Utopia Tech
▸ Engineering & Strategy Journal

Field notes from the edge.

What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
Security

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAP

UTUtopia Tech·1 min
Zero Trust for AI Agents Starts With Fixing Zero Visibility
Security

Zero Trust for AI Agents Starts With Fixing Zero Visibility

The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred

UTUtopia Tech·1 min
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Security

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution. The vulnerability was first exploited

UTUtopia Tech·1 min
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
Security

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows - CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Offic

UTUtopia Tech·1 min
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
Security

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out of 10.0. It only af

UTUtopia Tech·1 min
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
Security

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims. One of several selfies from the Facebook page of Cameron Wagenius. Cameron John Wa

UTUtopia Tech·4 min
Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
Strategy

Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee

I feel like someone who reads this blog will want to go to this : Families are invited to dive into the fascinating world of marine biology during an exciting, hands-on Family Squid Dissection at the Hands-On Science Center. Designed for curious learners of all ages, this unique experience combines an interactive lesson with the opportunity to explore the anatomy and adaptation

UTUtopia Tech·1 min
New software dependency validation process increases speeds by 54x
Industry

New software dependency validation process increases speeds by 54x

As if the pace of software creation hadn't accelerated enough thanks to generative AI coding agents, computer scientists in Japan have devised a way to turbocharge the process of build dependency verification. Speeds can increase by as much as 54x. Software build systems like Make, CMake, and the Zig build system automate the process of turning source code into executable progr

UTUtopia Tech·2 min
AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment
Security

AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment

When autonomous AI agents "escape the sandbox," the real story isn't rogue machines — it's the same access-control failures we've seen for decades.

UTUtopia Tech·1 min
What We Missed: Google Gemini Joins the AI Escape Party
Security

What We Missed: Google Gemini Joins the AI Escape Party

In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from Google Gemini models breaking containment to ShinyHunters ratting on TeamPCP hackers.

UTUtopia Tech·1 min
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Security

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload ke

UTUtopia Tech·1 min
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
Security

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHub Actions are listed below - actions-cool/issues-helper actions-cool/maintain-one-comment Visiting either of the repositories now shows the message: "Access to

UTUtopia Tech·1 min
LabCorp Settles Multistate Data Breach Investigation for $2.3 Million
Healthcare

LabCorp Settles Multistate Data Breach Investigation for $2.3 Million

A coalition of 44 state attorneys general has agreed to settle a multistate investigation of Laboratory Corporation of America (LabCorp) regarding a 2019 data breach at its debt collection company, American Medical Collection Agency (AMCA). LabCorp has agreed to pay $2,287,455, which will be divided among the 44 states participating in the action. AMCA is a subsidiary of the de

UTUtopia Tech·3 min
Stopping IT Worker Scams Requires Revamped HR Process
Security

Stopping IT Worker Scams Requires Revamped HR Process

Training human-resource managers in the latest tactics and warning signs goes a long way toward blunting the threat, but automated analysis can help even more.

UTUtopia Tech·1 min
Office 2016 and 2019 holdouts blame update for license deactivation bug
Industry

Office 2016 and 2019 holdouts blame update for license deactivation bug

Users report that a recent optional update for out-of-date Microsoft 365 applications might be connected to suddenly deactivated Microsoft Office 2016 and 2019 installations. The activation bug cropped up this week and appears to mostly impact Home and Business perpetual license installations, stripping away their authenticated status and forcing users into a loop where they ar

UTUtopia Tech·2 min
The SOC Doesn't Need to Start Over with Every Alert
Security

The SOC Doesn't Need to Start Over with Every Alert

Security leaders keep debating whether AI will produce an entirely new class of cyberattack. The nearer change is quieter and already visible: AI has made a failed attack cheap to retry. The routine version looks like this. An attacker lands on a low-privilege cloud account, and the first try at privilege escalation goes nowhere. That dead end used to cost hours of documentatio

UTUtopia Tech·1 min
Agents can now set up your website’s security with Turnstile Spin
Engineering

Agents can now set up your website’s security with Turnstile Spin

In 2023, Cloudflare declared itself free from CAPTCHAs with the launch of Turnstile, our privacy-first client-side challenge. Turnstile is free to use, works on any site (no need to proxy traffic through Cloudflare), and never asks a visitor to solve a puzzle. Now, we are launching Turnstile Spin, an agent-mediated end-to-end implementation of Turnstile. Initially built with de

UTUtopia Tech·4 min
Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
Security

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," BitGet said in a post shared on X. "Bitget's cold wallets and the overwhelming majority of platform assets r

UTUtopia Tech·1 min
On Anthropic’s AI Misuse Report
Strategy

On Anthropic’s AI Misuse Report

Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 117 findings. A few of the highlights: AI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows, and research while humans selected targets, set goals, and reviewe

UTUtopia Tech·1 min
Skip to main content