一个浏览器。一个插件。一个软件包。一个登录界面。都是些寻常的东西。这基本上就是本周的问题所在。
麻烦不断出现在人们已经信任的事物内部:代码走向失控、旧载荷死灰复燃、系统暴露、检查机制薄弱、虚假修复,以及看起来过于容易的攻击路径。就连研究领域也变得杂乱无章,发现增多,自动化程度提高,但清晰度却未必随之增加。
这里没有什么需要过度渲染的戏剧性情节。只是留下了大量未关闭的小门。以下是本周发生的情况。
⚡ 本周威胁
思科警告称ISE身份验证绕过漏洞正被积极利用——思科警告称,存在一个影响Identity Services Engine(ISE)的全新最高严重性安全漏洞,该漏洞已被证实处于积极利用状态。该漏洞被追踪为CVE-2026-76460(CVSS评分:10.0),可能允许未经身份验证的远程攻击者绕过身份验证。“此漏洞是由于API端点上的身份验证控制不足所致,”思科表示。“攻击者可以通过向受影响的API端点发送精心构造的请求来利用此漏洞。成功的利用可使攻击者通过绕过基于Web的管理界面,获得对受影响设备的未授权访问。”
🔔 头条新闻
美国查封与DDoS攻击相关的NightmareStresser域名——在美国法院授权的行动中,执法部门查封了两个与NightmareStresser相关的域名,该服务提供分布式拒绝服务(DDoS)租赁业务。据评估,自2022年以来,NightmareStresser已被用于对全球各地的受害者发动数十万次实际或 attempted DDoS攻击。美国司法部表示,这些攻击的目标包括教育机构、政府机构、游戏平台以及数百万民众。
使用Claude黑客攻击OpenAI——Hacktron声称,它利用Anthropic的Claude Opus 5串联了两个关键漏洞——OpenAI身份基础设施中的SSO配置错误和Discourse社区论坛中的libheif远程代码执行(RCE)漏洞(CVE-2026-32882)——从而获得对OpenAI员工ChatGPT账户的未授权访问,并利用这些账户访问OpenAI的内部存储库。该问题在负责任披露后14小时内得到修复。上游方面,该缺陷已于2026年5月在libheif 1.22.0版本中得到修复。
Plugin4Shell导致AI编程代理出现零点击RCE——AIR Security展示了一个名为Plugin4Shell的漏洞,这是一种零点击远程代码执行(RCE)漏洞,它绕过了四个主要AI编程代理中的SHA固定验证:Claude Code、OpenAI Codex、GitHub Copilot和Google Gemini CLI。“在这种首例AI供应链攻击中,受信任的插件被静默替换为恶意插件,并绕过代理的SHA固定验证自动安装——这是一个任何市场都无法修复的缺陷,因此用户必须更新其代理,”AIR Security表示。“这是一种插件SHA固定验证绕过:代理会检出市场固定的确切提交,但从不验证它是否确实位于该处,因此控制插件仓库的攻击者可以使检出版本解析为恶意代码,同时固定验证看起来仍然有效。结果是在Claude Code、Codex、GitHub Copilot和Gemini CLI上实现零点击远程代码执行。”
OpenAI披露新的不对齐事件——OpenAI披露了六起过去六个月中发生的“意外或令人担忧的模型行为”实例,同时分享了一个用于报告、跟踪、调查和披露模型不对齐的新框架,以提高透明度。“随着AI系统变得越来越先进并得到更广泛的部署,我们需要在对齐研究的进展方面建立更广泛、信息更充分的共识,”OpenAI表示。“我们认为,AI行业尚未将对齐和监控问题解决到足以继续以最高速度负责任地大规模扩展的程度。”
克里姆林宫银行恶意软件劫持 Chrome 和 Edge 以窃取凭证——此前未公开记录的巴西银行恶意软件运营组织被发现提供名为 KREMLIN 的工具包。该威胁行为者自至少 2025 年 5 月起活跃,利用伪装成十余家巴西银行的诱饵,在 Google Chrome 和 Microsoft Edge 上安装恶意浏览器扩展。“KREMLIN 恶意软件生态系统采用多阶段 JavaScript 加载器、自定义 C++ 安装程序和恶意浏览器扩展来窃取凭证、会话令牌和敏感数据,”Elastic 表示。该活动被追踪为 REF9334。
🔥 热门 CVE
漏洞每周更新,补丁与利用程序之间的差距正在迅速缩小。以下是本周的重点:高危、广泛使用或已在野外被探测的漏洞。
