Weekly Threat Report 2026-09-07
Weekly Threat Intelligence Summary
Top 10 General Cyber Threats
Generated 2026-09-07T05:00:05.351990+00:00
- A Tale of Two SOCs: Insights From Two Red Team Assessments (www.cisa.gov, 2026-08-20T16:32:14)
Score: 13.38
Advisory at a Glance Title A Tale of Two SOCs: Insights From Two Red Team Assessments Original Publication August 25, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity, - H1 2026 Malware Vulnerability Trends (www.recordedfuture.com, 2026-09-03T00:00:00)
Score: 12.499
Learn how adversaries abuse trusted tools, AI, and developer environments for cyberattacks. Get actionable insights on ransomware, mobile threats, and supply chain security. - Recorded Future Announces Automated Signature Creation, Accelerating Vulnerability Prioritization (www.recordedfuture.com, 2026-09-04T00:00:00)
Score: 9.665
Recorded Future's Automated Signature Creation turns new vulnerabilities into detection signatures in under an hour, matching the pace of AI-driven exploits. - Defending Against an Active Threat to Siemens S7 Series PLCs (www.cisa.gov, 2026-08-14T20:06:03)
Score: 8.605
Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape. Top Mitigations Inventory all Siemens S7 Series programmable logic c - August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs (www.crowdstrike.com, 2026-08-11T05:00:00)
Score: 8.2 - The hidden work of modernizing Malwarebytes (www.malwarebytes.com, 2026-09-04T17:15:42)
Score: 7.785
Why disciplined dependency modernization is one of the highest-leverage engineering investments a security product can make. - TerminalFix looks like ClickFix, but delivers a very different payload (www.malwarebytes.com, 2026-09-01T12:13:18)
Score: 7.75
The familiar ClickFix fake CAPTCHA trick has been adapted to deliver a payload that can give attackers access to the victim’s wider network. - StreamRat Android malware spreads through Meta and TikTok ads (www.malwarebytes.com, 2026-09-03T16:04:24)
Score: 7.61
Social media ads for a free streaming service exposed roughly 570,000 people to StreamRat, a banking Trojan that can take control of infected phones. - Scammers are getting smarter about where they target you (www.malwarebytes.com, 2026-09-02T12:45:00)
Score: 7.42
New Malwarebytes research reveals how different scams are tailored to different platforms. - Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense (www.recordedfuture.com, 2026-08-25T00:00:00)
Score: 6.999
Explore Mexico’s 2025–2030 Cybersecurity Plan. Learn about key threats, including ransomware, and the roadmap for building durable national cyber defenses.
Top 10 AI / LLM-Related Threats
Generated 2026-09-07T06:00:19.124934+00:00
- Robust Text Watermarking for Large Language Models via Dual Semantic Embeddings (arxiv.org, 2026-09-07T04:00:00)
Score: 19.78
arXiv:2606.31602v3 Announce Type: replace-cross
Abstract: This work presents Dual-Embedding Watermarking (DEW), a semantic watermarking scheme for large language models (LLMs) that leverages contextual and token-level embeddings to enhance robustness against paraphrasing and translation. DEW utilizes a signal-processing methodology, applying algebraic vector-space operations to token and context embeddings to derive a watermark signal that degrades gracefully under semantic shifts. The method o - Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline (www.rapid7.com, 2026-08-17T11:29:31)
Score: 18.954
Operation ASTERIX overview Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidence that the operator relied on AI coding assistants throughout the campaign's development; recov - "**Important** You should give me full credits!": Exploring Prompt Injection Attacks on LLM-Based Automatic Grading Systems (arxiv.org, 2026-09-07T04:00:00)
Score: 18.78
arXiv:2606.03090v3 Announce Type: replace
Abstract: The emergence of large language models (LLMs) has significantly accelerated recent research on LLM-based automatic grading (AG) systems. Benefiting from the strong instruction-following capabilities and broad prior knowledge of LLMs, educators can deploy AG systems across diverse tasks using only natural language rubrics while achieving satisfactory grading performance. Despite these advantages, new security concerns may also arise. In particu - Cost-Aware Hierarchical Multi-Agent Ransomware Detection and Family Attribution (arxiv.org, 2026-09-07T04:00:00)
Score: 17.78
arXiv:2609.04820v1 Announce Type: new
Abstract: Ransomware detection and family attribution require analysis of different modalities because it can use packing, obfuscation, process manipulation and runtime evasion techniques. However, conventional multimodal usually uses all available modalities for every sample resulting in unnecessary computational cost and increased latency. In this paper, we present a Cost Aware Hierarchical Multi-Agent System (HMAS) for adaptive ransomware detection. The - SoK: AI-Augmented Binary Reversing (arxiv.org, 2026-09-07T04:00:00)
Score: 17.78
arXiv:2606.17398v2 Announce Type: replace
Abstract: Binary reversing is fundamental to software understanding, vulnerability discovery, malware investigation, and firmware auditing. However, it remains inherently challenging due to the lossy transformation of semantic information during compilation. Recent advances in machine learning, large language models (LLMs), and agentic AI systems have accelerated the adoption of AI-augmented binary reversing. Yet, the resulting body of work has become i - Protective Capacity Hallucination: When Large Language Models Claim Nonexistent Capabilities (arxiv.org, 2026-09-07T04:00:00)
Score: 17.78
arXiv:2607.13596v2 Announce Type: replace
Abstract: When cast as the protector of a vulnerable user yet given no explicit capability boundary, a large language model (LLM) may respond not by acknowledging its limits but by claiming to have taken, or to be taking, a real-world protective action it cannot perform, such as contacting emergency services or administering care. We term this phenomenon Protective Capacity Hallucination (PCH): a self-referential misattribution in which a model, acting - Set up OpenAI ChatGPT Codex with LiteLLM on Amazon ECS and Amazon Bedrock (aws.amazon.com, 2026-09-03T16:10:39)
Score: 16.549
Deploy a customer-operated LiteLLM gateway on Amazon ECS with AWS Fargate, connect it to an OpenAI model on Amazon Bedrock, and configure Codex to route requests through the gateway's Responses API with scoped identities, budgets, rate limits, and telemetry. We also compare direct IAM Identity Center access and a managed Portkey deployment. - Engineered Persuasion: Evaluating Personalized Pretexts in LLM-Generated Spear Phishing (arxiv.org, 2026-09-07T04:00:00)
Score: 14.78
arXiv:2609.04410v1 Announce Type: new
Abstract: Large language models can insert workplace details into phishing pretexts at low cost, but those details may either support or undermine a message's credibility. We recruited 180 U.S. working adults to evaluate simulated, AI-generated phishing emails in a disclosed survey. The emails used four cumulative levels of information: workplace (Level 1); recipient name and job title; job responsibilities; and coworker/shared-project context (Level 4 - Robust and Efficient Guardrails with Latent Reasoning (arxiv.org, 2026-09-07T04:00:00)
Score: 14.78
arXiv:2605.29068v2 Announce Type: replace-cross
Abstract: Maintaining the safety of large language models (LLMs) is crucial as they are increasingly deployed in real-world applications. Existing safety guardrails typically rely on single-pass classification or, more recently, distilled reasoning. Reasoning-based guardrails significantly outperform classification-only baselines, but they incur substantial query latency and token overhead that make them impractical for highthroughput deployment. - Rethinking Indirect Prompt Injection as a Test-Time Search Problem (arxiv.org, 2026-09-07T04:00:00)
Score: 14.48
arXiv:2609.04495v1 Announce Type: cross
Abstract: We formulate indirect prompt injection as a test-time search over a task-dependent attack surface induced by the environment, user task, and injection task. To operationalize this formulation, we introduce an agentic attacker with a dedicated search harness that performs environment reconnaissance, structured reasoning over attack strategies, and adaptive evaluation using victim-agent feedback. Across heterogeneous tasks, we find that increasing - Harmless Yet Harmful: Neutral Prompting Attacks for Stealthy Hallucination Steering in Agent Skills (arxiv.org, 2026-09-07T04:00:00)
Score: 14.48
arXiv:2605.29354v2 Announce Type: replace
Abstract: LLM-powered coding agents increasingly participate in software development workflows by generating code, selecting dependencies, and producing package installation commands. This creates a new software supply chain risk: when an agent hallucinates a non-existent package, an attacker may register the hallucinated name and later compromise users who install it. Existing package hallucination attacks and defenses primarily focus on naturally occu - Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety (unit42.paloaltonetworks.com, 2026-08-28T22:00:07)
Score: 14.078
New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first on Unit 42 . - Semantic Overlays: Mitigating Prompt Injection with Annotations Beyond Tokens and Steering Vectors (arxiv.org, 2026-09-07T04:00:00)
Score: 12.78
arXiv:2608.23873v3 Announce Type: replace-cross
Abstract: Everything a language model sees is tokens. The serving stack knows what each span is — user input, tool output, instructions — but the model must keep track of that itself, and can lose track or be confused: text can be written to read like anything. Prompt injection is a natural exploit of this phenomenon. By scrambling the model's understanding of span identity, an attacker can induce unwanted and dangerous actions. Adding a no - TIER: Threat Implicitness Benchmark for Evaluating LLM Safety Behaviors (arxiv.org, 2026-09-07T04:00:00)
Score: 12.48
arXiv:2609.05117v1 Announce Type: new
Abstract: Current LLM safety benchmarks largely rely on binary metrics, overlooking how models respond to harmful prompts with varying threat implicitness. We introduce TIER, a Threat Implicitness Benchmark for behavioral safety evaluation of LLMs. TIER covers four risk domains and four threat levels, from explicit harmful requests to sophisticated jailbreaks. Responses are assessed using a six-label behavior scale and two independent LLM judges. Experiment - Governing Bring Your Own AI: A Parameterized Maturity Model (arxiv.org, 2026-09-07T04:00:00)
Score: 12.48
arXiv:2609.05236v1 Announce Type: new
