The Zero-Knowledge Threat Actor and the End of Responsible Disclosure

One of the most dangerous outcomes of the rise of AI in cybersecurity is the rise of the zero-knowledge threat actor. A threat actor who has negligible technical expertise but enough malicious intent. This actor can leverage AI, turn limited skills into usable offensive capability via generating malicious code, exploiting vulnerabilities, shaping attack steps and guiding execution.

AI Has Changed the Nature of Attacks

AI has not changed the traditional objectives of cybercrime:  stealing credentials, exploiting vulnerabilities, gaining privileged access, stealing sensitive data, disrupting operations, and impacting business continuity. What has changed is the speed of discovery, the democratization of capability, and the acceleration of attacks.

AI is making hidden software weaknesses easier to find. AI-powered tools are increasing the speed and volume of vulnerability discovery and exploitation, while vulnerability exploitation has surged to become the leading initial access vector for breaches, accounting for 31% of incidents, according to Verizon’s 2026 Data Breach Investigations Report (PDF). AI has also ensured that more people can participate in attacks regardless of expertise, attack preparation times are more compressed, and it is far easier to adapt attack campaigns quickly to cover more targets, environments, and defensive responses.

Zero-Knowledge Actors Have More Scope

AI can help attackers generate malware, create malicious payloads, bypass simple security checks, and convert vague malicious intent into functional code. These capabilities are no longer in the realm of speculation.

Advertisement. Scroll to continue reading.

But as AI is evolving, new risks are entering the chat. AI can now also support target analysis, reconnaissance, vulnerability surfacing, attack-vector selection, social engineering, exploit modification, and the integration of various kill chain aspects through multi-stage orchestration.

This is shifting the capability baseline, with organizations now having to defend against adversaries who may lack deep technical knowledge but can use AI to plan more steps, test more options, and execute attacks that were previously beyond their reach.

While human judgment is still involved in choosing targets, managing infrastructure, and turning access into impact, the threshold of expertise is clearly changing.

Easy Entry Points for Zero-Knowledge Attackers

Large enterprises are targets for attackers, but smaller organizations are better suited to zero-knowledge threat actor attacks. A weak patching culture, limited monitoring tools, a lack of a very large security team, and delayed incident response are among the security gaps that make smaller organizations easy targets. 

These smaller organizations are also part of larger business ecosystems, integral to their supply chains, and function as software providers, managed services partners, logistics providers, and more. For zero-knowledge threat actors, it is natural to see small organizations as initial targets that serve as doorways to a larger organization.

The Shrinking Disclosure Window

‘Zero-day’ refers to a vulnerability that is publicly exploited before a vendor patch exists. Coordinated vulnerability disclosure begins the moment a researcher privately notifies a vendor of an identified flaw. Between that initial notification and public disclosure lies a structured process: validating the vulnerability, assessing its severity, building a patch, coordinating with affected parties,and giving users enough time to apply the patch.  

Different organizations will have different responsible disclosure timelines, but irrespective of these timelines, there is no doubt that zero-knowledge threat actors are putting immense pressure on the disclosure window. These AI-enabled actors can not only discover vulnerabilities quickly but also exploit them faster. The security team, therefore, has to act quickly. The traditional breathing room is disappearing, which, in turn, is affecting responsible disclosure.

Responding to Zero-Knowledge Threat Actors

The first thing you must do to address zero-knowledge threat actors is not take them lightly. In fact, AI support has made them very dangerous and unpredictable. This should be the starting point of your defensive posture:

