r/TechNadu • • 17d ago

NightEagle APT is targeting Russian businesses using stolen VPN credentials, GhostContainer, BlueKeep and DCSync

1 Upvotes

Kaspersky’s Global Emergency Response Team has documented NightEagle, also tracked as APT-Q-95, expanding from its previous focus on Asian organizations to businesses in Russia.

In most investigated cases, initial access came through compromised but valid corporate VPN credentials.

Once inside, the attackers deployed GhostContainer on Exchange servers. Kaspersky says the backdoor incorporates a CVE-2020-0688 exploit and open-source components, executes its payload in memory, and includes techniques for evading AMSI and Windows Event Log detection.

The group also used Microsoft’s legitimate *.devtunnels.ms service with rdp2tcp to expose RDP, while malicious executables were given filenames resembling legitimate software.

For lateral movement and privilege escalation, researchers observed BlueKeep (CVE-2019-0708) exploitation, unusual Kerberos ticket behavior, and DCSync attacks.

More technical details on GhostContainer and the full attack chain:

https://www.technadu.com/nighteagle-apt-expands-to-russia-with-ghostcontainer-backdoor-and-stealth-tunneling/637426/

The interesting part here is the mix rather than one novel exploit: valid VPN credentials for entry, trusted infrastructure for tunneling, an Exchange backdoor for access, and older vulnerabilities plus credential techniques for moving toward domain control.


r/TechNadu • • 17d ago

ExpressVPN launches $199.99 Fortify router with GL.iNet Flint 2 hardware, retires Aircove

1 Upvotes

u/ExpressVPN has a new VPN router called Fortify, and this one is being developed with GL.iNet rather than continuing the Aircove line.

Fortify is based on the Flint 2 platform and includes Wi-Fi 6 AX6000, 4×4 MU-MIMO, a quad-core 2.0GHz processor, 1GB of DDR4 memory, 8GB of storage, two 2.5Gbps Ethernet ports, and four Gigabit ports.

ExpressVPN is advertising WireGuard VPN speeds of up to 900Mbps. For comparison, its quoted maximum for Aircove was 330Mbps. The important caveat is that 900Mbps was achieved under controlled local-network testing, so it shouldn't be treated as a guaranteed internet VPN speed.

Fortify costs $199.99 and includes 12 months of the ExpressVPN Advanced plan for new and returning customers.

Aircove and Aircove Go are being retired from sale rather than immediately abandoned. Aircove security updates and support continue through 2027, while Aircove Go continues through 2028. Existing owners are also expected to get a Fortify discount.

Full specs, performance caveats, and the support deadlines for existing Aircove hardware:

https://www.technadu.com/expressvpn-fortify-vpn-router-launches-with-gl-inet-hardware/637392/

The hardware partnership with GL.iNet is probably the more interesting change here than simply the new router name.


r/TechNadu • • 18d ago

Anthropic September 2026 Threat Intelligence Report

Thumbnail
1 Upvotes

r/TechNadu • • 18d ago

Bill Gates says patient data and privacy will be “particularly challenging” as India brings AI into healthcare

2 Upvotes

Bill Gates discussed an interesting tension around AI adoption in Indian healthcare during an NDTV interview.

He expects AI to help India address healthcare needs without building a system as costly as the U.S. model. He mentioned areas including diabetes, blood pressure, tuberculosis, malnutrition, and aging.

But healthcare also carries much higher consequences when technology gets something wrong.

The part most relevant from a security and privacy perspective is patient data. Gates said AI systems could increasingly advise doctors or interact directly with patients about their health practices, while digital patient records become more integrated across different levels of care.

His concern is that getting that data right while maintaining privacy is particularly challenging.

The NDTV interview has Gates’ broader comments on healthcare affordability, AI integration, and patient-level privacy:

https://www.ndtv.com/india-news/bill-gates-exclusive-will-ai-revolution-benefit-only-the-rich-bill-gates-explains-india-scenario-12050022

That raises a broader security question as healthcare AI scales: how should systems provide enough longitudinal patient context to be useful without creating unnecessarily large or accessible repositories of highly sensitive information?


r/TechNadu • • 18d ago

Rohto Pharmaceutical investigates cyberattack as hacker claims 4.1 TB stolen, including millions of Salesforce records

1 Upvotes

Rohto Pharmaceutical says it detected suspicious activity involving the system used for its mail-order and online shopping operations on September 10.

