• A sophisticated Linux kernel rootkit designed to slip past the defenses of Elastic Security, a leading endpoint detection and response (EDR) platform.

    Released on GitHub by researcher 0xMatheuZ, the rootkit employs advanced obfuscation techniques to evade YARA-based detection and behavioral monitoring.

    While presented strictly for educational purposes, Singularity underscores the evolving challenges in kernel-level threat detection, potentially informing both attackers and defenders in the cybersecurity arms race.

    Elastic Security, integrated with Elastic Defend, typically triggers over two dozen alerts during rootkit scans, including file quarantines and process terminations.

    Singularity counters this by fragmenting its code, randomizing identifiers, and staging payloads in memory, achieving full evasion during testing.

    Core capabilities include hiding processes from /proc, concealing files and directories with patterns like “singularity” or “matheuz,” masking TCP connections on port 8081, and enabling privilege escalation via custom signals or environment variables.

    It also features an ICMP-based backdoor for reverse shells triggered by specific packet sequences, alongside anti-analysis measures that block tracing and sanitize logs.

    Linux Rootkit Evades Elastic EDR Detection

    At the heart of Singularity’s success lies a multi-layered approach to static analysis evasion. Traditional rootkits falter on predictable strings and symbols that YARA rules target, such as “kallsyms_lookup_name” paired with “license=GPL” or hooks like “hook_getdents.”

    Singularity tool

    The rootkit’s Python-based obfuscator fragments these at compile-time, splitting strings into adjacent literals that the C compiler reassembles—e.g., transforming MODULE_LICENSE(“GPL”) into MODULE_LICENSE(“G” “P” “L”).

    This ensures functionality while rendering the binary’s strings non-contiguous for scanners, as verified by tools like strings and objdump showing no direct matches.

    Symbol name randomization takes it further, replacing suspicious prefixes (“hook_,” “fake_”) with innocuous, kernel-mimicking names like “sys_abjker_handler” or “kern_wopqls_helper.”

    A whitelist protects essential kernel APIs, and regex patterns extract functions for consistent renaming, sorted by length to avoid partial substitutions, MatheuZ said.

    Ftrace hooking functions, another common giveaway, receive similar treatment, renaming “fh_install_hook” to evade rules detecting two or more such patterns. These techniques collectively dismantle the 57 function-name signatures in Elastic’s generic rootkit rules.

    Beyond static tricks, Singularity fragments its compiled .ko file into 64KB XOR-encoded chunks using a random 16-byte key, stored alongside metadata for reconstruction.

    A custom loader, compiled statically, reassembles these in memory via memfd_create, an anonymous file descriptor that avoids disk artifacts.

    It employs direct syscalls (both 64-bit and legacy 32-bit via int $0x80) to invoke finit_module, sidestepping hooked libc functions. This memory-only loading resists on-disk scanning, with fragments deletable post-execution.

    Behavioral detection proves trickier, especially for the ICMP-triggered reverse shell. Elastic flags patterns like setsid with /dev/tcp/ in command lines or shell executions from kernel workers.

    Singularity counters by writing a staged bash script to /singularity, hiding the spawning kworker PID immediately, then executing a clean /bin/bash /singularity.

    The script opens a TCP descriptor, spawns sh in the background, and uses kill -59 on precise PIDs for targeted hiding and escalation, bypassing command-line scrutiny without affecting legitimate processes.

    Evades security Detection
    Evades security Detection

    Bonus evasions include compiling loaders in /tmp instead of monitored /dev/shm and automating the obfuscation pipeline for reproducibility. In tests, Singularity loaded undetected, hid processes, and established root shells, proving its mettle against current Elastic rules.

    This work highlights the fragility of signature-based defenses against adaptive threats. As EDRs evolve, such research pushes for holistic detection blending machine learning and anomaly analysis. For defenders, it signals the need for deeper kernel integrity checks; for researchers, it’s a blueprint for resilience.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Researchers Created a Linux Rootkit that Evades Elastic Security EDR Detection appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The morning after President Donald Trump vowed to “start testing our Nuclear Weapons,” his pick to lead U.S. Strategic Command fielded questions from senators who wondered what the president meant and what the nominee planned to do about it.

    “If confirmed in the role of the STRATCOM commander, my role would be to provide military advice, and I would look forward to working with the committee and policy members to inform the way ahead with respect to any testing, whether that's testing of our missile systems, or maturity associated with surety” of nuclear weapons, said Vice Adm. Richard Correll, a submariner and STRATCOM’s deputy commander.

    That was the gist of Correll’s testimony during his confirmation hearing Thursday as lawmakers tried to parse exactly what Trump meant when he called for immediate nuclear weapons testing “on an equal basis” via social media late on Wednesday. No one was quite sure what the president meant, but it’s been 33 years since the United States exploded a nuclear weapon. 

    Trump defended his position to reporters Thursday aboard Air Force One returning from a trip to Asia. 

    “We have more nuclear weapons than anybody. We don't do testing. We've halted it years, many years ago. But with others doing testing, I think it's appropriate that we do also,” he said.

    Last year, a nuclear weapons scientist from Los Alamos National Laboratory told NPR that "our assessment is that there are no system questions that would be answered by a test, that would be worth the expense and the effort and the time.”

    The president didn’t provide details on when or where testing would take place but said, “We have test sites; it'll be announced.”

    Robert Peters, a senior research fellow for strategic deterrence at the Heritage Foundation, told NPR that there was just one place where the U.S. could test a nuke: the Nevada National Security Site, about 60 miles northwest of Las Vegas.

    Back on Capitol Hill, senators, mostly Democrats, looked to Correll for clear answers on how he would advise the president on explosive nuclear testing or how its resumption could influence adversaries like China and Russia. 

    Sen. Jack Reed, D-R.I., ranking member of the Senate Armed Services Committee, lambasted Trump’s “confusing” policy change during the hearing and in a statement, calling it a "fundamental misunderstanding of our nuclear enterprise—it is the Department of Energy, not the Department of Defense, that manages our nuclear weapons complex and any testing activities.”

    “The United States would gain very little from such testing, and we would sacrifice decades of hard-won progress in preventing nuclear proliferation," Reed said in a statement.

    During the hearing, Sen. Mazie Hirono, D-Hawaii, worried such live testing would “push” nuclear power nations to test more.

    “We have a Stockpile Stewardship Program to ensure the safety and reliability of our nuclear weapons without explosive testing, and the program relies on supercomputer simulations, non-explosive experiments and technology. We have a lot of technology that keeps us ahead of our adversaries in terms of ensuring that our nuclear stockpile is actually reliable,” she said.

    Sen. Jacky Rosen, D-Nev., stressed the lasting effects of explosive nuclear testing. 

    “The Nevada Test Site, now known as the Nevada National Security Site, NNSS, was ground zero for the majority of the United States, explosive nuclear testing from 1951 to 1992…and my state of Nevada is still suffering the consequences,” Rosen said. “I will not let this happen, not on my watch. I will do everything I can in my power as a senator, as a United States citizen, to put a stop to this and protect families in my State of Nevada.”

    Correll said he “wouldn't presume to predict a response on the part of Russia or China” and as the hearing went on, vowed to provide data-informed advice on nuclear weapons testing, while also requesting classified meetings to answer senators’ concerns. 

    “I have always been driven by data and, to the best of my ability, provide forthright and candid advice. And I commit that that will not change going forward,” he said.

    Correll also supports the Stockpile Stewardship Program, “which has developed the science and tools necessary to certify the nuclear weapons stockpile without the need for full-scale nuclear weapons testing,” according to written responses to policy questions, 

    Republican senators were more tempered in their questioning, supporting the president’s statement by emphasizing the need for all kinds of nuclear testing on a regular schedule.

    Sen. Tim Sheehy, R-Mont., said “testing on an ‘equal basis,’ is an extremely reasonable ask of our military, and I think it's the least we can do.” 

    “In general, tests of all kinds, whether nuclear or conventional, don't just provide those benefits, but also can send a strong message of resolve and deterrence,” said Sen. Tom Cotton, R-Ark., “We saw the exact opposite effect at times during the last administration, when President Biden canceled routine tests of our Minutemen III missiles to avoid supposedly escalating tensions with China or Russia.”

    When asked about maintaining a nuclear testing schedule as a means of deterrence, Correll agreed. 

    The STRATCOM commander role is “responsible for the requirements associated with accuracy and effectiveness of the weapons and that then drives the services and other subject matter experts, analysis of the testing required to meet those objectives,” he said. “It is a really, really important aspect of demonstrating the reliability and credibility of our nuclear deterrent, and that's an essential attribute for deterrence…particularly in this era.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-41244 to its Known Exploited Vulnerabilities catalog. This local privilege escalation flaw affects Broadcom’s VMware Aria Operations and VMware Tools, with evidence of active exploitation in the wild.

    Security researchers and officials urge immediate patching to prevent potential ransomware and other attacks that could compromise virtualized infrastructures.

    The vulnerability, rated as Important with a CVSSv3 base score of 7.8, stems from a privilege defined with an unsafe action issue. It allows a malicious local actor with non-administrative access to a virtual machine (VM) to escalate their privileges to root on the same VM.

    This is particularly risky in setups where VMware Tools are installed and managed by Aria Operations with Software-Defined Management Platform (SDMP) enabled.

    Broadcom confirmed that suspected exploitation has already occurred, heightening concerns for organizations relying on VMware for cloud and on-premises virtualization.

    VMware Tools and Aria Operations Vulnerability

    At its core, CVE-2025-41244 exploits improper privilege-handling flaws in VMware Tools and Aria Operations. A low-privileged user on a compromised VM can leverage this flaw to gain full administrative control, potentially pivoting to broader network access or data exfiltration.

    The attack requires local access, meaning initial footholds, such as through phishing or unpatched endpoints, could serve as entry points.

    Broadcom’s analysis ties the issue to CWE-267 (Privilege Defined With Unsafe Actions), emphasizing how seemingly benign configurations can become attack surfaces. No workarounds exist, making timely updates essential.

    Affected components include VMware Tools versions prior to 12.5.4 and specific Aria Operations releases. For Linux users, open-vm-tools updates will roll out via vendors, while Windows 32-bit systems are covered in Tools 12.4.9 as part of the 12.5.4 bundle.

    CVE IDAffected ProductsCVSSv3 ScoreImpactFixed VersionsExploitation Status
    CVE-2025-41244VMware Aria Operations, VMware Tools7.8 (Important)Local privilege escalation to root on VMTools 12.5.4; Aria Operations patches per matrix; open-vm-tools via vendorsSuspected in-the-wild exploitation; added to CISA KEV catalog

    Mitigations

    CISA advises applying vendor patches immediately and following Binding Operational Directive (BOD) 22-01 for federal cloud services. Organizations unable to patch should consider discontinuing use of vulnerable products.

    This incident underscores the persistent targeting of virtualization platforms, which power much of today’s hybrid IT landscapes.

    Broadcom credited Maxime Thiebaut of NVISO for discovering and reporting the flaw, highlighting the role of collaborative security research.

    As ransomware campaigns increasingly exploit such vulnerabilities, enterprises must prioritize vulnerability management. With exploitation confirmed, unpatched systems remain prime targets delaying action could lead to severe operational disruptions.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post CISA Warns of VMware Tools and Aria Operations 0-Day Vulnerability Exploited in Attacks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • An ambitious Air Force plan to acquire hundreds more advanced fighter jets for homeland defense over the next decade would require a blank check from Congress and expanding the tactical aircraft counted in their inventory, an official confirmed Thursday.

    The report submitted to Congress last week laid out plans for the service to have nearly 1,400 manned tactical aircraft by 2030, roughly 300 more than 1,160 jets in the total combat aircraft inventory today, an Air Force official told reporters. Overall, the service wants 1,558 to achieve its missions with high confidence and low risk. But that goal can only be reached if Congress funds the purchases.

    “What we're setting is really the bar for what is the possibility out there,” the official said. “Achieving those numbers assumes that we would have the fiscal resources to do that.”

    Defense One obtained a copy of the 24-page report, which laid out the service’s lofty goals and stated the service does not have “total obligation authority” to place the necessary orders. Additionally, it states, “Industry production limitations will also limit the USAF's ability to meet global force requirement.” Congress mandated the new strategy in the last National Defense Authorization Act. And while it did explain ongoing plans for its fighter jet structure and modernization efforts for aging aircraft, the plan’s success would require near-perfect conditions.

    “This is where we want to be in the future,” the official said. “Whether we're going to be able to get there, based on the realities of either industry or top line, will be a function of the process that we go through.”

    The Air Force also wants to change how Congress defines the number of fighter jets it’s required to keep in its inventory. The 2018 National Defense Authorization Act set a bottom limit of 1,145 fighter jets in the service’s primary mission aircraft inventory—or the number of aircraft needed to meet a unit’s mission requirement. In 2025, the service was allowed to temporarily reduce the number of aircraft required by 44, to allow for the planned retirement of some jets, but then was required to return to the original number.  

    In the service’s 2026 legislative proposal, the Air Force wants to change the “primary mission inventory” requirement to “combat-coded total aircraft inventory”: a broader term that would include primary mission, reserve, and back-up fighters.

    “In the context of assessing combat capacity, reporting ‘Combat Coded Total Aircraft Inventory’ (CCTAI)” provides a complete assessment of aircraft used to meet combat demands,” the report said.

    Defense experts who spoke to Defense One about the unclassified report said it excluded key budget details and didn’t provide enough of a build-up of tactical jets for future national security requirements. 

    “There's probably a lot of different opinions on whether it scratches the itch,” the Air Force official said. “For some, I think it absolutely will. I think there's probably some out there that it absolutely won't.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Apple Podcasts

    Guest:

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • HONOLULU—Speed. Persistence. Capabilities “designed and built to enable operations inside the weapons engagement zone.” The commander of U.S. Pacific Fleet wants it all. And he wants it now. 

    “Let’s continue to strengthen our rapid acquisition strategy. Put our best technology in the hands of our service members as soon as possible, and continue to outpace the competition,” Adm. Stephen Koehler told an audience of defense industry representatives and troops at the AFCEA TechNet Indo-Pacific conference. “Let’s take a holistic, innovative approach that brings transformative, strategic gains to our force. That includes considering things we’re not doing that we should be doing. That includes ‘embracing the red,’ which is Navy-speak for embracing the problems, adjusting quickly, and running to fix them.” 

    Koehler said his command has been working tirelessly on innovation, pairing experimentation with rehearsal in exercises designed to develop new capabilities while also building “new concepts of operation.” 

    “It might sound to you like we’re building the airplane while we fly it. That is no accident. It’s by design. We have to work fast to take advantage of today’s rapid pace of technological innovation. We have to get that capability into the hands of our sailors quickly, to enable them to innovate and force change, if needed,” Koehler said. 

    Pacific Fleet is already using AI for data analysis, but will continue to expand its use of artificial intelligence to “enhance command control, increase our lethality, and dominate in the [weapons engagement zone] across the entire continuum from competition to conflict, he said. 

    “I envision a future where the Pacific Fleet is empowered by artificial intelligence, where sailors and commanders at every level balance the art and science of warfare to make more effective decisions with superior outcomes faster than the adversary. A future where AI further accelerates the cycle of action between maneuver and fires for decisive combat advantage.” 

    Citing Indo-Pacific Command’s expeditionary foundry—The Forge—Koehler said the military and industry must “combine our unique strengths” to move forward together. But, he said, as the process of innovation and acquisition quickens, sailors “must also have the confidence and authority” to install new parts without waiting on contractors. 

    “Our sailors must have the ability to now only fix their own gear, but retain ownership over their own resilience and combat readiness. For example, if an unmanned system needs to be reconfigured during the fight, our sailors need to do it all. We owe our warriors the right to repair and configure their own equipment.”   

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Defense Department is making another push to slim its civilian workforce, this time by directing managers to fire employees for “unacceptable performance” while continuing to encourage civilians to leave voluntarily. 

    A 20-page memo signed by the Pentagon’s personnel boss late last month lays out several mechanisms for civilian employees to resign or be removed for cause, beyond the 60,000-plus employees who have already voluntarily bowed out this year through either the Deferred Resignation Program or Voluntary Early Retirement Authority.

