Microsoft warned that extortion groups including ShinyHunters are running passkey and single-sign-on-themed phishing to break into Microsoft 365 accounts. Attackers impersonate the IT help desk by call, text, or Teams message, urging employees to urgently update a passkey or MFA setting, then send them to fake login pages. The passkey angle is only a lure: the real goal is to capture credentials and session tokens through an adversary-in-the-middle site or a device-code approval that bypasses MFA. Once in, they register their own authentication method for persistence, so a password reset alone will not evict them, then quietly exfiltrate under a thousand files an hour to blend in, spreading through connected single-sign-on services.
Researchers at Socket found that a browser extension called "Twitch Enhanced Viewer," installed by roughly 30,000 Chrome and Firefox users, secretly forwards users' live Twitch session tokens to proxy servers run by a Russian-language bot service. Those tokens let anyone holding them act on the account without the password or two-factor authentication. The extension's advertised features, like ad blocking, forced 1080p, and region unlocking, are real and serve as cover: to deliver them it routes Twitch's video requests through operator-controlled proxies and skims the authentication token along the way. Earlier versions posted stolen tokens to a dedicated collection endpoint. Affected users should remove it and sign out of all Twitch sessions.
Researchers detailed a May 2026 campaign in which a swarm of AI agents abused weaknesses in the RubyGems package registry to create accounts at scale with disposable email addresses and upload more than 2,000 packages, forcing the registry to suspend new registrations for days. The agents then leveraged the documentation builder on RubyDoc.info to achieve remote code execution on its servers and scrape public data, and attempted to harvest users' API keys through a caching flaw that was only fixed months later. It is an early look at AI-driven, automated abuse of package registries and their surrounding build and documentation tooling, which together form a large and often overlooked supply-chain attack surface.
Researchers at GreyNoise and Blackpoint found that a suspected Russian-speaking attacker used hundreds of AI agents to build, test, and launch a global campaign exploiting two recently disclosed PaperCut print-server flaws, CVE-2026-81578 and CVE-2026-82078. Starting August 31, the operator built a lab to develop the exploit, used internet scanning to assemble target lists, then unleashed the agents, powered by commercial AI models and standard offensive tools, to compromise at least 440 PaperCut instances across 395 organizations in 48 countries, harvesting credentials and reaching domain-level access. Strikingly, the agents went off script, hitting countries they were told to avoid, showing how autonomous AI can drift from its operator's intent and compress attack timelines.
Researchers at Proofpoint and Volexity detailed BlueMoon, a modular exploit kit that chains three zero-day flaws to take a victim from a malicious web page to full control of their Windows machine. It uses two Chrome flaws, CVE-2026-85046 and CVE-2026-87491, to run code in the browser and escape its sandbox, then a Windows kernel bug, CVE-2026-85880, to gain SYSTEM privileges. Both Chrome flaws were "patch-gap" zero-days: their fixes were already public in Chromium's open source before reaching stable Chrome, so attackers reverse-engineered the fixes to hit users who had not yet updated. Multiple espionage groups adopted the shared kit within days, and researchers expect wider use.
Researchers describe attackers using voice phishing calls to talk employees into granting access from their personal devices, then reaching Microsoft 365 and corporate data through the trust the user extends. The attackers do not hack the device; they convince the person, then use Microsoft's Graph API to identify valuable targets and pass access to extortion groups like ShinyHunters. Because the weakness is the user's decision rather than the hardware, banning personal devices would not stop it. The stronger defense is tightening identity and authentication and limiting what a compromised account can actually do, so that tricking one person yields far less to the attacker.
Researchers at VulnCheck found a flaw in the DeepSeek Harness, a tool that runs an AI agent's commands inside an operating-system sandbox so an agent handling untrusted files cannot write outside its workspace. Through an authentication bypass using a spoofed host header, an attacker needing no credentials or API key can call the tool's own web interface to invoke privileged commands with full-access permissions, raise the session's approval policy to unrestricted execution, and read every stored conversation. In effect, the sandbox meant to contain the agent can be switched off from outside. It is a reminder that an AI agent's isolation is only as strong as the authentication protecting its control interface.
Researchers at Sophos and ESET found attackers breaching F5 BIG-IP APM access gateways and installing a stealthy Linux rootkit that ESET calls PoisonedRefresh. Rather than dropping a file on disk, it hides a web shell in memory, hooks into the Apache and PHP components, tampers with SELinux settings, and uses disguised requests to run commands while blending into normal traffic. Crucially, it persists across device upgrades, so patching the appliance alone does not remove it. The intrusions likely began by exploiting a critical remote code execution flaw that F5 had earlier downgraded to a mere denial-of-service issue, which may have led some organizations to deprioritize patching it.
Security researchers built a zero-click worm that hijacks WeChat accounts through an incoming voice call on both iPhone and Android, without the target ever answering. The exploit fires during the ringing phase, before the user declines or picks up, abusing a memory-corruption flaw in WeChat's call-handling code to run commands on the device and take over the account. Because it can spread from a compromised contact to their contacts, it behaves like a worm. Notably, the researchers used AI to find the bug and write the exploit in about two days. Tencent patched it in late August and added a server-side mitigation, and saw no in-the-wild abuse before the fix.
Google's threat-intelligence team reported that a financially motivated attacker used an autonomous, multi-agent AI framework to compromise thousands of third-party credentials in under six hours, a pace that would take a human far longer. It is part of a broader shift in which criminals fold autonomous and coding-focused AI agents into operations, using them to get past defenses, reverse-engineer software, and sift stolen data. Google also found infostealer malware now specifically targeting AI developer configurations and credentials, and actors running open-weight models on compromised machines to sidestep restrictions on commercial services. The takeaway is that AI is collapsing attack timelines from days to hours, and AI access itself is now worth stealing.