The Signal
The highest-priority items call for separate response tracks: public-facing software and identity paths, edge-delivery integrity, recruitment-led targeting, and mobile accessibility abuse present different security boundaries. Treating initial access as the whole problem would miss the downstream exposure described across these cases. [1][2][3][4]
Must Know
AI & Agents · Securityaffairs
What happened
Attackers used a compromised, long-lived Cloudflare API key with full permissions to deploy a malicious Worker and alter Brevo-served scripts on customer websites. [2]
The edge-delivered malware reached visitors of Brevo’s site and sites using its services; Sansec estimated that more than 100,000 sites may have been affected. [2]
Why it matters
Because the Worker rewrote responses at the CDN edge and removed security headers while leaving origin files unchanged, origin hashes and standard integrity checks did not detect the modification. [2]
AI & Agents · Cyberscoop
What happened
U.S. and allied agencies warned that the North Korean group WaterPlum, also called Contagious Interview, poses as prospective employers to target software developers and IT professionals worldwide. [3]
The actors impersonate AI, cryptocurrency, and NFT companies, use recruiting services, and in some cases operate as North Korean IT workers performing web-system design and development for clients. [3]
Why it matters
The alert says WaterPlum infected more than 30,000 devices in over 100 countries and transferred nearly $11 million in cryptocurrency from more than 7,000 wallets to North Korea. [3]
AI & Agents · Securityaffairs
What happened
Researchers exploited a heap buffer overflow in libheif processing of HEIC/HEIF uploads on a Discourse forum, then used the compromised OpenAI SSO path to hijack staff ChatGPT and Codex accounts. [1]
The attack did not use phishing or a leaked password; it began through an image upload, and the reported sequence from finding the bug to accessing an internal OpenAI repository took less than 72 hours. [1]
Why it matters
The researchers confirmed local code execution and later obtained root-level access on a cloud instance; in OpenAI’s environment, they demonstrated account takeover by opening a single harmless pull request, without reading source code or merging changes. [1]
AI & Agents · Malwarebytes Labs
What happened
Zimperium zLabs analyzed RatHat, an Android Trojan using a multi-stage infection process and a live AI assistant that navigates the accessibility tree instead of following a hardcoded script. [4]
The reported infection chain uses smishing or malicious ads to deliver fake download pages, persuades victims to sideload an APK, and pressures them to enable Android Accessibility Service. [4]
Why it matters
The source says RatHat’s variable attack path makes detection harder for signature- and rule-based mobile security tools, while its self-pairing repurposes a legitimate Android debugging feature for escalation. [4]
Also Worth Knowing
Cloud · Cyberscoop
What happened
Ahmed Hossam Eldin Elbadawy pleaded guilty to wire fraud conspiracy and aggravated identity theft in connection with a Scattered Spider-linked extortion operation active from at least 2021 to 2023. [5]
AI & Agents · Securityaffairs
What happened
Helpfeel said attackers exploited a vulnerability in Gyazo’s image-upload server, ran malicious commands, and accessed a database containing approximately 23.6 million user records. [6]
Exploitation · The Hacker News
What happened
Fortinet reports that CVE-2026-58138, a critical unauthenticated remote-code-execution vulnerability affecting Orkes Conductor, is being actively exploited in the wild. [7]