Attacker Used AI to Build Custom PowerShell Recon Malware

2026-07-14T14:51:47Z8fe8bf778f57adda7386fffa2f09911823049f1132d9a98bf932452bf3e97a91
CVE-2008-4128active-directory-reconaes-encryptionai-generated-malwarecisacisco-ioscms-exploitationcrashstealercyber-sabotagedata-breachfsb-sanctionsgatekeeper-bypassjoomlaknown-exploited-vulnerabilitiesmacos-infostealernihon-kotsuodido-breachpowershellransomwareryuksharefilesupply-chain-riskthird-party-breachwebshellswordpress

What happened

Multiple active threats and incidents reported: Huntress discovered an AI-generated PowerShell reconnaissance script used to map Active Directory during a June 3, 2026 intrusion. Japan’s largest taxi operator Nihon Kotsu suffered a malware infection and service shutdown. A new macOS infostealer, CrashStealer, uses signed apps to bypass Gatekeeper, steals credentials and wallets, and AES-encrypts exfiltrated data. Lidl disclosed a third-party data breach affecting online-shop customers in Germany, Belgium and the Netherlands (payment data reportedly not exposed). CISA added Cisco IOS CVE-2008-4

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
8fe8bf778f57adda7386fffa2f09911823049f1132d9a98bf932452bf3e97a91
Enrichment time
2026-07-14T14:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.