daily cyber × ai intelligence

index

tagged

[malware]

5 editions · 7 items

September 4, 2026

Malware That Gaslights the AI Analyst

A North Korea-linked macOS implant called Gaslight embeds fake system error messages to trick AI analyzers into abandoning malware analysis while the payload executes. CISA added seven actively exploited vulnerabilities to its KEV catalog, including pre-auth flaws in SonicWall SMA 1000, JFrog Artifactory, and BerriAI LiteLLM, with post-exploitation involving reverse shells and crypto miners. ShinyHunters published stolen data from McKesson, Neogen, Elekta, and Jack Henry after extortion deadlines expired, while Shai-Hulud infostealer now targets 469 credential locations including AI tool configs. OpenAI's GPT-6 Astra crossed a critical cybersecurity threshold, finding two unknown zero-days during testing and marking what the company calls the start of the AGI era.

July 11, 2026

  • GigaWiper, flagged by Microsoft, is a modular Golang Windows backdoor bundling a standalone wiper, ransomware encryption, multi-pass wiping, and persistence, with C2 over RabbitMQ and Redis — an evolution of several prior malware families. The Register, SecurityWeek · Threat Activity & Malware
  • Operation "Muck and Load" — tracked by Socket and highlighted by NCSC-FI — abuses malicious Go modules and multi-stage PowerShell loaders across 222 GitHub repositories, using commit-farming, public dead drops, and protected archives to stage RATs, infostealers, spyware, and cryptominers. Socket via NCSC-FI, SecurityWeek · Threat Activity & Malware
  • SCMBANKER targets Mexican banking, fintech, and crypto customers via ClickFix fake-CAPTCHA lures dropping a PowerShell toolkit (tracked by Elastic as REF6045). The Hacker News · Threat Activity & Malware

in Progress Orders ShareFile Storage Controllers Offline Over Active Zero-Day Threat

June 23, 2026

  • Brazil's Emergency Alert System hijacked off a decade-old infostealer credential — an actor ("mizanthropiaz") pushed false alerts to hundreds of thousands across São Paulo, Rio, and Brasília after logging in with a username/password harvested by malware in 2016 and never rotated; reports describe no MFA, no IP allowlisting, no rate-limiting, and a static "2+2" CAPTCHA. A textbook case of identity hygiene failure at national scale. The Record · Threat Activity
  • AryStinger botnet enslaves 4,000+ D-Link devices — undocumented malware turns outdated routers and NAS boxes into a proxy network, raising risk of DNS tampering and traffic theft on EOL hardware. BleepingComputer · Malwarebytes · Threat Activity

in Five Eyes Warns Frontier AI Will Reshape Offensive Cyber Ops as a New Entra ID Conditional Access Bypass Surfaces