September 7, 2026
- Kimsuky's Operation GitPower is now mass-producing decoys with an AI coding agent: Genians analysed 13 malicious LNK files collected 11–19 August 2026 whose decoy PDF metadata names the open-source agent OpenCode as producer. Lures shifted from diplomacy and academia to finance and corporate operations (fund disbursement, insurance premiums, Visa payments); the LNKs launch PowerShell with encrypted loaders buried in over-long arguments padded with leading spaces, pull decoys and follow-on commands from GitHub Raw using hardcoded PATs, and now add Pastebin as a second-stage channel plus anti-analysis routines that check for virtualization and analysis tooling, inspect sandbox usernames and wipe command history. All 13 share the same decoder constant and array variable name — cheap hunting pivots.
· Threat Intelligence
in The Diff Is the Disclosure: MikroTik's Silent Patch Comes Apart
August 25, 2026
- Kimsuky LNK campaign against South Korean and Japanese targets. Nextron found multiple samples overlapping ENKI WhiteHat's reporting: phishing mail delivering OneDrive-hosted ZIPs containing oversized LNK files with embedded script content and URL-based payload retrieval (Valhalla rule).
· Threat Activity
in The Rogue Agent Staged an Apology, Then Pushed More Malware
August 22, 2026
- Kimsuky is installing a malicious Chrome extension that auto-exfiltrates victims' Gmail to C2 in spear-phishing against South Korean and Japanese targets, alongside abuse of legitimate remote-control tooling. Korean-language comments and debug strings throughout the extension's JavaScript suggest most of it was written with generative AI (ENKI).
· Threat Activity
in A CVSS 10.0 Lands in Entra ID — and Microsoft Can't Keep Its Exploitation Story Straight
August 13, 2026
Microsoft Defender flaw CVE-2026-50656 was bypassed by a new ShieldBreak proof-of-concept that grants SYSTEM privileges on fully patched Windows 11 and Server 2025. SharePoint authentication-bypass CVE-2026-55040 is now actively exploited in the wild, allowing attackers to forge JWT tokens and impersonate admin users. LiteLLM malicious PyPI releases exposed over 2,100 organizations to credential-stealing code that harvested cloud keys, SSH credentials, and database passwords in a supply-chain attack traced to an earlier Trivy compromise. Midnight Blizzard (APT29) weaponized hotel Wi-Fi captive portals through CaptiveCrunch to harvest Microsoft 365 credentials and deploy malware.
August 11, 2026
- North Korea's Kimsuky is running LLMs offline on its own servers to industrialize operations. Genians documents AI-generated decoy documents, local/private LLM deployments, RAG over stolen files, and .NET/C# AI libraries being collected to build AI into malware — moving beyond public chatbots (The Hacker News, The Register).
· AI & Model Security
in Metabase Zero-Day Blast Radius Widens to LexisNexis and Framework
July 26, 2026
in Hotel Wi-Fi Becomes an MFA-Bypass Machine for M365 Accounts
July 23, 2026
- Kimsuky compromises South Korean groupware vendors with a new Gomir variant. ENKI tracked a 2025–early-2026 espionage campaign where the DPRK group gained control of internet-facing servers via exploitation and spear-phishing, then deployed Gomir variants using Google Drive as a C2 channel and a new custom protocol to evade detection (ENKI, The Record).
· Threat Activity
in "Every Frontier Model Tried to Cheat": UK Safety Institute Puts Numbers Behind the OpenAI–Hugging Face Incident
July 1, 2026
in CitrixBleed Returns: watchTowr Discloses a New NetScaler Pre-Auth Memory Overread