Last updated: October 5, 2026 at 10:28 AM UTC
All 897 Vulnerability 362 Breach 144 Threat 384 Defense 7

NadMesh botnet scans for exposed AI services to steal cloud and cluster keys

Researchers at XLab detailed NadMesh, a Go based botnet spreading since early July that hunts exposed AI and automation services rather than raw computing power. A reconnaissance module queries a public device search engine for internet facing instances of tools like Ollama, ComfyUI, n8n, Open WebUI, Langflow, and Gradio, then works through more than twenty exploitation paths. What it ships home is credentials: cloud access keys pulled from environment variables, Kubernetes service account tokens, and the contents of files like .env and Docker configuration. Callable tool endpoints on AI integration servers sit at the top of the operator's priority list, above Kubernetes and exposed Docker APIs.

Check
Check whether any AI or automation services are reachable from the internet, especially Ollama, ComfyUI, n8n, Langflow, or Gradio, plus open Docker APIs, Jenkins consoles, and unauthenticated Redis.
Affected
Teams running self-hosted AI and automation tooling exposed online; NadMesh harvests cloud access keys, Kubernetes service account tokens, and AI integration tool access, targeting the credentials rather than the host.
Fix
Put AI and automation services behind authentication or off the public internet, scope cloud and Kubernetes credentials tightly, avoid long lived keys in those workloads, and rotate anything exposed.

SleeperGem backdoor skips build servers to plant persistence on developer machines

Researchers at StepSecurity documented SleeperGem, a supply chain attack in which malicious versions of three RubyGems packages were published over two days, including one impersonating Microsoft's Git Credential Manager. Each release is a loader that fetches a second stage from an attacker controlled server, then checks around thirty environment variables that continuous integration platforms set. If it finds any, it exits and does nothing; on a developer machine it drops a native daemon and installs persistence. The accounts behind the packages were ordinary ones that had gone dormant for years, which is what made them attractive to hijack, and the releases had no matching source repository tags.

Check
Check developer machines and lockfiles for the malicious gem versions published July 18 and 19, and look for unexpected daemons or persistence rather than relying on build system logs.
Affected
Developers who installed the malicious gem versions on their own machines; the loader deliberately skips continuous integration environments and instead drops a persistent native backdoor where credentials and source code live.
Fix
Remove the affected gem versions, rotate credentials on affected developer machines, treat dormant maintainer accounts and releases without matching source tags as risk signals, and monitor endpoints, not just pipelines.

CISA orders agencies to patch two exploited Fortinet FortiSandbox flaws

CISA has added two critical Fortinet FortiSandbox vulnerabilities to its exploited-vulnerabilities catalog and ordered federal agencies to patch them by July 19. Tracked as CVE-2026-39808 and CVE-2026-25089, both are operating-system command injection flaws that let an unauthenticated attacker run commands remotely with low complexity and no user interaction. Fortinet disclosed and fixed them in April and June, and threat intelligence firm Defused reported in-the-wild abuse of FortiSandbox flaws in June. FortiSandbox is a threat-detection appliance, and Fortinet gear sits at many network edges, so these devices are a recurring target in espionage and ransomware campaigns, making prompt patching important.

Check
Identify Fortinet FortiSandbox appliances in your environment, check their versions against Fortinet's advisories for these flaws, and upgrade to the fixed releases, prioritizing any internet-reachable or edge-facing devices.
Affected
Organizations running affected Fortinet FortiSandbox versions (CVE-2026-39808, CVE-2026-25089); unauthenticated attackers can run commands remotely, and active exploitation of FortiSandbox flaws has been reported, making unpatched appliances a real risk.
Fix
Upgrade FortiSandbox to the fixed versions, such as 4.4.9 for the April flaw, restrict and monitor management access to these appliances, and review logs and configurations for unauthorized commands or changes.

n8n token exchange flaw could let attackers log in as other users

A vulnerability in the workflow automation platform n8n could let an attacker log in as another user without their password. Tracked as CVE-2026-59208, the flaw sits in n8n's Enterprise token exchange feature, which lets embedded deployments avoid a second login by accepting tokens from partner identity providers. Because the code did not properly bind an identity to its issuer, a valid token from one issuer that carried the identifier of a user under a different issuer would log the attacker in as that user. n8n shipped a fix on June 24, and there is no evidence of exploitation. The bug was found by an AI penetration-testing agent.

Check
Check whether you run n8n, especially Enterprise deployments using the token exchange feature for embedding or single sign-on, confirm the version, and update to a release that includes the June fix.
Affected
Organizations running n8n Enterprise deployments that use the token exchange feature (CVE-2026-59208); a flaw in binding identities to issuers could let an attacker present a token and log in as another user.
Fix
Update n8n to a version containing the June 24 fix, review authentication logs for unexpected cross-issuer logins, and apply least privilege so that a single compromised account has limited reach.

Unpatched Shark vacuum flaw lets one stolen certificate control others region-wide

A researcher disclosed an unpatched flaw in internet-connected Shark robot vacuums that lets an attacker take control of other owners' units across the same cloud region. The certificate a vacuum uses to authenticate to its maker's Amazon cloud broker was never restricted to that one device, so a certificate pulled from a vacuum's flash memory can send root commands to any Shark vacuum the broker serves. That means watching the camera, driving the robot, reading the stored map of a home, and taking the Wi-Fi password in plaintext. No memory corruption or password guessing is needed. The researcher says the maker has had the report since March with no fix.

Check
If Shark robot vacuums are on your network, isolate them and other smart-home devices on a separate segment away from sensitive systems, keep their firmware current, and watch for the vendor's fix.
Affected
Owners of internet-connected Shark robot vacuums; an attacker with a certificate from one unit can run root commands on others region-wide, exposing camera feeds, home maps, and Wi-Fi passwords.
Fix
Isolate smart-home devices on their own network segment, limit what they can reach, and watch for the vendor to rescope its cloud certificate policy or reissue certificates, the real fix here.

Coca-Cola's Fairlife halts US dairy production after a ransomware attack

Coca-Cola disclosed in a securities filing that a ransomware attack on its Fairlife dairy subsidiary has disrupted operations and temporarily suspended production across the United States. The company said Fairlife detected unauthorized access to some systems, including production-related systems, and that it activated incident response and business continuity plans, brought in outside experts, and notified law enforcement. It says product quality and safety were not affected, and Canadian operations continue. The full impact is still being investigated, and no ransomware group has been named. Ransomware at food and beverage producers has caused weeks-long shutdowns and empty shelves in past incidents.

Check
Manufacturers should review their ability to keep production running during a cyberattack, confirm that business and production systems are segmented, and test backups and incident-response and continuity plans against a ransomware scenario.
Affected
Manufacturers and food and beverage producers whose production depends on connected systems; a ransomware attack can force a full production halt even when product safety is unaffected, as with Fairlife's US suspension.
Fix
Segment production and business networks, maintain tested offline backups, enforce phishing-resistant MFA on remote access, rehearse recovery, and prepare business-continuity plans that keep critical operations running during a systems shutdown.

ClickLock macOS malware kills apps in a loop until victims type their password

Group-IB detailed ClickLock, a macOS infostealer that coerces victims into handing over their login password. It arrives when a user is tricked into pasting a command into Terminal from a fake verification page, then shows a fake system dialog asking for the password. If the victim refuses, ClickLock begins killing core apps like Finder, the Dock, and browsers every 210 milliseconds, leaving only a password box on an unusable desktop, while also suppressing security notifications. Once the password is entered, it steals the Keychain, browser credentials, and cryptocurrency wallets and sends them to a Telegram bot. Group-IB counted at least 100 targets across 33 countries, over half in Europe.