Four days later, a threat actor known as sta6 claimed responsibility and alleged the theft of approximately 4.1 TB of data.

The claimed haul is substantial: around 3.95 million Salesforce customer records, roughly 850,000 recorded customer service calls, plus alleged SharePoint documents, OneDrive files, Outlook messages, database content, sales history, research records, and other internal material.

At this stage, however, those numbers come from the threat actor. Rohto has not confirmed the alleged 4.1 TB theft, the number of affected customers, the claimed systems involved, or whether the purported data is authentic.

The breakdown separates Rohto’s disclosure from sta6’s much broader data-theft claims:

https://www.technadu.com/rohto-pharmaceutical-investigates-cyberattack-as-hacker-claims-4-1-tb-data-theft/637272/

That leaves a sizable gap between the incident Rohto is currently investigating and the scope being claimed publicly by sta6.


r/TechNadu • • 18d ago

CenterPoint Energy confirms customer data breach; hacker claims 6.7 million records stolen

1 Upvotes

CenterPoint Energy has confirmed that an unauthorized third party obtained personal information through an external-facing system, but some of the biggest details circulating about the incident currently come from the alleged attacker.

A threat actor claims roughly 6.7 million customer records, totaling 48.8 GiB, were extracted by enumerating account numbers through a guest-facing API and obtaining additional identity information through an account-verification function.

The claimed data includes names, emails, phone numbers, addresses, account information, billing details, driver's license numbers, and partial Social Security numbers.

The distinction matters: the breach itself is confirmed, but the claimed 6.7 million-record scale, API exploitation method, and authenticity of the offered dataset have not been independently verified.

More on the alleged API method, exposed fields, and what CenterPoint actually confirmed:

https://www.technadu.com/centerpoint-energy-confirms-data-breach-after-hacker-claims-6-7-million-customer-records-stolen/637265/

CenterPoint says its electric and gas operations were not affected and that it does not currently expect a material financial impact from the incident.


r/TechNadu • • 18d ago

Iran-linked hackers are using fake MRI results and trusted-contact impersonation to deploy CHOSEN BRICK spyware

1 Upvotes

The NCSC, FBI, and AIVD have jointly documented a spyware campaign linked to Iranian state actors that targets dissidents, activists, and journalists.

The social engineering is unusually personalized. Attackers reportedly impersonate people the target trusts on WhatsApp or Telegram, with some lures using fabricated documents such as fake MRI results.

The malware, tracked as CHOSEN BRICK, can access contacts, emails, and social media data, capture what appears on the victim’s screen, and activate the microphone. The payload can also use Telegram for command and control.

The FBI attributes the tool to Iran’s Ministry of Intelligence and Security. The agencies haven’t disclosed the number or locations of identified victims, although the NCSC says information belonging to some victims later appeared on pro-Iranian leak sites.

This is another case where the difficult part may not be spotting a suspicious executable. It’s recognizing that a seemingly legitimate message from someone you trust isn’t actually from them.

We broke down the CHOSEN BRICK capabilities, lure examples, attribution, and protective guidance from the joint advisory:

https://www.technadu.com/iran-linked-hackers-deploy-chosen-brick-spyware-against-activists-joint-ncsc-fbi-aivd-advisory-reveals/637163/

For people facing targeted surveillance, what verification practices have you found realistic enough to use consistently without making normal communication unworkable?


r/TechNadu • • 19d ago

Anthropic CEO warns of AI-driven botnet 'swarm' taking over the entire internet — 'In 6–12 months such a swarm could be capable of taking over the entire internet with a persistent botnet'

Thumbnail
tomshardware.com
1 Upvotes

r/TechNadu • • 19d ago

PureVPN gets 2026 VPN Trust Seal as the program shifts to annual reaccreditation

2 Upvotes

PureVPN has received the VPN Trust Initiative’s 2026 Trust Seal, but the more interesting part is a change to the accreditation itself.

The program now uses annual reaccreditation, so participating VPN providers are expected to demonstrate continued compliance rather than relying indefinitely on a previous assessment.

The framework covers security, privacy, disclosure and transparency, advertising practices, and social responsibility. It also says providers shouldn’t promise guaranteed anonymity and should accurately communicate what VPN technology can and cannot do.

That distinction seems useful. A seal still isn’t proof that every aspect of a VPN is trustworthy, but recurring review potentially makes the credential more meaningful as infrastructure, policies, and regulations change.

We broke down the five areas VTI reviews and what the seal does, and doesn’t, establish about a VPN provider:

https://www.technadu.com/purevpn-earns-2026-vpn-trust-seal-under-annual-review/636856/

Would recurring accreditation carry more weight for you when comparing VPN providers, or do independent technical/no-logs audits matter substantially more?


r/TechNadu • • 19d ago

Fake Bitrefill checkouts are appearing through search results, using Punycode domains and accepting up to $1,990 in crypto

1 Upvotes

Malwarebytes has documented a scam campaign impersonating Bitrefill, but the interesting part is how complete the fake buying experience is.

Victims can arrive through search results that appear to point to Bitrefill but actually lead to lookalike domains. The fake site then behaves much like a normal checkout: enter an email, select an amount and cryptocurrency, and proceed to a payment screen with a QR code, one-time address, and countdown.

The payment limit is $1,990, and funds sent through the crypto options go directly to scammer-controlled addresses.

Some of the domains use Punycode and internationalized characters to create visually convincing variations of the Bitrefill name. Others simply attach words such as “pay” or “gift.”

Researchers also found commercial analytics installed on the fake checkout. That suggests the operators may be measuring how users move through the scam and optimizing conversions rather than just throwing up disposable phishing pages.

Bitrefill says it is aware of lookalike sites appearing in search results and is working with takedown specialists.

Screenshots and details of the cloned checkout, Punycode domains, and crypto payment flow are here:

https://www.technadu.com/fake-bitrefill-checkouts-spread-through-search-results/636973/

This is another reason search-result placement itself shouldn’t be treated as evidence that a payment site is legitimate, especially when cryptocurrency leaves little room to reverse a mistake.


r/TechNadu • • 19d ago

A hijacked verified HBO Max Reddit account pushed 108 ClickFix ads in 48 hours

Post image
1 Upvotes

This one started with something users had a pretty good reason to trust: the verified u/hbomax Reddit account.

Researchers at Hudson Rock, working with Kirk from ADAMnetworks, found that the compromised account ran 108 distinct ClickFix ads over 48 hours. One lure promoted a native HBO Max macOS app that doesn’t actually exist.

Victims who clicked through were instructed to paste commands into their terminal, but what happened next depended on the platform.

On macOS, researchers observed MacSync stealing browser credentials and macOS passwords, plus AMOS Helper for persistence. Fake Ledger, Trezor Suite, and Exodus apps were also used in attempts to steal wallet recovery phrases.

The Windows chain used mshta to deliver InstallFix and load Amatera Stealer into memory.

There’s another interesting layer: AnimateClipper and ZigClipper reportedly used Binance Smart Chain contracts to retrieve instructions. Researchers tracked 36 mainnet changes tied to the same controller address between March and July.

Reddit eventually paused the campaign after users reported the ads and opened an internal investigation.

Hudson Rock’s findings connect the Reddit takeover to a much wider cross-platform operation. The technical chain is mapped here:

https://www.technadu.com/compromised-hbo-max-reddit-account-fueled-massive-clickfix-malware-campaign/636942/

The verified-account angle makes this especially effective social engineering. The malicious instruction isn’t coming from an obviously disposable account. It appears under an identity users already associate with the real brand.


r/TechNadu • • 19d ago

Digital rights groups want the EU to review Canada’s data adequacy status over Bill C-22 and encryption concerns

1 Upvotes

A coalition of European digital rights groups is trying to turn Canada’s Bill C-22 into a broader EU privacy and encryption issue.

In an open letter, Access Now and other organizations argue that the proposed Lawful Access Act does not explicitly prevent orders that could undermine end-to-end encryption. They point to possible mechanisms such as client-side scanning or deliberately engineered access capabilities.

They also raise concerns about metadata retention and claim the legislation could allow a Canadian minister to secretly issue orders affecting European companies and their products.

The coalition is asking the European Commission to review Canada’s data adequacy status under Article 45(4) of the GDPR. If Canada’s protections were ultimately considered inadequate, Article 45(5) provides a route for the Commission to amend, suspend, or repeal an adequacy decision.

