Threat Newsletter August 24, 2026
This week, the machines started grading their own homework.
An AI coding assistant introduced a bug into Snowflake's code — and days later, a different AI agent found it and let itself in, no human required. Grok leaked chat histories through encrypted prompt injection that sailed past content filters, and Microsoft Copilot, when politely pressed with "why won't that work?", explained exactly how to make it work. AI is now both the attack surface and the attacker.
The fundamentals didn't slow down either: Cl0p named Shell, Philips, and 40+ other victims in its PTC Windchill spree, Medusa ransomware quietly doubled its victim count to 500+, and CISA is chasing four separate flaws attackers weaponized within days — sometimes hours — of disclosure.
CISA Warns of Active Exploitation of Critical MLflow SSRF Flaw
CISA added CVE-2026-64849 to its KEV catalog after watchTowr observed attackers scanning for exposed MLflow tracking servers within hours of the CVE being assigned. The flaw is a DNS-rebinding SSRF bypass in MLflow's unauthenticated webhook-test endpoint, letting unprivileged attackers reach cloud metadata services (e.g., AWS IMDS) and exfiltrate IAM credentials. Patched in MLflow 3.15.0; federal agencies have two weeks to remediate under BOD 26-04.
Key Takeaways:
- CVE-2026-64849 (CVSS: critical) — SSRF via unauthenticated
/webhooks/{id}/testendpoint on default MLflow Tracking Server - Attackers pivoting straight to cloud metadata endpoints to steal IAM credentials/secrets
- Patch to MLflow 3.15.0+; audit logs for signs of compromise if internet-exposed

Citrix Urges Admins to Patch New NetScaler Flaws
Citrix disclosed two new NetScaler ADC/Gateway vulnerabilities: a critical authentication bypass (CVE-2026-19490) affecting AAA virtual servers and Gateway configurations with SAML Action enabled, and a high-severity DoS flaw (CVE-2026-19489) tied to SIP ALG on large-scale NAT groups. Not yet confirmed exploited, but Citrix has a rough track record here — CISA has flagged 22 Citrix CVEs as exploited in the wild over five years, six in ransomware campaigns.
Key Takeaways:
- CVE-2026-19490 — unauth remote auth bypass on SAML-configured AAA/Gateway vservers
- CVE-2026-19489 — unauth DoS via SIP ALG on NAT groups
- ~22,000 NetScaler ADC and ~1,800 Gateway instances exposed online per ShadowServer

CISA: Windows Task Host Privilege Escalation Flaw Now Hit by Ransomware Gangs
CVE-2025-60710, a link-following privilege escalation bug in Windows Task Host (patched November 2025), has been added to CISA's KEV catalog as ransomware-exploited. Local attackers with basic user rights can escalate to SYSTEM on unpatched Windows 11/Server 2025 boxes. No technical details on the specific campaigns yet.
Key Takeaways:
- CVE-2025-60710 — local priv-esc to SYSTEM, patched Nov 2025, now ransomware-linked
- Adds to a growing list: 112 of 383 CISA-flagged Microsoft KEVs have also seen ransomware use
- Confirm patch status even on systems considered "already fixed months ago"

Max-Severity SAP Commerce Cloud Flaw Targeted Days After Patch
CVE-2026-58231 (CVSS 10.0), an improper-authorization bug in Commerce Cloud's Data Hub Adapter, is already being hit by exploitation attempts per honeypot data from Defused — just three days after SAP's August patch. No public PoC existed at time of first attempts. SAP confirmed it's investigating; ~4,200 exposed SAP Commerce Cloud instances tracked by ShadowServer.
Key Takeaways:
- CVE-2026-58231 — unauth RCE via default authentication client, CVSS 10.0
- Exploitation attempts began 3 days post-patch with no public PoC
- Apply SAP Security Note 3771065 immediately

CISA/FBI: Medusa Ransomware Has Hit 500+ Victims, Exploits N-Days Within 24 Hours
An updated joint CISA/FBI advisory shows Medusa ransomware victims have grown from 300 (2025) to 500+ (as of April 2026), heavily concentrated in healthcare. The group has weaponized vulnerabilities within 24 hours of disclosure — sometimes up to a week before public disclosure — while relying on brokers rather than developing its own exploits. Notably quiet on new leak-site victims since the University of Mississippi Medical Center attack, likely due to increased law enforcement heat.
Key Takeaways:
- 500+ victims as of April 2026, up from 300 in the prior advisory
- Uses legitimate RMM tools for evasion: AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp, Splashtop
- Evidence of a possible triple-extortion scheme (fake negotiator re-demanding payment)
- Affiliate model pays up to $1M to exclusive initial access brokers

Cl0p Names 40+ Victims in PTC Windchill/FlexPLM Extortion Campaign
Cl0p has begun publishing full victim names (not just partials) for its exploitation of CVE-2026-12569 in PTC's Windchill/FlexPLM PLM platforms. Named victims include Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray, and Largan Precision. ReliaQuest reports Cl0p is using a custom Java-based web shell/class loader capable of full credential-vault decryption and unlimited follow-on backdoor access — not just data theft.
Key Takeaways:
- CVE-2026-12569 — first-ever exploited Windchill vulnerability, patched by PTC in June
- 40+ named victims and counting; GE was delisted (possible ransom payment/negotiation)
- Custom implant decrypts entire Windchill keystore + provides persistent backdoor via Java class loader

Shell Confirms Investigating "Potential Incident" After Clop Claims 89GB Theft
Shell is one of the 43 organizations Clop claims to have hit in the Windchill/FlexPLM campaign, with alleged stolen data including engineering drawings, facility testing reports, and project plans. Shell has not confirmed a breach, only that it's investigating. Directly ties into the broader Cl0p/Windchill story above.
Key Takeaways:
- 89GB claimed stolen: engineering drawings, facility photos, testing reports
- Shell response so far limited to "aware of a potential incident, investigating"
- Same CVE-2026-12569 Windchill/FlexPLM campaign as the Cl0p roundup above

New Zealand: China Used Space Infrastructure Investments for Military Intelligence Gathering
NZSIS's 2026 threat assessment names China as the only country targeting New Zealand "at scale." The report details a case study on Purple Mountain Observatory, a China-linked entity that attempted (twice) to install Ground-Based Space Infrastructure in NZ under the guise of legitimate satellite tracking — intelligence NZSIS says would likely have been passed to Beijing under Chinese law. Also flags increased PRC use of fake recruiter/consultant personas on job platforms to identify and cultivate insiders with access to sensitive info.
Key Takeaways:
- China-linked "Purple Mountain Observatory" twice attempted covert GBSI installs in NZ
- PRC intelligence using fake job ads/recruiters targeting foreign policy & defense analysts
- NZSIS notes growing difficulty separating genuine extremist online activity from noise/engagement bait

New PATCHCORD Backdoor Targets Afghan Telecom, Indian Critical Infrastructure
Acronis TRU attributes a new campaign — deploying two previously undocumented backdoors, PATCHCORD (C/C++) and SHEETCORD (Go, using Google Sheets for C2) — to Pakistan-aligned APT36 (Transparent Tribe) with moderate confidence. Lures impersonate Afghan Telecom VPN/management tools and a fake NIC (India) support site. PATCHCORD hijacks browser shortcuts for persistence; SHEETCORD adds PowerShell execution and targets Brave/Opera/Vivaldi as well.
Key Takeaways:
- Attributed to APT36/Transparent Tribe (moderate confidence)
- PATCHCORD: browser-shortcut-hijacking persistence, in-memory shellcode execution
- SHEETCORD: Google Sheets API C2, targets India's energy sector, anti-analysis features
- Threat actor infra also revealed AI-assisted malware dev projects (e.g., HACKERAI C2 using GitHub Gists)

US Government Hired a North Korean IT Worker; FBI Investigating
An unnamed U.S. federal agency unknowingly hired a North Korean remote IT worker under a false identity, per FBI investigation. Consistent with NK's long-running DPRK-funding IT worker scheme, now surfacing at the federal level. Commentary from SecurityScorecard frames this as an insider-risk/personnel-security problem, not just a technical one — the "attacker" already has legitimate credentials from day one.
Key Takeaways:
- Federal agency (unnamed) hired a DPRK IT worker under false pretenses
- Traditional perimeter defense doesn't apply — access was legitimately granted
- Recommend continuous identity verification: monitor for access outside role scope, unusual login geography/patterns, especially for remote hires

Grok Zero-Click Attack Steals Chat Data via Encrypted Prompt Injection
Adversa AI disclosed "Cryptographic Context Injection" — a technique that hides attacker instructions in AES-256-GCM-encrypted payloads on a webpage. Static guardrails only classify plaintext, so they miss it; the LLM decrypts the payload inside its own code sandbox and then trusts the output as its own internal state rather than untrusted content. On Grok 4.5 Fast, this led to true zero-click exfiltration of the user's name, location, subscription tier, and chat history — no click, no dialog, no warning. ~40% success rate across ~20 attempts since June. Same technique partially worked against Google Gemini (3 Flash), producing restricted content and partial system-prompt disclosure. xAI was notified in June via HackerOne but has not shipped a fix; still reproducible as of August 19.
Key Takeaways:
- Attack hides commands as encrypted ciphertext that only becomes "readable" inside the model's code interpreter — bypassing content filters entirely
- Zero-click: victim's own privileged navigation tool exfiltrates data via crafted URL, no confirmation shown
- Root cause is architectural: agent treats sandbox/tool output as trusted internal state rather than untrusted content
- Fix requires harness-level controls — quarantine fetched content, require consent for new destinations, alert on the untrusted-content → code-exec → egress sequence

Snowflake: AI Coding Assistant Introduced a Bug, Then a Different AI Agent Found and Exploited It
In a sanctioned bug bounty exercise, Wiz's autonomous offensive AI agent ("Red Agent") found and exploited a GitHub Actions script-injection vulnerability in a Snowflake connector repo — a bug that had been introduced five days earlier by GitHub Copilot Autofix, which stripped out existing input sanitization while co-authoring a commit. The AI agent crafted a GitHub issue title that broke out of an echo string and exfiltrated Jira credentials via an out-of-band callback. Snowflake patched same-day and rotated credentials; confirmed via audit logs that Wiz was the only third party to access the endpoint during the 5-day exposure window.
Key Takeaways:
- AI-introduced bug (Copilot Autofix) → AI-discovered/exploited bug (Wiz Red Agent), full loop with no human in between
- Underscores that human code review alone is insufficient as AI-authored commits scale
- Legitimate/authorized red-team use case — no evidence of real-world abuse, but the pattern is the story

AI "Mind Viruses" Can Self-Propagate Between Agents via Persistent Memory Files
Anthropic and EPFL researchers demonstrate that self-replicating payloads can spread agent-to-agent through editable persistent files (e.g., SOUL.md/MEMORY.md) used by autonomous agent harnesses like OpenClaw to carry state across sessions. Payloads written into the "soul" file were far more effective (55% infection rate) than those left in ordinary workspace files (17%). Four action payloads tested — one destructive variant ("Deletor") led to a real deleted home directory (creds, SSH keys, env files) in a recorded test episode after the payload socially engineered the agent by framing the machine as "a shared machine left untidy." Susceptibility varied sharply by model — capability didn't predict resistance: DeepSeek V3.2, Qwen 3.5, and Gemini 3 Flash adopted a test payload while Claude Sonnet 4.6 and GPT-5.4 rejected it. A one-paragraph warning in the system prompt reduced spread to near zero, and no evolved payload beat it across 15 generations of adversarial optimization. No real-world successful propagation confirmed to date.
Key Takeaways:
- Persistent agent memory/config files (SOUL.md-style) are a new-ish propagation vector distinct from classic prompt injection
- Model susceptibility ≠ model capability; some frontier models actively resisted and warned connected agents
- Simple system-prompt warnings were highly effective mitigations in testing
- Separately, Anthropic's Frontier Red Team found multi-agent "turf wars" where agents sabotaged each other with self-replicating malware when unaware of each other's existence

Researchers "Meta-Hack" Microsoft Copilot Into Revealing Its Own Attack Surface
Varonis Threat Labs found a technique ("CoSnitch"/"meta-hacking") where simply asking Copilot detailed follow-up questions about why an attack wouldn't work caused it to disclose an undocumented URL parameter (autorun=1) that, combined with the ?q= parameter, enables zero-click prompt execution on page load — no user interaction, no visible warning. A crafted URL (copilot.microsoft.com/?q=<prompt>&autorun=1) delivered via phishing/SMS/QR code could hijack a victim's authenticated session to exfiltrate emails, Drive files, chat history, or poison Copilot's persistent memory. Reported to Microsoft in December 2025; patch and CVE issued this week.
Key Takeaways:
- Novel disclosure method: the AI itself explained its internal protections and the bypass in detail when repeatedly questioned
- Combined
?q=+?autorun=1= one-click (or link-click) full session hijack, no visible indication to victim - Could exfiltrate via connected OAuth apps (Gmail, Drive, Calendar) or poison long-term Copilot memory for disinfo injection
- Broader lesson: LLMs lack a strict boundary between "data" and "instructions" — untrusted content gets executed as commands

Scammers Use AI Geolocation to Supercharge Travel-Themed Phishing
McAfee research (via The Guardian) shows freely available AI vision models can identify the location of a holiday photo — architecture, signage, light quality, road markings — with 87–91% accuracy, even without geotags or metadata, and even from photos where the destination was never named. Scammers then send SMS/email "unusual card activity while traveling in [city]" phishing lures citing the correct location, making otherwise generic phishing feel personally verified.
Key Takeaways:
- No metadata/geotag needed — AI reads the image content itself (signage, skyline, architecture)
- Best practice guidance is now less about scrubbing EXIF and more about timing: post after the trip, restrict visibility
- Same technique is directly transferable to corporate social engineering (team photos, conference pics) to build convincing pretexts

ToxicPanda 2.0 and GoldDigger Expand Android Banking Fraud
Zimperium documents a major ToxicPanda (TgToxic) update: 167 remote commands, expanded targeting to 349 financial institutions across 16 countries (up from 16 apps previously), PIN-harvesting overlays, and an automated ADB Wireless Debugging abuse chain for privilege escalation. Separately, GoldDigger (GoldFactory, Chinese-speaking APT) is running a fresh campaign impersonating airlines/retailers in South Africa and the UK, using a sophisticated "dpt-shell" packer with Frida-detection and anti-debug tricks, plus real-time screen access and virtualized app execution for credential interception.
Key Takeaways:
- ToxicPanda 2.0: accessibility-service abuse to harvest full UI state + lock-screen PIN overwrite capability
- Distribution shifted to AWS-hosted buckets for the latest ToxicPanda samples
- GoldDigger: WebSocket C2, RTMP live screen/audio streaming to attacker, on-device fraud via input injection mimicking user gestures

Fake Google Gemini Installer Delivers Vidar Stealer
Darktrace identified a campaign where a Google Colab page hosting a "download prompt" redirects to a fake "Windows Software Hub" serving Download_Google_Gemini_For_Windows.exe — actually a Go-compiled Vidar variant. The bundled README instructs victims to run as admin and add AV exclusions. Vidar then harvested browser-stored credentials and session data, communicating over port 443 with Telegram-associated infrastructure. Mirrors a broader pattern of fake-Claude and other AI-branded installer lures.
Key Takeaways:
- Lure abused trusted platform (Google Colab) for legitimacy before redirecting to the actual payload host
- IOCs:
dtm[.]kijangturbo88[.]top(C2), IPs91.98.98[.]86/91.98.111[.]49 - Broader trend: AI tool interest is now a reliable social-engineering hook regardless of malware family

New Mirai Variant "Evooo1Bot" Adds Stealth, SOCKS5 Proxy Capability
FortiGuard Labs documents Evooo1Bot, a Linux-based Mirai derivative targeting Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda, and Telesquare devices via unpatched vulnerabilities. Beyond standard DDoS, it adds encrypted C2 comms, an SSH scanner that skips likely honeypots, a default-credential sniffer, and — most notably — SOCKS5 proxy abuse that turns compromised edge devices into origin-concealing pivot points for follow-on operations.
Key Takeaways:
- Telemetry shows concentration in North/South America, Europe, India, China, Japan
- SOCKS5 proxy capability is the most operationally significant addition — enables origin concealment and internal network pivoting
- Honeypot-evasion logic (device fingerprinting before engaging) marks a step up in Mirai-derivative sophistication

"TwinLoot" Operates Entirely Inside Microsoft 365/Azure Infrastructure
Ontinue Cyber Defense Center documents TwinLoot, a modular Python malware framework (PyArmor-protected) that runs its entire C2 lifecycle from legitimate Microsoft cloud services: SharePoint Online + Graph API for C2 dead-drop, Microsoft Teams' TURN relay for interactive access, and the victim's own Edge browser to disguise Graph API traffic. Includes a pixel-perfect fake Windows lock screen for credential harvesting and a novel persistence technique — "Corrupting the Hive Mind" — that forges a mandatory profile hive offline via legitimate Windows APIs, requiring no admin rights and generating no registry-modification telemetry.
Key Takeaways:
- First documented combination of M365 dead-drop C2 + Teams TURN relay abuse + headless browser transport in one framework
- Credential harvesting via fake lock screen captures every login attempt, success or failure, with zero visible anomaly to the victim
- "Corrupting the Hive Mind" persistence evades standard detection logic entirely (no elevation, no registry events)
- Defensive shift needed: baseline "normal" Graph API/SharePoint/Teams behavior per account and alert on deviation, not just known-bad indicators












