This week's articles
Frontier Forensics: OpenAI
A guide to evidence sources, logging, and retention across ChatGPT Workspace, the API Platform, and agentic workloads.
Aurora ransomware targets ESXi abuses Cursor Agent for exploitation
Aurora ransomware (active since April 2026) deploys a Linux/ESXi encryptor using ChaCha20+RSA-4096, kills VMs via esxcli before encrypting VMDK files, and abuses Cursor Agent (Claude Sonnet) to conduct hands-on exploitation across ten victim organizations. Russian-language operator instructions prohibited DCSync, account lockouts, and adding domain computer objects.
Breaking Claude Code Opus 5 Auto Mode
A multi-stage indirect prompt injection attack against Claude Code Opus 5 in Auto Mode achieved 60-80% RCE success via HTTP 415 trickery, ZIP-delivered Python module shadowing (struct.py), and C2 callbacks.
The Docs Say It's OK: When Documentation Replaces a Fix in Vertex AI
Two Vertex AI privilege escalation paths let holders of aiplatform.customJobs.create or aiplatform.reasoningEngines.create steal highly privileged Google-managed service agent tokens, reaching project-editor-equivalent access. Google's response: add documentation warnings instead of patching.
|