Researchers uncover malware that uses AI to choose its next move
2026-09-22T14:51:40Z•9678682026f2c805a4aedcc0edbf779042d1c0818f7c5825f6caa97436b6e986
CVE-2026-72735G securityAI-enabled malwareGoogle sign-inLAPSUS$Zyxel GS1900active exploitationbusiness email compromisedata exfiltrationdeepfakedomain hijackingfake base stationfraudulent AI subscriptionsnetwork switchesphishingsocial engineeringsubscriber tracking
What happened
Help Net Security reports multiple cybersecurity developments, including active exploitation of CVE-2026-7273 against nearly 1,000 Zyxel GS1900 switches across 48 countries, domain hijacking linked to a LAPSUS$-branded page, AI-enabled malware research, deepfake social-engineering incidents, fraudulent AI subscription sites using Google sign-in, and research into 5G subscriber tracking via fake base stations. The most urgent item is the widespread exploitation of the Zyxel vulnerability and associated data exfiltration.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 9678682026f2c805a4aedcc0edbf779042d1c0818f7c5825f6caa97436b6e986
- Enrichment time
- 2026-09-22T14:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.