Matthias Schulze

@percepticon.bsky.social

PhD in political science, studying infosec, cyber conflict & information war. Blue Team at SRLabs in Berlin. Blog and podcast about my work over at https://percepticon.de or https://ioc.exchange/@percepticon

Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover #cybersecurity #infosec

Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover

A Russia-aligned threat group used a “half-click” exploit against Microsoft Exchange’s Outlook Web Access to install a browser-based backdoor when recipients opened specially crafted emails. The campaign began on July 22 and was conducted by TA488, which is also tracked as Void Blizzard and Laundry Bear, according to a report from the cybersecurity firm Proofpoint. The attacks targeted government organizations in the US and Europe, as well as companies in the telecommunications, financial, hospitality, and aerospace sectors. Proofpoint did not name the targeted organizations or say how many attacks resulted in successful compromises. The attackers exploited CVE-2026-42897, a cross-site scripting vulnerability caused by inadequate sanitization of HTML in email bodies. A recipient did not have to click a link or open an attachment. Viewing a crafted message in OWA allowed malicious JavaScript to execute inside the browser. Microsoft has previously said the flaw affects all update levels of Exchange Server 2016 and 2019, as well as Exchange Server Subscription Edition, while Exchange Online is not affected. The company disclosed the vulnerability on May 14 and issued an emergency mitigation before releasing a code fix in June. Microsoft later said customers who installed its July 2026 Exchange security update could remove the earlier mitigation. Proofpoint found that infrastructure associated with the campaign had been created in March, before Microsoft disclosed the vulnerability. The company said the timeline made it feasible that TA488 had used the flaw as a zero-day, although it did not confirm that such exploitation occurred. “TA488 used intentionally vague message lures with no call-to-action for the targeted user,” Proofpoint said. The messages resembled routine informational updates, including material on supply chains and market indicators. Opening one in OWA triggered OWAReaper, a previously undocumented JavaScript implant that runs inside the reading pane. OWAReaper removes the exploit code from the message stored on the Exchange server after execution, reducing the evidence visible to users and investigators. It can collect account information and attempt to capture credentials entered through browser autofill. If OWAReaper finds an Outlook add-in with ReadWriteMailbox permissions, it can use the add-in to obtain an OAuth token and grant owner-level access to Exchange’s built-in “Default” identity. This could allow an attacker controlling another authenticated account in the organization to continue accessing the victim’s mail folders. Because those permissions are stored on the Exchange server, changing the victim’s password or rebuilding the endpoint would not remove them. Mailbox persistence OWAReaper shifts incident response beyond the affected device because the attacker can establish persistence within Exchange itself, said Sakshi Grover, senior research manager for IDC Asia Pacific Cybersecurity Services. “The most important shift is where the attacker establishes persistence,” she said. Organizations should treat the compromise as a server-side identity incident rather than only an infected endpoint or stolen password, said Keith Prabhu, founder and CEO of Confidis. “The normal incident response is usually to reset the password, revoke tokens, and reimage the endpoint,” Prabhu said. “This may no longer be sufficient.” Detection blind spots Security tools focused on endpoint files or processes may fail to identify an implant operating inside the OWA browser session, Prabhu said. “Traditional email-security controls may also struggle because the delivery emails contain no obvious malicious attachment or conventional phishing link,” Grover said. Because OWAReaper operates within an authenticated OWA session and can abuse legitimate mailbox functions, individual events may not appear malicious when examined in isolation. Detecting the threat requires cross-layer correlation, Prabhu said. He recommended starting with users that opened suspicious OWA messages, then reviewing subsequent mailbox-permission changes, add-in activity, and OAuth events. Investigators should also examine browser-storage artifacts and related network metadata.

csoonline.com

The majority of corporate IT is now off premises for the first time #cybersecurity #infosec

The majority of corporate IT is now off premises for the first time

IT is going remote while sucking up more power. Most corporate IT is now off-premises for the first time, according to Uptime Institute, while the average rack power density has crested above 11 kW for the first time as server fleets are gradually replaced with more powerful hardware. Uptime’s Global Data Center Survey 2026 reveals how the industry is managing to adapt to challenging circumstances, with the usual evergreen concerns over rising costs plus staffing and skills shortages. The survey polls more than 800 datacenter owners and operators across multiple countries, with more than half (52 percent) in North America and Europe. Off premise dominates: Every year, Uptime asks its enterprise respondents to estimate what percentage of their IT workloads are run in-house versus in third-party facilities. For the first time, third-party sites have the larger share, accounting for 46 percent of IT workloads, compared with 44 percent residing in enterprise-owned corporate server farms. Those figures don’t add up to 100 percent, as some respondents (10 percent) say they are using IT rooms and server cabinets rather than a dedicated facility. Uptime’s experts estimate that, by 2028, the proportion of workloads in self-owned server halls will remain the same, while those running in third-party sites will expand to 48 percent, eating away at those currently based in IT rooms and server cabinets. More power: While the headlines have featured AI infrastructure pushing IT infrastructure power density to 120 kW per rack or even higher, the reality is that most datacenters and servers operate at a much lower level than that. This year, the average of the most typical rack densities now surpasses 11 kW, as a gradual ongoing shift toward higher-powered hardware was compounded by a small number of new high-density facilities with racks above 30 kW. Without those few high-density facilities skewing the average, it sits at 7.8 kW, just slightly up from 7.5 kW in 2025. The majority of facilities still do not have any racks of 30 kW or above, Uptime finds, but more respondents (24 percent) now say they have some of these, compared with 19 percent last year. The increase was mostly in the 50-plus kW ultra-high-density range, including some respondents deploying AI and GPU servers into racks configured for above 100 kW. The trend for rising rack density will continue as organizations upgrade their infrastructure with newer hardware. Updated servers boost both workload capacity and energy performance, but maximizing these benefits means a corresponding rise in overall system power, Uptime states. Refresh shortened: Some operators are also pursuing more aggressive technology refresh timelines of less than 4 years, the report claims. If true, this would be the reverse of what some hyperscalers such as Microsoft, Google and Meta have been doing in recent years, extending lifecycles out to 6 or 7 years to save on depreciation expenses. Outages: When it comes to outages, this year’s report shows improvement for the sixth year in a row, with the number of respondents who experienced an outage in the past three years down by three percentage points. But Uptime warns against complacency, noting that many of the factors behind outages, such as reduced or unstable power availability, local grid reliability, supply chain constraints, and extreme weather, are on the increase. The flip side is that the costs of any outages that do occur continue to rise. This is because organizations have become more dependent on digital infrastructure, the report says, and so outages may have more financial impact than in the past. Overall, 71 percent of survey respondents reported that their most damaging outage cost at least $100,000, compared with 57 percent a year ago. Staffing shortage: Staffing has long been an issue for datacenter operators, and this year the greatest skills gaps reported were in electrical (38 percent of respondents), junior level operations (38 percent), operations management (35 percent) and mechanical roles (34 percent). However, more than half (53 percent) of operators report difficulties finding qualified candidates for vacant roles, up from 46 percent a year ago. Finally, Uptime found that financial pressure and resource constraints continue to grow among operators. In fact, the high prices of power, staff, and equipment, particularly for AI-related infrastructure, is the primary issue. Alongside that are escalating concerns over capacity forecasting, power availability and supply chain disruptions. ®

theregister.com

Pope's official prayer app commits cardinal sin, leaks 700K+ users' info #cybersecurity #infosec

Pope's official prayer app commits cardinal sin, leaks 700K+ users' info

Click To Pray, a prayer app endorsed by the Pope with hundreds of thousands of users worldwide, has leaked people’s names and email addresses for months - or longer - according to an ethical hacker who said she found and reported the security vulnerability six months ago to no avail. This app needs to take a vow of silence when it comes to your personal information. The app, available in seven languages and on iOS, Android, and clicktopray.org, is the official app of the Pope's Worldwide Prayer Network. It connects users across the globe to pray for the Holy Father’s intentions, and as of July 2026, it has 719,517 registered accounts. It’s also very leaky, according to security sleuth BobDaHacker, who says she spotted and disclosed the vulnerability to the Pope’s Worldwide Prayer Network on January 3. “The vulnerability is still live,” the hacker said in a Friday blog. “Nobody has ever responded. I guess my email wasn't in their prayers." The Reg readers likely remember BobDaHacker for her previous research exposing a free-food flaw in McDonald's ordering system and open controls on Chinese robot manufacturer Pudu Robotics. This latest security hole stems from an Insecure Direct Object Reference (IDOR) bug in the prayer app. This is a very common and easy-to-exploit type of flaw that occurs when a website or an app blindly accepts user-provided input to view or modify resources without checking to see if the user is actually authorized to retrieve the data. “You ask for your own data, the server gives it to you,” BobDaHacker explains. “You ask for someone else's data, the server gives you that too. Thou shalt not authorize, apparently.” When you sign up for a Click To Pray account, the app assigns you a sequential numeric user ID. As BobDaHacker uncovered, the API endpoint GET https://api[.]clicktopray.org/user/users/{id} will return user data for any account - not just your own account - so long as you supply a valid, five-digit user ID. It doesn’t perform any authorization check or ownership validation. “Just increment the number and get someone else's data,” she wrote. This data includes users’ email addresses, first and last names, country, dates of birth, and whether the account has been deleted, and the API exposes all 719,517 accounts on the prayer site. “With sequential user IDs and no rate limiting, an attacker could enumerate every single account on the platform,” the hacker explained. “One GET request per user. for i in range(1, 719518): scrape(). That's it. That's the exploit.” As BobDaHacker points out, many of these users are likely older individuals, not all that tech savvy, and very trusting of anything Vatican related, making these exposed accounts a “phishing goldmine.” “Imagine getting an email that says ‘The Holy Father requests your urgent attention’ with a Vatican-looking link,” she wrote. “Grandma is clicking that. Every time.” And then it gets even worse. The signup endpoint, POST https://api.clicktopray.org/user/users/sign-up, returns the account's validation_hash directly in the response body, and that value is the same UUID used in the email verification link. This means someone could sign up using any email address and verify the account before the confirmation message reached the inbox. Plus, BobDaHacker’s email client flagged the real verification email with a warning that it had failed the domain’s authentication requirements and might have been spoofed or improperly forwarded. “So not only is the API leaking 700,000 email addresses that could be used for phishing, but the real emails from Click To Pray already look like phishing,” the hacker noted. “An attacker wouldn't even need to try hard. They could send a pixel-perfect phishing email and it would have the same level of email authentication as the real thing: none. God works in mysterious ways.” The Register reached out to the Pope's Worldwide Prayer Network and did not receive any response. BobDaHacker says she’s still praying for one, too.®

theregister.com

Diese Forschenden sagen, dass ein CO2 Ausstoß erst nach ca 10 Jahren das Klima beeinflusst. D.h. die Hitzewellen von 2026 kommen vom CO2 von 2016. Seit 2016 ist der weltweite CO2 Ausstoß nochmal um 9% gestiegen. D.h. Herr Söder muss in den nächsten 10 Jahren noch viel mehr schwimmen.

Maximum warming occurs about one decade after a carbon dioxide emission

Maximum warming occurs about one decade after a carbon dioxide emission, Ricke, Katharine L, Caldeira, Ken

iopscience.iop.org

«Artificial intelligence is … a machine for shifting income and power from labor to capital. When capitalist investors pay billions of dollars to make computers ‹know things,› then their purpose is to cheapen the knowledge that people have, save on wages, and turn the savings into profit.»

