NEW#0001
Akamai2 days ago11 min▣LLM reporthigh Akamai researcher Shahak Morag demonstrated a 'Bring Your Own EDR' attack chain at DEF CON 34, abusing SentinelOne's exposed COM interfaces and installer validation to turn the EDR into a Trojan horse. By leveraging the SentinelHelper.1 COM object's Dump method, a local admin can dump any PPL-protected process, then chain this with PPLSystem to achieve unsigned code execution inside PPL processes such as Windows Defender. The attacker can install a rogue SentinelOne agent without a valid license, block management telemetry via local DNS manipulation, and use the EDR's own anti-tampering mechanisms to protect malicious payloads. The vulnerability was fixed in SentinelOne Agent version 26.1.1.
NEW#0002
Akamai4 days ago8 min▣LLM reporthigh Akamai's special SOTI report highlights how rapid enterprise AI adoption is expanding the threat surface through shadow AI usage, unmanaged browser/IDE extensions, and autonomous AI agents. Key findings include that 47% of enterprise AI conversations use personal accounts, 75% of AI browser extensions request high/critical permissions, and novel techniques like CometJacking and CursorJacking demonstrate how prompt injection and rogue extensions can compromise AI-driven workflows. Legacy security tools including DLP solutions are not designed to detect data exposure through AI prompts and unstructured interactions.
#0003
Akamai10 days ago8 min▣LLM reportcritical CVE-2026-66066 is a critical (CVSS 9.5) pre-auth remote code execution vulnerability in Ruby on Rails Active Storage, which uses libvips as its default image processor since Rails 7.0. An unauthenticated attacker can upload a specially crafted image that triggers unsafe libvips operations, enabling arbitrary file reads — most critically the application's secretkeybase and other environment secrets. With the secretkeybase compromised, the attacker can forge session cookies and achieve full RCE on the server. Immediate patching of Rails and libvips, along with rotation of all application secrets, is required.
#0004
Akamai17 days ago7 min▣LLM reportlow The article discusses Executive Order 14412, which sets binding PQC migration deadlines (2030/2031) for federal agencies and contractors, and argues that DNSSEC's reliance on RSA/ECDSA creates a currently unsolved quantum-safe migration challenge due to the much larger signature sizes of NIST PQC algorithms like ML-DSA. It emphasizes that most organizations lack visibility into their DNS estates, and that this lack of visibility—combined with DNS hygiene issues like orphaned records and dangling CNAMEs—creates subdomain hijacking risk that will worsen during cryptographic transitions. The piece is a vendor advisory promoting DNS estate visibility (via Akamai DNS Posture Management) as a prerequisite foundation for eventual PQC migration.
#0005
Akamai20 days ago8 min▣LLM reportcritical A critical vulnerability chain in WordPress Core (CVE-2026-63030 and CVE-2026-60137) allows unauthenticated attackers to exploit a handler-alignment desynchronization flaw in the REST Batch API to bypass parameter sanitization and perform SQL injection. This injection can be chained through WordPress's object caching and post-processing behavior to escalate privileges, assume an administrative context, install a malicious plugin, and achieve full remote code execution on default installations. Patches are available upstream but many environments remain unpatched.
#0006
Akamai23 days ago9 min▣LLM reporthigh The article details a precision prompt injection attack methodology against AI agents, using a fictional travel agent called 'Varda' as a case study. The attack follows a kill chain approach: reconnaissance to extract system prompt logic, enumerate tools, and learn data schemas; then weaponization to craft a fake payment confirmation that satisfies the agent's preconditions for booking flights. The core vulnerability is that the LLM treats conversation history as trusted context, allowing attackers to inject fabricated tool responses and fake assistant messages that bypass sequential validation checks, enabling unauthorized action execution without proper authorization.
#0007
Akamai25 days ago5 min▣LLM reportlow This article provides an overview of the post-quantum cryptography (PQC) landscape, covering newer signature algorithms (FN-DSA/Falcon, SLH-DSA), composite signatures, and the IETF PLANTS working group's development of Merkle Tree Certificates to address TLS handshake bloat. It notes that while symmetric encryption remains quantum-safe, the industry is accelerating PQC adoption timelines to 2029 in response to research suggesting cryptographically relevant quantum computers may arrive sooner than expected.
#0008
Akamai25 days ago8 min▣LLM reporthigh Akamai's SOTI Security report details how agentic AI is reshaping the threat landscape for commerce, with a 19% YoY increase in AI bot traffic and over 200 billion application/API attacks between 2024 and 2025. Attackers are exploiting consumer-facing chatbots through logic manipulation, back-end AI agents via prompt injection, and public AI endpoints for token freeloading. The retail vertical bore the brunt of Layer 7 DDoS activity (84%), with hacktivist groups like 313 Team leveraging Mirai-derived IoT botnets and browser impersonation for multi-vector attacks.
#0009
Akamai26 days ago10 min▣LLM reportcritical Attackers are actively exploiting CVE-2025-3248, a critical RCE vulnerability in Langflow's code validation API, to deploy a customized Gafgyt DDoS bot on AI development servers. The bot uses a modified RC4 stream cipher for C2 communications and is optimized purely for network flooding attacks (UDP, TCP, HOLD, Junk). AI infrastructure is targeted due to high bandwidth availability, shadow IT deployment practices, and permissive egress filtering.
#0010
Akamaiabout 1 month ago8 min▣LLM reportcritical CVE-2026-48282 is a critical unauthenticated path traversal vulnerability in Adobe ColdFusion's RDS FILEIO handler, exploitable via the /CFIDE/main/ide.cfm?ACTION=FILEIO endpoint. An attacker can send crafted HTTP requests with traversal sequences to read or write arbitrary files on the server, potentially achieving remote code execution by writing malicious .cfm files into web-accessible directories. Adobe has released patches under bulletin APSB26-68 for affected versions (2025.9 and earlier, 2023.20 and earlier).
#0011
Akamaiabout 1 month ago7 min▣LLM reportlow Akamai researchers developed a hybrid CNN-BiLSTM-Attention deep learning framework for real-time detection of Domain Generation Algorithms (DGAs) used by modern malware for resilient C2 communications. The approach specifically targets dictionary-based DGAs that generate human-readable domains mimicking legitimate traffic, which traditional static defenses and entropy-based detection methods fail to identify. The framework incorporates adaptive retraining strategies to counter concept drift as DGA techniques evolve.
#0012
Akamaiabout 1 month ago9 min▣LLM reportmedium The upcoming MCP 2026-07-28 specification fundamentally reshapes the protocol's security model by moving to a stateless architecture, eliminating protocol-managed sessions, and mandating OAuth 2.1 with PKCE. While this removes historical attack vectors like session hijacking and unsolicited server prompts, it introduces new risks: client-controlled state objects and tracking IDs enable cross-agent workflow hijacking, the _meta object allows metadata-based privilege escalation, new HTTP headers create desync and data leakage opportunities, MCP Apps bring stored XSS into AI interfaces, and asynchronous tasks introduce resource exhaustion DoS vectors. Security responsibility now rests squarely on MCP server developers and platform operators to implement cryptographic state verification, input validation, output encoding, and resource quotas.
#0013
Akamaiabout 2 months ago4 min▣LLM reportmedium Researchers identified a critical gap in AI chatbot security where assistants leak operational context, such as tool access and boundaries, through benign reconnaissance queries. This leaked information allows attackers to bypass static model guardrails and craft highly targeted prompt injections, highlighting the need for dynamic runtime protection.
#0014
Akamaiabout 2 months ago4 min▣LLM reporthigh The updated NIST SP 800-81r3 guidelines elevate DNS to a critical security control layer, highlighting severe risks from misconfigurations such as dangling CNAMEs, lame delegations, and exposed resource records. Automated scanners and AI bots are increasingly exploiting these vulnerabilities at scale to hijack subdomains and map infrastructure, necessitating continuous DNS posture management and cryptographic protections like DNSSEC.
#0015
Akamaiabout 2 months ago4 min▣LLM reporthigh In May 2026, a major Indian public sector bank was targeted by sophisticated, multi-vector DDoS attacks peaking at 1.78 Tbps and 171 Mpps. The attackers aimed to overwhelm network bandwidth and compute resources by targeting a critical login endpoint using globally distributed infrastructure. The attacks were successfully mitigated at the edge using preconfigured protections and continuous traffic profiling, resulting in no service disruption.
#0016
Akamai2 months ago4 min▣LLM reportmedium The transition to Post-Quantum Cryptography (PQC) introduces significantly larger cryptographic signatures, such as ML-DSA, which will force DNS responses to exceed standard UDP packet limits. This architectural shift will cause frequent fallbacks to TCP, introducing latency spikes and silent timeouts that pose a severe operational risk to automated, high-volume systems like agentic AI workflows. Furthermore, adversaries are already conducting 'Harvest now, decrypt later' attacks, underscoring the immediate need for organizations to map and secure their DNS and DNSSEC configurations across distributed cloud environments.
#0017
Akamai3 months ago4 min▣LLM reportcritical A critical SQL injection vulnerability (CVE-2026-9082) in Drupal core allows unauthenticated attackers to exfiltrate sensitive data or bypass authentication. The flaw specifically affects Drupal environments utilizing a PostgreSQL database backend alongside the JSON:API, Views, or Entity autocomplete modules, stemming from the improper sanitization of PHP array keys before they reach the database abstraction layer.
#0018
Akamai3 months ago6 min▣LLM reporthigh A sophisticated attack campaign is targeting Ollama AI endpoints to deploy a custom Go-based P2P remote access Trojan (RAT) and cryptominer. The malware, named 'vc', leverages decentralized networking via libp2p to evade traditional C2 blocking and utilizes RAM disk execution and process masquerading to maintain stealth.
#0019
Akamai3 months ago5 min▣LLM reporthigh Financial services are facing an escalating threat landscape characterized by massive DDoS attacks, AI-empowered botnets, and targeted web attacks against API endpoints. Attackers are increasingly exploiting overlooked DNS misconfigurations and leveraging hyperscale IoT botnets to bypass traditional IP reputation defenses, necessitating a shift toward behavioral heuristics and adaptive security architectures.
#0020
Akamai3 months ago4 min▣LLM reportcritical CVE-2026-42945, dubbed 'NGINX Rift', is a critical heap buffer overflow vulnerability in the NGINX HTTP rewrite module (ngxhttprewrite_module). It allows unauthenticated attackers to cause a Denial of Service (DoS) or potentially achieve Remote Code Execution (RCE) by sending crafted HTTP requests to servers configured with specific rewrite directives containing unnamed PCRE captures and a question mark.