Hackers abused Claude to extract secrets from 1.8M Android apps

2026-09-12T01:23:22Z115793c19ee19a72c44e15af6c4f156d9fea73e6e746afc8792c17cab79ca3fa
CVE-2026-85706AI abuseAndroid malwareChinese threat actorsCisco FMCGitLabJFrog ArtifactoryMicrosoft 365PaperCutRussian threat actorsactive exploitationcredential theftdata breachphishingransomwarespywarestate-sponsored activitysupply chainvulnerability management

What happened

A BleepingComputer security-news feed covering active exploitation, phishing, data breaches, malware, ransomware, and abuse of AI platforms. Key risks include exploited JFrog Artifactory and Cisco FMC flaws, a maximum-severity GitLab path-traversal vulnerability (CVE-2026-85706), passkey-themed Microsoft 365 phishing, PaperCut exploitation affecting 395 organizations, Android ransomware/spyware, and breaches involving Florida DMV and Surfshark infrastructure.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
115793c19ee19a72c44e15af6c4f156d9fea73e6e746afc8792c17cab79ca3fa
Enrichment time
2026-09-12T01:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Hackers abused Claude to extract secrets from 1.8M Android apps · Baitaphish