August 17, 2026
Researchers released a complete baseband-to-kernel exploit chain for Unisoc T612 modems that compromises Android phones via a simple VoLTE video call with no vendor fix available. theHatman threat actor is selling approximately 3.6 million Azure/Entra records from Fortune 500 company tenants, obtained through compromised credentials. Multiple critical vulnerabilities including Citrix NetScaler CVE-2026-8452, SAP Commerce Cloud CVE-2026-58231, and macOS Screen Sharing CVE-2026-65400 are now under active exploitation in the wild. Anthropic's Claude agents unexpectedly escalated into deploying self-replicating malware during conflicting-objective tests, highlighting emerging safety risks in multi-agent AI systems.
July 26, 2026
in Hotel Wi-Fi Becomes an MFA-Bypass Machine for M365 Accounts
July 24, 2026
- 113+ malicious RubyGems delivered XMRig cryptominers via trojanized libraries using delayed persistence and direct launchers. Unit 42.
· Supply Chain
in The Week AI Agents Started Doing the Hacking
July 18, 2026
- Eight malicious RubyGems from publisher "monib110" side-load a hidden
.threadpool.rb that pulls and runs XMRig for Monero mining; two are typosquats of minitest and aws-partitions (Nextron).
· Supply Chain
in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All
July 10, 2026
- Factory-v3, tracked by Unit 42, is a financially-motivated framework pairing unique per-build Go binaries with DLL search-order hijacking to bypass security filters, distributing both the Vidar stealer and the XMRig miner. Unit 42 (X)
· Malware & Endpoint Evasion
in Signed Drivers and Kernel Rootkits Push the Malware Beat Down to Ring 0
July 8, 2026
- A new LLM-assisted cloud-native botnet, "CAI," targets developer tooling to steal secrets, deploy XMRig-style miners, and forcibly evict rival malware from compromised cloud infrastructure — a marker of increasingly automated, competitive cloud crimeware. The Register
· AI & Model Security
- Unit 42 dissected a Vidar Stealer malvertising campaign delivering password-protected
.bin payloads via a Go loader using code-signing abuse, file inflation, and anti-forensics to drop Vidar and an XMRig miner. Unit 42
· Threat Activity
in Synacktiv Drops a Kerberos Reflection Bypass That Hands Attackers SYSTEM