Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

AI Watermarking Meant to Protect Against Misuse Could Actually Enable It

  A security feature designed to make AI text traceable appears to have an unintended side effect: it can change how a language model behave...

All the recent news you need to know

Former Engineer Jailed for Ransomware-Style Cyberattack

 

A former employee of a New Jersey-based industrial company has been sentenced to 32 months in federal prison for launching a computer network attack and attempting to extort his former employer. Daniel Rhyne, 59, of Kansas City, Missouri, was sentenced by U.S. District Judge Michael A. Shipp on September 28, 2026, at federal court in Trenton, New Jersey. The sentence followed his guilty plea to charges involving extortion through a threat to damage a protected computer and intentional damage to a protected computer. 

According to court documents and statements made during the proceedings, Rhyne previously worked as a core infrastructure engineer for the U.S.-based industrial company, identified in court records as Victim-1. While he was living in New Jersey in November 2023, he allegedly began preparing a plan to disrupt the company’s computer network and force it to pay a ransom. His position reportedly gave him technical knowledge and access that allowed him to plan the attack against the company’s critical systems. 

As part of the scheme, Rhyne initiated unauthorized remote desktop sessions and scheduled tasks designed to damage the company’s network. The planned actions included deleting network administrator accounts, changing passwords linked to other employee accounts and shutting down several company servers. These steps could have seriously disrupted business operations by preventing authorized staff from accessing systems and interrupting essential digital services. 

On November 25, 2023, Rhyne sent an extortion email to employees of the industrial company. In the message, he threatened to continue shutting down servers unless the company paid approximately 20 bitcoin. At the time, the cryptocurrency demand was valued at about $750,000. The case highlights how former employees with detailed knowledge of internal infrastructure can pose a significant cybersecurity risk, especially when access controls and administrative privileges are not promptly reviewed after employment ends. 

The investigation was conducted by special agents from the FBI’s Newark Field Office, with assistance from the FBI’s Kansas City Field Office. U.S. Attorney Robert Frazer announced the sentence, while Assistant U.S. Attorney Taj Moore of the Cybercrime Unit prosecuted the case. The conviction demonstrates that unauthorized access, deliberate disruption of computer networks and ransom demands can result in substantial federal prison sentences. It also underlines the importance of removing former employees’ access, monitoring remote sessions and protecting administrator accounts against misuse.

MALFEX npm Campaign Uses Three Malware Delivery Chains

 

A long-running malware campaign on the npm registry is using malicious JavaScript packages to compromise Windows systems with remote-access malware, information stealers and additional payloads. Researchers have linked the operation, known as MALFEX, to an apparent single operator active on npm since August 2023. 

The operator has published 12 packages, eight of which were found to contain malicious code. Together, the packages had recorded 40,767 downloads by October 1. However, those figures represent package downloads rather than confirmed infections. MALFEX currently uses three separate infection chains. The first delivers the Overlord Remote Access Trojan through packages including tlxbnhd, tldriver and mxdriver. 

Malicious installation scripts download and execute a Windows payload disguised as an image. Overlord can capture screenshots, keystrokes and clipboard data, search files and provide attackers with remote shell access. It also establishes persistence through a scheduled Windows task named “Maiden.” A second chain involves native-runner, img-to-native and cdn-img-fetch. 

Instead of relying on an npm installation script, the malicious code executes when the package is loaded. Data hidden inside an image is decrypted to produce a downloader, which retrieves movinlike, a Node.js information stealer. The malware targets Discord accounts, browser credentials, Telegram session data and cryptocurrency wallets before sending stolen information to an attacker-controlled Discord webhook. 

The third and longest-running chain revolves around function-flag. Its malicious versions contain code that downloads Windows executables from changing external locations. In version 1.7.3, a hidden routine triggered during installation downloads node.exe and executes it from the user’s application-data directory. function-color serves as a wrapper that installs function-flag. 

Three malicious packages remained installable as of September 29: function-flag, function-color and cdn-img-fetch. function-flag accounted for 37,419 downloads, making it by far the most widely downloaded package in the campaign. Despite that activity, it had no security advisory. function-color also lacked an advisory, while the advisory for cdn-img-fetch covered only versions 1.0.0 and 1.0.1, leaving malicious versions 1.0.2 and 1.0.3 outside its coverage. 

The campaign also uses several techniques to make detection harder. Malicious code can be hidden beyond the visible area of a typical editor, failed downloads may be suppressed without generating installation errors, and the attacker has published benign packages alongside the malicious ones. Security teams should block all eight identified malicious packages and check dependency trees and lockfiles for them. 

Any Windows system where one was installed should be treated as potentially compromised, isolated from the network and investigated. Organizations should also remove persistence mechanisms and rotate credentials from a clean device if sensitive accounts were used on the affected machine. 

MALFEX highlights the risk of relying solely on npm advisory feeds: malicious packages can remain installable even when related packages have been removed, while some dangerous versions may have no advisory coverage at all.

US Probes Cyberattack on Energy Tankers Over Possible Iran Ties


One of the Journal reported that US authorities are investigating a possible Iranian connection to cyberattacks targeting two energy tankers in August heading toward American ports. A number of vessels were attacked as they passed through the Strait of Gibraltar before proceeding towards Texas. These vessels were the oil tanker VL Prosperity and the liquefied petroleum gas carrier Kohaku which were targeted. 

At the time of the incident, the VL Prosperity was transporting more than two million barrels of oil from Egypt to Galveston, Texas. The Kohaku was also on its way to Texas where it was scheduled to load liquefied petroleum gas. Following the arrival of the vessels in the Gulf of Mexico, a specially trained cyber response team led by FBI personnel boarded both. 

The Coast Guard conducted several days of assessments of the incidents and checked to ensure that the vessels could continue operating safely after they discovered signs of a compromise of their information technology and operational systems. According to reports published in August, hackers gained access to the engine-room systems of the VL Prosperity and interfered with several engine functions, including cooling, speed, fuel, and engine oil. 

There was no claim of responsibility from any group, and the reported details were unable to be independently verified. Later on, the vessel's manager confirmed that US authorities examined the tanker's cybersecurity before clearing it for normal operations. This incident illustrates the risks associated with interconnected systems that are used aboard modern commercial vessels. 

As a result of the integration of information technology with propulsion, navigation, and engineering systems on board, it may be difficult for a successful intrusion to affect the vessel's physical performance. Neither incident has disrupted operational operations, caused harm to crews, or damaged the environment, and no attribution of these attacks has been made public to Iran. 

Additionally, the investigation takes place in the context of increased suspicions of Iranian-linked cyber activity by US agencies. A maritime security expert has warned that it may be difficult to determine the actual extent of attacks against shipping, especially when vessel operators restore systems quickly without thoroughly investigating how an intrusion occurred. 

According to Lloyd's List, US agencies are monitoring cyber threats involving almost 20 ships worldwide, which raises concerns over the growing vulnerability of commercial shipping. The risks extend beyond individual ships as well. Navigating, propulsion, steering, and other critical operations of commercial vessels are increasingly dependent on connected digital systems. The compromise of these systems could negatively impact a vessel’s movements or create broader difficulties around major shipping routes and ports. 

A serious disruption could result in a fire, explosion, or spill. An investigation of the tanker is also underway as key maritime routes are becoming increasingly congested. It is important to note that the crossing of the Strait of Hormuz has been repeatedly disrupted and attacked during the conflict, while Iran-backed Houthi forces have exerted increased pressure on vessels operating around the Red Sea and Bab al-Mandab Strait. 

Since cyberattacks could take place against vessels traveling outside these traditional conflict zones, maritime security concerns have been intensified. US authorities have not yet established that Iran was responsible for the attacks. There has also been no determination as to whether the attacks were connected to each other. Further investigations by the FBI and Coast Guard may clarify whether the attacks were isolated incidents or part of a broader campaign targeted at maritime infrastructure.

Japanase Media Company Nikkei Reveals Intrusions Attacking Users and Employees


Japanese media company Nikkei has disclosed two separate cyber incidents involving employee accounts on Microsoft 365 and Google Workspace. One of the incidents allowed attackers to use an employee's account to send about 9,000 phishing emails, while the other may have exposed the personal information of 1,646 employees and business partners.

The incidents were disclosed on October 4 and reveal the risks organizations face when attackers gain access to legitimate employee accounts. Nikkei has not attributed either incident to a specific hacking group or confirmed whether the two attacks were connected. 

Microsoft 365 account used to send phishing mails

The more recent incident involved an employee's Microsoft 365 account. According to Nikkei, attackers gained unauthorized access to the account and used it on September 30 to send approximately 9,000 emails.

The messages were sent to people both inside and outside the company. Some recipients were journalistic sources and other individuals who had previously communicated with Nikkei employees.

The emails contained links leading to malicious websites. Because the messages were sent from a legitimate Nikkei employee account, recipients could have been more likely to trust them. This type of account compromise can allow attackers to use an organization's existing relationships to distribute phishing messages.

