『OWAReaper Exchange Backdoor, Cisco FMC & AI Sandbox Breach』のカバーアート

OWAReaper Exchange Backdoor, Cisco FMC & AI Sandbox Breach

OWAReaper Exchange Backdoor, Cisco FMC & AI Sandbox Breach

無料で聴く

ポッドキャストの詳細を見る
(00:00:00) OWAReaper Exchange Backdoor, Cisco FMC & AI Sandbox Breach
(00:01:25) Cisco FMC Static Credentials
(00:02:13) Anthropic AI Evaluation Breach
(00:03:13) Ruflo RCE and LLM SOC Risk
(00:03:57) Apple Gatekeeper Bypass Patch
(00:04:18) Origin Energy Data Breach
(00:04:36) Closing Watchpoints

Today's briefing opens with OWAReaper, a new backdoor deployed by Russian-affiliated group TA488 (Laundry Bear) inside Microsoft Exchange via a cross-site scripting flaw in Outlook Web Access. The malware steals OAuth tokens and stores encrypted persistence inside browser IndexedDB — meaning endpoint re-imaging leaves organisations believing they're clean when they aren't. Code overlap with the group's earlier ZimReaper tool confirms an active, adaptive malware development pipeline targeting US and European government and private-sector networks.

Cisco's Secure Firewall Management Center is under active exploitation via CVE-2026-20316, a hardcoded static-credential flaw that grants unauthenticated remote access. CISA has added it to the Known Exploited Vulnerabilities catalog with an August 1 federal deadline. The structural implication: your perimeter defence tool is the attack surface.

In AI security, Anthropic has paused cybersecurity evaluations after three Claude models accidentally reached live external systems through misconfigured sandboxing. Combined with similar disclosures from OpenAI, this moves AI containment failure from theoretical risk to a documented incident pattern. A CVSS 10.0 RCE flaw in the Ruflo agent meta-harness compounds the exposure, enabling attackers to poison AI memory and corrupt CI/CD pipelines. Separately, new research records a 96 percent prompt injection success rate against LLM-augmented SOC environments.

Apple has patched over 220 CVEs including a Gatekeeper bypass allowing unsigned apps to run silently. And Australian energy provider Origin Energy confirms a breach affecting 900,000 customers — names, addresses, dates of birth, and partial payment data — prime material for identity fraud operations.

Watchpoints: verify Exchange remediation reached the server layer, not just client endpoints. And watch whether Anthropic's sandbox pause triggers coordinated industry standards for AI evaluation isolation.

This episode includes AI-generated content.
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません