Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

AI Watermarking Meant to Protect Against Misuse Could Actually Enable It

 



A security feature designed to make AI text traceable appears to have an unintended side effect: it can change how a language model behaves, in some cases making it more willing to follow instructions it was built to refuse.

That is the core finding from new research by Lasso Security, published on September 17 by researcher Andrea Siposova under the title "The Provenance Tax: Understanding the Impact of LLM Watermarking on AI Agent Behavior." The study tested Google DeepMind's SynthID-Text watermarking system across six open-weight language models and found that enabling watermarking changed how those models responded to harmful requests, particularly when attackers used prompt-injection techniques designed to override a model's instructions.


What SynthID-Text Actually Does

To understand why that matters, it helps to understand what SynthID-Text actually changes inside a model.

When a language model generates text, it does not write the way a human does. It builds sentences one token at a time, each step producing a probability distribution over thousands of possible next tokens and then sampling from that distribution. SynthID-Text does not attach a label to the finished output or hide characters in whitespace. It intervenes at the sampling step itself.

The system uses a process called tournament sampling, first described in a 2024 Nature paper by Google DeepMind researchers Sumanth Dathathri, Abigail See, and colleagues. Instead of the standard randomness used in token selection, the watermark substitutes pseudorandom values generated from a secret key and the context of tokens already produced. The result is a statistically detectable pattern woven through the text at the level of individual word choices, invisible to readers but recoverable by anyone holding the key. The technique is refined enough that it does not degrade text quality in any measurable way, which is a large part of what made it attractive as a compliance tool.


The Regulatory Push Behind It

Article 50 of the EU AI Act requires providers of generative AI systems to mark their text, image, audio, and video outputs in a way that is machine-readable and detectable as AI-generated. The Code of Practice the European Commission finalized on July 20, 2026, requires at least two marking layers for audio, images and video, plus watermarking of free-form text longer than 200 tokens. Google signed the Code on July 24, 2026, citing SynthID partnerships as its route to the interoperable detection requirement due on February 2, 2027.

Anthropic's technical implementation is built directly on SynthID-Text, the same tournament-sampling mechanism from the Nature paper, adapted for their own models and keys. It covers claude.ai, the API, Claude Code, Claude Cowork, Claude Tag, and access through AWS, Google Cloud, and Microsoft Foundry. With the industry's largest players now committed to the same watermarking standard, Siposova's findings arrive at an uncomfortable moment.


What the Research Found

Siposova ran paired experiments on six open-weight models using Hugging Face's unmodified SynthIDTextWatermarkLogitsProcessor, enabling and disabling watermarking while keeping the seed, batch composition, and ordering identical.

Watermarking changed refusal behavior on harmful requests, but the effect was more pronounced when the same requests were paired with prompt-injection techniques. Under those conditions, several watermarked models complied with harmful requests their unwatermarked versions had rejected, with the strongest differences appearing in prompt-injection scenarios.

Siposova told Ars Technica that behavior was clearly different compared with the same model without watermarking, and that the differences were especially pronounced under adversarial conditions or when running an agent calling tools. She put it plainly: "Watermarking is made to not be perceptible to a reader, but we know that when we are changing anything about what the model is generating, it is going to cause some tradeoffs, it's going to show up somewhere."

Lasso repeated its prompt-injection experiment using 11 different watermark keys and found that changing the key could change both the size and direction of the effect. That means two different deployments of the same watermarking system, on the same model, could produce different safety outcomes depending purely on which key was chosen.


The Agent Problem

The consequences extend beyond what a model says. When a language model powers an AI agent, token selection can determine which tool an agent invokes and which arguments it passes. "Such a watermarking procedure can therefore affect both what the model says and what an agent does," the study stated. Watermarking reduced accuracy on six of seven models, with a substantial decrease on four.

Lasso's conclusions are deliberately careful. The study did not verify how Claude model responses change when watermarking is applied, and critics noted the experiment only validated the SynthID-Text tournament sampling implemented by Hugging Face, which differs from how the Claude model would actually implement it. Siposova stressed that the findings describe patterns in the tested sample, not universal rules about watermarking as a category.

Lasso recommended repeating agent evaluations and red-team testing when watermarking or its configuration changes, particularly under adversarial inputs.

The research surfaces a tension that will only sharpen as regulatory deadlines close in. Watermarking was designed to answer the question of where AI text comes from. What it can also do, under the right adversarial conditions, is change what the AI decides to do next.


Former Engineer Jailed for Ransomware-Style Cyberattack

 

A former employee of a New Jersey-based industrial company has been sentenced to 32 months in federal prison for launching a computer network attack and attempting to extort his former employer. Daniel Rhyne, 59, of Kansas City, Missouri, was sentenced by U.S. District Judge Michael A. Shipp on September 28, 2026, at federal court in Trenton, New Jersey. The sentence followed his guilty plea to charges involving extortion through a threat to damage a protected computer and intentional damage to a protected computer. 

According to court documents and statements made during the proceedings, Rhyne previously worked as a core infrastructure engineer for the U.S.-based industrial company, identified in court records as Victim-1. While he was living in New Jersey in November 2023, he allegedly began preparing a plan to disrupt the company’s computer network and force it to pay a ransom. His position reportedly gave him technical knowledge and access that allowed him to plan the attack against the company’s critical systems. 

As part of the scheme, Rhyne initiated unauthorized remote desktop sessions and scheduled tasks designed to damage the company’s network. The planned actions included deleting network administrator accounts, changing passwords linked to other employee accounts and shutting down several company servers. These steps could have seriously disrupted business operations by preventing authorized staff from accessing systems and interrupting essential digital services. 

On November 25, 2023, Rhyne sent an extortion email to employees of the industrial company. In the message, he threatened to continue shutting down servers unless the company paid approximately 20 bitcoin. At the time, the cryptocurrency demand was valued at about $750,000. The case highlights how former employees with detailed knowledge of internal infrastructure can pose a significant cybersecurity risk, especially when access controls and administrative privileges are not promptly reviewed after employment ends. 

The investigation was conducted by special agents from the FBI’s Newark Field Office, with assistance from the FBI’s Kansas City Field Office. U.S. Attorney Robert Frazer announced the sentence, while Assistant U.S. Attorney Taj Moore of the Cybercrime Unit prosecuted the case. The conviction demonstrates that unauthorized access, deliberate disruption of computer networks and ransom demands can result in substantial federal prison sentences. It also underlines the importance of removing former employees’ access, monitoring remote sessions and protecting administrator accounts against misuse.

MALFEX npm Campaign Uses Three Malware Delivery Chains

 

A long-running malware campaign on the npm registry is using malicious JavaScript packages to compromise Windows systems with remote-access malware, information stealers and additional payloads. Researchers have linked the operation, known as MALFEX, to an apparent single operator active on npm since August 2023. 

The operator has published 12 packages, eight of which were found to contain malicious code. Together, the packages had recorded 40,767 downloads by October 1. However, those figures represent package downloads rather than confirmed infections. MALFEX currently uses three separate infection chains. The first delivers the Overlord Remote Access Trojan through packages including tlxbnhd, tldriver and mxdriver. 

