Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

Cosmos EVM flaw exploited across blockchains sharing the same vulnerable code

Cosmos Labs warned that attackers are actively exploiting a flaw in its Cosmos EVM module, the component that gives Cosmos blockchains Ethereum compatibility, and urged affected chains to halt their validators. The bug lies in how the module handles state during nested transactions, letting an attacker manipulate balance and ownership tracking to move funds without authorization. Because many independent chains share the same module code, the weakness is systemic: separate chains were hit in the days before the ecosystem-wide warning, suggesting attackers generalized one exploit across the shared codebase. A patch existed from earlier in the year, but new exploitation shows the risk persists. It echoes supply-chain risk applied to blockchain infrastructure.

Check
Operators of chains built on the Cosmos EVM module should follow Cosmos Labs' guidance, apply the latest patched module, and pause validators if advised until confirmed safe.
Affected
Blockchains built on the vulnerable Cosmos EVM module; incorrect state handling during nested execution lets attackers manipulate balances and ownership to steal funds, and shared code exposes many chains at once.
Fix
Update to the patched Cosmos EVM module, monitor for abnormal precompile calls and unauthorized transfers, coordinate with the ecosystem on halts, and recognize shared blockchain modules concentrate risk across every chain.

China-made ZBT routers ship with factory backdoors granting unauthenticated root

Researchers at VulnCheck found two undocumented factory implants in the firmware of routers made by the Chinese manufacturer ZBT, each giving a remote, unauthenticated attacker the ability to run commands as root. Named SPEAKINGSTONE and DARKLANTERN and tracked as CVE-2026-74232 and CVE-2026-74233, both scored around 9.3, require no privileges or interaction. SPEAKINGSTONE runs as a hidden service and beacons out over a fixed UDP port to a hardcoded command-and-control server; because it dials outward, it works from behind network address translation and normal egress filtering. The findings underscore the supply-chain risk of low-cost networking hardware with opaque firmware.

Check
Identify any ZBT or Zbtlink routers in your environment, isolate or replace affected models, and block outbound traffic to the implant's command-and-control server and its fixed UDP port.
Affected
Anyone operating affected ZBT-manufactured routers, including rebranded models; the built-in implants let a remote unauthenticated attacker gain root, and one beacons out to a hardcoded server, working even from behind NAT.
Fix
Replace untrustworthy OEM networking gear, segment and monitor such devices, block known implant command-and-control destinations, inspect egress for beaconing on the implicated port, and prefer vendors with transparent, verifiable firmware.

Malicious repository content can make Amazon's Kiro AI IDE leak local data

Researchers showed that Amazon Kiro, an AI-powered agentic development environment, can be turned against its user through prompt injection. Attacker-controlled content in a repository the developer opens can steer the Kiro agent into transmitting sensitive local information to an external server, abusing a feature called Kiro Powers that bundles model context protocol server configurations, steering files, and hooks. The developer only has to open the workspace and interact with the agent. It is part of a wider run of similar flaws in AI coding tools, where untrusted content or links quietly redirect an agent into exfiltrating data or executing code without any approval prompt. Updating the tool addresses the reported issue.

Check
Update Kiro to the latest version, and treat opening untrusted repositories in any agentic AI development environment as risky, since hidden instructions can drive the agent without an approval prompt.
Affected
Developers using Amazon Kiro or similar agentic AI IDEs who open untrusted repositories; malicious content can prompt-inject the agent to exfiltrate local data or alter its own tool and context configuration files.
Fix
Keep agentic IDEs updated, review model context protocol configs and steering files for tampering, limit what secrets and paths the agent can reach, and avoid opening untrusted projects in autonomous tools.

GPUThor Rowhammer defeats ECC on NVIDIA GPUs to reach host root

Academic researchers disclosed GPUThor, a Rowhammer attack that defeats the error-correcting memory that NVIDIA recommends as the defense against GPU Rowhammer. Demonstrated on Ampere-class workstation GPUs with GDDR6 memory, including the RTX A4000 through A6000 models common in AI and cloud infrastructure, it lets unprivileged code running on the GPU flip memory bits far more reliably than earlier attacks, finding an exploitable flip in about a minute. That enables denial of service, silent data corruption, and escalation to a root shell on the host. The researchers note error correction is not sufficient protection, which matters most where untrusted workloads share GPUs, as in multi-tenant cloud and AI platforms.

Check
Where GPUs run untrusted or multi-tenant workloads, avoid sharing a physical GPU across tenants, limit who can run arbitrary GPU code, and monitor for unusual error-correction events on affected NVIDIA cards.
Affected
Systems running untrusted GPU workloads on affected NVIDIA Ampere workstation cards with GDDR6 memory; unprivileged GPU code can flip memory bits despite error correction, causing denial of service or host root access.
Fix
Isolate GPU workloads and avoid cross-tenant sharing of physical GPUs, restrict arbitrary code execution on shared GPUs, monitor error-correction telemetry for hammering, and follow vendor guidance as hardware-level mitigations develop.

Attackers abuse npm and its mirrors to host fake CAPTCHA phishing pages

Researchers at OX Security found a campaign using two dozen npm packages as free phishing infrastructure rather than as malware aimed at developers. Each package is just a single HTML page, harmless to install, but once served through npm content-delivery mirrors like unpkg it becomes a live, fully rendered fake Cloudflare CAPTCHA page hosted on a trusted domain. The page then redirects victims to ClickFix-style phishing infrastructure, and while it currently forwards to a legitimate site, it can be reconfigured to deliver any phishing payload. The trick is not infecting people who install the packages, but abusing the registry and its mirrors as validated, reputable storage for attacker content.

Check
Treat fake CAPTCHA and ClickFix pages as hostile even when served from trusted domains like unpkg, and educate users not to run commands or steps a CAPTCHA prompt tells them to perform.
Affected
Anyone lured to a fake CAPTCHA page hosted on a trusted npm mirror; the pages redirect to ClickFix phishing, exploiting the reputation of legitimate infrastructure to bypass suspicion and some blocking.
Fix
Monitor and filter for HTML content served from package-mirror domains, block known phishing and ClickFix infrastructure, apply reputation-aware web filtering rather than trusting domains outright, and train users on fake CAPTCHA lures.

Mirage2FA phishing service hijacks Microsoft 365 sessions and bypasses two-factor

A commercial phishing-as-a-service toolkit called Mirage2FA has hit around 4,500 organizations by abusing legitimate Microsoft 365 login flows to steal passwords and session cookies and bypass two-factor authentication. Because it captures the session cookie after a real login completes, the attacker inherits an authenticated Microsoft 365 session and any single-sign-on connected services, defeating multi-factor authentication. Researchers at ANY.RUN linked the campaign to more than 9,000 potential compromise events and found that nearly half of targeted addresses may have been affected, with most victims in the United States across technology, manufacturing, and education. Hijacking one session can expand into connected apps and internal workflows.

Check
Move toward phishing-resistant authentication such as passkeys or hardware security keys, since attacker-in-the-middle kits like this defeat ordinary two-factor by stealing the session after login.
Affected
Microsoft 365 organizations relying on passwords plus standard two-factor authentication; Mirage2FA steals the post-login session cookie to hijack authenticated sessions and single-sign-on services, extending access well beyond the first account.
Fix
Adopt phishing-resistant multi-factor authentication, shorten session lifetimes and bind sessions to devices, monitor for anomalous token use and impossible-travel sign-ins, and revoke sessions on suspicion rather than trusting a successful login.

Crime group uses AI to mass-hack servers and deploy a Linux rootkit backdoor

Cisco Talos detailed a financially motivated, Chinese-speaking group it tracks as UAT-10147 that breaks into internet-facing Windows and Linux web servers at scale and installs malware for data theft and search-engine-optimization fraud. The group weaves AI tools through its operations, from exploiting known vulnerabilities to generating payloads, and Talos even found AI-generated code comments left in the source of its Linux kernel rootkit. Its cross-platform implant, SPECTRE, offers credential theft, process injection, encrypted command-and-control, and driver-based bypassing of endpoint detection. Investigators also recovered prompt logs from AI coding assistants on the attackers' own machines, a concrete look at adversaries using the same agent tools defenders do.

Check
Patch internet-facing web servers promptly since the group exploits known flaws at scale, enforce protections that block unsigned driver loads, and deploy endpoint detection with kernel-level visibility on Windows and Linux.
Affected
Organizations running internet-facing IIS or Linux web servers with unpatched known vulnerabilities; the group gains access at scale, deploys a rootkit and cross-platform backdoor, disables endpoint detection, and steals credentials and data.
Fix
Prioritize patching exposed servers, enable hypervisor-protected code integrity to counter driver-based evasion, monitor east-west traffic from web servers to internal Linux hosts, and hunt for kernel rootkits and unexpected HTTPS beacons.

Teams help desk impersonation delivers SynkLoader and a fake lock screen

Researchers at Expel found a new malware toolkit, SynkLoader, spread through Microsoft Teams messages in which attackers pose as a company's IT help desk. Using their own Microsoft tenant and an onmicrosoft.com address for credibility, they talk an employee into installing a fake "PowerShell Cleaner" hosted on Microsoft's own Azure storage. Once installed, SynkLoader can load modules including a convincing full-screen fake Windows lock screen that captures the user's password, plus a reverse proxy, remote shell, and remote desktop control. Its focus on counting Active Directory systems suggests it is used by a ransomware group or access broker to size targets. The fake lock screen can be escaped with Alt+Tab or Ctrl+Alt+Delete.

Check
Tell staff to verify unsolicited IT-support messages in Teams through a known internal channel before installing anything, and hunt for unapproved MSI installs, new scheduled tasks, and in-memory PowerShell.
Affected
Organizations allowing external Teams messages, where an attacker impersonating IT support can deliver SynkLoader; it steals passwords via a fake lock screen and provides proxy, shell, and remote-desktop access toward likely ransomware.
Fix
Restrict or closely monitor external Teams communication, block untrusted MSI downloads and known command-and-control infrastructure, watch for suspicious scheduled tasks and Python or PowerShell activity, and train staff on help-desk impersonation lures.

Microsoft Defender's own boot driver can be turned against security tools

Check Point researchers showed at Black Hat that Microsoft Defender's own legitimately signed boot-time cleanup driver, BTR.sys, can be abused to delete security software during startup. The driver, bundled inside Defender to finish removing malware after a reboot, can perform arbitrary kernel-level file and registry operations, and a released proof-of-concept wiped the entire Defender stack from a fully updated Windows 11 machine with tamper protection on. Unlike bring-your-own-vulnerable-driver attacks, this uses a driver present in every Windows since Windows 7, so it cannot be blocklisted. It requires administrator rights with a specific privilege, so Microsoft considers it a trust-boundary issue rather than a bug and will not patch it.

Check
Restrict the SeLoadDriverPrivilege to only accounts that truly need it, since the technique depends on it, and build detection for unexpected loading of the BTR.sys boot driver.
Affected
Windows systems from Windows 7 through 11 where an attacker gains administrator rights with SeLoadDriverPrivilege; they can use Defender's own signed boot driver to delete endpoint security tools before those tools load.
Fix
Limit local administrator rights and the driver-load privilege, monitor for boot-time driver abuse and security services vanishing, and prioritize detection engineering while the technique is public but not yet seen in attacks.

First car head unit malware spreads through built-in Android updaters

Kaspersky documented what it calls the first malware found on a car head unit with an infection chain built specifically for that kind of device. The malware spreads through the built-in software updaters of certain Android-based automotive head unit firmware, then pulls a multi-stage downloader that runs ad fraud and enrolls the unit into a reverse-proxy botnet. Researchers attribute it with high confidence to a group tied to the BADBOX ad-fraud and residential-proxy operation. A head unit is the central console that handles media and, on many vehicles, some vehicle functions, so malware delivered through its own update mechanism is a notable expansion of automotive supply-chain risk.

Check
For fleets and connected-vehicle programs, ask head unit and firmware suppliers about the integrity of their built-in updaters, and monitor automotive and IoT devices for proxy or ad-fraud traffic.
Affected
Vehicles using affected Android automotive head unit firmware whose built-in updater delivered the malware; infected units run ad fraud and act as reverse-proxy nodes, and the head unit has partial vehicle-function access.
Fix
Treat the firmware update channel as a supply-chain trust boundary, source head units from vendors with signed verified updates, monitor connected vehicles for anomalous outbound traffic, and track this actor's proxy infrastructure.