Plus: Shai-Hulud now searches 469 locations for credentials ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­    ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
Zero Trust Weekly

This week in Zero Trust

Trust is easy to abuse. Permissions are harder.

Estimated reading time: 6 minutes

 

In this issue:

  • Attackers convinced an AI agent they were the good guys
  • What happens when an AI agent can access your secrets?
  • How to properly secure PowerShell, WMI, and LOLBins
  • Threats: Fake software downloads turn off Windows Defender; Shai-Hulud's reach grows to 469 locations
View in browser

Manage preferences

From the CEO

What concerns me most about AI

 

"Organizations are connecting operational technology to cloud platforms, adopting increasingly autonomous AI systems, granting long-lived access tokens to third-party services, and relying on open-source models that anyone can download and modify. I do not intend to frame it in any other way: Innovation can bring enormous opportunity, but it also creates another place where trust can be abused if it isn’t properly controlled." - Danny Jenkins

From the ThreatLocker blog

 

Danny Jenkins on the Aur0ra Cursor AI hack

ThreatLocker CEO explains what the abuse of an AI tool reveals about AI security

  • What's happening: Members of the Aur0ra ransomware group reportedly persuaded the Cursor AI agent to assist during attacks on organizations in several countries. They repeatedly described their actions as authorized simulation to convince the AI agent to assist with credential theft and account takeover. According to reports, the agent did refuse some requests before the attackers restarted the conversation, reframed their activity as legitimate, and continued. 
  • Why it matters: AI cannot reliably determine human intent. Most cyberattacks do not appear malicious initially. The same tools and techniques can be used in legitimate operations and attacks. What separates the two is authorization, intent, and context.
  • The big picture: Expect attackers to continue testing AI guardrails as agents become more capable. Do not rely on AI tools to determine whether a user's intentions are legitimate. Instead, focus on security controls outside the AI. Read Danny Jenkins' full take on the Aur0ra Cursor AI hack.

When AI agents can access your secrets

A valid credential does not mean the action is safe

  • What's happening: Giving AI agents access to API keys, service-account tokens, and other secrets is an efficient way to automate, but it can also turn a single compromise into a direct attack pathway. AI agents are increasingly connected to code repositories, cloud platforms, databases, and other business-critical systems. If an agent is manipulated through prompt injection, a compromised dependency, or unsafe instructions, it could discover and use those credentials across connected systems within moments.
  • Why it matters: An overprivileged AI agent could use a valid credential to access data, execute commands, retrieve additional secrets, or move into another environment. Because the authentication itself is legitimate, this activity can look like normal automation.
  • The big picture: The more autonomy you give an agent, the greater the potential consequences of excessive agency. A credential should enable a specific task, not give an AI agent a blank check to explore your environment. See 7 controls AI agents need around credentials.

How to stop attackers from abusing PowerShell, WMI, and LOLBins

Without blocking the tools you need

  • What's happening: How do you stop an attack when attackers are using trusted tools essential to your operations? Attackers frequently take advantage of tools like PowerShell, Windows Management Instrumentation (WMI), and LOLBins instead of introducing malware. This is because seeing these tools running on an endpoint does not automatically indicate an attack. The difference between legitimate and malicious activity depends on context, which is not immediately clear.  
  • Why it matters: After the initial compromise, if an attacker is able to access powerful tools, the attack surface is vastly expanded. Furthermore, security teams cannot simply disable these tools because it would interfere with necessary business practices. What's needed are granular controls that restrict what an attacker can do after a compromise. 
  • The big picture: Gaining initial access through phishing or stolen credentials is becoming easier for attackers, and the defensive mindset needs to account for that. Security should not stop at who and what should be trusted. It needs to ask what each identity and application should be permitted to do. Learn how to control LOLBins without blocking them.

Threats you need to know

 

Fake software installers turn off Windows Defender

High-fidelity download sites trick users into disabling their own defenses

  • What's happening: An active malware campaign is using fake software-download websites to distribute malicious installers. Once launched, malware establishes persistence, creates Microsoft Defender exclusions, deletes volume shadow copies, and disables Windows Update services. At this point, the campaign has primarily affected China-based operations, with victims spanning healthcare, gaming, government, technology, and more. Microsoft has also assessed with moderate confidence that the activity is consistent with the Silver Fox threat cluster.

  • Why it matters: This attack begins by meeting the victim where they are—downloading software they intended to install. Because the fake websites so closely resemble their legitimate counterparts, the deception is hard to spot.
  • The big picture: Asking users to determine whether every installer they download is trustworthy is not feasible. Application control can prevent unknown software and scripts from running in the first place and restrict an attacker's ability to modify critical system settings. These controls stop a single mistaken click from becoming a compromise. 

Infostealer worm expands credential search

Shai-Hulud can search for secrets across 469 locations

  • What's happening: A new variant of the Shai-Hulud infostealer worm has expanded its credential-hunting capabilities, scanning 469 locations across developer environments, CI/CD tools, cloud configurations, and even AI tool configurations. These credentials can give attackers access to source code, cloud infrastructure, and package-publishing systems.

  • Why it matters: Attackers don't necessarily need to break software supply chains. Instead, they're going after valid credentials that allow them to insert themselves into the chain. Long-lived credentials and excessive privileges can also give attacks reusable access that extends beyond the original infected machine.
  • The big picture: Trying to predict where infostealers will search is a losing game for security teams. Instead, it's crucial to reduce what attackers can find and use. Eliminate exposed and long-lived credentials, replace standing access with narrowly scoped authentication, and limit the privileges attached to every identity. The fewer reusable credentials sitting in an environment, the fewer opportunities for attackers to turn one compromise into a supply chain attack.

ThreatLocker webinars

 

MFA stops credential theft. Patching eliminates a vulnerability. Signed applications are inherently trustworthy.

 

It's time to put these common assumptions to the test. 

 

Join ThreatLocker CEO Danny Jenkins and CPO Rob Allen as they show you exactly how attackers get around MFA, exploit previously patched vulnerabilities, abuse trusted applications, and more.

 

Tuesday, Sept. 29 | 11 a.m. EDT

Debunk cybersecurity myths.

Zero Trust World 2027

Feb. 17–19, 2027

Orlando, FL

 

Sharpen your skills and advance your expertise through hands-on hacking labs, SME-led speaking sessions, and training exercises. 

Reserve your spot now

Cyber Hero Frontline, Issue 5

ThreatLocker Cyber Hero Frontline Issue 5 mockup

In this issue:

  • Why allowlisting is key to fighting unknown threats

  • CISA's latest guidance makes the case for Zero Trust
  • Inside Appin, RebSec, and Asia's growing hack-for-hire economy
Read Issue 5 now

ThreatLocker events

Meet the Cyber Hero Team in person at these upcoming events

  • Cybersec Netherlands | Sept. 9–10
    Utrecht, NL
  • CMIT Connect Live| Sept. 9–11
    Indianapolis, IN
  • APPA Academy | Sept. 13–16
    San Antonio, TX
  • Gartner Symposium | Sept. 14–16
    Broadbeach, AU
  • Workplace Ninja | Sept. 14–17
    Baden, CH
  • IndoSec | Sept. 15–16
    Jakarta, ID
See more upcoming events
ThreatLocker: Zero Trust Platform | Zero Trust Weekly

ThreatLocker, 1901 Summit Tower Blvd, Orlando, Florida 32810, United States

Manage preferences

Connect with us

                             

©2026 ThreatLocker Inc., All Rights Reserved