<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Mark0</title>
    <description>The latest articles on DEV Community by Mark0 (@mark0_617b45cda9782a).</description>
    <link>https://dev.to/mark0_617b45cda9782a</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3702447%2F0301e2c9-634f-4567-8171-fd5d9da0b3aa.jpg</url>
      <title>DEV Community: Mark0</title>
      <link>https://dev.to/mark0_617b45cda9782a</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/mark0_617b45cda9782a"/>
    <language>en</language>
    <item>
      <title>The Closed Quorum: Inside the first reported autonomous AI C2 implant</title>
      <dc:creator>Mark0</dc:creator>
      <pubDate>Thu, 24 Sep 2026 04:15:32 +0000</pubDate>
      <link>https://dev.to/mark0_617b45cda9782a/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant-3e84</link>
      <guid>https://dev.to/mark0_617b45cda9782a/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant-3e84</guid>
      <description>&lt;p&gt;CLOSEDQUORUM is a pioneering Windows implant identified by Cisco Talos that implements a fully autonomous command-and-control (C2) architecture. By utilizing a panel of commercial Large Language Models (LLMs)—including DeepSeek, Mistral, and Gemini—the malware delegates tactical decision-making to AI. This shift represents a significant move toward effort displacement, where the attack chain continues to progress without the need for constant human operator involvement.&lt;/p&gt;

&lt;p&gt;Technically, the malware is a 64-bit Go executable that performs credential harvesting from LSASS, web browsers, and cryptocurrency wallets. It employs sophisticated techniques such as direct system calls, process hollowing, and APC injection, while utilizing Discord webhooks for data exfiltration. The 'LLM-as-C2' design allows the threat to bypass traditional domain-based blocking by communicating with legitimate AI provider endpoints.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;&lt;a href="https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/" rel="noopener noreferrer"&gt;Read Full Article&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>ai</category>
      <category>malware</category>
    </item>
    <item>
      <title>EDR Evasion Stack Helps Process Injection Slip Past Defenses</title>
      <dc:creator>Mark0</dc:creator>
      <pubDate>Thu, 24 Sep 2026 04:14:54 +0000</pubDate>
      <link>https://dev.to/mark0_617b45cda9782a/edr-evasion-stack-helps-process-injection-slip-past-defenses-30bm</link>
      <guid>https://dev.to/mark0_617b45cda9782a/edr-evasion-stack-helps-process-injection-slip-past-defenses-30bm</guid>
      <description>&lt;p&gt;No article content was provided for summarization. The input indicated a failure to download content from the specified URL. Therefore, a summary of the technical article cannot be generated at this time.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.darkreading.com/endpoint-security/edr-evasion-stack-helps-process-injection-slip-past-defenses" rel="noopener noreferrer"&gt;Read Full Article&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>contenterror</category>
      <category>downloadfailed</category>
      <category>inputissue</category>
      <category>noarticle</category>
    </item>
    <item>
      <title>UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks</title>
      <dc:creator>Mark0</dc:creator>
      <pubDate>Thu, 24 Sep 2026 04:12:24 +0000</pubDate>
      <link>https://dev.to/mark0_617b45cda9782a/uae-saudi-arabia-face-onslaught-of-increasingly-complex-cyberattacks-4bcp</link>
      <guid>https://dev.to/mark0_617b45cda9782a/uae-saudi-arabia-face-onslaught-of-increasingly-complex-cyberattacks-4bcp</guid>
      <description>&lt;p&gt;⚠️ &lt;strong&gt;Region Alert: UAE/Middle East&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The United Arab Emirates and Saudi Arabia are currently facing a significant surge in cyberattacks, accounting for half of all recorded incidents in the Gulf region during the first half of 2026. While regional conflicts continue to drive hacktivism, there is a growing trend of financially motivated threats targeting the expanding digital infrastructure of these nations. Organizations in the region are experiencing nearly 2,700 attacks per week, with a shift away from simple DDoS attacks toward stealthy, complex intrusions designed for persistence and data extraction.&lt;/p&gt;

&lt;p&gt;The threat landscape is being further transformed by the integration of artificial intelligence, which allows attackers to automate vulnerability discovery and code generation. Experts warn that the timeline for autonomous cyberattacks has accelerated, making it critical for organizations to modernize legacy systems and secure IoT deployments. To counter these advanced threats, both public and private sectors must prioritize AI-driven defense strategies and reduce their overall attack surface to keep pace with the speed of modern exploits.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.darkreading.com/threat-intelligence/uae-saudi-arabia-face-onslaught-of-increasingly-sophisticated-automated-cyberattacks" rel="noopener noreferrer"&gt;Read Full Article&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>threatintelligence</category>
      <category>ai</category>
    </item>
    <item>
      <title>2026-09-14: Backdoor using ScreenConnect from malicious emailt</title>
      <dc:creator>Mark0</dc:creator>
      <pubDate>Wed, 23 Sep 2026 04:23:14 +0000</pubDate>
      <link>https://dev.to/mark0_617b45cda9782a/2026-09-14-backdoor-using-screenconnect-from-malicious-emailt-4eab</link>
      <guid>https://dev.to/mark0_617b45cda9782a/2026-09-14-backdoor-using-screenconnect-from-malicious-emailt-4eab</guid>
      <description>&lt;p&gt;This report details a phishing campaign observed on September 14, 2026, which leveraged emails impersonating the Social Security Administration (SSA). The attack chain begins with a malicious email containing a shortened link that redirects victims to a sophisticated landing page designed to mimic an official SSA statement download portal.&lt;/p&gt;

&lt;p&gt;Once on the fraudulent site, victims are prompted to download a customized ScreenConnect client installer. This executable acts as a backdoor, establishing encrypted communication with remote relay servers on port 443. The use of legitimate remote desktop software allows attackers to bypass traditional security controls and maintain persistent access to the compromised environment.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.malware-traffic-analysis.net/2026/09/14/index.html" rel="noopener noreferrer"&gt;Read Full Article&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>phishing</category>
      <category>malware</category>
    </item>
    <item>
      <title>2026-09-15: SmartApeSG ClickFix to unidentified RAT to MeshAgent</title>
      <dc:creator>Mark0</dc:creator>
      <pubDate>Wed, 23 Sep 2026 04:22:13 +0000</pubDate>
      <link>https://dev.to/mark0_617b45cda9782a/2026-09-15-smartapesg-clickfix-to-unidentified-rat-to-meshagent-222p</link>
      <guid>https://dev.to/mark0_617b45cda9782a/2026-09-15-smartapesg-clickfix-to-unidentified-rat-to-meshagent-222p</guid>
      <description>&lt;p&gt;This report details a multi-stage infection chain observed on September 15, 2026, which begins with a SmartApeSG fake verification page. The campaign employs 'ClickFix' social engineering tactics to trick users into executing malicious commands, leading to the installation of an unidentified Remote Access Trojan (RAT).&lt;/p&gt;

&lt;p&gt;Following the initial RAT infection, the attackers deploy MeshAgent, a remote management tool, to establish long-term persistence on the compromised Windows host. The article provides comprehensive forensic artifacts including PCAP files, malware samples, and screenshots of the malicious Mesh C2 server and persistence mechanisms in the AppData directory.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.malware-traffic-analysis.net/2026/09/15/index.html" rel="noopener noreferrer"&gt;Read Full Article&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>malware</category>
      <category>threatintel</category>
    </item>
    <item>
      <title>2026-09-17: Seven days of scans and probes and web traffic hitting my web server</title>
      <dc:creator>Mark0</dc:creator>
      <pubDate>Wed, 23 Sep 2026 04:21:20 +0000</pubDate>
      <link>https://dev.to/mark0_617b45cda9782a/2026-09-17-seven-days-of-scans-and-probes-and-web-traffic-hitting-my-web-server-3082</link>
      <guid>https://dev.to/mark0_617b45cda9782a/2026-09-17-seven-days-of-scans-and-probes-and-web-traffic-hitting-my-web-server-3082</guid>
      <description>&lt;p&gt;This technical entry provides a network traffic capture (PCAP) documenting seven days of continuous scans, probes, and general web traffic targeting a web server. Dated September 17, 2026, the dataset offers a practical look at the automated reconnaissance and background noise typical of internet-facing infrastructure.&lt;/p&gt;

