TCSR Weekly Roundup: Cloud Key Exposures, Android Auto Malware, and AI Defense Funds
This week's roundup covers leaked AWS keys, emerging Android car malware, Microsoft Teams phishing, and the latest AI security developments.
Welcome to this week's TCSR roundup. In this edition, we analyze critical exposures ranging from leaked cloud credentials to sophisticated malware targeting unexpected IoT devices like car head units. We also cover the growing intersection of AI and cybersecurity, supply chain vulnerabilities, and key enterprise software threats that demand the attention of IT leads and business owners.
Cloud Exposures and Supply Chain Vulnerabilities
Cloud security and supply chain integrity remain top priorities for enterprise defenders. This week, researchers revealed that hundreds of leaked AWS keys have been found in the wild, granting complete control over affected corporate accounts. This highlights the critical importance of secure credential management.
Meanwhile, U.S. Bank clarified that recent data breach claims were linked to a fourth-party vendor incident, illustrating how deeply supply chain risks can run. Additionally, software supply chains faced threats as 14 trojanized npm packages were discovered distributing the RedC2 4.0 Linux backdoor, which features AI-assisted command-and-control (C2) capabilities.
How TCSR helps: Regularly scanning your external attack surface for exposed files, credentials, and misconfigured cloud repositories is a crucial first step in preventing these types of supply chain compromises.
Android and IoT Malware Diversifies
Android malware is expanding its tactics and target base. The ToxicPanda banking trojan (alongside other active threats like Manic and Grandoreiro) has been observed abusing VPN permissions to block Google Play and evade detection.
In a more unusual development, threat actors are now targeting Android-based car head units. Using built-in system updaters, attackers are infecting these automotive systems with proxy botnet malware to conduct ad fraud, showing that IoT and automotive devices remain highly vulnerable to exploitation.
The Dual Role of AI in Security
Artificial intelligence continues to reshape both defensive and offensive security strategies. On the defensive side, Anthropic has expanded access to its Mythos 5 model for cyber defenders and unveiled a $35 million open-source fund to support defensive tools.
Conversely, the risks associated with AI are growing. The Open Worldwide Application Security Project (OWASP) released a new security blueprint flagging the top AI skill risks for organizations. In other AI news, researchers report that AI is learning to write genetic code, while GitHub recently denied claims that an AI assistant was responsible for a software bug.
Infrastructure, Protocol, and OS Threats
Enterprise Windows environments and industrial networks face notable challenges this week:
- Driver Weaponization: A new technique shows that Microsoft Defender's own driver can be weaponized at boot to delete security software, bypassing traditional protections.
- Named Pipes: Security researchers warned of attacks targeting Named Pipes, a critical mechanism used for Windows interprocess communication.
- Teams Phishing: A new phishing campaign on Microsoft Teams is actively distributing "SynkLoader" malware.
- OT Risks: Experts warned that an emerging industrial protocol family could put Operational Technology (OT) systems at risk if not properly secured.
Regulatory, Legal, and Industry Updates
In regulatory news, TikTok has agreed to a $400 million settlement to resolve a U.S. child privacy lawsuit. On the government front, U.S. lawmakers are calling for an investigation into how recent staffing cuts at the Cybersecurity and Infrastructure Security Agency (CISA) might impact national defense.
In the healthcare sector, Canada's Hospital for Sick Children was targeted by cybercriminals once again, resulting in the theft of employee data. Additionally, former NSA Director Paul Nakasone has launched a new national security advisory firm, and reports emerged that T-Mobile recently cut a physical cable to stop active hackers.
What This Means for You
This week's developments emphasize that security is only as strong as your weakest link—whether that is a fourth-party vendor, an exposed AWS key, or a trusted system driver. To protect your organization, maintain a proactive defense posture. Regularly auditing your external attack surface, scanning for exposed files, verifying TLS configurations, and tracking known CVEs are essential steps to identifying and mitigating these vulnerabilities before they can be exploited.
Sources
- Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund — SecurityWeek
- ToxicPanda Android malware uses VPN permissions to block Google Play — BleepingComputer
- TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit — The Hacker News
- Hackers infect Android car head units with proxy botnet malware — BleepingComputer
- Named Pipes Under Attack: Securing Windows Interprocess Communication — BleepingComputer
- Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight — SecurityWeek
- Friday Squid Blogging: Neon Flying Squid — Schneier on Security
- How an Emerging Industrial Protocol Family Could Put OT at Risk — Dark Reading
- Lawmakers call for investigation into impact of CISA staffing cuts — The Record
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 — The Hacker News