<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Bob’s Newsletter]]></title><description><![CDATA[Bob Bragg is an expert in national security and cybersecurity, with extensive experience in both government and private industry. His daily newsletter offers readers a comprehensive look at the latest developments in these fields, including breaking news ]]></description><link>https://bragg.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!IDIP!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cc9d8f7-a45f-4383-a94e-aaf7d7648851_1024x1024.png</url><title>Bob’s Newsletter</title><link>https://bragg.substack.com</link></image><generator>Substack</generator><lastBuildDate>Tue, 21 Jul 2026 06:28:43 GMT</lastBuildDate><atom:link href="https://bragg.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Bob Bragg]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[bragg@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[bragg@substack.com]]></itunes:email><itunes:name><![CDATA[Bob Bragg]]></itunes:name></itunes:owner><itunes:author><![CDATA[Bob Bragg]]></itunes:author><googleplay:owner><![CDATA[bragg@substack.com]]></googleplay:owner><googleplay:email><![CDATA[bragg@substack.com]]></googleplay:email><googleplay:author><![CDATA[Bob Bragg]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Daily Drop (1335) ]]></title><description><![CDATA[07-16-26]]></description><link>https://bragg.substack.com/p/daily-drop-1335</link><guid isPermaLink="false">https://bragg.substack.com/p/daily-drop-1335</guid><dc:creator><![CDATA[Bob Bragg]]></dc:creator><pubDate>Thu, 16 Jul 2026 08:24:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/Nx5_eSUk4PM" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Thursday, July 16, 2026 // <a href="https://buymeacoffee.com/infodom">Buy Bob a Coffee</a> // <a href="https://ghostwire.news">Ghostwire</a></strong></p><h1><strong>Lebanon-Iran Negotiations Risk Repeating Camp David&#8217;s &#8220;Front Separation&#8221; Pattern</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A War on the Rocks analysis argues that current negotiations involving Iran and Lebanon risk repeating a pattern associated with the Camp David Accords: resolving the front that imposes the greatest immediate cost while separating other theaters from the broader political settlement. The author warns that treating Lebanon primarily as a security problem&#8212;while making Israeli withdrawal conditional on Hizballah&#8217;s disarmament&#8212;could leave Lebanese sovereignty unresolved and redistribute conflict rather than end it.</strong></p><p><strong>Analyst Comments:</strong> In this framework, a regional war is divided into bilateral tracks, allowing negotiators to close the most strategically dangerous front while postponing the political claims attached to the others. The comparison is useful, but it should not be treated as a direct historical equivalence. Egypt entered the Camp David process as a sovereign state negotiating over Egyptian territory it had demonstrated the capacity to contest militarily. Iran can impose regional costs through maritime pressure and aligned armed groups, but it cannot negotiate Lebanese sovereignty on Lebanon&#8217;s behalf. That difference limits how far the Sinai analogy can be taken.</p><p><strong>READ THE STORY: <a href="https://warontherocks.com/the-peace-that-redistributes-war-what-camp-david-reveals-about-lebanon-and-iran/">War on The Rocks</a></strong></p><h1><strong>Washington to Receive $547,000 in 23andMe Data Breach Settlement</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Washington state will receive approximately $547,000 from an $18 million multistate settlement tied to 23andMe&#8217;s 2023 data breach, which exposed genetic and personal information belonging to nearly 6.9 million users, including more than 220,000 Washington residents. The state&#8217;s share will fund consumer-protection investigations and enforcement costs&#8212;not direct payments to affected customers. Consumer compensation is being handled separately through a $46.8 million class-action settlement.</strong></p><p><strong>Analyst Comments:</strong> Genetic data cannot be reset like a password or replaced like a payment card, making the long-term privacy impact difficult to contain. Once compromised, it may create lasting risks involving identity correlation, family-member identification, health profiling, and targeted social engineering. The settlement also highlights a recurring problem in breach enforcement: regulatory payments often fund government investigations while affected individuals receive limited compensation through separate legal proceedings. That does not make the enforcement action meaningless, but it does illustrate the gap between institutional accountability and direct consumer recovery.</p><p><strong>READ THE STORY: <a href="https://www.seattletimes.com/business/wa-to-receive-547000-in-23andme-data-breach-settlement/">The Seattle Times</a></strong></p><h1><strong>SonicWall Warns Two SMA1000 Zero-Days Are Under Active Exploitation</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>SonicWall says attackers are actively exploiting two vulnerabilities affecting SMA1000 appliances: CVE-2026-15409, a critical unauthenticated server-side request forgery flaw, and CVE-2026-15410, a post-authentication command-injection vulnerability. Organizations running affected SMA1000 6210, 7210, or 8200v systems should install the latest hotfix immediately, review the published indicators of compromise, and rebuild the appliance if compromise is confirmed. SonicWall says patching is the only effective mitigation.</strong></p><p><strong>Analyst Comments:</strong> CVE-2026-15409 carries a CVSS score of 10.0 and can reportedly be exploited remotely without authentication. CVE-2026-15410 requires administrative access, but it allows arbitrary operating-system command execution. The obvious concern is chaining: an attacker could potentially use the SSRF flaw to reach otherwise restricted management functionality and then exploit the command-injection vulnerability for full appliance control. SonicWall has not confirmed that such a chain is being used, so defenders should treat it as a plausible scenario rather than an established attack path. Still, internet-facing remote-access appliances are valuable targets because compromise can expose credentials, sessions, configuration data, and internal network access.</p><p><strong>READ THE STORY: <a href="https://www.t00ls.com/articles-75374.html">t00ls</a></strong></p><h1><strong>Zoom Patches Critical Windows Vulnerability That Could Enable Account Takeover</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Zoom has released security updates for CVE-2026-53412, a critical improper input validation vulnerability affecting multiple Windows products. The flaw carries a CVSS score of 9.8 and could allow an unauthenticated remote attacker to take over a Zoom account through network access. Zoom also fixed three high-severity Windows privilege-escalation vulnerabilities. No active exploitation has been reported, but organizations should update affected clients, VDI components, SDK deployments, and Zoom Rooms immediately.</strong></p><p><strong>Analyst Comments:</strong> The critical issue deserves priority because it combines remote access, no authentication requirement, and potential account takeover. Zoom has not publicly described the attack path in detail, so the exact prerequisites and post-exploitation impact remain unclear. Still, a compromised Zoom account could expose meeting data, internal contacts, chat history, cloud recordings, or trusted access to scheduled meetings, depending on the victim&#8217;s permissions and configuration.</p><p><strong>READ THE STORY: <a href="https://thehackernews.com/2026/07/zoom-patches-critical-windows-flaw-that.html">THN</a></strong></p><h1><strong>Researchers Identify HTTP Headers as a New Prompt-Injection Delivery Surface</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>SecurityBreak researcher Marco Pedrinazzi documented indirect prompt-injection payloads embedded in HTTP response headers rather than visible webpage content. Observed instructions attempted to manipulate AI agents into leaking credentials, exfiltrating files, redirecting cryptocurrency payments, contacting external systems, disrupting services, altering future requests, and producing output that could enable cross-site scripting. The finding expands the prompt-injection attack surface beyond HTML and page text: AI agents must treat HTTP headers and all retrieved metadata as untrusted data, not executable instructions.</strong></p><p><strong>Analyst Comments:</strong> Any field passed into a model&#8217;s context can become an instruction channel, regardless of whether a human user can see it. The issue is not that HTTP headers have special control over an AI model. They do not. The vulnerability appears when an application collects attacker-controlled headers, places them in the model&#8217;s context without clear trust boundaries, and then allows the model to invoke tools or produce output that downstream systems treat as safe. The highest-risk scenarios involve agents with access to email, payment systems, local files, credentials, browsers, databases, or shell commands. A malicious header by itself may only be text. Combined with excessive tool permissions and weak output handling, it can become an account-takeover, data-loss, fraud, or code-execution path.</p><p><strong>READ THE STORY: <a href="https://blog.securitybreak.io/the-payload-is-in-the-header-a427a1182c5a?gi=69839994890f&amp;source=rss----77db2cb82174---4">Medium</a></strong></p><h1><strong>Stripped PoC for Unpatched Windows &#8216;LegacyHive&#8217; Zero-Day Released</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Security researcher Nightmare Eclipse has disclosed an unpatched Windows local privilege escalation vulnerability dubbed LegacyHive. The flaw affects the Windows User Profile Service and can reportedly allow a local attacker to mount another user&#8217;s registry hive, including one belonging to an administrator. The published proof of concept was intentionally stripped of key functionality, but the researcher says the full exploit can work against systems with Microsoft&#8217;s July 2026 patches installed. Microsoft had not acknowledged the issue at the time of reporting.</strong></p><p><strong>Analyst Comments:</strong> LegacyHive is not a remote compromise path. An attacker first needs local access, and the released proof of concept reportedly requires credentials for another standard user plus the name of a third target account. That lowers the immediate risk compared with a remote unauthenticated zero-day, but it does not make the vulnerability harmless. Registry hives can contain user-specific configuration, application settings, persistence locations, shell associations, and potentially sensitive operational data. Mounting an administrator&#8217;s hive could give an attacker visibility into privileged configuration or create opportunities for follow-on abuse, depending on which hive data can be accessed or modified.</p><p><strong>READ THE STORY: <a href="https://www.securityweek.com/nightmare-eclipse-drops-legacyhive-windows-zero-day/">Security Week</a></strong></p><h1><strong>Items of interest</strong></h1><h1><strong>Justice Department Seizes Four Domains Tied to Iranian Cyber Operations and Death Threat Campaigns</strong></h1><p><strong>Bottom Line Up Front (BLUF): The U.S. Department of Justice seized four domains allegedly operated on behalf of Iran&#8217;s Ministry of Intelligence and Security. Authorities say the infrastructure supported destructive cyberattacks, data leaks, psychological operations, doxing, and threats against journalists, dissidents, Israeli personnel, and Jewish communities. The disruption removes several public-facing components of the operation, but the actors, tooling, and supporting infrastructure may remain active.</strong></p><p><strong>Analyst Comments:</strong> According to the Justice Department, Iran used fabricated activist personas and leak sites to turn stolen data into intimidation, propaganda, and real-world threats. That combination&#8212;intrusion, public disclosure, doxing, and incitement&#8212;is designed to create psychological impact well beyond the technical damage of the original breach. The domain seizures will disrupt distribution and branding, but they are unlikely to end the underlying campaign. Operators can rebuild websites quickly, shift to social media or messaging platforms, and register replacement infrastructure. Security teams should monitor for new Handala-linked domains, impersonation accounts, recycled leak content, and targeting of organizations connected to Iran, Israel, dissident communities, journalism, healthcare, and critical infrastructure.</p><p><strong>READ THE STORY: <a href="https://www.justice.gov/opa/pr/justice-department-disrupts-iranian-cyber-enabled-psychological-operations">DoJ</a></strong></p><h1><strong>MOSSAD vs IRAN&#8217;s Cyber Spies: The Shadow War | Inside the Hidden Digital Battlefield (Video)</strong></h1><p><strong>FROM THE MEDIA: </strong><span>A secret war is raging in cyberspace &#8212; unseen, silent, and deeply personal. This is the untold story of the digital battlefield between Mossad and Iran&#8217;s elite cyber units, a war that changed modern espionage forever.</span></p><div id="youtube2-Nx5_eSUk4PM" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;Nx5_eSUk4PM&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/Nx5_eSUk4PM?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1><strong>Your Life as Every Rank of Iranian Cyber Warfare (Video)</strong></h1><p><strong>FROM THE MEDIA: </strong><span>What does it feel like to spend 13 years as an Iranian cyber warfare operative &#8212; from a university dorm room to attacking hospital networks across the Middle East?</span></p><div id="youtube2-zcrak6QRDpQ" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;zcrak6QRDpQ&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/zcrak6QRDpQ?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don&#8217;t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com. </p>]]></content:encoded></item><item><title><![CDATA[Daily Drop (1334) ]]></title><description><![CDATA[07-13-26]]></description><link>https://bragg.substack.com/p/daily-drop-1334</link><guid isPermaLink="false">https://bragg.substack.com/p/daily-drop-1334</guid><dc:creator><![CDATA[Bob Bragg]]></dc:creator><pubDate>Mon, 13 Jul 2026 08:46:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_B8s!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9a9000-afe7-42a9-a1d1-01f7d841703b_1448x1086.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Monday, July 13, 2026 // <a href="https://buymeacoffee.com/infodom">Buy Bob a Coffee</a> // <a href="https://ghostwire.news">Ghostwire</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_B8s!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9a9000-afe7-42a9-a1d1-01f7d841703b_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_B8s!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9a9000-afe7-42a9-a1d1-01f7d841703b_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!_B8s!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9a9000-afe7-42a9-a1d1-01f7d841703b_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!_B8s!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9a9000-afe7-42a9-a1d1-01f7d841703b_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!_B8s!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9a9000-afe7-42a9-a1d1-01f7d841703b_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_B8s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9a9000-afe7-42a9-a1d1-01f7d841703b_1448x1086.png" width="1448" height="1086" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6d9a9000-afe7-42a9-a1d1-01f7d841703b_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2867727,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://bragg.substack.com/i/206807894?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9a9000-afe7-42a9-a1d1-01f7d841703b_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_B8s!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9a9000-afe7-42a9-a1d1-01f7d841703b_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!_B8s!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9a9000-afe7-42a9-a1d1-01f7d841703b_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!_B8s!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9a9000-afe7-42a9-a1d1-01f7d841703b_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!_B8s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9a9000-afe7-42a9-a1d1-01f7d841703b_1448x1086.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>GhostCommit Attack Hides Prompt Injection in Images to Steal Developer Secrets</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Security researchers at the University of Missouri&#8211;Kansas City&#8217;s ASSET Research Group demonstrated GhostCommit, a proof-of-concept software supply-chain attack that places malicious instructions inside a PNG image referenced by an apparently legitimate </strong><code>AGENTS.md</code><strong> file. AI code-review systems may approve the pull request because they inspect only its textual changes, while a vision-capable coding agent later opens the image, follows its instructions, reads the repository&#8217;s </strong><code>.env</code><strong> file, and writes the secrets into source code as an innocuous-looking tuple of integers.</strong></p><p><strong>Analyst Comments:</strong> The most important point is that GhostCommit is not traditional image steganography. The malicious instructions are rendered as readable text inside the PNG; they remain &#8220;hidden&#8221; only because the tested review systems do not inspect image contents. CodeRabbit&#8217;s default configuration excluded PNG files, while Cursor Bugbot returned no findings even when the image explicitly referenced prompt injection and instructed the agent to read <code>.env</code>.</p><p><strong>READ THE STORY: <a href="https://www.anquanke.com/post/id/315788">Anquanke</a></strong></p><h1><strong>Internet Scanners Probe MCP Servers and AI Assistant Credentials</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A SANS Internet Storm Center review of 14 days of Apache and ModSecurity logs found automated scanners probing for exposed Model Context Protocol servers, AI-assistant configuration files, stored Claude credentials, and unauthenticated local language-model APIs. The most significant activity involved valid JSON-RPC initialization requests sent to </strong><code>/mcp</code><strong>, indicating that some scanners are no longer merely guessing filenames but are attempting to identify servers that actually speak the MCP protocol. The findings provide credible evidence that AI infrastructure has entered routine internet reconnaissance, although the limited dataset&#8212;one small web host&#8212;does not establish the total scale, ownership, or intent of the scanning activity.</strong></p><p><strong>Analyst Comments:</strong> The SANS data reportedly included roughly 200 requests associated with MCP, LLM, and AI-assistant reconnaissance. MCP handshakes originated from 49 distinct source IP addresses, more than any other reconnaissance category in the observed dataset. That distribution supports the assessment that the requests were not generated by a single researcher repeatedly testing one server. It does not, however, prove that the addresses were controlled by one coordinated campaign; they could represent several independent scanners, compromised systems, commercial exposure-monitoring services, research projects, or shared scanning infrastructure.</p><p><strong>READ THE STORY: <a href="https://isc.sans.edu/diary/rss/33150">SANS</a></strong></p><h1><strong>Operation Capsule Vault Uses Malicious ISO Files and Process Injection to Deliver RokRAT</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Genians Security Center identified a targeted spear-phishing campaign, named Operation Capsule Vault, that used materials from a real South Korean academic conference to deliver the RokRAT remote-access Trojan. The June 22, 2026, campaign directed researchers, policy specialists, and academics to a Dropbox-hosted ISO image containing a PIF executable disguised as a PDF; once opened, the loader displayed the expected conference document while decrypting shellcode, injecting an x64 RokRAT variant into </strong><code>explorer.exe</code><strong>, and establishing command-and-control communications through legitimate cloud-storage services. Genians assesses that APT37 was highly likely responsible, based on malware similarities, reused cloud infrastructure, persistent Yandex account activity, and overlapping tactics with earlier RokRAT operations.</strong></p><p><strong>Analyst Comments:</strong> Operation Capsule Vault demonstrates that the campaign&#8217;s strongest component was not a novel exploit but a carefully constructed social-engineering chain. The attackers reused information from the legitimate &#8220;Why Wonsan-Kalma Tourism Now?&#8221; conference held at Seoul COEX on June 12, presenting the phishing message as an ordinary distribution of event materials. Victims were shown what appeared to be an attached PDF booklet, but clicking it redirected them to Dropbox and downloaded an ISO image named to resemble the legitimate conference materials.</p><p><strong>READ THE STORY: <a href="https://gbhackers.com/operation-capsule-vault-uses-iso-files/">GBhackers</a></strong></p><h1><strong>ReferenceError: WebSocket Is Not Defined in Node.js</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A July 13, 2026, troubleshooting article explains how to resolve </strong><code>ReferenceError: WebSocket is not defined</code><strong> in Node.js by upgrading Node, installing the </strong><code>ws</code><strong> package, or importing </strong><code>WebSocket</code><strong> from Undici. The central advice is sound, but the article oversimplifies Node.js version support and pads the solution with generic debugging material containing several technical errors.</strong></p><p><strong>Analyst Comments:</strong> The error means the runtime cannot locate a variable or global named <code>WebSocket</code>. In this context, it usually occurs because the application is running on an older Node.js version, browser-oriented code is being executed in Node, or a third-party WebSocket library was not imported. Node&#8217;s browser-compatible WebSocket client was introduced experimentally in Node 20.10.0 and 21.0.0, enabled by default in Node 22.0.0, and marked stable in Node 22.4.0. Therefore, the article&#8217;s claim that Node 21 and earlier always require <code>ws</code> or Undici is too broad.</p><p><strong>READ THE STORY: <a href="https://itsourcecode.com/referenceerror/referenceerror-websocket-is-not-defined-node/">IT Source Code</a></strong></p><h1><strong>VEXAIoT AI Agents Autonomously Exploit IoT Vulnerabilities With 95% Success Rate</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers developed VEXAIoT, a two-agent framework that uses a large language model and established offensive-security tools to automate reconnaissance, vulnerability correlation, exploit selection, execution, validation, and retries against vulnerable IoT environments. The framework achieved a 95% overall success rate across 260 controlled attack trials&#8212;94.5% against OWASP IoTGoat and 96.7% against Metasploitable2&#8212;but the results demonstrate reliable automation against deliberately vulnerable test systems, not the ability to compromise arbitrary real-world IoT devices.</strong></p><p><strong>Analyst Comments:</strong> VEXAIoT divides the attack process between a vulnerability-detection agent and an attack-execution agent. The first uses Nmap to identify exposed ports, services, and protocols before using SearchSploit to associate detected software with known vulnerabilities and public exploits. That information is provided to GPT-5.1 Thinking, which creates an ordered attack plan. The second agent chooses tools or scripts, generates commands, executes them, and returns the results for validation or another attempt. The system logs its plans, commands, and outputs, allowing optional human intervention even though the workflow can run autonomously.</p><p><strong>READ THE STORY: <a href="https://gbhackers.com/new-vexaiot-ai-agents-autonomously-exploit-iot-vulnerabilities/">GBhackers</a></strong></p><h1><strong>VeriChat AI Assistant Checks Hardware Designs for Hidden Trojans</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>University of Florida researchers developed VeriChat, a specialized conversational assistant that combines retrieval-augmented generation with electronic design automation tools to help engineers assess register-transfer-level hardware designs for security weaknesses. In a controlled demonstration, VeriChat analyzed an AES substitution-box design containing a researcher-planted hardware Trojan, identified seven suspicious flip-flops, triggered the implant through simulation, and formally proved that it could leak an encryption key through a status output. The results show that agentic AI can coordinate established hardware-verification tools, but they do not demonstrate reliable detection of unknown implants in fabricated chips or arbitrary third-party designs.</strong></p><p><strong>Analyst Comments:</strong> VeriChat is more accurately described as an AI-assisted pre-silicon verification interface than an autonomous chip-backdoor detector. It analyzes uploaded RTL source code, such as Verilog, rather than inspecting finished physical processors. The system connects a conversational interface to Icarus Verilog for syntax checking and simulation, Yosys for synthesis and structural analysis, and SymbiYosys with the Z3 solver for formal verification.</p><p><strong>READ THE STORY: <a href="https://www.helpnetsecurity.com/2026/07/13/hardware-security-ai-assistant-hidden-backdoors/">HNS</a></strong></p><h1><strong>Items of interest</strong></h1><h1><strong>From Prompt Engineering to Intent Engineering: AI Workflows Shift From Instructions to Outcomes</strong></h1><p><strong>Bottom Line Up Front (BLUF): Daniel Miessler argues that users should stop prescribing step-by-step methods to advanced AI systems and instead define the outcome they want. He calls this shift &#8220;Intent Engineering&#8221;&#8212;a prompting approach that gives capable models room to determine the best way to complete a task rather than constraining them with increasingly outdated human workflows.</strong></p><p><strong>Analyst Comments:</strong> The argument tracks with Sutton&#8217;s Bitter Lesson: as general-purpose AI systems improve, handcrafted rules and elaborate prompting frameworks are likely to become less useful&#8212;and may actively degrade performance. Detailed instructions still matter when a task has hard constraints, compliance requirements, or a specific operating procedure. But for open-ended analysis, research, coding, and content generation, excessive scaffolding can narrow the model&#8217;s reasoning and lock it into a weaker approach. Organizations should review existing prompt libraries and separate genuine requirements from legacy instructions that merely describe how a human would perform the task.</p><p><strong>READ THE STORY: <a href="https://danielmiessler.com/blog/intent-engineering">Dan Miessler</a></strong></p><h1><strong>Prompt Engineering Full Course (Video)</strong></h1><p><strong>FROM THE MEDIA:  Tech with Tim explains what it is, why it's important, how to do it faster. The top techniques and methods and advanced strategies to get the most out of loops.</strong></p><div id="youtube2-2BpCk4d2Cc0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;2BpCk4d2Cc0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/2BpCk4d2Cc0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1><strong>You SUCK at Prompting AI (Here's the secret) (Video)</strong></h1><p><strong>FROM THE MEDIA: </strong><span>You&#8217;re probably using AI wrong. Don&#8217;t worry, it&#8217;s not your fault. Most people suck at prompting, but today I&#8217;m showing you real prompting techniques I learned from top Coursera prompting courses, official docs from Anthropic/Google/OpenAI, and advice from some of the best prompt engineers in the world.</span></p><div id="youtube2-pwWBcsxEoLk" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;pwWBcsxEoLk&quot;,&quot;startTime&quot;:&quot;419s&quot;,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/pwWBcsxEoLk?start=419s&amp;rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don&#8217;t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com. </p>]]></content:encoded></item><item><title><![CDATA[Daily Drop (1333) ]]></title><description><![CDATA[07-12-26]]></description><link>https://bragg.substack.com/p/daily-drop-1333</link><guid isPermaLink="false">https://bragg.substack.com/p/daily-drop-1333</guid><dc:creator><![CDATA[Bob Bragg]]></dc:creator><pubDate>Sun, 12 Jul 2026 12:39:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!uDmY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc391e8-d69c-4eb4-b023-9d97794d6667_1448x1086.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Sunday, July 12, 2026 // <a href="https://buymeacoffee.com/infodom">Buy Bob a Coffee</a> // <a href="https://ghostwire.news">Ghostwire</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uDmY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc391e8-d69c-4eb4-b023-9d97794d6667_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uDmY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc391e8-d69c-4eb4-b023-9d97794d6667_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!uDmY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc391e8-d69c-4eb4-b023-9d97794d6667_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!uDmY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc391e8-d69c-4eb4-b023-9d97794d6667_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!uDmY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc391e8-d69c-4eb4-b023-9d97794d6667_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uDmY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc391e8-d69c-4eb4-b023-9d97794d6667_1448x1086.png" width="1448" height="1086" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1fc391e8-d69c-4eb4-b023-9d97794d6667_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3178395,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://bragg.substack.com/i/206678018?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc391e8-d69c-4eb4-b023-9d97794d6667_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uDmY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc391e8-d69c-4eb4-b023-9d97794d6667_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!uDmY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc391e8-d69c-4eb4-b023-9d97794d6667_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!uDmY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc391e8-d69c-4eb4-b023-9d97794d6667_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!uDmY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fc391e8-d69c-4eb4-b023-9d97794d6667_1448x1086.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>China Recovers Long March 10B Booster in First Net-Based Orbital Rocket Catch</strong></h1><p><em><strong>NOTE: </strong></em></p><p><em><strong>China's first orbital booster recovery lands as more than a domestic milestone; it recalibrates the international launch competition. With this catch, China joins SpaceX and Blue Origin as the only entities to recover an orbital-class booster &#8212; ending a decade in which reusability was an exclusively American capability. That symbolism matters. Reusable launch has been the single largest driver of the cost and cadence gap between US and non-US space access, and its demonstration by a state-owned Chinese enterprise signals that the moat is eroding.</strong></em></p><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>China successfully launched and recovered the first stage of its new Long March 10B rocket on July 10, 2026, using a sea-based net and cable system. The mission marked China&#8217;s first controlled recovery of an orbital-class booster and the first known use of a net-based capture method for an orbital launch vehicle. Chinese officials plan to refly the recovered stage before the end of 2026.</strong></p><p><strong>Analyst Comments:</strong> The Long March 10B launched from the Wenchang Commercial Space Launch Site at 04:15 UTC on July 10. Roughly 10 minutes later, the first stage descended toward an offshore platform in the South China Sea, where tensioned cables captured hooks mounted on the booster and left the vehicle suspended above the deck. The approximately 63.6-meter rocket uses seven kerosene-fueled YF-100K engines in its first stage and a methane-fueled YF-219 engine in its upper stage. It is designed to carry about 16 metric tons to low-Earth orbit, slightly less than SpaceX&#8217;s Falcon 9. The flight also deployed the CX-26 experimental satellite.</p><p><strong>READ THE STORY: <a href="https://arstechnica.com/space/2026/07/china-recovered-its-first-reusable-rocket-and-showed-a-new-way-to-do-it/">arsTechnia</a></strong></p><h1><strong>Russian-Linked Hackers Allegedly Hijack IP Cameras to Monitor NATO Supply Routes Into Ukraine</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Dutch intelligence reportedly identified a Kremlin-linked operation that compromised internet-connected residential and commercial cameras across NATO member states and Ukraine. The attackers allegedly targeted devices overlooking strategic transport corridors, allowing them to monitor military shipments to Ukraine in near real time.</strong></p><p><strong>Analyst Comments:</strong> The exposure reflects a familiar Internet of Things problem: inexpensive cameras are widely deployed, rarely updated, and often protected by default or reused credentials. Many are also connected directly to the internet through vendor cloud services or insecure remote-access configurations. A compromised camera may appear insignificant on its own, but hundreds of cameras positioned along the same logistics network can create a persistent surveillance capability.</p><p><strong>READ THE STORY: <a href="https://t.me/worldandwe/29152">Telegram</a></strong></p><h1><strong>South Korean Military Faced Nearly 19,000 Cyberattack Attempts in 2025 as Talent Retention Worsened</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>South Korea&#8217;s military recorded 18,951 cyberattack attempts in 2025, a five-year high and a 31 percent increase from roughly 14,400 incidents in 2024. Nearly all reported activity targeted military websites, while malicious email campaigns also continued to rise. At the same time, the armed forces are struggling to retain and recruit trained cyber officers, creating a widening gap between operational demand and defensive capacity.</strong></p><p><strong>Analyst Comments:</strong> The attack count is notable, but volume alone does not reveal how many attempts were sophisticated, successful, or linked to North Korea. The more important signal is the combination of sustained targeting and declining defender retention. South Korea can absorb routine scanning and low-grade intrusion attempts, but persistent state-backed operators benefit when experienced military personnel leave faster than replacements can be trained.</p><p><strong>READ THE STORY: <a href="https://www.koreaherald.com/article/10805958">The Korean Herald</a></strong></p><h1><strong>Italy Alleges Russian Espionage Network Targeted Air-Defense Systems Supplied to Ukraine</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Italian authorities reportedly uncovered a Russian intelligence network seeking classified information on air-defense systems, missiles, and other military technologies connected to Ukraine. Investigators allege that Russian military attach&#233; Mikhail Astakov directed former Italian intelligence officer Gavino Piras, who used cash to recruit sources inside Italy&#8217;s armed forces. Italy subsequently expelled two Russian military attach&#233;s, including Astakov.</strong></p><p><strong>Analyst Comments:</strong> The reported collection priorities align with Russia&#8217;s immediate operational needs: identifying the capabilities, vulnerabilities, deployment patterns, and future development paths of Western systems supporting Ukraine. Information on SAMP/T, CAMM-ER, Storm Shadow, and emerging Leonardo platforms could support countermeasure development, targeting decisions, electronic-warfare planning, and strategic procurement assessments.</p><p><strong>READ THE STORY: <a href="https://t.me/worldandwe/29154">Telegram</a></strong></p><h1><strong>China- and India-Aligned Threat Actors Target Pakistani Police Systems in Sustained Espionage Campaigns</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>SentinelOne researchers identified sustained cyberespionage activity targeting Pakistani law enforcement organizations between February 2024 and April 2026. The campaigns compromised network appliances, email infrastructure, and web applications containing criminal, biometric, personnel, hotel, tenant, and national identity data. At least four intrusion clusters deployed PlugX, ShadowPad, Cobalt Strike, and Remcos RAT, with activity assessed as linked to China- and India-aligned operators.</strong></p><p><strong>Analyst Comments:</strong> Pakistani law enforcement networks are high-value intelligence targets because they reveal the government&#8217;s internal security picture: active investigations, personnel records, biometric data, border-control activity, and assessments of domestic threats. The simultaneous presence of suspected Chinese and Indian operators is not surprising. Both have distinct geopolitical interests in Pakistan, and both benefit from access to the same sensitive institutions.</p><p><strong>READ THE STORY: <a href="https://thehackernews.com/2026/07/hackers-weaponize-balochistan-police.html">THN</a></strong></p><h1><strong>Google Pays $250,000 for KVM Escape Vulnerability Affecting Cloud Hosts</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A security researcher received a $250,000 reward through Google&#8217;s kvmCTF program after disclosing a KVM virtual machine escape vulnerability tracked as CVE-2026-53359 and dubbed &#8220;Januscape.&#8221; The flaw reportedly allows an attacker with code execution inside a guest virtual machine to break isolation and execute arbitrary commands on the underlying Linux host, creating serious risk for cloud, VPS, and multi-tenant environments.</strong></p><p><strong>Analyst Comments:</strong> A working KVM escape is one of the highest-impact vulnerability classes in cloud security because it undermines the isolation boundary between tenants and the hypervisor. An attacker could rent a low-cost virtual machine, exploit the flaw from inside the guest, and gain control of the physical host. From there, the attacker could potentially access neighboring workloads, steal customer data, compromise management systems, or use the host as a pivot into the wider provider environment. The $250,000 payout reflects the severity of the outcome rather than the size of the code defect. Google&#8217;s kvmCTF assigns its highest reward to a complete guest-to-host escape because this type of bug threatens the trust model underpinning public cloud infrastructure. The source states that researchers disclosed the issue responsibly, waited for Linux kernel fixes, and released only limited proof-of-concept material rather than a complete weaponized escape chain. Even so, providers should assume exploit development will continue and prioritize patching and rebooting affected hosts.</p><p><strong>READ THE STORY: <a href="https://www.t00ls.com/articles-75339.html">t00ls</a> (CN)</strong></p><h1><strong>OpenAI Safety Chief Departs as Company Integrates Safety More Deeply Into Model Research</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>OpenAI&#8217;s head of safety systems, Johannes Heidecke, is leaving the company as it reorganizes its safety and research functions. According to WIRED, OpenAI&#8217;s safety teams will report to Mia Glaese, whose role is expanding to vice president of research and safety, while Saachi Jain will serve as interim head of safety systems.</strong></p><p><strong>Analyst Comments:</strong> The departure matters less as an isolated personnel change than as part of a broader shift in how OpenAI structures safety oversight. Integrating safety teams directly with frontier-model research could give evaluators earlier access to model development and greater influence over launch decisions. It could also reduce organizational independence if the same leadership chain is responsible for both capability development and safety approval.</p><p><strong>READ THE STORY: <a href="https://www.wired.com/story/openai-head-of-safety-leaving/">Wired</a></strong></p><h1><strong>Ghost GitHub Accounts Map Organizations in Coordinated Reconnaissance Campaigns</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Datadog identified multiple campaigns using more than 50 dormant GitHub accounts to systematically enumerate organizations, repositories, users, and access relationships through GitHub&#8217;s API. Most activity focused on publicly available data and blended with legitimate traffic, but some operations escalated to cloning repositories and accessing private commit paths with exposed user tokens.</strong></p><p><strong>Analyst Comments:</strong> This is reconnaissance, but it should not be dismissed as harmless scraping. Public GitHub data can reveal an organization&#8217;s development structure, active projects, employee relationships, technology stack, and likely high-value repositories. That information can support targeted phishing, credential theft, dependency attacks, and follow-on intrusion planning. The use of accounts created years earlier is a deliberate trust-evasion tactic. Dormant identities are less likely to trigger scrutiny than newly registered accounts, and API calls to public resources return normal HTTP 200 responses instead of authentication failures. That leaves defenders with weak signals unless they are monitoring user agents, request patterns, account age, and changes from normal organizational activity.</p><p><strong>READ THE STORY: <a href="https://www.securityweek.com/ghost-accounts-abuse-github-api-in-mass-recon-campaign/">Security week</a></strong></p><h1><strong>Apple Sues OpenAI Over Alleged Theft of Hardware Trade Secrets</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Apple has filed a federal lawsuit accusing OpenAI, its hardware chief Tang Tan, and other defendants of misappropriating confidential hardware designs, prototype information, supplier details, and internal security procedures. Apple alleges that OpenAI encouraged departing employees to bring proprietary materials into its hardware program and coached recruits on how to avoid Apple&#8217;s security controls. OpenAI denies having any interest in competitors&#8217; trade secrets.</strong></p><p><strong>Analyst Comments:</strong> This is a major insider-risk and intellectual-property dispute, not just a talent-poaching case. Apple&#8217;s allegations describe a deliberate collection process involving former employees, unreleased components, supplier intelligence, internal presentations, and guidance on evading exit procedures. If substantiated, the case could expose serious weaknesses in how sensitive hardware organizations manage departing personnel, supplier access, and post-employment monitoring. The broader issue is that elite technical hiring increasingly overlaps with trade-secret exposure. Companies building new AI hardware are recruiting from the same small pool of engineers, designers, and suppliers that support established consumer-device manufacturers. That creates a persistent risk that institutional knowledge, prototype details, and manufacturing methods move with employees faster than legal and security controls can respond.</p><p><strong>READ THE STORY: <a href="https://www.wired.com/story/apple-sues-openai-allegedly-stealing-ip-hardware/">Wired</a></strong></p><h1><strong>GigaWiper Combines Espionage, Ransomware, and Disk Destruction in a Modular Go Backdoor</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Microsoft has detailed GigaWiper, a Go-based backdoor that combines remote-access functionality with multiple destructive capabilities, including disk wiping, unrecoverable file encryption, and commands that can erase Windows installations. Observed since October 2025, the malware gives operators the flexibility to conduct surveillance, steal data, deploy additional tools, or trigger system-wide destruction on demand.</strong></p><p><strong>Analyst Comments:</strong> GigaWiper is significant because destruction is not its only purpose. Traditional wipers are often built for a single terminal action: destroy data and render systems unusable. GigaWiper instead provides persistent remote control before the operator decides whether to spy, extort, disrupt, or erase. That flexibility increases the incident-response risk. By the time defenders observe disk wiping, encryption, or forced crashes, the attacker may already have spent weeks collecting data, mapping the environment, and preparing follow-on actions. Recovery planning must therefore account for both destructive impact and prior data compromise.</p><p><strong>READ THE STORY: <a href="https://www.t00ls.com/articles-75345.html">t00ls</a> (CN)</strong></p><h1><strong>CISA Adds Critical Joomla Extension Flaws to KEV Catalog After Active Exploitation</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>CISA added two arbitrary file-upload vulnerabilities affecting the iCagenda and Balbooa Forms Joomla extensions to its Known Exploited Vulnerabilities catalog. Both flaws can enable attackers to upload executable files and achieve remote code execution. U.S. federal civilian agencies must remediate the vulnerabilities by July 13, 2026.</strong></p><p><strong>Analyst Comments:</strong> CVE-2026-48939 carries a CVSS score of 10.0 and can allow PHP code execution through iCagenda&#8217;s attachment functionality. CVE-2026-56291 affects Balbooa Forms and reportedly permits unauthenticated upload of executable files, leading to full remote code execution. Once attackers gain code execution, they can deploy web shells, steal credentials, alter site content, or use the server as infrastructure for follow-on attacks. Organizations running Joomla should treat exposure of either extension as an incident-response priority, not a routine patching task.</p><p><strong>READ THE STORY: <a href="https://securityaffairs.com/195164/security/u-s-cisa-adds-icagenda-and-balbooa-forms-flaws-to-its-known-exploited-vulnerabilities-catalog.html">Security Affairs</a> </strong></p><h1><strong>Windows Trojan Infects Visual Studio Projects to Spread Through Developer Builds</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Doctor Web researchers identified a multi-stage Windows malware operation that infects C++ and C# development projects to propagate through software builds. The malware adds malicious pre-build instructions to Visual Studio project files, allowing it to execute whenever affected code is compiled. Its capabilities include credential theft, remote access, clipboard hijacking, cryptocurrency mining, persistence, and infection of additional source code and executables.</strong></p><p><strong>Analyst Comments:</strong> By modifying <code>.vcxproj</code>, <code>.csproj</code>, and related development files, the malware turns trusted developer workflows into a supply-chain distribution mechanism. A compromised workstation can poison internal applications, public repositories, build artifacts, and downstream systems without requiring the attacker to breach each target directly. The use of project-level pre-build events is particularly dangerous because the malicious execution can appear to be part of the normal compilation process. Developers who clone and build an infected repository may trigger the payload before security teams recognize that the source tree itself has been altered.</p><p><strong>READ THE STORY: <a href="https://gbhackers.com/c-c-project-files-windows-backdoor/">GBhackers</a></strong></p><h1><strong>Compromised Jscrambler npm Releases Deploy Cross-Platform Infostealer Against Developer Systems</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Attackers used a compromised npm publishing credential to distribute a Rust-based infostealer through five malicious versions of the </strong><code>jscrambler</code><strong> package: 8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0. The malware targeted Windows, macOS, and Linux systems, stealing cloud credentials, developer tokens, browser data, password-manager sessions, cryptocurrency wallets, and credentials stored by AI coding tools. Jscrambler and Socket recommend upgrading to version 8.22.0 and treating any system that executed an affected release as compromised.</strong></p><p><strong>Analyst Comments:</strong> This incident is a direct supply-chain attack on developer workstations and CI infrastructure&#8212;the exact environments most likely to hold high-value secrets. The early malicious releases relied on <code>preinstall</code> hooks, but versions 8.18.0 and 8.20.0 reportedly moved the dropper into the package&#8217;s main code and command-line interface. That change matters because disabling npm lifecycle scripts or using <code>npm install --ignore-scripts</code> would not prevent execution when the package was imported or run. Defenders should not treat an upgrade as sufficient remediation. Any host that installed or executed an affected version should undergo incident response, credential rotation, persistence checks, and network review. The Linux payload&#8217;s apparent eBPF capability also warrants deeper forensic analysis because it may provide functionality beyond conventional userspace credential theft.</p><p><strong>READ THE STORY: <a href="https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html">THN</a></strong></p><h1><strong>Ghostcommit Attack Hides Prompt-Injection Payloads in Images to Compromise AI Coding Agents</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>ASSET Research Group disclosed &#8220;Ghostcommit,&#8221; a software supply-chain technique that hides malicious prompt-injection instructions inside PNG images committed to a repository. Text-only code reviewers may ignore the image, allowing the payload to survive review and later manipulate an AI coding agent into reading sensitive files such as </strong><code>.env</code><strong> and encoding their contents into source code.</strong></p><p><strong>Analyst Comments:</strong> Ghostcommit exposes a control gap in AI-assisted development: security depends as much on the agent harness, repository instructions, and file-processing pipeline as it does on the underlying model. The attack does not need to exploit a conventional software vulnerability. It abuses trusted project context&#8212;such as <code>AGENTS.md</code> files&#8212;and an agent&#8217;s ability to interpret images and access local secrets.</p><p><strong>READ THE STORY: <a href="https://cybersecuritynews.com/ghostcommit-attack-hides-prompts/">CSN</a></strong></p><h1><strong>Study Finds Widespread Privacy and Security Failures in Free Android VPN Apps</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers testing 281 popular free Android VPN applications found that many failed to provide the privacy and security users expect from a VPN. Twenty-nine apps leaked traffic outside the encrypted tunnel, 61 transmitted data in plaintext, and five downloaded configuration files without encryption&#8212;creating a path for attackers on the same network to redirect users through malicious VPN servers. Apps with at least one identified issue accounted for more than 2.4 billion installations.</strong></p><p><strong>Analyst Comments:</strong> These findings reinforce a basic reality: a VPN does not eliminate trust&#8212;it transfers trust from the internet service provider to the VPN operator. When the application leaks DNS traffic, uses obsolete cryptography, transmits configuration files over HTTP, or embeds advertising trackers, the product can create more risk than it removes.</p><p><strong>READ THE STORY: <a href="https://blog.segu-info.com.ar/2026/07/estudio-de-aplicaciones-vpn-gratuitas.html">Segu Info</a></strong></p><h1><strong>Linux Kernel ptrace Flaw Enables Local Privilege Escalation on Vulnerable Systems</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>CVE-2026-46333 is a Linux kernel privilege-management flaw involving </strong><code>__ptrace_may_access()</code><strong> and process teardown behavior. According to a Codeby.net technical analysis, an unprivileged local user may be able to exploit a race condition to access privileged file descriptors, potentially exposing </strong><code>/etc/shadow</code><strong>, SSH host keys, or authenticated D-Bus connections. Public proof-of-concept code is reportedly available, increasing the urgency for organizations running affected kernels.</strong></p><p><strong>Analyst Comments:</strong> This is a post-compromise escalation issue, not a remote entry point. An attacker first needs local code execution or valid low-privilege access through another vector, such as a vulnerable web application, stolen SSH credentials, or a compromised CI runner. Once inside, however, a reliable kernel-level privilege-escalation primitive can turn a limited foothold into full host compromise.</p><p><strong>READ THE STORY: <a href="https://codeby.net/threads/lokal-noye-povysheniye-privilegii-linux-cherez-cve-2026-46333-ptrace-race-condition-ot-shella-do-root.94656/">Codeby</a></strong></p><h1><strong>Items of interest</strong></h1><h1><strong>From Prompt Engineering to Intent Engineering: AI Workflows Shift From Instructions to Outcomes</strong></h1><p><strong>Bottom Line Up Front (BLUF): Daniel Miessler argues that users should stop prescribing step-by-step methods to advanced AI systems and instead define the outcome they want. He calls this shift &#8220;Intent Engineering&#8221;&#8212;a prompting approach that gives capable models room to determine the best way to complete a task rather than constraining them with increasingly outdated human workflows.</strong></p><p><strong>Analyst Comments:</strong> The argument tracks with Sutton&#8217;s Bitter Lesson: as general-purpose AI systems improve, handcrafted rules and elaborate prompting frameworks are likely to become less useful&#8212;and may actively degrade performance. Detailed instructions still matter when a task has hard constraints, compliance requirements, or a specific operating procedure. But for open-ended analysis, research, coding, and content generation, excessive scaffolding can narrow the model&#8217;s reasoning and lock it into a weaker approach. Organizations should review existing prompt libraries and separate genuine requirements from legacy instructions that merely describe how a human would perform the task.