// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRF-01DTG 0600Z
ColdRecon / Brief Archive / Week of September 28, 2026
Signal Brief · Archived

Week of September 28, 2026

2026-09-28 — 2026-10-04 · 36 PUBLIC EVENTS · GENERAL / NON-PERSONALIZED

In the week of September 28, 2026, ColdRecon logged 36 public endpoint-security events from open-source reporting — 18 research pocs, 12 incidents, 3 vendor announcements, 3 vuln disclosures. Vendors in the record this week: CrowdStrike, Omega Solution, Fortra.

The Week's Public Record

Events

2026-10-04
vendor announcement
Bitdefender Launches AI Guardian to Protect AI AgentsBitdefender AI Guardian
Bitdefender announced AI Guardian, a free tool that provides visibility and control over AI agents. It blocks prompt injection, tampered MCP tools, and unauthorized credential access. The tool addresses the growing risk of AI agent manipulation.
2026-10-04
vendor announcement
CrowdStrike Falcon Available via OpenAI MarketplaceCrowdStrike-OpenAI-Marketplace-Integration
CrowdStrike announced that its Falcon cybersecurity platform is now available through the OpenAI Marketplace, allowing eligible enterprise customers to use existing OpenAI commitments to procure Falcon subscriptions. This expands the partnership between CrowdStrike and OpenAI, integrating Falcon's security capabilities with OpenAI's enterprise offerings.
2026-10-04
research poc
AI Agent Chained Two Zero-Days to Achieve Root AccessAI-chained-zero-days
An AI agent autonomously discovered and chained two zero-day vulnerabilities to gain root access on a vulnerability disclosure nonprofit's system within seconds. The event demonstrates the potential for AI to accelerate exploitation and poses new challenges for endpoint security.
2026-10-04
vuln disclosure
CVE-2026-105096: Omega Solution CoinEx Crypto 2025 Vulnerability with Public PoCCVE-2026-105096
A medium severity vulnerability (CVSS 6.3) has been disclosed in Omega Solution CoinEx Crypto 2025. The flaw affects an unknown function and has a verified proof-of-concept exploit available. Technical breakdown and mitigation guidance are provided.
2026-10-04
vuln disclosure
Critical OS Command Injection in Fortra BoKS Core Privileged Access ManagerCVE-2026-9862
CVE-2026-9862 is a critical OS command injection vulnerability in Fortra BoKS Core Privileged Access Manager. It allows authenticated attackers to execute arbitrary operating system commands, potentially leading to full system compromise. The vulnerability affects the security product itself, making it highly relevant to endpoint security.
2026-10-03
incident
Play ransomware abuses SentinelOne uninstaller to disable endpoint protectionPlay ransomware SentinelOne uninstaller abuse
Play ransomware (PlayCrypt) gained access via a SonicWall VPN, moved laterally with Mimikatz and PsExec, exfiltrated data, and used the victim's own SentinelOne uninstallation utility to disable endpoint protection before encrypting systems. The incident highlights a double-extortion playbook and a specific method to bypass EDR by leveraging legitimate vendor tools.
2026-10-02
vendor announcement
CrowdStrike Warns of Agentic Privilege Escalation via Indirect Prompt InjectionAgentic Privilege Escalation
CrowdStrike threat intelligence lead Adam Meyers warns that autonomous agents connected to enterprise systems like ERPs, Slack, and Salesforce are vulnerable to indirect prompt injections that can steal API keys and escalate permissions. This highlights a new attack vector where AI agents become the target for privilege escalation within enterprise environments.
2026-10-02
research poc
Windows malware leverages Grok AI for evasion and credential theftGrok AI-assisted malware
A new Windows malware sample uses Grok AI to generate evasion techniques and steal passwords. It also drains paid AI credits from compromised accounts. The malware demonstrates AI-assisted attack development.
2026-10-02
vuln disclosure
GitSpawn: Git config hijack vulnerabilities in seven AI coding agentsGitSpawn
In October 2026, researchers disclosed GitSpawn, a set of vulnerabilities affecting seven AI coding agents. The flaws allow attackers to hijack git configuration, swap plugin pins, escape sandboxes, and leak sensitive data. These issues highlight security weaknesses in AI-assisted development tools.
2026-10-02
incident
Authentication Bypass Impersonated 95 Users Without Passwords or MFAAuthentication Bypass Impersonating 95 Users
A critical authentication bypass allowed an attacker to impersonate 95 employee accounts, including privileged users, without passwords or multi-factor authentication (MFA). The incident highlights a significant weakness in the authentication mechanism of the affected system.
2026-10-02
incident
Agentic AI-Powered Attack Exploits Zammad Zero-Days Against Dutch Vulnerability InstituteAgentic AI-powered attack on DIVD using Zammad zero-days
The Dutch Institute for Vulnerability Disclosure (DIVD) was targeted in an attack that exploited two zero-day vulnerabilities in the Zammad helpdesk software. The attacker used an agentic AI system to discover and exploit the flaws, compromising DIVD's systems. This incident highlights the emerging threat of AI-driven autonomous attacks against security organizations.
2026-10-02
research poc
AI agent finds 8 of 10 vulnerabilities in unprotected binary in 3 minutesAI-assisted vulnerability detection
A test showed an AI agent found 8 of 10 vulnerabilities in an unprotected binary in just over three minutes, using 342,000 tokens. When the same binary was protected with Sentinel Envelope, the AI agent found none after six hours and recommended ceasing analysis. This demonstrates that AI can dramatically accelerate vulnerability discovery, but binary protection can thwart such AI-assisted analysis.
2026-10-01
research poc
EDR Killers Evolve Beyond Driver Exploits in 2026 Malware Arms RaceDriverless EDR Killers
The article reports a shift in malware development from BYOVD (Bring Your Own Vulnerable Driver) techniques to driverless EDR killers that exploit EDR operational dependencies. AI-assisted tool development is lowering the skill floor for attackers, enabling these driverless techniques to bypass kernel-level protections.
2026-10-01
research poc
Antino Backdoor Uses Microsoft 365 for C2 and Data ExfiltrationAntino backdoor
Researchers discovered a Windows backdoor named Antino that abuses Microsoft 365 services, specifically Outlook and OneDrive, for command-and-control (C2), data theft, and persistent access. The backdoor leverages legitimate cloud services to blend in with normal traffic, making detection difficult.
2026-10-01
incident
GlassWorm Targets macOS via Malicious VS Code ExtensionsGlassWorm macOS campaign
The GlassWorm threat group has expanded to macOS, using malicious Visual Studio Code extensions to deliver encrypted payloads and steal cryptocurrency wallets. This campaign demonstrates a shift in targeting and technique, posing a new threat to macOS users.
2026-10-01
incident
China-Nexus Hackers Compromise 350 Systems Across Asia With New Antino BackdoorAntino
A China-nexus cyber-espionage campaign compromised approximately 350 endpoints across Asia using a previously undocumented Rust-based Windows backdoor called Antino. The backdoor enables attackers to maintain persistent access and exfiltrate data from compromised systems.
2026-10-01
incident
Microsoft Warns of MSP360 RMM Abuse in Phishing AttacksMSP360 RMM abuse in phishing attacks
In July 2026, phishing campaigns distributed a disguised MSP360 RMM installer, which provided attackers with initial access and led to the installation of ScreenConnect for remote control. Microsoft warns that legitimate remote monitoring and management tools are being abused to bypass security controls.
2026-10-01
research poc
New 2CLoader Malware Uses Anti-VM and API Hooking to Deliver Vidar and Remus Stealers2CLoader
Researchers identified a new Windows malware loader named 2CLoader that employs anti-analysis techniques, indirect system calls, API tampering, and in-memory execution to deliver Vidar and Remus stealers. The loader's evasion capabilities pose a challenge to endpoint detection and response (EDR) solutions.
2026-10-01
incident
Warlock Ransomware Attacks Water and Telecom OperatorsWarlock Ransomware
Warlock ransomware targeted water and telecom operators in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. Attackers used a vulnerable signed driver (K7RKScan) to disable security software, abused Visual Studio Code tunneling for covert remote access, and leveraged SYSVOL to spread ransomware across domains. The campaign demonstrated broad domain-wide deployment with an AV/EDR killer component.
2026-09-30
research poc
Russian state hackers use new RedFlick technique to push malwareRedFlick
Russian state actor Star Blizzard has been observed using a new malware installation tactic called RedFlick to deploy its CosmicPulse backdoor. The technique involves abusing legitimate Windows features to evade detection and maintain persistence. This development highlights evolving evasion methods by advanced threat actors.
2026-09-30
research poc
Index Engines research finds ransomware variants built to evade detection and undermine recoveryRansomware variants built to evade detection and undermine recovery
Index Engines' CyberSense Research Lab analyzed ransomware variants and found they are increasingly designed to evade detection and undermine recovery efforts. The research highlights techniques that specifically target detection and recovery mechanisms, making ransomware more resilient against security tools.
2026-09-30
research poc
OpenAI discovers self-replicating prompt injection in AI modelsSelf-replicating prompt injection
OpenAI found that their AI models are vulnerable to a self-replicating prompt injection attack, which could theoretically spread like a worm. This research highlights a new attack vector where malicious prompts can replicate themselves across AI systems.
2026-09-30
incident
Bitget Hackers Planted 25 Days Before $388M Drain via Third-Party Security Product Zero-DayBitget $388M hot wallet drain
Attackers exploited a zero-day vulnerability in a third-party security product to gain database access on Aug. 31, 2025, 25 days before draining $388 million from Bitget's hot wallet on Sept. 24. The breach was reported by SlowMist, highlighting a supply-chain style compromise through a security tool.
2026-09-30
research poc
SectopRAT Malware Hides in Legitimate Software to Steal Browser Credentials and Crypto WalletsSectopRAT
A newly analyzed SectopRAT campaign demonstrates how threat actors weaponize trusted application components to conceal a full-featured remote access trojan. The malware steals browser credentials and cryptocurrency wallet data, posing significant risk to endpoint security.
2026-09-30
research poc
Anthropic warns China's GLM-5.3 model can build cyber exploits autonomouslyGLM-5.3 autonomous exploit generation
Anthropic has issued a warning that China's GLM-5.3 large language model can autonomously generate cyber exploits. The model's capability highlights rapid advancement in AI-driven offensive security and raises concerns about potential widespread malicious cyber activities.
2026-09-29
research poc
Hackers Weaponize ChatGPT Custom GPT Feature to Distribute MalwareChatGPT Custom GPT Malware Distribution
Huntress researchers discovered threat actors abusing ChatGPT's Custom GPT feature to impersonate AI products and trick users into installing a remote access trojan (RAT). The attackers create malicious custom GPTs that appear legitimate, then use them to deliver malware. This highlights the risk of AI platforms being leveraged for social engineering and malware distribution.
2026-09-29
research poc
DPRK-Linked Hackers Add HashHiding to Blockchain C2 Network for Takedown-Resistant MalwareHashHiding
DPRK-linked operators behind the Cross-Chain TxDataHiding (XCTDH) campaign have expanded their blockchain-backed command-and-control infrastructure with a new technique called HashHiding. This technique leverages blockchain transactions to hide C2 communications, making malware more resilient to takedowns.
2026-09-29
incident
China-based actor uses NeedyMantis modular malware for long-term network accessNeedyMantis
Microsoft observed a China-based threat actor deploying NeedyMantis, a modular malware, in intrusions against telecommunications, universities, medical, and government organizations. The malware provides long-term access to compromised networks, enabling persistent espionage and data theft.
2026-09-29
incident
Attackers abuse trusted RMM software to deploy surveillance RATRMM abuse for initial access
Threat actors are abusing trusted remote monitoring and management (RMM) software to gain legitimate-looking access to Windows endpoints, then deploying a full surveillance remote access trojan (RAT). The abuse of legitimate RMM tools allows attackers to blend in with normal administrative activity and evade detection.
2026-09-28
incident
Black Basta Ransomware Gang Operations Exposed via Leaked Chat LogsBlack Basta
Leaked internal chat logs from the Black Basta ransomware group reveal their operational tactics, including the sale of a private loader for $84,000 per month, heavy use of social engineering inspired by Scattered Spider, and reliance on botnets, antivirus evasion techniques, and SOCKS proxies for anonymity.
2026-09-28
incident
Xie Jiayin: First security incident involving third-party security software supply chainXie Jiayin security incident
An attack targeted a third-party security software supply chain, exploiting vulnerabilities in third-party products to obtain internal network credentials. Private keys were not leaked and cold wallet assets remained secure. The incident is classified as a special attack on the security software supply chain.
2026-09-28
research poc
Ransomware Groups Use AI to Build Application-Specific ImplantsAI-assisted application-specific implant development
Ransomware groups are shifting from generic malware to application-specific implants, using AI to generate and iterate exploit code at machine speed. This approach allows them to study target applications' internals and build implants that understand them, increasing effectiveness. The trend highlights a growing sophistication in ransomware operations.
2026-09-28
research poc
Researchers Discover AI-Powered Attack Machine with Exposed Control PanelAI-Powered Attack Machine
ThreatMon researchers discovered an exposed server belonging to an attacker group, revealing an AI-powered attack machine. The server contained operational material including credentials and exploitation tools, indicating automated discovery and attack workflows. This highlights the growing use of AI in offensive operations and the risk of misconfigured attacker infrastructure.
2026-09-28
research poc
Google warns hackers use AI to develop zero-day exploitsAI-assisted zero-day exploit development
Google's Threat Analysis Group reported that attackers used an AI model to identify a previously undiscovered vulnerability and develop an exploit, bypassing two-factor authentication. The vulnerability was patched in collaboration with the affected vendor before large-scale deployment. Forensic analysis suggests the malicious code was AI-generated or heavily assisted.
2026-09-28
research poc
New Tool Detects AI-Guided MalwareAI-guided malware
A new tool has been developed to detect malware that is guided by an AI. The article discusses the transformative shift in the malware landscape in 2026, with AI being used to guide malicious software. This development is significant as it represents an evolution in malware capabilities, potentially making threats more adaptive and harder to detect.
2026-09-28
research poc
TraderTraitor macOS Backdoors Target IT Service Firms via Weaponized Terraform FilesTraderTraitor macOS Backdoors
SentinelOne discovered new macOS backdoors attributed to the TraderTraitor campaign targeting IT service firms. The backdoors are delivered through weaponized Terraform files, indicating a supply-chain style attack on development infrastructure. This research highlights evolving macOS malware techniques used by financially motivated threat actors.
Every event in this brief is a record in ColdRecon's canonical set, drawn from public open-source reporting and linked to its source. This is the general, non-personalized signal — published 7 days after the fact. The live daily brief, written for your deals, is for cleared officers.

This is last week, public. Get this morning's, written for you.

The live ColdRecon brief lands at 0600 daily — the same signal, filtered to your competitors and framed for your deals. Request clearance and tomorrow's is yours.

Request Clearance →