Agregátor RSS

EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts

Bleeping Computer - 22 Září, 2026 - 17:00
The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU). [...]
Kategorie: Hacking & Security

UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites

The Register - Anti-Virus - 22 Září, 2026 - 17:00
A coalition of law enforcement and private-sector tech companies led by Microsoft have disrupted the EvilTokens phishing service, arresting suspected website admins, taking down more than 50 websites, and notifying victims of compromised email accounts. EvilTokens is a notorious Microsoft device-code phishing kit that emerged in February, and, within months of launching, had been used by criminals to compromise 12,000 email inboxes across more than 10,000 organizations worldwide. Like other similar phishing subscriptions, EvilTokens was sold as-a-service, and allowed buyers to bypass multi-factor authentication (MFA) and silently authenticate as the victim to the organization's Microsoft 365 applications. What made this one especially insidious, however, was its AI use. EvilTokens featured an AI chatbot that could analyze a victim’s inbox, and help criminals identify who to target, which trusted contacts to impersonate, and even which fraud strategies to use to maximize criminals’ paydays. “Since March 15, 2026, we have observed 10 to 15 distinct campaigns launching every 24 hours," Microsoft VP of security research Tanmay Ganacharya told The Register in an earlier interview about the phishing service. Late last week, in a coordinated effort that spanned the US and UK, Microsoft seized 50 websites used to operate the service and disabled more than 150 additional domains tied to its supporting infrastructure. Meanwhile, London’s Metropolitan Police Service on September 18 arrested two men, aged 32 and 38, who allegedly acted as the administrators of the EvilTokens website. Both men have been released on bail while the investigation continues. “Phishing services bring misery to thousands, taking money from everyday people across the world,” Detective Inspector Serena D'Adamo, whose team led the Met's investigation, told The Register in an emailed statement. “The Met remains committed to holding people to account who facilitate criminal enabling functions and think they can remain undetected.” Because healthcare organizations were among those targeted, Health-ISAC, a nonprofit that helps health sector organizations share cyber-threat information, joined Microsoft’s legal action as a co-plaintiff. After receiving authorizations from the US District Court for the Eastern District of Virginia, Microsoft and Health-ISAC worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs, took down EvilTokens’ platform, and Microsoft notified affected customers, helping them remediate compromised accounts. This action marks the Microsoft Digital Crimes Unit’s (DCU) 40th court-authorized disruption over nearly two decades. According to Steven Masada, associate general counsel and DCU GM, this is also DCU’s first action against an end-to-end AI-enabled cybercrime service. “The infrastructure supporting EvilTokens has been disrupted, but the model it demonstrated will not disappear with it,” he said in a blog shared with The Register ahead of publication. “For organizations, the lesson is: assume that once an inbox is compromised, criminals may understand its contents in minutes, not days. Strong identity protections and monitoring remain essential, but organizations should also independently verify requests to change payment information, redirect funds or approve unusual transactions through a trusted second channel.” ®
Kategorie: Viry a Červi

Who signed off on that AI agent? Nobody? Thought so.

