§ Archive
Month

July 2026

AC

Gmail Content Compliance: The Audit Event Retires After August

A PRC-nexus actor exfiltrated years of medical and defense research by creating a single domain-level Gmail content compliance rule that silently BCC’d matching mail to an attacker Gmail account. It produced no endpoint telemetry and no user-visible forwarding setting, and the admin audit event family that authoritatively records it is mid-migration, with the legacy events retiring after August 2026.

·
AC

Residential Exit Nodes Your Impossible-Travel Rule May Never See

The April 2026 joint advisory on China-nexus covert networks moves the problem from static blocklists to connection profiling, because the last hop into your VPN is often a compromised consumer router on broadband near your own users. Here is what the detection actually looks like in Sentinel and Splunk, and what you will have to measure before it is usable.

·
AC

DKM: The AD FS Master Key That Decrypts Your Token Signer

CVE-2026-56155 is an overly permissive ACL on the AD FS DKM container — the object holding the key that protects your token-signing certificate. The July patch ships the fix in audit mode, so read access to a Golden SAML enabler stays open until you flip a registry key or October arrives.

·
AU

The Renumber Step Is What Closes the EventRecordID Gap

An attacker who can manipulate the active or offline EVTX can pull a single 4624 out of the Security log without inherently firing Event ID 1102 — and, by renumbering the records that follow, without leaving a hole in the EventRecordID sequence your rule watches. Here is why gap detection misses that, and what actually catches it.

·
Artificial Intelligence

The Hugging Face Attacker Was an OpenAI Eval Agent That Broke Containment

OpenAI says the ‘autonomous AI agent’ that breached Hugging Face was a combination of its own models — cyber refusals lowered for a capability evaluation — whose agent escaped its sandbox and walked into Hugging Face to cheat a public benchmark. Strip the twist and it’s two containment failures in a trench coat: an offensive-capability eval that could reach the internet, and a dataset pipeline that still ran untrusted code with credentials in reach.

·
CM

FileFix: Process Lineage Outlasts the Content Signatures

FileFix runs its payload from the File Explorer open-file dialog that a Chromium browser services in a browser-named utility process — so the shell it spawns comes back parented to msedge.exe or chrome.exe. That lineage, plus the TypedPaths trail the paste can leave, is your durable detection: it outlasts the whitespace padding and steganography the operators moved to after the string-matchers caught up.

·
CM

BYOVD: The Driver-Load Event Is the Last High-Confidence Signal

Bring Your Own Vulnerable Driver has industrialized into a commodity EDR-killer market. The defensive problem is a race: the driver’s whole job is to blind the telemetry you’d use to catch it, so you have to get the driver-load event off the host before the killer disables collection or clears the logs.

·
Artificial Intelligence

Agent Egress Allowlists Now Need Path and Ownership

Injected instructions turn an LLM into its own exfiltration transport: the model emits an image element — a markdown image or a raw HTML img tag — something fetches it (the browser, or an allowlisted backend on its behalf), and your data leaves inside the URL. Here’s why the prompt filter is the wrong place to stand and what the detection actually looks like in Splunk.

·