The last day brought a privacy flaw affecting Apple devices, a self-spreading botnet built from hijacked AI infrastructure, real consequences for a hacker behind one of the largest cloud data-theft campaigns, and a fast-moving phishing trend aimed squarely at Microsoft 365 users. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.

A flaw in Apple’s browser engine can expose your real IP address even when you think a privacy tool is hiding it. Security researchers found that three features in WebKit, the engine behind Safari and every iOS browser, can bypass proxy settings entirely and leak a device’s real IP address or DNS activity, undermining the protection offered by Apple’s own iCloud Private Relay as well as third-party privacy browsers like Tor and Psylo. Device-level VPNs are not affected, only app-level proxy tools. If your business relies on Private Relay or a privacy browser rather than a full VPN to protect traffic on company iPhones or Macs, especially for remote or traveling staff, this is worth knowing does not fully hold up until Apple ships a fix. Read more at Malwarebytes

Attackers are hijacking AI computing clusters and turning them into a self-spreading botnet, and the group behind it has been active since 2020. Researchers linked a group called TeamPCP to ShadowRay 2.0, an ongoing campaign that exploits a known flaw in Ray, a popular open source framework used to power many AI systems, to seize control of exposed computing clusters and enlist them into a botnet capable of cryptojacking, data theft, and denial-of-service attacks. The same infrastructure ties back to attacks on Redis and Docker dating to 2020, well before AI clusters were a target. If your business or a vendor runs Ray for any machine learning workloads, this is worth confirming those clusters are not exposed to the open internet, since this specific flaw has been public and exploitable for years. Read more at SecurityWeek

The hacker behind one of the largest cloud data-theft campaigns in recent memory has pleaded guilty, and he collected millions doing it. Connor Riley Moucka, a 26 year old Canadian, pleaded guilty to using stolen credentials to break into more than 165 organizations’ Snowflake cloud accounts, stealing data that included financial records, Social Security numbers, and passport numbers, then extorting victims for over $2.5 million. He faces up to 32 years in prison at sentencing in October. If your business uses Snowflake or any similar cloud data platform, the core lesson holds regardless of the vendor: this campaign succeeded almost entirely through stolen credentials rather than a platform vulnerability, which is exactly what multi-factor authentication on every account is meant to stop. Read more at TechCrunch

A fast-growing phishing trend is stealing Microsoft 365 logins in as little as 12 minutes, and it is aimed mostly at leadership. Phishing-as-a-service platforms built around OAuth device-code abuse and adversary-in-the-middle kits, including one called EvilTokens that has AI built in, are driving a sharp rise in attacks that steal Microsoft 365 session tokens rather than just passwords, sidestepping multi-factor authentication in the process. Researchers found 77 percent of these Microsoft Teams-based social engineering attempts targeted executives, managers, or directors specifically, with a median time of just 12 minutes from the first message to a malicious script running. If your business runs on Microsoft 365, this is worth a direct reminder to your leadership team in particular: a device login code or Teams message asking you to approve something quickly is exactly the pressure this attack is designed to create. Read more at Huntress


Follow up on this week’s AI agent stories: Meta has become the third major AI lab in a matter of weeks to disclose that one of its models breached an outside company during testing. Meta said its Muse Spark model gained unauthorized access to another company’s systems and altered internal data during a security evaluation, after testing partner Irregular mistakenly gave the model open internet access it was never supposed to have. Meta says this was a configuration error rather than the model escaping any sandbox on its own, but it follows comparable disclosures from Anthropic and OpenAI in recent weeks, making Meta the third lab to admit its AI touched real systems it should never have reached. The pattern across all three incidents is the same: not a single flaw in the AI itself, but a testing environment that was not as isolated as everyone assumed. Read more at Al Jazeera


Sponsored by Lucky 13 Solutions

Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.


Get the Business IT News Roundup in your inbox: