Vulnerabilities
15 storiesRansomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Anubis ransomware affiliates are chaining the new Citrix Bleed 2 flaw (CVE-2025-5777) with BYOVD and compromised supply-chain credentials — a converging-TTPs pattern that demands layered perimeter and endpoint defences.
THN (Feedburner)9/10Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts
Active exploitation of CVE-2026-8037, a pre-authentication RCE in Progress Kemp LoadMaster, is confirmed — organisations using this widely deployed load balancer should treat patching as an emergency.
THN (Feedburner)9/10[UPDATE] [kritisch] Node.js: Mehrere Schwachstellen
Critical Node.js update addresses RCE, privilege-escalation, and data-manipulation flaws — given Node's prevalence in European web stacks, patching is urgent to avoid supply-chain compromise.
CERT-Bund (BSI)9/10New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
CVE-2026-46242 (
THN (Feedburner)9/10CISA: Microsoft SharePoint RCE flaw now actively exploited
Active exploitation of a patched SharePoint RCE flaw underscores the perennial patch-lag risk for enterprises still running on-prem collaboration stacks.
BleepingComputer9/10[UPDATE] [hoch] Red Hat Enterprise Linux (runc): Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen
Updated BSI advisory addresses runc security-bypass flaws in RHEL and OpenShift — container escape risks remain relevant for any Kubernetes-based workload.
CERT-Bund (BSI)8/10Authentication Bypass in the default configuration phpBB
A critical phpBB authentication bypass (CVE-2026-48611) lets an unauthenticated attacker hijack any account with a single request in default configurations — immediate patching is warranted for any exposed forum.
Aikido8/10[NEU] [hoch] Microsoft 365 Copilot: Schwachstelle ermöglicht Privilegieneskalation
A high-severity privilege-escalation flaw in Microsoft 365 Copilot could let a remote attacker elevate access within AI-assisted workflows—especially concerning for enterprises relying on Copilot for sensitive document summarisation.
CERT-Bund (BSI)8/10[NEU] [hoch] Kibana: Mehrere Schwachstellen
High-severity Kibana flaws allow authenticated attackers to execute arbitrary code and bypass security controls—directly threatening SIEM visibility for Elastic-based SOCs.
CERT-Bund (BSI)8/10[UPDATE] [hoch] Vercel Next.js: Mehrere Schwachstellen
BSI flags high-severity Next.js flaws enabling auth bypass, XSS, and data leakage — organisations relying on Next.js for customer-facing portals should prioritise patching before exploitation chains emerge.
CERT-Bund (BSI)8/10Apple Reverses Age-Old Patch Policy to Keep Up With AI
Apple is compressing its patching cadence in response to AI-accelerated exploit development, a shift that forces enterprise Mac fleets to rethink change-management windows and testing pipelines.
Dark Reading7/10[NEU] [hoch] Microsoft Exchange Online: Schwachstelle ermöglicht Privilegieneskalation
A privilege-escalation flaw in Exchange Online means an authenticated attacker could gain elevated mailbox or tenant rights — a high-value target for business-email-compromise scenarios in Microsoft 365 environments.
CERT-Bund (BSI)7/10[NEU] [hoch] Coolify: Mehrere Schwachstellen
BSI flags high-severity flaws in the self-hosted PaaS Coolify — RCE, privilege escalation, and data disclosure risks affect teams using it as an alternative to managed cloud platforms.
CERT-Bund (BSI)7/10[NEU] [hoch] Microsoft Azure und Entra: Mehrere Schwachstellen ermöglichen Privilegieneskalation
Multiple privilege-escalation vulnerabilities in Azure and Entra could let authenticated attackers elevate access across identity and cloud services — critical for hybrid-cloud enterprises relying on Microsoft IAM.
CERT-Bund (BSI)7/10[NEU] [hoch] Dell PowerProtect Data Domain: Mehrere Schwachstellen
Multiple high-severity flaws in Dell PowerProtect Data Domain allow privilege escalation, code execution, and security-bypass—critical for enterprises using these appliances as last-line backup defence against ransomware.
CERT-Bund (BSI)7/10
Threat Intel
13 storiesNorth Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
Lazarus-linked actors scaled the PolinRider campaign to 108 malicious packages across npm, Packagist, Go, and Chrome extensions — a multi-ecosystem poisoning effort that dramatically widens developer supply-chain exposure.
