Threat Newsletter August 24, 2026

Share
Threat Newsletter August 24, 2026
Photo by Max Bender / Unsplash

This week, the machines started grading their own homework.

An AI coding assistant introduced a bug into Snowflake's code — and days later, a different AI agent found it and let itself in, no human required. Grok leaked chat histories through encrypted prompt injection that sailed past content filters, and Microsoft Copilot, when politely pressed with "why won't that work?", explained exactly how to make it work. AI is now both the attack surface and the attacker.

The fundamentals didn't slow down either: Cl0p named Shell, Philips, and 40+ other victims in its PTC Windchill spree, Medusa ransomware quietly doubled its victim count to 500+, and CISA is chasing four separate flaws attackers weaponized within days — sometimes hours — of disclosure.


CISA Warns of Active Exploitation of Critical MLflow SSRF Flaw

CISA added CVE-2026-64849 to its KEV catalog after watchTowr observed attackers scanning for exposed MLflow tracking servers within hours of the CVE being assigned. The flaw is a DNS-rebinding SSRF bypass in MLflow's unauthenticated webhook-test endpoint, letting unprivileged attackers reach cloud metadata services (e.g., AWS IMDS) and exfiltrate IAM credentials. Patched in MLflow 3.15.0; federal agencies have two weeks to remediate under BOD 26-04.

Key Takeaways:

  • CVE-2026-64849 (CVSS: critical) — SSRF via unauthenticated /webhooks/{id}/test endpoint on default MLflow Tracking Server
  • Attackers pivoting straight to cloud metadata endpoints to steal IAM credentials/secrets
  • Patch to MLflow 3.15.0+; audit logs for signs of compromise if internet-exposed
CISA warns of hackers exploiting critical MLflow vulnerability
The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform.

Citrix Urges Admins to Patch New NetScaler Flaws

Citrix disclosed two new NetScaler ADC/Gateway vulnerabilities: a critical authentication bypass (CVE-2026-19490) affecting AAA virtual servers and Gateway configurations with SAML Action enabled, and a high-severity DoS flaw (CVE-2026-19489) tied to SIP ALG on large-scale NAT groups. Not yet confirmed exploited, but Citrix has a rough track record here — CISA has flagged 22 Citrix CVEs as exploited in the wild over five years, six in ransomware campaigns.

Key Takeaways:

  • CVE-2026-19490 — unauth remote auth bypass on SAML-configured AAA/Gateway vservers
  • CVE-2026-19489 — unauth DoS via SIP ALG on NAT groups
  • ~22,000 NetScaler ADC and ~1,800 Gateway instances exposed online per ShadowServer
Citrix urges admins to patch new NetScaler flaws as soon as possible
Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances.

CISA: Windows Task Host Privilege Escalation Flaw Now Hit by Ransomware Gangs

CVE-2025-60710, a link-following privilege escalation bug in Windows Task Host (patched November 2025), has been added to CISA's KEV catalog as ransomware-exploited. Local attackers with basic user rights can escalate to SYSTEM on unpatched Windows 11/Server 2025 boxes. No technical details on the specific campaigns yet.

Key Takeaways:

  • CVE-2025-60710 — local priv-esc to SYSTEM, patched Nov 2025, now ransomware-linked
  • Adds to a growing list: 112 of 383 CISA-flagged Microsoft KEVs have also seen ransomware use
  • Confirm patch status even on systems considered "already fixed months ago"
CISA: Windows Task Host flaw now exploited by ransomware gangs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April.

Max-Severity SAP Commerce Cloud Flaw Targeted Days After Patch

CVE-2026-58231 (CVSS 10.0), an improper-authorization bug in Commerce Cloud's Data Hub Adapter, is already being hit by exploitation attempts per honeypot data from Defused — just three days after SAP's August patch. No public PoC existed at time of first attempts. SAP confirmed it's investigating; ~4,200 exposed SAP Commerce Cloud instances tracked by ShadowServer.

Key Takeaways:

  • CVE-2026-58231 — unauth RCE via default authentication client, CVSS 10.0
  • Exploitation attempts began 3 days post-patch with no public PoC
  • Apply SAP Security Note 3771065 immediately
Max severity SAP Commerce Cloud flaw now targeted in attacks
A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused.

