This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before.
That is the thread running through the pile. Trusted paths get poisoned. Old bugs find new jobs. AI tools leak more than expected. Fake prompts look real enough. And some attacks barely need an exploit at all — just one weak setting or one person doing what the screen tells them.
Nothing here looks especially dramatic. That is what makes it useful.
The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
-
AI-Assisted Banking Trojan
A previously undocumented Android banking trojan dubbed RemControl is targeting retail banking customers across Western Europe (Italy, France, Spain, Poland, Portugal), the Middle East, and Canada. The malware is distributed via fake Google Play Store pages impersonating the TVTap IPTV application. Users are directed to the web page through Meta ads. It was first observed in July 2026. “The malware abuses Android’s Accessibility Service to inject phishing overlays over legitimate banking applications, stream the device screen in real time, log keystrokes, and provide the operator with full remote control over infected devices,” Group-IB said. “C2 address is resolved dynamically through an encrypted Telegram dead-drop, making infrastructure rotation straightforward without recompiling the malware. Both the operator panel documentation and phishing overlays contain artifacts of AI-assisted development, including a complete AI assistant response left verbatim in a live phishing page served to banking victims.” The presence of Russian-language code comments in multiple overlay HTML files indicates the involvement of a Russian speaker. Overlapping campaign naming conventions, delivery mechanisms, the use of Telegram dead-drop and affiliate tag similarities suggest a possible link to the Medusa UNKN affiliate botnet.
-
AI Code Privacy Concern
Chinese artificial intelligence company Z.ai has disabled several features of its ZCode coding assistant after a default setting was caught sending users’ local code repositories to Alibaba Cloud servers in China without their consent, a couple of months after SpaceXAI’s Grok Build coding CLI was found uploading entire Git repositories to a Google Cloud Storage bucket under its control. Although Z.ai has since disabled the workflow responsible for generating and uploading local repository snapshots in its ZCode client and opened up its codebase for public scrutiny, the development raises fresh concerns for enterprises over how AI tools handle sensitive source code.
-
Critical Infrastructure Access Risk
The U.S. Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) have published a fact sheet to “highlight considerations for critical infrastructure entities to reduce risk and minimize vulnerabilities when working with third-party industrial control system (ICS) integrators.” The alert urges critical infrastructure owners and operators to maintain caution when granting third-party ICS integrators high levels of access or control over industrial processes and ensure the principle of least privilege (PoLP) is applied. “Not adopting principles such as PoLP could expose owners and operators to malicious cyber actors seeking to compromise critical infrastructure, possibly providing sensitive access to pathways that actors can exploit to cause disruptive and destructive effects to equipment and critical functions,” the authoring agencies said.
-
Super-App Surveillance Capabilities
MAX is a state-backed Russian mobile “super-app” developed by VK (aka VKontakte) that combines instant messaging, e-commerce, banking, and public government services. A new forensic research published by a group of researchers from the University of Michigan, University of Calgary, Georgia Institute of Technology, and Indian Institute of Technology, Delhi, has revealed the extent of its surveillance capabilities: “Playing the role of an active adversary, we found five distinct capabilities that allow MAX to act as a man-in-the-middle for all mini-app interactions: (1) MAX can capture screenshots of mini-app content without holding any special system permissions, and without alerting the user; (2) It holds full read and write access to all mini-app local storage, meaning no data a mini-app persists on-device is private from MAX; (3) It injects JavaScript into running mini-apps, enabling silent, undetectable modification of mini-app functions at run-time; (4) It mediates all mini-app network traffic, and in the Russian regional build specifically, routes this traffic through a GOST TLS proxy, raising acute concerns about state-level interception [18]; (5) Finally, it controls the authentication tokens and session context supplied to each mini-app, granting it the ability to silently impersonate any user to any service hosted within the super-app ecosystem. These findings uncover that MAX’s super-app architecture can actively and silently undermine the security guarantees that users assume when interacting with each mini-app.”
-
Fake Giveaway Phishing Trap
A fake Claude Max giveaway has used a spoofed Google sign-in window to steal users’ login credentials by means of a browser-in-the-browser (BitB) attack. “There is no form to collect card details and no download,” Malwarebytes said. “Instead, it offers a free upgrade and asks you to sign in with your Google account. Clicking the Google button doesn’t open a real Google sign-in window. Instead, the page draws a browser window inside the existing tab, complete with a padlock and a correctly spelled Google sign-in address. It can even be dragged around the page.”
-
EDR Evasion Technique
In July 2026, researchers Max Hirschberger and Ogulcan Ugur detailed a technique called Process Parameter Poisoning to inject code in foreign processes without triggering traditional security mechanisms. Flashpoint has now released a proof-of-concept implemented in Rust to demonstrate the EDR evasion technique. “Process Parameter Poisoning is a novel endpoint detection and response (EDR) evasion technique that combines process parameter spoofing and thread execution hijacking to inject code into foreign processes without triggering standard security detection mechanisms,” Flashpoint said. “Instead of calling memory-accessing APIs to allocate and write into a target process, the technique hides the malicious payload directly inside standard process initialization structures during the initial creation of a process. The result is a fundamental shift in defense evasion that effectively blinds traditional, API-hooking EDR agents during the initial stages of code execution.”
-
Faster Ubuntu Kernel Fixes
The “recent explosion” in the volume of CVEs, mainly driven by AI, has prompted Canonical to transition to a unified, 2-week release cycle that merges its four-week cycle for regular Stable Release Updates (SRUs) and its two-week cycle for security fixes. “These recurring 2 week cycles cascade: each cycle begins the week after the previous one starts. Because of this overlap, kernel releases will take place weekly,” Canonical said. “The first week will focus on kernel package preparation. This is where we select what updates and patches land on each kernel depending on specific needs.”
-
AI Search Poisoning Campaign
A massive AI disinformation attack is poisoning ChatGPT, Gemini, and Google AI Overviews with false information, fraudulent phone numbers, email addresses, and login pages, according to Vigilance Security’s Ariel Simon. “When users look up everyday info of hundreds of major companies, AI is delivering phishing traps disguised as trusted answers,” Simon said. “Attackers are flooding the web with carefully optimized posts, PDFs, reviews, and fake support pages, to trick AI into presenting fraudulent phone numbers, email addresses, and login pages.” Targets of the campaign include Delta, Lufthansa, Qatar Airways, Chase, Bank of America, Airbnb, TripAdvisor, and several other companies. The fake content is uploaded to social media, websites that allow file uploads, website hosting platforms (Google sites, GitHub pages, WordPress, and Blogger), fundraisers, job search, and event platforms (Posh.vip, onecause.com, bebee.com, and raiselysite.com), and even reviews on Yelp and Apple Maps.
-
ClickFix MaaS Copycat
Sekoia has shed light on a new ClickFix malware distribution framework dubbed Exvicy that has been advertised by a Russian-speaking actor under a malware-as-a-service (MaaS) model on Exploit.in since May 26, 2026. It launched at $1,200 per month and rose to $2,000 in mid-August, with the operator claiming “detections are becoming daily.” The framework employs the Windows Run dialog tactic on fake Cloudflare CAPTCHA checks injected into compromised WordPress sites to distribute malware. “Exvicy is a copycat of ErrTraffic, directly reusing its injected JavaScript, ClickFix HTML, and C2 communication logic,” security researcher Quentin Bourgue said. “Examination of the Excvicy JavaScript framework demonstrated that it reuses the ErrTraffic JavaScript codebase, including the obfuscated script injected to compromised WordPress sites and the ClickFix lure responsible for command-and-control (C2) communications.”
-
Malicious WordPress Update
A malicious version of the Admin Menu Editor Pro plugin for WordPress was uploaded to adminmenueditor[.]com on September 14, 2026. “This showed up as a version 2.35 update to users who had the plugin active,” Janis Elsts, the plugin’s maintainer, said. “This version included a new file includes/wp-user-consent.php that installs a web shell on the user’s site.” After a clean version (2.36) was pushed the same day, threat actors managed to again compromise the new version, suggesting they may have obtained root-level access to the server. As of September 20, the maintainer has released version 2.37 for customers who don’t have a clean copy of the plugin. The root cause has been traced back to a vulnerability in an outdated Linux kernel version, with the earliest sign of compromise dating back to September 13, 2026, at around 7:40 p.m. UTC. The maintainer also said they were working on “rebuilding the update server and licensing API nearly from scratch,” an effort that “could easily take a couple of weeks.” In a statement shared with Bleeping Computer, Elsts said at least 230 customers installed the malicious update on 1,500 sites.
-
Government Impersonation Scams
The FBI is warning that scammers are impersonating U.S. and foreign law enforcement or government officials to extort money or personally identifiable information (PII) from victims as part of widespread fraud schemes. Between January 2025 and July 2026, the FBI’s Internet Crime Complaint Center (IC3) is said to have received nearly 61,000 complaints of law enforcement or government impersonation scams, leading to losses totaling more than $1.6 billion. “Scammers will use a variety of approaches while impersonating these officials, such as using urgent and aggressive tones, refusing to speak to or leave messages with anyone other than the targeted victim, keeping victims on the phone for the duration of the scam, or urging victims not to tell family, friends, financial institutions, or law enforcement about the call,” the FBI said. “The scammers demand payment through a variety of methods, including prepaid cards, couriers, bank wires, cryptocurrency, or cash inserted into cryptocurrency kiosks.”
-
GitHub Cache Poisoning Defense
GitHub has announced that developers can now use cache-mode to apply least-privilege access to the GitHub Actions cache at the workflow or job level. “By granting each workflow or job only the cache access it needs, you can prevent unnecessary restores or saves and help protect trusted workflows from cache poisoning,” GitHub said. “This capability is now generally available on all plans.” According to Socket, the new setting targets cache poisoning attacks such as those observed in the case of the Ultralytics PyPI package in 2024 and the TanStack npm packages in May 2026. “Cache poisoning works because an entry written to the shared Actions cache in one context can be restored and run in another,” Socket noted. “An attacker who gains write access to a cache key that a trusted workflow later reads can plant malicious build artifacts or dependencies that execute with that workflow’s permissions and secrets.”
-
Software Supply Chain Attack
SafeDep has disclosed that an unknown threat actor added on September 8, 2026, a malicious source dependency to Deep-Live-Cam, a Python face swapping application with 96,600 GitHub stars. “The dependency contains a loader that downloads a cryptocurrency clipboard hijacker for Windows and macOS,” SafeDep added. “The recovered payload replaces wallet addresses in clipboard text and registers itself to run at login.” In another case, the supply chain security company detected a malicious npm package named ulid-xyz that typosquats as ulidx but harbors a cross-platform remote access trojan that’s triggered via postinstall hook. “The postinstall hook reads as a guard that checks if a build file exists,” SafeDep said. “It actually launches dist/node/utils.js as a detached background process, which starts dist/node/payload.js, a 467 KB bundled trojan. That bundle decodes an obfuscated configuration and beacons to a hard-coded command server over WebSocket. It then installs persistence on Windows, macOS and Linux under the name MicrosoftSystem64.” The malware is equipped to fingerprint the host, access the file system, and run arbitrary code sent by the attacker. MicrosoftSystem64 has been previously delivered through js-logger-pack and terminal-logger-utils packages, and is a stealer and implant linked to North Korea.
-
OpenAI Credential Phishing
A fraudulent subscription invoice email campaign is targeting users with an aim to steal their account credentials using fake login pages, luring them to take action within 48 hours to avoid service interruption. “While AI chatbots are extremely helpful tools in performing repetitive tasks, users need to be aware that, like with all account creation, the threat of credential theft is still persistent,” Cofense said. “Whether it is a traditional phishing attack similar to the one described in this article or the use of smishing/vishing, attackers are constantly finding unique pathways through security systems and secure email gateways (SEGs).” In another phishing campaign, payment plan-themed emails are being used to initiate a multi-stage attack chain that leads to the deployment of the Global Group ransomware. “Global Group is a rebranding of the legacy Black Lock and Mamona ransomware families by inheriting an established backend infrastructure, reusing core code artifacts, and launching an immediately scalable extortion enterprise,” Cofense said. “They partner heavily with Initial Access Brokers (IABs) to purchase pre-compromised corporate credentials, allowing their affiliates to bypass perimeter defenses. Global Ransomware utilizes double extortion and threats of public data leaks as part of their aggressive negotiation tactics.”
-
DarkMe Returns via Social Engineering
Huntress said it has spotted the DarkMe malware in two separate incidents affecting different organizations on August 31, 2026. DarkMe is a Visual Basic trojan linked to a threat actor known as Water Hydra (aka DarkCasino). “Two years ago, DarkMe developed a reputation by leveraging two separate zero days to deliver its malware: WinRAR (CVE-2023-38831) and Windows Defender SmartScreen (CVE-2024-21412),” Huntress said. “But in these new incidents, the malware didn’t leverage exploits, relying on social engineering to convince users to run a .pif file linked from an email. The absence of exploits made the attack chain cheaper and more indiscriminate, reflecting a broader industry trend of adversaries abandoning complex technical exploits for high-volume, low-skill attacks that rely on user error.”
-
One-Click VS Code Compromise
Remedio has detailed a Visual Studio Code vulnerability that could transform Microsoft’s code editor into a vector for compromise through a single link. “It works by defeating the exact security feature built to stop it: Workspace Trust,” Remedio said. “The purpose of that feature is to decide whose code is allowed to run. This attack makes that decision for you, without asking. The price of admission for the attacker is low. No exploit chain. No memory corruption. No zero-day dropper. Just one click on a link that looks completely normal, the kind of link you have clicked a thousand times without a second thought. Click it once, and an attacker is running code on your machine, as you, with access to your files, your SSH keys, your cloud tokens, and your source code. And it comes back every time you reopen the editor.”
That is it for this week. Different tricks, same weak spots: trust, access, old software, bad defaults, and people moving too fast.
Most of these attacks do not need magic. They just need one small thing left open long enough. Fix those first, and a lot of the noise gets quieter.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


