daily cyber × ai intelligence

index

tagged

[shai-hulud]

6 editions · 5 items

September 10, 2026

One Exploit Kit, Four Espionage Crews: BlueMoon Turns Chrome's Patch Gap Into a Shared Weapon

BlueMoon exploit kit chains Chrome and Windows zero-days within days of patch publication, with four suspected China-linked espionage groups weaponizing the same toolkit on US and Southeast Asian targets from late August onward. Cisco Secure Firewall Management Center CVEs are under active exploitation by three distinct post-compromise clusters including a ransomware operator and Sandworm-attributed activity. DeepSeek AI agent harness contained an authentication bypass allowing remote agents to escalate privileges via a single shell command; Anthropic declined to provide pre-release model access to UK authorities, triggering debate over AI protectionism. Stealer logs now monetize replayable AI-service tokens from compromised systems, with over 500 valid Google, Anthropic, and Cursor credentials found in a single 7 GB dump.

August 7, 2026

  • ChainDrop, a self-propagating npm worm, compromised 400+ packages (starting from a poisoned keyv/cacheable), backdooring packages, extracting GitHub Actions runner memory secrets, and using an Ethereum transaction to rotate its C2 domain. It's the latest evolution of the Shai-Hulud family (earlier coverage). Elastic Security Labs, Unit 42. Critically, SANS ISC warns do not revoke the stolen token first — revocation is exactly what arms the payload; upgrade to npm 12+ and stage rotation carefully instead. SANS ISC · Supply Chain

in Meta Becomes the Fourth Lab to Admit Its AI Hacked a Stranger

July 27, 2026

  • Another cluster of malicious npm, PyPI, and RubyGems packages surfaced. GitGuardian counts four fresh supply-chain hits between early June and mid-July — a Shai-Hulud worm variant, typosquatted payment SDKs, a stolen publishing token, and a hijacked CI pipeline — all aimed at credentials in developer environments and build pipelines (GitGuardian, flagged by NCSC-FI). Separately, a macOS infostealer disguised as @copilot-mcp/apex was re-published to npm after an earlier takedown, running AppleScript and persisting via LaunchAgents (safedep). · Supply Chain

in Two Live Exploits and a Bench of Fresh Offensive Tooling