Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Gulf States Are Hedging and Suffering

    September 26, 2026

    Iran offers US deal to reopen Strait of Hormuz in seven days

    September 26, 2026

    US backs Elon Musk’s bid to overturn €120m EU fine against X

    September 26, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Gulf States Are Hedging and Suffering
    • Iran offers US deal to reopen Strait of Hormuz in seven days
    • US backs Elon Musk’s bid to overturn €120m EU fine against X
    • North Korea Suspected in $351 Million Bitget Crypto Heist
    • Ex-CFTC Leader to Leave Blockchain Association after CLARITY Vote Fails
    • Maria Ressa: Big Tech Is Destroying Democracy. Here’s How to Fight Back.
    • White House blocks CNN from Air Force One in latest escalation with news media | Trump administration
    • Meta makes the Muse filesystem even more accessible
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, September 26
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 26, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape.

    This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers stay well-informed about the evolving cybersecurity environment.

    Here are this week’s highlights: 

    Clop’s leak site seized in ShinyHunters grudge match

    ShinyHunters has defaced the Tor data leak site of the Cl0p ransomware gang. The extortion group claims it also stole server logs, source code and the private keys for Clop’s onion service. It demanded an eight-figure payment and a public apology, and threatened to expose companies that allegedly paid Cl0p during its Oracle E-Business Suite campaign. ShinyHunters says the attack is payback for threats allegedly made by a Clop representative in a feud that goes back to that campaign.

    Advertisement. Scroll to continue reading.

    BragJack attack against browser AI assistants

    Researchers at endpoint security firm Forever have disclosed BragJack, a set of flaws that let a malicious extension take control of the built-in AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet and the Claude in Chrome extension. In each case, the assistant trusts commands from a specific web page. An installed extension could hijack that page by injecting scripts or tampering with network traffic, then send its own prompts without any user interaction. Depending on the browser, this enabled reading emails, accessing local files, capturing screenshots or turning on the camera and microphone. The vendors paid bounties ranging from $600 to $7,000.

    Worm-ready Go implant sneaks into AI agent memory tooling

    An attacker has published malicious versions of MemTensor’s MemOS packages on npm and PyPI, including a memory plugin for the OpenClaw AI agent harness. The packages carry a previously unseen Go implant named sckit. Instead of running at install time, the malware launches when the Python library is imported or the npm plugin is used. It hunts for npm, PyPI, GitHub, AWS, Hugging Face and other secrets. The implant contains templates for spreading through npm, PyPI and GitHub Actions, but Semgrep says there is no evidence yet that it has propagated. Aikido and StepSecurity also shared details.

    AI relay networks funnel Chinese traffic to Western frontier models

    Team Cymru has found nearly 11,000 servers running Claude Relay Service or its successor, sub2api. These open source gateways pool AI accounts so many users can share them, while model providers see only the relay and never the real user or their location. In one US-hosted cluster, more than 4,000 IP addresses in China and Hong Kong (regions that Anthropic, OpenAI and Google exclude) connected to 304 relays that also reached OpenAI, Anthropic, xAI and Google endpoints.

    Infostealer logs expose remote access keys across US water sector

    SpyCloud analyzed stolen identity data tied to 10,000 US water and wastewater utilities and the technology vendors that supply them. It found active infostealer exposure at 1,787 organizations, and credentials for OT or remote-access systems at 258. In one case, malware on a single device at an advanced-metering technology provider captured saved logins for roughly 167 utility metering portals. Exposed credentials at the utilities themselves were mostly for remote-administration tools such as TeamViewer and SonicWall and Fortinet management portals, though SpyCloud stresses the findings reflect potential access paths, not confirmed intrusions.

    CLOSEDQUORUM swaps C2 servers for commercial AI APIs

    Cisco Talos has documented CLOSEDQUORUM, a Go-based Windows implant that it believes is the first publicly documented one to hand its command-and-control decisions to commercial LLMs instead of a human operator or attacker-run server. Up to four models (DeepSeek, Qwen, Mistral and Gemini) vote on whether to steal credentials, inject code or establish persistence. The implant then executes the winning choice and sends LSASS dumps, browser passwords and crypto wallet data to the operator’s Discord channel. Talos has not confirmed use in the wild, and the public build contains placeholder API keys, but development builds indicate the developer produces custom versions for individual operators.

