ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories
AI Summary
A threat actor known as CL-CRI-1171 operated a pay-per-install (PPI) marketplace using YouTube and SEO poisoning to distribute malware, delivering payloads such as Docro Hijacker, ARKTunnel, and the Insomnia RAT via the OfferLoader custom loader. Separately, unauthenticated LocalAI instances were exploited to gain command execution and exfiltrate sensitive data, including military and AWS credentials. A critical VMware vCenter vulnerability, CVE-2026-59310, is being actively exploited by ransomware gangs for remote code execution. Additionally, Cyclops Blink has reemerged in a new variant targeting Cisco FMC devices, leveraging CVE-2026-20079 and CVE-2026-20316 for network reconnaissance and persistence.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | luciferus[.]io | Details → |