Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

Researcher remotely controls BYD Shark 6 lights locks and cabin audio in authorised test

In an authorised test reported by ABC Four Corners on September 21, automotive security researcher Dan Hreszczuk remotely locked doors, operated wipers and washers, toggled headlights while the vehicle moved slowly, and played media through the infotainment system of a BYD Shark 6, while also tracking it and accessing in-cabin audio. He said the access path his team used had no password. He could not reach brakes or cameras and considered those well protected, and found no control over steering or acceleration. ABC did not publish the model year, software build, initial access method, affected versions, or a vulnerability identifier, so fleet-wide reproducibility remains unestablished.

Check
Treat this as a single prepared-vehicle demonstration, not a fleet-wide exploit, and track for a vendor advisory, affected builds, or independent replication before acting.
Affected
One BYD Shark 6 allowed remote control of lights, locks, wipers, and infotainment plus location tracking and cabin audio through an access path reportedly lacking a password.
Fix
For connected fleets, review remote-access authentication on comfort and telematics functions, segment them from safety systems, and press vendors for disclosure detail.

New ChainScript trojan hides command server in a Polygon blockchain smart contract

Blackpoint researchers documented ChainScript, a previously unseen remote access trojan spread through ClickFix-style lures that impersonate Spotify, Zoom, and Microsoft Teams. It uses an EtherHiding-style technique, querying a Polygon smart contract to locate its active WebSocket command infrastructure so operators can rotate servers without changing the malware. The chain starts with a ClickFix lure leading to a malicious MSI run through msiexec, which deploys a Node.js runtime and launches a JavaScript agent through hidden PowerShell and VBScript stages dropped into Microsoft-looking paths under LOCALAPPDATA. ChainScript offers interactive command shells, file operations, screenshots, remote JavaScript, and enumeration of cryptocurrency wallets in both desktop applications and browser extensions.

Check
Block ClickFix-style paste-to-run lures, alert on msiexec spawning Node.js with PowerShell and VBScript stages, and review crypto wallet exposure on developer endpoints.
Affected
Users tricked by fake Spotify, Zoom, or Teams ClickFix lures run an MSI that installs a resilient RAT enumerating desktop and browser crypto wallets.
Fix
Restrict msiexec and script interpreters, monitor outbound blockchain RPC from endpoints, and educate staff against copy-paste terminal or run-dialog instructions.

Malicious npm package hides loader in runtime method to bypass install script controls

Checkmarx found an ongoing npm campaign built around indexed-btree, a package impersonating the popular sorted-btree library that has amassed two million weekly downloads. Instead of using preinstall or postinstall scripts, the malware hides its loader inside the BTree.prototype.set method that applications call constantly, so it executes at runtime rather than install time. This sidesteps the npm approval gates GitHub added in June to block lifecycle scripts, and installation looks clean to static scanners. Once triggered, it fingerprints the host, exfiltrates details over hardcoded Slack and Telegram channels, and polls an Ethereum Sepolia smart contract for encrypted second-stage commands.

Check
Audit dependency trees for indexed-btree and typosquats of sorted-btree, then remove them and rotate any credentials exposed to affected build or runtime hosts.
Affected
Projects that installed indexed-btree run the loader the first time application code calls the tree, giving attackers host fingerprinting and staged command execution.
Fix
Pin dependencies to reviewed versions, scan for runtime-triggered loaders not just install scripts, and block outbound Slack, Telegram, and testnet RPC from build hosts.

Stolen Cloudflare key let attackers poison Brevo scripts on 100,000 sites

Attackers stole a Cloudflare API key from marketing platform Brevo and used it to inject malicious code into the scripts that Brevo's customers embed on their own websites, affecting more than 100,000 sites. The key was long-lived, had full account permissions, and was hardcoded in application source code, which let the attackers create a Cloudflare Worker that modified Brevo's forms, widget, and loader scripts at the network edge for about five and a half hours. Visitors saw a fake verification page with ClickFix instructions to run a command on Windows, and on WordPress sites where an admin was logged in, the script tried to silently install a backdoor plugin.

Check
Keep API keys out of source code, replace long-lived full-permission keys with scoped short-lived credentials in a secrets manager, and review third-party scripts your sites embed for unexpected changes or injected content.
Affected
Websites embedding Brevo's scripts and their visitors during the incident; a stolen key let attackers modify those trusted scripts at the edge to push ClickFix malware and a WordPress backdoor plugin.
Fix
Scope and rotate API keys, store them outside code, constrain embedded third-party scripts with subresource integrity and content security policy, monitor for edge content changes, and teach users to reject paste-a-command prompts.

RatHat Android malware turns on wireless debugging to control phones and survive removal

Researchers at Zimperium documented RatHat, an Android banking trojan that gains deep control of a phone by abusing its own debugging tools. After tricking the user into granting accessibility permissions, it uses automated taps to enable wireless debugging, reads the on-screen pairing code, and connects to the phone's local debugging service to get shell-level access with no computer attached. It then drops components that disable security apps, open a hidden tunnel to the attacker, and restore the malware even after uninstall, intercepting the removal screen with a fake error. RatHat also uses a generative-AI engine to read the screen and navigate on its own, making it more adaptable than scripted malware.

Check
Warn users not to sideload apps from links, ads, or third-party stores, not to grant accessibility to unexpected apps, and to watch if developer options or wireless debugging turn on by themselves.
Affected
Android users who sideload apps disguised as streaming, browser, or banking software and grant accessibility; RatHat then enables wireless debugging to gain shell access, steal banking data, and persist beyond uninstallation.
Fix
Restrict sideloading and accessibility grants through mobile device management, deploy mobile threat detection, keep Google Play Protect enabled, and on infected phones expect a factory reset may be needed for full removal.

Attacker hijacks an AI coding session and spreads Shai-Hulud to 100 repositories

Mandiant reported that an attacker hijacked a developer's active AI coding-assistant session at a software company and used it to spread the self-replicating Shai-Hulud worm across about 100 internal code repositories. The chain started when the AI assistant recommended a piece of software the attacker had poisoned, and the developer accepted the suggestion. Using the live session, the attacker installed an infostealer through a poisoned PyPI package and stole GitHub access tokens, then unleashed the worm, which stole repository secrets and source code. The attacker also poisoned a package in the company's own namespace, so a second developer's pull caused a reinfection. It shows AI-recommended dependencies as a new poisoning path.

Check
Check dependencies that an AI assistant recommends against cryptographic checksums and an approved allowlist before installing them, and keep API keys and long-lived OAuth tokens out of reach of coding-assistant extensions.
Affected
Development teams using AI coding assistants that install dependencies with the developer's credentials; a poisoned recommendation or hijacked session can plant an infostealer, steal tokens, and spread a worm through repositories.
Fix
Route dependency traffic through internal repositories, verify AI-suggested packages before use, scope tokens the assistant can reach, monitor for worm-like package activity, and treat a compromised coding session as a supply-chain incident.

One malicious extension can hijack the built-in AI in several browsers

Researchers at Forever Security showed that a single malicious browser extension can hijack the AI assistant built into several AI-enabled browsers, including Chrome, Edge, Comet, Opera Neon, and Claude in Chrome. The core problem is that putting an AI agent inside the browser reopens a privilege-escalation path browsers normally work to close, letting a low-privilege extension reach a high-privilege part of the browser. Two of the findings received identifiers, one in Chrome, patched in January, and one in Edge, patched in July, while the others were fixed through bug bounties without dates. There is no evidence of real-world use yet, and each method still requires the user to install the extension.

Check
Update Chrome, Edge, and other AI-enabled browsers to their latest versions, review installed extensions and remove untrusted ones, and restrict extension installation through browser policy where possible.
Affected
Users of browsers with a built-in AI assistant who install a malicious extension; it can escalate from its low privileges to the high-privilege in-browser AI agent, controlling the assistant and its access.
Fix
Keep AI-enabled browsers updated, enforce extension allowlisting by policy, limit what the built-in AI agent can access, and treat the in-browser AI assistant as a privilege boundary extensions must not reach.

Mass scanning hunts exposed Vite dev servers for cloud credentials and secrets

Researchers at F5 documented a mass-scanning campaign that harvests cloud credentials from internet-exposed Vite development servers. It exploits CVE-2026-39364, an unauthenticated file-read flaw that bypasses Vite's protections for sensitive files: by appending query parameters like raw or import to a request, an attacker can retrieve files the server is supposed to block, such as environment files, certificates, and source code. The scanners cycle through wordlists of secret files, pulling API keys, database passwords, AWS and Azure credentials, and infrastructure-as-code state. It only affects setups that expose the dev server to the network, and it shows how quickly a newly disclosed bypass is folded into automated credential theft.

Check
Never expose a Vite or other development server to the internet, update Vite, and rotate any secrets, cloud keys, or state files an exposed dev server could have leaked.
Affected
Teams running internet-exposed Vite development servers on vulnerable versions (CVE-2026-39364); attackers can read blocked files to steal environment secrets, AWS and Azure credentials, and infrastructure-as-code state, without any authentication.
Fix
Keep dev servers bound to localhost and off the public internet, patch Vite, scan your external attack surface for exposed dev tooling, rotate leaked secrets, and treat exposed dev environments as targets.

DDRop hardware attack breaks Intel and AMD confidential computing protections

Researchers disclosed DDRop, a hardware attack that defeats the memory protection behind Intel and AMD confidential computing, the technology cloud providers use to keep customer data private even from themselves. These systems encrypt a server's memory but, to cover large amounts of it, skip a guarantee that memory holds its latest value, so old encrypted data still decrypts correctly. Using a memory interposer costing under 200 dollars, DDRop silently drops writes, and the processor reads the stale data as current while the encryption engine notices nothing. On Intel's technology this enables attestation forgery, and on AMD it allows copying one protected page into another. It needs physical access, threatening cloud environments.

Check
For confidential-computing workloads, enable available memory-integrity modes on Intel processors, weigh the physical-security assumptions of your cloud or hosting provider, and treat attestation as one control rather than a complete guarantee.
Affected
Cloud and hosting environments relying on Intel TDX or SGX or AMD SEV-SNP confidential computing; an attacker with physical access to memory can drop writes to defeat attestation or copy protected pages.
Fix
Enable cryptographic memory-integrity modes where the hardware supports them, factor physical-access risk into confidential-computing threat models, follow vendor guidance on stronger future designs, and avoid over-trusting attestation for the most sensitive workloads.

Stealthy BambooToken malware controls Windows and Linux over the IoT MQTT protocol

Researchers at Black Lotus Labs detailed BambooToken, a stealthy malware framework active since at least 2023 that controls infected Windows and Linux systems using MQTT, a lightweight messaging protocol designed for internet-of-things devices. Instead of connecting directly to attacker servers, infected machines subscribe to topics on a message broker, and operators publish commands to them, which helps evade detection and keeps working through network disruptions. The malware is installed by side-loading a malicious library through a legitimately signed USB-token tool or by impersonating office software. It compromised about a dozen enterprises, including a source-code server, and researchers note that command-and-control over an uncommon protocol like MQTT is an easy blind spot.

Check
Monitor servers and workstations for unexpected MQTT or message-broker traffic, watch for signed programs side-loading unexpected libraries, and add uncommon command-and-control protocols to your detection and network-monitoring coverage.
Affected
Windows and Linux enterprise systems tricked into side-loading the malware through signed software or office-suite impersonation; once infected, they take commands over MQTT, an IoT protocol many defenses do not inspect.
Fix
Restrict and monitor outbound traffic to unexpected message brokers and MQTT ports, enforce application control against DLL side-loading, verify signed software supply chains, and hunt for the campaign's indicators across hosts.