daily cyber × ai intelligence

index

tagged

[kairos]

2 items

July 6, 2026

The Gentlemen Weaponize a Signed Kontron Driver Into an EDR Killswitch

The Gentlemen ransomware crew exploited a zero-day in a signed Kontron driver to disable endpoint defenses via BYOVD, gaining kernel-level access to terminate security processes before deploying ransomware. CVE-2026-46242 (Bad Epoll) now has a public proof-of-concept for a Linux kernel use-after-free that enables privilege escalation on 6.4+ kernels with 99% reliability. Medtronic is notifying 3.8 million individuals after a ShinyHunters data breach exposed personal and medical data. Multiple new red-team tools and offensive-security frameworks including T3MP3ST, goshs, and Knossos were released, alongside DOJ filings revealing how Microsoft telemetry helped the FBI identify alleged Scattered Spider member Peter Stokes via Windows Global Device ID correlation.

July 5, 2026

Confidential Computing's Root of Trust May Be Unfixable

Remote attestation, the cryptographic mechanism underpinning confidential computing and EU sovereign-cloud strategies, is reported to have an unfixable architectural flaw that undermines its entire security model. Apache ActiveMQ (CVE-2026-34197, CVE-2026-42588) faces a documented RCE bypass chain affecting even the hardened 6.2.6 release. Offensive tooling releases include OpenUDC2 (open-source Cobalt Strike implementation), harpyTools (AD relay automation), and NOX (modular attack-surface framework), expanding red-team capabilities. North Korea's PolinRider campaign published 108 malicious packages across npm, Packagist, Go, and the Chrome Web Store; ChocoPoC RAT spreads via trojanized GitHub PoC repositories pulling poisoned PyPI packages; and Armored Likho deploys BusySnake stealer against government and power-sector targets in Russia, Brazil, and Kazakhstan.