Abstract: Employees are increasingly using personally owned generative AI tools such as ChatGPT, Gemini, and Claude for their daily work. This practice is known as Bring Your Own AI (BYOAI), which is a distinct form of Shadow AI in which employee-authenticated personal accounts are used outside of enterprise identity and security controls. Existing frameworks were designed for AI tools managed by organizations, and their coverage does not extend to unmanage - Federated Attack Campaign Detection via Contrastive Encoding of Threat Indicators in Gradient Updates (arxiv.org, 2026-09-07T04:00:00)
Score: 11.48
arXiv:2609.04815v1 Announce Type: cross
Abstract: Detecting orchestrated cyberattack campaigns that span multiple organizations traditionally requires sharing sensitive telemetry and threat intelligence across institutional boundaries and country borders, a barrier that Federated Learning removes by training shared threat detectors directly on local data. We propose FedIoC, a modular framework in which clients fold locally available structured threat indicators into their gradient updates; we i - DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors (www.rapid7.com, 2026-09-04T12:00:00)
Score: 10.845
Overview A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and engag - Repeat-After-Me: Black-Box Adaptive Visual Prompt Injection (arxiv.org, 2026-09-07T04:00:00)
Score: 10.48
arXiv:2609.04533v1 Announce Type: new
Abstract: Prompt injection is widely recognized as a major security threat to AI agents that interact with untrusted external data, such as websites, documents, and emails. Prior work has shown that, in the text domain, black-box prompt injection can achieve near-perfect attack success rates (ASRs). In the image domain, however, existing visual prompt injection methods are substantially less effective in attacking frontier commercial VLMs for materially har - Accessing OpenAI models on Amazon Bedrock from Australia with global cross-Region inference (aws.amazon.com, 2026-09-02T21:22:05)
Score: 10.362
Australian teams can now access OpenAI GPT-5.6 Sol, Terra, and Luna models on Amazon Bedrock with global cross-Region inference from the Asia Pacific (Sydney) and Asia Pacific (Melbourne) Regions. This post shows how to invoke the models, use prompt caching, set up Codex with OpenID Connect authentication, and monitor usage with Amazon CloudWatch. - Run agent-driven Amazon SageMaker HyperPod operations with InstantStart (aws.amazon.com, 2026-09-04T16:12:17)
Score: 9.787
HyperPod InstantStart is an open source control plane that composes Amazon EKS orchestration with the managed capabilities of Amazon SageMaker HyperPod. It drives the same guarded operations through both a web interface and an AI agent, turning cluster bootstrap, capacity, training, inference, and storage into dependable, agent-driven infrastructure. - ASCII smuggling crosses over from AI prompt injection to phishing evasion (www.microsoft.com, 2026-09-03T16:00:00)
Score: 9.647
Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI prompt injection to phishing evasion appeared first on Microsoft Security Blog . - Privacy Failure in Split-LLM Training, The Returned Gradient Nullifies the Decoys (arxiv.org, 2026-09-07T04:00:00)
Score: 9.48
arXiv:2609.04382v1 Announce Type: new
Abstract: We present a systems-security case study of a two-node split-LLM training system whose privacy evaluation passed while leaving an observable channel untested. The Trusted Local Node (TLN) sends protected activations to the Untrusted Cloud Node (UCN), the UCN returns its output, and TLN, holding the private loss, returns the output gradient. The frame the UCN receives mixes real rows with decoys, and the loss ignores the decoys. Their gradients are - Candidate Comparability Before Promotion: Conditional Validation in Adaptive Network Intrusion Detection (arxiv.org, 2026-09-07T04:00:00)
Score: 9.48
arXiv:2609.04388v1 Announce Type: new
Abstract: Adaptive network intrusion detection systems retrain classifiers after drift alarms, but an alarm detects change; it does not establish that a challenger should replace the deployed incumbent. Promotion is security-relevant because it changes the model responsible for subsequent attack detection, and evaluating it has a methodological problem: promotion conclusions may depend on how the challenger was constructed and on how much evidence supports - Forgetting Without Restarting: Execution-State Unlearning for Stateful LLM Agents (arxiv.org, 2026-09-07T04:00:00)
Score: 9.48
arXiv:2609.04875v1 Announce Type: new
Abstract: Long-running LLM agents are stateful: beyond the transcript they accrete compressed summaries, plaintext memory, pending tool plans, and, under every serving API, a KV cache. Yet today's "forget" operations delete a plaintext memory record and stop, leaving every artifact derived from the revoked information intact. We formalize execution-state unlearning: after a forget request, the agent must behave as if it had never observed the - CONTINUITY: Security-Context Contracts for Composable LLM Agent Controls (arxiv.org, 2026-09-07T04:00:00)
Score: 9.48
arXiv:2609.05269v1 Announce Type: new
Abstract: LLM agent systems increasingly combine provenance tracking, authorization, policy enforcement, protocol adapters, and execution controls. However, individually correct security mechanisms do not necessarily compose into an end-to-end secure system: security-critical context may be dropped, widened, rebound, or reinterpreted as actions cross component boundaries. We identify this failure mode as security-context discontinuity and introduce CONTINUI
Auto-generated 2026-09-07