Summaries
Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.
Showing 1-6 of 6 results
| Date | Provider | Score | Summary |
|---|---|---|---|
| 30 Sep 2026, 11:00 PM | The Hacker News | 7.5 | Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Huntress observed a late-September 2026 campaign where attackers published two Custom GPTs on chatgpt.com (both named "Plus 5.6") and promoted them through Google sponsored results for searches like "chatgpt." When a victim prompts the GPT, it replies with a Google Sites link that shows a fake Cloudflare CAPTCHA, triggering a ClickFix attack that tells the user to copy and run a PowerShell command, which drops an MSI installer ("ISOSimple.msi") that chains DLL sideloading, shellcode, a persistence script, and a RAT payload. Huntress says no fewer than 40 users were infected, and notes earlier campaigns abused shared ChatGPT conversations and malicious Claude Artifacts the same way. Why: The delivery channel is a legitimate chatgpt.com URL plus a sponsored ad, so URL-reputation checks and 'is this really OpenAI's domain' instincts both fail. If you or your users install Custom GPTs found via search ads, treat any reply that hands you a backup-domain link or a PowerShell command to paste as the payload, not support — and note the same pattern has already been run through shared ChatGPT conversations and Claude Artifacts, so it isn't specific to one vendor's feature. |
| 01 Oct 2026, 10:37 PM | The Hacker News | 6.0 | WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
Sucuri researchers documented a WordPress compromise, codenamed SC after "SC_" markers in injected content, that maintains at least eight simultaneous persistence points across files, the database, and System V shared memory. Named components include .user.ini setting auto_prepend_file, loaders at wp-content/c1b12371.php and its dot-prefixed twin .c1b12371.php, db.php carrying a Base64-encoded compressed payload, advanced-cache.php rebuilding the plugin from five sources, and a theme copy at wp-content/themes/khorshidi/functions.php. Researcher Gabriel Barbosa describes it as a "self-healing mesh" in which each location can rebuild the others; the code uses no readable function names and is scrambled with a substitution cipher, and Sucuri says it is blockchain-controlled. The excerpt does not state affected WordPress versions, an entry vector, or a CVE. Why: If you run or host WordPress sites for clients — common for Malaysian agencies and SME brochure/e-commerce sites — your standard cleanup of deleting the malicious plugin or theme file is insufficient here: db.php, advanced-cache.php, .user.ini, and a shared-memory segment each restore the rest, so remediation has to cover database options, drop-ins, mu-plugins, and shared memory, or you reimage the host. Note the excerpt gives no affected versions, entry vector, or CVE, so you cannot yet say which sites are at risk from this text alone — treat any "cleaned" WP site as potentially reinfected until you check all eight locations. |
| 29 Sep 2026, 1:38 AM | The Hacker News | 6.0 | RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
Cleafy traced nearly 100 deployments since April 2026 of the RatHat Android banking-trojan console, run as malware-as-a-service where each customer operates a separate copy. The latest console versions — following an earlier one called Fisher and newer builds named BlackCat Remote Control Management and Panda Workshop V5/V6 — feed captured text messages and credentials from fake banking-app overlays to Google's Gemini to estimate each victim's bank balance and sort phones into high-value and mid-value groups; Cleafy found no use of the model to move money, only to decide 'which victims are worth an operator's time.' The console doubles as a build tool: it signs the malicious app, publishes it to Amazon S3 or a web server, and can rebuild it hourly to change the file hash, while the on-device malware abuses Accessibility access to enable wireless debugging, read the ADB pairing code off the screen, and open a shell through Android Debug Bridge. Why: Two concrete things to act on. First, the on-device chain is Accessibility access → enable wireless debugging → read the pairing code → ADB shell, so if you ship an Android app, that sequence — not generic 'mobile malware' — is what you should test against and consider detecting. Second, hourly rebuilds from the same malware source mean any pipeline relying on file-hash matching to spot known bad apps will miss these; if you use hash-based scanning for sideloaded builds, that gap is now demonstrated at ~100 console deployments. For anyone adding an LLM to a product, the Gemini use here is purely ranking/triage with no write access, which is the low-risk adoption pattern. |