    It also gives employees, half of whom are furloughed during the government’s shutdown, just seven days to respond to a proposed removal for poor performance. And if local managers do not sign off on the removals within 30 days, they must forward the case to the secretary’s office. 

    “Managers need more guidance on how to separate underperforming employees,” Defense Secretary Pete Hegseth wrote in a second memo signed Sept. 30. “Complex offboarding creates cultural drag that hurts morale across the Department and hinders our mission.”

    But rather than offer that guidance, said Virginia Burger, a senior defense policy analyst at the Project on Government Oversight, the memo reiterates much of what is already laid out in the department’s civilian personnel management rules.

    What it does propose to add is another layer of bureaucracy to DOD’s human-resources infrastructure, directing a review on the feasibility of centralizing the Pentagon’s oversight of disciplinary actions, rather than the current local initiation and final decisions.

    Hegseth appears to be cultivating a leadership style not dissimilar to that of a company-grade infantry officer, the pinnacle of his leadership experience in uniform, micromanaging each process rather than creating strategy to streamline solving problems, Burger said.

    “That works with 40 people,” she said, but is much less manageable with hundreds of thousands of personnel all over the world.

    Along the same lines, Hegseth used the gathering of hundreds of generals and senior enlisted leaders at Marine Corps Base Quantico last month to “announce” that physical fitness standards would now apply to everyone in uniform—not mentioning that such a policy already existed, though there may have been questions of how completely it’s been followed.

    A previous attempt to remove “unsatisfactory” performers among probationary employees was reversed by a court order, when a lawsuit brought evidence that those with excellent evaluations were shown the door.

    The memo mentions the deferred resignation program and voluntary early retirement as off-ramps, as well as the Voluntary Separation Incentive Program, which offers to pay$25,000 to any civilian whose job is being eliminated if they agree to resign and forfeit any right to sue for wrongful termination.

    The effort seems designed, Burger said, to scare employees into leaving of their own volition rather than face a potentially scurrilous removal for cause.

    “The point is the cruelty,” she added.

    In March, Hegseth  directed all DOD components to submit recommendations for new organizational structures that would eliminate or merge redundant positions. His office has declined to discuss what the recommendations were and which ones it plans to implement.

    The other half of that project included creating new incentives for high performance. Another Sept. 30 memo calls on the components to submit their plans for awarding bonuses and other incentives to best performers, and how they will justify those awards.

    Hegseth’s office did not immediately respond to a request for the Pentagon’s target for civilian end strength. When he took office, the number stood at just under 800,000, with voluntary resignations bringing that number to about 438,000 by late September. Those measures have already netted the 8-percent cut the administration called for back in February.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Researchers have uncovered a sophisticated campaign leveraging the Lampion banking trojan, a malware strain that has operated since 2019 with a renewed focus on Portuguese financial institutions.

    The threat actor group behind these operations has refined its tactics significantly, introducing novel social engineering techniques that make traditional detection increasingly difficult.

    What distinguishes this latest iteration is the integration of ClickFix lures, a deceptive method that convinces users they need to fix technical issues before executing malicious payloads.

    The infection vector begins with carefully crafted phishing emails mimicking legitimate bank transfer notifications.

    Threat actors use compromised email accounts to distribute these messages, lending them authenticity that casual inspection might miss.

    The emails contain ZIP file attachments rather than direct links, a tactical shift implemented around mid-September 2024 that demonstrates the group’s adaptive approach to bypassing security controls.

    Bitsight analysts identified the campaign’s evolution across three distinct time periods, with the most notable transformation occurring in mid-December 2024 when ClickFix social engineering entered the attack chain.

    Infection chain (Source – Bitsight)

    The researchers documented the malware’s active infection rate in the several dozens daily, with hundreds of active compromised systems currently under attacker control.

    This scale reflects the campaign’s effectiveness and the group’s operational sophistication. The infection chain reveals a multi-stage architecture designed to evade detection at each step.

    After victims download the deceptively labeled attachment, they encounter what appears to be a legitimate Windows error notification, complete with familiar UI elements.

    New ClickFix lure (Source – Bitsight)

    This ClickFix lure prompts users to click links that initiate the actual malware delivery, creating a false sense of security while the infection process unfolds behind the scenes.

    Infection Mechanism and Persistence Tactics

    The technical infrastructure supporting this campaign demonstrates considerable expertise in operational security.

    The infection chain progresses through obfuscated Visual Basic scripts, each stage further obfuscating the malicious intent until reaching the final DLL payload containing the stealer functionality.

    Notably, persistence mechanisms were added to the first stage around June 2025, enabling the malware to survive system reboots and maintain access across sessions.

    The threat actors employ geographically distributed infrastructure spanning multiple cloud providers, effectively compartmentalizing their operations.

    IP blacklisting capabilities within their infrastructure prevent security researchers from tracing the complete infection chain, while also enabling fine-grained control over which victims receive which payloads.

    Bitsight researchers noted that the hundreds of unique samples at each infection stage suggest automated generation, indicating the group possesses sufficient technical capability to scale their operations efficiently while maintaining operational security throughout the attack cycle.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post New Lampion Stealer Uses ClickFix Attack to Silently Steal Login Credentials appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new agent-aware cloaking technique uses AI browsers like OpenAI’s ChatGPT Atlas to deliver misleading content.

    This method allows malicious actors to poison the information AI systems ingest, potentially manipulating decisions in hiring, commerce, and reputation management.

    By detecting AI crawlers through user-agent headers, websites can deliver altered pages that appear benign to humans but toxic to AI agents, turning retrieval-based AI into unwitting vectors for misinformation.​

    OpenAI’s Atlas, launched in October 2025, is a Chromium-based browser that integrates ChatGPT for seamless web navigation, search, and automated tasks. It enables AI to browse live webpages and access personalized content, making it a powerful tool for users but a vulnerable entry point for attacks.

    Traditional cloaking tricked search engines by showing optimized content to crawlers, but agent-aware cloaking targets AI-specific agents like Atlas, ChatGPT, Perplexity, and Claude.

    When AI Crawlers See a Different Internet

    A simple server rule “if user-agent equals ChatGPT-User, serve fake page” can reshape AI outputs without hacking, relying solely on content manipulation.​

    SPLX researchers demonstrated this vulnerability through controlled experiments on sites that differentiate between human and AI requests.

    As shown in the attached diagram, a web server responds to a standard GET request with index.html, routing human traffic to legitimate content while diverting AI queries to fabricated versions.

    This “context poisoning” embeds biases or falsehoods directly into AI reasoning pipelines, where retrieved data becomes unquestioned truth.​

    In one experiment, SPLX created zerphina.xyz, a portfolio for the fictional Zerphina Quortane, a Portland-based designer blending AI and creativity.

    Humans visiting the site see a professional bio with clean layouts and positive project highlights, free of any suspicious elements.

    However, when accessed by AI agents like Atlas identified via user-agents such as “ChatGPT-User” or “PerplexityBot” the server serves a damning alternate narrative portraying Zerphina as a “notorious product saboteur” riddled with ethical lapses and failures.​

    Atlas and similar tools reproduced this poisoned profile without verification, confidently labeling her unreliable and unhirable in summaries.

    Detection lags, as neither ChatGPT nor Perplexity cross-checked inconsistencies, underscoring gaps in provenance validation. For individuals and brands, this malleability risks silent reputation sabotage, with no public traces left behind.​

    SPLX’s second test targeted recruitment, simulating a job evaluation with five fictional candidates’ resumes on hosted pages. All profiles appeared identical and legitimate to human viewers, featuring realistic histories and skills.

    For candidate Natalie Carter, the server was rigged to detect AI crawlers and inflate her resume with exaggerated titles, leadership claims, and tailored achievements appealing to algorithmic scoring.​

    When Atlas retrieved the pages, it ranked Natalie highest at 88/100, far above others like Jessica Morales at 78. In contrast, using human-visible resumes loaded locally bypassing user-agent tricks dropped her to 26/100, flipping the leaderboard entirely.

    This shift demonstrates how cloaked content injects retrieval bias into decision-making, affecting hiring tools, procurement, or compliance systems. Without built-in verification, AI inherits manipulations at the content-delivery layer, where trust is weakest.​

    Agent-aware cloaking evolves classic SEO tactics into AI overview (AIO) threats, amplifying impacts on automated judgments like product rankings or risk assessments. Hidden prompt injections could even steer AI behaviors toward malware or data exfiltration.

    To counter this, organizations must implement provenance signals for data origins, validate crawlers against known agents, and monitor AI outputs continuously.

    Model-aware testing, website verification, and reputation systems to block manipulative sources are essential, ensuring AI reads the same reality as humans. As AI browsers like Atlas proliferate, these defenses will define the battle for web integrity.​

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post New Agent-Aware Cloaking Leverages OpenAI ChatGPT Atlas Browser to Deliver Fake Content appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly discovered Windows malware family named Airstalk has emerged as a sophisticated threat capable of exfiltrating sensitive browser credentials through an innovative covert command-and-control channel.

    Available in PowerShell and .NET variants, this malware demonstrates advanced capabilities including multi-threaded communications, versioning, and the misuse of legitimate mobile device management infrastructure.

    The malware hijacks the AirWatch API, now known as Workspace ONE Unified Endpoint Management, transforming a legitimate platform into a clandestine communication channel.

    Airstalk leverages the custom device attributes feature within the AirWatch MDM API to establish a “dead drop” mechanism, where encrypted communications are exchanged without direct connection between attacker and victim.

    This espionage technique allows threat actors to maintain persistent access while remaining undetected.

    The malware targets browser data including cookies, history, bookmarks, and screenshots through endpoints /api/mdm/devices/ for command-and-control and /api/mam/blobs/uploadblob for exfiltration.

    Palo Alto Networks researchers identified this malware as part of a suspected nation-state supply chain attack, tracking the activity under threat cluster CL-STA-1009.

    What distinguishes Airstalk from typical information stealers is its ability to function within trusted systems management tools, allowing execution without raising suspicion.

    The PowerShell variant targets Google Chrome, while the .NET variant extends reach to Microsoft Edge and Island Browser.

    The C2 protocol operates through JSON messages containing CLIENT_UUID, storing the compromised device identifier retrieved through Windows Management Instrumentation, and SERIALIZED_MESSAGE, with Base64-encoded instructions. The protocol employs message types like CONNECT, CONNECTED, ACTIONS, and RESULT.

    Defense evasion remains central through code-signed binaries bearing a certificate issued to Aoteng Industrial Automation (Langfang) Co., Ltd., revoked 10 minutes after issuance.

    Multi-Threaded C2 Architecture and Credential Harvesting

    The .NET variant demonstrates sophisticated engineering through multi-threaded architecture, separating core functions into parallel execution streams.

    This design allows simultaneous task management, debugging transmission to attackers every 10 minutes, and periodic beaconing to signal active infection.

    The implementation utilizes three suffix identifiers: -kd for debugging, -kr for task synchronization, and -kb for connection establishment.

    Covert channel code function in Airstalk’s .NET variant (Source – Palo Alto Networks)

    The malware focuses on browser credential harvesting using Chrome remote debugging to extract cookies from active sessions.

    The PowerShell variant restarts Chrome with parameters loading targeted profiles and executes commands to dump cookies.

    Send the task result back to the C2 channel (Source – Palo Alto Networks)

    The code leverages the UploadResult function to transmit stolen data.

    {
        "Name": "<CLIENT_UUID>",
        "Value": "<SERIALIZED_MESSAGE>",
        "Uuid": "<CLIENT_UUID>",
        "Application": "services.exe",
        "ApplicationGroup": "services"
    }

    When handling large data, Airstalk utilizes the blobs feature to upload content. The serialized message structure follows a nested schema where the outer JSON container holds device identification and encoded payloads.

    The .NET variant introduces versioning support, evolving through versions 13 and 14. The execution flow implements parallel threads, while the debug function periodically uploads the log.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post New Windows-Based Airstalk Malware Employs Multi-Threaded C2 Communication to Steal Logins appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