Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

Carbonato botnet hijacks exposed Docker hosts to run a Telegram controlled AI agent

ThreatDown detailed Carbonato, a botnet that targets Docker daemons exposed without authentication on port 2375 and deploys the open-source Hermes Agent AI framework. It installs the framework unchanged, then overwrites its SOUL.md persona file with a 39-line prompt directing the agent to execute tasks received over Telegram, maintain persistence, and collect credentials. On each host it launches a privileged container to run commands on the underlying system, then scans neighboring networks every five minutes to spread further, giving it worm-like propagation. Researchers found the operation through an unauthenticated Docker registry publicly accessible since May, whose staged data included details of the botnet and a separate campaign distributing trojanized cryptocurrency wallet apps.

Check
Ensure no Docker daemon is exposed on port 2375 without authentication, restrict daemon access, and hunt hosts for Hermes Agent and rogue privileged containers.
Affected
Hosts running Docker daemons reachable without authentication on port 2375 can be taken over, run a Telegram-controlled AI agent, and be used to spread further.
Fix
Bind the Docker API to localhost or protect it with TLS and authentication, segment container hosts, and alert on unexpected privileged containers.

Popular Chrome ad blocker extensions disclose selling users' browsing data to third parties

LayerX research found dozens of Chrome extensions, reaching millions of users, that legally sell or share user data under terms accepted at install. Among ad blockers, it confirmed eight reserving the right to sell or share user information, together reaching over 5.5 million users. Stands AdBlocker, with three million users, sells browsing data for market analytics, and Poper Blocker, with two million users, discloses selling identifiers, browsing activity, and behavioral profiles inferred from visited URLs. Smaller ad blockers route browsing data and even AI conversations through data brokers. The finding shows tools installed to stop tracking can themselves become data exfiltration channels, a browser extension supply chain risk static malware scanning misses.

Check
Inventory browser extensions across managed fleets, remove data-selling ad blockers like the named ones, and enforce an allowlist for permitted extensions.
Affected
Users who installed these ad blockers consented in the terms to having their browsing data, identifiers, and inferred profiles sold or shared with third parties.
Fix
Deploy an enterprise extension allowlist, review extension permissions and privacy terms, and educate users that ad blockers can monetize their data.

Lunex stealer abuses vulnerable AMD driver to disable security tools and steal credentials

Ontinue tied the Psychedelic Stealer, spread through compromised Ukrainian websites using ClickFix-style fake Cloudflare verification pages, to a wider malware-as-a-service platform called Lunex. The chain starts with a bogus CAPTCHA that delivers a malicious MSI, which drops LunexLoader. The loader bypasses User Account Control through the CMSTPLUA COM object, then uses a bring-your-own-vulnerable-driver technique against the AMD Radeon Software driver PDFWKRNL.sys, affected by CVE-2023-20598, to escalate and evade defenses before fetching the stealer. Researchers note BYOVD is rarely used as a precursor to an infostealer. The final payload extracts credentials from seven Chromium-based browsers, exfiltrates cryptocurrency wallets, and installs a PowerShell-based browser Native Messaging Host for persistent remote filesystem access.

Check
Block the vulnerable PDFWKRNL.sys driver via Microsoft's blocklist, alert on ClickFix-style CAPTCHA lures, and hunt for rogue browser Native Messaging Hosts.
Affected
Windows users tricked by fake Cloudflare CAPTCHA lures run an MSI that loads a vulnerable AMD driver to disable defenses and steal browser and wallet data.
Fix
Enable the vulnerable driver blocklist, restrict MSI and script execution, block copy-paste run-dialog lures, and monitor for UAC bypass via CMSTPLUA.

Compromised GitHub Actions came back online still executing Mini Shai-Hulud credential malware

Socket reported that two GitHub Actions, actions-cool/issues-helper and actions-cool/maintain-one-comment, were disabled a second time after their repositories became accessible again on September 16, months after being compromised in the May Mini Shai-Hulud campaign. When the repositories returned, their release tags were not cleaned up and still pointed to the malicious content introduced on May 18, so any workflow referencing either action by a version tag resumed downloading and executing the payload on its next run. The original May 18 compromise ran code that harvested credentials from CI/CD pipelines and exfiltrated them, activity linked to the Mini Shai-Hulud cluster through a shared exfiltration domain. GitHub has again disabled both repositories.

Check
Audit workflows for references to the two actions-cool actions, pin actions to trusted commit hashes, and rotate any CI/CD secrets exposed since September 16.
Affected
Pipelines referencing the affected actions-cool actions by version tag re-ran the May 18 payload after September 16, harvesting and exfiltrating CI/CD credentials.
Fix
Remove or repin the actions to vetted commits, rotate pipeline secrets, and prefer commit-hash pinning over mutable version tags for third-party actions.

PamStealer macOS malware adds server-side decryption and fake crypto wallet lure

Jamf Threat Labs flagged a new version of the PamStealer macOS infostealer that can only be unpacked with the attacker's server. Earlier variants embedded payload key material directly in the JavaScript for Automation dropper, but the latest completes a key exchange with the server before the payload unwraps, so it cannot be recovered from a static sample alone. The lure also changed: where July and August versions impersonated the Maccy, Scoppr, and Nancy Clipboard apps, victims are now drawn to a fake site advertising a non-existent cryptocurrency wallet called Wavel. Clicking Download for macOS retrieves a disk image whose AppleScript opens Script Editor with instructions to run the dropper.

Check
Warn macOS users against installing apps from search-driven download sites, and alert on AppleScript files opening Script Editor and JXA droppers reaching external servers.
Affected
macOS users lured by the fake Wavel crypto wallet site run a JXA dropper that fetches a server-side decrypted stealer payload with layered persistence.
Fix
Restrict installation to trusted sources, monitor for JXA and osascript activity contacting unknown hosts, and educate users on fake wallet and app lures.

Attackers plant Go malware in HashiCorp Terraform registry in first such supply chain abuse

Aikido disclosed Go-based malware distributed through two Go modules and two Terraform providers, the first time attackers have used HashiCorp's centralized registry as a distribution vector. The flagged items include kreuzwenker/docker, with 1,449 downloads, and gocommunity-io/dockerd, alongside two Go modules. The malware overlaps with the Graphalgo campaign that ReversingLabs attributed to North Korean actors in February, in which developers are approached on LinkedIn, Facebook, or job forums by fake Web3 companies and asked to run a benign repository that pulls the malicious behavior from a dependency. The discovery coincides with a fresh batch of malicious npm and PyPI packages delivering the same threat, flagged by Checkmarx, JFrog, and SafeDep.

Check
Vet Terraform providers and Go modules by publisher and source, pin and review versions, and scan developer machines for the flagged packages and modules.
Affected
Developers pulling the malicious Terraform providers or Go modules, or the paired npm and PyPI packages, execute Go malware tied to the Graphalgo campaign.
Fix
Restrict registries to vetted providers, enforce allowlists for infrastructure-as-code sources, and treat unsolicited coding tasks from recruiters as supply chain risk.

ShinyHunters claims FBI breach through Oracle PeopleSoft zero-day as agency stays silent

The extortion group ShinyHunters claimed on its dark web site that it breached the FBI and stole data on current and former employees and job applicants, naming Criminal Justice, HR, and Medlink services. A spokesperson told The Register the group exploited a new Oracle PeopleSoft zero-day to gain remote code execution and deface the FBI jobs site. The claim, first reported by 404 Media, is unverified, and the FBI has not confirmed any compromise. ShinyHunters framed it as retaliation for a May FBI advisory about its Canvas targeting, disputing those allegations and rejecting reported ties to the wider criminal collective. Treat the specifics as an attacker claim pending independent confirmation.

Check
Track independent confirmation before acting, and separately prioritize Oracle PeopleSoft patching and exposure review given repeated zero-day claims against that platform.
Affected
Internet-facing Oracle PeopleSoft deployments are the claimed entry point, so unpatched or exposed HR and applicant systems on that platform warrant urgent review.
Fix
Apply current PeopleSoft security fixes, restrict and monitor internet-facing instances, and wait for verified reporting before drawing conclusions about the FBI claim.

Malicious npm package impersonates Twilio bug bounty probe to exfiltrate developer credentials

ReversingLabs detailed a malicious npm package, tw-pkgprobe-7731, that masquerades as an authorized Twilio bug-bounty research probe while harvesting developer data. Uploaded in mid-August by an account that no longer exists, it shipped eleven versions within about 45 minutes. Comments inside describe it as an authorized HackerOne probe that runs only inside Twilio's serverless sandbox and takes no destructive action. On execution it first checks for a Twilio developer environment and exits otherwise, then collects environment variables plus system details like mounts and temporary folders and exfiltrates them through a webhook. Later versions specifically target developers using Twilio APIs by searching for folders tied to particular Twilio account identifiers, sharpening the credential theft.

Check
Block and audit for tw-pkgprobe-7731 across developer and build environments, then rotate Twilio credentials and API keys exposed on any affected machine.
Affected
Developers integrating Twilio who installed the package inside a matching environment had environment variables and account-linked configuration harvested and sent to an attacker webhook.
Fix
Pin and vet npm dependencies, alert on packages that fingerprint the environment before acting, and restrict outbound webhooks from build and developer hosts.

Rogue external MFA provider in Entra captures user passwords during legitimate logins

Varonis Threat Labs detailed a post-compromise technique it calls TrustSink, in which an attacker holding a highly privileged Microsoft Entra account registers a rogue External Authentication Method as an external MFA provider. During normal sign-ins, Entra redirects users to the rogue provider to complete the second factor, and the attacker inserts a convincing Microsoft password prompt that captures the password in plaintext before returning a valid signed token, so the login completes with no error. In testing, every sign-in succeeded while the attacker server logged passwords with source IPs. Resetting a captured password does not remove the rogue provider, which persists in the configuration and works against any external provider model.

Check
Audit Entra External Authentication Methods for unrecognized providers, remove rogue entries, and tighten which roles can register or modify external MFA providers.
Affected
Tenants where an attacker already holds a highly privileged Entra role can have a rogue external MFA provider silently harvest every user's password during normal logins.
Fix
Restrict and monitor privileged Entra roles, alert on External Authentication Method changes, and review provider configuration after any privileged-account compromise.

Fake LastPass installer loads signed kernel driver that disables antivirus and endpoint defenses

LastPass and Delphos Labs reported a fake LastPass Authenticator installer, hosted on a lookalike GitHub page, that installs a Windows kernel driver to shut off security software before a password stealer runs. The driver, named Alinubx.sys, was signed through Microsoft's hardware-compatibility program, scored zero detections on VirusTotal in August, and was not on Microsoft's blocklist. It carries 145 antivirus and security process names and terminates each from the kernel, below where endpoint tools can see or block it. The installer uses DLL side-loading through a renamed Microsoft debugger, escalates to SYSTEM, and ships in padded 128 to 148 MB archives to evade size-limited scanners.

Check
Warn users to install LastPass Authenticator only from official stores, and hunt endpoints for Alinubx.sys, vsdbg side-loading, and unexpected kernel-mode drivers.
Affected
Windows hosts where a user runs the fake installer get a signed kernel driver that silently kills antivirus and endpoint detection before credential theft.
Fix
Deploy Microsoft's vulnerable driver blocklist, restrict driver loading, block the lookalike GitHub domain, and alert on mass termination of security processes.