Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This article reports on research presented ahead of Black Hat USA, revealing exploitable flaws in how Microsoft handles passkeys. These flaws could allow attackers to impersonate privileged users, demonstrating that old attack techniques remain effective against modern authentication methods.
Researchers discovered exploitable flaws in Microsoft's passkey implementation ahead of the Black Hat security conference, demonstrating that even next-generation authentication mechanisms can contain critical vulnerabilities. Passkeys, which replace passwords with cryptographic key pairs stored on devices, are intended to be phishing-resistant and immune to credential theft, but implementation flaws in how they are generated, stored, validated, or synced between devices can reintroduce the very attack surfaces they aim to eliminate.
This article discusses Sandworm_Mode, an early malware example that abuses trusted AI tools and workflows. By mimicking normal AI activity, it makes malicious behavior nearly impossible to detect.
The Sandworm_Mode malware represents an evolution in attacker tradecraft by exploiting trusted AI tools and agentic workflows to live off the AI toolchain, analogous to living off the land techniques that abuse legitimate system tools. Rather than deploying custom malware that might be detected, attackers manipulate AI coding assistants, agentic frameworks, and ML pipelines to perform malicious actions under the guise of legitimate AI operations.
The Sandworm_Mode malware represents an evolution in attacker tradecraft by exploiting trusted AI tools and agentic workflows to live off the AI toolchain, analogous to living off the land techniques that abuse legitimate system tools. Rather than deploying custom malware that might be detected, attackers manipulate AI coding assistants, agentic frameworks, and ML pipelines to perform malicious actions under the guise of legitimate AI operations.
A fake Bahrain government alert application distributed through unofficial channels, masquerading as a legitimate Google Play app, delivers a sophisticated four-stage Android spyware payload. The multi-stage infection process makes detection by antivirus engines and static analysis tools significantly harder, as each stage decrypts or downloads the next component only after specific conditions are met.