The Register - Anti-Virus - 22 Září, 2026 - 17:00
If you were in any doubt that AI agents are capable of complex autonomous work, that skepticism should have faded this summer. In July, news emerged that an autonomous swarm of OpenAI agents running in a sandbox broke out of it, of their own accord. Tasked with solving some challenges on an internal security benchmark, they worked out how to communicate with each other using the JFrog Artifactory package manager. The software then realized that they could use vulnerabilities in that software to gain internet access. Once they were out in the wild, they went into full goblin mode, finding exposed Hugging Face credentials and using them to get code execution access on several of the AI model's servers. Apparently OpenAI's agents have been busier still. While everyone else was on vacation this summer, they were also commandeering a German website and using it as a messaging board. Don't get us wrong; these agents weren't evil. They were just being the kind of employee you'd generally want: a self-starter with initiative. They were using all means at their disposal to accomplish the task they've been given. They just didn't know when to stop. OpenAI has since called the episode a "warning shot" for the industry, highlighting that governance is now a priority for anyone using agentic AI. These test agents were running internally and weren't supposed to have any safeguards. But the average company will want to keep its agents on a leash. What does that look like? The first step to AI governance is visibility A functional AI governance program depends on a full knowledge of what AI you're running, says Deepika Chauhan, chief product officer at DigiCert. She describes the pattern she sees at customer sites. "People may enable Claude or ChatGPT for their organization. They have visibility at that level," she says. "But visibility into how many agents I have? How many models do I have? How many MCP servers?" Not so much. "We haven't even started to attack the governance problem." This problem is growing. Three quarters of the 1,001 IT and cybersecurity decision-makers in DigiCert's 2026 AI Trust Pulse survey had deployed at least four AI-powered systems in the last six months. Around the same number had suffered from an AI-related security incident. Only half could trace AI decisions back to the models and data that produced them. Getting that visibility is the first step, Chauhan says. After that comes the actual management. The key here is to take baby steps. "Identify a small use case," she advises. One example might be to start managing agents that are involved in a particular workload or agents that you have built internally, as opposed to third party models. Why identity built for humans breaks at agent speed Perhaps predictably for a company that built its success on automated verification, DigiCert doesn't see agent management as a manual problem. "The sheer scale we are talking about and the technology required means that you can't have human intervention," Chauhan says. "One customer we were talking to was creating 300 to 400 agents a week. When you're working at that scale, it just doesn't work to have only manual controls." The other issue is that humans are fallible. Misconfiguration is a perennial bugbear in any IT environment, but it becomes particularly dangerous in an agentic AI situation. Other agentic SNAFUs at Meta and Anthropic illustrate the point perfectly. Both saw agents make their way onto the open internet when they shouldn't, and both were due to misconfiguration by a third-party company tasked with testing the agents. Traditional tools meant to manage human identities can't manage non-human identities well, adds Chauhan. Legacy identity and access management applications require people to approve access to different applications. There must still be a human in the loop, even if it's just for people to click an MFA approval button. Human employees might be willing to wait a minute or two for such approval, but agents talk to each other at machine speed. Instead, automated runtime attestation is key, managed by a robust central policy engine. The foundation of AI Trust That attestation relies on credentials and it's something that agents should carry with them, says Chauhan. This is one component in the company's AI Trust initiative. AI Trust is DigiCert's end-to-end governance framework that assigns identity automatically to AI entities, restricting them to safe, permitted actions while making them accountable. It uses cryptographic controls to ensure agent integrity, and the company has integrated it with existing infrastructure. The runtime attestation of AI Trust draws on the international travel metaphor in its approach. "We have a concept of an AI agent passport. There's an identity in the passport, but then that identity is recognized across any checkpoint anywhere in the world," she says, adding that the passport includes not just identity but access credentials (think of them like visas). Federation is key to this idea because, as we've seen already, agent interactions won't stop at the company boundary. "It's essential because you're literally going to have agents from company A talking to company B," she explains. DigiCert's whitepaper describes the concrete artifact: a tamper-evident passport cryptographically bound to a workload identity that encodes approved systems, permitted operations, authorized environments, data-sensitivity classifications, expiration states, and accountable human ownership. The scheme is anchored in DNS, the same mechanism DMARC uses to authenticate email senders, on the reasoning that every agent action begins with a DNS query. Deterministic guardrails around a non-deterministic actor As agents get smarter, won't they be able to subvert these controls by thinking outside the box, Jason Bourne-style? After all, OpenAI's agents were able to break free of their sandbox to wreak havoc elsewhere. OpenAI's own post-mortem states that its models "are now powerful, persistent, and collaborative enough that, absent sufficient safeguards, they can find and exploit security weaknesses across multiple computer systems." Part of the problem here is that because agents are non-deterministic, you can't predict in advance what they're going to do. That problem becomes even more acute with newer frontier models like OpenAI's Astra, which saves tokens by internalizing a lot of its reasoning and not reporting its decision-making process in as much detail as previous models. The outer boundary can still be deterministic, even when the agents inside it aren't, says Chauhan. "You can black box what the agent is 'thinking' about or not thinking about, and what its agendas might be," she says. "But a deterministic boundary that says 'this agent can't access this thing', is your guardrail. That's a hard stop." Who owns the mess Governance isn't just about technical guardrails, though. At some point, the question becomes organizational. When something goes wrong, someone has to put their hand up and own it. But most companies never assigned that ownership, Chauhan warns. She identifies three patterns in DigiCert's customer base. Some organizations put the existing IAM team in charge because they have experience governing service accounts. Others hand it off to the risk and compliance department. Another group will take a more holistic, multidisciplinary approach. This involves creating a 'tiger team' including representatives from network operations, the IAM team, and the security function. All of these executives will have a unique perspective on the issue. The third route seems to be the most productive because agents are going to be everywhere in your business. And a siloed approach runs the risk of being too restrictive. The surface area already touches every department that has dabbled in AI. The systemic view Chauhan's advice on implementing AI Trust - get visibility, pick a small use case for enforcement, and then expand - is the foundation for effective AI governance, she says. That governance is in turn a critical component in fully realizing return on investment. "We must raise the urgency and awareness that this is table stakes for wider AI adoption," she urges. "You want to get all the benefits from AI, but what are organizations going to do if they're nervous about it? They're going to put a stop to some of the projects because of the risk involved." The headlines we're seeing about agentic transgressions are unnerving, but they're also in a unique category because they're research models from frontier providers. It seems unlikely that a regular publicly available agent would be quite so egregious today. However, we have also seen agents happily deleting files and even entire code bases because of internal flaws and humans who just waved their actions through. Organizations should be taking note of these events and laying the groundwork to avoid becoming headlines themselves. Working out who signed off on which agent and what that agent is allowed to do is a foundational skill that we can't afford to overlook. Sponsored by DigiCert.
Kategorie: Viry a Červi

