Hackers breached propulsion system of U.S.-bound oil supertanker

Posted in Commentary with tags , on October 5, 2026 by itnerd

The FBI and The U.S.Coast Guard investigators found evidence that hackers gained access to the digital propulsion system of the VL Prosperity, a fully loaded oil supertanker bound for Galveston, Texas, according to Bloomberg.

The hackers had temporary access to the propulsion system as the vessel approached the Texas coast this summer. Investigators have not determined how the attackers gained access, how long they remained in the system, who was responsible or what ship functions they may have been capable of controlling.

The FBI and Coast Guard boarded the VL Prosperity in August after the vessel lost communications and authorities received indications that its network had been compromised. The agencies also boarded a second vessel in the Gulf of Mexico because of a suspected cyber threat. By September, U.S. agencies were tracking cyber threats involving nearly 20 vessels around the world and had requested advance notice if any planned to enter a U.S. port. The VL Prosperity remains anchored offshore Galveston as the investigation continues.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“Access and control are separate findings, and the public evidence on VL Prosperity stops before engine control. If investigators can show that an intruder reached a write-capable propulsion controller and issued a valid command, this would be the first publicly documented, independently confirmed cyberattack against a commercial vessel’s propulsion controls. That is a much bigger claim than temporary access to a digital system.

“Bloomberg reports that investigators found temporary access to the tanker’s digital propulsion system. The public joint statement from the Federal Bureau of Investigation and U.S. Coast Guard says the agencies boarded the vessel to examine its information technology (IT) and operational technology (OT) systems after indications that its networks were compromised. It reports no operational disruption, vessel instability, physical danger to the crew, or environmental impact.

“That distinction matters because a propulsion-related bridge console, engineering workstation, machinery automation gateway, and engine controller are materially different findings. The U.S. Coast Guard’s 2019 response to a malware incident aboard a deep-draft vessel is the useful comparison. The malware seriously degraded the ship’s onboard computer network, but investigators found that essential vessel control systems were unaffected. Maersk made a similar distinction during the 2017 NotPetya attack, when its shore and terminal systems were disrupted while its vessels remained maneuverable.

“The closest publicly documented physical-control event was the 2013 University of Texas test that moved a yacht off course by spoofing the Global Positioning System (GPS) and inducing navigation corrections. The researchers did not control the engine. In 2025, French authorities investigated Remote Access Trojan (RAT) malware found on the Fantastic ferry, but the operator said the intrusion was neutralized without operational consequences.

“VL Prosperity could change that record. The decisive evidence is a forensic trail showing a write-capable session sent a valid command to the engine controller and that the controller accepted it. Until authorities produce that, call this a propulsion-access incident. The public record does not yet support a confirmed propulsion takeover.”

ㅤ

Damon Small, Board of Directors, Xcape, Inc.:

“The rapid escalation from a single novel maritime intrusion to federal tracking of nearly 20 compromised vessels globally directly threatens an already precarious global oil market, creating upward pressure on crude prices and downstream refined products. These supertankers operate as self-sufficient floating cities governed by complex operational technology (OT) systems that manage crew life support, navigation, and critical cargo onboarding and offboarding. Although threat actor attribution remains unconfirmed, the scale and sophistication strongly suggest coordinated state-sponsored activity targeting maritime OT.

“A widespread compromise across vessel networks could ground entire fleets or trigger catastrophic physical disruption at sea. To mitigate these systemic risks, asset owners must enforce rigorous physical and digital network segmentation between vessel bridge controls, satellite communications, and IT networks, while implementing unidirectional security gateways and mandatory anomaly monitoring across onboard industrial control systems.”

“Critical Takeaways

  • “Escalating Market Impact: Global tracking of nearly 20 compromised vessels shifts maritime cyber risk from an isolated novelty to a material supply chain threat capable of driving up global oil prices.
  • “Complex OT Vulnerabilities: Supertankers rely on interconnected OT for life support, propulsion, and cargo operations, making unauthorized access to onboard control networks potentially devastating to fleet operations.
  • “Essential Defensive Controls: Security teams must enforce strict network segmentation between bridge IT, satellite communications, and OT systems, backed by unidirectional gateways and continuous industrial network monitoring.

“Air-gapping vessel networks only works if you do not run an ethernet cable straight from the satellite dish to the propulsion engine.”

Ladies and gentlemen, we welcome you to your next high value target. The good thing is that many of the defensive strategies are pretty much the same. Therefore those should be employed ASAP.

Inside a 50TB ransomware operation exposed by one open server

Posted in Commentary with tags on October 5, 2026 by itnerd

A Russian-speaking ransomware affiliate spent months breaching companies across six countries, then quietly betrayed the gang he worked for, running his own leak site on the side and publishing victims independently. A single exposed server gave up the whole operation, and a new investigation from CloudSEK’s threat intelligence team has now mapped it end to end.

Key highlights from the report:

  • The betrayal. The actor, who calls himself Azazel, worked as an affiliate of the Gentlemen ransomware group, using its tooling, negotiation channels and ransom note template. At the same time he ran an independent leak site, LEAKNED, publishing victim data independently without routing it through the Gentlemen program. Victims were exposed to both. It is not a pattern seen often in the affiliate world.
  • The scale. More than two dozen organisations across logistics, insurance, pharmaceutical, AI, medical devices and government-adjacent infrastructure, in six countries. The operator ran more than 50TB of dedicated physical servers, including a 22TB long-term vault built to retain loot across multiple campaigns, far larger than a typical affiliate setup.
  • One way in. Every confirmed victim was reached through stolen CI/CD secrets. A single compromised GitLab instance produced footholds at two unrelated organisations, and one CI/CD token exposed more than 150 databases across a SaaS platform and its clients, according to the operator’s own published claims.
  • A criminal first with AI tooling. Azazel registered a reverse shell as a callable tool inside an AI agent harness via the Model Context Protocol, and ran his attacks through it. CloudSEK found no prior public reporting of this technique outside this operation. He also built infrastructure to scan the internet for exposed AI assistant ports, and used an AI assistant to manage his own criminal infrastructure.
  • A deeper second campaign. Against one AI company, he ran a sustained compromise that began with an unvalidated AI imaging API, then moved through bulk credential decryption, a JWT token recovered from git history, offline Grafana password cracking and a full Kubernetes sweep. More than 6TB was taken, and the transfer was still running when investigators found it, growing by hundreds of gigabytes between observations.
  • Destruction after theft. In one case involving a government-linked financial registry, the actor exfiltrated more than 120,000 records, according to the operator’s own published claims, then deleted the victim’s live production database.
  • Attribution signals. Multiple operational scripts contain fluent Russian prose, and the staging server was codenamed “novostnik”, Russian for “newsman”.

Before publication, CloudSEK coordinated notifications to identified organisations that had not yet appeared on the leak site and shared full technical details with each named victim’s security contact.

The investigation is part of CloudSEK’s ongoing series documenting exposed attacker infrastructure. The full report, with the indicators of compromise, a detection rule and mitigation guidance, is here:

 https://www.cloudsek.com/blog/caught-in-4k-the-gentlemen-files

Guest Post – Flirt as an attack vector: The most expensive date you’ll never go on

Posted in Commentary with tags on October 5, 2026 by itnerd

If you think seduction as a tool for data gathering belongs solely in James Bond movies, think again. Cybercriminals are actively using flirtation and romance as attack vectors.

The FBI recently issued a public warning: Scammers are hijacking accounts to steal intimate content and sell it on criminal marketplaces or to blackmail victims, both adults and minors. The perpetrators pose as romantic interests to manipulate targets into revealing credentials, clicking malicious links, or sharing sensitive material.

A calculated emotional investment

“For an attacker, technical breaches are usually costly. Emotional ones are nearly free — they require only patience. Instead of investing in tools and code, criminals spend a week or two on conversations and compliments, creating the illusion of mutual understanding. When the trust or attraction is established, things can quickly go downhill,” says Deividas Ambrazevicius, an engineering manager at NordPass.

Ambrazevicius shared the story of a man who recently met a woman on vacation. They had a great time, and by day four, he received a link with a note: “Here’s our photo album, just for you.” Ten minutes later, his own personal photos, videos, sensitive files, and everything from active login sessions to internal documents were in someone else’s hands. No password was stolen — trust was. The victim clicked on the alleged link to a photo album and installed the malware himself, blindsided by emotions and a vacation romance.

Common romantic attack vectors include:

  • Flirtation as an opener. Emotional closeness dulls critical thinking. A link from a romantic interest gets scrutinized far less than one from your bank.
  • Fake relationships. Long-term emotional investment makes a single request — for money, photos, or credentials — feel natural.

“The weakest link isn’t the password — it’s the desire to be noticed. It’s also a risk for organizations. They must train employees to recognize emotional manipulation, not just fake banking emails. A romantic scam targeting an employee can become a gateway into corporate infrastructure. The most sophisticated firewall won’t help if an employee hands over credentials to someone they trust because of an emotional attachment,” says Ambrazevicius.

Hacker claims live access to SMS data linked to Airbnb, Uber, PayPal, Booking.com and Google

Posted in Commentary with tags on October 5, 2026 by itnerd

A hacker is selling 54 million records allegedly linked to Airbnb, Uber, PayPal, Booking.com, and Google.

The threat actor, known as Marx, claims to have live access to the source of the data, potentially allowing them to intercept sensitive communications, including authentication codes, as they reach users.

Cybernews researchers looked at the claims, here’s what they found:

  • The samples of data appear to originate from a single third-party SMS service.
  • The samples contain phone numbers and mobile carrier information, while the alleged Uber data also includes names of people who booked rides. The message contents seem to be heavily stripped.
  • The samples examined appear geographically limited to India and Oman, and researchers could not determine the full scope of the alleged breach.

If proven to be legitimate, such exposed data could result in increased risks of phishing attacks and, in some cases, account takeovers.

Here’s the full investigation:

https://cybernews.com/security/airbnb-uber-google-data-breach-claims

NETGEAR Enterprise’s first APEX and APEX MSP partners give customers access to validated network expertise  

Posted in Commentary with tags on October 2, 2026 by itnerd

NETGEAR today announced that Thomas-Krenn.AG and Connectivity Warehouse have become the world’s first partners to achieve APEX and APEX MSP certification, respectively, through the NETGEAR DRIVE Partner Success Program. For their customers, these certifications mean one thing above all: the engineering, sales, and service delivery capabilities of the team managing or installing their NETGEAR network have been independently verified before they ever arrive on site. 

When a network problem stops a production line, delays patient care, or takes down a multi-site organization, customers need answers fast. Whether they get them depends on whether their partner has the right skills in the room. NETGEAR introduced the DRIVE Partner Success Program in November 2025 to give customers a clear way to identify that expertise. Rather than recognizing partners for what they purchase, the program certifies them for what they can do: the engineers they have trained, the customer deployments they have validated, and the service practices they have implemented. 

Connectivity Warehouse — first APEX MSP partner 

For businesses that rely on a managed service provider to keep their network running, it’s important that the partner they choose will remain accountable even if something goes wrong six months after installation. APEX MSP is the DRIVE program’s highest tier, requiring partners to qualify three certified post-sales engineers and pass a live virtual audit of their IT service management practices, in addition to the engineering and sales certifications required for APEX. Connectivity Warehouse, a Dallas, Texas-area networking solutions provider serving offices, healthcare facilities, warehouses, and multi-site organizations, is the first partner worldwide to meet that standard. Its customers now have independently verified assurance that the team managing their NETGEAR infrastructure has been evaluated on service delivery, not just product knowledge. 

Thomas-Krenn.AG — first APEX partner 

Customers who work with Thomas-Krenn.AG to build server and storage infrastructure have historically needed separate expertise for the network connecting those systems. APEX certification changes that. Thomas-Krenn.AG, which has manufactured custom server and storage systems at its facility in Germany since 2002, has now certified its engineers and sales staff on NETGEAR infrastructure, meeting every APEX requirement including validated customer success stories. The businesses it serves in the defense, industrial, data center, and public sectors can now work with a single team qualified to design, deploy, and support both the server platform and the NETGEAR switching infrastructure that connects it. 

Further information about the NETGEAR DRIVE Partner Success Program is available at www.netgear.com/drive 

ThreatLocker CEO on Cyber Awareness Month: 5 Ways Businesses Can Limit the Damage From One Bad Click

Posted in Commentary with tags on October 2, 2026 by itnerd

As Cybersecurity Awareness Month kicks off, Danny Jenkins, CEO of ThreatLocker,  says businesses should look beyond simply training employees to spot phishing emails and focus on building security controls that limit what an attacker can do when someone inevitably makes a mistake.

Danny has outlined five practical steps businesses can take to reduce their exposure:

1. Don’t let one bad click become a breach.

“We spend a lot of time telling employees not to click suspicious links, but the reality is that someone eventually will. Good security isn’t about expecting people to be perfect. It’s about putting controls in place so one mistake doesn’t give an attacker the keys to the entire organization.”

2. Make “default deny” the default.

“If an application or process doesn’t have a legitimate reason to run, why should it be allowed to run? A default-deny approach changes the equation from trying to identify everything that’s malicious to only allowing what the business has already decided it trusts.”

3. Give users and applications only the access they actually need.

“Least privilege is one of the simplest ways to limit the damage from a compromised account. If a user, application or service doesn’t need access to a particular resource to do its job, that access shouldn’t be there in the first place.”

4. Treat remote access as an attack path that needs to be controlled.

“Remote access is essential for modern businesses, but every remote connection is another potential path into the environment. Companies should be asking who can connect, what they can access, from which devices, and whether that access is still necessary.”