查看列表,修补您现有的系统,并优先处理标记为紧急的项目——CVE-2026-58138(Orkes Conductor)、CVE-2026-58704(Google Pixel)、CVE-2026-90894 即 ParaShells(Parallels Desktop)、CVE-2026-82079(Nintendo Switch)、CVE-2026-89049(AWS Systems Manager Agent)、CVE-2026-43502 即 ZcopyReaper、CVE-2026-80844 即 DirtyAH6、CVE-2026-81000 即 TUNderflow、CVE-2026-68121 即 PPPoEject、CVE-2026-74469 即 DiagSpill(Linux 内核)、CVE-2026-70416、CVE-2025-43936(Dell ObjectScale 和 Elastic Cloud Storage)、CVE-2026-68488(Please Backup Manager)、CVE-2026-56711、CVE-2026-73324(VLC Media Player)、CVE-2026-65638(cPanel ConfigServer Security & Firewall)、CVE-2026-85982、CVE-2026-78626、CVE-2026-78623(Okta)、CVE-2026-0310(Palo Alto Networks PAN-OS)、CVE-2026-85061(MapLibre GL JS)、GHSA-rvhw-4hpw-9vrx、GHSA-rrgq-978q-36mq、GHSA-4xhx-8cv5-wh62、GHSA-8v35-895w-232p(ArangoDB)、CVE-2026-65812(Microsoft Teams for Android)、CVE-2026-80172、CVE-2026-61410、CVE-2026-80238(Dell Secure Connect)、CVE-2026-18851(Ivanti Endpoint Manager Mobile)、CVE-2026-91721、CVE-2026-91749、CVE-2026-91726、CVE-2026-93374、CVE-2026-93372(Google Chrome)、CVE-2026-92033、从 CVE-2026-92005 到 CVE-2026-92013、从 CVE-2026-92015 到 CVE-2026-92020、从 CVE-2026-92022 到 CVE-2026-92029、从 CVE-2026-92034 到 CVE-2026-92038(Mozilla Firefox)、CVE-2026-15315、CVE-2026-15316(TP-Link Tapo 摄像头)、CVE-2026-82232、CVE-2026-77147、CVE-2026-73178(Apache Syncope)、CVE-2026-76669、CVE-2026-76670、CVE-2026-76672、CVE-2026-76673、CVE-2026-76674(HPE Networking EdgeConnect SD-WAN 网关和 SD-WAN Orchestrator)、CVE-2026-73693、CVE-2026-73694、CVE-2026-73698、CVE-2026-73699(FileRun)、CVE-2026-39919(Ghostscript)、CVE-2026-91998(Casdoor)、CVE-2026-91932、CVE-2026-91931(Flowise)、CVE-2026-65400、CVE-2026-65414、CVE-2026-65346、CVE-2026-84607、CVE-2026-43790(Apple)、CVE-2026-90999(Sentry Seer)、CVE-2026-77692、CVE-2026-76163、CVE-2026-19667、CVE-2026-19666、CVE-2026-80274(ISC BIND 9)、CVE-2026-91843(Check Point)、CVE-2026-77179(Docker)、CVE-2026-81642、CVE-2026-82717(Unbound DNS)、Click2Shell(WordPress)、CVE-2026-28326、CVE-2026-28323、CVE-2026-28309、CVE-2026-28306、CVE-2026-28308、CVE-2026-28310、CVE-2026-28314、CVE-2026-28313、CVE-2026-28307、CVE-2026-28305、CVE-2026-28317、CVE-2026-28304、CVE-2026-28312、CVE-2026-28316、CVE-2026-28311、CVE-2026-28302、CVE-2026-28321、CVE-2026-28315(SolarWinds)、CVE-2026-89026(Issabel Framework)、CVE-2026-78175(Tutor LMS)、Dokploy 中的操作系统命令注入漏洞,以及 MLflow 中的 pickle 反序列化漏洞。
🎥 网络安全网络研讨会
如何在访问失控之前发现并控制 AI 智能体 → AI 智能体正在比大多数团队能够管理它们的速度更快地获取对应用程序、数据、凭证和工作流的访问权限。真正的问题不在于采用——而在于知道哪些智能体存在,它们能访问什么,以及访问权限在何处已悄然变得过于宽泛。本次网络研讨会将分解如何在不妨碍使用它们的团队效率的情况下,将 AI 智能体纳入控制范围。
AI攻击在几分钟内即可完成。以下是如何在运行时阻止它们的方法 → 由人工智能驱动的攻击正在缩短防御者的反应时间。当传统警报被调查时,攻击者可能已经渗透了整个环境。本次网络研讨会展示了运行时身份安全如何实时做出访问决策、更早地阻止高风险活动,并为安全团队提供对抗机器速度攻击的更好机会。
📰 全球网络安全动态
Google文档导致ClickFix攻击 — Huntress披露了一起ClickFix攻击的细节,一名安全研究人员在X平台上遭到伪装成加密货币营销高管的黑客目标攻击。“威胁行为者发送了一个指向真实Google文档的链接,该文档带有自定义侧边栏,旨在诱骗收件人下载恶意软件:macOS上的AMOS信息窃取器,或Windows上的PowerShell加载器链,”Huntress表示。“该Google文档展示了一个显示虚假解密失败消息的侧边栏,其中包含针对不同操作系统用户的所谓补救说明,包括将某些命令复制并粘贴到终端中的选项。这个ClickFix诱饵以及旁边的‘手动更新’按钮实际上就是恶意软件的投递载体。侧边栏本身是一个绑定到文档的Google Apps Script,因此无需下载任何内容即可运行。”该Apps Script在受害者的浏览器客户端执行,收集受害者的公共IP地址和地理位置,并扫描加密货币钱包。
Brevo供应链攻击在客户网站注入ClickFix脚本 — 客户互动平台Brevo成为供应链攻击的受害者,导致恶意代码被注入超过10万个网站。“2026年9月14日,攻击者利用被盗的Brevo Cloudflare API密钥在我们的账户上部署了一个Cloudflare Worker,”Brevo表示。“在大约五个半小时内,该Worker将恶意脚本注入brevo.com和sibforms.com的页面,以及客户嵌入其自身网站的三个JavaScript文件中。”该脚本向选定的访问者展示虚假的Cloudflare验证码提示,指示他们在计算机上粘贴并运行恶意命令,这种技术也被称为ClickFix。分享了攻击更多细节的Sansec表示,“攻击者利用嵌入的Brevo小部件在Brevo客户网站上安装WordPress恶意软件,并对其访问者发起ClickFix攻击。”总体而言,该事件向Brevo自身网站和超过10万个客户网站的访问者投递了恶意软件。该恶意软件包含两个组件:一个是在站点管理员访问其自身站点时安装的恶意WordPress插件,以及一个在向浏览客户网站或点击Brevo发送的活动电子邮件中的链接(包括取消订阅链接)的任何人显示的ClickFix覆盖层。本月早些时候,Brevo披露了一起独立事件,攻击者劫持了客户账户并发起针对Brevo客户下游用户的钓鱼攻击。“攻击者利用了Brevo处理SAML SSO方式的漏洞以访问138个Brevo账户,”Brevo表示。“其中6个账户被用于向存储在那里的联系人发送钓鱼电子邮件,而对于43个账户,他们导出了这些联系人。”受影响的包括Trezor、CoinTracking和BitBox。
加密货币盗窃活动滥用Google可视化API作为命令与控制(C2)渠道——研究人员观察到,一起新的加密货币盗窃活动利用Google可视化API进行命令与控制(C2),并从公开发布的Google Sheets文档中获取混淆后的JavaScript代码,随后将其注入受害者的浏览器会话中。“攻击者使用了ClickFix社会工程学的一种变体,”Cisco Talos表示。“他们不是说服目标运行针对操作系统的命令,而是诱骗目标将JavaScript粘贴到Chrome地址栏中,或安装到Tampermonkey浏览器扩展程序中,从而获得持久化访问权限。”该诱饵伪装成泄露的漏洞报告,描述了加密货币兑换服务中不存在的API缺陷,这意味着该活动针对的是愿意利用此类漏洞获取经济利益的潜在网络犯罪分子。这些诱饵通过Telegram、DarkForums和粘贴网站进行分发。“注入的脚本充当网页挂马工具(web skimmer),”Talos补充道。“它挂钩浏览器的fetch API,替换服务器响应和用户剪贴板中的加密货币存款地址,并显示伪造的‘奖金’界面元素。”据悉,该活动自2025年10月以来一直在持续。共有49个BTC钱包地址与该活动有关联,截至2026年8月初,其中24个地址已收到来自受害者的资金,总额达10,000美元。
Shai-Hulud蠕虫在消失111天后重现——Aikido Security表示,他们发现了四个npm软件包——feishu-docx-mcp@0.3.2、bmc-i18n-extract-cli@1.1.1、blueai-cli@0.7.0和bmc-translate-utils@1.1.1——其中包含此前在2026年5月针对AntV的攻击中发现的Shai-Hulud蠕虫。“四个软件包的数量看似很少,但背后隐藏着一个更大的事实:一个具有已知、已发布且可索引哈希值的载荷,在没有任何人使用它的工具链中闲置了三个多月,随后又被重新发布到一个注册表中,而该注册表今年明确表示会在软件包上线前对其进行扫描,”Aikido指出。“注册级别扫描声称的功能与哈希值完全相同的重新激活所显示的实际捕获结果之间的差距,才是这里真正值得关注的故事。”
Google推出AndroidX安全状态库——Google宣布稳定发布AndroidX Security State版本1.1.0和Security State Provider版本1.0.0库,旨在提高Android设备安全态势的透明度。这些库提供了一个“旨在为整个Android生态系统中的全面安全态势和待处理更新带来进一步透明度的集中机制”,Google表示。“无论你是开发面向消费者的关键安全应用(如银行、金融科技或医疗领域),还是开发移动设备管理(MDM)解决方案,这些库都使你能够通过编程方式按组件验证设备的安全状态。与其依赖粗略的、整体性的安全补丁级别(SPL),你可以通过androidx.security.state库评估真正的组件级保护状态,以及修复措施是否正在待处理。对于原始设备制造商(OEM)和空中下载技术(OTA)客户端开发者而言,配套的androidx.security.state.provider库使你能够通过标准化机制暴露更新可用性。”
乌克兰黑客因勒索软件攻击在瑞士获刑——苏黎世法院判处一名乌克兰IT专家12年9个月监禁,因其开发了用于对公司实施勒索攻击的勒索软件,其中包括Stadler Rail。法院认定被告是Lockergoga、MegaCortex和Nefilim勒索软件家族的主要开发者,尽管他声称自己仅作为顾问为一家不知名的客户从事IT安全领域的工作,并且不知道自己的软件被用于勒索软件攻击。该活动导致估计损失达1.23亿美元。
Surfshark披露安全事件——Surfshark披露称,由于配置错误导致其内部测试服务器暴露在互联网上,未知威胁行为者访问了其中一台服务器。“由于人为失误,我们的工程团队使用的一台内部测试服务器配置不当,使其可从互联网访问,”Surfshark表示,“该服务器包含部分系统二进制文件和某些服务的内部配置。个人信息从未在此存储或可访问,VPN流量和浏览活动本身就不会被记录或保留,您设备上的应用程序和浏览器扩展也未被以任何方式篡改。”该事件于2026年8月31日被发现。
新型Panzer勒索软件出现——一个名为Panzer的勒索软件组织于2026年8月初现身,其数据泄露网站已声称控制了32名受害者。该组织主要瞄准德国、印度尼西亚、法国、西班牙和意大利的技术、制造、政府和教育行业。据CyberXTron称,“Panzer采用80/20的收入分成模式,80%的勒索款项归附属人员所有,20%作为平台留存。”
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week.
The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not always more clarity.
Nothing here needs much drama. Just a lot of small doors left open. Here’s what happened.
⚡ Threat of the Week
Cisco Warns of Actively Exploited ISE Auth Bypass — Cisco warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface."
🔔 Top News
U.S. Seizes NightmareStresser Domains Linked to DDoS Attacks — A U.S. court-authorized operation seized two domains associated with NightmareStresser, which offered a distributed denial-of-service (DDoS)-for-hire service. NightmareStresser is assessed to have been used to launch hundreds of thousands of actual or attempted DDoS attacks against victims across the world since 2022. These attacks have targeted educational institutions, government agencies, gaming platforms, and millions of people, the U.S. Justice Department said.
Using Claude to Hack OpenAI — Hacktron said it used Anthropic's Claude Opus 5 to chain two critical vulnerabilities – an SSO misconfiguration in OpenAI's identity infrastructure and a libheif RCE in the Discourse community forum ( CVE-2026-32882 ) – to gain unauthorized access to OpenAI employees' ChatGPT accounts and then use them to access internal OpenAI repositories. The issue was fixed 14 hours after responsible disclosure. Upstream, the flaw was fixed in libheif 1.22.0 in May 2026.
Plugin4Shell for 0-Click RCE in AI Coding Agents — AIR Security demonstrated a flaw called Plugin4Shell, a zero-click remote code execution (RCE) vulnerability that bypasses SHA-pinning verification in four major AI coding agents: Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. "In this first-of-its-kind AI supply-chain attack, a trusted plugin is silently swapped for a malicious one and auto-installed past the agent's SHA pinning -- a flaw no marketplace can fix, so users must update their agent," AIR Security said. "It is a plugin SHA-pinning bypass: the agent checks out the exact commit the marketplace pinned but never verifies it landed there, so an attacker who controls the plugin's repo makes the checkout resolve to malicious code while the pin still looks honored. The result is zero-click remote code execution across Claude Code, Codex, GitHub Copilot, and Gemini CLI."
OpenAI Reveals New Misalignment Incidents — OpenAI disclosed six new instances of "unexpected or concerning model behavior" that took place over the past six months, while sharing a new framework for reporting, tracking, investigating, and disclosing model misalignment in a bid to improve transparency. "As AI systems grow more advanced and more widely deployed, we need to build a broader and better-informed consensus on the progress of alignment research," OpenAI said. "We do not believe that the AI industry has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer."
KREMLIN Banking Malware Hijacks Chrome and Edge for Credential Theft — A previously undocumented Brazilian banking malware operation has been found to deliver a toolkit called KREMLIN. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and Microsoft Edge. "The KREMLIN malware ecosystem employs multi-stage JavaScript loaders, custom C++ installers, and malicious browser extensions to steal credentials, session tokens, and sensitive data," Elastic said. The activity is being tracked as REF9334.
️🔥 Trending CVEs
Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.
Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-58138 (Orkes Conductor), CVE-2026-58704 (Google Pixel), CVE-2026-90894 aka ParaShells (Parallels Desktop), CVE-2026-82079 (Nintendo Switch), CVE-2026-89049 (AWS Systems Manager Agent), CVE-2026-43502 aka ZcopyReaper, CVE-2026-80844 aka DirtyAH6, CVE-2026-81000 aka TUNderflow, CVE-2026-68121 aka PPPoEject, CVE-2026-74469 aka DiagSpill (Linux kernel), CVE-2026-70416, CVE-2025-43936 (Dell ObjectScale and Elastic Cloud Storage), CVE-2026-68488 (Please Backup Manager), CVE-2026-56711, CVE-2026-73324 (VLC Media Player), CVE-2026-65638 (cPanel ConfigServer Security & Firewall), CVE-2026-85982 , CVE-2026-78626 , CVE-2026-78623 (Okta), CVE-2026-0310 (Palo Alto Networks PAN-OS), CVE-2026-85061 (MapLibre GL JS), GHSA-rvhw-4hpw-9vrx , GHSA-rrgq-978q-36mq , GHSA-4xhx-8cv5-wh62 , GHSA-8v35-895w-232p (ArangoDB), CVE-2026-65812 (Microsoft Teams for Android), CVE-2026-80172, CVE-2026-61410, CVE-2026-80238 (Dell Secure Connect), CVE-2026-18851 (Ivanti Endpoint Manager Mobile), CVE-2026-91721, CVE-2026-91749, CVE-2026-91726 , CVE-2026-93374, CVE-2026-93372 (Google Chrome), CVE-2026-92033, from CVE-2026-92005 to CVE-2026-92013, from CVE-2026-92015 to CVE-2026-92020, from CVE-2026-92022 to CVE-2026-92029, from CVE-2026-92034 to CVE-2026-92038 (Mozilla Firefox), CVE-2026-15315, CVE-2026-15316 (TP-Link Tapo cameras), CVE-2026-82232 , CVE-2026-77147 , CVE-2026-73178 (Apache Syncope), CVE-2026-76669, CVE-2026-76670, CVE-2026-76672, CVE-2026-76673, CVE-2026-76674 (HPE Networking EdgeConnect SD-WAN Gateways and SD-WAN Orchestrator), CVE-2026-73693, CVE-2026-73694, CVE-2026-73698, CVE-2026-73699 (FileRun), CVE-2026-39919 (Ghostscript), CVE-2026-91998 (Casdoor), CVE-2026-91932 , CVE-2026-91931 (Flowise), CVE-2026-65400, CVE-2026-65414, CVE-2026-65346, CVE-2026-84607, CVE-2026-43790 (Apple), CVE-2026-90999 (Sentry