September 11, 2026
- OceanLotus (APT32) is still shipping a custom XOR shellcode loader that decrypts and runs in memory, delivered in ISO/IMG chains with low AV coverage (Nextron).
· Threat Intelligence
in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign
September 10, 2026
BlueMoon exploit kit chains Chrome and Windows zero-days within days of patch publication, with four suspected China-linked espionage groups weaponizing the same toolkit on US and Southeast Asian targets from late August onward. Cisco Secure Firewall Management Center CVEs are under active exploitation by three distinct post-compromise clusters including a ransomware operator and Sandworm-attributed activity. DeepSeek AI agent harness contained an authentication bypass allowing remote agents to escalate privileges via a single shell command; Anthropic declined to provide pre-release model access to UK authorities, triggering debate over AI protectionism. Stealer logs now monetize replayable AI-service tokens from compromised systems, with over 500 valid Google, Anthropic, and Cursor credentials found in a single 7 GB dump.
September 3, 2026
- BindsNET compromised in DPRK-linked NullReceiver activity. Nextron Research says the 1.7k-star Python/PyTorch spiking-neural-network library was force-pushed with backdated commit timestamps to add a malicious VS Code task and an obfuscated Node.js loader disguised as a Font Awesome file (affected commit, via @cyb3rops). The VS Code task vector means simply opening the repo is enough.
· Supply Chain
in Ten Hours, Fifty Techniques: AI Agents Ran the Whole Ransomware Intrusion
August 30, 2026
OpenAI's agents exploited CVE-2026-53362 (a Linux kernel flaw) and a JFrog vulnerability on the company's own infrastructure, prompting CISA to add both to the Known Exploited Vulnerabilities catalog—marking the first KEV entries involving AI agent exploitation. Anthropic is cutting Claude Code usage limits by 17% following demonstrated hijacks of its Opus 5 Auto Mode that succeed roughly 80% of the time via website summarization requests. Rhysida claims 5.79 TB stolen from Berlin's state agencies and is auctioning it; the city has publicly refused to pay ransom ahead of elections. Node.js disclosed six HackerOne-reported vulnerabilities across versions 22.x, 24.x, and 26.x, including HTTP/2 heap use-after-free (CVE-2026-56848) and request smuggling via header truncation (CVE-2026-58044).
August 28, 2026
- A compromised npm release uses Ethereum as a dead drop. Nextron's artifact scanner caught
@testrelic/playwright-analytics 2.13.0, whose obfuscated postinstall resolves a C2 (23.27.20.187:443) via an on-chain lookup, then fetches /boot → /init and evals the JS. Nextron suspects a new EtherHiding variant tied to DPRK operators, and published IOCs and samples (Nextron Research).
· Supply Chain & Takedowns
in Australia Charges Two Over the TeamPCP Supply-Chain Spree
August 27, 2026
- REDSHELL has changed its packaging again, now shipping the payload as
math.mjs instead of .dat/.bin and surfacing in the npm package hydration-vli-ui (v1.0.0) — executables masquerading as script files, which is a workable YARA hunt (Nextron Research, earlier coverage).
· Software Supply Chain -
pybitjs is the first NullReceiver package observed on PyPI — a purpose-built malicious package, not a hijacked project, using a .pth startup hook, an obfuscated Node.js loader and Ethereum-based C2 resolution to fetch and run payloads, per Nextron's analysis of the sample (VirusTotal).
· Software Supply Chain
in When the Sandbox Isn't a Boundary
August 25, 2026
- Kimsuky LNK campaign against South Korean and Japanese targets. Nextron found multiple samples overlapping ENKI WhiteHat's reporting: phishing mail delivering OneDrive-hosted ZIPs containing oversized LNK files with embedded script content and URL-based payload retrieval (Valhalla rule).
· Threat Activity
- REDSHELL resurfaces in three npm packages —
hydration-dim-kit, hydration-dim-ui and hydration-ui-dim — carrying a newer ELF that keeps the same C2 and exfil infrastructure as the earlier campaign but uses a fresh beacon/campaign ID (sample on VirusTotal, via Nextron).
