ClickFix Attacks Evolve to Better Hide Malicious Payloads

Threat actors have evolved ClickFix attacks by hiding malicious payloads using DNS TXT records and browser cache pre-fetching, making early detection more difficult. In these campaigns, victims are tricked into pasting commands that retrieve hidden instructions from attacker-controlled servers or cached scripts, enabling stealthier deployment of malware like remote access Trojans and credential stealers. Security experts recommend user training on ClickFix patterns and deploying technical controls such as PowerShell script-block logging and application control to mitigate these advanced social engineering threats.

https://www.darkreading.com/cyberattacks-data-breaches/clickfix-attacks-evolve-better-hide-malicious-payloads

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

A critical arbitrary file access vulnerability (CVE-2026-21589) affecting multiple Atlassian Data Center products has been actively exploited within two hours of its public disclosure, allowing unauthenticated attackers to access sensitive files if the exact file path is known. Atlassian has released patches and recommends immediate mitigation steps, while telemetry shows exploitation attempts originating from IP addresses in Japan and the U.S., raising urgent patching priorities for affected organizations.

https://thehackernews.com/2026/10/atlassian-data-center-flaw-draws.html

AI-powered Phishkit Arms Criminals with Account-Hijacking Tools in 10 Minutes

The BlueKit phishing-as-a-service toolkit enables cybercriminals to launch sophisticated account-hijacking scams in about 10 minutes without requiring advanced technical skills. It offers a vast library of realistic phishing templates for consumer, financial, social media, AI, and business platforms, alongside features like session cookie theft and an integrated AI assistant that helps create scam emails and texts. Since its debut, BlueKit has attracted over 1,000 customers, highlighting the growing commercialization of phishing infrastructure that lowers barriers for attackers and increases the risk of convincing, large-scale phishing attacks.

https://www.malwarebytes.com/blog/threat-intel/2026/10/ai-powered-phishkit-arms-criminals-with-account-hijacking-tools-in-10-minutes

ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

A new ClickFix attack technique abuses compromised websites to prefetch malicious script payloads disguised as images into browser caches, bypassing Windows Run command character limits by executing cached content locally. The attack chain uses VBScript and PowerShell to download and execute further malware stages in memory, enabling credential theft and persistent access while evading traditional detection methods. Microsoft advises enhanced monitoring of browser cache activity and warns users against running commands prompted by CAPTCHA or error messages to mitigate this social engineering threat.

https://thehackernews.com/2026/10/clickfix-smuggles-payloads-through.html

Google Halts Open-Source Bug Bounty Program Amid AI Spam Surge

Google has temporarily suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) due to a surge in low-quality, AI-generated vulnerability reports overwhelming the system. The company continues to accept supply chain vulnerability reports and security patches through other programs, and plans to update and relaunch the OSS VRP with improvements in early 2027. This move follows a growing trend of bug bounty programs facing challenges from automated AI report floods.

https://www.bleepingcomputer.com/news/google/google-halts-open-source-bug-bounty-program-amid-ai-spam-surge/

Debian’s Latest Kernel Security Update Has 1,313 Reasons to Patch

Debian has released a Linux kernel security update addressing 1,313 CVE entries, reflecting the impact of AI-assisted vulnerability discovery on maintainers’ workloads. The update for Debian 13’s kernel version 6.12.111-1 includes many broadly classified issues, some affecting older kernel versions, with CVEs assigned automatically after fixes reach stable kernels to ensure cautious tracking of security implications.

https://www.theregister.com/os-platforms/2026/10/05/debians-latest-kernel-security-update-has-1313-reasons-to-patch/5301124

Is It Fair to Blame ‘Rogue’ AI for Security Failures?

Experts argue that labeling AI incidents as “rogue” anthropomorphizes large language models (LLMs) and shifts responsibility away from vendors, obscuring underlying security failures. Instead, defenders should treat AI systems as unpredictable software requiring strict security architectures with zero-trust principles, limiting access and enforcing controls outside the model to prevent unauthorized actions. While AI agents can autonomously discover and exploit vulnerabilities at unprecedented speed and scale, these issues reflect failures in security controls rather than intentional malicious behavior by the AI itself.

https://www.darkreading.com/insider-threats/blame-rogue-ai-security-failures

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT Via ClickFix Lures

Threat actors are abusing ChatGPT’s Custom GPT feature to trick users into visiting malicious sites that deploy ClickFix lures, leading to the download of a remote access trojan (RAT). The attack starts with sponsored search results directing victims to attacker-created Custom GPTs, which provide links to fake Cloudflare CAPTCHA pages that execute PowerShell commands to install malware using DLL sideloading and evasion techniques. Over 40 users have been infected so far in this campaign, highlighting continued exploitation of trusted AI platforms for social engineering and malware delivery.

https://thehackernews.com/2026/09/attackers-abuse-chatgpt-custom-gpts-to.html

TeamViewer Urges Users to Patch Severe Flaws “as Soon as Possible”

TeamViewer has released security updates to address multiple high-severity vulnerabilities, including a remote session access control bypass that could allow unauthorized remote code execution across Windows, Linux, and macOS platforms. The company strongly urges users to update to version 15.82 immediately to mitigate risks, although no active exploitation or public exploit code has been detected so far. These flaws pose risks of code execution and privilege escalation, highlighting the importance of prompt patching to maintain system security.

https://www.bleepingcomputer.com/news/security/teamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible/

Apple Patches CoreGraphics Zero-Day Flaw Exploited in Attacks

Apple has released security updates to fix a zero-day vulnerability (CVE-2026-86950) in its CoreGraphics framework, exploited in sophisticated targeted attacks on iOS devices. The flaw, an out-of-bounds write weakness, could allow arbitrary code execution, and Apple addressed it with improved bounds checking in iOS 26.7.1, iPadOS 26.7.1, and macOS updates for impacted devices. Users are urged to install these patches promptly to prevent potential exploitation.

https://www.bleepingcomputer.com/news/security/apple-patches-coregraphics-zero-day-flaw-exploited-in-attacks/

JadePuffer Crims Hijacked Azure Identities and Used Them to Blow up Cloud Resources

Microsoft has identified the cybercriminal group Storm-3168, associated with the JadePuffer agentic ransomware, hijacking Azure service principals to conduct extensive cloud resource reconnaissance, destruction, and credential theft over an 18-hour period. The attackers deleted numerous Azure Storage accounts, Key Vaults, and other resources while targeting backup and recovery mechanisms, suggesting preparation for a ransomware attack, although no ransom demand or confirmed data exfiltration occurred. This incident highlights risks from exposed credentials and the potential for automated, AI-driven ransomware operations within cloud environments.

https://www.theregister.com/security/2026/09/28/jadepuffer-crims-hijacked-azure-identities-and-used-them-to-blow-up-cloud-resources/5299591

AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft

Microsoft has disrupted EvilTokens, an AI-driven phishing platform responsible for compromising over 12,000 email accounts across 10,000 organizations worldwide through device code phishing. The platform used AI to craft targeted phishing messages, manage compromised inboxes, and optimize attacks, operating as a paid service until Microsoft seized 50 related websites, disabled 150 domains, and helped arrest two suspects in the UK.

https://www.securityweek.com/ai-powered-phishing-platform-eviltokens-disrupted-by-microsoft/

How Device Code Phishing Gives Scammers Access to Your Account

Device code phishing exploits the OAuth 2.0 Device Authorization Grant by tricking victims into entering a legitimate short code on a real sign-in page, unknowingly approving a scammer’s sign-in request and granting them access to the victim’s account. This attack bypasses typical security measures such as multifactor authentication because the victim themselves authorizes the sign-in, allowing attackers to obtain authentication tokens to access emails, files, or other services depending on granted permissions. Users should be wary of unexpected requests to enter sign-in codes purportedly for meetings or documents and verify legitimate device sign-ins, while monitoring account activity if a scam is suspected.

https://www.malwarebytes.com/blog/how-to/2026/09/how-device-code-phishing-gives-scammers-access-to-your-account

AI Coding Agents’ 0-Click RCE Flaw Could Hand Attackers Keys to the Kingdom

A zero-click remote code execution vulnerability called Plugin4Shell affects major AI coding agents—including Anthropic’s Claude Code, OpenAI’s Codex, Google’s Gemini CLI, and Microsoft’s Copilot—by exploiting a flaw in how these agents enforce SHA-pinning for marketplace plugins. This supply-chain attack allows attackers to replace trusted plugins with malicious versions without user interaction, potentially granting full access to affected systems. While Anthropic and OpenAI have patched the flaw, Google and Microsoft have not fully addressed it, leaving users vulnerable.

https://www.theregister.com/security/2026/09/17/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom/5297335

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts Via Chained Flaws

Researchers at Hacktron leveraged Anthropic’s Claude Opus 5 to chain vulnerabilities—starting from a memory-corrupting image flaw in OpenAI’s public forum software to weaknesses in OpenAI’s single sign-on system—enabling them to take over OpenAI staff ChatGPT and Codex accounts and gain access to internal code repositories. The team reported the issues responsibly, leading to a fix within 14 hours and a $6,500 bounty, while highlighting broader risks where shared single sign-on between public and internal systems can escalate compromises. They also demonstrated AI-assisted exploit development, underscoring how advanced models are accelerating offensive security research and attack capabilities.

https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html

Scroll to Top