Malicious installation scripts download and execute a Windows payload disguised as an image. Overlord can capture screenshots, keystrokes and clipboard data, search files and provide attackers with remote shell access. It also establishes persistence through a scheduled Windows task named “Maiden.” A second chain involves native-runner, img-to-native and cdn-img-fetch. 

Instead of relying on an npm installation script, the malicious code executes when the package is loaded. Data hidden inside an image is decrypted to produce a downloader, which retrieves movinlike, a Node.js information stealer. The malware targets Discord accounts, browser credentials, Telegram session data and cryptocurrency wallets before sending stolen information to an attacker-controlled Discord webhook. 

The third and longest-running chain revolves around function-flag. Its malicious versions contain code that downloads Windows executables from changing external locations. In version 1.7.3, a hidden routine triggered during installation downloads node.exe and executes it from the user’s application-data directory. function-color serves as a wrapper that installs function-flag. 

Three malicious packages remained installable as of September 29: function-flag, function-color and cdn-img-fetch. function-flag accounted for 37,419 downloads, making it by far the most widely downloaded package in the campaign. Despite that activity, it had no security advisory. function-color also lacked an advisory, while the advisory for cdn-img-fetch covered only versions 1.0.0 and 1.0.1, leaving malicious versions 1.0.2 and 1.0.3 outside its coverage. 

The campaign also uses several techniques to make detection harder. Malicious code can be hidden beyond the visible area of a typical editor, failed downloads may be suppressed without generating installation errors, and the attacker has published benign packages alongside the malicious ones. Security teams should block all eight identified malicious packages and check dependency trees and lockfiles for them. 

Any Windows system where one was installed should be treated as potentially compromised, isolated from the network and investigated. Organizations should also remove persistence mechanisms and rotate credentials from a clean device if sensitive accounts were used on the affected machine. 

MALFEX highlights the risk of relying solely on npm advisory feeds: malicious packages can remain installable even when related packages have been removed, while some dangerous versions may have no advisory coverage at all.

US Probes Cyberattack on Energy Tankers Over Possible Iran Ties


One of the Journal reported that US authorities are investigating a possible Iranian connection to cyberattacks targeting two energy tankers in August heading toward American ports. A number of vessels were attacked as they passed through the Strait of Gibraltar before proceeding towards Texas. These vessels were the oil tanker VL Prosperity and the liquefied petroleum gas carrier Kohaku which were targeted. 

At the time of the incident, the VL Prosperity was transporting more than two million barrels of oil from Egypt to Galveston, Texas. The Kohaku was also on its way to Texas where it was scheduled to load liquefied petroleum gas. Following the arrival of the vessels in the Gulf of Mexico, a specially trained cyber response team led by FBI personnel boarded both. 

The Coast Guard conducted several days of assessments of the incidents and checked to ensure that the vessels could continue operating safely after they discovered signs of a compromise of their information technology and operational systems. According to reports published in August, hackers gained access to the engine-room systems of the VL Prosperity and interfered with several engine functions, including cooling, speed, fuel, and engine oil. 

There was no claim of responsibility from any group, and the reported details were unable to be independently verified. Later on, the vessel's manager confirmed that US authorities examined the tanker's cybersecurity before clearing it for normal operations. This incident illustrates the risks associated with interconnected systems that are used aboard modern commercial vessels. 

As a result of the integration of information technology with propulsion, navigation, and engineering systems on board, it may be difficult for a successful intrusion to affect the vessel's physical performance. Neither incident has disrupted operational operations, caused harm to crews, or damaged the environment, and no attribution of these attacks has been made public to Iran. 

Additionally, the investigation takes place in the context of increased suspicions of Iranian-linked cyber activity by US agencies. A maritime security expert has warned that it may be difficult to determine the actual extent of attacks against shipping, especially when vessel operators restore systems quickly without thoroughly investigating how an intrusion occurred. 

According to Lloyd's List, US agencies are monitoring cyber threats involving almost 20 ships worldwide, which raises concerns over the growing vulnerability of commercial shipping. The risks extend beyond individual ships as well. Navigating, propulsion, steering, and other critical operations of commercial vessels are increasingly dependent on connected digital systems. The compromise of these systems could negatively impact a vessel’s movements or create broader difficulties around major shipping routes and ports. 

A serious disruption could result in a fire, explosion, or spill. An investigation of the tanker is also underway as key maritime routes are becoming increasingly congested. It is important to note that the crossing of the Strait of Hormuz has been repeatedly disrupted and attacked during the conflict, while Iran-backed Houthi forces have exerted increased pressure on vessels operating around the Red Sea and Bab al-Mandab Strait. 

Since cyberattacks could take place against vessels traveling outside these traditional conflict zones, maritime security concerns have been intensified. US authorities have not yet established that Iran was responsible for the attacks. There has also been no determination as to whether the attacks were connected to each other. Further investigations by the FBI and Coast Guard may clarify whether the attacks were isolated incidents or part of a broader campaign targeted at maritime infrastructure.

Japanase Media Company Nikkei Reveals Intrusions Attacking Users and Employees


Japanese media company Nikkei has disclosed two separate cyber incidents involving employee accounts on Microsoft 365 and Google Workspace. One of the incidents allowed attackers to use an employee's account to send about 9,000 phishing emails, while the other may have exposed the personal information of 1,646 employees and business partners.

The incidents were disclosed on October 4 and reveal the risks organizations face when attackers gain access to legitimate employee accounts. Nikkei has not attributed either incident to a specific hacking group or confirmed whether the two attacks were connected. 

Microsoft 365 account used to send phishing mails

The more recent incident involved an employee's Microsoft 365 account. According to Nikkei, attackers gained unauthorized access to the account and used it on September 30 to send approximately 9,000 emails.

The messages were sent to people both inside and outside the company. Some recipients were journalistic sources and other individuals who had previously communicated with Nikkei employees.

The emails contained links leading to malicious websites. Because the messages were sent from a legitimate Nikkei employee account, recipients could have been more likely to trust them. This type of account compromise can allow attackers to use an organization's existing relationships to distribute phishing messages.

Nikkei said the incident may have exposed recipients' names and email addresses, along with the contents of some emails. The company is still investigating the number of people whose personal information may have been affected. According to Nikkei, “There may be an increase in emails impersonating Nikkei employees or our group companies,”

Google workspace breach

Nikkei also disclosed a separate incident involving an employee's Google Workspace account. The account was accessed without authorization beginning in late July.

The company discovered the intrusion in early August after receiving an alert from Google. Nikkei then changed the account's password and said it has not detected any further unauthorized access.

The incident may have exposed information belonging to 1,646 employees and business partners. The potentially affected information included names and email addresses.

Nikkei said the exposed information did not include data related to its readers or journalistic sources. The company also said it has found no evidence that the information was misused. 

Nikkei’s response

After the Microsoft 365 incident, Nikkei changed the affected password and contacted recipients of the phishing emails, asking them to delete the messages. The company warned that additional emails impersonating Nikkei employees or its group companies could appear.

Nikkei has also reported the incidents to Japan's data protection authority. Investigations into the scope of the Microsoft 365 compromise and the information potentially exposed are continuing.

Nikkei has experienced other cybersecurity incidents in recent years. In November 2025, the company disclosed a malware-related credential theft incident that potentially exposed information connected to more than 17,000 employees and business partners. 

Meta's AI Agent Read 187,000 Private Messages. Now Apple Is Changing the Rules




Apple has announced plans to overhaul one of macOS's most powerful privacy settings, citing security risks posed by AI agents that have been using it to access user data in ways most people never anticipated.

The setting, Full Disk Access, lives inside Privacy & Security in macOS Settings and was introduced with macOS Mojave (version 10.14). It gives users control over which applications can read system-level data, including files, Mail, Messages, Safari history, and Time Machine backups. Security tools and backup software rely on it legitimately. The problem is that once granted, an application can bypass many of the protections Apple built to keep sensitive data off-limits to third parties.

Apple warned in a developer advisory that some developers are using Full Disk Access to expose everything on a user's system without their full knowledge, and that for communication apps this also compromises the privacy of the people those users are messaging. The company said it plans to update the setting so access can only be granted through an explicit user action, and that as AI agents grow more capable and autonomous, the risks tied to this level of access will only increase. When the new controls will arrive has not been said.

The announcement follows a controversy involving Meta's personal AI agent, Muse. When the app launched on September 8, Inc. columnist Jason Aten installed it and says he explicitly declined to give it access to his Messages, calendar, or personal data. Despite that, Muse pitched him a column idea drawn from a private text exchange with his podcast co-host. Aten says Full Disk Access was disabled on his machine, yet the agent had synced more than 187,000 rows of his private iMessages to Meta's cloud. When he asked Muse directly how it read those conversations, the agent told him the paired Mac app was only relaying notification previews, an explanation that turned out to be false. Meta's David Singleton later called it a fabricated account of the feature.

Meta disputed the broader account. Singleton and communications head Andy Stone both argued that reading Messages requires two separate permissions: Full Disk Access must be active in macOS, and the Messages connector within Muse must also be switched on. Singleton said that without Full Disk Access, all related options are greyed out and the feature does not work. Whether that permission was ever active on Aten's Mac is something the two sides still disagree on.

What the episode made clear, regardless of how that specific question gets resolved, is exactly the scenario Apple is now trying to prevent: AI agents accumulating sweeping system permissions that users did not fully understand they had handed over.

The problem extends beyond confusing permission dialogs. On September 21, security researcher Patrick Wardle, founder of the Objective-See Foundation, published a zero-day flaw in Muse's Mac app before Meta had a patch ready, accompanied by a working proof of concept called "not-a-mused." The flaw centered on an undocumented configuration setting called "endo_voyager_dictation_endpoint" that any unprivileged local process could overwrite without admin rights and without triggering macOS security prompts. An attacker who had already landed on the machine could use it to redirect Muse's dictation traffic, capture audio and prompts, inject malicious instructions, and take advantage of every permission the agent held, covering files, microphone, camera, calendar, location data, and linked iOS devices. Wardle's proof of concept demonstrated over 50 commands being executed through the compromised agent.

Meta deployed a patch within 24 hours of disclosure, but Wardle argued that a ClickFix-style attack could have made the exploit remote, giving attackers access to any device running Muse, not just machines they had already penetrated by other means. He described Muse's extensive system permissions as making it trivial to turn the agent into a ready-made backdoor.

Wardle also separately reported a flaw in OpenAI's ChatGPT Mac app, tracked as CVE-2026-100754, that could have let attackers take over the assistant and access chat logs and other stored data. He described the exploit as insanely trivial, requiring roughly a dozen lines of code, and noted it could also be used to get ChatGPT to run commands on an attacker's behalf, with the requests appearing as legitimate instructions from the OpenAI software. OpenAI has since patched it.

Wardle has said he will present analysis of multiple AI macOS application vulnerabilities at Objective by the Sea, an Apple-focused security conference in November, and has already submitted a further finding to OpenAI related to the integration between ChatGPT and the company's always-on Dots AI assistant.

The pattern across all three incidents points to a structural problem the industry has not resolved. AI agents need deep system access to function, and that same access makes them attractive targets. "AI companies are fixated on adding features right now," Wardle said, and the permission frameworks macOS relies on were not designed with always-running, autonomous agents in mind. Apple's planned changes to Full Disk Access are an attempt to close that gap, though what those controls will actually look like when they ship remains unknown.


AI Spam Surge Forces Google to Pause Open Source Bug Bounty Program


OSS VRP (Open Source Software Vulnerability Rewards Program) has temporarily been suspended after a sharp increase in automated reports that were found to be valid. Since October 1, security teams and open-source maintainers have been facing an increasing number of low-quality vulnerability reports generated via artificial intelligence. 


The pause, which took effect on October 1, is in response to increasing volumes of low-quality vulnerability reports. Google announced the OSS VRP in August 2022 as a means of rewarding researchers who identifies and responsibly discloses security flaws in open-source software maintained by the company. 

The program covers projects such as Golang, Angular, Bazel, Protocol Buffers and Fuchsia, along with selected third-party dependencies. Security concerns regarding GitHub Actions, application configurations, repository settings, and access control rules are also covered by this program. There was initially a range of rewards available from $100 to $31,337 under the program, with particular emphasis placed on vulnerabilities that could potentially pose significant risks for software suppliers. 

As a result of the company's wider vulnerability rewards program, millions of dollars have since been awarded to researchers, making the OSS VRP an important means of identifying security vulnerabilities in widely used open-source projects. An increase in automated submissions was responsible for the current suspension, according to the company, with the majority failing to identify valid security issues. 

Although the use of artificial intelligence-assisted tools has made the generation of vulnerability reports at scale easier, the resulting volume may also include incorrect findings, duplicate claims, and reports concerning vulnerabilities that do not exist. OSS VRP is currently being reviewed by Google to address the issue and determine how the program should handle the growing number of automated submissions. 

A further update is anticipated in the first quarter of 2027. Additionally, the company clarifies that the change does not affect outstanding reports or product vulnerabilities submitted prior to October 1. The impact of the AI-driven reporting surge extends beyond Google's program as well. 


It has not been the company's first time experiencing a sharp increase in low-quality vulnerability submissions that have been generated by automated tools. This raises concerns about the time security teams will need to spend validating reports that do not identify genuine vulnerabilities. The Google Patch Rewards Program continues to offer incentives to researchers for submitting high-impact open-source security patches that qualify for rewards of up to $15,000. 

Google Cloud's Cloud Vulnerability Reward Program provides a means of reporting security vulnerabilities affecting open-source repositories related to Google Cloud products. Google's decision follows similar developments elsewhere in the security industry. In January, the curl project maintainer terminated its HackerOne bug bounty program in response to a significant number of low-quality, artificial intelligence-generated vulnerability reports. 

As part of its Intigriti bug bounty program, Intel also removed financial rewards in September, though the company did not provide a publicly stated reason for the change. As the use of artificial intelligence tools increases in speed, potential vulnerabilities are identified and reported more rapidly, while the review process remains the responsibility of security researchers and maintainers. 

Earlier this year, Microsoft warned that AI-assisted vulnerability discovery could increase the number and scale of security discoveries, potentially increasing the operational demands on security teams. Google has not yet confirmed that the Open Source OSS VRP will be permanently discontinued. The company is reviewing the program and anticipates making changes in the first quarter of 2027. 

For now, the temporary suspension reflects a growing challenge for bug bounty programs, namely, how to handle a large volume of automated reports without allowing invalid findings to overwhelm genuine security issues. 

The decision of Google highlights the difficulty of vulnerability reward programs as AI-assisted security research increases submissions. It will become increasingly important for these programs to distinguish genuine findings from automated and inaccurate reports in order for them to be effective.

South Korea Orders Financial Sector Probe After Series of Data Breaches

 

South Korea is gearing up to respond to a string of cyber disruptions that targeted financial institutions, with the President demanding a thorough inquiry about the recent personal data breaches and protection of future incidents.  

The Financial Services Commission (FSC) is leading the response and is holding meetings with industry bodies, regulators, and officials from impacted financial institutions to discuss the next steps. FSC Chairman Lee Eog-weon warned that finance companies must remain on high alert as the authorities trace the source of the cyberattack. The security breach investigation was initiated after Shinhan Bank notified the FSC about the incident on September 30. 

Following that, regulators opened on-site inspections and expanded the probe as more financial institutions reported a cyberattack. Shinhan Bank and KB Kookmin Bank were the two financial firms named by the FSC, while Yonhap News Agency reported that Hana Bank and Woori Bank also experienced data leaks. FSC decided to call an emergency meeting of senior officials to review the situation, moving it from its original date, October 7. 

According to Korean media, the main reason for the emergency meeting was related to the fact that more financial institutions became victims of cyberattacks, and that additional breaches at secondary financial institutions were also suspected. Regulators are also considering the possibility that AI might be involved in the cyberattack. Lee warned that the involvement of AI in the cyberattack cannot be ruled out and that the response should be based on AI-driven cybersecurity solutions. 

In addition, the FSC is considering implementing enhanced cybersecurity measures for the finance sector. Among the first steps taken by the FSC is a recommendation that financial institutions conduct a cyber hygiene review. FSC urged finance companies to implement stricter access controls, reduce the exposure of their systems, and introduce additional measures to protect consumers from potential data abuse. Furthermore, the FSC is pressuring financial institutions to share information about the cyber incidents. 

The information exchange process should include attack methods, internet protocol (IP) addresses, and other details. It would enable financial companies to develop a joint response and recognize other potentially impacted entities. The cyberattack might have been targeting financial hubs rather than the single institution, according to one scenario produced by South Korean regulators and reported by Yonhap. The unnamed regulators believe that the cyber attackers targeted several financial institutions in an attempt to scan the system to find weaker areas.  

According to the information provided by the banks to the National Assembly, the cyberattack came from various IP addresses. Those locations spanned across several countries, including the US, Japan, Singapore, Vietnam, and the UK. South Korea’s opposition People Power Party is demanding that the government investigate whether North Korea was behind the cyberattack. 

The cyberattack could be a retaliation for decades of cyber espionage and economic sabotage by Pyongyang, according to the party. The response from the FSC is to keep investigating the cyber incidents and urge financial institutions to boost their cybersecurity measures and share information about the cyber incidents.

Denmark Population Registry Breach Exposes 8.8 Million Citizens

 

Denmark is grappling with one of the most significant data breaches in its history after unauthorized actors gained access to the Central Population Register (CPR), exposing the personal information of approximately 8.8 million individuals. The breach, discovered in early October 2026, affects not only current residents but also includes data on people who have moved abroad and even deceased individuals. The CPR serves as Denmark's national civil registry and contains highly sensitive information including names, addresses, dates of birth, marital status, and unique CPR identification numbers that are integral to daily life in the Scandinavian nation. 

The attack was carried out through a sophisticated method involving a private Danish company that had legitimate access to the registry system. According to authorities, threat actors misused this company's credentials to extract data from the CPR database. The Danish Data Protection Agency revealed that the attackers employed brute-force techniques to enumerate valid CPR numbers before systematically extracting associated personal data from each entry. This method allowed them to harvest information on a massive scale, impacting roughly 80% of the 11 million registered citizens currently in the CPR system, making it one of the largest population registry breaches ever recorded in Europe. 

Security officials detected the breach on October 2, 2026, though the actual incident occurred earlier in September. Once the CPR administration became aware of the compromise, they immediately blocked the private company's access to the registry and launched a comprehensive investigation with police assistance. Minister for Research, Education and Digitalization Christina Egelund described the incident as extremely serious and promptly informed Parliament's Business and Digitalization Committee. The government has since implemented additional security measures to prevent similar incidents and is working with all relevant authorities to establish the full extent of the damage caused by this unprecedented security failure.

In response to the breach, Danish authorities have established a dedicated cyber hotline to assist potentially affected individuals and provide guidance through the website sikkerdigital.dk. Officials are urgently warning citizens to remain vigilant against unsolicited communications, emphasizing that criminals may use the stolen data to craft convincing phishing attempts. The government specifically cautioned that people should never disclose passwords or confidential information in response to telephone calls, emails, or similar communications, even if the caller appears to know their name, address, and CPR number. This warning is particularly critical because the exposed data could enable highly targeted social engineering attacks that would be difficult for ordinary citizens to identify as fraudulent. 

The Denmark CPR breach represents a stark reminder of the vulnerabilities inherent in centralized population databases and the catastrophic consequences when such systems are compromised. As investigations continue, questions remain about how the private company's credentials were obtained and whether additional security lapses contributed to the scale of the breach. For millions of Danes, the incident means living with heightened risk of identity theft, financial fraud, and privacy violations for years to come. The breach also raises broader concerns about data protection practices across Europe and may prompt other nations to reassess the security of their own civil registry systems in an increasingly dangerous digital landscape where personal information has become a valuable commodity for cybercriminals worldwide.

Belarusian Hackers Compromised Russian Healthcare Network for Two Years


A Belarusian hacktivist gang allegedly maintained access to the network of a Russian healthcare organization for almost two years, potentially gaining access to sensitive medical information, cybersecurity researchers have reported.

Researchers from Russian cybersecurity company Solar said they discovered the intrusion in December 2025. However, their investigation found evidence suggesting that the attackers had entered parts of the organization’s infrastructure as early as 2024.

Attack details

The attack was attributed to the Belarusian Cyber Partisans, a group known for cyber operations against Belarusian and Russian government organizations and businesses.

Despite remaining inside the network for an extended period, the attackers did not appear to destroy systems or cause major disruption. Researchers believe maintaining access may have been more valuable to the attackers than immediately carrying out destructive activity. 

Intrusion details

Solar researchers identified several tools associated with the intrusion, including an updated version of the Vasilek Windows backdoor.

Vasilek was previously documented by Kaspersky as malware used by the Cyber Partisans. The backdoor can communicate with attackers through the Telegram Bot API and receive commands through a Telegram group. It can collect information from infected computers, execute Windows commands, transfer files, capture screenshots and record keystrokes. 

Attack tactic 

Solar said the newer version found during its investigation was version 1.5.8. Researchers also identified techniques for maintaining persistence inside the victim’s environment. These included Windows services and the replacement of the vmtools.dll library associated with VMware Tools.

The attackers also used other communication and tunnelling tools, including DNS tunnels and proxy chains. This gave them alternative methods of communicating with compromised systems if one channel became unavailable. 

Telegram restrictions in Russia affected Vasilek’s communications, but researchers said the attackers could use other methods to maintain their access.

What next?

The compromised organization was not publicly identified. However, researchers said it operated a large infrastructure connected to multiple other healthcare organizations.

This created a potential trusted-relationship attack risk. Once attackers gained control of one organization, its connections with other trusted healthcare entities could potentially provide opportunities to reach additional networks.

The researchers said the attackers accessed sensitive medical data but did not destroy the victim’s systems. The long period of access suggests that espionage, intelligence gathering and maintaining future access may have been more important than immediate disruption. 

CloudSyncD Backdoor Spread Through Fake Zoom Installer Targeting macOS

Using fake Zoom installers, a macOS malware campaign distributes a backdoor known as CloudSyncD, a backdoor for MacOS. 

Jamf Threat Labs first identified the malware during its development in mid-September, but later samples indicated it had moved to a live command-and-control infrastructure. It is initiated by the use of a disk image that is made to resemble the Zoom installer. When a package is opened, it appears as a volume titled Zoom and uses familiar installation elements to create the impression that the application is genuine. 

Using fake Zoom installers, a macOS malware campaign distributes a backdoor known as CloudSyncD, a backdoor for MacOS.

Jamf Threat Labs first identified the malware during its development in mid-September, but later samples indicated it had moved to a live command-and-control infrastructure. It is initiated by the use of a disk image that is made to resemble the Zoom installer. When a package is opened, it appears as a volume titled Zoom and uses familiar installation elements to create the impression that the application is genuine.

During installation, victims are presented with an authorization prompt designed to obtain their account password. The installer also relies on the user allowing the application to run despite macOS Gatekeeper protections. Before continuing with the infection process, CloudSyncD verifies the supplied credentials against the local account. Rather than immediately forwarding those credentials to its operators, the malware retains them on the compromised machine inside a disguised configuration file.

The stored password is deliberately made difficult to identify through an ordinary inspection of the file. CloudSyncD combines encoded information with invisible zero-width Unicode characters, effectively concealing the credential within otherwise inconspicuous data. The password subsequently becomes useful to the malware itself, allowing the next stage of the infection to run with greater privileges. The accompanying CloudSyncD component is delivered as a universal Mach-O binary, allowing it to operate across both Intel and Apple silicon systems.

For the next stage, the malware first tries to launch its payload without relying on a conventional file being written to the system. If macOS protections prevent this approach, CloudSyncD can fall back to placing the payload temporarily on disk. It can then make use of the previously obtained password with `sudo` to execute the component with elevated permissions.

Once running, the second-stage component operates primarily as a backdoor rather than as a conventional information-stealing program. Its purpose is to establish contact with attacker-controlled infrastructure and create a channel through which additional executables or compressed archives can be delivered. This gives the operators an opportunity to introduce further malware or tooling after access to the Mac has already been established.

By creating a working directory and maintaining encrypted activity logs, the malware avoids the need for a visible persistence mechanism. Check-ins occur every 8 to 16 seconds and include a hardware identifier, suggesting a periodic check-in is occurring. Compared to a simple command shell, the C2 channel provides the attackers with greater flexibility.

Using CloudSyncD, the compromised Mac can be supplied with compressed archives or executables, which can then be used to run the supplied content. Jamf Threat Labs identified multiple later builds of the backdoor communicating with two live domains following the initial infection. This enables the backdoor to serve as a delivery mechanism for additional malware or tools. They use the same URI structure, which was designed to resemble a request for a jQuery script.

Both domains were registered with the same registrar in 2011 and were protected by Cloudflare. As of the time of the researchers’ analysis, neither domain was flagged by a security service. A number of technical similarities were also observed between the different samples, including similar string-obfuscation schemes, installation paths, daemon names, and process disguise schemes.

More importantly, the builds shared the same C2 encryption key and initialization vector, which means network traffic captured from different versions could potentially be decrypted using recovered configuration material. According to the findings, CloudSyncD had moved from an unfinished test build to a functional backdoor utilizing social engineering, while maintaining a relatively simple infection route.

Researchers distinguish the malware from a conventional infostealer despite the fact that it collects system and user information for reconnaissance. Rather than being sent to the attackers, the captured password is used locally to obtain elevated privileges, while the backdoor's primary function is to provide access and facilitate the execution of additional payloads.

California Court Dismisses El Faro Journalists' Pegasus Spyware Lawsuit Against NSO Group for Second Time

 



A California federal judge has once again dismissed a lawsuit brought by journalists from Salvadoran investigative outlet El Faro against NSO Group, the Israeli company behind the Pegasus spyware allegedly used to surveil their phones for nearly two years. The ruling, issued Wednesday, marks the second time the case has been thrown out on jurisdictional grounds, though the journalists' legal team at the Knight First Amendment Institute at Columbia University has said it intends to appeal.

The case, Dada v. NSO Group, was the first lawsuit against NSO filed in any U.S. court when the Knight Institute took it on in November 2022 on behalf of 18 current and former El Faro journalists and staff. Between June 2020 and November 2021, Pegasus spyware was deployed against the outlet's employees at least 226 times, according to the Institute. Digital forensic analysis eventually confirmed that 22 members of El Faro's staff had their phones infected. The attacks were not random. Surveillance peaked during significant political moments and in the run-up to major investigations, including reporting on the Bukele administration's secret negotiations with criminal gangs, the theft of pandemic food relief, back-channel Bitcoin dealings, and the financial holdings of government officials.

The lead plaintiff, Carlos Dada, is the co-founder and director of El Faro, one of Central America's most prominent independent news organizations. El Faro was founded in El Salvador in 1998 and has built a reputation for independent investigative reporting. The outlet has paid a steep price for that journalism. Beyond the spyware attacks, El Faro says it has faced physical surveillance, advertiser harassment, and public defamation from government officials and ruling-party legislators. In 2023, the newsroom relocated its administrative and legal operations out of El Salvador entirely.

The core question before the court was whether Northern California was the right place to try this dispute. Dada and the plaintiffs argued it was, pointing to compromised U.S.-based infrastructure that was used as part of the attack chain. The judge was not persuaded. The court noted that there was no allegation Apple's California servers were actually exploited in delivering the Pegasus infections, even where the plaintiffs alleged the attacks moved through Apple's iMessage or iCloud systems. The same argument had failed once before: in March 2024, a California federal judge threw out the same lawsuit, saying the case was "entirely foreign" and that the journalists had no standing to sue in the U.S.

