Here's what matters more for your security ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­    ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
Zero Trust Weekly

This week in Zero Trust

A kill switch won't undo damage 

Estimated reading time: 5 minutes

 

In this issue:

  • What the AI Kill Switch Act means for enterprise security
  • Don't overlook these key compliance requirements for GDPR
  • How to catch common persistence methods in your environment
  • Threats you need to know: ClickFix campaign targets Mac users and critical Rails RCE flaw
View in browser

Manage preferences

From the CEO

AI and defenders need to work together

 

"AI can help researchers find far more vulnerabilities, but those findings still have to be validated and passed to the people who can fix them. Restricting access to the most capable models may slow defenders down more than attackers. Cybercriminals and nation-state groups are not going to follow access policies or responsible-use agreements. They will use stolen models, open-weight models they can run themselves, and anything else they can obtain." - Danny Jenkins

From the ThreatLocker blog

Detection is strongest when it works alongside prevention

 

The AI Kill Switch Act is a new phase in AI governance

AI systems require their own set of rules as they become more autonomous

  • What's happening: The proposed AI Kill Switch Act would require developers to maintain the ability to shut down advanced AI systems should an exceptional risk arise. This is an important discussion for policymakers and industry leaders, but for enterprise defenders, the immediate concern is still how to stop an attack operating at machine speed inside their own environment. AI-powered attacks reduce the time gaps human-led attacks typically have, and a developer-controlled kill switch won't change that. 
  • Why it matters: Stopping technology that introduces new capabilities and efficiencies isn't the goal. The focus should remain on enabling responsible innovation while reducing unnecessary risk. This depends on enforcing default-deny policies that prevent unknown and untrusted actions from taking place.  
  • The big picture: AI-powered attacks may move at machine speed, but they depend on the same permissions as a human-driven attack. If unapproved code cannot execute and privileges are limited, the AI model will hit a wall just like any other attack. 

GDPR has real teeth and an expansive reach

A practical guide to data protection compliance

  • What's happening: The General Data Protection Regulation (GDPR) is the EU's data privacy law, but its reach extends far beyond the EU. Any organization that offers goods or services to individuals in the EU or monitors their behavior may be subject to the GDPR, regardless of where it's headquartered. GDPR has become the global benchmark for data privacy, but compliance is about much more than publishing a privacy policy. Organizations must understand what personal data they collect, why they collect it, where it is stored, who can access it, and how it is protected throughout its lifecycle. 
  • Why it matters: Meeting GDPR requirements means building repeatable processes around data protection. Organizations must establish a lawful basis for processing personal data, maintain records of processing activities, manage third-party vendors, honor individual privacy rights, notify regulators of qualifying breaches, and implement appropriate safeguards.
  • The big picture: Avoiding GDPR penalties requires continuous monitoring and visibility over your data and your vendors. Strong access controls, data governance, and continuous monitoring make it easier to identify unusual activity, respond to data requests, and demonstrate compliance when required. 

How attackers stay hidden for months

The unexpected changes that should raise alarm bells

  • What's happening: Attackers rarely accomplish everything during the initial compromise. By establishing persistence, they can quietly return days, weeks, or even months later to steal data, escalate privileges, or deploy ransomware. Common persistence methods include scheduling malicious tasks, placing malware in startup folders, creating or modifying Windows services, and hijacking trusted applications, especially those with broad permissions. 
  • Why it matters: Persistence methods are often designed to survive patching and routine administrative actions, meaning once attackers get inside, addressing the initial access vector has little effect. If persistence remains, attackers can regain access long after organizations believe the incident has been contained.
  • The big picture: Default-deny is a crucial part of Zero Trust, but continuous monitoring should not be overlooked. Continuous monitoring of your environment helps you understand what "normal activity" is, making it easier to identify suspicious actions, even when they're coming from legitimate applications. Combined with default-deny policies, this makes it easier to stop attackers from establishing persistence and limits the impact of a compromise.
Join ThreatLocker at Black Hat USA, August 1–6, Las Vegas

Proud to be a Black Hat Apex Partner (first and only!)

 

If you'll be at Black Hat USA next week, don't miss the Cyber Hero Team:

  • Booth 3333: Tuesday–Thursday, stop by our booth for swag, Threat Talks, and live in-booth recording with David Bombal, Windows Weekly, and Security Now
  • Welcome Reception at Mandalay Bay: Tuesday from 7–9 p.m. Register here
  • Keynote:  Defending against hidden risks of AI tools in the workplace, Wednesday, 10:30 a.m., Business Hall Main Stage
Connect with ThreatLocker at Black Hat

 Threats you need to know

New ClickFix campaign targeting macOS and Ruby on Rails flaw

 

ClickFix verification trap targeting Mac users

Turning users into the initial access vector

  • What's happening: Attackers are targeting macOS users in a new ClickFix campaign using fake browser verification pages. Users are instructed to open Terminal and paste a command, supposedly as part of a human verification process. Instead, the command downloads and executes malware and gives attackers access without exploiting a vulnerability. ClickFix campaigns have typically targeted Windows environments in the past. 

  • Why it matters: Starting with a fake CAPTCHA or verification gate gives users a false sense of security, especially non-technical users. The user is following instructions on a supposedly trustworthy page, so they may ignore built-in warnings. 
  • The big picture: The more convincing fake verification pages become, the less organizations can rely on users to spot them. Default-deny policies that block unauthorized code and scripts from executing are becoming the only dependable way to stop these attacks after a user has been tricked. 

Ruby on Rails flaw exposes servers through image uploads

Crafted image uploads could lead to file disclosure and remote code execution

  • What's happening: Researchers disclosed a critical vulnerability (CVE-2026-66066) in Ruby on Rails' Active Storage component that could allow unauthenticated attackers to read arbitrary files through crafted image uploads. The flaw could also be escalated to remote code execution under certain conditions, exposing encryption keys, credentials, and configuration files. Organizations running affected Rails versions should apply the available patches immediately. 
  • Why it matters: Patching is the first priority, but defenders should also assume sensitive data may have been exposed before remediation. Rotate credentials where appropriate, review logs for suspicious upload activity, and validate the integrity of affected systems. 
  • The big picture: Framework vulnerabilities are inevitable, making deny-by-default more crucial. Limiting application privileges, restricting application access, and preventing unauthorized child processes helps contain a successful exploitation before it spreads.

ThreatLocker events

Meet the Cyber Hero Team in person at these upcoming events

  • FINRA Conference| Aug. 10–11
    New York City
  • AFCEA Tech Net | Aug. 18–20
    Augusta, GA
  • AdelaideSEC | Aug. 21
    Adelaide, AU
  • ILTACON 2026 | Aug. 23–27
    Nashville, TN

  • Arizona Tech Summit | Aug. 25
    Scottsdale, AZ
  • ISACA Silicon Valley | Aug. 27–28
    Santa Clara, CA
See more upcoming events
ThreatLocker: Zero Trust Platform | Zero Trust Weekly

ThreatLocker, 1901 Summit Tower Blvd, Orlando, Florida 32810, United States

Manage preferences

Connect with us

                             

©2026 ThreatLocker Inc., All Rights Reserved