Cyber Threat Intelligence 24 September 2026
-
New Tooling
- Prismor: Open-Source Runtime Control Plane For AI Agents
"Prismor is a free, open-source security layer for AI coding agents. It sits between an agent such as Claude Code, Codex, or Cursor and the actions that agent wants to take, and it checks each tool call against a policy before the call runs. Every call gets one of three verdicts: allow, warn, or block. AI coding agents run shell commands, read and write files, handle credentials, and call outside APIs, often chaining many steps with little human review. Anyone running one is exposed to a poisoned file, issue, or web page that redirects the agent mid-task, to an agent that opens a .env file while debugging and sends its contents out, and to installs of compromised packages. Endpoint security tools watch the kernel and file system, so they only see what the agent does after the choice is made. PrismorSec built Prismor to step in before that point."
https://www.helpnetsecurity.com/2026/09/23/prismor-open-source-ai-agent-security/
https://github.com/PrismorSec/prismor
Vulnerabilities
- Check Point Warns Of Hackers Exploiting Security Gateway VPN RCE Flaw
"Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. The same advisory also warns of threat actors exploiting a pre-authentication path traversal flaw tracked as CVE-2026-93616, which impacts the Management web service and can allow script execution and Java class loading. The company says that CVE-2026-93616 has been exploited as a zero-day since July 23."
https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/ - Critical Next.js ImageResponse Flaw Can Lead To Server Code Execution Via Crafted SVG Input
"A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image. Vercel, which develops Next.js, fixed the flaw on September 22 in version 16.3.6. The flaw, tracked as CVE-2026-94545, affects Next.js 16.2.0 through 16.3.5 when ImageResponse runs on the Node.js runtime, which Next.js uses by default. Vercel's advisory rates it critical, with a CVSS score of 9.5. The Edge version of ImageResponse is not affected, and neither is Next.js 15."
https://thehackernews.com/2026/09/critical-nextjs-imageresponse-flaw-can.html - CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After The Patch
"Yesterday we wrote up CVE-2026-87902, the unauthenticated local file inclusion in WordPress page template resolution fixed in 7.1.2. That post covered the sink, the preconditions and the fix. This is the follow-up on what we are seeing hit our firewall. Update, 23 September 2026: when this post first went up, every request we had seen was reconnaissance against harmless core files. That is no longer true. Attackers are now including pearcmd.php and using it to write PHP files to disk, and public scanning tooling for this CVE is in circulation. The Update section below covers what changed. The original first day analysis is kept underneath it as a record."
https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/
https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/
https://securityaffairs.com/199564/hacking/cve-2026-87902-how-close-is-your-wordpress-to-remote-code-execution.html
https://www.helpnetsecurity.com/2026/09/23/cve-2026-87902-wordpress-7-1-2-security-release/ - F5 Patches BIG-IP APM Zero-Day Flaw Exploited In RCE Attacks
"F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks. BIG-IP APM (short for Access Policy Manager) is the company's centralized access management proxy solution that helps admins secure access to their organizations' networks, applications, cloud, and application programming interfaces (APIs). Tracked as CVE-2026-94127, the flaw affects instances configured as an OAuth Authorization Server when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server."
https://www.bleepingcomputer.com/news/security/f5-warns-of-big-ip-apm-remote-code-execution-zero-day-exploited-in-attacks/
https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html
https://www.theregister.com/security/2026/09/23/someones-attacking-a-critical-0-day-rce-in-f5-big-ip-apm/5298659
https://www.securityweek.com/critical-f5-big-ip-vulnerability-exploited-as-zero-day/
https://securityaffairs.com/199619/security/f5-big-ip-apm-zero-day-exploited-in-zero-day-rce-attacks.html - New cPanel Flaw Lets a Hosting Account Run Code As Root, Take Full Server Control
"A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts. cPanel has released fixed versions for both, along with a fix for a third flaw in the same service, which stores each account's calendars and contacts. That third flaw lets a local user on the server read other accounts' calendar events and contacts, but not change them or gain root access."
https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account_0272795595.html - Adobe Patches Critical Flaws In Connect, AEM Forms
"Adobe on Tuesday rolled out patches for 36 vulnerabilities across its products, including critical-severity flaws in Connect and Experience Manager (AEM) Forms. The Adobe Connect update resolves nine security defects, including six critical issues that could be exploited for arbitrary code execution and privilege escalation. Tracked as CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, and CVE-2026-75698, they are described as SQL injection, cross-site scripting (XSS), and improper input validation flaws."
https://www.securityweek.com/adobe-patches-critical-flaws-in-connect-aem-forms/ - Chrome 154 Patches 108 Vulnerabilities
"Google on Tuesday announced the release of Chrome 154 to the stable channel with patches for 108 vulnerabilities, including 11 critical-severity bugs. The critical security defects include buffer overflows (three in ANGLE and one in WebGL), out-of-bounds writes (two in GPU and one in WebGL), and use-after-free bugs in ServiceWorker, Fullscreen, WindowDialog, and AdFilter. Nine of the critical issues were reported by external researchers. In total, 32 of the newly patched flaws were reported externally, while the rest were discovered by Google."
https://www.securityweek.com/chrome-154-patches-108-vulnerabilities/ - Send GitLab An Email, Push To Main
"GitLab projects have a button labeled "Email work item to this project". If you click it, GitLab shows you a private email address. Email anything to that address and a new issue appears in that project, authored by you. incoming+project-id-glimt-XXXXXXXXXXXXXX-issue@incoming.gitlab.com. The glimt- string in the middle of that address is a credential. It's a long-lived token tied to your account, and it never expires."
https://www.aikido.dev/blog/gitlab-email-push-to-main
https://www.darkreading.com/application-security/gitlab-email-addresses-supply-chain-attacks
https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html - MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password Or SSH Key
"Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at least September 2, one day before MikroTik shipped patches in RouterOS 6.49.21, 7.23.4, and 7.24.2. As previously reported, CERT Polska warned on September 5 that attackers were using RouterOS flaws to take control of devices whose SSH service was reachable from public networks."
https://thehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.html - Containers Are No Longer a Security Boundary
"Containers are generally considered as a robust security isolation boundary and are widely used to isolate workloads across enterprise and cloud environments. As AI accelerates kernel vulnerability discovery and exploitation, the barrier to escaping containers by attacking kernel has fallen so significantly that we must assume attackers can do so at will. There are nearly 6000 kernel CVEs published as of September 2026. In this post, we demonstrate such a case using CVE-2026-80521, a Linux kernel use-after-free vulnerability in the AF_UNIX subsystem discovered with dfs-large1. The exploit code is available on GitHub. Organizations should move sensitive and untrusted workloads to stronger isolation technologies such as Firecracker or Kata Containers."
https://depthfirst.com/research/containers-are-no-longer-safe
https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html - Stealing OAuth Tokens Through Microsoft's Front Door
"I was hunting for the next regsvr32. Not that binary specifically, but its category: a Microsoft-signed binary already on every Windows box that will fetch remote code and run it, so an attacker never has to drop anything unsigned. I pulled a catalog of signed binaries that don't appear in LOLBAS and filtered for anything that could reach the network and execute what it got back. The AppX web-host family came up in that filter, and one binary stood out. WWAHost.exe, the Windows Web App Host, will render whatever web content an AppX package points it at. That alone makes it interesting. However, what made me stop was the manifest flag: declare WindowsRuntimeAccess="all" and the remote JavaScript it renders doesn't just run, it inherits the full Windows Runtime API surface, including the API that drives OAuth sign-in. That was the moment it clicked as an attack. If a page I controlled could reach that sign-in API, it could stand up a real Microsoft login and pocket the tokens it handed back. I wanted to know if it actually worked."
https://www.huntress.com/blog/stealing-oauth-tokens-through-microsofts-front-door
Malware
- Placeholder Domain Used In Dev Docs Now Serves ClickFix Attacks
"The "third-party[.]com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell commands. The domain third-party[.]com has long been used in documentation to represent an arbitrary external website, API, or service, similar to how developers use domains such as example[.]com. However, unlike example[.]com, example[.]net, and example[.]org, which IANA reserves specifically for documentation, third-party[.]com is a normally registered domain whose content its owner can control."
<https://www.bleepingcomputer.com/news/security/placeholder-domain-used-in-dev-docs-now-* serves-clickfix-attacks/> - RemControl: AI Built The Overlays. Victims Lose Their PINs
"Group-IB researchers have discovered a previously undocumented Android banking trojan, internally named RemControl by its operator, targeting retail banking customers across Western Europe, the Middle East, and Canada. The malware abuses Android’s Accessibility Service to inject phishing overlays over legitimate banking applications, stream the device screen in real time, log keystrokes, and provide the operator with full remote control over infected devices. It is distributed through fake Google Play Store pages impersonating the TVTap IPTV application, with malvertising campaigns confirmed as one of the delivery channels."
https://www.group-ib.com/blog/remcontrol-android-banking-trojan/
https://www.bleepingcomputer.com/news/security/new-remcontrol-android-banking-malware-targets-users-in-europe-and-canada/ - Autonomous AI Agents Are Breaking Into Hundreds Of Online Retailers For $25 a Target In An Ongoing Campaign
"A financially motivated threat actor is using open source AI harnesses to attack hundreds of online retailers, at a marginal cost of tens of dollars per company. Gambit Security's Threat Intelligence team recovered the operator's staging server and reconstructed the campaign from it. Between 10 and 15 September alone, 105 attack projects were launched and at least 27 companies were compromised to varying degrees. The activity goes back to July 2026 and is still running."
https://gambit.security/blog-posts/autonomous-ai-agents-online-retailers-25-a-company
https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/ - Dark Sourcery: How Hackers Manipulate AI To Scam You
"ChatGPT, Gemini, and Google AI Overview are being poisoned by a massive AI disinformation attack. When users look up everyday info of hundreds of major companies, AI is delivering phishing traps disguised as trusted answers. Attackers are flooding the web with carefully optimized posts, PDFs, reviews, and fake support pages, to trick AI into presenting fraudulent phone numbers, email addresses, and login pages. The targets included Delta, Lufthansa, Qatar Airways, Chase, Bank of America, Airbnb, TripAdvisor, and hundreds more."
https://medium.com/@arielsimon/dark-sourcery-how-hackers-manipulate-ai-to-scam-you-88df434d2073
https://www.darkreading.com/threat-intelligence/attackers-manipulate-ai-chatbots-mass-disinformation-phishing-campaign - DarkMe Email Campaign Broadens Targeting For APT RAT
"DarkMe, a Visual Basic 6 (VB6) spy trojan and remote access tool became well known in February 2024 for its use of zero days to deliver malware. But this malware family was first observed in September 2021 and publicly documented a year later by NSFOCUS under "Operation DarkCasino" attributed to a group called EvilNum. Researchers at Trend Micro and SonicWall have also tied this malware, with the usual attribution caveats, to Water Hydra, an APT group with the unusual profile of chasing money rather than espionage. Its campaigns are typically financially motivated, targeting forex traders, stock-trading forums, online gambling platforms, and cryptocurrency users."
https://www.huntress.com/blog/darkme-rat-abandons-exploits
https://www.helpnetsecurity.com/2026/09/23/darkme-rat-phishing-email-hits-corporate-targets/ - Fake Claude Max Giveaway Hides a Google Account Phishing Trap
"Phishing follows whatever people want at the moment, and right now that includes AI subscriptions they don’t have to pay for. We recently uncovered a new variation on this theme: A fake Claude Max giveaway that uses a convincing Google sign-in window to steal login information. Claude’s paid plans start at $20 a month and cost considerably more for higher usage limits, while free accounts have stricter limits. That makes the promise of a free upgrade an attractive lure."
https://www.malwarebytes.com/blog/threat-intel/2026/09/fake-claude-max-giveaway-hides-a-google-account-phishing-trap
https://www.helpnetsecurity.com/2026/09/23/fake-claude-max-giveaway-phishing/ - x47.c Botnet Comes With 18 Attack Methods, Including AI API Draining
"x47.c is a previously undocumented Windows botnet advertised with 18 attack methods, credential theft, SOCKS5 proxies, and an AI module designed to help it remain on infected machines. Qrator Research Labs identified the offering, sold by WraithTools, during routine threat hunting. One of the advertised methods, “AI API drain,” is designed to exhaust a victim’s paid AI credits. Using a valid API key, an operator can send repeated requests that consume the account’s balance or increase its bill. OWASP describes this type of attack as Denial of Wallet (DoW)."
https://qrator.net/blog/details/x47.c-botnet
https://www.infosecurity-magazine.com/news/x47c-botnet-ai-api-draining-18/ - MemTensor Npm And PyPI Packages Hit By a Go Worm
"On September 23, 2026, an attacker published malicious versions of two MemTensor packages. The affected packages are the OpenClaw plugin @memtensor/memos-cloud-openclaw-plugin on npm and the MemOS Python library MemoryOS on PyPI. Both versions contain the same Go implant, sckit. The binary runs in the background each time the package loads. It collects credentials from the home directory and sends them to servers under skyleen[.]fr. It also includes the code it needs to copy itself into other repositories and packages that the stolen credentials can reach. The attacker got the publish tokens from MemTensor’s own GitHub Actions release pipelines. To do this, they pushed commits that made the release job hand its npm or PyPI token to the attacker before the job published anything."
https://safedep.io/memtensor-sckit-worm-npm-pypi/
https://www.aikido.dev/blog/supplychain-local-memtensor-npm-pypi
https://socket.dev/blog/memtensor-compromise
https://www.stepsecurity.io/blog/sckit-supply-chain-worm-hits-memtensor-npm-pypi-scopes
https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html - Meet AvisLoader: A Windows Loader Built To Outlast a Takedown
"Varonis Threat Labs recently discovered AvisLoader, a new Windows loader named after the Latin word for bird. We found it on an exposed staging server alongside a ClickFix lure, supporting tools, and its Command Center. The attack starts with a familiar ClickFix lure. A page posing as a document-signing request asks visitors to copy and run an attacker-supplied command on their machine. The more interesting part is how AvisLoader stays connected. It communicates via Tox, an encrypted peer-to-peer (P2P) messaging network that carries commands and additional payloads from the operator."
https://www.varonis.com/blog/meet-avisloader-a-windows-loader-built-to-outlast-a-takedown - Operation Conflict Compass: Konni Targets Ukraine Via Malicious LNK Lures
"Since 2009, the Democratic People’s Republic of Korea (DPRK) has fully integrated cyber operations into its national strategy, leveraging state-nexus threat groups to execute cyberespionage, conduct sabotage and influence operations, and generate revenue for state-sponsored nuclear weapons programs. Recently, the SOCRadar Threat Research Unit (STRU) uncovered Operation Conflict Compass, a targeted campaign by the DPRK-aligned actor Konni, aimed at gathering intelligence on the ongoing trajectory of the Russian invasion of Ukraine."
https://socradar.io/blog/operation-conflict-compass-konni-ukraine-lnk-lure/
Breaches/Hacks/Leaks
- GitHub App Private Keys: 474 Leaked Keys Exposed
"Supply-chain security has been a hot topic in recent years. Threat actors have exploited the npm, PyPI, and Rust ecosystems to compromise developer machines at scale, and GitHub has played a central role as an entry point through badly configured Action workflows. GitHub Apps are a lesser-explored vector in that same landscape. Because of the privileges they hold, they are one of the most sensitive components in the GitHub ecosystem, capable of reaching into every repository an installation covers and, in the worst cases, taking over the organizations that installed them. The recent CISA leak showed exactly how far that reach can go: a single compromised App became an open door into the organization's information system."
https://blog.gitguardian.com/github-app-private-keys-leaked/
https://www.infosecurity-magazine.com/news/hundreds-leaked-github-app-keys/
General News
- InfraTrust Report Warns Network Management Systems Under Attack
"Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. This was reported in the September edition of Eclypsium's InfraTrust Pulse, a monthly report tracking security advisories affecting network devices, servers, firmware, chips, and other infrastructure. Between August 25 and September 17, InfraTrust tracked 158 new security advisories across 17 vendors, covering 1,699 vulnerabilities."
https://www.bleepingcomputer.com/news/security/infratrust-report-warns-network-management-systems-under-attack/
https://pulse.infra-trust.org/september-2026/ - Ryuk Ransomware Member Sentenced To 24 Months In Prison
"An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks. 35-year-old Karen Serobovich Vardanyan (also known online as "Maneeken" or "Karl Lagerfeld"), who specialized in gaining initial access to corporate networks, pleaded guilty in July after being extradited from Kyiv, Ukraine, following his April 2025 arrest. According to court documents, Vardanyan hacked into the networks of multiple U.S. organizations in Ryuk ransomware attacks between March 2019 and approximately June 2020."
https://www.bleepingcomputer.com/news/security/ryuk-ransomware-member-sentenced-to-24-months-in-prison/
https://therecord.media/ransomware-ryuk-sentenced-doj
https://cyberscoop.com/ryuk-ransomware-operator-karen-vardanyan-sentenced/ - CISA Lays Out Future Of CVE Vulnerability Program
"The U.S. Cybersecurity and Infrastructure Security Agency published a short whitepaper Wednesday, laying out four "dimensions of quality" it will pursue to improve the Common Vulnerabilities and Exposures program it oversees, which catalogs and characterizes newly discovered software vulnerabilities. The CVE program is widely regarded as one of the world's most trusted and widely used cybersecurity public goods. It's employed by cyber defenders all over the world. Its future is a matter of enormous importance to the large cybersecurity vendor ecosystem that has grown up around vulnerability prioritization and management."
https://www.bankinfosecurity.com/cisa-lays-out-future-cve-vulnerability-program-a-32912
https://cyberscoop.com/cisa-cve-data-quality-white-paper-expert-reaction/ - How The CISO-CMO Alliance Builds Trust Before Crisis Strikes
"Chief information security officers (CISOs) and chief marketing officers (CMOs) sit at the intersection of a critical tension: CMOs seek to leverage vast pools of customer data to drive growth, brand loyalty, and market share. CISOs work to minimize risk exposure and protect that same data. But rather than viewing these objectives as opposing forces, forward-thinking organizations recognize that CISO-CMO alignment is foundational to a competitive advantage. Unfortunately, as is often the case, if this relationship isn't already established, miscommunication and misalignment can turn a security incident into a brand disaster."
https://www.darkreading.com/cybersecurity-operations/how-ciso-cmo-alliance-builds-trust-before-crisis - Cyberthreats To The Gulf States In H1 2026
"A high level of economic development, a key role in the global energy sector driven by oil and gas exports, and heavy investments in digital technologies make the Gulf states an attractive target for financially motivated cybercriminals. Additionally, the tense geopolitical climate in the region has led to increased activity from hacktivists and advanced persistent threat (APT) groups. This report analyzes the cyberthreat landscape in the Gulf states during the first half of 2026. The countries covered include Bahrain, Iraq, Iran, Kuwait, Oman, Qatar, Saudi Arabia, and the United Arab Emirates (UAE)."
https://positechglobal.com/en/research/analytics/cyberthreats-to-the-gulf-states-in-h1-2026/
https://www.darkreading.com/threat-intelligence/uae-saudi-arabia-face-onslaught-of-increasingly-sophisticated-automated-cyberattacks - Cloud Intrusions Now Move At Machine Speed
"Cloud-native environments are vital to AI initiatives and business transformation. That also makes them high-value targets. Fortinet FortiCNAPP intelligence shows that threat actors are now using automated attack workflows to identify vulnerable deployments, breach them, and quickly turn access into profit. The 2026 Cloud-Native Threat Landscape Report draws exclusively on FortiCNAPP intelligence to examine the scale of adversary activity, the paths attackers use, the gaps they exploit, and the actions security leaders must now take to strengthen cloud resilience and accelerate defender velocity."
https://www.fortinet.com/blog/industry-trends/cloud-intrusions-now-move-at-machine-speed - Nearly Two-Thirds Of Tested Websites Fail Every Bot Test
"Malicious bot activity increased 124% between July 2025 and June 2026, compared with 13.2% growth in human traffic. Traffic from AI agents and large language model crawlers rose 82.3% during the same period, according to DataDome’s State of Bot & Agent Security Report 2026. The company analyzed trillions of requests across more than 75,000 customer sites during the 12-month period. Bots and AI agents generated approximately 26.5% of all traffic in the dataset."
https://www.helpnetsecurity.com/2026/09/23/datadome-growing-bad-bot-traffic-report/ - Ransomware Attacks Reach Record High For 2026
"Over 1000 organizations globally were hit with ransomware attacks during August, as the number of cyber extortion campaigns reached a new high for 2026, analysis of incidents has warned. According to NCC Group’s Cyber Threat Intelligence Report for August 2026, published on September 23, 1073 companies fell victim to ransomware attacks during the month. The report stated the figure represented a record high for 2026 and a 12% increase on the 973 organizations hit by ransomware attacks during July. During August, North America was the most common target for ransomware attacks, accounting for 44% of incidents, organizations in Europe accounted for 26% of known incidents, while 13% of ransomware attacks targeted victims in Asia."
https://www.infosecurity-magazine.com/news/ransomware-attacks-reach-record/ - EU Auditors Warn Information-Sharing Gaps Are Hindering Cyber Incident Response
"The EU’s top audit institution has criticized the union for various “shortcomings” that are hindering its detection and response to large-scale cyber incidents. The EU Court of Auditors said in a new report that the bloc’s €1.4bn ($1.6bn) budget for cybersecurity is doing some good, but that it suffers from an Achilles heel, “The insufficient exchange of information.” A lack of formally defined roles is hampering cooperation between country-level CSIRTs and European Cyber Crisis Liaison Organisation Network (EU-CyCLONe), it warned."
https://www.infosecurity-magazine.com/news/eu-auditors-slam-blocs-cyberinfo/ - Anthropic And OpenAI Models Still Attempt Restricted Actions In Safety Tests
"Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior. Opus 5.5, per Anthropic, is a "major step up from Opus 5," and "achieves the best scores of any model to date on our automated behavioral audit, our alignment suite that tests Claude across thousands of simulated scenarios." The AI company said the model is less likely than its other recent models to carry out hard-to-reverse actions or act outside the boundaries it's been given, adding it's more resistant than Opus 5 to prompt injection."
https://thehackernews.com/2026/09/anthropic-and-openai-models-still.html - Latvia Arrests Suspected Hacker For Electronics Repair Company Breach
"Latvian police arrested a 23-year-old man suspected of hacking at least two companies, stealing personal information and attempting to extort money from the victims, authorities said Wednesday. The first attack was detected in February, while a second — using similar methods — was discovered in early September at TSC, an electronics repair company belonging to Latvian telecommunications group LMT."
https://therecord.media/latvia-hacker-arrest-cyberattack - A Look At AI Doomsday Scenarios That Researchers Say Could Put Humanity At Risk
"For years, artificial intelligence researchers have warned of ways the technology could wipe out humanity: AI bots could design an unstoppable disease, unleash a nuclear war, or transform all of Earth into paper clip factories, as one thought experiment goes. Debates inside the AI industry and beyond over the plausibility of these doomsday scenarios have heated up since several executives endorsed slowing the technology’s development for safety reasons. Despite warnings of the potential for humans to lose their grip on the technology, some suspect the worst-case scenarios described by the AI companies themselves have more to do with validating the importance of their work than reality."
https://www.securityweek.com/a-look-at-ai-doomsday-scenarios-that-researchers-say-could-put-humanity-at-risk/
อ้างอิง
Electronic Transactions Development Agency (ETDA)
- Prismor: Open-Source Runtime Control Plane For AI Agents