The AI Is Writing the Exploits Now: SonicWall Zero-Days, Aurora Ransomware, $600K API Theft, and a Week That Rewired Everything | SunsetHost Hacker News
SunsetHost Hacker News
Feature Edition  |  August 29 – September 2, 2026
Five Days. One Story. Everything Changed.

The AI Is Writing the Exploits Now. The Humans Just Point It at a Target.

SonicWall zero-days chained into one attack path. Aurora ransomware operators running Cursor AI to break into networks. Researchers porting PLC exploits between industrial controllers with Claude. A $600,000 API theft from an AI safety research organization. ClickFix evolving into TerminalFix. Five WordPress plugins opening sites to full takeover. A humanoid robot with root RCE over Bluetooth. And the week ended with the EU telling organizations they now have to report vulnerabilities they are not yet required to fix.

Zero-Day Chaining AI-Assisted Exploitation SonicWall SMA 1000 Aurora Ransomware Fire Ant / Cisco IOS XR METR API Theft GuardBreaker TerminalFix Cosmos EVM UAC-0099
Active exploitation confirmed across multiple stories this edition. Critical patches require immediate verification.
2
SonicWall Zero-Days Chained
$600K
AI API Credits Stolen
5
WordPress Plugins Compromised
19
Crypto-Draining Extensions
6
Blockchains Drained
255
Fake Accounts Used in Excel Campaign
9.8
Switchvox CVSS Score
Sept 11
EU CRA Reporting Starts
The Core Argument

AI Is No Longer Helping Attackers. It Is Becoming the Attacker.

Three distinct stories this week confirmed what previous editions of this publication have been tracking across the past two months: artificial intelligence has moved from productivity tool to autonomous offensive operator, and the people pointing it at targets do not need to understand the techniques it uses to execute them successfully.

Aurora ransomware operators used Cursor AI, the AI-powered coding assistant, to break into ten target networks. Forescout Research used Claude to port a working pre-authentication remote code execution exploit from one WAGO programmable logic controller model to another, executing attacker-controlled code on industrial hardware that was never the original exploit’s target. And METR, an AI safety research organization that exists specifically to evaluate frontier AI models for dangerous capabilities, had its API key stolen and approximately $600,000 in AI credits consumed by an attacker who used that access to run their own workloads on infrastructure METR paid for.

The Aurora ransomware group did not need to write exploit code. They directed Cursor AI at the target network and it found the path in. The AI did not know it was committing a crime. It just solved the problem it was given.

The Forescout research is technically distinct because it was conducted as authorized security research, not as an attack. What it demonstrates, deliberately and in documented detail, is that an AI model can take a working exploit for one industrial controller and adapt it to run successfully on a different model with different firmware, without the researcher needing deep expertise in the target platform’s specific architecture. The time required for that adaptation dropped from what would previously have taken a specialist days to what Claude accomplished in a single session.

Industrial control systems. Two different PLC models. One AI. One session.

Shadow AI compounds all of this. Researchers identified malicious AI skills, MCP servers, plugins, and repository configurations hiding inside platforms that organizations have already approved and deployed. The malicious components steal credentials, exfiltrate data, and execute code while appearing to be legitimate extensions of sanctioned tools. The AI governance problem is not just about what your employees are doing with AI you did not authorize. It is now also about what is hiding inside the AI infrastructure you did authorize.

Zero-Day / VPN Appliance

Two SonicWall SMA 1000 Zero-Days Chain Into a Single Attack Path Against Enterprise VPN Infrastructure

Active Zero-Day Exploitation / SonicWall SMA 1000 Series

SonicWall disclosed two zero-day vulnerabilities this week in its Secure Mobile Access 1000 series VPN appliances, confirmed as exploited in attacks, and the detail that has enterprise security teams most concerned is the chaining relationship between them. The two flaws appear to function as components of a single attack chain, with one vulnerability creating the access condition that the second exploits to achieve its full impact.

VPN appliances are perimeter infrastructure by definition. They are the devices that control remote access to the internal network, authenticate users before they reach internal resources, and in many enterprise architectures, represent one of the few externally reachable management surfaces. Chained zero-days in VPN infrastructure means two things simultaneously: an attacker who can reach the device from the internet may be able to achieve the full exploit chain without authentication, and the device being targeted is the one controlling who else gets in.

A zero-day in your VPN appliance is not a vulnerability in one server. It is a vulnerability in the door through which every remote employee and every remote access session enters your network. Compromise the appliance, and you become the gatekeeper.