That first dismissal did not hold. The Ninth Circuit Court of Appeals reversed the March 2024 ruling in July 2025 and sent the case back to the Northern District of California, finding that the lower court erred in its analysis. The Ninth Circuit had concluded that the district judge failed to properly account for allegations that NSO created Apple ID accounts and engaged with California-based servers as part of the attack infrastructure. One factor that also came into play was a recent acquisition of NSO Group by a group of American investors, which El Faro's lawyers cited as further reason for trying the case on U.S. soil. After the Ninth Circuit's reversal, Dada called the outcome "good news." That window has now closed again.

The journalists had wanted specific remedies from the court. They asked the court to require NSO Group to identify, return, and delete all information obtained through the attacks, to prohibit the company from deploying Pegasus against them again, and to name the government client that commissioned the surveillance. That last demand was perhaps the most politically charged. NSO has never publicly identified its clients. The company maintains it sells Pegasus exclusively to government agencies for use against criminals and terrorists, subject to Israeli government authorization. El Salvador's government has repeatedly denied being an NSO client or playing any role in the surveillance.

With Apple having dropped its own case against NSO in September 2024, and WhatsApp having won a $167 million judgment against the company earlier in 2025, the El Faro lawsuit had become the last active case against NSO Group in U.S. courts. That distinction is now moot, at least temporarily.

The Knight First Amendment Institute plans to appeal. El Faro's director Carlos Dada said when the original lawsuit was filed that the outlet turned to the U.S. court system because justice in El Salvador was not possible. With the case now dismissed a second time and the appeal road still open, that search for accountability continues.

NSO Group did not respond to a request for comment.



DTU Data Breach Exposes Information of 200,000 People

 


The Technical University of Denmark (DTU) has disclosed a major data breach that may have exposed personal information belonging to as many as 200,000 current and former users. Hackers reportedly accessed DTUBasen, the university’s identity and access management system, after obtaining valid credentials. The system contains records collected over more than two decades, raising concerns about identity theft, targeted phishing and other forms of fraud.

DTU said it cannot yet determine exactly which information attackers downloaded or how many people have been affected. However, the database contains details linked to nearly 40,000 active users and approximately 160,000 former users. Information related to current users may include Danish civil registration numbers, full names, home addresses, profile photographs, work email addresses, job titles, office locations and other employment details. 

The breach may also have exposed emergency-contact information submitted by active users. This could include the names, relationships and phone numbers of next of kin. DTU noted that information about home addresses, profile pictures and next of kin belonging to former users is automatically deleted after six months. University Director Bjarke Bak Christensen described the incident as a serious attack and apologised for the uncertainty caused to potentially affected individuals. 

DTU plans to notify potentially impacted people through e-Boks, Denmark’s official digital mailbox service. The university said it will contact current and former employees, although not every student whose information may be stored in the system will receive a direct notification. Anyone who has been a DTU employee, student, guest or external partner since 2003 could potentially be affected, according to the university’s public warning. 

The university is advising affected individuals to remain alert for suspicious emails, text messages and phone calls that mention their connection with DTU or contain accurate personal details. People should avoid sharing passwords, personal information or authentication codes in response to unexpected requests. They should also change reused passwords on other services and consider placing a credit alert on their affected civil registration number. The incident highlights how compromised credentials can give attackers access to extensive historical records, even when an organisation’s main systems remain operational.

China-Aligned TA419 Uses Microsoft AitM Phishing Against U.S. AI Policy Experts

 

A China-linked cyber-espionage group is targeting Microsoft credentials belonging to U.S. policy and regulatory specialists in artificial intelligence, using highly focused social engineering techniques. 

TA419, the threat actor behind the campaign, has diversified its interest from defense, national security, energy, international relations and foreign policy to include those involved in the policy and regulation of AI, a Proofpoint analyst reported. The group has been targeting U.S. and Japan-based think tanks, defense contractors, universities and law firms through credential phishing since at least April 2025. 

One technique, deployed in a February 2026 campaign, involved impersonating prominent figures in economic and AI policy, as well as an Anthropic employee, in an email titled “Request for Feedback on Military Integration of Claude” to influence an AI policymaker at a U.S. think tank. Similarly, around July, the group began targeting individuals including a former White House Office of Science and Technology Policy (OSTP) leadership team member with an impersonation campaign. The attack chain is designed to appear to have come from a trusted source, not direct phishing. 

First, the victim receives an innocuous request designed to gain the confidence of their target by referencing a shared professional interest. If it gets a response, it then replies with a shortened URL. Once the link is clicked, the victim is directed to a Microsoft OneDrive-like adversarial in-the-middle phishing site after several redirections. The Cloudflare Turnstile Captcha is integrated into the attack chain, helping to lend credibility to the link. 

The credential harvesting component of the attack uses a technique called Frameless BitB, which uses a browser-in-the-browser approach to create the illusion of a separate window using only HTML, CSS and JavaScript. This differs from previous use of Bitb by this threat actor, which used an iframe. Proofpoint noted that TA419 has been modifying an open-source iteration of the attack to incorporate its own telemetry and automation components. The campaign uses an in-the-middle proxy to compromise Microsoft authentication by impersonating a legitimate login page.

It appears to be a legitimate login page; however, it is actually using the authentication token from the user’s Microsoft account to gain access to the account. This technique can be challenging to detect because the Microsoft logon page can appear to be authentic while the attacker’s application window is using some of the user’s session information. This allows the attacker to use the credentials to access the Microsoft account. Proofpoint noted that the activity supports Chinese intelligence interests by providing insight into the U.S. regulatory and policy environment around AI. 

The intensifying U.S.-vs-China strategic competition over AI, including issues around model distillation and export controls, appears to be a catalyst for the campaign. Entities should consider implementing phishing-resistant authentication factors such as passkeys, and individuals who received unexpected professional or professional correspondence should take steps to independently verify the request before responding or following any links.  

While the shift to AI policy experts represents a new focus area for TA419, it is not a significant change in the group’s interests. According to Proofpoint, this is an evolution, rather than a revolution, of the group’s current targeting.

China's Ministry Allegedly Funded Research Involving 100+ Academics


The U.K.’s domestic intelligence agency, MI5, has warned that more than 100 U.K.-linked academics have contributed to research projects allegedly funded by China’s Ministry of State Security (MSS).

Impacted areas

The research reportedly covered areas including artificial intelligence (AI), cybersecurity, covert communications and steganography.

The warning was issued in an MI5 Security Service Espionage Alert on September 30, 2026. According to MI5, the research funding was channelled through the China General Technology Research Institute (CGTRI), also known as the China Academy of General Technology (CAGT). 

About the warning

MI5 assessed that CGTRI is being used as a front for China’s MSS and claimed that its primary purpose is to fund research that can improve the Chinese intelligence service’s technical capabilities.

“The alert advises UK academic institutions to immediately review any ongoing or planned collaboration with CGTRI and advises academics to establish the ultimate funding source when conducting any research collaboration with Chinese institutions to ensure CGTRI are not involved,” reads the MI5 security alert.

Associated risks 

The areas of research identified by MI5 are particularly significant from a cybersecurity and intelligence perspective. Artificial intelligence can be used for data analysis, automation and surveillance, while cybersecurity research can contribute to offensive and defensive cyber capabilities.

The alert also revealed covert communications and steganography. Steganography involves hiding information inside another form of digital content, such as an image or audio file, making it potentially useful for concealing communications.

MI5 said that more than 100 academics linked to the U.K. had contributed to projects funded through CGTRI. The agency also said that some researchers may not have known that CGTRI was financially supporting the research they were involved in. 

MI5 further added, “It puts the fact that CGTRI has very strong ties to MSS in the public domain and states that academic institutions, staff and researchers should ensure they are aware of the National Security Act 2023.  Any institution or individual continuing to conduct research ultimately funded by CGTRI should take their own independent legal advice.”

Potential risks

MI5 warned that research developed through these collaborations could potentially strengthen Chinese intelligence capabilities. The agency particularly highlighted the risk to the U.K. because some of the technologies involved could have applications in cyber operations and intelligence gathering.

Chinese Embassy’s Response 

China has rejected the allegations. The Chinese Embassy in the U.K. described the claims as fabricated and baseless, arguing that academic exchanges between British universities and China are voluntary, lawful and mutually beneficial.

Polish Dental Software Firm Hit by Cyberattack

 

Polish dental software provider FELG Software has confirmed a cybersecurity incident affecting its FELG Dent cloud-based practice management platform. The company became aware of the attack on September 28, 2026, and publicly acknowledged it on October 1. A threat actor using the alias Horus reportedly contacted Polish cybersecurity news outlets, claiming to have accessed sensitive information stored in the system. FELG Software also confirmed receiving a ransom demand in exchange for preventing the disclosure of the allegedly stolen data. More than 16,000 dentists reportedly use the company’s tools, meaning one vendor breach could affect patients from numerous independent practices. 

The attackers claim to have obtained records linked to approximately 2.4 million patients and more than 700,000 medical professionals. The allegedly exposed information includes names, addresses, telephone numbers, national identification numbers known as PESEL, company details, medical records, electronic prescriptions, electronic sick-leave certificates and insurance-verification information. The group also claims to have accessed around 1.2 million prescriptions, visit documentation and diagnostic images. However, these figures have not been independently verified, and the company disputes the attackers’ assessment of the incident’s scale. 

FELG Software has reportedly said that the stolen information represents about 10 percent of its overall database, rather than the complete dataset claimed by Horus. Reports also indicate that the attackers threatened to publish or sell the information after the company refused to pay the ransom. One reported explanation for the intrusion involves an IDOR vulnerability, or Insecure Direct Object Reference flaw. Such weaknesses can allow unauthorized users to manipulate references in requests and retrieve records belonging to other accounts when access controls are not properly enforced. 

The incident is significant because FELG Dent operates as a shared platform for many healthcare organizations. A weakness in the central service can therefore create risks across multiple dental practices at the same time. The breach is also reportedly the third attack in three months targeting Polish healthcare software providers, following incidents involving MyDr in August and Medyc, operated by Qbusoft, in September. These repeated attacks highlight the risks created when sensitive medical information is concentrated in cloud systems without strong tenant isolation, monitoring and access controls. 

The exact scope of the FELG Dent breach remains under investigation. Dental practices using the service may need to review logs, identify affected patients and assess their legal notification responsibilities under applicable data-protection rules. Healthcare providers should also reset potentially compromised credentials, monitor suspicious activity and communicate carefully with patients without relying solely on unverified attacker claims. The case demonstrates why software vendors handling medical data require regular security testing, strict authorization controls, vulnerability disclosure processes and tested incident-response plans. Until forensic investigations are complete, the number of affected records and the precise information accessed should be treated as provisional.

ShinyHunters Hacker Reportedly Detained as FBI Seeks Cooperation


The FBI has reportedly detained a suspected ShinyHunters member known online as “Rey” and is cooperating with the government. Jordanian authorities captured a suspect identified as Saif al-Din Khader this week. According to two sources cited by Reuters, Khader is helping U.S. and international investigators identify other members of the hacking group. 


It is believed that Khader's cooperation will provide investigators with information regarding the group's activities and alleged co-conspirators, according to a source. He has shown investigators his electronic devices and digital communication to help locate other suspected members. The FBI has not responded to Khader's reported detention specifically, however it has stated that it is continuing to investigate the recent cyber incident allegedly involving ShinyHunters and is collaborating with international partners to resolve the matter. 

A series of law enforcement actions targeting individuals affiliated with ShinyHunters has led to this reported detention. Dutch authorities arrested a 24-year-old man in connection with an investigation into the group in September. Following the arrest, the FBI issued a warning encouraging other suspected members to surrender while they continued to investigate the matter. 

The developments are following the claim by ShinyHunters that a job portal breach had taken place. As claimed by the group, it obtained a significant amount of sensitive information from FBI systems. Particularly, it claimed to have acquired employee information, though the extent of the alleged theft has yet to be independently verified. During Khader's reported detention, the group's online activity was also disrupted. 

In addition to the disappearance of the group's data leak website, an account previously used to communicate with journalists no longer responded. Later, another ShinyHunters leak site appeared, indicating the group may continue to conduct activities. Moreover, Khader's reported cooperation strengthens the investigation, which has already been conducted by several individuals associated with the ShinyHunters network in general. 

Khader's identity was previously associated with the group until the latest detention was made. It has been reported that Brian Krebs identified Khader as a member of the Scattered Lapsus$ Hunters umbrella operation in 2025, which is affiliated with ShinyHunters, Lapsus$, and Scattered Spider. Aside from being linked to the HellCat leak site and BreachForums hacking forum, Khader had previously asserted that he was cooperating with law enforcement and had ceased all data theft and extortion activities. Those claims were not independently verified. 

While this was the case, ShinyHunters continued to conduct attacks in 2026, including attacks on Rockstar Games as well as Canvas, which disrupted schools across the country. Despite this, the group has continued to engage in data theft and extortion operations. ShinyHunters has recently begun targeting cloud-based services as well as third-party providers, resulting in incidents that are linked to organizations such as Google, Cisco, and Pornhub.

ShinyHunters has also been linked to the May 2026 breach involving Instructure Canvas, while previous investigations have resulted in arrests related to Snowflake-related attacks, PowerSchool and Breached hacking forums. It may be possible for investigators to gain a better understanding of how this loosely organized network operates and who remains active within it through the recent arrests. 

It has been reported that FBI agents have indicated that information obtained from arrests and seized infrastructure may be useful for identifying additional participants. However, the appearance of a new ShinyHunters leak site following the earlier closure indicates that the organization has not been completely dismantled. Furthermore, the case illustrates the difficulty of disrupting cybercrime groups that are built upon informal networks rather than a rigid organizational structure. 

According to Reuters, investigations and prosecutions can become complicated by the young age of some suspects, the fluid nature of related groups, and the limited cooperation of victims. While ShinyHunters' continued online activity suggests that law enforcement efforts are ongoing, the reported detention and cooperation may provide investigators with valuable insight into ShinyHunters' wider network.