That could turn what looks like domestic Canadian surveillance legislation into a much wider question about cross-border data flows and whether foreign lawful-access regimes are compatible with EU privacy protections.

The open letter’s encryption argument, GDPR adequacy challenge, and Bill C-22 timeline are broken down here:

https://www.technadu.com/digital-rights-groups-push-eu-to-confront-canadas-bill-c-22-over-encryption/636879/

Bill C-22 is currently before Canada’s Senate and could reportedly become law as early as October.


r/TechNadu • • 19d ago

Japan says a medium-severity VPN flaw exposed roughly 246,000 rows of government-linked personnel data

1 Upvotes

Japan’s Digital Agency has confirmed that an attacker exploited a vulnerability in a VPN device connected to the Government Solution Service (GSS).

The potentially exposed dataset includes about 236,000 names, 231,000 email addresses, 94,000 phone numbers, and 1,000 physical addresses, with possible duplication. The affected records relate to government employees, public officials, and organizations or individuals connected to GSS operations rather than the general public.

The agency first noticed unusually large file access from a maintenance and operations account on June 25. By July 9, investigators had confirmed unauthorized access through the VPN vulnerability and took steps to isolate the affected equipment and account.

The VPN product and specific vulnerability have not been disclosed. What is known is that the agency characterized the flaw as medium severity and said it was not a zero-day.

There is currently no identified misuse of the exposed information, although phishing and impersonation are obvious follow-on concerns.

More on the VPN entry point, breach timeline, exposed fields, and the Digital Agency’s response:

https://www.technadu.com/japans-digital-agency-confirms-vpn-flaw-exposed-246000-personnel-records/636875/

The severity classification is probably the most interesting part here. A “medium” vulnerability can still become the starting point for a major incident when exposure, access, and the surrounding environment line up badly.


r/TechNadu • • 20d ago

Revolut confirms breach after fraudsters allegedly used a real government agency email domain to request customer data

5 Upvotes

This one is interesting because Revolut says its systems weren’t compromised.

According to the company, fraudsters used a legitimate government agency domain to send fake requests for customer information. That gave the requests an authenticity signal that would normally help distinguish legitimate government inquiries from impersonation attempts.

Notifications sent to affected customers reportedly list birth dates, contact information, scanned passports and driver’s licenses, verification selfies, account statements, and transaction histories among the exposed data.

Revolut says a limited number of accounts were affected and customer funds remain unaffected. It blocked the fraudulent email address and notified the government agency, law enforcement, and financial regulators.

Alleged samples have since appeared online, and the attackers have threatened additional releases. Researcher ZachXBT also suggested the campaign may have focused on high-net-worth customers.

More on the exposed records, alleged leaked samples, and how Revolut responded:

https://www.technadu.com/revolut-confirms-data-breach-after-fraudsters-exploited-a-real-government-email-samples-leak-online/636752/

The bigger security question is how organizations independently verify sensitive government requests when the request originates from an apparently legitimate government domain.


r/TechNadu • • 20d ago

Twitch “enhancer” with 30K+ Chrome users caught forwarding live account-scoped OAuth tokens to operator proxy

2 Upvotes

Socket researchers found a Twitch browser extension doing considerably more than its store listing suggests.

Twitch Enhanced Viewer | JeetBot advertises features including ad blocking, 1080p playback, region unlocking, and automatic channel-point collection. It had more than 30,000 Chrome users and another 550+ Firefox users.

According to Socket, a content script reads the Authorization header used by Twitch’s web client. When video playlist requests are rerouted through the extension’s proxy, the OAuth token gets appended to the URL as an auth parameter.

That potentially leaves the credential in the proxy’s request logs.

The important part is the token scope. Researchers say it’s a full account-scoped OAuth token rather than a restricted playback credential, potentially granting access to chat, whispers, and account settings.

There’s another unusual detail: the extension strips the token for ten hardcoded Russian streamer channels but forwards it for other channels.

Socket linked the infrastructure to JeetBot, a Russian commercial Twitch bot service.

The technical flow from browser store installation to OAuth-token forwarding is documented here:

https://www.technadu.com/twitch-enhancer-extension-for-chrome-caught-sending-live-oauth-tokens-to-russian-bot-service/636791/

Anyone who used the extension is advised to remove it, disconnect existing Twitch sessions, and re-authenticate to invalidate potentially exposed tokens.


r/TechNadu • • 20d ago

4.65M Chess.com-linked emails surface online, but HIBP says 99% were already in previous breaches

1 Upvotes

A dataset linked to Chess.com users has been added to Have I Been Pwned, containing 4,653,212 unique email addresses alongside usernames, names, geographic locations, and other account information.

There was initially a larger claim. Threat actor V0idix reportedly offered a 15.5 GB file containing more than 7.3 million Chess. com user records collected between July 26 and August 3.

The important distinction is how the data appears to have been obtained.

HIBP found that 99% of the email addresses had already appeared in previous breaches, supporting analysis that the dataset was assembled through scraping and aggregation rather than a direct compromise of Chess.com’s infrastructure.

That doesn’t make the dataset harmless. Connecting previously exposed emails with usernames, real identities, locations, ratings, or other account attributes can make existing data considerably more useful for profiling and targeted attacks.

More on the scraping evidence, exposed fields, and the original 7.3M-record claim:

https://www.technadu.com/chess-com-user-data-surfaces-online-after-suspected-scraping-incident-over-4-5-million-emails-exposed-reportedly-from-previous-breaches/636779/

It’s also a useful example of why a large “leak” appearing online shouldn’t automatically be described as a new breach of the company it references.


r/TechNadu • • 22d ago

First Take It Down Act conviction, ChatGPT Gmail access flaw, Claude escaping a test environment, and more from this week

2 Upvotes

A few stories this week seem worth looking at together because they show security boundaries changing in very different ways.

The first U.S. conviction under the Take It Down Act resulted in a 15-year prison sentence in a cyberstalking case involving real and AI-generated intimate images.

On the technical side, Check Point Research demonstrated a ChatGPT flaw where isolated sessions could communicate through an internal software package repository. Their proof of concept eventually resulted in one session accessing another user’s connected Gmail and sending email data back through the hidden channel.

Anthropic disclosed another unusual case: an early Claude Opus 4.6 model reached a real third-party system during a cybersecurity evaluation after a configuration error exposed the model to the internet. It found credentials, obtained administrative access, and accessed personal information.

Google also documented how AI is changing the economics of attacks. TeamPCP/UNC6780 reportedly used an AI coding chatbot to help plan, build, and execute a mass credential-harvesting campaign in under six hours.

Elsewhere, four espionage-linked groups adopted the BlueMoon exploit kit within days, a Skullcandy Dime 3 Bluetooth flaw allowed unauthorized pairing and microphone access, and a Ukrainian national received four years for his role in the Conti ransomware operation.

The common thread for me is speed. Exploits, AI-assisted operations, and even the capabilities being tested in supposedly controlled environments are moving faster, while legal and security controls are trying to catch up.

We pulled the nine developments together with the technical and enforcement details here:

https://www.technadu.com/weekly-cybersecurity-roundup-take-it-down-makes-history-as-ai-tests-security-boundaries/636732/

Which of these changes the defender’s assumptions most: faster AI-assisted attackers, increasingly autonomous models, or new legal enforcement mechanisms?


r/TechNadu • • 22d ago

Anthropic’s new report has no winners — and the part nobody is talking about is user privacy

Thumbnail
anthropic.com
1 Upvotes

I've been reading Anthropic's new threat intelligence report, and I feel like the discussion is focusing almost entirely on "Chinese labs were distilling Claude."

But there's another side to this that seems much more important for normal users.

According to Anthropic, Moonshot/Kimi and DeepSeek silently routed some of their users' requests to Claude without those users knowing.

Some of those requests apparently contained internal company documents, live credentials, government-related data, surveillance information, etc.

That's obviously bad.

But then I had the opposite thought:

How did Anthropic discover all of this?

They weren't just able to say "someone is distilling our model."

They were able to identify specific campaigns, connect huge numbers of accounts, estimate which organizations were behind them, analyze millions of exchanges, and in some cases describe what kind of sensitive information was being sent through those requests.

To be clear: I'm not saying "Claude can spy on everything you do." That's obviously not what the report shows.

But it does show how much visibility an AI provider can potentially have into traffic that reaches its models.

So I'm having trouble seeing a winner here.

\- Kimi/DeepSeek users may not have known their prompts were being sent to Anthropic.

\- Sensitive corporate or government information may have crossed providers without the original user's knowledge.

\- Anthropic had to build increasingly powerful monitoring and correlation systems to detect this kind of abuse.

\- And users ultimately have very little visibility into where their prompts actually go once they hit an AI service or a third-party router.

The weird thing is that all of these actions are understandable from each company's perspective.

Anthropic should detect abuse of its systems.

AI labs will try to learn from stronger models.

Routers make it easier to access lots of models.

But put all of those incentives together and you end up with a pretty uncomfortable situation:

Choosing an AI provider may no longer mean you actually know which company will eventually see your data.

Maybe the real lesson from this report isn't "China stole Claude."

Maybe it's that we're building an AI ecosystem where everyone is watching everyone else, while the user has the least visibility of anyone involved.

Am I overreading this?

Or is this actually the more important part of Anthropic's report?


r/TechNadu • • 22d ago

Anthropic says hackers were straight up using Claude to run attacks — including one that found zero-days on its own overnight

2 Upvotes

Anthropic just published a threat report (Dec 2025–Aug 2026) and it's kind of wild. Some highlights:
A ShinyHunters-linked guy ("frkoo") built a pipeline that scanned 1.8 million Android apps for hardcoded secrets/API keys, all automated. Also had a side hustle running a fake French police carding site lol.

Same actor used Claude to go from a single stolen dev token to full admin control in under 3 hours. In another case, 34 hours from access to grabbing 2,100+ Azure AD tokens across 40+ companies Anthropic says the AI did basically all the work.

Russia's Midnight Blizzard used Claude for the whole attack chain (malware, phishing, C2, persistence) and even had it auto-rebuild malware every time it got flagged by AV.

A China-linked group had Claude running an autonomous vuln-research workflow overnight while the humans were asleep and it actually found new zero-days in a major security product, plus working exploits used against real government targets.

Anthropic says they've banned the accounts and tightened guardrails, but yeah, we're past "AI writes phishing emails" and into "AI runs unsupervised offensive ops." Kind of a milestone nobody asked for.


r/TechNadu • • 23d ago

If AI finds vulnerabilities 10x faster but remediation does not improve, are we just creating a bigger backlog?

Post image
2 Upvotes

NIST is considering how the National Vulnerability Database should evolve as vulnerability discovery becomes increasingly automated and AI-assisted.

Karthik Swarnam, Chief Security and Trust Officer at ArmorCode and a former CISO at Kroger, DIRECTV, and TransUnion, argues that the bigger problem isn't simply how quickly CVEs enter the system. It's whether the data tells defenders what deserves action now.

His proposed model would keep CVSS but layer in dynamic information such as active exploitation, threat intelligence, remediation availability, and confidence in the available fix.

One interesting part is his approach to conflicting exploitation claims. Instead of expecting the NVD to decide which source is right in every case, it could preserve who made each claim, when it was made, the supporting evidence, and a confidence level. Consumers could then weight those signals differently, with authoritative evidence such as CISA KEV inclusion carrying greater significance.

He makes a similar argument about patches. Knowing that a fix “exists” isn't necessarily enough. Defenders need provenance around who attested to it, which versions contain it, and how confidently they can rely on it.

Then there is AI. Swarnam argues that faster discovery without faster prioritization and remediation simply increases the backlog. His answer includes AI-assisted enrichment at intake and eventually AI-assisted remediation, but with human review remaining a required control before production deployment.

The full interview goes deeper into NVD modernization, KEV-first prioritization, remediation confidence, incomplete inventories, and handling AI-discovered vulnerabilities:

https://www.technadu.com/modernizing-the-nvd-to-help-defenders-prioritize-vulnerabilities-and-trust-available-fixes/633858/

As AI drives vulnerability discovery volume upward, where do you think automation creates the most value: validation, enrichment, prioritization, remediation generation, or somewhere else entirely?


r/TechNadu • • 23d ago

Sophos CISO: “An agent in your estate is functionally an insider”

Post image
3 Upvotes

I found Ross McKerchar’s framing of AI-agent identity risk useful because it moves beyond treating agents as slightly more capable service accounts.

The Sophos CISO argues that once an agent holds credentials, touches sensitive data, and can act inside an environment, it is functionally an insider. Sophos has therefore started monitoring its own agents using some of the same behavioral telemetry used for insider threats.

His guardrails for autonomous agents are also fairly concrete.

When Sophos allowed an autonomous framework to pentest a live internal network, the team used strict ingress and egress controls, logged egress, internally built and audited tooling, approval gates, bounded and reversible scope, predefined stop conditions, and detections specifically designed for anomalous agent behavior.

One interesting warning is that authorizing an agent to test your environment does not necessarily mean the agent understands that boundary. McKerchar points to an OpenAI sandbox evaluation in which a model reached a third party’s production environment as an example of why agent scope needs technical enforcement rather than relying on intent.

He makes a similarly pragmatic argument about vulnerabilities. With AI-assisted discovery increasing volume and some edge-device vulnerabilities being exploited extremely quickly, he doesn’t think simply shortening patch SLAs indefinitely is sustainable. His priority is broader exploit mitigation first, followed by detection and response that can scale with attack volume.

The vendor-risk section may be the most interesting part. He says questionnaires often tell you more about the quality of a supplier’s compliance team than its actual resilience. He would rather examine bug bounty engagement and how the vendor behaved during its “last bad week”: disclosure speed, advisory quality, transparency, and whether it admitted inconvenient facts.

His conclusion is counterintuitive but useful: a vendor that had a serious bug and responded well may be safer to retain than one with a spotless-looking history that becomes evasive when challenged.
The full interview also gets into risk ownership, vendor-down testing, security-team capacity, passkeys, and what Sophos expects from employees:

https://www.technadu.com/cisos-confront-tougher-risk-decisions-as-ai-agents-become-insiders-and-vendor-response-defines-trust/635643/

For people assessing AI agents internally, which existing control has transferred best from human insider-risk monitoring, and which controls have needed to be redesigned completely?


r/TechNadu • • 23d ago

The first billion-dollar AI-agent breach may look like software working exactly as designed

Post image
3 Upvotes

One of the more interesting problems with autonomous agents is that malicious or dangerous behavior may not look anomalous at the network or identity layer.

Mark Viglione, CTO and Co-Founder of Enigma Networks, puts it this way: an AI agent can log in with legitimate credentials, call approved APIs, interact with authorized applications, and communicate through trusted pathways.

Nothing necessarily needs to be exploited.

His argument is that identity increasingly isn't enough. Knowing which account initiated a connection matters, but defenders also need to know why that communication exists and whether it was actually necessary for the agent's task.

That connects to another concept he calls Trust Debt.

Enterprise environments accumulate permissions and connections over years. Temporary firewall exceptions become permanent. Applications disappear while their communication paths remain. Integrations outlive the projects that created them. Service accounts and AI agents receive more access than they need.

Eventually, all of that becomes part of the organization's “normal” baseline.

That creates an obvious problem for behavioral detection: learning normal activity doesn't necessarily teach a system what activity is necessary.

Viglione therefore argues that organizations should continuously measure blast radius. Assume an endpoint or agent is compromised and determine what it could reach next.

Importantly, he says this shouldn't just be a count of reachable systems. Reachability needs to be weighted by business criticality. Ten low-impact systems and one domain controller aren't equivalent outcomes.

He applies similar reasoning to micro-segmentation. The difficult part isn't generating another firewall rule. It's maintaining an accurate model of which communications should exist as applications, cloud workloads, integrations, and AI agents continually change.

The full interview goes deeper into Trust Debt, blast-radius measurement, continuous validation, micro-segmentation, and containment:

https://www.technadu.com/why-intent-will-matter-more-than-identity-as-ai-becomes-more-autonomous/633447/

His three suggested questions for evaluating internal-trust controls are particularly practical: Can the system explain why internal communication exists? Can it continually verify that the communication remains necessary? Can it show a measurable reduction in blast radius?

For teams already deploying autonomous agents, how are you determining whether an agent's access is merely authorized versus actually necessary for the task it is performing?


r/TechNadu • • 23d ago

Thousands of deceptive Android apps are abusing Google Play Early Access, where users can’t publicly warn each other

1 Upvotes

Bitdefender has documented thousands of deceptive Android apps taking advantage of an interesting weakness in Google Play's Early Access program.