  • Employee Awareness: Give employees a drill-down security awareness training focusing on AI-enabled phishing messages, impersonation attempts, and social engineering campaigns. Expose employees to realistic simulations of AI-generated phishing attacks, so that they don’t trust even hyper-personalized messages by default.
  • Red Teaming: Your AI systems must be tested against malicious prompts, jailbreaking, and all manner of misuse scenarios.  With attackers getting better at leveraging AI to probe AI systems, testing will tell you whether your AI systems can be manipulated or made to expose sensitive information.
  • End-to-End Visibility: Zero-knowledge threat actors have been known to harness AI to test different attack paths, bring variation in their attacks, and quickly move across users, devices, cloud services, applications, and networks. The use of fragmented security tools means that signals are scattered across different systems, making attacks difficult to detect. An integrated security architecture like SASE is the way forward for monitoring, detecting, and analyzing suspicious activity across the length and breadth of the environment.
  • Faster Patching: Faster vulnerability discovery demands accelerated remediation.  Patching is the underrated front-line defense against zero-knowledge threat actors. Organizations should keep critical systems, exposed applications, and widely used software up to date. Don’t make things easier for threat actors by keeping known weaknesses open.
  • Planned Incident Response: Your security posture should be ready for an attack at any given time. Rehearse incident response with tabletop exercises, clearly lay out escalation paths, and focus on recovery testing. This helps the organization bake resilience into the cybersecurity posture.
  • Security Frameworks: Adopt recognized AI security frameworks to address AI-specific risks surfaces. MITRE ATLAS helps teams map adversarial tactics targeting ML systems. The OWASP Top 10 for LLM Applications is essential if your organization builds or deploys LLM-based tools. Google’s Secure AI Framework (SAIF) provides principles for embedding security into AI development lifecycles.

In Summary

AI has not made every attacker advanced, but it has made low-skill attackers far more capable. For security teams, the answer is not panic; it is sharper visibility, faster action, and practiced response. This will help organizations address zero-knowledge threat actors proactively rather than scrambling to deliver an effective response. 

Learn More at the AI Risk Summit | Ritz-Carlton, Half Moon Bay

https://www.securityweek.com/the-zero-knowledge-threat-actor-and-the-end-of-responsible-disclosure/




Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches

A critical-severity vulnerability in multiple HP Poly Voice VoIP phone models can be exploited for remote code execution (RCE) with root privileges, allowing attackers to gain a foothold in enterprise networks, Rapid7 warns.

Tracked as CVE-2026-0826 (CVSS score of 9.2), the bug is described as a stack-based buffer overflow issue in the parsing of Session Description Protocol (SDP) attributes and affects devices that have the Interactive Connectivity Establishment (ICE) feature enabled.

The security defect was identified in a function that parses individual components of candidate attributes. The parsing function is called during the processing of SDP data, when ICE is enabled.

“The candidate attribute is intended to contain a transport address for a candidate that can be used for connectivity checks,” Rapid7 explains.

The parser copies the incoming string line into a 256-byte stack buffer without checking its length, and a candidate attribute with a greater length can be supplied to trigger the buffer overflow.

An attacker can exploit the vulnerability by sending a SIP INVITE request containing a malicious candidate attribute, which will trigger a crash, providing the attacker with control of the program counter, general-purpose registers, and data in the stack pointer.

Advertisement. Scroll to continue reading.

To bypass ASLR and No Execute (NX) mitigations, which prevent the execution of the stack data, the attacker can use a Return Oriented Programming (ROP) chain containing null bytes, which results in arbitrary code execution.

The bug has been confirmed on HP VVX series (VVX 150, VVX 250, VVX 350, and VVX 450) and Trio IP Conference series (Trio 8800, Trio 8500, and Trio 8300) VoIP phones. Patches are available for all of them.

Disabling ICE connectivity where it is not required mitigates the vulnerability. To fully address it, administrators are advised to update Poly Voice devices to a patched firmware release.

According to Rapid7 vulnerability intelligence director Douglas McKee, the main issue is that these devices reside in inherently trusted places, including conference rooms, offices, help desks, and hospital stations.

“A compromise in that context is not just about device access. It’s about what that access enables,” McKee notes, explaining that these devices typically don’t run endpoint protection software and can be abused to establish a persistent foothold into an environment and then intercept transmissions or move laterally.

“A compromised desk phone sitting in an executive office or conference room is not just a way to eavesdrop on sensitive discussions. It can also become a collection point for exactly the kind of audio that can be reused in vishing, deep fakes, social engineering, or even fraudulent financial authorization attempts,” McKee says.

Related: WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites

Related: Critical Windows Netlogon Vulnerability in Attackers’ Crosshairs

Related: 19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access

Related: Recent Palo Alto Networks Vulnerability Exploited for Weeks

https://www.securityweek.com/critical-vulnerability-in-hp-voip-phones-enables-enterprise-network-breaches/




Oracle WebLogic Vulnerability Exploited in the Wild

CISA is warning organizations that an Oracle WebLogic vulnerability patched nearly two years ago is being exploited in the wild.

The security hole, tracked as CVE-2024-21182, was patched by Oracle in the Java application server with its July 2024 CPU. The software giant’s advisory shows that the flaw was discovered and reported independently by several researchers.

Several proof-of-concept (PoC) exploits targeting CVE-2024-21182 have been made publicly available since the vulnerability’s existence came to light, but CISA appears to be the first to warn about its in-the-wild exploitation.

CISA added CVE-2024-21182 to its Known Exploited Vulnerabilities (KEV) catalog on June 1, instructing federal agencies to address it by June 4.

The flaw can be leveraged by remote, unauthenticated hackers to compromise vulnerable Oracle WebLogic Server instances.

“Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data,” the agency noted in its KEV entry.

Advertisement. Scroll to continue reading.

There does not appear to be any information on attacks exploiting the vulnerability.

CISA’s KEV catalog includes a dozen other WebLogic Server flaws. The majority are vulnerabilities with CVEs assigned in 2020 or earlier, but most were added to the KEV catalog several years after Oracle patched them.

Related: Oracle’s First Monthly Patches Resolve 77 Vulnerabilities

Related: Oracle Patches 450 Vulnerabilities With April 2026 CPU

Related: Oracle Releases Emergency Patch for Critical Identity Manager Vulnerability

Related: Oracle EBS Hack: Only 4 Corporate Giants Still Silent on Potential Impact

https://www.securityweek.com/oracle-weblogic-vulnerability-exploited-in-the-wild/




Meta AI Hands Over High-Profile Instagram Accounts to Hackers

Threat actors compromised multiple high-profile Instagram accounts last week by simply asking Meta’s AI-powered account recovery assistant to hand them over.

The attackers exploited a logic flaw in the AI assistant, a classic ‘confused deputy’ issue, to have their own email addresses linked to the targeted accounts and take them over.

Confused deputy weaknesses have been known to security researchers for decades and involve tricking a deputy that has elevated privileges into performing specific actions on the attacker’s behalf.

In this case, the Meta AI assistant had API access to account management systems, being deployed to help users re-link email addresses, reset passwords, and verify they are the owners of specific accounts.

Due to the logic flaw, hackers were able to simply ask the chatbot to link a targeted account to a new email address, under the pretense that they had been hacked or that they had lost access to the previously linked email address.

To bypass Meta’s fraud detection protections, they used VPNs to appear as if they were in the target’s geographic location.

Advertisement. Scroll to continue reading.

The AI assistant happily linked the new email address and then sent a code that allowed the attackers to reset the password for the targeted account, locking the rightful owner out.

In the event that the chatbot asked for a selfie to verify account ownership, the attackers reportedly modified victims’ photos using AI tools and submitted the altered images.

Inexplicably, the attack also bypassed two-factor authentication (2FA) protections for the targeted accounts, and some victims say they were never notified of the password reset attempts.

Hundreds of high-profile accounts were reportedly compromised and immediately sold on the dark web. Some miscreants were seen sharing videos and instructions on how the account takeover is performed.

Using the trick, the hackers gained access to the Obama White House handle and to the accounts of Sephora and John Bentivegna, the Chief Master Sergeant of the Space Force.

Instagram parent company Meta has resolved the issue, and the exploit no longer works, but it’s unclear how many accounts might have been affected. SecurityWeek has emailed the company for a statement and will update this article if it responds.

“This is a great illustration of why AI agent authorization is the harder, and more critical, problem than authentication. Meta’s bot verified nothing about who was asking; it just helpfully did what it was told to do, up to and including sending the attacker a confirmation code to make sure the new email address was valid. The industry is pretty focused on keeping AI from saying bad things. That’s fine, as long as we don’t completely overlook whether AI should be allowed to do what it’s trying to do,” FusionAuth senior director Dan Moore commented.

Related: As the Pentagon Pushes for Battlefield AI, Some Military Leaders Urge Caution

Related: Researcher Discovers 4th WhatsApp View Once Bypass; Meta Won’t Patch

Related: McDonald’s Chatbot Recruitment Platform Exposed 64 Million Job Applications

Related: Pro-Iranian Hacking Group Claims Credit for Hack of FBI Director Kash Patel’s Personal Account

https://www.securityweek.com/meta-ai-hands-over-high-profile-instagram-accounts-to-hackers/




Supply Chain Attack Hits 32 Red Hat NPM Packages

On Monday, hackers hit Red Hat’s NPM repository in a new supply chain attack, publishing malicious versions of 32 packages to distribute a credential-stealing worm.

Within a 72-second window, the threat actor published poisoned iterations across all 32 packages, likely using automation, ReversingLabs notes.

The affected packages cover the entire Red Hat Hybrid Cloud Console JavaScript ecosystem and have nearly 10 million collective downloads.

According to Aikido, the attackers likely compromised the CI/CD pipeline and used the GitHub Actions OIDC to publish the malicious package versions. ReversingLabs believes that the hackers had access to @redhat-cloud-services NPM scope credentials.

The packages contained a preinstall hook that led to the execution of malware during NPM install, before the package is imported or used.

The payload contains the string “Miasma: The Spreading Blight” and appears to be a variant of the Mini Shai-Hulud worm that TeamPCP used in several attacks against the open source software community over the past months.

Advertisement. Scroll to continue reading.

The hacking group released the malware’s source code last month, inviting miscreants to use it in supply chain attacks as part of a challenge.

According to Ox Security, the threat actor behind the Red Hat compromise infected a repository on May 29, likely to test its capabilities.

The malware was designed to harvest “GitHub Actions secrets, npm tokens, cloud credentials, Kubernetes and Vault material, SSH keys, Git credentials, and other sensitive files,” Socket reports.

Like Mini Shai-Hulud, it exfiltrates the collected data to an attacker-controlled server and uses a GitHub-based fallback mechanism, publishing the stolen information to newly created public repositories.

While the full scope of infection is yet unknown, Ox identified 210 repositories containing stolen credentials, suggesting that at least as many developers were infected after downloading and installing the malicious Red Hat package versions.

The malware was also observed attempting to use stolen GitHub tokens to enumerate repositories. It contains a GitHub Actions workflow modification logic and can write malicious index.js payloads into repositories/actions.

Red Hat maintainers have published clean versions of all 32 affected packages, and the malicious iterations have been removed from NPM.

Users are advised to update to a clean release as soon as possible. Anyone who installed a malicious version should consider their system and build environment compromised and should immediately rotate credentials, tokens, API keys, and other sensitive information the malware might have accessed.

Developers are also advised to check transitive dependencies, as the packages are widely used as indirect libraries, and to monitor their environments for anomalous outbound connections.

Related: IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell”

Related: ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems

Related: Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack

Related: Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack

https://www.securityweek.com/supply-chain-attack-hits-32-red-hat-npm-packages/




Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads

Password management and credential security solutions provider Dashlane revealed on Monday that it has been targeted in a brute-force attack campaign that resulted in a limited number of encrypted vaults being downloaded by the attackers.

According to Dashlane, the attack began on May 31, with attackers attempting to brute-force 2FA to register their own devices on targeted accounts. 

The hackers, the company said, used automated software to “rapidly submit every possible numeric combination to the system, hoping to guess the exact sequence before the short-lived security code expires”.

Registering a device gives the attacker the access required to download the targeted user’s encrypted vault from Dashlane servers.

The attack was quickly detected and the targeted accounts were automatically locked to limit impact. 

However, Dashlane said the attackers did manage to compromise some accounts. The threat actor downloaded a copy of the encrypted vaults belonging to fewer than 20 personal plan users. 

Advertisement. Scroll to continue reading.

“Dashlane vault data cannot be accessed without the Master Password, and our vault encryption ensures that any attempts to gain access to the vault are statistically unlikely to succeed, even over a long period of time,” Dashlane said. 

The company noted that the only way for an attacker to obtain a user’s master password is through phishing.