</p><p><strong>READ THE STORY: <a href="https://danielmiessler.com/blog/intent-engineering">Dan Miessler</a></strong></p><h1><strong>Prompt Engineering Full Course (Video)</strong></h1><p><strong>FROM THE MEDIA:  Tech with Tim explains what it is, why it's important, how to do it faster. The top techniques and methods and advanced strategies to get the most out of loops.</strong></p><div id="youtube2-2BpCk4d2Cc0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;2BpCk4d2Cc0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/2BpCk4d2Cc0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1><strong>You SUCK at Prompting AI (Here's the secret) (Video)</strong></h1><p><strong>FROM THE MEDIA: </strong><span>You&#8217;re probably using AI wrong. Don&#8217;t worry, it&#8217;s not your fault. Most people suck at prompting, but today I&#8217;m showing you real prompting techniques I learned from top Coursera prompting courses, official docs from Anthropic/Google/OpenAI, and advice from some of the best prompt engineers in the world.</span></p><div id="youtube2-pwWBcsxEoLk" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;pwWBcsxEoLk&quot;,&quot;startTime&quot;:&quot;419s&quot;,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/pwWBcsxEoLk?start=419s&amp;rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don&#8217;t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com. </p>]]></content:encoded></item><item><title><![CDATA[Daily Drop (1332) ]]></title><description><![CDATA[07-08-26]]></description><link>https://bragg.substack.com/p/daily-drop-1332</link><guid isPermaLink="false">https://bragg.substack.com/p/daily-drop-1332</guid><dc:creator><![CDATA[Bob Bragg]]></dc:creator><pubDate>Wed, 08 Jul 2026 08:32:46 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!AM15!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a0ff45-e545-4ef9-aaeb-28064b88d0fa_1448x1086.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Wednesday, July 08, 2026 // <a href="https://buymeacoffee.com/infodom">Buy Bob a Coffee</a> // <a href="https://ghostwire.news">Ghostwire</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AM15!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a0ff45-e545-4ef9-aaeb-28064b88d0fa_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AM15!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a0ff45-e545-4ef9-aaeb-28064b88d0fa_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!AM15!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a0ff45-e545-4ef9-aaeb-28064b88d0fa_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!AM15!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a0ff45-e545-4ef9-aaeb-28064b88d0fa_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!AM15!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a0ff45-e545-4ef9-aaeb-28064b88d0fa_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AM15!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a0ff45-e545-4ef9-aaeb-28064b88d0fa_1448x1086.png" width="1448" height="1086" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f8a0ff45-e545-4ef9-aaeb-28064b88d0fa_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3281804,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://bragg.substack.com/i/206012274?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a0ff45-e545-4ef9-aaeb-28064b88d0fa_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AM15!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a0ff45-e545-4ef9-aaeb-28064b88d0fa_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!AM15!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a0ff45-e545-4ef9-aaeb-28064b88d0fa_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!AM15!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a0ff45-e545-4ef9-aaeb-28064b88d0fa_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!AM15!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a0ff45-e545-4ef9-aaeb-28064b88d0fa_1448x1086.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>CISA Reportedly Uses Anthropic Mythos to Scan Federal Software for Vulnerabilities</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>CISA is reportedly using Anthropic&#8217;s Mythos AI model to scan federal government software repositories for security flaws. The effort appears focused on helping agencies identify and patch vulnerabilities before exploitation by foreign intelligence services or cybercriminal groups. While details on affected agencies, vulnerability severity, and review scope remain undisclosed, the report signals a shift toward AI-assisted vulnerability discovery inside federal software assurance programs.</strong></p><p><strong>Analyst Comments:</strong> This is the direction AI security tooling has been heading: less &#8220;summarize this alert&#8221; and more &#8220;find the bug before someone else does.&#8221; That is useful, but it also creates a new operational burden. AI-generated findings still need validation, exploitability analysis, prioritization, and remediation ownership. Otherwise, agencies risk replacing one backlog with another. The federal angle matters. If CISA is using frontier models for code review at scale, enterprises will feel pressure to evaluate similar tooling for internal software risk programs. That is not a bad thing, but CISOs need guardrails before turning powerful models loose on source code, secrets, regulated data, or sensitive system details.</p><p><strong>READ THE STORY: <a href="https://cisowhisperer.com/cisa-reportedly-uses-anthropic-mythos-to-scan-government-software-for-flaws/">CISO Whisper</a></strong></p><h1><strong>China-Aligned Actors Chain Roundcube Bugs to Target University Research Departments</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Proofpoint researchers report that a suspected China-aligned espionage cluster exploited two critical Roundcube vulnerabilities to compromise U.S. and Canadian universities. The campaign targeted physics and engineering departments, especially administrators and professors tied to national security research, astrophysics, and particle physics. Proofpoint has identified fewer than 10 confirmed university victims but assesses that several dozen institutions may be affected and that the campaign is likely ongoing.</strong></p><p><strong>Analyst Comments:</strong> This is not routine phishing. The notable shift is that attackers used email as the delivery path to compromise the mail server itself, not just to steal a user&#8217;s credentials or drop commodity malware on an endpoint. That matters because university mail infrastructure is a high-value target. It holds sensitive research correspondence, grant discussions, collaboration details, identity data, and long-term institutional access. Once a mail server is compromised, webshells and backdoors give attackers persistence that can outlast password resets and user-level containment.</p><p><strong>READ THE STORY: <a href="https://cyberscoop.com/china-espionage-attacks-us-canada-universities-proofpoint/">Cyberscoop</a></strong></p><h1><strong>HalluSquatting Turns AI Coding Agents Into a Scalable Botnet Risk</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers disclosed &#8220;HalluSquatting,&#8221; a pull-based prompt-injection attack that abuses AI coding agents&#8217; tendency to hallucinate repository and resource names. By registering likely hallucinated identifiers and seeding them with malicious instructions or code, attackers could trick tools such as Cursor, Gemini CLI, Windsurf, GitHub Copilot, Cline, OpenClaw, ZeroClaw, and NanoClaw into retrieving attacker-controlled resources. The risk is not theoretical: the attack model could support large-scale botnets, DDoS activity, cryptomining, ransomware staging, or broader developer workstation compromise.</strong></p><p><strong>Analyst Comments:</strong> The dangerous part is the combination of hallucinated resource resolution and agentic tooling with shell access. Coding assistants are increasingly wired into terminals, package managers, Git repositories, and local development environments. Once those agents start pulling unverified resources and executing instructions, attackers get a scalable path that looks less like classic prompt injection and more like software supply-chain compromise.</p><p><strong>READ THE STORY: <a href="https://arstechnica.com/security/2026/07/hackers-can-use-9-of-the-most-popular-ai-tools-to-assemble-massive-botnets/">arsTECHNICA</a></strong></p><h1><strong>Outdated PHP Leaves Over 70% of Public WordPress Sites Exposed to Attack</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Censys analysis found that more than 70% of publicly visible WordPress sites with exposed version data are running outdated PHP versions, with PHP 7.4 the most common despite reaching end-of-life in November 2022. The issue affects a large slice of the web ecosystem and creates a durable attack surface for automated exploitation, plugin abuse, defacement campaigns, and broader CMS compromise.</strong></p><p><strong>Analyst Comments:</strong> The dangerous part is the combination of hallucinated resource resolution and agentic tooling with shell access. Coding assistants are increasingly wired into terminals, package managers, Git repositories, and local development environments. Once those agents start pulling unverified resources and executing instructions, attackers get a scalable path that looks less like classic prompt injection and more like software supply-chain compromise.</p><p><strong>READ THE STORY: <a href="https://gbhackers.com/over-70-of-public-wordpress-sites-running-outdated-php-exposed/">GBhackers</a></strong></p><h1><strong>Linux &#8220;Bad Epoll&#8221; Local Privilege Escalation PoC Goes Public</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Proof-of-concept code is now public for CVE-2026-46242, a Linux kernel local privilege escalation flaw dubbed &#8220;Bad Epoll.&#8221; The vulnerability affects Linux kernel 6.4 and later and may allow an unprivileged local process to gain root privileges. Public PoC availability raises the risk for servers, desktops, container hosts, and Android devices running affected kernels.</strong></p><p><strong>Analyst Comments:</strong> Local privilege escalation bugs become serious fast when attackers already have a foothold through phishing, exposed services, weak credentials, or container compromise. Bad Epoll is especially concerning because it sits in kernel-level event handling and now has public exploit research demonstrating kernel memory leakage and control-flow hijacking.</p><p><strong>READ THE STORY: <a href="https://www.t00ls.com/articles-75334.html">t00ls (CN)</a></strong></p><h1><strong>GhostLock Linux Kernel Flaw Enables Root Access and Container Escape</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers disclosed GhostLock, tracked as CVE-2026-43499, a 15-year-old Linux kernel vulnerability affecting kernels from 2.6.39 through 7.1 unless patched. The flaw reportedly enables reliable local privilege escalation and container escape, with a 97% exploit reliability rate demonstrated in Google&#8217;s kernelCTF environment. Organizations running Linux infrastructure, container hosts, shared hosting, or cloud workloads should prioritize kernel patching immediately.</strong></p><p><strong>Analyst Comments:</strong> This is the kind of Linux kernel bug defenders hate: old, widespread, local, reliable, and useful for breaking out of containers. It does not require elevated privileges or namespaces, which makes the attack surface much broader than a typical &#8220;only exploitable in weird configurations&#8221; kernel issue. The container escape angle is the real operational problem. A low-privileged process inside a container becoming root on the host turns a workload compromise into a platform compromise. For cloud providers, CI/CD runners, Kubernetes nodes, shared hosting, and multi-tenant Linux environments, this deserves urgent attention.</p><p><strong>READ THE STORY: <a href="https://gbhackers.com/15-year-old-ghostlock-linux-kernel-vulnerability/">GBhackers</a></strong></p><h1><strong>Items of interest</strong></h1><h1><strong>RedAmon Brings AI-Driven Recon, Exploitation, and Remediation Into One Offensive Security Pipeline</strong></h1><p><strong>Bottom Line Up Front (BLUF): RedAmon is a new open-source, Docker-based offensive security platform that combines asset reconnaissance, vulnerability exploitation, post-exploitation workflows, AI-assisted vulnerability triage, automated code remediation, and GitHub pull request generation. The platform is designed to turn fragmented penetration testing activity into an end-to-end pipeline, but its capabilities also underscore the need for strict authorization controls around AI-enabled security tooling.</strong></p><p><strong>Analyst Comments:</strong> The interesting piece is not just that it can scan or exploit; plenty of tools already do that. The shift is the chaining: recon data flows into a graph, AI agents reason over the attack surface, exploitation paths are tested, findings are triaged, and remediation code can be pushed into a pull request. That is powerful for authorized security teams, especially where vulnerability validation and remediation handoff are slow. It also raises the stakes. A tool that can coordinate recon, exploitation, post-exploitation, and code changes needs governance, scope controls, approval gates, logging, and human review. The built-in confirmation prompts and Rules of Engagement support are important, but organizations should still treat this as high-risk tooling.</p><p><strong>READ THE STORY: <a href="https://www.anquanke.com/post/id/315747">Anquanke</a></strong></p><h1><strong>Build an Autonomous AI Red Team Agent from Scratch | LangGraph + Metasploit + Neo4j Full Tutorial (Video)</strong></h1><p><strong>FROM THE MEDIA: A public RedAmon tutorial walks users through building an open-source AI-powered red team agent capable of automating penetration testing workflows from reconnaissance through exploitation and post-exploitation. The tutorial frames the system as a fully autonomous security assessment agent with source code available, highlighting both the defensive value of AI-assisted testing and the operational risk of offensive automation being packaged for broad use.</strong></p><div id="youtube2-mO5CCkYlY94" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;mO5CCkYlY94&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/mO5CCkYlY94?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1><strong>RED TEAMING explained in 8 Minutes (Video)</strong></h1><p><strong>FROM THE MEDIA: </strong><span>The useful takeaway here is the distinction between &#8220;finding vulnerabilities&#8221; and &#8220;testing whether an organization can withstand a realistic attack path.&#8221; Penetration testing usually checks whether doors are locked. Red teaming asks whether an attacker can get inside, move around, avoid detection, and achieve an objective before defenders respond.</span></p><div id="youtube2--X1vf69CxCA" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;-X1vf69CxCA&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/-X1vf69CxCA?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don&#8217;t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com. </p>]]></content:encoded></item><item><title><![CDATA[Daily Drop (1331) ]]></title><description><![CDATA[07-07-26]]></description><link>https://bragg.substack.com/p/daily-drop-1331</link><guid isPermaLink="false">https://bragg.substack.com/p/daily-drop-1331</guid><dc:creator><![CDATA[Bob Bragg]]></dc:creator><pubDate>Tue, 07 Jul 2026 08:22:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!IXDQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca384972-b246-4204-8677-12cbfa0d1bea_1448x1086.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Tuesday, July 07, 2026 // <a href="https://buymeacoffee.com/infodom">Buy Bob a Coffee</a> // <a href="https://ghostwire.news">Ghostwire</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IXDQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca384972-b246-4204-8677-12cbfa0d1bea_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IXDQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca384972-b246-4204-8677-12cbfa0d1bea_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!IXDQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca384972-b246-4204-8677-12cbfa0d1bea_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!IXDQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca384972-b246-4204-8677-12cbfa0d1bea_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!IXDQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca384972-b246-4204-8677-12cbfa0d1bea_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IXDQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca384972-b246-4204-8677-12cbfa0d1bea_1448x1086.png" width="1448" height="1086" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ca384972-b246-4204-8677-12cbfa0d1bea_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3174959,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://bragg.substack.com/i/205732905?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca384972-b246-4204-8677-12cbfa0d1bea_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IXDQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca384972-b246-4204-8677-12cbfa0d1bea_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!IXDQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca384972-b246-4204-8677-12cbfa0d1bea_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!IXDQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca384972-b246-4204-8677-12cbfa0d1bea_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!IXDQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca384972-b246-4204-8677-12cbfa0d1bea_1448x1086.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>BeyondTrust Patches Critical Pre-Auth Bypass Flaws in Remote Support and Privileged Remote Access</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>BeyondTrust released patches for four vulnerabilities affecting Remote Support and Privileged Remote Access, including two critical pre-authentication access-control bypass flaws rated CVSS 9.2. Successful exploitation could allow unauthenticated attackers to gain unauthorized access to vulnerable appliances, including accounts with elevated privileges, under specific authentication configurations. Organizations running RS or PRA 25.3.2 or earlier should upgrade to 25.3.3 or later immediately.</strong></p><p><strong>Analyst Comments:</strong> Remote support and privileged access appliances are not &#8220;just another patch.&#8221; They sit directly in the administrative control path, which makes pre-auth flaws especially dangerous. If attackers can bypass authentication on these systems, they may inherit the same reach defenders gave the tool for legitimate administration. BeyondTrust says it is not aware of exploitation in the wild, but that should not slow anyone down. RS and PRA have already been targeted in prior campaigns, including exploitation of CVE-2024-12356 and CVE-2026-1731 to deploy web shells and backdoors. That history matters. Attackers know these products are high-value, and critical pre-authentication bugs in remote access infrastructure tend to move from advisory to exploitation quickly.</p><p><strong>READ THE STORY: <a href="https://thehackernews.com/2026/07/beyondtrust-patches-critical-auth.html">THN</a></strong></p><h1><strong>Multiple High-Severity Citrix NetScaler Vulnerabilities: Patch Internet-Facing ADC and Gateway Appliances Immediately</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The Centre for Cybersecurity Belgium is warning organizations to urgently patch six high-severity vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway. The flaws include memory overread, memory overflow, arbitrary file read, and denial-of-service issues, with several exploitable remotely without authentication. NetScaler Gateway sits directly in the authentication and remote access path for many organizations, making exposed appliances high-value targets.</strong></p><p><strong>Analyst Comments:</strong> These appliances often front VPN, ICA Proxy, AAA, SAML, load balancing, and remote access workflows&#8212;meaning compromise or disruption can quickly become an enterprise-wide problem. CVE-2026-8451 is especially concerning because it involves unauthenticated memory overread when NetScaler is configured as a SAML IDP, putting it in the same uncomfortable neighborhood as prior &#8220;CitrixBleed&#8221;-style risk. CCB does not state that exploitation is confirmed in the wild, but public technical analysis is already available, so exposure windows matter.</p><p><strong>READ THE STORY: <a href="https://ccb.belgium.be/advisories/warning-multiple-high-vulnerabilities-citrix-netscaler-patch-immediately">CCB</a></strong></p><h1><strong>Tenda Router Firmware Contains Hidden Admin Backdoor: CERT/CC Warns of Full Device Takeover Risk</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>CERT/CC is warning that several Tenda router firmware versions contain an undocumented administrative backdoor tracked as CVE-2026-11405. The flaw allows attackers to bypass normal password verification and gain full admin access to the device web management interface without valid credentials. The issue remains unpatched as of the report, so affected users should disable remote management and reduce exposure immediately.</strong></p><p><strong>Analyst Comments:</strong> The Hacker News reported that CERT/CC disclosed CVE-2026-11405, an undocumented authentication backdoor affecting multiple Tenda firmware versions. The backdoor exists inside the login() function of the /bin/httpd web server binary. The normal login flow first performs MD5-based password verification, but if authentication fails, the firmware checks an alternate value stored as sys.rzadmin.password. If the supplied password matches that hidden configuration value, the device grants administrator-level access with role=2 and creates a valid elevated session. CERT/CC noted that the associated rzadmin username is not actually validated, meaning any username can succeed when paired with the backdoor password. The mechanism is not documented and is not visible through the administrative interface.</p><p><strong>READ THE STORY: <a href="https://thehackernews.com/2026/07/certcc-warns-of-hidden-admin-backdoor.html">THN</a></strong></p><h1><strong>AI-Driven CNAPP Platforms in 2026: Cloud Security Tools Still Fail Without Real Detection Workflows</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A Codeby analysis compares five major CNAPP platforms&#8212;Wiz, CrowdStrike Falcon Cloud Security, Microsoft Defender for Cloud, Orca Security, and Prisma Cloud&#8212;against real-world cloud detection needs. The key finding is blunt: high compliance scores and clean CSPM dashboards do not equal attack-path coverage. Modern cloud intrusions increasingly rely on valid credentials, identity chaining, misconfigured roles, and overlooked storage access, so SOC teams need platforms that correlate posture, identity, runtime telemetry, and SIEM alerts&#8212;not just isolated findings.</strong></p><p><strong>Analyst Comments:</strong> The strongest point in the article is the gap between configuration visibility and exploitability. A CSPM tool can tell you an S3 bucket, IAM policy, or workload is misconfigured. That does not mean it can explain whether an attacker can move from a compromised service account into production, reach sensitive data, disable logging, and exfiltrate storage contents. That attack-path context is where CNAPP platforms are supposed to earn their keep. The trade-off remains familiar. Wiz is strong for fast deployment and graph-based attack-path analysis, but it does not provide inline runtime blocking. CrowdStrike has stronger runtime visibility through its agent model, but deployment and cost are real constraints. Defender for Cloud makes the most sense in Azure-heavy environments, while AWS and GCP coverage requires more work. Orca reduces operational overhead through agentless scanning, but snapshot-based detection is not the same as real-time protection. Prisma Cloud is powerful in mature DevSecOps environments, but the learning curve and operational load are higher.</p><p><strong>READ THE STORY: <a href="https://codeby.net/threads/cloud-security-platformy-2026-sravneniye-ai-driven-cnapp-po-real-nomu-detection-pokrytiyu.94536/">Codeby(RU)</a></strong></p><h1><strong>Rare Werewolf Phishing Campaign Uses Fake Contract Thread to Deploy Hidden AnyDesk and Steal Credentials</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Angara MTDR reported a new phishing campaign attributed to Rare Werewolf, also tracked as Rezet or Librarian Ghouls. The campaign uses convincing business-email lures and password-protected archives to deliver a malicious executable disguised as a contract document. Once opened, the payload installs AnyDesk in hidden mode, configures unattended access, extracts saved browser and email credentials, exfiltrates results over attacker-controlled SMTP infrastructure, weakens Windows defenses, and removes many local artifacts.</strong></p><p><strong>Analyst Comments:</strong> This is not exotic malware, but it is practical, quiet, and effective. Rare Werewolf is leaning on a familiar playbook: business-context phishing, encrypted archives to dodge scanners, legitimate remote access tooling, and credential theft utilities that defenders have seen for years. The social engineering is the real delivery mechanism here. The email mimics normal corporate contract review traffic, uses &#8220;Fwd&#8221; and &#8220;Re&#8221; prefixes, references specific contract language, provides an archive password, and even includes a fake security-mail-gateway notice to lower suspicion.</p><p><strong>READ THE STORY: <a href="https://habr.com/ru/companies/angarasecurity/articles/1056230/">habr(RU)</a></strong></p><h1><strong>JADEPUFFER Shows Agentic Ransomware Has Arrived: AI-Driven Attack Chain Runs from Exploitation to Destruction</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The Centre for Cybersecurity Belgium is warning organizations to urgently patch six high-severity vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway. The flaws include memory overread, memory overflow, arbitrary file read, and denial-of-service issues, with several exploitable remotely without authentication. NetScaler Gateway sits directly in the authentication and remote access path for many organizations, making exposed appliances high-value targets.</strong></p><p><strong>Analyst Comments:</strong> Security researchers report that JADEPUFFER represents the first fully documented case of &#8220;agentic ransomware,&#8221; where an LLM-driven AI Agent executed the attack chain end to end without direct human keyboard control. The operation reportedly abused a patched Langflow vulnerability, harvested credentials, moved through MinIO, MySQL, and Nacos infrastructure, encrypted 1,342 configuration records, and then shifted into destructive database deletion. The real issue is not novel malware&#8212;it is the automation of known weaknesses at machine speed.</p><p><strong>READ THE STORY: <a href="https://www.anquanke.com/post/id/315724">Anquanke (CN)</a></strong></p><h1><strong>Oracle PeopleSoft Zero-Day Campaign Hits Nissan: Employee HR and Payroll Data May Be Exposed</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Nissan says a cyberattack tied to Oracle PeopleSoft zero-day CVE-2026-35273 may have exposed personal data belonging to current and former employees in the United States, Brazil, Mexico, and Canada. The potentially affected data includes contact details, bank account information, tax records, government-issued ID numbers, and dependent or beneficiary information. Oracle reportedly warned Nissan that attackers targeted PeopleSoft systems as part of a broader campaign affecting more than 100 organizations.</strong></p><p><strong>Analyst Comments:</strong> PeopleSoft is exactly the kind of enterprise system attackers love: old, business-critical, full of sensitive HR and payroll data, and often treated as &#8220;back office&#8221; infrastructure until something breaks. That makes this incident more than a Nissan problem. If the reporting is accurate, CVE-2026-35273 gave attackers a clean path into high-value employee data across multiple organizations.</p><p><strong>READ THE STORY: <a href="https://www.t00ls.com/articles-75331.html">t00ls (CN)</a></strong></p><h1><strong>Items of interest</strong></h1><h1><strong>Flock &#8220;Vehicle Fingerprint&#8221; Expands Surveillance Beyond License Plate Reads</strong></h1><p><strong>Bottom Line Up Front (BLUF): Bruce Schneier highlights a 2024 Flock presentation showing that the company&#8217;s cameras can help law enforcement identify vehicles even without full license plate data. Flock&#8217;s &#8220;Vehicle Fingerprint&#8221; capability reportedly lets officers search for decals, bumper stickers, racks, temporary tags, unique state tags, and vehicles believed to be traveling together.</strong></p><p><strong>Analyst Comments:</strong> The issue is not just whether police can read plates; it is whether they can build persistent movement profiles from visual features that people do not think of as identifiers. A car with a distinctive bumper sticker, roof rack, dent pattern, temporary tag, or state-specific marker can become trackable even when the plate is missing, obscured, or unknown. Schneier&#8217;s comparison to cellphone location correlation is the right frame: once a system can identify objects that repeatedly appear near each other, it can infer relationships, routines, and associations. That is useful for investigations, but it also creates obvious privacy and abuse risks when deployed at scale.</p><p><strong>READ THE STORY: <a href="https://www.schneier.com/blog/archives/2026/07/flock-cameras-can-surveil-cars-without-license-plates.html">Schneier</a></strong></p><h1><strong>Flock Cameras: What Your City Isn&#8217;t Telling You (Video)</strong></h1><p><strong>FROM THE MEDIA: Flock Safety's license plate reader network has spread to over 5,000 cities, tracking vehicles with no warrant required. Federal criminal defense attorney Ron Chapman examines the Flock camera surveillance system, the Fourth Amendment questions surrounding it, and the wave of cities now ripping these cameras out.</strong></p><div id="youtube2-MqVJ-_6QDPM" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;MqVJ-_6QDPM&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/MqVJ-_6QDPM?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1><strong>FLOCK CAMERAS! Everything you NEED TO KNOW (Video)</strong></h1><p><strong>FROM THE MEDIA: </strong><span>Flock Safety cameras are not just license plate readers. According to Bruce Schneier&#8217;s summary of a 2024 company presentation, Flock can also identify vehicles using decals, bumper stickers, racks, temporary tags, unique state tags, and other visual characteristics when full plate data is unavailable. The company calls this a &#8220;Vehicle Fingerprint,&#8221; giving law enforcement another way to search, track, and correlate vehicles across locations.</span></p><div id="youtube2-PxH5UShouSY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;PxH5UShouSY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/PxH5UShouSY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don&#8217;t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com. </p>]]></content:encoded></item><item><title><![CDATA[Daily Drop (1330) ]]></title><description><![CDATA[07-03-26]]></description><link>https://bragg.substack.com/p/daily-drop-1330</link><guid isPermaLink="false">https://bragg.substack.com/p/daily-drop-1330</guid><dc:creator><![CDATA[Bob Bragg]]></dc:creator><pubDate>Fri, 03 Jul 2026 13:17:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!wGJQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00754b3f-5fd3-4a44-8540-ff0ccad3c590_1448x1086.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Friday, July 03, 2026 // <a href="https://buymeacoffee.com/infodom">Buy Bob a Coffee</a> // <a href="https://ghostwire.news">Ghostwire</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wGJQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00754b3f-5fd3-4a44-8540-ff0ccad3c590_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wGJQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00754b3f-5fd3-4a44-8540-ff0ccad3c590_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!wGJQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00754b3f-5fd3-4a44-8540-ff0ccad3c590_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!wGJQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00754b3f-5fd3-4a44-8540-ff0ccad3c590_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!wGJQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00754b3f-5fd3-4a44-8540-ff0ccad3c590_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wGJQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00754b3f-5fd3-4a44-8540-ff0ccad3c590_1448x1086.png" width="1448" height="1086" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/00754b3f-5fd3-4a44-8540-ff0ccad3c590_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2927419,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://bragg.substack.com/i/204873271?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00754b3f-5fd3-4a44-8540-ff0ccad3c590_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wGJQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00754b3f-5fd3-4a44-8540-ff0ccad3c590_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!wGJQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00754b3f-5fd3-4a44-8540-ff0ccad3c590_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!wGJQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00754b3f-5fd3-4a44-8540-ff0ccad3c590_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!wGJQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00754b3f-5fd3-4a44-8540-ff0ccad3c590_1448x1086.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>Iran&#8217;s Wartime Internet Controls Reshape Connectivity Into a Tiered Access System</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Iran&#8217;s internet restrictions during a 40-day regional military confrontation did more than cut access; they restructured connectivity into a layered, monetized system. Global internet access became unstable or unavailable for most users, while selected groups received limited or privileged access through institutional channels, informal markets, and expensive circumvention tools.</strong></p><p><strong>Analyst Comments:</strong> It is infrastructure-level governance: raise friction, ration access, monetize scarcity, and decide who gets reliable connectivity. That model is harder to measure than a full blackout and potentially more durable because it allows the state to preserve critical business and institutional access while constraining the broader population. The result is a dual internet: one expensive, unstable, and filtered for most users, and another selectively available to journalists, institutions, businesses, researchers, and technically privileged users. For civil society, businesses, and security teams, the risk is that &#8220;temporary&#8221; crisis controls become normalized operating conditions.</p><p><strong>READ THE STORY: <a href="https://pulse.internetsociety.org/en/blog/2026/06/how-war-restructured-irans-internet-into-a-tiered-and-monetized-system/">Internet Society Pulse</a></strong></p><h1><strong>Anthropic Proposes Cyber Jailbreak Severity Framework for Claude Fable 5 Safeguards</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Anthropic released technical details on the cybersecurity safeguards built into its redeployed Claude Fable 5 model and introduced a proposed Cyber Jailbreak Severity (CJS) framework for measuring AI jailbreak risk. The framework is meant to give industry and government stakeholders a common way to assess how dangerous jailbreak techniques are, especially when they could unlock offensive cyber capabilities.</strong></p><p><strong>Analyst Comments:</strong> The same model behavior that helps a defender analyze malware, write detections, or triage incidents can also help an attacker refine exploit chains, automate credential attacks, or scale phishing operations. The CJS framework is useful because it focuses on practical risk rather than vague &#8220;AI safety&#8221; language&#8212;attacker uplift, breadth, weaponization, and discoverability are the right dimensions to measure. The tradeoff is obvious: tighter classifiers reduce abuse but increase false positives for legitimate security teams. Expect this tension to keep shaping enterprise AI adoption, especially for SOC, red-team, and incident-response workflows.</p><p><strong>READ THE STORY: <a href="https://gbhackers.com/anthropic-unveils-cyber-jailbreak-severity-framework/">GBhackers</a></strong></p><h1><strong>ChatGPT File Download Flow Flaw Exposed Sandbox Path Traversal Risk</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> Z<strong>er0dac disclosed a remediated ChatGPT vulnerability chain that combined prompt-based guardrail manipulation with a traditional path traversal flaw in the platform&#8217;s file download flow. The proof of concept reportedly allowed access to </strong><code>/etc/passwd</code><strong> inside ChatGPT&#8217;s sandboxed execution environment, limiting real-world impact but highlighting how LLM workflow logic and conventional web app bugs can combine into exploitable chains.</strong></p><p><strong>Analyst Comments:</strong> The researcher uploaded a dummy HTML file, then requested a download link. ChatGPT initially denied the request based on temporary file deletion logic. The researcher then reframed the request by asking for an edit to the file, claiming it had been accidentally deleted, and requesting a re-download link. This produced a backend download URL using the structure <code>/backend-api/conversation/{id}/interpreter/download?message_id={id}&amp;sandbox_path=/mnt/data/test.html</code>.</p><p><strong>READ THE STORY: <a href="https://cybersecuritynews.com/chatgpt-file-download-flow-vulnerability/">CSN</a></strong></p><h1><strong>Vect Ransomware Partners With TeamPCP in Supply Chain Credential-Theft Pipeline</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Sophos is warning of an &#8220;industrialized ransomware&#8221; model after Vect ransomware partnered with TeamPCP, a cybercriminal group known for large-scale software supply chain credential theft. The tie-up means organizations whose developer, CI/CD, cloud, SSH, or Kubernetes credentials were stolen by TeamPCP may face elevated risk of follow-on Vect ransomware deployment.</strong></p><p><strong>Analyst Comments:</strong> TeamPCP steals the keys at scale, especially from developer and security tooling ecosystems, while Vect brings ransomware operations and monetization. That division of labor shortens the path from credential theft to extortion and makes the software development environment a high-value ransomware staging ground. The Trivy compromise example is the warning shot: when CI/CD workflows and cloud tokens are exposed, attackers may not need malware-heavy intrusion chains. They can walk in through trusted automation and turn stolen access into ransomware impact.</p><p><strong>READ THE STORY: <a href="https://www.infosecurity-magazine.com/news/industrialized-cyberattacks/">InfoSecMag</a></strong></p><h1><strong>Pegasus Spyware Hits European Parliament Member Investigating Spyware Abuse</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Former European Parliament member Stelios Kouloglou was repeatedly hacked with NSO Group&#8217;s Pegasus spyware while serving on the PEGA Committee, the EU body investigating abuse of Pegasus and similar commercial surveillance tools. Citizen Lab forensic analysis found Pegasus infections on Kouloglou&#8217;s iPhone in October 2022 and March 2023, potentially exposing confidential committee documents and deliberations.</strong></p><p><strong>Analyst Comments:</strong> A lawmaker investigating commercial spyware abuse was allegedly compromised by the very class of tool his committee was scrutinizing. Even without attribution to a specific government, the targeting pattern is serious: Citizen Lab says the infrastructure overlaps with a campaign against Russian and Belarusian-speaking exiled journalists and activists in Europe, suggesting a Pegasus customer authorized to operate across multiple EU jurisdictions. The bigger issue is not just one hacked phone; it is the failure of political and legal controls around mercenary spyware. These tools keep showing up against journalists, activists, opposition figures, and now lawmakers involved in oversight.</p><p><strong>READ THE STORY: <a href="https://thehackernews.com/2026/07/european-parliament-member.html">THN</a></strong></p><h1><strong>China Expands AI-Assisted VPN Detection to Tighten Great Firewall Controls</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>NetAskari reports that Chinese security vendors and research institutions are advancing AI- and machine-learning-based systems to detect unauthorized VPN traffic, particularly in universities and other controlled networks. The shift is not a sudden &#8220;end of VPNs&#8221; in China, but an incremental hardening of the Great Firewall&#8217;s ability to classify encrypted circumvention traffic without relying on full packet inspection.</strong></p><p><strong>Analyst Comments:</strong> Traditional VPN protocols like OpenVPN, IPSec, WireGuard, and vanilla Shadowsocks have already become unreliable in China, but newer obfuscation tools made enforcement harder. Machine-learning approaches change the game by looking at flow behavior &#8212; packet timing, duration, window sizes, payload ratios, and other metadata &#8212; instead of needing to read encrypted content. That does not make circumvention impossible, but it raises the technical bar and makes casual &#8220;wall climbing&#8221; riskier, especially on campuses and managed networks where authorities can combine traffic analysis with user identity.</p><p><strong>READ THE STORY: <a href="https://netaskari.substack.com/p/chinas-anti-vpn-measures-chasing">Netaskari</a></strong></p><h1><strong>Google Disrupts NetNut Residential Proxy Network Used by Cybercriminals and Espionage Groups</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Google, working with the FBI, Lumen, and other partners, disrupted NetNut, a large residential proxy network also known as Popa. Google says the network consisted of roughly 2 million compromised home devices, including smart TVs, streaming boxes, and other consumer hardware, that were abused to route malicious traffic and hide attacker infrastructure.</strong></p><p><strong>Analyst Comments:</strong> Residential proxy networks are a major enabler for modern cybercrime because they let attackers blend into normal consumer internet traffic. That matters for account takeover, credential stuffing, password spraying, fraud, scraping, and espionage operations where origin masking is the point. The consumer angle is also ugly: people buying cheap streaming boxes or installing apps that promise money for &#8220;unused bandwidth&#8221; may unknowingly turn their home networks into attacker exit nodes. Google&#8217;s action will hurt NetNut&#8217;s utility, but this is not a one-and-done fix. Proxy providers often share, resell, or rebuild infrastructure, so defenders should keep treating residential IP traffic as a risk signal when behavior looks automated or abusive.</p><p><strong>READ THE STORY: <a href="https://securityaffairs.com/194690/cyber-crime/law-enforcememt-operation-disrupted-malicious-residential-proxy-networks-netnut.html">Security Affairs</a></strong></p><h1><strong>The Gentlemen Ransomware Group Uses Custom Go Backdoor for Command Execution and SOCKS Pivoting</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> A <strong>ransomware group The Gentlemen is deploying a custom Go-based backdoor shortly before encryption to execute commands, establish SOCKS proxy tunnels, and pivot through compromised enterprise networks. The implant supports reconnaissance and internal movement, suggesting the group is investing in stealthier pre-ransomware operations rather than relying only on smash-and-encrypt tactics.</strong></p><p><strong>Analyst Comments:</strong> This is ransomware tradecraft moving closer to full intrusion operations. A SOCKS-capable backdoor gives operators a flexible internal foothold: they can route traffic through a compromised host, reach segmented systems, scan from inside the network, and stage the environment before detonating ransomware. The one-day gap between backdoor deployment and encryption is important because it gives defenders a narrow detection window. Watch for unusual Go binaries, Yamux-based TCP sessions, WMI-based UUID collection, event log clearing, cmd.exe child processes, and internal scanning from hosts that do not normally perform admin activity.</p><p><strong>READ THE STORY: <a href="https://cyberpress.org/gentlemen-backdoor-socks-pivot/">Cyberpress</a></strong></p><h1><strong>Decades-Old Squid Proxy Flaw &#8220;Squidbleed&#8221; Can Leak User Data From Shared Proxies</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Calif.io disclosed CVE-2026-47729, a Squid Proxy memory leak vulnerability dating back to 1997. Dubbed &#8220;Squidbleed&#8221; because of its Heartbleed-like behavior, the flaw can expose prior users&#8217; uncleared HTTP request data in shared proxy environments.</strong></p><p><strong>Analyst Comments:</strong> The FTP parser angle matters: exploitation requires an attacker-controlled FTP server reachable through the proxy, but in corporate, school, or public Wi-Fi proxy environments, that can still be enough to siphon sensitive data from other users. The risk is narrower than Heartbleed because standard HTTPS CONNECT tunnels are not affected, but cleartext HTTP, TLS-terminating proxy deployments, legacy apps, API keys, session tokens, and internal credentials are still in play. Disable FTP support if it is not needed and move quickly to patched Squid builds.</p><p><strong>READ THE STORY: <a href="https://www.securityweek.com/decades-old-squid-proxy-flaw-squidbleed-can-expose-user-data/">Securityweek</a></strong></p><h1><strong>Microsoft Exchange SSRF Flaw Enables Arbitrary File Reads by Low-Privileged Users</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>CVE-2026-45504, a Microsoft Exchange Server 2019 SSRF vulnerability rated CVSS 8.8, allows authenticated low-privileged users to read arbitrary files from vulnerable Exchange servers. The flaw stems from improper URL validation in Exchange&#8217;s WOPI integration, specifically in how the OneDriveProUtilities component handles WebApplicationUrl values when generating WAC tokens.</strong></p><p><strong>Analyst Comments:</strong> A low-privileged mailbox account is often not hard to obtain through phishing, password spraying, or credential reuse. From there, arbitrary file read can expose configuration data, local secrets, service context, or other sensitive files that help escalate an intrusion. The <code>file://</code> scheme abuse is the core issue: Exchange trusts a URL returned by an attacker-controlled endpoint, then processes it as a local file request. Until patches are available and deployed, defenders should watch for unusual EWS reference attachments, suspicious WOPI-related requests, outbound calls from Exchange to unknown hosts, and attempts to access local file paths through backend workflows.</p><p><strong>READ THE STORY: <a href="https://gbhackers.com/microsoft-exchange-ssrf-vulnerability/">GBhackers</a></strong></p><h1><strong>Fake API Documentation Tricks AI Agents Into Sending Crypto Payments</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Attackers are using fake API documentation, SEO poisoning, malicious JSON-LD metadata, and hidden page instructions to manipulate autonomous AI agents into making cryptocurrency payments. The campaign abuses indirect prompt injection by embedding payment instructions in web content that agents may treat as authoritative during automated development or research workflows.</strong></p><p><strong>Analyst Comments:</strong> This is prompt injection with a payment rail attached. The attacker does not need to compromise the model directly; they poison the information the agent consumes. Fake documentation pages are especially dangerous because developers and coding agents already expect them to contain setup steps, licensing instructions, package names, and API keys. Once structured metadata says a &#8220;developer license&#8221; is required, weaker agent workflows may treat the payment as a legitimate task rather than a scam. Any agent allowed to browse the web and spend money needs hard transaction gates, source validation, and a rule that web content can never authorize payments on its own.</p><p><strong>READ THE STORY: <a href="https://gbhackers.com/fake-api-documentation-to-trick-ai/">GBhackers</a></strong></p><h1><strong>Items of interest</strong></h1><h1><strong>Flock &#8220;Vehicle Fingerprint&#8221; Expands Surveillance Beyond License Plate Reads</strong></h1><p><strong>Bottom Line Up Front (BLUF): Bruce Schneier highlights a 2024 Flock presentation showing that the company&#8217;s cameras can help law enforcement identify vehicles even without full license plate data. Flock&#8217;s &#8220;Vehicle Fingerprint&#8221; capability reportedly lets officers search for decals, bumper stickers, racks, temporary tags, unique state tags, and vehicles believed to be traveling together.</strong></p><p><strong>Analyst Comments:</strong> The issue is not just whether police can read plates; it is whether they can build persistent movement profiles from visual features that people do not think of as identifiers. A car with a distinctive bumper sticker, roof rack, dent pattern, temporary tag, or state-specific marker can become trackable even when the plate is missing, obscured, or unknown. Schneier&#8217;s comparison to cellphone location correlation is the right frame: once a system can identify objects that repeatedly appear near each other, it can infer relationships, routines, and associations. That is useful for investigations, but it also creates obvious privacy and abuse risks when deployed at scale.</p><p><strong>READ THE STORY: <a href="https://www.schneier.com/blog/archives/2026/07/flock-cameras-can-surveil-cars-without-license-plates.html">Schneier</a></strong></p><h1><strong>Flock Cameras: What Your City Isn&#8217;t Telling You (Video)</strong></h1><p><strong>FROM THE MEDIA: Flock Safety's license plate reader network has spread to over 5,000 cities, tracking vehicles with no warrant required. Federal criminal defense attorney Ron Chapman examines the Flock camera surveillance system, the Fourth Amendment questions surrounding it, and the wave of cities now ripping these cameras out.</strong></p><div id="youtube2-MqVJ-_6QDPM" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;MqVJ-_6QDPM&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/MqVJ-_6QDPM?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1><strong>FLOCK CAMERAS! Everything you NEED TO KNOW (Video)</strong></h1><p><strong>FROM THE MEDIA: </strong><span>Flock Safety cameras are not just license plate readers. According to Bruce Schneier&#8217;s summary of a 2024 company presentation, Flock can also identify vehicles using decals, bumper stickers, racks, temporary tags, unique state tags, and other visual characteristics when full plate data is unavailable. The company calls this a &#8220;Vehicle Fingerprint,&#8221; giving law enforcement another way to search, track, and correlate vehicles across locations.</span></p><div id="youtube2-PxH5UShouSY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;PxH5UShouSY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/PxH5UShouSY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don&#8217;t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com. </p>]]></content:encoded></item><item><title><![CDATA[Daily Drop (1329) ]]></title><description><![CDATA[06-30-26]]></description><link>https://bragg.substack.com/p/daily-drop-1329</link><guid isPermaLink="false">https://bragg.substack.com/p/daily-drop-1329</guid><dc:creator><![CDATA[Bob Bragg]]></dc:creator><pubDate>Wed, 01 Jul 2026 01:44:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!O30m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dc2d631-8c23-4596-a305-15a92e5d9b81_1448x1086.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Tuesday, Jun 30, 2026 // <a href="https://buymeacoffee.com/infodom">Buy Bob a Coffee</a> // <a href="https://ghostwire.news">Ghostwire</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!O30m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dc2d631-8c23-4596-a305-15a92e5d9b81_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!O30m!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dc2d631-8c23-4596-a305-15a92e5d9b81_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!O30m!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dc2d631-8c23-4596-a305-15a92e5d9b81_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!O30m!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dc2d631-8c23-4596-a305-15a92e5d9b81_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!O30m!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dc2d631-8c23-4596-a305-15a92e5d9b81_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!O30m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dc2d631-8c23-4596-a305-15a92e5d9b81_1448x1086.png" width="1448" height="1086" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9dc2d631-8c23-4596-a305-15a92e5d9b81_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3391078,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://bragg.substack.com/i/204204011?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dc2d631-8c23-4596-a305-15a92e5d9b81_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!O30m!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dc2d631-8c23-4596-a305-15a92e5d9b81_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!O30m!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dc2d631-8c23-4596-a305-15a92e5d9b81_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!O30m!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dc2d631-8c23-4596-a305-15a92e5d9b81_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!O30m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dc2d631-8c23-4596-a305-15a92e5d9b81_1448x1086.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>FCC Expands Ban on Chinese-Produced Network Equipment Tied to Cyber Risks</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The FCC moved on June 26 to block imports of equipment and services from firms on its Covered List, closing a loophole that allowed previously approved older models to remain available in the U.S. market. The rule targets Chinese telecom and surveillance vendors including Huawei, ZTE, and Hikvision, along with Russia&#8217;s Kaspersky, as Washington continues pushing adversarial technology out of core U.S. networks.</strong></p><p><strong>Analyst Comments:</strong> Older approved equipment can carry the same security risks as newer banned models, especially when vendors remain tied to adversarial governments or intelligence requirements. The gap is that the rule does not force operators to rip and replace equipment already deployed, meaning some risk remains baked into existing infrastructure. Expect the FCC to keep expanding its national security role, especially as concerns grow around Chinese access to telecom networks, routers, drones, surveillance systems, and submarine cable infrastructure. The next logical step would be restricting Covered List firms from providing domestic telecom services or interconnecting with U.S. providers.</p><p><strong>READ THE STORY: <a href="https://www.fdd.org/analysis/2026/06/30/fcc-introduces-new-bans-on-chinese-produced-equipment-linked-to-cyber-risks/">FDD</a></strong></p><h1><strong>CISA Re-Staffing Push Emerges After Deep Federal Cyber Workforce Cuts</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>CyberScoop reports that OMB Director Russell Vought told lawmakers he is open to working with DHS Secretary Markwayne Mullin on rebuilding CISA&#8217;s workforce after major Trump administration cuts. Mullin has floated adding back roughly 600 personnel, while CISA has reportedly lost more than 1,000 staff from an agency that had about 3,400 employees at the end of the Biden administration.</strong></p><p><strong>Analyst Comments:</strong> Cyber talent is hard to recruit in normal conditions; doing it after layoffs, political scrutiny, and internal disruption makes the pitch even harder. The operational risk is straightforward: fewer people means less capacity for incident response, infrastructure support, vulnerability coordination, election security work, and engagement with state, local, and private-sector partners. Even if leadership approves new billets, restoring institutional knowledge and trust will take longer than posting job openings.</p><p><strong>READ THE STORY: <a href="https://cyberscoop.com/russell-vought-cisa-staffing-trump-budget-cuts/">Cyberscoop</a></strong></p><h1><strong>U.S. Lifts Export Controls on Anthropic&#8217;s Mythos and Fable AI Models</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The Trump administration is lifting export controls on Anthropic&#8217;s Mythos 5 and Fable 5 models after the company reached an agreement with the Commerce Department. The decision removes licensing requirements for export, reexport, in-country transfer, and deemed export of the models, reversing earlier restrictions tied to concerns that foreign nationals could access advanced AI capabilities through jailbreaks.</strong></p><p><strong>Analyst Comments:</strong> This is a major policy shift for frontier AI controls. The government appears to be moving from hard access restrictions toward negotiated safeguards, monitoring, and standards cooperation. That may be more practical than pretending jailbreaks can be eliminated entirely, but it also raises the risk that powerful models with cyber-relevant capabilities become more widely accessible before enforcement mechanisms are mature. For defenders, the signal is clear: advanced AI capabilities are moving back into broader circulation, and security teams should assume threat actors will continue testing these models for phishing automation, exploit development support, vulnerability research acceleration, and operational tooling.</p><p><strong>READ THE STORY: <a href="https://www.wired.com/story/trump-administration-lifts-export-controls-on-anthropics-mythos-and-fable-ai-models/">Wired</a></strong></p><h1><strong>China-Linked CL-STA-1062 Targets Southeast Asian Critical Infrastructure</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A China-linked threat group CL-STA-1062 has shifted from targeting Taiwanese web-hosting infrastructure to compromising critical infrastructure and government-linked organizations across Southeast Asia. Palo Alto Networks says the group has targeted more than 10 regional organizations, including electricity and water providers, and deployed a new lightweight C# backdoor called TinyRCT.</strong></p><p><strong>Analyst Comments:</strong> The critical infrastructure targeting is the key signal here, even if researchers have not observed direct operational technology malware or electricity-related data theft. TinyRCT&#8217;s anti-analysis and self-destruct features suggest an actor trying to preserve access and limit forensic visibility. The open question is whether CL-STA-1062 is running full-cycle espionage operations or acting as an initial access provider for another China-nexus team. Either way, defenders in Southeast Asia should treat government, military, utility, and adjacent service-provider environments as connected targets, not isolated victims.</p><p><strong>READ THE STORY: <a href="https://www.darkreading.com/threat-intelligence/china-linked-group-targets-southeast-asia-critical-systems">DR</a></strong></p><h1><strong>Phantom Squatting Turns AI-Hallucinated Domains Into Supply Chain Attack Surface</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>LLMs routinely hallucinate plausible web domains for legitimate brands, and attackers are registering those nonexistent domains to capture traffic generated by AI tools. Palo Alto Networks calls the technique &#8220;phantom squatting,&#8221; an extension of slopsquatting that shifts the risk from fake software packages to fake web infrastructure, API endpoints, portals, and brand domains.</strong></p><p><strong>Analyst Comments:</strong> Developers, AI agents, and enterprise workflows increasingly treat LLM-generated links as trusted output. That creates a clean delivery path for attackers: register a domain the model is likely to invent, wait for the AI system to recommend it, then harvest credentials, push malware, or intercept workflow data. The worst case is not a human clicking a bad link; it is an autonomous agent fetching a malicious endpoint, processing attacker-controlled content, or passing secrets into a fake API without a human decision point. Traditional URL reputation controls are weak here because newly registered phantom domains are born with no malicious history.</p><p><strong>READ THE STORY: <a href="https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/">Unit 42</a></strong></p><h1><strong>Amazon-Themed Job Texts Fuel Task Scam Campaigns Targeting Job Seekers</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Malwarebytes warns that scammers are impersonating Amazon recruiters in &#8220;high-paying, low-effort&#8221; job texts sent through SMS, WhatsApp, Telegram, and email-to-text gateways. The lure promises $250&#8211;$500 per day for 60&#8211;90 minutes of remote work, but it fits the pattern of task scams designed to extract deposits, steal identity data, push victims into mule activity, or deliver phishing and malware links.</strong></p><p><strong>Analyst Comments:</strong> The Amazon branding gives the scam credibility, while the &#8220;easy money&#8221; pitch filters for people willing to engage. The real danger comes after the first reply: scammers typically move victims to WhatsApp, Telegram, or a fake work portal where they can build trust, show fake earnings, and eventually demand deposits to &#8220;unlock&#8221; payouts. Defenders should treat these campaigns as both consumer fraud and credential-theft risk, especially where employees may reuse passwords, share identity documents, or install fake &#8220;work&#8221; apps on personal devices that later touch corporate accounts.</p><p><strong>READ THE STORY: <a href="https://www.malwarebytes.com/blog/scams/2026/06/watch-out-for-high-paying-low-effort-amazon-job-texts">Malwarebytes</a></strong></p><h1><strong>BioShocking Attack Shows How Malicious Sites Can Jailbreak AI Browsers</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>LayerX researchers demonstrated a new AI browser attack, dubbed BioShocking, that tricks browser-based LLM agents into ignoring safety guardrails. The proof of concept uses a malicious website game that rewards false answers, such as treating 2 + 2 as 5, pushing the model into a &#8220;fantasy&#8221; context where forbidden actions appear acceptable.</strong></p><p><strong>Analyst Comments:</strong> AI browsers blur that separation by giving an agent both context and action authority. Once a prompt injection can influence the agent, the attacker is no longer just manipulating page content; they may be manipulating the user&#8217;s assistant into crossing security boundaries on their behalf. BioShocking may not yet be a stealthy, end-to-end exploit, but it highlights the core issue: guardrails are brittle when the model can be socially engineered through hostile web content.</p><p><strong>READ THE STORY: <a href="https://arstechnica.com/security/2026/06/ai-browsers-can-be-lulled-into-a-dream-world-where-guardrails-no-longer-apply/">arsTECHNICA</a></strong></p><h1><strong>Citrix Patches NetScaler Memory Disclosure Flaw With CitrixBleed-Like Risk</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Citrix released fixes for six vulnerabilities in NetScaler ADC and NetScaler Gateway, including CVE-2026-8451, a high-severity memory disclosure flaw tied to malformed SAML authentication requests. Researchers at watchTowr say the bug echoes the vulnerability class behind CitrixBleed, raising concern because NetScaler flaws have repeatedly been exploited in real-world attacks, including ransomware campaigns.</strong></p><p><strong>Analyst Comments:</strong> NetScaler appliances sit in exactly the wrong place for memory disclosure bugs: exposed, authentication-adjacent, and often deeply trusted by enterprise identity flows. The SAML angle matters because leaked memory can become more than &#8220;just data exposure&#8221; if session material, tokens, or authentication context are exposed. Citrix says there is no confirmed exploitation yet, but defenders should not treat that as comfort. NetScaler has a long KEV history, and these bugs tend to move quickly once technical details are public. Patch now, verify SAML configurations, and assume internet-facing appliances will be probed almost immediately.</p><p><strong>READ THE STORY: <a href="https://cyberscoop.com/citrix-netscaler-flaw-cve-2026-8451-citrixbleed/">Cyberscoop</a></strong></p><h1><strong>Researchers Expose &#8220;Role Confusion&#8221; Flaw: Prompt Injection Still Breaks LLM Safety Boundaries</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers Charles Ye, Jasmine Cui, and MIT&#8217;s Dylan Hadfield-Menell argue that modern LLM security relies too heavily on role tags such as system, user, assistant, tool, and think. Their research shows models can confuse attacker-supplied text for trusted internal reasoning, enabling prompt-injection attacks that bypass safety controls. In one test, their &#8220;Chain-of-Thought Forgery&#8221; method raised attack success rates from near zero to roughly 60 percent across tested models.</strong></p><p><strong>Analyst Comments:</strong> This is not just another jailbreak trick. The useful takeaway is that role separation in LLMs is still more convention than hard security boundary. The researchers&#8217; core point is uncomfortable but fair: models often infer trust from writing style rather than from a reliable authorization mechanism. That means attackers do not always need to &#8220;convince&#8221; the model; they can sometimes make malicious input look like something the model already decided internally.</p><p><strong>READ THE STORY: <a href="https://www.theregister.com/ai-and-ml/2026/06/30/security-researchers-tricked-llms-into-giving-them-cocaine-recipes-by-abusing-role-models-for-prompt-injection/5264115">The Register</a></strong></p><h1><strong>Fake Bug Reports Can Hijack AI Coding Agents Through Poisoned Telemetry</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Tenet Security demonstrated an &#8220;agentjacking&#8221; technique that tricks AI coding agents into executing attacker-controlled code by planting malicious instructions inside a fake bug report. In testing, Claude Code, Cursor, and Codex retrieved poisoned Sentry error data and, in many cases, ran code on the developer&#8217;s machine.</strong></p><p><strong>Analyst Comments:</strong> The scary part is not the sophistication of the attack; it is how normal the workflow looks. A developer asks an AI agent to investigate a bug, the agent pulls telemetry through MCP, treats attacker-controlled log content as trusted diagnostic guidance, and acts with the developer&#8217;s permissions. That makes cloud keys, GitHub tokens, SSH keys, CI/CD secrets, source code, and dependency pipelines potential blast-radius targets. Existing IAM, EDR, and network controls may miss it because the agent is not &#8220;breaking in&#8221; &#8212; it is using authorized access in a poisoned context.</p><p><strong>READ THE STORY: <a href="https://www.darkreading.com/cyber-risk/fake-bug-report-hijacks-ai-coding-agents">DR</a></strong></p><h1><strong>Items of interest</strong></h1><h1><strong>Chinese Users Bypass Anthropic&#8217;s Claude Restrictions Through Proxies, Resold Accounts, and API Relay Services</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>WIRED reports that Anthropic&#8217;s efforts to block Claude access from China are being routinely bypassed through VPNs, foreign phone numbers, resold accounts, fake identities, and &#8220;transfer station&#8221; API relay services. The workaround economy has grown into a shadow market that gives Chinese users access to Claude while creating new risks around fraud, identity abuse, prompt interception, and unauthorized model access.</strong></p><p><strong>Analyst Comments:</strong> Anthropic can tighten geofencing, account bans, identity checks, and proxy detection, but as long as Claude remains valuable and publicly accessible elsewhere, users in restricted regions will keep finding paths around the gate. The stronger the restriction, the more the market shifts from casual VPN use to professionalized brokers, relay services, and fake identity vendors. The security risk cuts both ways. For Anthropic and U.S. policymakers, these workarounds undermine export-control and model-access restrictions, especially where advanced coding and agentic capabilities are involved. For Chinese users and companies, using underground relay services means their prompts, source code, credentials, business plans, and research data may pass through untrusted intermediaries that can log, resell, or manipulate traffic.</p><p><strong>READ THE STORY: <a href="https://archive.is/53zxo">Wired</a></strong></p><h1><strong>China&#8217;s 97% Off GPT &amp; Claude API Scam Exposed (Video)</strong></h1><p><strong>FROM THE MEDIA: What if I told you some students in China are reportedly getting access to GPT 5.4 and Claude API keys for up to 97% less than the official price? It sounds like the ultimate AI loophole: spend just a dollar or two, burn through tens of millions of tokens, plug the key into Cursor or VS Code, and start building. On the surface, it looks like a dream for developers, indie hackers, and anyone obsessed with AI coding tools.</strong></p><div id="youtube2-jQfqhGmPsOY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;jQfqhGmPsOY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/jQfqhGmPsOY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1><strong>Cheap Claude Tokens: The Million-Dollar Scam (Video)</strong></h1><p><strong>FROM THE MEDIA: </strong><span>Grey-market &#8220;Claude&#8221; access can look like a huge discount, but the real price may be your prompts, source code, tool outputs, and accepted agent patches.</span></p><div id="youtube2-ryEuB3t3YJo" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;ryEuB3t3YJo&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/ryEuB3t3YJo?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don&#8217;t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com. </p>]]></content:encoded></item><item><title><![CDATA[Daily Drop (1328) ]]></title><description><![CDATA[06-28-26]]></description><link>https://bragg.substack.com/p/daily-drop-1328</link><guid isPermaLink="false">https://bragg.substack.com/p/daily-drop-1328</guid><dc:creator><![CDATA[Bob Bragg]]></dc:creator><pubDate>Sun, 28 Jun 2026 17:23:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ebs_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd6895e-da80-4096-8164-c2a712b379af_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Sunday, Jun 28, 2026 // <a href="https://buymeacoffee.com/infodom">Buy Bob a Coffee</a> // <a href="https://ghostwire.news">Ghostwire</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ebs_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd6895e-da80-4096-8164-c2a712b379af_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ebs_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd6895e-da80-4096-8164-c2a712b379af_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!ebs_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd6895e-da80-4096-8164-c2a712b379af_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!ebs_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd6895e-da80-4096-8164-c2a712b379af_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!ebs_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd6895e-da80-4096-8164-c2a712b379af_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ebs_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd6895e-da80-4096-8164-c2a712b379af_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9fd6895e-da80-4096-8164-c2a712b379af_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2267650,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://bragg.substack.com/i/203971230?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd6895e-da80-4096-8164-c2a712b379af_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ebs_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd6895e-da80-4096-8164-c2a712b379af_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!ebs_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd6895e-da80-4096-8164-c2a712b379af_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!ebs_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd6895e-da80-4096-8164-c2a712b379af_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!ebs_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fd6895e-da80-4096-8164-c2a712b379af_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>US-Iran Ceasefire Teeters After Fresh Strikes Around Gulf Bases and Strait of Hormuz</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>United States and Iran exchanged new military strikes despite a mid-June ceasefire memorandum mediated by Pakistan. CENTCOM allegedly targeted Iranian surveillance, communications, air defense, drone, and mine-laying infrastructure after accusing Tehran of violating the ceasefire near the Strait of Hormuz. Iran reportedly retaliated against U.S. facilities in Kuwait and Bahrain, while both Gulf states said they responded to or condemned Iranian attacks.</strong></p><p><strong>Analyst Comments:</strong> The claims are significant: attacks on U.S. facilities in Kuwait and Bahrain, strikes near the Strait of Hormuz, threats against commercial shipping, and a U.S. presidential warning about regime-ending military action. Those are not minor developments, and they would normally require corroboration from multiple official and independent sources. The strategic center of gravity is the Strait of Hormuz. If Iran is tightening maritime control or threatening vessels that do not follow Iranian directives, the risk moves beyond bilateral U.S.-Iran exchanges and into global energy security. Tanker attacks, mine-laying capabilities, and drone strikes near the waterway could drive insurance costs, disrupt crude flows, and pull Gulf states further into the conflict.</p><p><strong>READ THE STORY: <a href="https://www.kurdistan24.net/en/story/922518">K24</a></strong></p><h1><strong>Israel-Slovenia Partnership Pitched as Counterweight to Iranian Influence in Europe</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A Middle East Forum Observer article argues that Israel should use Slovenian Prime Minister Janez Jan&#353;a&#8217;s return to power to build a stronger European foothold against Iran. The piece recommends cyber cooperation, defense testing, diplomatic coordination, and investment around Slovenia&#8217;s Port of Koper to reduce Israeli dependence on U.S. policy swings and counter Iranian influence networks in Europe.</strong></p><p><strong>Analyst Comments:</strong> The author frames the June 2026 Washington-Tehran agreement as a strategic failure that strengthens Iran, reopens financial flows, and leaves Israel exposed to American political cycles. Slovenia is presented as a temporary but valuable opening inside the EU and NATO after Jan&#353;a&#8217;s return to office. This is advocacy, not neutral reporting. The article is essentially a policy blueprint for turning Slovenia into a forward Israeli node in Europe: cyber defense hub, weapons-testing environment, diplomatic influence platform, and logistics corridor. It also casts the previous Slovenian government&#8217;s posture toward Israel as &#8220;appeasement politics,&#8221; while describing Jan&#353;a as a reliable friend of Israel. That framing tells you exactly where the piece is coming from.</p><p><strong>READ THE STORY: <a href="https://www.meforum.org/mef-observer/can-israel-partner-with-slovenia-to-counter-irans-influence-in-europe">Middle East Forum</a></strong></p><h1><strong>China&#8217;s LineShine Supercomputer Claims Top Spot Without GPUs Despite US Export Controls</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>WIRED reports that China&#8217;s LineShine supercomputer, installed at the National Supercomputing Center in Shenzhen, has overtaken the US system El Capitan in the TOP500 ranking. The system reportedly delivers 2,198 exaflops while using only CPUs, not GPUs, and is built on Chinese-developed hardware and software. The story frames the achievement as a direct signal that China can still compete in high-performance computing despite US restrictions on advanced chips and AI hardware.</strong></p><p><strong>Analyst Comments:</strong> The strategic angle here is bigger than benchmark bragging rights. If the reported performance numbers hold, LineShine would show that China is finding ways around GPU access constraints by leaning into domestic CPU-heavy architecture, custom interconnects, and national operating system stacks. That matters because supercomputing feeds directly into AI, weapons modeling, cryptanalysis, climate simulation, materials science, and other national-security-relevant workloads.</p><p><strong>READ THE STORY: <a href="https://www.wired.com/story/china-defies-us-restrictions-and-builds-the-worlds-fastest-supercomputer/">Wired</a></strong></p><h1><strong>Xi Deepens PLA Purge as Six Senior Chinese Military Officials Removed From Legislature</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>China removed six senior People&#8217;s Liberation Army officials from the National People&#8217;s Congress on June 26, 2026, in what the outlet frames as another sign of Xi Jinping&#8217;s continuing military purge. The removals span the Eastern Theater Command, Western Theater Command, PLA Army, PLA Air Force, Central Military Commission Equipment Development Department, and PLA Cyberspace Force.</strong></p><p><strong>Analyst Comments:</strong> The key point is that loss of NPC deputy status does not automatically prove criminal wrongdoing. Beijing often gives little detail when senior military figures are removed, and formal corruption or disciplinary announcements can come later, or not at all. Still, simultaneous removals across multiple military organs usually raise eyebrows because similar personnel actions in recent years have often preceded formal investigations.</p><p><strong>READ THE STORY: <a href="https://english.pardafas.com/china-removes-six-senior-pla-officials-as-xis-military-purge-deepens/?utm_source=nepalipatro&amp;utm_medium=np_mobile&amp;utm_campaign=np_news">Epardafas</a></strong></p><h1><strong>US Hearing Warns China&#8217;s Economic Espionage Is Shifting Toward AI</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The Star, republishing South China Morning Post reporting, says a U.S. House Select Committee on China hearing focused on Chinese economic espionage and alleged targeting of artificial intelligence advances. Witnesses warned that Beijing blends cyber espionage, human intelligence, academic collaboration, and commercial investment to acquire Western technology, while other participants cautioned against broad measures that stigmatize Chinese-Americans, students, and researchers.</strong></p><p><strong>Analyst Comments:</strong> The hawkish side of the hearing frames Chinese technology acquisition as a coordinated &#8220;whole-of-society&#8221; campaign that benefits the PLA and narrows the U.S. military-tech edge. The counterargument is not that espionage risk is imaginary; it is that overbroad enforcement can damage U.S. innovation, scare off foreign talent, and harm Asian-American communities. That tension matters. AI security policy is moving into a difficult space where export controls, research collaboration, corporate security, immigration politics, and civil rights all collide. A &#8220;sledgehammer&#8221; approach may look tough but can create its own security problems if it drives talent away or discourages legitimate research partnerships. The more effective approach is targeted: protect sensitive AI models and data, harden corporate and university environments, improve disclosure rules, and pursue actual espionage rather than ethnicity-based suspicion.</p><p><strong>READ THE STORY: <a href="https://www.thestar.com.my/aseanplus/aseanplus-news/2026/06/28/us-hearing-warns-chinese-economic-espionage-now-targets-ai">The Star</a></strong></p><h1><strong>Russian Telegram Channel Urges Economic Retaliation Against Europe Over Ukraine Support</strong></h1><p><em>NOTE: </em></p><p><em>This post reflects a clearly pro-Russian, pro-war perspective. It frames the EU and Ukraine as hostile actors waging an &#8220;existential war&#8221; against Russia, treats Ukrainians as expendable proxies of Europe, and criticizes the Kremlin only for being too restrained or ineffective&#8212;not for the war itself. The author&#8217;s recommended response is escalation through economic retaliation, including cutting Russian exports of strategic commodities to European industry.</em></p><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A Russian-language Telegram post argues that Moscow&#8217;s repeated &#8220;existential war&#8221; rhetoric has backfired by convincing Europe to intensify support for Ukraine. The post claims the EU has accepted confrontation with Russia as inevitable and is now supplying Kyiv with components for long-range weapons while facing little meaningful Russian retaliation. The author calls for Moscow to stop relying on &#8220;red line&#8221; threats and instead target European industry by restricting exports of critical Russian commodities.</strong></p><p><strong>Analyst Comments:</strong> The proposed response is economic coercion: cutting or legally blocking exports of enriched uranium, titanium, palladium, high-purity nickel, and LNG to European states. That framing is meant to portray Russia as still holding strategic leverage over Europe&#8217;s industrial base. The reality is more complicated. Commodity leverage cuts both ways: export bans could hurt European supply chains, but they would also reduce Russian revenue and accelerate substitution, sanctions workarounds, and supplier diversification. The author acknowledges the budget hit but argues continued war costs and attacks on Russian infrastructure are already imposing comparable damage.</p><p><strong>READ THE STORY: Telegram (Worldandwe)</strong></p><h1><strong>Brazil Emergency Alert Hack Turns Alien Invasion Hoax Into Public Warning System Risk</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Their are reports that hackers compromised Brazil&#8217;s emergency alert system and sent fake push notifications warning users of an &#8220;alien attack.&#8221; The prank quickly shifted from absurd UFO humor to a cybersecurity concern, raising questions about trust in public warning systems. The same article also covers China&#8217;s secretive Shenlong spaceplane releasing an unknown object in orbit and unverified reports of &#8220;jellyfish drones&#8221; seen over Iran.</strong></p><p><strong>Analyst Comments:</strong> The Brazil incident is the real security story here. Emergency alert systems depend on public trust. Once attackers can alter templates or push fake messages, the damage is not just one night of panic or memes. The bigger problem is alert fatigue and doubt. During a real disaster, people may hesitate, assume it is another prank, or ignore instructions entirely. The UFO framing makes the article more clickable, but the practical takeaway is about integrity controls around public notification infrastructure. These systems need strong authentication, restricted template access, change logging, approval workflows, and rapid revocation paths. A compromised alert channel is not just a communications failure; it can become a public safety incident.</p><p><strong>READ THE STORY: <a href="https://cybernews.com/tech/ufo-uap-brazil-china-iran/">Cyber News</a></strong></p><h1><strong>US Export Controls on Anthropic Models Framed as Poor Fit for Digital AI Risk</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Bulletin of the Atomic Scientists argues that the U.S. directive restricting foreign-national access to Anthropic&#8217;s Mythos 5 and Fable 5 models reflects a flawed attempt to apply traditional export controls to intangible AI systems. The piece says the national security concern is real&#8212;especially around vulnerability-discovery AI and foreign adversary misuse&#8212;but that export controls built for physical goods are poorly suited to software, models, and data that can be copied, stolen, or accessed through front companies and insiders.</strong></p><p><strong>Analyst Comments:</strong> The core argument is not &#8220;AI risk is fake.&#8221; It is that the chosen policy tool is blunt. Physical export controls work best when the controlled item is hard to move, hard to reproduce, and tied to manufacturing capacity. AI models are different: once weights, code, data, or access paths leak, replication is fast and cheap. That makes a nationality-based access ban look more like symbolic containment than durable risk reduction. The article also raises a serious alliance-management problem. Blocking non-U.S. nationals could exclude close partners from evaluating or using cyber-focused AI tools, including European security institutions. That may push allies toward non-U.S. technology stacks, which would undercut Washington&#8217;s broader strategic position. In other words, an overbroad control meant to slow China could also alienate partners and weaken U.S. influence.</p><p><strong>READ THE STORY: <a href="https://thebulletin.org/2026/06/why-ai-models-like-claude-fable-and-mythos-defy-traditional-export-control-frameworks/">The Bulletin</a></strong></p><h1><strong>GREYVIBE Turns Dating Lures Into Browser-Based Surveillance Against Ukrainian Targets</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Cybersecurity Insiders reports that GREYVIBE, a Russia-nexus threat group tracked by WithSecure, used a fake Ukrainian adult-club/dating lure called PrincessClub to infect Ukrainian combatants with RATs and spyware. The campaign builds on a long-running honey-trap playbook but adds a notable twist: post-compromise audio and video collection through WebRTC in the browser, making surveillance traffic look like normal video-call activity.</strong></p><p><strong>Analyst Comments:</strong> TThe targeting, lures, timing, and victim profile align with Russian wartime intelligence priorities against Ukraine, even if WithSecure stops short of clean state attribution. This is not just credential theft or generic malware delivery. It is social engineering designed to turn personal trust into battlefield intelligence collection. The WebRTC piece matters because it moves surveillance into a traffic category defenders usually allow. A SOC can block sketchy Android APKs or flag suspicious permission requests, but browser-based audio/video activity over WebRTC is common in normal business and personal use. That makes PrincessClub harder to separate from legitimate calls unless defenders correlate the full chain: lure visit, malware persistence, PowerShell RAT behavior, WebSocket or REST C2, browser-data theft, Telegram/WhatsApp collection, and RDP setup.</p><p><strong>READ THE STORY: <a href="https://www.cybersecurity-insiders.com/how-greyvibe-rewrote-the-dating-lure-surveillance-playbook/">Cybersecurity Insiders</a></strong></p><h1><strong>Connected and Protected: CISOs Securing Telecom and Network Services Infrastructure</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>CISO Whisperer profiles six security leaders working across telecom, IaaS, application delivery, regional cloud, and nonprofit research network environments. The piece frames network security as infrastructure security, arguing that outages or breaches in these environments can cascade across the organizations that depend on them. Featured leaders include Ahmad Douglas, Rafael Pierosan, Sean Pike, Sharad Kumar, Dave Phillips, and Kevin Hayes.</strong></p><p><strong>Analyst Comments:</strong> The angle here is industry recognition rather than incident reporting. It is not warning about a breach or threat campaign; it is highlighting the people responsible for defending connectivity-heavy environments that usually sit beneath the more visible parts of enterprise security. The pro-security message is clear: telecom and network services may not get the same attention as finance or healthcare, but they carry systemic risk because so many sectors depend on them.</p><p><strong>READ THE STORY: <a href="https://cisowhisperer.com/connected-and-protected-cisos-to-watch-in-telecom-and-network-services/?utm_source=rss#038;utm_medium=rss&amp;#038;utm_campaign=connected-and-protected-cisos-to-watch-in-telecom-and-network-services">CISO Whisperer</a></strong></p><h1><strong>Supply Chain Attack Hits JDownloader: Malicious Installers Delivered RAT Payloads Through Official Download Links</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>CSIRT Italia warns that JDownloader was hit by a supply chain compromise affecting specific Windows and Linux installer download links between May 6&#8211;7, 2026. Attackers manipulated official redirect links to deliver malicious packages that installed Remote Access Trojan tooling on affected systems. Users who downloaded but did not execute the files can delete them; users who executed them should treat the system as fully compromised.</strong></p><p><strong>Analyst Comments:</strong> This is a clean example of why &#8220;official download source&#8221; does not always mean &#8220;trusted binary.&#8221; The attackers reportedly did not compromise JDownloader&#8217;s core filesystem, in-app updates, macOS installers, Flatpak, Snap, Winget packages, or the main JAR. Instead, they abused redirect paths for selected Windows and Linux installers, which is enough to burn users who trust the download page.</p><p><strong>READ THE STORY: <a href="https://www.acn.gov.it/portale/w/supply-chain-attack-rilevata-distribuzione-di-versione-malevola-di-jdownloader">ACN</a></strong></p><h1><strong>Ransomware Crews Share New EDR Killer: BYOVD Tool Blinds Endpoint Defenses Before Encryption</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Singapore&#8217;s Cyber Security Agency warns that at least eight ransomware groups are using a new EDR killer tool to disable endpoint security before deploying ransomware. The tool appears to be an evolution of RansomHub&#8217;s &#8220;EDRKillShifter&#8221; and has been tied to BlackSuit, RansomHub, Medusa, Qilin, DragonForce, Crytox, Lynx, and INC. Its use of vulnerable signed drivers, HeartCrypt packing, and customized builds gives operators a reliable way to create endpoint blind spots during intrusions.</strong></p><p><strong>Analyst Comments:</strong> This is the ransomware playbook maturing in real time. EDR used to be the thing defenders counted on when prevention failed; now crews are building dedicated tooling to knock that layer offline before the real payload lands. The BYOVD angle is the important part: if attackers can load a vulnerable but signed driver, they can operate with kernel-level privileges while still looking &#8220;legitimate&#8221; enough to slip past weaker controls.</p><p><strong>READ THE STORY: <a href="https://www.csa.gov.sg/alerts-and-advisories/advisories/ad-2025-018/">CSA</a></strong></p><h1><strong>KDDI Email System Breach May Expose 14.2 Million ISP Logins in Japan</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Japanese telecom operator KDDI disclosed a breach affecting an email system used by multiple ISPs, potentially exposing up to 14.2 million customer email addresses and passwords. The compromise was discovered on June 17, 2026, and traced to a vulnerability in unnamed third-party software. Affected users should reset email passwords immediately and enable 2FA where available.</strong></p><p><strong>Analyst Comments:</strong> KDDI says some passwords were hashed or encrypted, which helps, but the company has not clarified how many accounts were protected, whether any passwords were plaintext, or what hashing/encryption methods were used. That ambiguity matters. Weak hashing, reversible encryption, or partial plaintext storage can turn &#8220;possible exposure&#8221; into account takeover at scale.</p><p><strong>READ THE STORY: <a href="https://www.bleepingcomputer.com/news/security/data-breach-exposes-up-to-142-million-email-logins-at-six-isps/">Bleeping Computer</a></strong></p><h1><strong>Chinese Forum Post Seeks Windows Kernel Privilege Escalation Path From Constrained Write Primitive</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A Kanxue forum user is asking how to turn a limited Windows kernel write primitive&#8212;writing a fixed negative DWORD such as </strong><code>-1</code><strong> or </strong><code>-2</code><strong> to an arbitrary kernel address&#8212;into a full privilege escalation chain on Windows 10/11. The post discusses I/O Ring exploitation attempts, kernel object field corruption, and possible abuse of globals or structure fields. This is clearly offensive kernel exploitation research and should be treated as high-risk dual-use content.</strong></p><p><strong>Analyst Comments:</strong> It is a technical help request from someone trying to weaponize a constrained arbitrary write into local privilege escalation. The interesting part is the constraint: the attacker cannot write an arbitrary value and does not have arbitrary read, only a fixed negative 32-bit write. That makes classic token-stealing or direct pointer overwrite paths harder, especially under modern Windows defenses like SMEP, SMAP, KASLR, and kernel CFG. The user&#8217;s I/O Ring angle tracks with public Windows exploitation research, where attackers try to corrupt kernel structures to expand a weak primitive into stronger read/write capability. Their blockers&#8212;sign extension behavior, inability to allocate specific usermode addresses, and collateral corruption of adjacent fields&#8212;are exactly the sort of reliability issues that separate a crash from a working exploit.</p><p><strong>READ THE STORY: <a href="https://bbs.kanxue.com/thread-291796.htm">Kanxue</a></strong></p><h1><strong>ARS3NAL Bundles Pentest Workflows Into an Offline Russian-Language Toolkit</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A Habr post introduces ARS3NAL, an open-source offline toolkit that consolidates common penetration testing resources into a single Russian-language interface. The project includes command builders, checklists, curated payloads, wordlist references, GTFOBins, CyberChef, reverse shell generation, and target tracking. The author frames it as a productivity tool for authorized testing, CTFs, Hack The Box, and bug bounty workflows.</strong></p><p><strong>Analyst Comments:</strong> The security value is obvious: ARS3NAL reduces friction by putting commands, payloads, checklists, and notes in one place, offline, with no telemetry. That is useful for legitimate testing teams, especially Russian-speaking practitioners who lose time translating documentation or digging through scattered resources. The dual-use angle is also obvious. Anything that makes authorized pentesting easier can also help less disciplined or malicious users move faster. The inclusion of PayloadsAllTheThings, GTFOBins, reverse shell generation, wordlists, and exploitation checklists means defenders should treat this as another example of offensive tradecraft becoming more accessible and more packaged. The author does include a legal-use disclaimer, but tooling distribution still lowers the operational barrier.</p><p><strong>READ THE STORY: <a href="https://habr.com/ru/articles/1052866/">HABR</a></strong></p><h1><strong>Items of interest</strong></h1><h1><strong>Chinese Users Bypass Anthropic&#8217;s Claude Restrictions Through Proxies, Resold Accounts, and API Relay Services</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>WIRED reports that Anthropic&#8217;s efforts to block Claude access from China are being routinely bypassed through VPNs, foreign phone numbers, resold accounts, fake identities, and &#8220;transfer station&#8221; API relay services. The workaround economy has grown into a shadow market that gives Chinese users access to Claude while creating new risks around fraud, identity abuse, prompt interception, and unauthorized model access.</strong></p><p><strong>Analyst Comments:</strong> Anthropic can tighten geofencing, account bans, identity checks, and proxy detection, but as long as Claude remains valuable and publicly accessible elsewhere, users in restricted regions will keep finding paths around the gate. The stronger the restriction, the more the market shifts from casual VPN use to professionalized brokers, relay services, and fake identity vendors. The security risk cuts both ways. For Anthropic and U.S. policymakers, these workarounds undermine export-control and model-access restrictions, especially where advanced coding and agentic capabilities are involved. For Chinese users and companies, using underground relay services means their prompts, source code, credentials, business plans, and research data may pass through untrusted intermediaries that can log, resell, or manipulate traffic.</p><p><strong>READ THE STORY: <a href="https://archive.is/53zxo">Wired</a></strong></p><h1><strong>China&#8217;s 97% Off GPT &amp; Claude API Scam Exposed (Video)</strong></h1><p><strong>FROM THE MEDIA: What if I told you some students in China are reportedly getting access to GPT 5.4 and Claude API keys for up to 97% less than the official price? It sounds like the ultimate AI loophole: spend just a dollar or two, burn through tens of millions of tokens, plug the key into Cursor or VS Code, and start building. On the surface, it looks like a dream for developers, indie hackers, and anyone obsessed with AI coding tools.</strong></p><div id="youtube2-jQfqhGmPsOY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;jQfqhGmPsOY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/jQfqhGmPsOY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1><strong>Cheap Claude Tokens: The Million-Dollar Scam (Video)</strong></h1><p><strong>FROM THE MEDIA: </strong><span>Grey-market &#8220;Claude&#8221; access can look like a huge discount, but the real price may be your prompts, source code, tool outputs, and accepted agent patches.</span></p><div id="youtube2-ryEuB3t3YJo" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;ryEuB3t3YJo&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/ryEuB3t3YJo?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don&#8217;t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com. </p>]]></content:encoded></item><item><title><![CDATA[Daily Drop (1327) ]]></title><description><![CDATA[06-27-26]]></description><link>https://bragg.substack.com/p/daily-drop-1327</link><guid isPermaLink="false">https://bragg.substack.com/p/daily-drop-1327</guid><dc:creator><![CDATA[Bob Bragg]]></dc:creator><pubDate>Sun, 28 Jun 2026 02:39:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!iqcd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03ec7872-d929-4e1a-9c26-f6c6772d95b6_1448x1086.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Saturday, Jun 27, 2026 // <a href="https://buymeacoffee.com/infodom">Buy Bob a Coffee</a> // <a href="https://ghostwire.news">Ghostwire</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iqcd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03ec7872-d929-4e1a-9c26-f6c6772d95b6_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iqcd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03ec7872-d929-4e1a-9c26-f6c6772d95b6_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!iqcd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03ec7872-d929-4e1a-9c26-f6c6772d95b6_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!iqcd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03ec7872-d929-4e1a-9c26-f6c6772d95b6_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!iqcd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03ec7872-d929-4e1a-9c26-f6c6772d95b6_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iqcd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03ec7872-d929-4e1a-9c26-f6c6772d95b6_1448x1086.png" width="1448" height="1086" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/03ec7872-d929-4e1a-9c26-f6c6772d95b6_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2709659,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://bragg.substack.com/i/203849621?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03ec7872-d929-4e1a-9c26-f6c6772d95b6_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iqcd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03ec7872-d929-4e1a-9c26-f6c6772d95b6_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!iqcd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03ec7872-d929-4e1a-9c26-f6c6772d95b6_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!iqcd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03ec7872-d929-4e1a-9c26-f6c6772d95b6_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!iqcd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03ec7872-d929-4e1a-9c26-f6c6772d95b6_1448x1086.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>Qihoo 360 Claims Tulongfeng is China&#8217;s Answer to Anthropic Mythos</strong></h1><p><strong>Bottom Line Up Front (BLUF): Qihoo 360 introduced Tulongfeng, an AI-driven vulnerability discovery system positioned as China&#8217;s response to Anthropic&#8217;s Mythos. Rather than relying on a single frontier model, Tulongfeng uses a swarm of specialized AI agents to model threats, identify risky attack surfaces, trace data flows, generate sandbox environments, and test exploitability.</strong></p><p><strong>Analyst Comments:</strong> The swarm model is the interesting part. Instead of trying to match U.S. frontier models head-on, Qihoo 360 is arguing that specialized agents backed by years of malware research, attack investigation data, and infrastructure defense experience can close the gap. That is a practical strategy. Security work is often not one big reasoning task; it is a chain of smaller tasks: scope selection, code analysis, data-flow tracing, exploit generation, sandbox testing, and validation. The risk is also clear. A system that can automatically find vulnerabilities, build sandboxes, generate exploit code, and test attack paths is inherently dual-use. In defensive hands, it can accelerate patching and software assurance. In offensive hands, it becomes a vulnerability factory.</p><p><strong>READ THE STORY: <a href="https://orbitaltoday.com/2026/06/27/chinese-ai-could-counter-u-s-military-operations-cnas-report-warns/">Orbital Today</a></strong></p><h1><strong>Russia Signals Future Security Talks with Europe After Ukraine Objectives Are Met</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>TASS reported that Russia plans to reassess its security relationship with Europe after achieving the objectives of its &#8220;special military operation&#8221; in Ukraine. Moscow is framing any future engagement with European states as part of a broader Eurasian security architecture, with Hungary and Serbia cited as examples of countries open to continued dialogue.</strong></p><p><strong>Analyst Comments:</strong> The report reflects Moscow&#8217;s current diplomatic posture: Russia views the existing European security framework as no longer workable and is positioning Eurasian security cooperation as the next phase after the war in Ukraine. Russian officials continue to argue that Western actions drove the crisis and that Moscow&#8217;s military and political response is necessary to protect its security interests.</p><p><strong>READ THE STORY: <a href="https://tass.com/politics/2152297">TASS (RU)</a></strong></p><h1><strong>Ukraine and FBI Uncover Russian Intelligence Campaign Targeting Messaging Accounts</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Ukraine&#8217;s Security Service said it worked with the FBI to uncover a long-running Russian intelligence campaign targeting messaging accounts used by government officials, military personnel, politicians, activists, and Ukrainian nationals across Ukraine, Europe, and the United States. The attackers used fake support-themed SMS messages to trick victims into handing over credentials and account access material.</strong></p><p><strong>Analyst Comments:</strong> This campaign fits the broader Russian intelligence pattern of targeting secure messaging platforms through social engineering rather than breaking encryption. The goal is simple: get the user to surrender the account. Once attackers obtain confirmation codes, PINs, passwords, QR-pairing access, or recovery keys, they can access sensitive conversations without needing to defeat the underlying security of apps like Signal or WhatsApp.</p><p><strong>READ THE STORY: <a href="https://thehackernews.com/2026/06/ukraine-says-russian-intelligence-used.html">THN</a></strong></p><h1><strong>Allegedly China&#8217;s GLM-5.2 Self-Audit Finds Vulnerabilities in AI-Generated Parsers (Kanxue)</strong></h1><p><strong>Bottom Line Up Front (BLUF): A post on Kanxue claims that the GLM-5.2 coding model used the 7884 V12 structural induction engine to autonomously build parsers for 10 file formats, then audit its own generated code. The test reportedly found security flaws in 6 of 10 parser modules, totaling 8 issues, with the full process completed in under five minutes.</strong></p><p><strong>Analyst Comments:</strong> Parsers are notoriously dangerous code paths because they handle complex, attacker-controlled input. If an AI model is generating parsers quickly and 60% of the resulting modules contain flaws, that reinforces a point security teams already know: AI-generated code cannot be trusted just because it compiles or appears functional. The more interesting claim is the workflow itself. The post frames GLM-5.2 as both the developer and the auditor, using the 7884 engine to guide structure recognition and vulnerability discovery. That kind of self-audit may be valuable for fast triage, but it should not replace human review, fuzzing, SAST, or exploitability validation. AI can accelerate bug discovery, but it can also miss edge cases, misunderstand formats, or produce unsafe fixes.</p><p><strong>READ THE STORY: <a href="https://bbs.kanxue.com/thread-291801.htm">Kanxue</a></strong></p><h1><strong>Qihoo 360 Claims Tulongfeng is China&#8217;s Answer to Anthropic Mythos</strong></h1><p><strong>Bottom Line Up Front (BLUF): Qihoo 360 introduced Tulongfeng, an AI-driven vulnerability discovery system positioned as China&#8217;s response to Anthropic&#8217;s Mythos. Rather than relying on a single frontier model, Tulongfeng uses a swarm of specialized AI agents to model threats, identify risky attack surfaces, trace data flows, generate sandbox environments, and test exploitability.</strong></p><p><strong>Analyst Comments:</strong> The swarm model is the interesting part. Instead of trying to match U.S. frontier models head-on, Qihoo 360 is arguing that specialized agents backed by years of malware research, attack investigation data, and infrastructure defense experience can close the gap. That is a practical strategy. Security work is often not one big reasoning task; it is a chain of smaller tasks: scope selection, code analysis, data-flow tracing, exploit generation, sandbox testing, and validation. The risk is also clear. A system that can automatically find vulnerabilities, build sandboxes, generate exploit code, and test attack paths is inherently dual-use. In defensive hands, it can accelerate patching and software assurance. In offensive hands, it becomes a vulnerability factory.</p><p><strong>READ THE STORY: <a href="https://www.redhotcyber.com/en/post/china-responds-to-the-anthropic-mythos-qihoo-360-presents-tulongfeng-a-swarm-based-device/">RHC</a></strong></p><h1><strong>Third-Party Breaches Expose Vendor Risk Across the Education Sector</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Dark Reading reports that schools and universities are facing growing exposure from third-party software breaches, especially ransomware and Web application attacks affecting widely used education platforms. Verizon&#8217;s 2026 DBIR recorded 1,252 education-sector breaches last year, with more than half involving malware and 65% of those malware incidents involving ransomware.</strong></p><p><strong>Analyst Comments:</strong> Most districts and universities do not have the budget, staffing, or leverage to fully assess every SaaS provider they depend on. That creates a frustrating situation: the institution may take the public hit for a breach even when the failure starts inside a vendor&#8217;s environment. The Canvas incidents show the operational side of the risk. Taking a learning management system offline during finals creates immediate pressure, just like ransomware against hospitals. Attackers understand timing. End-of-school-year disruption gives them maximum leverage over institutions that need systems online to finish exams, grades, and administrative work.</p><p><strong>READ THE STORY: <a href="https://www.darkreading.com/cyber-risk/third-party-breaches-teaches-education-lesson-vendor-risk">DR</a></strong></p><h1><strong>Chinese Uni-App Framework Used to Power 200,000+ Scam Sites</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>SecurityWeek reported that threat actors are using scam templates built with the legitimate Chinese open source DCloud Uni-App framework to run large-scale investment fraud operations. Infoblox identified more than 236,000 second-level domains tied to the activity, including fake crypto exchanges, gambling impersonation sites, WhatsApp phishing pages, crypto wallet drainers, and pig-butchering infrastructure.</strong></p><p><strong>Analyst Comments:</strong> Uni-App is a legitimate cross-platform development toolkit. The issue is that criminals have standardized on it because it lets them rapidly build and deploy convincing scam sites across mobile and web formats. That scale matters. When fraud crews can buy ready-made templates and launch thousands of sites quickly, takedowns become a whack-a-mole problem. The infrastructure also appears coordinated in places, with Infoblox observing synchronized dips in new domain registrations across scam sites hosted on different providers. That suggests at least some centralized control or shared disruption response.</p><p><strong>READ THE STORY: <a href="https://www.securityweek.com/chinese-framework-powers-200000-scam-sites/">Security Week</a></strong></p><h1><strong>Anthropic Restores Claude Mythos 5 Access for Select U.S. Critical Infrastructure Defenders</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Anthropic has restored access to Claude Mythos 5 for approved U.S. organizations involved in critical infrastructure defense after a two-week suspension that began on June 12, 2026. Access is being reinstated through a phased authorization process coordinated with federal agencies, while broader availability of Fable 5 remains under review.</strong></p><p><strong>Analyst Comments:</strong> Mythos 5 is being treated less like a commercial SaaS feature and more like a sensitive national security capability. That matters for security teams because access to high-end AI cyber tooling may increasingly depend on authorization, sector, use case, and government risk review. For defenders, the upside is clear: models like Mythos 5 can help process threat telemetry, prioritize vulnerabilities, accelerate incident response, and support analysts during high-tempo operations. That is especially relevant for organizations inside CISA&#8217;s 16 critical infrastructure sectors, where attack surfaces are large and response windows are shrinking.</p><p><strong>READ THE STORY: <a href="https://gbhackers.com/claude-mythos-5-redeployed/">GBhackers</a></strong></p><h1><strong>OpenAI Previews GPT-5.6 Sol Under Restricted Access for Cyber Defense Use</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>OpenAI released a limited preview of GPT-5.6 in three variants: Sol, Terra, and Luna. Sol is positioned as the flagship model and OpenAI&#8217;s most capable cybersecurity model to date, but access is restricted to a small group of government-approved companies and partners while OpenAI tests stronger cyber safeguards and misuse controls.</strong></p><p><strong>Analyst Comments:</strong> OpenAI is clearly trying to thread the needle: give defenders better tools for vulnerability research, patch development, code review, and incident response, while preventing the same model from being used for exploitation, weaponization, or offensive tradecraft. The difficult part is that the boundary is messy. Vulnerability research and exploit development overlap heavily with offensive cyber activity. A model that can identify memory safety issues, generate credible exploit leads, and work with build systems can help defenders move faster, but it also raises the risk of misuse if guardrails fail or access controls are bypassed.</p><p><strong>READ THE STORY: <a href="https://thehackernews.com/2026/06/openai-limits-gpt-56-rollout-as-sol.html">THN</a></strong></p><h1><strong>Malicious OpenClaw Skills Expose New AI Supply Chain Risks</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers at Palo Alto Networks Unit 42 found five malicious skills on ClawHub, the marketplace for the OpenClaw AI agent ecosystem. The skills bypassed platform security checks and included infostealers, detection evasion, and agent-specific abuse techniques designed to steal data, manipulate recommendations, and exploit AI agents for financial gain.</strong></p><p><strong>Analyst Comments:</strong> OpenClaw skills are not just plugins with limited functionality; they can access local files, credentials, APIs, and connected workflows. That makes a malicious skill closer to a hostile extension running inside an agent&#8217;s trusted execution path. The more concerning development is the shift from classic malware to agentic abuse. Infostealers are bad enough, but skills designed to manipulate recommendations, inject affiliate links, or coordinate financial schemes show how attackers are starting to exploit the decision-making role of AI agents. Once users trust agents to recommend tools, move money, summarize data, or execute workflows, the agent itself becomes a target for manipulation.</p><p><strong>READ THE STORY: <a href="https://www.darkreading.com/cyber-risk/malicious-openclaw-skills-clawhub-threaten-ai-supply-chain">DR</a></strong></p><h1><strong>Critical Veeam Backup &amp; Replication RCE Puts Backup Servers at Risk</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The Centre for Cybersecurity Belgium is urging organizations to patch CVE-2026-44963, a critical remote code execution vulnerability in Veeam Backup &amp; Replication versions 12 through 12.3.2. The flaw affects domain-joined deployments and allows a standard authenticated domain user to execute code on the Veeam Backup Server over the network.</strong></p><p><strong>Analyst Comments:</strong> If an attacker gains control of the Veeam Backup Server, they may be able to delete or encrypt backups, steal stored credentials, and move laterally before launching ransomware. The authentication requirement should not lower urgency. Standard domain credentials are often available to attackers early in an intrusion through phishing, infostealers, password reuse, or compromised VPN access. In a ransomware scenario, backup infrastructure is usually one of the first targets because attackers want to prevent recovery before encrypting production systems.</p><p><strong>READ THE STORY: <a href="https://ccb.belgium.be/advisories/warning-critical-remote-code-execution-veeam-backup-replication-patch-immediately">CCB</a></strong></p><h1><strong>Cloud Bucket Hijacking Can Redirect Logs and Sensitive Data Across AWS, GCP, and Azure</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Unit 42 researchers disclosed a cloud storage attack technique called cloud bucket hijacking that can redirect active data streams to attacker-controlled storage. The issue affects common cloud workflows across AWS, Google Cloud, and Microsoft Azure, where bucket or storage account names can become part of the trust model. If an attacker can delete a target bucket and recreate the same name under their control, existing logging, replication, or transfer jobs may continue sending data to the attacker.</strong></p><p><strong>Analyst Comments:</strong> The attacker changes the destination by deleting and reclaiming the bucket name. From the victim&#8217;s side, the pipeline may still look valid because the configured destination name has not changed. That is what makes this dangerous. Security teams tend to monitor changes to logging sinks, replication rules, and transfer jobs. They may not treat bucket deletion as an immediate exfiltration risk. In this case, deletion is the pivot point. Once the name is reclaimed, audit logs, telemetry, replicated objects, and other sensitive data can silently flow into an attacker-controlled account.</p><p><strong>READ THE STORY: <a href="https://gbhackers.com/cloud-bucket-hijacking/">GBhackers</a></strong></p><h1><strong>Cisco SD-WAN Zero-Day Exploitation Used Rogue Peering and Root-Level Account Creation</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Mandiant revealed new details on attacks exploiting CVE-2026-20245, a Cisco Catalyst SD-WAN command injection vulnerability that allowed authenticated attackers to execute commands as root. The attackers used the flaw after gaining access to SD-WAN infrastructure, created a rogue root account named troot, extracted configuration data, and used anti-forensic cleanup to hide activity.</strong></p><p><strong>Analyst Comments:</strong> Rogue peering connections, access to SD-WAN Manager, configuration extraction, and unauthorized changes pushed to edge devices all point to a campaign focused on control, persistence, and stealth. The root account creation is the loudest technical detail, but the more important operational issue is certificate and peering trust. Mandiant noted that some rogue peering activity occurred on systems not vulnerable to previously disclosed authentication bypass flaws, and Cisco suggested stolen certificates from earlier compromises may have been used. That means patching CVE-2026-20245 is necessary, but not enough. Organizations need to review trust relationships, certificates, peer connections, and historical access.</p><p><strong>READ THE STORY: <a href="https://www.bleepingcomputer.com/news/security/mandiant-reveals-how-cisco-sd-wan-zero-day-attacks-gained-root-access/">Bleeping Computer</a></strong></p><h1><strong>Pedit COW Linux Kernel Flaw Enables Local Root Privilege Escalation</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-46331 and dubbed Pedit COW, allows an unprivileged local user to gain full root access on vulnerable systems. A working public proof-of-concept exploit, packet_edit_meme, appeared within 24 hours of CVE assignment, sharply increasing risk for unpatched Linux hosts.</strong></p><p><strong>Analyst Comments:</strong> This belongs in the same mental bucket as Dirty Pipe, DirtyClone, and Dirty Frag: a kernel fast-path bug that lets an attacker write where they should not be able to write. The difference here is the entry point. Pedit COW abuses the Linux traffic-control subsystem and can be reached from a user namespace, allowing an unprivileged user to obtain namespace-local CAP_NET_ADMIN and then turn that into host-level root. That makes this especially relevant for multi-user and multi-tenant environments: Kubernetes nodes, CI/CD runners, shared build systems, developer workstations, hosting platforms, and research clusters. Anywhere untrusted users or workloads can execute local code should be prioritized.</p><p><strong>READ THE STORY: <a href="https://gbhackers.com/critical-linux-kernel-flaw-2/">GBhackers</a></strong></p><h1><strong>Items of interest</strong></h1><h1><strong>Chinese Users Bypass Anthropic&#8217;s Claude Restrictions Through Proxies, Resold Accounts, and API Relay Services</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>WIRED reports that Anthropic&#8217;s efforts to block Claude access from China are being routinely bypassed through VPNs, foreign phone numbers, resold accounts, fake identities, and &#8220;transfer station&#8221; API relay services. The workaround economy has grown into a shadow market that gives Chinese users access to Claude while creating new risks around fraud, identity abuse, prompt interception, and unauthorized model access.</strong></p><p><strong>Analyst Comments:</strong> Anthropic can tighten geofencing, account bans, identity checks, and proxy detection, but as long as Claude remains valuable and publicly accessible elsewhere, users in restricted regions will keep finding paths around the gate. The stronger the restriction, the more the market shifts from casual VPN use to professionalized brokers, relay services, and fake identity vendors. The security risk cuts both ways. For Anthropic and U.S. policymakers, these workarounds undermine export-control and model-access restrictions, especially where advanced coding and agentic capabilities are involved. For Chinese users and companies, using underground relay services means their prompts, source code, credentials, business plans, and research data may pass through untrusted intermediaries that can log, resell, or manipulate traffic.</p><p><strong>READ THE STORY: <a href="https://archive.is/53zxo">Wired</a></strong></p><h1><strong>China&#8217;s 97% Off GPT &amp; Claude API Scam Exposed (Video)</strong></h1><p><strong>FROM THE MEDIA: What if I told you some students in China are reportedly getting access to GPT 5.4 and Claude API keys for up to 97% less than the official price? It sounds like the ultimate AI loophole: spend just a dollar or two, burn through tens of millions of tokens, plug the key into Cursor or VS Code, and start building. On the surface, it looks like a dream for developers, indie hackers, and anyone obsessed with AI coding tools.</strong></p><div id="youtube2-jQfqhGmPsOY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;jQfqhGmPsOY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/jQfqhGmPsOY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1><strong>Cheap Claude Tokens: The Million-Dollar Scam (Video)</strong></h1><p><strong>FROM THE MEDIA: </strong><span>Grey-market &#8220;Claude&#8221; access can look like a huge discount, but the real price may be your prompts, source code, tool outputs, and accepted agent patches.</span></p><div id="youtube2-ryEuB3t3YJo" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;ryEuB3t3YJo&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/ryEuB3t3YJo?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don&#8217;t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com. </p>]]></content:encoded></item><item><title><![CDATA[Daily Drop (1326) ]]></title><description><![CDATA[06-26-26]]></description><link>https://bragg.substack.com/p/daily-drop-1326</link><guid isPermaLink="false">https://bragg.substack.com/p/daily-drop-1326</guid><dc:creator><![CDATA[Bob Bragg]]></dc:creator><pubDate>Sat, 27 Jun 2026 01:41:56 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!qeLl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3069c99-bc2e-477d-85eb-d11a349f1efc_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Friday, Jun 26, 2026 // <a href="https://buymeacoffee.com/infodom">Buy Bob a Coffee</a> // <a href="https://ghostwire.news">Ghostwire</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qeLl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3069c99-bc2e-477d-85eb-d11a349f1efc_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qeLl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3069c99-bc2e-477d-85eb-d11a349f1efc_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!qeLl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3069c99-bc2e-477d-85eb-d11a349f1efc_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!qeLl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3069c99-bc2e-477d-85eb-d11a349f1efc_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!qeLl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3069c99-bc2e-477d-85eb-d11a349f1efc_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qeLl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3069c99-bc2e-477d-85eb-d11a349f1efc_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f3069c99-bc2e-477d-85eb-d11a349f1efc_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3445029,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://bragg.substack.com/i/203755684?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3069c99-bc2e-477d-85eb-d11a349f1efc_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qeLl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3069c99-bc2e-477d-85eb-d11a349f1efc_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!qeLl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3069c99-bc2e-477d-85eb-d11a349f1efc_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!qeLl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3069c99-bc2e-477d-85eb-d11a349f1efc_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!qeLl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3069c99-bc2e-477d-85eb-d11a349f1efc_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>Chinese Users Bypass Anthropic&#8217;s Claude Restrictions Through Proxies, Resold Accounts, and API Relay Services</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>WIRED reports that Anthropic&#8217;s efforts to block Claude access from China are being routinely bypassed through VPNs, foreign phone numbers, resold accounts, fake identities, and &#8220;transfer station&#8221; API relay services. The workaround economy has grown into a shadow market that gives Chinese users access to Claude while creating new risks around fraud, identity abuse, prompt interception, and unauthorized model access.</strong></p><p><strong>Analyst Comments:</strong> Anthropic can tighten geofencing, account bans, identity checks, and proxy detection, but as long as Claude remains valuable and publicly accessible elsewhere, users in restricted regions will keep finding paths around the gate. The stronger the restriction, the more the market shifts from casual VPN use to professionalized brokers, relay services, and fake identity vendors. The security risk cuts both ways. For Anthropic and U.S. policymakers, these workarounds undermine export-control and model-access restrictions, especially where advanced coding and agentic capabilities are involved. For Chinese users and companies, using underground relay services means their prompts, source code, credentials, business plans, and research data may pass through untrusted intermediaries that can log, resell, or manipulate traffic.</p><p><strong>READ THE STORY: <a href="https://archive.is/53zxo">Wired</a></strong></p><h1><strong>Russian Intelligence Hackers Target Signal Backup Recovery Keys in Account Takeover Campaign</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The FBI and CISA updated their warning on Russian intelligence-linked phishing campaigns targeting secure messaging accounts, adding a new Signal-specific tactic: attackers are now tricking users into revealing their Signal Backup Recovery Key. Once obtained, the key can allow attackers to restore message backups, read private and group chat history, and potentially take over the account.</strong></p><p><strong>Analyst Comments:</strong> Signal&#8217;s crypto is holding; the account owner is being socially engineered into handing over the recovery material. That makes this campaign especially dangerous for high-value targets because the attackers are no longer just chasing one-time codes or linked-device access. They are going after the key that unlocks the message archive. The persistence angle is ugly. According to the advisory, the old recovery key may remain useful even if the victim creates a new Signal account using the same phone number. That gives defenders a clear remediation step: generate a new recovery key immediately if exposure is suspected. But anything already restored by the attacker should be treated as compromised.</p><p><strong>READ THE STORY: <a href="https://thehackernews.com/2026/06/fbi-warns-russian-intelligence-hackers.html">THN</a></strong></p><h1><strong>Meta Tests Facial Recognition Smart Glasses for Police and Military Use</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Bruce Schneier highlighted reporting that Meta is prototyping facial recognition capabilities for smart glasses with a Pentagon supplier, raising concerns about real-time identification by police, military, and immigration enforcement. The post connects the development to broader fears that wearable facial recognition could normalize persistent public surveillance.</strong></p><p><strong>Analyst Comments:</strong> Smart glasses with real-time facial recognition are not just another camera platform. They change the surveillance model from fixed infrastructure to mobile, person-mounted identification at street level. The civil liberties risk is obvious: protests, immigration enforcement, political gatherings, and routine policing become easier to monitor without visible checkpoints or fixed cameras. Even if Meta frames this as a prototype or restricted deployment, the concern is function creep. Tools built for military or law enforcement use tend to migrate, expand, and get normalized once the operational value is proven.</p><p><strong>READ THE STORY: <a href="https://www.schneier.com/blog/archives/2026/06/meta-is-testing-facial-recognition-for-police-and-military.html">Schneier</a></strong></p><h1><strong>Confidence Drops in Fully Autonomous AI Penetration Testing</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A new Cobalt report shows confidence in fully autonomous AI penetration testing has fallen sharply, with only 9% of organizations willing to rely on AI-powered pentesting in 2026, down from 29% in 2025. Security teams are still adopting AI for assessment workflows, but most now favor human-in-the-loop testing because autonomous tools miss serious vulnerabilities, generate noisy findings, and create unpredictable costs.</strong></p><p><strong>Analyst Comments:</strong> The market is correcting from &#8220;AI will replace pentesters&#8221; to &#8220;AI can accelerate pentesters.&#8221; That is a healthier place to be. Autonomous tools are useful for breadth, repetition, reconnaissance, first-pass testing, and surfacing leads. They are still weak at judgment, exploitability validation, business-context prioritization, and chaining findings into real-world attack paths.</p><p><strong>READ THE STORY: <a href="https://www.darkreading.com/cybersecurity-operations/ai-decline-confidence-autonomous-penetration-testing">DR</a></strong></p><h1><strong>Secret Service Review Finds Personal Phone Use and Weak Mobile Security During Protective Missions</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A Department of Homeland Security inspector general review found that U.S. Secret Service employees routinely used personal phones for official communications during protective operations, including domestic and overseas missions. The report also found government-issued mobile devices lacked continuous threat protection, contained vulnerable apps, and were not consistently wiped after international travel, creating serious operational security risks.</strong></p><p><strong>Analyst Comments:</strong> Personal phones used during protective missions can expose communications, contacts, photos, location data, and mission details. In this context, phone compromise is not just an IT problem; it can become a physical security problem for agents, protectees, and visiting heads of state. The uncomfortable part is that employees were not simply ignoring policy for convenience. The review found that government-issued devices lacked the capabilities needed to perform mission work, pushing agents toward personal phones, hotspots, and blocked websites. That is how shadow IT becomes normalized: the official tool fails the mission, so the workforce routes around it.</p><p><strong>READ THE STORY: <a href="https://www.theregister.com/security/2026/06/26/even-the-secret-service-wont-use-company-issued-phones/5263356">The Register</a></strong></p><h1><strong>DirtyClone Linux Kernel Flaw Can Enable Local Root Access</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers disclosed DirtyClone, a high-severity Linux kernel local privilege escalation vulnerability tracked as CVE-2026-43503. The flaw can allow a local unprivileged attacker to gain root access by abusing socket buffer fragment handling in the kernel&#8217;s networking code. Remote exploitation is not possible, but systems that allow local code execution or unprivileged user namespaces face elevated risk.</strong></p><p><strong>Analyst Comments:</strong> Most real intrusions eventually reach a point where the attacker has low-privilege code execution and needs root. DirtyClone gives them a plausible path there. The container angle is also worth watching. If unprivileged user namespaces expose capabilities such as CAP_NET_ADMIN inside a namespace, the blast radius may extend beyond a normal local privilege escalation and into container escape scenarios. That does not mean every containerized workload is automatically vulnerable, but it does mean Linux hosts running mixed-trust workloads should move quickly.</p><p><strong>READ THE STORY: <a href="https://linuxiac.com/linux-gets-dirty-again-dirtyclone-kernel-flaw-can-lead-to-local-root-access/">Linuxiac</a></strong></p><h1><strong>Critical Veeam Backup &amp; Replication RCE Threatens Enterprise Recovery Infrastructure</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The Centre for Cybersecurity Belgium is warning organizations to patch CVE-2026-44963, a critical remote code execution vulnerability affecting Veeam Backup &amp; Replication versions 12 through 12.3.2. The flaw carries a CVSS 4.0 score of 9.4 and allows an authenticated domain user to execute code on the Veeam Backup Server over the network.</strong></p><p><strong>Analyst Comments:</strong> Veeam servers are high-value targets because they often hold stored credentials, manage backup repositories, and control the recovery path after a ransomware incident. If an attacker gets code execution on the backup server, they may be able to delete backups, encrypt recovery data, steal credentials, or pivot into connected infrastructure.</p><p><strong>READ THE STORY: <a href="https://ccb.belgium.be/advisories/warning-critical-remote-code-execution-veeam-backup-replication-patch-immediately">CCB</a></strong></p><h1><strong>Prinz Eugen Ransomware Abuses RemotePC and PowerShell Stagers for Enterprise Intrusions</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A newly observed ransomware operation is using compromised RDP credentials, legitimate RemotePC remote management software, and PowerShell stagers to deploy Prinz Eugen ransomware. The malware, written in Go, prioritizes recently modified files, uses strong ChaCha20-Poly1305 encryption, removes itself after execution, and avoids writing ransom notes to disk, making post-incident recovery and forensics harder.</strong></p><p><strong>Analyst Comments:</strong> Prinz Eugen does not look like commodity ransomware sprayed blindly across the internet. The operator appears to understand enterprise environments, forensic blind spots, and victim pressure points. Targeting recently modified files first is especially nasty because it hits active business data before older backup-friendly files, increasing operational pain fast. The abuse of RemotePC is also worth flagging. Threat actors continue to lean on legitimate RMM tools because they blend into normal admin behavior and often bypass controls focused only on malware. Pair that with PowerShell staging, weak or stolen RDP credentials, and a manually created local admin account, and this becomes a familiar but effective intrusion chain.</p><p><strong>READ THE STORY: <a href="https://cybersecuritynews.com/hackers-use-remotepc-rmm-and-powershell-stagers/">CSN</a></strong></p><h1><strong>CISA Orders Urgent Patching for Exploited Cisco Unified CM SSRF Flaw</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>CISA added CVE-2026-20230, a critical Cisco Unified Communications Manager Server SSRF vulnerability, to its Known Exploited Vulnerabilities catalog after confirmed exploitation in the wild. Federal agencies have until June 28, 2026 to patch or mitigate the issue under BOD 26-04. CISA also added CVE-2026-12569, a critical RCE flaw affecting PTC Windchill and FlexPLM, with the same deadline.</strong></p><p><strong>Analyst Comments:</strong> Cisco Unified Communications Manager is not just another enterprise app. It sits inside voice and collaboration infrastructure, often trusted by internal networks and tied into identity, call routing, and business communications. A remotely exploitable, unauthenticated SSRF in that environment is ugly enough. Active exploitation makes this a drop-everything patch item.</p><p><strong>READ THE STORY: <a href="https://www.bleepingcomputer.com/news/security/cisa-sets-urgent-deadline-to-fix-cisco-flaw-exploited-in-attacks/">Bleeping Computer</a></strong></p><h1><strong>Operation Endgame Disrupts StealC and Amadey Malware Infrastructure</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>International law enforcement and private-sector partners disrupted infrastructure tied to StealC and Amadey, two malware families frequently used together for access, credential theft, payload delivery, and follow-on cybercrime. The action hit 326 servers and 142 domains, froze more than &#8364;41 million in crypto assets, and followed a related takedown of SocGholish infrastructure.</strong></p><p><strong>Analyst Comments:</strong> StealC and Amadey sit in the messy middle of the cybercrime supply chain: initial access, credential theft, loader activity, and payload delivery. That makes them useful to ransomware crews, fraud groups, and access brokers alike. The interesting part is the convergence. Microsoft, Proofpoint, IBM X-Force, Europol, and law enforcement treated separately developed malware families as part of a broader shared operational ecosystem because they relied on overlapping infrastructure. That is the right approach. Malware crews do not operate in clean silos, and defenders should not investigate them that way either.</p><p><strong>READ THE STORY: <a href="https://www.helpnetsecurity.com/2026/06/24/operation-endgame-stealc-amadey-malware-disrupted/">HSN</a></strong></p><h1><strong>Microsoft Patches Critical M365 Copilot SearchLeak Vulnerability That Exposed Sensitive User Data</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Microsoft patched a critical vulnerability in M365 Copilot that researchers showed could be abused to steal sensitive data from a user&#8217;s Microsoft 365 environment, including 2FA codes stored in email. The exploit chain, dubbed SearchLeak by Varonis, used prompt injection through a search URL parameter, temporary raw HTML rendering, and Bing as an allowed request relay to exfiltrate data without the victim typing anything.</strong></p><p><strong>Analyst Comments:</strong> The exploit is especially concerning because it targets the enterprise tier of Copilot. That means the exposed data is not limited to personal inbox content. Depending on permissions, Copilot may be able to surface emails, meeting notes, SharePoint documents, OneDrive files, and other indexed organizational data. In other words, SearchLeak turns &#8220;whatever this user can access&#8221; into the blast radius.</p><p><strong>READ THE STORY: <a href="https://arstechnica.com/security/2026/06/critical-copilot-vulnerability-allowed-hackers-to-seal-2fa-code-from-users/">arsTECHNICA</a></strong></p><h1><strong>Items of interest</strong></h1><h1><strong>U.S. Delays Blacklisting DeepSeek, CXMT, and 100+ Firms Flagged as Security Risks</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Reuters reports that the U.S. has held off adding China&#8217;s DeepSeek, memory chipmaker CXMT, and more than 100 other companies to the Commerce Department&#8217;s Entity List despite an interagency committee approving them for blacklisting. The delay leaves U.S. goods, software, and technology potentially available to companies already deemed national security risks.</strong></p><p><strong>Analyst Comments:</strong> The Entity List is supposed to be one of Washington&#8217;s sharpest tools for limiting adversary access to sensitive U.S. technology, especially chips, AI tooling, semiconductor equipment, and dual-use systems. If companies have already cleared the interagency process for listing but remain unpublished, the practical effect is a gap attackers, military suppliers, and sanctions-evasion networks can exploit. DeepSeek is the headline name because of AI, but the broader concern is the scale: more than 100 firms reportedly approved but not listed, including entities tied to restricted Nvidia chip flows, Chinese military-linked drone and robot-dog suppliers, and companies allegedly connected to Russian drones recovered in Poland. That points to a larger enforcement problem, not a paperwork delay.</p><p><strong>READ THE STORY: <a href="https://www.reuters.com/world/china/us-holds-off-blacklisting-chinas-deepseek-more-than-100-firms-deemed-security-2026-06-17/">Reuters</a></strong></p><h1><strong>DeepSeek V4: What Are They Hiding (Video)</strong></h1><p><strong>FROM THE MEDIA: The long-awaited DeepSeek V4 update raises more questions than answers. When you put the pieces together, the pattern becomes hard to ignore.</strong></p><div id="youtube2-gQjV3BJaF-U" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;gQjV3BJaF-U&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/gQjV3BJaF-U?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1><strong>DeepSeek dodges addition to US trade blacklist (Video)</strong></h1><p><strong>FROM THE MEDIA: </strong><span>The US has held off adding China's AI startup DeepSeek, memory chipmaker CXMT and more than 100 other companies flagged as national security risks to a trade blacklist, according to two people familiar with the matter.</span></p><div id="youtube2-60Yibxsj5Vg" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;60Yibxsj5Vg&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/60Yibxsj5Vg?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don&#8217;t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com. </p>]]></content:encoded></item><item><title><![CDATA[Daily Drop (1325) ]]></title><description><![CDATA[06-24-26]]></description><link>https://bragg.substack.com/p/daily-drop-1325</link><guid isPermaLink="false">https://bragg.substack.com/p/daily-drop-1325</guid><dc:creator><![CDATA[Bob Bragg]]></dc:creator><pubDate>Wed, 24 Jun 2026 11:32:33 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!P3m2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba8a1e6-95ed-45d6-a66e-14384bfc7d9c_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Wednesday, Jun 24, 2026 // <a href="https://buymeacoffee.com/infodom">Buy Bob a Coffee</a> // <a href="https://ghostwire.news">Ghostwire</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!P3m2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba8a1e6-95ed-45d6-a66e-14384bfc7d9c_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!P3m2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba8a1e6-95ed-45d6-a66e-14384bfc7d9c_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!P3m2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba8a1e6-95ed-45d6-a66e-14384bfc7d9c_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!P3m2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba8a1e6-95ed-45d6-a66e-14384bfc7d9c_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!P3m2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba8a1e6-95ed-45d6-a66e-14384bfc7d9c_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!P3m2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba8a1e6-95ed-45d6-a66e-14384bfc7d9c_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3ba8a1e6-95ed-45d6-a66e-14384bfc7d9c_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3331063,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://bragg.substack.com/i/203369697?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba8a1e6-95ed-45d6-a66e-14384bfc7d9c_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!P3m2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba8a1e6-95ed-45d6-a66e-14384bfc7d9c_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!P3m2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba8a1e6-95ed-45d6-a66e-14384bfc7d9c_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!P3m2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba8a1e6-95ed-45d6-a66e-14384bfc7d9c_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!P3m2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ba8a1e6-95ed-45d6-a66e-14384bfc7d9c_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>Five Eyes Warn AI Will Transform Cyber Operations Within Months, Not Years</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The Five Eyes intelligence alliance (United States, United Kingdom, Canada, Australia, and New Zealand) issued an unusually direct warning that frontier AI models are expected to fundamentally reshape cybersecurity within months rather than years. Intelligence officials believe AI will dramatically accelerate both offensive and defensive cyber capabilities, reducing the time between vulnerability discovery and active exploitation while lowering barriers for less sophisticated threat actors.</strong></p><p><strong>Analyst Comments:</strong> When the Five Eyes publishes a coordinated warning, it's worth paying attention. What's notable here isn't that AI will impact cybersecurity&#8212;that's already happening. The significant part is the timeline. Intelligence agencies are effectively signaling that the pace of capability development is outstripping current organizational preparedness. This aligns with recent developments across the industry: OpenAI's Daybreak vulnerability remediation initiative, Anthropic's increasingly autonomous enterprise agents, AI-assisted vulnerability discovery research, and growing evidence that threat actors are operationalizing AI for phishing, reconnaissance, malware development, and social engineering. The warning reflects a growing consensus that organizations are approaching a period where cyber operations become increasingly machine-speed rather than human-speed.</p><p><strong>READ THE STORY: <a href="https://therecord.media/five-eyes-alert-artificial-intelligence">The Record</a></strong></p><h1><strong>OpenAI Expands Daybreak Initiative to Automate Vulnerability Remediation and Open-Source Security</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>OpenAI has expanded its Daybreak cybersecurity initiative, shifting AI security efforts beyond vulnerability discovery and into automated remediation. The company announced major enhancements to Codex Security, expanded access to GPT-5.5-Cyber, launched a cyber partner ecosystem, and introduced Patch the Planet, an initiative focused on helping open-source projects identify and fix vulnerabilities. The move reflects a broader industry push toward using AI to address the growing backlog of unpatched software flaws.</strong></p><p><strong>Analyst Comments:</strong> Security teams are drowning in scanner results, bug bounty submissions, CVEs, and dependency alerts while developer resources remain constrained. OpenAI&#8217;s strategy directly targets this imbalance by focusing AI on validation, prioritization, and patch generation rather than simply increasing vulnerability discovery rates. If successful, this could significantly reduce remediation timelines and help organizations address one of the largest operational challenges in modern security programs. The real test, however, will be whether enterprises trust AI-generated patches in production environments. Generating a fix is one thing; deploying it safely at scale is another.</p><p><strong>READ THE STORY: <a href="https://www.helpnetsecurity.com/2026/06/23/openai-expanded-daybreak-cybersecurity-initiative/">HNS</a></strong></p><h1><strong>Anthropic Launches Claude Tag for Slack, Bringing Persistent AI Agents Into Enterprise Workflows</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Anthropic has launched Claude Tag, a new AI agent capability for Slack that transforms Claude from a chatbot into a persistent, collaborative team member capable of executing tasks, accessing approved enterprise data, and autonomously managing workflows. Available in beta for Claude Enterprise and Team customers, the feature allows organizations to embed AI directly into operational processes, signaling a major step toward agentic AI adoption across the enterprise.</strong></p><p><strong>Analyst Comments:</strong> Claude Tag moves AI from an on-demand assistant model to an embedded operational role inside the collaboration platforms where work actually happens. The security implications are substantial. Organizations are no longer granting AI access to a single conversation&#8212;they are granting it persistent visibility into channels, code repositories, datasets, workflows, and business processes. While Anthropic emphasizes access controls, audit logging, and role separation, the real challenge for security teams will be governance. Every new AI identity effectively becomes a privileged service account that requires the same scrutiny applied to human users, APIs, and automation platforms. Expect competitors to accelerate similar offerings as enterprise AI shifts from productivity enhancement to workflow execution.</p><p><strong>READ THE STORY: <a href="https://gbhackers.com/anthropic-launches-claude-tag-ai-agent/">GBhackers</a></strong></p><h1><strong>DifyTap: Four Vulnerabilities Expose Cross-Tenant Data Across 1M+ AI Applications</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers at Zafran Labs disclosed four vulnerabilities in the open-source AI platform Dify that could allow attackers to access private documents, AI conversations, and application data across tenant boundaries. Two flaws are rated critical (CVE-2026-41947 and CVE-2026-41948), including an unauthenticated vulnerability that enables access to internal Plugin Daemon endpoints. Dify is used by major enterprises and powers more than one million AI applications across over 60 industries, making the potential exposure significant.</strong></p><p><strong>Analyst Comments:</strong> The most concerning issue is the breakdown of tenant isolation, allowing one customer to potentially access another customer&#8217;s data. This is the type of failure cloud providers spend years engineering to prevent. The research also exposes a broader challenge facing AI ecosystems: platforms routinely process untrusted files, plugins, and user content while relying on complex third-party components that often receive insufficient security scrutiny. Expect threat actors to increasingly focus on AI orchestration platforms as they become embedded into enterprise operations. This is less a Dify problem and more a preview of what defenders should expect across the AI application stack.</p><p><strong>READ THE STORY: <a href="https://securityaffairs.com/194081/hacking/difytap-four-bugs-put-over-1-million-ai-apps-at-risk.html">Security Affairs</a></strong></p><h1><strong>Cisco Unified CM Vulnerability Now Under Active Exploitation Following Public PoC Release</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Threat actors have begun actively exploiting CVE-2026-20230, a high-severity Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME) vulnerability that enables unauthenticated attackers to abuse a Server-Side Request Forgery (SSRF) flaw to write arbitrary files to the underlying operating system. Researchers have observed exploitation attempts in the wild following publication of technical details and proof-of-concept (PoC) code. Successful exploitation can ultimately lead to root-level access on vulnerable systems.</strong></p><p><strong>Analyst Comments:</strong> Cisco released patches on June 3, and within weeks researchers are observing live attacks against internet-facing systems. While the current activity appears largely reconnaissance-oriented&#8212;testing whether systems are vulnerable&#8212;the publication of a functional PoC significantly raises the likelihood of broader exploitation. Unified CM sits at the heart of enterprise voice infrastructure, often integrated with Active Directory, collaboration platforms, contact centers, and critical communications systems. A compromise here isn&#8217;t just a phone system problem; it can become an enterprise access problem. Organizations running Cisco Unified CM should assume opportunistic scanning is already underway.</p><p><strong>READ THE STORY: <a href="https://thehackernews.com/2026/06/cisco-unified-cm-flaw-exploited-after.html">THN</a></strong></p><h1><strong>PoC Released for Microsoft Exchange EWS SSRF Vulnerability</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A proof-of-concept exploit is now available for CVE-2026-45502, a Microsoft Exchange Server SSRF flaw in the Exchange Web Services InstallApp operation. Authenticated mailbox users can abuse the ManifestUrl parameter to force Exchange servers to make HTTP requests to internal or external systems, enabling internal reconnaissance and possible attack chaining.</strong></p><p><strong>Analyst Comments:</strong> This is not a headline-grabbing unauthenticated Exchange bug, but defenders should not shrug it off. Exchange servers often sit in privileged network positions with visibility into internal services attackers cannot normally reach. Even a &#8220;blind&#8221; SSRF can be useful for mapping internal assets, probing metadata endpoints, and setting up follow-on exploitation. The public PoC raises the likelihood of opportunistic testing, especially against organizations slow to apply June 2026 Exchange updates.</p><p><strong>READ THE STORY: <a href="https://gbhackers.com/poc-released-for-microsoft-exchange-server-vulnerability/">GBhackers</a></strong></p><h1><strong>Critical Jenkins Deserialization Flaw Enables User Impersonation and Potential RCE</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The Centre for Cybersecurity Belgium (CCB) is warning organizations to immediately patch CVE-2026-53435, a high-severity Jenkins deserialization vulnerability affecting Jenkins versions prior to 2.567 and LTS 2.555.2. The flaw allows authenticated users to impersonate other users, execute arbitrary code, and access sensitive files, creating a significant risk for organizations that rely on Jenkins for CI/CD operations.</strong></p><p><strong>Analyst Comments:</strong> Jenkins remains one of the most attractive targets in enterprise environments because it often sits at the center of development pipelines with access to source code, secrets, build infrastructure, and production deployment workflows. While exploitation requires an authenticated account with specific permissions, that&#8217;s not much comfort in environments where attackers routinely gain footholds through phishing, credential theft, or compromised developer accounts. Once inside Jenkins, the ability to impersonate users and potentially access the script console can quickly turn a low-level compromise into full environment takeover. Organizations should treat this as more than a routine patch cycle item&#8212;Jenkins servers frequently hold the keys to the kingdom.</p><p><strong>READ THE STORY: <a href="https://ccb.belgium.be/advisories/warning-high-arbitrary-code-execution-vulnerability-jenkins-patch-immediately">CCB</a></strong></p><h1><strong>Webmin Stored XSS Flaw Allows Low-Privilege Users to Target Root Administrators</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A stored cross-site scripting (XSS) vulnerability tracked as CVE-2026-22678 affects Webmin versions prior to 2.641 and allows authenticated users with limited permissions to inject malicious JavaScript into notification email templates. When a privileged administrator or root user views the modified template, the payload executes in their browser session, potentially leading to session hijacking, privilege escalation, and full system compromise.</strong></p><p><strong>Analyst Comments:</strong> Stored XSS vulnerabilities in administrative platforms are often underestimated because they typically require some level of authenticated access. That's a mistake. In environments where multiple administrators, operators, or delegated users access management consoles, stored XSS can become an effective privilege-escalation mechanism. In this case, a low-privilege Webmin user can potentially compromise a root-level administrator simply by planting a payload and waiting. Since Webmin frequently manages Linux servers, credentials, services, and configuration settings, successful exploitation could provide attackers with direct access to critical infrastructure. The attack path is straightforward, and organizations running Webmin should prioritize patching.</p><p><strong>READ THE STORY: <a href="https://gbhackers.com/webmin-stored-xss-vulnerability/">GBhackers</a></strong></p><h1><strong>FortiBleed: 110 Million Credentials Harvested Through Global FortiGate Access Operation</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Security researchers have uncovered FortiBleed, a large-scale credential harvesting campaign targeting more than 430,000 FortiGate firewalls worldwide and resulting in the collection of over 110 million credentials. Rather than relying on a zero-day vulnerability, the operation combines mass scanning, credential stuffing, brute forcing, configuration harvesting, password cracking, and passive credential interception to systematically build a catalog of enterprise access for monetization and downstream attacks.</strong></p><p><strong>Analyst Comments:</strong> FortiBleed represents the evolution of the modern Initial Access Broker (IAB) model. This is not a ransomware operation, espionage campaign, or smash-and-grab intrusion. It's industrialized access harvesting. The operators appear less interested in any single victim than in creating a scalable pipeline that continuously converts exposed perimeter devices into credentials, credentials into network access, and network access into a marketable commodity. The most concerning aspect is that the campaign reportedly does not rely on a new vulnerability. Instead, it exploits weak passwords, credential reuse, poor MFA adoption, exposed services, and operational security gaps that exist in thousands of organizations today. This is exactly the kind of campaign that demonstrates why identity has become the primary battleground in cybersecurity.</p><p><strong>READ THE STORY: <a href="https://thehackernews.com/2026/06/fortibleed-targeted-fortigate-firewalls.html">THN</a></strong></p><h1><strong>LastPass Customer Data Exposed Through Klue Supply Chain Attack</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>LastPass disclosed that attackers leveraged compromised OAuth tokens stolen during a breach of Klue, a third-party market intelligence platform, to access customer information stored in its Salesforce environment. While password vaults, products, and core infrastructure were not affected, exposed CRM data includes customer contact information, support records, and sales-related data that could fuel targeted phishing and social engineering campaigns.</strong></p><p><strong>Analyst Comments:</strong> The compromise was not the result of a direct attack against LastPass but rather a trusted third-party platform holding privileged OAuth access into business systems. Threat actors continue to target these integration points because a single compromise can provide access to multiple downstream organizations. Given LastPass's history and high-profile customer base, attackers will likely weaponize the stolen data for credential harvesting, business email compromise (BEC), and impersonation campaigns. Organizations should review third-party OAuth permissions, continuously monitor connected applications, and enforce token lifecycle management to reduce exposure from similar supply chain compromises.</p><p><strong>READ THE STORY: <a href="https://www.helpnetsecurity.com/2026/06/24/lastpass-klue-data-breach-salesforce-environment/">HNS</a></strong></p><h1><strong>GhostShell Targets Ukraine&#8217;s UAV Ecosystem Using RAR Exploit and Persistent VBS Loader</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers identified a targeted espionage campaign against Ukraine&#8217;s unmanned aerial vehicle (UAV) sector that abuses RAR archive vulnerabilities (CVE-2025-8088 and CVE-2025-6218) to deploy a persistent Visual Basic Script (VBS) loader. The operation, attributed to a previously untracked actor dubbed GhostShell, uses drone-related decoy documents to infect military, procurement, engineering, and defense-sector personnel before delivering a multi-stage malware framework designed for intelligence collection.</strong></p><p><strong>Analyst Comments:</strong> Rather than pursuing financial gain, GhostShell appears focused on collecting information from Ukraine&#8217;s drone ecosystem&#8212;a strategic target given the central role UAVs play in the conflict. The operation combines social engineering, archive exploitation, persistence mechanisms, encrypted payload delivery, and custom command-and-control infrastructure. What stands out is the actor&#8217;s targeting discipline. The lure documents reference drone hardware, launch systems, charging stations, and procurement materials, suggesting reconnaissance and victim selection were conducted well before delivery. This is not opportunistic malware; it is a focused collection effort aligned with military and defense objectives.</p><p><strong>READ THE STORY: <a href="https://gbhackers.com/vbs-in-ukraine-uav-malware/">GBhackers</a></strong></p><h1><strong>Dropping Elephant Uses Fake PDF Shortcut and &#8220;GoogleErrorReport&#8221; Persistence to Deploy Memory-Resident RAT</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers have identified a new campaign by the Dropping Elephant threat group that uses a malicious Windows shortcut file disguised as an industrial contract document to deploy a memory-resident remote access trojan (RAT). The malware abuses legitimate Microsoft binaries, DLL side-loading, PowerShell, and a scheduled task named GoogleErrorReport to maintain persistence while evading traditional endpoint defenses.</strong></p><p><strong>Analyst Comments:</strong> This campaign is a textbook example of modern intrusion tradecraft: low-complexity initial access combined with sophisticated post-exploitation techniques. The initial lure&#8212;a disguised LNK file&#8212;isn't new, but what follows is more concerning. The operators leverage trusted Windows components, in-memory execution, API obfuscation, and security control tampering to avoid detection. The scheduled task named <em>GoogleErrorReport</em> is particularly notable because it blends into normal system activity while repeatedly relaunching the malware every minute. Defenders should view this less as a malware problem and more as a behavioral detection challenge. Organizations relying heavily on signature-based controls are likely to miss activity that never writes a traditional payload to disk.</p><p><strong>READ THE STORY: <a href="https://cisowhisperer.com/hackers-use-googleerrorreport-scheduled-task-for-persistence-in-dropping-elephant-campaign/?utm_source=rss#038;utm_medium=rss&amp;#038;utm_campaign=hackers-use-googleerrorreport-scheduled-task-for-persistence-in-dropping-elephant-campaign">CISO Whisperer</a></strong></p><h1><strong>DOJ Seizes Huione Cloud Infrastructure Tied to $31 Billion Cybercrime Ecosystem</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The U.S. Department of Justice seized a cloud computing account used by subsidiaries of Cambodia-based HuiOne Group, a key facilitator of cryptocurrency fraud, money laundering, phishing operations, and cyber-enabled scams. Authorities say the infrastructure supported Huione Guarantee (later Haowang Guarantee), a criminal marketplace that processed more than $31 billion in cryptocurrency transactions, making it the largest illicit online marketplace ever recorded.</strong></p><p><strong>Analyst Comments:</strong> While ransomware groups attract headlines, the industrial-scale fraud ecosystem centered in Southeast Asia has arguably become the most profitable cybercrime model globally. Huione functioned as a one-stop shop for cybercriminals, offering stolen data, phishing kits, money laundering services, fake investment platform development, deepfake technology, and even services supporting human trafficking operations tied to scam compounds. The seizure demonstrates increasing Western focus on disrupting the financial and technical infrastructure that enables large-scale fraud rather than solely pursuing individual threat actors. However, as seen after previous marketplace takedowns, criminal operators have already adapted by launching replacement platforms and migrating to proprietary communications systems. Expect continued fragmentation rather than elimination of the ecosystem.</p><p><strong>READ THE STORY: <a href="https://thehackernews.com/2026/06/doj-seizes-huione-cloud-account-tied-to.html">THN</a> // <a href="https://cyberscoop.com/doj-huione-group-cybercrime-seizure/">Cyberscoop</a></strong></p><h1><strong>Where IT Meets OT: Railway Cybersecurity Faces Growing Risk as Legacy Systems Connect to Modern Networks</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Railway operators are facing a growing cybersecurity challenge as decades-old operational technology (OT) systems become increasingly interconnected with modern IT infrastructure, cloud services, and AI-driven applications. According to DNV&#8217;s Global Head of Railway Services, Jorge Aldegunde, the traditional separation between IT and OT has effectively disappeared, expanding attack surfaces across rail networks and making cyber resilience a critical operational requirement rather than a compliance exercise.</strong></p><p><strong>Analyst Comments:</strong> Rail systems were originally designed for safety, reliability, and availability&#8212;not adversarial environments. As operators connect signaling systems, SCADA platforms, maintenance systems, cloud analytics, and passenger services through IP-based networks, they inherit the same cyber risks that enterprise IT environments have battled for years. The difference is that a compromised railway system can create immediate operational and public safety consequences. The most important takeaway isn't the technology discussion&#8212;it's the shift toward resilience. Railway operators increasingly accept that prevention alone is unrealistic and are instead focusing on detection, containment, and maintaining safe operations during cyber incidents.</p><p><strong>READ THE STORY: <a href="https://www.helpnetsecurity.com/2026/06/24/jorge-aldegunde-dnv-railway-cybersecurity/">HNS</a></strong></p><h1><strong>Items of interest</strong></h1><h1><strong>Two Scattered Spider Members Plead Guilty Over Transport for London Cyberattack</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Two alleged Scattered Spider members, Thalha Jubair, 20, and Owen Flowers, 18, pleaded guilty to compromising Transport for London between August 31 and September 3, 2024. The attack caused major disruption, forced password resets for roughly 28,000 employees, impacted Oyster services, and generated estimated losses of &#163;29 million. Sentencing is expected on July 16, 2026.</strong></p><p><strong>Analyst Comments:</strong> Scattered Spider&#8217;s strength is not exotic malware; it is identity abuse, social engineering, credential theft, and fast coordination across collaborative platforms. The TfL case also shows why identity compromise is now critical infrastructure risk. A few operators with stolen credentials and remote access can disrupt public services, delay customer reimbursements, and force enterprise-wide resets. For defenders, the lesson is blunt: if help desk workflows, MFA recovery, and privileged access monitoring are weak, attackers do not need zero-days.</p><p><strong>READ THE STORY: </strong><a href="https://gbhackers.com/two-scattered-spider-hackers-convicted/">GBhackers</a></p><h1><strong>Scattered Spider | The Cybercrime Apex Predator (Video)</strong></h1><p><strong>FROM THE MEDIA: Scattered Spider &#8212; the hacker collective behind massive cyber threats like the MGM Resorts shutdown and the Marks &amp; Spencer cyberattack &#8212; is changing the cybersecurity landscape.</strong></p><div id="youtube2-GHBFZtRSOGo" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;GHBFZtRSOGo&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/GHBFZtRSOGo?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1><strong>Inside Scattered Spider: Who They Are (Video)</strong></h1><p><strong>FROM THE MEDIA: </strong><span>Scattered Spider is no ordinary threat actor.<br> This decentralized, English-speaking cybercrime collective has breached the likes of Twilio, DoorDash, and major financial institutions, relying not on brute force, but highly believable social engineering.</span></p><div id="youtube2-pLrpUHI_WE4" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;pLrpUHI_WE4&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/pLrpUHI_WE4?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don&#8217;t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com. </p>]]></content:encoded></item><item><title><![CDATA[Daily Drop (1324) ]]></title><description><![CDATA[06-23-26]]></description><link>https://bragg.substack.com/p/daily-drop-1324</link><guid isPermaLink="false">https://bragg.substack.com/p/daily-drop-1324</guid><dc:creator><![CDATA[Bob Bragg]]></dc:creator><pubDate>Wed, 24 Jun 2026 01:10:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!bKR0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa78a4793-f36a-4a9e-9ab7-8e7ca906d317_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Tuesday, Jun 23, 2026 // <a href="https://buymeacoffee.com/infodom">Buy Bob a Coffee</a> // <a href="https://ghostwire.news">Ghostwire</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bKR0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa78a4793-f36a-4a9e-9ab7-8e7ca906d317_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bKR0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa78a4793-f36a-4a9e-9ab7-8e7ca906d317_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!bKR0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa78a4793-f36a-4a9e-9ab7-8e7ca906d317_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!bKR0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa78a4793-f36a-4a9e-9ab7-8e7ca906d317_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!bKR0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa78a4793-f36a-4a9e-9ab7-8e7ca906d317_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bKR0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa78a4793-f36a-4a9e-9ab7-8e7ca906d317_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a78a4793-f36a-4a9e-9ab7-8e7ca906d317_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3724763,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://bragg.substack.com/i/203326965?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa78a4793-f36a-4a9e-9ab7-8e7ca906d317_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bKR0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa78a4793-f36a-4a9e-9ab7-8e7ca906d317_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!bKR0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa78a4793-f36a-4a9e-9ab7-8e7ca906d317_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!bKR0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa78a4793-f36a-4a9e-9ab7-8e7ca906d317_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!bKR0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa78a4793-f36a-4a9e-9ab7-8e7ca906d317_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>U.S. Government Domains Lead Global DNS Resilience, Australia Lags on DNSSEC Adoption</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A new academic study assessing the resilience of authoritative DNS infrastructure across federal government domains in six countries found that the United States maintains the strongest overall DNS resilience, while Australia trails due to widespread lack of DNSSEC implementation. Researchers warn that weaknesses in authoritative DNS infrastructure increase the risk of service disruption, DNS manipulation, and cyberattacks against critical government services.</strong></p><p><strong>Analyst Comments:</strong> DNS rarely receives executive attention until something breaks, but it remains one of the most critical components of national digital infrastructure. Government services ranging from taxation and healthcare to public safety rely on authoritative DNS as the single source of truth for routing users to legitimate systems. If attackers can disrupt, manipulate, or spoof DNS responses, they can potentially redirect citizens to malicious services, conduct credential theft campaigns, or deny access to essential government functions.</p><p><strong>READ THE STORY: </strong><a href="https://pulse.internetsociety.org/en/blog/2026/06/how-resilient-are-government-dns-services/">Internet Society Pulse</a></p><h1><strong>White House Accelerates Post-Quantum Crypto Deadline Amid Growing Quantum Threat Concerns</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The White House has issued a new executive order significantly accelerating the U.S. government&#8217;s transition to post-quantum cryptography (PQC). Federal high-value assets and high-impact systems must migrate to quantum-resistant key establishment mechanisms by December 31, 2030, and quantum-safe digital signatures by December 31, 2031&#8212;roughly 4-5 years earlier than many previous government timelines. The move reflects growing concerns that advances in quantum computing could enable adversaries to decrypt sensitive data collected today.</strong></p><p><strong>Analyst Comments:</strong> While no cryptographically relevant quantum computer exists today, recent research continues to reduce the estimated resources needed to break RSA and elliptic curve cryptography, forcing governments and major technology providers to act sooner rather than later. The bigger concern is not immediate decryption but &#8220;harvest now, decrypt later&#8221; operations. Nation-state adversaries can collect encrypted diplomatic, military, intelligence, healthcare, financial, and corporate data today and store it until quantum capabilities mature. Organizations delaying crypto modernization may discover that their most sensitive information was compromised years before the technology to decrypt it became available.</p><p><strong>READ THE STORY: </strong><a href="https://arstechnica.com/information-technology/2026/06/executive-order-bumps-up-deadline-to-move-off-quantum-vulnerable-crypto/">arsTECHNICA</a></p><h1><strong>CISA Adds Lantronix Industrial Device Vulnerability to Known Exploited Vulnerabilities Catalog</strong></h1><p><em>NOTE:</em></p><p><em>Many of the impacted devices&#8212;including Siemens industrial controllers, Honeywell building management systems, Trane automation platforms, EV charging infrastructure, and Lantronix network devices&#8212;sit at the intersection of IT and OT environments. As organizations continue connecting traditionally isolated operational systems to enterprise networks and cloud-based management platforms, the attack surface expands significantly.</em></p><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-67038, affecting Lantronix EDS5000 industrial networking devices, to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation. The update elevates the risk profile for organizations operating industrial control systems (ICS), operational technology (OT), and critical infrastructure environments using affected Lantronix equipment.</strong></p><p><strong>Analyst Comments:</strong> For industrial environments, that distinction matters. Many ICS vulnerabilities remain difficult to exploit in practice, but KEV inclusion indicates adversaries are already using the flaw successfully. The Lantronix EDS5000 is commonly deployed as an industrial device server and connectivity platform within operational technology environments. These systems often bridge legacy industrial assets with modern IP networks, making them attractive targets for attackers seeking initial access, persistence, or lateral movement into critical infrastructure.</p><p><strong>READ THE STORY: </strong><a href="https://www.cyber.gc.ca/en/alerts-advisories/control-systems-cisa-ics-security-advisories-av26-241">Cyber Canada</a> (CA)</p><h1><strong>Iranian Cyber Groups Use AI to Increase Attacks on Space Infrastructure</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Iranian-aligned threat actors are increasingly leveraging artificial intelligence to enhance cyber operations targeting military and civilian space infrastructure during the ongoing Iran conflict. Security researchers report a significant increase in attack volume, more sophisticated social engineering campaigns, and improved operational security, making attribution and detection more difficult for defenders.</strong></p><p><strong>Analyst Comments:</strong> The headline is not that AI is creating entirely new attack techniques&#8212;it is making existing ones faster, more scalable, and more convincing. Iranian groups historically relied heavily on phishing, credential theft, and influence operations. AI allows them to improve targeting, eliminate language barriers, automate reconnaissance, and create more persuasive impersonation campaigns. Of particular concern is the targeting of space-sector organizations. Satellites, ground stations, space logistics platforms, and supporting contractors are increasingly viewed as critical infrastructure during conflicts. Space systems provide communications, intelligence, navigation, and military support capabilities, making them attractive targets for disruption and espionage.</p><p><strong>READ THE STORY: </strong><a href="https://www.nationaldefensemagazine.org/articles/2026/6/23/just-in-iranian-hacker-groups-increase-space-satellite-hacking-efficiency-with-ai-experts-say">National Defense</a> // <a href="https://www.fdd.org/in_the_news/2026/06/23/is-there-a-houthi-threat-to-israel/">FDD</a></p><h1><strong>Israel-Linked Cyberattack Disrupts Iranian Banking System Amid Escalating Conflict</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A major cyberattack has disrupted operations at several Iranian banks, with reports indicating the attack was carried out by the pro-Israel hacktivist group Predatory Sparrow (Gonjeshke Darande). The incident temporarily impacted banking services across Iran and marks the latest cyber operation targeting critical financial infrastructure as tensions between Israel and Iran continue to escalate.</strong></p><p><strong>Analyst Comments:</strong> Predatory Sparrow has built a reputation for conducting some of the most sophisticated and operationally disruptive cyberattacks attributed to a pro-Israel actor. Unlike typical hacktivist groups focused on website defacements or data leaks, the group consistently targets operational systems tied to strategic Iranian infrastructure, including fuel distribution networks, steel production facilities, rail systems, and now financial institutions. The timing is notable. As kinetic and diplomatic pressure on Iran increases, cyber operations appear to be functioning as an additional layer of statecraft. Whether Predatory Sparrow operates independently or with state support remains publicly unconfirmed, but its historical targeting, technical sophistication, and strategic impact have long fueled speculation about links to Israeli interests.</p><p><strong>READ THE STORY: </strong><a href="https://www.telegraph.co.uk/world-news/2026/06/23/israel-behind-cyber-attack-on-iranian-banks/">The Telegraph</a></p><h1><strong>Tata Electronics Confirms Cyberattack After World Leaks Publishes Alleged Apple Manufacturing Data</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Tata Electronics has confirmed a cyberattack affecting portions of its IT infrastructure after the World Leaks extortion group published data allegedly stolen from the company. While Tata states manufacturing operations remain unaffected, the leaked material reportedly includes Apple-related manufacturing documents, component schematics, PCB designs, and development files. The incident highlights growing espionage and extortion risks facing global technology supply chains.</strong></p><p><strong>Analyst Comments:</strong> If the leaked files are authentic, the incident could provide threat actors, competitors, or nation-state intelligence services with insight into manufacturing processes, component designs, and product development workflows. World Leaks&#8217; involvement is also notable. Unlike traditional ransomware operators, the group has shifted to a pure data-extortion model, focusing on stealing sensitive information and leveraging public exposure as the primary pressure mechanism. That trend continues across the threat landscape as organizations improve recovery capabilities and reduce the effectiveness of encryption-based attacks.</p><p><strong>READ THE STORY: </strong><a href="https://www.bleepingcomputer.com/news/security/tata-electronics-confirms-cyberattack-as-hackers-leak-data/">Bleeping Computer</a></p><h1><strong>Samsung KNOX Kernel Flaw Could Enable Full Galaxy Device Compromise Across Multiple Generations</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers at LucidBit Labs disclosed CVE-2026-20971, a kernel-level use-after-free (UAF) vulnerability within Samsung's KNOX security framework that could allow attackers to achieve kernel memory corruption and potentially full device compromise. The flaw affects a broad range of Samsung Galaxy devices spanning Galaxy S9 through S25, including A-series devices running Android 13-16. Samsung patched the issue in its January 2026 security update.</strong></p><p><strong>Analyst Comments:</strong> The vulnerability resides inside Samsung&#8217;s KNOX security architecture&#8212;software specifically designed to improve device security&#8212;but ultimately introduced a new kernel attack surface. What makes this finding noteworthy is not simply the UAF itself, but the researchers&#8217; ability to transform a narrow race condition into practical exploitation primitives despite modern mitigations such as Kernel Control Flow Integrity (KCFI). While KCFI successfully blocked some arbitrary code execution paths, researchers still identified alternate methods to achieve controlled memory corruption.</p><p><strong>READ THE STORY: </strong><a href="https://securityaffairs.com/194090/security/samsung-knox-kernel-uaf-exposes-millions-of-galaxy-devices.html">Security Affairs</a></p><h1><strong>OpenClaw Skill Marketplace Abused by Malware, Fraud, and AI Supply Chain Attacks</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Palo Alto Networks Unit 42 identified multiple malicious skills in the OpenClaw AI ecosystem that bypassed existing security controls and abused the platform&#8217;s agentic execution model. Researchers found infostealers, defense-evasion techniques, affiliate fraud schemes, and AI-driven financial manipulation campaigns operating through ClawHub, demonstrating that AI agent marketplaces are rapidly becoming a new software supply chain attack surface.</strong></p><p><strong>Analyst Comments:</strong> Traditional software supply chain attacks typically focus on code execution. In contrast, malicious AI skills can weaponize trust, instructions, and agent autonomy. The most concerning finding is not the malware itself&#8212;it&#8217;s the emergence of &#8220;agentic threats&#8221; where attackers manipulate AI agents into generating affiliate revenue, promoting financial products, or participating in coordinated market activity without requiring a conventional exploit.</p><p><strong>READ THE STORY: </strong><a href="https://unit42.paloaltonetworks.com/openclaw-ai-supply-chain-risk/">Unit 42</a></p><h1><strong>Icarus Expands Salesforce Data Theft Campaign Through Klue OAuth Breach</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The scope of the Klue OAuth compromise continues to grow as multiple technology and cybersecurity firms confirm unauthorized access to Salesforce data after attackers abused OAuth tokens obtained during Klue&#8217;s breach. The extortion group Icarus has begun leaking stolen data and claims additional victims will emerge. While most impacted organizations report no compromise of core products or infrastructure, the incident demonstrates how third-party SaaS integrations can create cascading supply chain exposure across entire customer ecosystems.</strong></p><p><strong>Analyst Comments:</strong> The story is not Salesforce itself&#8212;it&#8217;s the trust relationship created by OAuth integrations. Once attackers obtained Klue&#8217;s access, they effectively inherited visibility into customer Salesforce environments across multiple organizations. The victim list is notable because it includes security vendors and technology companies that generally maintain mature security programs. That reinforces a recurring lesson: third-party integrations often bypass traditional security boundaries. The attack also echoes the 2025 Salesloft-related Salesforce compromises, where exposed CRM environments contained API tokens, operational data, and other sensitive business information.</p><p><strong>READ THE STORY: </strong><a href="https://www.darkreading.com/cyberattacks-data-breaches/scope-salesforce-attacks-expands-icarus-leaks-data">DR</a></p><h1><strong>Cisco SD-WAN Zero-Day Campaign Highlights Growing Focus on Network Infrastructure</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Federal agencies reached CISA's June 23 remediation deadline for two actively exploited network infrastructure vulnerabilities: Cisco Catalyst SD-WAN Manager CVE-2026-20245 and Arista EOS CVE-2026-7473. The Cisco flaw is particularly noteworthy because it represents the seventh actively exploited Cisco SD-WAN zero-day disclosed in 2026, reinforcing concerns that attackers are systematically targeting enterprise network management platforms rather than individual endpoints.</strong></p><p><strong>Analyst Comments:</strong> For years, defenders concentrated on securing servers, workstations, and identity systems. Increasingly, threat actors are targeting the infrastructure that controls everything else. Cisco SD-WAN Manager serves as the central authority for enterprise routing, traffic steering, segmentation, and policy enforcement across potentially hundreds of branch locations. A compromise at that layer gives attackers network-wide influence without needing to compromise each endpoint individually. The fact that Cisco has now disclosed seven exploited SD-WAN vulnerabilities in a single year suggests a sustained campaign against management-plane infrastructure rather than isolated vulnerability discovery.</p><p><strong>READ THE STORY: </strong><a href="https://www.techtimes.com/articles/318952/20260623/cisco-sd-wan-logs-seventh-zero-day-2026-cisa-patch-deadline-arrives-today.htm">Techtimes</a></p><h1><strong>Microsoft Rolls Out Point-in-Time Restore in Windows 11 Preview Update</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Microsoft has released the optional Windows 11 KB5095093 preview update, introducing Point-in-Time Restore, a new recovery capability that allows users to roll back their entire system&#8212;including applications, settings, and personal files&#8212;to a previous state within minutes. The update also includes reliability improvements across networking, Bluetooth, File Explorer, Windows Update, and accessibility features.</strong></p><p><strong>Analyst Comments:</strong> Unlike traditional System Restore, which primarily targets system files and settings, Microsoft's new approach captures a broader system state and can restore applications and user data from snapshots taken automatically over the previous 72 hours. From a cybersecurity and operational resilience perspective, this provides organizations with a faster recovery option following failed updates, software instability, configuration errors, or limited malware incidents. While it is not a replacement for backups or disaster recovery solutions, it adds another layer to endpoint resilience and could reduce downtime for both enterprise and consumer systems. The broader trend is clear: Microsoft is increasingly building recovery and resilience features directly into Windows as ransomware and operational disruptions continue to drive demand for faster restoration capabilities.</p><p><strong>READ THE STORY: </strong><a href="https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5095093-update-rolls-out-new-point-in-time-restore-feature/">Bleeping Computer</a></p><h1><strong>Critical pgAdmin 4 Flaws Enable Unauthenticated RCE and Database Credential Theft</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Belgium's Centre for Cybersecurity (CCB) is warning organizations to immediately patch pgAdmin 4 versions prior to 9.16 after the disclosure of three critical vulnerabilities that can enable unauthenticated remote code execution, credential theft, database compromise, and cross-site scripting attacks. The most severe issues carry CVSS scores up to 9.3 and affect one of the most widely used PostgreSQL administration platforms.</strong></p><p><strong>Analyst Comments:</strong> Together, they create several viable attack chains that can result in full database administration compromise and, in certain configurations, underlying server compromise. The standout issue is CVE-2026-12046, which allows unauthenticated attackers to reach vulnerable SQL Editor endpoints that expose a pickle deserialization sink. Unauthenticated RCE in administrative software is always a high-priority event, especially for platforms that often manage production databases containing sensitive business data.</p><p><strong>READ THE STORY: </strong><a href="https://ccb.belgium.be/advisories/warning-remote-code-execution-and-cross-site-scripting-pgadmin-4-can-be-exploited">CCB</a></p><h1><strong>Cisco Unified CM Vulnerability Now Under Active Exploitation</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A high-severity Cisco Unified Communications Manager (Unified CM) vulnerability, CVE-2026-20230 (CVSS 8.6), is now being actively exploited in the wild. The flaw allows unauthenticated attackers to abuse a Server-Side Request Forgery (SSRF) vulnerability in the WebDialer component to write arbitrary files to the underlying operating system, creating a pathway to root-level compromise. Organizations running vulnerable Unified CM or Unified CM Session Management Edition (SME) systems should prioritize patching immediately.</strong></p><p><strong>Analyst Comments:</strong> While current activity appears focused on reconnaissance and vulnerability validation, that window rarely stays open for long. Unified CM systems are attractive targets because they often sit at the center of enterprise voice infrastructure, maintain privileged network access, and frequently support business-critical communications. Once attackers move beyond testing payloads, defenders should expect webshell deployment, credential harvesting, persistence mechanisms, and lateral movement attempts. The fact that exploitation requires no authentication significantly raises the risk profile, especially for internet-exposed deployments.</p><p><strong>READ THE STORY: </strong><a href="https://www.bleepingcomputer.com/news/security/cisco-unified-cm-sme-flaw-cve-2026-20230-now-exploited-in-attacks/">Bleeping Computer</a></p><h1><strong>Items of interest</strong></h1><h1><strong>Two Scattered Spider Members Plead Guilty Over Transport for London Cyberattack</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Two alleged Scattered Spider members, Thalha Jubair, 20, and Owen Flowers, 18, pleaded guilty to compromising Transport for London between August 31 and September 3, 2024. The attack caused major disruption, forced password resets for roughly 28,000 employees, impacted Oyster services, and generated estimated losses of &#163;29 million. Sentencing is expected on July 16, 2026.</strong></p><p><strong>Analyst Comments:</strong> Scattered Spider&#8217;s strength is not exotic malware; it is identity abuse, social engineering, credential theft, and fast coordination across collaborative platforms. The TfL case also shows why identity compromise is now critical infrastructure risk. A few operators with stolen credentials and remote access can disrupt public services, delay customer reimbursements, and force enterprise-wide resets. For defenders, the lesson is blunt: if help desk workflows, MFA recovery, and privileged access monitoring are weak, attackers do not need zero-days.</p><p><strong>READ THE STORY: </strong><a href="https://gbhackers.com/two-scattered-spider-hackers-convicted/">GBhackers</a></p><h1><strong>Scattered Spider | The Cybercrime Apex Predator (Video)</strong></h1><p><strong>FROM THE MEDIA: Scattered Spider &#8212; the hacker collective behind massive cyber threats like the MGM Resorts shutdown and the Marks &amp; Spencer cyberattack &#8212; is changing the cybersecurity landscape.</strong></p><div id="youtube2-GHBFZtRSOGo" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;GHBFZtRSOGo&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/GHBFZtRSOGo?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1><strong>Inside Scattered Spider: Who They Are (Video)</strong></h1><p><strong>FROM THE MEDIA: </strong><span>Scattered Spider is no ordinary threat actor.<br> This decentralized, English-speaking cybercrime collective has breached the likes of Twilio, DoorDash, and major financial institutions, relying not on brute force, but highly believable social engineering.</span></p><div id="youtube2-pLrpUHI_WE4" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;pLrpUHI_WE4&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/pLrpUHI_WE4?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don&#8217;t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com. </p>]]></content:encoded></item><item><title><![CDATA[Daily Drop (1323) ]]></title><description><![CDATA[06-22-26]]></description><link>https://bragg.substack.com/p/daily-drop-1323</link><guid isPermaLink="false">https://bragg.substack.com/p/daily-drop-1323</guid><dc:creator><![CDATA[Bob Bragg]]></dc:creator><pubDate>Tue, 23 Jun 2026 08:42:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!GFCm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d30dd2f-e0de-4963-b1c9-b3df86dc13fb_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Monday, Jun 22, 2026 // <a href="https://buymeacoffee.com/infodom">Buy Bob a Coffee</a> // <a href="https://ghostwire.news">Ghostwire</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GFCm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d30dd2f-e0de-4963-b1c9-b3df86dc13fb_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GFCm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d30dd2f-e0de-4963-b1c9-b3df86dc13fb_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!GFCm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d30dd2f-e0de-4963-b1c9-b3df86dc13fb_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!GFCm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d30dd2f-e0de-4963-b1c9-b3df86dc13fb_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!GFCm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d30dd2f-e0de-4963-b1c9-b3df86dc13fb_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GFCm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d30dd2f-e0de-4963-b1c9-b3df86dc13fb_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4d30dd2f-e0de-4963-b1c9-b3df86dc13fb_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3275786,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://bragg.substack.com/i/203175761?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d30dd2f-e0de-4963-b1c9-b3df86dc13fb_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GFCm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d30dd2f-e0de-4963-b1c9-b3df86dc13fb_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!GFCm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d30dd2f-e0de-4963-b1c9-b3df86dc13fb_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!GFCm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d30dd2f-e0de-4963-b1c9-b3df86dc13fb_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!GFCm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d30dd2f-e0de-4963-b1c9-b3df86dc13fb_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>CyberSentinel AI v3.0 Launches as Open-Source Autonomous Security Platform Integrating 33 Offensive and Defensive Tools (CN TOOL)</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>CyberSentinel AI v3.0, a new open-source cybersecurity platform, has been released, combining 33 real-world security tools, threat intelligence feeds, and multiple large language model (LLM) providers into a fully self-hosted, autonomous security platform. The framework supports Claude, GPT-4o, OpenRouter, and offline inference via Ollama, while executing tools such as Nmap, SQLMap, Nuclei, Nikto, and OWASP ZAP within an isolated Kali Linux Docker sandbox. The platform represents a notable step toward AI-driven security automation by enabling agents to autonomously select, execute, and analyze security tools without cloud dependencies.</strong></p><p><strong>Analyst Comments:</strong> The ability to chain reconnaissance, vulnerability scanning, threat intelligence enrichment, and reporting functions into a single agent-driven workflow significantly reduces the technical barrier to performing advanced security operations. From a defensive perspective, platforms like CyberSentinel could improve SOC efficiency by automating repetitive tasks such as vulnerability validation, IOC enrichment, and attack surface mapping. However, the same capabilities lower the operational overhead required for offensive activity. Autonomous execution of tools like SQLMap, Nuclei, and OWASP ZAP creates dual-use concerns, particularly as open-source AI frameworks increasingly enable less-skilled actors to perform sophisticated reconnaissance and vulnerability discovery at scale.</p><p><strong>READ THE STORY: </strong><a href="https://www.anquanke.com/post/id/315663">Anquanke</a></p><h1><strong>SpaceX Unveils Starfall Orbital Cargo Vehicle for Rapid Global Delivery and In-Space Manufacturing</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>SpaceX is preparing to launch the first demonstration of Starfall, a new reusable orbital reentry vehicle designed to enable rapid point-to-point cargo delivery anywhere on Earth and support the emerging in-space manufacturing economy. The saucer-shaped vehicle can carry approximately 1 metric ton (2,200 pounds) of payload, reenter Earth's atmosphere, and splash down under parachutes after missions lasting only a few hours. The platform could provide the U.S. military and commercial customers with a new capability for delivering critical cargo on unprecedented timelines.</strong></p><p><strong>Analyst Comments:</strong> While marketed as a cargo and manufacturing return vehicle, its most immediate strategic relevance is likely in military applications. The Pentagon has long pursued the concept of Rocket Cargo, where critical equipment, medical supplies, spare parts, or specialized payloads can be delivered globally within hours instead of days or weeks. Starship remains the centerpiece of that vision, but its size and infrastructure requirements limit operational flexibility. Starfall offers a potentially more practical option for smaller, high-priority deliveries that do not require landing a 20-story spacecraft.</p><p><strong>READ THE STORY: </strong><a href="https://arstechnica.com/space/2026/06/with-starfall-spacex-eyes-an-edge-in-global-cargo-delivery-from-orbit/">arsTECHNICA</a></p><h1><strong>Researchers Disclose &#8216;Squidbleed&#8217; (CVE-2026-47729): 29-Year-Old Squid Proxy Flaw Leaks Authorization Headers and API Keys</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Security researchers have disclosed CVE-2026-47729, dubbed &#8220;Squidbleed,&#8221; a decades-old information disclosure vulnerability in Squid Proxy that can expose sensitive data, including HTTP Authorization headers, bearer tokens, and API keys. The flaw stems from a heap buffer over-read in Squid&#8217;s legacy FTP directory listing parser and has reportedly existed since at least 1997. An attacker controlling an FTP server accessible by a vulnerable Squid instance can leak residual memory contents from other users&#8217; sessions, creating significant credential exposure risks in environments using plaintext HTTP or TLS interception.</strong></p><p><strong>Analyst Comments:</strong> The vulnerability does not provide remote code execution, but information disclosure flaws that expose authentication material can be equally damaging, particularly in enterprise environments where proxies sit in the middle of sensitive communications. The root cause&#8212;a subtle misuse of <code>strchr()</code> when processing malformed FTP directory listings&#8212;highlights the difficulty of identifying edge-case memory bugs in mature codebases. More concerning is Squid&#8217;s use of recycled, uncleared memory pools, allowing stale HTTP request data from one user to be exposed to another. In practical terms, an attacker could potentially recover API keys, bearer tokens, and authorization headers that enable lateral movement or unauthorized access to downstream services.</p><p><strong>READ THE STORY: </strong><a href="https://gbhackers.com/29-year-old-squid-proxy-vulnerability/">GBhackers</a></p><h1><strong>Two Scattered Spider Members Plead Guilty in Transport for London Cyber Attack That Caused &#163;29 Million in Damages</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Two alleged members of the Scattered Spider cybercrime collective, Thalha Jubair (20) and Owen Flowers (18), have pleaded guilty to conducting a cyberattack against Transport for London (TfL) between August 31 and September 3, 2024. The intrusion disrupted critical public transportation services, forced password resets for approximately 28,000 employees, and resulted in an estimated &#163;29 million ($39 million) in financial losses. Investigators also uncovered evidence linking the suspects to intrusions targeting U.S. healthcare organizations, underscoring Scattered Spider's continued focus on identity-based attacks against high-value sectors.</strong></p><p><strong>Analyst Comments:</strong> Scattered Spider has repeatedly demonstrated that social engineering, credential theft, and abuse of legitimate access mechanisms remain highly effective against large organizations. The group&#8217;s success stems from its ability to exploit human trust, help desk procedures, and weak identity controls rather than relying on advanced malware or novel vulnerabilities. The TfL incident is particularly significant because it highlights the real-world consequences of cyberattacks against critical infrastructure. The compromise disrupted transportation services used by millions, impacted children&#8217;s travel programs through Oyster photocard service interruptions, and imposed substantial recovery costs. Cyber incidents increasingly produce physical-world effects, even when the initial intrusion vector is purely digital.</p><p><strong>READ THE STORY: </strong><a href="https://gbhackers.com/two-scattered-spider-hackers-convicted/">GBhackers</a></p><h1><strong>Maine Shuts Down Data Breach Portal After Fake VRChat and Discord Breach Notices Expose Verification Failures</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Maine&#8217;s Office of the Attorney General has temporarily taken its public-facing data breach notification portal offline after unknown actors submitted fraudulent breach disclosures impersonating VRChat and Discord. The hoax filings falsely claimed breaches affecting millions of users and exploited a process that automatically published submissions without independent verification. The incident raises concerns about the integrity of public breach reporting systems and demonstrates how trusted disclosure platforms can be manipulated to inflict reputational damage and spread disinformation.</strong></p><p><strong>Analyst Comments:</strong> State breach registries are widely used by journalists, threat intelligence firms, investors, and security teams as authoritative sources of disclosure information. The ability to publish fabricated breach notices directly onto an official government portal creates opportunities for reputation attacks, market manipulation, and information operations. The abuse also highlights a broader issue: many disclosure ecosystems were designed under the assumption that filers would act in good faith. That assumption no longer holds. As cyber incidents increasingly carry financial, legal, and reputational consequences, adversaries have incentives to weaponize trusted reporting mechanisms.</p><p><strong>READ THE STORY: </strong><a href="https://cyberpress.org/maine-takes-data-breach/">CyberPress</a> // <a href="https://cisowhisperer.com/maine-closes-data-breach-portal-after-fake-breach-notices/?utm_source=rss#038;utm_medium=rss&amp;#038;utm_campaign=maine-closes-data-breach-portal-after-fake-breach-notices">CISO Whisperer</a></p><h1><strong>1,000 Data Breaches Later, Disclosure Delays Are Getting Worse Despite Global Privacy Regulations</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Have I Been Pwned (HIBP) founder Troy Hunt marked the platform's 1,000th breach by highlighting a troubling trend: organizations are taking longer than ever to disclose data breaches, even after victims' data is already publicly circulating. Hunt argues that despite the introduction of regulations such as GDPR and CCPA, many companies prioritize legal risk management and litigation concerns over timely customer notification, leaving victims unaware of their exposure for weeks&#8212;or potentially indefinitely.</strong></p><p><strong>Analyst Comments:</strong> Threat actors like ShinyHunters increasingly publish stolen data within days of an intrusion, often distributing it across dark web forums, Telegram channels, and clear-web repositories long before organizations formally acknowledge the incident. The underlying incentives are misaligned. Privacy regulations generally require notification only when organizations determine that a breach is likely to result in significant harm. This creates substantial discretion for companies to delay notifications while conducting investigations or, in some cases, avoid disclosure entirely by narrowly interpreting regulatory thresholds. The result is a system where victims frequently learn of their exposure from third-party services such as HIBP rather than from the organizations entrusted with their data.</p><p><strong>READ THE STORY: </strong><a href="https://www.troyhunt.com/1000-data-breaches-later-the-disclosure-lag-is-worse-than-ever/">Troyhunt</a></p><h1><strong>FulcrumSec Claims Theft of 1.3TB From Novo Nordisk, Including Drug Research, Clinical Data, and Internal AI Models</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Cyber extortion group FulcrumSec claims it stole more than 1.3 terabytes of data comprising over 700,000 files from pharmaceutical giant Novo Nordisk after allegedly maintaining access to the company's networks for more than two months. The threat actors claim the stolen data includes source code, proprietary drug research, clinical trial information, employee and patient data, manufacturing information, and details related to Novo Nordisk's internal AI models. Novo Nordisk has acknowledged unauthorized data publication claims and is investigating the incident.</strong></p><p><strong>Analyst Comments:</strong> The alleged theft of unreleased drug research, clinical trial data, and internal AI models could have long-term implications that extend beyond immediate financial losses and regulatory obligations. Pharmaceutical companies are increasingly attractive targets because they sit at the intersection of valuable intellectual property, sensitive health information, and critical manufacturing operations. Drug development timelines span years and require billions in investment, making proprietary research and trial data exceptionally valuable to competitors, nation-state intelligence services, and criminal actors seeking extortion leverage.</p><p><strong>READ THE STORY: </strong><a href="https://finance.yahoo.com/healthcare/articles/novo-nordisk-data-breach-hackers-150106943.html">Benzinga</a></p><h1><strong>Texas TPWD Vendor Breach Exposes Personal Data of Over 3 Million Hunting and Fishing License Holders</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The Texas Parks and Wildlife Department (TPWD) disclosed that a cyberattack against its third-party licensing vendor exposed the personal information of 3,087,721 individuals. Compromised data includes driver&#8217;s license information, passport numbers, email addresses, phone numbers, and residential addresses. While Social Security numbers, dates of birth, and financial data were not affected, the exposed information creates significant risks of phishing, identity fraud, and targeted social engineering attacks.</strong></p><p><strong>Analyst Comments:</strong> The breach did not occur within TPWD&#8217;s own infrastructure, yet more than three million individuals are now dealing with the consequences. The absence of Social Security numbers and financial information lowers the immediate risk of traditional identity theft, but the exposed dataset is still highly valuable to threat actors. Driver&#8217;s license information, contact details, and residential addresses provide enough intelligence to build convincing impersonation campaigns, conduct account recovery attacks, and execute highly targeted phishing operations.</p><p><strong>READ THE STORY: </strong><a href="https://www.bleepingcomputer.com/news/security/texas-govt-data-breach-exposes-over-3-million-drivers-licenses/">Bleeping Computer</a></p><h1><strong>Ireland&#8217;s HSE Fined &#8364;300,000 Over Ransomware Breach Affecting 84,000 Patients</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Ireland&#8217;s Data Protection Commission fined the Health Service Executive &#8364;300,000 after a ransomware incident at Midlands Regional Hospital Tullamore exposed systems processing patient and laboratory data. The breach affected approximately 84,000 individuals and led regulators to find that HSE failed to implement appropriate technical and organizational safeguards under GDPR.</strong></p><p><strong>Analyst Comments:</strong> Healthcare organizations do not get a pass because the attacker was external; regulators are increasingly judging whether controls were reasonable before the incident happened. The case also highlights the risk of interconnected clinical, lab, and administrative systems. Once ransomware reaches patient data environments, the blast radius can quickly expand from IT disruption to sensitive health-data exposure and compliance liability.</p><p><strong>READ THE STORY: </strong><a href="https://cisowhisperer.com/hse-fined-e300000-after-tullamore-hospital-data-breach/?utm_source=rss#038;utm_medium=rss&amp;#038;utm_campaign=hse-fined-e300000-after-tullamore-hospital-data-breach">CISO Whisperer</a></p><h1><strong>Google Patches 74 Chrome Vulnerabilities, Confirms Active Exploitation of CVE-2026-11645</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The Center for Internet Security (CIS) has issued an advisory warning that 74 vulnerabilities in Google Chrome could allow arbitrary code execution, with Google confirming that CVE-2026-11645, an out-of-bounds memory access flaw in V8, is being actively exploited in the wild. Successful exploitation could enable attackers to execute code in the context of the logged-on user, potentially leading to malware installation, data theft, account creation, or system compromise. Organizations should immediately update Chrome to 149.0.7827.102/.103 for Windows and macOS and 149.0.7827.102 for Linux.</strong></p><p><strong>Analyst Comments:</strong> The overwhelming majority of flaws in this release are use-after-free, out-of-bounds, type confusion, and input validation issues, many of which are historically associated with remote code execution chains. The most important detail is Google&#8217;s confirmation that CVE-2026-11645 is already being exploited in the wild. Once a browser zero-day reaches active exploitation status, organizations should assume that exploitation tooling will quickly proliferate among both criminal and state-sponsored actors. Browser vulnerabilities remain attractive because they can be triggered through drive-by compromise scenarios, requiring little more than a user visiting a malicious or compromised website.</p><p><strong>READ THE STORY: </strong><a href="https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-054">CIS</a></p><h1><strong>Items of interest</strong></h1><h1><strong>Go Security Pitfalls Persist: GolangConf Presentation Highlights Injection, Request Smuggling, and Authentication Risks</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A presentation by MTS Web Services Application Security Engineer Georgy Fateev warns that Go&#8217;s simplicity and strong standard library do not inherently produce secure applications. Common vulnerabilities&#8212;including command injection, SQL injection, HTTP request smuggling, insecure logging, and authentication flaws&#8212;continue to affect production Go environments. The presentation emphasizes that secure development depends more on engineering discipline, testing, and security culture than on language choice.</strong></p><p><strong>Analyst Comments:</strong> The presentation&#8217;s emphasis on &#8220;never trust user input&#8221; remains highly relevant, as injection-based vulnerabilities continue to drive breaches despite decades of awareness. The recommendation to use reachability-based dependency analysis tools such as <code>govulncheck</code> is particularly noteworthy because it reduces alert fatigue by prioritizing vulnerabilities that are actually exploitable within an application&#8217;s code path. The discussion of HTTP request smuggling is also timely. Misconfigurations between reverse proxies and backend services remain a frequent source of high-impact vulnerabilities capable of enabling authentication bypass and request desynchronization attacks. Likewise, insecure logging practices continue to be an underappreciated source of credential exposure and compliance violations.</p><p><strong>READ THE STORY: </strong><a href="https://habr.com/ru/companies/oleg-bunin/articles/1048122/">HABR</a></p><h1><strong>The GO Situation Is CRAZY... (Video)</strong></h1><p><strong>FROM THE MEDIA: The video correctly identifies a real concern&#8212;software supply-chain attacks in the Go ecosystem</strong></p><div id="youtube2-EyO_SMl2YBk" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;EyO_SMl2YBk&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/EyO_SMl2YBk?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1><strong>What is LLM Distillation?(Video)</strong></h1><p><strong>FROM THE MEDIA: Welcome to another Software Architecture in Go/Golang video, in today's episode I'm discussing Security, specifically in the context of Dependencies, this is narrowed down to Standard Library Packages and Third Party Packages.</strong></p><div id="youtube2-5E9QOuop5lo" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;5E9QOuop5lo&quot;,&quot;startTime&quot;:&quot;12s&quot;,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/5E9QOuop5lo?start=12s&amp;rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don&#8217;t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com. </p>]]></content:encoded></item><item><title><![CDATA[Daily Drop (1322) ]]></title><description><![CDATA[06-21-26]]></description><link>https://bragg.substack.com/p/daily-drop-1322</link><guid isPermaLink="false">https://bragg.substack.com/p/daily-drop-1322</guid><dc:creator><![CDATA[Bob Bragg]]></dc:creator><pubDate>Sun, 21 Jun 2026 18:12:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!46hn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83d8dfe9-fd80-4387-903f-554460f96e26_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Sunday, Jun 21, 2026 // <a href="https://buymeacoffee.com/infodom">Buy Bob a Coffee</a> // <a href="https://ghostwire.news">Ghostwire</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!46hn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83d8dfe9-fd80-4387-903f-554460f96e26_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!46hn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83d8dfe9-fd80-4387-903f-554460f96e26_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!46hn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83d8dfe9-fd80-4387-903f-554460f96e26_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!46hn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83d8dfe9-fd80-4387-903f-554460f96e26_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!46hn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83d8dfe9-fd80-4387-903f-554460f96e26_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!46hn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83d8dfe9-fd80-4387-903f-554460f96e26_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/83d8dfe9-fd80-4387-903f-554460f96e26_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3315136,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://bragg.substack.com/i/202978651?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83d8dfe9-fd80-4387-903f-554460f96e26_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!46hn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83d8dfe9-fd80-4387-903f-554460f96e26_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!46hn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83d8dfe9-fd80-4387-903f-554460f96e26_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!46hn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83d8dfe9-fd80-4387-903f-554460f96e26_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!46hn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83d8dfe9-fd80-4387-903f-554460f96e26_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>Pentagon Commits $1.2 Billion to Rare Earth Supply Chain as Defense Production Concerns Mount</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The Pentagon's Office of Strategic Capital (OSC) has signed two conditional loans totaling $1.225 billion to expand domestic rare earth processing and magnet production capabilities. Energy Fuels will receive a $725 million loan to develop a U.S.-based rare earth separation and metallization facility, while Phoenix Tailings secured $500 million for its planned "Freedom Facility." The investments are part of a broader Trump administration effort to reduce U.S. dependence on foreign critical mineral supply chains essential for defense production.</strong></p><p><strong>Analyst Comments:</strong> Rare earths, gallium, and germanium are foundational materials for modern military systems, including precision-guided munitions, fighter aircraft, radars, electronic warfare systems, and advanced semiconductors. The Pentagon is increasingly treating access to these materials as a strategic vulnerability on par with munitions production capacity itself. Michael Cadenazzi&#8217;s comment that weapons scaling is a &#8220;pipe dream&#8221; without critical minerals reflects growing concern that the defense industrial base cannot surge production during a major conflict if upstream supply chains remain concentrated overseas. China&#8217;s dominance in rare earth mining and processing has repeatedly exposed the fragility of Western supply chains and demonstrated how resource dependencies can become geopolitical leverage.</p><p><strong>READ THE STORY: </strong><a href="https://breakingdefense.com/2026/06/pentagon-inks-pair-of-rare-earth-mineral-loans-for-1-2-billion/">Breaking Defense</a></p><h1><strong>China's MSS Warns Foreign Intelligence Services Are Using Pop-Up Ads for Surveillance and Ideological Infiltration</strong></h1><p><em>NOTE: </em></p><p><em>A core stated goal is to recruit the public as counterintelligence eyes and ears. China has a citizen-reporting apparatus (hotlines, reward systems for reporting suspected spies), and these warnings function as a steady drumbeat reminding people that threats are everywhere and that vigilance is a civic duty. The MSS even runs public-facing channels&#8212;it opened a WeChat account in 2023 partly to push this kind of content.</em></p><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>China's Ministry of State Security (MSS) has warned that foreign intelligence agencies are allegedly exploiting online pop-up advertisements for intelligence collection, target identification, and ideological infiltration activities. According to the MSS, foreign services are collaborating with advertising companies to aggregate user data, social media information, and precise geolocation data to build detailed profiles of individuals inside China and deliver tailored influence content.</strong></p><p><strong>Analyst Comments:</strong> While the MSS statement should be viewed through the lens of China's broader information security and censorship policies, the underlying tradecraft described is technically plausible. Digital advertising ecosystems have long been scrutinized for their ability to collect granular behavioral data, including device identifiers, location information, browsing habits, and demographic profiles. Multiple governments and researchers have previously warned that advertising data can be leveraged for surveillance, influence operations, and intelligence targeting.</p><p><strong>READ THE STORY: </strong>GT (CN)</p><h1><strong>Trump Threatens Renewed Military Action Against Iran Amid Switzerland Negotiations</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>U.S. President Donald Trump threatened additional military action against Iran if Tehran does not restrain Hezbollah and other Iran-backed groups in Lebanon, warning that the United States would strike Iran "even harder" than previous operations. The comments come as Iran, the United States, Pakistan, and Qatar have launched mediated negotiations in Switzerland under a reported 60-day framework outlined in the 14-point Islamabad Memorandum of Understanding.</strong></p><p><strong>Analyst Comments:</strong> Trump's remarks underscore the fragile nature of the current diplomatic process. While negotiations are formally underway, Washington is simultaneously signaling that it remains prepared to use military pressure if it believes Iran is failing to curb the activities of its regional proxies. The messaging reflects a dual-track strategy of diplomacy backed by coercive leverage.</p><p><strong>READ THE STORY: </strong><a href="https://en.mehrnews.com/news/245504/US-president-threatens-Iran-amid-Siwtzerland-talks">MEHR</a></p><h1><strong>U.S. Disputes Iranian Claims of Strait of Hormuz Closure as Negotiators Convene in Switzerland</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>U.S. and Iranian negotiators are set to begin talks in Switzerland under a 60-day ceasefire framework, even as Washington disputes Iranian claims that the Strait of Hormuz has been closed. Iran's Islamic Revolutionary Guard Corps (IRGC) warned commercial vessels away from the waterway, citing Israeli operations in Lebanon, but U.S. Central Command reported that 55 merchant ships carrying more than 17 million barrels of oil transited the strait on Saturday. The conflicting narratives underscore the fragility of the ceasefire and the potential for renewed regional escalation.</strong></p><p><strong>Analyst Comments:</strong> The Strait of Hormuz remains one of the world&#8217;s most strategically important maritime chokepoints, and even disputed claims of its closure carry immediate geopolitical and economic implications. Tehran appears to be leveraging the threat of disrupting global energy flows as diplomatic pressure during negotiations, while Washington is signaling that freedom of navigation remains intact and enforceable. The talks are beginning against a backdrop of unresolved tensions in Lebanon, where Israeli and Hezbollah exchanges continue despite the ceasefire framework. Both sides are effectively negotiating while simultaneously maintaining coercive leverage. For Iran, the ability to threaten maritime disruption and proxy activity remains a bargaining chip. For the United States, demonstrating continued commercial transit through Hormuz and maintaining military presence serves as proof that Iranian pressure tactics have not materially altered regional realities.</p><p><strong>READ THE STORY: </strong><a href="https://archive.ph/d2LXB">Reuters</a></p><h1><strong>Israeli Airstrikes in Lebanon Raise Questions Over Ceasefire Durability</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Lebanese authorities report that Israeli airstrikes killed seven people and wounded one in eastern and southern Lebanon, marking another alleged violation of the recently established ceasefire framework tied to the June 18 Iran-U.S. memorandum. The strikes add pressure to an already fragile truce and risk complicating ongoing diplomatic negotiations between Washington and Tehran.</strong></p><p><strong>Analyst Comments:</strong> From a strategic perspective, Lebanon remains a critical pressure point in broader regional negotiations. Tehran has explicitly linked ceasefire compliance in Lebanon to the credibility of U.S. commitments under the memorandum, raising the possibility that sustained violence could spill over into the ongoing Switzerland talks. The risk is not necessarily an immediate collapse of diplomacy but rather a gradual erosion of trust that complicates efforts to address larger issues, including regional security arrangements and nuclear negotiations.</p><p><strong>READ THE STORY: </strong><a href="https://en.mehrnews.com/news/245486/Israel-continues-ceasefire-breaches-in-Lebanon">MEHR</a></p><h1><strong>Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM, Permanently Compromising Boot Chain Security</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers at Paradigm Shift have released usbliter8, a working exploit that achieves arbitrary code execution inside the SecureROM of Apple's A12 and A13 chips. Because the vulnerability resides in immutable BootROM code burned into silicon, it cannot be patched through software updates. The exploit requires physical access, DFU mode, and a dedicated RP2350-based USB device, but ultimately grants attackers privileged EL1 execution before Apple's signed boot chain loads, allowing unsigned iBoot images and temporary demotion of production security controls.</strong></p><p><strong>Analyst Comments:</strong> While the practical risk to average users remains low due to the physical access requirement, the implications for high-value targets, forensic workflows, and government environments are substantial. Once a BootROM vulnerability becomes public, it effectively becomes a permanent characteristic of every affected device. The exploit also reinforces an uncomfortable reality about hardware trust boundaries: some vulnerabilities simply cannot be patched. Organizations using A12- and A13-based devices in sensitive roles now face a hardware lifecycle problem rather than a vulnerability management problem. Device custody, physical access controls, and accelerated hardware refresh cycles become the primary mitigations.</p><p><strong>READ THE STORY: </strong><a href="https://thehackernews.com/2026/06/unpatchable-usbliter8-exploit-breaks.html">THN</a></p><h1><strong>AWS Launches Continuum and Context to Address AI Agent Security and Business Context Gaps</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Amazon Web Services (AWS) unveiled two new services&#8212;AWS Continuum and AWS Context&#8212;designed to make AI agents more secure and operationally reliable in enterprise environments. Continuum automates vulnerability discovery, validation, and remediation of AI-generated code, while Context provides agents with business knowledge through a shared knowledge graph to improve decision-making and reduce hallucinations. The announcements reflect growing industry concerns that AI-generated code and autonomous agents are evolving faster than traditional security and governance models can manage.</strong></p><p><strong>Analyst Comments:</strong> AWS is effectively acknowledging two of the biggest barriers to enterprise agent adoption: security and context. The company explicitly states that AI-powered threats and specialized models like Anthropic's Mythos can identify vulnerabilities and attack paths faster than traditional defensive workflows can respond. That is a significant admission from one of the world's largest cloud providers and reinforces a broader industry shift toward AI-assisted defensive automation.</p><p><strong>READ THE STORY: </strong><a href="https://the-decoder.com/aws-says-ai-agents-lack-business-context-and-security-launches-two-services-to-patch-the-gaps/">The Decoder</a></p><h1><strong>Virus vs. Worm: Why Understanding the Difference Still Matters for Defenders</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Although "virus" and "worm" are often used interchangeably, the distinction remains operationally important because propagation models dictate both defensive priorities and potential impact. Viruses require user interaction and a host file to spread, while worms are autonomous, self-replicating malware that can move across networks without user action. History shows that worm outbreaks such as SQL Slammer and WannaCry can escalate from initial compromise to global disruption in minutes or hours, often outpacing traditional response processes.</strong></p><p><strong>Analyst Comments:</strong> The propagation mechanism determines the blast radius. Viruses generally provide defenders with opportunities to interrupt the attack chain through user awareness, email filtering, and application controls because they rely on human interaction. Worms remove that dependency entirely. Once execution begins, they can spread at machine speed, turning unpatched vulnerabilities and flat networks into force multipliers.</p><p><strong>READ THE STORY: </strong><a href="https://latesthackingnews.com/2026/06/21/virus-vs-worm-why-it-matters/">LHN</a></p><h1><strong>FortiBleed Campaign Demonstrates How Cheap AI Infrastructure Has Democratized Supercomputing for Cybercriminals</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Hudson Rock's latest analysis of the FortiBleed campaign reveals that threat actors leveraged rented GPU infrastructure from decentralized cloud provider Vast.ai to conduct industrial-scale password cracking operations against compromised Fortinet devices. Using a 36-GPU cluster managed via Telegram and supported by AI-assisted tooling, the operators achieved hundreds of billions of hashes per second at an estimated cost of less than $350 per day, transforming credential attacks into a low-cost, highly scalable business model. The findings highlight how the AI compute boom has inadvertently lowered the barrier to entry for advanced cryptographic attacks and large-scale initial access operations.</strong></p><p><strong>Analyst Comments:</strong> Capabilities once reserved for nation-state intelligence services can now be rented on demand with a credit card. The commoditization of enterprise-grade GPU infrastructure has fundamentally changed the threat landscape by allowing financially motivated actors to perform computationally intensive attacks at negligible cost. FortiBleed demonstrates a modern cybercrime pipeline that is highly optimized and almost entirely automated. The operators reportedly used AI-assisted code editors to build management tools, Telegram bots to orchestrate GPU resources, Hashtopolis to distribute cracking workloads, and agentic penetration testing frameworks to automate internal reconnaissance. The attack chain reflects a mature, capital-efficient operating model rather than a technically novel exploit.</p><p><strong>READ THE STORY: </strong><a href="https://www.infostealers.com/article/supercomputing-on-a-credit-card-from-the-ai-rush-enabled-the-massive-fortibleed-campaign/">InfoStealers</a></p><h1><strong>Items of interest</strong></h1><h1><strong>Go Security Pitfalls Persist: GolangConf Presentation Highlights Injection, Request Smuggling, and Authentication Risks</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A presentation by MTS Web Services Application Security Engineer Georgy Fateev warns that Go&#8217;s simplicity and strong standard library do not inherently produce secure applications. Common vulnerabilities&#8212;including command injection, SQL injection, HTTP request smuggling, insecure logging, and authentication flaws&#8212;continue to affect production Go environments. The presentation emphasizes that secure development depends more on engineering discipline, testing, and security culture than on language choice.</strong></p><p><strong>Analyst Comments:</strong> The presentation&#8217;s emphasis on &#8220;never trust user input&#8221; remains highly relevant, as injection-based vulnerabilities continue to drive breaches despite decades of awareness. The recommendation to use reachability-based dependency analysis tools such as <code>govulncheck</code> is particularly noteworthy because it reduces alert fatigue by prioritizing vulnerabilities that are actually exploitable within an application&#8217;s code path. The discussion of HTTP request smuggling is also timely. Misconfigurations between reverse proxies and backend services remain a frequent source of high-impact vulnerabilities capable of enabling authentication bypass and request desynchronization attacks. Likewise, insecure logging practices continue to be an underappreciated source of credential exposure and compliance violations.</p><p><strong>READ THE STORY: </strong><a href="https://habr.com/ru/companies/oleg-bunin/articles/1048122/">HABR</a></p><h1><strong>The GO Situation Is CRAZY... (Video)</strong></h1><p><strong>FROM THE MEDIA: The video correctly identifies a real concern&#8212;software supply-chain attacks in the Go ecosystem</strong></p><div id="youtube2-EyO_SMl2YBk" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;EyO_SMl2YBk&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/EyO_SMl2YBk?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1><strong>What is LLM Distillation?(Video)</strong></h1><p><strong>FROM THE MEDIA: Welcome to another Software Architecture in Go/Golang video, in today's episode I'm discussing Security, specifically in the context of Dependencies, this is narrowed down to Standard Library Packages and Third Party Packages.</strong></p><div id="youtube2-5E9QOuop5lo" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;5E9QOuop5lo&quot;,&quot;startTime&quot;:&quot;12s&quot;,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/5E9QOuop5lo?start=12s&amp;rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don&#8217;t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com. </p>]]></content:encoded></item><item><title><![CDATA[Daily Drop (1321) ]]></title><description><![CDATA[06-20-26]]></description><link>https://bragg.substack.com/p/daily-drop-1321</link><guid isPermaLink="false">https://bragg.substack.com/p/daily-drop-1321</guid><dc:creator><![CDATA[Bob Bragg]]></dc:creator><pubDate>Sat, 20 Jun 2026 13:12:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!SnMw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bdd05f-874f-484f-b2a4-071fa7603785_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Saturday, Jun 20, 2026 // <a href="https://buymeacoffee.com/infodom">Buy Bob a Coffee</a> // <a href="https://ghostwire.news">Ghostwire</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SnMw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bdd05f-874f-484f-b2a4-071fa7603785_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SnMw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bdd05f-874f-484f-b2a4-071fa7603785_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!SnMw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bdd05f-874f-484f-b2a4-071fa7603785_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!SnMw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bdd05f-874f-484f-b2a4-071fa7603785_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!SnMw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bdd05f-874f-484f-b2a4-071fa7603785_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SnMw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bdd05f-874f-484f-b2a4-071fa7603785_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/51bdd05f-874f-484f-b2a4-071fa7603785_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3314129,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://bragg.substack.com/i/202832887?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bdd05f-874f-484f-b2a4-071fa7603785_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SnMw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bdd05f-874f-484f-b2a4-071fa7603785_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!SnMw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bdd05f-874f-484f-b2a4-071fa7603785_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!SnMw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bdd05f-874f-484f-b2a4-071fa7603785_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!SnMw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51bdd05f-874f-484f-b2a4-071fa7603785_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>Unit 42 Warns of Large-Scale Credential Attacks Targeting Fortinet, Sophos, and MSSQL Services</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Palo Alto Networks' Unit 42 has issued a threat brief on the ongoing FortiBleed campaign, a massive credential theft and password spraying operation targeting internet-exposed Fortinet SSL VPNs, Sophos devices, and MSSQL services. Threat actors are using previously compromised credentials and offline password cracking to build an expanding password corpus that enables persistent, high-privilege access across organizations worldwide. Unit 42 has also observed suspicious login activity in customer telemetry and is urging organizations to harden remote access services immediately.</strong></p><p><strong>Analyst Comments:</strong> The attackers are treating credentials as a renewable resource: stolen passwords are cracked, validated, and recycled into future password spraying operations, creating a compounding effect where each successful compromise fuels subsequent attacks. The mention of an Initial Access Broker (IAB) advertising harvested credentials on the Russian-language forum <strong>Exploit[.]in</strong> is noteworthy, although Unit 42 has not independently validated those claims. If accurate, it suggests the campaign is feeding into the broader cybercrime ecosystem, where compromised VPN and infrastructure credentials are sold to ransomware affiliates, espionage actors, and other threat groups.</p><p><strong>READ THE STORY: </strong><a href="https://unit42.paloaltonetworks.com/large-scale-credential-attacks/">Unit42</a></p><h1><strong>China-Linked FishMonger Ports SprySOCKS to Windows With Kernel-Level Stealth and Potential UEFI Bootkit Capability</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>ESET researchers have identified two previously undocumented Windows variants of the SprySOCKS backdoor, a malware family previously exclusive to Linux and attributed with high confidence to the China-linked FishMonger espionage group. The new variants, dubbed WIN_DRV and WIN_PLUS, target primarily government organizations in Honduras, Taiwan, Thailand, and Pakistan and significantly expand the group's cross-platform capabilities through kernel drivers, rootkit functionality, hidden network communications, and possible UEFI bootkit deployment.</strong></p><p><strong>Analyst Comments:</strong> The porting of SprySOCKS to Windows represents a notable evolution in FishMonger&#8217;s tooling and demonstrates continued investment in long-term espionage capabilities. The most concerning development is the WIN_DRV variant&#8217;s use of kernel drivers to hide processes, files, registry keys, and network connections while silently redirecting traffic to hidden backdoor ports. This is not commodity malware behavior; it is the kind of operational security typically associated with mature state-sponsored operators. The limited evidence suggesting potential exploitation of CVE-2023-24932 to deploy a UEFI bootkit is equally significant. UEFI-level persistence dramatically raises the cost and complexity of remediation, allowing attackers to survive reinstallation efforts and maintain long-term access to targeted networks. Even though ESET characterizes the evidence as limited, the possibility alone warrants attention from government and critical infrastructure defenders.</p><p><strong>READ THE STORY: </strong><a href="https://www.welivesecurity.com/pt/pesquisas/arsenal-do-fishmonger-atualizado-sprysocks-para-windows/">welivesecurity</a></p><h1><strong>Russia-Linked Hackers Breached NATO Networks; Evidence Remains Limited</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The Odessa Journal, citing Eastern Herald, reports that Russia-linked hackers allegedly bypassed NATO cyber defenses and gained access to restricted systems within several NATO member states. If accurate, the incident would represent a significant cyber espionage escalation. However, the report provides few technical details, no named victims, and no official NATO confirmation, making independent verification difficult.</strong></p><p><strong>Analyst Comments:</strong> The allegations align with established Russian cyber objectives of long-term intelligence collection and pre-positioning within sensitive networks. However, extraordinary claims of breaching protected NATO systems require substantial evidence. At present, the report should be treated as unverified intelligence reporting rather than a confirmed cyber incident.</p><p><strong>READ THE STORY: </strong><a href="https://odessa-journal.com/russia-linked-hackers-reportedly-bypass-nato-cyber-defenses-and-access-restricted-systems">The Odessa Journal</a></p><h1><strong>History Shows Why AI Export Controls Struggle: Mythos Ban Echoes Encryption and Spyware Failures</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The Trump administration&#8217;s emergency restriction on Anthropic&#8217;s Fable and Mythos models marks the first major attempt to apply traditional cyber export controls to frontier AI. History suggests such efforts rarely prevent the spread of dual-use technologies, instead creating compliance burdens, incentivizing workarounds, and potentially weakening domestic competitiveness while foreign capabilities continue to advance.</strong></p><p><strong>Analyst Comments:</strong> The Mythos ban is less about one model and more about whether governments can realistically contain software-based capabilities once they become strategically valuable. The U.S. tried this with strong encryption in the 1990s and with spyware exports under the Wassenaar Arrangement, with mixed to poor results. Encryption proliferated despite export restrictions, and spyware vendors routinely relocated to jurisdictions with weaker oversight. The same dynamics likely apply to AI. Frontier models are expensive to train, but capabilities diffuse quickly through talent movement, research publication, model distillation, and international competition. Restricting access to U.S. models may temporarily delay proliferation, but it is unlikely to stop determined state or commercial actors from achieving similar capabilities independently.</p><p><strong>READ THE STORY: </strong><a href="https://techcrunch.com/2026/06/19/encryption-spyware-and-now-mythos-history-shows-why-cyber-export-control-doesnt-work/">TC</a></p><h1><strong>ShinyHunters Leaks Madison Square Garden Data After Alleged June 5 Breach</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>ShinyHunters has published data allegedly stolen from Madison Square Garden, including customer communications and files referencing Knicks-related personalities, talent details, addresses, representative contacts, and risk labels. The leak appears tied to an extortion attempt after MSG allegedly declined to pay.</strong></p><p><strong>Analyst Comments:</strong> Talent rosters, contact details, pricing, internal classifications, and customer emails can be abused for phishing, impersonation, harassment, and social engineering. The Knicks&#8217; NBA Finals win likely increases media attention and attacker leverage, but the alleged breach date of June 5 suggests the compromise may have preceded the championship spotlight. ShinyHunters&#8217; involvement matters. The group has a history of high-profile data theft and extortion, so defenders should treat the leak as credible until disproven. MSG should assume exposed contacts may receive targeted phishing and fraud attempts using real internal data as lure material.</p><p><strong>READ THE STORY: </strong><a href="https://www.404media.co/hackers-publish-knicks-and-madison-square-garden-data-online/">404</a></p><h1><strong>Vidar Infostealer Bypasses Chrome ABE Protections Using APC Injection</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Vidar operators have developed a technique to bypass Google Chrome&#8217;s Application-Bound Encryption (ABE) by extracting the browser&#8217;s master decryption key from live memory. The malware uses process forking, memory scanning, and APC injection to execute decryption inside Chrome&#8217;s process context, allowing theft of cookies and stored credentials protected by ABE.</strong></p><p><strong>Analyst Comments:</strong> Chrome&#8217;s ABE raised the bar by preventing simple offline decryption of browser secrets, but Vidar sidesteps the control by moving into the browser&#8217;s runtime environment where the key can still be decrypted legitimately. The key point: this is not breaking Chrome encryption outright. It is abusing trusted Windows and browser process behavior to make Chrome decrypt its own protected material. That makes detection harder because the technique leans on legitimate APIs such as <code>NtCreateProcessEx</code>, <code>NtQueryVirtualMemory</code>, <code>NtReadVirtualMemory</code>, and APC queuing rather than noisy, traditional code injection.</p><p><strong>READ THE STORY: </strong><a href="https://gbhackers.com/vidar-infostealer-google-chromes-abe-encryption/">GBhackers</a></p><h1><strong>MDR Provider Response Times Vary Widely as Organizations Continue to Struggle With Threat Detection Speed</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A comparison of major Managed Detection and Response (MDR) providers found significant differences in mean time to respond (MTTR), with publicly reported response timelines ranging from six minutes to several days. The analysis, benchmarked against Verizon's 2025 Data Breach Investigations Report (DBIR), highlights a persistent industry challenge: organizations still take a median of 16 hours to detect active threats, allowing attackers substantial dwell time before containment measures begin.</strong></p><p><strong>Analyst Comments:</strong> Speed remains one of the most meaningful metrics in incident response because attacker success is largely determined by dwell time. Whether the threat is ransomware, credential theft, or data exfiltration, every additional hour of undetected access increases the likelihood of lateral movement, persistence, and broader business impact. However, MTTR figures should be interpreted cautiously. Vendors often measure response speed differently, and aggressive automation can improve response times at the expense of false positives. Conversely, analyst-driven investigations may take longer but provide more accurate containment decisions. The operational question for organizations is not simply who is fastest, but which response model aligns with their risk tolerance and staffing capabilities.</p><p><strong>READ THE STORY: </strong><a href="https://hackread.com/mdr-provider-comparison-discover-respond-threats/">HR</a></p><h1><strong>Malicious npm Packages Can Hijack Claude Code MCP and Steal Persistent OAuth Tokens</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Mitiga Labs demonstrated an attack chain that uses a malicious npm package to silently modify Claude Code's Model Context Protocol (MCP) configuration and redirect OAuth traffic through attacker-controlled infrastructure. The technique allows interception of persistent bearer and refresh tokens for SaaS platforms such as Jira, Confluence, and GitHub, potentially granting long-term access to enterprise environments. Anthropic acknowledged the report but classified it as out of scope because the attack requires initial code execution on the endpoint.</strong></p><p><strong>Analyst Comments:</strong> The initial compromise vector&#8212;a malicious npm package with a <code>postinstall</code> hook&#8212;is well understood. The innovation is what happens next: the attacker inherits the user&#8217;s trust posture, persistently rewrites MCP endpoints, and captures OAuth tokens that continue to appear legitimate to service providers. The most concerning aspect is attribution and detection. SaaS providers see a real user, valid OAuth tokens, and requests originating from Anthropic&#8217;s trusted egress infrastructure. Traditional indicators such as suspicious IP addresses, impossible travel, or invalid credentials are unlikely to trigger. The compromise lives entirely within local Claude Code configuration files, meaning organizations must shift toward configuration integrity monitoring and behavioral analytics.</p><p><strong>READ THE STORY: </strong><a href="https://cyberpress.org/exploit-claude-code-mcp/">CyberPress</a></p><h1><strong>Gravity SMTP Flaw Exposes API Keys on 100,000+ WordPress Sites; Mass Exploitation Already Underway</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Threat actors are actively exploiting a medium-severity information disclosure vulnerability in the Gravity SMTP WordPress plugin (CVE-2026-4020, CVSS 5.3), affecting approximately 100,000 websites. The flaw allows unauthenticated attackers to retrieve sensitive system information, including API keys, OAuth tokens, and detailed server configuration data through an exposed REST API endpoint. Wordfence has blocked more than 17 million exploitation attempts, with activity peaking at over four million requests in a single day.</strong></p><p><strong>Analyst Comments:</strong> Although CVE-2026-4020 carries only a medium CVSS score, its operational impact is potentially significant because it exposes live credentials rather than merely leaking metadata. This is a classic example of why information disclosure vulnerabilities are often underestimated. Exposed email service credentials could enable attackers to send phishing emails from trusted domains, conduct business email compromise (BEC) operations, or abuse email infrastructure for spam campaigns.</p><p><strong>READ THE STORY: </strong><a href="https://thehackernews.com/2026/06/hackers-exploit-gravity-smtp-wordpress.html">THN</a></p><h1><strong>FortiBleed Exposes Industrial-Scale Credential Spraying Against Fortinet VPNs Across 21,000+ Organizations</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers uncovered an exposed attacker infrastructure dubbed FortiBleed, revealing a massive credential-spraying operation targeting Fortinet SSL VPNs, Sophos portals, and MSSQL servers worldwide. The campaign conducted billions of login attempts, leveraged network sniffers and GPU-based password cracking, and allegedly compromised organizations across multiple countries. The findings underscore that internet-exposed VPN infrastructure remains a high-value target and that compromised credentials continue to be the primary initial access vector.</strong></p><p><strong>Analyst Comments:</strong> The reported scale is significant: more than 1.16 billion FortiGate login combinations and 2.1 billion MSSQL authentication attempts executed through highly parallelized tooling. The operation demonstrates how attackers increasingly treat credential theft and password spraying as a manufacturing process rather than a targeted intrusion activity. Perhaps the most concerning finding is the overlap between exposed FortiGate devices and existing compromise indicators. According to the report, 88% of sampled organizations appeared in breach or stealer-log datasets, and 38% had active infostealer infections. This reinforces a growing trend in intrusion operations: attackers correlate multiple sources of compromised credentials, replay VPN session cookies, and move rapidly from perimeter access to Active Directory compromise.</p><p><strong>READ THE STORY: </strong><a href="https://securityaffairs.com/193931/hacking/fortibleed-exposes-global-credential-spraying-operation.html">SA</a></p><h1><strong>AutoJack Exploit Chain Enables Zero-Click RCE Against Microsoft AutoGen Studio Browsing Agents</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers disclosed a critical exploit chain dubbed AutoJack that allows a single malicious web page to hijack Microsoft AutoGen Studio's browsing agent and execute arbitrary code on the host machine without user interaction beyond submitting a URL. The attack chains three vulnerabilities in AutoGen Studio's Model Context Protocol (MCP) WebSocket implementation to bypass localhost protections, evade authentication, and achieve OS command execution. Developers building from source are most at risk, while the vulnerable MCP surface was reportedly never shipped in the current PyPI release (</strong><code>autogenstudio 0.4.2.2</code><strong>).</strong></p><p><strong>Analyst Comments:</strong> AutoJack is an early example of a new class of vulnerabilities emerging in AI agent frameworks: <strong>agent-mediated localhost compromise</strong>. Traditionally, localhost has been treated as a trusted security boundary because external websites cannot directly access services running on <code>127.0.0.1</code>. AI browsing agents fundamentally change that assumption. The exploit is notable because it requires neither phishing attachments nor user approval prompts. Instead, the AI agent becomes the attacker&#8217;s proxy. Once the agent renders malicious content, its inherited localhost identity allows attacker-controlled JavaScript to communicate with privileged local services that were never designed to face hostile web content.</p><p><strong>READ THE STORY: </strong><a href="https://ghostwire.news/article/gbhackers-189866">Ghostwire</a></p><h1><strong>Texas TPWD Vendor Breach Exposes 3 Million Customer Records</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A third-party vendor breach affecting the Texas Parks and Wildlife Department exposed personal records for 3,087,721 customers. The stolen data includes driver&#8217;s license details, passport numbers where provided, emails, phone numbers, and residential addresses. TPWD says Social Security numbers, dates of birth, and credit card data were not compromised.</strong></p><p><strong>Analyst Comments:</strong> Driver&#8217;s license data, addresses, phone numbers, and email addresses are more than enough for convincing impersonation, account recovery abuse, and targeted scams posing as TPWD, license vendors, law enforcement, or state agencies. The vendor angle matters. TPWD did not need to be directly breached for millions of customers to be exposed, which is exactly why third-party access and data retention deserve hard scrutiny. Hunters, anglers, and TPWD employees who used the same licensing systems should expect follow-on phishing attempts.</p><p><strong>READ THE STORY: </strong><a href="https://ghostwire.news/article/gbhackers-189889">GBhackers</a></p><h1><strong>Items of interest</strong></h1><h1><strong>Go Security Pitfalls Persist: GolangConf Presentation Highlights Injection, Request Smuggling, and Authentication Risks</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A presentation by MTS Web Services Application Security Engineer Georgy Fateev warns that Go&#8217;s simplicity and strong standard library do not inherently produce secure applications. Common vulnerabilities&#8212;including command injection, SQL injection, HTTP request smuggling, insecure logging, and authentication flaws&#8212;continue to affect production Go environments. The presentation emphasizes that secure development depends more on engineering discipline, testing, and security culture than on language choice.</strong></p><p><strong>Analyst Comments:</strong> The presentation&#8217;s emphasis on &#8220;never trust user input&#8221; remains highly relevant, as injection-based vulnerabilities continue to drive breaches despite decades of awareness. The recommendation to use reachability-based dependency analysis tools such as <code>govulncheck</code> is particularly noteworthy because it reduces alert fatigue by prioritizing vulnerabilities that are actually exploitable within an application&#8217;s code path. The discussion of HTTP request smuggling is also timely. Misconfigurations between reverse proxies and backend services remain a frequent source of high-impact vulnerabilities capable of enabling authentication bypass and request desynchronization attacks. Likewise, insecure logging practices continue to be an underappreciated source of credential exposure and compliance violations.</p><p><strong>READ THE STORY: </strong><a href="https://habr.com/ru/companies/oleg-bunin/articles/1048122/">HABR</a></p><h1><strong>The GO Situation Is CRAZY... (Video)</strong></h1><p><strong>FROM THE MEDIA: The video correctly identifies a real concern&#8212;software supply-chain attacks in the Go ecosystem</strong></p><div id="youtube2-EyO_SMl2YBk" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;EyO_SMl2YBk&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/EyO_SMl2YBk?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1><strong>What is LLM Distillation?(Video)</strong></h1><p><strong>FROM THE MEDIA: Welcome to another Software Architecture in Go/Golang video, in today's episode I'm discussing Security, specifically in the context of Dependencies, this is narrowed down to Standard Library Packages and Third Party Packages.</strong></p><div id="youtube2-5E9QOuop5lo" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;5E9QOuop5lo&quot;,&quot;startTime&quot;:&quot;12s&quot;,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/5E9QOuop5lo?start=12s&amp;rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don&#8217;t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com. </p>]]></content:encoded></item><item><title><![CDATA[Daily Drop (1320) ]]></title><description><![CDATA[06-19-26]]></description><link>https://bragg.substack.com/p/daily-drop-1320</link><guid isPermaLink="false">https://bragg.substack.com/p/daily-drop-1320</guid><dc:creator><![CDATA[Bob Bragg]]></dc:creator><pubDate>Fri, 19 Jun 2026 11:38:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Uq__!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F123d032d-baba-4b49-9238-2d124d2fdb7a_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Friday, Jun 19, 2026 // <a href="https://buymeacoffee.com/infodom">Buy Bob a Coffee</a> // <a href="https://ghostwire.news">Ghostwire</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Uq__!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F123d032d-baba-4b49-9238-2d124d2fdb7a_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Uq__!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F123d032d-baba-4b49-9238-2d124d2fdb7a_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Uq__!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F123d032d-baba-4b49-9238-2d124d2fdb7a_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Uq__!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F123d032d-baba-4b49-9238-2d124d2fdb7a_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Uq__!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F123d032d-baba-4b49-9238-2d124d2fdb7a_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Uq__!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F123d032d-baba-4b49-9238-2d124d2fdb7a_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/123d032d-baba-4b49-9238-2d124d2fdb7a_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3336224,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://bragg.substack.com/i/202697204?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F123d032d-baba-4b49-9238-2d124d2fdb7a_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Uq__!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F123d032d-baba-4b49-9238-2d124d2fdb7a_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Uq__!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F123d032d-baba-4b49-9238-2d124d2fdb7a_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Uq__!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F123d032d-baba-4b49-9238-2d124d2fdb7a_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Uq__!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F123d032d-baba-4b49-9238-2d124d2fdb7a_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>China Issues New Network Data Security Risk Assessment Rules: Annual Assessments Required for Important Data Processors</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>China's Cyberspace Administration (CAC), Ministry of Industry and Information Technology (MIIT), and Ministry of Public Security (MPS) jointly issued the Measures for Risk Assessment of Network Data Security (&#32593;&#32476;&#25968;&#25454;&#23433;&#20840;&#39118;&#38505;&#35780;&#20272;&#21150;&#27861;) on June 18, 2026, with implementation beginning August 20, 2026. The measures establish a nationwide framework for network data security risk assessments, mandate annual risk assessments for processors of important data, and grant regulators expanded authority to inspect assessments, order remediation, and suspend important data processing activities that pose risks to national security or the public interest.</strong></p><p><strong>Analyst Comments:</strong> According to the Cyberspace Administration of China, all network data security risk assessments conducted within China must comply with the new measures beginning August 20, 2026. The rules require important data processors to conduct annual risk assessments, with additional assessments required whenever significant security changes occur. Organizations processing general data are encouraged to conduct assessments at least every three years. Risk assessments may be performed internally or by third-party assessment agencies, which are encouraged to obtain official certification and must promptly notify organizations of significant data security risks. Relevant government authorities may inspect assessment reports, require the use of certified assessors, and order rectification or suspension of important data processing activities if national security or public interests are at risk.</p><p><strong>READ THE STORY: </strong><a href="https://www.cac.gov.cn/2026-06/18/c_1783525609778371.htm">CAC.GOV.CN</a></p><h1><strong>Bulgaria Licensed Surveillance Exports to Rights Violators Despite EU Human Rights Safeguards</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Human Rights Watch revealed that Bulgaria approved export licenses between 2018 and 2023 for commercial surveillance technologies destined for countries with documented histories of using spyware and interception tools against journalists, activists, and political dissidents. The licenses involved products from Bulgarian-based surveillance firm Circles, raising renewed concerns that EU export controls for dual-use cyber capabilities are failing to prevent technologies from reaching authoritarian governments.</strong></p><p><strong>Analyst Comments:</strong> This is another example of the persistent gap between cyber export regulations and their enforcement. The issue is not whether surveillance technology can be abused&#8212;that has been demonstrated repeatedly with NSO Group, Intellexa, and similar vendors. The concern is that European governments continue approving exports to destinations with established records of digital repression while maintaining that adequate due diligence was performed.</p><p><strong>READ THE STORY:</strong> <a href="https://www.hrw.org/news/2026/06/18/bulgaria-licensed-surveillance-exports-to-rights-violators">HRW</a> // <a href="https://therecord.media/bulgaria-allowed-surveillance-tech-firm-to-sell-to-repressive-regimes-report">The Record</a></p><h1><strong>UK Cyber Chief Warns Hostile States Behind Majority of Critical Infrastructure Attacks</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The UK&#8217;s National Cyber Security Centre (NCSC) says approximately 75% of cyber incidents affecting British critical national infrastructure (CNI) are linked to hostile states. NCSC Director Richard Horne warned that adversaries are increasingly prepositioning inside critical infrastructure networks, establishing footholds that could be leveraged for disruptive operations during future geopolitical crises or conflicts. The warning comes as the UK advances new cyber resilience legislation and prepares for AI-driven increases in attacks against aging infrastructure.</strong></p><p><strong>Analyst Comments:</strong> The NCSC is effectively saying that many nation-state actors are no longer focused solely on espionage. They are establishing persistent access within critical infrastructure environments, creating options for future disruption if geopolitical tensions escalate. The reference to Volt Typhoon is particularly telling. That campaign demonstrated how state-linked actors can quietly embed themselves within critical systems for extended periods, avoiding immediate disruption while preserving operational access for future contingencies. The same playbook is increasingly being observed globally: gain access, establish persistence, remain dormant, and wait for strategic utility.</p><p><strong>READ THE STORY: </strong><a href="https://cisowhisperer.com/hostile-states-behind-most-attacks-on-uk-critical-infrastructure/?utm_source=rss#038;utm_medium=rss&amp;#038;utm_campaign=hostile-states-behind-most-attacks-on-uk-critical-infrastructure">CISO Whisper</a></p><h1><strong>Critical Oracle Solaris Vulnerabilities Include CVSS 10.0 Flaw in Remote Administration Daemon</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The Cyber Security Agency of Singapore (CSA) has warned of multiple vulnerabilities affecting Oracle Solaris 11.4, including CVE-2026-46978, a critical CVSS 10.0 vulnerability in the Remote Administration Daemon (RAD) that can be exploited remotely over HTTPS by an unauthenticated attacker. Additional flaws in the Filesystem and Libraries components could allow low-privileged attackers to access sensitive data and cause denial-of-service conditions. Organizations running Oracle Solaris 11.4 should prioritize patching immediately.</strong></p><p><strong>Analyst Comments:</strong> While Oracle Solaris has a smaller market share than Linux and Windows, it remains widely deployed in telecommunications, financial services, government, and legacy enterprise environments, where systems often support high-value applications and may not be patched as quickly as mainstream platforms. These environments can also have extended maintenance windows, creating opportunities for threat actors to target unpatched systems.</p><p><strong>READ THE STORY: </strong><a href="https://www.cac.gov.cn/2026-06/18/c_1783525609778371.htm">CAC.GOV.CN</a></p><h1><strong>Fortinet Confirms Active Exploitation of Critical FortiSandbox Flaws: Unauthenticated RCE and Privilege Escalation Under Attack</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Threat intelligence firm Defused reports active exploitation of multiple critical vulnerabilities affecting Fortinet FortiSandbox, including CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. The vulnerabilities allow unauthenticated attackers to perform remote code execution (RCE) and privilege escalation through low-complexity command injection attacks requiring no user interaction. Organizations running vulnerable FortiSandbox deployments should treat this as an immediate patching priority.</strong></p><p><strong>Analyst Comments:</strong> The most concerning aspect is the attack chain's accessibility: no authentication, low complexity, and no user interaction required. Those characteristics make these vulnerabilities highly attractive for mass exploitation campaigns and rapid weaponization. Defused has already observed exploitation attempts against CVE-2026-39813 and CVE-2026-39808, while activity involving CVE-2026-25089 appears to involve potentially faulty or incomplete exploit code, suggesting attackers are actively experimenting with exploitation techniques.</p><p><strong>READ THE STORY: </strong><a href="https://www.bleepingcomputer.com/news/security/critical-fortinet-fortisandbox-flaws-now-exploited-in-attacks/">Bleeping Computer</a></p><h1><strong>Cisco Patches Exploited SD-WAN Zero-Day Allowing Root-Level Privilege Escalation</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Cisco patched CVE-2026-20262, a zero-day vulnerability in Catalyst SD-WAN Manager that has already been exploited in limited real-world attacks. The flaw lets an authenticated attacker with write access send crafted HTTP requests to a vulnerable API, create or overwrite arbitrary files, and potentially escalate privileges to root.</strong></p><p><strong>Analyst Comments:</strong> Compromise of that console can give attackers broad visibility and influence over routing, device management, and enterprise connectivity. The bug does require a valid account, but that should not make defenders comfortable. In real intrusions, attackers often obtain credentials first and then use flaws like this to escalate access and fully take over management infrastructure. Cisco SD-WAN has also had repeated exploitation this year, which means attackers are clearly paying attention to this product line.</p><p><strong>READ THE STORY: </strong><a href="https://ghostwire.news/article/xakep-https:%2F%2Fxakep.ru%2F2026%2F06%2F19%2Fsd-wan-patch%2F">Xakep</a> (RU)</p><h1><strong>Critical Splunk AI Toolkit Vulnerability Enables OS Command Execution: CVE-2026-20266 Earns CVSS 9.1</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Splunk disclosed a critical OS command injection vulnerability (CVE-2026-20266) affecting all versions of the Splunk AI Toolkit prior to v5.7.4. The flaw, rated CVSS 9.1, allows authenticated administrators to execute arbitrary system commands on the underlying host, potentially leading to full compromise of Splunk environments and broader enterprise security infrastructure. The vulnerability resides within the AI Toolkit&#8217;s btool configuration helper, highlighting the growing security risks introduced by AI-enabled enterprise components.</strong></p><p><strong>Analyst Comments:</strong> Administrative accounts for SIEM platforms are among the most sought-after targets in an attack chain because they provide visibility into and control over an organization&#8217;s entire security apparatus. The more concerning aspect is where the vulnerability resides: an AI component rather than the core platform. As vendors rapidly integrate LLMs, copilots, and autonomous agents into security products, they are expanding the attack surface with components that frequently execute scripts, invoke external tools, and interact with high-privilege system resources. CVE-2026-20266 demonstrates that traditional vulnerabilities such as command injection have not disappeared&#8212;they have simply migrated into AI-enabled functionality.</p><p><strong>READ THE STORY: </strong><a href="https://www.anquanke.com/post/id/315618">Anquanke</a></p><h1><strong>Novo Nordisk Breach Highlights Software Supply Chain Risk: Single GitHub Token Led to Alleged 1.3TB Data Theft</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Pharmaceutical giant Novo Nordisk disclosed a cyber incident after attackers reportedly gained initial access using a single exposed GitHub personal access token. Threat group FulcrumSec claims it spent more than two months inside the company&#8217;s environment, exfiltrating approximately 700,000 files totaling 1.3TB, including source code, clinical research data, proprietary drug information, manufacturing records, and internal AI models. The incident underscores how exposed machine credentials and development environments have become prime targets for software supply chain attacks.</strong></p><p><strong>Analyst Comments:</strong> The attackers did not exploit a zero-day or bypass sophisticated defenses&#8212;they reportedly found a high-privileged GitHub token embedded in client-side JavaScript, authenticated as a trusted user, and pivoted from there. Development environments are now among the highest-value targets in an organization. Source repositories contain far more than code; they often include infrastructure definitions, deployment pipelines, API credentials, and documentation that effectively serves as a roadmap to the enterprise. Once an attacker gains authenticated access to a repository, traditional security controls such as code reviews and branch protections become largely irrelevant.</p><p><strong>READ THE STORY: </strong><a href="https://www.darkreading.com/cyber-risk/novo-nordisk-breach-exposes-dev-pipeline-risk">DR</a></p><h1><strong>Miasma Supply Chain Worm Compromises 73 Microsoft Repositories, Targets AI Coding Tools and Developer Credentials</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A variant of the Miasma (Mini Shai-Hulud) supply chain worm compromised 73 Microsoft GitHub repositories, primarily within the Azure organization, temporarily disrupting CI/CD pipelines worldwide and exposing a new attack vector aimed at AI-assisted development tools. The malware targeted credentials associated with Claude Code, Gemini CLI, Cursor, and Visual Studio Code, using malicious configuration files to automatically execute payloads when developers opened compromised repositories. The incident highlights how threat actors are increasingly exploiting trusted development environments and AI coding ecosystems as software supply chain attack surfaces.</strong></p><p><strong>Analyst Comments:</strong> Previous supply chain compromises largely focused on package registries like npm and PyPI. Miasma deliberately bypassed those controls and moved to a less-monitored surface: configuration files used by AI coding agents and developer tooling. The attackers did not need to modify source code or poison package dependencies. Instead, they weaponized trust relationships between developers and AI-assisted coding environments. Once a compromised repository was opened in an affected IDE or AI coding tool, credentials could be harvested automatically and used to propagate the worm further. That&#8217;s a dangerous shift because most organizations have not yet built security controls around AI coding agent configurations.</p><p><strong>READ THE STORY: </strong><a href="https://ghostwire.news/article/darkreading-https:%2F%2Fwww.darkreading.com%2Fapplication-security%2Fmiasma-supply-chain-worm-73-microsoft-repositories">DR</a></p><h1><strong>Klue OAuth Breach Fuels &#8216;Icarus&#8217; Extortion Campaign: Stolen Tokens Used to Exfiltrate Salesforce Data</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Market intelligence platform Klue suffered a breach that allowed threat actors associated with the emerging Icarus extortion group to steal OAuth tokens and access Salesforce environments belonging to multiple customers. Attackers used compromised service accounts and stolen OAuth credentials to systematically query and exfiltrate CRM data, leading Salesforce to disable the Klue Battlecards integration while the investigation continues.</strong></p><p><strong>Analyst Comments:</strong> Once an attacker obtains a valid OAuth token, they effectively inherit the permissions of the application integration and can operate as a trusted service. The attack also reinforces the growing risk posed by third-party SaaS integrations. Organizations tend to focus security efforts on user accounts while overlooking service-to-service trust relationships. In this case, attackers reportedly compromised Klue&#8217;s backend environment, deployed malicious code to harvest customer tokens, and then directly accessed connected Salesforce environments without needing to breach each customer individually.</p><p><strong>READ THE STORY: </strong><a href="https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/">Bleeping Computer</a></p><h1><strong>Salesforce Disables Klue Integration After OAuth Token Theft Enables Customer Data Breaches</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Salesforce has disabled the Klue Battlecards integration after threat actors compromised Klue&#8217;s infrastructure, stole customer OAuth tokens, and accessed Salesforce environments belonging to multiple organizations. The campaign, attributed to the emerging Icarus extortion group, resulted in the exfiltration of CRM data, including business contacts, price quotes, and sales communications. The incident highlights the growing security risks posed by third-party SaaS integrations and non-human identities.</strong></p><p><strong>Analyst Comments:</strong> Once attackers obtained Klue&#8217;s OAuth tokens, they were able to operate as trusted integrations and directly query customer Salesforce environments without exploiting any vulnerability in Salesforce itself. The attack also demonstrates the dangers of legacy credentials and forgotten integrations. According to Klue and Huntress, the initial compromise stemmed from a long-unused but still active credential created for a prototype integration that was later abandoned. This is a recurring issue in cloud environments: organizations frequently decommission applications but fail to retire associated service accounts, API keys, and OAuth credentials.</p><p><strong>READ THE STORY: </strong><a href="https://thehackernews.com/2026/06/salesforce-disables-klue-app.html">THN</a></p><h1><strong>Hive0117 Targets Accountants in Russia and CIS With DarkWatchman Malware</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The Hive0117 group is running a renewed phishing campaign against accountants in Russia and CIS countries, using password-protected RAR archives to deliver DarkWatchman malware. Once inside, attackers steal banking access, monitor cryptographic token use, deploy remote access tools, and abuse corporate remote banking systems to move funds through fake payroll registries.</strong></p><p><strong>Analyst Comments:</strong> Accountants are the right target because they sit closest to payment workflows, banking portals, and hardware or cryptographic tokens used for corporate transfers. The use of payroll registries is the key shift. Instead of obvious one-off transfers, attackers are blending theft into normal salary-payment activity, which may evade weaker fraud checks. DarkWatchman&#8217;s fileless behavior, keylogging, clipboard monitoring, and token tracking also make it well suited for quietly waiting until the victim connects banking credentials or signing devices.</p><p><strong>READ THE STORY: </strong><a href="https://xakep.ru/2026/06/19/hive0117-attacks/">Xakep (RU)</a></p><h1><strong>Microsoft Uncovers &#8216;Crypto Clipper&#8217; Worm: USB-Propagated Malware Steals Crypto Wallets and Uses Tor for Stealth</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Microsoft has identified a new self-propagating malware family, dubbed Crypto Clipper, that spreads via infected USB drives, steals cryptocurrency wallet credentials and seed phrases, and communicates with attacker infrastructure over Tor. The malware combines clipboard hijacking, screenshot capture, and remote code execution (RCE), effectively functioning as both a cryptocurrency stealer and a lightweight backdoor capable of maintaining persistent access to compromised systems.</strong></p><p><strong>Analyst Comments:</strong> Crypto Clipper is notable because it blends old-school worm propagation techniques with modern operational security. USB-based malware has largely fallen out of favor in enterprise environments, but it remains effective in air-gapped networks, industrial environments, and organizations with poor removable media controls. The use of a portable Tor client and local SOCKS5 proxy eliminates the need for traditional command-and-control (C2) infrastructure, complicating detection and attribution efforts.</p><p><strong>READ THE STORY:</strong> <a href="https://arstechnica.com/security/2026/06/microsoft-spots-new-self-propagating-malware-for-stealing-cryptocurrency/">arsTECHNICA</a></p><h1><strong>China Issues Warning on &#8216;VoidLink&#8217; Malware: Advanced Linux Threat Targets Cloud and Container Environments</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>China's Ministry of Industry and Information Technology (MIIT), through its Cybersecurity Threat and Vulnerability Information Sharing Platform (CSTIS), issued a warning regarding VoidLink, a highly modular malware framework targeting Linux servers in cloud and container environments. First observed in late 2025, VoidLink leverages supply chain compromise, cloud misconfigurations, and container escape techniques to gain initial access, while employing kernel-level rootkit capabilities and multi-channel command-and-control (C2) communications to establish stealthy, persistent control over compromised systems.</strong></p><p><strong>Analyst Comments:</strong> VoidLink exhibits characteristics increasingly associated with modern cloud-focused advanced threats: environment awareness, modular architecture, rootkit-based stealth, and resilient C2 mechanisms. While public attribution remains unavailable, the tradecraft described by CSTIS suggests a mature threat actor with significant expertise in Linux internals and cloud-native infrastructure. The malware's initial access methods are particularly concerning because they exploit issues many organizations still struggle to address&#8212;unsigned container images, leaked credentials, and software supply chain contamination. These weaknesses continue to represent some of the most effective attack paths into cloud environments because they bypass traditional perimeter controls and exploit trusted workflows.</p><p><strong>READ THE STORY: </strong><a href="https://news.cnr.cn/native/gd/20260615/t20260615_527661986.shtml">CNR</a> (CN)</p><h1><strong>Steam Workshop Malware Campaign Uses Wallpaper Engine to Steal Accounts and Deploy Backdoors</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Attackers are abusing Wallpaper Engine and the Steam Workshop to distribute malicious wallpapers disguised as images of attractive women, game themes, and utility tools. The campaign, first observed in late 2025 and documented by Kaspersky, uses malicious EXEs, DLLs, scripts, and encrypted archives to install backdoors that steal Steam credentials and, in some cases, deploy cryptocurrency miners. Victims are overwhelmingly concentrated in China (89%), with additional infections reported in Russia and other regions.</strong></p><p><strong>Analyst Comments:</strong> The use of Wallpaper Engine is particularly effective because it occupies a trusted position within the Steam ecosystem and supports community-generated content. Users often assume that content hosted on Steam Workshop has undergone some level of vetting, lowering their guard when downloading and executing files. The attackers further increase success rates by using borderline or suggestive content as lures, exploiting curiosity and reducing user scrutiny. The campaign&#8217;s persistence mechanism is also noteworthy. Stolen Steam accounts are allegedly used to publish additional malicious Workshop content, creating a self-sustaining distribution ecosystem. Even if individual accounts are banned, compromised accounts can continue propagating malicious themes and harvesting additional victims.</p><p><strong>READ THE STORY: </strong><a href="https://www.t00ls.com/articles-75281.html">Tools</a> (CN)</p><h1><strong>Operation Endgame Disrupts SocGholish Malware Network Tied to Evil Corp Ransomware Operations</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>International law enforcement agencies have disrupted the SocGholish malware infrastructure as part of Operation Endgame, remediating approximately 15,000 compromised websites and dismantling portions of a botnet frequently used by the Russia-based cybercrime group Evil Corp. Authorities also seized 106 servers and domains associated with the operation, targeting one of the most prolific malware delivery mechanisms used to facilitate ransomware and other cyberattacks.</strong></p><p><strong>Analyst Comments:</strong> This takedown is significant because SocGholish is not merely another malware family&#8212;it is a malware distribution service that has repeatedly served as an initial access mechanism for ransomware operators, including Evil Corp. By compromising legitimate WordPress sites and using fake browser or software update prompts, SocGholish has been able to infect users at scale and provide downstream access to a variety of criminal groups. The operation demonstrates a growing trend in law enforcement strategy: targeting cybercrime enablers rather than focusing solely on ransomware payloads themselves. Disrupting malware distribution infrastructure can have a multiplier effect, depriving multiple threat actors of a reliable initial access channel.</p><p><strong>READ THE STORY: </strong><a href="https://www.infosecurity-magazine.com/news/operation-endgame-socgholish-evil/">INFO MAG</a></p><h1><strong>Sohu Publishes Profile of China's Most Influential Early Hackers and Patriotic Hacking Figures</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A Sohu article revisits the history of China's early hacker community, profiling many of the country's most prominent first-generation hackers and founders of influential groups such as the Green Army, China Hacker Alliance, China Eagle Alliance, and Red Hacker Alliance. The article highlights individuals associated with the 1999&#8211;2001 era of patriotic hacking, including participants in the 2001 Sino-U.S. hacker conflict, and details their subsequent transitions into cybersecurity consulting, government support roles, and commercial security leadership positions.</strong></p><p><strong>Analyst Comments:</strong> The Sohu article profiles numerous well-known figures from China's early hacker scene, including KING (Tan Xuwu), founder of the China Hacker Alliance and a participant in the 2001 Sino-U.S. hacker conflict; goodwell (Gong Wei) and coldface (Zhou Shuai) of the Green Army; chinaeagle (Wan Tao), founder of the China Eagle Alliance; and Lion (Lin Yong), founder of the Red Hacker Alliance. The article describes many of these individuals as pioneers in network security research, exploit development, Unix and Linux security, vulnerability research, and anti-intrusion technologies. Several are noted as later serving as consultants to government agencies, public security organizations, and cybersecurity companies.</p><p><strong>READ THE STORY: </strong><a href="https://cul.sohu.com/a/971906028_122508998">Sohu</a> (CN)</p><h1><strong>Kanxue Highlights Evidence-Driven Mobile Security: Single Indicators Insufficient for Android and iOS Trust Decisions</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Kanxue (&#30475;&#38634;) Security Community argues that mobile application security should be built around evidence-based trust models rather than relying on single indicators such as app signature verification, bootloader status, or App Attest results. The paper advocates for collecting and correlating runtime evidence, device posture, server-side verification, and application integrity signals to make risk decisions across Android and iOS environments.</strong></p><p><strong>Analyst Comments:</strong> Many mobile security controls still rely heavily on single signals&#8212;such as whether an APK signature validates, whether a device is rooted, or whether App Attest succeeds. The authors argue these approaches create blind spots because attackers can patch individual controls or manipulate isolated trust indicators. Instead, the article proposes building chains of evidence that combine package lineage, runtime behavior, attestation status, device configuration, and backend verification. The emphasis on server-side interpretation is particularly notable. The paper repeatedly stresses that mobile applications should report evidence, while final business decisions&#8212;such as permitting logins, payments, or data exports&#8212;should remain on the backend to avoid creating fixed patch points or exposing sensitive verification logic.</p><p><strong>READ THE STORY: </strong><a href="https://bbs.kanxue.com/thread-291702.htm">Kanxue</a></p><h1><strong>Items of interest</strong></h1><h1><strong>AI-Powered Cyberattacks Outpace Traditional Defenses as Security Vendors Shift Toward Small, Specialized Models</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>AI is dramatically accelerating cyber offense, reducing attack timelines from days to minutes and enabling threat actors to automate vulnerability discovery, malware generation, and credential attacks at unprecedented scale. In response, NSFOCUS is advocating and actively developing a hybrid AI defense architecture that combines frontier models with smaller, specialized models capable of operating at the edge, arguing that large general-purpose models alone cannot meet the speed, cost, and deployment requirements of modern cybersecurity operations.</strong></p><p><strong>Analyst Comments:</strong> While much of the market narrative centers on deploying ever-larger security models, NSFOCUS is positioning itself around a different thesis&#8212;that effective cyber defense will require an ecosystem of specialized small models working in conjunction with larger reasoning engines. The company says it is continuously designing and deploying small, scenario-specific models that filter legitimate traffic, establish customer-specific behavioral baselines, and escalate only uncertain events for deeper analysis by larger models. This architecture mirrors a teacher-student model increasingly seen across the industry, where frontier models provide reasoning capabilities while distilled, task-specific models perform frontline detection and triage. The approach also addresses operational realities such as latency requirements, data residency restrictions, and the high costs of processing massive volumes of benign traffic. Despite advances in automation, NSFOCUS emphasizes that human expertise remains indispensable for managing false positives, handling edge cases, and making strategic decisions in rapidly evolving threat environments.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://blog.nsfocus.net/%E8%B5%9B%E5%8D%9A%E6%97%A0%E9%97%B4%E9%81%93%EF%BC%9Aai%E6%97%B6%E4%BB%A3%E7%9A%84%E7%BD%91%E7%BB%9C%E6%94%BB%E9%98%B2%E6%88%98/">NSFOCUS</a></strong></p><h1><strong>Knowledge Distillation: How LLMs train each other (Video)</strong></h1><p><strong>FROM THE MEDIA: In this video, we break down knowledge distillation, the technique that powers models like Gemma 3, LLaMA 4 Scout &amp; Maverick, and DeepSeek-R1. Distillation was prominently discussed at LlamaCon 2025.</strong></p><div id="youtube2-jrJKRYAdh7I" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;jrJKRYAdh7I&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/jrJKRYAdh7I?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1><strong>What is LLM Distillation?(Video)</strong></h1><p><strong>FROM THE MEDIA: What is LLM Distillation ? Large Language Model (LLM) Distillation is revolutionizing how we make AI models smaller, faster, and more efficient&#8212;without losing their power! In this video, we&#8217;ll break down what LLM distillation is, why it matters, and how it works. You&#8217;ll learn how researchers take massive AI models, like GPT and LLaMA, and distill their knowledge into lighter, more cost-effective versions that can run efficiently on edge devices and enterprise applications.</strong></p><div id="youtube2-h7DUpHPasME" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;h7DUpHPasME&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/h7DUpHPasME?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don&#8217;t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com. </p>]]></content:encoded></item><item><title><![CDATA[Daily Drop (1319) ]]></title><description><![CDATA[06-16-26]]></description><link>https://bragg.substack.com/p/daily-drop-1319</link><guid isPermaLink="false">https://bragg.substack.com/p/daily-drop-1319</guid><dc:creator><![CDATA[Bob Bragg]]></dc:creator><pubDate>Wed, 17 Jun 2026 01:14:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!umSj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcae8b2-8772-4bbf-983f-8d245ec1d791_1402x1122.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Tuesday, Jun 16, 2026 // <a href="https://buymeacoffee.com/infodom">Buy Bob a Coffee</a> // <a href="https://ghostwire.news">Ghostwire</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!umSj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcae8b2-8772-4bbf-983f-8d245ec1d791_1402x1122.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!umSj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcae8b2-8772-4bbf-983f-8d245ec1d791_1402x1122.png 424w, https://substackcdn.com/image/fetch/$s_!umSj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcae8b2-8772-4bbf-983f-8d245ec1d791_1402x1122.png 848w, https://substackcdn.com/image/fetch/$s_!umSj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcae8b2-8772-4bbf-983f-8d245ec1d791_1402x1122.png 1272w, https://substackcdn.com/image/fetch/$s_!umSj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcae8b2-8772-4bbf-983f-8d245ec1d791_1402x1122.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!umSj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcae8b2-8772-4bbf-983f-8d245ec1d791_1402x1122.png" width="1402" height="1122" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2fcae8b2-8772-4bbf-983f-8d245ec1d791_1402x1122.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1122,&quot;width&quot;:1402,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3112414,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://bragg.substack.com/i/202354079?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcae8b2-8772-4bbf-983f-8d245ec1d791_1402x1122.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!umSj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcae8b2-8772-4bbf-983f-8d245ec1d791_1402x1122.png 424w, https://substackcdn.com/image/fetch/$s_!umSj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcae8b2-8772-4bbf-983f-8d245ec1d791_1402x1122.png 848w, https://substackcdn.com/image/fetch/$s_!umSj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcae8b2-8772-4bbf-983f-8d245ec1d791_1402x1122.png 1272w, https://substackcdn.com/image/fetch/$s_!umSj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcae8b2-8772-4bbf-983f-8d245ec1d791_1402x1122.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>China&#8217;s Ministry of State Security Warns of &#8216;AI Transit Stations&#8217; as NSFOCUS Positions Firewall Platform for AI Boundary Security</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>China&#8217;s Ministry of State Security (MSS) has warned that third-party &#8220;AI transit stations&#8221;&#8212;proxy services that aggregate access to multiple large language models through a single interface&#8212;pose systemic risks related to data leakage, malicious content injection, and unauthorized cross-border data transfers. In response, NSFOCUS is positioning its NF Firewall as a boundary security solution for AI governance, arguing that AI service security has become an organizational issue requiring network-level controls, data inspection, and audit capabilities.</strong></p><p><strong>Analyst Comments:</strong> The MSS warning reflects Beijing&#8217;s growing concern that AI adoption is creating new, poorly governed supply chains for sensitive data. AI transit stations effectively act as intermediaries between users and frontier models, introducing an additional trust layer that organizations neither control nor fully understand. For Chinese government agencies and state-owned enterprises operating under strict cybersecurity, data localization, and personal information regulations, these services represent both a security and compliance risk.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://blog.nsfocus.net/%E5%9B%BD%E5%AE%89%E9%83%A8%E7%82%B9%E5%90%8Dai%E4%B8%AD%E8%BD%AC%E7%AB%99%EF%BC%8C%E6%94%BF%E4%BC%81%E6%9C%BA%E6%9E%84%E5%A6%82%E4%BD%95%E5%AE%88%E4%BD%8Fai%E5%AE%89%E5%85%A8/">NSFOCUS</a></strong></p><h1><strong>Beijing Isn&#8217;t Trying to Win the Frontier AI Race&#8212;It&#8217;s Building a Lean, Open-Source Ecosystem Designed for Global Diffusion</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>China's AI sector is pursuing a fundamentally different strategy than the United States, emphasizing cost efficiency, open-source models, rapid application deployment, and global diffusion rather than competing directly for artificial general intelligence (AGI) supremacy. Resource constraints, smaller domestic monetization opportunities, and export controls have pushed Chinese firms toward leaner architectures and open ecosystems that are increasingly shaping global AI adoption, particularly across emerging markets.</strong></p><p><strong>Analyst Comments:</strong> The prevailing narrative that China is merely "catching up" to U.S. AI capabilities misses the larger strategic shift underway. Chinese firms are increasingly behaving like what the authors describe as "skinny athletes"&#8212;lean, efficient, and optimized for rapid deployment and cost-effective scaling. Rather than outspending U.S. hyperscalers on compute-intensive frontier models, China is attempting to industrialize AI by embedding lower-cost, open-source technologies across businesses and economies worldwide. This approach is producing a different form of competition: one centered on accessibility and adoption rather than raw model size.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://fortune.com/2026/06/16/china-ai-deepseek-open-source-efficiency-global-expansion-strategy/">Fortune</a></strong></p><h1><strong>MSS Alleges Foreign Intelligence Services Are Deploying &#8216;Spy Turtles&#8217; and &#8216;Spy Fish&#8217; to Conduct Maritime Surveillance.</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>China&#8217;s Ministry of State Security (MSS) claims foreign intelligence agencies are using marine animals equipped with sensors&#8212;including so-called &#8220;spy turtles&#8221; and &#8220;spy fish&#8221;&#8212;to collect oceanographic and seabed data in Chinese coastal waters. While Beijing framed the issue as an emerging espionage threat to national and military security, experts note that similar bio-logging technologies are routinely used worldwide for legitimate scientific and environmental research.</strong></p><p><strong>Analyst Comments:</strong> Oceanographic data absolutely has intelligence value. Information on currents, salinity, seabed composition, and maritime conditions can support naval operations, submarine navigation, and undersea infrastructure mapping. Intelligence services have historically experimented with unconventional collection methods, including animal-assisted programs.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://www.audacy.com/krld/news/local/china-accuses-foreign-spies-of-using-spy-turtles-and-spy-fish-in-coastal-waters">Audacy</a></strong></p><h1><strong>Anthropic&#8217;s Mythos/Fable Retreat Gives China&#8217;s Open-Source AI Ecosystem a Strategic Opening</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Bloomberg Opinion argues that Anthropic&#8217;s troubled Mythos and Fable rollout handed Chinese open-source AI firms an unexpected win. The core issue is not just model performance&#8212;it is trust, availability, and geopolitical reliability.</strong></p><p><strong>Analyst Comments:</strong> If U.S. frontier models can be abruptly restricted or withdrawn under national security pressure, global customers will look for alternatives that feel more dependable, customizable, and locally deployable. That plays directly into China&#8217;s open-weight AI strategy, where firms like DeepSeek, Qwen, and MiniMax compete on cost, accessibility, and diffusion rather than closed frontier dominance. The security rationale for restricting powerful models may be real, especially if cyber or dual-use capabilities are involved, but the market consequence is also real: every unavailable U.S. model makes open Chinese models more attractive.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://archive.ph/SinIx">Bloomberg</a></strong></p><h1><strong>China Unveils &#8216;LineShine&#8217; CPU-Only Supercomputer as Beijing Pursues Compute Self-Sufficiency Without Nvidia GPUs</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>China has reportedly developed a new supercomputer, dubbed LineShine, capable of delivering up to 1.54 exaflops of performance without relying on GPUs. Instead, the system uses more than 2.45 million CPU cores, specialized Arm vector and matrix extensions, and a high-speed interconnect architecture to compensate for the absence of Nvidia accelerators, underscoring Beijing&#8217;s push for indigenous computing capabilities amid ongoing U.S. export restrictions.</strong></p><p><strong>Analyst Comments:</strong> Whether or not LineShine matches the efficiency of Western heterogeneous CPU-GPU architectures, its strategic significance lies elsewhere. China is demonstrating that export controls may slow access to leading-edge accelerators but are unlikely to halt advances in high-performance computing altogether. The system appears to represent an engineering workaround born from necessity&#8212;substituting massive parallelism and optimized CPU architectures for scarce GPUs.</p><p><strong>READ THE STORY:</strong> <a href="https://www.bgr.com/2189816/china-supercomputer-without-gpu-lineshine/">BGR</a></p><h1><strong>ClickFix Campaigns Evolve With New Loaders as Threat Actors Rapidly Adapt Delivery Techniques</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers have identified multiple ClickFix campaigns delivering new malware loaders&#8212;BabaDeda Loader, Lorem Ipsum Loader, and Potemkin&#8212;through fake browser updates, compromised WordPress sites, and social engineering lures that trick users into executing malicious PowerShell commands. The campaigns demonstrate how threat actors continue to pivot quickly, adopting modular loader architectures and new delivery methods despite law enforcement and industry disruption efforts.</strong></p><p><strong>Analyst Comments:</strong> ClickFix has officially graduated from a clever social engineering trick to a mature malware delivery ecosystem. The technique's success isn't due to sophisticated exploits or novel zero-days&#8212;it's because it weaponizes one of the oldest vulnerabilities in cybersecurity: humans follow instructions, especially when they appear to come from an authoritative-looking prompt. "Press Win+R, paste this command, and hit Enter" remains alarmingly effective.</p><p><strong>READ THE STORY:</strong> <a href="https://thehackernews.com/2026/06/clickfix-campaigns-expand-malware.html">THN</a></p><h1><strong>FishMonger Expands SprySOCKS Malware to Windows, Uses Kernel Drivers to Evade Detection</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers have uncovered a previously undocumented Windows version of the SprySOCKS backdoor used by FishMonger&#8212;a China-nexus cyber espionage group linked to contractor i-Soon. The new variant leverages malicious kernel drivers to hide processes and files, providing advanced stealth capabilities against government targets in Honduras, Taiwan, Thailand, and Pakistan.</strong></p><p><strong>Analyst Comments:</strong> The use of kernel drivers also reinforces an enduring lesson for defenders: once an adversary reaches the kernel, visibility becomes significantly more difficult. By hooking system calls such as NtQuerySystemInformation, the malware can effectively disappear from normal administrative and security tooling. That said, ESET's findings suggest this is not necessarily evidence of a cutting-edge zero-day capability. The operators appear to have relied on a leaked code-signing certificate that only functions on outdated or misconfigured systems&#8212;a reminder that sophisticated threat actors are often pragmatic. If an organization leaves the front door unlocked, there's little reason to pick the lock.</p><p><strong>READ THE STORY:</strong> <a href="https://www.darkreading.com/threat-intelligence/sprysocks-windows-variant-kernel-drivers">DR</a> </p><h1><strong>Three Critical FortiSandbox Vulnerabilities Under Active Exploitation as Attackers Target Unpatched Systems</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Threat intelligence firm Defused reports active exploitation of three critical FortiSandbox vulnerabilities&#8212;CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089&#8212;that allow unauthenticated attackers to bypass authentication and execute arbitrary commands via specially crafted HTTP requests. Although Fortinet initially stated there was no evidence of exploitation when patches were released, attackers appear to have begun exploiting the flaws over the weekend, making immediate patching imperative.</strong></p><p><strong>Analyst Comments:</strong> At this point, unpatched Fortinet appliances have become the cybersecurity equivalent of leaving your car unlocked with the keys in the ignition and a sign that says, &#8220;Please don&#8217;t steal me.&#8221; The more notable issue is timing. Two of the vulnerabilities were patched in April and the third only last week, yet exploitation appears to have begun almost immediately after disclosure. This reinforces a recurring reality in vulnerability management: threat actors monitor vendor advisories closely and often weaponize newly disclosed flaws faster than organizations can patch.</p><p><strong>READ THE STORY:</strong> <a href="https://www.theregister.com/security/2026/06/16/three-critical-fortinet-sandbox-bugs-splattered-by-unknown-attackers/5256461">The Register</a></p><h1><strong>Items of interest</strong></h1><h1><strong>AI-Powered Cyberattacks Outpace Traditional Defenses as Security Vendors Shift Toward Small, Specialized Models</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>AI is dramatically accelerating cyber offense, reducing attack timelines from days to minutes and enabling threat actors to automate vulnerability discovery, malware generation, and credential attacks at unprecedented scale. In response, NSFOCUS is advocating and actively developing a hybrid AI defense architecture that combines frontier models with smaller, specialized models capable of operating at the edge, arguing that large general-purpose models alone cannot meet the speed, cost, and deployment requirements of modern cybersecurity operations.</strong></p><p><strong>Analyst Comments:</strong> While much of the market narrative centers on deploying ever-larger security models, NSFOCUS is positioning itself around a different thesis&#8212;that effective cyber defense will require an ecosystem of specialized small models working in conjunction with larger reasoning engines. The company says it is continuously designing and deploying small, scenario-specific models that filter legitimate traffic, establish customer-specific behavioral baselines, and escalate only uncertain events for deeper analysis by larger models. This architecture mirrors a teacher-student model increasingly seen across the industry, where frontier models provide reasoning capabilities while distilled, task-specific models perform frontline detection and triage. The approach also addresses operational realities such as latency requirements, data residency restrictions, and the high costs of processing massive volumes of benign traffic. Despite advances in automation, NSFOCUS emphasizes that human expertise remains indispensable for managing false positives, handling edge cases, and making strategic decisions in rapidly evolving threat environments.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://blog.nsfocus.net/%E8%B5%9B%E5%8D%9A%E6%97%A0%E9%97%B4%E9%81%93%EF%BC%9Aai%E6%97%B6%E4%BB%A3%E7%9A%84%E7%BD%91%E7%BB%9C%E6%94%BB%E9%98%B2%E6%88%98/">NSFOCUS</a></strong></p><h1><strong>Knowledge Distillation: How LLMs train each other (Video)</strong></h1><p><strong>FROM THE MEDIA: In this video, we break down knowledge distillation, the technique that powers models like Gemma 3, LLaMA 4 Scout &amp; Maverick, and DeepSeek-R1. Distillation was prominently discussed at LlamaCon 2025.</strong></p><div id="youtube2-jrJKRYAdh7I" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;jrJKRYAdh7I&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/jrJKRYAdh7I?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1><strong>What is LLM Distillation?(Video)</strong></h1><p><strong>FROM THE MEDIA: What is LLM Distillation ? Large Language Model (LLM) Distillation is revolutionizing how we make AI models smaller, faster, and more efficient&#8212;without losing their power! In this video, we&#8217;ll break down what LLM distillation is, why it matters, and how it works. You&#8217;ll learn how researchers take massive AI models, like GPT and LLaMA, and distill their knowledge into lighter, more cost-effective versions that can run efficiently on edge devices and enterprise applications.</strong></p><div id="youtube2-h7DUpHPasME" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;h7DUpHPasME&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/h7DUpHPasME?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don&#8217;t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com. </p>]]></content:encoded></item><item><title><![CDATA[Daily Drop (1318) ]]></title><description><![CDATA[06-15-26]]></description><link>https://bragg.substack.com/p/daily-drop-1318</link><guid isPermaLink="false">https://bragg.substack.com/p/daily-drop-1318</guid><dc:creator><![CDATA[Bob Bragg]]></dc:creator><pubDate>Tue, 16 Jun 2026 00:27:05 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NrAB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed868739-4a76-44cf-9060-39744a3bed62_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Monday, Jun 15, 2026 // <a href="https://buymeacoffee.com/infodom">Buy Bob a Coffee</a> // <a href="https://ghostwire.news">Ghostwire</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NrAB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed868739-4a76-44cf-9060-39744a3bed62_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NrAB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed868739-4a76-44cf-9060-39744a3bed62_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!NrAB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed868739-4a76-44cf-9060-39744a3bed62_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!NrAB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed868739-4a76-44cf-9060-39744a3bed62_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!NrAB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed868739-4a76-44cf-9060-39744a3bed62_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NrAB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed868739-4a76-44cf-9060-39744a3bed62_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ed868739-4a76-44cf-9060-39744a3bed62_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3380737,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://bragg.substack.com/i/201968932?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed868739-4a76-44cf-9060-39744a3bed62_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NrAB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed868739-4a76-44cf-9060-39744a3bed62_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!NrAB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed868739-4a76-44cf-9060-39744a3bed62_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!NrAB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed868739-4a76-44cf-9060-39744a3bed62_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!NrAB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed868739-4a76-44cf-9060-39744a3bed62_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>US and Iran Sign Framework Deal to End Conflict, Reopen Strait of Hormuz</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The United States and Iran have signed an initial framework agreement to end their conflict, extend the current ceasefire for another 60 days, and reopen the Strait of Hormuz. The deal, electronically signed by senior officials from both countries, includes the immediate cessation of military operations on all fronts, including Lebanon. Formal signing is scheduled for later this week in Geneva, with negotiations on a permanent settlement to continue during the ceasefire period.</strong></p><p><strong>Analyst Comments:</strong> The BBC reports direct confirmation from President Trump and senior U.S. officials, significantly increasing the credibility of the agreement. The reopening of the Strait of Hormuz is arguably the most consequential near-term development, as roughly 20% of global oil and natural gas flows through the waterway. Markets have already reacted with declining oil prices. However, the deal remains a framework agreement rather than a final peace settlement, and significant obstacles remain, including Iran's nuclear program, sanctions relief, and Israeli opposition to aspects of the agreement. The risk of spoilers remains high, particularly given reports of continued Israeli strikes in Lebanon after the announcement.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://www.bbc.com/news/articles/c39yvvy273ko">BBC</a></strong></p><h1><strong>Israeli Backlash Threatens Durability of US-Iran Peace Deal Despite Formal Agreement</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A major update to the U.S.-Iran peace agreement is emerging: while the framework deal has been signed and the Strait of Hormuz is set to reopen, significant Israeli opposition threatens its long-term viability. Israeli officials across the political spectrum have denounced the agreement, rejected provisions affecting Lebanon, and signaled continued military operations against Hezbollah. The biggest risk to the deal may now come from implementation challenges rather than U.S.-Iran negotiations themselves.</strong></p><p><strong>Analyst Comments:</strong> The center of gravity has shifted. The initial question was whether Washington and Tehran could reach an agreement. They did. The new question is whether regional actors&#8212;particularly Israel&#8212;will comply with or actively undermine it. Public criticism from Israeli ministers, opposition leaders, and Netanyahu allies indicates a serious strategic divergence between Washington and Jerusalem. Reports that Trump personally rebuked Netanyahu following Israeli strikes in Beirut underscore an unusually public rift between the two governments. This is becoming as much a U.S.-Israel political crisis as a U.S.-Iran diplomatic breakthrough.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://archive.is/3m0qr">The Washington Post</a></strong></p><h1><strong>Semiconductor Supply Chain &#8220;Chokepoints&#8221; May Deter Taiwan Conflict More Than Military Power</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A new analysis argues that Taiwan&#8217;s so-called &#8220;silicon shield&#8221; is not TSMC alone but an interconnected global network of semiconductor supply chain chokepoints spanning the United States, Europe, Japan, and Taiwan. The authors contend that these non-substitutable dependencies&#8212;particularly ASML&#8217;s EUV lithography systems and U.S.-dominated chip design software&#8212;create economic and strategic costs that deter conflict over Taiwan. However, aggressive export controls and reshoring policies risk accelerating Chinese self-sufficiency and weakening this deterrent over time.</strong></p><p><strong>Analyst Comments:</strong> The &#8220;silicon shield&#8221; narrative has always implied that Taiwan&#8217;s chip production alone deters invasion. The authors argue the real deterrent is the broader ecosystem of interlocking dependencies&#8212;what they call the &#8220;silicon testudo.&#8221; For cybersecurity and national security professionals, this matters because advanced computing, AI, and military modernization all depend on these supply chains. The concern is that prolonged export restrictions and supply chain decoupling may incentivize China to build indigenous capabilities, reducing the strategic leverage currently provided by Western technological dominance.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://warontherocks.com/the-chain-of-peace-do-supply-chain-chokepoints-deter-war/">WOTR</a></strong></p><h1><strong>US Government&#8217;s Anthropic Model Ban Sparks Fears of AI Supply Chain and Defensive Security Risks</strong></h1><p><em>NOTE:</em></p><p><em>Strip away the AI-jailbreak framing and this is a dual-use technology control story with an unresolved factual core. The central dispute &#8212; whether the bypass is a narrow, single-instance unlock (Anthropic's position) or one that opens the model's full offensive cyber capabilities (the administration's position, reportedly based on findings from Amazon and several other testers) &#8212; is exactly the question that should determine whether the response was proportionate, and it isn't settled in public reporting. For defenders, the more durable lesson is structural: if a government can pull a deployed model overnight, AI capabilities embedded in vulnerability management, code review, and SOC workflows become a new supply-chain dependency with its own continuity risk. Expect CISOs to start treating model access like any other critical third-party dependency &#8212; inventorying it, abstracting it, and planning for sudden loss.</em></p><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The U.S. government&#8217;s order forcing Anthropic to pull its Fable 5 and Mythos 5 models offline was reportedly not driven by a sophisticated jailbreak but by concerns over a guardrail bypass related to vulnerability discovery capabilities. The move has triggered criticism from cybersecurity experts who argue the action deprives defenders of advanced security tooling while establishing a precedent for direct government intervention in commercial AI services.</strong></p><p><strong>Analyst Comments:</strong> The precedent is the real issue. Security teams are increasingly integrating AI into vulnerability management, code review, and defensive operations. If a government can effectively pull a model offline overnight, AI platforms become a new category of supply chain dependency and operational risk. Attackers do not stop pursuing offensive capabilities because of export controls; defenders, however, can suddenly lose tools they rely on. Expect CISOs to begin evaluating AI resilience strategies, including multi-model architectures, abstraction layers, and contingency planning for critical AI-driven workflows.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://techcrunch.com/2026/06/15/the-us-governments-anthropic-models-ban-was-never-about-an-ai-jailbreak/">TC</a> // <a href="https://snyk.io/blog/government-ban-ai-model-engineer-perspective/">Snyk</a></strong></p><h1><strong>Palo Alto GlobalProtect Auth Bypass Actively Exploited Against VPN Edge Devices</strong></h1><p><em>NOTE:</em></p><p><em>From a threat perspective, the danger is the combination of an easy, unauthenticated bypass with who runs GlobalProtect: the largest banks, healthcare systems, government agencies, and critical infrastructure operators, meaning one bug potentially unlocks the front door at thousands of high-value targets at once. The compromised device is the worst kind to lose &#8212; an internet-facing, deeply trusted remote-access VPN that grants internal network access and typically sits outside EDR visibility. The barrier to exploitation is low and dropping fast, since it's already exploited in the wild, listed in CISA's KEV catalog, and backed by public proof-of-concept code that lets even low-skill actors mass-target exposed portals. And while no major lateral movement has been seen yet, edge-VPN access is the classic precursor to credential theft, ransomware staging, and espionage &#8212; so the current quiet is a timing artifact, not reassurance.</em></p><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Palo Alto Networks confirmed active exploitation of CVE-2026-0257, a GlobalProtect authentication bypass affecting PAN-OS deployments with authentication override cookies enabled and risky certificate reuse. Attackers can forge cookies, bypass login, and establish unauthorized VPN sessions. CISA added the flaw to KEV, and exposed GlobalProtect portals should be patched or mitigated immediately.</strong></p><p><strong>Analyst Comments:</strong> Help Net Security, and Unit 42 report that CVE-2026-0257 affects GlobalProtect portal and gateway components in PAN-OS and Prisma Access configurations where authentication override cookies are enabled. The issue stems from cookie decryption without proper integrity validation, allowing attackers to craft accepted authentication cookies when certificates are reused. Rapid7 observed exploitation beginning May 17, 2026, with additional activity on May 21. Unit 42 listed observed infrastructure including 23.128.228[.]6, 104.207.144[.]154, 146.19.216[.]119, 179.43.172[.]213, and 202.144.192[.]47. Recommended actions include upgrading to fixed PAN-OS versions, disabling authentication override, or using a dedicated certificate only for cookie encryption and decryption.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://gbhackers.com/palo-alto-warns-globalprotect-vpn-flaw/">GBhackers</a></strong></p><h1><strong>Researchers Develop AI &#8220;Fingerprinting&#8221; Method to Detect Misrepresented LLMs and Counterfeit Model Endpoints</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers on the Kanxue Security Community have proposed a technique for identifying whether an AI service is actually running the model it claims to provide. The method uses genetic algorithms to generate highly discriminative prompts and then analyzes response embedding distances to classify model identities. The authors claim the approach can distinguish among multiple commercial and open-source models, potentially exposing &#8220;transfer stations&#8221; that rebrand lower-tier models as premium offerings.</strong></p><p><strong>Analyst Comments:</strong> As organizations increasingly rely on third-party AI gateways, API aggregators, and regional providers, model provenance has become a supply chain issue. A service advertising GPT-5.5 but quietly routing requests to another model introduces security, privacy, and compliance concerns. Beyond detecting counterfeit AI services, the technique could also be adapted for attribution, benchmarking, and monitoring unauthorized model substitution in enterprise environments. Expect model fingerprinting and attestation mechanisms to become increasingly important as AI ecosystems become more fragmented.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://bbs.kanxue.com/thread-291619.htm">Kanxue</a></strong></p><h1><strong>Chinese Perspective of Red Teams Shift to &#8220;Unorthodox&#8221; Phishing Techniques to Bypass Mature Email Defenses</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Chinese security researchers report that red teams are increasingly abandoning traditional email phishing in favor of unconventional delivery channels that bypass enterprise controls. Emerging tactics include targeting third-party contractors outside EDR coverage, abusing customer support and ticketing systems to deliver malware, leveraging personal email accounts, and compromising centralized management platforms to distribute malicious payloads. Mac systems with low EDR adoption are also becoming attractive initial access targets.</strong></p><p><strong>Analyst Comments:</strong> This trend reflects a simple reality: traditional phishing is becoming less effective in mature environments. As email gateways, attachment sandboxing, and user awareness programs improve, adversaries are looking for blind spots in the enterprise attack surface. The focus has shifted from defeating security controls head-on to identifying places where controls do not exist. Third-party personnel, niche file-sharing channels, and unmanaged endpoints represent high-value opportunities because they often combine weaker security monitoring with legitimate access to corporate resources. Defenders should view this as another evolution of &#8220;living off the environment&#8221; tactics&#8212;except the environment now includes business processes and supply chains.</p><p><strong>READ THE STORY:</strong> <strong>Kanxue</strong></p><h1><strong>EtherRAT Campaign Uncovers Shared Criminal Infrastructure Hosting Malware, Phishing Kits, and Remote Access Tools</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Chinese security researchers report that red teams are increasingly abandoning traditional email phishing in favor of unconventional delivery channels that bypass enterprise controls. Emerging tactics include targeting third-party contractors outside EDR coverage, abusing customer support and ticketing systems to deliver malware, leveraging personal email accounts, and compromising centralized management platforms to distribute malicious payloads. Mac systems with low EDR adoption are also becoming attractive initial access targets.</strong></p><p><strong>Analyst Comments:</strong> This is more than another commodity RAT campaign. The story here is the infrastructure. The operators appear to maintain a multi-purpose ecosystem capable of supporting malware delivery, phishing operations, and potentially multiple affiliates or customers. The use of blockchain-based C2 discovery is particularly notable because it reduces dependence on static infrastructure and complicates traditional domain takedown efforts. The discovery of open directories and exposed phishing kits also</p><p><strong>READ THE STORY:</strong> <strong><a href="https://www.malwarebytes.com/blog/threat-intel/2026/06/inside-a-malicious-infrastructure-delivering-etherrat-phishing-pages-and-malicious-software">Malwarebytes</a></strong></p><h1><strong>Cisco SD-WAN Manager Zero-Day Added to CISA KEV After Root Escalation Attacks</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>CISA added CVE-2026-20262 to its KEV catalog after active exploitation against Cisco Catalyst SD-WAN Manager. The flaw lets authenticated low-privilege attackers abuse file upload handling to create or overwrite files, potentially escalating to root. Cisco has released fixed versions and says there are no workarounds.</strong></p><p><strong>Analyst Comments:</strong> The credential requirement lowers the rating, but stolen or low-privileged accounts are not exactly rare. Once an attacker can write files and pivot to root on SD-WAN management infrastructure, this becomes a serious control-plane risk. Patch this fast and review logs for suspicious file upload activity. CISA added CVE-2026-20262 and CVE-2026-54420 to the KEV catalog on June 15, 2026. Cisco confirmed limited exploitation of CVE-2026-20262 in June and said the flaw affects all Catalyst SD-WAN Manager deployment types. BleepingComputer and The Register report attackers can send crafted HTTP requests to an affected API endpoint to create or overwrite files, later using them to gain root privileges. Cisco advised administrators to review vmanage-server, vmanage-appserver, and serviceproxy-access logs for attempts to upload <code>index.jsp</code> and <code>.war</code> files.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://www.theregister.com/patches/2026/06/15/cisco-sd-wan-make-me-root-bug-under-attack/5255916">The Register</a></strong></p><h1><strong>DPAPISnoop Update Enables Offline Cracking of Windows CREDHIST Password History Files</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers from Nettitude CyberLabs updated the open-source DPAPISnoop tool to extract offline-crackable hashes from Windows DPAPI CREDHIST files. The capability allows attackers with filesystem access to recover historical passwords, identify password reuse patterns, and potentially traverse a user's credential history chain. While not a software vulnerability, the technique significantly enhances post-compromise credential access opportunities.</strong></p><p><strong>Analyst Comments:</strong> This is a post-exploitation capability that defenders should pay attention to because it turns an obscure Windows artifact into a valuable source of password intelligence. The real risk isn't that DPAPI is broken&#8212;it isn't. The problem is that once an attacker gains local or administrative access, CREDHIST files can reveal years of password habits, including incremental changes and reuse patterns that often extend into privileged accounts. Older entries protected with weaker cryptography are particularly attractive because they may provide an easier foothold into recovering newer credentials. Expect red teams and threat actors to add this technique to credential harvesting playbooks.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://ghostwire.news/article/gbhackers-189302">Ghostwire</a></strong></p><h1><strong>Items of interest</strong></h1><h1><strong>Shadow AIS Fleet Tactics Expose Maritime Sanctions Evasion Across Venezuela, Libya, and the Mediterranean</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The tanker SKIPPER (IMO: 9304667) reportedly went 200 days without AIS transmissions, spoofed a location roughly 1,200 nautical miles away, and appeared off Guyana while allegedly loading at Venezuela&#8217;s San Jose terminal. Similar AIS dark activity, false positioning, and identity manipulation are now being observed along the Libyan coast and across Mediterranean smuggling routes.</strong></p><p><strong>Analyst Comments:</strong> The SKIPPER case matters because it shows how a vessel can create a parallel reality: one track for regulators and commercial monitoring platforms, another for the actual cargo movement. When a tanker &#8220;paints&#8221; itself hundreds or thousands of miles from its real location, standard compliance workflows can fail unless analysts correlate AIS with satellite imagery, port activity, draft changes, ownership records, and terminal schedules. The same tradecraft showing up near Libya is especially concerning. Libya&#8217;s fragmented security environment, contested oil infrastructure, and proximity to Mediterranean shipping corridors make it attractive for smuggling networks. Expect more use of AIS gaps, false destinations, name changes, flag hopping, shell ownership, and ship-to-ship transfers just outside high-visibility zones.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://ghostwire.news/article/codeby-https:%2F%2Fcodeby.net%2Fthreads%2Fot-slezhivaniye-tenevogo-flota-ais-poshagovaya-osint-metodologiya-raskrytiya-kontrabandy-cherez-liviyu-i-sredizemnomor-ye.94082%2F">Codeby</a> // <a href="https://www.occrp.org/en/feature/practical-osint-for-investigating-shadow-fleets">OCCRP</a></strong></p><h1><strong>How to track dark ships using OSINT (Video)</strong></h1><p><strong>FROM THE MEDIA: In this OSINT deep dive, professional OSINT analyst Ray Baker joins David Bombal to explore the shadowy world of maritime cybersecurity and vessel tracking. Discover the critical differences between the dark fleet and shadow fleet, and learn the exact open-source intelligence methods used to track ships attempting to hide their identities on the open ocean. From manipulating AIS tracking data and repainting ship decks to the terrifying reality of hacking Chinese-made port cranes, this video uncovers the hidden cyber threats facing global supply chains. We also explore the tools used by professionals, such as MarineTraffic and Equasis, to investigate illicit maritime activities and track adversarial movements.</strong></p><div id="youtube2-niL4JPfcD3g" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;niL4JPfcD3g&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/niL4JPfcD3g?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1><strong>AML Expert Shadow Fleet trailer | Fighting illicit oil | Financial CPD (Video)</strong></h1><p><strong>FROM THE MEDIA: This Expert AML module uncovers how a single tanker explosion &#8212; the Pablo &#8212; illuminated one of the fastest&#8209;growing laundering ecosystems on earth: the global shadow fleet. Through the real story of how aging, opaque tankers move sanctioned oil through shell companies, forged documents, AIS manipulation, and digital deception, we unpack how sanctions evasion has evolved into a full&#8209;scale value&#8209;laundering system operating far outside the regulated maritime world.</strong></p><div id="youtube2-QhweZKBiZdY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;QhweZKBiZdY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/QhweZKBiZdY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don&#8217;t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com. </p>]]></content:encoded></item><item><title><![CDATA[Daily Drop (1317) ]]></title><description><![CDATA[06-13-26]]></description><link>https://bragg.substack.com/p/daily-drop-1317</link><guid isPermaLink="false">https://bragg.substack.com/p/daily-drop-1317</guid><dc:creator><![CDATA[Bob Bragg]]></dc:creator><pubDate>Sat, 13 Jun 2026 13:37:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!kjjo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d3ab4f-3ebe-4dda-9579-a6c203c2023f_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Saturday, Jun 13, 2026 // <a href="https://buymeacoffee.com/infodom">Buy Bob a Coffee</a> // <a href="https://ghostwire.news">Ghostwire</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kjjo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d3ab4f-3ebe-4dda-9579-a6c203c2023f_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kjjo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d3ab4f-3ebe-4dda-9579-a6c203c2023f_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!kjjo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d3ab4f-3ebe-4dda-9579-a6c203c2023f_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!kjjo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d3ab4f-3ebe-4dda-9579-a6c203c2023f_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!kjjo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d3ab4f-3ebe-4dda-9579-a6c203c2023f_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kjjo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d3ab4f-3ebe-4dda-9579-a6c203c2023f_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e2d3ab4f-3ebe-4dda-9579-a6c203c2023f_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3184834,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://bragg.substack.com/i/201857706?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d3ab4f-3ebe-4dda-9579-a6c203c2023f_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kjjo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d3ab4f-3ebe-4dda-9579-a6c203c2023f_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!kjjo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d3ab4f-3ebe-4dda-9579-a6c203c2023f_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!kjjo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d3ab4f-3ebe-4dda-9579-a6c203c2023f_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!kjjo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2d3ab4f-3ebe-4dda-9579-a6c203c2023f_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>Iran-Linked Handala Breached California Water Service Via Exposed GPS Platform, Leaks 5GB of Customer Data</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Iran-linked threat group Handala claimed responsibility for breaching California Water Service (Cal Water), publishing a 5GB proof-of-concept data dump containing customer billing information and exposing an internet-facing RTKBase GNSS platform used for precision GPS operations. Researchers assess the exposed GPS infrastructure likely served as the initial access vector or lateral movement point into the billing environment. While no operational technology (OT) disruption has been confirmed, Handala has a documented history of escalating from data theft to destructive attacks using custom wipers and MBR-overwriting malware.</strong></p><p><strong>Analyst Comments:</strong> An internet-accessible Raspberry Pi-based RTKBase deployment should never provide a pathway into customer billing systems. The exposure of plaintext administrative credentials and full NTRIP infrastructure mapping suggests basic security hygiene was lacking.The bigger issue is the threat actor. Handala has repeatedly demonstrated a &#8220;data theft first, destruction later&#8221; operating model. Their previous deployment of wipers against Stryker shows they are willing to transition from espionage and psychological operations to disruptive activity. Water utilities are increasingly attractive targets because they provide opportunities for outsized societal impact and media attention. This incident aligns closely with recent CISA warnings regarding Iranian interest in U.S. water infrastructure.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://securityaffairs.com/193565/uncategorized/iran-linked-handala-breached-a-california-water-utility-it-could-have-done-worse-and-it-knows-that.html">Security Affairs</a></strong></p><h1><strong>Operation Ghost Hook Dismantles China-Based Phishing-as-a-Service Network Linked to $1.9 Billion in Fraud Losses</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The FBI, in coordination with Google and Lumen Technologies, has disrupted Outsider, a China-based Phishing-as-a-Service (PhaaS) operation allegedly responsible for approximately $1.9 billion in losses and attacks spanning 55 countries. The operation, dubbed Operation Ghost Hook, resulted in the seizure of core infrastructure, phishing domains, payment wallets, and customer data associated with the cybercrime enterprise. The case also highlights the growing use of AI platforms to accelerate phishing operations.</strong></p><p><strong>Analyst Comments:</strong> This was not a single phishing gang running isolated campaigns&#8212;it was an ecosystem providing phishing infrastructure, automation, customer support, AI-assisted lure generation, and authentication bypass capabilities to a global customer base. The economics are striking. For as little as $88 per week, cybercriminals could access professionally maintained phishing kits capable of impersonating trusted brands and defeating multiple forms of authentication. This dramatically lowers the barrier to entry, enabling less sophisticated actors to conduct highly effective fraud campaigns at scale.</p><p><strong>READ THE STORY:</strong> <strong>CyberScoop</strong></p><h1><strong>China-Linked Velvet Ant Backdoored Linux Authentication Stack, Maintaining Covert Access for Nearly a Decade</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Incident responders at Sygnia uncovered a long-running cyber espionage campaign by the China-linked threat group Velvet Ant, which modified Linux PAM and OpenSSH authentication components to establish highly resilient persistence inside an isolated network. The operation, dubbed Operation Highland, dates back to at least 2016 and demonstrates a sophisticated strategy of compromising trusted infrastructure components rather than deploying conventional malware.</strong></p><p><strong>Analyst Comments:</strong> Rather than deploying implants that defenders routinely hunt for, Velvet Ant compromised the very mechanisms responsible for authenticating users and managing remote access. By backdooring PAM (Pluggable Authentication Modules) and OpenSSH, the attackers effectively controlled the trust layer itself. The significance cannot be overstated. Password resets, session terminations, and standard malware remediation procedures become largely ineffective when the authentication system has been subverted. Every new credential can simply be captured again, and secret access mechanisms remain available even after apparent remediation.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://thehackernews.com/2026/06/china-linked-hackers-backdoored-linux.html">THN</a></strong></p><h1><strong>Russian Infrastructure Operator Tied to Kremlin-Linked Void Blizzard Cyber Espionage Campaign</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>U.S. authorities have charged 36-year-old Russian national Denis Obrezko in federal court in Boston for allegedly providing infrastructure support to the Kremlin-linked cyber espionage group Void Blizzard. While not accused of conducting intrusions directly, Obrezko allegedly procured and managed servers, domains, and cryptocurrency-funded infrastructure used in cyber operations targeting at least 11 U.S. organizations across government, defense, technology, healthcare, media, transportation, and NGO sectors.</strong></p><p><strong>Analyst Comments:</strong> Governments are increasingly targeting not just the operators conducting intrusions, but the broader ecosystem that enables them. Infrastructure brokers, bulletproof hosting providers, domain registrars, cryptocurrency facilitators, and technical support personnel have become strategic targets because they provide the logistical backbone that allows both criminal and state-sponsored campaigns to operate at scale. The allegations surrounding Void Blizzard illustrate how modern espionage operations increasingly leverage the same commercial infrastructure and financial channels used by cybercriminal groups. Virtual private servers, disposable domains, cryptocurrency payments, and illicit credential markets have created a shared support ecosystem where the boundaries between cybercrime and state activity are increasingly blurred.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://www.escudodigital.com/en/cybersecurity/us-strikes-at-the-heart-of-russian-cybercrime-network-void-blizzard.html">DS</a></strong></p><h1><strong>FCC Proposal Would Effectively End Anonymous &#8216;Burner Phones&#8217; in the U.S.</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The U.S. Federal Communications Commission (FCC) is considering new rules that would require telecommunications providers to collect and retain government-issued identification numbers and physical addresses for new and renewing customers. If implemented, the proposal would significantly restrict the ability to purchase anonymous or pseudonymous &#8220;burner phones&#8221; in the United States, raising concerns among privacy advocates, civil liberties groups, journalists, and domestic violence organizations.</strong></p><p><strong>Analyst Comments:</strong> While framed as an anti-fraud and anti-scam measure, the practical effect would be the creation of a much more comprehensive identity-to-phone-number linkage system. From a cybersecurity perspective, there are two competing realities. On one hand, anonymous phone services are routinely abused by scammers, fraud operators, and criminal networks. Better subscriber attribution could improve investigations into phishing campaigns, business email compromise (BEC), SIM swapping, and telecom-enabled fraud.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://www.404media.co/fcc-wants-to-kill-burner-phones-by-forcing-telecoms-to-get-all-customers-ids/">404</a></strong></p><h1><strong>CISA Revives Long-Delayed Cyber Incident Reporting Rules Amid Pressure to Finalize CIRCIA</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The Cybersecurity and Infrastructure Security Agency (CISA) has resumed public consultations on implementing the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), a regulation that could require up to 300,000 critical infrastructure entities to report significant cyber incidents within 72 hours and ransomware payments within 24 hours. While lawmakers are urging CISA to finalize the rules quickly, industry groups continue to argue that the current draft is overly broad, ambiguous, and risks creating substantial reporting burdens.</strong></p><p><strong>Analyst Comments:</strong> CIRCIA represents one of the most consequential shifts in U.S. cyber regulation since the creation of CISA itself. The agency has largely operated through voluntary partnerships and information sharing since its establishment in 2018. CIRCIA changes that dynamic by introducing mandatory incident reporting requirements across sixteen critical infrastructure sectors.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://federalnewsnetwork.com/cybersecurity/2026/06/cisa-revives-push-toward-long-awaited-cyber-incident-reporting-rules/">FNN</a></strong></p><h1><strong>U.S. Government Orders Anthropic to Restrict Fable 5 and Mythos 5 Access Over National Security Concerns</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Anthropic has temporarily suspended access to its flagship Fable 5 and Mythos 5 models worldwide after receiving a U.S. government directive requiring the company to block access by all foreign nationals, including individuals inside the United States and Anthropic&#8217;s own foreign-national employees. The order reportedly stems from concerns over a potential jailbreak capability and raises significant questions about AI export controls, technological sovereignty, and the future regulation of frontier AI models.</strong></p><p><strong>Analyst Comments:</strong> The practical implications are enormous. The government reportedly ordered Anthropic to prohibit access by any foreign national regardless of location, a requirement so broad that the company determined it had to shut off both models globally to remain compliant. If accurate, this represents a dramatic escalation in how governments view advanced AI capabilities and their potential national security implications. The stated trigger&#8212;a reportedly narrow jailbreak allowing the model to analyze code and identify vulnerabilities&#8212;is equally notable. Anthropic argues that these capabilities already exist in other publicly available models and are routinely used by defenders. If governments begin recalling or restricting models over limited jailbreak scenarios, the industry could face substantial uncertainty around deployment standards and export compliance requirements.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://www.bleepingcomputer.com/news/security/us-gov-asks-anthropic-to-ban-foreign-national-access-to-fable-mythos/">Bleeping Computer</a> // <a href="https://t.me/DevQ_A/519">Telegram</a></strong></p><h1><strong>ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Target Universities Worldwide</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Google Threat Intelligence Group (GTIG) and Mandiant have confirmed that ShinyHunters (UNC6240) exploited the critical Oracle PeopleSoft zero-day CVE-2026-35273 (CVSS 9.8) to compromise more than 100 organizations globally, with 68% of identified victims belonging to the higher education sector. The campaign leveraged unauthenticated remote code execution, custom malware staging infrastructure, credential spraying, and data exfiltration techniques to steal sensitive data and extort victims.</strong></p><p><strong>Analyst Comments:</strong> PeopleSoft isn&#8217;t just another business application&#8212;it often serves as the central repository for HR records, payroll data, student information, financial systems, and identity information. A compromise of PeopleSoft can quickly become a compromise of the entire institution. The attackers&#8217; methodology also stands out. Rather than directly attacking databases, ShinyHunters reportedly operated through legitimate PeopleSoft application logic and APIs, reducing the likelihood of detection by traditional database monitoring controls. This is increasingly common in modern intrusions: attackers abuse the application&#8217;s intended functionality instead of exploiting infrastructure in ways that trigger security alarms.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://hackread.com/shinyhunters-universities-oracle-peoplesoft-zero-day-attack/">HACKREAD</a></strong></p><h1><strong>FBI Unveils 22,000-Square-Foot &#8220;Kinetic Cyber Range&#8221; Replica Town for Cyberattack and Digital Forensics Training</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The FBI disclosed details of its Kinetic Cyber Range, a 22,000-square-foot replica town in Huntsville, Alabama, designed to simulate real-world cyber incidents and train investigators in cyber response, digital forensics, and critical infrastructure investigations. The facility replicates homes, businesses, hospitals, power infrastructure, and corporate IT environments to provide hands-on training against ransomware, infrastructure attacks, and device exploitation scenarios.</strong></p><p><strong>Analyst Comments:</strong> The inclusion of fully functional IT environments and critical infrastructure simulations is particularly notable. Training investigators to operate in realistic conditions&#8212;including noisy data centers, interconnected systems, and time-sensitive scenarios&#8212;should improve incident response capabilities and evidence collection during major cyber events. The digital forensics component also highlights an ongoing tension in cybersecurity. Law enforcement increasingly relies on <strong>zero-day-based forensic tools</strong> capable of bypassing modern encryption and device protections. While these capabilities are often essential for criminal investigations, they also raise longstanding concerns around vulnerability disclosure and the retention of undisclosed exploits that could potentially be discovered or reused by adversaries.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://techcrunch.com/2026/06/13/the-fbi-built-its-own-replica-small-town-to-simulate-real-world-cyberattacks/">TC</a></strong></p><h1><strong>Tenable Launches VM-Native OT Discovery to Improve Visibility Across Converged IT and OT Environments</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Tenable announced VM-Native OT Discovery, a new capability integrated into Tenable Vulnerability Management, Tenable Security Center, and the Tenable One Exposure Management Platform that provides safe, protocol-aware discovery of operational technology (OT), IoT, and cyber-physical assets without requiring specialized hardware deployments. The initiative aims to address one of the industry's biggest challenges: limited visibility into increasingly interconnected OT environments.</strong></p><p><strong>Analyst Comments:</strong> IT teams are increasingly inheriting responsibility for securing building management systems, industrial devices, and other cyber-physical assets but often lack the visibility and tooling needed to understand their exposure. Tenable is positioning this release as an &#8220;on-ramp&#8221; to OT security by lowering the cost and complexity traditionally associated with OT asset discovery. That&#8217;s significant because many organizations avoid OT security projects due to fears of disrupting fragile devices, the expense of deploying specialized sensors, and operational resistance to installing new infrastructure.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://securityboulevard.com/2026/04/unlocking-foundational-visibility-for-cyber-physical-systems-with-ot-vulnerability-management-2/">Security Boulevard</a></strong></p><h1><strong>Linux Authentication Stack, Maintaining Covert Access for Nearly a Decade</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Incident responders at Sygnia uncovered a long-running cyber espionage campaign by the China-linked threat group Velvet Ant, which modified Linux PAM and OpenSSH authentication components to establish highly resilient persistence inside an isolated network. The operation, dubbed Operation Highland, dates back to at least 2016 and demonstrates a sophisticated strategy of compromising trusted infrastructure components rather than deploying conventional malware.</strong></p><p><strong>Analyst Comments:</strong> Rather than deploying implants that defenders routinely hunt for, Velvet Ant compromised the very mechanisms responsible for authenticating users and managing remote access. By backdooring PAM (Pluggable Authentication Modules) and OpenSSH, the attackers effectively controlled the trust layer itself. The significance cannot be overstated. Password resets, session terminations, and standard malware remediation procedures become largely ineffective when the authentication system has been subverted. Every new credential can simply be captured again, and secret access mechanisms remain available even after apparent remediation.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://thehackernews.com/2026/06/china-linked-hackers-backdoored-linux.html">THN</a></strong></p><h1><strong>Researchers Reverse Engineer Apple Music&#8217;s X-Apple-ActionSignature Protection on Android, Exposing Advanced Obfuscation Techniques</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A reverse engineering analysis published on the Kanxue Security Community details how Apple Music&#8217;s Android implementation of X-Apple-ActionSignature employs multiple layers of code obfuscation, including indirect branch (BR) obfuscation, mixed-boolean arithmetic (MBA), control-flow flattening, stack address encryption, white-box cryptography, and modified MT19937-based operations. The research highlights the growing complexity of mobile application protections and the increasing difficulty of analyzing modern authentication and request-signing mechanisms.</strong></p><p><strong>Analyst Comments:</strong> Major technology companies increasingly assume that client-side code will be reverse engineered and therefore deploy multiple, overlapping anti-analysis mechanisms designed to significantly raise the cost of reverse engineering. The reported use of indirect branch obfuscation, white-box cryptography, and encrypted stack references reflects techniques more commonly associated with DRM systems, anti-cheat technologies, and high-assurance financial applications. These protections are specifically designed to defeat static analysis, complicate dynamic tracing, and slow the extraction of sensitive algorithms such as request-signing logic and cryptographic routines.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://bbs.kanxue.com/thread-291582.htm">Kanxue</a></strong></p><h1><strong>New macOS Tahoe 26 Artifact Reveals User Intent Through Menu Click Tracking</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Palo Alto Networks&#8217; Unit 42 has identified a previously undocumented macOS Tahoe 26 forensic artifact, App.MenuItem, that records users&#8217; specific menu selections across the operating system. Stored within Apple&#8217;s Biome framework, the artifact provides investigators with a detailed chronology of user actions&#8212;such as compressing files, deleting data, and emptying the trash&#8212;offering unprecedented visibility into user intent rather than merely system events.</strong></p><p><strong>Analyst Comments:</strong> Traditional forensic artifacts can show that a ZIP archive was created or files were deleted, but they often cannot definitively establish whether those actions were deliberate or automated. App.MenuItem introduces a behavioral layer that captures the human interaction with the operating system. For insider threat investigations, intellectual property theft cases, and incident response scenarios involving data exfiltration, the artifact could become exceptionally valuable. An analyst may now reconstruct a sequence such as: navigating to sensitive data, compressing it, moving evidence to the trash, and emptying the trash&#8212;all from explicit menu selections made by the user.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://unit42.paloaltonetworks.com/new-macos-artifact-discovered/">Unit42</a></strong></p><h1><strong>NanoClaw Partners With JFrog to Secure AI Agent Package Downloads and Combat Supply Chain Risk</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Secure agent framework NanoClaw has integrated with JFrog&#8217;s vetted package registries to reduce the risk of AI agents downloading malicious dependencies during self-improvement and tool acquisition processes. The partnership addresses a growing concern in agentic AI systems: autonomous package retrieval can expose agents to software supply chain attacks, dependency confusion, and malicious code execution. NanoClaw also introduced an AI-driven pull request (PR) review system designed to handle the surge of AI-generated code contributions while maintaining human approval for consequential actions.</strong></p><p><strong>Analyst Comments:</strong> Modern AI agents increasingly possess the ability to install libraries, fetch tools, generate code, and modify their own capabilities. While this dramatically improves productivity, it also creates a new attack surface where adversaries can weaponize package registries, typosquatting, dependency confusion, and malicious open-source packages to compromise agent workflows. The integration with JFrog is effectively an attempt to establish a trusted software supply chain for AI agents. Instead of allowing agents to indiscriminately pull packages from public registries such as npm, NanoClaw agents can retrieve dependencies from pre-vetted repositories that have undergone security review and provenance checks.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://ghostwire.news/article/theregister-security-https:%2F%2Fwww.theregister.com%2Fai-and-ml%2F2026%2F06%2F13%2Fnanoclaw-integrates-jfrog-registries-to-secure-ai-agent-downloads%2F5255189">The Register</a></strong></p><h1><strong>Anthropic&#8217;s Claude Fable 5 Jailbroken to Generate Exploit Code and Leak 120,000-Character System Prompt</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers claim that Anthropic&#8217;s Claude Fable 5, the flagship public model in the new Mythos series, was successfully jailbroken within days of release using multi-agent attacks, Unicode obfuscation, narrative framing, and prompt decomposition techniques. The researchers also reportedly extracted and published approximately 120,000 characters of system prompts, exposing internal safety instructions and model orchestration mechanisms. The jailbreak allegedly enabled the model to generate detailed exploit guidance, including stack buffer overflow development techniques and other prohibited technical content.</strong></p><p><strong>Analyst Comments:</strong> The bigger issue is what it reveals about the security assumptions behind multi-model safety architectures. According to the reporting, Fable 5 and its restricted counterpart, Claude Mythos 5, share the same underlying model but rely on a classification layer that routes high-risk requests to a less capable fallback model. This approach appears designed to preserve usability while limiting dangerous outputs. The alleged jailbreak suggests that if one component in a multi-agent pipeline can be manipulated, it may assist in bypassing controls protecting another component.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://www.freebuf.com/articles/485588.html">Freebuf</a></strong></p><h1><strong>152 Malicious Chrome Extensions Spoof Google Search Traffic and Harvest User Telemetry</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers at Socket have uncovered a coordinated network of 152 malicious Chrome extensions spread across 38 Chrome Web Store publisher accounts that masqueraded as benign "live wallpaper" new-tab extensions while secretly generating fraudulent Google organic search traffic and collecting user telemetry. The campaign amassed approximately 105,000 installs and leveraged deceptive attribution techniques, anti-forensic mechanisms, and distributed infrastructure to evade detection and maximize advertising revenue.</strong></p><p><strong>Analyst Comments:</strong> Although the campaign did not appear to deploy credential theft or malware payloads, it demonstrates how threat actors increasingly weaponize browser ecosystems for advertising fraud, telemetry harvesting, and analytics manipulation. The most interesting aspect is the abuse of Google attribution mechanisms. By forcing browser tabs to open with <code>utm_source=google&amp;utm_medium=organic</code> parameters and leveraging Google&#8217;s own redirect wrappers during uninstall events, the operators effectively manufactured fake organic search traffic that appeared indistinguishable from legitimate user behavior.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://ghostwire.news/article/gbhackers-189193">GBhackers</a></strong></p><h1><strong>Items of interest</strong></h1><h1><strong>Shadow AIS Fleet Tactics Expose Maritime Sanctions Evasion Across Venezuela, Libya, and the Mediterranean</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The tanker SKIPPER (IMO: 9304667) reportedly went 200 days without AIS transmissions, spoofed a location roughly 1,200 nautical miles away, and appeared off Guyana while allegedly loading at Venezuela&#8217;s San Jose terminal. Similar AIS dark activity, false positioning, and identity manipulation are now being observed along the Libyan coast and across Mediterranean smuggling routes.</strong></p><p><strong>Analyst Comments:</strong> The SKIPPER case matters because it shows how a vessel can create a parallel reality: one track for regulators and commercial monitoring platforms, another for the actual cargo movement. When a tanker &#8220;paints&#8221; itself hundreds or thousands of miles from its real location, standard compliance workflows can fail unless analysts correlate AIS with satellite imagery, port activity, draft changes, ownership records, and terminal schedules. The same tradecraft showing up near Libya is especially concerning. Libya&#8217;s fragmented security environment, contested oil infrastructure, and proximity to Mediterranean shipping corridors make it attractive for smuggling networks. Expect more use of AIS gaps, false destinations, name changes, flag hopping, shell ownership, and ship-to-ship transfers just outside high-visibility zones.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://ghostwire.news/article/codeby-https:%2F%2Fcodeby.net%2Fthreads%2Fot-slezhivaniye-tenevogo-flota-ais-poshagovaya-osint-metodologiya-raskrytiya-kontrabandy-cherez-liviyu-i-sredizemnomor-ye.94082%2F">Codeby</a> // <a href="https://www.occrp.org/en/feature/practical-osint-for-investigating-shadow-fleets">OCCRP</a></strong></p><h1><strong>How to track dark ships using OSINT (Video)</strong></h1><p><strong>FROM THE MEDIA: In this OSINT deep dive, professional OSINT analyst Ray Baker joins David Bombal to explore the shadowy world of maritime cybersecurity and vessel tracking. Discover the critical differences between the dark fleet and shadow fleet, and learn the exact open-source intelligence methods used to track ships attempting to hide their identities on the open ocean. From manipulating AIS tracking data and repainting ship decks to the terrifying reality of hacking Chinese-made port cranes, this video uncovers the hidden cyber threats facing global supply chains. We also explore the tools used by professionals, such as MarineTraffic and Equasis, to investigate illicit maritime activities and track adversarial movements.</strong></p><div id="youtube2-niL4JPfcD3g" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;niL4JPfcD3g&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/niL4JPfcD3g?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1><strong>AML Expert Shadow Fleet trailer | Fighting illicit oil | Financial CPD (Video)</strong></h1><p><strong>FROM THE MEDIA: This Expert AML module uncovers how a single tanker explosion &#8212; the Pablo &#8212; illuminated one of the fastest&#8209;growing laundering ecosystems on earth: the global shadow fleet. Through the real story of how aging, opaque tankers move sanctioned oil through shell companies, forged documents, AIS manipulation, and digital deception, we unpack how sanctions evasion has evolved into a full&#8209;scale value&#8209;laundering system operating far outside the regulated maritime world.</strong></p><div id="youtube2-QhweZKBiZdY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;QhweZKBiZdY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/QhweZKBiZdY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don&#8217;t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com. </p>]]></content:encoded></item><item><title><![CDATA[Daily Drop (1316) ]]></title><description><![CDATA[06-12-26]]></description><link>https://bragg.substack.com/p/daily-drop-1316</link><guid isPermaLink="false">https://bragg.substack.com/p/daily-drop-1316</guid><dc:creator><![CDATA[Bob Bragg]]></dc:creator><pubDate>Fri, 12 Jun 2026 08:19:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!tFgX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bdc4ac-32a0-4c33-b861-d468958fe1c4_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Friday, Jun 12, 2026 // <a href="https://buymeacoffee.com/infodom">Buy Bob a Coffee</a> // <a href="https://ghostwire.news">Ghostwire</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tFgX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bdc4ac-32a0-4c33-b861-d468958fe1c4_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tFgX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bdc4ac-32a0-4c33-b861-d468958fe1c4_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!tFgX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bdc4ac-32a0-4c33-b861-d468958fe1c4_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!tFgX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bdc4ac-32a0-4c33-b861-d468958fe1c4_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!tFgX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bdc4ac-32a0-4c33-b861-d468958fe1c4_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tFgX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bdc4ac-32a0-4c33-b861-d468958fe1c4_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e5bdc4ac-32a0-4c33-b861-d468958fe1c4_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3515073,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://bragg.substack.com/i/201712395?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bdc4ac-32a0-4c33-b861-d468958fe1c4_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tFgX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bdc4ac-32a0-4c33-b861-d468958fe1c4_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!tFgX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bdc4ac-32a0-4c33-b861-d468958fe1c4_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!tFgX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bdc4ac-32a0-4c33-b861-d468958fe1c4_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!tFgX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bdc4ac-32a0-4c33-b861-d468958fe1c4_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1><strong>AI Sovereignty Turns Data Centers into Strategic Cyber and National Security Targets</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers from the University of Maryland and Sandia National Laboratories warn that AI sovereignty is increasingly tied to physical infrastructure, making large-scale AI data centers attractive targets for cyber operations, supply chain attacks, influence campaigns, and even kinetic strikes. As nations concentrate AI capabilities into massive facilities housing hundreds of thousands of accelerators, adversaries gain identifiable targets that can be disrupted, degraded, or denied.</strong></p><p><strong>Analyst Comments:</strong> This research highlights a reality that&#8217;s often overlooked in AI discussions: AI isn&#8217;t just software anymore. It&#8217;s power grids, water systems, semiconductor supply chains, cooling infrastructure, and highly visible facilities with fixed geographic coordinates. For years, cyber strategists focused on protecting data and networks. The AI era expands that attack surface dramatically. Frontier AI capabilities now depend on infrastructure that looks increasingly like critical national infrastructure. A successful cyberattack against cooling systems, power management platforms, or chip supply chains could have strategic consequences comparable to attacks on telecommunications networks or energy assets.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://www.helpnetsecurity.com/2026/06/12/ai-sovereignty-data-centers/">HSN</a></strong></p><h1><strong>Senate Narrowly Rejects Proposal to Create U.S. Cyber Force</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A Senate Armed Services Committee proposal to establish a standalone U.S. Cyber Force was narrowly defeated in a 14-13 vote, delaying what would have become the nation&#8217;s seventh military branch. While lawmakers remain divided on whether Cyber Command requires its own service, the close vote highlights growing bipartisan concerns that current military personnel pipelines are not adequately preparing cyber operators to compete with adversaries such as China and Russia.</strong></p><p><strong>Analyst Comments:</strong> A near-successful committee vote signals that frustration with the current model is reaching a tipping point. The core issue remains talent generation. U.S. Cyber Command depends on personnel sourced from existing military branches, many of which prioritize traditional warfighting missions over cyber operations. Supporters argue a dedicated Cyber Force would professionalize recruitment, training, and career development for cyber operators in the same way the Space Force did for space operations.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://therecord.media/cyber-force-not-included-senate-defense-roadmap">The Record</a></strong></p><h1><strong>China-Linked JDY Botnet Expands Reconnaissance Against U.S. Military Networks</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Lumen&#8217;s Black Lotus Labs reports that the China-linked JDY botnet has grown to more than 1,500 compromised SOHO and IoT devices, up from roughly 650 in January 2024. Unlike commodity botnets, JDY is built for reconnaissance: scanning, fingerprinting, and mapping exposed services&#8212;especially networks tied to the U.S. military and associated entities&#8212;often within hours of new vulnerability disclosures.</strong></p><p><strong>Analyst Comments:</strong> The botnet turns compromised routers, cameras, and edge devices into a distributed sensor network. That lets operators scan from legitimate-looking residential and small-business IPs, making geofencing, static blocklists, and IP reputation controls much less effective. The fact that JDY quickly shifted toward Fortinet targets after disclosure of CVE-2026-35616 shows how fast reconnaissance is now being operationalized. For defenders, the lesson is blunt: exposed edge infrastructure needs faster patching and tighter access controls. Waiting days or weeks to patch internet-facing routers, firewalls, VPNs, and IoT devices gives actors like JDY plenty of time to map the environment before exploitation begins.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://www.csoonline.com/article/4184043/china-linked-recon-botnet-outpaces-enterprise-defenses.html">CSO</a> // <a href="https://www.bleepingcomputer.com/news/security/china-linked-jdy-botnet-expands-targeting-of-us-military-networks/">Bleeping Computer</a></strong></p><h1><strong>Chinese APT VerdantBamboo Maintains 18-Month Access Using BRICKSTORM Malware on Firewalls and Edge Appliances</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Researchers at Volexity uncovered a long-running intrusion by Chinese state-linked threat actor VerdantBamboo (also tracked as UNC5221 and WARP PANDA) that leveraged the BRICKSTORM malware family to compromise firewalls, storage appliances, NAS devices, and managed service provider infrastructure. The group maintained access to victim environments for at least 18 months, repeatedly re-establishing persistence even after remediation efforts, highlighting the growing threat posed by attacks against edge infrastructure that often lacks traditional endpoint security controls.</strong></p><p><strong>Analyst Comments:</strong> Firewalls, NAS devices, VPN gateways, storage systems, and management platforms often sit outside EDR visibility while maintaining privileged access to critical environments. The most concerning aspect isn&#8217;t BRICKSTORM itself&#8212;it&#8217;s VerdantBamboo&#8217;s operational discipline. The group compromised an MSP, harvested administrative credentials, leveraged exposed firewalls, deployed multiple fallback implants, and maintained redundant access paths. That&#8217;s the behavior of an actor focused on long-term intelligence collection rather than smash-and-grab operations.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://cybersecuritynews.com/chinese-apt-verdantbamboo-uses-brickstorm-malware/">CSN</a></strong></p><h1><strong>Microsoft&#8217;s Record 206-CVE Patch Tuesday Signals AI-Driven Shift in Vulnerability Discovery</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Microsoft&#8217;s June 2026 Patch Tuesday set a new company record with fixes for 206 vulnerabilities, surpassing the previous high of 175 CVEs. The release includes three publicly disclosed zero-days, 32 critical flaws, and 13 vulnerabilities Microsoft rates as &#8220;Exploitation More Likely.&#8221; Security researchers increasingly attribute the growing volume of disclosed vulnerabilities to AI-assisted discovery, signaling that large patch cycles may become the norm rather than the exception.</strong></p><p><strong>Analyst Comments:</strong> Now we&#8217;re seeing the other side of the equation: AI dramatically accelerating vulnerability research and disclosure. More bugs found means more bugs patched, but it also means security teams face a growing backlog of remediation work every month. The two most urgent issues are CVE-2026-47291 (Windows HTTP.sys) and CVE-2026-44815 (Windows DHCP Client), both carrying CVSS 9.8 scores and affecting widely deployed Windows systems. The DHCP Client flaw is particularly concerning because of its potential reach across enterprise environments. While not every disclosed vulnerability will see active exploitation, threat actors routinely prioritize critical Windows flaws immediately after release. Organizations that rely on traditional monthly patching cycles may find themselves falling behind as disclosure volumes continue to climb.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://cisowhisperer.com/microsofts-record-206-cve-patch-tuesday-signals-a-new-era-of-ai-driven-vulnerability-discovery/?utm_source=rss#038;utm_medium=rss&amp;#038;utm_campaign=microsofts-record-206-cve-patch-tuesday-signals-a-new-era-of-ai-driven-vulnerability-discovery">CISO Whisperer</a></strong></p><h1><strong>CISA Orders Federal Agencies to Patch High-Risk Vulnerabilities Within 72 Hours</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>CISA has issued Binding Operational Directive (BOD) 26-04, requiring federal civilian agencies to remediate the highest-risk vulnerabilities within three calendar days. The directive replaces previous vulnerability management mandates and shifts federal patching toward a risk-based model that prioritizes vulnerabilities based on exploitability, exposure, and real-world threat activity rather than severity scores alone.</strong></p><p><strong>Analyst Comments:</strong> The three-day remediation requirement is aggressive but reflects today&#8217;s threat landscape. Threat actors increasingly weaponize vulnerabilities within hours of disclosure, and AI-assisted reconnaissance is accelerating target identification. A critical flaw sitting on an internet-facing system is no longer a &#8220;patch this month&#8221; problem&#8212;it&#8217;s often a &#8220;patch before the weekend&#8221; problem. What&#8217;s particularly notable is the requirement for forensic triage alongside remediation when dealing with high-risk vulnerabilities. CISA is recognizing that by the time organizations discover a KEV-listed vulnerability, compromise may have already occurred. Patching alone is no longer considered sufficient.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://gbhackers.com/cisa-orders-federal-agencies-to-patch-critical-vulnerabilities/">GBhackers</a></strong></p><h1><strong>Google Confirms ShinyHunters Exploited Oracle PeopleSoft Zero-Day Against Universities</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Google has confirmed that the ShinyHunters cybercrime group exploited CVE-2026-35273, a critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft, as a zero-day before Oracle released mitigations. Google observed attacks between May 27 and June 9, notified more than 100 potentially affected organizations, and linked the activity to data theft campaigns primarily targeting the higher education sector.</strong></p><p><strong>Analyst Comments:</strong> PeopleSoft remains deeply embedded across universities, government agencies, and large enterprises, often serving as the system of record for HR, payroll, student information, and financial operations. An unauthenticated RCE against those environments is about as attractive as it gets for threat actors. What&#8217;s notable is the speed and scale of the campaign. Google observed exploitation activity before public disclosure, while ShinyHunters reportedly targeted roughly 300 PeopleSoft instances across 100 organizations. That suggests the group already had a mature targeting list and moved quickly once it identified a viable attack path.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://www.securityweek.com/google-confirms-exploitation-of-oracle-peoplesoft-zero-day-by-shinyhunters/">Security Week</a></strong></p><h1><strong>Hackers Weaponize AI Safety Guardrails to Evade Malware Analysis</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Security practitioners are discussing a novel evasion technique where threat actors embed prompts related to biological weapons and nuclear weapon design inside code comments to intentionally trigger AI safety mechanisms during automated malware analysis. The technique exploits the fact that some AI-powered security tools may refuse to process content containing prohibited topics, potentially causing malicious code to be skipped or inadequately analyzed.</strong></p><p><strong>Analyst Comments:</strong> Traditional malware authors spend years learning how to evade signatures, sandboxes, and behavioral detection. Now they&#8217;re experimenting with ways to manipulate the decision-making processes of AI-powered security tools. The concept is simple: place adversarial text inside comments that have no impact on code execution but are visible to an AI analyst. If the model prioritizes the embedded prompt over the actual code, it may refuse analysis, generate warnings, or terminate processing. In effect, the attacker attempts to turn safety alignment into a denial-of-analysis mechanism.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://www.t00ls.com/articles-75272.html">Tools</a></strong></p><h1><strong>French Government Confirms Tchap Messaging Breach Impacting 73,000+ Public Sector Employees</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>The French government has confirmed that a breach of its Tchap encrypted messaging platform exposed data belonging to 73,467 public sector employees after attackers compromised a user account and accessed unencrypted public chat rooms. While private encrypted conversations were not affected, the incident exposed user information and raises concerns about the security of government collaboration platforms increasingly relied upon for official communications.</strong></p><p><strong>Analyst Comments:</strong> Tchap&#8217;s end-to-end protection appears to have worked as designed for private conversations, but public channels created a separate attack surface that became accessible once the threat actor obtained a valid account. The breach highlights a recurring challenge for government collaboration platforms: authentication is often the weakest link. If the attacker&#8217;s social engineering claims are accurate, this wasn&#8217;t a cryptographic failure or sophisticated exploit&#8212;it was an identity compromise that provided legitimate access to sensitive environments.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://www.bleepingcomputer.com/news/security/french-govt-says-tchap-breach-affected-over-73-000-accounts/">Bleeping Computer</a></strong></p><h1><strong>China Launches First Large-Scale Malware Search Engine for Threat Hunting</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>Chinese threat intelligence provider ThreatBook has launched what it describes as the country's first large-scale malware search and threat hunting platform, allowing analysts to search across a repository containing hundreds of billions of files and more than 2 million new samples per day. The platform, branded X File Threat Hunting, is designed to help defenders identify malware families, uncover attacker infrastructure, track APT activity, and perform large-scale malware pivoting beyond traditional hash-based searches.</strong></p><p><strong>Analyst Comments:</strong> This is essentially bringing the &#8220;Google for malware&#8221; concept to a much broader analyst audience. Most defenders can identify a malicious hash. Far fewer can quickly pivot from a single sample to discover related malware families, backup C2 infrastructure, developer artifacts, signing certificates, and historical variants. The most interesting capability is not the sample volume&#8212;it&#8217;s the ability to search on behavioral, structural, and content-based indicators rather than simple hashes. Modern threat actors routinely recompile malware, modify packers, and rotate infrastructure. Hashes become obsolete almost immediately. Features like import table hashes, fuzzy hashes, PDB paths, certificate metadata, embedded strings, and raw byte-pattern searches provide much more durable hunting pivots.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://bbs.kanxue.com/thread-291559.htm">Kanxue</a></strong></p><h1><strong>Items of interest</strong></h1><h1><strong>Chinese Reverse-Engineer of FortiWeb 8.0 Firmware Protection, Recover Root Filesystem Decryption Process</strong></h1><p><strong>Bottom Line Up Front (BLUF):</strong> <strong>A researcher published a detailed reverse-engineering analysis of Fortinet&#8217;s newer firmware protection mechanisms, claiming to have reconstructed the process used to decrypt Forti 8.0 firmware root file systems. According to the research, Fortinet replaced earlier hardcoded ChaCha20-based protection with an RSA-wrapped key release mechanism and a heavily modified RC4-like stream cipher. The author states the protections can be reversed to recover and decrypt firmware images for analysis, potentially lowering the barrier for vulnerability research and firmware auditing.</strong></p><p><strong>Analyst Comments:</strong> This is not a vulnerability disclosure in the traditional sense, but it is still important for defenders because firmware encryption and integrity mechanisms often serve as friction points that slow reverse engineering. When researchers publicly document how those protections work, both defenders and attackers gain the ability to analyze firmware internals more efficiently. The key takeaway is that Fortinet appears to have moved away from the older model where decryption material could allegedly be extracted directly from memory. The new design reportedly introduces RSA-based key wrapping and a customized RC4-derived algorithm intended to obscure firmware contents. According to the researcher, those changes increase complexity but do not ultimately prevent determined reverse engineering.</p><p><strong>READ THE STORY:</strong> <strong><a href="https://bbs.kanxue.com/thread-291526.htm">Kanxue</a></strong></p><h1><strong>How Hackers Reverse Engineer Firmware (Video)</strong></h1><p><strong>FROM THE MEDIA: Binwalk is a powerful reverse engineering tool used to uncover hidden files, compressed data, and embedded systems inside firmware images. In this video, I&#8217;ll show you how to scan, extract, and explore firmware like a pro. We&#8217;ll also take a look at the newer Rust-based version of Binwalk now included in Kali Linux, and how it compares to the original.</strong></p><div id="youtube2-D2KEQH0dR-I" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;D2KEQH0dR-I&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/D2KEQH0dR-I?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1><strong>FortiWeb: Preventing the use of weak cryptographic algorithms (Video)</strong></h1><p><strong>FROM THE MEDIA: Fortinet is deprecating and removing support for weak cryptographic algorithms in FortiWeb as part of broader efforts to strengthen platform security and align with modern cryptographic standards. Organizations running legacy SSL/TLS configurations, outdated ciphers, or older integrations should review current deployments to ensure compatibility before upgrading.</strong></p><div id="youtube2-iV0xY2rFHIw" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;iV0xY2rFHIw&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/iV0xY2rFHIw?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don&#8217;t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com. </p>]]></content:encoded></item></channel></rss>