SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph"><strong>Ninety-five percent of organizations believe they have visibility into their AI and machine identity exposures, yet only 36% are actually monitoring them.</strong></p> <p class="wp-block-paragraph"><a href="https://spycloud.com/">SpyCloud</a>, the leader in identity threat protection, today released its annual <a href="http://spycloud.com/resource/report/identity-threat-report-2026/"><strong>SpyCloud Identity Threat Report</strong></a>, a survey-based study finding that non-human identities (NHIs) – the AI agents, service accounts, API keys, and authentication tokens that connect to internal systems – have become the most common route attackers take into the enterprise.</p> <p class="wp-block-paragraph"><img loading="lazy" src="https://imgproxy.citrusreader.com/1AyES5Jw_sIhmcOBiLEDyOM0GHa6JZbQNvfw_aS31uE/raw:1/aHR0cHM6Ly9iMmItY29udGVudGh1Yi5jb20vY2RiMzJhYmQtMDA0MS00ZmIwLThjYTEtNzMzNWViYzEzZjYw" width="602" height="531">SpyCloud 2026 Identity Threat Report, Source: SpyCloud</p> <p class="wp-block-paragraph">The survey found that compromised NHIs (31%) are nearly 2x as likely to be the primary entry point compared to phishing and social engineering (17%), the second-ranked answer. NHI-related misuse was also the most commonly reported identity-based event type at 42%, yet the vast majority of organizations aren’t watching for them. While 95% of organizations believe they have adequate visibility into AI- and NHI-related exposures, only 36% monitor them, making machine identities the least-watched category of identity risk in the report. Further amplifying the problem, 68% of organizations experienced an identity-based event in the same period, with those affected averaging eight events each.</p> <p class="wp-block-paragraph">Organizations typically maintain a clear inventory of their human workforce, but few extend that same visibility to the service accounts, API keys, and AI agents authenticating into their systems every day. These identities are provisioned for convenience and often hold real privilege, yet in most environments nobody owns them: a service account doesn’t get off-boarded, doesn’t rotate its own credentials, and doesn’t fail an MFA challenge, so once one is exposed it can stay usable for months.</p> <p class="wp-block-paragraph">“That asymmetry is what attackers are exploiting,” said <strong>Trevor Hilligoss, SpyCloud’s Chief Intelligence Officer.</strong> “Every one of these identities is a standing invitation that renews itself until someone notices.”</p> <p class="wp-block-paragraph">This year’s report is based on a survey of 750 cybersecurity leaders and practitioners at organizations with 500+ employees across North America (US and Canada), the United Kingdom, and select European markets – Spain, Germany, the Netherlands, Austria, and Switzerland. It benchmarks how organizations detect, remediate, and govern identity threats across human and non-human identities.</p> <p class="wp-block-paragraph"><strong>Additional key findings include:</strong></p> <ul class="wp-block-list"> <li><strong>AI adoption has outpaced governance. </strong>Nearly all organizations (91%) use AI tools or agents with access to internal systems, applications, or data, but only 56% have formal governance and ownership for the resulting privileges. Another 41% rely on informal processes or partial ownership, leaving shadow access – privileged connections operating outside normal governance and monitoring.</li> <li><strong>Exposed session blind spots track with higher event rates. </strong>Organizations that had visibility into stolen session cookies experienced identity-based events at a meaningfully lower rate (37%) than those that could not (50%). </li> <li>Session cookies and tokens let attackers bypass authentication controls like MFA by resuming an already-authenticated session. This gives them trusted access to applications and data, it’s no surprise then that SpyCloud research shows that session data has overtaken passwords as <a href="https://spycloud.com/newsroom/spycloud-surpasses-one-trillion-recaptured-identity-assets/">attackers’ top target</a>.</li> <li><strong>Phishing and malware remain the delivery mechanism. </strong>Phishing and social engineering is cited as a common access path for identity events (37%) with 40% reporting incomplete visibility into successful phishing attacks, and 53% can see malware exposures on managed devices <em>only</em>.</li> <li><strong>Malware and exposed access top the list of supply chain identity events. </strong>Malware-infected third-party devices (23%) and exposed API keys or application access involving vendors and partners (22%) were the leading reported causes of supply chain identity events.</li> <li><strong>Third-party exposures are getting found, but not closed. </strong>Nearly 40% of organizations have no consistent process to confirm that a third-party identity exposure was actually resolved, even as 32% name enhancing supply chain and vendor risk management among their planned investments for the next 12 to 18 months.</li> </ul> <p class="wp-block-paragraph">Non-human identities and third-party exposures are creating new paths into the enterprise, while stolen sessions give attackers ways around controls designed to protect authenticated users.</p> <p class="wp-block-paragraph">“Every control that works pushes attackers toward what it doesn’t cover – we hardened passwords, so they targeted sessions; we tightened employee accounts, so they looked to service accounts and vendor connections,” added Hilligoss. “SpyCloud continues to track threat actor behavior closely to understand where attackers are moving, what data they value, and how those patterns evolve over time.”</p> <p class="wp-block-paragraph"><strong>Continuous monitoring &amp; automation separate the most resilient identity programs</strong></p> <p class="wp-block-paragraph">Identity exposure creates an ongoing operational burden that extends well beyond the initial incident, and how quickly organizations respond has a direct impact on business outcomes. Those relying on manual, case-by-case remediation reported higher incident response costs than organizations with high levels of automation (39% versus 32%) and greater loss of customer or partner trust (47% versus 36%).</p> <p class="wp-block-paragraph">The report also introduces <a href="https://spycloud.com/identity-threat-protection-maturity-assessment/">SpyCloud’s Identity Threat Protection Maturity Model</a>, which groups respondents into four maturity tiers – Reactive, Building, Operational, and Optimized – across identity exposure visibility, monitoring, governance, automation, and remediation. The findings reflect that the more mature an identity program gets, the more it relies on continuous identity exposure monitoring and automated remediation – and that combination is what actually drives incident rates down.</p> <p class="wp-block-paragraph">At enterprise scale, some share of an organization’s employees, vendors, and machine accounts will be exposed in the near future regardless of how strong its controls are. What changes business outcomes is how long that exposure stays usable.</p> <p class="wp-block-paragraph">“Most identity programs are still measured on whether an exposure happened. That’s the wrong scoreboard,” said <strong>Damon Fleury, Chief Product Officer at SpyCloud</strong>. “Organizations that pair continuous identity monitoring with automated remediation of workforce exposures create the greatest friction for criminals and gain the biggest edge in preventing follow-on attacks.”</p> <p class="wp-block-paragraph">Users can access the full, no form-fill <a href="http://spycloud.com/resource/report/identity-threat-report-2026/">2026 SpyCloud Identity Threat Report</a> and benchmark their organization against the Identity Threat Protection Maturity Model by taking the free assessment <a href="https://spycloud.com/identity-threat-protection-maturity-assessment/">here</a>.</p> <p class="wp-block-paragraph"><strong>About SpyCloud</strong></p> <p class="wp-block-paragraph">SpyCloud transforms recaptured darknet data to disrupt cybercrime. Its automated identity threat protection solutions use advanced analytics and AI to accelerate investigations and protect workforce, consumer, and supplier identities from the threats that matter most: authentication bypass, session hijacking, malicious insiders, account takeover, ransomware, and fraud. Its data from malware-infected devices, successful phishes, combolists, and third-party breaches also powers many popular dark web monitoring and identity theft protection offerings. Customers include 7 of the Fortune 10, along with hundreds of global enterprises, mid-sized companies, and government agencies worldwide. Headquartered in Austin, TX, SpyCloud is home to more than 250 cybersecurity experts whose mission is to protect businesses and consumers from the stolen identity data criminals are using to target them now.</p> <p class="wp-block-paragraph">To learn more and see insights on your company’s exposed data, visit<a href="http://spycloud.com"> spycloud.com</a>.</p> <h5 class="wp-block-heading"><strong>Contact</strong></h5> <p class="wp-block-paragraph"><strong>Account Director</strong></p> <p class="wp-block-paragraph"><strong>Emily Brown</strong></p> <p class="wp-block-paragraph"><strong>REQ on behalf of SpyCloud</strong></p> <p class="wp-block-paragraph"><strong>spycloud@req.co</strong></p> </div></div></div></div>