Seer), CVE-2026-77692, CVE-2026-76163, CVE-2026-19667, CVE-2026-19666, CVE-2026-80274 (ISC BIND 9), CVE-2026-91843 (Check Point), CVE-2026-77179 (Docker), CVE-2026-81642, CVE-2026-82717 (Unbound DNS), Click2Shell (WordPress), CVE-2026-28326, CVE-2026-28323, CVE-2026-28309, CVE-2026-28306, CVE-2026-28308, CVE-2026-28310, CVE-2026-28314, CVE-2026-28313, CVE-2026-28307, CVE-2026-28305, CVE-2026-28317, CVE-2026-28304, CVE-2026-28312, CVE-2026-28316, CVE-2026-28311, CVE-2026-28302, CVE-2026-28321, CVE-2026-28315 (SolarWinds), CVE-2026-89026 (Issabel Framework), CVE-2026-78175 (Tutor LMS), an operating system command injection vulnerability in Dokploy, and a pickle deserialization vulnerability in MLflow.
🎥 Cybersecurity Webinars
How to Find and Control AI Agents Before Access Gets Out of Hand → AI agents are getting access to apps, data, credentials, and workflows faster than most teams can govern them. The real problem is not adoption — it is knowing which agents exist, what they can reach, and where access has quietly become too broad. This webinar breaks down how to bring AI agents under control without slowing down the teams using them.
AI Attacks Move in Minutes. Here's How to Stop Them at Runtime → AI-powered attacks are shrinking the time defenders have to react. By the time a traditional alert is investigated, the attacker may already have moved through the environment. This webinar shows how runtime identity security can make access decisions in real time, block risky activity earlier, and give security teams a better chance against machine-speed attacks.
📰 Around the Cyber World
Google Doc Leads to ClickFix Attack — Huntress disclosed details of a ClickFix attack in which a security researcher was targeted in an X exchange by a threat actor posing as a crypto marketing executive. "The threat actor sent a link to a real Google Doc with a custom sidebar designed to trick the recipient into downloading malware: an AMOS infostealer on macOS, or a PowerShell loader chain on Windows," Huntress said . "The Google Doc featured a sidebar displaying a fake decryption failure message, with supposed remediation instructions for users of different operating systems, including the option to copy and paste certain commands into the Terminal. This ClickFix lure, and the "manual update" button beside it, are what actually delivered the malware. The sidebar itself was a Google Apps Script bound to the document, so nothing had to be downloaded for it to run." The Apps Script executed client-side in the victim's browser, and collected the victim's public IP address and geolocation and scanned for crypto wallets.
Brevo Supply Chain Attack Injects ClickFix Scripts on Customer Sites — Customer engagement platform Brevo fell victim to a supply chain attack that led to malicious code being injected into over 100,000 websites. "On 14 September 2026, an attacker used a compromised Brevo Cloudflare API key to deploy a Cloudflare Worker on our account," Brevo said. "For about five and a half hours, the Worker injected a malicious script into pages of brevo.com and sibforms.com and into three JavaScript files that customers embed on their own websites." The script showed selected visitors a fake Cloudflare CAPTCHA prompt that instructed visitors to paste and run a malicious command on their computer, a technique also called ClickFix. Sansec, which shared additional details of the attack, said the "attackers piggy-backed on embedded Brevo widgets to install WordPress malware on Brevo customer sites and launch ClickFix attacks against their visitors." In all, the incident served malware to visitors of Brevo's own site and over 100,000 customer sites. The malware featured two components: a malicious WordPress plugin that was installed when site admins visited their own site and a ClickFix overlay that was displayed to everyone browsing a customer site or clicking a link (including the unsubscribe link) in a Brevo-sent campaign email. Earlier this month, Brevo disclosed a separate incident wherein attackers hijacked customer accounts and launched phishing attacks targeting downstream users of Brevo's customers. The attacker "exploited a flaw in the way Brevo handles SAML SSO to gain access to 138 Brevo accounts," Brevo said. "6 of those accounts were used to send phishing emails to the contacts stored there, and for 43 accounts they exported the contacts." Among those impacted were Trezor , CoinTracking , and BitBox .
Cryptocurrency Theft Campaign Abuses Google Visualization API for C2 — A new cryptocurrency-stealing campaign has been observed using Google Visualization API for command-and-control (C2), while fetching obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session. "The actors use a variation on ClickFix social engineering," Cisco Talos said . "Instead of convincing targets to run commands against the operating system, they convince targets to paste JavaScript into the Chrome address bar or install it into the Tampermonkey browser extension , which also provides persistence." The lure masquerades as leaked vulnerability reports describing non-existent API flaws at cryptocurrency swap services, meaning the campaign is aimed at aspiring cybercriminals who are willing to exploit such vulnerabilities for financial gain. The lures are distributed via Telegram, DarkForums, and paste sites. "The injected script functions as a web skimmer," Talos added. "It hooks the browser's fetch API, replaces cryptocurrency deposit addresses in server responses and the user's clipboard, and displays counterfeit 'bonus' interface elements." The campaign is said to have been ongoing since October 2025 . A total of 49 BTC wallet addresses have been tied to the campaign, with 24 receiving funds amounting to $10,000 from victims as of early August 2026.
Shai-Hulud Resurfaces After 111 Days — Aikido Security said it discovered four npm packages – feishu-docx-mcp@0.3.2, bmc-i18n-extract-cli@1.1.1, blueai-cli@0.7.0, and bmc-translate-utils@1.1.1 – containing the Shai-Hulud worm previously discovered in the attack targeting AntV in May 2026 . "Four packages is a small number attached to a larger fact: a payload with a known, published, indexed hash sat untouched in nobody's toolchain for over three months and was then republished on a registry that, as of this year, explicitly scans every package before it goes live," Aikido said . "That gap between what registry-level scanning claims to do and what a hash-identical reactivation shows it actually caught is the real story here."
Google Debuts AndroidX Security State Libraries — Google announced the stable release of AndroidX Security State version 1.1.0 and Security State Provider version 1.0.0 libraries to bring more transparency into the security posture of an Android device. These libraries provide a "centralized mechanism designed to bring further transparency to the comprehensive security posture and pending updates across the Android ecosystem," Google said . "Whether you develop security-critical, consumer-facing apps (such as banking, fintech, or healthcare) or Mobile Device Management (MDM) solutions, these libraries enable you to verify the security state of the device per component programmatically. Rather than relying on a coarse, monolithic Security Patch Level (SPL), you can evaluate true component-level protection and whether remediations are actively pending via the androidx.security.state library. For OEMs and Over-The-Air (OTA) client developers, the companion androidx.security.state.provider library allows you to expose update availability via standardized mechanisms."
Ukrainian Hacker Jailed in Switzerland for Ransomware Attacks — A Zurich court sentenced a Ukrainian IT specialist to 12 years and nine months in prison for developing ransomware used in extortion attacks on companies, including Stadler Rail. The court identified the defendant as the lead developer behind the Lockergoga, MegaCortex, and Nefilim ransomware families, although he claimed that he only worked as a consultant for an unknown client in the field of IT security and that he had been unaware that his software was being used for ransomware attacks. The activity led to $123 million in estimated losses.
Surfshark Discloses Security Incident — Surfshark disclosed that unknown threat actors accessed one of its internal test servers after a configuration error exposed it to the internet. "Due to a human error, an internal test server used by our engineering teams was misconfigured in a way that made it reachable from the internet," Surfshark said . "It contained parts of the system binaries and internal configurations for certain services. Personal information was never held and accessible from here, VPN traffic and browsing activity are not logged or retained in the first place, and the apps and browser extensions on your devices were not altered in any way." The incident was discovered on August 31, 2026.
New Panzer Ransomware Emerges — A ransomware group called Panzer , which emerged in early August 2026, has already claimed 32 victims on its data leak site. The group mainly targeted technology, manufacturing, government, and education sectors in Germany, Indonesia, France, Spain, and Italy. According to CyberXTron , "Panzer operates on an 80/20 revenue split, with 80% of ransom proceeds going to the affiliate and 20% retained as a pl
首次收录 · 2026-09-22 · 9.57 分