BagheeraAltered's CyberSecurity Newsletter logo

BagheeraAltered's CyberSecurity Newsletter

Archives
Subscribe
June 29, 2026

Mythos is driving a new cybersecurity arms race

Chinese cybersecurity firm Qihoo 360 has escalated the global AI arms race by claiming to have developed an automated bug-finder that outperforms Anthropic's highly restricted Mythos model. Unveiled by CEO Zhou Hongyi at the Beijing Cybersecurity Conference, the new tool is being framed not just as a standard defensive measure, but as a critical strategic deterrent. Zhou explicitly likened advanced Western models like Mythos to cyber nuclear weapons, arguing that US access bans give America an unchecked advantage in discovering zero-days across global software infrastructure. By building its own parallel, machine-speed vulnerability discovery system rather than trying to replicate Western technology, Qihoo 360 is signaling a major shift in digital conflict where the ability to automatically unearth critical flaws is now a baseline requirement for national security.

Subscribe to this newsletter
I’m speaking at BlackHat

Chinese cybersecurity vendor Qihoo 360 claims it’s built an AI bug-finder that’s better than Anthropic’s Mythos model. CEO Zhou Hongyi revealed the model in a speech at the 14th Beijing Cybersecurity Conference, which Qihoo 360 organizes. Chinese media outlets have transcribed the talk, in which Zhou described Mythos as “equivalent to a ‘cyber nuclear weapon’,” because the USA’s ban on foreign nationals accessing the model gives America a tool with which to find flaws in software upon which other nations rely. Zhou thinks China needs equivalent capabilities as a deterrent, but suggested replicating Mythos is not a viable approach.
https://www.theregister.com/security/2026/06/26/chinese-cybersecurity-company-claims-its-built-a-better-than-mythos-bug-finder/5262642


For two decades, proving you’re human online has meant clicking traffic lights, squinting at warped text, or ticking an “I’m not a robot” box. In June 2026, Google began testing something a little more demanding: a reCAPTCHA that asks you to switch on your camera and wave at your own screen. The feature, called hand gesture verification, is part of Google’s reCAPTCHA service. It’s rolling out slowly as an option for websites, and it arrives at an awkward moment, just as people are growing more wary about how much of themselves they hand over to pass a routine security check. Ticking a few box was slightly annoying but performing for your webcam is a different ask.
https://blog.mega.io/google-hand-gesture-recaptcha

A critical Gemini CLI vulnerability allows OS command injection in continuous integration pipelines. Attackers can execute arbitrary code by supplying a malicious environment file. Developers must update their GitHub Actions workflows immediately to secure their build environments.
https://securityonline.info/gemini-cli-vulnerability/

SentinelLABS discovered the macOS Gaslight malware. This Rust backdoor attacks security analysts using prompt injection to break AI triage tools. Furthermore, it steals browser data and passwords while hiding its communications from defenders.
https://securityonline.info/macos-gaslight-malware/

Microsoft Exchange Server provides email and messaging services, and enables enterprise users to send, receive, and manage email through Outlook. Successful exploitation of CVE-2026-45504 requires an authenticated attacker with low privileges. Abusing the vulnerability could allow an attacker to read local files with system-level access. This will result in severe degradation of confidentiality. A Proof-of-Concept for the exploit is publicly available increasing the risk of exploitation.
https://ccb.belgium.be/advisories/warning-privilege-escalation-vulnerability-exchange-server-2016-2019-and-subscription

Qilin ransomware activity was detected involving AXIONLOG on June 29, 2026, followed by a separate listing involving TRANSCORE earlier the same day. At this stage, these incidents remain unverified claims from dark web monitoring sources, meaning the appearance of an organization on a ransomware group’s victim list does not automatically confirm that a successful breach occurred.
https://undercodenews.com/qilin-ransomware-dark-web-recent-claims-axionlog-and-transcore-reported-as-new-victims-in-growing-cyber-extortion-campaign-video/

GitLab has rolled out Community Edition (CE) and Enterprise Edition (EE) security updates that resolve 13 vulnerabilities, including three high-severity bugs. The most severe is CVE-2026-10086, an XSS flaw in the Analytics dashboard of GitLab EE, rooted in the improper sanitization of user-supplied input. According to GitLab, the security defect could have allowed an authenticated user with developer rights to execute arbitrary client-side code in the context of other users’ sessions.
https://www.securityweek.com/gitlab-patches-code-execution-information-disclosure-vulnerabilities/

CheatGPT, a dark web platform that presents itself as an AI-powered hacking assistant. At first glance, the website appears to be another attempt to capitalize on the popularity of AI by offering an underground alternative to mainstream chatbot services. However, a closer look reveals a far more interesting story. What began as a routine investigation into a dark web AI service gradually expanded into a broader examination of the infrastructure, payment systems, and contact mechanisms supporting the platform. Along the way, multiple connections emerged that suggested CheatGPT may not exist in isolation. Instead, it appeared to be part of a much larger ecosystem operating across the dark web.
https://stealthmole-intelligence-hub.blogspot.com/2026/06/from-chatgpt-to-cheatgpt-what-lies.html

Money mule networks have become a critical component of modern cybercrime and financial fraud ecosystems, enabling threat actors to launder and monetize proceeds generated through phishing, Business Email Compromise (BEC), banking malware, ransomware, investment scams, and account takeover operations. In recent years, traditional mule recruitment has increasingly evolved into professionalized Mule-as-a-Service (MaaS) ecosystems that provide scalable laundering infrastructure to cybercriminals.
https://www.kelacyber.com/blog/mule-as-a-service-money-laundering/

MASTA CVE-2026-48907 Scanner, Single-file, self-contained scanner for Joomla! JCE Editor < 2.9.99.5 — Unauthenticated Remote Code Execution (CVE-2026-48907)
https://github.com/gh1mau/masta-cve-2026-48907

Google told a security researcher his bug was a nice catch, lined up his payout, then eleven days later called it harmless and refused to pay a cent. The flaw he reported lets anyone with basic Kubernetes access take over a complete Google Cloud organization in about five seconds, with three lines of text and no special permissions at all. Months on, it still is not fixed. He named it ConfigConfusion, The man who found it goes by Justin O’Leary, a cloud bug hunter. What he found lives inside a Google tool called Config Connector.Config Connector lets teams manage their Google Cloud setup by writing simple text files in Kubernetes, instead of clicking around in the cloud console. You describe what you want in a file, and Config Connector goes and makes it happen on Google Cloud for you.
https://hackingpassion.com/configconfusion-google-no-bounty/

Copy Fail (CVE-2026-31431) is a logic bug in the Linux kernel's authencesn cryptographic template. It lets an unprivileged local user trigger a deterministic, controlled 4-byte write into the page cache of any readable file on the system. A single 732-byte Python script can edit a setuid binary and obtain root on essentially all Linux distributions shipped since 2017.
https://xint.io/blog/copy-fail-linux-distributions

A sophisticated Phishing-as-a-Service (PhaaS) platform called Bluekit has been confirmed operational at scale, with cybersecurity firm Netcraft detecting approximately 70 live hostnames in a single week. First documented by Varonis Threat Labs as an emerging tool still in development, Bluekit has since matured into a fully operational threat capable of bypassing multi-factor authentication (MFA) and harvesting Microsoft login credentials in real time.
https://cybersecuritynews.com/bluekit-paas-bypasses-mfa/

J&J Gaming, A U.S. amusement, arcade & attractions company added to the PLAY ransomware data-leak site. The actor claims theft of confidential corporate data and threatens to release it on the stated publication date. Volume and scope are unverified.
https://darkwebinformer.com/play-ransomware-allegedly-claims-u-s-firm-j-j-gaming/

Scammers in China are selling fake RTX 4090 graphics cards for around $222, using a plastic GPU die instead of real silicon. The counterfeit cards are marked with impossible future production dates like 2030 and contain no working VRAM, making them completely non-functional. A Chinese hardware shop owner discovered the scam after buying what was advertised as a broken but potentially repairable card. Physical inspection revealed the fake die had incorrect markings, a smooth plastic texture, no QR code, and lacked proper adhesive. This marks a new level of GPU counterfeiting, building on previous scams involving swapped or hollow dies. Buyers are strongly warned to avoid suspiciously cheap high-end GPUs and to thoroughly inspect hardware before purchase.
http://www.techamok.com/?pid=scammers-sell-fake-rtx-4090-with-plastic-gpu-die-for-just-222-26252

Microsoft has released a security update addressing CVE-2025-60727, a high-severity out-of-bounds read vulnerability in Microsoft Office Excel that enables arbitrary code execution on affected systems.
https://cyberpress.org/microsoft-365-apps-security-update/

Hackers have unleashed a new, highly deliberate ransomware family dubbed Prinz Eugen. Named after a World War II German heavy cruiser, this fresh Go-based encryptor stands out for its lack of a traditional ransom note, rapid infrastructure teardown, and aggressive targeting of actively used files. Security researchers recently investigated an intrusion and found that the threat actors rely heavily on Living off the Land (LOTL) techniques.
https://cyberpress.org/prinz-eugen-ransomware-attack/

A public proof-of-concept is now out for CVE-2026-55200, a critical flaw in libssh2 that lets a malicious or compromised SSH server trigger memory corruption on a connecting client, with possible code execution. No credentials, no user interaction. The bug affects every release up to and including 1.11.1 and carries a CVSS 4.0 score of 9.2.
https://cybersecurity.rozeepk.com/public-poc-released-for-critical-libssh2-cve-2026-55200-client-side-ssh-flaw

Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts. "This attack avoids the most common npm execution paths through lifecycle scripts, perhaps in an attempt to remain 'compatible' with npm v12's security hardenings," JFrog said in a technical analysis.
https://thehackernews.com/2026/06/hijacked-npm-and-go-packages-use-vs.html

Explore how GitLab self-hosted runners can be repurposed as a fully functional Command and Control framework using a legitimate, digitally signed binary. Covers the GitRunner C2 proof-of-concept, execution model via CI pipelines, file transfer through GitLab Artifacts, and a detailed detection walkthrough with real Wazuh and Sysmon events, MITRE ATT&CK mapping, and high-fidelity detection rules.
https://vrls.ws/posts/abusing-gitlab-ci-runners-as-c2/

Don't miss what's next. Subscribe to BagheeraAltered's CyberSecurity Newsletter:
← Newer Smugness won’t protect Mac Users from this new threat Older → Here are 24 billion reasons never to reuse a password
Share this email:
Share on Twitter Share on LinkedIn Share via email
Powered by Buttondown, the easiest way to start and grow your newsletter.