Cybersecurity startup Gambit says a financially motivated threat actor has been using open-source AI agent tools since July to attack online retailers at scale, breaching at least 27 companies in a five-day span and launching over 100 attacks. The operation reportedly stole more than 600,000 valid card records from two companies and planted skimmer malware on five others, using three tools—Strix for scanning, Cairn for exploitation, and Hermes, powered by Claude Opus 4.6, for orchestration and tactical decisions.
bleepingcomputer.com
· 2026-09-23
Cisco Talos researchers identified Windows malware named CLOSEDQUORUM that consults DeepSeek, Qwen, Mistral and Google Gemini to decide its next actions on infected machines, continuing to function if one service goes down. The tool, designed to steal credentials and cryptocurrency, has no built-in mechanism for human operators to issue commands directly, and Talos linked it to 2025 credit-card fraud forum activity, though the creator and any real-world targets remain unidentified.
techspot.com
· 2026-09-23
Cybersecurity firm SpyCloud analyzed over 66,000 public-facing systems tied to roughly 10,000 EPA-registered water and wastewater organizations and discovered that infostealer malware had already harvested login credentials from 1,787 of them. At least 250 of those organizations had exposed credentials that could grant access to operational networks controlling physical pumps and water flow. In one case, malware on a device belonging to a metering technology vendor exposed passwords for 167 utilities that relied on its services.
techcrunch.com
· 2026-09-22
Cisco Talos researchers identified a Go-based Windows malware called ClosedQuorum that queries Google Gemini, DeepSeek, Qwen, and Mistral to decide post-compromise actions without human input. The models vote on options such as credential theft, code injection, and persistence, with DeepSeek breaking ties, and stolen data is sent to attackers via a Discord webhook.
bleepingcomputer.com
· 2026-09-22
Cisco Talos researchers released an open-source system called CAIRN designed to detect and classify malware that relies on artificial intelligence for decision-making. Using the tool, they identified a new strain, CLOSEDQUORUM, which queries up to four large language models to determine its next actions inside a compromised system rather than following pre-programmed commands.
wired.com
· 2026-09-22
An extension can read and change everything you do in the browser, including pages you are signed into. That is worth about ninety seconds of checking first.
gokawiil.com
· 2026-09-22
Security researchers at SafeDep discovered that a malicious npm package called mathmain, disguised as a copy of the popular mathjs library, contains a hidden remote access implant. The malicious code stays encrypted and dormant until a specific equation is solved using the library's lusolve() solver function, which acts as a decryption key to unlock and execute the payload.
safedep.io
· 2026-09-21
Authorities in Australia, Germany, Japan and the US say a North Korean hacking group known as WaterPlum has compromised over 30,000 devices and 7,000 crypto wallets by posing as recruiters and sending malware-laced coding tests to tech workers. The scheme has netted at least $10.71 million in cryptocurrency, funneled back to North Korea.
techspot.com
· 2026-09-21
Security researchers uncovered a North Korean state-linked hacking operation that impersonated job recruiters to trick victims into installing malware, ultimately compromising roughly 30,000 devices across multiple countries. The campaign used fake hiring processes and interview-related documents as delivery mechanisms for malicious software.
yro.slashdot.org
· 2026-09-21
Security firm Zimperium has identified RatHat, a new Android malware strain that tricks users into installing a fake app resembling Google Chrome through a spoofed Play Store page. Once granted accessibility permissions, it silently enables developer-level ADB Shell access, deploys an AI-driven agent to run system commands, and funnels stolen data to remote servers. Researchers have already found 162 infected apps tied to roughly a dozen attacker-controlled servers, with China-linked actors primarily targeting payment apps like WeChat Pay and Alipay.
cnet.com
· 2026-09-20
Windows 11 includes Microsoft Defender, a free antivirus tool within Windows Security that automatically scans for threats and logs its findings under Virus & threat protection. Users can review allowed threats and protection history, run a deeper Full scan, or use an offline scan via Windows Recovery Environment to catch malware that hides from standard scans. The Firewall & network protection settings should also be checked to ensure all three connection types are protected.
engadget.com
· 2026-09-19
Security firm Sublime found that malicious calendar invites sent via email, known as ICS phishing, have surged dramatically, rising 282% in June, 338% in July, and 1,216% in August, with a projected 2,852% jump in September. These fake invites exploit a default feature in Outlook, Gmail, and Apple Mail that auto-adds ICS files to a user's calendar before they accept or decline them.
zdnet.com
· 2026-09-18