Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Plugin4Shell: The Zero-Click Flaw That Broke Every Prominent AI Coding Agent at Once

The security promise was simple. A plugin marketplace reviews a piece of code, locks it to a specific, verified version, and every AI coding...

All the recent news you need to know

Microsoft Fixes Critical Azure AI Flaw Rated CVSS 10.0

 

Microsoft has patched a maximum-severity vulnerability in Azure AI Foundry that could allow unauthorized attackers to escalate their privileges over a network. Tracked as CVE-2026-85889, the flaw carries a CVSS score of 10.0, making it one of the most serious security issues affecting Microsoft’s cloud-based artificial intelligence services. The company said the vulnerability resulted from missing authentication for a critical function within Azure AI Foundry. There is currently no evidence that the flaw has been exploited in real-world attacks. 

Azure AI Foundry, also known as Microsoft Foundry, is an enterprise platform used to build, deploy and manage generative AI applications and autonomous agents. A successful exploit could have enabled an unauthorized attacker to gain elevated privileges, potentially increasing access to sensitive resources or administrative functions. Security researcher Rémy Marot, who uses the handle @R_Marot, discovered and reported the vulnerability to Microsoft. The company has already addressed the issue across its cloud infrastructure. 

Microsoft said customers do not need to take any action because the affected cloud services have been fully mitigated. Alongside CVE-2026-85889, the company also fixed several other critical cloud vulnerabilities. These include CVE-2026-85885, a command injection flaw in Microsoft 365 Copilot rated 9.9; CVE-2026-85878, an improper authorization issue in Azure Database for PostgreSQL rated 9.9; and CVE-2026-87701, an improper neutralization vulnerability in Azure Cosmos DB rated 9.6. 

The tech giant separately released updates for two Windows vulnerabilities. CVE-2026-62721 affects the Windows User-Mode Power Service and could allow an authorized local attacker to gain SYSTEM privileges. CVE-2026-85921 is a double-free vulnerability in Windows Secure Kernel Mode that could enable privilege escalation to Virtual Trust Level 1. Both vulnerabilities were fixed through an out-of-band update for Windows 11 version 26H1, distributed as cumulative update KB5129194 for arm64 and x64 systems. 

The latest fixes arrive shortly after Microsoft patched 974 vulnerabilities across its software portfolio. Two of those flaws, affecting Windows Advanced Local Procedure Call and the Windows Update Stack, were reportedly exploited in active attacks. Proofpoint and Volexity said the ALPC flaw was chained with two Google Chrome vulnerabilities to create the BlueMoon exploit kit, which multiple espionage-linked threat actors allegedly used to deliver malicious payloads. The developments highlight the growing security risks surrounding cloud platforms, enterprise AI tools and widely deployed operating systems.

WeaselBiscuit Stealer Found in 13 Malicious npm Packages


Researchers have discovered 13 npm packages carrying a previously undocumented JavaScript information stealer called WeaselBiscuit, introducing yet another malicious threat to the npm package ecosystem. In addition to linking the packages together via shared indicators, OpenSourceMalware found several similarities between BeaverTail and OtterCookie, two North Korean malware families. 


A number of packages are included, including @biz44/id10-client, @biz44/id12-client, @biz44/id44-client, @biz44/id79-client, @biz44/id95-client, @biz44/id99-client, @biz44/process-runtime-utils, @biz44/runtime-utils, @biz44/engin1, id79-client, process-lhpm, process-mite, and process-tailwind. Many were first observed between September 12 and September 16, 2026, with some versions still available on NPM at the time of analysis. 

In comparison to BeaverTail and OtterCookie, WeaselBiscuit appears much smaller. In addition to remote access and cryptocurrency theft functions, the malware focuses on profiling hosts and collecting data collected by Chrome extensions rather than carrying a broad range of remote access functions. Malware loaders are launched when a compromised package is imported, causing detached Node.js processes to begin execution.

After retrieving an encoded payload from an Npoint URL, the loader executes the decoded code directly in memory. Following execution, the malware obtains its command-and-control configuration from another Npoint endpoint before connecting to 103.170.217.184:8787. Among the data collected are hostnames, usernames, operating systems, CPUs, and memory, as well as local and public IP addresses. 

Chrome profiles are also searched for extension storage on Windows, Mac OS, and Linux platforms. Chrome's Local Extension Settings directory may contain information associated with browser extensions, including cryptocurrency wallet extensions, which makes this collection especially significant. 

Instead of relying on a specific list of wallet extensions, OpenSourceMalware reported the stealer uploads readable, non-empty files from these locations. C2 servers can also provide commands for monitoring the clipboard and logging Windows keystrokes. 

Despite these capabilities, the recovered malware does not include direct wallet draining functionality, browser password decryption, seed phrase searching, screenshots, or a remote shell access. Additionally, some BeaverTail and OtterCookie activities have a Python-based InvisibleFerret stage that is not present in any other activity. 

