<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Team-CWD &#8211; Cyberwire Daily</title>
	<atom:link href="https://cyberwiredaily.com/author/admin_vxxtu2u6/feed/" rel="self" type="application/rss+xml" />
	<link>https://cyberwiredaily.com</link>
	<description></description>
	<lastBuildDate>Wed, 05 Aug 2026 10:09:51 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://cyberwiredaily.com/wp-content/uploads/2025/09/icon-150x150.png</url>
	<title>Team-CWD &#8211; Cyberwire Daily</title>
	<link>https://cyberwiredaily.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>ChainDrop Worm Hits 400 npm Packages with Two Billion Monthly Installs</title>
		<link>https://cyberwiredaily.com/chaindrop-worm-hits-400-npm-packages-with-two-billion-monthly-installs/</link>
					<comments>https://cyberwiredaily.com/chaindrop-worm-hits-400-npm-packages-with-two-billion-monthly-installs/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 10:09:51 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/chaindrop-worm-hits-400-npm-packages-with-two-billion-monthly-installs/</guid>

					<description><![CDATA[Security researchers have warned of a major new Shai-Hulud-based campaign which has already compromised more than 430 packages with a combined two billion monthly installs. The ChainDrop campaign began on August 4 when attackers compromised the GitHub account of a maintainer behind the popular keyv key storage library, which has around 127 million weekly npm [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div id="layout-19667f94-6b17-46ac-a641-6afe1e1e054c" data-layout-id="2" data-edit-folder-name="text" data-index="0">
<p>
	Security researchers have warned of a major new Shai-Hulud-based campaign which has already compromised more than 430 packages with a combined two billion monthly installs.</p>
<p>
	The ChainDrop campaign began on August 4 when attackers compromised the GitHub account of a maintainer behind the popular keyv key storage library, which has around 127 million weekly npm downloads, according to Aikido Security.</p>
<p>
	They used that access to inject a credential-stealing worm across other packages, including cacheable (29 million downloads/month), flat-cache (565 million), and file-entry-cache (557 million), the write-up claimed.</p>
<p>
	“The compromise was carried out by pushing malicious files directly to the main branch and then immediately cutting a new release, meaning the poisoned versions were published to npm with valid provenance signed by GitHub Actions,” Aikido <a href="https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack" target="_blank">explained</a>.</p>
<p>
	<em>Read more on Shai-Hulud: Shai-Hulud-Like Worm Targets Developers via npm and AI Tools</em></p>
<p>
	The malicious packages contain an <a href="https://www.infosecurityeurope.com/en-gb/blog/threat-vectors/guide-infostealer-malware.html">infostealer</a> designed to harvest npm and GitHub tokens, AWS credentials, Kubernetes secrets, HashiCorp Vault tokens, Stripe and Slack tokens, and perform a generic file system scan.</p>
<p>
	Once stolen, they’re encrypted and sent to a public GitHub repository with the description &#8220;Shai-Hulud: Here We Go Again.&#8221;</p>
<p>
	Like the infamous Shai-Hulud campaigns, ChainDrop features worm-like capabilities allowing it to spread to other maintainers and repositories via the stolen npm and GitHub tokens.</p>
<p>
	Packages associated with Deliveroo, Ornikar, OneReach, Picsart and Qlik have been compromised as part of the campaign.</p>
<h2>
	<strong>Wiz Security’s Mitigation and Protection Guidance</strong></h2>
<p>
	<a href="https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/" target="_blank">Microsoft </a>and <a href="https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack" target="_blank">Wiz Security </a>also published analysis of the campaign including indicators of compromise (IOCs) and mitigation advice. The latter’s recommendations are as follows:</p>
<ul>
<li>
		Identify and remove affected package versions from development, build, and CI/CD environments</li>
<li>
		Treat affected systems as potentially compromised and rebuild them if malicious packages were installed</li>
<li>
		Rotate exposed credentials (eg cloud credentials, GitHub tokens, SSH keys, Kubernetes configurations, Terraform credentials)</li>
<li>
		Review cloud and source-code environments for unauthorized access or suspicious activity following package installation</li>
<li>
		Monitor for published IOCs, including the relevant domains, file artifacts, and other indicators</li>
<li>
		Build resilience by enabling dependency allowlisting, package integrity verification, and provenance controls where available</li>
</ul>
<p>
	Katie-Paxton Fear, ethical hacker and staff security advocate at Semgrep, argued that the ChainDrop playbook is nothing new following Shai-Hulud last year.</p>
<p>
	“The worm steals developer credentials, uses them to compromise more packages and keeps moving through trusted publishing workflows,” she added.</p>
<p>
	“Even without a brand-new technique, organizations can’t assume that if they aren&#8217;t using the package that they are safe. They need to treat any installation, even if they aren&#8217;t using it, as a possible credential breach, and rotate exposed secrets, check logs for unauthorized access and audit their own packages for infection.”</p>
</div>
<p><br />
<br /><a href="https://www.infosecurity-magazine.com/news/chaindrop-worm-400-npm-two-billion/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/chaindrop-worm-hits-400-npm-packages-with-two-billion-monthly-installs/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Mythos Asks the Right Question. It Doesn&#8217;t Answer It.</title>
		<link>https://cyberwiredaily.com/mythos-asks-the-right-question-it-doesnt-answer-it/</link>
					<comments>https://cyberwiredaily.com/mythos-asks-the-right-question-it-doesnt-answer-it/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 10:03:09 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/mythos-asks-the-right-question-it-doesnt-answer-it/</guid>

					<description><![CDATA[AI is compressing exploit timelines. The real question isn&#8217;t whether your vulnerability management playbook needs to change, it&#8217;s which part of it you&#8217;ve been getting wrong all along. The conversation happening in security circles right now goes something like this: Mythos is here. Exploit timelines are collapsing. Does the vulnerability management playbook need to change? [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div id="articlebody">
<div class="separator" style="clear: both;"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0mieQQ57yqCRvM0amMKsszEvpX9AK9C4fSA6fyD6rx9VpNdjgYpiFk2D_AfSYT386yNTNuL1-ki2llA_LR-LXYw9r0p0nb2FZCnnP-u33sN2McktovTGN13k_n_i7HExGQdX6GcRSG0uKJAawc_6wusYkt37jY5sTvjz7k8kLa8RTIZM_NABBL64mbnY/s1600/meshs.jpg" style="display: block; padding: 1em 0; text-align: center; clear: left; float: left;"></a></div>
<p><em>AI is compressing exploit timelines. The real question isn&#8217;t whether your vulnerability management playbook needs to change, it&#8217;s which part of it you&#8217;ve been getting wrong all along.</em></p>
<p>The conversation happening in security circles right now goes something like this: Mythos is here. Exploit timelines are collapsing. Does the vulnerability management playbook need to change?</p>
<p>The honest answer is yes. But not the part most people are focused on.</p>
<p>The discussion around Mythos, Anthropic&#8217;s frontier model and its implications for offensive security, tends to center on discovery. AI accelerates reconnaissance. It helps attackers identify exposures faster, chain techniques more efficiently, and move at machine speed through environments that were previously protected, in part, by the attacker&#8217;s own time constraints.</p>
<p>That&#8217;s real. And it matters.</p>
<p>But here&#8217;s the part getting less attention: most security teams weren&#8217;t winning the prioritization battle before Mythos arrived. The compressed timeline doesn&#8217;t create a new problem. It raises the cost of an existing one.</p>
<p><em>&#8220;A CVSS 9.8 with no path to a critical asset is less urgent than a CVSS 5.5 sitting one hop from your customer database. That was true before Mythos. It&#8217;s just more expensive to get wrong now.&#8221;</em></p>
<h2>The Prioritization Problem Didn&#8217;t Start with AI</h2>
