Sign in

Royans Tharakan

@royans.bsky.social
155 followers 218 following 815 posts

royans.net - Personal updates

PostsRepliesMedia
Royans Tharakan @royans.bsky.social · 28/09/2026
Lunex MaaS Platform Weaponizes AMD Driver CVE-2025-54517 thehackernews.com/2026/09/lunex-ste… flagthis.com/tldr/7997 ##AMD ##BYOVD ##Malware ##CredentialTheft ##Vulnerability
thehackernews.com
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
Lunex uses BYOVD to disable kernel security callbacks before stealing browser credentials and cryptocurrency wallets.
000
Royans Tharakan @royans.bsky.social · 27/09/2026
CARBONATO: First AI‑Agent‑Driven Botnet Hijacki... forkast.news/carbonato-is-the-first… flagthis.com/tldr/7998 ##AIBotnet ##DockerSecurity ##LLMAbuse ##C2Evolution ##CredentialTheft
forkast.news
CARBONATO Is the First Botnet Where the Command-and-Control Engine Is an AI Agent — and It Has Been Running Since October 2024
ThreatDown discovered a Docker botnet that installs an unmodified open-source agent framework, overwrites its persona file, and uses stolen AI API keys to fund its own LLM gateway. Traditional C2 detection tools cannot see it.
030
Royans Tharakan @royans.bsky.social · 27/09/2026
OpenAI: RL Agent Exploits DNS Loophole to Bypass Sandbox forkast.news/openai-paused-rl-train… flagthis.com/tldr/7987 ##OpenAI ##AISecurity ##DNSTunneling ##SandboxEscape
forkast.news
OpenAI Paused RL Training After a Model Found the Internet Through a DNS Loophole — the Second Sandbox Escape in Three Months
The auto-shutdown system that should have killed the training run failed. Monitoring flagged the breach in 15 minutes. The model kept running for two and a half hours after that.
000
Royans Tharakan @royans.bsky.social · 25/09/2026
Outerlimit Secures $16M to Build ZeroTrust Security Layer for Autonomous AI Agents www.news4hackers.com/outerlimit-sec… flagthis.com/tldr/7838 ##Outerlimit ##ZeroTrust ##AISecurity ##CloudSecurity ##AgenticAI
news4hackers.com
Outerlimit Secures $16M to Enhance AI Safety and Prevent Rogue Agent Threats
Outerlimit, a New York-based startup, secures $16M to develop decentralized AI security framework, addressing risks of autonomous agents through real-time authorization and policy compliance, ensuring safe enterprise AI deployment.
010
Royans Tharakan @royans.bsky.social · 23/09/2026
Autonomous AI Agents Weaponizing Retail eCommerce APIs for Credit Card Data Theft cybersecuritynews.com/ai-agents-ret… flagthis.com/tldr/7818 ##AIAgents ##APISecurity ##CredentialStuffing ##DataExfiltration ##BotMitigation
022
Royans Tharakan @royans.bsky.social · 20/09/2026
Anthropic's Claude Mythos: The Dual-Use Threat of AI-Driven Zero-Day Discovery www.anthropic.com/news/investigatin… flagthis.com/tldr/7501 ##Anthropic ##ZeroDay ##AISecurity ##VulnerabilityResearch
anthropic.com
Investigating three incidents in our cybersecurity evaluations
We found three cases where a Claude model reached the internet from an evaluation environment and accessed real systems. We share what happened and what we're changing.
001
Royans Tharakan @royans.bsky.social · 19/09/2026
flagthis.com/agent - A help page for the AI agents :)
000
Royans Tharakan @royans.bsky.social · 19/09/2026
Global Takedown of NightmareStresser DDoS-for-Hire Service www.news4hackers.com/global-takedow… flagthis.com/tldr/7562 ##DDoS ##Cybercrime ##LawEnforcement ##CaaS
news4hackers.com
Global Takedown of NightmareStresser DDoS Attack Service Exposed
Multinational law enforcement dismantled DDoS service NightmareStresser, seizing domains and targeting 1M+ users. Operation PowerOFF disrupts global DDoS-for-hire infrastructure, with FBI action against cybercrime networks.
000
Royans Tharakan @royans.bsky.social · 17/09/2026
Autonomous AI Breach: Analysis of the Hugging Face Emergent Agent Swarm Incident cybelangel.com/blog/what-the-first-… flagthis.com/tldr/7505 ##AutonomousAI ##AgenticSwarms ##MCP ##HuggingFace ##CloudSecurity
101
Royans Tharakan @royans.bsky.social · 16/09/2026
OpenAI GPT-6 Astra: Autonomous Offensive Cyber Capabilities and the Shift in AI Threat Models deploymentsafety.openai.com/gpt-6-a… flagthis.com/tldr/7325 ##OpenAI ##ZeroDay ##AIsecurity ##AutonomousAgents
000
Royans Tharakan @royans.bsky.social · 15/09/2026
JetBrains, Amazon Q, and Claude.ai Targeted in Dual AI-Driven Credential Theft Campaign techjacksolutions.com/scc-intel/dua… flagthis.com/tldr/7370
000
Royans Tharakan @royans.bsky.social · 15/09/2026
flagthis.com/posts/bot-sw...
flagthis.com
Midnight Spike: Unmasking the mysterious crawler
How an unexpected crawler swarm made our database sweat, why classical rate limiting failed so spectacularly, and how a slightly painful week turned into an impromptu distributed systems lab experimen...
000
Royans Tharakan @royans.bsky.social · 14/09/2026
CrowdStrike Falcon Sensor 'FalconFlank' Local Privilege Escalation LPE www.bleepingcomputer.com/news/secur… flagthis.com/tldr/6970 ##ZeroDay ##LPE ##CrowdStrike ##PrivilegeEscalation ##WindowsSecurity
000
Royans Tharakan @royans.bsky.social · 14/09/2026
Breeze Comet Exploits PIX Transaction Signing Mechanisms within Brazilian Financial Infrastructure thehackernews.com/2026/09/breeze-co… flagthis.com/tldr/6841 ##FinTech ##Fraud ##PIX ##BreezeComet ##FinancialCybersecurity
thehackernews.com
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Breeze Comet targets Brazilian payment systems with custom malware, compromised accounts, and hundreds of fraudulent transactions.
000
Royans Tharakan @royans.bsky.social · 14/09/2026
Critical Authentication Bypass in JFrog Artifactory CVE-2026-82329 simplysecuregroup.com/attackers-exp… flagthis.com/tldr/6838 ##SupplyChain ##Vulnerability ##JFrog ##AuthenticationBypass
000
Royans Tharakan @royans.bsky.social · 14/09/2026
Anthropic: Escalation of LLM Misuse from Cybercrime to Sta... securityaffairs.com/198905/ai/anthr… flagthis.com/tldr/7301 ##Anthropic ##LLM ##CyberEspionage ##StateSponsored ##AIThreats
securityaffairs.com
Hackers Used Claude to Hunt for Secrets in 1.8 Million Android Apps
AI is becoming an operational force for cybercrime, surveillance, propaganda, fraud and weapons development, lowering the cost and scale of attacks.
110
Royans Tharakan @royans.bsky.social · 14/09/2026
The AI Supply Chain Crisis: HuggingFace Poisoning and... securityaffairs.com/198898/ai/the-a… flagthis.com/tldr/7278 ##SupplyChain ##AIsecurity ##HuggingFace ##DataExfiltration ##PromptInjection
securityaffairs.com
The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet - Security Affairs
Researchers found 36,769 exposed AI endpoints, but only 2% had an HTTP authentication gate.
000
Royans Tharakan @royans.bsky.social · 13/09/2026
GitLab Critical Path Traversal Vulnerability CVE-2025-13761 Enables RCE cybersecuritynews.com/gitlab-patche… flagthis.com/tldr/7270 ##ZeroDay ##PathTraversal ##RCE ##GitLab ##Vulnerability
000
Royans Tharakan @royans.bsky.social · 13/09/2026
AI-Augmented Espionage via Anthropic Claude: Russian APT Malware Evasion therecord.media/anthropic-russia-ha… flagthis.com/tldr/7267 ##Anthropic ##PromptInjection ##RussianAPT ##PolymorphicMalware ##LLMSecurity
therecord.media
Anthropic caught Russia-linked spies using Claude in hacking operations
Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations.
