More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
A Russian-speaking broker has been running “FortiBleed” against FortiGate firewalls since February, brute-forcing more than 430,000 devices and snaring credentials for 24 protocols. They deploy “FortigateSniffer” to intercept logins, feed them into a Golang CyberStrike Harvester pipeline, crack hashes with Hashcat/Hashtopolis, then rank and resell access. Over 110 million credentials changed hands. Meanwhile, Zafran Security found four critical flaws in Dify’s open-source LLMOps platform (CVE-2026-41947 through CVE-2026-41950) that let any console user read other tenants’ chats, files and internal APIs. Patches shipped in Dify 1.14.2, and a WAF rule is advised for the worst path-traversal bug.
On the malware front, Symantec and Zscaler have linked Python-based ModeloRAT and the in-memory, diskless Mistic backdoor to the Woodgnat access broker. ModeloRAT rides on signed pythonw.exe with RC4-encrypted C2, while Mistic sideloads EndpointDlp.dll via MpExtMs.exe, hooks critical APIs and self-deletes. Defenders should hunt for MpExtMs.exe loading EndpointDlp.dll, Run-key persistence and signed pythonw.exe spawning unknown scripts. At Johnson & Johnson, two web apps exposed nearly 1,000 student records because MSAL checks were bypassable and AWS APIs accepted a hardcoded key. An audit-tracking app also leaked user lists and admin functions through unauthenticated APIs until a journalist’s inquiry forced fixes. Novee’s Cordyceps research mapped CI/CD flaws across 30,000 GitHub Actions workflows, uncovering 300 chains that let anyone with a free account run code, steal tokens and push tainted artifacts into environments at Microsoft, Google, Apache, Cloudflare and beyond.
Detection and defense are evolving too. One post lays out how to feed Claude Compliance API events into a SIEM and use an LLM-as-judge to spot intent, not just regex hits. New tools include caddy-waf, a Go middleware for regex rules, blacklists, rate limiting and JSON metrics, plus Geordie, which inventories and monitors AI agents, and Cloudflare’s “security-audit-skill” that runs multi-phase vulnerability hunts with adversarial review to cut false positives. On the intel side, Anthropic’s Mythos model—tested under Project Glasswing—quickly found holes in classified US systems but wasn’t shown to exploit them. Finally, IBM, Red Hat and Palo Alto Networks have teamed up to stitch virtual patching into a subscription-style security layer, pairing network-level shields from Palo Alto’s Prisma with IBM/Red Hat’s Lightwell fixes so customers get defenses the day a vulnerability pops.
Questions about this article
No questions yet.