ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them.

This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough.

So the threat landscape is not getting cleaner. It is just getting more places to make the same mistake. Here’s what showed up this week.

The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.

  • Malware PPI operation exposed

    CL-CRI-1171 Offers PPI Marketplace

    A threat actor known as CL-CRI-1171 has stayed under the radar for at least two years, offering a pay-per-install (PPI) marketplace that allows other threat actors to distribute their malware through YouTube channels and a parallel search engine optimization (SEO)-poisoning funnel. "These channels were actively interacting with viewers to promote gaming content laced with links to download malware," Palo Alto Networks Unit 42 said. "Although the videos provided real content for gamers, they also served as the delivery vehicle for infection, prompting viewers to download malicious tools. The SEO funnel targeted a more professional audience, promoting trojanized software that resulted in malware deployment on corporate endpoints, including critical infrastructure and even government entities." Both these chains lead to a custom loader called OfferLoader that has delivered three payloads between July 2025 and April 2026: Docro Hijacker (a Chrome backdoor that can bypass modern integrity protections), ARKTunnel (a WebSocket tunneling RAT), and a new variant of a previously unnamed cross-platform backdoor that's been codenamed Insomnia remote access Trojan (RAT) and can target both Windows and macOS. Post-April 2026, the PPI infrastructure has led to GCleaner and Socks5Systemz.

  • Exposed LocalAI instances compromised

    Large-Scale Attacks Target LocalAI Infrastructure

    A large-scale campaign has been found to target LocalAI instances exposed to the internet without authentication and achieve command execution inherent in MCP STDIO configuration. "Attacker artifacts indicated that 230 of 243 unauthenticated LocalAI instances were assessed as exploitable," Oasis Security said. "Callback logs independently confirmed command execution with root privileges on 23 servers. Post-compromise activity included exfiltration from a workstation associated with the Thai military and collection of 127 AWS credential records." The unknown threat actor is said to have selected high-value infrastructure from those LocalAI targets and compromised a desktop LocalAI workstation and a related private network. This was followed by exfiltration of sensitive data, including personal information, GPS coordinates, banking-application screenshots, and national ID card scans. Additional compromise activity consisted of exploitation of legacy infrastructure, authentication bypass, a broad sweep of cryptocurrency wallets and API keys, and theft of AWS ECS task credentials.

  • Agents rewrite their own models

    AI Agents Can Retrain Own Models Mid-Task

    New research from Irregular has found that AI agents can retrain the model that powers them, in the process leaking secrets and eliminating refusals the model had been previously trained to enforce. "Given a routine software-maintenance task to fix incorrect application responses, the agent identified the shared model as the source of the problem, fine-tuned it, and replaced the model powering both the application and future instances of the agent itself," Irregular said. "It did so without being instructed to train, modify the model, or deploy a replacement." This phenomenon has been codenamed agentic self-modification. "Nothing in these experiments establishes malicious intent, self-preservation, or deception; the agents modified models because training appeared to help accomplish the assigned engineering task," Irregular added. "Agentic self-modification can arise during ordinary software maintenance when a coding agent has access to the model weights, training tools, and a deployment path to modify the model directly."

  • AI agent linked to data breach

    Spain's Data Protection Agency Receives First Report of AI-Powered Data Breach

    The Spanish Data Protection Agency (AEPD) said it was notified of a data breach that was allegedly executed by an AI agent. "The attacker launched a scan for vulnerabilities in generic files and successfully logged in," AEPD said. "Once inside the system, the attacker began independently searching for vulnerabilities in the application; once found, this allowed the attacker to modify personal data and access invoices. What is relevant from a data protection perspective is that a third party appears to have used an AI agent as a tool to successfully chain together different phases of the attack."

  • Ransomware exploits VMware RCE

    Critical VMware RCE Flaw Now Exploited by Ransomware Gangs

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that ransomware gangs have now started exploiting a critical VMware vCenter vulnerability patched in July. The flaw, tracked as CVE-2026-59310, is a critical directory traversal vulnerability in the vCenter Syslog server that unauthenticated attackers can exploit to execute arbitrary code. In August 2026, German incident response company QUIRSO uncovered evidence that a China-nexus advanced persistent threat (APT) has been exploiting the flaw shortly after public disclosure.

  • Oracle patches 800-plus flaws

    Oracle Announces Patches for 100s of Flaws

    Oracle has announced the release of new security patches as part of its September 2026 Critical Security Patch Update (CSPU). The patches address over 800 flaws. None of them have been flagged as actively exploited. "It's hard not to sound like a broken record these days when talking about security updates," Tyler Reguly, Fortra's Associate Director of Security Research and Development, said. "We're continually seeing large numbers of vulnerabilities and we're all starting to feel a little burnt out. I've said it before and I say it again, there is a light at the end of this tunnel and the record numbers of patches for record numbers of vulnerabilities will not last. I'm confident of this. Do everything you can to avoid burning out and just work on surviving this onslaught. I think that CISA BOD 26-04 did a great job of helping people to understand how to prioritize based on risk. I think that a 3-day turnaround is very tight when you need to also test your patches, but it helps lay out priorities that make a real difference – is it publicly exposed, is it on the Known Exploited Vulnerabilities list, can it be automated, and does it give complete control. When you can answer these questions, you can start to identify the risk that it plays. Are there other components you can include? Sure, but this is a great start if you don’t really know what risk looks like for your organization. Once you know what risk looks like, you can start to prioritize your patches more appropriately."

  • Insider SIM swaps draw prison term

    Oregon Man Sentenced to 16 Months in Prison for SIM Swaps

    Former Oregon-based AT&T Store employee, Kenneth Carter, 44, has been sentenced to 16 months in prison for abusing his access to perform SIM swaps that helped criminals take over customers' bank accounts. Three victims suffered intended losses of nearly $600,0000, with Carter typically receiving $1,000 to $2,000 for each fraudulent SIM swap. Carter, who worked at the store from May 2018 to November 2019, has also been ordered to pay $99,528 in restitution. Carter pleaded guilty to the crimes earlier this March.

  • AI drives malware evasion

    Threat Actors Use AI for Polymorphic Malware Evasion

    Google-owned Mandiant said it has observed advanced malware campaigns using embedded, lightweight AI models to facilitate stealthy, long-term persistence within victim networks. "In these environments, the malware does not rely on a static payload that might be flagged by traditional signature-based detection," Google said. "Instead, it uses local AI inference to analyze the host environment and identify the specific security tools currently active on the endpoint. During the attack phase, the malware dynamically rewrites its own command execution strings at runtime to bypass detection. By constantly altering the syntax and logic of its automated actions, the payload successfully evades static endpoint detection and response (EDR) signatures." The tech giant also warned that bad actors are using AI command-line interfaces (CLIs) to orchestrate and manage command-and-control (C2) infrastructure through natural-language queries and breaching cloud environments to "initialize an unisolated VM instance and transform it into a live, AI-assisted offensive hub" with an aim to debug and optimize offensive tools in real-time.

  • Cyclops Blink returns on Cisco FMC

    New Variant of Cyclops Blink Spotted

    Sophos said it observed a variant of Cyclops Blink, a modular botnet and malware framework, on multiple compromised Cisco Firewall Management Center (FMC) devices in August 2026. "Unlike the WatchGuard-focused samples documented in 2022, the 2026 variant runs on x86-64 Linux and uses generic System V (SysV) persistence rather than vendor-specific firmware modification," Sophos said. "This change broadens the range of potentially compatible network-edge appliances. The implant's expanded capabilities include active network and service discovery, programmable packet surveillance, file transfer, and payload execution, allowing a compromised device to serve as a platform for internal reconnaissance, intelligence collection, and follow-on operations. The malware supports five worker modules that perform host reconnaissance, file transfer and payload execution, active network discovery, selective packet capture and content surveillance, and persistence. Cisco has described the Cyclops Blink activity as one of three separate campaigns involving two vulnerabilities in its Secure FMC software: CVE-2026-20079 and CVE-2026-20316. The findings once again show how compromised network appliances and other edge devices can give attackers a privileged vantage point into enterprise environments and allow them to observe traffic, conduct network probes, and launch additional attacks.

  • RF signals leak analog secrets

    New InjectEave Attack Detailed

    A group of academics from the Hong Kong University of Science and Technology and the Hong Kong Polytechnic University has demonstrated InjectEave, a new class of electromagnetic side-channel attacks in which an external RF signal induces hardware nonlinearities that leak low-frequency analog secrets. "This vulnerability exists in ubiquitous nonlinear analog interfaces across the 11 commercial off-the-shelf devices we evaluated, allowing attackers to eavesdrop on headphone and landline audio, infer smart-fan speed and smart-lamp brightness, and recover other analog secrets that digital encryption and software defenses can hardly protect," the researchers said. "We demonstrate eavesdropping on audio played through wired and wireless headphones from up to 30 m away, as well as in through-wall scenarios, and characterize injection-induced EM leakage of other low-frequency secrets." Tests on 11 commercial devices, including headphones, VoIP phones, smart fans and lamps, showed that attackers could recover private audio or determine appliance states without physical access or modifying the devices. "Hardware-aware mitigations such as twisted-pair wiring, shielding, and filtering can lower the energy that the injected carrier couples into the device, reducing the exposure," the researchers said. "These mitigations raise the bar, but they do not guarantee immunity."

  • Settra ransomware expands attacks

    Settra Ransomware Emerges

    A new ransomware group called Settra has deployed MeshAgent remote access software in two intrusions analyzed by Huntress. "Although the initial access method could not be confirmed, both attacks used ransomware executables named after the victim organization's domain and followed a highly similar operational pattern," Huntress said. "In the observed intrusions, attackers deployed remote monitoring and management (RMM) tools for persistence and then encrypted files, dropped RESTORE_FILES.txt ransom notes, cleared Windows event logs, and disabled Windows recovery options. One incident also included signs of Bring Your Own Vulnerable Driver (BYOVD); as well as a notable misspelling by the threat actors during the attack, which left them unable to clear the Windows Defender Event Log." Settra emerged in June 2026 and has mainly targeted entities in the U.S., Germany, the U.K., Canada, and Australia spanning technology, professional services, manufacturing, and retail sectors, according to researcher Rakesh Krishnan. The group has claimed 70 victims to date. In another case investigated by Cynet, "the ransomware engine was buried inside an encrypted blob and gated behind an operator-supplied password. Without the correct password, the executable simply terminated, leaving researchers and automated sandboxes with little to analyze."

  • Uncensored AI sold underground

    Uncensored Luciferus AI Service Advertised

    A threat actor named Optimus_Prime (aka OptimusPrimero) is advertising an uncensored AI subscription service named Luciferus on the Exploit underground forum as an alternative to jailbreaking mainstream providers like ChatGPT, Claude, or Gemini. "The August advertisement describes Luciferus as an AI system that answers requests without moral or ethical restrictions and claims that it is based on a proprietary model that has '120 billion parameters,'" Sophos said, adding the tool is likely built on Alibaba's Qwen family of AI models. The service costs $35 per month and claims to support three models on its website ("luciferus[.]io"). "The emergence of Luciferus aligns with a broader trend in which threat actors are increasingly commercializing AI through underground forums, Telegram channels, and cybercriminal marketplaces," Sophos said. "Rather than developing their own models, many threat actors are offering access to uncensored or modified LLMs via AI-as-a-service schemes in the same way malware, phishing kits, and ransomware are commoditized."

  • VectraRAT MaaS hits the market

    New VectraRAT MaaS Goes on Sale

    SOCRadar has disclosed details of a new malware-as-a-service (MaaS) platform called VectraRAT that's been built from scratch and is available for $250 a month. "It gives operators hidden-desktop control, keylogging, clipboard hijacking, browser credential theft, and a UAC bypass that elevates with no prompt," SOCRadar said. "It pairs a Go control server called VectraHub, with a Vue3 operator panel compiled into the binary, with a native C++ Windows implant. The two speak a proprietary binary TCP protocol using MessagePack over port 3308." The operator "Vectra" is a rebrand of "Nyxel," active since at least August 2022. The malware is delivered via Amadey and ClickFix lure pages.

  • Casbaneiro hits Latin America

    Latin America Targeted with Casbaneiro

    A Casbaneiro attack campaign was observed targeting users in Latin America in August 2026, using phishing emails and PDF files themed around fake invoices and legal notices as an initial access vector. "Casbaneiro exhibits characteristics common to other malware families targeting financial institutions and users in Latin America, including clipboard injection and the use of fake windows to facilitate fraudulent activities," Fortinet FortiGuard Labs said. "In this attack campaign, the malware is delivered via a multi-stage infection chain that includes an HTA downloader and an AutoIt loader, with the latter responsible for injecting the final payload into a Windows process."

  • KATARU brute-forces Telnet access

    KATARU IoT Malware Breaks In via Telnet Brute-Force

    An IoT malware dubbed KATARU has leveraged Telnet credential brute-forcing to break into Linux and embedded systems. "While it retains familiar Mirai-style botnet functionality, it stands out for its unusually broad capability set, including multiple Linux n-day local privilege escalation exploits, extensive persistence coverage across Linux and embedded environments, encrypted C2 communications, anti-analysis checks, and decoy traffic," Nozomi Networks said. The end goal is to establish communications with a C2 server and receive DDoS attack commands. It's suspected that KATARU was assembled with AI assistance.

  • AI boosts LATAM intrusions

    AI Tool Use Targeting Orgs in Latin America

    Palo Alto Networks Unit 42 said it detected two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations in Latin America that leverage AI to enhance the threat actor's capabilities: CL-CRI-1131, which has used living-off-the-land (LotL) techniques and executed iterative batch scripts to troubleshoot issues and exfiltrate sensitive data, and CL-CRI-1163, which has used resume-themed phishing emails to deploy custom RATs and tunneling tools, including a Go-based SOCKS5 proxy. CL-CRI-1131 impacted a transportation organization, alongside federal government ministries and municipal water utilities in Mexico and Ecuador, while CL-CRI-1163 has singled out the Brazilian financial sector. "The threat actors behind the CL-CRI-1131 and CL-CRI-1163 campaigns have enhanced their technical capabilities by incorporating commercial LLMs into their workflows," Unit 42 said. "This integration enables them to author advanced proxy configurations and dynamically address complex execution failures. However, the infrastructure they deployed to leverage this AI became their Achilles' heel."

  • Azalea RAT enables full control

    Azalea RAT Offers Extensive Remote Control

    A MaaS offering called Azalea RAT has been promoted as a modular malware platform with a wide range of post-compromise capabilities. "Azalea RAT combines remote administration, stealth mechanisms, privilege escalation, persistence, information theft, and an extensible plugin architecture," Rubrik Zero Labs said. "Once executed, the RAT allows an operator to manage the infected host, execute commands and additional payloads, collect sensitive information, manipulate system resources, and maintain remote access through an extensive command-and-control framework." The .NET RAT is designed for persistent and interactive control over compromised Windows systems. Azalea RAT arrives in the form of a Windows shortcut that masquerades as a PDF document to trigger the execution of a first-stage loader, which then performs anti-analysis checks before extracting a DLL that's responsible for setting up Microsoft Defender exclusion paths and ultimately launching the RAT.

  • Infostealers target AI agent data

    Infostealers Come for AI Agents

    Infostealers like Amatera and Remus are expanding their data collection focus beyond browser passwords and cryptocurrency wallets to collect access tokens, MCP configurations, prompt histories, and project data stored by AI tools. "Amatera targets data associated with Cline and Continue, while Remus targets Claude, Cursor, and OpenCode," Gen Digital said. "The figures may overlap and describe detections rather than successful infections, but they show that AI agent data has already entered the information-stealer economy. What the malware is collecting goes far beyond harmless preferences. Depending on the agent and its configuration, local files may contain access and refresh tokens, credentials stored in MCP configurations, prompt histories, conversation databases, account details, and traces of the projects a developer has been working on. In one archive, an attacker may obtain both the means to access an account and the context needed to understand what is valuable behind it."

