
Worming its way through WeChat.
Researchers build a self-propagating attack against WeChat. Threat actors move toward multi-agent AI frameworks. N-able issues an emergency patch for a maximum-severity bug under active exploitation. MikroTik patches multiple RouterOS vulnerabilities. China accesses restricted American technology through subsidiaries and overseas partners. An active phishing campaign abuses legitimate Google services to make malicious links appear trustworthy. Australians may soon be able to disable the algorithm. Monday business briefing. Jason Lancaster, Chief Investigations Officer at SpyCloud, discusses how AI is affecting shifting cybercrime from traditional investigations to agentic AI at scale. Electromagnetic eavesdropping gets personal.
Today is Tuesday September 8th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
Researchers build a self-propagating attack against WeChat.
Researchers at Palo Alto security company Calif say advanced AI models helped them build a self-propagating attack against WeChat in little more than a week. Dubbed WeWorm, the proof-of-concept exploited a zero-day vulnerability that could compromise an account when a call from an already-compromised contact simply rang—no click required. The worm could then access messages, make calls, control the account, and automatically target saved contacts, potentially spreading exponentially across WeChat’s more than 1.4 billion monthly users. Researchers said additional vulnerabilities could have turned account access into full device compromise across both iOS and Android. Tencent confirmed the vulnerability and patched it after Calif’s disclosure, saying it had no evidence users were affected. Calif emphasized that AI didn’t create the attack autonomously; human researchers guided the process. Still, the demonstration suggests AI is dramatically accelerating the discovery and weaponization of software vulnerabilities.
Threat actors move toward multi-agent AI frameworks.
Google’s Threat Intelligence Group says threat actors are moving beyond simple AI coding assistants toward multi-agent frameworks capable of automating multiple stages of cyberattacks. In one incident, a financially motivated attacker used AI agents to build and launch a mass credential-harvesting campaign in under six hours. The agents scanned for vulnerabilities, collected thousands of credentials, troubleshot failures, rotated IP addresses, and used compromised cloud infrastructure to evade detection. Researchers also discovered an automated framework managing more than 23,800 stolen secrets. State-backed groups are experimenting with similar technology for exploitation, reconnaissance, monitoring, phishing, malware development, and other operations. Google cautions that fully autonomous hacking isn’t yet widespread, and researchers haven’t observed autonomous pipelines discovering zero-days and exploiting real-world networks. But increasing automation is shrinking defenders’ response windows by taking humans out of more of the attack loop.
N-able issues an emergency patch for a maximum-severity bug under active exploitation.
N-able has issued an emergency patch for a maximum-severity remote code execution vulnerability in its N-central management platform. CVE-2026-86218 carries a CVSS score of 10 and can be exploited without authentication. All on-premises builds before 2026.3.1.14 are vulnerable, while hosted instances have already been patched. New reporting indicates attackers are actively exploiting the flaw, creating unauthorized administrator accounts and using N-central’s remote-control capabilities to pivot into managed endpoints. Customers should install Hotfix 4 immediately and restrict or disconnect exposed consoles until patched.
MikroTik patches multiple RouterOS vulnerabilities.
MikroTik has patched six RouterOS vulnerabilities, including two actively exploited flaws dubbed MikroTrick. CERT Poland says attackers are chaining an SSH authentication bypass with a privilege manipulation vulnerability to take full control of devices exposed to the internet. Attacks have been observed since at least September 2, with compromised routers sometimes containing an account named “ops.” More than 120,000 MikroTik devices recently had SSH publicly accessible. Users should update RouterOS immediately and block SSH access from untrusted sources.
China accesses restricted American technology through subsidiaries and overseas partners.
A New York Times investigation found that Inspur, a Chinese technology giant blacklisted by Washington over its military ties, has continued accessing advanced American technology through subsidiaries and overseas partners. After Inspur was added to the U.S. entity list in 2023, its Silicon Valley subsidiary began operating as Aivres and continued exporting billions of dollars in advanced equipment. From April 2024 through February 2026, records show Aivres shipped at least $5.6 billion in technology to Southeast Asia, including more than $3 billion in systems containing Nvidia’s cutting-edge Blackwell chips. Some equipment went to data centers serving major Chinese technology companies, while other servers apparently traveled through Malaysia before reaching China. The investigation suggests Inspur’s network has exploited gaps in export controls involving subsidiaries, company addresses, and remote access to overseas data centers. Federal officials have reportedly examined Aivres, but the status of that inquiry is unclear.
An active phishing campaign abuses legitimate Google services to make malicious links appear trustworthy.
KnowBe4 Threat Lab says an active phishing campaign is abusing multiple legitimate Google services to make malicious links appear trustworthy to security tools and victims alike. Attackers route targets through Google properties including Meet, Search, DoubleClick, Custom Search, Image Search, Tag Manager and Analytics before reaching credential-harvesting infrastructure. The final phishing page is personalized in real time, pulling the victim organization’s logo, website imagery and email domain information to mimic a legitimate login portal. The campaign also checks email domains and uses anti-analysis steps to filter out sandboxes and researchers.
Victims are then sent down one of two paths: credential theft, with stolen passwords exfiltrated through Telegram, or installation of ScreenConnect for persistent remote access. KnowBe4 says the campaign’s strength is that nearly every intermediate step looks legitimate, reducing the usefulness of simple domain-based blocking.
Australians may soon be able to disable the algorithm.
Australia’s government plans to require social media platforms to let users over 16 turn off algorithmic recommendations and instead see content only from accounts and groups they choose to follow. The proposal, called “my feed, my way,” would use a pop-up asking users to select their default feed, with fines exceeding A$100 million for non-compliance. Separate digital duty-of-care rules would require social media services, games, apps and AI chatbots to protect minors from harms including pornography, eating-disorder content, misogyny, glorification of crime, bullying and serious mental distress. Australia’s eSafety commissioner would gain removal powers and require platforms to document their safeguards. The legislation is expected before Christmas, but faces political debate over censorship, enforcement thresholds and whether opt-out mechanisms go far enough.
Monday business briefing.
Cybersecurity investment and dealmaking remain active. Digital identity verification company Socure raised $156 million at a $5.2 billion valuation and acquired fraud and compliance automation firm Fravity, whose technology will be integrated into Socure’s RiskOS platform. Israeli AI agent supply-chain security startup AIR emerged from stealth with $50 million, while vulnerability remediation company DataAgent launched with $10 million. Mobile fraud prevention startup Kazimi raised $2.6 million.
Eight acquisitions and spinoffs were also announced. Palo Alto Networks acquired agentic workflow platform Console to expand automated security operations. WithSecure spun off its Salesforce security business as an independent company. A-LIGN acquired security firm Pathfynder, while Echo purchased technology assets from the shuttering secure-container provider Minimus. Ampcus acquired security data platform SmarterD, Integrity360 bought identity security company CyberIAM, and ePlus acquired MSSP Daymark Solutions to strengthen its Microsoft-focused services.
Electromagnetic eavesdropping gets personal.
Researchers in Hong Kong have demonstrated InjectEave, an electromagnetic eavesdropping technique that can recover audio from ordinary headphones from as far as 30 meters away. Rather than simply listening for electromagnetic leakage, InjectEave sends a carefully chosen radio signal at a device, where electronic components unintentionally mix it with internal signals and rebroadcast useful information. In tests, researchers recovered intelligible headphone audio, including through a 30-centimeter concrete wall. They also extracted information from smart fans and lamps that could reveal household routines, and demonstrated both eavesdropping and audio manipulation on a landline phone. The good news is that this isn’t exactly casual neighborhood snooping. An attacker needs specialized radio equipment, suitable frequencies, and ideally an identical device for profiling. Still, the research shows that walls—and apparently headphones—aren’t always as private as their users might reasonably assume.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.
