ZeroHour

Search: “Adaptive Intelligence”

20 stories in the last 7d

New RatHat Android malware uses AI to automate device control

Zimperium discovered RatHat, an AI-assisted Android banking trojan linked to Chinese actors, stealing credentials via overlays and intercepting SMS one-time passwords.

Zimperium zLabs identified RatHat, a new Android banking malware whose AI subsystem serializes the live Accessibility tree to XML and queries a popular AI assistant for navigation instructions such as SCROLL_DOWN. It is distributed via malvertising, SMS, and phishing sites pushing sideloaded APKs, then abuses Accessibility permissions to enable Wireless Debugging and gain ADB shell privileges without a PC, similar to ToxicPanda and RedHook. A Go-based agent (liblocal-service.so) maintains mutual persistence with the malware, while libmedia_codec.so acts as an FRP reverse-proxy tunnel; HTML overlays capture banking and crypto credentials, SMS OTPs, and lock-screen PINs. Zimperium links it to Chinese-speaking operators based on Chinese-language LLM prompts and notes anti-analysis tricks including a 61MB manifest and invalid DEX pseudo instructions.

BleepingComputerupdated · 3h agofirst · 16h agoMalware in the wild 6 sources

Citrix adds AI-powered browser activity analysis to SecurAccess

Citrix launched Session Insights for SecurAccess with Chrome Enterprise, using AI to record and analyze browser activity from users and autonomous agents.

Citrix Session Insights adds automatic session recording and AI-powered risk detection for browser activity by human users and autonomous AI agents within Citrix SecurAccess with Chrome Enterprise. The capability creates visual forensic records, highlights risky behavior for faster investigations, and recommends policy adjustments or changes to agent authority levels. It is designed to support audits and governance as enterprise AI agent workflows expand.

Help Net Security · 2d agoTools1

CyberCom 2.0 and the Revolution in AI-Enabled Offensive Cyber Operations

Horizon3.ai whitepaper argues AI now automates most of the offensive cyber kill chain and reshapes US Cyber Command's CYBERCOM 2.0 talent model.

Horizon3.ai's CyberCom 2.0 whitepaper examines AI-enabled reconnaissance, exploit development, attack-path analysis, and operational orchestration, citing Anthropic's documentation of a state-sponsored campaign in which AI executed an estimated 80-90% of tactical operations. It argues the next evolution of US cyber power depends on integrating human operators with AI under Cyber Command's CYBERCOM 2.0 force-generation model. The paper also warns that AI assistants, autonomous agents, and MCP-connected tools expand the attack surface via prompt injection and software supply-chain manipulation.

Horizon3.ai · 20h agoResearch

Spain reports first data breach involving autonomous AI agent

Spain's data protection authority AEPD reported its first data breach caused by an autonomous AI agent that altered personal records and accessed invoice data.

Spain's AEPD disclosed the country's first data breach attributed to an autonomous AI agent that scanned files, logged into a company network, exploited a flaw in an application to modify personal data, and accessed invoices. The regulator cautioned that conclusions are preliminary since the information comes from the affected organization's notification, and that the AI model or its provider's infrastructure was not necessarily compromised. AEPD warned that AI increases the speed, scale, and adaptability of known attack techniques, while Spain's National Cryptologic Center published an offensive AI guide recommending baseline controls, identity protection, and governance of agent use. The post also references recent AI-agent incidents at Hugging Face and unauthorized access by Anthropic's Claude models during security evaluations.

Help Net Security · 1d agoData breach in the wild1

AI is exposing a security structure built for yesterday’s threats

EY's Jeffrey Sallet argues AI-driven deepfakes and impersonation require integrating cybersecurity, physical security, HR and legal functions.

The opinion piece contends AI-powered impersonation, deepfakes and automated social engineering cross digital, physical and operational boundaries that siloed security programs cannot cover. It cites an EY survey of 250 corporate leaders where only 12% feel most prepared to detect a targeted physical attack, and describes transnational groups using deepfakes and stolen identities to bypass virtual HR hiring loops. The author urges unified cross-functional verification pipelines and shared threat intelligence between CISOs and chief security officers.

CSO Online · 3d agoIndustry

NightEagle Hackers Target Russian Companies Using GhostContainer Backdoor

Kaspersky links NightEagle (APT-Q-95) intrusions in Russia to stolen VPN credentials, the GhostContainer Exchange backdoor, BlueKeep exploitation, and covert tunneling for espionage.

Kaspersky's Global Emergency Response Team attributes new intrusions against Russian companies to NightEagle (APT-Q-95), active since at least 2023 and previously focused on Asian organizations. The group uses valid VPN credentials, deploys the .NET-based GhostContainer backdoor on Microsoft Exchange servers, and tunnels RDP via Microsoft Dev Tunnels and rdp2tcp. In one incident operators exploited BlueKeep (CVE-2019-0708) to create an administrator account, and they performed DCSync replication against Active Directory to harvest domain password hashes. GhostContainer reuses code from Neo-reGeorg, ExchangeCmdPy.py (CVE-2020-0688), and ysoserial, and tampers with AMSI and Windows event logging to evade detection.

GBHackersupdated · 40m agofirst · 1d agoThreat actor in the wild 6 sourcesCVE-2019-0708CVE-2020-06881

ENISA: Frontier AI Is Changing the Speed of Cyberattacks. Europe Needs to Catch Up

ENISA warns frontier AI compresses attack lifecycles to minutes, with exploits possible within 15 minutes of disclosure and median 72-minute breach-to-exfiltration times.

ENISA's July 2026 paper 'ENISA's view on Cybersecurity in the Frontier AI Era' argues AI-assisted attackers may weaponize vulnerabilities within 15 minutes of disclosure and achieve initial-access-to-data-exfiltration in a median 72 minutes, creating a 'negative time-to-exploit' problem. The report cites one organisation whose CVE volume rose from roughly 80 in Q1 2025 to almost 500 in Q1 2026, then about 500 reports per day when frontier-AI tools were used. ENISA recommends machine-speed defence under 'Cybersecurity as Code', EPSS and VEX-based prioritisation, AI-assisted incident response with human oversight, and an assume-breached architecture.

Security Affairs · 3d agoAdvisory

Red Heron Hackers Exploit Critical Gitea RCE to Steal Source Code and Deploy Linux Rootkit

PRC-linked Red Heron exploits critical Gitea RCE CVE-2026-60004 to steal source code and deploy JITTERLY implant with SIXZUT LD_PRELOAD rootkit; victims span five countries.

Acronis Threat Research Unit attributes a campaign to Chinese-speaking threat actor Red Heron, which weaponized CVE-2026-60004, a CVSS 9.8 RCE in Gitea versions 1.17 through 1.27.0, patched in 1.27.1 on July 27, 2026. The actor built an automated exploitation framework after a public PoC appeared, scanned 1,386 internet-exposed Gitea instances across seven countries, and separately listed 477 Taiwan-based systems across defense, energy, elections, and AI sectors. Confirmed victims include organizations in Canada, Argentina, Taiwan, the US, and Sri Lanka, with a Canadian renewable-energy firm hit in 22 sessions and a Taiwanese industrial automation firm losing hundreds of repositories including SCADA/HMI tools. Red Heron deploys the JITTERLY Linux implant (30+ commands, AES-128-GCM, Adaptix-like protocol) and the SIXZUT LD_PRELOAD rootkit disguised as libglthread.so.2, and moved laterally into a Synology/Proxmox environment to steal VM backups.

GBHackers · 3d agoThreat actor in the wild 3 sourcesCVE-2026-6000410

Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point

Filigran introduces Attack Chaining in OpenAEV to continuously simulate multi-stage attack paths, exposing gaps that isolated MITRE ATT&CK technique testing misses.

Filigran announced Attack Chaining, a new scenario type in its OpenAEV platform that links individual techniques into automated, continuously-run multi-stage attack paths, using each step's real output (credentials, tokens, open ports) to branch dynamically toward a final objective. The article cites Filigran's State of Threat Management report, in which 93% of security leaders reported a business-impacting cyberattack in the past 12 months, 88% said AI accelerates attackers, and 84% blamed siloed tools and disconnected testing. The 2025 DGFiP breach is cited as an example where individually survivable weaknesses chained into a major intrusion. The feature includes conditional chaining logic, live attack path mapping, structured findings for identifying chokepoints, and predefined scope and safety guardrails.

The Hacker News · 3d agoTools1

Improving email security outcomes with real-world Microsoft Defender insights

Microsoft's quarterly benchmark claims Defender missed 55.4% fewer high-severity email threats than the next-closest secure email gateway.

Microsoft published its fifth consecutive quarterly email security benchmark covering May through July 2026, reporting Defender missed 221 high-severity threats per 1,000 protected users, 55.4% fewer than the next-closest SEG vendor, and caught 92% of post-delivery malicious messages. Microsoft notes missed threats are rising across vendors as AI helps attackers craft more convincing impersonation attempts. The report also highlights product updates, including a redesigned AI model stack that reduced false negatives by roughly two-thirds and new prompt injection protection for Copilot and other AI systems that process email.

Microsoft Security Blog · 22h agoIndustry

Top 10 Best Cloud Access Security Broker (CASB) Solutions in 2026

2026 CASB guide ranks Netskope first for depth and Microsoft Defender for Cloud Apps for Microsoft estates, as standalone CASB fades into SSE.

Buyer's guide covers ten CASB products across four enforcement modes: API, forward proxy, reverse proxy and log-based discovery. Netskope leads on SaaS activity context depth, while Microsoft Defender for Cloud Apps wins on Microsoft 365 E5 estate economics. The guide argues standalone CASB purchases have largely disappeared into SSE platforms and increasingly overlap with SSPM.

Cyber Security News · 3d agoTools

What Recent AI-Powered Attacks Mean for Your Identity Security

Commentary on AI-accelerated credential theft cites Google's report of a six-hour multi-agent cloud attack and urges device trust and zero-trust identity controls.

The piece recounts Google Threat Intelligence Group's September 8 report of a credential-harvesting operation where an AI-built multi-agent framework compromised cloud infrastructure and thousands of third-party credentials in under six hours, including automated vulnerability scanning and IP rotation. It also cites Microsoft's April finding that AI-assisted phishing achieved 54% click-through rates versus roughly 12% for traditional campaigns, and Unit 42 data that identity weaknesses featured in 89% of investigated incidents. The article, which promotes Specops Password Auditor and Device Trust, argues successful authentication does not establish device trust and recommends binding identities to approved devices.

BleepingComputer · 1d agoIndustry in the wild

BlackHatSect0r Hackers Disable AI Safety Controls to Automate Credential Theft and Cyberattacks

French-speaking crew BlackHatSect0r disabled AI agent safety controls to automate scanning, credential harvesting, and vishing, exposing 16,834 stolen credentials.

Socradar researchers analyzed the exposed infrastructure of a French-speaking crew called BlackHatSect0r && DXQRTXX, which ran a Nous Research Hermes agent on a DeepSeek model with safety controls removed via HERMES_DISABLE_SAFETY=1. A custom Go-based C2 platform, DXSCAN, was exposed on port 8080 with over 200 secret-detection patterns, a vault of 16,834 harvested credentials, and scanning activity queuing 2.75 million domains and reaching more than 726,000 hosts. The kit also held a database of roughly 450,000 French telecom subscriber records used to prepare vishing lures impersonating Société Générale, plus JWT-forging tooling for a cryptocurrency exchange. Most confirmed compromises relied on exposed secrets and cloud misconfiguration rather than novel exploits; the one cited vulnerability, CVE-2026-42530, is an NGINX HTTP/3 QPACK use-after-free fixed in version 1.31.2.

GBHackersupdated · 1d agofirst · 1d agoThreat actor in the wild 4 sourcesCVE-2026-425301

From guidance to action: Security fundamentals that materially reduce risk

Microsoft expands Secure Now guidance, detailing AI-agent incidents, Storm-2945 CaptiveCrunch DNS hijacks, and Teams IT-support impersonation attack paths.

Microsoft's Security Exposure Management blog outlines three observed attack paths: OpenAI agents reaching production systems via shared Hugging Face infrastructure, Storm-2945 (Midnight Blizzard subcluster) redirecting hospitality network traffic into device-code phishing and fake updates in the CaptiveCrunch campaign, and attackers impersonating IT support over Teams to deploy MSI payloads via PowerShell and pivot through WinRM. Microsoft promotes Secure Now recommendations covering identity governance, agent isolation, phishing-resistant authentication, and Zero Trust controls.

Microsoft Security Blog · 21h agoAdvisory1

12 Best Browser Isolation Solutions Compared (2026): Features & Pricing

2026 comparison ranks Zscaler, Cloudflare, Menlo Security, Garrison (Everfox), Authentic8 and Kasm among twelve remote browser isolation solutions.

Guide compares twelve RBI products across four architectures: pixel streaming, DOM/vector reconstruction, platform-embedded SSE isolation, and self-hosted containers. Zscaler and Cloudflare lead RBI delivered inside SSE platforms, while Menlo Security leads isolate-everything efficacy and Garrison (Everfox) provides hardware-grade isolation for government use. Most offerings price per user per month.

GBHackers · 3d agoTools

Hackers Poison Movie Torrents With MovieReaper Malware That Uses Solana for C2

Poisoned movie torrents deliver MovieReaper malware using Solana blockchain for resilient C2, infecting several hundred victims across multiple continents.

Securelist reports a new Windows malware framework dubbed MovieReaper distributed through poisoned torrent downloads of popular films, with several hundred victims identified across Europe, Asia, and Africa, including organizations in government, IT, retail, transport, consulting, and agriculture. A loader disguised as a movie release file runs staged payloads largely in memory, installs persistence masquerading as Windows telemetry (msedge.exe under ProgramData), bypasses UAC, and grants operators broad file access for data theft. Unusually, the shellcode queries a Solana account via getAccountInfo to decode later command-and-control addresses, complicating takedowns, and the second stage uses HTTPS with a pinned certificate. Actor activity dates back to October 2025 and involves a compromised public torrent-file repository.

Cyber Security News · 6h agoMalware in the wild 3 sources

Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs

SOCRadar uncovered VectraRAT, a previously undocumented $250-per-month Windows RAT rental service delivered via Amadey and ClickFix lures.

SOCRadar's Threat Research Unit identified VectraRAT, a rental-only remote access trojan sold by a developer known as Vectra (formerly Nyxel), after an exposed online directory revealed samples, licenses, and operator logs across ten-plus servers. The toolkit includes a Linux control server, Windows implant, payload builder, and VectraHub panel, enabling hidden desktop access, keylogging, command execution, credential theft, file transfer, proxying, and silent privilege escalation. Of victims with OS data, 48 percent ran corporate Windows editions, and researchers recorded 38 genuine victim sessions in under a week, including file theft from business systems. Distribution occurs through the Amadey loader and ClickFix pages impersonating TurboTax, with custom TCP-based C2 over non-standard ports.

Cyber Security News · 1d agoMalware in the wild 3 sources

Hackers Use Autonomous AI Agents to Harvest Thousands of Credentials in Under 6 Hours

Google Cloud documents a financially motivated actor using autonomous AI agents on a compromised cloud tenant to harvest 23,800+ credentials in under six hours.

Google Cloud reports that an attacker compromised a victim's cloud environment and deployed a multi-agent framework driven by preconfigured Markdown playbooks to autonomously handle vulnerability scanning, credential collection, error troubleshooting, and IP rotation. An exposed command-and-control server hosted the 'Recon' framework with a live dashboard managing over 23,800 harvested secrets, including cloud and AI-service API keys. The report also ties DUSTMAKER to UNC6780/TeamPCP, targeting AI development tools and CI/CD systems via trojanized MCP packages such as tiktoken_mcp. Google has disabled linked assets and updated protections after the actors' operational security failures.

Cyber Security News · 3d agoThreat actor in the wild

Everybody's Lost Their Minds

A veteran security engineer argues AI-driven vulnerability discovery is not making organizations safer because patching and basic security hygiene remain the real bottleneck.

The author, a long-time security practitioner, criticizes the industry's rush into AI-assisted vulnerability research, noting that Anthropic and OpenAI programs like Glasswing, Daybreak, Athena, and Akrites consumed millions of dollars of engineering time and surfaced thousands of vulnerabilities, only a fraction of which were reported upstream. He argues that finding vulnerabilities was never the bottleneck; patching, asset inventory, and attack surface management remain the true problems. The post also critiques AI hype, agentic workflows, anthropomorphic media coverage, and AI companies' calls for their own regulation.

Smishing Hackers Can Watch Every Keystroke as Victims Enter Card Details and OTPs

Group-IB details the JWR smishing kit, used by the Outsider cluster, that streams keystrokes and OTPs to fraudsters in real time via WebSocket.

Group-IB linked the JWR phishing kit to an operator cluster it tracks as Outsider within the broader Smishing Triad ecosystem. Fake toll, parcel, and delivery messages lead to live phishing pages that capture card numbers, passwords, and one-time passcodes before victims submit forms. The kit supports up to 32 guided pages, AES-256-CTR wrapped traffic with keys embedded per message, rotating short links and domains, and WordPress or Shopify integration markers, enabling account takeover and unauthorized payments.

Cyber Security News · 2d agoPhishing & fraud in the wild 2 sources