DJBSEC's CyberNews 2026-08-25
Today’s daily news covers the following categories: Vulnerability Malware Threat Intelligence Privacy Nation-State/APT
Claude Mythos 5 Comes to Claude Security for Enterprise Vulnerability Scanning
Vulnerability
Anthropic has made Claude Mythos 5 available through Claude Security, giving enterprise customers access to its advanced cybersecurity model for AI-assisted vulnerability scanning. The public-beta service analyzes selected code repositories and produces findings organized by weakness type, severity, confidence level, and recommended remediation. Rather than providing unrestricted access to Mythos 5, Anthropic is placing the model behind controlled defensive workflows designed to reduce the risk that its capabilities could be repurposed for offensive operations. Proposed fixes are not automatically applied, leaving human reviewers responsible for approving remediation before changes are implemented. Anthropic is also launching a $35 million Defender Advantage Fund that will provide Claude credits for projects focused on open-source security and vulnerability remediation.
Trojanized npm Packages Deliver AI-Assisted RedC2 Linux Backdoor
Malware
Researchers discovered 14 trojanized npm packages masquerading as legitimate calendar and date utilities while secretly deploying a Linux backdoor associated with RedC2 4.0. The packages provide their advertised functionality, but importing one anywhere in a dependency chain can silently launch the bundled RedShell implant without requiring a traditional installation hook. Once active, the malware supports credential theft, persistence, network pivoting, file operations, shell access, browser and SSH-key harvesting, and additional in-memory payload execution. RedC2 also includes an LLM-powered component called Red Agent that translates natural-language instructions into post-exploitation commands for operators. Researchers warn that combining software supply-chain distribution with AI-assisted command and control could lower the expertise required to conduct complex intrusions.
Zombie Card Attack Revives Expired Visa Cards for Contactless Payments
Vulnerability
University of Massachusetts Amherst researchers demonstrated a weakness in Visa’s contactless payment implementation that can allow expired cards to successfully complete real-world purchases. The attack exploits the fact that the expiration date checked by a payment terminal is not cryptographically bound to the expiration information processed by the issuing bank. Using a man-in-the-middle position on NFC communications, researchers could replace the expiration date seen by the terminal with a future date while leaving the cryptographically protected transaction information intact. The researchers successfully demonstrated the technique at real merchants, showing that even physically damaged or discarded expired cards could potentially remain useful for fraudulent contactless transactions. The research highlights a weakness in Visa’s implementation of the EMV contactless payment process rather than a compromise of the card’s underlying cryptographic keys.
Attackers Exploit Critical MLflow Flaw to Reach Cloud Credentials
Vulnerability
Attackers are actively exploiting CVE-2026-64849, a critical vulnerability in the widely used MLflow machine-learning platform that carries a CVSS score of 9.3. The unauthenticated server-side request forgery flaw affects MLflow’s webhook system and can trick vulnerable servers into connecting to internal resources that should not normally be accessible from the internet. Attackers can exploit redirects to bypass existing SSRF protections and potentially query cloud metadata services, exposing credentials, secrets, and information from internal systems. Researchers observed widespread scanning for vulnerable MLflow servers within hours of the vulnerability becoming public, along with attempts to access internal services and cloud metadata endpoints. The vulnerability affects MLflow versions before 3.15.0, making rapid patching especially important for internet-accessible deployments.
Security Leaders Warn Defenders to Use AI Against Their Own Networks
Threat Intelligence
Cybersecurity leaders are warning organizations that they need to begin using AI agents to continuously test their own environments because adversaries are increasingly adopting the same technology. AI-powered offensive tools can autonomously search for vulnerabilities, identify exploit chains, map networks, locate sensitive information, and conduct personalized social-engineering attacks at speeds that traditional security teams may struggle to match. Former CISA official Matt Hartman also warns that organizations should treat internal AI agents as privileged identities because they increasingly have access to sensitive systems, applications, and data. One controlled exercise used thousands of autonomous agents to generate 17 million offensive actions over three days, uncovering 38 validated attack paths and 238 security findings. The growing capability of autonomous offensive AI is driving interest in continuous AI-powered red teaming, automated penetration testing, phishing-resistant authentication, and stronger zero-trust controls.
TikTok Agrees to $400 Million Child Privacy Settlement
Privacy
TikTok has agreed to pay $400 million to settle a U.S. government lawsuit accusing the social media platform of violating federal children’s privacy protections. The Justice Department and Federal Trade Commission alleged that TikTok knowingly allowed children under 13 to create accounts and unlawfully collected information from children using the platform’s Kids Mode. Regulators also accused TikTok and parent company ByteDance of failing to properly honor parents’ requests to delete children’s accounts and associated personal information. TikTok will pay $300 million immediately and another $100 million after a previous consent decree involving predecessor Musical.ly is vacated. The Justice Department described the agreement as one of the largest recoveries obtained under the Children’s Online Privacy Protection Act.
Critical GitLab GraphQL Flaw Under Active Exploitation
Vulnerability
GitLab is warning customers that attackers are actively exploiting CVE-2026-19478, a critical GraphQL vulnerability carrying a CVSS score of 9.4. Under certain conditions, an unauthenticated attacker can remotely modify or delete public projects and user data through a malicious GraphQL directive. GitLab released an emergency security update on August 17, five days after its regular update cycle, with the vulnerability affecting self-managed installations rather than the company’s hosted service. Customers running older 18.2 through 18.10 releases will need to move to a supported patched branch because fixes are not being provided directly for those versions. Administrators should urgently patch internet-facing GitLab servers and review logs for suspicious GraphQL requests that could indicate previous exploitation.
ToxicPanda 2.0 Expands Android Banking Attacks Across 16 Countries
Malware
The ToxicPanda Android banking trojan has received a major upgrade that expands its target list from 16 banking applications to 349 financial institutions across 16 countries. The malware disguises itself as a legitimate application, requests VPN permissions through a fake installation interface, and uses that access to interfere with Google Play Protect while installing its malicious payload. Once active, ToxicPanda abuses Android’s Accessibility Service to monitor the victim’s screen, interact with applications, and steal banking credentials through malicious overlays. The latest version also introduces a technique that automates activation of Android Wireless Debugging and extracts the pairing code, giving attackers deeper control over infected devices. With 167 remote commands now available, researchers say ToxicPanda 2.0 represents a substantial increase in both the malware’s geographic reach and its fraud capabilities.
Iran-Linked Hackers Shut Down UK Power Plant for Four Days
Nation-State/APT
Iran-linked hackers reportedly forced a British power plant offline for four days in what is believed to be the first successful cyberattack of its kind against UK energy infrastructure. The affected facility has not been publicly identified for security reasons, and while the plant was small enough that the shutdown did not disrupt the wider electricity supply, personnel required four days to restore operations. The incident occurred alongside attacks against wastewater infrastructure across 12 U.S. states that reportedly caused flooding, reduced water pressure, and boil-water advisories in some communities. U.S. government sources reportedly believe those attacks also originated from actors in Tehran, while the UK incident may have been intended to demonstrate Iran’s ability to access and disrupt Western critical infrastructure. The activity reinforces growing concerns about politically motivated cyberattacks against energy, water, and other operational technology environments.
Enjoy Reading This Article?
Here are some more articles you might like to read next: