🔍 1 new social source(s) auto-discovered:
- [twitter] @jsrailton — from schneier.com/blog/…/embedding-forbidden-text-in-spywa
🚨 ACTIVE EXPLOITS & INCIDENTS
- CISA warns of max severity Ubiquiti flaws exploited in attacks — BleepingComputer CISA alerts on active exploitation of critical vulnerabilities in Ubiquiti UniFi OS and Lantronix serial-to-ethernet servers. These flaws allow unauthenticated remote attackers to execute commands, alter system settings, and access accounts, posing immediate risk to enterprise and ISP environments.
- Amadey, StealC malware operations disrupted in Operation Endgame action — BleepingComputer Microsoft, Europol, and partners dismantled hundreds of C2 servers supporting Amadey and StealC malware, disrupting key infrastructure used by ransomware gangs and cybercriminal services. This coordinated takedown impacts ongoing campaigns relying on these malware families.
- New ‘Mistic’ RAT Opens Door to Several Ransomware Families — SecurityWeek The Mistic backdoor, linked to ransomware access broker KongTuke, is actively used to provide initial access for multiple ransomware groups including Qilin, Black Basta, and others. Targets span insurance, education, IT, and professional services sectors, indicating broad attack surface and evolving ransomware supply chain.
🔓 VULNERABILITIES & CVEs
- Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks — The Hacker News Researchers reveal “Cordyceps,” a critical CI/CD workflow vulnerability allowing unauthenticated attackers to hijack build pipelines and compromise open-source supply chains. Affected repos include those of Microsoft, Google, and Apache, exposing millions of users to supply chain attacks. Immediate review of CI/CD pipeline permissions and workflows is advised.
- macOS Weaknesses Chained to Silently Disable Endpoint Security Agents — SecurityWeek A newly disclosed macOS attack chain leverages legitimate OS behaviors to silently disable endpoint security agents using only a non-admin user account. This technique bypasses traditional vulnerability-based detection, requiring defenders to reassess macOS security posture and monitoring strategies.
📋 VENDOR BULLETINS & ADVISORIES
- Advancing Product Security: New IoT Guidance and New Engagement — NIST Cybersecurity Insights NIST released an initial public draft of SP 800-213 Revision 1, updating IoT product cybersecurity guidelines for federal agencies. The guidance aims to help organizations operationalize IoT security requirements amid growing device complexity and evolving threats. Stakeholders encouraged to review and provide feedback.
🕵️ THREAT RESEARCH & DEEP DIVES
- Embedding Forbidden Text in Spyware to Discourage AI Analysis — Schneier on Security Malware authors are embedding politically sensitive and “forbidden” text blocks inside large JavaScript comments in spyware payloads to confuse AI-based automated analysis tools. This novel evasion technique targets AI-driven threat detection pipelines by triggering policy filters or derailing language model-based scanners.
- Agentic AI Security: Wrong Context, Wrong Decisions at Machine Speed — SecurityWeek Analysis of emerging agentic AI threats highlights risks from AI systems making security decisions without proper contextual understanding. Misaligned AI can accelerate attack timelines and amplify errors, underscoring the need for rigorous context validation in AI-powered security tools.
- Dawn of the Apex Agentic Adversary — The Hacker News The cybersecurity landscape is shifting from human-paced to machine-speed adversaries leveraging agentic AI for autonomous attack orchestration. This evolution compresses dwell time and response windows, demanding new detection paradigms and automated defense mechanisms.
📰 LESSER-KNOWN / UNDER-REPORTED
- BeyondTrust, LastPass Impacted by Klue-Salesforce Incident — SecurityWeek Over a dozen Klue customers, including BeyondTrust and LastPass, confirm data theft from compromised Salesforce instances. The breach highlights risks in third-party SaaS integrations and the need for enhanced monitoring of cloud-to-cloud data flows.
- White House’s state infrastructure cybersecurity initiative stalled — Cybersecurity Dive Federal efforts to pilot innovative cybersecurity defenses in state infrastructure remain delayed, with most states awaiting participation calls. This stall may impact nationwide resilience against critical infrastructure threats.