🤖 AI Agents - Enterprise Identity Security
AI agents integrate into enterprise identity systems, enabling data access and workflow execution. This introduces new potential attack vectors. Elad Shamir discusses how to manage these attack paths for Microsoft Entra Agent ID.
Key Points:
• AI agents function as an identity layer within enterprises.
• Their access to data and workflows creates new attack surfaces.
• Attack Path Management frameworks can extend to AI agent identities.
• BloodHound Enterprise offers tools for this extension, specifically for Microsoft Entra Agent ID.
🔗 Resources:
• SpecterOps Blog ↗ - Article on managing attack paths for Microsoft Entra Agent ID
🤖 Industrial Control Systems - Security Advisories
CISA released twelve public advisories concerning Industrial Control Systems (ICS). These advisories detail current security issues, vulnerabilities, and exploits affecting ICS environments.
Key Points:
• CISA published 11 new and 1 updated ICS advisories.
• These documents inform about security issues and exploits.
• The advisories target vulnerabilities within Industrial Control Systems.
🔗 Resources:
• CISA ICS Advisories ↗ - Access the latest public ICS security bulletins
💡 Threat Intelligence - AI Output Validation
When AI processes and republishes threat intelligence, human oversight remains necessary. This applies particularly to the validation of generated YARA rules and overall content accuracy.
Key Points:
• AI-processed threat intelligence requires verification.
• YARA rules generated by AI must be tested for accuracy.
• A human or an independent agent should review AI output.
✨ YARA - Community Contributions
This post acknowledges the contributors responsible for submitting bug fixes to the YARA project. Their efforts improve the tool's functionality and stability.
Key Points:
• Bug fixes are important for YARA's maintenance.
• Contributors are recognized for their work on these fixes.
• Community contributions aid project improvement.
🔗 Resources:
Image
Image
Image
🤖 Malware Analysis - APT36 and Vibeware
A new malware sample associated with APT36 (Transparent Tribe) has been identified and is available on VirusTotal. This group is reportedly shifting to an AI-driven malware development approach known as "vibeware".
Key Points:
• A new malware sample linked to APT36 is now on VirusTotal.
• APT36, also known as Transparent Tribe, is a Pakistan-based threat actor.
• They are using an AI-driven development model, "vibeware," for high-volume malware generation.
• Sample Hash: 39e6cd3e098a0c23f1695e3e8ad4a30c.
🤖 Malware Analysis - Mellowtel Activity
The Mellowtel malware family has re-emerged, as detailed in a recent blog post. This report outlines its recent activity and associated characteristics.
Key Points:
• Mellowtel malware is active again.
• Analysis of its recent activity is available.
🔗 Resources:
• Secure Annex Blog ↗ - Article discussing the re-emergence of Mellowtel
Image
Image
Image
Image
🤖 APT Research - Mirage Kitten Toolset
Research has identified new malware associated with the Mirage Kitten APT group. This group targets aerospace, aviation, defense, and telecommunications sectors in the Middle East and Africa.
Key Points:
• Mirage Kitten APT uses new malware.
• Targets include aerospace, aviation, defense, and telecommunications.
• Geographic focus is the Middle East and Africa.
• The toolset includes a new Windows backdoor and two custom WebSocket tunnelers.
🔗 Resources:
Image
💡 DEF CON - Photo and Recording Policies
DEF CON reminds attendees about its photo policies, specifically prohibiting meta-style glasses with recording capabilities. This rule applies even to prescription recording eyewear.
Key Points:
• Meta-style recording glasses are prohibited at DEF CON.
• This restriction includes prescription recording glasses.
• Attendees should review DEF CON's full photo policies.
🔗 Resources:
• DEF CON Photo Policies ↗ - Official guidelines on photography and recording
🤖 Software Supply Chain - Malicious Go Packages
Following a JFrog report on hijacked npm packages, telemetry data revealed over 15 malicious Go packages containing the same payload. Some of these packages remain available on GitHub and Go module proxies.
Key Points:
• Malicious payloads were found in over 15 Go packages.
• These packages used a consistent payload.
• Some affected packages are still accessible on GitHub and Go module registries.
🔗 Resources:
• GitHub Repository ↗ - Example of a confirmed malicious Go package
Image
💡 Software Supply Chain - Timestamp Reliability
This update clarifies the reported "2018 origin" for malicious Go packages. The initial assessment relied on Git commit timestamps, which are forgeable and therefore do not provide a reliable timeline for payload submission.
Key Points:
• Initial timeline for malicious Go packages was based on Git commit timestamps.
• Git commit timestamps (GIT_AUTHOR_DATE, GIT_COMMITTER_DATE) are easily forged.
• The 2018 origin for these payloads is now considered unverified.
⭐️ Support
If you liked reading this report, please star ⭐️ this repository and follow me on Github ↗, 𝕏 (previously known as Twitter) ↗ to help others discover these resources and regular updates.