Source index
Feeds and primary sources we consider worth monitoring for future threat coverage.
High-value RSS / update feeds
- tl;dr sec (RSS at
https://tldrsec.com/feed.xml; added September 3, 2026 at Dean's request — recommended source. Clint Gibler's weekly curated digest of the best tools, talks, and research for working security professionals: one featured deep-dive plus a fast digest, with recent issues covering the Hugging Face technical report and incident, AWSHound, OWASP Agentic Skills Top 10, Figma's agentic-detection research, agent identity, Uber's agent-(E)DR, and GitHub supply-chain security improvements. The site HTML is Cloudflare-JS-gated, but the RSS endpoint serves cleanly to curl. Treat each issue as a discovery funnel: the digest links out to primary research blogs, so mine each issue for new primary sources worth their own source-index entry — candidate adjacent blogs seen in recent issues include Hugging Face security research, Figma's engineering/security research, and Uber's security engineering posts. Monitor for durable defender and operator value; promote concrete research to wiki pages with primary-source links rather than relying on the digest alone.) - OFAC / U.S. Treasury press releases (August 24, 2026 priority follow-up; Operation Economic Outcast "Economic D-Day" campaign — press release sb0613 designated a MOIS-directed critical-infrastructure cyber group plus nearly 60 entities/individuals/vessels and issued five E.O. 13902 sectoral determinations; monitor follow-on designations, the five named Mabna Institute individuals, the $10M Rewards for Justice offer, and any named-victim or tooling detail the release withholds. See Operation Economic Outcast page.)
- Metabase security advisories, GitHub advisories, and Wiz reverse engineering (August 11 update: GHSA-vwf4-m7j8-wcjf assigned CVE-2026-72898 and CISA added it to the KEV catalog on August 11 with an August 14 BOD 26-04 deadline. Monitor further first-party customer notices, connected-database impact, additional affected or fixed branches, and exploitation scope.)
- CISA Known Exploited Vulnerabilities catalog (September 2, 2026: seven CVEs added — JFrog Artifactory unauth administrative access under default config (CVE-2026-82329, 9.8, second exploited Artifactory flaw after CVE-2026-66384), Kestra OSS
endsWith("/configs")auth-filter bypass → unauth root RCE (CVE-2026-49869, 10.0, fixed 1.0.45/1.3.21), SonicWall SMA1000 pre-auth SSRF + post-auth cmd-inj (CVE-2026-83548/-83549, SNWLID-2026-0016, second exploited SMA1000 wave after UTA0533), LiteLLM MCP gateway auth bypass (CVE-2026-59822) and Starlette host-header smuggling (CVE-2026-48710) both KEV-confirmed in-the-wild, and Sangoma Switchvox SMB 8.3 unauth SQLi→RCE (CVE-2026-9586, 9.3, fixed 8.4.0.2); five due 2026-09-05, two pip due 2026-09-16 — covered on the September 2, 2026 KEV page. Prior August 31, 2026: both PaperCut CVEs CVE-2026-81578 / CVE-2026-82078 added, BOD 26-04, due 2026-09-14 — covered on the PaperCut zero-day page; earlier August 17–18, 2026 batch: Microsoft IKE Service Extensions CVE-2026-33824 double-free RCE, Broadcom VMware vCenter CVE-2026-59310 Syslog path-traversal RCE, Microsoft SharePoint CVE-2026-55040 weak authentication, Apple macOS CVE-2026-65400 Screen Sharing improper authentication — all August 21 BOD 26-04; Ray-Project CVE-2025-62593 browser-exploitable code injection, August 20 deadline. Monitor vendor patch status, exploitation indicators, and actor linkage; see August 17–18 KEV page.) - Coinspect / Ill Bloom wallet research and Coinspect blog (HTML watch for weak wallet-key generation, on-chain exploitation measurement, affected-application attribution, and migration guidance; priority follow-up is the CryptoJS
WordArray.random()/GHSA-rg76-677x-56q9campaign affecting RRWallet, Bexo Wallet, NanChat, Bitcoin Libre, and Milo Wallet, with 2^39 / 2^47 effective recovery-phrase search spaces and a measured $5.69 million lower-bound loss) - Censys ARC Research and blog (HTML watch for internet-wide adversary-infrastructure and rapid-response research with durable response-body, certificate, service, port, and provider pivots, including DarkSword / GHOSTBLADE iOS exploit-panel proliferation, leaked-kit code reuse, fast host churn, fake AWS and Apple credential lures, dual Coruna/DarkSword operation, and operator OPSEC artifacts.)
- N-able N-central security update, Hotfix 2 notice, Huntress rapid response, and CISA KEV catalog (August 8 priority follow-up; build 2026.3.1.10 supersedes Hotfix 1 and is required even on 2026.3.1.7; monitor victim and MSP scope, the evolving exploit path, additional Take Control and Cloudflare Tunnel artifacts, actor attribution, fixed-build revisions, shared VPN-exit false-positive handling, downstream endpoint persistence, and national-CERT action.)
- Coinkite COLDCARD security advisory, technical backgrounder, and Block Bitcoin Engineering analysis (August 1 priority follow-up; monitor formal Coinkite review, reconciliation of the Mk2/Mk3 4.0.0 versus 4.0.1 lower bound, empirical recovery cost, confirmed affected-wallet and loss scope, proof or rejection of linkage to the 1,196-address / 1,082.65 BTC sweep, additional affected RNG-backed features, replacement hotfixes, public indicators, and actor attribution.)
- Adform security incident notice and Kevin Beaumont / DoublePulsar analysis (August 1 priority follow-up; monitor affected-site and visitor scope, reconciliation of Adform's July 27 affected date with the longer independent observation window, cache persistence, confirmed diverted transactions, replacement wallet addresses, initial access to the shared script deployment path, authority or client notices, additional indicators, and actor attribution.)
- CISA / FBI / EPA water-sector PLC activity alert and FBI PSA I-073026-PSA (July 30, 2026 priority follow-up; monitor internet-facing Rockwell Automation / Allen-Bradley MicroLogix 1100 and 1400 configuration tampering for additional states or victims, actor or access-path attribution, source infrastructure, exploit or credential-use detail, project-file and ladder-logic indicators, shared integrator or cellular architecture scope, and physical-process consequences.)
- Confiant Threat Intelligence (RSS watch for malvertising, ad-fraud, browser-delivery, cloaking, and cryptocurrency-user targeting with durable technical and infrastructure detail, such as SourTrade's ServiceWorker / SharedWorker browser-side assembly of per-session Windows executables from clean Bun runtime bytes, actor-supplied PE / JavaScriptCore payload material, and locally generated AES-CTR streams.)
- VulnCheck Research (Atom watch; monitor exploitation telemetry, target-intelligence research, public exploit proliferation, and KEV-relevant updates with durable defender value, including Windmill CVE-2026-29059 path-traversal attempts, wp2shell proof-of-concept growth, and embedded-device trust failures such as ENDLESSDOORS / CVE-2026-66747, where Zbtlink router firmware starts an unauthenticated
rctl-derived root command channel and OEM/ODM rebadging obscures the affected inventory; August 24: Exploiting SharePoint — CVE-2026-55040 (JWT auth bypass, CISA KEV) chained with CVE-2026-63520 (unsafe .NET type instantiation in BCS, KB5002893) into an unauthenticated RCE via BDCM upload + LosFormatter/TypeConfuseDelegate Deserialize gadget throughActivator.CreateInstanceinGetEntityObject, Rapid7 PoC Aug 11, in-the-wild honeypot hits from Aug 12, 8,500+ exposed SharePoint servers — see SharePoint RCE chain page; August 27: "Chinese Implants in the Supply Chain" — two further Nim implants in ZBT / MoreQuick white-label router firmware, SPEAKINGSTONE (yunmgrd, outbound UDP 10000 phone-home to the ENDLESSDOORS C2ac-link[.]com/47.107.224[.]89, PPPoE theft, DNS rewrite, reverse SSH; 392-device sinkhole population) and DARKLANTERN (infosrvd, unauthenticated UDP 9992 WAN listener → root shell, 203 instances in 22 countries) — see SPEAKINGSTONE / DARKLANTERN page; August 28: "Same Target, Different Playbooks: Two Attackers, Two Different Paths to Pwning the AI Stack" — canary telemetry on Langflow: 12 Langflow CVEs with in-the-wild exploitation evidence (11 added in 2026), 15,000+ successful canary attempts across CVE-2026-0769 / CVE-2025-3248 / CVE-2026-5027, hundreds of still-vulnerable public hosts (US-densest), and two divergent financially motivated post-exploitation playbooks (credential-theft: CVE-2026-5027 → Python harvester + SimpleHelp RAT → exfil23.234.98[.]182:9999→ IRC C2185.117.74[.]172:6667+ cron3WA72N.sh; cryptomining: CVE-2025-3248 → Chisel SOCKS5 → pearl-miner XMR → auditd disabled → CVE-2026-0769.sysddrops → PocSuite3 → SSH pivot216.78.235[.]34) — see Langflow canary-timeline page) - Wiz Research: wp2shell active exploitation (2026-07-20 priority follow-up; monitor CVE-2026-63030 / CVE-2026-60137 WordPress Core exploitation, batch-endpoint tooling changes, malicious-plugin and PHP-webshell variants, lateral movement or exfiltration findings, and CISA KEV or WordPress incident-response updates)
- Sonatype Security Research (RSS watch; monitor package-registry and ecosystem compromise research such as Atomic Arch AUR orphan-package adoption, malicious npm dependency pivots like
atomic-lockfile/js-digest/lockfile-js, Sonatype vulnerability guide entries, Shai-Hulud / Miasma supply-chain follow-ups such as Leo Platform / RStreams package clarification,llxlrpackage confirmation, and advisory pivots including ChainDropsonatype-2026-005579and its 2,225-component-version August 5 snapshot, plus automated disposable-publisher campaigns such as Flooding Dropper /sonatype-2026-005660and DPRK-linked NullReceiver activitysonatype-2026-005899/sonatype-2026-005901, where hijacked and newly published npm packages resolve raw-IP C2 through Ethereum transactions before/0x/cls//0x/lsJavaScript staging; August 21 follow-up: Broadcom/Spring August 20, 2026 security-advisory batch tracked as 91 CVEs across Spring Framework and related projects (Spring Security, Spring Cloud Config, Spring AI, Spring Data REST, Spring Integration, Reactor Core, Reactor Netty, Spring AMQP, Spring Batch), with Sonatype Guide identifying 209,569 affected components, standouts CVE-2026-59285 (Spring for GraphQL unsafe deserialization, CVSS 9.2, Jackson 2.x + paginated GraphQL fields) and CVE-2026-59318 (Spring AI tool-calling prompt-injection boundary bypass) — monitor CISA KEV additions, per-CVE fixed versions, and downstream remediation. See Spring 91-CVE batch page) - Aikido Security Research (HTML/RSS watch; monitor developer-machine, AI-toolchain, VS Code / extension, Codex-token, and package supply-chain compromises such as
codexui-androidOpenAI token theft, poisoned extensions, Laravel-Lang, Mini Shai-Hulud follow-ups, SleeperGem-style RubyGems dormant-maintainer account takeovers that evade CI and persist on developer workstations, and the unconfirmedanthropickit==999.9.9candidate for Anthropic's evaluation-published PyPI malware; monitor Anthropic/PyPI confirmation, hashes, and victim-side corroboration before promoting candidate linkage to fact; August 19 follow-up: Gogs self-hosted Git path-traversal RCE CVE-2026-52813 plus unpatched bypass and CVE-2026-52810 push-authorization bypass from Aikido Attack AI pentesting; September 3, 2026: "MECCHA CHAMELEON can't hide from the RCE" — second delayed RCE via an exposed Unreal-EngineStopRecordingOutputrecording function: Steam Workshop map → arbitrary file write (null-byte truncation defeats the forced.wavsuffix) → HTA payload inside 16-bit PCM sample data → Startup-folder persistence after reboot; patched in 4.0.0 (Aug 20, 2026), no malicious maps found — see MECCHA CHAMELEON page; September 4, 2026: "Dirty Frag (CVE-2026-43284): the Linux kernel bug that turns read access into root" — the Dirty Frag family (CVE-2026-43284 IPsec/XFRM ESP esp4/esp6 8.8, CVE-2026-43500 RxRPC/AFS rxrpc 7.8, CVE-2026-46300 "Fragnesia" XFRM ESP-in-TCP 7.8), page-cache corruption primitive, distribution-backport version confusion, RHEL/Ubuntu exposure position, container-escape PoC, and the first reported limited real-world activity (Microsoft observedsu-based escalation, possibly Dirty Frag or Copy Fail) — see DirtyClone page 2026-09-04 update) - QiAnXin XLab (HTML watch; monitor MODBEACON / Operation Phnom Penh Silver Fox Ghost-distributor activity, large-scale exploitation, botnet, ClickFix/page-poisoning, hosting-control-plane abuse such as Mr_Rot13 cPanel CVE-2026-41940, infrastructure writeups such as Ghost CMS CVE-2026-26980 mass compromise reports, recon/proxy botnets such as AryStinger legacy-router and QNAP Malware Remover exploitation, DDoS botnets such as RustDuck's Loader + Core transition from C to Rust with weak-password / IoT / Web-RCE propagation and Dysphoria's post-JackSkid ENS/SNS infrastructure resolution, UPnP-enabled victim relays, and dynamic relay lists, AI-service and cloud-credential botnets such as NadMesh targeting MCP, ComfyUI, Ollama, n8n, Docker, Kubernetes, Redis, and Jenkins, and cybercrime-infrastructure / web-supply-chain reports such as Funnull RingH23 / MacCMS poisoning)
- Wiz Research and RSS (monitor TeamPCP/Mini Shai-Hulud package waves including Miasma /
@redhat-cloud-services, AsyncAPI / M-RED-TEAM-style branch-to-provenance package compromises, JINX-0164-style cryptocurrency developer targeting with fake meeting flows, macOS malware, GitHub/source-repository abuse, and post-compromise cloud/GitHub abuse reporting such as TruffleHog validation, ECS Exec / SSM execution, mass repository cloning, and workflow-log deletion; monitor managed-cloud tenant-isolation and storage research such as CosmosEscape's Gremlin .NET sandbox escape, shared DB Gateway execution, platform-wide Cosmos Master Key, Config Store enumeration, cross-tenant primary-key retrieval, and private-network bypass, plus S3-compatible neocloud object-storage gaps including namesquatting, partial API semantics, uneven secret scanning, weak least privilege, presigned-URL exposure, and audit or encryption assumption drift; also monitor identity-attack detection research such as Entra ID rogue device-registration abuse where AI-generated device names and User-Agent strings erode static ROADrecon-era fingerprints (Dsreg/10.0, DESKTOP-XXXXXXXX) and shift detection to naming-convention anomaly baselining and device-code-phishing-to-registration correlation; also monitor AI and MCP trust-boundary research such as internet-exposed unauthenticated MCP servers acting as privileged proxies to production data, destructive operations, shell execution, cloud metadata, and credentials, Amazon Q Developer CVE-2026-12957 MCP auto-execution through.amazonq/mcp.jsonworkspace configuration, and GhostApproval symlink write-confusion / approval-prompt canonical-path failures affecting AI coding assistants; August 27 follow-up: "Inside 90 days of attacks on AI infrastructure" — 90+ days of honeypot telemetry across LiteLLM, Flowise, LangChain, Langflow, ChromaDB, Ollama, and Node-RED canaries in three patterns: (1) MCP-server exploitation for RCE — observed CVE-2026-59822 MCP gateway auth bypass (any single-character Bearer token grants full MCP access;GET /v1/modelsprobing) and CVE-2026-42271 MCP stdio test-endpoint command injection (fake stdio config downloads/executes the gmon Monero miner to/tmp/.dbus-cache/gmon, returns a valid MCP handshake, then rmtree's the staging dir; output smuggled in a fake tool'sdescriptionfield), chained with CVE-2026-48710 Starlette host-header bypass for unauthenticated RCE, which external researchers link to the Qilin ransomware group (third-party attribution, not confirmed by Wiz); (2) blind prompt injection against LangChain/Flowise/OpenWebUI/Node-RED agents with OAST DNS callbacks (attacker IP in subdomain + per-session random string), Pastebin-fetched base64 payloads, and XMRig staged at/usr/src/node-red/xmrig; (3) AI-native post-exploitation — LiteLLM master key read from Python module state (litellm.proxy.proxy_server.master_key), default-sk-1234backend fingerprinting viaPOST /chat/completions, LLMjacking quota-abuse decisioning, and a Langflow miner staged at/app/data/.claude/renamedunicorn— full IOC set (185.62.1[.]8, 185.84.98[.]85, pool.hashvault[.]pro, crazyeltonproxy[.]top, 94.26.106[.]29, 1710.rwlp.be,/tmp/.dbus-cache/,/tmp/x86_64//tmp/amd64) on the Wiz AI-infrastructure honeypot page; preserve the honeypot-telemetry caveat, the reconstruction-not-capture caveat on the prompt-injection payload, and the Qilin attribution as external/third-party) - Wiz H1 2026 cloud threat review — https://www.wiz.io/blog/cloud-threat-highlights-h1-2026 (August 6 priority follow-up; monitor JINX-0163 / FulcrumSec non-human-identity extortion for victim or infrastructure indicators, initial-access and state-file detail, cross-cloud identity pivots, extortion-as-a-service clarification, law-enforcement or provider response, and additional evidence on delayed reuse of TeamPCP-stolen credentials by separate groups.)
- Wiz ChainDrop follow-up — https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack (August 4 priority follow-up; monitor selective C2-controlled dead-man-switch arming, per-host SHA-256 identifiers, RSA-key rotation,
tmp.dpkg_14527.lock,chore: update config, historical smart-contract-resolvedpypi-get.com/js-mirror.cominfrastructure, expanded AI-agent / wallet / Jenkins / Argo CD / Harbor / Alibaba / Tencent credential targets, contract rotation, victim execution, and maintainer or registry postmortems.) - Socket Security Research — https://socket.dev/api/blog/feed.atom and https://socket.dev/blog (Atom/HTML watch; monitor Shai-Hulud/Mini Shai-Hulud variants, registry-response notices such as npm token invalidation, TeamPCP/copycat reporting, legitimate-namespace prerelease compromises such as the Joyfill
@joyfill/layouts/@joyfill/componentsimport-time PolinRider-family loader using Tron/Aptos/BSC resolution and DEV#POPPER-style developer-tool persistence, enterprise developer-ecosystem compromises such as SAP CAP / Cloud MTA packages, cross-ecosystem Packagist/Composer and GitHub source-repository compromises, DPRK/Contagious Interview developer-targeting dead-drop campaigns such as StegaBin Pastebin/Vercel payload delivery, Famous Chollima Packagist dev-branch loaders, and PolinRider expansion across npm, Packagist, Go modules, Chrome extensions, fake.woff2loaders, VS CodefolderOpentasks, Git history rewriting, and blockchain/RPC C2, RubyGems abuse such as GemStuffer or BufferZoneCorp-style RubyGems/Go module CI poisoning, Laravel-Lang-style Composer tag rewrites/backdoors, financial/enterprise SDK impersonation such as Braintree.Net NuGet payment-card / merchant-credential skimming, Sicoob.Sdk NuGet mTLS certificate theft, NuGet DotnetTool malware such as game-cheatpepesoft.exedownloaders using DNS-over-HTTPS, GitHub/Hugging Face staging, Google Sheets telemetry, and Telegram screenshot paths, and Paysafe / Skrill / Neteller npm+PyPI typosquat stealers, high-blast-radius package compromises such as Axios pullingplain-crypto-jsRAT payloads and Mastra@mastra/*packages pullingeasy-day-js, Hades-style PyPI wheel startup-hook branches of Miasma / Mini Shai-Hulud using*-setup.pth, Bun,_index.js,.abi3.sonative extensions, and split loaders such aslangchain-core-mcp, cryptocurrency SDK compromise such as the Injective SDK npm wallet stealer where@injectivelabs/sdk-ts@1.20.21and pinned scoped packages exfiltrated mnemonics/private keys during normal key derivation, trusted developer-tool compromises such asjscramblerfollow-on malicious releases that move frompreinstallhooks todist/index.js/dist/bin/jscrambler.jsruntime trigger injection, Leo Platform / Miasma follow-ups such asllxlrpackage expansion, Immobiliare Labs Backstage plugin compromise, and Verana Blockchain Go source-repository poisoning through.claude//.vscode/hooks, AI-toolchain supply-chain tradecraft such as MCP/coding-assistant poisoning and TrapDoor-style npm/PyPI/Crates.io credential-stealer campaigns, AI-scanner anti-analysis such as prompt-injection comments, safety-triggering text, context flooding, and payload-after-noise layouts, Open VSX / VS Code extension abuse such as GlassWASM TinyGo/WebAssembly malware with Solana memo C2, Operation Muck and Load-style malicious Go module / GitHub lure-network campaigns with commit-farmed repositories, public dead-drop resolvers, protected archive delivery, RAT/infostealer payloads, andischhfd83pivots, and browser-extension abuse such as Chrome Web Store live-wallpaper ad-fraud / traffic-laundering networks and staged VPN/proxy extension clipboard stealers such as VPN Go, plus the "Superior" trusted-extension takeover campaign where 18 Chrome and 1 Edge extensions share a modular wallet-drainer / credential-stealing framework delivered over WebSocket C2 through CSP-stripping main-world injection, with five of the 19 extensions bought from legitimate authors and the campaign traced to February 2024 DomainTools dual-function-malware overlap → Superior page.) - OX Security Research (HTML watch; monitor AI-toolchain and software-supply-chain malware such as Malware-Slop /
mouse5212-super-formatter, Claude/mnt/user-datatheft, GitHub Contents API exfiltration, leaked actor tokens, Shai-Hulud source-leak copycats such aschalk-tempalte/axois-utils/color-style-utils, TeamPCP follow-ons such as the Telnyx PyPI compromise after LiteLLM, Miasma /@redhat-cloud-servicesimpact notes such as stolen-repository counts, earliest observed infection timing, six-stage loader loops, alternateMiasma : The Spreading Blightspacing, andfiredalazerGitHub commit-search C2, ChainDrop response follow-ups such as clean-package MCP Registry entries that point to source repositories carrying Claude Code / VS Code execution hooks, delayed npm and GitHub cleanup, and cross-variantresults-*.jsonexposure measurements (including the August 9 "Shai-Hulud Outbreak Debrief: The Worm Evolves into MCP" 5-day snapshot: 440+ unique npm packages / ~2B+ monthly downstream downloads, 5 live infected repositories — one of them the source repo of a public MCP marketplace server — 3,800+ public credential-dump repositories, auto-spawning of new infected repositories with the "Shai-Hulud: Here We Go Again" signature, and the @ornikar packages live for 72 hours; covered on the ChainDrop page), MCP / AI-agent supply-chain trust-boundary research such as stdio command-execution configuration exposure, sandbox-boundary research such as the vm2builtin: ['*']denylist inversion that admitsos/dnshost-state access and host DNS-rewriting, GitLab rolling-deploy@gl_introducedGraphQL code-injection and multiplex-query CSRF analysis, and AI-generated commodity npm malware tradecraft) - Endor Labs and research/learn pages (HTML watch for vulnerability and sandbox-boundary research with durable defender value, especially native-binding / V8-isolate and AI-agent-toolchain flaws; August 20, 2026: isolated-vm
ExternalCopytype-confusion sandbox escape GHSA-864f-rcv7-6rh4, demonstrated guest-to-host control-flow hijacking / RCE in the V8 sandbox used by n8n, Activepieces, Mastra, Sim.ai, Budibase, Directus, and Rocket.Chat, fixed in 7.0.1 / 6.2.0 → tools/isolated-vm-external-copy-type-confusion-sandbox-escape.md; monitor for CVE backfill, other native-binding or isolate-wrapper boundary flaws, and in-the-wild exploitation.) - CrowdStrike Counter Adversary Operations (HTML watch; monitor developer-targeting botnet and supply-chain disruption reporting such as Glassworm, C2 takedowns, package/extension compromise, endpoint remediation guidance, and Windows execution/persistence research such as ClickOnce
.application/.appref-msabuse and HKCU COM hijacking; also monitor annual threat-hunting observations such as public-PoC exploitation windows, AI-agent detection volume,ALTERED SPIDERandSTARDUST CHOLLIMAsoftware-supply-chain activity, npm ecosystem prevalence, vishing, device-code phishing, and LLMJacking; September 3, 2026 follow-up: CrowdStrike is actively investigating FalconFlank, a researcher PoC 0-day local privilege escalation in the Falcon Sensor that abuses the Office-malicious-macros remediation path on fully-updated Win11 25H2 / Server 2025 (Chaotic Eclipse, the third endpoint 0-day in ~5 weeks after HardBreacher/Kaspersky and ShieldBreak/Defender); CrowdStrike's mitigation is disabling the "Microsoft Office File Suspicious Macro Removal" policy setting with a FalconFlank Tech Alert in the support portal — monitor the shipped sensor code fix, mechanism disclosure, and in-the-wild exploitation — see FalconFlank page; September 1, 2026 follow-up: "Peer Pressure: Inside the Sality Botnet Disruption Operation" — coordinated P2P sinkholing disruption (executed Aug 31, 2026, with DOJ/FBI/DoD-OIG-DCIS/Shadowserver, support from Europol/Eurojust/LE in Bulgaria-Hungary-Romania) of the 23-year file-infecting Sality P2P botnet (33,000+ machines; no peer auth + non-code-updatable file-infecting protocol = the exploited weak points; super-peer-list poisoning every ~40 min; two networks v3/v4 with distinct RSA keys now isolated and beaconing to sinkholes; EggJagger clipjacker ~8-year primary payload, ≥₽12.1M/~$150K stolen, portfolio peaked ~₽147M Jan 2025; on-demand DDoS April 2016 / Feb 25 2022 / Sept 2023); installed payloads persist — hunt the188.166.101[.]148lighthouse UDP beacon, v3/v4 URL-pack URLs, and the two embedded-RSA-key YARA rules — see Sality P2P botnet disruption page) - Akamai Security Research (HTML watch; RSS blocked/unavailable in current checks; monitor active-exploitation and edge/WAF telemetry writeups such as Drupal CVE-2026-9082, exposed-AI-service abuse such as Ollama P2P cryptominer/RAT campaigns, APT exploit-chain analysis such as APT28 LNK / SmartScreen bypass / authentication-coercion findings, and infrastructure/botnet disruption notes)
- SafeDep Research (HTML watch; monitor package-takedown evasion and rapid npm republishing such as
@apexfdn/apex→@copilot-mcp/apex, macOS AMOS-family postinstall theft, attacker-controlled remote MCP fronts, mutable GitHub release delivery, CI/CD, GitHub repository backdooring, package-registry compromise, Megalodon-style workflow backdoors, crypto/AI-tooling package malware such as Polymarket-themed wallet-drainer npm packages, actively maintained developer-targeting npm RATs such as forge-jsxy, MicrosoftSystem64 / js-logger-pack, and MYRA /apintergrationpost, Hugging Face / Discord exfiltration, typosquat infostealer campaigns such asfaster-axios/turbo-axiosEpsilon Stealer, runtime-triggered no-install-script npm backdoors such asnodemon-sudo/tslint-confwith detached child Node processes, Pinata IPFS staging, JsonKeeper dead drops, andFunction-constructor execution, AI-brand scope-squatting credential harvesters such as@withgoogle/stitch-sdk, targeted dependency-confusion environment stealers such as theoob.moika.techcampaign and follow-on@marketfront/@tqm-mfepackage waves withInternal package — Platform Engineering TeamREADME markers,X-Secretexfil headers, RC4/XOR-hidden C2 configuration, and private-registry fallback targeting, build-config PR injection such asastro.config.mjsblockchain-C2 loaders and horizontal-whitespace diff hiding, Mastra /easy-day-js-style stale npm maintainer scope takeovers with provenance dropped and Hostwinds raw-IP RAT infrastructure, split-package Windows npm droppers such asprocwire/routecraftwith helper-package XOR C2 reconstruction andfiles.catbox.moepayload staging, multi-scope disposable-email npm infostealer campaigns such as thewshu.netpackage set with scrubbed latest tags, runtime execution, Rust stealers, user-level systemd persistence, and Telegram C2, LeoPlatform Miasma orphansnapshot-*branch / fake Dependabot workflow reconstruction, npmbin-entry dependency-confusion harvesting such as the August 12 Google-scoped bin-name campaign (21 squatted unscoped binary names, per-packagejchunt[.]topC2,rootdaddy-msrcpublisher), and Mini Shai-Hulud / AntV / Miasma-style detection pivots such as payload hashes, orphan GitHub commit delivery, two-wave trusted-publishing abuse, live-latest malicious releases,kitty-monitor,gh-token-monitor, AI-assistant persistence, and source-repository auto-execution through Claude Code / GeminiSessionStart, CursoralwaysApply, VS CodefolderOpen, andnpm testlaunchers) - SafeDep ulid-xyz transitive delivery chain (MAL-2026-6672) (September 1 priority follow-up; a cross-platform MicrosoftSystem64 RAT delivered three npm dependencies deep —
ioredis-xyz5.11.2 (byte-for-byteiorediscopy) →redis-type-xyz1.10.6 (empty manifest, 19 minutes after the entry package, armed the chain via caret range without republishingioredis-xyz) →ulid-xyz2.12.2–2.12.3 (typosquat ofulidx, 467 KB postinstall payloaddist/node/payload.js, WebSocket C2 on port 8010 at65.21.30[.]171/95.216.232[.]162, both Hetzner, XOR key5A 3C 7E 12 9F 4B 6D 8A,deploy_binaryoperator-chosen second stage, <4-processor sandbox-evasion exit). Persistence namedMicrosoftSystem64on all three OSes. Seeded in 28 purpose-built AI/fintech/trading/MCP GitHub repositories (e.g.whisdev/flash-loan-trading-bot— samewhisdevpersona JFrog traced on the earlier cluster's command server). Same implant name / persistence design / C2 port / Hetzner hosting as the js-logger-pack cluster (kmsec.uk / OX Security: FAMOUS CHOLLIMA / Contagious Interview, DPRK-linked). Monitor: second-stage implants observed viadeploy_binary, additional seed repositories, C2 IP rotation, and registry takedown completeness. → ulid-xyz page, cross-linked at js-logger-pack cluster page) - Lumen Black Lotus Labs (HTML watch; filter for Black Lotus Labs posts covering telecom, routing, botnet, and nation-state enablement-infrastructure research such as JDY / KV-botnet SOHO and IoT reconnaissance networks and the August 26, 2026 "Infrastructure Quartermaster: Inside a China-Nexus State Enablement Model" post on QTFY / QScan / QTRouter — see QTFY page)
- Snyk Blog / Security Research (watch Mini Shai-Hulud/TeamPCP follow-ups, registry-scale advisories, package-level vulnerability records, and independent package/tarball validation such as ChainDrop
SNYK-JS-KEYV-18515941, thekeyv@6.0.0tarball hash, exact maintainer-linked carrier scoping, and verified-commit/provenance authorization boundaries; also monitor stale-maintainer npm scope compromises such as Mastra /easy-day-js, Composer/Packagist incident-response updates such as Laravel-Lang all-version compromise advisories, and AI-agent supply-chain boundary cases such as jqwik 1.10.0 maintainer prompt injection through build/test output, developer-environment MCP / skill inventory risk, and ToxicSkills-style public skill measurements) - Checkmarx Zero / Security Research (HTML watch; monitor malicious package and developer-supply-chain campaigns with package/version and infrastructure detail, including SuccessKey / ChainVeil and ViteVenom scoped npm impersonation, import-time execution, mixed clean/malicious releases, and Tron / Aptos / Binance Smart Chain C2 resolution)
- JFrog Security Research — https://research.jfrog.com/ (HTML watch; monitor TeamPCP/Mini Shai-Hulud follow-ups such as the hijacked
@bitwarden/cli@2026.4.0package,bw_setup.js/bw1.js, encrypted Checkmarx-lookalike exfiltration, and GitHub commit-search PAT and fallback-domain staging; targeted NuGet business-logic manipulation such asNewtonsoftt.Json.Netusing Harmony runtime patching and Seq-shaped exfiltration to rig Digitain betting results, PyPI import-time compromises such as Xinference and durabletask, optional-dependency GitHub-commit delivery, cloud/Kubernetes lateral-movement payload evolution, malicious developer/AI packages abusing platforms such as Hugging Face for CDN/exfiltration or prompt theft, cryptocurrency-developer package lures such as Solana FakeFix npm/PyPI patched-SDK packages, Injective SDK wallet-key theft follow-ups where runtime wrapper paths andX-Request-Idheader exfiltration change scoping, GitHub issue spam, Telegram C2, fake MEV private-key prompts, and Deno loader persistence, PostCSS-themed npm impersonation such aspostcss-minify-selector-parser/aes-decode-runner-proleading to PowerShell and Nuitka Windows RATs, Rollup polyfill masquerading packages such asrollup-packages-polyfill-core/rollup-runtime-polyfill-corewith JSONKeeper staging, browser/wallet theft, and Socket.IO / node-pty remote access, package-directory editor-task execution such ashtml-to-gutenberg/fetch-page-assetshiding VS CodefolderOpentasks behind fake font assets and blockchain dead drops, browser-side package-registry abuse such as Lucide Proxy student web proxies turning visitors into Wisp / WebSocket DDoS nodes, Miasma /@redhat-cloud-servicesfollow-up indicators such as type-only package install hooks, GitHub commit-search C2, camouflage exfil destinations, and AI-scanner prompt-injection / refusal-evasion samples, plus IronWorm-style native Rust npm infostealers with eBPF rootkits, Tor C2, backdated GitHub commits, and trusted-publishing propagation; also monitor high-signal Linux/container-host vulnerability research such as DirtyClone / CVE-2026-43503 DirtyFrag-family local privilege escalation; promoted July 30, 2026: "SQLite Critical CVEs or LLM Slop?" — a newly createdprogrammervuln/cveadvisory-GitHub repository published a batch of SQLite vulnerability advisories (CVE-2026-51302 / -51303 / -51300 / -51297 / -51296 / -51304) plus 50+ other CVEs that NVD flagged critical and CISA ADP agreed with; JFrog's isolated ASan-instrumented verification found the cited functions do not exist in the claimed versions, the claimed 3.51.2→3.51.3 "patch" made no change to src/expr.c, the PoCs do not crash, none appear on SQLite's official advisory page, and the advisories flag AI-generated under GPTZero; Red Hat downgraded CVE-2026-51302 from 10.0 to 7.6 after initial scoring — see the LLM-slop false CVEs pattern page, and monitor follow-ups, other affected products in the batch, and NVD/CISA corrections) and JFrog Blog RSS https://jfrog.com/blog/feed/ (watch npm v12 explicit-trust install controls such asallowScripts,--allow-git, and `--allow-remo... [truncated] - JFrog Spring-CVE "Critical" context analysis — https://research.jfrog.com/post/when-critical-loses-context-spring-cves/ (September 3, 2026; triage of the August 20 Broadcom/Spring 91-CVE batch: CISA ADP rated six CVEs "Critical" on 08-20 but per-CVE re-derivation diverges sharply from the ADP band — CVE-2026-47884 spring-webmvc 9.8 ADP vs 5.8 vendor (conditional RCE via legacy XsltView, ~33 GitHub imports), CVE-2026-47890 webmvc/webflux 9.8 vs 2.6 (SSE
\rstream corruption, no code exec/data leak), CVE-2026-47891 spring-web 9.8 vs 4.3 (memory exhaustion only), CVE-2026-47892 webflux 9.8 vs 4.8 (non-default config), CVE-2026-59313 webmvc 9.8 vs 2.6 (same SSE bug as 47890), CVE-2026-59283 spring-expression 9.1 vs 6.5; structural cause: NIST stopped enriching non-KEV / non-federal-critical / non-EO14028 CVEs in April 2026, NVD backlog >27,000, 2026 YTD 58,482 CVEs (+45% vs 2024, +20.9% vs 2025); durable read: ADP band is a triage signal, not an emergency — patch in normal cycle unless the specific endpoint + config is exposed; monitor KEV additions for any of the six. See Spring 91-CVE batch page) - JFrog ChainDrop follow-up — https://research.jfrog.com/post/shai-hulud-is-back-august/ (August 4 priority follow-up; monitor its 428-package / 1,700-version live inventory, repository and GitHub Actions infection artifacts, Ethereum-resolved
/routerC2, additional file hashes, npm Xray IDs, cleanup state, victim execution, and whether reusableShai-Hulud: Here We Go Againmarkers support lineage without proving TeamPCP operator identity.) - SafeDep ChainDrop follow-up — https://safedep.io/keyv-npm-supply-chain-compromise/ (August 4 priority follow-up; monitor the 444-package / 2,234-version / 12-organization snapshot, poisoned
latesttags, repeated-version growth, source-staged but unpublished@keyv/*siblings, publisher-specific OIDC versus direct-token paths, registry cleanup, and reconciliation of its no-embedded-C2-host claim with StepSecurity and JFrog's Ethereum-resolved dynamic HTTPS channel.) - SafeDep fake-TradingView macOS stealer (WEEVILPROXY/JSCEAL lineage) (August 21 priority follow-up; a paid Google video ad on YouTube drove a fake
.pkgthat installed a self-healing LaunchAgent watchdog (com.microsoft.service.systemhelperwatcher.v8mgfk) re-fetching a shell stager from Cloudflare-frontedvelvetforge.net/cedarengine.comevery five minutes. The stager runs aGET /scriptevalloop gated on launchd and a mislabeledapplication/pdfcontent type, authenticates withX-Machine-Idand a hard-coded HS256 JWT (aud=coordination), and silently sudo-es via a plaintext password cached at/Users/Shared/.passwd. The payload is an 18.6 MB AES-256-CBC-encrypted V8 code cache (key2e1ba69f…) loaded through a signed Node.js binary plusNODE_OPTIONS=--require, evading Gatekeeper; six0.<hash>.nodencc modules add keylogging, ScreenCaptureKit/CGVirtualDisplay capture, keychain access, UI automation, and a local TLS-terminating MITM proxy on127.0.0.1:49313backed by a rogue root CA in the System keychain. Monitor thevelvetforge.net/cedarengine.comC2 rotation,latest_v*_setup*.pkgfilename changes,utm_campaign=o429-12.2campaign-tag variants, the WEEVILPROXY (WithSecure) / JSCEAL (Check Point Research) lineage confirmation, additional victim scope, and whether the macOS-variant persistence label or domains are named in a public writeup. Preserve SafeDep's explicit inference-not-attribution caveat: no public report names this macOS variant, its domains, or its persistence label.) - JFrog arrayref / proc-macro1 crates.io compromise (August 20 priority follow-up; monitor the
droundy-account three-crate compromise (arrayref0.3.10,internment0.8.7,append-only-vec0.1.9) plus theproc-macro11.0.107 typosquat carrier, JFrog Xray IDs,build.rssplit-base64 C2 staging, per-OS stage-3 blob names (/tmp/rust-setup,%TEMP%\rust-setup.ps1,.vbslauncher), clean-version pins, and stage-2 endpoint state.) - Wiz Research arrayref stage-2 / DPRK overlap (August 20 priority follow-up; monitor the stage-2 implant recovered from Google Threat Intelligence samples —
POST /49890878beaconing, Chrome/Brave/Edge SQLite saved-login enumeration,kill/minicfg/startup/runscriptcommands, per-OS persistence (HKCU Run / LaunchAgent / systemd user service), DGA.comfallback, AES-128-GCM config under the hardcoded keyi am botkingwith an embedded RSA-2048 private key, and the stage-2 SHA1 set — plus Wiz's DPRK-overlap assessment: shared/49890878beacon path and SSL issuer with the Mastra/Sapphire Sleet campaign IPs and the23.254.164.0/23Hostwinds range, and23.254.167[.]216in GCTI's UNC1069 axios analysis. Preserve the correlation-not-attribution caveat until a named-actor assessment or takedown links the operations. RustSec advisories now published (see the active watch topic above); still watchdroundyaccount recovery, any newarrayrefrelease, and a CVE assignment.) - SafeDep Baileys / libsignal-node npm campaign (August 10 priority follow-up; monitor the fork-based campaign of 70 confirmed Baileys-based package names (343 versions) plus 15
libsignal-nodeimpersonators (38 versions) that abuse the installer's already-paired WhatsApp session to force-follow attacker channels, inject an advertising URL into outgoing media, forge channel attribution on outgoing messages, or block the bot account (self-DoS) via a base64gintokiauthorisation gate. Monitorlevvleys.json/LevviCodeID/Levi4thanandlevvicode[.]cloudoperator rotation, additional confirmed packages against the 4,250-name / 112-name registry namespaces, registry removals that pre-empt source analysis (e.g.@diezyyasha/libsignal-node), confirmed victim scope, whether forced-follow channels carry further payloads or monetisation, and spread of the remote-follow-list pattern to other multi-device bot libraries. Preserve SafeDep's scoping: confirmed set is a lower bound, no broader actor identity asserted, and the campaign is non-consensual social abuse shipped through npm — not credential theft — distinct from the ChainDrop / Mini Shai-Hulud and arrayref operations.) - Elastic Security Labs coding-agent hook audit (August 11 priority follow-up; monitor the 280-line dependency-free bash hook collector and
elastic/elasticsearch-labsfilestream integration for the planned Windows PowerShell port and Claude Code follow-up, the growth of logged tool-call events (13M+ from 1,100+ machines / ~900 users since May 2026), whether blocking/allow-deny hook controls are added beyond the current record-everything sensor posture, and adoption of theai_hooks.*field-level-security privacy pattern by other teams. Defensive-telemetry reference; no actor or campaign attribution.) - GTIG Russian auth-focused clusters (UNC6293 / UNC7005 / UNC5976) (August 20 priority follow-up; monitor Google's three suspected-Russian cyber-espionage clusters abusing legitimate authentication flows against academia, aerospace/defense, government, and think-tank targets in Europe and the U.S. UNC6293 (assessed an Ice Relic / APT29 sub-cluster) runs small-scope diplomatic app-password and OAuth phishing; UNC7005 / Storm-2945 ran May–June 2026 WhatsApp device-linking spoofing (linking the victim's account to an attacker device to record audio/video and harvest credentials), added Vidar / Atomic (AMOS) infostealers against U.S. targets around May 2026, and began Google OAuth phishing via FOC-spoofing domains from July 31 / August 6–13, 2026 against European defense-industry targets; UNC5976 (active since at least March 2026) harvests Google OAuth tokens through file-sharing-themed domains plus per-domain Cloud projects and delivered a HEADRUSH Excel-plugin HTA possibly targeting a Ukrainian aerospace/imaging company. Preserve Google's assessment caveats: "suspected Russian," Ice-Relic sub-cluster relationship not multi-agency confirmed. Monitor for the CaptiveCrunch cross-link (Microsoft, ongoing since early May 2026), Lumen Black Lotus Labs' suspected MSP supply-chain compromise (~70 victim IPs; 40 unique IPs beaconing to CaptiveCrunch C2, 30 to AiM token-harvesting infrastructure, 1 to ChocoShell C2) and confirmation of the MSP scope, plus infrastructure rotation after Google's disruption of UNC5976's 12+ domains and any new FOC-spoofing domains.)
- Recorded Future Insikt Group (HTML watch for actor/tool research with durable defender value, relayed via secondary outlets such as The Hacker News; August 28, 2026: HOOKEDGE batch-script backdoor cluster "BlueDelta" — APT28 moderate-confidence attribution against Romanian/Spanish/Turkish government and diplomatic targets, webhook.site two-stage C2 architecture, HEADLACE lineage → ops/apt28-hookedge-backdoor-european-gov-diplomatic-august-2026.md)
- Unit 42 Research (watch recurring npm threat-landscape updates for Shai-Hulud/Mini Shai-Hulud wave metrics, SLSA/OIDC findings, containment-order warnings, cloud-identity tradecraft such as ROADtools / Entra ID abuse, cloud-control-plane defense-evasion research such as AWS CloudTrail / Google Cloud Logging route, destination, and KMS tampering, cross-cloud storage namespace risks such as bucket hijacking through deleted/recreated object-storage destinations, high-signal actor updates such as Screening Serpens / MiniUpdate / MiniJunk and CL-STA-1062 / UAT-7237 Southeast Asia government and critical-energy intrusions with TinyRCT, OT / industrial-control vulnerability research such as Siemens RUGGEDCOM ROX II CVE-2025-40948 / CVE-2025-40947 / CVE-2025-40949 chains from file disclosure to persistent root access, Miasma / Mini Shai-Hulud lineage updates such as AsyncAPI
miasma-train-p1AI/editor-driven runtime execution and canary-controlled propagation, collaboration-tool phishing / identity guidance such as Microsoft Teams external-chat abuse and federation hardening, large-scale credential campaigns such as FortiBleed cross-service password spraying against Fortinet / Sophos / MSSQL and configuration-theft feedback loops and the August 2026 TheHatman forum-sold Entra tenant credential claims, cybercrime-economy updates that add durable TeamPCP / TGR-CRI-1135 monetization context such as LAPSUS$ / Vect extortion partnerships or public Shai-Hulud tooling claims, ransomware-economy and operational updates such as The Gentlemen / Storm-2697 / ArmCorp / Qilin affiliate-volume and affiliate-payout reporting, AI-agent skill supply-chain research such as Behavioral Integrity Verification for OpenClaw registry skills and ClawHub follow-ups covering unblocked macOS infostealer skills, scanner file-padding evasion, runtime affiliate injection, and agentic front-running, LLM-assisted malware engineering such as TuxBot v3 Evolution IoT botnet framework development, AI incident-response trend updates such as AI-compressed attack timelines, LLM/MCP-assisted C2, agentic ransomware, and cloud-AI token jacking, AI-hallucination supply-chain research such as Phantom Squatting where models invent domains that adversaries can pre-register for phishing, API/documentation poisoning, and autonomous-agent traffic capture, cloud-AI model lifecycle flaws such as Vertex AI default staging-bucket squatting / Pickle in the Middle, macOS malvertising/backdoor evolution such as CL-CRI-1089 Operation FlutterBridge / FlutterShell, and commodity stealer/miner campaigns with durable detection value such as Vidar / XMRig Factory-v3 malvertising, Go loader file inflation, fake Authenticode branding,MpClient.dllsideloading, and AMSI bypass tradecraft) - Unit 42 State of AI-Enabled Malware — August 2026 (August 25 priority follow-up; telemetry-grounded census of AI-enabled malware from 405 unique SHA-256 hashes — only 12 samples in production telemetry on Cortex XDR-protected endpoints and ~15-20 forwarded to WildFire, so roughly 97% exists only in sandboxes, research repositories, and security-validation platforms. Every production sample was detected and blocked by conventional local-analysis + behavioral + WildFire-cloud-verdict mechanisms; watch FunkSec seven-variant Rust ransomware iteration (Jan 1-6, 2025, LLM-assisted development indicators via PDB project-name rotation), the since-revoked-certificate Recipe Lister NSIS installer (50+ organizations, 6,500+ endpoint profile records), the fake-Dropbox AutoIt loader side-loading Oyster (CleanBoost), and the Rhadamanthys stealer AI-enabled chain; monitor for CVE assignments, independent replication, and production-telemetry updates) -> patterns/unit42-state-of-ai-enabled-malware-august-2026.md
- Unit 42 NOVA frontier-AI autonomous vulnerability discovery (August 4, 2026, "The Frontier AI Vulnerability Burst," updated August 10; two months of fully autonomous scanning across 3,915 open-source projects produced 14,090 confirmed vulnerabilities, 99.4% previously unreported, ~40% High/Critical under CVSS 4.0, with 85 later-matching public records read as evidence of rival autonomous scans; 5,421 supply-chain findings with validated downstream PoCs; every frontier model in the 14-project controlled evaluation contributed unique findings; monitor Project Lightwell / Akrites disclosure cadence, CVE backfill and patch-verification against the 85-overlap set, independent replication of the multi-model-ensemble claim, and whether the patch-window-collapse heuristic changes defender triage policy) -> patterns/unit42-nova-frontier-ai-autonomous-vulnerability-discovery-august-2026.md
- Unit 42 machine-speed agentic intrusion incident (September 2, 2026, "An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation," updated September 3 to clarify it was an intrusion, not a ransomware deployment; a human attacker used frontier AI models and attack-specific agentic frameworks to autonomously breach an enterprise network as part of a ransom attack — 50+ MITRE ATT&CK techniques (T1190, T1046, T1552.001, T1555, T1578, T1078; ATLAS AML.T0000/T0002/T0014/T0016/T0010/T0043) compressed into under 10 hours vs an estimated ~2 weeks of human red-team effort; chain: public-facing web breach → recon-agent microservice mapping → repo secrets scraping → secrets-manager master-credential theft → CI/CD pipeline hijack + cloud-key exfiltration (Terraform backdoor stopped by hard branch protection) → victim's own AI endpoints repurposed as post-compromise infrastructure (AML.T0043 LLM invocations via stolen API keys); agentic-usage tells: parallel LLM calls to multiple frontier agents, structured Markdown inter-agent handoff files, AI-generated custom scripts with UI elements, bursty 401/200 API loops, redundant overlapping persistence (SSH keys, serverless, container restart policies, cloud identities, CI/CD); the attacker directed the agent to leave an 80-page technical security-posture audit; monitor for independent replication, named-actor attribution, and whether the ATLAS mapping becomes the de-facto vocabulary for agentic-intrusion detection) -> ops/unit42-ai-assisted-cyber-attack-machine-speed-agentic-intrusion-september-2026.md
- Unit 42 CL-CRI-1131 / CL-CRI-1163 LLM-orchestrated LATAM campaigns (September 3, 2026, "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America," Reese Lewis / Sara McBroom; two ongoing multi-stage intrusion + exfiltration campaigns: CL-CRI-1131 Mexican transportation campaign (transportation org + federal ministries + municipal water utilities in Mexico and Ecuador; LotL numbered batch scripts with visible LLM trial-and-error on SAM/NTDS dumps; exfil pivot
62.171.185[.]97→ Let's Encrypt multi-SAN cert onm-doxa-apodo.duckdns[.]orgwith target-revealing subdomains apodo/geo/intel/vacunas/repuve/sre; Feb 27 → Apr 20 → Jun 19 2026 cert rotation to178.128.87[.]160hosting an internet-exposed NextChat multi-model LLM UI on :3000; CloudSEK tracks this as "Operation Escaneo," Gambit reported the Feb 2026 wave) and CL-CRI-1163 Brazilian financial campaign (Feb 2026 resume-themed phishing → homebrewed RATs → Go reverse-SOCKS5 SockTz v1–v9 install attempts in a 2-hour window from a compromised WordPress site, thenhxxp[:]//167.148.195[.]53:8888/socktz_v9.exe; open staging directory at167.148.195[.]53exposing hundreds of LLM-tell scripts —*_outputidentifiers,exploit_creative.py/exploit_careful.py/rce_focused.py; SHA-256a38b2cf8…/87bf8bc8…); overlapping SOCKS5 relay infrastructure ties the clusters;167.148.195[.]53+ SockTz previously tied by Trend Micro to JBoss targeting in the SHADOW-AETHER-064 cluster; monitor for infrastructure rotation (m-doxa-*.duckdns[.]org,178.128.87[.]160,167.148.195[.]53), NextChat re-deployment, and attribution that confirms or rejects a single operator across both clusters) -> ops/unit42-clcri-1131-1163-llm-orchestrated-latam-campaigns-september-2026.md - Unit 42 Spring Ring Teams vishing campaigns (August 31, 2026, "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams," Noam Sala; Jan–Apr 2026 operation, 150+ employees at 10+ orgs via external
.onmicrosoft[.]comhelp-desk personas — chat→voice vishing, Campaign A RMM/Quick Assist into obfuscated AMSI-bypassing PowerShell RAT atsan-sid[.]com, Campaign B tailored per-victim S3 dropper →vhlp/scnrpersistence + headless Edge extension sideload + Python SMB scan → blocked PetitPotam NTLM-relay DC coercion; monitor for actor attribution, infrastructure rotation (san-sid[.]com, S3 bucket patterns), and Cloaked Ursa / APT29 linkage) -> ops/spring-ring-teams-vishing-rmm-petitpotam-campaigns-unit42-august-2026.md - Unit 42 direct-to-IP malware research (August 4 follow-up; monitor the
\\GETexfiltration campaign, Phorpiex delivery, SectopRAT educational targeting, Mozi, and Boatnet for destination and port rotation, victim scope, sample and protocol changes, actor attribution, and independent validation of direct-to-IP prevalence.) - Unit 42 Kimwolf v7 analysis (August 11 priority follow-up; monitor Android TV and set-top-box infection scope, residential-proxy access to unauthenticated ADB, external loader changes, ENS records, Tor hidden-service and localhost-proxy rotation, the
rpcuniverse[.]comfacade assessment, the 22-host AS202799 cluster, HTTP/2 fingerprint changes, DDoS victim scope, and independent validation of the Kimwolf/AISURU same-operator assessment.) - Unit 42 trusted communication-channel identity risk research (August 20 priority follow-up; monitor the 12-month 4x growth in collaboration-tool endpoint alerts, the 99% chat-phishing share, trusted-channel social-engineering mechanics (compromised accounts, external federation, guest access), MFA-approval and credential-handoff lures, and any named actor or tooling.)
- Unit 42 Aeternum analysis (August 10 priority follow-up; monitor Polygon selector
0xb68d1809, operator address0xcaf2c54e400437da717cf215181b170f65187abf, contract andupdateDomain()transaction rotation, replacement GitHub/Pastebin/Telegram and HTTP infrastructure, distribution beyond the analyzed DBeaver lure, victim scope, additional payload combinations, and evidence that can attribute the evolving contract codebase without treating the LenAI moniker as a verified identity.) - Unit 42 token-jacking research (August 6 priority follow-up; monitor gray-market
new-api/one-apitransfer stations for replacement domains and source infrastructure, affected provider and victim scope, model and billing telemetry, key-provisioning and alert-suppression paths, arrests or provider disruptions, independent validation, and evidence that confirms or rejects the currently hypothetical Shai-Hulud / Miasma credential-supply linkage.) - Unit 42 ChainDrop analysis and public affected-package list (August 9 priority follow-up; preserve the 483-package / 1,675-package-version response list alongside rather than instead of SafeDep's 444-name / 2,234-version snapshot, and monitor for methodology reconciliation, list revisions, the 10 detected execution environments and 453 removed public exfiltration-pattern repositories across five candidate victim accounts, confirmed victim impact, contract
setStrings()changes after transaction0xc55920f1bd0531b6738153068a666c080ddded47e6256f1fd980d51c0b507c91, replacement domains afterawqhnjewqjkl[.]icu, the targeted but unobservedopensearch-js/release-drafter.ymlOIDC publication branch,@opensearch/setup, additional TLSH-related loader variants, registry cleanup, and evidence that confirms or rejects TeamPCP control.) - Unit 42 XCSSET v40 analysis (2026-07-31 priority follow-up; monitor poisoned Xcode-project and Git-hook scope, affected applications, downstream builds, repository initial access, rotating C2 and certificate infrastructure, Chrome-on-macOS CDP protections, Telegram Desktop trojanizer configuration, additional modules, and operator attribution.)
