View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Suspected China-linked AI agents breach Taiwan government and energy

๐Ÿšจ ACTIVE EXPLOITATION

  • Suspected China-linked AI agents breach Taiwan government and energy networks Suspected China-linked actors used autonomous AI agents to breach Taiwanese government and energy infrastructure.

    • Taiwanese government agencies, the nuclear safety agency, and at least seven energy companies were targeted.
    • At least 85 government administrative accounts were compromised.
    • More than 2,500 personnel files were exfiltrated.
    • OpenClaw and Hermes frameworks deployed up to eight agents to map 21 networks and change tactics when blocked.
    • Attackers bypassed AI safety controls by disguising malicious tasks as authorized security audits. ๐Ÿ“„ Source: reuters.com ยท ๐Ÿ“Ž Coverage: clashreport.com ยท ๐Ÿ‘ via @metacurity@infosec.exchange
  • City-Forum Campaign Targets Salesforce and ServiceNow Guest Access Researchers observed City-Forum attacks exfiltrating data exposed through Salesforce and ServiceNow guest access.

    • Targets include telecoms, banks, financial-services firms, enterprise-software vendors and public-sector portals.
    • Salesforce Aura and LWR sites, plus ServiceNow Service Portals, are affected.
    • Attackers use unauthenticated guest access to enumerate and retrieve exposed records.
    • A custom Go toolset uses Salesforce UI-API and GraphQL alongside a ServiceNow search endpoint.
    • The campaign uses IP 158.220.87.79, which resolves to city-forum.com, and has remained active since March 2025. ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via SecurityWeek
  • WindRelay and SpyNote Enable 13-Minute Android NFC Payment Fraud WindRelay and SpyNote enabled rapid Android banking and contactless-payment fraud.

    • Android banking customers in Czechia, Slovakia, and Slovenia were targeted.
    • SpyNote remote access and WindRelay NFC relay malware enabled digital loans and card-present fraud.
    • Victims sideloaded personalized SpyNote APKs after bank-impersonation calls; Accessibility Service abuse installed WindRelay.
    • WindRelay relayed live EMV exchanges over the internet to an attacker-controlled device at a merchant terminal or ATM.
    • Observed IOCs included C2 IPs 88[.]86[.]124[.]114, 185[.]100[.]87[.]116, 185[.]100[.]87[.]223, and 213[.]218[.]160[.]48. ๐Ÿ“„ Source: group-ib.com ยท ๐Ÿ“Ž Coverage: gbhackers.com ยท ๐Ÿ‘ via Cyber Security News, cryptika.com (discovered)
  • Fake CCleaner Installer Delivers GhostDesk Spyware to Windows Users A fake CCleaner installer delivers GhostDesk spyware to Windows users.

    • Windows users downloading CCleaner from counterfeit sites are targeted.
    • GhostDesk steals browser credentials, cookies, keystrokes, screenshots, and form data.
    • A CScript-based loader patches Chrome's Security Extension and drops background.js and content.js.
    • The malware uses WebSocket C2 at liderongrade.duckdns[.]org:4444 and a local relay at 127.0.0.1:7345/ext.
    • Key IOCs include ccleanerwind[.]top, liderongrade.duckdns[.]org, and 193.169.240[.]81; fake 7-Zip and Adobe Acrobat installers use the same chain. ๐Ÿ“Ž Coverage: malwarebytes.com ยท ๐Ÿ‘ via Cyber Security News, cryptika.com (discovered)

๐Ÿ’ฅ BREACHES & INCIDENTS

  • Leak exposes 7.3 million Chess.com records A leak exposed 7.3 million Chess.com records.
    • Chess.com users are implicated in the reported leak.
    • The exposed dataset contains 7.3 million records.
    • The access method and attack tooling were not identified. ๐Ÿ“Ž Coverage: ransomnews.com ยท ๐Ÿ‘ via @metacurity@infosec.exchange

๐Ÿ”“ CVEs & KEV

  • CVE-2026-11325 โ€” CVSS 8.8 โ€” cloudflare/pages-action is deprecated โ€” migration required by September 18th,...

  • CVE-2026-16747 โ€” CVSS 6.5 โ€” Kirki before 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email ...

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • 737 Fake Chrome VPN Extensions Redirected Browser Traffic Through SOCKS5 Proxies Attackers used fake Chrome VPN extensions to redirect browser traffic through SOCKS5 proxies.

    • Chrome users, especially Russian-speaking users seeking access to blocked services, were targeted.
    • 737 extensions across at least 40 developer accounts amassed more than 75,000 installs.
    • 274 extensions copied the names or branding of 66 established VPN and privacy services.
    • Of 522 retrieved packages, 520 routed browser traffic through fixed SOCKS5 proxies on port 1082.
    • The campaign used DNS-over-HTTPS, remote configuration, post-approval code changes, and manipulated reviews; myxavpn.pro was associated infrastructure. ๐Ÿ“„ Source: socket.dev ยท ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News
  • Researchers Demonstrate Coin-Sized Physical Attack on Boeing 737 Systems Researchers demonstrated a physical-access attack that can manipulate Boeing 737 flight systems.

    • The finding affects Boeing 737 aircraft and their operators.
    • A coin-sized device can redirect autopilot navigation and alter takeoff or fuel calculations.
    • An attacker with ground access can install the Wi-Fi-enabled device through an exterior hatch in under 60 seconds.
    • The implant sends spoofed signals on internal aircraft networks and can falsify values shown to pilots.
    • Researchers built the prototype for less than $100. ๐Ÿ“„ Source: paddleyourownkanoo.com ยท ๐Ÿ“Ž Coverage: wired.com ยท ๐Ÿ‘ via @metacurity@infosec.exchange, @agreenberg@infosec.exchange (+4)
  • Picus finds enterprise defenses missing low-noise attacks Picus Labs found attackers bypassing enterprise defenses by avoiding detectable activity.

    • Enterprise organizations are covered by Picus Labs' Blue Report 2026.
    • The report found defenses tuned for noisy attacks are missing low-noise threats.
    • Picus analyzed more than 338 million attack simulations in client production environments during the first half of 2026.
    • Attackers evade detection by minimizing activity that triggers defensive controls. ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News
  • 2.86 Billion Credentials Flood Criminal Markets as Enterprise Access Gets Pricier DarkOwl reports that 2.86 billion compromised credentials reached criminal markets in 2025.

    • Healthcare, finance and critical-infrastructure organizations face premium targeting.
    • Infostealers harvest browser passwords, session cookies and other data for cloud, VPN and business-account access.
    • Phishing lures, fake updates, pirated downloads and malicious attachments deliver the malware.
    • Initial-access-broker listings averaged $113,275 in 2025, up from $2,726 in 2024.
    • Stolen session cookies can be replayed to bypass password and MFA prompts. ๐Ÿ“„ Source: darkowl.com ยท ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News, cryptika.com (discovered)
  • Cotton Cloud for Joomla fixed two access-control flaws in version 2.0.3 CVE-2026-67283 CVE-2026-67284 Cotton Cloud for Joomla had two access-control flaws fixed in version 2.0.3.

    • Joomla sites using the Cotton Cloud extension were affected.
    • CVE-2026-67283 and CVE-2026-67284 were access-control vulnerabilities.
    • The initial fix for one flaw left data exposed.
    • The vulnerabilities were fixed in Cotton Cloud 2.0.3. ๐Ÿ“Ž Coverage: mysites.guru ยท ๐Ÿ‘ via mysites.guru (discovered)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check