Attacker Used AI to Build Custom PowerShell Recon Malware
2026-07-14T14:51:47Z•8fe8bf778f57adda7386fffa2f09911823049f1132d9a98bf932452bf3e97a91
CVE-2008-4128active-directory-reconaes-encryptionai-generated-malwarecisacisco-ioscms-exploitationcrashstealercyber-sabotagedata-breachfsb-sanctionsgatekeeper-bypassjoomlaknown-exploited-vulnerabilitiesmacos-infostealernihon-kotsuodido-breachpowershellransomwareryuksharefilesupply-chain-riskthird-party-breachwebshellswordpress
What happened
Multiple active threats and incidents reported: Huntress discovered an AI-generated PowerShell reconnaissance script used to map Active Directory during a June 3, 2026 intrusion. Japan’s largest taxi operator Nihon Kotsu suffered a malware infection and service shutdown. A new macOS infostealer, CrashStealer, uses signed apps to bypass Gatekeeper, steals credentials and wallets, and AES-encrypts exfiltrated data. Lidl disclosed a third-party data breach affecting online-shop customers in Germany, Belgium and the Netherlands (payment data reportedly not exposed). CISA added Cisco IOS CVE-2008-4
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 8fe8bf778f57adda7386fffa2f09911823049f1132d9a98bf932452bf3e97a91
- Enrichment time
- 2026-07-14T14:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.