Cybernews Digest
Weekly cybersecurity news roundup ·
2026
Week 37 — 11 Sep – 17 Sep
Week 36 — 04 Sep – 10 Sep
-
Staying Ahead of Adversarial AI Through Agentic Source Code Review | Google Cloud Blog
Google Cloud's Mandiant introduced the Agentic Vulnerability Discovery Harness (AVDH), a multi-agent AI framework that accelerates vulnerability discovery, validation, and exploitation path identification in source code, achieving over 100 critical true-positive findings in two days during an incident response and uncovering 12 assigned CVEs.
-
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Attackers are exploiting unauthenticated administrative access via exposed SSH on internet-facing MikroTik routers, as disclosed by CERT Polska, necessitating immediate patching and forensic review.
-
GitHub - elastic/supply-chain-monitor
GitHub's elastic/supply-chain-monitor automates the detection of supply chain compromises in PyPI and npm packages by diffing releases, analyzing changes via Cursor Agent CLI LLM, and alerting malicious findings to Slack.
-
ClickExfil: My iteration on ClickFix and FileFix
ClickExfil demonstrates a social engineering-driven exfiltration technique leveraging user interaction to extract plaintext credentials and sensitive data (e.g., ~/.claude/.credentials.json, session transcripts) via browser-based commands, bypassing traditional malware execution and evading EDR detection.
-
Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
Threat actors compromised over 5,400 WordPress and PrestaShop sites to deliver evolving ClickFix and WebRTC-based payloads via malicious smart contracts on the BNB Smart Chain Testnet, leveraging the EtherHiding technique for resilient, dynamic command-and-control execution.
-
ClickExfil: My iteration on ClickFix and FileFix
ClickExfil demonstrates a social engineering-driven exfiltration technique leveraging user interaction to extract plaintext credentials and sensitive session data from AI tools like Claude Code, bypassing traditional EDR detection by masquerading as legitimate user commands.
-
Don't Make AI Your Forensic Analyst | SIPDEP
AI-assisted forensic scribing leverages local LLMs to automate organizational tasks in digital forensics, avoiding full autonomous investigation due to current hardware limitations and reliability concerns.
Week 35 — 28 Aug – 03 Sep
-
TerminalFix campaign deploys a reverse tunnel through multistage intrusion | Microsoft Security Blog
The TerminalFix campaign employs a multi-stage attack chain, starting with a fake Cloudflare CAPTCHA to deliver a malicious PowerShell command that initiates DLL sideloading, steganographic payload extraction, extensive Active Directory reconnaissance, and ultimately deploys a Python-based reverse-tunnel implant for persistent, encrypted WebSocket-based network proxy access.
-
Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs
DOUBLECUP, a Russian Loader-as-a-Service (LaaS) for ClickFix campaigns, delivers CountLoader (v4.5p for Windows/macOS) and a new RAT, DeviceManager, via a multi-stage steganographic PNG dropper that decrypts payloads in-memory using a custom SHA-256 CTR-mode stream cipher and victim IP-derived XOR key.
Week 33 — 14 Aug – 20 Aug
Week 30 — 24 Jul – 30 Jul
-
Hackers abuse Notepad++ plugins to stealthily install malware
Threat actor UAC-0099 abused legitimate Notepad++ plugins and DLL hijacking in version 8.8.3 to stealthily deliver LunchPoke malware, BurnyBear loader, and MatchBoil V2 payload via a multi-stage VBScript and ZIP archive attack chain targeting Ukrainian organizations.
Week 29 — 17 Jul – 23 Jul
-
ClickLock Stealer: Paste Once, Lose Everything
Group-IB discovered ClickLock Stealer, a new modular macOS info-stealer malware distributed via ClickFix phishing pages and compromised WordPress domains, which exfiltrates browser credentials, password manager data, crypto wallet files, macOS Keychain, shell history, and FTP credentials while deploying a GSocket-based backdoor for persistent access.
-
Top ATT&CK Techniques
-
OCTOPUS
Octopus is an AI-driven automation system integrating three operational modes—assistive decision support, task execution, and autonomous remote operation—while dynamically learning workflows from user interactions without requiring separate tuning processes.
-
Introducing the Amazon GuardDuty investigation agent: on-demand AI-powered threat assessment | Amazon Web Services
Amazon GuardDuty's new investigation agent, now in public preview, leverages AI-powered cross-Region inference to automate and accelerate security investigations across AWS environments, delivering structured risk assessments, MITRE ATT&CK mappings, and actionable remediation steps with reduced manual effort.
-
A Tour of WebAuthn
WebAuthn leverages public key cryptography (e.g., ECDSA, RSA) to mitigate password-related risks like brute-force attacks, credential stuffing, and phishing by replacing password hashes with public keys and using hardware-backed private keys for authentication.
-
I Inspected My Take-Home Interview Project. It Was a Whole Operation.
A malicious take-home interview project embedded Git hooks that executed OS-specific remote payloads, installing obfuscated Node.js-based malware with suspicious dependencies like Hardhat, clipboardy, and fs, likely for cryptocurrency wallet exploitation or data exfiltration.
Week 28 — 10 Jul – 16 Jul
-
CrowdStrike Uncovers New Prompt Injection Techniques
CrowdStrike's research team unveiled 18 new prompt injection techniques, expanding their taxonomy to over 200 distinct methods, highlighting evolving threats such as delayed triggers, semantic constraints, and boundary spoofing that adversaries leverage to manipulate AI agents and systems.
-
Every Laptop Is a Credential Store: Complete Map of Hidden Secrets
Research reveals that developer laptops store dozens of long-lived, unrotated credentials across multiple hidden locations—including shell history, cloud caches, AI agent configs, and browser storage—which are systematically harvested by infostealers and evade traditional repo/CI secret scanners.
-
Build your own vulnerability harness
The article describes the development of a model-agnostic vulnerability discovery harness that treats AI models as interchangeable components to mitigate context exhaustion, persistence gaps, and cross-repo dependency blind spots, while employing a two-stage workflow (VDH and VVS) with distinct models for discovery and validation to enhance security coverage.
Week 27 — 03 Jul – 09 Jul
-
The Setup
Researcher demonstrated a prompt injection attack in YouTube Studio's Ask Studio AI assistant, enabling attackers to manipulate AI responses to exfiltrate private video titles via crafted comments, bypassing creator awareness through comment editing and trusted UI interactions.
-
2-Click Remote Code Execution in Meccha Chameleon
A 2-click remote code execution (RCE) vulnerability in *Meccha Chameleon* was exploited via malicious Steam Workshop maps containing UE5 Blueprints that leveraged the LaunchURL function to execute arbitrary batch files hosted in predictable Workshop directories.
Week 26 — 26 Jun – 02 Jul
Week 25 — 19 Jun – 25 Jun
Week 24 — 12 Jun – 18 Jun
-
Steam Workshop abused to spread malware via Wallpaper Engine app
Threat actors abused Steam Workshop’s Wallpaper Engine app to distribute malware via malicious application wallpapers, enabling account hijacking, backdoor deployment, cryptomining, and credential theft, with payloads executing automatically upon installation.
Week 23 — 05 Jun – 11 Jun
-
Detection Studio – detection.studio
Detection Studio by north.sh is a tool designed to generate SIEM queries, such as Splunk SPL, from Sigma rules for correlating suspicious events.
Week 22 — 29 May – 04 Jun
-
ChatGPT share links abused to host fake outage pages to deliver malware
Threat actors abused ChatGPT's LLMShare feature via Google ads to deliver malware by hosting fake outage pages on legitimate chatgpt.com/s/ links, redirecting users to a malicious OpenAI impersonation site (openew[.]app) that deploys infostealers.
-
LLMShare: using shared chatbot pages to distribute malware
Attackers are abusing AI chatbot platforms' shared content features (ChatGPT and Claude) to host malicious pages on trusted domains, distributing malware via malvertising and SEO poisoning, evading URL reputation checks and leveraging code rendering to mimic legitimate service disruption notices.
-
IBM and Red Hat Commit $5 Billion to Redefine the Future of Open Source in the AI Era
IBM and Red Hat announced Project Lightwell, a $5 billion initiative leveraging AI and 20,000 engineers to establish a trusted open-source security clearinghouse for large-scale vulnerability identification, validation, and remediation across enterprise software supply chains.
-
New CIFSwitch Linux flaw gives root on multiple distributions
A local privilege escalation vulnerability in the Linux kernel's CIFS subsystem (CVE-2026-46243) allows attackers to forge cifs.spnego key requests, abuse the cifs.upcall helper, and achieve root privileges via malicious NSS module loading.
-
FSB’s matryoshka #1/3: Inside Gamaredon Cyber Operations
Sekoia.io’s analysis reveals Gamaredon’s 2026 modular malware arsenal—GammaPhish, GammaLoad, GammaWorm, and GammaSteel—used in a multi-stage infection chain exploiting CVE-2025-8088 for initial access, employing ADS, DDRs, and DPAPI to evade detection while enabling persistent espionage and data exfiltration against Ukrainian targets.
-
VS Code zero-day lets hackers steal GitHub tokens in one click
A zero-day vulnerability in Visual Studio Code's sandboxed webview message-passing system enables attackers to steal GitHub OAuth tokens via malicious extensions, exploiting github.dev's OAuth token handling to gain full repository access.
Subscribe
Get the cybersecurity digest in your inbox every Friday at 05:00 UTC.