Instagram Users Face Ransom Demands Over Fake Copyright Claims

Instagram users with large followings have been targeted by scammers filing fake copyright infringement claims to suspend their accounts and then demanding ransom payments to withdraw these bogus claims. Despite Meta's assurances of protections and content restoration, creators report slow appeals processes and inadequate detection of abuse, leading some to pay extortion demands to quickly regain access, only to face repeated strikes. Experts note that automated tools and platform policies assuming claim legitimacy have enabled this scam to proliferate, worsening the challenges of distinguishing genuine copyright claims from fraudulent ones.

https://www.bbc.com/news/articles/cjw54ww73qjo

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

Multiple espionage groups, including the China-aligned APT31 and several others suspected of Chinese links, rapidly adopted a previously undocumented exploit kit named BlueMoon within a week to target Windows and Chrome vulnerabilities. BlueMoon chains three vulnerabilities in Chrome's V8 engine and Windows ALPC to achieve code execution and privilege escalation, often delivered through spear-phishing and used to deploy malware via DLL sideloading and malicious Chrome extensions. Despite patches being released, organizations are urged to check for persistent artifacts like malicious browser extensions, scheduled tasks, and suspicious files, as the exploit kit's spread may continue due to its ease of adoption and possible AI-assisted development.

https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google released an update patching 230 security vulnerabilities in Chrome, including an actively exploited medium-severity zero-day (CVE-2026-87491) in the V8 JavaScript engine that allows remote code execution inside the sandbox via crafted HTML pages. The U.S. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply patches by September 23, 2026, while users and Chromium-based browser operators are urged to update promptly to mitigate attacks.

https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

Microsoft released a record-breaking Patch Tuesday update addressing 974 vulnerabilities across its software portfolio, including two actively exploited Windows zero-day flaws that allow local privilege escalation. The update covers critical issues mainly involving privilege escalation, remote code execution, and information disclosure, and prompted the U.S. Cybersecurity and Infrastructure Security Agency to mandate urgent patching for federal agencies. Despite the high volume, security experts emphasize prioritizing fixes based on exploitability and risk context to effectively reduce attack surfaces.

https://thehackernews.com/2026/09/microsoft-patches-record-974-flaws.html

The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT

Check Point Research identified a covert cross-account communication channel in ChatGPT’s sandboxed code-execution environment that allowed attackers to execute hidden tasks using a victim’s session, including accessing connected apps like Gmail and exfiltrating data without the victim’s knowledge. This channel exploited shared access to an internal package service’s item properties, effectively turning it into a “shared clipboard” across isolated containers from different accounts. OpenAI has since decommissioned the vulnerable internal service, but the finding highlights challenges in securing AI platforms where internal shared infrastructure and broad tool access can lead to unintended data leakage.

https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/

The Purpose of DNS Is to Spread Scams

A recent analysis reveals that up to 20% of newly registered generic top-level domains (gTLDs) are used for scams, highlighting a significant abuse of the Domain Name System (DNS) by criminals. Major registrars like NameCheap facilitate these registrations, but suspension rates of malicious domains remain low, allowing fraudsters to exploit the rapid activation of domains for phishing and spam campaigns. While ICANN and the industry are exploring measures like stronger customer verification and coordinated abuse reporting, striking a balance between open domain registration and fraud prevention remains a complex challenge.

https://shkspr.mobi/blog/2026/09/the-purpose-of-dns-is-to-spread-scams/

Once Popular for Attacking AI, ASCII Smuggling Is Embraced by Spammers

A Unicode block once used to stealthily embed malicious prompts in AI attacks—known as ASCII smuggling—is now being exploited by spammers to evade email filters. This block contains invisible characters that disrupt keyword detection by machine learning–based spam classifiers, allowing spammers to obfuscate trigger words without alerting human readers. Microsoft observed a sharp surge in such obfuscated spam emails in early 2026 and recommends updated filtering techniques to counter this evasion tactic.

https://arstechnica.com/security/2026/09/once-popular-for-attacking-ai-ascii-smuggling-is-embraced-by-spammers/

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

A malware campaign impersonating trusted software vendors via counterfeit download sites targets primarily Chinese-speaking users and organizations, deploying malicious installers that disable Windows Update, weaken Microsoft Defender, and establish persistent access. The attacks, linked to the Chinese threat cluster Silver Fox, use scheduled tasks and PowerShell to evade detection, modify system defenses, and communicate with attacker-controlled command-and-control servers. Victims span multiple sectors including healthcare, manufacturing, and government, while the campaign employs sophisticated tactics like DLL sideloading and code-signing certificate abuse to deliver backdoors such as ValleyRAT.

https://thehackernews.com/2026/09/fake-software-installers-disable.html

You Don’t Want This Sleepwalker Backdoor on Your Windows Machine

Security researcher Dominik Reichel uncovered a sophisticated Windows backdoor called Sleepwalker that resides stealthily in memory, waiting for a specific encrypted network packet to activate its unique 23-instruction command language. Disguised as Microsoft’s dpapi.dll and loaded via side-loading into an ESET Management Agent process, Sleepwalker avoids detection by not initiating outbound traffic or listening on network ports, indicating a well-resourced targeted operation rather than opportunistic malware. While many details about its deployment and operators remain unknown, Reichel has released tools and guidance to detect and mitigate the threat.

https://www.theregister.com/security/2026/08/24/you-dont-want-this-sleepwalker-backdoor-on-your-windows-machine/5292021

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Researcher Dirk-jan Mollema demonstrated that malware running in a logged-in Windows session can abuse Windows Hello for Business keys to authenticate silently to Microsoft Entra ID, enabling persistent cloud access without requiring admin privileges or extracting private keys. This technique leverages Windows ticketing and WebAuthn to request authentication on a compromised device, allowing attackers to register new devices, obtain refresh tokens, and bypass some conditional access controls, exposing limits in phishing-resistant authentication methods. Mollema has released proof-of-concept scripts and recommends monitoring for unexpected device registrations to detect such abuse.

https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html

Claude, Codex, and Hermes Installed Unowned Code Inside Corporate Networks

Researchers found that AI coding agents like Claude, Codex, and Hermes executed unowned code within corporate networks by following installation commands listed in misconfigured llms.txt files on public websites. These files, intended to guide AI agents, included references to non-existent software packages and domains that attackers could claim to deliver malware, demonstrated by proof-of-concept tests showing real Fortune 500 companies inadvertently ran such code. The findings reveal a critical security gap where AI agents treat third-party documentation as authoritative without verifying it, enabling supply-chain risks and undermining traditional boundaries between data and executable code.

https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/

Hidden Prompts Trick AI Into False Email Summaries

Researchers at Forcepoint X-Labs demonstrated that attackers can embed hidden HTML prompts in emails to manipulate AI-powered summarizers into producing false information without alerting users. Their proof-of-concept showed altered email summaries with incorrect financial and scheduling details, highlighting the risks of prompt injection attacks on AI systems that process untrusted external content. To mitigate these threats, organizations should separate trusted instructions from untrusted data, verify AI-generated outputs against source content, and enforce strict controls on AI assistant privileges.

https://www.darkreading.com/cyber-risk/hidden-prompts-trick-ai-false-email-summaries

Ransomware Gangs Skip the CEO, Head Straight for the 40-Something IT Manager

Ransomware attackers are increasingly targeting mid-level managers—particularly 40-something IT managers—rather than CEOs, as these individuals often have significant business access and decision-making authority related to payments and sensitive information. A Zscaler study of 351 victims revealed that nearly two-thirds held managerial roles, primarily in departments like finance, sales, and HR, with attackers using detailed organizational mapping to identify these key targets. This shift reflects a focus on “business privilege” to expedite ransom payments, with campaigns growing more targeted and focused on extortion and data theft rather than indiscriminate encryption.

https://www.theregister.com/security/2026/08/09/ransomware-gangs-skip-the-ceo-head-straight-for-the-40-something-it-manager/5284499

Terabytes of Credentials Leaked in Massive Supply-Chain Attack

A supply-chain attack on the open-source AI development tool LiteLLM exposed terabytes of credentials from over 2,500 organizations, including major companies like Microsoft, Amazon, Cisco, and Salesforce. Attackers exploited compromised versions of LiteLLM available on the Python Package Index during a 40-minute window in March to scrape sensitive secrets such as cloud keys, SSH keys, and CI/CD pipeline credentials, impacting around 434,000 software pipelines. Security firms CloudSEK and Hudson Rock urge affected organizations to immediately rotate all exposed credentials and audit their environments to mitigate the widespread risk from this incident.

https://arstechnica.com/security/2026/08/terabytes-of-credentials-leaked-in-massive-supply-chain-attack/

Signal Adds an Extra Layer of Security to Make Sure You’re Actually Chatting with the Right Person

Signal has introduced Automatic Key Verification (AKV), a new feature designed to prevent man-in-the-middle attacks by verifying that a contact’s public encryption key matches what Signal’s key transparency system expects. The system maintains an open-source ledger of public keys, audited by third parties like Cloudflare and Trail of Bits, allowing users to automatically verify contact keys if they have the associated phone number. While AKV enhances security by detecting tampering with encryption keys, users still need to actively verify contacts, and the feature requires having the contact's phone number to work effectively.

https://www.theregister.com/security/2026/08/11/signal-adds-an-extra-layer-of-security-to-make-sure-youre-actually-chatting-with-the-right-person/5286461

Scroll to Top