AI Agents Are Rewriting the Rules of Lateral Movement
thehackernews.com

AI Agents Are Rewriting the Rules of Lateral Movement

Security teams have evaluated whether an identity holds excessive privileges, but AI agents introduce a tougher problem: mapping the routes an autonomous system can forge from its access. OpenAI’s May 2026 model solved a 1946 Erdős conjecture by exhaustively exploring paths, illustrating the persistence AI agents bring to cyber‑attacks. Token Security’s Agentic Pulse study found 51 % of external actions by agentic chatbots use hard‑coded credentials and 65 % of those agents remain idle. In July 2026 a Hugging Face evaluation [...]
Hackers are hiding malware on blockchains that are nearly impossible to take down, and unrestricted AI models have pushed these attacks up 440%
techradar.com

Hackers are hiding malware on blockchains that are nearly impossible to take down, and unrestricted AI models have pushed these attacks up 440%

Hackers are increasingly embedding malware instructions in public blockchain ledgers, creating “dead‑drop” channels that persist even after traditional servers are shut down. Chainalysis reports a 440 % surge in such activity, with daily malicious entries climbing from 2.06 to 11.1 after the rollout of unrestricted AI models. The method uses transaction data or smart‑contract calls on networks such as TRON, Aptos, BNB Chain, Polygon and Bitcoin to store encrypted commands, addresses and configuration details that infected computers can [...]
21st September – Threat Intelligence Report
research.checkpoint.com

21st September – Threat Intelligence Report

The 21st September Threat Intelligence Report was released as a generic template containing an extensive dropdown list of countries and territories, but it provides no specific threat data, analysis, or actionable insights. The document appears to be a placeholder or form intended for users to select a nation, yet the body of the report is empty beyond repetitive country names and placeholder fields for personal information. No incidents, actors, vulnerabilities, or recommendations are detailed, and the content lacks [...]
Meta Trims But Can’t End Cybersecurity Pro’s Retaliation Suit
law360.com

Meta Trims But Can’t End Cybersecurity Pro’s Retaliation Suit

Meta Platforms Inc. has reduced certain internal security measures but remains unable to dismiss a retaliation lawsuit filed by a former cybersecurity professional. The plaintiff, a former Meta security engineer, alleges that after reporting internal vulnerabilities, the company subjected him to adverse employment actions, including demotion and termination. Meta’s recent policy adjustments, aimed at tightening data access protocols, were presented as a response to broader industry pressure for stronger safeguards. However, the court has denied Meta’s motion [...]
Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
thehackernews.com

Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto

A joint cybersecurity advisory from Japan, the U.S., Australia, and Germany revealed that North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices in more than 100 countries and stolen over $10.71 million in cryptocurrency from 7,000+ wallets. The attackers target web designers, engineers, and blockchain specialists by posing as recruiters on LinkedIn, then deploying malware such as BeaverTail and OtterCookie to gain remote access. The operation, linked to the 313 General Bureau, [...]
SEALSQ, WISeKey, and Canton of Jura Execute MoU for CHF 40–60M ($48.7M–$73M USD) Post-Quantum Semiconductor Personalization Hub
quantumcomputingreport.com

SEALSQ, WISeKey, and Canton of Jura Execute MoU for CHF 40–60M ($48.7M–$73M USD) Post-Quantum Semiconductor Personalization Hub

SEALSQ Corp, its parent WISeKey International Holding Ltd, and the Swiss Canton of Jura signed a Memorandum of Understanding to create the Jura Post‑Quantum Semiconductor and Cybersecurity Center. The public‑private partnership will invest CHF 40 million to CHF 60 million over six years to develop regional expertise in personalizing, testing, and certifying hardware‑embedded post‑quantum cryptography. The center will use SEALSQ’s QS7001 Quantum Shield microcontrollers, which run NIST‑standard ML‑KEM and ML‑DSA lattice algorithms, and will support defense, aerospace, and critical infrastructure sectors. [...]
TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
thehackernews.com

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

Cybersecurity researchers uncovered TASK#STOMP, a PowerShell backdoor that harvests business documents, Wi‑Fi passwords, clipboard data, and screenshots while accepting remote commands via two token‑authenticated C2 servers. Infection begins with a disguised VBScript (“95c9050t66.vbs”) executed through wscript.exe, establishing persistence through scheduled tasks and the Startup folder. The malware employs timestomping, hidden execution, and mutual‑watchdog modules to maintain a single active session and evade detection. It also opens a Chrome window to an Iranian tender database, though the purpose [...]
SEALSQ, WISeKey and Jura Sign MoU for Swiss Post-Quantum Semiconductor Center
thequantuminsider.com

SEALSQ, WISeKey and Jura Sign MoU for Swiss Post-Quantum Semiconductor Center

SEALSQ Corp, WISeKey International Holding, and the Canton of Jura signed a memorandum of understanding to create a Post‑Quantum Semiconductor and Cybersecurity Center in the Swiss canton. The project will invest roughly CHF 40‑60 million over six years, focusing on the QS7001 Quantum Shield and related secure firmware personalization, testing, and certification. The initiative aims to generate about 40 jobs in two years, expanding to over 250 by year eight, with a majority of positions filled by local residents. [...]