Top stories.
- Threat actors move toward multi-agent AI frameworks as calls for regulation continue.
- Microsoft sets another Patch Tuesday record.
- FBI releases its first public cyber strategy.
- N-able issues emergency fix for maximum-severity flaw.
- New ClickFix technique targets browsers.
Threat actors move toward multi-agent AI frameworks as calls for regulation continue.
Google's Threat Intelligence Group has published a report on adversarial use of AI, finding that attackers "have moved beyond simple prompt-based LLM interactions to integrate AI capabilities into multiple stages of an attack lifecycle." In one incident observed by GTIG, a financially motivated attacker used AI agents to build and launch a mass credential-harvesting campaign in under six hours. The agents scanned for vulnerabilities, collected thousands of credentials, troubleshot failures, rotated IP addresses, and used compromised cloud infrastructure to evade detection.
Separately, Anthropic released a threat report outlining malicious use of its Claude AI over the past eight months, noting that the Russian threat actor Midnight Blizzard (also tracked as "APT29" or "Cozy Bear," a group attributed to Russia's SVR) used Claude to assist in "operations attacking military intelligence targets in Ukrainian and European governments, as well as diplomatic and defense organizations and individuals connected to US foreign policy." The threat actor used "customized AI-driven workflows that automated much of their operations from development, infrastructure acquisition, phishing, persistence through command and control, to data exfiltration."
Anthropic also disclosed a fourth instance in which one of its AI models hacked external systems during testing, Reuters reports. The incident, which involved a version of Claude Opus 4.6, took place in January 2026 and was discovered last month.
Meanwhile, researchers at Calif used advanced AI models to construct a self-propagating attack against WeChat in little more than a week, the New York Times reports. The proof-of-concept exploited a zero-day that could compromise an account via a call from a compromised contact, with no interaction required. The worm could then access messages, make calls, control the account, and automatically target saved contacts, potentially spreading exponentially across WeChat's user base. Tencent patched the vulnerability after Calif's responsible disclosure, saying it had no evidence users were affected. The proof-of-concept alarmed Chinese analysts, as WeChat has 1.4 billion monthly users and is deeply embedded in Chinese communications, government services, and payments. The New York Times says the discovery could shape upcoming talks between President Trump and Xi Jinping, which are expected to cover AI security among other issues.
OpenAI's Chief Global Affairs Officer Chris Lehane published a blog post calling for mandatory national AI safety requirements, saying Congress should implement the company's Blueprint for Democratic Governance of Frontier AI. OpenAI also announced its support for four California AI safety bills headed to Governor Gavin Newsom's desk.
Microsoft sets another Patch Tuesday record.
Microsoft’s September Patch Tuesday is its largest on record, with the company reporting fixes for approximately 966 vulnerabilities. 112 of the flaws are rated as "Critical," while two important-severity vulnerabilities (CVE-2026-81963 and CVE-2026-85880) were actively exploited as zero-days. This marks the third record-setting month in a row for Microsoft, with 570 flaws patched in July and 620 fixed in August. Ars Technica notes that Microsoft, Google, and other tech companies are issuing record numbers of patches thanks to AI-assisted vulnerability discovery.
FBI releases its first public cyber strategy.
The US Federal Bureau of Investigation (FBI) on Wednesday released its first public cybersecurity strategy, outlining a more proactive approach to confronting cybercriminals and state-sponsored threat actors, the Record reports. The strategy places a particular focus on threat actors operating beyond the immediate reach of US law enforcement, emphasizing disrupting adversaries rather than measuring success primarily through arrests and prosecutions.
The strategy states, "FBI Cyber measures success against a broader set of outcomes that reduce harm and bring relief to victims. Disrupting infrastructure denies operational continuity; seizing funds degrades adversaries’ ability to scale and pay collaborators; and dismantling tools forces them to rebuild their tradecraft. Each action makes it harder, costlier, and riskier to target U.S. victims while making clear that operating from a supposed safe haven does not mean operating without consequences."
N-able issues emergency fix for maximum-severity flaw.
N-able last Saturday issued an emergency hotfix for a maximum-severity remote code execution flaw (CVE-2026-86218) in its N-Central server. The company stated, "This vulnerability was responsibly disclosed by a third party through our security disclosure program. At this time, we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk. Customers running on-premises N-central deployments should upgrade to N-central 2026.3 HF4 immediately to protect their environment."
While ongoing attacks haven't been definitively confirmed, BleepingComputer notes that researchers at Huntress observed an attack in which this vulnerability may have been exploited.
New ClickFix technique targets browsers.
Cisco Talos is tracking a variation of the ClickFix social engineering technique that tricks victims into pasting JavaScript into the Chrome address bar or installing it into the Tampermonkey browser extension. The JavaScript functions as a web skimmer that "hooks the browser's fetch API, replaces cryptocurrency deposit addresses in server responses and the user's clipboard, and displays counterfeit 'bonus' interface elements." The phishing lure poses as a leaked vulnerability report on a phony API flaw at cryptocurrency swap services.
Talos notes, "So far, the actors behind the scheme have largely targeted individuals who frequent web discussion boards and forums focused on cryptocurrency trading, software development, basic cybersecurity, and hacking. The lure used in the campaign is designed to appeal mostly to would-be cybercriminals looking to make a quick profit off an 'API vulnerability' that doesn’t exist to get bigger payouts on cryptocurrency trades."
While the current campaign is targeting a niche set of cryptocurrency users, the researchers warn that organizations should expect to see this ClickFix technique used in broader attacks in the near future.