❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Massive supply-chain attack compromises 440 packages under four hours

4 August 2026 at 18:07

In less than four hours early Tuesday, an attacker compromised a GitHub maintainer account and unleashed a self-replicating piece of malware which injected malicious code into more than 440 distinct npm packages, according to multiple security firms.Β 

The worm, built on the open-source Mini Shai-Hulud repository that TeamPCP published in May, was initially let loose in keyv, a data management interface software package with more than 600 million monthly downloads. The attacker spent the next 30 minutes compromising additional packages controlled by the same maintainer, including cacheable, flat-cache, file-entry-cache.

The attack spread to other maintainers, eventually compromising more than 860 packages with a β€œcombined total of over 2 billion monthly installs,” Ilyas Makari, malware researcher at Aikido Security, wrote in a blog post.Β 

Wiz researchers told CyberScoop it hasn’t observed any new malicious packages since the initial wave moved through a massive footpoint of cloud and code environments in those first four hours.Β 

β€œThis is the most critical initial compromise, with over 155 million weekly downloads on the root packages,” Wiz Research said in an email.Β 

Some of the compromised packages, including keyv, flat-cache and file-entry-cache, are present in more than 46% of all cloud environments, according to Wiz. β€œBy comparison, back in the Shai-Hulud 2.0 campaign the most prevalent packages were only in about 28% of environments,” the company said.Β 

β€œTime will tell whether the eventual cost and impact outpaces past attacks, or whether adoption of hardening mechanisms such as package aging, and the usage of the relatively less aggressive Mini Shai-Hulud code as basis, will defray the final toll here,” Wiz Research added.Β 

Researchers from multiple firms sprung into action to monitor the widening attack spree and published indicators of compromise to help potential victims hunt for malicious activity in their systems.Β 

The Mini Shai-Hulud variant used in these attacks scoops up a trove of sensitive data, including npm, GitHub, AWS and continuous integration credentials. It also steals AI-related configuration files and cryptocurrency wallets, researchers said.Β 

Microsoft, Aikido, Socket and Wiz all said the same payload and pattern was observed across all affected packages, indicating a single attacker or threat cluster was behind the supply-chain attack and using multiple stolen tokens.Β 

The malware showcased a few pieces of new functionality, but retained the same core mechanisms that are hallmarks of Mini Shai-Hulud.Β 

β€œThe evolution is consistent with what we’ve seen from them in past waves, however we don’t yet have the hard links” to confidently attribute the attacks to TeamPCP, Wiz Research said.

The notorious threat actor, which Google previously told CyberScoop it attributes to one core operator that was located in South Africa during at least some of the attacks, compromised and injected malicious code into more than 1,000 software packages in less than four months earlier this year.

The post Massive supply-chain attack compromises 440 packages under four hours appeared first on CyberScoop.

Microsoft's $450 Billion Jump Is Biggest In Stock Market History

By: BeauHD
30 July 2026 at 17:00
Microsoft shares surged as much as 17% after reporting 43% growth in Azure revenue, putting the company on track to add a record $490 billion in market value in a single day. Bloomberg notes that it "would eclipse Nvidia's $440 billion addition, following President Donald Trump's announcement of a 90-day tariff pause last year, as the biggest ever." From the report: The nearly $500 billion jump is larger than the market capitalization of roughly 96% of S&P 500 stocks, data compiled by Bloomberg show. It's also bigger than the combined value of the benchmark's 44 smallest members, which includes companies like Domino's Pizza Inc., Clorox Co. and Hasbro Inc. Microsoft's one-day add in value also dwarfs many of the world's other equity markets. South Africa, Turkey, Finland and Vietnam all have total stock market values that are less than what the software maker is set to add on Thursday.

Read more of this story at Slashdot.

No bubble in the cloud, yet

30 July 2026 at 04:00
In the news: Microsoft reported blowout fiscal Q4 2026 earnings today, and the stock is jumping hard in after-hours trading. Here ae the headlines: Revenue: $90.0 billion, up 18% year-over-year, well above the roughly $87.6 billion analysts expected Net income: $35.8 billion (GAAP), up 31%; diluted EPS of $4.81 GAAP / $4.74 adjusted, versus a […]

AI-assisted security tools are finding more bugs, but the threat level has not changed

28 July 2026 at 11:08

AI systems like Anthropic’s Project Glasswing and Microsoft’s MDASH are aiding in the discovery of vulnerabilities, filling the ever-growing pool of defects that defenders have to address before exploitation occurs. Yet, through the first half of 2026, these vulnerabilities were no more or less likely to be exploited than all vulnerabilities disclosed during that period, VulnCheck said in a report Tuesday.Β 

Concerns remain high about AI-discovered vulnerabilities fueling more attacks, but VulnCheck’s review of exploitation data shows that those fears are unfounded, at least so far.Β 

Patrick Garrity, security researcher at VulnCheck and report author, identified 1,061 vulnerabilities attributed to AI-assisted discovery during the first six months of the year. Of those vulnerabilities discovered by AI, 14 ( 1.3%) were exploited in the wild, a breakdown that aligns with the exploitation rate researchers observed across all vulnerabilities during the same period.Β 

β€œWhile AI-assisted vulnerability discovery clearly has value for both attackers and defenders, the data does not suggest that AI discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods,” Garrity wrote.

While AI’s contribution to actively exploited vulnerabilities was muted in the first half of the year, it’s too soon to assume that trend will continue. Moreover, none of these major vulnerability-hunting models were running for that full period. Project Glasswing rolled out in April, while Microsoft’s MDASH and OpenAI’s Daybreak were both unveiled in May.

The upward trend in Microsoft’s monthly Patch Tuesday indicates how much the floodgates might open through the remainder of the year as AI models discover more vulnerabilities. The company’s July security update contained an all-time-record of 622 vulnerabilities, besting the previous record-breaking June update with 206 vulnerabilities.

VulnCheck’s state of exploitation report also found that vulnerabilities were exploited much faster after CVE publication, speeding up from an average of 120 days in 2025 to 80 days during the first half of the year.

The intelligence firm also determined which technology categories were actively exploited most often. Content management systems accounted for nearly one-third of the 495 known exploited vulnerabilities VulnCheck identified during the first half of 2026. Network edge devices were responsible for almost 14%, followed by operating systems at nearly 9%, server software at 8%, and AI products β€” an emerging attack surface β€” at almost 6%.

The post AI-assisted security tools are finding more bugs, but the threat level has not changed appeared first on CyberScoop.

Microsoft debuts AI cybersecurity offerings as competition heats up

By: Greg Otto
27 July 2026 at 18:45

Microsoft threw its hat into the ring Monday in the increasingly heated competition among AI-powered cybersecurity offerings, unveiling tools that it claims are better and cheaper than its rivals.

The new agentic model MAI-Cyber-1-Flash, runs inside another Microsoft security tool, MDASH, and is part of an AI-powered security platform the company dubbed Project Perception.

Microsoft argues that its existing in-house capabilities give Project Perception an edge.

β€œProject Perception brings together signals, context, models and specialized agents into a continuously learning system of defense,” the company said in a blog post. β€œIt can reason, prioritize and act at machine speed while keeping humans firmly in control and empowering them with powerful new workflows.”

Its release follows splashy AI cybersecurity suite debuts from OpenAI and Anthropic. Companies have been racing to advertise their AI offerings for their ability to find vulnerabilities, even as the most dire warnings about AI being used on the offensive side have yet to come to fruition.

As proof of its superiority, Microsoft said that MDASH with MAI-Cyber-1-Flash beat Mythos, Gemini and GPT on CyberGym, β€œthe gold standard benchmark for evaluating how systems reason over large codebases to find real vulnerabilities in the code.” It scored 96%, 12 percentage points ahead of the next-best.

Microsoft said MAI-Cyber-1-Flash was built with a focus on safety first, and was independently assessed by a third party it didn’t name. AI cybersecurity systems made big news in the past week after OpenAI said its models broke free of its testing confinement to hack Hugging Face, a major AI code platform.Β 

Price also was a big part of Microsoft’s rollout: It said MAI-Cyber-1-Flash in MDASH can do the job at half the cost of other leading models.

β€œThis is the benefit of building the harness, context/signals, and action space separate from one model family,” Microsoft Chairman and CEO Satya Nadella said on social media after the company unveiled Project Perception in San Francisco Monday. β€œBy combining specialized models and data with the right agents, tools, security context, and harness, we can advance the frontier of cost to outcome.”

Project Perception enters public preview on Aug. 3, Microsoft said.

The post Microsoft debuts AI cybersecurity offerings as competition heats up appeared first on CyberScoop.

Google’s solution to hacker name confusion? Yet another naming system

By: Greg Otto
27 July 2026 at 13:17

If you are a CISO, here is a new problem for the pile: Do I worry more about Sandworm Relic or Strawberry Tempest?

Last week, Google Threat Intelligence Group joined a list of rivals in changing how it names hackers, replacing years of split naming systems with a single set of code names built around memorable word pairs.

The company said in a blog post that the change merges two systems that had grown apart for years inside Google: Mandiant, the security firm Google bought in 2022, and its in-house Threat Analysis Group. Combining those units left Google with overlapping names for the same hacking groups, a problem the new system aims to fix.

β€œThreat tracking shouldn’t be an exercise in memorization, but rather one of intuition,” the post reads.

Each tracked group will now get a two-word name. The first word is a distinct term meant to be easy to recall, often pulled from names already used in past reporting on a specific group. When no such name exists, researchers will generate one at random and have analysts check it before use. The second word sorts each group by category, such as country of origin or motive. In Google’s published examples, CASTLE pairs with groups tied to China, ION with Iran, NEPTUNE with North Korea, RELIC with Russia, and COMET with financially motivated threat actors not tied to a nation-state.

The approach echoes one CrowdStrike has long been known for. CrowdStrike pairs a specific term with an animal tied to a country or motive: PANDA for China, BEAR for Russia, SPIDER for cybercriminals, JACKAL for hacktivists. Google’s system swaps the animals for words like CASTLE and NEPTUNE but follows the same basic structure, down to the argument for why it works: A two-part name carries more information than a bare country label or number, and it can change as attribution is fine-tuned.

Microsoft took its own turn at a naming overhaul in April 2023, dropping a system built on chemical elements, trees and volcanoes in favor of weather terms. Under that system, Typhoon marked China, Blizzard marked Russia, Sandstorm marked Iran, and Tempest marked financially motivated cybercriminals. The switch produced names that drew as much attention for their sound as their substance, among them Strawberry Tempest, Pumpkin Sandstorm and Pistachio Tempest. Industry experts bristled over the change, saying the names compared the groups to ice cream flavors or cocktails.

By 2025, the industry’s naming sprawl had become enough of a shared headache that two of the biggest players in it agreed to try to sort it out together. Microsoft and CrowdStrike announced a joint mapping effort in June of that year, pairing Microsoft’s weather names with CrowdStrike’s animal names for the same tracked groups, with Google, Mandiant and Palo Alto Networks Unit 42 also signed on to contribute. Both companies were careful to say the project was not an attempt to force the industry onto one naming system, just to make the existing ones easier to translate between.

Googleβ€˜s rollout starts with several dozen of the most actively tracked hacking groups, with more to follow over time. Older names will stay searchable within Google’s threat intelligence platform, alongside mappings to the MITRE ATT&CK framework and to the naming systems used by other vendors.Β 

The company says groups will keep carrying β€œUNC,” for uncategorized, if it is still too early to identify exactly where a group fits in this taxonomy.

The post Google’s solution to hacker name confusion? Yet another naming system appeared first on CyberScoop.

Microsoft, tech companies throw weight behind spread of open-source AI

By: djohnson
24 July 2026 at 11:22

Microsoft, along with more than two dozen tech companies, are pressing policymakers to support open-source AI systems and code across society, arguing that it will be a safer approach than attempting to restrict access or relying on a handful of closed, proprietary models.

The open letter, posted Friday, draws parallels to the software industry of the 1980s, when large businesses worried that open-source software code would cut into their business. While industry lost that battle, the end result was a vibrant ecosystem that now underpins much of the modern internet, government IT and even commercial software products.

It also created a β€œshared foundation of knowledge” that has fed countless future software projects and innovations.

β€œThe United States now faces a similar choice with artificial intelligence,” the companies wrote. β€œOur AI leadership will be judged not by one frontier AI model, but by whether the United States builds a strong, open ecosystem that diffuses into every sector.”

Expanding access and support to open-source AI comes with meaningful security risk. Cybersecurity experts warn that one of the biggest beneficiaries of broadly available AI tools areΒ  low-level criminals who until now lacked the technical expertise or resources to launch serious attacks.

Once a model is open weight, anyone can download it, customize it, strip it of any guardrails and use it for their own purposes. As open-source models have gotten better at creating deepfakes and other AI generated imagery, the danger of locally-customized CSAM and sexualized deepfakes could also grow.

But the letter argues that open-weight AI models are most beneficial to startups, universities, research labs and other small, ambitious organizations that can innovate and iterate the technology and make it more broadly useful to society.

β€œOpen weights let every organization match the right model to the right job at the right cost, reserving frontier-scale capability for genuine frontier problems and running efficient specialized specialized models everywhere else,” The companies wrote. β€œThat discipline is what will make AI economically sustainable as its use scales into the billions of everyday tasks.”

Β For cybersecurity specifically, the letter argues that defenders armed with open-source AI will outpace attackers better than any closed model approach.

β€œIn a world where cybersecurity attackers use advanced AI, defenders need access to models with comparable capabilities so they can detect, simulate, and respond to emerging threats,” the companies wrote. β€œOpen models broaden defensive capability, increase transparency, and allow vulnerabilities to be discovered and remediated across many teams.”

Other notable companies signing the letter include Meta, Palantir, Perplexity, Mistral, NVIDIA, Mozilla, The Linux Foundation, Hugging Face, Dell Technologies and IBM.

US policymakers continue to grapple with balancing unrestrained support for the domestic AI industry and providing oversight and regulation of harms that result from their use.

The Trump administration has cycled through several frameworks since coming into office, first a laissez-faire approach within no restrictions, then an executive order creating a voluntary testing regime for industry, then the imposition of export controls on Anthropic’s Fable model and reportedly pressuring OpenAI to delay the release of their models out of cybersecurity concerns.

The letter comes as the Trump administration has reportedly considered an executive order that would restrict American access and availability to Chinese-made open-source models.

But the White House and US companies are trying to thread a needle in recognizing the overall benefits of an open source approach while being wary of doing anything that could potentially benefit their Chinese rivals.

Earlier this month the White House announced the creation of its Gold Eagle AI cybersecurity clearinghouse that would help coordinate government, private sector and civil society work finding and closing AI-discovered vulnerabilities. A big part of that effort, a senior White House official said, is supporting providers and maintainers of open-source AI tools.

The post Microsoft, tech companies throw weight behind spread of open-source AI appeared first on CyberScoop.

Microsoft Responds to LG Monitors Installing McAfee Ads On Windows

By: BeauHD
23 July 2026 at 18:00
LG is removing a McAfee pop-up ad from its LG Monitor App Installer after criticism that some LG monitors were silently installing the app through Windows Update and showing ads on every boot. Microsoft says LG agreed to disable the McAfee pop-up, but the broader issue remains: Windows allows certain peripheral companion apps to install automatically without notifying users. Ars Technica reports: Following Gamers Nexus' video, a Microsoft representative stated that the LG Monitor App Installer will no longer show pop-up ads for McAfee. In response to a social media post about the app, Pavan Davuluri, EVP of Windows and devices at Microsoft, said this week: "We've connected with the team at LG and as an immediate next step, they have agreed to disable the McAfee pop-up from their app. We appreciate LG working with us toward a shared goal of a better experience for our mutual customers. We will keep improving here with our ecosystem partners." As mentioned, some LG monitors appear to have been installing LG Monitor App Installer onto Windows computers for months. Publication Windows Latest noted that the app recently got an update, "and its changelog mentions McAfee as an additional app," which could be what prompted more people to see the ads... and then complain about them. However, the removal of McAfee doesn't address the problem of a peripheral installing ad-pushing software onto people's computers. Users have been finding LG Monitor App Installer and its ads on their systems without LG ever showing a prompt or asking for permission. LG has some of the most expensive computer monitors available. Paying, in some cases, over $1,000 for a monitor that ends up forcing ads onto Windows is disruptive and a privacy concern. Once the app is installed, "LG technically possesses permission to use 'all system resources,'" as well as to "collect geolocation, device data, online activity, contacts, user credentials, transactions, and more," [editor-in-chief of Gamers Nexus, Steve Burke] said.

Read more of this story at Slashdot.

LibreOffice Once Again Slams Microsoft For Using 'Lock-In' With Office Files

By: BeauHD
20 July 2026 at 11:00
An anonymous reader quotes a report from XDA Developers: One of the founding members of The Document Foundation and handler of LibreOffice's PR and media relations, Italo Vignoli, took to the LibreOffice blog to call out Microsoft's practices with its Office application. The last time we saw Vignoli take to the stage, we saw him accusing Euro-Office of being just as bad as Microsoft with its practices. Vignoli's new post focuses entirely on Microsoft's strategy. He says that "the dominant format for office documents" is owned by Microsoft Office, particularly the DOCX, XLSX, and PPTX formats. The problem with these formats, Vignoli states, is that they "belong to Microsoft, are controlled by Microsoft and serve Microsoft's interest." This makes it difficult for other formats to take hold. Vignoli explains his point by stating that open document formats don't hide anything. People developing their own apps can use the format to both read and write the document format with perfection. Meanwhile, proprietary formats such as Microsoft's "contain undocumented features, private extensions or behaviors" that developers can't fully adapt to. That means that a presentation that looks great in the source software comes out strange when rebuilt in a third-party app. This, Vignoli says, is a huge issue [...]. Vignoli claims this creates a huge issue with document preservation. If a Word document was saved in one version of Office, will it still be readable in 20 years? Microsoft has added legacy support to its software before, but the company can one day decide that it's not worth the effort anymore and cut it out. When that happens, you have old documents that are either jumbled or unable to be opened at all.

Read more of this story at Slashdot.

❌
❌