SonicWall has released patches. Organizations running SMA 1000 series appliances that are internet-exposed should treat this as the highest-priority patch event on the queue this week, ahead of everything else, because the attack surface is the perimeter itself and the exploitation is already confirmed in the wild.

Ransomware / AI-Assisted Attack

Aurora Ransomware Used Cursor AI to Break Into Ten Networks. SpaceX’s Coding Tool. Used for Ransomware.

Aurora / Aur0ra Ransomware Group

Cloudbric confirmed this week that threat actors associated with the Aurora ransomware operation used Cursor, the AI-powered coding assistant backed by SpaceX, to conduct intrusions against ten target networks. Cursor is designed for developers. It reads codebases, generates code, and helps engineers solve technical problems faster. Aurora’s operators used it to solve the technical problem of breaking into networks they did not have access to.

The specific operational details of how Cursor was directed at the targets are still being analyzed, but the confirmed use of a commercial AI coding assistant in active ransomware intrusions represents a documented expansion of the AI-assisted attack pattern beyond what was visible even two weeks ago. The Hermes agent framework, used in the Thailand Ministry of Finance attack and the DeepSeek autonomous attack campaign covered in previous editions, required some level of configuration expertise. Cursor is a mainstream developer product with a polished interface designed for non-expert users.

Ten networks. One AI coding tool. No advanced exploit development required.

The implication for the threat actor population is that the technical barrier to conducting sophisticated network intrusions continues to compress. Aurora did not need to develop custom tooling, purchase exploit code, or hire technical specialists. They used software that is available to any developer with a subscription, pointed at targets, and used its output to navigate the attack.

AI Infrastructure Theft

Someone Stole METR’s API Key and Ran $600,000 in AI Workloads on an Organization That Studies AI Safety

METR, the Model Evaluation and Threat Research nonprofit that evaluates frontier AI models for their capacity to carry out dangerous long-horizon agentic tasks, had its API key compromised and approximately $600,000 worth of AI compute credits consumed by an attacker who used the stolen credentials to run their own workloads. The target is specifically notable: an organization whose work involves understanding how AI models can be used to cause harm was itself harmed through its AI infrastructure credentials.

API key theft for AI platform access represents an emerging category of credential theft that is distinct from traditional credential compromise. Stolen cloud credentials have historically provided access to compute, storage, and services. Stolen AI API credentials provide access to large language model inference at scale, which has its own market value for training data generation, automated content production, and in the case of frontier model access, capabilities that are otherwise gated behind capacity limits and pricing.

Credits Consumed
$600K
Approximate value of stolen AI compute
Target
METR
AI safety evaluation nonprofit
Vector
API Key
Credential theft for inference access

For organizations with AI API credentials in their infrastructure, the METR incident is a direct argument for treating those credentials with the same rigor applied to cloud provider root credentials. Rotation schedules, usage monitoring with anomaly alerting, and minimum-necessary permission scoping for API keys are controls that apply here. $600,000 in consumed credits is detectable if the monitoring exists. It is invisible if it does not.

Nation-State / Network Infrastructure

Fire Ant Moves From VMware Hypervisors to Cisco IOS XR Routers to Steal Credentials and Destroy Logs

Fire Ant / China-Nexus Espionage Actor

The China-linked espionage actor tracked as Fire Ant expanded a long-running campaign this week beyond its previously documented VMware hypervisor targeting to compromise Cisco IOS XR routers and Terminal Access Controller Access-Control System servers. The expansion is operationally significant because TACACS servers are authentication infrastructure: they control who can log in to network devices and what those users are permitted to do once authenticated.

Compromising a TACACS server gives Fire Ant visibility into authentication events across the network device environment and potentially the ability to harvest the credentials that administrators use to manage routers, switches, and firewalls. Blinding security logs is the second documented objective: an attacker who can clear or suppress logging on network infrastructure can conduct ongoing operations in that environment without generating the event records that monitoring tools depend on for detection and investigation.

Compromise the TACACS server and you can see every credential that authenticates to every network device it manages. Blind the logs on those devices and none of that activity is recorded. Fire Ant did both.

Network infrastructure compromise of this depth is persistent espionage infrastructure. Fire Ant is not conducting smash-and-grab data theft. They are building the access to conduct long-term, low-visibility intelligence collection from inside the network management layer, where they can observe traffic, intercept authentication, and operate below the detection threshold of endpoint and application monitoring tools that do not have visibility into network device management plane activity.

