Akamai security researchers have uncovered an interesting attack technique they call “Bring Your Own EDR.”
The research demonstrates how a trusted, privileged EDR component can potentially become an attacker’s tool against the system it was designed to protect.
In a SentinelOne case study, researchers found that exposed interfaces could be abused by an administrator to bypass Windows Protected Process Light protections and interact with highly protected processes. By chaining multiple techniques, they demonstrated how legitimate security software could potentially be turned into a powerful attack mechanism.
The bigger lesson is important: security software itself is part of the attack surface.
EDR solutions operate with extremely high privileges, which makes vulnerabilities, exposed interfaces, weak trust assumptions, and insecure management mechanisms particularly significant. Organizations should consider not only whether their security tools detect threats, but also how well those tools protect themselves from abuse.
“Bring Your Own EDR” is an interesting evolution of the traditional BYOVD concept and another reminder that trusted software should never automatically be treated as inherently trustworthy.
#Cybersecurity #EDR #EndpointSecurity #ThreatResearch #ZeroTrust #WindowsSecurity #SecurityResearch #InformationSecurity
https://www.akamai.com/blog/security-research/bring-your-own-edr-turn-commercial-edr-trojan-horse
About This Hashtag
#threatresearch
32 posts
Last used 1d
#threatresearch
32 posts· Last used 1d
A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.
New.
"In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."
Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? https://www.picussecurity.com/resource/blog/openai-rubygems-incident-ai-agents #infosec #threatresearch #RubyGems #cyberattack #OpenAI
The recent MikroTik RouterOS vulnerabilities have several conditions for exploitation.
That may make mass exploitation more difficult, but targeted attacks are another story.
@martijn_grooten@mastodon.social and @silas@infosec.exchange break down what an attacker needs. https://censys.com/podcasts-videos/censys-arc-flash-episode-5/
#CensysARC #MikroTik #ThreatIntelligence #ThreatResearch #InfoSec #Cybersecurity
New.
"Dropping Elephant is an espionage-focused APT first observed in December 2015. It targets government, defense, energy, research, aviation, financial, technology, pharmaceutical, NGO, and think tank organizations across Asia, Europe, Türkiye, and the United States."
Picus: Dropping Elephant (Patchwork): Espionage APT Tactics and Tools https://www.picussecurity.com/resource/blog/dropping-elephant-patchwork-espionage-apt-tactics-and-tools #infosec #threatresearch #espionage #Windows #Android
New.
Huntress: Wallet-depleting macOS malware wants your crypto https://www.huntress.com/blog/mac-crypto-draining-malware @huntress@infosec.exchange #infosec #threatresearch #macOS #Apple #scam #malware
New.
Fortinet: QuickFox Supply Chain Attack Used to Deploy FDMTP Implant https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant @fortinet@infosec.exchange #threatresearch #infosec #cyberattack #supplychain #Windows
New.
Cisco: “Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI https://blog.talosintelligence.com/keep-going-bro-youve-got-this-a-data-driven-look-at-how-adversaries-are-weaponizing-ai/ @TalosSecurity@mstdn.social
More:
"Talos said guardrails 'did not provide much protection', and that it encountered no sophisticated encoding or evasion techniques. Where guardrails did engage, they achieved little, and the pattern held across models and platforms rather than affecting any single vendor."
Infosecurity-Magazine: Cisco: Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks Across Multiple Sessions https://www.infosecurity-magazine.com/news/talos-attackers-split-tasks-evade/ #infosec #Cisco #threatresearch #cybercrime
From yesterday:
Pillar: I'll Just Call You: Agent-to-Agent Privilege Boundary Failures in CI/CD on Google's ADK Repository https://www.pillar.security/blog/ill-just-call-you-agent-to-agent-privilege-boundary-failures-in-ci-cd-on-googles-adk-repository
More:
The Hacker News: Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent https://thehackernews.com/2026/08/google-deletes-3-adk-ai-workflows-after.html @thehackernews@social.tchncs.de #infosec #Google #bots #GitHub #threatresearch
New.
Socket: Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-namespaces-compromised-in-active-supply-chain @SocketSecurity@fosstodon.org
More:
The Hacker news: Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html @thehackernews@social.tchncs.de #infosec #npm #threatresearch #JavaScript
New.
True or false, the easiest thing to do is to blame a foreign country. But it's important to remember that this happened in the embattled state of Minnesota. Things being as they are, nothing should be off the table.
"Attribution remains open. Minnesota state and local officials declined to say who was responsible, and TJ Sayers, senior director of threat intelligence at the Center for Internet Security, confirmed the attacks had not been attributed to any party and that it was unclear whether the PLCs CISA warned about were involved."
Picus: Minnesota Water Systems Attacks: Internet-Exposed PLCs Under Attack https://www.picussecurity.com/resource/blog/minnesota-water-systems-attacks-internet-exposed-plcs-under-attack #infosec #threatresearch #cyberattack
Unit 42 published the related report yesterday:
Unit 42: Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ @unit42_intel@beta.mstdn.cf #threatresearch
Infosecurity-Magazine: Chinese Threat Actor Uses DeepSeek AI to Orchestrate Vulnerability Exploits https://www.infosecurity-magazine.com/news/chinese-hacker-deepseek-ai/ #infosec #DeepSeek #opensource #Telegram
New.
Picus: FrigidStealer Explained: macOS Infostealer and Gatekeeper Bypass https://www.picussecurity.com/resource/blog/frigidstealer-explained-macos-infostealer-and-gatekeeper-bypass #infosec #macOS #threatresearch #Apple
New,
Socket: Fake Corepack Site Distributes Infostealer and Proxyware to Developers https://socket.dev/blog/fake-corepack-site-distributes-infostealer-and-proxyware @SocketSecurity@fosstodon.org #infosec #threatresearch #malware
New.
Cisco: Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/ @TalosSecurity@mstdn.social
Group-IB (co-written by a marketer): Ransomware in 2026: Same Business, New Rules https://www.group-ib.com/blog/ransomware-2026-rules/
Warning: Recorded Future sells everything and the kitchen sink to third parties, including Google. No consent, no options.
Recorded Future: TAG-195 Upgrades MaaS Ecosystem with Modular Tools https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem
Microsoft: Email threat landscape: Q2 2026 trends and insights https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/
Proofpoint; TA488 Targets Zimbra Mailservers with Half-Click Exploits https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits
---
Rapid7: What Happened Between OpenAI and Hugging Face? https://www.rapid7.com/blog/post/ai-openai-hugging-face-what-happened/ @Rapid7Official@infosec.exchange
Picus:
"OpenAI was doing something reasonable and responsible. It was measuring how good its frontier models are at offensive cyber operations, so it could understand the risk."
Picus: The Day an AI Cheated on Its Exam by Hacking Another Company https://www.picussecurity.com/resource/blog/the-day-an-ai-cheated-on-its-exam-by-hacking-another-company
---
Posted yesterday:
Huntress: Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat @huntress@infosec.exchange
Fortinet: Inside a TrickBot Variant Using DNS Tunneling for C2 https://www.fortinet.com/blog/threat-research/inside-a-trickbot-variant-using-dns-tunneling-for-c2 @fortinet@infosec.exchange #infosec #threatresearch #ransomware #Windows #Microsoft #Claude #phishing #OpenAI #Zimbra
Socket published this yesterday, if you missed it:
Socket: Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign https://socket.dev/blog/github-actions-abuse-powers-cpanel-and-whm-exploitation @SocketSecurity@fosstodon.org #infosec #threatresearch #GitHub
New.
Proofpoint: Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service https://www.proofpoint.com/us/blog/threat-insight/unpacking-cruciferra-analysis-sophisticated-crypter-service #infosec #threatresearch #cybercrime
Meet CrashStealer. This one takes delivery more seriously than most, a signed and Apple-notarized dropper that's pulling its second stage payload down through GitHub.
The payload is a native C++ stealer with client-side AES-GCM encryption and layered anti-analysis.
Check out our writeup for additional details and indicators of compromise.
https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/
#infostealer #malware #macos #threatresearch
Microsoft, posted yesterday: Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery https://www.microsoft.com/en-us/security/blog/2026/07/15/unpacking-asyncapi-npm-supply-chain-compromise-import-time-payload-delivery/ #Microsoft #infosec #supplychain #npm #threatresearch #JavaScript
New.
Any.Run: Hidden Infrastructure Exposed: ANY.RUN Reveals Hijacked Gov Websites Delivering Malware https://any.run/cybersecurity-blog/phantomenigma-research/ @anyrun_app@infosec.exchange #infosec #phishing #threatresearch
New.
"Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025."
Cisco: UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/ @TalosSecurity@mstdn.social #infosec #threatresearch #Python