Cyber security developments for Wednesday the 5th of August 2026 covering articles added to the BlueTeamSec community on infosec.pub. Today we have 7 articles to cover. All attribution is by the article authors. All article analysis is automated.
Kaspersky have documented two new backdoors, OctLurk and SilkLurk, being used by Chinese-speaking actors against government organisations across Central Asia since January last year. The malware runs in memory using loaders tied to specific hardware identifiers, which makes analysis harder and keeps the operation under the radar.
The U.S. State Department has issued a formal alert regarding North Korean IT workers operating globally under false identities. They're securing remote employment contracts to fund weapons programmes whilst posing insider threats to the organisations that hire them — worth flagging if you're involved in recruitment or vetting for technical roles.
Following on from the Hugging Face intrusion we covered earlier this week, Truffle Security scanned seven point six petabytes of training data on the platform and found over two hundred and twenty thousand live credentials exposed across six thousand public datasets. That includes thousands of cloud service keys, GitHub tokens with elevated privileges, and credentials for AI providers — all quietly sitting in scraped data that's been remixed into training corpora.
ENISA have published a Secure by Design and Default playbook containing twenty-two frameworks aimed at helping organisations, particularly smaller ones, embed security throughout the development lifecycle rather than retrofitting it later. Useful background if you're looking to formalise secure development practices.
Researchers at Nanyang Technological University have developed a multi-agent AI framework called iFinder that uncovered implicit trust vulnerabilities in five G and four G core carrier networks. The tool exploits the architectural mismatch between legacy closed networks and cloud-native deployments, where network functions still assume internal traffic is inherently trusted — enabling session hijacking and state-management attacks.
Security researchers have published RedLotus, a proof-of-concept bootkit written in Rust that compromises the boot process at the firmware layer before the operating system even loads. It hooks kernel functions and bypasses endpoint detection by executing before security tools initialise, though it does require Secure Boot to be disabled and relies on hardcoded offsets for specific Windows versions.
And finally, a Binary Ninja plugin called binja-diff has been released that enables side-by-side binary comparison for patch analysis and firmware diffing. One for reverse engineers looking to identify code changes between software versions.
That concludes today's briefing.