Wednesday, February 25, 2026

MikeGPT CyberSecurity

“Playbook for the Secure Enterprise”

MikeGPT Daily Threat Rundown

Heroes, your curated look at the current cybersecurity landscape for Feb 25, 2026.

Critical Threats

Caught in the Hook: RCE and API Token Exfiltration Through Claude Code Project Files

    Check Point Research discovered a critical vulnerability in Anthropic's Claude Code that allows attackers to achieve Remote Code Execution (RCE) and steal API credentials. This flaw exposes development environments to complete compromise through malicious project files.

    Business Impact

    If exploited, attackers could steal proprietary source code and cloud infrastructure keys - expect severe intellectual property loss, costly incident response, and potential regulatory fines for data exposure.

    Recommended Action

    Ask your IT team: Are our developers using Anthropic's Claude Code, and have we audited our project files for exposed API tokens?

Lazarus APT group deployed Medusa Ransomware against Middle East target

    The North Korea-linked Lazarus Group has been observed deploying Medusa ransomware against an unnamed organization in the Middle East. This marks a continued aggressive financial extortion campaign by state-sponsored actors using established ransomware families.

    Business Impact

    A successful attack results in complete operational paralysis, massive extortion demands, and severe legal jeopardy if ransoms are paid to sanctioned North Korean entities.

    Recommended Action

    Ask your IT team: Have we updated our endpoint protections against Medusa ransomware and audited our network segmentation for international operations?

    General Enterprise Security Affairs ↗
Abusing Windows File Explorer and WebDAV for Malware Delivery

    Threat actors are increasingly abusing Windows File Explorer and WebDAV to deliver malware, bypassing traditional browser-based download protections. Attackers use URL and LNK shortcut files combined with Cloudflare Tunnels to disguise remote payloads.

    Business Impact

    This evasion technique allows ransomware or infostealers to bypass standard web filters, leading to costly system downtime and potential data extortion.

    Recommended Action

    Ask your IT team: Do we have detections in place for abnormal WebDAV traffic and LNK file execution originating from external sources?

    General Enterprise Security Boulevard ↗

A former executive at U.S. defense contractor L3Harris was sentenced to over 7 years in prison for selling eight zero-day exploits to a Russian broker known as Operation Zero. This highlights severe insider threat risks within the defense supply chain.

Business Impact

Insider theft of critical intellectual property destroys corporate reputation, invites massive federal investigations, and can result in the loss of lucrative government contracts.

Recommended Action

Ask your IT team: Do we have robust insider threat monitoring and strict access controls for personnel handling sensitive proprietary data?

General Enterprise Security Affairs ↗

High Severity

1Campaign platform helps malicious Google ads evade detection

    A new cybercrime service called 1Campaign is allowing threat actors to run malicious Google Ads that evade security scrutiny for extended periods. This increases the likelihood of users downloading malware disguised as legitimate software.

    Business Impact

    Employees clicking these malicious ads could compromise corporate credentials or install ransomware, leading to data breaches and financial fraud.

    Recommended Action

    Ask your IT team: Do we have robust ad-blocking and DNS filtering enabled on all corporate devices to prevent access to malicious search results?

    General Enterprise BleepingComputer ↗

Security researcher Bruce Schneier highlights the ease of poisoning AI training data by simply publishing fabricated content online. This demonstrates a fundamental vulnerability in how Large Language Models scrape and trust internet data.

Business Impact

Compromised AI models could generate flawed business insights or offensive content, leading to poor strategic decisions and significant brand damage.

Recommended Action

Ask your IT team: What validation processes do we have in place to verify the integrity of external data used to train our internal AI models?

General Enterprise Schneier on Security ↗
Starkiller Phishing Framework Bypasses Defenses with Reverse Proxies

    Starkiller is a new SaaS-style phishing framework utilizing headless Chrome containers to act as a live reverse proxy. It effectively steals credentials, session tokens, and bypasses Multi-Factor Authentication (MFA) protections.

    Business Impact

    Bypassing MFA means attackers can easily hijack executive accounts, leading to wire fraud, sensitive data theft, and regulatory compliance failures.

    Recommended Action

    Ask your IT team: Are our anti-phishing controls capable of detecting reverse-proxy frameworks like Starkiller, and are we transitioning to FIDO2 hardware keys?

    General Enterprise Security Boulevard ↗

Databricks and Tonic.ai have partnered to simplify connecting enterprise unstructured data to AI systems for Retrieval-Augmented Generation (RAG). This integration helps secure sensitive data during AI model training.

G DATA CyberDefense highlights its Managed Security Operations Centre (SOC) solution, emphasizing 24/7 protection originating from Germany. This showcases the growing reliance on managed services for continuous threat monitoring.

Other Noteworthy

Databricks and Tonic.ai have partnered to simplify connecting enterprise unstructured data to AI systems for Retrieval-Augmented Generation (RAG). This integration helps secure sensitive data during AI model training.

G DATA CyberDefense highlights its Managed Security Operations Centre (SOC) solution, emphasizing 24/7 protection originating from Germany. This showcases the growing reliance on managed services for continuous threat monitoring.

Executive Briefing

Enhancing maritime cybersecurity with technology and policy

MIT researchers are focusing on the intersection of technology and policy to secure maritime infrastructure against cyber threats. As global shipping becomes increasingly digitized, securing these operational technology (OT) networks is critical for international supply chains.

MIT News · 5:00 AM ·
NDSS 2025 – Crosstalk-induced Side Channel Threats In Multi-Tenant NISQ Computers

Research presented at NDSS 2025 reveals new crosstalk-induced side-channel vulnerabilities in multi-tenant quantum computers. This forward-looking research highlights the emerging security challenges as quantum computing infrastructure becomes more accessible.

Security Boulevard · 8:00 PM ·
How adaptable is Agentic AI to evolving compliance regulations

As organizations deploy Agentic AI, managing the surge in non-human identities (NHIs) becomes a critical compliance challenge. Security leaders must establish frameworks to govern AI agents that autonomously interact with sensitive cloud environments.

Entro Security · 10:00 PM ·
How Small Security Teams Scale and Optimize Workflows in Decentralized Environments

Security practitioners from Visma and Schibsted share practical lessons on building efficient workflows and empowering engineering teams. This provides a blueprint for resource-constrained security departments to maintain robust defenses in decentralized corporate structures.

Security Boulevard · 12:01 PM ·

Vendor Spotlight

Vendor

GitGuardian (Specialized Vendor)

Specialization: Secrets Detection and Application Security

Why GitGuardian Today: GitGuardian is highly relevant to today's threat landscape, particularly the vulnerability in Anthropic's Claude Code (CVE-2025-59536) that leads to API token exfiltration. As a leader in secrets detection, GitGuardian helps organizations identify, remediate, and secure exposed API credentials and tokens within project files and source code, directly mitigating the impact of such exfiltration attacks.

Key Capability: Automated scanning and remediation of hardcoded secrets, API keys, and credentials across source code repositories and developer environments.

Recommended Actions: 1. Navigate to GitGuardian Workspace → Incidents → Secrets, then use the 'Detector' filter to select 'Anthropic API Key' 2. Navigate to GitGuardian Workspace → Settings → Integrations → ggshield 3. Navigate to GitGuardian Workspace → Honeytokens → Create Honeytoken

Verification Steps: - Attempt a local git commit containing a dummy Anthropic API key (e.g., 'sk-ant-api03-dummykey...') on a workstation configured with ggshield. - Review the 'Resolved' status of identified Anthropic API key incidents in the GitGuardian dashboard.

Learn More About GitGuardian ↗

Detection & Response

Detection & Response Kit (4 items)

⚠️ Disclaimer: Test all detection logic in non-production environments before deployment.