The Socialist Case Against Nationalizing AI

AI is not a neutral technology whose benefits need to be redistributed. It is a weapon of class war from above, designed to cheapen labor and concentrate power. Nationalizing it does nothing to change...

jacobin.com

This fake Apple app can unlock your Mac’s password vault #cybersecurity #infosec

This fake Apple app can unlock your Mac’s password vault

CrashStealer is a new macOS infostealer that masquerades as Apple’s CrashReporter component, uses an Apple‑notarized installer to slip past Gatekeeper, tricks users into handing over their password, and then systematically loots browsers, password managers, crypto wallets, and Keychain secrets before exfiltrating them in AES‑encrypted bundles. Researchers have been following the development of CrashStealer since May 2026. It impersonates Apple’s CrashReporter component by taking the name CrashReporter.app. It also creates a LaunchAgent named com.apple.crashreporter.helper and uses the legitimate tool’s icon and metadata to look as trustworthy as possible. Gatekeeper, basically macOS’s bouncer at the door, checks whether an app looks safe before letting it run. By using a notarized installer—one that Apple has scanned and stamped as acceptable—Gatekeeper is more likely to let it through without raising alarms. Getting notarized doesn’t mean Apple intentionally approved the malware. It means the installer passed Apple’s automated checks, and the attackers abused that trust. The notarized installer, called “Werkbit Setup” is distributed from a fake software site registered in late June and gated behind a meeting PIN (Personal Identification Number), suggesting a targeted, invitation‑only campaign. When launched, the malware displays a fake macOS password prompt that users will expect to see when running a legitimate system operation requiring administrator privileges. In reality, the malware uses that password to unlock the user’s Keychain, which stores passwords and other sensitive data in macOS’s encrypted password vault. Image courtesy of Jamf Labs The malware then steals browser credentials and cookies, cryptocurrency wallet extensions, password manager data, and small files from common user directories. The stolen data is encrypted and sent to a command and control (C2) server. CrashStealer is a reminder that macOS is firmly in the sights of credential‑stealing operations. Notarization and Gatekeeper reduce many classes of risk, but they do not remove the need for layered defenses, cautious user behavior, and ongoing threat monitoring. How to stay safe There are a few things you can do to protection yourself from CrashStealer and other infostealers. * Be skeptical of “CrashReporter” downloads. Apple’s crash‑reporting tools ship with macOS, so you should never need to download a separate CrashReporter app from a third‑party site. * Treat PIN‑gated installers with caution. If a meeting invite or collaboration tool requires you to download software from an unfamiliar domain and enter a private PIN to unlock the installer, verify the request with the organizer through a separate trusted channel. * Treat a password request that appears immediately after launching a new or unfamiliar app—especially one claiming to be a system component—as a red flag. * Use reputable security software that supports macOS. Keep it, and macOS itself, up to date. * Separate your risk. Avoid keeping high‑value crypto wallets, password vaults, and everyday browsing credentials on the same machine and user profile wherever possible. Malwarebytes detects CrashStealer as MacOS.Stealer.Crash. --- We don’t just report on threats—we remove them Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

malwarebytes.com

Geheimdienstreform: Zeitenwende für Spione #cybersecurity #infosec

Geheimdienstreform: Zeitenwende für Spione

Bundesnachrichtendienst und Verfassungsschutz sollen „echte“ Geheimdienste werden, sagt Innenminister Dobrindt. Jetzt zeigt der Entwurf für die Komplettreform, was das heißt: Zurückhacken, Abschnorcheln, Kameras anzapfen – und das mit weniger öffentlicher Kontrolle als zuvor. Innenminister Dobrindt will BND und BfV aufrüsten. – BfV - Alle Rechte vorbehalten: IMAGO / newspix, BND - CC BY 2.0: Alper Çuğun, Dobrindt - CC BY 4.0: European Union Fast 700 Seiten lang ist der Gesetzentwurf aus dem Innenministerium, der Verfassungsschutz und Bundesnachrichtendienst in nie dagewesenem Ausmaß aufrüsten soll. Die Dienste sollen etwa Zurückhacken dürfen und bekommen ein Arsenal neuer Befugnisse zu KI und Biometrie. Schon vor mehr als einem halben Jahr gab es Berichte zu Arbeiten an dem Gesetz. An einigen Stellen soll es gehakt haben, die Abstimmungen zum Bundesverfassungsschutzgesetz hätten sich verzögert. Bundesinnenminister Alexander Dobrindt (CSU) habe unbedingt beide Gesetze gemeinsam durch die Tür bringen wollen. Nun ist der Referentenentwurf aus dem Innenministerium öffentlich. Es geht nicht nur um Ergänzungen, sondern um eine komplett neue Grundlage für die Arbeit der Dienste. Außerdem sollen mehr als zehn weitere Gesetze geändert werden. Der noch nicht in der Regierung abgestimmte Entwurf enthält zudem neue Regelungen für die Aufsicht der Geheimdienste. Unterm Strich soll die Kontrolle der Behörden schlanker werden – und öffentliche Transparenz noch weiter sinken. Die Übersicht. * Drei übergeordnete Ziele * Geheimdienste und Polizei nähern sich an * Mittel sollen geheim bleiben * Abschnorcheln bleibt erlaubt * Behörden sollen hacken dürfen * Dienste sollen KI kaufen, nutzen, trainieren * Niedrige Hürden für unsichere US-Software * Gesichter suchen, öffentliche Kameras anzapfen * Geheimdienst-Kontrolle soll schlanker werden * Noch weniger Transparenz als zuvor Drei übergeordnete Ziele Die umfassende Reform des Nachrichtendienstrechts, so der Entwurf, verfolge „drei übergeordnete Ziele“: Erstens sollen die Dienste in Anbetracht der „verschärften Bedrohungslage im In- und Ausland“ mehr Befugnisse erhalten. Zweitens solle der Entwurf der Vorrede zufolge die Kontrolle über die Geheimdienste stärken. Und drittens nehme er Anpassungen vor, die das Bundesverfassungsgericht gefordert hatte. Ein Urteil aus dem Jahr 2024 beanstandet etwa, wie der BND mit innerdeutscher Kommunikation umgeht. Außerdem erachten die Richter:innen eine hauptamtliche Aufsicht als erforderlich, weil die bisher für die Kontrolle zuständige G‑10-Kommission nicht ausreiche. Um die Mängel zu beheben, hat das Gericht der Bundesregierung eine Frist Ende 2026 gesetzt. Das heißt: Die Zeit für eine Neuregelung drängt. Laut Medienberichten will die Bundesregierung den Entwurf noch vor der parlamentarischen Sommerpause abstimmen – dann könnte ab Herbst der Bundestag darüber diskutieren. Geheimdienste und Polizei nähern sich an Die geplanten Umbrüche für BND und Verfassungsschutz greifen das Trennungsgebot an, das in Deutschland wegen historischer Lehren bislang eine wichtige Grundlage für Geheimdienst- und Polizeipolitik war. Die verschiedenen Institutionen, so die Konsequenz aus Erfahrungen mit Gestapo und Stasi, sollten getrennte Aufgaben und Befugnisse haben. Während die Geheimdienste vor allem Informationen sammeln sollen, darf die Polizei auch direkt eingreifen. Mit der Reform will Innenminister Dobrindt, „dass aus dem Nachrichtendienst nun ein echter Geheimdienst wird“, wie er Anfang des Jahres mit Blick auf den Verfassungsschutz sagte. Offenbar versteht er darunter, dass ein Geheimdienst auch eingreifen soll. Das zeigt sich etwa an den geplanten Befugnissen für aktive Eingriffe in IT-Systeme. Verfassungsschutz und BND sollen demnach unter bestimmten Bedingungen zurückhacken dürfen. Die Trennung zwischen Geheimdiensten und anderen Sicherheitsbehörden verschwimmt auch bei den Möglichkeiten, Daten auszutauschen. Im Entwurf finden sich etwa Passagen, die es dem Verfassungsschutz erlauben, gemeinsam mit anderen deutschen Behörden Daten auszuwerten, auch automatisiert. Mittel sollen geheim bleiben Im Vergleich zu den vorigen Gesetzen schafft der neue Entwurf mehr Übersicht. Das aktuelle BND-Gesetz verweist an vielen Stellen auf die Regelungen für den Verfassungsschutz. Das soll sich ändern. Der Entwurf für die beiden neuen Gesetze zählt auch klarer als bisher „nachrichtendienstliche Mittel“ auf, die Verfassungsschutz und BND nutzen dürfen. Dazu gehören beispielsweise verdeckte Ermittler:innen im Internet, die sich in Online-Netzwerke einschleusen, sowie die Überwachung von Wohnräumen und Telekommunikation. Aber diese Aufzählung ist nicht abschließend. Die Dienste sollen ihre nachrichtendienstlichen Mittel lediglich in einer Dienstvorschrift „abschließend“ benennen. Darin hat die Öffentlichkeit jedoch keinen Einblick, denn Dienstvorschriften der Geheimdienste bleiben wie so vieles geheim. Genau so funktioniert auch das Gesetz für den Militärischen Abschirmdienst (MAD), das im Dezember verabschiedet wurde. Abschnorcheln bleibt erlaubt Nach wie vor soll der BND in großem Umfang Daten abschnorcheln. Konkret bedeutet das: Der Auslandsgeheimdienst soll Internetknoten anzapfen dürfen, Kommunikationsdaten ausleiten und die erhobenen personenbezogenen Daten auswerten. Bislang hieß das Fernmeldeaufklärung, der neue Gesetzentwurf bezeichnet das als „strategische Aufklärung“. Dem Entwurf zufolge soll der Geheimdienst solche Maßnahmen auf das „notwendige Maß“ und auf maximal 15 Prozent des Datenvolumens beschränken, „welches in allen Telekommunikationsnetzen übertragen werden kann“. Eine solche Beschränkung lässt sich aber nur schwer kontrollieren, was das Bundesinnenministerium (BMI) in seiner Begründung selbst einräumt. Schwarz-Rot will die Informationsfreiheit beschneiden. Wir kämpfen für Transparenz. Mit deiner Unterstützung. Jetzt spenden Zudem können etwa über den Internetknoten in Frankfurt am Main, den DE-CIX, mehr als 200 Terabit pro Sekunde (Tbit/s) fließen. In den vergangenen 12 Monaten flossen jedoch nur durchschnittlich rund 13 Tbit/s. Darf der BND also 15 Prozent des höchstmöglichen Datenvolumens abschöpfen, entspräche das schlicht dem gesamten Datenverkehr. Ein solches Ausspähen „reiner Inlandskommunikation“ ist für den Auslandsgeheimdienst grundsätzlich unzulässig. Allerdings lässt sich technisch nicht klar eingrenzen, welche Daten ausschließlich zum Inland gehören. Der BND müsste die Daten dem Entwurf zufolge also filtern – „soweit technisch möglich“. Dass das nicht immer funktioniert, war bereits vor mehr als zehn Jahren klar. Der Betreiber des DE-CIX sagte damals für seinen Internetknoten, dass selbst wenn „der BND das weltbeste Filtersystem bauen könnte, das 99,9 Prozent [Genauigkeit] erreicht, dann redet man immer noch über mehrere Millionen fehlerhaft getaggter Verbindungen – jeden Tag“. Das allein führt wohl dazu, dass der Auslandsgeheimdienst zwangsweise auch inländische Telekommunikation überwachen wird. Erlaubt ist ihm das allerdings nur, „wenn im Einzelfall tatsächliche Anhaltspunkte dafür vorliegen, dass die Maßnahme erforderlich ist, um Informationen zu zumindest erheblichen Bedrohungen zu erlangen“. Behörden sollen hacken dürfen Eine neue Befugnis im Entwurf ist, dass der BND ausdrücklich zurückhacken darf – wenn „eine unmittelbar bevorstehende Gefahr für ein besonders gewichtiges Rechtsgut besteht“. In diesem Fall soll der Auslandsgeheimdienst Daten verändern oder löschen dürfen, Datenströme umleiten oder „den Betrieb informationstechnischer Systeme einschränken oder unterbinden“. Der BND soll also nicht nur Angriffe auf IT-Systeme aufdecken, sondern die Systeme der Angreifenden selbst angreifen dürfen. Unterstützung soll der BND von „inländischen öffentlichen Stellen“ wie dem Bundesamt für Sicherheit in der Informationstechnik (BSI) erhalten. Das BSI soll Software-Schwachstellen und auch sogenannte Zero-Day-Schwachstellen künftig proaktiv an den Geheimdienst weitergeben. Der BND soll diese Sicherheitslücken dann für Cyberangriffe auf andere Systeme ausnutzen dürfen. Zero Day („null Tage“) bedeutet, dass Angreifende eine Schwachstelle bereits verwenden können, während die Anbieter davon nichts wissen. Das heißt, es verbleiben null Tage Zeit, um sie zu schließen. Auch der Verfassungsschutz soll hacken dürfen. Dabei soll der Dienst Geräte manipulieren dürfen, die Daten umleiten, löschen oder Fehlinformationen verbreiten. Dieses Zurückhacken ist auch unter dem Begriff „Hackback“ bekannt, Fachleute kritisieren die Maßnahmen aus strategischen, rechtlichen und technischen Gründen. Dienste sollen KI kaufen, nutzen, trainieren Sowohl Verfassungsschutz als auch BND sollen dem Entwurf zufolge ausdrücklich personenbezogene Daten automatisiert auswerten dürfen. Für den BND ist das etwa im Paragrafen über die „Allgemeine Befugnis zur Weiterverarbeitung“ geregelt. Damit sind auch sogenannte KI-Systeme gemeint. Die dazu gehörige Begründung nennt Anwendungen, „welche für ihre Funktion selbstlernende Systeme verwenden und anpassungsfähig auf einen autonomen Betrieb ausgelegt sind“. Zudem soll der BND mit personenbezogenen Daten auch eigene KI-Anwendungen trainieren dürfen. Für einige KI-Auswertungen gibt es höhere Hürden, zum Beispiel wenn der Geheimdienst „personenbezogene Vorhersagen oder Empfehlungen“ erstellt oder automatisiert „Verhaltens- und Persönlichkeitsprofile“, um das „individuelle Bedrohungspotenzial“ einer Person einzuschätzen. Diese Ergebnisse gelten dann als „Auswertungsprodukte mit erheblichem Eingriffsgewicht“. Die Hürde: Solche Vorhersagen müssten dazu dienen, eine „zumindest erhebliche Bedrohung“ aufzuklären. Solche „erheblichen“ Bedrohungen gibt es im Aufgabenbereich des BND jedoch viele. Dazu zählen zum Beispiel organisierte Kriminalität, hybride Einflussnahme, Extremismus und dessen Unterstützung oder auch: „krisenhafte Entwicklungen im Ausland“, die theoretisch eine Auswirkung auf Deutschland haben könnten. Es ist also ein Begriff, der sich breit interpretieren lässt. Dass automatisierte Anwendungen und KI-Systeme schnell zu Verzerrungen und falschen Ergebnissen führen können, ist dabei offenbar auch dem Innenministerium klar. Der BND dürfe „keine diskriminierenden Algorithmen nutzen oder entwickeln“, heißt es analog zu anderen Gesetzen wie dem hessischen Polizeigesetz. Aber wie soll der BND – oder irgendeine Behörde – so etwas sicherstellen? Es gehört zum Wesen vieler KI-Systeme, dass sich deren Ergebnisse nicht leicht nachvollziehen lassen. Daher soll sich der BND die Ergebnisse stichprobenartig genau anschauen, heißt es im Entwurf, und sicherstellen, dass eine Entscheidung „zur Weiterverarbeitung/Maßnahmenveranlassung auch von einem Menschen aufgrund der vorliegenden Informationen getroffen worden wäre“. Niedrige Hürden für unsichere US-Software Eine der Sorgen bei den jüngsten KI-Regelungen für Polizeien war, dass Systeme von US-Anbietern wie Palantir zum Einsatz kommen könnten – Stichwort: digitale Souveränität. Dem will das Innenministerium durch eine Vorzugsregel für eigene und EU-Produkte entgegenwirken. Von privaten oder öffentlichen Stellen aus anderen Staaten dürfe der BND nur Anwendungen kaufen, wenn er selbst oder andere europäische Stellen keine ebenso geeignete Anwendung haben. Besonders eng, das wird aus der Begründung des Gesetzes deutlich, will man es hier aber nicht sehen. Wenn ein Produkt einmal angeschafft ist, soll es auch „beliebig lange“ genutzt werden dürfen. Und der BND soll auch nicht jedes Mal prüfen müssen, ob es auch eine europäische Lösung gibt. Es reiche, wenn er alle paar Jahre – die Begründung nennt drei bis fünf – schaut, „welche kommerziell verfügbaren Anwendungen für seine Tätigkeit von Relevanz sein könnten und ob es für diese Anwendungen europäische/deutsche Anbieter gibt“. Für den Softwaremarkt ist das eine sehr lange Zeit. Neben dem BND soll auch der Verfassungsschutz eine KI-Erlaubnis bekommen. Das steht in der Norm über „Qualifizierte Auswertung“. Die Rede ist von einer „automatisierten Anwendung, die durch Verknüpfung neue Erkenntnisse über die Persönlichkeit einer Person oder ihre Beziehungen zu anderen Personen oder zu Objekten gewinnt“. Alles netzpolitisch Relevante Drei Mal pro Woche als Newsletter in deiner Inbox. Jetzt abonnieren Gesichter suchen, öffentliche Kameras anzapfen Neben ausdrücklichen KI-Befugnissen geht es im Gesetzentwurf auch um biometrische Daten. Der Verfassungsschutz soll biometrische Merkmale mit allem abgleichen dürfen, worauf er „zur Erfüllung seiner Aufgaben zugreifen darf“, wenn „tatsächliche Anhaltspunkte“ vorliegen, dass das für seine Aufgaben erforderlich ist. Das heißt, er soll es eigentlich immer machen dürfen, wenn es einen Grund dafür gibt, „also nicht lediglich auf Vorrat ins Blaue“. In der Begründung zum Entwurf heißt es weiter, dass ein Abgleich mit Daten erfolgen soll, die der Verfassungsschutz selbst gespeichert hat – oder mit für ihn zugänglichen Daten von Verfassungsschutzbehörden der Länder. Biometrische Abgleiche soll die Behörde auch nutzen dürfen. Damit soll sie Videoüberwachung live auswerten dürfen und prüfen, ob eine Person im Visier der Behörde an einem bestimmten Ort auftaucht. Für den Zugriff auf entsprechende Kamera soll der Verfassungsschutz Betreiber verpflichten dürfen, Aufnahmen herauszugeben, live auszuleiten oder gleich die Videoüberwachungsanlagen mit zu nutzen – zumindest wenn es um Überwachung von öffentlich zugänglichen Räumen geht. Das heißt, der Verfassungsschutz dürfte in Echtzeit Kameras am Bahnhof oder im Einkaufszentrum anzapfen. Auch der BND soll biometrische Daten auswerten dürfen. Ein Vergleich mit öffentlich zugänglichen Daten aus dem Internet soll ausdrücklich erlaubt sein. Das Verständnis von öffentlicher Zugänglichkeit ist hier allerdings etwas anders gefasst, als man es erwarten könnte. Denn dazu zählen für das BMI „alle Bereiche des Internets, auch solche, die mittels einer vorgelagerten Zugangshürde geschützt sind“. Erst wenn „Schutzmechanismen über rein formale Hürden hinausgehen“ werde dann der Zugriff zum Einsatz eines „nachrichtendienstlichen Mittels“, für das andere Hürden gelten. Um biometrische Daten abzugleichen, müsste der BND laut Entwurf keine eigenen Mittel nutzen – ein Abgleich dürfte auch über öffentliche oder private Stellen im Ausland erfolgen, wenn er selbst oder andere deutsche oder europäische Stellen das nicht können. Das öffnet die Tore dafür, dass der BND am Ende Anwendungen nutzt, die es nach europäischen Datenschutzrechten nicht geben dürfte. Der Geheimdienst könnte bei außereuropäischen Partnern um Hilfe bitten, für die schwächere Regeln gelten. Geheimdienst-Kontrolle soll schlanker werden Für die Kontrolle des Inlands- und Auslandsgeheimdienstes sind bislang unter anderem die G10-Kommission, das Parlamentarische Kontrollgremium und der Unabhängige Kontrollrat (UKRat) zuständig. Die G‑10-Kommission soll dem Entwurf zufolge jedoch wegfallen. Das G‑10-Gesetz regelt derzeit, unter welchen Voraussetzungen in Deutschland die Geheimdienste von Bund und Ländern in das durch Artikel 10 des Grundgesetzes geschützte Brief‑, Post- und Fernmeldegeheimnis eingreifen dürfen und wie derartige Eingriffe kontrolliert werden. Künftig soll mehr Kontrolle im UKRat gebündelt werden, der neue Aufgaben bekommt und das Parlamentarische Kontrollgremium unterstützen soll. Bislang ist der UKRat als oberste Bundesbehörde nur für den Auslandsgeheimdienst BND zuständig. Laut Gesetzentwurf soll er künftig auch den Inlandsgeheimdienst kontrollieren. Ähnlich wie ein Gericht soll der UKRat besonders eingriffsintensive Einzelmaßnahmen beider Geheimdienste vorab genehmigen. Außerdem soll er die Dienste administrativ kontrollieren, etwa wie sie personenbezogene Daten verarbeiten. Mehr Befugnisse für den UKRat würden jedoch weniger Befugnisse für die Bundesdatenschutzbeauftragte bedeuten. Eine solche Schwächung der für Geheimdienste mitunter lästigen Behörde hatte die aus dem Amt scheidende Louisa Specht-Riemenschneider bereits befürchtet. Ihr Nachfolger Moritz Hennemann dürfte demnach nur noch weniger sensible Bereiche beaufsichtigen, etwa die Verarbeitung personenbezogener Daten bei der allgemeinen Verwaltung des BND oder bei Aus- und Fortbildungen. Noch weniger Transparenz als zuvor Einige neue Regeln sollen die Informationsfreiheit weiter einschränken. Schon heute sind die Geheimdienste vom Informationsfreiheitsgesetz ausgenommen und müssen keine Dokumente an Bürger:innen freigeben – außer es geht um Umweltinformationen. Künftig sollen für Bürger:innen selbst solche Informationen über die drei Geheimdienste des Bundes tabu sein, die anderen staatlichen Stellen vorliegen. Insbesondere soll das für den Unabhängigen Kontrollrat gelten. In der Begründung des Entwurfs heißt es: „Alle Tätigkeiten der Nachrichtendienste sollen nach dem Willen des Gesetzgebers vom Anspruch auf Informationszugang ausgeschlossen sein.“ Das hätte weitreichende Folgen. Nicht einmal eine Statistik über künftige Agent:innen in Ausbildung soll es noch geben. Eine Ausnahme im Gesetz für Hochschulstatistik soll verhindern, dass feindliche Akteure erfahren, wie viel Spionage-Personal Deutschland in Zukunft haben könnte. Während ihre Macht enorm wächst, sollen Deutschlands Geheimdienste also noch intransparenter werden. --- Die Arbeit von netzpolitik.org finanziert sich zu fast 100% aus den Spenden unserer Leser:innen. Werde Teil dieser einzigartigen Community und unterstütze auch Du unseren gemeinwohlorientierten, werbe- und trackingfreien Journalismus jetzt mit einer Spende.

netzpolitik.org

China's industry regulator flags 'backdoor' risk in Claude Code #cybersecurity #infosec

China's industry regulator flags 'backdoor' risk in Claude Code

(China Daily) China's industry regulator has flagged security risks in Claude Code, an artificial intelligence programming tool developed by US startup Anthropic, warning that certain versions could expose sensitive user information through unauthorized data transmission.   The Ministry of Industry and Information Technology's Network Security Threat and Vulnerability Information Sharing Platform said on Wednesday that it had detected a potential "backdoor" risk in Claude Code, describing the threat as serious.   Claude Code, an AI coding assistant that can independently generate, debug, and modify software based on natural-language instructions, has become part of a new wave of AI tools reshaping software development.   The NVDB said affected versions range from 2.1.91 to 2.1.196. It alleged that the tool's built-in monitoring mechanisms could transmit sensitive information — including users' location data and identity-related identifiers — to remote servers without user authorization.   The platform urged companies and developers using affected versions to immediately conduct security checks and remove the vulnerable versions or upgrade to the latest releases that have eliminated the relevant code.   It also advised organizations to tighten controls over external connections from development tools on critical business networks and strengthen traffic monitoring to prevent unauthorized leakage of sensitive data. Source: By Cheng Yu | chinadaily.com.cn | Updated: 2026-07-08 14:38

technologynewschina.com

Suspected Chinese snoops caught breaking into universities' Roundcube mailservers #cybersecurity #infosec

Suspected Chinese snoops caught breaking into universities' Roundcube mailservers

Suspected Chinese spies have been breaking into major US and Canadian universities since May, exploiting vulns in Roundcube mailservers to steal data belonging to physics and engineering administrators and professors, according to Proofpoint threat researchers. Proofpoint directly observed “less than 10” universities targeted in these intrusions, Greg Lesnewich, principal threat research engineer at Proofpoint, told The Register. “We estimate the total volume of targets would be a few dozen universities, but stress that this is at best a guess, not substantiated by our data.” While the most recent sighting occurred in early June, “we believe it is likely that the campaign is ongoing,” Lesnewich said. The email security shop tracks the crew as UNK_MassTraction, and says that it focuses on individuals in departments with national security ties or in astrophysics and particle physics - all topics that support Beijing’s intelligence-gathering goals and, as such, are frequently targeted by government-backed cyber goons. To gain initial access, the intruders exploit CVE-2024-42009, a cross-site scripting vulnerability in Roundcube that only requires that the email is opened in the mail client to achieve access to the server. “The targeted departments were likely specifically chosen because they were all running [vulnerable] versions of Roundcube … indicating that UNK_MassTraction had conducted reconnaissance into the targets prior to conducting the campaign,” the threat hunters wrote in a Tuesday blog. While the espionage activity is similar to an earlier campaign disclosed by Trellix that used a filename parsing vulnerability to deliver VShell malware, a Go-based backdoor used primarily by Chinese APT groups for remote access, file operations, and post-exploitation control, Proofpoint says it cannot definitely link this earlier activity to UNK_MassTraction. It all starts with a generic phishing email The UNK_MassTraction attack chain begins with a phishing email sent to university departments from both compromised legitimate senders and abused domains vulnerable to spoofing. According to the threat hunters, the lures are generic, sometimes purporting to be a university marketing message, and this could imply “a larger targeting swath” than Proofpoint observed. It could also indicate “an attempt to resemble marketing or spam content because targets may open the email but ultimately overlook it (and not investigate it), which is still sufficient for the actor to gain access,” they wrote. Opening the email triggers CVE-2024-42009. The bug abuses a desanitization issue, and can allow remote attackers to steal and send messages. Once the user opens the email in the webmail client of a vulnerable Roundcube instance, a JavaScript loader stored in the message body executes, and allows the attacker to remotely deliver a fully functioning stealer called IceCube. IceCube first escapes Roundcube's iFrame instantiation via DOM traversal, which gives the stealer access to the entire Document Object Model (DOM) in the browser and Roundcube authentication session. Then it sets to work stealing usernames, passwords, session tokens, and cookies, and it also conducts reconnaissance against the browser, collecting info on the language in use, screen size, and form field values. The stealer sends this initial data to the attacker’s command-and-control servers via HTTP POST, and then uses the session’s CSRF token to set up gadgets to exploit another Roundcube vulnerability. This one, a deserialization exploit tracked as CVE-2025-49113, allows the miscreants to install a webshell called SquareShell that allows for remote code execution, as well as a VShell implant. Proofpoint notes that its researchers scanned for SquareShell on compromised servers, and coordinated with government and industry partners to notify the identified victims. As of June, the threat hunters also observed the attackers introducing a fallback channel in case the original webshell deployment didn’t work. Previously, if the webshell didn’t execute, the attack chain would fail. More links to PRC-backed spies The fallback channel executes a shell script that sets up the execution of another loader that Google tracks as SnowLight. “The shell script has been used in other exploit-driven intrusions by Chinese adversaries, likely indicating a privately shared capability,” Proofpoint notes. Proofpoint’s security sleuths say that they have identified “several cases” of virtual private server IP addresses within the headers of the phishing emails that belong to a “covert infrastructure network likely used by multiple China-aligned threat actors.” The access to this network, along with the low-volume targeting of US and Canadian universities, VShell usage, and Chinese-language artifacts within the phishing emails, “leads us to assess that UNK_MassTraction is likely a China-aligned espionage motivated threat actor that has demonstrated moderate operational security awareness,” the team wrote.®

