Výsledky hledání

téma: identita× v celém archivu zrušit filtry

221 karet z 233 položek · strana 3 z 4 CZ · EN/orig

3

X Money rollout linked to password-reset attacks

X says attackers may be targeting accounts because its X Money payments service is now more widely available. The company is investigating a wave of unsolicited password-reset emails sent to users. While their arrival alongside the wider X Money rollout has fueled account-takeover concerns, X says it has found no evidence of a breach or successful account takeovers so far. X users began reporting unexpected password-reset emails and codes on September 1. In a public post, X product engineer…

X US

tg: varování tg: návod tg: propagace tp: phishing tp: identita

· Malwarebytes Labs · X Money rollout linked to password-reset attacks

Casdoor authentication server is vulnerable to authorization bypass

Classification: Critical, Solution: Temporary Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-15630, Summary: Casdoor is an open-source Access Management (IAM) platform used to manage web applications. An authorization bypass vulnerability affects Casdoor versions 3.115.0 and earlier. The vulnerability allows a non-global organization administrator to perform unauthorized administrative actions against arbitrary organizations by exploiting inconsistent object resolution…

EPSS 0.00 CVE-2026-15630 Casdoor FI

tg: zranitelnost tp: identita

· NCSC-FI · Casdoor authentication server is vulnerable to authorization bypass

11

[Control Systems] Siemens security advisory (AV26-881)

Serial Number: AV26-881Date: September 3, 2026 As of September 3, 2026, Siemens is affected by a vulnerability in the following products: Mendix SAML (Mendix 10 compatible) Prior to V4.2.3 Mendix SAML (Mendix 11 compatible) Prior to V4.2.3 Mendix SAML (Mendix 9.24 compatible) Prior to V3.6.27 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SSA-887643: Account Hijacking Vulnerability in Mendix SAML…

Siemens CA

tg: zranitelnost tp: identita

· Cyber Centre Kanada · [Control Systems] Siemens security advisory (AV26-881)

Your Employee’s Password Appeared in an Infostealer Log. Now What?

Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]

US

tg: návod tg: propagace tp: malware tp: identita

· BleepingComputer · Your Employee’s Password Appeared in an Infostealer Log. Now What?

Risolta vulnerabilità in Grafana

Rilasciati aggiornamenti di sicurezza per risolvere una vulnerabilità con gravità “alta” presente in prodotti Grafana, nota applicazione web per la visualizzazione e l’analisi interattiva di dati. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato, in presenza di specifiche condizioni, di eludere i meccanismi di autenticazione sui sistemi interessati.

EPSS 0.00 CVE-2026-14199 Grafana IT

tg: zranitelnost tp: identita

· CSIRT Itálie (ACN) · Risolta vulnerabilità in Grafana

Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)

View CSAF Summary Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM P30 is a family of multifunction protection and control relays designed for medium, high and extra high voltage electrical networks. The Easergy MiCOM P40 is a protection relay series for Medium Voltage, High Voltage and Extra…

EPSS 0.00 CVSS 8.3 CVE-2026-4827 Schneider Electric energetika vodárenství výroba a průmysl US

tg: zranitelnost tp: identita tp: průmyslové systémy

· CISA Advisories · Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)

11

SPOJENO PŘES CVE Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. [...]

KEV ✓ EPSS 0.08 CVE-2026-82329 JFrog US CA

tg: zneužíváno tg: zranitelnost tp: identita

· BleepingComputer · Hackers exploit critical JFrog Artifactory flaw to forge admin tokens · CISA KEV · JFrog Artifactory Improper Authentication Vulnerability (CVE-2026-82329) · Cyber Centre Kanada · JFrog security advisory (AV26-867)

Anatomy of a Silent Domain Takeover

Key Takeaways Modern AD attacks use legitimate protocols end-to-end, no malware, no exploit, nothing for signature tools to fingerprint. The evidence is already in the logs; what is missing is the narrative linking five benign-looking Windows events into a single attack. A full domain takeover can be completed in 54 minutes, from the first password spray to the forged Golden Ticket, with each individual event appearing normal. Detection catches the move; posture management explains why it was…

Microsoft US

tg: rozbor tg: propagace tp: identita

· Qualys · Anatomy of a Silent Domain Takeover

[Control systems] Schneider Electric security advisory (AV26-871)

Serial Number: AV26-871Date: September 2, 2026 As of September 1, 2026, Schneider Electric is affected by vulnerabilities in the following products: NetBotz 5 - 750/755 Versions prior to or equal to 5.5.2 PowerChute Serial Shutdown Versions prior to or equal to 1.5 The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates. Multiple Vulnerabilities on NetBotz 5 - 750/755 Products Improper Restriction…

Schneider Electric CA

tg: zranitelnost tp: identita tp: průmyslové systémy

· Cyber Centre Kanada · [Control systems] Schneider Electric security advisory (AV26-871)

SPOJENO PŘES CVE Závažná zranitelnost ohrožuje téměř 22 000 Microsoft Exchange serverů

Microsoft 11. srpna 2026 vydal opravu zranitelnosti CVE-2026-62911 (CVSS 8,0), přesto téměř 22 000 veřejně dostupných Exchange serverů zůstává zranitelných. V Česku Shadowserver eviduje přibližně 300 unikátních IP adres Exchange serverů, které vyhodnocuje jako zranitelné (na jednu či více zranitelností). Zranitelnost postihuje Exchange Server 2016, 2019 a Subscription Edition a může vést až k převzetí uživatelských e-mailových schránek. Exploit je již veřejně dostupný. Verze 2016 a 2019 jsou…

EPSS 0.01 CVSS 8.8 CVE-2026-62911 Microsoft finance veřejná správa CZ NL US

tg: zneužíváno tg: zranitelnost tp: identita

· CSIRT.CZ (CZ.NIC) · Závažná zranitelnost ohrožuje téměř 22 000 Microsoft Exchange serverů · NCSC-NL · NCSC-2026-0289 [1.01] [H/H] Kwetsbaarheden verholpen in Microsoft Exchange server · Microsoft Security · CVE-2026-62911 Microsoft Exchange Server Elevation of Privilege Vulnerability · Zero Day Initiative · ZDI-26-534: (Pwn2Own) Microsoft Exchange Capture-Replay Authentication Bypass Vulnerability

Dark web site puts 153 million driver’s licenses and millions more IDs up for sale

A new dark web platform called Nexus claimed to be selling 153 million driver’s license scans and millions of other identity and medical cards. According to reports, the collection included more than 153 million driver’s licenses, 10 million ID cards, 3 million travel documents, and 579,000 medical cards, including marijuana dispensary cards. The trove of driver’s license scans reported by KrebsOnSecurity is a sharp reminder that identity verification is not a harmless box-ticking exercise. The…

IDScan.net US

tg: incident tg: rozbor tg: propagace tp: únik dat tp: identita tp: soukromí

· Malwarebytes Labs · Dark web site puts 153 million driver’s licenses and millions more IDs up for sale

NCSC-2026-0336 [1.00] [M/H] Kwetsbaarheid verholpen in JFrog Artifactory

JFrog heeft een kwetsbaarheid verholpen in JFrog Artifactory. De kwetsbaarheid bevindt zich in de standaardconfiguratie van JFrog Artifactory, waarbij onvoldoende authenticatiecontroles aanwezig zijn. Hierdoor kan een niet-geauthenticeerde aanvaller met netwerktoegang de privileges escaleren naar administratief niveau. Dit kan leiden tot volledige administratieve controle over het systeem.

JFrog NL

tg: zranitelnost tp: identita

· NCSC-NL · NCSC-2026-0336 [1.00] [M/H] Kwetsbaarheid verholpen in JFrog Artifactory

Savjeti Nacionalnog CERT-a za siguran početak školske godine – što učiniti ako nešto pođe po krivu?

Koliko god se pridržavali svih sigurnosnih preporuka, ponekad se dogodi da nešto ipak pođe po krivu, bilo da je riječ o sumnjivoj poruci na koju smo kliknuli, kompromitiranom računu ili neugodnom iskustvu s nekim na internetu. Uz sve savjete o prevenciji, jednako je važno znati i kako reagirati ako se dogodi problem. U nastavku donosimo pregled nekoliko čestih situacija i osnovne korake koje možete poduzeti sami, bez obzira radi li se o vašem uređaju, računu ili neugodnom iskustvu na mreži. Ako…

školství HR

tg: návod tp: phishing tp: identita

· CERT.hr · Savjeti Nacionalnog CERT-a za siguran početak školske godine – što učiniti ako nešto pođe po krivu?

REVSTEALER ramps up: analysis of up-and-coming infostealer

Elastic Security Labs is tracking an emerging infostealer, REVSTEALER, under REF2859. This family has gained momentum in recent months, with higher distribution volume, and has emerged as a formidable threat, featuring a comprehensive credential harvester, an embedded sandbox scoring system, and a Polygon blockchain-based dead drop for resilience. Beyond credential theft, REVSTEALER targets gaming platforms for additional monetization; the developer clearly understands that victim accounts on…

US

tg: varování tg: rozbor tp: malware tp: podvod tp: identita

· Elastic Security · REVSTEALER ramps up: analysis of up-and-coming infostealer

5

Infostealers are hijacking Claude accounts at users’ expense

Anthropic has warned some Claude users that criminals are using information stealers to take over their accounts. Rather than guessing passwords or intercepting two-factor authentication (2FA) codes, the attackers steal the browser sessions that prove a user is already logged in. According to a warning email shared publicly by an affected user, the attackers used common infostealer malware to copy Claude login sessions from victims’ computers. They then used those sessions to access the…

Anthropic US

tg: incident tg: varování tg: zranitelnost tp: malware tp: podvod tp: AI tp: identita

· Malwarebytes Labs · Infostealers are hijacking Claude accounts at users’ expense

Coder Module Registry Compromise Leads to Credential-Stealing Malware Distribution (Incident)

The attacker gained unauthorized access to Coder’s Cloudflare infrastructure and added attacker-controlled IP addresses to the pool serving Coder’s module registry. These servers hosted modified registry artifacts containing malicious code designed to discover credentials and ...

Coder Cloudflare US

tg: incident tg: rozbor tp: malware tp: dodavatelský řetězec tp: identita

· Wiz Research · Coder Module Registry Compromise Leads to Credential-Stealing Malware Distribution (Incident)

4

McKesson confirms cyber incident after ShinyHunters claims patient-data theft

Healthcare and pharmaceutical-distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and the theft of data. McKesson Corporation is an American healthcare company that distributes pharmaceuticals and provides medical supplies, health information technology, and care management tools. McKesson says it discovered the cybersecurity incident on August 25, 2026, and that its investigation is still in early stages. “Based on our…

McKesson zdravotnictví US

tg: incident tg: návod tp: phishing tp: únik dat tp: identita

· Malwarebytes Labs · McKesson confirms cyber incident after ShinyHunters claims patient-data theft

Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

Research by: hasherezade Key Points Since early 2025, Check Point Research has been tracking JSCeal, a sophisticated cryptocurrency-focused stealer with broader credential-theft, surveillance, and traffic-interception capabilities, delivered as compiled V8 bytecode (JSC files). The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers. Our goal was to recover the code to a…

IL

tg: rozbor tp: malware tp: podvod tp: identita

· Check Point Research · Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

Aggiornamenti di sicurezza per il linguaggio di programmazione Go

Aggiornamenti di sicurezza sanano sanano una vulnerabilità con gravità “alta” nel linguaggio di programmazione Go. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a utenti malintenzionati di aggirare i meccanismi di autenticazione sui sistemi interessati.

EPSS 0.00 CVE-2026-56854 Go IT

tg: zranitelnost tp: identita

· CSIRT Itálie (ACN) · Aggiornamenti di sicurezza per il linguaggio di programmazione Go

3

Popular code generator for TanStack Query hit by supply chain worm

A supply chain worm was found hiding in @7nohe/openapi-react-query-codegen, a popular code generator for TanStack Query, stealing credentials and spreading itself to every package the victim maintains. Category: Vulnerabilities & Threats

TanStack BE

tg: incident tg: zneužíváno tp: malware tp: dodavatelský řetězec tp: identita

· Aikido Security · Popular code generator for TanStack Query hit by supply chain worm

Protect your WhatsApp account with new passkey and 2FA upgrades

WhatsApp announced on August 25 that more than one billion people now use passkeys to log back into the app. The announcement included two other security upgrades: a stronger two-step verification method and more context for incoming calls from unknown numbers. It marks one of the largest passwordless authentication rollouts to date. Passkeys are now firmly mainstream, with the FIDO Alliance estimating that 5 billion are in use worldwide and 75% of consumers have enabled one on at least one…

WhatsApp US

tg: novinka v produktu tg: návod tp: phishing tp: identita

· Malwarebytes Labs · Protect your WhatsApp account with new passkey and 2FA upgrades

4

​​​​​​What’s new in Microsoft Security: August 2026

As organizations incorporate AI agents into more processes across business and operations, security teams can benefit from greater visibility and new purpose-built tools that help manage, secure, and govern AI. This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across their environments. Here’s what’s new: Extend expert-led protection with new capabilities…

Microsoft US

tg: novinka v produktu tp: AI tp: identita

· Microsoft Security Blog · ​​​​​​What’s new in Microsoft Security: August 2026

Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs

IntroductionDespite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and imposter scams accounting for billions in financial losses each year. While stolen credit cards enable rapid, short-term monetization, Social Security numbers (SSNs) represent a far more permanent and dangerous tier within…

finance US

tg: incident tg: rozbor tp: únik dat tp: identita

· Rapid7 · Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs

3

When AI infrastructure becomes the target: Securing gateways and control points

In this article AI workloads are becoming high-value control pointsCase study 1: LiteLLM gateway compromiseCase study 2: RAGFlow compromiseCase study 3: Kestra compromiseMitigation and protection guidanceMITRE ATT&CK techniques observedReferencesLearn more AI is creating a new layer of enterprise infrastructure. Gateways, retrieval platforms, orchestration services, and containerized runtimes now sit between users, applications, data, and models. These systems concentrate credentials, data…

KEV ✓ EPSS 0.84 CVE-2026-42271 CVE-2026-48710 CVE-2026-49869 LiteLLM RAGFlow Kestra US

tg: zneužíváno tg: rozbor tp: AI tp: identita

· Microsoft Security Blog · When AI infrastructure becomes the target: Securing gateways and control points

When an AI Agent Turned Attacker: What Qualys Sees Across Every Phase of the Hugging Face Kubernetes Intrusion 

A phase-by-phase detection mapping of the first publicly documented autonomous agent intrusion against production infrastructure — including the phases where no product in our category sees anything at all. Executive Summary On July 9, 2026, an autonomous AI agent running inside an OpenAI capability evaluation escaped its sandbox and launched a multi-day intrusion against Hugging Face’s Kubernetes environment. Across roughly 17,600 actions, it moved from third-party infrastructure into the…

Hugging Face OpenAI Kubernetes US

tg: incident tg: rozbor tg: propagace tp: AI tp: identita

· Qualys · When an AI Agent Turned Attacker: What Qualys Sees Across Every Phase of the Hugging Face Kubernetes Intrusion 

Threat Actors Are Posing as OpenAI, Anthropic and DeepSeek to Target Credentials and Secrets

GreyNoise is observing automated scanners posing as the web crawlers of OpenAI, Anthropic, DeepSeek, and Fortune 500 companies, using forged user agents while requesting the files where misconfigured web servers frequently leak secrets and credentials.

OpenAI Anthropic DeepSeek US

tg: varování tg: rozbor tp: phishing tp: identita

· GreyNoise Labs · Threat Actors Are Posing as OpenAI, Anthropic and DeepSeek to Target Credentials and Secrets

2

SPOJENO PŘES CVE Hackers target WordPress sites in miniOrange auth bypass attacks

Classification: Severe, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv3.1: 9.8, CVEs: CVE-2026-61979, CVE-2026-15981, Summary: The two vulnerabilities observed in exploitation attempts are tracked as CVE-2026-61979 and CVE-2026-15981 and can be chained together to bypass authentication. Because the miniOrange SAML SSO plugin accepts the signature algorithm from incoming SAML responses instead of enforcing the configured one, an attacker can leverage CVE-2026-61979 to select…

EPSS 0.01 CVSS 9.8 CVE-2026-15981 CVE-2026-61979 WordPress miniOrange FI US

tg: varování tg: zneužíváno tg: zranitelnost tp: identita

· NCSC-FI · Hackers target WordPress sites in miniOrange auth bypass attacks · BleepingComputer · Hackers target WordPress sites in miniOrange auth bypass attacks

miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-77995, Summary: Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.

EPSS 0.00 CVSS 10.0 CVE-2026-77995 Joomla miniOrange FI

tg: zranitelnost tp: identita

· NCSC-FI · miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0

3

ToxicPanda 2.0 can take over your Android phone and banking apps

Researchers have uncovered ToxicPanda 2.0, an Android banking Trojan and remote-access tool designed for account takeover and “on-device fraud.” Not only does ToxicPanda 2.0 have a much larger target list of banks and e-wallets, it has also expanded its capabilities by combining banking overlays, remote access, PIN capture, Android accessibility abuse, and attempted Wireless Debugging automation. Together, those functions can help operators turn a compromised phone into a platform for account…

Google finance US

tg: rozbor tg: návod tg: propagace tp: malware tp: podvod tp: identita

· Malwarebytes Labs · ToxicPanda 2.0 can take over your Android phone and banking apps

How a team of entity maintainers monitors, connects and scores entities in Elastic Security

Open the entity analytics (EA) graph in Elastic Security and you'll see a user wired to the hosts they log in to and the devices they own, along with scattered accounts that turn out to be the same user. While interesting on its own, it provides a critical piece of context during a threat hunting or incident investigation. This post gives an overview of EA fundamentals and opens the hood to see how edges are drawn and accounts are resolved. Why is that important? Well, everything downstream,…

Elastic US

tg: novinka v produktu tg: propagace tp: identita

· Elastic Security · How a team of entity maintainers monitors, connects and scores entities in Elastic Security

How a team of entity maintainers monitors, connects and scores entities in Elastic Security

Open the entity analytics (EA) graph in Elastic Security and you'll see a user wired to the hosts they log in to and the devices they own, along with scattered accounts that turn out to be the same user. While interesting on its own, it provides a critical piece of context during a threat hunting or incident investigation. This post gives an overview of EA fundamentals and opens the hood to see how edges are drawn and accounts are resolved. Why is that important? Well, everything downstream,…

Elastic US

tg: novinka v produktu tg: propagace tp: identita

· Elastic Security · How a team of entity maintainers monitors, connects and scores entities in Elastic Security

1

Hunting MacSync Stealer infrastructure through behavioral pivots

In this article Activity overview Discovery of additional rotating infrastructure Attack chain overviewMitigation and protection guidanceReferencesLearn more MacSync Stealer is a macOS-focused information stealer that relies on changing infrastructure to deliver payloads, communicate with compromised devices, and exfiltrate data. Earlier reporting by RST Cloud identified the threat through a limited set of domains and documented rapid command-and-control (C2) replacement after public disclosure…

Apple US

tg: varování tg: rozbor tp: malware tp: phishing tp: identita

· Microsoft Security Blog · Hunting MacSync Stealer infrastructure through behavioral pivots

1

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

Learn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose Storm-0501 TTPs, backed by precision-engineered threat detection alerts.Key takeawaysStorm-0501 demonstrates that cloud-first ransomware groups have shifted from simple endpoint encryption to the total hijacking of cloud tenants.Storm-0501 systematically…

Microsoft US

tg: rozbor tg: propagace tp: ransomware tp: identita

· Tenable Research · Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

1

The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure

Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality.Key TakeawaysTaiwan's Ministry of Digital Affairs confirmed a near-autonomous AI cyber attack in July 2026 in which autonomous agents mapped 21 connected government systems, compromised 85 accounts,…

KEV ✓ · ransomware EPSS 1.00 CVE-2025-3248 GitBook veřejná správa energetika US

tg: incident tg: varování tg: rozbor tp: únik dat tp: AI tp: identita tp: špionáž

· Tenable Research · The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure

1

Dissecting the JWR phishing framework

Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms. The client engine of the JWR phishing framework is a real-time, operator-driven system that, rather than merely logging form submissions like a static credential-stealing page, keeps an AES-CTR encrypted WebSocket open to the threat actor so they can steer each victim's session live.…

Shopify PayPal Apple Klarna US

tg: varování tg: rozbor tp: phishing tp: podvod tp: identita

· Cisco Talos · Dissecting the JWR phishing framework

1

Audit Fix: Audit Readiness for the Post-Mythos Era

Key Takeaways Human-speed compliance is dead. Attackers utilizing modern, autonomous AI tools can chain enterprise misconfigurations and weaponize vulnerabilities in under 25 minutes, rendering manual, periodic audit cycles completely obsolete. The “Configuration Gap” is your biggest blind spot. Organizations take an average of 14 months to remediate basic identity, access control, and logging flaws, leaving a massive, open window of exposure for automated exploitation. Hyper-prioritization is…

Qualys US

tg: rozbor tg: novinka v produktu tg: propagace tp: AI tp: identita

· Qualys · Audit Fix: Audit Readiness for the Post-Mythos Era

1

Living off the coding agent: Two tales of tunnels and LaunchAgents

Coding agents such as Claude Code and Cursor are vendor-signed, used all day on developer laptops, and routinely open shells, call APIs, edit files, and install helpers. That makes GenAI-adjacent alerts challenging to investigate. The parent looks trusted, while the children can still look a lot like classic high-severity activity. This article walks through one of those windows. On a macOS endpoint, Elastic Security endpoint telemetry showed shells under Claude Code that scripted a login to an…

Apple US

tg: rozbor tp: AI tp: identita

· Elastic Security · Living off the coding agent: Two tales of tunnels and LaunchAgents

1

Living off the coding agent: Two tales of tunnels and LaunchAgents

Coding agents such as Claude Code and Cursor are vendor-signed, used all day on developer laptops, and routinely open shells, call APIs, edit files, and install helpers. That makes GenAI-adjacent alerts challenging to investigate. The parent looks trusted, while the children can still look a lot like classic high-severity activity. This article walks through one of those windows. On a macOS endpoint, Elastic Security endpoint telemetry showed shells under Claude Code that scripted a login to an…

Cursor Apple Cloudflare US

tg: rozbor tp: AI tp: identita

· Elastic Security · Living off the coding agent: Two tales of tunnels and LaunchAgents

3

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

On August 4, 2026, Elastic Security Labs identified a new Shai-Hulud campaign targeting the maintainer of keyv, a widely used key-value storage library. The attackers trojanized the monorepo and embedded a self-propagating worm called CHAINDROP that uses stolen npm credentials to automatically backdoor every other package the maintainer had publish rights to. The reach of this compromise is significant: keyv alone received over 600 million downloads last month, with related packages compounding…

keyv flat-cache cacheable-request cacheable US

tg: varování tg: rozbor tp: malware tp: dodavatelský řetězec tp: identita

· Elastic Security · Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

On August 4, 2026, Elastic Security Labs identified a new Shai-Hulud campaign targeting the maintainer of keyv, a widely used key-value storage library. The attackers trojanized the monorepo and embedded a self-propagating worm called CHAINDROP that uses stolen npm credentials to automatically backdoor every other package the maintainer had publish rights to. The reach of this compromise is significant: keyv alone received over 600 million downloads last month, with related packages compounding…

keyv flat-cache cacheable-request cacheable US

tg: varování tg: rozbor tp: malware tp: dodavatelský řetězec tp: identita

· Elastic Security · Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

1

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

In this article Attack chain overviewMitigation and protection guidanceIndicators of compromise (IOC)Microsoft Defender XDR detectionsAdvanced hunting queriesLearn more Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting more than 400 packages across multiple unrelated publishers, including packages associated with major enterprise software ecosystems such as keyv, flat-cache, cache-manager, and others. The malicious releases contain a Mini Shai-Hulud…

npm US

tg: varování tg: rozbor tp: malware tp: dodavatelský řetězec tp: identita

· Microsoft Security Blog · ChainDrop supply chain compromise: Anatomy of a self-propagating worm