The locked accounts have since been restored and affected users have been notified.

“There is no evidence that Dashlane’s internal system has been impacted,” Dashlane said.

Related: Carnival Data Breach Exposed 6 Million People

Related: Charter Communications Data Breach Could Impact Nearly 5 Million

Related: 185,000 Likely Impacted by 7-Eleven Data Breach

https://www.securityweek.com/dashlane-brute-force-attack-leads-to-limited-encrypted-vault-downloads/




Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts

Both ZachXBT and Dark Web Informer also confirmed how hackers had targeted and resold particularly valuable Instagram accounts, including the short handles @hey and @jowo with a “combined gray-market valuation estimated above $1 million,” according to the CyberSec Guru. Such accounts can be valuable even if hackers hold them for just a few days because of “clout, resale or brand impersonation,” the security blog reported.

The wide security hole

The CyberSec Guru also described the exploit as representing the classic “confused deputy” problem from computer security, in which a program with elevated permissions is tricked into misusing those permissions on behalf of a less privileged third party. But in this case, the “deputy” was a large language model with a “probabilistic response model you can nudge with words” instead of a “deterministic program” with “hard-coded conditionals you’d need to bypass with code.”

It’s worth keeping in mind that users had simple security solutions available, even with the Meta AI support chatbot being exploited. The hackers reported their exploit failing against any accounts that had enabled multifactor authentication (MFA), including the “least robust form of MFA that Instagram offers” in the form of one-time codes sent through SMS, according to KrebsOnSecurity.

But the exploit still highlights the broader risk of tech companies and other organizations rushing to deploy AI agents with elevated permissions that allow them to modify, create, or delete critical data. Meta had launched its Meta AI support assistant in March 2026 with the promise that it could “provide reliable, 24/7 support for nearly any support issue at any time.”

The “minimum” architecture required to do this more safely, according to the CyberSec Guru, would include “out-of-band verification before any account modification… rate limiting on AI-initiated reset flows keyed to account risk signals, action logging with anomaly detection for unusual AI-driven account modifications, and a hard deterministic gate.”

https://arstechnica.com/ai/2026/06/meta-ai-support-chatbot-gave-hackers-access-to-notable-instagram-accounts/




Dozens of Red Hat packages backdoored through its official NPM channel

The worm, dubbed Shai-Hulud, has all the hallmarks of malware released last month as freely available open source. TeamPCP was the first group to use Shai-Hulud, and it promoted a competition that promised a $1,000 payment to the hacker who carried out the biggest supply-chain attack using the malware. TeamPCP has also been behind a rash of previous supply-chain attacks. Now that the worm is in the hands of many other threat groups, supply-chain attacks may ramp up further.

The malware devotes considerable attention to CI/CD (continuous integration/continuous delivery) systems, which allow for faster and more reliable software releases by automating the building, testing, and deploying of code changes. The malware spread in Monday’s attack was published through GitHub Actions OIDC (OpenID Connect), indicating that Red Hat’s CI/CD pipeline was compromised. OIDC is a security measure designed to interact with cloud services through the use of temporary credentials.

Once installed, the malware targets other organizations’ CI/CD credentials. The compromise of Red Hat’s GitHub Actions OIDC was very possibly the result of a previous supply-chain attack that infected an employee’s machine.

In an email sent after this post went live, Red Hat said it has removed the malicious packages.

“The packages are strictly limited to internal development, and the malicious code was never published for customer consumption via the console.redhat.com system,” the email said. “While our investigation is ongoing, we have not identified any impact to customer or partner environments or Red Hat production systems.”

Given the success of other recent supply-chain attacks, anyone who touched one of the affected packages in the past 36 hours should assume compromise of their workstations, CI/CD pipelines, and all credentials for cloud services and repositories. That means employees should drop whatever they’re doing at the moment and investigate thoroughly.

In a recent supply-chain attack that hit Checkmarx, the security firm failed to fully drive out the party responsible. Checkmarx was then hit two more times. The Checkmarx credentials used in the first attack came from a supply chain attack on the Trivy software developer. The pivot to Checkmarx and its failure to fully remediate the initial breach demonstrates the difficulty of completely recovering from such security lapses and the risks that result.

Both Socket and Aikido have lists of affected Red Hat packages and other indicators of compromise that any potentially affected person or organization should make use of promptly.

Story updated to add Red Hat comment.

https://arstechnica.com/security/2026/06/dozens-of-red-hat-packages-backdoored-through-its-offical-npm-channel/




Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say

Russia’s intelligence agencies have grown more aggressive in their efforts to steal Western technology and defense secrets as sanctions squeeze the country’s wartime economy, three senior European intelligence officials told The Associated Press.

Moscow’s agents are building fake companies, recruiting middlemen and deploying cyber spies and hackers who are gathering information that could also be used to attack key infrastructure, they said.

Four years of international sanctions have hampered Moscow’s ability to procure machinery, technology and research from Europe, while the grinding war in Ukraine has taxed key industries and pushed the country toward a potential financial crisis.

“They really know what they need,” and are putting “serious effort” into acquiring advanced machine tools, factory equipment, research and dual-use technology, said Christoffer Wedelin, deputy head of operations at the Swedish Security Service.

Russia seeks high-end research, defense technology and software

In Sweden, Russia is targeting the defense industry and high-end research on the country’s most advanced weaponry, such as the Gripen fighter jet, Wedelin said. It is also trying to procure camera and laser technology developed for civilian purposes that could be integrated into Russian weapons systems, he said.

Moscow is also trying to steal technology to help it keep pace — or give it an edge — against the West in the decades ahead, said Juha Martelius, the director of Finland’s Security and Intelligence Service.

Advertisement. Scroll to continue reading.

“We’re talking about space technology, quantum … arctic technology, marine technology,” he said, adding that space technology is something Russia needs “right now,” without elaborating. Countries use such technology for satellite imaging, communications and navigation.

Russia also needs sanctioned computer technology and software updates for machine tools, Martelius said.

On Wednesday, Anne Keast-Butler, the director of the U.K’s signals intelligence agency, accused Russia of “relentlessly targeting” the U.K. and its European allies, by stealing technology and plotting sabotage and assassination attempts.

In May, Swedish police arrested two people on suspicion of violating sanctions relating to a company in Turkey that has made dozens of shipments of metalworking and metal-turning machine tools to Russia.

As the schemes to acquire technology grow more complex, companies need to be more aware they could unwittingly become part of Russia’s war supply chain, Wedelin said.

“All of the security and intelligence services in Russia are helping out on the state’s efforts to get this,” he said.

Intelligence officials say Russia cares less about getting caught

Moscow is also deploying cyberattacks against European firms and critical infrastructure in an attempt to gather information, which it could exploit “when they get the chance and when it serves their purpose,” Wedelin said. He pointed to an attack on a Swedish power plant last year.

Russia-linked actors tried to “destroy” the plant but failed because the system detected the intrusion, Wedelin said. He said the attack was partly aimed at undermining Western support for Ukraine.

Before then, Sweden’s security services had mostly observed reconnaissance for potential attacks, intelligence gathering or activity linked to cybercriminals. The attack marked a “switch” in Russia’s modus operandi, Wedelin said.

“They’re no longer caring as much about potential attribution after their activities, so they are taking greater risks to achieve their goals,” he said.

Problems are mounting for Russia’s economy

Russia’s increasingly aggressive tactics may reflect mounting internal concerns about its economy, which “is not doing well at all,” said Kaupo Rosin, the head of Estonia’s Foreign Intelligence Service.

About a third of Russia’s gross domestic product currently goes to the war effort, Martelius said. The war and ensuing sanctions have slowed growth and fueled stubborn inflation.

Russian officials planned to have a budget deficit of 3.7 trillion rubles ($52.1 billion) for the whole of 2026 and had already reached about 3.4 trillion rubles ($47.9 billion) by the end of February, Rosin said.

The Iran war that erupted on Feb. 28 has provided a boost by causing oil prices to soar. The U.S. has granted sanctions waivers for the sale of Russian oil and the U.K. watered down its sanctions in an attempt to lower global fuel costs.

