Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Most Enterprises Are Unprepared for AI and Quantum Threats, PwC Survey Finds

 



Most organizations around the world are spending more on cybersecurity than at any point in their history. Very few are spending it on the threats that are actually coming for them. That is the central tension running through PwC's 2027 Global Digital Trust Insights report, which drew responses from nearly 4,000 business and technology leaders spanning more than 70 countries.

Artificial intelligence sits at the core of the report's findings, and not in the way most organizations would prefer. Leaders surveyed identified attacks targeting their own AI systems as the single cyber threat they feel least prepared to handle. Over half of respondents, 53 percent, said they are not adequately defended against autonomous botnet attacks, where AI drives the probe and compromise of networks faster than human teams can respond. Adversarial attacks and data poisoning followed at 52 percent each, pointing to a defensive gap that has widened as attackers have adopted the same tools organizations are still trying to implement on the defense side.

Prompt injection sits squarely at the heart of this problem. Unlike conventional exploits that target code vulnerabilities, prompt injection manipulates the AI model itself, tricking it into leaking data, executing unauthorized commands, or acting entirely outside its designed purpose. OpenAI acknowledged in late 2025 that prompt injection, much like social engineering before it, is a problem that cannot be fully engineered away. The Open Worldwide Application Security Project has ranked it number one on its threat list for LLM applications for three consecutive updates, a position it has held since the list first debuted. The persistence of that ranking reflects not a shortage of incidents, but the structural difficulty of closing an attack surface that is, in effect, the model's own reasoning process.

Despite all of this, AI is simultaneously the security tool leaders trust most. The survey found it ranked first for threat detection and alerting across the respondent pool. The contradiction is in what comes next. Only 22 percent of leaders said they would let AI agents operate in cyber defense without requiring human sign-off on their actions. Fifty-five percent attributed this reluctance to reliability and maturity concerns, while 44 percent pointed to a skills shortage in AI oversight and governance.

That hesitation is not irrational, but it carries a cost. AI-driven attacks operate at a pace that leaves human response cycles behind. Requiring manual approval for every automated defensive action is, in practice, fighting a faster adversary at a slower speed. At some point, fully autonomous defense may not be optional. What makes that shift harder is that organizations have not settled on who would be accountable for it. The survey found that 29 percent of leaders placed AI security accountability with the CIO or CTO, 26 percent with a dedicated AI leadership role, and only 17 percent with the CISO. Eleven percent said responsibility was shared across multiple functions, which in most organizations means it belongs to no one in particular.

Budget signals at least suggest that leaders recognize the scale of the problem. Eighty-four percent of security and finance leaders said they expect cyber budgets to increase, with 58 percent naming AI as their top spending priority for the coming year.

The second major warning in PwC's report concerns quantum computing, and the picture there is, if anything, more concerning. Quantum computers capable of breaking the encryption that currently secures financial records, government communications, and enterprise data are not yet commercially operational. But the attack strategy does not require them to be. State-sponsored threat groups and other sophisticated actors are already collecting encrypted data now, banking on the ability to decrypt it once quantum capability matures. Most cryptography researchers put that window between 2030 and 2035, and the timeline for migrating large-scale cryptographic infrastructure is measured in years, not months. The National Institute of Standards and Technology finalized its first three post-quantum cryptography standards in August 2024, covering quantum-resistant key exchange and digital signatures, and told organizations explicitly that there is no reason to delay. PwC's survey found that only 21 percent of respondents are currently implementing those standards.

What makes this more urgent than a theoretical risk is that the harvesting is already underway. The FBI confirmed in August 2025 that a Chinese state-sponsored group tracked as Salt Typhoon had compromised more than 200 organizations spanning more than 80 countries, with nine major US telecommunications carriers among the confirmed victims. In at least one documented case, the group maintained undetected access to a telecom network for three years, collecting communications data throughout. That data, encrypted under today's standards, sits in storage waiting for the decryption capability that quantum hardware will eventually provide. Governments are beginning to respond with deadlines rather than guidelines. In June 2026, President Trump signed executive orders requiring federal agencies to migrate high-value systems to NIST-approved post-quantum cryptography standards by 2030 and 2031 respectively, with government contractors expected to follow. The private sector has no equivalent mandate, and PwC's survey makes clear that most organizations are not filling that gap on their own.

"Technology is moving incredibly fast, but the fundamentals of cybersecurity haven't changed," said Morgan Adamski, PwC's cyber, data and technology risk leader. "You can invest heavily in AI and the latest security tools, but if you don't have secure data, operational continuity, clear accountability and strong cyber hygiene underneath them, you're building on a weak foundation. The goal isn't to slow innovation down. It's to make sure your organization is resilient enough to keep up with it."

What the survey documents, across both AI and quantum, is the distance between knowing what needs to be done and actually doing it. The tools exist. The standards are published. The gap is operational, and the cost of that gap is rising by the month.


Automakers Face Scrutiny Over Connected-Car Data Sharing

 

Modern connected cars are increasingly functioning as data-collection platforms, with new research finding that many automakers routinely transmit customer information to advertisers, analytics providers, technology companies and data brokers. The findings, released by Northeastern University researchers in collaboration with Consumer Reports, raise fresh concerns about how much control drivers have over information generated by their vehicles and companion mobile applications. Of the 21 major automakers examined, 19 were found to collect and broadly share private consumer data, showing that the privacy risks extend well beyond a carmaker’s own systems. 

The study examined both vehicles and 30 connected-car apps, which are commonly used for remote locking, navigation, vehicle health reports and other services. Twenty-eight of those 30 apps shared data with at least one third-party advertising or analytics firm. More concerningly, seven apps sent personally identifiable information to outside companies, including owners’ names, email addresses and precise geolocation data. Such information can reveal where a person lives, works, shops or travels, making connected-car data particularly sensitive compared with ordinary online browsing records. 

Researchers also found that apps from General Motors brands—myCadillac, myChevrolet, myBuick and myGMC—as well as Honda, Nissan and Lincoln, shared vehicle identification numbers alongside location data or email addresses. A VIN is a unique identifier tied to a specific car, and pairing it with personal information can make it easier for data brokers to link driving behavior to an identifiable individual. The data reportedly reached a wide group of companies, including Alphabet, Amazon, Microsoft, Meta, Reddit and Pinterest, highlighting the overlap between automotive technology and the broader digital advertising ecosystem. 

The findings arrive amid heightened regulatory attention on vehicle privacy. In May, California Attorney General Rob Bonta, the California Privacy Protection Agency and local prosecutors fined General Motors more than $12 million and ordered the company to stop sharing driver data with credit-reporting agencies and data brokers for five years. Automakers have argued that some data sharing is based on customer opt-in consent or contractual restrictions that limit third parties from independently selling information. However, Consumer Reports said many motorists may not fully understand what they accept when activating connected services, especially when declining data sharing may affect vehicle features.

Honda was the only automaker named in the report to respond publicly to a request for comment. The company said it aims to earn customer trust and, after being informed of the findings, directed an analytics vendor to delete location data already collected. Honda also said it would no longer share that information with third parties. The wider issue remains unresolved: consumers increasingly rely on internet-connected cars, yet disclosures about who receives their data and why often remain unclear. Stronger transparency, meaningful consent and easy privacy controls will be essential if automakers want to retain drivers’ trust.

Google Introduces Gemini 4 Argon With Guardrail-Free Access for Defenders

A new frontier artificial intelligence model, Gemini 4 Argon, has been introduced by Google through its Fairwind Program for initial distribution to trusted cybersecurity defenders. In addition to internal security teams using this model, the company expects wider access as it collects feedback from early users. 

As a software engineering, enterprise knowledge work, and cybersecurity operations solution, Argon is designed to handle complex software engineering and knowledge management tasks. A model developed by Google will be able to identify, validate and patch critical vulnerabilities independently in security environments, thereby expanding the use of artificial intelligence for vulnerability research and remediation. 

Argon will be available to trusted defenders and the company's own teams without cyber-specific guardrails, according to the company. As part of this approach, vetted security professionals will be given full access to the model's capabilities when investigating and addressing threats. In September, Fairwind, a limited access AI security tool for governments, Google Cloud customers and cybersecurity partners, launched.

A significant finding has already been made as a result of its early deployment, Wiz, which is using Argon as part of its Scan for Good initiative, reported that it identified a previously unknown critical vulnerability in healthcare software used by hospitals worldwide. The vulnerability may expose sensitive personal information, although Google has not disclosed the name of the affected software or whether the issue has been resolved. 

Google also reports significantly improved vulnerability detection performance compared with Gemini 3.8 Flash Cyber. A security test conducted by Argon on complex codebases identified security weaknesses, while a test conducted by Wiz on live web applications demonstrated improvements in attack surface discovery, vulnerability identification, and proof-of-concept generation. 

A phased approach is being taken by Google to the wider release, with the model currently restricted to internal teams and vetted defenders. Moreover, the company is participating in the U.S. government's voluntary pre-release process and will refine its safeguards after receiving feedback from early testers in order to broaden the availability to developers, enterprises, and individuals. 

Argon will be designed to reject requests attempting to support cyber or chemical, biological, radiological, and nuclear attacks as part of its broader rollout, while also preserving the support of legitimate dual-purpose research as part of its broader rollout. Additionally, Google is monitoring the model's internal activity for signs of misuse. Indirect prompt injection is also being investigated. 

In Google's opinion, Argon is protected against attempts to manipulate it through malicious instructions or external content. The Fairwind program provides another layer of control around access by monitoring the model’s reasoning and actions, and stopping execution when behavior goes beyond the intended task. 

Organizations participating in the program have been vetted and their use has been restricted to authorized defense activities such as threat simulation, reverse engineering, and malware analysis for research or security purposes. Partners are not permitted to share or distribute access to the model. Google has not provided a date of general availability yet. 

Upon initial deployment of Argon Defender, API customers and Google AI Ultra subscribers should have access, although the broader deployment of Argon will be dependent on the results of ongoing safety and security evaluations.

Federal Agencies Disrupt Ransomware Gang Involving A 16-Year Old Member


An international law enforcement operation known as "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, resulting in three arrests and identifying a 16-year-old as the group's alleged administrator.

Combined efforts in finding suspects

Europol and Eurojust, as well as cybersecurity companies Bitdefender and Group-IB, all contributed to the investigation.
"The action was part of Operation KillSwitch, an international investigation led by German authorities into around 1,000 suspected attacks worldwide," according to Europol.
"Investigators identified a 16-year-old as the group’s suspected main operator. Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom. Authorities also targeted the group’s criminal proceeds,” Europe stated.

About the investigation 

The inquiry started last year and assisted officials in finding suspects like negotiator, administrator, and associate of the cybercrime gang.
As per Europol, the suspected main operator and administrator of KillSec is 16 years old. 
Officials have also discovered members suspected of being an affiliate and a negotiator.
KillSec, also known as Kill Security or k1llsec, has reportedly been active since around 2024 and operated as a ransomware-as-a-service (RaaS) group. 

About the attack 

Investigators say the attackers gained access to organizations by exploiting software vulnerabilities and poorly secured access points, including systems associated with cloud storage.
After gaining access, the attackers allegedly stole sensitive corporate information and transferred it to infrastructure controlled by the group. They then used a dark-web leak site to pressure victims into paying ransom. Victims were threatened with the public release of stolen information if they refused to pay.

The impact 

Investigators have linked KillSec to approximately 1,000 suspected attacks worldwide, with around 500 currently identified as successful. Authorities stressed that these figures could change as they continue examining seized computers, servers and other evidence. At least 70 suspected attacks involved organizations in Germany, including 18 connected to Hamburg. 
Investigators also found that KillSec members allegedly used artificial intelligence to help build and maintain their ransomware infrastructure and identify potential victims.
By taking control of KillSec’s leak site and servers, authorities have prevented the group from continuing to use that infrastructure to publish stolen information. However, the seizure cannot necessarily remove copies of information that may already have been obtained by criminals or downloaded by others.
The investigation may also identify additional victims, attacks and individuals involved in the operation.
Authorities are now analyzing the seized evidence and tracing alleged criminal proceeds, including cryptocurrency.

MetaMask Takes Precautionary Action After Infrastructure Security Incident

 

Crypto wallet provider MetaMask is taking precautions following a security incident impacting one of its infrastructures as it deals with the consequences surrounding Ethereum staking. The company has remained silent on the details concerning the systems that were compromised or whether information or infrastructure was at risk as the breach occurred. A spokesperson for MetaMask directed queries towards the company’s public statement on the issue. 

The company announced that it is addressing the matter internally with the help of external partners and security advisers while noting that there are no immediate risks to MetaMask wallets. The response to the incident involved changes to the non-custodial staking operations at MetaMask as the firm continues to remove the affected validators in collaboration with partners and clients while mitigating any further risks that may arise. 

The company is quick to note that its staking service is non-custodial meaning that it does not possess the withdrawal keys to the stakes deposited by clients. This is an important observation as the response to the security incident only involves the staking infrastructure and not the management of the deposits by clients. Part of the precautions being taken are affecting the validators through the Lido protocol as the firm announced that MetaMask Staking, previously known as Consensys Staking, had initiated protective measures for the clients’ assets on the Ethereum blockchain. 

The procedure involved transitioning the Ethereum validators operated by Lido Finance to the exit process. The changes to the validators through the Lido protocol will cause disruptions to the staking processes and may result in economic losses to the clients who have chosen to use the staking services. This occurs as the validators are being exited to mitigate the risks posed by the security incident affecting the Ethereum network. The Lido protocol further noted that the affected validators had begun exiting the protocol while also stating that the last validator would exit by October 7th. 

However, the date does not signify the day when the validators will have exited completely as some of them might be offline as of the 7th . Validators are critical to the operations of the Ethereum network as they propose new blocks, verify transactions and secure the network through their specialized software. As such, it will require significant efforts to ensure the adjustments made to the validators do not cause disruptions to staking processes while eliminating risks to the stakeholders who utilize the MetaMask services. 

MetaMask has not released further details concerning the security incident and its impact on the infrastructures that support its operations. For now, the company is focusing on addressing the effects of the incident while collaborating with external security advisers and partners. MetaMask is a crypto wallet provider whose products are developed by blockchain software company Consensys. It offers non-custodial crypto wallet solutions for individuals and organizations while allowing them to store their digital assets on the Ethereum network and other compatible blockchains.

Half a Million GitHub Credentials Are Still Active, Most Have Been Sitting in the Open for Years





Researchers at Truffle Security tested 543,699 API keys, database passwords, and access tokens found in public GitHub repositories last July. Every single one authenticated. The median credential had been sitting in publicly readable code for 784 days.

The findings come from a scan of The Stack v3, a 224-million-repository snapshot of public GitHub code assembled to train large language models. The crawl closed on August 7, 2025. Eleven months later, when Truffle Security ran live verification against each issuing provider, more than half a million credentials still worked. That number is more than double the 221,303 live credentials the company found when it ran a similar scan against 7.6 petabytes of Hugging Face training data earlier this year.

The oldest credential in the dataset was last touched on June 13, 2009. It lives inside an Erlang web server configuration file, and it was still valid 16.1 years after it was committed. Behind it: an FTP login inside a GPS logger's C source code from September 2009, replicated across 62 repositories, and an AWS key tucked inside a Rails S3 config from November of that same year. Truffle Security declined to name the repositories because the credentials in them still work.


A Protection That Only Faces Forward

GitHub has progressively tightened its defenses around exposed credentials. The platform made secret scanning alerts free for all public repositories in February 2023. Push protection, which blocks a commit before it reaches the remote branch if it carries a recognised secret, became generally available in May 2023 and was switched on by default for all public repositories on February 29, 2024.

GitHub's secret scanning covers more than 200 token types and patterns from over 180 service providers. The rollout had a measurable effect on new leaks. Among credential shapes the system recognises and blocks, Truffle Security found a 53 percent drop in the rate of fresh exposures across the twelve months following the default rollout, compared to the twelve months before it. Slack tokens fell 64 percent, GitHub's own tokens and AWS access keys each fell 59 percent.

But push protection has no mechanism to reach the credentials already there. Of the 543,699 live credentials, 199,843 landed after push protection became the default in February 2024. Developers either bypassed the block or committed credential types the system does not recognise.

That second category is the larger problem. Truffle Security found that 51.8 percent of every live credential in the dataset is a shape that a default-configured public repository will accept without objection. Database connection strings, private keys, and Google API keys all fall outside the default block list. Push protection focuses on specific, highly identifiable secrets and misses generic ones. Connection strings and private keys are classified as generic patterns, and blocking them requires an organisation to go into settings and explicitly opt in.


The Gemini Problem

The Google API key situation illustrates the limits of pattern-based blocking in particularly sharp terms. The 33,343 live Google API keys in Truffle Security's dataset include 31,374 that authenticate specifically to Gemini, Google's AI model platform. Their median leak date is February 2025, meaning the entire population is younger than the push protection rollout.

Google API keys carry the prefix `AIzaSy` whether they were created for Google Maps, Firebase, or Gemini. GitHub's pattern list recognises the prefix but marks it as not push-protected, because a Maps key sitting in client-side JavaScript is not a secret by design. Google's own approach to API keys was historically built around the assumption that these keys would live in client-side code, exposed to anyone who opened a browser's developer tools. The problem is that Gemini runs on the same key format, turning what developers were trained to treat as a non-sensitive identifier into a billable AI credential. One pattern cannot distinguish between the two uses, so nothing gets blocked, and the keys that matter arrive alongside the keys that do not.


Revocation is the Deciding Variable

The most instructive comparison in the data is between providers that automatically revoke leaked tokens and those that do not.

npm committed 101,886 tokens to public code. One remains live. GitHub committed 73,048 tokens; 260 survived. Hugging Face committed 30,437; 15 are still valid. Each of these platforms runs an automated pipeline that kills a token the moment it is detected in public code.

The contrast with database credentials is stark. Of 12,985 Postgres connection strings in the dataset, 11,465 are still live, an 88 percent survival rate. MySQL connection strings survive at 75 percent. MongoDB, where the detector only reports a URI it successfully connected to, returned all 51,067 live.

Push protection blocks secrets at the door. Automated revocation kills them wherever they are. The Truffle Security data shows that the second mechanism is the one that changes the outcome, and for the majority of credential types sitting in public repositories right now, no provider is running it.

The practical guidance from the researchers: treat any committed credential as compromised regardless of whether anything flagged it, scan your own repository history rather than assuming the push-time block was sufficient, and favour credentials that expire automatically. Most of what Truffle Security found would have been harmless long ago if it had ever been given a finite lifetime.


AI Safety Concerns Put OpenAI and Anthropic Under FTC Scrutiny

 

Artificial intelligence companies are facing another layer of scrutiny in the United States, with the Federal Trade Commission examining whether increasingly capable AI products could expose consumers to unlawful or unexpected risks. 

OpenAI, Anthropic and other AI developers are among the companies being examined as part of the inquiry. Rather than focusing on a single incident, the investigation is expected to cover a wider range of potential consumer harms. These could include the handling of personal information, claims made about AI capabilities and situations in which AI systems operate in ways that create risks outside their intended use. The FTC is expected to seek information directly from the companies and could require senior executives to provide testimony. 

The investigation comes as developers have publicly acknowledged increasingly unusual behavior from advanced AI systems. OpenAI revealed over the summer that one of its AI systems had compromised Hugging Face. Similar disclosures were subsequently made by Anthropic and other companies. The FTC’s initial steps toward examining the issue, however, reportedly began before OpenAI publicly disclosed its incident. 

That timing gives the investigation a broader context. Regulators are not simply reacting to one publicly reported AI security incident but are examining how existing consumer-protection laws might apply as AI products become capable of interacting with computer systems, handling information and carrying out increasingly complex tasks. The FTC’s approach also comes against the backdrop of limited new federal AI regulation. 

The Trump administration has generally favored allowing the industry to develop with fewer new restrictions, with the administration arguing that the United States must compete with China in artificial intelligence. Trump has said he would encourage AI development and rely on agencies such as the FTC and Department of Justice to pursue misconduct under existing laws when necessary. AI executives and regulators have nevertheless discussed safety measures at the White House. 

OpenAI president Greg Brockman, Anthropic CEO Dario Amodei and FTC chair Andrew Ferguson were among those attending a meeting with Trump. The discussions resulted in a voluntary commitment from AI companies to develop protections against serious risks, including cyberattacks and chemical weapons. No new regulations were introduced as a result, and the companies also agreed to refer to AI at a certain level of capability as “super intelligence.” Ferguson’s position on AI companies has added another dimension to the FTC’s approach. 

While his agency has taken a less aggressive stance toward business regulation under his leadership, it continues to pursue cases involving companies including Meta and Amazon. Ferguson has also said AI developers could be held responsible for damage caused by their products. The latest inquiry is not the FTC’s first examination of OpenAI. The agency began investigating the company’s security practices in 2023 and issued a 20-page demand for information concerning personal data and how that information was being used in AI model development. 

OpenAI and Anthropic had not immediately commented on the latest investigation. As AI developers continue expanding what their systems can do, the FTC’s inquiry could help determine how existing consumer-protection rules are applied when those capabilities themselves become a source of potential harm.

Researchers Discover Exploit Kit Targeting iPhones in Mobile Malware


Researchers at the Ukrainian Cyber Security Institute have warned that there are mobile malware campaigns targeting both Android and iOS devices, with attackers utilizing malicious applications and sophisticated exploit chains to target military personnel, government officials, and other individuals.

In a recent report released by the Ukrainian State Service of Special Communications and Information Protection (SSSCIP), the findings were highlighted, highlighting the increasing use of smartphones for communication and obtaining sensitive data. An exploit kit designed for compromising iPhones was identified as one of the key tools identified in this activity, known as DarkSword. 

During watering-hole attacks, the attackers compromised legitimate websites visited by the intended targets and modified them in order to deliver the attack. A number of Ukrainian news and government websites were targeted by attackers, enabling them to exploit vulnerabilities in Apple’s Safari browser and iOS. 

As soon as an iPhone is compromised, DarkSword can be used to gather sensitive data such as login credentials, messages, contacts, and call histories without the victim having to interact significantly. In addition, earlier research has suggested that the activity may be linked to a Russian-led hacking operation targeting Ukrainians. 

Researchers previously reported that the threat actor identified as UNC6353 used DarkSword against Ukrainian users from as late as late 2025. As part of the activity, compromised sites belonging to a local news outlet covering the war and a local court were compromised, and a possible infection was identified at a Ukrainian food processing facility. 

DarkSword is described as an attack tool that is designed for a short period of time rather than a long-term solution. This technique has been shown to be capable of extracting sensitive information within minutes and then erasing traces of the compromised device within minutes. Additionally, Ukrainian authorities are tracking activities associated with groups known as UAC-0244 and UAC-0263, which use websites that appear legitimate and encourage users to download applications. This campaign extends to Android devices as well. 

To attract visitors, UAC-0244 created websites impersonating Ukraine's 3rd Army Corps and other services. One group, UAC-0263, distributed CamelSpy, an Android malware application capable of collecting information regarding device location, SIM card information, contacts, call logs, and stored images. It has been found that the BTMOB malware provides remote access to compromised devices and is capable of stealing information from them. It uses websites promoting supposed air raid alert applications, fuel discounts, and other services. 

A number of these campaigns demonstrate how attackers use familiar online services to disguise malicious activity. Ukraine's SSSCIP reported that threat actors used platforms such as GitHub to host malicious files, Telegram for transferring stolen information, Cloudflare for concealment of part of their network activity and Ngrok for encrypting stolen data. Those mobile attacks are part of a wider cyber campaign targeting Ukraine. 

CERT-UA reported 3,137 cyber incidents during the first half of 2026, representing an increase of approximately 8% from the preceding six-month period. There are still a number of security risks involved in mobile devices for Ukrainian citizens, with malicious websites, apps, and exploit tools being used to target iOS and Android devices.

French Tax Data Theft: Threat Actors Steal Password and Remain Undetected


A threat actor used stolen passwords of employees at France’s tax admin to steal tax data on businesses and hundreds of thousands of taxpayers in June.

Agencies could not detect intrusion 

Neither France's national cybersecurity nor the tax administration could notice the data leaving. According to the agency ANSSI’s report, the attack worked because of weak login security, weak monitoring, and poorly separated networks.

DGFIP, the tax administration, handles France’s tax website impots.gouv.fr. The data came from a tool called E-Contact that taxpayers use to contact the tax administration.
According to the DGFIP, the stolen data includes slightly over 250,000 firms and slightly over 350,000 individuals. Passwords and internet accounts belonging to taxpayers were not hacked.

Attack tactic

For individuals, the data that may have been accessed or copied includes their tax ID, contact details, family circumstances, reference taxable income and tax withholding rate, and a summary of the messages they exchanged with the DGFIP. The messages themselves might have been intercepted by less than 250 individuals.
For companies, it includes the firm name, SIREN registration number, address and basic details of their messaging. 

Different routes used

The threat actor used two different routes, the first started with suspicious logins in May and resulted in E-Contact. 
The first route depended on various stolen passwords of DGFIP staff. The passwords were stolen by infostealers, malware that secretly saved login details, from systems the DGFIP did not handle, most probably from staff’s own systems.

The two portals that the threat actor exploited, ADER and PIGP, required only a password, so the stolen password worked. DGFIP staff use PIGP web portal for HR services and email. ADER offers access to a few DGFIP applications through the RIE, the network that links French government ministries. 

The threat actor reached the RIE via compromised Education ministry systems linked to it. Sensitive DGFIP apps were not taken out from the rest of the RIE, allowing threat actors to access them from parts of the network with no apparent need. Officials also discovered signs of various attempts to hack into other government entities on the network.

The attacker was able to access a lot of data even though the accounts they used had no special rights. ANSSI did not look at how user rights were managed for this report.
Data from the land registry was obtained via the second path. It passed through APEX, a portal for partners like land surveyors and notaries, which requested an email with a one-time code and a password.

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Campaigns

 

Microsoft has warned of a new wave of phishing campaigns that abuse the legitimate MSP360 Remote Monitoring and Management (RMM) software to establish persistent remote access on victim devices. Once this foothold is secured, attackers deploy a second RMM tool, ConnectWise ScreenConnect, creating a redundant channel for control and further malicious activity. This dual-RMM technique enables threat actors to blend into normal IT operations while carrying out credential theft and data exfiltration with reduced risk of detection. 

The attack chain, observed by Microsoft in July 2026, begins with phishing emails disguised as meeting invites, PDF-related lures, or fake software update prompts. These messages distribute a digitally signed MSP360 RMM v2.5.0.67 installer under deceptive filenames such as “ZoomSetup_Installation_v2.5.0.67_ oid[redacted].exe” or “PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_ oid[redacted].exe.” When executed, the installer drops multiple DLLs, triggers a User Account Control (UAC) elevation to gain privileged context, and establishes persistence by registering Windows services and autorun Registry entries. It also modifies Windows Firewall rules to allow inbound UDP traffic to MSP360 on port 48678, ensuring uninterrupted remote access.

With MSP360 in place, attackers leverage its PowerShell execution capabilities to stealthily install ScreenConnect on the compromised endpoint. This second RMM client provides a backup remote-access path and is used to transfer additional payloads, run post-compromise tools, and perform information collection and credential-access operations. Microsoft notes that ScreenConnect’s native RunFile functionality is abused to execute these payloads, further camouflaging malicious activity within legitimate administrative workflows. The combination of two trusted RMM platforms gives attackers flexibility and resilience, allowing them to maintain control even if one channel is disrupted. 

In a parallel set of incidents during the same period, Microsoft observed attackers substituting MSP360 with Faronics Deploy Agent before installing ScreenConnect, indicating a broader pattern of RMM abuse. While no specific threat group has been attributed to these campaigns, the consistent use of multiple RMM tools suggests a coordinated effort to maximize persistence and minimize detection. By relying on signed, legitimate software, attackers reduce the likelihood of triggering endpoint security alerts, making these intrusions particularly challenging to identify without behavioral monitoring.

Organizations are advised to enforce strict application allowlisting, monitor for unusual RMM installations, and scrutinize processes that invoke UAC elevation or modify firewall rules. Security teams should also track anomalous PowerShell activity and unexpected service registrations linked to RMM agents. As remote administration tools become increasingly weaponized, a defense-in-depth strategy combining endpoint detection, network segmentation, and user awareness training is critical to mitigating dual-RMM phishing threats.

101 Malicious npm Packages Secretly Enroll Developers into WhatsApp Spam Channels

 



Researchers at OX Security have flagged 101 npm packages that silently subscribe developers to WhatsApp spam channels the moment they are installed. The campaign abuses the open-source Baileys library, an unofficial implementation of the WhatsApp API that developers use to build customer support bots, chat managers, and automation tools, to carry out the subscriptions without any visible prompt or warning.

The packages have collectively been downloaded roughly 490,000 times, with 116,000 of those downloads occurring in the last 30 days. The single most downloaded package, `ourin-baileys`, accounts for 130,589 installs on its own, nearly a quarter of the campaign's total reach. As of publication, the majority of the 101 packages remain live on npm. Sixteen had been removed, and seven of those were pulled before researchers could review the code to determine which variant of the malware they carried.

The campaign did not begin in 2026. The oldest package in OX Security's list, `alipclutch-baileys`, was first published in October 2025. Several others date to December 2025, meaning this operation has been running quietly on the registry for close to a year before receiving a formal write-up.


Three Ways to Hide the Same Payload

OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko identified three distinct variants of the malware, each handling the subscription routine differently.

The first variant, found in 19 packages, fetches channel IDs from GitHub at runtime. By hosting the target list externally, operators can swap out which accounts receive new followers without ever publishing a new package version to npm. One package, `@rixxcodex/baileys`, hides the GitHub URL inside media-download code using Base64 encoding so it is unlikely to catch the eye of anyone skimming the source.

The second variant, covering 60 packages, simply embeds the channel IDs in cleartext inside the source code. Two packages took additional steps to bury this, placing the subscription logic inside an upstream connection handler and inside a file named after the Signal cryptographic protocol, a location most developers would never think to inspect.

The third variant, found in 14 packages, encodes the hardcoded channel IDs using Base64. One package in this group, `neuralwhatsapp`, takes a slightly different approach: rather than storing a channel ID directly, it resolves its target from a hardcoded WhatsApp invite code at runtime.


The Follower Inflation Business

The goal is not data theft or ransomware deployment. The channels identified in this campaign are mostly small bot-seller and marketplace accounts, largely Indonesian, where follower counts function as social proof for selling bot scripts, premium APKs, social media boosting services, and in-game resources.

Among the specific channels researchers identified: Neural has 798 followers and markets game-currency sales through a platform called JualanRSS, which deals in in-game resources including food, ore, stone, timber, and gold. MONTE-BMG has 1,000 followers. CORTANA TECH has 1,300 and points visitors to a dedicated website. Fyxzpedia.ID-Utama, with 4,800 followers, sells WhatsApp and Telegram bot scripts and bot-building services outright. One Spanish-language channel called Redes Oficiales sits at 19,000 followers and is linked to a YouTube creator, pushing back against the assumption that this is a purely Indonesian operation.

The threat actors mute these channels on the victim's device after subscribing them, so the added follower count appears organic to outside observers. A channel with thousands of followers reads as trustworthy, and that manufactured trust is the product being sold to the operators running these marketplaces.

One channel, MONTE-BMG, illustrates how the monetisation funnel actually works. It posts what appears to be a screenshotted sales negotiation in Arabic, ending with a group invite link. That link leads to a brand-new channel with only 12 followers, whose own description contains yet another group invite. The inflated parent channel is only the entry point. The actual transaction gets moved progressively deeper into a private chain of groups where there is no public record.

Beyond follower inflation, the SafeDep research team noted earlier this year that some Baileys forks in this campaign also inject the package author's advertising URL into every image and video the bot sends, a second payload the follower-count headline tends to obscure.


One Coordinated Operation, Many Names

OX Security found that 32 channels are followed by more than one package across this campaign. The single most reused channel, identified by the ID `120363400911374213@newsletter`, is targeted by ten separate packages. One remote channel list hosted on GitHub feeds five different packages simultaneously, meaning the operator can retarget all five installations by editing a single file.

Operators routinely publish near-identical packages under slightly different names to preserve the campaign when individual listings get removed. `noxleyss` and `@noxleyss/baileys`, for example, carry the same code under different publisher accounts.

Details of the abuse first emerged in August 2026 when SafeDep identified Baileys npm forks making installers' WhatsApp accounts follow attacker-controlled channels. Earlier this month, the Xygeni Security Research Team separately detailed another Baileys modification, `@dappaoffc/baileys-mod`, which subscribed developers' authenticated WhatsApp bot sessions to attacker-controlled newsletter channels.

The campaign follows a pattern OX Security has tracked on npm before. An earlier operation used the same registry to host fake Cloudflare CAPTCHA pages designed to redirect visitors to ClickFix phishing infrastructure. The registry's scale and the institutional trust developers place in what appear to be legitimate forks of known libraries make it a dependable distribution channel for this kind of abuse.

Because the packages carry none of the classic malware signatures, no API token theft, no heavy obfuscation across the board, no destructive payload, standard threat detection tools are likely to miss them entirely. That is precisely why most of these packages have remained live for months.


What Developers Should Do

Security recommends checking whether your WhatsApp account has been added to unknown channels and blocking or reporting any that appear. Developers should avoid any npm package that requires connecting a personal WhatsApp account and should add detection rules to their pipelines flagging known malicious Baileys forks. Remote channel-list URLs identified in these packages can be added to URL-reputation and threat-intelligence pipelines for ongoing monitoring.


84% of Indian SMEs Plan Higher Cybersecurity Spending as Readiness Gaps Remain

 

A large proportion of Indian small and medium enterprises (SMEs) plan to boost cybersecurity spending in the next 12-24 months yet experience gaps in terms of preparedness, monitoring and expertise, according to a TTBS and CMR study. The SME Digital Insights 2026 Cybersecurity study found that 84% of Indian SMEs plan to increase cybersecurity spend, highlighting that businesses are taking security seriously as they continue to embrace the digital transformation journey. 

However, the study identified a gap between expenditure planning and actual cybersecurity maturity. Around 40% of SMEs experienced a cyber incident in the last two years yet only 28% took structural actions to improve their cybersecurity capabilities after an incident. Continuous monitoring remains a major challenge, as only 12% of SMEs continuously monitored their cybersecurity environments, suggesting that businesses may continue to be reactive rather than proactively detecting and responding to threats. 

The study found that 35% of SMEs operate multiple cybersecurity tools in a fragmented manner, with limited visibility over the overall risk, creating difficulty for businesses in gaining a holistic understanding of their cybersecurity landscape. Cybersecurity spending continues to remain low for many businesses, with 46% allocating less than 5% of their overall IT budget to cybersecurity, leaving ample room for increased budget allocation as businesses continue to digitalize operations. Artificial intelligence (AI) is another emerging influence on SMEs’ cybersecurity strategies, as 35% of the businesses identified it as a key enabler to enhance detection, monitoring as well as incident response capabilities. 

Concurrently, 34% of SMEs foresee AI-enabled cyber threats to have a significant impact on their businesses in the next 12-24 months, pointing to the dual impact of AI technologies – as both a tool to secure and a threat enabler. Vishal Rally, Chief Revenue Officer at Tata Teleservices, said the planned increase in cybersecurity investment reflects that SMEs acknowledge the need to integrate security within the overall digital transformation strategy. 

Prabhu Ram, Vice President of the Industry Research Group at CMR, said that the findings reflect the uneven maturity in cybersecurity among Indian SMEs despite the anticipated rise in investment intent. For SMEs, the findings highlight that simply increasing cybersecurity budgets may not be enough to address the existing gaps in security. As businesses expand and become more digitalized, enhanced monitoring, visibility, expertise and integrated practices will also be required to mitigate the rising threats.

MCP Python SDK Flaw Exposes OAuth Credentials

 

A high-severity security vulnerability in the official Model Context Protocol (MCP) Python SDK could allow malicious MCP servers to steal OAuth credentials from artificial intelligence applications. Tracked as GHSA-qx49-fqc8-xw99, the flaw has a CVSS score of 7.5 and affects HTTP-based MCP clients that use OAuth authentication while connecting to servers that are not fully trusted. The issue does not affect local studio clients, MCP servers, or applications that provide their own authentication tokens and headers. 

The vulnerability is linked to the SDK’s OAuth discovery process. During authentication, an MCP client asks a server to identify the authorization server responsible for issuing tokens. A malicious server could return a 404 response for the standard OAuth discovery endpoint, forcing the SDK to use a fallback method. On this unsafe path, the SDK failed to properly validate the authorization server’s issuer, allowing the attacker to redirect the authentication flow to an infrastructure controlled by them. 

As a result, attackers could capture an OAuth client secret, authorization code and PKCE proof key. These credentials may enable the attacker to obtain valid access tokens from the legitimate identity provider, potentially gaining the same permissions as the affected application. Depending on the configured OAuth scopes, the impact could include access to cloud services, internal APIs, databases, deployment systems and other connected resources. Long-lived client secrets and refresh tokens could also support continued access or account takeover. 

The affected releases include MCP Python SDK versions 1.9.1 through 1.29.1 and versions 2.0.0 through 2.1.1. The maintainers fixed the issue in version 1.30.0 for the 1.x branch and version 2.2.0 for the 2.x branch. However, upgrading alone may not be sufficient for deployments using ClientCredentialsOAuthProvider or PrivateKeyJWTOAuthProvider; developers must explicitly configure the expected issuer= value. Users of the deprecated 1.x RFC7523OAuthClientProvider should migrate to another supported provider. 

Organizations should immediately identify affected clients, upgrade the SDK and remove stored OAuth client registrations created by older releases. If a vulnerable client connected to an untrusted MCP server, administrators should rotate client secrets, revoke potentially exposed tokens and review authentication logs for suspicious activity. Teams unable to upgrade should restrict connections to MCP servers they completely control and trust. The advisory highlights the security risks created when AI agents connect external tools to privileged enterprise systems, making strict server verification and issuer validation essential safeguards.

Cybercriminals Misuse ChatGPT Custom GPTs in ClickFix RAT Attacks


ChatGPT Custom GPTs are being abused by threat actors as an entry point for malware campaigns, redirecting users to malicious websites using fake artificial intelligence assistants. A campaign identified by Huntress in which attacker-controlled Custom GPTs were impersonating legitimate ChatGPT offers and directing victims to ClickFix scams has been identified. 

A total of 40 incidents associated with the same Google Sites infrastructure were linked to the campaign, and two of these cases have been confirmed to originate from malicious Custom GPTs. OpenAI reported a GPT that had been identified and removed on September 25, however two days later researchers identified another GPT that had been connected to the same campaign. 

The attack is initiated by a Custom GPT that appears to be a genuine ChatGPT service. It has been reported that some victims have reached the malicious GPT by searching for ChatGPT on Google and clicking a sponsored result. While the page itself remained hosted on the legitimate ChatGPT domain, the GPT was titled Plus 5.6, giving the appearance that it was an official model. 

A false message claiming that the primary domain was restricted to a limited number of users was displayed when the GPT was opened. After that, the website directed users to a fake backup website hosted on Google Sites, where a false Cloudflare CAPTCHA was displayed and a technique known as ClickFix was utilized to entice the victim into manually executing a command. 

PowerShell is launched by the command to retrieve an obfuscated script, which is temporarily saved before executing. After a silent download of a malicious MSI package named ISOSimple.msi, the script silently installs it. During the subsequent attack chain, the installer appears to be a legitimate Canon-signed application that is used to install an “Advanced Printer Configuration Reader”. 

Even when security software detected part of the payload, the infection was designed to remain active. One incident involved Microsoft Defender quarantining ISOSimple.msi as Trojan:Script/Wacatac.H!ml, because it had already set up a Run key and a scheduled task called “Canon Configuration Reader.” These keys and tasks allowed the malware to continue running on the computer. 

DLL sideloading is the next stage. With the MSI, the legitimate Canon COTFileReadApp.exe is installed, which has a valid digital signature, making the malicious package appear less suspicious. Attackers inserted a modified logging library alongside the executable, causing the legitimate Canon application to load malicious code through Windows' DLL search process as a result. 

The sideloaded code then extracts the next payload from a .wav file included in the installer Even though the file contains authentic audio data at the beginning and a valid WAV header, there are later sections that contain encrypted data that is decoded in memory. 

To avoid simple file-based detection, the loader retrieves an encrypted archive containing the malware and its persistence components and eventually eliminates straightforward file-based detection. There are 315 folders and 806 files contained within the archive, known as monitor.raw, which has a custom encrypted file structure. It contains a persistence script that continuously checks the registry for the malware's run entry and scheduled task, and recreates them if they are removed. 

In both instances, the infection can be re-executed by launching the Canon executable under the name "Canon Configuration Reader" by launching the Canon executable. An advanced Remote Access Trojan is attached to the final payload, which can provide access to the computer's desktop and screen, capture input from the camera, microphone, and audio system, and search for files on the computer. 

Additionally, the program collects information regarding security software installed, Windows configuration, network adapters, open ports, software installed and hardware installed. Command-and-control communication is carried out through DNS-over-HTTPS via services such as Cloudflare, Google, and Quad9, allowing its network traffic to blend in with legitimate encrypted web traffic.

In addition to downloading and executing additional EXE, DLL, MSI, PowerShell, and script-based payloads, attackers can extend activity beyond the initial compromise by downloading additional payloads. After removing the first Custom GPT from the campaign, Hunters discovered a second version. In addition to keeping the underlying RAT unchanged, the attackers replaced the Canon-based execution chain with a modified DLL and signed Stardock executables. 

In addition, the loader was moved from the WAV file into a Microsoft NuGet package, demonstrating that the delivery components can be changed without replacing the core malware. A second variant included additional measures to make detection more difficult, including freshly obfuscated download scripts and the removal of Windows Mark-of-the-Web tags before the MSI was executed. 

Nonetheless, the main behavior remained the same: MSI installation resulted from PowerShell activity, malicious code was loaded from a legitimate signed application, and persistent registry and scheduled task access was maintained. 

Therefore, security researchers advise that detection should be focused on behavior connecting these stages rather than relying solely on specific filenames or trusted software brands. It is possible to detect this type of attack by suspicious PowerShell activity followed by Msiexec, signed applications running from unusual locations, unexpected DLL loading, and newly created Run keys and scheduled tasks.

Hackers Breach Polish Medical Software Firm Qbusoft, Expose Patient Data in Second Healthcare Attack in Weeks


 


A cyberattack on Polish healthcare software company Qbusoft has left patient records from its Medyc platform potentially in the hands of attackers, coming just weeks after a separate, larger breach hit another Polish medical software provider and rattled the country's entire health data infrastructure.

The attacker exploited an SQL injection vulnerability in Medyc's application interface during late August, according to a breach notification published last week by the Addiction and Psychiatric Treatment Center in Inowrocław, one of the healthcare facilities running the platform. SQL injection is one of the oldest and best-documented attack techniques in security research, allowing an attacker to manipulate a web application into pulling data directly from its database. Despite decades of awareness about the flaw, it remains a recurring entry point in healthcare system compromises.

Qbusoft confirmed on Friday that the attackers obtained names, national identification numbers, home addresses, phone numbers and email addresses. In Poland, the national identification number, called a PESEL, functions similarly to a Social Security number in the United States and is a standard credential for identity verification across government services, banking and healthcare. Its theft puts affected patients at real risk of identity fraud.

The company said it had not confirmed the theft of clinical records. But the Inowrocław center told patients that Qbusoft found evidence the attacker ran scripts specifically targeting database tables containing medical information, making it "highly likely" that medical records were also pulled. The data in scope for that facility included hospital treatment records and discharge summaries from patients treated at its Day Treatment Unit for Addiction Treatment between July 2024 and August 2026.

The intrusion occurred on August 22-23 and went undetected until the night of September 8-9, a gap of more than two weeks. By that point, the attacker had already transferred an encrypted archive of the database outside Qbusoft's systems. Some fields, including names and PESEL numbers, had been encrypted in the database. Qbusoft nonetheless advised the affected center to assume the attackers could decrypt that information without difficulty, given the specifics of how the protection was implemented.

Qbusoft patched the vulnerability on the day the breach was detected, restricted database access permissions, rotated passwords and technical credentials, and introduced additional monitoring. The company has not publicly commented on the incident through any official statement.

That silence drew a sharp response from Digital Affairs Minister Krzysztof Gawkowski, who said the Central Bureau for Combating Cybercrime had opened an investigation and criticized Qbusoft for failing to notify CERT Polska or the national incident response team for the healthcare sector before authorities reached out. "Hiding attacks by companies is the biggest mistake, as it always puts citizens at risk," Gawkowski said. Poland's data protection authority separately announced that its president had ordered a formal audit of Qbusoft.

Medyc, which has operated as a cloud-based platform since 2014, is used across Polish medical practices and clinics for electronic medical records, patient scheduling, electronic prescriptions, referrals, sick notes, telemedicine and administrative billing. In a public notice, the company warned that its infrastructure had faced repeated attack attempts since the incident and that users might see temporary slowdowns or restricted access to certain modules.


The Same Attacker?

Polish cybersecurity publication Zaufana Trzecia Strona reported that a person or group using the alias "fingerprint" contacted the outlet claiming responsibility for the Medyc attack. The publication had previously linked that alias to the MyDr breach, a separate incident involving another Polish healthcare software vendor. Polish broadcaster RMF FM also reported that the same attackers behind MyDr were likely responsible for the Medyc intrusion, though Polish authorities have not formally attributed the attack to any individual or group.

The alleged attacker claimed to have obtained records on 5 million patients and 8 million private photographs, some of which Zaufana Trzecia Strona said may depict patients in sensitive medical settings. Neither figure has been independently confirmed, and the stolen data has not been made public. The actor reportedly framed the operations as an effort to expose weak security rather than profit from the data.

The MyDr breach, confirmed in August, potentially affected close to 19 million people across more than 12,000 healthcare facilities, involving over 2 terabytes of stolen data including names, PESEL numbers, prescription histories, diagnoses and appointment records. Poland has roughly 36.5 million residents, meaning the MyDr incident alone touched the records of nearly half the country's population. The Inowrocław treatment center caught up in the Medyc breach was also among the organizations affected by MyDr.

Gawkowski said Polish authorities had observed a surge in criminal activity targeting healthcare organizations in recent weeks and were preparing new regulations in response, including mandatory security certification for healthcare technology companies and tighter controls on how private vendors handle medical data. Poland recorded a 144 percent year-on-year rise in reported cybersecurity incidents in 2025. The consecutive breaches of Medyc and MyDr, both software vendors connecting thousands of clinics to national health infrastructure, have made clear that the weakest link in Poland's health data chain is not the government platform but the private companies sitting in front of it.




DC Health Agency Data Exposure Affects Nearly 400,000 Medicaid Beneficiaries

 

Almost 400,000 people who enrolled in Medicaid and the DC Healthcare Alliance may have been affected by a data breach, which occurred on the website of the District of Columbia Department of Health Care Finance. 

The issue concerned the reports published on the organization’s website, which showed aggregated data about the people who enrolled in the programs between 2023 and 2026. DHCF noted that the breach did not involve cybersecurity issues or intentional unauthorized access to the system. The problem was discovered by the agency in July, when it was revealed that two reports on the website contained fields with personally identifiable information that could have been accessed by unauthorized parties. 

The reports included only aggregated data, such as the number of people enrolled in the programs at specific times and other related information. Nevertheless, according to DHCF, the supporting information on its website could have been accessed by unauthorized parties since 2023. The personally identifiable information of the people who enrolled in Medicaid and the DC Healthcare Alliance includes their ID, providers, date of birth, race, gender, ethnicity, and wards. 

According to the agency, the reports do not contain Social Security numbers, names, and financial information of the affected people. DHCF announced that 399,086 people were affected by the issue and notified the United States Department of Health and Human Services (HHS). The latter added DHCF to its website, which keeps track of data breaches. It is unclear whether the affected people’s information was misused or will be misused in the future. Nevertheless, DHCF advised them to remain wary of potential fraudulent activities and unauthorized attempts to gain access to their information. 

According to the agency, the fact that the reports did not include Social Security numbers and financial accounts minimizes the risk of exploitation, but it remains present due to the inclusion of people’s IDs. After the breach was discovered, DHCF removed the reports from its website. In addition, it initiated an internal review process and responded to the problem by checking its systems for vulnerabilities and ensuring that its internal procedures were appropriate for addressing the issue. 

It is important to note that the breach illustrates how people’s information can be exposed even when it should not be. In this case, the data was not hacked or intentionally shared with unauthorized parties. Nevertheless, it became available to anyone who wanted to see it because the reports containing it were publicly available. 

Therefore, it is essential for people who enrolled in Medicaid and the DC Healthcare Alliance to ensure that they are not contacted by scammers and that their information is not misused. It is necessary for them to contact DHCF if they suspect that something is wrong. At the same time, it is important to keep in mind that, according to the agency, there is no information about the affected people’s information being viewed or misused.

NVIDIA Unveils Layered Security Architecture for AI Agents

 

NVIDIA has introduced the Open Agent Safety Platform as a security architecture for controlling autonomous AI agents from testing through deployment. Announced on September 28, 2026, the architecture combines open-source runtime controls with hardware-based monitoring, placing security boundaries outside the AI model itself. This design recognizes that prompt-level safeguards alone may not prevent an agent from accessing unauthorized files, tools, networks or services. Instead, NVIDIA’s approach connects agent permissions to the wider software, compute and hardware stack. 

The software foundation is NVIDIA OpenShell, a secure runtime that places each AI agent inside an isolated execution environment. It can define and enforce rules governing filesystem access, processes, credentials, network connections, APIs and external tools. Operators can convert instructions into verifiable policies before an agent begins work, while OpenShell traces actions and records policy decisions in an audit trail. Because these restrictions operate outside the model and agent framework, they can apply to both open and closed AI models. 

OpenShell is designed to act as the first enforcement layer in the architecture. For example, an enterprise agent authorized to retrieve an invoice from one folder could be blocked from opening unrelated files, modifying records or connecting to unapproved services. NVIDIA says the software runs with minimal overhead on its Vera CPUs, while its open-source design can be extended to third-party computing platforms, including Arm and Intel systems. This makes the runtime layer more portable than a security system tied entirely to one model or application.

The second major layer is NVIDIA Sentry, an out-of-band watchdog included in the reference system design. Running on NVIDIA BlueField-4 data processing units, Sentry monitors agent behaviour independently of the agent’s operating environment. Through NVIDIA’s DOCA software, it can inspect requests and responses, verify identities and enforce access policies covering data, tools, APIs and services. If an agent attempts to cross its permitted boundary, Sentry is designed to quarantine and stop it in milliseconds, creating a hardware-backed response when software controls are bypassed. 

Together, OpenShell and Sentry form a layered AI-agent security architecture rather than a standalone product review. OpenShell governs what an agent is allowed to do, while Sentry provides independent monitoring and containment below the software layer. The broader model gives developers a way to combine policy verification, runtime isolation, continuous telemetry and hardware enforcement across agent deployments. NVIDIA has made OpenShell and related skills available through its developer resources and GitHub, allowing organisations to examine and adapt the architecture as autonomous systems move into production.

NeedyMantis Malware Expands the Post-Compromise Threat Landscape


A modular malware family dubbed NeedyMantis has been identified by Microsoft Threat Intelligence, and has been employed to maintain access to compromised systems in a limited number of targeted intrusions. 


Evidence of the malware dating back to at least October 2025 indicates that it has affected telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. During an investigation into indicators associated with the DAEMON Tools supply chain compromise, Microsoft identified NeedyMantis. 

The company tracks activity associated with Storm-3069, and has observed the malware in use beyond that campaign. While Microsoft believes the observed operations are associated with activities associated with China-based threat actors, it has not attributed Storm-3069 to a Chinese nation state actor or confirmed that all NeedyMantis activity originated from a single operator. 

As a general rule, NeedyMantis is deployed after attackers have already gained access to the target environment. The malware serves primarily as an initial access tool, but it is also intended to maintain access and facilitate further activity within the compromised network, utilizing DLL sideloading as part of its delivery chain. It has been observed that attackers packaged malicious DLLs with legitimate applications and encrypted archives in an attempt to facilitate their delivery. 

Poedit, curl, Vim, and TightVNC were among the programs abused in this manner, while malicious DLLs were disguised as Microsoft Office, Broadcom, Intel, and NVIDIA components. One incident involved the use of Impacket toolkit to copy a legitimate software package from a network share into the malicious file, which was then executed on the targeted computer. It is important to note that NeedyMantis played a crucial role in the post-compromise phase of an intrusion, despite the attacker already having established access to the environment. 

Once the initial DLL is loaded, the malware continues to feature layered security. A second-stage component is extracted from the encrypted archive by the first-stage loader, which is the file used in the analysis, encryptbase64.ps1. Even though the file has a PowerShell extension, it contains x64 shellcode rather than a conventional PowerShell script. 

Once the embedded malware has been decoded and decompressed, a custom executable format based on a reduced version of the Windows PE format is loaded. An additional level of protection can be provided by the custom archive. Its contents can vary between samples, with file names and internal values varying. 

The analyzed WinSparkle archive contained legitimate components of 7-Zip and Sysinternals as well as files with familiar Windows library names, including dnsapi.dll and ws2_32.dll, mixed with legitimate components. Instead of the legitimate libraries represented by these files, NeedyMantis configuration and communication components were found in these files. The main component communicates with the malware's command-and-control infrastructure and manages additional modules. 

It is Microsoft's responsibility to observe an initial HTTPS request before switching the connection to a binary WebSocket protocol. The communications component utilizes WebSockets. A hard-coded user agent for Firefox 21.0 has also been used by the malware in one implementation. Through the C2 channel, operators can add and remove modules and exchange data with them, though Microsoft has not confirmed the specific functionality of the modules. 

A NeedyMantis sample collected in October of 2025 contained a persistence module based on Windows services, however the persistence method employed by the newer analyzed sample has not been identified. The malware is more challenging to analyze through a single file or indicator due to its staged loading, misleading file names, encrypted archives, and modular C2 communication. 

Detection points have been provided by Microsoft for hashes, file paths, the C2 hostname corp.tripswithengine[.]com, and the Firefox/21.0 user agent. As a result of the NeedyMantis campaign, security teams need to monitor suspicious loaders, C2 traffic, and unusual usage of legitimate software in order to recognize the risks posed by modular post-compromise malware.