daily cyber × ai intelligence

index

tagged

[kimsuky]

8 editions · 7 items

September 7, 2026

  • Kimsuky's Operation GitPower is now mass-producing decoys with an AI coding agent: Genians analysed 13 malicious LNK files collected 11–19 August 2026 whose decoy PDF metadata names the open-source agent OpenCode as producer. Lures shifted from diplomacy and academia to finance and corporate operations (fund disbursement, insurance premiums, Visa payments); the LNKs launch PowerShell with encrypted loaders buried in over-long arguments padded with leading spaces, pull decoys and follow-on commands from GitHub Raw using hardcoded PATs, and now add Pastebin as a second-stage channel plus anti-analysis routines that check for virtualization and analysis tooling, inspect sandbox usernames and wipe command history. All 13 share the same decoder constant and array variable name — cheap hunting pivots. · Threat Intelligence

in The Diff Is the Disclosure: MikroTik's Silent Patch Comes Apart

August 13, 2026

ShieldBreak Turns a "Patched" Defender Bug Back Into SYSTEM

Microsoft Defender flaw CVE-2026-50656 was bypassed by a new ShieldBreak proof-of-concept that grants SYSTEM privileges on fully patched Windows 11 and Server 2025. SharePoint authentication-bypass CVE-2026-55040 is now actively exploited in the wild, allowing attackers to forge JWT tokens and impersonate admin users. LiteLLM malicious PyPI releases exposed over 2,100 organizations to credential-stealing code that harvested cloud keys, SSH credentials, and database passwords in a supply-chain attack traced to an earlier Trivy compromise. Midnight Blizzard (APT29) weaponized hotel Wi-Fi captive portals through CaptiveCrunch to harvest Microsoft 365 credentials and deploy malware.

July 23, 2026

  • Kimsuky compromises South Korean groupware vendors with a new Gomir variant. ENKI tracked a 2025–early-2026 espionage campaign where the DPRK group gained control of internet-facing servers via exploitation and spear-phishing, then deployed Gomir variants using Google Drive as a C2 channel and a new custom protocol to evade detection (ENKI, The Record). · Threat Activity

in "Every Frontier Model Tried to Cheat": UK Safety Institute Puts Numbers Behind the OpenAI–Hugging Face Incident