June 23, 2026
Five Eyes Warns Frontier AI Will Reshape Offensive Cyber Ops as a New Entra ID Conditional Access Bypass Surfaces
29 sources → 262 gathered → 262 triaged → 45 clustered → 45 written
A practitioner-heavy day: the Five Eyes agencies put a months-long timeline on AI-accelerated offensive operations, dirkjanm dropped a Conditional Access bypass via resource exclusion, and fresh EDR-evasion and exploit research landed. On the threat side, the Klue fallout widened to a long list of security vendors and a Norwegian IT provider was advertised for a 21TB dump.
Offensive & Red Team
- Entra ID Conditional Access bypass via resource exclusion — dirkjanm details a token-scope enforcement gap where apps can reach broader directory data than a policy intends when a CA policy carries a resource exclusion; Microsoft is rolling out a new baseline scope-enforcement setting to close it. Worth reviewing CA policies for over-permissive exclusions now. dirkjanm.io
- Cobalt Strike profile tuning for EDR evasion (Part 3) — White Knight Labs walks through Cobalt Strike 4.13 malleable-profile improvements, Drip Loading, and timing delays, with simplified loader configuration. White Knight Labs
- QoS policies abused to throttle EDR telemetry — iPurpleTeam shows how Windows QoS policy can be used to choke an EDR’s network traffic, and pairs it with a concrete detection strategy — a clean purple-team test case. iPurpleTeam
AI & Model Security
- Five Eyes warns frontier models could reshape offensive cyber ops “within months” — the intelligence alliance cautions that increasingly capable models will materially lower the barrier to high-impact operations against governments and businesses. Strategic framing rather than a specific capability disclosure, but notable for the explicit timeline. The Decoder
- DifyTap: four flaws in Dify expose AI chats across tenants — Zafran Security details unauthenticated bugs in the 146k-star open-source agentic workflow platform Dify that let an attacker silently read other customers’ AI conversations. The Hacker News
- Microsoft patches AutoGen Studio “AutoJack” RCE — the previously reported flaw in Microsoft’s agent-prototyping UI, which let a malicious webpage coax an agent into running host commands, has now been fixed. BleepingComputer
- “Prompt Injection as Role Confusion” — a new paper reframes prompt injection as a role-confusion problem in LLM applications, a useful lens for reasoning about agentic/tool-using systems. role-confusion.github.io · arXiv
- OpenAI expands Daybreak with GPT-5.5-Cyber — billed as its “strongest model yet for finding and helping patch software vulnerabilities,” released to trusted defenders, claiming sustained analysis across large codebases. The Hacker News
Vulnerabilities & Exploits
- Squidbleed: 29-year-old Squid proxy heap over-read leaks cleartext HTTP — Calif.io disclosed a Heartbleed-style bug (traced to a 1997 FTP-parsing change) that can leak another user’s request — including credentials or session tokens — to anyone allowed through the same proxy. Live in Squid’s default config. The Hacker News · SecurityWeek
- PowerVR GPU kernel/firmware flaws — Project Zero published two issues: a UAF in
SYNC_PRIMITIVE_BLOCKhandling enabling arbitrary memory access, and dangling page-table entries in_MMU_AllocLevel()error paths — both paths toward privilege escalation. 488427334 · 488373434 - adb-to-root on Google TV Streamer via setresuid glitch — Raelize used EM fault injection to bypass kernel capability checks and reach root, though SELinux enforcement blocked full compromise. Raelize
- Enterprise VPN client teardown — a reverse-engineering write-up finds hardcoded secrets, forgeable posture reports, missing TLS verification, and exposed management interfaces — “security” reduced to constants in a binary. Medium
- PoCs out for two web app RCE chains — CVE-2026-48909, a PHP object injection → RCE in SP LMS (CVSS 9.5), and CVE-2026-25860, a reflected XSS → OS command execution in OpenClinic GA’s DICOM upload, both have public exploit code. SP LMS PoC · OpenClinic write-up
Threat Activity
- Brazil’s Emergency Alert System hijacked off a decade-old infostealer credential — an actor (“mizanthropiaz”) pushed false alerts to hundreds of thousands across São Paulo, Rio, and Brasília after logging in with a username/password harvested by malware in 2016 and never rotated; reports describe no MFA, no IP allowlisting, no rate-limiting, and a static “2+2” CAPTCHA. A textbook case of identity hygiene failure at national scale. The Record
- Two Scattered Spider members plead guilty to the TfL attack — Thalha Jubair (20) and Owen Flowers (18) admitted the Transport for London intrusion that cost tens of millions; sentencing is set for July 16, 2026, with the NCA noting Flowers violated release conditions twice. NCA
- FortiBleed update: custom FortiGate sniffers and 86k confirmed creds — SOCRadar reports the campaign deployed custom sniffers on compromised firewalls to harvest authentication secrets, and Unit 42 frames it as broad password spraying against Fortinet, Sophos, and MSSQL using a curated list built from prior breaches; Fortinet says ~86,000 working credentials were validated. BleepingComputer · SecurityWeek
- Deepfake instructs victims to steal their own session cookies — Unit 42 tracks an evolved campaign using an AI-generated tutorial video that walks social-media users through extracting their own session cookies via browser DevTools, abusing six SaaS platforms across 800+ lure pages. Unit 42
- WhatsApp-borne VBScript drops RMM software — an active campaign spreads malicious VBScript via WhatsApp Desktop/Web DMs disguised as financial documents, deploying remote-management tooling; victims span Malaysia (highest), Brazil, India, Mexico, Singapore, UK, Spain and more. Securelist
- OXLOADER delivers CastleStealer via malicious Google Ads — Elastic Security Labs profiles a previously unreported loader fronting malvertising, attributed to a likely Russian-speaking financially motivated actor. The Hacker News
- AryStinger botnet enslaves 4,000+ D-Link devices — undocumented malware turns outdated routers and NAS boxes into a proxy network, raising risk of DNS tampering and traffic theft on EOL hardware. BleepingComputer · Malwarebytes
- ShapedPlugin WordPress build pipeline backdoored — Wordfence reports attackers tampered with the vendor’s official release channel to inject backdoor code into Pro plugin updates. The Hacker News
Threat Intelligence
- Klue breach fallout widens to a who’s-who of security vendors — after Icarus posted stolen data on June 22, affected Klue customers now include HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium. Huntress says no product data, telemetry, passwords, or card data were touched — exposure is limited to business metadata (names, products trialed, subscription/pricing, sales notes) — and warns the data is ripe for Klue/Huntress impersonation. SecurityWeek · Huntress
- Prinz Eugen rebrands as a “for-profit hacking” outfit — the group relaunched its leak site, says it does not currently run a RaaS program, and closed membership to existing core members — an infrastructure/branding shift worth tracking. Ido Cohen
- Two new extortion crews emerge — SevyWare, a RaaS claiming ex-affiliate ties and aggressively recruiting initial-access brokers and insiders, and Booba Project, a self-styled “data decryption service.” Neither has posted victims yet. Ido Cohen
Data Breaches
- Norwegian IT services firm Alpha IT advertised for 21TB dump — a threat actor claims financial records, HR documents, client data, mailboxes, databases and exports from alphait.no. Unverified, but a managed-services provider of this scale carries downstream risk to customer environments. Daily Dark Web
- Tata Electronics breach claims Apple and Tesla trade secrets — an actor alleges exfiltration of sensitive partner data; claims are unverified. Yahoo/Reuters
- Apollo.io dataset (486M records / 194GB) offered for sale — “ShadowSiphon” advertises B2B lead data tying business contacts to detailed employer and role info — high-value fuel for targeted phishing and BEC. Dark Web Informer
- Carrefour and Whise.eu data leaks advertised in the EU — a claimed SQLi dump of Carrefour customer PII (including passport, national ID, and SSN fields) and a 40M+ record dataset from real-estate CRM Whise.eu (37.7M email records) surfaced on cybercrime forums. Carrefour · Whise.eu
Industry & Policy
- Anthropic’s feud with the US government escalates — MIT Technology Review unpacks the dispute around Anthropic’s Mythos model and what to watch as government pressure on AI capabilities grows. MIT Tech Review
- Meta pauses AI keystroke-tracking program after internal leak — the abandoned effort would have used employee keystrokes as training data; surfaced via an internal leak over privacy concerns. Business Insider
- AWS Lambda adds MicroVMs for isolated user/AI-generated code — a relevant primitive for sandboxing untrusted or model-generated code execution. AWS
Topics
Vendors
Threat actors
Models