Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 50 most important stories from August 31 – September 5, 2026. AI ran through the whole week: OpenAI’s GPT-6 Astra built working exploits, Anthropic shipped Claude Fable 5.1 and Mythos 5.1, Claude gained the ability to control computers, and frontier agents breached an enterprise network in under 10 hours.
The threat side stayed intense — APT28-linked hackers deployed the new HOOKEDGE backdoor across Europe, CISA flagged actively exploited PaperCut flaws, a Chrome V8 zero-day was abused in the wild, and Panzer ransomware hit victims across 11 countries.
Here’s everything your peers are reading this week.
Top Stories of the Week — 9 stories
AI Under Attack — 8 stories
Critical Vulnerabilities & Patches — 9 stories
Malware & APT Campaigns — 9 stories
Breaches, Fraud & Attacks — 8 stories
Industry News & Defense — 7 stories
1. Aurora Ransomware Hackers Use Cursor AI Agent for Hands-On Exploitation and ESXi Attacks
Aug 31, 2026 • gbhackers.com
An Aurora ransomware crew used the Cursor AI agent for hands-on exploitation and ESXi attacks. It is a concrete example of criminals folding AI coding tools into live operations.
2. Claude AI Can Now Control macOS and Windows Computers to Click, Type and Open Apps
Sep 3, 2026 • gbhackers.com
Claude AI can now control macOS and Windows computers to click, type and open apps. The capability promises productivity gains but also new abuse and oversight challenges.
3. OpenAI GPT-6 Astra Discovers Zero-Day Flaws and Builds Working Exploits in Cyber Tests
Sep 4, 2026 • gbhackers.com
OpenAI’s GPT-6 Astra discovered zero-day flaws and built working exploits in cyber tests. The results intensify concern over offensive uses of frontier models.
4. Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours
Sep 5, 2026 • gbhackers.com
Researchers used frontier AI agents to breach an enterprise network in under 10 hours. It sets a stark benchmark for how fast autonomous attackers can move.
5. CrowdStrike Falcon Zero-Day Lets Attackers Escalate Privileges on Windows Systems
Sep 4, 2026 • gbhackers.com
A CrowdStrike Falcon zero-day lets attackers escalate privileges on Windows systems. A flaw in a security agent is especially dangerous because it runs with high trust.
6. CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
Sep 1, 2026 • gbhackers.com
CISA flagged multiple PaperCut NG/MF flaws being exploited in the wild. Organizations running the print software are urged to patch without delay.
7. Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe
Sep 5, 2026 • gbhackers.com
Russian APT28-linked hackers deployed a new HOOKEDGE backdoor in espionage attacks across Europe. The implant gives the state-backed crew stealthy, persistent access.
8. Shai-Hulud Trinitite Worm Infects Popular TanStack Query npm Package to Steal Developer Secrets
Aug 31, 2026 • gbhackers.com
The Shai-Hulud Trinitite worm infected the popular TanStack Query npm package to steal developer secrets. Supply-chain worms in package registries can spread fast and silently.
9. New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption
Sep 5, 2026 • gbhackers.com
New Panzer ransomware hit 16 victims across 11 countries with data theft and encryption. The double-extortion model pressures victims on two fronts at once.
10. OpenAI Warns Astra AI Model May Develop Zero-Day Exploits and Launch Autonomous Cyberattacks
Aug 31, 2026 • gbhackers.com
OpenAI warned that its Astra model may develop zero-day exploits and launch autonomous cyberattacks. The caution underscores dual-use risks in the most capable models.
11. Anthropic Unveils Claude Fable 5.1 and Mythos 5.1 With Powerful Cybersecurity Capabilities
Sep 2, 2026 • gbhackers.com
Anthropic unveiled Claude Fable 5.1 and Mythos 5.1 with powerful cybersecurity capabilities. The models push further into automated defense and secure development.
12. LLMjacking Attack Abuses Leaked AWS Credentials to Hijack Amazon Bedrock AI Models
Sep 4, 2026 • gbhackers.com
An LLMjacking attack abuses leaked AWS credentials to hijack Amazon Bedrock AI models. Stolen keys can rack up huge bills and expose sensitive model access.
13. AI Shopping Assistant Vulnerabilities Enable Remote Code Execution on Retailer’s Servers
Aug 31, 2026 • gbhackers.com
AI shopping assistant vulnerabilities enable remote code execution on a retailer’s servers. Consumer-facing AI tools expand the enterprise attack surface.
14. Google Unveils Gemini 3.8 Flash Cyber for Autonomous Vulnerability Discovery and Automated Patching
Sep 3, 2026 • gbhackers.com
Google unveiled Gemini 3.8 Flash Cyber for autonomous vulnerability discovery and automated patching. It joins a wave of AI models pitched at defensive security work.
15. OWASP Launches OASIS to Use AI and AppSec Experts to Fix Open-Source Vulnerabilities
Sep 2, 2026 • gbhackers.com
OWASP launched OASIS to combine AI and AppSec experts to fix open-source vulnerabilities. The project pairs community expertise with automated remediation.
16. Bright Security Expands its AI SDLC Security Platform and Launches an AI PT Module
Sep 1, 2026 • gbhackers.com
Bright Security expanded its AI SDLC security platform and launched an AI penetration-testing module. The tools aim to bake security into fast AI-driven development.
Sep 3, 2026 • gbhackers.com
OpenMatter Network expanded its platform with new capabilities for secure AI, computing and data collaboration. The push targets safer sharing of models and sensitive data.
18. Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities
Aug 31, 2026 • gbhackers.com
Metasploit added an exploit for the PaperCut MF/NG zero-day RCE vulnerabilities. Public tooling sharply raises the urgency to patch exposed print servers.
19. GitSpawn Flaw Enables Arbitrary Code Execution in Claude Code, Codex, Cursor and Grok
Sep 3, 2026 • gbhackers.com
A GitSpawn flaw enables arbitrary code execution in Claude Code, Codex, Cursor and Grok. Cloning a booby-trapped repo could compromise an AI coding assistant.
20. Hackers Exploit Critical Langflow and Ruby on Rails Flaws in Active RCE Attacks
Sep 1, 2026 • gbhackers.com
Hackers are exploiting critical Langflow and Ruby on Rails flaws in active RCE attacks. Both power widely used AI and web apps, widening the exposure.
21. Google Chrome V8 Flaw Actively Exploited in the Wild, Update Released
Sep 4, 2026 • gbhackers.com
A Google Chrome V8 flaw is being actively exploited in the wild, and Google shipped an update. With billions of users, Chrome zero-days demand fast patching.
22. Microsoft 365 Direct Send Bypass Lets Attackers Spoof Internal Users Without Credentials
Sep 4, 2026 • gbhackers.com
A Microsoft 365 Direct Send bypass lets attackers spoof internal users without credentials. Convincing internal-looking mail supercharges phishing.
23. TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft
Sep 4, 2026 • gbhackers.com
TP-Link Archer AX55 flaws enable remote code execution and admin password theft. With millions deployed, the routers put many home and small-office networks at risk.
24. 12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
Sep 5, 2026 • gbhackers.com
A 12-year-old PostgreSQL flaw lets attackers execute code and take over database servers. The long-dormant bug exposes a huge base of production deployments.
25. 13 Malicious Packagist Themes Exploit iPhone Vulnerabilities to Steal Crypto Wallet Seeds
Sep 1, 2026 • gbhackers.com
Thirteen malicious Packagist themes exploit iPhone vulnerabilities to steal crypto wallet seeds. Poisoned developer packages become a route to end-user funds.
26. Android 17 Adds New Network Security Features to Block 2G SMS Blaster Attacks
Aug 31, 2026 • gbhackers.com
Android 17 adds new network-security features to block 2G SMS blaster attacks. The change targets fake base stations used to push fraudulent texts.
27. Chrome and Edge Extensions Strip CSP and Inject JavaScript to Drain EVM, Solana and Tron Wallets
Aug 31, 2026 • gbhackers.com
Malicious Chrome and Edge extensions strip CSP and inject JavaScript to drain EVM, Solana and Tron wallets. Browser add-ons remain a stealthy path to crypto theft.
28. Infostealer Infection Exposes Blind Eagle-Linked Operator’s Malware Production Pipeline
Aug 31, 2026 • gbhackers.com
An infostealer infection exposed a Blind Eagle-linked operator’s malware production pipeline. The rare leak offers defenders insight into the group’s tooling.
29. Trojanized Exodus Wallet Installer Deploys RAT to Steal Browser Credentials and Cookies
Sep 2, 2026 • gbhackers.com
A trojanized Exodus wallet installer deploys a RAT to steal browser credentials and cookies. Crypto users are lured into infecting their own machines.
30. Fake Microsoft Edge, Kaspersky and Razer Installers Used to Compromise Windows Systems
Sep 2, 2026 • gbhackers.com
Fake Microsoft Edge, Kaspersky and Razer installers are being used to compromise Windows systems. Impersonating trusted brands helps the lures land.
31. 255 Fake Accounts Used to Send Malicious Excel Files to 80,000 Freelancers
Sep 2, 2026 • gbhackers.com
Attackers used 255 fake accounts to send malicious Excel files to 80,000 freelancers. The gig economy is a broad, soft target for mass malware campaigns.
32. Rogue ScreenConnect Clients Spread Worm-Like Malware Across Connected Windows Systems
Sep 3, 2026 • gbhackers.com
Rogue ScreenConnect clients spread worm-like malware across connected Windows systems. Abusing legitimate remote tools helps the campaign evade defenses.
33. NodeStealer Spyware Adds Keylogging, Screenshot Capture and Facebook Data Theft
Sep 4, 2026 • gbhackers.com
NodeStealer spyware added keylogging, screenshot capture and Facebook data theft. The upgrades broaden what the malware can quietly harvest.
34. Contagious Interview Operators Move Beyond Git Hooks With Trojanized Mac Applications
Sep 4, 2026 • gbhackers.com
Contagious Interview operators moved beyond Git hooks to trojanized Mac applications. North Korea-linked crews keep refining their developer-targeted lures.
35. Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors
Sep 4, 2026 • gbhackers.com
Hackers turned HiveMQ and Element Messenger into command channels for Windows backdoors. Riding legitimate messaging traffic helps the malware hide.
36. Hackers Use Infostealer Malware to Steal Claude Session Cookies and Hijack Accounts
Aug 31, 2026 • gbhackers.com
Hackers are using infostealer malware to steal Claude session cookies and hijack accounts. Session theft continues to undercut multi-factor protection.
37. BGP Hijacking Attack Delivers Malicious Virtualizor Updates to Servers
Sep 1, 2026 • gbhackers.com
A BGP hijacking attack delivered malicious Virtualizor updates to servers. Routing-layer attacks let adversaries poison trusted software channels.
38. Hackers Compromise More Than 14,500 Dahua Security Cameras in Massive Campaign
Sep 4, 2026 • gbhackers.com
Hackers compromised more than 14,500 Dahua security cameras in a massive campaign. Mass IoT compromise builds ready-made infrastructure for attacks.
39. CARS24 Data Breach Exposes 3,100 Customer Records, Leads Allegedly Sold for ₹1,000 Each
Sep 5, 2026 • gbhackers.com
A CARS24 data breach exposed 3,100 customer records, with leads allegedly sold for ₹1,000 each. Resale markets monetize even modest data sets.
40. Mirage Kitten Hackers Use Fake Coding Challenges to Deploy NodeRabbit and PollCat RATs
Sep 1, 2026 • gbhackers.com
Mirage Kitten hackers use fake coding challenges to deploy the NodeRabbit and PollCat RATs. The lure exploits job-seekers’ trust in technical tests.
41. Hackers Pose as IT Support on Microsoft Teams to Target More Than 150 Employees
Sep 1, 2026 • gbhackers.com
Hackers posed as IT support on Microsoft Teams to target more than 150 employees. Social engineering over trusted tools keeps opening doors.
42. Fake Acquisition Scam Uses Forged NDAs to Demand €626,000 Corporate Payment
Sep 3, 2026 • gbhackers.com
A fake acquisition scam used forged NDAs to demand a €626,000 corporate payment. Business-email-compromise crews keep refining their pretexts.
43. QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes
Sep 3, 2026 • gbhackers.com
QR phishing hit record levels as attackers hide malicious links inside QR codes. ‘Quishing’ sidesteps many link-scanning defenses.
44. Broadcom Unveils VMware AI Factory With Secure Sandboxes for Enterprise AI Workloads
Sep 1, 2026 • gbhackers.com
Broadcom unveiled VMware AI Factory with secure sandboxes for enterprise AI workloads. The platform targets governance gaps in fast-moving AI rollouts.
45. Simple Router DNS Tweak Blocks Malware and Phishing Across All Connected Devices
Aug 31, 2026 • gbhackers.com
A simple router DNS tweak blocks malware and phishing across all connected devices. The one-time change protects every device on the network.
46. Firefox for iPhone Adds Built-In Ad Blocker to Block Third-Party Ads and Trackers
Sep 2, 2026 • gbhackers.com
Firefox for iPhone added a built-in ad blocker to block third-party ads and trackers. The move brings privacy controls to more mobile browsing.
47. Threat Intelligence: Definition, Benefits, and Use Cases
Sep 2, 2026 • gbhackers.com
A GBHackers explainer breaks down threat intelligence: its definition, benefits and real-world use cases. It is a useful primer for teams building a program.
48. Hackers Hide Reverse Shell Traffic Behind Signed Apps and AWS API Gateway
Sep 2, 2026 • gbhackers.com
Hackers hide reverse-shell traffic behind signed apps and AWS API Gateway. Blending into trusted cloud services helps their traffic evade detection.
49. Fewer Attacks, More Force: Link11’s European Cyber Report Finds New DDoS Records for H1 2026
Sep 3, 2026 • gbhackers.com
Link11’s European Cyber Report found fewer but far more forceful attacks, setting new DDoS records for the first half of 2026. Attackers are trading volume for raw power.
50. Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security
Sep 5, 2026 • gbhackers.com
Chainguard reached 1 billion build manifests with its AI-powered software supply chain security. The milestone signals rising demand for hardened build pipelines.
A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to…
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS…
A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers…
Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also…
GitLab has issued an emergency security update to address two critical vulnerabilities that could lead…