Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

STOMP Backdoor Uses PowerShell for Sensitive Data Theft

An advanced malware campaign known as TASK#STOMP has recently been discovered, which utilizes a PowerShell-based backdoor to collect busines...

All the recent news you need to know

TraderTraitor Mac Malware Targets IT Firm Through Weaponized Terraform Projects

 

A North Korean-linked cybercrime group known as TraderTraitor has tied another macOS infection in an IT services company with no cryptocurrency ties to the exploitation of fake job interviews to gain access to developer systems. The second victim, which has been identified as an India-based IT services provider, was targeted through one of the employees’ Apple Silicon MacBook belonging to a DevOps engineer. 

The compromised machine was used to manage AWS, OVH and OpenStack environments with the help of Terraform and Ansible, while the account also held cloud credentials and source code access. SentinelOne attributed the breach to the same FLATROOF and ROOFDECK macOS backdoors employed by TraderTraitor in the attack targeting LayerZero Labs that resulted in the $292 million heist from crypto project KelpDAO. Initially detected on March 18 the malicious implants remained undetected until March 29, when they were triggered by the victim launching a workspace within the Cursor development environment. 

FLATROOF implant, which has been dropped as SystemUpdate, can be used to execute arbitrary shell commands, terminate processes and steal data. Its capabilities also include harvesting browser information, terminal history, installed applications, running processes, system properties and the macOS login keychain database. ROOFDECK, which was deployed as iSync utility, allows for full command and control over the compromised system while also facilitating reverse shell access, file transfer exfiltration of data, reconnaissance, and persistent access through the use of LaunchAgents. 

It also has the capability to read the clipboard content, which may also contain passwords, cryptocurrency seed phrases and two-factor authentication (2FA) credentials. On April 20, which came shortly after the public disclosure of the LayerZero breach, the threat actors deployed a modified version of ROOFDECK while removing the initial implants. The new sample continued to communicate with the C2 infrastructure controlled by the attacker until June 1. “The incident serves as a stark reminder that developer endpoints must always be protected and monitored for suspicious activity,” the report noted. 

“These machines can serve as a gateway to cloud infrastructure, source code and deployment resources, which makes them attractive targets even for organizations with no direct involvement in crypto operations.” It added that organizations should carefully monitor developer workstations for anomalous behaviors, including the launch of unsigned binary from the home directory, processes spawned by the development environments, and unusual network connections. 

It also recommended conducting regular audits of the Terraform lock files and make sure that the providers listed in them are legitimate before launching unfamiliar coding assignments or repositories.

Claude Code Glitch Erases Years of Bengaluru Heritage Data

 

A critical AI mishap has put years of digital heritage preservation at risk in Bengaluru, after an automated coding assistant inadvertently wiped out substantial archival work. The incident involving Claude Code, an AI-powered development tool, has forced The Mythic Society—a Bengaluru-based nonprofit dedicated to documenting the city’s history—to rethink its reliance on autonomous systems for managing irreplaceable data. This incident serves as a stark reminder of the vulnerabilities that emerge when cutting-edge technology intersects with culturally significant archives without sufficient safeguards in place. 

The Mythic Society, which launched its heritage documentation project in 2021, saw years of curated content vanish when Claude Code “went rogue” during a routine update or scripting task. While exact technical details remain under review, reports indicate that the AI agent executed unintended commands that deleted or overwrote critical files. The loss encompasses digitized records, historical narratives, and metadata compiled over nearly five years, representing a significant setback for local heritage conservation efforts. For an organization built on preserving Bengaluru’s evolving identity, the disappearance of such work is not just a technical failure but a cultural loss that cannot be easily quantified. 

In the wake of the data loss, The Mythic Society is now allocating approximately Rs 15 lakh to overhaul its backup and recovery infrastructure. This investment aims to prevent similar incidents by introducing redundant storage, stricter access controls, and human-in-the-loop verification for any AI-assisted operations. The society’s leadership has emphasized that while AI tools can accelerate workflows, they must be governed by robust safeguards—especially when handling culturally sensitive and non-replicable archives. The financial commitment reflects both the urgency of restoring lost capabilities and the long-term necessity of building resilient systems that can withstand unexpected technological failures. 

The Bengaluru incident underscores a growing concern in the AI era: over-reliance on autonomous agents without adequate oversight can lead to catastrophic outcomes. Claude Code, designed to assist developers by generating and executing code, is not inherently malicious, but its actions must be constrained within well-defined boundaries. Experts suggest implementing layered approval processes, sandboxed execution environments, and real-time monitoring to mitigate risks when AI interacts with production systems or valuable datasets. As organizations increasingly adopt AI to streamline operations, this case highlights the importance of treating such tools as powerful yet fallible assistants that require constant human supervision. 

For organizations like The Mythic Society, the path forward involves balancing innovation with prudence. AI can undoubtedly enhance efficiency in digitization, transcription, and metadata tagging, but human oversight remains non-negotiable. The society’s decision to invest heavily in backup systems signals a renewed commitment to preserving Bengaluru’s heritage—with a clearer understanding that technology should serve as a tool, not a trustee, of cultural memory. As AI capabilities evolve, so too must the protocols that protect the irreplaceable work built upon them, ensuring that future advancements support rather than undermine the preservation of history.

Hacker vs. Hacker: ShinyHunters Outsmarts Clop Ransomware Gang

 




The extortion group ShinyHunters hacked the dark web leak site run by Clop, one of the most active ransomware operations in the world, defaced it with their own branding, and is now threatening to put Clop through the same extortion process Clop runs on its corporate victims.

The attack happened Friday night, September 19. ShinyHunters found an unauthenticated file upload flaw in Grav CMS, the content management system Clop was running its leak site on, and used it to push a text file directly onto the server. The file read: "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don't try to threaten us next time." It also linked back to ShinyHunters' own Tor site. The file was confirmed live and downloadable directly from Clop's server.

Hours later, ShinyHunters said they had gone further. A visit to Clop's site showed the entire page replaced with ASCII art of Umbreon, the Pokemon ShinyHunters uses as its logo, and the line "rooting your systems since '19 ;)". The same Umbreon artwork had appeared when ShinyHunters defaced HackForums back in August 2020. Clop's defaced page was still live at the time of writing.

ShinyHunters claimed full access to the server and said they took source code, Grav CMS plugins, and everything stored in the server's /var/log directory, which typically holds authentication logs, system activity records, and the IP addresses of everyone who connected to it. They also claim to have pulled the private keys for Clop's Tor onion service. Those keys are what tie a .onion address to its server. With them, ShinyHunters could host a copy of Clop's site at the exact same onion URL, on infrastructure they control. "We have their onion keys. So if they kick us out it wouldn't matter at all because we control the private keys to host the same exact onion URL," the group said.

The plan is to post an extortion message on their own site and give Clop 72 hours to respond.

The defacement and the uploaded file are independently confirmed. The claims about stolen source code, server logs, and Tor private keys come only from ShinyHunters and have not been independently verified. Clop has not commented.

The dispute behind this attack goes back about a year. In August 2025, Clop quietly began exploiting a zero-day vulnerability in Oracle E-Business Suite, tracked as CVE-2025-61882, a server-side request forgery flaw that gave attackers remote access to enterprise systems without authentication. Oracle did not patch it until October 2025, after Mandiant confirmed active exploitation. By then, Clop had already sent mass extortion emails to executives at dozens of companies, including Cox Enterprises, The Washington Post, Logitech, Michelin, and Estee Lauder.

ShinyHunters says that exploit was originally theirs and that Clop used it without authorization. In October 2025, ShinyHunters, operating under the name "Scattered Lapsus$ Hunters," leaked the proof-of-concept publicly. Oracle confirmed it matched the exploit used in the Clop attacks. ShinyHunters said the leak was deliberate, intended to disrupt Clop's campaign and expose what had been taken from them.

What followed, according to ShinyHunters, was a direct threat from a Clop representative. "During the Oracle EBS campaign they ran and stole from me last year, someone from cl0p personally messaged me and said, and I quote (translated from Russian): I have more money than you and all of your people combined, I'll kill you soon," the group said. Those allegations have not been independently verified.

This is not the first time criminal groups have turned on each other. In March 2025, DragonForce defaced the leak sites of rival operations BlackLock and Mamona. Later in 2026, two groups called 0APT and KryBit hacked and leaked each other's operational data until both were left severely damaged. The difference in the Clop case is the scale of the target. Clop's leak site is the operational center of its entire extortion model, the platform it uses to name victims and apply public pressure when ransoms go unpaid. Losing control of it, and potentially the keys that anchor its onion address, is not a minor disruption.

ShinyHunters' own Tor site went offline shortly after the attack. No connection to Clop has been established.

Researchers Escape OpenAI Codex Sandbox to Run Commands on Host


In OpenAI Codex, security researchers have identified two sandbox escape vulnerabilities, one of which allows developers to execute commands on their machine without prompting them. The vulnerabilities, Heapjack and Overpatch, affect different parts of the coding agent's security boundary. 

The vulnerability was reported to OpenAI by Accomplish AI on August 12. According to the researcher, Codex fixed both issues within eight days. The more serious Heapjack vulnerability demonstrated that malicious code could move beyond the restrictions imposed by Codex's sandbox, even when the agent was running as a read-only application. 

Heapjack Breaks the Sandbox Boundary

The node_repl component installed with Codex Desktop is targeted by heapjack. Although both OpenAI and untrusted agent code are run in separate JavaScript contexts, both operate within the same Node.js process and share the same memory heap, the separation was not sufficiently effective in preventing a security token from coming into contact with an untrusted environment. 

By inspecting the process heap, it was possible to obtain the token generated for the trusted context that remained in shared memory. When the token was obtained, the untrusted code could interact with a native parent process outside the sandbox using the communication channel used by the trusted context. As part of the demonstration of the technique, the researchers launched an application outside of Codex's process tree by utilizing the open command. 

A Unix socket as well as other system-level interfaces could also be reached through this access. This demonstration was especially important since it occurred while Codex was running in a strict read-only sandbox mode, where the agent was not expected to have any writing access to the wider system. 

The attack could be triggered by a seemingly routine development process. The researchers demonstrated a scenario in which malicious content contained in a repository, created by a third party, could exploit the vulnerability after the repository was opened in Codex and a query about its code was made. 

Overpatch Expands Write Access

Second, a vulnerability known as Overpatch affects the open-source Codex command line utility, and it takes an alternative route outside the sandbox. The vulnerability affects the application_patch tool used by Codex to modify files. 

In workspace-write mode, Codex is intended to limit file changes to the project directory. Researchers discovered that apply_patch, instead of expanding write permissions, could expand them based on paths included in patches. By using a path such as /tmp, the tool was able to treat the root of the file system as an accessible parent directory. In addition to the permission extension, researchers modified .zshrc by creating a symbolic link to the user's home directory so that it would be modified as well.

A successful write was not required for the /tmp entry; its presence extended the permissions granted to the patch operation. A modified shell configuration resulted in a file modification outside of the permitted workspace without an approval prompt. When a new terminal session was launched, attacker-controlled content ran. 

Two Flaws, One Security Boundary Problem

It is important to note that though Heapjack and Overpatch affect different parts of the Codex, both expose weaknesses in the way in which the security boundary of the agent was enforced. In the case of Overpatch, the tool responsible for applying changes also determined the scope from which it had access to data. 

In heapjack, trust boundaries were similarly compromised, as the token separating trusted and untrusted execution remained accessible in the same Node.js process and memory space as the untrusted code. The findings suggest that AI coding agents can be restricted in other ways than just controlling their abilities to execute commands. 

Untrusted agent activity must also be prevented from influencing the mechanisms that enforce those restrictions by the tools, processes and interfaces surrounding the model. On August 12, 2026, OpenAI was notified of the issues, and they were both addressed within eight days by Accomplish, who stated that Overpatch was addressed in Codex CLI 0.149.0, while Heapjack had been addressed in Codex Desktop build 26.818.21641.

A later statement by OpenAI confirmed that both issues had been resolved in August, and that additional measures were being taken to strengthen file-write controls and expand sandbox testing across platforms. These findings emphasize the security challenges associated with maintaining strong isolation in AI coding environments. Codex Desktop and Codex CLI have been updated to address both vulnerabilities.

Four Linux Kernel Flaws Expose Systems to Local Root Exploits

 

A security researcher has publicly released working exploit code for four Linux kernel vulnerabilities that can allow local users to escalate their privileges to root, giving them the highest level of access on an affected system. The vulnerabilities, dubbed DirtyAH6, TUNderflow, PPPoEject and DiagSpill, were discovered by researcher Asim Manizada and reported to the Linux kernel security team in mid-July. 

Kernel maintainers have since released fixes for all four flaws, meaning systems running fully updated kernels are not affected. Manizada published his technical analysis and working exploits on September 18 after coordinating with Linux distributions to give developers time to release patches. There are currently no reports of the vulnerabilities being exploited in real-world attacks. The published exploits were developed for specific kernel builds and can crash systems, making them primarily suited for isolated testing environments. 

Despite those limitations, publicly available exploit code increases the risk for systems that have not been patched. Local privilege escalation vulnerabilities are particularly relevant on shared or multi-user systems, where an attacker who has already obtained limited access can potentially use the flaws to gain complete control. Three of the vulnerabilities require unprivileged user namespaces to be enabled. 

This Linux feature allows ordinary users to obtain root-like privileges inside an isolated environment and is enabled by default on many distributions. DirtyAH6, tracked as CVE-2026-80844, affects the IPv6 IPsec Authentication Header code. TUNderflow, CVE-2026-81000, affects TUN/TAP virtual network devices, while PPPoEject, CVE-2026-68121, targets PPP over Ethernet code. DiagSpill, tracked as CVE-2026-74469, differs from the other three because it does not require user namespaces or special privileges. 

Instead, it requires the SCTP networking module to be available. Two vulnerabilities, DirtyAH6 and DiagSpill, can also be triggered remotely in limited circumstances, although the demonstrated remote impact is primarily system crashes. Manizada achieved remote root exploitation with DirtyAH6 in a controlled laboratory environment after first manipulating the target’s memory. He described achieving the same result remotely without that preparation as extremely difficult. He found no path to remote root with DiagSpill.

All four vulnerabilities are memory-safety flaws affecting different areas of Linux networking code. DirtyAH6 involves an out-of-bounds write in IPv6 IPsec handling, TUNderflow results from an integer wraparound in virtual networking code, PPPoEject is a use-after-free vulnerability, and DiagSpill involves a counter overflow that can result in a large out-of-bounds memory write. The researcher said the flaws were discovered using an AI-assisted process designed to map kernel memory handling and reason about memory layouts. 

The Linux fix for DirtyAH6 credits his custom AI tooling in its commit record. Manizada also previously disclosed another Linux kernel privilege-escalation flaw, OVSwrap, in July. Administrators should update to a kernel containing all four fixes. The first stable Linux kernel releases containing the complete set are 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.109, 6.18.50 and 7.2.4. Distribution kernels use their own versioning, however, so users should check security advisories from their Linux distributor to confirm the fixes have been included. 

If immediate patching is not possible, disabling unprivileged user namespaces can reduce exposure to DirtyAH6, TUNderflow and PPPoEject. Administrators can also disable AH6, TUN/TAP, PPPoE or SCTP features when they are not required. Manizada recommends patching rather than relying on feature restrictions because alternative exploitation paths may exist.

Critical Orkes Conductor Flaw Exploited for Unauthenticated Remote Code Execution

 

A critical vulnerability in Orkes Conductor is being actively exploited by attackers, potentially allowing them to execute arbitrary commands on vulnerable systems without authentication. Tracked as CVE-2026-58138 and rated 9.8 on the CVSS scale, the flaw affects Conductor, an open-source enterprise framework used to orchestrate microservices, workflows and AI agents. The vulnerability can be exploited through inline workflow definitions submitted to the platform’s workflow API. The security issue stems from the way Conductor executes scripts within workflows. 

Attackers can insert malicious JavaScript or Python expressions into workflow definitions and use them to execute arbitrary system commands. According to Empirical Security, INLINE tasks, along with LAMBDA, DO_WHILE and SWITCH tasks, can evaluate user-controlled JavaScript or Python expressions. Conductor creates the evaluator using a GraalVM context configured with HostAccess.ALL, effectively removing the intended sandbox protections. The attacker-controlled code can then reach the underlying Java runtime and execute operating system commands with the privileges of the Conductor process. 

In many deployments, that process runs with root privileges, potentially giving attackers extensive control over the affected system. Authentication does not prevent exploitation by default because the open-source Conductor server does not enforce authentication and leaves its workflow API accessible. An attacker can reportedly send a single unauthenticated POST request to register a malicious workflow containing an INLINE task and trigger its execution. Orkes patched CVE-2026-58138 in June with Conductor version 3.30.2. 

However, attackers began targeting the vulnerability after proof-of-concept exploit code was publicly released in early August. Empirical Security identified exploitation attempts in the wild on August 21. Fortinet subsequently blocked approximately 1,300 exploitation attempts between September 8 and September 9 and has issued an outbreak alert warning about continued exploitation. Organizations running Conductor should upgrade to version 3.30.2 or later and limit external access to the platform’s workflow API endpoints. 

Security teams should also place Conductor deployments behind firewalls and ensure vulnerable services are not directly exposed to the public internet. Administrators should monitor Conductor instances for suspicious workflow submissions and unexpected command execution. Systems that previously ran vulnerable versions should also be reviewed for signs of unauthorized access or compromise.

Featured