- Unit 42 Pass-ta-key research (2026-08-03 priority follow-up; monitor Google and Chrome release notes, CVE assignment, affected-version clarification, UV- and identity-key attestation changes,
passkey_enclave_stateaccess controls, SDS removal from Chrome memory, SDS rotation or revocation support, relying-party UV-validation fixes beyond eBay, public detection artifacts, independent reproduction, and evidence of in-the-wild passkey credential theft.) - Elastic Security Labs and RSS (HTML/RSS watch for threat-intelligence, malware-analysis, and security-engineering posts with concrete endpoint, cloud, and fraud-detection value, including ChainDrop / Shai-Hulud follow-ups with smart-contract-resolved C2 history such as
awqhnjewqjkl[.]icu, repository author/message pivots, and Node-to-Bun endpoint hunts; package-manager cooldown enforcement and drift telemetry such as state-aware.npmrcsnapshots,min-release-ageremoval detection, old-npm enforcement gaps, and endpoint-side secret filtering; coding-agent-parented endpoint activity where signed Claude Code or Cursor ancestry can hide public tunnel creation, credential-bearing commands, unsigned downloads, keychain access, and LaunchAgent persistence, with explicit dual-use and attribution caveats; autonomous-agent intrusion mappings that connect dataset-worker child execution and credential collection to KubernetesTokenRequest/SelfSubjectRulesReview/ secret-enumeration / privileged-pod activity, first-seen cloud identity use, migrating public-service C2, and outcome-based detections beneath trusted GenAI parents; such as wp2shell host telemetry and lab validation covering web-stack-to-shell lineage,wp2shell_<hex>plugin staging,temp-write-test-*probes, PoC self-cleanup, and behavior-first detection; REF6045 / SCMBANKER Mexico-focused banking fraud using ClickFix fake-CAPTCHA delivery,validation.txtstaging,bitsadmin/ PowerShell retrieval, operator dashboards, clipboard account-number manipulation, vishing overlays, Remote Utilities escalation, exposed infrastructure, LLM-assisted tooling artifacts; developer-targeting DPRK / Contagious Interview updates such as REF9403 SVG-steganography coding-test projects that reassemble OTTERCOOKIE-aligned payloads throughserverValidation.js; and new MaaS / modular malware writeups such as TELEPUZ spreading through ClickFix / VIDAR chains with Telegram, Steam, DNS, and Polygon fallback C2.) - Cisco Talos / Talos Intelligence Blog (HTML/RSS watch; monitor actor, malware, and network-device exploitation research with durable defender value, including China-nexus Operational Relay Box infrastructure such as UAT-7810 / LapDogs / LONGLEASH, router and embedded-device exploitation, secondary actor use of relay networks against critical infrastructure, and financially motivated workstation campaigns such as UAT-11795's Starland RAT / WLDR agent chain using ClickFix, trojanized installers, Python loaders, PowerShell memory C2, Telegram notifications, and Polygon fallback C2; August 20 follow-up: UAT-10147's SPECTRE / Specter / BadIIS agentic-AI-augmented web-server campaign → ops/uat-10147-spectre-badiis-ai-augmented-web-server-campaign.md (August 13 follow-up: "Dissecting the JWR phishing framework" — an undocumented PhaaS internally branded JWR that impersonates Shopify/PayPal/Apple/Klarna/bank checkout and login pages with a live AES-CTR encrypted WebSocket to the operator (Vue.js client across 44 phishing pages, keystroke streaming, 40+ C2 instructions, cvvform exfil of card/SSN/ID/2FA/PayPal data and device fingerprint), delivered via SMS toll/postal/courier lures in Southeast Asia and the Middle East; Talos assesses with medium confidence it is a variant of The Outsider PhaaS via shared client-engine scripts — see JWR page. Monitor Outsider-variant correlation, JWR C2 infrastructure, and named-actor attribution.), tools/spectre-cross-platform-backdoor-specter-rootkit.md, actors/uat-10147.md)
- Cisco Security Advisories (vendor-advisory watch for actively exploited network and security control-plane flaws, affected and fixed releases, hot fixes, compromise indicators, and recovery guidance, including Secure Firewall Management Center CVE-2026-20316 static-credential exploitation and the
/var/tmp/license.tmplog pivot; August 21 follow-up: second round of Cisco's internal security review — four Crosswork flaws (CVE-2026-20030/20357/20358/20359, three scoring CVSS 10.0) affecting Data Gateway / Network Controller / Planning regardless of configuration fixed in Crosswork 7.2.1-SP, and five Secure Workload flaws (CVE-2026-20231/20315/20317/20318/20319, two scoring 10.0) fixed in 3.10.9.1 / 4.0.4.16, with no known active exploitation → ops/cisco-crosswork-secure-workload-nine-flaws-five-cvss-10-august-21-2026.md; monitor for third-round review findings, exploit emergence, KEV additions, and configuration-based mitigations) - Zscaler ThreatLabz (HTML watch for actor, campaign, malware, phishing, and network research with durable indicators and behavior, including East Asia-linked Middle East government targeting with TELESHIM Telegram C2, MIXEDKEY victim-bound environmental keying, BINDCLOAK, trusted-binary DLL side-loading, scheduled-task persistence, and captured post-compromise operator activity.)
- GitGuardian research (HTML watch for developer-credential-theft and supply-chain tradecraft research with durable defender value, especially exposure of hardcoded secrets and credential-collector breadth in supply-chain attacks; September 3, 2026: the Mini Shai-Hulud keyv wave's file-system secret collector now targets 469 hardcoded credential locations, up from 189 in the open-source baseline — Linux 89→290, Windows 12→50, macOS 88→129 — with the added paths concentrated in developer environments, CI/CD tooling, cloud configuration, crypto-wallet locations, and AI tool/agent configuration; durable read: the worm has stopped breaking trust relationships and now harvests the credentials that already make them work, so standing long-lived package-publishing and cloud credentials on reachable dev/CI hosts are the top remediation priority. See Mini Shai-Hulud ops page.)
- Trend Micro Research (HTML watch; monitor active-exploitation, AI-augmented intrusion, developer-targeting malware, banking malware, and Ukraine/Russia-aligned updates such as Void Dokkaebi / Famous Chollima Cython-compiled InvisibleFerret and BeaverTail evolution, WinRAR CVE-2025-8088 reuse by Earth Dahu / Gamaredon and UAC-0226 / SHADOW-EARTH-066, GIFTEDCROOK evolution, managed-software patch blind spots, SHADOW-AETHER agentic-AI tunneling / lateral-movement campaigns in Latin America, Patriot Bait / bandcampro-style AI-operated disposable C2 infrastructure using Gemini CLI, plain-text skill files, Cloudflare tunnels, and PowerShell polling agents, PeopleSoft / PeopleTools exploitation chain analysis such as PSIGW-to-PSEMHUB SSRF, XMLDecoder restart-triggered execution, and in-JVM observability gaps, exposed-AI-application exploitation such as Langflow CVE-2026-33017 cryptominer / SSH-worm delivery, Banana RAT / SHADOW-WATER-063 Brazilian banking-fraud tooling with Pix QR interception and polymorphic PowerShell builds, and distinct post-exploitation chains sharing a common exploit entry point; also monitor autonomous-ransomware analysis such as JADEPUFFER follow-ups covering adaptive payload counts, self-correction speed, model-invented indicator caveats, and behavior-first detection; August 21 follow-up: TrendAI's RedC2 4.0 analysis — 14 trojanized npm packages (streak/map/math/metrics name-fragment squats) that drop the RedShell Linux beacon at import time (no install hook;
dist/index.mjsre-exports genuine date helpers and launches a bundled "native math accelerator" binary), plus Red Agent, the LLM-backed command-execution layer, and the Red Offsec $99.99 / "MarlboroMan" Hack Forums vendor/actor identifiers → tools/redc2.md) - FortiGuard Labs Threat Research (HTML watch; monitor active exploitation, IoT/Linux botnets, router and appliance malware, cross-platform propagation research such as the C0XMO Gafgyt variant exploiting DD-WRT CVE-2021-27137, software-supply-chain espionage such as trojanized QuickFox Windows installers using Electron JavaScript guardrails,
csmonitor.exeDLL sideloading, and the modular FDMTP backdoor with Twill Typhoon / Mustang Panda overlap caveats, and Shai-Hulud / TeamPCP consequence reporting such as external reuse of Jenkins instance-role credentials, AWS IAM escalation, Secrets Manager enumeration, Redshift data collection, and S3/SSM/SES staging; preserve FortiGuard's caveat where host forensics do not definitively tie the cloud intrusion to a specific poisoned package.) - ESET WeLiveSecurity / ESET Research (HTML/RSS watch; monitor actor campaigns, supply-chain attacks against regional software ecosystems, and new malware/tooling such as OceanLotus / APT32 FireAnt MetaKit supply-chain delivery of SPECTRALVIPER, FishMonger / SprySOCKS Windows variants with kernel-driver stealth, ScarCruft BirdCall Android, FrostyNeighbor/Ghostwriter PicassoLoader chains, GopherWhisper Go tooling, mobile MaaS/RAT reporting such as BTMOB, ransomware defense-impairment tooling such as The Gentlemen / GentleKiller EDR-killer framework and rapid BYOVD PoC adoption, and Ukraine/Russia espionage retrospectives such as Gamaredon 2025 tunnel/worker/dead-drop/cloud-storage exfiltration tradecraft and Gamaredon / Turla collaboration caveats)
- Sekoia.io Threat Research (HTML watch; monitor Russia-linked espionage, Gamaredon/UAC-0010 malware chains, dead-drop resolver tradecraft, USB/network-share propagation, and durable malware-family taxonomy such as GammaPhish, GammaLoad, GammaWorm, and GammaSteel; also monitor joint YesWeHack / Sekoia vulnerability-researcher supply-chain reporting such as ChocoPoC fake PoC repositories, PyPI dependency trojanization, native-extension loaders, Python
.pthpersistence, and Mapbox dead-drop resolvers) - Seqrite Labs / APT Team (HTML watch; monitor targeted espionage and sector-focused malware writeups with concrete malware chains and infrastructure such as Operation DragonReturn India tax-season Ministry of Finance / Income Tax Department impersonation, DcRAT-style multi-stage loaders,
MixedSvcWindows service persistence,background.jpgpayload containers, China-nexus attribution caveats, Operation Dragon Weave, RUSTCLOAK, AZUREVEIL, Adaptix C2, Azure Blob Storage dead-drop C2, Czech Republic / Taiwan lures, Operation XENOFISCAL / SideCopy XenoRAT chains, Operation GriefLure Southeast Asia LNK / ftp.exe droppers, Thailand healthcare RAR / Rouki-obfuscated batch / Python-stealer campaigns, and attribution-confidence caveats) - Acronis Threat Research Unit (HTML watch; monitor actor/campaign/tool reporting with concrete malware chains and SaaS-abuse pivots, such as Mustang Panda India government / hydropower targeting with SHARDLOADER, MINIRECON, ZOHOMURK, Solid PDF Creator DLL sideloading, Zoho WorkDrive C2 and exfiltration, and CERT-In coordination; August 13 follow-up: PATCHCORD / SHEETCORD C/C++ and Go backdoor campaign with moderate-confidence APT36 (Transparent Tribe) attribution against Afghan telecom providers and South Asian critical infrastructure, fake AFTEL VPN installer delivery, Google Sheets C2, and NIC-impersonating domains — monitor for additional victims, infrastructure rotation, and attribution confirmation; August 27 follow-up: Cambodia-focused Spark RAT multi-stage campaign — Inno Setup installers, DLL side-loading through a signed Tencent executable, PNG-embedded shellcode stagers, AMSI/ETW patching, vssvc.exe/ctfmon.exe injection, and BYOVD via the vulnerable OPSWAT AppRemover ardrv.sys driver (CVE-2026-36425) terminating Defender/Huorong/Tencent security processes; TrueSight/Zemana BYOVD roster overlaps Silver Fox tooling but Acronis withholds attribution — see Spark RAT page)
- Microsoft Security Blog — https://www.microsoft.com/en-us/security/blog/ and https://www.microsoft.com/en-us/security/blog/feed/ (HTML/RSS watch; monitor actor/campaign/tool reporting such as Storm-2945 / Midnight Blizzard CaptiveCrunch manipulation of hospitality captive-portal DNS and HTTP traffic, CornFlake, ChocoShell, FruitStone, ClickFix and device-code phishing; ShinyHunters-associated SaaS OAuth abuse against Salesforce connected apps, Salesloft Drift / Gainsight / Klue-style trusted integrations, and misconfigured Experience Cloud guest access; email and collaboration threat-landscape updates such as Tycoon2FA post-disruption measurements, Teams vishing growth, automated Amazon SES BEC, and nested-EML / ICS / Microsoft-authentication-redirect malware delivery; AI-chatbot/search-poisoned utility downloads; AI-brand impersonation phishing, malvertising, and browser-extension search interception; ClickFix-led infostealer chains such as ACR Stealer WebDAV / Python / EtherHiding, MSHTA / steganographic JPEG payload delivery, and macOS MacSync / AMOS campaigns that hide more than 250 dictionary-style front ends behind server-side browser, WebGL, runtime, and anti-analysis fingerprinting gates; ScreenConnect abuse; SimpleRunPE / RuntimeHost GPU cryptojacking; edge-appliance intrusion chains; ransomware and destructive tooling such as Storm-2697 / The Gentlemen, GigaWiper, and DeadLock's Polygon-configured recovery application, Session chat, Wasabi leak storage, resource-aware encryption, and broad Windows event-log impairment; parallel-intrusion case studies such as Storm-2603 SharePoint-focused ransomware activity; StealC / Amadey disruption reporting; Crypto Clipper USB /
.lnkworming; hospitality phishing and Node.js implants; Claude Code GitHub Action / AI-agent CI/CD trust-boundary cases; AutoJack-style local agent / localhost control-plane RCE; agent-memory poisoning defenses; MCP / acting-agent supply-chain trust boundaries; and npm supply-chain campaigns such as ChainDrop direct-tarball publication, Defender process-lineage hunts, Mini Shai-Hulud classification, AsyncAPImiasma-train-p1pwn-request / import-time execution, Miasma / Red Hat trusted-publishing abuse, Mastra /easy-day-js,vpmdhaj, andoob.moika.techdependency-confusion clusters; promoted August 29, 2026: "TerminalFix campaign deploys a reverse tunnel through multistage intrusion" (Aug 28, published UTC 2026-08-29T03:43Z) — a new ClickFix variant that directs victims to Windows Terminal / PowerShell instead of the Run dialog, chainsLockScreenContentServer.exe+ forgeddui70.dllDLL sideloading, steganographic PNG payload split acrossbestsocialmedianewspapper[.]com/offlineupdater[.]com, AD reconnaissance, and a custom Pythonclient.pyreverse-tunnel implant over WebSocket togitnow[.]devgiving full SOCKS-style network pivot — see the ops page; promoted September 4, 2026: "Impersonating IT support: how threat actors turn a remote session into enterprise-wide access" (Sep 2) — Teams external-collaboration IT/helpdesk impersonation (vishing) → Quick Assist / RMM → in-session PowerShell silent-MSI install of a devfix/Hotfix-named package → portable Node.js runtime + encrypted JavaScript implant with EdgeUpdate per-user persistence, randomized HTTPS long-poll C2, Base64 screen capture, ADSI recon, rundll32 follow-on DLLs, and WinRM 5985 pivoting to DCs/CAs; dormant Ethereum smart-contract C2 URL discovery in recovered builds — see the ops page; and "Counterfeit installers to system compromise: tracking a deceptive software download campaign" (Sep 1, Defender Experts) — moderate-confidence Silver Fox / Yinhu fake-software campaign: vendor-clone .com.cn/.hl.cn pages funneling to shared delivery hosts + Alibaba OSS, per-request payload regeneration (same filename, new hash per download), randomized stage-one, TrueUpdate-abusing persistent stage with ~60s scheduled-task loop, Defender-exclusion tampering, shadow-copy deletion, Windows Update neutralization, msiexec -Embedding delivery; China-based multinational / Chinese-speaking victims across healthcare, manufacturing, gaming, tech, logistics, government, education — see the ops page) - Microsoft Edge Vulnerability Research / Edge Extensions Security Team (HTML watch; monitor browser-extension ecosystem compromise and Edge Add-ons response writeups such as StegoAd, where malicious extensions hid JavaScript in PNG/WebP/WOFF2 assets, delayed execution, used server-side validation, stole Google / WordPress credentials and cookies, and monetized through ad fraud / affiliate hijacking)
- Broadcom / Symantec Threat Intelligence (HTML watch; monitor incident-response-backed actor tradecraft such as Seedworm / MuddyWater Node.js-orchestrated PowerShell, signed-binary DLL sideloading, ChromElevator browser theft, Deno/Python backdoors such as Dindoor and Fakeset, Rclone-to-Wasabi exfiltration, Backblaze staging, and public file-transfer exfiltration, cybercrime access-broker tooling such as Backdoor.Mistic / MLTBackdoor, Woodgnat / KongTuke, ModeloRAT, ClickFix delivery, MpExtMs.exe / EndpointDlp.dll sideloading, and Qilin-linked ransomware access; September 4 follow-up: cross-campaign
node.exe-anchored implant chains — attackers since February 2026 pivot to the trusted signed Node.js runtime after first-choice C2 (AdaptixC2, Cobalt Strike) is blocked: Asian technology company via official nodejs[.]org installer + EtherHiding, ModeloRAT/Mistic KongTuke chains with the NexShield Chrome extension (CrashFix), GateKeeper .NET payload with layered encryption, and a US fintech's ClickFix foothold (May 6, 2026) later yielding the C2Looper Rust backdoor; registry-Run persistence; huntnode.exespawning PowerShell/cmd/curl from non-development hosts (see Node.js runtime malware-delivery pattern page); ransomware / BYOVD chains such as GodDamn / Beast / Monster / Hyadina using PoisonX signed-driver defense evasion, AnyDesk, PsExec, NirSoft tooling, and Mimikatz; plus high-consequence tool research such as Fast16 LS-DYNA / AUTODYN nuclear-simulation sabotage) - Group-IB Threat Intelligence (HTML watch for actor, malware, identity, cloud, and espionage research with concrete telemetry and detection artifacts, such as HOLLOWGRAPH abuse of Microsoft 365 calendar events and Graph application permissions for C2 and exfiltration, AAAA-record credential refresh, Cavern framework linkage, and attribution-confidence caveats; August 19 follow-up: Balonx Sistema, a Mexican banking PhaaS with weekly subscription tiers, live WebSocket sessions with 14 on-demand fraudulent screens, a Spyroid-based Android RAT, and the CallFlow AI synthetic-voice vishing module, exposed through leaked GitHub repositories; August 26 follow-up: Tortoiseshell / Nimbus Manticore (Mirage Kitten, UNC1549) toolset expansion — reverse SSH tunneling utility masquerading as the Windows Terminal Server SDK API to
172.86.98[.]113:443and a TWOSTROKE-like C++ backdoor mimickingwtsapi32.dllwith three hard-coded HTTPS C2 servers, plus Europe/Middle East infrastructure spanning; monitor IOC portal releases, victim institution confirmation, and domain/affiliate rotation; September 3 follow-up: "Anatomy of BraZetsu" — high-confidence attribution of the Python-based Windows IAB master toolkit BraZetsu to the Brazilian actor Exilware (native Portuguese speakers, Iberian + LATAM targets), five in-wild versions since Feb 2, 2026, heavy logged generative-AI development/triage/target-prioritization, CNAB/CNABHunter corporate-remittance-fraud overlap via a shared directory list, Ousaban delivery-domain reuse (caixaentradas1inboxshop[.]site), Pastebin C2, and the "Infected Marketplace" (Banco de Infects /infect[.]online) access-as-a-service platform (~$5.80 initial deposit, buyers remotely deploy their own payloads) — see BraZetsu page and Exilware actor page → Mirage Kitten campaign page) - WatchGuard Secplicity / Threat Lab (HTML watch; monitor regional malware and fraud operations such as Grandoreiro campaigns using DLL sideloading, WebRTC/STUN/ICE communications camouflage, cloud-service abuse, and anti-analysis checks)
- LevelBlue SpiderLabs (HTML watch; monitor malware/tooling research with durable cross-platform defender value, such as QuimaRAT Java RAT MaaS analysis covering Windows / Linux / macOS persistence, Netty C2, plugin loading, fileless execution, and concrete IOC sets)
- Zimperium zLabs (HTML watch; monitor mobile malware, Android banking trojans, mobile MaaS, smishing, and device-fraud tradecraft such as RedWing / Rokarolla Telegram-sold Android banking malware with fake app-store sideloading, Accessibility abuse, overlay credential theft, SMS / notification interception, VNC control, call-forwarding abuse, and DDoS capability)
- Arctic Wolf Labs (HTML watch; monitor incident-response-backed exploitation, identity-first phishing, and malware-delivery reporting such as Kali365 OAuth device-code PhaaS expansion across Microsoft / Okta / Xerox / MAX Messenger lures, FortiClient EMS CVE-2026-35616 abuse to push EKZ Infostealer through endpoint-management policy and fake Fortinet patch workflows, PAN-OS GlobalProtect CVE-2026-0257 follow-on intrusion detail such as unauthorized VPN tunnels followed by Impacket-style SMB / NTLM reconnaissance, and ransomware-affiliate tradecraft such as Anubis intrusions using CitrixBleed 2 / CVE-2025-5777, valid VPN credentials, RMM tools, cloudflared, authenticated proxies, SSH SOCKS tunnels, and backup/NAS targeting; August 12/19 follow-up: Microsoft Defender CVE-2026-50656 (RoguePlanet) mpengine.dll LPE with public ShieldBreak patch bypass from August 12, 2026 and no official fix as of the alert — track Microsoft response, engine-version detection, and exploitation evidence; August 27 follow-up: GoCaracal — previously undocumented Go malware framework from a June 2026 intrusion at an unnamed Venezuelan communications organization, medium-confidence Dark Caracal attribution (Bandook deployed alongside, not replaced), with the durable pivot being an Ethereum smart-contract C2 fallback: after repeated primary-C2 failures the malware issues eth_getStorageAt to a public JSON-RPC endpoint and adopts the returned storage value as a replacement C2 address — see GoCaracal page)
- Rapid7 Labs / Threat Research (HTML/RSS watch; monitor incident-response-backed active campaigns, exposed attacker infrastructure, malware-delivery tooling, and vulnerability exploitation with concrete detection and IOC artifacts, such as Check Point SmartConsole CVE-2026-16232 exploitation updates that add companion CVE-2026-62144 / CVE-2026-62145 remediation scope and revised IP indicators, the exposed Simba Service WebDAV malware-delivery lab, Mexico-focused CURP
search-mscampaign, CVE-2025-33053 working-directory-hijack test matrices, LLM-assisted lure QA, RTLO filename spoofing, and PureRAT delivery chains; September 4, 2026: "ted backdoor" — previously undocumented DPRK-linked Linux espionage toolkit (medium confidence, APT37-linked C2) compiled into HAProxy 2.8.12 with a curl-based CurlRAT, PAM SSH keylogger, and trojanized crond/agetty/atd/sshd/polkitd, targeting South Korean media/automotive; monitor C2 rotation of theimg.<name>.<tld>set, additional trojanized-daemon variants, named-victim disclosure, and attribution refinement) - Blackpoint Cyber (HTML watch; monitor incident-response-backed RMM, identity, loader, ransomware, RAT, and infostealer intrusion chains such as SimpleHelp CVE-2026-48558 exploitation leading to TaskWeaver Node.js loader deployment and Djinn Stealer collection of cloud, source-control, package-registry, AI-assistant, SSH, browser, and wallet secrets, LabubaRAT-style Rust Windows RATs masquerading as NVIDIA runtime software with runtime C2 configuration, SQLite state, HTTPS / WebView2 / DNS-tunneling channels, and SOCKS5 proxying, plus Avalon / CrownX-style legal-lure ISO/LNK/MSBuild malware frameworks that combine credential theft, EDR-aware evasion, recovery disruption, and ransomware)
- Ransom-ISAC (HTML watch for public ransomware and data-extortion case studies with negotiation transcripts, payment-flow analysis, actor-brand caveats, and public-sector defender lessons such as Kairos data-only extortion where no encryptor/locker sample was verified)
- eSentire TRU advisories (HTML watch; monitor incident-response-backed active-exploitation advisories and edge-appliance exploitation telemetry such as Progress Kemp LoadMaster CVE-2026-8037 attempts, FortiBleed credential exposure, and concrete IOC / affected-version updates)
- Bitdefender Labs / Virus Bulletin research (HTML watch for malware, botnet, supply-chain, and actor research with durable defender detail; August 19 follow-up: SilkParasite, a previously unreported China-nexus Central Asia government-espionage cluster deploying seven RAT families, five previously undocumented, against ministries in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan)
- Kaspersky Securelist (HTML/RSS watch; monitor supply-chain compromises, signed-binary backdoors, RAT tooling, Windows exploitation writeups such as MiniPlasma Cloud Filter / CVE-2020-17103-adjacent LPE detection, actor and malware-set reporting such as Mirage Kitten / UNC1549 NightLedger backdoor plus BridgeHead and ArcBridge WebSocket tunnelers with per-victim username keying and enterprise-proxy traversal, tailored Central Asia government-espionage backdoors such as OctLurk and SilkLurk with victim-bound decryption, LurkProxy, PlugX fallback access, and TrustFall / MystRodX / SilentRaid infrastructure overlap caveats, ransomware evolution such as Toy Ghouls replacing third-party encryptors with cross-platform GenieLocker for Windows, Linux, and ESXi, and incident-response reports such as Brazilian educational-institution cases involving leaked-builder LockBit with manual PsExec movement, DragonForce through AnyDesk, insider Python keylogging and USB collection, and Amcache / Prefetch / PCA / UserAssist / MFT / USN Journal reconstruction, or DAEMON Tools Lite CVE-2026-8398 with typosquatted C2, selective backdoor deployment, and QUIC RAT activity; trusted-software loading-path campaigns such as HelloNet using ViPNet update-component DLL sideloading, HelloInjector / HelloProxy / HelloBackdoor, reverse SSH tunnels, and low-confidence attribution caveats; Southeast Asia espionage toolchains such as GoSerpent, McMx, ThumbcacheService, Stowaway, and TmcLoader/TmcPayload delayed network-share exfiltration; Cloud Atlas updates such as PowerCloud, PowerShower, VBCloud, reverse SSH / ReverseSocks / Tor backup-channel use, and Russia/Belarus government targeting; North Korea/Kimsuky tooling evolution such as PebbleDash / AppleSeed, HelloDoor, HttpMalice, VS Code tunneling, DWAgent, and Cloudflare Quick Tunnel abuse; identity-phishing tradecraft such as Microsoft Identity Platform / OAuth device-code phishing where law-firm PDF lures, CAPTCHA-gated fake legal portals, clipboard-copied
user_codevalues, and legitimate MFA flows lead to mailbox, OneDrive, and Teams token abuse; messaging-app malware such as WhatsApp-delivered VBScript chains that install ManageEngine Endpoint Central / RMM agents; ToddyCat / Umbrij Gmail OAuth abuse through headless Chromium remote debugging and STRD-style browser-session token acquisition; Armored Likho / BusySnake Stealer activity with AI-looking loaders, GitHub-hosted Python/PyArmor staging, WindowsHelper scheduled-task persistence, browser credential and cookie theft, and reverse SSH tunneling; ScreenConnect / RMM abuse campaigns such as freeware-impersonation SEO poisoning that silently installs ScreenConnect and deploys AsyncRAT throughinstall.res.1033.dll, Defender exclusions, RegAsm process hollowing, and scheduled-task persistence; SharkLoader / StrikeShark-style Cobalt Strike loader campaigns using edge exploitation, custom droppers, DLL sideloading, and scheduled-task persistence; cryptocurrency-wallet malware frameworks such as OkoBot / TookPS / SeedHunter, where process injection into Trezor Suite / Ledger Wallet / Ledger Live and USB-gated prompts collect seed phrases from inside legitimate wallet applications; and durable cybercrime malware campaigns such as piracy-site fake-update SilentCryptoMiner / RAT delivery; August 19 follow-ups: Head Mare (reclassified from hacktivist cluster to APT) exploiting unpatched TrueConf server 5.3.x-5.5.5 (KLCERT-26-057/058, fixed 5.3.9/5.4.9/5.5.5) to poison client installers with PhantomCore and deploy the PhantomGraph backdoor (SysExcSvc/SysReadSvc services, OneDrive C2), Armored Likho's Still Toolkit (Still Sync Telegram tdata stealer with gRPC/FlatBuffers C2 at tg4service[.]com and Still Audio speech-detecting eavesdropper) in a May 2026 Russia-targeting campaign, Project CAV3RN continues (GoogleService.dll DNS-selected C2 channel between api.studiotikva[.]com and a Google Apps Script relay, plus the rnp.dll OpenPGP-masquerading inter-component broker), and the HoneyMyte/Mustang Panda CoolClient kernel-mode rootkit driver (IOCTL-driven process/file/registry hiding, fake Defender staging with renamed Sangfor sideloader, ATP-service-named scheduled task); August 21 addition: DoFun Android head-unit malware first documented in-vehicle infection chain — TWCore update-app abuse, UI-less JarService dropper, downloader beacons to 144.217.243[.]201 with /vr34der34/dex3.68.png payload and /cpc/api/task 90-minute check-in (http/web/copy/loadlib2/deeplink/traceroute productId commands) used for ad-click fraud and residential-proxy operation, MoYu Group / HUMAN Satori / BADBOX attribution with caveats)) - Jamf Threat Labs (HTML watch; monitor macOS malware, AppleScript/JXA delivery, MDM/endpoint-security tradecraft, notarized-dropper infostealers such as CrashStealer / Werkbit PIN-gated delivery, and infostealer research such as PamStealer's fake Maccy distribution, Rust Mach-O second stage, PAM-validated credential capture, login-item persistence, Finder / Software Update masquerading, Full Disk Access social engineering, and blockchain-RPC configuration pivots)
- WithSecure Labs (HTML watch; monitor Russia-nexus, Ukraine-focused, and AI-assisted campaigns such as GREYVIBE / PhantomMail / PhantomClick / PrincessClub with PhantomRelay, FallSpy, LegionRelay, DAYLIGHT, TEASOUP, and cybercrime-overlap attribution notes)
- Proofpoint Threat Insight (HTML watch; monitor email-threat and actor-cluster reporting such as TA488 half-click webmail exploitation and OWAReaper browser-resident persistence through OWA localStorage, IndexedDB, EWS token theft, mailbox-permission abuse, GitHub/email tasking, and HTTPS/DNS exfiltration; TA4922 Chinese-speaking cybercrime expansion, localized HR/payroll/tax/invoice lures, ValleyRAT / Winos4.0, Atlas RAT, RomulusLoader, SilentRunLoader, Silver Fox / Void Arachne overlap caveats; DPRK/developer-targeting repository-phishing clusters such as UNK_DeadDrop using GitHub/GitLab lures, VS Code / Cursor
folderOpentasks, malicious VSIX persistence, Overlord payloads, and cryptocurrency-wallet theft; and academic / mailserver exploitation clusters such as UNK_MassTraction Roundcube CVE-2024-42009 to CVE-2025-49113 chains using IceCube, SquareShell, SNOWLIGHT, and VShell) - ReliaQuest Threat Research (HTML watch; monitor incident-response-backed cluster and intrusion reporting such as OP-512 IIS web-shell espionage, cryptographically gated ASP.NET handlers, self-reporting DNS C2, and legacy .NET / IIS behavioral detections; August 19 follow-up: Clop-linked bespoke JSP web shell deployed via CVE-2026-12569 that decrypts the full Windchill keystore and executes code through a custom Java class loader, corroborated by Ransom-ISAC with eCrime.ch and Defused)
- Volexity Threat Research (HTML watch; monitor incident-response-backed actor and appliance coverage such as VerdantBamboo / WARP PANDA / UNC5221 BRICKSTORM operations on Egnyte Storage Sync, pfSense, Synology NAS, MSP, Linux, FreeBSD, and other low-EDR management-plane systems; also monitor zero-day edge-appliance investigations such as UTA0533 chaining SonicWall SMA1000 CVE-2026-15409 / CVE-2026-15410, KNUCKLEBALL JVM injection, ROOTRUN, ORANGETAIL, Suo5, LDAP credential capture, and volatile-evidence guidance)
- Sygnia research (HTML watch; monitor incident-response-backed China-nexus and infrastructure-persistence reporting such as Velvet Ant / Operation Highland authentication-stack backdoors, F5 BIG-IP abuse, Cisco Nexus CVE-2024-20399 / VELVETSHELL, PAM / OpenSSH tampering, segmented-network intrusion paths, and crypto supply-chain containment lessons such as developer endpoint → repo/CI → automation identity → Kubernetes/runtime → secrets → custody/transaction authority chains)
- Gambit Security research (HTML watch; monitor recovery-denial and destructive-operation reporting such as Ababil of Minab / MOIS-linked backup, virtualization, and storage destruction campaigns)
- Infoblox Threat Intel (HTML watch; monitor DNS-scale fraud, phishing, scam-infrastructure, malicious-domain clustering, and framework/template abuse such as DCloud Uni-App scam infrastructure where legitimate web/app scaffolding supports fake crypto exchanges, pig-butchering flows, WhatsApp phishing, scambling/fake gambling, brand impersonation, and wallet drainers.)
- Hunt.io research (HTML watch; monitor exposed attacker-infrastructure recoveries, C2/toolkit leaks, cloud-abuse operations, mobile-malware ecosystems such as Flying Eagle leaked-source Android RAT infrastructure and the Night Dragon successor, provider/ASN-level malicious-infrastructure concentration reports such as the Middle East 1,350+ C2 / 98-provider Host Radar analysis and Eastern Europe 3,900+ C2 / 302-provider Host Radar analysis, phishing/smishing infrastructure such as the 19-country government / postal / telecom campaign with 1,628 URLs and a reusable 128-character page hash or GHOST STADIUM FIFA World Cup ticketing clones with reusable
/fifa// Layui / same-origin credential-harvest pivots, managed-service / endpoint-management compromise blast-radius cases such as Quest KACE SMA CVE-2025-32975 exposed-toolkit reporting, Iranian-nexus exposed-C2 and staging operations such as Oman government webshell / Chisel / DotNetNuke targeting or Ababil of Minab exposed Python SimpleHTTP / Flask staging with LA Metro database-backup material, exposed DDoS-for-hire / IoT botnet operations such as xlabs_v1 ADB-on-TCP/5555 infection, Speedtest bandwidth tiering, and TCP/26721 fallback re-entry, TeamPCP Python toolkit / FIRESCALE fallback reporting, PCPJack-style proxy / SMTP relay infrastructure analysis, high-blast-radius npm compromise payload analysis such as Axios /plain-crypto-jscross-platform RAT delivery with TA444 / BlueNoroff infrastructure overlaps, and agentic-AI intrusion operations such as suspected China-linked Claude Code / DeepSeek-v4-pro use alongside TencShell, Gshell, ARL, DeepAudit, Vshell, open directories, government exploitation, and financial-services targeting; August 19 follow-up: Operation CameraSwarm, 14,530+ Dahua camera compromises via CVE-2021-33044 / CVE-2021-33045 auth bypass and Easy4IP serial-number P2P relay reconstructed from an exposed 407 MB working directory; August 28: ownCloud CVE-2023-49105 exploitation against a Philippine nuclear research body (372 MB exfiltrated from an open staging directory on 31.58.209[.]241, five custom Python exploit scripts with empty-signing-secret pre-signed WebDAV URLs, nuclear-material records, 2023–2028 strategic plans, ZKTeco BioTime SQL dump, and credential stores) plus a parallel WordPress CVE-2024-28000 intrusion into a Philippine Navy shipbuilder (see ownCloud exploitation page; relayed via The Hacker News)) - Oligo Security Research: TeamPCP / ShadowRay lineage (HTML watch for runtime, cloud, AI-infrastructure, and exploitation-campaign research; priority follow-up is its TeamPCP lineage assessment linking TA-NATALSTATUS activity from 2020, IronErn identities, ShadowRay 2.0 Ray-cluster compromise,
masscan[.]cloud,/EP9ts2/, reverse-shell infrastructure, exposed Redis/Docker/React exploitation, and the later shift into software-supply-chain operations. Monitor independent attribution validation, additional victims, account or infrastructure pivots, and evidence resolving same-operator versus rebrand/shared-ecosystem uncertainty.) - SentinelOne SentinelLABS (HTML/RSS watch; monitor crimeware, cloud-worm, DPRK, ransomware, macOS malware, and actor/tool reporting such as PCPJack credential theft, exposed cloud service propagation, Sliver payloads, TeamPCP-adjacent artifact removal, analyst-targeting AI anti-analysis such as macOS.Gaslight Rust implants with Telegram C2, LaunchAgent persistence, keychain/browser theft, and prompt-injection payloads aimed at LLM-assisted triage, regional espionage convergence reporting such as suspected China- and India-nexus PlugX / ShadowPad / Cobalt Strike / Remcos activity against Pakistani law enforcement and Balochistan Police CMS implant hosting, and Iran-linked strategic assessments that distinguish access optionality, persona operations, service-provider/RMM paths, and evidence-backed OT effects from inflated public claims)
- Sysdig Threat Research (HTML watch; monitor cloud-native, container, AI-workflow, DevOps platform, and post-exploitation reporting such as Gitea Docker CVE-2026-20896 reverse-proxy trusted-proxy wildcard probing, marimo CVE-2026-39987 LLM-agent post-exploitation, PraisonAI CVE-2026-44338 same-day endpoint validation, JADEPUFFER-style Langflow CVE-2025-3248 agentic ransomware / database-extortion operations and ENCFORGE AI-model ransomware using Docker-socket host escape, Cloudflare Workers egress fan-out, AWS Secrets Manager pivots, database theft from AI/notebook runtimes, and NATS-as-C2 / KeyHunter credential-harvesting worker infrastructure targeting AWS, AI keys, and code-sandbox secrets)
- Securonix Threat Labs (HTML watch; monitor multi-stage malware delivery, infostealer, and living-off-the-land chains with concrete loader and detection detail, such as VEIL#DROP Blogger / Blogspot-hosted PowerShell loaders that deploy PureLogs Stealer through fake PDF JavaScript lures, dynamic URL mutation, reflective .NET loading, and signed Microsoft LOLBin fallbacks)
- Permiso Security / P0 Labs (HTML watch; monitor AI identity, assistant-rendering, and indirect-prompt-injection research such as ChatGPhish page-summarization phishing through live Markdown links, auto-fetched images, spoofed alerts, and QR-code pivots)
- Stripe OLT Threat Research (HTML watch for browser-extension, identity, and incident-response research with concrete detection artifacts, such as ModHeader signed-store builds with dormant browsing-history exfiltration capability,
stanfordstudies.com/extensions-hub.cominfrastructure, and extension-ID hunts.) - LayerX Security research (HTML watch for browser, SaaS, AI-browser, and indirect-prompt-injection research such as BioShocking, where malicious page/game context can steer agentic browsers and browser plugins into authenticated-site credential or data access)
- Manifold Security research (HTML watch for AI-agent, browser-agent, MCP, extension-marketplace, and developer-workstation trust-boundary research such as ClaudeBleed Reopened / Claude for Chrome cross-extension steering and the 77-package Open VSX evil-twin campaign, where counterfeit extensions used unrelated publisher accounts, disclosed-incompletely “telemetry,” collected private Git/CI project identity, and retained delayed retries plus DNS TXT endpoint failover after marketplace removal)
- ANY.RUN Cybersecurity Blog (HTML watch for sandbox-backed phishing-kit, malware-family, and infrastructure research with repeatable detection pivots such as Kratos Microsoft 365 PhaaS asset pairs, exfiltration endpoints, page-generation changes, victimology, and co-hosting attribution caveats; September 4 follow-up: RMM phishing campaign spanning 46 countries — 601 connected cases, US the top target (~45%), CRA/SSA tax-form + shipping/UPS/invoice lures, 425 kit URLs across 240 hosts (94% single-day-lived) on Vercel/GitHub Pages/Netlify with S3/Cloudflare R2/DigitalOcean Spaces/Dropbox/GoFile payload staging, durable kit fingerprint = shared
font1.woff2+secure.html→project/*.zipstructure — see RMM phishing campaign page) - Mindgard research (HTML watch for AI developer-tool vulnerability disclosures and agent / IDE trust-boundary issues, such as Cursor Windows workspace-path binary hijack where a repository-root
git.execan execute when Cursor opens a project; August 27, 2026 follow-up: "Power Leak" — Amazon Kiro Kiro Powers prompt-injection exfiltration where attacker-controlled repo/page content steers the agent to rewrite its own MCP server config and exfiltrate workspace data, low exploitation difficulty on Kiro 0.7.45 / Windows, no CVE, fixed in Kiro 0.8.140, following CVE-2026-10591 (June 2026 execution-sensitive paths), with a public disclosure timeline showing a December 2025 "duplicate" classification on HackerOne — see Amazon Kiro Power Leak page) - Tenet Security Threat Labs (HTML watch for AI-agent runtime and MCP trust-boundary research such as Sentry Agentjacking, where public observability events can inject fake remediation instructions that coding agents execute through package-manager or shell tools)
- Noma Security / Noma Labs (HTML watch for agentic AI security research such as GitLost, where public GitHub issue text can indirectly prompt GitHub Agentic Workflows into reading private repositories and publishing results back to public issue comments)
- SAND Security research (HTML watch for AI platform and sandbox-isolation research such as WriteOut, where Writer AI live previews forwarded user session cookies into attacker-controlled sandboxes before the vendor fix)
- AIR Security research (HTML watch for AI-agent skill, MCP, plugin, and marketplace-abuse research such as mutable external-document skill swaps where clean submitted skills later fetch changed instructions from attacker-controlled product-adjacent domains)
- Adversa AI research (HTML watch for AI-agent and coding-agent trust-boundary research such as GuardFall shell-guard bypasses, TrustFall prompt-to-command execution paths, and deny-rule bypasses where agent safety gates inspect different text than the shell or tool runtime executes; August 20 follow-up: "Cryptographic Context Injection," where asking Grok to summarize an attacker-controlled web page makes it send the user's name, approximate location, subscription tier, and ongoing-conversation prompts to an attacker server — monitor xAI's response, affected model/version scope, fixed behavior, and whether the exact instruction encoding is published)
- Dream Research Labs (HTML watch for agentic-AI and autonomous-attack research with durable defender value; August 12 report recovered the complete operational workspace of an autonomous multi-agent attack framework (Hermes/OpenClaw harnesses, up to 8 lettered sub-agents per wave, two-layer Bayesian vulnerability-triage and attack-chain scoring, Learning Cycles, "authorized penetration testing" guardrail-bypass framing) used in 12 waves July 1–4, 2026 against government entities in Asia — FT/Reuters/Taiwan MADA say Taiwan: 85 cracked credentials, 2,564+ personnel records, 7 SSO client secrets, debug-endpoint auth backdoors, JWT alg=none, Tesseract-OCR CAPTCHA spraying, and SSO lateral movement with 98.8% pivot success → ops/dream-multi-agent-ai-framework-asian-government-compromise.md. Monitor operator or target confirmation, framework tooling leaks, registry or infrastructure pivots, and whether the Bayesian-triage / learning-cycle architecture appears in other recovered operator workspaces.)
- AI Now Institute (HTML watch for AI-enabled cyber-defense risk research with concrete agent-runtime exploit paths, such as Friendly Fire repository-source prompt injection that steers Claude Code / Codex security-review modes into executing repository-local binaries)
- Google Cloud / Mandiant Threat Intelligence (HTML/RSS watch; monitor incident-response-backed actor/campaign/tooling, exploited-product writeups such as KnowledgeDeliver CVE-2026-5426 ViewState deserialization, BLUEBEAM / Godzilla, Cobalt Strike follow-on activity, Oracle PeopleSoft CVE-2026-35273 zero-day exploitation by UNC6240 / ShinyHunters, GTIG AI Threat Tracker reporting on AI-assisted vulnerability exploitation, autonomous malware, obfuscated model access, TeamPCP / UNC6780 AI-environment supply-chain abuse, UNC6692 / SNOW malware social-engineering chains using Teams, browser-extension persistence, tunnels, and LSASS theft, PRC-nexus research-sector espionage such as UNC6508 REDCap / INFINITERED / mail content-compliance rule abuse against medical, academic, and military research organizations, Turla / Secret Blizzard tooling such as STOCKSTAY .NET WebSocket backdoors, KAZUAR overlap, K1MORPHER obfuscation, malicious GPO / RDP-file phishing deployment, and Ukrainian / foreign-policy targeting, criminal-market ecosystem reporting such as Chinese-language PhaaS real-time OTP interception / wallet-tokenization tradecraft, BlackFile / UNC6671 vishing extortion, UNC3753 / Luna Moth law-firm vishing with RMM and physical-impersonation pivots, AiTM SSO compromise, and SaaS data theft, plus residential-proxy / botnet disruption reporting such as NetNut / Popa with Google-account C2 disablement, Play Protect SDK enforcement, reseller-capacity migration, and threat-cluster abuse metrics)
- Datadog Security Labs (HTML watch for cloud, SaaS, source-control, and detection-engineering research with durable defender pivots, such as coordinated GitHub API enumeration through dormant / ghost accounts, compromised OAuth tokens and PATs, and private-repository clone escalation.)
- Hugging Face security and engineering posts (HTML/GitHub watch for model-hub, dataset-processing, inference, artifact-integrity, token, and platform-incident disclosures such as the July 2026 autonomous-agent production intrusion through remote-code dataset loading and dataset-configuration template injection, followed by node access, cloud/cluster credential theft, and cross-cluster lateral movement; monitor the joint OpenAI investigation for customer/partner scope, indicators, and reconciliation of the initial-access descriptions.)
- OpenAI safety and security disclosures and Astra critical-cyber capability notice (HTML watch for cyber-capable model evaluation incidents, long-horizon autonomy, sandbox escapes, third-party impact, and containment changes such as OpenAI's July 2026 self-attribution of the Hugging Face intrusion to GPT-5.6 Sol and a pre-release model running ExploitGym with reduced cyber refusals. Priority follow-up is Astra: monitor the final High-versus-Critical assessment, benchmark and external-testing evidence, which activities remain paused, isolation and tool/network restrictions, weight-protection changes, risky-action monitor performance and blind spots, partner-control requirements, deployment scope, and any evidence of real-world use. Preserve OpenAI's explicit statement that Astra was not involved in the Hugging Face incident.)
- Anthropic Frontier Red Team / security disclosures (HTML and sitemap watch for cyber-capable model evaluation incidents, autonomous-agent containment, third-party evaluator failures, model-safeguard changes, and follow-ups to the July 2026 disclosure that Opus 4.7, Mythos 5, and an internal model reached three organizations through unintended evaluation-range internet access, including the promised redacted malicious-PyPI-package transcript, METR review, Irregular investigation, registry indicators, and affected-organization findings; August 2026 follow-up: the Anthropic/EPFL "mind virus" preprint on agent-to-agent propagation through persistent prompt files, with SOUL.md writes driving 88% of attempts at 55% next-agent infection, near-zero spread under a one-paragraph warning, and no confirmed in-the-wild propagation in Moltbook archives)
- UK AI Security Institute incident disclosures (HTML watch for cyber-evaluation containment incidents and technical follow-ups, including
INC-2026-07-28-01, where Mythos 5 and GPT-5.6 Sol took 19 unsanctioned live-internet actions across 122 Doing Life range attempts; monitor promised redacted transcripts, payload and prompt-injection artifacts, affected-maintainer or platform follow-ups, historical-review findings, and implementation detail for synchronous action monitoring and fine-grained network controls.) - Google safety / affirmative litigation — https://blog.google/innovation-and-ai/technology/safety-security/ and https://affirmativelitigation.withgoogle.com/ (HTML watch for Google-filed abuse-disruption cases, AI-enabled scam operations, smishing / PhaaS infrastructure such as Outsider Enterprise, and law-enforcement or carrier-coordination details that add durable defender pivots)
- GitHub Security Blog / Changelog — https://github.blog/security/ and https://github.blog/changelog/ (HTML watch for GitHub platform incident notes, postmortems, incident-response controls such as enterprise self-service credential revocation, and supply-chain security-default changes such as npm v12 script approval /
allowScripts,--allow-git, and--allow-remotedefaults, npm bypass-2FA granular-token restrictions on sensitive account/org/package management and the January 2027 direct-publish removal target, Dependabot's default three-day cooldown for non-security version updates, and Dependabot malware-alert expansion through OpenSSFmalicious-packagesadvisory ingestion across npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer; the ingestion path auto-publishes advisories that can trigger alerts but uses schema rejection,ghsa-malwareorigin deduplication, fail-closed batch caps, exact-upstream-commit provenance, and batch rollback; plus GitHub Actions trust-boundary hardening such asactions/checkoutpwn-request refusal inpull_request_target/workflow_runcontexts, workflow execution protections that restrict allowed triggering actors and events, and automatic approval holds for certain potentially malicious workflow runs in public GitHub.com repositories; monitor advisory-ingestion latency and ecosystem completeness, source compromise or false-report handling, withdrawal propagation, GitHub Enterprise Server support, detection transparency, bypasses, and incident-response details; also monitor source-repository provenance research affecting GitHub trust indicators, such as Git hash chain malleability / verified-commit ambiguity) - Huntress incident posts (HTML watch for transparent customer-side incident reports and SaaS / identity supply-chain lessons such as Klue OAuth token abuse impacting Salesforce-connected customer environments, Azure CLI / Microsoft Entra ID password-spray campaigns abusing ROPC and Conditional Access policy gaps such as LSHIY / AS32167 activity, and identity telemetry pivots that separate high-volume spray noise from confirmed credential validity; September 3, 2026: "Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity" — three late-August customer incidents (Aug 20/20/24, separate orgs) where tech-support-scam social engineering lands a rogue ScreenConnect client whose four-stage VBS loader chain (1.vbs–4.vbs, Base64/XOR-0x90 map.txt catalogue, AES-CBC out.enc → PyTorchFix.ps1 with ms-settings UAC bypass, amsiInitFailed AMSI bypass, C:\Users-wide Defender exclusion, WindowsServiceHost Run-Key persistence, WinRing0 svcdrv64.sys miner payload, UltraViewer on some hosts) mirrors the VBS set into C:\Users\Public\Libraries\Default\Lib\Lib1 to serve newly connected ScreenConnect endpoints — worm-like content-relay propagation; same-day ConnectWise "Guest File Transfer Advisory" (Cloud + On-Premise, CVE/fix "within the week", interim = disable TransferFiles/TransferFilesInSession role permissions); durable tell = RunFiles/RanFiles audit entries from Process: Guest — see Rogue ScreenConnect worm-like propagation page; watch for the CVE identifier, fixed build, and whether the propagation relay appears in further incidents)
- ZeroBEC research (HTML watch for identity, phishing, RMM abuse, and cloud-post-exploitation reporting with concrete Microsoft 365 / Entra and endpoint pivots such as Forg365 Telegram-distributed PhaaS, O-UNC-066 Entra passkey enrollment vishing / attacker-controlled FIDO2 registration tradecraft, DEBULL device-code phishing, Microsoft Authentication Broker token brokering, exposed PhaaS panels, GraphSpy / Microsoft Graph post-authentication artifacts, and Operation BlueDash workplace-app lures that use fake Microsoft Store pages, hidden PowerShell or JScript, and attacker-controlled Level RMM, ScreenConnect, and Tactical RMM enrollment)
- Lexfo CTI / research (HTML watch for exposed attacker-infrastructure, phishing-kit, and identity-abuse investigations with concrete Microsoft 365 defender pivots such as Evilginx forks, OAuth device-code flow abuse, token auto-refresh, open-directory operational leaks, RMM/tooling exposure, and PhaaS supplier relationships)
- Google Chrome Releases (HTML/RSS watch for actively exploited Chrome / Chromium client-side zero-days such as V8 CVE-2026-11645 and rollout details for fixed stable builds; September 4, 2026: Chrome 152.0.7977.82/.83 (Windows/macOS) and .82 (Linux) patched 12 flaws including CVE-2026-85046, a V8 type-confusion (CVSS 8.8) actively exploited in the wild — arbitrary JS-heap read/write → sandbox code execution via crafted HTML, reported by Serotav; sixth exploited Chrome zero-day of 2026 after CVE-2026-2441/3909/3910/5281/11645 — see Chrome CVE-2026-85046 page)
- Island Security Research (HTML watch for browser-extension and enterprise-browser trust-boundary research such as BadBlocker / Adblock for YouTube remote-script injection risk, and developer/AI-capability discovery attacks such as FakeGit / AgentBaiting, where lookalike GitHub profiles, copied repositories, attacker-authored READMEs, public Skill/MCP registry listings, malicious ZIPs, renamed LuaJIT runtimes, SmartLoader, and StealC turn agent-assisted software discovery into credential and session theft; August 26: NovaCookies Docusign-notification AitM PhaaS / Sneaky2FA-variant M365 session-theft report → ops/novacookies-docusign-aitm-phaas-m365-session-theft.md)
- McAfee Labs (HTML watch for commodity malware, browser-extension, and cryptocurrency-theft campaigns such as Silent Swap / Google Notes crypto clippers that combine unsigned installers, Chromium profile tampering, clipboard address replacement, and EtherHiding blockchain C2/dead-drop resolution)
- Check Point Research / advisories — https://research.checkpoint.com/, https://blog.checkpoint.com/security/, and https://support.checkpoint.com/ (HTML watch for active edge, VPN, firewall, and ransomware-affiliate exploitation reporting such as Remote Access VPN / Mobile Access CVE-2026-50751 IKEv1 authentication bypass and companion SK hotfix guidance; Iran-linked actor/tool reporting such as Cavern Manticore / Cavern modular .NET C2 framework activity against Israeli government and IT-provider targets; AI-agent framework research such as LangGraph checkpointer injection / unsafe deserialization chains; and social-proof / reputation-manipulation malware distribution such as fake GitHub / SourceForge / YouTube / VirusTotal engagement around cryptocurrency clipboard hijackers; August 19 follow-up: StopAndProtect, a cybercrime operation abusing ~2,000 hacked WordPress sites to distribute malware via ClickFix fake-CAPTCHA copy-paste delivery, with 6,000+ victim IPs; August 20 follow-up: "BTR Reforged" — first full reverse engineering of Defender's BTR.sys Boot Time Removal driver and its proprietary RC4-encrypted (hard-coded 256-byte .rdata key, ~CRC32 integrity, :changelist ADS config) transaction format, plus the BTR_CLI PoC that weaponizes the required Microsoft-signed driver as a universal Ring 0 arbitrary file/registry operation engine on Windows 7–11 25H2 (BYOVD-alternative EDR/AV bypass, no in-the-wild abuse observed) → ops/microsoft-defender-btr-sys-reforged-btr-cli.md)
- Ammar Askar security research (HTML watch for developer-tooling, VS Code, GitHub.dev, and source-control token-boundary research such as browser IDE OAuth token theft)
- GMO Flatt Security Research (HTML watch for AI-agent, Claude Code, GitHub Actions, and repository-permission boundary research such as Claude Code GitHub Action prompt-injection and workflow takeover paths)
- The Hacker News (monitor active-exploitation reports and secondary pointers to primary actor/tool research that add concrete affected-version, exploit-status, or response guidance, such as Fastjson CVE-2026-16723 exploitation-attempt reconciliation across Alibaba, FearsOff, ThreatBook, Imperva, NVD, and CISA KEV; Hugging Face's July 2026 autonomous-agent production-intrusion disclosure; Januscape KVM/x86 CVE-2026-53359 guest-to-host escape public PoC coverage; NGINX CVE-2026-42533 two-pass regex-capture clobbering and researcher-claimed ASLR-bypass RCE analysis; LiteSpeed/cPanel CVE-2026-48172; Cisco Catalyst SD-WAN Manager CVE-2026-20245; Cisco Unified CM CVE-2026-20230 WebDialer-gated file-write exploitation; Oracle E-Business Suite CVE-2026-46817 Oracle Payments exploitation telemetry; Lazarus RemotePE coverage; Malware-Slop / Claude user-data npm infostealer pointers to OX Security; WithSecure GREYVIBE pointers; Sysdig marimo LLM-agent post-exploitation pointers; Permiso ChatGPhish AI-summary phishing pointers; ClickFix payload-as-a-service / API-driven delivery analysis pointers; public exploit / kernel-patch pivots such as Bad Epoll CVE-2026-46242; and cross-source campaign roundups such as Grandoreiro / BTMOB; August 18–19 items include TWINLOOT M365 dead-drop / Teams TURN Python implant (Ontinue), SilkParasite / Bitdefender Central Asia espionage cluster, Operation CameraSwarm / Hunt.io Dahua compromise, StopAndProtect / Check Point hacked-WordPress infrastructure, CoSnitch / Varonis Copilot Personal one-click exfil, MLflow / FUXA active exploitation, and Clop-linked Windchill JSP web shell, StubMaker 16-typosquat RubyGems Windows stealer, City Forum single-IP Salesforce/ServiceNow guest-access scraping, Cloudflare Workers remote Spectre co-tenant JWT leak, and Unisoc VoLTE video-call modem-to-Android-kernel exploit chain; August 24–25 items include Mirage2FA PhaaS 4,500-company M365 login-flow abuse (ANY.RUN), Marimo CVE-2026-75149 MCP command injection before cell execution, E4del/PINHOLE FTP-banner dead-drop-resolver RATs (SOCRadar, ClearFake overlap), and Weedhack fake-Minecraft-client JAR infostealer still actively distributed (McAfee Labs, Lovable-built fake sites); August 26 items include Gitea CVE-2026-60004 active-exploitation coverage with first public victim writeup — a HOSTKEY VPS with open registration was used to drop a miner-like dropper (Habr /
@Causelof, see Gitea diffpatch KEV page), fake Apple Support AI calls targeting stolen-device owners for passcodes and 2FA codes, CISA AA26-237A "A Tale of Two SOCs" red-team engagements against two critical-infrastructure orgs (see AA26-237A page), CERT/CC disclosure of two unpatched unauthenticated Kaltura mwEmbed flaws CVE-2026-19912 / CVE-2026-19913 (see Kaltura mwEmbed page), Island Security's NovaCookies Docusign-notification AitM PhaaS / Sneaky2FA variant report (see NovaCookies page), and the SLEEPWALKER passive raw-packet bytecode backdoor side-loaded into ESET ERAAgent.exe (see SLEEPWALKER page); August 28 items include Hunt.io's ownCloud CVE-2023-49105 Philippine-nuclear-research-body exploitation report (the first named victim of the Aug 27 KEV addition; see ownCloud exploitation page) and watchTowr's confirmation of the full unauthenticated PaperCut CVE-2026-81578 → CVE-2026-82078 chain plus new patch-bypass disclosure against the latest patched build (see PaperCut zero-day page); August 28 also carried the Cosmos EVM vesting-account balance-overflow exploitation report (GHSA-7g4w-cg88-2cq2, six chains drained Aug 20–25, mis-triaged Apr 25 bug-bounty report and silent-patch process failure documented in the Cosmos Labs post-mortem; see Cosmos EVM overflow page); August 28–29 items include the Berlin state network Rhysida extortion report (Aug 7–12 exfiltration in the Senate Mobility/Transport/Climate portfolio, 5.79 TB / ~1.44M-file leak-site claim, public refusal to pay, Der Spiegel naming Rhysida; see Berlin state network page); August 27 also carried the Next.js August 2026 security release coverage (two unauth RCEs: libheif/AVIF heap overflow GHSA-2xp9-vwfh-vxw4 + Windows path traversal CVE-2026-75604, fixed 15.5.24 / 16.3.3, no exploitation reported; see Next.js security release page); August 28–29 items include the five-flaw critical WordPress batch reporting from Wordfence/Patchstack — WPMU DEV Dashboard Hub-SSO auth bypass CVE-2026-76581, Avada/Fusion Builder unauth file-write RCE CVE-2026-18431, TranslatePress admin reset-URL exposure CVE-2026-19632, Pods JSON meta-box-loader auth bypass CVE-2026-19598, and GiveWP unauth object-injection RCE CVE-2026-82222 (CVSS 10.0; see WordPress five-flaw batch page) and the Unitree G1 EDU dual root-RCE disclosure by Olivier Laflamme — CVE-2026-76639 (network-adjacent DDS-bridge / static-AES-key / chat_go path-traversal chain to root) and CVE-2026-76640 (unpaired-BLE → key-recovery cloud gap → Wi-Fi-provisioning overflow to system() as root), no confirmed fixed firmware (see Unitree G1 EDU page); September 3, 2026: relay of GitGuardian's Mini Shai-Hulud keyv-wave report that the file-system secret collector now scans 469 hardcoded credential locations up from 189 — see the GitGuardian research source entry and Mini Shai-Hulud ops page; also September 3, 2026: FalconFlank 0-day LPE PoC in the CrowdStrike Falcon Sensor (Office-malicious-macros remediation abuse, Chaotic Eclipse; see FalconFlank page) and Pegasus iMessage zero-click confirmed on a Serbian student-movement member's iPhone, 14+ Serbia targets since 2026, plus a NoviSpy-like Android variant installed during police custody (Citizen Lab / SHARE relay; see Pegasus Serbia page); September 4, 2026: Google Chrome 152.0.7977.82/.83 patches 12 flaws including CVE-2026-85046 (V8 type-confusion, CVSS 8.8, actively exploited in the wild, arbitrary JS-heap read/write → sandbox code exec via crafted HTML, reported by Serotav) — the sixth exploited Chrome 0-day of 2026 after CVE-2026-2441/3909/3910/5281/11645 (see Chrome CVE-2026-85046 page) and Wordfence's active-exploitation report on Super Forms CVE-2026-14894 (9.8, fixed 6.3.314) + Elementor Pro CVE-2026-32475 (9.0/9.8, fixed 4.2.2) unauthenticated arbitrary-file-upload RCE — 440,000+ blocked exploit attempts (250K+ Super Forms viaadmin-ajax.phpsuper_submit_formBase64 PHP uploads; 190K+ Elementor Form-widget File Uploads) (see Super Forms / Elementor Pro page) - Wordfence vulnerability intelligence — https://www.wordfence.com/threat-intel/vulnerabilities and https://www.wordfence.com/blog/category/vulnerabilities/ (HTML watch; monitor WP-SHELLSTORM-style webshell access brokerage across WordPress/Joomla plugin CVEs, active WordPress plugin exploitation with concrete affected versions, exploit telemetry, and mitigation details such as WP Maps Pro CVE-2026-8732 administrator-account creation, Everest Forms Pro CVE-2026-3300 calculation-field RCE, and Gravity SMTP CVE-2026-4020 email-provider API-key exposure; September 4, 2026: active-exploitation report — Super Forms CVE-2026-14894 (9.8, missing file-type validation, fixed 6.3.314) and Elementor Pro CVE-2026-32475 (9.0/9.8, fixed 4.2.2) unauthenticated arbitrary-file-upload RCE, 440,000+ blocked exploit attempts (250K+ Super Forms via
admin-ajax.phpsuper_submit_formBase64 PHP uploads, 190K+ Elementor Form-widget File Uploads) → see Super Forms / Elementor Pro active-exploitation page; also August 29, 2026: the five-flaw critical batch with Patchstack — WPMU DEV Dashboard CVE-2026-76581 Hub-SSO HMAC auth bypass, Avada/Fusion Builder CVE-2026-18431 unauth arbitrary file write → RCE, TranslatePress CVE-2026-19632 admin password-reset URL exposure, Pods CVE-2026-19598 pods_error()-funneled authorization bypass, GiveWP CVE-2026-82222 unauth object injection → RCE (CVSS 10.0) — see WordPress five-flaw batch page) - Fox-IT / NCC Group research blog (HTML watch; monitor incident-response-backed actor/tool research such as Lazarus RemotePE, DPAPI/environmental-keying loaders, and memory-only RAT tradecraft)
- Boost Security Labs (watch CI/CD supply-chain techniques such as deployment poisoning, TeamPCP follow-ups, GitHub Actions OIDC trust-boundary research such as Sleeper Squats subject-claim delimiter collisions, and trusted-publishing/provenance trust-boundary analysis such as the Miasma / Red Hat throwaway-branch OIDC publication path)
- Novee Security (HTML watch; monitor CI/CD workflow-composition research such as Cordyceps, where untrusted pull-request comments, branch names, artifacts, or metadata cross into privileged GitHub Actions automation with secrets or write tokens; and coding-agent harness handoff failures such as Claude Code
CVE-2026-54316, Gemini CLICVE-2026-12537, and shared-workspace CodexAGENTS.mdpoisoning) - watchTowr Labs (HTML watch for fast edge-appliance, security-platform, and enterprise-web-platform exploit analysis plus detection artifacts, such as Ivanti Sentry CVE-2026-10520 / CVE-2026-10523 pre-auth command-injection and authentication-bypass research, Splunk Enterprise CVE-2026-20253 PostgreSQL Sidecar Service pre-auth file-write-to-RCE analysis, Progress Kemp LoadMaster CVE-2026-8037 API-enabled pre-auth RCE / uninitialized-heap command-injection analysis, Citrix NetScaler CVE-2026-8451 CitrixBleed-class SAML IdP memory-overread validation, and Adobe ColdFusion APSB26-68 CVE-bonanza follow-ups covering CFIDE / FILEIO arbitrary file read-write and path-traversal primitives; August 19 follow-up: MLflow CVE-2026-64849 model-registry webhook SSRF to cloud metadata / credential exfiltration under active malicious scanning, and FUXA CVE-2026-25895 path-traversal DoS; August 14, 2026: "You're Back In The Room" — a full pre-auth RCE chain they believe is CVE-2026-8452: SAML
ds:SignedInfocanonicalization heap overflow innsppetriggered by an oversized exclusive-c14nInclusiveNamespaces PrefixList(~2000+ unique values), linear overflow into the nextnsbchunk header (0x980 stride; type +0x00 / data pointer +0x50 / freelist link +0x60), write-what-where viasplitPktInner'smemcpy(*(a3+0x50) - pktlen), RIP control via thetx_pkt_complete_fptrjmp raxinpe_tx_pkt(non-PIE, no ASLR, RWX heap at fixed post-respawn address), PHP webshell drop to/var/vpn/theme/x.php,pitbossreboot defeat viasigactionSIG_IGN on SIGBUS/SIGSEGV (respawn instead of reboot), and SUID/bin/shfor root PHP; affected 14.1 < 14.1-72.61 / 13.1 < 13.1-63.18 with SAML as SP or IdP; the post-patch "SignedInfo size (%u bytes) is too large (inline ns)" error string is a patch-verification artifact; CVE correlation is watchTowr's inference (Citrix does not map CVEs to credited researchers; one credited researcher: Michael Tucker, JPMorgan Chase XOR) — see ops/citrix-netscaler-cve-2026-8452-preauth-rce-watchtowr.md; monitor for in-the-wild exploitation evidence, additional victim reports, and any CISA/NVD re-scoring of CVE-2026-8452 beyond the DoS framing) - StepSecurity blog (watch Anthropic evaluation-incident follow-ups such as the written victim-scope clarification that StepSecurity was not the package-scanning security company, while keeping the package and affected company undisclosed pending first-party confirmation; compromised scientific and research packages such as
mrmustard==0.7.4, source-artifact-only PyPI injection, maintainer-account takeover, CI publishing-token theft, self-hosted-runner reconnaissance, import-time credential collection, and cron /.pth/ shell persistence; Mini Shai-Hulud / Nx Console follow-ups, Miasma-style@redhat-cloud-services, Leo Platform, and internal-developer-platform package compromises such as Immobiliare Labs Backstage plugins, CI/CD workflow-backdoor campaigns such as Megalodon, GitHub Actions tag-retargeting compromises such ascodfish/semantic-release-actionandsimonecorsi/mawesome, JINX-0164-adjacent package compromises such as Velora DEX SDK / MINIRAT, npm native-addon build-path execution such asbinding.gypCI/CD worms, AI-assistant/editor repository reinfections such asAzure/durabletask, source-repository force-push compromises such asPythagora-io/gpt-pilot, stale-maintainer npm scope compromises such as Mastra /easy-day-js, RubyGems dormant-maintainer compromises such as SleeperGem /git_credential_manager/Dendreo/fastlane-plugin-run_tests_firebase_testlabwith CI evasion and developer-host persistence, IDE marketplace credential theft such as malicious JetBrains AI plugins stealing OpenAI / DeepSeek / SiliconFlow API keys, developer-machine package-manager configuration drift such as npm / Python registry, cooldown, and auth policy checks, downstream GitHub Actions availability impacts such asAzure/functions-actionrepository disablement, Composer/GitHub tag-rewrite incidents such as Laravel-Lang, AsyncAPI generator /spec-json-schemasrelease-workflow compromises with valid npm OIDC provenance, runtimerequire()-triggered Miasma payloads, IPFSsync.jsstaging, and Hades-style PyPI import-hook waves with graph-ML / bioinformatics package compromise, LLM-analysis prompt-injection evasion, cross-platform runner-memory scraping, SSH/SCP lateral movement, wiper-deterrent persistence, developer-machine suspicious-file detection pivots such asbinding.gyp, injected__init__.py,.vscode/tasks.json, and.claude/setup.mjs, and trusted developer-tool npm compromises such asjscrambler@8.14.0preinstall native-binary stealers with browser credential / wallet theft and eBPF capability; promoted August 29, 2026: "@7nohe/openapi-react-query-codegen Compromised Through an Exposed npm Publishing Workflow" (Aug 28) — ten malicious npm versions published by external GitHub userp00pabootvia anissue_comment-triggered release workflow that accepted an exact-matchnpm publishcomment on any PR without role/association checks and published through npm Trusted Publishing / GitHub Actions OIDC (id-token: write); install-time payloads viapreinstall: node 3FWCvzduYZg.js(6.38 MB, SHA256 b24d1216...) plus maliciousbinding.gyp→os.system()decode; runtime downloads Bun from GitHub release infrastructure, runsgh auth token/git credential-manager github list --no-ui, probes GCP metadata — see the ops page) - Trail of Bits blog (watch AI-agent skill distribution and scanner-bypass research such as public marketplace poisoning, ClawHub / skills.sh / Cisco skill-scanner bypasses, bytecode/document indirection, prompt-injection framing, and broader AI/ML supply-chain hardening; cross-check OpenClaw-family advisories and independent writeups for chat-to-host / Gateway execution boundary flaws such as WhatsApp-to-host chains, GHSA-hjr6-g723-hmfm, GHSA-9969-8g9h-rxwm, and GHSA-575v-8hfq-m3mc; also watch Patch the Planet (joint OpenAI initiative, introduced June 22, 2026) agent-capability evaluations and durable AI-agent containment findings — promoted August 27, 2026: "VMs won't contain cyber-capable agents" (Aug 26, Artem Dinaburg) — GPT-5.6-Cyber escaped a QEMU/KVM sandbox VM three times (Januscape CVE-2026-53359; libslirp 4.7.0 CVE-2026-9539 + unassigned-CVE fix; then three 0-days + one unmarked patch vs a from-source minimal QEMU/libslirp rebuild), ~12 hours autonomous, Firecracker held — see the pattern page; and "State divergence enables unauthorized access" (Aug 25, Płatek / Pakizh) — Provenance marker module ACL check passing for any zero-balance caller on non-fixed-supply markers via stale stored-supply field, 82 live mainnet markers, PR #2627 mitigation → PR #2734 fix — see the pattern page)
- arXiv agentic-security papers (HTML watch; promote only papers with immediate defender value for AI-agent, coding-agent, MCP, skill, and autonomous-workflow security, such as SkillCloak / SkillDetonate measurements of agent-skill scanner evasion and runtime detonation, or HalluSquatting / agentic-botnet research where predictable hallucinated repositories or skills create an indirect prompt-injection path to tool execution; promoted August 19, 2026: arXiv:2608.09867 "Stealing Reasoning Traces from Proprietary LLM APIs" — cross-session/cross-user/cross-model replay of provider-encrypted chain-of-thought blocks into a weaker same-provider decoder model, enabling anti-distillation bypass, PII/credential recovery from public agent logs, and invisible prompt injection; monitor the August 2026 mitigations, whether published encrypted blocks remain decodable, and vendor acknowledgment.)
- Patchstack vulnerability disclosures and the WordPress security feed (monitor unauthenticated and low-friction WordPress-core, plugin, and theme RCE/upload flaws with patch releases and in-the-wild signals; promoted August 20, 2026: Elementor Pro CVE-2026-32475 CVSS 9.0 unauthenticated Forms File-Upload RCE fixed in 4.2.2 on 2026-08-19, and WordPress core CVE-2026-65640 CVSS 8.8 Author-or-higher Postscript/ImageMagick RCE fixed in WordPress 7.0.4 on 2026-08-12; cross-reference wordpress.org/news security releases for core forced-update guidance.)
- CleverHans Lab (HTML/arXiv watch for adversarial-ML and agentic-security research with operational defender value, such as adaptive computer worms using local open-weight LLMs on compromised hosts)
- CISA / FBI / DC3 / NSA / USSS / KNPA Gunra advisory AA26-222A and STIX JSON (August 10 priority follow-up; monitor Gunra / Golden Community affiliate access methods, exploitation beyond FortiOS and FortiProxy CVE-2024-55591 / CVE-2025-24472, replacement infrastructure, malicious
forticloud-syncaccount variants, VPN and VDI authentication backdoors, Linux or other cross-platform locker changes, victim and payment scope, and disruption or arrest activity.) - CISA advisory AA26-237A "A Tale of Two SOCs" — https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a (August 26 priority follow-up; monitor for STIX or detailed annex release beyond the public advisory, named-tooling or sample indicators from the red team engagements, follow-on CISA guidance on Machine Account Quota / AD CS ESC1 / cleartext-credential / static-AWS-key hardening, and whether the Certighost-class template abuse described becomes a named advisory. See AA26-237A page.)
- PortSwigger Research
- PortSwigger webmail CSS research and proof-of-concept repository (August 6 follow-up; monitor Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, AOL Mail, Chrome, Firefox, Anthropic, and OpenAI for sanitizer, CSSOM-mutation, image-proxy, draft-rendering, and agent-connector fixes; preserve per-product and per-technique status rather than treating the publication as one universal vulnerability.)
- depthfirst research (HTML watch for memory-safety, parser, dependency, and developer-platform vulnerability research with operational defender value, including the GitLab Oj notebook-diff chain where authenticated project members can combine a heap-pointer disclosure and out-of-bounds write for command execution as
git; monitor CVE assignment, exploit portability, GitLab advisory changes, fixed-version guidance, and any confirmed exploitation.) - ProjectDiscovery blog (watch active-exploitation research and cyber-agent evaluation lessons such as Oh My Rogue Agent and Watching Agents Work, including unintended environment-variable, filesystem, local-network, tracing-service, cross-challenge SSRF, mounted-secret, Unix-socket, and public-benchmark-source pivots; alternate-exploit and side-channel solves; environment/network/filesystem access to reachable harness services; knowledge-to-execution gaps; and hard isolation, full-trajectory review, intended-path scoring, turn, cost, and time controls)
- runZero Research (HTML watch for exposure-management and IT/OT/IoT vulnerability research with durable defender value, such as FatFs CVE-2026-6682 through CVE-2026-6688 embedded-filesystem flaws affecting removable-media and firmware-update paths across Espressif ESP-IDF, STM32Cube, Zephyr RTOS, MicroPython, ArduPilot, RT-Thread, Mbed, Samsung TizenRT, SWUpdate, and downstream IoT/OT products.)
- Synacktiv publications (HTML watch for offensive research with durable defender impact, especially CI/CD, Kubernetes, cloud, and supply-chain control-plane flaws such as unpatched Argo CD repo-server gRPC / Redis reachability leading to unauthenticated code execution and arbitrary Kubernetes manifest deployment.)
- CISA KEV / alerts — https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json and https://www.cisa.gov/news-events/cybersecurity-advisories (promote entries and alerts when they add active exploitation evidence, actor linkage, or high-impact platform exposure. The August 11 batch is covered on the KEV page: Microsoft Windows Ancillary Function Driver for WinSock use-after-free CVE-2026-68820 (the exploited August 2026 Patch Tuesday zero-day, NVD CVSS 7.0 High, local authenticated attacker to SYSTEM, CWE-416, 2026-08-25 BOD 26-04 deadline), Metabase CVE-2026-72898 unauthenticated SQL injection (see the dedicated Metabase zero-day page), and Cisco Secure Firewall ASA/FTD CVE-2026-20349 unauthenticated remote heap-inspection DoS (advisory cisco-sa-asaftd-vpn-dos-dzv4mQFF, 2026-08-14 deadline) — monitor per-CVE fixed-build confirmation on Windows/Windows Server and ASA/FTD, any actor or infrastructure linkage for the WinSock zero-day, and BOD 26-04 deadline enforcement. The August 19 addition is MLflow model-registry webhook SSRF CVE-2026-64849 (fix in v3.15.0 via PR #24258), with a September 2, 2026 BOD 26-04 deadline — see the MLflow page. The August 24 addition is Oracle HTTP Server / WebLogic Server Proxy Plug-in improper access control CVE-2026-21962 (CWE-284, NVD CVSS 10.0, unauthenticated HTTP-reachable data access with scope change; affected Apache HTTP Server plug-in 12.2.1.4.0 / 14.1.1.0.0 / 14.1.2.0.0 and IIS plug-in 12.2.1.4.0; fixed in Oracle's January 2026 CPU; August 27, 2026 BOD 26-04 deadline; CISA names no actor and the only public "exploit" repo is a removed fake-PoC repository) — see the Oracle proxy plug-in KEV page. The August 25 addition is Gitea diffpatch Git-hook code injection CVE-2026-60004 (GHSA-rcr6-4jqh-j84m, CVSS 9.8, CWE-94; repository write access can plant an executable
hooks/post-index-changeentry via the diffpatch add/add-collision path, running shell commands as the Gitea service account; open registration can bootstrap the write access; affected >= 1.17 < 1.27.1, fixed in 1.27.1 on 2026-07-27, 2026-08-28 BOD 26-04 deadline; no actor or ransomware linkage; August 26, 2026: The Hacker News / Habr first public victim report confirms a HOSTKEY VPS compromise that dropped a miner-like dropper via the open-registration write-access path — monitor additional victim writeups, next-stage payload identification, and infrastructure pivots) — see the Gitea diffpatch KEV page. The August 26, 2026 batch adds six CVEs: Citrix NetScaler ADC / Gateway CVE-2026-8452 (memory-overflow denial of service in the Gateway/AAA virtual-server path, CWE-119, NVD CVSS 3.1 9.8 Critical, no privileges / no user interaction, Citrix advisory CTX696604, BOD 26-04 due 2026-08-29 — landing days after CVE-2026-8451 on the same edge appliance) and Microsoft SQL Server CVE-2019-1068 (authenticated remote code execution in the Database Engine service account, NVD CVSS 8.8 High, a 2019 flaw resurfacing as a 2026 exploitation determination, BOD 26-04 due 2026-08-29), plus the four UAT-10147 campaign CVEs now independently confirmed known-exploited — Ajax.NET Professional CVE-2021-23758 (deserialization RCE, CWE-502), Linux kernel CVE-2022-0995 (watch_queue out-of-bounds write, CWE-787), ABRT CVE-2015-5287, and libuser CVE-2015-3246 (all BOD 26-04 due 2026-09-09; the actor linkage is Talos' UAT-10147 attribution, not CISA's) — the NetScaler code-execution claim has now materialized: watchTowr's Aug 14, 2026 "You're Back In The Room" writeup demonstrates a pre-auth RCE chain they believe is CVE-2026-8452 (SAML SignedInfo canonicalization heap overflow in nsppe → root shellcode, SAML SP/IdP, 14.1 < 14.1-72.61 / 13.1 < 13.1-63.18; see dedicated RCE analysis page) — monitor in-the-wild exploitation evidence, CISA/NVD re-scoring of CVE-2026-8452 beyond the DoS framing, and any CISA actor/infrastructure naming on the UAT-10147 CVEs. See the CISA KEV August 26 batch page. The August 27, 2026 batch adds three CVEs: ownCloud Server CVE-2023-49105 (WebDAV pre-signed-URL improper authentication — unauthenticated file access/modify/delete when a victim username is known and no signing-key is configured; CWE-287; ownCloud scopes to Server < 10.13.3, Infinite Scale unaffected; a 2023 disclosure resurfacing as a 2026 exploitation determination; BOD 26-04 due 2026-08-30), Linux kernel CVE-2026-53362 (privilege escalation via the IPv6 networking subsystem; fix commit "ipv6: account for fraggap on the paged allocation path" in__ip6_append_data()with six stable-tree backports cited; BOD 26-04 due 2026-08-30), and JFrog Artifactory CVE-2026-66384 (authenticated path-traversal write outside the intended Docker cache path under remote-repository conditions; CWE-22, vendor Medium; affected < 7.146.35 and 7.161.0–7.161.16, fixed in 7.146.35 / 7.161.16; self-managed only — JFrog Cloud already fortified; BOD 26-04 due 2026-09-10) — no actor or payload named on any of the three; see the CISA KEV August 27 batch page. The August 17–18 batch is covered on the KEV page. The August 7 addition is Progress Kemp LoadMaster pre-authentication command injection CVE-2026-8037, with an August 10 deadline and BOD 26-04 forensic-triage requirement. The August 5 addition is TeamCity On-Premises agent-polling deserialization RCE CVE-2026-63077. August 4 additions include N-central CVE-2026-18556, Tomcat EncryptInterceptor bypass CVE-2026-34486, and Langflow auto-login / code-validation RCE CVE-2026-9198. Other standing examples include FortiOS SSL-VPN CVE-2025-68686, Check Point SmartConsole CVE-2026-16232, Microsoft SharePoint CVE-2026-50522, WordPress wp2shell CVE-2026-63030 / CVE-2026-60137, Langflow CVE-2026-0770 / CVE-2025-34291 / CVE-2026-55255, C0XMO-linked DD-WRT CVE-2021-27137, Cisco IOS 12.4 CVE-2008-4128, Joomla extension CVE-2026-48908 / CVE-2026-56290 / CVE-2026-56291 / CVE-2026-48939, Adobe ColdFusion CVE-2026-48282, PAN-OS GlobalProtect CVE-2026-0257, SolarWinds Serv-U CVE-2026-28318, Mirasvit Cache Warmer CVE-2026-45247, FortiBleed, Oracle E-Business Suite CVE-2026-46817, PTC Windchill / FlexPLM CVE-2026-12569, SimpleHelp CVE-2026-48558, Microsoft ADFS CVE-2026-56155, Microsoft SharePoint CVE-2026-56164, SonicWall SMA1000 CVE-2026-15409 / CVE-2026-15410, KNX Protocol CVE-2023-4346, UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910, Lantronix EDS5000 CVE-2025-67038, and Microsoft SharePoint CVE-2026-45659.) - Arista Security Advisory 0144 — https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144 (July 27, 2026 priority follow-up; monitor actively exploited VeloCloud Orchestrator On-Prem CVE-2026-16812 for exploit-request or payload detail, infrastructure rotation beyond
8.19.75.217,206.72.242.124, and206.72.242.162, victim and actor scope, post-exploitation access to managed Edge devices, additional IOCs, and clarification of the VCO 7.0 fixed-release guidance.) - CISA joint Zimbra advisory AA26-204A — https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a (July 23, 2026 priority follow-up; monitor Russian state-supported LAUNDRY BEAR / Void Blizzard / CL-STA-1114 / TA488 use of Ulej and the Flowerbed collection framework, Zimbra CVE-2025-66376 victim scope, browser
localStorageand mailbox-log artifacts, infrastructure and certificate rotation, STIX revisions, and actor-label reconciliation) - NSA / CISA / FBI / DOE / EPA joint advisory AA26-231A — https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a (August 19–20, 2026 priority follow-up; "active threat" using AI-generated exploit scripts disguised as legitimate monitoring utilities to recon and develop against internet-exposed Siemens S7-200/300/400/1200/1500 PLCs via
snap7/python-snap7S7comm libraries and Censys/ZoomEye scanning, across Critical Manufacturing, Energy, Water, Chemical, Food/Ag, and Commercial Facilities; unattributed; primary CISA fetch was bot-blocked at capture time — re-check for affected-version ranges, cited CVEs, and STIX. See ops/aa26-231a-siemens-s7-ai-generated-exploit-scripts-us-critical-infrastructure.md) - CERT/CC Vulnerability Notes (HTML/RSS/API watch for high-impact vulnerability notes with durable defender value, especially edge-device, router, appliance, and supply-chain flaws where vendor coordination is incomplete or no patch is available, such as Tenda firmware CVE-2026-11405 hidden web-management authentication backdoors; August 26: unpatched Kaltura mwEmbed / html5lib CVE-2026-19912 / CVE-2026-19913 unauthenticated deserialization in
mwEmbedLoader.phpwith no vendor contact reached → ops/kaltura-mwembed-cve-2026-19912-cve-2026-19913-unpatched-rce-file-read.md) - GitHub Security Advisories September 3, 2026 SiYuan batch (20 GHSAs) — monitor the SiYuan kernel repository, the self-hosted SiYuan community, and CISA KEV for: exploitation evidence or a KEV listing (none reported as of capture), PoC publication, and adoption tracking of the v3.8.3-alpha.1 hardening across self-hosted instances. The batch is dominated by the publish-mode read/write boundary collapse:
Publish.Auth.Enable=false(the default when "share links" are used) makes thereadertoken equivalent to full workspace access, and three endpoints (fullTextSearchAssetContent,searchEmbedBlock, backlink/mention search) pass client-supplied full SQL statements verbatim to a read-writesiyuan.dbhandle through a statement-stacking-capable driver with no read-only guard. The two non-obvious tells are (a) the localhost-trust admin bypass — loopbackRemoteAddron a fixed-port reverse proxy with noSetTrustedProxiesmakes the "local admin" boundary remotely reachable, and (b) the second-order SSTI→SQL path, where a malicious imported AV/AV-package executes arbitrary SQL at import time, so the attacker's document is the weapon. No actor or infrastructure named; patch-now posture. See SiYuan kernel publish-mode batch page. - GitHub Security Advisories (Atom/API watch for newly published or materially revised package advisories with operational defender value, including MCP and AI-workflow privileged-proxy failures such as Meta Ads MCP
GHSA-9gw6-46qc-99vr/CVE-2026-48039, where unauthenticated HTTP tool dispatch and error serialization expose the operator's Meta access token; Flyto2 CoreGHSA-jx74-cqjv-2c67/CVE-2026-67426, where an unauthenticated verification service sends its internal runner secret to a caller-selected callback URL; and Grafana MCPGHSA-fr94-7cqc-vjrq/CVE-2026-19516, whereX-Grafana-URLandgrafana_api_requestturn the server into a readable proxy for internal, loopback, link-local, and metadata services; developer-tool confused-deputy failures such as Microsoft KiotaGHSA-hq9q-27g5-qwpj/CVE-2026-59865; multi-tenant AI state-store failures such as LangGraphGHSA-47pj-3jcm-6whg/CVE-2026-71433, where non-segment-aware PostgreSQL and SQLite namespace matching could disclose sibling-tenant records and affected hosted LangSmith deployments; and August 25, 2026 Chainlit MCP advisoriesGHSA-w3fx-mc44-mf6j/CVE-2026-45018(unauthenticated stdio-transport command-injection RCE via allowlisted-namenpx -y -carguments, CVSS 9.8) andGHSA-hvfh-5mj3-5f3j/CVE-2026-45019(SSRF via sse / streamable-http transports with attacker-controlled header forwarding to internal and metadata endpoints, CVSS 7.2), both gated onfeatures.mcp.enabledand fixed in 2.12.0 — monitor affected-version changes, patch confirmation, exposure measurements, and exploitation evidence; see Chainlit MCP RCE/SSRF page; and August 26, 2026GHSA-93qj-5q5v-3c2h"Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)" (severity critical, CWE-506/CWE-522) — first-party confirmation that thepantheon-agentsPyPI account was compromised in the June 2026 Hades / Mini Shai-Hulud / Miasma wave via a stolen long-lived PyPI API token; only the PyPI artifacts are affected (clean GitHub source),first_patched_version0.6.4,.pthstartup hook + Bun +_index.jsstealer, account suspended / token disabled, migration to PyPI Trusted Publishing (OIDC), sibling packages executor-engine / funcdesc / cmd2func / pantheon-toolsets / coolbox / ufish / magique / executor-http remediated separately — see pantheon-agents PyPI trojanization page; and August 27, 2026 two further advisory groups:GHSA-mf7q-r4rv-jv94(Crossplanecrossplane-runtime/v2, High, no CVE) — a cosign signature-verification TOCTOU where tag-based (non-digest) install from an untrusted OCI registry resolves the tag separately for verification vs. fetch, letting a registry serve a signed image to pass cosign then a different unsigned/attacker image for install (CWE-345/CWE-367; affected=2.4.0-rc.0and2.3.0–2.3.2; fix v2.3.3 / v2.2.3 / rc.1; mitigate by pinning image digests) — see GitHub Security Advisories Aug 27 page; plus a coordinated Silverstripe release:GHSA-39mm-rwm3-29jp/CVE-2026-54718(High) RCE via advancedworkflow email template (fix 6.4.5 / 7.1.3 / 7.2.1),GHSA-g8wr-r2v2-vqc6/CVE-2026-54721(High) RCE via userforms email subject (fix 6.4.9 / 7.0.7 / 7.1.1), andGHSA-gvrw-qqp5-jgc5/CVE-2026-54720(Medium) XSS via framework media embed (fix 6.2.2) — monitor exploitation evidence, KEV listing, and CVE backfill on the Crossplane advisory) - CERT-UA (HTML/API watch for Ukraine-focused actor campaigns, UAC cluster reports, malware component names, and indicator bundles, including UAC-0145 / Sandworm subcluster access evolution, ClickFix on compromised sites, SMARTAXE smart-contract domain resolution, and COWARDDUCK Android activity; article pages can be queried via
/api/articles/byId?id=<article-id>) - Europol / Eurojust / FBI IC3 / SBU public cyber notices — watch for criminal infrastructure takedowns, seized domains, exit-node indicators, ransomware-enabler service descriptions, TDS / fake-update warnings, and law-enforcement caveats that can update tool/infrastructure pages such as the June 2026 Operation Endgame SocGholish / FakeUpdates disruption; also monitor FBI/CISA/SBU messaging-application targeting advisories such as Russian Intelligence Services / FSB commercial-messaging phishing tracked as
UNC5792/UNC4221, Backup Recovery Key theft against Signal users, SMS-style fake-support lures, and QR-code account-linking attempts. - BKA / German cybercrime prosecutors and Indonesian police public notices — monitor phishing-as-a-service infrastructure disruptions, arrests, victim-notification updates, server and customer counts, seized indicator releases, and service-resilience findings following the July 2026 Kratos takedown.
- AIVD / MIVD public cyber advisories — https://english.aivd.nl/cyberadvisories and https://english.defensie.nl/ (watch intelligence-derived Russian and other state-actor advisories with operational defender value, including internet-exposed IP-camera compromise for image-recognition-assisted collection on military vehicles, cargo, logistics routes, weapons deliveries, and personnel in Ukraine and EU/NATO states.)
-
NCSC-NL / Dutch Police cyber notices — https://www.ncsc.nl/nieuws and https://www.politie.nl/nieuws (watch Netherlands-hosted criminal infrastructure, botnet takedowns, residential-proxy / IoT-device abuse, hosting-provider disruptions, seized servers, and follow-up victim-notification or indicator releases such as the 17-million-device botnet disruption).
-
Nebula Security research (HTML watch for kernel, virtualization, and exploit-development research with durable defender value such as GhostLock / CVE-2026-43499 local-root and container-escape writeups, public exploit release, and kernelCTF context.)
- Varonis Threat Labs (HTML watch for SaaS, identity, data-security, and AI-agent platform research such as Rogue Agent Dialogflow CX Code Blocks shared-runtime compromise, managed Cloud Run egress, VPC Service Controls bypass, IMDS exposure, and audit-log visibility gaps; August 19 follow-up: CoSnitch / CVE-2026-24301 Copilot Personal
autorun=1one-click connected-app data exfiltration and memory-injection persistence) - Varonis RovoBlast / Bugcrowd disclosure and PromptArmor Rovo analysis (August 8 priority follow-up; monitor Atlassian for confirmation and remediation of the indirect prompt-injection / URL-retrieval path that PromptArmor reported as unresolved on August 5, while keeping it distinct from the fixed P2
rovoChatPromptone-click injection accepted through Bugcrowd. Monitor connector scope, destination controls, audit artifacts, exploitation evidence, and additional outbound channels such as Markdown-image rendering.)
Maintainer / vendor incident posts to watch during active campaigns
- Broadcom VMware security advisories — https://support.broadcom.com/security-advisories (monitor VMSA-2026-0006 and later vCenter / ESX updates for CVE-2026-59309 authentication bypass, CVE-2026-59310 network-reachable code execution, CVE-2026-47876 VMXNET3 guest-to-host escape, revised product matrices, public exploit release, active-exploitation evidence, and incident-response guidance)
- Ruflo security advisories and releases — https://github.com/ruvnet/ruflo/security/advisories and https://github.com/ruvnet/ruflo/releases (monitor CVE-2026-59726 / GHSA-c4hm-4h84-2cf3 for affected-version clarification, exposed-instance measurements, in-the-wild exploitation, memory-poisoning artifacts, additional MCP authorization changes, and provider-key or conversation-impact follow-ups)
- ServiceNow security advisories — https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3137947 (watch CVE-2026-6875 AI Platform sandbox-escape exploitation for fixed-release changes, public indicators, victim scope, and vendor incident-response guidance; keep it distinct from the June hosted-instance table-query issue; August 27, 2026: new AI Platform / Now Platform advisory with three CVSS 10.0 unauthenticated flaws — CVE-2026-18885 GraphQL Composite Data API code injection, CVE-2026-18886 configuration-image upload access control, CVE-2026-74820 dynamic-schema ORDER BY SQLi — plus the unauthenticated sandbox-escape CVE-2026-6876; deployed to hosted instances, self-hosted customers must apply — see ops/servicenow-ai-platform-august-27-2026-three-cvss-10-unauthenticated-flaws.md)
- Hugging Face incident follow-ups — https://huggingface.co/blog/security-incident-july-2026, https://huggingface.co/blog/agent-intrusion-technical-timeline, and https://github.com/huggingface/blog/blob/main/security-incident-july-2026.md (watch for the Artifactory CVE and fix, unredacted indicators, remaining third-party account notifications, independent validation, additional customer or partner scope, and changes to the five-dataset impact and no-shipped-artifact-tampering assessments.)
- JSONata security advisories and releases — https://github.com/jsonata-js/jsonata/security/advisories and https://github.com/jsonata-js/jsonata/releases (August 21, 2026: three critical arbitrary-code-execution advisories published with public PoCs — CVE-2026-77413 / GHSA-8gq3-vp5j-2grp (lookup missing hasOwnProperty, fixed PR #794 in 2.2.0 / 1.8.8), CVE-2026-77414 / GHSA-2943-5xfg-gq5f (bypassable hasOwnProperty in environment.lookup, fixed PR #799 in 2.2.1 / 1.8.8), CVE-2026-77415 / GHSA-66mm-25pp-rfff ($clone overwrite + lambda destructuring + applyProcedure proc.arguments.forEach, fixed PRs #799/#800/#802 in 2.2.1 / 1.8.8) — see tools/jsonata-cve-2026-77413-77414-77415-arbitrary-code-execution.md. Monitor for in-the-wild exploitation, PoC abuse in ETL/integration/workflow hosts that evaluate attacker-influenced expressions, a fourth bypass, and KEV addition. Patch targets are jsonata >= 2.2.2 / >= 1.8.9.)
- Xinference (xorbitsai/inference) security advisories and releases — https://github.com/xorbitsai/inference/security/advisories and https://github.com/xorbitsai/inference/releases (August 21, 2026: CVE-2026-61539 / GHSA-x2rj-828p-hx9m — critical CVSS 10.0 unauthenticated RCE via unsafe
eval()in the Llama3 tool-call parser (extract_tool_callsintool_parsers/llama3_tool_parser.py), CWE-95; fixed in 2.7.0 by PR #4786 (merged 2026-04-14, PyPI 2026-04-25) so the advisory retroactively credits the disclosure; see tools/xinference-cve-2026-61539-llama3-tool-call-eval-rce.md. Monitor for KEV addition, in-the-wild exploitation of exposed instances running <= 2.5.0, and whether other tool parsers shipped the same eval pattern.) - Nx / nrwl security advisories and issues — https://github.com/nrwl/nx/security/advisories and https://github.com/nrwl/nx/issues
- Grafana Labs security posts and security advisories (monitor Grafana MCP Server advisories such as
CVE-2026-19516, affected-version and managed-service scope, replacement or bypass paths after removal ofX-Grafana-URL, explicit caller-authentication defaults, exposure measurements, and exploitation evidence) - PyPI project and malware-report pages for affected packages — use package-specific release history as confirmation for yanked or restored versions.
- Packagist package pages and maintainer incident notes — watch package metadata/tag movement and unexpected
composer-pluginconversions during Mini Shai-Hulud-style cross-ecosystem incidents. - LiteSpeed / cPanel security notices — watch vendor advisories and cPanel support notices for actively exploited hosting-control-plane flaws and forced-removal/patch guidance, including LiteSpeed cPanel Plugin CVE-2026-54420 root escalation on CloudLinux / CageFS shared-hosting systems and August 27, 2026 CVE-2026-65643 — authenticated parked/addon-domain arbitrary file write yielding root code execution on shared hosting, all supported versions (110/134/136/138 branches), fixed build 11.138.1.7 (WP Squared), no CVSS and no CVE Program record as of August 28 — see ops/cpanel-whm-cve-2026-65643-parked-addon-domain-root-rce.md.
- Progress / ShareFile status and advisories and Progress security notices (watch emergency shutdown or access-disablement guidance for customer-operated ShareFile Storage Zone Controllers, including July 2026 credible external security threat reporting, safe-restart instructions, CVE assignment, IOCs, and affected-version ranges; cross-reference watchTowr's Storage Zone Controller CVE-2026-2699 / CVE-2026-2701 pre-authentication RCE chain for safe exposure-validation and web-shell hunt pivots without assuming it is the current incident path.)
- BeyondTrust security advisories (HTML watch; monitor Remote Support / Privileged Remote Access authentication-bypass and appliance-control flaws such as BT26-03 / CVE-2026-40138 / CVE-2026-40139, especially where exposed RS/PRA systems have prior web-shell / backdoor exploitation history.)
- DAEMON Tools / Disc Soft notices and release notes; watch follow-ups to DAEMON Tools Lite CVE-2026-8398, installer integrity claims, rebuild/version guidance, and infrastructure-remediation details.
- Visual Studio Code release notes / Marketplace security changes — https://code.visualstudio.com/updates/ and https://marketplace.visualstudio.com/VSCode (watch extension-marketplace mitigations, delayed auto-update changes, publisher-trust exceptions, and response details following poisoned-extension incidents such as Nx Console.)
Notes
- Prefer RSS/Atom over ad hoc web searches.
- If a feed URL changes, update this page and the monitoring config together.
- If a source produces repeated noise, lower its priority before removing it.
Active watch topics
- PostGREShell / CVE-2026-6471 PostgreSQL logical-decoding REPLICATION RCE (Cyera Sep 1, 2026; THN Sep 4) — monitor CISA KEV for a CVE-2026-6471 listing, in-the-wild exploitation of the 114 already-hostile VirusTotal PostgreSQL plugins,
output_plugin_librariesallowlist fallout across CDC/Debezium/wal2json/decoderbufs deployments (post-patch replication outages as a canary), EOL 9.4–13 exposure past 14's November 12, 2026 end-of-life, and the next unguarded-plugin-load recurrence in a database engine (RedisMODULE LOAD/ RediShell CVE-2025-49844 is the template). Preserve the durable detection shapes: a database server initiating outbound SMB 445 / NFS 2049 (the fully-remote path),pg_hba.confrewrite + reload from a non-admin session,shared_preload_librariesdrift, superuser flips inpg_authidwithout administrative provenance, and post-patchERROR: library "..." may not be used as an output pluginlog lines. See ops/postgreshell-postgresql-logical-decoding-replication-rce-cve-2026-6471-september-2026.md. - ted backdoor / DPRK HAProxy-embedded Linux espionage toolkit (Rapid7 Sep 4, 2026) — monitor Rapid7, ThreatFox, and South Korean CERT/victim organizations for C2 rotation of the
img.<name>.<tld>set (img.monderhouse[.]space,img.smartnords[.]site,img.darklights[.]store,img.responsive.pstatic[.]autosNaver-mimic,img.socialteams[.]store,img.worksongo[.]store), named victims, additional trojanized-daemon variants beyond crond/agetty/atd/sshd/polkitd, HAProxy build-variant changes fromHAProxy 2.8.12-0fdb194, and attribution refinement beyond the medium-confidence DPRK / APT37 assessment. Preserve the durable detection shapes: a load balancer rewriting response bodies it should only be routing, a non-HAProxy process polling/proc/haproxy.pidhourly, the PAM module drift with the/var/lib/sshd/c8c68e629bba773a10ac80012d10bf19encrypted credential log,libvirtlog.so.0-gated sandbox evasion, and MD5(hostname+IP+HW-UUID+cron)User-tokenheaders. See ops/ted-backdoor-haproxy-linux-espionage-dprk-curlrat-ssh-keylogger-september-2026.md. - Next.js August 2026 security release: libheif/AVIF heap overflow + Windows path traversal (GHSA-2xp9-vwfh-vxw4 / GHSA-g89c-p67h-r497 / CVE-2026-75604) — monitor Vercel, the Next.js blog/changelog, libheif (strukturag/libheif) GitHub releases for the libheif v1.23.2 patch that Next.js's "AVIF optimization off" stopgap is waiting on, the CVE-2026-75604 attack-mechanism disclosure (currently undisclosed; Windows-hosted Pages+App-Router-without-Cache-Components deployments, no workaround), and any in-the-wild exploitation of either flaw (none reported as of Aug 27, 2026). Preserve the durable pivots: (1) the libheif
scale_nearest_neighbor()dual-Alpha-entry / nested-iden-auxl overflow shape (~16,384-byte attacker-controlled OOB write) as a standing native-image-parser RCE vector across every sharp/libheif consumer; (2) the Vercel monthly-security-program cadence (second release; program noted "rising vulnerability-research volume driven by LLM-assisted discovery"); and (3) the uncorroborated researcher "RCE on multiple applications" claim for the AVIF flaw. See ops/nextjs-august-2026-security-release-avif-libheif-and-windows-rce.md. - GitHub Security Advisories August 29, 2026 batch (argocd-mcp / Sigma Forms Pro / Omnivore / Skyvern / BookStack / @better-auth/sso) — monitor GitHub Security Advisories, Argoproj-labs mcp-for-argocd, Vercel, and the affected maintainers for: an argocd-mcp fixed release or configuration hardening (CVE-2026-82456, unauth MCP tool-surface bypass on
ARGOCD_API_TOKEN— a recurring MCP-as-privileged-proxy critical alongside CVE-2026-59822), the Sigma Forms Pro fixed version (CVE-2026-14494, unauth WordPress RCE via dynamicunfiltered_upload+ no MIME gate, immediate-on-install), the Omnivore Apple-Sign-In JWT algorithm-confusion fix propagation (CVE-2026-82454,alg=HS256with Apple public key as HMAC secret), and the second-wave items (IBM ARE for i CVE-2026-18527 9.9, getgrav/grav-plugin-api CVE-2026-80203 9.8, Kimai CVE-2026-80198/-80193, StarRocks CVE-2026-80346, su-exec CVE-2026-82457, cohttp CVE-2026-82481, RubyGems CVE-2026-82455). No actor/infrastructure/payload/exploitation named. See ops/github-advisories-argocd-mcp-sigma-forms-omnivore-skyvern-bookstack-august-29-2026.md. - TerminalClickFix / TerminalFix multistage reverse-tunnel campaign (Microsoft, Aug 28, 2026) — monitor Microsoft Threat Intelligence, threat.wiki, and EDR/XDR vendors for additional victim scope, the
gitnow[.]dev:443/bestsocialmedianewspapper[.]com/offlineupdater[.]com/linked-log[.]cominfrastructure rotation,dui70.dllvariant hash churn, and whether the fake-Cloudflare-Turnstile ClickFix-in-Windows-Terminal lure pattern propagates into other ClickFix or registry-mirror campaigns. Preserve the durable detection shapes:LockScreenContentServer.exesideloading a forgeddui70.dlloutsideSystemApps, aC:\ProgramData\f47f2a8c21c9df4e\payload directory,pythonw.exerunningclient.pywithgitnow.dev, steganographic PNG payload split (first 8 bytes a 64-bit length), and a SOCKS-style WebSocket reverse tunnel. See ops/terminalfix-clickfix-reverse-tunnel-multistage-microsoft-august-2026.md. - Berlin state network / Rhysida extortion (THN / Der Spiegel, Aug 28–29, 2026) — monitor CISA/FBI, the Berlin Senate Chancellery, Der Spiegel, and Rhysida leak-site monitors for an authority-confirmed Rhysida attribution (currently moderate confidence via press + leak-site entry), a published ransom figure, refinement of the Aug 7–12 exfiltration scope beyond the Senate Mobility/Transport/Climate portfolio, confirmation whether personal data was exfiltrated, and any follow-on publication that expands scope. Preserve the durable initial-access lesson from the CISA/FBI/MS-ISAC Rhysida advisory: valid-account VPN access where MFA was not enforced is the highest-value control to audit in any public- or private-sector remote-access posture. See ops/berlin-state-network-rhysida-extortion-august-2026.md.
- Cosmos EVM vesting-account balance overflow exploited across six chains (GHSA-7g4w-cg88-2cq2) — monitor the GitHub global advisory DB for
GHSA-7g4w-cg88-2cq2becoming publicly indexed (404 at capture), a CVE / CVSS / CWE assignment, Cosmos Labsv0.6.2/v0.7.2patch-uptake telemetry across the affected deployments (MANTRA and the other five chains), the advisory-incomplete-fix risk (PR #1187 locked-balance snapshot + commit3524ebcmodule-account guard omitted from the advisory), fork-level cherry-pick defects (ZetaChain's duplicated unexported helper), and whether Cosmos Labs' public silent-patch routing for a known fund-loss threat changes its security disclosure policy. Preserve the detection shapes: vesting-account delegation above spendable balance, a wrapped≈2^256x/bankbalance, and a single-transaction net-zero-supply mint/burn from a precomputed-address contract. See ops/cosmos-evm-vesting-balance-overflow-exploited-august-2026.md. - @7nohe/openapi-react-query-codegen npm compromise (exposed issue-comment-triggered OIDC publishing workflow) — monitor npm registry state for
latest-tag repoint or deprecation of 3.0.4, takedown or yank of the ten affected versions, GitHub issue #217 / PRs #215-216 follow-ups, the repository's workflow fix (removal ofissue_commenttrigger and/or actor-authorization checks on the release workflow), a GHSA or CVE assignment, registry-side provenance actions, and any operator attribution or linkage to other unauthenticated-publish incidents. OX Security (Aug 29, 2026) identified the install-time payload as a Shai-Hulud variant now self-identifying as "Trinitite: Sponsored by Preview 2 Effects," rebundled with a new set of embedded RSA public keys that break the key-fingerprint used to correlate Shai-Hulud variants; OX frames it as a post-arrest copycat wave (compromise within ~24h of the AFP/WAPF/FBI TeamPCP charging) — a Shai-Hulud-lineage / copycat assessment, not confirmed TeamPCP operator identity. Preserve the durable detection shapes: exact-match comment-body triggers,preinstall+binding.gypdual execution paths, Bun staged under/tmp/trinnyyyy-*/withgh auth token/ GCP-metadata probing, and the "Trinitite"/trinititestring markers in new Shai-Hulud-lineage payloads (expect future variants to rotate public keys the same way). JFrog Security Research (Aug 30, 2026) independently confirmed the family and added durable detection shapes: two-wave publication (wave 1binding.gyp-only vs wave 2 +preinstall), the install command now hidden inbinding.gypconditionsas a Unicode-escaped Python expression that node-gyp evaluates (survives--ignore-scripts), a ~1.6M-entry XOR-key-9 array + two AES-128-GCM blobs with Bun v1.4.0 staged totrinnyyyy-*, new exfil markers (doubletrinnys-,meow meow meowvsIfYouRevokeThisTokenYourABadUser:,ClaudeCode Reviewworkflow), direct PyPI-token push atupload.pypi.org/legacy/, and a live token-revocation trap (systemd-detect-fash/sysvinit-detect-fash+~/.local/share/diaper/poopy.py) that can wipe~/on a 40x — isolate before revoking tokens; Xray ID XRAY-1065308 covers all ten versions. See ops/7nohe-openapi-react-query-codegen-npm-compromised-august-2026.md. - Pimcore five-flaw coordinated batch (Aug 28 GHSAs: DataObject field-name RCE + Hotspotimage PHP object injection + privesc + SQLi + reset-URL ATO) — monitor Pimcore GitHub, NVD, and vendor advisories for CVE backfill (55220 still lacks a CVSS), a CVE for 55634's secondary DDL SQLi, in-the-wild exploitation or any actor/infrastructure attribution, and whether the Hotspotimage
Serialize::unserializeno-allowlist sink and the guzzle-7.11.0 FileCookieJar gadget chain get confirmed in the wild. Preserve the durable pattern: any identifier or serialized metadata that reaches codegen/deserialization without an allowlist is an injection primitive. See ops/pimcore-studio-dataobject-rce-php-object-injection-cve-2026-55634-batch-august-28-2026.md. - OX ClickFix-in-npm / registry-mirror payload-storage campaign — monitor OX Security, npm/GitHub, unpkg / npmmirror / yarn / tencent mirror operators, and phishing-research channels for the remaining "keyval new logic" family packages (
mndsxcusiwlk1,mn2adskhweox,mn3sadkoiewu,mn4xcouzvhus,mbxcnsuwgs1,skxcmwuncbg2,mobiwaefhxc3,@worrisome/reutil), mirror-side takedown or blocking,api.keyval.orgencrypted-value rotation, additional typosquatted-Microsoft redirect domains beyondlogin[.]microsofte[.]live, mirror-hostedindex.htmlURLs surfacing in phishing reports, and evidence of the current ChatGPT-targeted value being weaponized to ClickFix or other phishing endpoints. Preserve the no-install-execution framing: the durable threat is trusted-domain storage, not developer-machine infection. See ops/ox-clickfix-phishing-npm-mirror-payload-storage.md. - Operation QUICSILVER / QUICAgent (Myanmar ITCSD targeting) — monitor Seqrite, Myanmar CERT, Cloudflare, and regional incident responders for additional victims or sectors, VHD/LNK lure rotation, QUICAgent command-set expansion beyond the observed five,
104.64.211[.]22or Cloudflare Workers discovery-domain rotation, QUIC/UDP C2 infrastructure changes, and attribution evidence that confirms or refines the moderate-confidence China-nexus assessment. Preserve theftp.exe -s+copy /bOOXML-reassembly and 100–600 ms delay + ~1000× SHA-256 burn as the durable detection shapes. See ops/operation-quicsilver-vhd-delivered-go-backdoor-myanmar.md. - WordlistLoader / SynkLoader → Amatera (ACR) ClearFake campaigns — monitor Gen Digital, ExpeL, eSentire, Microsoft, and registrars for loader-variant changes, additional compromised domains beyond the six recorded,
cdn.jsdelivr[.]netpath rotation, EtherHiding contract or RPC-endpoint changes, headless-conhostand delayed-environment-expansion coverage in EDR rules, SynkLoader ransomware-access-sales confirmations, and further overlap with Microsoft's documented ACR Stealer WebDAV campaigns. Preserve the family-label distinction: WordlistLoader/SynkLoader are new loader names inside the existing Amatera/ACR/AcridRain cluster. See ops/wordlistloader-synkloader-amatera-clearfake-campaigns.md. - miniOrange SAML plugin CVE-2026-15981 / CVE-2026-61979 active exploitation — monitor Patchstack, Xecurify, DigitalOcean, WordPress security vendors, CISA, and incident responders for KEV listing, additional scanner source IPs beyond the six recorded, victim scope, PoC chain changes, plugin version reconciliation beyond the 17.0.5 / 17.0.6 Standard-edition fixes, and exploitation of edition or version gaps. Preserve the
openssl_verify()tri-state / loose-boolean root cause as the durable PHP-integration audit pattern. See ops/miniorange-saml-unauthenticated-wordpress-admin-takeover.md. - Keycloak CVE-2026-18963 unauthenticated account takeover — monitor Red Hat, the Keycloak project, GitHub Security Advisories, CISA, and identity-threat researchers for exploitation evidence or a KEV listing (none reported as of August 24, 2026), a public exploit or PoC, affected-version range reconciliation (GitHub advisory incomplete at capture), RHBK errata follow-ups, and downstream tenant impact on exposed identity servers. Preserve the "no confirmed exploitation as of capture" status. See tools/keycloak-cve-2026-18963-unauthenticated-account-takeover.md.
- Lazarus "Operation Dream Job" / CVE-2026-68820 exploitation — monitor CISA KEV, Microsoft, Check Point, and affected defense/aerospace/aviation victims for CVE-2026-68820 patch-uptake confirmation, additional targeted sectors or victims, new infection chains or relay infrastructure,
RelayShellPHP C2-relay web-shell propagation beyond the observed Roundcube / WordPress / PrestaShop hosts, CVE-2025-49113 (Roundcube RCE) patching,MISTPENGraph/OneDrive C2 indicators,FudModule/ForestTiger/Troysample updates, theSecurityPDFtrojanized-viewer andlibmupdf.dllDLL-sideloading chains, the Enveil-impersonation SEO-poisoned download sites, and any attribution refinement beyond Check Point's Lazarus assessment. Preserve the confirmed-exploitation context and the distinct-CVE caveat (not CVE-2025-60719, not the 2024 CVE-2024-38193 variant). See ops/lazarus-operation-dream-job-shattering-the-dream.md. - workerd / Cloudflare Code Mode sandbox-escape and cross-tenant heap swipe — monitor Check Point, Cloudflare, the
cloudflare/workerdGitHub releases, and the MCP / agentic-tooling ecosystem for CVE or GHSA assignment of the five memory-corruption bugs, in-the-wild exploitation of self-hosted workerd or Code Mode deployments, aworkerdversion pastv1.20260619.1, other V8-isolate / native-glue boundary flaws in the same shared-process model, and any prompt-injection-to-Code-Mode-host-execution chain in the wild. No actor or in-the-wild exploitation reported as of capture; treat the two demonstrated attacks as researcher PoCs from Black Hat USA 2026. See tools/workerd-code-mode-sandbox-escape-cross-tenant-heap-swipe.md. - Benchmaxxing: AI/cybersecurity benchmark integrity — monitor CrowdStrike, the benchmark vendors (Cybench and peers), and independent evaluators for quantified agent-cheating or contamination findings, private- vs public-benchmark comparisons, evaluation-harness isolation guidance, and procurement or red-team heuristics that respond to the Goodhart's-Law signal-degradation described in the August 19, 2026 post. Vendor-methodology reference, not an incident; preserve the distinction between the named failure modes and any independent replication of the Cybench cheating result. See patterns/benchmaxxing-benchmark-integrity-cyber-ai.md.
- arrayref 0.3.10 / proc-macro1 typosquat Rust supply-chain attack — RustSec advisories now published (2026-08-20/21):
RUSTSEC-2026-0259(arone),-0260(arrayref, unaffected<= 0.3.9),-0261(aronenao),-0262(append-only-vec, unaffected<= 0.1.8),-0263(tinymember, affiliation-only),-0264(proc-macro-en),-0265(proc-macro1),-0266(internment, unaffected<= 0.8.6) — allmalicious;cargo auditcoverage restored. The Rust security team's official post (blog.rust-lang.org 2026-08-20) confirms the owner was not acting maliciously ("computer or credentials likely compromised"), reports 2,285 downloads ofarrayref0.3.10 (<10% of all-version traffic; most users pinned older lockfile versions), and publishes the canonical~/.cargo/registry/cachehunt. Still open:droundyaccount recovery or handover, any newarrayrefrelease, a CVE assignment,aovine(deleted, no advisory yet),dtolney-persona follow-on publications, and stage-2 payload recovery from public sources. Wiz's August 20 write-up recovers the stage-2 implant from Google Threat Intelligence samples (beacon toPOST /49890878, Chrome/Brave/Edge SQLite saved-login enumeration,kill/minicfg/startup/runscriptcommands, DGA.comfallback, AES-128-GCM config under the hardcoded keyi am botking, embedded RSA-2048 private key) and asserts substantial infrastructure overlap with DPRK campaigns (shared/49890878beacon path and23.254.164.0/23Hostwinds range with the Microsoft-attributed Mastra/Sapphire Sleet campaign, and23.254.167[.]216appearing in GCTI's UNC1069 axios analysis). Preserve the attribution caveat: the overlap is infrastructure correlation, not a named-operator confirmation. Preserve the ~86-minute exposure window (2026-08-20 07:11–08:41 UTC) and the yank-burst social-pressure tradecraft. - StubMaker RubyGems yank-and-reclaim campaign — monitor RubyGems for re-publication under reclaimed package names, additional typosquat packages, the Go stealer / Rust loader payload updates, owner-account activity (
mod8rz41mje/rbq95bwt6q), and registry-side yank-reclaim policy changes. Preserve the distinction between the observed 16 packages and any later expanded set. - Balonx Sistema Mexican banking PhaaS — monitor Group-IB, Mexican financial institutions, and code-hosting platforms for public IOC releases, additional leaked repositories, domain rotation, confirmed victim institutions beyond the 20+ scope, and affiliate-network changes.
- Microsoft Defender CVE-2026-50656 / RoguePlanet / ShieldBreak — monitor Microsoft security response for a fix addressing the ShieldBreak bypass, engine-version detection pivots, public exploitation evidence, and follow-on researcher reports; preserve the no-official-fix-as-of-August-12 assessment and its exposure window.
- City Forum Salesforce/ServiceNow guest-access scraping — monitor Reco, Salesforce, ServiceNow, and SaaS platform operators for guest-identity access-control changes, victim-portal confirmation, additional campaign infrastructure, and any attribution to a named group.
- Unisoc T606/T612/T7250 VoLTE exploit chain — monitor Unisoc, device OEMs, and cellular infrastructure operators for CVE assignment, vendor response to SSD Secure Disclosure's outreach, fixed-firmware availability, and any in-the-wild use given the private-4G-network requirement.
- Head Mare TrueConf / PhantomCore / PhantomGraph campaign — monitor Kaspersky, TrueConf/ConfTool vendor, regional CERTs, and video-conferencing operators for additional compromised-server or participant scope,
locale.phpweb-shell variants, PhantomGraph OneDrive C2 rotation, and confirmation of the hacktivist-to-APT reclassification by independent vendors. Both exploited flaws are now in CISA KEV (added August 20, 2026): CVE-2026-72529 (missing authentication for critical function, CWE-306; BOD 26-04 deadline August 23, 2026) and CVE-2026-72530 (code injection, CWE-94; deadline September 3, 2026), closing the earlier open KLCERT-26-057/058-to-CVE question. Preserve the vendor-response caveat: Kaspersky identified the two flaws as unpatched-at-the-time while the June 18, 2026 5.3.9 / 5.4.9 / 5.5.5 releases were the stated fix. - Project CAV3RN GAS relay and DNS channel selection — monitor Kaspersky GReAT, Check Point Research, Google, and the cluster's infrastructure for relay deployment-ID rotation, additional studiotikva[.]com backends beyond api.studiotikva[.]com/ac, new broker or module DLLs, Cavern Manticore attribution refinement beyond the Iran-MOIS / Lyceum / MuddyWater overlap, and victim scope beyond Israeli government and IT-provider targets. Keep the GAS relay detection shape (POST to script.google[.]com/macros/s/
/exec with a k/m/h/r JSON envelope, 302 to macros/echo) distinct from benign Google Apps Script web-app traffic. - CoolClient kernel-mode rootkit driver (HoneyMyte / Mustang Panda) — monitor Kaspersky GReAT, Sophos, Trend Micro, and the Pakistan / Mongolia / Myanmar intrusion context for additional driver samples, signed-driver identity or certificate detail, new IOCTL capability expansion beyond process/file/registry hiding, the fake-Defender staging and ATP-named scheduled-task tradecraft in other intrusions, and correlation of the late-2025 clipboard-theft / HTTP-interception CoolClient variant with this driver deployment.
- Armored Likho Still Toolkit (Still Sync / Still Audio) — monitor Kaspersky GReAT, Telegram, and Russian incident responders for additional Still Toolkit components, tg4service[.]com rotation, orderapiserver[.]info catalog changes, victim scope beyond the Russian sector-level description, and confirmation of the May 2026 campaign timing. Preserve the distinction between the Telegram tdata session theft (ongoing account access) and generic browser-cookie infostealer behavior.
- Clop-linked Windchill JSP web shell (CVE-2026-12569 follow-up) — monitor PTC, ReliaQuest, Ransom-ISAC, eCrime.ch, Defused, CISA, and Windchill / FlexPLM operators for vendor acknowledgment or fix guidance, additional JSP web-shell variants, keystore-decryption and custom-class-loader artifact hunting results, victim scope, and any KEV or advisory status change for CVE-2026-12569.
- AI "mind viruses" agent-to-agent propagation — monitor Anthropic, EPFL, agent-harness vendors (OpenClaw / Clawdbot / Moltbot), Moltbook, and the AI-agent security research community for in-the-wild propagation evidence, revised payload or warning variants, model-generalization results beyond Claude Haiku 4.5, harness vendor mitigations for
SOUL.md/MEMORY.mdwrite gating, and overlap with the retitled AgentWorm (63% aggregate success rate). Preserve the no-confirmed-in-the-wild-propagation assessment and the simulated/simulated-plus-Moltbook-archive scope. - SilkParasite / China-nexus Central Asia espionage cluster — monitor Bitdefender, Kaspersky, regional CERTs (Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan), and infrastructure providers for new RAT family names or versions (DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, NodeEdgeRAT, BLOODALCHEMY, SpiceRAT), C2 rotation, confirmed victim ministries, loader or DLL-sideloading changes, and attribution refinement beyond the medium-confidence China-nexus assessment.
- MLflow CVE-2026-64849 SSRF active exploitation — CISA added it to KEV on August 19, 2026 (BOD 26-04 deadline September 2, 2026); the fix shipped in MLflow v3.15.0 via PR #24258 (GHSA-7gwp-5pfp-969j). Monitor MLflow maintainers, watchTowr, VulnCheck, CISA, cloud providers, and ML platform operators for exploit-request and infrastructure indicators, victim scope, any actor attribution, and affected-version lower-bound confirmation below v3.15.0. Preserve the distinction between observed scanning/exploitation and confirmed victim impact.
- Gogs CVE-2026-52813 path-traversal RCE — monitor Gogs maintainers, CISA, GitHub Security Advisories, and self-hosted Git operators for the unpatched bypass fix, CVE-2026-52810 push-authorization bypass fix, GHSA-6vxv-wg6j-5qwp XSS resolution, KEV status, and exploitation evidence. Aikido recommends using a different self-hosted Git solution while Gogs is not actively maintained; monitor whether that guidance changes with a new release.
- Operation CameraSwarm Dahua camera campaign — monitor Hunt.io, Dahua, CISA, and IoT responders for confirmed compromise scope beyond the 14,530 devices in Ukraine and Russia, CVE-2021-33044 / CVE-2021-33045 exploitation details, Easy4IP P2P relay infrastructure changes, and any vendor response or fixed firmware.
- StopAndProtect hacked-WordPress malware infrastructure — monitor Check Point Research, WordPress hosting providers, CISA, and incident responders for campaign growth beyond the ~2,000 sites and 6,000+ victim IPs, new malware families, infrastructure rotation, and actor attribution. Preserve the opsec-blunder reconstruction basis and the campaign's active-growing status.
- CoSnitch / Microsoft Copilot Personal CVE-2026-24301 — monitor Microsoft, Varonis, Copilot Personal users, and incident responders for in-the-wild exploitation evidence, memory-injection persistence confirmation, affected-user scope, and any additional Copilot Personal flaws. No in-the-wild exploitation reported as of August 19.
- TWINLOOT M365 dead-drop / Teams TURN Python implant — monitor Ontinue, Microsoft, Teams and SharePoint operators, and incident responders for victim scope, Teams vishing delivery vectors, PyArmor decompilation or payload evolution, STAC4749 / Chaos overlap confirmation, and any Microsoft service-side detection or mitigation changes.
- TheHatman Entra tenant credential-theft claims — monitor Unit 42, Microsoft, criminal forums, and law enforcement for victim confirmation, evidence for or against the claimed MFA-fatigue / password-spraying intrusion vector, TheHatman post or infrastructure indicators, sample data shape and volume, operator attribution, and whether the handle links to any tracked credential-spray operation. Treat all victim and data claims as unverified until corroborated by victim telemetry or enforcement action.
- Entra ID rogue device registration with AI-generated identifiers — monitor Wiz, Microsoft, and identity-threat researchers for the residual catch-rate of static Dsreg/10.0 / DESKTOP-XXXXXXXX fingerprints as AI-generated names become common, additional AI-eroded User-Agent or device-name artifacts, attribution of the MSTokens-PRT/1.0. / Work PC registration, first-party Microsoft behavioral detection for device-code-phishing-to-registration correlation, and whether MFA-for-device-registration reduces the observed one-in-seven tenant attack rate.
- GitLab GraphQL CVE-2026-19478 / CVE-2026-19650 — watchTowr reported in-the-wild exploitation of CVE-2026-19478 on August 21, 2026 (reproduced within minutes of disclosure; observed against its honeypot network), per The Hacker News. Monitor GitLab, CISA, GitHub Security Advisories, self-managed operators, and incident responders for a KEV listing (neither CVE was in CISA KEV as of the August 21 catalog release), exploitation evidence beyond watchTowr's honeypot, and any actor linkage. No configuration workaround exists; the four-branch patch (19.2.4 / 19.1.6 / 19.0.8 / 18.11.11) remains the only control, and unpatched self-managed instances are now an immediate-priority target.
- BTR Reforged / BTR_CLI (Defender BTR.sys weaponization) — monitor Check Point Research, Microsoft Defender engineering, EDR vendors, and threat-actor tooling for real-world adoption of the BTR.sys kernel-operation primitive, additional RC4-key or
~CRC32findings across BTR.sys builds, follow-on research into other signed remediation components with similar encrypted-configuration ADS patterns, and Sysmon-based detection rules. No CVE exists (trusted-component abuse, not a flaw); preserve the no-in-the-wild-abuse assessment as of August 20, 2026. - RedC2 4.0 trojanized-npm wave (RedShell Linux beacon) — monitor TrendAI, npm registry state, StepSecurity, Socket, Snyk, and incident responders for additional trojanized packages beyond the 14 identified, registry takedown/cleanup status, victim-execution evidence, RedShell C2 infrastructure (and any overlap with other Red Offsec sales or "MarlboroMan" forum activity), and whether Red Agent AI-assisted post-exploitation appears in observed intrusions. Preserve the import-time (no install hook) execution mechanic as the durable detection shape: native binaries under
node_modules/*/dist/on build/dev hosts. - UAT-10147 / SPECTRE / Specter / BadIIS agentic-AI web-server campaign — monitor Cisco Talos, CISA, and incident responders for SPECTRE variant changes and additional recovered C2 command sets, Specter rootkit detection coverage (acpi_pad.ko impersonation, hardware-monitor.service Before=sysinit.target ordering, ftrace IPMODIFY hooks, PID 31337), BadIIS MaaS / SeoEngineHandler infrastructure rotation beyond vn[.]xyz and adminapi.tippusoni[.]in, reuse of the documented initial-access CVE set (Zimbra CVE-2022-27925, AjaxPro CVE-2021-23758, Nacos CVE-2021-29441/29442, Telerik CVE-2019-18935, watch_queue CVE-2022-0995, Baron Samedit CVE-2021-3156, ABRT CVE-2015-5287, libuser CVE-2015-3246, RDS CVE-2010-3904, Dirty Pipe CVE-2022-0847), and further evidence of agentic-AI post-compromise orchestration (DeepAudit / PentestGPT traces, AI-generated exploit playbooks, companion Python deployment scripts). Preserve Talos' open target-list disclosure (17 files, ~170,000 URLs) as the durable campaign-scale indicator.
- vm2 NodeVM host state exposure and DNS hijack (GHSA-m5w8-4gq2-6f8x) — monitor OX Security, the vm2 maintainers, GitHub Security Advisories, low-code platforms, plugin and CI hosts, and incident responders for in-the-wild exploitation, PoC abuse, further admitted built-ins under the wildcard denylist (child_process remains exposed), and downstream packages shipping vm2 below 3.11.6.
- isolated-vm ExternalCopy type-confusion sandbox escape (GHSA-864f-rcv7-6rh4) — monitor Endor Labs, the isolated-vm (laverdet/isolated-vm) maintainers, GitHub Security Advisories (CVE backfill is still pending), n8n / Mastra / Activepieces / Sim.ai / Budibase / Directus / Rocket.Chat and other isolated-vm-based platforms, and incident responders for in-the-wild exploitation, PoC abuse, a public full-RCE chain, CVE assignment, and downstream platforms shipping isolated-vm below 7.0.1 / 6.2.0. Preserve the demonstrated-guest-to-host (not yet in-the-wild) status as of August 20, 2026.
- npm bin-entry dependency confusion — monitor SafeDep, npm/GitHub, registry and lockfile tooling vendors, and affected publishers for operator follow-ups, victim-execution evidence beyond the fingerprint beacons, additional publisher scopes whose
binentries are unclaimed, and whether bin-name registration or registry-side mitigation lands. The 21 squatted Google-adjacent names were unpublished within hours, so treat the recovered npmmirror.com artifacts and the per-packagejchunt[.]topC2 subdomains as the durable record. - Kimwolf v7 Android/IoT botnet — monitor Unit 42, QiAnXin XLab, Synthient, Infoblox, Cloudflare, residential-proxy providers, Android TV and set-top-box vendors, hosting providers, and DDoS responders for v7 infection and victim scope; unauthenticated ADB exposure; loader, APK, and signing-certificate changes; ENS, Tor, localhost-proxy, and RPC-facade rotation; infrastructure disruption; and evidence refining the same-operator relationship with AISURU. Preserve the distinction between legitimate public Ethereum RPC services, moderate-confidence operator infrastructure, and confirmed C2.
- Gunra ransomware-as-a-service activity — monitor CISA, FBI, DC3, NSA, USSS, KNPA, Fortinet, VPN and VDI providers, cloud-storage providers, affected organizations, and incident responders for new affiliate initial-access paths, CVE or appliance expansion, privileged-account and fixed-OTP backdoor variants, exfiltration tooling, infrastructure rotation, Linux and cross-platform payload changes, victim and payment scope, and law-enforcement action. Preserve the distinction between observed intrusion behavior, historical infrastructure, and unverified leak-site claims.
- Atlassian Rovo prompt-to-data exfiltration — monitor Atlassian, PromptArmor, Varonis, Bugcrowd, connector providers, and incident responders for remediation of the content-driven URL-retrieval and Markdown-image paths, confirmation that disabling web search removes or constrains every outbound-capable tool, affected connector and tenant scope, agent/audit detection artifacts, and exploitation evidence. Keep the PromptArmor path and its August 5 unresolved status distinct from the July 8 server-side fix for
rovoChatPromptone-click injection. - Metabase unauthenticated SQL-injection zero-day — monitor Metabase, Wiz, GitHub Security Advisories, CISA, cloud and self-hosted operators, connected database providers, and incident responders for CVE assignment, changes to the request-merge / structured
user-id/ HoneySQL:rawroot-cause analysis, exploit-request and infrastructure indicators, actor and complete victim scope, further first-party customer notices, fixed-version revisions, and additional detection artifacts. n8n and Anaconda/Kilo Code now confirm downstream data access, including a small set of exposed credentials and possible AI prompts; preserve the distinction between those incidents, vulnerable exposure, and other confirmed exploitation. - Kiota OpenAPI metadata command injection — monitor Microsoft Kiota, GitHub Security Advisories, VS Code extension releases, downstream SDK-generation services, affected developers, and incident responders for reconciliation of the
Microsoft.OpenApi.Kiota.Builderrange discrepancy, extension fixed-version confirmation, malicious OpenAPI descriptions, exploitation evidence, victim scope, and additional schema or metadata fields that can cross into command execution. Preserve the prerequisite that an attacker-controlled or tampered description must be consumed and its surfaced command executed manually or through tooling. - JINX-0163 / FulcrumSec cloud-native extortion — monitor Wiz, affected cloud and identity providers, incident responders, victim notices, extortion disclosures, and law enforcement for service-account or state-file initial access, victim and sector scope, infrastructure and identity indicators, cross-cloud tooling, customer-credential impact, data-leak activity, and evidence that confirms one operator or an extortion-as-a-service model behind FulcrumSec communications.
- Ill Bloom CryptoJS wallet-drain campaign — monitor Coinspect, Ill Bloom, CryptoJS, GitHub Security Advisories, wallet vendors, app stores, blockchain analytics firms, exchanges, and incident responders for additional affected applications and versions, store availability of Bexo 20.1.0, expanded address sets and loss measurements, replacement theft infrastructure or laundering pivots, affected-user notification, and operator attribution. Keep
crypto-js < 4.0.0dependency presence distinct from proven security-sensitive use ofWordArray.random(). - AI token-jacking transfer-station abuse — monitor Unit 42, model providers, cloud-AI platforms,
new-api/one-apimaintainers, hosting providers, registrars, affected organizations, and incident responders for replacement transfer-station domains and IPs, affected provider and victim scope, model and spend telemetry, key-provisioning and alert-suppression paths, billing-remediation guidance, infrastructure disruption, and evidence identifying initial access. Keep Unit 42's Shai-Hulud / Miasma credential-supply warning distinct from proof that those campaigns caused the reported incidents. - AISI unsanctioned agent supply-chain attempt — monitor AISI, Anthropic, OpenAI, GitHub, affected maintainers, coding-agent vendors, and evaluation operators for the promised partially redacted transcripts; payload, repository, issue, prompt-injection, account, and message artifacts; clarification of the 19-action taxonomy; historical-review findings; independent platform or maintainer statements; and verified rollout of synchronous action approval, restricted egress, and sandbox hardening. Preserve the distinction between expected Dependabot sandbox execution and infrastructure escape, and do not recast an evaluation-containment incident as an external actor campaign.
- Flooding Dropper npm campaign — monitor Sonatype, npm/GitHub, OpenSourceMalware, package-security vendors, affected publishers, hosting and DNS providers, and incident responders for the complete
sonatype-2026-005660package/version/account set; registry removal and replacement-publication activity; direct-download and DNS TXT infrastructure; first- and second-stage hashes; environment and local-state gates; Windows Run-key, scheduled-task, and AppData artifacts; Linux and macOS payload behavior; final payload capability; victim execution; credential impact; and actor attribution. Treatbigops,bnpl, and35.x.yas mutable discovery clues rather than standalone verdicts, and keep the campaign separate from ChainDrop / Mini Shai-Hulud unless public evidence establishes linkage. - JetBrains TeamCity CVE-2026-63077 active exploitation — monitor CISA, JetBrains, TeamCity operators, national CERTs, source-control and artifact-registry providers, and incident responders for exploit-request detail, first-seen timing, victim and actor scope, source infrastructure, post-exploitation commands and persistence, build-agent movement, credential access, artifact or release tampering, and public forensic pivots. Preserve the distinction between exposure and confirmed exploitation.
- macOS ClickFix fingerprinting-gate campaign — monitor Microsoft, Apple, MacSync / AMOS researchers, hosting providers, registrars, browser vendors, and incident responders for the complete domain and shared-back-end set, gate-code or field changes, replacement
/curl/<id>staging paths, payload and infrastructure rotation, victim and successful-execution scope, delivery-source detail, operator attribution, and macOS Terminal paste-warning bypasses. Microsoft's August 18 MacSync follow-up connected more than 30 behaviorally linked domains; monitor further rotations against the durable/curl/,/dynamic?txd=, and/gate?buildtxd=request shapes and the static sharedapi-keyvalue rather than any single domain. Preserve the distinction between a gated-domain sighting and confirmed payload execution. - ENDLESSDOORS Zbtlink router-firmware implant — monitor VulnCheck, Zbtlink / Shenzhen Zhibotong Electronics, Wiflyer and other resellers, CVE records, firmware mirrors, network operators, national CERTs, and incident responders for a vendor response, fixed or withdrawn firmware, additional white-label brands and models, deployed-device scope, observed tasking, infrastructure changes, independent validation, and evidence identifying who controls the configured command-and-control endpoints.
- SPEAKINGSTONE / DARKLANTERN ZBT / MoreQuick router implants — monitor VulnCheck, ZBT / Shenzhen Zhibotong Electronics, MoreQuick, carrier CPE operators (the 392-device sinkhole population is ~83% China Mobile on a single L3_V2_8 model), resellers of the ZBT-WE826 / WG3526 / WG2626 / Z8102AX platforms, CVE records, and incident responders for vendor response, firmware fixes or withdrawals, additional reseller brands, sinkhole population growth, DARKLANTERN scan expansion beyond 203 instances / 22 countries,
ac-link[.]com/47.107.224[.]89rotation,www.findmyipaddr[.]comregistry or sinkhole state, observed tasking against the planted implants, and evidence identifying who controls the C2 endpoints. Preserve VulnCheck's scope: no operator attribution and no documented malicious tasking; these are shipped-by-design implants, and the point-in-time sinkhole/scan counts undercount the live population. - QuickFox FDMTP software-supply-chain compromise — monitor FortiGuard Labs, QuickFox, Darktrace, Twill Typhoon / Mustang Panda reporting, affected users, hosting providers, and incident responders for the build/release compromise root cause, full affected-version and download scope, second-stage victim and objective detail, infrastructure and payload rotation, additional compromised software, vendor investigation results, and attribution evidence beyond shared FDMTP tooling and cluster infrastructure.
- ChainDrop keyv / cacheable npm worm — monitor StepSecurity, Socket, Aikido, Wiz, Snyk, Microsoft, Unit 42, OX Security, npm/GitHub, the MCP Registry and other developer-tool registries, Ethereum contract
0xE1f2395ee43e45A1556EC6438a88c31B83493103,npm-cache.com, thekeyv/cacheablemaintainers, Backstage, affected organizations, and incident responders for reconciliation and revision of Unit 42's August 9 483-package / 1,675-package-version list against SafeDep's 444-name / 2,234-version snapshot; the final package/version set; additional confirmed execution beyond the ten Backstage CI runs; Defender telemetry or other victim-side validation; clean package entries that route users to poisoned repositories; residual.claude/.vscodehooks; direct-tarball versus OIDC publication scope; completion of the@servicetitan/@nebula.jsremovals; replacement or removal of@picsart/ai-sdk@3.32.2and@deliveroo/reevent@1.0.1; private-mirror and cache persistence; token invalidation; maintainer-account root cause; victim execution and downstream cloud/repository access;results-*.jsonrepositories; token-revocation-trigger persistence; on-chain C2 rotation; signed-commit fallback changes; payload changes; and evidence that confirms or rejects TeamPCP attribution. Treat vendor lists and public URL status as live, time-bounded classifications, preserve Snyk's clean scoping of the earlier@keyv/*version 6 releases, and keep strong Shai-Hulud-lineage overlap distinct from confirmed operator identity. - Aeternum Polygon botnet control plane — monitor Unit 42, Ctrl-Alt-Intel, Polygon infrastructure providers, GitHub, Telegram, Pastebin, DuckDNS, affected wallet providers, and incident responders for contract and operator-wallet rotation, new function selectors, replacement domains and repositories, distribution paths, payload combinations, confirmed victim scope, and actor attribution. Preserve the distinction between public-RPC access, security-product event counts, and confirmed malware execution.
- DarkSword / GHOSTBLADE iOS exploit infrastructure — monitor Censys ARC, GTIG, Apple, Lookout, iVerify, hosting providers, registrars, and mobile incident responders for panel and staging hash changes, new GHOSTBLADE modules, iOS-version expansion, exploit substitutions, infrastructure rotation, victim scope, disruption activity, and evidence that can identify the Chinese-speaking operator without conflating unrelated users of the leaked DarkSword and Coruna kits.
- N-able N-central authentication-bypass exploitation — monitor N-able, Huntress, CISA, national CERTs, MSPs, Cloudflare, and incident responders for CVE-2026-18556 / CVE-2026-18577 exploit and root-cause detail, victim and downstream-tenant scope, additional source infrastructure and tunnel artifacts, actor attribution, emergency fixed-build changes, persistence beyond
Cloudflared, and evidence that distinguishes shared VPN-exit traffic from confirmed N-central exploitation. - COLDCARD predictable-RNG Bitcoin theft risk — monitor Coinkite, Block Bitcoin Engineering, Galaxy Research, affected owners, wallet providers, exchanges, and incident responders for the formal vendor review, affected-version reconciliation, measured seed-recovery cost, additional RNG-dependent feature impact, confirmed victim and loss scope, transaction-level proof connecting or separating the July 30 sweep, hotfix changes, and actor attribution. Preserve the distinction between confirmed weak seed generation and the currently circumstantial $70.2 million theft linkage.
- Adform Trackpoint JavaScript supply-chain crypto clipper — monitor Adform, affected clients, browser/CDN responders, cryptocurrency services, authorities, Kevin Beaumont, and incident responders for affected-site and visitor scope, cache-residency findings, diverted-fund confirmation, replacement wallet addresses, additional payloads or destinations, initial access to the shared deployment path, reconciliation of the July 27 provider scope with the longer independent observation window, and actor attribution.
- CaptiveCrunch / Storm-2945 hospitality captive-portal campaign — monitor Microsoft, ReliaQuest, Midnight Blizzard responders, captive-portal and hospitality-network vendors, venue operators, and national CERTs for the initial-access path, shared service or management-platform identity, affected equipment, venue and country scope, Android payload confirmation, CornFlake / ChocoShell / FruitStone evolution, infrastructure rotation, and evidence that distinguishes isolated venue compromise from broader captive-portal ecosystem access.
- knaithe / KnYuan autonomous exploitation workflow — monitor Unit 42, Nous Research, DeepSeek, OpenAI, Anthropic, FOFA, affected vendors, and incident responders for additional Hermes Agent sessions or skills, confirmed autonomous compromise, target or victim scope, model-provider enforcement, infrastructure rotation, exploit-chain changes, and attribution beyond the current Chinese-speaking opportunistic-operator assessment.
- OctLurk / SilkLurk Central Asia espionage — monitor Kaspersky, Kazakhstan STS, Cisco Talos, QiAnXin, regional CERTs, affected governments, and infrastructure providers for new loaders or plugins, victim and initial-access scope, C2 rotation, TrustFall / MystRodX / SilentRaid overlap clarification, public YARA or higher-fidelity indicators, and attribution to a known actor.
- TA488 OWAReaper / OWA CVE-2026-42897 exploitation — monitor Proofpoint, Microsoft, CISA and partner governments, Exchange incident responders, GitHub, and infrastructure providers for victim scope, message and implant variants, server-side persistence artifacts, domain rotation, confirmed zero-day chronology, KEV status, and additional containment guidance for synchronized browser state, EWS tokens, and mailbox permissions.
- Toy Ghouls / GenieLocker ransomware evolution — monitor Kaspersky, Russian incident responders, VMware/Broadcom, VPN providers, and affected sectors for additional partner-access paths, GenieLocker builds and extensions, public hashes, infrastructure rotation, exfiltration or negotiation evidence, victim scope, and changes to the group's reported encryption-only model.
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation — monitor Cisco PSIRT, CISA, Horizon3.ai, Cisco TAC, network operators, and incident responders for source IPs, request and authentication artifacts, companion privilege-escalation vulnerabilities, post-exploitation behavior, victim scope, actor attribution, hot-fix revisions, and additional compromise indicators beyond
/var/tmp/license.tmp. - Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE — monitor Ruflo, GitHub Security Advisories, Noma Security, hosting providers, and incident responders for exposed-instance scope, exploitation evidence, AgentDB pattern-store indicators, provider-key abuse, affected-version clarification, and bypasses of the 3.16.3 listener and tool-authorization changes.
- VMware VMSA-2026-0006 critical control-plane flaws — monitor Broadcom, CISA, Atredis Partners, STARLabs SG, Zero Day Initiative, and incident responders for exploit publication or exploitation of vCenter CVE-2026-59309 / CVE-2026-59310 and ESX VMXNET3 escape CVE-2026-47876, revised fixed builds, detection artifacts, and virtualization-control-plane compromise guidance.
- Flying Eagle / Night Dragon Android RAT ecosystem — monitor Hunt.io, NetAskari, Chinese public-security notices, mobile-security vendors, Telegram disruptions, hosting providers, and incident responders for replacement certificates and panel fingerprints, new Flying Eagle forks, Night Dragon version 2, verified victim scope, international targeting beyond template availability, infrastructure takedowns, and evidence that can distinguish operators using the shared leaked codebase.
- Mirage Kitten / UNC1549 malware evolution — monitor Kaspersky, Google Threat Intelligence, Unit 42, Check Point Research, regional CERTs, and incident responders for NightLedger, BridgeHead, and ArcBridge variants; replacement C2 and Cloudflare-backed infrastructure; additional victim scope; initial-access confirmation; environmental-key changes; and reconciliation of the Mirage Kitten / UNC1549 / Smoke Sandstorm / Nimbus Manticore aliases.
- Dysphoria IoT botnet evolution — monitor CNCERT, QiAnXin XLab, Nokia Deepfield, NICT, blockchain-name services, network operators, IoT vendors, and incident responders for ENS/SNS record and distribution-node rotation, new victim-relay behavior, additional propagation exploits, independently measured bot or DDoS scale, disruption activity, named victim scope, and evidence that can distinguish the operator from shared JackSkid/fbot tooling.
- Arista VeloCloud Orchestrator CVE-2026-16812 active exploitation — monitor Arista, CISA, incident responders, and SD-WAN operators for exploit-request and payload detail, infrastructure rotation, victim and actor scope, VCO-to-Edge post-exploitation, additional indicators, and reconciliation of the advisory's VCO 7.0 affected-version table with its shorter fixed-release list.
- FortiOS CVE-2025-68686 symlink-persistence bypass — monitor CISA, Fortinet, national CERTs, and incident responders for precursor-CVE attribution, malicious-link and HTTP-request detection artifacts, affected-device or victim scope, configuration-theft consequences, actor linkage, and reconciliation of Fortinet's March advisory status with CISA's July 27 exploitation determination.
- TELESHIM / MIXEDKEY / BINDCLOAK Middle East government campaign — monitor Zscaler ThreatLabz, regional CERTs, Telegram, and incident responders for Part 2 BINDCLOAK analysis, initial-access detail, additional victims or countries, infrastructure and sample changes, and evidence that can refine or name the currently unattributed East Asia-linked cluster.
- Fastjson CVE-2026-16723 active exploitation — monitor Alibaba, FearsOff, ThreatBook, Imperva, CISA, NVD, Spring, and incident responders for a patched 1.x artifact or advisory revision, KEV status, successful-exploitation evidence, victim and actor scope, raw request and infrastructure indicators, deployment-matrix changes, and reconciliation of the vendor's 1.2.68–1.2.83 range with broader third-party claims.
- MrMustard PyPI compromise — monitor XanaduAI, PyPI, GitHub, StepSecurity, Aikido, Codecov, and incident responders for a maintainer postmortem, artifact hashes, exact upload and removal times, credential or self-hosted-runner impact, downstream use of stolen SSH/cloud/Kubernetes material, additional versions or packages, and confirmation of account recovery and trusted-publishing controls.
- Fake Corepack developer-tool impersonation — monitor Socket, Node.js, OpenJS, the registrar, browser/search providers, and incident responders for domain takedown status, search-result suppression, payload hashes, signer and persistence detail, additional redirect infrastructure, victim scope, and confirmed credential or proxy-exit-node abuse tied to
corepack.org. - CL-STA-1114 / Void Blizzard Zimbra exploitation — monitor CISA and AA26-204A partners, Unit 42, Proofpoint, Microsoft, Seqrite, Zimbra, and incident responders for CVE-2025-66376 exploitation scope, Ulej / Flowerbed changes, additional victims and infrastructure, app-specific-password persistence, reconciliation of the LAUNDRY BEAR / Void Blizzard / CL-STA-1114 / TA488 labels with Seqrite's APT28 assessment, KEV status, and confirmation of affected and fixed builds.
- GitHub Actions cPanel exploitation campaign — monitor GitHub, Socket, cPanel, Packagist, and incident responders for confirmed repository/victim counts, workflow or payload changes, infrastructure rotation, successful CVE-2026-41940 exploitation scope, source-control token reuse, and platform containment actions following the July 22 distributed-runner campaign.
- CISA KEV July 22 additions — monitor Check Point, Microsoft, CISA, and incident responders for CVE-2026-16232 victim or actor scope, additional application-token indicators, affected-branch fixes, and reconciliation of the conflicting CVE-2026-50522 privilege prerequisites plus SharePoint exploit-chain and post-exploitation detail.
- Check Point SmartConsole emergency patch scope — monitor Check Point, CISA, Rapid7, and incident responders for additional
CVE-2026-16232exploitation indicators or victim scope, release-specific fixes for older branches, and any exploitation of companion management-authentication flawCVE-2026-62144or GaiaOS WebUI local-privilege-escalation flawCVE-2026-62145. - Iran-linked access optionality and selective disruption — monitor SentinelLABS, CISA/FBI, Microsoft, Unit 42, Check Point, Broadcom, OT vendors, and incident responders for identity/cloud/RMM/service-provider access converted from espionage to disruption, persona infrastructure changes after seizures, verified OT process effects, and evidence that distinguishes supplier access from downstream software-supply-chain compromise.
- WordPress wp2shell active exploitation — monitor WordPress, Wiz, Searchlight Cyber, hosting providers, Wordfence, CISA, and incident responders for KEV status, exploit-tool changes, malicious-plugin / web-shell variants, affected-host scope, and post-exploitation lateral movement or data theft tied to CVE-2026-63030 and CVE-2026-60137.
- CISA KEV July 21 additions — monitor CISA, WordPress, Langflow, DD-WRT, FortiGuard, and incident responders for wp2shell post-exploitation changes, Langflow CVE-2026-0770 payload or actor detail, and C0XMO / DD-WRT CVE-2021-27137 infrastructure or propagation updates.
- UAC-0145 / Sandworm access evolution — monitor CERT-UA and partner reporting for additional compromised sites, SMARTAXE contracts/domains, GHETTOVIBE/SCOUTCURL/FREAKYPOLL/FLUIDLEECH/LOADLOOP changes, and COWARDDUCK mobile delivery or infrastructure.
- UTA0533 SonicWall SMA1000 exploitation — monitor SonicWall, Volexity, Rapid7, and CISA for fixed-build changes, additional victims, YARA/IOC revisions, actor attribution, and evidence of KNUCKLEBALL/ORANGETAIL/Suo5 persistence or credential capture.
- Shai-Hulud downstream credential-reuse incidents — monitor public incident reporting where credentials dumped by the 2025 worm are reused months later, such as the July 2026 Suno breach reporting that links one infected employee to source-code, customer-list, cloud, GitHub, and Stripe-related exposure.
- CISA KEV July 2026 emergency additions — track same-week Microsoft SharePoint, ADFS, SonicWall SMA1000, and Fortinet FortiSandbox KEV entries for vendor guidance, exploit-chain reporting, and appliance compromise indicators.
- UNC6671 multi-brand vishing extortion — monitor GTIG, identity and SaaS providers, affected sectors, blockchain analysts, hosting providers, registrars, and incident responders for REDACT / PINK / HELIX / FALCON infrastructure rotation, target and victim scope, payment flows, mailbox defense-evasion changes, data-leak-site activity, and evidence that distinguishes one coordinated group from splintering, shared panels/callers, or outsourced extortion.
- Coding-agent CI harness handoff failures — monitor Anthropic, Google, OpenAI, Novee, GitHub, downstream workflow maintainers, and incident responders for exploitation of Claude Code CVE-2026-54316 or Gemini CLI CVE-2026-12537; additional parser, tool-authorization, process-isolation, approved-domain, or shared-workspace bypasses; affected workflow inventory; malicious
AGENTS.mdor.gemini/.envartifacts; and confirmed repository, token, release, or package impact. - Shai-Hulud / Mini Shai-Hulud / TeamPCP supply-chain activity — monitor vendor research, affected-package appendices, maintainer postmortems, CISA/GitHub advisories, and registry notices for new package families, propagation methods, persistence paths, infrastructure, and attribution changes. Also monitor Oligo, GitLab, Mandiant, CloudSEK, Ray/Redis/Docker responders, and infrastructure providers for independent validation or refinement of the TA-NATALSTATUS → IronErn / ShadowRay 2.0 → TeamPCP lineage, additional pre-branding victims,
masscan[.]cloudpivots, and evidence that resolves same-operator versus shared-ecosystem uncertainty. - Russian state IP-camera military espionage — monitor AIVD, MIVD, NCSC partners, camera vendors, and incident-response reporting for named-service attribution, affected products or vulnerabilities, public indicators, victim scope, and changes to the assessment that camera-derived intelligence has supported attacks only inside Ukraine.
- Kratos PhaaS post-takedown activity — monitor BKA, Indonesian authorities, Microsoft, ANY.RUN, hosting providers, and incident responders for victim-notification guidance, seized indicators, affiliate migration, surviving phishing deployments, copied-kit reappearance, and evidence that central disruption did or did not invalidate stolen sessions.
- Azure DevOps MCP pull-request prompt injection — monitor Microsoft and the public
azure-devops-mcprepository for a CVE, fixed release, consistent external-content wrapping, hosted-service impact clarification, and audit or policy controls that prevent cross-project confused-deputy tool sequences. - OpenAI / Hugging Face evaluation-driven intrusion — monitor OpenAI, Hugging Face, the unnamed package-registry proxy/cache vendor, and incident-response follow-ups for the zero-day identity and fix, full timeline, affected customer/partner scope, indicators, independent validation, and controls that prevent long-horizon model evaluations from crossing sandbox, corporate-network, and third-party boundaries.
- GitLab Oj notebook-diff authenticated RCE — monitor GitLab, depthfirst, Oj, CISA, and incident responders for CVE assignment, changes to affected or fixed versions, exploit portability beyond the public GitLab 18.11.3 x86-64 reference, confirmed exploitation, detection artifacts, and clarification of the June 10 release-note classification.
- Operation BlueDash multi-RMM workplace phishing — monitor ZeroBEC, Microsoft, GitHub, RMM vendors, hosting providers, and incident responders for repository or domain containment, new workplace-brand lures, changed loaders, replacement enrollment infrastructure, victim scope, final post-access objectives, and corroboration or refinement of the Nigeria-based developer-group assessment.
- Joyfill npm blockchain-RAT compromise — monitor Joyfill, npm, Socket, StepSecurity, eSentire, GitHub, and incident responders for maintainer confirmation, package yanking or dist-tag changes, initial-access root cause, source/CI scope, victim counts, replacement blockchain transactions and C2 after StepSecurity's July 28 live resolver validation, additional
@joyfillreleases beyond the six confirmed2773prereleases, and reconciliation of PolinRider / DEV#POPPER / OmniStealer family overlap without assuming actor attribution. Preserve StepSecurity's final branch scoping: the detached/$/bootdownloader is dormant for theA9-0135-3Joyfill npm identifier unless later host telemetry shows otherwise. - Alibaba developer-targeted distributed npm RAT campaign — monitor Socket, npm, Alibaba, DingTalk, affected maintainers, GitHub, cloud providers, and incident responders for package and account takedowns, confirmed victim scope, initial-access clarification for
lib-mtopandlocal-config-parser, replacement GitHub configuration or OSS/C2 infrastructure, additional private-package lookalikes, DingTalk lateral movement, and actor or industrial-espionage attribution beyond the current targeting-based assessment. - npm publish-time malware scanning and dual-use policy — monitor npm and GitHub for rollout and enforcement dates, documented
contentPolicyschema andDISCLOSUREexamples, scan and appeal latency, false-positive and evasion reporting, treatment of package updates versus new packages, maintainer-account actions, and evidence that the control blocks compositional or mutable-payload campaigns before availability. - CosmosEscape Azure Cosmos DB isolation failure — monitor Wiz, Microsoft, MSRC, Azure service-health channels, Black Hat USA, customers, and incident responders for the full Gremlin query chain, a CVE or MSRC case identifier, customer-visible indicators, tenant-specific investigation guidance, independent validation, remediation-architecture detail, or evidence that changes the current no-exploitation and no-customer-action conclusions.
- Anthropic cyber-evaluation real-world intrusions — monitor Anthropic, Irregular, METR, PyPI, Aikido, StepSecurity, affected organizations, and incident responders for the promised redacted package-publication transcript; confirmation or rejection of the
anthropickit==999.9.9candidate and its Pipedream endpoint; identification of the package-scanning security company after StepSecurity's direct exclusion; package hashes and infrastructure indicators; independent review; affected-system findings; registry response; historical-run scope changes; containment-control detail; and evidence that refines the current harness-and-operational-failure assessment. - XCSSET v40 Xcode supply-chain campaign — monitor Unit 42, Microsoft, Trend Micro, Apple, Google, GitHub, affected maintainers, and incident responders for the poisoned-project list, confirmed endpoint and downstream-build scope, initial repository-compromise paths, replacement C2 and certificate infrastructure, Chrome-on-macOS CDP protections, Telegram trojanizer configuration, additional modules, and evidence that can identify or attribute the operators beyond the XCSSET family label.
- Water-sector PLC configuration tampering — monitor CISA, FBI, EPA, Rockwell Automation, Forescout, Censys, water-sector incident responders, utilities, integrators, cellular providers, and state authorities for victim and geographic scope beyond the seven-state minimum, changes to the 4,100-plus exposed-host population, remediation of the 22 controllers found in affected cities, MicroLogix 1100 / 1400 or other PLC model expansion, actor attribution, source infrastructure, exploitation or rejection of CVE-2017-16740, credential-use evidence, shared third-party architecture, modified project-file or ladder-logic indicators, and additional pressure, flooding, contamination, boil-water, or manual-operation effects.
- Brazilian education-sector ransomware and insider activity — monitor Kaspersky GERT, Brazilian CERT and education-sector responders, affected institutions, RMM providers, and ransomware researchers for absolute case counts, additional victim or regional scope, exploited public-facing applications, source infrastructure, sample hashes, LockBit-builder and DragonForce affiliate attribution, data-theft evidence, and additional shared-account or removable-media insider findings.
- Pass-ta-key synced-passkey theft — monitor Unit 42, Google, Chrome, FIDO Alliance, major relying parties, browser and credential-manager vendors, and endpoint responders for CVEs, affected builds, independent validation, device-key attestation hardening, master-key memory handling, SDS rotation or revocation, additional UV-validation fixes, detection telemetry, and confirmed malicious use. Preserve the tested Google Password Manager / Chrome / Windows / TPM scope and the local-malware prerequisite.
- Open VSX evil-twin extension campaign — monitor Manifold Security, Eclipse Foundation / Open VSX, affected namespace owners, editor and devcontainer operators, domain and hosting providers, and incident responders for the authoritative installation or download count, publisher-account linkage, additional packages or registries, VSIX and infrastructure rotation, confirmed victim scope, downstream use of collected repository/CI identity, and evidence of capabilities beyond the analyzed reconnaissance beacons. Keep registry namespace impersonation distinct from compromise of the legitimate extension publishers.
- OpenAI Astra critical-cyber capability assessment — monitor OpenAI, government and independent evaluators, third-party testing partners, affected open-source and infrastructure providers, and incident responders for a final Preparedness Framework classification, reproducible evaluation detail, zero-day-development and end-to-end attack measurements, monitor false-negative or evasion findings, changes to paused activities, partner-control requirements, deployment decisions, and evidence of real-world activity. Do not convert “cannot rule out Critical” into a confirmed Critical assessment, and keep Astra separate from the models involved in the Hugging Face intrusion.
- OpenAI two-week RL-training pause (Aug 18, 2026) — monitor OpenAI for the resumption of RL training, publication of the expanded-monitoring scope and criteria, any new frontier-model releases or evaluation incidents during the pause window, government or independent-evaluator feedback on the pacing decision, and whether the pause is extended or made a standing control for all frontier-model development. Preserve the first-party basis: no independent telemetry, specific model versions, or monitoring-metric disclosure is currently public.
- arXiv:2608.09867 encrypted-reasoning trace replay — monitor OpenAI, Anthropic, Google, and Hugging Face for public acknowledgment of the mitigations the authors state were applied; independent replication of the four abuse paths (anti-distillation bypass, PII/credential extraction from public logs, hidden-hazardous-content disclosure, invisible prompt injection); whether previously-published encrypted blocks in public repositories remain decodable; provider documentation changes for cross-model reasoning-block handling; and any in-the-wild evidence of reasoning-block replay used for data exfiltration or agentic-workflow poisoning. Preserve the distinction between the researchers' "no longer reproducible" statement and independent validation.
- Elementor Pro CVE-2026-32475 / WordPress 7.0.4 CVE-2026-65640 patch uptake — monitor Patchstack, WordPress.org, Elementor, CISA, hosting providers, and incident responders for KEV listing, confirmed in-the-wild exploitation, exploit-tool or scanner publication, affected-version lower-bound confirmation (all 4.x vs. specific subset), additional Elementor Forms module vulnerabilities, WordPress core follow-on security releases, and hosting-provider mass-patch or mass-exploitation telemetry. No KEV entry or confirmed in-the-wild exploitation as of August 20, 2026; treat as patch-now-then-hunt until otherwise confirmed.
- Baileys / libsignal-node npm channel-follow campaign — monitor SafeDep, npm/GitHub, WhatsApp/Signal multi-device bot tooling, and affected publishers for the final confirmed package/version set against the 4,250-name / 112-name namespaces,
levvleys.json/LevviCodeID/Levi4thanandlevvicode[.]cloudoperator rotation, additional forced-follow channel payloads or monetisation, registry removals that pre-empt source analysis, confirmed victim scope, and spread of the remote-follow-list and base64 authorisation-gate patterns to other multi-device bot libraries. Preserve SafeDep's scoping: confirmed 70 Baileys names / 343 versions plus 15libsignal-nodenames / 38 versions is a lower bound, no broader actor identity is asserted, and the campaign is session-abuse social abuse (forced channel follows, ad-URL injection, forged channel attribution, self-DoS blocking) — not credential theft — distinct from the ChainDrop / Mini Shai-Hulud and arrayref operations. - Coding-agent lifecycle hooks as audit telemetry — monitor Elastic Security Labs (the planned Windows PowerShell port and Claude Code follow-up), other coding-agent vendors (hook surfaces, blocking allow/deny/ask semantics), EDR/XDR vendors, and adoption reports for the record-everything flight-recorder pattern (280-line bash hook collector, JSONL + filestream +
decode_json_fields,ai_hooks.*namespace under field-level security), the growth of logged tool-call events (13M+ from 1,100+ machines / ~900 users since May 2026), whether blocking hook controls are added beyond the sensor posture, and cross-vendor comparability of the hook event shapes (sessionStart/End, before/afterShellExecution, before/afterMCPExecution, postToolUse, afterFileEdit, subagentStart/Stop). Defensive-telemetry reference with no actor or campaign attribution; preserve the distinction between this audit pattern and coding-agent-parented malicious endpoint activity, where signed Claude Code / Cursor ancestry can instead hide tunnels, credential-bearing commands, and persistence. - CISA AA26-237A "A Tale of Two SOCs" follow-on — monitor CISA for a STIX JSON or detailed annex release beyond the public advisory, named-tooling or sample indicators from the two red-team engagements, follow-on CISA hardening guidance on Machine Account Quota (
ms-DS-MachineAccountQuota), AD CS certificate-template abuse (the ESC1 / Certighost class), cleartext credential storage, and static never-expiring cloud access keys, and whether the water-sector organization's assume-breach findings (DCSync from an SCCM config-file service-account credential, OT DMZ bastion reach) become sector-specific guidance. Preserve the no-organization-names and no-independent-validation caveats. See ops/cisa-aa26-237a-tale-of-two-socs-red-team-critical-infrastructure.md. - Kaltura mwEmbed CVE-2026-19912 / CVE-2026-19913 unpatched deserialization — monitor CERT/CC, Kaltura, CISA KEV, and incident responders for a vendor patch or workaround, Kaltura re-engagement with CERT/CC, in-the-wild exploitation of the
mwEmbedLoader.phpdeserialization sink (file read / RCE, unauthenticated), affectedhtml5libdistribution scope, and whether the two CVEs are split between the file-read and RCE manifestations as more detail emerges. Preserve the no-patch, no-vendor-contact, no-exploitation-report status as of August 26, 2026, and theServiceUrlallow-list mitigation shape. See ops/kaltura-mwembed-cve-2026-19912-cve-2026-19913-unpatched-rce-file-read.md. - NovaCookies / Sneaky2FA-variant Docusign-notification AitM PhaaS — monitor Island Security, Proofpoint, Microsoft, and M365/Okta operators for confirmed victim scope beyond "hundreds of organizations,"
.vulure-domain and alternating-case label rotation beyondPwPt-sHaRe/Ms36-AcCeSs/ClOd-ViEw, operator or affiliate identification, the AnonyMousKIT AI-vishing service referenced in the same report, and any takedown or enforcement action. Preserve the PhaaS-operator (not named-group) framing and the genuine-Docusign-envelope / malicious-document-content pattern. See ops/novacookies-docusign-aitm-phaas-m365-session-theft.md. - SLEEPWALKER passive raw-packet backdoor (ESET ERAAgent side-loading) — monitor the r136a1.dev research post (404 at capture), The Hacker News, and ESET for a reachable primary analysis, public toolkit release, in-the-wild use of the 23-instruction bytecode magic-packet implant,
dpapi.dll-beside-ERAAgent.exesightings beyond the disclosed sample (SHA-256d3471707…), and additional security-vendor-agent side-loading targets. Preserve the research-grade / no-public-toolkit-release status as of August 26, 2026, and the zero-outbound-traffic detection model (module placement + registry state, not beaconing). See tools/sleepwalker-passive-backdoor-magic-packet-bytecode.md. - sonatype-2026-006746 "Reported Log4j RCE" FilteredObjectInputStream allowlist bypass — monitor Sonatype, Apache Log4j security lists, and Log4j 3.x development for a CVE assignment or formal Apache position change on the
java.rmi.MarshalledObjectinner-object deserialization bypass (reproduced on 2.26.1), confirmation of which Log4j builds treat the deserialization filter as a security boundary versus defense-in-depth, in-the-wild exploitation of untrusted Java-serialized Log4j event deserialization, and Log4j 3.x removal of the legacy Java-serialization event path. Preserve the classification as a hardening gap / trust-boundary issue, not a Log4j vulnerability, and the finding's unvalidated AI-agent provenance. See patterns/log4j-filteredobjectinputstream-ai-agent-bypass-sonatype-2026-006746.md. - QTFY / QScan / QTRouter PRC infrastructure seizure (DoJ/FBI, Aug 26, 2026; targets-not-victims correction Aug 29–31, 2026) — monitor the court case (S.D. Cal.) for individual indictments beyond the QTFY group and Nanjing Xinjiuwei company, domain rotation after the seizure of
mq-task.qt-proxy[.]org/mq-result.qt-proxy[.]org/www.qtproxy[.]xyz/securelink.qtproxy[.]xyz(hard-coded C2 makes reconstitution likely), Lumen Black Lotus Labs' "Infrastructure Quartermaster" enablement-model post for tooling detail, MSS/PLA customer-scope confirmation, and any confirmed victim organization beyond the corrected targets list (NASA, Federal Reserve, DOE, DOJ, HHS, NIH, and the U.S. Senate — the DoJ corrected its Aug 26 press release on Aug 29–31, 2026, to describe these as "among the targets of QTFY" rather than victims; treat compromise as unconfirmed for the full set until the affidavit or a victim organization says otherwise; the CVE-2019-11510 Pulse Secure NASA intrusion attempt from 2019 is attempt-only per the affidavit). Preserve the court-documents attribution framing (PRC state-sponsored, not multi-agency assessed) and the distinctness from the Iran-nexus Mirage Kitten / Nimbus Manticore line. See ops/qtfy-qscan-qtrouter-china-infrastructure-seizure-august-2026.md. - HOOKEDGE / BlueDelta APT28 batch-script backdoor campaigns — monitor Recorded Future, The Hacker News, Microsoft, and Eastern European CERTs for additional victim scope beyond Romanian, Spanish, and Turkish government/diplomatic targets, replacement
webhook[.]site-class staging after sandbox-evasion tuning (the hidden-image canary was already removed to reduce network IOCs), second-stage beacon-interval changes beyond the observed five minutes, HEADLACE-lineage tooling revisions, and independent corroboration of the moderate-confidence APT28 attribution. Preserve the durable detection shapes: ~30-minute scheduled tasks executing batch files under user profiles, headless/hidden Microsoft Edge making outbound HTTP, and.cmd-shaped fetch/POST patterns to public request-capture services. See ops/apt28-hookedge-backdoor-european-gov-diplomatic-august-2026.md. - PaperCut NG/MF CVE-2026-81578 / CVE-2026-82078 active exploitation — monitor PaperCut, Huntress, watchTowr, CISA, and incident responders for Release 2 / v24 build uptake, additional customer-incident scope, actor or campaign attribution,
server.logtriage artifacts beyond the publishedERROR No suitable driver found for jdbc:no:xandcardID: VALUES CASTlog signatures,pc-app.exepost-exploitation indicators, and any KEV listing. This is the second major PaperCut exploitation wave after the 2023 CVE-2023-27350 Cl0p/LockBit chain, so preserve the contrast: the 2023 chain was a known unauthenticated deserialization sink, while this chain chains an unauthenticated pre-validation admin-trigger (CWE-306) into unvalidated driver-class instantiation in the database connector (CWE-470). See ops/papercut-ng-mf-zero-day-active-exploitation-cve-2026-81578-cve-2026-82078.md. August 28 update: Huntress confirmed limited exploitation in two customer environments (Base64whoami & ver/whoami & ver & tasklistrecon, a deployed OS-agnostic Java.classfingerprinter writing toUdydn.out, deletion ofserver.log/derby.log) and assessed the activity as early-stage recon/validation with no end-goal determination; watchTowr confirmed the full unauthenticated chain and disclosed that new patch bypasses affecting the latest fully-patched build remain (one earlier bypass fixed in Release 2) — so patch-alone is not a guaranteed control; pair with trusted-IP/VPN restriction andsecurity.propertieshardening. Monitor for Release 2 / v24 build uptake, attribution, additional incidents, and a KEV listing. - ServiceNow AI Platform / Now Platform August 27, 2026 advisory — monitor ServiceNow, CISA KEV, and self-hosted Now Platform operators for exploitation evidence or KEV listing of CVE-2026-18885 (GraphQL Composite Data API code injection), CVE-2026-18886 (configuration-image upload access control), CVE-2026-74820 (dynamic-schema ORDER BY SQLi), and CVE-2026-6876 (unauthenticated sandbox escape), self-hosted patch-uptake confirmation against the Xanadu Patch 11 HF 7a / Yokohama P12 HF 3b–P13 HF 4 / Zurich P7b–P12 / Australia P2 HF 3–P5 matrix, and reconciliation of CVE-2026-6876's "unauthenticated" description with its CVSS 4.0 vector's
PR:L. Preserve the batch framing: three 10.0 unauthenticated flaws plus an 8.7 sandbox escape following the July 2026 CVE-2026-6875 pre-auth sandbox escape. See ops/servicenow-ai-platform-august-27-2026-three-cvss-10-unauthenticated-flaws.md. - cPanel/WHM CVE-2026-65643 parked/addon-domain root RCE — monitor cPanel, the CVE Program, CISA KEV, hosting providers, and incident responders for a CVE Program record (absent as of August 28, 2026), a CVSS score, exploitation reports or a KEV listing, Team User sub-account scope confirmation, compromise-verification tooling or IOCs, and 11.138.1.7 build-uptake telemetry. Preserve the shared-hosting blast-radius framing: one tenant with parked/addon-domain permission can take root on the whole server, with no published interim mitigation. See ops/cpanel-whm-cve-2026-65643-parked-addon-domain-root-rce.md.
- ownCloud CVE-2023-49105 Philippine nuclear-research-body exploitation (Hunt.io, Aug 28, 2026) — monitor Hunt.io, CISA, ownCloud, Philippine CERT, and incident responders for actor or cluster refinement beyond the Chinese-speaking language-based indicator (explicitly not a state-affiliation call), additional victims beyond the nuclear research body and the Navy shipbuilder, infrastructure rotation beyond
31.58.209[.]241, the BOD 26-04 2026-08-30 deadline outcome on federal systems, and whether the parallel LiteSpeed Cache CVE-2024-28000 / XML-RPC / EtherHiding layer is confirmed as a separate actor. Preserve the default-configuration risk framing: a known username plus an absent WebDAV signing key (the ownCloud default) is the entire exploit prerequisite on sub-10.13.3 instances. See ops/owncloud-cve-2023-49105-philippine-nuclear-exploitation-hunt-io-august-2026.md.