<p><a name="more"/></p>
<p>We&#8217;ve spent the past year talking to security architects, heads of detection and response, and CISOs across midmarket and growth enterprise organizations. When we ask how they prioritize vulnerabilities, the answers are remarkably consistent:</p>
<p><em>&#8220;A large proportion of the vulns we uncover aren&#8217;t actually exploitable but we don&#8217;t know that unless we research each one heavily, which we lack the time and headcount to do.&#8221;</em></p>
<p><em>&#8220;Currently by CVSS score&#8230; and not well.&#8221;</em></p>
<p><em>&#8220;We use Tenable and external security exercises which provide severity ratings, and that&#8217;s how we prioritize. It&#8217;s all very slow and we can do better.&#8221;</em></p>
<p>These aren&#8217;t small shops with immature programs. These are organizations running Qualys, Tenable, Rapid7, CrowdStrike, Wiz, Okta, and Splunk simultaneously. Serious tools. Serious budgets. Still working from a CVSS-sorted backlog.</p>
<p>The root cause isn&#8217;t scanner quality or coverage. It&#8217;s context. Specifically, the absence of three things that CVSS scores don&#8217;t include:</p>
<ul>
<li>Identity context. Which accounts have access to the vulnerable system, and are they overprivileged?</li>
<li>Reachability. Is this asset internet-exposed? Is it one hop from a crown-jewel system?</li>
<li>Path continuity. Does a confirmed exploit chain exist that connects this CVE to something that actually matters to the business?</li>
</ul>
<p>Without those three inputs, 50,000 findings is not a prioritized list. It&#8217;s a backlog with no compass.</p>
<h2>What Mythos Actually Changes, and What It Doesn&#8217;t</h2>
<p>Mythos and models like it compress the time between vulnerability disclosure and exploitation. A security team that used to have three weeks to patch after a CVE dropped might now have three days. In some cases, hours.</p>
<p>That&#8217;s a meaningful shift in operating conditions. But it doesn&#8217;t change the underlying architecture problem, it just makes the cost of that problem much higher.</p>
<p>If your team is working from a CVSS-sorted list of 50,000 findings, faster exploit timelines don&#8217;t help you. You&#8217;re still starting from the wrong list.</p>
<p><em>&#8220;Mythos accelerates the attacker. The question is whether your prioritization is fast enough to keep up, and right now, for most organizations, it isn&#8217;t.&#8221;</em></p>
<p>The question of whether Mythos demands a new vulnerability management playbook is worth asking. But the answer isn&#8217;t a faster scanner or a more aggressive patching cadence.</p>
<p>The playbook that needs to change is this one: stop treating vulnerability management as a standalone function that produces a sorted list of CVEs. Start asking which exposures, combined with which identity context, which network reachability, and which business criticality, create a confirmed path to a crown-jewel asset.</p>
<p>That&#8217;s not a detection problem. That&#8217;s an architecture problem.</p>
<h2>The Architecture Gap Nobody Is Talking About</h2>
<p>Here&#8217;s what a typical enterprise security stack looks like today:</p>
<ul>
<li>Identity: Okta or Entra</li>
<li>Cloud security: Wiz or Orca</li>
<li>Vulnerability management: Qualys, Tenable, or Rapid7</li>
<li>Endpoint: CrowdStrike or SentinelOne</li>
<li>Network: Zscaler or Palo Alto</li>
<li>SIEM: Splunk or Sentinel</li>
</ul>
<p>Each of these tools does exactly what it was built to do.</p>
<p>Wiz sees the misconfiguration. Okta sees the overprivileged service account. CrowdStrike sees the endpoint state. Qualys sees the CVE.</p>
<p>None of them see the chain that connects all four into a viable attack path to your customer database.</p>
<p><strong>Every one of those tools can hand you a risk score. None of them can hand you a decision you can defend to your board.</strong></p>
<p>That&#8217;s not a gap in any one tool. It&#8217;s a gap in the architecture.</p>
<p>We talked to a security architect whose team runs exactly this stack. Their description of the situation:</p>
<p><em>&#8220;We have good signals from all our tools, but correlating identity + cloud + endpoint into one attack path still takes manual work.&#8221;</em></p>
<p>That manual work, the tab-switching, the cross-referencing, the analyst hours spent building a picture that should already exist, is exactly what Mythos exploits. An attacker operating at machine speed doesn&#8217;t give you the two hours it takes to manually correlate your tools.</p>
<h2>What Attack-Path-Driven Prioritization Actually Looks Like</h2>
<p>The alternative isn&#8217;t a new scanner or a faster patching process. It&#8217;s a fundamentally different question:</p>
<p><em>Not &#8220;what is the CVSS score of this CVE?&#8221; But &#8220;can this CVE reach a crown-jewel asset, through which identity, across which trust boundary, with what blast radius?&#8221;</em></p>
<p>The math changes significantly when you add identity context. An overprivileged service account adjacent to an unpatched CVE isn&#8217;t a medium-severity finding. It&#8217;s a critical attack path.</p>
<p>A CVSS 5.5 on an internet-facing system with a direct route to your customer database is more urgent than a CVSS 9.8 on an isolated test environment. CVSS alone can&#8217;t tell you that. Your individual tools can&#8217;t tell you that. Only a system that correlates across them can.</p>
<p><em>&#8220;The security teams that respond effectively to AI-compressed exploit timelines aren&#8217;t the ones with the fastest patching processes. They&#8217;re the ones who know which 12 findings out of 50,000 actually matter.&#8221;</em></p>
<p>This is what Mesh was built to deliver. It ingests your existing vulnerability management tools and adds the context they&#8217;re missing:</p>
<ul>
<li>Identity context from Okta or Entra: Is an overprivileged account adjacent to this vulnerability?</li>
<li>Network reachability from Zscaler or Palo Alto: Is this asset internet-exposed?</li>
<li>Crown-jewel mapping: Does a confirmed path exist from this exposure to a critical asset?</li>
<li>Attack simulation validation via Horizon3.ai: Is this path actually exploitable today, not just theoretical?</li>
</ul>
<p>The output isn&#8217;t 50,000 findings sorted by severity. It&#8217;s 12 prioritized, evidence-backed exposures that have a confirmed path to something that matters.</p>
<p><strong>That&#8217;s not more data. That&#8217;s a decision.</strong></p>
<p>That&#8217;s the list that&#8217;s defensible in front of your board. That&#8217;s the list that lets you operate at the speed Mythos demands.</p>
<h2>The Playbook That Actually Needs to Change</h2>
<p>The old playbook: run your scanners, sort by CVSS, assign tickets, track remediation rates.</p>
<p>The new one:</p>
<ul>
<li>1. Connect your tools. Not replace them. Sit a unified intelligence layer above your existing stack that correlates across identity, cloud, endpoint, and vulnerability data simultaneously.</li>
<li>2. Prioritize by path, not by score. Ask which exposures have a confirmed route to a crown-jewel asset, through which identity, with what blast radius.</li>
<li>3. Validate before you remediate. Confirm a path is actually exploitable before committing remediation resources. Prioritize confirmed paths over theoretical ones.</li>
<li>4. Operate continuously, not periodically. Mythos means the window between exposure and exploitation can close in hours. Point-in-time assessments aren&#8217;t a baseline anymore; they&#8217;re a liability.</li>
</ul>
<p>None of this requires replacing the tools you&#8217;ve already deployed. Qualys still finds your CVEs. Okta still governs your identities. Wiz still flags your cloud misconfigs. The gap isn&#8217;t in what those tools see individually, it&#8217;s that nothing connects what they see collectively into one picture.</p>
<p>That&#8217;s the architecture problem. And Mythos just made it a lot more expensive to ignore.</p>
<p>Mythos doesn&#8217;t invalidate vulnerability management. It invalidates vulnerability management that operates without context. AI won&#8217;t punish organizations because they patch too slowly. It will punish them because they&#8217;re patching the wrong things. That&#8217;s the playbook that actually needs to change.</p>
<p>See what <a href="https://mesh.security/demo" target="_blank">your real attack paths</a> look like in your own environment.</p>
<p><em>&#8211;</em></p>
<p>Mesh is the unified intelligence layer for enterprise security teams operating across fragmented security stacks with no shared context. Connecting agentlessly to your existing tools, Mesh correlates signals across identity, cloud, SaaS, endpoint, and AI environments to reveal viable attack paths to your most critical assets. By providing enterprise-wide context that no individual tool can deliver alone, Mesh helps security teams prioritize what matters most and eliminate risk faster through guided or autonomous remediation workflows.</p>
<p>Your Tools, Unified. Your Risks, Eliminated. <a href="https://mesh.security" target="_blank">https://mesh.security</a></p>
</div>
<p><br />
<br /><a href="https://thehackernews.com/2026/07/mythos-asks-right-question-it-doesnt.html" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/mythos-asks-the-right-question-it-doesnt-answer-it/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser</title>
		<link>https://cyberwiredaily.com/researchers-show-a-single-malicious-webpage-visit-can-compromise-tor-browser/</link>
					<comments>https://cyberwiredaily.com/researchers-show-a-single-malicious-webpage-visit-can-compromise-tor-browser/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 06:02:28 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/researchers-show-a-single-malicious-webpage-visit-can-compromise-tor-browser/</guid>

					<description><![CDATA[Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser&#8217;s renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. &#8220;No settings or additional [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div id="articlebody">
<div class="separator" style="clear: both;"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOwFIxqT8kRBNj9LdZBZhO1g2RPJwUttxQosrS_mPoNXkIR-JB-yM87HPzuPZ1tazourGhRg9Sco6YQEGZkC77DSqXBYjp0DkNDAUHOaAOnIisRYNPAQfNWwqnmoILXOgR0wwyGVNlU3kSVRU6TcfyAx5ztaAWZfbKnCDJYgUeIVsM7n7O2zq7fGc-xnI/s1600/tor-exploit.gif" style="display: block; padding: 1em 0; text-align: center; clear: left; float: left;"></a></div>
<p>Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser.</p>
<p>Tracked as <strong>CVE-2026-10702</strong>, the bug provides arbitrary code execution inside the browser&#8217;s renderer process. Mozilla rated it High and fixed it in the <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2026-54/" target="_blank">Firefox 151.0.3 update</a>.</p>
<p>&#8220;No settings or additional user interaction are required,&#8221; Eten Zou, CEO of Nebula Security, told The Hacker News. &#8220;Visiting a malicious webpage is enough to trigger it,&#8221; Zou said every Tor Browser release that incorporated a vulnerable Firefox version was affected, though researchers have not identified the exact Tor releases.</p>
<p>On its own, the bug runs code only inside Firefox&#8217;s sandboxed content process. Nebula <a href="https://github.com/NebuSec/CyberMeowfia/commits/main/IonStack/CVE-2026-10702" target="_blank">released public exploit material</a> and used the flaw as the first stage of IonStack, a browser-to-kernel chain built for an ARM64 device running Android 17. The released end-to-end code targets one supported Google build, although Zou said the browser flaw itself is not ARM-specific.</p>
<p>The public code contains Firefox 151.0 offsets for the supported ARM64 Android 17 build. Zou said each exploitation step is architecture-independent and described the x86 path as more stable, although Nebula has not completed the full chain for that architecture.</p>
<p><!--adsense--></p>
<p>Firefox users should update to the latest release. The Hacker News traced the faulty alias declaration through Mozilla&#8217;s source history to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1995077" target="_blank">Bug 1995077</a>, which landed for Firefox 147. The override is present in <a href="https://raw.githubusercontent.com/mozilla-firefox/firefox/FIREFOX_151_0_2_RELEASE/js/src/jit/MIR.h" target="_blank">Firefox 151.0.2</a> and absent from <a href="https://raw.githubusercontent.com/mozilla-firefox/firefox/FIREFOX_151_0_3_RELEASE/js/src/jit/MIR.h" target="_blank">Firefox 151.0.3</a>. That places the affected stable-release range at Firefox 147 through 151.0.2.</p>
<p><a name="more"/></p>
<p>Mozilla&#8217;s advisory does not list Firefox ESR, and the faulty override is absent from <a href="https://raw.githubusercontent.com/mozilla-firefox/firefox/FIREFOX_140_12_0esr_RELEASE/js/src/jit/MIR.h" target="_blank">Firefox ESR 140.12</a>. As of July 28, 2026, the available primary-source record does not establish exploitation against users in the wild.</p>
<p>In its <a href="https://nebusec.ai/research/ionstack-part-1-cve-2026-10702/" target="_blank">technical analysis</a>, Nebula traces the issue to MObjectToIterator when it runs with skipRegistration set to true. Firefox&#8217;s just-in-time (JIT) compiler turns frequently run JavaScript into native machine code, and to do that safely it has to track which operations can touch memory.</p>
<p>Firefox treated the operation as a read even though resolving a lazy property can allocate a replacement dynamic-slots buffer and free the old one.</p>
<p>Global value numbering then treated a later slots-buffer load as redundant and reused the earlier pointer after it had become stale. Nebula&#8217;s <a href="https://github.com/NebuSec/CyberMeowfia/blob/main/IonStack/CVE-2026-10702/exploit.html" target="_blank">released exploit</a> reclaims the freed allocation, leaks a hidden-class pointer, builds a fake object, and corrupts a Uint8Array to gain arbitrary memory read and write. The Android code then changes memory protections and redirects a WebAssembly function entry point to ARM64 shellcode.</p>
<p>The failure turns on a narrow compiler contract: an operation capable of replacing the object&#8217;s dynamic-slots buffer was labelled as a read. That incorrect contract let otherwise valid optimisation logic preserve a pointer the runtime had already invalidated.</p>
<p><!--linkads--></p>
<p>Mozilla&#8217;s <a href="https://github.com/mozilla-firefox/firefox/commit/e43e678" target="_blank">source-level fix</a> removes the custom read-only alias handling from ObjectToIterator and adjusts the related iterator operation. That prevents the optimiser from treating a mutation-capable step as a harmless load and retaining the stale pointer.</p>
<p>IonStack&#8217;s second stage is CVE-2026-43499, a separate Linux kernel futex flaw that Nebula calls GhostLock. CVE-2026-10702 provides the remote browser foothold; CVE-2026-43499 carries it to root on the supported Android build.</p>
<p>Zou said GhostLock is invoked directly from Firefox. He added that Android&#8217;s weaker sandbox makes exploitation easier, but Nebula does not believe a stronger desktop sandbox would prevent the attack.</p>
<p>Updating Firefox blocks the documented browser entry point, but it does not patch GhostLock itself.</p>
</div>
<p><br />
<br /><a href="https://thehackernews.com/2026/07/researchers-show-single-malicious.html" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/researchers-show-a-single-malicious-webpage-visit-can-compromise-tor-browser/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>UK’s Police National Legal Database Reveals Data Breach</title>
		<link>https://cyberwiredaily.com/uks-police-national-legal-database-reveals-data-breach/</link>
					<comments>https://cyberwiredaily.com/uks-police-national-legal-database-reveals-data-breach/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Tue, 04 Aug 2026 22:15:58 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/uks-police-national-legal-database-reveals-data-breach/</guid>

					<description><![CDATA[A major database containing the work details of British police officers and criminal justice professionals has been compromised, it has emerged. The Police National Legal Database (PNLD) is managed by the West Yorkshire Police and contains information on officers from all 43 police forces in England and Wales, as well as the British Transport Police, [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div id="layout-07d78835-db42-4a7f-85b4-522066f94764" data-layout-id="2" data-edit-folder-name="text" data-index="0">
<p>
	A major database containing the work details of British police officers and criminal justice professionals has been compromised, it has emerged.</p>
<p>
	The Police National Legal Database (PNLD) is managed by the West Yorkshire Police and contains information on officers from all 43 police forces in England and Wales, as well as the British Transport Police, the Crown Prosecution Service, the Independent Office for Police Conduct, and His Majesty&#8217;s Courts and Tribunals Service.</p>
<p>
	An August 3 statement from the PNLD revealed the service had suffered a “data security incident,” which was identified on July 26.</p>
<p>
	“Information including the names, organizations and work email addresses of police officers, staff and other criminal justice professionals, government partners and customers has been compromised and published on the dark web. There is no evidence to suggest that passwords or other security credentials have been compromised,” it explained.</p>
<p>
	“Since the incident was identified, we have been working with specialist cybersecurity organizations and the National Crime Agency to investigate the circumstances and take appropriate action.”</p>
<p>
	<em>Read more on police data breaches: PSNI Faces £750,000 Data Breach Fine After Spreadsheet Leak</em></p>
<p>
	Also impacted was the Ask the Police service operated by the PNLD.</p>
<p>
	“As a result, some names and email addresses of people who have previously submitted a question to Ask the Police have been published on the dark web,” the notice read.</p>
<p>“If you have been affected, you will have already received an email from Ask the Police with more information and guidance.”</p>
<p>
	The PNLD explained that it doesn’t hold any confidential information relating to victims, witnesses, or offenders.</p>
<h2>
	<strong>ExfilSquad Claims Responsibility for PNLD Hack </strong></h2>
<p>
	ExfilSquad, the extortion group responsible for a recent data breach at the UK&#8217;s Department for Education, claimed it was also behind the PNLD incident.</p>
<p>
	According to screenshots of its leak site <a href="https://x.com/ChaosLensX/status/2084363969477939613" target="_blank">posted to X</a>, the group claimed to have 1.9GB of data in its possession, including 135,000 records, some of which it leaked to prove it means business.</p>
<p>
	“Once your company’s data is posted here it’s never leaving the public eye and will be passed around the internet forever,” a note by the group read. “The payment we request of you is simply a rounding error compared to the litigation costs of your data leaking. Be smart and just pay.”</p>
<p>
	For PNLD to pay is highly unlikely given the UK government’s intention to introduce a de facto ban on public sector organizations paying extortion demands made by cyber adversaries.</p>
<p>
	Any individuals named in the breach ought to be on the lookout for follow-on attacks if their data is leaked.</p>
<p>
	Dray Agha, senior manager, security operations center EMEA at Huntress, said: &#8220;While the absence of compromised passwords is a relief, exposing the names and work emails of UK police and justice staff on the dark web hands cybercriminals a readymade directory to launch highly targeted spear-phishing and social engineering attacks against the very people defending our justice system.&#8221;</p>
</div>
<p><br />
<br /><a href="https://www.infosecurity-magazine.com/news/uks-police-national-legal-database/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/uks-police-national-legal-database-reveals-data-breach/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack</title>
		<link>https://cyberwiredaily.com/73-of-organizations-say-they-are-not-fully-ready-for-a-major-cyberattack/</link>
					<comments>https://cyberwiredaily.com/73-of-organizations-say-they-are-not-fully-ready-for-a-major-cyberattack/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Tue, 04 Aug 2026 22:08:40 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/73-of-organizations-say-they-are-not-fully-ready-for-a-major-cyberattack/</guid>

					<description><![CDATA[Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack. According to The State of Incident Response Readiness 2026, based on a survey of 600 senior IT security decision makers conducted by [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div id="articlebody">
<div class="separator" style="clear: both;"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixbolkSzPCa__qy94Mm27YfEsvVeyY94SOG5BrCQCGtAe-QenE0qDM5Tkbb7eOy0PwSCECFGMrZ7IG7lVePoMWjqMn8s_7-5_r8JUSQ7WVHsHAo-zZIhyphenhyphenyNW5aGTbFkpgtu99ucSeEgcJK75UdxkAsWKjXf_x8zEGpcDURPf9UJjcDz8JSHFD0uahDcOI5/s1600/ss.jpg" style="display: block; padding: 1em 0; text-align: center; clear: left; float: left;"></a></div>
<p>Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack.</p>
<p>According to <em><a href="https://www.sygnia.co/guides-and-tools/ciso-survey-2026/" target="_blank">The State of Incident Response Readiness 2026</a></em>, based on a survey of 600 senior IT security decision makers conducted by Vanson Bourne in January and February 2026, 73% of organizations admit they would not be &#8220;fully ready&#8221; if a significant cybersecurity attack occurred tomorrow.</p>
<p>The findings point to a critical gap between having incident response capabilities and being able to execute them effectively under pressure.</p>
<p>The report also found that cyberattacks are already a recurring business risk. More than three-quarters of organizations, 76%, experienced at least one cyberattack in the past 12 months, while 32% experienced more than one.</p>
<h2 style="text-align: left;">Incident Response Readiness Remains a Weak Point</h2>
<p>Incident response has evolved far beyond technical containment. A mature response now requires executive crisis management, legal and regulatory coordination, stakeholder communications, enterprise-wide investigation, remediation, recovery, and post-incident monitoring.</p>
<p>The survey indicates that many organizations are struggling to bring these elements together in a coordinated way. Fewer than 40% of respondents described key incident response components as &#8220;highly effective,&#8221; including areas such as documented plans, tabletop exercises, threat hunting, digital forensics, and 24/7 monitoring.</p>
<p><a name="more"/></p>
<p>The issue is not simply whether these capabilities exist. The larger concern is whether they work together when decisions must be made quickly.</p>
<h2 style="text-align: left;">Coordination Breakdowns Slow Response</h2>
<p>One of the most significant findings is the extent to which internal friction affects response efforts. The report found that 90% of organizations expect difficulty coordinating stakeholders during a significant incident.</p>
<p>That coordination challenge becomes especially problematic when legal, communications, security, IT, and executive teams are not aligned before an incident begins. The research found that 75% of respondents agree delays or uncertainty around legal and communications team involvement slow decision-making during cyber incidents.</p>
<p>The report also found that 89% cite limited executive or board involvement in incident response readiness and decision-making.</p>
<p>This creates a dangerous pattern during a live incident:</p>
<ul>
<li>Technical teams investigate and contain the attack</li>
<li>Executives require updates before approving major actions</li>
<li>Legal and communications teams become involved late</li>
<li>Disclosure, customer messaging, and escalation decisions lag</li>
<li>Response teams lose time when containment decisions need speed</li>
</ul>
<p>In practice, unclear ownership can turn an incident response process into a reactive cycle. Instead of executing a rehearsed plan, teams spend critical time briefing stakeholders, clarifying authority, and waiting for approvals.</p>
<h2 style="text-align: left;">Visibility Gaps Increase the Risk of Repeat Incidents</h2>
<p>The report also highlights a major technical challenge: organizations often cannot fully see where attackers have moved.</p>
<p>According to the survey, 78% of respondents agree blind spots in their environment create persistent attacker access and increase the risk of repeated incidents. These blind spots can span on-premises infrastructure, public cloud environments, endpoints, SaaS platforms, identity systems, and operational technology environments.</p>
<p>That lack of visibility can prevent responders from confidently answering essential questions, such as:</p>
<ul>
<li>Where did the attacker enter?</li>
<li>Which systems were accessed?</li>
<li>Has the attacker moved laterally?</li>
<li>Are privileged accounts compromised?</li>
<li>Has malware or persistence been removed?</li>
<li>Could the attacker return after recovery?</li>
</ul>
<p>Without reliable visibility, organizations risk containing only part of the incident while leaving attacker access intact.</p>
<h2 style="text-align: left;">OT and ICS Environments Add Business Risk</h2>
<p>The report found that 84% of organizations are concerned about attackers crossing from corporate IT systems into operational technology or industrial control system environments.</p>
<p>This concern is particularly serious for sectors such as manufacturing, energy, healthcare, transportation, and critical infrastructure, where cyber incidents can affect physical operations. If attackers move from IT into OT or ICS systems, the impact may extend beyond data theft or business disruption. It can affect production, safety, service delivery, and recovery timelines.</p>
<p>The findings suggest that many organizations recognize this exposure but still lack the unified visibility needed to detect and stop cross-environment movement quickly.</p>
<h2 style="text-align: left;">Cyberattacks Are Already Causing Business Damage</h2>
<p>The report shows that cyber incidents are producing tangible consequences across sectors and regions. Among organizations hit by a cyberattack in the past 12 months, impacts included operational shutdowns, data loss, reputational damage, customer loss, lost revenue, and executive disruption.</p>
<p>The findings vary by sector:</p>
<ul>
<li>Retail organizations were most likely to report operational shutdowns and lost revenue or profit.</li>
<li>Manufacturing and financial services organizations were more likely to report data loss.</li>
<li>Crypto and decentralized finance organizations reported the highest attack incidence.</li>
<li>Private healthcare organizations reported high concern around legal and communications delays.</li>
</ul>
<p>Regional differences also emerged. North America reported the highest cyberattack incidence, while APAC respondents were most likely to report data loss, reputational damage, and customer loss. Europe reported fewer incidents overall, but incidents there were more likely to result in lost revenue or profit.</p>
<h2 style="text-align: left;">Ransomware and Cloud Attacks Lead Future Concerns</h2>
<p>Looking ahead, respondents identified a broad set of threats that could cause serious financial, operational, or reputational disruption. Ransomware ranked as the leading concern, followed closely by cloud environment attacks.</p>
<p>However, the findings suggest that organizations are not facing a single dominant threat. Instead, they are preparing for a crowded threat landscape that includes cloud compromise, identity abuse, third-party risk, AI-enabled threats, ransomware, and attacks that move across hybrid environments.</p>
<p>This makes incident response readiness harder to define. Organizations must be able to respond across multiple attack paths, not just prepare for one scenario.</p>
<h2 style="text-align: left;">AI Adoption Is Rising, but It Is Not a Substitute for Readiness</h2>
<p>The report shows that organizations are increasingly adopting AI and machine learning-driven capabilities for threat detection and incident response.</p>
<p>Nearly one-third of organizations now report extensive AI use across most or all threat detection and incident response activities, up from 25% last year. By 2027, 63% expect AI to be embedded across these activities.</p>
<p>The report suggests that <a href="https://www.sygnia.co/solutions/artificial-intelligence-cybersecurity-services/" target="_blank">AI can strengthen incident response</a> when it is integrated into mature workflows. Organizations with moderate or extensive AI use were more likely to rate incident response elements as effective compared with organizations using AI in a limited way.</p>
<p>However, the findings also indicate that AI should not be treated as a replacement for governance, visibility, and disciplined response execution. AI can accelerate triage, threat hunting, and investigation, but it cannot resolve unclear decision rights, fragmented stakeholder coordination, or incomplete visibility on its own.</p>
<h2 style="text-align: left;">Organizations Are Re-Evaluating Incident Response Support Models</h2>
<p>Another notable finding is that many organizations are reconsidering their external <a href="https://www.sygnia.co/solutions/incident-response-services/" target="_blank">incident response</a> and managed detection and response relationships.</p>
<p>The report found that many organizations expect to switch providers at the end of their current contracts. Drivers include the need for:</p>
<ul>
<li>More proactive readiness support</li>
<li>Better coverage across IT, OT, cloud, and hybrid environments</li>
<li>Stronger expertise in complex incidents</li>
<li>Improved visibility beyond a single technology ecosystem</li>
<li>Faster support during high-pressure investigations</li>
</ul>
<p>The findings also highlight concern about overreliance on narrow technology ecosystems during incident response. When response teams are limited to one platform or toolset, investigation and containment may be constrained by what that ecosystem can detect, access, or support.</p>
<p>Organizations may benefit from evaluating whether their internal teams and external providers can operate across multiple security tools, cloud platforms, identity systems, SaaS applications, and OT environments.</p>
<h2 style="text-align: left;">How Organizations Can Strengthen Incident Response Readiness</h2>
<p>The findings suggest that incident response readiness should be treated as an ongoing operational discipline rather than a static plan or annual compliance exercise. Organizations can reduce response delays by focusing on several practical areas.</p>
<h3 style="text-align: left;">1. Define decision rights before an incident</h3>
<p>Security teams, executives, legal, communications, compliance, and business leaders should understand their roles before a crisis begins. Escalation paths, approval thresholds, and communication responsibilities should be documented and rehearsed.</p>
<h3 style="text-align: left;">2. Test cross-functional coordination</h3>
<p>Tabletop exercises should include both technical and non-technical stakeholders. These exercises can help identify where decision-making slows, where authority is unclear, and where response plans do not reflect real business dependencies.</p>
<h3 style="text-align: left;">3. Validate visibility across critical environments</h3>
<p>Organizations should assess whether they can investigate activity across endpoints, identity systems, cloud platforms, SaaS applications, on-premises infrastructure, and OT environments where applicable. Visibility should be tested through exercises such as threat hunting, attack simulation, red team assessments, or purple team engagements.</p>
<h3 style="text-align: left;">4. Use AI to support, not replace, response processes</h3>
<p>AI and automation can help accelerate triage, alert enrichment, investigation, and threat hunting. However, these capabilities should be embedded into defined workflows with human oversight, clear escalation criteria, and tested response procedures.</p>
<h3 style="text-align: left;">5. Assess internal and external response capacity</h3>
<p>Organizations should determine which incident response functions they can handle internally and where external expertise may be required. External providers, where used, should be evaluated based on incident experience, response speed, technical depth, ability to operate across environments, communication practices, and support for post-incident improvement.</p>
<p>The central lesson is that readiness depends on execution. Plans, tools, and providers all matter, but they only reduce risk when they are connected through tested processes, clear authority, and reliable visibility.</p>
<h2 style="text-align: left;">The Bottom Line</h2>
<p>The research paints a clear picture: most organizations are being attacked, but many are not confident that their incident response capabilities will hold under pressure.</p>
<p>The challenge is no longer just building a response plan. It is ensuring that the plan works across teams, technologies, executives, legal stakeholders, communications teams, and business operations when a real attack occurs.</p>
<p>As attackers move faster across cloud, IT, identity, SaaS, and OT environments, incident response readiness must become a continuous business discipline. Organizations that wait until a live incident to discover gaps in visibility, authority, or coordination may find that the cost of delay is measured not only in systems affected, but in revenue, reputation, and trust.</p>
<p><noscript><br />
<img decoding="async" alt="" height="1" src="https://px.ads.linkedin.com/collect/?pid=4003889&amp;fmt=gif" style="display:none;" width="1"/><br />
</noscript></p>
</div>
<p><br />
<br /><a href="https://thehackernews.com/2026/07/73-of-organizations-say-they-are-not.html" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/73-of-organizations-say-they-are-not-fully-ready-for-a-major-cyberattack/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Cloud and SaaS Environments Now Top Targets for Attackers</title>
		<link>https://cyberwiredaily.com/cloud-and-saas-environments-now-top-targets-for-attackers/</link>
					<comments>https://cyberwiredaily.com/cloud-and-saas-environments-now-top-targets-for-attackers/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Tue, 04 Aug 2026 18:15:26 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/cloud-and-saas-environments-now-top-targets-for-attackers/</guid>

					<description><![CDATA[Cloud and Software-as-a-Service (SaaS) environments have become top targets for cyber-threat actors this year, according to a new report by Darktrace. The cybersecurity firm noted that H1 2026 saw a continuation of an evolution observed in 2025 where attackers shifted away from malware and vulnerability exploitation towards compromising identities. However, whereas in 2025 threat actors [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div id="layout-24cb5968-a6f7-414d-8d09-2f45f99a7396" data-layout-id="2" data-edit-folder-name="text" data-index="0">
<p>
	Cloud and Software-as-a-Service (SaaS) environments have become top targets for cyber-threat actors this year, according to a new report by Darktrace.</p>
<p>
	The cybersecurity firm noted that H1 2026 saw a continuation of an evolution observed in 2025 where attackers shifted away from malware and vulnerability exploitation towards compromising identities.</p>
<p>
	However, whereas in 2025 threat actors primarily targeted account credentials, the first half of 2026 has seen attacks extend to email authentication, cloud entitlements, software supply chains, AI gateways, remote administration tooling and non-human identities. Darktrace said this trend makes “trust” the new attack surface.</p>
<p>
	Compromised cloud and SaaS environments in particular provide enormous opportunities for attackers.</p>
<p>
	In one case highlighted by Darktrace, a single compromised SaaS account led to malicious activity across email, SaaS and network layers, such as inbox rule changes and the launch of phishing attacks. This type of attack is difficult to detect as none of the indicators were decisive in isolation, but together represented a clear intrusion.</p>
<p>
	The vendor also cited several cases where attackers exploited trusted digital supply chain infrastructure used by victims in H1 2026. This included threat actors in April hijacking Axios to spread remote access trojans (RATs). Axios is a JavaScript library downloaded over 100 million times a week and used as a dependency in countless developer environments and CI/CD pipelines.</p>
<p>
	Atatckers were also observed abusing legitimate blockchain infrastructure to distribute <a href="https://www.infosecurityeurope.com/en-gb/blog/threat-vectors/guide-infostealer-malware.html" target="_blank">infostealers</a>, including AMOS and Phexia. The researchers noted that such services are frequently used by users with limited security resources and often enable malicious actors to reach a far wider victim base.</p>
<p>
	“Increasingly, attackers do not need to bypass trust controls in these environments; they inherit them through compromised identities, delegated access, and legitimate administration tools,” the researchers noted in the <a href="https://www.darktrace.com/blog/why-trust-is-the-new-attack-surface-darktraces-mid-year-threat-update-2026" target="_blank">report</a> published on August 3.</p>
<h2>
	<strong>Email Attacks Prioritize Quality Over Quantity</strong></h2>
<p>
	The study found that email-based attacks are growing in sophistication, with attackers investing in quality over “noise.”</p>
<p>
	Around two-thirds of phishing emails sent in H1 2026 passed the DMARC email validation protocols, which the researchers said show that authentication is no longer sufficient to protect accounts.</p>
<p>
	More than a third (37%) of phishing attacks contained a high volume of text in H1 2026, up from 32% in the same period in 2025.</p>
<p>
	In addition, 39% of phishing featured novel social engineering techniques and VIP users were targeted in 25% of observed attacks. This suggests that threat actors are increasingly customizing attacks to specific targets.</p>
<p>
	ClickFix social engineering, a technique designed to trick users into running malicious code themselves, continued to be a common attack vector from 2025.</p>
<h2>
	<strong>AI is Growing the Attack Surface</strong></h2>
<p>
	The growing use of AI in enterprises has significantly expanded opportunities for cyber attackers, according to the Darktrace study.</p>
<p>
	This includes threat actors leveraging AI tools to launch attacks at scale. This was demonstrated with the use of AI-generated malware exploiting the React2Shell vulnerability, in which an attacker used an LLM to produce working exploit code and deploy it at scale.</p>
<p>
	In July, the world’s first fully AI-generated ransomware campaign, dubbed JadePuffer, was highlighted by security researchers. An agentic threat actor exploited a vulnerability in an internet-facing server before launching a fully automated ransomware attack.</p>
<p>
	“AI is accelerating the path from vulnerability disclosure to operational exploitation,” the Darktrace researchers wrote.</p>
</div>
<p><br />
<br /><a href="https://www.infosecurity-magazine.com/news/cloud-saas-targets-attackers/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/cloud-and-saas-environments-now-top-targets-for-attackers/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity</title>
		<link>https://cyberwiredaily.com/russia-charges-telegram-founder-pavel-durov-with-aiding-terrorist-activity/</link>
					<comments>https://cyberwiredaily.com/russia-charges-telegram-founder-pavel-durov-with-aiding-terrorist-activity/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Tue, 04 Aug 2026 18:05:49 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/russia-charges-telegram-founder-pavel-durov-with-aiding-terrorist-activity/</guid>

					<description><![CDATA[The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information in violation of Russian law. The principal security agency said the instant messaging platform &#8220;failed to remove numerous channels, chats, and bots on the platform [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div id="articlebody">
<div class="separator" style="clear: both;"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMUnFYtFjTBTc4gylDAEu-XkRP-crArKjOPCGhPhdX7S3Of7UKlVyAbHVb9CyAStiVaXJkXjUgXssYTKSJNnQvJvxdn_diL69NGa-2lhE_6GJCBFp0qMshbqCPnCksje_5yYMqhqh43Np9-CEkjJDa_gs6Axq0lxbi12SlPKqPWf-s6_Roin-zR0DIBjvy/s1600/x-post-telegram.jpg" style="display: block; padding: 1em 0; text-align: center; clear: left; float: left;"></a></div>
<p>The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information in violation of Russian law.</p>
<p>The principal security agency <a href="http://www.fsb.ru/fsb/press/message/single.htm%21id%3D10440775%40fsbMessage.html" target="_blank">said</a> the instant messaging platform &#8220;failed to remove numerous channels, chats, and bots on the platform that are actively used by Ukrainian special services and by terrorist and extremist organizations to plan and coordinate acts of sabotage and terrorism, mass killings, and cyber-fraud operations within the Russian Federation.&#8221;</p>
<p>These actions have resulted in numerous casualties, including among women and children, as well as significant damage amounting to billions, it added.</p>
<p>Durov has been charged in connection with an ongoing criminal investigation under Part 1.1 of <a href="https://www.unodc.org/cld/en/legislation/rus/the_criminal_code_of_the_russian_federation_russianenglish/chapter_24/article_205.1_-_205.3/article_205.1_-_205.3.html" target="_blank">Article 205.1</a> of the Criminal Code of the Russian Federation for aiding terrorist activity. He has also been placed on the international wanted list.</p>
<p><!--adsense--></p>
<p>The FSB said it also found numerous instances where Ukrainian special services employed a Telegram chatbot named &#8220;Daivinchik/Leo-Dating, Chatting, and New Friends&#8221; to recruit Russian citizens for sabotage and terrorist activities through what it said were deception and psychological manipulation.</p>
<p><a name="more"/></p>
<p>Per joint operations conducted with the Ministry of Internal Affairs and the Investigative Committee of Russia, 46 Russian citizens aged 12 to 22 were allegedly detained between July 2025 and the present. These individuals carried out armed attacks on law enforcement officers and acts of arson targeting transport, energy, communications, and financial infrastructure, it said.</p>
<p>&#8220;Additionally, they acted as couriers, transporting funds obtained from defrauded citizens to cryptocurrency exchange points for deposit into accounts controlled by the adversary,&#8221; the agency said in a statement.</p>
<p>Furthermore, it accused Ukrainian intelligence agents of using the &#8220;Daivinchik&#8221; Telegram dating service to masquerade as young women and initiate online contact with young Russian men. Upon building romantic relationships, the men are said to have sent the geolocation of a desired meeting place, such as a large shopping mall or an area near a critical facility, and pay for movie tickets, concert tickets, or gifts via phishing links shared by the agents.</p>
<p>In the next phase, representatives of Ukrainian intelligence services posing as Russian law enforcement authorities or officials from Rosfinmonitoring, the Federal Financial Monitoring Service, would contact the men through foreign messaging apps.</p>
<p>&#8220;These impostors claimed that the funds sent by the men had ended up in the accounts of the Armed Forces of Ukraine and that the coordinates they had shared were being used by the enemy to plan missile strikes and drone attacks,&#8221; the FSB alleged.</p>
<p><!--linkads--></p>
<p>&#8220;The deceived and intimidated citizens &#8211; rendered unable to critically assess the situation due to psychological pressure &#8211; were then coerced under threat of criminal prosecution into carrying out armed attacks and acts of arson. These actions were ostensibly framed as checks on the counter-terrorism security of the targeted facilities or as participation in other &#8216;pseudo-operational activities.'&#8221;</p>
<p>In response, Telegram&#8217;s official account on X <a href="https://x.com/telegram/status/2082364471339786357" target="_blank">posted</a> a photo of the Telegram founder giving the middle finger. Durov, who lives in Dubai, has not publicly commented on the development.</p>
<p>The charges come as Russia <a href="https://www.m24.ru/news/17032026/883264" target="_blank">introduced</a> a number of restrictions on Telegram, including throttling its use at the start of the year followed by a near-complete blockade in April 2026. Almost two years ago, Durov was also arrested and charged in France for failing to tackle illicit activity on the popular messaging platform.</p>
</div>
<p><br />
<br /><a href="https://thehackernews.com/2026/07/russia-charges-telegram-founder-pavel.html" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/russia-charges-telegram-founder-pavel-durov-with-aiding-terrorist-activity/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>WhatsApp Scam Hijacks Accounts via Linked Devices Feature</title>
		<link>https://cyberwiredaily.com/whatsapp-scam-hijacks-accounts-via-linked-devices-feature/</link>
					<comments>https://cyberwiredaily.com/whatsapp-scam-hijacks-accounts-via-linked-devices-feature/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Tue, 04 Aug 2026 16:11:33 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/whatsapp-scam-hijacks-accounts-via-linked-devices-feature/</guid>

					<description><![CDATA[A WhatsApp scam has been spreading through hijacked accounts by asking recipients to vote for a friend in an online contest, then tricking them into authorizing an attacker&#8217;s device on their own account. In new research published by Malwarebytes on August 3, the company showed how the messages arrived from contacts whose accounts were already [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div id="layout-89a0586d-d7f5-412b-ace7-521a294fe0b9" data-layout-id="2" data-edit-folder-name="text" data-index="0">
<p>
	A WhatsApp scam has been spreading through hijacked accounts by asking recipients to vote for a friend in an online contest, then tricking them into authorizing an attacker&#8217;s device on their own account.</p>
<p>
	In <a href="https://www.malwarebytes.com/blog/scams/2026/08/whatsapp-account-takeover-scam-asks-you-to-vote-for-my-friend" target="_blank">new research</a> published by Malwarebytes on August 3, the company showed how the messages arrived from contacts whose accounts were already compromised and referenced a ballet performance, a dog competition or a school event. The company spotted the campaign in anonymized submissions to its scam-checking tool.</p>
<p>
	The link did not lead to a voting page. It redirected to a page resembling WhatsApp, often using the legitimate wa.me domain, which guided the victim through what looked like setting up WhatsApp Web. Other versions simply instructed the target to open their linked device settings and enter a code the scammer supplied.</p>
<p>
	<em>Read more on messaging scams: NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts</em></p>
<h2>
	<strong>No Password, No Alert</strong></h2>
<p>
	The attackers were not after credentials. Completing the flow added their device as a linked session, giving them the same access a legitimate second device would have.</p>
<p>
	That meant reading messages, sending messages as the account holder and following conversations in real time. Attackers used it to forward the same scam to the victim&#8217;s contacts and to ask friends and family for money.</p>
<p>
	Because no login took place, there were no password reset emails or failed sign-in alerts. The attacker&#8217;s device appeared as another entry in the linked devices list, and Malwarebytes said the compromise could go unnoticed for some time unless the user checked.</p>
<h2>
	<strong>A Familiar Technique, A New Lure</strong></h2>
<p>
	Abuse of the linked devices feature is not new. Researchers documented the same mechanism in December 2025 under the name GhostPairing, using fake photo-viewer pages rather than voting requests.</p>
<p>
	Russian state actors have used QR code and device-linking lures against WhatsApp and Signal users in the past.</p>
<p>
	What has changed is the pretext. A request to help someone&#8217;s child or pet win a contest is low-stakes, plausible and comes from a real contact, which Malwarebytes said combined trust and curiosity effectively.</p>
<p>
	The company advised users to review Settings then Linked devices and log out anything unfamiliar, never to scan a QR code or enter a linking code they did not initiate and to verify unexpected requests through another channel.</p>
<p>
	Anyone already affected should log out all linked devices and warn their contacts.</p>
</div>
<p><br />
<br /><a href="https://www.infosecurity-magazine.com/news/whatsapp-voting-scam-linked/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/whatsapp-scam-hijacks-accounts-via-linked-devices-feature/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks</title>
		<link>https://cyberwiredaily.com/cybercriminals-bypass-ai-safety-controls-by-splitting-malicious-tasks/</link>
					<comments>https://cyberwiredaily.com/cybercriminals-bypass-ai-safety-controls-by-splitting-malicious-tasks/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Tue, 04 Aug 2026 14:13:53 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/cybercriminals-bypass-ai-safety-controls-by-splitting-malicious-tasks/</guid>