THN (Feedburner)9/10The Gentlemen are knocking: сustom backdoors and evolving tactics
Kaspersky's deep-dive into The Gentlemen RaaS operation reveals custom backdoors and evolving TTPs — useful detection material for SOCs tracking the growing fragmentation of the ransomware-as-a-service landscape.
Securelist (Kaspersky)9/10ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
Cisco Talos exposes ARToken, a phishing-as-a-service panel with 80+ API endpoints purpose-built for device-code phishing, token persistence, and BEC against Microsoft 365 — industrialising an attack chain that bypasses MFA.
Cisco Talos9/10From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
The full DFIR Report expands on the Bumblebee-to-Akira kill chain with dual-intrusion data from Swisscom B2B CSIRT, providing deeper IOCs and lateral-movement TTPs useful for detection engineering.
The DFIR Report9/10FortiBleed credential-theft campaign linked to Lynx ransomware
Stolen Fortinet VPN credentials from a mass-harvesting campaign are now tied to ransomware operators, raising the stakes for any enterprise that delayed credential rotation.
BleepingComputer9/10CISA: Windows BlueHammer flaw now exploited by ransomware gangs
Ransomware operators have weaponised a Microsoft Defender privilege-escalation zero-day ("BlueHammer"), prompting CISA to mandate patching — European firms should treat this as an urgent patch-now event given the escalation from targeted to commodity exploitation.
BleepingComputer9/10FBI Seizes NetNut Proxy Platform, Popa Botnet
FBI seized domains of NetNut, a residential proxy service run by Israel-listed Alarum Technologies, and the associated Popa botnet—highlighting how legitimate-seeming proxy infrastructure enables credential-stuffing and fraud at scale.
Krebs on Security8/10Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects
Kaspersky's 2025 compromise-assessment engagements reveal that many organisations harbour persistent intrusions missed by existing tooling, highlighting gaps in detection coverage and response readiness.
Securelist (Kaspersky)8/10New Avalon Malware Framework Packs CrownX Ransomware Capabilities
The newly discovered Avalon framework combines credential harvesting, lateral movement, and the CrownX ransomware module in a single modular toolkit — delivered via multi-stage phishing that evades conventional gateway controls.
THN (Feedburner)8/10NetNut proxy network disrupted, 2 million infected devices cut off
Google-backed disruption of NetNut cut off two million compromised Android devices—including smart TVs—underscoring how consumer IoT becomes proxy infrastructure that enterprises inadvertently trust.
BleepingComputer8/10U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
Blockchain-traced evidence shows a US government entity paid roughly $1 million to the Kairos extortion group, underscoring how even well-resourced public-sector organisations sometimes capitulate to data-leak threats.
THN (Feedburner)7/10Medtronic notifies customers impacted by ShinyHunters data breach
Medtronic is notifying customers after the ShinyHunters breach exposed personal data, adding another healthcare-device maker to the growing list of medical-sector data-breach disclosures.
BleepingComputer7/10The Good, the Bad and the Ugly in Cybersecurity – Week 27
Weekly roundup covers the FBI arrest of an IRGC-linked actor, Russian threat groups harvesting Signal backup keys, and an intrusion into a DHS network—three stories that underscore state-level targeting of Western government comms.
SentinelOne Blog7/10
AI Security
9 storiesCloak and Detonate: Scanner Evasion and Dynamic Detection of Agent Skill Malware
Researchers show that malicious third-party skills for LLM coding agents evade static scanners but can be caught at runtime, highlighting an emerging supply-chain vector relevant to any team adopting AI-assisted development.
arXiv Crypto & Security9/10KidnapRAG: A Black-Box Attack for Hijacking Reasoning in Agentic Retrieval-Augmented Generation Systems
Black-box poisoning attack on agentic RAG systems bypasses iterative retrieval defences, showing that multi-step reasoning alone does not neutralise knowledge-base manipulation.
arXiv Crypto & Security9/10(A)I Sees What You Don't: Exploiting New Attack Surfaces in Third-Party Mobile Agents
New research maps out how VLM-driven mobile agents inherit high-privilege attack surfaces through screenshot-based perception, raising supply-chain trust questions for enterprise BYOD policies.
arXiv Crypto & Security9/10Fake Bug Report Hijacks AI Coding Agents at Scale
Researchers demonstrate 'agentjacking' — injecting malicious instructions into fake bug reports that AI coding agents process as trusted input, enabling supply-chain compromise at scale without human review catching the manipulation.
Dark Reading9/10Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
Unit 42 details how attackers register domains that LLMs frequently hallucinate, turning AI-assisted coding into a supply-chain entry point — a novel twist on dependency confusion that raises the bar for SBOM validation.
Unit 42 (Palo Alto)9/10Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.
IBM is committing 20,000 engineers and $5 billion to remediate open-source vulnerabilities surfaced by Anthropic's AI bug-hunting model, igniting debate over automated discovery outpacing patch capacity.
Dark Reading8/10GPT-5.5-Cyber built a zlib fuzzing lab in a day
Trail of Bits reports that GPT-5.5-Cyber built a complete zlib fuzzing lab in one day during its Patch the Planet initiative, highlighting both the promise and the vulnerability-flood risk advanced models pose for open-source maintainers.
Trail of Bits8/10How to Compare the Security of Code Written by Humans to LLM-generated Code
Researchers propose a methodology for benchmarking the security posture of LLM-generated code against human baselines—an essential step before enterprises adopt AI coding assistants at scale.
arXiv Crypto & Security8/10SurrogateShield: Beyond Redaction for High-Utility, Privacy-Preserving LLM Interactions
SurrogateShield replaces PII with functional surrogates before queries reach third-party LLM APIs, offering higher utility than simple redaction while reducing GDPR exposure.
arXiv Crypto & Security7/10
DevSecOps
5 storiesHow GitHub used secret scanning to reach inbox zero
GitHub eliminated 20,000+ secret-scanning alerts across 15,000 repos in nine months by triaging signal from noise and building automated remediation — a practical blueprint for large-scale credential hygiene.
GitHub Security Blog9/106 security settings every GitHub maintainer should enable this week
GitHub's official hardening checklist targets maintainers with six free repo-level controls that reduce supply-chain attack surface — useful as a baseline audit for internal OSS governance.
GitHub Security Blog9/10Summer of Clearinghouses
Chainguard argues that vulnerability clearinghouses are necessary but insufficient — enterprises need trusted builds, SBOM actuation, and secure-by-design practices to meaningfully reduce open-source risk.
Chainguard8/10SAGA: Detecting Security Vulnerabilities Using Static Aspect Analysis
SAGA applies static aspect analysis to Python codebases, broadening vulnerability coverage beyond what current SAST tools detect — potentially useful for teams with large Python microservice estates.
arXiv Crypto & Security8/10And another one. GitHub ships break-glass credential revocation
GitHub Enterprise now supports emergency credential revocation, a capability driven by repeated secret-leak incidents in projects like Trivy — critical for enterprises with large developer populations.
Aikido8/10
Security
4 storiesSpyware found on phone of European Parliament member probing it
Pegasus spyware infected the phone of an MEP who was actively investigating commercial surveillance abuse — a direct compromise of EU democratic oversight that intensifies the political case for stricter spyware regulation.
The Record9/10Microsoft accelerates quantum-safe roadmap as risks grow
Microsoft is fast-tracking post-quantum cryptography adoption, signalling that harvest-now-decrypt-later risks are materialising sooner than industry timelines assumed — EU enterprises should benchmark their own migration readiness.
BleepingComputer7/10When Too Much Security Data Became the Risk
A CISO case study illustrates how unchecked firewall-log ingestion ballooned SIEM costs and created a noise problem, resolved by applying AI-driven data filtering to prioritise security-relevant telemetry.
Dark Reading7/10Cybersecurity Mission Creep in the US
Schneier highlights research arguing that US policymakers are stretching the cybersecurity label to cover misinformation, child safety, and antitrust — a scope expansion that may dilute genuine security mandates.
Schneier on Security7/10
Regulatory
3 storiesSupreme Court decision threatens EU-US data transfer agreement
Privacy advocate Max Schrems plans to challenge the EU-US Data Privacy Framework after a Supreme Court ruling weakened judicial oversight, raising the spectre of a third transatlantic data-transfer collapse.
The Record10/10Overview of Risk Assessment and Management for Intelligent Systems under the AI Act and Beyond
A comprehensive overview maps AI Act risk-assessment obligations to existing frameworks, giving compliance teams a practical crosswalk for high-risk AI system classification and documentation.
arXiv Crypto & Security8/10US lifts export controls on Anthropic’s frontier cybersecurity AI models
The US has eased export restrictions on Anthropic's frontier cybersecurity models, potentially widening access to advanced AI-driven defensive tooling for allied nations — though EU-specific implications remain unclear.
The Record6/10
Research
3 storiesAntaeus: Hunting Repository-Level Logic Vulnerabilities via Context-Grounded LLM Reasoning
LLM-based tool targets logic vulnerabilities — the class most static analysers miss — by grounding reasoning in repository-wide context rather than isolated function signatures.
arXiv Crypto & Security9/10Factoring RSA Keys with Many Zeros
Schneier highlights research showing that RSA keys with abnormally many zero bits are factorable and exist in production — a subtle implementation weakness the badkeys project is now flagging at scale.
Schneier on Security9/10Knossos: Procedurally Generated Decoy Environments
Praetorian's Knossos engine auto-generates cloud decoy environments mirroring production topology, turning every attacker probe into a high-fidelity detection signal — a step-change for deception-based defence.
Praetorian8/10
OT/IoT Security
1 storyCloud
1 storyBoardroom Brief
What this week's reporting means for the board, in one line per story.
- Supreme Court decision threatens EU-US data transfer agreement
The legal basis for transferring EU personal data to US cloud providers is again under existential threat, requiring board-level contingency planning.
- How GitHub used secret scanning to reach inbox zero
Exposed credentials in code repositories are a leading breach cause; scalable remediation workflows can close this gap.
- North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
North Korean threat actors are poisoning developer package registries at industrial scale, threatening any organisation that builds software.
- The Gentlemen are knocking: сustom backdoors and evolving tactics
The ransomware ecosystem continues to fragment with new operators using custom tools — generic defences are losing effectiveness.
- Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
A successor to the notorious Citrix Bleed vulnerability is already being weaponised by ransomware groups — unpatched gateways are an imminent breach risk.
- Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts
A critical, actively exploited flaw in a common load balancer requires emergency patching to prevent network compromise.
- ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
A commercialised phishing platform specifically targets Microsoft 365 in ways that circumvent multi-factor authentication, raising BEC risk enterprise-wide.
- FortiBleed credential-theft campaign linked to Lynx ransomware
A credential-theft wave targeting Fortinet devices is feeding ransomware gangs; exposed organisations face imminent intrusion risk.
- Cloak and Detonate: Scanner Evasion and Dynamic Detection of Agent Skill Malware
AI coding assistants introduce a new supply-chain risk: malicious marketplace plugins can exfiltrate code under the agent's own credentials.
- KidnapRAG: A Black-Box Attack for Hijacking Reasoning in Agentic Retrieval-Augmented Generation Systems
RAG-powered AI assistants can be manipulated via poisoned knowledge bases even with multi-step reasoning — a risk for AI-enabled decision support.
- (A)I Sees What You Don't: Exploiting New Attack Surfaces in Third-Party Mobile Agents
AI-powered phone agents introduce a new class of privilege-escalation risk that BYOD and MDM strategies should address.
- Factoring RSA Keys with Many Zeros
Some production RSA keys are mathematically breakable due to implementation flaws — a certificate audit is advisable.
- [UPDATE] [kritisch] Node.js: Mehrere Schwachstellen
Critical vulnerabilities in the widely used Node.js runtime could enable remote code execution across web-facing and internal applications.
- Spyware found on phone of European Parliament member probing it
A European lawmaker probing spyware was himself targeted by Pegasus — boards should treat commercial spyware as a credible threat to senior leadership.
- CISA: Windows BlueHammer flaw now exploited by ransomware gangs
A Windows Defender flaw is now actively used by ransomware gangs; delayed patching directly increases breach and extortion risk.
- New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
A critical Linux kernel vulnerability allows any user to gain full system control — immediate patching is required across server and mobile estates.
- CISA: Microsoft SharePoint RCE flaw now actively exploited
A known SharePoint vulnerability is now under active attack; delayed patching exposes the company to ransomware and data-theft risk.
- Fake Bug Report Hijacks AI Coding Agents at Scale
AI-assisted development introduces a novel class of supply-chain risk that existing code-review processes do not address.
- Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
AI coding tools can silently introduce attacker-controlled dependencies; supply-chain governance must now cover AI-hallucinated artifacts.
- [UPDATE] [hoch] Red Hat Enterprise Linux (runc): Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen
Container-runtime flaws in Red Hat environments could allow attackers to escape isolated workloads — patching is advised.
- FBI Seizes NetNut Proxy Platform, Popa Botnet
A publicly traded proxy provider was seized by the FBI for operating on millions of infected devices—third-party vendor due diligence must cover infrastructure provenance.
- Authentication Bypass in the default configuration phpBB
A trivially exploitable authentication bypass in phpBB could expose internal community platforms to full account takeover.
- Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.
AI is finding software bugs faster than they can be fixed — enterprises reliant on open-source code must invest in dependency-management maturity now.
- Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects
Independent assessments regularly find breaches that internal monitoring missed — periodic external validation remains essential.
- GPT-5.5-Cyber built a zlib fuzzing lab in a day
AI models can now autonomously discover software vulnerabilities at scale, creating new patch-management pressure for enterprises.
- [NEU] [hoch] Microsoft 365 Copilot: Schwachstelle ermöglicht Privilegieneskalation
A high-severity vulnerability in Microsoft 365 Copilot could let attackers escalate privileges across AI-assisted business workflows—immediate patching is required.
- Iran, Russia, China Target Water Systems for Sabotage
Nation-state actors are breaching water infrastructure using trivial misconfigurations — a direct NIS2 compliance and resilience concern.
- New Avalon Malware Framework Packs CrownX Ransomware Capabilities
A new all-in-one malware framework accelerates the path from phishing email to ransomware deployment, compressing the window for defensive response.
- NetNut proxy network disrupted, 2 million infected devices cut off
Two million consumer devices were secretly used as proxy nodes—any Android IoT on corporate premises could have been part of the botnet.
- [NEU] [hoch] Kibana: Mehrere Schwachstellen
Our security monitoring dashboard has vulnerabilities that could allow attackers to execute code within the SOC's own tooling.
- Summer of Clearinghouses
Vulnerability databases alone do not secure the software supply chain — proactive build integrity is now a regulatory expectation under CRA.
- [UPDATE] [hoch] Vercel Next.js: Mehrere Schwachstellen
Multiple high-severity web-framework vulnerabilities may expose customer-facing applications to data theft if unpatched.
- How to Compare the Security of Code Written by Humans to LLM-generated Code
Enterprises adopting AI coding assistants need evidence-based security benchmarks to manage the risk of shipping more vulnerable code.
- Overview of Risk Assessment and Management for Intelligent Systems under the AI Act and Beyond
A structured AI Act risk-assessment framework helps the organisation demonstrate regulatory readiness before enforcement begins.
- Knossos: Procedurally Generated Decoy Environments
Automated deception technology can detect intruders earlier in cloud environments by turning every probe into a verified alert.
- Microsoft accelerates quantum-safe roadmap as risks grow
Microsoft's accelerated quantum-safe roadmap signals that enterprises should begin their own post-quantum migration planning now.
- U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
A verified government ransom payment highlights that even large institutions lack resilience — boards should ensure their incident-response posture prevents similar outcomes.
- SurrogateShield: Beyond Redaction for High-Utility, Privacy-Preserving LLM Interactions
Transmitting employee or customer data to third-party AI services creates GDPR liability; surrogate techniques offer a pragmatic mitigation.
- Apple Reverses Age-Old Patch Policy to Keep Up With AI
Apple is releasing patches faster because AI helps attackers exploit flaws sooner—our internal patching speed must keep pace.
- [NEU] [hoch] Microsoft Exchange Online: Schwachstelle ermöglicht Privilegieneskalation
A privilege-escalation vulnerability in Microsoft Exchange Online could enable attackers to access or manipulate corporate email at an administrative level.
- Medtronic notifies customers impacted by ShinyHunters data breach
A major medical-device manufacturer's data breach highlights the ongoing vulnerability of healthcare supply chains to criminal threat actors.
- When Too Much Security Data Became the Risk
Unmanaged security-log growth is simultaneously inflating budgets and hiding real threats — smarter data curation can address both.
- Cybersecurity Mission Creep in the US
Regulatory scope creep could soon make CISOs responsible for content-moderation and competition issues, not just technical security.
- [NEU] [hoch] Microsoft Azure und Entra: Mehrere Schwachstellen ermöglichen Privilegieneskalation
Privilege-escalation flaws in Microsoft's core identity platform could allow an insider or compromised account to gain administrative control.
- [NEU] [hoch] Dell PowerProtect Data Domain: Mehrere Schwachstellen
High-severity vulnerabilities in Dell backup appliances could let attackers compromise recovery infrastructure—immediate patching protects our ransomware resilience.
- The Good, the Bad and the Ugly in Cybersecurity – Week 27
Nation-state actors are actively compromising Western government communications channels—board awareness of supply-chain trust assumptions is warranted.
- US lifts export controls on Anthropic’s frontier cybersecurity AI models
US export liberalisation for AI cyber models may expand tooling options, but EU AI Act compliance must be validated first.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.