ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

In the ever-evolving landscape of cybersecurity, this week has revealed a series of threats that masquerade as benign tools and applications, making them particularly insidious. The common thread among these threats is not merely advanced hacking techniques but rather a clever exploitation of borrowed trust—leveraging familiar names, permissions, and seemingly harmless actions to execute malicious intents.

Security Changes and Threats

GitHub recently announced a significant security update that will impact support bundle uploads from older versions of GitHub Enterprise Server (GHES). Effective August 18, 2026, command-line support bundle uploads from outdated GHES appliances lacking the necessary security patches will be rejected. Users are urged to update their systems to the latest patch versions to avoid disruptions.

Meanwhile, a troubling npm package, @copilot-mcp/apex, has been identified as a post-install dropper that installs a macOS infostealer. This malicious payload not only phishes for sensitive information but also establishes a persistent connection to the attacker’s command-and-control server, ensuring ongoing access to the compromised system.

In a similar vein, a rogue extension on the Microsoft Visual Studio Code marketplace, disguised as “Markdown All Pro,” has been found to impersonate a legitimate tool. Upon installation, it sends machine details to an attacker and opens a backdoor for further commands. Despite its removal, the extension reappeared under a slightly altered name, highlighting the persistent nature of such threats.

Phishing and Malware Campaigns

Phishing continues to be a favored tactic among cybercriminals, with a new campaign targeting Portuguese users through deceptive emails that deliver the Lampion banking malware. This malware, which has been active since 2019, employs complex obfuscation techniques to evade detection, complicating the analysis of its malicious activities.

Additionally, DoubleVerify has reported a surge in “AfterCall” apps that exploit user permissions to display intrusive ads immediately after phone calls. This ad fraud scheme has generated hundreds of millions of ad impressions, showcasing the lengths to which attackers will go to monetize their efforts.

Innovative Attack Techniques

A novel attack method known as GhostCommit has emerged, utilizing pull requests to hide malicious instructions within PNG images. This technique allows attackers to steal repository secrets without detection, as the image appears benign to text-based reviewers.

In another alarming development, the U.S. government has updated its advisory regarding Iranian-affiliated cyber activity targeting operational technology devices. This includes attempts to manipulate data on critical infrastructure systems, emphasizing the need for robust security measures in these environments.

Surveillance and Data Harvesting

Dream has uncovered an Android app masquerading as a civil defense alert system that embeds malware capable of extensive data harvesting. This app, distributed through look-alike domains, exemplifies the use of social engineering to trick users into installing malicious software under the guise of public safety.

Moreover, an Iranian threat actor has been observed distributing MarkiRAT malware through fake applications, targeting individuals both inside and outside Iran. This highlights the ongoing surveillance operations linked to state-sponsored actors.

AI and Vulnerabilities

As artificial intelligence continues to permeate various sectors, vulnerabilities in AI-generated code have come to light. An analysis of 28 AI-coded applications revealed 434 unique vulnerabilities, with many stemming from inadequate security measures. Cisco’s introduction of Antares, a family of security small language models, aims to address this issue by pinpointing vulnerabilities within codebases more efficiently.

In a concerning twist, a Russian-speaking threat actor has been dismantling guardrails on AI models to create offensive tools, showcasing how quickly adversaries can adapt and leverage emerging technologies for malicious purposes.

As the cybersecurity landscape becomes increasingly complex, the imperative for vigilance grows. The question now extends beyond merely assessing safety; it encompasses understanding the potential repercussions of seemingly innocuous actions. As threats evolve, so too must our approach to security, ensuring that even the smallest actions are scrutinized for their potential impact.

AppWizard
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories