Threat Intel
11 storiesBehind the console: An AiTM phishing kit harvesting AWS console credentials and beyond
Datadog Security Labs dissects a June 2026 adversary-in-the-middle phishing kit that cloned the AWS console to harvest credentials and MFA tokens — a direct threat to any organisation managing cloud workloads via browser.
Datadog Security Labs9/10Lazarus Group's Latest: Brandjacking Campaign on npm
Lazarus Group escalates npm supply-chain attacks beyond typosquatting to brandjacking—mimicking legitimate package names via suffixes and version tricks to deliver second-stage payloads.
Sonatype Blog9/10Europe Evolves Into Ransomware's Favorite Region
Dark Reading reports ransomware groups are pivoting toward EU targets and their supply chains after a global lull, making European enterprises — especially Mittelstand firms — front-line targets.
Dark Reading9/10STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
Google's deep-dive into Turla's evolving .NET backdoor STOCKSTAY gives SOC teams fresh detection signatures for a Russia-linked APT that persistently targets European government and diplomatic networks.
Google Threat Intel9/10The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
The Gentlemen RaaS operation distributes a modular EDR-killer framework called GentleKiller that targets roughly 400 security processes, reflecting a maturing affiliate ecosystem focused on disabling defences before encryption.
THN (Feedburner)9/10DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic
DragonForce ransomware operators tunnel C2 traffic through Microsoft Teams relay infrastructure using a custom Go RAT called Backdoor.Turn, making malicious communications nearly indistinguishable from legitimate collaboration traffic.
THN (Feedburner)9/10Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses
Russia's FSB-linked Gamaredon group has upgraded its malware delivery and C2 infrastructure concealment, requiring defenders to refresh detection signatures and hunting hypotheses for this prolific Ukraine-focused operation.
Dark Reading8/10Turla group adds more malware to Russia’s espionage efforts against Ukraine
Google researchers detail StockStay, a fresh implant from Russia's Turla group, broadening the Kremlin's cyber-espionage toolkit aimed at Ukrainian targets — a reminder that state-level adversaries continually rotate tradecraft.
The Record8/10Five Eyes agencies sound alarm about AI’s threat to cybersecurity
Five Eyes agencies issued a joint alert warning that AI-enabled offensive capabilities are maturing within months rather than years, urging immediate defensive posture adjustments across critical sectors.
The Record8/10Amadey, StealC malware operations disrupted in Operation Endgame action
Europol-led Operation Endgame has dismantled Amadey and StealC infrastructure in a cross-border action involving Microsoft — a significant blow to the info-stealer ecosystem that feeds ransomware operators with stolen credentials.
BleepingComputer8/10FBI: Russian hackers now target Signal backup recovery keys
Russian intelligence operatives have evolved their Signal-targeting campaigns to steal backup recovery keys, granting access to full message histories — a significant escalation beyond real-time interception.
BleepingComputer8/10
DevSecOps
6 storiesNode-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp
A novel npm worm abuses node-gyp's binding.gyp compilation step to execute code without lifecycle scripts—evading the standard mitigations that registries and lockdown tools rely on, while also persisting through GitHub token theft.
Snyk Blog9/10Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
The Miasma malware family has expanded from npm into Go packages and now abuses GitHub Actions workflows, demonstrating how polyglot supply-chain attacks can propagate across multiple ecosystems simultaneously.
THN (Feedburner)9/10Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets
Attackers hijacked codfish/semantic-release-action by retagging v2–v5 to a credential-stealing payload, exposing CI/CD secrets of any project that pinned to mutable version tags.
Aikido9/10'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows
Malicious pull requests dubbed 'Cordyceps' exploit CI/CD workflow weaknesses in major projects including Azure Sentinel, Google AI Dev Kit, and Cloudflare Workers — a supply-chain threat at the build-pipeline level.
Dark Reading9/10A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope
A dormant contributor account was hijacked to republish every package in the @mastra npm scope with an injected crypto-stealer dependency, illustrating how forgotten accounts with residual publish rights become the weakest link in scope ownership.
Snyk Blog9/10npm v12 delivers one of the biggest security improvements in years
npm v12 defaults install scripts to opt-in, effectively closing the most exploited execution vector behind this year's wave of supply-chain worms — a structural security improvement enterprise teams should fast-track.
Aikido9/10
AI Security
4 storiesInherited Circuits, Learned Semantics: How Fine-Tuning Creates Evasion Vulnerabilities Invisible to Standard Evaluation
Fine-tuned LLM security classifiers can inherit hidden evasion paths invisible to standard test sets, meaning enterprises using fine-tuned models for malware or phishing detection may harbour blind spots.
arXiv Crypto & Security9/10Computer-Use and TOCTOU: What You Click Is Not What You Get!
Research reproduces a time-of-check/time-of-use flaw in AI agents with computer-use capabilities, showing that UI elements can be swapped between approval and execution to hijack automated actions.
Embrace The Red (AI Security)9/10FreeBSoD: Leveraging Language Models to Find and Exploit Kernel Bugs (Part 1 of 2)
Praetorian used Claude to discover and exploit FreeBSD kernel bugs — demonstrating that LLM-assisted vulnerability research is crossing from theory into practical 0-day output.
Praetorian9/10Interesting Paper Exploring Prompt Injection
Schneier highlights research showing LLMs learn to recognise instruction-block text styles rather than just tags, meaning prompt-injection defences built on role delimiters alone are fundamentally brittle.
Schneier on Security9/10
Research
3 storiesChai: Agentic Discovery of Cryptographic Misuse Vulnerabilities
Chai uses agentic AI to discover cryptographic misuse vulnerabilities — a bug class that resists traditional fuzzing — offering potential for automated crypto-hygiene audits in enterprise codebases.
arXiv Crypto & Security9/10Disposable Tooling: Building LLM-Generated Mythic Agents from Prompt to Deployment
SpecterOps demonstrates how LLMs can generate single-use Mythic C2 agents on demand, lowering the barrier for signature-evasive offensive tooling that defenders must now plan for.
SpecterOps9/10Embedding Forbidden Text in Spyware to Discourage AI Analysis
Malware authors are embedding content about nuclear and biological weapons into spyware code to trigger AI safety guardrails and block automated analysis — a creative anti-analysis technique that undermines AI-driven threat detection.
Schneier on Security9/10
Vulnerabilities
2 storiesMandiant reveals how Cisco SD-WAN zero-day attacks gained root access
Mandiant details how attackers exploited CVE-2026-20245 in Cisco Catalyst SD-WAN to gain root and create rogue accounts — enterprises running affected appliances need immediate patching.
BleepingComputerCVE-2026-202457.89/10[UPDATE] [hoch] Microsoft Exchange: Mehrere Schwachstellen
BSI updates its high-severity Microsoft Exchange advisory covering admin-takeover, RCE, and spoofing — given Exchange's history as an APT target, European organisations should verify patch status urgently.
CERT-Bund (BSI)8/10
Compliance
2 storiesProbabilistic Agents in Deterministic Audits: Evaluating Multi-Agent Systems for Automated Audits Based on the German IT-Grundschutz
Companion study evaluates multi-agent LLM systems performing automated IT-Grundschutz audits, quantifying where probabilistic AI outputs clash with deterministic compliance requirements under NIS2.
arXiv Crypto & Security9/10An Approach for a Supporting Multi-LLM System for Automated Certification Based on the German IT-Grundschutz
Multi-LLM system with hybrid RAG automates large portions of BSI IT-Grundschutz certification — directly relevant to German Mittelstand organisations facing NIS2 compliance deadlines with limited audit resources.
arXiv Crypto & Security9/10
Regulatory
2 storiesAI and Liability
A German court ruling holds Google liable for AI-generated search summaries, rejecting the defence that users should verify AI outputs — setting a precedent that may shape EU AI Act liability interpretation.
Schneier on Security8/10Trump directs federal agencies to protect US data from quantum threats
A US executive order mandating federal post-quantum cryptography migration signals that European enterprises — especially those in transatlantic supply chains — should accelerate their own PQC readiness assessments now.
The Record8/10
Security
1 storyBoardroom Brief
What this week's reporting means for the board, in one line per story.
- Behind the console: An AiTM phishing kit harvesting AWS console credentials and beyond
A new phishing kit bypasses MFA to steal AWS admin access — organisations should move to phishing-resistant authentication immediately.
- Inherited Circuits, Learned Semantics: How Fine-Tuning Creates Evasion Vulnerabilities Invisible to Standard Evaluation
AI-based security tools may miss threats if their evaluation methods fail to account for vulnerabilities introduced during model customisation.
- Chai: Agentic Discovery of Cryptographic Misuse Vulnerabilities
AI-driven detection of cryptographic implementation flaws could automate a historically manual and error-prone audit process.
- Computer-Use and TOCTOU: What You Click Is Not What You Get!
AI agents that interact with screens can be tricked by race conditions into performing unintended actions — a growing risk as enterprises automate workflows.
- Disposable Tooling: Building LLM-Generated Mythic Agents from Prompt to Deployment
AI now lets attackers auto-generate unique, hard-to-detect hacking tools — pushing defenders toward behaviour-based detection.
- Embedding Forbidden Text in Spyware to Discourage AI Analysis
Attackers are weaponising AI safety filters against defenders, potentially blinding automated threat analysis pipelines.
- FreeBSoD: Leveraging Language Models to Find and Exploit Kernel Bugs (Part 1 of 2)
Language models are now finding and exploiting real kernel vulnerabilities, compressing attacker timelines and demanding faster defensive response.
- Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access
A zero-day in widely deployed Cisco SD-WAN gear gave attackers full root access — patching and forensic review are urgent.
- Interesting Paper Exploring Prompt Injection
New research shows that the main technique used to protect AI chatbots from manipulation is weaker than assumed, raising risk for enterprises using LLM-powered automation.
- Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp
A new npm worm bypasses established supply-chain defences by hiding in native build files, requiring updated security controls across developer toolchains.
- Lazarus Group's Latest: Brandjacking Campaign on npm
A North Korean threat group is targeting software supply chains with increasingly sophisticated package impersonation on npm.
- Europe Evolves Into Ransomware's Favorite Region
Europe is now ransomware's top target region — boards must ensure incident-response and regulatory-reporting capabilities match the elevated threat.
- STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
Russia-linked Turla continues evolving espionage tools targeting European institutions — fresh intelligence enables proactive defence.
- The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
Ransomware gangs now ship dedicated tools to disable endpoint security before encryption, making EDR tamper-resistance a board-level investment question.
- DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic
Ransomware actors are hiding command-and-control traffic inside Microsoft Teams infrastructure, making detection extremely difficult without advanced monitoring.
- Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
A supply-chain attack campaign now spans multiple programming ecosystems and CI/CD systems, broadening exposure for software-producing organisations.
- Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets
A compromised open-source CI/CD component may have exfiltrated repository credentials from any project that used it.
- 'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows
A new class of supply-chain attack targets the build pipelines of major open-source projects that enterprises depend on daily.
- A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope
An abandoned developer account was exploited to inject malware across an entire npm scope—dormant access rights are a supply-chain liability.
- npm v12 delivers one of the biggest security improvements in years
A fundamental change in the npm package manager now blocks the primary attack vector behind recent supply-chain compromises by default.
- Probabilistic Agents in Deterministic Audits: Evaluating Multi-Agent Systems for Automated Audits Based on the German IT-Grundschutz
Research highlights reliability limits of AI-driven audit automation that boards should weigh before scaling adoption.
- An Approach for a Supporting Multi-LLM System for Automated Certification Based on the German IT-Grundschutz
AI-assisted automation of BSI IT-Grundschutz certification could materially reduce NIS2 compliance costs for mid-market firms.
- Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses
A highly active Russian state hacking group has significantly improved its capabilities, raising risk for organisations connected to Ukraine.
- Turla group adds more malware to Russia’s espionage efforts against Ukraine
Russia's top cyber-espionage unit is fielding new malware; organisations with Eastern-European operations should verify detection coverage.
- AI and Liability
A German court precedent makes companies liable for their AI's outputs, foreshadowing stricter accountability under upcoming EU AI Act enforcement.
- [UPDATE] [hoch] Microsoft Exchange: Mehrere Schwachstellen
Critical Exchange vulnerabilities could allow full mail-system takeover — immediate patching verification recommended.
- Five Eyes agencies sound alarm about AI’s threat to cybersecurity
Allied intelligence agencies warn that AI-driven cyber threats are advancing on a timeline of months, requiring accelerated investment in adaptive defences.
- Amadey, StealC malware operations disrupted in Operation Endgame action
A Europol-led takedown disrupted two major malware platforms that supply stolen credentials to ransomware groups, temporarily easing enterprise exposure.
- FBI: Russian hackers now target Signal backup recovery keys
Russian intelligence now targets Signal backup keys for full message history access — a direct threat to secure executive communications.
- Trump directs federal agencies to protect US data from quantum threats
US government PQC mandates will reshape procurement expectations for European suppliers within this decade.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.