← Back to Feed

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

September 17, 2026 · The Hacker News · Severity: HIGH

Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough. So the threat landscape is not getting cleaner. It is just getting more places to make the same mistake. Heres what showed up this week. The threats change every week. Subscribe, and well alert you when each new ThreatsDay Bulletin is out. Malware PPI operation exposed CL-CRI-1171 Offers PPI Marketplace A threat actor known as CL-CRI-1171 has stayed under the radar for at least two years, offering a pay-per-install (PPI) marketplace that allows other threat actors to distribute their malware through YouTube channels and a parallel search engine optimization (SEO)-poisoning funnel.

Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough. So the threat landscape is not getting cleaner. It is just getting more places to make the same mistake. Heres what showed up this week. The threats change every week. Subscribe, and well alert you when each new ThreatsDay Bulletin is out. Malware PPI operation exposed CL-CRI-1171 Offers PPI Marketplace A threat actor known as CL-CRI-1171 has stayed under the radar for at least two years, offering a pay-per-install (PPI) marketplace that allows other threat actors to distribute their malware through YouTube channels and a parallel search engine optimization (SEO)-poisoning funnel. "These channels were actively interacting with viewers to promote gaming content laced with links to download malware," Palo Alto Networks Unit 42 said . "Although the videos provided real content for gamers, they also served as the delivery vehicle for infection, prompting viewers to download malicious tools. The SEO funnel targeted a more professional audience, promoting trojanized software that resulted in malware deployment on corporate endpoints, including critical infrastructure and even government entities." Both these chains lead to a custom loader called OfferLoader that has delivered three payloads between July 2025 and April 2026: Docro Hijacker (a Chrome backdoor that can bypass modern integrity protections ), ARKTunnel (a WebSocket tunneling RAT), and a new variant of a previously unnamed cross-platform backdoor that's been codenamed Insomnia remote access Trojan (RAT) and can target both Windows and macOS. Post-April 2026, the PPI infrastructure has led to GCleaner and Socks5Systemz . Exposed LocalAI instances compromised Large-Scale Attacks Target LocalAI Infrastructure A large-scale campaign has been found to target LocalAI instances exposed to the internet without authentication and achieve command execution inherent in MCP STDIO configuration. "Attacker artifacts indicated that 230 of 243 unauthenticated LocalAI instances were assessed as exploitable," Oasis Security said . "Callback logs independently confirmed command execution with root privileges on 23 servers. Post-compromise activity included exfiltration from a workstation associated with the Thai military and collection of 127 AWS credential records." The unknown threat actor is said to have selected high-value infrastructure from those LocalAI targets and compromised a desktop LocalAI workstation and a related private network. This was followed by exfiltration of sensitive data, including personal information, GPS coordinates, banking-application screenshots, and national ID card scans. Additional compromise activity consisted of exploitation of legacy infrastructure, authentication bypass, a broad sweep of cryptocurrency wallets and API keys, and theft of AWS ECS task credentials. Agents rewrite their own models AI Agents Can Retrain Own Models Mid-Task New research from Irregular has found that AI agents can retrain the model that powers them, in the process leaking secrets and eliminating refusals the model had been previously trained to enforce. "Given a routine software-maintenance task to fix incorrect application responses, the agent identified the shared model as the source of the problem, fine-tuned it, and replaced the model powering both the application and future instances of the agent itself," Irregular said . "It did so without being instructed to train, modify the model, or deploy a replacement." This phenomenon has been codenamed agentic self-modification. "Nothing in these experiments establishes malicious intent, self-preservation, or deception; the agents modified models because training appeared to help accomplish the assigned engineering task," Irregular added. "Agentic self-modification can arise during ordinary software maintenance when a coding agent has access to the model weights, training tools, and a deployment path to modify the model directly." AI agent linked to data breach Spain's Data Protection Agency Receives First Report of AI-Powered Data Breach The Spanish Data Protection Agency (AEPD) said it was notified of a data breach that was allegedly executed by an AI agent. "The attacker launched a scan for vulnerabilities in generic files and successfully logged in," AEPD said . "Once inside the system, the attacker began independently searching for vulnerabilities in the application; once found, this allowed the attacker to modify personal data and access invoices. What is relevant from a data protection perspective is that a third party appears to have used an AI agent as a tool to successfully chain together different phases of the attack." Ransomware exploits VMware RCE Critical VMware RCE Flaw Now Exploited by Ransomware Gangs The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that ransomware gangs have now started exploiting a critical VMware vCenter vulnerability patched in July. The flaw, tracked as CVE-2026-59310 , is a critical directory traversal vulnerability in the vCenter Syslog server that unauthenticated attackers can exploit to execute arbitrary code. In August 2026, German incident response company QUIRSO uncovered evidence that a China-nexus advanced persistent threat (APT) has been exploiting the flaw shortly after public disclosure. Oracle patches 800-plus flaws Oracle Announces Patches for 100s of Flaws Oracle has announced the release of new security patches as part of its September 2026 Critical Security Patch Update (CSPU). The patches address over 800 flaws. None of them have been flagged as actively exploited. "It's hard not to sound like a broken record these days when talking about security updates," Tyler Reguly, Fortra's Associate Director of Security Research and Development, said. "We're continually seeing large numbers of vulnerabilities and we're all starting to feel a little burnt out. I've said it before and I say it again, there is a light at the end of this tunnel and the record numbers of patches for record numbers of vulnerabilities will not last. I'm confident of this. Do everything you can to avoid burning out and just work on surviving this onslaught. I think that CISA BOD 26-04 did a great job of helping people to understand how to prioritize based on risk. I think that a 3-day turnaround is very tight when you need to also test your patches, but it helps lay out priorities that make a real difference is it publicly exposed, is it on the Known Exploited Vulnerabilities list, can it be automated, and does it give complete control. When you can answer these questions, you can start to identify the risk that it plays. Are there other components you can include? Sure, but this is a great start if you dont really know what risk looks like for your organization. Once you know what risk looks like, you can start to prioritize your patches more appropriately." Insider SIM swaps draw prison term Oregon Man Sentenced to 16 Months in Prison for SIM Swaps Former Oregon-based AT&T Store employee, Kenneth Carter, 44, has been sentenced to 16 months in prison for abusing his access to perform SIM swaps that helped criminals take over customers' bank accounts. Three victims suffered intended losses of nearly $600,0000, with Carter typically receiving $1,000 to $2,000 for each fraudulent SIM swap. Carter, who worked at the store from May 2018 to November 2019, has also been ordered to pay $99,528 in restitution. Carter pleaded guilty to the crimes earlier this March. AI drives malware evasion Threat Actors Use AI for Polymorphic Malware Evasion Google-owned Mandiant said it has observed advanced malware campaigns using embedded, lightweight AI models to facilitate stealthy, long-term persistence within victim networks. "In these environments, the malware does not rely on a static payload that might be flagged by traditional signature-based detection," Google said . "Instead, it uses local AI inference to analyze the host environment and identify the specific security tools currently active on the endpoint. During the attack phase, the malware dynamically rewrites its own command execution strings at runtime to bypass detection. By constantly altering the syntax and logic of its automated actions, the payload successfully evades static endpoint detection and response (EDR) signatures." The tech giant also warned that bad actors are using AI command-line interfaces (CLIs) to orchestrate and manage command-and-control (C2) infrastructure through natural-language queries and breaching cloud environments to "initialize an unisolated VM instance and transform it into a live, AI-assisted offensive hub" with an aim to debug and optimize offensive tools in real-time. Cyclops Blink returns on Cisco FMC New Variant of Cyclops Blink Spotted Sophos said it observed a variant of Cyclops Blink, a modular botnet and malware framework, on multiple compromised Cisco Firewall Management Center (FMC) devices in August 2026. "Unlike the WatchGuard-focused samples documented in 2022, the 2026 variant runs on x86-64 Linux and uses generic System V (SysV) persistence rather than vendor-specific firmware modification," Sophos said . "This change broadens the range of potentially compatible network-edge appliances. The implant's expanded capabilities include active network and service discovery, programmable packet surveillance, file transfer, and payload execution, allowing a compromised device to serve as a platform for internal reconnaissance, intelligence collection, and follow-on operations. The malware supports five worker modules that perform host reconnaissance, file transfer and payload execution, active network discovery, selective packet capture and content surveillance, and persistence. Cisco has described the Cyclops Blink activity as one of three separate campaigns involving two vulnerabilities in its Secure FMC software: CVE-2026-20079 and CVE-2026-20316. The findings once again show how compromised network appliances and other edge devices can give attackers a privileged vantage point into enterprise environments and allow them to observe traffic, conduct network probes, and launch additional attacks. RF signals leak analog secrets New InjectEave Attack Detailed A group of academics from the Hong Kong University of Science and Technology and the Hong Kong Polytechnic University has demonstrated InjectEave, a new class of electromagnetic side-channel attacks in which an external RF signal induces hardware nonlinearities that leak low-frequency analog secrets. "This vulnerability exists in ubiquitous nonlinear analog interfaces across the 11 commercial off-the-shelf devices we evaluated, allowing attackers to eavesdrop on headphone and landline audio, infer smart-fan speed and smart-lamp brightness, and recover other analog secrets that digital encryption and software defenses can hardly protect," the researchers said . "We demonstrate eavesdropping on audio played through wired and wireless headphones from up to 30 m away, as well as in through-wall scenarios, and characterize injection-induced EM leakage of other low-frequency secrets." Tests on 11 commercial devices, including headphones, VoIP phones, smart fans and lamps, showed that attackers could recover private audio or determine appliance states without physical access or modifying the devices. "Hardware-aware mitigations such as twisted-pair wiring, shielding, and filtering can lower the energy that the injected carrier couples into the device, reducing the exposure," the researchers said. "These mitigations raise the bar, but they do not guarantee immunity." Settra ransomware expands attacks Settra Ransomware Emerges A new ransomware group called Settra has deployed MeshAgent remote access software in two intrusions analyzed by Huntress. "Although the initial access method could not be confirmed, both attacks used ransomware executables named after the victim organization's domain and followed a highly similar operational pattern," Huntress said . "In the observed intrusions, attackers deployed remote monitoring and management (RMM) tools for persistence and then encrypted files, dropped RESTORE_FILES.txt ransom notes, cleared Windows event logs, and disabled Windows recovery options. One incident also included signs of Bring Your Own Vulnerable Driver (BYOVD); as well as a notable misspelling by the threat actors during the attack, which left them unable to clear the Windows Defender Event Log." Settra emerged in June 2026 and has mainly targeted entities in the U.S., Germany, the U.K., Canada, and Australia spanning technology, professional services, manufacturing, and retail sectors, according to researcher Rakesh Krishnan . The group has claimed 70 victims to date . In another case investigated by Cynet, "the ransomware engine was buried inside an encrypted blob and gated behind an operator-supplied password. Without the correct password, the executable simply terminated, leaving researchers and automated sandboxes with little to analyze." Uncensored AI sold underground Uncensored Luciferus AI Service Advertised A threat actor named Optimus_Prime (aka OptimusPrimero) is advertising an uncensored AI subscription service named Luciferus on the Exploit underground forum as an alternative to jailbreaking mainstream providers like ChatGPT, Claude, or Gemini. "The August advertisement describes Luciferus as an AI system that answers requests without moral or ethical restrictions and claims that it is based on a proprietary model that has '120 billion parameters,'" Sophos said , adding the tool is likely built on Alibaba's Qwen family of AI models. The service costs $35 per month and claims to support three models on its website ("luciferus[.]io"). "The emergence of Luciferus aligns with a broader trend in which threat actors are increasingly commercializing AI through underground forums, Telegram channels, and cybercriminal marketplaces," Sophos said. "Rather than developing their own models, many threat actors are offering access to uncensored or modified LLMs via AI-as-a-service schemes in the same way malware, phishing kits, and ransomware are commoditized." VectraRAT MaaS hits the market New VectraRAT MaaS Goes on Sale SOCRadar has disclosed details of a new malware-as-a-service (MaaS) platform called VectraRAT that's been built from scratch and is available for $250 a month. "It gives operators hidden-desktop control, keylogging, clipboard hijacking, browser credential theft, and a UAC bypass that elevates with no prompt," SOCRadar said . "It pairs a Go control server called VectraHub, with a Vue3 operator panel compiled into the binary, with a native C++ Windows implant. The two speak a proprietary binary TCP protocol using MessagePack over port 3308." The operator "Vectra" is a rebrand of "Nyxel," active since at least August 2022. The malware is delivered via Amadey and ClickFix lure pages. Casbaneiro hits Latin America Latin America Targeted with