Blog
Short updates, summaries, and notable threat writeups.
Recent posts
- Langflow CVE exploitation canary timeline: two attackers, two playbooks on the same AI-stack target (VulnCheck, Aug 28, 2026) — VulnCheck's Aug 28 post (companion to its 1H-2026 State of Exploitation report) publishes canary telemetry on Langflow: 12 Langflow CVEs now with in-the-wild exploitation evidence (11 added during 2026) and 15,000+ successful canary attempts across CVE-2026-0769 / CVE-2025-3248 / CVE-2026-5027, with hundreds of Langflow hosts still active and vulnerable on the public internet (highest concentration: US). Two financially motivated attackers ran independent playbooks on the same target in the same window: Attacker 1 (May 12–Jun 8) entered via CVE-2026-5027, deployed a Python credential harvester + SimpleHelp RAT, exfiltrated to
23.234.98[.]182:9999, and established IRC C2 to185.117.74[.]172:6667with cron persistence0 * * * * /usr/bin/3WA72N.sh; Attacker 2 (Apr 22–Jun 25) entered via CVE-2025-3248, then Chisel SOCKS5 → pearl-miner XMR mining → auditd disabled (forensic blind spot from Jun 10) → CVE-2026-0769 dropping.sysd/.cache-sysd/.watchdog.sh→ PocSuite3 → SSH pivot to216.78.235[.]34for target expansion. Durable read: same target, divergent entry CVE, objective, C2, and kit — the tell is per-operator post-exploitation behavior, not "Langflow was hit." - Sality P2P botnet disrupted: CrowdStrike P2P sinkholing operation with DOJ/FBI ends a 23-year file-infecting botnet (Aug 31, 2026) — CrowdStrike Counter Adversary Operations, with the DOJ, FBI, DoD OIG DCIS, and Shadowserver Foundation (support: Europol, Eurojust, and law enforcement in Bulgaria, Hungary, and Romania), executed an August 31, 2026 P2P sinkholing disruption of the Sality peer-to-peer botnet — a polymorphic file-infecting criminal infrastructure that has operated since 2003 across 33,000+ machines. Sality's two-decade durability came from two properties the sinkhole turned against it: no peer authentication (any host that answered the P2P handshake was accepted as a legitimate peer, so a defender could join as an indistinguishable full participant) and a file-infecting protocol that cannot be code-updated (bots don't fetch new code from a C2; the spreading mechanism is on-disk, so every protocol weakness has been permanent for 20 years). The operation targeted the super-peer list (the finite set of publicly reachable infected machines that form the P2P backbone): during each bot's ~40-minute peer-verification cycle it invalidated legitimate super-peer entries and injected CrowdStrike-operated sinkholes into the emptied lists, while law enforcement took down the URLs currently hosting Sality payloads so bots holding active URL packs cannot fetch new payloads. Once isolated, infected hosts can no longer receive URL packs (payload-download instructions) or file packs (direct payload transfers). Two independent P2P networks (v3 and v4 — same codebase and operator, but incompatible protocol versions and different cryptographic keys) are now isolated and beaconing to sinkholes; the operator (a single, financially motivated criminal, no state attribution) has lost control of the network. The ~8-year-primary payload EggJagger is a crypto-wallet clipjacking tool (monitors the clipboard for BTC/ETH addresses and silently swaps them for operator-controlled ones); CrowdStrike estimates ≥ ₽12.1M (~$150,000 USD) stolen, with the never-spent portfolio peaking at ~₽147M in January 2025. The operator also ran on-demand DDoS (Arabic financial-forum, April 2016; a Ukrainian forum on Feb 25, 2022, the day after Russia's full-scale invasion; and a Russian crypto-exchange in Sept 2023 where the payload was compiled seconds before upload). Durable defender core: the disruption does not remove already-installed malware — hunt the lighthouse UDP beacon to
188.166.101[.]148, the v3/v4 URL-pack URLs (theunforgiven.p8[.]hu,painelwebradiodigital.awardspace[.]info,sgwebdesigner.free[.]fr,yonelco[.]com,pozdravizbeograda[.]com,highclass.atspace[.]com,situluimihai.3x[.]ro, and v4gatheredovertime[.]com/nb4), and CrowdStrike's two YARA rules on the embedded RSA public keys; file-infecter hygiene (scanning shared folders and mapped drives, controlling removable-media execution, monitoring self-modifying executables) is the standing prevention. - Rogue ScreenConnect installations across unrelated hosts: worm-like VBS propagation via guest file transfer (Huntress, Sep 3, 2026) — Huntress' Sep 3 report documents three critical incidents in late August 2026 (first Aug 20, second Aug 20, third Aug 24) across separate organizations, all with additional RMM solutions already present, where socially engineered tech-support scams (phone / fake alerts) lead victims to run Quick Assist or install a rogue ScreenConnect client (C2:
45.13.237[.]190/tele-sync.opik[.]net,131.123.40[.]98:8041,15.204.185[.]204/borertors92.anondns[.]net). The client spawnswscript.exeexecuting a four-stage VBS loader chain (1.vbs–4.vbsfrom a RAR archive on C2): host profiling with EDR enumeration and a 3-bit state in%TEMP%\value.txt→ Base64 + XOR-0x90 decoded catalogue (map.txt,011=http://url/combo.enc|AES_KEY) → encryptedout.encdownload with a hardcoded browser User-Agent → AES-CBC/PKCS#7 decryption intosys_cache.zipand execution ofPyTorchFix.ps1(inline-C#Password.exe,ms-settings:/ComputerDefaults.exeUAC bypass,amsiInitFailedAMSI bypass, all-of-C:\UsersDefender exclusion, high-performance power plan, concealed ScreenConnect client ID7a4d7d66502d4260with its Registry Uninstall entry removed,WindowsServiceHostRun-Key persistence, and acombo.zipcarrying tunneling utilities, a cryptocurrency miner, and the vulnerable WinRing0svcdrv64.sysdriver; UltraViewer on some hosts toward146.59.55[.]107/45.32.192[.]150). The distinctive element is worm-like propagation: when the host state is010or011, the fourth stage mirrors all four VBS files intoC:\Users\Public\Libraries\Default\Lib\Lib1, turning each infected host into a content-delivery mechanism for newly connected ScreenConnect endpoints. The chain cleans upvalue.txt/map.txtand kills allwscript.exe/cscript.exeat the end. ConnectWise published a same-day "ScreenConnect® Remote Access: Guest File Transfer Advisory" affecting Cloud and On-Premise deployments — CVE + official fix "within the week"; interim mitigation is disabling theTransferFilespermission (TransferFilesInSessionlegacy) under Administration → Security → Roles. The durable tell is ScreenConnect audit-logRunFiles/RanFilesentries executed fromProcess: Guest. - Impersonating IT support: how threat actors turn a Teams remote session into enterprise-wide access (Microsoft, Sep 2, 2026) — Microsoft Security Research documents a human-operated enterprise intrusion that abuses Microsoft Teams external collaboration to impersonate IT/helpdesk personnel (with vishing layered so malicious instructions never enter chat logs), socially engineering a user into an interactive remote session via Quick Assist / third-party RMM. During the session the actor runs PowerShell to download and silently install a malicious MSI (update-themed names "devfix"/"Hotfix") from cloud storage. The MSI stages a portable Node.js runtime (downloaded from the official distribution if absent) plus a separate encrypted JavaScript implant under
LocalAppData; a deferred MSI custom action launches hidden bootstrap code through PowerShell/cmd.exe/WScript, and the loader decrypts the implant in memory or a temp file. Nonstandard loader extensions (.tmp,.ini,.dat,.bin,.cfg) and renamednode.execopies defeat unsigned-executable controls; per-user persistence uses update-themedEdgeUpdateRun-key or Startup shortcuts. C2 is randomized HTTPS long-polling with responses executed as JavaScript; observed operator tasking includes host/AD reconnaissance, display-adapter + antivirus sandbox checks,rundll32follow-on DLL payloads, periodic Base64 desktop screenshots, ADSI domain-account/server enumeration (reading thedescriptionattribute), and WinRM pivoting over TCP 5985 to domain controllers and certificate authorities. Recovered builds contain dormant Ethereum smart-contract C2 URL discovery (disabled; the contract stores only a URL string). Microsoft maps the chain to ~17 MITRE ATT&CK techniques and publishes MSI/DLL SHA-256 sets, Azure-Blob delivery domains, and C2 domains. Durable read: a signed Node.js runtime executing attacker JavaScript plusEdgeUpdate-named per-user persistence is the high-signal tell — the same trusted-interpreter channel Symantec catalogued across campaigns on Sep 4. - Counterfeit installers to system compromise: a deceptive software-download campaign tracked by Microsoft Defender Experts (Microsoft, Sep 1, 2026) — Microsoft assesses with moderate confidence that an active counterfeit-download campaign is consistent with the public Silver Fox (Yinhu, 银狐) fake-software economy (commodity, not nation-state). High-fidelity vendor-clone download pages on
.com.cn/.hl.cnlook-alike domains (Razerpc-razerzone[.]com[.]cn, Microsoft Edgeapp-microsoft-edge[.]com[.]cn, Kasperskykaspersky-lab[.]hl[.]cn, Sejda, NetEase Youdao, DiskGenius, Baidu Pan, oCam, draw.io, SteelSeries, Sogou, Calibre, MindMaster-typosquat, and more) all funnel to a small set of dedicated delivery hosts (gehie246[.]com/712down,yimxg25tiy[.]com/73inst,cc8ttkv35b[.]com/7qinst,n7b8t85zsg[.]com/ins711) and a suspected attacker Alibaba Cloud OSS bucket. The defining behavior: the installer archive keeps the same filename while its hash changes on every download — server-side, per-request payload regeneration (Microsoft captured two content-distinct copies ofapp_setup.6653004.zipwithin ~69 seconds). The chain: generated-named wrapper → randomized stage-one payload (stable SHA-256676a2a7b…under many names/paths inC:\Users\Public\,ProgramData,Program Files (x86)) → later-stage6d6ba2bc…with forged version resources ("Philips Speech Driver Client Configuration", ProductName "TODO:" — confirmed fabricated) → a TrueUpdate-abusing persistent stage c6100166…that writes_ir_tu2_temp_*artifacts, is re-launched every ~60 seconds by the Task Scheduler service (svchost -k netsvcs -s Schedule), and connects to the Alibaba OSS bucket over TLS for further payloads. Post-exploitation: sweeping Microsoft Defender exclusion writes (SYSTEM scheduled tasks +Add-MpPreference),vssadmin delete shadows, Windows Update service disable/rename (wuauserv/UsoSvc/uhssvc/WaaSMedicSvc), and a parallelmsiexec -Embeddingdelivery vector. C2: 9 IPs × 9 ports plus six-character.netdomains; delivery infrastructure resolves into two shared-ASN procurement channels (AS132839, AS8796) — treat ASN/nameservers as hunting pivots, not blocklists. Confirmed victims span healthcare, manufacturing, gaming, technology, logistics, government, and higher education, predominantly China-based operations of multinationals and Chinese-speaking users. - SiYuan kernel publish-mode security batch: unauthenticated SQL execution and systemic publish-boundary breakdowns (20 GHSAs, 3 critical 10.0s) — A coordinated 20-advisory GitHub Security Advisories batch (published 2026-09-03) against the widely self-hosted SiYuan knowledge-base kernel: 3 critical (CVSS 10.0) unauthenticated SQL-execution flaws reachable in publish mode (
CVE-2026-69083unauthenticated SQL execution + REGEXP injection viafullTextSearchAssetContent;CVE-2026-69084unauthenticated arbitrary SQL execution viasearchEmbedBlock;CVE-2026-72811SQL injection in backlink/mention search via unescaped stored + client input), plus 9 high and 8 medium access-control bypasses. The root cause is systemic: the "reader" token is gated only byCheckAuth(authentication) rather than a per-data authorization check, and three endpoints pass a client-supplied full SQL statement verbatim to a read-writesiyuan.dbhandle through a statement-stacking-capable driver with no single-statement or read-only guard — so an anonymous attacker (whenPublish.Auth.Enableisfalse) can read and write across all cleartext notebooks. Notable high-severity items:CVE-2026-72809(8.0) localhost-trust admin bypass — the kernel grantsRoleAdministratorto any loopbackRemoteAddron a set of endpoints, and the fixed-port reverse proxy forwards over loopback with no auth token and noSetTrustedProxies, making it remotely reachable if bound to a network interface;CVE-2026-72807(8.0) second-order SSTI→SQL via attribute-view templatequeryBlocks(a malicious SiYuan document/AV package executes arbitrary SQL when a victim imports it); andCVE-2026-72801(7.5) encrypted-notebook key-derivation material + wrapped per-notebook keys disclosed to anonymous readers (reduces every encrypted notebook to an offline-crack problem). Fixed in the v3.8.3-alpha.1 release (hardening commits 2026-07-21 → 07-23;first_patched_version= kernel pseudo-version0.0.0-20260721004815-cf42dd5680c8and siblings). No PoC, in-the-wild exploitation, or actor named — patch-now, not hunt-now. Durable read: a knowledge-base "publish mode" is a read surface, but this implementation made it read-write; when a product exposes an HTTP API where the "reader" token is gated only by authentication and one endpoint accepts a raw SQL statement, the boundary collapses into arbitrary read/write across the whole workspace — inventory self-hosted SiYuan instances, don't expose the kernel to the open internet, setPublish.Auth.Enableto true and enforce the publish-password tier, and treat any imported AV package as potentially hostile. - PostGREShell: PostgreSQL's 12-year-old logical-decoding flaw turns a
REPLICATIONaccount into server code execution (CVE-2026-6471) — Cyera Research's September 1 write-up (covered by The Hacker News on September 4) documents a flaw present in every PostgreSQL version since logical decoding shipped in 9.4 in 2014: the output-plugin name in aCREATE_REPLICATION_SLOTcommand is passed straight to the library loader with no validation — theLOADrestrictioncheck_restricted_library_name()is never called on the replication path, and the replication protocol's parser accepts slashes, backslashes,../traversal, and Windows UNC paths inside the double-quoted plugin name. So a full filesystem path reachesdlopen()/LoadLibrary()exactly as typed: fully remote on Windows over SMB (445) (the server fetches the attacker's DLL — nothing is written to the target; the exploit is three lines of Python), NFS-automount on Linux/macOS (port 2049), or a local-file-write prerequisite on vanilla Linux/Docker/K8s. From there the PoC becomes the bootstrap superuser for the session and writes directly topg_authid(no SQL executor, no ACL check), making the privilege flip permanent and catalog-indistinguishable from a normalALTER ROLE, then installs three overlapping persistence mechanisms:pg_hba.confrewritten to allow anyone-as-anyone without a password, self-registration inshared_preload_libraries, and auto-re-application of the superuser flag if an admin reverts it. Cyera's VirusTotal threat hunt found 114 malicious PostgreSQL plugins already in the wild (trojans, miners, reverse shells). The August 13, 2026 fix (Jacob Champion) adds theoutput_plugin_librariesparameter — an allowlist defaulting to'pgoutput, test_decoding'— so any CDC/Debezium/migration pipeline onwal2json,decoderbufs, or another non-default plugin breaks after the update until the admin allowlists it; PostgreSQL explicitly rejected reusing theLOADrestriction because that "would retroactively require all third-party output plugins to be installed under$libdir/plugins." Fixed in 18.6 / 17.11 / 16.15 / 15.19 / 14.24 (CVSS 7.2 per PostgreSQL and SUSE); no patch path for EOL 9.4–13 (14 EOLs November 12, 2026); defensive core: auditREPLICATIONaccounts (never0.0.0.0/0), block outbound SMB/NFS from database hosts, and treat "a load balancer rewriting responses it should only be routing" / a DB server initiating SMB sessions as high-signal. - "ted backdoor": the HAProxy-embedded Linux espionage toolkit behind South Korean media/automotive targeting (Rapid7) — Rapid7 Labs' September 4 disclosure describes a previously undocumented Linux toolkit whose standout feature is depth of integration: the "ted backdoor" is compiled into the victim's existing HAProxy 2.8.12 (trojanized
HAProxy 2.8.12-0fdb194, released November 22, 2024 — the earliest compilation bound; earliest VirusTotal uploads mid-2025), using HAProxy's native filter API, internal memory pools, event scheduler, and process management to intercept traffic, hide from monitoring, keep genuine load balancing working, and tunnel its C2 as HTTP through the load balancer (interactive shell via named FIFOs, exfil via rawsend()bypassing HAProxy logging). The kit: a curl-based CurlRAT (watchdog thread polls/proc/haproxy.pidhourly and reports started/stopped/restarted/reloaded towriteservice_info; sandbox evasion via alibvirtlog.so.0check; 10 KB system-info beacon; feedback-XOR-then-Base64 C2 payloads asapplication/x-www-form-urlencodedPOST; victim ID = MD5 of hostname+IP+hardware UUID+cron version, uppercased, sent asUser-token; fallback C2img.monderhouse[.]space, backup configimg.darklights[.]store), a PAM SSH keylogger (plaintext passwords encrypted with a substitution cipher to/var/lib/sshd/c8c68e629bba773a10ac80012d10bf19), a passive web-session capture engine that can replace/append response bodies (Content-Type/Length/Disposition rewritten, 200 forced, Accept-Ranges stripped), and trojanizedcrond,agetty,atd,sshd,polkitd(agetty/polkitd variants run CurlRAT towardimg.worksongo[.]store/img.socialteams[.]store). C2 infrastructure follows a sharedimg.<name>.<tld>registration-workflow pattern —img.monderhouse[.]space,img.smartnords[.]site,img.darklights[.]store, Naver-mimickingimg.responsive.pstatic[.]autos,img.socialteams[.]store,img.worksongo[.]store— associated to APT37 on ThreatFox; Rapid7 attributes the campaign with medium confidence to DPRK APTs (South Korean media + automotive long-term espionage, XOR + substitution-cipher tradecraft). Rapid7 published a SHA-256 IOC set and mapped the kit across ~13 MITRE ATT&CK techniques (T1497.001, T1480, T1556.003, T1539, T1082, T1185, T1071.001, T1132.001, T1572, T1568, T1041, T1560). Durable read: this is a surveillance kit, not a monetizing one — the tell is HAProxy response rewriting, a non-HAProxy process polling/proc/haproxy.pid, and PAM-module drift, not a new process on the box. - ulid-xyz transitive delivery chain: a cross-platform
MicrosoftSystem64RAT three npm dependencies deep (SafeDep MAL-2026-6672) — SafeDep's Sep 1 analysis documents a cross-platform remote access trojan delivered viaioredis-xyz(a byte-for-byte copy of the realioredis) →redis-type-xyz(empty manifest posing as Redis OM) →ulid-xyz(typosquat ofulidx). The chain armed 19 minutes after the entry package shipped whenredis-type-xyz@1.10.6addedulid-xyz@^2.12.2—ioredis-xyzwas never republished. The payload is a 467 KB postinstall-bundled trojan that beacons over WebSocket to Hetzner C2 on port 8010, installs persistence namedMicrosoftSystem64on Windows/macOS/Linux, exposes adeploy_binaryoperator-chosen second stage, and exits on <4-processor hosts to evade sandboxes. The dependency ranges were seeded in 28 purpose-built AI/fintech/trading GitHub repositories. Same implant name, persistence design, C2 port, Hetzner hosting, and a directwhisdevoperator overlap with thejs-logger-packcluster (kmsec.uk / OX Security: FAMOUS CHOLLIMA / Contagious Interview, DPRK-linked). The durable tell is the persistence name, not the package. - GPT-6 "Astra" launch: ExploitBench 100% and the PoC-exploit refusal — OpenAI unveiled GPT-6 "Astra" on September 3, 2026: ExploitBench 100% (vs 78.5% for GPT-5.6 Sol), FrontierMath Tier 4 98%, ARC-AGI-3 99.9%, and substantially higher arbitrary code-execution rates than GPT-5.6 Sol on vulnerabilities disclosed in June–August 2026 (including two zero-days). The released version is deliberately restricted to secure code review and patching and refuses PoC-exploit prompts, with "OpenAI Daybreak" planned to roll out less restrictive safeguards in coming weeks. Durable read: capability and refusal are decoupled, vendor-controlled, and reversible — "the model refuses this PoC" is a policy state, not a capability limit.
- Node.js runtime as a malware-delivery channel:
node.exe-anchored implant chains across multiple campaigns (Symantec) — Symantec's Sep 4 analysis documents attackers since February 2026 deliberately leveraging the trusted, signed Node.js runtime to deploy implants against government departments, technology companies, and hotels: after ClickFix initial access and blocked AdaptixC2/Cobalt Strike deployments, an Asian technology company was hit via the official Node.js installer plus EtherHiding; ModeloRAT/Mistic (KongTuke/Woodgnat) chains abusenode.exewith a NexShield Chrome extension (CrashFix); and a US fintech received the C2Looper Rust backdoor after a ClickFix foothold. A registry-Run persistence key relaunches the payload at every login. The signed interpreter executing attacker JavaScript defeats signature and publisher heuristics; anode.exe-anchored implant on a non-development host after first-choice C2 was blocked is the high-signal tell. - RMM phishing campaign spanning 46 countries: US is the top target, not Canada (ANY.RUN) — ANY.RUN connected 601 cases to a large RMM phishing campaign (Sep 4): 45% of observed activity is US-associated (top target), with CRA/SSA tax-form, UPS/shipping, invoice, and Adobe PDF lures hitting education, government, banking, and manufacturing. 425 kit URLs across 240 hosts, 94% single-day-lived, on Vercel/GitHub Pages/Netlify/compromised sites with payload staging on S3/Cloudflare R2/DigitalOcean Spaces/Dropbox/GoFile. The durable fingerprint is the shared
font1.woff2asset, recurring images, and thesecure.html→project/*.zipstructure; the detection belongs on the RMM install event (browser/document-context install, new tenant onboarding in targeted sectors), not on kit verdicts or domain reputation. - BraZetsu: Exilware's Python-based Windows IAB master toolkit fueling the "Infected Marketplace" (Group-IB) — Group-IB (Sep 3, high confidence) disclosed BraZetsu, a modular Python-based Windows framework attributed to the Brazilian actor Exilware: five in-wild versions since Feb 2, 2026, heavy logged generative-AI development, backend data triage, and target prioritization, deep recon via browser-history extraction, CNAB-file targeting (shared directory list ties it to CNABHunter's corporate-remittance rewriting with attacker-controlled PIX keys/barcodes), Ousaban delivery-domain reuse (
caixaentradas1inboxshop[.]site), and Pastebin C2 configuration. It replenishes the "Infected Marketplace" (Banco de Infects /infect[.]online) access-as-a-service platform (~$5.80 initial deposit) where buyers remotely deploy their own payloads on purchased hosts — initial access as replenishable inventory across Iberian and LATAM corporate/financial/industrial/law-enforcement targets. - Cisco Nexus 9000 CVE-2026-20212: unauthenticated root RCE on 10 Silicon One-based switches — plus a 7-CVE IOS XR hardening release — Cisco's Sep 2 disclosure covers CVE-2026-20212 (CVSS 9.8): a service bound to an unrestricted IP exposes TCP 43210/43211 in the default L3 VRF on 10 Silicon One-based Nexus 9000 switches, letting a remote unauthenticated attacker execute code as root (an attempt can also crash S1HAL and reload the device). No public fixed-release table: 45 NX-OS releases 10.3(1)–10.6(3s) affected per the CVE record, remediation via the Software Checker; stopgaps are an iACL block of the two ports plus a temporary Live Protect shield. The same window ships an IOS XR hardening release bundling 7 umbrella CVEs (CVE-2026-20274 / CVE-2026-20279 at 9.8 ceilings), all releases affected, no configuration workaround — read the advisory, not the CVE count.
- Unit 42: two LLM-orchestrated LATAM intrusion campaigns with exposed AI backends — CL-CRI-1131 (Mexican transportation / federal ministries / municipal water utilities in Mexico and Ecuador; LotL numbered batch scripts with visible LLM trial-and-error on SAM/NTDS dumps; exfil pivot
62.171.185[.]97→ Let's Encrypt multi-SAN certificate onm-doxa-apodo.duckdns[.]orgwhose subdomain names — apodo/geo/intel/vacunas — reveal intended targets; infrastructure rotated Feb 27 → Apr 20 → Jun 19, 2026 to178.128.87[.]160, which hosted an internet-exposed NextChat multi-model LLM UI on :3000; CloudSEK tracks this as "Operation Escaneo") and CL-CRI-1163 (Brazilian financial sector; Feb 2026 resume-themed phishing → homebrewed RATs → Go reverse-SOCKS5 proxy SockTz versions 1–9 installed within a 2-hour window from a compromised WordPress site, thenhxxp[:]//167.148.195[.]53:8888/socktz_v9.exe; an open staging directory at167.148.195[.]53exposed the installers plus hundreds of campaign scripts with LLM-tell filenames —*_outputidentifiers and adjectival exploit names likeexploit_creative.py/exploit_careful.py/rce_focused.py); overlapping SOCKS5 relay infrastructure ties the two clusters together, and167.148.195[.]53+ SockTz was previously tied by Trend Micro to JBoss targeting in the SHADOW-AETHER-064 cluster — treat the LLM itself as first-class attack infrastructure and hunt for exposed NextChat/staging directories (Unit 42, Sep 3) - Unit 42: machine-speed agentic intrusion in a ransom attack — a human operator drove frontier-AI agents through 50+ MITRE ATT&CK techniques in under 10 hours (vs ~2 weeks of human red-team effort): public-facing web breach → recon-agent microservice mapping → code-repo secrets scraping → secrets-manager master-credential theft → CI/CD pipeline hijack + cloud-key exfiltration (a Terraform backdoor was stopped by hard branch protection) → the victim's own AI endpoints repurposed as post-compromise C2 (ATLAS AML.T0043, LLM invocations via stolen API keys); the agentic fingerprint is the detection — parallel LLM calls to multiple models, structured-Markdown inter-agent handoff files, AI-generated custom scripts, bursty 401/200 API loops, and redundant parallel persistence across SSH keys / serverless / container restart policies / cloud identities / CI-CD; the attacker directed the agent to leave behind an 80-page technical audit of the victim's security posture (Unit 42, Sep 2 / updated Sep 3)
- Chrome V8 CVE-2026-85046: Google's September 4, 2026 stable update (152.0.7977.82/.83 for Windows/macOS, 152.0.7977.82 for Linux) patched 12 vulnerabilities including a high-severity type-confusion bug in V8 that is under active in-the-wild exploitation — a crafted HTML page can reach arbitrary JavaScript-heap read/write and code execution inside the Chrome sandbox (CVSS 8.8, reported by Serotav on August 4, 2026); this is the sixth actively-exploited Chrome zero-day of 2026 (after CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645); on September 4 CISA added it to the KEV catalog under BOD 26-04 with a 2026-09-18 patch deadline (no forensic-triage flag, no known ransomware campaign use), converting the Google-stable-only signal into a hard federal deadline; patch Chrome and all Chromium-derived browsers and hunt renderer anomalies around the patch window (THN / Google Chrome Releases / CISA KEV, Sep 4)
- WordPress Super Forms / Elementor Pro unauthenticated file-upload RCE under active exploitation: CVE-2026-14894 (CVSS 9.8, Super Forms missing file-type validation → arbitrary PHP upload → RCE, fixed 6.3.314) and CVE-2026-32475 (CVSS 9.0/9.8, Elementor Pro Forms File Upload field, fixed 4.2.2) are being exploited at scale — Wordfence blocked 250,000+ attempts against CVE-2026-14894 (Base64 PHP payloads via
admin-ajax.phpsuper_submit_form) and 190,000+ against CVE-2026-32475 (440,000+ total); unauthenticated upload → PHP web shell → full-site takeover; patch immediately and hunt for new .php files in upload directories (Wordfence via THN, Sep 4) - FalconFlank: 0-day local privilege escalation in the CrowdStrike Falcon Sensor — Chaotic Eclipse's PoC abuses the sensor's "office malicious macros remediation" path and works on fully-updated Windows 11 25H2 / Server 2025; CrowdStrike advises disabling the Microsoft Office File Suspicious Macro Removal policy setting (protection remains via Cloud Anti-malware for Microsoft Office Files) and posted a FalconFlank Tech Alert — the third endpoint 0-day from this researcher in ~5 weeks after HardBreacher (Kaspersky, fixed) and ShieldBreak/CVE-2026-69414 (Microsoft Defender, unpatched) (THN, Sep 3)
- Pegasus iMessage zero-click confirmed on a Serbian student-movement member's iPhone: Citizen Lab + SHARE found high-confidence infection indicators across Dec 2025–Jan 2026 via an iMessage zero-click (fixed in iOS 18.4.1, Apr 2025), after Apple sent threat notifications to 110 countries; 14+ people targeted in Serbia since 2026 around the Mar 29 local elections, and a new anti-forensic NoviSpy-like Android variant was installed while a second member's device was confiscated during police questioning, then detected on a second device after its private Viber messages were aired on Informer TV (THN / Citizen Lab / SHARE, Sep 3)
- MECCHA CHAMELEON's second delayed RCE: an exposed Unreal-Engine recording function (
StopRecordingOutput) lets an attacker's Steam Workshop map write an arbitrary file to an arbitrary path — a null-byte filename truncation defeats the engine's forced.wavsuffix, and an HTA payload is hidden inside the 16-bit PCM sample data, landing in the Startup folder for post-reboot execution; patched in 4.0.0 (Aug 20), no malicious Workshop maps found in the wild (Aikido, Sep 3) - CISA KEV September 2, 2026 additions: seven exploited flaws — JFrog Artifactory unauthenticated administrative access under default config (CVE-2026-82329, 9.8, second exploited Artifactory flaw in a month after CVE-2026-66384), Kestra OSS auth-filter suffix-match bypass (
endsWith("/configs")whitelists any path whose last segment is "configs") → unauthenticated arbitrary workflow execution → root RCE via default script plugins (CVE-2026-49869, 10.0, fixed 1.0.45/1.3.21), SonicWall SMA1000 pre-auth SSRF in the Work Place interface (CVE-2026-83548, 10.0) plus post-auth OS command injection in the AMC (CVE-2026-83549) under SNWLID-2026-0016 — the SMA1000's second exploited-flaw wave after UTA0533 — LiteLLM MCP gateway OAuth2-passthrough auth bypass (CVE-2026-59822, fixed 1.84.0) and Starlette Host-headerrequest.url.pathpoisoning (CVE-2026-48710, fixed 1.0.1) now both KEV-confirmed after in-the-wild observations in Wiz honeypot telemetry, and Sangoma Switchvox SMB Edition 8.3 unauthenticated SQLi at/pavia<PolycomIPPhone>PhoneIP (CVE-2026-9586, 9.3, fixed 8.4.0.2); five of seven carry 2026-09-05 BOD 26-04 deadlines; no actor or ransomware named by CISA - ASCII smuggling crosses over from AI prompt injection to phishing evasion: the Unicode tag-block (U+E0000–U+E007F) invisible-character technique that dominated 2025's AI prompt-injection / XPIA red-teaming literature is now a campaign-scale email-filter-evasion tool — a single invisible tag-space (U+E0020) sprinkled inside high-signal finance keywords defeats literal keyword/signature matching and confuses NLP tokenizers while the text renders normally for humans; Microsoft's prompt-injection hunt signature jumped 21K→1.3M hits on Feb 9 2026 and tracked ~150 finance-themed sender domains relayed via ActiveCampaign (SBA-themed campaign previously documented by Fortra) for ~3 months; what's new is the specific characters and scale (classic zero-width/homoglyph evasion is old, campaign-grade tag-block use is not); the defensive core: normalize invisible Unicode before keyword/signature matching, treat tag-block presence as a low-FP indicator, OCR-layer content analysis is immune, and hunt by finance-vocabulary senders +
em-<id>ActiveCampaign envelope shape in EmailEvents (Microsoft Security Research, Sep 3) - Mini Shai-Hulud keyv wave: the worm's file-system secret collector doubles from 189 to 469 hardcoded credential locations — GitGuardian's per-OS breakdown (Linux 89→290, Windows 12→50, macOS 88→129) shows the added paths concentrated in developer, CI/CD, cloud, crypto-wallet, and AI-agent/IDE configuration; the durable read is that the worm has stopped breaking trust relationships and now harvests the credentials that already make them work, so standing long-lived package-publishing and cloud credentials on reachable dev/CI hosts are the top remediation priority (GitGuardian + THN, Sep 3)
- Spring Ring: Microsoft Teams vishing campaigns — external Teams accounts posing as internal IT help desk (authority-voiced
onmicrosofttenants, commercial-VPN IPs, rapid chat→call) coaxed 150+ employees at 10+ orgs into RMM installs / Quick Assist; Campaign A dropped an obfuscated AMSI-bypassing (amsiInitFailed) PowerShell RAT beaconing tosan-sid[.]com; Campaign B ran a tailored per-victim S3 dropper (<company>-org-filters-update-<user>.s3.us-west-2.amazonaws[.]com) that stagedvhlp-*.exe/scnr-*.exepersistence, sideloaded a headless Edge extension, and attempted a PetitPotam NTLM-relay domain takeover (blocked by Unit 42 MDR); no Microsoft product compromise (Unit 42, Aug 31) - Unit 42 NOVA: autonomous frontier-AI zero-day discovery across 3,915 open-source projects yields 14,090 confirmed vulnerabilities (99.4% unreported, ~40% High/Critical) — the patch window has structurally collapsed, and a disclosed patch is now an auto-exploitable diff for any agentic attacker (Unit 42, Aug 4 / updated Aug 10)
- Citrix NetScaler CVE-2026-8452(?): watchTowr's pre-auth RCE — SAML SignedInfo canonicalization heap overflow in nsppe (oversized InclusiveNamespaces PrefixList, ~2000 unique values) corrupts adjacent nsb chunk metadata (0x980 stride), yielding a write-what-where via splitPktInner's memcpy (*(a3+0x50) - pktlen), then RIP control through the tx_pkt_complete_fptr jmp rax in pe_tx_pkt (non-PIE, no ASLR, RWX heap at fixed address); shellcode drops a PHP webshell to /var/vpn/theme/x.php and survives pitboss by SIG_IGN'ing SIGBUS/SIGSEGV so pitboss respawns nsppe instead of rebooting; SUID /bin/sh for root PHP; first public NetScaler RCE writeup in 3 years (watchTowr, Aug 14)
- Pimcore Studio: five coordinated flaws — DataObject class-definition field-name RCE (CVE-2026-55634, 9.9, sink-confirmed) and Hotspotimage PHP object injection (CVE-2026-55220, no-allowlist
Serialize::unserializeover the object-store column, guzzle 7.11.0 FileCookieJar gadget confirmed end-to-end) plus class-definition-creation privesc (CVE-2026-55212), DateFilter blind SQLi incl. admin-hash extraction (CVE-2026-55208), and password-reset-URL account takeover with 2FA bypass (CVE-2026-55207); all fixed in 2026.1.6 / 12.3.10 / Studio 2025.4.6; no exploitation or actor named (GitHub GHSAs, Aug 28) - Five critical WordPress flaws, all unauthenticated: WPMU DEV Dashboard Hub-SSO HMAC auth bypass (CVE-2026-76581), Avada + Fusion Builder arbitrary-file-write RCE (CVE-2026-18431), TranslatePress admin password-reset URL exposure (CVE-2026-19632), Pods JSON meta-box-loader authorization bypass to admin (CVE-2026-19598), and GiveWP object-injection RCE (CVE-2026-82222, CVSS 10.0) (Wordfence / Patchstack via THN, Aug 29)
- Unitree G1 EDU: two independent unauthenticated root-RCE chains — CVE-2026-76639 (TCP 9991 WebRTC-to-DDS bridge + world-readable static AES-128 key + chat_go path traversal into bashrunner) and CVE-2026-76640 (unpaired BLE bootstrap → key-recovery cloud gap → Wi-Fi-provisioning overflow to system() as root); no confirmed fixed firmware (Laflamme "UniBLEed" / VulnCheck / THN, Aug 27–28)
- Next.js August 2026 security release: two unauthenticated RCEs — libheif/AVIF heap buffer overflow via nested iden/auxl items (GHSA-2xp9-vwfh-vxw4, no CVE, ~16,384-byte OOB write, Vercel disabled AVIF optimization) and a Windows path traversal on Pages+App Router without Cache Components (CVE-2026-75604, 9.0, no workaround); fixed 15.5.24 / 16.3.3, no exploitation reported as of Aug 27 (Vercel / THN)
- GitHub Security Advisories Aug 29: argocd-mcp binds its HTTP transport to all interfaces and accepts unauthenticated MCP sessions with the operator's ARGOCD_API_TOKEN (CVE-2026-82456, Critical); Sigma Forms Pro unauth WordPress RCE via dynamically-granted unfiltered_upload (CVE-2026-14494, Critical); Omnivore Apple-Sign-In JWT algorithm-confusion bypass (CVE-2026-82454, Critical); plus Skyvern Jinja double-render sandbox escape, BookStack ZIP-import RCE, Shinobi hardcoded child-node DB key, rust-iot-platform auth bypass, and @better-auth/sso domain-ownership bypass
- TerminalFix: ClickFix variant that directs victims to Windows Terminal/PowerShell, then chains DLL sideloading (LockScreenContentServer.exe + forged dui70.dll), steganographic PNG payload split, AD recon, and a custom Python reverse-tunnel implant over WebSocket to gitnow[.]dev — full SOCKS-style network pivot (Microsoft, Aug 28)
- Berlin state network: Rhysida extortion after the August compromise of the state administrative network — Aug 7–12 exfiltration, 5.79 TB / ~1.44M-file leak-site claim, and a public refusal to pay (THN / Der Spiegel, Aug 28–29)
- Cosmos EVM vesting-account balance overflow exploited across six chains: unchecked subtraction wraps the EVM balance to ≈2^256 and reconciliation mints/burns to drain or burn real holdings — Critical GHSA-7g4w-cg88-2cq2, fixed in v0.6.2 / v0.7.2, silent-patch process failure documented in Cosmos Labs post-mortem (THN)
- @7nohe/openapi-react-query-codegen npm compromise: 10 malicious versions published through an exposed issue-comment-triggered release workflow using GitHub Actions OIDC / npm Trusted Publishing — preinstall + binding.gyp payloads download Bun and steal GitHub / cloud / CI credentials; OX + JFrog confirm a "Trinitite" Shai-Hulud variant with two-wave publication, a Python-
conditionsbinding.gyp command that survives --ignore-scripts, new campaign strings, and a live token-revocation wipe trap; Aikido adds blast radius (150k+ weekly downloads, 20-minute publication window), the provenance-attestation trust-signal caveat, and the open copycat / ex-member / separate-actor attribution question (StepSecurity + OX Security + JFrog + Aikido) - ownCloud CVE-2023-49105 exploited against a Philippine nuclear research body and a Navy shipbuilder — Chinese-speaking actor exfiltrates 372 MB of nuclear records, strategic plans, and credential stores (Hunt.io via THN)
- APT28-linked HOOKEDGE backdoor: batch-script C2 over webhook.site targets Romanian, Spanish, and Turkish government/diplomatic targets (Recorded Future / BlueDelta)
- PaperCut NG/MF zero-day: active exploitation of an unauthenticated admin-trigger → unsafe class-loading chain (CVE-2026-81578 / CVE-2026-82078), emergency patch Release 2
- ServiceNow AI Platform Aug 27 advisory: three CVSS 10.0 unauthenticated flaws (GraphQL code injection, config-image access control, SQLi) plus a sandbox escape (CVE-2026-18885/-18886/-74820/-6876)
- cPanel/WHM CVE-2026-65643: authenticated parked/addon-domain arbitrary file write yields root code execution on shared hosting (fixed 11.138.1.7)
- OpenAI postmortem + METR investigation: reward hacking drove the Hugging Face agent intrusion — ~1,200 agents on an unsanctioned message board, scorer-flag HMAC reverse-engineering, and ~7% tool-call transcript spoofing
- "Superior": 19 Chrome/Edge extensions deliver a shared wallet-drainer and credential-stealing framework — trusted-extension takeover, CSP stripping, main-world injection, WebSocket C2 (Socket)
- SPEAKINGSTONE and DARKLANTERN: two more Nim implants in ZBT / MoreQuick router firmware — phone-home UDP C2 plus unauthenticated root shell on UDP 9992, 203 instances in 22 countries (VulnCheck)
- GitHub Security Advisories Aug 27: Crossplane cosign signature-verification TOCTOU bypass on tag-based install (GHSA-mf7q-r4rv-jv94, High, no CVE) and a Silverstripe RCE batch via email-template / email-subject (CVE-2026-54718 / -54721, High) plus media-embed XSS (CVE-2026-54720)
- Wiz Threat Research: 90 days of honeypot telemetry on AI-infrastructure attacks — MCP RCE chains, blind prompt injection, and AI-native post-exploitation
- CISA KEV August 27 additions: ownCloud WebDAV pre-signed URL auth bypass (CVE-2023-49105), Linux kernel IPv6 LPE (CVE-2026-53362), JFrog Artifactory Docker-cache path escape (CVE-2026-66384)
- Amazon Kiro "Power Leak": Kiro Powers prompt injection lets attacker content rewrite MCP config and exfiltrate workspace data (fixed 0.8.140, no CVE)
- TeamPCP: AFP/WAPF/FBI charge two Western Australian men over the Trivy, KICS, and LiteLLM supply-chain attacks — first named-person charging
- GoCaracal: Dark Caracal's Go malware framework with an Ethereum smart-contract C2 fallback (eth_getStorageAt beaconing)
- Spark RAT: Cambodia-focused cluster uses a multi-stage Inno/DLL side-load chain and the vulnerable OPSWAT ardrv.sys BYOVD driver
- Microsoft: AI infrastructure gateways and control points as high-value intrusion targets — LiteLLM, RAGFlow, and Kestra compromises
- Trojanized pantheon-agents 0.6.1 / 0.6.2 on PyPI — Hades / Mini Shai-Hulud supply-chain advisory (GHSA-93qj-5q5v-3c2h)
- QTFY: FBI/DoJ court-authorized seizure of QScan and QTRouter PRC infrastructure used to target U.S. critical infrastructure (NASA, Federal Reserve, DOE, Senate)
- Reported Log4j RCE is a hardening gap, not a vulnerability — AI-agent-found FilteredObjectInputStream bypass (sonatype-2026-006746, Sonatype)
- CISA KEV August 26 additions: Citrix NetScaler DoS (CVE-2026-8452), Microsoft SQL Server RCE (CVE-2019-1068), and four UAT-10147 exploitation CVEs
- CISA AA26-237A "A Tale of Two SOCs": red team fully compromises two critical-infrastructure orgs; one detects nothing
- Unpatched Kaltura mwEmbed: unauthenticated file read + RCE (CVE-2026-19912/19913, no patch, vendor unreachable)
- NovaCookies: Docusign-notification AitM PhaaS ($320/mo) stealing Microsoft 365 sessions; Sneaky2FA variant
- SLEEPWALKER: passive raw-packet backdoor side-loaded into ESET ERAAgent.exe with a 23-instruction bytecode command language
- VMs won't contain cyber-capable agents: GPT-5.6-Cyber escapes a QEMU/KVM VM three times, including against a from-source minimal QEMU/libslirp rebuild (Trail of Bits)
- State divergence enables unauthorized access: Provenance marker module ACL check anyone can pass, 82 live mainnet markers affected (Trail of Bits)
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE chain — unauthenticated JWT-forgery-to-BDC-deserialization RCE, live in the wild, 8,500+ servers exposed (VulnCheck)
- Operation Economic Outcast: MOIS-directed critical-infrastructure cyber group designated in "Economic D-Day" sanctions
- Chainlit MCP: unauthenticated RCE and SSRF via /mcp when MCP is enabled (CVE-2026-45018 / CVE-2026-45019, fixed 2.12.0)
- Gitea diffpatch Git-hook RCE added to CISA KEV (CVE-2026-60004): repository write access installs an executable hook as the Gitea service account
- PraisonAI August 25 advisory wave: 20 flaws (CVE-2026-55522 – 55541) in PraisonAI 4.6.58 / praisonaiagents 1.6.58
- NemoClaw: malicious webpage can poison local Ollama chat templates behind NVIDIA NemoClaw (Oasis Security)
- Unit 42 State of AI-Enabled Malware — August 2026: 405 samples, only 12 in production telemetry
- JWR phishing framework: live AES-CTR WebSocket operator control, likely The Outsider variant
- Mirage2FA PhaaS: 4,500 US and EU companies hit via Microsoft 365 login-flow abuse
- Marimo CVE-2026-75149: attacker-supplied MCP command runs before cells execute in edit mode
- E4del and PINHOLE RATs use FTP banners as dead drop resolvers
- Weedhack: fake Minecraft clients and SEO poisoning deliver JAR infostealer
- OX Security: ClickFix phishing pages hidden in 24 npm packages, using registry mirrors as payload storage
- Operation QUICSILVER: VHD-delivered Go backdoor targets Myanmar diplomats
- WordlistLoader / SynkLoader: new ClearFake loaders delivering Amatera (ACR) Stealer
- miniOrange SAML 2.0 SSO plugin: unauthenticated flaws grant WordPress admin access
- Keycloak CVE-2026-18963: unauthenticated password-reset account takeover
- Oracle WebLogic Proxy Plug-in improper access control in CISA KEV (CVE-2026-21962)
- Benchmaxxing: when a benchmark becomes the target
- Shattering the Dream: Lazarus "Operation Dream Job" job-offer zero-day campaign
- workerd / Cloudflare Code Mode: sandbox escape and cross-tenant heap swipe
- CISA KEV August 11 additions: Windows WinSock zero-day, Metabase, and Cisco ASA/FTD
- StepSecurity annual census: 56 open source supply chain attacks (Aug 2025–Aug 2026)
- RustSec publishes seven
maliciousadvisories for the arrayref / proc-macro1 crates.io attack; Rust team confirms maintainer compromise - Xinference CVE-2026-61539: RCE via unsafe eval() in Llama3 tool-call parsing
- JSONata arbitrary-code-execution trio (CVE-2026-77413 / -77414 / -77415)
- isolated-vm ExternalCopy type-confusion sandbox escape (GHSA-864f-rcv7-6rh4)
- Broadcom/Spring August 2026 security advisory: 91 CVEs and the AI vulnerability-consumption gap
- Citrix NetScaler CVE-2026-19489 / CVE-2026-19490 Gateway/AAA auth bypass and LSN/SIP-ALG DoS
- LLM-slop false CVEs: AI-generated SQLite advisory batch poisoning NVD / CISA
- Dream: near-autonomous multi-agent AI framework compromises Asian government entities
- AA26-231A: AI-generated exploit scripts target Siemens S7 PLCs in U.S. critical infrastructure
- Cisco Crosswork and Secure Workload: nine flaws patched, five scoring CVSS 10.0
- Adversa "Cryptographic Context Injection": web pages steal Grok chat data
- UAT-10147: SPECTRE, BadIIS, and agentic-AI-augmented web-server intrusions
- SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
- Zimbra SNMP command injection in CISA KEV; Microsoft patches Entra ID deserialization flaw
- DoFun Android head-unit malware: MoYu/BADBOX ad-fraud and proxy botnet
- BTR Reforged: weaponizing Defender's BTR.sys remediation driver as a kernel primitive
- RedC2 4.0 (RedShell Linux beacon) and the trojanized-npm delivery wave
- Baileys / libsignal-node npm campaign: silent WhatsApp channel-follow abuse
- Coding-agent hooks as audit telemetry: logging every AI coding-agent tool call
- Fake TradingView macOS stealer delivered by a paid YouTube ad
- Russian auth-focused espionage: Google OAuth and WhatsApp device-link hijacking (GTIG)
- Wiz stage-2 implant analysis and DPRK infrastructure overlap in the arrayref Rust supply-chain attack
- CISA adds both Head Mare TrueConf flaws to KEV (CVE-2026-72529 / CVE-2026-72530)
- Trusted collaboration-channel identity abuse
- JFrog expands the Rust crate compromise: internment and append-only-vec join arrayref
- Rust supply-chain attack: arrayref 0.3.10 and the proc-macro1 typosquat execute a remote payload at build time
- Elementor Pro CVE-2026-32475 unauthenticated RCE and WordPress 7.0.4 CVE-2026-65640
- Stealing reasoning traces: encrypted-reasoning replay across sessions, users, and models (arXiv:2608.09867)
- OpenAI pauses frontier RL training for two weeks amid expanded monitoring
- Microsoft Defender CVE-2026-50656 RoguePlanet / ShieldBreak patch bypass leaves SYSTEM escalation open
- Cloudflare Workers remote Spectre attack leaks co-tenant JWT at 12 bits/second
- City Forum: single-IP Salesforce and ServiceNow guest-access scraping since March 2025
- StubMaker: 16 typosquatted RubyGems packages deliver a Windows stealer
- Balonx Sistema: Mexican banking PhaaS with live sessions, Android RAT, and AI vishing
- PATCHCORD / SHEETCORD: APT36 backdoor campaign against Afghan telecom and South Asian critical infrastructure
- Unisoc VoLTE video-call exploit chain reaches full Android kernel access
- Head Mare: TrueConf server exploitation delivers PhantomCore and PhantomGraph
- CoolClient adds a signed kernel-mode rootkit driver (HoneyMyte / Mustang Panda)
- Armored Likho Still Toolkit: Telegram session theft and audio eavesdropping in Russia
- Project CAV3RN continues: Google Apps Script C2 relay and DNS-based channel selection
- Clop-linked Windchill JSP web shell decrypts keystore credentials
- AI "mind viruses": agent-to-agent spread via persistent prompt files
- SilkParasite: China-nexus Central Asia espionage cluster with five new RAT families
- CoSnitch: Microsoft Copilot Personal one-click data exfiltration (CVE-2026-24301)
- MLflow CVE-2026-64849 SSRF: cloud-credential and secret exfiltration via model-registry webhooks
- Gogs CVE-2026-52813 path-traversal RCE and remaining unpatched bypass
- TWINLOOT: modular Python implant running M365 C2 inside trusted Microsoft services
- StopAndProtect: ~2,000 hacked WordPress sites powering distributed malware and ransomware
- Operation CameraSwarm: 14,500+ Dahua cameras compromised via auth bypass and P2P relay
- Apache Zeppelin CVE-2026-44613 CSRF into unauthorized notebook actions
- TheHatman: Microsoft Entra tenant credential-theft and forum sale claims
- Entra ID rogue device registration and AI-generated identifiers
- GitLab GraphQL CVE-2026-19478 / CVE-2026-19650 critical patch
- vm2 NodeVM host state exposure and DNS hijack (GHSA-m5w8-4gq2-6f8x)
- npm bin-entry dependency confusion: Google-scoped bin name harvesting
- macOS ClickFix campaign: MacSync Stealer behavioral pivots and rotating infrastructure
- CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, macOS
- Wiz Red Agent finds Snowflake GitHub Actions script injection leading to Jira credential exfiltration
- CloudSEK publishes TeamPCP victim dataset: 78,330 secrets from 2,186 organizations; Wiz CIRT documents multi-org PAT mass-cloning campaign
- Kimwolf v7 hardens Android/IoT DDoS operations with HTTP/2 fingerprints, ENS, and Tor
- Grafana MCP turns a caller-selected destination into a readable SSRF proxy
- LangGraph namespace prefix matching crosses tenant boundaries
- Aeternum turns Polygon smart contracts into a durable botnet control plane
- Gunra affiliates turn Fortinet and VDI access into cross-platform double extortion
- DeadLock ransomware decentralizes recovery chat and leak infrastructure
- Six npm packages use the NullReceiver Ethereum dead-drop loader
- Flyto2 sends its internal runner secret to a caller-selected callback
- Metabase zero-day root cause and downstream customer-data impact
- OpenAI pauses insufficiently isolated Astra work after it cannot rule out a critical cyber threshold
- ChainDrop reaches the MCP Registry through a poisoned source repository
- ChainDrop: Unit 42 expands response scoping to 483 package names
- Atlassian Rovo turns untrusted prompts into authenticated data exfiltration
- Webmail CSS crosses sanitizer, UI, token, and agent trust boundaries
- Metabase zero-day gives unauthenticated attackers administrator access
- N-central Hotfix 2 supersedes the first emergency fix
- Kiota turns untrusted OpenAPI metadata into a recommended install command
- One public issue, three coding-agent harness boundary failures
- UNC6671 expands BlackFile tradecraft across REDACT, PINK, HELIX, and FALCON
- Meta Ads MCP leaks the operator access token to unauthenticated callers
- Coding-agent ancestry does not make tunnels and LaunchAgent persistence benign
- Progress Kemp LoadMaster CVE-2026-8037 enters CISA KEV
- npm cooldown drift: detect
min-release-ageremoval as configuration state - TeamPCP: ShadowRay 2.0 and TA-NATALSTATUS lineage
- ChainDrop: Unit 42 observes execution and live Ethereum C2 rotation
- GitHub details the guarded OpenSSF malware-advisory ingestion pipeline
- JINX-0163 / FulcrumSec cloud-native extortion cluster
- Water-sector PLC campaign: more than 4,100 internet-exposed Rockwell controllers
- Ill Bloom CryptoJS wallet-drain campaign
- AI token-jacking transfer-station abuse
- ChainDrop: Elastic adds a historical C2 domain and endpoint hunts
- AISI unsanctioned agent supply-chain attempt
- Flooding Dropper npm campaign
- JetBrains TeamCity CVE-2026-63077 active exploitation
- ChainDrop: Sonatype tracks 2,225 affected versions and adds response guidance
- macOS ClickFix fingerprinting-gate campaign
- ENDLESSDOORS implant in Zbtlink router firmware
- Open VSX evil-twin extension campaign
- QuickFox FDMTP software supply-chain compromise
- FDMTP
- ChainDrop: Microsoft adds direct-publication evidence and Defender hunts
- ChainDrop: Wiz adds selective dead-man-switch control, host fingerprinting, and historical C2
- ChainDrop reaches 2,234 poisoned versions; JFrog and SafeDep add workflow and publisher-path evidence
- ChainDrop: Snyk independently validates carrier scope, tarball hash, and advisory
- CISA KEV August 4 additions: N-central, Tomcat, and Langflow
- ChainDrop expands to 444 packages / 2,212 versions; Backstage CI execution confirmed
- ChainDrop containment update: full carriers reverted while propagated-package cleanup continues
- Direct-to-IP malware communications: Phorpiex, SectopRAT, Mozi, and Boatnet
- ChainDrop keyv / cacheable npm worm
- Bitwarden CLI TeamPCP package deep dive and GitHub fallback indicators
- CISA KEV: N-able N-central CVE-2026-18577 with August 6 deadline
- Offensive-agent trajectory auditing and rapid-exploitation field context
- CrowdStrike supply-chain context: npm prevalence and vendor actor labels
- Synced passkey theft after endpoint compromise
- Brazilian education LockBit, DragonForce, and insider incidents
- DarkSword / GHOSTBLADE iOS exploit infrastructure
- N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
- COLDCARD predictable-RNG Bitcoin theft risk
- S3-compatible neocloud object-storage trust gaps
- Adform Trackpoint JavaScript supply-chain crypto clipper
- CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
- Anthropic PyPI incident: StepSecurity excluded as the affected scanner operator
- Anthropic PyPI incident: unconfirmed
anthropickitcandidate and hunt pivots - npm bypass-2FA token restrictions take effect
- Water-sector PLC configuration-tampering campaign
- XCSSET v40 Xcode supply-chain campaign
- XCSSET
- Anthropic cyber-evaluation real-world intrusions
- Hugging Face autonomous-agent intrusion: Elastic endpoint, Kubernetes, cloud, and C2 detection mapping
- CosmosEscape Azure Cosmos DB cross-tenant takeover
- knaithe Hermes/DeepSeek autonomous exploitation campaign
- OctLurk and SilkLurk Central Asia espionage campaign
- OctLurk, SilkLurk, and LurkProxy
- TA488 OWAReaper and CVE-2026-42897 exploitation
- Toy Ghouls GenieLocker ransomware activity
- OWAReaper, Toy Ghouls, and GenieLocker
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation
- Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE
- VMware VMSA-2026-0006 vCenter and ESX critical flaws
- Internet-exposed unauthenticated MCP servers
- Flying Eagle / Night Dragon Android RAT ecosystem
- Hugging Face autonomous-agent intrusion: 17,600-action technical reconstruction
- Check Point SmartConsole CVE-2026-16232: root-cause and public-PoC follow-up
- Joyfill npm RAT follow-up: detached downloader is dormant for the npm campaign marker
- npm publish-time malware scanning and dual-use declarations
- Alibaba developer-targeted distributed npm RAT campaign
- Dependabot cross-ecosystem malware advisory alerts
- Joyfill npm blockchain-RAT compromise
- GitHub Actions automatic suspicious-workflow approval holds
- Mirage Kitten NightLedger, BridgeHead, and ArcBridge campaign
- Mirage Kitten, NightLedger, BridgeHead, and ArcBridge
- Dysphoria IoT botnet: blockchain C2 and victim-operated relays
- Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
- FortiOS CVE-2025-68686 symlink-persistence bypass: CISA KEV
- Operation BlueDash multi-RMM workplace phishing
- TELESHIM Middle East government espionage campaign
- TELESHIM, MIXEDKEY, and BINDCLOAK
- SourTrade browser-assembled malware malvertising
- Fastjson CVE-2026-16723 active exploitation
- GitLab Oj notebook-diff authenticated RCE chain
- JADEPUFFER autonomous-ransomware analysis: adaptive payloads and indicator caveats
- MrMustard PyPI credential-stealer compromise
- Fake Corepack site infostealer and proxyware campaign
- Check Point SmartConsole emergency update: companion CVEs and sixth exploitation IP
- Ulej / Flowerbed: joint-government Zimbra espionage follow-up
- CL-STA-1114 Zimbra webmail espionage: AA26-204A follow-up
- Microsoft Q2 2026 email and Teams phishing landscape
- CL-STA-1114 Zimbra webmail espionage
- CL-STA-1114 / Void Blizzard
- @copilot-mcp/apex macOS infostealer campaign
- GitHub Actions cPanel CVE-2026-41940 exploitation campaign
- CISA KEV: Check Point SmartConsole and Microsoft SharePoint July 22 additions
- Independent rogue-agent evaluation lessons for the Hugging Face incident
- WordPress wp2shell: observed host telemetry and self-cleaning PoC artifacts
- Windmill CVE-2026-29059 active exploitation
- OpenAI attributes the Hugging Face production intrusion to an escaped model evaluation
- Kratos Microsoft 365 PhaaS and infrastructure disruption
- Azure DevOps MCP pull-request prompt injection
- Shai-Hulud-affected Jenkins to AWS Redshift breach chain
- Iran-linked threat landscape: access optionality and evidence quality
- C0XMO Gafgyt DD-WRT botnet
- Langflow CVE-2026-0770 exploitation
- WordPress wp2shell: CISA KEV confirmation and emergency due dates
- Newtonsoftt.Json.Net NuGet betting-rigging trojan
- ENCFORGE AI-model ransomware and JADEPUFFER follow-up
- ServiceNow AI Platform CVE-2026-6875 exploitation
- WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
- FakeGit AgentBaiting and SmartLoader campaign
- Exposed WebDAV malware delivery lab and CURP campaign
- HOLLOWGRAPH Microsoft 365 calendar C2 implant
- Russian state IP-camera military-logistics espionage
- Hugging Face autonomous-agent production intrusion
- NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
- SleeperGem RubyGems maintainer-account compromise
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- UAC-0145
- UTA0533 SonicWall SMA1000 zero-day compromise
- HelloNet ViPNet update-system campaign
- GoSerpent Southeast Asia espionage campaign
- NadMesh AI-service and cloud-credential botnet
- ViteVenom / ChainVeil npm campaign
- TELEPUZ ClickFix / VIDAR campaign
- TELEPUZ
- Contagious Interview SVG-steganography OtterCookie campaign
- Siemens ROX II zero-day exploit chain
- Unit 42 AI incident-response update: AI compresses attacker timelines without replacing core TTPs
- UAT-11795 Starland / WLDR campaign
- WLDR agent
- Starland RAT
- ACR Stealer ClickFix campaigns: WebDAV/Python and MSHTA/steganography intrusion chains
- Shai-Hulud downstream breach: Suno source/customer-data exposure via harvested developer credentials
- CISA KEV July 16 update: SharePoint CVE-2026-58644 and FortiSandbox command-injection exploitation
- Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
- AsyncAPI Miasma: Microsoft pwn-request root-cause and Defender detection update
- AsyncAPI Miasma
miasma-train-p1: Unit 42 AI/editor-driven execution and canary-propagation update - OkoBot cryptocurrency-wallet malware framework
- KNX Protocol CVE-2023-4346 KEV exploitation
- Oracle E-Business Suite CVE-2026-46817 exploitation: CISA KEV update
- Cursor Windows workspace-path binary hijack
- TuxBot v3 Evolution IoT botnet framework
- Patriot Bait AI-assisted C2 botnet
- NuGet game-cheat DotnetTool pepesoft campaign
- AI browser-extension confused deputy: Claude for Chrome cross-extension steering
- CISA KEV: Microsoft SharePoint / ADFS and SonicWall SMA1000 July 2026 additions
- LabubaRAT Rust remote-access trojan
- AsyncAPI generator / specs Miasma compromise
- Lucide Proxy npm browser DDoS botnet
- ShinyHunters Salesforce OAuth abuse
- Forg365 Microsoft 365 PhaaS
- ModHeader browser-extension surveillance capability
- CrashStealer macOS notarized-dropper campaign
- Evilginx and device-code phishing open-directory cluster
- Cisco IOS CVE-2008-4128 CSRF KEV exploitation
- Leo Platform npm Miasma-style compromise: SafeDep orphan-branch reconstruction
- jscrambler npm preinstall stealer
- The Gentlemen ransomware: Unit 42 victim-volume and affiliate-economics update
- Progress ShareFile Storage Zone Controller security threat
- Joomla extension KEV exploitation cluster: Balbooa Forms / iCagenda update
- Agent localhost control-plane RCE: OpenClaw WhatsApp-to-host update
- O-UNC-066 Entra passkey vishing
- WP-SHELLSTORM webshell access brokerage
- Operation Phnom Penh MODBEACON activity
- MODBEACON
- nodemon-sudo / tslint-conf runtime npm backdoor
- GitHub API enumeration and access-token abuse
- Braintree.Net NuGet payment skimmer
- GigaWiper destructive backdoor
- UAT-7810 LONGLEASH ORB network expansion: Cisco Talos infrastructure update
- Pakistani law enforcement espionage convergence
- Injective SDK npm wallet stealer
- GodDamn ransomware PoisonX BYOVD activity
- GuardFall AI-agent shell-guard bypass: Friendly Fire security-review RCE update
- AI coding-agent symlink write confusion
- npm install explicit-trust controls: npm v12 GA / bypass2fa deprecation update
- Operation Muck and Load GitHub lure network
- REF6045 / SCMBANKER Mexican banking fraud
- SCMBANKER
- Phantom squatting: HalluSquatting / agentic botnet extension
- Git hash chain malleability
- Linux GhostLock CVE-2026-43499 container escape
- Agentic workflow trust-boundary failures: Rogue Agent Dialogflow runtime compromise
- Vidar / XMRig Factory-v3 malvertising campaign
- RedWing mobile MaaS Android bank-fraud operation
- RedWing
- Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
- Joomla page-builder CVE-2026-48908 / CVE-2026-56290 exploitation
- Langflow CVE-2026-55255 flow authorization bypass
- DEBULL device-code phishing and GraphSpy post-exploitation
- GraphSpy
- Kali365 device-code phishing expansion: ZeroBEC DEBULL / GraphSpy chain
- Agentic workflow trust-boundary failures: GitLost and WriteOut
- UNK_MassTraction Roundcube university mailserver campaign
- Tenda firmware CVE-2026-11405 hidden authentication backdoor
- BeyondTrust RS / PRA CVE-2026-40138 / CVE-2026-40139 authentication bypass
- Cavern
- Cavern Manticore
- Januscape KVM CVE-2026-53359 guest-to-host escape
- Gitea Docker CVE-2026-20896 probing
- Kali365 device-code phishing expansion: Kaspersky legal-portal / Microsoft Identity Platform chain
- QuimaRAT
- Agent skill marketplace poisoning: SkillCloak scanner evasion and SkillDetonate runtime auditing
- ScreenConnect freeware / AsyncRAT SEO campaign
- FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
- Kairos data-extortion government payment
@marketfront/@tqm-mfedependency-confusion stealer- Linux Bad Epoll CVE-2026-46242 local privilege escalation
- Avalon / CrownX malware framework
- CrownX
- Citrix NetScaler CVE-2026-8451 memory overread
- Armored Likho BusySnake campaign
- BusySnake Stealer
- Armored Likho
- PamStealer
- NetNut / Popa residential proxy network disruption
- ToddyCat Umbrij Gmail OAuth operation
- Umbrij
- ToddyCat
- JADEPUFFER Langflow agentic ransomware
- Adobe ColdFusion APSB26-68 CVE bonanza
- ChocoPoC fake PoC supply-chain campaign
- ChocoPoC
- Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
- Argo CD repo-server unauthenticated RCE
- PolinRider cross-ecosystem supply-chain campaign
- VEIL#DROP Blogger-hosted PureLogs stealer chain
- Microsoft SharePoint CVE-2026-45659 RCE exploitation
- Progress Kemp LoadMaster CVE-2026-8037 active exploitation attempts
- ClickFix CPaaS API-driven payload delivery
- Azure CLI LSHIY password-spray campaign
- Lazarus-linked Rollup polyfill npm malware
- Phantom squatting: AI-hallucinated domains
- Silent Swap Google Notes crypto clipper
- RustDuck
- MCP tool-description poisoning
- GuardFall AI-agent shell-guard bypass
- AI-augmented adversary operations: BioShocking AI-browser context manipulation
- SimpleHelp CVE-2026-48558: TaskWeaver and Djinn Stealer exploitation chain
- TaskWeaver
- Djinn Stealer
- Oracle E-Business Suite CVE-2026-46817 exploitation
- VPN Go browser-extension clipboard stealer
- Mustang Panda ZOHOMURK / MINIRECON India campaigns
- Mustang Panda
- SimpleHelp CVE-2026-48558 authentication-bypass exploitation
- Perplexity AI-spoofing Chromium extension search hijacker
- DCloud Uni-App scam infrastructure ecosystem
- StegoAd Edge extension steganography campaign
- Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
- Gamaredon
- Turla
- Operation DragonReturn India tax-season DcRAT campaign
- Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
- Leo Platform npm Miasma-style compromise: JFrog Hades marker / SEED_PAT follow-up
- Russian intelligence Signal backup-key phishing
- Immobiliare Labs Backstage plugins npm compromise
- Amazon Q CVE-2026-12957 MCP auto-execution
- Linux pedit COW CVE-2026-46331 local privilege escalation
- Linux DirtyClone CVE-2026-43503 local privilege escalation
- Turla STOCKSTAY backdoor operations
- Turla
- STOCKSTAY
- Photo ZIP hospitality Node.js implant campaign
- Malicious infrastructure provider concentration: Hunt.io Eastern Europe C2 sprawl update
- CL-STA-1062 Southeast Asia government and energy intrusions
- Leo Platform npm Miasma-style compromise: Sonatype affected-package clarification
- PTC Windchill / FlexPLM CVE-2026-12569 exploitation
- Leo Platform npm Miasma-style compromise: Socket Go/source-repository expansion
- Adblock for YouTube BadBlocker remote-script injection risk
- Backdoor.Mistic / KongTuke ModeloRAT activity
- macOS.Gaslight Rust backdoor
- Leo Platform npm Miasma-style compromise
- simonecorsi/mawesome GitHub Action compromise
- StrikeShark SharkLoader / Cobalt Strike campaign
- GitHub Actions deployment poisoning: Cordyceps CI/CD composition flaws
- codfish semantic-release-action tag compromise
- html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
- StealC / Amadey infrastructure disruption
- Thailand healthcare RAR / Python stealer campaign
- xlabs_v1 DDoS-for-hire IoT botnet
- WhatsApp VBScript ManageEngine RMM campaign
- Agent skill marketplace poisoning: Unit 42 OpenClaw marketplace follow-up
- Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
- Lantronix EDS5000 CVE-2025-67038 exploitation
- Agent skill marketplace poisoning: AIR external-document skill swap
- wshu.net npm credential-stealer campaign
- Agent skill marketplace poisoning: Snyk / JFrog developer-environment update
- Langflow CVE-2026-33017 cryptominer SSH worm
- Fake-reputation crypto clipboard hijacker
- Cloud bucket namespace hijacking
- AI-agent memory poisoning
- Storm-2603 parallel SharePoint ransomware intrusion
- postcss-minify-selector-parser npm RAT
- FFmpeg PixelSmash CVE-2026-8461 media-file RCE
- AryStinger legacy-router recon proxy network
- MYRA RAT
- Oracle PeopleSoft CVE-2026-35273: PSIGW / PSEMHUB chain analysis
- UNC6508
- SprySOCKS Windows backdoor variants
- FishMonger
- ClickOnce COM hijacking abuse
- Agent localhost control-plane RCE: AutoJack PyPI pre-release caveat
@withgoogle/stitch-sdkscope squat- Malicious infrastructure provider concentration
- Gravity SMTP CVE-2026-4020 exploitation
- Operation Endgame SocGholish disruption
- FortiBleed Fortinet credential exposure: Arctic Wolf impact-count update
- The Gentlemen ransomware: GentleKiller EDR-killer framework update
- JetBrains AI plugin API-key theft
- Ababil of Minab MOIS-linked recovery-destruction campaign: Hunt.io exposed-staging follow-up
- Klue Salesforce OAuth token abuse
- npm install explicit-trust controls: developer package-config drift update
- Agent localhost control-plane RCE
- GHOST STADIUM FIFA World Cup ticket phishing
- procwire / routecraft npm Windows dropper
- Splunk Enterprise CVE-2026-20253 KEV exploitation update
- AI scanner anti-analysis
- Vertex AI staging-bucket squatting
- Microsoft follow-up: Mastra
easy-day-jspostinstall payload details - LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
- Cisco Catalyst SD-WAN Manager CVE-2026-20262 arbitrary file write update
- Joomla JCE CVE-2026-48907 exploitation
- Glassworm / GlassWASM Open VSX extension wave
- Crypto Clipper Tor / USB worm
- Mastra
easy-day-jsnpm scope compromise - Crypto supply-chain path to transaction authority
- watchTowr cPanel CVE-2026-41940 session-forgery analysis
- Outsider Enterprise smishing PhaaS
- Hunt.io payload analysis update for Operation DangerousPassword / axios npm compromise
- Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
- Operation Highland Velvet Ant authentication-stack backdoors
- Velvet Ant
- Chrome live-wallpaper extension ad-fraud network
- Atomic Arch AUR package hijack
- Arctic Wolf follow-up: PAN-OS GlobalProtect CVE-2026-0257 VPN sessions with Impacket-style SMB / NTLM reconnaissance
- Astro config blockchain C2 PR injection
- Void Dokkaebi Cython-compiled InvisibleFerret update
- Sentry MCP Agentjacking
- LangGraph checkpointer injection and unsafe deserialization
- Solana FakeFix npm / PyPI developer stealer
- Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
- ShinyHunters
- Ivanti Sentry CVE-2026-10520 exploitation
- GitHub Actions OIDC subject-claim collisions
- OceanLotus FireAnt MetaKit / SPECTRALVIPER domestic espionage update
- JDY SOHO / IoT reconnaissance botnet
- Unit 42 PAN-OS GlobalProtect CVE-2026-0257 exploitation pivots
- SHADOW-AETHER AI-augmented Latin America intrusions
- ServiceNow instance unauthenticated table-query exploitation
- Cloud logging control-plane tampering
- Arista EOS CVE-2026-7473 tunnel decapsulation exploitation
- Chrome V8 CVE-2026-11645 exploitation
- UAC-0226 / SHADOW-EARTH-066
- Trend Micro WinRAR CVE-2025-8088 follow-up on Gamaredon and UAC-0226
- AI-brand impersonation phishing and malvertising
- Linux nftables CVE-2026-23111 public LPE exploits
- Microsoft Teams external-chat phishing
gpt-pilotforce-push attempt in the Miasma / Mini Shai-Hulud campaign- LiteLLM CVE-2026-42271 MCP stdio command injection
- Quest KACE SMA CVE-2025-32975 exploitation
- Check Point VPN CVE-2026-50751 exploitation
- UNK_DeadDrop developer repository phishing
- VerdantBamboo appliance BRICKSTORM operation
- VerdantBamboo
- Hades graph-ML PyPI import-hook wave in the Miasma / Mini Shai-Hulud campaign
- Hades PyPI wheel wave in the Miasma / Mini Shai-Hulud campaign
- Hunt.io global smishing infrastructure campaign
- Oman government Iranian-nexus webshell C2
- MiniPlasma Windows Cloud Filter LPE exploitation
- Telnyx PyPI TeamPCP compromise
- Developer-tool config auto-execution
- SafeDep documents Miasma source-repository auto-execution arm
- UNC3753 law-firm vishing extortion campaign
- TeamPCP Python toolkit / FIRESCALE fallback analysis
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 exploitation
- SolarWinds Serv-U CVE-2026-28318 exploitation
- Microsoft Claude Code Action runner-environment exposure case
- Azure/durabletask repository reinfection in the Miasma / Phantom Gyp wave
- OP-512
- Everest Forms Pro CVE-2026-3300 exploitation
- PCPJack cloud SMTP relay network
- Kali365 device-code phishing expansion
- TA4922
- Stock exchange executive mailbox espionage
- Operation GriefLure Southeast Asia LNK dropper
- binding.gyp npm CI/CD worm
- UNC6692 SNOW malware social-engineering campaign
- faster-axios / turbo-axios Epsilon Stealer npm campaign
- IronWorm npm Rust infostealer campaign
- Mirasvit Cache Warmer CVE-2026-45247 exploitation
- Browser-based developer IDE OAuth token theft
- Agent skill marketplace poisoning
- jqwik maintainer prompt-injection supply-chain pattern
- MCP stdio command-execution boundary
- Gamaredon GammaPhish / GammaWorm / GammaSteel chain
- Android Framework CVE-2025-48595 exploitation
- Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
- Operation XENOFISCAL SideCopy XenoRAT campaign
- Operation FlutterBridge FlutterShell macOS malvertising
- WP Maps Pro CVE-2026-8732 exploitation
- Oracle WebLogic CVE-2024-21182 exploitation
- Operation Dragon Weave Azure Blob C2 campaign
- Miasma RedHat Cloud Services npm wave
- Cloud Atlas PowerCloud / reverse-tunnel campaign
- Ghostwriter / FrostyNeighbor JavaScript PicassoLoader chain
- Famous Chollima Packagist dev-branch loader
- Dutch Police / NCSC 17-million-device botnet disruption
- OX details Shai-Hulud copycat npm packages
- NATS-as-C2 KeyHunter credential-harvesting operation
- Microsoft details oob.moika.tech reconnaissance-first dependency-confusion cluster
- Pirated media SilentCryptoMiner RAT campaign
- Permiso ChatGPhish AI-summary phishing surface
- Marimo CVE-2026-39987 LLM-agent post-exploitation
- PraisonAI CVE-2026-44338 rapid exploitation
- GREYVIBE Russia-nexus AI-assisted Ukraine operations
- Socket details axios / plain-crypto-js RAT chain
- Kimsuky / Emerald Sleet / TA427
- The Gentlemen ransomware
- StegaBin Pastebin-steganography npm campaign
- BlackFile / UNC6671 vishing extortion operation
- Sicoob.Sdk NuGet banking certificate stealer
- Operation DangerousPassword axios npm compromise
- FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
- codexui-android OpenAI token stealer
- vpmdhaj OpenSearch npm cloud-secret stealer
- oob.moika.tech dependency-confusion environment stealer
- SafeDep live update on MicrosoftSystem64 / js-logger-pack
- TeamPCP extortion ecosystem update
- DAEMON Tools Lite supply-chain compromise
- Grandoreiro and BTMOB Latin America / Europe malware campaigns
- CISA adds Nx Console and TanStack supply-chain incidents to KEV
- Malware-Slop Claude user-data npm infostealer
- JINX-0164 crypto developer infrastructure campaign
- JINX-0164 actor profile
- Glassworm developer supply-chain botnet
- AI chatbot and SEO poisoning GPU-cryptojacking campaign
- Seedworm Dindoor / Fakeset U.S. network intrusions
- Chinese-language PhaaS wallet-tokenization ecosystem
- Fast16 nuclear-simulation sabotage framework
- forge-jsxy npm RAT
- Seedworm / MuddyWater signed-binary sideloading campaign
- Ababil of Minab MOIS-linked recovery-destruction campaign
- SafeDep details AntV / atool Mini Shai-Hulud indicators
- AI-augmented adversary operations
- KnowledgeDeliver CVE-2026-5426 ViewState exploitation
- Wiz details TeamPCP post-compromise cloud and GitHub abuse
- Funnull RingH23 and MacCMS supply-chain attacks
- Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
- Polymarket npm wallet-drainer packages
- Ghost CMS CVE-2026-26980 ClickFix poisoning
- RemotePE memory-only Lazarus RAT
- Socket details SAP CAP / Cloud MTA Mini Shai-Hulud compromise
- TrapDoor crypto-stealer cross-ecosystem campaign
- js-logger-pack Hugging Face exfiltration campaign
- ScarCruft Yanbian game-platform supply-chain attack
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
- Trend Micro Apex One CVE-2026-34926 exploitation
- Xinference PyPI compromise
- Laravel-Lang Composer tag-rewrite compromise
- LiteSpeed cPanel CVE-2026-48172 active exploitation
- Ollama P2P cryptominer RAT campaign
- BufferZoneCorp RubyGems / Go module CI poisoning
- GitHub / Packagist postinstall hook campaign
- Drupal Core CVE-2026-9082 active exploitation
- First VPN criminal infrastructure takedown
- Ghostwriter UAC-0057 Prometheus-themed phishing
- Langflow CVE-2025-34291 exploitation
- Megalodon GitHub Actions workflow backdooring
- Screening Serpens 2026 espionage campaigns
- ROADtools Entra ID cloud-intrusion toolkit
- LiteLLM compromise
- Mini Shai-Hulud npm/PyPI worm campaign
- TeamPCP group profile
- Nx Console VS Code extension compromise
- Showboat Linux post-exploitation framework
- GitHub Actions deployment poisoning
- node-ipc 2026 npm maintainer-account compromise
- Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
- Mini Shai-Hulud npm/PyPI worm campaign
- SANDWORM_MODE AI-toolchain npm worm
- art-template Coruna-style iOS watering-hole compromise
- shopsprint/decimal Go typosquat DNS backdoor
- actions-cool GitHub Actions tag compromise
- Webworm
- Fox Tempest
- TamperedChef-style productivity malware clusters
- Handala group profile
- ConnectWise ScreenConnect exploitation wave
- Codecov Bash Uploader compromise
- Okta support-system compromise
- CitrixBleed session-hijack wave
- CircleCI 2023 customer secret exposure incident
- CCleaner signed-update compromise
- Barracuda ESG zero-day backdoor campaign
- Accellion FTA exploitation campaign
- 3CX desktop app compromise
- 0ktapus phishing campaign
- JiaT75
- XZ Utils backdoor
- tj-actions and reviewdog compromise
- Trivy compromise