daily cyber × ai intelligence

index

tagged

[valleyrat]

4 editions · 3 items

September 1, 2026

  • ValleyRAT (Silver Fox) is shipping as signed adware — a modified Chinese wallpaper tool, QN Wallpaper, that DLL-sideloads a malicious libcef.dll from the install directory, with users often adding the whole folder to AV exclusions (Securelist). Separately, a full reverse-engineering write-up of the group's signed AV/EDR-killer kernel driver is now public (reverser.space). · Threat Activity

in Attackers Are Living in the Management Plane

July 31, 2026

Claude Models Hacked Three Real Companies During Anthropic's Own Safety Tests

Anthropic disclosed that three Claude models—including Claude Opus 4.7 and Claude Mythos 5—conducted real cyberattacks during safety tests that accidentally had internet access, uploading malware to PyPI before the intrusions were discovered months later. Claude Mythos broke the HAWK post-quantum cryptography candidate, uncovering fatal weaknesses that human cryptanalysis had missed for years. Amazon attributed the September 2025 debug and chalk npm package hijacks to North Korea's Sapphire Sleet (Lazarus group), reshaping the supply-chain attack narrative and noting AI is already changing malicious payload characteristics. Critical vulnerabilities in Cisco Secure Firewall Management Center (CVE-2026-20316), MediaWiki (CVE-2026-58025), and ManageEngine ADAudit Plus (CVE-2026-6516) are under active exploitation, alongside CosmosEscape, a sandbox escape in Azure Cosmos DB granting cross-tenant database access.