profile

CyberSHIELD | CybersecurityOS 🛡️

This week in cybersecurity: the first autonomous AI malware, plus 3 zero-days to patch now


Hey — it's been a loaded week. Cisco Talos disclosed what looks like the first malware with genuinely autonomous command-and-control, three separate zero-days went from "actively exploited" to "patch now," and the courts caught up with a Ryuk operator and a soldier who extorted AT&T and Verizon. Here's what you need to know.

🚨 Critical Threats

CLOSEDQUORUM: The First Reported Autonomous AI C2 Implant

Abstract digital shield and circuit patterns representing an autonomous AI command-and-control implant

Cisco Talos' CAIRN project uncovered CLOSEDQUORUM, a malware binary that runs a fully autonomous C2 loop — executing parts of the attack chain without an operator steering it in real time. Expect this pattern to spread; "someone was at the keyboard" is no longer a safe assumption during triage. Read more →

Two Unpatched Citrix NetScaler RCE Zero-Days, Actively Exploited

Blue and gold digital shield over a network grid representing the Citrix NetScaler zero-day

watchTowr disclosed two RCE zero-days in Citrix NetScaler ADC/Gateway, already exploited in the wild with no patch yet from Citrix. If you run NetScaler, this is a today problem — monitor closely and be ready to take appliances offline. Read more →

F5 Patches Critical BIG-IP APM Zero-Day (CVE-2026-94127)

Blue and silver digital shield representing the F5 BIG-IP APM zero-day patch

Unauthenticated RCE against BIG-IP APM when it's acting as an OAuth authorization server — a direct line to every app trusting those tokens. F5 shipped hotfixes Sept 22; if APM is in your identity stack, patch now. Read more →

ShinyHunters' WAF Bypass Trick Against Oracle PeopleSoft

Digital shield and keys representing the ShinyHunters WAF bypass against Oracle PeopleSoft

A URL-encoding trick is letting ShinyHunters slip past WAF rules meant to block CVE-2026-35273 exploitation on PeopleSoft servers. Lesson: patch the CVE directly, don't lean on WAF coverage alone. Read more →

BragJack: Malicious Extensions Are Hijacking AI Browser Agents

Digital padlock and data waves representing malicious extensions hijacking AI browser agents

A single malicious extension can hijack AI browser assistants (Claude in Chrome, Edge, Opera Neon, Perplexity Comet) via a technique called Prompt Forcing — proven by researcher Gal Weizman, who earned $20K+ in bounties. Audit your extensions; the browser is now the AI agent's attack surface. Read more →

Chained Vulnerabilities in Claude Opus 5 Used to Access OpenAI Staff Accounts

Interlocking gears and padlocks representing chained vulnerabilities used to access OpenAI staff accounts

Hacktron researchers chained a help-forum bug with a login-system flaw — using Claude Opus 5 itself — to reach OpenAI staff accounts and an internal repo. A clean example of how "minor" bugs compose into something serious. Read more →

🛠️ Tools & Strategy

Vectra AI launches Ascent — an expanded partner program aimed at security teams navigating the AI-driven attack era. If you're job-hunting, note the pattern: vendors are explicitly hiring for "security + AI" skill combos. Read more →

Anthropic's Claude Opus 5.5 adds cybersecurity safeguards — new enhancements target threat detection and code analysis at scale. AI-assisted triage is quickly becoming table stakes in SOC tooling — worth hands-on time this week. Read more →

AI sandbox escapes: forensic readiness beats containment alone — Dark Reading argues that "AI escaping the sandbox" is usually the same old access-control failure in a new coat. Make sure you can reconstruct what an autonomous agent did, not just that it was boxed in. Read more →

Should you care about an "AI slowdown"? — Talos' Threat Source newsletter makes the case that patching, training, and monitoring still beat chasing the newest AI security tool. Fundamentals first, AI tooling on top — not instead. Read more →

📰 Industry News

U.S. soldier sentenced to 70 months for hacking telecoms and stealing metadata on 100M+ AT&T customers, plus ~$300K in restitution. Read more →

Ryuk ransomware member sentenced to 24 months plus 3 years supervised release for encrypting and extorting U.S. companies. Read more →

Data broker Radaris loses its domains after a New Jersey privacy-law suit and a judge who wasn't having the stonewalling. A sharp precedent for privacy enforcement with teeth. Read more →

~80,000 relay servers are masking Chinese access to frontier U.S. AI models — likely to clone them, researchers say. IP protection is becoming an AI-security problem, not just a policy one. Read more →

That's the week — autonomous malware, three zero-days, and two people who found out ransomware and extortion have a shelf life. Keep patching, keep questioning who (or what) is really on the other end of an intrusion, and we'll see you next Sunday. 🔐


Sponsored

Make — If you want to automate the boring parts of security work, Make is worth a look: CVE/GitHub watchers that tag by severity into a morning digest, or OSINT sweeps that auto-enrich IOCs against WHOIS/VirusTotal and post straight to Telegram, no scraper required. Transparency: this is an affiliate link — if you sign up, it may support CyberShield at no extra cost to you.

Canva — Turning a finding into something a stakeholder will actually read is its own skill. This shared Canva stack has ready-made threat-model canvases, ATT&CK/kill-chain diagrams, and SOC-style incident one-pagers for your briefs and portfolio pieces. Transparency: this is an affiliate link — if you sign up, it may support CyberShield at no extra cost to you.


Michael Tayo - CEO/Founder

P.S. Whenever you're ready, there are 4 ways we can help you:

  1. Expert Guidance: New to cybersecurity? Apply for mentorship
  2. Cybersecurity Career Quick Start: Advance towards a rewarding future with our exclusive guide.
  3. Digital Library: Access valuable cybersecurity resources.
  4. Stay Updated: Follow us on LinkedIn and X for news and tips.

SPONSOR THIS NEWSLETTER

CybersecurityOS is currently one of the world's fastest-growing newsletters, adding thousands of Cybersecurity enthusiasts a week to our incredible family of over 10,000! Our readers work at top companies like CDW, U.S. Bank, Tempus AI, HashiCorp, Kirkland & Ellis, and many more.

If you want to share your company or product with fellow cybersecurity enthusiasts before we're fully booked, contact us here

CyberSHIELD | CybersecurityOS 🛡️

Engineering security from first principles. I'm d0uble 3L, I write CybersecurityOS, where I break down secure-by-design architecture, DevSecOps, cloud security, and emerging-tech risk into practical frameworks for engineers, leaders, and teams. Weekly perspectives, clarity over complexity.

Share this page