Agregátor RSS

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

The Hacker News - 3 Srpen, 2026 - 18:24
Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen. Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets the master key
Kategorie: Hacking & Security

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

The Hacker News - 3 Srpen, 2026 - 18:24
Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen. Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets the master keySwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The Hacker News - 3 Srpen, 2026 - 18:15
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per
Kategorie: Hacking & Security

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The Hacker News - 3 Srpen, 2026 - 18:15
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Russian spies turn public Wi-Fi into malware delivery systems

The Register - Anti-Virus - 3 Srpen, 2026 - 17:39
Conference-goers may want to think twice about connecting to public Wi-Fi after Microsoft disclosed that Russian foreign intelligence operatives (SVR) are compromising captive portal networks to deliver infostealers, keyloggers, and other malware. With the help of ReliaQuest's earlier work, Redmond fingered Storm-2945, a subdivision of the SVR's Midnight Blizzard (aka Nobellium), in an attack campaign targeting users of public Wi-Fi networks at places like hotels, conference centers, and other shared venues in the hospitality sector. Microsoft is still trying to determine how the hackers initially compromise captive-portal networks. The broader AI-assisted operation dates to February 2026, with traffic manipulation observed since early May. After gaining control of the network layer, Storm-2945 manipulates DNS and HTTP traffic to reroute users through attacker-controlled infrastructure, Microsoft said. The crew also abuses operating systems' connectivity checks to trigger malicious prompts and redirects. This gives the attackers an adversary-in-the-middle (AitM) position. Such prompts adopt ClickFix-style methods, which in some cases try to convince public Wi-Fi users to install malware under the guise of OS updates, driver repairs, and web verification failures. Users who follow through on the instructions provided in the prompts may then find their device infected with malware. Microsoft calls the campaign "CaptiveCrunch." One of the malware strains it delivers is CornFlake. Described as "a full-featured Windows RAT" written in Go, CornFlake is the SVR's go-to persistent implant in these hospitality network attacks. After presenting users with a "convincing" fake Windows update progress window, it provides attackers with a wealth of capabilities once installed. These include: Keylogging Clipboard monitoring Screenshot capture Audio surveillance Video surveillance Browser credential theft File exfiltration USB drive monitoring Security posture sweep Remote shell Microsoft also said that CornFlake exposes a localhost HTTP API server to transform the malware into a modular platform, delivering additional payloads such as ChocoShell, a PowerShell-based infostealer. ChocoShell is delivered and executed entirely in-memory, Microsoft said. SVR uses it primarily to suck up victims' browser session cookies, saved passwords, SSO tokens, and Wi-Fi credentials. Microsoft neatly summarized the two: "Where CornFlake provides the operator with a persistent, long-running foothold on the device, ChocoShell is designed to extract the most operationally valuable credentials, giving the operator access to victim cloud environments." The attacks primarily target Windows machines, but Microsoft has also seen indications of ClickFix prompts tailored to Android devices, encouraging users to download and install an APK file. In addition to the malware element, "a portion" of SVR's CaptiveCrunch activity is devoted to device code phishing. Users sent to attacker-controlled landing pages may be instructed to enter a device code on a legitimate Microsoft authentication page, unwittingly authorizing the attacker's session. Device code phishing exploits a legitimate OAuth flow, typically reserved for devices that struggle to open browsers, such as smart TVs. In such scenarios, attackers request an authentication code from Microsoft, which they then send to phishing targets. In the CaptiveCrunch campaign, this looks like a fake landing page, served to the user thanks to the AitM component of the attack. Targets are then asked to copy the code, which was originally given to the attacker, open a legitimate Microsoft authentication window, enter the code, and choose which account they wish to authenticate. Choosing the account completes the authentication flow, but in turn authenticates the attacker into the chosen account. This gives the attacker a valid OAuth token for the victim's Microsoft 365 account, potentially granting access to cloud data permitted by the token until it expires or is revoked. Device code phishing is not a new or unique attack, but can be an effective route to bypassing MFA, especially when an attacker already controls the flow of traffic after a captive portal compromise. "This activity is consistent with previously reported device code phishing operations conducted by Midnight Blizzard since August 2024," Microsoft said. "The observed technique does not appear fundamentally novel; however, integrating device code phishing into captive portal and traffic manipulation operations might increase the likelihood that users perceive the authentication request as legitimate." The main takeaway, in Microsoft's book, is to stop trusting public Wi-Fi so much. It did not discourage using hospitality networks' Wi-Fi services altogether, but said favoring personal hotspots and satellite internet connections over public networks is a safer bet. The majority of Redmond's advice could be brought under the user education umbrella: Don't trust public networks; teach users not to download updates over public networks or via prompts; educate users about what ClickFix attacks look like. That sort of stuff. But organizations have a role to play too. Among other technical implementations, passwordless authentication can thwart many phishing techniques, although device code phishing may bypass even passkeys. The best response would be for an employer to disable the device code authentication flow altogether, wherever possible, preventing staffers from surrendering their workplace cloud access to attackers. ®
Kategorie: Viry a Červi

T-Mobile nikdo k blokaci ‚dezinfowebu‘ AC24 nenutil, píše soud

AbcLinuxu [zprávičky] - 3 Srpen, 2026 - 17:26
Firma T-Mobile blokovala „dezinformační web“ AC24 bez toho, aniž by k tomu měla závazný pokyn orgánů veřejné moci. Píše to ve svém rozsudku Městský soud v Praze, který po čtyřech letech uzavřel kauzu blokace zmíněného webu. Operátor musí uhradit škodu ve výši 35 tisíc korun. Advokát společnosti T-Mobile se snažil i u odvolacího senátu argumentovat tím, že firma jednala v dobré víře, když na stránky omezila přístup poté, co ji k tomu vyzvalo Národní centrum kybernetických operací (NCKO), které spadá pod Vojenské zpravodajství. Stejně tak se odvolával na to, že blokaci schválili také představitelé vlády svým usnesením. Tento argument ale neuspěl. Podle soudu totiž muselo být operátorovi jasné, že ho ani usnesení, ani dopis zpravodajců – kterými byl k blokaci takzvaných dezinformačních webů na začátku ruského vpádu na Ukrajinu v roce 2022 vyzván – k podobnému kroku nezavazuje.
Kategorie: GNU/Linux & BSD

Rumunská armáda musela odstřelit kus Dunaje. Jejich jediná jaderná elektrárna je na suchu

Živě.cz - 3 Srpen, 2026 - 17:15
Extrémně nízká hladina Dunaje připomíná poněkud nedomyšlenou zranitelnost jaderných elektráren, které jinak řadíme mezi ty nejspolehlivější a nejstabilnější zdroje elektřiny. Nedostatek vody nyní vážně ohrozil jedinou rumunskou jadernou elektrárnu Cernavodă, jejíž dva reaktory pokrývají zhruba ...
Kategorie: IT News

ExfilSquad hackers leak info of over 100,000 UK police officers, staff

Bleeping Computer - 3 Srpen, 2026 - 17:04
A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. [...]
Kategorie: Hacking & Security

Inside the Underground Business of the Android BTMOB RAT malware

Bleeping Computer - 3 Srpen, 2026 - 16:45
Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. [...]
Kategorie: Hacking & Security

Windows 11 zaberou méně paměti. Na počítače se 4 GB ale Microsoft zapomněl

Živě.cz - 3 Srpen, 2026 - 16:45
Microsoft v hrubých obrysech nastínil další chystaná vylepšení Windows 11. • Ve druhém pololetí se zaměří i na optimalizaci, cílí ale na 8 GB operační paměti. • Jenže Windows 11 mohou oficiálně běžet i se na konfiguracích se 4 GB paměti.
Kategorie: IT News

Responding to a Web Server Compromise

LinuxSecurity.com - 3 Srpen, 2026 - 16:36
Your website isn’t acting normally. Users report errors. Monitoring detects unexpected outbound connections. You discover a recently modified PHP file in your web root. Nobody can explain why. What do you do first?
Kategorie: Hacking & Security

Padla obžaloba v bitcoinové kauze

AbcLinuxu [zprávičky] - 3 Srpen, 2026 - 16:35
Padla obžaloba v bitcoinové kauze. Státní zástupkyně chce pro Blažka 6,5 roku vězení, pro Titze 8 let.
Kategorie: GNU/Linux & BSD

What Is Fuzzing? Inside the Search for Hidden Linux Kernel Bugs

LinuxSecurity.com - 3 Srpen, 2026 - 16:06
If you spend time reading Linux kernel bug reports or security patches, that line is everywhere. It sits quietly at the bottom of code fixes across the entire operating system, from network drivers to file systems.
Kategorie: Hacking & Security

⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks

The Hacker News - 3 Srpen, 2026 - 16:03
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from
Kategorie: Hacking & Security

⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks

The Hacker News - 3 Srpen, 2026 - 16:03
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Ohnivý mrak nad Francií přináší novou hrozbu. Může proměnit lesní požáry v ještě větší pohromu

Živě.cz - 3 Srpen, 2026 - 15:45
Extrémní lesní požáry v jihozápadní Francii vytvořily nebezpečný ohnivý mrak • Pyrokumulonimbus generuje vlastní blesky a silné nárazy větru daleko od ohniska • Mrak unáší saze do stratosféry a komplikuje veškeré záchranné práce
Kategorie: IT News

Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict

The Register - Anti-Virus - 3 Srpen, 2026 - 15:33
Georgia and Michigan are the latest US states to report cyberattacks on water systems, as the FBI investigates incidents across at least seven states. Iran-backed hackers are the leading suspects, although the bureau has not publicly attributed the campaign. Officials in both states told journalists over the weekend that water facilities had detected activity consistent with the attacks on more than 30 Minnesota sites last week. Neither state reported operational disruption. Nine Michigan water systems reported hostile cyber activity to the state's Department of Environment, Great Lakes, and Energy. Department communications director Dale George said the state received "a small number" of reports consistent with the activity seen in Minnesota, but no public health consequences followed. "All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern," said George. Georgia also confirmed to ABC News that it was affected, but said the damage was limited. Neither Georgia nor Michigan has published any form of public-facing notification about the cyberattacks. The three states are among at least seven affected by the intrusions, according to an FBI advisory posted last week. The bureau did not name a culprit or mention Iran. "Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations," it stated in its advisory. The FBI said it had so far observed the activity only against Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), although it warned organizations deploying other manufacturers' devices to follow the same hardening advice. A broader CISA advisory, updated on July 22, warned that Schneider Electric, Siemens, and potentially other PLC brands were also being targeted by Iran-affiliated actors. Security researchers at Tenable were among the first to publicly suspect Iran's involvement, citing similarities with previous attacks by the IRGC-linked CyberAv3ngers group. Minnesota was the first state to confirm it was hit by the attacks, which took place over July 26-27. The state's IT department (MNIT), said more than 30 community water systems were targeted, but still has not officially attributed the attacks. According to WIRED, a restricted WaterISAC notice shared with water utilities said the Minnesota activity aligned with an earlier Iran-affiliated campaign. WaterISAC told WIRED that it had not assessed attribution "at any time" and publicly stated that it had not supplied the leaked document to the publication. President Trump also rejected the Iran link, offering no evidence for his alternative explanation. He told reporters following a cabinet meeting on Friday that "they blame it on Iran. I don't think so. I blame it on Minnesota because they're grossly incompetent." He added: "I think the governor is behind it. I don't think there was an Iranian cyberattack." Tim Walz, Minnesota's Democratic governor, suggested Iran was indeed behind the attacks, and highlighted Trump's funding cuts leaving sites such as water facilities more vulnerable to cyberattacks. "Trump knows exactly who is responsible for this attack, and knows that other states were hit too," he said. "This is what modern warfare looks like, and it further illustrates there's no plan to win a war in Iran. "DOGE took an axe to CISA and left the US exposed to cyberattacks. Thankfully, our experts in Minnesota were able to identify the vulnerability quickly and work with local communities to stop it." ®
Kategorie: Viry a Červi

Statcounter: Linux na desktopu 7,53 %, Firefox na desktopu 6,51 %

AbcLinuxu [zprávičky] - 3 Srpen, 2026 - 15:30
Z aktuálních globálních statistik společnosti Statcounter: na desktopu má Linux celosvětově podíl 7,53 % (USA 11,92 %, Česko 4,31 %, Slovensko 4,36 %) a Firefox celosvětově podíl 6,51 % (USA 10,86 %, Česko 11,07 %, Slovensko 13,61 %).
Kategorie: GNU/Linux & BSD

