As promised, we've published our analysis of #Cruciferra - an EDR/AV-killing malware loader delivered via #ErrTraffic-generated #ClickFix campaigns. The loader heavily relies on DLL side-loading to bypass SmartScreen - a majority of targeted apps are developer toolchain-based. Full target list and analysis below!
https://t.co/QHUHchJ2IZ
DLL side-load targets:
https://t.co/FJum3AjR9l
Check Point's Jaromír Hořejší analyses StopAndProtect, a new operation combining file encryption with data theft. The attackers abuse thousands of hacked WordPress sites as their infrastructure to spread malware, control victim machines & store stolen data https://t.co/rOPgMyZ9tr
Gen Threat Labs researchers describe WordlistLoader, a new loader used to deliver Amatera Stealer via ClearFake campaigns. They also highlight the changes Amatera has introduced between v 4.0.2 Beta (documented by eSentire) and current version 4.3.3-alpha1 https://t.co/wWif1wf1uD
⚒️ BTR Reforged: Weaponizing Defender's Remediation Driver as a Kernel Operation Primitive
⚠ Trusted Remediation Primitives with Undocumented Internals.
🔓 15+ years. Unchanged. Unblockable.
🤔 What if an attacker learned its language? We did.
👇
https://t.co/AICs7JCI4d
A handy .NET reverse engineering trick:
Add a sample.exe.config file next to your sample and you can trace e.g. all network requests, including content and headers without hooking or bothering with proxies. Helpful to e.g. quickly inspect c2 traffic:
https://t.co/WE6gFSQAkg
🚨 Hackers are already exploiting a flaw in LiteLLM, a widely used open-source AI gateway.
One bug (CVE-2026-42271) lets any logged-in user run commands on the server. Chain it with a second bug, and attackers get in with no login at all.
🔗 Details: https://t.co/pGSIrWhUI3
🔥 An AI worm used a local open-weight LLM to find targets, choose attack paths, and copy itself.
> No human help.
> No OpenAI or #Anthropic API.
> No API key to shut off.
In 7 days, it replicated to 62% of a 33-host test network.
It also used fresh CVE advisories to find new attack paths.
Read full story: https://t.co/NVZZjUGZXF
BRAINBLAST JUST EXPANDED TO THE ENTIRE SOFTWARE DEVELOPMENT LIFECYCLE
@brainblast_ai has released v0.6.0, transforming brainblast from a security tool into security infrastructure.
- GitHub Actions Integration
- AI Agent MCP Server
- Dependency Risk Diff Analysis
Brainblast now works:
- Before you write code
- While you upgrade dependencies
- Inside AI agent workflows
- Directly inside pull requests
Brainblast v0.6.0 moves security upstream, downstream, and into AI workflows.
We've created an obsidian brain for smart contract audits and the results are shocking 🫣🫣
No AI fluff - only all the crits from @SoloditOfficial and @RektHQ scraped to markdown files, and extrapolated to:
- protocols from bounty platforms, rekt, selected public audit portfolio reports
- complex ai-based tagging system dividing bugs into sectors
- methodologies and checks that would've prevented each bug
- language specifics, protocol specifics, l2 specifics and more
- who reported the bug
- who missed the bug
AND MUCH MORE!
A common use case:
> We start an audit on a zk-heavy protocol
> Load the obsidian vault locally
> tag:#sector/zk AND path:classifications/bug/check
this extracts all zk-tagged CHECKS, meaning all the checks corresponding to critical issues in the vault, that are to be checked against zk sector
auditing staking pools? prediction markets? multisig? gaming protocols? etc.
same for auditing rust? anchor? stylus? cairo? yul?!
Best part - it lets your AI agent save enormous amount of tokens by using obsidian's wikilinks feature to simply get highly relevant data.
I personally use this at the start of every new audit and improve it gradually.
Would you use something like this? should I make it open source?
Retweet this post and spread the word to let me know‼️
I think AI coding hype follows roughly four stages:
1. Amazement
You try it and can’t believe how much code it generates from a few prompts.
2. Expansion
You start more and more projects because shipping suddenly feels cheap and fast.
This is also the phase where people start convincing everyone around them:
- coworkers
- management
- friends in other companies
because nobody wants to “fall behind” in 6–12 months.
That creates a massive snowball/FOMO effect.
3. The grind phase
You realize the generated code has architectural issues, sloppy mistakes, weird abstractions, duplicated logic, broken edge cases, etc.
So you start:
- re-prompting
- switching models
- increasing reasoning effort
- reviewing fixes
- generating fixes for previous fixes
And suddenly you spend your days reviewing AI-generated pull requests instead of building software.
4. Realization
You realize AI coding increases output much faster than it increases certainty.
The code still needs:
- review
- testing
- ownership
- architectural understanding
- long-term maintenance
Usually by expensive senior engineers.
And the interesting thing is:
this whole cycle can take many months or even more than a year because people become socially and professionally invested in the narrative themselves.
Once teams, managers, and entire companies have been convinced that this is the future, it becomes psychologically and politically very hard to later say:
“Actually, the ROI is much lower than we expected.”
🛑 Your AI model upload could be hijacked before it even lands.
Researchers found a Google Vertex AI SDK flaw that let attackers pre-create a predictable bucket, intercept an ML model upload, and swap in a malicious model in under 2 seconds.
Read ➝ https://t.co/gkACw2RubL
🚨 One weak LiteLLM account could take over an AI gateway.
A CVSS 9.9 flaw chain lets attackers become admin, run code, steal AI keys, read prompts, and tamper with AI agent responses.
Read the full story: https://t.co/ZqQtUeX5uY
Google Threat Intelligence Group, Lookout & iVerify have identified DarkSword - a new iOS full-chain exploit using multiple 0-days to fully compromise devices - that's been deployed by commercial surveillance vendors & suspected state-sponsored actors. https://t.co/632xRQoxFr
The Zscaler ThreatLabz team presents a technical analysis of SnappyClient, including its core features, configuration, network communication protocol, commands, and post-infection activities. https://t.co/LyOgaiZNex
#Malware#SmartLoader disguised using OpenClaw-related topics
Threat actor built malicious Github repo on the basis of a legimate one.
Report: https://t.co/sBR7XQ0ojZ
hxxp://89.169.12[.235/api/
hxxp://213.176.73[.145/api/
hxxp://213.176.73[.162/api/
Threat Actors are "Bringing Their Own Forensics"
In a recent ClickFix campaign, we saw threat actors likely related to Interlock Ransomware, running Volatility (https://t.co/Vq0vkvWutb) directly on victim machines.
Commonly a tool for defenders, the TAs are using it to: