<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyberwire Daily</title>
	<atom:link href="https://cyberwiredaily.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://cyberwiredaily.com</link>
	<description></description>
	<lastBuildDate>Wed, 29 Jul 2026 06:04:25 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://cyberwiredaily.com/wp-content/uploads/2025/09/icon-150x150.png</url>
	<title>Cyberwire Daily</title>
	<link>https://cyberwiredaily.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Coca Cola Reveals Subsidiary Fairlife Suffered Data Breach</title>
		<link>https://cyberwiredaily.com/coca-cola-reveals-subsidiary-fairlife-suffered-data-breach/</link>
					<comments>https://cyberwiredaily.com/coca-cola-reveals-subsidiary-fairlife-suffered-data-breach/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Wed, 29 Jul 2026 06:04:25 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/coca-cola-reveals-subsidiary-fairlife-suffered-data-breach/</guid>

					<description><![CDATA[A dairy company owned by Coca-Cola Company suffered data theft as well as production outages following a July ransomware attack, the drinks giant has revealed. Coca-Cola said in a brief statement on July 27 that Chicago-based Fairlife had now “resumed the majority of production” at its four US facilities. However, it added that the incident [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div id="layout-4e269dfc-ab09-4a83-98d0-ed0477d3bf65" data-layout-id="2" data-edit-folder-name="text" data-index="0">
<p>A dairy company owned by Coca-Cola Company suffered data theft as well as production outages following a July ransomware attack, the drinks giant has revealed.</p>
<p>Coca-Cola said in a brief statement on July 27 that Chicago-based Fairlife had now “resumed the majority of production” at its four US facilities.</p>
<p>However, it added that the incident reported earlier in July “involved access by an unauthorized third party to a portion of the company’s systems and taking of certain data,” as well as production outages.</p>
<p>Fairlife makes over $1bn in annual revenue from its ultra-filtered milk and protein shakes.</p>
<p><em>Read more on ransomware: Coca-Cola Investigates Data Breach Claim</em></p>
<p>Coca-Cola explained in an SEC Form 8-K filing that its subsidiary identified unauthorized access on July 16.</p>
<p>Although incident response and business continuity protocols kicked in and external experts were brought in to assist, the firm was forced to temporarily shut down production in the US.</p>
<p>According to screenshots <a href="https://x.com/CyberWatch05/status/2081887788744745391" target="_blank">posted to X</a>, ransomware group Anubis was behind the breach. It claimed to have 671GB of data including HR records, engineering/technical documentation and production data. The group said it has now leaked this trove on its ransomware blog.</p>
<h2>A Long Shelf Life</h2>
<p>Ross Filipek, CISO at Corsica Technologies, argued that the data theft may have a “much longer shelf life” than the production shutdown that impacted the company.</p>
<p>“That information creates options. Criminals could impersonate executives or vendors. They could redirect payments or target employees with convincing phishing messages. Operational details could also reveal which suppliers are essential and where future disruption would create the most pressure,” he suggested.</p>
<p>“The broader lesson is that internal business data shouldn’t be treated as harmless simply because it isn’t customer-facing. Organizations need to know where that information lives. Access should be limited, monitored, and separated so one compromised system doesn’t expose the company’s entire playbook.”</p>
<p>For its part, Coca-Cola played down any long-term impact from the incident.</p>
<p>“Retail availability of Fairlife products has been largely unimpacted, due to the availability of existing inventory. Product quality and safety have not been impacted,” it noted in its statement.</p>
<p>“Based on the information currently available, the company believes the incident has not had, and is not reasonably likely to have, a material impact on the company’s financial condition or results of operations.”</p>
</div>
<p><br />
<br /><a href="https://www.infosecurity-magazine.com/news/coca-cola-subsidiary-fairlife-data/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/coca-cola-reveals-subsidiary-fairlife-suffered-data-breach/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication</title>
		<link>https://cyberwiredaily.com/hackers-exploit-windmill-flaw-to-read-arbitrary-server-files-without-authentication/</link>
					<comments>https://cyberwiredaily.com/hackers-exploit-windmill-flaw-to-read-arbitrary-server-files-without-authentication/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Wed, 29 Jul 2026 06:03:16 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/hackers-exploit-windmill-flaw-to-read-arbitrary-server-files-without-authentication/</guid>

					<description><![CDATA[A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill&#8217;s &#8220;get_log_file&#8221; endpoint (&#8220;/api/w/{workspace}/jobs_u/get_log_file/{filename}&#8221;). &#8220;The filename parameter is concatenated into a file path without sanitization, allowing an attacker to read [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div id="articlebody">
<div class="separator" style="clear: both;"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgnFuvwtbu7JlyR-HJX7Eyz41wIZYMuzDLiZ1XlV2ipWOE-d2aPRZkYZn8nCWJynhewu3iTAR8H15UaKqmeAMkb85_m2NpSjRyaNlp6gTgKwswcVtwzjQ8A6pQXESU-AIwRUf6qUkeVDewHfGovPjgN0lKC2lHBb3dkSJGs3NYhmv5_QawPER0P4xFGpHf/s1600/git.jpg" style="display: block; padding: 1em 0; text-align: center; clear: left; float: left;"></a></div>
<p>A high-severity security flaw impacting open-source developer platform <a href="https://github.com/windmill-labs/windmill" target="_blank">Windmill</a> has come under active exploitation in the wild, per VulnCheck.</p>
<p>The vulnerability in question is <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29059" target="_blank">CVE-2026-29059</a></strong> (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill&#8217;s &#8220;get_log_file&#8221; endpoint (&#8220;/api/w/{workspace}/jobs_u/get_log_file/{filename}&#8221;).</p>
<p>&#8220;The filename parameter is concatenated into a file path without sanitization, allowing an attacker to read arbitrary files on the server using ../ sequences,&#8221; according to an advisory <a href="https://github.com/windmill-labs/windmill/security/advisories/GHSA-24fr-44f8-fqwg" target="_blank">published</a> by Windmill in March 2026.</p>
<p>&#8220;The primary sensitive value exposed by this vulnerability is the SUPERADMIN_SECRET environment variable, readable via /proc/1/environ. When set, this secret can be used as a Bearer token to authenticate as a superadmin and execute arbitrary code through the job preview API.&#8221;</p>
<p>However, it&#8217;s worth noting that SUPERADMIN_SECRET is not set by default, and for standalone Windmill instances without SUPERADMIN_SECRET configured, the impact of the vulnerability is limited to arbitrary file read. The issue has since been addressed in Windmill 1.603.3, released in January 2026, by adding sanitization checks to the filename parameter to prevent directory traversal.</p>
<p>According to VulnCheck, whose security researcher Valentin Lobstein is credited with discovering and reporting the flaw, exploitation efforts have been directed against Windmill&#8217;s &#8220;get_log_file&#8221; endpoint to extract sensitive information from the &#8220;/etc/passwd&#8221; file.</p>
<p>&#8220;We&#8217;ve observed exploits aimed at both direct Windmill endpoints and the Nextcloud proxy path,&#8221; Caitlin Condon, vice president of security research at VulnCheck, <a href="https://www.linkedin.com/feed/update/urn:li:share:7485310719874318336/" target="_blank">said</a> in a post on LinkedIn.</p>
<p>The cybersecurity company said it identified about 170 vulnerable systems exposed across 24 countries.</p>
<p>The disclosure comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) <a href="https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog" target="_blank">added</a> four security flaws to its Known Exploited Vulnerabilities (<a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank">KEV</a>) catalog, including two WordPress bugs tracked as wp2shell (CVE-2026-60137 and CVE-2026-63030), along with a stack-based buffer overflow in DD-WRT (CVE-2021-27137) and an unauthenticated remote code execution issue in Langflow (CVE-2026-0770).</p>
<p>&#8220;wp2shell is one of the most significant WordPress Core security events in recent years,&#8221; Wordfence <a href="https://www.wordfence.com/blog/2026/07/wp2shell-aftermath-the-first-critical-unauthenticated-wordpress-core-rce-in-nearly-a-decade/" target="_blank">said</a>. &#8220;The combination of unauthenticated reachability, no plugin or theme requirement, a large global attack surface, a path to administrator access and code execution, as well as public proof-of-concept exploit availability makes this vulnerability chain unusually serious.&#8221;</p>
<p>Attack data captured by the WordPress security company shows that threat actors are issuing requests to exploit the REST API batch request route-confusion issue and an unauthenticated SQL injection to achieve code execution.</p>
<p>VulnCheck also said it had verified more than two-dozen unique PoC exploits targeting WP2Shell as of July 19, 2026. &#8220;Affected users should update to a fixed version of WordPress as soon as possible, given the overwhelming likelihood that various public exploits and large-scale exploitation will follow the high-profile disclosure,&#8221; it <a href="https://www.vulncheck.com/blog/wp2shell" target="_blank">added</a>.</p>
<p>As for CVE-2026-0770, KEVIntel&#8217;s Ryan Dewhurst told The Hacker News that first in-the-wild attack efforts targeting the flaw were detected against its sensors on June 27, 2026, recording 137 exploitation attempts from 46 unique attacker IP addresses associated with 17 countries since then.</p>
<p>No less than 75 attempts, which account for more than half of the activity, originated from 20 attacker IP addresses during the last seven days. Observed payloads include base command execution checks, attempts to extract the contents of &#8220;/etc/passwd&#8221; or access AWS credentials, environment variable collection, malware downloads using wget or curl, and shell script execution to install second-stage payloads.</p>
<p>&#8220;The activity is not limited to vulnerability checks,&#8221; Dewhurst said. &#8220;While much of it involved commands such as id, whoami and reading /etc/passwd, we also observed payloads attempting to download malware and obtain environment variables, AWS credentials and container metadata.&#8221;</p>
<p>Federal Civilian Executive Branch (FCEB) agencies are advised to remediate the identified flaws by July 24, 2026.</p>
</div>
<p><br />
<br /><a href="https://thehackernews.com/2026/07/hackers-exploit-windmill-flaw-to-read.html" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/hackers-exploit-windmill-flaw-to-read-arbitrary-server-files-without-authentication/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Microsoft Launches Flurry of AI Security Initiatives</title>
		<link>https://cyberwiredaily.com/microsoft-launches-flurry-of-ai-security-initiatives/</link>
					<comments>https://cyberwiredaily.com/microsoft-launches-flurry-of-ai-security-initiatives/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Tue, 28 Jul 2026 22:21:17 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/microsoft-launches-flurry-of-ai-security-initiatives/</guid>

					<description><![CDATA[You need agents to fight agents. At least that’s what David Weston, corporate VP for AI security at Microsoft told his audience during a Microsoft Security launch preview on July 27. During the event, the Redmond-based company announced a flurry of new AI and security products and initiatives. First, Microsoft launched Project Perception, a new [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div id="layout-70944724-754f-4ce3-9eb4-c6cc5515c695" data-layout-id="2" data-edit-folder-name="text" data-index="0">
<p>You need agents to fight agents. At least that’s what David Weston, corporate VP for AI security at Microsoft told his audience during a Microsoft Security launch preview on July 27.</p>
<p>During the event, the Redmond-based company announced a flurry of new AI and security products and initiatives.</p>
<p>First, Microsoft launched <a href="https://blogs.microsoft.com/blog/2026/07/27/rethinking-security-for-the-age-of-ai/" target="_blank">Project Perception</a>, a new agentic security system designed to help cyber defenders continuously identify, evaluate and reduce security risk.</p>
<p>Microsoft’s Perception coordinates three classes of specialized agents that work together to improve security posture over time:</p>
<ul>
<li>Red agents identify potential attack paths and vulnerabilities before they can be exploited</li>
<li>Blue agents investigate findings, apply security context and determine what represents meaningful risk</li>
<li>Green agents take corrective action and strengthen defenses across the environment</li>
</ul>
<p>This is akin to Google’s <a href="https://cloud.google.com/blog/products/identity-security/introducing-google-ai-threat-defense?hl=en" target="_blank">AI Threat Defense</a> platform, powered by Wiz’s Red, Blue and Green agents, released in May 2026.</p>
<p>Speaking at Microsoft’s launch event, Hayete Gallot, executive VP at Microsoft Security, explained that the global reach of Microsoft means the company see about 100 trillion signals a day.</p>
<p>“We sit at your identity, data, cloud, code and even AI level. If you add our security research, threat intelligence and red teaming efforts, you end up with even more signals,” she said.</p>
<p>“However, if you were to apply an agent to that raw data, it would be very slow and you would get terrible results. That’s why we are connecting and correlating all those signals so we can provide a ‘security context,’ which is organized efficiently for our agents.”</p>
<p>Weston added that Project Perception will be multi-model and demonstrated to the audience several “playbooks” based on a set of operations a security operations center (SOC) could face.</p>
<p>“We believe fundamentally you need agents to fight agents,” he said.</p>
<p>Perception will be available in Preview mode for all Microsoft customers from August 3.</p>
<p><em>Read more: Google Cloud&#8217;s New CISO Chris Betz on Integrating AI in Cyber Defenses</em></p>
<h2><strong>Microsoft’s First Cyber-Focused AI Model: MAI-Cyber-1-Flash </strong></h2>
<p>Gallot also announced the launch of a new Microsoft-made generative AI model specifically designed for cybersecurity use cases, especially software vulnerability analysis.</p>
<p>Developed by Microsoft AI (MAI), the model, named <a href="https://microsoft.ai/news/introducing-mai-cyber-1-flash-inside-mdash/" target="_blank">MAI-Cyber-1-Flash</a>, is based on the company’s internally developed MAI-Thinking-1 reasoning model. It has been integrated into Microsoft Security’s multi-model agentic scanning harness (MDASH).</p>
<p>According to Mustafa Suleyman, CEO at Microsoft AI, the system is further enhanced by GPT-5.4 and has outperformed competing solutions from Anthropic, OpenAI and Google in CyberGym benchmarking.</p>
<p>The MAI-Cyber-1-Flash and GPT4.5 enhancement have achieved a 95.95% success rate according to the CyberGym benchmark.</p>
<p>By comparison, OpenAI’s GPT-5.5 Cyber scored 85.6%, GPT-5.6 Sol achieved 83.6%, Anthropic’s Mythos recorded 83.8%, and Google’s Gemini 3.5 Flash Cyber reached 83.2%.</p>
</div>
<div id="layout-65ab2a25-259e-45e0-b430-47b5a7107828" data-layout-id="2" data-edit-folder-name="text" data-index="2">
<p>Within MDASH, MAI-Cyber-1-Flash handles approximately 90% of queries, identifying and patching software vulnerabilities before verifying that the fixes work. The remaining 10% of more complex tasks are passed to the larger GPT-5.4 model.</p>
<p>Suleyman said GPT-5.4 is around ten times larger than MAI-Cyber-1-Flash and can resolve the queries handed off to it.</p>
<p>He claimed that the collaboration between the two models delivers stronger performance than competing systems while costing roughly 50% less.</p>
<h2><strong>From DARPA AIxCC Winners to Microsoft Security FORGE Lab</strong></h2>
<p>The tech firm also announced the launch of the Microsoft Security Frontier Offensive Research and Generative Exploration (FORGE) Lab.</p>
<p>The lab will be led by Team Atlanta,, the group of cybersecurity researchers that won the US Defense Advanced Research Projects Agency’s (DARPA) AI Cyber Challenge (AIxCC) at DEFCON in the summer 2025, after Microsoft hired the team to head the new initiative, Gallot said.</p>
<p>The FORGE Lab will be headed by Taesoo Kim, who also led Team Atlanta.</p>
<p>During the Microsoft launch event, Kim described the DARPA competition as a “real world AI cyber challenge” and said the winning teams combined cutting‑edge research with practical engineering.</p>
<p>He reported that DARPA’s process encouraged teams to “strike the balance between engineering and high‑risk, high‑return research throughout the competition,” and that Microsoft provided the ideal environment to translate those advances into production given its scale across Azure and GitHub.</p>
<p>Kim added that the lab’s mission is to “advance the frontier of offensive security research and accelerate the evolution from AI‑assisted vulnerability discovery to autonomous security research,” positioning FORGE as the bridge from DARPA‑level breakthroughs to enterprise defenses.</p>
<h2><strong>Launch of the External Red Team Alliance</strong></h2>
<p>Finally, Microsoft announced the <a href="https://www.microsoft.com/en-us/security/blog/2026/07/27/enhancing-ai-security-through-global-ai-red-teaming/" target="_blank">External Red Team Alliance</a> (EXTRA), a two-pronged initiative designed to broaden the scope of AI safety research.</p>
<p>The first piece involves Microsoft&#8217;s in-house AI red team distributing &#8220;unrestricted gifts&#8221; to 18 university labs spread across six continents, all in support of AI safety-related research.</p>
<p>Ram Shankar Siva Kumar, Microsoft&#8217;s head of the AI red team, explained in a blog post published on July 17 that the funding comes with no strings attached because the goal isn&#8217;t to steer research toward specific products or predetermined outcomes.</p>
<p>He noted that while some of these universities are digging into the cybersecurity risks posed by AI systems themselves – looking at how such models might be exploited, manipulated or misused in real-world settings – others are tackling the flip side and explore how AI can actually be leveraged to strengthen defenses and enhance cyber operations.</p>
<p>The initiative&#8217;s second component focuses on assembling a distributed network of specialized experts who can contribute to red teaming efforts in niche areas.</p>
<p>According to Siva Kumar, this network will draw on researchers, practitioners, and regional specialists with knowledge of particular attack methods, languages, cultural nuances, or technical fields, areas where Microsoft&#8217;s internal teams may lack complete coverage on their own.</p>
</div>
<div id="layout-9147c7cd-7ca0-41fa-9ea9-020d15c0e00f" data-layout-id="2" data-edit-folder-name="text" data-index="3">
<p><em>Image credits: Tada Images / Mijansk786 / Shutterstock.com</em></p>
</div>
<p><br />
<br /><a href="https://www.infosecurity-magazine.com/news/microsoft-ai-security-initiatives/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/microsoft-launches-flurry-of-ai-security-initiatives/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The Fastest Path to AI Adoption Runs Through Security</title>
		<link>https://cyberwiredaily.com/the-fastest-path-to-ai-adoption-runs-through-security/</link>
					<comments>https://cyberwiredaily.com/the-fastest-path-to-ai-adoption-runs-through-security/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Tue, 28 Jul 2026 22:19:49 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/the-fastest-path-to-ai-adoption-runs-through-security/</guid>

					<description><![CDATA[Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, employees the tools they want, and CISOs the strategic influence they have earned. According to McKinsey&#8217;s State of AI report, 76 percent of employees now [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div id="articlebody">
<div class="separator" style="clear: both;"><a href="https://www.adaptivesecurity.com/resources/checklists/ai-governance-checklist-for-security-leaders" style="clear: left; cursor: pointer; display: block; float: left; padding: 1em 0px; text-align: center;"></a></div>
<p><em>Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, employees the tools they want, and CISOs the strategic influence they have earned.</em></p>
<p>According to McKinsey&#8217;s State of AI report, 76 percent of employees now use AI in some capacity at work, up from 55 percent the year before. Writing assistants, coding copilots, meeting summarizers, AI-powered research tools: they are woven into daily work. Most were never reviewed by security.</p>
<p>The conventional response is restriction. An application appears, the security team blocks it, employees find a workaround within days, and the cycle repeats. It comes down to speed: the approval path moves slower than the pace of AI releases. When the official route takes six weeks, and a workaround takes six minutes, most employees will choose the workaround.</p>
<p>Technology gets adopted because people find it useful. Governance that ignores that human behavior will always be routed around. The cycle of blocking and workarounds happens when policy is designed without accounting for the people it governs. The <a href="https://www.adaptivesecurity.com/resources/checklists/ai-governance-checklist-for-security-leaders" target="_blank">security leaders breaking that cycle</a> have already changed the path.</p>
<h2><strong>Governance as an Enablement Function</strong></h2>
<p>When a business unit wants to deploy a new AI capability, the first call goes to security. That happens because security proved it could move fast and add value. The teams earning that reputation built AI governance around one idea: give employees a clear, fast path to access approved tools, request new ones, and understand why the guidelines exist.</p>
<p><a name="more"/></p>
<p>That reputation compounds. CISOs who build it find themselves in strategy conversations at the planning stage, before decisions are locked, where their input actually shapes the outcome.</p>
<p>The foundation is a current inventory: which AI tools are running, who relies on them, and what data each one can access. OAuth audits of connected apps and browser-native monitoring build that picture quickly. Without it, governance is guesswork.</p>
<h2><strong>The Policy, Reasoning, and Speed</strong></h2>
<ul>
<li><a href="https://www.adaptivesecurity.com/resources/checklists/generative-ai-governance-policy-template" target="_blank">An effective AI acceptable use policy</a> does four things: lists approved tools with a clear path to access them, defines which data categories stay out of AI tools entirely, confirms training opt-out status for every approved tool, and gives employees a process for requesting new ones with a turnaround time.</li>
<li>The element that gets skipped most often is the reasoning. An employee who understands why connecting a productivity tool to Google Workspace can hand an entire shared drive to a third-party vendor carries that judgment into every future decision. That reasoning is what converts a rule employees read once into a habit they apply for years.</li>
<li>Publish the approved list. Set a turnaround time and keep it. Organizations that do this see shadow AI usage decline on its own. Employees with a fast official path have little reason to find another one.</li>
</ul>
<h2><strong>The Seat at the Table</strong></h2>
<p>The security teams earning a seat at the strategy table are the ones who approached governance as a design problem. They started by asking how to make the secure path the one employees want to use, rather than focusing on how to control the AI tools they were already using.</p>
<p>When you build from that understanding, you end up with something rules alone cannot produce. Employees use the system willingly, and the organization starts to see security as the team that understands both people and risk.</p>
<p>AI adoption is accelerating regardless of what any governance effort does. The security leaders keeping pace are the ones who started with the right question.</p>
<p><em>Adaptive Security&#8217;s AI Governance product gives security teams real-time visibility into every AI tool and shadow app running across their organization, with automated policies and just-in-time employee coaching built in. Learn more at <a href="https://www.adaptivesecurity.com" target="_blank">adaptivesecurity.com</a>.</em></p>
</div>
<p><br />
<br /><a href="https://thehackernews.com/2026/07/the-fastest-path-to-ai-adoption-runs.html" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/the-fastest-path-to-ai-adoption-runs-through-security/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched</title>
		<link>https://cyberwiredaily.com/ai-assisted-bug-hunt-uncovers-linux-kernel-0-day-in-net-sched/</link>
					<comments>https://cyberwiredaily.com/ai-assisted-bug-hunt-uncovers-linux-kernel-0-day-in-net-sched/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Tue, 28 Jul 2026 18:10:55 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/ai-assisted-bug-hunt-uncovers-linux-kernel-0-day-in-net-sched/</guid>

					<description><![CDATA[A years-old Linux kernel flaw allowing local privilege escalation to root has been disclosed after AI-assisted research uncovered a race condition in net/sched. In new research published July 27, Lee Jia Jie of Singapore offensive security firm STAR Labs said he found the use-after-free during an internship, his first Linux kernel work. It is tracked [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div id="layout-0520bac4-5ce1-4da8-9318-6c7eeee0b533" data-layout-id="2" data-edit-folder-name="text" data-index="0">
<p>A years-old Linux kernel flaw allowing local privilege escalation to root has been disclosed after AI-assisted research uncovered a race condition in net/sched.</p>
<p>In<a href="https://starlabs.sg/blog/2026/07-when-ai-makes-0-days-feel-like-n-days/" style="text-decoration:none;" target="_blank"> new research</a> published July 27, Lee Jia Jie of Singapore offensive security firm STAR Labs said he found the use-after-free during an internship, his first Linux kernel work.</p>
<p>It is tracked as CVE-2026-53264.</p>
<h2><strong>Race Condition Exposes Freed Kernel Object</strong></h2>
<p>Net/sched controls when and how network packets are transmitted. The flaw stems from mismatched locking around a shared data structure: one function reads entries under a Read-Copy-Update (RCU) lock, while another path can free an entry without waiting for the RCU grace period.</p>
<p>That gap creates a race window in which the kernel may continue using an object after its memory has been released. Successful abuse could give a local unprivileged user root access, but requires unprivileged user namespaces and two supporting kernel options. Testing targeted a CentOS Stream 9 desktop.</p>
<p><em>Read more on Linux kernel flaws: CrackArmor Flaws Expose Linux Systems to Privilege Escalation</em></p>
<p>Jia Jie used AI to identify the bug, produce a crash proof and improve the reliability of triggering the race. Separately, optimization reduced the time required to hit the condition from more than 15 minutes to about five seconds.</p>
<p>The result follows previous Google OSS-Fuzz work using AI to expose hidden flaws in open-source projects.</p>
<h2><strong>Competition Miss and Wider Kernel Findings</strong></h2>
<p>The exploit was prepared for TyphoonPwn 2026&#8217;s Linux local privilege escalation category, which offered prizes of $70,000, $35,000 and $17,500. Jia Jie drew position eight of 11, but the category closed after three winners, so his entry was never demonstrated.</p>
<p>KyleBot, an AI system, had independently reported the same bug two days before TyphoonPwn 2026. Jia Jie said the defect had existed for two to three years, describing this as evidence that AI can make zero-day work resemble n-day analysis.</p>
<p>He also reported two exploitable flaws in the perf events subsystem. One was assigned CVE-2026-64300; the issues were reachable on Intel bare-metal systems under a permissive performance-monitoring setting, affecting RHEL-based and Arch systems rather than Debian-based distributions, and were mainly relevant to desktop Linux.</p>
<p>Jia Jie said AI accelerated bug hunting but still showed blind spots and reasoning failures. He concluded that detailed subsystem knowledge remains important for finding weaknesses automated systems miss.</p>
<p>CVE-2026-53264 has been patched upstream. The fix defers freeing the affected object until after the RCU grace period, removing the use-after-free window. Linux users and administrators should obtain fixed kernels through their distribution&#8217;s security update channels.</p>
</div>
<p><br />
<br /><a href="https://www.infosecurity-magazine.com/news/ai-linux-kernel-zero-day-net-sched/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/ai-assisted-bug-hunt-uncovers-linux-kernel-0-day-in-net-sched/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark</title>
		<link>https://cyberwiredaily.com/openai-says-its-ai-models-escaped-sandbox-targeted-hugging-face-to-cheat-benchmark/</link>
					<comments>https://cyberwiredaily.com/openai-says-its-ai-models-escaped-sandbox-targeted-hugging-face-to-cheat-benchmark/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Tue, 28 Jul 2026 18:09:45 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/openai-says-its-ai-models-escaped-sandbox-targeted-hugging-face-to-cheat-benchmark/</guid>

					<description><![CDATA[OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an &#8220;even more capable pre-release model,&#8221; was behind the security incident that targeted Hugging Face&#8217;s production infrastructure last week. The AI company said the models were operating with &#8220;reduced cyber refusals for evaluation purposes&#8221; that might otherwise limit their [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div id="articlebody">
<div class="separator" style="clear: both;"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQ67gB4XtAR4QxYNABuJhWfBIduFUT7TMSA0K2c9TXbTTwqdfMJwBb5busuLeMPlrljP3xuTUrhbMQxwctepF9oPtgJkqo-RAxN86O2t25jcjIHfs5A8SVvG3Y8WJJa4pqAp0UiTBzAPZtzSaNcNceJokt7ATaoq7GTXYJjbsxaQfTEs4cwdaOz4Fg72nG/s1600/openai.jpg" style="clear: left; display: block; float: left; padding: 1em 0px; text-align: center;"></a></div>
<p>OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an &#8220;even more capable pre-release model,&#8221; was behind the security incident that targeted Hugging Face&#8217;s production infrastructure last week.</p>
<p>The AI company <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/" target="_blank">said</a> the models were operating with &#8220;reduced cyber refusals for evaluation purposes&#8221; that might otherwise limit their ability to conduct cyber attacks, adding it expects such incidents to &#8220;become more commonplace with the proliferation of increasingly cyber-capable models.&#8221;</p>
<p>Incidents like this may become more common. <span data-push-label="AI Security Incidents" data-push-topic="ai_security_incident:c, ai security:t, artificial intelligence:i">Subscribe, and we’ll alert you</span> only when another major AI security story breaks.</p>
<p>Describing it as an &#8220;unprecedented cyber incident&#8221; and one involving state-of-the-art cyber capabilities, OpenAI said it intends to conduct a thorough investigation in partnership with Hugging Face to get to the bottom of the matter.</p>
<p>As part of an internal evaluation, the models are said to have identified and chained vulnerabilities across OpenAI&#8217;s research environment and Hugging Face&#8217;s production infrastructure to find solutions for the <a href="https://www.cybergym.io/exploitgym/" target="_blank">ExploitGym</a> benchmark.</p>
<p><!--adsense--></p>
<p>Evidence unearthed by OpenAI suggests the models&#8217; hyperfocus caused them to go to &#8220;extreme lengths&#8221; to achieve the goal at any cost, even managing to break out of its highly isolated sandboxed environment and obtain open internet access by discovering and exploiting a zero-day vulnerability in an unspecified vendor&#8217;s software, which acts as a proxy and cache for package registries. This required spending a &#8220;substantial amount of inference compute.&#8221;</p>
<p><a name="more"/></p>
<p>&#8220;With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with internet access,&#8221; the company explained.</p>
<p>Surmounting the internet access blockade, the models subsequently inferred Hugging Face as the repository that hosted models, datasets, and solutions for ExploitGym, which, in turn, caused them to look for ways to gain access to secret information that it could use to cheat the benchmark.</p>
<p>At one point, the models strung together several attack vectors, including using stolen credentials and zero-day vulnerabilities, to find a remote code execution path on the Hugging Face servers.</p>
<p>As part of incident response efforts, OpenAI said it&#8217;s implementing strict controls in infrastructure configuration, responsibly disclosed the zero-day flaw in the third-party software, adding Hugging Face to its trusted access program to improve their defenses, and incorporating stronger guardrails around future training and evaluations.</p>
<p><!--linkads--></p>
<p>&#8220;This incident points to the need to further strengthen our model&#8217;s alignment, cyber protections during evaluation time, and monitoring during internal testing,&#8221; OpenAI said.</p>
<p>The development comes as the company also <a href="https://openai.com/index/safety-alignment-long-horizon-models/" target="_blank">revealed</a> that long-running models, while taking on complex, open-ended problems, can open the door to taking unwanted actions, such as finding weaknesses in the operational environment, in pursuit of their objective through repeated attempts over extended periods of time.</p>
<p>&#8220;It also shows how a model that operates effectively over long time horizons can learn the blind spots of an approval system and work around it to achieve its goals,&#8221; OpenAI said. &#8220;Long-horizon safety requires not only asking &#8216;is this action allowed?&#8217; but also &#8216;what outcome is this sequence of actions working toward?.'&#8221;</p>
</div>
<p><br />
<br /><a href="https://thehackernews.com/2026/07/openai-says-its-own-ai-models-escaped.html" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/openai-says-its-ai-models-escaped-sandbox-targeted-hugging-face-to-cheat-benchmark/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard</title>
		<link>https://cyberwiredaily.com/bugs-in-hugging-face-diffusers-bypass-custom-code-safeguard/</link>
					<comments>https://cyberwiredaily.com/bugs-in-hugging-face-diffusers-bypass-custom-code-safeguard/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Tue, 28 Jul 2026 15:47:21 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/bugs-in-hugging-face-diffusers-bypass-custom-code-safeguard/</guid>

					<description><![CDATA[Three high-severity flaws in vulnerable versions of Hugging Face’s diffusers library let crafted model repositories silently execute arbitrary code during affected loading flows, bypassing the safeguard built to prevent exactly that. According to research from threat exposure management firm Zafran Security published on July 27, the flaws defeated trust_remote_code, the check meant to stop unreviewed code [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div id="layout-ed4523c4-5577-442f-9cf1-3e8186bc0d00" data-layout-id="2" data-edit-folder-name="text" data-index="0">
<p>Three high-severity flaws in vulnerable versions of Hugging Face’s diffusers library let crafted model repositories silently execute arbitrary code during affected loading flows, bypassing the safeguard built to prevent exactly that.</p>
<p>According to<a href="https://www.zafran.io/resources/facehugger-vulnerabilities-in-hugging-face-diffusers-open-door-to-supply-chain-attacks-on-enterprise-ai" style="text-decoration:none;" target="_blank"> research</a> from threat exposure management firm Zafran Security published on July 27, the flaws defeated trust_remote_code, the check meant to stop unreviewed code running when a model is fetched.</p>
<p>The library draws roughly seven million downloads a month, close to 200,000 a day, sitting inside production AI pipelines, CI/CD systems and container images.</p>
<p>The findings land days after OpenAI&#8217;s frontier models breached Hugging Face&#8217;s production infrastructure, logging over 17,000 events across a weekend. That intrusion exploited dataset-processing paths; these target model loading. Zafran said both point to the same weakness: AI repository content is treated as passive data when it can quietly cross into executable code.</p>
<p>Commenting on the OpenAI incident, Crystal Morin, cybersecurity strategist at AI cloud security firm Sysdig, said what caught the Hugging Face intrusion was &#8220;behavioral anomaly detection at the infrastructure level,&#8221; not perimeter defenses. Teams should verify they can spot a privileged container spinning up from an application process, she said, and back up model weights as rigorously as databases.</p>
<p><em>Read more on Hugging Face threats: Malicious Hugging Face Repository Typosquats OpenAI</em></p>
<h2><strong>Check Separated from Code Load</strong></h2>
<p>All three flaws shared a root cause: the trust check runs at a different point from the actual code load. When a model is fetched, the check ran against the configuration file in the first of two sequential, non-atomic HTTP requests, so anything that makes the loader see custom code the check did not created a bypass.</p>
<p>CVE-2026-44827 (CVSS 8.8) exploited a string-formatting quirk. With no custom pipeline argument supplied, the loader built the filename None.py and checked whether it existed in the repository. The check used a different code path and did not flag None.py, so a repository containing that file passes while executing attacker code on load.</p>
<p>CVE-2026-45804 (CVSS 7.5) exploited the gap between the two requests. Modifying the configuration to reference custom code after the first request completed but before the second ran executes the injected code. Zafran&#8217;s testing put the window at around 0.3 seconds, and the exploit required an uncached first download. Still, the firm noted a popular repository could achieve statistical success by briefly pushing a malicious config and reverting it.</p>
<h2><strong>Patched in May</strong></h2>
<p>Three further variants under CVE-2026-44513 (CVSS 8.8) shared the root cause, including one bypassing the check entirely when loading from a local snapshot. Zafran also disclosed a parallel flaw in Hugging Face&#8217;s transformers package, which it said the security team has acknowledged.</p>
<p>Jeremy Powell, CISO at log management vendor Sumo Logic, said the defenses that mattered now were &#8220;the unglamorous ones&#8221;: egress control, segmentation and credential hygiene, alongside detection operating at the speed of the attack.</p>
<p>Hugging Face released diffusers 0.38.0 on May 1, moving the security checks to the dynamic-module loading step and closing the identified variants. Zafran said it reported the first two flaws on March 19, and CVEs were published in May.</p>
</div>
<p><br />
<br /><a href="https://www.infosecurity-magazine.com/news/hugging-face-diffusers-trust/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/bugs-in-hugging-face-diffusers-bypass-custom-code-safeguard/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Phishing Dominates as Initial Entry Method for Cyber-Attacks</title>
		<link>https://cyberwiredaily.com/phishing-dominates-as-initial-entry-method-for-cyber-attacks/</link>
					<comments>https://cyberwiredaily.com/phishing-dominates-as-initial-entry-method-for-cyber-attacks/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Tue, 28 Jul 2026 14:09:03 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/phishing-dominates-as-initial-entry-method-for-cyber-attacks/</guid>

					<description><![CDATA[Phishing attacks were the dominant method of initial entry for cyber incidents that required remediation during the last quarter, analysis of attacks by the incident responders who were called in to deal with them has revealed. This as campaigns have become more innovative around evading detection. According to the Cisco Talos Incident Response Trends report [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div id="layout-c8b53d01-1040-46a7-8c9c-b8a36e48b252" data-layout-id="2" data-edit-folder-name="text" data-index="0">
<p>Phishing attacks were the dominant method of initial entry for cyber incidents that required remediation during the last quarter, analysis of attacks by the incident responders who were called in to deal with them has revealed.</p>
<p>This as campaigns have become more innovative around evading detection.</p>
<p>According to the <em>Cisco Talos Incident Response Trends</em> report for March to June 2026, <a href="https://blog.talosintelligence.com/ir-trends-q2-2026/">published on July 28</a>, phishing accounted for the initial attack vector in just over half of incidents investigated.</p>
<p>This represented a significant rise compared with the previous quarter, when Cisco Talos reported that <a href="https://www.infosecurityeurope.com/en-gb/blog/threat-vectors/tackle-evolving-email-based-attacks.html">phishing attacks</a> represented the initial entry point for a third of incidents they investigated.</p>
<p>Other top observed initial access vectors included exploitation of public-facing applications and drive-by compromise attacks, which happen when users visit compromised websites designed to deliver malicious code to victims.</p>
<p>The rise in phishing coincides with a period which saw attackers experiment with new tools and techniques to help the attacks <a href="https://www.infosecurityeurope.com/en-gb/blog/threat-vectors/hacking-your-brain-top-13-social-engineering-techniques.html">socially engineer victims</a>, while also evading the cybersecurity protections designed to detect against malicious intrusions.</p>
<p>An example of this, as detailed by researchers, was a QR code phishing campaign which targeted organizations in an effort to harvest login credentials and further propagate the attacks by automatically targeting the victims’ contacts too.</p>
<p>The campaign, which is described as persistent and was ongoing as of late June 2026, uses auto-generated victim-tailored PDF documents which contain QR codes that direct victims to adversary-controlled Microsoft 365 credential harvesting pages.</p>
<p>Attributed by Cisco Talos to a threat actor they dubbed UAT-11764, the campaign uses two methods to help bypass protections.</p>
<p>First, the QR codes evade detections used by many traditional email gateways to identify potentially malicious behavior. Second, the credential harvesting pages are hosted on trusted cloud platforms, something which might not be flagged by cybersecurity solutions.</p>
<p>Once the credentials had been successfully stolen, in addition to accessing the victim’s inbox, the attacks conducted various post-compromise actions including creating email inbox rules for defense evasion, as well as using the compromised account to send further phishing emails.</p>
<p>“By weaponizing existing, trusted infrastructure like SharePoint and Microsoft 365, UAT-11764 can bypass many standard email security gateways,” the paper warned.</p>
<p>“As such, network defenders should implement policies that block or flag emails containing QR codes within PDF attachments, enforce phishing-resistant multi-factor authentication on Microsoft 365 accounts, and monitor for suspicious inbox rule creation and anomalous SharePoint file staging as indicators of post-compromise activity.”</p>
<h2><strong>Phishing-as-a-Service Kits With Expanded Capabilities</strong></h2>
<p>The report also noted phishing-as-a-service (PhaaS) kits are becoming more complex and powerful, providing cybercriminal users with a whole suite of tools designed to make attacks more effective.</p>
<p>This ranged from toolkits to secretly bypass MFA through the OAuth device authorization flow rather than stealing passwords, to services which provide users with a comprehensive post-compromise toolkit to help the attacker meet their goals, such as searching for specific information in emails with keyboards.</p>
<p>Capabilities observed while investigating incidents during the period included capabilities including automated token management, persistent access through Primary Refresh Tokens (PRTs), OneDrive and SharePoint administration, geo-dynamic templates, inbox rule manipulation, cross-account keyword monitoring, and collaborative token sharing.</p>
<p>Researchers also identified advanced anti-analysis techniques, including layered evasion mechanisms and encrypted client-side payloads.</p>
<p>According to the report, techniques like this highlight “the increasing sophistication of modern PhaaS platforms”</p>
<p>To help protect networks and users against phishing attacks and other cyber threats, Cisco Talos offered the following advice:</p>
<ul>
<li>Implement properly configured, phishing-resistant MFA and tighten authentication controls</li>
<li>Configure centralized logging with adequate retention across the environment</li>
<li>Conduct robust patch management and reduce exposed infrastructure</li>
<li>Enforce strict outbound email thresholds to disrupt attack propagation</li>
</ul>
</div>
<p><br />
<br /><a href="https://www.infosecurity-magazine.com/news/phishing-dominates-initial-entry/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/phishing-dominates-as-initial-entry-method-for-cyber-attacks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA</title>
		<link>https://cyberwiredaily.com/police-dismantle-kratos-phishing-kit-built-to-steal-microsoft-365-sessions-and-bypass-mfa/</link>
					<comments>https://cyberwiredaily.com/police-dismantle-kratos-phishing-kit-built-to-steal-microsoft-365-sessions-and-bypass-mfa/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Tue, 28 Jul 2026 14:06:54 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/police-dismantle-kratos-phishing-kit-built-to-steal-microsoft-365-sessions-and-bypass-mfa/</guid>

					<description><![CDATA[German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world&#8217;s most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it. In a joint announcement on Monday, the Frankfurt public prosecutor&#8217;s cybercrime unit (ZIT) and Germany&#8217;s [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div id="articlebody">
<div class="separator" style="clear: both;"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgjOaY5kPe-g7dmQXqM_VwJIUOZk8mqgDII9sHVnZgWraV6lnXp9Pu6d664E6wSS82UCkvOd7MkPhzJBnbIKwJO9SLjHaVADbVE0zaSYhZJsHeBkBIh3Y9edJnmW4Ck1ndx5OwkkA5jJMo7gP6ocN_61sO7mOCACXBvzompiLGwnZCRkn2TkaXL6Ay94Fg/s1600/phishkit.jpg" style="display: block; padding: 1em 0; text-align: center; clear: left; float: left;"></a></div>
<p>German and US law enforcement have taken down the core infrastructure of <strong>Kratos</strong>, described by German investigators as one of the world&#8217;s most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it.</p>
<p>In a joint <a href="https://www.bka.de/SharedDocs/Kurzmeldungen/DE/Kurzmeldungen/260720_Schlag_gegen_Phishing_Gruppierung_Kratos.html" target="_blank">announcement</a> on Monday, the Frankfurt public prosecutor&#8217;s cybercrime unit (ZIT) and Germany&#8217;s Federal Criminal Police Office (BKA) said they pulled more than 200 servers offline. Investigators estimate roughly 1,800 paying customers used Kratos to run about 15,000 phishing campaigns a month.</p>
<p>Kratos harvested more than passwords. The kit was designed to steal the session cookie along with the login, and that cookie is enough to walk past two-factor authentication into the account as the user, the BKA said.</p>
<p>ANY.RUN, which <a href="https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/" target="_blank">reverse-engineered the kit</a>, found operators could pick one of two modes: a plain PHP page that only harvests credentials, or a Node.js reverse proxy designed to relay the login to Microsoft in real time and capture the resulting session. That second mode is the adversary-in-the-middle technique that has made ordinary MFA a much weaker backstop than it looks.</p>
<p><!--adsense--></p>
<p>The operation ran like a franchise, with customers the BKA called franchisees. They paid in cryptocurrency and signed up through a dedicated website and a Telegram shop to manage their accounts and organize campaigns, so even low-skill actors could point a working AiTM kit at a target.</p>
<p><a name="more"/></p>
<p>The authorities put the number of victims since late 2024 in the hundreds of thousands, spread across more than 30 countries and concentrated in Europe and the United States. They estimate the operators earned more than 300,000 euros since 2024, and that each campaign could hit several thousand recipients.</p>
<p>Kratos was already being tracked. <a href="https://www.microsoft.com/en-us/security/blog/2026/03/19/when-tax-season-becomes-cyberattack-season-phishing-and-malware-campaigns-using-tax-related-lures/" target="_blank">Microsoft Threat Intelligence</a> identifies the same kit as <strong>SneakyLog</strong>, a phishing-as-a-service platform it says has run credential-and-2FA theft against Microsoft 365 since at least early 2025, and it caught one campaign in the act.</p>
<p>On February 10, operators sent tax-themed emails to about 100 organizations, mostly in the US, across manufacturing, retail, and healthcare, each carrying a W-2 document with a QR code personalized to the recipient that led to a fake Microsoft 365 login.</p>
<p>Stolen Microsoft logins are rarely the end of the line. The BKA said the stolen credentials could be used for further phishing, sold to other criminals, or turned into a foothold inside companies by spreading through their Microsoft 365 environments, the familiar path from one phished inbox to business email compromise.</p>
<p>Carsten Meywirth, who heads the BKA&#8217;s cybercrime division, said the operation shows &#8220;that even highly professional phishing infrastructures can be effectively combated.&#8221; The ZIT&#8217;s Benjamin Krause framed it as proof of the office&#8217;s &#8220;disruptive&#8221; approach of dismantling a criminal service outright rather than only charging the people behind it.</p>
<p><!--linkads--></p>
<p>Microsoft is notifying users caught in the campaigns. For anyone Microsoft is notifying, the fix depends on how they were hit. Where the kit only harvested credentials, a password reset and an MFA check cover it. Where its reverse-proxy mode lifted a live session, that session survives the reset, so it has to be revoked, with high-value accounts moved to phishing-resistant sign-in.</p>
<p>Defenders hunting for exposure can look for the kit&#8217;s tell: ANY.RUN found its login pages almost always load the paired assets barr.svg and lg.svg, then POST stolen credentials to endpoints like next.php or save.php. It rates that pairing at 90% recall with near-zero false positives.</p>
<p>For now, the servers are offline and, the BKA says, Kratos-powered campaigns cannot continue. What the takedown did not touch is the roughly 1,800 customers or the kit code they already hold. ANY.RUN found Kratos running on disposable domains, compromised WordPress sites, and hosting shared with other adversary-in-the-middle kits, the kind of setup that reappears under a new name once the servers go down.</p>
</div>
<p><br />
<br /><a href="https://thehackernews.com/2026/07/police-dismantle-kratos-phishing-kit.html" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/police-dismantle-kratos-phishing-kit-built-to-steal-microsoft-365-sessions-and-bypass-mfa/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>NVIDIA’s Open Security AI Alliance Is Missing Some Big Names</title>
		<link>https://cyberwiredaily.com/nvidias-open-security-ai-alliance-is-missing-some-big-names/</link>
					<comments>https://cyberwiredaily.com/nvidias-open-security-ai-alliance-is-missing-some-big-names/#respond</comments>
		
		<dc:creator><![CDATA[Team-CWD]]></dc:creator>
		<pubDate>Tue, 28 Jul 2026 10:04:44 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://cyberwiredaily.com/nvidias-open-security-ai-alliance-is-missing-some-big-names/</guid>

					<description><![CDATA[NVIDIA has assembled nearly 40 technology companies behind a new initiative to build open source security tools for AI, although the coalition launches without participation from several of the industry&#8217;s most influential AI developers. Announced on July 27, the Open Secure AI Alliance members including Adobe, Cisco, Microsoft, CloudStrike, Space X, SAP and the Linux [...]]]></description>
										<content:encoded><![CDATA[<p> <br />
</p>
<div id="layout-594ce048-5a42-47a9-b11a-f58fbe72d98e" data-layout-id="2" data-edit-folder-name="text" data-index="0">
<p>NVIDIA has assembled nearly 40 technology companies behind a new initiative to build open source security tools for AI, although the coalition launches without participation from several of the industry&#8217;s most influential AI developers.</p>
<p>Announced on July 27, the Open Secure AI Alliance members including Adobe, Cisco, Microsoft, CloudStrike, Space X, SAP and the Linux Foundation.</p>
<p>However, big-name AI vendors including Google, Anthropic and OpenAI were notable absences from the initial list of signatories.</p>
<p>The alliance – which builds on the Linux Foundation’s Akrites initiative and OpenSSF community work – will focus much of its effort on finding, fixing and disclosing vulnerabilities in AI products.</p>
<p><em>Read more on AI threats: AI Agents Now the Enterprises Fastest Growing Exposed Attack Surface.</em></p>
<p>“Across the alliance, contributors are building an open defense stack for agents – from identity and isolation to safe model formats, multi-model scanning and secure coding workflows,” said NVIDIA in a <a href="https://blogs.nvidia.com/blog/open-secure-ai-alliance/" target="_blank">blog post.</a></p>
<p>“Defenders need both frontier closed models and frontier open models, working together, so they can choose the right system for the job and ensure that transparency, adaptation and sovereign control are available wherever security demands them.”</p>
<p>While it is not clear why Google, Anthropic and OpenAI are not part of the initiative, one industry CISO noted that broader participation and clearer accountability is needed to improve the NVIDIA initiative’s chances of success.</p>
<p>Exabeam CISO, Kevin Kirkwood said, “The major frontier model developers need to be at the table, and the industry needs agreed rules for liability when an agent exceeds scope. Better tools help defenders fight dark AI. Better governance keeps the defensive tools from becoming part of the problem.”</p>
<h2><strong>Hugging Face Incident Reinforces Open Source Message</strong></h2>
<p>The move comes just days after a serious and unprecedented incident last week in which two OpenAI models autonomously broke out of a sandbox and hacked Hugging Face’s production systems.</p>
<p>Hugging Face revealed that it was forced to use an open-weight Chinese model to repel the attack because safety filters on proprietary US equivalents limited their usefulness.</p>
<p>As the Trump administration mulls whether to restrict access to such models, the NVIDIA alliance is arguing for more openness.</p>
<p>“The right response is not to deny defenders access to capable open systems. It is to pair openness with strong safeguards, clear rules against malicious misuse, rigorous evaluation and rapid remediation,” it said.</p>
<p>“In cybersecurity, the safer path is the one that gives more defenders the ability to test, verify and strengthen the systems on which society relies.”</p>
<h2><strong>Experts Remain Skeptical</strong></h2>
<p>Gene Moody, field CTO at Action1, said the launch of the alliance is recognition of the fact that “the technology is advancing faster than many organizations can responsibly govern it.”</p>
<p>However, he questioned whether it would have the required impact.</p>
<p>“Open source models already exist by the thousands, many capable of running entirely on local hardware, disconnected from any cloud service or vendor oversight. Once a model is operating in isolation, safety controls become just another layer of software,” said Moody.</p>
<p>“They can be modified, removed, retrained, or replaced altogether. You cannot program a conscience into an artificial intelligence. You can only program behaviors, and behaviors are subject to manipulation by anyone with sufficient technical skill.”</p>
<p>Black Hills Information Security owner, John Strand, was similarly skeptical.</p>
<p>“As researchers continue to show AI systems escaping their intended boundaries or interacting with other systems in unexpected ways, concerns about AI safety are growing,” he said.</p>
<p>“That’s why you’re seeing so many new AI security initiatives. In many cases, they’re trying to establish industry standards before governments step in with legislation or regulation. Whether those efforts are enough remains to be seen.”</p>
</div>
<p><br />
<br /><a href="https://www.infosecurity-magazine.com/news/nvidia-open-security-ai-alliance/" style="font-size: 11px;color:#D5DBDB">Source</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cyberwiredaily.com/nvidias-open-security-ai-alliance-is-missing-some-big-names/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