Casbaneiro A Casbaneiro attack campaign was observed targeting users in Latin America in August 2026, using phishing emails and PDF files themed around fake invoices and legal notices as an initial access vector. "Casbaneiro exhibits characteristics common to other malware families targeting financial institutions and users in Latin America, including clipboard injection and the use of fake windows to facilitate fraudulent activities," Fortinet FortiGuard Labs said . "In this attack campaign, the malware is delivered via a multi-stage infection chain that includes an HTA downloader and an AutoIt loader, with the latter responsible for injecting the final payload into a Windows process." KATARU brute-forces Telnet access KATARU IoT Malware Breaks In via Telnet Brute-Force An IoT malware dubbed KATARU has leveraged Telnet credential brute-forcing to break into Linux and embedded systems. "While it retains familiar Mirai-style botnet functionality, it stands out for its unusually broad capability set, including multiple Linux n-day local privilege escalation exploits, extensive persistence coverage across Linux and embedded environments, encrypted C2 communications, anti-analysis checks, and decoy traffic," Nozomi Networks said . The end goal is to establish communications with a C2 server and receive DDoS attack commands. It's suspected that KATARU was assembled with AI assistance. AI boosts LATAM intrusions AI Tool Use Targeting Orgs in Latin America Palo Alto Networks Unit 42 said it detected two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations in Latin America that leverage AI to enhance the threat actor's capabilities: CL-CRI-1131, which has used living-off-the-land (LotL) techniques and executed iterative batch scripts to troubleshoot issues and exfiltrate sensitive data, and CL-CRI-1163, which has used resume-themed phishing emails to deploy custom RATs and tunneling tools, including a Go-based SOCKS5 proxy. CL-CRI-1131 impacted a transportation organization, alongside federal government ministries and municipal water utilities in Mexico and Ecuador, while CL-CRI-1163 has singled out the Brazilian financial sector. "The threat actors behind the CL-CRI-1131 and CL-CRI-1163 campaigns have enhanced their technical capabilities by incorporating commercial LLMs into their workflows," Unit 42 said . "This integration enables them to author advanced proxy configurations and dynamically address complex execution failures. However, the infrastructure they deployed to leverage this AI became their Achilles' heel." Azalea RAT enables full control Azalea RAT Offers Extensive Remote Control A MaaS offering called Azalea RAT has been promoted as a modular malware platform with a wide range of post-compromise capabilities. "Azalea RAT combines remote administration, stealth mechanisms, privilege escalation, persistence, information theft, and an extensible plugin architecture," Rubrik Zero Labs said . "Once executed, the RAT allows an operator to manage the infected host, execute commands and additional payloads, collect sensitive information, manipulate system resources, and maintain remote access through an extensive command-and-control framework." The .NET RAT is designed for persistent and interactive control over compromised Windows systems. Azalea RAT arrives in the form of a Windows shortcut that masquerades as a PDF document to trigger the execution of a first-stage loader, which then performs anti-analysis checks before extracting a DLL that's responsible for setting up Microsoft Defender exclusion paths and ultimately launching the RAT. Infostealers target AI agent data Infostealers Come for AI Agents Infostealers like Amatera and Remus are expanding their data collection focus beyond browser passwords and cryptocurrency wallets to collect access tokens, MCP configurations, prompt histories, and project data stored by AI tools. "Amatera targets data associated with Cline and Continue, while Remus targets Claude, Cursor, and OpenCode," Gen Digital said . "The figures may overlap and describe detections rather than successful infections, but they show that AI agent data has already entered the information-stealer economy. What the malware is collecting goes far beyond harmless preferences. Depending on the agent and its configuration, local files may contain access and refresh tokens, credentials stored in MCP configurations, prompt histories, conversation databases, account details, and traces of the projects a developer has been working on. In one archive, an attacker may obtain both the means to access an account and the context needed to understand what is valuable behind it." Three Russians extradited ov

Key Takeaways

  • Multiple security vulnerabilities (CVE-2026-20316, CVE-2026-59310, CVE-2026-20079) have been identified, requiring prompt patching and assessment to mitigate potential exploitation risks.
  • Given the HIGH severity rating assigned to these vulnerabilities, organizations should prioritize remediation as part of their risk management workflow.
  • According to reporting from The Hacker News, this development highlights evolving cybersecurity challenges that security teams should monitor for emerging threats.
☕ Buy a Coffee