An analysis of incidents at Brazilian educational institutions

Kaspersky Securelist - 3 Srpen, 2026 - 15:00

Introduction

Because of the amount of data that can be obtained and the high impact that successful attacks may have, educational institutions are frequent targets of cybercriminals. Both public and private schools and universities rely on software for managing personally identifiable information (PII) that is often insecure or insufficiently tested against known vulnerabilities. In addition, machines used by multiple people without accountability can be vulnerable to insider threats.

The complexity of academic environments amplifies this risk. Unlike corporate networks, educational institutions have to provide a network that supports students, professors, researchers, administrative staff, third-party contractors, and visitors. Each of these groups has different security requirements and access control levels, making it difficult to enforce consistent security policies. A security breach can have severe consequences since it may expose vast amounts of sensitive information, such as social security numbers (CPF in Brazil), addresses, phone numbers, and even parents’ names. Armed with this information, attackers can attempt phishing attacks and impersonate the victims in SIM swapping attacks, a common practice in Brazil.

In this article, we provide details about attacks on educational institutions in Brazil observed by our Global Emergency Response Team (GERT) since 2025. We share general statistics, common threats, initial access vectors, and the impact of such violations. Additionally, we present some interesting cases encountered by our team and the identified TTPs. Finally, we offer recommendations to help institutions protect themselves against future attacks.

Key findings and statistics

Our dataset encompasses incident response cases from January 2025 to June 2026. As the chart below shows, the majority of attacks targeted institutions in São Paulo state, Brazil’s most populous state and a significant center of economic and financial activity. We also had cases in Rio de Janeiro and Pernambuco.

Geographical distribution of incident response requests at educational institutions (download)

Of the customers who requested incident response, 60% were private institutions and 40% were public institutions.

Private and public institutions (download)

The most frequent reasons for requesting IR services were related to suspicious endpoint activities, encrypted files, and the presence of suspicious files.

Incident response request reasons (download)

High-severity incidents accounted for 40% of the total cases, while the remaining 60% were medium severity.

Distribution of incidents by severity (download)

The high-severity incidents were mainly related to ransomware attacks. Interestingly, private institutions were the most targeted by ransomware, while incidents in public institutions were mostly related to suspicious endpoint activity and privilege escalation attempts. The most common ransomware families found in our dataset were DragonForce and LockBit 3, whose builder was leaked back in 2022. By using the leaked LockBit builder with a valid privileged account, attackers can build variants capable of disabling defenses and erasing logs.

The most common initial access vectors included the use of valid accounts, exploitation of public-facing applications, and insiders.

Initial access vectors (download)

For privilege escalation, the attackers often relied on Potato variants (GodPotato, SweetPotato, and BadPotato).

We also observed attackers using tools like AnyDesk for remote access, PsExec for lateral movement within compromised infrastructures, and AV-killer malware to terminate the system’s defenses. The latter was mainly used in ransomware-related incidents.

These data reveal an interesting pattern in the threat landscape affecting educational institutions in the region. Many incidents were not caused by highly sophisticated techniques but rather by the abuse of common weaknesses such as valid accounts, exposed applications, and inadequate patch management, as well as the use of publicly available tools that are well-known to the adversaries. The prevalence of ransomware in private institutions suggests a stronger financial motivation, likely because attackers assume these organizations are more capable of paying for data recovery than public schools and universities.

Most attacks were discovered promptly and lasted from a few minutes to a couple of hours. However, technical incident response activities averaged 9.6 hours. This indicates that the impact caused by an incident often extends beyond the timeframe of the active attack, requiring extensive triage and analysis by the forensic investigators to fully restore operations.

One interesting fact is that we are still observing the use of Windows 10 in the infrastructures of educational institutions, even after Microsoft’s official end-of-support date of October 2025. In addition, we found that some customer organizations were using Windows Server 2016 without security patches and fixes. Using outdated and unsupported operating systems increases the attack surface of an infrastructure because attackers can exploit publicly available vulnerabilities to access vulnerable systems and expand their presence in the network. In addition, legacy operating systems may be incompatible with modern evidence collection tools, necessitating extra time and alternative procedures for forensic acquisition.

Obsolete systems in organizations (download)

Interesting cases Case 01 – Leaked LockBit builder

In one case, we identified the use of a custom version of LockBit that was generated using the leaked builder. The ransomware was delivered to the organization’s infrastructure via a valid account that had been leaked. It encrypted the organization’s internal systems, including file servers and databases that stored student profiles and other data. There was no evidence of data exfiltration from the affected machines.

During our analysis of the LockBit sample, we were able to extract its configuration. Interestingly, it was configured without the impersonation and spreading options. This meant the attacker had to perform manual lateral movement to deploy the malware across the network.

"config": { "settings": { "impersonation": false, "local_disks": true, "network_shares": true, "kill_processes": true, "kill_services": true, "set_wallpaper": true, "self_destruct": true, "kill_defender": true, "wipe_freespace": true, "psexec_netspread": false, "gpo_netspread": false, …

Further analysis revealed that the attacker used PsExec for lateral movement. By analyzing the Update Sequence Number (USN) Journal, we were able to identify .KEY files associated with PsExec that showed us the previously compromised machines used by the attacker.

After gaining access to the target machines, the adversaries deployed a batch script to disable the system’s defenses. Our analysis of this artifact showed that they had the administrative credentials to disable the EDR in place. In addition, the script enabled RDP, which gave the attackers remote access to the target. The listing below shows an excerpt of the script:

reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f netsh advfirewall firewall add rule name="allow RemoteDesktop" dir=in protocol=TCP localport=3389 action=allow reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableRealtimeMonitoring /t REG_DWORD /d 1 /f reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableBehaviorMonitoring /t REG_DWORD /d 1 /f reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableOnRealTimeProtection /t REG_DWORD /d 1 /f reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableIOAVProtection /t REG_DWORD /d 1 /f reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableScriptScanning /t REG_DWORD /d 1 /f reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SpyNetReporting /t REG_DWORD /d 0 /f reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SubmitSamplesConsent /t REG_DWORD /d 2 /f reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "SecurityHealth" /t REG_SZ /d "" /f reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{UUID}" /f reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v ServiceKeepAlive /t REG_DWORD /d 0 /f sc stop WinDefend sc config WinDefend start= disabled

Finally, by cross-checking the Prefetch files, we were able to identify the precise dates of PsExecSvc.exe and LBB.exe (LockBit) execution. This revealed that the attacker established the initial connection to the analyzed machine around 5:30am UTC and ran LBB.exe for the last time at 10am UTC on the same day, resulting in an activity window of approximately four hours and thirty minutes. We were able to identify the extent of the compromise and the additional machines that required network isolation for further forensic analysis, containment, and remediation.

Case 02 – DragonForce deployed via AnyDesk

In another incident, we identified a compromised user account that the adversaries used to install the AnyDesk software to enable remote access. Although the attacker erased the system logs after encrypting the victim’s files, we were able to identify the ransomware execution event via the Prefetch and Amcache.hve files, which provided us with the SHA-1 hash of the sample.

Once we obtained the SHA-1 of the malicious artifact (named by the attacker as 1.EXE), we were able to confirm that it was a DragonForce variant. Even though the lack of evidence made the analysis more difficult, this case shows that forensic investigators must be prepared to identify information that the attackers missed or left untouched.

Case 03 – Python keylogger used by an insider

The third incident illustrates how a series of bad practices enabled an insider to collect passwords from other users inside the infrastructure. First, the customer contacted us stating that a machine was exhibiting strange behavior: files containing passwords were being created. We started with triage collection on one of the affected machines.

Evidence from the Program Compatibility Assistant (PCA) showed the execution of two suspicious files, Windows Host Widgets.exe and Windows Host Widgets_.exe, both located in the C:\Users\<user>\.vscode\dlo directory, where <user> represents a user account shared by everyone who uses the machine. The same artifacts were identified within the Amcache.hve file, and multiple executions were also confirmed by analyzing the Prefetch files. Another interesting source of evidence, UserAssist, confirmed that the threat actor also executed both EXE files by double-clicking on them.

