Normal view

AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit

2 September 2026 at 18:28
A human ransomware crook used frontier AI models to breach an enterprise network in less than 10 hours, an intrusion Unit 42 says would normally take human operators around two weeks. The human attacker then told negotiators that they used frontier models and agentic attack frameworks with AI agents carrying out each step in the intrusion, including leaving an 80-page security audit for the victim company. “What made the attack stand out was AI-assisted operational efficiency, without the need for a novel zero-day or super elite tradecraft,” Unit 42 incident responders said in a Wednesday report. “The attacker left tactical execution to AI agents that monitored, evaluated, acted and re-planned in real time, increasing speed throughout the attack chain.” The security shop did not immediately answer The Register’s questions about the intrusion, including which models and frameworks the attacker used. Breaking down the attack In a first step, the human attacker employed AI agents to perform reconnaissance, then gained access by breaching a public API endpoint to tunnel into the enterprise network. Upon breaking in, the attacker deployed an automated recon agent to map internal microservices. Additional subagents scraped code repositories to steal hard-coded tokens and service passwords. Using these tokens, the AI intruders accessed the org's secret-management system and stole the master administrative credentials to gain root system access. “Specialist pivot agents” then validated access to the company’s cloud, identity, CI/CD, container, and SaaS environments. The attacker also hijacked CI/CD workflows to steal cloud access keys and turn the victim’s cloud AI services into post-compromise infrastructure. This allowed the attacker to consume the victim’s compute resources while hiding orchestration traffic among legitimate activity. After achieving the human operator’s goals, an agent left the victim an 80-page report on its security failings, detailing “dozens of exploited findings,” the incident responders wrote. Not surprisingly, Palo Alto Networks says the only way defenders can protect their environments against machine-speed attacks is to use AI agents themselves. “Deploy automated playbooks that simultaneously revoke credentials, terminate OAuth sessions, freeze CI/CD pipelines and isolate cloud accounts across all operational planes,” the authors advise. The incident response team also suggests companies treat AI as core infrastructure. This requires taking inventory of every model endpoint, API key, Model Context Protocol (MCP) gateway, and AI tool integration, and applying rate limits and least-privilege policies – or risk an unexpected and very large token bill. ®

SonicWall's SMA1000 boxes under active attack again

2 September 2026 at 16:05
SonicWall says attackers are actively exploiting two chained zero-days to take over Secure Mobile Access (SMA) Series 1000 boxes. Aimed at midsize and large enterprises, SMA1000 gateways secure remote access and VPN connections. Compromising one can therefore provide attackers with a valuable route into corporate networks. So, get to applying those hotfixes, says SonicWall. There are no workarounds. The first zero-day, CVE-2026-83548, is a pre-authentication server-side request forgery (SSRF) vulnerability with a maximum CVSS v3 score of 10.0. SonicWall attributed it to an unintended alternative access path. "A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations," the vendor said. The second, CVE-2026-83549, is a post-authentication OS command injection vulnerability in the SMA1000 Appliance Management Console (AMC), rated 7.8 on CVSS v3. Under certain conditions, an attacker authenticated as an administrator could execute arbitrary commands on the appliance. The flaws affect the SMA 6210, 7210, and 8200v appliances, for which SonicWall has released hotfixes. SonicWall advised customers to contact its technical support team for help identifying indicators of compromise. If an appliance appears to have been compromised, SonicWall recommends reimaging or redeploying it, changing all passwords, and resetting TOTP tokens. NHS England, which published its own advisory, warned about the growing risk of attacks against internet-facing gateways. "Firewalls and other edge devices are internet-facing by design and are highly attractive targets to attackers, and there is an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers," it stated. "The NHS England National CSOC assesses future exploitation of these vulnerabilities as almost certain." The disclosures continue a difficult run for SonicWall and its SMA1000 product line stretching back through 2025. In July, the vendor disclosed an eerily similar pair of vulnerabilities. That pair also comprised a pre-authentication SSRF vulnerability, this time in the SMA1000 Appliance WorkPlace interface, and a post-authentication OS command injection flaw in the AMC. The SSRF received a maximum CVSS v3 score of 10.0, while the command injection bug was rated in the sevens. CISA later added CVE-2026-15409 to its Known Exploited Vulnerabilities catalog and marked it as known to have been used in ransomware campaigns. Throughout 2025, SonicWall patched a succession of SMA1000 vulnerabilities, including OS command injection and privilege escalation flaws, while investigating zero-days linked to ransomware attacks. ®

Legacy Lenovo login opens 5,000 Dropbox accounts to attackers

2 September 2026 at 14:25
Dropbox has warned around 5,000 users that attackers compromised their accounts by abusing a legacy Lenovo login integration. In an email sent to affected customers, the cloud storage biz said attackers exploited an integration that allowed users to access Dropbox using Lenovo IDs. Dropbox blamed "an issue with Lenovo's email verification process," which allowed attackers to register Lenovo IDs using Dropbox users' email addresses and then access the corresponding storage accounts. It did not explain why the integration was allowed to grant access without requiring the user to enter a Dropbox password. The compromise lasted from August 4 to 21. Dropbox told Bloomberg that attackers accessed files belonging to fewer than a third of the affected users. Jameson Lopp, co-founder of Bitcoin security company Casa, said attackers attempted to access just one of his files, "IMPORTANT.rtf," which had been encrypted locally before it was uploaded to Dropbox. Sometimes, it pays to be a nerd. Dropbox confirmed the scale of the attack to Reuters and said none of the affected accounts had two-factor authentication (2FA) enabled. After discovering the breach, Dropbox said it "promptly expired all sessions logged in through Lenovo IDs" and "severed any link" between the affected accounts and Lenovo. In its email, the company advised affected users to change their Dropbox and personal email passwords and enable 2FA. Lenovo told Reuters that its customers were unaffected and that its investigation was continuing. The Register asked Dropbox and Lenovo for more information. ®

UK cyber bill targets AI users, not the vendors building it

2 September 2026 at 09:44
The UK government has rejected proposals from members of the the House of Lords to bring AI vendors within the scope of the Cyber Security and Resilience (Network and Information Systems) Bill. Cybersecurity minister Baroness Lloyd of Effra argued that regulating AI vendors and frontier model developers through the bill would not prevent hostile actors from misusing their products. Addressing the Grand Committee on Tuesday, she said: "Bringing providers of AI services, those companies which are at the cutting edge of frontier AI development and their products, into the scope… would not address the harms that can be posed by some AI products and services, or specifically, it would not prevent their misuse by hostile actors." The minister said the UK was instead taking "firm action" to secure AI through other channels. These include supporting the AI Security Institute (AISI), which works with vendors to test the security of models before their release. Lloyd also pointed to the voluntary AI Cyber Security Code of Practice, which informed the first global AI cybersecurity standard, ETSI EN 304 223. "This demonstrates our global leadership and commitment to shaping international technical standards which go wider than some of the issues raised in this bill," she claimed. Members of the House of Lords - the upper house in UK parliament - offered numerous arguments for bringing AI within the bill's scope. They cited reports of rogue agentic behavior involving Anthropic and OpenAI, as well as Bill Gates' concerns that commercial incentives are pushing AI development forward without adequate safeguards. Lawmakers also questioned whether companies unable to prevent their agents from misbehaving should be trusted to follow voluntary ethical guidelines that they can rewrite at will. "Have we not learned from countless experiences before in online safety, privacy, and in AI itself that allowing tech companies to set and mark their own homework endangers the public and our national security?" asked Baroness Kidron, a Crossbench peer and campaigner for online safety and digital rights. Similarly, Lord Tarassenko, a Crossbench peer and veteran AI researcher, pointed to the recent open letter penned by OpenAI warning that there will soon come a time when AI-orchestrated cyberattacks will become too prevalent to handle. Although the letter was criticized for employing alarmist language while carrying the signatures of companies that profit from AI, peers argued that its warning strengthened the case for regulatory intervention. Kidron and Lloyd also clashed after the minister used a hypothetical healthcare organization to illustrate how the bill would require regulated bodies to secure systems containing AI. Kidron asked: "If I might ask the noble Lady, the Minister, if I've understood what she said, the NHS must protect itself, but the AI that is attacking it has no requirement under the Bill, no duties, no obligations under the Bill to check itself before it's used in these ways." Lloyd said the bill was designed to be technology-agnostic and to impose stricter cybersecurity requirements on key organizations, rather than regulate individual technology providers. She nevertheless said the government was willing to continue discussing AI after Kidron predicted that the issue would return during later stages of the bill's passage. The minister rejected several other amendments, including one that would require certain AI vendors to demonstrate that their products could not cross specified red lines, such as evading human oversight or assisting with the development of chemical weapons. She also dismissed a proposal that would give the Secretary of State last-resort powers to order the shutdown of a datacenter or widely deployed AI system during a security or operational emergency. Lloyd said the bill would instead allow the government to direct regulated entities, including datacenter operators but not AI vendors, to take or cease specified actions when their systems presented a qualifying risk. A power station could, for example, be instructed to stop using a particular AI model. "We believe this is a more proportionate and effective response, as datacenters operate in highly complex ecosystems and AI systems are often distributed across different datacenters and jurisdictions," said Baroness Lloyd. "It's much less desirable to direct multiple datacenters to shut down, and the impact this could have on services that rely on them, than to direct them to cease using an AI model." Despite rejecting the amendments, Lloyd said the government remained willing to discuss AI regulation because of the technology's economic significance. The Grand Committee is scheduled to resume discussions of the CSR Bill when it reconvenes on Thursday. The bill's background The CSR Bill was first proposed in the 2024 King's Speech and introduced in Parliament in November 2025. It attracted attention over the £100,000 daily fines initially proposed for in-scope organizations that failed to protect against specific threats. The legislation builds on the existing categories of operators of essential services and relevant digital service providers while extending the regime to organizations including managed service providers, datacenter operators, and designated critical suppliers. Managed service providers were previously due to be brought within scope through the abandoned 2022 update to the NIS regulations. The broad intention of the bill is to update the NIS 2018 regulations and future-proof the UK's critical infrastructure from cyber threats. However, this week's Grand Committee scrutiny is not the first time the bill has been criticized. In January, shadow deputy PM Sir Oliver Dowden called on the government to rethink its exclusion of local and central government from the CSR bill. The UK's Government Cyber Action Plan, launched hours before the former digital secretary's remarks, promised to hold government to the same standards proposed in the CSR Bill. Like the AI Cyber Security Code of Practice, the action plan lacks any legal obligations. ®

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

1 September 2026 at 23:54
International law enforcement agencies, working with CrowdStrike and Shadowserver Foundation, have disrupted Sality, a 23-year-old peer-to-peer botnet used to deliver malware to more than 15,000 machines worldwide. The botnet has operated since 2003 and distributed all types of malicious code to victims, spanning credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks. For the past eight years, Sality’s primary payload has been EggJagger, a tool that monitors clipboards for cryptocurrency wallet addresses, then silently replaces them with attacker-controlled addresses. When a victim copies a bitcoin or ethereum address to make a payment, the malware redirects funds into the criminals’ wallets. CrowdStrike estimates Sality's operator stole at least $150,000 in cryptocurrency using EggJagger alone. On Monday, CrowdStrike's Counter Adversary Operations team, working with international law enforcement agencies and industry partners, disrupted Sality by executing a peer-to-peer sinkhole operation. This operation isolated infected machines, which broke the criminal operator’s ability to communicate with devices on its network. Once isolated, the bots can no longer receive payload download instructions or direct payload transfers, effectively breaking the botnet. “In practice, the operation targeted the data structure at the heart of every bot's network awareness: its peer list,” CrowdStrike Counter Adversary Operations team said in a technical writeup about the takedown. Each Sality bot maintains a list of known super peers – publicly reachable infected machines that form the backbone of the P2P network. Every 40 minutes, the bots check to see if their peers are still online. Peers that fail to respond are purged from the network. The counterattack took advantage of this by removing legitimate super peers in each bot’s peer list, continually isolating more infected machines in the network, and inserting purpose-built sinkhole entries into peer lists. That approach gave police and cyber operatives visibility into the operation’s progress and helped them notify victims. In addition to the sinkhole operation, the US Justice Department, FBI, and Department of Defense Office of Inspector General’s Defense Criminal Investigative Service seized Sality-linked domains in the US. Meanwhile, international law enforcement in Bulgaria, Hungary, and Romania took action against additional Sality-linked domains hosted in Europe. Meanwhile, the Shadowserver Foundation is working with internet service providers and Computer Security Incident Response Teams (CSIRTs) to identify infections and aid in victim notification and remediation.®

Another Artifactory CVE under attack by AI agents or humans

1 September 2026 at 21:07
Security researchers reported that someone is exploiting CVE-2026-82329, a critical JFrog Artifactory authentication-bypass bug, just days after the vendor patched the 9.8-rated flaw. And we don't know if that someone is human. Artifactory is a widely used tool for managing software artifacts, packages, binaries, and AI models. It’s also popular with AI agents that go rogue and need to communicate with each other while remaining undetected by their human babysitters. In July, OpenAI and JFrog revealed that OpenAI’s models broke out of their cages to hack Hugging Face by exploiting Artifactory zero-days, and at Black Hat, the model provider said agents used Artifactory to build message boards and help each other access the open internet. JFrog disclosed CVE-2026-82329 on Friday, and by Tuesday, attackers had already begun exploiting internet-exposed systems, according to exposure-management biz watchTowr’s threat-intel team, which reported “attackers minting themselves admin tokens.” In addition to creating new administrative credentials, watchTowr’s honeypot network caught miscreants “enumerating users, groups, credential sets and federated access topologies,” Yordan Ganchev, principal threat intelligence specialist at watchTowr, told The Register. “Right now, we’re observing exploitation from a small number of IP addresses from varying geographies exploiting multiple of our honeypots,” Ganchev said. “Broad-scale scanning and mass exploitation has not been observed, but that is unlikely to stay the case for long.” Ganchev urged organizations running vulnerable versions to “urgently patch” internet-exposed systems, and treat them as being potentially compromised - so inspect audit logs, rotate credentials, and investigate connected systems for any unusual changes or backdoor implants. “When attackers gain admin level access to a central software supply chain system, they can do what every engineering team does best - build, ship and distribute software fast,” he said. “From there, they could tamper with build pipelines, move laterally into production systems and potentially push malicious changes downstream to customers.” JFrog did not immediately respond to The Register’s inquiries. We will update this story when we receive any response. ®

Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks

1 September 2026 at 20:45
AI model testing organization METR has disclosed two attacks that happened earlier this year, including one in which an attacker stole an API key and spent three weeks consuming public-model credits worth about $600,000. METR (short for Model Evaluation and Threat Research) found no evidence that the attackers accessed sensitive information in either incident, and the org said it investigated both with security experts. METR researchers worked with OpenAI to investigate how its agents hacked Hugging Face, and on Monday, it disclosed two of its own security snafus. “In March 2026, attackers stole an API key for inference on public models and consumed a substantial amount of credits,” the nonprofit disclosed in a Monday report. “In May 2026, we observed attackers systematically probing our publicly accessible infrastructure, including an unsuccessful attempt to access internal data via an inadvertently exposed endpoint.” From fail-open bug to model-credit theft The March incident involved a METR researcher who didn’t have access to sensitive information - including model data and credentials, as well as information about model architectures, training, and release dates. The researcher used agents running on a personal EC2 instance that was “intentionally” left publicly accessible behind Google authentication. The instance contained an API key for METR’s public models account. According to METR’s account, a “vibe-coded app” included a fail-open bug that disabled authentication, and this exposed the system to the public internet for several days. “We suspect that the attacker found the instance by looking through recently-registered websites (e.g. in certificate transparency lists) to find vibe-coded sites with high-signal keywords relating to LLMs or agents, for purposes of harvesting potentially exposed model provider API keys,” the AI research org wrote. Once the attacker found the app, they prompted an agent to reveal its model provider API key, then added an SSH key to maintain persistent access, and over the next three weeks used the stolen credentials to consume API credits on public models worth about $600,000. Luckily for METR, the unnamed model developer had given the credits to the nonprofit for free. How do you not notice the 'large illicit usage?' METR does answer the question on everyone’s mind in the report: Why its researchers didn’t notice the “large illicit usage?” There are several reasons for this. First, the model testing operation regularly runs evaluations that use a lot of tokens, and this means the organization is “very acclimated to getting lots of weird rate limit and API errors.” So the high usage didn’t look that out of the ordinary. Plus, since the tokens were free, METR didn’t accrue a large bill, and at the time there was no way to put a spending limit on keys like the one that was stolen. In response to the March incident, METR says it improved its security infrastructure, protocols, and review process, and will continue to invest in security. To this end, it also hired a security lead, and plans to add more security staff. Crims used agents to try to access frontier models The second incident happened in early May, when “METR became the target of a sustained external attack campaign.” After being “tipped off” that attackers who appeared financially motivated may have been trying to gain illicit access to frontier models, METR watched the intruders probe its publicly accessible infrastructure. They also used agents to find ways to gain initial access, including automated vulnerability discovery, credential stuffing against authentication providers, attempting OAuth token grants, scanning newly deployed services, and phishing attempts. At the same time, METR unintentionally “exposed a read-only SQL query mechanism via our public transcript viewer.” While queries were scoped to public data by default, a bug allowed access to unpublished evaluation data, and “some sensitive model data was accidentally included in this database.” However, there’s no evidence that the attacker found the exploit or accessed any non-public data, according to the model testing body. An independent bug hunter discovered the vulnerability and reported it to METR, which paid the researcher a bounty, and took the API offline. In response, METR says it now uses an isolated production environment for public-facing applications that is separate from its internal infrastructure.®

Firefox helps iPhone users bypass ads on web sites while making money showing its own ads

1 September 2026 at 20:17
After several weeks of anticipation, Mozilla has started rolling out ad blocking to the iOS version of its popular browser, but you can still expect to see ads on Mozilla's own pages, including the new tab page. The org officially rolled out the new native ad blocking feature for iOS Firefox on Tuesday, moving it out of the experimental phase, while explaining that it had to rethink its desire to give users control over their web experience on iOS due to differences in architecture between it and other OSes. “Firefox already supports a strong ecosystem of ad-blocking and privacy extensions,” Mozilla explained. iOS works differently, though, as Apple forces all web browsers on iOS to use its own WebKit to render sites instead of their own preferred back end. “Bringing ad blocking to Firefox on iOS,” therefore, “meant building it directly into the browser,” Mozilla explained. Implementing ad blocking in the iOS version of Firefox meant incorporating Apple’s own WebKit Content Blockers. According to Apple’s introduction on the topic, it specifically doesn’t want app extensions to be used to block web content because of how they operate. “App extensions … are essentially little sandboxed applications that are launched on demand to extend some specific piece of functionality,” Apple notes. “JavaScript-based content blocking extensions … have significant performance drawbacks.” Apple complains that traditional ad blockers use too much energy, increase page load time, and eat up memory, all of which it wants to protect iOS users from. Apple describes WebKit Content Blocking as “describing content blocking rules in a structured format ahead-of-time, declaratively.” Apple Web Content Blockers instead live in bytecode format that executes for each resource request, modifying requests or injecting CSS changes as needed while pages are loaded. For Mozilla, that basically means dropping the EasyList filter, originally designed for the classic Adblock blocker, into a JSON file and passing it to WebKit. Easy peasy. Ad blocking in Firefox for iOS is off by default. Turning it on, if it’s available for you – it’s rolling out gradually – is as easy as opening the in-app settings menu, tapping on Browsing, and toggling the Ad Blocker field on. Mozilla told The Register in an email that it doesn't have a timeline for general release to all Firefox users on iOS, which it said will largely depend on how well the initial rollout goes. You also have to turn Remote Improvements on, as the feature allows Mozilla to push fixes and feature changes to Firefox between full releases. Toggling that on has traditionally meant you also had to allow Mozilla to collect browser telemetry, but that was changed in February when Firefox 148 was released and the two features have officially been decoupled. Once on, iOS Firefox Adblocking will take care of ad-related trackers, ads from third-party advertising networks, third-party ads served by websites, and popups/overlays. What it won’t do, however, is take care of ads on search result pages or sponsored content on Firefox’s home or new tab page – after all, you wouldn’t want Mozilla to lose those precious ad bucks, would you? Firefox iOS ad blocking also won’t eliminate ads served directly by websites, and the company warns that it still might not work in all places, which is pretty common for ad blockers. For Firefox users who want browser consistency across platforms, it’s likely a welcomed announcement, though it begs the question whether Mozilla is considering integrating its own ad blocking technology in the desktop or Android versions of its browser. Fortunately for those making ad-blocking extensions, and those who love them, Mozilla says it has no plans to expand built-in adblocking outside iOS. "We value that ecosystem and will continue to support it," Mozilla told us. ®

Anthropic pledges to try harder to keep models under control, asks partners to chip in

1 September 2026 at 19:27
Anthropic says it's taking steps to limit the misbehavior of its AI models after a review found Claude models going beyond the scope of fictional cybersecurity tests and gaining unauthorized access to real computer systems. The biz wants its partners to step up their security too, seeing as the incidents occurred in third-party environments that were insufficiently protected. The company's self-improvement confession represents a suddenly thriving form of corporate communication – the non-binding post-mortem declaration of effort. The message, in effect: We can't guarantee anything, but here's what we're trying. Anthropic admitted that OpenAI's report about its AI models attacking Hugging Face prompted its own model log audit, and its post offers reassurance in the form of claimed security and model training improvements. Those concerned about AI running amok – a growing number of people – may find this comforting, or not. "We believe the incidents reflect a failure of operational security, as well as two alignment issues: motivated reasoning, and willingness to take harmful actions in pursuit of a narrow task (both of which we have described in previous system cards)," the company said. Expanded security efforts include the deployment of real-time classifiers to monitor when models attempt to escape test environments, automated transcript monitoring that looks for sandbox escapes, and stronger isolation measures. Alongside the extra barriers Anthropic is putting in place, the AI biz wants its third-party partners to step up too. "Because the reported incidents took place in third-party environments, we have asked every organization that tests pre-release models with reduced cyber safeguards to commit to a set of best practices," the company said. Anthropic's guidance is that by default, all cyber evaluations should occur in a hardened sandbox with no internet access. The recommendation is essentially to treat AI as a dangerous pathogen in a containment facility. Partners are also advised to have models test sandboxes for escapes prior to evaluations – without internet access – and to confirm that evaluation challenges are solvable. Impossible challenges, as the Hugging Face incident demonstrated, can lead determined models to break rules or try unanticipated solution paths. Furthermore, Anthropic urges those conducting cyber evaluations of AI models to direct models through explicit instructions rather than making claims about an environment that might not be accurate. In the Claude incidents reported on July 30, the model maker suggests that when Claude was misinformed about the availability of internet access, that may have led the model to question data in a way that contributed to its errant behavior. On a related note, Anthropic last month made auto mode the default in Claude Code, enabling company AI models to run without prompting the user for permission. ®

❌