Agregátor RSS
EXCLUSIVE There's no honor among thieves as a new worm steals from other infectious software. It pilfers “multiple” victims’ credentials and mines for cryptocurrency while killing competitors’ processes, including similar secret-harvesting malware. It’s called Cloud AI Infrastructure Attack Framework (CAI), and it’s a centralized botnet that targets cloud-native developer tools like Docker, Kubernetes, Redis, etcd, Kubelet, and Ray for credential theft and cryptomining. The scripts “are heavily inspired” by the likes of other similar credential-stealing worms that have wreaked havoc across cloud environments and supply chains this year, “using code comments like ‘PCPJack-aligned,’” according to security researcher Michael R. “CAI explicitly seeks out and kills TeamPCP and PCPJack processes, to further monopolize on compromised targets,” he posted on X. TeamPCP is the malware-developing crew behind the mini Shai-Hulud, Miasma, and Canister worms that have been poisoning open source registries and harvesting cloud access tokens, credentials, API keys, and other sensitive data since the Trivy supply-chain attack earlier this year. And PCPJack is a newer secret-stealing copycat worm that not only nabs credentials, but also deletes TeamPCP artifacts to kick that competitor out of victims’ cloud infrastructure. CAI seems to have taken lessons from both. “CAI is a constantly evolving framework meant to rival toolkits utilized by TeamPCP and PCPJack,” Hunt.io threat researcher Michael Rippey told The Register. Hunt.io’s team was the first to spot CAI on June 15, when it observed the first of three open directories via the security shop’s web-scanning engine, AttackCapture, that were linked to the operator. “Over three weeks, the operator moved from testing worm code mimicking TTPs used by PCPJack, to full production, deployment and compromise of networks,” Rippey said. “The codebase shows signs of LLM-assisted development, reflecting a deliberate progression of someone studying what works to build a competitive platform.” While the malware isn’t “overly sophisticated,” it is effective, with recent command-and-control logs confirming “active exploitation attempts, with wallet activity confirming multiple successful compromises,” Rippey said. CAI’s framework consists of a “scanning engine [that] feeds targets into automated exploit queues, with centralized C2 control coordinating attacks across cloud infrastructure with an emphasis on Docker, Redis, etcd, Kubelet, and more,” he added. “Currently, compromised hosts receive miners, credential stealers, and a Python backdoor,” Rippey said. “CAI’s emergence alongside TeamPCP and PCPJack indicates a growing number of competing threat actors targeting each other and cloud infrastructure.” Defenders and developers alike should take note, as we’ve already seen the damage that these new-ish cloud worms leave in their wake as they burrow across supply chains. Plus, it’s unlikely that this will be the last of the miscreants seeking to monetize companies’ cloud infrastructure and developers’ secrets.®
A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim's phone, steal their banking logins, and capture the one-time codes that protect their accounts.
Zimperium's zLabs, which found the operation, says it looks like a new variant of Oblivion, a $300-a-month rent-a-malware tool
A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim's phone, steal their banking logins, and capture the one-time codes that protect their accounts.
Zimperium's zLabs, which found the operation, says it looks like a new variant of Oblivion, a $300-a-month rent-a-malware tool Swati Khandelwalhttp://www.blogger.com/profile/ [email protected]
PACT chce nahradit CAPTCHA anonymním ověřováním důvěryhodnosti uživatelů. • Webům slibuje lepší ochranu proti botům bez narušení soukromí. • Zároveň ale může změnit fungování otevřeného webu.
A critical flaw in Google's Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google Cloud project.
From there, they could read live conversations, steal the data users shared, and make the bots send attacker-written messages, including requests to re-enter a password.
Security firm Varonis found it
A critical flaw in Google's Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google Cloud project.
From there, they could read live conversations, steal the data users shared, and make the bots send attacker-written messages, including requests to re-enter a password.
Security firm Varonis found it Swati Khandelwalhttp://www.blogger.com/profile/ [email protected]
Eight victims of Greece’s spyware scandal, later dubbed “Predatorgate,” have sued the Athens-based company behind the program used to surveil them. According to the Predator victims’ lawyer, Zacharias Kesses, each of the plaintiffs is asking for €1 million in moral damages after having their devices hacked between 2020 and 2021. Among those seeking damages is journalist Thanasis Koukakis, who was one of the most high-profile victims at the time. Others include lawyers, intelligence officials, law enforcement workers, and more. Kesses said that the lawsuit was directed at Intellexa SA and 13 individuals associated with it, including founder Tal Dilian. “The lawsuits detail the structure, operation and division of roles of the network of companies and individuals associated with the development, distribution and use of Predator,” Kesses told Greek newspaper Kathimerini. “This process constitutes the next institutional step towards full accountability of all those involved and redress for victims, both at national and European levels.” Intellexa is a distinct Athens-based corporate entity, but also the name of a consortium of other companies that sit around it as holding companies and vendors, all registered in different jurisdictions. Put simply, it developed Predator spyware, one of the most capable offerings of its kind. Athens-based Intellexa SA, Irish companies Intellexa Limited and Thalestris Limited, North Macedonia-based Cytrox AD, and Hungary-based Cytrox Holdings were all added to the US Treasury’s sanctions list in 2024 for their roles in supporting Predator spyware. Key figures such as consortium founder Dilian and his ex-wife Sara Hamou, a corporate offshoring specialist who worked for the consortium, joined the organizations on the list at the same time. Both Dilian and Hamou, as well as Greeks Felix Bitzios and Yiannis Lavranos, a former Intellexa boss and owner of Krikel, a Predator vendor, respectively, were found guilty earlier this year of violating telephone communications confidentiality and illegally accessing personal data. An Athens misdemeanors court sentenced each to 126 years and eight months in prison, pending appeals, although domestic law would cap these at eight years. Greek government officials have continuously waved away the numerous accusations that it, or its intelligence services, were behind the attacks on Greeks in 2020-2021. A resulting probe into Predatorgate revealed that at least 87 high-profile Greeks were targeted by Predator spyware via hundreds of SMS messages containing malicious links that exploited Chrome and Android zero-day vulnerabilities. Civil liberties groups, such as Amnesty International, continue to question whether the state was in any way involved in the procurement of Predator for use in these attacks, despite its repeated denials. A 2024 Supreme Court prosecutor's probe found no evidence that the Greek government or its intelligence services were involved in the scandal, which first came to light in 2022. The Greek spyware scandal came at a similar time as others like it involving other EU member states, including Spain, Hungary, and Poland. Frustrated at the lack of action following these separate cases, campaigners co-signed an open letter this week calling on the EU to properly investigate and attribute each of the illegal spyware attacks that have occurred across member states. ®
Začalo to skriptem v Pythonu pro hledání historického počasí, který Jakub Čížek zveřejnil na X. Pokračovalo projektem pro AI agenty a nakonec tímto článkem. Na hračce s počasím lze totiž pěkně ukázat, jak AI agenti fungují a jak je využít pro vytvoření zajímavé aplikace. Ta naše najde bez ...
The National Police in Spain have arrested a man who is suspected of being an active member of the CyberArmy of Russia Reborn (CARR) and Z-Pentest, both pro-Russian hacktivist groups. [...]
A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC.
"The campaign did not depend on a fake Microsoft password page. It used a malicious collaboration-style lure to push users into the legitimate Microsoft device login experience,
A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC.
"The campaign did not depend on a fake Microsoft password page. It used a malicious collaboration-style lure to push users into the legitimate Microsoft device login experience,Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
A 16-year-old KVM vulnerability recently hit the news, and honestly? It’s a healthy dose of reality. We like to think of our hypervisors as these impenetrable walls, but this is a reminder that VM isolation isn't a permanent guarantee. Even in the most mature Linux virtualization stacks, you’ve got code paths that haven't been touched in over a decade, just waiting for the right researcher to pull on the wrong thread. For those of us running KVM hosts, this isn't just about grabbing the late...
One of the easiest mistakes to make in detection engineering is assuming a rule keeps working simply because nobody has touched it. Most of the time, nobody removes the rule. Nobody disables it. It just gets forgotten.
A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization's private repositories, researchers at Noma Security have shown.
The attacker needs only to open a normal-looking issue on a public repository, with no stolen credentials and no access to the organization. If that organization has given the agent read access across its repositories, private ones
A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization's private repositories, researchers at Noma Security have shown.
The attacker needs only to open a normal-looking issue on a public repository, with no stolen credentials and no access to the organization. If that organization has given the agent read access across its repositories, private ones Swati Khandelwalhttp://www.blogger.com/profile/ [email protected]
ActiveState explains how GitHub Actions attack chains can evade traditional CI security scanners, why passing a scan doesn't guarantee a secure pipeline, and how organizations can better govern their CI/CD workflows. [...]
Scientists used AI to find targets shared by thousands of related viruses and build what they hope is a universal vaccine.
Researchers at the University of Cambridge have developed what they describe as a fundamentally new type of vaccine using artificial intelligence. The vaccine’s key component was designed entirely by AI and has now been tested in people for the first time.
The goal is ambitious: a single vaccine that works not just against all known human coronavirus variants, but against related bat viruses that could jump from animals to humans and cause future pandemics.
Traditional vaccines train our immune system to recognize one specific virus. The problem is that viruses mutate. When they change enough, the vaccine stops working, which is why we need a new flu shot every year and why Covid vaccines have been updated repeatedly since 2021.
AI offers a way around this. By analyzing genetic data from thousands of related viruses, it can identify the parts that stay the same across different strains and that are unlikely to change over time. Target those stable features, and you have a vaccine that should work against the whole family, not just the strain you started with.
This is exactly what the Cambridge team did. They used AI to scan viruses from the sarbecovirus family, which includes the viruses that cause both SARS and Covid, as well as a range of animal coronaviruses—looking for shared features that evolution has left largely untouched. Those features became the basis of the vaccine.
DNA Vaccines
While many people are familiar with the mRNA shots used during the pandemic, this new vaccine uses DNA. DNA vaccines are generally more stable than mRNA vaccines, making them easier to store and transport. This is a significant advantage in lower-income countries where “cold-chain” infrastructure is limited.
They can also be administered without needles. A high-pressure stream of liquid delivers the vaccine through the skin, making administration less painful and easier to scale up during an outbreak.
Could It Protect Against Future Pandemics?
These practical advantages matter most if the vaccine itself can do something no existing jab can: protect against viruses we haven’t encountered yet.
Broad-spectrum vaccines could change the way the world responds to emerging infectious diseases. By offering much wider protection than traditional vaccines, they could provide rapid immunity against new and emerging viral threats. This would equip public health officials with tools to stop future outbreaks in their tracks before they have a chance to turn into global pandemics.
They could also transform our approach to more familiar diseases. Influenza is a prime target because it exists in many different strains and evolves so rapidly. Scientists have to predict which strains will dominate each flu season, and if they guess wrong, vaccine effectiveness can suffer. A universal flu vaccine that targets features shared across multiple strains could eventually end the annual race to keep up with the virus.
The Ebola virus shows why this matters right now. The recent outbreak in the Democratic Republic of the Congo and Uganda is driven by the Bundibugyo strain, which bypasses existing vaccines. While researchers rush to create a new vaccine specifically for this strain, local communities remain at high risk. A broad-spectrum vaccine designed to cover an entire virus family could transform that picture.
What the Trial Found
This is the first human trial of an AI-designed vaccine. The results showed that this DNA vaccine was able to stimulate the immune system to produce antibodies that can recognize different types of sarbecoviruses. The technology was found to be safe and well tolerated.
This is an exciting advance because it demonstrates how AI has the potential to design variant-proof vaccines against future pandemic threats. The needle-free delivery system could also make the vaccine easier to administer and distribute worldwide.
However, there is more work to do. Although the results in this study are encouraging, the immune responses following vaccination were modest. It was also uncertain how long the protection lasts and whether further boosters will be required. Larger trials are also needed to determine whether the vaccine can prevent or reduce viral infections in the real world.
A universal vaccine remains a few years away. And any new vaccine must still pass larger trials to prove it is safe, effective, and provides lasting protection. But this study shows the goal is getting closer—and AI may help us get there faster.
This article is republished from The Conversation under a Creative Commons license. Read the original article.
The post The First AI‑Designed Vaccine Has Been Tested in People. Here’s What Happened. appeared first on SingularityHub.
První česká družice navržená a sestavená výhradně studenty se dostala na oběžnou dráhu Země. Družice KOSTKA, kterou vyvinul studentský tým YSpace z Vysokého učení technického v Brně (VUT), dnes odstartovala na palubě rakety Falcon 9 společnosti SpaceX v rámci mise Transporter-17 z kalifornské základny Vandenberg Space Force Base.
|