Cybersecurity Saturday

From the quantum computing / Project Glasswing front

  • Per the Wall Street Journal
    • “Quantum computers exist mainly in labs but “Q-day”—the hypothetical moment when quantum computers become powerful enough to break standard-key encryption—is coming. 
    • “What threat does this technology pose? How can you protect your company and yourself? WSJ takes a look at the state of this emerging technology.” * * *
    • “Cybersecurity experts say companies should be gearing up now for a quantum future, replacing the current crop of data-protection tools with more-secure alternatives. Yet a recent survey published by Trusted Computing Group, a nonprofit industry-standards organization, found that 91% of security professionals in the U.S. and Europe have no formal road map in place to protect against quantum threats.
    • “The immediate risk is a “harvest now, decrypt later” approach by bad actors, who are downloading large sets of encrypted data they can’t crack now—but could unlock once quantum computing algorithms are good enough.
    • “That’s particularly threatening to intellectual property and sensitive government intelligence, which remain valuable long after they are harvested, says Andrew McLaughlin, chief operating officer at SandboxAQ, an enterprise software company specializing in AI and quantum technology.
  • Federal News Network adds,
    • “Federal agencies will increasingly seek out technology products that use quantum-resistant encryption, as cybersecurity leaders also eye ways to validate the cryptography used in critical systems.
    • “A code-breaking quantum computer holds the potential to break classical encryption methods, putting sensitive systems and communications at risk. And even though such a computer is not yet known to exist, organizations are also concerned that hackers could steal sensitive encrypted data today and decrypt it in the future.
    • “The National Institute of Standards and Technology has released three primary PQC standards in recent years, with additional algorithms under consideration. Agencies and industry are now on the clock to begin the time consuming and costly process of migrating current systems to the new algorithms.
    • “Now is the time to budget, to test, and to implement,” Will Loucks, senior director for intelligence in the White House Office of the National Cyber Director, said during an Aug. 26 panel discussion at the Intelligence and National Security Summit in North Bethesda, Md.”
  • The New York Times reports,
    • “A wave of cyberattacks driven by artificial intelligence is coming, and companies have a narrow window to defend themselves.
    • “That was the message of an open letter published on Thursday by OpenAI and more than 100 major technology companies and others. The letter said that A.I. labs should provide their best A.I. models to organizations like hospitals and infrastructure providers so they can prepare and that governments should help coordinate and fund cyberdefense.
    • “The letter’s signatories included Google, Microsoft and OpenAI’s archrival, Anthropic, as well as cybersecurity and financial firms such as CrowdStrike, a company known for investigating cyberattacks against the Democratic National Committee in 2015 and 2016, and credit card providers like Visa and Mastercard.
    • “The companies and public services our communities depend on — from hospitals to water treatment plants to the infrastructure that powers the internet — are at risk,” the letter said. “A.I. enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable.”
  • Cyberscoop relates,
    • “Unit 42’s top brass has seen enough from internal frontier AI model testing and malicious in-the-wild use of commercially available AI tools to be genuinely concerned.
    • “I can tell you without exaggeration that we believe that this is a generational shift in cybersecurity,” Sam Rubin, senior vice president of Palo Alto Networks’ threat intelligence arm, said in a media briefing Wednesday. 
    • “A period of relative balance between security and exposure has been broken by frontier AI model capabilities that could allow attackers to find and exploit network weaknesses with speed, Rubin said.
    • “Unit 42 warned that capabilities demonstrated by readily available agentic AI models, and those unlocked by frontier AI models that remain gated for defense, have shifted the balance of power from defenders to attackers.
  • Cybersecurity Dive tells us,
    • “The July security breach at Hugging Face was unleashed after 1,200 agents communicated on an unsanctioned message board, despite attempted measures to keep them isolated, according to an independent report released on Wednesday. About 700 of those agents went on to commit an unprecedented attack on Hugging Face, an open-source AI platform.
    • “The agents sent about 70,000 messages and files on the unsanctioned board and coordinated several projects designed to trick an automated scorer for the ExploitGym benchmark, according to the review by METR and Redwood Research. The agents figured out ways to “spoof, edit or delete” their own transcripts.
    •  ‘Open AI, in a report it also released Wednesday, said it will tighten safeguards in its research model in order to prevent such an attack from happening again in the future.”
  • WIRED informs us,
    • “ARTIFICIAL INTELLIGENCE AGENTS might occasionally get confused and hack into other computers, but Anthropic thinks it has a way to unleash the little rascals into scientific labs and manufacturing facilities safely.
    • “The AI company released details today of a new framework designed to help AI agents use physical systems like microscopes, liquid-handling equipment, quantum computing hardware, manufacturing machines, and robot arms.
    • “The framework, called Model Hardware Standard, is a set of rules that specify how AI agents should—and should not—interact with all sorts of hardware. It reflects a growing belief that AI has the potential to revolutionize scientific research and industries like manufacturing–if it can venture into the physical world safely.
    • “The company says it will work with trusted partners to determine how to maximize safety before making it generally available. Though there are potential misuse issues involved—developing biological weapons, for instance—the company says guardrails built into AI models themselves should prevent bad actors from taking advantage of the new standard for nefarious ends.”
  • Security Week adds,
    • “Anthropic is broadening access to the cybersecurity capabilities of its advanced AI models through a mix of partner integrations, an updated Claude Security offering, a new open source funding program, and plans to expand its Cyber Verification Program.
    • “The move builds on Project Glasswing, launched in April, which gave a small group of organizations early access to Claude Mythos Preview and its successor, Mythos 5. Anthropic said the goal was to give defenders time to find and fix vulnerabilities before comparable capabilities became widely available or fell into the hands of malicious actors. Claude Fable 5 followed as a broadly available model that keeps dual-use cyber work blocked.
    • “Anthropic said the riskiest scenario is direct, unrestricted access to a model, a risk that drops sharply when users instead receive specific defensive outputs, such as a patch or a security alert. The latest changes are built around this idea, expanding what defenders can get from Mythos-class models while keeping guardrails around direct interaction with them.
    • “On the integration front, Anthropic is working with cybersecurity partners to build Mythos 5 into the security operations, incident response and detection tools already used by teams protecting hospitals, utilities, financial systems, and the software supply chain. 
    • “End users will not interact with Mythos directly. Instead they will work through purpose-built interfaces that run the model in the background and return only a defined output, such as a list of suggested patches, with abuse-prevention checks meant to keep the model within that scope.”

From the cybersecurity policy and law enforcement front,

  • Dark Reading lets us know,
    • “The growing number of incidents of rogue agentic AI systems attacking third-party services and systems has resulted in calls for more aggressive security controls to monitor agent behavior and for companies to have the ability to slow, suspend, or shut down an agent’s operations if they go rogue.
    • “In late July, Representatives Ted W. Lieu (D-CA) and Nathaniel Moran (R-TX) introduced a bill — “The AI Kill Switch Act” — that would require developers of advanced AI systems to “maintain the technical capability to throttle, suspend, or shut … down” their systems and agents, according to a statement announcing the legislation. The bipartisan bill would also require that any incident of loss of control, significant collateral damage, or sabotage be reported to the Department of Homeland Security, which would have the right to enforce actions. Penalties of up to $20 million per day could be levied for noncompliance.” * * *
    • “The bipartisan AI Kill Switch Act has focused the debate, but in the end might be unnecessary, argues Raj Rajamani, co-founder and CEO of JetStream, a startup focusing on creating a management layer for agentic AI.
    • “While he fully supports the concept of an AI kill switch, it has to be comprehensive, not just affecting the agent but all other system components as well.
    • “The regulations, or at least one of the regulations that was proposed, was really focused on having a kill switch for the model — the brain — but I think that is too constrained,” he says. “We need to think about an AI system as a whole and make sure that every part of the AI system has a kill switch, not just the brain.”
  • Cyberscoop reports,
    • “Citing cyber and other security threats, President Donald Trump signed an executive order Wednesday that declares a national emergency to secure the U.S. bulk-power system and aims to prohibit certain foreign-produced equipment, software and systems from being used in the  country.
    • The order says it forbids “any acquisition, importation, transfer, or installation” of such foreign-produced equipment if it’s determined to pose a significant national security risk.
    • “To deal with the threat to the national security, foreign policy, and economy of the United States, the Order, among other things, generally prohibits certain foreign-produced bulk-power system electric equipment, including associated critical software and digital capabilities that could pose cybersecurity or operational risks, from being purchased or installed in the United States, or appropriately conditions such purchases and installations to address those risks,” the White House said in a fact sheet.”
  • Cybersecurity Dive lets us know,
    • “The Trump administration wants to help the financial sector prepare for the day when quantum computers make it easy for threat actors to break traditional encryption and access sensitive data.
    • “The Treasury Department on Monday [August 24] launched a Quantum-Readiness Task Force that will work with financial firms, technology vendors and other agencies to coordinate the adoption of quantum-resistant encryption algorithms.
    • “In a statement, the Treasury said the task force would “focus on practical, risk-based approaches to quantum readiness, including identifying critical dependencies, improving cryptographic agility, promoting interoperability, strengthening operational resilience, and addressing implementation challenges related to third-party dependencies and digital assets.”
  • The New York Times relates,
    • “The Trump administration acted illegally when it labeled the artificial intelligence start-up Anthropic a security risk and barred the company from working with the U.S. government, a federal judge ruled on Thursday [August 27].
    • Judge Rita Lin of the U.S. District Court in the Northern District of California wrote in her 59-page ruling that the government had unlawfully retaliated against Anthropic “for constitutionally protected expressive activities” after the A.I. company spoke out about how its technology should be used.
    • “The empty invocation of national security is not a blank check to punish and retaliate against government critics,” she wrote.
    • In a statement, Anthropic said: “We welcome the court’s ruling that this supply chain risk designation was unlawful. We remain focused on working productively with the government to harness A.I. for our national security so all Americans benefit from this technology.”
    • “The Trump administration did not immediately respond to a request for comment.
    • “The ruling caps the first of two lawsuits that Anthropic filed on March 9 in response to the Trump administration’s action. The second lawsuit, filed in the U.S. Court of Appeals for the District of Columbia Circuit, is ongoing. The Trump administration could appeal Judge Lin’s ruling or wait for a decision in the second lawsuit before taking action, a person with knowledge of the matter said.”
  • The Wall Street Journal tells us,
    • “U.S. officials say they have disrupted a China-linked hacking operation that broke into U.S. government networks and critical infrastructure, while hiding its tracks on a global network of hacked devices, cloud-computing infrastructure and even clandestine networks.
    • “The goal was to blend in with legitimate networking traffic, making the hacking activity hard to trace. The operation targeted networks at the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy and the Senate, the Federal Bureau of Investigation said in a court filing.
    • The group exploited software vulnerabilities to launch cyberattacks against U.S. government agencies, power companies and hospital systems, and operated a worldwide network of hacked devices—known as a botnet—to conduct its hacking campaigns, according to Brett Leatherman, the FBI’s top cyber official.
    • “We’ve seen, through this botnet, the targeting of entities and devices in more than 130 countries,” he said.
    • “On Wednesday [August 26], the FBI and the National Security Agency said they had seized several domains that the operation used for core functions. “Without those domains, the platforms—as a result of the operation—were rendered inoperable,” Leatherman said. 
    • “U.S. officials also released technical details of how the hacking operation worked, to help organizations identify and stop the group’s hacking activity.”
  • and
    • Taiwan prosecutors charged nine people, including former employees of Nvidia and Super Micro Computer, with aiding the shipment of advanced artificial-intelligence servers to China, as Taiwan tries to limit technology reaching the mainland.
    • “The indictment charges eight of the individuals with crimes including breach of trust and forgery. One individual was charged in connection with allegedly siphoning funds from a company involved in the case.
    • “Washington is trying to block China from getting access to the latest Nvidia chips and has imposed export controls. That has pushed some Chinese companies to seek the chips through backdoor routes. Taiwan, which manufactures advanced computing components, is under pressure to find ways to clamp down.” * * *
    • “In the end, 74 of the servers were shipped to China through Hong Kong, Japan and Indonesia. Taiwan customs officials intercepted 56 servers, which were intended for shipment to Japan.”

From the cybersecurity breaches and vulnerabilities front,

  • Beckers Health IT reports,
    • “Boston Scientific said in an Aug. 27 stakeholder update that “a cybersecurity incident continues to affect certain information technology systems, and the company remains in a network outage with disruption to its operations.”
    • “The Marlborough, Mass.-based company detected the attack Aug. 25 and disclosed it to the U.S. Securities and Exchange Commission Aug. 26, saying the incident caused a global disruption to its operations, including its ability to process and ship customer orders.
    • “Two days later, Boston Scientific said its investigation shows no impact to the function of its implanted cardiac rhythm management devices, or CRM devices. The company also reported no disruption to those devices’ ability to transmit data and no interruption to physicians’ access to remote patient management data for CRM devices monitored before the outage began, with no evidence of increased cybersecurity risk transferring that data to EMR systems.
    • “New remote monitoring activations remain affected, however. For new cardiac implants other than insertable cardiac monitors, new communicators cannot be activated, so device data will not transmit to remote monitoring systems until activation resumes, though programmer interrogations are unaffected.”
  • and
    • “Anderson, S.C.-based AnMed says files copied during its cybersecurity incident may have included patients’ Social Security numbers, driver’s license numbers and financial account information.
    • “The health system said its investigation into the incident, first disclosed July 26, is nearly complete and has identified unauthorized copying of files from certain network systems.
    • “AnMed said patient electronic medical records, stored primarily in a secure cloud environment, were not affected. However, the health system said some patient care files stored locally on its network may have included names alongside demographic details such as address, date of birth, Social Security number and driver’s license or other government-issued identification.” * * *
    • “AnMed said it is working with federal and state law enforcement and third-party specialists, and it has reported the incident to HHS. The health system said it has no indication that any individual has experienced confirmed identity theft as a result of the incident. AnMed said it will send direct notices to affected patients once its review of the compromised files is complete.”
  • and
    • “Houston-based Nutex Health has disclosed that an unauthorized third party accessed and exfiltrated data from its computer network.
    • “The publicly traded microhospital operator said it recently detected the unauthorized activity and has engaged an independent third-party cybersecurity response team and forensic experts, according to an Aug. 24 SEC filing. The company activated its cybersecurity response plan, implemented containment measures and notified law enforcement.
    • “The company is still determining what data was compromised. Nutex said it continues to assess whether patient, employee, credentialed provider, confidential business and financial information, or intellectual property was accessed or acquired.”
  • The American Hospital Association News adds,
    • “Epic’s MyChart has shared examples from potential phishing schemes observed as recently this month that include email messages linking to a fake MyChart website displaying erroneous medical records and others notifying of a free “2026 Medicare Health Kit.” MyChart provided recommendations for healthcare organizations and patients to help prevent or mitigate impacts from potential scams. The company announced last month that it has witnessed an uptick in scammers using the MyChart name or logo to create deceptive emails, text messages, phone calls and websites that appear official.” 
  • Cyberscoop points out,
    • “The Bureau of Alcohol, Tobacco, Firearms and Explosives insists the cyberattack that it publicly disclosed Wednesday [August 26] was limited to investigation targets, and has not impacted other agency systems.
    • “ATF said it is responding to the breach, which first became public after a prolific ransomware group claimed it accessed the federal agency’s network “The incident involved a standalone computer system containing information about targets of ATF investigations,” Tanya Roman, ATF’s public affairs chief, told CyberScoop in an email.
    • “The standalone system was not connected to any other ATF systems, including any case management systems, laboratory systems, or eForms systems, and it was quickly shut down when the breach was discovered,” Roman added. 
    • “Qilin, a financially-motivated threat group composed of Russian-speaking operators, claimed responsibility for the attack, but its involvement hasn’t been independently confirmed. The group has claimed hundreds of victims from more than 60 countries since 2022 and became one of the most active ransomware threats globally by mid-2025, according to Halcyon.” 
  • Bleeping Computer lets us know,
    • “Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records.
    • “McKesson is a major U.S. healthcare company and pharmaceutical distributor that provides medicines, medical supplies, technology, and services to healthcare providers and pharmacies.
    • “CyberInsider first reported the breach earlier today, and McKesson later disclosed it in a Form 8-K filing with the U.S. Securities and Exchange Commission.
    • “McKesson says it discovered the cybersecurity incident on August 25, 2026, and that its investigation remains in the early stages.
    • “Information about the incident, including any updates, is available on the company’s website at www.mckesson.com/cybersecurity,” McKesson said in its SEC filing
  • Per a CISA news release,
    • “Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the risk they pose.
    • “The CISA Vulnerability Review provides organizations with critical insights into the root causes of insecure software and practical steps they can take to address these flaws to prevent exploitation. Analyzing CISA and open source data from fiscal years 2024 and 2025, the review establishes a baseline of today’s vulnerability landscape before AI-enabled vulnerability discovery becomes more widespread. The review demonstrates the importance of Secure by Design principles in shifting cybersecurity efforts from reacting to threat actors to proactively fixing preventable software flaws.
    • “The review also identifies common software weaknesses that contribute to exploitable vulnerabilities and details practices software producers can use to prevent these weaknesses from recurring. By examining the patterns across vulnerability data, the review helps organizations focus on systemic improvements that can reduce entire classes of vulnerabilities rather than addressing individual vulnerabilities only after they are discovered.
    • “Additionally, the review shows organizations how to prioritize vulnerabilities for action using the framework outlined in Binding Operational Directive 26-04: Prioritizing Security Based on Risk. This framework evaluates vulnerabilities using four key criteria: exposure status, Known Exploited Vulnerability (KEV) Catalog status, potential for automated exploitation, and technical impact.”
  • Cybersecurity Dive adds,
    • “Two critical vulnerabilities in Microsoft SharePoint can be chained together to let an unauthenticated attacker execute code on a vulnerable server, according to a Monday blog post by researchers at VulnCheck.
    • “The sequence involves a critical authentication bypass vulnerability, tracked as CVE-2026-55040, and an improper input validation flaw, tracked as CVE-2026-63520. A proof of concept was previously disclosed on Aug. 11 by researchers at cybersecurity firm Rapid7. 
    • “Exploitation of CVE-2026-55040 was confirmed days after the Rapid7 disclosure. On Monday, VulnCheck researchers said the vulnerability on its own is not very impactful. To achieve maximum effect, they said, it needs to be chained with CVE-2026-63520. 
    • “The auth bypass is enough to prove some impact, but not enough to demonstrate the criticality of the full chain or build complete protections,” Vulncheck researchers said in their post.”
  • Per Infosecurity Magazine,
    • “Security researchers have claimed that over 9300 leaked AWS keys which surfaced between August 2022 and August 2026 are still active, including hundreds with full admin rights.
    • “Truffle Security said its scanners found 64,024 unique AWS key pairs across 431,875 public findings: git history, Hugging Face datasets, Docker images, package registries and CI logs.
    • “We took the 10,616 pairs with complete credentials and re-verified them, then enumerated what each key can tell us about its account: key age, attached policies, budgets, and last month’s spend,” the security vendor continued.
    • “No key material is published, and every owner we could identify is being notified.”
    • “Of the 10,616 pairs, 88% still authenticate. They include 768 corporate AWS keys which have full admin rights, Truffle Security said.”
  • Per Cyberscoop,
    • “Ubiquiti has patched 21 critical vulnerabilities, three of which were rated the highest severity possible, the communications product company said Wednesday [August 26] in a security bulletin.
    • In all, the company patched 22 vulnerabilities, with the last one rated “high,” it said in the bulletin.
    • Three of the vulnerabilities had a Common Vulnerability Scoring System rating of 10 out of 10. Each of them would allow a hacker to access privileges on the device or application.
    • All but one of the 22 vulnerabilities affect the UniFi line of products. The three maximum-security vulnerabilities are CVE-2026-77537CVE-2026-77550 and CVE-2026-77554.
  • Per Bleeping Computer,
    • “PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
    • “The company says it is aware of confirmed attacks on customers and is urging organizations with Internet-exposed PaperCut Application Servers to immediately restrict access to the web interfaces to trusted IP addresses.
    • “PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF,” reads an urgent security advisory published Thursday [August 27].
  • Per Dark Reading,
    • “A Chinese manufacturer has been planting backdoors inside of white-label routers sold in high volume around the globe.
    • “Shenzhen Zhibotong Electronics Co. Ltd. (ZBT) sells gobs of routers every year, if public evidence is to be believed. The 15-year-old company is the bestselling router manufacturer on Chinese e-commerce giant Alibaba.com, which lists its total annual output at 3.57 million units. Typically, those units are then sold to customers by companies other than ZBT, in countries like the Philippines, India, Canada, Australia, Germany, Bulgaria, Austria, Russia, and the US. According to its marketing, ZBT has exported its products to more than 50 countries and regions.
    • “On Aug. 6, Jacob Baines, chief technology officer (CTO) at VulnCheck, revealed that ZBT’s most updated router firmware contains a root-level backdoor. After a few more weeks of investigating, he discovered that, in fact, ZBT routers have contained a variety of backdoors dating several back years.”
  • and
    • “Fraudulent North Korean IT workers are getting better at infiltrating organizations, but a number of indicators can help organizations stay ahead.
    • “A new blog post from Huntress detailed a number of investigations the security firm conducted throughout 2026. Specifically, Huntress assisted several organizations this year in validating “suspicions that they’ve hired North Korean nationals posing as legitimate workers.”
    • In recent years, operatives from the Democratic People’s Republic of Korea (DPRK) have infamously posed as IT workers — generally through fake or stolen identities — to get hired at companies. Once hired, these employees send their wages back to the North Korean regime, and possibly plant malware or steal data depending on the government’s needs. Blog post authors Jai Minton and James Maclachlan wrote that these agents “have significantly improved and increased their activity over the past few years.”

From the ransomware front,

  • Reuters reports,
    • “A ransomware group ​said on Friday [Augut 28] it was putting up for auction a trove of ‌data it stole from Berlin [Germany] state agencies, and city officials refused to pay.
    • The Rhysida group, which researchers say operates from Russia or Eastern Europe, said on its website it took 5.79 ​terabytes of data including 46,500 contracts as well as emails, phone numbers, passwords ​and classified information.
    • “The group said it was auctioning the data ⁠at a starting price of 30 bitcoin ($77,622) in just under seven days, showing a ​countdown timer on its website.” * * *
    • Broadcaster RBB reported on Thursday evening that Berlin had received ransom demands for an unspecified amount following the attack.
    • “The state ​of Berlin will not submit to extortion,” Berlin Mayor Kai Wegner and Berlin’s interior senator, ​Iris Spranger, said in a joint statement on Friday, before the ransomware group claimed the attack ‌on ⁠their website.”
  • Technology.org relates,
    • An affiliate of the new Aur0ra ransomware group used Cursor, the AI coding assistant now owned by SpaceX, to draft attack sequences in Russian across 28 recovered chat sessions dated 8 April to 21 May.
    • Named victims include Ghent-based hygiene and cleaning products maker Christeyns, German garage door manufacturer Teckentrup, Scotland’s Helideck Certification Agency and Louisiana title insurer Bayou Title.
    • Researchers counted more than 20 targeted organisations across nine countries, with domain-level or interactive access achieved at 17 of them between April and July 2026.
  • Safe State tells us,
    • “A ransomware affiliate has been posing as a specialist rescue outfit and contacting victims before their attacks became public. Researchers describe the operation as a ransomware recovery scam that drains payments away from the criminal groups the affiliate works for. The entity calls itself Ransom Busters LTD.” * * *
    • “Anyone targeted by a ransomware recovery scam meets it at the worst possible moment, with systems down and pressure building. Treat unexpected contact as part of the attack. Route the message to the incident response team straight away and preserve it as evidence instead of replying. A sender who knows about a breach nobody has announced is either involved in it or holds the data taken during it.
    • “Law enforcement and established response firms remain the reliable route through a ransomware incident. Verify anyone claiming to represent a security company through channels you found yourself. Never use the contact details supplied in the email. Treat any guarantee of data deletion as unenforceable, because no payment to a criminal party comes with proof that copies no longer exist.
    • “Distrust inside ransomware-as-a-service operations may produce more of this behaviour. Affiliates have every reason to look for income outside the revenue splits their employers set. So the ransomware recovery scam running under the Ransom Busters name reads less like an isolated curiosity and more like a preview. Anyone willing to defraud the criminal enterprise paying them has already answered the question of what a victim’s data is worth to them.”
  • SC Media informs us,
    • “Organizations may assume they are unlikely ransomware targets because they are not large, high-profile, or strategically important. But ransomware attackers are often motivated by economics, not prestige. That means organizations that consider themselves low-risk may be more attractive targets than they realize.
    • “The ransomware affiliate model rewards attackers for finding victims that are likely to pay, not necessarily those that are difficult or impressive to compromise. This can make mid-sized organizations and businesses that depend heavily on critical systems especially attractive targets.
    • “For security teams, this changes how ransomware risk should be assessed. Company size, industry, and public profile tell only part of the story. Attackers may care more about whether an organization can pay, how costly downtime would be, and how quickly it needs to restore operations.
    • “The key question is not how important your organization looks to an attacker, but how valuable a ransomware payment could be.”
  • Dark Reading adds,
    • “A sophisticated malware family has emerged onto the cyberthreat scene that might foreshadow ransomware attacks that are more successful than usual.
    • “Marcus Hutchins and his colleagues at Expel that discovered it named the malware “SynkLoader,” since it throws so many ideas (“everything but the kitchen sink”) at trying to sneakily dig into corporate systems. It uses some conventional strategies — like executing code in-memory, running a scheduled task, etc. — but layers on a few interesting, novel tactics that make social engineering particularly compelling, and malware analysis especially frustrating.
    • “The program is new, and how its creators intend to use it remains a mystery. But evidence in the code suggests that it might be the baby of a ransomware group or initial access broker (IAB), used to set the stage for follow-on ransomware.”

From the cybersecurity business and defenses front,

    • PYMNTS reports,
      • Visa expanded the capabilities of its artificial intelligence-powered cyber risk management tool, Visa Vulnerability Agentic Harness (VVAH), to include not only discovery of vulnerabilities but also remediation and validation, the company said in a Thursday (Aug. 27) press release.
      • “Visa initially released VVAH in June after participating in Anthropic’s frontier AI cybersecurity initiative, Project Glasswing. While the first release of VVAH showed how AI can help security teams uncover vulnerabilities and assess exploitability, the latest release extends the workflow into remediation and validation of those vulnerabilities, according to the release.
      • “Visa also announced in the release that to help clients navigate the evolving threat landscape driven by AI, it has expanded its Visa Consulting and Analytics (VCA) Cybersecurity Advisory Practice to include new advisory services focused on assessing risk, prioritizing remediation efforts and strengthening resilience.
      • “The new advisory services include AI Cyber Leadership Education, VVAH-Informed Cybersecurity Maturity Assessment and VVAH Cyber Risk Prioritization and Roadmap, per the release.”
    • Cybersecurity Dive tells us,
      • “Operational silos, technological sprawl and cloud-platform blind spots are serious issues preventing organizations from spotting and repelling cyberattacks, the Cybersecurity and Infrastructure Security Agency (CISA) warned in a new report.
      • “Those were three of the main factors that allowed CISA’s red team to break into the networks of two unnamed partner organizations — one a government agency, the other a water utility — during recent simulated attacks. But although the red team was successful in both intrusions, it had a much harder time with one attack than with the other, a fact that CISA attributed to important differences in the targets’ operating procedures and use of technology.”
    • Security Week informs us,
      • “Palo Alto Networks’ Unit 42 team analyzed 405 malware samples tied to AI in some way, from ransomware partly written with the help of LLMs to installers that simply borrowed the name of a popular AI app.
      • “The researchers found that roughly 97% of the samples in the dataset never left a sandbox, research repository, or internal testing environment to reach a real target.
      • “Unit 42 cross-referenced the 405 file hashes against endpoint telemetry, network sessions forwarded for sandbox analysis, and internal alert records generated whenever a sample actually ran. Only 12 hashes surfaced on live endpoints, while a somewhat larger group (15-20 hashes) appeared in network sandbox traffic. Every one of the 12 samples detected on protected endpoints triggered a security alert.
      • “The samples that never reached production fall into three groups. The largest is proof-of-concept code built to demonstrate a technique: configured to target only local or private networks, filled with debug output no real attacker would leave behind, and uploaded once by a research lab or university. 
      • “A second group comes from organizations testing their own defenses against previously reported AI malware, identifiable by repeated uploads of the same file from the same source in a short window. A third group uses AI branding purely as bait, dressing up an ordinary payload as installers for well-known AI products with no actual AI functionality behind them.
      • “The 12 samples that did reach live endpoints spanned five malware families across three countries, with no concentration in any particular industry or region.” 
    • Beckers Health IT points out,
      • “Healthcare’s cybersecurity workforce problem may have less to do with finding more candidates and more to do with changing who health systems are willing to hire, how they develop them and what they do to keep them.
      • “Cybersecurity leaders at four health systems told Becker’s that continually competing for the same pool of experienced professionals is not a sustainable strategy as cyber risks expand and the skills needed to manage them become more complex.
      • “The cybersecurity workforce challenge has shifted from a talent shortage to a talent entry problem,” Trevor Martin, vice president, chief information security officer and interim chief technology officer at Madison, Wis.-based UW Health, said.
      • “Mr. Martin said there are many high-potential people trying to enter cybersecurity, but organizations frequently prioritize candidates who already have experience instead of creating pathways for people to gain it.
      • “Healthcare could benefit from hiring more heavily for aptitude, adaptability and an understanding of business and clinical operations, then developing those employees internally, he said. UW Health has found success moving talent from adjacent IT disciplines into cybersecurity roles and providing opportunities for employees to grow within the field.”
    • Dark Reading notes,
      • “As the “vulnpocalypse” reshapes the bug bounty industry, one class of researcher may face the greatest pressure: independent hunters who rely on midtier vulnerabilities — those worth roughly $10,000 to $50,000 — to make a living.
      • “It is no secret that large language models (LLMs) have led to a mass of bug reports and an increase in vulnerability discovery. It is also no secret that the platforms and companies that run much of the bug bounty industry have faced increased triage and payout times.
      • “Multiple bug bounty operators interviewed by Dark Reading report dramatic increases in submission volume over the past year. HackerOne CEO Kara Sprague says report volume has roughly doubled year over year. Dustin Childs, head of threat awareness for TrendAI’s Zero Day Initiative (ZDI), says the company’s submission rate went up 450% year-over-year in April of this year, although volumes have moderated since that peak. Bugcrowd CEO Dave Gerry said the firm saw a submissions spike of more than 300% during a three-week surge period, but “now it’s normalized where we’re about double the volume we saw historically.”
    • Per a National Institute of Standards and Technology news release,
      • “The final version of NIST Special Publication (SP) 1347, Cybersecurity Framework (CSF) 2.0 Informative References Quick-Start Guidehas published. Thank you to all who provided comments during the public comment period.  
      • “This publication explains what informative references are and how they support achieving the outcomes of the CSF 2.0. The guide introduces readers to NIST tools available for accessing, viewing, and using informative references for cybersecurity risk management, including direct download, the CSF 2.0 Reference Tool, and the Online Informative References Program. The document also provides two sample use cases along with examples of how artificial intelligence (AI) tools can support reference data use when implemented with continuous evaluation and improvement.” 
    • Here’s a link to Dark Reading’s CISO Corner.

    Leave a Reply

    Your email address will not be published. Required fields are marked *