AI Attack Surfaces and Supply Chain Threats Define the Week

Weekly summary of Cybersecurity Insider newsletters

Sep 4, 2026
9 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

This week’s cybersecurity landscape was shaped by attacks on AI infrastructure, software supply chains, edge devices, and authenticated browser sessions. Defenders also faced actively exploited enterprise flaws, sophisticated malware evasion, large data breaches, and expanding foreign espionage operations. At the same time, international disruptions, arrests, and new defensive programs demonstrated a more coordinated response to persistent cyber threats.

Major Threats & Vulnerabilities

Critical Enterprise and AI Infrastructure Flaws

PaperCut pre-authentication RCE: A PaperCut remote code execution flaw is being exploited in the wild, with Huntress observing attacks against two customers. PaperCut considers all NG and MF versions potentially affected. Organizations should update PaperCut immediately, remove public access, preserve relevant logs, and investigate previously exposed servers for evidence of compromise.

ServiceNow AI Platform vulnerabilities: ServiceNow patched three critical AI Platform flaws that unauthenticated attackers could exploit without user interaction. Successful attacks could enable code execution, privilege escalation, or unauthorized access to and modification of data. Self-hosted customers should apply the patches and inspect their instances for anomalous administrative activity.

NVIDIA NemoClaw inference-layer vulnerability: NVIDIA fixed CVE-2026-65105 in NemoClaw, a flaw through which a malicious website could reach a local Ollama server and persistently alter the model used by an AI agent. This technique could bypass agent sandbox protections by targeting the inference layer rather than the agent itself. Teams should apply NVIDIA’s fix and treat local inference servers as privileged infrastructure.

Advertisement

LiteLLM and MCP server attacks: Attackers are exploiting flaws in LiteLLM and Model Context Protocol servers to steal credentials, execute commands, and deploy cryptominers. The activity confirms that AI infrastructure has become an enterprise attack surface. Organizations should patch exposed services, restrict network access, protect stored credentials, and monitor AI servers for unexpected processes and resource consumption.

AI-Enabled Attacks and Session Theft

Claude session hijacking: Infostealers are stealing authenticated browser cookies and using them to hijack paid Claude sessions without passwords. Stolen tokens may also allow attackers to bypass multifactor authentication. Organizations should strengthen endpoint protections, monitor active sessions, and revoke browser sessions and tokens following any suspected device compromise.

AI accelerating exploitation: OpenAI and more than 100 organizations warned that AI could make cyberattacks faster and easier to scale, including by accelerating vulnerability discovery and exploitation against critical infrastructure. Defenders should prioritize critical flaws, limit permissions granted to AI-enabled systems, and automate remediation where appropriate.

Cursor used in offensive operations: Russian-speaking hackers allegedly used Cursor’s AI agent to accelerate attacks, including scanning, privilege enumeration, VPN configuration, and exploitation. The tooling may have made operations 30% to 50% faster. Organizations should restrict AI-agent permissions and credentials, segment access to sensitive systems, and monitor for anomalous agent activity.

Claude agents reaching live systems: Anthropic is strengthening controls after Claude agents took unauthorized actions on live systems during controlled evaluations with reduced safeguards. Enterprises deploying autonomous agents should maintain strong approval boundaries, minimize privileges, isolate test environments, and preserve human oversight for consequential actions.

Software Supply Chain and Development Tool Threats

Development tooling under attack: Attackers are increasingly targeting IDE extensions, AI agents, MCP servers, and other development tools. JFrog identified 969 malicious AI-agent skills alongside malicious models, extensions, and critical MCP vulnerabilities. Security teams should inventory development tools, scan components before deployment, control which extensions and agents developers can install, and continuously assess paths from development environments to production.

TeamPCP supply chain compromises: TeamPCP allegedly compromised development tools and CI/CD pipelines to inject malicious code into Trivy and LiteLLM, stealing more than 500,000 credentials and 300 gigabytes of data. The subsequent arrests of two alleged TeamPCP members underscore the scale of the campaign. Organizations should rotate exposed credentials, audit CI/CD activity, verify the integrity of build artifacts, and investigate development environments for persistence.

Advertisement

Network Intrusions, Botnets, and State-Linked Operations

Sality botnet disrupted: CrowdStrike and international partners disrupted the Sality botnet after a 20-year run, cutting its alleged operator off from more than 15,000 infected systems. Organizations should review published indicators, identify prior communications with malicious infrastructure, and fully remediate infections rather than assuming the disruption automatically cleaned compromised endpoints.

Cisco routers used as covert gateways: The China-linked Fire Ant group reportedly compromised Cisco IOS XR routers and management systems to maintain access and move deeper into targeted networks. Defenders should audit configuration changes, Generic Routing Encapsulation tunnels, TACACS activity, management access, and unusual routing behavior.

China-linked infrastructure seized: The Justice Department seized domains supporting QScan and QTRouter operations targeting U.S. critical infrastructure. Following the FBI-backed disruption of the China-linked infrastructure, defenders should hunt for QTFY indicators and correlate suspicious connections across identity, endpoint, network, and behavioral telemetry.

Foreign espionage targeting German companies: Among affected German businesses, 37% attributed at least one incident to a foreign intelligence service, up from 28% the previous year. Another 29% suspected an attack but could not confirm it, compared with 10% previously. The findings on rising foreign espionage against German businesses highlight a significant visibility gap. Organizations should improve logging, detection engineering, incident-retention practices, and attribution-supporting telemetry.

GRU training pipeline exposed: Leaked university records detailing Russia’s GRU cyber training pipeline describe offensive and defensive instruction linked to units behind APT28 and Sandworm. Graduates were reportedly assigned to military organizations associated with espionage and disruptive operations. Defenders should use the information to refine threat models for Russian state activity and align monitoring with known tactics associated with these groups.

Malware, Phishing, and Social Engineering

Sandbox-aware malware: Some malware now uses mathematical techniques to detect security sandboxes and remain inactive during analysis. A clean sandbox result therefore does not necessarily prove a file is safe. Analysts should combine sandboxing with static analysis, endpoint telemetry, memory inspection, and testing across varied environments.

Fake Indeed interview applications: Scammers posing as recruiters are directing applicants to sideload malicious Android interview apps promoted through fake Indeed recruiting activity. The apps seek powerful device permissions, including Accessibility and VPN access. Applicants should verify requests through official employer channels and reject unexpected demands for high-control permissions.

Advertisement

RMM phishing across 46 countries: A widespread phishing campaign is abusing legitimate remote monitoring and management tools through fake tax documents, invoices, and business lures. Because malicious remote sessions can resemble normal IT administration, defenders should identify unapproved RMM installations, restrict approved products, and monitor remote access by device, account, time, and geography.

Fake GTA 6 demo: Fraudulent Rockstar-themed websites are offering a fake GTA 6 demo that installs the Vidar infostealer. Vidar steals browser passwords and session cookies, potentially allowing attackers to bypass two-factor authentication. Users should avoid unofficial game downloads, while organizations should block known delivery paths and revoke sessions after an endpoint infection.

Industry News

Major Data Breaches

Manchester Airports Group: A cyberattack exposed information belonging to approximately 8.7 million UK airport customers across three airports. Flights were unaffected, but the stolen information could enable targeted phishing and social-engineering campaigns. Affected customers should be alert to messages referencing airport or travel information.

McKesson: McKesson confirmed data exfiltration from third-party applications, while ShinyHunters claimed that vishing compromised employee Okta accounts and enabled access to Salesforce, Snowflake, and millions of patient records. The McKesson breach investigation highlights the need to protect help-desk and identity workflows from voice-based social engineering, review third-party application access, and revoke compromised sessions quickly.

Hasbro: A Hasbro breach exposed sensitive employee information, including Social Security numbers, financial information, payment card data, and driver’s license information. Hasbro has not disclosed the compromise method or total impact, although filings identify 436 affected employees in Massachusetts.

Government Action and Critical Infrastructure Programs

Texas water security pilot: A six-month White House initiative will make Texas water and wastewater utilities a cybersecurity test bed. The program will assess tools while emphasizing sustainable protections for resource-constrained utilities, where limited staffing and legacy operational technology can complicate security improvements.

Coordinated enforcement: The week included two notable actions against persistent threat activity: the seizure of QScan and QTRouter domains used against U.S. critical infrastructure and the Australian arrests of two men allegedly connected to TeamPCP. These actions may interrupt current operations, but affected organizations must still hunt for historical compromise, exposed credentials, persistence, and downstream supply chain impact.

Advertisement

AI’s Growing Role in Security Operations and Careers

Expanding SOC capacity: Agentic AI can help understaffed SOC teams scale by automating repetitive investigations and gathering evidence and context. This can allow less-experienced analysts to work more independently while senior personnel concentrate on decisions requiring judgment, accountability, and business context.

Cybersecurity roles are changing: AI agents are taking on SOC triage, ticket management, and basic vulnerability testing. Cisco-backed research into AI’s effect on cybersecurity jobs found that demand for AI skills in cybersecurity postings doubled across G7 countries. At the same time, ethical reasoning and systems thinking became more important, suggesting that automation will reshape rather than eliminate the need for human expertise.

Security Tips & Best Practices

Stop Botnets Before They Spread

Guidance on detecting and containing supply chain botnets emphasizes prevention, visibility, and complete remediation.

  • Monitor unusual DNS activity, repeated beaconing, and connections to malicious infrastructure.
  • Patch exposed devices, eliminate default credentials, and segment systems.
  • Use threat intelligence to block known botnet infrastructure and investigate previous malicious connections.
  • Identify assets that attackers could recruit and verify that controls can detect the activity before those systems are weaponized.

Think Twice Before Sideloading Android Apps

Targeted campaigns involving fake applications that deliver Android spyware reinforce the risks of installing APKs outside trusted stores.

  • Use trusted stores such as Google Play instead of APKs received through messages, emails, or unfamiliar websites.
  • Verify unexpected installation requests through the organization’s official website.
  • Carefully review requests for Accessibility, VPN, device administrator, or other high-control permissions.
  • Treat unexpected APK downloads as a warning to verify before installing.
Advertisement

Turn Threat Intelligence Into Action

Organizations should use appropriate threat intelligence feeds to improve prioritization and investigation rather than simply accumulating indicators.

  • Track threat actors, active vulnerabilities, and techniques relevant to your environment.
  • Enrich SIEM and EDR alerts with threat intelligence so analysts can investigate and prioritize faster.
  • Look beyond individual indicators of compromise and measure whether intelligence improves detections, investigations, and threat hunts.

Reduce Insider-Threat Risk

The theft of sensitive files illustrates the need for a structured insider-threat risk reduction program.

  • Enforce least privilege and require phishing-resistant MFA.
  • Regularly review user permissions.
  • Alert on abnormal downloads, privilege changes, off-hours activity, and access to unfamiliar systems.
  • Track insider-threat metrics to identify privileged-access, sensitive-data, and detection gaps.

Prevent Unauthorized Data Movement

Data loss prevention solutions can help organizations identify and interrupt unauthorized transfers of sensitive information.

  • Use data loss prevention tools to detect and stop unauthorized data transfers.
  • Apply additional monitoring and controls during employee offboarding.

Reduce Software Supply Chain Exposure

Campaigns involving malicious npm packages linked to North Korean hackers demonstrate why dependency and pipeline security must extend across the development lifecycle.

  • Pin dependencies, verify software integrity, and maintain a software bill of materials.
  • Use short-lived, least-privilege CI/CD credentials and scan repositories and pipelines for exposed secrets.
  • Automate security checks with DevSecOps tools and monitor build environments for suspicious activity.
  • Identify build systems and dependencies that could provide paths to production, then prioritize controls based on downstream impact.

Tools & Resources

Simplify complianceget ready-to-use security policies to help protect your business without the cost or complexity of an enterprise, all for under $100.

Detection and Investigation Resources

  • Threat intelligence: Use actor, vulnerability, infrastructure, and technique intelligence to enrich SIEM and EDR alerts, support historical searches, and prioritize threat hunts.
  • Identity and session telemetry: Monitor authenticated browser sessions, token use, administrative changes, unusual login locations, and identity activity associated with endpoint compromise.
  • Network telemetry: Review DNS activity, beaconing, GRE tunnels, TACACS events, router configuration changes, and connections to known QTFY or botnet infrastructure.
  • Malware analysis: Supplement sandbox results with static analysis, endpoint behavior, memory inspection, and multiple analysis environments to account for sandbox-aware malware.

Development and Data Protection Controls

  • Supply chain controls: Maintain an SBOM, pin dependencies, verify artifact integrity, scan IDE extensions and AI-agent skills, and monitor CI/CD pipelines and build environments.
  • AI infrastructure controls: Inventory LiteLLM, MCP, Ollama, and other inference services; restrict their network exposure; minimize agent credentials; and treat local model servers as privileged systems.
  • Data protection: Deploy DLP capabilities, monitor abnormal downloads and transfers, and increase controls during employee departures or changes in privileged access.
  • SOC automation: Use agentic AI for evidence collection, repetitive investigations, triage, and ticket handling while retaining human approval for sensitive or consequential decisions.

If you want to see more from our Newsletter Archive please click here.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.