The Infrastructure is Leaking: AI SSRF, Destructive Backups, and IT Helpdesk Vishing
Vulnerability
SSRF Vuln Disrupts Open Source AI Tool Integration
An SSRF flaw was discovered affecting the way many popular open source LLM frameworks interact with external tools. If you're self-hosting models, this is a direct path to internal network scanning and data exfiltration that warrants an immediate audit.
Malware
Qilin Ransomware Debuts New Linux/ESXi Encryptor
Qilin affiliates have deployed a new, fully rewritten ransomware variant specifically optimized to encrypt hypervisor configurations and virtual machine disk files. This aggressively confirms the trend: patching your host OS is no longer enough if your backup, object storage, and identity fabric are not independently secured.
Tools
ProjectDiscovery Revamps Nuclei Template Syntax for Builders
ProjectDiscovery just landed a major update in their public repository introducing an entirely new syntax schema for writing Nuclei templates, designed to cut down code duplication and logic bugs. If you are building custom scanners or vulnerability management automation, this is a direct productivity boost worth adopting immediately.
Trend
Ransomware Actors Systematically Targeting Cloud Backups
Forget double extortion; we are seeing a distinct shift toward 'destructive extortion' where actors wipe cloud snapshots and S3 buckets before rendering on-prem files unreadable. This changes the backup architecture entirely: air-gapping or immutable 'WORM' storage is now a primary control rather than a nice-to-have.
Operations
FBI Warns of 'Luna Moth' Callback Phishing Waves
Luna Moth is running an effective mass-callback campaign where victims receive fake subscription notices and are tricked into installing legitimate remote management software. Once installed, the attacker has a direct, high-privilege tunnel into your environment without triggering standard malware definitions.
Stay Ahead
Delivered each morning.