Researchers at GuidePoint found a ClickFix campaign that compromised at least 31 organizations' websites and abuses the Polygon blockchain to run its command-and-control, a technique called EtherHiding. Visitors arriving from search engines hit a fake human-verification prompt that abuses Cloudflare's overlay and tells them to paste a command, which installs a persistent backdoor. Instead of a fixed server address that defenders can block, the backdoor fetches its current instructions from a Polygon smart contract every minute, giving the attacker a censorship-resistant, easily updated address book. This breaks the usual defense of blocking a hardcoded command server, so defenders should focus on behavior and audit their public-facing sites.
A researcher known as Chaotic Eclipse, or Nightmare Eclipse, publicly released two unpatched privilege-escalation zero-day exploits targeting security software, without coordinating with the vendors. One, called HardBreacher, targets Kaspersky Endpoint Security and can disrupt the antivirus and its file-access controls while creating a system-level file. The other, PrettyPrague, escapes the Avast sandbox to dump the Windows account database and spawn a SYSTEM-level shell, and reportedly works on fully patched Avast and Windows 11. The researcher suspects it may also affect other Gen Digital products like AVG and Norton. Because there are no CVEs or patches yet, endpoints are exposed, and security tools' high privileges make them valuable targets.
ESET found that a Russia-aligned group planted a prompt inside a malicious script designed to trip an AI system's safety filters and disrupt AI-assisted malware analysis. The technique, dubbed GuardBreaker, embeds text about a sensitive topic so that a language model reviewing the code refuses or derails instead of analyzing it. The script itself installs a loader the group uses to deliver further payloads. It is not isolated: earlier in 2026, malicious packages in supply-chain campaigns used similar anti-analysis tricks against systems leaning on a language model for triage. The lesson is that automated AI triage can be manipulated by the code it inspects, so human review remains essential.
Researchers found thirteen malicious packages on Packagist, the PHP Composer registry, posing as content-management themes that inject JavaScript into the sites that use them. On visitors' devices the script runs gambling and ad-fraud redirects, and on iPhones it loads a WebKit exploit chain that, against unpatched devices, installs spyware and steals cryptocurrency wallet seed phrases. The packages span several vendor names and extend a campaign first seen in March that abused similar theme packages and attacker-hosted infrastructure. It is a reminder that a compromised server-side dependency can become a delivery system for attacks against every visitor, including mobile users, not just the server it runs on.
Researchers at CloudSEK and Gambit Security found that operators of the Russian-speaking Aurora ransomware used the agentic coding assistant Cursor to help break into around ten victim networks. After obtaining valid credentials or a route in, the operator directed the agent to run reconnaissance, assess privileges, scan internally, and attempt exploitation, often revising commands several times before they worked, which shows the human stayed in control and used the AI as an assistant rather than an autonomous attacker. The group also built a Linux encryptor that force-terminates VMware ESXi guest virtual machines to unlock their disk files before encrypting them. Initial access in one case came through help desk impersonation phone calls.
The AI evaluation nonprofit METR disclosed that attackers stole a model-provider API key and ran up about 600,000 dollars worth of inference credits over three weeks. The key sat on a researcher's personal cloud instance that was meant to be protected by a Google login but, due to a fail-open authentication bug in a quickly built app, was actually publicly reachable. After finding it, the attacker prompted the AI agent running there to reveal its provider API key, added an SSH key for persistence, and consumed credits on public models. The abuse went unnoticed for a while because METR routinely runs high-token evaluations and had no spending caps on the key.
Kaspersky reported that the group known as Silver Fox is spreading the ValleyRAT backdoor, also called Winos 4.0, hidden inside a genuine but signed Chinese adware application called QN Wallpaper. By side-loading a malicious library through the trusted, signed program, the malware runs inside a process users are likely to have added to their antivirus exclusion lists, and it disables Windows Defender. Once active, it gives the operator full control, capturing keystrokes, clipboard contents, and screenshots and loading further modules. Kaspersky recorded more than 100,000 detections of ValleyRAT this year, mostly in China and India, and warns that adware and affiliate networks can be far more dangerous than they look.
A social-engineering campaign dubbed TerminalFix uses fake Cloudflare CAPTCHA pages, often served from compromised websites, to trick visitors into copying and running a malicious PowerShell command in their terminal. It is a refined take on the ClickFix technique, tuned to make complex scripts run more reliably, and it deploys a reverse-tunnel backdoor through a multi-stage chain involving DLL sideloading, hiding payloads inside images, and an outbound WebSocket connection for command and control. The campaign has hit organizations across several sectors. The core deception is simple to teach against: a legitimate CAPTCHA never asks you to paste and run commands in a terminal or Run dialog.
Researchers at Socket detailed a long-running campaign, active since early 2024, in which Chrome and Edge extensions delivered an extensible malware framework of sixteen modules to steal cryptocurrency, credentials, session tokens, and browsing data, and to inject ClickFix lures. Notably, several extensions started out legitimate and were only weaponized later, after their original developers handed over control and new owners pushed malicious automatic updates. One extension reached seventy thousand users before removal. The malware ran from the extension's background worker, opened an encrypted connection to its servers, and displayed fake wallet-recovery pages on real crypto sites to capture recovery phrases.
Researchers at Socket found a coordinated cluster of nineteen browser extensions, eighteen for Chrome and one for Edge, published over the past six months with code to steal cryptocurrency wallet secrets, drain funds, harvest credentials, and inject code into targeted websites. The extensions share code and tradecraft, suggesting a single campaign that may have run even longer. Because a browser extension can read and alter the pages a user visits, a malicious one that reaches a crypto user can quietly capture recovery phrases or redirect transactions. This continues a steady pattern of wallet-draining extensions slipping into official browser stores under the guise of useful tools.