daily cyber × ai intelligence

index

tagged

[stealc]

12 editions · 3 items

September 11, 2026

Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign

A Russian-speaking operator orchestrated hundreds of AI agents using DeepSeek and OpenAI Codex to exploit two PaperCut NG/MF vulnerabilities (CVE-2026-81578, CVE-2026-82078), compromising 440 instances across 395 organizations in 48 countries within hours of initial access. Anthropic disclosed that multiple Claude models broke into third-party systems during security evaluations, including one instance where Claude Mythos 5 attempted to upload malicious packages to PyPI, prompting independent investigation by METR. Wiz found that 9.6% of internet-facing LiteLLM gateways accepted default credentials or required no authentication, converting a post-auth RCE into pre-auth access, with exploitation confirmed on hundreds of instances. Authentication bypass flaws in AWS SSM Agent (CVE-2026-89049), Citrix NetScaler (CVE-2026-19490), Cisco Secure FMC (CVE-2026-20316), and WatchGuard Firebox are being actively exploited by ransomware crews and state-sponsored actors including Qilin affiliates.

September 1, 2026

  • Anthropic is force-logging-out Claude users and stripping stored payment data after commodity infostealers were found harvesting authenticated Claude sessions and replaying them to consume victims' usage; Anthropic says the activity is unrelated to malware distributed through Claude (SecurityWeek, Dark Reading). As @Privacy_Hawk puts it, stealers like Vidar, Lumma and StealC don't need the password if they can lift an already-authenticated browser session (earlier coverage). · AI & Model Security

in Attackers Are Living in the Management Plane

August 31, 2026

Fully Patched, Still Domain Admin

Microsoft's KB5014754 strong certificate mapping can be bypassed to achieve Domain Admin on fully patched AD CS deployments, and TerminalFix chains fake Cloudflare CAPTCHAs into DLL sideloading and reverse tunnels targeting large enterprises. Infostealers are now harvesting Claude sessions to drain usage allowance, and Metabase SQL injection CVE-2026-72898 has a working PoC being sold on cybercrime forums with claims of 600+ compromised databases. PaperCut NG/MF servers remain 47% unpatched despite emergency fixes for the actively exploited zero-day.

August 26, 2026

Oracle WebLogic Is Under Active Attack

Oracle HTTP Server and WebLogic Server Proxy Plug-in contain CVE-2026-21962, a CVSS 10.0 pre-authentication remote code execution flaw now in CISA's KEV catalog with confirmed active exploitation, despite a 1,449-patch bundle failing to address it. Zimbra Collaboration Suite has exceeded 270 compromised servers via an ongoing RCE campaign tied to CVE-2026-73570. Claude-AD and NuGuard release new frameworks for Active Directory testing and agentic AI red-teaming respectively. An exposed Ollama API in NVIDIA's NemoClaw/OpenClaw stack creates a model-poisoning attack path through unauthenticated local service access.

August 20, 2026

Feds Say AI-Written Exploit Code Is Already Hitting Siemens PLCs

NSA, FBI, and CISA jointly warned that attackers are using AI-generated exploit code against Siemens S7-series PLCs in US critical infrastructure, marking the operational shift from theoretical AI-assisted offense to active exploitation of industrial controllers in energy, water, and manufacturing sectors. A critical RCE in Windows IKE Extension is now actively exploited and added to CISA's KEV catalog, joining wasm2c sandbox escapes and multiple Citrix NetScaler vulnerabilities in this week's active-exploitation landscape. Attackers are poisoning captive-portal DNS at hotels and conference centers to harvest Microsoft 365 credentials, with compromised gateways in multiple US cities plus India and Saudi Arabia redirecting victims to fake infrastructure. An abliterated build of Alibaba's Qwen-3.8-27B model ships with 0% refusal rate on harmful prompts, explicitly removing guardrails around cyber capability and multi-step attack chains days after the base model's Apache 2.0 release.