Possible Links to DPRK Malware

WeaselBiscuit has been compared to malware associated with the DPRK-linked Contagious Interview campaign, but the attribution has yet to be confirmed. OpenSourceMalware did not find conclusive evidence that the attack was originated by North Korea based on operational infrastructure, victimology, campaign metadata or other identifying materials. 

WeaselBiscuit employs the dead-drop technique of Npoint.io as a dead-drop service, a technique previously observed in Contagious Interview campaigns. Some of its technical indicators, however, overlap with earlier campaigns. Additionally, its code performs public IP and geolocation checks using IPify.org and IP-API.com, while parts of its command-and-control design are similar to OtterCookie's. 

Among the numeric identifiers found in the malware are 10, 12, 44, 79, 95, and 99. These identifiers are similar to campaign markers associated with PolinRider activity, however their exact purpose in WeaselBiscuit is unclear. In terms of capability, BeaverTail and OtterCookie are more closely related. 

Several features are retained in WhistlerBiscuit, including system profiling, Chrome extension data collection, clipboard monitoring, and keylogging, all of which are common to those malware families. However, several of their heavier features are removed, including remote access functions, wallet draining capabilities, screenshots, and secondary payload delivery. 

Researchers at Cisco Talos observed a similar overlap in October 2025, when they discovered that the node-nvm-ssh package contained characteristics related to both BeaverTail and OtterCookie. The findings suggest that code and techniques from these malware families have been found in a variety of combinations within npm-based malicious code. 

The WeaselBiscuit stealer should be viewed for the time being as a distinctive lightweight stealer with distinct technical similarities to DPRK-related tooling rather than a new DPRK malware family confirmed by the DPRK. For a more conclusive attribution, further evidence from infrastructure, campaigns, or code levels would be required.

With the discovery of WeaselBiscuit, security risks are highlighted within the npm ecosystem, particularly for developers utilizing third-party packages. In addition to the ability to collect Chrome extension data and similarity to BeaverTail and OtterCookie, it warrants continued investigation as researchers investigate its origins and wider activities.

RatHat Android Malware Uses AI to Control Infected Devices

 

A new Android backdoor called RatHat utilizes an AI-powered system to remotely navigate compromised devices, while also stealing sensitive information and using a variety of methods to maintain its presence. Researchers at Zimperium’s zLabs found indications that RatHat may be associated with threat actors based in China after they discovered Chinese language prompts within the malware’s AI subsystem. 

The malware is reported to be distributed through malicious advertising, SMS messages and phishing websites that promote APK downloads outside Google Play. RatHat takes advantage of Android’s Accessibility permissions to obtain extensive control over infected devices. This allows it to enable Developer Options and Wireless Debugging, granting it a local shell-level execution environment without the need for a separate computer. Researchers observed similarities with this technique that have been previously seen in the ToxicPanda and RedHook Android malware families. 

The malware utilizes Android Debug Bridge (ADB) access to install a Go-based agent called liblocal-service.so. The agent can execute commands with ADB shell privileges, bypassing battery restrictions and establishing persistence. It can also restore the malware in the case that the main component is removed or stopped. The relationship works in both directions, with the malware being able to restore the agent if the agent itself is deleted. 

RatHat also makes use of a second component, libmedia_codec.so, which acts as an FRP reverse-proxy client and establishes a persistent tunnel to the attackers. The malware has the ability to display HTML overlays over targeted banking and cryptocurrency applications in order to acquire the users’ credentials. Its information-stealing capabilities include SMS messages and notifications, including one-time passwords. RatHat can also monitor text changes, extract URLs from browser address bars and capture lock-screen PINs, passwords and unlock patterns. 

One of RatHat’s most interesting features is its AI-powered interface automation engine. According to Zimperium, the malware converts the Android Accessibility tree into XML and sends the resulting information to an unnamed popular AI assistant. This system can recognize the screen coordinates of requested interface elements and determine their displayed text and provide navigation commands such as scrolling instructions. This enables the malware to navigate Android interfaces more dynamically than other malware that exclusively rely on predetermined scripts. 

Zimperium stated that the AI-driven system makes the malware more adaptable and arguably harder for security software to detect. RatHat actively prevents victims from uninstalling the malware. When an uninstall confirmation screen appears, the malware can intercept the process and cancel the removal and display a fake Google Play overlay, which shows a fraudulent error message. The malware also contains a number of anti-analysis measures, including APK container manipulation, an unusually large 61MB Android manifest and invalid DEX pseudo-instructions that are designed to confuse or disrupt the functionality of security analysis tools. 

Android users are advised to avoid downloading APK files from outside Google Play unless the publisher is explicitly trusted and to be careful when granting Accessibility permissions to applications. In addition, users should regularly scan their devices using Google Play Protect.

Docker Fixes Critical Sandboxes Flaw That Could Expose Host Files

 




Docker has patched two vulnerabilities in Docker Sandboxes that could allow malicious code running inside an isolated sandbox to cross its intended workspace boundary and interact with resources on the host system.

The more severe issue, tracked as CVE-2026-77179, affects Docker Sandboxes versions 0.28.0 through versions before 0.42.0 on macOS and is rated Critical. Docker fixed the vulnerability in Sandboxes 0.42.0, released September 7. The company disclosed the security issues publicly on September 15.

Docker Sandboxes are designed to give AI coding agents their own microVM environment where they can execute code, install packages and use development tools without directly accessing the host. The security architecture treats the microVM as the primary trust boundary, with the agent receiving full control, including "sudo", inside that environment. Resources such as a developer's project directory are selectively exposed across the boundary.

The problem in CVE-2026-77179 occurs in the virtio-fs host server, which handles filesystem sharing between the macOS host and the sandbox. Docker said the component could follow a symbolic link when reopening an unlinked file through a previously stored pathname.

A malicious process inside the VM could exploit this behavior by changing a parent directory into a symbolic link after the original path had been accepted. When the host subsequently reused the stored path, the operation could be redirected to a different location outside the authorized workspace.

This creates a path traversal condition across the VM boundary. Docker said an attacker could consequently read or modify arbitrary host files available to the account running the virtual machine monitor. Depending on what files can be changed, the access could potentially be turned into host-side code execution.

The requirement for malicious code to already be executing inside the sandbox does not eliminate the security concern. Docker Sandboxes are intended to contain precisely the type of untrusted code that an autonomous coding agent might encounter through a compromised repository, malicious dependency, poisoned package or manipulated instruction. If that code can alter host-visible filesystem paths, the microVM's isolation boundary becomes vulnerable at the point where the host performs the subsequent filesystem operation.

The second vulnerability, CVE-2026-79994, affects versions 0.37.0 through versions before 0.42.0. Docker rates it High with a CVSS 4.0 score of 8.7.

This issue affects the guest-to-host relay used for Unix domain sockets. The relay initially verified that a requested socket was located inside an authorized workspace, but later established the connection by using the pathname again. A malicious guest could change an intermediate directory into a symlink during that interval, causing the host to connect to an AF_UNIX socket outside the permitted workspace.

The vulnerability is classified as a time-of-check to time-of-use (TOCTOU) race condition, because the security decision is made against a pathname whose meaning can change before the privileged operation occurs. The resulting connection could expose data or host-side capabilities provided by the targeted socket.

Together, the two flaws expose different host interfaces through a similar underlying weakness: trusting a pathname after an attacker-controlled environment has had an opportunity to alter what that pathname resolves to.

The risk is amplified by how Sandboxes share development workspaces. Docker says "sbx run" normally mounts the current directory into the sandbox with read-write access, meaning an agent can directly modify the developer's working tree. Docker also warns that files such as Git hooks, CI configuration, IDE task definitions and project scripts can affect subsequent host-side development activity.

For users unable to update immediately, Docker recommends clone mode and advises against additional read-write host mounts. Clone mode mounts the repository read-only at "/run/sandbox/source" while the agent works from a private clone inside the VM. However, it is not a confidentiality boundary: files available in the mounted repository, including untracked files such as ".env", may still be readable by the agent.

Docker has reported no exploitation of either vulnerability. Neither issue was listed in CISA's Known Exploited Vulnerabilities catalog at the time of disclosure.

The company credited Oren Yomtov of accomplish.ai with discovering CVE-2026-77179 and Jurre van Bergen of ThreatNotify with finding CVE-2026-79994.

The fixes arrived amid wider security scrutiny of AI coding environments. Earlier research from Cyera Research Labs demonstrated how a prompt-injected coding agent operating inside a Docker-based environment could be used as part of an attack chain against the host through a separate Docker Engine vulnerability. The latest disclosures reinforce the importance of treating autonomous coding agents as potentially hostile workloads, even when they are placed inside purpose-built isolation mechanisms.

Users running affected Sandboxes versions should upgrade to 0.42.0 or later. Docker Sandboxes 0.43.0, released September 15, is the latest stable release as of September 18.

FBI Seizes NightmareStresser DDoS-for-Hire Domains in Global Crackdown

 

The U.S. Department of Justice has announced the court-authorized seizure of internet domains linked to “NightmareStresser,” one of the world’s longest-running Distributed Denial of Service (DDoS) for-hire services. The operation, led by the FBI Anchorage Field Office with support from the Royal Canadian Mounted Police, targets so-called “booter” and “stresser” platforms that enable paying customers to launch powerful cyberattacks against individuals, organizations, and critical online infrastructure across Alaska and globally. 

According to the seizure warrant affidavit, NightmareStresser was used to carry out hundreds of thousands of actual or attempted DDoS attacks worldwide since 2022. These services lower the barrier to entry for cybercrime by allowing users with minimal technical expertise to disrupt internet connections, knock targeted devices offline (“booting”), and degrade or completely interrupt access to websites and online services. Victims have included schools, government agencies, gaming platforms, and millions of everyday users whose connectivity was affected by these coordinated attacks.

The takedown forms part of Operation PowerOFF, an ongoing international law enforcement initiative aimed at dismantling criminal DDoS-for-hire infrastructures and holding both administrators and users accountable. Over the past eight years, federal prosecutors and investigators in Anchorage and Los Angeles have charged twelve defendants involved in facilitating DDoS-for-hire services and seized more than 100 associated domains. This latest action expands on those efforts by targeting all known booter sites, shutting down as many as possible, and coupling enforcement with a public education campaign on the harms caused by illegal DDoS activity. 

Assistant U.S. Attorneys Adam Alexander and Ainsley McNerney are prosecuting the case in the District of Alaska. The Justice Department emphasizes that booter and stresser services not only harm direct targets but also undermine broader internet reliability and safety. As digital dependence grows, such crackdowns signal a sustained push to disrupt the ecosystem enabling low-cost, high-impact cyberattacks—and to deter would-be offenders by removing the domains and infrastructure these services rely on to operate.

Unbound 1.26.1 Patches Critical RCE, DoS, and DNSSEC Flaws

 

A major security update has been issued for Unbound, the widely used validating DNS resolver developed by NLnet Labs. On September 16, 2026, the project disclosed a batch of high-severity vulnerabilities affecting versions up to and including 1.26.0, with fixes released in version 1.26.1. These flaws range from heap buffer overflows and use-after-free bugs to DNSSEC validation bypasses, any of which could allow attackers to crash servers or, in some cases, achieve remote code execution. 

RCE and denial-of-service risks 

Among the most serious issues is a heap buffer overflow in Unbound’s DNSSEC validator that can be triggered by a malicious DNSKEY record containing a self-referential compression pointer. This bug, credited to researchers from Nankai University, can lead to denial of service and potential remote code execution because the digest buffer overflows when processing such crafted records. Two additional memory-corruption bugs were also reported: one in DNSSEC canonicalization that affects long query names over TCP, and another in CNAME synthesis that can progressively corrupt heap memory and, under specific conditions, allow code execution. All three vulnerabilities are fixed in the 1.26.1 release, and manual patches are available for administrators who cannot immediately upgrade. 

Unbound’s support for encrypted DNS transports is also affected. A use-after-free bug in the DNS-over-QUIC (DoQ) implementation can be triggered by a malicious client that sends a RESET_STREAM and withholds ACKs, eventually causing the server to exit abnormally after as few as 20 queries. Similarly, a use-after-free in the DNS-over-HTTPS (DoH) cleanup path can be exploited when RPZ drops queries or under heavy traffic, potentially leading to process termination on hardened allocators. In addition, a degradation-of-service flaw in TCP/DoT handling allows an attacker to monopolize a worker’s event loop by streaming distinct uncached queries over a single connection, with no limit on consecutive reads. Fixes for these issues adjust stream shutdown behavior, correct DoH mesh accounting, and introduce read limits similar to those already used for UDP. 

Beyond memory safety, several logic errors undermine Unbound’s security guarantees. A ZONEMD verification bypass creates a window where tampered zone data can be served or written to disk before integrity checks complete, affecting zones below a trust anchor. A cross-zone cache-poisoning bug allows a malicious actor controlling one delegated zone under an NSEC-signed parent to inject insecure wildcard DS records for unrelated sibling domains, effectively forging delegations. Another flaw lets the “serve-expired” feature bypass the wait-limit counter introduced for the DNSBomb mitigation (CVE-2024-33655), enabling pulsing DoS amplification attacks from a single IP. The “ReTrap” family of algorithmic-complexity attacks (TagTrap, DelegationTrap, NsecTrap, AdditionalTrap) can also degrade service by forcing excessive DNSSEC validation work; Unbound 1.26.1 adds throttles and disables validation of the additional section by default to mitigate this. 

Role of administrators 

All users running Unbound 1.26.0 or earlier are urged to upgrade to version 1.26.1 as soon as possible, especially on internet-facing resolvers or those handling DNSSEC-validated traffic. If immediate upgrade is not feasible, NLnet Labs provides individual patches for each CVE that can be applied manually to the source tree. Operators should also review configurations for features like DNS-over-QUIC, DNS-over-HTTPS, DNSCrypt, response-ip/RPZ, and serve-expired, since several vulnerabilities require these options to be enabled. Given Unbound’s role in the DNS infrastructure of countless networks, prompt patching is critical to prevent outages and exploitation in the wild.

Featured