started · updated
Cybersecurity threats escalate as hackers exploit development tools and AI
Cybersecurity research highlights a growing trend of sophisticated hacking organizations targeting corporate infrastructure through software development environments and automated tools. A joint study by SentinelOne and Tenable revealed that groups such as North Korea’s Lazarus and Russia’s APT29 have exploited vulnerabilities in ‘TeamCity’, a software development automation tool, to gain access to internal systems.
These attackers target the software supply chain by compromising the environments where code is built and tested. Beyond development tools, hackers are also targeting VPNs and firewalls to move laterally within networks. The study noted a significant delay in patching these critical vulnerabilities, with a median period of 461 days.
In a separate development, analysis of the ransomware group ‘The Gentleman’ by Oasis Security uncovered evidence of organized training for hackers to bypass Endpoint Detection and Response (EDR) solutions. The group reportedly used AI coding assistants to develop a custom command-and-control framework named ‘TukTuk’, which includes features for remote command execution and credential theft via forged Windows security dialogs.
Entities
Lazarus Group · Microsoft · Oasis Security · SentinelOne · Tenable