Jamf Threat Labs reported CloudSyncD, a new macOS backdoor that spreads through a fake Zoom installer and beacons to its server every 8 to 16 seconds. First caught as a VirusTotal sample that looked unfinished, it now appears in builds that connect to live infrastructure in what Jamf calls an active campaign.
Perspective Coverage
5 publishers
- Builder
- Builder 25%
- Operator
- Operator 70%
- Investor
- Investor 5%
Reality
- Evidence70
- Adoption15
- Hype gap+15
- Incentives
- Insufficient
- Confidence68
Roblox Account Manager's developer traced a Defender trojan verdict, from 1 of 75 VirusTotal engines, to the commit that added libsodium. Build-and-scan bisection found the dependency, though the developer can only hypothesise why the model objects to it.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence50
Group-IB says a 13-minute call ended with a loan in the victim's name and card data streaming to a fake merchant terminal, every transaction approved with the victim's own PIN.
Perspective Coverage
3 publishers
- Builder
- Builder 27%
- Operator
- Operator 63%
- Investor
- Investor 10%
Reality
- Evidence62
- Adoption20
- Hype gap+10
- Incentives40
- Confidence65
Dominik Reichel's write-up describes a passive Windows implant with no listening port and no embedded payload. Recovering its AES key still leaves you holding bytecode for an interpreter only it understands.
Perspective Coverage
3 publishers
- Builder
- Builder 43%
- Operator
- Operator 52%
- Investor
- Investor 5%
Reality
- Evidence58
- Adoption10
- Hype gap+6
- Incentives35
- Confidence68
Palo Alto's threat unit says about 97% of AI-linked malware never leaves sandboxes and VirusTotal, and that what does arrive is caught by detection layers customers already run.
Reality
- Evidence55
- Adoption15
- Hype gap+20
- Incentives75
- Confidence55
Huntress worked two Settra intrusions, in July and September, and found MeshAgent installed for remote control, Windows event logs cleared and recovery partitions removed. SOCRadar counts 93 victims claimed since June.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence70
Manifold Security found third-party.com, a placeholder in more than 1,700 public repositories, serving a ClickFix clipboard lure to Windows browsers since at least June 2026. Static scans of the same files come back clean, because the server chooses what to send.
Reality
- Evidence58
- Adoption62
- Hype gap+12
- Incentives62
- Confidence60
LastPass and Delphos Labs say a single malware-as-a-service kit impersonated at least 40 companies on GitHub, and the kernel driver it delivered was Microsoft-attested and undetected by every engine on VirusTotal.
Publishers:blog.lastpass.com
Reality
- Evidence62
- Adoption48
- Hype gap+12
- Incentives68
- Confidence55
Cisco Talos says its CLOSEDQUORUM sample asks four language models for executable decisions, tallies the votes and acts on the winner. An entire phase of the attack runs while the operator is offline.
Reality
- Evidence50
- Adoption8
- Hype gap+40
- Incentives62
- Confidence54
Alinubx.sys terminates security agents from kernel mode under a Microsoft Windows Hardware Compatibility Publisher signature dated March 2023, and nothing in the driver has to be exploited for that to work.
Reality
- Evidence62
- Adoption40
- Hype gap+8
- Incentives55
- Confidence55
LastPass TIME and Delphos Labs analysed a malware-as-a-service kit that arrives as a padded ZIP from an SEO-boosted fake repository and ends with a signed driver terminating security processes from kernel mode.
Reality
- Evidence45
- Adoption30
- Hype gap+12
- Incentives55
- Confidence40
HP tracked the campaign from April to June 2026, in which a fake AI crypto trading agent shipped a genuine Microsoft utility to satisfy Windows reputation checks before the DLL loaded beside it stole browser wallet passwords.
Reality
- Evidence60
- Adoption40
- Hype gap+15
- Incentives70
- Confidence55
Cloudflare says its graph model flagged eight malicious scripts running on live storefronts. A retrospective check put seven of the eight outside VirusTotal entirely. URLScan flagged none of the eight as malicious.
Reality
- Evidence45
- Adoption40
- Hype gap+30
- Incentives85
- Confidence50
Mandiant's report describes an assistant that had permission to clone internal repositories and an approved domain to push them to, and an accounting agent whose runaway loop billed about $50,000 in under an hour.
Reality
- Evidence45
- Adoption30
- Hype gap+20
- Incentives70
- Confidence50
A Rust canary submitted to VirusTotal under a fake product name sent back OS build, uptime, core count and parent process from the environments that ran it, and its DNS heartbeat escaped runs that never posted a dossier.
Reality
- Evidence42
- Adoption10
- Hype gap−8
- Incentives35
- Confidence40
Elastic documented four programs that stay in the user profile after the stealer wipes itself. The credential rotation that closes the ticket does not restore the update services or clear the Defender exclusions.
Reality
- Evidence60
- Adoption45
- Hype gap−10
- Incentives70
- Confidence58
OpenAI ran the ExploitGym benchmark with safety classifiers disabled and sandbox egress limited to one Artifactory proxy. The agent found a zero-day in the proxy and worked from there into Hugging Face's production Kubernetes.
Reality
- Evidence46
- Adoption55
- Hype gap+20
- Incentives75
- Confidence52
Cisco Talos found the loader running from a WebDAV UNC path at a Ukrainian government organisation in April 2026, delivered by a ClickFix prompt whose JavaScript was stored on BNB Smart Chain. The primary payload is Amatera stealer.
Reality
- Evidence68
- Adoption38
- Hype gap−12
- Incentives55
- Confidence60
Cyera says an account with the REPLICATION attribute could load arbitrary code inside the PostgreSQL server process and climb to superuser. Fixes shipped on August 13, and the harder work is naming who holds those accounts.
Reality
- Evidence58
- Adoption22
- Hype gap+28
- Incentives68
- Confidence55
Group-IB says the Exilware crew built BraZetsu to score compromised Iberian and Latin American machines by value and sell entry to whoever wants to run their own payload, which changes how a stealer alert should be triaged.
Reality
- Evidence55
- Adoption38
- Hype gap+18
- Incentives68
- Confidence48
Earlier coverage
- RevStealer spread via fake free Claude Opus 5 desktop build on GitHub
Security · September 1, 2026 · 2 publishers
- Georgia Tech found malware could move money unassisted in 35 of 159 banking apps it tested
Invest · August 27, 2026 · 1 publisher
- Unit 42 counted 405 AI malware samples. Twelve reached a real endpoint.
Science · August 27, 2026 · 1 publisher
- A fake internet, not a tighter cage: catching a trojan that waits for DNS
Build · August 25, 2026 · 1 publisher
- PavinLoader: the lures keep changing, the MSBuild stage does not
Security · August 24, 2026 · 1 publisher
- PyInstaller exits zero, then the real work starts: notarization traps that report success
Build · August 21, 2026 · 1 publisher
- Exposed MCP servers are now a scanned entry point, and N4D's agent calls the tools itself
Science · August 21, 2026 · 1 publisher
- ClickFix in the sidebar: Def Con follow-up phishing turns a real Google Doc into the payload
Security · August 20, 2026 · 2 publishers