{"id":2826,"date":"2026-09-14T16:24:58","date_gmt":"2026-09-14T16:24:58","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2826"},"modified":"2026-09-14T16:24:58","modified_gmt":"2026-09-14T16:24:58","slug":"rogue-ai-agents-wechat-worm-papercut-attacks-ai-espionage-and-rootkits","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2826","title":{"rendered":"Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 14, 2026<\/span><\/span><span class=\"p-tags\">Cybersecurity \/ Hacking<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgubijVX34VFFHDXzT2j2iTTWrHaElVXjylLKHKAjeSU59q3jTZvRM_O35zw5QOCnrT8ejrYHTG-kjYyt0-R127H_2qEgIWJNuKynEL1FcM9JLyPbsJPY5OZW9rrkJpRprrxpWP8oAGZA2ARZ3xg_0DvBw1I2wbIoXKItcVEjNXQH-CXCMRyuqp1u53ALj7\/s1700-nu-rw-lo-l85-e365\/recap-cyber.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination.<\/p>\n<p>The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of these stories are clever. Most are just easy.<\/p>\n<p>Here\u2019s what mattered this week.<\/p>\n<h2 style=\"text-align: left;\"><strong>\u26a1 Threat of the Week<\/strong><\/h2>\n<p><strong>OpenAI Agents Behind May 2026 Attack on RubyGems <\/strong>\u2014 The \u00abmajor malicious attack\u00bb that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to researchers. The event was driven by a cluster of OpenAI agents that engaged in en masse publication of thousands of packages to RubyGems in May and June 2026. \u00abThe swarm behaves extremely similarly to the German-wiki agents we previously found,\u00bb researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx said. The development came as Anthropic owned up to yet another incident in which its models accessed third-party systems without authorization. The new AI trespass dates back to January 2026. It involved an early version of Claude Opus 4.6 that was given a Capture the Flag (CTF) challenge. \u00abThe model discovered a machine belonging to a third party that it was able to access, and stated that it believed this third party was part of the CTF,\u00bb it said. \u00abInside the machine, the model found a file listing a password, which it used to gain admin access to the system.\u00bb The model went on to collect more credentials, altered a system setting to make the system easier to reach, and read personal information belonging to one individual connected to that unnamed organization. It may have done more but for the fact that it exhausted its allotted computing budget, causing the session to come to an end. Many incidents involving agents from frontier AI labs acting against their programming to escape restrictions in pursuit of their goals have heightened concerns over the increasing capacity of AI models and developers&#8217; ability to contain them. While AI developers have a responsibility to build guardrails that prevent models from conducting harmful actions, the incidents also highlight the responsibility of companies performing these evaluations to set up their testing environments properly. While AI companies routinely highlight their models capabilities, much less is said about accountability if those safeguards prove insufficient, or about who bears the consequences when increasingly capable systems are misused despite those controls. <\/p>\n<h2 style=\"text-align: left;\"><strong>\ud83d\udd14 Top News<\/strong><\/h2>\n<ul>\n<li><strong><a href=\"https:\/\/thehackernews.com\/2026\/09\/autonomous-ai-agents-compromise.html\" target=\"_blank\">Anthropic and Google Detail Abuse of AI <\/strong>\u2014 Threat actors are increasingly integrating AI capabilities into multiple stages of an attack lifecycle with an aim to automate and scale their operations. \u00abOver the past quarter, threat actors have moved beyond simple prompt-based LLM interactions to integrate AI capabilities into multiple stages of an attack lifecycle,\u00bb Google Threat Intelligence Group (GTIG) said. \u00abWhile traditional script-based automation has long been a staple of threat actor operations, groups are increasingly upgrading these workflows, creating highly autonomous systems capable of reasoning through complex tasks and making dynamic decisions without the need for human oversight.\u00bb GTIG said it \u00abhas not yet observed threat actors deploying fully autonomous pipelines against targets in the wild,\u00bb with the adversarial adoption of agentic AI signaling \u00aba gradual maturation of tradecraft,\u00bb as adversaries employ commercial and open-weight models to turn public disclosures and patch delays into working N-day exploit code, refining their tooling, and progressing \u00abtoward constructing functional, multi-stage exploit chains.\u00bb<\/li>\n<li><strong>Threat Actors Exploit New Vulnerability Chain <\/strong>\u2014 Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The exploit chains together two Google Chrome flaws (CVE-2026-85046 and CVE-2026-87491) and one in Microsoft Windows Advanced Local Procedure Call (CVE-2026-85880) to deliver a previously undocumented exploit kit called BlueMoon. The exploit chain has been put to use by four espionage-focused clusters, three of them assessed to be China-aligned. Proofpoint said it observed less than 20 organizations targeted globally as part of the campaigns. The episode fits a recurring pattern in which otherwise separate China-linked threat actors obtain access to the same offensive tooling at about the same time, raising questions about a digital quartermaster that supplies them with the same tool, or if it&#8217;s being sold to multiple threat actors as a service.<\/li>\n<li><strong>Disgruntled Researcher Drops New Microsoft Defender PoC <\/strong>\u2014 The disgruntled security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. ShieldBreak itself was a bypass for another Defender flaw called RoguePlanet (CVE-2026-50656). The release of this new zero-day is the latest in a long back-and-forth between the security researcher and the software giant over the company&#8217;s alleged handling of their bug reports. The researcher has since revealed himself to be <a href=\"https:\/\/x.com\/MSNightmare2000\/status\/2099082012996858204\" target=\"_blank\">Abdelhamid Naceri<\/a>, a former Microsoft employee who said he was fired in September 2024 over concerns that he \u00abput the company and customers at risk by sharing vulnerability information with external parties.\u00bb Naceri has been previously credited with CVE-2021-41379 and CVE-2021-24084.<\/li>\n<li><strong>Xinbi Guarantee Goes Down in Law Enforcement Action <\/strong>\u2014 The U.S. Department of Justice (DoJ) announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime syndicates. The Treasury Department announced sanctions on the Chinese-language platform, Xinbi Guarantee, and two businesses it accused of supporting the marketplace&#8217;s operations: Anwen Technology, the Cambodia-based developer of a cryptocurrency payment app called XinbiPay, and SafeW Technology Co., maker of an encrypted messaging application allegedly used by Xinbi&#8217;s money-laundering and merchant networks. \u00abXinbi runs an escrow-backed marketplace that connects scam syndicates with vendors selling stolen data, fake identity documents, deepfake tools, and cash-out services, settling primarily in USDT on TRON,\u00bb TRM Labs <a href=\"https:\/\/www.trmlabs.com\/resources\/blog\/the-us-sanctions-xinbi-one-of-southeast-asias-largest-illicit-crypto-marketplaces\" target=\"_blank\">said<\/a>. The marketplace is estimated to have processed over $36 billion in transactions since 2022, particularly driven by the decline of sanctioned Huione Guarantee and Tudou Guarantee.<\/li>\n<li><strong>Zero-Click WeChat Worm Could Hijack Accounts and Spread via Single Call <\/strong>\u2014 Calif researchers disclosed details of a <a href=\"https:\/\/www.nytimes.com\/2026\/09\/08\/us\/politics\/calif-ai-worm-wechat-hack.html\" target=\"_blank\">critical vulnerability<\/a> in Tencent-owned WeChat that could be used to create a worm, dubbed WeWorm, that&#8217;s capable of spreading through calls across both Android and iOS, even without the recipient answering the call. A fix for the vulnerability was pushed by Tencent on August 21, 2026, for Android (8.0.77) and iOS (8.0.76). The exploit essentially takes control of a victim&#8217;s WeChat account within seconds, which then calls another contact and repeats the process without user interaction. Declining the call, however, stops the infection, but answering it or allowing it to ring allows the infection to spread. \u00abExploitation takes only seconds, and gives us full control of the WeChat account,\u00bb Calif said. \u00abWe can read and send messages, make calls, and act on the victim&#8217;s behalf.\u00bb A key prerequisite is that the exploit requires the attacker to be on the victim&#8217;s friends list. In a hypothetical attack scenario, an attacker could exploit another app, gain root access using techniques like those in <a href=\"https:\/\/calif.io\/research\/oempocalypse\" target=\"_blank\">OEMpocalypse<\/a> to take over the victim&#8217;s WeChat app, and use it to initiate the attack. There is no evidence the WeChat flaw was exploited in the wild.<\/li>\n<li><strong>Google Play Early Access Becomes a Security Blind Spot <\/strong>\u2014 Bad actors are misusing Google Play&#8217;s Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. \u00abThe same feature that shields developers from unfair criticism also strips users of the earliest warning that an app cannot be trusted,\u00bb Bitdefender said. The company&#8217;s analysis found thousands of Early Access apps that appeared to include fake casino and reward games, and potentially misleading utilities and applications using recognizable third-party trademarks. Many of these apps are promoted through TikTok, Facebook, and other social platforms, including advertisements featuring AI-generated deepfakes of celebrities and other public figures. Some of these apps have been found to seek unusual permissions (e.g., a QR code scanner prompting to replace the official Android launcher) and engage in clickjacking. The findings are concerning because Early Access eliminates one of the mechanisms users normally rely on to identify sketchy software: bad reviews and poor ratings.<\/li>\n<li><strong>Hackers Deploy Linux Rootkit on F5 BIG-IP APM Devices <\/strong>\u2014 Bad actors are deploying a Linux rootkit on hacked F5 BIG-IP APM devices to intercept PHP file loading and inject a fileless web shell directly into memory. The malware is suspected to be deployed as a second stage following the exploitation of CVE-2025-53521, a critical remote code execution (RCE) flaw that was patched by F5 in March 2026. The injected web shell accepts specially formatted requests, decrypts their contents, executes them through PHP&#8217;s eval() function, and returns an HTTP 201 response dressed up as a CSS stylesheet. ESET is tracking the same malware as PoisonedRefresh.<\/li>\n<li><strong>Hackers Exploit Sogou Input Method Flaw to Deploy GRAYRABBIT <\/strong>\u2014 Threat actors with links to a China-aligned espionage group have been found exploiting a critical vulnerability (CVE-2026-51990) in Tencent&#8217;s Sogou Input Method for Windows to deploy GRAYRABBIT, a backdoor previously identified as used by UNC3569. \u00abThe vulnerability chains three separate weaknesses into a single, one-click exploit: unvalidated command-line argument injection in the sgbiz: custom protocol handler, unrestricted URL navigation in a CEF-based webview, and a severely outdated, unsandboxed Chromium browser engine,\u00bb Gen said. The one-click remote code execution exploit also leverages an V8 type confusion vulnerability affecting older versions of Chrome prior to 95.0.4638.69 (CVE-2021-38003) owing to the fact that Sogou bundled version 80 of the Chromium browser. Tencent fixed the flaw in April 2026.<\/li>\n<\/ul>\n<h2 style=\"text-align: left;\"><strong>\u200e\ufe0f\u200d\ud83d\udd25 Trending CVEs<\/strong><\/h2>\n<p>Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.<\/p>\n<p>Check the list, patch what you have, and hit the ones marked urgent first \u2014 CVE-2026-85880, CVE-2026-81963 (Microsoft Windows), CVE-2026-85706 (GitLab), CVE-2026-44756, CVE-2026-58240 (SAP), <a href=\"https:\/\/access.redhat.com\/security\/cve\/CVE-2026-76578\" target=\"_blank\">CVE-2026-76578<\/a> (FreeIPA), <a href=\"https:\/\/kb.cert.org\/vuls\/id\/943094\" target=\"_blank\">CVE-2026-84282<\/a> (Ascensio System SIA ONLYOFFICE ownCloud integration plugin), <a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/43187903921559-Security-CVE-2026-67401-SQL-Injection-Vulnerability-in-cPanel-s-EmailTrack-Functionality-September-8-2026\" target=\"_blank\">CVE-2026-67401<\/a> (cPanel and WHM), <a href=\"https:\/\/www.ox.security\/blog\/cve-2026-82533-deepseek-harness-ai-agent-sandbox-escape\/\" target=\"_blank\">CVE-2026-82533<\/a> (DeepSeek Harness), <a href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2026-10090\" target=\"_blank\">CVE-2026-10090<\/a> (Red Hat Advanced Cluster Management for Kubernetes), <a href=\"https:\/\/www.tenable.com\/security\/tns-2026-21\" target=\"_blank\">CVE-2026-18667<\/a> (Tenable Sensor Proxy), <a href=\"https:\/\/kb.cert.org\/vuls\/id\/718077\" target=\"_blank\">CVE-2026-20293, CVE-2026-33197, CVE-2026-6485<\/a> (UEFI Shell), <a href=\"https:\/\/kb.cert.org\/vuls\/id\/859658\" target=\"_blank\">CVE-2025-20701<\/a> (Skullcandy Dime 3), <a href=\"https:\/\/www.fortiguard.com\/psirt\" target=\"_blank\">CVE-2026-84390, CVE-2026-84388, CVE-2026-26084, CVE-2026-84393<\/a> (Fortinet), <a href=\"https:\/\/www.ivanti.com\/blog\/september-2026-security-update\" target=\"_blank\">CVE-2026-12647, CVE-2026-12645, CVE-2026-12646, CVE-2026-12650, CVE-2026-12744, CVE-2026-12745<\/a> (Ivanti), <a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX697034&amp;articleURL=Citrix_Workspace_app_for_Windows_Security_Bulletin_CVE_2026_78546_and_CVE_2026_78547\" target=\"_blank\">CVE-2026-78546, CVE-2026-78547<\/a> (Citrix), <a href=\"https:\/\/support.checkpoint.com\/results\/sk\/sk1000117\/\" target=\"_blank\">CVE-2026-85102<\/a>, <a href=\"https:\/\/support.checkpoint.com\/results\/sk\/sk1000118\/\" target=\"_blank\">CVE-2026-85103<\/a> (Check Point), <a href=\"https:\/\/www.gendigital.com\/blog\/insights\/research\/one-click-backdoor-sogou\" target=\"_blank\">CVE-2026-51990<\/a> (Tencent Sogou Input Method), <a href=\"https:\/\/www.wiz.io\/blog\/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201\" target=\"_blank\">CVE-2026-42016, CVE-2026-42018, CVE-2026-82329<\/a> (JFrog Artifactory), <a href=\"https:\/\/kb.cert.org\/vuls\/id\/369611\" target=\"_blank\">CVE-2026-84286<\/a> (ExLlamaV3), <a href=\"https:\/\/blog.quarkslab.com\/chamilo-lms-its-raining-0days-hallelujah-its-raining-0days.html\" target=\"_blank\">CVE-2026-61578, CVE-2026-61582, CVE-2026-61583, CVE-2026-61584, CVE-2026-61585, CVE-2026-61587, CVE-2026-61600, CVE-2026-61601, CVE-2026-61602, CVE-2026-70647, CVE-2026-70648<\/a> (Chamilo), and a <a href=\"https:\/\/kb.cert.org\/vuls\/id\/687587\" target=\"_blank\">local privilege escalation vulnerability<\/a> in AOMEI Backupper amwrtdrv.sys driver.<\/p>\n<h2 style=\"text-align: left;\"><strong>\ud83c\udfa5 Cybersecurity Webinars<\/strong><\/h2>\n<ul>\n<li><strong><a href=\"https:\/\/thehacker.news\/outpacing-ai-era-attacks\" target=\"_blank\">Learn How to Know What to Fix First Before AI Speeds Up the Attack<\/a><\/strong> \u2192 AI-powered attacks are accelerating, but fragmented security data slows down the response. Join this webinar to learn how to connect SBOM, application, cloud, and vulnerability data, identify truly exploitable risks, and prioritize what to fix first.<\/li>\n<li><strong><a href=\"https:\/\/thehacker.news\/ready-for-mythos-class-attacks\" target=\"_blank\">How to Identify Which CVEs Are Truly Exploitable Within Hours<\/a><\/strong> \u2192 AI can turn newly disclosed vulnerabilities into working attacks within hours. Join this webinar to learn how real-world attack simulation helps security teams confirm which CVEs are exploitable, validate whether existing controls can stop them, and prioritize the exposures that demand immediate action.<\/li>\n<\/ul>\n<h2 style=\"text-align: left;\"><strong>\ud83d\udcf0 Around the Cyber World<\/strong><\/h2>\n<ul>\n<li><strong>China Company Uses Claude for Deceptive Dating Network <\/strong>\u2014 Anthropic <a href=\"https:\/\/www.anthropic.com\/threat-intelligence-report-september-2026#scams-and-fraud-sep-26\" target=\"_blank\">said<\/a> it observed a China-based app studio using Claude to build over 20 dating apps with 4,700 AI personas that held conversations with at least 25,000 users who thought they were talking to real people. While the studio also recruited real people for live video calls and social media follows, the AI personas were instructed never to admit they were automated and to deflect requests for photos or calls. The backend fabricated likes, visitors, and video, and kept track of which users had started to suspect. The development comes as the company said it detected and disrupted unauthorized large-scale efforts by China-based AI labs including Alibaba, Moonshot, and DeepSeek to train their models using Claude. Anthropic said operators affiliated with Alibaba used Claude outputs to help train its Qwen models, while Moonshot relayed some Kimi user requests to Claude and used some of the resulting exchanges to train its own models. China <a href=\"https:\/\/arstechnica.com\/tech-policy\/2026\/09\/six-chinese-ai-firms-accused-of-aggressively-copying-us-frontier-models\/\" target=\"_blank\">dismissed<\/a> the U.S. allegations as \u00abgroundless.\u00bb<\/li>\n<li><strong>Russia Uses AI for Cyber Espionage <\/strong>\u2014 In more AI abuse, Anthropic also said it disrupted a cyber espionage operation whose tradecraft and targeting match the Russian state-nexus group tracked as Midnight Blizzard. The activity involved the use of Claude to monitor if its malware evaded detection by security products. When a tool was flagged, AI agents automatically modified and rebuilt it, then redeployed it, and repeated the process until the malware went undetected again. This approach, Anthropic said, shifts the onus back on defenders, allowing capable adversaries to \u00abclose the loop\u00bb and bypass traditional security controls faster than defenders can develop and deploy them. The group also compromised at least three hospitality vendors that operate hotel guest Wi-Fi, using stolen admin credentials to redirect guest traffic through DNS hijacking, a campaign called CaptiveCrunch. The same actor bulk-exported mailboxes at drone component manufacturers and stole a complete software development kit for a drone vision system. The findings illustrate that threat actors are not only getting aboard the illicit model usage train to increase the speed of their attacks but also targeting AI credentials and infrastructure. What&#8217;s more, the technology has collapsed the skill gap that set state-sponsored hackers apart from script kiddies. In other words, sophistication is no longer a \u00abreliable signal of who is behind an operation.\u00bb Anthropic also said, \u00abWith AI, diverse target environments are made trivial to understand and adjust to; unique and obscure configurations are made clear and exploitable. The old adage of &#8216;security through obscurity&#8217; is no longer viable in this new AI-assisted world: everything connected to the internet is a potential target for exploitation.\u00bb Google&#8217;s David Agranovich <a href=\"https:\/\/x.com\/DavidAgranovich\/status\/2098168519259218096\" target=\"_blank\">said<\/a>: \u00abThe gap between a lone operator and a nation-state actor has mostly closed. Agentic tooling can do recon, exploitation, and exfil and develop\/deploy capabilities that rival those APTs traditionally deployed.\u00bb<\/li>\n<li><strong>OpenAI&#8217;s Agents Used 10 Sites for Unauthorized Comms <\/strong>\u2014 In a report last week, Reuters <a href=\"https:\/\/www.reuters.com\/world\/openais-rogue-agents-used-least-10-more-sites-unauthorized-comms-researchers-say-2026-09-09\/\" target=\"_blank\">said<\/a> AI agents from OpenAI used more than 10 previously undisclosed websites for unsanctioned communications earlier this year, indicating that the rogue activity was much wider in scope than previously thought. This included \u00aba core set of communally edited wikis, online text storage sites, and a pair of link shorteners run by two universities.\u00bb<\/li>\n<li><strong>Anthropic Calls for Pacing the Frontier <\/strong>\u2014 Anthropic CEO Dario Amodei <a href=\"https:\/\/darioamodei.com\/post\/we-must-pace-the-frontier\" target=\"_blank\">said<\/a> the company is \u00abunilaterally committing\u00bb to giving third-party evaluators permanent, employee-like access to verify its adherence to safety measures, in addition to urging AI companies to slow how quickly they improve their most advanced models. The second step requires AI companies to establish \u00abcommon safety standards\u00bb with the help of governments in order to restrict the rate of unchecked AI progress. The final measure would have the U.S. and other democratic governments coordinate with authoritarian governments to ensure everyone is on the same page about compliance. OpenAI CEO Sam Altman <a href=\"https:\/\/www.cnbc.com\/2026\/09\/12\/anthropics-amodei-proposes-plan-to-slow-the-pace-of-advancing-ai-capabilities.html\" target=\"_blank\">said<\/a> he agrees with Amodei that \u00abcommitting to having independent evaluators with employee-like access is a great idea\u00bb, and OpenAI will follow suit. Google DeepMind&#8217;s Demis Hassabis <a href=\"https:\/\/www.cnbc.com\/2026\/09\/13\/china-dilemma-ai-slowdown-anthropic.html\" target=\"_blank\">said<\/a> \u00abthe direction is correct for meeting this critical moment.\u00bb<\/li>\n<li><strong>Ukrainian National Sentenced to 4 Years in Prison for Conti Attacks <\/strong>\u2014 Oleksii Oleksiyovych Lytvynenko, 44, was sentenced to sentenced to four years in prison for his participation in Conti, a ransomware group that attacked more than 1,000 organizations globally before it disbanded in 2022. Lytvynenko pleaded guilty in June 2026. \u00abLytvynenko joined that conspiracy as both an intruder and a developer \u2014 personally harming at least 12 companies, storing stolen data from victims, and helping build the malicious tools Conti used to extort and threaten communities,\u00bb the U.S. Justice Department said. \u00abEven after the Conti conspiracy ended, he continued engaging in active ransomware operations until his arrest.\u00bb<\/li>\n<li><strong>PaperCut Flaws Exploited in the Wild <\/strong>\u2014 watchTowr said it has observed recent PaperCut NG\/MF vulnerabilities (CVE-2026-81578 and CVE-2026-82078) being exploited for benign fingerprinting, to mass scanning, to full exploitation, and eventually to a human operator reading files through a web shell. \u00abAfter gaining code execution in one particular case, a threat actor dropped in-memory implants, including Godzilla C2 web shells and &#8216;suo5&#8217; HTTP proxy tunnels,\u00bb the company <a href=\"https:\/\/watchtowr.com\/resources\/papercut-ng-mf-zero-day-cve-2026-81578-cve-2026-82078-active-exploitation-underway\/\" target=\"_blank\">said<\/a>. \u00abBoth were deployed as servlet filters, designed to intercept inbound HTTP requests and operate entirely out of memory with nothing written to disk, persisting until the PaperCut service is restarted. Eighteen seconds after the second wave was deployed on our PaperCut instance, a new and separate IP address began interacting with the deployed Godzilla web shell, using the correct AES key and password.\u00bb<\/li>\n<li><strong>FireClient\u202fAttack Chain Evolves <\/strong>\u2014 BlueVoyant\u202fsaid it identified a new deployment method for the\u202fFireClient backdoor during its investigations into Microsoft Teams-based social engineering campaigns. \u00abWhile\u202fFireClient&#8217;s\u202fpost-compromise capabilities\u202fremain\u202flargely unchanged [&#8230;], the threat actor has significantly evolved the malware&#8217;s installation routine by replacing the Firefox profile abuse technique with an MSI-based delivery mechanism that\u202fleverages\u202fportable applications and DLL sideloading,\u00bb security researcher Thomas Elkins <a href=\"https:\/\/www.bluevoyant.com\/blog\/fireclient-msi-dll-sideloading-teams-attacks\" target=\"_blank\">said<\/a>. \u00abThe updated infection chain delivers\u202fFireClient\u202fthrough Windows Installer (MSI) packages\u202fcontaining\u202fa portable version of Kodi, which sideloads a\u202ftrojanized\u202fzlib.dll\u202fto execute the\u202fFireClient\u202floader. Following initial compromise, the loader\u202festablishes\u202fcommunication with command-and-control (C2) infrastructure hosted behind AWS API Gateway REST API endpoints before deploying the\u202fFireClient\u202fbackdoor. Threat actors later deploy environment-specific\u202fFireClient\u202floader variants masquerading as VMware Tools and NCPA. The intrusion progresses through credential theft, lateral movement, and concludes with data exfiltration.\u00bb<\/li>\n<li><strong>Abuse of Direct Send <\/strong>\u2014 Threat actors are continuing to abuse Microsoft 365 Direct Send in phishing campaigns. \u00abIt was designed for a practical, unglamorous purpose: letting office printers, scanners and legacy on-premises applications send email without needing a dedicated account and also bypassing security gateways,\u00bb KnowBe4 Threat Lab <a href=\"https:\/\/blog.knowbe4.com\/direct-send-how-attackers-weaponize-your-infrastructure-against-you\" target=\"_blank\">said<\/a>. \u00abAttackers have found that this path works just as well for them. By connecting to that same open endpoint, they can send an email claiming to be from anyone at your organization&#8217;s HR, accounting, admin or your CEO. The email arrives looking like it came from an internal address, because technically, it entered through your own infrastructure.\u00bb KnowBe4 said it found 29,785 confirmed Direct Send spoofs across July and August 2026. Attackers were observed to be particularly active from Monday to Tuesday during U.S. Eastern business hours, with volumes peaking just before noon, before dropping and reaching their highest point at around 2 p.m. EST.<\/li>\n<li><strong>Google Adds Option to Switch Between Password Managers on Android <\/strong>\u2014 Google introduced a new password manager switching experience on Android that doesn&#8217;t require users to download CSV files when migrating to a new app. \u00abHistorically, moving your passwords meant downloading them into an unencrypted text file, which left them unprotected on your device,\u00bb Google <a href=\"https:\/\/blog.google\/products-and-platforms\/platforms\/android\/switch-password-managers\/\" target=\"_blank\">said<\/a>. \u00abAnd passkeys couldn&#8217;t be transferred at all, so you&#8217;d have to recreate them across multiple sites and apps. Now, moving your passwords and passkeys to a new password manager is simpler and safer.\u00bb The new transfer experience is currently available on Google Password Manager, 1Password, Bitwarden Password Manager, and Dashlane, with more to follow.<\/li>\n<li><strong>IDScan Confirms Breach <\/strong>\u2014 Identity verification firm IDScan confirmed unknown threat actors obtained customer data held in its cloud platform following an investigation that connected the Louisiana-based company to a database breach that exposed scans of 153 million driver&#8217;s licenses. \u00abIDScan.net has determined that an unauthorized third party may have accessed and\/or copied certain customer information stored within their accounts on the IDScan.net cloud,\u00bb IDScan <a href=\"https:\/\/idscan.net\/notification-data-security-incident\/?7194ef805fa2d04b0f7e8c9521f97343\" target=\"_blank\">said<\/a>. \u00abThe types of information contained within the affected data may include full names and driver\u2019s license or other government-issued identification numbers.\u00bb The leak was exposed after an illicit service called Nexus was advertising access to more than 153 million driver\u2019s license scans belonging to Canadian and U.S. citizens. The service has since gone offline.<\/li>\n<\/ul>\n<h2 style=\"text-align: left;\"><strong>Conclusion<\/strong><\/h2>\n<p>That\u2019s the week. More automation, faster abuse, old bugs still earning their keep, and plenty of systems making the easy path easier than it should be.<\/p>\n<p>Most of this still comes back to basic things: patch sooner, lock down what does not need to be open, and assume someone will test the shortcut. The tools are changing. The weak spots are not.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 14, 2026Cybersecurity \/ Hacking AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job.&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2827,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[335,24,691,3209,699,1041,3345,821],"class_list":["post-2826","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-agents","tag-attacks","tag-espionage","tag-papercut","tag-rogue","tag-rootkits","tag-wechat","tag-worm"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2826","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2826"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2826\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2827"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2826"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2826"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2826"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}