Posts

Showing posts with the label Threat Intelligence

The Mythos Dilemma: Anthropic's 'Too Dangerous' AI Is Rewriting the Rules of Cybersecurity

Image
A month after Anthropic unveiled Claude Mythos — an AI model so capable at finding software vulnerabilities that the company deemed it "too dangerous" to release publicly — the cybersecurity world is still trying to figure out what it actually means. The model has sparked a cascade of reactions: from panicked banking regulators to a policy shift that's quietly rewriting the rules of AI access. What started as a controlled experiment in responsible AI release has become one of the defining cybersecurity stories of 2026. Mythos was released in April 2026 under extreme restrictions. Only about 50 companies — mostly US-based tech giants like Amazon, Microsoft, Apple, and Google — were granted access through a program called Project Glasswing . Participants were given access to the model's vulnerability-finding capabilities but were barred from sharing their findings with anyone outside the program. The rationale was straightforward: if this kind of AI can autonomously ...

When a Supply-Chain Attack on npm Becomes a War of Attrition: TanStack, GitHub, and Grafana

Image
The TanStack npm supply-chain attack, delivered via the Shai-Hulud malware campaign by the threat group TeamPCP , is the kind of cascading failure that exposes how brittle the entire developer toolchain has become. What started as compromised npm packages in early May 2026 snowballed into the compromise of 3,800 GitHub internal repositories and a breach of Grafana's own codebase — two of the most consequential security incidents to hit major infrastructure providers in months. The attack chain is methodical and well-documented. On May 19 , Nx developers revealed they were investigating a malicious version of Nx Console 18.95.0 — the official VS Code extension for managing monorepos and multi-project codebases — that had been live on the Visual Studio Marketplace for approximately 18 hours. The extension carried an embedded credential-stealing module designed to harvest secrets from developer environments. But this wasn't an isolated incident; the Nx Console compromise was i...

China-aligned hackers built malware that turns telecom Linux servers into SOCKS5 proxies

Image
Chinese threat actors have been quietly compromising telecommunications providers across the Asia Pacific and the Middle East since at least 2022, and the tools they use are unusually well-suited to the kind of long-haul infrastructure spying you'd expect from a state-aligned group. Researchers at Lumen's Black Lotus Labs and PwC Threat Intelligence published details today of two new implants — Showboat for Linux and JFMBackdoor for Windows — that the Calypso (AKA Red Lamassu) group has been using to turn compromised telco systems into network pivots. Showboat is a modular post-exploitation framework that runs on Linux servers and does the kind of thing that makes sysadmins nervous: it collects host information, maintains persistence through new services, and then opens a SOCKS5 proxy on the compromised machine so attackers can hop deeper into the internal network. It also has a neat trick — a "hide" command that pulls code from dead drops like Pastebin pages, meani...

China-aligned hackers built malware that turns telecom Linux servers into SOCKS5 proxies

Chinese threat actors have been quietly compromising telecommunications providers across the Asia Pacific and the Middle East since at least 2022, and the tools they use are unusually well-suited to the kind of long-haul infrastructure spying you'd expect from a state-aligned group. Researchers at Lumen's Black Lotus Labs and PwC Threat Intelligence published details today of two new implants — Showboat for Linux and JFMBackdoor for Windows — that the Calypso (AKA Red Lamassu) group has been using to turn compromised telco systems into network pivots. Showboat is a modular post-exploitation framework that runs on Linux servers and does the kind of thing that makes sysadmins nervous: it collects host information, maintains persistence through new services, and then opens a SOCKS5 proxy on the compromised machine so attackers can hop deeper into the internal network. It also has a neat trick — a "hide" command that pulls code from dead drops like Pastebin pages, meani...