theregister.com

Cybersecurity Mission Creep in the US #cybersecurity #infosec

Cybersecurity Mission Creep in the US

Interesting paper: “Cybersecurity Mission Creep.” Abstract: Cybersecurity is experiencing mission creep. Policymakers are casting more and more problems as issues of cybersecurity. So reframed, wildly different policy issues, from misinformation, to child social media safety laws, to antitrust regulations, to alleged journalist misconduct, to anti-sex trafficking statutes become what this Article calls “cybersecuritized.” Before this reframing, these issues present as important but not existential. But once cybersecuritization positions the issues as threats intensified by their technological nature, they gain access to the politics and law of urgency and exceptionalism and invite troubling governance responses. Positioned as security threats, cybersecuritized issues become endowed with the apparent normative power to override countervailing considerations, oversimplifying the problem. Cybersecuritization’s oversimplification similarly risks unidimensional solutions and invites use of argumentative trump cards, like First Amendment challenges. Cybersecuritization also invites deference to purported specialists and their proposed solutions. Together, the reductive tendencies of cybersecuritization and the deference it prompts to specialists renders ultimate governance choices more opaque. And this opacity can erode public trust and political legitimacy. This Article surfaces the phenomenon of cybersecuritization and offers a novel framework for analyzing and critiquing it. Mining cases from across criminal and civil domains, the account also demonstrates the insidiousness of cybersecuritization and the likelihood that it will continue to expand. Confronting cybersecuritization is crucial. If we continue to ignore it, we risk abdicating further responsibility for difficult choices to the trump card of cybersecurity. This Article’s analysis and critique aim to help reclaim the hard work of governance for our hands.

schneier.com

Council of Europe hacked in ShinyHunters' PeopleSoft heist #cybersecurity #infosec

Council of Europe hacked in ShinyHunters' PeopleSoft heist

ShinyHunters claims to have breached the Council of Europe and stolen more than 297 GB of data after exploiting a zero-day flaw in Oracle PeopleSoft and abusing that hole to hack more than 100 organizations. According to a post on the extortion crew’s data-leak site, the 429,000 pilfered files contain HR and payroll records, payslips, purchase-order records, CVs, and employees’ salary, banking, tax, and medical records. A Council of Europe spokesperson told The Register that it is “currently investigating the matter and assessing the situation,” but declined to comment further. A spokesperson for the cybercrime group told us that the Council is yet another victim of the Oracle PeopleSoft heist. Oracle has yet to respond to The Register’s inquiries, and it's unclear if the vulnerability, tracked as CVE-2026-35273, has been patched. ShinyHunters previously told us that the gang exploited the CVE to compromise more than 100 organizations across 300 vulnerable instances, and that these victims included the University of Nottingham. Last week, the crims listed the UK uni on their leak site, then dumped data belonging to around 454,600 current and former students, including personal and academic records. Meanwhile, a Google threat report published late last week noted malicious activity, “consistent with the exploitation of CVE-2026-35273,” between May 27 and June 9, and said that its incident responders notified more than 100 global orgs “whose IP addresses correlated with potentially vulnerable endpoints." Most of these are US-based organizations, and 68 percent operated within the higher education sector. This latest heist follows another ShinyHunters intrusion targeting data belonging to university and K-12 students, teachers, and staff. In mid-May, ed-tech giant Instructure said it “reached an agreement” - this is corporate-speak for “paid the ransom demand” - with the data theft and extortion crew after ShinyHunters breached its Canvas digital learning platform and accessed data tied to 275 million students, teachers, and staff. In March, ShinyHunters claimed it stole data from K-12 software provider Infinite Campus as part of a broader wave of Salesforce-related intrusions. The ed tech company did not pay up, and the group subsequently published data they claim was stolen from Infinite Campus, including 137,000 individuals’ email addresses along with names, phone numbers, physical addresses and support tickets. Infinite Campus, in its data breach notification, said that the leaked files largely consisted of “names and contact information for school staff" and that “the majority is directory information commonly found on school websites.” ®

theregister.com

France probes compromise of gov messaging platform after account hijack #cybersecurity #infosec

France probes compromise of gov messaging platform after account hijack

French officials are investigating a compromise of the government’s encrypted messaging service Tchap after attackers hijacked an account and gained access to public chat rooms. The incident came to light on June 7 when France's National Cybersecurity Agency (ANSSI) detected suspicious activity on Tchap, the government's homegrown messaging service used across ministries and public sector organizations. The French Digital Affairs Directorate (DINUM), which operates the platform, said it immediately began investigating the compromise and moved to block the affected account. French officials insist the damage was limited and said the attacker could only see messages posted in public chat rooms, which are accessible to all Tchap users. Private conversations, the government says, are encrypted, and their contents remain inaccessible even when an account is compromised. Not everyone is buying that version of events. A cyber criminal has claimed responsibility for the attack and said they were able to gain access after they “social engineered” a valid agent account associated with Tchap's education environment. The alleged hacker claims they accessed more than 73,000 user accounts, 643,000 messages, nearly 60,000 media files, and hundreds of chat rooms. The post, shared by Dark Web Intelligence, also claimed user enumeration was possible through a directory search function and suggested the data included references to documents marked "Diffusion Restreinte," a French government restricted-distribution classification. None of those claims have been independently verified, and DINUM's statement makes no mention of user directory exposure, restricted documents, or the volumes of data cited by the hacker. What French officials have confirmed is that investigators are still working through logs to determine exactly which conversations were accessed and whether any data was exfiltrated. The agency has also notified France's data protection watchdog, CNIL, after determining that personal information may have been exposed through content shared in conversations accessible to the attacker. “A message has been sent to all Tchap users reminding them that a public chat room can be found and joined by any user and that its content is not encrypted,” French officials added. “In accordance with Tchap's terms of service, no personal, sensitive, or confidential information should be exchanged in public chat rooms: such exchanges should be reserved for private chat rooms.” Whether the incident amounts to a limited exposure of public chat rooms or something considerably larger will depend on what investigators find in the logs, but for now, the government and the attacker are telling very different stories. ®

theregister.com