|
Hey — it's been a loaded week. Cisco Talos disclosed what looks like the first malware with genuinely autonomous command-and-control, three separate zero-days went from "actively exploited" to "patch now," and the courts caught up with a Ryuk operator and a soldier who extorted AT&T and Verizon. Here's what you need to know.
🚨 Critical Threats
CLOSEDQUORUM: The First Reported Autonomous AI C2 Implant
Cisco Talos' CAIRN project uncovered CLOSEDQUORUM, a malware binary that runs a fully autonomous C2 loop — executing parts of the attack chain without an operator steering it in real time. Expect this pattern to spread; "someone was at the keyboard" is no longer a safe assumption during triage. Read more →
Two Unpatched Citrix NetScaler RCE Zero-Days, Actively Exploited
watchTowr disclosed two RCE zero-days in Citrix NetScaler ADC/Gateway, already exploited in the wild with no patch yet from Citrix. If you run NetScaler, this is a today problem — monitor closely and be ready to take appliances offline. Read more →
F5 Patches Critical BIG-IP APM Zero-Day (CVE-2026-94127)
Unauthenticated RCE against BIG-IP APM when it's acting as an OAuth authorization server — a direct line to every app trusting those tokens. F5 shipped hotfixes Sept 22; if APM is in your identity stack, patch now. Read more →
ShinyHunters' WAF Bypass Trick Against Oracle PeopleSoft
A URL-encoding trick is letting ShinyHunters slip past WAF rules meant to block CVE-2026-35273 exploitation on PeopleSoft servers. Lesson: patch the CVE directly, don't lean on WAF coverage alone. Read more →
BragJack: Malicious Extensions Are Hijacking AI Browser Agents
A single malicious extension can hijack AI browser assistants (Claude in Chrome, Edge, Opera Neon, Perplexity Comet) via a technique called Prompt Forcing — proven by researcher Gal Weizman, who earned $20K+ in bounties. Audit your extensions; the browser is now the AI agent's attack surface. Read more →
Chained Vulnerabilities in Claude Opus 5 Used to Access OpenAI Staff Accounts
Hacktron researchers chained a help-forum bug with a login-system flaw — using Claude Opus 5 itself — to reach OpenAI staff accounts and an internal repo. A clean example of how "minor" bugs compose into something serious. Read more →
🛠️ Tools & Strategy
Vectra AI launches Ascent — an expanded partner program aimed at security teams navigating the AI-driven attack era. If you're job-hunting, note the pattern: vendors are explicitly hiring for "security + AI" skill combos. Read more →
Anthropic's Claude Opus 5.5 adds cybersecurity safeguards — new enhancements target threat detection and code analysis at scale. AI-assisted triage is quickly becoming table stakes in SOC tooling — worth hands-on time this week. Read more →
AI sandbox escapes: forensic readiness beats containment alone — Dark Reading argues that "AI escaping the sandbox" is usually the same old access-control failure in a new coat. Make sure you can reconstruct what an autonomous agent did, not just that it was boxed in. Read more →
Should you care about an "AI slowdown"? — Talos' Threat Source newsletter makes the case that patching, training, and monitoring still beat chasing the newest AI security tool. Fundamentals first, AI tooling on top — not instead. Read more →
📰 Industry News
U.S. soldier sentenced to 70 months for hacking telecoms and stealing metadata on 100M+ AT&T customers, plus ~$300K in restitution. Read more →
Ryuk ransomware member sentenced to 24 months plus 3 years supervised release for encrypting and extorting U.S. companies. Read more →
Data broker Radaris loses its domains after a New Jersey privacy-law suit and a judge who wasn't having the stonewalling. A sharp precedent for privacy enforcement with teeth. Read more →
~80,000 relay servers are masking Chinese access to frontier U.S. AI models — likely to clone them, researchers say. IP protection is becoming an AI-security problem, not just a policy one. Read more →
That's the week — autonomous malware, three zero-days, and two people who found out ransomware and extortion have a shelf life. Keep patching, keep questioning who (or what) is really on the other end of an intrusion, and we'll see you next Sunday. 🔐
Sponsored
Make — If you want to automate the boring parts of security work, Make is worth a look: CVE/GitHub watchers that tag by severity into a morning digest, or OSINT sweeps that auto-enrich IOCs against WHOIS/VirusTotal and post straight to Telegram, no scraper required. Transparency: this is an affiliate link — if you sign up, it may support CyberShield at no extra cost to you.
Canva — Turning a finding into something a stakeholder will actually read is its own skill. This shared Canva stack has ready-made threat-model canvases, ATT&CK/kill-chain diagrams, and SOC-style incident one-pagers for your briefs and portfolio pieces. Transparency: this is an affiliate link — if you sign up, it may support CyberShield at no extra cost to you.
Michael Tayo - CEO/Founder
P.S. Whenever you're ready, there are 4 ways we can help you:
-
Expert Guidance: New to cybersecurity? Apply for mentorship
-
Cybersecurity Career Quick Start: Advance towards a rewarding future with our exclusive guide.
-
Digital Library: Access valuable cybersecurity resources.
-
Stay Updated: Follow us on LinkedIn and X for news and tips.
SPONSOR THIS NEWSLETTER
CybersecurityOS is currently one of the world's fastest-growing newsletters, adding thousands of Cybersecurity enthusiasts a week to our incredible family of over 10,000! Our readers work at top companies like CDW, U.S. Bank, Tempus AI, HashiCorp, Kirkland & Ellis, and many more.
If you want to share your company or product with fellow cybersecurity enthusiasts before we're fully booked, contact us here
|