Daily Recap, AI and automation featured prominently as Anthropic warned that Russian hackers used Claude to automate malware evasion and that AI could enable smaller actors to run state-level campaigns, while AI agents exploited PaperCut issues to compromise 395 organizations. Major follow-on risk and governance items included OpenAI facing Senate scrutiny over a Hugging Face probe, major patches and exploits across GitLab, Cisco FMC, and Microsoft Teams/Outlook/RDS/Excel, and the Surfshark breach of internal testing and proxy servers. #Claude #Anthropic #RussianHackers #OpenAI #HuggingFace #PaperCut #395Organizations #GitLab #CiscoFMC #BlueMoon #MicrosoftTeams #MicrosoftOutlook #RemoteDesktopServices #Android #GooglePlay #Trezor #Brevo #IDScan #Treasury #Conti #Surfshark #Kiteworks #BonfyAI #KevinMandia #Amazon #ThreatsDay #Pistachio
AI Threats
- Anthropic said Russian hackers used Claude to automate malware evasion, while its research also warned that AI can let smaller actors run state-level campaigns and a researcher resigned over AI safety concerns β Claude Abuse, AI Campaigns, AI Warning
- AI agents exploited PaperCut flaws to compromise 395 organizations, highlighting automated attack chains that combine vulnerability exploitation with scaling β PaperCut Attack, AI Exploit
- OpenAI faced Senate scrutiny over a Hugging Face breach probe as Cyber Command tapped an intelligence veteran for a top AI role β OpenAI Probe, AI Hire
Vulnerability Exploits
- GitLab urged users to patch a max-severity path traversal flaw, while Check Point disclosed two 9.8-rated VPN certificate bugs enabling unauthenticated RCE β GitLab Patch, VPN Flaws
- Cisco FMC flaws were reportedly exploited by a ransomware gang and state-sponsored hackers, and a new BlueMoon kit was found abusing Windows and Chrome zero-days β Cisco Exploits, BlueMoon Kit
- Microsoft shipped fixes for Teams and Outlook launch failures on ARM Windows PCs, while Windows Server September updates broke Remote Desktop Services and an Excel patch disrupted copy-paste for some users β Teams/Outlook Fix, RDS Breakage, Excel Bug
Malware & Mobile
- A new Android malware strain was seen encrypting files, stealing data, and harassing victims, while another roundup warned of 200 Android flaws, browser-built phishing, and 119K scam shops β Android Malware, ThreatsDay
- Google Play Early Access was abused to push thousands of deceptive Android apps, and passkeys can now move between password managers on Android β Play Abuse, Passkey Transfer
- Trezor said 347,000 users were targeted in phishing after the Brevo breach, showing how third-party incidents fuel downstream credential attacks β Trezor Phish
Data Breaches & Fraud
- IDScan confirmed a breach tied to 153 million stolen driverβs licenses offered on the dark web, underscoring the scale of identity-data exposure β IDScan Leak, IDScan Notice, IDScan Confirmed
- The Treasury urged banks to report cyber scams, citing nearly $13 billion in losses since 2023, and a report noted cheap SIM-swapping style attacks can still kick a strangerβs phone off the network β Treasury Scam, SIM Costs
Ransomware & Criminal Justice
- A Conti ransomware gang member was sentenced to 4 years in prison, while guidance on building a ransomware decision tree and reporting scam losses aimed to improve preparedness β Conti Sentence, Conti Conviction, Ransomware Prep
VPNs & Service Incidents
- Surfshark said hackers breached its internal testing and proxy servers, adding to vendor-security concerns around private network infrastructure β Surfshark Hit, Surfshark Breach
Industry Moves
- Kiteworks acquired Bonfy.AI to expand runtime data governance and close the AI governance gap, while Kevin Mandia joined the Amazon board and the month saw 33 cybersecurity M&A deals β Kiteworks Deal, Kiteworks Expand, Mandia Joins, M&A Roundup
Research & Risk
- Security research said companies may be measuring phishing resilience the wrong way, while another report highlighted the top threats found by investigating every alert for a quarter β Phishing Metrics, Threat Review
- ThreatsDay also surfaced broader ecosystem risks including Android flaws, browser phishing, and large-scale scam operations β ThreatsDay