Hugging Face Breached by Autonomous AI Agent

Posted in Commentary with tags on July 20, 2026 by itnerd

Open-source AI and machine learning platform Hugging Face said it detected and responded to an intrusion into part of its production infrastructure. They said it was different from anything they had previously handled in that it was driven end to end, by an autonomous AI agent system that accessed to a limited set of internal datasets and to several credentials used by their services,

Hugging Face has posted details here: https://huggingface.co/blog/security-incident-july-2026

Rohit Valia, CEO of cybersecurity company Tumeryk, provided the following comments: 

“Open source model repositories like Hugging Face now represent a meaningful supply chain risk. As adversaries increasingly target training and fine-tuning data rather than source code, organizations need to test open source models for behavioral drift, not just code-level vulnerabilities. An AI trust score gives enterprises a way to verify a model hasn’t been altered and is safe to use, while aligning to frameworks like the Cloud Security Alliances RiskRubric v2 which provide the structured testing methodology.”

If you use Hugging Face, you might want to see if you are at risk. And you might want to do it sooner rather than later.

UPDATE: Two more comments came in staring with Gidi Cohen, CEO & Co-Founder, Bonfy.AI:

“This incident should be a wake-up call, not because AI was involved, but because it shows how fast AI-native attacks are outpacing security programs.

An autonomous agent didn’t use fancy tricks, it just exploited familiar gaps in the system like code execution paths, credentials, and lateral movement. The difference is speed. Thousands of coordinated actions across short-lived environments shrank the response window from days to hours.

The bigger issue is defense. Hugging Face found its own response constrained by model guardrails. This s a new imbalance we see everywhere: the attacker operates without limits, while defenders (security personnel or security platforms) rely on tools that can refuse to help. If your company’s response tech stack isn’t fully under your control, your security posture isn’t either.

From this case, we have three takeaways for leaders: 1) “Data as code” is now a real attack surface. 2) Speed is the new risk multiplier. 3) You need internal, controllable AI for incident response, not just external APIs.

Security is shifting from hardening systems to operating at the speed of agents with tools you own. Organizations that plan for both sides of AI (attacker and defender) will set a new baseline for resilience.”

Toghrul Tahirov, Head of AI Governance,  Polygraf AI

“What stands out to me in this Hugging Face incident is that the attack reportedly began with something organizations routinely trust: data entering an AI processing pipeline. Once AI agents can execute code and access infrastructure, a malicious dataset is no longer just bad content. It can become an entry point for credential theft and lateral movement. This is a reminder that AI systems must be treated as privileged software, not as just a smarter generation of the chatbots we’re used to.

My professional opinion is that secure AI adoption requires controls around the entire interaction: inspect untrusted data, isolate execution, minimize permissions, use short-lived credentials, restrict network access, and maintain clear audit trails. Organizations also need incident-response tools they can operate privately without exposing sensitive evidence. The answer is not to avoid AI agents, but to ensure governance and security ar

UPDATE #2: More commentary starting with John Strand, Owner, Black Hills Information Security, Inc.

“There are plenty of jokes to be made about autonomous AI agents attacking a website that hosts autonomous AI agents, but that’s not the part that concerns me. What caught my attention was the claim that everything had been verified as clean despite hosting more than 45,000 models. At that scale, what does ‘verified clean’ really mean? Validating tens of thousands of models is an enormous challenge. That’s the reality we’re going to keep running into with software supply chain attacks. Whether it’s Hugging Face or any other platform hosting code that developers depend on, proving that everything is truly clean is only going to get harder as these ecosystems continue to grow.” 

Donald McFarlane, Advisory Board Member, Xcape, Inc. 

“This incident underscores how AI is changing the economics of cyber offense. AI-enabled tools allow attackers to automate reconnaissance, accelerate exploitation, and operate at machine speed. Just as leaders who eschewed advances such as longbows, RADAR, or drones have repeatedly found themselves facing defeat, defenders cannot afford to ignore AI. We must leverage AI to modernize cyber defense so as to increase attackers’ costs while reducing defenders’ workload. Meanwhile, organizations continue to need strong identity controls, segmentation, containment and resilience. 

