SECURITYWEEK’S roundup highlights a series of developments spanning ransomware, AI systems, supply-chain security and critical infrastructure. ShinyHunters claims it seized and defaced Cl0p’s Tor leak site, stole server logs, source code and private onion-service keys, and demanded an eight-figure payment and public apology. Researchers at Forever disclosed BragJack, in which malicious browser extensions can hijack built-in AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet and Claude in Chrome.
Depending on the product, attackers could read emails, access local files, take screenshots or activate cameras and microphones without user interaction.
A malicious MemTensor package published on npm and PyPI contained the previously unseen sckit Go implant, which activates when libraries are imported or used and searches for credentials across services including npm, PyPI, GitHub, AWS and Hugging Face. Semgrep found templates for propagation but no evidence that the malware had spread.
SpyCloud identified infostealer exposure at 1,787 US water-sector organisations, including OT or remote-access credentials at 258; it stressed these represented potential access paths, not confirmed intrusions. Team Cymru also found nearly 11,000 AI relay servers obscuring users’ locations from model providers.
Other findings include CARBONATO, a Docker botnet targeting unauthenticated daemons on port 2375 and prioritising AI API keys; Cisco Talos’s CLOSEDQUORUM implant, which uses commercial LLMs to choose malicious actions but has not been confirmed in the wild; and CVE-2026-42542, a pre-authentication denial-of-service flaw in TDengine versions 3.4.0.0 through 3.4.1.5, fixed in 3.4.1.6. Canonical said it would move to weekly kernel releases and provide workarounds within 24 to 48 hours of public disclosure.