Connect with us

CyberSecurity

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

Published

on

Windows zero-day PoC

The Discovery: LegacyHive Explained

Just hours after Microsoft’s latest Patch Tuesday rollout, a security researcher known as Chaotic Eclipse (also going by Nightmare-Eclipse) dropped a new Windows zero-day PoC exploit. The proof-of-concept, dubbed LegacyHive, targets a vulnerability in the Windows User Profile Service — the core system component that manages user accounts and environments.

The flaw is an arbitrary hive load elevation of privileges vulnerability. In plain terms, it lets an attacker load a malicious registry hive into a privileged context, potentially gaining SYSTEM-level access. That’s about as bad as it gets for a local privilege escalation bug.

What makes this particularly troubling is the timing. Microsoft’s monthly security updates are meant to patch known vulnerabilities, but this PoC arrived right after the patch drop — suggesting either a missed fix or a newly discovered flaw that wasn’t addressed in time.

How the Exploit Works

The PoC requires an attacker to already have a foothold on the target system. Once they do, LegacyHive exploits the User Profile Service (also known as ProfSvc) to load a specially crafted hive file. This isn’t a remote code execution scenario — it’s a post-compromise tool that turns a low-privilege user into an administrator or SYSTEM.

According to the researcher’s description, the exploit leverages the way ProfSvc handles hive loading during user profile creation. By manipulating this process, the attacker can trick the service into loading a malicious hive in a privileged context.

Who’s at Risk?

Any Windows system with the User Profile Service enabled is potentially vulnerable. That includes Windows 10, Windows 11, and likely Windows Server versions. The exact affected versions haven’t been fully disclosed yet, but given that ProfSvc has been a persistent target for researchers, it’s safe to assume broad impact.

Why This Matters for Your Security Posture

This Windows zero-day PoC is a reminder that Patch Tuesday isn’t a magic bullet. Even after Microsoft pushes updates, there are gaps. Security teams should treat every patch cycle as a starting point, not a finish line.

The bigger concern is the speed at which PoCs appear. When a researcher releases exploit code, it’s only a matter of time before threat actors weaponize it. The window between PoC release and active exploitation is shrinking, and defenders need to move fast.

Immediate Steps to Mitigate Risk

  • Monitor Microsoft’s security advisories for updates related to the User Profile Service.
  • Restrict local access to critical systems — this exploit requires an initial foothold.
  • Use endpoint detection and response (EDR) tools to catch suspicious hive load activity.
  • Apply patches as soon as they’re available, but don’t assume you’re safe just because you’re up to date.

Response from the Security Community

The release has sparked discussion in security circles. Some researchers are praising the PoC for its technical elegance, while others are questioning the ethics of releasing exploit code without a working patch. It’s a familiar debate — one that’s been playing out in the infosec community for years.

Chaotic Eclipse has a history of publishing research on Windows internals, and this isn’t their first zero-day. But the timing here feels deliberate. Dropping a PoC right after Patch Tuesday maximizes visibility and pressure on Microsoft to address the issue quickly.

What’s Next for Microsoft and Users

Microsoft hasn’t issued an official response yet, but given the nature of the vulnerability, they’ll likely fast-track a fix. In the meantime, users should be extra cautious about running untrusted code and limiting user privileges where possible.

For those following the broader Windows security landscape, this is another data point in a trend: privilege escalation bugs are becoming more common, and the tools to exploit them are getting more sophisticated. The Patch Tuesday zero-day cycle is no longer just about waiting for the next update — it’s about proactive defense.

Stay tuned for updates as more details emerge about LegacyHive and its impact. If you’re responsible for enterprise security, now is the time to review your privilege escalation defense strategies and ensure your detection rules are up to date.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

CyberSecurity

The Approval Gap Nobody Talks About: How a Single Tag Can Expose Your Entire Site

Published

on

approval gap ad tech

The Quiet Danger in Your Marketing Tags

One approved marketing tag. That’s all it takes.

Behind that single snippet of code, a fourth-party script can quietly load—something your security team has never reviewed. No ticket. No sign-off. Just silent access to your forms, your customer data, and your checkout pages.

This isn’t a hypothetical. It’s a pattern that repeats across thousands of sites, and it’s called the approval gap.

What Exactly Is the Approval Gap?

The approval gap forms when a vendor you trust (a second party) integrates another vendor (a third party), which then pulls in code from yet another source (a fourth party). Each step adds functionality—but also risk. At some point, nobody remembers who approved what.

Your marketing team approved the original tag. Your security team never saw the fourth-party script. And by the time anyone notices, that script has already been reading session data or skimming payment fields.

Why AI Makes It Worse

AI-era ad tech accelerates this problem. Tools now auto-generate tags, swap providers dynamically, and optimize campaigns in real time. That means the code on your page today might not be the code you approved last week.

The attack surface isn’t shrinking. It’s compounding.

What a Single Rogue Script Can Actually Do

Let’s be concrete about the blast radius:

  • Form hijacking: Capturing every email and password typed into your lead-gen forms.
  • Payment skimming: Reading credit card fields at checkout—often without breaking the page’s functionality.
  • Session theft: Exfiltrating cookies and tokens to impersonate logged-in users.
  • Data leakage: Sending customer PII to servers in jurisdictions your compliance team never approved.

None of this requires a sophisticated attacker. It just requires one overlooked line of code.

Closing the Gap Before Someone Else Finds It

The webinar walks through a practical blueprint for closing this gap. It’s not about blocking all third-party scripts—that would break your ad operations. It’s about visibility and control.

Key steps covered in the session include:

  1. Inventory everything: Map every script on your site, including the ones you didn’t explicitly approve.
  2. Establish an approval workflow: Make it impossible for a tag to go live without a security review.
  3. Monitor continuously: Set up alerts for unexpected code changes, not just annual audits.
  4. Automate enforcement: Use tools that block unapproved scripts in real time, not after the fact.

Why Waiting Is Costly

An auditor, regulator, or attacker could find the gap first. The difference is what happens next. An auditor issues a finding. A regulator issues a fine. An attacker issues a data breach notification.

None of those are good outcomes—but only one of them ends up in the news.

Watch the On-Demand Webinar

This on-demand webinar is now available. It explains how the approval gap forms, why AI-era ad tech makes it worse, and how your team can close it before someone else exploits it.

If you’re responsible for marketing tag security or ad tech compliance, this session is worth the 30 minutes.

The gap is real. The fix is knowable. The only question is whether you’ll act before an attacker does.

Continue Reading

CyberSecurity

Nuclear Sabotage Malware Test Trips Up Most Frontier AI Models

Published

on

AI malware benchmark

The Benchmark Nobody Asked For — But Everyone Needed

SentinelOne just dropped a new benchmark that puts frontier AI models through a brutal, real-world test: reverse-engineering a piece of malware tied to Iran’s nuclear program. The results? Most models flunked.

The benchmark, built by SentinelLabs, uses the Fast16 malware — a 2005 Windows threat designed to interfere with LS-DYNA, engineering software allegedly used in Iran’s nuclear weapons development. Think Stuxnet, but earlier. And possibly American-made.

This isn’t another abstract AI quiz. It’s a long-horizon investigation that mimics what human reverse engineers actually do. The goal: see which models can sustain a trustworthy analysis across eight escalating stages, where new evidence repeatedly contradicts their earlier conclusions.

Which Models Passed — and Which Crashed

SentinelLabs tested OpenAI’s GPT-5.5 and the newer GPT-5.6 Sol, Z.ai’s GLM-5.2, and Anthropic’s Opus 4.x. Only GPT-5.6 Sol completed all eight stages — and it needed three separate runs at different reasoning-effort settings to do it.

GPT-5.5 never got past the first stage. The Opus models (4.7 and 4.8) produced solid local analysis but kept declaring the work finished before defects were resolved. GLM-5.2 stalled somewhere in between.

The gap wasn’t about technical skill or raw insight. SentinelLabs calls it project-scale recovery — the ability to withdraw a disproven conclusion, trace everything downstream that depended on it, fix the root cause, and carry that correction through the rest of the investigation. Patching the immediate error isn’t enough. Most models just can’t do that.

Why Fast16 Is the Perfect Test Case

Fast16 is a nasty piece of work. Discovered by SentinelLabs in April, it’s a Windows malware from 2005 that targets LS-DYNA, engineering software used to simulate complex physics — the kind of thing you’d need to design a nuclear weapon. The malware predates Stuxnet, and researchers believe it may have been developed by the United States to sabotage Iran’s nuclear program.

Using a real, historically significant malware sample makes the benchmark brutally practical. It’s not a synthetic puzzle. It’s the kind of investigation that could actually matter in a national security context.

The Human Factor: Why Analysts Still Matter

Even the winner made significant technical mistakes. SentinelLabs researchers concluded that human oversight remains essential — even GPT-5.6 Sol, the only model to finish, wasn’t exactly flawless.

“Senior reverse engineers remain essential,” the researchers said. “Even the strongest runs made semantic errors, accepted weak quality controls, and claimed readiness prematurely. We assess the best current use as supervised investigative agency, with human analysts defining objectives, exposing blind spots, and retaining final publication authority.”

In other words: AI can be a powerful assistant, but it’s not ready to run a malware investigation on its own. Not even close.

What This Means for Security Teams

This benchmark has real implications for how security teams should think about AI tools. If you’re considering using a frontier model to assist with malware analysis, you need to know its limits.

  • GPT-5.6 Sol is the only model tested that can sustain a full investigation — but it still needs human oversight.
  • Opus models are good at local analysis but tend to stop early, declaring victory before the job’s done.
  • GPT-5.5 can’t even get past the initial stage, which is a stark reminder that newer isn’t always better.

For security teams, the takeaway is clear: use AI to augment your analysts, not replace them. Define the objectives, expose blind spots, and keep final authority in human hands. The technology is improving, but it’s not there yet.

This isn’t just about malware analysis either. The same principles apply to other AI-driven security tasks, like vulnerability management automation or AI-powered threat hunting. The models can help, but they need supervision.

The Bottom Line

SentinelOne’s benchmark is a wake-up call for anyone who thinks frontier AI models are ready to handle complex security investigations on their own. They’re not. The technology is impressive — GPT-5.6 Sol’s ability to complete all eight stages is genuinely remarkable — but it’s still a tool, not a replacement for human expertise.

As AI continues to evolve, benchmarks like this will become increasingly important. They give us a realistic picture of what these models can and can’t do, and they help security teams make informed decisions about where to deploy AI assistance. For now, the message is simple: keep your senior reverse engineers close, and treat AI as a powerful ally — not a substitute.

Continue Reading

CyberSecurity

SASE Has an AI Blind Spot. Inspecting Packets Is No Longer Enough.

Published

on

SASE AI blind spot

The Old Playbook Worked. Until It Didn’t.

For years, routing traffic through cloud proxies was good enough. You’d push everything through a secure web gateway, inspect the packets, and call it a day. It was a solid model — when work happened inside the corporate perimeter and data lived in predictable places.

That world is gone. Work now happens in browsers, across SaaS applications, and inside a sprawling ecosystem of generative AI tools, unsanctioned browser extensions, and autonomous agents. Employees routinely paste intellectual property into ChatGPT prompts without a second thought. They upload customer lists to AI summarizers. They share source code with coding assistants.

And the packets? They look perfectly normal. That’s the problem.

Why Packet Inspection Hits a Wall

Packet inspection was designed for a different era. It could catch malware signatures, block known bad domains, and enforce URL filtering. But it can’t see what’s happening inside an encrypted session — and it certainly can’t understand context.

Think about what a packet actually reveals. It tells you that data moved from point A to point B. It doesn’t tell you whether that data was a harmless spreadsheet or your company’s entire customer database. It doesn’t know that the prompt being sent to an AI tool contains proprietary algorithms. It’s like a security guard who checks IDs at the door but never looks at what people are carrying inside.

Modern threats don’t announce themselves in packet headers. They hide in API calls, in browser extensions, in the normal-looking TLS traffic that makes up the vast majority of enterprise traffic today.

The Browser Is the New Perimeter

Here’s the uncomfortable truth: the browser has become the primary workspace. Email, documents, CRM, chat, even development environments — they all live in the browser now. That means the most sensitive data in your organization flows through a piece of software that most security teams treat as a black box.

Browser extensions make it worse. A single malicious extension can read everything a user types on any page. It can exfiltrate data to a remote server without ever triggering a traditional security alert. Packet inspection sees the traffic leaving — but it can’t tell you that the traffic shouldn’t be leaving in the first place.

AI Agents Are the New Wildcard

Generative AI didn’t just change how employees work. It changed how data moves. When an employee pastes a contract into an AI clause analyzer, or a developer asks an AI assistant to review code, the data leaves the corporate environment in ways that don’t fit the old inspection model.

Autonomous agents take this to another level. These aren’t employees making mistakes — they’re automated systems that can access multiple applications, retrieve data, and make decisions. They don’t get tired. They don’t make judgment calls. They just execute. And if an agent has access to sensitive data, it can move that data in ways that packet inspection simply can’t interpret.

The AI data security challenge isn’t just about blocking access. It’s about understanding intent. Was that API call legitimate business use, or was it data exfiltration disguised as a normal operation? Packet-level analysis can’t answer that question.

What SASE Needs to Evolve

This doesn’t mean SASE is obsolete. It means SASE needs to grow up. The architecture that worked for a cloud-first, but still mostly web-based, world needs to adapt to an AI-first, browser-centric reality.

Here’s what that evolution looks like:

  • Context-aware inspection: Instead of just looking at packet headers, security tools need to understand the full context — which user, which application, which data type, which action.
  • Data-level visibility: The ability to identify sensitive data as it moves, whether it’s in a document, a chat message, or an API call. This is about data classification, not just traffic inspection.
  • Browser-native security: Security that lives inside the browser itself, not just at the network edge. This gives visibility into extensions, page content, and user behavior.
  • API and SaaS protection: Monitoring the interactions between applications, not just user-to-internet traffic. Agents and integrations need the same scrutiny as human users.
  • Behavioral analytics: Detecting anomalies in how data flows — unusual access patterns, unexpected data volumes, or out-of-policy actions.

Some vendors are already moving in this direction. The shift from pure SASE to SSE (Security Service Edge) is part of it. But the industry needs to go further, treating the browser as a security control point and AI interactions as a first-class security concern.

The Cost of Ignoring the Blind Spot

Every day that security teams rely on packet inspection alone, they’re exposed. The data loss that happens through AI tools isn’t a hypothetical — it’s happening now, in every industry. Legal, healthcare, finance, technology — all of them have sensitive data flowing through AI applications that traditional security can’t see.

The question isn’t whether your organization will face an AI-related data breach. It’s when, and how much it will cost.

Security leaders need to ask themselves a hard question: is your SASE strategy built for the world as it was, or the world as it is? If the answer is the former, the blind spot isn’t just in your technology. It’s in your strategy.

The good news is that the tools to fix this exist. The challenge is adopting them before the inevitable incident forces the issue. Because when that happens, packet inspection won’t be able to tell you what went wrong — or what was taken.

Continue Reading

Trending