CTO at NCSC Summary: week ending July 5th
"Data from Report Fraud reveals that 323 organisations reported a ransomware attack between April 2025 and March 2026. Of the reports received, more than 50% were from Small Medium Enterprises"
Welcome to the weekly highlights and analysis of the blueteamsec (and my wider reading). Not everything makes it in, but the best bits do. A community member is doing daily AI generated podcast of the last 24hours of posts.
Operationally this week nothing overly of note.
In the high-level this week:
Building more resilient CNI: what industry penetration testers told us - UK NCSC details - “when we asked: ‘What can organisations do to make your job harder?’” — Segment your networks and Have logging and monitoring in place”
Cyber Security and Resilience (Network and Information Systems) Bill: factsheets - Department for Science, Innovation and Technology updates - “Minor updates to the factsheets on 'information sharing' and 'incident reporting' for clarity and legal purposes”
Don’t pay the ransom: Warning to organisations to protect themselves from ransomware attacks as more than 320 businesses affected last year - City of London Police details - “Data from Report Fraud reveals that 323 organisations reported a ransomware attack between April 2025 and March 2026. Of the reports received, more than 50 per cent were from Small Medium Enterprises (SMEs) (175 reports). Financial losses totalling around £270,000 were reported, a 50 per cent increase compared to previous year. However, these figures are likely to be much higher, as businesses often underreport financial losses, as admission of ransom payments could be seen as supporting criminal activity or breaching compliance regulations.”
Bank of England and Financial Conduct Authority’s approach to joint regulation of systemic stablecoin issuers - Bank of England and the Financial Conduct Authority publish - “Through a co-ordinated approach and regulatory framework, we aim to provide regulatory clarity and certainty to firms issuing stablecoins in the UK whatever the size, aspirations or business model.”
Sterling-denominated systemic stablecoins: Policy statement and consultation on draft Code of Practice - “Our position on the use of public permissionless ledgers (PPLs) by systemic stablecoin issuers remains unchanged from the November 2025 CP. We remain open to the use of PPLs by systemic stablecoin issuers provided they can meet our expectations and ensure trust and confidence in money. However we remain of the view that it may be challenging for these ledgers to meet our expectations when it comes to accountability, settlement finality and operational resilience, including cyber security.”
New Thinking on UK Cyber Effects: An Edited Collection - RUSI think tank- “This book explores the UK's approach to cyber effects operations, analysing strategic culture and policy in the evolving landscape of modern cyber warfare.”
Communications Security Establishment Canada Annual Report 2025-2026 - Communications Security Establishment Canada details - “In 2025–2026, the Cyber Centre recorded more than 3,200 cyber incidents affecting Government of Canada institutions and critical infrastructure sectors.”
New analysis on the EU’s most threatening criminal networks - European Commission / EuroPol analyses - 1.9% of said networks are apparently involved in cyber attacks today
FCC Aims to Accelerate Secure Submarine Cable Infrastructure Buildout - FCC announces - “Specifically, the rules adopted today presumptively exempt cable applications from the rigorous Team Telecom licensing review when licensees can certify to high security standards that are structured to increase certainty, predictability, and faster timelines for the licensing process. Currently, all submarine cable applications get referred to Team Telecom, an Executive Branch interagency task force that reviews license applications for national security risks. The changes adopted would exempt applications from applicants that have operated cables without incident, can certify to the highest national security standards, and agree to ongoing oversight and monitoring. “
C.I.A. Reorganization Prioritizes Cyberoperations - The New York Times reports - “John Ratcliffe, the C.I.A. director, announced on Tuesday that the agency was reorganizing to ensure that it can adopt technology faster and further develop offensive cyberoperations division.” … “He promised that the agency would use new technology more aggressively and take “smart risks,” even as it prioritized human decision making and oversight of artificial intelligence and other innovations.”
Following user outcry, AMD reinstates memory encryption in consumer CPUs - Ars Technica reports - “The incident, and AMD’s refusal to discuss it, is emblematic of the public relations landscape that has emerged over the past two decades. Once, Big Tech and corporations in general were willing to acknowledge service and product changes to ensure customers had a predictable experience. They also showed a willingness to admit mistakes and to say how they planned to do better. Now, there’s only silence. As the companies’ power and dominance have mushroomed, their sense of accountability has diminished proportionately.”
Cognitive Warfare: The Case for Disaggregation - Myriam Dunn Cavelty and Arthur Laudrain argue - “Cognitive warfare is currently at the volatile beginning of this exact curve. Institutional incentives, ranging from broader mandates to bureaucratic competition for funding, presently reward threat inflation. The task for policymakers is therefore not to deny the underlying risks, but to disaggregate them. The goal of a mature defence strategy must be to replace a singular, dramatic label with a set of narrower problems, clearer causal standards, and appropriate, civilian-led policy toolkits.”
Cybersecurity: Selected Agencies Need to Better Protect Cloud Data - US Government Accountability Office details - “Agencies we reviewed varied in implementing key cloud computing security practices. For example, some agencies didn't fully continuously monitor security controls. Also, some agencies didn't document how to respond to or recover from cybersecurity incidents.”
Reporting on/from China
“Send a USB drive from Japan”: A secret mission to a foreign student; the shadow of the Chinese military looms over past cyberattacks. - Nikkei reports - “USB drives have been repeatedly used as a means of cyberattack. An investigation by the Nikkei Shimbun revealed that the Japan Self-Defense Forces used USB drives infected with a Chinese virus, and USB drives have also been used in past attacks against Japan. There is a possibility that the Chinese military was operating in an organized manner.”
ADS rules in place with key Chinese input - China Daily reports - “As the first global regulation covering the full life cycle of Level 3 and Level 4 automated driving systems, the new rules — known as ADS GTR — were recently adopted by the United Nations Economic Commission for Europe and were jointly led by China, the European Union, the United Kingdom, the United States, Canada and Japan.” - of note is their activity in international standard setting
Geely-Backed Polestar Forced Out of U.S. by Chinese Auto Tech Ban - Caixin Global reports - “Under regulations finalized by the Commerce Department in early 2025, the U.S. will ban vehicles equipped with connected systems or autonomous driving software linked to China or Russia starting in 2027. Automakers caught in the crosshairs must apply for special authorization to remain in the market.”
Robot nation: China’s bid to beat its demographic decline - Financial Times reports - “From Communist Party leaders in Beijing to business owners across China, there is a growing consensus that the country needs to embed “embodied artificial intelligence”, as AI-controlled robots are known, into as many tasks as possible and as soon as possible.”
