Fire Ant China-Nexus Actor Deploys AI Workloads on Compromised Cisco and VMware Infrastructure
The China-nexus threat actor "Fire Ant" is executing a "compute hijacking" campaign by deploying AI/ML frameworks, such as PyTorch and TensorFlow, directly onto compromised victim infrastructure. By targeting VMware hypervisors, Cisco IOS XR routers, and Linux-based management hosts, the actor utilizes the victim's local computational resources to process AI workloads. This strategy bypasses traditional egress monitoring and Data Loss Prevention (DLP) solutions by eliminating the need to communicate with external AI service providers. The campaign facilitates deep lateral movement via compromised TACACS authentication servers and management planes, enabling high-stealth persistence and automated, AI-driven exploitation of core network layers.
Industrial-Scale Model Theft: NSA, CISA, and FBI Identify DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun, and Z.AI
The NSA, CISA, and FBI have issued a joint advisory identifying a coordinated, industrial-scale campaign by Chinese AI firms—specifically DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun, and Z.AI—to conduct large-scale model theft. The primary attack vector is knowledge distillation, where proprietary intelligence is systematically extracted from U.S. frontier LLMs via high-volume API exploitation. This process involves harvesting billions of tokens to train competitive models, such as Moonshot AI's Kimi-K2 and Kimi-K3, effectively bypassing the massive R&D and compute requirements of original model development.
Google Chrome Emergency Patch: CVE-2026-85046 Zero-Day in V8 Engine
Google has issued an emergency security update to address CVE-2026-85046, a critical type confusion vulnerability within the V8 JavaScript and WebAssembly engine. This zero-day flaw has been actively exploited in the wild by at least four China-linked cyber-espionage groups to facilitate remote code execution (RCE). By delivering malicious web-based payloads, attackers can bypass security boundaries to execute arbitrary code on the host system. Given the vulnerability's impact on approximately 3 billion Chrome installations, immediate remediation is essential. Organizations must deploy Chrome version 152.0.7977.82 or later to mitigate the risk of unauthorized system compromise and intelligence theft.
Microsoft Patch Tuesday: Record-Breaking Vulnerability Volume and Active Exploitation
The September 2026 Microsoft Patch Tuesday release addresses a historic 974 CVEs, including over 100 critical vulnerabilities. Of significant concern are two actively exploited zero-day vulnerabilities: CVE-2026-81963 (improper link resolution in the Windows Update Stack) and CVE-2026-85880 (Windows ALPC heap-based buffer overflow), both enabling elevation of privilege and sandbox escapes. Additionally, a CVSS 9.8 RCE in the Windows DNS Server presents a high risk of wormable, infrastructure-wide compromise, reminiscent of the SigRed vulnerability. With 723 vulnerabilities affecting the Windows core and high-severity RCEs in Remote Desktop Services, immediate remediation is critical to prevent lateral movement and widespread perimeter breach.
PEEP Post-Exploitation Toolkit Targets Google Chrome and Microsoft Edge
PEEP is a specialized post-exploitation toolkit targeting Chromium-based browsers, specifically Google Chrome and Microsoft Edge. Deployed as a secondary-stage payload following initial administrative compromise or arbitrary code execution (ACE), PEEP achieves persistence by injecting malicious extensions directly into browser profile directories. The toolkit bypasses Web Store validation and suppresses installation prompts by forging "Secure Preferences" integrity values. By leveraging the Native Messaging API, PEEP establishes a communication bridge between the browser environment and the host operating system, enabling arbitrary shell command execution, credential exfiltration, and session hijacking, effectively transforming the browser into a stealthy command-and-control node.
OpenAI ChatGPT Sandbox Flaw Enables Cross-Account Gmail Data Exfiltration
Researchers at Check Point discovered a critical sandbox escape vulnerability in OpenAI's ChatGPT execution environment that permits cross-account data exfiltration. By leveraging indirect prompt injection, an attacker can deploy malicious instructions that transform the LLM into a stealthy agent. This agent exploits a shared clipboard mechanism—acting as a hidden communication channel within the sandbox—to facilitate unauthorized data transfer. The vulnerability targets Gmail API integrations, allowing attackers to retrieve private email content and exfiltrate it to an attacker-controlled account. The risk is amplified by the "Deep Research" agent, which introduces a zero-click vector by autonomously triggering the exfiltration during standard, unprompted research operations.
Factoring Legacy RSA Public Keys of a 1990s Certificate Authority
Researcher M. Pherrin has successfully executed the factorization of the RSA public keys belonging to a legacy Certificate Authority (CA) operating in the 1990s. By utilizing the General Number Field Sieve (GNFS) algorithm—likely via the CADO-NFS implementation—the researcher recovered the private prime factors (p, q) from the CA's public modulus (n). This achievement demonstrates that legacy RSA bit-lengths, previously considered computationally secure, are now susceptible to modern distributed computing resources. The successful factorization highlights a critical risk in Public Key Infrastructure (PKI) environments where antiquated root certificates or legacy-supported domains may still reside in trust stores, potentially allowing for the unauthorized issuance of forged X.509 certificates.
Vietnam-linked Advance Passenger Information System APIS Database Exposure
An unprotected, internet-facing Advance Passenger Information System (APIS) database, reportedly managed by Vietnam-linked entities, has exposed approximately 220.8 million records. The breach encompasses highly sensitive datasets including full legal identities, passport numbers, flight itineraries, and crew records spanning from January 2017 to April 2026. The lack of access controls allowed unauthorized access to a centralized repository of international travel data. This exposure presents critical risks of large-scale identity theft, passport forgery, and targeted espionage via the physical tracking of high-value passengers and aviation personnel.
Critical Unauthenticated RCE "StyleSmuggler" in Adobe Commerce and Magento
Sansec has identified "StyleSmuggler," a critical zero-day vulnerability enabling unauthenticated remote code execution (RCE) within Adobe Commerce and Magento Open Source. Exploitation, detected in the wild on September 4, 2026, utilizes injection via CSS and style-related parameters to bypass existing security filters. Attackers leverage this vector to deploy sophisticated web shells and persistent backdoors capable of surviving subsequent security patches. This flaw grants complete server-level control, facilitating the theft of customer PII and payment data. Organizations must prioritize immediate file integrity monitoring and credential rotation to mitigate the risk of deep-seated persistence.
MikroTik RouterOS: Critical "MikroTrick" Authentication Bypass Exploitation
A critical exploit chain, dubbed "MikroTrick," targets MikroTik RouterOS by combining an SSH authentication bypass (CVE-2026-67276) with an unauthenticated file-read vulnerability via the WebFig interface (CVE-2026-67281). This chain allows remote attackers to achieve full administrative takeover of internet-exposed devices without possessing legitimate RSA private keys. Despite MikroTik attempting a "silent" security patch on September 3, 2026, intelligence from CERT Polska confirms active exploitation was detected as early as September 2, 2026. This 24-hour discrepancy indicates that threat actors successfully bypassed authentication and gained control of target infrastructure prior to the availability of any vendor mitigation.