Daily Recap, AI agent security drew attention as attackers abuse agentic workflows and new runtime enforcement and guardrails are proposed to prevent hidden instruction hijacking. At the same time, patch and exploitation activity stayed intense, including Microsoftβs record September Patch Tuesday fixes and active targeting of F5 BIG-IP APM devices.
#Akeyless #AI Agents #Chrome V8 #F5 BIG-IP APM #Linux Rootkit #PHP Web Shell #Microsoft #Patch Tuesday #WeChat #DoppelCart #ShinyHunters #Florida #DAVID DMV #ShinyHunters #Liquid #Elements #Liquid #Slim Spider #Brazil #Schneider Electric #Siemens #EU CRA #Maduro #CIA
#Akeyless #AI Agents #Chrome V8 #F5 BIG-IP APM #Linux Rootkit #PHP Web Shell #Microsoft #Patch Tuesday #WeChat #DoppelCart #ShinyHunters #Florida #DAVID DMV #ShinyHunters #Liquid #Elements #Liquid #Slim Spider #Brazil #Schneider Electric #Siemens #EU CRA #Maduro #CIA
AI Security
- AI agents are increasingly being abused in attacks and defended with new controls, as Akeyless adds real-time enforcement for production agents, hidden instructions can hijack them, and researchers warn threat actors are giving AI agents a bigger role in cyberattacks. β AI Control
- China is under fire over AI capability extraction, with U.S. agencies and CISA warning that Chinese firms are systematically distilling and siphoning frontier model knowledge from American companies. β AI Extraction, Model Distill, China AI
- Gartner says 70% of SOCs will pilot AI agents but only 15% will get results, while new tools like AI-Infra-Guard, Zscaler Agentic SOC, and Mars Security push AI deeper into detection and response. β SOC AI
- Meta launched its personal AI agent Muse, emphasizing safety and privacy. β Muse
Major Vulnerabilities
- Microsoft patched a record 974 vulnerabilities, including 2 actively exploited zero-days, across its September Patch Tuesday releases. β Patch Tuesday, MSFT Bugs, Record Fixes
- Adobe fixed more than 170 vulnerabilities, including a Commerce zero-day. β Adobe Patch
- Chrome V8 has a zero-day being exploited in the wild for sandboxed code execution, while N-able N-central, cPanel, SAP (OVERPASS), and Plex were all hit by serious flaws or exposed systems. β Chrome Zero-Day, cPanel RCE, N-able RCE, Plex Servers
- Schneider Electric and Siemens fixed critical ICS bugs on Patch Tuesday, underscoring ongoing risk in industrial environments. β ICS Patch
- Windows 10 and Windows 11 got new updates, while some Windows Server 2016 systems saw 0xc0000409 errors after August patches. β Win10 ESU, Win11 Updates, Server Error
Active Exploitation
- Attackers are exploiting F5 BIG-IP APM devices with a Linux rootkit that hides a PHP web shell in memory to evade disk-based scans. β F5 Rootkit, F5 Breach
- A zero-click WeChat worm can hijack accounts and spread through a single call, highlighting major messaging-app risk. β WeChat Worm
Fraud, Crypto & Breaches
- The DoppelCart fraud network used 119,000 fake shops to steal credit cards, while ShinyHunters claimed a breach of Floridaβs DAVID DMV database. β DoppelCart, DMV Breach
- Liquid hackers returned 3,400 Bitcoin from the Elements bug theft and still hold about $47 million in BTC; separately, a scammer tied to a $245 million crypto heist pleaded guilty to RICO charges. β Liquid BTC, Liquid Return, Crypto RICO
- Slim Spider stole crypto custody secrets from a Brazilian financial institution, adding to regional financial-targeting concerns. β Slim Spider
- A Russian national was extradited to the U.S. over an alleged bank-account takeover scheme. β Extradited Suspect
- CIA cyber operations continue to expand, with officials saying cyber intelligence is reshaping agency activity and contributing to operations involving Venezuelaβs Maduro. β CIA Cyber, Maduro Ops
Platform & Infrastructure
- AWS said it spent years rebuilding its routing control plane without taking the network down, underscoring large-scale resilience engineering. β AWS Routing
- cPanel, Plex, and Windows updates rounded out a busy patch cycle for admins managing exposed internet-facing services. β cPanel Flaw, Plex Risk
Policy & Risk
- The EU CRA debate is sharpening around accountability for what shipped and when vendors knew it, while water utility security experts warn no single entity owns the whole network. β EU CRA, Water Risk