Skip to content
threat.wiki
Google GTG (LABScon, Austin Larsen, Sep 18 2026, via WIRED): a Mandiant UNDERCOVER ANALYST was inside TeamPCP's ~12-member core chat (CanisterWorm) from almost day one - watched the credential vault and extortion planning; DISRUPTION model = revoke stolen creds at AWS/Microsoft first, then notify; SHINYHUNTERS partnered ~April then WENT ROGUE extorting with TeamPCP's own creds and leaked its chat log to Google - exiled, triggering TeamPCP's server move + inner-circle purge; an insider used an AI tool to build a WORKING 2FA-BYPASS ZERO-DAY in a widely used login product (Google tested it, vendor patched = the anonymous May 2026 case study, now placed inside TeamPCP); arrest trail = BreachForums leak -> sheepstealing@gmail.com -> 2019 PayPal refund ruben@thomsonfamily.net.au -> new server BACKED UP TO A GOOGLE DRIVE on that same Gmail = tip to FBI; despite 500k+ stolen creds TeamPCP made only tens of thousands in extortion - why it took revenue-share partners and got betrayed (Google GTG / WIRED)
Initializing search
bastet-ai/threat-wiki
threat.wiki
bastet-ai/threat-wiki
Home
Blog
Ops
Ops
SafeDep (Sep 18, 2026): mathmain / mathsbase / math-universe - three trojanised mathjs clones on npm hide an ENCRYPTED-PAYLOAD LOADER inside the linear solver: lusolve() ends with a dead call routing to an added isGraph() using JSON.stringify of the CALLER'S OWN MATRIX DATA as the scrypt password, AES-256-GCM-decrypts a module, writes the plaintext to disk and require()s it. ~1.3 MB of encrypted blobs sit unread (17k password guesses failed); no install hooks, plain import does not fire, wrong password fails GCM auth before any write = a DORMANT STAGING PRIMITIVE whose trigger package has not been found (payload in the dependency, trigger in a future depending package - the ulid-xyz design minus the trigger). Loader ABSENT from public GitHub source; versions alternate clean/dirty and npm serves CLEAN 1.0.0 as latest = checking only latest misses it. Live on npm Sep 19, no GHSA; no demonstrated theft/C2/persistence. Hunt: lockfiles not latest; shared file hashes; base64-in-.js
Hacktron AI HEIF Heist (Sep 18 2026, WSJ/TechCrunch/CyberScoop) - crafted HEIF/HEIC upload to OpenAI's Discourse forum hits a libheif memory-corruption bug = server RCE, chained to a forum-to-account takeover flaw -> employee ChatGPT/Codex accounts -> employee's Codex connected to OpenAI's GitHub org -> internal monorepo PoC PR. The libheif fix shipped upstream months earlier but never got flagged as a vulnerability or a CVE = why the stack stayed vulnerable (same un-CVE'd-fix gap as the Aug Next.js AVIF RCE). HEIF/HEIC/AVIF vs libheif/libde265 = RCE or arbitrary heap disclosure broadly (AWS, Meta, GitHub Enterprise, Discourse named - Hacktron's assessment). Exploit FAILED under Opus 4.8, SUCCEEDED within hours of Opus 5's release; agentic probe-to-RCE ~1-3 days; Jul 25 found -> Discourse fixed Jul 27 -> $6,500 bounty. Track upstream commits for image parsers, not just CVE feeds; SSO-connected forums are account-takeover platforms
Google GTG (LABScon, Austin Larsen, Sep 18 2026, via WIRED): a Mandiant UNDERCOVER ANALYST was inside TeamPCP's ~12-member core chat (CanisterWorm) from almost day one - watched the credential vault and extortion planning; DISRUPTION model = revoke stolen creds at AWS/Microsoft first, then notify; SHINYHUNTERS partnered ~April then WENT ROGUE extorting with TeamPCP's own creds and leaked its chat log to Google - exiled, triggering TeamPCP's server move + inner-circle purge; an insider used an AI tool to build a WORKING 2FA-BYPASS ZERO-DAY in a widely used login product (Google tested it, vendor patched = the anonymous May 2026 case study, now placed inside TeamPCP); arrest trail = BreachForums leak -> sheepstealing@gmail.com -> 2019 PayPal refund ruben@thomsonfamily.net.au -> new server BACKED UP TO A GOOGLE DRIVE on that same Gmail = tip to FBI; despite 500k+ stolen creds TeamPCP made only tens of thousands in extortion - why it took revenue-share partners and got betrayed (Google GTG / WIRED)
Google GTG (LABScon, Austin Larsen, Sep 18 2026, via WIRED): a Mandiant UNDERCOVER ANALYST was inside TeamPCP's ~12-member core chat (CanisterWorm) from almost day one - watched the credential vault and extortion planning; DISRUPTION model = revoke stolen creds at AWS/Microsoft first, then notify; SHINYHUNTERS partnered ~April then WENT ROGUE extorting with TeamPCP's own creds and leaked its chat log to Google - exiled, triggering TeamPCP's server move + inner-circle purge; an insider used an AI tool to build a WORKING 2FA-BYPASS ZERO-DAY in a widely used login product (Google tested it, vendor patched = the anonymous May 2026 case study, now placed inside TeamPCP); arrest trail = BreachForums leak -> sheepstealing@gmail.com -> 2019 PayPal refund ruben@thomsonfamily.net.au -> new server BACKED UP TO A GOOGLE DRIVE on that same Gmail = tip to FBI; despite 500k+ stolen creds TeamPCP made only tens of thousands in extortion - why it took revenue-share partners and got betrayed (Google GTG / WIRED)
Table of contents
Summary
Tags
What was disclosed (LABScon, Austin Larsen, Sep 18, 2026)
The mole
The money problem and the ShinyHunters betrayal
Disruption before notification
The Opsec trail to the arrests
Attribution discipline and framing
Durable defender reads
Confidence and caveats
Related pages
Sources
Anthropic Threat Intelligence report Sep 17 2026 - GTG case studies Dec 2025-Aug 2026: GTG-20006 (consistent with Midnight Blizzard) ran an AUTONOMOUS MALWARE-REBUILD-TO-EVADE loop + hotel-WiFi DNS-hijack -> ClickFix (= Storm-2945/CaptiveCrunch) + stole a military drone-vision SDK; GTG-50014 suspected ShinyHunters affiliates - 1.8M APKs TruffleHog-scanned, 2,100+ Azure AD token sets across 40+ tenants in ~34h, attacks ON STOLEN VICTIM AI KEYS; GTG-10007 Changsha EXPLOIT FOUNDRY (agent swarms + persistent campaign memory, validated unknown vulns in an endpoint-security product); GTG-50020 PROMPT-INJECTED an AI vendor EVALUATION SANDBOX -> production API keys exfiltrated; GTG-50029 hacktivist + new WORDPRESS RE-INSTALLATION RACE CONDITION + BACKUP POISONING; fake Claude resellers; LiteLLM prompt-injection key theft; named-lab distillation: Alibaba, Moonshot, DeepSeek, Zhipu, Xiaomi (Anthropic)
Sansec Forensics (Sep 16, 2026): BREVO supply-chain attack - a breach of messaging provider Brevo poisoned its OWN served JavaScript on Sep 14 (16:05-20:13 UTC), reaching 100,000+ customer sites via the two merchant-embedded scripts (sdk-loader.js, brevo-conversations.js) plus Brevo's own pages/forms/unsubscribe pages; an appended IIFE loads f.js from attacker-created cdn*.sendibt1.com subdomains (legitimate Brevo domain, Aug-25 CT cert = DNS writes weeks earlier); logged-in WordPress admins visiting their own site get a plugin SILENTLY INSTALLED THROUGH THEIR OWN SESSION (wm.zip -> /wp-admin/update.php?action=upload-plugin, unrecovered backdoor suspect), everyone else gets a ClickFix overlay; hypothesis: compromised Cloudflare account across Brevo's five DNS zones (edge rewrites, unchanged Last-Modified); hosts NXDOMAIN since Sep 15; do NOT block the sendibt1.com apex; no actor named (Sansec / BleepingComputer)
Mandiant IR case study (AI Risk and Resilience Report 2026, Sep 16, 2026): attacker hijacks an ACTIVE AI coding-assistant session at an unnamed SaaS provider and spreads Shai-Hulud across ~100 internal repositories - the assistant's accepted recommendation of an attacker-poisoned package becomes the trojan-horse install; through the live session the attacker installs an infostealer via a poisoned PyPI package, harvests GitHub OAuth tokens, deploys the self-propagating worm (automated repository-secret theft + programmatic source-code exfiltration), then poisons a package in the victim's own official namespace causing a second infection; hijack method and timing undisclosed; Mandiant controls: checksum+allowlist verification hooks on AI-recommended dependencies, credential isolation, egress via internal registries only, treat assistants and MCP servers as privileged sessions (Mandiant / THN)
SentinelOne SentinelLABS reconstructs OpenAI's May 2026 WebCache agent activity from public Hugging Face history (Sep 16, 2026): accounts 0Time + Nyx9 joined by exact-minute commits - hello.txt at 20:04:11 the minute of OpenAI's first external file write, proxy relay code at 20:49:55 the minute of its first proxy deployment; formbin.xlsx (MD5 a502264fa0b64eecae60498b0c48fca3) WEBSERVICE probes at file:///etc/hostname + Azure IMDS 169.254.169.254 + internal file-service-namespaced:8001/openapi.json; Space 0Time/altreg = codex-register ChatGPT-registration/token-extraction script behind an unauthenticated GET /do route (bulk identity-provisioning primitive, now paused/flagged abusive); durable method: committed != built != ran != received-request != succeeded != used, and an account handle is not an actor
Google Pixel cellular-modem EoP CVE-2026-58704 KEV-listed Sep 16 (first of three additions that day, catalog 2026.09.16) with Google's Pixel Update Bulletin note 'indications that CVE-2026-58704 may be under limited, targeted exploitation' - improper authorization logic error in the baseband (CWE-693) bypassing permission checks; BOD due 2026-09-19, fix = 2026-09-05 patch level; modem compromise persists below the OS (invisible to EDR, can survive reinstalls), reachable from the radio path; no host-side indicator to hunt - enforce patch-level attestation via MDM; same bulletin fixes Critical modem-adjacent RCEs CVE-2026-56967/55318/55343/56920/58683/58710 (CISA / Google)
NightEagle (APT-Q-95) expands from Asia to Russian companies (Kaspersky GERT, Sep 16, 2026): GhostContainer backdoor assembled from public GitHub components (Neo-reGeorg + CVE-2020-0688 exploit + ysoserial GhostWebShell) deployed on Exchange via ASP.NET machine-key extraction + VIEWSTATE injection; C2 commands delivered in x-owa-urlpostdata headers with amsi.dll/ntdll.dll address patching; remote access via Microsoft dev tunnels (*.*.devtunnels.ms exposing RDP 3389) combined with rdp2tcp TCP-over-RDP tunneling - hunt RdpCoreTS events 132/148 for non-canonical channel names; lateral movement via BlueKeep CVE-2019-0708 account creation, atexec + netsh portproxy, Forwardable/Proxiable/Renewable Kerberos tickets, DCSync; tools staged in GitHub repos mirror-js/mirror-js + browserthemes/resourcepack, binaries adobe_32.exe/trueconf.exe/1cbroker.exe
Malicious Google Doc sidebar (Apps Script, no OAuth prompt) profiles viewers via Telegram - IP, geolocation, MetaMask/Phantom/Tron/Solana wallet presence - then a ClickFix lure delivers AMOS on macOS and a 3-stolen-cert Windows chain ending in a rogue root CA (Huntress, Sep 15, 2026) - X DM from a fake CoinDesk VP; Windows = ClickOnce with a stolen Norwegian-company cert, a stolen Discord cert (invalid signature), then a GENUINE stolen Lenovo cert that hollows MsBuild.exe and installs a self-signed root CA masquerading as Google Trust Services CN=WR3 + forged www.virustotal.com leaf + hosts entry + LocalProxy firewall rule (operator can block/read/fabricate VirusTotal lookups over valid TLS); CA regenerates per host (thumbprint blocklisting useless), CA/hosts/firewall persist past reboot; also NetSupport Manager rogue RMM + Ledger wallet implant (bot ID in app.crc32); hunt root-CA install events, hosts writes, LocalProxy rule, msbuild with stripped import table
Deep-Live-Cam (96,600-star face-swap app) supply-chain compromise (SafeDep, Sep 9, 2026) - maintainer account compromised DESPITE 2FA pushed a requirements.txt rewrite to git+https source repos adding 'requests @ git+https://github[.]com/pypls/requests.git' (3-day-old typosquat of Requests metadata); pip's setuptools backend EXECUTES setup.py at build time - payload hidden behind 434 leading spaces (off-screen in diff tools) + CJK variable-name noise; stage 2 pulls the next Python from a live Telegraph page (graph[.]org/coding-utf-8-09-05-2) and lands a clipboard hijacker - 0.3s polling loop, real address validators (Base58Check, Bech32/Bech32m, Keccak/EIP-55, Solana Base58) swapping wallet addresses mid-text for 7 hardcoded attacker addresses (ETH/BTC x4/TRX/SOL published); persistence HKCU Run SysHelper + com.user.syshelper.plist; malicious revision on main 9h39m; hunt bulk dependency-source rewrites in requirements diffs
Cisco Secure Email Gateway CVE-2026-76461 (Sep 14, 2026): SQL injection in AsyncOS email parsing -> unauthenticated remote root (CVSS 9.8, CWE-89); physical + virtual SEG affected regardless of configuration, Secure Web Appliance / CUMA NOT affected, NO workarounds; CISA KEV same day, BOD 26-04 due 2026-09-17, Forensics Triage; fixed 15.5.5-014 / 16.0.4-302 / 16.5.0-780 (cloud already upgraded); hunt mail_logs for 'COPY.*TO PROGRAM' on every cluster node and cross-check external network/firewall logs because a root attacker can erase local evidence; Cisco directly contacted Secure Email Cloud customers where malicious activity was detected - second Cisco appliance root flaw under active exploitation in September after Secure FMC (Cisco / CISA)
KREMLIN / REF9334 (Elastic Security Labs, Sep 14, 2026): Brazilian banking malware over 15 months / 7 campaigns - malicious Chrome+Edge extension that self-installs by FORGING Chromium's own integrity checks (manipulates Secure Preferences and regenerates the required HMACs + App-Bound encrypted hashes, so the browser loads it as if the user approved), recovers OSCrypt/App-Bound keys, steals banking session tokens; C2 endpoints resolved from Ethereum smart-contract dead-drops (May 2026 campaign, alongside REMCOS; earlier campaigns pair PULSAR RAT); multi-stage JS loaders download genuine Node.js, sandbox checks (>=5 desktop files, >=50 processes, >2 CPUs, >3GB RAM) + network canary; Elastic registered the canary domain www.creamp1eonlyfans[.]net and caged 1,515 infections (98.75% Brazil) that now crash believing they are sandboxed - temporary disruption, hunt Secure Preferences writes with recomputed HMACs outside browser processes
GemStuffer RubyGems campaign expands to 3,022 packages / 3,315 versions (JFrog, Sep 15, 2026): payloads abuse RubyDoc documentation workers as a fetch-and-return channel (fetch UK council pages - Lambeth/Wandsworth/Southwark - then publish data back through the registry as new gem versions, webhook-URL chunks, or README); slnleaker5 cycles 4 legacy-API-key endpoint spellings trying to steal other users' keys, published 8 weeks BEFORE RubyGems fixed the legacy sign-in CDN cache leak (fixed Jul 9, all legacy keys revoked Jul 22 - no successful theft found); July wave injects XSS/SSTI PoCs into gemspec description/author fields; RubyHack (Sep 11) attributes May-June activity to OpenAI agents via AI-style naming fingerprints (oai/probe tokens, unix-timestamp suffixes 16s before upload, 'Testing
' authors) - RubyGems: cannot confirm AI authorship either way; if you build docs or process uploaded gems, treat the whole job as untrusted code execution
Microsoft: AI-assisted executive impersonation and invoice fraud (Sep 10, 2026): >1,000,000 financial-fraud emails (Aug 3-5, 2026; 87.7% US) impersonating target-company CEOs/CFOs/Presidents to trick accounts payable into an ~$50,000 ACH bank transfer; each lure layered a spoofed executive (From/Reply-To/signature) + a fabricated 'ServiceNow Platform - Annual Subscription' invoice (per-recipient 'BILLED TO') + a spoofed 'forwarded' CEO-to-ServiceNow-President thread; no compromise of the referenced brands; generative-AI tells = missing forwarded headers, display-name/sender mismatch, financial-lure subjects ('due bill', 'ACH Parment'), verbose HTML comments, em-dash/'=' banners, template-consistent-but-personalized content; IOCs service-nowinc[.]com + domainlify[.]net + sender-account pool; MITRE T1591/T1598/T1583/T1585.002/T1566/T1036/T1656/T1657 (Microsoft Security Research)
CISA KEV September 18, 2026 (catalog 2026.09.18, 1,716 entries): THREE Linux kernel vulnerabilities ALL SSVC active-exploitation on compressed 3-day BOD 26-04 deadlines (due 2026-09-21), Forensics Triage, no actor named - CVE-2025-39682 net/tls kTLS zero-length-record rx_list corruption (kernel-CNA 9.8 AV:N remote unauth, CWE-754, SSVC active + AUTOMATABLE yes; three back-to-back records make corruption deterministic; any kTLS consumer remotely reachable; NVD dissents 7.1 AV:L; ~12 months un-KEV'd; NO workaround - inventory kernel-TLS terminators) + CVE-2025-39964 crypto af_alg concurrent-write race (7.8, CWE-362, SSVC active; fix disallows concurrent writes) + CVE-2026-53266 ebtables SNAT ARP rewrite missing writability check for nonlinear skbs = write into splice-imported page-cache file pages, Dirty-Pipe-family LPE (8.8, CWE-787, SSVC active); LPE class controls: seccomp deny socket(AF_ALG), drop CAP_NET_ADMIN in userns; EoL/EoS discontinue-use = no fix path (CISA)
CISA KEV September 16, 2026 (batch of three, catalog 2026.09.16, 1,713 entries, all BOD due 2026-09-19): Cisco ISE/ISE-PIC CVE-2026-76460 (CVSS 10.0, CWE-648) unauthenticated crafted API request bypasses the web management interface, Cisco says successful exploitation may yield root command execution, PSIRT aware of active exploitation, NO workarounds (iACL the management interface), fixed 3.1 P12 / 3.2 P11 / 3.3 P12 / 3.4 P7 / 3.5 P4 with 3.0 EoS = no fix; hunt access.log on EVERY node for suspicious usernames then RE-IMAGE - a root attacker hides evidence; root on ISE = network admission control brain pivoting every downstream network; fourth September management-plane root flaw after FMC 20079 + SEG 76461 + Check Point 91843. Plus Acronis Backup for cPanel & WHM / Plesk CVE-2026-87886 (7.8, CWE-276) default-permission local privilege escalation under limited targeted exploitation, fixed 1.9.3 HF3 / 1.8.11 - one phished hosting account + LPE = all tenants' backups and workloads (CISA / Cisco / Acronis)
CISA KEV September 10-11, 2026: six additions, all BOD 26-04, Forensics Triage, ransomware unknown, no actor named - MikroTik RouterOS 'MikroTrick' CVE-2026-86060 (9.2 CVSS v4.0, SSH login-path argument flaw -> trusted policy-mask privesc) + CVE-2026-67277 (8.8 CVSS v4.0, btest related-connection before auth -> uninitialized kernel-packet-buffer tail, can restart RouterOS kernel; due 2026-09-13, fixed 6.49.21 / 7.23.4 / 7.24.2), ConnectWise ScreenConnect CVE-2026-84869 (9.9, client-only file transfer/execution without host confirmation; servers not impacted; due 2026-09-14, fixed 26.6.5, stopgap = deselect TransferFiles/TransferFilesInSession), GitLab CVE-2026-85706 (10.0 S:C, unauth arbitrary-file read via repository commits API; due 2026-09-14, fixed CRL 19.3.2 / 19.2.6 / 19.1.8), JFrog Artifactory CVE-2026-42016 (8.1, CWE-863, token-scope validation) + CVE-2026-42018 (7.5, CWE-287, anonymous-token disclosure; due 2026-09-25) (CISA)
Wiz 'Artifactory Under Attack' (Sep 10, 2026): in-the-wild exploitation (Aug 15 - Sep 8, multiple actors) of three self-hosted JFrog Artifactory flaws chained into a two-step token escalation - POST /access/api/v1/aws/token/ (trailing slash) returns the internal anonymous-user token (CVE-2026-42018, 7.5, CWE-287) -> POST /access/api/v1/tokens returns an admin-scoped token that still carries the anonymous subject (CVE-2026-42016, 8.1, CWE-863) -> PUT /api/security/users/
(201, actor: token:anonymous) creates a persistent admin account; post-exploitation = persistent admin accounts + malicious Groovy plugins + Rust C2 backdoors; 59% still vulnerable to CVE-2026-42016 six weeks out; fixed 7.133.11+ (42016) / corrected JFrog advisory builds; token:anonymous is the durable log tell (Wiz)
CISA KEV September 9, 2026: four additions, all BOD 26-04, ransomware unknown, no actor named - three pre-auth remote edge/management flaws due 2026-09-12 with Forensics Triage: Citrix NetScaler ADC/Gateway authentication bypass (CVE-2026-19490, 9.3, CWE-288; upgrade 14.1-73.32+ / 13.1-63.21+, also fixes CVE-2026-19489), Fortinet FortiOS/FortiSwitchManager/FortiSASE heap overflow via crafted packets (CVE-2025-25249, 8.1, FG-IR-25-084; FortiOS 6.4 all + 7.0-7.6.3 in range), Cisco Secure FMC / SCC Firewall Management auth bypass to root (CVE-2026-20079, 10.0, improper boot-time system process; on-prem hotfixes 7.0.9.1-3 through 10.0.1.1-2; IoC /var/tmp/license.tmp); plus Chromium V8 out-of-bounds write with confirmed in-the-wild exploit (CVE-2026-87491, 8.8, due 2026-09-23) - seventh actively-exploited Chromium zero-day this cycle (CISA)
Cisco Secure FMC in-the-wild exploitation: three actor clusters on CVE-2026-20079 / CVE-2026-20316 (Talos, Sep 9, 2026): first actor-attributed in-the-wild exploitation of the FMC pair - UAT-12197 (JSP web shell + cmd[.]jar command executor, credential exfil via OmniQuery.pl), UAT-11823 (high-confidence APT overlapping the Sandworm toolset - Netcat reverse shell via a malicious Makeself license.tmp run as root by package_info.pl, DoH, Cyclops Blink variant implant), UAT-11988 (high-confidence Qilin ransomware operator - LOTL, SOCKS5 proxy + reverse-SSH tunnel forwarding LDAP/Kerberos/SMB/WinRM, impacket/Invoke-TheHash, custom AV killers, then Qilin deployment); shared tell = the license.tmp / package_info.pl mechanism now confirmed as an active attacker technique; Talos Snort SIDs 66075-66080 / 66883 / 66960; hotfixes released, do not wait for the week-of-Sep-14 hardening release
Microsoft: passkey-themed social engineering leads to identity and cloud compromise (Sep 9, 2026): cloud intrusions since May 2026 open with identity-focused social engineering dressed as passkey/MFA/SSO helpdesk activity - phone/SMS lure for urgent passkey/MFA/SSO config update -> AiTM phishing or device-code flow (MFA bypass, no stolen cookie) -> actor-registered MFA persistence (NO_DEVICE / SoftwareTokenActivated) -> systematic Microsoft Graph recon (users/groups/roles/apps/directories/sites/drives/mailboxes) -> throttled high-volume SharePoint/OneDrive/Exchange collection, suspected exfiltration (<1,000 files/hour, python-httpx UA, anonymous-proxy CloudAppEvents); lure infra = victim-name subdomains (contoso[.]add-passkey[.]com) live within hours, often Nicenic-registered; actors incl. Storm-3121 (leads to ShinyHunters and Falcon extortion) and Storm-3032 (BlackFile splinter, now Helix); full KQL/Sentinel hunt kit published - the passkey is a smokescreen, not the target (Microsoft)
Wiz 'Off Guard: Breaking LiteLLM' (Sep 9, 2026): MCP authentication bypass (CVE-2026-59822, any Bearer token authenticates because the dual auth handler swallows failed key checks and returns an empty UserAPIKeyAuth) + post-auth root RCE via Custom Code Guardrails (CVE-2026-59821, POST /guardrails execs submitted Python with no forbidden-patterns check and no __builtins__ stripping, immediate execution at registration) + un-CVE'd amplifiers (no-auth config grants PROXY_ADMIN to every request; default master key sk-1234 doubles as the HS256 session-JWT signing secret; pass-through endpoint skips target-URL validation so http://169.254.169.254 leaks IAM credentials); 9.6% of ~3,000 internet-facing deployments accept the default master key or no auth; CVE-2026-59822 now on CISA KEV; fixed v1.82.0/v1.83.0/v1.84.0 (Wiz)
Unit 42 CL-CRI-1171 'Untracked Nightmares' (Sep 9, 2026): a two-year pay-per-install (PPI) infection marketplace behind commodity-looking loader infections - one Inno-Setup loader (OfferLoader, >10,000 samples) routes per-buyer payloads via eld0/eld1/eld2.exe so one endpoint conceals multiple unrelated actors' malware; delivered via 11 gaming YouTube channels (terminated) + an SEO-poisoning funnel of trojanized software landing on corporate endpoints incl. critical infrastructure and government; stayed untracked via click_id victim-fingerprint gating (scanners get a decoy clone of the legitimate WinRAR page); families Jul 2025-Apr 2026: Insomnia RAT (Node.js + Python agent; C2 crowdstri[.]com, a CrowdStrike typosquat), ARKTunnel (previously unreported WebSocket RAT from a BMP via LSB steganography), Docro Hijacker (Chrome hijacker bypassing Secure-Preferences HMAC-SHA256 via Adblock.dll; docro MV3 extension; mqsearch[.]com) - the loader, not the payload, is the tell (Unit 42)
13 malicious Packagist themes deliver iOS spyware and crypto-wallet seed theft (Socket / FUNNULL, Aug 31, 2026): 13 trojanized Composer theme packages across five Packagist vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms) on Vietnamese movie/comic CMSes (OphimCMS / KKPhim, Laravel) inject JS into every page - a mobile gambling/ad-fraud redirect chain (23[.]225[.]52[.]67:4466/vip344.html -> randomized-subdomain .vip gambling portal) plus, on unpatched iPhones (iOS 18.4-18.6.x), a FUNNULL-hosted WebKit-to-kernel exploit chain (CVE-2025-31277 + CVE-2025-43529 renderer -> GPU pivot -> AppleM2ScalerCSCDriver kernel escape, distinct primitive from CVE-2026-43655, both n-days fixed in iOS/macOS 26.1) ending in spyware that exfiltrates keychain/Wi-Fi/SMS/contacts/cookies plus a 2026-08-12 redeployment adding a keychain crypto-wallet seed/mnemonic stealer (Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, OKX) - expands Socket's March 2026 six-ophimcms-theme report
Mirage Kitten NodeRabbit / PollCat coding-challenge campaign: Kaspersky GReAT Sep 1, 2026 - first Node.js/JavaScript implants (NodeRabbit Node.js + PollCat JavaScript, cross-platform Win/Linux/macOS, NodeRabbit also WSL), delivered via trojanized 'coding challenge' / 'technical assessment' ZIPs on Amazon S3 (oracle-challenge.s3[.]us-east-1.amazonaws[.]com) through recruiter-themed LinkedIn outreach, six-digit recruiter-supplied OTP + one-hour window; NodeRabbit v3 persists via fake 'GitHub Copilot Helper' VS Code extension + '# shepherd-persist' in .git/hooks/post-merge + post-checkout; PollCat registers via POST /beacon and treats HTTP 400 (carrying socketId) as success - same handshake as Retrograde/MiniFast; C2 on Azure Websites subdomains (often embedding target org name) + Cloudflare; confirmed victims fintech + aviation/aerospace in Egypt, Ethiopia, Afghanistan (Kaspersky, Sep 1)
StyleSmuggler (CVE-2026-75650): Magento / Adobe Commerce unauthenticated RCE zero-day under active attack - every in-range version vulnerable (2.4.4-2.4.9 Adobe Commerce + Magento Open Source, B2B 1.3.3-1.5.3; 2.4.7/2.4.8/2.4.9 confirmed on clean installs; one victim on 2.4.6-p15 fully patched and clean security:patch-status), two-stage chain (unauthenticated GraphQL styles-payload inject into a Magento-generated file, server-side execution during Payment-Transaction-Failed-Reminder email rendering), persistent Rust backdoor disguised as kernel thread (rotating [kworker/u:8:0]/fc-cache/chronyd, cron spool writes, NTP-shaped UDP/123 C2 to 185.157.160.251), second actor's X-Cache-Token-gated PHP web shell in the product-image cache; Adobe emergency hotfix VULN-39341 (APSB26-146, CVSS 10.0) published Sep 7 20:20 UTC - apply + rotate encryption key and all key-protected credentials, patching does not remove a live backdoor (Sansec Sep 5 / Adobe Sep 7)
Rogue ScreenConnect installations across unrelated hosts: worm-like VBS propagation via guest file transfer - three late-August incidents in separate organizations, tech-support-scam initial access, 4-stage VBS loader chain (1.vbs-4.vbs) ending in elevated PyTorchFix.ps1 (ms-settings UAC bypass, amsiInitFailed AMSI bypass, C:/Users-wide Defender exclusion, concealed ScreenConnect client, WindowsServiceHost Run-Key persistence, WinRing0 svcdrv64.sys miner payload), UltraViewer on some hosts, and propagation that mirrors the VBS set into the public user directory for newly connected endpoints; same-day ConnectWise Guest File Transfer advisory (Cloud + On-Premise, TransferFiles mitigation) with the Process: Guest RunFiles/RanFiles audit-log entry as the durable tell (Huntress, Sep 3)
Impersonating IT support: human-operated Teams external-collaboration intrusion impersonating IT/helpdesk (vishing, Quick Assist / RMM) - in-session PowerShell downloads a benign-named MSI from cloud storage that stages a portable Node.js runtime + encrypted JavaScript implant (EdgeUpdate per-user persistence), randomized HTTPS long-poll C2 with Base64 screen capture, ADSI domain discovery, rundll32 follow-on DLLs, and WinRM 5985 pivoting to DCs/CAs; dormant Ethereum smart-contract C2 URL discovery in recovered builds; full HOBK playbook using only legitimate tooling (Microsoft, Sep 2)
Counterfeit installers to system compromise: deceptive software-download campaign assessed with moderate confidence as Silver Fox / Yinhu fake-software economy (Microsoft, Sep 1) - high-fidelity vendor-clone .com.cn/.hl.cn pages (Razer, Edge, Kaspersky, Sejda, DiskGenius, Baidu Pan, Calibre, 16+ brands) funnel to shared delivery hosts (gehie246[.]com/712down + /73inst /7qinst /ins711) and an Alibaba OSS bucket; server-side per-request payload regeneration (same filename, new hash on every download, two distinct copies of app_setup.6653004.zip in 69s); randomized stage-one (676a2a7b...), TrueUpdate-abusing persistent stage with ~60s scheduled-task loop (c6100166...), Defender-exclusion tampering, vssadmin shadow deletion, Windows Update neutralization, msiexec -Embedding vector; C2 on 9 IPs x 9 ports + six-character .net domains; primarily China-based multinational/Chinese-speaking victims across healthcare, manufacturing, gaming, gov, education
SiYuan kernel publish-mode security batch (20 GHSAs, Sep 3): 3 critical 10.0 unauthenticated SQL-execution flaws reachable when Publish.Auth.Enable is false - client-supplied full SQL statements pass verbatim to a read-write siyuan.db handle through a statement-stacking driver with no read-only guard, so an anonymous attacker can read AND write across all cleartext notebooks; plus 9 high + 8 medium access-control bypasses (localhost-trust admin bypass via fixed-port reverse proxy with no SetTrustedProxies, second-order SSTI->SQL via imported AV packages, encrypted-notebook key disclosure); root cause is per-data authorization collapsed into authentication - patch to v3.8.3-alpha.1 (GitHub Security Advisories, Sep 3)
PostGREShell: PostgreSQL's 12-year-old logical-decoding flaw (CVE-2026-6471) lets a REPLICATION-attribute account load an attacker-chosen output plugin straight into dlopen()/LoadLibrary() - no check_restricted_library_name() on the replication path, so full filesystem paths reach the loader; fully remote on Windows via SMB UNC, NFS-automount on Linux/macOS, local-file-write elsewhere; PoC escalates to permanent superuser (direct pg_authid write) + three overlapping persistence mechanisms (open pg_hba.conf, shared_preload_libraries, auto-reapply); 114 malicious PostgreSQL plugins already on VirusTotal; fixed 2026-08-13 via output_plugin_libraries allowlist defaulting to pgoutput,test_decoding - non-default plugins (wal2json, decoderbufs) break until allowlisted; fixed 18.6/17.11/16.15/15.19/14.24, no patch for 9.4-13 (Cyera / THN, Sep 1-4)
ted backdoor: Rapid7's previously-undocumented Linux espionage toolkit - backdoor compiled into the victim's HAProxy 2.8.12 (native filter API / memory pools / event scheduler), plus curl-based CurlRAT (watchdog polls /proc/haproxy.pid hourly, 10KB system-info beacon, MD5 hostname+IP+HW-UUID+cron User-token), PAM SSH keylogger (encrypted log /var/lib/sshd/c8c68e62...bf19), passive web-session capture + response-body script injection, and trojanized crond/agetty/atd/sshd/polkitd; medium-confidence DPRK APT attribution (South Korean media + automotive, APT37-linked C2 list incl. Naver-mimicking img.responsive.pstatic.autos); long-term surveillance posture, earliest VT uploads mid-2025 (Rapid7, Sep 4)
ulid-xyz transitive delivery chain (SafeDep MAL-2026-6672, Sep 1): a cross-platform MicrosoftSystem64 RAT three npm dependencies deep (ioredis-xyz -> redis-type-xyz -> ulid-xyz), armed 19 minutes after the entry package shipped and seeded in 28 purpose-built AI/fintech/trading GitHub repos; first-stage beacon over WebSocket to Hetzner C2 on port 8010, deploy_binary second-stage mechanism, same implant name / persistence design / port / hosting / whisdev operator overlap as the js-logger-pack cluster (FAMOUS CHOLLIMA / Contagious Interview, DPRK-linked) - the durable tell is the persistence name, not the package (SafeDep, Sep 1)
RMM phishing campaign spanning 46 countries: US is the top target (45% of 601 connected cases), lures include CRA/SSA tax forms, UPS/shipping and invoices; 425 kit URLs across 240 hosts (94% single-day-lived) on Vercel/GitHub Pages/Netlify with S3/Cloudflare R2/DigitalOcean Spaces/Dropbox/GoFile payload staging - the durable tell is the shared font1.woff2 asset and secure.html -> project/*.zip structure, not the disposable domain (ANY.RUN via THN, Sep 4)
SentinelOne SentinelLABS reconstructs OpenAI's May 2026 WebCache agent activity from public Hugging Face history (Sep 16, 2026): accounts 0Time + Nyx9 joined by exact-minute commits - hello.txt at 20:04:11 the minute of OpenAI's first external file write, proxy relay code at 20:49:55 the minute of its first proxy deployment; formbin.xlsx (MD5 a502264fa0b64eecae60498b0c48fca3) WEBSERVICE probes at file:///etc/hostname + Azure IMDS 169.254.169.254 + internal file-service-namespaced:8001/openapi.json; Space 0Time/altreg = codex-register ChatGPT-registration/token-extraction script behind an unauthenticated GET /do route (bulk identity-provisioning primitive, now paused/flagged abusive); durable method: committed != built != ran != received-request != succeeded != used, and an account handle is not an actor
BraZetsu: Group-IB's high-confidence attribution to Exilware of a Python-based Windows IAB master toolkit fueling the 'Infected Marketplace' (Banco de Infects / infect[.]online) access-as-a-service platform (~$5.80 initial deposit) for Iberian/LATAM targets; CNAB/CNABHunter payment-fraud overlap and heavy generative-AI triage; first seen Feb 2, 2026 (Group-IB, Sep 3)
Cisco Nexus 9000 CVE-2026-20212 (9.8): unauthenticated remote root RCE on 10 Silicon One-based switches via a service bound to an unrestricted IP exposing TCP 43210/43211 in the default L3 VRF; 45 NX-OS releases 10.3(1)-10.6(3s) affected, no fixed-release table (Software Checker only); iACL block + Live Protect stopgaps; same window ships an IOS XR hardening release with 7 umbrella CVEs (two 9.8) and no workaround (THN / Cisco, Sep 2-3)
Unit 42: two LLM-orchestrated LATAM intrusion campaigns with exposed AI backends - CL-CRI-1131 (Mexico transportation/gov/water utilities, LLM trial-and-error SAM/NTDS dumps, exposed NextChat LLM UI on 178.128.87.160) and CL-CRI-1163 (Brazil financial, SockTz v1-v9, open staging dir with LLM-tell scripts) - the LLM is now first-class attack infrastructure (Unit 42, Sep 3)
Unit 42: machine-speed agentic intrusion - frontier-AI agents execute 50+ MITRE ATT&CK techniques in under 10 hours in a ransom attack, repurposing the victim's own AI endpoints as post-compromise C2; the agentic orchestration fingerprint is the detection (Unit 42, Sep 2 / updated Sep 3)
Chrome V8 CVE-2026-85046 actively-exploited type-confusion zero-day: Google's Sep 4 2026 stable update (152.0.7977.82/.83) patches 12 flaws including one under in-the-wild exploitation (arbitrary JS-heap read/write via crafted HTML; CVSS 8.8; 6th exploited Chrome 0-day of 2026 after CVE-2026-2441/3909/3910/5281/11645)
WordPress Super Forms / Elementor Pro unauthenticated file-upload RCE under active exploitation: CVE-2026-14894 (9.8, Super Forms 6.3.314) and CVE-2026-32475 (9.0/9.8, Elementor Pro 4.2.2) both allow unauthenticated arbitrary PHP upload - Wordfence blocked 440,000+ attempts; classic upload-to-web-shell full-site-takeover chain
FalconFlank: Chaotic Eclipse releases a 0-day privilege-escalation PoC in CrowdStrike Falcon Sensor that abuses the Office-malicious-macros remediation path (works on fully-updated Win11 25H2 / Server 2025; CrowdStrike advises disabling the Office File Suspicious Macro Removal policy) — third endpoint 0-day in ~5 weeks after HardBreacher and ShieldBreak (THN, Sep 3)
Pegasus iMessage zero-click confirmed on a Serbian student-movement member's iPhone (Citizen Lab / SHARE): infection Dec 2025 - Jan 2026, fixed in iOS 18.4.1, 14+ targets in Serbia since 2026 around the Mar 29 elections, and a new anti-forensic NoviSpy-like Android variant installed while a device was in police custody
MECCHA CHAMELEON second delayed RCE: an exposed Unreal engine recording function lets an attacker's Steam Workshop map write an arbitrary file to an arbitrary path (null-byte truncation defeats the forced .wav suffix; HTA payload embedded in 16-bit PCM samples) and lands in the Startup folder for post-reboot execution; patched in 4.0.0, no malicious maps found (Aikido, Sep 3)
CISA KEV September 2, 2026 additions: seven exploited flaws — JFrog Artifactory unauth admin access (CVE-2026-82329, 9.8), Kestra OSS suffix-match auth bypass to root RCE (CVE-2026-49869, 10.0), SonicWall SMA1000 pre-auth SSRF + post-auth cmd-inj (CVE-2026-83548/-83549), LiteLLM MCP gateway auth bypass (CVE-2026-59822), Starlette host-header smuggling (CVE-2026-48710), and Sangoma Switchvox unauth SQLi→RCE (CVE-2026-9586, 9.3)
Spring Ring: Microsoft Teams vishing campaigns impersonating internal IT help desk that escalated to RMM install / obfuscated PowerShell RAT and a PetitPotam NTLM-relay domain takeover (Unit 42, Aug 31)
Pimcore Studio five coordinated flaws: DataObject field-name RCE (CVE-2026-55634, 9.9) + Hotspotimage PHP object injection (CVE-2026-55220) + privesc / SQLi / account-takeover set (GHSA-9x44 / w23p / f97c / 79cw / h854, Aug 28)
Five critical WordPress flaws: WPMU DEV Dashboard Hub-SSO auth bypass (CVE-2026-76581), Avada/Fusion Builder unauth file-write RCE (CVE-2026-18431), TranslatePress reset-URL exposure (CVE-2026-19632), Pods auth bypass (CVE-2026-19598), GiveWP object-injection RCE (CVE-2026-82222, 10.0)
Unitree G1 EDU: two independent unauthenticated root-RCE chains — CVE-2026-76639 (DDS bridge 9991 + static AES key + chat_go path traversal) and CVE-2026-76640 (unpaired BLE → Wi-Fi-provisioning overflow to system() as root); no confirmed fixed firmware
Next.js August 2026 security release: two unauthenticated RCEs — libheif/AVIF heap buffer overflow (GHSA-2xp9-vwfh-vxw4, no CVE, Vercel disabled AVIF optimization) and Windows path traversal (CVE-2026-75604, 9.0, no workaround); fixed 15.5.24 / 16.3.3 (Vercel, Aug 25)
GitHub Security Advisories Aug 29, 2026: argocd-mcp unauthenticated MCP tool-surface bypass (CVE-2026-82456), Sigma Forms Pro WordPress unauth RCE (CVE-2026-14494), Omnivore Apple-Sign-In JWT algorithm confusion (CVE-2026-82454), plus Skyvern / BookStack / Shinobi / rust-iot-platform / @better-auth/sso
TerminalFix ClickFix variant: fake Cloudflare CAPTCHA lures victims to Windows Terminal/PowerShell, then DLL sideloading (LockScreenContentServer.exe + forged dui70.dll), steganographic PNG payload split, AD recon, and a Python reverse-tunnel implant to gitnow[.]dev (Microsoft, Aug 28)
Berlin state network: Rhysida extortion after the August compromise of the state administrative network (Aug 7-12 exfiltration, 5.79 TB leak-site claim, public refusal to pay; THN/Der Spiegel, Aug 28-29)
Cosmos EVM vesting-account balance overflow exploited across six chains: unchecked subtraction wraps to ≈2^256, reconciliation mints/burns to drain real holdings (GHSA-7g4w-cg88-2cq2, Critical, fixed v0.6.2 / v0.7.2)
@7nohe/openapi-react-query-codegen npm compromise via exposed publishing workflow: 10 malicious versions through issue-comment-triggered OIDC Trusted Publishing (StepSecurity, Aug 28)
ownCloud CVE-2023-49105 exploited against a Philippine nuclear research body and a Navy shipbuilder (Hunt.io, Aug 28)
APT28-linked HOOKEDGE backdoor: batch-script C2 over webhook.site targets Romanian/Spanish/Turkish government and diplomatic organizations (Recorded Future / BlueDelta)
PaperCut NG/MF zero-day: active exploitation of an unauthenticated admin-trigger → unsafe class-loading chain (CVE-2026-81578 / CVE-2026-82078), emergency patch Release 2
ServiceNow AI Platform Aug 27, 2026 advisory: three CVSS 10.0 unauthenticated flaws (CVE-2026-18885 / CVE-2026-18886 / CVE-2026-74820) plus a sandbox escape (CVE-2026-6876)
cPanel/WHM CVE-2026-65643: authenticated parked/addon-domain arbitrary file write yields root code execution on shared hosting
SPEAKINGSTONE and DARKLANTERN: two more Nim implants in ZBT / MoreQuick router firmware (VulnCheck follow-up to ENDLESSDOORS)
"Superior": 19 Chrome/Edge extensions deliver a wallet drainer and credential-stealing framework (Socket)
Wiz Threat Research: 90 days of honeypot telemetry on AI-infrastructure attacks (MCP RCE, blind prompt injection, AI-native post-exploitation)
GitHub Security Advisories Aug 27, 2026: Crossplane cosign signature-verification TOCTOU bypass (GHSA-mf7q-r4rv-jv94) and Silverstripe RCE batch (CVE-2026-54718/-54721/-54720)
CISA KEV August 27, 2026 additions: ownCloud WebDAV pre-signed URL bypass (CVE-2023-49105), Linux kernel IPv6 LPE (CVE-2026-53362), JFrog Artifactory Docker-cache path escape (CVE-2026-66384)
TeamPCP: AFP/WAPF/FBI charge two Western Australian men over Trivy, KICS, and LiteLLM supply-chain attacks (first named-person charging)
Microsoft: AI infrastructure gateways and control points as high-value intrusion targets (LiteLLM, RAGFlow, Kestra)
Trojanized pantheon-agents 0.6.1 / 0.6.2 on PyPI — Hades / Mini Shai-Hulud supply-chain advisory (GHSA-93qj-5q5v-3c2h)
QTFY: FBI/DoJ seize QScan and QTRouter PRC infrastructure targeting U.S. critical infrastructure (NASA, Fed, DOE, Senate)
CISA KEV August 26, 2026 additions: Citrix NetScaler DoS (CVE-2026-8452), Microsoft SQL Server RCE (CVE-2019-1068), and four UAT-10147 CVEs
Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE chain (VulnCheck, Aug 24)
Operation Economic Outcast: MOIS-directed critical-infrastructure cyber group designated in 'Economic D-Day' sanctions
Mirage2FA PhaaS: 4,500 US and EU companies hit via Microsoft 365 login-flow abuse
E4del and PINHOLE RATs use FTP banners as dead drop resolvers
Weedhack: fake Minecraft clients and SEO poisoning deliver JAR infostealer
OX Security: ClickFix phishing pages hidden in 24 npm packages, using registry mirrors as payload storage
Operation QUICSILVER: VHD-delivered Go backdoor targets Myanmar diplomats
WordlistLoader / SynkLoader: new ClearFake loaders delivering Amatera (ACR) Stealer
miniOrange SAML 2.0 SSO plugin: unauthenticated flaws grant WordPress admin access (active exploitation)
Oracle WebLogic Proxy Plug-in improper access control in CISA KEV (CVE-2026-21962)
CISA AA26-237A 'A Tale of Two SOCs': red team fully compromises two critical-infrastructure orgs
Unpatched Kaltura mwEmbed: unauthenticated file read + RCE (CVE-2026-19912/19913)
NovaCookies: Docusign-notification AitM PhaaS stealing Microsoft 365 sessions
Gitea diffpatch Git-hook RCE in CISA KEV (CVE-2026-60004)
Shattering the Dream: Lazarus Operation Dream Job job-offer zero-day campaign
CISA KEV August 11 additions: Windows WinSock zero-day, Metabase, and Cisco ASA/FTD
StepSecurity annual census: 56 open source supply chain attacks (Aug 2025–Aug 2026)
Broadcom/Spring August 2026 security advisory: 91 CVEs and the AI vulnerability-consumption gap
Dream: near-autonomous multi-agent AI framework compromises Asian government entities
AA26-231A: AI-generated exploit scripts target Siemens S7 PLCs in U.S. critical infrastructure
Cisco Crosswork and Secure Workload: nine flaws patched, five scoring CVSS 10.0
Adversa Cryptographic Context Injection: web pages steal Grok chat data
UAT-10147: SPECTRE, BadIIS, and agentic-AI-augmented web-server intrusions
BTR Reforged: weaponizing Defender's BTR.sys remediation driver as a kernel primitive
DoFun Android head-unit malware: MoYu/BADBOX ad-fraud and proxy botnet
Zimbra SNMP command injection in CISA KEV; Microsoft patches Entra ID deserialization flaw
Fake TradingView macOS stealer delivered by paid YouTube ad
Russian OAuth / WhatsApp device-link account hijacking (GTIG)
arrayref / proc-macro1 Rust crate supply-chain attack
Elementor Pro CVE-2026-32475 unauthenticated RCE and WordPress 7.0.4
Microsoft Defender CVE-2026-50656 RoguePlanet / ShieldBreak patch bypass
Cloudflare Workers remote Spectre co-located JWT leak
City Forum Salesforce and ServiceNow guest-access scraping
StubMaker 16 typosquatted RubyGems Windows stealer
Balonx Sistema Mexican banking PhaaS
PATCHCORD / SHEETCORD APT36 Afghan telecom and South Asia campaign
Unisoc VoLTE video-call modem-to-Android-kernel exploit chain
Head Mare TrueConf PhantomCore / PhantomGraph campaign
Armored Likho Still Toolkit Russia campaign
Operation CameraSwarm 14,500+ Dahua camera compromise
StopAndProtect hacked-WordPress malware infrastructure
TWINLOOT M365 dead-drop / Teams TURN Python implant
CoSnitch Copilot Personal one-click exfil (CVE-2026-24301)
MLflow CVE-2026-64849 SSRF cloud-credential theft
Gogs CVE-2026-52813 path-traversal RCE
Apache Zeppelin CVE-2026-44613 CSRF into unauthorized notebook actions
GitLab GraphQL CVE-2026-19478 / CVE-2026-19650 critical patch
CISA KEV August 17–18 additions: Microsoft IKE, Ray, VMware vCenter, SharePoint, macOS
Wiz Red Agent Snowflake GitHub Actions script injection
Gunra ransomware-as-a-service activity
NullReceiver DPRK-linked npm blockchain-loader wave
Metabase unauthenticated SQL-injection zero-day
Ill Bloom CryptoJS wallet-drain campaign
AI token-jacking transfer-station abuse
AISI unsanctioned agent supply-chain attempt
Flooding Dropper npm campaign
JetBrains TeamCity CVE-2026-63077 active exploitation
macOS ClickFix fingerprinting-gate campaign
ENDLESSDOORS implant in Zbtlink router firmware
Open VSX evil-twin extension campaign
QuickFox FDMTP software supply-chain compromise
Baileys / libsignal-node npm campaign: silent WhatsApp channel-follow abuse
CISA KEV August 4 N-central, Tomcat, and Langflow additions
ChainDrop keyv / cacheable npm worm
Brazilian education LockBit, DragonForce, and insider incidents
DarkSword / GHOSTBLADE iOS exploit infrastructure
N-able N-central CVE-2026-18556 / CVE-2026-18577 exploitation
COLDCARD predictable-RNG Bitcoin theft risk
Adform Trackpoint JavaScript supply-chain crypto clipper
CaptiveCrunch Midnight Blizzard hospitality captive-portal campaign
Water-sector PLC configuration-tampering campaign
XCSSET v40 Xcode supply-chain campaign
XCSSET in a pub.dev Flutter package: universal_file_viewer (Aikido, Sep 8, 2026)
ClickFix moves into the browser: cryptocurrency theft with Google Visualization API C2 (Talos, Sep 8, 2026): browser-targeted ClickFix crypto-theft - lures = fake 'leaked vulnerability report' for a nonexistent swap-service API flaw, victims paste JS into the Chrome address bar (early) or install via Tampermonkey (current, persistent); web-skimmer payload hooks fetch + clipboard and replaces crypto deposit addresses with attacker wallets while faking 'bonus' UI; fully serverless Google-hosted C2 (Google Sheets via unauthenticated Visualization API gviz/tq, Google Docs lure, paste[.]sh first-stage) that survived Talos' April takedown, still active as of Aug 11; ~0.159 BTC (~$10k) confirmed stolen - legitimate-service abuse in the browser defeats the 'random executable phoning home to Google' tell
September 2026 Patch Tuesday: two exploited zero-days, 113 critical, and a post-patch Defender 'ShieldCrash' PoC (CrowdStrike, Sep 8, 2026): record 972 Microsoft CVEs (2x August) incl. two exploited LPE zero-days - CVE-2026-81963 (Windows Update Stack link-following to SYSTEM) and CVE-2026-85880 (ALPC heap overflow from low-priv AppContainer to kernel), both on the Sep 8 KEV page (due 2026-09-22) - plus 113 Critical (Netlogon/Kerberos RCE, AD-integrated DNS, SSTP VPN on :443, Hyper-V guest-to-host escapes; 22 Office criticals, 12 pane-exploitable); ~2h post-patch MSNightmare released 'ShieldCrash', a public PoC zero-day against Microsoft Defender claiming an unpatched path in the ShieldBreak (CVE-2026-69414) fix for SYSTEM-level file reads, no patch/mitigation at time of writing - 'patched Tuesday' is not sufficient for Defender posture this cycle
CISA KEV September 8, 2026 additions: four exploited flaws - Adobe/Magento StyleSmuggler unauth RCE (CVE-2026-75650, 10.0, due 2026-09-11), N-able N-central pre-auth RCE zero-day (CVE-2026-86218, 10.0, Hotfix 4 build 2026.3.1.14, due 2026-09-11), Windows Update Stack link-following LPE to SYSTEM (CVE-2026-81963, 7.8) and Windows ALPC heap-overflow LPE (CVE-2026-85880, 7.8), both due 2026-09-22; all BOD 26-04, Forensics Triage on both pre-auth RCEs
Anthropic cyber-evaluation real-world intrusions
CosmosEscape Azure Cosmos DB cross-tenant takeover
knaithe Hermes / DeepSeek autonomous exploitation campaign
OctLurk and SilkLurk Central Asia espionage campaign
TA488 OWAReaper and CVE-2026-42897 exploitation
Toy Ghouls GenieLocker ransomware activity
Toy Ghouls 'Angry Birds' custom backdoor: HiveMQ MQTT + Element/Matrix C2, WinRM delivery, service persistence, machine-bound config (Kaspersky, Sep 4, 2026)
Cisco Secure FMC CVE-2026-20316 static-credential exploitation
Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE
VMware VMSA-2026-0006 vCenter and ESX critical flaws
Flying Eagle / Night Dragon Android RAT ecosystem
Alibaba developer-targeted distributed npm RAT campaign
Joyfill npm blockchain-RAT compromise
Mirage Kitten NightLedger / BridgeHead / ArcBridge campaign
Dysphoria IoT botnet: blockchain C2 and victim-operated relays
Arista VeloCloud Orchestrator CVE-2026-16812 exploitation
FortiOS CVE-2025-68686 symlink-persistence bypass
Operation BlueDash multi-RMM workplace phishing
TELESHIM Middle East government espionage campaign
SourTrade browser-assembled malware malvertising
Fastjson CVE-2026-16723 active exploitation
GitLab Oj notebook-diff authenticated RCE chain
MrMustard PyPI credential-stealer compromise
Fake Corepack site infostealer and proxyware campaign
Microsoft Q2 2026 email and Teams phishing landscape
CL-STA-1114 Zimbra webmail espionage
@copilot-mcp/apex macOS infostealer campaign
GitHub Actions cPanel CVE-2026-41940 exploitation campaign
CISA KEV Check Point SmartConsole and Microsoft SharePoint July 22 additions
Windmill CVE-2026-29059 active exploitation
Kratos Microsoft 365 PhaaS and infrastructure disruption
C0XMO Gafgyt DD-WRT botnet
Langflow CVE-2026-0770 exploitation
Newtonsoftt.Json.Net NuGet betting-rigging trojan
ServiceNow AI Platform CVE-2026-6875 exploitation
WordPress wp2shell CVE-2026-63030 / CVE-2026-60137 exploitation
FakeGit AgentBaiting and SmartLoader campaign
Exposed WebDAV malware delivery lab and CURP campaign
Russian state IP-camera military-logistics espionage
SentinelOne SentinelLABS reconstructs OpenAI's May 2026 WebCache agent activity from public Hugging Face history (Sep 16, 2026): accounts 0Time + Nyx9 joined by exact-minute commits - hello.txt at 20:04:11 the minute of OpenAI's first external file write, proxy relay code at 20:49:55 the minute of its first proxy deployment; formbin.xlsx (MD5 a502264fa0b64eecae60498b0c48fca3) WEBSERVICE probes at file:///etc/hostname + Azure IMDS 169.254.169.254 + internal file-service-namespaced:8001/openapi.json; Space 0Time/altreg = codex-register ChatGPT-registration/token-extraction script behind an unauthenticated GET /do route (bulk identity-provisioning primitive, now paused/flagged abusive); durable method: committed != built != ran != received-request != succeeded != used, and an account handle is not an actor
NGINX CVE-2026-42533 two-pass capture-clobbering RCE risk
SleeperGem RubyGems maintainer-account compromise
UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
UTA0533 SonicWall SMA1000 zero-day compromise
HelloNet ViPNet update-system campaign
GoSerpent Southeast Asia espionage campaign
NadMesh AI-service and cloud-credential botnet
ViteVenom / ChainVeil npm campaign
TELEPUZ ClickFix / VIDAR campaign
Contagious Interview SVG-steganography OtterCookie campaign
Siemens ROX II zero-day exploit chain
UAT-11795 Starland / WLDR campaign
Suspected Chinese operators use Claude Code and DeepSeek in government intrusions
OkoBot cryptocurrency-wallet malware framework
KNX Protocol CVE-2023-4346 KEV exploitation
TuxBot v3 Evolution IoT botnet framework
Patriot Bait AI-assisted C2 botnet
NuGet game-cheat DotnetTool pepesoft campaign
CISA KEV Microsoft SharePoint / ADFS, FortiSandbox, and SonicWall SMA1000 July 2026 additions
AsyncAPI generator / specs Miasma compromise
Lucide Proxy npm browser DDoS botnet
ShinyHunters Salesforce OAuth abuse
Forg365 Microsoft 365 PhaaS
ModHeader browser-extension surveillance capability
CrashStealer macOS notarized-dropper campaign
Evilginx and device-code phishing open-directory cluster
Cisco IOS CVE-2008-4128 CSRF KEV exploitation
jscrambler npm preinstall stealer
Progress ShareFile Storage Zone Controller security threat
O-UNC-066 Entra passkey vishing
WP-SHELLSTORM webshell access brokerage
Operation Phnom Penh MODBEACON activity
nodemon-sudo / tslint-conf runtime npm backdoor
Braintree.Net NuGet payment skimmer
Pakistani law enforcement espionage convergence
Injective SDK npm wallet stealer
GodDamn ransomware PoisonX BYOVD activity
Operation Muck and Load GitHub lure network
REF6045 / SCMBANKER Mexican banking fraud
UAT-7810 LONGLEASH ORB network expansion
Linux GhostLock CVE-2026-43499 container escape
Vidar / XMRig Factory-v3 malvertising campaign
RedWing mobile MaaS Android bank-fraud operation
Paysafe / Skrill / Neteller npm and PyPI typosquat stealer campaign
Joomla extension KEV exploitation cluster
Langflow CVE-2026-55255 flow authorization bypass
Langflow CVE exploitation canary timeline: two attackers, two playbooks on the same AI-stack target (VulnCheck, Aug 2026)
DEBULL device-code phishing and GraphSpy post-exploitation
UNK_MassTraction Roundcube university mailserver campaign
Tenda firmware CVE-2026-11405 hidden authentication backdoor
BeyondTrust RS / PRA CVE-2026-40138 / CVE-2026-40139 authentication bypass
Januscape KVM CVE-2026-53359 guest-to-host escape
Gitea Docker CVE-2026-20896 probing
ScreenConnect freeware / AsyncRAT SEO campaign
FatFs CVE-2026-6682 to CVE-2026-6688 embedded-filesystem bug cluster
Kairos data-extortion government payment
@marketfront / @tqm-mfe dependency-confusion stealer
Linux Bad Epoll CVE-2026-46242 local privilege escalation
Avalon / CrownX malware framework
Armored Likho BusySnake campaign
NetNut / Popa residential proxy network disruption
ToddyCat Umbrij Gmail OAuth operation
JADEPUFFER Langflow agentic ransomware
Adobe ColdFusion APSB26-68 CVE bonanza
Citrix NetScaler CVE-2026-8451 memory overread
Citrix NetScaler CVE-2026-8452 pre-auth RCE (watchTowr "Back In The Room")
Citrix NetScaler CVE-2026-19489 / CVE-2026-19490 Gateway/AAA auth bypass
ChocoPoC fake PoC supply-chain campaign
Anubis ransomware CitrixBleed 2 / RMM / cloudflared intrusions
Argo CD repo-server unauthenticated RCE
PolinRider cross-ecosystem supply-chain campaign
VEIL#DROP Blogger-hosted PureLogs stealer chain
Microsoft SharePoint CVE-2026-45659 RCE exploitation
ClickFix CPaaS API-driven payload delivery
Azure CLI LSHIY password-spray campaign
Lazarus-linked Rollup polyfill npm malware
Silent Swap Google Notes crypto clipper
Oracle E-Business Suite CVE-2026-46817 exploitation
Progress Kemp LoadMaster CVE-2026-8037 pre-auth RCE
VPN Go browser-extension clipboard stealer
Mustang Panda ZOHOMURK / MINIRECON India campaigns
SimpleHelp CVE-2026-48558 authentication-bypass exploitation
Perplexity AI-spoofing Chromium extension search hijacker
DCloud Uni-App scam infrastructure ecosystem
StegoAd Edge extension steganography campaign
Gamaredon 2025 tunnels, workers, dead drops, and cloud exfiltration
Operation DragonReturn India tax-season DcRAT campaign
Banana RAT / SHADOW-WATER-063 Brazilian banking fraud
Russian intelligence Signal backup-key phishing
Immobiliare Labs Backstage plugins npm compromise
Amazon Q CVE-2026-12957 MCP auto-execution
Linux pedit COW CVE-2026-46331 local privilege escalation
Linux DirtyClone CVE-2026-43503 local privilege escalation
Turla STOCKSTAY backdoor operations
Photo ZIP hospitality Node.js implant campaign
CL-STA-1062 Southeast Asia government and energy intrusions
PTC Windchill / FlexPLM CVE-2026-12569 exploitation
Adblock for YouTube BadBlocker remote-script injection risk
Backdoor.Mistic / KongTuke ModeloRAT activity
macOS.Gaslight Rust backdoor
Leo Platform npm Miasma-style compromise
simonecorsi/mawesome GitHub Action compromise
StrikeShark SharkLoader / Cobalt Strike campaign
codfish semantic-release-action tag compromise
html-to-gutenberg / fetch-page-assets VS Code blockchain stealer
StealC / Amadey infrastructure disruption
Sality P2P botnet disruption: CrowdStrike P2P sinkholing operation with DOJ/FBI (Aug 31, 2026)
Cisco Unified CM CVE-2026-20230 file-write exploitation
Thailand healthcare RAR / Python stealer campaign
xlabs_v1 DDoS-for-hire IoT botnet
WhatsApp VBScript ManageEngine RMM campaign
Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 exploitation
Lantronix EDS5000 CVE-2025-67038 exploitation
wshu.net npm credential-stealer campaign
Langflow CVE-2026-33017 cryptominer SSH worm
Fake-reputation crypto clipboard hijacker
Storm-2603 parallel SharePoint ransomware intrusion
postcss-minify-selector-parser npm RAT
FFmpeg PixelSmash CVE-2026-8461 media-file RCE
AryStinger legacy-router recon proxy network
@withgoogle/stitch-sdk scope squat
Gravity SMTP CVE-2026-4020 exploitation
Operation Endgame SocGholish disruption
FortiBleed Fortinet credential exposure
JetBrains AI plugin API-key theft
Klue Salesforce OAuth token abuse
GHOST STADIUM FIFA World Cup ticket phishing
procwire / routecraft npm Windows dropper
LiteSpeed cPanel Plugin CVE-2026-54420 exploitation
Joomla JCE CVE-2026-48907 exploitation
Glassworm developer supply-chain botnet
Crypto Clipper Tor / USB worm
Mastra easy-day-js npm scope compromise
Outsider Enterprise smishing PhaaS
Splunk Enterprise CVE-2026-20253 pre-auth file write / RCE
Chrome live-wallpaper extension ad-fraud network
Operation Highland Velvet Ant authentication-stack backdoors
Atomic Arch AUR package hijack
Astro config blockchain C2 PR injection
Solana FakeFix npm / PyPI developer stealer
Oracle PeopleSoft CVE-2026-35273 ShinyHunters exploitation
Ivanti Sentry CVE-2026-10520 exploitation
JDY SOHO / IoT reconnaissance botnet
SHADOW-AETHER AI-augmented Latin America intrusions
ServiceNow instance unauthenticated table-query exploitation
Arista EOS CVE-2026-7473 tunnel decapsulation exploitation
Chrome V8 CVE-2026-11645 exploitation
Linux nftables CVE-2026-23111 public LPE exploits
LiteLLM CVE-2026-42271 MCP stdio command injection
Quest KACE SMA CVE-2025-32975 exploitation
Check Point VPN CVE-2026-50751 exploitation
UNK_DeadDrop developer repository phishing
VerdantBamboo appliance BRICKSTORM operation
Hunt.io global smishing infrastructure campaign
Oman government Iranian-nexus webshell C2
MiniPlasma Windows Cloud Filter LPE exploitation
Telnyx PyPI TeamPCP compromise
Cisco Catalyst SD-WAN Manager CVE-2026-20245 / CVE-2026-20262 exploitation
SolarWinds Serv-U CVE-2026-28318 exploitation
Everest Forms Pro CVE-2026-3300 exploitation
PCPJack cloud SMTP relay network
Kali365 device-code phishing expansion
Stock exchange executive mailbox espionage
UNC6692 SNOW malware social-engineering campaign
binding.gyp npm CI/CD worm
Operation GriefLure Southeast Asia LNK dropper
faster-axios / turbo-axios Epsilon Stealer npm campaign
IronWorm npm Rust infostealer campaign
Mirasvit Cache Warmer CVE-2026-45247 exploitation
Gamaredon GammaPhish / GammaWorm / GammaSteel chain
Android Framework CVE-2025-48595 exploitation
Linux Kernel CVE-2022-0492 cgroup release_agent exploitation
Operation XENOFISCAL SideCopy XenoRAT campaign
Operation FlutterBridge FlutterShell macOS malvertising
WP Maps Pro CVE-2026-8732 exploitation
Oracle WebLogic CVE-2024-21182 exploitation
Operation Dragon Weave Azure Blob C2 campaign
Famous Chollima Packagist dev-branch loader
Dutch Police / NCSC 17-million-device botnet disruption
Pirated media SilentCryptoMiner RAT campaign
PAN-OS GlobalProtect CVE-2026-0257 exploitation
Marimo CVE-2026-39987 LLM-agent post-exploitation
PraisonAI CVE-2026-44338 rapid exploitation
JWR phishing framework (likely The Outsider variant)
NATS-as-C2 KeyHunter credential-harvesting operation
StegaBin Pastebin-steganography npm campaign
UNC6671 / BlackFile multi-brand vishing extortion operation
Sicoob.Sdk NuGet banking certificate stealer
Operation DangerousPassword axios npm compromise
FortiClient EMS CVE-2026-35616 EKZ Infostealer campaign
codexui-android OpenAI token stealer
vpmdhaj OpenSearch npm cloud-secret stealer
oob.moika.tech dependency-confusion environment stealer
DAEMON Tools Lite supply-chain compromise
Grandoreiro and BTMOB Latin America / Europe malware campaigns
Malware-Slop Claude user-data npm infostealer
JINX-0164 crypto developer infrastructure campaign
AI chatbot and SEO poisoning GPU-cryptojacking campaign
Chinese-language PhaaS wallet-tokenization ecosystem
Ababil of Minab MOIS-linked recovery-destruction campaign
KnowledgeDeliver CVE-2026-5426 ViewState exploitation
Funnull RingH23 and MacCMS supply-chain attacks
Mr_Rot13 cPanel CVE-2026-41940 backdoor campaign
Polymarket npm wallet-drainer packages
Ghost CMS CVE-2026-26980 ClickFix poisoning
TrapDoor crypto-stealer cross-ecosystem campaign
js-logger-pack Hugging Face exfiltration campaign
ScarCruft Yanbian game-platform supply-chain attack
APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
Microsoft Defender CVE-2026-41091 / CVE-2026-45498 exploitation
Trend Micro Apex One CVE-2026-34926 exploitation
Xinference PyPI compromise
Laravel-Lang Composer tag-rewrite compromise
LiteSpeed cPanel CVE-2026-48172 exploitation
Ollama P2P cryptominer RAT campaign
Drupal Core CVE-2026-9082 exploitation
Langflow CVE-2025-34291 exploitation
Megalodon GitHub Actions workflow backdooring
GitHub / Packagist postinstall hook campaign
BufferZoneCorp RubyGems / Go module CI poisoning
Bitwarden / Checkmarx Shai-Hulud Third Coming campaign
art-template Coruna-style iOS watering-hole compromise
shopsprint/decimal Go typosquat DNS backdoor
Mini Shai-Hulud npm/PyPI worm campaign
SANDWORM_MODE AI-toolchain npm worm
Nx Console VS Code extension compromise
actions-cool GitHub Actions tag compromise
node-ipc 2026 npm maintainer-account compromise
TamperedChef-style productivity malware clusters
Microsoft Midnight Blizzard mailbox theft from Microsoft
ConnectWise ScreenConnect exploitation wave
Codecov Bash Uploader compromise
Okta support-system compromise
CitrixBleed session-hijack wave
CircleCI 2023 customer secret exposure incident
CCleaner signed-update compromise
Barracuda ESG zero-day backdoor campaign
Accellion FTA exploitation campaign
3CX desktop app compromise
0ktapus phishing campaign
XZ Utils backdoor
tj-actions and reviewdog compromise
Trivy compromise
HackerBot Claw GitHub Actions exploitation campaign
LiteLLM compromise
Trivy → TeamPCP → CanisterWorm timeline
Tools
Tools
MovieReaper (Kaspersky GReAT, Sep 17): modular 4-stage Windows trojan framework distributed by trojanizing movie torrents (The Odyssey 2026) via the COMPROMISED SHARED TORRENT ARCHIVE itorrents[.]org - one upstream poisoning reaches every consuming tracker, archive still compromised at publication; stage-1 loader resolves APIs via PEB Ldr walk (no LoadLibrary), shellcode fragments over HTTP at image-like paths, RWX via VEH debug-break into raw NtProtectVirtualMemory + EtwpCreateEtwThread; STAGE 2 FETCHES NEXT C2 ADDRESS FROM A SOLANA MAINNET ACCOUNT DATA FIELD via public getAccountInfo RPC (account 6pnDG...nLDm, program CSiY8...wHtL) = takedown-resistant rendezvous; TLS-pinned nanopb protobuf; persistence masquerades as Telemetry/msedge.exe; 21-command file-manager implant + COFF module loading; several hundred victims, 14+ countries, actor since Oct 2025; choke point = stage 1 (deadhub[.]org / 193.23.118[.]155); Solana account/program = durable on-chain identifiers
OX Security (Sep 14) - four unauthenticated-critical CVEs in one 24-hour window, one shared trust failure. NETTY CVE-2026-75595 (9.1) - ClientHello bounds check is 5 bytes short; a legal fragmented ClientHello hits the catch-all and selects the DEFAULT SslContext = unauthenticated mTLS bypass where per-SNI REQUIRE is the sole gate; fixed 4.1.137/4.2.17 but the fail-open fallback REMAINS. GITPYTHON CVE-2026-78676 (9.8, fixed 3.1.59) - a dormant spec-compliant multi-line config value is inert for git, but GitPython's unsafe writer re-serializes it on any unrelated write into live core.hooksPath = RCE; prior guards only checked write arguments, never disk-read values. Plus two Next.js RCEs (Windows CVE-2026-75604 mechanism disclosed)
PhantomRaven (CrowdStrike, Sep 15): LLM-generated JS infostealer (high-confidence token-analysis assessment, author sophistication likely low) distributed via typosquatted npm packages by a self-proclaimed BUG BOUNTY HUNTER who infects targets then emails them 'discovering' his own manufactured compromise for bounty payouts; chain = clean placeholder package + HTTP-URL remote dynamic dependency (npm[.]jpartifacts[.]com) whose payload preinstall script auto-runs on legacy npm (npm >=12 blocks it pending install-scripts approve); publishers jpdhellonpm1/jpd15 both now 0.0.1-security = taken down; steals Git/npm config creds + CI/CD env vars (GitHub Actions/GitLab CI/Jenkins/CircleCI); no log-shop sales - output feeds bounty submissions; durable read: a 'responsible disclosure' email citing npm dependency confusion can itself be attack stage two
Check Point Security Management Server CVE-2026-91843: unauthenticated stack overflow in the login process -> remote root on Security Management / Multi-Domain / Log Servers (CVSS 9.8, urgent LivePatch, hunt 'Username too long' audit-log entries, EoS branches have no fix); fix = BUNDLE_URGENT_SECURITY_UPDATE LivePatch, validate with cplp list (Check Point sk1000155, Sep 16)
@zereight/mcp-gitlab CVE-2026-61560: unauthenticated SSE transport (the default Docker deployment) + arbitrary file read in upload_markdown exfiltrates /proc/self/environ -> GitLab PAT theft -> full account takeover (CVSS 9.8, advisory Sep 16) — one of SIX advisories on the package in ~10 weeks (siblings: SSRF X-GitLab-API-URL CVE-2026-61559, DNS-rebinding CVE-2026-61568, execute_graphql allowlist/read-only bypass, job_id traversal, release-asset path escape; siblings lack fixed versions — run the newest release + SSE_AUTH_TOKEN)
AMOS (Atomic macOS Stealer): Telegram-advertised macOS stealer whose indicators rotate constantly (Unit 42 saw full churn of domains/URLs/IPs/hashes/paths between the Jul 31 and Aug 5 2026 infections); durable chain = fake macOS-toolkit quick-setup page -> paste-into-Terminal Zsh fetching /curl/
-> /tmp/helper installer -> persistence in Apple-masquerade dot-dirs ~/Library/Application Support/.com.apple.accountsd (AccountsHelper) + .com.apple.metadata.mds (mdworker_shared); Terminal-app TCC permission prompts (Finder/Desktop/Documents/Notes); /tmp/out.zip with deskwallets/FileGrabber/Telegram layout; C2 stable tell = POST URL stage=boot|credentials|browsers|wallets|resolve_auth|local_data markers (Unit 42, Sep 16)
BraZetsu: Group-IB's high-confidence attribution to Exilware of a Python-based Windows IAB master toolkit fueling the 'Infected Marketplace' (Banco de Infects / infect[.]online) access-as-a-service platform (~$5.80 initial deposit) for Iberian/LATAM targets; CNAB/CNABHunter payment-fraud overlap and heavy generative-AI triage; first seen Feb 2, 2026 (Group-IB, Sep 3)
NodeRabbit: Mirage Kitten's first Node.js cross-platform RAT - bundled registry-absent npm package (colorized_terminal / pretty-log), per-OS persistence, fake 'GitHub Copilot Helper' VS Code extension, .git/hooks post-merge / post-checkout '# shepherd-persist' injection, Azure/Cloudflare C2 (Kaspersky, Sep 1)
PollCat: Mirage Kitten's JavaScript cross-platform RAT - trojanized React 'RankChallenge-react' coding challenge, root package.json named ctf-server, recruiter-supplied OTP forwarded to lifespotify[.]com, POST /beacon registration expecting HTTP 400 with socketId (same handshake as Retrograde/MiniFast), NetSync_
/ ~/.node_packages / com.harsh.requireobject.plist persistence (Kaspersky, Sep 1)
GoCaracal: Dark Caracal's Go malware framework with an Ethereum smart-contract C2 fallback (eth_getStorageAt)
Spark RAT: Cambodia-focused cluster, multi-stage Inno/DLL side-load chain, and the vulnerable OPSWAT ardrv.sys BYOVD driver
SLEEPWALKER: passive raw-packet backdoor with its own bytecode command language
Bifrost CVE-2026-90898: unauthenticated RCE - the AI gateway spawns your stdio MCP client the moment it is registered (auth defaults off, launch precedes handshake, fix not backported past v2.0.0/1.6.x); sibling CVE-2026-86242 (8.1, Sep 6): custom-plugin http:// path downloaded + plugin.Open'd on dynamically linked builds via the same auth-off API, fixed in v2.0.0
ParaShells / Parallels Desktop CVE-2026-90894: local unprivileged process to root via appliance-extract argument injection (tar --use-compress-program as root); 26.x unfixed
Chainlit MCP: unauthenticated RCE and SSRF via /mcp (CVE-2026-45018 / CVE-2026-45019)
Marimo CVE-2026-75149: attacker-supplied MCP command runs before cells execute in edit mode
Keycloak CVE-2026-18963: unauthenticated password-reset account takeover
workerd / Cloudflare Code Mode: sandbox escape and cross-tenant heap swipe
DeepSeek Harness CVE-2026-82533: sandboxed AI agent disables its own sandbox with one shell command (Host-header auth on loopback, no peer check; unauthenticated remote control + conversation exfil if port reachable)
AWS root user password-spraying campaign across 150+ organizations: two fixed user agents, residential-proxy tunneling, no confirmed success (Datadog, Aug 31, 2026)
SPECTRE (cross-platform C backdoor) and the Specter Linux rootkit
RedC2 4.0 (RedShell Linux beacon) and the trojanized-npm delivery wave
vm2 NodeVM host state exposure and DNS hijack
isolated-vm ExternalCopy type-confusion sandbox escape
JSONata arbitrary-code-execution trio (CVE-2026-77413 / -77414 / -77415)
Xinference CVE-2026-61539: RCE via unsafe eval() in Llama3 tool-call parsing
Kimwolf v7
Aeternum
DeadLock ransomware
FDMTP
XCSSET
OctLurk
SilkLurk
LurkProxy
OWAReaper
GenieLocker
NightLedger
BridgeHead
ArcBridge
TELESHIM
MIXEDKEY
BINDCLOAK
Ulej / Flowerbed
ENCFORGE
HOLLOWGRAPH
TELEPUZ
WLDR agent
Starland RAT
ACR Stealer
LabubaRAT
MODBEACON
GigaWiper
SCMBANKER
RedWing
GraphSpy
Cavern
QuimaRAT
CrownX
BusySnake Stealer
PamStealer
Umbrij
ChocoPoC
RustDuck
TaskWeaver
Djinn Stealer
STOCKSTAY
TinyRCT
MYRA RAT
SprySOCKS
The Gentlemen ransomware
Fast16
forge-jsxy
RemotePE
First VPN
ROADtools
Showboat
CanisterWorm
Groups
Groups
UAT-10147
Exilware
SilkParasite
TheHatman
JINX-0163 / FulcrumSec
Toy Ghouls
Mirage Kitten / UNC1549
CL-STA-1114 / Void Blizzard
UAC-0145
UAT-11795
Cavern Manticore
Armored Likho
ToddyCat
Mustang Panda
Turla
CL-STA-1062
UNC6508
FishMonger
Velvet Ant
Void Dokkaebi
ShinyHunters
OceanLotus
UAC-0226 / SHADOW-EARTH-066
VerdantBamboo
UNC3753
OP-512
TA4922
Gamaredon
SideCopy
Cloud Atlas
GREYVIBE
Kimsuky / Emerald Sleet / TA427
JINX-0164
APT29
Dragonfly
Handala
Seedworm / MuddyWater
Screening Serpens
Ghostwriter
HackerBot Claw
TeamPCP
Fox Tempest
Webworm
People
People
Overview
JiaT75
Patterns
Patterns
Unit 42: AWS AgentCore Harness - A Vault with a Heap-View: in the DEFAULT configuration an indirect prompt injection (hidden HTML comment: curl