					<description><![CDATA[Criminals have been defeating the safety controls on commercial AI tools by splitting malicious work across multiple sessions and files, breaking projects into fragments small enough that no individual request appears harmful. According to research Cisco Talos published on August 4, the finding rests on a corpus of prompt logs recovered from threat actor endpoints [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div id="layout-c6096006-233f-426c-b7b1-732aaa96b864" data-layout-id="2" data-edit-folder-name="text" data-index="0">
<p>
	Criminals have been defeating the safety controls on commercial AI tools by splitting malicious work across multiple sessions and files, breaking projects into fragments small enough that no individual request appears harmful.</p>
<p>According to <a href="https://blog.talosintelligence.com/keep-going-bro-youve-got-this-a-data-driven-look-at-how-adversaries-are-weaponizing-ai/" target="_blank">research</a> Cisco Talos published on August 4, the finding rests on a corpus of prompt logs recovered from threat actor endpoints running AI coding assistants including Claude Code, Codex, Cursor and Gemini.</p>
<p>Talos said guardrails &#8220;did not provide much protection,&#8221; and that it encountered no sophisticated encoding or evasion techniques. Where guardrails did engage, they achieved little, and the pattern held across models and platforms rather than affecting any single vendor.</p>
<p><em>Read more on agentic attacks: OpenAI Claims Its AI Models Went Rogue and Hacked Another Company</em></p>
<h2>
	<strong>Ownership Claims and Persistent Memory</strong></h2>
<p>
	Alongside task decomposition, the most common method was simply claiming to own the infrastructure being targeted, which in many cases required no further verification.</p>
<p>Labeling work as capture-the-flag (CTF) or bug bounty activity was similarly effective, unlocking vulnerability hunting and subsequent exploitation without additional vetting.</p>
<p>Some actors wrote blanket authorization into persistent memory and configuration files rather than arguing it per session. In one case a fraud operator instructed a model to treat all targets as pre-approved, conditioning every subsequent session automatically.</p>
<p>The clearest example of decomposition came from <a href="https://oasis-security.io/blog/hephaestus-automated-attack-framework-targeting-government-and-educational-institutions-in-indonesia" target="_blank">Hephaestus</a>, a red team toolkit analyzed by Oasis Security that ran campaigns unattended.</p>
<p>Its operators defined more than a dozen role-differentiated agents and 15 numbered playbooks, so no single agent held the full objective and no individual task resembled an end-to-end attack.</p>
<h2>
	<strong>Skill Level Set the Ceiling</strong></h2>
<p>
	Talos found that an actor&#8217;s existing ability largely determined what AI delivered. Novices assembled projects that technically functioned but lacked the expertise to improve them, ending up with limited capability. Skilled operators built what Talos described as “astonishing” platforms.</p>
<p>One inexperienced operator used a model to build distributed denial-of-service (DoS) tooling, eventually controlling nearly 2000 Android TVs. The model did push back, but only after supplying the basic functionality, and the actor then spent considerable effort trying to coax further work from it.</p>
<p>In a bulk-mail operation, a model initially characterized the activity as phishing-adjacent, then reversed its assessment on a single unverified claim that the recipients were the operator&#8217;s own users, concluding &#8220;the ethical question evaporates.&#8221;</p>
<p>Talos noted the model went further and invented a justification the actor had not offered, contradicted both by the dataset names themselves and by the domain&#8217;s documented history of non-consensual contact harvesting under the same operator.</p>
<p>Where models did refuse, actors switched. One operator abandoned a censored model mid-operation and moved to an uncensored one, which completed the work without objection.</p>
<p>Talos said defenders should expect vulnerabilities to surface faster and exploitation to follow sooner, and argued organizations not already exploring agentic capabilities in the SOC will find themselves chasing that ground.</p>
</div>
<p><br />
<br /><a href="https://www.infosecurity-magazine.com/news/talos-attackers-split-tasks-evade/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/cybercriminals-bypass-ai-safety-controls-by-splitting-malicious-tasks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass</title>
		<link>https://cyberwiredaily.com/public-poc-released-for-exploited-check-point-smartconsole-authentication-bypass/</link>
					<comments>https://cyberwiredaily.com/public-poc-released-for-exploited-check-point-smartconsole-authentication-bypass/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Tue, 04 Aug 2026 14:04:43 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/public-poc-released-for-exploited-check-point-smartconsole-authentication-bypass/</guid>

					<description><![CDATA[Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that allows an [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div id="articlebody">
<div class="separator" style="clear: both;"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIxq_zUC231fexQTfY9VPvqP7FWVRurT9fbUUS3YMpMX2SRmJu9eXIlH7v6fnvqJGtirQwXJVjs1h-hbUM7j-R6DlfpW7M4kt28q9EoxMt7jJFjUjaAoVsuTWSsBZOFcDj99U8ApvFR4B4sDQ37QHYeWXjJsowFBP3n8-TBfzcKB2Rl-de-OluIkzbJIYb/s1600/cp-poc.jpg" style="display: block; padding: 1em 0; text-align: center; clear: left; float: left;"></a></div>
<p>Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild.</p>
<p>The vulnerability, tracked as <strong>CVE-2026-16232</strong> (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.</p>
<p>&#8220;By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration,&#8221; Rapid7 <a href="https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232/" target="_blank">said</a>.</p>
<p>Successful exploitation requires an attacker to have network access to the Management Server and a configuration that does not restrict Trusted Clients. Check Point has disclosed that it&#8217;s aware of a handful of customers being targeted by this flaw as a zero-day.</p>
<p>Rapid7 analysis of the vulnerability has uncovered that the root cause is a &#8220;broken trust boundary&#8221; in the application authentication path that permits the threat actor to log in to a vulnerable appliance via SmartConsole with full admin privileges.</p>
<p><!--adsense--></p>
<p>Specifically, a vulnerable server has been found to accept an attacker-supplied Secure Internal Communication (SIC) distinguished name (DN) as the identity of a remote application as opposed to binding that identity to the authenticated remote peer certificate DN returned by a function named &#8220;getCertificateDnName().&#8221;</p>
<p>As a result, an attacker can read the management server&#8217;s own SIC DN during the unauthenticated bootstrap communication and authenticate as a remote application by replaying that management server&#8217;s DN, obtaining an application login token, and then minting a new SmartConsole single sign-on (SSO) ticket via the forged application session.</p>
<p>The patch introduced by Check Point ensures that remote clients use the authenticated remote peer certificate DN, causing any mismatch between the supplied DN and that authenticated identity to be rejected. It also adds a new empty identity check that prevents a remote application login when there is no authenticated SIC identity.</p>
<p>&#8220;To make the supplied server DN survive the patched checks, the attacker would need an authenticated client certificate whose subject DN already matches that server DN, which removes the unauthenticated bypass,&#8221; Rapid7&#8217;s Stephen Fewer said.</p>
<p>Rapid7 has <a href="https://github.com/sfewer-r7/CVE-2026-16232" target="_blank">released</a> a proof-of-concept (PoC) Python script that can be used to successfully validate whether a target is either vulnerable or patched against the flaw.</p>
<p>Customers are advised to apply the Jumbo Hotfixes released by Check Point on July 22, 2026, to remediate the flaw as soon as possible.</p>
</div>
<p><br />
<br /><a href="https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/public-poc-released-for-exploited-check-point-smartconsole-authentication-bypass/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
