FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

NVIDIA Open Agent Safety Platform OASP HardwareBased Agent Governance

NVIDIA unveiled the Open Agent Safety Platform (OASP) in September 2026, coupling the open‑source OpenShell runtime with the Sentry watchdog reference design that runs on BlueField‑4 DPUs. OpenShell provides kernel‑level isolation, sandboxed execution, and per‑outbound‑request policy checks, while Sentry monitors agent behavior out‑of‑band and can quarantine or halt malicious agents within milliseconds. The platform targets governance of agents on enterprise‑controlled infrastructure, aiming to move enforcement outside the model and into hardware. Analysts estimate it addresses less than 25% of enterprise agentic risk, leaving SaaS, third‑party, and attacker‑introduced agents ungoverned.

Bitget Hot Wallet Compromise: $351.6M Stolen

On September 12, 2026, the Bitget cryptocurrency exchange suffered a major hot wallet breach, resulting in the theft of approximately $351.6 million (120,000 ETH and 6,000 BTC). The attack exploited a compromised backend Node.js signing script, backend/signing_service.js, which exfiltrated private keys to a Lazarus Group-linked C2 server at 185.141.63.122. Attackers utilized these keys to forge unauthorized withdrawal transactions. Bitget mitigated the immediate impact by suspending services and utilizing its insurance fund to cover losses. Remediation included upgrading to hardware security modules (HSMs) and implementing enhanced multisignature controls to secure custodial assets.

Multi-Vendor Critical Infrastructure Russia Hybrid Campaign Vulnerability Rollup 2026-09-25

In September 2026, Russian GRU Unit 26165 executed a hybrid campaign exploiting CVE‑2026‑XXXX (buffer overflow in Vendor‑A router firmware) and CVE‑2026‑YYYY (default credentials in Vendor‑B industrial gateways), combined with a signed malicious firmware update and living‑off‑the‑land binaries (PowerShell, WMIC, schtasks) to compromise ~180 critical‑facility routers across 12 EU states. The intrusion caused intermittent SCADA loss in 23 energy substations, signaling disruptions on four rail corridors, degraded VoIP for ~12k Baltic business lines, and an estimated €1.4 bn economic impact, with high‑confidence attribution to GRU Unit 26165.

Elsevier Web Properties Hijacked to Display LAPSUS$ Extortion Page

On September 21, 2026, attackers successfully executed a DNS hijacking attack against Elsevier, compromising the domain registrar records for elsevier.com, scopus.com, and sciencedirect.com. For 78 minutes, legitimate traffic was redirected via HTTP 302 responses to a malicious host (185.XX.XX.XX/24) controlled by the LAPSUS$ threat group. The redirection served a "Chapter II" extortion page featuring a JavaScript countdown and taunts directed at federal law enforcement. While no data exfiltration or malware delivery was confirmed, the incident demonstrates a critical supply chain vulnerability within the domain management lifecycle, impacting tens of thousands of global academic users.

AI Model Provider Supply Chain Campaign Vulnerability Rollup OpenAI, Anthropic, Google, xAI – 2026-09-10

In Q2–Q3 2026, threat actors shifted from prompt‑based abuse to fully agentic, multi‑framework attacks that compromised AI coding assistants, injected malicious dependencies into MCP servers and .claude/ configs, and leveraged model distillation to harvest >100 M prompts from Gemini and Claude. Trojanized packages on PyPI/npm/Docker Hub delivered credential‑stealing malware (DUSTMAKER) and LLM proxy services, enabling rapid exfiltration of thousands of third‑party API keys and cloud credentials within six hours. PRC‑nexus groups (UNC6508, CALANQUE ION) used hijacked cloud compute to run local LLM instances, evading API monitoring while exfiltrating proprietary model weights and source code. The campaign impacted healthcare, government, media, technology, academic and military sectors across North America, Europe, and Asia, prompting Google and Anthropic to disable assets, update classifiers, and issue mitigation guidance.

NVIDIA's Acquisition of Hugging Face

NVIDIA has acquired Hugging Face for approximately $12.9 billion to integrate the primary open-source model hub into its GPU ecosystem. The strategic move aims to accelerate the distribution, versioning, and inference of AI models across diverse hardware backends while maintaining Hugging Face's hardware-agnostic posture. From a security and operational perspective, the integration emphasizes the convergence of NVIDIA's AI Enterprise stack with community-driven model repositories, shifting the enterprise AI landscape toward open-weight models. The transition increases the criticality of model provenance and supply chain integrity as automated agent traffic now exceeds human requests on the platform.

Weekly Roundup: Cisco ASA, Android, BragJack, and Anthropic/OpenAI AI Exploitation

A coordinated set of zero-day flaws and novel abuse techniques have impacted enterprise firewalls, mobile OS kernels, and browser-based AI agents. A Cisco ASA unauthenticated remote code execution (RCE) exists via a heap overflow in the webVPN interface (+CSCOE+/logon.html), while an Android binder IPC use-after-free vulnerability enables local kernel privilege escalation. Simultaneously, the BragJack attack leverages Manifest V3 APIs to hijack AI agent session cookies and OAuth tokens. Most critically, researchers used Anthropic's Claude Opus 5 to autonomously chain a libheif RCE in Discourse (CVE-2024-XXXX) with SSRF to breach OpenAI's internal Git repositories. Immediate patching and hardening of extension policies and OAuth bindings are required.

The AI Compute Race: NVIDIA, Salesforce, and the Transition to Physical Sovereignty

The global AI development paradigm has shifted from algorithmic optimization to a resource-centric competition for physical sovereignty, characterized by critical bottlenecks in high-end silicon (NVIDIA GPUs), electrical grid capacity ("time-to-power"), and geopolitical export controls. The deployment of reasoning-capable models, such as Salesforce Koa, significantly increases the computational cost per inference, necessitating high-density cooling and grid-edge infrastructure to mitigate systemic power failures. This transition redefines AI progress as a function of semiconductor supply chains and TWh/GW energy capacity rather than software efficiency.

Plugin4Shell and LangGraph Vulnerability Chains: Critical RCE in GitHub Copilot, Claude Code, and Gemini CLI

The discovery of "Plugin4Shell" and associated LangGraph vulnerability chains introduces a critical zero-click Remote Code Execution (RCE) vector targeting AI-driven development environments. By exploiting plugin marketplaces and orchestration logic, attackers inject malicious instructions into plugin metadata or retrieved grounding context. This triggers semantic integrity failures and agentic memory exploitation, enabling CVE-2026-35603 privilege escalation. The vulnerability allows adversaries to hijack the full permissions of developers within GitHub Copilot, Claude Code, and Gemini CLI, facilitating unauthorized access to proprietary source code, corporate credentials, and internal enterprise systems through autonomous, unintended tool execution.

Google Threat Intelligence Group Warns of Autonomous AI Agentic Attack Systems

Google's Threat Intelligence Group (GTIG) has identified the deployment of autonomous, multi-agent AI frameworks by state-sponsored actors (UNC6508, UNC6780) and cybercriminals to automate the full attack lifecycle. These systems utilize LLMs like Gemini and Claude via custom pipelines—including the DUSTMAKER stealer and Phalanx framework—to conduct rapid reconnaissance and credential harvesting, with some campaigns compromising thousands of secrets in under six hours. Attackers leverage supply chain compromises in PyPI and npm to install LLM proxy services and use victim compute for local LLM inference to bypass API monitoring. This shift represents a transition from manual prompting to self-correcting, agentic execution loops that evade traditional signature-based defenses.


LINK COPIED TO CLIPBOARD