Connect with us

Security

GhostJacking AI: The Rise of EtherHiding ClickFix and Other Cyber Threats

Published

on

into valid HTML code with proper indentation.


<div id="articlebody" readability="85.633492543133"><br />
  <div class="separator"><br />
    <img decoding="async" alt="" border="0" data-original-height="470" data-original-width="900" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnZSPrbeVOhfz52pccm_PbosfzvUlARZ8YoAhLmLd28aHQJ0Nw4T-TeYS2gCgc4bQaNS_c7sFfSFY-tQdGZDD4Uajt1hFhjPzl-XZVyoM72eC5vYStjyfuKwis_vDgrvUgTK7MUJx0kkEHwBJxmIuqp6qkPB-km81UXl6ycj1u9uIORUrVXtYz9L5-Julh/s1600/td.jpg"><br />
  </div><br />
  <p>Some weeks have one big security story. Others bring many smaller updates that are easy to miss but still matter. This week has plenty of them, covering cloud services, AI tools, malware, data breaches, scams, and new attack methods.</p><br />
  <p>The latest ThreatsDay Bulletin puts all of these short updates in one place, so you can quickly catch up on what happened, what changed, and what security teams should know.</p><br />
  <div class="article-board" readability="34"><br />
    <b></b><br />
    <p>The threats change every week. <span data-push-label="ThreatsDay Bulletin" data-push-topic="threatsday bulletin:t, recap:i">Subscribe, and we’ll alert you</span> when each new ThreatsDay Bulletin is out.</p><br />
  </div><br />
  <div class="td-wrap"><br />
    <section aria-labelledby="threatsday-title" class="td-section"><br />
      <ol class="td-timeline" role="list"><br />
        <li class="td-item" readability="5.6299559471366"><br />
          <span aria-hidden="true" class="td-dot"></span><br />
          <div class="td-stack" readability="21.581497797357"><br />
            <span class="td-punch">Guest Access Data Theft</span><br />
            <p class="td-desc"><br />
              An ongoing campaign dubbed City-Forum has been observed targeting unauthenticated guest user access in both Salesforce Experience Cloud sites and ServiceNow (SNOW) Service Portals. "A single server is pulling records out of Salesforce Experience Cloud sites and ServiceNow (SNOW) Service Portals, from infrastructure that has been standing since March 2025," Reco said. "Except for Aura, the attacker reaches Salesforce Lightning Web Runtime (LWR) sites through the UI-API, a data layer we have not seen any public tool or write-up about, and it hammers a native ServiceNow Service Portal search endpoint that has almost no online documentation or well-known open source tools." The IP address in question is 158.220.87[.]79, which resolves to the domain "city-forum[.]com," giving the campaign its name. The use of little known techniques in the activity points to an advanced threat actor. Data is exfiltrated from Salesforce LWR sites using GraphQL. Targets include telecoms, banks and financial-services firms, enterprise-software vendors including security and data-privacy companies, and public-sector portals. Per Reco, the busiest target recorded more than 560,000 events from the attacker’s IP address, with nearly all of them related to guest Aura enumeration.<br />
            </p><br />
          </div><br />
        </li><br />
        <li class="td-item" readability="5.5991649269311"><br />
          <span aria-hidden="true" class="td-dot"></span><br />
          <div class="td-stack" readability="21.463465553236"><br />
            <span class="td-punch">Customer Data Exposed</span><br />
            <p class="td-desc"><br />
              ShipMonk, one of Trezor’s shipping providers, has experienced a data breach that exposed sensitive customer order data, including full names, shipping addresses, phone numbers, and email addresses. "This data breach can potentially affect new customers who received an order from the following countries: the U.S., the U.K., Sweden, Colombia, Brazil, Italy, and Portugal between 10th of May and 8th of August 2026," Trezor said.<br />
            </p><br />
          </div><br />
        </li><br />
        <li class="td-item" readability="5.237539766702"><br />
          <span aria-hidden="true" class="td-dot"></span><br />
          <div class="td-stack" readability="20.950159066808"><br />
            <span class="td-punch">Pre-Trust Code Execution</span><br />
            <p class="td-desc"><br />
              Cursor has fixed an issue in its command-line (CLI) coding agent that allowed a cloned repository to run any command on a developer’s machine before they were prompted if they trusted it, and outside the sandbox even when the sandbox had been explicitly enabled. "A repository could execute any command it chose on your machine, as you, the moment you started Cursor’s CLI agent in it with -w," Manifold Security said. "It ran before the workspace-trust dialog, and fired even for users who had explicitly passed –sandbox enabled. The command sat in a normal tracked file, .cursor/worktrees.json, so it arrived with an ordinary git clone. Nothing on that path constrained it: reading ~/.ssh, taking cloud credentials from the environment, opening a reverse shell, writing persistence." Following responsible disclosure on July 20, 2026, a patch was released three days later.<br />
            </p><br />
          </div><br />
        </li><br />
        <li class="td-item" readability="7.2707160096541"><br />
          <span aria-hidden="true" class="td-dot"></span><br />
          <div class="td-stack" readability="25.205148833467"><br />
            <span class="td-punch">Vishing at Scale</span><br />
            <p class="td-desc"><br />
              Okta has published details about Work Panel, an operator console that’s used by threat actors running vishing campaigns targeting identity providers, including itself. "Work Panel is a multi-tenant platform that packages everything an operator needs to run a vishing-driven account takeover operation," the company said. "Registering a new phishing domain, cloning a target brand, and standing up a new isolated phishing site are each one-button operations. New campaigns can be launched in minutes." Work Panel is used by infrastructure owners, campaign managers, and outsourced callers, indicating a cybercrime ecosystem that supports such voice phishing campaigns at scale. One threat actor that uses Work Panel is UNC6671 (aka Cordial Spider and O-UNC-045). "It is a full web application designed to run a vishing-driven account takeover business," Okta added. "The console organizes the work into multiple sections covering target recon, voice-call routing, brand cloning, infrastructure provisioning, live session management, captured-credential review, and an audit log. Different roles see different tabs, and the access boundary is enforced on the server rather than hidden in the client."<br />
            </p><br />
          </div><br />
        </li><br />
        <li class="td-item" readability="3.7606244579358"><br />
          <span aria-hidden="true" class="td-dot"></span><br />
          <div class="td-stack" readability="17.862966175195"><br />
            <span class="td-punch">AI Agent Hijacking</span><br />
            <p class="td-desc"><br />
              A new attack called GhostJacking expands on Agentjacking to trick AI agents into running arbitrary code on developer machines, once again highlighting the need for securing the AI supply chain. The attack can leverage something as simple as a poisoned log or alert to make the agent act on the attacker’s data, escalate privileges and pivot to enterprise cloud infrastructure, exfiltrate data to the attacker (in this case, using a now-patched sandbox escape in Anthropic’s Claude Desktop), and establish persistence by leaving a backdoor in the agent’s configuration. "Companies are handing AI agents the keys to their code, their monitoring, and their infrastructure," Tenet Security said. "An AI cannot tell a real instruction from a trap hidden in the data it reads. The usual defenses do not fire, because nothing breaks a rule. Every step is something the agent was already allowed to do." The findings underscore the need for guardrails around AI agents to protect against hijacking attacks that leverage their legitimate access and elevated privileges against their users.<br />
            </p><br />
          </div><br />
          <div class="separator"><br />
            <img decoding="async" alt="" border="0" data-original-height="661" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwd4FEitpGh_Bq9WOmPScNVuDIClU5wvRrrdxi1TwXgdQLxWsMVsULFDKe-EKLXNzwjzpKqcM_-klB1U_8ldJj4vzWaatC1ID5quYfwP9kyKYbYIvv4D0XVNKEEL9zZ469xosmnNvCRxfVYz9rV5_L7HR7p73W4fwNQf2Bz095gSzRG4jJ73dfs0HM-9Xb/s1600/zero.jpg"><br />
          </div><br />
        </li><br />
        <li class="td-item" readability="2.8378378378378"><br />
          <span aria-hidden="true" class="td-dot"></span><br />
          <div class="td-stack" readability="16.081081081081"><br />
            <span class="td-punch">On-Device Scam Detection</span><br />
            <p class="td-desc"><br />
              Meta has announced a new optional feature called Scam Alert that makes use of an on-device machine learning model to alert a user about potential scam messages.<br />
            </p><br />
          </div><br />
        </li><br />
      </ol><br />
    </section><br />
  </div><br />
</div><br />
```     </p><br />
</div><br />
</li> Standard binary reputation lookups, signature validation, and application allow-listing controls failed to trigger alerts because the malicious payload was entirely contained within the uncompiled script content of an add-on skill package. <h2>The Evolution of Cyber Threats in Q2</h2><br />
<p>In the second quarter of the year, the landscape of cyber threats continued to evolve. The extortion model, which was previously focused on encryption, shifted towards data theft-only operations. Additionally, there was a rise in geopolitically influenced activity, with state-aligned actors operating behind ransomware branding. Some of the notable threat actors responsible for the largest victim volumes during this period were Qilin (140), Akira (129), The Gentlemen (125), DragonForce (76), and LockBit 5.0 (62).</p><br />
<br />
<h2>Expanding Malware Alerts</h2><br />
<p>GitHub announced enhancements to the GitHub Advisory Database to include malware reports from OpenSSF's malicious-packages repository. This update covers eight major package ecosystems, including npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. Users can now receive alerts from Dependabot and GitHub if they are using a malicious dependency across these ecosystems. Malware alerts are opt-in and can be enabled in repository, organization, or enterprise security settings.</p><br />
<br />
<h2>Surge in Hyper-Volumetric DDoS Attacks</h2><br />
<p>Cloudflare reported a significant increase in hyper-volumetric DDoS attacks, with the company mitigating 23.2 million network-layer and 29.64 trillion HTTP DDoS requests since the beginning of 2026. These attacks, defined as exceeding 1 Tbps, 1 Bpps, or 1 Mrps, have surged in frequency. Cloudflare mitigated 805 network-layer attacks exceeding 1 Tbps, marking a six-fold increase from the previous quarter. The most targeted industries included media, gambling, IT services, computer software, and telecommunications providers. The U.S., China, Indonesia, Turkey, and France were the most attacked locations, with traffic originating from Brazil, the U.S., Indonesia, China, and Germany.</p><br />
<br />
<p>The key takeaway from these developments is that attacks are becoming more sophisticated, often leveraging trusted tools and features to exploit vulnerabilities. It is crucial for defenders to stay vigilant and adapt to the changing threat landscape.</p><br />
<br />
<p>While individual security incidents may seem isolated, they collectively highlight the dynamic nature of cybersecurity and the need for continuous monitoring and adaptation. New vulnerabilities, scam tactics, malware strategies, and defensive measures all contribute to the evolving cybersecurity environment, emphasizing the importance of proactive defense strategies.</p>
See also  Undercover: IT Support Turned Cyber Threat in Microsoft Teams Attack

Trending