{"id":3018,"date":"2026-09-21T15:30:53","date_gmt":"2026-09-21T15:30:53","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3018"},"modified":"2026-09-21T15:30:53","modified_gmt":"2026-09-21T15:30:53","slug":"cisco-0-day-ai-agent-rce-clickfix-attacks-clickfix-surge-and-browser-hijacks","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3018","title":{"rendered":"Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjovXeakmAmPG68i_kNoeGFJjwSSGDdpj-29aojemBxtTQVOHzR668zKtV5GGPhnJ0zyCEdlsNCc11LIT-F8n1U8Rkv3jr-3AAt6HC4YwwyfENs_Y8V-O_OlPC4_WByxrsUBq6NifTKHQpgWuSnIqnV4bg4rXVoe9BrtMtgRCo4ECfMLWHRIKOQsqjb0zEt\/s1700-nu-rw-lo-l85-e365\/recap-2.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week.<\/p>\n<p>The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not always more clarity.<\/p>\n<p>Nothing here needs much drama. Just a lot of small doors left open. Here\u2019s what happened.<\/p>\n<h2 style=\"text-align: left;\"><strong>\u26a1 Threat of the Week<\/strong><\/h2>\n<p><strong>Cisco Warns of Actively Exploited ISE Auth Bypass <\/strong>\u2014 Cisco warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. \u00abThis vulnerability is due to insufficient authentication control on an API endpoint,\u00bb Cisco said. \u00abAn attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.\u00bb<\/p>\n<h2 style=\"text-align: left;\"><strong>\ud83d\udd14 Top News<\/strong><\/h2>\n<ul>\n<li><strong><a href=\"https:\/\/thehackernews.com\/2026\/09\/us-seizes-nightmarestresser-domains.html\" target=\"_blank\">U.S. Seizes NightmareStresser Domains Linked to DDoS Attacks <\/strong>\u2014 A U.S. court-authorized operation seized two domains associated with NightmareStresser, which offered a distributed denial-of-service (DDoS)-for-hire service. NightmareStresser is assessed to have been used to launch hundreds of thousands of actual or attempted DDoS attacks against victims across the world since 2022. These attacks have targeted educational institutions, government agencies, gaming platforms, and millions of people, the U.S. Justice Department said.<\/li>\n<li><strong>Using Claude to Hack OpenAI <\/strong>\u2014 Hacktron said it used Anthropic&#8217;s Claude Opus 5 to chain two critical vulnerabilities \u2013 an SSO misconfiguration in OpenAI&#8217;s identity infrastructure and a libheif RCE in the <a href=\"https:\/\/community.openai.com\/\" target=\"_blank\">Discourse community forum<\/a> (<a href=\"https:\/\/github.com\/discourse\/discourse\/security\/advisories\/GHSA-vhm9-85gw-x335\" target=\"_blank\">CVE-2026-32882<\/a>) \u2013 to gain unauthorized access to OpenAI employees&#8217; ChatGPT accounts and then use them to access internal OpenAI repositories. The issue was fixed 14 hours after responsible disclosure. Upstream, the flaw was fixed in<a href=\"https:\/\/github.com\/strukturag\/libheif\/releases\/tag\/v1.22.0\" target=\"_blank\"> libheif 1.22.0<\/a> in May 2026.<\/li>\n<li><strong>Plugin4Shell for 0-Click RCE in AI Coding Agents <\/strong>\u2014 AIR Security demonstrated a flaw called Plugin4Shell, a zero-click remote code execution (RCE) vulnerability that bypasses SHA-pinning verification in four major AI coding agents: Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. \u00abIn this first-of-its-kind AI supply-chain attack, a trusted plugin is silently swapped for a malicious one and auto-installed past the agent&#8217;s SHA pinning &#8212; a flaw no marketplace can fix, so users must update their agent,\u00bb AIR Security said. \u00abIt is a plugin SHA-pinning bypass: the agent checks out the exact commit the marketplace pinned but never verifies it landed there, so an attacker who controls the plugin&#8217;s repo makes the checkout resolve to malicious code while the pin still looks honored. The result is zero-click remote code execution across Claude Code, Codex, GitHub Copilot, and Gemini CLI.\u00bb<\/li>\n<li><strong>OpenAI Reveals New Misalignment Incidents <\/strong>\u2014 OpenAI disclosed six new instances of \u00abunexpected or concerning model behavior\u00bb that took place over the past six months, while sharing a new framework for reporting, tracking, investigating, and disclosing model misalignment in a bid to improve transparency. \u00abAs AI systems grow more advanced and more widely deployed, we need to build a broader and better-informed consensus on the progress of alignment research,\u00bb OpenAI said. \u00abWe do not believe that the AI industry has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer.\u00bb<\/li>\n<li><strong>KREMLIN Banking Malware Hijacks Chrome and Edge for Credential Theft <\/strong>\u2014 A previously undocumented Brazilian banking malware operation has been found to deliver a toolkit called KREMLIN. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and Microsoft Edge. \u00abThe KREMLIN malware ecosystem employs multi-stage JavaScript loaders, custom C++ installers, and malicious browser extensions to steal credentials, session tokens, and sensitive data,\u00bb Elastic said. The activity is being tracked as REF9334.<\/li>\n<\/ul>\n<h2 style=\"text-align: left;\"><strong>\u200e\ufe0f\u200d\ud83d\udd25 Trending CVEs<\/strong><\/h2>\n<p>Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.<\/p>\n<p>Check the list, patch what you have, and hit the ones marked urgent first \u2014 <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-58138\" target=\"_blank\">CVE-2026-58138<\/a> (Orkes Conductor), <a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/pixel\/2026\/2026-09-01\" target=\"_blank\">CVE-2026-58704<\/a> (Google Pixel), <a href=\"https:\/\/jfrog.com\/blog\/parallels-desktop-turns-appliance-install-into-root-shell\/\" target=\"_blank\">CVE-2026-90894<\/a> aka ParaShells (Parallels Desktop), <a href=\"https:\/\/www.nintendo.com\/security-advisories\/assets\/pdf\/20260910e.pdf\" target=\"_blank\">CVE-2026-82079<\/a> (Nintendo Switch), <a href=\"https:\/\/github.com\/aws\/amazon-ssm-agent\/security\/advisories\/GHSA-w9jw-h72g-6hxc\" target=\"_blank\">CVE-2026-89049<\/a> (AWS Systems Manager Agent), <a href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2026\/09\/08\/1\" target=\"_blank\">CVE-2026-43502<\/a> aka ZcopyReaper, <a href=\"https:\/\/heyitsas.im\/posts\/lpe-quartet\/\" target=\"_blank\">CVE-2026-80844<\/a> aka DirtyAH6, <a href=\"https:\/\/heyitsas.im\/posts\/lpe-quartet\/\" target=\"_blank\">CVE-2026-81000<\/a> aka TUNderflow, <a href=\"https:\/\/heyitsas.im\/posts\/lpe-quartet\/\" target=\"_blank\">CVE-2026-68121<\/a> aka PPPoEject, <a href=\"https:\/\/heyitsas.im\/posts\/lpe-quartet\/\" target=\"_blank\">CVE-2026-74469<\/a> aka DiagSpill (Linux kernel), <a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-in\/000505935\/dsa-2026-393-security-update-for-dell-objectscale-multiple-vulnerabilities\" target=\"_blank\">CVE-2026-70416, CVE-2025-43936<\/a> (Dell ObjectScale and Elastic Cloud Storage), <a href=\"https:\/\/support.plesk.com\/hc\/en-us\/articles\/43248932867351-Vulnerability-in-Plesk-s-Backup-Manager-symlink-race-during-restore-allows-root-privilege-escalation\" target=\"_blank\">CVE-2026-68488<\/a> (Please Backup Manager), <a href=\"https:\/\/www.vulncheck.com\/advisories\/vlc-media-player-3.0.0-through-3.0.23-heap-out-of-bounds-read-via-unterminated-realrtsp-response-line\" target=\"_blank\">CVE-2026-56711, CVE-2026-73324<\/a> (VLC Media Player), <a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/43387915588375-Security-CVE-2026-65638-CSF-Security-Release\" target=\"_blank\">CVE-2026-65638<\/a> (cPanel ConfigServer Security &amp; Firewall), <a href=\"https:\/\/trust.okta.com\/security-advisories\/stored-cross-site-scripting-xss-in-auth0-ad-ldap-connector-cve-2026-85982\/\" target=\"_blank\">CVE-2026-85982<\/a>, <a href=\"https:\/\/trust.okta.com\/security-advisories\/improper-input-sanitization-in-okta-access-gateway-protected-rules-cve-2026-78626\/\" target=\"_blank\">CVE-2026-78626<\/a>, <a href=\"https:\/\/trust.okta.com\/security-advisories\/improper-handling-of-saml-assertion-attributes-in-okta-access-gateway-advanced-mode-datastores-cve-2026-78623\/\" target=\"_blank\">CVE-2026-78623<\/a> (Okta), <a href=\"https:\/\/security.paloaltonetworks.com\/CVE-2026-0310\" target=\"_blank\">CVE-2026-0310<\/a> (Palo Alto Networks PAN-OS), <a href=\"https:\/\/github.com\/maplibre\/maplibre-gl-js\/security\/advisories\/GHSA-jrc7-96c5-q579\" target=\"_blank\">CVE-2026-85061<\/a> (MapLibre GL JS), <a href=\"https:\/\/github.com\/arangodb\/arangodb\/security\/advisories\/GHSA-rvhw-4hpw-9vrx\" target=\"_blank\">GHSA-rvhw-4hpw-9vrx<\/a>, <a href=\"https:\/\/github.com\/arangodb\/arangodb\/security\/advisories\/GHSA-rrgq-978q-36mq\" target=\"_blank\">GHSA-rrgq-978q-36mq<\/a>, <a href=\"https:\/\/github.com\/arangodb\/arangodb\/security\/advisories\/GHSA-4xhx-8cv5-wh62\" target=\"_blank\">GHSA-4xhx-8cv5-wh62<\/a>, <a href=\"https:\/\/github.com\/arangodb\/arangodb\/security\/advisories\/GHSA-8v35-895w-232p\" target=\"_blank\">GHSA-8v35-895w-232p<\/a> (ArangoDB), <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-65812\" target=\"_blank\">CVE-2026-65812<\/a> (Microsoft Teams for Android), <a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-in\/000503426\/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities\" target=\"_blank\">CVE-2026-80172, CVE-2026-61410, CVE-2026-80238<\/a> (Dell Secure Connect), <a href=\"https:\/\/forums.ivanti.com\/s\/article\/Security-Advisory---Ivanti-Endpoint-Manager-Mobile-CVE-2026-18851\" target=\"_blank\">CVE-2026-18851<\/a> (Ivanti Endpoint Manager Mobile), <a href=\"https:\/\/chromereleases.googleblog.com\/2026\/09\/stable-channel-update-for-desktop_0541751186.html\" target=\"_blank\">CVE-2026-91721, CVE-2026-91749, CVE-2026-91726<\/a>, <a href=\"https:\/\/chromereleases.googleblog.com\/2026\/09\/stable-channel-update-for-desktop_0194356994.html\" target=\"_blank\">CVE-2026-93374, CVE-2026-93372<\/a> (Google Chrome), <a href=\"https:\/\/www.mozilla.org\/en-US\/security\/advisories\/mfsa2026-90\/\" target=\"_blank\">CVE-2026-92033, from CVE-2026-92005 to CVE-2026-92013, from CVE-2026-92015 to CVE-2026-92020, from CVE-2026-92022 to CVE-2026-92029, from CVE-2026-92034 to CVE-2026-92038<\/a> (Mozilla Firefox), <a href=\"https:\/\/www.opswat.com\/blog\/authentication-bypass-and-dos-vulnerabilities-opswat-discovers-cve-2026-15315-cve-2026-15316-in-tp-link-tapo-cameras\" target=\"_blank\">CVE-2026-15315, CVE-2026-15316<\/a> (TP-Link Tapo cameras), <a href=\"https:\/\/lists.apache.org\/thread\/v5zrdqcn0w0v4pk1d22ndt7frcrplo2b\" target=\"_blank\">CVE-2026-82232<\/a>, <a href=\"https:\/\/lists.apache.org\/thread\/qr464o2lyj3rxp8b0q25ssn0qwjxyrgz\" target=\"_blank\">CVE-2026-77147<\/a>, <a href=\"https:\/\/lists.apache.org\/thread\/owcdm0stb39mnkpyps0h6yw4gp2olnkj\" target=\"_blank\">CVE-2026-73178<\/a> (Apache Syncope), <a href=\"https:\/\/support.hpe.com\/hpesc\/public\/docDisplay?docId=hpesbnw05135en_us&amp;docLocale=en_US\" target=\"_blank\">CVE-2026-76669, CVE-2026-76670, CVE-2026-76672, CVE-2026-76673, CVE-2026-76674<\/a> (HPE Networking EdgeConnect SD-WAN Gateways and SD-WAN Orchestrator), <a href=\"https:\/\/www.vulncheck.com\/blog\/filerun-delegated-admin-sql-to-object-injection-rce\" target=\"_blank\">CVE-2026-73693, CVE-2026-73694, CVE-2026-73698, CVE-2026-73699<\/a> (FileRun), <a href=\"https:\/\/www.vulncheck.com\/advisories\/ghostscript-heap-buffer-overflow-via-jpeg-2000-output-adapter\" target=\"_blank\">CVE-2026-39919<\/a> (Ghostscript), <a href=\"https:\/\/www.vulncheck.com\/advisories\/casdoor-through-4.4.0-cross-organization-user-administration-via-api-mcp\" target=\"_blank\">CVE-2026-91998<\/a> (Casdoor), <a href=\"https:\/\/www.vulncheck.com\/advisories\/flowise-before-3.1.4-remote-code-execution-via-cwd-parameter\" target=\"_blank\">CVE-2026-91932<\/a>, <a href=\"https:\/\/www.vulncheck.com\/advisories\/flowise-before-3.1.4-remote-code-execution-via-custom-mcp-npx\" target=\"_blank\">CVE-2026-91931<\/a> (Flowise), <a href=\"https:\/\/www.thezdi.com\/blog\/2026\/9\/16\/the-apple-security-update-review-for-september-2026\" target=\"_blank\">CVE-2026-65400, CVE-2026-65414, CVE-2026-65346, CVE-2026-84607, CVE-2026-43790<\/a> (Apple), <a href=\"https:\/\/kb.cert.org\/vuls\/id\/212479\" target=\"_blank\">CVE-2026-90999<\/a> (Sentry Seer), <a href=\"https:\/\/kb.isc.org\/docs\/aa-00913\" target=\"_blank\">CVE-2026-77692, CVE-2026-76163, CVE-2026-19667, CVE-2026-19666, CVE-2026-80274<\/a> (ISC BIND 9), <a href=\"https:\/\/support.checkpoint.com\/results\/sk\/sk1000155\" target=\"_blank\">CVE-2026-91843<\/a> (Check Point), <a href=\"https:\/\/docs.docker.com\/security\/security-announcements\/#docker-sandboxes-0420-security-update-cve-2026-77179-and-cve-2026-79994\" target=\"_blank\">CVE-2026-77179<\/a> (Docker), <a href=\"https:\/\/nlnetlabs.nl\/projects\/unbound\/security-advisories\/\" target=\"_blank\">CVE-2026-81642, CVE-2026-82717<\/a> (Unbound DNS), <a href=\"https:\/\/pwn.ai\/blog\/click2shell\" target=\"_blank\">Click2Shell<\/a> (WordPress), <a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\" target=\"_blank\">CVE-2026-28326, CVE-2026-28323, CVE-2026-28309, CVE-2026-28306, CVE-2026-28308, CVE-2026-28310, CVE-2026-28314, CVE-2026-28313, CVE-2026-28307, CVE-2026-28305, CVE-2026-28317, CVE-2026-28304, CVE-2026-28312, CVE-2026-28316, CVE-2026-28311, CVE-2026-28302, CVE-2026-28321, CVE-2026-28315<\/a> (SolarWinds), <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-89026\" target=\"_blank\">CVE-2026-89026<\/a> (Issabel Framework), <a href=\"https:\/\/www.wordfence.com\/blog\/2026\/09\/100000-wordpress-sites-exposed-to-remote-code-execution-via-php-object-injection-vulnerability-found-by-wordfence-argus-in-tutor-lms\/\" target=\"_blank\">CVE-2026-78175<\/a> (Tutor LMS), an <a href=\"https:\/\/kb.cert.org\/vuls\/id\/280377\" target=\"_blank\">operating system command injection vulnerability<\/a> in Dokploy, and a <a href=\"https:\/\/kb.cert.org\/vuls\/id\/369093\" target=\"_blank\">pickle deserialization vulnerability<\/a> in MLflow.<\/p>\n<h2 style=\"text-align: left;\"><strong>\ud83c\udfa5 Cybersecurity Webinars<\/strong><\/h2>\n<ul>\n<li><a href=\"https:\/\/thehacker.news\/ai-agents-governance\" target=\"_blank\">How to Find and Control AI Agents Before Access Gets Out of Hand<\/a> \u2192 AI agents are getting access to apps, data, credentials, and workflows faster than most teams can govern them. The real problem is not adoption \u2014 it is knowing which agents exist, what they can reach, and where access has quietly become too broad. This webinar breaks down how to bring AI agents under control without slowing down the teams using them.<\/li>\n<li><a href=\"https:\/\/thehacker.news\/runtime-identity-security\" target=\"_blank\">AI Attacks Move in Minutes. Here&#8217;s How to Stop Them at Runtime<\/a> \u2192 AI-powered attacks are shrinking the time defenders have to react. By the time a traditional alert is investigated, the attacker may already have moved through the environment. This webinar shows how runtime identity security can make access decisions in real time, block risky activity earlier, and give security teams a better chance against machine-speed attacks.<\/li>\n<\/ul>\n<h2 style=\"text-align: left;\"><strong>\ud83d\udcf0 Around the Cyber World<\/strong><\/h2>\n<ul>\n<li><strong>Google Doc Leads to ClickFix Attack <\/strong>\u2014 Huntress disclosed details of a ClickFix attack in which a security researcher was targeted in an X exchange by a threat actor posing as a crypto marketing executive. \u00abThe threat actor sent a link to a real Google Doc with a custom sidebar designed to trick the recipient into downloading malware: an AMOS infostealer on macOS, or a PowerShell loader chain on Windows,\u00bb Huntress <a href=\"https:\/\/www.huntress.com\/blog\/google-doc-sidebar-malware-mac-windows\" target=\"_blank\">said<\/a>. \u00abThe Google Doc featured a sidebar displaying a fake decryption failure message, with supposed remediation instructions for users of different operating systems, including the option to copy and paste certain commands into the Terminal. This ClickFix lure, and the \u00abmanual update\u00bb button beside it, are what actually delivered the malware. The sidebar itself was a Google Apps Script bound to the document, so nothing had to be downloaded for it to run.\u00bb The Apps Script executed client-side in the victim&#8217;s browser, and collected the victim&#8217;s public IP address and geolocation and scanned for crypto wallets.<\/li>\n<li><strong>Brevo Supply Chain Attack Injects ClickFix Scripts on Customer Sites <\/strong>\u2014 Customer engagement platform Brevo <a href=\"https:\/\/status.brevo.com\/incidents\/01M2QBC4EZ24ZACW6SWQYVW8N3\/write-up\" target=\"_blank\">fell victim to a supply chain attack<\/a> that led to malicious code being injected into over 100,000 websites. \u00abOn 14 September 2026, an attacker used a compromised Brevo Cloudflare API key to deploy a Cloudflare Worker on our account,\u00bb Brevo said. \u00abFor about five and a half hours, the Worker injected a malicious script into pages of brevo.com and sibforms.com and into three JavaScript files that customers embed on their own websites.\u00bb The script showed selected visitors a fake Cloudflare CAPTCHA prompt that instructed visitors to paste and run a malicious command on their computer, a technique also called ClickFix. Sansec, which <a href=\"https:\/\/sansec.io\/research\/brevo-supply-chain-attack\" target=\"_blank\">shared additional details<\/a> of the attack, said the \u00abattackers piggy-backed on embedded Brevo widgets to install WordPress malware on Brevo customer sites and launch ClickFix attacks against their visitors.\u00bb In all, the incident served malware to visitors of Brevo&#8217;s own site and over 100,000 customer sites. The malware featured two components: a malicious WordPress plugin that was installed when site admins visited their own site and a ClickFix overlay that was displayed to everyone browsing a customer site or clicking a link (including the unsubscribe link) in a Brevo-sent campaign email. Earlier this month, Brevo disclosed a <a href=\"https:\/\/status.brevo.com\/incidents\/01M266V1CZKJQNGZRNEGFD5CQE\/write-up\" target=\"_blank\">separate incident<\/a> wherein attackers hijacked customer accounts and launched phishing attacks targeting downstream users of Brevo&#8217;s customers. The attacker \u00abexploited a flaw in the way Brevo handles SAML SSO to gain access to 138 Brevo accounts,\u00bb Brevo said. \u00ab6 of those accounts were used to send phishing emails to the contacts stored there, and for 43 accounts they exported the contacts.\u00bb Among those impacted were <a href=\"https:\/\/x.com\/trezor\/status\/2097786518110609620\" target=\"_blank\">Trezor<\/a>, <a href=\"https:\/\/x.com\/Coin_Tracking\/status\/2097800407103783325\" target=\"_blank\">CoinTracking<\/a>, and <a href=\"https:\/\/x.com\/bitboxswiss\/status\/2097793026336981079\" target=\"_blank\">BitBox<\/a>.<\/li>\n<li><strong>Cryptocurrency Theft Campaign Abuses Google Visualization API for C2 <\/strong>\u2014 A new cryptocurrency-stealing campaign has been observed using Google Visualization API for command-and-control (C2), while fetching obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim&#8217;s browser session. \u00abThe actors use a variation on ClickFix social engineering,\u00bb Cisco Talos <a href=\"https:\/\/blog.talosintelligence.com\/clickfix-moves-into-the-browser\/\" target=\"_blank\">said<\/a>. \u00abInstead of convincing targets to run commands against the operating system, they convince targets to paste JavaScript into the Chrome address bar or install it into the <a href=\"https:\/\/www.tampermonkey.net\/\" target=\"_blank\">Tampermonkey browser extension<\/a>, which also provides persistence.\u00bb The lure masquerades as leaked vulnerability reports describing non-existent API flaws at cryptocurrency swap services, meaning the campaign is aimed at aspiring cybercriminals who are willing to exploit such vulnerabilities for financial gain. The lures are distributed via Telegram, DarkForums, and paste sites. \u00abThe injected script functions as a web skimmer,\u00bb Talos added. \u00abIt hooks the browser&#8217;s fetch API, replaces cryptocurrency deposit addresses in server responses and the user&#8217;s clipboard, and displays counterfeit &#8216;bonus&#8217; interface elements.\u00bb The campaign is said to have been <a href=\"https:\/\/bolster.ai\/blog\/swapzone-profit-trick-web-inject-from-lure-to-live-dom-hijack\" target=\"_blank\">ongoing since October 2025<\/a>. A total of 49 BTC wallet addresses have been tied to the campaign, with 24 receiving funds amounting to $10,000 from victims as of early August 2026.<\/li>\n<li><strong>Shai-Hulud Resurfaces After 111 Days <\/strong>\u2014 Aikido Security said it discovered four npm packages \u2013 feishu-docx-mcp@0.3.2, bmc-i18n-extract-cli@1.1.1, blueai-cli@0.7.0, and bmc-translate-utils@1.1.1 \u2013 containing the Shai-Hulud worm previously discovered in the attack targeting AntV in May 2026. \u00abFour packages is a small number attached to a larger fact: a payload with a known, published, indexed hash sat untouched in nobody&#8217;s toolchain for over three months and was then republished on a registry that, as of this year, explicitly scans every package before it goes live,\u00bb Aikido <a href=\"https:\/\/www.aikido.dev\/blog\/shai-hulud-npm-resurfaces\" target=\"_blank\">said<\/a>. \u00abThat gap between what registry-level scanning claims to do and what a hash-identical reactivation shows it actually caught is the real story here.\u00bb<\/li>\n<li><strong>Google Debuts AndroidX Security State Libraries <\/strong>\u2014 Google announced the stable release of AndroidX Security State version 1.1.0 and Security State Provider version 1.0.0 libraries to bring more transparency into the security posture of an Android device. These libraries provide a \u00abcentralized mechanism designed to bring further transparency to the comprehensive security posture and pending updates across the Android ecosystem,\u00bb Google <a href=\"https:\/\/android-developers.googleblog.com\/2026\/09\/introducing-androidx-security-state-libraries.html\" target=\"_blank\">said<\/a>. \u00abWhether you develop security-critical, consumer-facing apps (such as banking, fintech, or healthcare) or Mobile Device Management (MDM) solutions, these libraries enable you to verify the security state of the device per component programmatically. Rather than relying on a coarse, monolithic Security Patch Level (SPL), you can evaluate true component-level protection and whether remediations are actively pending via the androidx.security.state library. For OEMs and Over-The-Air (OTA) client developers, the companion androidx.security.state.provider library allows you to expose update availability via standardized mechanisms.\u00bb <\/li>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjBZLC_J3TKElcDQDQ_QNaKd_wp-z6UC50CpSunWOSDGZpeAk4xCMFAp3b_VLrh_nhhNicaP5GFTZx-6hscMi4VexDwlo_nFM4WM90tnI11fBAWiRx3ldDvt4LPlueSy7PDTEO0cBSwZE1dwZyvwgD1D5Y_5JfBG7bHEg1zYXaTZanBi-aOzxgC03hpbCGD\/s1700-nu-rw-lo-l85-e365\/androidz.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjBZLC_J3TKElcDQDQ_QNaKd_wp-z6UC50CpSunWOSDGZpeAk4xCMFAp3b_VLrh_nhhNicaP5GFTZx-6hscMi4VexDwlo_nFM4WM90tnI11fBAWiRx3ldDvt4LPlueSy7PDTEO0cBSwZE1dwZyvwgD1D5Y_5JfBG7bHEg1zYXaTZanBi-aOzxgC03hpbCGD\/s1700-nu-rw-lo-l85-e365\/androidz.png\" alt=\"\" border=\"0\" data-original-height=\"1040\" data-original-width=\"1600\"\/><\/a><\/div>\n<li><strong>Ukrainian Hacker Jailed in Switzerland for Ransomware Attacks <\/strong>\u2014 A Zurich court <a href=\"https:\/\/www.swissinfo.ch\/eng\/swiss-politics\/ukrainian-hacker-jailed-in-switzerland-over-ransomware-attacks\/92040952\" target=\"_blank\">sentenced<\/a> a Ukrainian IT specialist to 12 years and nine months in prison for developing ransomware used in extortion attacks on companies, including Stadler Rail.  The court identified the defendant as the lead developer behind the Lockergoga, MegaCortex, and Nefilim ransomware families, although he claimed that he only worked as a consultant for an unknown client in the field of IT security and that he had been unaware that his software was being used for ransomware attacks. The activity led to $123 million in estimated losses.<\/li>\n<li><strong>Surfshark Discloses Security Incident <\/strong>\u2014 Surfshark disclosed that unknown threat actors accessed one of its internal test servers after a configuration error exposed it to the internet. \u00abDue to a human error, an internal test server used by our engineering teams was misconfigured in a way that made it reachable from the internet,\u00bb Surfshark <a href=\"https:\/\/surfshark.com\/blog\/security-update-september-2026-incident-report\" target=\"_blank\">said<\/a>. \u00abIt contained parts of the system binaries and internal configurations for certain services. Personal information was never held and accessible from here, VPN traffic and browsing activity are not logged or retained in the first place, and the apps and browser extensions on your devices were not altered in any way.\u00bb The incident was discovered on August 31, 2026.<\/li>\n<li><strong>New Panzer Ransomware Emerges <\/strong>\u2014 A ransomware group called <a href=\"https:\/\/www.ransomware.live\/group\/Panzer\" target=\"_blank\">Panzer<\/a>, which emerged in early August 2026, has already claimed 32 victims on its data leak site. The group mainly targeted technology, manufacturing, government, and education sectors in Germany, Indonesia, France, Spain, and Italy. According to <a href=\"https:\/\/cyberxtron.com\/resources\/blogs\/panzer-ransomware-profile-of-an-emerging-double-extortion-operator-8102\" target=\"_blank\">CyberXTron<\/a>, \u00abPanzer operates on an 80\/20 revenue split, with 80% of ransom proceeds going to the affiliate and 20% retained as a platform fee. The group supports cross-platform builds for Windows, Linux, ESXi, and FreeBSD. Its stated rules prohibit targeting CIS countries and entities involving minors under 18.\u00bb<\/li>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhjmJELgIMU4WxjTOB-GdbSJQOffPBog8zO8_6OnSM52UeIusTJ_g7kBTZ9GuiaB1JCClR1lo9AooATvBQd18NkDFfYnkJpPZaQxUmw79WpOyEnviLkDpD1oHzj2z229xRWpH70GNQC5kHbS0PeY8gdC_I-I4rK1baU8m8U4sTwI2TFl868IleYM84rsljr\/s1700-nu-rw-lo-l85-e365\/panzer.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhjmJELgIMU4WxjTOB-GdbSJQOffPBog8zO8_6OnSM52UeIusTJ_g7kBTZ9GuiaB1JCClR1lo9AooATvBQd18NkDFfYnkJpPZaQxUmw79WpOyEnviLkDpD1oHzj2z229xRWpH70GNQC5kHbS0PeY8gdC_I-I4rK1baU8m8U4sTwI2TFl868IleYM84rsljr\/s1700-nu-rw-lo-l85-e365\/panzer.png\" alt=\"\" border=\"0\" data-original-height=\"681\" data-original-width=\"954\"\/><\/a><\/div>\n<li><strong>Review of Anthropic&#8217;s Project Glasswing Ledger <\/strong>\u2014 VulnCheck&#8217;s review of Anthropic&#8217;s Project Glasswing ledger found that only 202 of 26,153 claimed findings have been addressed after nearly five months, while 245 have been withdrawn and 2 have been marked as duplicates. \u00abFive months into the project, the 202 fixed findings in the ledger span 113 unique projects, resulting in an average of just 1.79 fixed findings per project,\u00bb VulnCheck&#8217;s Patrick Garrity <a href=\"https:\/\/www.vulncheck.com\/blog\/anthropic-glasswing-receipts\" target=\"_blank\">said<\/a>. \u00abThe ledger has more withdrawn\/duplicate findings than fixed vulnerabilities, which makes me question Anthropic&#8217;s 91.4% true-positive claim.\u00bb The analysis also showed a significant gap between Claude&#8217;s severity assessments and those of maintainers: Claude rated 91.5% of findings as critical or high severity, compared with only 51.3% from maintainers.<\/li>\n<li><strong>Google Unveils Agent Anomaly Detection <\/strong>\u2014 Google unveiled Agent Anomaly Detection in private preview on the Gemini Enterprise Agent Platform, which acts as a \u00abreasoning-based oversight and audit layer\u00bb that examines what an agent actually does using its reasoning traces, tool calls, and execution flow across a session. \u00abIt reads the logs and OpenTelemetry traces your agents already emit, evaluates that activity to decide whether an agent is operating outside its intended boundaries, and flags behavioral anomalies, suspicious intent, and policy violations,\u00bb Google <a href=\"https:\/\/developers.googleblog.com\/agent-anomaly-detection-now-in-private-preview-on-the-gemini-enterprise-agent-platform\/\" target=\"_blank\">said<\/a>.<\/li>\n<\/ul>\n<h2 style=\"text-align: left;\"><strong>Conclusion<\/strong><\/h2>\n<p>The lesson this week is pretty basic: trust less, check more. A familiar tool, package, login flow, browser prompt, or cloud setup can still be the weak spot. Old payloads can come back, exposed systems still get found, and \u00abtrusted\u00bb does not mean \u00absafe.\u00bb<\/p>\n<p>The other lesson is speed. Attack paths are getting shorter, research is getting faster, and weak defaults do not stay quiet for long. Patch what matters, watch what is exposed, and do not assume the boring stuff is harmless. That is usually where the week starts.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3019,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[346,683,24,265,124,225,774,316,1276],"class_list":["post-3018","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-0day","tag-agent","tag-attacks","tag-browser","tag-cisco","tag-clickfix","tag-hijacks","tag-rce","tag-surge"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3018","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3018"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3018\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3019"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3018"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3018"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3018"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}