← All issues
cybersecurityCyberBubbleransomware

The First AI-Run Ransomware Attack Is Here — and It Did Everything Itself

🌐  World Intel
UK: Two Scattered Spider Members Plead Guilty Over Transport for London Hack

Thalha Jubair, 20, and Owen Flowers, 18, admitted in a UK court to breaking into Transport for London's computer systems in August 2024 — an attack that disrupted the city's entire public transport network. Flowers also admitted involvement in hacking two US healthcare providers, and Jubair faces a separate US indictment alleging he helped orchestrate 120 network break-ins that earned the group at least $115 million in ransom payments. The guilty pleas came on the very first day of what was expected to be a six-week trial.

↗ Krebs on Security
USA: FBI Seizes NetNut Proxy Network, Cuts Off 2 Million Compromised Devices

The FBI seized hundreds of domains belonging to NetNut, a service run by Israeli company Alarum Technologies that secretly turned smart TVs and streaming boxes into botnet nodes. Security firms found that at least two million home devices were quietly roped into relaying criminal traffic — including account takeovers and ad fraud — without their owners knowing. Google helped by disabling NetNut's accounts and sharing intelligence with law enforcement, and the company's parent says it will cooperate with investigators.

↗ Krebs on Security
China-Linked Hackers Target US and Canadian University Physics Departments

A suspected China-aligned hacking group tracked as UNK_MassTraction has been exploiting flaws in Roundcube webmail to break into physics, engineering, and astrophysics departments at North American universities since May 2026. The attackers stole login credentials and installed hidden tools to maintain long-term access — specifically targeting departments with national security research ties. The vulnerability used has been patched, but university IT teams need to confirm their systems are updated.

↗ The Hacker News
⚔️  Active Attacks
Fake IT Support Calls on Microsoft Teams Installing Malware

Criminals are calling employees through Microsoft Teams, pretending to be company IT support staff. Once they have the employee's trust, they talk them into installing a piece of malware called EtherRAT, which quietly hands attackers full access to that person's work computer and the broader corporate network. This is a classic social engineering attack — no technical flaw is exploited, just human trust. Microsoft Teams is a particularly convincing disguise because many employees already expect IT calls to come through it.

🛡 What to do: Verify any unexpected IT support contact by calling your company's official helpdesk number directly — never trust a caller just because they appeared in Teams. Your real IT team will never ask you to install software during an unscheduled call.
Fake Job Interview Emails Stealing Google Accounts from Marketing Professionals

A phishing campaign is impersonating over 30 big-name brands — including Adobe, Netflix, Coca-Cola, and OpenAI — to lure marketing professionals with fake job interview invitations. Clicking through leads to a page that harvests the victim's Google account credentials. The campaign is deliberately targeted: attackers know marketing professionals are likely to apply for jobs at recognizable companies and are less likely to question a familiar logo.

🛡 What to do: Always go directly to a company's official careers page to verify any job offer you receive by email — and never enter your Google password on a page you reached by clicking a link in an unsolicited message.
🔓  New Vulnerabilities
CVE-2026-11405 Tenda Router Firmware CRITICAL

Several popular Tenda home and business routers contain a hidden backdoor baked directly into the router's software. An attacker on your network — or in some cases over the internet — can use it to take full administrative control of your router without needing a password at all. Affected models include the FH1201, W15E, AC10, AC5, and AC6. Because your router controls all traffic flowing in and out of your home or office, this is about as serious as it gets.

Status: No official patch from Tenda as of publication. CERT/CC has issued an alert. If you own an affected model, check Tenda's website for updates and consider replacing the device if no fix is released promptly.

CVE-2026-40138 / CVE-2026-40139 BeyondTrust Remote Support & PRA CRITICAL 9.2

BeyondTrust makes software that IT teams use to remotely access and fix employees' computers. Two newly discovered flaws let an attacker log in without any valid credentials at all — effectively walking in through the front door without a key. Because this software is designed to give deep access to corporate systems, a successful exploit could hand criminals the keys to an entire organization's IT infrastructure.

Status: Patches are available now. If your organization uses BeyondTrust Remote Support or Privileged Remote Access, apply the updates immediately.

CVE-2024-42009 Roundcube Webmail CRITICAL 9.3

This flaw in the Roundcube webmail platform — the kind of email system many universities and smaller organizations run themselves — allowed attackers to steal login credentials and plant hidden tools for persistent access. China-linked hackers have actively been exploiting it against US and Canadian universities since at least May 2026. The vulnerability has been patched by Roundcube, but any organization that hasn't updated is still exposed.

Status: Patch available. Update Roundcube immediately and review server logs for signs of unauthorized access or web shells.

🛠  New Tech
Januscape: A 16-Year-Old Linux Flaw That Lets Attackers Break Out of Virtual Machines

Researchers disclosed a vulnerability in the Linux kernel — nicknamed Januscape — that has apparently sat undetected for 16 years. It allows an attacker already inside a virtual machine to break out and run code on the underlying host system — effectively escaping the digital sandbox meant to contain them. This affects both Intel and AMD devices. The discovery matters because virtual machines are widely used by businesses to keep workloads separated and secure; a VM escape shatters that isolation entirely. Organizations running Linux-based virtualization environments should watch for kernel patches and apply them as soon as they land.

💡  Deep Dive
AI Just Ran Its First Solo Ransomware Attack — and It Did the Whole Thing Itself

For years, security researchers warned that AI would eventually be weaponized for cyberattacks. This week, that future arrived. Researchers documented what they believe is the first ransomware attack planned and carried out entirely by a large language model AI agent — no human hacker directing each step. The operation, linked to a group called JadePuffer, used the AI to automate the entire chain: finding a target, breaking in, moving through the network, encrypting files, and delivering a ransom demand.

Think of it like this: traditional ransomware attacks are like a burglar who cases a house, picks the lock, grabs valuables, and leaves a note — but that burglar still has to show up and do the work. JadePuffer handed all of that to a robot that never sleeps, never gets nervous, and can run dozens of jobs simultaneously. The AI agent made real-time decisions, adapting its approach based on what it encountered inside the victim's systems, without waiting for a human to type the next instruction.

For regular people and businesses, this changes the math on how fast attacks can happen. Human-run ransomware operations are constrained by time zones, fatigue, and the number of skilled criminals available. An AI agent has none of those limits. Security teams that rely on having hours or days to detect and respond to an intrusion may find that window shrinking dramatically. The speed advantage that defenders have always quietly relied on is now under threat.

What to watch for: whether other criminal groups rush to copy this approach, and whether the cybersecurity industry can build equally fast AI-powered defenses in response. The CISA and security vendors are almost certainly already studying the JadePuffer case closely. If AI-automated attacks become common, the concept of a human reviewing every security alert before acting will need to be rethought entirely.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →