AI agents wage near-autonomous cyberattack on Asian government networks

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">Autonomous AI agents built on open-source frameworks breached Taiwanese government systems, compromised credentials, and probed a nuclear safety agency in a multi-day cyberattack that researchers say signals a new phase in AI-enabled operations.</p> <p class="wp-block-paragraph">The campaign unfolded over four days in early July, during which multiple AI agents operated in parallel to map networks, identify vulnerabilities, and execute intrusion steps across interconnected systems, according to research published by cybersecurity firm Dream.</p> <p class="wp-block-paragraph">“In roughly four days, the agentic attacker produced 1,395 files, 85 cracked credentials, thousands of exfiltrated personnel records, and gained a persistent foothold inside state infrastructure,” Dream wrote in a blog post. “It spells out one thing loudly – the cost of running a competent attack has collapsed, but the cost of defending against one has not.”</p> <p class="wp-block-paragraph">They described the activity as a “near-autonomous attack,” adding that “AI-enabled offensive operations are now at an inflection point.”</p> <h2 class="wp-block-heading" id="taiwan-link-emerges-as-government-flags-ai-assisted-attack">Taiwan link emerges as government flags AI-assisted attack</h2> <p class="wp-block-paragraph">Dream did not identify the affected country but stated that it was “government entities in Asia.” However, Taiwan’s Ministry of Digital Affairs said it detected an “AI agent-assisted” cyberattack targeting government agencies during the same period, according to Reuters, which reported that the activity involved AI-driven tools such as OpenClaw.</p> <p class="wp-block-paragraph">“The relevant attack sources, methods, and scope of impact have all been fully ‌investigated, and ⁠the affected units have successively completed their handling,” the report added, quoting an official from the Ministry of Digital Affairs of Taiwan, though neither Dream nor Taiwanese authorities have explicitly confirmed a link between the two.</p> <p class="wp-block-paragraph">Responding to CSO’s queries, a Dream spokesperson declined to comment on the identity of the target or the attacker and said its research did not find evidence of a confirmed breach of the entity’s systems. “We cannot comment on the identity of the target or attacker. Our report describes the framework at the time of our analysis.” </p> <p class="wp-block-paragraph">The company further said that since the publication of its initial blog post, it has identified evidence indicating the use of a DeepSeek-V4-Flash model within this framework. “We do not know whether it was the only model used,” the spokesperson said.</p> <p class="wp-block-paragraph">The Government of Taiwan did not immediately respond to a request for comment.</p> <h2 class="wp-block-heading" id="multi-agent-system-executes-coordinated-attack-waves">Multi-agent system executes coordinated attack waves</h2> <p class="wp-block-paragraph">The researchers wrote that the attack framework was built on Hermes and OpenClaw agents and deployed multiple sub-agents simultaneously, each assigned to specific targets and tasks across successive attack waves.</p> <p class="wp-block-paragraph">Across 12 attack waves, the agents carried out reconnaissance, credential attacks, and exploitation efforts in parallel, incorporating planning loops and feedback mechanisms.</p> <p class="wp-block-paragraph">This allowed the system to “run an intrusion campaign rather than answer questions about one,” the researchers wrote.</p> <p class="wp-block-paragraph">Colin Ferris, head of threat hunting and incident response at Silverfort, said the use of multiple agents working in parallel reflects how such systems can divide tasks and adapt in real time.</p> <p class="wp-block-paragraph">“AI does to cybersecurity what cheap drones have done to conventional warfare,” Ferris said, adding that attackers can deploy “a handful of inexpensive AI agents to continuously find and exploit the gaps they haven’t fixed yet.”</p> <h2 class="wp-block-heading" id="identity-systems-and-apis-form-initial-entry-points">Identity systems and APIs form initial entry points</h2> <p class="wp-block-paragraph">The campaign began with automated reconnaissance, during which the system mapped government infrastructure by extracting API endpoints and authentication configurations from publicly accessible code, according to the blog post.</p> <p class="wp-block-paragraph">The researchers wrote that the framework identified unauthenticated APIs exposing user data and, in one instance, an entire user database without authentication.</p> <p class="wp-block-paragraph">They added that the system used a combination of techniques to gain access, including exploiting hidden authentication endpoints, conducting credential attacks, and bypassing token validation mechanisms.</p> <p class="wp-block-paragraph">The compromised accounts were then used to move laterally across connected systems through single sign-on integrations.</p> <p class="wp-block-paragraph">Cris Thomas, security advocate at cybersecurity firm Semgrep, said the techniques described are not new, but AI is changing how they are executed.</p> <p class="wp-block-paragraph">“This demonstrates that AI is just a tool, one that defenders and attackers can both use,” Thomas said. “Attackers are going to attack, and they will find a way around a harness and other restrictions.”</p> <h2 class="wp-block-heading" id="campaign-expands-to-supply-chain-and-critical-sectors">Campaign expands to supply chain and critical sectors</h2> <p class="wp-block-paragraph">The researchers wrote that the operation extended beyond initial targets to include supply chain partners, a government email system, and organizations in the energy sector.</p> <p class="wp-block-paragraph">They added that the campaign reached a nuclear safety-related organization, though the report does not identify the country or specify the level of access achieved.</p> <p class="wp-block-paragraph">Ferris said such campaigns highlight how attackers can use widely available tools to scale operations, noting that systems can “research targets, divide responsibilities, and change tactics when blocked.”</p> <h2 class="wp-block-heading" id="growing-concern-over-autonomous-ai-in-cyber-operations">Growing concern over autonomous AI in cyber operations</h2> <p class="wp-block-paragraph">Recent disclosures from AI developers have pointed to similar risks. OpenAI recently <a href="https://www.csoonline.com/article/4207311/openai-says-astra-could-reach-critical-cyber-capability-tightens-safeguards.html">said</a> it cannot rule out that advanced models could autonomously identify and exploit vulnerabilities, while Anthropic has <a href="https://www.csoonline.com/article/4205612/openai-anthropic-ai-agents-resorted-to-deception-in-new-cybersecurity-incidents.html">reported</a> instances of AI agents attempting to access external systems during testing.</p> <p class="wp-block-paragraph">The researchers wrote that safeguards designed to restrict AI behavior were bypassed in the campaign by framing the activity as authorized testing. They added that linguistic analysis suggests the campaign was carried out by a “Chinese-language operator,” though the report does not attribute it to any specific group or country.</p> </div></div></div></div>

2026/8/13
阅读更多

Trump administration opens door to private-sector cyber offensives

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">The Trump administration is opening the door for vetted US companies to conduct cyber operations against foreign cybercriminal organizations under federal supervision, giving the private sector a more direct role in disrupting cyber-enabled crime.</p> <p class="wp-block-paragraph">A presidential <a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/" target="_blank" rel="noreferrer noopener">memorandum</a> issued on August 12 directs the National Coordination Center to create a program authorizing participating companies to conduct cyber surveillance and cyber effects operations against foreign groups engaged in cyber-enabled crime targeting US interests.</p> <p class="wp-block-paragraph">The memorandum says, “any resulting operational action will be exclusively conducted on behalf of and under the supervision of the Federal Government.”</p> <p class="wp-block-paragraph">Companies admitted to the program will have to contract with either the Department of</p> <p class="wp-block-paragraph">Justice or the Department of Homeland Security and undergo government vetting. The memorandum gives officials 60 days to establish operating procedures and requires written approval for every proposed operation before a participating company can act.</p> <p class="wp-block-paragraph">The program could extend well beyond conventional threat monitoring. Cyber surveillance operations involve accessing systems without the owner’s authorization or exceeding authorized access, while cyber effects operations can interfere with systems or infrastructure and may extend to their destruction.</p> <p class="wp-block-paragraph">The memorandum allows participating companies to receive threat information collected by private-sector organizations during normal business activities, which may then be used to propose cyber operations to the National Coordination Center.</p> <h2 class="wp-block-heading" id="the-collateral-damage-problem">The collateral damage problem</h2> <p class="wp-block-paragraph">The arrangement amounts to a limited form of <a href="https://www.csoonline.com/article/573597/u-s-government-offensive-cybersecurity-actions-tied-to-defensive-demands.html">government-authorized private-sector “hack back,”</a> although it differs substantially from companies independently pursuing attackers, said <a href="https://pareekh.com/" target="_blank" rel="noreferrer noopener">Pareekh</a> Jain, CEO of Pareekh Consulting.</p> <p class="wp-block-paragraph">Government control may constrain what participating companies can do, but it does not eliminate the operational risks, Jain said. An incorrectly identified target could belong to an innocent organization or fall under another country’s jurisdiction, while disruptive action could also provoke retaliation against the security company carrying it out.</p> <p class="wp-block-paragraph">“Avoiding collateral damage is extremely hard,” he said. “Cybercriminals often don’t buy their own servers as they hide inside real company networks, hack smart home devices, and rent standard cloud servers using stolen credit cards.”</p> <p class="wp-block-paragraph"><a href="https://omdia.tech.informa.com/authors/jonathan-ong">Jonathan Ong</a>, senior analyst for managed security services at Omdia, said the accountability picture for participating companies also remains unclear.</p> <p class="wp-block-paragraph">“The commercial cyber company has neither immunity nor indemnity that we can see from the memorandum, and does not have the protection from nation-state capabilities that a government agency does,” Ong said.</p> <p class="wp-block-paragraph">As a safeguard, the memorandum says companies must stop an operation and immediately notify the National Coordination Center if they unintentionally target a US person or certain US-linked systems.</p> <p class="wp-block-paragraph">Such steps are useful, Jain said, but their effectiveness will depend on how accurately targets can be identified and on rules that have yet to be developed.</p> <h2 class="wp-block-heading" id="a-new-purpose-for-threat-intelligence">A new purpose for threat intelligence</h2> <p class="wp-block-paragraph">For CISOs, the policy could change how threat intelligence gathered during normal business activities is ultimately used. Data provided by enterprises could feed proposals for government-approved cyber operations.</p> <p class="wp-block-paragraph">“Enterprise CISOs should be careful before feeding telemetry into these programs,” said <a href="https://counterpointresearch.com/en/opinion-leader/10" target="_blank" rel="noreferrer noopener">Neil Shah</a>, vice president for research at Counterpoint Research. “The threat intelligence is used to block and defend, but in the future, if it is used under this framework for monitoring, intelligence, and to actively disrupt and/or destroy, it would be detrimental.”</p> <p class="wp-block-paragraph">Shah said CISOs will also want assurance that information they share does not expose details of their own infrastructure, particularly where systems may already have been compromised by attackers. Data sharing could also raise privacy concerns if it involves deep tracking of customers, he said.</p> <p class="wp-block-paragraph">CISOs should also check whether existing contracts and privacy rules allow such information to be shared if it could later be used for an <a href="https://www.csoonline.com/article/4141989/trumps-cyber-strategy-emphasizes-offensive-operations-deregulation-ai.html">offensive operation</a>, according to Jain.</p> <p class="wp-block-paragraph">Attribution adds another complication. Infrastructure associated with an attack may itself have been compromised, meaning an IP address or server may not identify the attacker behind an intrusion, Jain said.</p> <h2 class="wp-block-heading" id="will-cyber-firms-participate">Will cyber firms participate?</h2> <p class="wp-block-paragraph">The commercial case for participation is another open question.</p> <p class="wp-block-paragraph">“I don’t see the financial incentive for a mega-cap cyber company to undertake the risks,” Ong said. Access to adversary infrastructure could offer intelligence value, but Ong said that information may not necessarily translate into material that can be used for detection engineering or commercial threat feeds.</p> </div></div></div></div>

2026/8/13
阅读更多

It took $58 to break Microsoft’s SCCM, but a patch made it harder

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">Researchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment.</p> <p class="wp-block-paragraph">Enterprises use Microsoft System Center Configuration Manager (<a href="https://www.csoonline.com/article/2089612/open-source-scanner-can-identify-risky-microsoft-sccm-configurations.html">SCCM</a>) to deploy operating systems, manage patches, distribute software, and monitor compliance across large Windows fleets. XM Cyber’s attack can move from an ordinary domain account to code execution as “NT AUTHORITY\SYSTEM” on the primary site server.</p> <p class="wp-block-paragraph">“After the Site Server is compromised, all of its managed clients are compromised as well, which usually means taking over all the company assets,” XM Cyber’s <a href="https://www.linkedin.com/in/omri-baso/" target="_blank" rel="noreferrer noopener">Omri Baso</a> told CSO.</p> <p class="wp-block-paragraph">The revealed attack chain combines four weaknesses, including a broken authorization in the AdminService upload functionality, a path-traversal flaw dubbed “CabSlip,” weak code-signing validation that could be tricked with a $58 commercial certificate, and an unsigned DLL-loading path in the SMS Executive service.</p> <p class="wp-block-paragraph">Microsoft fixed the initial authorization flaw, tracked as <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47301" target="_blank" rel="noreferrer noopener">CVE-2026-47301</a>, in July, but Baso said the remaining links in the chain are not expected to be fully addressed until ConfigMgr 2609, planned for October.</p> <h2 class="wp-block-heading"><a></a>The patch did not patch</h2> <p class="wp-block-paragraph">The initial foothold comes from SCCM’s AdminService API. Its normal extension-upload endpoint checks whether a user has the required permission, but its “chunked-upload” counterpart does not. That allows an authenticated Active Directory user to submit a malicious CAB archive without SCCM administrative privileges.</p> <p class="wp-block-paragraph">Microsoft’s July fix blocks that route for standard domain users. However, the downstream chain remains reachable through another path. Users assigned the built-in Operations Administrator role, or a custom role with Create permission on “SMS_ConsoleExtensionData,” can still trigger the same sequence.</p> <p class="wp-block-paragraph">But there is an important qualification here. XM Cyber said it believes organizations are unlikely to be exposed through the Operations Administrator route because it is already a highly privileged role.</p> <p class="wp-block-paragraph">Once the CAB reaches the server, CabSlip allows files to escape the intended temporary extraction directory and be written elsewhere on the filesystem. The attacker can use this arbitrary file-write capability to replace “adsource.dll,” a secondary library loaded by the SYSTEM-level SMS Executive service without its own signature check.</p> <p class="wp-block-paragraph">When the service subsequently loads the DLL, the attacker gets code execution as SYSTEM.</p> <h2 class="wp-block-heading"><a></a>A $58 certificate can cross the trust boundary</h2> <p class="wp-block-paragraph">The chain becomes particularly notable because SCCM’s signature validation does not establish that the signing certificate belongs to Microsoft or the target organization. It checks that the signature is structurally valid and non-expired, while revocation checks are disabled.</p> <p class="wp-block-paragraph">That means an attacker does not need an enterprise certificate. XM Cyber said the attack depends on a code-signing certificate and can also abuse certificates leaked online. For his own research, Baso used a Certum Open Source Developer Certificate that cost about $58.</p> <p class="wp-block-paragraph">For defenders, XM Cyber recommends restricting network access to the AdminService API and auditing SCCM <a href="https://www.csoonline.com/article/572177/what-is-rbac-role-based-access-control-explained.html">RBAC</a> assignments, particularly accounts with the Operations Administrator role or equivalent Create permissions.</p> <p class="wp-block-paragraph">Teams should also monitor the Site Server’s “AdminService.log” for a “System.IO.DirectoryNotFoundException” followed by an HTTP 500 response, a pattern that can indicate the path traversal was triggered, XM Cyber added.</p> <p class="wp-block-paragraph">Unexpected modifications to adsource.dll in the Configuration Manager installation directory can provide another detection signal.</p> <p class="wp-block-paragraph">Microsoft is reportedly working on patches for the remaining flaws. It did not immediately respond to CSO’s request for comment.</p> </div></div></div></div>

2026/8/13
阅读更多

Microsoft wants you to rethink your approach to cyber defense

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">Cyber defenders need to shake off traditional best practices and switch from reactive patching to building inherently resilient systems in the face of AI-accelerated vulnerability discovery, according to a senior security manager at Microsoft.</p> <p class="wp-block-paragraph">David Weston, group manager in the Windows team at Microsoft, told delegates at Black Hat USA that traditional approaches to <a href="https://www.csoonline.com/article/526536/vulnerability-management-the-basics.html">vulnerability remediation</a> fail to work in an era when AI tools are making vulnerability discovery and exploit development cheaper, faster, and more scalable.</p> <p class="wp-block-paragraph">Weston’s keynote — entitled “<a href="https://blackhat.com/us-26/features/schedule/index.html?track%5b%5d=keynotes&amp;track%5b%5d=main-stage#keynote-the-end-of-rare-defending-when-offense-is-cheap-56597">The End of Rare: Defending When Offense Is Cheap</a>” — challenged industry vulnerability best practices that Weston said where from a time when developing exploits and mounting attacks was time consuming and expensive. That’s no longer the case, he said.</p> <p class="wp-block-paragraph">As evidence, Weston explained how the Microsoft Security Response Center (MSRC) is doubling the number of vulnerabilities it processes and patches every six weeks. “That is an incredible number,” he said. “We’re nine times the vulnerability volume that we were in March.”</p> <p class="wp-block-paragraph">The accelerating pace of vulnerability discovery is “highly correlated” to rising use of increasingly capable AI tools, and presents a cross-industry problem, he said.</p> <p class="wp-block-paragraph">“These are serious vulnerabilities, the kind that I used to take a year to bespoke craft,” Weston pointed out. “They’re being spit out at industrial speed, and it’s not [just] Windows. You look at Linux, you look at any other operating system out there, I think you’ll see a pretty strong correlation.”</p> <p class="wp-block-paragraph"><a href="https://www.csoonline.com/article/4180467/microsoft-wants-to-put-ai-agents-on-a-short-leash.html">Microsoft’s MDASH</a>, short for Multi-model Agentic Scanning Harness, found roughly 200 Linux kernel vulnerabilities in the company’s internal Azure Linux distribution that Microsoft is working with the community to fix.</p> <p class="wp-block-paragraph">Microsoft also added a new module to MDASH to help its engineers triage vulnerabilities. The technology is capable of turning a static analysis result into proof-of-concept exploit code.</p> <p class="wp-block-paragraph">“That’s worked much better than we ever thought,” said Weston, who leads Microsoft’s AI vulnerability-discovery and frontier-model research. “Of the 200 vulnerabilities, we can automatically generate 182 crash-level POCs. Many of them are fully working exploits. I’m talking root exploits automatically spit out from vulnerability.”</p> <p class="wp-block-paragraph">The average computing cost of detecting those vulnerabilities and generating their exploits was just $3.61, with a time to generation of 21 minutes.</p> <p class="wp-block-paragraph">Microsoft’s work provides further evidence that developing an exploit from a security vulnerability is not likely a factor holding back any attackers with access to advanced AI-based security tools.</p> <p class="wp-block-paragraph">“By the end of the year, we’ll be looking at automatic exploit generation being pretty commonplace and pretty commodity,” Weston warned.</p> <h2 class="wp-block-heading" id="traditional-mitigations-failing">Traditional mitigations failing</h2> <p class="wp-block-paragraph">Nondeterministic mitigations that introduce randomness or unpredictability, such as ASLR (Address Space Layout Randomization), may continue to be an obstacle for attackers but are not likely to stem the rising tide of AI-mediated vulnerability discovery for long.</p> <p class="wp-block-paragraph">Enterprises have historically relied heavily on threat detection for defense, but that layer of protection assumes attackers face cost and time challenges in changing the tools and techniques they use. Those comforting assumptions are also being undermined by AI, Weston said.</p> <p class="wp-block-paragraph">The idea used to be that it’s “super expensive to code a framework or an implant, so people just keep using packers and obfuscation tools on the same stuff, and they keep using the same TTP, so we’ll work against that. And that’s gonna give us durability in detection,” Weston said.</p> <p class="wp-block-paragraph">“Instead of having to retrain the operator, which would have been expensive for cyber operations, we can just use autonomous operations,” he noted of attackers’ evolving mentality. “Instead of obfuscating, we can create a bespoke set of tools or frameworks per target.”</p> <h2 class="wp-block-heading" id="how-to-turn-the-table-on-attackers">How to turn the table on attackers</h2> <p class="wp-block-paragraph">In response to the changing economics of security, the industry must adopt memory-safe computer programming languages such as Rust alongside the use of AI-based tools to improve the resilience of existing code bases.</p> <p class="wp-block-paragraph">“We don’t wanna go vulnerability for patch,” Weston argued. “We don’t want to go exploit for detection, evasion for detection. Hand-to-hand combat with attackers will cause us to lose in defense.”</p> <p class="wp-block-paragraph">About 70% of vulnerabilities that are patched today, at least by the major vendors, are memory safety issues. Safer computer programming languages, such as Rust and Golang, “eliminate those,” according to Weston. For example, <a href="https://blog.google/security/rust-in-android-move-fast-fix-things/">Google reduced memory safety flaws</a> from 76% of Android vulnerabilities in 2019 to below 20% in 2025 after it switched to Rust.</p> <p class="wp-block-paragraph">More recently, Microsoft rewrote the Azure hypervisor, the software that isolates virtual machines from one another, using Rust, and scaled it across 1.5 million virtual machines without any adverse incident.</p> <p class="wp-block-paragraph">A project from the <a href="https://www.darpa.mil/news/2024/memory-safety-vulnerabilities">Defense Advanced Research Projects Agency</a>, called Tractor, automates the conversion of legacy C code into Rust. Microsoft Research’s <a href="https://www.microsoft.com/en-us/research/publication/rustassistant-using-llms-to-fix-compilation-errors-in-rust-code/">AI-based project RustAssistant,</a> introduced last year, uses AI-based technology to detect and suggest remedies for Rust compilation errors.</p> <p class="wp-block-paragraph">Weston added: “We can shift left and make more secure software. That’ll limit vulnerability.”</p> <p class="wp-block-paragraph">Detection of attacks is still important but no longer sufficient. Both enterprises and vendors should be investing in durability.</p> <p class="wp-block-paragraph">“We can move to more prevention mechanisms,” Weston said. “And we can use secure by construction and even formal methods to get the deterministic safety. If we can do that along a realistic timeline, then we can turn the tables and drive this problem towards attackers.”</p> <h2 class="wp-block-heading" id="vulnerability-research-in-the-age-of-ai">Vulnerability research in the age of AI</h2> <p class="wp-block-paragraph">Yan Shoshitaishvili, an associate professor at Arizona State University and well-known vulnerability researcher, presented a Black Hat USA keynote on how <a href="https://www.csoonline.com/article/4207666/the-future-of-ai-security-research-isnt-autonomous-its-human-amplified.html">agentic AI is drastically reducing</a> the cost and time required to discover and exploit vulnerabilities.</p> <p class="wp-block-paragraph">The talk — “<a href="https://blackhat.com/us-26/features/schedule/index.html?track%5b%5d=keynotes#keynote-vulnerability-research-in-the-agentic-age-55627">Vulnerability Research in the Agentic Age</a>” — offered a companion piece to Weston’s presentation. AI tools have shifted the human skills in bug hunting toward developing better search strategies, validation pipelines, and exploitability checks.</p> <p class="wp-block-paragraph">“Going from asking GPT to find bugs, to having an agentic pipeline that’s vulnerability-aware requires human innovation, human understanding of the threat models, of the vulnerability space,” Shoshitaishvili said.</p> <p class="wp-block-paragraph">He and his research student Hong Kai Chen applied these techniques to a study on OpenHarmony, the open-source foundation behind parts of Huawei’s commercial HarmonyOS ecosystem for mobile devices.</p> <p class="wp-block-paragraph">“We found dozens of flaws, ranging from Bluetooth, device takeovers, to privacy leaks, location, all of this, very fun stuff, in Open Harmony, because we started from the vulnerability properties that we extracted from Android bugs,” Shoshitaishvili said. “Now we’re doing this agentically, and the results are incredible.”</p> <p class="wp-block-paragraph">With agentic pipelines, Shoshitaishvili’s team is finding vulnerabilities far faster than they can responsibly disclose with accompanying documentation and proposed fixes.</p> <p class="wp-block-paragraph">Shoshitaishvili tested the “just rewrite everything in Rust” idea using agentic code generation on a Rust rewrite of <code>coreutils</code> shipped with Ubuntu. His team found that memory-safety bugs (buffer overflows, use-after-free) were largely gone but logic vulnerabilities, such as time-of-check–time-of-use (TOCTOU) races and cryptographic, reappeared.</p> <p class="wp-block-paragraph">Rewriting in a safer language removes some classes of bugs but not the underlying design-level weaknesses unless active steps to rewrite problematic code are undertaken, Shoshitaishvili concluded.</p> </div></div></div></div>

2026/8/13
阅读更多

Researcher bypasses Microsoft Defender security patch, seizing control

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent bypass that provides system-level control to attackers once they gain any level of access. </p> <p class="wp-block-paragraph">The researcher, who goes by the name Nightmare Eclipse, has been engaged in a <a href="https://www.csoonline.com/article/4178869/microsoft-and-security-researchers-dueling-posts-about-cybersecurity-disclosures-get-nasty.html" target="_blank">long-running battle with Microsoft Security</a>. </p> <p class="wp-block-paragraph">Nightmare Eclipse has not provided the further details we requested, however Microsoft sent a brief statement, saying, “Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims,” and reiterating its commitment to investigating issues and supporting coordinated disclosure.</p> <p class="wp-block-paragraph">But the proof of concept (PoC) security bypass, ShieldBreak, <a href="https://github.com/MSNightmare/ShieldBreak" target="_blank" rel="noreferrer noopener">described by Nightmare Eclipse</a> in <a href="https://git.projectnightcrawler.dev/NightmareEclipse/ShieldBreak" target="_blank" rel="noreferrer noopener">a series of</a> public <a href="https://git.churchofmalware.org/Nightmare_Eclipse/ShieldBreak" target="_blank" rel="noreferrer noopener">posts</a>, potentially threatens to be more damaging than earlier bypass. </p> <p class="wp-block-paragraph">Like other <a href="https://www.csoonline.com/article/4205751/enterprise-passkey-security-under-threat-from-malware-2.html" target="_blank">recently reported vulnerabilities</a>, ShieldBreak requires an attacker to first somehow gain system access, typically via a successful phishing scam. Once in, however, the attacker can gain full admin/root access.</p> <p class="wp-block-paragraph">But there is a troubling psychological component to ShieldBreak, in that it is a bypass for a recently posted security patch from Microsoft, noted <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence.  The problem is that CISOs who have already deployed that patch might feel protected when they are not.</p> <p class="wp-block-paragraph">“This one is concerning because the patch bypass directly calls the integrity of the remediation into question,” he said. “ShieldBreak appears to demonstrate that an attacker can bypass the fix Microsoft shipped for CVE-2026-50656 and ultimately obtain system-level privileges on the endpoint. That is an important distinction for enterprise defenders, because organizations may believe they have already remediated the underlying vulnerability. A successful patch bypass means the exposure can persist even after the normal vulnerability-management process says the system is protected.”</p> <p class="wp-block-paragraph">Greis added that such bypass can reduce overall trust in official patches. </p> <p class="wp-block-paragraph">“When public proof of concept code can bypass it, the CISO’s question becomes ‘have we actually removed the exposure?’ rather than simply ‘have we deployed the patch?’,” he said. “From an architecture perspective, organizations should be very careful about allowing the same security product to become both the control being relied upon and the only source of evidence that the control is working.”</p> <p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group, said he was especially concerned about the timing of the PoC’s release, given that it seemed to be intended to put the most pressure on Microsoft, given its <a href="https://www.csoonline.com/article/4208185/patch-tuesday-august-2026-a-zero-day-winsock-driver-hole-under-exploit-and-a-maximum-severity-sap-vulnerability.html" target="_blank">typical timing for security patches</a>. </p> <p class="wp-block-paragraph">“This vulnerability, if valid, would need a fix from Microsoft, but because those patches are usually only released on the second Tuesday of the month and the security researcher seems to have carefully timed the release of the PoC, we may have this exposure for another 4 weeks unless Microsoft deems this a very high severity risk, which is unlikely,” he pointed out.</p> <p class="wp-block-paragraph">Cybersecurity consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, agreed that CISOs should not underestimate the damage potential if this PoC proves valid. </p> <p class="wp-block-paragraph">“What makes it dangerous is what it does once they’re in: it turns an ordinary low-privilege account into full system control by abusing Defender itself, the security tool running at the highest privilege on the box,” he said. “An exploit that lives inside your antivirus is quiet, it’s trusted, and it can be used to blind or disable the very thing you’re counting on to catch the intruder. It’s not a worm, but it’s a near-ideal second stage for ransomware crews and anyone doing hands-on-keyboard intrusion.”</p> <p class="wp-block-paragraph">Levine suggested that CISOs not wait for a Microsoft fix, but immediately take an aggressive defensive stance.</p> <p class="wp-block-paragraph">“Assume it’s live and lean on defense in depth, because this is exactly the scenario where treating Defender as your only line fails you. Application allowlisting, such as WDAC or AppLocker in enforced mode, is the strongest hardening available and can stop the payload even if the race succeeds,” Levine said. </p> <p class="wp-block-paragraph">“Tighten local admin rights and least privilege so a foothold has less to escalate from. And give your hunters one very specific thing to watch for: an interactive shell or scripting host running as system whose parent process is Defender’s engine, MsMpEng.exe. That should never happen in a healthy environment and it’s a high-fidelity sign someone is running this.”</p> <p class="wp-block-paragraph">But he also suggested that CISOs not assume that the PoC necessarily works as advertised. </p> <p class="wp-block-paragraph">“This is a single researcher’s proof of concept. It hasn’t been independently verified, and it’s coming from someone in the middle of a very public and very bitter fight with Microsoft, so perhaps some of the theater around it should be discounted,” Levine said. “But you can’t wave it away either. Patch bypasses are extremely common, and the claim that Microsoft’s fix for RoguePlanet didn’t fully close the door is entirely plausible. Defenders should treat it as credible until proven otherwise, not the reverse.”</p> <p class="wp-block-paragraph">Although Levine and other analysts were initially dubious, there are now indications that the PoC’s effectiveness has been independently verified. </p> <p class="wp-block-paragraph">Cybersecurity and risk advisor <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, a former cybersecurity risk specialist at Walmart, said, “I’ve seen <a href="https://cyberplace.social/@GossiTheDog/117082623896479140" target="_blank" rel="noreferrer noopener">independent confirmation</a> that ShieldBreak works, although its exploitation method differs materially from the original RoguePlanet exploit. RoguePlanet relied on a filesystem race condition, while ShieldBreak appears to use a different Defender/Cloud Filter API path,” Fisher said. “So while it is being characterized as a bypass of Microsoft’s CVE-2026-50656 fix, it is not simply a replay of the original exploit.”</p> <p class="wp-block-paragraph">He added that cybersecurity researcher Kevin Beaumont has already published <a href="https://github.com/GossiTheDog/ThreatHunting/blob/master/AdvancedHuntingQueries/ShieldBreak.kql" target="_blank" rel="noreferrer noopener">Microsoft Defender Advanced Hunting detections</a> for ShieldBreak that organizations can incorporate into monitoring while evaluating their exposure.</p> <p class="wp-block-paragraph">And <a href="https://www.linkedin.com/in/pieter-arntz-04164b2/" target="_blank" rel="noreferrer noopener">Pieter Arntz</a>, malware intelligence researcher at Malwarebytes, also said he has seen confirmation from a researcher he tracks, <a href="http://and%20peter%20arntz,%20malware%20intelligence%20researcher%20at%20malwarebytes,%20said%20he%20has%20seen%20confirmation%20from%20a%20researcher%20he%20tracks%20named%20will%20dormann.https//infosec.exchange/@wdormann/117079587486018149" target="_blank" rel="noreferrer noopener">Will Dormann</a>.</p> <p class="wp-block-paragraph"><em>This article has been updated with a statement from Microsoft and further confirmation of the exploit.</em></p> <p class="wp-block-paragraph"></p> </div></div></div></div>

2026/8/12
阅读更多

Fake CCleaner downloads turn Chrome into a credential-stealing surveillance tool

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">A convincing fake version of the widely used CCleaner utility is being used to deliver a multi-stage Windows malware that ultimately abuses Google Chrome for credential theft and surveillance.</p> <p class="wp-block-paragraph">Researchers from Malwarebytes found the campaign distributing a malicious Chrome extension called GhostDesk, which can capture credentials, cookies, keystrokes, and screenshots while also allowing attackers to inject arbitrary JavaScript into active browser tabs.</p> <p class="wp-block-paragraph">Attackers created a lookalike CCleaner download site and used it to distribute a malicious “CCleaner.exe,” researcher <a href="https://www.linkedin.com/in/sav-wheeler-80b1b2271/" target="_blank" rel="noreferrer noopener">Sav Wheeler</a> said in a blog <a href="https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware" target="_blank" rel="noreferrer noopener">post</a>.</p> <p class="wp-block-paragraph">Alongside GhostDesk, the researchers also identified fake 7-zip and Adobe Acrobat applications using the same techniques and command-and-control (C2) infrastructure.</p> <p class="wp-block-paragraph">CCleaner is a popular Windows PC cleaner <a href="https://www.ccleaner.com/ccleaner/download?srsltid=AfmBOoqFWtpR8d9AueS7Z9YLHF3ZQfXMcJEs6EFT_E1cgyCfEgSgt4Xy">utility</a>, with more than 2 billion downloads worldwide. Wheeler said “the executable (fake CCleaner) initially drops a legitimate instance of CScript, then uses it to launch a series of (malicious) scripts.”</p> <h2 class="wp-block-heading"><a></a>A fake cleaner with a multi-stage payload</h2> <p class="wp-block-paragraph">The attack begins when a victim downloads the fake CCleaner executable file from the impersonated site “ccleanerwind[.]top.” Malwarebytes found that both the site’s regular and “Cleaner Pro” download buttons delivered the same malicious file.</p> <p class="wp-block-paragraph">When executed, “cscript.exe” runs a series of scripts carrying out basic system reconnaissance like collecting the machine GUID, hostname, and supported languages. It then replaces “runtimebroker.dll” in the user’s AppData directory with a reflexive loader and modifies Chrome’s Security Extension manifest.</p> <p class="wp-block-paragraph">This modification allows the attacker to inject two JavaScript files, “background.js” and “content.js,” that run as a malicious extension whenever Chrome starts. The resulting malware Malwarebytes tracks as GhostDesk.</p> <p class="wp-block-paragraph">While content.js was seen recording keystrokes and scanning submitted forms for credentials, authentication tokens, and financial information, background.js provided cookie theft, screenshot capture, and arbitrary <a href="https://www.csoonline.com/article/4168568/13-new-critical-holes-in-javascript-sandbox-allow-execution-of-arbitrary-code.html">JavaScript</a> execution.</p> <p class="wp-block-paragraph">content.js was also found capable of monitoring clipboard activity and replacing cryptocurrency addresses when victims paste them into websites.</p> <p class="wp-block-paragraph">background.js provides persistence as it communicates through a WebSocket relay and can re-establish that connection when Chrome starts, Wheeler pointed out.</p> <h2 class="wp-block-heading"><a></a>The campaign is bigger than GhostDesk</h2> <p class="wp-block-paragraph">The campaign’s impact was traced beyond users who specifically searched for CCleaner. Malwarebytes found fake 7-zip and Adobe Acrobat samples using the same CScript loading mechanism, with the samples communicating with the same C2 at “liderongrade.duckdns[.]org.”</p> <p class="wp-block-paragraph">The only difference observed was some Adobe samples using “wscript.exe” instead of cscript.exe, likely attackers attempting to adapt delivery to different software, Wheeler noted.</p> <p class="wp-block-paragraph">The combination of browser cookies, credentials, keystrokes and screen captures <a href="https://www.csoonline.com/article/4198788/new-acr-stealer-campaigns-use-webdav-mshta-to-evade-detection.html">makes</a> the compromise concerning for enterprises and worth setting protections against. Captured authentication tokens and financial information add further risk.</p> <p class="wp-block-paragraph">Malwarebytes recommended checking the web address carefully before downloading software, noting that sponsored search results can be abused by cybercriminals. It also advised treating software download links shared through social media, SMS and email with caution, and verifying downloads against trusted sources such as the publisher’s official website or app stores.</p> <p class="wp-block-paragraph">The company also recommended using an up-to-date, real-time anti-malware solution with web protection. The one from Malwarebytes blocks connections to unsafe sites such as the fake CCleaner landing page and detects the fake installer as “Trojan.Dropper,” it added.</p> <p class="wp-block-paragraph">Keeping the operating system, browser, and security software up to date remains a must.</p> </div></div></div></div>

2026/8/12
阅读更多

4 gaps slowing AI in enterprise SOCs

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">Artificial intelligence (AI) has quickly become a strategic priority for enterprise security teams. Yet despite growing investment in AI-driven security software, many enterprise SOCs are struggling to translate AI into measurable operational improvements.</p> <p class="wp-block-paragraph">The issue isn’t whether AI belongs in the SOC. It does.</p> <p class="wp-block-paragraph">The challenge is that many organizations are approaching AI adoption in cybersecurity without a clear operational strategy. Instead of reducing analyst workload and improving response times, new AI initiatives often introduce additional complexity, fragmented workflows, and uncertainty.</p> <p class="wp-block-paragraph">Enterprise security operations leaders don’t need more AI. They need AI that fits into the way their SOC already works while creating a practical path toward greater automation.</p> <p class="wp-block-paragraph">Here are the four adoption gaps slowing enterprise SOC AI security operations today – and what successful organizations are doing differently.</p> <h2 class="wp-block-heading" id="gap-1-trust-and-explainability">Gap #1: Trust and explainability</h2> <p class="wp-block-paragraph">For most enterprise security leaders, the biggest obstacle isn’t technology – it’s trust.</p> <p class="wp-block-paragraph">Security teams operate in highly regulated environments where every investigation, alert, and response decision may need to be explained to auditors, executives, or regulators. If an AI platform simply produces an answer without showing how it reached that conclusion, analysts are forced to choose between accepting a black-box recommendation or redoing the investigation manually.</p> <p class="wp-block-paragraph">Neither outcome improves security operations management. Successful AI implementations prioritize explainability. Analysts should be able to see:</p> <ul class="wp-block-list"> <li>Every data source consulted</li> <li>Every investigative step performed</li> <li>How conclusions were reached</li> <li>Where human validation is expected</li> </ul> <p class="wp-block-paragraph">When AI provides transparent reasoning instead of opaque automation, analysts gain confidence in the platform while maintaining accountability for final decisions. Human expertise remains in control, with AI accelerating the investigative process rather than replacing it.</p> <h2 class="wp-block-heading" id="gap-2-skills-and-workflow-gaps">Gap #2: Skills and workflow gaps</h2> <p class="wp-block-paragraph">Most enterprise SOCs have spent years developing playbooks, runbooks, and operational processes.</p> <p class="wp-block-paragraph">The question isn’t whether those investments should be replaced. <a href="https://www.csoonline.com/article/4198016/socs-face-a-human-challenge-as-ai-speeds-alerts-and-threats.html">It’s how they evolve</a>.</p> <p class="wp-block-paragraph">Many organizations assume adopting AI means rebuilding workflows from scratch or asking security engineering teams to develop custom AI capabilities internally. Others delay adoption because they aren’t sure where AI should fit into existing analyst processes.</p> <p class="wp-block-paragraph">This creates unnecessary friction.</p> <p class="wp-block-paragraph">A more practical approach is to augment existing workflows rather than replace them. Start with the highest-value use cases, automate repetitive investigative tasks, and expand capabilities incrementally.</p> <p class="wp-block-paragraph">Think of AI adoption as a crawl, walk, run strategy:</p> <ul class="wp-block-list"> <li>Begin with your most critical systems.</li> <li>Automate repetitive investigations first.</li> <li>Expand integrations over time.</li> <li>Allow analysts to learn alongside the technology.</li> </ul> <p class="wp-block-paragraph">This approach not only accelerates adoption but also develops stronger analysts. When AI shows each investigative step, teams continue building security expertise instead of becoming overly dependent on automation.</p> <h2 class="wp-block-heading" id="gap-3-fragmented-security-tools-and-data">Gap #3: Fragmented security tools and data</h2> <p class="wp-block-paragraph">One of the biggest SOC team challenges has nothing to do with AI itself. It’s the sheer number of tools.</p> <p class="wp-block-paragraph">Enterprise analysts often spend more time pivoting between dashboards than investigating incidents. SIEMs, EDR platforms, vulnerability management systems, identity tools, cloud security platforms, ticketing systems, and collaboration platforms all contain valuable context, but rarely present it together.</p> <p class="wp-block-paragraph">Many AI initiatives attempt to solve this by first consolidating everything into a security data lake or retraining large language models on centralized datasets. While valuable for some organizations, those projects can take months or even years to complete.</p> <p class="wp-block-paragraph">A faster approach is to <a href="https://andesite.ai/blog/cybersecurity-needs-a-new-data-architecture/">unify access rather than relocate the data</a>.</p> <p class="wp-block-paragraph">Instead of forcing organizations into lengthy migration projects, modern AI platforms can securely connect existing security technologies, allowing analysts to query multiple systems through natural language while leaving data where it already resides.</p> <p class="wp-block-paragraph">Rather than navigating ten different interfaces, analysts gain a unified operational view across their existing environment. That dramatically reduces investigation time while protecting previous technology investments.</p> <h2 class="wp-block-heading" id="gap-4-governance-without-operational-strategy">Gap #4: Governance without operational strategy</h2> <p class="wp-block-paragraph">Many organizations recognize they need AI. Fewer have established governance around how AI should actually be used inside the SOC.</p> <p class="wp-block-paragraph">Without clear governance, AI initiatives often focus on implementing technology rather than solving operational problems. Teams deploy automation without defining analyst oversight, approval processes, or success metrics.</p> <p class="wp-block-paragraph">Effective AI governance starts with a simple question: What operational problem are we trying to solve?</p> <p class="wp-block-paragraph">From there, security leaders can establish guardrails that ensure AI supports human decision-making instead of replacing it.</p> <p class="wp-block-paragraph">Strong governance includes:</p> <ul class="wp-block-list"> <li>Clearly defined analyst oversight</li> <li>Transparent decision-making</li> <li>Incremental automation</li> <li>Measurable operational outcomes</li> <li>Continuous review of workflow effectiveness</li> </ul> <p class="wp-block-paragraph">The goal isn’t autonomous security. It’s trusted security operations supported by intelligent automation.</p> <h2 class="wp-block-heading" id="turning-ai-into-operational-value">Turning AI into operational value</h2> <p class="wp-block-paragraph">Successful enterprise SOC AI security operations don’t begin with replacing existing technology. They begin by making existing technology work together.</p> <p class="wp-block-paragraph">Organizations seeing the greatest value from AI are focusing on:</p> <ul class="wp-block-list"> <li>Unifying security data without massive migration projects</li> <li>Preserving existing investments while reducing operational complexity</li> <li>Giving analysts a single conversational interface across security tools</li> <li>Automating documentation and investigation summaries</li> <li>Providing explainable AI that strengthens analyst decision-making</li> </ul> <p class="wp-block-paragraph">Instead of asking analysts to jump between dozens of consoles, modern AI can surface relevant context, correlate findings across multiple systems, document investigative actions automatically, and generate incident summaries that are ready for ticketing or collaboration platforms.</p> <p class="wp-block-paragraph">The result isn’t simply more automation. It’s faster investigations, stronger analyst productivity, and security operations management that scales with the growing complexity of today’s enterprise environments.</p> <h2 class="wp-block-heading" id="the-path-forward">The path forward</h2> <p class="wp-block-paragraph">AI adoption in cybersecurity is <a href="https://www.csoonline.com/article/4175349/ai-becoming-an-soc-imperative-for-curtailing-emerging-cyber-threats.html">no longer a question of if but how</a>.</p> <p class="wp-block-paragraph">Enterprise security leaders don’t need to rebuild their SOCs overnight or replace every existing platform. They need an approach that respects existing investments, integrates with current workflows, and builds analyst confidence through transparency.</p> <p class="wp-block-paragraph">Organizations that address the four gaps are positioned to move beyond AI experimentation and toward measurable security operations outcomes.</p> <p class="wp-block-paragraph">Because the future of AI in the enterprise SOC isn’t about replacing analysts. It’s about giving them the visibility, context, and automation they need to make better security decisions, faster.</p> </div></div></div></div>

2026/8/12
阅读更多

The AI harness is the new attack surface

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">Ask a security researcher what makes an AI agent dangerous, and the instinct is to talk about the model — what it will and won’t refuse, how easily it can be jailbroken, whether its weights can be trusted.</p> <p class="wp-block-paragraph">That instinct is increasingly out of date. A growing body of security research — exploit demonstrations, independent red-teaming, and assessments by security researchers— points to the code sitting between the model and the world instead.</p> <p class="wp-block-paragraph">That code, increasingly called the harness, wraps the model, gives it tools, and turns its token-by-token output into a shell command, a file write, an API call. It is also under-inventoried, under-tested, and frequently under-owned inside enterprises.</p> <p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/eladmeged/">Elad Meged</a>, founding engineer and security researcher at Novee Security, <a href="https://novee.security/blog/critical-flaws-in-anthropic-google-and-openais-coding-agents/">broke into the official automation repositories</a> of Anthropic, Google, and OpenAI using nothing more than GitHub issues.</p> <p class="wp-block-paragraph">Researchers at Lasso Security <a href="https://www.lasso.security/blog/claude-agent-sdk-vs-deepagents-agent-harness-red-teaming">found that swapping one piece</a> of supposedly neutral agent plumbing for another moved a model’s attack success rate from 1% to 24% — using the identical model, prompt, and tools.</p> <p class="wp-block-paragraph">And <a href="https://www.linkedin.com/in/michaelbargury/">Michael Bargury</a>, co-founder and CTO of AI security firm Zenity, found attackers hiding credential-stealing malware <a href="https://www.csoonline.com/article/4204731/attackers-are-crafting-malicious-ai-instruction-files-to-turn-your-agentic-workflows-into-quiet-criminal-helpers.html">inside AI “skills”</a> that had already passed every scanner on the market, including official ones from Anthropic and Cisco.</p> <p class="wp-block-paragraph">The failures are different, but they share an important characteristic: None requires a model to become malicious or even behave unexpectedly. They exploit the software around it — the layer that determines what the model can see, what it can touch, and what happens when it acts.</p> <p class="wp-block-paragraph">That’s why a growing number of AI security researchers argue that the harness needs to be treated as an attack surface in its own right, rather than invisible scaffolding that arrives with the model.</p> <h2 class="wp-block-heading" id="what-a-harness-actually-is">What a ‘harness’ actually is</h2> <p class="wp-block-paragraph">Ask practitioners to define a harness and the metaphors converge from different directions.</p> <p class="wp-block-paragraph">Bargury tells CSO he calls it the model’s “hands and legs and eyes.” The model itself produces tokens in and tokens out; the harness turns those tokens into a shell command, a file write, or an API call.</p> <p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/leerob/">Rob T. Lee</a>, chief AI officer and chief of research at the SANS Institute, describes the model as the engine and the harness as the chassis. <a href="https://www.linkedin.com/in/michael-sromin-33548a60/">Michael Sromin</a>, senior ML engineer at Lasso Security, likens it to the operating system of the agent, running the agent’s loop and connecting the model, tools, and user. “I see it as … an operating system that operates this entire … infinite loop of the agentic application,” he tells CSO.</p> <p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/santosomar/">Omar Santos</a>, distinguished engineer at Cisco, offers a more formal definition.</p> <p class="wp-block-paragraph">“An AI harness is the layer that surrounds a model and makes it useful,” Santos tells CSO. “This includes orchestration, tool use, prompts, context, roles, evals, guardrails, and the operational workflow that turns raw model output into bounded, repeatable action.”</p> <p class="wp-block-paragraph">The descriptions all point to the same security problem, namely that the harness is where an agent’s authority gets exercised. It sits between a model’s reasoning and a real filesystem, API key, or production database.</p> <p class="wp-block-paragraph">“Security teams should treat the harness as an attack surface because it is where the agent gets its authority, context, and paths to act,” Santos says.</p> <p class="wp-block-paragraph">And harness code has vulnerabilities just like any other software.</p> <p class="wp-block-paragraph">A perfectly aligned model can sit inside a harness that trusts a wildcard shell pattern or reuses a workspace across two passes of untrusted content. At that point, the model’s alignment is largely beside the point. The vulnerability isn’t in the model.</p> <h2 class="wp-block-heading" id="three-failure-modes-one-attack-surface">Three failure modes, one attack surface</h2> <p class="wp-block-paragraph">Some of the most detailed research this year has exposed three distinct ways harnesses fail: architectural trust boundaries, implementation choices, and supply-chain compromise.</p> <p class="wp-block-paragraph">Meged <a href="https://attend.blackhatevents.virtual.informatech.com/event/black-hat-usa-26/planning/UGxhbm5pbmdfNDUwNjU1Mg==">demonstrated</a> the first (architectural trust boundaries) at Black Hat after breaking into Anthropic’s, Google’s, and OpenAI’s official automations using nothing more than GitHub issues.</p> <p class="wp-block-paragraph">The recurring pattern, he said, was: “Decide in one place, consumed in another with more power.”</p> <p class="wp-block-paragraph">Each vendor’s vulnerability was different. One gave him code execution. One leaked credentials the harness thought it had stripped. Another let him plant instructions that a later, more privileged stage trusted without re-checking them.</p> <p class="wp-block-paragraph">But the underlying architectural mistake was remarkably consistent. One component made a security decision and a more powerful component downstream trusted that decision without validating it again.</p> <p class="wp-block-paragraph">That’s not a model failure. It’s a trust-boundary failure.</p> <p class="wp-block-paragraph">Lasso’s research exposes a second problem. Even without an exploitable coding mistake, the design of the harness itself can radically alter an agent’s security.</p> <p class="wp-block-paragraph">“When you choose your LLM and the tools and everything, and you choose the harness, you get one agent,” Sromin says. “And when you choose another harness, you get a completely different agent.”</p> <p class="wp-block-paragraph">That is a bigger distinction than many organizations may realize. Some security professionals still treat the harness as little more than a pass-through loop — interchangeable plumbing between the model and its tools.</p> <p class="wp-block-paragraph">Lasso’s numbers suggest otherwise. Swapping harnesses under an identical open-weight model moved its attack success rate from 1% to 24% and flipped the outcome entirely on 43 of 100 model-and-task pairings.</p> <p class="wp-block-paragraph">“It’s not just an arbitrary choice,” Sromin says. “It’s a careful choice. It can really affect and move the needle in whatever you’re doing out there.”</p> <p class="wp-block-paragraph">His recommendation is to benchmark the harness along with the model. Selecting one off the shelf without testing it means making a consequential security choice without knowing you’ve made one.</p> <p class="wp-block-paragraph">The harness’s supply chain is rapidly expanding, Bargury’s research at Zenity shows, and it’s already being exploited.</p> <p class="wp-block-paragraph">His team investigated “skills” — files that teach an agent how to perform new tasks — and found an old security problem appearing in a new form.</p> <p class="wp-block-paragraph">“This is just a supply chain problem, resurfacing again with skills,” <a href="https://attend.blackhatevents.virtual.informatech.com/event/black-hat-usa-26/planning/UGxhbm5pbmdfNDUwNjUyOA==">Bargury said at Black Hat</a>.</p> <p class="wp-block-paragraph">But agent skills create some unusual variations on that problem because they can alter the environment an agent repeatedly trusts.</p> <p class="wp-block-paragraph">Every time an agent starts, for example, it can reload a memory file containing instructions about what it is supposed to do. Zenity found that a malicious skill could write itself into that memory. Delete the skill and the instruction to reinstall it remains, allowing the malware to return the next time the agent runs.</p> <p class="wp-block-paragraph">Another malicious skill Zenity examined masqueraded as a legitimate Anthropic tool. Once executed, it deleted the real tool and replaced it with the attacker’s version, leaving the agent running malicious code without an obvious change visible to the user.</p> <p class="wp-block-paragraph">The most striking example was a campaign of cloned versions of popular open-source tools, secretly modified to steal login credentials. The malicious skills outperformed the legitimate tools they copied on skills.sh and <a href="https://www.csoonline.com/article/4206851/trojanized-ai-skills-gain-1-7m-installs-in-agent-targeted-attack.html">accumulated roughly 1.7 million downloads</a> before the campaign was disrupted.</p> <p class="wp-block-paragraph">The lesson across all three bodies of research is the same: Securing the model is not the same thing as securing the agent.</p> <h2 class="wp-block-heading" id="what-cisos-should-know">What CISOs should know</h2> <p class="wp-block-paragraph">For CISOs, the research points to three immediate problems: finding the harnesses already running inside the organization, controlling what they are allowed to touch, and independently testing whether their security controls actually work.</p> <p class="wp-block-paragraph">The first may be harder than it sounds because most organizations don’t maintain a category called “AI harness.”</p> <p class="wp-block-paragraph">“Teams think in terms of apps, services, pipelines, or bots,” Santos says. Harnesses disappear into code repositories, SaaS products, and vendor configuration screens instead of showing up as discrete assets in security inventories.</p> <p class="wp-block-paragraph">Even the terminology is inconsistent.</p> <p class="wp-block-paragraph">“One team may call something an agent, another a copilot, another a workflow assistant, another a plugin-based automation,” Santos says, “even though all of them are effectively harnesses.”</p> <p class="wp-block-paragraph">His recommendation is to build a live inventory of every production agent, identify its harness, and map every tool and resource it can access. Then reduce those permissions to the minimum required.</p> <p class="wp-block-paragraph">Organizations shouldn’t wait for perfect visibility. Santos estimates that 60% to 70% visibility can be achieved relatively quickly by starting with production systems, leaving prototypes and shadow AI for a second phase.</p> <p class="wp-block-paragraph">The second problem is controlling everything the harness trusts.</p> <p class="wp-block-paragraph">Agents don’t operate in isolation. They ingest instructions and content from tools, plugins, skills, MCP servers, websites, and other systems, often while holding credentials and permissions that let them act on behalf of users.</p> <p class="wp-block-paragraph">Attackers therefore don’t need to compromise the model. They need to compromise something the harness is willing to trust.</p> <p class="wp-block-paragraph">“You’re sharing your laptop with your agents, and your laptop has everything — has your identity, has your files, has your secrets,” Bargury says.</p> <p class="wp-block-paragraph">For organizations without a dedicated AI security budget, he recommends, at minimum, running agents inside open-source containment tooling. “This is not a fix,” he cautions, “but it is helpful.”</p> <p class="wp-block-paragraph">The size of the potential supply chain makes the problem qualitatively different from conventional software dependency management.</p> <p class="wp-block-paragraph">“Supply chain for software is, what, 10 or 15 package registries?” Bargury says. “Supply chain for agents is any content, any image, any text, any website, any CRM object, any skill, any MCP server, any content on the internet.”</p> <p class="wp-block-paragraph">The third problem is assuming a vendor’s security claims transfer to the environment where an agent will actually run.</p> <p class="wp-block-paragraph">A vendor claiming it blocks 99% of prompt injections, Bargury says, may be citing “a benchmark that is not attached to reality on the ground.”</p> <p class="wp-block-paragraph">Lasso’s findings demonstrate why that matters. Hold the model, prompt, and tools constant and change only the harness, and the security outcome can change dramatically.</p> <p class="wp-block-paragraph">That means organizations evaluating agents may be asking the wrong question. It isn’t simply which model is safest. It’s which combination of model, harness, tools, permissions, and external inputs remains safe under the conditions in which the organization will actually deploy it.</p> <p class="wp-block-paragraph">Meged distilled the lesson from breaking three vendors’ official automations: “Read the defaults, not the documentation.”</p> <p class="wp-block-paragraph">“The product said it was safe,” he said, “and that’s where we started.”</p> </div></div></div></div>

2026/8/12
阅读更多

17 old software bugs that took way too long to squash

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <hr class="wp-block-separator has-alpha-channel-opacity"> <p class="wp-block-paragraph">In 2021, a vulnerability was revealed in a system that lay at the foundation of modern computing. An attacker could force the system to execute arbitrary code. Shockingly, the vulnerable code was almost 54 years old — and there was no patch available, and no expectation that one would be forthcoming.</p> <p class="wp-block-paragraph">Fortunately, that’s because the system in question was Marvin Minsky’s <a href="https://www.theregister.com/2021/05/11/turing_machine_0day_no_patch_available/" target="_blank" rel="noreferrer noopener">1967 implementation of a Universal Turing Machine</a>, which, despite its momentous theoretical importance for the field of computer science, had never actually been built into a real-world computer. But in the decade or so after Minsky’s design, the earliest versions of Unix and DOS came into use, and their descendants are still with us today in the 21st century. Some of those systems have had bugs lurking beneath the surface for years or even decades.</p> <p class="wp-block-paragraph"><a href="https://www.csoonline.com/article/4198019/claude-mythos-faq-capabilities-access-competitors-implications.html">Frontier AI tools such as Claude Mythos are making it much easier to uncover latent vulnerabilities at pace</a> since discovery is no longer limited by human attention span or manual triage speed. The resulting acceleration on flaw discovery is possible not because AI tools are uncovering new exploit classes but because they are able to scan, chain reasoning, and test exploit paths at machine speed.</p> <p class="wp-block-paragraph">Here are 17 noteworthy bugs that, once long dormant, took over a decade to be discovered and fixed — in descending order of how long they went unaddressed.</p> <h2 class="wp-block-heading"><a></a>Libpng graphics library flaw</h2> <p class="wp-block-paragraph"><em>Age:</em><strong> 30 years</strong><br><em>Date introduced: </em><strong>1995</strong><br><em>Date fixed:</em><strong> February 2026</strong></p> <p class="wp-block-paragraph">Researchers unearthed a <a href="https://www.csoonline.com/article/4132296/researchers-unearth-30-year-old-vulnerability-in-libpng-library.html">legacy flaw in the widely used libpng open-source library</a> that had existed since the technology was first released more than 30 years ago.</p> <p class="wp-block-paragraph">The heap buffer overflow vulnerability (<a href="https://www.cvedetails.com/cve/CVE-2026-25646/">CVE-2026-25646</a>) meant that applications using the flawed software would crash when presented with a maliciously constructed PNG raster image file. Although difficult to exploit, the vulnerability potentially poses an information disclosure or remote code execution risk.</p> <p class="wp-block-paragraph">The vulnerable png_set_quantize function, previously called png_set_dither, is rarely used. This in combination with the difficulty of exploitation mean that the flaw earns a CVSS score of 8.3, rating it as a “high” rather than “critical” risk.</p> <p class="wp-block-paragraph">Nonetheless many Linux distributions (Debian, Red Hat, Ubuntu), desktop apps, and some Java runtimes rely on vulnerable versions of the library and need to be patched.</p> <h2 class="wp-block-heading" id="printdemon">PrintDemon</h2> <p class="wp-block-paragraph"><em>Age: </em><strong>24 years<br></strong><em>Date introduced: </em><strong>1996<br></strong><em>Date fixed: </em><strong>May 2020</strong></p> <p class="wp-block-paragraph">Printers are a frequent pain point for IT because there are a <em>lot </em>of models, they aren’t made by the same vendors who make computers and operating systems, and users expect to plug them in and start printing. Microsoft in its early years battled to make installing a printer driver relatively easy and painless. But a bug found in 2020, dubbed <a href="https://www.csoonline.com/article/569383/printdemon-vulnerability-explained-its-risks-and-how-to-mitigate.html">PrintDemon</a>, showed that maybe they took that a bit too far back in the ’90s — and paid for it for decades.</p> <p class="wp-block-paragraph">The core of the vulnerability lies in three facts: Non-administrative users can add printers to a Windows machine; the underlying mechanics make it possible to print to a file rather than a physical printing device; and crucial <a href="https://www.csoonline.com/article/572319/vulnerabilities-found-in-250-hp-printer-models.html">printing services</a> on Windows run with system privileges. That means that, if you do it right, you can build a “printer” driver that can create a file (even an executable one) anywhere on the filesystem (even in privileged directories). There are plenty of exploits that have been cooked up to take advantage of these design flaws — <a href="https://www.csoonline.com/article/562691/stuxnet-explained-the-first-known-cyberweapon.html">Stuxnet</a>, it turns out, was one of them — but PrintDemon was a real doozy, made possible because Microsoft’s fixes over the years had been patches rather than a complete rebuild of the printing subsystem.</p> <p class="wp-block-paragraph">As <a href="https://windows-internals.com/printdemon-cve-2020-1048/" target="_blank" rel="noreferrer noopener">Winsider described it</a>, “With very subtle file system modifications, you can achieve file copy/write behavior that is not attributable to any process, especially after a reboot … with a carefully crafted port name, you can imagine simply having the Spooler drop a [portable executable] file anywhere on disk for you.” </p> <h2 class="wp-block-heading" id="win32k-sys-vulnerabilities">win32k.sys vulnerabilities</h2> <p class="wp-block-paragraph"><em>Age: </em><strong>23 years<br></strong><em>Date introduced: </em><strong>1996<br></strong><em>Date fixed: </em><strong>2019</strong></p> <p class="wp-block-paragraph">Two big vulnerabilities were detected in the Win32 API in Microsoft Windows in 2019. The first, found in April, was a <a href="https://encyclopedia.kaspersky.com/glossary/use-after-free/?utm_source=securelist&amp;utm_medium=blog&amp;utm_campaign=termin-explanation">Use-After-Free vulnerability</a>, in which OS coding errors made it possible for programs to access system memory that should’ve been protected; this vulnerability was detected by security researchers when they discovered malicious hackers <a href="https://securelist.com/new-win32k-zero-day-cve-2019-0859/90435/" target="_blank" rel="noreferrer noopener">attempting to use it in the wild</a> to gain control of computers. The other, discovered in December, was an elevation-of-privilege vulnerability lurking in the OS’s window switching functionality; this vulnerability was similarly discovered in the course of <a href="https://securelist.com/windows-0-day-exploit-cve-2019-1458-used-in-operation-wizardopium/95432/" target="_blank" rel="noreferrer noopener">active attacks</a>, which simulated keystrokes to create memory leaks.</p> <p class="wp-block-paragraph">Both vulnerabilities have their origins in the early days of Windows. “The problem originates from the time when WIN32K made its debut with Windows NT 4.0, when much of Win32’s graphics engine was moved from user level to kernel to boost performance,” explained Boris Larin, senior security researcher at Kaspersky, back in 2019. And while these two vulnerabilities have been patched, that long-ago decision on the part of Microsoft has had much broader effects — and probably will continue to do so, Larin said then. “Throughout the years, the WIN32K component has been responsible for more than a half of all kernel security vulnerabilities discovered in Windows.”</p> <h2 class="wp-block-heading" id="putty-heap-overflow">PuTTY heap overflow</h2> <p class="wp-block-paragraph"><em>Age: </em><strong>20 years, 9 months<br></strong><em>Date introduced: </em><strong>January 1999<br></strong><em>Date fixed: </em><strong>October 2019</strong></p> <p class="wp-block-paragraph">PuTTY is a free and open-source suite of tools that includes a serial console, a terminal emulator, and various network file transfer applications, with SSH and other encryption schemes built in. It was originally released to bring tools Unix admins took for granted to Windows and Mac OS, but has expanded its scope and is <a href="https://www.networkworld.com/article/2867362/improving-your-putty-connections.html" target="_blank">now in wide use on Unix systems as well</a>. While PuTTY was designed to secure network connections, it turns out there was a vulnerability lurking at its heart. This was a heap overflow that could be triggered by an insufficiently long SSH key, which could result in crashing PuTTY or even remote code execution.</p> <p class="wp-block-paragraph">The vulnerability was <a href="https://hackerone.com/reports/630462" target="_blank" rel="noreferrer noopener">submitted to HackerOne</a> as part of a bug bounty program, netting the submitter a $3,645 reward and a thank you from the PuTTY team, which noted that the bug had been present in the very earliest versions of the source code, dating back to 1999.</p> <h2 class="wp-block-heading" id="postgresql-database-vulnerabilities">PostgreSQL database vulnerabilities</h2> <p class="wp-block-paragraph"><em>Age: </em><strong>20+ years</strong><strong><br></strong><em>Date introduced: <strong>2005</strong></em><strong><br></strong><em>Date fixed: <strong>February</strong></em><strong><em> 2026</em></strong><strong><em></em></strong></p> <p class="wp-block-paragraph">An AI-powered security analysis tool was able to <a href="https://www.csoonline.com/article/4167137/ai-finds-20-year-old-bugs-in-postgresql-and-mariadb.html">uncover a high-severity vulnerability in PostgreSQL</a>, stemming from a flaw that dated back more than 20 years to early versions of the open-source relational database technologies.</p> <p class="wp-block-paragraph">The AI tool — Xint Code — surfaced a <a href="https://www.zeroday.cloud/blog/postgres-xint">critical remote code execution (RCE) vulnerability in PostgreSQL’s ‘pgcrypto’ extension</a>, an encryption-based technology first contributed in 2005.</p> <p class="wp-block-paragraph">Another team of security researchers discovered a critical validation vulnerability in the same PostgreSQL ‘pgcrypto’ extension. Both flaws were discovered during security vendor <a href="https://www.zeroday.cloud/blog">Wiz’s zeroday.cloud hacking event</a> in late 2025, reported to developers and patched in February 2026.</p> <p class="wp-block-paragraph">Developers of both PostgreSQL and MariaDB responded with the release of software updates to address all these security flaws.</p> <h2 class="wp-block-heading" id="nginx-web-server">Nginx web server</h2> <p class="wp-block-paragraph"><em>Age: <strong>18</strong></em><strong> years<br></strong><em>Date introduced: <strong>2008</strong></em><strong><br></strong><em>Date fixed: <strong>May 2026</strong></em><strong><em></em></strong></p> <p class="wp-block-paragraph">A <a href="https://www.csoonline.com/article/4171437/ai-agent-finds-18-year-old-remote-code-execution-flaw-in-nginx.html">critical and long latent vulnerability in the popular Nginx web server software</a> was exposed by an AI-based security scanning tool.</p> <p class="wp-block-paragraph">The <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42945">CVE-2026-42945</a> vulnerability, a heap buffer overflow in NGINX’s URL rewrite module, was one of four flaws uncovered by security startup DepthFirst’s LLM-powered analysis platform.</p> <p class="wp-block-paragraph"><a href="https://my.f5.com/manage/s/article/K000161019">Developers at F5 warn</a> exploitation can cause a crash, and in some conditions could enable arbitrary code execution, especially if Address Space Layout Randomization (ASLR) is disabled.</p> <p class="wp-block-paragraph">System administrators are urged to update to patched versions of the software, 1.30.1 and 1.31.0, for the open-source version of Nginx. The commercial product, Nginx Plus, was also patched against the CVE-2026-42945 vulnerability and the three less severe flaws discovered by DepthFirst, as explained in a <a href="https://depthfirst.com/research/nginx-rift-achieving-nginx-rce-via-an-18-year-old-vulnerability">blog post</a>.</p> <h2 class="wp-block-heading" id="sigred-dns-vulnerability">SIGRed DNS vulnerability</h2> <p class="wp-block-paragraph"><em>Age: </em><strong>17 years<br></strong><em>Date introduced: </em><strong>2003<br></strong><em>Date fixed: </em><strong>2020</strong></p> <p class="wp-block-paragraph">DNS is one of the underrated backbones of the internet, the system by which your <a href="https://www.networkworld.com/article/3268449/what-is-dns-and-how-does-it-work.html" target="_blank">computer knows what IP address correlates to any given URL</a>. The system is hierarchical, with requests sent up and down the pyramid looking for DNS servers that know the answer to the question, “Where is this computer?” As a result, DNS has been built into all major operating systems.</p> <p class="wp-block-paragraph">In 2020, Microsoft disclosed a <a href="https://www.csoonline.com/article/569845/sigred-what-is-it-how-serious-is-it-and-how-should-you-respond.html">critical vulnerability in its own version of DNS</a>, which had been lurking in the code for 17 years. The vulnerability, <a href="https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/" target="_blank" rel="noreferrer noopener">dubbed SIGRed by its discoverers at Check Point</a>, was a <a href="https://www.csoonline.com/article/568835/what-is-a-buffer-overflow-and-how-hackers-exploit-these-vulnerabilities.html">buffer overflow</a> flaw in Windows DNS servers that could be triggered by exploit code tucked into a DNS packet’s signature. A malicious nameserver could send such packets in response to requests, bypassing most security protections and potentially gaining remote access to the Microsoft DNS server. The attack would be potentially wormable, meaning that it could be automated and spread without user intervention.</p> <h2 class="wp-block-heading" id="linux-kernel-based-virtualization-module-januscape-vulnerability">Linux kernel-based virtualization module Januscape vulnerability</h2> <p class="wp-block-paragraph"><em>Age: </em><strong>16 years<br></strong><em>Date introduced: </em><strong>2010<br></strong><em>Date fixed: </em><em><strong>June</strong></em><strong> 2026</strong></p> <p class="wp-block-paragraph">A <a href="https://www.csoonline.com/article/4194085/16-year-old-kvm-flaw-allows-attackers-to-escape-vms-and-take-over-linux-servers.html">long dormant vulnerability in a Linux kernel-based virtualization module (KVM)</a> poses arbitrary code execution risk to multi-tenant cloud environments and virtualized enterprise servers.</p> <p class="wp-block-paragraph">The critical vulnerability — dubbed <a href="https://github.com/V4bel/Januscape">Januscape</a> — creates a means for potential mechanism for attackers to escape VMs and execute malware upon host systems.</p> <p class="wp-block-paragraph">More specifically the <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-53359">CVE-2026-53359</a> vulnerability arises from a use-after-free memory bug in the shadow MMU emulation of KVM on x86 CPU architecture machines. As such the critical vulnerability circumvents the security boundary that cloud providers and enterprises rely on to isolate sensitive processes on servers.</p> <p class="wp-block-paragraph">The flaw stems from software introduced into Linux kernel code in 2010 and is the first KVM guest-to-host escape vulnerability that works on both Intel and AMD CPUs, according to <a href="https://x.com/v4bel">Hyunwoo Kim</a>, the security researcher who discovered the flaw.</p> <h2 class="wp-block-heading" id="python-tarfile-vulnerability-rises-again">Python tarfile vulnerability rises again</h2> <p class="wp-block-paragraph"><em>Age: </em><strong>15 years<br></strong><em>Date introduced: </em><strong>2007<br></strong><em>Date fixed: </em><strong>September 2022</strong></p> <p class="wp-block-paragraph">Cybersecurity company Trellix discovered that CVE-2007-4559, a vulnerability affecting Python’s tarfile module first identified in 2007, continued to affect hundreds of thousands of repositories up until at least September 2022.</p> <p class="wp-block-paragraph">“While investigating an unrelated vulnerability, Trellix Advanced Research Center stumbled across a vulnerability in Python’s tarfile module,” Kasimir Schulz, a vulnerability researcher for Trellix’s Threat Labs, <a href="https://www.trellix.com/en-us/about/newsroom/stories/research/tarfile-exploiting-the-world.html" target="_blank" rel="noreferrer noopener">wrote on the firm’s blog</a>. “Initially we thought we had found a new zero-day vulnerability. As we dug into the issue, we realized this was in fact CVE-2007-4559.”</p> <p class="wp-block-paragraph">According to NIST, <a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4559" target="_blank" rel="noreferrer noopener">CVE-2007-4559</a> is a directory traversal vulnerability in the extract and extractall functions in the tarfile module in Python that allows user-assisted remote attackers to overwrite arbitrary files via a “..” sequence in filenames in a TAR archive.</p> <p class="wp-block-paragraph">Bad actors can create exploits with as few as six lines of code added to the tarfile module, which allows users to add a filter to parse and modify a file’s metadata before it is added to the tar archive, Schulz said. CVE-2007-4559 “is incredibly easy to exploit, requiring little to no knowledge about complicated security topics. Due to this fact and the prevalence of the vulnerability in the wild, Python’s tarfile module has become a massive supply chain issue threatening infrastructure around the world.” Trellix has found more than 300,000 repositories affected by the vulnerability.</p> <p class="wp-block-paragraph">Trellix developed a <a href="https://github.com/advanced-threat-research/Creosote" target="_blank" rel="noreferrer noopener">scanning utility</a> to identify the vulnerability and patched a number of open-source repositories.</p> <h2 class="wp-block-heading" id="linux-scsi-subsystem-bugs">Linux SCSI subsystem bugs</h2> <p class="wp-block-paragraph"><em>Age: </em><strong>15 years<br></strong><em>Date introduced: </em><strong>2006<br></strong><em>Date fixed: </em><strong>March 2021</strong></p> <p class="wp-block-paragraph">SCSI, a 1980s-era data transfer standard, is still in use in some contexts today, and Linux, always intended to be as flexible and universal as possible, still has an extensive SCSI subsystem for those systems that need it. These modules are available via <em>automatic module loading,</em> in which the OS grabs and installs the system code it needs when it needs it — helpful if you find yourself plugging a SCSI drive into your Linux machine and don’t want to hunt down the necessary supporting code.</p> <p class="wp-block-paragraph">Cybersecurity consultancy Grimm posted an extensive breakdown of <a href="https://blog.grimm-co.com/2021/03/new-old-bugs-in-linux-kernel.html" target="_blank" rel="noreferrer noopener">several bugs in this Linux SCSI code</a> that they discovered in March 2021. One was a buffer overflow vulnerability that could allow a normal user to gain root privileges, and the others were errors where information from the kernel could be leaked to user space<s>, and.</s> All could be used to get privileged information or as part of a DoS attack on the affected machine. Grimm dates the bugs back to 2006 and dryly notes that they’re “an indication of a lack of security-conscious programming practices that was prevalent at the time this code was developed.”</p> <h2 class="wp-block-heading" id="domain-time-ii-man-on-the-side-attack">Domain Time II man-on-the-side attack</h2> <p class="wp-block-paragraph"><em>Age: </em><strong>14 years<br></strong><em>Date introduced: </em><strong>2007<br></strong><em>Date fixed: </em><strong>April 2021</strong></p> <p class="wp-block-paragraph">If two computers on the same network can’t agree on the time, the results can range from <a href="https://www.networkworld.com/article/3189131/the-growing-importance-of-time-sensitive-networks.html" target="_blank">annoying to disastrous</a>. This <a href="https://en.wikipedia.org/wiki/Clock_synchronization" target="_blank" rel="noreferrer noopener">longstanding problem</a> was to be solved by <a href="https://www.greyware.com/software/domaintime/" target="_blank" rel="noreferrer noopener">Domain Time II</a>, a closed-source application in use on Windows, Linux, and Solaris.</p> <p class="wp-block-paragraph">But Domain Time II harbored for most of its existence a very serious vulnerability. At intervals or on conditions the user can set, the program sends UDP queries to an update server run by Greyware Automation Products, the software’s vendor. If the server replies with a URL, Domain Time II will run a program with admin privileges to download and install an update from that URL.</p> <p class="wp-block-paragraph">The problem? If a malicious actor manages to reply to the query before Greyware’s server does, that attacker can <a href="https://blog.grimm-co.com/2021/04/time-for-upgrade.html" target="_blank" rel="noreferrer noopener">send its own reply</a>, prompting Domain Time II to download whatever <a href="https://www.csoonline.com/article/565999/what-is-malware-viruses-worms-trojans-and-beyond.html">malware</a> the attacker wants installed. In a true <a href="https://www.csoonline.com/article/566905/man-in-the-middle-attack-definition-and-examples.html">man-in-the-middle attack</a>, the attacker would be intercepting communications in both directions; in contrast, this <em>man-on-the-side</em> attack can’t stop replies to its target machine getting through and so has to send its own reply more quickly.</p> <p class="wp-block-paragraph">In practice, this means the attacker would need to control a computer on the target’s local network to pull this off, but this attack represents a way an attacker could escalate their intrusion onto more valuable and secure machines within a local network. This vulnerability was spotted by the security firm Grimm, which noted that the flaw was present in versions of the software going back at least to 2007.</p> <h2 class="wp-block-heading"><a></a>Critical vulnerability in Redis in-memory store</h2> <p class="wp-block-paragraph"><em>Age: </em><strong>13 years</strong><br><em>Date introduced:</em><strong> 2012</strong><br><em>Date fixed:</em><strong> October 2025</strong></p> <p class="wp-block-paragraph">A <a href="https://www.csoonline.com/article/4069136/10-0-severity-rce-flaw-puts-60000-redis-instances-at-risk.html">vulnerability in Redis in-memory store</a> posed a critical risk for servers hosting the database.</p> <p class="wp-block-paragraph">The vulnerability, identified as CVE-2025-49844 or RediShell, stemmed from a use-after-free memory corruption bug that has existed in the Redis code base for around 13 years and posed a remote code execution risk.</p> <p class="wp-block-paragraph">While the flaw required authentication to exploit, an estimated 60,000 internet exposed Redis instances were exposed to the internet without authentication enabled, leaving these systems open to attack. Wiz researchers discovered the flaw and used it in the Pwn2Own Berlin contest in May 2025, weeks before its public disclosure in October 2025.</p> <h2 class="wp-block-heading" id="lionwiki-local-file-inclusion">LionWiki local file inclusion</h2> <p class="wp-block-paragraph"><em>Age: </em><strong>11 years, 11 months<br></strong><em>Date introduced: </em><strong>November 2008<br></strong><em>Date fixed: </em><strong>October 2020</strong></p> <p class="wp-block-paragraph"><a href="https://lionwiki.0o.cz/index.php?page=Main+page" target="_blank" rel="noreferrer noopener">LionWiki</a> is a minimalist wiki engine, programmed in PHP. Unlike many popular wiki engines, LionWiki doesn’t use a database, and instead is entirely file-based. Because its goal is simplicity, this is a strength, but it also makes a significant vulnerability possible.</p> <p class="wp-block-paragraph">In essence, the various files underlying a particular LionWiki instance are accessed by file and pathnames in the URL of the corresponding pages. This means that, with a correctly crafted URL, you could traverse the filesystem of the server hosting the LionWiki instance. There are URL-filtering provisions in place to block attempts to do this, but as Infosec Institute’s cyber range engineer June Werner discovered, they could be <a href="https://www.junebug.site/blog/cve-2020-27191-lionwiki-3-2-11-lfi" target="_blank" rel="noreferrer noopener">defeated fairly easily</a>.</p> <p class="wp-block-paragraph">One thing Werner noted is that the vulnerability persisted despite attempts to correct it. “Some mitigations were first put in place in July of 2009, and then more extensive mitigations were put in place in January of 2012,” she noted. “Despite these mitigations, the code was still vulnerable to the same type of attack. This vulnerability stayed in the code for another eight years until it was rediscovered, along with a way to bypass the mitigations, in October 2020.” After the bug was <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27191" target="_blank" rel="noreferrer noopener">formally reported</a>, it was patched by the developer.</p> <h2 class="wp-block-heading" id="sudo-host">sudo host</h2> <p class="wp-block-paragraph"><em>Age: </em><strong>11 years, 10 months<br></strong><em>Date introduced: </em><strong>September 2013<br></strong><em>Date fixed: </em><strong>July 2024</strong></p> <p class="wp-block-paragraph">The sudo command is an important tool in any Unix admin’s toolkit, granting <a href="https://www.networkworld.com/article/3322504/selectively-deploying-your-superpowers-on-linux.html" target="_blank">superpowered user privileges</a> to those who have the permission to invoke it. To access these privileges, a user must be listed in a configuration file called sudoers. Because many organizations centrally administer many Unix hosts, sudoers can include a list of specific hosts where each user has sudo rights, so that these config files can be written once and then be pushed out to all the organization’s hosts.</p> <p class="wp-block-paragraph">The problem is that, to get access to the sudoers file and see the hosts on which you or another user might have sudo powers, you need those sudo powers yourself. But a command-line flag intended to let users view host-specific privileges could be abused to trick sudo into treating the command as if it were running on a different host — potentially one where the user has elevated privileges. That could allow the user to run commands, including those that edit sudoers, even if they shouldn’t have that access on the local machine. This <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32462">security flaw isn’t rated as too serious</a>, but it did lurk undetected for nearly 12 years. (Another <a href="https://www.csoonline.com/article/4018715/how-a-12-year-old-bug-in-sudo-is-haunting-linux-users.html">more serious flaw with the chroot option</a>, revealed at the same time, is a mere baby at two years old.)</p> <h2 class="wp-block-heading"><a></a>HashiCorp Vault and CyberArk Conjur logic flaws</h2> <p class="wp-block-paragraph"><em>Age: </em><strong>10 years</strong><br><em>Date introduced:</em><strong> 2015</strong><br><em>Date fixed:</em><strong> August 2025</strong></p> <p class="wp-block-paragraph"><a href="https://www.csoonline.com/article/4035274/researchers-uncover-rce-attack-chains-in-popular-enterprise-credential-vaults.html">Multiple flaws in components of HashiCorp Vault and CyberArk Conjur</a>, two open-source credential management systems, left the door open to a variety of attacks, including authentication bypass and the theft or erasure of supposedly protected secrets.</p> <p class="wp-block-paragraph">Both HashiCorp Vault and CyberArk Conjur are used for storing and controlling access to secrets such as API keys, database passwords, certificates, and encryption keys. Each technology is commonly used in DevSecOps pipelines.</p> <p class="wp-block-paragraph">Researchers from Cyata discovered an array of issues, many of which had remained hidden in the codebase of widely used open-source secrets vaults for years. The vulnerabilities were discovered after manual code reviews that focused on logic flaws in components responsible for authentication and policy enforcement rather than memory corruption issues typically detected by automated tools.</p> <p class="wp-block-paragraph">Findings from the research — which led to the discovery of a combined total of 14 vulnerabilities in the two secrets vaults — were revealed at Black Hat USA in August 2025.</p> <p class="wp-block-paragraph">The most severe vulnerability in HashiCorp Vault (<a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6000" target="_blank" rel="noreferrer noopener">CVE-2025-6000</a>) created a mechanism for attackers to delete a critical file containing the keys needed to decrypt stored secrets, leaving data unreachable.</p> <p class="wp-block-paragraph">All the vulnerabilities were addressed before the research was publicly disclosed.</p> <h2 class="wp-block-heading" id="linux-grub2-secure-boot-hole">Linux GRUB2 Secure Boot hole</h2> <p class="wp-block-paragraph"><em>Age: </em><strong>10 years<br></strong><em>Date introduced: </em><strong>2010<br></strong><em>Date fixed: </em><strong>July 2020</strong></p> <p class="wp-block-paragraph">When UEFI was introduced to replace BIOS, it was <a href="https://www.csoonline.com/article/548540/ultimate-pc-security-requires-uefi-and-windows-8-or-linux.html">deemed the cutting edge of security</a>, with features to fight attacks that operated on the level of the bootloading software that starts up an OS. Key to this is an interlocked chain of signed cryptographic certificates that verifies each bootloader program as legitimate, a mechanism known as Secure Boot. The root certificate for UEFI is signed by Microsoft, and Linux distributions put their own bootloaders, each with its own validated certificate, further down the chain.</p> <p class="wp-block-paragraph">But GRUB2, a widely popular Linux bootloader with a UEFI-ready certificate, <a href="https://www.csoonline.com/article/569663/linux-grub2-bootloader-flaw-breaks-secure-boot-on-most-computers-and-servers.html">contains a buffer overflow vulnerability</a> that can be exploited by malicious code inserted into in its configuration file. (While GRUB2 itself is signed, its configuration file, meant to be editable by local admins, is not.) This hole was <a href="https://eclypsium.com/2020/07/29/theres-a-hole-in-the-boot/" target="_blank" rel="noreferrer noopener">spotted by Eclypsium</a>, and while an attacker would need to have a degree of local control of the target machine to implement this attack, if they pulled it off successfully, they could ensure that they remain in control of that computer going forward each time it boots up, making it difficult to evict them from the system.</p> <h2 class="wp-block-heading"><a></a>Telnet</h2> <p class="wp-block-paragraph"><em>Age:</em> <strong>10 years, 8 months</strong><br><em>Date introduced:</em> <strong>May 2017</strong><br><em>Date fixed:</em> <strong>Jan 2026</strong></p> <p class="wp-block-paragraph">Telnet is an early internet protocol and associated tools used for remotely logging into another machine via a text-based terminal session. Although superseded by the more secure and encrypted SSH technology since the mid-1990s, Telnet is still widely used by embedded systems, network hardware, and other legacy systems.</p> <p class="wp-block-paragraph">An <a href="https://www.csoonline.com/article/4120997/trivial-telnet-authentication-bypass-exposes-devices-to-complete-takeover.html">easily-exploited Telnet authentication bypass vulnerability</a> (CVE-2026-24061), introduced in code changes release in May 2017, left devices running pre-patched versions of the software wide open to remote compromise, provided that its Telnet server was exposed to the internet.</p> </div></div></div></div>

2026/8/12
阅读更多

Metabase SQLi exploit grants attackers total access

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">Business intelligence (BI) platform provider Metabase has disclosed a zero-day SQL Injection vulnerability, warning that customers’ sensitive credentials, tokens, API keys, and other data may have been exposed.</p> <p class="wp-block-paragraph">The Metabase vulnerability revealed on August 6, designated <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-72898" target="_blank" rel="noreferrer noopener">CVE-2026-72898</a>, is identified as critical, with a severity score of 10, the highest possible rating. It is present in versions 1.58 and up.</p> <p class="wp-block-paragraph">“You don’t see a perfect 10/10 on CVSS often, but when you do, be worried,” noted <a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="noreferrer noopener">David Shipley</a>, CEO of Beauceron Security. SQL injection is “old school and painful, as there’s now working proof of concept exploit code.”</p> <h2 class="wp-block-heading" id="unmitigated-raw-database-access">‘Unmitigated, raw’ database access</h2> <p class="wp-block-paragraph">Metabase is an open-source BI tool that customers can connect to popular databases, including Databricks, MongoDB, Oracle, Snowflake, Amazon, BigQuery, and many others. They can use the platform to access analytics, query and visualize data, and build dashboards, among other actions.</p> <p class="wp-block-paragraph">Search engine Shodan has tracked roughly 2,500 Metabase instances, and security company Wiz <a href="https://www.wiz.io/blog/inside-the-metabase-sqli-exploited-in-the-wild">reported that</a> around 13% of cloud environments have deployed self-hosted Metabase instances; of those, about 25% are fully accessible on the internet.</p> <p class="wp-block-paragraph">According to Metabase’s disclosure, a threat actor used a zero-day SQL injection vulnerability in the company’s platform to gain access. The entry point is <em>/api/session/reset_password</em>.</p> <p class="wp-block-paragraph">Metabase said that after it discovered the attack, it immediately blocked the exploited endpoints, patched the vulnerability, terminated relevant sessions, and revoked credentials used in the incident. Metabase Cloud customers have already been upgraded and patched against the vulnerability, but self-hosted Metabase customers may still be vulnerable unless they have patched.</p> <p class="wp-block-paragraph">“This vulnerability allows attackers to have unmitigated, raw SQL access to the Metabase database,” said <a href="https://www.linkedin.com/in/scottmiserendino" target="_blank" rel="noreferrer noopener">Scott Miserendino</a>, CTO at DataBee. They can steal or alter account credentials for connected databases, create new administrator accounts, change app configurations, escalate privileges, or even “degrade, alter or destroy” information.</p> <p class="wp-block-paragraph">He emphasized that this vulnerability can also affect platforms that use original equipment manufacturer (OEM) versions of  Metabase as part of their infrastructure. This means affected users may not even know they are affected, because they are not aware that Metabase is part of the product they purchased.</p> <p class="wp-block-paragraph">“It is a very serious vulnerability,” Miserendino cautioned.</p> <h2 class="wp-block-heading" id="victims-so-far">Victims so far</h2> <p class="wp-block-paragraph">Companies that have been impacted by the breach seem, at least to so far, to be smaller organizations and startups. They include <a href="https://www.anaconda.com/blog/metabase-incident-impacting-kilo-code-data" target="_blank" rel="noreferrer noopener">Kilo Code</a>, which was recently acquired by Anaconda; Y Combinator backed <a href="https://news.ycombinator.com/item?id=49213500" target="_blank" rel="noreferrer noopener">Tally</a>, which is building autonomous accounting agents; personal computer manufacturer <a href="https://community.frame.work/t/framework-data-breach-discussion/83939" target="_blank" rel="noreferrer noopener">Framework</a>; workflow automation platform <a href="https://blog.n8n.io/metabase-security-incident-update/" target="_blank" rel="noreferrer noopener">n8n</a>; and AI testing and monitoring platform provider <a href="https://www.checklyhq.com/blog/metabase-security-incident/" target="_blank" rel="noreferrer noopener">ChecklyHQ</a>.</p> <p class="wp-block-paragraph">The impacted companies report that <a href="https://www.csoonline.com/article/4205861/evidence-points-to-cybercriminals-stepping-up-their-ai-game.html" target="_blank">threat actors</a> accessed records containing usernames, email addresses, cloud passwords, cryptographic hashes of OpenTelemetry (OTel) API keys used for trace collection, Slack access tokens, and other sensitive information.</p> <p class="wp-block-paragraph">They all report that they are directly contacting impacted customers and have taken mitigation actions, including rotating potentially impacted credentials and API keys, resetting all user passwords, invalidating all Slackbot authentication tokens for impacted users, removing compromised admin accounts, and reviewing internal audit logs.</p> <p class="wp-block-paragraph">“The vulnerability was in a vendor’s product, but protecting your data is our job, and this incident put some of it at risk,” Checkly said in its notice.</p> <p class="wp-block-paragraph">It said it is rethinking internal processes around analytics tools, improving sanitation when storing check configurations and data, and performing extensive audits to limit exposure. Its on-call engineers will also be paged when future vendor security notices are released to allow for faster response.</p> <p class="wp-block-paragraph">“Rotating credentials fixes the immediate problem,” the company noted. “It does not fix the reason this hurt: Our analytics environment held more sensitive data and had broader access than it needed.”</p> <h2 class="wp-block-heading" id="what-affected-customers-should-do">What affected customers should do</h2> <p class="wp-block-paragraph">The attack pattern, according to Metabase, is:</p> <ul class="wp-block-list"> <li>A call to <em>POST /api/session/reset_password</em> with a 400 status code</li> <li>This is followed by a call to <em>GET /api/user/current</em> with a 200 status code</li> </ul> <p class="wp-block-paragraph">“If you find that pattern in your application logs or in your Metabase server ingress logs, it is likely that your instance has been compromised,” the company said.</p> <p class="wp-block-paragraph">Customers should upgrade to an appropriate patch as soon as possible. For instance, if running Metabase 0.58.6, move to 0.58.24 or later. Those unable to immediately upgrade can implement a temporary workaround by blocking the <em>/api/session/reset_password</em> endpoint.</p> <p class="wp-block-paragraph">If the <em>/api/session/reset_password</em> endpoint of a Metabase instance is publicly accessible, enterprises should revoke all active user sessions; review and delete any unrecognized API keys; audit data warehouse logs and admin accounts for unauthorized access or other unexpected changes; rotate credentials for all connected databases; and review Metabase activity and query histories.</p> <p class="wp-block-paragraph">If wrapping a third-party’s REST interface, enterprises should always perform their own SQLi detection, DataBee’s Miserendino advised. This can be done by incorporating a web access firewall (WAF) or reverse proxy.</p> <p class="wp-block-paragraph">“Enterprises should also monitor their security and database logs for the creation of new or recently elevated administrator accounts,” he said, “or other unusual activity such as large volumes of data drops.”</p> <p class="wp-block-paragraph">Anaconda, for its part, urges customers to remain diligent: “Be on alert for phishing/social engineering, and maintain credential hygiene (including auditing, reviewing, and rotating credentials regularly) and spam monitoring.”</p> </div></div></div></div>

2026/8/12
阅读更多

Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">A currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixes issued today in Microsoft’s August Patch Tuesday releases.</p> <p class="wp-block-paragraph">The hole is in Windows’ Ancillary Function Driver for WinSock (<a href="https://app.opencve.io/cve/CVE-2026-68820">CVE-2026-68820</a>), which, according to <a href="https://www.linkedin.com/in/todd-schell-20a8bb3">Todd Schell</a>, principal product manager at Ivanti, has been a recurring target for local privilege-escalation bugs throughout 2026. Past vulnerabilities in this component have let an authorized attacker win a race condition to gain SYSTEM privileges.</p> <p class="wp-block-paragraph">“Exploitation has already been detected,” noted <a href="https://www.linkedin.com/in/bicer">Jack Bicer</a>, director of vulnerability research at Action1, “making this the highest priority vulnerability in this month’s release.”  </p> <p class="wp-block-paragraph">Separately, SAP issued 29 new and updated security patches, the most severe of which is <a href="https://app.opencve.io/cve/CVE-2026-58231">CVE-2026-58231</a>, with a CVSS score of 10. This is an improper authorization issue in SAP Commerce Cloud’s Data Hub Adapter.</p> <h2 class="wp-block-heading" id="42-critical-microsoft-vulnerabilities">42 critical Microsoft vulnerabilities</h2> <p class="wp-block-paragraph">In total, Microsoft addressed 398 CVEs. Of them, 42 were rated critical, while 355 were rated Important. However, <a href="https://www.fortra.com/profile/tyler-reguly">Tyler Reguly</a>, associate director of security R&amp;D at Fortra, noted that 236 CVEs affect Windows and are covered by a cumulative update. Another 98 are Office CVEs that are covered by separate Office cumulative updates, unless you happen to still run Office 2016</p> <p class="wp-block-paragraph">In addition to the actively exploited zero-day, Microsoft also warned of two other zero-days. <a href="https://app.opencve.io/cve/CVE-2026-62832">CVE-2026-62832</a> is an elevation of privilege vulnerability in the Windows User Profile Service, rated Important. Action1 pointed out this has been publicly disclosed, so exploitation is likely; Ivanti noted that it is the flaw behind “LegacyHive,” the unpatched proof-of-concept released by researcher Nightmare-Eclipse just hours after July’s Patch Tuesday. This vulnerability lets a standard user coerce the User Profile Service into loading another user’s registry hive, even an administrator’s, to gain unauthorized access to that user’s Classes registry data.</p> <p class="wp-block-paragraph"><a href="https://vuldb.com/cve/CVE-2026-72971">CVE-2026-72971</a> is a tampering vulnerability in the Windows Container Isolation FS Filter Driver (<em>unionfs.sys</em>), rated Important. Public disclosure ahead of the patch means exploit code could follow quickly, said Ivanti. It added that IT departments running Windows containers, build agents, or CI infrastructure on affected hosts should prioritize this update.</p> <p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/satnamnarang">Satnam Narang</a>, senior staff research engineer at Tenable, said CISOs should pay particular attention to the elevation of privilege flaw in the Windows Ancillary Function Driver (<em>afd.sys</em>) for WinSock, which handles socket commands. Not only was this vulnerability exploited in the wild, he said, it could be a flaw leveraged by nation state actors, as was 2024’s<a href="https://nvd.nist.gov/vuln/detail/cve-2024-38193"> CVE-2024-38193</a>, reportedly attacked by North Korean hackers linked to the <a href="https://www.csoonline.com/article/3818521/lazarus-group-tricks-job-seekers-on-linkedin-with-crypto-stealer.html">Lazarus</a> group. Tenable says historical tradecraft of this nature is typically leveraged by APT groups in limited, targeted attacks.</p> <h2 class="wp-block-heading" id="many-remote-vulnerabilities-this-month-dont-need-authentication">Many remote vulnerabilities this month don’t need authentication</h2> <p class="wp-block-paragraph">A significant portion of this month’s risk comes from critical vulnerabilities that can potentially be exploited remotely, without authentication or user interaction, noted Action1’s Bicer. For example, he pointed out, Windows DNS Server Remote Code Execution Vulnerability (<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62878">CVE-2026-62878</a>), Microsoft QUIC Remote Code Execution Vulnerability, Windows iSCSI Target Service Remote Code Execution Vulnerability (<a href="https://app.opencve.io/cve/CVE-2026-65791">CVE-2026-65791</a>) and Windows Deployment Services TFTP Server Remote Code Execution Vulnerability each carries a CVSS score of 9.8.</p> <p class="wp-block-paragraph">“These vulnerabilities represent particularly serious attack paths because a malicious network request or packet could potentially lead directly to code execution,” Bicer said. “The TFTP Server Remote Code Execution Vulnerability (<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62893">CVE-2026-62893</a>) deserves additional attention because exploitation is assessed as more likely, despite no confirmed exploitation at publication.”</p> <p class="wp-block-paragraph">SharePoint represents another important concentration of risk, Bicer said. Microsoft SharePoint Server Remote Code Execution Vulnerability (<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-65665">CVE-2026-65665</a>) allows an authenticated attacker with at least Site Owner privileges to execute arbitrary code remotely, and is assessed as more likely to be exploited. The Microsoft SharePoint Server Elevation of Privilege Vulnerability (<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62827">CVE-2026-62827</a>) and a second Microsoft SharePoint Server Elevation of Privilege Vulnerability (<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-64921">CVE-2026-64921</a>) can allow authenticated attackers with domain access to elevate themselves to SharePoint administrator.</p> <p class="wp-block-paragraph">“These vulnerabilities are particularly relevant where SharePoint contains sensitive corporate information or supports important business processes,” Bicer said. “A compromised identity could potentially become a path to administrative control, arbitrary code execution, information theft, or disruption of collaboration services.” </p> <h2 class="wp-block-heading" id="advice-for-csos">Advice for CSOs</h2> <p class="wp-block-paragraph">For CSOs, the primary strategic priority should be reducing the window of exposure around CVE-2026-68820, because exploitation is already occurring, Bicer said. CVE-2026-62832 should follow closely, because it is publicly disclosed and assessed as more likely to be exploited. The next priority should be unauthenticated remote code execution vulnerabilities with low attack complexity, particularly Windows DNS Server Remote Code Execution Vulnerability, Microsoft QUIC Remote Code Execution Vulnerability, Windows iSCSI Target Service Remote Code Execution Vulnerability, and Windows Deployment Services TFTP Server Remote Code Execution Vulnerability.</p> <p class="wp-block-paragraph">He said IT leadership should also require accelerated remediation and explicit validation for DNS, DHCP, SharePoint, Exchange, Active Directory Certificate Services (AD CS), Routing and Remote Access Services (RRAS), Secure Socket Tunneling Protocol (SSTP), and other critical services. Because no documented workaround is identified for the highlighted vulnerabilities, Bicer said patch deployment remains the primary risk reduction measure. Systems that cannot be patched within established timelines, he added, should receive documented risk acceptance, exposure reduction, segmentation, enhanced monitoring, and compensating controls until remediation is complete. </p> <h2 class="wp-block-heading" id="the-new-normal">‘The new normal’</h2> <p class="wp-block-paragraph">“While this month’s release is smaller than last month’s, 398 new CVEs prove that massive patch loads are officially the ‘new normal,’” commented <a href="https://www.linkedin.com/in/dustincchilds">Dustin Childs</a>, head of threat awareness at TrendAI’s Zero Day Initiative. “The saving grace is that only one bug is currently being actively exploited. Security teams need to fix that zero-day today, but realize that managing this sheer volume of patches is now standard operating procedure.”</p> <p class="wp-block-paragraph">But security teams shouldn’t be awed by the hundreds of new CVEs this month, stressed <a href="https://www.linkedin.com/in/zacharyfinstad">Zack Finstad</a>, VP of cybersecurity at Logically.<em> </em>“Volume alone is not the same as risk,” he said. “The practical move is to triage by exploitation status and internet exposure first, then work outward. A CVE that is already being exploited in the wild against internet-facing systems deserves a very different response than a theoretical local privilege escalation on an isolated workstation.”</p> <h2 class="wp-block-heading" id="sap-critical-patches">SAP critical patches</h2> <p class="wp-block-paragraph">The improper authorization vulnerability in SAP Commerce Cloud’s Data Hub Adapter (<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-58231">CVE-2026-58231</a>) is the most critical of the patches released today, says <a href="https://pathlock.com/author/jonathan-stross/">Jonathan Stross</a>, senior manager for cybersecurity research and innovation at Pathlock. An unauthenticated remote attacker with network access to an affected instance can submit crafted data to the Data Hub import endpoint, potentially leading to arbitrary code execution. Stross said successful exploitation could expose customer and order data, manipulate application behavior, interrupt storefront or integration flows, and compromise credentials or services trusted by the Commerce environment.</p> <p class="wp-block-paragraph">SAP also addressed two critical code injection flaws in Manufacturing Integration and Intelligence (MII), tracked as CVE-2026-44772 (with a CVSS score of 9.9) and <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44758">CVE-2026-44758</a> (CVSS score of 9.1).</p> <p class="wp-block-paragraph"><a href="https://onapsis.com/blog/sap-security-patch-day-august-2026/">In a research note, Onapsis said</a> the problem in MII is a vulnerable servlet component that is open to server-side template injection and server-side request forgery. The patch removes the vulnerable component.</p> <p class="wp-block-paragraph">Another critical defect is <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34265">CVE-2026-34265</a> (CVSS score of 9.8), which is described as a memory corruption issue in Application Server ABAP for NetWeaver and ABAP Platform.</p> <p class="wp-block-paragraph">The memory corruption comes from logical errors in DIAG protocol parsing that allow an unauthenticated attacker to generate memory corruptions, said Onapsis. The vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application. Stross noted that an attacker does not require authentication to exploit this hole.</p> </div></div></div></div>