Lutnick signals possible action on Chinese robots after Commerce review - Politico reports - “Commerce Secretary Howard Lutnick told executives at a closed-door meeting Monday that his department is studying state-subsidized robotics imports and signaled the administration could take strong action once the review is complete, according to three people who attended the meeting and were granted anonymity to discuss it.
Officials increasingly see China’s state-backed robotics industry as a national security threat, fearing subsidized Chinese robots could dominate global markets before U.S. manufacturers have the scale to compete.”
Anyverse Dynamics Raises Over $200 Million as China’s Robotics Funding Boom Accelerates - Caixin Global reports - “The capital injection underscores a funding surge in China’s robotics industry, as startups race to build war chests for compute-intensive AI model training and position robotics as a future pillar industry comparable to electric vehicles.”
AI
Warner Unveils Discussion Draft of Legislation to Create Innovative Market for Secure Artificial Intelligence Agents - U.S. Sen. Mark R. Warner (D-VA) enters - “Specifically, the AI Agent Act would:
Establish rights and responsibilities for guaranteed secure access by AI agents to certain large online platforms.
Create a Federal Trade Commission registry of trusted, secure AI agents – with a regulatory environment swift enough to approve innovative user services or quickly curtail products that violate consumers’ trust.
Require AI agents protect users’ privacy and user data and act transparently in a user’s best interest and in a manner that makes clear to third-party websites and online service providers that an AI agent has valid authorization.
Direct NIST to identify technical standards and open protocols to make online services more accessible to AI agents and to ensure consensus-based standards around critical mechanisms like authentication.
Protect businesses, users, and online providers from AI agent abuse or misuse.”
‘Digital ID cards’: China moves to regulate AI agents with unified identity system - South China Morning Post reports - “China is establishing an identity system for artificial intelligence agents, as part of new national standards released on Friday to regulate the next frontier of autonomous technology. The State Administration for Market Regulation (SAMR) unveiled the standard for “Artificial Intelligence Agent Interconnection”, aiming to establish a “closed-loop system” with a unified identity management framework for all AI agents”
US lawmaker introduces bill to require AI companies to report critical incidents - Reuters reports - “The draft legislation, introduced by U.S. Representative Nathaniel Moran of Texas, would mandate AI companies to report to the U.S. Commerce Department within seven days of discovering dangerous activity, with Commerce required to notify Congress within 48 hours of the most serious incidents.”
EnclaveX: End-to-End Confidential AI with CPU/GPU TEEs - TU Dresden and friends outline - “This paper addresses this gap by presenting an end-to-end workflow that combines CPU and GPU TEEs. We propose mechanisms to ensure confidentiality and integrity at both the VM level (via Intel TDX and AMD SEV-SNP) and the application level, highlighting vulnerabilities such as Kubernetes administrators’ ability to access confidential VM contents. Finally, we evaluate the performance overhead of our system using industry benchmarks, focusing on configurations that integrate Intel TDX with NVIDIA H200 GPUs.”
Patterns for Building Cybersecurity Evals - Eugene Yan, Anthropic outlines - “Here, we discuss some benchmarks that measure this, from capture-the-flag exercises to data exfiltration on a 50-host network.” - these small scale non-representative of small, medium or large operational environments need to come with various extrapolation caveats.
Direct Causation in International Humanitarian Law and the Challenge of AI-Mediated Civilian Cyber Operations - The University of Tokyo and friends outline - “International humanitarian law protects civilians from direct attack unless and for such time as they take direct part in hostilities, with the ICRC’s 2009 Interpretive Guidance operationalising this rule through a three-criterion cumulative test. This paper argues that AI-mediated civilian cyber operations challenge the direct causation element of this test in a structurally specific way: when a civilian deploys an autonomous multi-agent cyber system of the kind recently demonstrated in offensive AI research, the “one causal step” standard fails because harm is produced by systemgenerated decisions made after human disengagement, and the integral-part requirement does not extend because it presupposes downstream human contributors whose conduct can be independently classified”
What’s In America’s Code? - There are major risks with allowing Chinese LLMs to code for U.S. applications - Booze Allen evaluates - “we put LLMs to the test. In May 2026, Booz Allen used its AI-native test platform to evaluate five frontier AI models head-to-head: four Chinese models commonly used by U.S. developers and one American model. We explored three main questions:
Do Chinese models generate more vulnerable code based on who is asking?
Do Chinese models refuse to engage with political topics that are sensitive in China?
Does the model’s country of origin affect code quality and content behavior?”
Internal Safety Collapse in Frontier Large Language Models - Various researchers present - “This work identifies a critical failure mode in frontier large language models (LLMs), which we term Internal Safety Collapse (ISC): under certain task conditions, models enter a state in which they continuously generate large volumes of harmful content while executing otherwise benign tasks.”
FAI Launches Frontier Legal Defense Program - The Foundation for American Innovation announces - “Frontier Legal Defense will be a rapid-response legal team that combats the concentration of power, incumbent rent-seeking, and government overreach in AI that threaten American progress, prosperity, and freedoms. It will conduct the legal advocacy, public interest litigation, and education necessary to counter these many threats.”
China’s Zhipu AI sparks new ‘DeepSeek moment’ with cost-effective coding model - South China Morning Post reports - “Matt Velloso, a former vice-president at Meta Platforms and Google DeepMind, said on X last week that he had been using GLM-5.2 “all day” and found it to be the “first open model that passes the bar as a daily driver”.”
Chinese physical AI start-up proposes new paradigm that bypasses OpenAI, Meta road maps - South China Morning Post reports - “The start-up, founded by former Nvidia senior manager Zhang Lihua, said the model “represents a new paradigm” that could effectively address issues commonly faced by currently available world models, such as “physical illusions, reasoning failures, and breakdowns in non-standard scenarios”.”
Cyber proliferation
Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus - Citizen Lab discloses - “We found that former Member of the European Parliament Stelios Kouloglou was hacked with Pegasus spyware while serving on the PEGA committee, which investigated Pegasus and other spyware abuses in Europe. Through forensic analysis of his device, we found that the attackers could have had access to confidential documents and committee deliberations.”
EU Politicians Investigated Pegasus Spyware. Then It Ended Up on One of Their Phones - WIRED reports - “He says that when he recently found out his device had been compromised by the powerful spyware, he was shocked and then angry. “Me being a member of the Pegasus Committee investigating Pegasus and at the same time being hacked by Pegasus,” he says, “it was something really too reckless.”
Bounty Hunting
Alleged Member of Criminal Cyber Hacking Group “Scattered Spider” Arrested in Finland and Extradited to the United States - US Department of Justice announces - “A criminal complaint unsealed Tuesday charges Peter Stokes, 19, a dual citizen of the United States and Estonia, with conspiracy, computer intrusion, and fraud. Stokes was arrested by Finnish authorities in April pursuant to an Interpol Red Notice and extradited to the United States last week. He made an initial appearance on Tuesday in federal court in Chicago and was ordered to remain in law enforcement custody.”
How Greek electricity theft ring caused more than €9m in losses through tampered meters - Πρώτο Θέμα reports - “In EDMIATLAS-type digital meters, the method was more technically advanced. Police said the group used illegal firmware installed in the body of the meter through a special optical probe. This gave them unauthorised access to the meter’s software and to HEDNO’s telemetry information system, through which electricity consumption data is transmitted online.”
FBI Seizes NetNut Proxy Platform, Popa Botnet - KrebsOnSecurity reports - “Earlier today, NetNut’s homepage was replaced with a seizure notice from the FBI and the Internal Revenue Service Criminal Investigation division. The seizure notice thanked Google, Lumen, Shadowserver and other industry partners for their help in dismantling hundreds of domains tied to the Popa botnet, which experts say has long been synonymous with NetNut’s residential proxy infrastructure.”
Market Incentives
Startup sues Palo Alto Networks’ Koi Security, saying an AI-hallucinated report falsely linked it to Chinese espionage - The Register reports - “MeetingTV has sued Palo Alto Networks after its newly acquired Koi Security threat-intelligence biz published a blog that linked the video conferencing and webinar startup to a Chinese corporate espionage operation. The legal complaint filed against Koi Security, its researchers, and Palo Alto Networks alleges that Koi used an LLM to generate the threat report, the AI system hallucinated findings about MeetingTV, and the security shop then published those as facts in a December 30 blog.”
US Cyber Insurance Market Sees Flat Premium, More Third-Party Claims Hit Loss Ratio - Insurance Journal reports - “The U.S. cyber insurance market may be facing a time of transition as certain signs point to eventual adverse development. According to AM Best, the market’s loss ratio in 2025 increased for the second straight year to 53—the first time over 50 since the ransomware spike seen during the COVID pandemic. In the meantime, third-party claims are rising and total premium was basically flat after considering that a perceived increase in 2025 was caused by insurer Beazley’s move of a block of business from an offshore entity to the U.S.”
No reflections this week.
Not getting this via email? Subscribe:
Think someone else would benefit? Share:
All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.
Have a lovely Saturday…
Ollie
Cyber threat intelligence
Who is doing what to whom and how allegedly.
Reporting on Russia
Since the beginning of the full-scale war, the SBU has neutralized over 16 thousand Russian cyberattacks and cyberincidents
Cybersecurity Department (DCIB) of the SBU, Ukraine discloses the scale of alleged Russian activity since the war began.
The attackers launched an attack on the information and communication systems of this TV channel with a phishing campaign and simultaneously tried to penetrate the adjacent infrastructure. SBU specialists detected the intrusion in a timely manner and prevented the enemy from achieving its ultimate goal - gaining control over a resource for publishing propaganda content on behalf of Ukrainian media," the head of the SBU's State Committee for Information and Communication Affairs reported.
Analysis of APT-C-20’s covert attack activities using techniques such as explorer hijacking and LSB steganography
360 Advanced Threat Research Institute in China details an alleged Russian capability which will be of interest given various considerations. Ensuring detection coverage is recommended.
[We] discovered that this group uses decoy documents carrying malicious macros as the initial carrier. After the macro code is executed, it parses and releases malicious components from within the document. Subsequently, it uses COM hijacking to establish a user-level persistence mechanism and triggers the loading of a malicious DLL by using the process of initializing COM objects through the file explorer. The loaded core module further extracts and executes shellcode from steganized image resources, ultimately building a stealthy control framework based on the legitimate cloud storage platform Filen.io in memory, achieving fileless residency and remote control capabilities.
https://mp.weixin.qq.com/s/TDb_UzNfebMzMxh_bQdMvA
Reporting on China
ToddyCat: your hidden email assistant
Andrey Gunkin details alleged Chinese capability which shows a degree of tenacity in order to gain and sustain access to cloud based e-mail.
The attackers continued their search for ways to bypass security solutions and developed a new tool to gain access to a victim’s cloud account via the Google API. Armed with this tool, the group automated all stages of the attack and managed to remain undetected by monitoring systems.
The methods used in that campaign indicated that ToddyCat was attempting to access corporate correspondence while evading monitoring tools. However, all of the group’s methods we described previously are effectively detected by EPP and EDR solutions.
https://securelist.com/toddycat-apt-umbrij-tool-and-oauth/120251/
Mustang Panda targets India’s government and energy sectors with ZOHOMURK and MINIRECON
Santiago Pontiroli and Subhajeet Singha detail an alleged Chinese campaign which highlight both the victimology as well as capability. The prevalence of DLL side loading in the report suggests there is value from focusing on detection of it.
{We have] been tracking two concurrent campaigns orchestrated by Mustang Panda targeting Indian government entities, delivering new malware implants and abusing Zoho WorkDrive, a legitimate cloud storage platform commonly used in the Indian government sector.
The two identified campaigns target India’s hydropower sector and government entities engaged in cooperation agreements (MOUs) with Taiwanese government institutions, leveraging a newly discovered malware toolkit comprising SHARDLOADER, MINIRECON and ZOHOMURK.
SHARDLOADER variants demonstrate moderate sophistication, leveraging persistence and DLL sideloading to deploy two newly identified implants: ZOHOMURK and MINIRECON.
ZOHOMURK is a newly identified implant that leverages Zoho WorkDrive for command-and-control, data exfiltration and remote task execution.
https://www.acronis.com/en/tru/posts/mustang-panda-targets-indias-government-and-energy-sectors/
Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India/MoF Tax Infrastructure via Multi-Stage DcRAT Deployment
Dixit Panchal details an alleged Chinese campaign which has a very specific focus. The specific tradecraft however is rudimentary.
As part of our latest investigation, we uncovered a campaign that demonstrates operational and technical similarities to a China-nexus threat cluster. Further analysis revealed overlapping TTPs with a prominent and highly active threat actor known for conducting cyber-espionage operations against Asian countries through the deployment of RAT-based malware.
Geographic Focus: India (Pan-India taxpayer base)
Corporate Companies & Businesses.
Individual Taxpayers.
Tax Professionals & CAs.
Government Contractors.
Tax Consultants & Filing Agents.
Corporate Finance & Accounts Teams.
Anatomy of a WHQL-Signed Windows Filtering Platform (WFP) Kernel-Resident Network Backdoor
Pierre-Henri Pezier details a malicious driver which someone, potentially in China, managed to get signed…
wskmon.sysis a 64-bit Windows kernel-mode driver that acts as a fully-featured remote access backdoor. Unlike conventional rootkits, it requires no IOCTL interface, no user-mode agent, and no injected DLL. The entire attack surface is a single.sysfile that registers a Windows Filtering Platform (WFP) stream callout to intercept inbound TCP traffic.Commands arrive encrypted over the network, are authenticated with HMAC-SHA256, and executed entirely within the kernel. The driver was first submitted to VirusTotal on 2026-06-15 03:55:33 UTC from China. Its Authenticode certificate carries the subject 深圳市奥联信息安全技术有限公司 (Shenzhen Aolian Information Security Technology Co., Ltd.) — allowing the driver to load on systems that trust Microsoft’s driver-signing ecosystem.
Reporting on North Korea
Lazarus-Linked npm Malware Masquerades as Rollup Polyfills
Yair Benamou details an alleged North Korean operation which uses look alike packages. Unclear how effective it was in practice.
This campaign is effective because each layer appears ordinary when viewed on its own. The entry package looks like Rollup polyfill infrastructure. The second-stage package looks like an SVG utility. The JSONKeeper response appears to be structured data. Only after following the full chain does the real behavior become clear: remote access, browser and wallet theft, file collection, and clipboard monitoring.
Lookalike build dependencies deserve careful review even when the name is not an obvious typo. A copied README, a trusted repository link, and functional-looking package code can be enough to hide a serious compromise.
https://research.jfrog.com/post/rollup-polyfill-masquerading/
PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems
Karlo Zanki details an alleged North Korean campaign which shows the scale of the operations and their persistence.
Our latest findings show that the campaign has expanded beyond npm into additional open source ecosystems, with 162 malicious release artifacts identified across 108 unique packages, including compromise traces in 80 Go modules, 10 Packagist packages, and one Chrome extension. The campaign remains active, and new malicious packages are likely to continue appearing as threat actors compromise maintainer accounts, modify legitimate repositories, and publish infected package versions where they retain or obtain registry access.
https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands
Reporting on Iran
Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool
Insikt Group® details an alleged Iranian operation which relies on social engineering for initial access.
It is highly likely that TAG-182 is targeting Iranians living inside and outside the country using different lures, including free download tools and fake VPN applications. The group’s operations are highly likely active across social media platforms like Instagram.
TAG-182 is highly likely a component of Iran’s broader surveillance ecosystem, using MarkiRAT malware distributed through fake Android applications masquerading as legitimate services such as VPNs and media tools to collect intelligence from Iranian targets.
The MarkiRAT sample identified during this research shares notable tradecraft overlaps with historical variants, including the use of the Background Intelligent Transfer Service (BITS), suggesting a credible relationship between TAG-182 and activity previously attributed to Ferocious Kitten. However, while these similarities support an operational connection, additional evidence is necessary to confidently assess that the two clusters are organizationally linked.
https://www.recordedfuture.com/research/nexus-tag182-disseminates-markirat
Reporting on Other Actors
Boss Scam: Don’t Trust Every “Urgent” Message from Your Boss!
Azhagan KMS details an interesting campaign which monitors for WhatsApp web sessions in order to obtain session details for further social engineering.
It runs in the background till it finds an active WhatsApp Web session in Chromium-based browsers such as Google Chrome and Microsoft Edge. Once an authenticated WhatsApp Web session is identified, it collects browser session artifacts, including authentication tokens, cookies, encryption material, and other browser data required to potentially restore or hijack an authenticated WhatsApp Web session.
https://labs.k7computing.com/index.php/boss-scam-dont-trust-every-urgent-message-from-your-boss/
Inside StegoAd
Microsoft Edge Extensions Security Team details a long running and scaled campaign which is technically interesting. The criminal driver is of note given the technical investment and efforts gone to in order to protect.
At its core, StegoAd is a monetization and credential theft platform. Every technique, including steganography, polymorphism, and time-delayed activation protects a multi-layered revenue and data theft engine:
Steganography, polymorphism, RCE backdoors, and 119 malicious browser extensions: dissecting an ever-evolving campaign
119 browser extensions impersonating popular tools — ad blockers, VPNs, translators, and video downloaders
~2.6 million users impacted across 2 years of steganographic campaign (March 2024 – April 2026); threat actor active since at least 2021
Steganographic payload delivery via PNG, WebP, and WOFF2 font files — a first for browser extension threats at this scale
Remote Code Execution (RCE) backdoor where the C2 server delivers arbitrary JavaScript executed via setTimeout(), enabling full browser-context RAT capability
https://microsoftedge.github.io/edgevr/assets/files/stego_ad/Microsoft_Edge_Security_StegoAd.pdf
ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
Michael Kelley provides further details around this campaign including the initial lure. Of note is the fact that SPF, DKIM and DMARC all failed their checks.
[We] identified a fully-featured phishing-as-a-service (PhaaS) operator panel, branded “ARToken,” that shares infrastructure, API contracts, and operational patterns with the EvilTokens platform documented by Sekoia and Microsoft in early 2026.
The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token (PRT) persistence, email access, business email compromise (BEC) operations, and SharePoint exfiltration — all accessible to operators through a React-based dashboard.
Analysis of the platform’s publicly served JavaScript bundle reveals the complete post-compromise toolkit available to affiliates, including capabilities not previously detailed in public reporting on EvilTokens.
The phishing kit deploys a seven-layer anti-analysis system combining client-side behavioral verification with XOR-encrypted payloads, a more sophisticated evasion approach than the server-side X-Antibot-Token mechanism documented in prior EvilTokens research.
Most public reporting on EvilTokens covers the panel and the kit. What it has not shown is how an ARToken lure actually reaches an inbox. Talos recovered two near-identical messages, sent roughly four minutes apart on April 20, 2026, that initiate the chain. The tradecraft is targeted, not spray-and-pray.
…
All three checks fail: SPF, DKIM (body-hash mismatch), and DMARC (compauth=none reason=405). The display identity is not authenticated from the sending path.
JADEPUFFER: Agentic ransomware for automated database extortion
Michael Clark details an operation which shows agentic use - note this is a productivity gain and not a world end moment.
JADEPUFFER's own payloads were self-narrating. They contained natural language reasoning, target prioritization, and the kind of detailed annotations that human operators don’t often write but LLM-generated code produces reflexively. The operation also adapted in real time, retrying failed steps within refined parameters. In one sequence, it went from a failed login to a working fix in 31 seconds.
