daily cyber × ai intelligence

index

June 26, 2026

Malware Weaponizes Prompt Injection to Sabotage AI Analysis as Gamaredon Retools Against Ukraine

36 sources 355 gathered 355 triaged 45 clustered 45 written

A Rust-based macOS stealer dubbed Gaslight is the first publicly documented sample to embed prompt-injection payloads aimed at derailing AI-assisted malware analysis. On the threat-intel side, ESET published a deep teardown of Gamaredon’s 2025 arsenal, and a batch of fresh PoCs landed for Exchange, FFmpeg, GeoServer, and curl.

AI & Model Security

  • Gaslight, a previously undocumented Rust macOS implant and infostealer, hides prompt-injection strings and fake debugging/error data in the binary to trick an analyst’s AI tooling into aborting or refusing analysis — a direct adversarial response to AI-augmented reverse engineering. BleepingComputer, The Hacker News
  • Embrace The Red reproduced a TOCTOU race-condition attack against computer-use agents (building on Jun Kokatsu’s ChatGPT Operator finding), showing that “what you click is not what you get” — the agent can be steered to act on swapped content between verification and execution. Embrace The Red
  • A new paper argues prompt injection succeeds because LLMs lean on learned role patterns rather than explicit role markers, pointing to genuine “role perception” as a prerequisite for robust defenses. Schneier on Security

New Tools & Releases

  • KHAOS — a modern C2 framework that routes agent traffic through cloud services already trusted on enterprise networks, blending C2 into normal egress. GitHub
  • Bitwarden C2 — a full command-and-control channel over icons.bitwarden.net: commands inbound via PNG-metadata polyglots, results exfiltrated via DNS, all to a trusted Azure-hosted domain. thecontractor.io
  • CrystalSliver — swaps Sliver’s default reflective loader and post-ex execution path for Raphael Mudge’s Crystal Palace evasion kit. GitHub
  • SiteManagementAx — a web-delivery extender for AdaptixC2 that hosts payloads over HTTP/HTTPS and generates one-liners across 17 delivery methods. GitHub
  • AudioDG.exe DLL hijacking for LPE — executes as LOCAL SERVICE and escalates to SYSTEM via Scheduled Tasks, with a reboot-free restart primitive. GitHub
  • exclusion-auditor — read-only NGAV/EDR exclusion risk and hygiene auditor (CrowdStrike-first, vendor-agnostic) for finding dangerous exclusion gaps; useful for purple-team coverage checks. GitHub
  • A two-part write-up on Windows Defender evasion via direct syscalls and XOR-encrypted shellcode, with lab setup and working code. Part 1, Part 2

Vulnerabilities & Exploits

  • CVE-2026-45504 — a Microsoft Exchange SSRF lets any low-privileged authenticated user read arbitrary files via malicious WOPI URLs; a Python PoC is public. HawkTrace, PoC
  • CVE-2025-52465 (“GeoLocate”) in GeoServer is being exploited in the wild — admins can dump plaintext master passwords, enabling JSP webshell injection and (on Windows with UNC paths) NTLM credential leakage. partywave.site
  • CVE-2026-8461 (“PixelSmash”) — a heap OOB write in FFmpeg’s MagicYUV decoder yields RCE via a crafted media file; a public exploit dropped. JFrog, PoC
  • CVE-2026-38526 (CVSS 9.9) — Krayin CRM RCE via the TinyMCE upload endpoint (/admin/tinymce/upload) to drop a PHP webshell; PoC published. PoC
  • curl shipped fixes for a large batch of CVEs including its oldest-ever reported bug (~24–25 years old), with HackerOne reports detailing several credential-leak and connection-reuse flaws — stale proxy passwords (CVE-2026-9079), .netrc password mispairing (CVE-2026-8926), an SSH host-key mismatch silently accepted (CVE-2026-9547), STARTTLS session reuse enabling MITM (CVE-2026-8286), and ASan-validated UAF/Referer leaks (CVE-2026-9546). Aisle, SecurityWeek
  • CISA warns critical Ubiquiti UniFi OS flaws (CVE-2026-34908/-34909/-34910) are being exploited to create rogue admin accounts; patch unpatched controllers. SecurityWeek

Threat Intelligence

  • ESET detailed Gamaredon’s 2025 evolution: six new PowerShell downloaders (PteroDee, PteroDum, PteroPaste, PteroOdd, PteroEffigy, PteroCache) plus the revived PteroSetup weaponizer, 35 spear-phishing campaigns against Ukrainian government/military, and heavy infrastructure laundering via Cloudflare Workers, Microsoft dev tunnels, Loophole, and dead drops on Telegram, Telegraph, Rentry, Dropbox, Supabase and Clever Cloud. WeLiveSecurity, whitepaper + IOCs
  • China-aligned TA416 resumed espionage against EU/NATO diplomatic missions from mid-2025, running web-bug and malware-delivery waves and expanding to Middle East government targets after the Iran conflict. Proofpoint
  • A new actor tracked as GhostShell has targeted Ukraine’s drone-defense sector since February 2026 with data-stealing, spying malware disguised as legitimate files. Hackread
  • Cellebrite’s phone-extraction tooling kept being used by Russian authorities against a dissident after the firm said in 2021 it would stop serving the country, suggesting vendors struggle to claw back deployed gear from authoritarian customers. The Record
  • ASIO disclosed that nation-state actors have pre-positioned in Australian critical infrastructure to “cripple it at a time of their choosing,” and is leaning on AI and offensive hacking capabilities in response. The Register
  • Japan’s Ground Self-Defense Force unknowingly used counterfeit Chinese-made USB drives carrying malware for nearly a year, compromising 50+ systems before detection. CyberInsider
  • A malicious Adblock for YouTube Chrome extension with 10M+ installs and a Featured badge was found capable of arbitrary JS injection, and a malicious Edge extension (Edgecution) abused Native Messaging to escape the browser sandbox and deploy a Python backdoor in a ransomware intrusion. The Hacker News, BleepingComputer
  • Nextron began scanning Packagist and flagged a malicious PHP package, dcat-auth-google-2fa@v1.0.2.0, with obfuscated credential exfiltration to r[.]keepex[.]xyz and a hardcoded 2FA bypass code. Nextron
  • The Bluekit phishing-as-a-service platform added browser-in-the-middle (BitM) capability and spun up ~70 new hostnames in a week, while Shopify’s Shop order-tracking app is being abused to inject fake receipts that lure victims into callback-phishing support numbers. BleepingComputer (Bluekit), BleepingComputer (Shop)
  • Poland’s anti-cybercrime bureau arrested four members of a SIM-swapping crew that breached telecom partners and hijacked email accounts to drain crypto accounts, laundering tens of millions of złoty, with FBI/HSI support. BleepingComputer

Data Breaches

  • A threat actor is advertising an alleged Robinhood database of 14.5M records claiming full PII, SSNs, driver’s-license and linked bank-account details, balances, password hashes and 2FA status — unverified, but among the most sensitive financial datasets touted this year. Daily Dark Web
  • A separate actor published an alleged Hargreaves Lansdown dataset of 658K UK customer records (names, addresses, DOBs, contact details), claimed to be ~50% of the platform’s users. Daily Dark Web

Around the Region

  • Finland’s National Bureau of Investigation warns of fraudsters posing as police on video calls, pressuring victims (especially immigrants) to show payment cards or hand over banking/personal data under threat of account closure or deportation. Yle