DJBSEC's CyberNews 2026-08-26
Today’s daily news covers the following categories: Vulnerability Malware Threat Intelligence Privacy Nation-State/APT
Claude Mythos 5 Comes to Claude Security for Enterprise Vulnerability Scanning
Vulnerability
Anthropic has made Claude Mythos 5 available through Claude Security, giving enterprise customers access to its advanced cybersecurity model for AI-assisted vulnerability scanning. The public-beta service can scan selected code repositories and return findings classified by weakness type, severity, confidence level, and suggested remediation. Anthropic is keeping direct access to the powerful model constrained behind purpose-built safeguards, while findings and proposed fixes remain subject to human review before implementation. The capability is available to Claude Enterprise customers and is billed through standard token usage rather than as a separate add-on. The approach reflects a broader push to give defenders access to advanced AI vulnerability-discovery capabilities while limiting opportunities for offensive misuse.
Trojanized npm Packages Deliver AI-Assisted RedC2 Linux Backdoor
Malware
Researchers discovered 14 trojanized npm packages masquerading as legitimate calendar and productivity utilities while secretly deploying an AI-assisted Linux implant called RedC2 4.0. Unlike malware that relies on installation scripts, the malicious packages can execute the bundled payload when the module is simply imported anywhere in a dependency graph, including as a transitive dependency. Once active, RedC2 provides extensive post-exploitation capabilities, including credential theft, persistence, network pivoting, file operations, browser and SSH-key harvesting, and remote shell access. The framework also incorporates an AI component that can translate natural-language instructions into commands for operators, potentially making complex post-exploitation activity easier to conduct. The campaign demonstrates how software supply-chain attacks and AI-assisted offensive tooling are increasingly converging.
Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
Vulnerability
University of Massachusetts Amherst researchers demonstrated an attack that can allow expired Visa cards to successfully complete contactless purchases under certain conditions. The technique exploits differences between how payment terminals and issuing banks validate expiration information, allowing an attacker positioned between a card and terminal to alter the expiration date presented during the transaction. Researchers demonstrated the technique against real payment systems without needing to compromise the card’s underlying cryptographic keys. The findings suggest that even expired or discarded cards could potentially retain value for attackers if enough of the physical card remains usable. The research highlights how subtle inconsistencies in payment-protocol implementations can undermine protections that consumers and merchants assume are enforced throughout a transaction.
Attackers Exploit Critical MLflow Flaw to Reach Internal Cloud Resources
Vulnerability
Attackers are actively exploiting CVE-2026-64849, a critical vulnerability affecting the widely deployed MLflow machine-learning platform. The unauthenticated server-side request forgery flaw affects MLflow’s webhook functionality and can allow attackers to force vulnerable servers to connect to otherwise inaccessible internal resources. This could include cloud metadata services containing temporary credentials, secrets, or other sensitive infrastructure information. Researchers observed scanning and exploitation activity shortly after details of the vulnerability became public, demonstrating how quickly flaws in popular AI infrastructure are being weaponized. Organizations running vulnerable MLflow deployments should update to a fixed release and investigate exposed instances for evidence of attempts to access internal or cloud metadata endpoints.
Security Leaders Warn Defenders to Use AI Against Their Own Networks
Threat Intelligence
Cybersecurity leaders are warning that organizations should begin using AI-powered offensive testing against their own infrastructure because adversaries are increasingly adopting similar capabilities. Autonomous systems can accelerate vulnerability discovery, network reconnaissance, exploit-chain development, and identification of sensitive data at a scale difficult for traditional security teams to replicate manually. The growing use of AI agents also creates a defensive challenge because those agents themselves can possess powerful credentials and access to sensitive enterprise systems. Security teams are increasingly exploring continuous AI-powered red teaming and automated penetration testing as ways to discover attack paths before adversaries do. The broader message is that AI is changing both sides of cybersecurity, forcing defenders to adopt automation without losing oversight of the new risks that automation creates.
TikTok Agrees to $400 Million U.S. Child Privacy Settlement
Privacy
TikTok has agreed to pay $400 million to settle a U.S. government lawsuit accusing the social media platform of violating federal children’s privacy protections. The Justice Department and Federal Trade Commission alleged that TikTok knowingly allowed children under 13 to create accounts and collected personal information from young users without obtaining required parental consent. Regulators also accused TikTok and parent company ByteDance of failing to properly honor requests from parents to delete children’s accounts and associated information. Under the settlement, TikTok will initially pay $300 million, followed by another $100 million once a previous consent decree involving predecessor Musical.ly is vacated. The case represents another major regulatory action over how technology platforms collect, retain, and protect children’s personal information.
Critical GitLab GraphQL Flaw Under Active Exploitation
Vulnerability
GitLab is warning customers about active exploitation of CVE-2026-19478, a critical GraphQL vulnerability carrying a CVSS severity score of 9.4. Under certain conditions, the flaw can allow an unauthenticated remote attacker to modify or delete public projects and user data through malicious GraphQL requests. GitLab released an emergency security update outside its normal patching schedule after learning of exploitation activity affecting self-managed installations. Customers operating older releases may need to upgrade to a supported patched branch rather than simply applying an incremental update to their existing version. Administrators should prioritize internet-facing GitLab servers and examine logs for suspicious GraphQL activity that could indicate exploitation occurred before patching.
ToxicPanda 2.0 Expands Android Banking Attacks Across 16 Countries
Malware
The ToxicPanda Android banking trojan has received a major upgrade that significantly expands both its target list and remote-control capabilities. The new version targets hundreds of financial institutions across 16 countries and uses deceptive installation techniques before abusing Android’s Accessibility Service to monitor and manipulate infected devices. Attackers can use malicious overlays to steal banking credentials while remotely interacting with applications and monitoring information displayed on the victim’s screen. ToxicPanda 2.0 also introduces techniques involving Android Wireless Debugging, potentially giving attackers deeper control over compromised devices. The expanded command set and geographic reach show the malware evolving from a relatively focused banking threat into a more capable mobile fraud platform.
Iran-Linked Hackers Reportedly Shut Down UK Power Plant for Four Days
Nation-State/APT
Iran-linked hackers reportedly forced a British power plant offline for four days in a significant cyber incident involving operational technology infrastructure. The affected facility has not been publicly identified, and its relatively small size meant the shutdown did not cause a wider interruption to the UK’s electricity supply. The incident reportedly occurred alongside cyberattacks targeting wastewater infrastructure across multiple U.S. states, raising concerns about coordinated Iranian activity against Western critical infrastructure. The operations demonstrate how cyberattacks against industrial environments can move beyond espionage or data theft and produce direct physical and operational consequences. The incidents add to concerns that energy, water, and other critical infrastructure will increasingly become targets during periods of geopolitical tension.
Enjoy Reading This Article?
Here are some more articles you might like to read next: