{"id":2306,"date":"2026-08-10T16:40:55","date_gmt":"2026-08-10T16:40:55","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2306"},"modified":"2026-08-10T16:40:55","modified_gmt":"2026-08-10T16:40:55","slug":"ai-goes-rogue-metabase-0-day-mcp-supply-chain-attacks-and-router-backdoors","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2306","title":{"rendered":"AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 10, 2026<\/span><\/span><span class=\"p-tags\">Cybersecurity \/ Hacking<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjtXmkUOPD6prrNPMK9N1Rhu2dm3QFGQ2DUTiu3xrj2WWbauZ_IK2HemME36-4WBIqGh01SFOkNJuutFeXLgS_ZMUBFn5ZDzIP5_IeNrwJWDfKcOPQgZl3spOFVS8R84Hbthy6o3sx9IWJ1yRo4FiW5acGYGBrf2nljmx6yvSd55LWRrkX6JhJ9b5bHJX0g\/s1700-e365\/recaps.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default.<\/p>\n<p>That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place.<\/p>\n<p>That\u2019s only part of it. Here\u2019s everything else that made the Monday recap.<\/p>\n<h2 style=\"text-align: left;\"><strong>\u26a1 Threat of the Week<\/strong><\/h2>\n<p><strong>Anthropic&#8217;s Model Attempts to Poison Open-Source Project <\/strong>\u2014 A new evaluation conducted by the U.K. AI Security Institute (AISI) found that AI models with access to the internet reached out into the real world to target individuals and organizations autonomously across 10 of the total of 122 runs. Of 19 such actions recorded, 17 originated from Anthropic&#8217;s Mythos 5 and the remaining two involved OpenAI&#8217;s GPT-5.6-Sol with cyber classifiers. In the most serious case, Anthropic&#8217;s Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project and engaged in social engineering by creating fake online identities and using them to pressure the project&#8217;s maintainer to approve the code. Ultimately, a human maintainer caught and refused to approve the malicious code. \u00abThese attempts were unsuccessful, and our investigations have not evidenced any resulting real-world harm,\u00bb AISI said. But this is the first time we have seen risks around autonomy and deception manifest this clearly, without specific prompting, in the real-world.\u00bb<\/p>\n<h2 style=\"text-align: left;\"><strong>\ud83d\udd14 Top News<\/strong><\/h2>\n<ul>\n<li><strong><a href=\"https:\/\/thehackernews.com\/2026\/08\/metabase-zero-day-exploited-in-wild.html\" target=\"_blank\">Metabase 0-Day Exploited in Attacks <\/strong>\u2014 Metabase warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain administrator access to the instance. Armed with the elevated access, the attacker can change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. One of the companies that has been affected is Framework.<\/li>\n<li><strong>New Interrupt Injection Attack Bypass Spectre v2 Defenses on Intel and AMD CPUs <\/strong>\u2014 A group of researchers demonstrated a way to bypass defenses for the Spectre vulnerability impacting modern CPUs. \u00abThe defenses work by wiping or isolating the processor&#8217;s prediction machinery, removing anything an attacker might have planted,\u00bb MIT&#8217;s Computer Science and Artificial Intelligence Laboratory (CSAIL) said. \u00abThe catch [&#8230;] is that the wipe and the moment the predictions get used can&#8217;t happen at the same instant. There is always a gap \u2014 sometimes only a handful of instructions wide. Anything that runs in that gap can dirty the machinery all over again. The researchers call this class of attack TONTOU.\u00bb The study found a reliable way to get code into that gap using a technique called Interrupt Injection to ultimately pull secrets out of memory.<\/li>\n<li><strong>New CSS Attacks Can Break Webmail Defenses <\/strong>\u2014 New research demonstrated at the Black Hat conference last week detailed attack chains spanning Microsoft Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail that can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email. \u00abTrouble is you can create discrepancies between what the sanitizer thinks is safe and what the browser actually renders,\u00bb PortSwigger said. \u00abSome webmail clients go a step further by letting the browser parse the HTML and CSS first, then filtering the browser&#8217;s interpreted output rather than the original source. Yet even this can be mutated into something malicious.\u00bb<\/li>\n<li><strong>UNC6671 Vishing Attacks Target Financial Firms <\/strong>\u2014 A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671. The attacks employ voice phishing to target enterprise employees and trick them into visiting spoofed login portals where adversary-in-the-middle (AitM) infrastructure intercepts credentials and multi-factor authentication (MFA) tokens. The threat actors then leverage the captured data to establish session persistence and deploy automated Python and PowerShell scripts for data exfiltration from enterprise cloud environments and SaaS applications, including Microsoft 365 and Okta. UNC6671 has diversified its operations across multiple extortion brands including Redact, Pink (aka CL-CRI-1147), Helix, and Falcon (aka CL-CRI-1182). UNC6671 was previously said to have operated under the BlackFile (aka CL-CRI-1116) brand, targeting organizations via vishing and SSO compromise, before it was retired on May 11, 2026.<\/li>\n<li><strong>Chinese-Made Zbtlink Routers Ship With Backdoor <\/strong>\u2014 An analysis of firmware associated with Chinese router manufacturer Zbtlink has unearthed a factory-shipped backdoor that&#8217;s designed to phone home and run commands received from the server. The backdoors are designed such that they start automatically and attempt to beacon to Chinese command-and-control (C2) infrastructure as often as every 35 seconds. The backdoor is implanted in at least 20 router models. In response to the findings, Zbtlink reiterated that the \u00abremote management component\u00bb is used only for after-sales technical support and to \u00abassist customers with device troubleshooting and configuration only upon their explicit request and authorization.\u00bb The company also said it has never been used for unauthorized access. The company also said it&#8217;s developing and releasing firmware updates to address the issue.<\/li>\n<\/ul>\n<h2 style=\"text-align: left;\"><strong>\u200e\ufe0f\u200d\ud83d\udd25 Trending CVEs<\/strong><\/h2>\n<p>Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.<\/p>\n<p>Check the list, patch what you have, and hit the ones marked urgent first \u2014 CVE-2026-34348, <a href=\"https:\/\/kb.cert.org\/vuls\/id\/987105\" target=\"_blank\">CVE-2026-18497<\/a> (stb TrueType), <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/\" target=\"_blank\">CVE-2026-63508, CVE-2026-56162, CVE-2026-65667, CVE-2026-50515, CVE-2026-62830, CVE-2026-59115, CVE-2026-50481<\/a> (Microsoft Windows), CVE-2026-64638 (WordPress), CVE-2026-64564 (Linux SCTP), CVE-2026-56181 (Microsoft Windows NAT), CVE-2026-63913 (Linux), CVE-2026-64561 (Linux kernel), CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20267, CVE-2026-20272 (Cisco), CVE-2026-18830 (AWS AgentCore), CVE-2026-18236 (Google ADK), CVE-2026-64650, CVE-2026-64651 (Vercel), CVE-2026-41679, GHSA-x8hx-rhr2-9rf7 (Paperclip), CVE-2026-58073, CVE-2026-58072 (Veeam), CVE-2026-16498, CVE-2026-16496, CVE-2026-14869 (HashiCorp), CVE-2026-15307 (GeoDjango), CVE-2026-64531 (Linux kernel Open vSwitch), CVE-2026-18577, CVE-2026-18556 (N-able N\u2011central), CVE-2026-59774 (Gitea), CVE-2026-58048 (cPanel), CVE-2026-17583 (Thermo Fisher Scientific), <a href=\"https:\/\/kb.cert.org\/vuls\/id\/487613\" target=\"_blank\">CVE-2026-8496<\/a> (Alinto SOGo), <a href=\"https:\/\/support.apple.com\/en-us\/148170\" target=\"_blank\">CVE-2026-65400<\/a> (Apple macOS Tahoe, macOS Sequoia, and macOS Sonoma), <a href=\"https:\/\/chromereleases.googleblog.com\/2026\/08\/stable-channel-update-for-desktop_01193673229.html\" target=\"_blank\">CVE-2026-19137, CVE-2026-19149, CVE-2026-19154, CVE-2026-19157, CVE-2026-19170, CVE-2026-19172<\/a> (Google Chrome), <a href=\"https:\/\/kevintel.com\/CVE-2013-3821\" target=\"_blank\">CVE-2013-3821<\/a> (Oracle PeopleSoft), <a href=\"https:\/\/kevintel.com\/CVE-2025-8943\" target=\"_blank\">CVE-2025-8943<\/a> (Flowise), and an SQL injection in Metabase.<\/p>\n<h2 style=\"text-align: left;\"><strong>\ud83c\udfa5 Cybersecurity Webinars<\/strong><\/h2>\n<ul>\n<li><strong><a href=\"https:\/\/thehacker.news\/secure-ai-development\" target=\"_blank\">Build a Security Strategy for AI-Speed Development<\/a><\/strong> \u2192 AI is pushing software delivery far beyond the pace traditional security programs were designed for. This session shows security leaders how to govern AI-built software, reduce risk without slowing teams down, and build controls that scale with machine-speed development.<\/li>\n<li><strong><a href=\"https:\/\/thehacker.news\/ai-coding-risk\" target=\"_blank\">Benchmark Your AI Coding Risk Against 300 Security and Engineering Leaders<\/a><\/strong> \u2192 AI coding is bringing more unvetted open source into production and expanding remediation debt. This session gives security and engineering leaders peer benchmarks, a data-backed framework for measuring business impact, and a clear view of which governance models are actually reducing risk.<\/li>\n<li><strong><a href=\"https:\/\/thehacker.news\/ai-threat-readiness\" target=\"_blank\">Build a Security Operations Strategy for Machine-Speed Attacks<\/a><\/strong> \u2192 AI can now find vulnerabilities, generate exploits, and build attack paths at machine speed. This session gives security leaders a practical framework to assess AI threat readiness, improve attack-surface visibility, and accelerate investigation and remediation before existing processes become the bottleneck.<\/li>\n<\/ul>\n<h2 style=\"text-align: left;\"><strong>\ud83d\udcf0 Around the Cyber World<\/strong><\/h2>\n<ul>\n<li><strong>New Shai-Hulud Version Weaponizes the MCP Registry <\/strong>\u2014 A new version of the Shai-Hulud worm spread through the open-source ecosystems is equipped to deliver the payload via the Model Context Protocol (MCP) Registry. \u00abWhile earlier iterations of Shai-Hulud tampered with local AI coding client configs, this marks the first time we observed a Shai-Hulud payload being delivered directly through the official Model Context Protocol (MCP) Registry (registry.modelcontextprotocol.io),\u00bb OX Security <a href=\"https:\/\/www.ox.security\/blog\/shai-hulud-outbreak-debrief-the-worm-evolves-into-mcp\/\" target=\"_blank\">said<\/a>. The attack works like this: the npm and PyPI package linked by the MCP server is completely clean, but opening or cloning the linked MCP server GitHub repository (\u00abjUXTAPOSITION1\/V.A.P.E\u00bb) inside Claude Code or VS Code triggers the malware, leading to the collection of developer tokens, cloud credentials, and session keys. The worm spread through 440 unique npm packages.<\/li>\n<li><strong>China Launches Review of Palo Alto Networks <\/strong>\u2014 China&#8217;s Cyberspace Administration (CAC) has announced it&#8217;s conducting a review of Palo Alto Networks&#8217; products. \u00abIn order to ensure the safe and stable operation of critical information infrastructure, prevent hidden risks of network security, and safeguard national security, in accordance with the National Security Law of the People&#8217;s Republic of China and the Cyber Security Law of the People&#8217;s Republic of China, the Network Security Review Office implements network security review of products sold by Palo Alto in China in accordance with the &#8216;Network Security Review Measures,'\u00bb the CAC <a href=\"https:\/\/www.cac.gov.cn\/2026-08\/06\/c_1787764332950791.htm\" target=\"_blank\">said<\/a>.<\/li>\n<li><strong>Papyrus Uses Fake Novel Reading Apps for Ad Fraud <\/strong>\u2014 A new mobile ad fraud scheme dubbed Papyrus has been observed leveraging a \u00abcluster of novel-reading applications that monetize users&#8217; reading sessions by running hidden browser activity in the background,\u00bb Integral Ad Science <a href=\"https:\/\/integralads.com\/insider\/papyrus-inside-a-mobile-scheme-built-to-fake-clicks-scrolls-and-attention\/\" target=\"_blank\">said<\/a>. \u00abWhile users believe they&#8217;re simply reading a story, the apps are secretly using their phone to visit websites, generate clicks, and create fake engagement behind the scenes. The apps present themselves as entertainment products built around long-form fiction and serialized stories, but IAS observed them covertly navigating to web domains under the direction of command-and-control infrastructure.\u00bb Papyrus is built around BootNova, an orchestration layer that controls hidden browser activity inside the app. When the app runs, BootNova contacts remote command-and-control infrastructure for configuration. The remote configuration can control enablement, timing, geographic targeting, retry behavior, the number of WebViews to run, destination URLs, and the interaction logic applied to those pages. Papyrus has been linked to more than 800 domains and nearly 8,000 unique hostnames.<\/li>\n<li><strong>Estimated $30M Stolen in Violent Crypto Attacks in 2026 <\/strong>\u2014 An estimated $30 million is said to have been stolen in violent \u00abwrench attacks\u00bb in 2026, according to Chainalysis. \u00abHome invasions now account for 37% of incidents in 2026, up from 26% in 2023,\u00bb it <a href=\"https:\/\/www.chainalysis.com\/blog\/violent-crypto-wrench-attacks-2026\/\" target=\"_blank\">said<\/a>. \u00abKidnappings have remained relatively stable year-over-year (YoY) in terms of share of total attacks.\u00bb In contrast, annual value stolen in violent attacks peaked at $58 million in 2025.<\/li>\n<li><strong>26 Ransomware Attacks Per Day in July 2026 <\/strong>\u2014 According to Comparitech, July 2026 saw nearly 26 ransomware attacks per day, up from 22 per day in June. The number of ransomware attacks jumped from 668 in June to 799 in July. \u00abThe education sector saw a significant increase (up 44%), as did finance companies (up 71%), tech firms (up 62%), and businesses operating within the healthcare sector, e.g. pharmaceutical manufacturers and medical billing providers (up 46%),\u00bb Comparitech <a href=\"https:\/\/www.comparitech.com\/news\/ransomware-roundup-july-2026\/\" target=\"_blank\">said<\/a>. The most prolific groups were The Gentlemen (135), Qilin (125), DragonForce (41), INC (36), and CRPx0 (33).<\/li>\n<li><strong>Device Code Phishing Evasion Techniques Detailed <\/strong>\u2014 Palo Alto Networks Unit 42 <a href=\"https:\/\/github.com\/PaloAltoNetworks\/Unit42-timely-threat-intel\/blob\/main\/2026-07-23-Device-code-phishing-evasion-techniques.txt\" target=\"_blank\">said<\/a> it identified four evasion techniques that are currently being used in device code phishing campaigns. This includes CAPTCHA gates, multi-step flows that go through multiple SaaS hosting platforms separating the initial link from the phishing content to evade URL reputation checks, blob URL delivery, and the use of Cyrillic characters in place of Latin letters, zero-width spaces, and strings inside <bdi> tags to break content-based detection.<\/bdi><\/li>\n<li><strong>From LLMJacking to Token Jacking <\/strong>\u2014 A growing number of security incidents involving AI token jacking have resulted in financial losses for victims. \u00abThe financial loss comes from criminals gaining access to API keys used by legitimate developers for access to popular AI platforms,\u00bb Unit 42 <a href=\"https:\/\/unit42.paloaltonetworks.com\/ai-token-jacking\/\" target=\"_blank\">said<\/a>. \u00abThe unrelenting frenzy of AI adoption and soaring costs of model access are converging into an irresistible opportunity for cybercriminals. Premium pricing on scarce AI processing power means stolen access via tokens can generate a quick and easy profit for attackers. Complex, patchwork billing management and limitless scaling by default can lead to massive financial losses in short periods.\u00bb<\/li>\n<li><strong>ScarCruft Leverages RokRAT in New Attacks <\/strong>\u2014 Spear-phishing emails disguised as materials for actual academic events and seminars are being used to deliver RokRAT, a remote access trojan linked to a North Korean group known as ScarCruft. \u00abAlthough the file was disguised as a PDF, it actually delivered a malicious ISO file through a cloud storage link,\u00bb Genians <a href=\"https:\/\/www.genians.co.kr\/en\/blog\/threat_intelligence\/rokrat_capsule_vault\" target=\"_blank\">said<\/a>. \u00abThe ISO contained an executable disguised as a PDF document, using the &#8216;.pdf,&#8217; &#8216;.pif&#8217; extension to induce the user to run it. The attack loaded the shellcode payload into memory and injected a RokRAT variant into a process.\u00bb<\/li>\n<li><strong>Kimsuky Uses New Gomir Variant <\/strong>\u2014 Speaking of North Korean threat groups, the threat actor tracked as Kimsuky is said to have gained control of internet-facing servers through vulnerability exploitation and spear-phishing and deployed a new variant of a backdoor called Gomir, a Linux variant of the Windows-based GoBear backdoor. \u00abKimsuky developed Gomir variants with significantly altered C2 communication methods to evade detection, including leveraging Google Drive as a C2 channel and implementing a new custom protocol,\u00bb ENKI <a href=\"https:\/\/www.enki.co.kr\/en\/media-center\/blog\/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant\" target=\"_blank\">said<\/a>. In at least one case in December 2025, the threat actor has been found deploying HttpTroy, which is then used to install additional tools, including DWAgent and a proxy tool. Kimsuky has also been <a href=\"https:\/\/www.genians.co.kr\/en\/blog\/threat_intelligence\/kimsuky_ai_llm\" target=\"_blank\">observed<\/a> setting up local large language model (LLM) environments using Ollama, GPT4All, and Msty to augment its operations and target foreign diplomatic missions, as well as the military, security, and virtual asset sectors. The attacks have leveraged <a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/dprk-related-campaigns-with-lnk-and-github-c2\" target=\"_blank\">Git-based repositories<\/a> as C2 and distribution channels for encrypted AsyncRAT payloads. The activity has been codenamed Operation GitPower, citing similarities with FlowerPower. Last year, the group was tied to campaigns that involved abusing OpenAI&#8217;s ChatGPT to forge deepfake military ID cards in a spear-phishing campaign against South Korean defense-affiliated entities and other individuals focused on North Korean affairs, such as researchers, human rights activists, and journalists.<\/li>\n<\/ul>\n<h2 style=\"text-align: left;\"><strong>Conclusion<\/strong><\/h2>\n<p>Maybe the real problem is not that security keeps failing in surprising ways. It\u2019s that the \u201csurprising\u201d part usually disappears the moment someone shows how little it took.<\/p>\n<p>That\u2019s worth remembering. Attackers do not need perfect conditions. They just need one assumption nobody checked, one shortcut nobody revisited, or one old weakness that quietly stayed useful.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 10, 2026Cybersecurity \/ Hacking A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed.&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2307,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[346,24,104,765,2955,699,697,579],"class_list":["post-2306","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-0day","tag-attacks","tag-backdoors","tag-mcp","tag-metabase","tag-rogue","tag-router","tag-supplychain"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2306","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2306"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2306\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2307"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2306"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2306"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2306"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}