{"id":2961,"date":"2026-09-18T05:25:27","date_gmt":"2026-09-18T05:25:27","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2961"},"modified":"2026-09-18T05:25:27","modified_gmt":"2026-09-18T05:25:27","slug":"self-rewriting-agents-800-flaws-patched-insider-sim-swaps-and-22-more-new-stories","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2961","title":{"rendered":"Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 17, 2026<\/span><\/span><span class=\"p-tags\">Hacking News \/ Cybersecurity News<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEizRobrCcZcWNzLjEmyk91HaJj5g2vkMbOgX_lP1vNQqfvh8krm4975WJ5zi9VFY1FsF44ZTJ5znBY5sBuKYiN-riJQspK3iLLnvhW5crViG9fJMPF_SCEN3dKPk-ypSjFQfD_gN1zA-KbryzexASNOVcKRHf4hf3iZ1XBuvYG9WKWhBdVWbs1dzJS9BUIQ\/s1700-nu-rw-lo-l85-e365\/threatsday-main.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them.<\/p>\n<p>This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough.<\/p>\n<p>So the threat landscape is not getting cleaner. It is just getting more places to make the same mistake. Here\u2019s what showed up this week.<\/p>\n<div class=\"article-board\">\n <b\/><\/p>\n<p>The threats change every week. <span data-push-label=\"ThreatsDay Bulletin\" data-push-topic=\"threatsday bulletin:t, recap:i\">Subscribe, and we\u2019ll alert you<\/span> when each new ThreatsDay Bulletin is out.<\/p>\n<\/div>\n<div class=\"td-wrap\">\n<section aria-labelledby=\"threatsday-title\" class=\"td-section\">\n<ol class=\"td-timeline\" role=\"list\">\n<a name=\"more\"\/><\/p>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Malware PPI operation exposed<\/span><\/p>\n<p class=\"td-desc\">\n      A threat actor known as CL-CRI-1171 has stayed under the radar for at least two years, offering a pay-per-install (PPI) marketplace that allows other threat actors to distribute their malware through YouTube channels and a parallel search engine optimization (SEO)-poisoning funnel. \u00abThese channels were actively interacting with viewers to promote gaming content laced with links to download malware,\u00bb Palo Alto Networks Unit 42 <a href=\"https:\/\/unit42.paloaltonetworks.com\/ppi-network-malware-campaign-analysis\/\" target=\"_blank\">said<\/a>. \u00abAlthough the videos provided real content for gamers, they also served as the delivery vehicle for infection, prompting viewers to download malicious tools. The SEO funnel targeted a more professional audience, promoting trojanized software that resulted in malware deployment on corporate endpoints, including critical infrastructure and even government entities.\u00bb Both these chains lead to a custom loader called OfferLoader that has delivered three payloads between July 2025 and April 2026: Docro Hijacker (a Chrome backdoor that can bypass <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2015\/05\/winyahoo-pup-modifies-chrome-secure-preferences\" target=\"_blank\">modern integrity protections<\/a>), ARKTunnel (a WebSocket tunneling RAT), and a new variant of a <a href=\"https:\/\/medium.com\/walmartglobaltech\/nodejs-backdoors-delivering-proxyware-and-monetization-schemes-1562917ed107\" target=\"_blank\">previously unnamed cross-platform backdoor<\/a> that&#8217;s been codenamed Insomnia remote access Trojan (RAT) and can target both Windows and macOS. Post-April 2026, the PPI infrastructure has led to GCleaner and Socks5Systemz.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Exposed LocalAI instances compromised<\/span><\/p>\n<p class=\"td-desc\">\n      A large-scale campaign has been found to target LocalAI instances exposed to the internet without authentication and achieve command execution inherent in MCP STDIO configuration. \u00abAttacker artifacts indicated that 230 of 243 unauthenticated LocalAI instances were assessed as exploitable,\u00bb Oasis Security <a href=\"https:\/\/hunt.io\/blog\/silkparasite-spicerat-central-asia-infrastructure\" target=\"_blank\">said<\/a>. \u00abCallback logs independently confirmed command execution with root privileges on 23 servers. Post-compromise activity included exfiltration from a workstation associated with the Thai military and collection of 127 AWS credential records.\u00bb The unknown threat actor is said to have selected high-value infrastructure from those LocalAI targets and compromised a desktop LocalAI workstation and a related private network. This was followed by exfiltration of sensitive data, including personal information, GPS coordinates, banking-application screenshots, and national ID card scans. Additional compromise activity consisted of exploitation of legacy infrastructure, authentication bypass, a broad sweep of cryptocurrency wallets and API keys, and theft of AWS ECS task credentials.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Agents rewrite their own models<\/span><\/p>\n<p class=\"td-desc\">\n      New research from Irregular has found that AI agents can retrain the model that powers them, in the process leaking secrets and eliminating refusals the model had been previously trained to enforce. \u00abGiven a routine software-maintenance task to fix incorrect application responses, the agent identified the shared model as the source of the problem, fine-tuned it, and replaced the model powering both the application and future instances of the agent itself,\u00bb Irregular <a href=\"https:\/\/www.irregular.com\/research\/agentic-self-modification-in-open-weights-systems\" target=\"_blank\">said<\/a>. \u00abIt did so without being instructed to train, modify the model, or deploy a replacement.\u00bb This phenomenon has been codenamed agentic self-modification. \u00abNothing in these experiments establishes malicious intent, self-preservation, or deception; the agents modified models because training appeared to help accomplish the assigned engineering task,\u00bb Irregular added. \u00abAgentic self-modification can arise during ordinary software maintenance when a coding agent has access to the model weights, training tools, and a deployment path to modify the model directly.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">AI agent linked to data breach<\/span><\/p>\n<p class=\"td-desc\">\n      The Spanish Data Protection Agency (AEPD) said it was notified of a data breach that was allegedly executed by an AI agent. \u00abThe attacker launched a scan for vulnerabilities in generic files and successfully logged in,\u00bb AEPD <a href=\"https:\/\/www.aepd.es\/prensa-y-comunicacion\/blog\/primera-notiviacion-brecha-datos-personales-causada-por-ataque-ejecutado-mediante-agente-ia\" target=\"_blank\">said<\/a>. \u00abOnce inside the system, the attacker began independently searching for vulnerabilities in the application; once found, this allowed the attacker to modify personal data and access invoices. What is relevant from a data protection perspective is that a third party appears to have used an AI agent as a tool to successfully chain together different phases of the attack.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Ransomware exploits VMware RCE<\/span><\/p>\n<p class=\"td-desc\">\n      The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search=CVE-2026-59310&amp;field_date_added_wrapper=all&amp;field_cve=&amp;sort_by=field_date_added&amp;items_per_page=20&amp;url=\" target=\"_blank\">warned<\/a> that ransomware gangs have now started exploiting a critical VMware vCenter vulnerability patched in July. The flaw, tracked as CVE-2026-59310, is a critical directory traversal vulnerability in the vCenter Syslog server that unauthenticated attackers can exploit to execute arbitrary code. In August 2026, German incident response company QUIRSO uncovered evidence that a China-nexus advanced persistent threat (APT) has been exploiting the flaw shortly after public disclosure.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Oracle patches 800-plus flaws<\/span><\/p>\n<p class=\"td-desc\">\n      Oracle has <a href=\"https:\/\/www.oracle.com\/security-alerts\/cspusep2026.html\" target=\"_blank\">announced<\/a> the release of new security patches as part of its September 2026 Critical Security Patch Update (CSPU). The patches address over 800 flaws. None of them have been flagged as actively exploited. \u00abIt&#8217;s hard not to sound like a broken record these days when talking about security updates,\u00bb Tyler Reguly, Fortra&#8217;s Associate Director of Security Research and Development, said. \u00abWe&#8217;re continually seeing large numbers of vulnerabilities and we&#8217;re all starting to feel a little burnt out. I&#8217;ve said it before and I say it again, there is a light at the end of this tunnel and the record numbers of patches for record numbers of vulnerabilities will not last. I&#8217;m confident of this. Do everything you can to avoid burning out and just work on surviving this onslaught. I think that <a href=\"https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-prioritizing-security-updates-based-risk\" target=\"_blank\">CISA BOD 26-04<\/a> did a great job of helping people to understand how to prioritize based on risk. I think that a 3-day turnaround is very tight when you need to also test your patches, but it helps lay out priorities that make a real difference \u2013 is it publicly exposed, is it on the Known Exploited Vulnerabilities list, can it be automated, and does it give complete control. When you can answer these questions, you can start to identify the risk that it plays. Are there other components you can include? Sure, but this is a great start if you don\u2019t really know what risk looks like for your organization. Once you know what risk looks like, you can start to prioritize your patches more appropriately.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Insider SIM swaps draw prison term<\/span><\/p>\n<p class=\"td-desc\">\n      Former Oregon-based AT&amp;T Store employee, Kenneth Carter, 44, has been <a href=\"https:\/\/www.justice.gov\/usao-cdca\/pr\/oregon-man-sentenced-16-months-federal-prison-abusing-his-role-mobile-phone-store-give\" target=\"_blank\">sentenced to 16 months<\/a> in prison for abusing his access to perform SIM swaps that helped criminals take over customers&#8217; bank accounts. Three victims suffered intended losses of nearly $600,0000, with Carter typically receiving $1,000 to $2,000 for each fraudulent SIM swap. Carter, who worked at the store from May 2018 to November 2019, has also been ordered to pay $99,528 in restitution. Carter pleaded guilty to the crimes earlier this March.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">AI drives malware evasion<\/span><\/p>\n<p class=\"td-desc\">\n      Google-owned Mandiant said it has observed advanced malware campaigns using embedded, lightweight AI models to facilitate stealthy, long-term persistence within victim networks. \u00abIn these environments, the malware does not rely on a static payload that might be flagged by traditional signature-based detection,\u00bb Google <a href=\"https:\/\/cloud.google.com\/security\/resources\/ai-risk-and-resilience-2026?linkId=63734760#case-studies-4-3\" target=\"_blank\">said<\/a>. \u00abInstead, it uses local AI inference to analyze the host environment and identify the specific security tools currently active on the endpoint. During the attack phase, the malware dynamically rewrites its own command execution strings at runtime to bypass detection. By constantly altering the syntax and logic of its automated actions, the payload successfully evades static endpoint detection and response (EDR) signatures.\u00bb The tech giant also warned that bad actors are using AI command-line interfaces (CLIs) to orchestrate and manage command-and-control (C2) infrastructure through natural-language queries and breaching cloud environments to \u00abinitialize an unisolated VM instance and transform it into a live, AI-assisted offensive hub\u00bb with an aim to debug and optimize offensive tools in real-time.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Cyclops Blink returns on Cisco FMC<\/span><\/p>\n<p class=\"td-desc\">\n      Sophos said it observed a variant of Cyclops Blink, a modular botnet and malware framework, on multiple compromised Cisco Firewall Management Center (FMC) devices in August 2026. \u00abUnlike the WatchGuard-focused samples documented in 2022, the 2026 variant runs on x86-64 Linux and uses generic System V (SysV) persistence rather than vendor-specific firmware modification,\u00bb Sophos <a href=\"https:\/\/www.sophos.com\/en-gb\/blog\/-eye-spy-cyclops-blink-returns-with-extended-capabilities\" target=\"_blank\">said<\/a>. \u00abThis change broadens the range of potentially compatible network-edge appliances. The implant&#8217;s expanded capabilities include active network and service discovery, programmable packet surveillance, file transfer, and payload execution, allowing a compromised device to serve as a platform for internal reconnaissance, intelligence collection, and follow-on operations. The malware supports five worker modules that perform host reconnaissance, file transfer and payload execution, active network discovery, selective packet capture and content surveillance, and persistence. Cisco has described the Cyclops Blink activity as one of three separate campaigns involving two vulnerabilities in its Secure FMC software: CVE-2026-20079 and CVE-2026-20316. The findings once again show how compromised network appliances and other edge devices can give attackers a privileged vantage point into enterprise environments and allow them to observe traffic, conduct network probes, and launch additional attacks.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">RF signals leak analog secrets<\/span><\/p>\n<p class=\"td-desc\">\n      A group of academics from the Hong Kong University of Science and Technology and the Hong Kong Polytechnic University has demonstrated InjectEave, a new class of electromagnetic side-channel attacks in which an external RF signal induces hardware nonlinearities that leak low-frequency analog secrets. \u00abThis vulnerability exists in ubiquitous nonlinear analog interfaces across the 11 commercial off-the-shelf devices we evaluated, allowing attackers to eavesdrop on headphone and landline audio, infer smart-fan speed and smart-lamp brightness, and recover other analog secrets that digital encryption and software defenses can hardly protect,\u00bb the researchers <a href=\"https:\/\/injecteave.github.io\/\" target=\"_blank\">said<\/a>. \u00abWe demonstrate eavesdropping on audio played through wired and wireless headphones from up to 30 m away, as well as in through-wall scenarios, and characterize injection-induced EM leakage of other low-frequency secrets.\u00bb Tests on 11 commercial devices, including headphones, VoIP phones, smart fans and lamps, showed that attackers could recover private audio or determine appliance states without physical access or modifying the devices. \u00abHardware-aware mitigations such as twisted-pair wiring, shielding, and filtering can lower the energy that the injected carrier couples into the device, reducing the exposure,\u00bb the researchers said. \u00abThese mitigations raise the bar, but they do not guarantee immunity.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Settra ransomware expands attacks<\/span><\/p>\n<p class=\"td-desc\">\n      A new ransomware group called Settra has deployed MeshAgent remote access software in two intrusions analyzed by Huntress. \u00abAlthough the initial access method could not be confirmed, both attacks used ransomware executables named after the victim organization&#8217;s domain and followed a highly similar operational pattern,\u00bb Huntress <a href=\"https:\/\/www.huntress.com\/blog\/new-settra-ransomware-variant\" target=\"_blank\">said<\/a>. \u00abIn the observed intrusions, attackers deployed remote monitoring and management (RMM) tools for persistence and then encrypted files, dropped RESTORE_FILES.txt ransom notes, cleared Windows event logs, and disabled Windows recovery options. One incident also included signs of Bring Your Own Vulnerable Driver (BYOVD); as well as a notable misspelling by the threat actors during the attack, which left them unable to clear the Windows Defender Event Log.\u00bb Settra emerged in June 2026 and has mainly targeted entities in the U.S., Germany, the U.K., Canada, and Australia spanning technology, professional services, manufacturing, and retail sectors, according to researcher <a href=\"https:\/\/theravenfile.com\/2026\/09\/14\/settra-ransomware\/\" target=\"_blank\">Rakesh Krishnan<\/a>. The group has claimed <a href=\"https:\/\/ransomware.live\/group\/settra\" target=\"_blank\">70 victims to date<\/a>. In <a href=\"https:\/\/www.cynet.com\/blog\/inside-cynets-settra-ransomware-investigation\/\" target=\"_blank\">another case<\/a> investigated by Cynet, \u00abthe ransomware engine was buried inside an encrypted blob and gated behind an operator-supplied password. Without the correct password, the executable simply terminated, leaving researchers and automated sandboxes with little to analyze.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Uncensored AI sold underground<\/span><\/p>\n<p class=\"td-desc\">\n      A threat actor named Optimus_Prime (aka OptimusPrimero) is advertising an uncensored AI subscription service named Luciferus on the Exploit underground forum as an alternative to jailbreaking mainstream providers like ChatGPT, Claude, or Gemini. \u00abThe August advertisement describes Luciferus as an AI system that answers requests without moral or ethical restrictions and claims that it is based on a proprietary model that has &#8216;120 billion parameters,'\u00bb Sophos <a href=\"https:\/\/www.sophos.com\/en-us\/blog\/uncensored-luciferus-ai-service-advertised-underground\" target=\"_blank\">said<\/a>, adding the tool is likely built on Alibaba&#8217;s Qwen family of AI models. The service costs $35 per month and claims to support three models on its website (\u00abluciferus[.]io\u00bb). \u00abThe emergence of Luciferus aligns with a broader trend in which threat actors are increasingly commercializing AI through underground forums, Telegram channels, and cybercriminal marketplaces,\u00bb Sophos said. \u00abRather than developing their own models, many threat actors are offering access to uncensored or modified LLMs via AI-as-a-service schemes in the same way malware, phishing kits, and ransomware are commoditized.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">VectraRAT MaaS hits the market<\/span><\/p>\n<p class=\"td-desc\">\n      SOCRadar has disclosed details of a new malware-as-a-service (MaaS) platform called VectraRAT that&#8217;s been built from scratch and is available for $250 a month. \u00abIt gives operators hidden-desktop control, keylogging, clipboard hijacking, browser credential theft, and a UAC bypass that elevates with no prompt,\u00bb SOCRadar <a href=\"https:\/\/socradar.io\/blog\/vectrarat-undocumented-stack-maas\/\" target=\"_blank\">said<\/a>. \u00abIt pairs a Go control server called VectraHub, with a Vue3 operator panel compiled into the binary, with a native C++ Windows implant. The two speak a proprietary binary TCP protocol using MessagePack over port 3308.\u00bb The operator \u00abVectra\u00bb is a rebrand of \u00abNyxel,\u00bb active since at least August 2022. The malware is delivered via Amadey and ClickFix lure pages.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Casbaneiro hits Latin America<\/span><\/p>\n<p class=\"td-desc\">\n      A Casbaneiro attack campaign was observed targeting users in Latin America in August 2026, using phishing emails and PDF files themed around fake invoices and legal notices as an initial access vector. \u00abCasbaneiro exhibits characteristics common to other malware families targeting financial institutions and users in Latin America, including clipboard injection and the use of fake windows to facilitate fraudulent activities,\u00bb Fortinet FortiGuard Labs <a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers\" target=\"_blank\">said<\/a>. \u00abIn this attack campaign, the malware is delivered via a multi-stage infection chain that includes an HTA downloader and an AutoIt loader, with the latter responsible for injecting the final payload into a Windows process.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">KATARU brute-forces Telnet access<\/span><\/p>\n<p class=\"td-desc\">\n      An IoT malware dubbed KATARU has leveraged Telnet credential brute-forcing to break into Linux and embedded systems. \u00abWhile it retains familiar Mirai-style botnet functionality, it stands out for its unusually broad capability set, including multiple Linux n-day local privilege escalation exploits, extensive persistence coverage across Linux and embedded environments, encrypted C2 communications, anti-analysis checks, and decoy traffic,\u00bb Nozomi Networks <a href=\"https:\/\/www.nozominetworks.com\/blog\/kataru-iot-malware-adopts-public-lpe-exploits\" target=\"_blank\">said<\/a>. The end goal is to establish communications with a C2 server and receive DDoS attack commands. It&#8217;s suspected that KATARU was assembled with AI assistance.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">AI boosts LATAM intrusions<\/span><\/p>\n<p class=\"td-desc\">\n      Palo Alto Networks Unit 42 said it detected two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations in Latin America that leverage AI to enhance the threat actor&#8217;s capabilities: CL-CRI-1131, which has used living-off-the-land (LotL) techniques and executed iterative batch scripts to troubleshoot issues and exfiltrate sensitive data, and CL-CRI-1163, which has used resume-themed phishing emails to deploy custom RATs and tunneling tools, including a Go-based SOCKS5 proxy. CL-CRI-1131 impacted a transportation organization, alongside federal government ministries and municipal water utilities in Mexico and Ecuador, while CL-CRI-1163 has singled out the Brazilian financial sector. \u00abThe threat actors behind the CL-CRI-1131 and CL-CRI-1163 campaigns have enhanced their technical capabilities by incorporating commercial LLMs into their workflows,\u00bb Unit 42 <a href=\"https:\/\/unit42.paloaltonetworks.com\/ai-tool-use-targeting-latam-orgs\/\" target=\"_blank\">said<\/a>. \u00abThis integration enables them to author advanced proxy configurations and dynamically address complex execution failures. However, the infrastructure they deployed to leverage this AI became their Achilles&#8217; heel.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Azalea RAT enables full control<\/span><\/p>\n<p class=\"td-desc\">\n      A MaaS offering called Azalea RAT has been promoted as a modular malware platform with a wide range of post-compromise capabilities. \u00abAzalea RAT combines remote administration, stealth mechanisms, privilege escalation, persistence, information theft, and an extensible plugin architecture,\u00bb Rubrik Zero Labs <a href=\"https:\/\/zerolabs.rubrik.com\/blog\/azalea-rat-stealthy-loader-full-system-control#second-stage-loader\" target=\"_blank\">said<\/a>. \u00abOnce executed, the RAT allows an operator to manage the infected host, execute commands and additional payloads, collect sensitive information, manipulate system resources, and maintain remote access through an extensive command-and-control framework.\u00bb The .NET RAT is designed for persistent and interactive control over compromised Windows systems. Azalea RAT arrives in the form of a Windows shortcut that masquerades as a PDF document to trigger the execution of a first-stage loader, which then performs anti-analysis checks before extracting a DLL that&#8217;s responsible for setting up Microsoft Defender exclusion paths and ultimately launching the RAT.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Infostealers target AI agent data<\/span><\/p>\n<p class=\"td-desc\">\n      Infostealers like Amatera and Remus are expanding their data collection focus beyond browser passwords and cryptocurrency wallets to collect access tokens, MCP configurations, prompt histories, and project data stored by AI tools. \u00abAmatera targets data associated with Cline and Continue, while Remus targets Claude, Cursor, and OpenCode,\u00bb Gen Digital <a href=\"https:\/\/www.gendigital.com\/blog\/insights\/research\/infostealers-your-ai-agent\" target=\"_blank\">said<\/a>. \u00abThe figures may overlap and describe detections rather than successful infections, but they show that AI agent data has already entered the information-stealer economy. What the malware is collecting goes far beyond harmless preferences. Depending on the agent and its configuration, local files may contain access and refresh tokens, credentials stored in MCP configurations, prompt histories, conversation databases, account details, and traces of the projects a developer has been working on. In one archive, an attacker may obtain both the means to access an account and the context needed to understand what is valuable behind it.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Three Russians extradited over cybercrime cases<\/span><\/p>\n<p class=\"td-desc\">\n      The Moscow Times has <a href=\"https:\/\/www.themoscowtimes.com\/2026\/09\/10\/us-extradites-3-russians-accused-of-cybercrime-since-june-a93681\" target=\"_blank\">reported<\/a> that U.S. authorities have extradited three Russian nationals since June to face charges in separate cybercrime cases involving malware attacks, bank fraud, and the hacking of government and private-sector organizations. One involves <a href=\"https:\/\/www.justice.gov\/usao-ndca\/pr\/russian-national-indicted-exploiting-online-platform-used-freelance-employment-and\" target=\"_blank\">Searzhudin Aktulayev<\/a>, 40, who was arrested in Cyprus in May 2025 and extradited to the U.S. on August 28, 2026. The two other cases relate to Russian web developer Sergei Filimonov and Denis Obrezko, who was arrested in Thailand in November 2025 and was <a href=\"https:\/\/www.reuters.com\/legal\/government\/us-charges-suspected-russian-hacker-with-facilitating-cyber-campaign-2026-06-10\/\" target=\"_blank\">extradited<\/a> to the U.S. in June in connection with a large-scale cyber espionage campaign being carried out by a group known as \u200bVoid Blizzard.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">ClickFix chain delivers SloppyRAT<\/span><\/p>\n<p class=\"td-desc\">\n      A new malware called SloppyRAT, likely leveraged by a ransomware-related threat actor, is being delivered through a multi-stage ClickFix infection chain to establish a foothold for lateral movement. It was identified by Zscaler ThreatLabz in June 2026. \u00abThe malware supports a variety of features including a large number of built-in PowerShell-like commands, encrypted code blocks, EtherHiding for command-and-control (C2) resolution through the Polygon JSON-RPC protocol, and multiple anti-analysis techniques,\u00bb ThreatLabz <a href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/sloppyrat-new-tool-ransomware-attacks\" target=\"_blank\">said<\/a>. \u00abSloppyRAT uses certificate pinning to prevent networking monitoring solutions from using man-in-the-middle (MitM) attacks to inspect TLS traffic. Beyond SloppyRAT&#8217;s capabilities, the malware is notable because the codebase includes numerous software flaws, which suggest that it is still under development.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Five-stage chain drops AsyncRAT<\/span><\/p>\n<p class=\"td-desc\">\n      A five-stage infection chain has been observed using a socially engineered batch file to deliver AsyncRAT. While the exact initial access vector is unknown, threat actors are known to rely on phishing emails, malicious links, trojanized software, and instant messaging platforms to distribute malware. \u00abThe batch file launches PowerShell with a hidden window and a disabled profile, then reassembles a Base64 payload from ten fragments, strips deliberately inserted junk characters, and decodes it through repeating key XOR,\u00bb Point Wild <a href=\"https:\/\/www.pointwild.com\/threat-intelligence\/asyncrat-delivered-via-autoit-full-chain-analysis\/\" target=\"_blank\">said<\/a>. \u00abIt drops three files into an obfuscated build-specific folder under %LOCALAPPDATA%\\Temp: a renamed but legitimate signed AutoIT interpreter, an AutoIT loader script (kojuyn.ini), and an extensionless encrypted payload. The batch file written to the Startup folder relaunches the pair at every logon, with no registry key.\u00bb The AutoIT script is designed to decrypt the payload in memory and inject it into a Microsoft-signed Windows process. The payload then triggers a three-step process to launch the final AsyncRAT malware.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Black Axe leaders extradited<\/span><\/p>\n<p class=\"td-desc\">\n      Five alleged Nigeria-based leaders of the Black Axe cybercrime syndicate (Perry Osagiede, Franklyn Edosa Osagiede, Osariemen Eric Clement, Collins Owhofasa Otughwor, and Musa Mudashiru), known for their involvement in global-scale cyber-enabled financial fraud, have been extradited from South Africa to the U.S. to face wire fraud and money laundering charges. Perry Osagiede, Franklyn Osagiede, and Clement are also charged with wire fraud, and Perry Osagiede, Franklyn Osagiede, and Otughwor are also charged with aggravated identity theft. \u00abFrom at least 2011 through 2021, the Black Axe defendants and other conspirators worked together from Cape Town to engage in widespread internet fraud involving romance scams and advance fee schemes,\u00bb the U.S. Justice Department <a href=\"https:\/\/www.justice.gov\/usao-nj\/pr\/five-prominent-black-axe-members-extradited-conspiring-engage-internet-scams-and-money\" target=\"_blank\">said<\/a>. \u00abMany of these fraudulent narratives involved claims that an individual was traveling to South Africa for work and needed money or other items of value following a series of unfortunate and unforeseen events, often involving a construction site or problems with a crane. The conspirators used social media websites, online dating websites, and voice over internet protocol phone numbers to find and talk with victims in the United States, while using a number of aliases. The conspirators\u2019 romance scam victims believed they were in romantic relationships with the person using the alias and, when requested, the victims sent money and items of value overseas, including to South Africa. Sometimes, when victims expressed hesitation in sending money, the conspirators used manipulative tactics to coerce the payments, including by threatening to distribute personally sensitive photographs of the victim.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">ATM jackpotting plot ends in guilty pleas<\/span><\/p>\n<p class=\"td-desc\">\n      Five Venezuelan nationals have pleaded guilty to attempting to steal U.S. currency from ATMs. Luis Alberto Velasquez-Artigas, 27, Royder Adrian Figuera-Perez, 29, Javier Mejia, Jr, 27, Gabriel Alexjandro Corales-Garcia, 33, and Italo Lizandro Corrales-Carrillo, 26, all pleaded guilty to one count of conspiracy to commit bank larceny. \u00abIn December 2025, the defendants traveled from Indiana to Kansas to attempt to steal cash from ATMs in Wamego and Manhattan through jackpotting,\u00bb the Justice Department <a href=\"https:\/\/www.justice.gov\/usao-ks\/pr\/fbi-investigation-leads-five-venezuelan-nationals-plead-guilty-attempting-jackpot-kansas\" target=\"_blank\">said<\/a>. \u00abTheir plan was for one conspirator to physically install the malware into the ATMs, then later for the group to remotely activate a command causing the ATMs to dispense cash that they would go collect. The conspirators were unsuccessful in installing the malware on the ATM in Wamego, but their attempts at installing the malware triggered the alarm, causing law enforcement to respond, and the culprits didn\u2019t return to the site. In Manhattan, the group was equally unsuccessful in getting the ATM to dispense money. Both attempted thefts were captured by surveillance cameras, and the perpetrators were arrested a few days later.\u00bb According to the U.S. Federal Bureau of Investigation, 1,900 incidents have been recorded since 2020. In 2025 alone, there were more than 700 incidents with more than $20 million in losses.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Eight-year sentence for ATM jackpotting<\/span><\/p>\n<p class=\"td-desc\">\n      In more ATM jackpotting action, another 27-year-old from Venezuela, Juan Manuel Gouveia-Aguilera, has been sentenced to eight years in prison for his role in a conspiracy to deploy Ploutus malware and steal millions of dollars from ATMs in the U.S. Gouveia-Aguilera has also been ordered to pay restitution as part of his sentence. \u00abThe Court found Gouveia-Aguilera to be responsible for more than $3.5 million in losses and this sentence is believed to be the longest federal sentence imposed for an individual\u2019s role in ATM jackpotting,\u00bb the Justice Department <a href=\"https:\/\/www.justice.gov\/usao-ne\/pr\/venezuelan-man-sentenced-8-years-prison-atm-jackpotting\" target=\"_blank\">said<\/a>. \u00abSpecifically, Gouveia-Aguilera was convicted of conspiracy to commit bank fraud, conspiracy to commit bank burglary and fraud in connection with computers, bank fraud, bank burglary, and fraud in connection with computers following a guilty plea.\u00bb In recent years, cyber criminals have used <a href=\"https:\/\/securelist.com\/atmii-a-small-but-effective-atm-robber\/82707\/\" target=\"_blank\">ATMii<\/a>, <a href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/2017_double-attack-what-are-fileless-banking-attackers-really-after\" target=\"_blank\">ATMitch<\/a>,<a href=\"https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/Meet-GreenDispenser\" target=\"_blank\"> GreenDispenser<\/a>, <a href=\"https:\/\/www.tripwire.com\/state-of-security\/lean-mean-alice-malware-designed-solely-empty-safe-atms\" target=\"_blank\">Alice<\/a>, <a href=\"https:\/\/web.archive.org\/web\/20220519012616\/https:\/\/www.fireeye.com\/blog\/threat-research\/2016\/08\/ripper_atm_malwarea.html\" target=\"_blank\">RIPPER<\/a>,<a href=\"https:\/\/securelist.com\/atm-infector\/74772\/\" target=\"_blank\"> Skimer<\/a>, <a href=\"https:\/\/web.archive.org\/web\/20220705154006\/https:\/\/www.fireeye.com\/blog\/threat-research\/2015\/09\/suceful_next_genera.html\" target=\"_blank\">SUCEFUL<\/a>, and Ploutus malware to steal cash in ATM jackpotting attacks.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Nearly $13B tied to suspected crypto scams<\/span><\/p>\n<p class=\"td-desc\">\n      The U.S. Department of the Treasury&#8217;s Financial Crimes Enforcement Network (FinCEN) said it analyzed 33,904 Bank Secrecy Act (<a href=\"https:\/\/www.fincen.gov\/resources\/bank-secrecy-act-filing-information\/what-bsa-data\" target=\"_blank\">BSA<\/a>) reports involving suspected digital asset investment scam-related activity filed between September 8, 2023, and December 31, 2025, totaling about $12.7 billion in financial activity tied to suspected digital asset investment scams perpetrated by overseas scam centers. \u00abActors often used assumed names or identities to pose as potential romantic partners, new friends, or new business partners to target scam victims,\u00bb FinCEN <a href=\"https:\/\/www.fincen.gov\/news\/news-releases\/fincen-identifies-nearly-13-billion-linked-suspected-digital-asset-scams\" target=\"_blank\">said<\/a>. \u00abScammers often created websites and mobile applications that imitated legitimate investment services to carry out their criminal activity,\u00bb FinCEN said scam center operators are using guarantee marketplaces to purchase illicit services, such as online account creation, phishing, and money laundering services.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<\/ol>\n<\/section>\n<\/div>\n<p>The lesson this week is not that attackers suddenly got smarter. It is that useful things keep becoming attack surfaces faster than teams learn to treat them that way.<\/p>\n<p>So check what is exposed. Check what holds tokens, prompts, configs, and keys. Kill weak defaults. Patch the boring old stuff too. New tech does not cancel old mistakes; it just gives them more places to hide.<\/p>\n<p>That is the useful part of weeks like this. Not panic. Better instincts. Fewer easy wins left on the table.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 17, 2026Hacking News \/ Cybersecurity News Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2962,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[335,11,3448,1707,3447,1383,187,3449],"class_list":["post-2961","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-agents","tag-flaws","tag-insider","tag-patched","tag-selfrewriting","tag-sim","tag-stories","tag-swaps"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2961","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2961"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2961\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2962"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2961"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2961"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2961"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}