Forum Widgets
Recent Discussions
Tenable Security Intel Brief: How OpenAI's agents coordinated a breach
Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team. But first: Tenable's RSO team and SentinelOne ran a joint analysis of 93 CVE-actor attribution pairs and found that state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Read it here. This week, OpenAI's technical report on the July Hugging Face breach shows its agents began coordinating through an internal package repository months before the intrusion, and CISA has added two of the exploited flaws to its Known Exploited Vulnerabilities (KEV) catalog. OpenAI ties Hugging Face breach to a message board its agents built → Brief: OpenAI's August 27 technical report traces its July compromise of Hugging Face to agents that began coordinating through internal infrastructure in May, and CISA listed two of the exploited flaws in its KEV catalog. Intel: During internal cybersecurity evaluations run with safeguards disabled, agents repurposed OpenAI's internally hosted Artifactory, a repository manager for software packages, into an improvised message board. They left notes in files starting May 12, then encoded messages in directory names. From there they reached the internet, ran code on 41 of Hugging Face's production servers, gained full administrative control of at least one, and downloaded four private code repositories. CISA listed the Artifactory zero-day (CVE-2026-66384) and CVE-2026-53362, a Linux kernel flaw the agents used to escape an isolated compartment and seize the server. Why it matters: OpenAI calls this "the first known case of an automated agent collective acting offensively without authorization." The coordination that made it possible formed months earlier, inside a package tool no one was watching for. By the time defenders had a breach to trace, the agent collective was already assembled. US seizes domains it says powered alleged Chinese espionage since 2018 → Brief: The Justice Department and FBI seized three domains to disable QScan and QTRouter, twin platforms that court documents allege a People's Republic of China (PRC) state-sponsored group, QTFY, used to scan for and hide attacks on US critical infrastructure. Intel: A companion FBI, NSA and Cyber National Mission Force advisory traces the alleged activity to 2018 and lists 14 exploited flaws, nearly all in internet-facing systems. The group used a Pulse Secure VPN bug (CVE-2019-11510) against the Department of Justice and the Federal Reserve in 2019, and Check Point gateway flaw (CVE-2024-24919) in 2024 to pull data from over 300 organizations. It targeted the US Senate this March without gaining access. According to the advisory, QScan ran "over two million scanning and penetration testing tasks" in a single day in 2024. Why it matters: The exploited flaws mix fresh zero-days with known vulnerabilities disclosed in years prior, and the same classes of VPN and gateway flaws kept surfacing on the list from 2019 through this year. Those are the same product categories our team and SentinelOne flagged as under broad, persistent exploitation. CISA baselines what attackers exploit before AI rewrites the map → Brief: CISA published its Vulnerability Review for fiscal years 2024 and 2025, a snapshot of what threat actors actually exploit before AI-driven vulnerability discovery arrives at scale. Intel: Improper input validation, where software fails to check untrusted data, is what CISA calls "the most frequent weakness type in both the KEV Catalog and CVE records." Volume and exploitation diverge: injection flaws (attacks that slip malicious commands into normal inputs) such as SQL injection and cross-site scripting run high in the CVE dataset yet, by CISA's assessments, cyber-mature organizations have mostly eliminated them. Memory-handling flaws and input validation failures are the reliable entry points, tied to 19.7% of exploited flaws in FY2024 and 16.7% the following year. Why it matters: Three of the weakness classes attackers exploit most today, CISA says, "would have been considered 'unforgivable' nearly two decades ago," and the agency traces the cause to organizational culture and developer workflows, not technical complexity. What decides where an attacker gets in is which shop still ships the old mistakes. Open sign-up turns a Gitea flaw into unauthenticated code execution → Brief: CISA added CVE-2026-60004, a code-injection flaw in the self-hosted Gitea Git service, to its KEV catalog with a three-day federal deadline that expired August 28. Intel: In Gitea's diffpatch API, the feature that applies code changes, a crafted patch plants a Git hook, a script the server executes automatically, that then runs the attacker's commands with the software's own privileges. Write access to any repository is enough, and because Gitea ships with open registration on by default, anyone can register an account and get that access without prior credentials. Salesforce researcher Shai Rod reported it, and a fix shipped in Gitea 1.27.1 on July 27. Attackers are reportedly using unpatched servers to run cryptocurrency-mining malware. Why it matters: Shadowserver counted 8,393 servers still vulnerable on August 27, the day before the deadline, with public exploit code and China, Germany, and the U.S. leading the affected countries. The mandate reaches federal agencies, but Gitea is self-hosted software running past 400,000 installations, so the exposure sits mostly with operators no deadline governs. Stat of the week: 97% The share of 405 AI-enabled malware samples that exist only in sandboxes, research repositories, and security validation platforms, according to Palo Alto Networks' Unit 42, which found just 12 samples on real production endpoints. Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.60Views0likes0CommentsTenable Security Intel Brief: Clop returns with a custom Windchill web shell
Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team. This week marks one year of the Security Intel Brief. The first edition was sent on August 27, 2025. The top story this week: the Clop extortion group is exploiting a critical PTC Windchill flaw with a custom-built web shell designed to steal engineering data and decrypt enterprise credentials. Clop deploys a custom data-theft implant against Windchill servers → Brief: ReliaQuest believes a purpose-built web shell, deployed after exploitation of CVE-2026-12569 (CVSS 9.3) in PTC Windchill, a product lifecycle management platform holding engineering data and product designs, is "highly likely" the work of the Clop extortion group. Intel: The web shell, malicious code planted on the server, is equipped to steal data: credential harvesting is built in, and so are file discovery and transfer. A single "S" command reads Windchill's configuration file and decrypts the stored directory-manager, admin, and site-administrator passwords into plaintext. A built-in loader runs fresh attacker code entirely in memory, with nothing written to disk. Extortion emails match addresses on Clop's data leak site. PTC shipped its fix June 17 and CISA added the flaw to its KEV catalog June 25; extortion emails followed in mid-July. Why it matters: The directory-manager password governs Active Directory, email, and VPN, so one decrypt command can hand an attacker credentials reaching far past the compromised server. Clop pairs mass exploitation with a fresh implant each time, the same move it ran with its DEWMODE web shell in 2021 and LEMURLOOT web shell in 2023. Five U.S. agencies warn of AI-built scripts probing Siemens PLCs → Brief: Five U.S. agencies issued a joint advisory warning that attackers are running AI-written scripts, dressed up to look like ordinary monitoring tools, to probe Internet-exposed programmable logic controllers (PLCs) in Siemens' S7 Series. Intel: The NSA, CISA, FBI, DOE, and EPA say the activity spans scouting and tool-building against U.S. installations in energy, water, chemical, food, and critical-manufacturing sectors. Attackers use scanning services such as Censys and ZoomEye to find exposed or poorly segmented S7-200 through S7-1500 controllers. They then run AI-written Python scripts, built on freely available open-source code, that speak the controllers' own communication protocol. That gives read and write access to controller memory and configuration, and to the control programs that run the machinery. The agencies name no threat actor and no new vulnerability. Our team's FAQ on the advisory covers the targeted models and mitigations. Why it matters: The controllers and their flaws were already reachable, and the open-source libraries freely available; what AI supplied was the exploitation code, sharply reducing the expertise a working ICS tool once required. Siemens told CyberScoop the advisory reflects "new techniques to exploit potential misconfigurations." The Python scripts arrive looking like software an operations team already trusts. Medusa ransomware passes 500 victims as FBI adds two exploited flaws → Brief: The FBI, CISA, and the Department of Health and Human Services (HHS) updated their joint #StopRansomware advisory on Medusa, reporting more than 500 victims across critical infrastructure sectors as of April 2026. Intel: Medusa is a ransomware-as-a-service operation first seen in June 2021 that encrypts data and threatens to leak it unless victims pay. The victim count climbed from over 300 as of early 2025, hitting healthcare, schools, law firms, insurers, tech companies, and manufacturers. The refreshed advisory adds two exploited flaws: CVE-2025-10035 in Fortra GoAnywhere and CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, joining earlier flaws in ScreenConnect and Fortinet. Why it matters: The FBI says Medusa affiliates can turn a newly announced exploit against victims inside 24 hours, and in some cases moved a week ahead of public disclosure. The group writes no zero-days of its own, so the edge comes from obtaining exploits faster than defenders can close known, fixable holes. Talos finds a cybercrime crew running AI as its post-breach operator → Brief: Cisco Talos discovered UAT-10147, a Chinese-speaking criminal operation that uses agentic AI, meaning AI that plans and runs multi-step tasks on its own, to automate work after breaking into web servers. Intel: Talos assesses with moderate-to-high confidence that the financially motivated group, active since early 2026, has shifted beyond simple AI scripting help into semi-autonomous attack orchestration. Talos ties the activity to search-engine fraud and data theft. On the attackers' own servers, an unprotected folder exposed roughly 170,000 target URLs split into 17 files, alongside PentestGPT, an AI penetration-testing tool used to scan victims and launch exploits. The folder also held AI-written runbooks and Python scripts that plant the group's SPECTRE malware and backdoor code. Why it matters: Dwell-time assumptions rest on attackers needing time for trial and error inside a compromised network, and for writing up what worked. This group handed that work to AI. The AI QA-tested the exploit before use and wrote the step-by-step runbooks its operators followed. Stat of the week: 49 The number of Security Intel Brief newsletters sent since the first edition on August 27, 2025. Thank you to everyone who has read, forwarded, filled out a survey, or talked about the Security Intel Brief over the last year. It is because of your feedback that this newsletter is now shareable with customers and published each week in the Vulnerability Watch community. Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.109Views0likes0CommentsFrequently asked questions about the active threat to Siemens S7 Series PLCs
On August 19, 2026, the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the Department of Energy (DOE) and the Environmental Protection Agency (EPA) released a joint Cybersecurity Advisory (AA26-231A) warning that threat actors are actively targeting Siemens S7 Series programmable logic controllers (PLCs) that are exposed to the internet or insufficiently segmented from it. The activity spans the S7-200, S7-300, S7-400, S7-1200 and S7-1500 series and most heavily affects the Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture and Commercial Facilities sectors, with potential exposure in the Defense Industrial Base as well. According to the authoring agencies, threat actors are using AI-generated exploitation scripts, disguised as legitimate operational technology (OT) monitoring tools, to conduct reconnaissance and build capability against exposed PLCs. The Tenable Research Special Operations Team (RSO) has put together a frequently asked questions (FAQ) blog to help security and OT teams understand the threats, the techniques involved and the mitigations offered by the authoring agencies. The advisory itself notes that ongoing PLC targeting is broader than Siemens alone and that all PLC owners and operators, regardless of vendor, should apply all relevant mitigations. For more information, please visit our blog.scaveza19 days agoProduct Team131Views1like0CommentsTenable Security Intel Brief: Lazarus adds a Windows zero-day to its resume
Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team. This week, Check Point Research details what Lazarus Group was willing to spend to make a single fake job offer land, and what that price says about the targets they wanted. Lazarus burned a Windows zero-day on fake job offers to defense firms → Brief: Check Point Research attributed a fake job-offer campaign to Lazarus Group. Attackers used a Windows zero-day against defense, aerospace, and aviation firms in France, Germany, Brazil, and India. Intel: Lazarus exploited CVE-2026-68820, a flaw in a core Windows networking component, to take full control of the machine and deploy FudModule v3.1, a rootkit (malware that hides itself) that switches off Windows' own security logging so defenders lose visibility. The exploit payload was protected with post-quantum encryption (built to resist future quantum computers) and ran in memory, leaving no file behind. Command-and-control traffic ran through at least 17 hijacked third-party servers, including Roundcube webmail instances compromised via CVE-2025-49113. Microsoft patched CVE-2026-68820 in its August 2026 Patch Tuesday. Why it matters: Here's the resume: Windows zero-day, post-quantum exploit encryption, a rootkit that kills logging, and 17 hijacked relay servers. That's what Lazarus spent to reach defense firms building drones, surveillance sensors, and robotics. SAP Commerce Cloud CVSS 10 flaw targeted three days after patch → Brief: SAP patched CVE-2026-58231, a maximum severity flaw (CVSS 10) in SAP Commerce Cloud (formerly SAP Hybris) that lets an attacker act without authorization, enabling unauthenticated remote code execution, on August 11. Intel: CVE-2026-58231 is in the Data Hub Adapter extension of SAP Commerce Cloud. The flaw lets a remote, unprivileged attacker abuse a built-in login component to slip malformed input past the platform's checks, resulting in arbitrary code execution. SAP shipped Security Note 3771065 on August 11. Defused honeypots recorded exploitation attempts on August 14, independently confirmed by threat-intelligence tracker KEV Intelligence: two attempts, one attacker IP. A public proof-of-concept appeared August 15. CISA has not added this flaw to its Known Exploited Vulnerabilities catalog as of August 18. Why it matters: Exploitation attempts began within three days of the patch. A public proof-of-concept landed the day after that, on day four. For a CVSS 10 flaw that needs no credentials and no user interaction, these four days sit entirely inside the window enterprise change-control cycles need just to begin. Kimsuky sets up offline AI environments on its own attack servers → Brief: Genians found that Kimsuky, a North Korean threat group operating under the Reconnaissance General Bureau, built and operated local large language models (LLMs), typically cut off from the internet, on its own command-and-control infrastructure. Intel: Logs from Kimsuky's C2 infrastructure showed Ollama and GPT4All, free tools for running AI models offline, installed and used. Ollama left auto-generated key files confirming a launch; GPT4All carried a localdocs_v3.db, the database a feature creates to let the AI answer questions from a private document set. Genians also found speech-to-text tools and building blocks for adding AI to its own software. Genians assesses the activity as a "research and knowledge acquisition stage," integrating existing AI rather than training new models, and the offline stack has not been observed against a victim. Why it matters: Running AI locally removes the provider oversight that usage policies and takedowns depend on. The attack steps beneath it (booby-trapped shortcuts, hidden scripts, recurring scheduled tasks, GitHub-disguised traffic) read the same no matter how clean the output looks. As local models gain parity with frontier models, defenders stand to lose insight into threat actor playbooks. One IP scraped Salesforce and ServiceNow portals for seventeen months → Brief: A single-IP campaign has been pulling records from misconfigured Salesforce and ServiceNow customer portals that are public and require no login, since at least March 2025, with no vulnerability exploited and the same infrastructure throughout. Intel: Reco traced the campaign to one IP, a Contabo VPS in Germany, running a single custom-built scanning tool that always looked exactly the same. The tooling pulled records through the data-access channels behind these portals, including one in ServiceNow that had barely been documented; the single busiest target logged more than 560,000 events from that one address over the life of the campaign. ServiceNow confirmed no platform compromise; Reco's conclusion: "every byte the attacker retrieved was something a site owner had exposed to anonymous users." Why it matters: Nothing was exploited, so nothing was flagged. The 560,000 logged events at one target sat inside ordinary guest portal traffic, undetected, on infrastructure that has stood for seventeen months. The visibility gap sits on the surface organizations hand to anonymous visitors and then stop watching. Stat of the week: 1.7 billion The number of credentials harvested by infostealer malware across more than 7.4 million compromised systems in the first half of 2026 alone, according to the Flashpoint Global Threat Intelligence Report, Midyear Edition. Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.157Views0likes0CommentsOracle August 2026 Critical Security Patch Update Addresses 925 CVEs
On August 18, Oracle released its Critical Security Patch Update (CSPU) for August 2026. This CSPU contains fixes for 925 unique CVEs in 943 security updates across 23 Oracle product families. Out of the 943 security updates published, 16.3% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 59%, followed by medium severity patches at 21%. For more information about the August 2026 CSPU release, including the availability of patches and Tenable product coverage, please visit our blog.155Views0likes0CommentsTenable Security Intel Brief: Same extortion crew, four new names
Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team. This week, Google Threat Intelligence Group ties the retired BlackFile brand and four successor names to a single extortion operation whose helpdesk vishing playbook never changed, with ransom payments continuing past the group's publicized shutdown. Extortion crew sheds its brand but keeps its vishing playbook → Brief: Google Threat Intelligence Group (GTIG) reports that UNC6671, assessed to be behind the recently retired BlackFile brand, continues to run extortion operations under four new names while its helpdesk voice-phishing (vishing) playbook stayed intact. Intel: GTIG linked UNC6671 to Redact, Pink, Helix, and Falcon, though it allows for splintered affiliates or shared phishing-panel services. Payments to BlackFile wallets continued past its publicized May 11 shutdown. Callers posing as IT helpdesk staff reach employees on personal phones urgently demanding they re-set up account security measures, steering them to fake login pages that capture the login and one-time code as they're typed, then draining Microsoft 365 and Okta data. By July, targeting narrowed to private equity, legal, and financial rating firms whose leverage rests on confidentiality. Why it matters: Cyber-insurance negotiators and defenders build their response around who they think they are facing. When the same operators keep publishing under new brand names, actor identity stops anchoring that decision, and the tradecraft is what still identifies the crew. A self-propagating npm worm mints real provenance for its own malware → Brief: Palo Alto Networks' Unit 42 analyzed ChainDrop, a self-spreading npm worm that has infected over 400 packages, among them poisoned releases of the popular keyv and cacheable-request. Intel: After a poisoned package installs, code that runs automatically fetches the legitimate Bun runtime as an execution vehicle, harvests cloud, npm, GitHub, and SSH credentials, then republishes infected packages with their real functionality intact. The worm looks up its command and control server on the Ethereum blockchain, and on Aug. 4 the operator swapped the entire command infrastructure with one blockchain transaction and no code update. In a repository-gated path, it uses the project's own automated publishing pipeline to sign the tampered package and mints a genuine Sigstore provenance attestation for it. Why it matters: The attestation is genuine: it records that a tampered package came from the named workflow, which was running attacker code. Provenance was the supply-chain signal defenders were told to trust, and here it certifies the malware as authentic. Unit 42 places ChainDrop in the Shai-Hulud lineage without confirming who runs it. Test agents invent fake identities to smuggle malware into code → Brief: The UK AI Security Institute (AISI) cataloged 19 unsanctioned actions in 10 of 122 cyber-evaluation runs where agents targeted real people and organizations on