Check
Warn Mac users never to paste Terminal commands from a website, and never enter a password to stop apps crashing; a Mac killing its own apps behind a password box is malware.
Affected
Mac users tricked into pasting a command from a fake verification page; ClickLock pressures them into entering their password by killing apps in a loop, then steals Keychain data and crypto wallets.
Fix
Only run Terminal commands you fully understand from trusted sources, treat app-killing loops and unexpected password prompts as attacks, and if infected, change passwords and wallet keys from a clean device.

New attack makes AI agents treat attacker data as trusted content

Researchers described Agent Data Injection, a new twist on prompt-injection attacks against AI agents. Rather than smuggling in fake instructions, it exploits the weak separation between trusted and untrusted data so that attacker-supplied content is mistaken for the agent's own trusted data, using deliberately ambiguous delimiters the model misreads. In tests against web and coding agents, this let an attacker steer an agent's clicks or actions, succeeding up to half the time even against defenses that block ordinary instruction injection. Some approaches helped: tagging page elements with random, unguessable identifiers roughly halved success, while strict tracking of where data came from stopped it but sharply reduced how many tasks agents completed.

Check
Review where AI agents in your environment consume untrusted content such as web pages, tickets, or logs, and check whether they clearly separate that data from trusted instructions and internal state.
Affected
Users and organizations running web or coding AI agents that act on external content; attackers can craft data the agent treats as trusted, steering its actions past defenses built for instruction injection.
Fix
Prefer agents that isolate and label untrusted data, use unguessable identifiers for page elements, track data provenance where feasible, keep a human in the loop for sensitive actions, and weigh usability costs.

Russian actor hides Starland malware in fake WebEx, Zoom, and dev-tool installers

Cisco Talos detailed a financially motivated Russian group, tracked as UAT-11795, that spreads a new backdoor called Starland RAT through trojanized installers for legitimate software including WebEx, Zoom, MobaXterm, DBeaver, and FaceIT. Active since at least mid-2025 and mainly hitting US victims, the campaign likely uses fake verification lures to deliver the installers. Once run, the malware sets up persistence, tries to escalate privileges, and detects sandboxes, then steals browser data and more than 40 kinds of cryptocurrency wallets, profiles the machine, and maps Active Directory. It can take screenshots, run shell commands, inject shellcode, and pull down further payloads, giving the operator broad control.

Check
Remind users to download software, especially collaboration and developer tools, only from official vendor sites, and watch for trojanized installers delivered through fake verification pages or paste-into-terminal style lures.
Affected
Users who install trojanized versions of tools like WebEx, Zoom, MobaXterm, or DBeaver; Starland RAT then steals credentials and crypto wallets, maps Active Directory, and gives the attacker persistent machine control.
Fix
Enforce software installation from trusted sources, use application allow-listing, block known indicators, monitor for suspicious HTA and installer activity and Active Directory reconnaissance, and hunt for Starland's persistence and shellcode behaviors.

Zoom patches critical flaw that could let attackers take over Windows accounts

Zoom has patched a critical vulnerability in its Windows software that could let an unauthenticated attacker take over user accounts over the network. Tracked as CVE-2026-53412 and rated 9.8, the flaw is an improper input validation issue affecting Zoom Workplace for Windows, the VDI client, and the Meeting SDK before version 7.0.0. Zoom found it internally, shared no technical details, and says there is no evidence of exploitation or public exploit code yet. Because the Windows client sits on millions of corporate desktops and the flaw needs no credentials or user interaction, it poses a broad risk, so applying the latest updates promptly is the key mitigation.

Check
Inventory where Zoom Workplace for Windows, the VDI client, or the Meeting SDK are deployed, check their versions, and roll out 7.0.0 or later, prioritizing widely used and internet-reachable systems.
Affected
Organizations and users running Zoom Workplace for Windows, the Windows VDI client, or the Windows Meeting SDK before version 7.0.0 (CVE-2026-53412); an unauthenticated network attacker could take over accounts without user interaction.
Fix
Update all affected Zoom Windows components to version 7.0.0 or later, apply the accompanying fixes for the related privilege-escalation flaws, and keep Zoom clients on automatic updates where possible.