Cosmos Labs warned that attackers are actively exploiting a flaw in its Cosmos EVM module, the component that gives Cosmos blockchains Ethereum compatibility, and urged affected chains to halt their validators. The bug lies in how the module handles state during nested transactions, letting an attacker manipulate balance and ownership tracking to move funds without authorization. Because many independent chains share the same module code, the weakness is systemic: separate chains were hit in the days before the ecosystem-wide warning, suggesting attackers generalized one exploit across the shared codebase. A patch existed from earlier in the year, but new exploitation shows the risk persists. It echoes supply-chain risk applied to blockchain infrastructure.
Researchers at VulnCheck found two undocumented factory implants in the firmware of routers made by the Chinese manufacturer ZBT, each giving a remote, unauthenticated attacker the ability to run commands as root. Named SPEAKINGSTONE and DARKLANTERN and tracked as CVE-2026-74232 and CVE-2026-74233, both scored around 9.3, require no privileges or interaction. SPEAKINGSTONE runs as a hidden service and beacons out over a fixed UDP port to a hardcoded command-and-control server; because it dials outward, it works from behind network address translation and normal egress filtering. The findings underscore the supply-chain risk of low-cost networking hardware with opaque firmware.
Researchers showed that Amazon Kiro, an AI-powered agentic development environment, can be turned against its user through prompt injection. Attacker-controlled content in a repository the developer opens can steer the Kiro agent into transmitting sensitive local information to an external server, abusing a feature called Kiro Powers that bundles model context protocol server configurations, steering files, and hooks. The developer only has to open the workspace and interact with the agent. It is part of a wider run of similar flaws in AI coding tools, where untrusted content or links quietly redirect an agent into exfiltrating data or executing code without any approval prompt. Updating the tool addresses the reported issue.
Academic researchers disclosed GPUThor, a Rowhammer attack that defeats the error-correcting memory that NVIDIA recommends as the defense against GPU Rowhammer. Demonstrated on Ampere-class workstation GPUs with GDDR6 memory, including the RTX A4000 through A6000 models common in AI and cloud infrastructure, it lets unprivileged code running on the GPU flip memory bits far more reliably than earlier attacks, finding an exploitable flip in about a minute. That enables denial of service, silent data corruption, and escalation to a root shell on the host. The researchers note error correction is not sufficient protection, which matters most where untrusted workloads share GPUs, as in multi-tenant cloud and AI platforms.
Researchers at OX Security found a campaign using two dozen npm packages as free phishing infrastructure rather than as malware aimed at developers. Each package is just a single HTML page, harmless to install, but once served through npm content-delivery mirrors like unpkg it becomes a live, fully rendered fake Cloudflare CAPTCHA page hosted on a trusted domain. The page then redirects victims to ClickFix-style phishing infrastructure, and while it currently forwards to a legitimate site, it can be reconfigured to deliver any phishing payload. The trick is not infecting people who install the packages, but abusing the registry and its mirrors as validated, reputable storage for attacker content.
A commercial phishing-as-a-service toolkit called Mirage2FA has hit around 4,500 organizations by abusing legitimate Microsoft 365 login flows to steal passwords and session cookies and bypass two-factor authentication. Because it captures the session cookie after a real login completes, the attacker inherits an authenticated Microsoft 365 session and any single-sign-on connected services, defeating multi-factor authentication. Researchers at ANY.RUN linked the campaign to more than 9,000 potential compromise events and found that nearly half of targeted addresses may have been affected, with most victims in the United States across technology, manufacturing, and education. Hijacking one session can expand into connected apps and internal workflows.
Cisco Talos detailed a financially motivated, Chinese-speaking group it tracks as UAT-10147 that breaks into internet-facing Windows and Linux web servers at scale and installs malware for data theft and search-engine-optimization fraud. The group weaves AI tools through its operations, from exploiting known vulnerabilities to generating payloads, and Talos even found AI-generated code comments left in the source of its Linux kernel rootkit. Its cross-platform implant, SPECTRE, offers credential theft, process injection, encrypted command-and-control, and driver-based bypassing of endpoint detection. Investigators also recovered prompt logs from AI coding assistants on the attackers' own machines, a concrete look at adversaries using the same agent tools defenders do.
Researchers at Expel found a new malware toolkit, SynkLoader, spread through Microsoft Teams messages in which attackers pose as a company's IT help desk. Using their own Microsoft tenant and an onmicrosoft.com address for credibility, they talk an employee into installing a fake "PowerShell Cleaner" hosted on Microsoft's own Azure storage. Once installed, SynkLoader can load modules including a convincing full-screen fake Windows lock screen that captures the user's password, plus a reverse proxy, remote shell, and remote desktop control. Its focus on counting Active Directory systems suggests it is used by a ransomware group or access broker to size targets. The fake lock screen can be escaped with Alt+Tab or Ctrl+Alt+Delete.
Check Point researchers showed at Black Hat that Microsoft Defender's own legitimately signed boot-time cleanup driver, BTR.sys, can be abused to delete security software during startup. The driver, bundled inside Defender to finish removing malware after a reboot, can perform arbitrary kernel-level file and registry operations, and a released proof-of-concept wiped the entire Defender stack from a fully updated Windows 11 machine with tamper protection on. Unlike bring-your-own-vulnerable-driver attacks, this uses a driver present in every Windows since Windows 7, so it cannot be blocklisted. It requires administrator rights with a specific privilege, so Microsoft considers it a trust-boundary issue rather than a bug and will not patch it.
Kaspersky documented what it calls the first malware found on a car head unit with an infection chain built specifically for that kind of device. The malware spreads through the built-in software updaters of certain Android-based automotive head unit firmware, then pulls a multi-stage downloader that runs ad fraud and enrolls the unit into a reverse-proxy botnet. Researchers attribute it with high confidence to a group tied to the BADBOX ad-fraud and residential-proxy operation. A head unit is the central console that handles media and, on many vehicles, some vehicle functions, so malware delivered through its own update mechanism is a notable expansion of automotive supply-chain risk.