  • Three Russians extradited over cybercrime cases

    U.S. Extradites 3 Russians Accused of Cybercrime

    The Moscow Times has reported that U.S. authorities have extradited three Russian nationals since June to face charges in separate cybercrime cases involving malware attacks, bank fraud, and the hacking of government and private-sector organizations. One involves Searzhudin Aktulayev, 40, who was arrested in Cyprus in May 2025 and extradited to the U.S. on August 28, 2026. The two other cases relate to Russian web developer Sergei Filimonov and Denis Obrezko, who was arrested in Thailand in November 2025 and was extradited to the U.S. in June in connection with a large-scale cyber espionage campaign being carried out by a group known as ​Void Blizzard.

  • ClickFix chain delivers SloppyRAT

    SloppyRAT Delivered via ClickFix Lures

    A new malware called SloppyRAT, likely leveraged by a ransomware-related threat actor, is being delivered through a multi-stage ClickFix infection chain to establish a foothold for lateral movement. It was identified by Zscaler ThreatLabz in June 2026. "The malware supports a variety of features including a large number of built-in PowerShell-like commands, encrypted code blocks, EtherHiding for command-and-control (C2) resolution through the Polygon JSON-RPC protocol, and multiple anti-analysis techniques," ThreatLabz said. "SloppyRAT uses certificate pinning to prevent networking monitoring solutions from using man-in-the-middle (MitM) attacks to inspect TLS traffic. Beyond SloppyRAT's capabilities, the malware is notable because the codebase includes numerous software flaws, which suggest that it is still under development."

  • Five-stage chain drops AsyncRAT

    AsyncRAT Distributed via AutoIT

    A five-stage infection chain has been observed using a socially engineered batch file to deliver AsyncRAT. While the exact initial access vector is unknown, threat actors are known to rely on phishing emails, malicious links, trojanized software, and instant messaging platforms to distribute malware. "The batch file launches PowerShell with a hidden window and a disabled profile, then reassembles a Base64 payload from ten fragments, strips deliberately inserted junk characters, and decodes it through repeating key XOR," Point Wild said. "It drops three files into an obfuscated build-specific folder under %LOCALAPPDATA%Temp: a renamed but legitimate signed AutoIT interpreter, an AutoIT loader script (kojuyn.ini), and an extensionless encrypted payload. The batch file written to the Startup folder relaunches the pair at every logon, with no registry key." The AutoIT script is designed to decrypt the payload in memory and inject it into a Microsoft-signed Windows process. The payload then triggers a three-step process to launch the final AsyncRAT malware.

  • Black Axe leaders extradited

    5 Alleged Black Axe Leaders Extradited to the U.S.

    Five alleged Nigeria-based leaders of the Black Axe cybercrime syndicate (Perry Osagiede, Franklyn Edosa Osagiede, Osariemen Eric Clement, Collins Owhofasa Otughwor, and Musa Mudashiru), known for their involvement in global-scale cyber-enabled financial fraud, have been extradited from South Africa to the U.S. to face wire fraud and money laundering charges. Perry Osagiede, Franklyn Osagiede, and Clement are also charged with wire fraud, and Perry Osagiede, Franklyn Osagiede, and Otughwor are also charged with aggravated identity theft. "From at least 2011 through 2021, the Black Axe defendants and other conspirators worked together from Cape Town to engage in widespread internet fraud involving romance scams and advance fee schemes," the U.S. Justice Department said. "Many of these fraudulent narratives involved claims that an individual was traveling to South Africa for work and needed money or other items of value following a series of unfortunate and unforeseen events, often involving a construction site or problems with a crane. The conspirators used social media websites, online dating websites, and voice over internet protocol phone numbers to find and talk with victims in the United States, while using a number of aliases. The conspirators’ romance scam victims believed they were in romantic relationships with the person using the alias and, when requested, the victims sent money and items of value overseas, including to South Africa. Sometimes, when victims expressed hesitation in sending money, the conspirators used manipulative tactics to coerce the payments, including by threatening to distribute personally sensitive photographs of the victim."

  • ATM jackpotting plot ends in guilty pleas

    5 Venezuelan Nationals Plead Guilty to ATM Jackpotting

    Five Venezuelan nationals have pleaded guilty to attempting to steal U.S. currency from ATMs. Luis Alberto Velasquez-Artigas, 27, Royder Adrian Figuera-Perez, 29, Javier Mejia, Jr, 27, Gabriel Alexjandro Corales-Garcia, 33, and Italo Lizandro Corrales-Carrillo, 26, all pleaded guilty to one count of conspiracy to commit bank larceny. "In December 2025, the defendants traveled from Indiana to Kansas to attempt to steal cash from ATMs in Wamego and Manhattan through jackpotting," the Justice Department said. "Their plan was for one conspirator to physically install the malware into the ATMs, then later for the group to remotely activate a command causing the ATMs to dispense cash that they would go collect. The conspirators were unsuccessful in installing the malware on the ATM in Wamego, but their attempts at installing the malware triggered the alarm, causing law enforcement to respond, and the culprits didn’t return to the site. In Manhattan, the group was equally unsuccessful in getting the ATM to dispense money. Both attempted thefts were captured by surveillance cameras, and the perpetrators were arrested a few days later." According to the U.S. Federal Bureau of Investigation, 1,900 incidents have been recorded since 2020. In 2025 alone, there were more than 700 incidents with more than $20 million in losses.

  • Eight-year sentence for ATM jackpotting

    Venezuelan Man Sentenced to 8 Years in Prison for ATM Jackpotting

    In more ATM jackpotting action, another 27-year-old from Venezuela, Juan Manuel Gouveia-Aguilera, has been sentenced to eight years in prison for his role in a conspiracy to deploy Ploutus malware and steal millions of dollars from ATMs in the U.S. Gouveia-Aguilera has also been ordered to pay restitution as part of his sentence. "The Court found Gouveia-Aguilera to be responsible for more than $3.5 million in losses and this sentence is believed to be the longest federal sentence imposed for an individual’s role in ATM jackpotting," the Justice Department said. "Specifically, Gouveia-Aguilera was convicted of conspiracy to commit bank fraud, conspiracy to commit bank burglary and fraud in connection with computers, bank fraud, bank burglary, and fraud in connection with computers following a guilty plea." In recent years, cyber criminals have used ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL, and Ploutus malware to steal cash in ATM jackpotting attacks.

  • Nearly $13B tied to suspected crypto scams

    FinCEN Identifies ~13B Linked to Suspected Digital Asset Scams

    The U.S. Department of the Treasury's Financial Crimes Enforcement Network (FinCEN) said it analyzed 33,904 Bank Secrecy Act (BSA) reports involving suspected digital asset investment scam-related activity filed between September 8, 2023, and December 31, 2025, totaling about $12.7 billion in financial activity tied to suspected digital asset investment scams perpetrated by overseas scam centers. "Actors often used assumed names or identities to pose as potential romantic partners, new friends, or new business partners to target scam victims," FinCEN said. "Scammers often created websites and mobile applications that imitated legitimate investment services to carry out their criminal activity," FinCEN said scam center operators are using guarantee marketplaces to purchase illicit services, such as online account creation, phishing, and money laundering services.

The lesson this week is not that attackers suddenly got smarter. It is that useful things keep becoming attack surfaces faster than teams learn to treat them that way.

So check what is exposed. Check what holds tokens, prompts, configs, and keys. Kill weak defaults. Patch the boring old stuff too. New tech does not cancel old mistakes; it just gives them more places to hide.

That is the useful part of weeks like this. Not panic. Better instincts. Fewer easy wins left on the table.

Deja una respuesta

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *