El colectivo hacktivista italiano Autistico/Inventati cierra tras ser designado como organización terrorista

Autistici/Inventati (A/I) es un colectivo hacktivista italiano nacido en 2001 para ofrecer infraestructura digital autónoma y segura frente a la comercialización de internet y la vigilancia estatal. 

Surgido de la confluencia entre la cultura hacker, el software libre y el activismo de los centros sociales, el grupo se consolidó como un pilar de la privacidad digital global tras destapar en 2005 que la policía italiana había instalado un sniffer en sus servidores para espiar a sus usuarios, lo que impulsó una profunda renovación en sus protocolos de cifrado e independencia técnica.

A/I opera bajo una estructura horizontal y asamblearia que rechaza cualquier forma de monetización, publicidad o recolección de datos personales. Se financia exclusivamente mediante donaciones comunitarias y el trabajo voluntario de sus miembros, garantizando la gratuidad de sus plataformas sin recurrir al modelo de negocio de las grandes corporaciones tecnológicas.

Su ideario político defiende la soberanía tecnológica, el anticapitalismo y la privacidad como un derecho fundamental indispensable para la libre organización social. 

Tras este cuarto de siglo, los servicios gratuitos de Autistici/Inventati habían crecido hasta albergar unas 16.000 direcciones de correo electrónico, 1.500 sitios web, 5.500 listas de correo y una red de unos 10.000 blogs, todo ello con el compromiso de proteger los datos de sus usuarios.

Sin embargo, tras 25 años de trayectoria, el grupo se ha visto obligado a cerrar sus puertas. La decisión ha llegado después de que el pasado 26 de agosto el Departamento de Estado de EE.UU. lo calificara como un «grupo extremista» que opera infraestructura para «militantes de extrema izquierda en todo el mundo».

El organismo anunció que cualquiera que tuviera relaciones financieras con el colectivo corría el riesgo de ser objeto de sanciones. Y esto lo habría dejado completamente sin recursos ni apoyos logísticos.  

«El grupo de hackers radicales y desarrolladores tecnológicos de A/I proporciona una gama completa de servicios –que incluyen chats y correo electrónico cifrados, alojamiento web, videoconferencias y retransmisiones seguras, protección del anonimato y un conjunto de otras herramientas tecnológicas– a grupos marxistas, anarquistas y otros grupos extremistas de izquierda en EE.UU., Europa y otros lugares»señalaba la agencia

Desde el Departamento de Estado aseguraron que su infraestructura digital permitía amparar a grupos de izquierda que planeaban ataques violentos, citando incidentes de sabotaje contra sistemas ferroviarios y energéticos en Europa, atentados con bomba contra centros de ayuda a mujeres embarazadas en crisis en EE.UU. y protestas contra el Centro de Capacitación de Seguridad Pública de Atlanta, conocido entre los activistas como «Cop City».

En un principio, A/I afirmó que EE.UU. los había designado como terroristas de manera injusta. Señalaron que querían eliminarlos con un «decreto unilateral y arbitrario»

Sin embargo, su defensa no sirvió de mucho. Esa etiqueta de organización terrorista les pesó como una losa y tuvo un efecto prácticamente inmediato. El Public Interest Registry, con sede en EE.UU., suspendió el dominio del grupo el 28 de agosto. Ese mismo día, el banco italiano del colectivo, Banca Etica, también canceló su cuenta debido a los riesgos de sanciones, al tiempo que declaró que «condena enérgicamente el uso de las listas de la OFAC con fines políticos». 

Antes de su clausura total, A/I ha indicado a los usuarios cómo hacer copias de seguridad del contenido de blogs, buzones de correo y sitios web. 

«La posibilidad de que nuestro trabajo pueda acarrear consecuencias legales y financieras a nuestros allegados –o incluso a personas que tengan alguna relación con nosotros– no nos deja otra opción», han explicado. «En estas circunstancias, ya no podemos mantener nuestra misión original: ofrecer herramientas digitales seguras y sin ánimo de lucro», han concluido. 

Un «precedente peligroso»

La European Digital Rights (EDRi) ha salido en defensa del colectivo y ha criticado la decisión. Sostiene que calificar la provisión de redes de comunicación neutras y de uso general como apoyo al terrorismo vulnera derechos fundamentales como la libertad de expresión y asociación, y sienta «un precedente peligroso«, empujando a la sociedad civil a depender exclusivamente de las Big Tech y sus sistemas de vigilancia.

«El simple hecho de que EE.UU. decida que alguien es terrorista –sin ningún procedimiento judicial, sin nada contra lo que se pueda oponer legalmente–, es decir, una simple decisión del Departamento de Estado, hace que toda la estructura de gobernanza de internet se desmorone», ha comentado. «Creo que eso plantea muchas preguntas».

Según la red europea, esta injerencia ejecutiva de un país tercero pasa por encima del Estado de derecho de la Unión Europea socava marcos legales como la Ley de Servicios Digitales (DSA), al castigar arbitrariamente a una entidad no lucrativa constituida y regulada bajo la legislación italiana.

Ante esta situación, insta al Gobierno estadounidense a retirar la orden y pide a las instituciones financieras e intermediarios de la UE que no acaten resoluciones extranjeras sin validez legal en territorio europeo. Asimismo, hace un llamamiento a la Unión Europea y al Gobierno de Italia para que utilicen mecanismos de protección como el Estatuto de Bloqueo (Reglamento CE 2271/96) para defender a las organizaciones sin ánimo de lucro y blindar la infraestructura cívica y no comercial del continente frente a presiones internacionales.

El grupo de ransomware Panzer afirma haber atacado a la AEMET y exige un rescate por 5 GB de datos

Un grupo de ciberdelincuentes de reciente creación denominado Panzer ha sumado a la Agencia Estatal de Meteorología (AEMET) a su lista de objetivos. 

Según las afirmaciones de la banda, habrían logrado sustraer un total de 5 GB de información interna del organismo público español.

La amenaza lanzada por los cibercriminales incluye un ultimátum habitual en la modalidad de doble extorsión: si la entidad pública no accede a sus demandas de chantaje económico, los 5 GB de datos serán publicados en su espacio de la web oscura en un plazo estimado de entre 20 y 21 días. La cuantía exigida en concepto de rescate no ha trascendido públicamente. 

Aunque el atacante no ha detallado públicamente la tipología exacta de los archivos comprometidos, en ataques similares este grupo acostumbra a exfiltrar documentación corporativa sensible, credenciales internas y registros de trabajadores o colaboradores.

El último en llegar

Panzer es uno de las bandas más nuevas y activos en el panorama del ransomware. Operan como un modelo de Raas (ransomware as a service) y cuenta con cargas maliciosas capaces de infectar entornos de sistemas Windows, Linux y plataformas de virtualización VMware ESXi.

Durante sus primeras semanas de actividad, la banda ha reivindicado ataques contra cerca de una veintena de organizaciones de diversos industrias y países, incluyendo otras instituciones gubernamentales de la Unión Europea e infraestructuras del ámbito autonómico español. En nuestro país accedieron a los sistemas de la Junta de Comunidades de Castilla-La Mancha a mediados de agosto.

Hasta ahora Panzer se ha prodigado con víctimas de sectores muy dispares, que van más allá de las administraciones públicas, como la consultoría estratégica, las entidades financieras, la manufactura, las telco, la automoción, la construcción o la educación. 

Desde Escudo Digital nos hemos puesto en contacto con el Gabinete de Prensa de la AEMET para verificar la veracidad del incidente, conocer si existe alguna afectación en la infraestructura o en la operatividad de sus servicios de predicción meteorológica y saber qué protocolos de contención se han activado. Actualizaremos esta información tan pronto como obtengamos una respuesta oficial por parte del organismo.

Aumentan las falsas tiendas de moda que utilizan IA y grandes descuentos para estafar

Una modelo pasea por la calle con un vestido aparentemente recién comprado. Explica ante la cámara lo bien que le queda y recomienda una tienda en la que, casualmente, hay importantes descuentos. Cuidado, no todo es lo que parece y podría ser una estafa. Y es que, pese a que la grabación parece auténtica, puede que ni la mujer ni la conversación ni el comercio existan realmente.

Las falsas tiendas de moda están aprovechando la inteligencia artificial (IA) para construir campañas cada vez más convincentes en redes sociales. ESET ha alertado de la evolución de estas estafas, en las que los delincuentes combinan vídeos generados artificialmente, anuncios atractivos y páginas de comercio electrónico diseñadas para parecer negocios legítimos.

Los vídeos falsos son cada vez más difíciles de detectar

Hace unos meses todavía podían encontrarse pistas evidentes en muchas grabaciones creadas mediante IA. Extremidades deformadas, problemas de sincronización entre labios y voz o marcas de agua permitían detectar que algo no encajaba.

Ahora esos fallos resultan menos frecuentes. Algunas campañas muestran supuestas entrevistas callejeras en las que una persona pregunta a otra dónde ha comprado su ropa. Otras presentan directamente a una mujer hablando de un vestido que acaba de adquirir.

Facebook e Instagram pueden identificar determinadas publicaciones como contenido generado mediante inteligencia artificial, pero esa indicación no siempre aparece inmediatamente. Durante ese intervalo, un usuario puede interpretar el vídeo como una recomendación realizada por una persona real.

El objetivo final es conseguir un clic y trasladar al potencial comprador desde la red social hasta una falsa tienda.

Grandes descuentos para acelerar la compra

Una vez dentro, el usuario encuentra una web visualmente cuidada, con fotografías de productos, catálogos completos y rebajas llamativas.