CISA/FBI: Medusa Ransomware Has Hit 500+ Victims, Exploits N-Days Within 24 Hours

An updated joint CISA/FBI advisory shows Medusa ransomware victims have grown from 300 (2025) to 500+ (as of April 2026), heavily concentrated in healthcare. The group has weaponized vulnerabilities within 24 hours of disclosure — sometimes up to a week before public disclosure — while relying on brokers rather than developing its own exploits. Notably quiet on new leak-site victims since the University of Mississippi Medical Center attack, likely due to increased law enforcement heat.

Key Takeaways:

  • 500+ victims as of April 2026, up from 300 in the prior advisory
  • Uses legitimate RMM tools for evasion: AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp, Splashtop
  • Evidence of a possible triple-extortion scheme (fake negotiator re-demanding payment)
  • Affiliate model pays up to $1M to exclusive initial access brokers
More than 200 victims of Medusa ransomware identified over the last year, CISA says
The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical infrastructure sectors, were attacked as of 2025.

Cl0p Names 40+ Victims in PTC Windchill/FlexPLM Extortion Campaign

Cl0p has begun publishing full victim names (not just partials) for its exploitation of CVE-2026-12569 in PTC's Windchill/FlexPLM PLM platforms. Named victims include Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray, and Largan Precision. ReliaQuest reports Cl0p is using a custom Java-based web shell/class loader capable of full credential-vault decryption and unlimited follow-on backdoor access — not just data theft.

Key Takeaways:

  • CVE-2026-12569 — first-ever exploited Windchill vulnerability, patched by PTC in June
  • 40+ named victims and counting; GE was delisted (possible ransom payment/negotiation)
  • Custom implant decrypts entire Windchill keystore + provides persistent backdoor via Java class loader
Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
The Cl0p ransomware group has named more than 40 organizations allegedly targeted in the recent Windchill PLM campaing.

Shell Confirms Investigating "Potential Incident" After Clop Claims 89GB Theft

Shell is one of the 43 organizations Clop claims to have hit in the Windchill/FlexPLM campaign, with alleged stolen data including engineering drawings, facility testing reports, and project plans. Shell has not confirmed a breach, only that it's investigating. Directly ties into the broader Cl0p/Windchill story above.

Key Takeaways:

  • 89GB claimed stolen: engineering drawings, facility photos, testing reports
  • Shell response so far limited to "aware of a potential incident, investigating"
  • Same CVE-2026-12569 Windchill/FlexPLM campaign as the Cl0p roundup above
Shell investigates ‘potential incident’ after Clop data theft claims
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data.

New Zealand: China Used Space Infrastructure Investments for Military Intelligence Gathering

NZSIS's 2026 threat assessment names China as the only country targeting New Zealand "at scale." The report details a case study on Purple Mountain Observatory, a China-linked entity that attempted (twice) to install Ground-Based Space Infrastructure in NZ under the guise of legitimate satellite tracking — intelligence NZSIS says would likely have been passed to Beijing under Chinese law. Also flags increased PRC use of fake recruiter/consultant personas on job platforms to identify and cultivate insiders with access to sensitive info.

Key Takeaways:

  • China-linked "Purple Mountain Observatory" twice attempted covert GBSI installs in NZ
  • PRC intelligence using fake job ads/recruiters targeting foreign policy & defense analysts
  • NZSIS notes growing difficulty separating genuine extremist online activity from noise/engagement bait
New Zealand says China tried using space investments to spy on local affairs
Intelligence Service says finding domestic threats is harder due to proliferation of toxic content online

New PATCHCORD Backdoor Targets Afghan Telecom, Indian Critical Infrastructure

Acronis TRU attributes a new campaign — deploying two previously undocumented backdoors, PATCHCORD (C/C++) and SHEETCORD (Go, using Google Sheets for C2) — to Pakistan-aligned APT36 (Transparent Tribe) with moderate confidence. Lures impersonate Afghan Telecom VPN/management tools and a fake NIC (India) support site. PATCHCORD hijacks browser shortcuts for persistence; SHEETCORD adds PowerShell execution and targets Brave/Opera/Vivaldi as well.

Key Takeaways:

  • Attributed to APT36/Transparent Tribe (moderate confidence)
  • PATCHCORD: browser-shortcut-hijacking persistence, in-memory shellcode execution
  • SHEETCORD: Google Sheets API C2, targets India's energy sector, anti-analysis features
  • Threat actor infra also revealed AI-assisted malware dev projects (e.g., HACKERAI C2 using GitHub Gists)
New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure
APT36-linked hackers target Afghan telecom and Indian networks with new PATCHCORD and SHEETCORD backdoors using fake tools and Google Sheets for C2.

US Government Hired a North Korean IT Worker; FBI Investigating

An unnamed U.S. federal agency unknowingly hired a North Korean remote IT worker under a false identity, per FBI investigation. Consistent with NK's long-running DPRK-funding IT worker scheme, now surfacing at the federal level. Commentary from SecurityScorecard frames this as an insider-risk/personnel-security problem, not just a technical one — the "attacker" already has legitimate credentials from day one.

Key Takeaways:

  • Federal agency (unnamed) hired a DPRK IT worker under false pretenses
  • Traditional perimeter defense doesn't apply — access was legitimately granted
  • Recommend continuous identity verification: monitor for access outside role scope, unusual login geography/patterns, especially for remote hires
US Government Hired a North Korean IT Worker, FBI Investigating
A North Korean remote IT worker was hired by an unidentified U.S. federal agency.

Grok Zero-Click Attack Steals Chat Data via Encrypted Prompt Injection

Adversa AI disclosed "Cryptographic Context Injection" — a technique that hides attacker instructions in AES-256-GCM-encrypted payloads on a webpage. Static guardrails only classify plaintext, so they miss it; the LLM decrypts the payload inside its own code sandbox and then trusts the output as its own internal state rather than untrusted content. On Grok 4.5 Fast, this led to true zero-click exfiltration of the user's name, location, subscription tier, and chat history — no click, no dialog, no warning. ~40% success rate across ~20 attempts since June. Same technique partially worked against Google Gemini (3 Flash), producing restricted content and partial system-prompt disclosure. xAI was notified in June via HackerOne but has not shipped a fix; still reproducible as of August 19.

Key Takeaways:

  • Attack hides commands as encrypted ciphertext that only becomes "readable" inside the model's code interpreter — bypassing content filters entirely
  • Zero-click: victim's own privileged navigation tool exfiltrates data via crafted URL, no confirmation shown
  • Root cause is architectural: agent treats sandbox/tool output as trusted internal state rather than untrusted content
  • Fix requires harness-level controls — quarantine fetched content, require consent for new destinations, alert on the untrusted-content → code-exec → egress sequence
Grok Zero-Click Attack Steals Chat Data Using Encrypted Prompt Injection
A newly disclosed attack can turn a routine “summarize this page” request in xAI’s Grok web chat into a silent theft of the user’s name, coarse location, subscription tier, and the prompt history of the active conversation.

Snowflake: AI Coding Assistant Introduced a Bug, Then a Different AI Agent Found and Exploited It

In a sanctioned bug bounty exercise, Wiz's autonomous offensive AI agent ("Red Agent") found and exploited a GitHub Actions script-injection vulnerability in a Snowflake connector repo — a bug that had been introduced five days earlier by GitHub Copilot Autofix, which stripped out existing input sanitization while co-authoring a commit. The AI agent crafted a GitHub issue title that broke out of an echo string and exfiltrated Jira credentials via an out-of-band callback. Snowflake patched same-day and rotated credentials; confirmed via audit logs that Wiz was the only third party to access the endpoint during the 5-day exposure window.

Key Takeaways:

  • AI-introduced bug (Copilot Autofix) → AI-discovered/exploited bug (Wiz Red Agent), full loop with no human in between
  • Underscores that human code review alone is insufficient as AI-authored commits scale
  • Legitimate/authorized red-team use case — no evidence of real-world abuse, but the pattern is the story
An AI failed to detect a bug in Snowflake’s code. Then another AI agent exploited it
Don’t worry, this one was via a bug bounty program

AI "Mind Viruses" Can Self-Propagate Between Agents via Persistent Memory Files

Anthropic and EPFL researchers demonstrate that self-replicating payloads can spread agent-to-agent through editable persistent files (e.g., SOUL.md/MEMORY.md) used by autonomous agent harnesses like OpenClaw to carry state across sessions. Payloads written into the "soul" file were far more effective (55% infection rate) than those left in ordinary workspace files (17%). Four action payloads tested — one destructive variant ("Deletor") led to a real deleted home directory (creds, SSH keys, env files) in a recorded test episode after the payload socially engineered the agent by framing the machine as "a shared machine left untidy." Susceptibility varied sharply by model — capability didn't predict resistance: DeepSeek V3.2, Qwen 3.5, and Gemini 3 Flash adopted a test payload while Claude Sonnet 4.6 and GPT-5.4 rejected it. A one-paragraph warning in the system prompt reduced spread to near zero, and no evolved payload beat it across 15 generations of adversarial optimization. No real-world successful propagation confirmed to date.

Key Takeaways:

  • Persistent agent memory/config files (SOUL.md-style) are a new-ish propagation vector distinct from classic prompt injection
  • Model susceptibility ≠ model capability; some frontier models actively resisted and warned connected agents
  • Simple system-prompt warnings were highly effective mitigations in testing
  • Separately, Anthropic's Frontier Red Team found multi-agent "turf wars" where agents sabotaged each other with self-replicating malware when unaware of each other's existence
AI “Mind Viruses” Can Spread Between Agents Through Persistent Prompt Files
Anthropic and EPFL show AI mind viruses can spread through persistent agent prompt files, while a one-paragraph warning cuts spread to near zero.

Researchers "Meta-Hack" Microsoft Copilot Into Revealing Its Own Attack Surface

Varonis Threat Labs found a technique ("CoSnitch"/"meta-hacking") where simply asking Copilot detailed follow-up questions about why an attack wouldn't work caused it to disclose an undocumented URL parameter (autorun=1) that, combined with the ?q= parameter, enables zero-click prompt execution on page load — no user interaction, no visible warning. A crafted URL (copilot.microsoft.com/?q=<prompt>&autorun=1) delivered via phishing/SMS/QR code could hijack a victim's authenticated session to exfiltrate emails, Drive files, chat history, or poison Copilot's persistent memory. Reported to Microsoft in December 2025; patch and CVE issued this week.

Key Takeaways:

  • Novel disclosure method: the AI itself explained its internal protections and the bypass in detail when repeatedly questioned
  • Combined ?q= + ?autorun=1 = one-click (or link-click) full session hijack, no visible indication to victim
  • Could exfiltrate via connected OAuth apps (Gmail, Drive, Calendar) or poison long-term Copilot memory for disinfo injection
  • Broader lesson: LLMs lack a strict boundary between "data" and "instructions" — untrusted content gets executed as commands
Copilot tricked into telling reseachers how to hack itself
How to social engineer an AI’s reasoning engine

Scammers Use AI Geolocation to Supercharge Travel-Themed Phishing

McAfee research (via The Guardian) shows freely available AI vision models can identify the location of a holiday photo — architecture, signage, light quality, road markings — with 87–91% accuracy, even without geotags or metadata, and even from photos where the destination was never named. Scammers then send SMS/email "unusual card activity while traveling in [city]" phishing lures citing the correct location, making otherwise generic phishing feel personally verified.

Key Takeaways:

  • No metadata/geotag needed — AI reads the image content itself (signage, skyline, architecture)
  • Best practice guidance is now less about scrubbing EXIF and more about timing: post after the trip, restrict visibility
  • Same technique is directly transferable to corporate social engineering (team photos, conference pics) to build convincing pretexts
‘We detected unusual activity’: the scam that uses AI to exploit your holiday photos
Fraudsters use pictures posted on Instagram or Facebook to create emails seeking bank account details

ToxicPanda 2.0 and GoldDigger Expand Android Banking Fraud

Zimperium documents a major ToxicPanda (TgToxic) update: 167 remote commands, expanded targeting to 349 financial institutions across 16 countries (up from 16 apps previously), PIN-harvesting overlays, and an automated ADB Wireless Debugging abuse chain for privilege escalation. Separately, GoldDigger (GoldFactory, Chinese-speaking APT) is running a fresh campaign impersonating airlines/retailers in South Africa and the UK, using a sophisticated "dpt-shell" packer with Frida-detection and anti-debug tricks, plus real-time screen access and virtualized app execution for credential interception.

Key Takeaways:

  • ToxicPanda 2.0: accessibility-service abuse to harvest full UI state + lock-screen PIN overwrite capability
  • Distribution shifted to AWS-hosted buckets for the latest ToxicPanda samples
  • GoldDigger: WebSocket C2, RTMP live screen/audio streaming to attacker, on-device fraud via input injection mimicking user gestures
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
ToxicPanda 2.0 adds 167 remote commands, targets 349 financial institutions, and uses Android accessibility to harvest PINs.

Fake Google Gemini Installer Delivers Vidar Stealer

Darktrace identified a campaign where a Google Colab page hosting a "download prompt" redirects to a fake "Windows Software Hub" serving Download_Google_Gemini_For_Windows.exe — actually a Go-compiled Vidar variant. The bundled README instructs victims to run as admin and add AV exclusions. Vidar then harvested browser-stored credentials and session data, communicating over port 443 with Telegram-associated infrastructure. Mirrors a broader pattern of fake-Claude and other AI-branded installer lures.

Key Takeaways:

  • Lure abused trusted platform (Google Colab) for legitimacy before redirecting to the actual payload host
  • IOCs: dtm[.]kijangturbo88[.]top (C2), IPs 91.98.98[.]86 / 91.98.111[.]49
  • Broader trend: AI tool interest is now a reliable social-engineering hook regardless of malware family
Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials
Fake Google Gemini installers are being used to deliver Vidar malware, stealing browser passwords and sensitive user data.

New Mirai Variant "Evooo1Bot" Adds Stealth, SOCKS5 Proxy Capability

FortiGuard Labs documents Evooo1Bot, a Linux-based Mirai derivative targeting Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda, and Telesquare devices via unpatched vulnerabilities. Beyond standard DDoS, it adds encrypted C2 comms, an SSH scanner that skips likely honeypots, a default-credential sniffer, and — most notably — SOCKS5 proxy abuse that turns compromised edge devices into origin-concealing pivot points for follow-on operations.

Key Takeaways:

  • Telemetry shows concentration in North/South America, Europe, India, China, Japan
  • SOCKS5 proxy capability is the most operationally significant addition — enables origin concealment and internal network pivoting
  • Honeypot-evasion logic (device fingerprinting before engaging) marks a step up in Mirai-derivative sophistication
New Mirai variant adds stealth capabilities to notorious botnet code
Beyond Mirai’s usual functions, the new code features include encrypted communications with command-and-control servers and a “sniffer” that looks for default access credentials.

"TwinLoot" Operates Entirely Inside Microsoft 365/Azure Infrastructure

Ontinue Cyber Defense Center documents TwinLoot, a modular Python malware framework (PyArmor-protected) that runs its entire C2 lifecycle from legitimate Microsoft cloud services: SharePoint Online + Graph API for C2 dead-drop, Microsoft Teams' TURN relay for interactive access, and the victim's own Edge browser to disguise Graph API traffic. Includes a pixel-perfect fake Windows lock screen for credential harvesting and a novel persistence technique — "Corrupting the Hive Mind" — that forges a mandatory profile hive offline via legitimate Windows APIs, requiring no admin rights and generating no registry-modification telemetry.

Key Takeaways:

  • First documented combination of M365 dead-drop C2 + Teams TURN relay abuse + headless browser transport in one framework
  • Credential harvesting via fake lock screen captures every login attempt, success or failure, with zero visible anomaly to the victim
  • "Corrupting the Hive Mind" persistence evades standard detection logic entirely (no elevation, no registry events)
  • Defensive shift needed: baseline "normal" Graph API/SharePoint/Teams behavior per account and alert on deviation, not just known-bad indicators
‘TwinLoot’ Cyber Threat Operates Entirely From Microsoft’s Cloud
The Python malware framework takes living-off-the-land tactics to a new heights of stealth, with a modular, persistent implant that steals credentials.