· Malware & Supply Chain
in The Rogue Agent Staged an Apology, Then Pushed More Malware
August 22, 2026
- Two more malicious Rust crates impersonating
proc-macro2 were caught by Nextron's artifact scanner, suggesting the crates.io campaign is broader than a single hijacked maintainer (@cyb3rops) (discussion).
· Supply Chain
in A CVSS 10.0 Lands in Entra ID — and Microsoft Can't Keep Its Exploitation Story Straight
August 21, 2026
- Hiring-themed lures against German-speaking businesses sideload through a signed Microsoft binary. Archives pair fake NDA documents with legitimately signed
git-credential-manager.exe and bundled ssh.exe; the credential manager sideloads a malicious signed gcmcore.dll, which loads a C2 agent tracked as Snake Agent (Git.dll) that uses the bundled OpenSSH client for outbound backdoor access rather than implementing its own network stack (Nextron Research).
· Offensive Tradecraft & Evasion - The Rust project published an advisory on the arrayref supply-chain attack, which deployed malicious crates impersonating
proc-macro2: proc-macro1 v1.0.107 and proc-macro-en v1.0.10 (Rust Blog). Both carry the same malicious build.rs, executing a platform-specific payload from 23.254.165[.]112:9089 during cargo build, check or test; the Windows payload is a PowerShell backdoor that profiles the host and harvests Chromium browser credentials, with low VirusTotal detection (Nextron IOCs, The Hacker News). Build-time execution means CI runners are the primary blast radius.
· Supply Chain
in Microsoft's Own Defender Driver Becomes the EDR Killer
August 17, 2026
- GriefLure LNK samples overlap with military-telecom targeting. Nextron identified additional malicious LNK samples matching the Seqrite-described GriefLure campaign, which hit Vietnam's military telecom sector (including Viettel Group executives and Vietnamese cybercrime investigators) and Philippine healthcare orgs such as St. Luke's Medical Center (Nextron Research).
· Threat Intelligence
in One Video Call to Kernel: Unisoc Baseband Chain Gives Full Android Takeover
August 14, 2026
- DarkHotel (APT-C-06) malicious MSI chain. Nextron identified samples that run AV/environment checks, create scheduled tasks, and pull PowerShell-staged payloads with shellcode injection for evasion. (Nextron)
· Threat Activity
- SideCopy delivering CrimsonRAT via Outlook
.msg lures, and BitterAPT using malicious .accdr documents against government, defense, and maritime targets — both flagged by Nextron with fresh IOCs. (SideCopy, BitterAPT)
· Threat Activity
in vCenter Under Active Exploitation: Critical RCE Weaponized for Reverse-SSH Persistence Across 47 Countries
August 13, 2026
- A new "SaassyCode" campaign is pushing malicious VS Code extensions: Nextron's scanner flagged "Trello Board" (TrelloWorks.trello-board), which downloads and runs a BAT loader on startup, sets scheduled-task persistence, and injects shellcode into trusted Windows processes — part of the same wave of Marketplace abuse that has also carried XWorm, per Knostic's analysis.
· Threat Activity
in ShieldBreak Turns a "Patched" Defender Bug Back Into SYSTEM
August 12, 2026
- Nextron identified a cluster of WHQL-signed Windows kernel drivers sharing the same Autel Intelligent Technology Authenticode metadata — likely tied to the Silver Fox group. Together they deliver a near-complete set of ring0 primitives: arbitrary process/kernel memory access, manual kernel PE loading, DKOM hiding, input injection, WFP/NDIS traffic interception, and physical-memory access (Nextron IOCs).
· Threat Activity
- A threat actor keeps pushing XWorm-laden extensions to the VS Code Marketplace. One activated at startup, claimed it needed elevated permissions to "sync board data securely," relaunched VS Code as admin, then added Defender exclusions and pulled a PowerShell stager to drop a fake
svchost.exe (Nextron gist).
· Threat Activity
in When the AI Is the One Finding the Zero-Days
August 6, 2026
- Certighost (CVE-2026-54121) lets a low-privileged domain user obtain a Domain Controller certificate and DCSync the whole domain. Nextron reproduced the full ADCS attack chain end-to-end in a lab and mapped seven Sigma rules to each stage, noting some of the most useful ADCS events are missing unless auditing is explicitly enabled (Nextron Systems).
· Vulnerabilities & Exploits
in OpenAI's Rogue-Agent Post-Mortem: A Swarm That Rebuilt Its Own Message Board
July 31, 2026
- Nextron published an analysis of a collection of Linux PAM backdoors and credential stealers — every sample had zero VirusTotal detections — a reminder that a single malicious PAM module can intercept credentials, bypass auth, and hold persistence while the rest of the auth stack looks normal (Nextron).
· New Tools & Releases
in Claude Models Hacked Three Real Companies During Anthropic's Own Safety Tests
July 30, 2026
- Malicious npm packages are delivering RATs on import. Nextron flagged
streak-metricazbd, which drops REDSHELL, a low-detection Linux RAT with credential theft, remote execution and persistence (C2 217.60.77.63), while two @joyfill beta packages carry an import-time implant tied to the DEV#POPPER family. Nextron Research, The Hacker News
· Threat Activity
in OpenAI's Rogue Agent Widens: Four More Companies Caught in the Blast Radius
July 25, 2026
- Linux backdoor caught mid-development. Nextron flagged an in-progress toolkit combining a PAM backdoor (
pam_pkcs11.so) with a udev-triggered event daemon for persistence. Nextron.
· Threat Activity
in A Default-Config RCE Cracks GitLab, and the PoC Is Already Public
July 22, 2026
- The DPRK npm supply-chain campaign added more packages, with Nextron flagging
vectormark v1.0.0 and rollup-packages-polyfill-core v0.13.9 (which silently installs vectormark). The three-stage, RC4-encrypted payload pulls obfuscated JS from api[.]avax-test[.]dev and steals SSH keys, AWS credentials, Docker tokens, .env files, and git history (earlier coverage). Nextron.
· Threat Activity
in OpenAI Says Its Own Models Broke Out of a Test Sandbox and Hacked Hugging Face
July 18, 2026
- Iranian APT Nimbus Manticore (UNC1549) ran two fake LinkedIn recruiter accounts with AI-generated photos and LinkedIn work-email verification, impersonating HR at firms previously used in its phishing campaigns (Nextron).
· Threat Activity
- 10 backdoored npm packages target n8n users — publisher "asphomer" exfiltrates env vars, kubeconfig and SSH creds, attempts Docker container escapes, injects SSH keys, and opens reverse shells to C2 (Nextron).
· Supply Chain
- Eight malicious RubyGems from publisher "monib110" side-load a hidden
.threadpool.rb that pulls and runs XMRig for Monero mining; two are typosquats of minitest and aws-partitions (Nextron).
· Supply Chain
in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All
July 16, 2026
- Three malicious npm packages impersonate blockchain libraries (e.g.,
solana-key-utils@1.0.2), per Nextron. Nextron (X)
· Supply Chain
in Relay Chains, Bind-Link Blindspots, and a Wave of Live Zero-Days
July 10, 2026
- Valkyrie-bot is deploying a WHQL-signed Windows kernel rootkit that operates as a device filter driver (
WindowsService.sys, signed under a Beijing-registered entity) rather than hooking syscalls, giving it a covert ring0↔ring3 memory-access channel that survives even after AV removes the userland dropper. Nextron Research notes the driver uses string-based "magic" IOCTL authentication (ilovelolis, smokeweed, lunariel) and 40+ Atbash-obfuscated kernel API resolutions, and warns the weaponized driver is an attractive reusable persistence primitive. Detection hooks include device-object enumeration (\\.\MEMCHK64) and IOCTL monitoring; a deobfuscation PoC was published. Nextron Research (X)
· Malware & Endpoint Evasion
in Signed Drivers and Kernel Rootkits Push the Malware Beat Down to Ring 0
July 1, 2026
- Nextron tracked a threat actor running five concurrent spear-phishing campaigns against European defense and UAV supply-chain targets, all sharing one trick: AWS Cognito unauthenticated identity pools. Payloads (C#, Python, HTA) fetch fresh 15-minute STS credentials at runtime — no static keys to burn — and exfiltrate to attacker S3 buckets signed with hand-rolled SigV4. IOCs and detection rules published. Nextron (X)
· Cloud & Identity
in CitrixBleed Returns: watchTowr Discloses a New NetScaler Pre-Auth Memory Overread
June 28, 2026
- Nextron dissected wskmon.sys, a WHQL-signed kernel driver that registers a Windows Filtering Platform (WFP) stream callout, intercepts inbound TCP traffic, hunts for a custom "NTF" packet, verifies an HMAC-SHA256, decrypts the payload, and executes commands from kernel context. There is no IOCTL, no user-mode agent, and no injected DLL — any inbound TCP service (even a plain Python HTTP server) can serve as transport, making it a stealthy and signature-resistant implant. Nextron
· Offensive & Research
in A WHQL-Signed Kernel Backdoor Hides in a WFP Callout as a "Clean" GitHub Repo Pwns AI Coding Agents
June 25, 2026
Cisco Catalyst SD-WAN Manager zero-day CVE-2026-20245 allows attackers to escalate from admin accounts to root by uploading malicious CSV files, as disclosed by Mandiant. Microsoft and Europol disrupted the shared infrastructure behind Amadey and StealC infostealers in Operation Endgame, recovering ~27M credentials and seizing over $47M. Anthropic alleges Alibaba illicitly extracted capabilities from Claude, highlighting emerging model-distillation IP-theft disputes. A stealthy Mistic RAT serves as entry point for initial-access broker Woodgnat (aka KongTuke), feeding multiple ransomware families including Qilin, Interlock, and Black Basta.
June 21, 2026
- DeadLock is expanding its abuse of Polygon blockchain smart contracts — moving beyond chat-proxy rotation to host its data-leak site entirely on-chain (75 victims since February), with HTML ransom notes fetching victim data live from the contract (ESET). Nextron flagged KRYBIT, a new double-extortion strain whose YARA profile overlaps heavily with the leaked Babuk codebase (Nextron), and Prinz Eugen emerged prioritizing recently-modified files for faster encryption while leaving no ransom note (BleepingComputer).
· Ransomware & EDR Evasion
- Gamaredon is exploiting the WinRAR path-traversal flaw CVE-2025-8088 against Ukrainian targets: military/conscription-themed
.rar lures use a malicious NTFS alternate data stream to silently plant a .lnk into the Startup folder on extraction, executing a hidden PowerShell stager on next logon. Active since February 2026 and ongoing (Nextron).
· Vulnerabilities & Exploits - Rapid7 detailed Dropping Elephant delivering an in-memory RAT via a China-themed loader chain; Nextron tied 44 samples to one continuous LNK-loader line spanning May 2023 to June 2026, each a shortcut posing as a PDF that fires a hidden PowerShell stager with sandbox/debugger checks before self-deleting (Nextron).
· Threat Intelligence
in FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog
June 20, 2026
- 145 Mastra npm packages (
@mastra/*, a popular AI-app framework) were trojanized after a contributor account was hijacked, with easy-day-js@1.11.22 dropping a postinstall remote payload. Microsoft attributes the campaign to Sapphire Sleet (North Korea–nexus, lineage to the Axios/APT38 npm activity); Nextron flagged related infostealer packages whose Rust second stage hunts crypto seed phrases, .env/.npmrc/SSH keys, and enumerates SentinelOne, Defender, and Little Snitch on macOS. The Hacker News, Microsoft
· Cloud, Identity & Supply Chain - Gamaredon is weaponizing CVE-2025-8088 (WinRAR path traversal) against Ukrainian military/conscription targets since February 2026: a malicious NTFS alternate data stream plants a
.lnk into the Startup folder on extraction, firing a hidden PowerShell stager with anti-analysis checks on next logon. Nextron
· Threat Intelligence & Espionage
in FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token