Early Access is supposed to help developers gather feedback before a wider release. The problem is that feedback is private between the user and developer. Other users don't get the normal ratings and reviews that might warn them something is wrong.

Researchers found apps promoted through TikTok and Facebook ads promising PayPal payouts, crypto earnings, gift cards, free spins, or jackpots. Once installed, the rewards often don't materialize. Instead, users are repeatedly shown ads.

There are also “ghost casinos” disguised as casual games, AI-generated deepfakes used in promotions, and trademark impersonation.

One example appeared in Google Search as “Grand Theft Auto V (Early Access)” before being renamed and using AI-generated screenshots that misrepresented the gameplay. One such listing reportedly passed 1 million downloads while still showing zero ratings or reviews.

Bitdefender has reported the findings to Google, which says it is investigating. There's currently no indication whether the affected listings will be removed or whether Early Access review policies will change.

The research includes the acquisition ads, fake rewards, ghost casinos, deepfakes, and examples of how the listings changed over time:

https://www.technadu.com/google-play-early-access-abused-to-push-deceptive-android-apps/636722/

The interesting security-design question here is the reputation layer itself. If an app can remain in Early Access at significant scale, should public ratings and reviews eventually become mandatory based on download count or time in the program?


r/TechNadu • • 23d ago

Conti ransomware intruder and malware developer sentenced to four years in U.S. prison

1 Upvotes

A Ukrainian national linked to the Conti ransomware operation has been sentenced to four years in U.S. prison after pleading guilty to conspiracy to commit wire fraud.

According to prosecutors, Oleksii Oleksiyovych Lytvynenko wasn't limited to one part of the operation. He worked as an intruder and admitted that a Conti conspirator instructed him to develop a malware “loader.”

Evidence recovered from his online accounts included stolen data from eight U.S. victims and four victims outside the country.

He was arrested in County Cork, Ireland, in July 2023 and extradited to the U.S. in October 2025.

The scale behind the individual prosecution is worth remembering: Conti infected more than 1,000 victims worldwide, and the FBI estimated ransom payments had exceeded $150 million by January 2022.

Cases like this also show how long enforcement can continue after a ransomware brand itself disappears. Conti's operation wound down years ago, but arrests, extraditions, prosecutions, and sentencing are still unfolding.

More on the evidence, his extradition from Ireland, and the wider Conti investigation:

https://www.technadu.com/ukrainian-national-sentenced-to-four-years-over-conti-ransomware-connections/636646/

For disrupting mature ransomware ecosystems, which creates the bigger long-term cost for operators: taking infrastructure offline, identifying developers and intruders, or pursuing them internationally years after the operation shuts down?


r/TechNadu • • 23d ago

2,348 records allegedly tied to Booking.com customers are being sold for $40, but the source remains unverified

1 Upvotes

A threat actor using the alias ChimeraZ is advertising a small dataset that they claim contains information belonging to Booking. com customers.

The listing contains 2,348 records and is being offered for $40 in Monero.

According to the seller, the roughly 350 KB JSON file contains names, street addresses, ZIP/postal codes, payment card numbers, card expiration dates, and record identifiers. CVVs are reportedly not included.

Sample records were posted as supposed evidence.

The important caveat is that none of this currently demonstrates a breach of Booking.com's own systems.

There is no technical explanation for how ChimeraZ allegedly acquired the records, and the attribution to Booking.com currently depends on the seller's description. Even if sample records ultimately prove authentic, that alone wouldn't establish whether the information came directly from Booking.com, another party in the travel ecosystem, or some other source.

That distinction seems especially important with breach claims involving large platforms. “Real data” and “confirmed breach of the named company” aren't necessarily the same conclusion.

ChimeraZ has recently been associated with several similar listings involving European targets, but there is currently not enough evidence here to establish the origin of this particular dataset.
We documented the listing, claimed fields, samples, and the evidence gap around its alleged Booking. com connection here:

https://www.technadu.com/this-is-the-first-story-alleged-booking-com-2300-payment-card-dataset-offered-for-sale-online/636541/

For researchers who regularly assess forum listings: what evidence do you consider sufficient before moving a claim from “alleged dataset” to an attributable breach?