Increased revenue since then has likely improved Russia’s budget, but “it doesn’t save them,” Rosin said, adding that if Western pressure persists, Moscow could face a financial crisis toward the end of the year.

Rosin said intelligence seen by his agency shows a gloomier outlook among Russian officials over the past six months, with the narrative of “total victory” in Ukraine having vanished. Keast-Butler, of British intelligence, said almost 500,000 Russian soldiers have been killed in Ukraine since the full-scale invasion in 2022.

Russia and Ukraine have mostly kept their combat casualty figures under wraps.

Stalled progress on the battlefield and economic woes have many Russian officials privately asking “what is this all for,” Rosin said, citing the intelligence reports.

Martelius, of Finland’s intelligence service, said that while some reports on the war in Ukraine may have been “sanitized” before reaching President Vladimir Putin’s desk, he believes the Russian leader has a fairly clear picture of the economic challenges.

But that does not mean there will be political change.

It is “very dangerous … to start analyzing Russia as if it is some country like ours,” Martelius said. “It is not.”

https://www.securityweek.com/russian-spies-are-aggressively-seeking-western-technology-as-sanctions-bite-officials-say/




Exploit Code Published for Critical Flowise RCE Vulnerability

Obsidian Security has released technical information and proof-of-concept (PoC) code targeting a remote code execution (RCE) vulnerability in Flowise.

The issue, tracked as CVE-2026-40933 (CVSS score of 9.9), was disclosed in April along with several other security defects impacting AI ecosystems that rely on Anthropic’s MCP protocol.

Flowise, a popular open source platform that provides developers with a drag-and-drop interface for building LLM flows and AI agents, and which has over 52,000 GitHub stars, was flagged as one of the impacted products.

According to OX Security, the root cause of the issue is a “by design”, systemic command injection vulnerability in Anthropic MCP, which propagates through the ecosystem.

[Learn More: SecurityWeek to Host AI Risk Summit August 11-12 at the Ritz-Carlton, Half Moon Bay]

A NIST advisory describes CVE-2026-40933 as an unsafe serialization of stdio commands in the MCP adapter, allowing an attacker to add an MCP stdio server with an arbitrary command and achieve code execution.

Advertisement. Scroll to continue reading.

The security weakness existed because Flowise before version 3.1.0 allowed any user to add a new MCP and, when doing so, to add any command, enabling code execution on the underlying OS.

According to Obsidian, the bug can be exploited by attackers to take over servers by simply convincing a user to import a crafted chatflow. The import action triggers arbitrary code execution on the server.

“Any user who can create or edit chatflows can add a Custom MCP Tool and supply a malicious stdio MCP configuration. In practice, this requires a malicious insider or a compromised user account,” Obsidian notes.

A remote attacker, the cybersecurity firm explains, can include a malicious command in a Custom MCP Tool configuration, export the chatflow as JSON, and share it with the victim. The payload abuses Flowise’s legitimate functionality to execute the malicious command during the import process.

“Flowise’s Custom MCP node has an ‘Available Actions’ dropdown that lists the tools exposed by the configured MCP server. To populate that dropdown, the canvas asks the backend to enumerate the server’s tools. With stdio transport, enumeration starts the configured command. Because the dropdown loads when the imported chatflow renders on the canvas, the import alone can spawn the command,” Obsidian notes.

The cybersecurity firm has published PoC code that, when imported, creates a shell back to Docker’s bridge address for the host.

Obsidian says successful exploitation of CVE-2026-40933 leads to “OS-level execution with the Flowise process’s privileges, often root in containerized deployments. Every credential stored in the platform is readable. Every connected service is reachable. Flowise in production is typically wired into databases, APIs, and cloud accounts; the blast radius scales with whatever it connects to.”

The cybersecurity firm notes that Flowise Cloud is not affected, because it has stdio MCP disabled. Self-hosted instances are vulnerable by default.

Related: Raising the Cybersecurity Stakes: Ante up for the Agentic Era

Related: Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks

Related: Anthropic Releases New Claude Sandbox, Security Guidance Plugin

Related: ‘Claw Chain’ OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery

https://www.securityweek.com/exploit-code-published-for-critical-flowise-rce-vulnerability/