This week’s threats show attackers abusing trusted components, exposed systems, and weak assumptions to bypass defenses, from Microsoft-signed BTR.sys and vulnerable drivers to covert backdoors and CI/CD takeover flaws. Other highlights include major action against the Mabna Institute, Grandoreiro DLL sideloading, refrigeration controller RCE issues, and AI tools increasingly used for both privacy-preserving defense and exploitation research. #BTR.sys #MabnaInstitute #Grandoreiro #ErrTraffic #Cruciferra #CopelandXWEBPro #DanfossAKSM800A #Gogs #n8n #CircleCI #SaltTyphoon #TMobile #GLM53 #KriminalAI
Keypoints
- Check Point showed how Microsoft-signed BTR.sys can be repurposed to bypass endpoint defenses.
- The DoJ charged 17 Mabna Institute members for stealing academic and intellectual property data for Iran.
- Grandoreiro is abusing Duplicate Files Finder through DLL sideloading, mainly impacting Latin America.
- ErrTraffic is being used to deliver ClickFix lures and payloads like Cruciferra and Remus Stealer.
- New flaws in Gogs, n8n, CircleCI, and refrigeration controllers can lead to remote code execution.
Read More: https://thehackernews.com/2026/08/threatsday-gogs-100-rce-n8n-workflow-to.html