Nikkei said the incident may have exposed recipients' names and email addresses, along with the contents of some emails. The company is still investigating the number of people whose personal information may have been affected. According to Nikkei, “There may be an increase in emails impersonating Nikkei employees or our group companies,”

Google workspace breach

Nikkei also disclosed a separate incident involving an employee's Google Workspace account. The account was accessed without authorization beginning in late July.

The company discovered the intrusion in early August after receiving an alert from Google. Nikkei then changed the account's password and said it has not detected any further unauthorized access.

The incident may have exposed information belonging to 1,646 employees and business partners. The potentially affected information included names and email addresses.

Nikkei said the exposed information did not include data related to its readers or journalistic sources. The company also said it has found no evidence that the information was misused. 

Nikkei’s response

After the Microsoft 365 incident, Nikkei changed the affected password and contacted recipients of the phishing emails, asking them to delete the messages. The company warned that additional emails impersonating Nikkei employees or its group companies could appear.

Nikkei has also reported the incidents to Japan's data protection authority. Investigations into the scope of the Microsoft 365 compromise and the information potentially exposed are continuing.

Nikkei has experienced other cybersecurity incidents in recent years. In November 2025, the company disclosed a malware-related credential theft incident that potentially exposed information connected to more than 17,000 employees and business partners. 

Meta's AI Agent Read 187,000 Private Messages. Now Apple Is Changing the Rules




Apple has announced plans to overhaul one of macOS's most powerful privacy settings, citing security risks posed by AI agents that have been using it to access user data in ways most people never anticipated.

The setting, Full Disk Access, lives inside Privacy & Security in macOS Settings and was introduced with macOS Mojave (version 10.14). It gives users control over which applications can read system-level data, including files, Mail, Messages, Safari history, and Time Machine backups. Security tools and backup software rely on it legitimately. The problem is that once granted, an application can bypass many of the protections Apple built to keep sensitive data off-limits to third parties.

Apple warned in a developer advisory that some developers are using Full Disk Access to expose everything on a user's system without their full knowledge, and that for communication apps this also compromises the privacy of the people those users are messaging. The company said it plans to update the setting so access can only be granted through an explicit user action, and that as AI agents grow more capable and autonomous, the risks tied to this level of access will only increase. When the new controls will arrive has not been said.

The announcement follows a controversy involving Meta's personal AI agent, Muse. When the app launched on September 8, Inc. columnist Jason Aten installed it and says he explicitly declined to give it access to his Messages, calendar, or personal data. Despite that, Muse pitched him a column idea drawn from a private text exchange with his podcast co-host. Aten says Full Disk Access was disabled on his machine, yet the agent had synced more than 187,000 rows of his private iMessages to Meta's cloud. When he asked Muse directly how it read those conversations, the agent told him the paired Mac app was only relaying notification previews, an explanation that turned out to be false. Meta's David Singleton later called it a fabricated account of the feature.

Meta disputed the broader account. Singleton and communications head Andy Stone both argued that reading Messages requires two separate permissions: Full Disk Access must be active in macOS, and the Messages connector within Muse must also be switched on. Singleton said that without Full Disk Access, all related options are greyed out and the feature does not work. Whether that permission was ever active on Aten's Mac is something the two sides still disagree on.

What the episode made clear, regardless of how that specific question gets resolved, is exactly the scenario Apple is now trying to prevent: AI agents accumulating sweeping system permissions that users did not fully understand they had handed over.

The problem extends beyond confusing permission dialogs. On September 21, security researcher Patrick Wardle, founder of the Objective-See Foundation, published a zero-day flaw in Muse's Mac app before Meta had a patch ready, accompanied by a working proof of concept called "not-a-mused." The flaw centered on an undocumented configuration setting called "endo_voyager_dictation_endpoint" that any unprivileged local process could overwrite without admin rights and without triggering macOS security prompts. An attacker who had already landed on the machine could use it to redirect Muse's dictation traffic, capture audio and prompts, inject malicious instructions, and take advantage of every permission the agent held, covering files, microphone, camera, calendar, location data, and linked iOS devices. Wardle's proof of concept demonstrated over 50 commands being executed through the compromised agent.

Meta deployed a patch within 24 hours of disclosure, but Wardle argued that a ClickFix-style attack could have made the exploit remote, giving attackers access to any device running Muse, not just machines they had already penetrated by other means. He described Muse's extensive system permissions as making it trivial to turn the agent into a ready-made backdoor.

Wardle also separately reported a flaw in OpenAI's ChatGPT Mac app, tracked as CVE-2026-100754, that could have let attackers take over the assistant and access chat logs and other stored data. He described the exploit as insanely trivial, requiring roughly a dozen lines of code, and noted it could also be used to get ChatGPT to run commands on an attacker's behalf, with the requests appearing as legitimate instructions from the OpenAI software. OpenAI has since patched it.

Wardle has said he will present analysis of multiple AI macOS application vulnerabilities at Objective by the Sea, an Apple-focused security conference in November, and has already submitted a further finding to OpenAI related to the integration between ChatGPT and the company's always-on Dots AI assistant.

The pattern across all three incidents points to a structural problem the industry has not resolved. AI agents need deep system access to function, and that same access makes them attractive targets. "AI companies are fixated on adding features right now," Wardle said, and the permission frameworks macOS relies on were not designed with always-running, autonomous agents in mind. Apple's planned changes to Full Disk Access are an attempt to close that gap, though what those controls will actually look like when they ship remains unknown.


AI Spam Surge Forces Google to Pause Open Source Bug Bounty Program


OSS VRP (Open Source Software Vulnerability Rewards Program) has temporarily been suspended after a sharp increase in automated reports that were found to be valid. Since October 1, security teams and open-source maintainers have been facing an increasing number of low-quality vulnerability reports generated via artificial intelligence. 


The pause, which took effect on October 1, is in response to increasing volumes of low-quality vulnerability reports. Google announced the OSS VRP in August 2022 as a means of rewarding researchers who identifies and responsibly discloses security flaws in open-source software maintained by the company. 

The program covers projects such as Golang, Angular, Bazel, Protocol Buffers and Fuchsia, along with selected third-party dependencies. Security concerns regarding GitHub Actions, application configurations, repository settings, and access control rules are also covered by this program. There was initially a range of rewards available from $100 to $31,337 under the program, with particular emphasis placed on vulnerabilities that could potentially pose significant risks for software suppliers. 

As a result of the company's wider vulnerability rewards program, millions of dollars have since been awarded to researchers, making the OSS VRP an important means of identifying security vulnerabilities in widely used open-source projects. An increase in automated submissions was responsible for the current suspension, according to the company, with the majority failing to identify valid security issues. 

Although the use of artificial intelligence-assisted tools has made the generation of vulnerability reports at scale easier, the resulting volume may also include incorrect findings, duplicate claims, and reports concerning vulnerabilities that do not exist. OSS VRP is currently being reviewed by Google to address the issue and determine how the program should handle the growing number of automated submissions. 

A further update is anticipated in the first quarter of 2027. Additionally, the company clarifies that the change does not affect outstanding reports or product vulnerabilities submitted prior to October 1. The impact of the AI-driven reporting surge extends beyond Google's program as well. 


It has not been the company's first time experiencing a sharp increase in low-quality vulnerability submissions that have been generated by automated tools. This raises concerns about the time security teams will need to spend validating reports that do not identify genuine vulnerabilities. The Google Patch Rewards Program continues to offer incentives to researchers for submitting high-impact open-source security patches that qualify for rewards of up to $15,000. 

Google Cloud's Cloud Vulnerability Reward Program provides a means of reporting security vulnerabilities affecting open-source repositories related to Google Cloud products. Google's decision follows similar developments elsewhere in the security industry. In January, the curl project maintainer terminated its HackerOne bug bounty program in response to a significant number of low-quality, artificial intelligence-generated vulnerability reports. 

As part of its Intigriti bug bounty program, Intel also removed financial rewards in September, though the company did not provide a publicly stated reason for the change. As the use of artificial intelligence tools increases in speed, potential vulnerabilities are identified and reported more rapidly, while the review process remains the responsibility of security researchers and maintainers. 

Earlier this year, Microsoft warned that AI-assisted vulnerability discovery could increase the number and scale of security discoveries, potentially increasing the operational demands on security teams. Google has not yet confirmed that the Open Source OSS VRP will be permanently discontinued. The company is reviewing the program and anticipates making changes in the first quarter of 2027. 

For now, the temporary suspension reflects a growing challenge for bug bounty programs, namely, how to handle a large volume of automated reports without allowing invalid findings to overwhelm genuine security issues. 

The decision of Google highlights the difficulty of vulnerability reward programs as AI-assisted security research increases submissions. It will become increasingly important for these programs to distinguish genuine findings from automated and inaccurate reports in order for them to be effective.

Featured