Microsoft Threat Intelligence has discovered a new variant of XCSSET, a sophisticated modular macOS malware that targets Xcode projects. The malware was found in the wild during routine threat hunting and is the first known XCSSET variant to surface since 2022. This new version of XCSSET features stronger obfuscation methods, updated techniques to maintain persistence on infected machines, and new ways of infecting systems. These improvements help the malware steal and exfiltrate files, as well as sensitive system and user information, including digital wallet data and personal notes. XCSSET is designed to infect Xcode projects and executes when a developer…
Kirsten Doyle
In a recent investigation, Tenable researchers explored how DeepSeek, a large language model (LLM) built by a Chinese company, can be exploited to generate malware, including keyloggers and ransomware, despite its initial refusal to engage in harmful activities. Unlike popular AI models like GPT-4 or Claude, DeepSeek is fully open-source, so anyone can download and use it for free. It’s trained on large datasets, including code, making it very powerful — yet potentially dangerous. From Guardrails to Jailbreaks Mainstream GenAI platforms like ChatGPT and Gemini also have well-documented protections against malicious use. Reports like OpenAI’s “Disrupting malicious uses of AI…
OpenAI has officially called on US lawmakers to exempt it from complying with state-level AI regulations, instead urging a unified approach under federal AI rules. It argues that a consistent, nationwide framework is critical to maintain US leadership in AI development and deployment. In a newly released policy proposal, the company outlines what it calls a “freedom-focused” strategy, emphasizing that only a national approach will allow American innovation to flourish without being slowed by fragmented, state-specific requirements. Key Elements of OpenAI’s Policy Proposal: Shaping the Future Regulatory Landscape If these proposals are adopted, they could shape the future regulatory landscape.…
Industrial cybersecurity firm Dragos has revealed that a small electric and water utility in Massachusetts was breached by a sophisticated Chinese advanced persistent threat (APT) group for over 300 days. The attack targeted Littleton Electric Light and Water Departments (LELWD), which serves the towns of Littleton and Boxborough. According to a Dragos case study, the APT group, known as Volt Typhoon, had been inside LELWD’s network since February 2023 but was only discovered in November 2023, just before Thanksgiving. Volt Typhoon, a group linked to the Chinese government, was first publicly identified by Microsoft in May 2023. Since then, the…
The NHS is investigating claims made by a whistleblower regarding a security flaw at Medefer, an online healthcare provider working with the NHS. The whistleblower alleged that a flaw in the company’s application programming interface (API) exposed NHS patient data. Medefer, however, has denied the claims and insists that the vulnerability has been addressed. When a patient is referred to Medefer for an online appointment, the company receives patient data from the NHS’s e-referral system (e-RS) or the NHS Spine, which is then made available to medical professionals for consultations. The whistleblower, a software testing contractor, claimed that in November…
In a joint advisory, US federal agencies have issued a cybersecurity warning about a sharp increase in attacks by Medusa ransomware, urging business leaders and IT teams to act immediately to protect their organizations. The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) released the advisory as part of the national #StopRansomware initiative, which focuses on helping entities defend against ransomware threats. The Impact on Critical Infrastructure and Business Operations Medusa ransomware is a Ransomware-as-a-Service (RaaS) operation first detected in 2021. Since then, Medusa has been used to…
Google’s Threat Analysis Group (TAG) and Mandiant have uncovered a sophisticated espionage campaign linked to China-nexus threat actors, targeting vulnerable Juniper routers used in enterprise and government networks worldwide. This discovery highlights the ongoing risks posed by state-sponsored attacks against aging network infrastructure. The malicious actors honed in on end-of-life and unpatched Juniper routers, exploiting known vulnerabilities to gain a foothold in networks. Many of these devices are still in active use despite lacking security updates, making them compelling targets. After exploiting the routers, the actors behind the campaign deployed custom-built malware frameworks to maintain persistent access—tools that allowed them…
The House of Representatives has passed a bill that mandates contractors working with the federal government implement vulnerability disclosure policies (VDPs) in alignment with NIST guidelines. The Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025, introduced by Chairwoman Nancy Mace (R-S.C.) and Ranking Member Shontel Brown (D-Ohio), directs the Office of Management and Budget (OMB) to work with CISA, the National Cyber Director’s Office, NIST, and other agencies. The bill also asks the Defense Department to ensure defense contractors adopt similar policies. The Office of Management and Budget and the Department of Defense will be required to update federal acquisition…
New research has revealed that although 86% of employees believe they can confidently identify phishing emails, nearly half have fallen for scams. The study, conducted by KnowBe4, surveyed professionals in the UK, USA, Germany, France, Netherlands, and South Africa and revealed a growing chasm between confidence and competence in identifying cyber threats. Interestingly, South Africa leads with both the highest confidence levels and the highest scam victimization rate, suggesting that confidence is unwarranted and fuels a false sense of security, leaving workers more susceptible to advanced cyber threats. Fluctuating Confidence Levels Across all demographics, confidence levels depended largely on the…
A phishing email pretending to be from Binance, offering people the chance to claim newly created TRUMP coins, has turned out to be a phishing lure. Cofense is warning that if victims follow the email’s instructions and download what is called “Binance Desktop,” they actually install a remote access tool that gives malicious actors control of their computers within two minutes. To make the scam more convincing, the attackers used “Binance” as the sender’s name and included a fake “risk warning” to make the email seem trustworthy. They also fashioned a fake website that closely resembles the Binance site to…
