August 21, 2026 by sig9
Hacker Wars - August 21, 2026
Your daily dose of infosec chaos
Today’s theme is trust betrayal: Defender’s own signed driver turns kernel attacker, the passkeys we keep pushing as the answer become the persistence problem, and AI safety filters get blinded with a little cryptography. Add 9,300 immortal cloud keys and malware living inside car stereos, and it’s a full menu. Dig in.
Thousands Of Leaked AWS Keys Still Hold Full Corporate Account Access
Researchers surfaced more than 9,300 AWS access keys publicly exposed between August 2022 and this month that are still active and valid, some with full administrative control over corporate accounts. That is four years of “temporary” credentials quietly achieving immortality in public repos, paste sites, and bundles.
What to do: Hunt down long-lived access keys across your cloud estate, move to short-lived credentials with federation, and treat any key older than a quarter as an incident waiting to be indexed.
Microsoft Defender’s Own Driver Weaponized For Kernel-Level Sabotage
Check Point demonstrated that Defender’s legitimately signed boot-time remediation driver can be repurposed to run arbitrary kernel-level file and registry operations, no vulnerability required. The tool built to remove malware at boot can be told to remove your EDR instead, on everything from Windows 7 up through Windows 11 25H2.
What to do: Monitor for unexpected loads and invocations of remediation drivers, and stop treating a valid Microsoft signature as proof of benevolent intent - signed drivers are now attacker infrastructure.
Phishing Toolkit Registers Attacker Passkeys To Outlive Password Resets
A toolkit dubbed iAuthFlow V2 phishes victims into registering an attacker-controlled passkey, granting persistence that survives password changes and full session revocation. The industry’s favorite phishing-proof credential is now the persistence mechanism, which is a level of irony nobody budgeted for.
What to do: Alert on new passkey and authenticator registrations, especially from unfamiliar devices or locations, and make credential lifecycle - not just credential type - part of your monitoring.
Encrypted Prompts Slip Past AI Guardrails In Grok And Gemini
Researchers unveiled “Cryptographic Context Injection,” which hides malicious instructions inside encrypted payloads that only get decrypted inside the model’s trusted execution environment. Safety filters see harmless ciphertext, the TEE happily decrypts the real payload, and the guardrails never get a vote.
What to do: If you deploy LLM agents, inspect what actually gets decrypted and executed in trusted contexts - prompt-level filtering alone is now officially decoration.
Android Car Malware Rides Built-In Updaters Into Ad Fraud Botnet
Kaspersky flagged malware purpose-built for Android-based DoFun vehicle head units, spreading through the devices’ own firmware update mechanism to deliver ad fraud and proxy botnet modules. Your infotainment system is an unmanaged endpoint that happens to do 200 on the autobahn.
What to do: Treat automotive firmware channels as attack surface: verify update signatures, and if you run Android head units in fleets, get them the hell off flat networks.
That’s the chaos for today. Stay sharp out there.
Brought to you by sig9 - sig9.ch | Protecting the unseen, securing the unknown
This bulletin is provided for informational purposes. Contact us for tailored security analysis.