How a recent malware campaign highlights a tricky evasion technique
Abusing trusted infrastructure to deliver a malicious payload is at the heart of VEIL#DROP.

Caroline Nihill is a reporter for IT Brew. Her work primarily focuses on cybersecurity, IT operations, and tech interactions between the private and public sectors. Based in the D.C. area, Caroline has also worked for Scoop News Group outlets including FedScoop, CyberScoop, StateScoop, and others.
Abusing trusted infrastructure to deliver a malicious payload is at the heart of VEIL#DROP.
One expert suggests other companies could emulate Bloomberg’s tactics.
The attack leverages malicious domains that mimic actual hospitality and commerce websites.
One key ingredient: agentic AI.
Mapping internal- and external-facing systems is key to helping mitigate attacks.
And how the company keeps paving new ones.
Experts point to the need to secure systems before the technology fully arrives.
The GetReal Security founder and chief science officer says many defenders are doing nothing about deepfake threats.
No crystal ball was consulted during the reporting of this story.
Microsoft veteran says the tooling can assist with agentic development and testing frameworks.