Social Engineering / Malware Delivery

TerminalFix Evolves ClickFix Into a Reverse-Tunnel Backdoor Delivered Through Fake Cloudflare CAPTCHAs

Microsoft disclosed TerminalFix this week, a new variant of the ClickFix social engineering technique that directs victims to run malicious commands in Windows Terminal or PowerShell rather than in a browser. The delivery mechanism is a fake Cloudflare CAPTCHA that instructs the user to paste a command to prove they are human. The command installs a reverse-tunnel backdoor that provides the attacker with persistent remote access to the compromised machine.

The ClickFix family’s evolution is worth tracking as a case study in how effective social engineering techniques adapt to maintain their effectiveness as awareness of specific variants increases. The original ClickFix technique placed malicious commands on the clipboard and directed users to paste them. TerminalFix improves on this by targeting Windows Terminal, which runs with whatever permissions the user holds and which many technically sophisticated users treat as a trusted environment precisely because they are comfortable running commands in it.

Fake CAPTCHA. Clipboard. Terminal. Reverse tunnel. Done.

The fake Cloudflare branding is deliberate. Cloudflare’s CAPTCHA challenges are legitimately used by a large number of websites for bot protection, and users who encounter them frequently have a trained response to complete them without much scrutiny. TerminalFix exploits that trained response to make the malicious instruction delivery feel like a routine interaction. The user who pastes the command into Terminal is not being careless. They are being deceived by a technique specifically engineered to look like something they do regularly.

AI Defense Evasion / Russia-Aligned

UAC-0099 Planted a Nuclear Weapon Prompt in Malware to Break AI-Assisted Malware Analysis

UAC-0099 / Russia-Aligned / Ukraine Targeting

The Russia-aligned threat actor UAC-0099, active in campaigns against targets in Ukraine, disclosed a technique this week that researchers have named GuardBreaker, which involves embedding a nuclear weapon prompt directly inside malware code to disrupt AI-assisted malware analysis tools. When an AI analysis system processes the malware sample, the embedded prompt triggers behavior in the AI that interferes with the analysis, potentially causing the tool to refuse to analyze the sample, generate misleading output, or flag the analysis itself as policy-violating content.

This is adversarial prompt injection applied not to data or user-facing content but to the malware artifact itself, with the intent of degrading the defensive AI tools that security analysts use to examine it. The technique represents a direct attack on the AI layer of the security stack, rather than on the endpoints or networks that AI security tools are designed to protect.

The malware contains a prompt designed to break the AI that analyzes it. UAC-0099 is not just evading detection. They are attacking the detection tool itself, using the tool’s own capabilities against the analyst trying to use it.

Security teams using AI-assisted malware analysis tools need to understand that GuardBreaker-class techniques will become more common as AI analysis tools become more standard in security operations workflows. Samples that cause AI analysis tools to behave unexpectedly, refuse to produce output, or generate anomalous results should be flagged as potentially containing adversarial prompts and escalated for manual analysis rather than dismissed as tool errors.

Critical Exploitation / Developer Platforms

Langflow and Ruby on Rails Both Under Active Exploitation for Credential Access and C2 Activity

VulnCheck documented active exploitation of two critical vulnerabilities this week: CVE-2026-0768 in Langflow with a CVSS score of 9.8, and a corresponding critical flaw in Ruby on Rails. Both are being used in active campaigns for credential probing and command-and-control infrastructure establishment.

Langflow’s appearance here connects back to the JADEPUFFER campaign documented in this publication earlier this summer, in which a Langflow RCE was the initial access vector for what became the first confirmed fully autonomous AI-agent-executed ransomware attack. Langflow remains under active exploitation by multiple threat actors, which means that any organization running a Langflow instance that is accessible from the internet without the most current patches applied is operating known-vulnerable AI development infrastructure with confirmed active exploitation against it.

Ruby on Rails powers a significant portion of enterprise web applications and serves as the backend for platforms used across financial services, healthcare, e-commerce, and other sectors. A critical flaw under active exploitation in Rails is not a niche developer problem. It reaches the applications that real users and customers interact with daily.

CMS Security / Multiple CVEs

Five WordPress Plugins and Themes With Critical Flaws Enable Authentication Bypass, Account Takeover, and RCE

Five widely used WordPress plugins and themes disclosed critical security vulnerabilities this week: WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. The vulnerability types span authentication bypass, account takeover, and remote code execution. Combined user installs across the five affected products run into the millions, and WordPress’s plugin auto-update behavior means that sites that have not applied patches or disabled the affected plugins are potentially running exploitable code on public-facing web infrastructure.

GiveWP is particularly notable given its function: it is a donation management plugin used by nonprofits, charities, and religious organizations to process financial contributions. A critical flaw in donation processing infrastructure means that the vulnerability sits adjacent to payment data and donor personal information for exactly the organizations that have the least security operations capacity to respond quickly.

Avada is one of the most widely installed WordPress themes on the internet. Multiply the affected install base by a critical authentication bypass and the exposed surface is enormous.

Blockchain / Known Vulnerability Exploited

Cosmos EVM Flaw Was Known and Exploited Anyway: Six Blockchains Drained Between August 20–25

Cosmos Labs disclosed this week that a critical balance-handling flaw in the shared Cosmos EVM module was exploited between August 20 and August 25 to drain funds from six separate blockchains. The vulnerability was known to Cosmos Labs before the exploitation occurred. The attack window covered five days and multiple chains before it was contained.

Before August 20
Cosmos Labs aware of critical balance-handling flaw in shared EVM module
August 20–25
Exploitation begins, six blockchains drained of funds over five days
After August 25
Cosmos Labs discloses exploitation and acknowledges prior awareness of the vulnerability

The shared module architecture is the structural condition that made this incident possible at scale. A single flaw in a module shared across multiple blockchain implementations means that a single exploit works against every chain running that module simultaneously. The attacker did not need to find six separate vulnerabilities. They found one and applied it six times across infrastructure that was identically vulnerable by design.

KEV / Espionage

Nuclear Research Records Stolen From the Philippines Through an ownCloud Flaw Now on CISA’s KEV List

CISA added a critical ownCloud vulnerability to its Known Exploited Vulnerabilities catalog following reports that a Chinese-speaking threat actor exploited it to steal nuclear research records from a Philippine research body. The KEV addition confirms active exploitation in sensitive environments, and the specific data stolen, nuclear research records from a government scientific institution, indicates state-sponsored intelligence collection objectives rather than financially motivated opportunism.

ownCloud is an on-premises file sharing and collaboration platform deployed by organizations that need to maintain control over sensitive document storage rather than using cloud-hosted services. The organizations that choose ownCloud for that reason, including government research institutions, defense-adjacent entities, and regulated industries, are precisely the organizations whose data has the highest value to state-sponsored espionage actors.

Insider Threat / DPRK Expansion

North Korean Job Fraud Expands From IT Into Healthcare and Sales: The Infiltration Is Getting Broader

DPRK / North Korean IT Worker Network

The North Korean fraudulent worker campaign documented in previous editions of this publication has expanded its target sectors beyond information technology into healthcare and sales roles. The expansion reflects both the maturation of the operation’s social engineering capabilities and the recognition that the IT sector’s awareness of the campaign has increased scrutiny on technical hiring specifically.

Healthcare presents a particularly concerning expansion target. Healthcare workers with legitimate employment access handle patient records, prescription data, medical device systems, and in some cases clinical trial information. A fraudulent employee with legitimate healthcare system credentials has access to data that is both commercially valuable and personally sensitive at a scale that technology sector roles rarely match.

They got better at interviews. They moved to sectors with less scrutiny. The operation is learning.

Berlin’s refusal this week to pay hackers who compromised the city’s state administrative network and demanded extortion is worth noting alongside the North Korean worker story. Two separate incidents, both involving actors who had already achieved access to sensitive government data, both expecting payment. Berlin said no. The city’s data was exposed regardless. The extortion model works even when the target refuses to pay, because the threat of disclosure creates reputational and legal pressure that does not require the victim to cooperate.

Platform Security / IoT

Android 17 Hides Your Website Visits From Network Providers While a Humanoid Robot Offers Root RCE Over Bluetooth

Google announced Android 17’s OS-wide support for Encrypted Client Hello, a protocol extension that encrypts the domain name in TLS handshakes, preventing network providers, ISPs, and network-level surveillance infrastructure from observing which websites a user visits even when HTTPS is in use. ECH has been available at the browser level in some configurations for some time, but OS-level implementation means the protection applies to every app’s network connections rather than only those routed through a browser.

At the other end of the security spectrum, researcher Olivier Laflamme disclosed two independent root remote code execution chains affecting the Unitree G1 EDU humanoid robot, including one reachable over Bluetooth Low Energy without any prior authentication. The BLE path achieves root on the robot’s local controller from Bluetooth range, which for a mobile robot platform operating in a physical environment means the attack surface moves with the device wherever it goes.

