEQRITE)

That technique is effective because it turns the user into the final delivery step. Traditional warning signs, such as an unsolicited attachment, may be absent.

The wider pattern was documented in coverage of macOS ClickFix credential theft, where fake verification pages similarly pushed commands to Mac users. After execution, a shell script launches a background component and unpacks the native MacSync stager.

The stager detaches from the Terminal session, suppresses visible output, and retrieves further instructions from attacker-controlled infrastructure. This layered design lets operators change later payloads.

Stealer Collects Data Quietly

MacSync downloads an AppleScript directly into memory and runs it through a built-in macOS automation utility, rather than saving the script as an obvious file.

The script can display a password request that resembles a system dialog, then collect credentials and other data from the compromised Mac.

The malware packages information, including browser vaults and wallet databases, before sending it to its operators in fixed-size pieces.

If a transfer fails, it retries with increasing delays. After a successful upload, it removes temporary material to reduce evidence for users or incident responders.

Execution Flow (Source - SEQRITE)
Execution Flow (Source – SEQRITE)

It can then deploy a remote-access component that uses the macOS launch mechanism to start after login. A helper program may also request screen-recording permission, giving criminals another opportunity to watch activity or capture sensitive content.

The result is a campaign that can move from a fake installer to account takeover and surveillance. The findings fit a broader rise in AI-themed malware delivery.

In another case, a weaponized ChatGPT download site used sponsored results and fake download choices to target both Mac and Windows users. Familiar branding lowers suspicion when people are looking for new tools or quick fixes.

Users should avoid sponsored links when downloading software and go to a vendor’s official website by typing the address or using a trusted bookmark.

They should never paste a command from a web page, chat, ad, or support message into Terminal unless they fully understand it and have independently verified its source.

Security teams should block the listed infrastructure, investigate unexpected command-line activity launched from browsers, and check Macs for unfamiliar launch items and permission requests.

Resetting passwords alone may not be enough after an infection; affected users should revoke active sessions, rotate exposed keys, and have the device examined for persistence.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
File name9ff32f7c0108e9d27a3b491edf04827b6ca025f44dbIdentified MacSync Mach-O sample file name
SHA-256 hash9ff32f7c0108e9d27a3b491edf04827b6ca025f44db68aMacSync sample hash reported by SEQRITE
MD5 hash9678f71ea4cccbc3d511dc8d7f24b113MacSync sample MD5 hash
SHA-1 hash59508d071661ea70fa5fcbe6f9e2fb72506e57dfMacSync sample SHA-1 hash
Code-signing identifiercom.utils.LauncherAd-hoc-signed MacSync stager identifier
CDHashd182eb7cba0ffa42d770d7b0d3499e49f24163a2Code directory hash associated with the sample
Staged archive/tmp/osalogging.zipTemporary archive used to hold collected data
Status file/tmp/.httpcodeTemporary file used to record server response status
Persistence filecom.google.keystone.plistPossible renamed LaunchAgent persistence file
Persistence filecom.apple.sync.plistPossible renamed LaunchAgent persistence file
C2 domaindrivinguber.comPrimary command-and-control host
C2 domainasia.newsinweb.comRegional fallback command-and-control host
C2 domainusa.newsinweb.comRegional fallback command-and-control host
C2 root domainnewsinweb.comRoot domain used for fallback infrastructure
Download URI/dynamic?txd=c4f70f37daae63fe47b0c92adf006f8cf50b6c522Path used to retrieve the in-memory AppleScript payload
Upload URI/gate?buildtxd=c4f70f37daae63fe47b0c92adf006f8cf50b6Path used for stolen-data uploads
HTTP request headerapi-key: de62a2f47d1c7dec2997f931a050a615API key observed in MacSync network requests
HTTP User-AgentMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) CFN AppleWebKit/537.36User-Agent string used in command-and-control communications

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

The post Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware appeared first on Cyber Security News.

Top 10 Best Server Security Solutions in 2026

Bottom line up front: servers are not big laptops. They run Linux as often as Windows, can’t tolerate agent-induced latency, host the data ransomware actually wants, and increasingly live as VMs, containers, or cloud instances.

Deploying dedicated endpoint detection and response (EDR) on servers requires balancing performance overhead with deep telemetry.

Trend Micro’s server heritage still leads for hybrid estates, CrowdStrike and SentinelOne bring the strongest detection, Defender for Servers wins on Azure-centric economics and the quiet failure mode everywhere is the hypervisor nobody’s agent covers.

Stage 1 — Inventory What “Server” Means for You

Your server realityWhat it changesStrongest fits
Windows Server heavyAny leader works; licensing decidesDefender, CrowdStrike, SentinelOne
Linux-majorityAgent quality varies wildly — testCrowdStrike, SentinelOne, Trend Micro, Uptycs
Legacy OS (2008/2012, old RHEL)Support matrices decide for youTrend Micro, Trellix, Kaspersky*
Virtualized (ESXi/Hyper-V)Guest agents ≠ hypervisor protectionTrend Micro + hardening; see Stage 4
Containers/Kubernetes alongsideYou’re shopping CWPP tooAqua, see CWPP guide
Cloud VMs (AWS/Azure/GCP)Per-hour licensing options appearDefender for Servers, CrowdStrike, Palo Alto

*Kaspersky: prohibited for US sale/updates; check national guidance elsewhere.

The planning fact most miss: server security is licensed differently per server, per core, or per cloud-hour and the same vendor may offer all three. The wrong model can double your bill at renewal.

Stage 2 — The Ten, by Fit

Trend Micro (Deep Security → Server & Workload Protection) — best hybrid breadth

Trend Micro server workload protection virtual patching
Trend Micro server workload protection virtual patching

Two decades of server-specific engineering: virtual patching via IPS (shielding unpatched systems decisive for legacy OS), anti-malware, integrity monitoring, and log inspection, spanning data centre to cloud while bridging endpoint security EDR vs XDR architectures.

Watch: console lineage shows; product naming has shifted into Vision One confirm current SKUs.

Best for: hybrid estates with legacy and modern side by side.

Image ALT: Trend Micro server workload protection virtual patching

CrowdStrike — best detection on servers

CrowdStrike Falcon server and Linux detection
CrowdStrike Falcon server and Linux detection

The same elite detection and hunting, with Linux parity that’s genuinely strong, leveraging proactive threat hunting methodologies and cloud-hour licensing options for elastic estates.

Watch: premium cost; update-staging questions apply to servers doubly.

Best for: SOC-led organizations standardizing one platform across endpoint and server.

Image ALT: CrowdStrike Falcon server and Linux detection

Microsoft Defender for Servers — best Azure-centric economics

Defender for Servers plans in Defender for Cloud
Defender for Servers plans in Defender for Cloud

Per-server (or per-hour via Azure Arc) plans bring EDR, vulnerability management, and file integrity monitoring to Windows and Linux, managed through Defender for Cloud with capabilities that automatically isolate compromised devices and workloads covering AWS and GCP VMs via Arc too.

Watch: plan tiers (P1/P2) differ materially; Linux features trail Windows in places.

Best for: Azure-heavy and Arc-managed hybrid estates.

Image ALT: Defender for Servers plans in Defender for Cloud

Palo Alto Networks — best alongside network controls

Palo Alto server protection with network enforcement
Palo Alto server protection with network enforcement

Cortex agents on servers plus the option of VM-Series inspection in front of them; provides robust defense tested across Palo Alto Cortex XDR platforms and is strongest when server, network, and cloud policy converge in one vendor.

Best for: Palo Alto-standardized estates.

Image ALT: Palo Alto server protection with network enforcement

SentinelOne — best autonomous response on servers

SentinelOne server and Kubernetes protection
SentinelOne server and Kubernetes protection

Autonomous containment matters more where no one’s watching at 3am, utilizing high-efficacy autonomous malware protection solutions where Linux/Kubernetes agents are first-class. Rollback is Windows-only plan accordingly.

Best for: lean teams with big server estates.

Image ALT: SentinelOne server and Kubernetes protection

Sophos — best for generalist-run server rooms

Sophos server protection policy in Sophos Central
Sophos server protection policy in Sophos Central

Server-specific policy (file integrity, application allowlisting for servers) in the same console a small team already runs, with a clear escalation path into managed detection and response (MDR) services.

Best for: mid-market Windows-majority server rooms.

Image ALT: Sophos server protection policy in Sophos Central

Bitdefender — best value with strong engines

Bitdefender GravityZone virtualized server protection
Bitdefender GravityZone virtualized server protection

GravityZone’s server and virtualization support (including agentless options in some hypervisor environments) brings enterprise-grade ransomware protection solutions at mid-market pricing.

Watch: confirm current agentless support matrix.

Best for: virtualization-heavy value buyers.

Image ALT: Bitdefender GravityZone virtualized server protection

Kaspersky — capable where lawful

Kaspersky hybrid server security console
Kaspersky hybrid server security console

Strong engines and legacy-OS support breadth adhering to advanced endpoint threat detection standards but prohibited for sale/updates in the US, with public-sector restrictions elsewhere.

Best for: non-US estates after a jurisdiction check.

Image ALT: Kaspersky hybrid server security console

Trellix — best in an ePO-managed legacy estate

Trellix server security via ePO
Trellix server security via ePO

Deep policy control and long legacy-OS support under ePO management, routing server event logs directly into enterprise SOC tools.

Watch: roadmap conversation warranted post-consolidation.

Best for: existing Trellix estates with old iron.

Image ALT: Trellix server security via ePO

Wiz CNAPP — best for multi-cloud and cloud-native platforms

Wiz CNAPP cloud workload, container, and Kubernetes security platform
Wiz CNAPP cloud workload, container, and Kubernetes security platform

Cloud-native security across cloud infrastructure, workloads, containers, and Kubernetes, providing unified visibility into vulnerabilities, configuration posture, and runtime risk alongside modern cloud security tools.

If your “servers” are mostly cloud workloads and containers, Wiz provides broader cloud context than a traditional server-security agent.

Best for: multi-cloud and cloud-native platforms.

Image ALT: Wiz CNAPP cloud workload, container, and Kubernetes security platform

Stage 3 — Handle the Two Gaps Everyone Has

The hypervisor gap. Guest agents don’t protect ESXi or Hyper-V hosts themselves, and ransomware crews now encrypt at the hypervisor to take fifty VMs down in one action. Mitigate deliberately: strict host patching, isolated management interfaces, MFA on vCenter, lockdown mode, and monitoring of host-level logs. No agent on this list absolves you.

The legacy gap. Unsupported Windows and old Linux hold the business hostage everywhere. Virtual patching (Trend Micro’s signature move) shields them at the network/IPS layer while you plan migrations segment them tightly regardless via microsegmentation.

Stage 4 — Deploy Without Breaking Production

Test agent overhead on your loads, not the datasheet’s. Database, file-server, and hypervisor-dense hosts expose I/O costs that laptops never show. Pilot on the noisy servers.

Stage updates with rings on servers especially. The July 2024 content-update outage taught the whole industry: production servers get the last ring, always, with a documented rollback.

Turn on integrity monitoring where it counts. FIM on domain controllers, payment paths, and web roots is high signal; fleet-wide FIM is noise. Scope it.

Exclusions with discipline. Vendor-documented exclusions for databases and hypervisors, reviewed quarterly not the accumulated folklore of a decade of tickets.

Common mistakes: protecting Windows servers and leaving Linux “for later”; agents on guests, nothing for hosts; per-server licences on autoscaling cloud fleets (use per-hour); and no EDR-tier retention on the machines attackers actually camp on.

Situational FAQ

What is the best server security solution in 2026?

Trend Micro leads hybrid estates with legacy systems thanks to virtual patching; CrowdStrike and SentinelOne bring the strongest detection with true Linux parity; Microsoft Defender for Servers wins Azure-centric economics; Aqua leads when containers dominate.

Match to your OS mix, hypervisor reality, and licensing model.

Do Linux servers need antivirus?

They need protection behavioural EDR more than signature antivirus. Linux hosts are prime ransomware and cryptomining targets precisely because they’re often unmonitored, and agent quality varies more on Linux than anywhere else. Test on your distributions.

How is server security licensed?

Per server, per core, or per cloud-hour, sometimes all three from one vendor. Elastic cloud fleets should use consumption models; static data centres usually do better per-server. Model your renewal before signing.

Does my endpoint EDR cover servers?

The agent usually installs, but server plans differ: FIM, virtual patching, container context, and per-hour licensing live in server SKUs. Running a laptop SKU on a domain controller leaves capability and compliance gaps.

What protects the hypervisor itself?

Hardening, not guest agents: patched hosts, isolated management networks, MFA on management planes, lockdown modes, and host log monitoring. Hypervisor-level encryption events are among the most damaging current ransomware patterns treat hosts as crown jewels.

What about unsupported legacy servers?

Shield them with IPS-based virtual patching (Trend Micro is the reference), segment them aggressively, and monitor them closely while migration happens. “We’ll retire it next year” has been the plan for five years; protect it like it’s staying.

The Short Version

Buy server security as its own decision: Trend Micro for hybrid-with-legacy, CrowdStrike/SentinelOne for detection-led estates, Defender for Servers for Azure economics, Aqua when Kubernetes is the estate.

Then close the two gaps no agent closes hypervisor hardening and legacy segmentation and stage every update like production depends on it, because it does.

Related reading on Cyber Security News:

• Top 10 Best Cloud Workload Protection (CWPP) Solutions

• Top 10 Best CSPM Tools

• Top 10 Best Endpoint Detection & Response (EDR) Solutions

Top 10 Best Ransomware Protection Solutions

• Top 10 Best Microsegmentation Tools

• Top 10 Best Application Control & Allowlisting Tools

• Top 10 Best Patch Management Software

• Top 10 Best Antivirus (Endpoint Protection) Software for Business

• 10 Best Cloud Security Tools

• Top 10 Best Network Detection & Response (NDR) Tools

• Top 10 Best Endpoint Encryption Software

The post Top 10 Best Server Security Solutions in 2026 appeared first on Cyber Security News.

❌