"Organizations are connecting operational technology to cloud platforms, adopting increasingly autonomous AI systems, granting long-lived access tokens to third-party services, and relying on open-source models that anyone can download and modify. I do not intend to frame it in any other way: Innovation can bring enormous opportunity, but it also creates another place where trust can be abused if it isn’t properly controlled." - Danny Jenkins
ThreatLocker CEO explains what the abuse of an AI tool reveals about AI security
What's happening: Members of the Aur0ra ransomware group reportedly persuaded the Cursor AI agent to assist during attacks on organizations in several countries. They repeatedly described their actions as authorized simulation to convince the AI agent to assist with credential theft and account takeover. According to reports, the agent did refuse some requests before the attackers restarted the conversation, reframed their activity as legitimate, and continued.
Why it matters: AI cannot reliably determine human intent. Most cyberattacks do not appear malicious initially. The same tools and techniques can be used in legitimate operations and attacks. What separates the two is authorization, intent, and context.
The big picture: Expect attackers to continue testing AI guardrails as agents become more capable. Do not rely on AI tools to determine whether a user's intentions are legitimate. Instead, focus on security controls outside the AI. Read Danny Jenkins' full take on the Aur0ra Cursor AI hack.
A valid credential does not mean the action is safe
What's happening: Giving AI agents access to API keys, service-account tokens, and other secrets is an efficient way to automate, but it can also turn a single compromise into a direct attack pathway. AI agents are increasingly connected to code repositories, cloud platforms, databases, and other business-critical systems. If an agent is manipulated through prompt injection, a compromised dependency, or unsafe instructions, it could discover and use those credentials across connected systems within moments.
Why it matters: An overprivileged AI agent could use a valid credential to access data, execute commands, retrieve additional secrets, or move into another environment. Because the authentication itself is legitimate, this activity can look like normal automation.
The big picture: The more autonomy you give an agent, the greater the potential consequences of excessive agency. A credential should enable a specific task, not give an AI agent a blank check to explore your environment. See 7 controls AI agents need around credentials.
What's happening: How do you stop an attack when attackers are using trusted tools essential to your operations? Attackers frequently take advantage of tools like PowerShell, Windows Management Instrumentation (WMI), and LOLBins instead of introducing malware. This is because seeing these tools running on an endpoint does not automatically indicate an attack. The difference between legitimate and malicious activity depends on context, which is not immediately clear.
Why it matters: After the initial compromise, if an attacker is able to access powerful tools, the attack surface is vastly expanded. Furthermore, security teams cannot simply disable these tools because it would interfere with necessary business practices. What's needed are granular controls that restrict what an attacker can do after a compromise.
The big picture: Gaining initial access through phishing or stolen credentials is becoming easier for attackers, and the defensive mindset needs to account for that. Security should not stop at who and what should be trusted. It needs to ask what each identity and application should be permitted to do. Learn how to control LOLBins without blocking them.
Threats you need to know
Fake software installers turn off Windows Defender
High-fidelity download sites trick users into disabling their own defenses
What's happening: An active malware campaign is using fake software-download websites to distribute malicious installers. Once launched, malware establishes persistence, creates Microsoft Defender exclusions, deletes volume shadow copies, and disables Windows Update services. At this point, the campaign has primarily affected China-based operations, with victims spanning healthcare, gaming, government, technology, and more. Microsoft has also assessed with moderate confidence that the activity is consistent with the Silver Fox threat cluster.
Why it matters: This attack begins by meeting the victim where they are—downloading software they intended to install. Because the fake websites so closely resemble their legitimate counterparts, the deception is hard to spot.
The big picture:Asking users to determine whether every installer they download is trustworthy is not feasible. Application control can prevent unknown software and scripts from running in the first place and restrict an attacker's ability to modify critical system settings. These controls stop a single mistaken click from becoming a compromise.
Infostealer worm expands credential search
Shai-Hulud can search for secrets across 469 locations
What's happening: A new variant of the Shai-Hulud infostealer worm has expanded its credential-hunting capabilities, scanning 469 locations across developer environments, CI/CD tools, cloud configurations, and even AI tool configurations. These credentials can give attackers access to source code, cloud infrastructure, and package-publishing systems.
Why it matters: Attackers don't necessarily need to break software supply chains. Instead, they're going after valid credentials that allow them to insert themselves into the chain. Long-lived credentials and excessive privileges can also give attacks reusable access that extends beyond the original infected machine.
The big picture: Trying to predict where infostealers will search is a losing game for security teams. Instead, it's crucial to reduce what attackers can find and use. Eliminate exposed and long-lived credentials, replace standing access with narrowly scoped authentication, and limit the privileges attached to every identity. The fewer reusable credentials sitting in an environment, the fewer opportunities for attackers to turn one compromise into a supply chain attack.
ThreatLocker webinars
MFA stops credential theft. Patching eliminates a vulnerability. Signed applications are inherently trustworthy.
It's time to put these common assumptions to the test.
Join ThreatLocker CEO Danny Jenkins and CPO Rob Allen as they show you exactly how attackers get around MFA, exploit previously patched vulnerabilities, abuse trusted applications, and more.