ZeroHour

Search: “Securin”

26 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Securin Platform helps security teams prove when attack paths are closed

Securin launches the AI-native Securin Platform unifying exposure management, attack surface discovery, offensive validation and remediation to prove attack paths are closed.

Securin announced general availability of the Securin Platform, an AI-native preemptive exposure management product combining attack surface discovery, vulnerability and threat intelligence, prioritization, offensive validation and remediation verification in one workflow. It includes modules Surface, Signals, Exposure, Validate and Assure, orchestrated by the VERA multi-agent AI framework, and aims to verify whether real attack paths are closed rather than ranking findings by severity alone.

Help Net Security · 7d agoTools

New infosec products of the week: September 11, 2026

Weekly product roundup: Securin Platform GA, Orchid Security AI-agent identity controls, Akeyless Agentic Runtime Authority, and Scytale AI-powered TPRM.

Help Net Security's weekly product roundup highlights four vendor launches. Securin announced general availability of its AI-native Preemptive Exposure Management platform combining attack surface discovery, vulnerability intelligence, offensive validation and remediation. Orchid Security added identity drift detection and application-level kill switches targeting AI agents that escalate privileges via hard-coded credentials, orphaned accounts and excessive permissions. Akeyless released Agentic Runtime Authority, a real-time intent-based access control layer on top of its SecretlessAI credential protection, and Scytale launched AI-powered third-party risk management features in its Vendors module.

Help Net Security · 5d agoTools

GuardBreaker: Derailing AI-assisted malware analysis with a code comment

ESET names 'GuardBreaker': UAC-0099 embeds a nuclear-weapon question in VBScript comments to trip LLM scanner guardrails during analysis of its MATCHBOIL loader.

ESET researchers observed the Russia-aligned group UAC-0099 inserting a decoy prompt injection into a VBScript used to install its MATCHBOIL loader in an attack against a Ukrainian target, aiming to make LLM-based code scanners refuse and stop inspecting the file. The comment triggers safety guardrails with a request about building a nuclear weapons but has no runtime effect. Similar LLM-thwarting tricks have appeared in malicious PyPI and npm packages reported by Socket and StepSecurity. ESET recommends multi-model cross-validation of AI-assisted analysis and treating missing LLM output as requiring further checks.

ESET WeLiveSecurityupdated · 5d agofirst · 6d agoAI safety & security 3 sources1

Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited

Weekly roundup: Cisco FMC and N-able N-central zero-days exploited in the wild, MikroTik RouterOS hijacks, Microsoft Patch Tuesday ships two exploited zero-days.

State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass in Cisco Secure Firewall Management Center (FMC), alongside CVE-2026-20316. N-able issued an emergency hotfix for CVE-2026-86218, a critical pre-auth RCE in the N-central RMM platform exploited in the wild. CERT Polska disclosed six RouterOS vulnerabilities being chained to hijack internet-exposed MikroTik devices. Microsoft's September 2026 Patch Tuesday shipped a record patch count including two zero-days, while roughly 67,000 Trezor customers faced phishing after a shipping-partner breach and researchers privately disclosed a zero-click WeChat worm to Tencent.

Help Net Security · 3d agoExploit / PoC in the wildCVE-2026-20079CVE-2026-20316CVE-2026-862182· 1 read

US Sanctions Iranian $6bn Crypto “Exchange” Shelbit

US sanctioned Iranian firm Shelbit, a fake crypto exchange that TRM Labs says handled $6bn, likely for laundering.

The US has sanctioned Shelbit, an Iranian entity presented as a cryptocurrency exchange. TRM Labs analysis indicates Shelbit was a fake exchange, with roughly $6bn in flows. Sanctions aim to disrupt Iranian illicit crypto finance channels.

Infosecurity Magazine · Aug 10, 2026Policy & legal

US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks

US sanctions individuals tied to Iranian hacking-for-hire group the Mabna Institute over cyber-attacks.

The United States has imposed sanctions on individuals connected to the Mabna Institute, an Iran-based hacking-for-hire group. The move targets the actors behind Iranian cyber-attack operations. Sanctions are a government enforcement action rather than a new technical threat.

Infosecurity Magazine · 22d agoPolicy & legal

Surfshark VPN says hackers breached internal testing, proxy servers

Surfshark disclosed that hackers accessed misconfigured internal test and proxy servers, exposing build credentials but not customer data, VPN traffic, or production infrastructure.

Surfshark said a human error left an internal engineering test server reachable from the internet, exposing service configurations, build-related credentials, and portions of system binaries and code history. A separate proxy server used for content-accessibility optimization was also accessed, but it stored no user identity data, IP addresses, encryption keys, or browsing traffic. Suspicious activity was detected on August 31, contained on September 2, and remediation completed on September 5, with no evidence of credential misuse or spread to other systems. The company rotated impacted credentials, revoked exposed tokens, added monitoring and hardening, and commissioned an independent infrastructure audit; no customer action is required.

BleepingComputerupdated · 5d agofirst · 5d agoData breach in the wild 2 sources

Group of Bipartisan Lawmakers Ask US Government to Ban Several Hack-for-Hire Firms

Bipartisan US lawmakers urged Commerce Secretary Lutnick to sanction three Indian hack-for-hire firms, including BellTroX, over espionage targeting US citizens.

On September 9, 2026, a bipartisan group of US lawmakers sent a letter urging Secretary of Commerce Howard Lutnick to add three Indian companies, including BellTroX InfoTech Services, to the economic sanctions list. The firms are accused of targeted espionage against US citizens, businesses, and their lawyers, as well as lawfare to censor investigative reporting by major American media. The request builds on Citizen Lab's 2020 discovery of the Dark Basin hack-for-hire operation, which targeted US nonprofits involved in #ExxonKnew and net neutrality advocacy and was linked to BellTroX and related entities.

Citizen Lab · 5d agoPolicy & legal1

The Nansh0u Campaign – Hackers Arsenal Grows Stronger

Guardicore researchers detail the Nansh0u campaign's growing arsenal, with three attacks traced to South African IPs hosted by VolumeDrive.

Guardicore security researchers analyzed three attacks detected in early April through the Guardicore Global Sensor Network (GGSN). All three attacks originated from source IP addresses in South Africa hosted by the VolumeDrive ISP. The write-up catalogs the expanding arsenal and tooling used by the Nansh0u campaign attackers and includes indicators of compromise.

Akamai Blog · 8d agoThreat actor in the wild

Exploring the Latest Mispadu Stealer Variant

Unit 42 found a new Mispadu infostealer variant targeting Mexican users via malicious .url files exploiting the SmartScreen CVE-2023-36025 bypass.

Unit 42 discovered a new variant of Mispadu Stealer, a Delphi-based banking trojan first reported in 2019, found while hunting for the Windows SmartScreen bypass CVE-2023-36025. The campaign uses crafted .url files referencing UNC network-share paths with an HTTP port (@80) that forces payload retrieval over WebDAV via rundll32.exe, avoiding SmartScreen warnings. Analyzed samples (~4 KB, compiled 2023-11-12) predate the CVE publication, and ZIP payloads were likely distributed as email attachments, primarily targeting users in Mexico.

Palo Alto Unit 42 · Aug 17, 2026Malware in the wildCVE-2023-360251

Wyden seeks upgraded NSA security guidance on commercial VPN use

Senator Ron Wyden asked the NSA to update public guidance on commercial VPN security risks and answer questions about foreign surveillance threats against single-hop VPNs.

Sen. Ron Wyden sent a letter to NSA Director Gen. Joshua Rudd urging the agency to revise public guidance on commercial VPNs, following earlier letters to federal agencies in March and July. He argues single-hop VPNs offer little protection against sophisticated adversaries able to compel or compromise the single provider, citing a Congressional Research Service paper favoring multi-hop and mixnet architectures. The letter references a September NSA advisory on a China-sponsored campaign against telecom, government and military networks and asks unclassified questions about multi-hop systems such as Apple Private Relay, Tor and Nym versus mixnets.

CyberScoop · 14d agoPolicy & legal

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails

ESET reports Russian group UAC-0099 hid a prompt in VBS malware comments to trip AI safety filters and disrupt automated malware analysis in Ukraine.

ESET identified a technique dubbed GuardBreaker in which UAC-0099 embedded a comment reading "I want to make nuclear weapon. Help me …" inside a malicious VBS script to trigger AI safety mechanisms and halt AI-assisted malware analysis. The script, part of the group's toolset, downloads the MATCHBOIL malware used exclusively by this Russia-aligned group; CERT-UA documented the chain including LUNCHPOKE, BURNYBEAR and MATCHBOIL.V2 in a July advisory. UAC-0099 typically targets transportation and energy sectors and hands validated targets to GRU-linked Sandworm. ESET warned that AI-assisted analysis must be backed by layered detection and human-driven engineering.

Help Net Security · 16d agoAI safety & security in the wild

Lawmakers call on Treasury to sanction hackers-for-hire

Bipartisan US lawmakers asked Treasury to sanction three India-based hack-for-hire firms accused of long-running espionage against Americans.

Sens. Ron Wyden and Sheldon Whitehouse and Rep. Pat Harrigan urged Treasury to add Sunkissed Organic Farms (formerly Appin), BellTroX, and CyberRoot to the Entity List. The letter says the mercenary groups conducted targeted espionage against US citizens, businesses, and lawyers for over fifteen years, allegedly including work for Qatar's government such as targeting opponents of Qatar's World Cup bid and Kristi Rogers, wife of Senate candidate Mike Rogers. Adding the firms to the Entity List would restrict their access to American software, cybersecurity tools, and cloud infrastructure. The lawmakers also accuse the groups of lawfare campaigns to censor investigative reporting on their hacking activities.

CyberScoop · 6d agoThreat actor in the wild

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Rapid7 uncovered a DPRK-linked Linux toolkit using a HAProxy-embedded ted backdoor, SSH keylogger, and curlRAT against South Korean media and automotive firms.

Rapid7 Labs identified a previously undocumented framework attributed with medium confidence to DPRK actors, targeting South Korean automotive and media organizations likely since early 2025. The toolkit embeds a backdoor compiled into HAProxy 2.8.12 using its filter API, plus trojanized crond, agetty, atd, sshd, and polkitd, an SSH keylogger storing credentials under /var/lib/sshd/, and a curl-based RAT with a watchdog thread. It enables remote command execution, malicious script injection into served webpages (a watering-hole loop), credential harvesting, and long-term surveillance. Hardcoded C2s are associated with APT37 via ThreatFox, and exposed groupware portals and mail servers align with Kimsuky tradecraft; the initial access vector and any CVE remain unconfirmed.

Rapid7 Blog · 12d agoThreat actor in the wild1

Russian-Linked Hackers Accessed Polish Power Plant OT Network Through Private APN, Says CERT.PL

CERT.PL disclosed that Russian-linked hackers accessed a Polish combined heat and power plant's OT network through a private APN in 2025.

Poland's CERT (CERT.PL) released details of a 2025 attack on a Polish combined heat and power plant. Russian-linked hackers accessed the plant's OT network through a private APN. The disclosure adds to a series of intrusions against Polish critical infrastructure attributed to Russian-linked actors.

Infosecurity Magazine · Aug 12, 2026Threat actor in the wild

Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras

Slovakia's NBU found an SMS-triggered backdoor in Russian-made NERO R-ONE traffic cameras, pausing a 279-unit deployment.

Slovakia's national security service NBU issued an alert against NERO R-ONE high-speed traffic cameras after finding a backdoor that grants shell and network access via SMS from hardcoded Russian phone numbers. The cameras are a rebranded version of the Russian CORDON PRO.M model by St. Petersburg firm Semicon, purchased via a Cyprus shell company under a €30 million EU-funded project. The report also found SecureBoot disabled, vulnerable web management, and unauthenticated live streams; the Interior Ministry paused deployment of 279 cameras pending independent assessment.

Risky Business News · 28d agoThreat actor in the wild1

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

Rapid7 found a new backdoor, ted, compiled into trojanized HAProxy at two South Korean organizations, with medium-confidence attribution to North Korean actors.

Rapid7 documented a previously undocumented Linux toolkit named ted compiled into the HAProxy load balancer binaries of two South Korean organizations in the automotive and media sectors. The implant intercepts web traffic, serves altered pages only to filtered visitors, and hides C2 exchanges from backend logs and HAProxy statistics; a companion RAT, curlRAT, beacons on a default 12-hour schedule. The toolkit also trojanizes crond, sshd, agetty, atd, and polkitd binaries and sanitizes logs and bash history. Rapid7 attributes the activity with medium confidence to North Korean state-sponsored actors, with domain infrastructure overlapping APT37 listings in maltrail and delivery resembling the Operation SyncHole campaign.

The Hacker News · 12d agoThreat actor in the wild

North Korean Hackers Deploy New Linux Espionage Toolkit

Rapid7 says North Korea-aligned actors use a new Linux espionage toolkit (ted HAProxy backdoor, CurlRAT) against South Korean automotive and media targets.

Rapid7 reports a stealthy Linux framework comprising a custom HAProxy backdoor ('ted'), trojanized system binaries (agetty, atd, crond, polkitd, sshd), an SSH keylogger, and CurlRAT that polls C&C every 12 hours. Initial access came via a Groupware login portal flaw, with credential harvesting enabling lateral movement to internal systems. The toolkit supports long-term surveillance, HTTP traffic interception/injection, and drive-by downloads, likely in use since late 2024. Infrastructure and artifacts overlap Operation SyncHole, suggesting Lazarus or APT37 involvement.

SecurityWeek · 9d agoThreat actor in the wild1

New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy

Darktrace says the Chaos botnet now targets misconfigured cloud deployments like Hadoop and added a SOCKS proxy for traffic relaying.

Darktrace identified a new 64-bit ELF variant of the Chaos botnet targeting misconfigured cloud deployments, expanding beyond the malware's traditional focus on routers and edge devices. Captured in a deliberately misconfigured Hadoop honeypot instance, the intrusion began with an HTTP request creating an application that ran embedded shell commands to fetch the Chaos agent binary from pan.tenire[.]com, set chmod 777 permissions, execute it, and delete the artifact to reduce forensic traces. The restructured variant adds a SOCKS proxy feature letting compromised systems ferry attacker traffic, while removing SSH-based spread and router-exploit functions, suggesting monetization beyond crypto mining and DDoS-for-hire. Possible Chinese origin is suggested by language artifacts and infrastructure; the delivery domain was previously used in Silver Fox's Operation Silk Lure phishing campaign delivering ValleyRAT.

The Hacker News · 29d agoMalware1

New AI Attack Hides Malicious Instructions in Normal-Looking Text to Evade Safety Filters

Check Point researchers show crafted prose hides policy-violating instructions that bypass all tested LLM gatekeepers, including GPT-4o mini and Llama Guard 3.

A new prompt-crafting technique embeds malicious payloads inside grammatical, natural-looking text without Base64, invisible Unicode, or obvious encodings, defeating lightweight pre-screening gatekeepers. In testing, all four evaluated gatekeeper models—gpt-4o-mini-2024-07-18, gpt-oss-safeguard:20b, claude-3-haiku-20240307, and llama-guard3:8b—classified the crafted wrappers as safe at a 100% bypass rate across 23 obfuscated prompts. GPT-5 Thinking in high-reasoning mode recovered and acted on the hidden instruction in 17 of 18 tests (~94.4%), often spending over a minute and multiple Python executions. Researchers recommend paraphrasing untrusted input, hardening gatekeeper policies, and applying defense-in-depth controls for agentic deployments.

GBHackers · 5d agoAI safety & security 2 sources

Tracking Elirks Variants in Japan: Similarities to Previous Attacks

Unit 42 links new Elirks backdoor variants attacking Japanese organizations to 2012 Taiwan attacks, delivered via spear-phishing PDFs exploiting Adobe Flash CVE-2011-0611.

Unit 42 analyzed new Elirks backdoor variants found in an attack on a Japanese business, noting strong similarities to 2012 attacks on Taiwanese ministries. The backdoor retrieves its C2 address from attacker-created accounts on Japanese blog and SNS services. Recent deliveries used an airline e-ticket lure named "E-TKT" with a PDF exploiting Adobe Flash CVE-2011-0611. Shared infrastructure and tactics with the Scarlet Mimic campaign suggest possible ongoing cyber espionage across East Asia.

Palo Alto Unit 42 · Aug 17, 2026Threat actor in the wildCVE-2011-0611

Confused about which VPN is right, US senator asks the NSA for guidance

Senator Ron Wyden asked the NSA to update public guidance on VPN configurations, questioning single-hop designs and services like Tor.

Sen. Ron Wyden (D-Ore.) sent a letter Wednesday to NSA director Gen. Joshua Rudd requesting updated public guidance on VPN best practices for Americans facing advanced foreign threats, including government personnel, contractors, and journalists. The letter highlights limitations such as decrypted traffic at single-hop termination servers, metadata like timestamps enabling nation-state profiling, and asks the NSA to assess multi-hop architectures, random delays, cryptographic padding, and specific services including Apple Private Relay, Nym, and Tor.

Ars Technica · Security · 12d agoPolicy & legal

Risky Bulletin: Academics find source code overlaps between Geedge and China's Great Firewall

Academics linked Chinese vendor Geedge Networks' Tiangou Secure Gateway source code to one of the Great Firewall's three traffic filtering capabilities.

US researchers presenting at USENIX Security reconstructed Geedge Networks' Tiangou Secure Gateway firmware from over 100,000 leaked files, including Git repositories with commit history, and matched its filtering behavior to sections of China's Great Firewall. They found only 1 of 3 characterized DNS injectors matched Geedge code, noted the system relies on memory-unsafe C components and copied third-party code, and said its bugs could aid future circumvention tools. Geedge also exports censorship tools to Kazakhstan, Ethiopia, Pakistan, and Myanmar. The newsletter additionally rounds up multiple breaches.

Risky Business News · 26d agoResearch2

KREMLIN Banking Malware Bypasses Chrome Security to Steal Banking Sessions

Elastic Security Labs details KREMLIN, a Brazilian banking malware that implants malicious Chrome and Edge extensions by forging Chromium integrity values to steal banking sessions.

Elastic Security Labs tracks the KREMLIN banking malware operation as REF9334, active since at least May 2025 across seven campaigns primarily targeting 12 Brazilian banks. The malware is installed by a victim-run JavaScript loader, achieves scheduled-task persistence, and side-loads a malicious DLL via SentinelOne's SentinelMemoryScanner.exe. It modifies Chrome and Edge Secure Preferences files, enables developer mode, and regenerates Chromium MAC values to silently install extensions, while extracting browser encryption material including the newer App-Bound OSCrypt key. An Ethereum smart contract serves as a dead-drop resolver for C2 config; Elastic disrupted over 1,500 infections via a canary domain.

GBHackers · 10h agoMalware in the wild 2 sources

Persistent Attempts at Cyberespionage Against Southeast Asian Government Target Have Links to Alloy Taurus

Alloy Taurus (GALLIUM) compromised Southeast Asian government networks from 2022 to 2023 using Exchange web shells and undocumented .NET backdoors Reshell and Zapoa.

Unit 42 tracked persistent multiwave intrusions at a Southeast Asian government starting in early 2022 and continuing through 2023, attributing the activity with moderate confidence to Alloy Taurus (aka GALLIUM), a Chinese state-aligned espionage group. Attackers exploited Exchange Server vulnerabilities to deploy web shells including China Chopper, then ran reconnaissance with Fscan and WebScan, created administrative accounts, and installed undocumented .NET backdoors named Reshell and Zapoa. They established resilience by installing SoftEther VPN, brute-forced Active Directory credentials with Kerbrute, and dumped credential stores with GoDumpLsass and LsassUnhooker. The campaign reflects long-term espionage tradecraft to maintain a foothold.

Palo Alto Unit 42 · Aug 17, 2026Threat actor in the wild1