MFT analysis showed that multiple log files named cacheX.txt were created in the previously mentioned directory, where X was a number that increased with each malware execution. We then analyzed the EXE files to confirm their behavior. Luckily, both proved to be the same Python script, which we could easily decompile.

As shown in the listing below, the script contains methods and strings with Portuguese names. It is capable of hiding the log files from view in Explorer. The developer also set a procedure to identify when the Caps Lock key was pressed, in order to record the correct passwords.

def get_base_path(): ... def encontrar_proximo_nome(base='cache'): ... def set_file_hidden(filepath): ... ctypes.windll.kernel32.SetFileAttributesW(str(filepath), FILE_ATTRIBUTE_HIDDEN) ... with open(log_file, 'a', encoding='utf-8') as f: f.write(f'\n\n--- Registro iniciado em {datetime.datetime.now()} ---\n') set_file_hidden(log_file) ... def is_capslock_on(): return bool(ctypes.windll.user32.GetKeyState(20) & 1) ... def on_press(key): ... def on_release(key): ... def main(): with keyboard.Listener(on_press=on_press, on_release=on_release) as listener: listener.join() if __name__ == '__main__': main()

This simple script did not implement any persistence or automated data exfiltration mechanisms. Therefore, the insider likely had to manually retrieve the generated log files containing the text typed by the victims. By revisiting the previously collected evidence, we identified USB connections around the same time as the script’s executions. This suggests that removable media was probably used to collect the generated keylogging logs from the environment. As a result of the investigation, the customer changed the passwords of all affected accounts. However, without additional evidence or footage, it was not possible to conclusively attribute the activities to a specific individual and take the appropriate disciplinary and legal measures.

Conclusions and recommendations

The incidents highlighted in this article demonstrate that Brazilian educational institutions face a diverse set of threats, ranging from ransomware operations to insider activity. In many cases, the attackers relied on valid credentials, exposed services, remote access tools, poor patch management, and insufficient endpoint hardening rather than advanced malware or new techniques. Based on these findings, educational institutions should prioritize controls that reduce the likelihood of account compromise and the impact of ransomware deployment. They should also improve forensic visibility after an incident.

Institutions should enforce the use of multi-factor authentication (MFA) for all publicly accessible services, especially VPNs, remote access portals, and email accounts. Since valid accounts were one of the most common initial access vectors observed in our dataset, MFA can significantly reduce the likelihood that stolen or reused credentials alone will compromise the entire environment. We also recommend periodically reviewing privileged accounts, removing unnecessary administrative permissions, and avoiding shared accounts, especially on machines accessed by multiple users, since this makes accountability extremely difficult.

Each user should have their own account, following the principle of least privilege to prevent unauthorized software execution. Additionally, it is advisable to restrict and monitor the use of remote access tools such as AnyDesk or TeamViewer. Unexpected installations or executions of these tools should be treated as high-priority alerts.

To minimize the impact of ransomware, educational institutions should improve their backup and recovery strategy. Backups should be isolated from the primary environment (preferably in more than one location) and tested regularly. Centralized logging, extended EDR telemetry retention, and proper time synchronization across hosts can also improve the ability to reconstruct an attack timeline and implement the necessary response measures.

The use of outdated systems increases the attack surface, so we recommend that organizations adopt an effective update and patch management policy. It is also important to raise security awareness, since users must understand the risks associated with credential sharing, unknown executables, and unauthorized software.

From a digital forensics and incident response (DFIR) perspective, the reviewed incidents demonstrate that effective incident response activities require correlating multiple forensic artifacts in order to reconstruct the attacker’s actions. Investigators should be aware of how to find information even when logs are missing. Many other artifacts are preserved and can be used for this purpose, such as Amcache, PCA, Prefetch, UserAssist, MFT, and USN Journal. The attackers may fail to erase all traces of their activity, so taking a broad forensic approach is of the utmost importance for determining the scope of the compromise and supporting containment and remediation actions.

Observed TTPs

The table below shows the observed TTPs in our dataset, including cases not detailed in this post.

