Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIChina-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft has identified Storm-1175, a China-linked financially motivated threat actor, deploying a new ransomware variant called StormEncryptor, marking a shift from their previous use of Medusa ransomware. The C++-written malware appends the .encrypted extension to compromised files. This development represents an evolution in the threat actor's toolkit and operational capabilities.
AI⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
This week's security landscape highlights how routine IT operations—cloning repositories, answering calls, or using default configurations—continue to serve as primary attack vectors. The analysis covers emerging threats including supply chain vulnerabilities, zero-day exploits in Metabase, router backdoors, and the resurgence of previously patched vulnerabilities. The common thread is the minimal
AIKimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
North Korea's Kimsuky APT group has evolved beyond using public AI chatbots to deploying private, offline AI infrastructure on dedicated servers. The threat actor is leveraging AI for enhanced document analysis of stolen data and developing capabilities to integrate AI directly into malware creation processes, according to research from South Korean security firm Genians.
AIShipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development
AI-powered development tools are enabling teams to produce 10-50 times more code, creating a critical bottleneck for security teams that still operate at human speed. The challenge has shifted from simply identifying vulnerabilities to preventing security from slowing deployment velocity while maintaining control over what reaches production.
AINew Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Three new research efforts have revealed vulnerabilities in passkey authentication systems that bypass their phishing-resistant protections without breaking underlying cryptography. The attacks exploit weaknesses in implementation rather than cryptographic flaws, including reusing exposed Windows authentication material, abusing cloud-synced passkey systems through malware, and other bypass techni
AISolidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Cybersecurity researchers have identified malicious Visual Studio Code extensions masquerading as Solidity development tools that steal cryptocurrency wallet credentials and API keys. The extensions, named 'solidity-pro' and distributed under different publisher names, targeted blockchain developers but have since been removed from the Open VSX marketplace.
AIOpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause
OpenAI has temporarily halted internal activities related to its upcoming AI model Astra after internal evaluations revealed significant advancements in agentic coding and cybersecurity capabilities that exceeded expected thresholds. The company is implementing enhanced security controls and isolation measures for higher-capability models before proceeding. This pause reflects growing industry con
AINew CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
Security researchers have discovered new CSS-based attack vectors that allow malicious content within emails to break out of message boundaries and interact with webmail interfaces. These attacks affect major email providers including Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, enabling threat actors to steal passwords, hijack accounts, leak authentication tokens, and manipula
AIAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Security researchers have discovered vulnerabilities in Atlassian's Rovo AI assistant that allow attackers to extract sensitive Jira and Confluence data accessible to authenticated users by injecting malicious instructions. Two security firms independently identified different attack vectors, with only one confirmed as patched. The exploit involves embedding attacker-controlled prompts in content
AIN-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
N-able has released additional hotfixes for its N-central RMM platform in response to active exploitation of a recently disclosed security vulnerability. The company is proactively enhancing protections as threat actors evolve their attack techniques and have reportedly reached managed systems with persistent access. This represents an escalating security incident requiring immediate attention fro
AIMetabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Metabase has disclosed a critical zero-day vulnerability with a maximum CVSS score of 10.0 in its business intelligence platform that is being actively exploited in the wild. The flaw allows unauthenticated remote attackers to execute arbitrary SQL injection attacks against the Metabase application database, potentially granting unauthorized administrative access without any authentication require
AIClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
Cybercriminals are leveraging ClickFix-style social engineering attacks to distribute Go-based malware targeting macOS systems. The malware is designed to steal cryptocurrency wallet contents, browser passwords, Apple iCloud Keychain credentials, and cached authentication data through an infection chain that profiles the host system and delivers architecture-specific payloads.
AINearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
Nearly 800 malicious packages have been discovered on the npm registry, deploying cross-platform remote access trojans (RATs) and infostealers targeting Windows, Mac, and Linux systems. The packages utilize AI-generated typo-squatting techniques to deceive developers into downloading compromised code. This campaign represents a significant supply chain security threat to enterprise development env
AINew WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress has patched a critical pre-authentication reflected XSS vulnerability (CVE-2026-64638) affecting all versions of the CMS. The high-severity flaw, with a CVSS score of 8.9, requires no attacker privileges and can potentially be chained to achieve PHP code execution on the server, making immediate patching essential for all WordPress installations.
AI18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
A critical 18-year-old use-after-free vulnerability in Linux's SCTP networking code enables local privilege escalation to root access and container escape. Tencent researchers demonstrated successful exploitation to break out of containers and compromise the underlying host system. Patches are available in stable kernel versions released August 3, 2025, making immediate updates essential for syste
AIGrowing Up The Hard Way
Open source software enjoyed two decades of informal, trust-based development characterized by free distribution and minimal oversight. This idealistic period operated without formal governance, licensing enforcement, or accountability mechanisms. The industry is now facing a maturation phase that requires more structured approaches to sustainability and security.
AIAI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger's AI-assisted research system, HTTP Terminator, developed by James Kettle, successfully identified novel HTTP desynchronization attack techniques after analyzing 30,000 candidate attack vectors. The research also uncovered a zero-day vulnerability in Apache Traffic Server through a separate human-guided investigation, demonstrating the effectiveness of combining AI automation with expe
AIMicrosoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
A widespread phishing campaign is leveraging adversary-in-the-middle (AitM) techniques to compromise Microsoft 365 accounts, specifically targeting employees involved in payroll and financial operations. The attackers use residential proxies to mask malicious sign-ins as legitimate consumer traffic, making detection more difficult and enabling unauthorized access to sensitive financial communicati
AIMalware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Security researcher Malcolm Stagg has unveiled NatJack, a novel attack methodology that exploits network address translation (NAT) vulnerabilities to hijack TCP sessions, manipulate DNS responses, and compromise network infrastructure. The techniques, demonstrated at Black Hat USA 2026, enable attackers to expose victim IP addresses, exhaust NAT tables, and gain unauthorized access across various
