Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability

Threat actors have started exploiting a recently patched vulnerability in JetBrains TeamCity, the US cybersecurity agency CISA warns.

A continuous integration and continuous delivery (CI/CD) platform, TeamCity provides automated software building and deployment and is a central component of enterprise workflows, collaboration, and development practices.

Tracked as CVE-2026-63077 (CVSS score of 9.8), the critical security defect is related to deserialization of untrusted data and allows unauthenticated attackers to achieve remote code execution (RCE) via HTTP/S requests.

Impacting all TeamCity On-Premises versions, the flaw enables attackers to “bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process,” JetBrains warned last week.

Patches for the issue were included in TeamCity versions 2025.11.7 and 2026.1.3. A security patch plugin for version 2017.1+ was also released.

“An unauthenticated attacker could exploit the vulnerability via the TeamCity agent polling protocol,” JetBrains said, urging organizations to apply the patches to their TeamCity On-Premises deployments as soon as possible.

Advertisement. Scroll to continue reading.

In its advisory, JetBrains noted that the security defect was reported privately and that it was not aware of any active exploitation.

On Wednesday, roughly a week after public disclosure, CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, as mandated by BOD 26-04.

There does not appear to be any public information on the attacks exploiting the vulnerability.

Related: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

Related: New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts

Related: CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities

Related: Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

https://www.securityweek.com/hackers-start-exploiting-recent-jetbrains-teamcity-vulnerability/




How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones 

BLACK HAT – Two security researchers found a way to exploit vulnerabilities in Samsung software, including the virtual assistant Bixby, to hack mobile devices.

The research was conducted by Dimitrios Valsamaras, senior security researcher at Microsoft, and Ken Gannon, head of mobile research at Mobile Hacking Lab. 

Gannon and Valsamaras demonstrated the vulnerabilities at the Pwn2Own Ireland hacking competition in October 2025, where they earned $50,000 after exploiting them to hack a Samsung Galaxy S25 device.

The researchers have now detailed their findings in a talk at the Black Hat conference, describing the vulnerabilities they discovered and how they were chained to achieve remote system-level compromise. 

The exploit developed by Gannon and Valsamaras starts with an attacker tricking the targeted user into clicking a link delivered via malicious ads or a messaging application. 

After the victim clicks on the link, a vulnerability tracked as CVE-2025-21079 is exploited to force Samsung Members to connect to a malicious website. Samsung Members is an official user community, diagnostics, and support app that is preloaded on many mid-range and flagship Galaxy smartphones. 

Advertisement. Scroll to continue reading.

The malicious site then forces Samsung Members to open the Samsung Account app, which is designed to connect users to Samsung services. 

Next, a different vulnerability, CVE-2025-58486, is used to force Samsung Account to connect to an attacker-controlled website. This site then exploits an XSS vulnerability tracked as CVE-2025-58487 to force Samsung Account to open Bixby, the virtual assistant that can handle voice commands, visual searches, and device automation routines.

The researchers told SecurityWeek that this is possible because the Samsung Account app has a special permission that is required to interact with a specific ‘entry point’ in Bixby. 

“Think of it as a ‘side entrance’ and Samsung Account happens to be a key holder for the ‘side entrance,’” explained Gannon.

The next stage of the attack involves a Capsule, a hidden background service inside an app that acts like a mini internal server. When users issue a voice command, Bixby translates the request and sends it to the app’s Capsule to perform the actual task. Because Capsules can directly control app functions, Samsung restricts access so that normally only Bixby is allowed to talk to them. 

However, the researchers reverse-engineered the Capsule infrastructure on Samsung phones and found a way to force Bixby to use various Capsules maliciously. 

This enabled an attacker to exfiltrate sensitive data and achieve system-level permissions on the Android device—the highest privilege level that can be achieved on a stock consumer device. 

The researchers showed that once an attacker has obtained ‘system’ permissions, they can achieve remote code execution and take control of the device.

The researchers said they successfully reproduced the exploit on Samsung Galaxy S25, S24, and Flip 7 smartphones. 

Vulnerabilities patched by Samsung

Samsung started patching the vulnerabilities a few weeks after the Pwn2Own competition. Specifically, the company rolled out patches for the Samsung Members application in November 2025, preventing the exploit chain from being triggered via a web browser or messaging app. Patches released in December fixed the Samsung Account flaws.

The researchers told SecurityWeek that the attack works on older Samsung devices, which may not have received the patches, but noted that the exploit requires all of the targeted apps to be installed. While flagship models come with the apps preinstalled, it’s unclear if that applies to budget models as well.

Samsung has not responded to SecurityWeek’s request for comment.

Related: Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks

Related: What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out

Related: New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones

https://www.securityweek.com/how-a-50000-exploit-chain-turned-bixby-against-samsung-phones/




Black Hat USA 2026 – Summary of Vendor Announcements (Part 3)

Many companies are showcasing their cybersecurity products and services this week at the 2026 edition of the Black Hat conference in Las Vegas.

To help cut through the clutter, the SecurityWeek team is publishing a digest summarizing vendor announcements at Black Hat USA 2026, including new products and services, updates to existing offerings, reports, and other initiatives. 

This is the third part of the series. You can also read Part 1 and Part 2 if you haven’t already. 

Above Security’s strategic investment from CrowdStrike Falcon Fund

Above Security announced a strategic investment from the CrowdStrike Falcon Fund and integration with the CrowdStrike Falcon platform. Through the partnership, CrowdStrike customers will be able to extend their Falcon deployment, powering ready-made insider risk investigations with Falcon Next-Gen SIEM telemetry. Above correlates Next-Gen SIEM endpoint, identity, and third-party data into investigation-ready cases and streams completed investigations back into Falcon.  

ArmorCode launches vulnerability remediation agents

Advertisement. Scroll to continue reading.

ArmorCode announced four new Anya agents designed to help security teams analyze cloud risks, assess vulnerability exploitability, identify mitigation strategies, and coordinate patch orchestration. The company also added new Context Risk Graph capabilities for expanded attack path analysis, network reachability, and patch management. 

Commvault integrates Threat Scan with Google Threat Intelligence

Enterprise cyber resilience company Commvault announced a new integration that will incorporate Google Threat Intelligence into Commvault Threat Scan workflows. This capability can help organizations identify clean recovery points faster, as well as reduce downtime and speed up recovery following cyberattacks. This announcement adds to Commvault’s ongoing collaboration with Google Cloud, including expanded cyber resilience capabilities for Google Cloud environments via Clumio, and support for Google Cloud workloads.

CrowdStrike announces $100,000 international AI security challenge

CrowdStrike announced AI Unlocked: Agents of Chaos, a global AI red teaming competition created with AWS that challenges participants to exploit rogue AI agents using prompt injection and other techniques to better understand emerging agentic AI security risks. The virtual competition, which begins on August 31 and features a $100,000 prize pool, is designed to give defenders hands-on experience securing AI agents as they become a growing enterprise attack surface.

Dataminr threat landscape report

Dataminr has published its 2026 Mid-Year Threat Landscape Report, finding that the average patch window in H1 2026 got 11 days longer. Meanwhile, attackers can break out in less than 30 minutes, and Dataminr tracked a 69.2% jump in alerts from the second half of 2025.

DataBahn launches Federated Search and Orchestration

DataBahn launched Federated Search and Orchestration, an expansion of its agentic data control plane that moves companies from applying intelligence after data has moved through pipelines to orchestrating it as the data moves. Enterprises can ask one question across every store they own without needing to copy any of the data, and hand it off to an AI agent to complete the investigation.

FireMon integrates with Palo Alto Networks

FireMon announced it has completed its product integration with Palo Alto Networks Strata Cloud Manager to deliver intelligent and interoperable solutions that enable joint customers to innovate faster and solve their most complex cybersecurity challenges.

Intel 471 unveils new AI capabilities

Intel 471 announced two new AI capabilities in the Verity471 platform: MCP471 and Agent471. With the addition of MCP471 and Agent471, Verity471 makes its pre-attack and threat-hunt intelligence more accessible and operationalizes it to help organizations detect and respond rapidly.

Menlo Security extends platform to secure AI assistants and coding agents

Menlo Security expanded its cloud-based Menlo Agent Runtime Security platform to protect AI assistants and coding agents from prompt injection attacks and data exfiltration. The platform routes agent web traffic through a cloud environment to sanitize files and strip hidden instructions before an agent receives the content. Adaptive data loss prevention controls mask sensitive information, while token-based authentication assigns per-agent session identity to enforce specific web access policies. 

Mimecast unveils Agent Risk Center and Managed Threat Response

Mimecast announced a new expansion of its Incydr technology that discovers every AI agent and tool operating across an organization and ties each one back to the human who deployed it. The platform will also include a relaunched Managed Threat Response (MTR) service and expanded Google Workspace integrations.

Palo Alto Networks introduces evolution of PAN-OS and publishes research

Palo Alto Networks announced a new PAN-OS purpose-built for the Frontier AI era. PAN-OS 12.2 Ceres introduces Advanced Virtual Patching, automated blocking for direct-to-IP attacks, six AI security agents, and expanded hardware for securing AI data centers and critical infrastructure. Palo Alto Networks Unit 42 has also released new threat research detailing how an AI system built by its researchers uncovered more than 14,000 previously unknown vulnerabilities across nearly 4,000 widely used open source projects; and how analysis of more than 4 million reports found that 45.32% of malware with C&C activity communicates directly with IP addresses.

Prophet Security research on AI in Security Operations 

Prophet Security has released its second annual State of AI in Security Operations report. An independent survey of 250 IT and cybersecurity professionals finds that security operations teams are reaching a breaking point as alert overload, AI-powered attacks and staffing shortages force organizations to rethink how SOCs operate. According to the report, 96% of organizations are already using AI or actively evaluating AI for security operations, organizations leave an average of 28% of security alerts uninvestigated, and 56% report an increase in AI-driven attacks over the past year.

Proofpoint announces OEM Program

Proofpoint announced an OEM Program: a portfolio of OEM-ready threat intelligence and detection capabilities available for technology providers, cybersecurity vendors, managed service providers, and platform companies. The program cuts the time, cost, and operational lift of building threat intelligence capabilities from scratch, helping partners accelerate product roadmaps and bring differentiated offerings to market faster.

Rubrik adds agent identity controls to Agent Cloud

Rubrik expanded its Agent Cloud platform with Rubrik Agent Identity to manage autonomous AI agent access permissions at runtime. The solution eliminates standing credentials by generating short-lived, scoped tokens for individual tool calls and integrating with identity providers (including Okta and Microsoft Entra ID). Before execution, tool requests pass through a gateway that conducts semantic behavioral analysis, verifies infrastructure access policies, and authenticates session identities.

ServiceNow announces new security solutions and AI Center for Cyber Defense

ServiceNow launched six unified solutions that deliver prevention-first, AI-native cyber defense across unified exposure management, identity and access security, cyber-physical security, cyber risk and compliance, and agentic incident response. ServiceNow also unveiled its newly formed AI Center for Cyber Defense, a global hub for security innovation.

SOCRadar launches Human Identity Exposure

Threat intelligence company SOCRadar announced the launch of Human Identity Exposure, a new Identity & Access layer for its Extended Threat Intelligence (XTI) platform that gives analysts an instant, comprehensive snapshot of an individual’s identity risk. SOCRadar Human Identity Exposure unifies fragmented identity exposure data, including breach repositories, stealer infections, attacker telemetry, PII, data leaks, and CTI signals into a single, decision-ready record. 

Surf AI announces new integration and platform expansion 

Surf AI announced an integration with Claude’s Compliance API, alongside the general availability of Exposure Reduction Operations, extending the platform to govern AI model connectivity alongside identity, cloud, and SaaS exposures. The integration pulls activity logs from the Claude environment, maps the connection and access path to an accountable owner inside the Context Graph, and operationalizes remediation, including disabling unsanctioned MCP integrations and lingering Claude access after offboarding.

Tenable debuts open source AI agent exchange and expands AI risk coverage

Tenable launched CyberAgents Exchange, a free, open source AI agent exchange built for cybersecurity teams. It is a vendor-agnostic community where security professionals can discover, share and build trusted AI agents, skills, MCP servers and multi-agent playbooks, backed by code-level transparency into who built what and how it works. Founding members also include SentinelOne and Recorded Future. The company also unveiled new Tenable One AI Exposure capabilities that expand coverage across every major AI platform and key developer tools. 

Thales releases Luna 8

Thales released Luna 8, its first in-house designed hardware security module made to secure, store, protect, and manage cryptographic keys against quantum threats. The system features an upgradeable architecture to integrate future cryptographic algorithms while maintaining backward compatibility with existing interfaces and ancillaries. Delivered on a unified hardware platform, the appliance is undergoing independent evaluation for FIPS 140-3 Level 3 and EU Common Criteria standards.

Trustmi announces new AI investigation agent and new payment fraud threats

Trustmi unveiled an AI Investigation Agent that is purpose-built for B2B fraud detection. It introduces agentic workflows that investigate suspicious activity, reasons across business workflows, and connects evidence across systems. The company also announced the discovery of two emerging payment fraud threats: Ghost Executive, an attack in which fraudsters fabricate an executive’s approval so the payment looks like a decision has already been made; and Deadline Deception, which pairs fraudulent paperwork with a false deadline to pressure employees into releasing funds. 

VanishID adds AI exploitability management and external identity protection control

VanishID announced AI Exploitability Management and External Identity Protection. Operating externally without internal system credentials or installations, AI Exploitability Management breaks down over 40 attack scenarios to calculate individual risk scores based on public data availability. Complementing this tool, External Identity Protection deploys four categories of autonomous agents (detection, analyst, remediation, and residual risk) to scan data brokers, dark web repositories, and public records. Automated remediation agents submit and verify opt-out requests to erase public profiles.

https://www.securityweek.com/black-hat-usa-2026-summary-of-vendor-announcements-part-3/




The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict

Cyberspace is now the fourth domain of military conflict.

Geopolitics can be summarized as the behavior of a country or region influenced by its location in time (history and current events), and space (geographical proximity to other countries or regions). Those geopolitical actions are also influenced by the state of the economy and the psychology of its leaders. 

Geopolitical disagreements between countries are usually settled by diplomacy but sometimes by physical force of arms. The latter is usually a kinetic war involving, as necessary and available, land (an Army), air (an Air Force) and the sea (a Navy).

Over the last few decades, cyberspace has been increasingly co-opted into these conflicts as a fourth force. This article is a discussion on the confluence and effect of using adversarial cyber activity to support kinetic force of arms in solving geopolitical conflict. It is, in short, a discussion on geopolitics and cyberspace.

Background

In the modern world there are three types of warfare: kinetic war (traditional ‘boots on the ground’ physical conflict involving armed forces and usually preceded by cyber operations); cyberwar (aggressive cyber operations); and cyber-kinetic (cyber operations that result in physical damage). All three are generally motivated by politics or geopolitical differences, which makes the intersection of geopolitics and cyberspace an important study.

The three primary geopolitical motivations for nation state cyber operations in support of geopolitical differences are espionage, a desire for regime change, and territorial disputes. In each case the cyber activity has become a common precursor to kinetic activity.

Advertisement. Scroll to continue reading.

In broad terms, nation state activity is ideologically East versus West. The East is primarily China, Russia, Iran and North Korea (CRINK for short). The West is primarily North America, UK, EU, and the remaining members of the 5Eyes (Australia and New Zealand).

Nation state geopolitical cyber operations differ in motivation and practice from simple criminal activity. Criminal activity is motivated by monetary gain. The desire is to achieve this with as much speed and as little cost as possible. Being noisy is not a problem if you can get in, grab what you want, and leave as quickly as possible.

Nation state activity is very different. It is low and slow. Stealth and continuous dwell time are important. “If you detect nation state actors on your network,” comments Dmitri Alperovitch, “chances are they have already been there for weeks or months.” 

Alperovitch was a co-founder of CrowdStrike, is a renowned expert on geopolitics and cyberspace, and is author of World on the Brink. He spoke to SecurityWeek about the intersection of geopolitics and cyberspace, and provided invaluable thoughts and insights.

Cyberspace and espionage

Nation state espionage alone is not generally considered to be war, although it is often a prelude to, or part of, war. It has been practiced for as long as civilization has existed. There are records from ancient Mesopotamia (perhaps 4,000 years ago). The Amarna Letters (14th century BCE) from Ancient Egypt provide diplomatic and intelligence correspondence inscribed on clay tablets. More recently, approximately 2,500 years ago, Sun Tsu’s The Art of War has a chapter titled ‘The use of spies’ treating espionage as the foundation of military activity.

Cyber, however, now raises espionage to a new level of scale and purpose. Its motivation is as often economic as it is military. Nation states use cyber espionage to monitor other nations’ military capabilities and where possible steal military secrets, but also now to steal intellectual property from foreign enterprises. The latter means that commerce as well as the military must protect against nation state low and slow incursions. 

Every nation with a cyber capability is engaged in cyber espionage. The West, with the Five Eyes (FVEY) alliance, is probably the better actor. 

“It’s an intelligence alliance (US, Canada, UK, Australia and New Zealand) that evolved from the work of Alan Turing and Bletchley Park during the Second World War,” comments Alperovitch. It started as a signals intelligence alliance collecting from airwaves and detecting radio signals, but its activities have broadened into cyber espionage. 

“NSA, GCHQ, and the other countries in the alliance are now using cyber to accomplish national security priorities – which is the collection of intelligence on our adversaries. So, yes, we’re doing that. And I think we’re the best in the world at it.”

What we don’t do, he continues, “We don’t steal intellectual property from private companies for the benefit of our own industries. That’s what China does.”

A hypothetical example could be drawn with AI. AI will be seriously important in the future, militarily, sociologically, and economically. It is to be expected that both sides are already surveilling the state of AI in the other. Five Eyes might wish to watch DeepSeek-like companies for intelligence purposes; but that’s all. Beyond intelligence, China, however, might wish to watch, and exfiltrate, Anthropic-like intellectual property – and pass that IP on to its own DeepSeek-like AI enterprises. Other CRINK nations would do similar.

There are additional behaviors that CRINK might engage in that Five Eyes does not. “We don’t engage in ransom operations or theft of currency and cryptocurrency as North Korea does. Our operations follow the rule of law, both domestic and international. The operations are designed generally to not be escalatory unless we’re in a military conflict, in which case, anything goes.”

The last comment is interesting and explains the difficulty in understanding the role of cyberspace in geopolitics. When, exactly, can two nations be defined as ‘at war’? It used to be the presence of opposing armies on a battlefield, or a formal declaration of war between nations. 

However, since 2011 in the US, and 2016 in the rest of NATO, cyber is officially a military domain, and cyberspace is therefore a potential battlefield. In the US, Cyber Command was ordered by Secretary of Defense Robert Gates in 2009 and became operational within Strategic Command in 2010 before becoming an independent unified combatant command in 2018.

The logical implication of this process is that the moment one nation engages in cyber espionage against another nation on the cyberspace battlefield, the two nations are effectively at least at military quasi-war with each other.

But “We’re not going to go [full kinetic] war over espionage, because everyone does it,” adds Alperovitch. If espionage led to war, the world would have been at continuous war since ancient Mesopotamia.

Nevertheless, his earlier qualification (‘unless we’re in a military conflict, in which case, anything goes’) marks a major change in the role of cyberspace that comes to a head when kinetic conflict has either started or is inevitable.

Cyberspace and kinetic conflict

There are two primary causes for kinetic war: regime change and territorial disputes. In both cases, any kinetic activity is generally preceded by or concurrent with aggressive cyber activity. Cyber activity is unlikely to ever win kinetic wars – its purpose is to prepare for, support, and hasten a kinetic victory. 

There are two recent examples of attempted regime change (Venezuela and Iran), and two examples of territorial disputes: Russia with Ukraine, and China with Taiwan. 

Venezuela. Nicolás Maduro, then president of Venezuela, was arrested and removed from Venezuela through a kinetic US operation on January 3, 2026. This operation was almost certainly, and is commonly believed, to have included a cyber element, if only pre-kinetic espionage intelligence gathering. Operational support (possibly in assisting the power blackout that was part of the extraction) is likely, but unproven. This is not surprising – US intelligence would avoid disclosing any cyber access to Venezuelan networks in case it is needed again in the future.

In a press conference following the operation, General Dan Caine (chairman of the joint chiefs of staff) specifically mentioned Cyber Command as part of the layering of ‘different effects’ leading up to the operation.

Maduro was arrested and extracted to face charges related to ‘narco-terrorism’ and is currently being held in New York. The primary purpose of the extraction was, however, to effect regime change, prevent future narco-terrorism, and give the US greater influence over Venezuelan oil. It succeeded only in oil, where the US now has considerable influence. 

It failed in preventing the flow of narcotics into the US since Venezuela was a transit route for narcotics produced elsewhere (primarily Colombia). And it failed to effect regime change. The current ‘acting’ president is Delcy Rodríguez, previously Venezuela’s Executive Vice President. Officially, her position is that Maduro is still the legal and rightful president.

Iran. Epic Fury and Roaring Lion were respectively the joint US and Israeli combat missions launched on February 28, 2026, against Iran. The primary purposes were to destroy Iran’s potential to develop nuclear weaponry and to effect regime change to prevent any continuing desire for nuclear weaponry. Cyber activity was an important component at the launch of kinetic action.

Cyber operations degraded Iran’s radar grids to allow the initial wave of US and Israeli airstrikes. These were remarkably successful, including killing supreme leader Ayatollah Ali Khamenei. Many of the top military leaders were also killed. It is believed that cyber espionage played a part in knowing precisely when and where they were located. 

The initial kinetic action amounted to regime decapitation that would hopefully lead to the rise of a new regime. Psychological cyber operations were used to deliver anti-regime messaging and normal state media, government communication lines, and public apps were all targeted, hoping that the Iranian people would rise up against the Iranian government. This didn’t happen. Despite the success of the ‘remote’ kinetic action against Iranian military capabilities, Iran continues.

Iran has retaliated with its own kinetic activity against US and Israeli regional allies, and with its own cyberattacks against the US. On July 22, 2026, CISA warned that Iranian actors were exploiting ‘programmable logic controllers across US critical infrastructure’. 

This war is ongoing. At the time of writing, it is four months and four weeks since the commencement of kinetic activity. It has involved action in the air, on the seas, and in cyberspace – but not specifically on the ground. Ground forces are not currently involved. The implication here is that cyber activity can assist in areas of kinetic activity, but cannot ultimately succeed without human boots, troops, on the ground in the battlefield.

Cyberspace and territorial disputes

We have two examples of major geopolitical territorial disputes. One involves an ongoing war – in Ukraine. The second dispute is over Taiwan. China insists it is part of China. Taiwan and much of the West disputes this. There is, again at the time of writing, no kinetic war in or for Taiwan. However, if we accept that the role of cyber in geopolitics is to prepare for and assist in kinetic warfare, there are worrying signs.

Ukraine. On February 24, 2022, Russia invaded Ukraine. This was fundamentally a territorial dispute. Putin, that is Russia, considered Ukraine to be part of the Russian empire. He wished to return Russia to the preeminence it had in the USSR prior to the collapse that ended the Cold War. Ukraine disagreed.

Other factors played into this dispute. Historically, Ukraine and Russia have always been linked. When Zelensky came to power, he spoke Russian more fluently than Ukrainian.

Ukraine is effectively a buffer between Russia and its adversary NATO and the EU. Ukraine, however, displayed distinct preferences toward NATO and indicated a wish to join the EU in the future. Putin felt he had no option but to force Ukraine back into the Russian fold. 

Physically attempting to do this started almost exactly eight years before the current ongoing war in mainland Ukraine when Russia took Crimea.

On both occasions he employed the now textbook style of first disrupting the enemy via cyberspace. For Crimea, a cyber espionage campaign dubbed Operation Armageddon and targeting government, law enforcement, and defense agencies was conducted from 2013. Ukraine attributed it to the FSB. 

Russian malware, including Snake and Uroburos (closely related malware) that was developed and distributed by the Turla APT group, was used against Ukrainian government systems. 

As the kinetic invasion began, Russian special forces and cyber units raided Crimean telecommunications centers and cut communication between Crimea and mainland Ukraine, disrupted government phones, and DDoSed government websites, news outlets and social media.

Three months prior to the later invasion of mainland Ukraine in 2022, in late 2021, Alperovitch had declared that kinetic war was inevitable. “What convinced me,” he told SecurityWeek, “was what I was seeing in the cyber domain. Not exclusively – there was a buildup of Russian forces and rhetoric from the Russian government – but I was also seeing cyber intrusions into Ukrainian systems unlike any that I had seen since Crimea in 2014. This was a clear indication that Russia was again preparing for a full scale invasion.” 

He believes that aggressive cyberactivity is effectively a ‘canary in the coalmine’ warning on imminent kinetic warfare.

In some ways, Russian activity never ceased after 2014, with long running Sandworm (GRU Unit 74455), APT28 / Fancy Bear (GRU Unit 26165), and Gamaredon (FSB‑linked) campaigns. 

However, cyber activity escalated dramatically immediately prior to the 2022 invasion. Ukrainian government websites were defaced using WhisperGate. HermeticWiper struck hundreds of systems across Ukrainian financial, defense, aviation, and IT sectors. A second wiper (IsaacWiper) targeted government networks. And as the invasion began, a cyberattack disrupted Viasat’s KA-SAT satellite network, disabling thousands of modems across Ukraine and Europe, but more specifically severely degrading Ukrainian military C2 capabilities.

Kinetically, Ukraine (supported by the US and the EU, has proven remarkably resilient. Four years into the war (again at the time of writing) Russia has not succeeded in its kinetic invasion. While the cyber activity did what it was designed to do, history again suggests that cyber can assist kinetic but cannot guarantee kinetic success.

Taiwan. A second territorial dispute exists today, with China insisting that Taiwan is part of mainland China. Like Ukraine with Russia, Taiwan disagrees, insisting it is an independent island nation. But just as an independent Ukraine inhibits Russian influence eastward, so an independent Taiwan off the eastern coast constrains China’s strategic freedom of action across military, economic, diplomatic, and informational domains in the Pacific region.

While there is currently no specific kinetic activity from China, there is massive cyber hostility targeting Taiwan that has been ongoing for years. There is also massive Chinese pre-positioning in western critical industries. This latter is not a precursor to a Chinese kinetic invasion of the US, but more likely a defensive position to disrupt the US in interfering in any kinetic action against Taiwan.

China’s Volt Typhoon is an example, combining pre-positioning with living-off-the-land for stealth. It has been operating for years, quietly embedding itself inside utility sectors, including communications, energy, transportation, and water systems. The belief is this is designed to give China the ability to disrupt critical services in the event of a future crisis. That crisis could be any US reaction to an invasion of Taiwan.

All of this is necessary because of the importance of Taiwan to western economy. Unlike Ukraine, which has little direct relevance to the US if lost to Russia, Taiwan is critically important to US technology companies. It supplies around 90% of the world’s most advanced chips. 

Without Taiwan’s fabrication capacity, it is unlikely that companies like Apple, AMD, Google or AMD would be able to manufacture the processors they use; and the progress of AI would be inhibited by difficulties in building the necessary data centers. It would take many years and many billions of dollars for the US to build its own industry to replace Taiwan’s current capacity.

For this reason, the US is more aggressive in its support for Taiwan than it is in support of Ukraine. We do not know if this support is preventing a Chinese kinetic invasion of Taiwan or merely delaying it. It’s certainly not stopping China’s desire to take Taiwan. China wants Taiwan, and the US doesn’t want it to have Taiwan.

Interpretation of what is really happening is all conjecture. Is China ramping up cyber activities to force the US to be less reliant on Taiwan? If that were to happen, US defense of Taiwan might relax, enabling China to absorb Taiwan with less difficulty. Or should we see this aggressive cyberactivity as an indication of Alperovitch’s ‘a canary in the coalmine’? Only time will tell. The longer it takes for China to invade Taiwan, the less dramatic it will be. But if China were to invade Taiwan tomorrow, all bets are off.

Summary

The four examples of Venezuela, Ukraine, Iran and Taiwan demonstrate that over the last 15 years, cyberspace has become deeply embedded in geopolitical military actions around the globe. Nowhere, at least so far, has cyber activity done more than assist kinetic military force. The only successfully completed kinetic action was the arrest of Maduro in Venezuela, which involved boots on the ground. Boots on the ground have so far been excluded from the Iran war, and nobody seems to know what will happen without them. But there have been boots on the ground in Ukraine for the last four years, and there is still no winner.

Neither successful cyber activity nor greater force on the ground guarantees a successful kinetic operation – but there is little doubt that cyberspace and ground force will continue hand in hand in the future. Taiwan is a big concern. The geopolitical peculiarities of this situation suggest that any future kinetic conflict will be, for the first time, between two major powers each with nuclear capabilities.

We must hope that for Taiwan, geopolitical hostilities between East and West remain in cyberspace.

Related: China Admitted to Volt Typhoon Cyberattacks on US Critical Infrastructure: Report

Related: The Impact of Geopolitics on CPS Security

Related: Geopolitics Will Drive Aggressive Cyber Activity Throughout 2020

Related: The Increasing Effect of Geopolitics on Cybersecurity

Related: Understanding Geopolitics Key to Analyzing Cyber Espionage: German Intelligence Service

https://www.securityweek.com/the-fourth-battlefield-the-growing-role-of-cyber-operations-in-global-conflict/




New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts

Palo Alto Networks researchers have disclosed the details of new attack methods targeting passwordless authentication, showing how malware can hijack a passkey-protected account.

Passkeys are increasingly adopted by tech giants and are widely recommended because they are more secure against phishing.

The new attack methods, named ‘Pass-ta-key’ by Palo Alto Networks, focus on Google-synced passkeys. The security firm’s researchers showed how a threat actor could use the techniques to take over accounts without needing privilege escalation or user interaction.

In a Pass-ta-key attack, malware already present on a Windows machine running Chrome can examine the browser’s local synchronization database to identify which online accounts the user has protected with passkeys, along with associated usernames and encrypted credential material.

The malware recovers a device identity key that Chrome stores on disk or in memory. It then uses Windows cryptographic APIs to generate a signature over a challenge received from Google’s cloud authenticator service, without any biometric prompt, device unlock, or elevated privileges. 

The cloud service treats the signed request as coming from a legitimate trusted device. It returns a valid authentication assertion, which the attacker forwards to the target website to complete the login.

Advertisement. Scroll to continue reading.

In a more advanced variant, dubbed ‘Silver Pass-ta-key’, the malware forces Chrome into a device re-registration process. During a short window in that process, it registers its own user-verification key with the cloud authenticator. Once registered, the attacker can later authenticate from a completely different machine.

The most severe technique, ‘Golden Pass-ta-key’, extracts a master secret that briefly appears in Chrome’s process memory during re-enrollment. Possession of this secret allows the malware to decrypt every synchronized passkey private key belonging to the account, enabling the attacker to decrypt future passkeys as well.

Google has been notified and Palo Alto Networks’ blog post indicates that it has rolled out some mitigations. 

Related: Passkey Login Bypassed via WebAuthn Process Manipulation

Related: TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover

Related: Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

https://www.securityweek.com/new-attack-methods-enable-malware-to-hijack-passkey-protected-accounts/




311,000 Impacted by Brown Health Medical Group-MA Data Breach

Lifespan Physician Group of Massachusetts, doing business as Brown Health Medical Group-MA, is notifying over 311,000 individuals that their personal, medical, and financial information was stolen in a data breach.

The incident occurred in December 2025 at its Hawthorn location. It involved a historic file server, the healthcare organization says in a sample notification letter filed with the Massachusetts Office of Consumer Affairs and Business Regulation.

While the practice’s electronic health record system was not affected, Brown Health Medical Group-MA determined on June 22, 2026, that the attackers accessed files containing personal information.

The potentially compromised information, it says, includes names, contact information, dates of birth, Social Security numbers, driver’s license numbers, government ID numbers, medical and disability-related records, financial account information, and credit/debit card numbers.

Personnel and human resources records, including payroll and compensation information, and licensure or credentialing information, were also compromised.

“Not all categories of information were impacted for all individuals,” Brown Health Medical Group-MA says.

Advertisement. Scroll to continue reading.

The healthcare organization says it isolated the affected server immediately after identifying the incident, has implemented additional safeguards, and is re-training its employees.

Brown Health Medical Group-MA notified the US Department of Health and Human Services (HHS) that 311,760 people were affected by the data breach. Of these, 290,357 are Massachusetts residents.

The organization is providing the impacted individuals with two years of free fraud detection and identity protection and restoration services.

Brown Health Medical Group-MA has not named the threat actor behind the attack, and SecurityWeek has not seen any known ransomware or extortion groups claiming responsibility for the incident.

Related: 150,000 Impacted by Madera Community Hospital Data Breach

Related: Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations

Related: River Bank Says Hackers Deleted Data Stolen in Ransomware Attack

Related: Brinks Home Discloses Data Breach as Hackers Leak Files

https://www.securityweek.com/311000-impacted-by-brown-health-medical-group-ma-data-breach/




Mobile Application Security Fails to Match Levels of AI Use

A recent report by NowSecure analyzed current mobile application security risks. The report found that 95% of organizations report AI capabilities in their mobile applications. Generative AI is the most widespread use case at 81%, followed by AI agents at 71%. Seventy-four percent report having a formal AI governance policy. Yet 37% have not implemented AI behavioral monitoring as a security control.

According to the report, 68% of surveyed organizations report that more than half of their mobile application code consists of third-party software development kits (SDKs) and libraries. As a result, many enterprises are deploying apps built mostly with third-party code that may not have been fully assessed before deployment.

Organizations whose apps contain more than 505 third-party code experienced security incidents at more than double the rate of organizations whose apps contain less than 50% third-party code. Yet 49% always assess SDKs for security or AI-related risks before release. Mobile security leaders increasingly identify SDKs and partner integrations as among the most difficult parts of the attack surface to manage.

Download the report.

https://www.securitymagazine.com/articles/102459-mobile-application-security-fails-to-match-levels-of-ai-use




Majority of Organizations Lack Drone Mitigation Due to Legal Restrictions

New research by DroneShield finds that unauthorized drone activity has moved well beyond a theoretical threat, according to international airports, aviation authorities, correctional facilities, and port operators across North America, Europe, Africa, Asia, and the Middle East. The report found that 70% of respondents identified detection capability gaps as a barrier to effective counter-UAS operations.

According to the report, 60% of respondents also indicated that they lack the legal authority to take direct mitigation action against unauthorized drones, even when the threat to safety is clear and immediate. Other reasons cited as barriers to effective counter-UAS operations include integration complexity (at 48%) and training and preparedness (35%).

Respondents were also asked to describe their organization’s counter-UAS operational objectives:

  • Full combination (Awareness + Detection + Tracking + Response): 57%
  • Detection-focused (Partial): 13%
  • Awareness only: 13%
  • Undefined / No formal plan: 17%

In particular, 17% of respondents with no formalized counter-UAS plan represent a specific and acute risk: organizations that will be managing a drone incident for the first time during the incident itself, with no established procedures, no clear escalation pathway, and no baseline situational awareness from which to act.

Download the report.

https://www.securitymagazine.com/articles/102460-majority-of-organizations-lack-drone-mitigation-due-to-legal-restrictions




Building Public Trust in AI‑Enabled Security

All the coordinated efforts we accomplish in society — the bridges we build, the discoveries we make, even the games we play — are contingent on trust. Trust in the sciences and education keeps us curious and informed, trust in the governing bodies we elect makes us feel represented and confidence in our authorities and emergency responders helps us feel safe when a crisis strikes.

One of the central tenets of trust is knowledge. For an individual to receive, believe and act upon information, they must have faith in the way it was gathered. Despite its widespread adoption in industrial and personal contexts, only 66% of people use AI, and only 46% trust it. For the public to be more willing to accept the presence of AI in security platforms and processes, further work is needed to clarify how it can enhance human accountability while operating within defined safeguards, even more thoroughly than the way newer systems address concerns about auditability and transparency.

The Trust Gap and its Causes 

Although public-facing LLMs such as ChatGPT and Perplexity are ubiquitous, they are most commonly used to address personal issues. Asking a chatbot to create a shopping list or provide feedback on an interpersonal issue requires a degree of trust, but frequent users commonly observe how often these models make mistakes in low-risk situations like these.

However, the AI agents and systems involved in security, policing and emergency response are far more complex than most members of the public can access. As these technologies are built with such unique purposes and functionalities in mind, they fall into the larger blind spot of AI illiteracy. System specs do little to sway public perception when people’s objections concern fundamental rights and safety, such as:

Overall, the general public strongly supports greater AI regulation. 87% of the public favors laws that combat AI-generated misinformation and only 43% believe current legislation is adequate. 

Trust issues also become exacerbated when someone who lacks AI literacy reaches a position of power. Many respondents in the KPMG study cited above either misused AI or observed a coworker doing so, such as by uploading sensitive personal or company information to public chatbots. 

Machine learning is complex, and navigating a company’s terms and conditions can be even harder. Available findings indicate that there’s a strong need for internal and external AI education to evangelize the kind of knowledge that’s vital to building trust.

The Reality of Operations  

AI agents in security and public services have become productivity tools that enable staff to meet administrative demands and return to proactive work. Public safety and security agencies have been using them more frequently, primarily because of labor shortages and increasing workloads.

Police officers are deskbound 30–40% of the time to write reports and launch enquiries, but AI agents can reduce this time substantially by aggregating data and providing additional context that would otherwise require hours to gather manually. They’re not generating anything new; rather, this work is more closely related to the type of data analysis from which machine learning originated.

Popular applications of AI in traditional security settings include smart cameras that use adaptive algorithms to spot patterns that deviate from expected behavior. They can help:

  • Observe when staff aren’t following PPE requirements
  • Alert security teams of potential loitering or the presence of suspicious packages
  • Reduce time spent staring at monitors

Again, we can see that these systems are built to augment human activities, not to autonomously make decisions for individuals. Building public trust in AI requires frequently reiterating that humans remain firmly in the loop at all times. 

Visible Safeguards Are About more than Optics

Security systems with AI agents can reach the point where they are safer on average than those with humans alone, but it will not matter to the general public if transparency is not built in at a structural level. The observation of national and international data protection laws provides a baseline of trustworthiness, but as more people call for stricter regulation of the technology, it becomes increasingly necessary to exceed public expectations. 

Some applications of AI, such as those seen in policing and security, draw information from multiple sources, helping to mitigate fear of bias. Beyond this, such systems must take strong and open stances on: 

  • Strong data retention and minimal collection policies
  • Clearly defined use cases and user controls
  • Accessible audit trails and access logs 

To aid the building of public trust surrounding the implementation of AI technology, the public’s primary concerns must be addressed. Currently, many people share sensitive information with public chatbots without understanding how that data is stored or used.

Building trust requires a different path. By maintaining human-led oversight and strict data governance, our AI serves as a transparent and accountable partner in public safety. We aren’t just following the conversation on AI ethics; we are setting the standard for how it is applied to protect our world.

https://www.securitymagazine.com/articles/102456-building-public-trust-in-aienabled-security




Claude evade (di nuovo) e compromette tre aziende reali


Sembra proprio che tenere a bada i modelli IA sia complicatissimo e Anthropic sta accumulando una certa esperienza nel settore. L’azienda ha infatti rivelato che alcuni modelli della famiglia Claude sono riusciti ad accedere ai sistemi di tre organizzazioni reali durante esercitazioni di sicurezza, trasformando test che avrebbero dovuto svolgersi in ambienti controllati in vere e proprie compromissioni di sistemi esterni.

Non è stato un attacco deliberato

Anthropic precisa che non si è trattato di un comportamento malevolo intenzionale del modello, né di un tentativo di “ribellione” dell’intelligenza artificiale. Le prove delle compromissioni, infatti, sono emerse durante la revisione interna di oltre 141.000 valutazioni di sicurezza avviata dopo il recente incidente che aveva coinvolto OpenAI. L’analisi ha portato alla scoperta di tre casi nei quali versioni di Claude erano riuscite a raggiungere Internet da un ambiente di valutazione gestito da terze parti e ad accedere senza autorizzazione ai sistemi di tre differenti organizzazioni. Anthropic specifica che il problema è stato favorito da una combinazione di errori umani, configurazioni errate dell’ambiente di test e vulnerabilità reali presenti nei sistemi raggiunti dal modello.

Tre incidenti diversi, un unico denominatore

I modelli coinvolti comprendono Claude Opus 4.7, Claude Mythos 5 e un modello sperimentale interno e quello che rende il tutto più “pepato” è che le dinamiche dei tre episodi sono differenti. In un caso il modello ha confuso il dominio di un’azienda reale con quello previsto nello scenario di laboratorio, riuscendo così ad accedere a un database esterno. C’è da dire che, probabilmente, chi ha organizzato il test non ha verificato che il nome dell’azienda “fasulla perché inserita nel test” fosse inesistente. In un secondo episodio è statp eseguito un attacco alla supply chain attraverso la pubblicazione di un pacchetto Python malevolo sul repository pubblico PyPI che è stato successivamente scaricato da alcuni sistemi reali. Nel terzo incidente il modello ha iniziato a esplorare migliaia di server connessi a Internet e stava per sfruttare una vulnerabilità SQL Injection, interrompendo però autonomamente l’operazione quando ha riconosciuto di trovarsi al di fuori dell’ambiente previsto dal test. Anthropic attribuisce questi episodi principalmente a carenze operative nella gestione delle esercitazioni piuttosto che a un fallimento dei meccanismi di allineamento del modello. In effetti, i modelli hanno fatto il loro dovere, ma si deve evidentemente ancora lavorare su come tenerli a bada.

Il vero problema è il contenimento

Le aziende stanno investendo enormi risorse per misurare le capacità offensive dei nuovi modelli AI, ma questi incidenti mostrano che la sicurezza dell’ambiente di valutazione è importante quanto quella del modello stesso. Un agente capace di operare autonomamente, usare strumenti, accedere alla rete e prendere decisioni e metterle in pratica può infatti sfruttare qualsiasi errore di configurazione presente nell’infrastruttura di test: il rischio non nasce esclusivamente dall’intelligenza artificiale, ma dall’interazione tra modello, strumenti disponibili e ambiente operativo.

Mythos torna al centro dell’attenzione

Tra i modelli coinvolti figura anche Claude Mythos, il sistema che Anthropic ha deciso di non distribuire pubblicamente proprio a causa delle sue elevate capacità offensive in ambito cyber e molti ricorderanno che non è la prima volta che Mythos finisce al centro delle cronache. Già nei mesi scorsi il modello era stato protagonista di almeno altri due episodi che avevano alimentato il dibattito sulla sua gestione. Il primo riguarda la fuga non autorizzata di alcuni accessi alla versione preview del modello, comparsi poche ore dopo il suo annuncio all’interno di una comunità privata online. Anthropic aveva confermato che utenti non autorizzati erano riusciti a usare il sistema, pur trattandosi di una versione destinata esclusivamente a un ristretto gruppo di partner del progetto Glasswing.

Il secondo episodio è emerso dalla Hazard-Aware System Card pubblicata dalla stessa Anthropic. Durante prove di laboratorio dedicate alla verifica delle misure di contenimento, una versione sperimentale di Mythos era riuscita ad aggirare alcune restrizioni del sandbox, comunicare verso l’esterno e mettere in atto comportamenti inattesi, come modificare file cercando di nascondere le modifiche nella cronologia Git. Anche in quel caso l’azienda aveva sottolineato che gli eventi erano avvenuti in ambienti di test controllati e avevano contribuito a rafforzare le misure di sicurezza del progetto.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2026/08/04/claude-evade-di-nuovo-e-compromette-tre-aziende-reali/?utm_source=rss&utm_medium=rss&utm_campaign=claude-evade-di-nuovo-e-compromette-tre-aziende-reali