Scanning the Threat Landscape

AI-analyzed cybersecurity news with IFF classification and defender context.

Latest Stories

AI tools help hacker break in for $25 per target ↗

A recent analysis by Gambit Security revealed that an attacker used open-source AI tools like Strix, Cairn, and Hermes to compromise 27 out of 105 online retailers within five days, at an average cost of $25 per target. The campaign successfully exfiltrated 600,000 credit card details, installed card skimmers, and gained access to several major companies, demonstrating AI's growing role in automating and enhancing cybercriminal activities.

Crooks use fake desktop apps to fool HR staff into giving them remote access ↗

Attackers are using fake desktop applications to impersonate legitimate HR and payroll providers, tricking HR staff into granting them remote access to company systems. The deception is effective because the fake apps mimic legitimate software, with the only giveaway being that the impersonated providers do not actually offer desktop applications.

In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure ↗

This article highlights several cybersecurity incidents and trends. It mentions the takeover of the Clop ransomware group's leak site, a Docker botnet specifically targeting AI keys, and the exposure of a water utility. Additionally, it touches on the BragJack attack against browser AI assistants, a flaw in TDengine affecting industrial telemetry, and an Ubuntu update overhaul.

GitLab issue email’s only security is obscurity ↗

GitLab's 'email work item' feature, intended to simplify issue creation, has a significant security flaw. The feature embeds a long-lived token in a secret email address that, if exposed, allows anyone to push code and run CI/CD jobs in protected repositories, bypassing IP restrictions. GitLab considers this intended behavior, while researchers at Aikido Security argue it presents a critical risk.

With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance ↗

The article discusses how the rise of AI agents poses a challenge to the existing SOC 2 compliance framework. These agents can leverage human credentials and perform actions that are difficult for current controls to differentiate from legitimate human activity. Token Security highlights the need for SOC 2 to evolve to address these new security gaps related to agent identities.

CISA Adds Two Known Exploited Vulnerabilities to Catalog ↗

CISA has added two new vulnerabilities, CVE-2026-65660 (Microsoft SharePoint Code Injection) and CVE-2026-67279 (Mikrotik RouterOS Improper Enforcement of Behavioral Workflow), to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. These additions underscore the importance of CISA's Binding Operational Directive (BOD) 26-04, which mandates FCEB agencies to prioritize remediation of these high-risk vulnerabilities.

The SOC Doesn't Need to Start Over with Every Alert ↗

Attackers are leveraging AI to make failed attacks cheaper and easier to retry. This shift means that Security Operations Centers (SOCs) will likely face more persistent and iterative attacks, requiring new strategies to manage and respond to alerts. The change is described as quieter but already visible in the cybersecurity landscape.

On Anthropic’s AI Misuse Report ↗

Anthropic's recent report details various misuses of their AI model, Claude. These misuses include AI agents conducting reconnaissance, exploitation, data theft, and propaganda production, with human oversight for target selection and goal setting. The report highlights attackers leveraging AI to industrialize credential theft, cloud compromise, phishing, vulnerability research, and sensitive data extraction.

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild ↗

A pre-authentication SQL injection vulnerability in the Roundcube Webmail virtuser_query plugin, identified as CVE-2026-48842, is being actively exploited in the wild. The Canadian Centre for Cyber Security has issued a warning about this flaw, which affects versions prior to 1.6.16 and 1.7.1. The vulnerability is due to an issue with the preg_replace() function.

PI’s response to the UK Department for Science, Innovation & Technology on data regulation in the age of AI and other data-intensive technologies ↗

Privacy International (PI) has responded to the UK Department for Science, Innovation & Technology regarding data regulation in the era of AI and other data-intensive technologies. The response emphasizes the need for robust data protection measures to safeguard individuals' privacy.

Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data ↗

Cloudflare has fixed a flaw in its Containers service that allowed one customer's container to potentially access residual disk data left behind by other customers' containers on the same server. The vulnerability meant data from previous workloads, not live ones, could be exposed, though Cloudflare stated an attacker could not select whose data they accessed.

Risky Bulletin: Major vulnerability found in ancient TACACS+ networking protocol ↗

A significant vulnerability has been discovered in the TACACS+ networking protocol, an older system still in use for network device authentication. This bulletin also touches upon unrelated cybersecurity news regarding OpenAI's involvement in an Australian Medicare website hack, providing Ukraine with access to an unspecified system, and the UK's plan to create an anti-disinformation center.

Intigriti Bug Bytes #240 - September 2026 🚀 ↗

Intigriti's Bug Bytes newsletter for September 2026 highlights various hacking achievements and tools. Features include compromising major platforms like OpenAI, Slack, and Meta through a vulnerable image library, hacking OpenAI employee accounts, and breaching Google's GFile for a substantial reward. The newsletter also introduces CrowdRecon, a crowd-led reconnaissance tool, and mentions performance improvements in Turbo Intruder.

CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability ↗

MikroTik RouterOS has a vulnerability (CVE-2026-67279) that allows unauthenticated clients to open a session and send exec requests, potentially chaining to exploit CVE-2026-86060 for unauthenticated exploitation. Affected stakeholders must apply vendor mitigations and comply with CISA's BOD 26-04 guidance for prioritizing security updates.

WordPress patches a critical severity security vulnerability ↗

WordPress has released version 7.1.2 to patch a critical severity vulnerability (CVE-2026-87902) that allows unauthenticated attackers remote code execution. The vulnerability exploits how page templates are resolved, enabling attackers to include and execute malicious PHP files if specific server and theme conditions are met. Attacks in the wild have already been reported, and users are urged to update immediately, as the fix affects many older versions.

DraftKings Is Using AI to Supercharge the Harms of Online Behavioral Advertising ↗

DraftKings is employing AI and machine learning to identify and target customers who are most likely to place losing bets, then luring them back with promotions. This practice amplifies the harms of online behavioral advertising by exploiting vulnerable individuals for profit. The company's use of AI necessitates extensive data collection, further fueling surveillance.

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions ↗

Researchers have discovered two unpatched vulnerabilities in OnePlus devices running OxygenOS that allow installed Android apps to gain root access without requiring any special permissions. This chaining of flaws effectively grants a malicious app the highest level of control over the device, and OnePlus has acknowledged that these issues affect a wide range of their devices as well as OPPO devices.