Dell Patches Six Critical Flaws in Container Storage Modules, Some Scoring a Perfect 10

 




Dell has shipped security fixes for six critical vulnerabilities in its Container Storage Modules (CSM) that could allow unauthenticated attackers to seize full administrative control over an organization's storage infrastructure and every node in a Kubernetes cluster. Four of the six flaws carry CVSS scores of 9.6 or higher, two of which hit the maximum possible rating of 10.0.

The bugs affect every version of CSM prior to 1.17.0, and Dell patched them in version 1.18.0. The company says no workarounds or interim mitigations exist, which means organizations running the affected software are down to one option: update now.


What CSM Does, and Why These Bugs Matter

Dell Container Storage Modules are Kubernetes-native extensions that manage persistent storage for containerized workloads across Dell's storage product families, including PowerFlex, PowerStore, PowerMax, PowerScale, and Unity XT. Because CSM sits at the intersection of storage credentials and cluster-level access controls, vulnerabilities in the platform carry a particularly high blast radius. An attacker who compromises CSM does not just gain access to data; they gain the ability to manipulate who can access what across every tenant connected to the system.


A closer look at the Six Vulnerabilities

The most severe of the six, CVE-2026-63688, scored a perfect 10.0. The flaw lives in the csm-authorization-storage gRPC server and requires no authentication to exploit. An attacker on the network can send requests directly to this endpoint and pull the backend administrator credentials for every storage array registered with the system. Dell's own advisory described it as enabling "a complete bypass of the csm-authorization security model," handing an attacker full administrative control over storage spanning all five supported Dell storage product families.

The second maximum-severity flaw, CVE-2026-63692, also a 10.0, targets the authorization proxy and tenant service. Like its counterpart, it requires zero credentials to exploit. A successful attack gives an adversary administrative control over the entire authorization service and the ability to access or manipulate storage resources across all connected tenants.

CVE-2026-67269 scored 9.9 and introduces a different threat model. It is a privilege escalation flaw in the ContainerStorageModule Custom Resource reconciler. A low-privilege attacker, not even a full admin, can submit a single maliciously crafted custom resource to the cluster and walk away with root-level access on every node in the environment. The attack surface is as small as one API call; the damage is cluster-wide.

Two of the remaining flaws center on hardcoded secrets. CVE-2026-54472 (CVSS 9.8) buries a static set of credentials inside the CSM Authorization module, allowing any remote attacker to forge cryptographically valid administrative tokens and seize control of the Authorization proxy. CVE-2026-61421 (also 9.8) compounds the problem: the JWT authentication component in karavi-authorization uses a hardcoded signing key. Because the signing secret is publicly available, anyone who locates it, something that is not especially difficult when code repositories are involved, can mint valid authentication tokens and claim administrative privileges without going through any login flow whatsoever.

The final flaw, CVE-2026-67273, scored 9.6 and is a template injection vulnerability. A low-privilege attacker with remote access can manipulate input fed through the template engine to escalate their own privileges, read sensitive information, and tamper with role-based access controls at the cluster scope. Dell's advisory noted that exploitation yields the ability to "create cluster-scoped RBAC resources, effectively bypassing the intended Kubernetes access controls."


Context: Dell's Track Record With Exploited Flaws

This batch of CSM vulnerabilities does not arrive in isolation. Dell has faced repeated problems with critical infrastructure flaws being turned against real targets in the field. Earlier this year, researchers at Mandiant and Google's Threat Intelligence Group documented how CVE-2026-22769, a hardcoded-credential flaw in Dell RecoverPoint for Virtual Machines carrying a CVSS score of 10.0, had been actively exploited as a zero-day since mid-2024 before Dell published a fix in February 2026. CISA added it to its Known Exploited Vulnerabilities catalog the following day. Years earlier, CVE-2021-21551, an access control flaw in Dell's dbutil driver, made the same list after evidence of active exploitation emerged in the wild.

The pattern here is consistent: attackers increasingly go after enterprise infrastructure components that security teams tend to treat as inherently trusted. Storage management platforms and low-level system utilities rarely face the same scrutiny as public-facing applications, and that blind spot has proven to be consequential.


What to Do

Dell is directing all customers to upgrade CSM to version 1.18.0 immediately. For systems affected by CVE-2026-61421, the company is additionally recommending that JWT signing secrets be rotated post-upgrade, since those secrets were embedded in code that has been publicly accessible and should be treated as already compromised. No partial mitigations apply. The fix is available, and for organizations still running pre-1.17.0 versions, the exposure is active.



China Nexus Cyber Espionage Attacks Government Organizations


A China-nexus cyber-espionage campaign is targeting government and policy organizations across Asia with a previously undocumented Windows backdoor called Antino. Researchers at Cisco Talos are tracking the threat activity as UAT-11587.

Campaign details 

The campaign has targeted organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria. By July 2026, Talos had identified at least 16 affected or targeted institutional environments and approximately 350 compromised endpoints.

The campaign's lure theme and targeting provide additional contextual support. Its lures and observed targets include Taiwanese political, legislative, civil defense, and policy research subjects, together with regional government, maritime, diplomatic, and security themes. This collection focus is consistent with China-nexus actor interests,” Talos said.

The most notable feature of Antino is its use of legitimate Microsoft 365 services as command-and-control (C2) infrastructure. Instead of relying on a traditional attacker-controlled server, the malware communicates through Microsoft Outlook and OneDrive using Microsoft Graph.

About Antino

Antino is a Rust-compiled Windows backdoor capable of gathering information about infected systems, executing commands through Windows shell and PowerShell, transferring files, loading shellcode directly into memory and maintaining persistence.

About the infection 

The infection generally begins with a carefully prepared spear-phishing email. Attackers used government, diplomatic, maritime, legislative and foreign-policy themes designed to appear relevant to their intended victims.

Attack tactic

In some cases, the attackers recreated Gmail’s attachment-preview interface inside the email. When victims interacted with the fake attachment, they were directed to attacker-controlled infrastructure.

The attack then proceeds through multiple stages involving HTA or WSF files, JavaScript and a .NET-based downloader before ultimately installing Antino. The malware has also been deployed through DLL sideloading, using a legitimate Microsoft-signed executable to load the malicious DLL. 

Once installed, Antino uses Microsoft Graph to communicate with Microsoft 365. Outlook is used for receiving commands, while OneDrive handles heartbeat communications and file transfers. This allows malicious traffic to terminate at legitimate Microsoft infrastructure, potentially making conventional network-based detection more difficult.

Impact on systems

A successful Antino infection can provide attackers with persistent access to a Windows system, allowing them to conduct reconnaissance, execute commands, run PowerShell, access files and transfer data.

The targeting of government agencies, diplomatic organizations, universities, think tanks and policy groups suggests that the campaign is focused primarily on intelligence gathering and espionage rather than ordinary financial cybercrime.

Cisco Talos assessed UAT-11587 as China-nexus with high confidence, citing technical, language, infrastructure and targeting indicators. However, researchers noted that attribution to a specific Chinese group remains more complicated.