Financial Sector
FBI Investigation Leads To Five Venezuelan Nationals Pleading Guilty To Attempting To Jackpot Kansas ATMs"After a Federal Bureau of Investigation (FBI) investigation, five Venezuelan nationals admitted guilt in attempting to steal U.S. currency from automated teller machines (ATMs). U.S. Attorney Ryan A. Kriegshauser is encouraging banks and other financial institutions to take a proactive approach to guard against a criminal activity known as “jackpotting”, which is becoming more prevalent. Jackpotting involves installing malware into an ATM to force it to dispense sizeable amounts of money."
https://www.justice.gov/usao-ks/pr/fbi-investigation-leads-five-venezuelan-nationals-plead-guilty-attempting-jackpot-kansas
https://therecord.media/kansas-atm-jackpotting-guilty-pleas
New Tooling
Halo-Record: Open-Source Audit Trails For AI Agents"Brian Kuan wrote halo-record, a small Python package that sits inside an AI agent and writes down the moves it makes: tool calls, model calls, data access, approvals. Each action becomes one line in a file that only ever gets appended to, and every line carries a hash of the line before it, a hash being a short fingerprint computed from content. Edit a record later and every fingerprint after it stops matching. The code is open source, and anyone can run that check with no key, no account and no permission from the vendor whose agent produced the log."
https://www.helpnetsecurity.com/2026/08/31/halo-record-open-source-ai-agent-audit-trail/
https://github.com/bkuan001/halo-record
Vulnerabilities
Critical Ruby On Rails Vulnerability In Attackers’ Crosshairs"Hackers are exploiting a critical-severity Ruby on Rails vulnerability that leads to remote code execution (RCE), VulnCheck warns. Tracked as CVE-2026-66066 (CVSS score of 9.5) and referred to as KindaRails2Shell, the flaw is described as an arbitrary file read leading to secret exposure, RCE, and lateral movement. The security defect was disclosed in late July, when Ruby on Rails rolled out patches for it, urging the immediate patching of all Rails applications that rely on libvips for Active Storage image processing and allow image uploads from untrusted users."
https://www.securityweek.com/critical-ruby-on-rails-vulnerability-in-attackers-crosshairs/ CISA Adds Two Known Exploited Vulnerabilities To Catalog
"CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability"
https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog
https://www.securityweek.com/more-details-emerge-on-exploited-papercut-vulnerabilities/ Breaking Claude Code Opus 5 Auto Mode
"In this post, we explore how a simple website summary request hijacks Claude Code Opus 5 in Auto Mode and achieves code execution with 60-80% attack success rate using a small sample size. This is interesting because a third-party evaluation commissioned by Anthropic showed a 0.00% prompt injection attack success rate for Opus 5 in Auto Mode."
https://embracethered.com/blog/posts/2026/breaking-claude-code-opus-5-and-automode/
https://www.bankinfosecurity.com/hidden-attack-slips-past-claude-code-auto-mode-a-32693 Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit
"The researcher known as Nightmare Eclipse has dropped another zero-day — this time a privilege escalation exploit targeting a Kaspersky endpoint security product. Nightmare Eclipse, also known as Chaotic Eclipse, has released PoC exploits for many vulnerabilities in recent months, mainly Windows and Microsoft Defender flaws. The researcher started dropping zero-days after growing frustrated with Microsoft’s handling of vulnerability reports. While many of the exploits remained at the PoC stage, a few ended up being exploited in the wild by malicious actors. Over the weekend, Nightmare Eclipse released an exploit targeting a privilege escalation vulnerability in Kaspersky Endpoint Security. The exploit has been dubbed HardBreacher."
https://www.securityweek.com/nightmare-eclipse-drops-hardbreacher-kaspersky-product-exploit/
Malware
Fire Ant Evolves: From Hypervisors To Trusted Infrastructure"Fire Ant, first reported in 2025, remained active in 2026 and expanded its operations beyond hypervisors into the trusted infrastructure that routes traffic, authenticates administrators, manages access, and records activity. The main finding is that the actor was no longer targeting only individual systems, it was targeting the infrastructure layer that controls how entire environments connect and operate both within and across organizational boundaries."
https://www.sygnia.co/blog/fire-ant-evolves-from-hypervisors-to-trusted-infrastructure/
https://www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms/
https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html
https://securityaffairs.com/198183/apt/china-linked-fire-ant-hides-inside-trusted-infrastructure.html Anatomy Of BraZetsu: How Cybercriminals Fuel The Underground Ecosystem
"The Group-IB Threat Intelligence team has identified BraZetsu, a sophisticated Python-based Windows malware framework that we attribute, with high confidence, to the Brazilian threat actor known as Exilware. Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial assets. The framework exhibits high operational maturity, utilizing a modular architecture and stealth techniques that allowed some samples to remain fully undetectable on VirusTotal at the time of analysis."
https://www.group-ib.com/blog/brazetsu-ai-enhanced-iab-marketplace/ ValleyRAT Masquerading As Adware
"Attackers typically try to pass off malware as legitimate applications or as potentially unwanted programs that users deliberately search for and download, such as cheats or cracks. They often rely on ad and affiliate networks to deliver their creations to victims’ devices. This post examines a less conventional case: a well-known backdoor distributed under the guise of adware. The attackers may have chosen this distribution method because the adware was signed by the developer. On top of that, users often manually add these apps to exclusions, so their useful features don’t get blocked."
https://securelist.com/valleyrat-backdoor-adware/121175/
https://thehackernews.com/2026/08/valleyrat-backdoor-hides-in-signed.html
https://securityaffairs.com/198191/security/valleyrat-when-legitimate-software-becomes-a-malware-delivery-tool.html Spring Ring: An Inside Look At Voice Phishing Campaigns In Microsoft Teams
"Between January and April 2026, we uncovered a coordinated social engineering operation that leveraged external Microsoft Teams accounts to masquerade as IT help desk personnel. Our telemetry reveals that this operation targeted more than 150 employees across at least 10 companies in various industries. We call this activity Spring Ring. What seems like a benign chat is in fact a voice phishing (vishing) call, during which adversaries try to coerce victims into executing remote monitoring and management (RMM) tools or custom malware. In a more advanced variant, attackers transitioned from a vishing call to a full-blown Microsoft NT LAN Manager (NTLM) relay attack aimed at an organization's domain controller (DC)."
https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ Russian Hackers Plant Nuclear Weapon Prompt In Malware To Trip AI Safety Guardrails
"Russian state hackers are trying to interfere with AI-assisted malware analysis in Ukraine by deliberately setting off AI safety mechanisms, ESET has found. The technique, named GuardBreaker by ESET, appeared in a malicious VBS script tied to UAC-0099, a Russia-aligned group previously observed conducting initial-access operations and handing validated targets to the GRU-linked Sandworm hackers."
https://www.helpnetsecurity.com/2026/08/31/russian-hackers-ai-safety-filters-manipulation/
General News
AI Model Rules Are Not Security Controls"Known risks in agentic AI are manageable. The unknown unknowns, the paths a capable agent finds that no operator planned for, are where security architectures break. Recently, about 1,200 of OpenAI's agents found an unsanctioned communication channel despite controls meant to isolate them. About 700 ultimately joined an attack that reached Hugging Face's production systems while trying to find information that could help them cheat the ExploitGym benchmark instead of actually completing it as intended. Warning signs were logged but did not trigger adequate escalation to a human in the loop who could have intervened."
https://www.darkreading.com/cyber-risk/model-knowing-rules-is-not-security-control What Vulnerability Prioritization Looks Like When KEV, EPSS, And CVSS Disagree
"In this Help Net Security interview, Dr. Joye Purser, Global Field CISO at Cohesity, explains how to rank vulnerabilities when KEV, EPSS, and CVSS point in different directions. Active exploitation comes first, then exploit likelihood, then technical severity, with adjustments for asset exposure, business criticality, and compensating controls. The interview sets a 24 to 72 hour remediation target for exploited internet-facing systems and covers what an organization gives up to meet it, the hidden failure modes of deception technology, and where a 400-person manufacturer with a $250,000 budget should spend its first $50,000."
https://www.helpnetsecurity.com/2026/08/31/joye-purser-cohesity-kev-epss-cvss-conflicts/ AI AppSec Tools Agree On Just 5% Of Security Findings
"Software vulnerabilities are turning into exploits within hours, and application security teams carry patch backlogs that go back years. Contrast Security’s AppSec Overflow 2026 report draws on telemetry collected from inside hundreds of thousands of production applications and APIs. Adversaries touch the average application once every four minutes. Most of that traffic is automated reconnaissance, scanners mapping out weaknesses and cataloging services."
https://www.helpnetsecurity.com/2026/08/31/contrast-security-ai-appsec-tools-security-findings-report/ What The Hugging Face Incident Teaches Security Leaders About AI Agent Access
"Most security leaders (92%) worry that the growing use of AI agents will create new security risks. And for good reason. AI agents can now execute a full attack chain in double quick order, evidenced by the Hugging Face incident. AI agents broke into Hugging Face’s production environment and, in a little over four days, took 17,600 actions. In a separate lab test, an AI agent reached full domain administrator access in just 40 minutes. These are the kinds of incidents that once took humans multiple days to carry out, but with AI, they run on their own, end-to-end, with no human intervention. This puts the strain on unprepared security teams that are unable to close this gap."
https://www.securityweek.com/what-the-hugging-face-incident-teaches-security-leaders-about-ai-agent-access/
อ้างอิง
Electronic Transactions Development Agency (ETDA) cec7ebce-e6f8-4d0b-a080-27696b7de09a-image.png