New RatHat Android malware uses AI to automate device control

2026-09-18T07:23:21Z•1a4830b01941f1520b12f0760277f863bf878ef4fa77d9e634ccf4132d6a07ab
AI securityAndroid malwareCHOSEN BRICKCisco ISEClickFixCloudflare API key compromiseDDoS-for-hireKREMLIN malwareNightmareStresserRatHatSparroWockyWindows 11active exploitationcredential theftidentity securitymalicious browser extensionsransomwarestate-sponsored espionagesupply-chain attackzero-day

What happened

BleepingComputer feed covering current cybersecurity developments, including Android remote-access malware, AI agent misalignment, a Brevo supply-chain compromise distributing ClickFix scripts, state-linked espionage malware, malicious browser extensions, exploited Cisco ISE vulnerability activity, Windows authentication issues, and DDoS infrastructure seizure. The most urgent item is the actively exploited maximum-severity Cisco Identity Services Engine zero-day; other notable threats include RatHat Android malware, SparroWocky, CHOSEN BRICK, and KREMLIN browser-extension malware.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
1a4830b01941f1520b12f0760277f863bf878ef4fa77d9e634ccf4132d6a07ab
Enrichment time
2026-09-18T07:23:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · New RatHat Android malware uses AI to automate device control · Baitaphish