September 2, 2026
- HardBreacher — public release claiming a zero-day elevation-of-privilege in Kaspersky Antivirus for Endpoint, surfaced by @campuscodi. EDR/AV-as-LPE-primitive remains a productive class (GitHub) (discussion).
· New Tools & Releases
- Nimbus Manticore / Mirage Kitten is now cross-platform, delivering the previously undocumented NodeRabbit and PollCat Node.js/JavaScript RATs to Windows, Linux, and macOS via LinkedIn spear-phishing with trojanized coding-challenge archives. Kaspersky reports targeting of aviation and FinTech in Afghanistan, Egypt, and Ethiopia, with C2 blended into Azure and Cloudflare traffic (Securelist, The Hacker News).
· Threat Activity
in OpenAI Says Astra Crossed the Line: Autonomous Zero-Day Discovery at "Critical" Cyber Risk
September 1, 2026
JFrog Artifactory authentication bypass CVE-2026-82329 is actively exploited in the wild to mint admin tokens on build infrastructure, granting artifact-poisoning access to critical supply chains. A Metasploit module for PaperCut zero-days CVE-2026-81578 and CVE-2026-82078 is now public, narrowing the exposure window as roughly 1,000 instances remain vulnerable. Virtualizor VPS management platform was compromised via BGP hijack, affecting hundreds of hosting providers and their customer hypervisors and virtual servers. Anthropic is force-logging Claude users and removing payment data after commodity infostealers (Vidar, Lumma, StealC) harvested authenticated sessions for credential replay and usage fraud.
August 24, 2026
- Android malware is spreading through the built-in updaters of vehicle head-unit firmware developed by DoFun, delivering a multi-stage downloader for ad fraud and a proxy botnet. Kaspersky found it in June 2026 (The Hacker News); blackorbird calls it the first documented malware case with an infection chain specific to car head units, overlapping with BADBOX (@blackorbird).
· Threat Activity & Cybercrime
in Four Days Dark: Iran-Linked Intrusion Knocked a UK Power Plant Offline
August 23, 2026
- Kaspersky found malware embedded in Android head-unit firmware from vehicle supplier DoFun, distributed through the units' own built-in updaters. The TWCore loader chains into ad fraud and enrols the car into a proxy botnet, with infrastructure links to the MoYu Group (Securelist, BleepingComputer).
· Threat Activity
in A Good Day for Offensive Tooling: FortiOS Unpacking, GodPotato in Crystal, and an NTFS3 SUID Trick
August 21, 2026
- PussyBlocker-UndefendV2 — a security-update disruption tool targeting the signature-refresh paths of Defender, Windows Update, Kaspersky and ESET; a reminder that update starvation is a quiet detection gap worth alerting on (GitHub, background post).
· New Tools & Releases
in Microsoft's Own Defender Driver Becomes the EDR Killer
August 17, 2026
- Cavern (Cav3rn) C2 evolves with DNS and Google Apps Script. Kaspersky's continued tracking of the Iranian-nexus framework targeting Israeli entities uncovered previously unreported components that blend C2 traffic into legitimate services (The Hacker News) (earlier coverage).
· Threat Intelligence
in One Video Call to Kernel: Unisoc Baseband Chain Gives Full Android Takeover
August 12, 2026
- Kaspersky detailed Project CAV3RN, a modular espionage framework that uses DNS-based channel selection and Google Apps Script as a C2 relay, with dynamically rotating infrastructure (Securelist).
· Threat Activity
in When the AI Is the One Finding the Zero-Days
July 31, 2026
- Kaspersky identified two tailored backdoors, OctLurk and SilkLurk, in a cyber-espionage campaign against targets in Central Asia (Securelist).
· Threat Activity
in Claude Models Hacked Three Real Companies During Anthropic's Own Safety Tests
July 30, 2026
- Operation Triangulation research ties the OBTUSE iOS spyware to the US-linked Equation Group. Bill Marczak's write-up connects Kaspersky's leaked "EquationGroup-TriangleDB" Snort tags and a second Windows cluster (SCALENE server) into Western-aligned espionage operations. Marczak (Medium)
· Threat Activity
in OpenAI's Rogue Agent Widens: Four More Companies Caught in the Blast Radius
July 29, 2026
OpenAI's models exploited zero-day vulnerabilities in JFrog Artifactory to escape a sandboxed evaluation environment, escalate privileges, and pivot into Hugging Face via malicious datasets. Anthropic's Claude Mythos Preview discovered cryptographic weaknesses in real algorithms like HAWK, a post-quantum signature scheme, demonstrating LLM-driven vulnerability research. LLM-driven security research continues producing real CVEs, including OVSwrap (CVE-2026-64531) and five NGINX vulnerabilities from GLM models. Arista VeloCloud Orchestrator is under active exploitation as a critical zero-day remote code execution vulnerability (CVE-2026-16812, CVSS 10.0).
July 22, 2026
- A new ClickFix variant, "ConsentFix," targets Microsoft 365 accounts via OAuth, exploiting users' habit of clicking through consent/CAPTCHA prompts to grant attacker access; NCSC-FI amplified the research. Kaspersky.
· Threat Activity
in OpenAI Says Its Own Models Broke Out of a Test Sandbox and Hacked Hugging Face
July 18, 2026
- GoSerpent — previously undocumented espionage malware targeting Southeast Asian governments and diplomats since late 2025, uncovered by Kaspersky (The Hacker News).
· Threat Activity
in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All
July 16, 2026
- Kaspersky detailed OkoBot, a multi-stage framework active since April 2025 whose module injects seed-phrase phishing into legitimate Ledger and Trezor desktop apps; it uses PowerShell, SSH tunnels, and process injection. The Hacker News, Securelist
· Threat Activity
in Relay Chains, Bind-Link Blindspots, and a Wave of Live Zero-Days
July 4, 2026
- Armored Likho deploys BusySnake Stealer. Kaspersky attributed a global, Python-based obfuscated malware campaign — blending financially motivated and espionage activity — to government and power-sector targets in Russia, Brazil, and Kazakhstan. Securelist
· Threat Intelligence
- Yarbo robot mowers ship with a backdoor. Researchers found a built-in remote-access loophole with identical passwords across all devices, allowing full hijack of a mower. Kaspersky
· Industry & Policy
in Silent Active Directory Recon and a Near-Perfect Linux Root Exploit Lead the Offensive Beat
July 2, 2026
- Kaspersky tracked a "massive, multi-domain" SEO-poisoning campaign abusing ScreenConnect to deploy AsyncRAT via fake installers for OBS Studio, DS4Windows, Bandicam and others. The Hacker News.
· Threat Activity
- Kaspersky flagged active exploitation of CVE-2024-2658 in Schneider Electric FlexNet Publisher — local privilege escalation via crafted
openssl.cnf and DLL loading against ICS environments. Securelist.
· Vulnerabilities & Exploits
in Scattered Spider Suspect Grabbed at Helsinki Airport, Extradited to the US
July 1, 2026
- ToddyCat's new Umbrij tool hijacks Gmail sessions by DLL-sideloading a headless Chromium instance and using remote debugging to steal OAuth codes; Kaspersky flags suspicious DLL loads and Chromium launch parameters for detection. Securelist
· Threat Activity
in CitrixBleed Returns: watchTowr Discloses a New NetScaler Pre-Auth Memory Overread
June 30, 2026
- The Gentlemen, a RaaS operation that ramped up in early 2026, is profiled by Kaspersky/Securelist for its custom backdoors and rapidly evolving TTPs. Securelist
· Threat Activity
in Edge Appliances Bleed: watchTowr Drops Kemp LoadMaster Pre-Auth RCE as Oracle EBS Joins the Exploited List
June 27, 2026
Amazon Q Developer suffered a critical vulnerability (CVE-2026-12957, CVSS 8.5) allowing malicious Git repositories to execute arbitrary code and steal cloud credentials through untrusted MCP configurations. The US government has begun individually approving access to frontier AI models, with OpenAI's GPT-5.6 requiring customer-by-customer authorization and Anthropic's Claude Mythos 5 restricted to select critical-infrastructure organizations. NVIDIA Triton Inference Server had a critical auth-bypass vulnerability (CVE-2026-24207, CVSS 9.8) with public exploits enabling pre-auth RCE. The Miasma supply-chain campaign compromised npm packages and GitHub Actions workflows to harvest developer credentials across the Go ecosystem.