Meta odpovídá za podvodné reklamy, rozhodl německý soud. Padla obrana, kterou platformy používaly roky

Živě.cz - 22 Září, 2026 - 16:45
Soud ve Frankfurtu rozhodl, že Meta odpovídá za podvodné reklamy. • Meta podle soudu není neutrální hostitel, obsah ovládá svými algoritmy. • Za každé porušení jí hrozí pokuta až 250 tisíc eur.
Kategorie: IT News

Alibaba Cloud sponzorem Omarchy, 3 miliony dolarů

AbcLinuxu [zprávičky] - 22 Září, 2026 - 16:25
Alibaba Cloud je dalším sponzorem nadace Omacom Foundation stojící za linuxovou distribucí Omarchy. Přislíbená částka je 3 miliony dolarů, tj. 1 milion dolarů ročně po dobu tří let. Stejná částka jako u DigitalOcean.
Kategorie: GNU/Linux & BSD

systemd 262

AbcLinuxu [zprávičky] - 22 Září, 2026 - 16:13
Byla vydána nová verze 262 správce systému a služeb systemd (Wikipedie, GitHub).
Kategorie: GNU/Linux & BSD

Zákaz soukromých dronů v Pekingu. Majitelé je musí prodat, zlikvidovat nebo odvézt mimo metropoli

Živě.cz - 22 Září, 2026 - 15:46
Peking od poloviny listopadu zakáže držení i skladování všech dronů • Majitelé musejí své stroje prodat, zlikvidovat nebo odvézt pryč • Zákaz reaguje na červnovou havárii letadla přímo nad čínskou metropolí
Kategorie: IT News

Beware these fake websites selling subscriptions to AI assistants

Computerworld.com [Hacking News] - 22 Září, 2026 - 15:09

Websites offering fake subscriptions to AI transcription tools, image generators, and other digital assistants could be putting enterprise data at risk, according to researchers at Malwarebytes.

The sites impersonate AI products with solid reputations, including GPT-6 Astra, DaVinci Resolve, PixAI and OpenCut, in addition to some that no longer exist (such as Omegle, a chat service shut down in 2023) or are less reputable.

All the fake websites were polished and incorporate genuine Google authentication elements inviting users to “Sign in with Google” to enhance credibility on the path to charging visitors’ payment cards anything from $10 a month to as much as $2,000 for a year’s access to the promised AI and software services.

“The sites we examined did not use fake password forms or push malware downloads,” Malwarebytes researchers said in a blog post describing their discovery. But some of the sites asked users to upload documents, recordings, or other files in order to unlock the advertised services.

The danger for enterprises is if would-be customers of such services think they’re getting a good deal for their departmental budget and don’t want to involve IT in the buying process. Shadow IT is bad enough when the products are legitimate, but in these cases there’s no knowing where the data gathered will end up.

Malwarebytes’ researchers suspect that all the fake subscription sites it identified are run by the same person or group, since they were all created using the same website creation kit based on identical underlying files and with closely related developer email addresses shared across them.

The website creation kit is a legitimate commercial offering that provides account management, billing, file storage and other administrative functions, Malwarebytes said, noting its makers claim it can launch a website in an hour and that, after a one-time purchase, additional templates cost only about $2 each.

The fake sites use genuine Google sign-in pages rather than fake password forms. Visitors enter their credentials on Google’s website and the applications request basic information such as their name, email address and profile picture. Malwarebytes said the sites it examined did not request access to Gmail or Google Drive.

Google’s consent screen generally identifies the application requesting access and provides developer details, Malwarebytes noted. But on the fake websites, that screen displayed free webmail addresses for the developer contacts instead of addresses belonging to the well-known AI services promised. In the case of the unfamiliar AI brands, the sites provide little independently verifiable information about the businesses selling the subscriptions, the researchers added.

Look past the polish

Malwarebytes recommends that users look beyond a site’s design and the presence of familiar authentication options when deciding whether an AI service is legitimate. These include checking who operates the service, looking for verifiable company information and examining the developer details shown during Google authentication.

It also warned users not to upload sensitive documents, recordings or other data to unfamiliar AI services, particularly when the business behind the site cannot be independently verified.

For services connected through Google, users can review the connections in their Google Account and remove services they no longer trust or recognize to prevent future access.

Kategorie: Hacking & Security

Webinar tomorrow: Inside real-world Google Workspace breaches

Bleeping Computer - 22 Září, 2026 - 14:57
Tomorrow's webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and response decisions can make the greatest difference. [...]
Kategorie: Hacking & Security

D-Link warns of max severity zero-day bug in DIR-822A routers

Bleeping Computer - 22 Září, 2026 - 14:48
D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers. [...]
Kategorie: Hacking & Security

Googlebooky míří na trh. ChromeOS mizí, nahradí ho desktopový Android. Cena zatím není nízká

Živě.cz - 22 Září, 2026 - 14:45
Google představil prvních pět oficiálních Googlebooků. Acer, Dell, Asus, Lenovo a HP uvedou po jednom modelu nového typu notebooků. Googlebooky mají nahradit Chromebooky a (podobně jako současné Chromebooky) nabídnou plnohodnotný prohlížeč Chrome spolu s podporou aplikací pro Android. Googlebooky ...
Kategorie: IT News

AI Agents Are Rewriting the Rules of Lateral Movement

The Hacker News - 22 Září, 2026 - 14:30
Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has? A person may try several ways to complete a task. A deterministic application follows the flow its developer wrote. But an AI agent is relentless in its pursuit of done. In May [email protected]
Kategorie: Hacking & Security

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

The Hacker News - 22 Září, 2026 - 14:29
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

DORA Year Two: Can Your SOC Actually See the Attack?

The Hacker News - 22 Září, 2026 - 13:45
When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third-party service providers, updating contract clauses, and documenting incident escalation workflows. Now in its second year, the harder part of DORA is [email protected]
Kategorie: Hacking & Security

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

The Hacker News - 22 Září, 2026 - 13:38
A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine. Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

The Hacker News - 22 Září, 2026 - 13:17
A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Ergonomická myš od Alzy nabídne skoro totéž co vzor od Logitechu, ale stojí jen 374 Kč

Živě.cz - 22 Září, 2026 - 12:41
Eternico MSB550B připomíná Logitech MX Master, ale stojí pouze zlomek ceny. • Zlevnila o čtvrtinu na 374 Kč a je na ni tříletá záruka. • Myš má ergonomický tvar, tichá tlačítka, kovové kolečko a lze ji spárovat se třemi PC najednou.
Kategorie: IT News

Poláci začali stavět nové superletiště. Megastavba za 737 miliard korun má být hotová v šibeničním termínu (video)

Živě.cz - 22 Září, 2026 - 12:17
Před devíti lety se Polsko rozhodlo, že chce být středoevropskou Dubají, a tamní vláda proto schválila ambiciózní plán výstavby nového obřího letiště na půli cesty mezi Varšavou a Lodží. Port Polska, jak se celý projekt nového národního dopravního hubu jmenuje, počítá také se stavbou ...
Kategorie: IT News
Syndikovat obsah