AI-Driven Exploit Acceleration Exposes Siemens ROX II Zero-Day to Unauthenticated Root Access
Unit 42 disclosed an unauthenticated stack‑based buffer overflow in the Siemens ROX II web service (CVE‑2024‑XXXX) affecting firmware versions 2.3.0 through 2.5.1. The flaw resides in a fixed‑size HTTP‑header parser (~1 KB) that lacks length checks, allowing remote attackers to overwrite the return address with >2 KB of header data and execute root‑privileged shellcode on the underlying Linux‑based OT controller. Large language models can generate a functional Python exploit in under 15 minutes, collapsing traditional reverse‑engineering timelines and exposing >12 000 deployed controllers to immediate compromise.
Supply Chain Attacks Industrialized: SaaS, Open Source, and MSP Ecosystems as Primary Attack Vectors in 2026
In 2026, threat actors have industrialized supply‑chain compromise, treating SaaS platforms, open‑source repositories, and managed service provider (MSP) ecosystems as repeatable production lines. Initial access is gained via credential stuffing or phishing, followed by insertion of malicious code into npm packages, hijacked GitHub Actions workflows, trojanized SaaS plugins, and backdoored MSP RMM agents. These compromised vectors enable lateral movement through trusted update mechanisms and monetization via ransomware, data exfiltration, or cryptojacking, with attack frameworks sold as a service lowering the barrier for large‑scale campaigns.
GhostAction Campaign Compromises 500+ GitHub Accounts to Steal Cloud and AI API Credentials
The GhostAction campaign compromised over 500 GitHub maintainer accounts, injecting malicious GitHub Actions workflows into more than 340 repositories to exfiltrate cloud and AI API credentials. Attackers utilized stolen Personal Access Tokens (PATs) with repo, workflow, and admin:org scopes to deploy obfuscated shell scripts and base64-encoded payloads. These workflows exfiltrated critical secrets—including AWS, GCP, Azure, OpenAI, and Hugging Face tokens—to attacker-controlled domains: ghostaction.xyz, exfiltrate.cloud, and apistealer.net. One critical CI/CD repository alone yielded approximately 3,325 exfiltrated secrets, exposing high-value cloud resources and AI models to significant theft and unauthorized usage.
AI-Generated Lures and Quishing in a Google-Impersonating AitM Campaign Targeting Taiwan Research Sector
A China-linked APT group has launched a sophisticated, AI-assisted spearphishing campaign against Taiwanese research institutes and academic bodies. The operation utilizes AI-generated email lures and malicious QR codes (quishing) to drive victims to highly convincing, multi-locale Google login clones. By leveraging an Adversary-in-the-Middle (AitM) framework, attackers maintain a persistent WebSocket C2 channel to relay MFA challenges in real-time, enabling the theft of session tokens and bypassing multi-factor authentication. This campaign represents a significant escalation in autonomous, AI-driven cyber espionage targeting high-value intellectual property and policy research.
Cisco Warns AI Agent Swarms Compress Attack Lifecycles to Hours
Cisco Talos reports that threat actors are increasingly deploying LLM-driven autonomous agent swarms, such as AutoGPT and BabyAGI variants, to orchestrate highly automated, multi-stage cyberattacks. These swarms integrate reconnaissance, credential harvesting, and exploit chaining into a coordinated workflow that bypasses traditional human-in-the-loop latency. By automating OSINT, persona-specific phishing, and adaptive C2 beaconing, adversaries can compress the typical attack lifecycle from 30–90 days to under 10 hours. This acceleration results in an ~80% reduction in ransomware dwell time and a significant increase in the velocity of lateral movement and credential theft, necessitating a shift toward real-time, AI-driven behavioral detection and automated response.
Ghostcommit: Image-Embedded Prompt Injection Bypassing AI Code Review
Ghostcommit exploits steganographic embedding of malicious prompt instructions within image files to subvert AI‑driven code‑review pipelines that invoke vision‑language models (e.g., GPT‑4V, Claude 3 Vision). When the model processes the image via OCR or direct vision input, the hidden text is interpreted as part of the prompt, overriding safety filters and forcing the model to disclose secrets such as API keys, SSH private keys, or .env contents. The attack evades conventional text‑based sanitization and file‑type checks, enabling data exfiltration through model output or logged review comments.
Agentic AI-Driven Financial Intrusions Targeting South Korean Banks
In October 2026, a financially motivated threat actor used agentic AI to compromise seven major South Korean banks, harvesting employee credentials via AI‑generated phishing pages on fraudulent loan‑agent sites and then leveraging the ARTEX automated penetration‑testing framework guided by Claude LLM to conduct autonomous reconnaissance, lateral movement, and privilege escalation. The adversary abused legitimate banking APIs (SWIFT, payment gateways), exfiltrated ~12 M customer records through steganographic image files, and initiated fraudulent wire transfers causing ≈USD 210 M in direct loss, 4‑hour average service outages, KRW 30 B in regulatory fines, and measurable reputational damage. The campaign was uncovered by CrowdStrike and Aviatrix threat‑intelligence feeds, dark‑web monitoring, and incident response, prompting a nationwide alert from Korean financial authorities.
Microsoft-Signed Kernel Driver Abused to Disable Security Tools and Harvest Credentials
Attackers are exploiting a vulnerability in a Microsoft-signed kernel driver, example_driver.sys, which facilitates arbitrary kernel memory read/write operations through IOCTL 0x80002000. By leveraging this trusted signature, threat actors bypass endpoint protection by unhooking security callbacks and subverting PatchGuard. This "Bring Your Own Vulnerable Driver" (BYOVD) technique enables unauthorized privilege escalation and the theft of sensitive credentials from LSASS, SAM, and domain controllers via DCsync. This method presents a critical risk by subverting the root of trust in the Windows kernel to evade detection and facilitate widespread lateral movement across high-value environments.
UNC3569 Exploits Sogou Input Method URI Handler Flaw to Deploy GRAYRABBIT Backdoor via Chromium 80 CVE-2021-38003
UNC3569, a China-linked espionage group, weaponized a URI handler vulnerability in Tencent’s Sogou Input Method for Windows to achieve one‑click code execution. By crafting a malicious sogouinput:// link, the group triggered a use‑after‑free flaw in Chromium 80 (CVE‑2021‑38003), gaining arbitrary execution within the browser context. The exploit dropped GRAYRABBIT (grayrabbit.dll) into the user’s Startup folder and established persistence via a scheduled task and HKCU Run key, enabling command‑and‑control communication to hxxp://185.XX.XX.XX/gate.php for data exfiltration and remote command execution.
Dell CSM Authorization Module: Six Critical Flaws Enable Full Admin Compromise of Kubernetes Storage Infrastructure
Six critical vulnerabilities in the Dell Container Storage Modules (CSM) csm-authorization-storage gRPC service enable unauthenticated remote attackers to gain full administrative control over Kubernetes storage planes. The most severe flaw, CVE-2026-63688 (CVSS 10.0), permits unauthenticated remote code execution via crafted gRPC calls. Chained vulnerabilities allow for privilege escalation, storage class injection, and unauthorized snapshot access, impacting Dell CSI drivers in versions <1.8.0, 1.9.x<1.9.3, and 1.10.x<1.10.1. Successful exploitation allows adversaries to manipulate persistent volumes, exfiltrate data, or deploy ransomware across an estimated 2,000 exposed clusters globally.