🤖 Midnight Blizzard - AI-augmented Operations
This article describes Storm-2945's activity, also known as Midnight Blizzard, using AI-augmented phishing campaigns. It details their methods for gaining access and collecting data from Microsoft 365 environments.
Key Points:
• Storm-2945 initiated AI-augmented operations in February 2026.
• Attack methods include targeted device code and OAuth code phishing campaigns.
• These operations lead to Entra device registration and subsequent data collection from Microsoft 365.
• Activity continued and expanded since early May 2026, indicating ongoing threat presence.
🔗 Resources:
Image
Image
Image
Image
Image
Image
💡 Cybersecurity - Generic Detection Rules
This item highlights the utility of generic detection rules in identifying threats. It implies that broad-based rules can be effective against various attack patterns, offering wider coverage.
Key Points:
• Generic detection rules are effective for identifying diverse cyber threats.
• This approach provides broad coverage against various attack methodologies.
• Generic rules support the detection of unknown or evolving threat patterns.
🔗 Resources:
Image
Image
Image
Image
Image
🤖 Midnight Blizzard - Traffic Manipulation Attacks
This article reports on Midnight Blizzard's traffic manipulation campaigns targeting hotels globally. These operations aim to deliver malware or redirect authentication flows at their discretion.
Key Points:
• Midnight Blizzard is conducting widespread traffic manipulation attacks.
• These attacks target hotels globally.
• The objective is to deliver malware or redirect authentication flows.
• Activity since early May 2026 includes manipulation of DNS and HTTP traffic.
🔗 Resources:
Image
🤖 Threat Intelligence - LAPDOGS ORB Infrastructure
This intelligence update details the tracking of China-aligned LAPDOGS Operational Relay Box (ORB) infrastructure. It provides specific metrics and attribution information for this network.
Key Points:
• LAPDOGS is a China-aligned threat actor group.
• Their ORB infrastructure consists of 196 hosts across 19 distinct ASNs.
• The top observed countries for this infrastructure include Hong Kong, Japan, and Singapore.
• A sample IP address identified within this network is 1.9.117.13.
🔗 Resources:
Image
🤖 Linux Kernel - GhostLock CVE-2026-43499
This article announces research into exploiting a Linux kernel Stack Use-After-Free (UAF) vulnerability. The vulnerability is identified as GhostLock and tracked as CVE-2026-43499.
Key Points:
• A Linux kernel Stack UAF vulnerability, dubbed GhostLock, has been identified.
• This specific vulnerability is assigned CVE-2026-43499.
• Research exploring the exploitation of this UAF flaw is available.
🔗 Resources:
• Nebusec Research ↗ - Analysis of GhostLock Linux kernel UAF exploit
Image
🤖 Software Supply Chain - Malicious npm/PyPI Packages
This item reports the discovery of malicious packages on public npm and PyPI registries. Many of these packages were previously unknown and target AI developers with various attack vectors.
Key Points:
• Malicious packages were found on npm and PyPI public registries.
• 65% of these malicious packages were previously undetected.
• Attack methods include .env credential theft, crypto wallet stealing, and RCE droppers.
• Malware targets AI developers, including backdoors for #MCP servers.
🔗 Resources:
• Unit 42 Report ↗ - Details on extracted malware from public registries
💡 AI Development - Risk Management and Investment
This article discusses Leopold's perspective on managing risks in AI development, emphasizing "not blowing up" as a primary concern. It also touches on investment strategies related to AGI and superintelligence.
Key Points:
• Minimizing catastrophic risks in AI development is a top priority.
• Investment firms are making bets on AGI and superintelligence emerging this decade.
• Investment decisions reflect a belief in imminent AI breakthroughs.
🔗 Resources:
Image
💡 Threat Actor Behavior - Stealth vs. Operational Tactics
This item discusses observed threat actor behavior where stealth is not prioritized. It suggests that security models often fail to account for how real-world adversaries operate when their methods are not public.
Key Points:
• Some threat actors do not prioritize stealth in their operations.
• This observation indicates a potential blind spot in current security models.
• Understanding adversary behavior should consider methods not designed for public visibility.
🚀 Chrome Security - Bug Fixes
This item highlights an increase in security bug fixes within Chrome. Specifically, Chrome 149 and 150 addressed a notable number of vulnerabilities.
Key Points:
• Chrome versions 149 and 150 fixed 1072 security bugs.
• This number surpasses the total bug fixes from the prior 23 milestones combined.
• The recent volume of security patches indicates focused remediation efforts.
✨ Browser Extension - ClippyMon Clipboard History
This article introduces ClippyMon, a new browser extension designed to maintain a history of copied and pasted content. It helps users recall previously copied text.
Key Points:
• ClippyMon is a browser extension that tracks clipboard history.
• The extension helps users recall content they previously copied.
• It provides a utility for managing past clipboard data.
🔗 Resources:
Image
⭐️ Support
If you liked reading this report, please star ⭐️ this repository and follow me on Github ↗, 𝕏 (previously known as Twitter) ↗ to help others discover these resources and regular updates.