Google’s Threat Intelligence team reports the first observed case of a zero-day exploit likely developed with AI, designed to bypass 2FA, which they disrupted before mass use. The research details adversaries using LLMs to accelerate exploit development and polymorphic malware (e.g., PROMPTSPY), industrializing access to premium models via proxy middleware, and targeting AI components in supply-chain attacks (e.g., LiteLLM/BerriAI). The guidance: harden AI gateways and secrets, validate third‑party “skills” and integrations, and pair phishing‑resistant MFA with rapid credential rotation.
Source: GoogleCloud TI
Mini Shai‑Hulud: 400+ malicious npm/PyPI packages hit TanStack, Mistral AI, UiPath in fresh supply‑chain wave
A new campaign pushed more than 400 trojanized versions across 170 packages, compromising popular developer ecosystems tied to TanStack, Mistral AI, UiPath, and others. The packages profile environments and siphon developer tokens and credentials, with reports of destructive behavior when stolen tokens are revoked. Organizations should audit recent dependency changes, revoke and rotate exposed keys, enforce 2FA for registries, and pin/verify package integrity.
Source: SecurityWeek
Dirty Frag: Linux hit by second critical kernel flaw in two weeks; exploitation suspected
The new “Dirty Frag” bugs (CVE‑2026‑43284, CVE‑2026‑43500)—a follow‑on to last month’s Copy Fail—allow local privilege escalation, with indicators that exploitation may have started before patches landed. Admins should apply kernel updates as they become available, restrict untrusted local access (including shared multi‑tenant hosts), and increase monitoring for unusual privilege escalation paths while mitigations roll out.
Source: SecurityWeek
Canvas breach extortion deadline looms, threatening data from 8,800+ school systems
Attackers affiliated with The Com are pressuring Instructure as they threaten to leak stolen Canvas data impacting thousands of K‑12 and higher‑ed institutions. The incident underscores systemic third‑party risk and the long tail of stolen student and staff data that can enable future fraud and targeting. Schools should enforce SSO/MFA, rotate tokens and credentials, and notify affected users about phishing risks tied to this breach.
Source: CyberScoop
Apple patches 84 vulnerabilities across iOS, macOS, watchOS, tvOS, and more—update now
Apple’s latest round of platform updates fixes 84 CVEs across the current “26” generation and supported previous versions (including iOS/iPadOS 18 and macOS 14/15). Enterprises should expedite testing and deployment due to the breadth of components touched and to reduce exposure windows on mixed‑fleet environments.
Source: SANS ISC
Iran‑linked Seedworm breaches Korean electronics maker using signed‑binary DLL sideloading
Symantec attributes a global spying operation to Seedworm (aka MuddyWater), which abused signed Fortemedia and SentinelOne binaries for DLL sideloading and exfiltrated data via a public file‑transfer service. The campaign highlights the persistence of living‑off‑the‑land and trust‑abuse techniques; defenders should scrutinize signed‑binary load chains, enforce application control, and monitor outbound transfers to public file‑sharing platforms.
Source: Symantec Connect
FCC delays ban on security updates for restricted foreign‑made routers and drones to 2029
The FCC’s Office of Engineering and Technology pushed the deadline from 2027 to at least January 1, 2029, extending the transition period before a ban on security updates for certain restricted devices takes effect. While the delay reduces near‑term disruption, it also prolongs uncertainty and potential exposure for critical IoT fleets; organizations should inventory affected hardware and plan lifecycle replacement.
Source: RecordedFuture
You May Also Be Interested In...
Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack
cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor
CISA adds critical BerriAI LiteLLM flaw to Known Exploited Vulnerabilities catalog