daily cyber × ai intelligence

index

tagged

[mozilla]

6 editions · 3 items

August 21, 2026

Microsoft's Own Defender Driver Becomes the EDR Killer

Microsoft's Defender Boot-Time Removal driver (BTR.sys) can be weaponized as a Ring-0 primitive to bypass Tamper Protection and delete EDR/AV before they start, with no vulnerability or BYOVD required. Zimbra, GitLab, and MLflow are actively exploited in the wild, while OpenAI paused frontier RL training after the Hugging Face breach and deployed Astra autonomous agents. Citrix NetScaler CVE-2026-19490 is a critical authentication bypass expected to be exploited imminently, and a Rust supply-chain attack deployed malicious proc-macro crates with PowerShell backdoors targeting Windows build systems.

August 15, 2026

A Heavy Day for Exploit Research and In-the-Wild N-Days

Citrix NetScaler CVE-2026-8452, VMware vCenter critical auth-bypass and VMXNET3 flaws, and SAP Commerce Cloud CVE-2026-58231 (CVSS 10.0) are all under active exploitation in enterprise environments. GeoServer, Exchange Server, PostGIS, and Ruby 4.0 join a heavy wave of zero-day and n-day research, while autonomous AI agents weaponized against critical infrastructure and a guardrail bypass in production Claude deployments expose new attack surfaces. Clop ransomware targeted Shell and Philips likely via PTC Windchill, and ShinyHunters breached RingCentral for 1.6 million accounts; Anthropic's new watermark-detection API for Claude faced immediate circumvention attempts.

July 17, 2026

Live SonicWall Exploitation, a New C2 Release, and AI Agents Tricked Into Running Attacker Commands

SonicWall SMA1000 SSL-VPN appliances are under broad-scale exploitation via CVE-2026-15409 leveraging public PoC code, with CVE-2026-56155 remaining unfixed despite July patches. Nighthawk 1.0 C2 released with cross-platform UI and improved evasion capabilities including CET-compatible call-stack masking. AI agents can be compromised through data injection attacks that corrupt trusted facts, enabling attackers to trick agents into executing commands or clicking malicious links without direct prompt injection. Scattered Spider members received 5.5-year sentences for the 2024 Transport for London ransomware attack affecting 7 million users.