In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA
This week’s cybersecurity news highlights a range of threats, including AI-powered attacks targeting computing power, ongoing Grandoreiro banking trojan campaigns, and a self-propagating ransomware group utilizing obfuscated encryption. Additionally, there are concerns regarding exposed critical infrastructure systems and a recent data breach affecting Ultrahuman users. Finally, Let’s Encrypt is preparing for post-quantum certificate adoption and a Comodo firewall vulnerability was discovered.
Threat actors are increasingly leveraging AI to enhance their attacks, as demonstrated by Anthropic’s analysis of AI-enabled cyber operations mapped against the MITRE ATT&CK framework. This analysis revealed a significant rise in the use of Large Language Models (LLMs) for high-risk activities such as lateral movement and credential dumping, suggesting a shift towards more sophisticated and autonomous attack chains. Simultaneously, traditional malware threats remain active, with the Grandoreiro banking trojan continuing its campaign across financial institutions and a self-propagating ransomware group, ‘The Gentlemen,’ utilizing a Go-based encryptor. A recent data breach at Ultrahuman exposed user data due to a compromised employee laptop, while a supply chain compromise bundled a crypto-miner within the Hola Browser. Finally, a vulnerability in an unpatched Comodo firewall was triggered by a malformed IPv6 packet.
Government agencies are also grappling with escalating cyber risks, with CISA issuing warnings about exploited Automatic Tank Gauge (ATG) systems used in critical infrastructure, prompting immediate disconnection from the internet. The potential involvement of Iranian threat actors in these attacks adds another layer of concern. Palantir’s CTO is being considered for the CISA director role amidst budget cuts. Let’s Encrypt is proactively addressing the future of web security by adopting Merkle Tree Certificates to mitigate the bandwidth impact of post-quantum cryptography, with a planned rollout in 2027.