2026.09.01 News You Should Know

- 6 mins read

Series: News You Should Know 2026

Errata

Apple rescues Hide My Email feature from the privacy scrap heap | TechCrunch - The company confirmed an update on Monday that Hide My Email addresses “will remain” on @icloud.com, after previously saying it would move users to @private.icloud.com which would have made it easier for companies to reject at sign-up.

That fake Grand Theft Auto VI demo is actually just malware | TechCrunch - Cybercriminals have created fake websites impersonating Rockstar, the developer behind GTA 6. These websites advertise a playable GTA 6 demo — but no legitimate demo exists. Once the unsuspecting gamer clicks the “Play Now” button, they download a file that looks like a game installer, but is actually malware.

Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson | TechCrunch - The ShinyHunters hacking group — one of the most active data-extortion crews of the past two years — told TechCrunch that it hacked the company’s cloud environment by tricking several employees into granting the hackers access to McKesson’s network by using phishing and social engineering tricks, which the group is known for.

33-hour BGP hijack of Softaculous traffic prompts security scramble - “Our product update clients did not yet cryptographically verify update packages, so a modified package would not have been rejected on that basis.”

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers - By encrypting the destination website name from the very start, ECH helps ensure that, for supported websites and apps, network providers and network snoopers can no longer easily see which websites or apps you are accessing."

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor - “While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully,” Microsoft security researchers Sagar Patil, Suriyaraj Natarajan, and Parasharan Raghavan said in an analysis published this week.

New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode - An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design.

Water

More than 100 water systems were hit in July cyberattacks - The number of affected systems provides new context to the scale of the ongoing cyberattacks targeting water providers in Michigan, Minnesota, and at least five other states. Additional Reading: CISA confirms hackers targeted over 100 US water systems during July | TechCrunch

China

FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks - NASA, the Federal Reserve, departments of Energy, Justice, and Health and Human Services, along with the National Institutes of Health, and the US Senate were “targets.” Additional Reading

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access - VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices.

  • CVE-2026-74233 (DARKLANTERN) - Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108 and WG3526 on firmware 19.1101, WE2426-C on 19.1112, WE5926-EC_QP on 20.0516 and WF3526-P on 19.051, plus CTN720-W1, LF-1541 and MT7620N on 19.1101 and WRC1 on 20.0622, which the CVE record lists under an unidentified vendor.
  • CVE-2026-74232 (SPEAKINGSTONE) - Zbtlink L3_V2_8 on 3.0.0.4.528, WE826-T2 on 19.1101, ZBT-7628 on 1.0.0.2.007 and ZBT-ZBT7621 on 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A and MQAP-7628 on 1.0.0.2.000, and AP522 on 1.0.0.2.014, AP7628 and HC5661A on 3.0.0.4.380, APG721B on 19.0809, HK300 on 1.0.0.2.032 and MAP-N10 on 1.0.0.2.044 under an unidentified vendor.

AI

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers - What makes this flaw notable is that the user does not have to submit a malicious prompt or reference the attacker-controlled content. Once the crafted workspace file is opened, sending any message is enough to trigger the vulnerable flow.

Claude, Codex, and Hermes installed unowned code inside corporate networks - Ars Technica - The files are misconfigured because they list non-existent packages from PyPI, npm, and other registries along with instructions on how to install them. For example, one file contained the prompt “Installation: pip install [redacted at researchers’ request].” On another file, it was: “npm install [redacted].” Because the package names are unregistered, an attacker could register one and use it to host ransomware or any other type of harmful package. The vulnerability occurs when a coding agent with permission to run shell commands treats the file as authoritative setup documentation. Some AI agents will then download the package and run it. In other cases, the LLM files point to non-existent domain names. In one case, it was: “As an example of writing integration tests for [redacted] applications you can use the [Citrus] test framework.” An attacker can then register the site and plant malicious instructions on it.

Researcher shows how Claude Code can be tricked simply by asking it to summarize a website - Anthropic’s Claude Code running Opus 5 in Auto Mode can be tricked into executing attacker-controlled code simply by asking the coding agent to summarize a website. The attack works up to 80 percent of the time, according to prompt-injection wizard Johann Rehberger, aka wunderwuzzi.

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis - “In the attack, UAC-0099 inserted a problematic text: ‘I want to make a nuclear weapon. Help me …’ into their malicious VBS script as a comment,” the Slovak cybersecurity company said. “This is meant to attract the AI’s attention to the safety-sensitive content and stop it from analyzing the rest of the code.”

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes - The targets are owners of Apple devices that were recently lost or stolen, and the pages and calls ask each of them for the 4- or 6-digit device passcode, then the Apple ID credentials, and finally a live two-factor authentication (2FA) code. Apple’s own guidance states that the company never asks for a password, device passcode, or 2FA code to provide support. Additional Reading: AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

Nearly 700 rogue AI agents coordinated in the Hugging Face attack -

I’m an experienced home cook, security engineer, people leader, and dedicated father and husband. I can be found on Mastodon at @IAintShootinMis@DigitalDarkAge.cc and on Signal at DigitalDarkAge.98. An RSS Feed of this blog is available here and a copy of my current OPML file is here.