威胁日:AI驱动的零日攻击链、54.3万条活跃密钥、模型检查导致远程代码执行及另外13则报道
Ravie Lakshmanan2026年10月1日
黑客新闻 / 网络安全新闻
本周,那些有用的词汇听起来颇为枯燥:检查(inspect)、缓存(cache)、编译(compile)、存储(store)、信任(trust)。每一个听起来都无害。但当系统执行的操作超出人们的预期时,每一个都可能成为攻击路径。一次模型检查可能运行恶意代码。一个缓存可能导致请求混淆。一个公开泄露的密钥可能在多年后依然有效。
这正是贯穿本期列表的核心教训。攻击者并不总是需要高明的新花招。他们可以将命令隐藏在公共基础设施中,复用旧有的漏洞,滥用薄弱的默认设置,或者让自动化程序拼凑出一条粗糙但依然有效的攻击路径。更快的工具正在改变节奏,但基本的错误仍在造成大量破坏。
因此,本周有趣的问题不是“什么坏了?”,而是“我们因为看似平常而假设它是安全的,究竟有哪些?”完整列表中有答案。
威胁每周都在变化。订阅我们,以便在每期新的《威胁日》简报发布时收到提醒。
ATM大劫案打击行动
美国财政部制裁与ATM大劫案有关的10个目标
美国财政部海外资产控制办公室(OFAC)对参与“阿拉瓜火车”(Tren de Aragua)ATM大劫案的10个目标实施了制裁,该团伙从美国金融机构窃取了至少4073万美元。该网络利用加密货币洗钱。“阿拉瓜火车”是被指定的外国恐怖组织。大劫案攻击使用Ploutus恶意软件迫使ATM机吐出现金。财政部估算数据显示,截至2025年8月,美国境内超过1500起涉嫌由“阿拉瓜火车”实施的大劫案攻击造成的报告损失总额达4073万美元。TRM Lab表示,自2022年3月以来,这七个被指定的加密货币钱包地址已收到约610万美元的总流入。“‘阿拉瓜火车’正将ATM恶意软件用作恐怖融资工具,然后将现金转移到TRON网络上,使其看起来像普通的交易所存款,”TRM Labs全球政策主管Ari Redbord表示。“这正是我们反复从拥有链上基础设施的外国恐怖组织(FTO)身上看到的同一套手法。这些制裁针对的正是这套手法。我们看到财政部正在同时打击恶意行为者及其金融协助者。”
基于区块链的恶意软件隐藏
EtherHiding的使用日益增长
网络威胁行为者正利用公共区块链来隐藏恶意软件指令,使得查封或关闭变得极具挑战性。这种被称为EtherHiding的技术是更广泛的“区块链死投”(Blockchain Dead Drops, BDD)方法的一部分。Chainalysis表示,“朝鲜和伊朗国家支持的操作者是开发独特区块链死投技术的主要群体之一”,并补充道,“自中国无限制生成恶意代码的高容量开源AI模型发布以来,BDD的使用量激增了440%。”
AI安全审查正在进行中
月之暗面(Moonshot AI)开展内部审查
BBC新闻报道称,中国AI公司月之暗面正在开展内部审查,此前Mindgard在2026年7月的一份报告中发现,其AI模型Kimi K2.6和K3 Swarm能够绕过安全护栏并生成危险信息,包括提供网络攻击计划、恐怖主义阴谋和暗杀方案。
作为防御的提示注入
针对被消除上下文记忆的AI模型的“上下文炸弹”
2026年7月,Tracebit详细阐述了一种名为“Context Bombs”(上下文炸弹)的技术,该技术利用提示注入来触发AI模型提供商的运行时安全检查,从而阻止其执行恶意操作。在这份新报告中,这家AI安全公司表示,间接提示注入可用于阻止来自开放权重模型的攻击,无论这些模型是否经过abliterated(去抑制)处理。“我们转向了间接提示注入:即在代理执行任务时读取的材料中放置指令,”Tracebit称。“新的有效载荷旨在让代理相信其操作员已终止评估。我们将其放置在AWS Secrets Manager中的金丝雀密钥(canary secret)内,这样探索该账户的代理就能发现它。所使用的字符串利用对话分隔符,使密钥内容看起来像助手与其用户之间的交流。伪造的用户消息随后指示代理停止所有活动并确认该指令。”
新的EDR规避技术
用于绕过EDR的新进程注入方法
安全研究员Zero Salarium概述了一种新的进程注入技术,该技术不使用WriteProcessMemory(),而是利用控制台进程的stdin管道和WriteFile()将任意字节写入内存并执行。“与传统方法不同,控制台命名管道注入不使用VirtualAllocEx和WriteProcessMemory,”该研究员表示。“相反,它利用了通过命名管道进行的读写操作,以及控制台程序在内存中存储交互式命令的方式。因此,传统的监控方法无法可靠地检测或阻止此技术。”
缓存碰撞实现投毒
用于Web缓存投毒的缓存键注入
YesWeHack详细阐述了一种名为缓存键注入的Web缓存投毒技术,该技术将缓存键转化为攻击面。从宏观层面来看,如果缓存通过简单拼接受攻击者影响的字符串(不带分隔符)来构建其密钥,攻击者就可以使两个不同的HTTP请求产生相同的缓存密钥。这种碰撞随后可用于缓存欺骗、泄露缓存的限制性响应、拒绝服务,或在更特定的条件下,当注入可执行内容时导致存储型XSS。“当缓存连接不安全的片段且没有明确定义的边界时,就会产生缓存键注入漏洞,”YesWeHack表示。“不同的片段值组合随后可以产生相同的最终密钥。严重程度取决于受影响的端点、缓存生命周期、共享缓存的用户数量,以及投毒响应是否通过边缘或源缓存层传播。”
22TB数据泄露指控遭质疑
所谓印度大使馆22TB数据泄露受到审视
HackElite的一份网络威胁情报报告对一名威胁行为者从印度大使馆和外交事务实体窃取22 TB数据的说法提出质疑,因为研究人员发现作为证据共享的样本与公共来源中已有的信息存在重叠。这些数据于9月23日在X Forums上以20万美元的价格出售,据称包括使馆名录、外交服务记录、组织架构图、官员名单以及其他政府文件。报告称,该行为者使用了“RAYLEAS”这一用户名,并分享了Telegram账户@Rayhucker用于样本访问和销售咨询,而一项开源情报(OSINT)调查通过历史显示名称和公开资料将该账户与一名巴基斯坦籍人士联系起来。然而,研究人员强调,22 TB数据泄露的说法以及身份归因均未得到证实,并补充称这些发现应被视为情报评估,而非法律结论。
在受害者主机上编译挖矿程序
威胁行为者在受感染主机上编译挖矿软件
在Huntress记录的一起新型攻击中,威胁行为者在受害者的终端上编译了加密货币挖矿程序,而不是直接投放一个。Huntress表示:“事件始于利用已知的三星MagicINFO漏洞[CVE-2025-4632]。随后,攻击者部署了一个流氓AnyDesk实例(经过三次尝试),创建了一个新的本地管理员账户,并禁用了Defender防护功能。虽然此次攻击中的挖矿程序编译环节颇具趣味,但这一事件表明,防御者应超越已知的挖矿程序二进制文件:反复下载远程管理工具(RMM)和意外的编译器活动可以在最终载荷运行之前揭示系统已被入侵的事实。”
人工智能降低网络攻击门槛
中国警告称AI正在加速网络攻击
中国国家安全部部长陈一新表示,人工智能对政治安全、制度安全和意识形态安全产生影响,“敌对势力”利用合成内容以低成本、大规模地传播虚假政治谣言、有害信息并煽动对抗情绪。陈一新将Anthropic和OpenAI推出的前沿AI模型的出现称为“颠覆性变革”,并表示该技术提高了与发现网络漏洞和开发恶意软件相关的“效率和武器化能力”。网络战已进入一个新阶段,其特征是漏洞发现的工业化、攻防操作的全自动化以及AI对AI的对抗。某些国家和组织现在具备大规模快速发现漏洞、自动链接攻击路径并执行复杂黑客任务的能力;这极大地降低了发动网络攻击的技术门槛和成本,从而对中国关键信息基础设施构成严重风险。”
量子安全证书即将到来
Cloudflare宣布为后量子网络提供公共证书颁发机构
Cloudflare已宣布计划成为一家公共证书颁发机构(CA),能够颁发网站用于加密流量并向访问者证明其身份的量子安全数字证书。该公司表示:“新的CA将同时支持传统加密和下一代后量子Merkle树证书(MTCs),为每个网站提供一条随着计算能力提升而保持保护的路径——无需新工具或重新构建。”此外,Cloudflare已同意从GlobalSign收购既有的、受公众信任的根CA密钥材料,以确保证书在不再接收软件更新的旧款智能手机、操作系统和设备上正常工作。今年2月初,Google表示正在开发基于Merkle树证书(MTCs)的HTTPS证书演变版本,用于其Chrome浏览器。生产环境的MTC颁发计划于2027年第一季度进行。
超过50万密钥泄露
GitHub仓库暴露了543,699个凭证
Truffle Security的一项新研究发现,尽管该平台有防止此类数据泄露的安全措施,但仍有543,699个独特的凭证在公共GitHub仓库中暴露,且截至2026年7月仍然有效。Truffle Security表示:“中间值显示,这些凭证在公共默认分支中停留了784天。最古老的一个提交于2009年,至今仍然有效。”其中,不到20万个是在GitHub默认开启推送保护之后推送的。
加密备份抵达iOS
Signal为iPhone和iPad推出安全的设备端备份
Signal在版本8.30中为iPhone和iPad引入了设备端加密备份功能,该功能此前已在Android、Linux、macOS和Windows上得到支持。这款即时通讯应用还在测试允许用户在不提供电话号码的情况下注册账户的能力。目前形式的该功能不允许现有用户移除电话号码。该功能名为Signal Login,目前仅限于Signal Android Beta 8.28.1版本。
模型检查触发代码执行
Unsloth Studio中的模型检查导致关键任意代码执行漏洞
开源大语言模型微调与量化库Unsloth被发现,其Unsloth Studio中的模型选择组件存在一个漏洞,可自动从其仓库中执行Python代码。“在用户界面中选择模型会导致后端下载并运行该模型HuggingFace仓库中包含的Python代码,”Pillar Security表示。“该代码仅通过元数据检查即可运行;读取模型的config.json文件就足以触发利用;后端从未加载权重或运行推理——仅仅检查模型就足以运行其代码。”攻击者可以利用此缺陷泄露专有训练数据、模型工件以及该进程可访问的任何Hugging Face令牌、SSH密钥或云凭据。“攻击者可以以用户身份运行代码,这可能转化为窃取可访问的数据、篡改模型和训练输出,或利用可用凭据访问其他系统,”Pillar补充道。该问题已在2026年6月18日发布的版本2026.6.9中得到解决。
1600万美元加密货币诈骗案
越南国民因“杀猪盘”加密货币骗局被起诉
37岁的越南国民Trung Nguyen Van因涉嫌在一场电信欺诈“杀猪盘”骗局中骗取受害者数百万美元加密货币而被起诉。“在2024年6月至8月期间,受害者#1相信其正在向一个名为‘Triangle’的加密货币投资平台进行投资,从而转移了价值约16,000,000美元的加密货币,”美国司法部表示。“其中一笔转账发生于2024年8月7日,可直接追溯至Van的加密货币钱包,涉及超过569,000美元的加密货币。在2024年8月9日,Van的加密货币钱包收到了六笔转账,总计约569,569美元的加密货币,这些资金可追溯至受害者#1。在收到资金后,Van立即通过四笔交易将价值约567,999美元的加密货币转移到一个脱离中心化区块链网络的私有、非托管加密货币钱包中。”在2018年2月9日至2024年12月17日期间,Van的加密货币钱包从针对美国公民的电信欺诈方案中接收了约53,275,939美元的加密货币资产。
零日漏洞链式利用获取根权限
DIVD因Zammad零日漏洞遭黑客入侵
开源Zammad工单系统中的两个零日漏洞CVE-2026-102489和CVE-2026-102490已被威胁行为者串联利用,以入侵荷兰漏洞披露研究所(DIVD)。“结合使用时,它们允许攻击者在几秒钟内劫持会话、远程运行代码,并将权限从Zammad用户提升至root,这得益于此次黑客攻击的代理部分,”DIVD表示。“在此基础上,他们能够访问其他服务并读取和窃取数据。”其中包括其志愿者的用户数据,如DIVD电子邮件地址及可能的联系方式。证据表明,这场“喧闹且非常混乱”的攻击由AI驱动。“我们可以看到该代理自动工作,因为在每次行动后,它都以光速和粗略的逻辑或模式自行决定下一步,”DIVD补充道。“看起来该代理在其学习曲线上跳过了一些步骤,因为它做了一些相当愚蠢的事情,比如用密码喷洒污染其自身的中间人攻击。”
AI重塑漏洞发现
AI漏洞发现与利用趋势
Google威胁情报小组(GTIG)透露,每月披露的漏洞数量已翻倍,从2026年1月的5,045个上升至2026年7月的10,477个以及8月的10,740个。“利用漏洞的数量从2025年平均每月10.5个增加到2026年1月至2026年8月期间的平均每月18个,”GTIG表示。“零日漏洞的利用从2025年平均每月8个增长到2026年1月至2026年8月期间的平均每月11个。”这家科技巨头表示,AI不仅改变了漏洞发现和利用的速度,还改变了被发现漏洞的类型。“通过AI辅助发现的比例中,低风险漏洞更少,中等风险漏洞更多,导致远程代码执行(RCE)的漏洞也更多,”它说。高风险漏洞的数量从2026年1月的131个披露激增到2026年8月的350个,增长了167%。从2026年1月到2026年8月,共有141个不同的漏洞被披露和利用,而2025年全年为127个。大多数由AI辅助方法发现的缺陷包括RCE、拒绝服务、安全绕过、信息泄露和数据篡改。
189个月监禁判决
