Article

    Cyber News / Article / Is Cyber missing the Marque?

    Is Cyber missing the Marque?
    Mi
    Mick Baccio-22 days ago

    Is Cyber missing the Marque?

    Welcome to this week’s edition of the Threat Source newsletter.

    Hello friend.

    I’mMick.

    This is my first Threat Source newsletter, so I should probably introduce myself before I start telling you all the things I think you should be paying attention to. With assistance from an unnamed LLM, my bio reads like this:

    I also have a cat named qwerty and own too many Air Jordans.

    I’ve spent most of my career somewhere in the intersection of threat intelligence, cybersecurity, government, and the people trying to make sense of all of it. These days, i spend a lot of time thinking about the decisions we make about security ripple outward, often in ways we didn't consider. Most of my ramblings will probably center around that. There will be threats. There will be intelligence. Occasionally something weird, but always something that caught my eye, and maybe worth checking out.

    Which brings us this week. I picked a hell of a week to start.

    Last Wednesday, the White House issued a presidential memorandum titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.” You should probablyread it. The memorandum directs the DOJ and DHS to establish a program that can use private companies to conduct cyber operations against transnational criminal organizations outside the United States — beyond providing intelligence and assisting in the investigation. The memorandum explicitly envisions private companies conducting cyber surveillance and cyber effects operations under the direction and delegated authority of the U.S. government.

    This is a pretty big thing.

    For years, this industry has debated where line should exist between defending a network and reaching through the wire. We’ve debated hack back, active defense, attribution, proportional response, collateral damage, and what roles private companies have in offensive cyber operations. This is absolutely not “hack back" and calling it that misses important oversight built into the memorandum.

    At the same time, let’s be clear about what we are reading. The United States is creating a mechanism for private companies to participate directly in government-authorized offensive cyber operations against systems outside the United States. There will be plenty of debate whether this is good or bad policy; I will leave that for someone else. I’m much more interested in the operational questions it creates.

    Who establishes attribution strongly enough to authorize an operation? What happens when criminal and state infrastructure overlap? What happens when infrastructure is compromised and used as an ORB? Who owns access discovered during one of these operations? How is intelligence collected by a private company handled? What happens when a company conducting these operations also provides security services in that country?

    Most importantly (in my head): What happens when another country discovers that employees of an American cybersecurity company are conducting offensive operations against infrastructure inside its borders?

    This is not an argument against disrupting cybercrime. I’m all for it. These are questions about what happens when we fundamentally change who gets to do the disrupting.

    Read the memorandum.

    Seriously.

    What we have today is a framework. In 60 days, we should have a much better idea of what this will look like in practice, so circle that on your calendar. The memorandum gives DOJ and DHS 60 days to establish the operating procedures for the program, and no operation can be approved until those procedures are in place.

    In the area between “private cybersecurity company” and “authorized participant in U.S. offensive cyber operations,” the threat model for that company and its employees just changed considerably.

    The biggest question isn’t “Does this work?”

    It’s whether we’ve fully considered what happens if it does.

    Read the memorandum.

    And in 60 days, come back and ask again.

    Talos posted two blogs onUAT-10147, a recently discovered Chinese-speaking cybercrime group that uses agentic AI to orchestrate sophisticated post-compromise operations across global web servers. UAT-10147 uses AI to generate operational playbooks, automate exploits, and develop custom malware. This includes the newly identifiedSPECTRE implant, a cross-platform backdoor featuring a custom Linux kernel rootkit and Bring Your Own Vulnerable Driver (BYOVD) capabilities designed to completely blind endpoint detection and response (EDR) solutions.

    The integration of agentic AI into offensive workflows means threat actors can now scale complex attacks with ruthless efficiency. UAT-10147 is using AI to dynamically troubleshoot, validate exploit paths, and generate custom rootkits that neutralize organizations' security stacks from the kernel level up. When an adversary can automate their reconnaissance and seamlessly blind your EDR, your window for detection shrinks drastically.

    Defenders need to prioritize patching known one-day vulnerabilities in internet-facing applications like Zimbra, Nacos, and Telerik UI. Since UAT-10147 relies heavily on stolen ASP.NET MachineKeys for ViewState deserialization attacks, locking down your key material is an absolute must. You should also block known vulnerable drivers to shut down their BYOVD attacks, and tune your network monitoring to catch the anomalous HTTP 500 errors they use to silently validate exploits. Readbothblogsfor comprehensive coverage and indicators of compromise (IOCs).

    Critical GitLab zero-click flaw poses mitigation challengesGitLab wants organizations running self-managed versions of its software development and DevOps platform to immediately upgrade to new versions released Monday, but patching is not going to eliminate the risk to enterprises and others managing projects there. (Dark Reading)

    SANS 2026 AI Survey reveals cybersecurity AI adoption outpaces governanceThe survey found that 61% of cybersecurity practitioners now use AI in red team activities, while 76% have an enterprise AI governance role. Yet more than half said formal audit frameworks are not in place, and only 27% described their AI deployment as mature production. (Industrial Cyber)

    “Unprecedented” number of Apple users received recent spyware alert, say investigatorsSeveral people publicly and privately reported receiving Apple’s spyware alerts over the weekend, after Apple sent out a new wave of notifications on Friday alerting customers in 110 countries that they had been targeted with powerful spyware.  (TechCrunch)

    Critical macOS, SharePoint, vCenter, and Microsoft IKE flaws under active exploitationThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. (The Hacker News)

    Describing attacks with crime script analysisMartin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.

    Beers with Talos: For the record, no commentKaitlin Acharya joins the crew to take us inside what happens when Talos spots something that could become a major threat, how her team tracks changes in threat actor behavior, and how intelligence moves from an investigation into detection content.

    Don't scan that! QR code phishing and cloud-native threatsWhat happens when a  QR code leads to a major security incident? In this episode, Amy sits down with Senior Incident Response Consultant Terryn Valikodath to break down a recent, high-stakes breach at an Australian medical center.

    SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507MD5: 2915b3f8b703eb744fc54c81f4a9c67fTalos Rep:https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507Example Filename: VID001.exeDetection Name: W32.9F1F11A708-100.SBX.TG**

    SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91MD5: 7bdbd180c081fa63ca94f9c22c457376Talos Rep:https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exeDetection Name: Win.Dropper.Miner::95.sbx.tg**

    SHA256: 24fa02c3f6ab460648f2c1274aefffb3e25569b5afdcb0d4a5918c7c742780f1MD5: 8ef476fa2322d063896830f85bac2e7fTalos Rep:https://talosintelligence.com/talos_file_reputation?s=24fa02c3f6ab460648f2c1274aefffb3e25569b5afdcb0d4a5918c7c742780f1Example Filename: WebCompanion.exeDetection Name: W32.24FA02C3F6-95.SBX.TG

    SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0aTalos Rep:https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59Example Filename: tmp00055df5.dllDetection Name: Auto.90B145.282358.in02

    SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2MD5: 9a47c4d379998ade2f8f99e23a630c06Talos Rep:https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2Example Filename: WCInstaller_NonAdmin.exeDetection Name: W32.C4DD71E347-95.SBX.TG

    From engaging with cybercriminals to surviving a live Flamin’ Hot Cheetos taste test, Hazel reflects on the latest Beers with Talos with Azim, where they cover the full spectrum of what it takes to gather threat intel.

    In his first Threat Source newsletter, David Bianco explores the critical need for operational sovereignty in customizing AI guardrails to maintain the defender’s advantage.

    In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers.

    Original source