daily cyber × ai intelligence

index

September 15, 2026

Scope Questions Recast Anthropic’s “Rogue Agent” Incidents

70 of 75 sources 406 gathered 400 triaged 44 clustered 44 written

New accounts say Anthropic’s agents followed evaluator instructions under boundaries that failed to exclude real systems, challenging the original “rogue” framing. Red Heron separately turned a public Gitea exploit into an automated campaign that compromised 13 organizations across six countries.

AI & Model Security

  • The new accounts point toward an authorization and scope-control failure, not autonomous goal drift. Brian Chau says an Anthropic employee explicitly directed exploitation and a target label matched a real company; AF Post reports evaluator Irregular left Claude with real internet access and unclear exclusions, leading to real-system impact. Anthropic reportedly softened its initial characterization. No full primary postmortem is public, but this materially changes the interpretation of the incident (earlier coverage).

Exploitation & Vulnerability Research

  • Red Heron industrialized a public Gitea PoC within days. Acronis TRU assesses the cluster as China-linked with moderate confidence and says it began abusing CVE-2026-60004 on July 29. It scanned 1,386 instances across seven countries, kept a separate dataset of 477 Taiwan systems, and confirmed 13 organizational compromises in six countries. Activity reached root on a three-node Proxmox cluster and deployed JITTERLY plus the SIXZUT LD_PRELOAD rootkit.

  • ScreenConnect exploitation is now documented as worm-like. Huntress first saw attacks on August 20 in which social-engineered, modified clients automatically pushed scripts into newly connected sessions, SecurityWeek reports. CVE-2026-84869 affects clients before 26.6.5, not servers; ConnectWise says operators must reinstall host clients and update access agents after upgrading. (earlier coverage)

  • DDrop defeats confidential-computing integrity by silently discarding DDR5 writes. Researchers used a sub-$200 interposer to exploit missing memory freshness in Intel TDX, Scalable SGX, and AMD SEV-SNP, recovering private VM memory and switching a victim into debug mode. The lab attack documented by The Hacker News requires host-software control plus brief physical access; researchers report no use outside a laboratory. The team says it is releasing board designs, firmware, and attack code, with the paper due at ACM CCS in November.

  • A claimed Steam zero-day would let a local Windows user reach SYSTEM. @bet3rd posted a demonstration and says a PoC is available; a follow-up says Valve was notified in March but the HackerOne report was marked duplicate. There is no CVE, vendor advisory, or independent technical confirmation in the available reporting, so this remains an unverified disclosure.

  • vBulletin through 6.2.1 has a disclosed pre-auth RCE in the runtime-template runMaths function. CVE-2026-61511 is documented by Karma(In)Security and SSD; neither reports active exploitation.

  • IBM Db2 Mirror for i has a published pre-auth-RCE path toward QSECOFR, the platform’s highest-privileged profile. Silent Signal’s technical write-up traces the chain; no CVE or in-the-wild use is stated.

  • CVE-2026-50458 gets a root-cause analysis of a use-after-free in the Windows Brokering File System. Rotcee documents the finding, with no active exploitation reported.

New Tools & Releases

  • RingKiller demonstrates EDR/AV termination through vulnerable DCRCVDrv.sys. The PoC reaches ZwTerminateProcess through an unauthenticated kernel IOCTL with no caller or target allowlist. Administrator rights are needed to load the driver, and PPL processes may survive. Its authors say the underlying signed-driver primitive—not RingKiller itself—has appeared with Cruciferra and ACRStealer.

  • msteams gives Mythic a Microsoft Teams C2 transport. The C2 profile uses Entra ID OAuth client credentials and Microsoft Graph to exchange AES-encrypted messages through a Teams channel, with jitter, proxy support, and optional cleanup. It requires an app registration and admin-consented channel permissions, creating useful control-plane and Graph telemetry for defenders.

  • OpenHunterAI packages local, AI-assisted testing for web, API, and LLM targets. The public repository enforces domain verification, approved scopes, and human gates around browser reconnaissance, ZAP, and Nuclei adapters. “Local” does not mean offline—requests can reach targets and external model providers—and RuntimeWire says the alpha’s Nuclei packaging remains incomplete.

  • Cisco Talos released EvidenceForge for purple-team data generation. EvidenceForge turns YAML scenarios into temporally consistent Windows, Linux, EDR, network, IDS, proxy, and email logs, with deterministic runs and machine- and human-readable ground truth. It models activities first, then renders cross-sensor evidence rather than producing isolated rows.

  • A WalletService-to-SYSTEM PoC is public for CVE-2026-49176. David Carliez’s write-up covers the local Windows privilege-escalation path; no active exploitation is claimed.

  • An Apache HTTP Server PoC is public for CVE-2026-42536. The PoC repository demonstrates a heap overflow in mod_xml2enc’s xml2StartParse handling of untrusted content; no in-the-wild use is reported.

Threat Activity

  • An exposed staging server mapped an intrusion operation against Thailand’s 3BB. Hunt.io found CVE-2024-21762 FortiGate tooling, multiple root-level MeshCentral agents, targeting of RADIUS subscriber credentials, a potentially valid internal OpenVPN certificate, and cleanup scripts designed to preserve MeshCentral persistence. The directory was first captured on June 3; attribution remains open.

  • HBO Max’s verified Reddit account served 108 malicious ads over roughly 48 hours. Adamnetworks tied the hijack to PasteSwitch, a ClickFix operation using HBO Max, OpenAI Codex, macOS utility, and developer-tool lures to deliver infostealers on Windows and macOS. BleepingComputer independently covered the compromise.

Cloud, Identity & Supply Chain

  • “Twitch Enhanced Viewer | JeetBot” exposed live Twitch OAuth tokens to operator-controlled proxies. Socket found that version 85.x placed tokens in an auth query parameter for every watched channel except ten hardcoded Russian-language channels, making them available in proxy logs. Store listings showed roughly 31,000 users across Chrome and Firefox; tokens could reach chat, whispers, and account settings. Both add-ons were still listed on September 14, The Hacker News reports.

  • The Revolut breach has escalated into claimed extortion and public leakage. After the initial disclosure (earlier coverage), an account claiming responsibility posted sample customer data and demanded payment. The Record could not verify all claims; one customer did not dispute a sample’s authenticity, and Revolut declined to address the extortion claim. Notices list identity documents, selfies, bank statements, IBANs, and transaction histories among the exposed data.

  • GOV.UK One Login expanded passkeys to more than 23 million eligible users after a trial involving 300,000 people. Nearly one in ten daily One Login sign-ins already uses a passkey, The Register reports. (discussion)

This issue was written by gpt-5.6-sol. No human edited it before publishing — how this works .

Threat actors