El precio desempeña un papel fundamental: presentar una prenda como una oportunidad excepcional busca reducir el tiempo que el comprador dedica a comprobar quién está detrás del comercio.

Las páginas pueden incorporar también opiniones de supuestos clientes satisfechos. Estas reseñas aportan una apariencia adicional de confianza, aunque hayan sido inventadas.

Una comprobación externa puede revelar el engaño. Las tiendas recién creadas normalmente carecen de un historial independiente de opiniones o referencias. Esa ausencia resulta especialmente sospechosa cuando la página asegura llevar tiempo funcionando o presenta una elevada cantidad de compradores satisfechos.

El peligro no se limita a pagar por una prenda que nunca llegará. Los datos de la tarjeta introducidos durante la compra también pueden terminar utilizándose para realizar cargos fraudulentos.

Tener HTTPS no significa que la tienda sea legítima

Una web fraudulenta puede disponer perfectamente de certificado de seguridad. El conocido candado del navegador indica que la comunicación entre el dispositivo y el servidor está cifrada, pero no demuestra que detrás exista una empresa fiable.

Por ello, resulta útil comprobar cuándo se ha emitido el certificado. En algunas de las páginas investigadas se observan certificados obtenidos apenas un mes antes y con una vigencia de tres meses. Una antigüedad tan reducida, combinada con otras señales, debería despertar cautela.

Algo parecido sucede con el dominio. Diversas webs vinculadas a estas campañas han sido registradas recientemente y algunas comparten rangos de direcciones IP con páginas relacionadas con fraudes similares.

Dirección, NIF y razón social pueden descubrir el engaño

Los ciberdelincuentes también han mejorado la apariencia legal de sus tiendas. Es habitual encontrar apartados de contacto, condiciones de compra y políticas de privacidad, elementos que pueden transmitir una falsa sensación de normalidad.

El contenido, sin embargo, puede esconder inconsistencias. Algunos textos legales son documentos genéricos reutilizados que no identifican correctamente al responsable del tratamiento de los datos.

En otros casos aparece un teléfono o un nombre, pero faltan elementos básicos como una razón social verificable o un NIF válido.

La dirección física constituye otra pista. Introducirla en un servicio de mapas permite comprobar si realmente corresponde a un comercio o si conduce a una vivienda, un lugar sin relación con la empresa o incluso una ubicación inexistente.

Las campañas cambian según el tipo de víctima

La infraestructura descubierta apunta además a un fenómeno que puede ir mucho más allá de una única tienda. Dentro de rangos técnicos relacionados se han identificado otras páginas de comercio electrónico, algunas ya señaladas como potencialmente maliciosas y vinculadas a ofertas de ropa sospechosamente baratas.

Los responsables pueden modificar rápidamente nombres, dominios, productos y anuncios. También adaptan el perfil de las personas que aparecen en los vídeos al público al que quieren dirigirse. Una campaña puede centrarse en mujeres de determinada edad y la siguiente utilizar la misma estrategia con un grupo completamente diferente.

La inteligencia artificial complica así una de las recomendaciones tradicionales contra el fraude: confiar en lo que vemos. Una fotografía impecable, una persona aparentemente real y una tienda profesional ya no constituyen garantías suficientes. Antes de introducir los datos de una tarjeta conviene buscar referencias independientes, comprobar la antigüedad del dominio, revisar los datos societarios y verificar la dirección.

IDScan confirma una brecha tras la aparición de cientos de millones de carnés de conducir en la dark web

IDScan ha confirmado que un tercero no autorizado pudo acceder y copiar información almacenada en su plataforma, después de que apareciera en un mercado de la dark web una gigantesca base de datos con unos 153 millones de escaneos de permisos de conducir de EE.UU. y Canadá.

La compañía es un proveedor de tecnología de verificación de identidad. Su plataforma permite a empresas y organizaciones escanear carnés de conducir, documentos de identidad y pasaportes, comprobar su autenticidad y utilizar esos datos para verificar quién es una persona. Sus soluciones se emplean en sectores como la banca, la automoción, el transporte, los casinos, el comercio y los establecimientos que necesitan comprobar la edad de sus clientes.

IDScan tuvo conocimiento del acceso no autorizado alrededor del 1 de septiembre y ha puesto en marcha una investigación para determinar el alcance de lo ocurrido. La firma todavía no ha confirmado que los más de 150 millones de carnets ofrecidos en la dark web procedan íntegramente de sus sistemas ni ha precisado cuántas personas se han visto afectadas.

La base de datos incluye también alrededor de 10 millones de documentos nacionales de identidad, más de tres millones de identificaciones internacionales y unos 579.000 documentos médicos. Parte de esta información habría sido puesta a la venta en Nexus, un mercado clandestino relacionado con la ciberdelincuencia.

El periodista especializado en seguridad Brian Krebs fue quien descubrió la oferta y pudo comprobar la autenticidad de algunos registros. Entre ellos, curiosamente, se encontraba su propio permiso de conducir. Posteriormente, las evidencias apuntaron hacia IDScan como posible origen de la información.

La confirmación de la compañía supone un paso importante respecto a las primeras informaciones sobre el caso, puesto que ya no se trata únicamente de una base de datos de origen desconocido localizada en la dark web, sino de un acceso no autorizado reconocido por el proveedor que almacena y procesa este tipo de documentación.

Aún quedan detalles por conocer

El FBI también investiga el incidente. La compañía de identidad, por su parte, asegura que está colaborando con las autoridades y ha anunciado servicios gratuitos de protección frente al robo de identidad y monitorización crediticia para las personas potencialmente afectadas.

Quedan por determinar cuestiones clave como la vía utilizada para acceder a los sistemas, el volumen real de información sustraída y el número de personas total cuyos documentos han terminado en manos de los ciberdelincuentes.

Alerta en Google Play al multiplicarse las apps que prometen dinero y bloquean al usuario justo antes de cobrar

Ganar dinero jugando con el móvil o completando pequeñas tareas parece algo sencillo a la par que lucrativo. Pero, ¿en realidad el usuario obtiene finalmente estas ganancias? Estas apps engañosas no dejan de multiplicarse en Google Play.

Una investigación de Bitdefender ha analizado miles de aplicaciones disponibles mediante Early Access de Google Play y ha localizado numerosas apps engañosas. Entre ellas aparecen juegos de casino, sistemas de recompensas, lectores de PDF, escáneres QR, localizadores de teléfonos y aplicaciones que recurren a nombres de franquicias muy conocidas.

Recompensas que crecen rápidamente hasta que intentas cobrar

Uno de los comportamientos más llamativos afecta a las aplicaciones que prometen premios económicos. Al principio, el usuario obtiene recompensas virtuales con relativa facilidad, lo que genera la impresión de que alcanzar la cantidad mínima exigida para retirar el dinero será sencillo.

El funcionamiento cambia cuando la cuenta se aproxima a ese límite. El progreso se ralentiza o directamente queda bloqueado, de modo que resulta imposible alcanzar la cantidad necesaria para solicitar el pago.

Mientras tanto, la publicidad continúa apareciendo. Precisamente ahí se encuentra el negocio: conseguir que la persona permanezca utilizando la aplicación y visualice cuantos más anuncios mejor.

Los investigadores también localizaron aplicaciones que imitan la apariencia de juegos de casino, con tragaperras o puzles que prometen multiplicar el dinero depositado. Entre las temáticas detectadas figuran versiones de Chicken Road e Ice Fishing.

Una falsa aplicación de GTA V superó el millón de descargas

Al menos dos aplicaciones han llegado a publicarse bajo el nombre “Grand Theft Auto V (Early Access)”. Tras ser indexadas por Google, posteriormente cambiaron de denominación. Así de rápido.

Uno de los casos resulta especialmente significativo. Y es que, la aplicación consiguió superar el millón de descargas pese a no disponer de ninguna reseña pública. Además, las imágenes utilizadas para promocionarla presentaban indicios de haber sido creadas mediante inteligencia artificial.

Early Access tiene una particularidad concreta. Las valoraciones y opiniones públicas están desactivadas para impedir que los errores propios de una aplicación todavía en desarrollo se traduzcan en puntuaciones negativas permanentes. Esta característica legítima puede eliminar, al mismo tiempo, una referencia muy utilizada por los usuarios antes de instalar una aplicación: las experiencias de otras personas.

Deepfakes de famosos utilizados como reclamo

La estrategia comienza incluso antes de entrar en Google Play. La investigación ha identificado anuncios difundidos a través de TikTok y Facebook que utilizan deepfakes creados con inteligencia artificial de deportistas y personajes famosos. Estos contenidos promocionales presentan ofertas de dinero fácil o tiradas gratuitas para dirigir a las víctimas hacia determinadas aplicaciones.

También se ha observado una reutilización constante del mismo software. Aplicaciones presentadas como lectores de PDF o escáneres de códigos QR pueden ser prácticamente idénticas pese a publicarse con nombres diferentes y desde cuentas de desarrollador aparentemente distintas.

Las aplicaciones desaparecen pero vuelven con otro nombre

En algunos casos, cuando una de estas aplicaciones desaparece, otra puede ocupar rápidamente su lugar, complicando, claro está, su seguimiento. No existe, además, una única categoría que permita reconocerlas inmediatamente.

La investigación recalca un aspecto importante: no se ha identificado malware en estas aplicaciones ni se ha atribuido la actividad a un grupo concreto. Su finalidad es fundamentalmente económica y está basada en generar ingresos mediante la exposición continuada de publicidad. 

Y ojo, tampoco se trata de una vulnerabilidad técnica de Google Play. No se habría explotado ningún fallo de seguridad de la plataforma. El problema reside en desarrolladores que aprovechan las características con las que funciona Early Access para publicar aplicaciones engañosas.

Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits – CYBERDEFENSA.MX

AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination.

The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of these stories are clever. Most are just easy.

Here’s what mattered this week.

⚡ Threat of the Week

OpenAI Agents Behind May 2026 Attack on RubyGems — The «major malicious attack» that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to researchers. The event was driven by a cluster of OpenAI agents that engaged in en masse publication of thousands of packages to RubyGems in May and June 2026. «The swarm behaves extremely similarly to the German-wiki agents we previously found,» researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx said. The development came as Anthropic owned up to yet another incident in which its models accessed third-party systems without authorization. The new AI trespass dates back to January 2026. It involved an early version of Claude Opus 4.6 that was given a Capture the Flag (CTF) challenge. «The model discovered a machine belonging to a third party that it was able to access, and stated that it believed this third party was part of the CTF,» it said. «Inside the machine, the model found a file listing a password, which it used to gain admin access to the system.» The model went on to collect more credentials, altered a system setting to make the system easier to reach, and read personal information belonging to one individual connected to that unnamed organization. It may have done more but for the fact that it exhausted its allotted computing budget, causing the session to come to an end. Many incidents involving agents from frontier AI labs acting against their programming to escape restrictions in pursuit of their goals have heightened concerns over the increasing capacity of AI models and developers’ ability to contain them. While AI developers have a responsibility to build guardrails that prevent models from conducting harmful actions, the incidents also highlight the responsibility of companies performing these evaluations to set up their testing environments properly. While AI companies routinely highlight their models capabilities, much less is said about accountability if those safeguards prove insufficient, or about who bears the consequences when increasingly capable systems are misused despite those controls.

🔔 Top News

  • Anthropic and Google Detail Abuse of AI — Threat actors are increasingly integrating AI capabilities into multiple stages of an attack lifecycle with an aim to automate and scale their operations. «Over the past quarter, threat actors have moved beyond simple prompt-based LLM interactions to integrate AI capabilities into multiple stages of an attack lifecycle,» Google Threat Intelligence Group (GTIG) said. «While traditional script-based automation has long been a staple of threat actor operations, groups are increasingly upgrading these workflows, creating highly autonomous systems capable of reasoning through complex tasks and making dynamic decisions without the need for human oversight.» GTIG said it «has not yet observed threat actors deploying fully autonomous pipelines against targets in the wild,» with the adversarial adoption of agentic AI signaling «a gradual maturation of tradecraft,» as adversaries employ commercial and open-weight models to turn public disclosures and patch delays into working N-day exploit code, refining their tooling, and progressing «toward constructing functional, multi-stage exploit chains.»
  • Threat Actors Exploit New Vulnerability Chain — Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The exploit chains together two Google Chrome flaws (CVE-2026-85046 and CVE-2026-87491) and one in Microsoft Windows Advanced Local Procedure Call (CVE-2026-85880) to deliver a previously undocumented exploit kit called BlueMoon. The exploit chain has been put to use by four espionage-focused clusters, three of them assessed to be China-aligned. Proofpoint said it observed less than 20 organizations targeted globally as part of the campaigns. The episode fits a recurring pattern in which otherwise separate China-linked threat actors obtain access to the same offensive tooling at about the same time, raising questions about a digital quartermaster that supplies them with the same tool, or if it’s being sold to multiple threat actors as a service.
  • Disgruntled Researcher Drops New Microsoft Defender PoC — The disgruntled security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. ShieldBreak itself was a bypass for another Defender flaw called RoguePlanet (CVE-2026-50656). The release of this new zero-day is the latest in a long back-and-forth between the security researcher and the software giant over the company’s alleged handling of their bug reports. The researcher has since revealed himself to be Abdelhamid Naceri, a former Microsoft employee who said he was fired in September 2024 over concerns that he «put the company and customers at risk by sharing vulnerability information with external parties.» Naceri has been previously credited with CVE-2021-41379 and CVE-2021-24084.
  • Xinbi Guarantee Goes Down in Law Enforcement Action — The U.S. Department of Justice (DoJ) announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime syndicates. The Treasury Department announced sanctions on the Chinese-language platform, Xinbi Guarantee, and two businesses it accused of supporting the marketplace’s operations: Anwen Technology, the Cambodia-based developer of a cryptocurrency payment app called XinbiPay, and SafeW Technology Co., maker of an encrypted messaging application allegedly used by Xinbi’s money-laundering and merchant networks. «Xinbi runs an escrow-backed marketplace that connects scam syndicates with vendors selling stolen data, fake identity documents, deepfake tools, and cash-out services, settling primarily in USDT on TRON,» TRM Labs said. The marketplace is estimated to have processed over $36 billion in transactions since 2022, particularly driven by the decline of sanctioned Huione Guarantee and Tudou Guarantee.
  • Zero-Click WeChat Worm Could Hijack Accounts and Spread via Single Call — Calif researchers disclosed details of a critical vulnerability in Tencent-owned WeChat that could be used to create a worm, dubbed WeWorm, that’s capable of spreading through calls across both Android and iOS, even without the recipient answering the call. A fix for the vulnerability was pushed by Tencent on August 21, 2026, for Android (8.0.77) and iOS (8.0.76). The exploit essentially takes control of a victim’s WeChat account within seconds, which then calls another contact and repeats the process without user interaction. Declining the call, however, stops the infection, but answering it or allowing it to ring allows the infection to spread. «Exploitation takes only seconds, and gives us full control of the WeChat account,» Calif said. «We can read and send messages, make calls, and act on the victim’s behalf.» A key prerequisite is that the exploit requires the attacker to be on the victim’s friends list. In a hypothetical attack scenario, an attacker could exploit another app, gain root access using techniques like those in OEMpocalypse to take over the victim’s WeChat app, and use it to initiate the attack. There is no evidence the WeChat flaw was exploited in the wild.
  • Google Play Early Access Becomes a Security Blind Spot — Bad actors are misusing Google Play’s Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. «The same feature that shields developers from unfair criticism also strips users of the earliest warning that an app cannot be trusted,» Bitdefender said. The company’s analysis found thousands of Early Access apps that appeared to include fake casino and reward games, and potentially misleading utilities and applications using recognizable third-party trademarks. Many of these apps are promoted through TikTok, Facebook, and other social platforms, including advertisements featuring AI-generated deepfakes of celebrities and other public figures. Some of these apps have been found to seek unusual permissions (e.g., a QR code scanner prompting to replace the official Android launcher) and engage in clickjacking. The findings are concerning because Early Access eliminates one of the mechanisms users normally rely on to identify sketchy software: bad reviews and poor ratings.
  • Hackers Deploy Linux Rootkit on F5 BIG-IP APM Devices — Bad actors are deploying a Linux rootkit on hacked F5 BIG-IP APM devices to intercept PHP file loading and inject a fileless web shell directly into memory. The malware is suspected to be deployed as a second stage following the exploitation of CVE-2025-53521, a critical remote code execution (RCE) flaw that was patched by F5 in March 2026. The injected web shell accepts specially formatted requests, decrypts their contents, executes them through PHP’s eval() function, and returns an HTTP 201 response dressed up as a CSS stylesheet. ESET is tracking the same malware as PoisonedRefresh.
  • Hackers Exploit Sogou Input Method Flaw to Deploy GRAYRABBIT — Threat actors with links to a China-aligned espionage group have been found exploiting a critical vulnerability (CVE-2026-51990) in Tencent’s Sogou Input Method for Windows to deploy GRAYRABBIT, a backdoor previously identified as used by UNC3569. «The vulnerability chains three separate weaknesses into a single, one-click exploit: unvalidated command-line argument injection in the sgbiz: custom protocol handler, unrestricted URL navigation in a CEF-based webview, and a severely outdated, unsandboxed Chromium browser engine,» Gen said. The one-click remote code execution exploit also leverages an V8 type confusion vulnerability affecting older versions of Chrome prior to 95.0.4638.69 (CVE-2021-38003) owing to the fact that Sogou bundled version 80 of the Chromium browser. Tencent fixed the flaw in April 2026.

‎️‍🔥 Trending CVEs

Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.

Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-85880, CVE-2026-81963 (Microsoft Windows), CVE-2026-85706 (GitLab), CVE-2026-44756, CVE-2026-58240 (SAP), CVE-2026-76578 (FreeIPA), CVE-2026-84282 (Ascensio System SIA ONLYOFFICE ownCloud integration plugin), CVE-2026-67401 (cPanel and WHM), CVE-2026-82533 (DeepSeek Harness), CVE-2026-10090 (Red Hat Advanced Cluster Management for Kubernetes), CVE-2026-18667 (Tenable Sensor Proxy), CVE-2026-20293, CVE-2026-33197, CVE-2026-6485 (UEFI Shell), CVE-2025-20701 (Skullcandy Dime 3), CVE-2026-84390, CVE-2026-84388, CVE-2026-26084, CVE-2026-84393 (Fortinet), CVE-2026-12647, CVE-2026-12645, CVE-2026-12646, CVE-2026-12650, CVE-2026-12744, CVE-2026-12745 (Ivanti), CVE-2026-78546, CVE-2026-78547 (Citrix), CVE-2026-85102, CVE-2026-85103 (Check Point), CVE-2026-51990 (Tencent Sogou Input Method), CVE-2026-42016, CVE-2026-42018, CVE-2026-82329 (JFrog Artifactory), CVE-2026-84286 (ExLlamaV3), CVE-2026-61578, CVE-2026-61582, CVE-2026-61583, CVE-2026-61584, CVE-2026-61585, CVE-2026-61587, CVE-2026-61600, CVE-2026-61601, CVE-2026-61602, CVE-2026-70647, CVE-2026-70648 (Chamilo), and a local privilege escalation vulnerability in AOMEI Backupper amwrtdrv.sys driver.

🎥 Cybersecurity Webinars

  • Learn How to Know What to Fix First Before AI Speeds Up the Attack → AI-powered attacks are accelerating, but fragmented security data slows down the response. Join this webinar to learn how to connect SBOM, application, cloud, and vulnerability data, identify truly exploitable risks, and prioritize what to fix first.
  • How to Identify Which CVEs Are Truly Exploitable Within Hours → AI can turn newly disclosed vulnerabilities into working attacks within hours. Join this webinar to learn how real-world attack simulation helps security teams confirm which CVEs are exploitable, validate whether existing controls can stop them, and prioritize the exposures that demand immediate action.

📰 Around the Cyber World

  • China Company Uses Claude for Deceptive Dating Network — Anthropic said it observed a China-based app studio using Claude to build over 20 dating apps with 4,700 AI personas that held conversations with at least 25,000 users who thought they were talking to real people. While the studio also recruited real people for live video calls and social media follows, the AI personas were instructed never to admit they were automated and to deflect requests for photos or calls. The backend fabricated likes, visitors, and video, and kept track of which users had started to suspect. The development comes as the company said it detected and disrupted unauthorized large-scale efforts by China-based AI labs including Alibaba, Moonshot, and DeepSeek to train their models using Claude. Anthropic said operators affiliated with Alibaba used Claude outputs to help train its Qwen models, while Moonshot relayed some Kimi user requests to Claude and used some of the resulting exchanges to train its own models. China dismissed the U.S. allegations as «groundless.»
  • Russia Uses AI for Cyber Espionage — In more AI abuse, Anthropic also said it disrupted a cyber espionage operation whose tradecraft and targeting match the Russian state-nexus group tracked as Midnight Blizzard. The activity involved the use of Claude to monitor if its malware evaded detection by security products. When a tool was flagged, AI agents automatically modified and rebuilt it, then redeployed it, and repeated the process until the malware went undetected again. This approach, Anthropic said, shifts the onus back on defenders, allowing capable adversaries to «close the loop» and bypass traditional security controls faster than defenders can develop and deploy them. The group also compromised at least three hospitality vendors that operate hotel guest Wi-Fi, using stolen admin credentials to redirect guest traffic through DNS hijacking, a campaign called CaptiveCrunch. The same actor bulk-exported mailboxes at drone component manufacturers and stole a complete software development kit for a drone vision system. The findings illustrate that threat actors are not only getting aboard the illicit model usage train to increase the speed of their attacks but also targeting AI credentials and infrastructure. What’s more, the technology has collapsed the skill gap that set state-sponsored hackers apart from script kiddies. In other words, sophistication is no longer a «reliable signal of who is behind an operation.» Anthropic also said, «With AI, diverse target environments are made trivial to understand and adjust to; unique and obscure configurations are made clear and exploitable. The old adage of ‘security through obscurity’ is no longer viable in this new AI-assisted world: everything connected to the internet is a potential target for exploitation.» Google’s David Agranovich said: «The gap between a lone operator and a nation-state actor has mostly closed. Agentic tooling can do recon, exploitation, and exfil and develop/deploy capabilities that rival those APTs traditionally deployed.»
  • OpenAI’s Agents Used 10 Sites for Unauthorized Comms — In a report last week, Reuters said AI agents from OpenAI used more than 10 previously undisclosed websites for unsanctioned communications earlier this year, indicating that the rogue activity was much wider in scope than previously thought. This included «a core set of communally edited wikis, online text storage sites, and a pair of link shorteners run by two universities.»
  • Anthropic Calls for Pacing the Frontier — Anthropic CEO Dario Amodei said the company is «unilaterally committing» to giving third-party evaluators permanent, employee-like access to verify its adherence to safety measures, in addition to urging AI companies to slow how quickly they improve their most advanced models. The second step requires AI companies to establish «common safety standards» with the help of governments in order to restrict the rate of unchecked AI progress. The final measure would have the U.S. and other democratic governments coordinate with authoritarian governments to ensure everyone is on the same page about compliance. OpenAI CEO Sam Altman said he agrees with Amodei that «committing to having independent evaluators with employee-like access is a great idea», and OpenAI will follow suit. Google DeepMind’s Demis Hassabis said «the direction is correct for meeting this critical moment.»
  • Ukrainian National Sentenced to 4 Years in Prison for Conti Attacks — Oleksii Oleksiyovych Lytvynenko, 44, was sentenced to sentenced to four years in prison for his participation in Conti, a ransomware group that attacked more than 1,000 organizations globally before it disbanded in 2022. Lytvynenko pleaded guilty in June 2026. «Lytvynenko joined that conspiracy as both an intruder and a developer — personally harming at least 12 companies, storing stolen data from victims, and helping build the malicious tools Conti used to extort and threaten communities,» the U.S. Justice Department said. «Even after the Conti conspiracy ended, he continued engaging in active ransomware operations until his arrest.»
  • PaperCut Flaws Exploited in the Wild — watchTowr said it has observed recent PaperCut NG/MF vulnerabilities (CVE-2026-81578 and CVE-2026-82078) being exploited for benign fingerprinting, to mass scanning, to full exploitation, and eventually to a human operator reading files through a web shell. «After gaining code execution in one particular case, a threat actor dropped in-memory implants, including Godzilla C2 web shells and ‘suo5’ HTTP proxy tunnels,» the company said. «Both were deployed as servlet filters, designed to intercept inbound HTTP requests and operate entirely out of memory with nothing written to disk, persisting until the PaperCut service is restarted. Eighteen seconds after the second wave was deployed on our PaperCut instance, a new and separate IP address began interacting with the deployed Godzilla web shell, using the correct AES key and password.»
  • FireClient Attack Chain Evolves — BlueVoyant said it identified a new deployment method for the FireClient backdoor during its investigations into Microsoft Teams-based social engineering campaigns. «While FireClient’s post-compromise capabilities remain largely unchanged […], the threat actor has significantly evolved the malware’s installation routine by replacing the Firefox profile abuse technique with an MSI-based delivery mechanism that leverages portable applications and DLL sideloading,» security researcher Thomas Elkins said. «The updated infection chain delivers FireClient through Windows Installer (MSI) packages containing a portable version of Kodi, which sideloads a trojanized zlib.dll to execute the FireClient loader. Following initial compromise, the loader establishes communication with command-and-control (C2) infrastructure hosted behind AWS API Gateway REST API endpoints before deploying the FireClient backdoor. Threat actors later deploy environment-specific FireClient loader variants masquerading as VMware Tools and NCPA. The intrusion progresses through credential theft, lateral movement, and concludes with data exfiltration.»
  • Abuse of Direct Send — Threat actors are continuing to abuse Microsoft 365 Direct Send in phishing campaigns. «It was designed for a practical, unglamorous purpose: letting office printers, scanners and legacy on-premises applications send email without needing a dedicated account and also bypassing security gateways,» KnowBe4 Threat Lab said. «Attackers have found that this path works just as well for them. By connecting to that same open endpoint, they can send an email claiming to be from anyone at your organization’s HR, accounting, admin or your CEO. The email arrives looking like it came from an internal address, because technically, it entered through your own infrastructure.» KnowBe4 said it found 29,785 confirmed Direct Send spoofs across July and August 2026. Attackers were observed to be particularly active from Monday to Tuesday during U.S. Eastern business hours, with volumes peaking just before noon, before dropping and reaching their highest point at around 2 p.m. EST.
  • Google Adds Option to Switch Between Password Managers on Android — Google introduced a new password manager switching experience on Android that doesn’t require users to download CSV files when migrating to a new app. «Historically, moving your passwords meant downloading them into an unencrypted text file, which left them unprotected on your device,» Google said. «And passkeys couldn’t be transferred at all, so you’d have to recreate them across multiple sites and apps. Now, moving your passwords and passkeys to a new password manager is simpler and safer.» The new transfer experience is currently available on Google Password Manager, 1Password, Bitwarden Password Manager, and Dashlane, with more to follow.
  • IDScan Confirms Breach — Identity verification firm IDScan confirmed unknown threat actors obtained customer data held in its cloud platform following an investigation that connected the Louisiana-based company to a database breach that exposed scans of 153 million driver’s licenses. «IDScan.net has determined that an unauthorized third party may have accessed and/or copied certain customer information stored within their accounts on the IDScan.net cloud,» IDScan said. «The types of information contained within the affected data may include full names and driver’s license or other government-issued identification numbers.» The leak was exposed after an illicit service called Nexus was advertising access to more than 153 million driver’s license scans belonging to Canadian and U.S. citizens. The service has since gone offline.

Conclusion

That’s the week. More automation, faster abuse, old bugs still earning their keep, and plenty of systems making the easy path easier than it should be.

Most of this still comes back to basic things: patch sooner, lock down what does not need to be open, and assume someone will test the shortcut. The tools are changing. The weak spots are not.

What It Does to Your SOC – CYBERDEFENSA.MX

Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from developers running coding agents and non-technical staff signing consumer AI tools into corporate accounts.

We reviewed AI-related activity across numerous enterprise environments. Two numbers frame everything that follows. AI-related alerts still account for only 0.43% of all SOC alerts. And that share is climbing every single month, up 685% between February and June 2026. AI is a small slice of the alert stream today and the fastest-growing slice at the same time.

What makes those alerts worth a security team’s attention is not their volume but their composition. We sort everything an AI agent triggers in a SOC into three buckets: real attacks, risks, and noise, with the split being 94.1% noise, 5.8% genuine risk, and 0.02% real attacks. Meaning that across the data we investigated, real attacks that use AI agents are a drop in the ocean. The cost of AI in the SOC, so far, is not breaches. It is a rising tide of alerts that look alarming and almost never are, and a small, quiet set of genuine exposures that those alarms tend to bury.

This post walks through each of the three categories with anonymized examples. All customer names, hostnames, usernames, and identifiers have been removed; indicators are defanged.

The New Shape of the Alert Stream

AI adoption inside an enterprise is not one behavior it is two very different ones arriving at the same time.

The first is technical. Developers install coding agents that spawn shells, read credential stores, open network tunnels, download packages, and run security tooling all as legitimate work, and all of it indistinguishable to a detection engine from the early stages of an intrusion. This is the loud half, and it dominates the data.

The second is when employees grant OAuth consent to third-party AI applications, share information, and paste documents into generative-AI tools. This is the quiet half. It rarely trips an endpoint detection, but it is where data leaves the building.

Both halves land in the same place, the SOC, and both look, at first glance, like something to worry about. Sorting the signal from the noise is the entire job.

By the Numbers

AI accounts for a small share of the volume but is fast-growing**.** Of the roughly 16.9 million SOC alerts we reviewed, about 73,000 (0.43%) were AI-related. Read on its own, that is reassuringly small.

Number of AI-related alerts per month as seen in our system.

The rise is monotonic. Every full month is higher than the one before, and growth accelerated sharply in May 2026. Over the window when reporting is stable across regions (February to June), volume grew by 685%. The 0.43% figure is best understood as today’s floor, not a ceiling. A team that sizes its AI-alert handling to current volume will be under-provisioned within a quarter.

The composition is as lopsided as the trend is steep. Nearly all of the AI-generated alerts are noise.

For this research, we investigated the AI-related population and sorted each alert by the underlying activity. A real attack is a confirmed compromise. A security risk is not a compromise but a genuine exposure (for example, a coding agent running with its permission safeguards disabled). Noise is legitimate activity that tripped a detection written before AI agents existed. By that measure, nearly all of the AI-related alerts are noise (94.1%), a small portion are genuine security risks (5.8%), and real attacks are a sliver (0.02%).

The breakdown of the AI-related alerts based on the final classification of each alert.

The second measurement is how those same alerts were handled in production without a human in the loop. When an alert reaches an automated triage platform, two separate decisions are made about it.

  • The verdict states how dangerous the activity looks: it can be benign, suspicious, or malicious.
  • 79.8% received a benign verdict.
  • The response states what happens next: the alert can be suppressed (closed automatically, so no analyst ever sees it), flagged for follow-up, or escalated to a human.
  • 81.7% were automatically suppressed.

Of the AI-related population, only 5.4% were ever escalated to a human analyst; the remainder were flagged for follow-up.

A high-severity alert does not necessarily mean an actual threat. For example, a single detection at a single customer accounted for 55% of all “critical” verdict alerts flagging a Windows binary (Expand.exe) as a lateral-tool-transfer. Upon inspection, it was found that a developer’s coding agent was setting up a shell environment, and the behavior was normal for this type of work.

The lesson for any SOC is the same: severity labels on AI activity have to be read with suspicion, not taken at face value.

Category 1: Real Attacks

A real attack is an actual compromise or an attacker operation enabled by, or riding on, AI adoption. This is the category every executive asks about first, and it is the smallest, accounting for roughly 0.02% of AI-generated alerts.

When it comes to actual threats that were detected in this class of alerts, none was a compromise caused by an organization’s own AI agent. Every alert titled “AI agent running mimikatz,” “reverse shell from a coding tool,” or “credential theft” was resolved, on inspection, to a developer doing legitimate work or to a detection misfiring. We return to those in the Noise section.

What was real is an attack that rides on AI rather than through it: a live phishing campaign that weaponizes AI brand names as lures. Across multiple customers, and as we expanded to new ones during the window we studied, we observed malicious emails with AI-themed subject lines featuring the biggest names in AI. The lure works precisely because AI adoption has made these brands familiar and their notifications routine. Employees now expect email from these products, which is exactly what the attacker is counting on.

Here are some examples of incidents where we spotted the execution of tools or commands that usually indicate real attacks (or penetration testing), only in these cases they were invoked by Claude, Codex, etc. So the investigator also needs to question why the agents were running these tools and whether it was part of a real attack that exploited the agent.

  • Anthropic is used as bait in the business context. In that alert, the email subject is RE: Anthropic Engagement approval & payment, and the analysis says the sender references a supposed contract/invoice with Anthropic to make a large payment request appear legitimate. So Anthropic is not the sender or the threat source, it’s part of the pretext used to support the invoice fraud story.
  • An email uses a fake Google/Gemini Ads invitation lure to appear legitimate and trustworthy. It presents itself as a business-related workspace invitation, encouraging the recipient to connect or join what looks like an official Gemini Ads environment, but the sender and reply-to infrastructure are not associated with Google and instead rely on the suspicious domain gemini-advertisers[.]com, indicating a brand impersonation attempt designed to drive the user to a malicious site.
  • The email impersonates OpenAI (“OpenAI Partner Summit 2026”) but originates from noreply-zoomevents@zoom.us. Although the URLs use legitimate zoom.us infrastructure, the content and registration flow are being used to lend credibility to a fraudulent invitation.
Phishing email impersonating OpenAI
Device code phishing
  • The AI IDE Cursor seems to have moved from normal coding activity into unsafe low-level system actions: while likely attempting to complete a debugging or troubleshooting task, the agent used a known credential-dumping technique (MiniDump via comsvcs.dll) that can expose secrets from process memory. The parent-child chain Cursor.exe → powershell.exe → rundll32.exe, the temp .ps1 scripts, and the memory-dump commands show the IDE initiating an automated action sequence that may have been intended to help development, but did so in a way that created a serious credential-access risk on the endpoint.

The pattern across all three is worth stating plainly: the closer we looked, the more the “attack” dissolved into context. That is the defining characteristic of AI-era triage.

Category 2: Unsafe Use

About 5.8% of the AI-related alerts are the ones we think deserve the most attention. These alerts detect an unsafe use of AI tools, not necessarily a compromise (yet). It is the moment when an agent, behaving exactly as instructed and with no attacker involved, does something that materially exposes the organization or the user.

The main risk is agents running with a permission-bypass flag, the option that tells the agent to stop asking the user before it acts. Many users choose to trust the agent not to destroy their machines or execute dangerous commands, but as experience and, now, the data show us, in many cases, agents will attempt, and mostly succeed in executing commands that expose the organization and the user to great risks. It is worth noting that, especially when running the agent with the permission-bypass flag, it is recommended to use additional configurations, also known as harnesses, to programmatically prevent the agent from attempting to execute risky commands.

The split of permission-bypass flags as seen in our system.

On every sample we examined, the invocation was legitimate developer work. That is exactly why it matters. This is the same precondition abused in a publicly documented supply-chain attack, where an attacker’s malicious code executed freely because a coding agent had been launched with its permission prompts disabled. The exposure is not intent; it is that the rail is off, across many customers and at scale, waiting for the one time the code the agent is asked to run is not benign. Notably, these same permission-bypassed invocations are also the single largest source of false positives.

Other instances of unsafe use we surfaced:

  • A reverse tunnel opened by an AI IDE**:** In one of the environments, an AI code editor spawned PowerShell, which launched ngrok and opened a named reverse tunnel to the public internet using the user’s own auth token. While the intent is benign, it is a real risk and exposure.
  • An agent dumping the entire macOS keychain to read one token: To retrieve its own and cloud services’ stored credentials. An agent ran security dump-keychain > /tmp/, which writes every stored secret to a temp file, briefly exposing all of them.
  • Granting OAuth access to AI agents means that employees might share sensitive information with third-party service providers. But on top of that, it increases the risk of unauthorized data access via prompt injection or a compromised AI account. We observed multiple alerts for OAuth application consent granted to ChatGPT across tenants, “first sign-in to a new application: OpenAI” events, and, at one customer, a sizeable cluster of data-protection alerts for generative-AI uploads. Most are benign. But this is the surface where corporate data is sent to a third-party model, and it is almost invisible to endpoint tooling.

Category 3: Noise

Noise is the largest category by an order of magnitude, 94.1% of the AI-generated, and it is the one that directly determines whether a SOC drowns. Noise here is not random. It is specific and diagnosable: detections written before AI agents existed, now firing at high severity on routine agent work. This is not a new tendency in the SOC, as Sophos previously reported.

The clearest example is the AI vendors’ own software. The genuine Anthropic Claude Desktop installer, verified by its code signature, triggers major EDR rules such as “Ransomware Operations detected” and “Encoded PowerShell Download and Run” across several customers. The installer is legitimate. The detection describes installer behavior in the ransomware vocabulary.

Underneath that sit the agent-behavior false positives, all confirmed on inspection to be developers using tools as intended:

  • The update of a coding agent and the developers’ use of the agent triggered a “Ransomware Operations detected”. The binary that triggered the alert is a legitimate, signed software package. The behavior that looked “ransomware-like” came from normal Electron/Squirrel installer activity and developer tool usage.
Claude Setup.exe
Path: \Device\HarddiskVolume3\Users\{REDACTED}\Downloads\Claude Setup.exe
CMD: "C:\Users\{REDACTED}\Downloads\Claude Setup.exe"

Update.exe
Path: \Device\HarddiskVolume3\Users\{REDACTED}\AppData\Local\SquirrelTemp\Update.exe
CMD: --install .
Parent: Claude Setup.exe
Parent Path: \Device\HarddiskVolume3\Users\{REDACTED}\Downloads\Claude Setup.exe
Parent CMD: "C:\Users\{REDACTED}\Downloads\Claude Setup.exe"

squirrel.exe
Path: \Device\HarddiskVolume3\Users\{REDACTED}\AppData\Local\AnthropicClaude\app-1.1.1093\squirrel.exe
CMD: --updateSelf=C:\Users\{REDACTED}\AppData\Local\SquirrelTemp\Update.exe
Parent: Update.exe
Parent Path: \Device\HarddiskVolume3\Users\{REDACTED}\AppData\Local\SquirrelTemp\Update.exe
Parent CMD: --install .
  • A process originating from node.exe executing the OpenAI Codex CLI agent with –yolo or –dangerously-skip-permissions tripping ClickFix, DisableTools, and DLL-injection detections.
  • codex.exe
    Path: C:\Users\{REDACTED}\AppData\Roaming\...\bin\codex.exe
    CMD: codex.exe --yolo
    Parent: node.exe
    Parent Path: \...\Program Files\nodejs\node.exe
    Parent CMD: "node" "C:\Users\{REDACTED}\AppData\Roaming\...\codex\bin\codex.js" --yolo
  • Standard developer automation triggered “PowerShell created possible reverse TCP shell” detections. The process tree is consistent with normal developer automation rather than a real reverse shell. The parent process shows a signed OpenAI Codex sandbox binary that spawned powershell.exe, which in turn launched cmd.exe, python.exe, and conhost.exe. The PowerShell command is in clear text and shows benign orchestration logic: it checks ports on localhost on 127.0.0.1, selects an available port, starts a Python script from the project directory, and writes stdout and stderr to local log files in the artifacts directory.
  • The false-positive rates are the story. Across the noisiest AI activity detections, the benign share ranges from 77% to 99%. Several detections are wrong on the AI-generated more than four times out of five:

    View of the detection that was triggered on benign AI-related behavior.

    The one exception proves the rule. The ClickFix detection is the single cluster that leans genuinely severe, only 37% benign, and it does so precisely because it collides with the permission-bypass risk from the previous section: it fires on coding agents launched with –yolo. Even the “real-looking” noise traces back to legitimate AI use.

    What Security Teams Should Do

    From our analysis, the first step for every SOC is clear: tune the noisiest legacy detections, the ones firing at high severity on routine agent work. Next, define policies on what information can be shared with third-party AI platforms (as with any third-party platform) and, based on those policies, proactively hunt for permission-bypass flags, unauthorized tunnels, and risky OAuth grants rather than waiting to be alerted.

    The second step is harder, because it touches how triage itself works. AI tools execute commands on the user’s machine, with the user’s credentials, essentially acting on the user’s behalf. Alerts are therefore triggered by actions attributed to the user, and in many cases the user was not aware those actions took place. Before AI, suspicious activity executed on a user’s machine without their knowledge usually indicated a high probability that an attacker had taken over the machine. Now SOC teams face a new layer of complexity: first determine whether the action in question was executed by an AI agent or tool.

    To separate the user’s context from the agent’s, and to keep the agent away from credentials and sensitive information it should not have, we suggest running AI tools in an isolated environment with restricted access, such as a Docker container or a virtual machine. Isolation limits what the agent can reach, and it makes the agent’s behavior easier to distinguish from the user’s own activity.

    What This Means for the SOC

    Pulling the three categories together, the operational reality of enterprise AI adoption looks like this:

    • Real attacks (0.02%): none of the confirmed attacks we investigated were carried out by an organization’s own agents. The genuine attack activity we found rides on AI adoption from the outside, phishing lures built on brand names employees now trust, not on the agents themselves.
    • Security risks (5.8%): real, standing, and largely invisible to alerting. Agents run with their permission safeguards disabled, open tunnels to the public internet, over-expose stored secrets, and send corporate data to third-party models. None of this is an incident, and all of it is exposure.
    • Noise (94.1%): the dominant cost. The single highest-value action available to most SOCs today is not a new detection. It is tuning the legacy ones so that a developer running a coding agent does not generate a maximum-severity alert.

    The uncomfortable synthesis is that AI adoption has not, so far, brought a wave of AI-enabled breaches. It has brought a wave of alerts, small as a share of total volume today, that have grown 18-fold in six months and are overwhelmingly false, alongside a smaller, quieter set of genuine exposures that the alerts tend to bury. A SOC that treats every agent action as a potential intrusion will exhaust itself on false positives and, in doing so, will be less likely to notice the ngrok tunnel or the keychain dump that actually matters.

    The work ahead is therefore less about detecting AI attacks and more about teaching detection engines what normal AI behavior looks like before the volume that is doubling and tripling month over month makes that work unavoidable. Understanding this distinction is what separates a SOC that scales with AI adoption from one that is buried by it.

    About Intezer

    Intezer is an autonomous AI SOC platform built to solve exactly the problem this data illustrates: the growing gap between alert volume and analyst capacity. Rather than tuning individual detections one at a time, Intezer investigates every alert automatically, applying forensic-level analysis to determine what’s actually happening on an endpoint or in an email, then delivers a verdict a human can trust. That means 100% alert coverage — including the AI-related noise — without the SOC drowning in it.

    If you’re seeing the same shift in your own alert stream, visit intezer.com to see how Intezer’s platform handles it.

    Note: This article has been expertly written and contributed by Nicole Fishbein. Senior Security Researcher and Malware Analyst at Intezer.

    Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

    Claude Used to Automate Exploitation and Data Theft Across Multiple Victims – CYBERDEFENSA.MX

    Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026.

    The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals.

    «The cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators,» Anthropic said. «The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing reconnaissance, exploitation, and data exfiltration.»

    Among the notable cases highlighted by Anthropic is the development of an AI-assisted workflow by a Russian state-sponsored threat actor it calls GTG-20006, which shares tactical and tradecraft overlaps with a Russian advanced persistent threat (APT) group tracked as Midnight Blizzard (aka APT29 and Cozy Bear). Some of the other AI-enabled cyber campaigns highlighted by Anthropic in its 154-page report include –

    • GTG-50014 (aka MeowSHA, frkoo, and blazespider), a French-speaking operator and a suspected affiliate of the ShinyHunters collective that ran a distributed credential-harvesting pipeline across a fleet of 10 AWS EC2 workers that mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, scanned them for hard-coded secrets using TruffleHog, and sent verified findings to a Telegram group.
    • Another ShinyHunters affiliate that specialized in supply chain theft by compromising software-as-a-service (SaaS) vendors to steal data belonging to downstream customers, accelerate reconnaissance, and enable data exfiltration.
    • GTG-10007, a Chinese-speaking operator likely based out of Hunan province, some of whom have been identified as undergraduate students at a Chinese university and have used Claude to conduct intrusion attempts against production systems, reconnaissance of foreign-government networks across the Middle East, Europe, and Southeast Asia, a vulnerability-research and exploit development effort against major endpoint-security products, and develop an intelligence-collection platform for bulk-harvesting of open-source material aligned with Beijing’s priorities. The threat actor targeted about 50 organizations across education, retail, energy, technology, healthcare, finance, manufacturing, and government sectors globally. The group also maintained an autonomous vulnerability research program to produce working exploits for previously unknown vulnerabilities in network and security appliances.
    • GTG-50021, a Russian and Ukrainian-speaking group that ran a fraudulent AI reseller operation offering cheap Claude access, only for customers’ traffic to be silently proxied to a different AI model, while the illicit scheme installed a credential harvester to siphon their Anthropic account credentials and sell them to other proxy resellers for malicious use.
    • GTG-50020, a Russian-speaking, financially-motivated actor that has historically targeted hotel booking and financial technology platforms but has since focused on the AI supply chain by stealing model provider API keys and unsuccessfully attempting to gain access to pre-release AI models. The threat actor is estimated to have targeted about 30 AI vendors in a four-day window using similar techniques.
    • GTG-50029, a single French-speaking actor that used Claude to target European political parties, media, think-tanks, and the SaaS providers used by these organizations, including by exploiting a previously undocumented WordPress re-installation race condition that made it possible to create a rogue administrator account without valid credentials, as well as by abusing an exposed search endpoint to breach a political campaign management platform and siphon sensitive data. The threat actor has also been observed deploying web shells and a browser exploitation C2 framework against other targets. Central to the attacker’s operation was a purpose-built doxxing platform named «fafsearch» that offered the ability to cross-reference individual breach dumps against exfiltrated data.

    «At one end, actors used Claude conversationally: it acted as an engineering assistant in the creation of malware, phishing kits, and surveillance tooling,» Anthropic said. «Further along the spectrum, threat actors directed Claude to execute operations (such as running commands against victim networks, harvesting credentials, and exfiltrating data) with a human making each individual targeting decision (GTG-20006).»

    Cybersecurity

    «At the far end, operations ran autonomously, with minimal human input or supervision: these included multi-agent frameworks conducting reconnaissance, exploitation, and theft against multiple victims, in parallel, for hours or days at a time (GTG-50014, GTG-50020, GTG-50029).»

    The AI company said it also identified and took down a number of influence operations in which Claude played the role of a «sub-editor or content creator» to churn out content and run them at a scale beyond what low-resourced actors could have accomplished on their own. However, Anthropic emphasized that none of these efforts amassed authentic engagement and that they were disrupted before they could even build an audience.

    Some of the influence and surveillance campaign clusters flagged by Anthropic at a high level are below –

    • GTG-04001, a Russian-speaking actor in Bangui that engaged in a foreign information manipulation and interference operation in the Central African Republic to amplify pro-Russia, anti-France talking points.
    • GTG-54002, a commercial «influence-as-a-service» operation that used Claude to mass-produce and rewrite political content across about 70 fabricated news websites. The operation has been traced back to LKM Company, a France-based digital advertising agency.
    • GTG-84005, a single account that used Claude to run a commercial election manipulation platform primarily targeting users in Malaysia based on political and social factors, such as their race and religion, by posing as a defensive cyber intelligence and counter-disinformation tooling outlet. The activity has been found to share links with BBS Bilisim Teknolojileri, an Istanbul-based technology company.
    • GTG-24015, a set of four accounts that used Claude as an «editorial and news production desk» to distribute them via state media outlets like Sputnik Moldova, RIA Novosti, Sputnik en Español, Sputnik Africa, and RT’s English-language newsroom.
    • GTG-34001, a set of three Iranian state-aligned accounts that used Claude to shape public opinion, turn official government intelligence bulletins into tailored content, and disseminate the content across social media platforms.
    • GTG-54006, a sustained, automated disinformation network that used Claude to generate fabricated Bengali-language news in Bangladesh and promote the country’s Awami League party. The activity has been linked to a single actor based in Gaibandha District in Bangladesh via a set of 29 Claude accounts that were rotated to bypass platform limits and detection.
    • GTG-84006, a distributed influence operation that targeted Iranian audiences across the world with an aim to impersonate real activists and engage in live political conversations. The activity has been linked to People’s Mojahedin Organization of Iran (PMOI/MEK) and the National Council of Resistance of Iran (NCRI).
    • GTG-54004, an account used by a single actor to mass-produce Kenyan political content as part of what’s suspected to be a domestic astroturfing campaign with a pro-administration bent.
    • GTG-84002, an account used by a single actor to run a sustained influence operation against the Muslim Brotherhood, the Sudan conflict, and the United Nations accountability mechanisms.
    • GTG-54009, a commercial surveillance platform that used Claude to analyze, classify, and profile the social media activity of users in Iran and the Persian Gulf region. The activity is assessed to have been carried out by, or on behalf of, an Israeli-Singaporean commercial intelligence vendor named S2T Unlocking Cyberspace.
    • GTG-14010, a China state-aligned operation that used Claude to track, profile, and recruit Uyghurs and Uyghur armed formations in Syria. The actor has been found to use the AI model to convert conversations extracted in bulk from over 100 monitored WhatsApp groups and dozens of Telegram channels into structured Chinese-language data and «creating profiles of individuals who might be vulnerable to targeting due to financial stress, family separation, and ideological disillusionment.»
    • GTG-14020, a set of accounts likely linked to a Chinese government-aligned intelligence operation that used Claude to build Chinese-language dossiers targeting religious leaders and Chinese diaspora figures across Asia, as well as map religious venues and instruct the model to adopt «China’s standpoint.»
    • GTG-14021, a set of accounts from China-based actors that used Claude to support surveillance and transnational repression, including prompting the model to assume the role of an intelligence analyst serving China’s national security apparatus.
    • GTG-14022, a China-based «public opinion monitoring» and dissident surveillance operation that used Claude to produce government briefings that listed dissidents, activists, ethnic minority and Chinese diaspora communities, and foreign media as threats to political stability while asking it to play the role of a «senior emergency public opinion analyst serving the government of the People’s Republic of China.»
    • GTG-34007, a set of 16 accounts operated by two Iranian-nexus actors associated with paramilitary and domestic security agencies that used Claude to build a frontend for what appears to be a government-controlled surveillance case-management system, run social-network analysis over 155,216 X posts, and build domestic surveillance capabilities via a malicious Mozilla Firefox extension named «al-Najm al-thāqib» to harvest user identities from major social network platforms.
    • GTG-50027, a single account that used Claude to design a national mass interception and surveillance platform called Lakana 360 for Mali’s state intelligence service to monitor about 25 million SIM cards spanning three of the country’s national mobile operators, and generate intelligence dossiers for any phone number. The platform has a separate layer that collects call records, text messages, and voice calls across the mobile networks.
    • GTG-30004, an Iran-nexus threat actor that used Claude to develop an automated, open-source intelligence identity-profiling service targeting Israeli and Jewish diaspora organizations.
    • GTG-30005, an Iran-nexus threat actor that used Claude to gather and analyze publicly accessible data to develop targeting recommendations against U.S. naval forces in the region and build software components of a domestic mass-surveillance platform that combined automatic license-plate recognition with mobile-device identifier interception.
    • GTG-30006, an Iranian threat actor that leveraged free Claude.ai accounts to develop malware, a delivery pipeline, and a phishing portal targeting domestic Iranians. This included a bogus ESET NOD32 antivirus login page that transmits captured credentials to Telegram, a ClickFix-style Windows Run dialog lure, and geofenced delivery pages. The threat actor has also used Claude to build SECOMS64, a modular Windows implant with keylogging, screenshot capture, and Chrome credential extraction capabilities.
    Cybersecurity

    Elsewhere, Anthropic said it neutralized Claude misuse efforts by threat actors based in northern Yemen to develop guided weapons, two China-based operations to draft a Chinese-language specification for an anti-torpedo fire control system and build targeting software for electronic warfare, and a Russia-based operation to engineer a full-stack autonomous first-person-view (FPV) kamikaze drone swarm.

    «As AI models become more widely used, providers will continue to acquire threat-relevant visibility into real-world use that even governments and intergovernmental organizations lack,» the company said. «We hope that sharing these early insights with the public helps inform governments, the industry, and the general public on the nature of these risks, and the safeguards that are necessary for ensuring the safe deployment of AI models.»

    200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories – CYBERDEFENSA.MX

    A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?”

    An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already there.

    Nothing here needed magic. Mostly access, trust, weak edges, and someone willing to keep poking. That’s the week.

    The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.

    The lesson this week is smaller than “patch faster.” Stop giving ordinary things unlimited trust. Extensions, packages, redirects, sessions, AI tools, exposed services — most of the trouble begins when something familiar is allowed to do too much.

    Security still breaks at the boring handoffs: what gets access, what stays exposed, what gets inherited, and what nobody checks twice. Attackers do not need every door open. One lazy hinge is enough. That is probably the part worth remembering after the headlines disappear.

    Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores – CYBERDEFENSA.MX

    Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store’s server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5.

    Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. «Sansec is publishing early because stores are being compromised right now,» the company said.

    As of September 6, Adobe has not published an advisory, a CVE identifier, a patch, or a workaround, and its Adobe Commerce security bulletin index lists nothing after the August 11 update.

    A successful attack gives the attacker code execution on the store’s server and installs a persistent backdoor. Sansec said all current versions are affected, including 2.4.9, and that it reproduced the full unauthenticated chain on clean Magento Open Source installations of 2.4.7, 2.4.8, and 2.4.9.

    Its first victim ran 2.4.6-p15 with Adobe’s July and August 2026 security updates applied, which is the latest patch level Adobe offers for that release line and one that Adobe’s August bulletin labels 2.4.6-2026-aug.

    Sansec has not published a reproduction on Adobe Commerce or on Adobe Commerce on Cloud, and Adobe has not confirmed which versions are affected. Sansec has not said how many stores have been compromised.

    The researchers’ interim advice for stores not running its Shield product is to temporarily disable GraphQL until Adobe releases a fix.

    Disrex Group, a Magento hosting and development company that hosts and responded to two of the compromised stores, notes that headless and progressive web app storefronts require GraphQL, whereas most classic and Hyvä storefronts do not.

    Adobe’s next scheduled security release is on September 8, Sansec said, and it is not yet known whether that release will cover this bug.

    Disrex’s findings are independent evidence of exploitation from outside Sansec. In an incident-response repository published on September 5, the company said it handled two compromised stores and a third that was attacked but not breached, and that its web-server rules are based on attack traffic captured on one of the compromised stores. In answers to questions from The Hacker News, Disrex said both stores ran Magento Open Source rather than Adobe Commerce, and that it hosts them itself through its hosting brand RexHosting.

    The store Disrex labels Store A ran Magento Open Source 2.4.8 and was a Sansec Shield customer, with the module installed, enabled, and licensed. It was hit at 23:10 UTC on September 4, hours before Sansec’s first blocking rules for this flaw went live, and Disrex said Shield was active and blocking other malicious traffic against the store at the time.

    Store B, which was not a Shield customer, ran Magento 2.4.7-p2, a security patch level that Adobe’s version history dates to August 2024, eight levels behind the current 2.4.7-p10. It was first hit at 00:55 UTC on September 5, Disrex said, and it is the store from which the company’s web-server rules and its reading of the vulnerable code were taken.

    Both stores were breached inside the roughly eight-hour window between the first exploitation Sansec observed and the moment any defence for it existed, Disrex said. «Patch status was irrelevant here, which is the part merchants most need to hear,» the company told The Hacker News.

    The repository carries its own warning. «This repository was written with AI assistance, during a live incident, in a few hours,» its README says, adding that it has not been reviewed, that its Apache rules were never run against a live Apache server, and that most of its cleanup commands were written rather than executed.

    Sansec’s indicators describe the implant as a background process disguised under [kworker/u:8:0], a name that belongs to a Linux kernel thread, with a binary installed at ~/.local/share/.gvfsd/gvfsd-user under the site user’s home directory rather than the web root, and a cron entry that restarts it every five minutes.

    Disrex described the binary as a stripped, statically linked Rust program of roughly 1.9 MB built for x86-64 and arm64, and said the cron entry is written straight to the spool file under /var/spool/cron/crontabs/, so the system log shows no crontab replacement.

    One store carried the same line 1,728 times, and the implant re-added it within a second of removal.



    On one of the two stores, the implant made no outbound connection at all. It held 28 connections to the store’s own Redis instance on port 6379 and read Magento’s session storage from it, Disrex said, and neither of its two packet captures, each over 200 MB and taken while the implant was live, contained a single packet to the download host or the command-and-control address that Sansec listed.

    Disrex told The Hacker News over email that each store ran in its own isolated account with a single site owner, no sudo rights, and no path to any other customer, that the implant ran as the unprivileged site user and could reach nothing beyond that store, and that it confirmed no lateral movement and no other affected site on its platform.

    Both stores were contained the same day, roughly eleven and fourteen hours after first contact, the company said, and it found no evidence of data exfiltration, no rogue admin accounts, no injected payment skimmer, and no database backdoor. All sessions were invalidated, and credential rotation is underway as a precaution.

    Because it runs a number of Magento stores on its own platform and found the first compromise quickly, Disrex said, it swept its whole estate within the hour and found the second store the same afternoon. The company has also published an incident write-up.

    Sansec said that for Shield customers attacked before its rules went live, it has no indication that the backdoor was actually used, and recommended rotating Magento credentials wherever the process has been identified.

    The attack works in two stages, according to Sansec’s outline. It first plants PHP code in a file that Magento itself writes, for example, when generating a failure report. Then it makes Magento execute that file by triggering the platform’s standard «Payment Transaction Failed Reminder» email. The code runs while Magento renders the message, so no one has to open it, and the attack can succeed even if email delivery fails.

    Sansec has not yet published the full exploit chain and said a breakdown of the chain, the dropper, and the implant will follow in an update.

    Disrex’s reading of the chain, published in a mechanism write-up alongside its rules, is that a directive within the injected text drives a sequence of Magento’s own classes into code that exists solely to serve the command-line dependency-injection compiler.

    That code ends by including a file path the attacker chose: the log poisoned a moment earlier. The executed PHP dropper attempts six PHP functions in turn to start a process, then downloads and launches the implant. Disrex names three files under setup/src/Magento/Setup/Module/Di/Code/ as the point where the chain ends, and told The Hacker News it identified that sink on its own by reading Magento source on the compromised store. Sansec has not confirmed that reading, and Disrex does not publish the assembled request.

    Two locations matter for the first stage. Sansec’s published check searches var/report/ for the marker X_TRACE_. Disrex said both of its infections were poisoned through var/log/system.log instead and would have been missed by that check, so both directories need searching.

    The marker has already drifted: Disrex saw a trigger header of the form X-TRACE- followed by ten hex characters on the morning of September 5 and the same header without the word TRACE by the afternoon, so a search should match the shape rather than the exact string.

    A TypeError from array_merge() with an integer argument in system.log, immediately after the include, is evidence that the exploit succeeded, Disrex said. However, a stealthier variant returns an empty array and leaves nothing in the log.

    For the process, Disrex said that a genuine kernel thread is owned by root and has no resident memory, so a bracketed name on the site user with real memory usage is the implant. The implant sets its command line to the literal bracketed string, so a check written against the process’s comm field matches nothing.

    Disrex also found that the binary running in memory on one store was a different build from the file on disk, and advises hashing the running process from /proc//exe as well as the file. Unexpected bursts of «Payment Transaction Failed Reminder» emails are a reason to investigate, Sansec said, although legitimate declined payments generate the same notification.

    The following indicators have been published by Sansec and in Disrex’s indicator list

    • Process: [kworker/u:8:0] owned by a non-root user
    • File: ~/.local/share/.gvfsd/gvfsd-user
    • File: ~/.local/share/.gvfsd/.gvfsd_<8hex>.lock
    • File: /tmp/.gvfsd_<8hex>.lock
    • File: /tmp/.kw_
    • Cron: */5 * * * * exec /.local/share/.gvfsd/gvfsd-user, with a variant pointing at /tmp/.kw_
    • SHA-256: e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 (Sansec’s sample)
    • SHA-256: 8334b434fa3fe9f59cebe9609b11e0b1fd19d10212c45c705adec1902a1d06ef (on disk on both Disrex stores)
    • SHA-256: 251fabd50d7b18a8b5e1b3ef5d64e7198c17244778f6461fb1ab07f6169bf220 (running in memory on one Disrex store)
    • Domain: 247.cdnflare[.]xyz (malware download host)
    • IP: 99.84.67[.]186:443 (command-and-control over WebSocket and TLS, per Sansec)
    • IP: 88.216.72[.]181 (attacker source, per Sansec)
    • IP: 5.181.86[.]133 (attacker source sending in bulk, per Disrex)

    Sansec recommends its eComscan scanner to detect the implant, and said version 1.9.7 will terminate the process for Shield customers.

    Disrex reported a clean result on Store A. eComscan ran there at 10:00 UTC on September 5, roughly eleven hours after the implant first ran and while 1,728 cron lines were present, and reported the store clean. The cause was scope rather than a scanner fault, Disrex told The Hacker News: the scheduled scan was pointed at the store’s document root, and the implant had installed one directory above it, under the account’s home directory. Disrex has since widened the scan path and said it would confirm the eComscan build number separately.

    There is no vendor fix to install. Until Adobe ships one, the options are Sansec’s temporary GraphQL shutdown; three unofficial mitigations published by Disrex, ProxiBlue, and Graycore; and two server settings that do not depend on the flaw.

    Disrex published nginx and Apache rules that block requests carrying the exploit’s parameters in the URL query string. Its own test on a live store showed the limit: the same parameters sent in a POST body reached PHP, as did a JSON body, because nginx and Apache inspect only the query string, Disrex said. Disrex describes the rules as stopping the campaign as it currently runs rather than the vulnerability.

    Disrex’s main mitigation adds a check to three methods in Magento’s dependency-injection code scanners, preventing them from running outside the command line. The hand edit is reverted by every composer install, so Disrex also ships it as a composer-patches source patch that reapplies on deploy and, it says, applies unchanged from 2.4.6 through 2.4.9.

    One of the three files, ClassesScanner.php, is called over HTTP by at least one third-party module, mageplaza/module-admin-permissions, and guarding it breaks that module’s admin screen, so Disrex tells administrators to search their vendor directory before touching it.

    The guard was tested on a harness rather than inside a running store, and Disrex says it is not a complete fix on its own. Disrex told The Hacker News the guard is its own work, written during the response, and was not developed with anyone else. A GitHub user, ProxiBlue, separately published the same guard on September 5 as three unofficial patches. Neither Sansec nor Adobe has confirmed that these scanners are where the chain ends.

    Graycore, LLC published a Magento module on GitHub and Packagist on September 5 whose current code, Graycore says, hardens three points on the chain: the email template block directive refuses backend blocks, the grid row URL generator checks a class before building it, and PHP opening tags in Web API fatal error reports are broken.

    The version on Packagist at the time of writing was an earlier release whose only mitigation targeted a PayPal GraphQL resolver that has since been removed. The README says «That is hardening, not a fix» and warns that other paths through the vulnerability remain open and that a store may already be compromised.

    Two server settings do not depend on knowing the chain at all, Disrex said. At one of its two stores, the first four of the six PHP functions the dropper tried were disabled; proc_open was not, and the dropper used it to start the implant, with open_basedir doing nothing to contain the child process.

    Adding proc_open to PHP’s disable_functions, and mounting /tmp, /var/tmp and /dev/shm with noexec so a downloaded binary cannot run, are the layers Disrex puts ahead of every rule in its repository.

    For a store that is already infected, Disrex’s cleanup guide sets the order: preserve evidence first, remove the cron entry before killing the process because the process restores it, do not reboot because the copy under /proc may be the only remaining binary, and do not run composer install to clean up because it overwrites the timestamps that show what was touched.

    It then recommends flushing session storage since the implant read it, and rotating the crypt/key in app/etc/env.php, as well as every admin password, every payment provider API key, and every other integration credential in that file.

    Hosting providers Nexcess and Liquid Web posted identical incident notices on September 5, stating they were reviewing their server environments and implementing precautionary measures.

    Neither claims a confirmed customer compromise or its own reproduction of the flaw. Disrex recorded 26 distinct source addresses across its two stores, taken from the stores’ own nginx access logs and deduplicated, two of them hosting infrastructure sending in bulk and the rest a residential proxy pool sending two to six requests each, and said that blocking the single attacker address in Sansec’s advisory would have stopped less than a quarter of the traffic it saw. An earlier count of 28 included two of Disrex’s own servers making verification requests during the response, which it removed. No source has named the attackers.

    The Hacker News has reached out to Adobe, Sansec, and Graycore for comment, and will update the story if we hear back.