“Although Hugging Face reports no evidence that public models or the software supply chain were modified, incidents like this highlight the importance of protecting not only infrastructure, but also the credentials, private repositories, datasets, and deployment pipelines that support modern AI development.” 

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs

“Dataset processing pipelines get the same level of security scrutiny that CI/CD hooks and build functions get, which is almost none. Teams pour AppSec effort into the application layer and treat the infrastructure that ingests and transforms data as plumbing. The attacker exploited a remote code loader and a template injection in that plumbing, then let an autonomous agent framework chain them across 17,000 actions in a weekend. 

“A human attacker running that campaign needs a team and weeks. The agent framework did it with short-lived sandboxes and command-and-control staged on public services. Keeping pace requires AI-assisted incident response, and Hugging Face found out what happens when you reach for it mid-breach. 

“Hugging Face’s team fed attack logs to commercial frontier models, and safety filters blocked the analysis because the logs contained real exploit payloads. They ran GLM 5.2, an open-weight model, on their own infrastructure instead. I’ve hit the same wall. I still run Opus 4.6 for security work and haven’t upgraded because newer models’ guardrails increasingly block legitimate analysis of exploit code and attack artifacts. 

“Machine-speed exploitation requires machine-speed response, and that response can’t run on models that refuse to examine the evidence.” 

Waseem Ahmed, Head of Engineering, Secure.com:

   “For years we talked about the agentic attacker as a someday problem. Hugging Face just made it today’s problem. One agent, no human at the keyboard, credentials stolen and infrastructure crossed in a single weekend.

   “The response is as telling as the attack. Hugging Face used AI to reconstruct the full attacker timeline in hours rather than days — processing thousands of events that would have taken a human team far longer to sequence. AI ran the attack. AI ran the investigation. That is the new baseline.

   “The part that should concern every security team: you cannot out-click an attacker operating at machine speed across 45,000 models and 50,000 customer environments. The only viable answer is defence that runs at the same speed and never clocks out — AI that watches, triages, and acts alongside your team every hour of every day.

   “Fight autonomous attacks with autonomous defence, or you will always be a step behind.”

DPRK ClickFake Interview Campaign Drops PylangGhost and GolangGhost RATs

Posted in Commentary with tags on July 20, 2026 by itnerd

The SOCRadar Threat Research Unit (STRU) published an in-depth analysis of the latest ClickFake interview campaign, a North Korean social engineering operation targeting cryptocurrency and Web3 professionals with fake job interviews. 

In this campaign, operators pose as recruiters to walk targets through a bogus skill assessment that ends in a copy-and-paste command, delivering the PylangGhost RAT on Windows and the GolangGhost RAT on macOS. 

Key points include: 

  • Famous Chollima (aka Wagemole) is a North Korean-aligned threat actor that has been highly active through the Contagious Interview and the latest ClickFake Interview campaigns.
  • For ClickFake Interview the actors are creating fraudulent companies or impersonating known ones in the crypto industry, and reach out to targets on social media (e.g., LinkedIn), inviting them to ClickFix empowered fake skill assessments.
  • Their ClickFix panels incorporate gating, tailored questions based on advertised roles, psychological pressure to act fast, video recording, and social engineering that pushes targets to run malicious commands through fake camera errors.
  • The final payloads target both Windows, by deploying PylangGhost RAT, and macOS, by deploying GolangGhost RAT alongside a credential-harvesting SwiftUI application.
  • PylangGhost and GolangGhost consist of six interconnected modules: a main orchestrator, a configuration holder, an archive helper, a command launcher, a C2 component, and a stealer.
  • Both payload chains download the runtimes needed to run in victim environments: Python’s interpreter for PylangGhost and Golang’s compiler for GolangGhost.
  • In the latest variation of PylangGhost, the attackers also compiled their payloads as Python dynamic modules with Nuitka to further complicate detection and analysis.
  • Famous Chollima actors register multiple domains for their fake skill assessments, predominantly on Hostinger and NameCheap registrars, emphasizing speed and scale, rather than operational security and infrastructure resilience.

For full details, this study can be read here: https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/

New Fortra Benchmark Report: 9 out of 10 Phishing Emails Go Unreported 

Posted in Commentary with tags on July 20, 2026 by itnerd

Fortra’s new 2025 Phishing Simulation Benchmark Report analyzed 14 million recipients across 7,500+ simulations and found a concerning reality: While click rates average just 5.4%, nearly 90% of phishing emails go unreported.

The findings suggest organizations are measuring the wrong thing. While click rates remain a common benchmark, the greater risk is that 9 out of 10 malicious emails go unreported, denying security teams the visibility needed to stop active campaigns. As the report notes, “a single report may be the difference in determining whether a phishing campaign is successful or not.”

The data also reveals significant differences in phishing susceptibility across regions, languages, company sizes, and industries. Notably, defense employees clicked on phishing emails 13% of the time – more than double the global average, while insurance employees opened attachments 12.6% of the time, highlighting how phishing risks vary widely and where targeted awareness efforts may be most needed.

The full report can be accessed here: https://www.fortra.com/resources/guides/2025-phishing-simulation-benchmark-report

Craneware Pwned In Cyberattack

Posted in Commentary with tags on July 20, 2026 by itnerd

Healthcare technology firm Craneware, which provides software to hospitals, clinics and pharmacies across the US, has disclosed a cyberattack in which hackers stole customer and employee data.

The Company’s incident response plan has been activated, including the appointment by the Board of external cyber security and forensic specialists. Their investigation is ongoing, alongside the Craneware IT team and the Company’s retained cyber security service providers.

The incident has been contained and there has been no disruption to customer services or to the Company’s operations. The external specialists have confirmed that there are no residual indicators of compromise arising from the cyber security incident in the Company’s systems

Jeff Hamm, Solutions Architect at Binalyze had this comment:

“Craneware’s disclosure is a reminder that an incident isn’t defined solely by whether systems stay online. Once data has been accessed and exfiltrated, the priority shifts to understanding exactly what happened, what information was affected, and what the downstream risk is for customers and partners.

“The next few days will be about evidence. Regulators, customers and investors will all want clear answers, but those answers have to come from a thorough forensic investigation, not early assumptions. Organizations need to establish what data was accessed, whether the attacker achieved persistence, and whether there is any ongoing risk to connected systems.

“There is currently no indication that customer environments have been compromised, but any exposure of customer or partner information can increase the risk of highly targeted phishing, credential theft and other follow-on attacks. This is why incident response isn’t just about restoring operations. It’s about giving leadership the confidence that decisions are being made from evidence, and giving customers confidence that the organization understands the full scope of the incident.”

Honestly, if an environment has been pwned, it’s bad news. Everyone needs to do everything possible to make sure that they are not the next victim. Otherwise bad things will happen.

Hisense Delivers $500,000 in Cashback to Canadians Following Team Canada’s FIFA World Cup 2026™ Run

Posted in Commentary with tags on July 20, 2026 by itnerd

Hisense Canada is celebrating Team Canada’s historic performance at the FIFA World Cup 2026™ by delivering up to $500,000* in cashback rebates to Canadian consumers through its Win With Canada promotion, unlocking the campaign’s maximum reward pool.  

As an Official Partner of the FIFA World Cup 2026™, Hisense launched the promotion to give Canadians a tangible way to share in Team Canada’s success. Cashback rewards on eligible Hisense televisions, Laser TVs and select home appliances increased as Canada advanced through the tournament, culminating in the campaign’s maximum reward level of up to $1,000 cashback per eligible purchase following Team Canada’s historic tournament performance. 

The campaign generated strong participation across the country, with more than 575 rebate submissions received to date, subject to validating in accordance with program terms. Hisense’s 85-inch U88 Series TV emerged as the campaign’s best-selling model, followed by Laser TV products and 98-inch televisions, reflecting growing consumer demand for large-screen, immersive viewing experiences during major sporting events. 

With Canadians increasingly choosing larger screens to watch live sports, the tournament highlighted the important role home entertainment plays in bringing friends and families together. Through Win With Canada, consumers were able to upgrade their viewing experience while sharing in Team Canada’s success. The promotion also reinforces Hisense’s continued investment in Canadian consumers through innovative marketing programs. 

Although the purchase period has ended, eligible customers still have time to submit their receipts and claim their cashback through the campaign website. 

For more information, please visit winwithcanada.ca

About Win With Canada 

Win With Canada was a Hisense Canada promotion that rewarded consumers as Team Canada advanced through the FIFA World Cup 2026™. Purchasers of eligible Hisense televisions, Laser TVs and select refrigerators qualified for cashback rebates tied directly to Team Canada’s tournament performance. Following Team Canada’s historic FIFA World Cup 2026™ run, the promotion reached its maximum reward level, unlocking up to $1,000 cashback for eligible customers and a total reward pool of $500,000.* 

Consumers who purchased qualifying products during the promotion period can visit WinWithCanada.ca for complete program details and cashback redemption information. 

*Cashback rewards are subject to the terms and conditions of the Win With Canada promotion. In the event that eligible validated claims exceed the program’s maximum reward pool, rebate amounts may be adjusted on a pro rata basis in accordance with the promotion rules. For full details, visit WinWithCanada.ca. 

Netchex Launches Mesh: AI HR Teammates for the Deskless Workforce

Posted in Commentary with tags on July 20, 2026 by itnerd

Netchex, a payroll and human capital management (HCM) platform for businesses with deskless workforces, today announced Mesh, a team of AI HR teammates that anticipate problems and complete work before anyone asks. It goes beyond the ask-and-answer chatbots that define most AI in HR today.

Most HR software is built for the corporate office. But in a restaurant group, a hotel, a dealership, a healthcare practice, or another real-world business in America, roughly 80% of employees never sit at a desk. Shift swaps happen over group texts and timecards come in late. The HR teams behind these operations are lean and chronically understaffed. Often a single admin is running payroll, approving timecards, fielding PTO requests, and onboarding new hires, all before lunch. None of it is hard. All of it adds up.

Rather than waiting to be asked, Mesh’s six specialists continuously monitor payroll, scheduling, time, and HR data. Each handles a complete workflow, with humans approving the decisions that matter:

  1. Penny, a payroll assistant who chases missing timecards and flags payroll issues
  2. Atlas, a people ops coordinator who connects onboarding, status changes, documents, and approvals
  3. Sentinel, a compliance and risk analyst who watches for patterns and gaps teams don’t have time to see
  4. Nova, a workforce analyst who turns scattered data into signals managers can act on
  5. Milo, an employee concierge who files PTO, arranges shift coverage, pulls pay stubs, and answers policy questions instantly
  6. Nettie, a service partner who troubleshoots issues and answers product questions for admins, drawing on every Netchex knowledge article and training resource

These six are the founding roster. Netchex plans to add more teammates over time. Because Mesh sees across pay, scheduling, time, and HR in one platform, it connects dots other tools see only in pieces: flagging a schedule-loading pattern that is turning a strong employee into a flight risk, or catching expiring technician certifications weeks before they create a staffing gap.

Mesh builds on Netchex’s acquisition of Mesh.ai, a Y Combinator backed, AI-first performance and engagement platform. After the acquisition, the Mesh.ai team set out to scale the technology across every workflow an HR team touches, and built the AI teammates announced today.

Mesh also works where teams already are. Employees can file PTO, swap shifts, and check pay stubs directly inside ChatGPT or Claude. Managers can spot overtime trends and approve requests. Admins can run payroll audits and pull headcount reports without opening Netchex. Nothing sensitive is submitted without human approval.

Customers in Netchex’s early access program report winning back roughly half of their Monday admin time and a double-digit drop in payroll corrections (directional results from early access, not audited benchmarks). Gartner predicts 40% of enterprise applications will feature task-specific AI agents by 2026, up from less than 5% in 2025.

Mesh is rolling out to Netchex customers, beginning with early access. To meet the AI teammates or request a demo, visit www.netchex.com/mesh.

What the Oracle vulnerability says about today’s patching problem

Posted in Commentary with tags , on July 17, 2026 by itnerd

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite (EBS) financial application. The directive to repeat states that as mandated by Binding Operational Directive (BOD) 26-04, this needs to be patched by tomorrow. AKA Saturday.

Ted Miracco, Approov (https://www.linkedin.com/in/tedmiracco)

“Organizations continue to struggle to patch critical vulnerabilities quickly because enterprise resource planning (ERP) platforms like Oracle and SAP are highly customized and deeply interwoven with other business applications. Patching them isn’t like updating a web browser; a single database update can break custom API integrations, halting payroll, shipping, or manufacturing.

“The window for ‘safe testing’ no longer exists for edge-facing systems. In the past, organizations had 30 to 90 days to test and deploy patches before exploits were widely weaponized. Today, threat actors reverse-engineer patches and deploy exploits within days or even hours.

“To better prioritize and respond to these types of threats, security teams must implement strict Web Application Firewall (WAF) rules, sever internet exposure, or place vulnerable assets behind a Zero Trust Network Access (ZTNA) gateway until patches can be safely tested. When patches can be deployed to a staging environment, tested automatically, and instantly rolled back if they fail, emergency deployments become a low-risk routine rather than a weekend crisis.”

Damon Small, Board Member, Xcape, Inc. (https://www.linkedin.com/in/damon-small-7400501)

“Deploying a patch on a single computer may seem like a trivial task, but doing it across an enterprise that may have hundreds, or even thousands, of servers is daunting.  That said, we have seen incidents where a patched vulnerability is exploited months after it was resolved.  As an industry, we must strike a balance between operational readiness and patching fatigue.

The first open source vulnerability scanner was released in 1995.  Since then, vulnerability management has remained the least sexy, yet the most important, directive in cyber security.  Frankly, as an industry, we struggle to update software quickly, and this fact will become more problematic as the time between vulnerabilities being discovered and them being actively exploited continues to shrink.

Security leaders should first and foremost ensure that their organizations have accurate software and hardware inventories. You cannot defend what you can’t see. Additionally, as ‘silent’ or no-reboot patching becomes an industry standard, automatic updates may follow.”

Donald McFarlane, Advisory Board Member, Xcape, Inc. (https://www.linkedin.com/in/dmcfarlane)

“Organizations rarely fail to patch because they lack another alert: they struggle when they lack reliable asset inventories, clear ownership, tested maintenance paths, or the authority to interrupt business-critical systems and processes. In today’s machine-scale, machine-speed adversarial environment, IT organizations must deploy critical security patches far more quickly.  When immediate patching is not possible, leaders must prioritize vulnerabilities based on active exploitation, internet exposure, mission impact and potential blast radius, not severity scores alone.  They should know in advance who owns each critical system, how it can be isolated, and how emergency changes can be made safely.  

“Patching is not the finish line: organizations must determine whether an adversary arrived before the fix was applied. Find material exposure before an adversary does, fix it, and prove the risk actually went down.”

Kevin Surace, CEO, Token (https://www.linkedin.com/in/ksurace)

“Patching is rarely as simple as installing an update. Critical enterprise applications are often deeply connected to financial systems, databases, customized workflows, and third-party software, so teams fear that an untested patch could interrupt essential operations. 

“The deeper problem is that many organizations do not have an accurate, continuously updated inventory of their systems. They may not know which servers are exposed to the internet, which versions are running, who owns them, or whether a patch was successfully applied.

“In this case, Oracle released the patch in May, exploitation was observed by late June, and more than 1,000 Oracle E Business Suite systems were still exposed to the internet in July. That is not primarily a technology failure. It is a failure of ownership, visibility, testing capacity, and executive accountability.

“Urgent federal patching orders and extremely short remediation deadlines are becoming more visible, but this particular action was not technically a standalone Emergency Directive. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog under Binding Operational Directive 26 04 and required remediation within three days.

“The significance is the deadline. CISA is effectively telling agencies that once exploitation is confirmed, the traditional patching cycle is no longer acceptable. Attackers are weaponizing vulnerabilities faster, while many organizations are still operating through monthly maintenance windows, lengthy approval processes, and manual asset reviews.

“These directives also reveal an uncomfortable truth: too many organizations still need an external government deadline to force action on vulnerabilities that vendors have already patched.

“Security leaders should prioritize vulnerabilities based on actual exploitation, internet exposure, business importance, and the potential impact of compromise, not simply on the severity score. A vulnerability that is being actively exploited against an exposed financial system should move immediately ahead of a higher scoring flaw on an isolated test machine.

“Every critical system needs a named business owner, a technical owner, a tested emergency patching procedure, and a clearly defined authority capable of accepting the operational risk of patching or the security risk of delaying it. When exploitation is confirmed, teams should be able to patch, isolate, restrict network access, or temporarily remove a system from service without waiting through days of meetings.

“Organizations should also assume that patching may come too late. Organizations must review logs for evidence of earlier exploitation, rotate potentially exposed credentials, inspect connected systems, and protect privileged access with hardware based biometric assured identity.

“Biometric assured identity would not prevent an unauthenticated Oracle software exploit such as this one. It can, however, stop attackers from turning stolen administrator credentials into broader access after the initial compromise. Patching closes the software vulnerability. Biometric assured identity helps contain what attackers can do next.”

Steven Swift, Managing Director, Suzu Labs (https://www.linkedin.com/in/steven-swift-5238956a)

“Patching is a big thankless task, and it rarely gets the resourcing it would require to actually patch all the things quickly. In order to have any chance at keeping up with patching, organizations need to implement solutions to automate both patching and vulnerability scanning.

“A lot of organizations are hesitant to patch immediately, because there have been enough issues with bad patches being released over the years, that the risk of patching slowly is preferred over the risk of patching fast and breaking things.

“Patching automation is great for those systems which are consistently deployed across the organization. However, the applications that are only on a few systems are those least likely to have automated patching. This would be fine, except for that there tends to be a lot of applications that fall into this category. Practically, that means staff can patch the vast majority of things consistently and in a timely manner, and still always have a long tail of vulnerabilities that are more challenging to fix.

“This is compounded when ownership is split between different teams. Especially so when organizational priorities are split. If teams are under pressure to hit tight deadlines, the last thing they want to do is spend time fixing/patching things that don’t directly assist in that goal. This results in a lot of vulnerability management teams spending much of their time providing reports on what needs patching, to teams that will get to it when they get to it.

“As for what leadership can do to better prioritize and respond to new vulnerabilities? A big part of is keeping metrics so that the work being done isn’t invisible anymore. If the team is consistently patching 90% of all published CVEs in a timely manner, and yet all that leadership sees are reports showing the remaining 10%, it can look like the team just isn’t doing much patching when the opposite is true.

“Track stale vulnerabilities in the organization, and prioritize those. Stale can be older than 30, 90, or 365 days for example. Depending on how mature existing processes are. Once all of the stale vulnerabilities are remediated, build automation to handle as much repeatable work as is possible. Provide developers with vulnerability feedback as early in the process as you can, as it costs much less time and money to fix code early on, than it does after release.”

While it is beyond time to patch all the things, organizations need rethink how they go about keeping their environments safe. Because patching is clearly not enough.

FIFA World Cup Fraud Campaigns, an Analysis

Posted in Commentary with tags on July 17, 2026 by itnerd

The SOCRadar threat research unit (STRU) has published an in-depth analysis of fraud campaigns associated with the 2026 FIFA World Cup. With the final coming up this Sunday, SOCRadar has tracked the fraud ecosystem between April and July, spanning the counterfeit merchandise stores, FIFA portal impersonation, and ticketing/betting infrastructure. 

Interestingly, rather than peaking during the tournament’s biggest matches such as earlier this week’s semi-finals, fraud activity peaked before kickoff, as operators activated infrastructure that had been prepared weeks in advance. 

Key findings of this research include: 

  • The FIFA portal impersonation cluster, linked to the GHOST STADIUM phishing-kit lineage, now spans 850+ domains – nearly triple the 300+ publicly reported in May. STRU reconstructed the kit’s evolution through the developers’ own Chinese-language code comments, including a documented bug fix and an OPSEC migration between two generations – effectively the threat actor’s own development log.
  • 79% of domains observed at the activity peak were registered within the previous 30 days. Operators quietly bought infrastructure in May and activated it at the tournament’s opening.
  • The betting network hacked nothing. It legally purchased expired domains – a defunct US staffing agency, a French artisan site – for their retained SEO authority, a supply chain that is legal, frictionless, and largely beyond the reach of technical controls.
  • Counterfeit storefronts burned through domains in under five days and used deliberately modest 22-30% discounts, calibrated to look like a plausible promotion rather than a scam.
  • STRU also disproved three of its own most striking leads – a shared Telegram bot token, an identical registrant hash, a common template – all artifacts of shared infrastructure, not shared operators. A transparency point that sets the research apart from typical vendor reporting.
  • Defender takeaway with legs beyond the World Cup: for event-driven fraud, the critical monitoring window is before the event begins – directly applicable to the 2028 Olympics and every future major event.

For full details on SOCRadar’s findings, the research can be read here: https://socradar.io/blog/fifa-world-cup-2026-fraud-campaigns/

Trojanized Zoom/WebEx installers expose a growing trust problem

Posted in Commentary with tags , on July 17, 2026 by itnerd

Researchers are tracking a campaign distributing trojanized Zoom and WebEx installers to steal credentials and other sensitive data. The culprit, not that it matters, are Russians. This serves as a reminder that attackers are increasingly weaponizing trusted business software instead of relying on traditional phishing lures.

You get get more info here: https://www.bleepingcomputer.com/news/security/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware/

Donald McFarlane, Advisory Board Member, Xcape, Inc.

“Trust is part of the attack surface: attackers do not need to invent unfamiliar lures when they can impersonate the applications, people and workflows that employees already trust.

“AI continues to raise the quality and scale of such attacks. Adversaries can produce more convincing phishing, deepfakes, counterfeit interfaces and customized malware far faster than before, and security programs must therefore assume that even careful users will sometimes be deceived. The answer is not more training alone, but stronger controls around software provenance, managed installation, application execution, identity, endpoint behavior and unusual network activity. 

“Organizations should design systems so that a convincing fake cannot easily become a compromise, and so that blast radii are limited.”

Kevin Surace, CEO, Token (https://www.linkedin.com/in/ksurace)

“Attackers impersonate applications such as Zoom and Webex because employees already recognize, trust, and routinely install them. A familiar product removes much of the hesitation that an unknown application would create and makes the malicious download appear to be part of normal business activity.

“The attackers do not need to invent a compelling new story. They simply borrow the reputation, branding, and expected behavior of software the victim already uses.

“User trust has become one of the attacker’s most effective tools. The victim is not persuaded to run something that looks malicious, but rather something that appears necessary and legitimate. This is why employee awareness alone cannot solve the problem. Attackers only need one employee to trust the wrong installer once, and increasingly convincing websites, messages, and software packages make that mistake difficult to eliminate completely.

“Organizations should prevent employees from installing unauthorized software and distribute approved applications through controlled enterprise software portals. Application allowlisting, code signing verification, endpoint detection, restricted scripting tools, browser download controls, network segmentation, and automatic isolation of suspicious systems can help stop the malware before it becomes established.

“Organizations must also protect the identities and accounts the malware is designed to steal. Hardware based biometric assured identity makes stolen passwords and authentication codes useless because access still requires the registered physical device, the authorized user’s fingerprint, proximity to the computer, and a cryptographic request from the legitimate domain.

“Biometric assured identity does not replace endpoint security or prevent someone from downloading malware. It ensures that even when malware captures credentials, attackers cannot simply reuse them from another device to enter protected applications, cloud services, or corporate networks.”

Jacob Krell, Sr. Director, Secure AI Solutions & Cybersecurity, Suzu Labs (https://www.linkedin.com/in/jacob-krell)

“The shift to hybrid work changed how business software gets installed. Five years ago, IT deployed conferencing and collaboration tools through managed packages. Now employees download Zoom, WebEx, and remote administration tools themselves five minutes before a meeting or a support session, with no oversight and no verification beyond ‘does the website look right.’ 

UAT-11795 is exploiting that behavioral shift across multiple categories, from conferencing platforms to database clients to developer utilities. A trojanized installer works because the real software actually installs and runs. The user joins their meeting, opens their database, never suspects a thing. Meanwhile, endpoint security has improved at catching novel binaries, so attackers wrapped their payload inside software the endpoint already expects to see.

“User trust has become just the first domino in these attacks. The security stack trusts these applications too. EDR tools baseline their behavior and suppress alerts on their process activity. Firewalls allow their traffic patterns. Allowlists include their binary names.

“When attackers wrap malware inside a WebEx or Zoom installer, they inherit trust at every layer simultaneously, from the human, the endpoint agent, the network policy, and the application control rules. Enterprise business software sits at the intersection of human trust and automated trust. Attackers are picking targets where those compound.

“Organizations should restrict where software installs come from. If users can only install applications through a managed catalog like Intune or SCCM, a trojanized installer from a random URL never executes. That’s the prevention layer most orgs skip because it creates friction with end users.

“For detection, publisher code signature verification on installers is the first check. UAT-11795 used NSIS to package their payload, so the installer carries no legitimate vendor signature. Most orgs enforce signature checks on running executables but not on the installers that put them there.

“Process lineage monitoring is the backstop. Conferencing software spawning Python interpreters, database tools creating scheduled tasks with random suffixes, those are process tree anomalies that EDR can catch if the detection rules exist. I’ve seen environments where broad filename matching on the allowlist lets anything that looks like a business app sail through unchecked.”

This should serve as a warning that only trusted apps, as in trusted from your organization, are the only ones that need to be installed. All others should be discarded like the garbage that they are.

Cyberattack on Japanese refrigerated logistics provider disrupts restaurants

Posted in Commentary with tags on July 17, 2026 by itnerd

A cyberattack on Nichirei Logistics Group, Japan’s largest refrigerated logistics provider, has disrupted food deliveries to restaurants, retailers, and food manufacturers across the country.

The company, which serves approximately 5,000 customers through a network of 140 refrigerated distribution centers, confirmed hackers breached its servers and shut down key systems to contain the incident.

The disruption has affected all 1,300+ KFC Japan restaurants, with the chain warning of ingredient shortages, limited menus, shorter operating hours and potential temporary closures. KFC has also suspended online ordering through its website and mobile app.

Other businesses reporting delivery delays or product shortages include Hotto Motto, Yayoi Ken, Kura Sushi, retailer Aeon and frozen food manufacturer TableMark.

Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:

“This incident highlights how cyberattacks against operational technology and logistics providers can have immediate real-world consequences. While many organizations focus on protecting customer data, attacks that disrupt the availability of critical business systems can be just as damaging. In this case, the ripple effects extended from a single refrigerated logistics provider to thousands of restaurants, retailers, and food manufacturers that depend on timely deliveries.

 “Organizations should view this as a reminder that cybersecurity risk extends beyond their own environment. Critical third-party providers should be evaluated not only for their security posture, but also for their operational resilience and recovery capabilities. Business continuity planning should include scenarios where key suppliers become unavailable due to a cyber incident, with contingency plans for alternate suppliers, manual processes, and inventory management.

 “As attackers increasingly target supply chains to maximize disruption, resilience has become just as important as prevention. The organizations that recover the fastest are those that have already planned for the possibility that a critical partner will be temporarily offline.”

Donald McFarlane, Advisory Board Member, Xcape, Inc.:

“This incident is another reminder of the importance of supply-chain dependencies, and how cyber risk can cascade from one logistics provider into thousands of businesses and their customers.  Had the disruption been broader, the consequences could have extended far beyond limited menus.  Critical infrastructure security must follow a simple discipline: find material exposure before an adversary does, fix it, and prove the risk actually went down.”

If you are part of a supply chain, or even if you are not, you need to prepare yourself as the attackers are coming for you. And you it is a matter of when not if they arrive.