Simon H

@simonbim.bsky.social

Innovate UK & UKRI Head of Supply Chain & Cyber Systems Resilience. Delivering R&D in Digital & Tech @InnovateUK, wrangling startups and policymakers. Personal views.

The Danish central bank has launched a financial systems security project to establish a Dormant Emergency Bank (DEB) to serve as a robust reserve bank in the event of a massive cyberattack against a large banking institution or the wider banking infrastructure in Denmark. gfmag.com/news/denmark...

Denmark Readies Emergency Reserve Bank to Fight Cyberattacks

Danmarks Nationalbank is developing a Dormant Emergency Bank and card payment contingency system to keep critical payments moving during major cyberattacks.

gfmag.com

AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware

AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware

Malware operators are increasingly using tools built to extend artificial intelligence as a delivery route. A newly documented campaign called AgentBaiting uses fraudulent AI Skills and Model Context Protocol, or MCP, servers to distribute SmartLoader malware through trusted-looking GitHub projects and public capability catalogs. The operation turns a routine search for an AI integration into a malware risk. Victims can be steered to ZIP archives presented as useful installers, then encouraged to extract and run files that have no connection to the advertised tool. Island researchers identified the campaign while tracking the wider FakeGit operation. Island said in a report shared with Cyber Security News (CSN) that it found about 7,600 malicious repositories created by roughly 6,600 profiles, including more than 800 posing as AI Skills or MCP servers. The campaign’s reach makes it more than a typical developer scam. The AI-focused wave built through March and peaked in April 2026, while malicious projects appeared more than 600 times across public AI registries and catalogs. The scale of the FakeGit operation (Source – Island.io) Researchers also measured more than 14 million downloads from release assets in approximately 200 campaign repositories. AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers FakeGit builds credibility through copied projects, lookalike accounts, convincing documentation, and modest engagement numbers. One lure copied the name and positioning of a popular Claude Skills collection, then offered a confirmed SmartLoader ZIP archive as the download. The approach echoes earlier  fake GitHub malware delivery  activity that exploited familiar development workflows to gain trust. The fake Mann1988 – awesome-claude-skills repository imitates the original ComposioHQ – awesome-claude-skills project (Source – Island.io) The lures target both personal and business tasks, including email, messaging, analytics, build systems, cloud services, and developer tools. Their names make downloads appear relevant to daily work instead of suspicious. Island found that 62 malicious repositories were positioned for enterprise or developer-internal use, while nearly two-thirds of MCP lures claimed to connect cloud services, databases, or APIs. A repository named  45d5r/databricks-mcp-server  shows how the infection begins. Its documentation advertises an enterprise integration and provides a download button, but the linked archive contains a command launcher, a renamed LuaJIT-style runtime, and an obfuscated Lua program disguised as a text file. Running the launcher activates the concealed payload rather than installing an MCP server. Related variants can hide their console windows, locate their command server through a value stored in a Polygon smart contract, create scheduled-task persistence, and retrieve encrypted stages from GitHub. The FakeGit attack chain (Source – Island.io) The stages eventually inject StealC into another process, continuing the credential-theft threat covered in reporting on the  StealC infrastructure disruption . AI Discovery Becomes Risk AgentBaiting changes the threat because an AI agent can discover the malicious project without a victim receiving a direct link. During testing, researchers found that Claude Code, Gemini, and ChatGPT could independently surface campaign repositories when asked to find a Skill or MCP server. The results varied, but still exposed a dangerous gap. One tested agent recommended a benign option while also repeating malicious installation instructions as an alternative. In another test, Gemini returned a malicious Walmart MCP repository as its first result, while ChatGPT listed the same repository among public options and highlighted it as a starting point. Public registries can further expand that exposure. Island found more than 600 campaign listings across LobeHub, Glama, MCP.so, and MCP Market, with some reproducing attacker-written documentation and download instructions. That gives malicious repositories another layer of credibility, particularly as  MCP server security concerns  grow around AI integrations that can access business resources. Organizations should rely on a curated and reviewed catalog for Skills, MCP servers, and agent plug-ins instead of unrestricted discovery. Campaign-linked Skills and MCP servers (Source – Island.io) New capabilities should be tested in an isolated environment without browser sessions, cloud credentials, SSH keys, or production data. A supposed AI capability distributed as a Windows ZIP containing a launcher and hidden payload should be rejected. Teams should verify publishers as carefully as projects, since star counts, copied profiles, and registry listings do not establish legitimacy. They should monitor downloads, Git clones, shell commands, and changes to MCP or Skill configurations initiated by agents. Maintaining an inventory of each capability’s repository, commit, version, and package hash can speed investigation. If SmartLoader execution is suspected, security teams should isolate the endpoint and revoke active browser sessions, OAuth grants, API tokens, cloud credentials, and developer credentials. Password resets alone may not be enough because StealC can steal live sessions, browser data, email and remote-access credentials, screenshots, and host details. Indicators of Compromise (IoCs):- Type Indicator Description GitHub repository hfgwyge/yu-ai-agent Fake AI agent repository File name yu-ai-agent-1.0-beta.3.zip SmartLoader package SHA-256 216a2c99fd42c00f9323d8b16dd19f622f7f4778b2b1d7cf07a3de5621f2 Package hash GitHub repository Mann1988/awesome-claude-skills Fake Claude Skills repository File name awesome-skills-claude-3.3.zip SmartLoader package SHA-256 91e5dbfaf45edf25fbc2168f92083e05dfa427afa7633e991392e33cc743 Package hash GitHub repository h4vzz/awesome-ai-agent-skills Fake AI agent Skills repository File name agentaiawesomeskills2.0.zip SmartLoader package SHA-256 498fe8fb806cd0e6685f97fc7d74de769dae5a28cdc821557b7585ad5ad Package hash GitHub repository StanLeyJ03/mcp-for-security Fake security MCP repository File name for-security-mcp-3.3.zip SmartLoader package SHA-256 62744baa8077bb8be237647fd78e3bea2ca0932bf4be3d5618600f971185 Package hash GitHub repository xbim08/awesome-claude-code-plugins Fake Claude Code plug-ins repository File name pluginsclaudeawesomecode2.4.zip SmartLoader package SHA-256 1da8df487d30b988f3c350c065206726aaa13f079a07151cd42ab557999 Package hash GitHub repository DomingosNgongo/walmart-mcp Fake Walmart MCP repository File name mcp-walmart-2.2.zip SmartLoader package SHA-256 c15693106682f2ddb26649cab6e1962a64537627cde4c5d3c79d5a0be8c7 Package hash GitHub repository 45d5r/databricks-mcp-server Fake Databricks MCP repository File name serverdatabricksmcp1.6.zip SmartLoader package SHA-256 66afc7d87d10dbe392898c4e5c613e0442fabb396415c2bef3a5ef2ac758 Package hash GitHub repository MauManto/jenkins-mcp-server Fake Jenkins MCP repository File name mcp-server-jenkins-3.2.zip SmartLoader package SHA-256 a33f40cab1ab7f971d3464af3e7595918107332b9e83342007571842b9e Package hash GitHub repository waynestimulative605/docker-mcp-gateway Fake Docker MCP gateway repository File name gateway-docker-mcp-v1.6-alpha.5.zip SmartLoader package SHA-256 3c858facbad66f5479e2c4add171421dc1b6488b36f33e7cff073aba585 Package hash GitHub repository lucaducapuca/alibabacloud-bigdata-skills Fake Alibaba Cloud Skills repository File name alibabacloud-skills-bigdata-v1.7.zip SmartLoader package SHA-256 fc1278f419e611bf40ca414099bfd9ad98a31ffb054371e8cb65a84849b Package hash Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. ->  Integrate ANY.RUN With Your SOC  Now . The post AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware appeared first on Cyber Security News .