2026/8/12
阅读更多

Zoom zero-click RCE flaws allow attackers to compromise meeting participants

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">Zoom has fixed four vulnerabilities across its applications, including two that could allow attackers who join a meeting to execute malicious code on the systems of all other meeting participants with no interaction required from them.</p> <p class="wp-block-paragraph">Three of the vulnerabilities affect all Zoom client applications for all platforms before versions 7.1.5 and 7.0.6, while the fourth impacts Zoom Workplace VDI Client for Windows and VDI Plugins on all supported platforms before versions 7.0.11 and 6.6.15. Products such as Zoom Rooms and Zoom Meeting SDK before versions 7.1.0 are also affected.</p> <p class="wp-block-paragraph">The three client vulnerabilities are memory corruption issues in the text annotation function and were found by a researcher from A Security by using an AI agent.</p> <p class="wp-block-paragraph">“The entire operation, from finding the flaw to building a working exploit, was carried out by A [Security] using fewer than 20 prompts on publicly available AI models in under 24 hours,” the company said in <a href="https://a.security/blog/asecurity-zoomsday">its report</a>. “This class of capability would previously have only been available to nation-state threat actors, but the model requiring elite teams, months of effort, and weapons-grade budgets has collapsed. Today, a single researcher was able to develop a nation-state-level exploit in less than a day.”</p> <p class="wp-block-paragraph">The researchers point out the massive potential blast radius of such an exploit, with Zoom being used by 70% of the Fortune 100 companies, most of the Fortune 500 ones, and federal agencies. In addition, this exploit doesn’t need meeting participants to perform any type of action such as clicking or downloading anything. It all happens silently with no indication that the attacker has executed malicious code on their computer.</p> <h2 class="wp-block-heading" id="how-the-vulnerability-works">How the vulnerability works</h2> <p class="wp-block-paragraph">When a participant draws, writes, or highlights text on a shared screen or whiteboard in Zoom, their client doesn’t send pixels. Instead, it builds a typed in-memory object that describes the action, then serializes this object into a byte stream and sends it to Zoom’s Multimedia Router, which then forwards it to all meeting participants, whose client application deserializes the object.</p> <p class="wp-block-paragraph">Data serialization and deserialization operations have been a big source of memory corruption vulnerabilities in applications because it’s easy to get wrong and the input is attacker-controlled. Zoom allocates four fixed 128-byte buffers to write the deserialized annotation packets in, but the code only checks that the packets are non-zero, not their size.</p> <p class="wp-block-paragraph">Therefore, if an attacker can generate a packet that fills and exceeds the four fixed buffers, they have a buffer overflow condition they can exploit to insert malicious code in the application’s memory.</p> <p class="wp-block-paragraph">The A Security researcher has identified a buffer overflow vulnerability, <a href="https://www.zoom.com/en/trust/security-bulletin/zsb-26015/">CVE-2026-53413</a>, and a use-after-free memory error, <a href="https://www.zoom.com/en/trust/security-bulletin/zsb-26017/">CVE-2026-53415</a>, both of which can read to remote code execution. A third flaw, <a href="https://www.zoom.com/en/trust/security-bulletin/zsb-26016/">CVE-2026-53414</a>, is a missing bounds check that can lead to a denial-of-service condition.</p> <p class="wp-block-paragraph">Zoom also patched a path traversal flaw, <a href="https://www.zoom.com/en/trust/security-bulletin/zsb-26018/">CVE-2026-53416</a>, in the VDI client and plugins that could lead to information disclosure. Zoom VDI (Virtual Desktop Infrastructure) is a special version of the Zoom app that’s designed to run on virtual desktops such as Citrix, VMware Horizon, and Azure Virtual Desktop.</p> <h2 class="wp-block-heading" id="mitigation">Mitigation</h2> <p class="wp-block-paragraph">Aside from updating Zoom clients, organizations can disable the end-to-end encryption (E2EE) setting for their meetings. That’s because Zoom has deployed server-side mitigation for this flaw that filters malicious annotation messages. When E2EE is enabled, the server only sees encrypted messages and cannot perform such filtering.</p> <p class="wp-block-paragraph">Another mitigation is to set the per-platform minimum version for guests and staff in the meeting preferences and only allow patched clients to join meetings.</p> <p class="wp-block-paragraph">“This exploit needed only presence in the meeting, so joining rules are access control: waiting rooms, passcodes, authenticated-users-only, no published personal meeting link,” the researchers said. “Then cut what nobody uses, because every optional feature is another parser. In Zoom, consider locking annotation, file transfer, whiteboarding, remote control and third-party apps, and limiting screen sharing to hosts.”</p> </div></div></div></div>

2026/8/11
阅读更多

GitHub already has an EDR. You just have to listen to it

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">Many of the recent supply-chain attacks could have been caught earlier if defenders looked closely at the telemetry GitHub already provides, researchers said.</p> <p class="wp-block-paragraph">At their Black Hat USA 2026 presentation, researchers <a href="https://www.linkedin.com/in/yossi-weizman/" target="_blank" rel="noreferrer noopener">Yossi Weizman</a> of Microsoft and <a href="https://www.linkedin.com/in/morwn/" target="_blank" rel="noreferrer noopener">Mor Weinberger </a>of Echo argued the case, saying, “GitHub can tell you’re being hacked. You’re just not listening.”</p> <p class="wp-block-paragraph">The duo <a href="https://blackhat.com/us-26/briefings/schedule/?#github-can-tell-youre-being-hacked-youre-just-not-listening-building-edr-for-github-from-its-own-event-stream-53981" target="_blank" rel="noreferrer noopener">described</a> an EDR-style detection approach built from GitHub’s own event stream rather than relying solely on conventional endpoint or network telemetry.</p> <p class="wp-block-paragraph">After studying recent supply-chain attacks, including <a href="https://www.csoonline.com/article/4136476/shai-hulud-style-npm-worm-hits-ci-pipelines-and-ai-coding-tools.html">Shai-Hulud</a>, Trivy, and Megalodon, the researchers found that seemingly different incidents repeatedly used the same techniques, from forged commit identities and poisoned tags to workflow abuse, OpenID Connect (OIDC) theft, and attempts to erase evidence.</p> <p class="wp-block-paragraph">They said they turned those recurring techniques into behavioral detections, combining GitHub webhooks, API data, and Git repository inspection to build a historical view of activity.</p> <p class="wp-block-paragraph">Their new open-source tool, dubbed “GitHub Threat Detector,” reportedly includes 22 production detection rules and 12 beta rules, with compound detections designed to correlate individually weaker signals into high-confidence alerts.</p> <h2 class="wp-block-heading"><a></a>Everything leaves evidence on GitHub</h2> <p class="wp-block-paragraph">The central observation in Weizman and Weinberger’s <a href="https://i.blackhat.com/BH-USA-26/Presentations/USA26-Weinberger-GitHub_Can_Tell-Wed.pdf" target="_blank" rel="noreferrer noopener">research</a> is that supply-chain attacks often repeat the same patterns even when the targeted projects are unrelated.</p> <p class="wp-block-paragraph">A compromised identity, for example, may not be obvious from the commit itself because Git metadata can be forged. An attacker can set the author name, email, timestamp, parent, and other metadata to make a malicious commit appear legitimate.</p> <p class="wp-block-paragraph">But GitHub separately records the authenticated user who pushed the commit.</p> <p class="wp-block-paragraph">When the commit author does not match the authenticated pusher, defenders have something worth investigating, they explained. Added to this, their analysis revealed that attackers sometimes reuse the same forged identities across multiple victims. Searching GitHub for the same author’s email can therefore help connect seemingly unrelated incidents into a broader campaign.</p> <p class="wp-block-paragraph">“Forged identities in the repo which appear in other repos as well-is a strong indication of compromise,” they said.</p> <p class="wp-block-paragraph">The research found “forged maintainer’s identity” used across many attacks, including <a href="https://www.csoonline.com/article/4149905/pypi-warns-developers-after-litellm-malware-found-stealing-cloud-and-ci-cd-credentials.html">Trivy</a>, <a href="https://www.csoonline.com/article/4008621/github-actions-attack-renders-even-security-aware-orgs-vulnerable.html">tj-actions</a>, <a href="https://www.csoonline.com/article/4162865/bitwarden-cli-password-manager-trojanized-in-supply-chain-attack.html">Megalodon</a>, <a href="https://www.csoonline.com/article/4170284/mistral-ai-sdk-tanstack-router-hit-in-npm-software-supply-chain-attack.html">TanStack</a>, and <a href="https://www.csoonline.com/article/4179866/infected-red-hat-npm-packages-expose-developer-credentials.html">Red Hat</a>.</p> <p class="wp-block-paragraph">Another detection pitched on the same principle included tracking “Mass tag poisoning.” Mass tag poisoning involves force-moving numerous release tags onto a malicious commit so that workflows using a version such as @v1 execute attacker-controlled code. Researchers recommended adding tracking GitHub tag history through the GitHub API and comparing old and new commit references to catch this out.</p> <p class="wp-block-paragraph">OIDC offers another signal. Attackers can modify workflows to generate short-lived identities for cloud or package registries instead of stealing long-lived credentials. Watching for new or modified workflows that enable OIDC token issuance can help, the researchers said.</p> <h2 class="wp-block-heading"><a></a>Correlating weak signals for stronger detection</h2> <p class="wp-block-paragraph">GitHub Threat Detector follows an EDR-like pipeline: collect activity, enrich it with context, detect suspicious behavior, and then investigate or respond. The signals it ingests include live GitHub webhooks, API events, commits, tags, and Actions activity, while Git inspection provides additional context such as tag provenance.</p> <p class="wp-block-paragraph">Additionally, a PostgreSQL-backed activity store keeps the history needed to correlate events over time.</p> <p class="wp-block-paragraph">The tool took over 30 detection rules and tested them against 52 attack simulations, including reproduction of Trivy, TanStack, Megalodon, and Bitwarden CLI incidents. A separate “noise lab” helped researchers measure detection prevalence and recall, while tuning rules through allowlisting and severity adjustments.</p> <p class="wp-block-paragraph">The system, however, is not without drawbacks. Some of the trade-offs it carries include possibly disabled webhooks, rate-limited APIs, and Git inspection not being real-time.</p> </div></div></div></div>

2026/8/11
阅读更多

OpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response window

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">OpenAI has expanded its Daybreak cybersecurity program and introduced GPT-5.6-Cyber, a specialized model for approved security researchers, as the company warned that AI could give defenders less time to respond to developing threats.</p> <p class="wp-block-paragraph">Daybreak now has two access levels. Blue gives approved defenders access to frontier general-purpose models such as GPT-5.6 Sol for authorized defensive work, while Red provides specialized cyber models for more advanced activities, including vulnerability research, exploit validation, and security testing.</p> <p class="wp-block-paragraph">OpenAI said GPT-5.6-Cyber is designed to reduce refusals on higher-risk security tasks while improving its ability to conduct exploit development and vulnerability research. In an internal evaluation measuring how often models responded to advanced cybersecurity requests rather than refusing them, GPT-5.6-Cyber completed 95% of requests, compared with 2% for GPT-5.6 Sol under Daybreak Blue.</p> <p class="wp-block-paragraph">The company has also used GPT-5.6-Cyber to investigate real-world software. OpenAI said the model uncovered two previously unknown flaws in Google’s V8 JavaScript engine. Used together, the flaws could enable memory corruption and an escape from V8’s heap sandbox. The findings were reported to Google through coordinated vulnerability disclosure.</p> <p class="wp-block-paragraph">OpenAI categorized GPT-5.6-Cyber as reaching the “High” threshold for cybersecurity capability under its Preparedness Framework, but not the “Critical” threshold.</p> <p class="wp-block-paragraph">Access to Daybreak is limited to approved individuals and organizations, with controls including identity verification and monitoring. OpenAI will also require all individual Daybreak accounts to use hardware security keys beginning September 1, 2026.</p> <h2 class="wp-block-heading" id="pressure-on-vulnerability-response">Pressure on vulnerability response</h2> <p class="wp-block-paragraph">The immediate concern for security leaders is how quickly those capabilities could compress the time available to identify and remediate vulnerabilities.<br><br>“CISOs should assume that the <a href="https://www.csoonline.com/article/4156005/patch-windows-collapse-as-time-to-exploit-accelerates.html">time between</a> vulnerability discovery and exploitation will continue to shrink as advanced AI models accelerate vulnerability research, exploit validation, attack path analysis, and remediation activities,” said <a href="https://www.forrester.com/analyst-bio/biswajeet-mahapatra/BIO20046" target="_blank" rel="noreferrer noopener">Biswajeet Mahapatra</a>, principal analyst at Forrester.</p> <p class="wp-block-paragraph">Mahapatra said the larger change is not necessarily the emergence of entirely new offensive capabilities, but the ability of attackers and defenders to perform existing tasks faster and at greater scale.</p> <p class="wp-block-paragraph">“This increases pressure on organizations to move from periodic vulnerability management to continuous exposure management,” Mahapatra added.</p> <p class="wp-block-paragraph"><a href="https://confidis.co/about/our-leadership-team/" target="_blank" rel="noreferrer noopener">Keith Prabhu</a>, founder and CEO of Confidis, also argued that models such as GPT-5.6-Cyber may accelerate vulnerability discovery and weaponization without fundamentally shifting the attacker-defender balance, because attackers and defenders are likely to gain access to broadly similar capabilities</p> <h2 class="wp-block-heading" id="governance-for-high-risk-cyber-ai">Governance for high-risk cyber AI</h2> <p class="wp-block-paragraph">Enterprises using frontier cybersecurity AI models should impose tighter internal access controls, isolate them in air-gapped or highly restricted environments, and maintain comprehensive logging, monitoring, and anomaly detection, according to <a href="https://omdia.tech.informa.com/authors/lian-jye-su" target="_blank" rel="noreferrer noopener">Lian Jye Su</a>, chief analyst at Omdia.</p> <p class="wp-block-paragraph">Mahapatra said identity verification, monitoring, sandboxing, and restricted access are necessary but not sufficient. Enterprises should also require formal authorization for high-risk activities, retain <a href="https://www.csoonline.com/article/4206598/human-oversight-is-still-critical-as-ai-patching-tools-miss-security-risks.html">human oversight</a>, and review model outputs before they are acted on.</p> <p class="wp-block-paragraph">“Governance should focus not only on controlling access to the model but also on managing how model-generated findings, exploit chains, and recommendations are validated, approved, and acted upon before they affect production environments,” Mahapatra said.</p> <h2 class="wp-block-heading" id="measuring-effectiveness">Measuring effectiveness</h2> <p class="wp-block-paragraph"><a href="https://www.jpdata.co/about/" target="_blank" rel="noreferrer noopener">Anand Joshi</a>, managing director of market research firm JP Data, argued that the acceleration could give enterprises an advantage if they adopt the technology quickly. He pointed to <a href="https://www.csoonline.com/article/4169046/google-discovers-weaponized-zero-day-exploits-created-with-ai.html">zero-day discovery</a> as one of the most immediate enterprise uses for specialized cyber models.</p> <p class="wp-block-paragraph">Prabhu identified vulnerability triage, secure code review, patch validation, incident investigation, and attack-surface analysis as other near-term applications. But greater detection capability could compound a familiar problem for security teams already struggling with more findings than they can remediate.</p> <p class="wp-block-paragraph">“Most security teams already face more findings than they can address, so success should not be measured by the number of vulnerabilities identified,” Mahapatra said.</p> <p class="wp-block-paragraph">Su similarly cautioned against treating vulnerability volume as a measure of success. “The focus should be on continuous posture improvement and limiting downstream impact,” Su said.</p> <p class="wp-block-paragraph">CISOs should look for shorter exposure windows, Mahapatra said, along with faster remediation of critical flaws and fewer exploitable exposures. He added that vulnerability severity should be considered alongside exploit likelihood, the importance of the affected business system, and the context in which it is exposed.</p> </div></div></div></div>

2026/8/11
阅读更多

Security leaders’ rogue AI confidence could actually be disastrous

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">A large majority of IT and security leaders are confident in their teams’ ability to detect when an AI agent has gone rogue, but few are able to take quick action to mitigate the fallout when an agent exceeds its intended scope.</p> <p class="wp-block-paragraph">Nine in 10 IT and security leaders surveyed by <a href="https://www.cio.com/article/4176067/the-ai-governance-imperative-you-cant-afford-to-ignore.html?utm=hybrid_search">IT observability</a> vendor WanAware believe in their capabilities to find malfunctioning agents, but only 26% acknowledge that they can trace the downstream impact within minutes. Over 45% say it would take hours to understand the full impact of an agent incident.</p> <p class="wp-block-paragraph">That delay between detection and mitigation can be a huge problem, says <a href="https://www.linkedin.com/in/jmcollins/">Jeffrey Collins</a>, WanAware’s CEO. The survey suggests IT leaders are overconfident about their ability to control agents, he adds.</p> <p class="wp-block-paragraph">And here, timing is critical, Collins says, given that malfunctioning agents can lead to major outages and data breaches — damage that can start within seconds, he notes.</p> <p class="wp-block-paragraph">“That’s truly the gap here. It’s not if you understand it; it’s when you understand it,” Collins says. “If your average time to just knowing about an event is measured in days, weeks, or months, you have a serious problem right now.”</p> <p class="wp-block-paragraph">While it’s not always easy to tell whether an agent has gone beyond its scope, it’s even harder to tell the downstream impacts, he adds.</p> <p class="wp-block-paragraph">“What’s been affected if one machine was compromised, either from our own AI usage as a customer or from someone else’s, what else could happen, and how can we understand that quickly?” Collins asks.</p> <h2 class="wp-block-heading" id="machine-speed">Machine speed</h2> <p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/kevin-paige-578547a/">Kevin Paige</a>, field CISO at IT solutions provider C1, agrees that time is of the essence when an AI agent malfunctions.</p> <p class="wp-block-paragraph">“The problem is that agents move at machine speed, so the gap between an agent malfunctioning and you catching it isn’t measured in minutes, it’s measured in actions,” he says. “Every minute it’s wrong it’s still working, and because it’s usually running on borrowed standing credentials, the damage spreads across everything those credentials can reach before anyone can pin it on the agent.”</p> <p class="wp-block-paragraph">In many cases, organizations with rogue agents don’t find out from their <a href="https://www.cio.com/article/4195251/19-agentops-tools-for-monitoring-ai-activity-issues-and-costs.html">own detection tools</a>, but from customers, auditors, or broken downstream systems, he says.</p> <p class="wp-block-paragraph">“That’s the worst way to learn,” Paige adds. “The longer-term cost is trust, because one incident like that and the business pulls back on agents entirely, so failing to contain a malfunction fast is also what stalls adoption.”</p> <p class="wp-block-paragraph">The problem with detecting <a href="https://www.cio.com/article/4127774/1-5-million-ai-agents-are-at-risk-of-going-rogue-2.html?utm=hybrid_search">rogue agents</a> is that many organizations have built in visibility but not control, he says.</p> <p class="wp-block-paragraph">“When an agent goes out of scope it’s rarely dramatic,” Paige adds. “Usually, it’s using access it legitimately has, for a purpose nobody signed off on, which means your access model doesn’t even flag it. So you find out after the fact, and you fix it by hand.”</p> <p class="wp-block-paragraph">IT teams can stop agents that exceed their scope, but only if controls were built in before the agent was deployed, adds <a href="https://www.linkedin.com/in/chrisdcamacho/">Chris Camacho</a>, COO of Abstract Security.</p> <p class="wp-block-paragraph">“Every agent should have its own identity, narrowly scoped permissions, and a complete audit trail,” he says. “Just as important, organizations need the ability to immediately revoke that identity or suspend the agent without manually hunting through multiple consoles during an incident.”</p> <p class="wp-block-paragraph">Part of the challenge is that an agent’s activity is spread across identities, cloud platforms, SaaS applications, APIs, and security tools that were not designed to tell a complete story, Camacho says. Security teams often have to piece together events from multiple basic questions such as, what did the agent access, and what changed?</p> <p class="wp-block-paragraph">“Most organizations know where they’ve deployed AI agents,” he adds. “That’s very different from knowing exactly what an agent did after something unexpected happens.”</p> <p class="wp-block-paragraph">The organizations that most successfully manage agents won’t be the ones that deploy the most, he says. “They’ll be the ones that can explain every action an agent took, prove it operated within policy, and stop it immediately when it doesn’t,” he adds.</p> <h2 class="wp-block-heading" id="confidence-isnt-reality">Confidence isn’t reality</h2> <p class="wp-block-paragraph">The survey’s results make sense to <a href="https://www.linkedin.com/in/brinkleyjoseph/">Joe Brinkley</a>, director of offensive security research and community at pentest firm Cobalt. The high confidence in detecting malfunctions is compliance paperwork, whereas the minority of respondents who can detect problems quickly is the reality on the ground, he says.</p> <p class="wp-block-paragraph">“Tracing agent impact fast is brutal,” Brinkley says. “These systems do not run on fixed code paths. They use nondeterministic reasoning across a web of different APIs. Traditional logs only catch isolated events. They completely miss the full execution chain.”</p> <p class="wp-block-paragraph">By the time an anomaly alert hits, an agent has already executed multiple downstream actions, he adds.</p> <p class="wp-block-paragraph">In some cases, agent malfunctions are related to data flow vulnerabilities, such as when a prompt injection from an untrusted input such as a malicious email overwrites the system instructions, he says.</p> <p class="wp-block-paragraph">“We need to be clear about the actual technology; the AI is not waking up angry,” Brinkley says. “The agent suddenly thinks its official job is to dump your database. It spends tokens as fast as possible to do that.”</p> <p class="wp-block-paragraph">Agents are also vulnerable to loop failures, when they hit API errors and try to self-correct, he adds.</p> <p class="wp-block-paragraph">“It hits that same broken endpoint 10,000 times in two minutes,” he says. “It drains your budget and causes a self-inflicted denial of service. It is an automated wrecking ball moving faster than your monitoring can log it.”</p> <p class="wp-block-paragraph">Brinkley recommends that IT leaders put “hard kill” switches at the API layer to stop agents going out of scope.</p> <p class="wp-block-paragraph">“You can stop it, but soft guardrails are useless,” he says. “Do not try to patch the prompt or filter the text. You have to treat the agent like a compromised user account. Pull the OAuth tokens and kill the access immediately.”</p> </div></div></div></div>

2026/8/11
阅读更多

The future of AI security research isn’t autonomous, it’s human-amplified

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">Meet HTTP Terminator, a new AI system that has identified hundreds of websites vulnerable to HTTP request smuggling, hacked them live at scale, and even identified a “genuinely new class” of vulnerability, dubbed “shared-parser confusion.”</p> <p class="wp-block-paragraph">But it didn’t do it alone; it was guided by a human the entire time, which may be the most interesting finding of all.</p> <p class="wp-block-paragraph">A researcher from security company PortSwigger used his own processes to design and build the AI, HTTP Terminator, posed narrow, high-value questions, ruled out weak answers, applied anomaly-detection logic, used deterministic code to restrict agent behavior, and applied findings to subsequent ‘cascade’ research.</p> <p class="wp-block-paragraph">“This inverts the accepted narrative by showing an expert can be a massive amplifier for an AI research system,” <a href="https://portswigger.net/research/james-kettle" target="_blank" rel="noreferrer noopener">James Kettle</a>, PortSwigger’s director of research, explained in a <a href="https://portswigger.net/research/can-ai-do-novel-security-research" target="_blank" rel="noreferrer noopener">white paper</a>. “A human in the loop can still add significant value, as opposed to just building the loop, then stepping back.”</p> <h2 class="wp-block-heading" id="disrupting-http-request-flow">Disrupting HTTP request flow</h2> <p class="wp-block-paragraph">HTTP desync attacks, also known as <a href="https://portswigger.net/web-security/request-smuggling" target="_blank" rel="noreferrer noopener">HTTP request smuggling</a>, interfere with the way web sites process HTTP requests from various users. In this architecture, users send requests to a front-end server, which then forwards them to back-end servers.</p> <p class="wp-block-paragraph">The issue is in the inherently “weak” isolation of requests, Kettle pointed out: The front-end server typically sends several requests at once over the same back-end network connection to improve performance and efficiency.</p> <p class="wp-block-paragraph">“HTTP requests are sent one after another, and the receiving server has to determine where one request ends and the next one begins,” he explained. But front-end and back-end systems must “agree” on where each request ends, otherwise, attackers can send ambiguous messages that are interpreted as two requests by the back end.</p> <p class="wp-block-paragraph">Through response query poisoning (RQP), those attackers can inject false information into subsequent requests or otherwise manipulate data flows so that systems lose track of which responses came from where. They can then intercept responses intended for other users, which can sometimes include sensitive information, credentials, or API keys.</p> <p class="wp-block-paragraph">While request smuggling is typically associated with HTTP/1 requests, websites that support HTTP/2 might also be vulnerable, depending on their back-end architecture, Kettle noted.</p> <p class="wp-block-paragraph">“Request smuggling vulnerabilities are often critical in nature, allowing an attacker to bypass security controls, gain unauthorized access to sensitive data, and directly compromise other application users,” he said.</p> <h2 class="wp-block-heading" id="http-terminators-methodology">HTTP Terminator’s methodology</h2> <p class="wp-block-paragraph">Kettle built HTTP Terminator around his own research methodologies.</p> <p class="wp-block-paragraph">The initial phase is ideation: It autonomously generates hypothetical testable RQP attacks, such as, for instance, desync triggers, patterns, or weaponization techniques.</p> <p class="wp-block-paragraph">The next step is <a href="https://www.csoonline.com/article/4206598/human-oversight-is-still-critical-as-ai-patching-tools-miss-security-risks.html" target="_blank">evaluation</a>: hypotheses are tested at large scale to identify which actually worked. HTTP Terminator used live websites that allow security testing via bug-bounty and Vulnerability Disclosure Programs (VDPs). A built-in anomaly detection layer flagged unusual responses.</p> <p class="wp-block-paragraph">Following that is a weaponization phase, which determines whether findings actually have real-life impact.</p> <p class="wp-block-paragraph">In some cases, they did: HTTP Terminator initially generated 30,000 unique <a href="https://www.csoonline.com/article/4204731/attackers-are-crafting-malicious-ai-instruction-files-to-turn-your-agentic-workflows-into-quiet-criminal-helpers.html" target="_blank">attack vectors</a> that it tested continuously, soon identifying 700 vulnerable targets, including financial institutions and government infrastructure. The system even stole a live API key from one of these banks, and other breaches were traced back to flaws in popular enterprise products like Apache Traffic Server, Citrix NetScaler, and BeyondTrust.</p> <p class="wp-block-paragraph">Finally, there’s a step Kettle calls ‘cascade.’ Each finding may be a clue to an overlooked target or detection path. “When you discover something, if you explore back up the tree you may find other undiscovered branches,” he explained.</p> <p class="wp-block-paragraph">For instance: How could you detect similar behavior elsewhere? And could the behavior enable other types of attacks? Essentially, each finding becomes “the seed for the next.”</p> <p class="wp-block-paragraph">“That might not look like much, but it creates a positive feedback loop which can spiral into a cascade of discoveries taking you beyond predictable findings, into the unknown,” Kettle said.</p> <p class="wp-block-paragraph">Ultimately, “I realized that autonomous vs human is the wrong framing,” he explained. “It’s better to frame system design as AI vs code vs human.”</p> <h2 class="wp-block-heading" id="a-new-tool-for-security-teams">A new tool for security teams</h2> <p class="wp-block-paragraph">HTTP Terminator was able to invent and prove several novel desync triggers, one novel desync pattern, and a desync weaponization technique.</p> <p class="wp-block-paragraph">Notably, though, it identified a new “shared-parser confusion” technique that allows attackers to parse requests and responses and thus increase their attack surface.</p> <p class="wp-block-paragraph">“That, by itself, is absolutely huge,” Kettle said. But, he emphasized, “this discovery was not fully autonomous — the HTTP Terminator proposed it, and I validated it. Neither of us would have discovered it alone.”</p> <p class="wp-block-paragraph">Kettle has open-sourced HTTP Terminator along with his research blueprint so other security teams can “turn their own methodology and instincts into an autonomous research weapon.”</p> <p class="wp-block-paragraph">The researcher advised tackling tasks in four steps: Set an objective, create an evaluation strategy, establish inspiration sources, and explore cascade routes for new discoveries. </p> <p class="wp-block-paragraph">“Evaluation is the first concrete step for both design and implementation,” he said, “because any issues there will derail the entire project.”</p> <p class="wp-block-paragraph">It’s also important to “aggressively” identify and resolve data quality issues, as those will be difficult to correct later on. Further, ask high-value questions without being too broad; review outputs in initial test runs and use them to rule out low-value hypotheses; and remember that “every extra sentence of prompt risks context-contamination,” Kettle said.</p> <p class="wp-block-paragraph">When a system is fully AI-driven and also reliant on AI-built code, it’s near-impossible for it to improve over time, he said. It’s better to start quickly with an AI-heavy approach, then move responsibility to deterministic code for speed and accuracy.</p> <p class="wp-block-paragraph">“Fully autonomous research is real,” Kettle acknowledged. However, “humans are a massive power amplifier for AI research systems.”</p> </div></div></div></div>

2026/8/11
阅读更多

OpenAI says Astra could reach ‘critical’ cyber capability, tightens safeguards

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">OpenAI said its upcoming model Astra is showing cybersecurity capabilities that could reach its highest risk category, where a system can autonomously find and exploit vulnerabilities or carry out end-to-end cyberattacks against hardened targets.</p> <p class="wp-block-paragraph">The company disclosed the assessment following recent internal testing and expert reviews.</p> <p class="wp-block-paragraph">“Our latest internal evaluations of Astra, one of our upcoming models, over the past few days indicate significant advancements in agentic coding and cybersecurity,” OpenAI said in a <a href="https://openai.com/index/responding-next-frontier-critical-cyber-capabilities/" target="_blank" rel="noreferrer noopener">statement</a>. “These results, in addition to expert assessments, have led us to conclude last night that we cannot rule out critical cyber capabilities under our Preparedness Framework⁠.</p> <h2 class="wp-block-heading" id="what-has-changed">What has changed</h2> <p class="wp-block-paragraph">To explain the shift, OpenAI pointed to its internal <a href="https://cdn.openai.com/pdf/18a02b5d-6b67-4cec-ab64-68cdfbddebcd/preparedness-framework-v2.pdf" target="_blank" rel="noreferrer noopener">Preparedness Framework</a>, which tracks how far AI models advance in sensitive areas such as cybersecurity.</p> <p class="wp-block-paragraph">At the top end of that framework are systems that no longer just assist humans but can act on their own, the company said.</p> <p class="wp-block-paragraph">“A model reaches the Critical cybersecurity threshold if it can identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or can devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high-level desired goal,” the statement added.</p> <p class="wp-block-paragraph">The company said Astra has not yet been definitively classified at that level, but its early performance is “strong enough” that such a designation cannot be ruled out. Its earlier models, including GPT 5.6 Sol, “have been evaluated for frontier cyber capabilities and assessed at the High (rather than Critical) threshold.”</p> <p class="wp-block-paragraph">“This is a substantial inflection point,” said Apeksha Kaushik, senior principal analyst at Gartner. “An AI system could autonomously discover vulnerabilities, develop exploits, and execute end-to-end attacks with minimal human guidance.”</p> <h2 class="wp-block-heading" id="why-this-matters-for-enterprises">Why this matters for enterprises</h2> <p class="wp-block-paragraph">For security teams, the change is not just technical — it affects how attacks may unfold, analysts feel.</p> <p class="wp-block-paragraph">Kaushik said the pace of progress suggests “practical, real-world exploitation is becoming increasingly feasible,” meaning attackers could automate large parts of the attack process. That reduces the time defenders have to react.</p> <p class="wp-block-paragraph">“The implication is clear: enterprise security must evolve from reactive to preemptive,” she said, adding that organizations should move toward continuous, AI-driven exposure assessment and predictive analysis.</p> <p class="wp-block-paragraph">Sanchit Vir Gogia, chief analyst at Greyhound Research, said companies should not wait for a formal label before acting.</p> <p class="wp-block-paragraph">“OpenAI has said it cannot rule out critical cybersecurity capability in Astra and is treating the model accordingly. That is a precautionary trigger rather than a finished finding,” he said.</p> <p class="wp-block-paragraph">He added that the focus should shift beyond patching speed. “The measure that matters is defensive response latency. A flat vulnerability queue is no longer a security posture.”</p> <h2 class="wp-block-heading" id="what-openai-is-doing-now">What OpenAI is doing now</h2> <p class="wp-block-paragraph">Based on the development, OpenAI said it is tightening controls around Astra’s development.</p> <p class="wp-block-paragraph">“We are implementing stricter security controls for higher-capability models,” the company said, including “isolated testing environments, restricted network and tool access, enhanced model weight protections and encryption, additional monitoring and detection capabilities, and sandboxed execution,” OpenAI added I n the statement.</p> <p class="wp-block-paragraph">It is also “pausing internal activities involving Astra that do not yet meet these strengthened security control requirements.”</p> <p class="wp-block-paragraph">The company said it has expanded monitoring across how the model is used. “We have implemented universal monitoring for risky actions and misalignment,” it said, adding that systems can “trigger a security response to review and interrupt high-risk activity.”</p> <h2 class="wp-block-heading" id="are-the-safeguards-enough">Are the safeguards enough?</h2> <p class="wp-block-paragraph">Analysts said these steps are necessary, but may not fully address the risks as capabilities improve.</p> <p class="wp-block-paragraph">“Current safeguards such as restricted environments, continuous monitoring, and external red-teaming are necessary, but the gap between safeguards and emerging threats is increasing,” Kaushik said. She pointed to risks such as prompt injection and weak access controls in AI systems.</p> <p class="wp-block-paragraph">Gogia said safeguards need to be viewed in the context of the broader system.</p> <p class="wp-block-paragraph">“A capable model does not operate inside a framework document. It operates inside a system, and systems leak authority through their exceptions,” he said. “Gated access buys defenders time. It does not repeal a capability.”</p> <p class="wp-block-paragraph">OpenAI said it will work with governments and external safety groups to further test Astra.</p> <p class="wp-block-paragraph">“We will work with relevant government agencies and select AI safety organizations to test the capabilities for this model,” the company said, adding that it will also share guidance with third-party testing partners. The company said it is disclosing the findings to be transparent about what it called a “potential shift in capabilities.”</p> </div></div></div></div>

2026/8/10
阅读更多

One-click flaw in Atlassian Rovo exposed enterprise data via prompt injection attack

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">Atlassian’s enterprise AI assistant Rovo, which is usually connected across sensitive work environments like Slack, Microsoft 365, and Google Workspace, was found vulnerable to data leaks through malicious instructions.</p> <p class="wp-block-paragraph">At <a href="https://defcon.org" target="_blank" rel="noreferrer noopener">DEF CON 34</a>, researchers from Varonis demonstrated an attack that used Rovo’s rovoChatPrompt parameter to place attacker-controlled instructions directly into Rovo Chat.</p> <p class="wp-block-paragraph">“A single click on a link triggers the attacker’s embedded instructions and forces Rovo to accept externally supplied parameters as trusted inputs within a user’s session,” Varonis researcher Dolev Taler said in a blog <a href="https://www.varonis.com/blog/rovoblast" target="_blank" rel="noreferrer noopener">post</a>, dubbing the attack “RovoBlast.”</p> <p class="wp-block-paragraph">The attack only required one click by the victim on a specially crafted link, which then allowed the attacker to potentially access anything Rovo is privileged.</p> <p class="wp-block-paragraph">The issue was reported to Atlassian through a bug bounty program hosted on Bugcrowd, and the company has since <a href="https://bugcrowd.com/disclosures/bf1922fb-99d0-4d3b-b419-1728720d29ec/one-click-data-exfiltration-via-rovochatprompt-url-parameter-confluence-rovo" target="_blank" rel="noreferrer noopener">fixed</a> it. The company, however, did not immediately respond to CSO’s request for comments.</p> <h2 class="wp-block-heading"><a></a>Rovo’s broad access made the click worse</h2> <p class="wp-block-paragraph">Varonis found that Rovo could enumerate and search data across a wide range of sources available to an organization, including Jira, Confluence, Bitbucket, Slack, Google Workspace, Microsoft 365, relational databases, uploaded files, webpages, and archives.</p> <p class="wp-block-paragraph">Rovo connectors extend reach to more than 50 platforms, Varonis said. Attackers could access data protected behind credentials without a compromise. This could all look like legitimate activity performed by the assistant on behalf of a user.</p> <p class="wp-block-paragraph">Taler also noted that Rovo cannot be fully uninstalled.</p> <p class="wp-block-paragraph">“Organizations attempting to remove the risk may not be able to eliminate Rovo’s presence in their environment or the associated attack surface, making robust input validation and security controls even more critical,” he said.</p> <h2 class="wp-block-heading"><a></a>Exfiltration was possible</h2> <p class="wp-block-paragraph">Varonis researchers then looked at whether Rovo’s agent capabilities could turn the access to corporate information into an actual data-exfiltration path.</p> <p class="wp-block-paragraph">They found that they could.</p> <p class="wp-block-paragraph">Rovo’s “ResearchAgent,” it turned out, could perform deep, multi-source web research and navigate across websites through multiple autonomous steps. In Varonis’ testing, that created a potential chain in which Rovo could retrieve information from internal sources and move it toward an external destination.</p> <p class="wp-block-paragraph">Importantly, the researchers said they did not need a jailbreak, a double request technique, or a complicated prompt-surgery attack. The single culprit clicking on the crafted Rovo link was enough to seed the malicious instructions.</p> <p class="wp-block-paragraph">Once inside the session, autonomous agent capabilities were shown to be capable of carrying out the attack in its entirety. “Rovo includes built-in automation that accelerates exfiltration once misused,” Taler added.</p> <p class="wp-block-paragraph">As the threat extended from a failing AI guardrail to the risk of automated damage escalation, researchers advised measures beyond a patch.</p> <p class="wp-block-paragraph">They recommended shrinking Rovo’s blast radius by limiting connected systems, keeping highly sensitive areas such as legal, HR, finance, and incident response out of scope, and disabling browsing or multi-step automation that organizations do not need.</p> <p class="wp-block-paragraph">“The less the assistant can see, the less it can leak, regardless of prompt injection or agent abuse,” they said.</p> <p class="wp-block-paragraph">Varonis drew parallels with other recently disclosed AI attacks like <a href="https://www.csoonline.com/article/4186970/m365-copilot-searchleak-your-prompt-injection-attack-surface-just-got-bigger.html">SearchLeak</a>, <a href="https://www.csoonline.com/article/4068175/gemini-trifecta-ai-autonomy-without-guardrails-opens-new-attack-surface.html">EchoLeak</a>, <a href="https://www.csoonline.com/article/4059606/meet-shadowleak-impossible-to-detect-data-theft-using-ai.html">ShadowLeak</a>, and <a href="https://www.csoonline.com/article/4161382/prompt-injection-turned-googles-antigravity-file-search-into-rce.html">Antigravity</a>. The company said RovoBlast is just another example of a broader AI security issue where “untrusted inputs, autonomous behavior, and trusted communication” are together creating serious data exposure.</p> </div></div></div></div>

2026/8/10
阅读更多

4 million fake applications and one blind spot: A SOC playbook for OAuth client ID spoofing

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <h2 class="wp-block-heading" id="key-takeaways">Key takeaways</h2> <ul class="wp-block-list"> <li>OAuth client ID spoofing defeats detections that key off application name or a known application ID, because the field itself is fabricated, rotated or blank.</li> <li>AADSTS700016 paired with an unrecognized client ID can mean valid credentials, not a broken app registration — treat it as a triage signal, not noise.</li> <li>Effective detection logic correlates client ID cardinality, missing application names and AADSTS error sequences across a time window, not any single event.</li> <li>A rehearsed response runbook (reset, revoke, review) matters as much as the detection query itself, and the cost of skipping it shows up as account takeover, not just alert fatigue.</li> </ul> <h2 class="wp-block-heading" id="the-signal-hiding-in-plain-sight">The signal hiding in plain sight</h2> <p class="wp-block-paragraph">Picture a queue of failed sign-in alerts against Microsoft Entra ID. Each one points to a different application ID. None of the IDs are registered in the tenant. None crosses a volume threshold on its own. Nothing about the queue reads as a coordinated campaign; it reads like the normal debris of expired app registrations and forgotten test scripts that every tenant accumulates. An analyst scanning for a named application spiking in failures would scroll right past this queue without a second look. That is the point. Since December 2025, at least two threat actors have built enumeration campaigns specifically engineered to look like configuration noise instead of an attack, and the difference between the two is a detection-engineering question, not just a threat-intel one.</p> <h2 class="wp-block-heading" id="the-mechanism-in-three-error-codes">The mechanism, in three error codes</h2> <p class="wp-block-paragraph">The technique abuses the OAuth 2.0 Resource Owner Password Credentials (ROPC) flow, in which a single token request bundles a username, password, and client ID. Three Entra ID response codes carry the signal that matters.</p> <p class="wp-block-paragraph"><strong>AADSTS50034</strong> means the username doesn’t exist. <strong>AADSTS50126</strong> means the username exists, but the password is wrong. <strong>AADSTS700016</strong> fires when the username and password are both valid but the client ID isn’t recognized. That last code is the one worth building a detection around: on its own, it looks like an app-registration problem an admin forgot to clean up. When paired with an unfamiliar, constantly rotating client ID, it can mean an attacker has already confirmed a working credential pair and is one step away from account takeover.</p> <p class="wp-block-paragraph">ROPC persists in more environments than security teams expect. It survives in legacy scripts, CI pipelines and third-party integrations built before <a href="https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth-ropc">Microsoft’s guidance</a> to avoid it, precisely because it is the path of least resistance for developers who never need to open a browser. That installed base is what gives the technique room to operate. Attackers are not exploiting a rare misconfiguration; they are exploiting a flow that is still common enough to hide inside.</p> <div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/oauth-client-id-spoofing-attack-and-detection-workflow.png?w=1024" alt="Figure: OAuth client ID spoofing – Attack and detection workflow." class="wp-image-4206767" width="1024" height="625" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Figure 1. OAuth client ID spoofing attack and detection workflow.</figcaption></figure><p class="imageCredit">Sunil Gentyala</p></div> <h2 class="wp-block-heading" id="two-campaigns-one-detection-gap">Two campaigns, one detection gap</h2> <p class="wp-block-paragraph"><strong>UNK_pyreq2323. </strong><a href="https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy">Proofpoint</a> tracked this campaign running from AWS infrastructure, mutating the trailing digits of a real Exchange Online app ID across more than 700,000 variations, reusing each one against no more than a dozen accounts before discarding it. The campaign targeted over a million users across roughly 4,000 tenants, with about 28 percent of touched accounts hitting lockout.</p> <p class="wp-block-paragraph"><strong>UNK_OutFlareAZ. </strong>Running mostly through Cloudflare, this campaign skipped mutation entirely and generated a fresh random UUID per request: 3.7 million spoofed IDs against more than two million accounts, peaking near 720,000 targeted users on March 15, 2026.</p> <p class="wp-block-paragraph">Proofpoint’s own researchers say they can’t yet confirm whether this is one actor or two independent clusters converging on the same trick through forum discussion and trial and error, a point <a href="https://www.helpnetsecurity.com/2026/07/13/entra-id-oauth-client-id-spoofing/">Help Net Security</a> also covered in reporting on the research. For detection purposes, that ambiguity doesn’t matter. Both campaigns defeat the same control, per-application volume thresholds, using the same gap: an uncorrelated, disposable identifier field that nobody is watching for cardinality.</p> <h2 class="wp-block-heading" id="why-this-is-a-ciso-problem-not-just-a-queue-problem">Why this is a CISO problem, not just a queue problem</h2> <p class="wp-block-paragraph">A 28 percent lockout rate across a million-user campaign is not a rounding error. It is a helpdesk cost, a productivity hit and, for every account where AADSTS700016 fired before the lockout, a live credential an attacker has already validated and can use elsewhere: mailbox access, OAuth consent grants, lateral movement into connected SaaS. The detection gap here isn’t cosmetic. It is the difference between catching a validated-credential event while it’s still isolated to one authentication attempt and finding out about it three weeks later from a mailbox-forwarding rule or a fraudulent wire request. That is what makes this worth a rule, not just a footnote in a threat-intel digest.</p> <h2 class="wp-block-heading" id="building-the-detection">Building the detection</h2> <p class="wp-block-paragraph">A workable rule reconstructs the request sequence instead of scoring one event in isolation. Over Entra ID sign-in logs, or the equivalent SIEM ingestion, the core logic looks like this:</p> <pre class="wp-block-code"><code>SigninLogs | where TimeGenerated &gt; ago(1h) | where ResultType in ("50034", "50126", "700016") or isempty(AppDisplayName) | summarize DistinctClientIDs = dcount(AppId), ResultCodes = make_set(ResultType), Usernames = make_set(UserPrincipalName) by SourceIPAddress, UserAgent, bin(TimeGenerated, 15m) | where DistinctClientIDs &gt; 5 | where ResultCodes has "700016"</code></pre> <p class="wp-block-paragraph">The two variables that matter most are DistinctClientIDs, because a single source cycling through many unregistered app IDs is the tell that per-application thresholds miss, and the presence of AADSTS700016 in that same window, which elevates the event from configuration noise to possible credential validation in progress. Layer in username-pattern detection, alphabetic or dictionary progression across attempts from the same source, to catch the OutFlareAZ-style wordlist pattern specifically.</p> <p class="wp-block-paragraph">Tune the DistinctClientIDs threshold against your own tenant’s baseline before trusting it in production. A dev team running CI against a handful of test app registrations can produce a smaller version of the same shape, and Conditional Access policies scoped only to named applications will not catch a fabricated client ID that never matches an intended application scope in the first place.</p> <p class="wp-block-paragraph">Wire the rule into existing SOAR or ticketing workflows rather than a standalone dashboard nobody checks on a Friday afternoon. A detection that fires into the same queue as password-spray and impossible-travel alerts gets triaged with the same urgency; one that lands in an isolated identity-hygiene report gets read weeks later, if at all.</p> <h2 class="wp-block-heading" id="separating-signal-from-noise">Separating signal from noise</h2> <p class="wp-block-paragraph">Not every blank-app-name or 700016 event is an attack. Deleted app registrations, expired multi-tenant consent, wrong-tenant endpoint calls and CI pipelines pointed at the wrong client ID all produce similar-looking noise. Two filters cut the false-positive rate substantially. Legitimate misconfiguration is almost always low-cardinality, one or two client IDs, not dozens, and it repeats from known internal infrastructure. The attack pattern is high-cardinality and arrives from unfamiliar ASNs or hosting-provider ranges. Cross-referencing against existing password-spray and impossible-travel alerts before escalating avoids paging an analyst for a stale service principal, and tracking the rule’s precision over its first few weeks, confirmed incidents versus total fires, is worth doing before treating it as production-grade. Document the triage criteria alongside the rule itself, since the next analyst on shift needs the same reasoning to close a ticket with confidence rather than escalate out of caution.</p> <h2 class="wp-block-heading" id="the-response-runbook">The response runbook</h2> <p class="wp-block-paragraph">When the correlated signal fires, the runbook should be short and rehearsed before it’s needed, not improvised during the incident. Force a password reset on the affected account, revoke active sessions and refresh tokens, and review sign-in and mailbox-access activity for the days following the AADSTS700016 hit, since that is the window where a confirmed credential gets used elsewhere.</p> <p class="wp-block-paragraph">Retiring ROPC entirely, migrating interactive apps to browser-based auth and service workloads to managed identities or certificate-based service principals, removes the flow this technique depends on. Until that migration is complete, the detection above is what stands between a ticket closed as configuration noise and a caught account-takeover attempt.</p> <h2 class="wp-block-heading" id="the-broader-lesson-for-detection-engineers">The broader lesson for detection engineers</h2> <p class="wp-block-paragraph">The reusable lesson here isn’t about OAuth specifically. Any field a defender logs but doesn’t correlate — application ID, user agent, ASN, whatever comes next — is a candidate for an attacker to fragment their traffic across until per-field thresholds stop tripping.</p> <p class="wp-block-paragraph">Four million fake applications is what that gap looks like at scale when nobody is watching cardinality instead of volume, and it is the same underlying playbook as <a href="https://attack.mitre.org/techniques/T1078/004/">MITRE ATT&amp;CK’s Valid Accounts: Cloud Accounts</a>, T1078.004: an attacker using technically valid credentials. The fix generalizes regardless of which field gets exploited next. Build detections around behavioral sequences across multiple fields and a time window, not a single field crossing a static threshold.</p> </div></div></div></div>

2026/8/10
阅读更多

7 key trends defining the cybersecurity market today

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">AI is having a seismic impact on the cybersecurity market. Record-shattering amounts of venture capital is flowing into a new generation of startups focused on AI cybersecurity.</p> <p class="wp-block-paragraph">At the same time, established cybersecurity vendors are racing to integrate AI and agentic AI features into their platforms, triggering a surge in acquisition activity. But while AI is the most significant driver of cybersecurity market trends, it’s not the only one.</p> <p class="wp-block-paragraph">Here are the top cybersecurity market trends this year.</p> <h2 class="wp-block-heading" id="vc-funding-hits-new-highs">VC funding hits new highs</h2> <p class="wp-block-paragraph">Global venture funding reached a record $510 billion in the first half of 2026, topping the $440 billion invested last year, according to <a href="https://news.crunchbase.com/venture/global-startup-exits-ipo-ma-soar-ai-q2-h1-2026/">Crunchbase</a>. OpenAI and Anthropic accounted for $217 billion or 43% of that startup funding, but investors also poured billions into more than 5,000 other startups in the first half of 2026.</p> <p class="wp-block-paragraph">“Venture capital is concentrating into AI-enabled cybersecurity companies: 72% of US cyber deals through May 2026 involved an AI-enabled company,” according to John China, co-head of innovation economy at J.P. Morgan Commercial Banking.</p> <p class="wp-block-paragraph">Crunchbase predicts that 2026 “may be remembered not only as the year venture funding reached a new high, but as the beginning of a cycle in which record private investment and a functioning exit market reinforce one another,” leading to a new wave of public cybersecurity companies.</p> <p class="wp-block-paragraph">Here are three major 2026 VC deals involving cybersecurity companies:</p> <ul class="wp-block-list"> <li><strong>Keyfactor</strong>, which provides a trust infrastructure based on secure certificates and encryption keys for AI and machine identities, raised $1 billion in July.</li> <li><strong>Cyera</strong>, which offers an AI-native data security platform, raised $600M in June, boosting its total amount of VC investment to $2.3B.</li> <li><strong>Upwind Security</strong> raised $250M in January to support its runtime-first, cloud-native security platform.</li> </ul> <p class="wp-block-paragraph">See also: “<a href="https://www.csoonline.com/article/4080699/10-promising-cybersecurity-startups-cisos-should-know-about.html">10 promising cybersecurity startups CISOs should know about</a>.”</p> <h2 class="wp-block-heading" id="new-ai-centric-product-categories-emerge">New AI-centric product categories emerge</h2> <p class="wp-block-paragraph">AI has created entirely new product categories. Gartner lists some of them as LLM security, prompt injection detection, model integrity, AI firewalling, AI governance, AI red teaming, and shadow AI discovery.</p> <p class="wp-block-paragraph">Prompt Security has built an <a href="https://prompt.security/ai-security-startup-map">AI security startup map</a> that covers 367 companies. The breakdown, with companies potentially appearing multiple times, looks like this: AI observability and governance (239 vendors); runtime security and guardrails (188); agentic identity protection (89); MCP and LLM gateways (79); AI red teaming (78); AI-SPM (64); agentic data governance (63); and model security (52).</p> <p class="wp-block-paragraph">Richard Stiennon, who tracks cybersecurity vendors in his IT-Harvest database, has identified 21 distinct AI security categories, including SOC automation, governance, vulnerability management, guardrails, model security, deepfake defense, agent security, MCP security, and AI identity. There is no indication that the growth rate is slowing down. In June, Stiennon added 20 new AI security startups to his database.</p> <p class="wp-block-paragraph">Representative vendors include Noma Security, Hidden Layer, Zenity, Latera Guard, Rebuff, Vigil, LLM Guard, Vectra AI, 7ai, and Mindguard.</p> <p class="wp-block-paragraph">See also: “<a href="https://www.csoonline.com/article/3518733/ai-spm-buyers-guide-artificial-intelligence-security-posture-management-tools-compared.html">AI-SPM buyer’s guide: 14 tools to secure your AI infrastructure</a>.”</p> <h2 class="wp-block-heading" id="cyber-ma-activity-surges">Cyber M&amp;A activity surges</h2> <p class="wp-block-paragraph">For CISOs trying to make sense of the dizzying explosion of new AI-focused security tools, the traditional cybersecurity market leaders are filling gaps in their portfolios via acquisition.</p> <p class="wp-block-paragraph">Investment bank <a href="https://momentumcyber.com/cybersecurity-mid-year-market-review-h1-2026/">Momentum Cyber</a>, which tracks cybersecurity M&amp;A activity, reports that at the halfway point of 2026, there have been 219 transactions worth $9.1B, putting 2026 on pace for the highest deal count it has ever tracked and 11% above 2025’s record year.</p> <p class="wp-block-paragraph">For example, <a href="https://www.csoonline.com/article/4114957/crowdstrike-to-acquire-sgnl-for-740m-expanding-real-time-identity-security.html">CrowdStrike bought SGNL</a> to bolster identity security across human, non-human, and AI identities. Cisco bought agentic AI security vendor WideField Security, <a href="https://www.networkworld.com/article/4166695/cisco-grabs-astrix-to-secure-ai-agents.html">non-human identity security platform Astrix</a>, and <a href="https://www.networkworld.com/article/4156855/cisco-to-acquire-galileo-for-ai-observability.html">AI observability vendor Galileo</a>. Check Point acquired Cyata, which provides governance of AI agents. Zscaler is buying <a href="https://www.networkworld.com/article/4182976/zscaler-launches-zero-trust-platform-for-agentic-ai.html">AI and data security firm Symmetry Systems</a>.</p> <p class="wp-block-paragraph">Palo Alto Networks is acquiring <a href="https://www.csoonline.com/article/3518733/ai-spm-buyers-guide-artificial-intelligence-security-posture-management-tools-compared.html">AI gateway startup Portkey</a>, as well as <a href="https://www.networkworld.com/article/4133374/palo-alto-to-acquire-israeli-startup-koi-for-agentic-ai-security.html">Koi for its agentic endpoint security technology</a>. 1Password has acquired Apono, which specializes in just-in-time access governance for humans, machines, and AI. A10 Networks bought TrojAI to add AI red-teaming and runtime protection to its security portfolio.</p> <p class="wp-block-paragraph">June was the strongest month of the year with 39 M&amp;A transactions and $4.9B of disclosed value, signaling growing momentum toward larger, more transformative strategic outcomes in the second half, according to Momentum Cyber.</p> <p class="wp-block-paragraph">See also: “<a href="https://www.csoonline.com/article/569075/the-10-most-powerful-cybersecurity-companies.html">10 most powerful cybersecurity companies today</a>.”</p> <p class="wp-block-paragraph">Advertisement. Scroll to continue reading.</p> <h2 class="wp-block-heading" id="platform-momentum-grows">Platform momentum grows</h2> <p class="wp-block-paragraph">Despite the healthy VC market for startup security vendors, the overarching trend toward platforms remains unchallenged. Enterprise CISOs are certainly deploying specific point products to address security gaps, but they are also demanding tools that integrate with their broader platforms.</p> <p class="wp-block-paragraph">Gartner points out that enterprises that may have had 60 to 100 security tools are now targeting 20 to 30 integrated platforms. Vendors are responding by expanding into adjacent markets, such as endpoint security and identity management; SIEM and XDR; email and browser security.</p> <p class="wp-block-paragraph">The vendors with the strongest momentum in 2026 tend to share several characteristics: broad security platforms rather than single-purpose tools, AI-native automation and agentic capabilities, strong identity and cloud security integration, unified data architecture and outcome-focused messaging (reduced risk, faster response, measurable resilience).</p> <p class="wp-block-paragraph">“Conversely, vendors offering standalone products without differentiated AI, automation, or platform integration are under increasing pressure to consolidate, partner, or specialize,” Gartner says.</p> <p class="wp-block-paragraph">Forrester analyst Jess Burn puts it more bluntly: “It’s time to ditch standalone security tools that don’t integrate well or offer enough visibility. While single-function tools work for niche needs, relying too heavily on them creates inefficiencies — especially now that multipurpose platforms are more common. Focus instead on solutions that prioritize integration, automation, and productivity.”</p> <p class="wp-block-paragraph">See also: “<a href="https://www.csoonline.com/article/2515727/6-tips-for-consolidating-your-it-security-tool-set.html">6 tips for consolidating your IT security tool set</a>.”</p> <h2 class="wp-block-heading" id="quantum-security-gets-real">Quantum security gets real</h2> <p class="wp-block-paragraph">Threats posed by attackers using quantum computing to break public-key encryption have seemed like something CISOs could put on the back burner and deal with at some point in the future. But <a href="https://www.csoonline.com/article/4150887/google-the-quantum-apocalypse-is-coming-sooner-than-we-thought.html">that future has arrived</a>, and the vendor community is now offering tools to help enterprises identify potentially vulnerable datasets, and to migrate to quantum-safe environments.</p> <p class="wp-block-paragraph">The “<a href="https://www.csoonline.com/article/4180902/reap-now-decipher-later-thats-the-approach-to-cybersecurity-in-the-quantum-age.html">harvest-now, decrypt later</a>” approach taken by potential adversaries has created an urgency to protect sensitive data. And US President Donald Trump signed an executive order in June signaling the <a href="https://www.csoonline.com/article/4188510/trump-sets-post-quantum-crypto-deadlines-launches-broader-federal-quantum-initiative.html">federal government’s effort to accelerate quantum security</a>. The order calls for a nationwide transition to post-quantum cryptography by 2031.</p> <p class="wp-block-paragraph">Gartner analyst Alex Michaels says, “Post-quantum cryptography alternatives must be adopted now to avoid potential data breaches, legal liability, and financial loss from ‘harvest now, decrypt later’ attacks targeting long-term sensitive data.”</p> <p class="wp-block-paragraph">Some of the leading vendors in the emerging quantum security market include SandboxAQ, QuSecure, Post-Quantum, Quintessance, and Fortanix. In addition, familiar faces such as <a href="https://www.csoonline.com/article/3577874/ibm-adds-quantum-resistant-controls-within-new-security-suite.html?utm=hybrid_search">IBM</a>, <a href="https://www.csoonline.com/article/4123719/palo-alto-warns-of-quantum-risk-to-digital-security.html?utm=hybrid_search">Palo Alto Networks</a>, Microsoft, Cisco, and Google are offering or developing protections against quantum-based attacks.</p> <p class="wp-block-paragraph">See also: “<a href="https://www.csoonline.com/article/3552701/the-cisos-guide-to-establishing-quantum-resilience.html">The CISO’s guide to establishing quantum resilience</a>.”</p> <h2 class="wp-block-heading" id="managed-security-services-mss-gain-momentum">Managed security services (MSS) gain momentum</h2> <p class="wp-block-paragraph">The largest cybersecurity transaction in 2026 so far was Accenture’s $4.175B acquisitions of Dragos, NetRise, and runZero. Accenture’s goal is to create a unified cybersecurity platform to protect critical infrastructure, including industrial control systems, IoT, sensors, and cloud-connected devices — and to offer that protection as a managed service.</p> <p class="wp-block-paragraph">Accenture’s entry into managed security services is an attempt to offset softness in its consulting business, according to analysts, but also reflects the fact that <a href="https://www.csoonline.com/article/4040161/7-signs-its-time-for-a-managed-security-service-provider.html">managed security services is a hot growth area</a>.</p> <p class="wp-block-paragraph">“Cybersecurity is being reshaped by expanding attack surfaces, AI-enabled threats, and intensifying regulatory scrutiny. Managed security services (MSS) are reflecting this momentum, with spending expected to rise from approximately <strong>$35.6 billion in 2025 to over $52 billion by 2028</strong>,” according to <a href="https://www.frost.com/growth-opportunity-news/security/cybersecurity/from-security-operations-to-strategic-resilience-how-managed-security-services-mss-are-redefining-cyber-risk-management-sec02_tg02_managedsecurityservices_apr26_cim-ms/">Frost &amp; Sullivan</a>.</p> <p class="wp-block-paragraph">GrandView Research says that enterprises are turning to managed services for advanced threat intelligence, round-the-clock monitoring, incident response, and vulnerability management. “The services segment is witnessing robust growth as organizations prioritize agility, expertise, and scalable cybersecurity capabilities to safeguard critical data, ensure regulatory compliance, and strengthen overall resilience against sophisticated cyberattacks,” according to <a href="https://www.grandviewresearch.com/industry-analysis/cyber-security-market">GrandView</a>.</p> <p class="wp-block-paragraph">The market for managed cybersecurity services is rapidly expanding on two fronts. There are pure-play MSS vendors such as Arctic Wolf, Huntress, and SentinelOne. In addition, established vendors such as Dell, Microsoft, Cisco, Palo Alto Network, and others are <a href="https://www.csoonline.com/article/4022854/8-trends-transforming-the-mdr-market-today.html">delivering managed detection and response (MDR)</a>.</p> <p class="wp-block-paragraph">See also: “<a href="https://www.csoonline.com/article/573533/top-12-managed-detection-and-response-solutions.html">Top 12 managed detection and response solutions</a>.”</p> <h2 class="wp-block-heading" id="the-rise-of-data-security-posture-management-dspm">The rise of data security posture management (DSPM)</h2> <p class="wp-block-paragraph">The market has stepped up to meet the growing need for a holistic approach to securing data with a product category called <a href="https://www.csoonline.com/article/4166051/how-cisos-should-utilize-data-security-posture-management-to-inform-risk.html">data security posture management (DSPM)</a>. These tools discover, classify, and secure data across environments and use cases.</p> <p class="wp-block-paragraph">“In today’s landscape of expanding data assets, the use of AI, and evolving data breach threats, data security posture management tools are in high demand,” says Gartner analyst Jaimie Anderson.</p> <p class="wp-block-paragraph">Krista Case, research director at Futurum Group, adds, “DSPM is increasingly central to how organizations think about visibility and control over sensitive data in hybrid, multi-cloud environments.”</p> <p class="wp-block-paragraph">As often happens when a product category takes off, startups lead the way and established vendors start snapping them up. In the DSPM market, Palo Alto bought Dig Security, IBM bought Polar Security, Thales bought Imperva, Rubrik bought Laminar, Proofpoint bought Normalyze, Commvault bought Satori, Veeam bought Securiti, and so on.</p> <p class="wp-block-paragraph">This gives CISOs plenty of choices from among their platform partners, but there are still a number of independent DSPM players such as Cyera, Skyhigh, BigID, Concentric, and Sentra.</p> <p class="wp-block-paragraph">“The future looks bright for DSPM,” says Omdia Research analyst Adam Strange, adding, “DSPM has both critical mass and momentum.”</p> <p class="wp-block-paragraph">See also: “<a href="https://www.csoonline.com/article/2075321/top-12-data-security-posture-management-tools.html">DSPM buyer’s guide: Top 10 data security posture management tools</a>.”</p> </div></div></div></div>

2026/8/10
阅读更多