Source context

Why this day matters

  • GitLab fixes critical AI Gateway flaw that could let authenticated Duo users escape a prompt sandbox and execute commands on self-hosted gateways.
  • doxx.net’s new ADN platform prevents agentic misadventure while the agent is operating under the user’s authority. The post doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures appeared first on SecurityWeek .
Validated article intelligence

Enriched source records

Expand a row to inspect claims and citations

Luna-generated claims retained by the evidence and claim-validation gates. Automated validation does not imply human review. A record does not need a CVE to be included.

Luna-enriched source article · securityaffairs

Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel

Cisco Talos tracks UAT-11587, which it assesses with high confidence as China-nexus; by July 2026, the group had targeted at least 16 government and policy organizations across eight Asian countries.

8 retained claims27 cited excerpts

Source published Oct 3, 2026, 9:26 AM UTC · Evidence retrieved Oct 3, 2026, 2:51 PM UTC

What happened

Cisco Talos tracks UAT-11587, which it assesses with high confidence as China-nexus; by July 2026, the group had targeted at least 16 government and policy organizations across eight Asian countries. [1] [2]

Antino is a Rust-compiled Windows backdoor supporting reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence on both 32-bit and 64-bit Windows. [3] [4] [5]

Antino uses Microsoft Graph with Outlook and OneDrive for command-and-control: it reads commands from an Outlook mailbox, returns results through email, and transfers stolen files through OneDrive. [6] [7] [8] [9]

The intrusion began with targeted phishing using researched decoy documents, including material copied from a Taiwan Ministry of Finance ruling and a reused Associated Press story. [12] [13] [14] [15]

The delivery chain used a Gmail-like attachment preview linking to an attacker-controlled page, followed by HTA, Windows Script Host and .NET deserialization stages; Antino was sideloaded through a signed Microsoft diagnostic binary. [21] [22] [23] [24]

Why it matters

Using Microsoft Graph allows Antino traffic to blend with normal Microsoft 365 activity; the implant polls its Outlook mailbox for commands every ten seconds. [7] [8] [10] [11]

A spoofed message passed SPF but failed DMARC alignment; because the impersonated domain used monitoring rather than rejection, the email still reached the inbox. [16] [17] [18] [19] [20]

Known limitations

Talos based its China-nexus assessment on development, preparation-environment and targeting indicators, including Simplified Chinese metadata, UTC+8 timestamps and a mainland-China Rust package mirror; the assessment was not attributed to a single indicator. [2] [25] [26] [27]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Cisco Talos has been tracking a cluster of espionage activity since September 2025 that it calls UAT-11587, and by July 2026 the group had hit at least 16 government and policy organizations across eight Asian countries.
  2. [2]
    “Based on the development, preparation-environment, and targeting indicators detailed in this report, Talos assesses with high confidence that UAT-11587 is China-nexus.” the report concludes.
  3. [3]
    Antino is written in Rust and works on both 32-bit and 64-bit versions of Windows.
  4. [4]
    It supports the usual backdoor features, including shell and PowerShell access, file transfers, in-memory shellcode execution and persistence.
  5. [5]
    “Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence.
  6. [6]
    Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.” reads the report published by Talos.
  7. [7]
    What makes Antino different is how it communicates: instead of using its own command-and-control server, it uses Microsoft Graph to read commands from an Outlook mailbox and send stolen files to OneDrive.
  8. [8]
    Once Antino is running, it checks its Outlook mailbox for new commands every ten seconds.
  9. [9]
    “Command messages are identified by the subject prefix command_req_[session_id] and responses by command_res_[session_id], as indicated in the HTTP GET request sent by Antino: “ A separate system is used to upload stolen files to one OneDrive folder and download attacker tools from another.
  10. [10]
    This allows its traffic to blend in with normal Microsoft 365 activity.
  11. [11]
    The implant actively pulls commands from the threat actor’s Outlook mailbox folder every 10 seconds.
  12. [12]
    The attack starts in a more traditional way, with a convincing phishing email.
  13. [13]
    UAT-11587 created highly targeted documents that suggest the attackers had researched their victims, including a fake workshop document about Taiwan’s information warfare and a document that closely copied a real Taiwan Ministry of Finance ruling about tax treatment for legislators.
  14. [14]
    “The document exactly reproduces a public Taiwan Ministry of Finance ruling to make the decoy appear credible.” conctinues the report.
  15. [15]
    “Its subject strongly suggests that it was prepared for members of Taiwan’s public sector.” In another case, the attackers reused a real Associated Press story about alleged Russian offers to the US over Venezuela.
  16. [16]
    The delivery trick is a simple but effective email spoofing technique that takes advantage of a gap many people overlook.
  17. [17]
    The attackers sent the email through a legitimate provider, using one domain as the technical sender, while the visible From address showed the organization they were impersonating.
  18. [18]
    SPF passed because the real sending domain was authorized, but DMARC detected the mismatch and failed.
  19. [19]
    That still wasn’t enough to block the message.
  20. [20]
    The impersonated domain had a DMARC policy set to monitoring rather than rejection, so the failed email still reached the inbox.
  21. [21]
    The attackers recreated Gmail’s normal attachment preview card almost pixel by pixel using images embedded in the email’s HTML.
  22. [22]
    They then made the fake preview a link to a page controlled by the attackers.
  23. [23]
    From that click, a five-stage chain kicks in, leaning on legitimate-looking HTA files, Windows Script Host, and a scripted .NET deserialization trick that abuses a known gadget chain to load malicious code inside a trusted process.
  24. [24]
    The final stage sideloads Antino through a signed Microsoft diagnostic binary, meaning the thing dropping the backdoor onto disk is a tool Windows itself trusts by default.
  25. [25]
    The attribution case leans on accumulated small details rather than any single smoking gun, which is honestly how these assessments should work.
  26. [26]
    Decoy document metadata carries Simplified Chinese language tags and a UTC+8 timestamp, a combination more consistent with mainland China than Taiwan or Hong Kong, where Traditional Chinese dominates.
  27. [27]
    Separately, ten different Antino builds reference a Rust package mirror built specifically to speed up dependency downloads inside mainland China, the kind of tooling choice a developer picks for convenience, not for disguise.

Read the original article →

Published records

Additional source records

Expand a row to inspect provenance
Material developments

Fortra Patches Critical Vulnerabilities in BoKS

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed

Securityaffairs published details for CVE-2026-90970.

1 source recordContext source

What happened

Securityaffairs published details for CVE-2026-90970.

Why it matters

A reviewed impact interpretation has not been published for this record.

Structured associations

CVE-2026-90970 mentioned

Reviewed next steps

  • Check asset inventory and patch status for CVE-2026-90970.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Cloud and infrastructure

The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

The Hacker News published a source item for review.

1 source recordContext source

What happened

The Hacker News published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

AI and model reality

doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures

Securityweek published a source item for review.

1 source recordContext source

What happened

Securityweek published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.