Generated · Archived snapshot 15 findings · 2 CVEs
On this page

Exploitation Report

Executive Summary

Active exploitation campaigns are intensifying across multiple vectors, with threat actors leveraging both newly disclosed critical vulnerabilities and AI platforms to accelerate attacks. GitLab's maximum-severity path traversal flaw (CVE-2026-85706) drew in-the-wild probes within hours of disclosure, while Cisco FMC authentication bypass (CVE-2026-20079) is being exploited by three distinct threat clusters—including ransomware and state-sponsored groups—to steal credentials and deploy Qilin ransomware. Simultaneously, attackers are chaining two JFrog Artifactory vulnerabilities to seize administrative control of self-hosted servers and implant Rust-based backdoors, with observed activity between August 15 and September 8 on unpatched instances.

A parallel surge in AI-assisted operations sees Russian state-sponsored actors (GTG-20006, linked to Midnight Blizzard) using Claude to rebuild malware after detection, while seven China-based AI labs conduct industrial-scale model distillation attacks. Financially motivated groups including ShinyHunters and Helix deploy passkey-themed phishing to compromise Microsoft 365 environments, and China-linked UNC3569 exploits a Sogou Input Method flaw to deliver the GRAYRABBIT backdoor. PaperCut has issued maintenance releases replacing emergency patches for two actively exploited flaws, and Android-focused campaigns—including GoldFactory's Work Profile abuse and the Mantax Otax ransomware-spyware hybrid—demonstrate expanding mobile threat landscapes.

Active Exploitation Details

CriticalActive exploitationPatchCVE-2026-85706#

  • Description: A maximum-severity path traversal vulnerability in the GitLab repository commits API that allows an unauthenticated user to read arbitrary files from the GitLab server.
  • Impact: Unauthenticated remote attackers can access sensitive files on the GitLab server, potentially including configuration files, source code, and authentication tokens.
  • Status: Actively probed in the wild within hours of public disclosure; patches released by GitLab.

CriticalActive exploitationPatchCVE-2026-20079#

  • Description: An authentication bypass vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) software that allows an unauthenticated, remote attacker to bypass authentication controls.
  • Impact: Attackers can gain unauthorized administrative access to FMC, enabling credential theft and deployment of Qilin ransomware.
  • Status: Actively exploited by three distinct threat clusters (ransomware and state-sponsored) since recent patch release.

CriticalActive exploitationPatch#

  • Description: Two vulnerabilities in JFrog Artifactory that attackers chain to bypass authentication and gain administrative privileges on self-hosted servers, followed by deployment of a Rust-based backdoor.
  • Impact: Full administrative control of Artifactory instances, allowing supply chain compromise through malicious artifact injection and persistent backdoor access.
  • Status: Actively exploited between August 15 and September 8, 2026; JFrog released fixes prior to observed attacks, leaving only unpatched servers vulnerable.

CriticalActive exploitationPatch#

  • Description: Two security flaws in PaperCut NG/MF that have come under active exploitation, prompting emergency patches now replaced by regular maintenance releases.
  • Impact: Attackers can exploit these flaws to compromise PaperCut print management servers, potentially leading to lateral movement and data access.
  • Status: Actively exploited; PaperCut released versions 26.0.5, 25.0.13, and 24.1.10 as regular maintenance releases replacing earlier emergency patches.

HighActive exploitationPatch#

  • Description: A vulnerability in Sogou Input Method, a widely used Chinese character input tool for Windows, exploited via a crafted link to install the GRAYRABBIT backdoor.
  • Impact: Attackers gain the same privileges as the logged-in user, enabling full system control, data theft, and persistent access via the GRAYRABBIT backdoor.
  • Status: Actively exploited by China-linked threat group UNC3569; Tencent (Sogou owner) notified.

HighActive exploitationInvestigate#

  • Description: Multiple threat groups—including financially motivated and state-sponsored espionage actors linked to Russia and China—abuse Anthropic's Claude AI model to extract secrets from 1.8 million Android applications.
  • Impact: Massive credential harvesting from Android apps, enabling supply chain attacks, unauthorized access to backend services, and intellectual property theft.
  • Status: Ongoing campaigns identified and disrupted by Anthropic between December 2025 and August 2026.

HighActive exploitationMitigate#

  • Description: Social engineering campaigns using passkey and single sign-on-themed lures to compromise corporate Microsoft accounts and exfiltrate data from Microsoft 365 services.
  • Impact: Unauthorized access to corporate Microsoft 365 environments, data theft, and potential business email compromise.
  • Status: Active campaigns attributed to ShinyHunters, Helix, and other extortion gangs.

HighActive exploitationMitigate#

  • Description: Threat actors weaponize trusted AI platform features—including Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures—to host malicious content, poison search results, and trick users into installing malware.
  • Impact: Malware delivery, credential harvesting, and initial access via social engineering leveraging trust in legitimate AI platforms.
  • Status: Active campaigns observed by Huntress targeting AI users.

HighObservedMonitor#

  • Description: Russian state-sponsored threat actor GTG-20006 (aligned with Midnight Blizzard) uses Claude for an AI-assisted workflow to rapidly rebuild malware after detection, staying ahead of defensive signatures.
  • Impact: Accelerated malware iteration and evasion capabilities, reducing defender response windows and increasing campaign resilience.
  • Status: Campaign disrupted by Anthropic; attributed to GTG-20006.

MediumObservedMonitor#

  • Description: Seven China-based AI labs (Alibaba, Moonshot, DeepSeek, Z.ai/Zhipu, MiniMax) conduct industrial-scale illicit knowledge distillation attacks against Claude to replicate model capabilities without authorization.
  • Impact: Intellectual property theft, model capability replication, and potential erosion of AI safety controls.
  • Status: Identified and disrupted by Anthropic; ongoing industrial-scale activity.

HighActive exploitationMitigate#

  • Description: The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, targeting banking applications in Indonesia.
  • Impact: Financial credential theft, banking fraud, and persistent mobile device compromise.
  • Status: Active campaign targeting Indonesian users.

HighActive exploitationInvestigate#

  • Description: A new Android malware strain combining ransomware and spyware capabilities to encrypt files, steal sensitive data, and harass victims via spam.
  • Impact: Data encryption, exfiltration of personal information, financial loss, and psychological harassment.
  • Status: Active distribution; capabilities include ransomware, spyware, and harassment modules.

HighObservedInvestigate#

  • Description: Attackers accessed the Florida Department of Highway Safety and Motor Vehicles (FLHSMV) DAVID driver database using credentials stolen from a police department employee.
  • Impact: Exposure of driver license records and personal identifiable information for Florida residents.
  • Status: Confirmed breach; investigation ongoing.

HighObservedInvestigate#

  • Description: Phishing attacks targeting 347,000 Trezor cryptocurrency wallet users using email addresses exposed in the Brevo breach, with 2,500 users clicking malicious links.
  • Impact: Cryptocurrency wallet compromise, credential theft, and financial loss for affected users.
  • Status: Active campaign leveraging breached contact data.

HighObservedMonitor#

  • Description: Threat actors leverage Microsoft's Graph API to identify high-value targets in BYOD environments, then pass access to extortion groups including ShinyHunters.
  • Impact: Targeted credential theft, data exfiltration from Microsoft 365, and extortion operations.
  • Status: Active technique observed in voice caller campaigns.

Affected Systems and Products

Attack Vectors and Techniques

Threat Actor Activities