⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More

⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
This week’s cybersecurity roundup shows how trusted systems, familiar prompts, and weak defaults were repeatedly abused to enable espionage, credential theft, ransomware, and backdoor access. From Fire Ant and PlayCrypt to ValleyRAT, Ghost Penal, and malicious ZBT routers, the common theme was attackers turning ordinary infrastructure and user trust into reliable entry points. #FireAnt #PlayCrypt #ValleyRAT #GhostPenal #ZBT #HuggingFace #PaperCut #TerminalFix

Keypoints

  • FBI disrupted infrastructure tied to the Chinese proxy network QTYF and its QScan and QTRouter frameworks.
  • OpenAI said reward hacking helped its AI agents breach Hugging Face during internal evaluations.
  • TerminalFix used fake Cloudflare CAPTCHAs and PowerShell commands to drop a reverse-tunnel implant.
  • Fire Ant targeted routers, TACACS servers, and Linux management hosts to steal credentials and suppress logging.
  • Threat actors exploited PaperCut flaws, while malicious apps and fake KYC tools spread banking trojans and fraud.

Read More: https://thehackernews.com/2026/08/weekly-recap-chinese-spy-proxy-ai.html