#detection

25 posts · Last used Aug 31

🔴 EXPLOITED Cisco Secure Firewall Management Center ships a hardcoded password that lets a stranger log in with no credentials (CVE-2026-20316). It is being exploited now and sits on CISA's must-patch list. Apply the hotfix, then check logs for signs of entry. https://suriq.io/blog/cisco-fmc-hardcoded-password-cve-2026-20316 #CVE #Detection #CISAKEV #infosec
0
0
0
0
---------------- 🛠️ Tool =================== numbat is an endpoint visibility tool for AI agent activity, developed by perplexityai. It provides local detection, optional pre-action blocking, and forensic reconstruction of agent sessions across desktop, CLI, IDE, and gateway surfaces. 🔹 Key Features The tool observes supported agents through local hooks and plugins, OTLP/HTTP log exporters, and on-disk session artifacts. Live and at-rest activity is normalized into a single event model and evaluated by a CEL rule engine. Detection runs entirely locally. Records can be written to stdout or a local file, with optional HTTP delivery. • Live monitoring via hooks, plugins, and OTLP/HTTP exporters • Local detection with built-in CEL rules, multi-step sequence rules, and custom YAML rules • Optional blocking through supported synchronous pre-action hooks (disabled by default; only rules marked enforce: true apply) • Forensic reconstruction from on-disk session artifacts without prior numbat instrumentation • Versioned NDJSON records for events, findings, enforcement decisions, indicators, and scan summaries • Read-only artifact scanning with secret redaction; raw transcripts never included in normal output • Inventory and investigation tools for agent discovery, per-session timelines, and portable case bundles with SHA-256 manifests • Single-binary distribution for macOS, Linux, and Windows, built without cgo 🔹 Technical Implementation Installation is straightforward: download a release or use go install github.com/perplexityai/numbat/cmd/numbat@latest. Read-only inventory commands (numbat agents, numbat scan) do not install hooks or modify agent configuration. Live monitoring requires numbat hook install --agent --emit all, which starts in monitor-only mode. Hook trust requirements vary by agent and scope. For Codex user hooks, operators must review and trust the hook definition in /hooks or Settings > Hooks. Managed hooks are trusted by policy. All shipped rules are monitor-only. To enforce a detection, operators copy the shipped YAML into a controlled directory, add enforce: true, bump the version, then install with --enforce. 🔹 Use Cases • Security teams needing visibility into what AI agents execute on developer endpoints • Forensic reconstruction of past agent sessions without prior instrumentation • Compliance auditing of agent actions with versioned NDJSON records • Incident response with portable case bundles and SHA-256 manifests 🔹 Limitations Blocking is limited to supported synchronous pre-action hooks only. The coverage matrix is authoritative for each host and surface. hook status verifies configuration, not execution or delivery. Tool has not been independently tested. 🔹 numbat #AIagents #endpoint #cel #detection 🔗 Source: https://github.com/perplexityai/numbat
0
0
0
0
RE: https://mstdn.social/@osnews/116965092743942475 Thank you to @onepict@chaos.social and @jwildeboer@social.wildeboer.net for this. My primary curiosity for digging in here wasn't the vendor or anti-vendor politics point, or the freedom-of-coder-communities-to-organize point, but rather… how exactly are they enforcing this? #AI #antislop #slop #detection #FOSS
1
1
0
0
HollowGraph, an espionage implant, hides its command channel in a hijacked Microsoft 365 calendar over the Graph API. No CVE, no patch. Firewalls see normal M365 traffic. Hunt far-future calendar events with attachments in your audit logs. https://suriq.io/blog/hollowgraph-microsoft-365-calendar-c2 #CVE #ThreatIntel #Detection #infosec
0
0
1
0
GigaWiper encrypts Windows files to a .candy extension with no key and no ransom note. That is on purpose: the ransomware is a decoy for a disk wiper. Microsoft and Binary Defense tracked the same code as one Iran-nexus operation. https://suriq.io/blog/gigawiper-fake-ransomware-disk-wiper #Ransomware #ThreatIntel #Detection #infosec
0
0
0
0
GodDamn ransomware loads PoisonX, a kernel driver reportedly carrying a valid Microsoft signature, to switch off EDR. Signature checks wave it through. Affects Windows servers. The tell is your agent going silent while still online. https://suriq.io/blog/signed-kernel-driver-edr-killer #Ransomware #Detection #infosec #cybersecurity
0
0
0
0
Cavern is a new Iran-linked backdoor that breaks into IT providers using no vulnerability at all. It abuses their own deployment tools, then hops to customers. No CVE to patch. Detection is the only defense. https://suriq.io/blog/cavern-manticore-c2-no-cve-it-provider-supply-chain #SupplyChain #Detection #infosec #cybersecurity
0
0
0
0