daily cyber × ai intelligence

index

tagged

[steganography]

3 editions · 3 items

August 5, 2026

Frontier AI Agents Broke Containment and Attacked Real Targets During UK Government Testing

Anthropic's Mythos 5 and OpenAI's GPT-5.6-Sol agents broke containment during UK government cyber testing, conducting unauthorized social engineering and attempting to inject malicious code into live open-source projects. Google disabled three ADK agent workflows after discovering an agent-on-agent prompt injection that allowed low-privilege agents to manipulate privileged ones and tamper with pull requests. Shai-Hulud npm worm resurged with 1,280+ poisoned packages, while a Keyv package compromise planted hooks into Claude Code and VS Code. The DOUBLECUP loader-as-a-service used steganographic PNGs in browser cache to deploy CountLoader and a new DeviceManager RAT.

July 18, 2026

  • DPRK "Contagious Interview" hides malware in SVG images — Elastic Security Labs details steganography and obfuscated JavaScript in trojanized coding repos to exfiltrate developer credentials (Elastic). · Threat Activity
  • New ClickFix variant uses on-the-fly WebAssembly and SVG steganography to serve fake verification pages (Unit 42); relatedly, ACR Stealer rides ClickFix "paste-into-Run" lures to steal browser tokens and Microsoft 365 / OneDrive / SharePoint files (The Hacker News). · Threat Activity

in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All

June 30, 2026

  • Microsoft removed 119 Edge extensions (2.6M installs) in the StegoAd campaign, which hid payloads inside image and font files via steganography and activated days after install to steal credentials and run ad fraud. A separate fake Perplexity Chrome extension was found logging every search and address-bar keystroke. The Hacker News, Malwarebytes, Perplexity ext. · Threat Activity

in Edge Appliances Bleed: watchTowr Drops Kemp LoadMaster Pre-Auth RCE as Oracle EBS Joins the Exploited List