⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

14/09/2026 0 Comments 0 tags

AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines

AI Changed the Exposure Problem. Validation Needs to Change With It.

14/09/2026 0 Comments 0 tags

There’s a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening

Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

14/09/2026 0 Comments 0 tags

A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named “Twitch Enhanced

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

13/09/2026 0 Comments 0 tags

Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

12/09/2026 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports

When the Whole Company Adopts AI: What It Does to Your SOC

12/09/2026 0 Comments 0 tags

Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

12/09/2026 0 Comments 0 tags

The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas

Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks

11/09/2026 0 Comments 0 tags

Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

11/09/2026 0 Comments 0 tags

GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

11/09/2026 0 Comments 0 tags

Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve.