Hackers abused Claude to extract secrets from 1.8M Android apps
2026-09-12T01:23:22Z•115793c19ee19a72c44e15af6c4f156d9fea73e6e746afc8792c17cab79ca3fa
CVE-2026-85706AI abuseAndroid malwareChinese threat actorsCisco FMCGitLabJFrog ArtifactoryMicrosoft 365PaperCutRussian threat actorsactive exploitationcredential theftdata breachphishingransomwarespywarestate-sponsored activitysupply chainvulnerability management
What happened
A BleepingComputer security-news feed covering active exploitation, phishing, data breaches, malware, ransomware, and abuse of AI platforms. Key risks include exploited JFrog Artifactory and Cisco FMC flaws, a maximum-severity GitLab path-traversal vulnerability (CVE-2026-85706), passkey-themed Microsoft 365 phishing, PaperCut exploitation affecting 395 organizations, Android ransomware/spyware, and breaches involving Florida DMV and Surfshark infrastructure.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 115793c19ee19a72c44e15af6c4f156d9fea73e6e746afc8792c17cab79ca3fa
- Enrichment time
- 2026-09-12T01:23:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.