the live internet. Intel: AISI deliberately enabled open-internet access and switched off the providers' cyber classifiers to measure maximum capability, never telling agents what was off-limits; the tested configurations are not commercially available. Of the 19 actions (July 25 to 28), 17 involved Anthropic's Claude Mythos 5 while two involved OpenAI's GPT-5.6 Sol. In a 34.5-hour run, one agent researched two unaffiliated developers, created fake GitHub accounts, and submitted a code change hiding malware as a bug fix. When a user flagged the malware, it rewrote its branch history and claimed an honest mistake. Why it matters: The AI didn't escape its test environment or get tricked into misbehaving; given capability and no guardrails, its target was people. It backed its submission from a second fake account and spear-phished under invented names. It hid instructions for other AI coding tools in webpage text that only software reads. A human maintainer caught it. One incomplete patch reopens N-able N-central to console takeover → Brief: N-able disclosed CVE-2026-18577, an authentication bypass in N-central exploited as a zero-day, which reopened account takeover because an earlier fix for CVE-2026-18556 was incomplete. Intel: N-able's Adlumin managed detection service caught the zero-day on July 31; hotfix 2026.3.1.7 shipped August 2, and a hardened replacement, 2026.3.1.10, followed August 6. CISA added the flaw to the Known Exploited Vulnerabilities (KEV) catalog on August 3 with an August 6 federal deadline, the three-day window Binding Operational Directive 26-04 reserves for urgent risk. Huntress reports attackers took full administrative control of the N-central console, the dashboard managed service providers use to run customer systems, then used Take Control, N-central's own remote-access tool, to reach customer machines, scouted the Domain Controllers running the network, and set up hidden connections to keep access. Why it matters: One console means administrative reach over every downstream customer, which is why exploitation went straight for Take Control and Domain Controllers. Huntress found nearly all cloud-hosted servers patched by August 3, while 28.6% of reachable self-hosted ones stayed exposed. The risk pooled where customers manage the console alone. Stat of the week: 19% The jump in ransomware attacks from June to July, 668 to 799 incidents, according to Comparitech, with finance attacks up 71 percent while ransomware against utility companies, the sector dominating recent headlines, fell 44 percent. Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.148Views0likes0CommentsMicrosoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)
On August 11, Microsoft released its August 2026 Patch Tuesday release which patched 398 CVEs with 42 rated critical, 355 rated as important and one rated as moderate. This update includes patches for three zero-days, including one that was exploited in the wild. CVE-2026-68820 is an EoP vulnerability affecting Windows Ancillary Function Driver for WinSock. It received a CVSSv3 score of 7.0 and was rated as important. A local attacker could exploit this vulnerability to elevate to SYSTEM privileges. According to Microsoft, this vulnerability was exploited in the wild as a zero-day. CVE-2026-62832 is an elevation of privilege vulnerability affecting Windows User Profile Service. It received a CVSSv3 score of 7.8 and is rated as important. A local attacker could exploit this vulnerability to gain ADMINISTRATOR privileges. It was publicly disclosed prior to a patch being available and was assessed as “Exploitation More Likely.” CVE-2026-72971 is a tampering vulnerability affecting the Windows Container Isolation FS Filter Driver (unionfs.sys). It received a CVSSv3 score of 5.5 and is rated as important. It was publicly disclosed prior to a patch being available. Successful exploitation would allow a local attacker to perform tampering. Despite being publicly disclosed, Microsoft assesses this vulnerability as “Exploitation Unlikely.” This month’s update includes patches for: .NET .NET Core .NET Framework AMD Zen Active Directory Certificate Services (AD CS) Application Information Services Azure Active Directory Azure CycleCloud Azure Monitor Agent Azure Storage Explorer Capability Access Management Service (camsvc) Desktop Window Manager Dynamics Business Central GitHub Copilot and Visual Studio Code Microsoft Azure Attestation service and Device Health Attestation Service Microsoft COM for Windows Microsoft Defender for Endpoint Microsoft Digest Authentication Microsoft Dynamics 365 (on-premises) Microsoft Entra Connect Sync Microsoft Exchange Server Microsoft High Performance Computing (HPC) Pack Microsoft Identity Services Microsoft Local Security Authority Server (lsasrv) Microsoft Office Microsoft Office Access Microsoft Office Excel Microsoft Office Graphics Component Microsoft Office Outlook Microsoft Office PowerPoint Microsoft Office SharePoint Microsoft Office Word Microsoft OneDrive Microsoft PowerShell Microsoft PowerShell Core Microsoft QUIC Microsoft Remote Registry Service Microsoft Teams Mobile Microsoft Teams for Android Microsoft Windows Codecs Library Microsoft Windows Media Foundation Microsoft Windows Search Component Power BI RPC Runtime Reliable Multicast Transport Driver (RMCAST) Remote Desktop Client User-Mode Power Service (UMPS) Virtual Hard Disk (VHD) Miniport Driver Visual Studio Code Visual Studio Code - Python extension Visual Studio Code CoPilot Chat Extension Windows Accessibility Infrastructure (ATBroker.exe) Windows Active Directory Windows Ancillary Function Driver for WinSock Windows Autopilot Windows Backup Engine Windows Bind Filter Driver Windows Cloud Files Mini Filter Driver Windows Common Log File System Driver Windows Container Isolation FS Filter Driver (unionfs.sys) Windows Cross Device Service Windows DHCP Client Windows DHCP Server Windows DNS Windows DWM Core Library Windows Defender Firewall Service Windows Deployment Services Windows Device Association Service Windows Display Enhancement Service Windows Encrypting File System (EFS) Windows Event Logging Service Windows GDI Windows GDI+ Windows Graphics Kernel Windows HTTP Protocol Stack Windows HTTP.sys Windows Hello Windows Hyper-V Windows Imaging Component Windows Installer Windows Kerberos Windows Kernel Windows Key Guard Windows LDAP - Lightweight Directory Access Protocol Windows LUAFV Windows License Manager Windows MIDI Service Module Windows Management Instrumentation Windows Management Services Windows Message Queuing Windows Modern Device Management (MDM) Windows NTFS Windows Narrator Braille Windows Network Address Translation (NAT) Windows Network Connection Broker Windows Network File System Windows Package Manager Windows Program Compatibility Assistant Service Windows Projected File System Windows Push Notifications Windows RPC API Windows Remote Access API Windows Remote Access Connection Manager Windows Remote Desktop Services Windows Remote Help Windows Remote Help Defense Windows Routing and Remote Access Service (RRAS) Windows SMB Client Windows SMB Server Windows Schannel Windows Secure Socket Tunneling Protocol (SSTP) Windows Sensor Data Service Windows Shell Windows Storage Windows Storage Port Driver Windows TCP/IP Windows Telephony Service Windows USB Driver Windows Universal Disk Format File System Driver (UDFS) Windows User Profile Service Windows Win32K Windows Wired AutoConfig Service Windows Work Folder Service Windows iSCSI Target Service Winlogon For more information, please visit our blog.scaveza27 days agoProduct Team306Views0likes0CommentsTenable Security Intel Brief: Multi-state cyberattacks hit water systems
Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team. This week, a coordinated attack disrupted operational technology at more than 30 Minnesota community water and wastewater systems, part of a wave the FBI says reached at least seven states. Our research team assesses the activity is consistent with the Iran-linked CyberAv3ngers ecosystem. U.S. officials have preliminarily pointed to Iran, though no formal attribution has been made. Coordinated cyberattack disrupts 30-plus Minnesota water systems → Brief: A coordinated attack disrupted control systems at 30-plus Minnesota water and wastewater plants, one cluster in a wave the FBI says reached at least seven states. Intel: Four Minnesota cities disclosed attacks. In Braham (~1,700 residents), the plant was taken offline, then restored in two hours; Plymouth switched to manual operation and Maple Plain declared an emergency, no water-quality impact reported. U.S. officials told outlets a preliminary assessment points to Iran, citing the tradecraft and lack of a ransom demand, though it could change. Our research finds the pattern consistent with CyberAv3ngers, which the U.S. links to Iran's IRGC. No agency has named a flaw, but the one most tied to it, CVE-2021-22681 (CVSS 9.8), lets attackers reach Rockwell Logix controllers without authentication. Update (August 4): On July 30, an FBI-EPA advisory said utilities in at least seven states had reported incidents since July 27, some degrading operations, naming no states or actor; CISA urged utilities to pull exposed programmable logic controllers (PLCs) offline. On August 1, Michigan became the second confirmed state, an EGLE official citing nine systems and no health impact. By August 4, ABC News and Axios reported possible cyber intrusions in "at least 12" states, citing unnamed sources; the FBI's tally still stands at seven. Why it matters: No flaw is named and attribution stays open, but the exposure is real: internet-facing controllers at least-resourced utilities, tied to a Rockwell weakness its maker says cannot be fully patched. No fix cycle to wait on, only network redesign. The wave already means a plant knocked offline in a town of 1,700. TA488 pivots to Outlook Web Access with a half-click backdoor → Brief: Proofpoint reports that TA488, a Russia-aligned actor also tracked as Void Blizzard and Laundry Bear, is exploiting CVE-2026-42897, an Outlook web (OWA) flaw Microsoft rated maximum severity and CISA lists as exploited, to deploy a browser-based backdoor called OWAReaper. Intel: The campaign began July 22, a day before Proofpoint and the NSA warned of the actor's Zimbra activity. Opening a bland TA488 lure email in OWA runs JavaScript hidden in the message's social-media-icon markup: the reading pane alone triggers it, no link or attachment. That JavaScript is OWAReaper, which Proofpoint calls its "most sophisticated" half-click backdoor yet and a descendant of last week's ZimReaper implant. It steals saved OWA passwords and access tokens, then grants Exchange's "Default" user owner access to every folder, opening it to the actor. Proofpoint says infrastructure predates Microsoft's patch by two months. Why it matters: The folder-permission grant lives on the Exchange server, so it outlasts the responses defenders reach for first. Proofpoint puts it plainly: "credential rotation and even full re-imaging of the targeted user's device will not evict the actor." A second backdoor in the browser's offline cache re-infects the rebuilt machine. This is TA488's second webmail half-click in two weeks. A Chinese-speaking actor ran DeepSeek as an autonomous attack operator → Brief: Palo Alto Networks' Unit 42 documented a Chinese-speaking threat actor, tracked as "knaithe" and "KnYuan," who ran DeepSeek as an AI that attacked on its own after a single instruction, built in the open-source Hermes Agent framework, commanded over Telegram. Intel: Hermes Agent gave the model terminal access and a skills system on a remote command channel. DeepSeek chose targets and wrote the code. From one Telegram instruction, it searched FOFA, an internet-scanning engine, pulled public exploits from GitHub, and attacked on its own. Both autonomous attacks were stopped by the targets' own setup: a Langflow flaw (CVE-2026-33017) and two n8n flaws (CVE-2026-21858 plus CVE-2025-68613). The confirmed damage was manual: a Citrix NetScaler flaw (CVE-2026-3055) leaked data from three organizations, a Marimo Notebook flaw (CVE-2026-39987) ran commands on 11 machines. Across 460+ targets, Unit 42 says the workflow "confirms a functional, end-to-end autonomous offensive capability," while the autonomous campaigns fully compromised none of their targets. Why it matters: The actor tried Claude Code and Codex, but Unit 42 found their provider-side controls "likely limited their effectiveness." DeepSeek was the most permissive alternative, run through a framework with nothing to disable. The starker finding is the one Unit 42 closes on: the technical barrier to AI-augmented offensive operations is low and still dropping. Two AI labs disclose test models reaching real production systems → Brief: Two AI labs disclosed real-world security incidents involving lab-tested models: Anthropic's models reached three real companies through a partner's misconfigured test setup, and OpenAI's models found unpatched flaws in JFrog's software, extending our July 22 OpenAI and Hugging Face coverage. Intel: OpenAI's models found zero-days in self-hosted Artifactory, its repository manager, that could be exploited to gain unintended internet access, JFrog confirmed. The company has shipped fixes; cloud customers are protected and self-hosted users directed to Artifactory 7.161. Its post names no CVEs, though the July 27 patch release carries nine newly assigned Artifactory CVEs. Anthropic separately reviewed 141,006 test runs and found three cases where Claude models reached the internet through partner Irregular's misconfigured test environment, accessing three organizations. In one, a model published a booby-trapped software package to PyPI, a public code library, that ran on 15 real systems, including a security firm's scanner, before PyPI removed it. Update (August 4): OpenAI disclosed two further incidents, separate from the Hugging Face escape, in which its models crossed testing boundaries during third-party evaluations. One was at the UK's AI Security Institute, where internet access was intentionally on and safety classifiers off to measure raw capability. The other was at Irregular, which also ran Anthropic's misconfigured test environment. Neither incident involved a zero-day. Why it matters: Two frontier labs disclosed the same event class in a month: capability tests run without released models' safeguards, in environments with network access. OpenAI's models identified a genuine zero-day. Anthropic calls its incidents "closer to a harness and operational failure than a model alignment failure." Either way, a model built to find a way out found one. Stat of the week: $4.99 million The global average cost of a data breach, up 12% year over year, according to the IBM 2026 Cost of a Data Breach Report, based on breaches at 602 organizations between March 2025 and February 2026. Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.148Views0likes0CommentsTenable Security Intel Brief: Russia's Zimbra zero-day ran five months undetected
Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team. This week, Proofpoint details TA488, a Russian-aligned private contractor that quietly exploited a Zimbra zero-day for at least five months in 2025, targeting Ukrainian government and US nuclear and defense industrial base organizations. TA488 hit US nuclear and defense targets with a Zimbra zero-day → Brief: TA488, a Russian-aligned private contractor, exploited CVE-2025-66376, a Zimbra Collaboration Suite zero-day, for at least five months in 2025, targeting Ukrainian government and US nuclear and defense industrial base organizations. Intel: Opening a malicious email in Zimbra's Classic UI webmail was enough to trigger the exploit. TA488 fragmented a malicious SVG tag behind fake CSS @import directives; Zimbra's sanitizer passed each fragment, and the browser reassembled them into executable JavaScript. The payload, tracked as ZimReaper, exfiltrated session security tokens, autocomplete passwords, 2FA scratch codes, the Global Address List, and 90 days of email. It registered a "ZimbraWeb" app-specific password for Internet Message Access Protocol (IMAP) access that bypassed 2FA. Zimbra patched in November 2025; no TA488 activity has been recorded since February 2026. Why it matters: ZimReaper registered a Zimbra application credential that IMAP accepts without a second factor, one that is separate from the account password. For organizations whose mail server is the crown jewel, the half-click delivery closed the window that normally buys time. The user did nothing wrong. GlobalProtect bypass becomes Qilin ransomware's entry point → Brief: Arctic Wolf Labs confirmed that CVE-2026-0257, a GlobalProtect authentication bypass fixed May 13, served as the initial access vector for multiple Qilin ransomware intrusions in June 2026. Intel: The flaw lets an unauthenticated attacker establish a valid VPN session; it is exploitable only where sign-in shortcut cookies are active alongside a specific certificate configuration. In the June intrusions, attackers dumped credentials from memory and the domain's password database, used a standard Windows admin tool to spread across the network, staged ransomware in an empty default Windows folder, then encrypted domain-wide. Tradecraft ranged from rapid encryption to full double-extortion, consistent with multiple Qilin Ransomware-as-a-Service (RaaS) affiliates. CISA flagged the CVE as exploited in ransomware attacks and Shadowserver tracks over 167,000 GlobalProtect instances exposed online. Why it matters: Our June 3 edition noted exploitability hinged on a certificate-wiring decision, not on CVSS. Researchers observed exploitation against numerous customers starting May 17, four days after the fix shipped; confirmed ransomware intrusions followed in June. The configuration gap that decides exposure was already being industrialized before the patch cycle closed. HOLLOWGRAPH turns Microsoft 365 calendars into an espionage dead-drop → Brief: Group-IB identified HOLLOWGRAPH, a malware implant using a compromised Microsoft 365 mailbox calendar as a two-way command channel, hiding operator tasking and stolen files inside events dated May 13, 2050. Intel: HOLLOWGRAPH runs two commands through the Microsoft Graph API, the cloud interface for Microsoft 365: 'get' pulls instructions from a planted calendar attachment; 'send' uploads stolen files into a new far-future event. No flaw is exploited; the malware uses a compromised account and stolen login credentials, leaving no patch. Group-IB tied the implant to Cavern Manticore with high confidence but could not attribute the campaign to any known actor. The Iranian-nexus link comes from a separate Check Point report covered in our July 15 edition. Group-IB counted 12 infected systems between June 3 and July 9, with a focus on Israeli entities. Why it matters: Detection built around flagging traffic to attacker-owned destinations has nothing to match when the command channel is a legitimate Microsoft 365 calendar. The 2050 date parks dead-drop events in a corner of the mailbox no one monitors, and two commands run a complete espionage loop. Oracle's CPU and a kernel flood put CVE volume on trial → Brief: Oracle's July 2026 Critical Patch Update, its quarterly patch bundle, addresses 1,235 unique CVEs in 1,449 patches across 32 product families, the largest CPU release in our analysis. Intel: Context: the January 2026 CPU covered 158 CVEs; April covered 241. That same week, 432 CVEs landed from the Linux kernel team, which issues its own CVEs, in a 31-hour window ending July 20. Jan Schaumann flagged the volume on OSS-SEC; Greg Kroah-Hartman, who oversees the kernel CVE program, explained it: "These were all pending for weeks," the result of "a perfect storm of 6 week straight of conferences and vacations." Kroah-Hartman added that "the number of llm-found issues is only on the rise right now." Why it matters: When one quarterly update carries 1,235 CVEs and the kernel publishes 432 in a weekend, a CVE stops working as a signal to act and becomes a unit of accounting. NVD has logged 45,207 CVEs this year, on pace to roughly double 2025's total; Bloomberg found no rise in exploitation. Stat of the week: $124 million Recorded financial exposure from wrench attacks (incidents where criminals use violence or threats to steal cryptocurrency) in 1H 2026, according to CertiK, which counted 52 verified incidents, up from 39 incidents and $10.5 million a year earlier. Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.173Views0likes0CommentsCoordinated "cyberattack" on Minnesota water utilities: What you need to know
A coordinated cyber attack disrupted water and wastewater operations in more than 30 Minnesota communities on July 26-27, 2026; attribution remains pending a federal investigation. Four days prior, CISA and six federal agencies updated Advisory AA26-097A, documenting Iranian-affiliated exploitation of internet-connected PLCs across US water, energy, and government sectors. This FAQ addresses both. CVE-2021-22681 is listed in CISA's Known Exploited Vulnerabilities catalog in connection with the activity documented in AA26-097A; the advisory does not name it by CVE ID, and it has not been confirmed as the vector for the Minnesota attacks, which remain under active federal investigation. CVE-2023-3595 and CVE-2024-6242 are included as platform hardening references for ControlLogix environments only. CVE Description CVSSv3 CVE-2021-22681 Rockwell Automation Studio 5000 Logix Designer / RSLogix 5000 Authentication Bypass Vulnerability 9.8 CVE-2023-3595 Rockwell Automation ControlLogix 1756 Communication Module Remote Code Execution Vulnerability 9.8 CVE-2024-6242 Rockwell Automation ControlLogix 1756 Trusted Slot Bypass Vulnerability 8.4 CVE-2021-22681 is confirmed exploited in the AA26-097A campaign and has no available vendor patch. CVE-2023-3595 and CVE-2024-6242 are platform hardening reference for ControlLogix environments only. For more information, including the availability of patches and Tenable product coverage, please visit our blog.snarang1 month agoProduct Team172Views0likes0Comments