Tactic Technique ID Resource Development Compromise Accounts T1586 Collection Input Capture: Keylogging T1056.001 Execution System Services: Service Execution T1569.002 Execution Hijack Execution Flow: DLL T1574.001 Privilege Escalation Exploitation for Privilege Escalation T1068 Lateral Movement Remote Services: Remote Desktop Protocol T1021.001 Command and Control Remote Access Tools T1219 Exfiltration Exfiltration over Physical Medium: Exfiltration over USB T1052.001 Impact Data Encrypted for Impact T1486

Apple and the invisible wolf: AI slop drowns real security threats

Computerworld.com [Hacking News] - 3 Srpen, 2026 - 14:45

Apple has had to introduce a quota on security researcher reports because its systems are being overwhelmed by low-quality warnings generated by AI. 

It’s a classic illustration of the rule of unintended consequences: a technology meant to help us has become a barrier to getting things done. After all, not only has AI driven the cost of consumer electronics higher, but it is also being used to identify and exploit security vulnerabilities — while also overwhelming security teams with low-grade reports, thus eroding their attention span.

The cost of good intentions

This is what’s happened at Apple, as security researchers use AI as a tool to identify new bugs. Perhaps the reports are well-intended. Hopefully, the researchers aren’t just motivated by the promise of easy bug bounties. Or maybe this is a cynical attempt to overwhelm platform security teams with low-grade bug reports — while holding back larger attacks for actual use by well-resourced state-backed actors.

We can’t know whether attackers really are trying to overwhelm active platform defenses before going in for the kill. But given that it’s an actively used military strategy, it’s pretty hard to ignore the possibility.

Apple’s response

So, what’s happening at Apple? The company has put some limits in place to bug reporting as things got out of hand. It introduced a quota cap and a 30-day cool-off period for submitted reports, though researchers who exceed the cap can request an extension.

This follows Apple’s recent decision to increase its top security bounty payout to $5 million for the most severe exploits. Apple has paid out more than $35 million to around 800 researchers since launching its bug bounty program.

Financial Times report tells us the many of the reports were about identical bugs, some already resolved, some trivial, but in combination comprising a fog of war that made it harder and more time-consuming to identify the really big flaws. The situation became so febrile the company made the decision to put limits in place in June.

There is a little wriggle room to the approach: Apple has worked with the security community long enough to recognize some research teams. Those it trusts most can have their quota extended. Apple also deployed its own AI systems to triage incoming reports in an attempt to identify and remove AI-generated slop.

The company also uses internal systems from Anthropic and OpenAI to help identify and fix vulnerabilities; that led to an extensive collection of fixes in its most recent software patch.

The Times details an Italian company called Bynario, which identified a fairly nasty-sounding privilege escalation chain that lets attackers take complete control of a Mac. The company also reported a second bug, CVE-2026-43760, a macOS Screen Sharing flaw that allowed an authenticated VNC viewer to access protected data and create files with root privileges.

Unfortunately, the hard-working research team was unable to report the first bug, as it had filed more than 50 reports in just three weeks thanks to AI. In other words, it’s possible some security researchers right now are unable to file warnings of critical vulnerabilities to Apple because the system is overwhelmed by slop.

This is not just an Apple problem

What makes this far more problematic is that it isn’t just Apple that is affected – security teams on multiple platforms are grappling with the same problem. Rafe Pilling, a security expert at Sophos, told the FT that bug bounty programs across the industry have had to shift from finding vulnerabilities to validating reports of them “at machine speed.”

That follows comments from Jamf security expert Adam Boynton, who last week characterized AI use in security as, “an arms race between defenders and attackers who are both, increasingly, running the same kind of tools.”

When it comes to platform security, it is possible that AI has added a new dimension of complexity to an already complex environment. Hopefully, the real threats will continue to be swiftly identified as they emerge, rather than being wrongly characterized as AI slop.

When no one comes running

To understand how this works, try reading Aesop’s fable about a shepherd boy who raised the alarm so often that when the real wolf arrived, no one came to help and the young shepherd? He was eaten.

You can follow me on social media! Join me on BlueSky,  LinkedInMastodon and subscribe to The Core.

Kategorie: Hacking & Security
Syndikovat obsah