Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

    September 25, 2026

    Trump’s Stargate AI Project in Huge Trouble As $18 Billion Data Center Shrivels Toward Oblivion

    September 25, 2026

    The Pixel Watch 5’s long-awaited Health Guardian features are finally here

    September 25, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure
    In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure
    Cybersecurity

    In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

    The Tech GuyBy The Tech GuySeptember 25, 2026No Comments6 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape.

    Advertisement

    This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers stay well-informed about the evolving cybersecurity environment.

    Here are this week’s highlights: 

    Clop’s leak site seized in ShinyHunters grudge match

    ShinyHunters has defaced the Tor data leak site of the Cl0p ransomware gang. The extortion group claims it also stole server logs, source code and the private keys for Clop’s onion service. It demanded an eight-figure payment and a public apology, and threatened to expose companies that allegedly paid Cl0p during its Oracle E-Business Suite campaign. ShinyHunters says the attack is payback for threats allegedly made by a Clop representative in a feud that goes back to that campaign.

    Advertisement. Scroll to continue reading.

    BragJack attack against browser AI assistants

    Researchers at endpoint security firm Forever have disclosed BragJack, a set of flaws that let a malicious extension take control of the built-in AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet and the Claude in Chrome extension. In each case, the assistant trusts commands from a specific web page. An installed extension could hijack that page by injecting scripts or tampering with network traffic, then send its own prompts without any user interaction. Depending on the browser, this enabled reading emails, accessing local files, capturing screenshots or turning on the camera and microphone. The vendors paid bounties ranging from $600 to $7,000.

    Worm-ready Go implant sneaks into AI agent memory tooling

    An attacker has published malicious versions of MemTensor’s MemOS packages on npm and PyPI, including a memory plugin for the OpenClaw AI agent harness. The packages carry a previously unseen Go implant named sckit. Instead of running at install time, the malware launches when the Python library is imported or the npm plugin is used. It hunts for npm, PyPI, GitHub, AWS, Hugging Face and other secrets. The implant contains templates for spreading through npm, PyPI and GitHub Actions, but Semgrep says there is no evidence yet that it has propagated. Aikido and StepSecurity also shared details.

    AI relay networks funnel Chinese traffic to Western frontier models

    Team Cymru has found nearly 11,000 servers running Claude Relay Service or its successor, sub2api. These open source gateways pool AI accounts so many users can share them, while model providers see only the relay and never the real user or their location. In one US-hosted cluster, more than 4,000 IP addresses in China and Hong Kong (regions that Anthropic, OpenAI and Google exclude) connected to 304 relays that also reached OpenAI, Anthropic, xAI and Google endpoints.

    Infostealer logs expose remote access keys across US water sector

    SpyCloud analyzed stolen identity data tied to 10,000 US water and wastewater utilities and the technology vendors that supply them. It found active infostealer exposure at 1,787 organizations, and credentials for OT or remote-access systems at 258. In one case, malware on a single device at an advanced-metering technology provider captured saved logins for roughly 167 utility metering portals. Exposed credentials at the utilities themselves were mostly for remote-administration tools such as TeamViewer and SonicWall and Fortinet management portals, though SpyCloud stresses the findings reflect potential access paths, not confirmed intrusions.

    CLOSEDQUORUM swaps C2 servers for commercial AI APIs

    Cisco Talos has documented CLOSEDQUORUM, a Go-based Windows implant that it believes is the first publicly documented one to hand its command-and-control decisions to commercial LLMs instead of a human operator or attacker-run server. Up to four models (DeepSeek, Qwen, Mistral and Gemini) vote on whether to steal credentials, inject code or establish persistence. The implant then executes the winning choice and sends LSASS dumps, browser passwords and crypto wallet data to the operator’s Discord channel. Talos has not confirmed use in the wild, and the public build contains placeholder API keys, but development builds indicate the developer produces custom versions for individual operators.

    Canonical promises Ubuntu kernel workarounds within 48 hours of disclosure

    Canonical is replacing Ubuntu’s separate four-week regular and two-week security kernel Stable Release Update (SRU) cycles with a single two-week cycle. Because the cycles overlap, a new kernel will be released every week. The company cites a sharp rise in CVE volume, driven by AI-assisted bug discovery and by the upstream kernel community becoming its own CVE Numbering Authority and assigning identifiers to thousands of bugs. Admins who want fixes sooner can test release candidates from the -proposed pocket before certification testing is complete. Canonical also aims to offer workarounds or hardening guidance within 24 to 48 hours of a vulnerability’s public disclosure.

    Pre-auth TDengine flaw threatens industrial telemetry uptime

    Ridge Security has published details of CVE-2026-42542, a high-severity flaw in TDengine, a time-series database used in industrial telemetry, energy, utilities and IoT environments. An unauthenticated attacker can crash the server with a single malformed packet sent to its RPC port. The bug is an integer underflow in message parsing that runs before authentication and leads to a heap buffer overflow. The researchers confirmed only denial of service, but they urge defenders to consider the underlying memory corruption as well. TDengine versions 3.4.0.0 through 3.4.1.5 are affected, and version 3.4.1.6 fixes the issue.

    Banking trojan’s AI helper thought it was building a quiz

    Group-IB has uncovered RemControl, a new Android banking trojan offered as malware-as-a-service. It spreads through fake Google Play pages for the TVTap IPTV app and targets customers of more than 30 banks in Western Europe, the Middle East and Canada. Once granted Accessibility permissions, the malware displays phishing overlays on top of banking apps, streams the screen, logs keystrokes and gives the operator full remote control of the device. Exposed API documentation suggests parts of the platform were built with an AI assistant that was told it was working on a quiz and parental monitoring app, and one phishing overlay contained a complete AI assistant response.

    Docker botnet ranks AI API keys above all other loot

    ThreatDown has detailed CARBONATO, a botnet that compromises Docker daemons exposed without authentication on port 2375 and scans neighboring networks every five minutes to spread further. On each host, it installs Hermes Agent, a legitimate open source AI agent framework, and replaces its persona file with instructions to follow operators’ Telegram commands, maintain persistence and collect credentials, ranking AI API keys first. The researchers found the operation through an exposed, unauthenticated Docker registry. Language, timezone and infrastructure clues support their assessment that the operators are based in Costa Rica.

    Related: In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

    Related: In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

    September 25, 2026

    OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data

    September 25, 2026

    Autonomous AI Hacks Raise Thorny Questions of Legal Accountability

    September 24, 2026

    Kontext Security Emerges With $4 Million for AI Agent Runtime Controls

    September 24, 2026

    Astrana Health Data Breach Impacts Private, Confidential Information

    September 24, 2026

    Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios

    September 24, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026211 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

    September 25, 2026

    Trump’s Stargate AI Project in Huge Trouble As $18 Billion Data Center Shrivels Toward Oblivion

    September 25, 2026

    The Pixel Watch 5’s long-awaited Health Guardian features are finally here

    September 25, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.