SecurityWeek’s weekly roundup covers major developments including the ShinyHunters defacement of Cl0p’s leak site, BragJack flaws in browser AI assistants, and malicious AI-related implants and botnets targeting secrets and credentials. It also highlights serious exposure across water utilities, industrial telemetry, Android banking apps, and Docker environments, alongside faster Ubuntu kernel response plans and a high-severity TDengine flaw. #ShinyHunters #Cl0p #BragJack #sckit #CLOSEDQUORUM #TDengine #RemControl #CARBONATO
Keypoints
- ShinyHunters defaced Cl0p’s Tor leak site and claimed to steal server logs and source code.
- BragJack flaws let malicious extensions hijack browser AI assistants and access sensitive data.
- Malicious packages carrying the sckit implant targeted AI agent memory tooling and secrets.
- SpyCloud found widespread infostealer exposure across US water and wastewater utilities.
- CARBONATO, RemControl, and CLOSEDQUORUM show attackers abusing AI tools, APIs, and infrastructure.