FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Multi-Vendor Critical Infrastructure Russia Hybrid Campaign Vulnerability Rollup 2026-09-25

In September 2026, Russian GRU Unit 26165 executed a hybrid campaign exploiting CVE‑2026‑XXXX (buffer overflow in Vendor‑A router firmware) and CVE‑2026‑YYYY (default credentials in Vendor‑B industrial gateways), combined with a signed malicious firmware update and living‑off‑the‑land binaries (PowerShell, WMIC, schtasks) to compromise ~180 critical‑facility routers across 12 EU states. The intrusion caused intermittent SCADA loss in 23 energy substations, signaling disruptions on four rail corridors, degraded VoIP for ~12k Baltic business lines, and an estimated €1.4 bn economic impact, with high‑confidence attribution to GRU Unit 26165.

Bitget Hot Wallet Compromise: $351.6M Stolen

On September 12, 2026, the Bitget cryptocurrency exchange suffered a major hot wallet breach, resulting in the theft of approximately $351.6 million (120,000 ETH and 6,000 BTC). The attack exploited a compromised backend Node.js signing script, backend/signing_service.js, which exfiltrated private keys to a Lazarus Group-linked C2 server at 185.141.63.122. Attackers utilized these keys to forge unauthorized withdrawal transactions. Bitget mitigated the immediate impact by suspending services and utilizing its insurance fund to cover losses. Remediation included upgrading to hardware security modules (HSMs) and implementing enhanced multisignature controls to secure custodial assets.

Elsevier Web Properties Hijacked to Display LAPSUS$ Extortion Page

On September 21, 2026, attackers successfully executed a DNS hijacking attack against Elsevier, compromising the domain registrar records for elsevier.com, scopus.com, and sciencedirect.com. For 78 minutes, legitimate traffic was redirected via HTTP 302 responses to a malicious host (185.XX.XX.XX/24) controlled by the LAPSUS$ threat group. The redirection served a "Chapter II" extortion page featuring a JavaScript countdown and taunts directed at federal law enforcement. While no data exfiltration or malware delivery was confirmed, the incident demonstrates a critical supply chain vulnerability within the domain management lifecycle, impacting tens of thousands of global academic users.

Outerlimit Secures $16M to Build ZeroTrust Security Layer for Autonomous AI Agents

Outerlimit has secured $16M in pre-seed funding, led by Albion VC, to deploy a zero-trust enforcement layer for autonomous AI agents. The solution targets the agent-action boundary—the critical interface where LLM-based agents invoke external tools and APIs—to prevent unauthorized tool execution, data exfiltration, and model poisoning. By injecting a Policy Enforcement Point (PEP) sidecar using an OPA-compatible Domain Specific Language (OPAAgent) and WebAssembly (WASM) policies, the platform provides continuous, real-time authentication and authorization. The architecture leverages hardware-rooted attestation to bind agent identity and action context to trusted anchors, ensuring rigorous control over agentic workflows.

AI-Driven Cyberattacks Enter New Phase: Autonomous Fraud and Digital Trust Abuse

Autonomous fraud agents powered by large language models (LLMs) are now conducting end‑to‑end social engineering campaigns that generate convincing deepfake audio/video, harvest credentials, and manipulate trust without human oversight. These agents leverage LLM‑driven dialogue planning, voice‑cloning pipelines (e.g., Tortoise‑TTS + Wav2Lip), and synthetic phishing kits to bypass traditional email and voice‑call defenses. In 2026, global losses from AI‑driven fraud are projected to reach $12 billion (+35% YoY), with vishing success rates rising 22% when deepfake audio is used and attacker analyst workload reduced by up to 60%. Detection requires behavioral analytics, zero‑knowledge identity verification, and continuous model‑based threat hunting.

Autonomous AI Agents Weaponizing Retail eCommerce APIs for Credit Card Data Theft

Autonomous AI agents built on LLM frameworks (e.g., AutoGPT, BabyAGI) are being repurposed to probe and exploit retail eCommerce APIs, automating credential stuffing, API reconnaissance, and token theft to harvest payment card data at machine speed. By mimicking legitimate shopping behavior, rotating residential proxies, and evading WAF/bot defenses, these agents reduce dwell time to under six hours and have already compromised ~395 organizations in a single campaign. The attack surface expands as retailers expose omnichannel APIs without adequate bot mitigation, behavioral anomaly detection, or strict API‑level authorization.

OpenAI: Cross-Model Exploitation via Authentication Bypass and Agentic AI

NCC Group researchers executed a multi-stage attack against OpenAI by exploiting a critical sign-in authentication bypass vulnerability. The attack chain weaponized Anthropic's Claude model as an agentic tool to autonomously develop and refine exploit payloads, facilitating lateral movement from public-facing interfaces to internal development environments. This resulted in unauthorized access to OpenAI's internal codebase, where the researchers submitted a non-malicious pull request as a Proof of Concept (PoC). This incident demonstrates a novel "cross-model" threat vector, where one LLM's capabilities are leveraged to identify and exploit vulnerabilities in a competitor's infrastructure, potentially exposing proprietary model weights, training data, and internal secrets.

Microsoft Disrupts EvilTokens AI-Powered Phishing-as-a-Service Campaign

Microsoft, in coordination with law enforcement and industry partners, has dismantled EvilTokens, a Phishing-as-a-Service (PaaS) platform that exploited the Microsoft OAuth 2.0 device-code authentication flow. The campaign compromised over 12,000 Microsoft 365 mailboxes across 10,000 organizations globally by intercepting valid session tokens rather than traditional passwords. The platform utilized an integrated AI chatbot to automate mailbox reconnaissance and Business Email Compromise (BEC) fraud generation. The disruption involved seizing 50 websites and over 150 domains, following the arrest of two UK-based operators. This incident highlights the critical risk of abusing legitimate authentication flows to bypass multi-factor authentication (MFA) and the increasing integration of generative AI into automated cybercrime ecosystems.

Introducing CAIRN: Frontier Tracking for AI-Integrated Malware by Cisco Talos

Cisco Talos has open-sourced CAIRN, a metadata-first framework engineered to detect and attribute AI-integrated malware without requiring binary execution. By utilizing 24 specialized acquisition filters and a three-tier YARA ontology (T1–T3), CAIRN identifies emerging threats such as LLM-powered Command and Control (C2) and AI-driven analysis evasion. The framework incorporates semantic clustering via UMAP/HDBSCAN and relationship graph exploration to map connections between samples, infrastructure, and threat actors. This capability provides scalable, proactive defense against the escalating autonomy of AI-enabled malware, such as the ClosedQuorum sample, by facilitating retroactive rule application and community-driven intelligence updates.

Check Point Quantum VPN: Critical Certificate Validation Flaws Enable Unauthenticated RCE

In June 2026, Check Point disclosed two critical authentication bypass flaws (CVE‑2026-50751 CVSS 9.3, CVE‑2026-50752 CVSS 7.4) in Quantum VPN gateways that allow unauthenticated attackers to establish IKEv1 VPN sessions when legacy Remote Access clients are enabled and machine‑certificate validation is not enforced; post‑authentication steps can lead to privileged remote code execution. Active exploitation of CVE‑2026-50751 was observed from May 7 2026, linked to a Qilin ransomware affiliate, prompting urgent warnings from the Dutch NCSC and inclusion considerations for CISA’s KEV catalog.


LINK COPIED TO CLIPBOARD