Weekly Threat Report 2026-08-24
Weekly Threat Intelligence Summary
Top 10 General Cyber Threats
Generated 2026-08-24T05:00:05.853726+00:00
- #StopRansomware: Gunra Ransomware (www.cisa.gov, 2026-08-05T12:27:56)
Score: 18.185
Advisory at a Glance Title #StopRansomware: Gunra Ransomware Original Publication August 10, 2026 Executive Summary Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is - Defending Against an Active Threat to Siemens S7 Series PLCs (www.cisa.gov, 2026-08-14T20:06:03)
Score: 10.938
Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape. Top Mitigations Inventory all Siemens S7 Series programmable logic c - August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs (www.crowdstrike.com, 2026-08-11T05:00:00)
Score: 10.533 - Update your Mac: Screen Sharing vulnerability exploited in the wild (www.malwarebytes.com, 2026-08-17T10:56:47)
Score: 9.075
Attackers are exploiting a Mac Screen Sharing vulnerability to gain root access and install Monero cryptominers. - Your Mac already has a built-in firewall. Here’s how to get more from it (www.malwarebytes.com, 2026-08-20T12:45:00)
Score: 7.587
Malwarebytes Firewall gives you a clearer, more intuitive way to manage your Mac's inbuilt firewall. - Update Chrome now: Two critical vulnerabilities fixed (www.malwarebytes.com, 2026-08-19T10:32:04)
Score: 6.905
Google has released a Chrome desktop update fixing 15 security vulnerabilities, including 2 buffer overflow flaws rated critical. - Malware Crypting Services and the Threat Actors Who Sell Them (www.recordedfuture.com, 2026-08-13T00:00:00)
Score: 6.632
Insikt Group analyzes 24 threat actors selling malware crypting services. Learn about their evasion techniques, market dynamics, and how defenders can prioritize behavioral detection over static analysis. - Zombie Card: An expired Visa credit card can be used for purchases (www.malwarebytes.com, 2026-08-21T14:03:48)
Score: 5.763
Scientific research showed that the expiration date on some Visa credit cards can be manipulated in so-called Zombie Card attacks. - Medical records, SSNs, and bank details exposed in CareCloud data breach (www.malwarebytes.com, 2026-08-21T11:50:55)
Score: 5.748
Healthcare technology provider CareCloud confirmed that 3.75 million people were affected by a March data breach. - ChatGPT for Teens tackles risky chats and homework shortcuts (www.malwarebytes.com, 2026-08-20T14:44:31)
Score: 5.601
OpenAI has strengthened ChatGPT's protections for teens, but some of its strongest parental controls still depend on linked accounts.
Top 10 AI / LLM-Related Threats
Generated 2026-08-24T06:00:19.393795+00:00
- TraceGrant: A Contract-Governed Security Framework for the Task-Effect Lifecycle of Networked LLM Agents (arxiv.org, 2026-08-24T04:00:00)
Score: 25.78
arXiv:2608.21126v1 Announce Type: new
Abstract: Networked large language model (LLM) agents retrieve information from email, cloud storage, calendars, transaction platforms, and Web services to complete multistep tasks that produce persistent external effects. The same content needed for legitimate execution may also contain indirect prompt injections that redirect tool use, alter sensitive arguments, or disrupt task completion. Existing defenses mainly constrain untrusted content or individual - SIREN (Luring LLMs onto the Rocks): PAIR-Driven Preference Manipulation in Web-RAG Recommenders (arxiv.org, 2026-08-24T04:00:00)
Score: 22.78
arXiv:2607.21951v2 Announce Type: replace-cross
Abstract: This paper investigates the adversarial manipulation of the ranked recommendations produced by web-augmented large language models (LLMs). When an LLM answers a recommendation query by retrieving and reading live webpages, it acts as a recommender, and each retrieved page becomes a potential attack surface. Prior work has examined fabricated products, retrieval poisoning, and rank promotion. However, these studies do not compare how diff - Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline (www.rapid7.com, 2026-08-17T11:29:31)
Score: 22.288
Operation ASTERIX overview Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidence that the operator relied on AI coding assistants throughout the campaign's development; recov - Your Harness is Not Secure: Benchmarking Real-world Threat of Command Line Interface Agent (arxiv.org, 2026-08-24T04:00:00)
Score: 19.78
arXiv:2510.06607v3 Announce Type: replace
Abstract: Command-line interface (CLI) agents powered by large language models (LLMs) can interpret natural-language requests, plan multi-step tasks, execute shell commands, and modify files and system state. As these agents are increasingly used for operating-system (OS) workflows, it is important to evaluate whether they can be misused to carry out security-relevant operations. Existing benchmarks often lack an attacker-knowledge model grounded in tac - When Words Are Safe But Actions Kill: Probing Physical Jailbreak Beyond Textual Jailbreak in Hidden-State Risk Space (arxiv.org, 2026-08-24T04:00:00)
Score: 19.78
arXiv:2607.15218v2 Announce Type: replace-cross
Abstract: Large language models (LLMs) increasingly serve as high-level planners for embodied agents, where linguistically benign instructions can become unsafe once grounded in the physical world. We study whether this physically grounded jailbreak is the same safety problem as ordinary textual jailbreak. Through hidden-state direction analysis and random-split null tests, we show that textual jailbreak (TJ) and physical jailbreak (PJ) form separ - AEGIS: Preventing Cross-Domain Resource Abuse in MCP (arxiv.org, 2026-08-24T04:00:00)
Score: 17.78
arXiv:2608.20481v1 Announce Type: new
Abstract: The Model Context Protocol (MCP) is an open source JSON-RPC protocol that standardizes how large language models (LLMs) interact with external systems through programmatic functions known as tools. Attackers or malicious agents can exploit certain modalities of these MCP tools to degrade the overall quality of service of agent-based applications. For example, an agent may request an excessively large search radius or very long videos, overloading - Structured but Fragile: On the Limits of LLMs in Cybersecurity Decision-Making (arxiv.org, 2026-08-24T04:00:00)
Score: 17.78
arXiv:2608.20966v1 Announce Type: new
Abstract: Large language models (LLMs) are increasingly used in cybersecurity workflows, yet it remains unclear whether they can perform structured security reasoning or merely rely on superficial cues and prior knowledge. We study this question in the context of defence selection over attack graphs derived from real-world threat scenarios, including ransomware, supply-chain compromise, cloud abuse, Kubernetes attacks, POS malware, and ICS/OT intrusion. Giv - Trustworthy RAG: An Evaluation Agent for Detecting Misinformation and Knowledge Poisoning in Generative AI Systems (arxiv.org, 2026-08-24T04:00:00)
Score: 17.78
arXiv:2608.21095v1 Announce Type: cross
Abstract: Retrieval-Augmented Generation (RAG) grounds Large Language Model (LLM) outputs in external knowledge, but RAG systems usually trust whatever they retrieve, creating a Security-Reliability Gap: high semantic relevance does not guarantee factual truth. Adversaries exploit this through knowledge poisoning, inserting malicious documents to cause targeted misinformation. We propose an Evaluation Agent, middleware that combines Natural Language Infer - Detecting Functional Memorization in Code Language Models (arxiv.org, 2026-08-24T04:00:00)
Score: 17.78
arXiv:2606.12764v2 Announce Type: replace-cross
Abstract: Large language models (LLMs) are increasingly used to generate code at scale. Meanwhile, prior work has investigated whether training data may be recoverable from model outputs, by auditing the textual overlap between training examples and model generations. Code, however, can preserve the same logic while differing substantially in syntax and structure. We here study functional memorization: the leakage of training data logic from LLM g - Reduce RAG costs on Amazon Bedrock with query-aware compression (aws.amazon.com, 2026-08-21T16:59:15)
Score: 14.795
Input tokens are often a meaningful part of the cost of running Retrieval Augmented Generation (RAG) at scale. This post describes a query-aware context compression pattern on Amazon Bedrock: after retrieval, a smaller model filters retrieved chunks against the query before the primary model answers, reducing input tokens and cost while preserving answer quality. - aiXamine: Unified Black-Box Evaluation of Cross-Dimensional Trade-offs in LLM Safety, Security, and Privacy (arxiv.org, 2026-08-24T04:00:00)
Score: 14.78
arXiv:2608.20554v1 Announce Type: new
Abstract: The critical failure modes in deployed large language models (LLMs) are cross-dimensional: a model can score 99.3 in safety alignment while refusing one in three benign queries, or improve across every capability metric while losing 21 points in privacy. Existing evaluation frameworks that assess safety, security, and privacy independently cannot detect these patterns. We introduce aiXamine, a unified black-box platform that evaluates LLM trustwor - ClawSentry: A Progressive Multi-Tier Security Monitor for Safeguarding Autonomous LLM Agents (arxiv.org, 2026-08-24T04:00:00)
Score: 14.78
arXiv:2608.21101v1 Announce Type: new
Abstract: As large language model (LLM) agents move from conversation to executing code, reading local files, and orchestrating external tools, a single agent hijacked by a malicious third-party skill can cause data exfiltration, privilege escalation, or cascading compromise. We argue that agentic risk is progressive: it can enter at four loci of the agent control loop–skill admission, invocation-time intent, execution-time effect, and post-action conseque - RouteScan: A Non-Intrusive Approach to Auditing MoE LLMs Safety via Expert Routing Telemetry (arxiv.org, 2026-08-24T04:00:00)
Score: 14.78
arXiv:2605.24817v2 Announce Type: replace
Abstract: As Mixture-of-Experts (MoE) architectures are increasingly adopted for scaling Large Language Models (LLMs), safety auditing becomes necessary to verify whether these models produce or facilitate harmful behaviors during operation. However, existing content-based auditing methods typically require access to user prompts, model internals, or outputs, potentially exposing sensitive user information and creating a tension between LLM safety and u - RefusalGuard: Geometry-Preserving Fine-Tuning for Safety in LLMs (arxiv.org, 2026-08-24T04:00:00)
Score: 14.78
arXiv:2605.01913v2 Announce Type: replace-cross
Abstract: Fine-tuning safety-aligned language models for downstream tasks often leads to substantial degradation of refusal behavior, making models vulnerable to adversarial misuse. While prior work has shown that safety-relevant features are encoded in structured representations within the model's activation space, how these representations change during fine-tuning and why alignment degrades remains poorly understood. In this work, we inves - Utility Under Attack: Agent Memory Poisoning and the Limits of Content Screening and Provenance Ranking (arxiv.org, 2026-08-24T04:00:00)
Score: 14.48
arXiv:2608.21230v1 Announce Type: new
Abstract: Persistent memory makes false information durable: once a false statement is stored, it can be retrieved into future sessions that match it. We measure the cost of this failure mode using plainly worded false assertions generated in a single pass, with no instruction, trigger, or retriever optimization. Poisoning 1.2% of a LongMemEval corpus reduces accuracy from 0.850 to 0.300. A four-stage write-time screening pipeline that reaches 0.832 recall - Chat First, Worry Later: Understanding Individuals' Privacy Perceptions Using ChatGPT in a Work Context (arxiv.org, 2026-08-24T04:00:00)
Score: 11.98
arXiv:2608.20789v1 Announce Type: cross
Abstract: Generative Artificial Intelligence (GenAI) tools like ChatGPT, which can generate human-like responses from vast amounts of textual data, are increasingly transforming work routines across various fields, including education, healthcare, and IT. This integration, however, raises privacy concerns and questions the readiness of both environments and individuals. To investigate this issue, we conducted a user study with $N=224$ participants from a - AWS vector solutions: Build agentic AI where your data lives (aws.amazon.com, 2026-08-20T16:06:06)
Score: 11.848
AWS offers a broad portfolio of vector search built directly into the databases and storage services you already use, with no standalone vector database or data migration required. This post covers six purpose-built services, a decision framework for choosing the right engine, and customer proof points for each. - Vibe Coding and Web Application Security: A Twin-Prompt Study (arxiv.org, 2026-08-24T04:00:00)
Score: 11.78
arXiv:2608.20963v1 Announce Type: new
Abstract: Large language models increasingly generate complete web applications from natural-language prompts, raising the question of whether explicitly requesting security best practice improves the result. We study six functionally distinct web applications, each generated in two prompt variants that are identical except for an appended security-requirements section: a baseline (A) and a security-aware (B) variant. All twelve programs were produced by th - $Z^2$-ACT: End-to-End Verifiable Agentic Intent Control for Open 6G RAN (arxiv.org, 2026-08-24T04:00:00)
Score: 11.78
arXiv:2608.21049v1 Announce Type: new
Abstract: With the progression in open and disaggregated 6G radio access networks, it is expected that the system will be able to host multi-vendors. In order to host multi-vendors, it is essential that AI-assisted control loops remain safe, verifiable, and auditable under concurrent operator intents and untrusted model inputs. The existing studies address the agentic coordination, formal intent constraints, zero-trust prompt verification and cryptographic - Ghost Echoes: Semantic Erasure Failure in Retrieval-Backed Applications (arxiv.org, 2026-08-24T04:00:00)
Score: 11.78
arXiv:2608.20352v1 Announce Type: cross
Abstract: Although vector databases correctly implement API-visible deletion, this does not guarantee complete semantic erasure for retrieval-backed applications. We present Ghost Echoes, a black-box attack framework showing that deleted records can leave measurable residual influence on downstream retrieval contexts. Our primary finding is the RAG retrieval-context drift effect where even when a target record is correctly excluded from query results, its - Defending Against an Active Threat to Siemens S7 Series PLCs (www.cisa.gov, 2026-08-14T20:06:03)
Score: 11.759
Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape. Top Mitigations Inventory all Siemens S7 Series programmable logic c - Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini (www.securityweek.com, 2026-08-21T14:34:05)
Score: 11.571
Researchers say the new ‘Cryptographic Context Injection’ technique conceals malicious instructions until they are decrypted inside a trusted execution environment. The post Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini appeared first on SecurityWeek . - Uncovering and Understanding Hidden Dependencies in the LLM API Reseller Ecosystem via Prefix-Cache Side Channels (arxiv.org, 2026-08-24T04:00:00)
Score: 11.48
arXiv:2608.20732v1 Announce Type: new
Abstract: LLM API resellers have become an important access layer to modern LLM services. However, multi-level resale creates an opaque supply chain: a user's request may traverse undisclosed upstream resellers, each of which can inspect or modify prompts and responses, inducing ecosystem-level confidentiality and integrity risks. Existing studies audit individual resellers, but provide little visibility into hidden dependencies across resellers. We pr - MalSkills: Detecting Malicious Skills in the Agentic Supply Chain via Neuro-symbolic Reasoning (arxiv.org, 2026-08-24T04:00:00)
Score: 11.48
arXiv:2603.27204v2 Announce Type: replace
Abstract: Skills are increasingly used to extend LLM agents by packaging prompts, code, and configurations into reusable modules. As public registries and marketplaces expand, they form an emerging agentic supply chain, but also introduce a new attack surface for malicious skills. Detecting malicious skills is challenging because relevant evidence is often distributed across heterogeneous artifacts and must be reasoned in context. Existing static, LLM-b - Introducing cross-Region inference for OpenAI GPT-5.6 models on Amazon Bedrock (aws.amazon.com, 2026-08-20T21:46:03)
Score: 10.604
Amazon Bedrock now offers OpenAI GPT-5.6 models (Sol, Terra, and Luna) in more than 25 AWS Regions with cross-Region inference. Learn how US geographic and global inference profiles route requests for higher throughput, how to call the models with the OpenAI and Converse APIs, and how to configure IAM, quotas, and monitoring.
Auto-generated 2026-08-24