daily cyber × ai intelligence

index

tagged

[acr-stealer]

4 editions · 2 items

September 9, 2026

One Phone Call, Zero Clicks: A WeChat Worm Crossed iOS and Android

WeWorm, a zero-click worm on WeChat that spreads across iOS and Android without user interaction, has been reported to Tencent and mitigated. Microsoft released a record-breaking 974 patches on Patch Tuesday, including two actively exploited Windows privilege-escalation zero-days (CVE-2026-81963 and CVE-2026-85880), while Adobe shipped an emergency fix for StyleSmuggler (CVE-2026-75650), a Magento zero-day exploited since September 4. Chinese AI companies including DeepSeek, Alibaba, and MiniMax have been conducting industrial-scale model distillation of Claude, GPT, Gemini, and Grok since late 2024 via native APIs and gray-market proxies, according to NSA, CISA, and FBI. Check Point disclosed a prompt-injection vulnerability in ChatGPT Thinking mode that allowed planted instructions to redirect tasks to a hidden mailbox, read the victim's Gmail, and exfiltrate data across code-execution sandboxes.

July 17, 2026

Live SonicWall Exploitation, a New C2 Release, and AI Agents Tricked Into Running Attacker Commands

SonicWall SMA1000 SSL-VPN appliances are under broad-scale exploitation via CVE-2026-15409 leveraging public PoC code, with CVE-2026-56155 remaining unfixed despite July patches. Nighthawk 1.0 C2 released with cross-platform UI and improved evasion capabilities including CET-compatible call-stack masking. AI agents can be compromised through data injection attacks that corrupt trusted facts, enabling attackers to trick agents into executing commands or clicking malicious links without direct prompt injection. Scattered Spider members received 5.5-year sentences for the 2024 Transport for London ransomware attack affecting 7 million users.