This week’s threats focused on attacks that hide behind trusted updates, login pages, AI tools, and familiar links to steal credentials, hijack sessions, and gain control of devices and services. The roundup also highlighted supply chain abuse, EDR evasion, malicious WordPress updates, and phishing campaigns tied to RemControl, MAX, Exvicy, DarkMe, Global Group, and MicrosoftSystem64. #RemControl #MAX #Exvicy #DarkMe #GlobalGroup #MicrosoftSystem64
Keypoints
- RemControl abuses Android Accessibility to overlay banking apps and steal data.
- Z.ai disabled ZCode features after local repositories were sent to Alibaba Cloud.
- MAX can capture screenshots, inject JavaScript, and intercept mini-app traffic.
- Exvicy copies ErrTraffic to spread malware through fake Cloudflare CAPTCHA pages.
- Malicious updates, supply chain tampering, and phishing remain the main entry points.
Read More: https://thehackernews.com/2026/09/threatsday-ai-search-poisoning-ai.html