< ciso
brief />
Tag Banner

All news with #elastic tag

9 articles

Tokenomics Risks for AI-Driven Security Teams

🔒 Security teams implementing AI automation face new threats from token-based attacks that can exhaust budgets or trigger provider filters, disrupting incident response. Elastic’s cost estimates show large variability in agent-based SOC expenses, and prompt injection can dramatically inflate token consumption and latency. Practical defenses include deterministic handling of verifiable data, strict limits and alerts, predefined failover behaviors, careful permissioning, scanning untrusted inputs, and using local models to reduce vendor-induced outages.
read more →

KREMLIN malware forces browser extension installs

🔒 Researchers at Elastic Security Labs uncovered a banking malware toolkit called KREMLIN that has been active since mid-2025 and installs malicious Chrome and Edge extensions to steal credentials, session tokens, and other sensitive data. The infection begins with a malicious JavaScript file posing as banking documents, which downloads Node.js, establishes persistence, and retrieves payload locations from an Ethereum smart contract. KREMLIN copies extensions into browser profile directories, regenerates integrity HMACs using browser keys, and enables them without user consent, while also operating as an info-stealer and delivering RATs like REMCOS.
read more →

TELEPUZ modular malware spreads via ClickFix attacks

🛡️ Elastic Security Labs disclosed a new lightweight, modular malware named TELEPUZ that has been propagated through ClickFix (pastejacking) lures since late April 2026. The campaign delivers a Go-based Vidar stealer variant which then fetches a C-based TELEPUZ stager and main DLL, with artifacts hosted on a domain linked to the campaign. TELEPUZ includes extensive obfuscation, anti-VM and geofencing checks, AMSI/ETW unhooking, privilege escalation, service persistence, and WebSocket-based C2 with fallback retrieval via Telegram, Steam, DNS and a Polygon smart contract.
read more →

Threat Actor Used Elastic Cloud SIEM to Store Stolen Data

🔒 Researchers uncovered a campaign in which a threat actor exploited multiple enterprise software flaws to harvest system data and deposit it into a free-trial Elastic Cloud SIEM instance. The attacker used an encoded PowerShell payload to collect OS, hardware, Active Directory and patch details, sending records into an Elasticsearch index named systeminfo. Telemetry showed the trial was registered via a disposable email and accessed repeatedly through Kibana as the operator triaged victims. Huntress coordinated with Elastic and law enforcement to notify affected organisations and take the instance offline.
read more →

ClickFix Campaign Uses Compromised Sites to Deploy MIMICRAT

🔒 Elastic Security Labs disclosed a ClickFix campaign that leverages compromised legitimate websites to deliver a new remote access trojan named MIMICRAT. Attackers inject JavaScript to load an externally hosted PHP lure that shows a fake Cloudflare verification page and tricks victims into running a PowerShell command. A multi-stage PowerShell chain performs ETW and AMSI bypasses, then drops a Lua-based in-memory loader which decrypts shellcode to install the RAT. MIMICRAT communicates over HTTPS on port 443 using profiles that mimic web analytics and supports localized lures in 17 languages to widen impact.
read more →

Cybersecurity leaders' top seven takeaways from 2025

🛡️ In 2025 CISOs reported that AI moved from experiment to dominant force, giving defenders major productivity gains while simultaneously enabling faster, more precise attacks. Leaders from Smartsheet, Calendly, Elastic and HCLTech say AI reshaped priorities, forced strategy changes, and amplified non-human identities and third-party risk. Heightened regulation and stricter enforcement of standards like NIST and ISO pushed security accountability up to boards.
read more →

Dragon Breath Deploys RONINGLOADER to Deliver Gh0st RAT

🔒 Elastic Security Labs and Unit 42 describe a China‑focused campaign in which the actor Dragon Breath uses a multi‑stage loader named RONINGLOADER to deliver a modified Gh0st RAT. The attack leverages trojanized NSIS installers that drop two embedded packages—one benign and one stealthy—to load a DLL and an encrypted tp.png file containing shellcode. The loader employs signed drivers, WDAC tampering, and Protected Process Light abuse to neutralise endpoint protections popular in the Chinese market before injecting a persistent high‑privilege backdoor.
read more →

OpenSearch Adds Derived Source Feature to Reduce Storage

🔧 Amazon OpenSearch Service announced support for Derived Source, an opt-in feature that lets you omit persisting the document _source and reconstruct it dynamically when needed. The capability, available with OpenSearch 3.1, reduces domain storage by skipping stored _source fields while still supporting search, get, mget, reindex, and update operations. Enable Derived Source at index creation using composite index settings.
read more →

OpenSearch Star-Tree Index Speeds Aggregations for Analytics

⚡ OpenSearch introduces the Star-Tree Index, an opt-in index type that pre-aggregates data at ingestion to enable sub-second responses for frequent high-cardinality and multi-dimensional aggregations such as terms, histogram, and range. The feature is designed for real-time analytics and requires no query syntax changes; OpenSearch automatically routes supported queries to the optimized path. Early benchmarks indicate markedly faster aggregation performance on large datasets with minimal impact to ingestion throughput. Available in regions that support OpenSearch 3.1 and enabled at index creation via composite index settings.
read more →