ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, M Reward, GLM-5.3 AI Exploit and More
This week’s threats show attackers abusing trusted components, exposed systems, and weak assumptions to bypass defenses, from Microsoft-signed BTR.sys and vulnerable drivers to covert backdoors and CI/CD takeover flaws. Other highlights include major action against the Mabna Institute, Grandoreiro DLL sideloading, refrigeration controller RCE issues, and AI tools increasingly used for both privacy-preserving defense and exploitation research. #BTR.sys #MabnaInstitute #Grandoreiro #ErrTraffic #Cruciferra #CopelandXWEBPro #DanfossAKSM800A #Gogs #n8n #CircleCI #SaltTyphoon #TMobile #GLM53 #KriminalAI

Keypoints

  • Check Point showed how Microsoft-signed BTR.sys can be repurposed to bypass endpoint defenses.
  • The DoJ charged 17 Mabna Institute members for stealing academic and intellectual property data for Iran.
  • Grandoreiro is abusing Duplicate Files Finder through DLL sideloading, mainly impacting Latin America.
  • ErrTraffic is being used to deliver ClickFix lures and payloads like Cruciferra and Remus Stealer.
  • New flaws in Gogs, n8n, CircleCI, and refrigeration controllers can lead to remote code execution.

Read More: https://thehackernews.com/2026/08/threatsday-gogs-100-rce-n8n-workflow-to.html