Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

ClickFix campaign hides its command server on the Polygon blockchain

Researchers at GuidePoint found a ClickFix campaign that compromised at least 31 organizations' websites and abuses the Polygon blockchain to run its command-and-control, a technique called EtherHiding. Visitors arriving from search engines hit a fake human-verification prompt that abuses Cloudflare's overlay and tells them to paste a command, which installs a persistent backdoor. Instead of a fixed server address that defenders can block, the backdoor fetches its current instructions from a Polygon smart contract every minute, giving the attacker a censorship-resistant, easily updated address book. This breaks the usual defense of blocking a hardcoded command server, so defenders should focus on behavior and audit their public-facing sites.

Check
Teach users that no verification prompt should ask them to paste commands, audit public-facing websites for injected scripts, and hunt for backdoors that resolve command servers through blockchain queries.
Affected
Organizations whose websites are compromised to serve the fake verification lure, and users tricked into running the pasted command; the resulting backdoor persists and pulls updatable instructions from the blockchain.
Fix
Detect on behavior rather than static addresses, block or flag outbound blockchain-resolution queries from endpoints, monitor for domain-generation patterns, continuously audit websites for injected code, and train users against paste-a-command verification tricks.

Researcher drops unpatched zero-days that turn Kaspersky and Avast against the system

A researcher known as Chaotic Eclipse, or Nightmare Eclipse, publicly released two unpatched privilege-escalation zero-day exploits targeting security software, without coordinating with the vendors. One, called HardBreacher, targets Kaspersky Endpoint Security and can disrupt the antivirus and its file-access controls while creating a system-level file. The other, PrettyPrague, escapes the Avast sandbox to dump the Windows account database and spawn a SYSTEM-level shell, and reportedly works on fully patched Avast and Windows 11. The researcher suspects it may also affect other Gen Digital products like AVG and Norton. Because there are no CVEs or patches yet, endpoints are exposed, and security tools' high privileges make them valuable targets.

Check
Track these public exploits closely since no patch exists, monitor endpoints for antivirus tampering, unexpected SYSTEM shells, and access to the Windows account database, and press affected vendors for fixes.
Affected
Windows systems running Kaspersky Endpoint Security or Avast and other Gen Digital antivirus products; the released exploits can escalate a local user to SYSTEM, dump credentials, and disable protection, with no patch.
Fix
Watch for these exploits moving from proof-of-concept to real attacks, restrict local access, monitor for credential-database dumping and security-tool interference, apply vendor patches as soon as they ship, and add compensating detection.

Malware carries a hidden prompt to derail AI-assisted analysis

ESET found that a Russia-aligned group planted a prompt inside a malicious script designed to trip an AI system's safety filters and disrupt AI-assisted malware analysis. The technique, dubbed GuardBreaker, embeds text about a sensitive topic so that a language model reviewing the code refuses or derails instead of analyzing it. The script itself installs a loader the group uses to deliver further payloads. It is not isolated: earlier in 2026, malicious packages in supply-chain campaigns used similar anti-analysis tricks against systems leaning on a language model for triage. The lesson is that automated AI triage can be manipulated by the code it inspects, so human review remains essential.

Check
If you use language models to triage code or malware, assume attackers will manipulate them, and keep human analysts and traditional sandboxing in the loop rather than trusting AI output alone.
Affected
Security workflows relying on language models for first-pass code or malware triage; attackers embed prompts in samples to trigger safety refusals or misdirection, causing the AI to skip or misjudge malicious code.
Fix
Treat AI triage output as manipulable, isolate the model from acting on embedded instructions, combine it with signature and behavioral analysis and human review, and test pipelines against prompt-injection samples.

Malicious Packagist themes attack unpatched iPhones to steal wallet seed phrases

Researchers found thirteen malicious packages on Packagist, the PHP Composer registry, posing as content-management themes that inject JavaScript into the sites that use them. On visitors' devices the script runs gambling and ad-fraud redirects, and on iPhones it loads a WebKit exploit chain that, against unpatched devices, installs spyware and steals cryptocurrency wallet seed phrases. The packages span several vendor names and extend a campaign first seen in March that abused similar theme packages and attacker-hosted infrastructure. It is a reminder that a compromised server-side dependency can become a delivery system for attacks against every visitor, including mobile users, not just the server it runs on.

Check
Audit PHP Composer and Packagist dependencies, especially themes, for untrusted or recently changed packages, remove suspicious ones, and make sure devices, including iPhones, are patched against known WebKit flaws.
Affected
Websites pulling the malicious Composer themes and their visitors; injected JavaScript redirects users and, on unpatched iPhones, chains WebKit exploits to install spyware and steal cryptocurrency wallet seed phrases from victims.
Fix
Vet and pin server-side dependencies, monitor sites for injected scripts and unexpected redirects, keep client devices patched, use content security policies to limit injected code, and treat theme packages as supply-chain risk.

Aurora ransomware crew used an AI coding agent for hands-on network intrusion

Researchers at CloudSEK and Gambit Security found that operators of the Russian-speaking Aurora ransomware used the agentic coding assistant Cursor to help break into around ten victim networks. After obtaining valid credentials or a route in, the operator directed the agent to run reconnaissance, assess privileges, scan internally, and attempt exploitation, often revising commands several times before they worked, which shows the human stayed in control and used the AI as an assistant rather than an autonomous attacker. The group also built a Linux encryptor that force-terminates VMware ESXi guest virtual machines to unlock their disk files before encrypting them. Initial access in one case came through help desk impersonation phone calls.

Check
Assume attackers now use agentic AI to accelerate hands-on intrusion, and focus detection on the resulting behavior: unusual internal scanning, privilege checks, log clearing, Defender being disabled, and mass ESXi activity.
Affected
Organizations facing hands-on ransomware intrusions, including VMware ESXi environments; operators use AI assistants to speed reconnaissance and exploitation after entry, and the ESXi encryptor kills guests to encrypt their disks.
Fix
Harden help desk verification against impersonation calls, protect ESXi management interfaces, restrict lateral movement, alert on Defender tampering and log clearing, and keep offline backups, since AI mainly speeds familiar steps.

Stolen AI API key from an exposed app burned through 600,000 dollars in credits

The AI evaluation nonprofit METR disclosed that attackers stole a model-provider API key and ran up about 600,000 dollars worth of inference credits over three weeks. The key sat on a researcher's personal cloud instance that was meant to be protected by a Google login but, due to a fail-open authentication bug in a quickly built app, was actually publicly reachable. After finding it, the attacker prompted the AI agent running there to reveal its provider API key, added an SSH key for persistence, and consumed credits on public models. The abuse went unnoticed for a while because METR routinely runs high-token evaluations and had no spending caps on the key.

Check
Keep provider API keys off personal and non-organizational infrastructure, add spend caps and usage alerts to every key, and make sure agents cannot be prompted into revealing the credentials they hold.
Affected
Organizations with AI provider API keys on loosely protected or personal infrastructure; a stolen key with no spending cap can rack up costly inference, and exposed agents may leak keys when prompted.
Fix
Store keys in a secrets manager, scope and cap them, monitor for anomalous token spend, avoid embedding retrievable keys in agent environments, and verify quickly built apps fail closed, not open.

ValleyRAT backdoor hides in signed adware users add to antivirus exclusions

Kaspersky reported that the group known as Silver Fox is spreading the ValleyRAT backdoor, also called Winos 4.0, hidden inside a genuine but signed Chinese adware application called QN Wallpaper. By side-loading a malicious library through the trusted, signed program, the malware runs inside a process users are likely to have added to their antivirus exclusion lists, and it disables Windows Defender. Once active, it gives the operator full control, capturing keystrokes, clipboard contents, and screenshots and loading further modules. Kaspersky recorded more than 100,000 detections of ValleyRAT this year, mostly in China and India, and warns that adware and affiliate networks can be far more dangerous than they look.

Check
Warn users not to install questionable or adware-bundled software and never to add it to antivirus exclusion lists, and hunt for signed processes side-loading unexpected libraries or disabling Defender.
Affected
Windows users who install low-reputation adware and exclude it from antivirus scanning; the signed host process side-loads ValleyRAT, which disables Defender and gives attackers full remote control of the machine.
Fix
Block low-reputation and adware software through application control, avoid broad antivirus exclusions, monitor for DLL sideloading from signed processes and Defender being disabled, and treat trusted-but-questionable software as a real threat vector.

TerminalFix tricks users with fake CAPTCHAs into pasting a backdoor command

A social-engineering campaign dubbed TerminalFix uses fake Cloudflare CAPTCHA pages, often served from compromised websites, to trick visitors into copying and running a malicious PowerShell command in their terminal. It is a refined take on the ClickFix technique, tuned to make complex scripts run more reliably, and it deploys a reverse-tunnel backdoor through a multi-stage chain involving DLL sideloading, hiding payloads inside images, and an outbound WebSocket connection for command and control. The campaign has hit organizations across several sectors. The core deception is simple to teach against: a legitimate CAPTCHA never asks you to paste and run commands in a terminal or Run dialog.

Check
Warn users that no real CAPTCHA ever asks them to paste commands into a terminal, and treat any such prompt as an attack, closing the page and reporting it.
Affected
Users lured to compromised or malicious sites showing fake CAPTCHA verification; following the prompt to run a PowerShell command installs a reverse-tunnel backdoor that gives attackers remote access to the device.
Fix
Enforce application control and PowerShell script-block logging, monitor for anomalous outbound WebSocket traffic and DLL sideloading, restrict who can run scripts, and train users to recognize fake CAPTCHA and ClickFix lures.

Trusted browser extensions turned into crypto stealers through ownership handoffs

Researchers at Socket detailed a long-running campaign, active since early 2024, in which Chrome and Edge extensions delivered an extensible malware framework of sixteen modules to steal cryptocurrency, credentials, session tokens, and browsing data, and to inject ClickFix lures. Notably, several extensions started out legitimate and were only weaponized later, after their original developers handed over control and new owners pushed malicious automatic updates. One extension reached seventy thousand users before removal. The malware ran from the extension's background worker, opened an encrypted connection to its servers, and displayed fake wallet-recovery pages on real crypto sites to capture recovery phrases.

Check
Audit installed Chrome and Edge extensions, remove unneeded ones, and recognize that a once-safe extension can turn malicious through an update after its ownership changes, silently and without a new prompt.
Affected
Users of the affected Chrome and Edge extensions, especially crypto holders; the framework steals wallet recovery phrases, credentials, session cookies, and browsing data, and can prompt users into running attacker commands.
Fix
Restrict extension installs through browser policy, review extension permissions, keep crypto wallets off browsers used for general work, monitor for the campaign's indicators, and move funds if a compromised extension was installed.

Cluster of 19 Chrome and Edge extensions steal wallets and drain crypto

Researchers at Socket found a coordinated cluster of nineteen browser extensions, eighteen for Chrome and one for Edge, published over the past six months with code to steal cryptocurrency wallet secrets, drain funds, harvest credentials, and inject code into targeted websites. The extensions share code and tradecraft, suggesting a single campaign that may have run even longer. Because a browser extension can read and alter the pages a user visits, a malicious one that reaches a crypto user can quietly capture recovery phrases or redirect transactions. This continues a steady pattern of wallet-draining extensions slipping into official browser stores under the guise of useful tools.

Check
Review the browser extensions installed across your users, remove unknown or wallet-related ones from this cluster, and remind crypto users that a single malicious extension can drain their funds.
Affected
Users who installed any of the nineteen malicious Chrome or Edge extensions, especially cryptocurrency holders; the extensions steal wallet secrets, drain funds, harvest credentials, and can tamper with the websites users visit.
Fix
Restrict extension installation through browser policy, allowlist trusted publishers, audit installed extensions periodically, keep crypto wallets off browsers used for general browsing, and treat any exposed wallet as compromised.