特拉华州男子因网络入侵计划被判入狱
两名来自特拉华州的男子,Chijioke Timot
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
Ravie LakshmananOct 01, 2026
Hacking News / Cybersecurity News
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years.
That is the lesson running through the list. Attackers do not always need a brilliant new trick. They can hide commands in public infrastructure, reuse old flaws, abuse weak defaults, or let automation stitch together a rough path that still works. Faster tools are changing the pace, but basic mistakes are still doing plenty of the work.
So the interesting question this week is not “what broke?” It is “what did we assume was safe because it looked ordinary?” The full list has answers.
The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
ATM JACKPOTTING CRACKDOWN
U.S. Treasury Sanctions 10 Targets in Connection with ATM Jackpotting
The U.S. Treasury's Office of Foreign Assets Control (OFAC) sanctioned 10 targets involved in a Tren de Aragua ATM jackpotting scheme that stole at least $40.73 million from U.S. financial institutions. The network used cryptocurrency to launder the proceeds. Tren de Aragua is a designated Foreign Terrorist Organization. Jackpotting uses Ploutus malware to force ATMs to dispense cash. Treasury estimates show reported losses totaling $40.73 million from more than 1,500 alleged TdA jackpotting attacks in the U.S. as of August 2025. TRM Lab said the seven designated crypto wallet addresses have received approximately $6.1 million in total inflows since March 2022. "Tren de Aragua is using ATM malware as a terrorist financing tool, then moving the cash onto TRON so it looks like ordinary exchange deposits," said Ari Redbord, Global Head of Policy at TRM Labs. "That is the same playbook we keep seeing from FTOs with on-chain infrastructure. These sanctions target that playbook. We are seeing the Treasury go after both the bad actors and their financial facilitators."
BLOCKCHAIN-BASED MALWARE CONCEALMENT
Use of EtherHiding Grows
Cyber threat actors are using public blockchains to conceal malware instructions, making it challenging to seize or take down. This technique, referred to as EtherHiding, is part of a broader approach called Blockchain Dead Drops (BDD). Chainalysis said "North Korean and Iranian-state operators are among those developing distinct blockchain dead drop techniques," adding "BDDs have surged 440% since the launch of Chinese high-capacity open-source AI models that place no restrictions on generating malicious code."
AI SAFETY REVIEW UNDERWAY
Moonshot AI Conducts Review
BBC News has reported that Chinese AI company Moonshot is conducting an internal review after a July 2026 report from Mindgard found that its AI models, Kimi K2.6 and K3 Swarm, could bypass safety guardrails and generate dangerous information, including providing plans for cyberattacks, terrorism plots, and assassinations.
PROMPT INJECTION AS DEFENSE
Context Bombs Against Abliterated AI Models
In July 2026, Tracebit detailed a technique called Context Bombs that uses prompt injections as a way to trip an AI model provider's runtime safety checks and prevent it from taking malicious actions. In a new report, the AI security company said indirect prompt injections can be used to stop attacks from open-weight models, abliterated or otherwise. "We turned to indirect prompt injection: instructions placed in material an agent reads while carrying out its task," Tracebit said. "The new payload was designed to make the agent believe its operator had ended the assessment. We placed it inside a canary secret in AWS Secrets Manager, where an agent exploring the account could discover it. The string used conversation delimiters to make the secret’s contents resemble an exchange between the assistant and its user. The forged user message then told the agent to stop all activity and acknowledge the instruction."
NEW EDR EVASION TECHNIQUE
New Process Injection Method for EDR Evasion
Security researcher Zero Salarium has outlined a new process injection technique that, instead of WriteProcessMemory(), uses a console process's stdin pipe and WriteFile() to write arbitrary bytes into memory and execute them. "Unlike traditional approaches, console named-pipe injection does not use VirtualAllocEx and WriteProcessMemory," the researcher said. "Instead, it takes advantage of read and write operations through a named pipe, along with the way console programs store interactive commands in memory. As a result, traditional monitoring methods cannot be used to reliably detect and prevent this technique."
CACHE COLLISIONS ENABLE POISONING
Cache Key Injection for Web Cache Poisoning
YesWeHack has detailed a web cache poisoning technique called cache key injection that turns the cache key into an attack surface. At a high level, if a cache builds its key by simply combining attacker-influenced strings together without separators, an attacker can make two distinct HTTP requests produce the same cache key. This collision can then be used for cache deception, leaking cached restricted responses, denial-of-service, or, under more specific conditions, stored XSS when executable content is injected. "Cache key injection vulnerabilities arise when a cache concatenates unsafe fragments without clearly defined boundaries," YesWeHack said. "Different combinations of fragment values can then produce the same final key. Severity depends on the affected endpoint, cache lifetime, number of users sharing the cache, and whether the poisoned response propagates through edge or origin caching layers."
22TB BREACH CLAIM QUESTIONED
Alleged 22TB Indian Embassy Leak Under Scrutiny
A cyber threat intelligence report from HackElite has questioned claims that a threat actor stole 22 TB of data from Indian embassies and foreign-affairs entities after researchers found that samples shared as proof overlapped with information already available from public sources. The data was advertised on X Forums on September 23 for $200,000 and was said to include embassy directories, Foreign Service records, organizational charts, officer lists, and other government documents. The report said the actor used the handle “RAYLEAS” and shared the Telegram account @Rayhucker for sample access and sales inquiries, while an OSINT investigation linked the account to a Pakistan-based individual through historical display names and public profiles. However, the researchers stressed that the 22 TB breach claim and the identity attribution remain unverified, adding that the findings should be treated as an intelligence assessment rather than a legal conclusion.
MINER COMPILED ON VICTIM HOST
Threat Actor Compiles Miner on Infected Host
In a novel attack documented by Huntress, a threat actor compiled a cryptocurrency miner on the victim endpoint instead of dropping one directly. "The incident started with exploitation of a known Samsung MagicINFO flaw [CVE-2025-4632]," Huntress said. "Attackers then deployed a rogue AnyDesk instance (after three tries), created a new local admin account, and disabled Defender protections. While the miner compilation aspect of this attack is interesting, the incident shows why defenders should look beyond known miner binaries: repeated RMM downloads and unexpected compiler activity can reveal a compromise before the final payload runs."
AI LOWERS CYBERATTACK BARRIERS
China Warns of AI Accelerating Cyber Attacks
Chen Yixin, head of China's Ministry of State Security, said AI has implications for political security, institutional security, and ideological security, with "hostile forces" using synthetic content to spread fabricated political rumors, spread harmful information, and incite confrontational sentiments at low cost and in large quantities. Calling the emergence of frontier AI models from Anthropic and OpenAI a "disruptive transformation," Chen said the technology boosts the "efficiency and weaponization capabilities associated with discovering cyber vulnerabilities and developing malware. Cyber warfare has entered a new phase characterized by the industrialization of vulnerability discovery, fully automated offensive and defensive operations, and AI-versus-AI confrontations. Certain nations and organizations now possess the ability to rapidly discover vulnerabilities at scale, automatically chain attack paths, and execute complex hacking missions; this drastically lowers the technical barriers and costs associated with launching cyberattacks, thereby posing serious risks to China's critical information infrastructure."
QUANTUM-SAFE CERTIFICATES COMING
Cloudflare Announces Public Certificate Authority for the Post-Quantum Web
Cloudflare has announced plans to become a public Certificate Authority (CA) that can issue quantum-safe digital certificates that websites need to encrypt traffic and prove their identity to visitors. "The new CA will support both traditional encryption and next-generation post-quantum Merkle Tree Certificates (MTCs), giving every website a path to stay protected as computing power advances—with no new tools or rebuilds required," the company said. In addition, Cloudflare has agreed to acquire established, publicly trusted Root CA key material from GlobalSign to ensure certificates work on older smartphones, operating systems, and devices that no longer receive software updates. Earlier this February, Google said it's developing an evolution of HTTPS certificates based on Merkle Tree Certificates (MTCs) for use in its Chrome web browser. Production MTC issuance is scheduled for the first quarter of 2027.
OVER HALF A MILLION SECRETS EXPOSED
GitHub Repos Expose 543,699 Credentials
A new study from Truffle Security has found 543,699 unique credentials exposed in public GitHub repositories that were still valid as of July 2026 despite the platform's security measures to prevent leakage of such data. "The median one had been sitting in a public default branch for 784 days. The oldest was committed in 2009 and still works," Truffle Security said. "Just under 200,000 of them were pushed after GitHub turned push protection on by default."
ENCRYPTED BACKUPS REACH IOS
Signal Rolls out Secure On-Device Backups for iPhone and iPad
Signal has introduced on-device encrypted backups for iPhones and iPads with version 8.30, a feature that was already supported on Android, Linux, macOS, and Windows. The messaging app is also testing the ability for users to register for an account without providing their phone number. The feature, in its current form, does not allow an existing user to remove a phone number. The feature, called Signal Login, is currently limited to Signal Android Beta 8.28.1.
MODEL INSPECTION TRIGGERS CODE EXECUTION
Model Inspection in Unsloth Studio Leads to Critical Arbitrary Code Execution
Unsloth, an open-source library for fine-tuning and quantizing LLMs, has been found to contain a vulnerability in the model picker component in Unsloth Studio that could automatically execute Python code from its repository. "Selecting a model in the UI caused the backend to download and run Python code shipped inside that model's HuggingFace repository," Pillar Security said. "The code ran from nothing more than a metadata check. Reading the model's config.json was enough to trigger the exploit; the backend never loaded the weights or ran inference – the act of inspecting a model was enough to run its code." An attacker could exploit this flaw to expose proprietary training data, model artifacts, and any Hugging Face tokens, SSH keys, or cloud credentials accessible to that process. "An attacker could run code as the user, which could translate to stealing accessible data, altering models and training outputs, or using available credentials to access other systems," Pillar added. The issue has been addressed in version 2026.6.9 released on June 18, 2026.
$16 MILLION CRYPTO FRAUD CASE
Vietnamese National Charged in Pig Butchering Cryptocurrency Scam
Trung Nguyen Van, 37, a Vietnamese national, has been charged for his role in defrauding a victim out of millions of dollars' worth of cryptocurrency in a wire fraud pig butchering scam. "Between June and August of 2024, Victim #1 transferred approximately $16,000,000 worth of cryptocurrency, believing they were making an investment in a cryptocurrency investment platform called 'Triangle,'" the U.S. Justice Department said. "One such transfer, taking place on Aug. 7, 2024, directly traceable to Van’s cryptocurrency wallet, was for over $569,000 in cryptocurrency. On Aug. 9, 2024, Van’s cryptocurrency wallet received six transfers totaling approximately $569,569 in cryptocurrency, traceable to Victim #1. Immediately following the receipt of the funds, Van proceeded to transfer approximately $567,999 worth of cryptocurrency in four transactions to a private, un-hosted cryptocurrency wallet off the centralized blockchain network." Between February 9, 2018, and December 17, 2024, Van's cryptocurrency wallets received approximately $53,275,939 in cryptocurrency assets from wire fraud schemes targeting U.S. citizens.
ZERO-DAYS CHAINED TO ROOT ACCESS
DIVD Hacked via Zammad 0-Days
Two zero-day vulnerabilities in the open-source Zammad ticketing system, CVE-2026-102489 and CVE-2026-102490, have been chained by threat actors to break into the Dutch Institute for Vulnerability Disclosure (DIVD). "Used together, they allowed the attackers to hijack sessions, run code remotely and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack," DIVD said. "From there they were able to access other services and read and exfiltrate data." This includes user data of its volunteers, such as DIVD email addresses and possibly contact details. Evidence indicates that the "loud and very, very messy" attack was powered by AI. "We could see the agent working automated, because after every action it decided the next step itself, at the speed of light and sloppy logic or pattern," DIVD added. "It also looks like the agent skipped a few steps on its learning curve, because it has done some pretty dumb things, like polluting its own MitM attack with password spraying."
AI RESHAPES VULNERABILITY DISCOVERY
AI Vulnerability Discovery and Exploitation Trends
Google Threat Intelligence Group (GTIG) has revealed that the number of vulnerabilities disclosed per month has doubled, rising from 5,045 in January 2026 to 10,477 in July and 10,740 in August 2026. "The number of vulnerabilities exploited increased from an average of 10.5 per month in 2025 to an average of 18 per month from January 2026 to August 2026," GTIG said. "Zero-day vulnerability exploitation grew from an average of 8 per month in 2025 to an average of 11 per month from January 2026 to August 2026." The tech giant said AI is not only changing the pace of vulnerability discovery and exploitation, but also the types of vulnerabilities being discovered. "AI-assisted discovery found proportionally fewer Low-Risk vulnerabilities, more Moderate-Risk vulnerabilities, and more vulnerabilities leading to remote code execution (RCE)," it said. The number of High-Risk vulnerabilities has surged from 131 disclosures in January 2026 to 350 in August 2026, a 167% growth. From January 2026 to August 2026, a total of 141 distinct vulnerabilities have been disclosed and exploited, up from 127 for the entirety of 2025. Most of the flaws discovered by AI-assisted approaches include RCE, denial-of-service, security bypass, information disclosure, and data manipulation.
189-MONTH PRISON SENTENCES
Delaware Men Sentenced to Prison for Cyber Intrusion Scheme
Two Delaware men, Chijioke Timot
首次收录 · 2026-10-02 · 9.69 分