Skip to content
Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

Ravie LakshmananSep 17, 2026Hacking News / Cybersecurity News

Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them.

This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough.

So the threat landscape is not getting cleaner. It is just getting more places to make the same mistake. Here’s what showed up this week.

The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.

  1. Malware PPI operation exposed

    A threat actor known as CL-CRI-1171 has stayed under the radar for at least two years, offering a pay-per-install (PPI) marketplace that allows other threat actors to distribute their malware through YouTube channels and a parallel search engine optimization (SEO)-poisoning funnel. “These channels were actively interacting with viewers to promote gaming content laced with links to download malware,” Palo Alto Networks Unit 42 said. “Although the videos provided real content for gamers, they also served as the delivery vehicle for infection, prompting viewers to download malicious tools. The SEO funnel targeted a more professional audience, promoting trojanized software that resulted in malware deployment on corporate endpoints, including critical infrastructure and even government entities.” Both these chains lead to a custom loader called OfferLoader that has delivered three payloads between July 2025 and April 2026: Docro Hijacker (a Chrome backdoor that can bypass modern integrity protections), ARKTunnel (a WebSocket tunneling RAT), and a new variant of a previously unnamed cross-platform backdoor that’s been codenamed Insomnia remote access Trojan (RAT) and can target both Windows and macOS. Post-April 2026, the PPI infrastructure has led to GCleaner and Socks5Systemz.

The lesson this week is not that attackers suddenly got smarter. It is that useful things keep becoming attack surfaces faster than teams learn to treat them that way.

So check what is exposed. Check what holds tokens, prompts, configs, and keys. Kill weak defaults. Patch the boring old stuff too. New tech does not cancel old mistakes; it just gives them more places to hide.

That is the useful part of weeks like this. Not panic. Better instincts. Fewer easy wins left on the table.

Source link