2026/9/9
阅读更多

ChatGPT flaw lets attackers pull Gmail data across accounts via a hidden channel

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">A flaw in OpenAI’s ChatGPT allowed attackers to extract data from a victim’s connected Gmail account by passing hidden instructions between separate user sessions, according to research from Check Point.</p> <p class="wp-block-paragraph">In a proof-of-concept, Check Point demonstrated that a victim’s ChatGPT session could retrieve email data and relay it to an attacker-controlled session within a single, seemingly normal interaction.</p> <p class="wp-block-paragraph">“Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session,” Check Point researcher Alexey Bukhteyev <a href="https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/" target="_blank" rel="noreferrer noopener">wrote</a> in the report. “In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker.”  </p> <p class="wp-block-paragraph">OpenAI has since fixed the issue, according to the report, confirming that the internal service involved has been decommissioned.</p> <p class="wp-block-paragraph">Check Point described this as a “coerced insider” scenario, where the AI system itself is not compromised but can be manipulated into performing unintended actions within the organization’s trust boundary.</p> <p class="wp-block-paragraph">The attack’s reach extended to anything the victim’s session was already authorized to access, including Google Drive, Microsoft Teams and GitHub connectors, not just Gmail, the report added.</p> <h2 class="wp-block-heading" id="a-covert-cross-account-channel">A covert cross-account channel</h2> <p class="wp-block-paragraph">The vulnerability stemmed from ChatGPT’s code execution environment, where tasks run inside isolated containers tied to individual user accounts.</p> <p class="wp-block-paragraph">To support software installation inside those containers, OpenAI routes package requests through an internal service based on JFrog Artifactory, according to the report.</p> <p class="wp-block-paragraph">While containers are not supposed to communicate with each other, Check Point found that each container could write and read metadata in that shared service.</p> <p class="wp-block-paragraph">“The package delivery metadata effectively became a shared clipboard between containers that were supposed to be walled off from one another,” the report said.</p> <p class="wp-block-paragraph">By writing instructions into that shared metadata, an attacker’s session could pass tasks to a victim’s session. “A crafted instruction could make a victim’s ChatGPT session quietly process a second stream of tasks alongside the conversation the victim could actually see,” Check Point said in the report.</p> <h2 class="wp-block-heading" id="gmail-data-accessed-without-user-awareness">Gmail data accessed without user awareness</h2> <p class="wp-block-paragraph">In its demonstration, Check Point showed that the hidden task could instruct ChatGPT to retrieve data from a victim’s connected Gmail account and return it to the attacker.</p> <p class="wp-block-paragraph">“The visible answer looked completely ordinary,” the report said, even as the hidden task executed in parallel.</p> <p class="wp-block-paragraph">The scope of the attack depended on what the victim’s session was authorized to access, including email, files, and other connected applications such as cloud storage or collaboration tools, according to Check Point.</p> <p class="wp-block-paragraph">User awareness was minimal. The only indication observed was a small label ‘Talked to Gmail’ showing that an external service had been accessed, logged after the action had already taken place, the report said.</p> <h2 class="wp-block-heading" id="issue-tied-to-the-same-infrastructure">Issue tied to the same infrastructure</h2> <p class="wp-block-paragraph">Check Point Research said its proof of concept was already working before a separate chain of activity on the same Artifactory instance led into the Hugging Face compromise that OpenAI has since disclosed publicly. The two incidents used different techniques but trace back to the same shared internal service.</p> <p class="wp-block-paragraph">Shilpi Handa, associate research director at IDC, said a repeat isolation failure on the same infrastructure changes how enterprises should weigh vendor risk.</p> <p class="wp-block-paragraph">“Can one tenant’s container read or write data another tenant’s container can also access?” is a question CIOs should be putting directly to AI vendors, Handa said, since the answer isn’t something customers can verify independently.</p> <p class="wp-block-paragraph">Handa said enterprises should also ask vendors how many isolation-boundary findings they have logged over the past 12 months and what changed structurally after each one.</p> <p class="wp-block-paragraph">OpenAI did not immediately respond to a request for comment.</p> <h2 class="wp-block-heading" id="controls-that-enterprises-can-apply-now">Controls that enterprises can apply now</h2> <p class="wp-block-paragraph">Handa said enterprises don’t need to wait on vendor answers to reduce exposure. She recommended authorizing connected apps narrowly rather than by default, granting a calendar connector without also enabling Gmail and Drive access.</p> <p class="wp-block-paragraph">A limited grant “narrows what any container-level leak can expose,” Handa said.</p> <p class="wp-block-paragraph">She also recommended routing connected-app traffic through DLP or CASB inspection to catch regulated data before it leaves the pipeline, and requiring an API or webhook that logs every connected-app read and write, with timestamp and data category, exported to the enterprise’s own SIEM.</p> <p class="wp-block-paragraph">Without that logging, Handa said, “you can’t detect this class of leak even post-patch.” She said admin consoles at some vendors let customers override default risk-tiering on reads involving Gmail or Drive, forcing explicit approval rather than automatic access. That override is worth applying specifically to confidential or regulated data sources such as legal, HR, or finance systems, she said.</p> </div></div></div></div>

2026/9/9
阅读更多

ShinyHunters claims Florida DMV breach, puts data on the clock

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">ShinyHunters is claiming to have broken into a Florida government database containing sensitive information on the state’s drivers.</p> <p class="wp-block-paragraph">The notorious extortion group <a href="https://www.ransomware.live/id/U3RhdGUgb2YgRmxvcmlkYSBETVZAc2hpbnlodW50ZXJz" target="_blank" rel="noreferrer noopener">said</a> it has breached the Florida Department of Highway Safety and Motor Vehicles’ Driver and Vehicle Information Database (DAVID) and claims to have stolen more than 200,000 records.</p> <p class="wp-block-paragraph">As evidence, the attackers published a screenshot of a record belonging to Jeffrey Epstein that showed sensitive information, including an address, Social Security number, date of birth, driver’s license number, and registered vehicles.</p> <p class="wp-block-paragraph">The alleged breach comes just days after an <a href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/" target="_blank" rel="noreferrer noopener">investigation</a> uncovered a separate underground service offering more than 153 million digital scans of US and Canadian drivers’ licenses. That database, dubbed Nexus, was apparently populated with identity documents collected through an identity-verification provider, prompting an FBI investigation into the source of the scans.</p> <h2 class="wp-block-heading"><a></a>ShinyHunters puts a deadline on the DMV</h2> <p class="wp-block-paragraph">According to the group’s leak-site <a href="https://x.com/CyberIL/status/2097371659023814890" target="_blank" rel="noreferrer noopener">posting</a>, the Florida DMV was given a deadline of September 11 to negotiate before the stolen information is released.</p> <p class="wp-block-paragraph">The group has reportedly claimed that it obtained access to DAVID through a password-reset weakness and subsequently compromised multiple accounts, including accounts it claimed belonged to DMV employees. It then allegedly queried driver records by ID and downloaded pages and images.</p> <p class="wp-block-paragraph">DAVID provides authorized users with access to extensive driver and vehicle information, meaning a successful intrusion can yield considerably more than a database full of names and license numbers.</p> <p class="wp-block-paragraph">“A complete scan gives criminals much more than an identification number – it can reveal a person’s photograph, signature, address, date of birth and other information contained in a legitimate government credential,” said <a href="https://www.linkedin.com/in/dannyjenkinscyber/" target="_blank" rel="noreferrer noopener">Danny Jenkins</a>, CEO of ThreatLocker, about the potential identity theft. “Criminals could potentially use this data to open fraudulent accounts, conduct targeted phishing and password-reset attacks, commit insurance, medical, tax or government-benefit fraud, or create convincing synthetic identities.”</p> <h2 class="wp-block-heading"><a></a>Two different sources of license data</h2> <p class="wp-block-paragraph">The Florida incident and the Nexus case involve different sources of driver’s license data. ShinyHunters claims to have accessed a restricted Florida government database used by law enforcement and other authorized users to look up driver and vehicle records.</p> <p class="wp-block-paragraph">The Nexus database, by comparison, contained scans of government-issued IDs collected by <a href="http://idscan.net" target="_blank" rel="noreferrer noopener">IDScan</a>’s identity-verification technology. The breach exposed millions of scanned IDs and led to an FBI investigation and multiple <a href="https://www.infosecurity-magazine.com/news/multiple-class-action-lawsuits/" target="_blank" rel="noreferrer noopener">lawsuits</a>. IDScan.net has formally confirmed its breach, while the Florida DMV has not publicly confirmed the ShinyHunters claim yet.</p> <p class="wp-block-paragraph">However, the incident fits <a href="https://www.csoonline.com/article/4042191/shinyhunters-strike-again-workday-breach-tied-to-salesforce-targeted-social-engineering-wave.html">ShinyHunters’</a> usual pay-or-leak playbook. In the past, the group has compromised organizations, demonstrated access with samples, and then used a publication deadline to put pressure on the victims. One such operation involved the 2024 <a href="https://www.csoonline.com/article/2140487/snowflake-no-breach-just-compromised-credentials-say-researchers.html">Snowflake</a> customer-data campaign, which hit organizations including Ticketmaster, AT&amp;T, and Santander Bank.</p> <p class="wp-block-paragraph">With no public confirmation yet beyond ShinyHunters’ dark web claim and its account of how it allegedly carried out the breach, it remains to be seen how the group’s September 11 deadline will play out.</p> <p class="wp-block-paragraph">However, if the claims prove to be true, the exposed information could pose significant identity-theft risks. Jenkins spelled out the most troubling part. Much of the information contained on a driver’s license cannot simply be replaced.</p> <p class="wp-block-paragraph">“The greatest concern is the permanence of this information,” he said. “Consumers can replace a credit card or password, but they cannot easily replace their face, birth date, signature, or identity history.” </p> <p class="wp-block-paragraph">Jenkins recommended freezing credit, monitoring accounts, and using stronger authentication to reduce risks from the breach.</p> </div></div></div></div>

2026/9/9
阅读更多

When the prompt becomes the payload: A practical pen-testing guide for GenAI, LLM and RAG applications

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">Generative AI has moved well beyond the stand-alone chatbot. It now drafts code, searches internal knowledge, reviews contracts, opens support cases and, in some deployments, takes action through connected tools. That broader role changes the security question. A tester is no longer looking only for a model that will say something it should not. The real concern is whether manipulated language can reach protected data or trigger an unauthorized business action.</p> <p class="wp-block-paragraph">That makes an LLM application closer to an attack graph than a single endpoint. Prompts, retrieval services, vector databases, identities, plug-ins, model gateways and downstream APIs all influence the final result. A conventional web test still matters, but it will miss the routes that are unique to systems in which instructions and data arrive through the same channel.</p> <h2 class="wp-block-heading" id="start-with-the-application-not-the-model">Start with the application, not the model</h2> <p class="wp-block-paragraph">A useful engagement begins with an architecture walk-through. Document the system and developer prompts, model endpoints, fallback models, retrieval layer, embedding service, vector store, memory, tool definitions, API gateway, moderation controls, secrets, approval steps and logging. Mark each place where content changes trust level or where one component passes authority to another.</p> <p class="wp-block-paragraph">This map exposes the paths worth testing. A document uploaded by an ordinary user might later become trusted retrieval context for an executive. A model response might be treated as a parameter for an SQL query or a refund API. A tool result might be returned to the model without filtering. None of those transitions look dangerous when viewed in isolation; the chain is what creates the exploit.</p> <p class="wp-block-paragraph"><a href="https://genai.owasp.org/llmrisk/llm01-prompt-injection/">OWASP’s current guidance on prompt injection</a> distinguishes direct manipulation by a user from indirect instructions hidden in external content. It also notes that retrieval-augmented generation (RAG) and fine-tuning do not remove the underlying risk. In practice, that means the test surface includes email, tickets, web pages, PDFs, code repositories, spreadsheets and any other content the application can read.</p> <h2 class="wp-block-heading" id="set-rules-that-prevent-the-test-from-becoming-the-incident">Set rules that prevent the test from becoming the incident</h2> <p class="wp-block-paragraph">Agentic systems can produce side effects during testing. They may send a message, edit a record, call an external service, expose regulated data or consume a surprising amount of paid inference. The rules of engagement should therefore name the approved tenants, test identities, models, rate limits, cost ceiling, permitted tools and emergency stop condition. Destructive functions belong in a simulator or a disposable environment.</p> <p class="wp-block-paragraph">Use canaries instead of real secrets. Create synthetic customer records, decoy API keys and tenant-specific phrases that are easy to recognize in logs. Define success before the campaign starts: retrieving a canary from another tenant, invoking a tool without approval, changing a protected transaction value, persisting an instruction in memory or causing a measurable resource-exhaustion condition. A refusal to one obvious jailbreak is not a meaningful pass criterion.</p> <div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6aa1b46de1793"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img loading="lazy" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://imgproxy.citrusreader.com/FaqD8w38O5qNGOszae6eZhw8MUULbm2dTmG1c7Vgsyk/raw:1/aHR0cHM6Ly9iMmItY29udGVudGh1Yi5jb20vd3AtY29udGVudC91cGxvYWRzLzIwMjYvMDkvZ2VuYWktYW5kLWxsbS1wZW5ldHJhdGlvbi10ZXN0aW5nLXdvcmtmbG93LnBuZz93PTEwMjQ" alt="Figure 1. A repeatable workflow for testing GenAI and LLM applications." class="wp-image-4219806" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><button class="lightbox-trigger" type="button" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop"> <svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12"> <path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path> </svg> </button><figcaption class="wp-element-caption"><p><em>Figure 1. A repeatable workflow for testing GenAI and LLM applications.</em></p> </figcaption></figure><p class="imageCredit">Sunil Gentyala</p></div> <h2 class="wp-block-heading" id="treat-prompt-injection-as-a-campaign">Treat prompt injection as a campaign</h2> <p class="wp-block-paragraph">Single-turn prompts such as ‘ignore previous instructions’ are useful smoke tests, but experienced attackers do not depend on one phrase. Testers should vary the language, formatting, encoding, role-play, Unicode, attachments and conversation history. They should also divide intent across several turns, because controls that block an explicit request may fail when the objective is assembled gradually.</p> <p class="wp-block-paragraph">Model evasion testing should ask a practical question: can the attacker keep the harmful objective while changing its surface form? Try paraphrases, translations, long-context placement, quoted material, nested instructions and content that claims to come from a trusted workflow. Repeat the same objective after a session summary, context compression, model fallback or tool error. Those state changes often alter which instruction receives priority.</p> <p class="wp-block-paragraph">The strongest finding connects the injection to an observable effect. Can a poisoned document make the assistant retrieve a second restricted document? Can a support bot pass an altered refund amount to a tool? Can model-generated SQL, shell text, HTML or an API parameter reach an interpreter without deterministic validation? The report should show the complete chain, including the identity used, retrieved records, tool arguments and resulting state change.</p> <p class="wp-block-paragraph"><a href="https://csrc.nist.gov/pubs/ai/100/2/e2025/final">NIST’s 2025 adversarial machine-learning taxonomy</a> provides a sound frame for this work because it organizes attacks by model type, life-cycle stage, attacker objective, capability and knowledge. That wider lens keeps the assessment from collapsing every GenAI problem into the label ‘jailbreak.’</p> <h2 class="wp-block-heading" id="test-rag-and-vector-databases-as-security-controls">Test RAG and vector databases as security controls</h2> <p class="wp-block-paragraph">A RAG system introduces another decision layer: which content the model sees. Even a well-behaved model can produce a compromised answer when the retrieval pipeline supplies poisoned or unauthorized context. The assessment should cover ingestion, parsing, chunking, embedding, indexing, metadata, query construction and authorization filters.</p> <p class="wp-block-paragraph">Begin with controlled poisoning. Insert a synthetic document that contains a hidden instruction and observe whether the pipeline indexes, retrieves and follows it. Move the instruction through visible text, metadata, comments, white-on-white text, OCR layers, spreadsheet cells and source-code comments. Measure how consistently the poisoned object appears for targeted queries and whether it remains retrievable after the source is changed or deleted.</p> <p class="wp-block-paragraph">Isolation testing is just as important. Create two tenants or security groups with distinct canary facts, then issue semantically similar queries from both sides. Inspect the retrieved document IDs, not just the final prose. Authorization should limit the retrieval set before sensitive content enters the model context. Test empty metadata, malformed filters, case differences, wildcard values, stale access-control caches and permission changes made after indexing.</p> <p class="wp-block-paragraph"><a href="https://genai.owasp.org/llmrisk/llm082025-vector-and-embedding-weaknesses/">OWASP’s vector and embedding guidance</a> calls out unauthorized access, cross-context leakage, embedding inversion and data poisoning. It recommends permission-aware stores, logical partitioning, source validation and detailed immutable retrieval logs. Those recommendations translate neatly into pen-test assertions: prove that the filter cannot be bypassed, that untrusted content is traceable and that every sensitive retrieval can be reconstructed.</p> <h2 class="wp-block-heading" id="follow-the-ml-pipeline-upstream">Follow the ML pipeline upstream</h2> <p class="wp-block-paragraph">Some compromises happen before inference. Review training and fine-tuning data, notebooks, embedding code, model registries, object storage, CI/CD workflows, adapters, package dependencies and deployment manifests. Test whether an unauthorized user can replace a dataset, edit an evaluation set, publish a new model version or change which prompt and policy bundle is deployed.</p> <p class="wp-block-paragraph">For predictive ML components, bounded adversarial examples can expose evasion near decision thresholds. For generative systems, use controlled poisoning in a non-production corpus and measure whether a targeted behavior survives retraining, re-indexing or rollback. Artifact hashes, signatures and separation of duties should be tested, not accepted from a diagram. A reliable rollback also has to restore the prompts, retrieval index, tool policy and model version as one coherent release.</p> <p class="wp-block-paragraph">Secrets deserve their own test track. Search notebooks, prompt templates, environment variables, traces and model logs for credentials or sensitive context. Use decoys when attempting extraction. The evidence should demonstrate the route without copying a real production secret into the report.</p> <h2 class="wp-block-heading" id="use-python-to-make-the-attack-repeatable">Use Python to make the attack repeatable</h2> <p class="wp-block-paragraph">Manual probing is valuable for discovery, but it is a poor regression method. A small Python harness can define an objective, generate approved mutations, send them through the same interface used by clients, capture retrieval and tool traces, score the result and preserve evidence. The code should run only against authorized targets and should stop on unexpected side effects.</p> <pre class="wp-block-code"><code>for case in approved_cases: for prompt in mutate(case.seed): result = sandbox.send( prompt, identity=case.test_identity, trace=True, max_cost=case.cost_limit, ) finding = score_outcome(result, case.objective, case.canaries) evidence.write(case.id, prompt, result, finding) if finding.critical or result.unexpected_side_effect: emergency_stop() </code></pre> <p class="wp-block-paragraph"><a href="https://github.com/sunilgentyala/genai-llm-pentest-harness">A public reference implementation of this loop</a> runs these same four functions against a local, deliberately vulnerable RAG and tool-calling target, so every finding it reports is reproducible by running a test suite rather than asserted.</p> <p class="wp-block-paragraph">The framework around the loop matters more than the loop itself. Keep seeds and mutations under version control. Record the model and prompt versions, retrieved source IDs, identity, tool calls, latency, token use and policy state. Score concrete outcomes — a forbidden record retrieved, a file written, a tool called or an approval bypassed — rather than relying only on another model to judge whether a response sounds unsafe.</p> <p class="wp-block-paragraph"><a href="https://microsoft.github.io/PyRIT/latest/code/framework/">Microsoft’s current PyRIT documentation</a> uses a comparable modular design built around datasets, scenarios, attack techniques, executors, converters, targets and scorers. It is useful for scaling red-team campaigns, but it cannot decide the organization’s threat model or the business severity of a finding. That judgment still belongs to the tester and system owner.</p> <h2 class="wp-block-heading" id="report-exploitability-not-theater">Report exploitability, not theater</h2> <p class="wp-block-paragraph">A strong report separates model misbehavior from system compromise. Severity should account for access required, repeatability, persistence, affected users, data sensitivity, tool privileges and the presence of a meaningful human approval step. A dramatic prohibited answer may be less serious than a plain-looking response that quietly retrieves another tenant’s contract.</p> <p class="wp-block-paragraph">Because model behavior is probabilistic, repeat each material chain. Report the attack success rate, turns required, estimated cost, time to impact and whether the result survives a new session or model revision. For RAG, track unauthorized retrieval and poisoned-document influence. For agents, track unauthorized tool calls and approval-gate failures. For the ML pipeline, record whether integrity controls detected a modified artifact and prevented promotion.</p> <p class="wp-block-paragraph">Every high-risk finding should become a regression test. Prompt wording alone is rarely a durable fix. Effective remediation usually combines least-privilege tools, permission-aware retrieval, source provenance, output validation, sandboxing, deterministic policy checks, approval for irreversible actions, rate limits, monitoring and tested rollback.</p> <h2 class="wp-block-heading" id="test-the-chain-whenever-the-chain-changes">Test the chain whenever the chain changes</h2> <p class="wp-block-paragraph">GenAI penetration testing should begin before launch and return whenever the model, system prompt, tools, retrieval corpus, identity rules or permissions change. The final deliverable is not a collection of clever prompts. It is a set of reproducible paths showing where manipulated content crossed a trust boundary and what business consequence followed.</p> <p class="wp-block-paragraph">The practical objective is not to make a language model impossible to confuse. That is not a realistic security boundary. The objective is to design and verify the surrounding application so that a confused model cannot retrieve what it should not see, execute what it should not control or quietly change the state of the business.</p> </div></div></div></div>

