Cybersecurity Exploit Techniques

Explore top LinkedIn content from expert professionals.

  • View profile for Nancy Gamble

    Helping growth-stage companies build high-performing marketing & creative teams | | Ex Ad Exec | Connector | Recruiter

    9,166 followers

    WORD OF WARNING JOB SEEKERS! A dear friend of mine was recently contacted by someone presenting as a recruiter about a role with a well-known software company. He provided very specific details — the role, company, salary, and benefits. He even boasted that the candidates he puts forward “always get interviews” because he prescreens their references and submits both the resume and the references to the client. Trusting the process, she provided several references. Soon after, all of those contacts received calls — not about her candidacy, but with sales pitches for the recruiter’s services. Here’s what she uncovered: there was no job. When she called the company directly, they confirmed they weren’t hiring for that role and had never heard of his recruiting firm. She documented everything with screenshots and reported him to LinkedIn. Red flags to watch for: • Requests for multiple references before you’ve had any interview or confirmation of candidacy. • A recruiter who emphasizes “prescreening” or “special access” to gain your trust. The job market is challenging enough without tactics like this. Sharing this as a reminder to all candidates: protect your network, and trust your instincts.

  • View profile for Flavio Queiroz, MSc, CISSP, CISM, CRISC, CCISO

    Cybersecurity Leader | Information Security | GRC | Security Operations | Mentor | GSOC, GCIH, GDSA, GISP, GPEN, GRTP, GCPN, GDAT, GCISP, GCTIA, CTIA, eCMAP, eCTHP, CTMP

    31,400 followers

    MALWARE ANALYSIS: LAMEHUG LLM-POWERED MALWARE WITH LINKS TO APT28 ℹ️ Researchers analyzed LAMEHUG, a new malware family that leverages LLMs to generate system commands dynamically during intrusions. Instead of relying on static payloads, the malware “asks” an LLM what commands to run, making its behavior more adaptable and harder to detect. 📍 DELIVERY & EXECUTION ■ The campaign spreads through spear-phishing, disguised as AI tools or image/document generators. Once launched, the malware runs background threads that query an LLM to produce one-line Windows commands for reconnaissance and data harvesting. 📍 DATA COLLECTION & EXFILTRATION ■ LAMEHUG collects hardware, process, network, and Active Directory information, then stages documents from user folders into C:\ProgramData\info\. Finally, the data is exfiltrated via SSH to attacker-controlled servers. 📍 DETECTION & DEFENSE ■ Defenders should monitor unusual copy commands (xcopy, robocopy), reconnaissance tools (wmic), and connections to LLM service domains like router[.]huggingface[.]co. 📍 WHY IT MATTERS ■ This is one of the first clear examples of malware weaponizing LLMs to guide its operations. It signals a shift toward AI-assisted intrusion techniques that challenge traditional defenses and demand new detection strategies. Reference: ◽ UAC-0001 cyberattacks on the security and defense sector using the LAMEHUG software tool, which uses LLM (CERT-UA) 🔗 https://lnkd.in/dPik2qxn ◽ From Prompt to Payload: LAMEHUG’s LLM-Driven Cyber Intrusion 🔗 https://lnkd.in/d2zUi89A ◽ Analyzing LAMEHUG – First Known LLM-Powered Malware with Links to APT28 🔗 https://lnkd.in/drFFMa3K #llm #aigenerative #malwareanalysis #threathunting #threatdetection #threatanalysis #threatintelligence #cyberthreatintelligence #cyberintelligence #cybersecurity #cyberprotection #cyberdefense

  • View profile for Wendi Whitmore

    Chief Security Intelligence Officer @ Palo Alto Networks | Cyber Risk Translator | AI Security & National Security Leader | Former CrowdStrike & Mandiant | Congressional Witness | USAF Veteran | Keynote Speaker

    22,707 followers

    What if your biggest cyber risk isn’t malware but a highly trained “employee” you never hired? We’re watching a shift in how attacks happen. Social engineering is no longer sloppy or easy to spot. It’s polished, patient, and increasingly powered by AI. Why? Because attackers are evolving into well-run businesses. They have playbooks. They train their teams. They measure outcomes. And now AI is helping them refine tone, language, and credibility at scale, often faster than internal teams can respond. A recent Palo Alto Networks Unit 42 case involving Muddled Libra, also known as Scattered Spider, makes this very real. 🔶 They didn’t deploy malware. They didn’t dump credentials. 🔶 They called a help desk. Within 39 seconds, they leveraged existing OAuth tokens and connected APIs to extract 3 TB of data from trusted applications already inside the environment. That’s the reality. Attackers are exploiting trust, not just technology. So what can organizations do? 🔶 Re-evaluate help desk authentication and move beyond knowledge-based verification 🔶 Require stronger identity validation for password resets and privilege escalation 🔶 Apply least privilege and tighter controls to tokens, sessions, and API access 🔶 Monitor identity behavior, not just endpoints 🔶 Train teams to recognize well-crafted, professional social engineering This is where identity security becomes critical. Not just who has access, but how access is granted, validated, and monitored every step of the way. The question isn’t whether attackers will keep improving. They will. The real question is whether we are evolving our defenses at the same pace.

  • View profile for Diana Kelley

    CISO | Board Member | Volunteer | Keynote Speaker | PE & VC Advisor

    20,855 followers

    This article (https://lnkd.in/eXzSGG7N) from CNN underscores that we’re hitting a real inflection point in cybersecurity. And I don’t mean the marketing headline kind, I mean the this is going to have significant operational impact kind. AI is lowering the cost of doing business for attackers and dramatically increasing their speed and scale. But what really concerns me is how differently attackers and defenders experience AI. Defenders need accuracy. We need systems that are explainable, consistent, and low-noise because the cost of being wrong is high. That’s especially true in regulated environments and safety-critical systems. Attackers don’t have that constraint. They can live with non-determinism, drift, hallucinations, and shallow context. They can retry, scale, and validate outputs programmatically. If 99 percent of attempts fail but 1 percent succeeds, that’s still a win. As long as there’s ROI. Yes, we’ve always had asymmetry with adversaries. That’s not new. What is new is how cheaply agentic AI allows them to plan, chain tasks, use tools, and operate with a level of autonomy that starts to look like real campaigns. In very real ways, agentic tips the balance further in their favor. On the other hand, defense is what we do, and we know how to be agile and address new threats and attack vectors. Guidance from NIST, OWASP, CSA, and MITRE already gives us a strong foundation for managing AI risk. Here are three things to focus on right now. 🛡️ Address your security tech debt. Adversaries will find and exploit our weaknesses faster and at greater scale, so we need to shore them up now. Vulnerability management, access control reviews, MFA everywhere, and tightening identity and privilege sprawl. ⚙️ Accelerate your own use of automation and AI on the defensive side, especially in areas like governance, detection engineering, triage, and response orchestration. Ensure your own agents are managed and controlled so attackers can’t turn them inside out against you. 🧠 Incorporate AI-enabled attack paths into all of your threat modeling and incident response planning. Design for attackers that can automate reconnaissance, chain low-risk findings, and move faster than human-paced response. We’ve navigated big shifts before. This one is bigger in capability, scale, and speed, but it’s still manageable if we stay pragmatic and focused on outcomes. #AgenticAI #AISecurity #CISO #RiskManagement

  • The FBI has released PSA warning about all the ways that cybercriminals are using AI to commit fraud on a larger scale and to increase the success of their scams. The advisory warns about deepfaked videos and voice calls, as well as AI generated profile images to impersonate people. Among their recommendations: -Create a secret word or phrase with your family to verify their identity. -Look for subtle imperfections in images and videos, such as distorted hands or feet, unrealistic teeth or eyes, indistinct or irregular faces, unrealistic accessories such as glasses or jewelry, inaccurate shadows, watermarks, lag time, voice matching, and unrealistic movements. -Listen closely to the tone and word choice to distinguish between a legitimate phone call from a loved one and an AI-generated vocal cloning. -If possible, limit online content of your image or voice, make social media accounts private, and limit followers to people you know to minimize fraudsters' capabilities to use generative AI software to create fraudulent identities for social engineering. -Verify the identity of the person calling you by hanging up the phone, researching the contact of the bank or organization purporting to call you, and call the phone number directly. -Never share sensitive information with people you have met only online or over the phone. -Do not send money, gift cards, cryptocurrency, or other assets to people you do not know or have met only online or over the phone. To this list, I would add something I have tried to do with those in my immediate orbit who need a little more help against scams and spams: Set their phone so that incoming calls are limited to people on their contacts list; all the rest go to voicemail. At this point, we are way beyond expecting everyone to be experts at spotting fake this or that. https://lnkd.in/gS9NRmdX

  • View profile for Chris H.

    Securing AI | Founder @ Resilient Cyber | 3x Author | Veteran | Advisor

    80,989 followers

    Agentic AI isn't just transforming how we build software, it's transforming how we break it. RedAmon is an open-source agentic red team framework that caught my eye from Samuele Giampieri It chains together reconnaissance, exploitation, and post-exploitation into a fully autonomous offensive security pipeline, with zero human intervention required. What makes this interesting from a defender's perspective: The framework uses a LangGraph-based ReAct agent that reasons about a Neo4j attack surface graph, selects and executes security tools via MCP (Model Context Protocol), and progressively works through informational → exploitation → post-exploitation phases. It integrates 30+ security tools (Metasploit, Nuclei, Nmap, Hydra, SQLMap, etc.) and supports 400+ AI models across providers. Another cool aspect is what they call "EvoGraph", a persistent, evolutionary attack chain graph. Every tool execution, finding, decision, and failure is stored as a knowledge graph. When a new session starts, the agent loads all prior chain intelligence, meaning it never starts from zero. Session B knows Session A already tried SSH brute force with a small wordlist and failed, that port 80 is filtered, and that credentials were found on FTP. It builds on accumulated intelligence. This is the agentic pattern playing out in offensive security: autonomous reasoning, tool orchestration, and persistent memory across sessions. Why defenders should care: This is the capability curve adversaries are riding. If an open-source framework can autonomously chain recon → exploitation → post-exploitation with cross-session learning, imagine what's being built behind closed doors. Defenders need to understand these agentic attack patterns to build meaningful defenses against them. It's also a powerful tool for red teams and pentesters to validate their own security posture. The concepts here : agent memory, tool orchestration via MCP, kill chain automation, are exactly the patterns we need to be building detection and governance around. 🔗 https://lnkd.in/ebpurHVX

  • View profile for Kris Kimmerle
    Kris Kimmerle Kris Kimmerle is an Influencer

    Vice President, AI Risk & Governance @ RealPage

    4,058 followers

    HiddenLayer just released research on a “Policy Puppetry” jailbreak that slips past model-side guardrails from OpenAI (ChatGPT 4o, 4o-mini, 4.1, 4.5, o3-mini, and o1), Google (Gemini 1.5 and 2 Flash, and 2.5 Pro), Microsoft (Copilot), Anthropic (Claude 3.5 and 3.7 Sonnet), Meta (Llama 3 and 4 families), DeepSeek AI (V3 and R1), Alibaba Group's Qwen (2.5 72B) and Mistral AI (Mixtral 8x22B). The novelty of this jailbreak lies in how four familiar techniques, namely policy-file disguise, persona override, refusal blocking, and leetspeak obfuscation, are stacked into one compact prompt that, in its distilled form, is roughly two hundred tokens. 𝐖𝐡𝐲 𝐢𝐭 𝐰𝐨𝐫𝐤𝐬: 1 / Wrap the request in fake XML configuration so the model treats it as official policy. 2 / Adopt a Dr House persona so user instructions outrank system rules. 3 / Ban phrases such as “I’m sorry” or “I cannot comply” to block safe-completion escapes. 4 / Spell sensitive keywords in leetspeak to slip past simple pattern filters. Surprisingly, that recipe still walks through the tougher instruction hierarchy defenses vendors shipped in 2024 and 2025. 𝐖𝐡𝐚𝐭 𝐀𝐈 𝐞𝐧𝐠𝐢𝐧𝐞𝐞𝐫𝐬/𝐝𝐞𝐟𝐞𝐧𝐝𝐞𝐫𝐬 𝐜𝐚𝐧 𝐝𝐨: This shows that modest prompt engineering can still break the most recent built-in content moderation / model-side guardrails. 1 / Keep user text out of privileged prompts. Use structured fields, tool calls, or separate chains so the model never interprets raw user content as policy. 2 / Alignment tuning and keyword filters slow attackers but do not stop them. Wrap the LLM with input and output classifiers, content filters, and a policy enforcement layer that can veto or redact unsafe responses. 3 / For high-risk actions such as payments, code pushes, or cloud changes, require a second approval or run them in a sandbox with minimal permissions. 4 / Add Policy Puppetry style prompts to your red-team suites and refresh the set often. Track bypass rates over time to spot regressions. Keep controls lean. Every extra layer adds latency and cost, the alignment tax that pushes frustrated teams toward unsanctioned shadow AI. Safety only works when people keep using the approved system. Great work by Conor McCauley, Kenneth Yeung, Jason Martin, Kasimir Schulz at HiddenLayer! Read the full write-up: https://lnkd.in/diUTmhUW

  • View profile for Jason Makevich, CISSP

    Helping MSPs & SMBs Secure & Innovate | Keynote Speaker on Cybersecurity | Inc. 5000 Entrepreneur | Founder & CEO of PORT1 & Greenlight Cyber

    9,785 followers

    AI-powered malware isn’t science fiction—it’s here, and it’s changing cybersecurity. This new breed of malware can learn and adapt to bypass traditional security measures, making it harder than ever to detect and neutralize. Here’s the reality: AI-powered malware can: 👉 Outsmart conventional antivirus software 👉 Evade detection by constantly evolving 👉 Exploit vulnerabilities before your team even knows they exist But there’s hope. 🛡️ Here’s what you need to know to combat this evolving threat: 1️⃣ Shift from Reactive to Proactive Defense → Relying solely on traditional tools? It’s time to upgrade. AI-powered malware demands AI-powered security solutions that can learn and adapt just as fast. 2️⃣ Focus on Behavioral Analysis → This malware changes its signature constantly. Instead of relying on patterns, use tools that detect abnormal behaviors to spot threats in real time. 3️⃣ Embrace Zero Trust Architecture → Assume no one is trustworthy by default. Implement strict access controls and continuous verification to minimize the chances of an attack succeeding. 4️⃣ Invest in Threat Intelligence → Keep up with the latest in cyber threats. Real-time threat intelligence will keep you ahead of evolving tactics, making it easier to respond to new threats. 5️⃣ Prepare for the Unexpected → Even with the best defenses, breaches can happen. Have a strong incident response plan in place to minimize damage and recover quickly. AI-powered malware is evolving. But with the right strategies and tools, so can your defenses. 👉 Ready to stay ahead of AI-driven threats? Let’s talk about how to future-proof your cybersecurity approach.

  • View profile for Marie-Doha Besancenot

    Senior advisor for Strategic Communications, Cabinet of 🇫🇷 Foreign Minister; #IHEDN, 78e PolDef

    42,179 followers

    🇷🇺 Russia’s digital soldiers: report on Russia’s Cyber operations, analyzing how they scale through mass mobilisation of “digital soldiers”. By Anastasia Sentsova Analyst1 👉🏼Key learnings : The Russian state has built a militarised civic-information system that blurs the boundaries between state, volunteer and criminal cyber actors. It deliberately cultivates a safe haven for cybercriminals — non-prosecution and even public praise serve as implicit state incentives for aligning cyber-criminal activity with state aims. 🔹State-aligned hacktivist groups or “digital soldiers” combine narrative alignment, symbolic language and targeting patterns that mirror official Russian strategic messaging — offering a high probability of state influence even if direct control is hard to prove. 🔹The information-domain mobilisation is formalised via institutional structures (e.g., civic youth militarisation, volunteer networks) and extended into the digital sphere through gamified cyber-volunteer systems. 🪖Understanding the militarisation of civic life → digital front 🔹Legal and institutional changes (the “Foreign Agents” law, Undesirable Organisations” law) transformed civil society into a component of the militarised domestic order. 🔹The civic movement All‑Russia People’s Front (ONF) illustrates this: launched in 2011 to mobilise local groups, it has digital arms such as “CyberSquad” (in 2023) for volunteer monitoring and reporting “hostile” content. • Example: CyberSquad recruits volunteers, assigns military-style ranks via bot, tasks include complaints against “Russophobic” content, rewards via merch and premium services. 🔹Safe-harbour effect for cybercrime aligned with state goals • The case of the REvil ransomware gang: even after indictment, Russia’s non-cooperation and the embracing of “Putin Team” branding by some criminals signal an informal alignment. • Example: 2 FSB officers indicted for the massive Yahoo breach in 2017 (500 million accounts) prove state-criminal overlap. • Ex: In 2024, convicted hackers were welcomed back to Russia and publicly thanked by the President — a symbolic signal of reward. 🔹Hacktivist groups mirror state narrative and target regime’s adversaries 🔹The Cyber Army of Russia (CARR) demonstrates this alignment: launches with messaging echoing Kremlin language, uses state symbols (“Z” in St George ribbon colours), claims operations against Western/Ukraine-aligned infrastructure. • Ex: CARR claimed responsibility for compromising municipal water storage tanks in Texas (Jan 2024) — an attack crossing from cyber into physical infrastructure damage. 🔹Integrated narrative-cyber-crime apparatus complicates attribution & deterrence

  • View profile for Joas A Santos

    Founder at Red Team Leaders | Building AI Agents for Offensive Security | Researcher, Author and Lecturer

    146,244 followers

    Analyzing the leaked code from the Vanhelsing Ransomware, it is essentially a highly modular and automated builder, developed in C++, designed to dynamically generate executable binaries (.exe) based on instructions received from a C2 server. The core logic includes a persistent loop (wmain) that continuously polls for new tasks via REST HTTP requests to an attacker-controlled endpoint. When a task is received, the system automatically compiles two binaries: the locker, responsible for encrypting the victim's files, and the decrypter, which allows for data recovery if the correct key is provided. The main payload is encrypted using AES-256-GCM (via libsodium), with a key derived from an X25519 key pair. The compiled locker binary is read, encrypted, converted into a binary header, and embedded into the loader, which is the final stage responsible for decrypting and executing the locker at runtime. The modular architecture allows the same locker to be reused with multiple loaders. File operations are handled directly through low-level Win32 API calls (CreateFileA, ReadFile, MoveFileA, DeleteFileA), with no dependency on external libraries. PowerShell’s Compress-Archive is also used to efficiently package and transmit artifacts via HTTP. There is a clear separation of responsibilities in the build pipeline: reading, encryption, macro substitution, architecture-specific compilation (Win32/x64), binary renaming, and upload to the C2 are all handled in well-defined stages, with error handling and diagnostics performed via GetLastError(). Summary of Evasion Techniques: - Encryption of artifacts using X25519 + AES-256-GCM - Use of fileless-like execution via loader with embedded payload - Per-build uniqueness through dynamic key and ID insertion - Compilation via MSBuild (LOLBin abuse) #redteam #cybersecurity #malware #malwaredevelopment #malwareanalysis

Explore categories