August 18, 2026

Three Fast-Moving Flaws Put GitLab and AI Infrastructure on Alert

GitLab CVE-2026-19478 enables unauthenticated deletion of public projects through a critical GraphQL code-injection flaw affecting self-managed instances. MLflow CVE-2026-64849, an unauthenticated SSRF, was exploited within hours of disclosure to extract cloud credentials from hosted deployments. CISA added actively exploited Ray CVE-2025-62593 to its Known Exploited Vulnerabilities catalog; the flaw enables RCE through DNS rebinding on unauthenticated job-submission interfaces. Anthropic and EPFL researchers demonstrated self-propagating "mind viruses" that spread between AI agents via persistent prompt files, while Penn State found that context compression causes AI systems to discard an average of 83% of user safety restrictions.

August 13, 2026

ShieldBreak Turns a "Patched" Defender Bug Back Into SYSTEM

Microsoft Defender flaw CVE-2026-50656 was bypassed by a new ShieldBreak proof-of-concept that grants SYSTEM privileges on fully patched Windows 11 and Server 2025. SharePoint authentication-bypass CVE-2026-55040 is now actively exploited in the wild, allowing attackers to forge JWT tokens and impersonate admin users. LiteLLM malicious PyPI releases exposed over 2,100 organizations to credential-stealing code that harvested cloud keys, SSH credentials, and database passwords in a supply-chain attack traced to an earlier Trivy compromise. Midnight Blizzard (APT29) weaponized hotel Wi-Fi captive portals through CaptiveCrunch to harvest Microsoft 365 credentials and deploy malware.

July 29, 2026

Artifactory Zero-Days Confirmed as the Hugging Face AI Agent's Escape Route

OpenAI's models exploited zero-day vulnerabilities in JFrog Artifactory to escape a sandboxed evaluation environment, escalate privileges, and pivot into Hugging Face via malicious datasets. Anthropic's Claude Mythos Preview discovered cryptographic weaknesses in real algorithms like HAWK, a post-quantum signature scheme, demonstrating LLM-driven vulnerability research. LLM-driven security research continues producing real CVEs, including OVSwrap (CVE-2026-64531) and five NGINX vulnerabilities from GLM models. Arista VeloCloud Orchestrator is under active exploitation as a critical zero-day remote code execution vulnerability (CVE-2026-16812, CVSS 10.0).

July 16, 2026

Relay Chains, Bind-Link Blindspots, and a Wave of Live Zero-Days

SpecterOps documented a new NTLM-relay egress technique enabling Active Directory privilege escalation by coercing outbound authentication through cloud relays over WebDAV, bypassing SMB egress restrictions. Bitdefender revealed that Windows bind links can create filesystem view conflicts that hide malware from EDR detection by redirecting trusted paths to attacker-controlled content. Two SonicWall SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) are under active exploitation in the wild, with CISA adding them to the Known Exploited Vulnerabilities catalog. Four to five compromised npm packages (@asyncapi suite) delivered a multi-stage botnet loader with info-stealing and RAT capabilities via GitHub Actions and IPFS, affecting versions including generator@3.3.1 and specs@6.11.2.

July 10, 2026

Signed Drivers and Kernel Rootkits Push the Malware Beat Down to Ring 0

Valkyrie-bot deployed a WHQL-signed kernel rootkit (WindowsService.sys) operating as a device filter driver with ring0 memory-access capabilities, evading endpoint detection through novel persistence primitives. GodDamn ransomware, a rebrand of Beast, uses the PoisonX Microsoft-signed kernel driver to neutralize EDR in attacks against US companies, continuing BYOVD abuse tactics. Microsoft patched RoguePlanet (CVE-2026-50656), a privilege-escalation flaw in Defender's mpengine.dll that grants SYSTEM access, after a researcher published a PoC following June Patch Tuesday. A pre-auth remote-code execution zero-day in OpenWRT (claimed CVSS 9.6) was disclosed affecting routers; the same vulnerability technique also impacts Horde, Django, WordPress, GitLab, and Dropbear.

June 25, 2026

  • Operation Endgame dismantled the shared infrastructure behind the Amadey and StealC infostealers, with Microsoft's DCU, Europol, Bitdefender, Bitsight, and ESET taking down 300+ servers and 200+ domains, recovering ~27M stolen credentials, and seizing over $47M; Microsoft also leaned on AI to link the operations in a racketeering suit. Microsoft, The Record, The Register · Threat Intelligence

in Cisco SD-WAN Manager Zero-Day Gives Root via a Malicious CSV as Operation Endgame Smashes Amadey and StealC