DJBSEC's CyberNews 2026-08-10
Today’s daily news covers the following categories: Ransomware Threat Intelligence Vulnerability Phishing
Microsoft Defender Stops QNET Attack in 128 Seconds
Ransomware Microsoft detailed how Defender’s automatic attack disruption contained a multistage attack against QNET just 128 seconds after the first high-severity detection. The attacker abused the legitimate Windows mshta.exe utility to retrieve a malicious second-stage payload, but Defender automatically isolated the compromised endpoint before the attacker could establish persistence or move laterally. Microsoft says the new device-isolation capability uses AI-driven correlation and acts only after reaching a high-confidence verdict, while still allowing security teams to review and reverse the action. No additional payloads, command-and-control traffic, or lateral movement were observed after isolation. The case demonstrates how autonomous containment can dramatically reduce the time attackers have to turn an initial endpoint compromise into a larger incident. Read More
Ransomware Gangs Increasingly Target Managers Instead of CEOs
Ransomware Ransomware operators are increasingly targeting mid-level and senior managers rather than going directly after CEOs or traditional privileged administrators. Zscaler researchers tracked 351 victims across 334 organizations and found nearly two-thirds held manager-level positions or higher, with the average victim being 46 years old. Attackers are seeking what researchers call “business privilege” — access to invoices, budgets, contracts, customer accounts, HR records, and people who can influence ransom decisions. The research also found ransomware attempts blocked by Zscaler increased 146 percent over the past year, while publicly reported extortion cases rose 70 percent. The findings suggest organizations need to think about privileged access in terms of business influence as well as technical administrator rights. Read More
OpenAI Tightens Security Around High-Capability Astra Model
Threat Intelligence OpenAI says it is implementing stricter safeguards around its upcoming Astra model after internal evaluations showed significant advances in agentic coding and cybersecurity capabilities. The company says Astra could potentially reach a level of cyber capability requiring additional safeguards, including isolated testing environments, restricted network and tool access, stronger model-weight protections, sandboxing, and expanded monitoring. OpenAI also says it will pause internal Astra testing in environments where those protections are unavailable and provide safer testing recommendations to outside evaluation partners. The move comes as AI developers face growing scrutiny over increasingly autonomous models capable of performing sophisticated cybersecurity tasks. Meanwhile, Anthropic is moving in the opposite direction in some areas by relaxing certain Fable model refusals involving biology-related prompts. Read More
CSS Attacks Create New Risks for AI-Powered Email Tools
Vulnerability Security researcher Gareth Heyes demonstrated that malicious CSS embedded in email can be used to steal credentials, hijack sessions, manipulate interfaces, and potentially influence AI tools that process inbox content. The research examined attack techniques affecting major webmail platforms including Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. One Outlook technique abused trusted interface behavior to disguise a dropdown as a password field, while another technique demonstrated how browser and sanitization behavior could expose login tokens. The research is particularly concerning as AI assistants gain deeper access to email, potentially giving malicious messages another way to manipulate automated systems. The findings show that seemingly harmless presentation technologies such as CSS can cross security boundaries when combined with complex web applications and AI integrations. Read More
Phishing Attack Exposes Sensitive Data at U.S. Defense Manufacturer IEH
Phishing U.S. defense and aerospace manufacturer IEH Corporation disclosed that an employee fell victim to a phishing attack that compromised their Microsoft 365 mailbox. The attacker impersonated a prospective business contact, sent a fake Microsoft document-sharing link, and captured the employee’s credentials through a fraudulent login page. The compromised mailbox contained emails, attachments, customer information, engineering documents, and potentially export-controlled technical information, although IEH says it has not confirmed data exfiltration. Investigators also discovered malicious mailbox rules, suggesting the attacker attempted to maintain access or intercept future communications. The incident illustrates how a relatively simple credential-phishing attack can create national-security concerns when the victim sits inside the defense supply chain. Read More
Microsoft Teams Adds Centralized Security Detection Reporting
Threat Intelligence Microsoft is preparing to introduce a Security Detection Report in the Teams admin center that will give administrators centralized visibility into threats occurring across chats and channels. The dashboard will consolidate detections involving impersonation attempts, malicious URLs, and potentially weaponized file types while providing details such as senders, recipients, detection types, and conversation identifiers. Administrators will also be able to export detection data for SIEM and compliance workflows and directly block malicious external users through Teams settings. Microsoft currently expects general availability to begin in late August, with the global rollout completing in early September. The feature addresses a growing visibility gap as attackers increasingly use Teams for phishing, impersonation, malicious links, and malware delivery. Read More
Critical Metabase Zero-Day Exploited to Gain Administrator Access
Vulnerability Metabase has confirmed active exploitation of a critical zero-day vulnerability that allows unauthenticated attackers to gain administrator access to vulnerable business intelligence servers. The CVSS 10.0 flaw is an unauthenticated SQL injection affecting the publicly reachable password-reset endpoint in Metabase versions 1.58 and later. Attackers can manipulate database records to create administrator access, potentially exposing connected database credentials and sensitive information accessible through the platform. Metabase’s own cloud service was attacked on August 3, while Framework and Tally have also disclosed data exposure connected to exploitation of the vulnerability. Self-hosted customers are being urged to patch immediately, revoke sessions, audit administrator accounts and API keys, and rotate credentials for databases connected to Metabase. Read More
Enjoy Reading This Article?
Here are some more articles you might like to read next: