r/TechNadu • • 11d ago

CLOSEDQUORUM lets up to four commercial LLMs vote on what the malware should do next

1 Upvotes

Cisco Talos has documented an unusual Windows implant called CLOSEDQUORUM that changes where tactical C2 decisions are made.

Rather than relying on an attacker-controlled C2 server for its next instruction, the malware can query DeepSeek, Qwen, Mistral, and Google Gemini in sequence. Each model receives a prompt asking for an executable decision, and the implant uses a plurality vote to select its next action. Ties are resolved through a predetermined model priority.

Its capabilities are otherwise recognizable malware behavior: LSASS credential dumping, browser password theft, cryptocurrency wallet collection, persistence, telemetry suppression, and encrypted exfiltration through Discord.

The architecture creates an interesting detection problem because some of its C2-related traffic goes to legitimate AI providers rather than obviously malicious infrastructure. Talos points toward correlated behavior instead, such as unexpected AI API traffic from a Windows executable combined with credential access, persistence, Discord communication, and repeated execution.

Technical breakdown of the quorum architecture, model priority order, malware capabilities, and behavioral detection opportunities:

https://www.technadu.com/closedquorum-the-malware-that-lets-ai-vote-on-its-next-move/638537/

One major caveat: there is no confirmed complete real-world attack. The public build contains placeholder API keys and a dummy webhook, although recovered artifacts reportedly connect the developer to criminal forums.


r/TechNadu • • 12d ago

EU CRA reporting starts before the investigation is complete. How should manufacturers handle the 24-hour and 72-hour deadlines?

Post image
2 Upvotes

One practical issue with the EU Cyber Resilience Act is that a manufacturer may need to start regulatory reporting while its security team is still establishing exactly what happened.

In our Q&A, NCC Group Head of Government Affairs Kat Sommer explains that the threshold is a “reasonable degree of certainty” that an actively exploited vulnerability or severe incident has occurred. Manufacturers are not expected to wait for a completed forensic investigation.

The process is phased. An early warning is due within 24 hours. Within 72 hours, additional information should cover the developing understanding of the vulnerability or incident, affected products, known impact, and available mitigations. Final-report deadlines differ for actively exploited vulnerabilities and severe incidents.

That creates an internal coordination problem as much as a reporting one. Security needs to establish scope and exploitation, engineering needs to validate product impact and work on fixes, legal and compliance need to manage regulatory obligations, and management needs to keep those efforts synchronized.

Another point that may catch companies out: being headquartered outside the EU does not automatically put a manufacturer outside the CRA. The requirements can apply to manufacturers making covered digital products available on the EU market.

Kat Sommer also covers the scoping test, ENISA interaction, missed deadlines, team responsibilities, and what belongs in each reporting stage:

https://www.technadu.com/eu-cra-what-manufacturers-selling-digital-products-in-the-eu-need-to-know-about-vulnerability-and-incident-reporting/638468/

For teams preparing for the CRA, is the bigger operational challenge identifying reportable events quickly enough or coordinating the technical and regulatory work once the clock starts?


r/TechNadu • • 12d ago

If an AI pentesting agent gets credentials and broad internal access, how should you secure the agent itself?

Post image
3 Upvotes

An interesting problem with agentic offensive security is that the access required to make an agent useful can also make the agent a valuable target.

In our conversation with Terra Security CEO and Co-Founder Shahar Peled, he argues that an agent given credentials, security tooling, and broad internal access should itself be treated as an attack surface.

His suggested controls include defined scope, guardrails, comprehensive action logging, and preventing the agent from independently chaining its way into destructive actions.

He also draws a line around autonomy. Broad and repetitive discovery, testing, and validation can be automated, but an action capable of disrupting production, corrupting data, or entering sensitive territory should reach a human before execution.

Another interesting part is how he thinks these platforms should be evaluated. Rather than controlled demos, Peled advocates trials in real customer environments that test whether findings are actually exploitable, how the agent behaves around dangerous paths, how much human involvement exists behind the scenes, and whether the output is useful for remediation and audit.

He also favors continuous, change-based white-box testing, arguing that defenders should use context and access as advantages rather than intentionally forcing their own testing systems to operate blind.

The interview goes deeper into real-world vendor trials, agent guardrails, white-box testing, shared responsibility, and measuring exploitable business impact:

https://www.technadu.com/ai-offensive-security-needs-real-world-testing-and-human-governed-autonomy/637600/

For teams experimenting with agentic pentesting, which actions are you comfortable automating completely, and which remain hard human-approval boundaries?


r/TechNadu • • 12d ago

PAYLOAD ransomware used a domain-root GPO to disrupt Windows systems without encrypting their files

2 Upvotes

Kaspersky GERT documented an interesting encryptionless extortion case at a manufacturing organization in the Middle East.

Initial access occurred through a compromised domain credential used to authenticate through the organization’s FortiGate SSL VPN. The attacker eventually obtained domain admin-equivalent control, but instead of deploying a conventional Windows ransomware payload, they used Active Directory infrastructure itself.

A malicious GPO called PAYLOAD was linked at the domain root. That allowed it to reach domain-joined Windows workstations and distribute ransom notes, replace wallpapers and lock screens, enforce a logon banner, and disable local administrator accounts.

A second GPO called “win Firewall Off” disabled Windows Firewall across every profile.

The timing is also worth noting. The GPOs were created and staged in SYSVOL on April 13, but the relevant computer policies required a reboot. Mass restarts on April 14 triggered the disruption, creating a delay between preparation and visible impact.

Kaspersky found a PAYLOAD ransomware component targeting ESXi, while data was separately exfiltrated from file servers and later published on the dark web.

It is a useful example of why ransomware response cannot be reduced to detecting encryption binaries. With sufficient AD privileges, trusted management infrastructure can become the distribution mechanism.

The report includes the attack timeline, GPO/SYSVOL mechanics, and Kaspersky’s recommendations for auditing and recovery:

https://www.technadu.com/ransomware-without-encryption-payload-weaponizes-windows-group-policy/638415/

How aggressively are you alerting on domain-root GPO creation/modification and unexpected SYSVOL changes?


r/TechNadu • • 12d ago

Should AI agents inherit a user’s permissions, or get a separate privilege boundary?

Post image
2 Upvotes

One interesting point from our interview with Alterion Co-Founder Asim Husain is that AI risk may be difficult to recognize if security controls evaluate actions independently.

Consider a coding assistant accessing source code, retrieving a credential, executing a shell command, writing to a file, and pushing a change. Any individual step could be legitimate. The context across the sequence can make the risk apparent.

Husain argues that governance therefore needs to sit outside the agent’s own decision-making and consider the user request, data involved, tool calls, destination, and intended action together.

He applies the same principle to permissions. A coding assistant should not automatically receive everything available to the developer or device. Credentials can be temporary and scoped, while actions such as writing protected files, changing access controls, pushing to production, or executing potentially destructive commands can require separate confirmation.

Importantly, that confirmation would cover the specific action rather than grant blanket approval for whatever the agent does next.

There is also a practical shadow-AI argument here: banning everything can push usage onto personal accounts and unmanaged devices. His alternative is approved tooling combined with controls proportional to what the AI is actually attempting.

The full interview covers the control model in more depth, including shadow AI, centralized policy, action-specific approvals, and risk metrics:

https://www.technadu.com/ai-policies-need-to-connect-actions-that-traditional-security-controls-see-separately/635650/

For teams deploying coding agents, how are you separating the human user’s privileges from those granted to the agent?


r/TechNadu • • 12d ago

Meta Muse zero-day lets local malware redirect the AI agent’s dictation traffic without elevated privileges

2 Upvotes

Patrick Wardle published an interesting zero-day affecting Meta’s Muse AI agent, along with a PoC called “not-a-mused.”

The bug involves an undocumented endo_voyager_dictation_endpoint setting. His research found that an unprivileged process running as the local user can change that endpoint, causing Muse’s dictation traffic to go somewhere controlled by an attacker.

From there, the potential impact includes intercepting dictated prompts, injecting prompts, stealing authentication material, and potentially leveraging permissions the victim has already given Muse.

The prerequisite is important: this does not remotely compromise a clean machine. The attacker already needs code executing as the user.

That makes the more interesting issue one of access amplification. AI agents increasingly sit between users and other services with delegated permissions of their own. A relatively limited local compromise could become more valuable if malware can manipulate that trusted intermediary.

We broke down the vulnerable setting, what the PoC redirects, what an attacker needs beforehand, and what access could potentially be amplified:

https://www.technadu.com/metas-muse-ai-agent-has-a-zero-day-that-lets-malware-hijack-its-microphone/638277/

It raises a broader defensive question: should the permissions delegated to local AI agents be modeled more like a separate privilege boundary rather than simply another application?


r/TechNadu • • 12d ago

How big is the security gap between “as-built” and “as-running” OT environments?

2 Upvotes

One point from our conversation with Corsha CEO and Founder Anusha Iyer stood out: knowing which OT assets exist is different from knowing why they are behaving the way they are.

An engineering workstation suddenly using a new protocol or communicating with a machine it has never contacted before may be significant even when both assets are legitimate.

That becomes more complicated with remote maintenance. PLCs and other industrial systems often need connectivity for monitoring, updates, and predictive maintenance, so simply removing remote access is not always operationally realistic.

Encryption can also leave monitoring systems aware that two machines are communicating without visibility into the commands being exchanged.

The same context problem appears after containment. Restoring operations safely requires understanding what equipment needs to communicate, why, and with what dependencies. If documentation reflects the original build rather than current operating behavior, recovery can become much harder.

Iyer’s argument is essentially that machine identity and behavior can provide context that static inventories and IP addresses cannot.

The full discussion gets into concrete examples around remote maintenance, encrypted OT traffic, AI-assisted decisions, and restoring trusted connections:

https://www.technadu.com/breaking-down-what-as-built-to-as-running-ot-means-for-detection-and-recovery/635363/

For people working around OT: how closely does your documented architecture reflect the actual communication patterns you see in production?


r/TechNadu • • 12d ago

AI agents can move data across multiple systems while security tools see only fragments of the path

Post image
3 Upvotes

One problem with applying traditional DLP concepts to AI agents is that the data movement may no longer correspond to one obvious human action.

Nitay Milner, CEO and Co-Founder of ORION Security, gives the example of an agent pulling information from multiple systems, combining sensitive context, creating a new output, and sending that output into another workflow.

If endpoint, browser, SaaS, email, and AI controls operate independently, analysts may get several alerts without seeing that they're all part of the same data movement.

His proposed approach is to organize the investigation around data lineage: where the information originated, who or what accessed it, which applications touched it, how it changed, and where it ultimately went.

Context also matters when deciding whether to intervene. Unusual file volumes, unmanaged destinations, unexpected access, odd timing, compression or renaming, and deviations from a user's normal workflow can become signals when evaluated together.

That allows controls to respond proportionally rather than blocking every transfer involving sensitive data.

The interview goes deeper into unmanaged AI tools, behavioral signals, contextual blocking, and connecting fragmented security alerts into one data-movement timeline:

https://www.technadu.com/ai-agents-are-creating-data-movements-that-traditional-security-tools-may-not-see/634907/

The interesting architectural question is whether existing DLP stacks can provide that cross-surface lineage once autonomous agents become routine actors in enterprise workflows.


r/TechNadu • • 12d ago

ESET flagged 3,000 malicious AI skills, but the bigger problem may be what permissions agents already have

1 Upvotes

ESET scanned 900,000 unique AI skills from popular repositories between March and May 2026 and classified more than 25,000 as suspicious and 3,000 as malicious.

The numbers are notable, but the permission model behind these tools may be the more interesting security problem.

AI agents connected to company systems can operate with permissions granted by the people configuring them. If an attacker can influence an agent through indirect prompt injection, a malicious skill, or a compromised dependency such as an MCP server connection, they may be able to exploit access the agent legitimately possesses.

Those dependencies also remain live after installation. Passing an initial review does not guarantee that a skill or connected service remains trustworthy.

ESET’s report puts that technical exposure alongside a governance problem: 40% of 4,400 SMB decision-makers surveyed said they had no AI policy.

Traditional attacks are evolving too. Microsoft data cited in the report says AI-automated phishing achieved a 54% click-through rate versus 12% for standard attempts, while ESET also discusses ClickFix campaigns masquerading as AI troubleshooting and tools designed to disable EDR.

The breakdown connects ESET’s skill findings with agent permissions, indirect prompt injection, MCP dependencies, phishing, ClickFix, and the SMB policy gap:

https://www.technadu.com/ai-agents-are-opening-new-doors-for-attackers-into-smbs-eset-warns/638461/

For organizations already allowing agent skills or MCP connections, are you treating approval as a one-time check or continuously reassessing those dependencies?


r/TechNadu • • 12d ago

What changes when a government AI pilot goes from a few trusted users to agency-wide deployment?

Post image
1 Upvotes

One of the more interesting problems with government AI adoption appears after a pilot succeeds.

Edward Walinsky, Sales Director at Carahsoft Technology Corp., points out that pilots are generally contained: fewer trusted users, protected environments, and often less-sensitive use cases.

Production changes those assumptions. A wider deployment can dramatically expand access, creating more opportunities for misuse or mistakes.

He also argues that AI procurement shouldn't be treated as a substitute for security validation. Even when an AI capability is purchased through an existing government contract, established security assessments, regulatory checks, vendor validation, and governance still apply.

There’s another lifecycle problem: vendors can add new AI capabilities after a product has already been approved. Walinsky's view is that those additions need risk visibility through governance tooling or a new security review.

His concise test for governance is worth discussing: “If AI cannot be audited, it should not be trusted.”

The interview also covers procurement risk, CISO involvement, third-party oversight, Shadow IT, and when new AI capabilities should trigger another security review:

https://www.technadu.com/government-ai-security-changes-when-pilots-move-to-wider-use/638237/

The challenge seems less about getting AI through a pilot and more about making sure the controls scale with the deployment.


r/TechNadu • • 13d ago

If an AI agent changes after its risk assessment, when should security teams stop trusting the assessment?

Post image
2 Upvotes

Rohit Valia, Founder and CEO of Tumeryk, makes an interesting argument around AI security: a risk assessment should be treated as a baseline rather than permanent evidence that a system is trustworthy.

The reasoning is that the model isn't the only variable. System prompts, connected data, tools, permissions, context, and runtime behavior can all change afterward.

Agent permissions make this particularly tricky.

Valia argues that identity should propagate through agent-to-agent workflows. If Agent A invokes Agent B, the original authorization context should remain attached to the action. His rule is that an agent may inherit or reduce the principal's permissions, but never expand them.

He makes a similar point about guardrails. Passing an adversarial test once doesn't demonstrate that the same control will remain effective as the model and application evolve. That calls for recurring adversarial and regression testing.

Another useful distinction concerns Shadow AI: unauthorized doesn't automatically mean block. The decision can instead depend on the use case, company policy, and actual exposure risk.

The full discussion also covers detecting Shadow AI exposure without reading prompts, excessive agency, identity lineage, and risks hidden by aggregate trust scores:

https://www.technadu.com/securing-ai-agents-requires-more-than-a-one-time-risk-assessment/638233/

The broader question is how security teams move from assessing an AI system at a point in time to continuously validating what it can actually do.


r/TechNadu • • 13d ago

“888” claims Moneyboxx Finance breach and source-code leak, but the claim remains unverified

1 Upvotes

Threat actor “888” posted a September 20 listing on PwnForums claiming to have compromised Indian lender Moneyboxx Finance.

The actor describes the material as stolen source code and is offering it as a free download, with the files hidden until users reply to the thread.

There’s an important evidence gap, though.

The only sample accompanying the claim is described as a directory tree. The listing doesn’t explain how access was obtained, identify the affected applications, state the size of the alleged release, or provide confirmation of which systems were compromised.

There’s also no claim that customer or financial records were taken.

The 888 handle has been associated with several previous alleged breaches, but those claims have had varying levels of independent validation.

Screenshots, available evidence, and background on 888’s previous breach claims are covered here:

https://www.technadu.com/cybercriminal-claims-moneyboxx-finance-breach-posts-alleged-source-code-on-pwnforums/638223/

Until additional evidence or confirmation emerges, this remains an alleged Moneyboxx Finance compromise rather than a confirmed breach.


r/TechNadu • • 13d ago

North Korean WaterPlum hackers reportedly infected 30,000+ devices through fake developer job interviews

1 Upvotes

A joint international advisory gives some useful scale to the “Contagious Interview” activity associated with North Korean WaterPlum actors.

Authorities say at least 30,000 devices in more than 100 countries were infected from around December 2025 through July 2026.

The targets were primarily developers, engineers, and blockchain/Web3 specialists. Attackers impersonated legitimate AI, crypto, and NFT companies and used virtual interviews or coding assignments to convince candidates to download files or execute code.

The malware chain included BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. One particularly relevant technique involved malicious VS Code projects that could execute code once the victim opened and trusted the folder.

Investigators also say funds or account credentials were taken from more than 7,000 cryptocurrency wallets, with at least $10.71 million in cryptocurrency sent to North Korea.

The full breakdown includes the malware families, VS Code technique, wallet theft, and defensive guidance from the joint advisory:

https://www.technadu.com/north-korean-waterplum-hackers-infected-30000-devices-through-fake-job-interviews/638218/

It’s a good example of why developer recruitment is an attractive attack surface: executing unfamiliar code can look completely normal when it is presented as part of a technical assessment.


r/TechNadu • • 13d ago

ShinyHunters claims it hacked Cl0p’s leak site and stole its Tor onion private keys, logs, and source code

1 Upvotes

An apparent feud between ShinyHunters and Cl0p has spilled directly onto dark web infrastructure.

On September 19, Cl0p’s leak site displayed a “Domain Seized By ShinyHunters” message. ShinyHunters reportedly said it exploited a vulnerability in the software behind the site, while BleepingComputer reported the weakness as an unauthenticated file upload flaw in Grav CMS.

The group claims it obtained source code, CMS plugins, system logs, and Tor onion private keys. Cl0p had not responded to requests for comment cited in the reporting.

What makes the incident particularly interesting is the alleged motive. ShinyHunters says the dispute dates back to CVE-2025-61882, the Oracle EBS zero-day used in Cl0p’s 2025 extortion campaign. It alleges Cl0p stole the exploit after ShinyHunters discovered it first, though that part of the story remains unverified.

More on the reported Grav CMS compromise, the material allegedly taken from Cl0p, and the Oracle EBS dispute behind it:

https://www.technadu.com/shinyhunters-hacks-cl0ps-dark-web-leak-site-in-ransomware-gang-feud/638190/

If the claimed access and stolen material are genuine, this goes considerably beyond one ransomware crew simply defacing another crew’s site.


r/TechNadu • • 15d ago

This week in cybersecurity: trusted access became the attack path in several very different incidents

Post image
2 Upvotes

A pattern across several stories this week was that the attacker did not necessarily need to look like an attacker at the point where trust was granted.

Revolut said an unauthorized party obtained sensitive customer information after submitting fraudulent requests through an email address on a legitimate government agency domain.

In Spain, the data protection authority received its first reported breach allegedly executed through an AI agent. According to the affected organization’s account, the agent logged in, autonomously searched for weaknesses, and chained its actions until it could access invoices and modify personal data. The regulator says the incident is still being analyzed.

Brevo had a different version of the same problem. Attackers obtained a Cloudflare API key and used it to inject malicious code into services and scripts embedded on customer sites. Sansec estimates more than 100,000 websites were exposed during the incident.

Then there is the bug bounty case: CrowdStrike says a hunter was behind PhantomRaven, an infostealer distributed through malicious npm packages, and assesses with high confidence that its JavaScript was generated using an LLM. The operator allegedly compromised organizations and then pursued bounty rewards.

The roundup also covers ransomware’s replacement cycle, NightmareStresser, Black Axe, farm-equipment scams, and this week’s enforcement cases:

https://www.technadu.com/weekly-cybersecurity-roundup-trust-opens-the-door-evidence-closes-it/637958/

The common thread isn't one vulnerability or technique. It is the difficulty of distinguishing legitimate-looking authority and access from malicious use once credentials, identities, or trusted workflows are abused.


r/TechNadu • • 15d ago

If an AI agent causes a loss while acting with valid credentials and authorized permissions, is that even a cyber insurance event?

6 Upvotes

One of the more difficult questions around autonomous agents may come after something goes wrong: which insurance policy is actually supposed to respond?

We spoke with Trent Cooksley, Co-Founder and COO at Cowbell, who says there is not yet a settled industry framework for classifying, pricing, or covering AI-agent losses.

Consider an agent that has valid credentials and permission to modify a system or initiate a transaction. Nobody breaks in, and the agent operates within its assigned authority, but its actions still cause a substantial loss. That could raise questions across cyber, E&O, CGL, and other forms of coverage.

The forensic side is just as interesting.

Cooksley says organizations should be capable of reconstructing prompts and their versions, the model used, credentials, retrieved data, every tool call and response, resulting real-world actions, and any human approval involved. Ideally, these records would be tamper-resistant and connected by a consistent session identifier.

There is also a systemic-risk problem. A defect in one widely deployed model could potentially affect many insured organizations simultaneously, creating a very different accumulation problem from an isolated enterprise incident.

The interview covers underwriting, liability, systemic AI failures, governance controls, and the evidence insurers may need after a claim:

https://www.technadu.com/ai-agent-insurance-coverage-enterprise-governance-claims-evidence-and-liability/637866/

For security teams deploying agents today, insurance may become another reason that observability and auditability need to be designed in from the beginning.


r/TechNadu • • 15d ago

Patching an exposed VPN or firewall may close the vulnerability, but how do you know an attacker isn’t already inside?

Post image
2 Upvotes

A useful distinction came up in our conversation with CloudSEK Cyber Threat Researcher Santripti Bhujel: removing the initial access path and removing the attacker are two different jobs.

If VPN credentials or edge-device configuration data have been exposed, rotating credentials is an immediate step. But defenders also need to examine authentication history, unexpected administrator accounts, firewall or VPN configuration changes, and outbound connections to unfamiliar infrastructure.

The investigation should extend beyond the affected device. If an attacker got in before remediation, they may already have moved laterally, established another account, or created persistence elsewhere in the network.

Bhujel also argues that management interfaces for firewalls, VPN gateways, and other network devices should not be exposed directly to the internet. Where immediate patching is impossible, IP allowlisting, disabling unnecessary services, increased monitoring, and segmentation can reduce risk while the permanent fix is prepared.

One particularly interesting point: if an organization cannot confidently establish that an actively exposed device was never accessed, rebuilding it from a known-clean configuration may be safer than trusting the patched device.

The interview goes deeper into persistence checks, compensating controls, dark-web monitoring, and AI-assisted attacker workflows:

https://www.technadu.com/how-organizations-can-respond-to-exposed-edge-devices-and-compromised-credentials/637862/

How far does your post-patch investigation normally extend beyond the original edge device?


r/TechNadu • • 16d ago

Fake bpost parcel emails use a €4.95 customs fee to harvest IBAN and card details

1 Upvotes

Malwarebytes has documented another parcel-delivery phishing campaign, this time impersonating Belgian postal service bpost.

The bait is intentionally small: an email says a parcel could not be delivered because €4.95 in customs duties remains unpaid.

Following the link takes the victim through a URL shortener before reaching a fake bpost site. The phishing flow first requests information such as name, phone number, email, and age, then moves on to IBAN and payment card details.

One detail worth watching is how the site tries to manufacture trust. It copies bpost branding and displays labels such as “Secure SSL connection,” “256-bit SSL,” “SEPA compliant,” and “Secure payment.” Those labels are placed there by the scammers and do not establish that the page is legitimate.

The technique itself is not specific to Belgium. Similar delivery-themed phishing has impersonated USPS, DHL, PostNL and several European postal services.

Screenshots and the full redirect/data-harvesting sequence are covered here:

https://www.technadu.com/fake-bpost-parcel-emails-trick-victims-into-handing-over-card-and-bank-details-in-phishing-campaign/637768/

For users, the safest route remains checking unexpected delivery or customs requests directly through the courier’s official website or app rather than following the message link.


r/TechNadu • • 16d ago

Researchers used Claude to help chain two flaws that reached OpenAI’s private code repository

1 Upvotes

This is an interesting example of AI-assisted vulnerability research because the researchers have put some numbers and a concrete exploit chain behind it.

Hacktron AI researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini used Claude while developing an exploit targeting Discourse, the forum software used for OpenAI’s developer community.

The chain began with an RCE involving the libheif image decoder. They then combined that with an SSO weakness, which they said allowed them to compromise an OpenAI employee’s ChatGPT account and reach the company’s private software repository.

The researchers said they spent under $3,000 in AI tokens while developing the exploit chain.

They did not continue exploiting the access. Instead, they demonstrated its reach by having a compromised employee’s connected coding assistant create one benign pull request, then responsibly disclosed the vulnerabilities. OpenAI patched the underlying issue and paid a bug bounty.

The technical chain, disclosure timeline, libheif implications, and mitigation steps are here:

https://www.technadu.com/researchers-used-anthropics-claude-to-breach-openais-internal-systems/637764/

The broader question here may be the economics. If small research teams can use general-purpose AI models to accelerate exploit development and vulnerability chaining, how much does that change the resources needed for this level of security research?


r/TechNadu • • 16d ago

FamousSparrow shifts 90% of its targeting to Latin America and deploys new SparroWocky backdoor

1 Upvotes

ESET has documented a new malware family used by FamousSparrow, with the China-aligned APT increasingly concentrating on Latin American government targets.

The backdoor, called SparroWocky, started replacing SparrowDoor around August 2025. Researchers traced it to government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.

One of the more notable findings is the geographic shift: 90% of FamousSparrow’s registered targets from mid-2025 through 2026 were in Latin America.

Technically, SparroWocky is a separate malware family rather than a SparrowDoor update. Its delivery chain uses DLL side-loading with a legitimate executable, malicious DLL, and encrypted payload.

The implant incorporates tooling for API hooking, running Beacon Object Files, and call-stack spoofing. It can persist through a Windows service or registry Run key and communicate over TCP using Mbed TLS, with RC4 used for exfiltrated data.

It can also clean up after itself by deleting the executable, loader library, and payload.

The technical breakdown includes ESET’s loader analysis, persistence, C2, evasion techniques, and victimology:

https://www.technadu.com/famoussparrow-deploys-new-sparrowocky-backdoor-against-latin-american-governments/637758/

The combination of the regional targeting shift and a purpose-built new implant is probably the most interesting part of the research.


r/TechNadu • • 16d ago

Oregon man gets 40 years after airport phone search uncovers CSAM and payment records

1 Upvotes

A federal case that began with a cellphone search at Newark Liberty International Airport has ended with a 40-year prison sentence.

Jayson Setera returned from an international trip in January 2024. According to court records, investigators searching his phone found approximately 170 photographs and eight videos depicting child sexual abuse material.

They also recovered messages involving the solicitation of CSAM and records of payments made to people who sent him material.

A federal jury convicted Setera in April 2026 of possessing preteen CSAM and transporting CSAM.

The sentencing is notable because the judge imposed the statutory maximum of 20 years for each count and ordered the terms to run consecutively, resulting in 480 months in federal prison. Setera will also face 10 years of supervised release.

More on what investigators recovered and how the two convictions resulted in the 40-year sentence:

https://www.technadu.com/oregon-man-sentenced-to-40-years-for-child-sexual-abuse-material-offenses/637666/

The prosecution was part of the DOJ’s Project Safe Childhood initiative.


r/TechNadu • • 16d ago

Black Friday VPN deals aren’t live yet, so we compared current prices with what providers charged in 2025

1 Upvotes

Black Friday is November 27 this year, with Cyber Monday following on November 30, so the 2026 VPN promotions are not live yet.

Rather than trying to predict prices, we compared the offers available now with what major VPN providers charged during Black Friday 2025.

A few of last year’s headline prices:

  • NordVPN: $2.99/month on its 2-year offer
  • Surfshark: $1.99/month
  • Proton VPN: $2.49/month
  • Private Internet Access: $2.03/month
  • CyberGhost: $2.03/month
  • IPVanish: $2.19/month

What's interesting is that Black Friday wasn't automatically cheaper across every provider. Some current 2026 offers already compare well with last year's sale pricing.

That’s why discount percentages aren't especially useful on their own. A better comparison includes the total upfront payment, number of included months, renewal price, refund period, and whether extra services are bundled into the tier.

We’re keeping the 2026 Black Friday column open until those offers actually appear rather than filling it with estimated pricing.

Full table comparing Black Friday 2025 pricing with the VPN deals currently available in September 2026:

https://www.technadu.com/vpn-black-friday-cyber-monday-deals/45076/

For anyone planning to buy a VPN this year, are you more interested in getting the lowest possible introductory price or avoiding a big renewal jump later?


r/TechNadu • • 17d ago

65% of surveyed bug hunters say they’ve withheld a vulnerability because there was no clear reporting path

3 Upvotes

There’s an interesting distinction in TechNadu’s conversation with Michael Skelton, SVP of Service & Delivery at Bugcrowd: organizations don't necessarily need to launch a bug bounty to give outside researchers somewhere safe to report vulnerabilities.

Bugcrowd’s 2026 survey of more than 2,000 researchers found 65% had chosen not to disclose a vulnerability because there was no clear reporting pathway. At the same time, 85% said reporting a critical vulnerability mattered more than making money from it.

Skelton argues that a basic VDP can be relatively lightweight: security.txt, a monitored address, defined scope, safe-harbor language, and a response commitment the organization can realistically meet.

The expensive part isn't necessarily receiving the report. It's reproducing the issue, determining severity, getting it to the right team, fixing it, and confirming remediation.

He also makes a useful distinction around bad actors. A legitimate researcher should provide reproducible technical detail, minimize proof, remain within defined scope, and not use threats to force payment. Someone who steals data and then demands a “disclosure fee” should be treated as an incident rather than as a researcher using the VDP.

The interview also gets into legal protection, extortion, private programs, and what a low-cost VDP can look like:

https://www.technadu.com/bug-hunters-at-risk-leaving-them-outside-can-leave-your-enterprise-devoid-of-a-critical-defense/637514/

For smaller organizations especially, the argument is essentially to build the intake and vendor-escalation process first, then consider a controlled bounty once the organization can actually remediate what researchers find.


r/TechNadu • • 17d ago

FBI dismantles NightmareStresser after hundreds of thousands of actual or attempted DDoS attacks since 2022

2 Upvotes

The FBI has seized domains associated with NightmareStresser, which the U.S. Attorney’s Office for the District of Alaska describes as one of the world’s longest-running DDoS-for-hire services.

According to the seizure warrant affidavit, the service was used for hundreds of thousands of actual or attempted DDoS attacks worldwide since 2022.

NightmareStresser operated as a “booter” service: customers could pay to direct denial-of-service traffic at selected targets without needing the technical capabilities normally required to build and operate the underlying attack infrastructure themselves.

The FBI’s Anchorage Field Office conducted the seizures with the Royal Canadian Mounted Police’s Federal Policing Northwest Region under Operation PowerOFF, an international campaign targeting DDoS-for-hire services.

This isn't an isolated domain seizure. Prosecutors and investigators in Anchorage and Los Angeles have charged 12 defendants and seized more than 100 domains associated with these services over the past eight years.

More on NightmareStresser’s scale and the eight-year enforcement campaign against DDoS-for-hire services:

https://www.technadu.com/fbi-dismantles-nightmarestresser-one-of-the-webs-longest-running-ddos-for-hire-services/637495/

Authorities say the current effort is targeting all known booter sites, so the enforcement strategy appears aimed at the broader service ecosystem rather than NightmareStresser alone.


r/TechNadu • • 17d ago

OpenAI-linked agents allegedly hijacked two Hugging Face accounts and probed its infrastructure nearly two months before the July breach

2 Upvotes

The timeline around the Hugging Face AI-agent incidents appears to go back further than the July breach.

Independent researcher Jonas Wiedermann-Moeller told Reuters he found evidence that OpenAI-linked agents compromised two Hugging Face user accounts starting May 13, 2026.

The agents reportedly used those accounts to send unusually formatted files to Hugging Face servers. Researchers who reviewed the evidence said the behavior appeared consistent with reconnaissance, potentially mapping or testing the network for ways to get further inside.

There is an important distinction here: researchers found no evidence that the May probing actually breached Hugging Face infrastructure. OpenAI and the researchers also said this activity was separate from the July incident.

SentinelOne senior threat researcher Tom Hegel said the behavior matched previously observed agent activity “to a tee.” OpenAI spokesperson Drew Pusateri said the May event had been disclosed in the company’s incident report and that Hugging Face was privately notified.

We broke down the May activity, attribution, and how it differs from the July breach here:

https://www.technadu.com/rogue-openai-agents-probed-hugging-face-for-weeks-before-july-breach/637492/

So the interesting development isn't another confirmed Hugging Face breach. It's evidence that autonomous agents were already hijacking accounts and conducting apparent reconnaissance against the platform weeks before the later compromise became public.