Agentic AI has accelerated attacks by making long-standing technical, governance, skill, infrastructure, and AI-attack-surface debts easier for threat actors to collect on at scale. The article cites cases including JADEPUFFER, GTG-1002, PROMPTSTEAL, QUIETVAULT, PROMPTFLUX, FRUITSHELL, HONESTCUE, and the marimo intrusion to show that AI mostly changes speed, scale, and orchestration rather than introducing new attack techniques. #Anthropic #Claude #JADEPUFFER #HuggingFace #GTG-1002 #PROMPTSTEAL #QUIETVAULT #PROMPTFLUX #FRUITSHELL #HONESTCUE #marimo
Category: Threat Research
ChainDrop is a self-propagating npm worm linked to TeamPCP that compromised a maintainer account, abused trusted GitHub Actions releases, and spread poisoned packages with valid provenance. It stole developer credentials, used an Ethereum smart contract for rotating C2 domains, and planted persistence hooks in IDE and AI-agent configuration files, while also threatening destructive deletion when tokens were revoked. #ChainDrop #TeamPCP #keyv #Sigstore #SLSA #Ethereum
Cl0p has systematically targeted internet-facing managed file transfer and related enterprise applications, often using zero-day exploits, pre-attack reconnaissance, and reused infrastructure across campaigns such as MOVEit, Oracle E-Business Suite, and Centrestack. The report finds that Cl0p’s seasonal Q4 activity, long reconnaissance windows, and architectural weaknesses in MFT systems create strong defensive…
A legacy Entra ID WS-Trust autologon endpoint used for Seamless SSO can be abused to spray passwords past Smart Lockout, bypass normal sign-in logging, and reveal whether credentials are valid even when MFA or Conditional Access blocks the final sign-in. Microsoft has left this path available for older Office 2013 clients,…
Socket’s Threat Research Team uncovered a campaign of 737 free VPN and proxy Chrome extensions spread across at least 40 developer accounts, many of which impersonate established brands and route browser traffic through a single operator’s SOCKS5 infrastructure. The operation also includes fake premium servers, DNS-over-HTTPS evasion, post-approval code substitution, and coordinated store-review deception tied to Myxa VPN and related domains. #MyxaVPN #ChromeWebStore #AmneziaVPN #AntiZapret
Project CAV3RN is a modular espionage framework targeting Israel that uses a DNS-based control plane to switch between direct HTTPS and a Google Apps Script relay. The newly documented components include GoogleService.dll and rnp.dll, which support tasking, module discovery, runtime upgrades, and brokered communication. #ProjectCAV3RN #GoogleService.dll #rnp.dll #studiotikva.com
Storm-2945, a sub-cluster of Midnight Blizzard, is running CaptiveCrunch to hijack hotel and conference Wi-Fi captive portals, redirecting travelers to attacker-controlled sites for Microsoft 365 credential theft, device code phishing, and malware delivery. The campaign uses CornFlake and ChocoShell, manipulates DNS/HTTP traffic, and extends to Android via malicious APKs. #Storm2945 #MidnightBlizzard #CaptiveCrunch #CornFlake #ChocoShell #Microsoft365 #MicrosoftEntraID #Android
A fake CCleaner installer is being used to deliver the GhostDesk Chrome extension, which steals credentials, cookies, screenshots, and keystrokes from Windows users. The campaign also uses lookalike fake apps such as 7-Zip and Adobe Acrobat, all connecting to the same command-and-control infrastructure to spread the spyware payload. #CCleaner #GhostDesk #Chrome…
The Chrome extension “AI Sidebar with DeepSeek AI” was relisted after being removed for stealing AI conversation content, and its latest build now performs affiliate referral fraud through silent tab opens on update and uninstall. Netskope found the malicious version 1.7.3.0 being delivered to enterprise endpoints via Google’s CRX distribution, with the extension ID inhcgfpbfdjbjogdfjbclgolkmhnooop and prior exfiltration domains deepaichats[.]com and chatsaigpt[.]com. #AISidebarwithDeepSeekAI #inhcgfpbfdjbjogdfjbclgolkmhnooop #deepaichats #chatsaigpt
Check Point Research tracked a long-running Operation Dream Job campaign linked to Lazarus, with a latest wave targeting defense organizations in Europe and India using trojanized PDF viewers, spear-phishing, and compromised web infrastructure. The campaign deployed SecurityPDF, Troy, MISTPEN, RelayShell, and a new FudModule variant exploiting CVE-2026-68820 while also abusing Roundcube servers via CVE-2025-49113. #OperationDreamJob #Lazarus #SecurityPDF #Troy #MISTPEN #RelayShell #FudModule #CVE-2026-68820 #CVE-2025-49113
CERT-AGID observed a phishing campaign abusing the INPS name, logo, and visual identity to lure victims to a fake site that collects personal documents and photos. The fraudulent portal also uses an AI-based file validation step, reportedly identified as Gemini 1.5 PRO, to filter uploads and increase the quality of stolen data. #INPS #CERT-AGID #Gemini1.5PRO
Kaspersky reported a July 2026 Head Mare campaign that abused two TrueConf Server vulnerabilities to gain SYSTEM-level code execution, deploy a web shell, and replace legitimate client installers with infected versions carrying PhantomCore and PhantomGraph. The attackers used Microsoft OneDrive as C2 for one backdoor, installed persistence through registry and Windows services, and targeted Russian organizations across multiple industries. #TrueConf #HeadMare #PhantomCore #PhantomGraph
Unit 42 reports Kimwolf v7, an Android/IoT botnet update that strengthens DDoS flooding and adds a more resilient three-tier C2 system using Ethereum ENS, Tor, and a local proxy. The malware targets Android TV boxes and set-top boxes, spreads through abused ADB access, and uses HTTP/2 browser fingerprinting to make attack…
CloudSEK says Team PCP leveraged a compromised security toolchain to push malicious LiteLLM releases in March 2026, creating a large supply-chain exposure across AI infrastructure and CI/CD environments. The incident potentially exposed cloud credentials, repository tokens, Kubernetes secrets, and AI provider keys at thousands of organizations, while FBI FLASH-20260702-01 warns the stolen access may still be weaponized. #TeamPCP #LiteLLM #Trivy #FBI FLASH-20260702-01
Aeternum is a C++ botnet loader that moves command-and-control operations onto the Polygon blockchain, using smart contracts and RPC queries to retrieve encrypted or plaintext instructions. The investigation also links Aeternum to a Telegram-based Python malware family and a blended payload set involving XWorm RAT and the XMRig miner, while highlighting…