2026/9/9
阅读更多

Post-quantum cryptography adoption and the national security implications

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph"></p> <p class="wp-block-paragraph">Quantum computers have advanced significantly in capability and compute power in the last several years and are turning theoretical vulnerabilities in modern cryptography into real-world threats.  The shift to post-quantum cryptography (PQC) needs to start now, but several challenges need to be overcome.  One is: How do you convince people of the urgency that this not-quite-ready new technology represents?  I will argue that this technology will favor the nation-state actors over cyber criminals and ransomware gangs and therefore make it harder to convince those that aren’t already a target of nation-states of the threat.  This dynamic will create gaps that governments can exploit either covertly, as part of an open conflict or through state-sponsored economic espionage.</p> <h2 class="wp-block-heading" id="the-current-state-of-quantum-compute">The current state of quantum compute</h2> <p class="wp-block-paragraph">Because quantum computers have computers in the name, many people think these systems will replace their existing traditional computers.  The better way of thinking about them is as specialized devices that augment existing computers like graphics cards do today.  Quantum computers are being designed to run specific algorithms that are specialized in solving specific problems, such as breaking cryptographic systems.</p> <p class="wp-block-paragraph">Quantum systems, like <a href="https://quantumai.google/quantumcomputer">Google’s Quantum AI</a>, are also physically big, with supporting infrastructure usually taking up an entire room.  The significant capital and know-how required to build these systems will likely make them off-limits to all but a handful of corporations and governments for the foreseeable future.  Unless there is a major breakthrough in quantum computers with size and cost, there will likely remain a significant barrier to entry and <a href="https://en.wikipedia.org/wiki/Cloud-based_quantum_computing">gatekeepers to public access</a> akin to the early days of computers with mainframes and terminals.  We saw this play out briefly when Anthropic released Mythos and the <a href="https://www.anthropic.com/news/fable-mythos-access">US Government immediately put restrictions</a> on it due to national security concerns.  This is in contrast to the democratizing nature that AI has had with cyberattacks, regardless of the model.</p> <p class="wp-block-paragraph">There is still a significant debate as to when quantum computers will be able to break modern asymmetric cryptographic systems like RSA or Elliptic Curve Cryptography (ECC).  <a href="https://www.rsa.com/resources/blog/zero-trust/setting-the-record-straight-on-quantum-computing-and-rsa-encryption/">RSA, for example, claims</a> we are still a ways off before this is a realistic threat, if ever.  Google, on the other hand, says it may be as soon as 2029.  Both of these companies have skin in the game, but even independent cryptographic experts like Filippo Valsorda are sounding the alarm.  Valsorda argues convincingly, “The bet is not ‘are you 100% sure a CRQC [cryptographically relevant quantum computer] will exist in 2030?’, the bet is ‘are you 100% sure a CRQC will NOT exist in 2030?’ I simply don’t see how a non-expert can look at what the experts are saying, and decide ‘I know better, there is in fact &lt; 1% chance.’</p> <h2 class="wp-block-heading" id="assigning-a-risk-value">Assigning a risk value</h2> <p class="wp-block-paragraph">How do you assign risk to a future threat like quantum?  Impact and likelihood are the two classical inputs to risk.  The impact that quantum computers pose to existing asymmetric encryption is very high and can potentially result in uncovering significant amounts of encrypted data in motion or at rest.  The impact is obvious for organizations such as banks, governments, military and anyone that deals with confidential information.  This threat also opens up the door to attackers <a href="https://www.paloaltonetworks.com/cyberpedia/harvest-now-decrypt-later-hndl">harvesting now and decrypting later</a> when the quantum matures.  This means hackers with existing access to a network or encrypted communications link can collect encrypted information with the intent of decrypting it later.  This may be trivial if the information is time-sensitive and long since expired, but the damage could be severe in cases such as encrypted intellectual property.</p> <p class="wp-block-paragraph">So, the impact is pretty evident, but it’s the likelihood where things get complicated.  First, there is the likelihood that this won’t happen at all, as well as that it won’t happen on a time scale that matters for current investment strategies.  The remaining likelihood points to an increasingly near-term threat.  How do the players that will have access to the technology play into this?  As mentioned, quantum will likely remain confined to governments and large companies, with the remaining public likely vetted and monitored. </p> <p class="wp-block-paragraph">So, if your organization isn’t currently targeted by a nation-state actor or groups that have access to future quantum computers, is there an impact to them?  If most of the time the only compromise is to confidentiality, but relatively little monetary impact, is the risk acceptable to most organizations?  With the exception of North Korea, few nation-states cause financial damage as a result of their activities (beyond possible regulatory/compliance fines).  Much of their activities are driven by national security concerns like intelligence collection and posturing for future cyber support to a real-world conflict, not financial.</p> <p class="wp-block-paragraph">Organizations that are already targets of nation-state actors, such as governments, tech companies, large financial companies and nuclear facilities, will be the first to adopt PQC technology, while thinner-margin companies will likely push it to the back burner due to lack of perceived risk and limited resources. </p> <h2 class="wp-block-heading" id="national-security-risk">National security risk</h2> <p class="wp-block-paragraph">These conditions will likely leave large numbers of organizations vital to national security unable or unwilling to upgrade and therefore open themselves up to exploitation by nation-state actors.  The gap between individual organizations’ desire to pay and the cost of collective defense needs to be covered somehow.  This will also amplify the already existing cybersecurity issues with critical infrastructure, creating even more vulnerable networks.</p> <p class="wp-block-paragraph">Sectors like municipal utilities, small hospitals, critical manufacturing and local government emergency services will likely struggle to upgrade systems to PQC.  This vulnerability will further enable nation-state actors to leverage existing access to critical infrastructure, as seen in <a href="https://media.defense.gov/2025/Aug/22/2003786665/-1/-1/0/CSA_COUNTERING_CHINA_STATE_ACTORS_COMPROMISE_OF_NETWORKS.PDF">attacks like Salt Typhoon</a>, to gain access to new networks and data.</p> <p class="wp-block-paragraph">This could enable collecting sensitive information such as classified materials or corporate intellectual property.  It can also enable access to networks to position for effects during a time of conflict.  Things like disrupting communications, destroying data or gaining access to control systems for physical equipment.</p> <p class="wp-block-paragraph">Nation-state actors could also enable state-aligned hacking groups to conduct operations that they themselves don’t want attribution towards.  All of this happens now, but access to quantum computers will blow the doors off previously inaccessible systems and sensitive data.</p> <h2 class="wp-block-heading" id="possible-solutions">Possible solutions</h2> <p class="wp-block-paragraph">Solutions are already widely available, with NIST publishing PQS standards (FIPS 203-205) and multiple commercial companies offering PQC solutions.  But adoption will be slow due to the large amounts of critical software and hardware that will have to be upgraded.  Five things can help with the transition.  The new solutions will also need to be agile in case vulnerabilities in the new systems arise, known as <a href="https://csrc.nist.gov/projects/crypto-agility">crypto agility</a>.</p> <p class="wp-block-paragraph">First, government mandates can require adoption.  The <a href="https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/">recent Executive Order EO 14412</a> establishes a more rapid adoption of PQC systems within the Federal government.  Governments should further look to incentivize critical infrastructure companies to adopt PQC systems by either further mandates or potentially tax incentives.  Further regulations and compliance standards can force PQC adoption; for example, PCI DSS or ISO 27001 could explicitly require PQC.</p> <p class="wp-block-paragraph">A second method for wider adoption is having cloud service providers, network stacks (TLS) and software libraries switch to PQC algorithms by default.  In many cases, this will transparently migrate many users to the new standards.  Organizations can potentially use the quantum threat to push for greater cloud integration where PQC systems are already offered (i.e. <a href="https://cloud.google.com/blog/products/identity-security/announcing-quantum-safe-key-encapsulation-mechanisms-in-cloud-kms">Google</a>, <a href="https://aws.amazon.com/security/post-quantum-cryptography/">AWS</a>).</p> <p class="wp-block-paragraph">If costs and complexity are too great, a third option would be to prioritize the most critical network elements and storage systems.  Then upgrade these systems to either newer PQC systems or if even that is too difficult, update the existing keys to larger keys, for example, RSA 2048 to RSA 4096 or AES-128 to AES-256 to buy some more time.</p> <p class="wp-block-paragraph">Fourth, awareness of the need for PQC among cybersecurity professionals narrowly and business executives broadly.  Corporate boards and senior executives will be the ones making the call on whether to upgrade vulnerable systems and need to understand the risks of this technology.</p> <p class="wp-block-paragraph">Lastly, in line with the fourth, universities and colleges should expand class offerings to include quantum computing as well as specific cybersecurity solutions in order to build a workforce capable of both harvesting the power of quantum as well as guarding against the ramifications of this new technology.</p> </div></div></div></div>

2026/9/9
阅读更多

50% of CISOs see Mythos as a sign to exit the profession

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">CISOs already have it tough, but the straw that breaks the back of many IT security executives may be the rapidly advancing capabilities of frontier AI models, enterprise insistence on rapid and widespread AI experimentation, and the compounding risk responsibilities and personal liabilities surrounding all that.</p> <p class="wp-block-paragraph">“There are days where it feels exhausting,” says one CISO at a large enterprise in the software industry, who did not want to be quoted by name. “There are days when it feels like this is a lot.”</p> <p class="wp-block-paragraph">This executive is not alone.</p> <p class="wp-block-paragraph">In a <a href="https://www.absolute.com/resources/research-reports/the-state-of-enterprise-cyber-resilience-research-series">recent survey of 1,001 CISOs in the US and UK</a>, 50% agreed that the introduction of <a href="https://www.csoonline.com/article/4198019/claude-mythos-faq-capabilities-access-competitors-implications.html">Anthropic Mythos</a> and similar <a href="https://www.csoonline.com/article/4180920/beware-the-son-of-mythos-security-experts-warn.html">cyber-capable models</a> and tools has caused them to consider leaving the profession. Only 25% disagreed with that statement.</p> <p class="wp-block-paragraph">And 60% said pressure from the board and executive leadership to adopt AI was outpacing their organization’s ability to govern and secure its use.</p> <p class="wp-block-paragraph">Christine Gadsby, chief security advisor at BlackBerry, who spent years in cyber leadership positions and was the company’s CISO until switching to her new role last September, doesn’t miss being the CISO.</p> <p class="wp-block-paragraph">“It’s madness! Madness!” she says. “I wouldn’t say that I would never do a CISO role again, but it’s a tough time right now to be a CISO.”</p> <p class="wp-block-paragraph">CISOs have historically had shorter tenures than other executive positions, she notes. “Before, it was burnout. They had so much responsibility and so many things to do. And now, with AI, some of these challenges are just mindboggling,” she says.</p> <p class="wp-block-paragraph">The <a href="https://www.csoonline.com/article/3631759/personal-liability-sours-70-of-cisos-on-their-role.html">personal responsibility aspect of the job</a> is also tough, she adds. “One thousand percent. As an industry, we built the CISO role to take all of that liability and now we act surprised when people want out.”</p> <p class="wp-block-paragraph">According to a survey released earlier this year, <a href="https://www.splunk.com/en_us/blog/ciso-circle/ciso-ai-strategy-digital-resilience.html">78% of CISOs are concerned</a> about their own liability for security incidents — up from 56% a year ago. And 89% of CISOs say the breakneck pace of technology advancement is a challenge.</p> <p class="wp-block-paragraph">“As fast as AI evolves, the benefit is with the attacker right now,” says Gadsby. “Attackers are weaponizing vulnerabilities as fast as they can find them, sometimes even sooner than the fix is published.”</p> <h2 class="wp-block-heading" id="a-compounding-problem">A compounding problem</h2> <p class="wp-block-paragraph">As a result of these and other factors, experienced CISOs are retiring, moving to less stressful security-related positions, switching to consulting or sales support jobs, or <a href="https://www.csoonline.com/article/4127704/69-of-cisos-open-to-career-move-including-leaving-role-entirely.html">leaving the profession entirely</a>. That leaves companies having to hire less-experienced people, who are even more vulnerable to burnout.</p> <p class="wp-block-paragraph">“If you feel not ready for the role, or don’t feel empowered — especially right now — that’s when you’re like, ‘I’m out. I’m going to go do something else,’“ Gadsby says.</p> <p class="wp-block-paragraph">Plus, because every enterprise IT environment is different, it takes time for a new CISO to get up to speed, creating more security risks given today’s pace of change and attack — and thus putting even more stress on the CISO.</p> <p class="wp-block-paragraph">“You have to be a special person to want to do that job,” Gadsby says, likening the role to being a firefighter.</p> <p class="wp-block-paragraph">“Every once in a while, I’ll read something in the news and think, ‘Oh my gosh, all my friends are not sleeping tonight.’ I’m glad I’m not up at 2 a.m. trying to solve this. But sometimes I do miss being helpful, being a firefighter,” she says. “The heart of the role is wanting to protect people.”</p> <h2 class="wp-block-heading" id="addressing-liability-concerns">Addressing liability concerns</h2> <p class="wp-block-paragraph">So is there a path forward for the profession?</p> <p class="wp-block-paragraph">“There’s not an easy way out for the CISO,” says IDC analyst Chris Kissel. The average CISO tenure is now 18 months, he notes, and issues like personal liability for cybersecurity incidents and the new AI models aren’t helping. “The new world for CISOs is very scary.”</p> <p class="wp-block-paragraph">It will take acts of leadership to improve the situation, he says, such as a governing body that mandates minimal requirements for responsible behavior.</p> <p class="wp-block-paragraph">“And if you take these steps, that takes the CISO out of the legal indemnity,” he says. “There has to be a way to put the CISO in the clear.”</p> <p class="wp-block-paragraph">Oliver Legg, co-founder and cybersecurity recruiter at Aspiron Search, an executive search company focusing on cybersecurity, says he’s seeing the liability concerns when talking to prospective CISOs.</p> <p class="wp-block-paragraph">“Two years ago, we had CISO candidates ask about budget and headcount,” he says. “Now, the first questions are about indemnification and D&amp;O coverage.”</p> <p class="wp-block-paragraph">D&amp;O — or <a href="https://www.csoonline.com/article/2512968/if-youre-a-ciso-without-do-insurance-you-may-need-to-fight-for-it.html">directors and officers</a> — is liability insurance that protects business leaders from personal financial loss.</p> <h2 class="wp-block-heading" id="countering-ai-anxiety">Countering AI anxiety</h2> <p class="wp-block-paragraph">And dealing with the growing AI threats?</p> <p class="wp-block-paragraph">That can be managed as well. AI itself can be <a href="https://www.csoonline.com/article/4212560/7-ways-ai-can-be-used-to-enhance-security-operations.html">used to improve security operations</a>, as long as it’s handled responsibly.</p> <p class="wp-block-paragraph">“Mythos doesn’t really change what we need to do,” says Omar Khawaja, who teaches at Carnegie Mellon University’s CISO and CAIO programs and serves as the global field CISO at Databricks. “It changes how well, and how fast, and how much of it we need to do. And we need to change the approach and frameworks that we use so we can achieve a scale that’s 2X, 3X, 10X bigger than in the past.”</p> <p class="wp-block-paragraph">That means that security programs will have to become much more agentically driven, he says, with the proper precautions in place.</p> <p class="wp-block-paragraph">And fears of a <a href="https://www.csoonline.com/article/4213883/who-is-accountable-when-your-ai-agent-goes-rogue.html">company’s own AI going rogue</a> are a bit overblown, he adds.</p> <p class="wp-block-paragraph">“Almost every single one of those cases is where they’ve been experimenting with models that have not been released and the companies say that they’re not going to be released,” he says. “So if you move to an agentic environment in production, don’t use experimental AI. If you use one of the well-known AIs, it’s very doable to manage those securely.”</p> <p class="wp-block-paragraph">And organizations that are new to AI and don’t have all the experience and the guardrails yet should start with less risky use cases, learn to mitigate those risks, and then build from that.</p> <p class="wp-block-paragraph">“In the security space, I would use the AI for anomalies and to triage existing investigations,” he says. “I probably wouldn’t start out with using AI to automate my response. But if I work my way up, I can get there.”</p> <h2 class="wp-block-heading" id="a-new-opportunity">A new opportunity</h2> <p class="wp-block-paragraph">The Mythos effect is overstated, confirms Mike Privette, former CISO and founder and cybersecurity economist at Return on Security. These frontier models have just turned a public spotlight on problems that were already there.</p> <p class="wp-block-paragraph">“On the flip side, while frontier models are changing the speed and complexity of the threat landscape, many CISOs are more excited than ever to be in the seat,” he says. “For many people, this is one of the most exciting times to be operating in the field.”</p> <p class="wp-block-paragraph">That’s especially the case when the CISO is working at a company that’s embracing AI, and where they’re given executive support, the right budget, and the leeway to experiment, he says.</p> <p class="wp-block-paragraph">“I’ve had the opportunity to be in other roles in the middle of my CISO tenure,” says the executive at the large software company who did not want to be quoted by name. “And those other roles are so much easier. You can be at 90% and still get a pat on the back. But when you’re a CISO, and you’re at 99%, and there’s one server that allowed the bad guys to break in, nobody cares that you patched the other 99. Less than perfect is never good enough.”</p> <p class="wp-block-paragraph">Still, there are days when it feels exhilarating, the executive adds. “Though it’s a very fine line between the two.”</p> <p class="wp-block-paragraph">And keeping a company and its customers secure is an awesome challenge.</p> <p class="wp-block-paragraph">“Our platform is used by thousands of enterprises,” the executive says. “I keep reminding myself and my team that that’s the focus. We’re not doing it just for us. The more I can think about what an awesome challenge this is, the more the mission and objective feel very awesome.”</p> </div></div></div></div>

2026/9/9
阅读更多

September 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in Windows

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">Possibly wormable bugs and two zero-day holes highlight the almost 1,000 fixes issued today by Microsoft in its <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Sep" target="_blank" rel="noreferrer noopener">September Patch Tuesday release</a>.</p> <p class="wp-block-paragraph">The 964 vulnerabilities, another record since Microsoft began using AI in the middle of the year to find holes, require customer action. Excluded are 174 third-party/open-source CVEs and 23 Chromium/Edge CVEs, as well as nine Microsoft mitigated vulnerabilities in applications like Azure, Entra, and Copilot Studio where no customer action is required.</p> <p class="wp-block-paragraph">Separately, developers and SAP admins whose staff use SAP’s ABAP (Advanced Business Application Programming) should take action to close a critical vulnerability, with a CVSS score of 10.0, in the Extended Passport Processing (EPP) component. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application, say researchers at Onapsis. EPP is used in enterprise suites like SAP S/4Hana and NetWeaver to log document creation or trace end-to-end transactions.</p> <h2 class="wp-block-heading" id="microsoft-vulnerabilities">Microsoft vulnerabilities</h2> <p class="wp-block-paragraph">The two zero-days revealed today are:</p> <ul class="wp-block-list"> <li><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880">CVE-2026-85880</a>, a heap-based buffer overflow in Windows ALPC (Advanced Local Procedure Call), which is already being exploited. ALPC is an internal messaging system in Windows that lets programs talk to each other. An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system. No additional user interaction is required, <a href="https://www.action1.com/patch-tuesday/patch-tuesday-september-2026/">said Action1.</a> <br>Microsoft said affected products include certain versions of Windows Server 2012, Windows Server 2016, and Windows 10 Desktop.<br><a href="https://www.ivanti.com/blog/authors/chris-goettl">Chris Goettl</a>, Ivanti’s vice-president of product management, said this vulnerability “affects the entire Windows fleet.”</li> </ul> <ul class="wp-block-list"> <li><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963">CVE-2026-81963</a>, an escalation of privilege stemming from an improper link resolution before file access (also called link following) in Windows Update Stack. An attacker who successfully exploits this vulnerability could gain System privileges. Affected versions include Windows 11 Desktop and Windows Server 2025, said Microsoft. However <a href="https://www.action1.com/patch-tuesday/patch-tuesday-september-2026/">researchers at Action1 said</a> specific affected Windows versions cannot be confirmed from the available data.<br>There is no workaround other than installing the fix. Exploitation has been detected, Action1 noted, making remediation a high priority even though the severity and CVSS score cannot be confirmed. <br>This is the first zero-day of the seven privilege escalation flaws discovered in Windows Update Stack since 2022, and the first to be exploited, added <a href="https://www.tenable.com/profile/satnam-narang">Satnam Narang</a>, senior staff research engineer at Tenable.</li> </ul> <p class="wp-block-paragraph">The sheer number of this month’s Microsoft patches stunned some experts. <a href="https://www.linkedin.com/in/dustincchilds/" target="_blank" rel="noreferrer noopener">Dustin Childs</a>, head of threat awareness at the Zero Day Initiative, said, in a reference to the film <em>2001: A Space Odyssey</em>, “looking at nearly 1,000 vulnerabilities in a single month, all I can think is: ‘My God, it’s full of stars.'” </p> <p class="wp-block-paragraph">“AI-assisted bug discovery has exploded patch counts into a whole new galaxy,” he said, “and defenders simply have to embrace the suck.”</p> <p class="wp-block-paragraph">About 20 of the vulnerabilities could be wormable bugs, he warned. “We haven’t seen a global worm in years, but with a DNS flaw acting as the spiritual successor to <a href="https://nvd.nist.gov/vuln/detail/cve-2020-1350" target="_blank" rel="noreferrer noopener">SigRed</a>, that reality could change fast.” </p> <p class="wp-block-paragraph">That new vulnerability is <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-69730" target="_blank" rel="noreferrer noopener">CVE-2026-69730</a>, a Windows DNS remote code execution hole. As of Tuesday, it hadn’t yet been exploited, Microsoft said, but the company expects it will be. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system, with no authentication or user interaction required.</p> <p class="wp-block-paragraph">Asked about vulnerabilities that could be wormed, <a href="https://www.linkedin.com/in/bicer/" target="_blank" rel="noreferrer noopener">Jack Bicer</a>, Action1’s director of vulnerability research, drew attention to <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62893" target="_blank" rel="noreferrer noopener">CVE-2026-62893</a>, a Windows Deployment Services TFTP Server Remote Code Execution issue first patched in August, and <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-69590" target="_blank" rel="noreferrer noopener">CVE-2026-69590</a>, a Windows Routing and Remote Access Service Remote Code Execution. Neither requires authentication or user interaction. Because of this, he said, these types of vulnerability could spread quickly across a network if affected systems are not patched.</p> <p class="wp-block-paragraph"><a href="https://www.fortra.com/profile/tyler-reguly" target="_blank" rel="noreferrer noopener">Tyler Reguly</a>, Fortra’s associate director of security R&amp;D, pointed out that as long as Microsoft is playing catch-up on patching vulnerabilities, numbers have lost all meaning. </p> <p class="wp-block-paragraph">“This is not a Microsoft-specific problem,” he noted. “We see the same issue with Oracle and other large vendors that are being proactive. We need to remember that these large CVE counts are a good thing, as we’re reducing attack surface before attackers get a chance to find and utilize the vulnerabilities. Eventually, all those long-standing, hard to find vulnerabilities will be fixed, and Patch Tuesday will return to its typical cadence. Until that happens, prioritization is key, and gift cards for extra coffee for your admins would likely be appreciated.”</p> <p class="wp-block-paragraph">Bicer added that the scale of this month’s Microsoft releases requires security leaders to move beyond CVSS-driven patching and prioritize systems according to exploitability, network exposure, privilege requirements, business criticality, and the consequences of compromise. The most consequential risks, he said, are concentrated in remotely reachable infrastructure, identity and authentication services, database platforms, virtualization environments, and Windows components where successful exploitation could provide code execution or elevated privileges. </p> <p class="wp-block-paragraph">“One of the most important things to recognize across the recent rise in Patch Tuesday releases is that while the number of vulnerabilities being patched is rising, the number of vulnerabilities that can and will affect most organizations remains quite low,” Bicer stressed. “AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles. It’s critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context.”</p> <h2 class="wp-block-heading" id="patches-from-other-vendors">Patches from other vendors</h2> <p class="wp-block-paragraph">Researchers at Nightwing also noted that this week Adobe patched an actively exploited zero-day in Adobe Commerce and Magento (<a href="https://experienceleague.adobe.com/en/docs/commerce-knowledge-base/kb/announcements/commerce-apsb26-146" target="_blank" rel="noreferrer noopener">CVE-2026-75650</a>, CVSS 10.0), dubbed StyleSmuggler, which drops Linux backdoors and web shells. Adobe said “Urgent Action” is required.</p> <p class="wp-block-paragraph">Fortinet confirmed ongoing active exploitation of older two authentication bypass vulnerabilities in FortiOS (<a href="https://www.tenable.com/cve/CVE-2024-55591" target="_blank" rel="noreferrer noopener">CVE-2024-55591</a> and <a href="https://nvd.nist.gov/vuln/detail/cve-2025-24472" target="_blank" rel="noreferrer noopener">CVE-2025-24472</a>), allowing unauthenticated remote attackers to seize administrative control of edge firewalls.</p> <p class="wp-block-paragraph">Cisco Systems addressed <a href="https://www.csoonline.com/article/4219968/cisco-bundles-fixes-for-multiple-vulnerabilities-some-critical-into-one-patch-2.html" target="_blank">eight serious vulnerabilities</a> across IOS XR systems while warning of active exploitation targeting an unauthenticated denial-of-service flaw in Secure Firewall ASA devices (<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF" target="_blank" rel="noreferrer noopener">CVE-2026-20349</a>) first described last month.</p> <p class="wp-block-paragraph"> Red Hat fixed a critical privilege escalation vulnerability in Advanced Cluster Management for Kubernetes 2 (<a href="https://nvd.nist.gov/vuln/detail/cve-2026-10090" target="_blank" rel="noreferrer noopener">CVE-2026-10090</a>, CVSS 9.0, described last month) that enables attackers to breach multi-tenant container boundaries; and Tenable resolved a critical flaw in Sensor Proxy protecting the core pipeline organizations rely on for security auditing (<a href="https://nvd.nist.gov/vuln/detail/cve-2026-18667" target="_blank" rel="noreferrer noopener">CVE-2026-18667</a>, CVSS 9.6) that had permitted code execution with elevated privileges.</p> <h2 class="wp-block-heading" id="sap-vulnerabilities">SAP vulnerabilities</h2> <p class="wp-block-paragraph">Jonathan Stross, Pathlock’s senior product manager for cybersecurity R&amp;I, noted that three of the Security Notes this month reach full compromise territory without a single valid credential. “That is an unusually concentrated cluster of unauthenticated, network-reachable, maximum-impact issues for a single Patch Day,” <a href="https://pathlock.com/blog/sap-security-patch-day-september-2026/" target="_blank" rel="noreferrer noopener">he said in a commentary</a>.</p> <p class="wp-block-paragraph">The critical hole plugged by SAP Security Note <a href="https://me.sap.com/notes/3747649" target="_blank" rel="noreferrer noopener">#3747649</a> is a memory corruption vulnerability in the Extended Passport Processing (EPP) component in ABAP-based systems. Researchers at Onapsis Research Labs, <a href="https://onapsis.com/blog/sap-security-patch-day-september-2026/" target="_blank" rel="noreferrer noopener">who discovered the vulnerability</a>, have dubbed it OVERPASS. </p> <p class="wp-block-paragraph">Boundary validation is missing during the deserialization of EPP data, resulting in a memory safety violation when processing externally supplied length fields. This allows an unauthenticated attacker to send crafted network requests containing a malformed EPP header, causing undefined behavior and abnormal program termination. The SAP Security Note provides a patch for ABAP and Java kernels, and for SAP Web Dispatcher, version 9.16. Other Web Dispatcher versions and Web Dispatcher included in SAP S/4HANA Extended Application Services are not affected.</p> <p class="wp-block-paragraph">Onapsis urged immediate patching, since the vulnerability exists by default in a wide range of SAP components, is exploitable remotely and without authentication, allows remote attackers to run arbitrary operating system commands on the SAP host with SAP administrative privileges that results in full compromise of the underlying SAP business data and processes, and is reachable through several SAP components and several communication protocols. None of these require credentials, Onapsis pointed out, so no single network control can fully mitigate risk.</p> <p class="wp-block-paragraph">Onapsis also drew attention to SAP Security Note <a href="https://me.sap.com/notes/3759472" target="_blank" rel="noreferrer noopener">#3759472</a>, with a CVSS score of 9.8, in NetWeaver Message Server. This bug is the result of insufficient validation of the authenticity of internal application server components during registration. Consequently, unauthenticated attackers with network access can register unauthorized components and potentially perform unauthorized actions within the application environment.</p> <p class="wp-block-paragraph">A successful exploitation could result in a high impact on the confidentiality, integrity, and availability of the affected system, SAP said. The vulnerability, which the Onapsis Research Labs is dubbing S4GET, is present across SAP’s entire modern kernel family (9.16, 9.18, 9.19, 9.20), meaning every S/4HANA 2025 system, and any earlier release already moved to one of those kernels, is affected.</p> </div></div></div></div>

2026/9/9
阅读更多

Cisco bundles fixes for multiple vulnerabilities, some critical, into one patch

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">Cisco is looking to get ahead of attackers with a new set of more than a half-dozen fixes, some of them critical, for its IOS XR Linux-based network operating system (OS).</p> <p class="wp-block-paragraph">As part of its regular testing, Cisco’s software engineering team flagged “multiple internally-discovered <a href="https://www.csoonline.com/article/4218759/security-leaders-must-prepare-for-likely-threats-not-sensationalized-agentic-attacks.html" target="_blank">vulnerabilities</a>,” the company said. These flaws could allow attackers to perform remote code execution (RCE) and gain root access on a router, thereby allowing them to intercept traffic. Other potential risks could include access control failures, buffer overflows, and out-of-bounds access.</p> <p class="wp-block-paragraph">Cisco said all IOS XR releases, including IOS XR7, are impacted, regardless of configuration. There are no known workarounds, but the company has released software updates.</p> <p class="wp-block-paragraph">Cisco emphasizes that, as of yet, the vulnerabilities are not known to be actively exploited.</p> <p class="wp-block-paragraph">IOS XR runs on some of the most critical routing infrastructure in a network, explained <a href="https://www.infotech.com/profiles/erik-avakian" target="_blank" rel="noreferrer noopener">Erik Avakian</a>, a technical counselor at Info-Tech Research Group. “The most serious vulnerabilities can potentially be exploited remotely with low attack complexity, without privileges or any user interaction,” he said. “That’s enough to warrant immediate attention and timely patching.”</p> <h2 class="wp-block-heading" id="critical-vulnerabilities-allowing-for-improper-lifetime-control-issues">Critical vulnerabilities allowing for ‘improper’ lifetime control issues</h2> <p class="wp-block-paragraph">Two of the seven vulnerabilities identified by Cisco are rated 9.8 in severity (critical) based on the Common Vulnerability Scoring System (CVSS).</p> <p class="wp-block-paragraph"><a href="https://www.cve.org/CVERecord?id=CVE-2026-20274" target="_blank" rel="noreferrer noopener">CVE-2026-20274</a> and <a href="https://www.cve.org/CVERecord?id=CVE-2026-20274" target="_blank" rel="noreferrer noopener">CVE-2026-20279</a> both address lifetime resource control issues, such as inappropriate certificate validation, incorrect or missing authorization for critical functions, resource operation after release or expiration, out-of-bounds read or write, initialization of resources with insecure details, and resource allocation without throttling limits.</p> <p class="wp-block-paragraph">The five other vulnerabilities are rated between 8.8 and 8.2 (high severity). Those patches address incorrect network usage calculations (buffer size, overflow, underflow), improper checks or handling of exceptional conditions or inconsistencies, insufficient control flow management, and protection mechanism failures.</p> <p class="wp-block-paragraph">However, Cisco hasn’t explicitly said that every one of these issues can lead to RCE, Info-Tech’s Avakian noted. But access control issues could allow an attacker to reach resources they shouldn’t be able to, while memory-related flaws could cause system crashes, denial of service, or create a path toward code execution. If an attacker gained “meaningful control” of a device, that could result in network and business disruption, unapproved configuration changes, routing manipulation, or could pave the way for a broader attack, he said.</p> <p class="wp-block-paragraph">The two 9.8s are all about “getting access and persistence,” said <a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="noreferrer noopener">David Shipley</a> of Beauceron Security. Both RCE and root router access are in the Salt Typhoon playbook, he pointed out, adding, “worst case scenarios with some of these lower CVSS bugs is widespread network disruption and outages.”</p> <p class="wp-block-paragraph">These are critical flaws in carrier-grade equipment, and telecom companies worldwide should be paying attention, “because you can bet there is a bunch of nation-state hacking teams who are,” he noted.</p> <h2 class="wp-block-heading" id="what-cisco-customers-should-do-now">What Cisco customers should do now</h2> <p class="wp-block-paragraph">Customers can identify whether a device is running Cisco IOS XR by using the “show version” command, the company said. They should upgrade to a release with available software maintenance upgrades (SMUs), or targeted software patches that don’t require a full system upgrade, then apply appropriate SMUs.</p> <p class="wp-block-paragraph">Available SMUs cover software trains from various versions, starting with version 7.3. There may be up to 16 SMUs for each release, and customers requiring patches for other releases not identified by Cisco should contact their security support organization or open a Cisco service request, the company said. Future Cisco IOS XR Software releases (26.2.2 and 26.3.1) will be the first fixed releases not requiring SMUs.</p> <p class="wp-block-paragraph">Avakian advised prioritizing patching based on exposure and criticality. “Internet-facing and core routing systems keeping the network running should move to the front of the line,” he said. Another important step is to look closely at how these devices are being managed, and what’s actually exposed.</p> <p class="wp-block-paragraph">This makes the case for <a href="https://www.csoonline.com/article/4048002/88-of-cisos-struggle-to-implement-zero-trust.html" target="_blank">zero-trust principles</a>: Restricting administrative access, applying and validating segmentation and access control lists (ACLs), and using out-of-band management “where practical,” Avakian said. Meanwhile, response teams should look for unexpected process crashes, configuration changes, unusual authentication activity, or unexplained routing changes.</p> <p class="wp-block-paragraph">There’s one additional consideration: It’s quite possible that even though an organization might not be running IOS XR directly, their telecom provider, MSP, or another critical partner might be, he noted.</p> <p class="wp-block-paragraph">“So, I’d be asking your various suppliers how they’re addressing it on their end: Whether they’re affected, if they’ve patched, and when remediation will be completed,” Avakian said. While the good news is that Cisco isn’t currently aware of public exploitation, the vulnerabilities are still public, there are no workarounds, and the highest-severity issues have characteristics attackers may try to exploit, he pointed out, “so timely patching is critical.”</p> <h2 class="wp-block-heading" id="ai-heralding-a-whole-new-era-of-security">AI heralding a whole new era of security</h2> <p class="wp-block-paragraph">Interestingly, the total number of bugs addressed in the advisory is grouped around common weaknesses and use a CVE per weakness, instead of per bug, Shipley noted. Its bug count is quite the contrast with Microsoft’s, which has doubled the size of its Patch Tuesday update with all the bugs it’s fixing.</p> <p class="wp-block-paragraph">“Two global firms, both using AI, two different takes on communicating how many bugs were found that need to be fixed,” Shipley said.</p> <p class="wp-block-paragraph">“That doesn’t help transparency, “ he said. “But it does make [Cisco’s] products look like they have less bugs, which is more a marketing move than a security move.” </p> <p class="wp-block-paragraph">Also worth noting is that Cisco said the bugs were found during internal tests, using frontier AI, he added. </p> <p class="wp-block-paragraph">Avakian also noted the “new normal,” where AI is already beginning to find vulnerabilities much faster than humans can. That means that, while suppliers may find vulnerabilities faster, adversaries will also increasingly have access to the same types of capabilities and speed. “In many ways, it becomes an AI-against-AI race,” he said.</p> <p class="wp-block-paragraph">The challenge for CIOs and security leaders will now be how quickly they can understand their exposure, appropriately test the patches, and safely get fixes into production, Avakian said. “As AI accelerates exploit development while enterprise patching still takes weeks or months, the gap becomes increasingly unsustainable,” he pointed out.</p> <p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.networkworld.com/article/4219946/cisco-bundles-fixes-for-multiple-vulnerabilities-some-critical-into-one-patch.html" target="_blank">Network World</a>.</em></p> <p class="wp-block-paragraph"></p> </div></div></div></div>

2026/9/9
阅读更多

CISA tells operators to harden Siemens S7 PLCs. Here’s how to do it without disrupting production

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph">On a conventional server, disabling an unused service is usually a routine hardening task. On a Siemens S7 controller, the supposedly unused service may carry remote I/O traffic, supply process values to an HMI or provide the maintenance team’s only path to diagnostics. Close it without checking those dependencies and the security team may cause the outage it intended to prevent.</p> <p class="wp-block-paragraph">That is the implementation problem inside <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a">joint cybersecurity advisory AA26-231A</a>, issued on August 19 by the NSA, CISA, FBI, Department of Energy and Environmental Protection Agency. The agencies warn of active targeting of Siemens S7 programmable logic controllers and recommend patching, removing internet exposure, strengthening access controls, monitoring S7 communications and disabling unnecessary services.</p> <p class="wp-block-paragraph">Every recommendation is reasonable. Several can affect production if they are implemented without understanding the plant.</p> <h2 class="wp-block-heading" id="the-warning-is-not-a-patch-notice">The warning is not a patch notice</h2> <p class="wp-block-paragraph">The advisory covers all CPU variants in the S7-200, S7-300 and S7-400 series, the S7-1200 compact CPUs listed in the advisory and all S7-1500 variants, including F-series safety controllers. These generations do not provide identical security functions.</p> <p class="wp-block-paragraph">Threat actors are using internet-scanning services to find exposed or poorly segmented controllers. According to the agencies, they combine public information with AI-assisted scripts and libraries such as Snap7 and python-snap7. The tools can communicate through S7comm, commonly over TCP port 102, and may read or write PLC memory, configuration data and control logic.</p> <p class="wp-block-paragraph">AI accelerates tool development, but it is not the underlying weakness. The advisory says actors are taking advantage of “known vulnerabilities, misconfigurations and other weaknesses.” It does not disclose one new vulnerability shared by every S7 or identify a single patch that resolves the threat.</p> <p class="wp-block-paragraph">Siemens made the same distinction in a <a href="https://www.produktion.de/technik/siemens-s7-us-behoerden-warnen-vor-aktiven-angriffen/2727668">statement to German trade publication Produktion</a>. The company said AA26-231A does not describe new S7-series vulnerabilities, but methods that may exploit misconfigurations already addressed in its guidance. Siemens’ updated <a href="https://cert-portal.siemens.com/productcert/html/ssb-104599.html">ProductCERT bulletin SSB-104599</a> directs customers to current software, protected networks, strong passwords and model-specific documentation.</p> <p class="wp-block-paragraph">This changes the response: operators cannot wait for one emergency update. They must reduce exposure across controllers with different hardware, firmware and engineering environments.</p> <p class="wp-block-paragraph">When I review an OT hardening change, I first need five facts: the exact CPU and communication modules, the firmware, the process and safety function, the legitimate communication partners and the approved recovery route. A control available on one device may not exist on another.</p> <h2 class="wp-block-heading" id="unused-must-be-proved">“Unused” must be proved</h2> <p class="wp-block-paragraph">The most dangerous word in the guidance is “unused.” CISA recommends disabling web servers and protocols such as Modbus TCP and PROFINET if they are not operationally required. The qualification is critical. PROFINET may connect the CPU to distributed I/O, drives or other controllers. Modbus TCP may support a meter, analyzer or third-party package. A web server may be part of the diagnostic workflow even if it carries no continuous traffic.</p> <p class="wp-block-paragraph">Ten quiet minutes on a network sensor do not prove that a connection is unnecessary. Some communications appear only during startup, shutdown, failover or maintenance. I ask teams to prove “unused” three ways: from the engineering configuration, from representative traffic and through confirmation by the automation and maintenance owners. If those sources disagree, the service stays in scope.</p> <p class="wp-block-paragraph">The same discipline applies to the other measures in the advisory:</p> <figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><thead><tr><td><strong>Hardening measure</strong></td><td><strong>What could break</strong></td><td><strong>Safer implementation</strong></td></tr></thead><tbody><tr><td>Restrict TCP port 102</td><td>HMI, engineering or controller-to-controller traffic</td><td>Block it at the perimeter; internally permit only documented communication pairs</td></tr><tr><td>Disable the web server</td><td>Browser-based diagnostics and maintenance</td><td>Confirm how it is used; if required, restrict it to a management zone</td></tr><tr><td>Disable Modbus TCP or PROFINET</td><td>Third-party equipment, remote I/O or drives</td><td>Verify the project configuration and observe representative traffic first</td></tr><tr><td>Apply PLC-side MAC/IP allowlisting</td><td>Older CPUs may not support it; redundant HMI or failover paths may be excluded</td><td>Map primary, secondary and maintenance nodes; enforce the rule at an industrial firewall where PLC-side control is unavailable</td></tr><tr><td>Limit S7comm sessions</td><td>HMI, historian or engineering access may exhaust the available connections</td><td>Measure normal and peak use, retain maintenance capacity and apply limits only where supported</td></tr><tr><td>Enable stronger CPU protection</td><td>Legacy partners or emergency maintenance may lose access</td><td>Test credentials, compatibility and recovery before deployment</td></tr><tr><td>Update firmware or engineering tools</td><td>Modules, libraries, safety functions or third-party integrations may fail</td><td>Validate the exact combination in a representative environment and define the backout route</td></tr></tbody></table> </div></figure> <p class="wp-block-paragraph">The network edge is normally the safest starting point. CISA recommends blocking TCP port 102 at perimeter firewalls. Blocking it indiscriminately inside a cell can interrupt legitimate S7 traffic. Internally, access should be limited to known communication pairs. Remote support should terminate at a managed gateway with individual authentication, a defined time window and session logging.</p> <p class="wp-block-paragraph">CISA also recommends MAC/IP allowlisting on the controllers themselves. That instruction is not universally implementable. Older CPUs may not offer the control and an incomplete list on a newer installation can break redundant HMI, engineering or vendor paths. The desired policy may therefore need to be enforced at the network boundary instead of on the PLC.</p> <p class="wp-block-paragraph">The advisory is similarly imprecise when it refers to “complete restart protection.” Technicians will not find a universal TIA Portal setting with that exact name. Operators need model-specific guidance instead of a guessed configuration change. Know-how protection can restrict access to selected blocks, but it does not replace network controls or integrity monitoring.</p> <h2 class="wp-block-heading" id="treat-hardening-as-an-ot-change">Treat hardening as an OT change</h2> <p class="wp-block-paragraph">Firmware updates, protection levels and connection limits are changes to a production control system. They require the same engineering discipline as any other modification: an approved starting state, a test, a maintenance window, a rollback decision and operational verification.</p> <p class="wp-block-paragraph">“Patch quickly” and “test first” are not opposing instructions. Exposed controllers deserve priority, but an update can affect modules, HMI drivers, third-party libraries, redundancy or safety functions. The relevant unit is the exact CPU, firmware, modules, engineering version and connected environment. A project backup may not reverse an update, and downgrading may not be supported.</p> <p class="wp-block-paragraph">The advisory also recommends checking for ladder-logic changes. Operators should compare more than ladder. An S7 application may include function block diagrams, structured text, data blocks, hardware configuration and communication settings. The comparison also needs a trusted reference. An old directory called “final” is not a gold copy merely because it is the only project available.</p> <p class="wp-block-paragraph">Unexplained differences do not automatically prove compromise. They may expose a legitimate field change that never reached the master project. Reconcile them, approve the actual state and preserve it as the new baseline. Safety programs require their formal Siemens Safety comparison and acceptance process; a routine online/offline comparison is not sufficient to accept changes to an F-program or F-I/O configuration.</p> <p class="wp-block-paragraph">Monitoring should be tied to that baseline and the change process. Useful signals include S7comm from an unapproved source, writes outside a maintenance window, port 102 scans and Snap7 or Python tooling on an unexpected system. Snap7 itself is legitimate; context determines whether its use is authorized.</p> <p class="wp-block-paragraph">I use nine questions to keep a hardening change both secure and operationally defensible:</p> <ol start="1" class="wp-block-list"> <li><strong>Which exact asset is changing?</strong> Record the CPU, firmware and process function.</li> <li><strong>Which attack path will close?</strong> Tie the action to a specific exposure or weakness.</li> <li><strong>Which legitimate functions depend on it?</strong> Include operations, engineering and vendor access.</li> <li><strong>What is the approved starting state?</strong> Capture the configuration and relevant communication paths.</li> <li><strong>How was the change tested?</strong> Use a representative environment and operating scenario.</li> <li><strong>What triggers rollback?</strong> Define observable failures rather than “if there is a problem.”</li> <li><strong>Can the rollback actually be executed?</strong> Confirm tools, credentials, files, hardware and qualified staff.</li> <li><strong>How will the process be verified?</strong> Check I/O, HMI values, alarms, interlocks, redundancy and safety behavior.</li> <li><strong>What becomes the new baseline?</strong> Archive the result, evidence and operator acceptance.</li> </ol> <p class="wp-block-paragraph">Make one meaningful controller change at a time. If firmware, access levels, protocols and connection limits change together, a failed test gives little indication of which measure caused it. The safest sequence moves from the outside inward: remove public exposure, restrict remote and cross-zone access, establish monitoring, prove dependencies and only then change controller services, protection settings or firmware in a planned window.</p> <p class="wp-block-paragraph">Successful PLC hardening has two acceptance criteria: the attack path is closed, and the process still behaves exactly as the operator expects.</p> </div></div></div></div>

2026/9/8
阅读更多

Mars Security Debuts Automated Threat Engine Processing Live Cyber Intelligence Into Validated Rules Within Minutes

<div id="remove_no_follow"> <div class="grid grid--cols-10@md grid--cols-8@lg article-column"> <div class="col-12 col-10@md col-6@lg col-start-3@lg"> <div class="article-column__content"> <section class="wp-block-bigbite-multi-title"><div class="container"></div></section> <p class="wp-block-paragraph"><a href="https://marssec.ai/" target="_blank" rel="noreferrer noopener">Mars Security</a>, an autonomous threat hunting and detection engineering platform founded by offensive cybersecurity veterans, today announced Real-Time Intel-Based Detection. </p> <p class="wp-block-paragraph">The milestone expansion equips enterprise security operations centers (SOCs) to convert newly published threat intelligence advisories into production-ready, validated detection rules within minutes of release.</p> <p class="wp-block-paragraph">Developed by former military red team operators, the capability systematically ingests threat reports from organizations such as CISA, Mandiant, Unit 42, and Microsoft Threat Intelligence. </p> <p class="wp-block-paragraph">The platform translates raw indicators and adversary techniques into native, MITRE ATT&amp;CK-mapped detection logic across an enterprise’s active security infrastructure—including CrowdStrike Falcon, Wiz, Splunk, firewall logs, Linux Sysmon, identity providers, and data lakes like Snowflake and Databricks. </p> <p class="wp-block-paragraph">Every generated rule is automatically benchmarked against 30 days of the organization’s historic telemetry prior to deployment, eliminating the need for data ingestion or infrastructure changes.</p> <p class="wp-block-paragraph"><strong>Accelerating the Pipeline From Threat Advisory to Active Defense</strong></p> <p class="wp-block-paragraph">Enterprises invest heavily in threat intelligence feeds, yet operationalizing that data into active detection logic remains a persistent industry challenge. </p> <p class="wp-block-paragraph">Traditional detection engineering workflows require security analysts to manually parse advisory briefs, extract indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs), identify corresponding log sources, write custom queries, and execute manual tuning cycles.</p> <p class="wp-block-paragraph">Across most security organizations, this manual workflow consumes days or weeks. In contrast, threat actors rotate infrastructure and modify tools within hours. Mars Security closes this critical exposure window by automating the complete transition from intelligence ingestion to production deployment:</p> <ul class="wp-block-list"> <li><strong>Automated Native Query Authoring:</strong> As advisories land, Mars extracts pertinent indicators and tactics, maps them to MITRE ATT&amp;CK framework nodes, and authors native query logic tailored to whichever connected log collector maintains visibility over the threat.</li> <li><strong>Empirical Historical Backtesting:</strong> Prior to presenting a rule for team approval, Mars executes the generated query against 30 days of historical customer telemetry to quantify event matches and project false-positive rates.</li> <li><strong>Heuristic Noise Reduction:</strong> Indicators such as domain names, IP addresses, and file hashes undergo automated scoring against historical noise baselines. Stale, overly broad, or historically noisy indicators are pruned automatically before reaching a rule.</li> <li><strong>Streamlined Review &amp; Deployment:</strong> Validated rules populate an analyst queue where security teams can inspect telemetry matches, rerun backtests over custom windows, and deploy rules into production with a single click.</li> </ul> <p class="wp-block-paragraph">“We spent years on the offensive side, and the thing that surprised us most was how rarely anyone saw us, even when the intel on our tradecraft was already public. Threat intelligence has always told security teams what is happening in the world. It never handed them the detection to find it in their own environment. Mars does that now, and it tests the detection against your data before it goes anywhere near production.” – Shahaf Galili, Co-Founder and CEO, Mars Security.</p> <p class="wp-block-paragraph"><strong>Continuous Defensive Gap Analysis and Behavioral Threat Hunting</strong></p> <p class="wp-block-paragraph">In addition to processing external threat streams, Mars operates continuously in reverse—mapping existing defensive coverage against connected telemetry sources to surface critical blind spots. Recent automated recommendations include detecting AWS CloudTrail logging tampering, Route 53 domain transfer abuse, pass-the-hash lateral movement, and anomalous Microsoft Graph API interactions. For teams utilizing detection-as-code workflows, Mars delivers actionable recommendations directly as open pull requests for seamless code review and deployment.</p> <p class="wp-block-paragraph">By prioritizing behavioral mechanics over static signatures, Mars ensures detection integrity persists even as threat actors alter their tools or infrastructure. The underlying architecture also addresses emerging operational surfaces, including monitoring AI coding agents and identifying credentials inadvertently leaked into security logs.</p> <p class="wp-block-paragraph">“A SOC should not need a two-week backlog to act on a report that took an attacker two hours to make obsolete. When the intel lands, the detection should already be written, already tested against your data, and waiting for a click.” – Ran Lerer, Co-Founder and CTO, Mars Security.</p> <p class="wp-block-paragraph">“A campaign advisory used to sit in a queue for days before it became a rule anyone trusted. With Mars, it shows up already mapped, already tested against the environment it’s meant to protect, and it actually holds up. That is the first time detection has felt ahead of the threat instead of behind it.” – Andy Ellis, Former CISO, Akamai Technologies.</p> <p class="wp-block-paragraph"><strong>Availability</strong></p> <p class="wp-block-paragraph">Real-Time Intel-Based Detection is immediately available to all existing Mars Security customers at no additional cost. Mars deploys within hours, requires no centralized data ingestion, preserves existing security tooling, and is available on the AWS Marketplace.</p> <p class="wp-block-paragraph"><strong>About Mars Security</strong></p> <p class="wp-block-paragraph">Mars Security is the autonomous threat hunting and detection engineering platform that continuously converts threat intelligence into validated detections across an organization’s existing security stack. Founded by offensive security veterans Shahaf Galili, Ran Lerer, and Matan Caspi—who bring more than 50 years of combined hands-on cyber offense experience—Mars queries SIEM, EDR, identity, cloud, and data lake telemetry in place, with no ingestion and no rip-and-replace. Mars maps detection coverage gaps, delivers a behavior-based threat hunting library built from years of offensive operations, and replaces the patch treadmill with continuous detection engineering. Mars is SOC 2 compliant, available on AWS Marketplace, and backed by TLV Partners, Jibe Ventures, Bullet Ventures, CCL, and XPS.</p> <p class="wp-block-paragraph">Learn more at<a href="https://marssec.ai/" target="_blank" rel="noreferrer noopener"> marssec.ai</a>.</p> <p class="wp-block-paragraph"></p> </div></div></div></div>

2026/9/8
阅读更多

推荐订阅