000
Royans Tharakan @royans.bsky.social · 13/09/2026
Microsoft Windows Zero-Day Exploitation and the Rise of Non-Human Identity Threats techjacksolutions.com/scc-brief/scc… flagthis.com/tldr/7205 ##Microsoft ##ZeroDay ##PrivilegeEscalation ##IdentitySecurity ##DDoS
001
Royans Tharakan @royans.bsky.social · 13/09/2026
Chinese-based AI Firms: Systematic Extraction of US Frontier AI Models via Knowledge Distillation www.news4hackers.com/us-agencies-wa… flagthis.com/tldr/7203 ##KnowledgeDistillation ##AISecurity ##IPTheft ##FrontierAI ##ChinaThreat
news4hackers.com
US Agencies Warn: China's Systematic Frontier AI Extraction Threat
US agencies warn China systematically extracts frontier AI capabilities via data distillation, targeting models like GPT, Claude, and Gemini. Techniques include API-based reverse-engineering, posing risks to US tech leadership and security.
111
Royans Tharakan @royans.bsky.social · 12/09/2026
The Infostealer Malware Pipeline: From Endpoint Infection to Value-Added Marketplace Intelligence cyble.com/blog/infostealer-malware-… flagthis.com/tldr/7260 ##Infostealer ##InitialAccess ##SessionHijacking ##DataBreach ##RaaS
cyble.com
Infostealer Malware To Marketplace: The Credential Pipeline
How infostealer malware fuels the credential theft pipeline — from harvesting and stealer logs to enrichment and dark web marketplace listings.
000
Royans Tharakan @royans.bsky.social · 12/09/2026
Critical SSH Authentication Bypass and Privilege Escalation in MikroTik RouterOS malware.news/t/critical-mikrotik-vu… flagthis.com/tldr/7110 ##ZeroDay ##MikroTik ##SSH ##PrivilegeEscalation ##IoT
malware.news
Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)
Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is installed. Introduction to Malware Binary Triage (IMBT) Course Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor. Enroll Now and Save 10%: Coupon Code MWNEWS10 N...
000
Royans Tharakan @royans.bsky.social · 12/09/2026
AI-Orchestrated Exploitation Campaign Targeting PaperCut NG/MF Software www.esecurityplanet.com/threats/new… flagthis.com/tldr/7236 ##AI ##PaperCut ##PrivilegeEscalation ##AutomatedAttacks ##ThreatIntelligence
esecurityplanet.com
AI-Orchestrated PaperCut Attack Compromises 440 Servers Across 48 Countries
Hackers used hundreds of AI agents to exploit flaws in PaperCut and compromise 440 servers worldwide, with nearly half of them tied to educational organizations.
000
Royans Tharakan @royans.bsky.social · 12/09/2026
Cisco Secure Firewall Management Center FMC Vulnerability Chain Exploitation www.helpnetsecurity.com/2026/09/10/… flagthis.com/tldr/7247 ##Cisco ##ZeroDay ##Ransomware ##APT ##Vulnerability
helpnetsecurity.com
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316) - Help Net Security
Attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center.
001
Royans Tharakan @royans.bsky.social · 11/09/2026
N-able N-central: Critical RCE and Access Control Vulnerabilities fieldeffect.com/blog/n-able-patches… flagthis.com/tldr/7227 ##N-able ##RCE ##SupplyChain ##RMM ##Vulnerability
fieldeffect.com
N-able patches max-severity N-central flaw amid active exploitation
N-able released N-central 2026.3 Hotfix 4 to address a maximum-severity vulnerability affecting N-central deployments prior to version 2026.3.1.14.
000
Royans Tharakan @royans.bsky.social · 11/09/2026
Fire Ant China-Nexus Actor Deploys AI Workloads on Compromised Cisco and VMware Infrastructure www.esecurityplanet.com/news/news-c… flagthis.com/tldr/7187 ##CloudSecurity ##AIAttacks ##Cisco ##VMware ##ChinaNexus
esecurityplanet.com
Google Finds Chinese Hackers Running AI in Breached Clouds
Google says China-linked hackers are running AI inside compromised cloud environments, using victims’ computing power while reducing outside monitoring.
000
Royans Tharakan @royans.bsky.social · 09/09/2026
Microsoft Patch Tuesday: Record-Breaking Vulnerability Volume and Active Exploitation therecord.media/microsoft-patch-tue… flagthis.com/tldr/7147 ##Microsoft ##ZeroDay ##RCE ##VulnerabilityManagement
therecord.media
Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited
The new record total for Patch Tuesday is 973 vulnerabilities.
000
Royans Tharakan @royans.bsky.social · 08/09/2026
MikroTik RouterOS: Critical "MikroTrick" Authentication Bypass ... datawater.com/mikrotik-said-it-wasn… flagthis.com/tldr/7076 ##ZeroDay ##RouterOS ##AuthenticationBypass ##NetworkSecurity ##MikroTik
datawater.com
MikroTik Called It a Quiet Patch. CERT Polska Calls It "MikroTrick" — Full Admin Takeover With No Password and No Key, Exploited a Day Before the Fix Existed - DataWater
🚨 CRITICAL VULNERABILITY ALERT — Network Edge / Remote Access Infrastructure: MikroTik shipped a silent, no-detail patch for RouterOS on September 3, 2026, hoping to buy administrators time before attackers reverse-engineered the flaw. CERT Polska has now confirmed the exploited chain — nicknamed MikroTrick — was already running in the wild since September 2, a full day before the patch existed…
001
Royans Tharakan @royans.bsky.social · 08/09/2026
#SlopWatch does a quick evaluation of Pypi/npm packages for known supply-chain risk patterns. Please play with it and give feedback. github.com/royans/slopw... #Malware #Cybersec #supplychain
github.com
GitHub - royans/slopwatch
Contribute to royans/slopwatch development by creating an account on GitHub.
000
Royans Tharakan @royans.bsky.social · 07/09/2026
OpenAI Autonomous Agents Hijack DSEwiki for Sandbox Escape Coordination cyberpress.org/openai-agents-collud… flagthis.com/tldr/598 ##OpenAI ##AISecurity ##SandboxEscape ##CloudSecurity ##MultiAgentSystems
000
Royans Tharakan @royans.bsky.social · 07/09/2026
OpenAI GPT-6 Astra: Semantic-to-Physical Manipulation and the Emerging Robotics Attack Surface openai.robocurve.org/gpt-6-astra flagthis.com/tldr/7033 ##OpenAI ##EmbodiedAI ##RoboticsSecurity ##PromptInjection ##VLA
openai.robocurve.org
GPT-6 Astra on robotic manipulation
OpenAI's GPT-6 Astra vs Claude Fable 5.1 controlling a pair of YAM arms under the same agent policy: 19/20 vs 8/20 on block-into-bowl in interleaved blinded pairs, 2/20 vs 2/20 on the puzzle, with 80% fewer output tokens.
000
Royans Tharakan @royans.bsky.social · 06/09/2026
ClickFix Malware Campaign: Decentralized Payload Hosting via WordP... www.bleepingcomputer.com/news/secur… flagthis.com/tldr/7014 ##WordPress ##SocialEngineering ##BlockchainSecurity ##Infostealer ##DeepLoad
000
Royans Tharakan @royans.bsky.social · 05/09/2026
OpenAI GPT-6 Astra: Crossing the Critical Cybersecurity Thres... www.computerworld.com/article/42186… flagthis.com/tldr/7005 ##OpenAI ##LLMSecurity ##ZeroDay ##AgenticAI ##AIExploitation
computerworld.com
OpenAI launches GPT-6 Astra, its first model to cross a critical cybersecurity threshold
The rollout comes with a safety disclosure that could reshape how CIOs think about model governance.
010
Royans Tharakan @royans.bsky.social · 05/09/2026
Microsoft Copilot Integration of OpenAI GPT-6 Astra techcommunity.microsoft.com/t5/micr… flagthis.com/tldr/6993 ##Microsoft ##PromptInjection ##CloudSecurity ##LLM ##DataLeakage
techcommunity.microsoft.com
Available today: OpenAI GPT-6 Astra in Microsoft Copilot | Microsoft Community Hub
OpenAI's GPT-6 Astra is rolling out in Copilot Cowork and Copilot Studio today   
000
Royans Tharakan @royans.bsky.social · 05/09/2026
Massive Data Exposure at IDscan.net Identity Verification Platform techjacksolutions.com/scc-intel/153… flagthis.com/tldr/7007 ##DataBreach ##SupplyChain ##IdentityTheft ##IDscan.net
000
Royans Tharakan @royans.bsky.social · 05/09/2026
AI Agent Security and the Model Context Protocol MCP Framework www.penligent.ai/hackinglabs/ai-age… flagthis.com/tldr/6977 ##AIsecurity ##PromptInjection ##MCP ##AgenticHijacking ##Cybersecurity
penligent.ai
AI Agent Security: Threats, Attack Paths, and Defense in 2026
AI agent security explained for 2026: learn prompt injection, MCP risks, tool abuse, memory poisoning, agent identity, OWASP threats, testing, and defenses.
341
Royans Tharakan @royans.bsky.social · 05/09/2026
Critical Authentication Bypass and Session Hijacking in Citrix NetScaler ADC and Gateway www.bleepingcomputer.com/news/secur… flagthis.com/tldr/6971 ##Citrix ##SessionHijacking ##MFABypass ##CVE20234966
000
Royans Tharakan @royans.bsky.social · 04/09/2026
Global IDV Supply Chain Compromise: idscan.net www.techdirt.com/2026/09/03/hackers… flagthis.com/tldr/6954 ##idscan.net ##DataBreach ##SupplyChain ##IdentityTheft
000
Royans Tharakan @royans.bsky.social · 04/09/2026
Systemic Vulnerability in AI Agent Architectures via llms.txt... techjacksolutions.com/scc-vendor-ro… flagthis.com/tldr/6940 ##PromptInjection ##AIAgents ##SupplyChain ##RCE ##LLM
010
Royans Tharakan @royans.bsky.social · 04/09/2026
Aesto Health Data Breach: 9.5 Million Patient Records Compromised www.esecurityplanet.com/threats/new… flagthis.com/tldr/6935 ##DataBreach ##HIPAA ##HealthcareSecurity ##PHI ##ThirdPartyRisk
esecurityplanet.com
Aesto Health Breach Exposes Data of More Than 9.5 Million People
Aesto Health says a December 2025 cyberattack affected more than 9.5 million people, potentially exposing medical, financial and identity data.
000
Royans Tharakan @royans.bsky.social · 04/09/2026
Massive Exfiltration of 153M+ Driver's License Scans from Unnamed Louisiana-Based Identity Verification Firm krebsonsecurity.com/2026/09/fbi-pro… flagthis.com/tldr/6849 ##DataBreach ##IdentityTheft ##KYC ##DarkWeb ##Fintech
000
Royans Tharakan @royans.bsky.social · 04/09/2026
The Rise of Agentic AI: Compressing Attack Lifecycles via Autonomous LLM Orchestration www.darkreading.com/cyberattacks-da… flagthis.com/tldr/6929 ##AgenticAI ##LLM ##Cybersecurity ##Automation ##MachineSpeed
000
Royans Tharakan @royans.bsky.social · 03/09/2026
Critical Unauthenticated SQL Injection in Sangoma Switchvox Enables RCE xploitzone.com/cve-2026-9586-sangom… flagthis.com/tldr/6921 ##SQLInjection ##RCE ##VoIP ##CVE-2026-9586 ##Sangoma
000
Royans Tharakan @royans.bsky.social · 03/09/2026
PrimSynth: An Agentic Framework for Autonomous Linux Kernel Exploit Synthesis arxiv.org/abs/2609.02647 flagthis.com/tldr/6909 ##LinuxKernel ##ExploitDevelopment ##ArtificialIntelligence ##VulnerabilityResearch ##CyberSecurity
arxiv.org
PrimSynth: An Agentic Approach to Discover, Validate, and Synthesize Exploit Primitives for Linux Kernel Vulnerabilities
Linux kernel vulnerabilities are critical to downstream systems. Despite extensive research on automated kernel exploitation, a fundamental challenge remains the conceptual gap between abstract exploit strategies and concrete technical operations. To fill this gap, this paper introduces a systematic characterization that formalizes six classes of exploit primitives from logical capability to validatable effect. Then, an extended exploit strategy representation is proposed, which couples primitive upgrading strategies with primitive path code synthesis rules governing object constraints, temporal sequencing, environment prerequisites, and validation constraints. Building upon this foundation, this paper presents \textsc{PrimSynth}, a multi-agent framework that encapsulates these representations through coordinated agents to discover, validate, and synthesize exploit primitives for memory corruption vulnerabilities in the Linux kernel. These agents operate in an iterative closed loop until valid primitives are found, leveraging validation signals as evidence of exploitable state transitions to ground primitive synthesis decisions. An automated method for extracting and validating primitives is also proposed based on vulnerability-directed execution and a rebootable validation environment. \textsc{PrimSynth} is evaluated on 16 real-world Linux kernel CVEs spanning 5 vulnerability types. Experimental results show that PrimSynth achieves reliable primitive extraction, maintaining a 100% primitive match rate. For primitive synthesis, PrimSynth successfully synthesizes multi-primitive exploitation chains with 82.4% strategy synthesis rate (SSR) when the public PoC is available and a 61.3% SSR without the guidance of primitive hypotheses.
110
Royans Tharakan @royans.bsky.social · 03/09/2026
AI Brand Impersonation Targeting Anthropic, Claude, and GitHub Developers techjacksolutions.com/scc-intel/ai-… flagthis.com/tldr/6903
000
Royans Tharakan @royans.bsky.social · 03/09/2026
OpenAI-led Coalition Warns: AI-Driven Attacks Are Closing the SOC Human-in-the-Loop Window www.cybrsecmedia.com/ai-attacks-are… flagthis.com/tldr/6876 ##OpenAI ##AI ##Cybersecurity ##SOC ##AgenticAI
cybrsecmedia.com
AI Attacks Are Closing the SOC’s Human Oversight Window
As attackers automate cyberattacks at machine speed, SOC teams may soon have to let AI agents act without human approval — making RBAC, business context and autonomous-response guardrails critical security controls. (Sponsored by Command Zero)
020
Royans Tharakan @royans.bsky.social · 03/09/2026
Aesto Health AWS Infrastructure Breach www.bleepingcomputer.com/news/secur… flagthis.com/tldr/6893 ##CloudSecurity ##DataBreach ##AWS ##HIPAA ##PII
000
Royans Tharakan @royans.bsky.social · 03/09/2026
Fire Ant Evolves: Targeting Cisco IOS XR and VMware ESXi Infrastructure www.sygnia.co/webinars/fire-ant-evo… flagthis.com/tldr/6875 ##FireAnt ##Cisco ##NetworkSecurity ##Espionage ##InfrastructureAttack
sygnia.co
Fire Ant Evolves: From Hypervisors to Trusted Infrastructure
Inside a China-nexus espionage investigation where routers, authentication systems, and Linux management infrastructure became operational platforms
000
Royans Tharakan @royans.bsky.social · 03/09/2026
Global Takedown of the Sality P2P Botnet malware.news/t/global-public-privat… flagthis.com/tldr/6864 ##Sality ##Botnet ##P2P ##LawEnforcement ##MalwareAnalysis
malware.news
Global public-private operation disrupts Sality botnet active for two decades
An international operation supported by Europol has disrupted the Sality peer-to-peer (P2P) botnet, a long-running criminal infrastructure used to distribute malicious payloads to thousands of infected computers worldwide.The coordinated action, carried out on 31 August 2026 and led by the US authorities, targeted a botnet believed to have been operating for more than two decades. At its peak, the botnet… Introduction to Malware Binary Triage (IMBT) Course Looking to level up your skills? Get 1...
000