&lt;p&gt;The associated file is provided in a password-protected zip format for security analysis. Users are instructed to check the website's "about" page for the specific password required to extract the packet capture for further investigation.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.malware-traffic-analysis.net/2026/09/17/index.html" rel="noopener noreferrer"&gt;Read Full Article&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>network</category>
      <category>forensics</category>
    </item>
    <item>
      <title>Cloud Threat Emulation on Autopilot: Context is Everything</title>
      <dc:creator>Mark0</dc:creator>
      <pubDate>Wed, 23 Sep 2026 04:20:45 +0000</pubDate>
      <link>https://dev.to/mark0_617b45cda9782a/cloud-threat-emulation-on-autopilot-context-is-everything-43dn</link>
      <guid>https://dev.to/mark0_617b45cda9782a/cloud-threat-emulation-on-autopilot-context-is-everything-43dn</guid>
      <description>&lt;p&gt;Cloud threat emulation is often misunderstood as simple API detonation. This article argues for a rigorous, plan-first methodology specifically tailored for cloud, SaaS, and identity environments. Unlike endpoint testing, cloud emulation requires meticulous modeling of identities, control-plane APIs, and victim environments to produce meaningful detection data. The methodology involves defining objectives, threat modeling, provisioning controlled labs, and verifying telemetry against real events rather than assumptions.&lt;/p&gt;

&lt;p&gt;The lifecycle of a successful emulation includes scoping (atomic, micro, or full), starting from realistic compromised identities rather than admin sessions, and ensuring complete cleanup of both provisioned and orphaned resources. Automation and AI can streamline repetitive tasks like infrastructure deployment and log verification, but human judgment remains essential for maintaining realism and assessing detection quality. This structured approach ensures that security teams move beyond simple "vibes" to data-driven detection engineering.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.elastic.co/security-labs/threat-command/cloud-threat-emulation-methodology" rel="noopener noreferrer"&gt;Read Full Article&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>cloud</category>
      <category>detectionengineering</category>
    </item>
    <item>
      <title>From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies</title>
      <dc:creator>Mark0</dc:creator>
      <pubDate>Wed, 23 Sep 2026 04:19:56 +0000</pubDate>
      <link>https://dev.to/mark0_617b45cda9782a/from-exposure-to-lockdown-how-aws-neutralizes-compromised-iam-credentials-through-managed-policies-3id9</link>
      <guid>https://dev.to/mark0_617b45cda9782a/from-exposure-to-lockdown-how-aws-neutralizes-compromised-iam-credentials-through-managed-policies-3id9</guid>
      <description>&lt;p&gt;⚠️ &lt;strong&gt;Region Alert: UAE/Middle East&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This technical deep dive explores how AWS utilizes the &lt;code&gt;AWSCompromisedKeyQuarantine&lt;/code&gt; managed policy to automatically protect IAM identities when access keys are leaked publicly. The article highlights the strategic partnership between AWS and GitHub's secret scanning program, which triggers automated quarantine actions within seconds of a credential exposure, effectively limiting the blast radius of a potential breach.&lt;/p&gt;

&lt;p&gt;Furthermore, the analysis tracks the evolution of the policy across multiple versions (V1 to V3), demonstrating how its 'Deny' statements have expanded to cover newer cloud threats like S3 data deletion and malicious Amazon Bedrock usage. Security professionals are provided with specific CloudTrail monitoring strategies and user agent strings to identify quarantine events and GitHub validity checks in their own environments for rapid incident response.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;&lt;a href="https://unit42.paloaltonetworks.com/detecting-exposed-aws-iam-credentials/" rel="noopener noreferrer"&gt;Read Full Article&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>aws</category>
      <category>automation</category>
    </item>
    <item>
      <title>Introducing CAIRN: Frontier tracking for AI-integrated malware</title>
      <dc:creator>Mark0</dc:creator>
      <pubDate>Wed, 23 Sep 2026 04:18:59 +0000</pubDate>
      <link>https://dev.to/mark0_617b45cda9782a/introducing-cairn-frontier-tracking-for-ai-integrated-malware-4do7</link>
      <guid>https://dev.to/mark0_617b45cda9782a/introducing-cairn-frontier-tracking-for-ai-integrated-malware-4do7</guid>
      <description>&lt;p&gt;Cisco Talos has unveiled CAIRN (Cognitive Artifact Intelligence Research Network), a pioneering toolkit designed to hunt and classify emerging AI-integrated malware using a "metadata-first" approach. This methodology leverages "cognitive artifacts" – unintentional markers like prompt templates, API endpoints, and jailbreak terms – that attackers leave embedded in their AI-powered tooling. By analyzing these artifacts, defenders can identify, classify, and track AI-integrated malware families and infrastructure quickly and at scale, all without needing to examine the underlying binary code.&lt;/p&gt;

&lt;p&gt;CAIRN employs a sophisticated set of analysis strategies, including 24 acquisition filters targeting various AI-related artifacts, relationship-based pivoting to map interconnected malware and infrastructure, and YARA-based triage with a three-tier ontology (Primitive AI Artifacts, Behavioral Context, Operational Families). Complementing these, semantic discovery uses embedding models to identify semantically similar samples even without direct string overlaps. This layered approach ensures comprehensive identification and classification of malware that operationalizes, targets, or exploits AI systems.&lt;/p&gt;

&lt;p&gt;Initial findings from Talos's hunts with CAIRN reveal a rapid "autonomy escalation arc" in AI-integrated malware, alongside the swift spread of AI-specific tradecraft among threat actors. The framework also highlights challenges, such as distinguishing genuine AI integration from incidental AI-related strings. Talos has open-sourced CAIRN, inviting the security community to collaborate in refining its filters, rules, and reporting to collectively keep pace with the evolving landscape of AI-enabled threats and inform future detection and intelligence strategies.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;&lt;a href="https://blog.talosintelligence.com/introducing-cairn-frontier-tracking-for-ai-integrated-malware/" rel="noopener noreferrer"&gt;Read Full Article&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>ai</category>
      <category>malware</category>
    </item>
    <item>
      <title>Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO</title>
      <dc:creator>Mark0</dc:creator>
      <pubDate>Wed, 23 Sep 2026 04:18:01 +0000</pubDate>
      <link>https://dev.to/mark0_617b45cda9782a/group-policy-hijacked-payload-ransomware-weaponizes-active-directory-gpo-4e9</link>
      <guid>https://dev.to/mark0_617b45cda9782a/group-policy-hijacked-payload-ransomware-weaponizes-active-directory-gpo-4e9</guid>
      <description>&lt;p&gt;⚠️ &lt;strong&gt;Region Alert: UAE/Middle East&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Kaspersky’s Global Emergency Response Team (GERT) recently investigated a unique ransomware incident at a manufacturing organization in the Middle East involving the PAYLOAD group. The threat actor achieved domain admin-equivalent control and utilized a malicious Group Policy Object (GPO) to distribute ransom notes, hijack wallpapers, and disable local administrator accounts across all Windows workstations. Notably, no ransomware binaries were dropped and no files were encrypted on Windows systems, representing a sophisticated move toward encryptionless extortion and living-off-the-land (LotL) tactics within Active Directory.&lt;/p&gt;

&lt;p&gt;The attack exploited the GPO mechanism as a signed, privileged distribution channel, effectively bypassing traditional endpoint detection and response tools that do not typically inspect GPO modifications. This strategy allowed the attackers to maintain persistence and cause operational disruption without triggering file- or process-based detection stacks. To combat such threats, organizations must shift focus toward directory service change auditing, SYSVOL integrity monitoring, and the implementation of tiered administrative models to protect critical Active Directory infrastructure.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;&lt;a href="https://securelist.com/tr/payload-ransomware-via-group-policy/121335/" rel="noopener noreferrer"&gt;Read Full Article&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>ransomware</category>
      <category>activedirectory</category>
    </item>
    <item>
      <title>HP Advance / Output Central: unauthenticated SYSTEM RCE and two additional vulnerabilities (CVE-2026-89082/89083/89084)</title>
      <dc:creator>Mark0</dc:creator>
      <pubDate>Wed, 23 Sep 2026 04:17:15 +0000</pubDate>
      <link>https://dev.to/mark0_617b45cda9782a/hp-advance-output-central-unauthenticated-system-rce-and-two-additional-vulnerabilities-30hn</link>
      <guid>https://dev.to/mark0_617b45cda9782a/hp-advance-output-central-unauthenticated-system-rce-and-two-additional-vulnerabilities-30hn</guid>
      <description>&lt;p&gt;Three critical and high-severity vulnerabilities have been disclosed in HP Advance and HP Output Central products, specifically affecting the Drivve SecureScan and MFPsecure components. The most severe flaw, tracked as CVE-2026-89082, is an unauthenticated archive path traversal vulnerability that enables remote code execution (RCE) with NT AUTHORITY\SYSTEM privileges. The other vulnerabilities include a local-only authorization gate bypass via forged HTTP headers (CVE-2026-89083) and unauthenticated arbitrary XML file manipulation (CVE-2026-89084).&lt;/p&gt;

&lt;p&gt;HP has released security updates for version R4 of the affected products, but version R3 remains potentially vulnerable with no official fix identified at the time of publication. Cybersecurity analysts recommend that organizations using HP AC Print &amp;amp; Scan or HP Output Central apply the latest vendor updates immediately and restrict network access to the affected service interfaces to mitigate potential exploitation risks.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;&lt;a href="https://seclists.org/fulldisclosure/2026/Sep/66" rel="noopener noreferrer"&gt;Read Full Article&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>rce</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE</title>
      <dc:creator>Mark0</dc:creator>
      <pubDate>Wed, 23 Sep 2026 04:15:24 +0000</pubDate>
      <link>https://dev.to/mark0_617b45cda9782a/sharepoint-flaw-initially-listed-as-spoofing-by-microsoft-enables-authenticated-rce-1ehc</link>
      <guid>https://dev.to/mark0_617b45cda9782a/sharepoint-flaw-initially-listed-as-spoofing-by-microsoft-enables-authenticated-rce-1ehc</guid>
      <description>&lt;p&gt;Microsoft SharePoint Server faces a critical vulnerability, CVE-2026-65660, which was initially classified as a minor spoofing flaw but has been revealed to facilitate authenticated remote code execution (RCE). Detailed research by Dinh Ho Anh Khoa of Viettel Cyber Security shows the flaw affects SharePoint Server 2016, 2019, and Subscription Edition, carrying a CVSS score of 8.8.&lt;/p&gt;

&lt;p&gt;The vulnerability exists in how SharePoint validates server-side controls against the SafeControls list. By exploiting unescaped quotes in the ToolPane component, an attacker can inject directives to load arbitrary .NET classes and trigger code execution via XamlServices.Parse() deserialization. Although no wild exploitation is currently reported, the publication of a functional in-memory webshell payload increases the risk for unpatched systems.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;&lt;a href="https://thehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html" rel="noopener noreferrer"&gt;Read Full Article&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>sharepoint</category>
      <category>rce</category>
    </item>
  </channel>
</rss>
