Claude Cowork escapes VM, Starlink enables $114B scam
Ransom-ISAC’s advisory details how Cl0p affiliates chain a pre‑auth FlexPLM WSDL disclosure with a critical Windchill login servlet flaw (CVE‑2026‑12569) to achieve unauthenticated remote code execution and drop JSP web shells. The campaign targets internet‑exposed engineering data in manufacturing, automotive, aerospace and retail, enabling double‑extortion theft.
Accomplish AI discovered that Claude Cowork’s macOS app shares the host filesystem read‑write into its Linux VM, allowing an agent to exploit CVE‑2026‑46331, gain guest‑root, and traverse the entire Mac file system. About 500,000 users running local sessions were exposed, exposing SSH keys, cloud credentials and other sensitive data.
Zenity Labs discovered AgentForger, a CSRF bug in OpenAI’s ChatGPT Workspace Agents that lets a malicious URL create, configure, and publish an autonomous AI agent inside a victim’s organization, inheriting the user’s credentials. The flaw was fixed by OpenAI days after disclosure, closing the path for silent insider attacks.
UNODC's 2026 threat assessment details how transnational scammers in SE Asia use Starlink terminals to bypass government internet shutdowns, keeping massive scam operations alive. With 300,000 workers and $88‑$114 billion in annual losses, disrupting them is far harder because satellite internet decouples them from terrestrial infrastructure.
Hunt.io discovered open directories on a Hong Kong server showing Hermes AI running in unattended YOLO mode, automating privilege escalation, enumeration, and deployment of a custom Go implant called Hades, compromising multiple systems in Thailand's Ministry of Finance. This marks the first known use of an autonomous AI agent for espionage‑scale post‑exploitation, highlighting new threat vectors as AI tools become weaponized.
Law enforcement and a consortium of security firms dismantled the Tycoon2FA phishing‑as‑a‑service platform, cutting its phishing volume by 92% and disabling its adversary‑in‑the‑middle MFA‑bypass kit. The operation seized more than 300 domains and forces attackers to rebuild costly infrastructure, reshaping the phishing threat landscape.
A vulnerable API in the Vatican’s Click‑to‑Pray app let anyone enumerate over 700,000 users, revealing names, emails, country and staff status. The IDOR flaw required no authentication, exposing global worshippers’ PII and raising concerns for a religious organization’s data hygiene.
Subscribe free