A humanoid robot with root RCE accessible over Bluetooth is not a distant IoT security thought experiment. It is a deployed device with cameras, mobility, and physical presence in environments where it is treated as a trusted operator. Root access means the attacker controls all of that.

The Unitree G1 EDU is marketed to research institutions and educational environments. The attack surface it creates is proportional to what it can do: observe, move through, and interact with physical spaces. The security model of autonomous physical systems requires the same rigor applied to network infrastructure, and the Unitree disclosure makes clear that the industry has not yet arrived at that standard.

Regulation / Browser Security

The EU CRA Makes Vulnerability Reporting Mandatory on September 11 and 19 Crypto-Draining Browser Extensions Were Hiding in Plain Sight

The EU Cyber Resilience Act’s mandatory exploited vulnerability reporting requirement takes effect September 11, 2026, requiring organizations to notify authorities of actively exploited vulnerabilities within 24 hours of discovery. The reporting obligation arrives 15 months before the engineering requirements of the CRA apply, which creates a situation where organizations must report what they find without yet being legally required to have fixed it. The compliance posture this demands is active monitoring, discovery capability, and reporting infrastructure, all of which need to be in place by September 11 regardless of where organizations are in their broader CRA implementation journey.

Separately, researchers discovered 19 browser extensions, 18 in Chrome and one in Edge, containing wallet secret stealing and cryptocurrency draining capabilities, published over the past six months to the official browser extension stores. The extensions had passed the review processes of both stores and accumulated legitimate-appearing install counts before the malicious functionality was identified.

19 malicious extensions. Six months. Official stores. The extension review process is not a security guarantee.

Users who have installed free cryptocurrency wallet utilities, portfolio trackers, or trading assistants from browser extension stores in the past six months should audit those extensions against the disclosed list and remove any that appear on it. The wallet-draining capability in these extensions can operate silently on any wallet activity that occurs in the browser while the extension is active.

Enterprise Platform Vulnerabilities

PaperCut, GeoNetwork, and Switchvox: Three More Platforms Under Active Attack This Week

Three enterprise platforms joined the active exploitation list this week. PaperCut NG and MF, widely deployed print management software, have a newly patched vulnerability under active exploitation for arbitrary code execution, with the company releasing an emergency fix that includes additional hardening beyond the initial patch. GeoNetwork, the open-source geospatial metadata catalog used behind government geoportals and agency geographic information systems, has two vulnerabilities that chain to achieve unauthenticated remote code execution on the server. And Switchvox, Sangoma’s enterprise VoIP platform, carries CVE-2026-9586 with a CVSS score of 9.8 that allows unauthenticated remote code execution through reverse shell deployment.

PaperCut is present in a large number of enterprise and education environments. GeoNetwork sits behind government infrastructure. Switchvox handles enterprise voice communications. Three separate platforms, three separate attack surfaces, all under active exploitation in the same week. The breadth of what is being targeted simultaneously is a direct reflection of how automated and scalable exploitation has become. Attackers are not choosing between these targets. They are running against all of them in parallel.

Criminal Prosecution / Malware Campaign

Russian Hacker Extradited Over Excel Malware Campaign That Used 255 Fake Freelance Accounts to Reach 8,000 Victims

The U.S. Department of Justice charged a Russian national extradited from Cyprus with operating a malware campaign that used approximately 255 fake accounts on a freelance work platform to send malware-embedded Excel attachments to roughly 8,000 targets. The scale of the fake account infrastructure reflects the level of operational investment required to conduct a phishing campaign at that volume while maintaining plausibility: 255 separate personas, each with enough apparent history and legitimacy on the platform to make contact with targets who expected to receive files from freelance workers.

Excel as a malware delivery vehicle has remained effective longer than security awareness training would suggest it should have, because the expectation of receiving spreadsheet files from business contacts or freelance workers is deeply embedded in professional workflows. The DOJ’s extradition success in this case, following coordination with Cyprus, reflects the continued expansion of international law enforcement cooperation against cybercrime that this publication documented in the Kratos phishing kit takedown earlier this summer.

AI is writing exploits, porting them between targets, being used as ransomware infrastructure, and getting its credentials stolen. The same week. The question is no longer whether AI changes the threat landscape. It already did. The question is whether your security program has caught up to that reality yet.
SunsetHost Hacker News © 2026 August 29 – September 2, 2026  |  Feature Edition sunsethost.com
Scroll to Top