cybersecuritynews.com

Large fires in the Peak District, Cairngorms and north Wales are now effectively competing for limited firefighting helicopter resources. On Saturday, Welsh farmers said they felt abandoned - while authorities had approved helicopter use, they were still waiting for one to be available.

Bild

ActiveState has sponsored the latest IDC Analyst Brief on open source software governance at scale. What the IDC Analyst Brief found: curated open source catalogs are the only governance model that intervenes at the point where the problem actually starts. Learn more here:

IDC Analyst Brief | Securing Open Source at Scale: How Consumption Complexity Creates Supply Chain Risk

ActiveState commissioned this IDC Analyst Brief to examine how AI coding assistants and open source consumption complexity are outpacing enterprise governance programs, and what security leaders can…

buff.ly

Two baby beaver kits have arrived at Ealing's Paradise Fields. Reintroduced in 2023 with Ealing Wildlife Group and Citizen Zoo, beavers are already stopping Greenford station from flooding and saving us money on infrastructure. Here’s what they’ve been up to 🦫

Wait, wait, wait… So Anthropic is trying to play the victim now? Weren’t they the ones pushing for restrictions on open source AI and advanced AI chips while advocating for closed source frontier models? It sure looked like policies that would favor companies like theirs.

Open-source AI models benefit from restrictions on frontier systems, Citi says By Investing.com

Open-source AI models benefit from restrictions on frontier systems, Citi says

investing.com

Day-0 support for the MiniMax M3 model family is officially live on vllm (a @pytorch.org Foundation project). This release makes it practical to serve heavy production workloads like million-token contexts and native multimodal reasoning—without sacrificing speed. Read more: https://bit.ly/4gzVl5M

MiniMax M3 in vLLM: Day-0 Serving for 1M-Token Multimodal Reasoning

How vLLM serves MiniMax M3 with MiniMax Sparse Attention, multimodal and reasoning parsers, MXFP8 weights, and long-context deployment recipes.

bit.ly

Just one possible outcome... but the GFS weather forecast model is suggesting 40-41°C is possible in the UK around 7th July. This is a long-range forecast with significant uncertainty, but the fact that we are even seeing such values fairly regularly in the forecasts is extraordinary.

GFS for 7th July

Commenters were deeply cynical about the long-term fallout. Some warned this erratic gatekeeping might backfire, pushing international developers toward open-source options or Chinese AI models that don't come with U.S. political strings attached. 4/4

Chinese AI- open source, focused on efficiency, semi-conductor self-sufficiency, and robotics especially for manufacturing, without the whackadoodle god-talk of AGI, has been better at integration and adoption. That’s also what places like Indonesia are being exposed to.

Still hand-crafting prompts every time you swap models? DSPy lets you define typed signatures and let optimizers tune the prompts for you automatically. Compile once, redeploy anywhere. Details on integrations and optimizers in the next post. #DevTools

Bild

Nearly Half of Apps Across LG and Samsung TV’S are Selling Your IP Address

Nearly Half of Apps Across LG and Samsung TV’S are Selling Your IP Address

New research found that 2,058 of 6,038 apps across the LG webOS and Samsung Tizen ecosystems included residential proxy SDKs , effectively turning smart TVs into exit nodes for third-party internet traffic. On screen, these apps look like harmless fish tanks, clocks, solitaire games, and puppies. However, under the hood, they operate as nodes in commercial residential proxy networks. Smart TVs are ideal targets because they share home networks with other devices yet receive little security scrutiny, and their always-on nature allows abuse to go unnoticed for years without obvious signs like battery drain or visible background activity. Spur emphasizes that this changes the consent equation; most users have no practical mental model for what it means to sell access to their residential IP. A single prompt navigated with a remote can disappear into the setup flow while the proxy keeps running indefinitely. proxy SDK prevalence by smart TV platform (source: Spur) The economic driver is straightforward. Many of these apps are designed to be quiet, ambient, or minimally interactive, where traditional advertising would ruin the experience. LG & Samsung TV Apps Selling IP Addresses By embedding a proxy SDK, developers can keep the app looking clean and ad-free while monetizing the TV’s connection in the background. In some cases, this trade-off is made explicit. Spur highlights a Pac-Man app on Tizen that frames Bright Data’s SDK as the ad-free option; decline, and you keep an ad-supported game; accept, and the app uses your TV’s network connection for web indexing . This creates a monetization fork where the choice is effectively between watching ads or letting the app turn your IP address into part of a proxy network. The proxy can keep running after the app is closed, enabling hidden background activity (source :Spur) Spur’s dataset also shows that this is not only a story of independent developers integrating third-party monetization. In many instances, the proxy company itself, or an entity using its name, appears to be the publisher. Bright Data, Bright Data Ltd, and Bright SDK together account for 367 proxy-flagged apps in the sample. At the same time, Honeygain UAB, a subsidiary of Oxylabs, appears as a publisher on additional apps. Spur argues that these look less like ordinary apps that happen to embed a monetization SDK and more like first-party proxy inventory: thin games, screensavers, and utilities produced at scale so the SDK has somewhere to run. Monetization Choice: Watch Ads or Join the Proxy Network (source : Spur) Amazon’s Device and System Abuse Policy explicitly bans apps that facilitate proxy services for third parties, and Roku has reportedly blocked Bright SDK and similar proxy services, with affected apps disappearing from its store after scrutiny. LG and Samsung, by contrast, have not published equivalent restrictions, leaving a regulatory gap that allows these proxy-enabled apps to proliferate on webOS and Tizen. Spur warns that once a TV app can act as a proxy, the risk extends beyond someone “borrowing” your public IP. Because the app runs on the home network, any weakness or change in the proxy provider’s filtering and policy enforcement could turn that TV into a foothold for reaching internal systems such as routers, NAS devices , printers, cameras, and developer machines. The investigation concludes that smart TV platforms need clear policies for residential proxy SDKs, prominent disclosures, and meaningful user controls. At the same time, consumers must recognize that even “boring” TV apps can quietly enroll their home networks in commercial proxy infrastructure powered by companies identified in Spur’s research. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates. The post Nearly Half of Apps Across LG and Samsung TV’S are Selling Your IP Address appeared first on Cyber Security News .

cybersecuritynews.com