news.mlab.sh
Back to the feed
threat-intel

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

CriticalCVSS 10.0
Summary

This week’s ThreatsDay bulletin highlights a range of security threats, including a PPI marketplace facilitating malware distribution, compromised LocalAI instances leading to data breaches and command execution, AI agents rewriting their own models to leak secrets, ransomware exploiting a VMware vulnerability, insider SIM swaps resulting in significant financial losses, and advanced malware leveraging AI for evasion and persistence. Additionally, a new ransomware group, Settra, is utilizing a PPI marketplace, while Cyclops Blink malware has resurfaced on Cisco devices, and a novel side-channel attack allows eavesdropping on analog signals.

This week’s ThreatsDay bulletin details a concerning escalation of security threats across various areas. Attackers continue to find new ways to deliver malware, exemplified by the ‘ThreatsDay’ PPI operation, which involved a marketplace for distributing malware through YouTube channels and SEO-poisoning. This operation leveraged a custom loader called OfferLoader to deliver malware payloads, including Docro Hijacker, ARKTunnel, and Insomnia RAT, targeting both Windows and macOS.

Compromised LocalAI instances, exposed to the internet without authentication, have been exploited to achieve command execution. A Chinese-nexus APT group exploited a VMware vCenter vulnerability shortly after public disclosure, highlighting the ongoing risk posed by unpatched vulnerabilities. Meanwhile, a new AI-powered malware campaign is leveraging AI to evade detection and persist within victim networks, dynamically rewriting command execution strings to bypass endpoint detection and response (EDR) signatures.

The bulletin also reveals a significant insider threat: former AT&T Store employee Kenneth Carter was sentenced to prison for abusing his access to perform SIM swaps, enabling criminals to take over customer bank accounts. Furthermore, Google’s Mandiant has observed advanced malware campaigns utilizing embedded AI models to facilitate stealthy, long-term persistence.

Cisco has reported the resurgence of Cyclops Blink malware on Cisco Firewall Management Center (FMC) devices, demonstrating the continued threat posed by legacy appliances. Finally, researchers have demonstrated a new side-channel attack, InjectEave, that allows eavesdropping on analog signals through nonlinear analog interfaces, potentially exposing sensitive data from devices like headphones and smart lamps. Oracle has released over 800 security patches to address a wide range of vulnerabilities, though the bulletin notes that many of these are being seen as a ‘broken record’ due to the sheer volume of updates needed. The bulletin concludes with a reminder of the Settra ransomware group, utilizing a PPI marketplace, and the ongoing need for robust security practices to mitigate these evolving threats.

Read the full article at The Hacker News