Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIBdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
A supply chain attack targeting WordPress plugin vendor BdThemes has been discovered, leading to temporary suspension of their plugin downloads. The attack uniquely manipulated JSON data rather than modifying source code in the official WordPress.org repository, allowing threat actors to create unauthorized administrator accounts.
AIMultistate Water System Attacks Widen, Iran Suspected
Cyberattacks against water infrastructure have expanded across multiple U.S. states, with Iran suspected as the threat actor. The attacks exploit poorly secured programmable logic controllers (PLCs) that are directly exposed to the Internet, highlighting critical vulnerabilities in operational technology security across water utilities.
AI'GhostJacking' Exposes Identity Governance Gaps in AI Agents
Security researchers have identified a new attack vector called 'GhostJacking' that exploits identity governance vulnerabilities in AI agents. Attackers can manipulate security alerts and blocked events to hijack AI agents, revealing critical gaps in how organizations manage and secure AI-powered systems. This discovery highlights the urgent need for enterprises to strengthen identity and access m
AIThe Patch Gap: Why Defenders Need to Think in Chains, Not Checklists
Organizations need to shift from traditional CVSS-based vulnerability patching approaches to a strategic 'choke-point patching' methodology that focuses on breaking attack chains leading to critical assets. This approach prioritizes vulnerabilities based on their position in potential attack paths rather than severity scores alone, enabling more effective resource allocation and risk reduction.
AIChina-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft has identified Storm-1175, a China-linked financially motivated threat actor, deploying a new ransomware variant called StormEncryptor, marking a shift from their previous use of Medusa ransomware. The C++-written malware appends the .encrypted extension to compromised files. This development represents an evolution in the threat actor's toolkit and operational capabilities.
AICoruna, DarkSword iOS Exploits Proliferate Globally
Advanced iOS exploit chains, including Coruna and DarkSword, that were previously exclusive to nation-state threat actors are now being adopted by organized cybercrime groups. This proliferation represents a significant escalation in the threat landscape for mobile enterprise security, as sophisticated iPhone exploits become more widely accessible beyond state-sponsored actors.
AI⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
This week's security landscape highlights how routine IT operations—cloning repositories, answering calls, or using default configurations—continue to serve as primary attack vectors. The analysis covers emerging threats including supply chain vulnerabilities, zero-day exploits in Metabase, router backdoors, and the resurgence of previously patched vulnerabilities. The common thread is the minimal
AIOutdated Cybercrime Laws Put Security Researchers at Risk
A public policy expert has developed a five-point framework to protect ethical hackers and security researchers who operate in good faith, addressing the risks posed by outdated global cybercrime laws. The framework emerged from comprehensive mapping of cybercrime legislation worldwide, highlighting the need for legal reforms that distinguish between malicious actors and legitimate security profes
AISherlock Holmes was the “OG” Social Engineer
The article draws parallels between Sherlock Holmes' investigative methods and modern social engineering tactics used in cybersecurity. Holmes employed disguises, surveillance, and intelligence gathering techniques that mirror contemporary ethical and malicious hacking approaches. His methods offer instructive lessons for today's security professionals and threat actors alike.
AIKimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
North Korea's Kimsuky APT group has evolved beyond using public AI chatbots to deploying private, offline AI infrastructure on dedicated servers. The threat actor is leveraging AI for enhanced document analysis of stolen data and developing capabilities to integrate AI directly into malware creation processes, according to research from South Korean security firm Genians.
AIShipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development
AI-powered development tools are enabling teams to produce 10-50 times more code, creating a critical bottleneck for security teams that still operate at human speed. The challenge has shifted from simply identifying vulnerabilities to preventing security from slowing deployment velocity while maintaining control over what reaches production.
AINew Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Three new research efforts have revealed vulnerabilities in passkey authentication systems that bypass their phishing-resistant protections without breaking underlying cryptography. The attacks exploit weaknesses in implementation rather than cryptographic flaws, including reusing exposed Windows authentication material, abusing cloud-synced passkey systems through malware, and other bypass techni
AISolidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Cybersecurity researchers have identified malicious Visual Studio Code extensions masquerading as Solidity development tools that steal cryptocurrency wallet credentials and API keys. The extensions, named 'solidity-pro' and distributed under different publisher names, targeted blockchain developers but have since been removed from the Open VSX marketplace.
AIOpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause
OpenAI has temporarily halted internal activities related to its upcoming AI model Astra after internal evaluations revealed significant advancements in agentic coding and cybersecurity capabilities that exceeded expected thresholds. The company is implementing enhanced security controls and isolation measures for higher-capability models before proceeding. This pause reflects growing industry con
AINew CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
Security researchers have discovered new CSS-based attack vectors that allow malicious content within emails to break out of message boundaries and interact with webmail interfaces. These attacks affect major email providers including Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, enabling threat actors to steal passwords, hijack accounts, leak authentication tokens, and manipula
AIAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Security researchers have discovered vulnerabilities in Atlassian's Rovo AI assistant that allow attackers to extract sensitive Jira and Confluence data accessible to authenticated users by injecting malicious instructions. Two security firms independently identified different attack vectors, with only one confirmed as patched. The exploit involves embedding attacker-controlled prompts in content
AIN-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
N-able has released additional hotfixes for its N-central RMM platform in response to active exploitation of a recently disclosed security vulnerability. The company is proactively enhancing protections as threat actors evolve their attack techniques and have reportedly reached managed systems with persistent access. This represents an escalating security incident requiring immediate attention fro
AIMetabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Metabase has disclosed a critical zero-day vulnerability with a maximum CVSS score of 10.0 in its business intelligence platform that is being actively exploited in the wild. The flaw allows unauthenticated remote attackers to execute arbitrary SQL injection attacks against the Metabase application database, potentially granting unauthorized administrative access without any authentication require
AIClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
Cybercriminals are leveraging ClickFix-style social engineering attacks to distribute Go-based malware targeting macOS systems. The malware is designed to steal cryptocurrency wallet contents, browser passwords, Apple iCloud Keychain credentials, and cached authentication data through an infection chain that profiles the host system and delivers architecture-specific payloads.
