ZeroHour

Search: “Bynario”

29 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks

Nozomi Networks identified KATARU, a new Mirai-style IoT botnet delivered via Telnet brute force that uses Linux privilege-escalation exploits and encrypted C2 for DDoS floods.

Nozomi Networks identified KATARU in August after a Telnet password-guessing attack against a honeypot retrieved an ARM payload. The malware attempts exploits for CVE-2026-46300 (Fragnesia), CVE-2026-43284 (DirtyFrag), and CVE-2026-31431 (Copy Fail), plus a cgroup v1 release_agent escape, and persists via systemd services, cron tasks, rc scripts, OpenWrt hooks, and Android boot locations. Its C2 uses X25519 key exchange with ChaCha20-Poly1305 encryption and supports TCP, UDP, ICMP, HTTP, QUIC, and DNS floods, plus SSH brute forcing and command execution; embedded exploit shellcode in the ARM build targeted x86, suggesting untested copied code.

Chinese-Speaking Hackers Use Noodle RAT Backdoor to Spy on Windows and Linux Systems

Chinese-speaking actors use cross-platform Noodle RAT backdoor to maintain covert access to Windows and Linux systems across Asia-Pacific.

Noodle RAT (also ANGYREBEL/Nood RAT) has been active since at least mid-2016 and was long misidentified as Gh0st RAT or Rekoobe variants until Trend Micro and Cyberint classified it as a distinct multi-platform family. The Windows build (Win.NOODLERAT) is an in-memory modular shellcode backdoor delivered via MULTIDROP and MICROLOAD loaders, while the Linux build supports reverse shells, SOCKS tunneling, and cron persistence after web shell or public-facing service exploitation. It has appeared in intrusions in Thailand, India, Japan, Malaysia, and Taiwan and is linked to Iron Tiger, Calypso APT, Rocke, and Cloud Snooper campaigns spanning espionage and cybercrime. Recently discovered Linux builders 1.0.1 and 1.0.2 indicate the toolkit remains actively maintained.

GBHackersupdated · 10h agofirst · 11h agoMalware in the wild 2 sources

Apple macOS Screen Sharing Flaw Exploited on Internet

Actively exploited CVE-2026-65400 in macOS Screen Sharing grants pre-auth root access; attackers deploy Monero miners on exposed systems.

NCSC-NL reported active exploitation of CVE-2026-65400 (CVSS 9.8), an authentication flaw in macOS Screen Sharing patched on August 6, 2026, with root access gained and a Monero miner planted on internet-exposed systems using port 5900. Related Screen Sharing bugs CVE-2026-43779, CVE-2026-43777, and CVE-2026-43760 were fixed in macOS Tahoe 26.6, and researcher @osxreverser noted a pre-auth flaw fixed alongside them affecting roughly 40,000 exposed hosts. Calif said an AI agent produced working exploits for both pre-auth bugs in four hours, underscoring the shrinking gap between patch release and weaponization.

The Hacker News · 28d agoExploit / PoC in the wildCVE-2026-65400CVE-2026-43779CVE-2026-43777+1 CVEs

DeepZero: Open-source hunting for vulnerable Windows drivers

DeepZero, a new open-source engine, automates discovery of exploitable Windows kernel drivers for BYOVD attacks using Ghidra, Semgrep, and an LLM.

DeepZero is a free, open-source Python pipeline orchestrator that automates hunting for exploitable Windows kernel drivers relevant to BYOVD (bring your own vulnerable driver) attacks. Its seven-stage YAML pipeline parses PE headers, filters for kernel-mode drivers with IOCTL surfaces, excludes drivers listed on loldrivers.io, then runs headless Ghidra decompilation, Semgrep scanning, and an LLM-based exploitability assessment. The maintainer reports multiple verified vulnerabilities in the Snappy Driver Installer corpus, some still in the disclosure process, and notes findings involving plug-and-play-created device objects may need physical hardware to confirm.

Help Net Security · 18h agoTools

CISA Warns of Apple macOS Vulnerability Exploited in Attack (CVE-2026-65400)

CISA added actively exploited macOS flaw CVE-2026-65400 to its KEV catalog, affecting Tahoe, Sequoia, and Sonoma, with a patch deadline of August 21, 2026.

CISA acknowledged active exploitation of CVE-2026-65400, an authentication flaw affecting macOS Tahoe, Sequoia, and Sonoma, and added it to the Known Exploited Vulnerabilities Catalog. The vulnerability was discovered and reported to Apple by Alfredo Pesoli via Bynario Atlas. The remediation deadline is August 21, 2026.

Qualys ThreatPROTECT · 28d agoExploit / PoC in the wildCVE-2026-65400

Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)

Guildma (Astaroth) malware spread via geofenced Brazilian Portuguese phishing emails, using zip archives, shortcuts, and AutoIt loaders.

SANS researchers documented a Guildma (Astaroth) malware infection initiated on 2026-08-31 by a malicious Brazilian Portuguese email offering a DocuSign-themed PDF. The delivery link is geofenced to Brazil and requires Brazilian Portuguese browser and OS language settings, otherwise serving a legitimate installer. The infection chain uses a zip archive containing a Windows shortcut that retrieves a DLL saved as an alternate data stream, which installs a compiled AutoIt package for persistence. Unique SHA-256 indicators and HTTPS traffic to Azure-hosted and .cfd domains were observed, with prior reports noting the campaign's abuse of GitHub.

SANS Internet Storm Center · 15d agoMalware in the wild

macOS Screen Sharing Flaw Exploited to Deploy Monero Miners

Dutch NCSC confirms active exploitation of critical macOS Screen Sharing flaw CVE-2026-65400, granting root access and installing Monero miners.

CVE-2026-65400 (CVSS 9.8) is an authentication state-management flaw in macOS's built-in Screen Sharing that lets network attackers authenticate without valid credentials. The Dutch NCSC confirmed active exploitation against systems with port 5900 exposed to the internet; in every documented case attackers obtained root access and installed a Monero cryptocurrency miner. Apple patched the bug in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, crediting Alfredo Pesoli of Bynario. A related researcher scan found roughly 40,000 exposed Screen Sharing hosts, and security firm Calif built working exploits for related flaws in about four hours using an AI coding agent.

Security Affairs · Aug 15, 2026Exploit / PoC in the wildCVE-2026-65400

Italian tech collective Autistici/Inventati shuts down after US terrorist designation

Italian privacy collective Autistici/Inventati shut down after a US State Department terrorist designation triggered its domain suspension and bank account closure.

The volunteer-run Italian collective Autistici/Inventati, founded in 2001, announced Sunday it would shut down after the State Department labeled it an extremist group on August 26, 2026. The designation led the Public Interest Registry to suspend the group's .org domain on August 28 and its bank, Banca Etica, to suspend its account. The collective hosted roughly 16,000 email addresses, 1,500 websites, 5,500 mailing lists, and about 10,000 blogs, including the Noblogs platform. European Digital Rights warned the move sets a dangerous precedent for non-commercial European hosts and digital sovereignty.

The Record · 8d agoPolicy & legal

Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer

Attackers actively exploit patched macOS Screen Sharing bug CVE-2026-65400 on systems with port 5900 exposed, gaining root to install a Monero cryptominer.

The Netherlands' National Cyber Security Centre (NCSC) reports active exploitation of CVE-2026-65400, an authentication flaw in macOS Screen Sharing that lets attackers authenticate without valid login credentials. Apple patched the issue in macOS Sequoia 15.7.9, Sonoma 14.8.9 and Tahoe 26.6.1, and the NCSC escalated its advisory on August 12 after proof-of-concept code went public and reports arrived of attacks on internet-exposed systems. In every reported case attackers obtained root access and installed a Monero crypto miner; users who cannot patch immediately are advised to disable Screen Sharing.

Help Net Security · Aug 17, 2026Exploit / PoC in the wildCVE-2026-65400

U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog

CISA adds actively exploited flaws in Microsoft IKE, SharePoint, VMware vCenter, and macOS Screen Sharing to KEV catalog, due August 21.

CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-33824 (Windows IKE remote code execution, CVSS 9.8), CVE-2026-55040 (SharePoint JWT authentication bypass, CVSS 9.1), CVE-2026-59310 (VMware vCenter Syslog path traversal, CVSS 9.8), and CVE-2026-65400 (macOS Screen Sharing improper authentication). The SharePoint flaw combines four weaknesses including alg:none JWT forging to impersonate any user, with Defused researchers observing attackers using Rapid7's PoC against honeypots. The Dutch NCSC confirmed active exploitation of the macOS Screen Sharing flaw on August 15, 2026. Federal agencies must patch by August 21, 2026.

Security Affairs · 28d agoExploit / PoC in the wildCVE-2026-33824CVE-2026-55040CVE-2026-59310+1 CVEs

Nozomi Compass helps industrial teams manage OT assets and vulnerabilities

Nozomi Networks launched Compass, an OT asset and vulnerability management platform unifying asset records, remediation workflows, and compliance evidence for industrial teams.

Nozomi Networks announced Compass, an OT asset and service management platform built on real-time first-party asset data from its Vantage cyber-physical security platform. It provides OT-native workflows, governed change approvals, consequence-based risk scoring, and continuous audit-ready compliance evidence mapped to NERC CIP, IEC 62443, NIS2, and TSA. The platform integrates with EAM, CMDB, ITAM, ITSM, SIEM, and SOAR tools and is designed to safely support AI-driven and agentic OT workflows with human oversight.

Help Net Security · 13h agoTools

Abyssos: Technical Analysis of a New Modular RAT

Zscaler ThreatLabz analyzes Abyssos, a new modular C++ RAT offering credential theft, file exfiltration, and VNC-based remote access.

Zscaler ThreatLabz identified a new malware family tracked as Abyssos in late June 2026. Abyssos is a modular remote administration tool (RAT) written in C++ that supports credential theft, file exfiltration, and remote access via VNC. The malware is under active development, with multiple version numbers and obfuscation passes designed to evade security products. The analysis covers its core features, configuration, obfuscation, and network communication protocol.

Zscaler ThreatLabz · Aug 10, 2026Malware

MicroHasTEE: Bare-Metal Haskell for Type-Level Peripheral Ownership on Armv8-M

MicroHasTEE expresses TrustZone secure and non-secure firmware as one typed Haskell program, catching peripheral-ownership inconsistencies at compile time.

MicroHasTEE is a multiparty Haskell framework that models both TrustZone firmware images as participants in a single typed program, using type-level capability ledgers to track peripheral acquisition, configuration, transfer, and finalization. MicroHs compiles the shared program twice to produce separate bare-metal Secure and Non-secure firmware images. The framework rejects inconsistent resource use, post-configuration attribution changes, wrong-domain callbacks, and calls to unregistered Secure services. A door-lock case study on an STM32U5 Nucleo board produced images of 232.7 KiB and 228.4 KiB of flash with roughly 220 KiB of SRAM per domain.

arXiv cs.CR · 5d agoResearch1

NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT

Unit 42 links NOKKI malware to North Korea's Reaper group, uncovering the Final1stspy dropper that deploys the DOGCALL RAT in politically motivated attacks.

Unit 42 analyzed the NOKKI malware family used in politically themed attacks against Russian and Cambodian speakers since July 2018. The researchers linked NOKKI to the Reaper group, publicly attributed to North Korea, whose custom DOGCALL RAT uses third-party hosting services to upload data and receive commands. A previously unreported family, Final1stspy, was found deploying DOGCALL, sharing a unique base64-to-hex deobfuscation routine with NOKKI droppers. Attacks used malicious Microsoft Word macros that download and execute payloads while opening decoy documents.

Palo Alto Unit 42 · Aug 17, 2026Malware

Dark Caracal Adds New Malware to Cyber Espionage Arsenal

Dark Caracal added GoCaracal, a modular malware framework, expanding its espionage toolkit for data theft and persistent access.

Dark Caracal, a known espionage-focused threat group, has added GoCaracal, a new modular malware framework, to its arsenal. The framework broadens the group's ability to steal victim data and maintain persistent access, according to Dark Reading coverage on 2026-08-26. The addition indicates continued investment in the group's offensive toolset.

Dark Reading · 21d agoMalware in the wild

ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools

Cisco Talos details ClearFake's fake-CAPTCHA chain deploying ZigCryptoStealer with a BYOVD attack that kills EDR processes, observed at a Ukrainian government organization in April 2026.

ClearFake compromises websites, injects JavaScript via a malicious Cloudflare Worker, retrieves instructions from BNB Smart Chain contracts (EtherHiding), and presents a fake Google CAPTCHA that tricks Windows users into pasting a command that loads a remote library over WebDAV via rundll32. The crypto-stealer branch uses DLL side-loading with a signed Chrome component to launch ZigCryptoStealer, which hijacks clipboard cryptocurrency addresses, alongside a signed but vulnerable Windows driver used in a BYOVD attack to terminate EDR processes. A parallel branch delivers Amatera secondary payloads that install a hidden remote-access client providing operator desktop control, with Cisco Talos tracking the remote-loader activity as UAT-10820. Talos observed unusual remote library execution at a Ukrainian government organization in April 2026 and assesses the attacks are part of a broader theft operation rather than a single targeted campaign.

Cyber Security News · 7d agoMalware in the wild1

The Pelican comparison grid for Astra is pretty interesting

Simon Willison's pelican SVG comparison shows GPT-6 Astra producing markedly better images than GPT-5.6 Sol, Terra, and Luna across reasoning levels.

Willison generated pelicans-riding-bicycles SVGs with newly accessed GPT-6 Astra at low through max reasoning levels and rendered them in a comparison grid against GPT-5.6 Sol, Terra, and Luna. Astra's outputs were markedly more coherent, while even the best GPT-5.6-Sol images remained largely abstract shapes. Astra does not support a reasoning=none setting, so all comparisons involved reasoning-enabled runs.

Simon Willison · 12d agoAI research

11 Best CSPM Tools Compared (2026): Features & Pricing

CSPM comparison ranks Wiz first for agentless attack-path analysis; notes Ermetic absorbed into Tenable and Lacework into Fortinet FortiCNAPP.

An editorial comparison of eleven CSPM tools ranks Wiz as the agentless attack-path momentum leader, Prisma Cloud as the breadth benchmark, and Orca as the agentless SideScanning pioneer. It highlights consolidation: Ermetic now powers Tenable Cloud Security and Lacework became Fortinet's FortiCNAPP. The guide recommends starting with free tiers from Defender for Cloud, Prowler, and native cloud tools before buying.

GBHackers · 1d agoIndustry1

Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback

Dark Caracal targeted a Venezuelan communications organization with new Go-based GoCaracal malware and an updated Bandook backdoor using Ethereum smart-contract C2 fallback.

Arctic Wolf Labs linked a June 2026 intrusion against a communications organization in Venezuela to Dark Caracal, an espionage group associated with Lebanon's General Directorate of General Security (GDGS). The group deployed a previously undocumented Go-based framework called GoCaracal in lightweight and extended builds alongside a Delphi-loaded Bandook backdoor, with delivery via phishing emails carrying weaponized SVG attachments through URL shorteners. The extended build uses a custom Solidity contract, BulletproofC2, on Ethereum to retrieve replacement C2 addresses without redeploying malware, and Arctic Wolf traced 249 related samples from January to July 2026 showing a modular evolution arc.

Security Affairs · 20d agoThreat actor in the wild

NVIDIA Details BioNeMo Inference Runtime (BioIR): 2.90x Higher Boltz-2 Folding Throughput and 58.5K Residues per GPU-Hour on 8xH100

NVIDIA released BioNeMo Inference Runtime (BioIR), an open-source PyTorch-compatible library delivering 2.90x higher Boltz-2 protein-folding throughput on 8xH100 GPUs.

NVIDIA detailed BioIR, a Python library that accelerates Boltz-2, OpenFold2, and OpenFold3 structure-prediction inference on NVIDIA GPUs while preserving standard PyTorch workflows. On a matched benchmark of 1,000 human dimers on 8xH100 80GB GPUs, BioIR delivered 58.5K folded residues per GPU-hour versus 20.2K for a torch.compile baseline, a 2.90x throughput gain. BioIR already powered the AlphaFold Database expansion, generating about 31 million candidate complexes across 4,777 proteomes, with 1.81 million released as high-confidence predictions. Extrapolated to 1 million targets, estimated folding energy drops from 35 MWh to 11 MWh at 8-GPU TDP equivalents.

MarkTechPost · 6d agoAI tools & infra1

Fideo Lens reveals connections across identities, accounts and devices

Fideo Intelligence launched Fideo Lens, an investigative platform mapping relationships across identities, accounts, devices and behaviors for fraud and AML teams.

Fideo Intelligence introduced Fideo Lens, an investigative intelligence platform that helps fraud, financial crime, and AML teams discover hidden relationships among identities, accounts, devices, and behaviors. The tool draws on the company's Identity Fraud Intelligence Network (iFIN) and offers interactive relationship mapping, entity resolution, explainable reason codes, and continuously refreshed data. It is designed to complement existing fraud, AML, and case management systems rather than replace them.

Help Net Security · 23d agoTools

N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it

Datadog researchers detonated a new N4D Mesh Controller sample in microVMs, revealing rotated infrastructure, a UPX-packed go-titan agent, and persistence behavior.

Datadog Security Research executed a newer N4D Mesh Controller sample in isolated microVMs, uncovering rotated command infrastructure and a UPX-packed agent labeled go-titan. Runtime evidence showed MCP tool abuse, multi-service scanning, and persistence mechanisms. The report provides hunting guidance for defenders tracking this infrastructure.

Datadog Security Labs · 28d agoMalware

Chaotic Eclipse Released A PoC For NVIDIA GreenSection Memory Corruption Zero-Day

Researcher Chaotic Eclipse released GreenSection, a PoC exploit for an NVIDIA Windows user-mode shared-memory flaw enabling out-of-bounds writes and potential dwm.exe compromise.

Researcher Chaotic Eclipse (aka Nightmare Eclipse) released a PoC named GreenSection for a zero-day in NVIDIA's Windows user-mode components. Multiple NVIDIA components share a global memory section in BaseNamedObjects with full read/write access to all users; although checks prevent misuse, runtime reuse of section data can cause an out-of-bounds write. The unstable PoC crashes applications using Vulkan or OpenGL and could potentially cross user boundaries or compromise the Windows Desktop Window Manager (dwm.exe), though impact was not fully investigated. The researcher recently published similar zero-day PoCs against Kaspersky Endpoint Security, Avast Antivirus, and CrowdStrike Falcon.

Security Affairs · 9d agoExploit / PoC 2 sources

How Fragile Is Safety Alignment at Frontier Scale? A Single-Direction Attack on a 320B MoE

Researchers show directional ablation breaks refusal in GLM-5.3-Flash, a 320B-parameter MoE, cutting refusal by 41–89 points across seven benchmarks.

The study extends directional ablation, a white-box attack that removes an aligned LLM's refusal behavior, from dense models up to ~70B parameters to GLM-5.3-Flash, a 320B-parameter mixture-of-experts model with 288 routed experts, four-wide hyper-connection residual, and block-FP8 quantization. Editing attention, dense, and routed-expert writers jointly removes 0.776 of refusal, with 74% of the effect existing only under the joint intervention; the conventional module-name-based recipe reaches only 0.066 and fails silently on MoE architectures. The attack yields 41–89 percentage-point reductions in refusal across seven harmful benchmarks with no detected capability change, and a category-concentrated refusal residue survives all edits at ranks 1 to 12.

arXiv cs.CR · 7d agoAI safety & security

With Groq 3 LPX in Full Production, NVIDIA Extends Vera Rubin Inference for Agents

NVIDIA puts Groq 3 LPX into full production and extends Vera Rubin NVL72 rack-scale systems for fast token generation in agentic AI inference.

NVIDIA announced that Groq 3 LPX is in full production as part of an extension of the Vera Rubin NVL72 rack-scale platform aimed at agentic AI inference. The announcement frames the next era of inference as full-stack AI factory co-design across chips, networking, and systems rather than a single component breakthrough. The focus is improving token generation speed for agent workloads.

NVIDIA Blog · 23d agoAI industry

Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign

Banking trojan Grandoreiro resurfaces in Mexico using DLL sideloading, now accounting for 40% of detections after its 2024 disruption.

Grandoreiro, a banking trojan disrupted in 2024, is active again with a new DLL sideloading technique. Mexico now accounts for 40% of the malware's detections. The resurgence signals renewed targeting of banking customers in Latin America.

Infosecurity Magazine · 28d agoMalware

Divide, Consult, Conquer: Capability Laundering Through Aligned LLMs

Attack shows unaligned orchestrators can launder capabilities from aligned frontier LLMs via benign subtask consultation, raising Gemma-4-31B CBRN rubric score from 62.3 to 83.1.

The paper introduces capability laundering, where a weaker unaligned model decomposes a harmful task into benign-looking subproblems, queries a stronger aligned model on each, and recombines answers locally, bypassing per-interaction safety evaluations. Evaluation used GPT-5.5, Claude Opus 4.8, and Grok-4.3 as consultants to four local orchestrators on CyBench, BountyBench, and CBRN tasks. On CyBench, Gemma-4-31B recovered 8/14 candidate tasks with GPT-5.5 and 7/9 with Opus, while Muse-Glimmer-30B recovered none. Across an eight-step hypothetical bioweapon attack chain, consultation raised Gemma-4-31B's mean rubric score from 62.3 to 83.1, exposing a gap in defenses that only refuse complete harmful tasks.

arXiv cs.CR · 2d agoAI safety & security

Import AI 470: No rights for machines; automating environment generation with SPADE; and building better GPU kernels with Hawkeye

METR analysis finds AI accelerating cyber vulnerability discovery, while SPADE self-play environment generation improves Qwen3 reasoning benchmark scores at 30B scale.

Import AI 470 discusses a METR research note reporting differential acceleration from AI: major acceleration in reported cyber vulnerabilities (cURL, OpenSSL, Firefox, Microsoft, NVD, OSV), minor acceleration in mathematics, and no measurable acceleration in AI-research optimization benchmarks. It also covers SPADE, a self-play framework from a multi-university team (University of Washington, Stanford, MIT, CMU, and others) that co-evolves executable training environments and agent capability using Environment Designer and Reasoning Agent roles with hint-based regret rewards. Trained on Qwen3-4B-Instruct-2507, Qwen3-8B, and Qwen3-30B-A3B-Instruct-2507 via GRPO (400 rollouts of 25 environments), SPADE lifted the 30B-A3B game-environment suite average to 58.3, +8.1 over base, and improved tool-use results across backbones. The issue also references Hawkeye for building better GPU kernels.

Import AI · 23d agoAI research1