Summaries
Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.
Showing 1-3 of 3 results
| Date | Provider | Score | Summary |
|---|---|---|---|
| 28 Sep 2026, 5:08 PM | The Hacker News | 7.5 | JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
Microsoft, tracking the actor as Storm-3168, reports that JADEPUFFER-linked attackers used two compromised service principals in a single Azure tenant to run destructive operations over about 18 hours in early June 2026, deleting Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines, and App Services. JADEPUFFER was first documented by Sysdig as the first ransomware operation run end-to-end with an LLM, entering through a known Langflow flaw (CVE-2025-3248), and the same Langflow instance was later hit again with ENCFORGE, a Go-based strain that scans roughly 180 file extensions covering model checkpoints, vector databases, training datasets, and embedding indices, plus macOS Keychain stores, Xcode project files, and Apple Pages and Numbers documents. Why: Three concrete decisions: patch Langflow for CVE-2025-3248 if you self-host it, because that was the documented entry point. Don't assume Azure-native recovery saves you here, since recovery protection locks were among the deleted resources, so keep copies of vector databases, model checkpoints, and training datasets outside the subscription that runs them. And inventory your service principals and what each one can delete, because the access in this incident came from service principals in one tenant, not from user accounts. |
| 03 Oct 2026, 10:36 PM | The Hacker News | 3.5 | Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
Symantec and Carbon Black's Threat Hunter Team report that the actor tracked as Warlock (also Longlegs, Gold Salem, Storm-2603) is still exploiting Microsoft SharePoint Server flaws to attack on-premises deployments, hitting at least four organizations in two months — two critical infrastructure operators (a water utility and a telco), a regional government body, and a university — all in Portuguese- and Spanish-speaking countries. In one intrusion the attackers disabled security software on at least 40 hosts in about two hours, then deployed ransomware to at least 33 hosts by staging the payload in the domain's SYSVOL share so ordinary domain replication delivered it. Entry relies on web shells that harvest the SharePoint farm's ASP.NET machine keys, which are then used to forge a validly signed payload and get remote code execution inside the SharePoint application pool, alongside BYOVD and legitimate tools like Velociraptor for command-and-control. Why: If your organization runs SharePoint Server on-premises — still common in enterprise and government environments — this is a concrete reason to check patch status and, more importantly, treat ASP.NET machine keys as compromised material: stealing them lets an attacker forge signed payloads and execute code in the SharePoint app pool, so patching alone may not evict them. The SYSVOL staging detail also means your normal AD replication is the delivery mechanism, so watching for unusual file writes to SYSVOL and unexpected security-tool service stops is more useful than another perimeter alert. For everyone else, this is enterprise Windows infrastructure, not something most builders ship with — there is no Malaysia-specific detail in the source, and no stated impact on Malaysian organizations, cloud, payments, or startup tooling. |
| 02 Oct 2026, 12:55 AM | The Hacker News | 3.0 | Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
Police in Spain arrested a 16-year-old in Alicante on September 30, identified by Hamburg police as the suspected main administrator and operator of the KillSec ransomware group; two others were arrested, a man in his 20s in the U.K. and a 24-year-old in Romania (DIICOT searched four homes in Bucharest and Vaslui county and asked a Bucharest court to hold him 30 days). Authorities also seized KillSec's leak site and servers in an operation led by Hamburg police and prosecutors with Europol, the Guardia Civil, Mossos d'Esquadra, and U.S. prosecutors in Puerto Rico and the FBI's San Juan office; Puerto Rico has filed an extradition request for the U.K. suspect. Investigators named four roles in the group — administrator, developer, negotiator, affiliate — and said the suspected developer, identified but not arrested, turned 18 in August and was a minor when some alleged offenses took place. Why: There is no technical, tooling, or vulnerability detail here, so nothing in this item changes what you build or deploy this week. The one concrete fact worth noting is that the suspected developer was a minor during some alleged offenses and was not arrested, while the affiliate model spreads operations across jurisdictions — but the article gives no indicators of compromise, no KillSec tooling or TTP detail, and no Malaysia or Southeast Asia angle, so no defensive action follows from reading it. |