October 3, 2026
Why this day matters
- GitLab fixes critical AI Gateway flaw that could let authenticated Duo users escape a prompt sandbox and execute commands on self-hosted gateways.
- doxx.net’s new ADN platform prevents agentic misadventure while the agent is operating under the user’s authority. The post doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures appeared first on SecurityWeek .
Enriched source records
Luna-generated claims retained by the evidence and claim-validation gates. Automated validation does not imply human review. A record does not need a CVE to be included.
Luna-enriched source article · securityaffairsAntino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel
Cisco Talos tracks UAT-11587, which it assesses with high confidence as China-nexus; by July 2026, the group had targeted at least 16 government and policy organizations across eight Asian countries.
Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel
Cisco Talos tracks UAT-11587, which it assesses with high confidence as China-nexus; by July 2026, the group had targeted at least 16 government and policy organizations across eight Asian countries.
Source published Oct 3, 2026, 9:26 AM UTC · Evidence retrieved Oct 3, 2026, 2:51 PM UTC
What happened
Cisco Talos tracks UAT-11587, which it assesses with high confidence as China-nexus; by July 2026, the group had targeted at least 16 government and policy organizations across eight Asian countries. [1] [2]
Antino is a Rust-compiled Windows backdoor supporting reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence on both 32-bit and 64-bit Windows. [3] [4] [5]
Antino uses Microsoft Graph with Outlook and OneDrive for command-and-control: it reads commands from an Outlook mailbox, returns results through email, and transfers stolen files through OneDrive. [6] [7] [8] [9]
The intrusion began with targeted phishing using researched decoy documents, including material copied from a Taiwan Ministry of Finance ruling and a reused Associated Press story. [12] [13] [14] [15]
The delivery chain used a Gmail-like attachment preview linking to an attacker-controlled page, followed by HTA, Windows Script Host and .NET deserialization stages; Antino was sideloaded through a signed Microsoft diagnostic binary. [21] [22] [23] [24]
Why it matters
Using Microsoft Graph allows Antino traffic to blend with normal Microsoft 365 activity; the implant polls its Outlook mailbox for commands every ten seconds. [7] [8] [10] [11]
A spoofed message passed SPF but failed DMARC alignment; because the impersonated domain used monitoring rather than rejection, the email still reached the inbox. [16] [17] [18] [19] [20]
Known limitations
Talos based its China-nexus assessment on development, preparation-environment and targeting indicators, including Simplified Chinese metadata, UTC+8 timestamps and a mainland-China Rust package mirror; the assessment was not attributed to a single indicator. [2] [25] [26] [27]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Cisco Talos has been tracking a cluster of espionage activity since September 2025 that it calls UAT-11587, and by July 2026 the group had hit at least 16 government and policy organizations across eight Asian countries.
- [2]
“Based on the development, preparation-environment, and targeting indicators detailed in this report, Talos assesses with high confidence that UAT-11587 is China-nexus.” the report concludes.
- [3]
Antino is written in Rust and works on both 32-bit and 64-bit versions of Windows.
- [4]
It supports the usual backdoor features, including shell and PowerShell access, file transfers, in-memory shellcode execution and persistence.
- [5]
“Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence.
- [6]
Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.” reads the report published by Talos.
- [7]
What makes Antino different is how it communicates: instead of using its own command-and-control server, it uses Microsoft Graph to read commands from an Outlook mailbox and send stolen files to OneDrive.
- [8]
Once Antino is running, it checks its Outlook mailbox for new commands every ten seconds.
- [9]
“Command messages are identified by the subject prefix command_req_[session_id] and responses by command_res_[session_id], as indicated in the HTTP GET request sent by Antino: “ A separate system is used to upload stolen files to one OneDrive folder and download attacker tools from another.
- [10]
This allows its traffic to blend in with normal Microsoft 365 activity.
- [11]
The implant actively pulls commands from the threat actor’s Outlook mailbox folder every 10 seconds.
- [12]
The attack starts in a more traditional way, with a convincing phishing email.
- [13]
UAT-11587 created highly targeted documents that suggest the attackers had researched their victims, including a fake workshop document about Taiwan’s information warfare and a document that closely copied a real Taiwan Ministry of Finance ruling about tax treatment for legislators.
- [14]
“The document exactly reproduces a public Taiwan Ministry of Finance ruling to make the decoy appear credible.” conctinues the report.
- [15]
“Its subject strongly suggests that it was prepared for members of Taiwan’s public sector.” In another case, the attackers reused a real Associated Press story about alleged Russian offers to the US over Venezuela.
- [16]
The delivery trick is a simple but effective email spoofing technique that takes advantage of a gap many people overlook.
- [17]
The attackers sent the email through a legitimate provider, using one domain as the technical sender, while the visible From address showed the organization they were impersonating.
- [18]
SPF passed because the real sending domain was authorized, but DMARC detected the mismatch and failed.
- [19]
That still wasn’t enough to block the message.
- [20]
The impersonated domain had a DMARC policy set to monitoring rather than rejection, so the failed email still reached the inbox.
- [21]
The attackers recreated Gmail’s normal attachment preview card almost pixel by pixel using images embedded in the email’s HTML.
- [22]
They then made the fake preview a link to a page controlled by the attackers.
- [23]
From that click, a five-stage chain kicks in, leaning on legitimate-looking HTA files, Windows Script Host, and a scripted .NET deserialization trick that abuses a known gadget chain to load malicious code inside a trusted process.
- [24]
The final stage sideloads Antino through a signed Microsoft diagnostic binary, meaning the thing dropping the backdoor onto disk is a tool Windows itself trusts by default.
- [25]
The attribution case leans on accumulated small details rather than any single smoking gun, which is honestly how these assessments should work.
- [26]
Decoy document metadata carries Simplified Chinese language tags and a UTC+8 timestamp, a combination more consistent with mainland China than Taiwan or Hong Kong, where Traditional Chinese dominates.
- [27]
Separately, ten different Antino builds reference a Rust package mirror built specifically to speed up dependency downloads inside mainland China, the kind of tooling choice a developer picks for convenience, not for disguise.
Additional source records
Material developmentsFortra Patches Critical Vulnerabilities in BoKS
Securityweek published a source item for review.
Fortra Patches Critical Vulnerabilities in BoKS
Securityweek published a source item for review.
What happened
Securityweek published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Fortra Patches Critical Vulnerabilities in BoKS Securityweek · Published 2026-10-03T11:34:00Z · Retrieved Oct 3, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsCVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed
Securityaffairs published details for CVE-2026-90970.
CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed
Securityaffairs published details for CVE-2026-90970.
What happened
Securityaffairs published details for CVE-2026-90970.
Why it matters
A reviewed impact interpretation has not been published for this record.
Structured associations
Reviewed next steps
- Check asset inventory and patch status for CVE-2026-90970.
Evidence
- CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed Securityaffairs · Published 2026-10-03T10:43:39Z · Retrieved Oct 3, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Cloud and infrastructureThe State of Cybersecurity in 2026: Key Segments, Insights, and Innovations
The Hacker News published a source item for review.
The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations
The Hacker News published a source item for review.
What happened
The Hacker News published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations The Hacker News · Published 2026-10-03T11:00:00Z · Retrieved Oct 3, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
AI and model realitydoxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures
Securityweek published a source item for review.
doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures
Securityweek published a source item for review.
What happened
Securityweek published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures Securityweek · Published 2026-10-03T11:45:00Z · Retrieved Oct 3, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.