▶ VIDEO Security Weekly - A CRA Resource

AI Makes Finding Bugs Cheaper

Microsoft reports that AI-driven vulnerability detection now costs an average of $3.61 per successful case within 21.5 minutes. This approach excludes failed candidates, initial screening, human investigation, and patch preparation from the calculation. Companies can now identify and fix their own flaws without paying bug bounties or managing complex disclosure processes. The technology enables organizations to leverage their superior knowledge of their software to secure systems more efficiently than before.

▶ VIDEO John Hammond

Following The Payload

A malicious script executes a PowerShell command to retrieve content from app data runtime directories, specifically targeting BTC1 and RENV environments. The process includes a 60-second delay before cleaning up and writing a Base64-encoded zip file to the system. This operation connects to a full IP address and a specific URL, indicating a multi-stage attack vector. Analysts identified a third variant based on a different configuration, suggesting the threat actor is deploying diverse payloads to evade detection.