← Back to Posts

Posts

OS Weekly: AI Exploits, a New APT Toolkit & Smarter Defenses

OS Weekly: AI Exploits, a New APT Toolkit & Smarter Defenses

This week made one thing obvious: AI is now firmly on both sides of the fight. Security researchers chained a public help-forum bug with a login flaw — with an assist from Anthropic’s Claude Opus 5 — to walk into OpenAI staff accounts, while a suspected North Korean APT group debuted a brand-new Linux espionage toolkit against South Korean infrastructure. Meanwhile, vendors like Nvidia, CrowdStrike, and Vectra AI are racing to put AI to work on defense instead. Here’s what aspiring and working security professionals need to know from the last seven days.

AI on the Attack

Researchers chained two flaws — with Claude Opus 5’s help — to hijack OpenAI staff accounts

Illustration of chained digital vulnerabilities representing the Claude Opus 5-assisted breach of OpenAI staff accounts

Three researchers at the security firm Hacktron used Anthropic’s Claude Opus 5 to identify and chain together two distinct vulnerabilities: a bug in the software behind OpenAI’s public help forum, and a weakness in OpenAI’s login system. Chaining the two let them compromise the ChatGPT and Codex accounts of OpenAI employees and ultimately reach an internal code repository. The work was conducted and disclosed as security research rather than a malicious breach.

This is a clean, well-documented case study in how AI is accelerating vulnerability research on both sides of the fence. Attack chains built from individually “minor” bugs — a forum flaw here, a login quirk there — are exactly what AI-assisted recon is good at surfacing quickly. If you’re building red-team or bug-bounty skills, study how these two low-severity issues were combined into something serious, and get in the habit of treating small findings as potential chain links rather than closing them out as one-offs.

Read more →

BragJack hijacks AI browser agents through a single malicious extension

Illustration of a radiant padlock representing the BragJack attack hijacking AI browser agents via malicious extensions

Independent researcher Gal Weizman (Forever Security) built BragJack, a proof-of-concept attack that hijacks AI assistants built into Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome — all through one malicious browser extension, using a technique he calls Prompt Forcing. The research earned Weizman more than $20,000 in bug bounties and produced two CVEs.

As AI browser agents move from novelty to default, the browser extension store becomes a serious and under-scrutinized attack surface. A single bad extension can now potentially hijack not just your browsing but your AI assistant’s actions on your behalf. Audit installed extensions on any machine running an AI browser agent, and start treating “AI assistant + third-party extension” as its own risk category in threat models.

Read more →

Threats & Breaches

A suspected North Korean APT debuts a new Linux espionage toolkit against South Korean infrastructure

Illustration of interconnected digital circuits representing the APT attack on South Korean media and automotive sectors

A likely North Korean advanced persistent threat group has been observed using a previously undocumented Linux espionage toolkit to compromise load balancers belonging to organizations in South Korea’s media and automotive sectors. The toolkit gives attackers access to communications passing through the compromised infrastructure and a foothold for deeper network exploitation.

Linux-targeted APT tooling aimed at network infrastructure — rather than end-user Windows machines — is a reminder that detection coverage has to extend past the endpoint. If your organization’s monitoring stack is weighted heavily toward Windows telemetry, this is a good prompt to audit visibility into Linux hosts and network appliances like load balancers.

Read more →

Attackers are actively exploiting a WooCommerce plugin flaw to plant PHP web shells

Illustration of a metallic shield casting protective shadows representing the WooCommerce plugin flaw enabling PHP web shell attacks

Wordfence is reporting active, unauthenticated exploitation of a critical vulnerability in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with more than 6,000 active installations. The flaw allows attackers to upload arbitrary files — including PHP backdoors — leading to remote code execution. Wordfence says it has already blocked millions of exploitation attempts targeting the bug.

WordPress and WooCommerce plugin sprawl remains one of the most consistently exploited attack surfaces on the open web, precisely because plugins are numerous, unevenly maintained, and easy to overlook in patch cycles. If you manage or audit e-commerce sites, patch this immediately and add recurring plugin-inventory checks to your standard hardening workflow.

Read more →

Data broker Radaris loses its domains after a privacy lawsuit

Illustration of floating padlocks and keys representing the Radaris data broker privacy lawsuit

Radaris, a consumer data broker known for stonewalling requests to remove personal information, was sued for violating a New Jersey privacy law protecting state law enforcement officials from having their personal details published. A judge ordered radaris.com and several related data-broker domains transferred to the plaintiffs, citing what the ruling described as continuous stonewalling and deceit by the company.

Legal action against data brokers rarely results in consequences this concrete. For anyone working in privacy, compliance, or personal OPSEC, this is a notable precedent — and a useful reference point the next time a client, colleague, or protected individual asks whether pursuing a data broker is worth the effort.

Read more →

AI on Defense

Nvidia and CrowdStrike team up on new cybersecurity AI models

Illustration of interconnected network grids with a glowing shield representing the Nvidia and CrowdStrike AI partnership

Nvidia and CrowdStrike have partnered to develop new AI models aimed at strengthening threat detection and response, pairing Nvidia’s AI infrastructure expertise with CrowdStrike’s security platform. Technical details remain limited, but the partnership signals a broader industry shift toward AI-native defense stacks.

Vendor consolidation around AI-driven detection is accelerating. Understanding how these platforms reason about threats — not just how to operate their dashboards — is becoming a differentiator for analysts entering the field.

Read more →

Vectra AI launches Ascent to counter the new era of AI-driven attacks

Illustration of a luminous shield emerging from circuit patterns representing Vectra AI’s Ascent launch

Vectra AI has expanded its partner strategy with a new program, Ascent, designed to help organizations navigate increasingly complex security environments and meet growing demand for AI security expertise, specialized services, and improved outcomes.

As AI-driven attacks mature, expect more vendors to lean on partner ecosystems rather than in-house teams alone to deliver AI security expertise at scale — a trend worth watching if you’re weighing an in-house SOC role against a partner/MSSP career path. If you’re building the kind of case-study page or write-up index that makes you the obvious pick for that next role, Carrd is a fast, no-bloat way to get one live without fighting a CMS. Affiliate link — signing up may support CyberShield at no extra cost to you.

Read more →

Talos: “securing the unpatchable” in the age of AI-discovered vulnerabilities

Illustration of a glowing shield surrounded by AI shapes representing AI-driven vulnerabilities and cybersecurity challenges

As AI tooling uncovers vulnerabilities faster than organizations can patch them — some of which may be effectively unpatchable in practice — Cisco Talos recommends leaning on compensatory controls: appropriate network segmentation, rigorous visibility into network activity, and next-generation firewall/intrusion-prevention combinations.

“Patch everything, immediately” was never a fully realistic strategy, and AI-accelerated vulnerability discovery makes that gap more obvious. Segmentation and visibility are durable skills that hold up even as the volume of findings grows.

Read more →

Should you care about an “AI slowdown”? Talos says the fundamentals still win

Illustration of a glowing shield in a serene digital landscape representing considerations around an AI development slowdown

In this week’s Threat Source column, Talos argues that even as AI reshapes tooling and workflows, prioritizing fundamental security practices — patching, monitoring, training — remains the highest-leverage strategy. The piece frames it as an 80/20 problem: a small set of security basics, done consistently, protects against the majority of realistic threats.

It’s an easy, useful gut-check whenever a new AI security tool promises to replace fundamentals rather than augment them. Fundamentals compound; hype cycles don’t — and if you’re documenting your own research or write-ups as part of building that fundamentals-first reputation, Kit is the email platform we run CyberShield itself on, built for writing and growing a list you actually own. Affiliate link — signing up may support CyberShield at no extra cost to you.

Read more →

Also This Week

A “Secure Gmail” extension promises sender verification — proceed with normal scrutiny

Illustration of an organized inbox with padlocks representing a Chrome extension for cybersecurity-conscious inbox management

A new Chrome extension, Secure Gmail – Sender Verification, aims to help declutter inboxes while flagging spoofed or unverified senders to reduce phishing risk. Community engagement on the tool so far is minimal.

Extensions that promise security benefits deserve the same scrutiny as any other unaudited third-party code with access to your inbox — check permissions, developer reputation, and reviews before installing, regardless of how good the pitch sounds. Given this week’s BragJack story above, that scrutiny matters more than usual right now.

Read more →

Windows Server 2022 reaches end of mainstream support next month

Microsoft confirmed that Windows Server 2022 will reach the end of mainstream support next month, transitioning into extended support — critical security updates only, with no new features — through October 2031.

Extended-support-only windows are exactly when unpatched, feature-frozen infrastructure quietly becomes the weak link in an environment. If Windows Server 2022 is in your fleet, this is the moment to start the upgrade or migration conversation, not after the next incident.

Read more →


That’s the week: AI cutting both ways, a nation-state crew testing new tooling on critical infrastructure, and the fundamentals still holding the line regardless of how fast the tools around them change. Whichever side of this you’re building toward — offense, defense, or just staying sharp — keep learning in public, keep shipping, and follow CyberShield for the next one.

comments powered by Disqus