5. Reduce the attack surface before attackers find it.

“Security teams can’t protect what they don’t know they have. Unused applications, outdated software, unnecessary services and forgotten remote-access tools create opportunities for attackers. One of the most practical things a business can do is regularly remove what it no longer needs.”

Danny also recommends combining these technical controls with ongoing employee awareness training, strong identity security, network segmentation, software updates and monitoring. ThreatLocker’s Cybersecurity Awareness Month guide covers these and other practical measures for businesses and consumers.

Your WAF is a lovely front door. Such a shame the attackers found the side entrance 

Posted in Commentary with tags on October 2, 2026 by itnerd

The Abstract ASTRO team have been studying AI attack agents with Eyal Sela & Gambit Security and have found some interesting playbooks. They just blogged about this late yesterday evening.

One small yet interesting piece: a method for finding the real server behind your CDN. They check SPF records, the staging subdomain someone forgot to proxy (oops), and your favicon hash sitting in Shodan. Once they find your origin, they go straight to it and your WAF never gets a vote.

They’re tidy, too. Tools get shredded, logs get scrubbed, and timestamps get backdated before you’ve finished your coffee.

But the nice thing about robots is they’re lazy in very predictable ways. And their cleanup routine reads like a checklist of commands your web server should never run. Thanks for the detection list, guys!

It’s all written up: a script to find your own origin leaks before they do, plus managed detections that fire while the attacker is still on the box (not three days later in a log review).

Homework for this week: does your origin only accept 80/443 from your CDN’s ranges? If you’re not sure, the answer is probably no.

Automotive SBOM market projected to quadruple as security demands expand 

Posted in Commentary with tags on October 2, 2026 by itnerd

The global automotive Software Bill of Materials (SBOM) market is projected to grow from $440 million in 2026 to $1.8 billion by 2034, according to a new Fortune Business Insights report.

The market is projected to grow at a 19.3% CAGR from 2026 through 2034, driven by software-defined vehicles, cybersecurity regulations, complex software supply chains and lifecycle vulnerability management.

Electric vehicles are projected to be the fastest-growing propulsion segment at a 22.4% CAGR, while buses and coaches are projected to be the fastest-growing vehicle segment at 23.7%. Tier 2 and lower-tier suppliers are projected to grow at 22.0%, while professional and managed SBOM services and vulnerability correlation, VEX and remediation-management solutions are each projected to grow at 20.4%.

The U.S. market is estimated at $80 million in 2026, representing approximately 19% of global revenue, while China is estimated at $110 million, or approximately 24.8%. The report also points to manufacturers increasingly moving from periodic SBOMs toward continuously generated SBOMs integrated into development and DevSecOps workflows.

Matt Wyckhouse, Founder & CEO, Finite State:

“The interesting thing about the growth of the SBOM market is that the SBOM itself is becoming table stakes. The hard problem isn’t producing a list of components; it’s continuously determining what’s actually inside increasingly complex vehicle software, whether a newly disclosed vulnerability creates real risk, and how quickly manufacturers and suppliers can respond. In automotive, that requires going well beyond traditional SCA and analyzing the firmware and binaries that actually ship in the vehicle.”

SBOM is one of the best ways to ensure that you don’t get pwned. Everybody should insist of seeing one before engaging a service or buying a product. Cars are a good example seeing as third party products are inside cars these days. If that happens, companies will get on board quickly.

OpenAI Proves Again That It Cannot Be Trusted On A Pair Of Fronts

Posted in Commentary with tags on October 2, 2026 by itnerd

If you needed more of a reason to not trust OpenAI, here’s a couple to choose from. First there’s this:

OpenAI has fired three researchers for allegedly mishandling information, including work that involved an external organisation that analyses artificial intelligence (AI) models.

“Our investigation confirmed that these individuals mishandled sensitive information outside established company procedures, violating our policies and breaking the trust essential to our work,” a spokesperson told the BBC.

The ChatGPT-maker did not name the sacked workers, but at least two of them were involved in safety research at the firm.

Gee. That looks really sketchy. Like OpenAI has something to hide. Maybe I am being cynical here. But if you combine it with this disclosure, maybe not:

Artificial intelligence leader Open AI said a rogue agent accessed a second NSW government website in June, with authorities only now made aware.

The NSW Premier’s Office released a statement on Friday night revealing OpenAI had advised the government of a “misalignment” involving a rogue AI agent which had accessed public data on a NSW government web application.

“An OpenAI model accessed a National Parks and Wildlife Service web application containing historical information and data on fires in NSW,” a government statement read.

“It’s understood the incident occurred in June 2026 and was validated by Open AI and reported through to NSW government on 1 October 2026.”

The statement advised current investigations had not identified any unauthorised access to personal information.

This comes after this incident which is also in Australia where an OpenAI agent accessed an Australian website in a rogue manner. If you combine both of those incidents, this looks really sketchy to me. And what it says is that OpenAI cannot be trusted. They clearly don’t have their house in order and you have to question if it will ever get there.

UPDATE: Commentary has come in from the following sources:

Willy Leichter, CMO, PointGuard AI (https://www.linkedin.com/in/willyleichter)

“The Australian breaches point to failures in containment, not an inevitable consequence of AI. OpenAI and other frontier model builders, along with any organization deploying agents, need rigorous operating procedures, restricted access, strong guardrails and immediate kill switches. Testing is no excuse for unauthorized actions. Organizations that recklessly build or deploy agents should face direct legal accountability for resulting harm. Greater autonomy must come with greater responsibility.”

Seemant Sehgal, Founder & CEO, BreachLock (https://www.linkedin.com/in/s-sehgal)

“A second disclosure in a week from the same AI provider against the same government shifts the conversation from whether individual incidents will happen to whether the party deploying these agents can be meaningfully held accountable when they do.

“An AI agent cannot face consequences for its own actions. It cannot be fined, suspended, or named in a court filing, which means accountability has to live with the organization that built and deployed it, through clear ownership, documented authorization scope, and real notification obligations when something goes wrong. AI companies that build human accountability into their processes will be the ones governments and enterprises can actually work with.”

Jeremiah Fowler, Security Researcher, Black Hills Information Security (https://www.linkedin.com/in/fowler-jeremiah-26814ab9)

“With the tidal wave of recent incidents it is clear that we cannot treat AI guardrails as if they are the same thing as security controls. Prompting an AI agent not to access something is different from technically preventing access. We have entered a new world in terms of speed and scale. An autonomous agent could potentially make thousands of decisions and interact with multiple systems before human moderators can realize it has crossed the lines. I think in the very near future we will see individual countries pass regulations that hold AI developers accountable for the actions of their agents. Once this happens there will be legal and financial penalties that will force companies to add guardrails or a kill switch. Until that happens we are in a wild west scenario of an unregulated industry that is off to a difficult start keeping AI agents contained.

“In my opinion, any organization that deploys autonomous agents and has an ‘incident’ should be ready to provide the owners or administrators of affected networks and systems with full transparency of what happened and how it happened. This would include details on what the agent accessed, which credentials it used, what commands or requests it issued, what information it retrieved or modified, and why its controls permitted those actions.” 

Jacob Krell, Sr. Director: Security AI Solutions & Cybersecurity, Suzu Labs (https://www.linkedin.com/in/jacob-krell)

“The second New South Wales incident makes it harder to describe these events as isolated misfires. A pattern is emerging, agents take a broad hand to their objectives and reach for any system or data source that might help.

“That risk becomes harder to control when agents operate in swarms. One agent can find a route, another can test it and a third can use the result. Monitoring a single session will miss the larger operation unless it captures agent-to-agent messages, shared state and the combined objective.

“The controls need to sit outside the models, with real-time visibility across the swarm and automatic blocks on unauthorized systems. Accountability also has to cover the people and company that gave the agents those permissions.

“No personal information was accessed in this case. That is a fortunate outcome, not evidence of effective control. OpenAI has already had to discover and disclose unauthorized activity after the fact. The question now is how many more incidents are waiting in its logs.”

Nearly 20 million Minecraft player records are allegedly for sale

Posted in Commentary with tags on October 2, 2026 by itnerd

Created by Markus “Notch” Persson and developed by Mojang Studios, Minecraft has over 212 million monthly active players, and now the players’ data surfaced in an alleged 18 million breach

Two posts on underground cybercrime forums claim that Minecraft players’ data has been breached. One threat actor says 18 million user records are for sale, while another post cites a more modest 9 million records.

Cybernews researchers investigated the claims, and here is what was found:

  • Supposedly, different datasets appear to be the same 1,000 records.
  • The sample contains usernames, email addresses, and, in some cases, password hashes. 
  • The records also appear to have been collected from specific Minecraft servers, with only 3 unique servers appearing across the sample.
  • Information could be used for credential stuffing and social engineering scams, particularly if email addresses are paired with passwords victims have reused elsewhere.

The team found that email addresses in the sample appear in Have I Been Pwned and are referenced in multiple infostealer combo lists. This suggests that the data source may be infostealer malware.

For more information, read the article here:

https://cybernews.com/security/minecraft-players-data-breach