A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671 . “UNC6671 continues to rely …
AI Security Roundup
Daily AI security roundup covering malware, vulnerabilities, defensive research, cloud risk, and incident response signals from trusted technical sources.
** Ravie Lakshmanan ** Aug 08, 2026 Vulnerability / Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting …
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. …
** Ravie Lakshmanan ** Aug 07, 2026 Malware / Social Engineering ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as …
** Ravie Lakshmanan ** Aug 08, 2026 Vulnerability / Enterprise Security N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently …
** Swati Khandelwal ** Aug 08, 2026 Email Security / Vulnerability New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack …
** Ravie Lakshmanan ** Aug 08, 2026 Zero-Day / Vulnerability Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has …
Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found …
Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials
** Ravie Lakshmanan ** Jun 27, 2026 Messaging Security / Cyber Espionage The Security Service of Ukraine (SSU) said it, together with the U.S. Federal Bureau of Investigation (FBI), uncovered a …
OpenAI on Friday released three versions of GPT-5.6 , called Sol, Terra, and Luna , as a limited preview to a small number of companies as part of an ongoing engagement with the U.S. government. While …
ISC Stormcast For Wednesday, June 24th, 2026 https://isc.sans.edu/podcastdetail/9984, (Wed, Jun 24th)
ISC Stormcast For Wednesday, June 24th, 2026 <https://isc.sans.edu/podcastdetail/9984>
In a previous diary, I talked about stack strings[ 1 ] with a practical example of them. Since my SEC670 class, I’m even more interested in malware obfuscation techniques. I had a look at process …
What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)
[This is a Guest Diary by Nicole Phillips, an ISC intern as part of the SANS.edu BACS program] " I was just sitting here enjoying the company. Plants got a lot to say, if you take the time to …
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London , the entity responsible for the public transport …
Anthropic’s Fable 5 Model Jailbroken Within Days Fable 5 is the supposed safe version of Anthropic’s Mythos Preview, with guardrails to ensure that it can’t be used to create cyberattacks. Well, that …
Interesting Paper Exploring Prompt Injection This is a fascinating explotation of how LLMs fall for prompt injection attacks. It turns out that they learn to recognize the style of text in different …
Embedding Forbidden Text in Spyware to Discourage AI Analysis At least one malware developer is adding text about nuclear and biological weapons to their spyware, in an effort to stop automatic AI …
AI and Liability Earlier this month, a German court ruled that Google is liable for its AI search summaries. Rejecting defenses like “users can check for themselves,” and that they generally know …
One Million Passports Leaked Online A database of almost a million passports from around the world was leaked online. Note what happened. A high-value credential—a passport—was used in an ancillary …
The Chinese Control the Majority of Argentina’s Squid Fleet Chinese companies control nearly two-thirds of Argentina’s own squid fleet. Tags: squid Posted on June 26, 2026 at 4:57 PM • 1 Comments
Meta Is Testing Facial Recognition for Police and Military We know that ICE wants to deploy eyeglasses with facial recognition that can identify people in real time. Turns out Meta is prototyping the …
AI agents are moving through enterprise environments, inheriting permissions, traversing systems, and executing decisions at machine speed with minimal oversight. The identity infrastructure built to …
** Swati Khandelwal ** Jun 26, 2026 Linux / Vulnerability DirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit walkthrough …
** Ravie Lakshmanan ** Jun 26, 2026 Vulnerability / Software Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability …
** Swati Khandelwal ** Jun 26, 2026 Linux / Vulnerability A flaw in the Linux kernel’s traffic-control subsystem can let a local unprivileged user gain root on affected systems. CVE-2026-46331 , …