…
JADEPUFFER’s operation unfolded across two distinct targets: the internet-facing Langflow instance that provided initial access, and a separate production database server, which was JADEPUFFER’s true objective. The machine compromised during initial access was used in the compromise of the final target. All payloads were delivered as Base64-encoded Python through the Langflow RCE endpoint.
https://webflow.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion
A Djinn in the Machine: TaskWeaver’s Node.js Intrusion Chain
Nevan Beal and Sam Decker detail a campaign which is noteworthy for the theft of AI assistant authentication tokens.
The intrusion began with confirmed exploitation of CVE-2026-48558, allowing the attacker to bypass SimpleHelp OIDC authentication and obtain a technician session.
TaskWeaver is a heavily obfuscated Node.js loader, delivered as jquery.js and executed through node.exe, that implements an encrypted, reusable payload delivery channel rather than a fixed set of post exploitation commands.
The observed second stage payload, Djinn Stealer, targets Windows, macOS, and Linux systems.
Djinn Stealer collects credentials associated with cloud platforms, source control, package registries, infrastructure tooling, AI development assistants, browsers, SSH, and cryptocurrency wallets.
Stolen AI assistant tokens can hand attackers everything the AI was trusted to access, including repositories, databases, and cloud accounts, extending the breach well beyond the AI itself.
The attacker repurposed legitimate RMM capabilities to transfer files and remotely execute malware across managed systems.
https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/
Software Supply Chain Incursions
A reminder we issued guidance a number of weeks ago in Software supply chain attacks: check your dependencies for software developers
From CI/CD to Cloud Data: How Shai Hulud Persistence Leads to Redshift Breach
AI Security Incident Case: Miasma Worm Attacked Microsoft GitHub
PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems
Dropping Malware through Dependencies in VS Code: Inside the jsononifier npm
Discovery
How we find and understand the latent compromises within our environments.
The Blind Spot in the Watchtower: Detections for When Someone Attacks Your Sentinel
Rohit Ashokgowd details how you do protective monitoring of Sentinel itself which all defensive teams should read. Would you know if your Sentinel environment had been degraded?
For Sentinel to watch itself, it needs a record of the changes made to it. That record lives in three places, and each check below pulls from one of them.
AzureActivity is the broad log of who did what. When someone creates, changes or deletes something in Sentinel like a rule, a feed or a setting-it shows up here with the user name and IP address. This is the main sourcen and it comes from the Azure Activity connector which is free.
SentinelAudit is the detailed change log for detection rules. It shows who changed a rule and what it looked like before and after. It only works after you turn on Sentinel’s health and audit feature, which is also free.
SentinelHealth shows whether your rules are actually running. It also makes it clear when a rule is disabled and did not run. It uses the same health and audit feature switch.
Knossos: Procedurally Generated Decoy Environments
Mario Bartolome shows how to build practical decoy environments which has the opportunity to impose cost on adveraries.
How we built a procedural engine that learns your real cloud environment, generates decoy environments indistinguishable from production, and converts every attacker interaction into signal.
https://www.praetorian.com/blog/knossos-decoy-environments/
Detecting Agentic Threats in Claude: Writing Rules on the Execution Layer
Andrew Byford contributes another material uplift with this release on how to do practical protective monitoring of an AI environment.
In this post I look at the main threats from agentic platforms, and how we can use the execution-layer telemetry we’re getting from Claude to write detections for them.
https://www.papermtn.co.uk/detecting-agentic-threats-in-claude-writing-rules-on-the-execution-layer/
ARGUS: Production-Scale Tracing and Performance Diagnosis for over 10,000-GPU Clusters
Tencent from China shows how they are applying observability to their GPU stack. Including as there are potential read across to defensive use cases here.
We propose ARGUS, a low-overhead, fine-grained, always-on tracing and real-time analysis system for training workloads in 10,000+ GPU-scale production clusters. ARGUS decomposes observation along the training call hierarchy into CPU call stacks, framework semantics, and GPU kernel execution, with always-on collection under a combined overhead of less than 2%. It builds a unified data pipeline and compresses raw kernel events by approximately 3,700x from 10 MB to 2.7 KB per rank per step. Its progressive diagnosis framework automatically isolates anomalous windows, straggler ranks, and degraded kernels through iteration-time, phase-level, and kernel-level analysis. Deployed for over six months on a 10,000+ GPU production cluster, ARGUS has supported continuous fail-slow detection and performance optimization. Our case studies further demonstrate its effectiveness across representative anomalies, including compute stragglers, link degradation, pipeline-bubble amplification, FlashAttention JIT stalls, and compute stragglers masked by communication symptoms.
https://arxiv.org/abs/2606.20374
Claude Code Covert Telemetry Behavior Analysis
Andy Wang details…
Today I came across an article saying that Claude Code detects whether a user is using a proxy and their timezone, then secretly reports this information by modifying a few characters in the system prompt. The original post was on Reddit, titled “Anthropic embedded spyware in Claude Code — and attempted to hide it from you.” Below is my verification process. My environment is Windows 11, and my Claude Code version is 2.1.196, installed via npm.
https://mp.weixin.qq.com/s/6F4JPNaS0KcrjUVxmXP7Jw
Automatic Security Log Analysis Report Based on Large Model
The Cave of the Recluse in the Clouds from China walks through how they achieved the below hinting a the future way of working.
The core objective is to use the semantic analysis and professional judgment capabilities of large models to automatically generate standardized professional security analysis reports for department heads, replacing the repetitive work of manually sorting through logs line by line and manually summarizing and writing reports.
https://mp.weixin.qq.com/s/u6cSpn2c9kMIE3qQRnHFGA
Defence
How we proactively defend our environments.
Agentic SOC Practice: Flocks
Rosey from China walks through Flocks and again hints at a future way of working.
The most crucial aspect of Flocks is that it doesn't just provide a single agent; instead, it integrates multi-agent capabilities and a workflow execution engine onto the same platform. Agents can invoke workflows for execution, and workflows can also invoke agents, allowing for flexible orchestration and use.
..
In summary, Flocks provides not a single-point agent for the view that “AI Agent should first check evidence, supplement context, eliminate noise, and narrow the hypothesis space”, but a platform-based answer that can connect alarm access, process orchestration, tool invocation and agent analysis.
https://mp.weixin.qq.com/s/doB_kc72DzjRqfZUBtOckA
https://github.com/AgentFlocks/flocks
Mark-of-the-Web: the rules changed, the tools didn’t
Maxim Suhanov walks through the changes but also highlights were some gaps may emerge in third party software on this important taint mechanism.
Microsoft changed the under-the-hood rules of the MOTW propagation. These changes were implemented in their own software (like Windows Explorer and its supporting libraries), but third-party tools (like WinRAR) don’t follow the new rule.
…
The old rule was: simply check if the archive file has the Zone.Identifier stream set. The new rule extends: if it doesn’t, go to the container file and check if it has the Zone.Identifier stream set.
..
If yes, feel free to get a bunch of CVE IDs for software that doesn’t follow it. Because most third-party tools ignore fifty percent (1 out of 2 to be precise) of the current MOTW checks.
https://dfir.ru/2026/06/29/mark-of-the-web-the-rules-changed-the-tools-didnt/
Control who and what triggers GitHub Actions workflows
Github details some defensive improvements which teams will want to be aware of.
Workflow execution protections are now in public preview for GitHub Enterprise, organizations, and repositories. This new capability lets enterprise administrators define an allow list that controls who can trigger GitHub Actions workflows and which events are permitted to run them, giving you predictable, secure workflow execution.
Previously, a workflow ran based on the workflow file in the commit that triggered it. An attacker with repository access could modify that file to run malicious code. Workflow execution protections close that gap. Administrators define the rules and GitHub Actions evaluates them before a run, so an unauthorized actor or event can never trigger an unwanted workflow execution.
https://github.blog/changelog/2026-06-18-control-who-and-what-triggers-github-actions-workflows/
Page-Cache LPE Containment Kit
Douglas Mun shows how to defend against these vulnerabilities
Educational, defensive kit for two Linux page-cache-corruption LPEs (DirtyClone CVE-2026-43503, pedit COW CVE-2026-46331): hardening, detection, verification, seccomp + validation harness.
Both exploits depend on the same two structural conditions. Remove either and the documented chain breaks:
A path to
CAP_NET_ADMIN— both chains obtain it as a namespace-local capability via unprivileged user namespaces (unshare(CLONE_NEWUSER|CLONE_NEWNET)). NoCAP_NET_ADMIN, no XFRM/IPsec setup (DirtyClone) and notcaction config (pedit COW).A reachable vulnerable module surface —
act_pedit(pedit COW);esp4/esp6/rxrpcas the in-place-crypto write sinks andxt_TEE/nf_dup_ipv4/6as the clone trigger (DirtyClone).
https://github.com/douglasmun/pagecache-lpe-containment-kit
Incident Writeups & Disclosures
How they got in and what they did.
From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks
Arctic Wolf Labs walks through the end to end by this criminal activity.
Since the start of 2026, [we have] investigated Anubis ransomware intrusions involving both valid VPN credential use and exploitation of CitrixBleed 2 (CVE-2025-5777), expanding known initial access tradecraft associated with this ransomware brand.
Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remote Management and Monitoring (RMM) tooling, credential access, and hands-on-keyboard procedures used for lateral movement.
Anubis affiliates repeatedly abused legitimate remote access and administration tools, including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment, to blend in with normal IT activity while maintaining control of victim systems.
Multiple intrusions showed threat actors targeting high-value infrastructure such as Microsoft Remote Desktop Services servers, domain controllers, hypervisors, backup-adjacent systems, and Network-Attached Storage (NAS) devices, increasing operational impact and recovery complexity.
In some intrusions, threat actors attempted to establish alternate outbound access paths using tools such as cloudflared, authenticated proxies, and SSH-based SOCKS tunneling
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
The DFIR Report details a historic case which is useful as it sheds light on the end to end. Note the search-engine-optimisation as the initial access vector.
In July 2025, BumbleBee malware was deployed via SEO poisoning through a trojanized installer for ManageEngine OpManager.
Following initial access, BumbleBee dropped an AdaptixC2 beacon to facilitate further intrusion activities, allowing the threat actor to pivot to a domain controller and dump the NTDS.dit.
The threat actor returned the following day and established an SSH proxy, enabling lateral movement across the network and data exfiltration via FileZilla and SFTP to an external server.
The threat actor concluded the intrusion by deploying Akira ransomware across the root domain and returned two days later to encrypt a child domain.
Vulnerability
Our attack surface.
Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More)
Asim Viladi Oglu Manizada shows how to apply LLMs to real-world vulnerability discovery and the value of the harness..
the grossly overengineered, self-orchestrating team of vulnerability-hunting agents detailed below has discovered 20+ CVEs over the past few months, including CVE-2026-31432 and CVE-2026-31433: two remote, unauthenticated OOB writes in the Linux kernel’s ksmbd. Read on for the details of the setup that achieved this, including – yes! – getting LLMs drunk.
https://heyitsas.im/posts/drinking-llms/
Bad Epoll: The bug missed by Mythos
Jaeyoung Chung walks through the vulnerability but also an interesting observation around the potential miss by AI.
Bad Epoll (CVE-2026-46242) is a race-condition use-after-free in the Linux kernel's
epollsubsystem. This bug lets an unprivileged process become root, not only on Linux desktops and servers but also on Android devices.…
A single commit in 2023 introduced two separate race conditions into the epoll code, only about 2,500 lines in all. Both turned out to be critical bugs that can lead to privilege escalation.
…
The first was found by Anthropic's Mythos and reported as CVE-2026-43074. That result is impressive on its own, because kernel race bugs are known to be hard to find. It showed a frontier AI model's ability to find race bugs. An independent researcher later submitted a 1-day exploit for it to kernelCTF.
The other race is Bad Epoll, which Mythos missed. Given that Mythos found the first bug in this small epoll code path, it likely examined the same area with meaningful depth. We cannot know exactly why it missed Bad Epoll, but two factors likely made it hard to find.
https://github.com/J-jaeyoung/bad-epoll
Clone This Repo and I Own Your Machine
Andre Hall & Miller Engelbrecht walks through an attack chain of a contemporary AI era.
Indirect prompt injection in agentic coding tools can lead to full system compromise because authorized tools allow LLMs to run shell commands, access files, and make network calls without clear user visibility.
An attacker can gain code execution using a completely normal looking repository by chaining trusted setup instructions, routine error handling, and automated agent behavior.
The malicious payload does not exist in the repository at all and is instead fetched at runtime from a DNS TXT record, making it invisible to code review, static scanners, and even the agent itself.
The result is a reverse shell running as the developer’s own user, exposing credentials, API keys, and allowing persistence, all triggered by the agent attempting to fix a harmless looking setup error.
https://0din.ai/blog/clone-this-repo-and-i-own-your-machine
A Longitudinal Study of Android Apps Signing Key Protection
Mark Huasong Meng, Qing Zhang, Weirao Lu and Chunyang Chen ..
Our analysis identifies 5,673 compromised keystores on GitHub and 26 unique certificates linked to 278 real-world apps. These include 26 third-party apps in public app stores and 252 preinstalled apps from seven manufacturers, collectively affecting over 10 billion users. We demonstrate the practical exploitability of these leaks through a proof-of-concept app replacement attack and identify spillover risks in non-smartphone platforms, including a popular automotive head-unit platform installed in over 1,100 vehicle models. Our results reveal that signing-key mismanagement is a systemic risk, underscoring the need for a more rigorous key-management support in Android release engineering and distribution infrastructures.
https://arxiv.org/abs/2606.21487
IPV6_FRAG_ESCAPE
sgkdev drops this vulnerability and highlights that all patched vulns are increasingly shallow in shipped code/binaries etc.
A reliable unprivileged container / jail escape proof of concept for CentOS / RHEL 10.
It rides a now fixed IPv6 fragmentation bug in
__ip6_append_data()(closed upstream by38becddc, no CVE), an in-slab linear overflow into theskb_shared_infoat the tail of a packet’s own head object. This README documents the exploitation chain only. It does not cover the trigger.
https://github.com/sgkdev/ipv6_frag_escape
Squeezing Juicy Variant Bugs Out of Modern Browsers
Han Zheng, Flavio Toffalini, Qiang Liu and Mathias Payer show that vendors are yet to be comprehensive in their variant discovery.
Inspired by informal variant analysis developed by the hacker community, we create GRAPE, a structured approach that supports analysts in writing rules to detect bugs. By focusing on code patterns, GRAPE scales effectively to large-scale code projects. Moreover, our novel variant bug model enables analysis of cross-context interactions and exploitability verification using existing bug reports, eliminating the need for cross-domain dependencies. GRAPE represents the first systematic approach to variant analysis, introducing principles for variant pattern development.
We implement a prototype of GRAPE, which scans the entire Chromium code base in only 12 minutes. GRAPE discovered 24 new bugs, with four assigned CVEs and 17,500 USD in rewards from Chrome’s Vulnerability Rewards Program. These discoveries impact modern web browser and securitycritical complex software like OpenSSL. Beyond browsers, GRAPE uncovered three logic bugs in VSCode and Azure Data Studio, one of which received a CVE from Microsoft
https://kdsjzh.github.io/assets/pdf/26WOOT.pdf
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)
Aliz Hammond detail this vulnerability which will reveal a few bytes of memory in practice.
in contrast to the original CVE-2026-3055, in which kilobytes of binary data can be leaked, this overread will terminate the out-of-bounds read when various control characters are read, such as NULL (or even
>).
https://github.com/watchtowrlabs/watchTowr-vs-Netscaler-CVE-2026-8451
Offense
Attack capability, techniques and trade-craft.
Accelerating EDR Evasion with LLM-Driven Analysis
Adam Chester explores the utility in AI in supporting EDR evasion activities. This type of disclosure, one would expect, lead in the medium term to less EDR fragility.
As we are now learning, this is going to lead to a wave of endpoint security rule dumps, evasions integrated into offsec tooling, and honestly a bit of pain for defenders who rely on endpoint security products as their first line of defence.
LLM-assisted evasion is no longer theoretical. And it is clear that endpoint security vendors are going to have to consider their strategy moving forwards.
But before you throw your hands in the air and give up your job to become a farmer, remember that EDR’s are still a much needed part of any organisations security strategy. And while local rules and behavioral detections will be less effective in the short-term, it is also worth remembering that only a fraction of an EDR’s benefit comes from on-host detections alone, with telemetry constantly being surfaced from the host and analysed remotely.
https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/
KHAØS C2
28Zaaky drops this framework which teams will want to ensure coverage of..
KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.
On the network side there are five channels: Microsoft Teams, GitHub Gist, DNS-over-HTTPS, HTTP/S, and SMB named pipe. The idea is that at least one of them already looks like normal traffic in whatever environment you're working in.
https://github.com/28Zaaky/khaos-c2
SpotifyC2 — Cloud-Based Command Channel Research
Nirvana inspires around novelty here..
Instead of communicating with a traditional server, the client periodically polls a Spotify playlist and interprets the playlist title as a command. After executing the command locally, the resulting output is delivered to a configured Telegram Bot.
https://github.com/NirvanaOn/SpotifyC2/
CredSpy
Keanu Nys identifies a leak which will be interesting to watch Microsoft respond it.
Enumerate Microsoft Entra ID authentication methods for email addresses using the public
GetCredentialTypeAPI. This is the same endpoint the Microsoft login page uses when you enter a username. In contrast to most tools using the GetCredentialType method, CredSpy also shows the authentication methods supported for existing accounts.Useful for security assessments: user enumeration, preferred auth method discovery, and identifying accounts with password, Remote NGC (e.g. Passwordless Push Notification), FIDO2/passkeys, or certificate auth.
https://github.com/RedByte1337/CredSpy
GadgetSniper
Zaki Pedio releases this which will hopefully inspire EDR vendors to consider how they might detect the use of these gadgets.
A precision tool for hunting call-stack spoofing gadgets inside 64-bit Windows DLLs.
GadgetSniper scans PE32+ binaries for instruction sequences of the form
call X ; jmp qword ptr [non-volatile-reg], the exact primitive needed to build believable spoofed call stacks. Rather than grepping raw byte patterns and hoping for the best, it leans on Iced (a production-grade x86/x64 disassembler/decoder) to validate every candidate instruction, which eliminates the false positives that come with simple signature matching against variable-length x64 encodings.
https://github.com/ZakiPedio/GadgetSnipe
Hollow
Abderrahmen Dellaa provides this capability which we should expect deployment of by adversaries and thus ensure coverage.
hollow is a shellcode loader generator. You give it a raw shellcode binary and a profile, and it spits out a compiled Windows PE loader with your shellcode encrypted inside.
hollow follows a three-step pipeline: encrypt, substitute, compile.
Your shellcode is encrypted with AES-256-CBC using a randomly generated key and IV on every run. Both are embedded inside the output binary. The chosen C template then has its placeholders replaced with the encrypted shellcode, the key, and the IV, and the result is compiled into a stripped, statically linked PE by MinGW.
At runtime, the loader decrypts the shellcode using Windows BCrypt and executes it using whichever injection technique the template implements.
https://github.com/Chaelsoo/Hollow
Crystal Palace Evasion kit for Sliver
Simone Licitra provides this evasion kit. Noting that Sliver has been used by some state adversaries it will be interesting to see if they adopt this. Either way teams should ensure detection coverage.
Replaces Sliver’s default reflective loader and post-ex execution path with Crystal Palace (Raphael Mudge, BSD). The result is a position-independent code (PICO) blob that bundles:
ror13 hash-based API resolution (no plain
LoadLibrary/GetProcAddress)IAT hooks on
VirtualAlloc/VirtualProtect/VirtualFree/LoadLibraryADraugr call stack spoofing during callbacks
XOR sleep mask over the embedded DLL
libtcg-based runtime obfuscation
The Sliver implant DLL (or any post-ex DLL) is XOR-masked inside the PICO and only unmasked in memory at execution time.
https://github.com/licitrasimone/CrystalSliver
Terraforming Mythic
Qmadev released this terraform which is likely worth studying for a detection strategy.
