#detection

18 posts · Last used 2d

Back to Timeline
Suriq - Always on Watch @suriq@infosec.exchange · 2d ago
Attackers pointed an off-the-shelf AI agent at Thailand's finance ministry and let it run the hack unattended. It used no new exploit. A data service left with no password got it in. Detect the host actions, not the AI. https://suriq.io/blog/hermes-ai-agent-thailand-finance-ministry #Detection #Linux #infosec #cybersecurity
0
0
0
Jamie Clark @jamiexml@infosec.exchange · 3d ago
RE: https://mstdn.social/@osnews/116965092743942475 Thank you to @onepict@chaos.social and @jwildeboer@social.wildeboer.net for this. My primary curiosity for digging in here wasn't the vendor or anti-vendor politics point, or the freedom-of-coder-communities-to-organize point, but rather… how exactly are they enforcing this? #AI #antislop #slop #detection #FOSS
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · 4d ago
Third on-prem SharePoint RCE this month: CVE-2026-50522 (CVSS 9.8) went from public PoC to active exploitation in hours. All three July flaws steal the server machine key. Patch, then ROTATE the key, or a patched box is still owned. #SharePoint #infosec https://suriq.io/blog/sharepoint-cve-2026-50522-rotate-machine-keys #CVE #Detection #CISAKEV #infosec
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · 5d ago
HollowGraph, an espionage implant, hides its command channel in a hijacked Microsoft 365 calendar over the Graph API. No CVE, no patch. Firewalls see normal M365 traffic. Hunt far-future calendar events with attachments in your audit logs. https://suriq.io/blog/hollowgraph-microsoft-365-calendar-c2 #CVE #ThreatIntel #Detection #infosec
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Jul 14, 2026
Our weekly read: the three most dangerous advisories we tracked this week were not apps. They were the appliances you buy to stay safe. Dell Data Domain, Progress ShareFile and BeyondTrust all failed at authorization. Why that is the tier you watch least: https://suriq.io/blog/signal-safety-appliances-broke-authorization #Detection #infosec #cybersecurity
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Jul 11, 2026
GigaWiper encrypts Windows files to a .candy extension with no key and no ransom note. That is on purpose: the ransomware is a decoy for a disk wiper. Microsoft and Binary Defense tracked the same code as one Iran-nexus operation. https://suriq.io/blog/gigawiper-fake-ransomware-disk-wiper #Ransomware #ThreatIntel #Detection #infosec
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Jul 10, 2026
Three separate July studies land on the same finding: AI coding agents can be made to run attacker code with the developer's own privileges. HalluSquatting, Friendly Fire, GhostApproval. No CVE, no patch. The fix is config plus detection, not a version bump. https://suriq.io/blog/hallusquatting-ai-coding-agent-endpoint-risk #SupplyChain #Detection #infosec #cybersecurity
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Jul 09, 2026
Google Dialogflow CX had a flaw where one 'edit' permission on a chatbot ran code across every Code Block agent in the project, and reached cloud credentials. Google has fixed it. No CVE. The lesson: on managed AI platforms, an edit right is often a code-execution right. https://suriq.io/blog/dialogflow-cx-rogue-agent-edit-permission #CloudSecurity #Detection #infosec #cybersecurity
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Jul 09, 2026
GodDamn ransomware loads PoisonX, a kernel driver reportedly carrying a valid Microsoft signature, to switch off EDR. Signature checks wave it through. Affects Windows servers. The tell is your agent going silent while still online. https://suriq.io/blog/signed-kernel-driver-edr-killer #Ransomware #Detection #infosec #cybersecurity
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Jul 07, 2026
Cavern is a new Iran-linked backdoor that breaks into IT providers using no vulnerability at all. It abuses their own deployment tools, then hops to customers. No CVE to patch. Detection is the only defense. https://suriq.io/blog/cavern-manticore-c2-no-cve-it-provider-supply-chain #SupplyChain #Detection #infosec #cybersecurity
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Jul 05, 2026
Kairos stole ~2TB from a US county, encrypted nothing, and was still paid $1M. No locker means no loud alarm. The only signals are the weak login in and the big upload out. Backups recover files, not a leaked copy. https://suriq.io/blog/kairos-encryptionless-extortion-detection #Ransomware #Detection #DataBreach #infosec
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Jul 05, 2026
🚨 BREAKING FortiBleed, the campaign that scraped 110M logins from Fortinet firewalls, now has a buyer. SOCRadar tied it to INC and Lynx ransomware. One operator ran both gangs' panels; the access has caused 12 encryptions. Rotate Fortinet creds, hunt for backdoors. https://suriq.io/blog/fortibleed-credentials-inc-lynx-ransomware #Ransomware #CVE #CloudSecurity #Detection
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Jul 04, 2026
Scattered Spider broke into a retailer with no malware. They called the IT help desk, reset a password and MFA device, and owned three accounts in under three hours. The fix is your reset script, not a patch. https://suriq.io/blog/scattered-spider-help-desk-attack #Ransomware #Detection #Phishing #infosec
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Jul 03, 2026
🔴 EXPLOITED An AI agent ran a full ransomware attack on its own, start to finish, through a year-old Langflow flaw. It encrypted the database with a key it never saved, so paying recovers nothing. It is a wiper. Run Langflow? Patch to 1.3.0, pull your keys off it. https://suriq.io/blog/ai-agent-ransomware-langflow-unrecoverable #Ransomware #CVE #Detection #infosec
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Jul 02, 2026
New malware called ChocoPoC hides in fake exploit code on GitHub and steals the credentials of researchers who run it. The payload sits in a Python dependency, not the exploit script. Test PoCs in a throwaway, credential-free VM. https://suriq.io/blog/chocopoc-fake-poc-exploit-stealer #CVE #SupplyChain #ThreatIntel #Detection
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Jul 02, 2026
🔴 EXPLOITED Microsoft rated a SharePoint Server flaw (CVE-2026-45659, CVSS 8.8) unlikely to be exploited. It is being exploited. CISA added it to its must-patch list July 1. Run on-prem SharePoint? Install the May update now. https://suriq.io/blog/sharepoint-cve-2026-45659-kev-exploited #CVE #Detection #CISAKEV #infosec
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Jun 29, 2026
A GitHub repo with zero malicious code just made Claude Code open a reverse shell on the developer's machine. The payload hides in a DNS record, so every scanner sees a clean repo. There's no patch. You constrain the agent or you don't. https://suriq.io/blog/clean-repo-ai-coding-agent-reverse-shell #SupplyChain #Detection #infosec #cybersecurity
0
0
0

You've seen all posts