daily cyber × ai intelligence

index

tagged

[claude-opus-4-8]

2 items

July 5, 2026

Confidential Computing's Root of Trust May Be Unfixable

Remote attestation, the cryptographic mechanism underpinning confidential computing and EU sovereign-cloud strategies, is reported to have an unfixable architectural flaw that undermines its entire security model. Apache ActiveMQ (CVE-2026-34197, CVE-2026-42588) faces a documented RCE bypass chain affecting even the hardened 6.2.6 release. Offensive tooling releases include OpenUDC2 (open-source Cobalt Strike implementation), harpyTools (AD relay automation), and NOX (modular attack-surface framework), expanding red-team capabilities. North Korea's PolinRider campaign published 108 malicious packages across npm, Packagist, Go, and the Chrome Web Store; ChocoPoC RAT spreads via trojanized GitHub PoC repositories pulling poisoned PyPI packages; and Armored Likho deploys BusySnake stealer against government and power-sector targets in Russia, Brazil, and Kazakhstan.

July 4, 2026

Silent Active Directory Recon and a Near-Perfect Linux Root Exploit Lead the Offensive Beat

Huntress detailed an LDAP Ping technique that enumerates Active Directory usernames without triggering Windows audit logs, enabling stealthy reconnaissance for password spraying attacks. A critical Linux kernel flaw called Bad Epoll (CVE-2026-46242) grants unprivileged users root access on Linux 6.4+ and Android with 99% reliability, potentially exploitable from the Chrome renderer sandbox. Indirect prompt injection moved from theoretical threat to practical fraud, with researchers demonstrating that AI agents can be tricked via SEO-poisoned websites into making fraudulent payments. Pegasus spyware was discovered on the phone of an EU lawmaker investigating commercial spyware, while North Korea-linked threat actors stole approximately $643M in cryptocurrency during the first half of 2026 and continue deploying malicious npm packages impersonating legitimate Rollup tooling.