July 5, 2026
Confidential Computing's Root of Trust May Be Unfixable
28 sources → 281 gathered → 281 triaged → 55 clustered → 50 written
New research argues that remote attestation — the mechanism that lets a client verify it’s talking to a genuine Trusted Execution Environment — has an architectural flaw that undermines the entire “confidential computing” pitch now being sold as the backbone of European sovereign cloud. It was an active day for offensive tooling too, with an open-source Cobalt Strike UDC2 implementation, AD relay automation, and a modular attack-surface framework all shipping.
Vulnerabilities & Exploits
- Confidential computing’s core trust mechanism is reported broken, with no clear fix. New research (surfaced by NCSC-FI) claims remote attestation — the cryptographic proof that data is entering a genuine, unmodified TEE such as Intel TDX — rests on a fundamental architectural flaw, calling into question its use as the security foundation for EU sovereign-cloud ambitions. The Register
- Apache ActiveMQ RCE bypass chain published. Research covering CVE-2026-34197 and CVE-2026-42588 documents a bypass chain against ActiveMQ Classic, plus audit findings on the “hardened” 6.2.6 release showing some remote exploitation remains feasible despite tightened URI parsing and restricted Jolokia access. GitHub
- Apple “Hide My Email” flaw exposes real addresses. A vulnerability that can unmask the real email behind Apple’s relay-address feature has reportedly gone unpatched for over a year. 404 Media
- Guix substitute and
guix pullvulnerabilities disclosed, affecting the trust model around package substitution and channel updates in the GNU Guix build/distribution pipeline. Guix - Ukrainian banking SMS-bypass exploit advertised. A forum actor claims to sell (three copies, $1,000 each) a method to take over mobile-banking accounts at a major Ukrainian bank after obtaining a single SMS code, bypassing password and identity checks. Unverified. Daily Dark Web
New Tools & Releases
- OpenUDC2 — an open-source implementation of the Cobalt Strike UDC2 spec, letting open-source C2s (an Adaptix PoC is included) reuse existing CS tooling. GitHub
- harpyTools — Active Directory post-exploitation and NTLM relay automation utilities. GitHub
- skewrun — AD time-discovery toolkit that resolves the DC’s clock via CLDAP/SMB/NTP/Kerberos/NTLM and executes commands through
libfaketimefor stealthy Kerberos-context operations. GitHub - goshs — feature-rich single-binary file server for red teamers: HTTP/S, WebDAV, FTP/SFTP, SMB, LDAP/S with NTLM hash capture, and DNS/SMTP callbacks. A serious
python3 -m http.serverreplacement. GitHub - NOX — modular attack-surface-management and vuln-scanning framework in Go with 299 built-in modules spanning OSINT, subdomain enumeration, port scanning, web/API fingerprinting, auth/authz, and business-logic testing. GitHub
- tf-mythic-azure — Terraform to auto-deploy Mythic C2 infrastructure in Azure from a single codebase, with secrets in Key Vault and SSH port-forward access. GitHub
- BareMetal-RAM-Dumper — bare-metal x86 boot utility that dumps physical RAM straight to disk via BIOS interrupts, built for cold-boot attack experiments. GitHub
- ironcurtain — a secure runtime for autonomous AI agents where policy is derived from a plain-English “constitution.” Useful reference for anyone hardening agentic deployments. GitHub
- mastyf.ai — open-source AI-security platform providing perimeter defense for LLMs and agents: intercepts tool calls, enforces policy, and runs adversarial testing. GitHub
Threat Activity
- ChocoPoC RAT spreads via trojanized GitHub PoC repos, targeting researchers testing exploits. The malicious code isn’t in the exploit itself — the repos pull poisoned Python packages from PyPI that later fetch the RAT, which can run commands and steal browser data, files, and shell history. BleepingComputer
- North Korea’s PolinRider campaign publishes 108 malicious packages/extensions across npm, Packagist, Go, and the Chrome Web Store, linked to the ongoing Contagious Interview cluster. Compromised maintainer accounts mean the count is expected to grow. The Hacker News
- FBI warns of TeamPCP supply-chain attacks on developer tools used to steal cloud credentials and deploy malware, urging tighter build-pipeline controls and monitoring. Security Affairs
- Verified X ad pushes Mac malware plus a browser-based M365 token thief. A sponsored post from a verified account impersonated the DynamicLake utility and redirected to a lookalike domain instructing users to paste a Terminal command, delivering an Atomic Stealer variant (tracked as MacSync, with DigitStealer in some cases). The same report flags ConsentFix, a ClickFix-style trick that steals Microsoft 365 session tokens through the browser — no malware, no password. Malwarebytes
- Silver Fox (SwimSnake) runs an RBI-themed phishing lure to deliver ValleyRAT / Winos 4.0 via DLL sideloading to a live C2 — the first Reserve Bank of India-themed lure observed for this family (medium-high confidence). FalconFeeds
- Armored Likho targets government and electric-power organizations across Russia, Brazil, and Kazakhstan with the BusySnake stealer, blending financially motivated activity with espionage. The Hacker News
- Court docs in the Scattered Spider case reveal Microsoft’s “GDID” device tracking. Filings against extradited suspect Peter Stokes describe a Global Device Identifier tied to each Windows install that reported IPs, web activity, timestamps, and even game activity to Microsoft — a largely undocumented telemetry identifier that helped the FBI place him behind Ngrok tunnels. vx-underground
- A U.S. government entity paid ~$1M to “Kairos” in a pure data-extortion case. Ransom-ISAC reconstructed the negotiation from leaked chat logs and blockchain tracing; notably, no encryptor or locker binary has ever been linked to Kairos — just stolen data, deadlines, and an unverifiable deletion promise. The Hacker News
- Emerging “Wallstreet” ransomware brand claims early victims, including Baraga County Memorial Hospital and Edgewood Police Department — three victims in its first days on tracking platforms. Ido Cohen
- Cloudflare quietly killed the NWHStealer campaign. A researcher deobfuscating a BUN-bundled stealer (spread via fake GTA 6 ads) found its C2 (
unauth-amper[.]cc) already taken down by Cloudflare, ending the campaign. vx-underground
Cloud & Identity
- CERT.dk warns of 81 million login attempts against Microsoft 365 aimed at the Danish telecom sector — a password-spray surge consistent with the large-scale OAuth/ROPC campaigns seen elsewhere this week, and a reminder to enforce MFA and disable legacy auth flows. CERT.dk
AI & Model Security
- Claude Fable 5 came back “nerfed” after re-release. Re-running the July 1 build on BridgeBench showed sharp regressions (debugging 86→26, refactoring 74→38), which the tester attributes to new guardrails over-triggering and falling back to Opus 4.8. Anecdotal benchmark, but notable for anyone building on the model. bridgemindai
- Identity lifecycle management isn’t built for AI agents. A practitioner walkthrough of where human-centric IGA (joiner/mover/leaver, managers, departure dates) breaks down for autonomous agents that have none of those attributes — relevant as agents proliferate as first-class principals in enterprises. The Hacker News
- pxpipe exploits Anthropic’s per-pixel image pricing by rendering bulk text prompts into compact PNGs, reportedly cutting Claude/Fable 5 token costs 59–70% at some accuracy cost — an interesting side-channel on how multimodal billing can be gamed. The Decoder
Data Breaches & Threat Intel
- AstraZeneca corporate data advertised for sale, with the seller claiming source code (Java, Angular, Python), AWS/Azure Terraform configs, and secrets including private keys and vault credentials (~3 GB). Unverified; if authentic, a serious dev-environment and supply-chain exposure. Daily Dark Web
- Fluke Corporation data tied to ShinyHunters’ Salesforce campaign. A forum actor claims 21M+ Salesforce records (100GB+) with PII, attributed to ShinyHunters. Unverified. Daily Dark Web
- Teletrac Navman fleet-telematics data listed for sale, allegedly 672k GPS position records across 30,440 vehicles and 8,381 drivers in Australia/NZ — with government, water, mining, and critical-infrastructure fleets named. Unverified. Dark Web Informer
- Italian and Thai judiciary/law-enforcement mailbox access offered for $1,200, described as live webmail sessions with persistent cookies and no MFA, tied to police-commander and officer roles. Unverified. Dark Web Informer
- India probes a Tata Electronics leak exposing unreleased iPhone 18 Pro details/prototypes — a notable Apple supply-chain security incident. Khaleej Times
- Medtronic notifies patients of data exposure from an April cyberattack; no evidence of public exposure or device-safety impact, with credit monitoring offered. The Register
- Unverified government/education claims worth tracking: ICAI’s student portal (India) allegedly hit via an exposed
.gitdirectory (1.5M records), plus forum listings for Chile’s Transport ministry, multiple Mexican government/education targets (incl. SICEP Puebla, 1.4M students), Afghanistan government infrastructure, the University of Jordan, Adidas’ corporate extranet, and Brazil’s Wattio Energy (~7M lines). Treat as unconfirmed intrusion indicators. Daily Dark Web
Topics
Vendors
Threat actors
Malware
Models