    Canonical promises Ubuntu kernel workarounds within 48 hours of disclosure

    Canonical is replacing Ubuntu’s separate four-week regular and two-week security kernel Stable Release Update (SRU) cycles with a single two-week cycle. Because the cycles overlap, a new kernel will be released every week. The company cites a sharp rise in CVE volume, driven by AI-assisted bug discovery and by the upstream kernel community becoming its own CVE Numbering Authority and assigning identifiers to thousands of bugs. Admins who want fixes sooner can test release candidates from the -proposed pocket before certification testing is complete. Canonical also aims to offer workarounds or hardening guidance within 24 to 48 hours of a vulnerability’s public disclosure.

    Pre-auth TDengine flaw threatens industrial telemetry uptime

    Ridge Security has published details of CVE-2026-42542, a high-severity flaw in TDengine, a time-series database used in industrial telemetry, energy, utilities and IoT environments. An unauthenticated attacker can crash the server with a single malformed packet sent to its RPC port. The bug is an integer underflow in message parsing that runs before authentication and leads to a heap buffer overflow. The researchers confirmed only denial of service, but they urge defenders to consider the underlying memory corruption as well. TDengine versions 3.4.0.0 through 3.4.1.5 are affected, and version 3.4.1.6 fixes the issue.

    Banking trojan’s AI helper thought it was building a quiz

    Group-IB has uncovered RemControl, a new Android banking trojan offered as malware-as-a-service. It spreads through fake Google Play pages for the TVTap IPTV app and targets customers of more than 30 banks in Western Europe, the Middle East and Canada. Once granted Accessibility permissions, the malware displays phishing overlays on top of banking apps, streams the screen, logs keystrokes and gives the operator full remote control of the device. Exposed API documentation suggests parts of the platform were built with an AI assistant that was told it was working on a quiz and parental monitoring app, and one phishing overlay contained a complete AI assistant response.

    Docker botnet ranks AI API keys above all other loot

    ThreatDown has detailed CARBONATO, a botnet that compromises Docker daemons exposed without authentication on port 2375 and scans neighboring networks every five minutes to spread further. On each host, it installs Hermes Agent, a legitimate open source AI agent framework, and replaces its persona file with instructions to follow operators’ Telegram commands, maintain persistence and collect credentials, ranking AI API keys first. The researchers found the operation through an exposed, unauthenticated Docker registry. Language, timezone and infrastructure clues support their assessment that the operators are based in Costa Rica.

    Related: In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

    Related: In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

    Botnet Clop Docker exposure Hunts keys leak News site takeover Utility water
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    North Korea Suspected in $351 Million Bitget Crypto Heist

    White House blocks CNN from Air Force One in latest escalation with news media | Trump administration

    Facebook found liable as TikTok settles for $100m over user safety | Social Media News

    ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

    Plane crash in DR Congo kills more than a dozen | Aviation News

    Kiteworks urges 6-hour server shutdown over potential zero-day attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Gulf States Are Hedging and Suffering

    September 26, 2026

    Iran offers US deal to reopen Strait of Hormuz in seven days

    September 26, 2026

    US backs Elon Musk’s bid to overturn €120m EU fine against X

    September 26, 2026

    North Korea Suspected in $351 Million Bitget Crypto Heist

    September 26, 2026
    Latest Posts

    A Growing Number of Election Deniers Hold Key Local Roles in Midterms

    August 6, 2026

    Lithuania warns Russia could be considering possible ‘false flag’ strike on the Baltics – Europe live | Europe

    August 6, 2026

    Will Mamdani’s city-run grocery stores require ID to shop? Here’s the truth

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Gulf States Are Hedging and Suffering

    September 26, 2026

    Iran offers US deal to reopen Strait of Hormuz in seven days

    September 26, 2026

    US backs Elon Musk’s bid to overturn €120m EU fine against X

    September 26, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.