| 02 Oct 2026, 12:45 AM | The Hacker News | 5.5 | ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
This ThreatsDay roundup argues the week's attacks came from ordinary-looking operations that do more than expected: a model inspection step that can execute code, a cache that can mix up requests, and public secrets that stay usable for years. The concrete items given are OFAC sanctioning 10 targets tied to a Tren de Aragua ATM jackpotting scheme using Ploutus malware, with $40.73 million in reported losses across more than 1,500 U.S. attacks, and roughly $6.1 million in inflows to seven designated crypto wallets since March 2022. It also notes EtherHiding, where actors hide malware instructions on public blockchains so they cannot easily be seized or taken down, plus a claim of 543K live secrets and a model-inspection RCE that the excerpt does not name or detail. Why: Two of the listed items sit directly in AI and dev workflows: 'a model check can run code' means loading or inspecting third-party model artifacts is a code-execution decision, not a read-only one, and 543K live secrets implies leaked keys stay valid long after the leak. The excerpt does not name the affected tool, CVE, or vendor, so you cannot patch from this alone - treat it as a prompt to check whether your model-loading path uses safe formats and whether your own repos are still leaking usable credentials. The ATM jackpotting and sanctions items have no practical bearing on most builders in this audience. |
| 29 Sep 2026, 2:35 AM | The Hacker News | 4.5 | Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
Microsoft published a technical analysis of NeedyMantis, a malware family used to keep long-term access in networks that were already breached, seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors, with use dating back to at least October 2025. Microsoft found it while following indicators from Kaspersky's investigation into the DAEMON Tools supply chain attack, where signed DAEMON Tools Lite installers carried malicious code from April 8, 2026 until the developer replaced them with a clean version on May 5; Microsoft tracks that activity as Storm-3069. NeedyMantis arrives via DLL sideloading — a legitimate program plus a malicious DLL named after a file that program loads, plus an encrypted archive of the same name — using hosts including Poedit, curl, Vim, and TightVNC, and posing as DLLs from Microsoft Office, Broadcom, Intel, and NVIDIA, then connecting to C2 over HTTPS and switching to WebSocket. Why: If you ship or depend on signed Windows desktop installers, the concrete lesson is the April 8 to May 5, 2026 DAEMON Tools Lite window and the sideloading pattern: a trusted exe (Poedit, curl, Vim, TightVNC) sitting next to a same-named malicious DLL. Microsoft published file hashes, domains, file paths, and hunting queries, so the actionable step is to run those indicators rather than assume your EDR caught it — and to stop placing third-party binaries in writable directories beside signed executables you ship. |
| 30 Sep 2026, 1:20 AM | The Hacker News | 4.0 | Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
Microsoft says Russia's Star Blizzard ran at least 13 larger phishing campaigns since January against 100+ organizations tied to Ukraine, mostly in the U.S. and U.K., with at least one machine confirmed infected. The lures impersonate think tanks and NGOs such as Chatham House and the Atlantic Council, and the first email carries no attachment: only if the target replies does the group send a password-protected RAR or ZIP with the password shown in an image. Delivery this year uses a method Microsoft calls RedFlick, which abuses Windows scheduled tasks to install a backdoor named CosmicPulse, replacing 2025's ClickFix fake-CAPTCHA approach, and since March the emails have come from compromised WordPress and cPanel site accounts instead of free services like Proton. Why: The reply-gated, password-in-an-image archive is a concrete gap: nothing malicious arrives in the first message, so attachment sandboxing and link scanners see a clean email. If your team's playbook says 'no attachment, no risk,' it needs a rule about replying to unexpected event or conference invitations. The WordPress/cPanel detail also matters locally — if you or a client run mail on shared cPanel hosting, a compromised mailbox there can be repurposed to send these lures, so check outbound mail logs and scheduled tasks, not just inbound filters. |