{"id":1503,"date":"2026-06-29T15:08:53","date_gmt":"2026-06-29T15:08:53","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1503"},"modified":"2026-06-29T15:08:53","modified_gmt":"2026-06-29T15:08:53","slug":"linux-kernel-flaws-ai-malware-tricks-turla-backdoor-infostealers-and-more","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1503","title":{"rendered":"Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 29, 2026<\/span><\/span><span class=\"p-tags\">Cybersecurity \/ Hacking<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjFXmUW2VYnBd5oSyq6V328rZOIdanacqm-k4Wae2x53iAvPb7YvO7rqDcfWTklR_skhgLDVTThASQvf4UATgFVoVy1iHddO0Nxp9zkhuVEROXkqDAEyyWZZWzMZLNy1apXbCj1xttx9kYI_jPbLmV5hmUHJEkS_Efo9GiFAg5snM_JNwWKDDbMW5wuvwyl\/s1700-e365\/thn-recap-main.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>This week was a reminder that attackers do not always need big tricks. One small mistake, one old access path, one missed patch, and suddenly the door is open.<\/p>\n<p>The noise is not all noise, either. Forums are talking, researchers are finding easy cracks, and defenders have more cleanup waiting.<\/p>\n<p>Here\u2019s the full Monday recap.<\/p>\n<h2 style=\"text-align: left;\"><b>\u26a1 Threat of the Week<\/b><\/h2>\n<p><b>New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets <\/b>\u2014 Cybersecurity researchers detailed a new variant of the Dirty Frag Linux kernel flaw. Called DirtyClone (aka CVE-2026-43503), it allows local users to gain root privileges via cloned packets. The exploit works successfully on Debian, Ubuntu, and Fedora systems with default namespace configurations. \u00abAny local user on a server or device running a vulnerable kernel who holds or can acquire the CAP_NET_ADMIN capability (frequently obtainable via unprivileged user namespaces) [is exploitable],\u00bb JFrog said. \u00abThis poses the highest risk to multi-tenant cloud environments, Kubernetes clusters, and containerized workloads where user namespaces are enabled, or privileged containers are deployed.\u00bb<\/p>\n<h2 style=\"text-align: left;\"><b>\ud83d\udd14 Top News<\/b><\/h2>\n<ul>\n<li><b><a href=\"https:\/\/thehackernews.com\/2026\/06\/cisa-adds-exploited-ptc-windchill-rce.html\">Critical PTC Windchill PDMlink and PTC FlexPLM Flaw Exploited <\/b>\u2014 A critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Data Management (PDM) and Product Lifecycle Management (PLM) software has come under active exploitation in the wild to deploy JSP web shells on susceptible systems. The vulnerability, tracked as CVE-2026-12569, is a case of improper input validation that could allow an attacker to execute arbitrary code by sending a malicious request to the network. Patches for the vulnerability have been released.<\/li>\n<li><b>OpenAI Previews GPT-5.6 Sol, Terra, and Luna <\/b>\u2014 OpenAI officially unveiled GPT-5.6 Sol, Terra, and Luna, with Sol described as the <a href=\"https:\/\/metr.org\/blog\/2026-06-26-gpt-5-6-sol\/\">most capable model<\/a> yet for cybersecurity. The models are being released in a staggered manner with approval from the U.S. government. The release came days after the company released an improved version of its GPT\u20115.5\u2011Cyber model to trusted defenders as part of the Daybreak initiative and launched a new project called Patch the Planet in collaboration with Trail of Bits to help secure open-source projects. OpenAI has also warned about the dual-use nature of the technology, acknowledging that the same capability that helps a red teamer find a zero-day can also assist a bad actor in exploiting one, and that it will prioritize patching jailbreak techniques against the model. In addition, it has framed the effort as getting the tools in the hands of more defenders before attackers gain the same edge. Much of the concern surrounding the frontier models stems from the fact that artificial intelligence can now identify existing bugs within codebases and work towards creating exploits for them. While the automation of cybercrime is not new, these tools undoubtedly have the potential to further lower the barrier to entry for bad actors.<\/li>\n<li><b>New Gaslight macOS Malware Discovered <\/b>\u2014 A newly discovered macOS malware dubbed Gaslight is designed to confuse AI-assisted malware analysis tools through embedded prompt injection strings and fake debugging data within the executable. With cybersecurity researchers using AI-powered tools to assist with malware analysis and reverse engineering, the malware attempts to gaslight such tools into thinking there is some issue, potentially causing them to abort, truncate, or refuse an analysis of the artifact. Gaslight has been attributed with high confidence to a North Korean-linked threat actor. The malware itself is a Rust binary with backdoor and information-stealing functionality, enabling the operator to gain a persistent foothold over the infected host. The findings highlight how threat actors are experimenting with anti-analysis methods designed specifically to bypass AI-assisted security platforms.<\/li>\n<li><b>Turla Uses STOCKSTAY Backdoor in Ukraine Attacks <\/b>\u2014 The Russian state-sponsored threat actor known as Turla has leveraged a previously undocumented .NET backdoor called STOCKSTAY in attacks targeting government and military organizations in Ukraine, and entities that have an interest in Italian foreign policy. STOCKSTAY shares significant code and functional overlaps with Kazuar, a staple implant put to use by the adversary since 2017. Suspected development activity of malware dates back to December 2022.<\/li>\n<li><b>Amadey, StealC Malware Operations Disrupted in Operation Endgame <\/b>\u2014 A coordinated law enforcement operation, in partnership with private sector companies, dismantled criminal infrastructure powering Amadey and StealC. According to Europol, the operation led to the disruption of 326 servers and 142 domains, the identification of more than \u20ac41 million ($47 million) in cryptocurrency linked to criminal activity, and the recovery of approximately 27 million credentials stolen from over 385k compromised systems. Amadey and StealC are sold to cybercriminals under a malware-as-a-service (MaaS) model. Microsoft said criminals use Amadey to gain an initial foothold on victim devices to deploy additional malware, such as StealC, which then steals credentials, cryptocurrency wallets, and other sensitive information that can later be sold or leveraged in follow-on attacks. The two malware families were linked to more than 140,000 infected devices during the first two weeks of May 2026 alone. That said, no arrests were announced as part of the operation.<\/li>\n<\/ul>\n<h2 style=\"text-align: left;\"><b>\u200e\ufe0f\u200d\ud83d\udd25 Trending CVEs<\/b><\/h2>\n<p>Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.<\/p>\n<p>Check the list, patch what you have, and hit the ones marked urgent first \u2014 CVE-2026-47729 aka Squidbleed (Squid), CVE-2026-12957 (Amazon Q Developer), CVE-2026-12569 (PTC Windchill PDMlink and PTC FlexPLM), CVE-2026-43503 aka DirtyClone, CVE-2026-46331 aka pedit COW (Linux Kernel), <a href=\"https:\/\/kb.cert.org\/vuls\/id\/936962\">CVE-2026-30040, CVE-2026-30041<\/a> (FastStone Image Viewer), <a href=\"https:\/\/kb.cert.org\/vuls\/id\/226679\">CVE-2026-45585<\/a> (Microsoft WinRE), <a href=\"https:\/\/jfrog.com\/blog\/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons\/\">CVE-2026-8461<\/a> aka PixelSmash (FFmpeg), <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-55200\">CVE-2026-55200<\/a> (libssh2), <a href=\"https:\/\/lucidbitlabs.com\/blog\/when-defenses-become-attack-surface\/\">CVE\u20112026\u201120971<\/a> (Samsung KNOX kernel), <a href=\"https:\/\/docs.gitlab.com\/releases\/patches\/patch-release-gitlab-19-1-1-released\/\">CVE-2026-10086, CVE-2026-10712, CVE-2026-12053<\/a> (GitLab CE and EE), <a href=\"https:\/\/chromereleases.googleblog.com\/2026\/06\/stable-channel-update-for-desktop_0482630350.html\">CVE-2026-13028, CVE-2026-13032, CVE-2026-13033, CVE-2026-13038<\/a> (Google Chrome), <a href=\"https:\/\/research.jfrog.com\/vulnerabilities\/the-reachy-mini-wireless-image-is-vulnerable-to-a-local-privilege-escalation-via-an-unrestricted-sudo-systemctl-grant-jfsa-2026-001667223\/\">CVE-2026-53605<\/a> (Reachy Mini Wireless image), <a href=\"https:\/\/www.synology.com\/en-global\/security\/advisory\/Synology_SA_26_11\">CVE-2026-13136, CVE-2025-15660, CVE-2026-13135<\/a> (Synology MailPlus Server), <a href=\"https:\/\/www.manageengine.com\/products\/self-service-password\/advisory\/CVE-2026-11374.html\">CVE-2026-11374<\/a> (ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus and ADAudit Plus), and a <a href=\"https:\/\/aumlayer.com\/insights\/administrator-is-not-root-infoblox-nios-privilege-escalation\/#cve-publication\">critical Infoblox NIOS privilege escalation vulnerability<\/a> (no CVE).<\/p>\n<h2 style=\"text-align: left;\"><b>\ud83c\udfa5 Cybersecurity Webinars<\/b><\/h2>\n<ul>\n<li><b><a href=\"https:\/\/thehacker.news\/outpacing-mythos-cyberattacks\">Stop AI-Driven Cyberattacks Before They Stop Your Business<\/a><\/b> \u2192 Hackers are now using AI to launch cyberattacks at machine speed. If your defenses are built for human-speed threats, you are at risk. Join this webinar to get a step-by-step blueprint to fight back. Learn exactly how to block AI-driven attacks and protect your company before a crisis hits.<\/li>\n<li><b><a href=\"https:\/\/thehacker.news\/ai-goes-rogue\">When AI Goes Rogue: How to Secure the New Cyber Attack Surface<\/a><\/b> <b>\u2192 <\/b>As companies rush to adopt AI, hackers are turning these tools into a massive liability by hijacking AI agents and leaking trade secrets. Join this urgent webinar to see exactly how attackers weaponize AI against businesses. You&#8217;ll get a practical blueprint to lock down your setups, fix risky configurations, and stop your own tech from going rogue.<\/li>\n<li><b><a href=\"https:\/\/thehacker.news\/secure-ai-development\">Building at Machine Speed: How to Secure AI Software Delivery<\/a> <\/b>\u2192 AI tools are generating code faster than security teams can review it, introducing hidden risks into software pipelines. Join this webinar to learn how to catch vulnerabilities and govern AI risk without slowing down development. You&#8217;ll get a practical roadmap to protect your software supply chain and scale AI engineering safely.<\/li>\n<\/ul>\n<h2 style=\"text-align: left;\"><b>\ud83d\udcf0 Around the Cyber World<\/b><\/h2>\n<ul>\n<li><b>China&#8217;s New Zhipu AI Reportedly Matches Claude Mythos in Vulnerability Discovery <\/b>\u2014 The Wall Street Journal <a href=\"https:\/\/www.wsj.com\/tech\/ai\/chinese-ai-anthropic-mythos-cybersecurity-574b02c2\">reported<\/a> that a new model released by China&#8217;s Zhipu AI, GLM-5.2, matches the performance of Anthropic Mythos when it comes to finding vulnerabilities, narrowing the gap between top U.S. models and those developed by Chinese companies. The ability of AI systems to autonomously find security defects in software has created new urgency to efforts that entail the use of models to quickly close them before they can be exploited by bad actors. There are also worries that these models, in the wrong hands, can become potential enablers of cyber warfare. The Trump administration has called for the creation of a framework that grants the federal government the ability to evaluate AI models&#8217; capabilities and determine which qualify as \u00abcovered frontier models,\u00bb a designation for AI systems with advanced cyber capabilities.<\/li>\n<li><b>Indirect Prompt Injection in Agentic Coding Tools <\/b>\u2014 Mozilla&#8217;s Zero Day Investigative Network (0DIN) characterized indirect prompt injection as a \u00abvery real and serious attack vector that can result in catastrophic damage, much of which will be irreversible.\u00bb In the case of agentic IDEs and coding agents, they can request access to various tools, which, once approved, can pave the way for code execution, file system operations, and network calls. Specifically, an attacker can obtain code execution using a seemingly harmless repository by chaining trusted setup instructions, routine error handling, and automated agent behavior. The attacker-controlled repository does not even have to contain any malicious code. Instead, it&#8217;s fetched at runtime from a DNS TXT record by framing it as an essential step during the installation phase when a developer copies the repository link and instructs the agent to get it running. \u00abIn short, agentic coding tools have access to everything they need for this: private data, including environment variables, credentials, API keys, and local configuration files,\u00bb 0DIN said. \u00abUntrusted content, such as repositories, documentation, and error messages from recently installed packages, can inject malicious models to steal this data.\u00bb<\/li>\n<li><b>New KuinaExtractor Rust Infostealer Spotted <\/b>\u2014 A new Rust-based information stealer called <a href=\"https:\/\/www.threatray.com\/blog\/kuinaextractor-six-months-of-a-rust-infostealers-evolution\">KuinaExtractor<\/a> comes fitted with capabilities to harvest web browser data, crypto wallets and credentials for services such as Roblox, Steam and Discord. Said to be in active development since December 2025, the stealer also includes a Chrome app-bound encryption (ABE) bypass. In parallel, the malware developer worked on two short-lived projects known as KuinaCookieExtractor and Zenith C2 before they were abandoned. KuinaCookieExtractor goes beyond browser cookies to include Roblox and Steam sessions, Minecraft and FileZilla logins, Telegram tdata and Discord tokens, and exfiltrates over a Discord webhook rather than Telegram.<\/li>\n<li><b>New LokiBot Campaign Surfaces After a Hiatus <\/b>\u2014 A new email phishing campaign has been <a href=\"https:\/\/www.levelblue.com\/blogs\/spiderlabs-blog\/lokibot-after-a-decade-an-analysis-of-a-recent-lokibot-campaign\">observed<\/a> delivering LokiBot via a JavaScript attachment. Once launched, the script triggers the execution of a PowerShell loader that runs a .NET injector payload that deploys the LokiBot malware. LokiBot is capable of harvesting credentials from password managers like 1Password, Enpass, and KeePass, and contacts an external server to receive and execute commands.<\/li>\n<li><b>Phishing Campaign Drops Malicious Chrome Extension <\/b>\u2014 Invoice-themed email phishing lures written in Italian are being used to launch JavaScript attachments masquerading as PDF documents. \u00abThe most interesting part of this infection was not the initial JavaScript. The malware installed a malicious Google Chrome extension and paired it with a Native Messaging Host,\u00bb D3 Lab <a href=\"https:\/\/www.d3lab.net\/breaking-out-of-chromes-sandbox-a-native-messaging-backdoor-observed-in-italy\/\">said<\/a>. \u00abThis combination allowed code running inside Chrome to request PowerShell commands on the Windows system.\u00bb\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhbmiR6_dFSPW2vDDjWwITipzgXE6tDJ20pYeemDRxka89gSOYk9-jt4WuzbYCXeW0FWQOBKJ1UT7svIIqKEGuD45d4e90IK_JjLkUCm8VWnXIvMWI3rlKuj1zyZ5r9SZ3z0wGtUpxifT-QaNwiQxYokLFS-Gzvopxb7VkIKWsMQm5NzVCtQEke6ccdn2tq\/s1700-e365\/backdoor.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhbmiR6_dFSPW2vDDjWwITipzgXE6tDJ20pYeemDRxka89gSOYk9-jt4WuzbYCXeW0FWQOBKJ1UT7svIIqKEGuD45d4e90IK_JjLkUCm8VWnXIvMWI3rlKuj1zyZ5r9SZ3z0wGtUpxifT-QaNwiQxYokLFS-Gzvopxb7VkIKWsMQm5NzVCtQEke6ccdn2tq\/s1700-e365\/backdoor.jpg\" alt=\"\" border=\"0\" data-original-height=\"941\" data-original-width=\"1672\"\/><\/a><\/div>\n<\/li>\n<li><b>Time as an Attack Surface <\/b>\u2014 New research from NCC Group has argued the need for treating time as a \u00abfirst\u2011class attack surface,\u00bb stating clock drift, time synchronisation failures, and deliberate oscillator manipulation can be exploited to undermine cryptography, authentication, industrial automation, and safety systems. \u00abThe risk is amplified by broader technological trends,\u00bb NCC Group&#8217;s Andy Davis <a href=\"https:\/\/www.nccgroup.com\/research\/time-as-an-attack-surface\/\">said<\/a>. \u00abCloud computing, containerisation, and virtual machines abstract time away from physical hardware, placing it under the control of hypervisors and orchestration layers. At the same time, Industrial Control Systems, IoT devices, and safety-critical platforms increasingly rely on low\u2011cost oscillators and commodity components that are vulnerable to environmental influence and physical manipulation. Systems that once relied on isolated, deterministic timing sources are now interconnected, synchronised, and exposed.\u00bb<\/li>\n<li><b>Threat actors Exploit Xiongmai DVR Flaw to Deliver Proxy SDK <\/b>\u2014 Threat actors have been exploiting <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-3765\">CVE-2024-3765<\/a>, a vulnerability in Xiongmai DVR, to deploy commercial residential proxy SDKs using a Mirai botnet-derived HTTP downloader. \u00abAll DDoS and scanning capability has been stripped,\u00bb the Nokia Deepfield Emergency Response Team (ERT) <a href=\"https:\/\/github.com\/deepfield\/public-research\/blob\/main\/reports\/2026-03-19-xiongmai-packetsdk-ipidea.md\">said<\/a>. \u00abWhat remains is a minimal HTTP client and an embedded userspace ELF loader \u2013 Mirai reduced to a delivery truck.\u00bb The main stager installed following a successful compromise deploys a proxy binary called PacketSDK, which is part of the IPIDEA residential proxy network disrupted by Google earlier this year. The stager also contains a remote code execution backdoor that polls an external server for updates every 2 minutes.<\/li>\n<li><b>Nation-State Targeting of Water Systems <\/b>\u2014 DomainTools warned that water and wastewater infrastructure have become strategic pressure points for state and state-aligned actors from China, Iran, and <a href=\"https:\/\/apnews.com\/article\/texas-muleshoe-water-systems-cyberattacks-russia-5f388bf0d581fc8eb94b1190a7f29c3a\">Russia<\/a>. \u00abThe combination of chronic underinvestment and weak baseline operational technology (OT) security makes many of these critical systems easy to compromise,\u00bb the company <a href=\"https:\/\/dti.domaintools.com\/research\/threat-intelligence-report-nation-state-targeting-of-water-systems-2024-2026\">said<\/a>. \u00abSuch intrusions can have both physical and psychological impact, and disruptions often affect civilian life, public health, and trust in government.\u00bb<\/li>\n<li><b>Anthropic Accuses Alibaba of Obtaining Illicit Access to Claude <\/b>\u2014 Anthropic has <a href=\"https:\/\/www.reuters.com\/world\/china\/anthropic-says-alibaba-illicitly-extracted-claude-ai-model-capabilities-2026-06-24\/\">accused<\/a> the Chinese company Alibaba of what it <a href=\"https:\/\/www.ft.com\/content\/8496c940-fdc7-4554-bc8d-7bcc93e7d75c\">described<\/a> as the \u00ablargest campaign to illicitly extract Claude&#8217;s capabilities.\u00bb The attacks occurred between April 22 and June 5, 2026, when \u00aboperators af\ufb01liated with Alibaba and Alibaba Qwen, Alibaba&#8217;s AI lab,\u00bb allegedly generated \u00abmore than 28.8 million exchanges with Claude through almost 25,000 fraudulent accounts,\u00bb per Anthropic. The distillation campaign targeted its capabilities, such as agentic reasoning, software engineering, and long-horizon tasks, while evading detection using <a href=\"https:\/\/www.wired.com\/story\/how-people-in-china-keep-outsmarting-anthropics-geolocation-restrictions\/\">obfuscation techniques and proxy networks<\/a>.<\/li>\n<li><b>Linux Foundation Unveils Akrites and OSERA <\/b>\u2014 The Linux Foundation has announced <a href=\"https:\/\/akrites.org\/\">Akrites<\/a> as a coordinated effort to address and disclose vulnerabilities in critical open-source software as AI accelerates both the scale and speed of vulnerability discovery. \u00abThe initiative provides a single, trusted place to coordinate, remediate, and disclose, with a shared SIRT [Security Incident Response Team] serving as a predictable partner for maintainers rather than a flood of uncoordinated reports,\u00bb the foundation <a href=\"https:\/\/www.linuxfoundation.org\/press\/linux-foundation-and-industry-leaders-launch-akrites-to-defend-critical-open-source-software-against-ai-enabled-cyber-threats\">said<\/a>. The initiative also plans to work with critical infrastructure operators to help deploy fixes before in-the-wild exploitation. The Linux Foundation has also announced its intent to form an Open Source Enterprise Resiliency Alliance (OSERA) that aims to strengthen the open-source components that underpin the financial services sector through a vendor-neutral, upstream-aware approach. \u00abOSERA complements the recently announced Akrites, the cross-industry effort enabling coordinated disclosure and upstreaming,\u00bb the foundation <a href=\"https:\/\/www.linuxfoundation.org\/press\/finos-announces-intent-to-form-osera-a-global-financial-services-led-alliance-for-open-source-supply-chain-resiliency-in-the-era-of-ai\">said<\/a>. \u00abAs financial-services downstream complement to Akrites, OSERA will collaborate with Akrites in the upstreaming process and, together with the Open Source Security Foundation, to represent the voice of the industry in defining remediation standards.\u00bb<\/li>\n<li><b>Microsoft Extends Windows 10 Consumer Extended Security Updates by a Year <\/b>\u2014 Microsoft <a href=\"https:\/\/www.microsoft.com\/en-us\/windows\/extended-security-updates#cw\">quietly extended<\/a> the Extended Security Updates (ESU) program for Windows 10 consumers by a year, letting eligible users get updates through October 12, 2027. To enroll in the consumer Windows 10 ESU program, devices need to be running Windows 10, version 22H2 Home, Professional, Pro Education, or Workstations edition and cannot be offered for devices in kiosk mode or those that are joined to an Active Directory domain or Microsoft Entra and\/or enrolled in a Mobile Device Management (MDM) solution.<\/li>\n<li><b>Microsoft&#8217;s Secure Boot Certificates Have Expired <\/b>\u2014 In related Microsoft news, the certificates that <a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/windows-secure-boot-certificate-expiration-and-ca-updates-7ff40d33-95dc-4c3c-8725-a9b95457578e\">manage UEFI Secure Boot trust<\/a> \u2013 namely, Microsoft Corporation KEK CA 2011, Microsoft UEFI CA 2011, and Microsoft UEFI CA 2011 &#8212; expired on June 24 and 27 2026. A third certificate, Microsoft Windows Production PCA 2011, will expire on October 19, 2026. \u00abMany Windows PCs manufactured since 2024 already have the updated 2023 certificates,\u00bb Microsoft <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/windows-itpro-blog\/secure-boot-playbook-for-certificates-expiring-in-2026\/4469235\">said<\/a>. \u00abFor the remaining devices, Microsoft is delivering new Secure Boot certificates through Windows monthly updates, with partner original equipment manufacturers (OEMs) making firmware updates available to help ensure compatibility.\u00bb Google Cloud has also <a href=\"https:\/\/docs.cloud.google.com\/compute\/docs\/security\/ms-secure-boot-certificates-expiration\">released<\/a> guidance on how to update Compute Engine Shielded VM instances to trust the updated Microsoft Secure Boot certificates for UEFI Secure Boot. To apply Secure Boot certificate updates for Linux on Azure virtual machines, it&#8217;s recommended to follow the actions outlined by Microsoft <a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/secure-boot-certificate-updates-for-linux-on-azure-virtual-machines-df51ba85-4e1e-4eda-b1d8-f0881970e997\">here<\/a>. Separately, Linux users are <a href=\"https:\/\/www.redhat.com\/en\/blog\/expiration-secure-boot-signing-certificates-2026\">advised<\/a> to <a href=\"https:\/\/support.scc.suse.com\/s\/kb\/Microsoft-secure-boot-certificate-changes?language=en_US\">update their shims<\/a> to the latest versions signed by the new key. It&#8217;s important to note that devices that haven&#8217;t received the newer 2023 certificates will continue to function normally, and standard Windows updates will continue to install. However, these devices will no longer receive new security protections for the early boot process, including updates to Windows Boot Manager, Secure Boot databases, revocation lists, or mitigations for newly discovered boot-level vulnerabilities.<\/li>\n<li><b><br \/>\n    Fake OpenAI Organization Invites Used in New Poisoned Tenant Campaign<\/b> \u2014 Phishing emails are being sent from threat actor-controlled ChatGPT tenants, inviting recipients to join an organization with the likely goal of harvesting sensitive information shared in the AI chatbot. \u00abThe emails came from OpenAI&#8217;s legitimate notification address (noreply@tm.openai.com), passed all standard email authentication checks, and referenced our company by name,\u00bb Push Security <a href=\"https:\/\/pushsecurity.com\/blog\/openai-poisoned-tenant-attack\">said<\/a>. \u00abThey looked exactly like a routine organizational invitation because, technically, they were one.\u00bb The development comes as threat actors are <a href=\"https:\/\/www.kaspersky.com\/blog\/share-chatgpt-chat-clickfix-macos-amos-infostealer\/54928\/\">abusing AI chatbot chat sharing functionality<\/a> to distribute pages containing malicious instructions, turning them into malware delivery platforms. \u00abThe attacker has used ChatGPT&#8217;s code rendering feature to build a fully designed fake page that mimics a ChatGPT service disruption, redirecting victims to a convincing clone of ChatGPT&#8217;s download page that delivers a malicious executable,\u00bb Push Security <a href=\"https:\/\/pushsecurity.com\/blog\/llmshare-malvertising-campaign\/\">noted<\/a>. The activity has been codenamed LLMShare.\n  <\/li>\n<\/ul>\n<h2 style=\"text-align: left;\"><b>\ud83d\udd27 Cybersecurity Tools<\/b><\/h2>\n<ul>\n<li><a href=\"https:\/\/github.com\/praetorian-inc\/Sulla\">Sulla<\/a> \u2192 It is an open-source security tool by Praetorian that scans internal network SMB file shares to find exposed credentials and sensitive data. Operating as a fast, low-noise static binary, it maps Active Directory environments and uses multi-layered filtering with the Titus engine to perform in-memory analysis for cloud keys, passwords, and tokens. It outputs structured, real-time results to help security teams identify and remediate internal data exposure before it can be exploited.<\/li>\n<li><a href=\"https:\/\/github.com\/sicuranext\/karna\">Karna<\/a> \u2192 It is a Web Application Firewall (WAF) module specifically engineered for the Kong Gateway to provide modern, scalable security for web applications. By integrating directly into the Kong ecosystem, it allows organizations to enforce fine-grained security policies and filter malicious traffic at the gateway layer, ensuring that protection is applied consistently across distributed services without adding significant latency.<\/li>\n<\/ul>\n<p><i>Disclaimer: This is strictly for research and learning. It hasn&#8217;t been through a formal security audit, so don&#8217;t just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you\u2019re doing stays on the right side of the law.<\/i><\/p>\n<h2 style=\"text-align: left;\"><b>Conclusion<\/b><\/h2>\n<p>This week, keep it simple. Break the small thing, find the forgotten access, wait for someone to say they meant to patch it.<\/p>\n<p>No genius required. Just old mistakes with fresh damage. Shut the door. Check the locks.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 29, 2026Cybersecurity \/ Hacking This week was a reminder that attackers do not always need big tricks. One small mistake, one old access path, one missed patch, and&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1504,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[179,11,1708,1571,181,42,1916,1687],"class_list":["post-1503","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-backdoor","tag-flaws","tag-infostealers","tag-kernel","tag-linux","tag-malware","tag-tricks","tag-turla"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1503","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1503"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1503\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1504"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1503"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1503"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1503"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}