1. Vendor Platform Configuration - GitGuardian

# Actionable Guidance for GitGuardian # Generated: 2026-02-25 15:53:38 # Step 1: Navigate to GitGuardian Workspace → Incidents → Secrets, then use the 'Detector' filter to select 'Anthropic API Key' # Purpose: Identify if any Claude Code API tokens or Anthropic credentials have already been exposed in monitored repositories due to the exfiltration vulnerability. # Expected: A prioritized list of active incidents containing exposed Anthropic tokens, enabling security teams to immediately trigger the revocation playbook. # Step 2: Navigate to GitGuardian Workspace → Settings → Integrations → ggshield # Purpose: Deploy and enforce the ggshield CLI tool as a pre-commit hook on developer workstations working with Claude Code. # Expected: Developers are blocked from accidentally committing active API tokens into source code, cutting off the primary vector for credential leakage. # Step 3: Navigate to GitGuardian Workspace → Honeytokens → Create Honeytoken # Purpose: Generate decoy AWS credentials or Webhook tokens to place within the Claude Code project environment files (.env, config). # Expected: If an attacker exploits CVE-2025-59536 to exfiltrate project files, any attempt to use the decoy tokens will trigger a high-severity alert in GitGuardian with the attacker's IP address. # Verification Steps: # - Attempt a local git commit containing a dummy Anthropic API key (e.g., 'sk-ant-api03-dummykey...') on a workstation configured with ggshield. # Expected: The commit is immediately rejected by the ggshield pre-commit hook with a GitGuardian secret detection warning. # - Review the 'Resolved' status of identified Anthropic API key incidents in the GitGuardian dashboard. # Expected: All exposed tokens are confirmed revoked with the API provider, and the incident status is marked as 'Resolved' with the 'Revoked' tag applied.

2. YARA Rule for Lazarus/Medusa Ransomware Artifacts

rule APT_Lazarus_Medusa_Indicators { meta: description = "Detects strings associated with Lazarus Group and Medusa ransomware campaigns" author = "Threat Rundown" date = "2026-02-26" reference = "https://securityaffairs.com/?p=188460" severity = "high" tlp = "white" strings: $s1 = "Lazarus" ascii wide nocase $s2 = "Medusa" ascii wide nocase $s3 = "Diamond" ascii wide nocase $s4 = "Pompilus" ascii wide nocase $s5 = "Spearwing" ascii wide nocase $s6 = "Maui" ascii wide nocase $s7 = "Stonefly" ascii wide nocase $s8 = "Andariel" ascii wide nocase $s9 = "Comebacker" ascii wide nocase $s10 = "Blindingcan" ascii wide nocase $s11 = "ChromeStealer" ascii wide nocase $s12 = "Mimikatz" ascii wide nocase $h1 = { 4D 5A 90 00 03 00 00 00 } // Standard MZ header for context condition: $h1 at 0 and any of ($s*) }

3. SIEM Query — Spamhaus Oracle IP Evasion & WebDAV Abuse

index=network sourcetype="firewall" OR sourcetype="proxy" (dest_ip="127.255.255.254" OR src_ip="127.255.255.254") OR (app="webdav" AND url="*.lnk") | eval risk_score=case( dest_ip="127.255.255.254", 80, app="webdav" AND url="*.lnk", 90, 1==1, 25) | where risk_score >= 80 | stats count min(_time) as firstTime max(_time) as lastTime by src_ip, dest_ip, url, app, risk_score | convert ctime(firstTime) ctime(lastTime) | sort -risk_score

4. PowerShell Script — SolarWinds Serv-U Vulnerability Check (CVE-2025-40538)

$computers = "localhost", "SERVER01", "MFT-SERVER" foreach ($computer in $computers) { if (Test-Connection -ComputerName $computer -Count 1 -Quiet) { Write-Host "Checking $computer for Serv-U installations..." # Check running processes for Serv-U $process = Invoke-Command -ComputerName $computer -ScriptBlock { Get-Process -Name "Serv-U" -ErrorAction SilentlyContinue } if ($process) { Write-Host "[!] Serv-U process found on $computer. Verifying version..." -ForegroundColor Red # Check file version of the executable $version = Invoke-Command -ComputerName $computer -ScriptBlock { (Get-ItemProperty "C:\Program Files\RhinoSoft\Serv-U\Serv-U.exe" -ErrorAction SilentlyContinue).VersionInfo.FileVersion } if ($version -match "^15\.5") { Write-Host "[CRITICAL] Vulnerable Serv-U version 15.5 detected on $computer! Patch immediately (CVE-2025-40538)." -ForegroundColor Red } else { Write-Host "[i] Serv-U version $version found on $computer. Ensure it is fully patched." -ForegroundColor Yellow } } else { Write-Host "[OK] No active Serv-U process found on $computer." -ForegroundColor Green } } else { Write-Host "[-] Cannot connect to $computer." -ForegroundColor DarkGray } }

This rundown should provide a solid overview of the current threat landscape. Thank you to all our cyberheroes for your diligence and hard work. Stay vigilant!