This project allows operators to set up multiple Mythic C2 servers in Azure. Optionally, Azure CDN redirectors can be created as well. The idea is that you are able to create multiple “projects” that you can manage from this Terraform code. This way, operators can manage the resources for their infrastructure in a central place, as code.
https://github.com/qmadev/tf-mythic-azure
Exploitation
What is being exploited..
Remote Code Execution Vulnerability in PTC’s Windchill and FlexPLM Solutions
PTC disclose in the wild exploitation including indicators of compromise for these vulenrabilities. On June 25th they said..
Over the last several hours, we've received continued reports of heightened threat activity. We urge you to apply all patches and remediations immediately.
Exploitation of CitrixBleed 2 (CVE-2025-5777) Began Before PoC Was Public
Noah Stone shows that someone knew about this and was making rain with it..
GreyNoise has observed active exploitation attempts against CVE-2025-5777 (CitrixBleed 2), a memory overread vulnerability in Citrix NetScaler. Exploitation began on June 23 — nearly two weeks before a public proof-of-concept (PoC) was released on July 4.
https://www.greynoise.io/blog/exploitation-citrixbleed-2-cve-2025-5777-before-public-poc
Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs
Marcus Hutchins details the bring-your-own-vulnerable-driver exploited by this criminal group.
The Gentlemen are a relatively new ransomware group who first emerged in July of 2025.
In an incident investigated by Expel, the group used a zero-day vulnerability to disable the target’s EDR, preventing it from intervening in their ransomware attack.
The threat actor relies heavily on bring-your-own-vulnerable-driver (BYOVD) style attacks to disable endpoint protection.
Expel’s Threat Intelligence team captured and analyzed both the vulnerable driver and exploit code the threat actor used, which at the time of reporting is a zero-day, and not present in any public vulnerable driver blocklists.
Tooling and Techniques
Low level tooling and techniques for attack and defence researchers
How I broke Rhysida ransomware encryption
Adam Taguirov shows some cryptologic ability with this break..
Rhysida derives every per-file AES key from a PRNG seeded with the encryption timestamp. Recover the timestamp and you regenerate every key. A reverse-engineering walkthrough and a minimal decryptor.
https://sigreturn.com/blog/rhysida-analysis-decryption/
Time Travel Debugging with Codex
Kai Huang extends the ability to TTD to enable further methods of verification.
giving Codex access to Time Travel Debugging (TTD) traces through TTDObjectsPy, so it can query real execution history instead of reasoning only from static structure.
https://specterops.io/blog/2026/06/26/time-travel-debugging-with-codex/
About Hypervisor Cheats, Part 2: EPT/NPT, Split Views, and Second-Stage Fault Evidence
kernullist walks through various underlying page tables used in hypervisors.
Second-stage translation is where hypervisor cheat discussions often become either too vague or too casual. EPT and NPT are page tables below the guest page tables, but the important point is ownership: they decide the final memory view that Windows runs on. This post explains that view through permissions, backing pages, faults, invalidations, and stale translations.
The Current Status and Trends of Software Protection Countermeasures in the AI Era
Vulnerability War walks through the impact on code obfuscation by AI.
The future competition in software protection will not just be about obfuscation strength, but rather the ability to continuously compromise AI's input quality, inference stability, verification loop, and scalability. Software protection that can achieve this will truly be protection for the AI era.
https://mp.weixin.qq.com/s/zG3h0XsaA3e_7J_wV_vb2Q
Footnotes
Some other small (and not so small) bits and bobs which might be of interest.
Annual, quarterly and monthly reports
Nothing overly of note this week, but keep an eye on the Awesome Annual Security Reports 2026 collection and APT report collection
From shadows to screens: digital outreach strategies in intelligence and law enforcement
Reflections on the Evolution of Security Attack and Defense in the AI Era from Huawei
Artificial intelligence
Just a small pitch if you are a big arxiv.org user - out of China there is alphaxiv.org which is an AI powered incarnation / overlay
Fundamental
Applied non-cyber
Autodata: An agentic data scientist to create high quality synthetic data
XtraGPT: Context-Aware and Controllable Academic Paper Revision via Human-AI Collaboration
PaperDebugger: A Plugin-Based Multi-Agent System for In-Editor Academic Writing, Review, and Editing
AgentDoG 1.5: A Lightweight and Scalable Alignment Framework for AI Agent Safety and Security
ARGUS: Production-Scale Tracing and Performance Diagnosis for over 10,000-GPU Clusters
Phantom References: Hallucinated Citations That Survive Peer Review at Top-Tier Conferences
Behind the Refusal: Determining Guardrail Activation via Behavioral Monitoring
Applied cyber specific
From Similarity to Vulnerability: Key Collision Attack on LLM Semantic Caching - updated
Securing AI agents: When AI tools move from reading to acting
VeriChat: An Agentic Conversational AI Assistant for Hardware Security Verification
Detecting the Undetectable: Enhancing Unsupervised time series Anomaly Detection via Active Learning
Securing the AI Agent: A Unified Framework for Multi-Layer Agent Red Teaming
Cloak and Detonate: Scanner Evasion and Dynamic Detection of Agent Skill Malware
Skills Are Not Islands: Measuring Dependency and Risk in Agent Skill Supply Chains
Rise From The Ashes: LLM-based Static Analysis for Deep Learning Framework Bugs
AgentFlow: Building Agent Dependency Graphs for Static Analysis of Agent Programs
Generative AI and Federated Learning for Intrusion Detection Systems: A Survey
The Illusion of Safety: Multi-Tier Verification of AI vs. Human C++ Code
An Empirical Study of Security Calibration in Large Language Models for Code
Security--Fidelity Tradeoffs: The Hidden Cost of Prompt Injection Defense
Forensic Trajectory Signatures for Agent Memory Poisoning Detection
Breaking the Rounding Trap: Securing LLMs against Quantization-Conditioned Backdoors
Books
Nothing overly of note this week
Events
11th IEEE European Symposium on Security and Privacy - Lisbon, July 6 - 10, 2026
Video of the week goes to this presentation from Blackhat Europe 2025 on Understanding Trends & Patterns In Insider Threat: Analysis Of 1,000+ Cases
Finally finally the NCSC’s podcast series.
Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them.
This newsletter is subject to the NCSC website terms and conditions which can be found at https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions and you can find out more about how will treat your personal information in our privacy notice at https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.



