FBI grabs China's state hacking tools

FBI seizes Chinese hacking tools, Telegram flaw, and more.

FBI grabs China's state hacking tools

Hi there, this is your daily β˜•οΈ Cyberpresso.

In today's Cyberpresso:

πŸ‡¨πŸ‡³ FBI seizes Chinese state hacking tools

πŸ”“ Telegram Desktop flaw enables account takeover

πŸ› Hackers exploit backup server flaws

πŸ‘Ύ LMCache flaw lets hackers run code

Plus: πŸ’‘ 6 strategies & tactics, 🎁 6 more stories you might like, 🧰 6 tools, and πŸ“š 5 papers.

πŸ‡¨πŸ‡³ FBI seizes Chinese state hacking tools LINK

  • The FBI has seized seven domains used by the Chinese state-sponsored hacking group Flax Typhoon to run two tools, MicroScan and FishHub, operated by China-based Integrity Technology Group in attacks that breached critical infrastructure worldwide.
  • MicroScan is a Python-based scanner with more than 1,300 penetration-testing scripts that probed software like Oracle WebLogic, Apache Struts, and WordPress, paired with a Mirai-infected botnet; FishHub then used spear-phishing to plant malware giving attackers remote access and letting them steal files.
  • Investigators found stolen data from more than 20 organizations on a FishHub server, and a joint FBI, CISA, and NSA advisory urges organizations to review the published indicators of compromise, patch vulnerable systems, disable exposed services, and enforce multifactor authentication.

πŸ”“ Telegram Desktop flaw enables account takeover LINK

  • A public proof-of-concept shows how a flaw in Telegram Desktop lets attackers steal local files and hijack accounts after a victim clicks a crafted link opened outside the app, such as from a browser.
  • The bug (CVE-2026-107181, high severity at CVSS 8.6) affects versions before 7.2.9: when a link is passed to a running Telegram through its local communication channel, a record-separator character is not escaped, so an attacker can smuggle in a second command.
  • That injected command reaches an outdated internal helper that reads local files and sends them to a chat without consent, exposing session files for account takeover; Telegram fixed it in version 7.2.9, and as of today the reporting shows no known exploitation.

πŸ› Hackers exploit backup server flaws LINK

  • Hackers are chaining two flaws in Ahsay's AhsayCBS cloud backup console, software used by managed service providers to centralize backup operations, to break in and run code on exposed servers, Huntress reports.
  • They first abuse a medium-severity authentication flaw, then a critical bug (CVE-2026-105134) in the Replication Receiver whose API accepts a random token in place of valid credentials, letting them run code as SYSTEM, drop a JSP webshell, and install the XMRig Monero miner.
  • Exploitation has been active since October 7; all AhsayCBS versions through 10.3.4 are affected with no patch yet, so Huntress says to restrict management-interface access to trusted IPs or VPN and, if compromised, fully re-image from a trusted backup because attackers hid secondary backdoors.

πŸ‘Ύ LMCache flaw lets hackers run code LINK

  • A critical flaw in LMCache lets attackers with no login run their own code against instances reachable over the network, by sending data that the caching system unpacks unsafely.
  • The bug (CVE-2026-105192, CVSS 9.8, critical) hits LMCache's multiprocess mode, which opens an unauthenticated ZeroMQ socket on port 5555; a crafted message slips a malicious pickle object that runs an operating system command while the data is being decoded, before any checks run.
  • JFrog published an advisory and working proof-of-concept exploit on October 7, 2026 with no fixed release available then; the vulnerable path exists across current releases, and operators are urged to keep localhost binding, avoid routable `--host` settings, and firewall off cluster access until a fix ships.

πŸ’‘ Strategies & Tactics

> Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules: This release adds hacking tools for AI model servers, streaming media software and a 26-year-old Windows flaw, showing how widely security testers must now probe.

> VirusTotal Adds Scanning for Public IPv4 Space to Expose C2 Servers and Malware Infrastructure: VirusTotal now scans the whole public internet daily, letting analysts find hidden attacker servers by matching fingerprints and open ports even without malware detections.

> OAuth grants pile up faster than you can review them. Here's how to keep up.: Use Nudge Security's AI agent to automatically find and risk-score every app-permission grant employees create, since manually reviewing thousands is impossible but each is a breach path.

> Inside the Exchange Inspector: How Tenable uses OpenAI GPT cyber models to review open-source AI agents: Tenable screens community-built AI security tools through automated scans, OpenAI's cyber models, and human testing before tagging them trustworthy, so teams know an agent's behavior before deploying it.

> Preventing The MCP Layer From Becoming A Cyber Threat: Verify the metadata of AI agent tools as rigorously as executable code, because hidden instructions there can manipulate agents without touching the model.

> Microsoft Says PKI, HSMs and Security Appliances Must Prepare for Post-Quantum Authentication: Microsoft urges organizations to test every system that issues or stores digital certificates before quantum-resistant authentication breaks hidden dependencies across hardware, applications, and vendors.

Other news you might like

  • Citrix warns admins to patch new NetScaler RCE flaw immediatelyLINK
  • Russian-aligned spies upgrade malware used in attacks on Ukrainian transport, energy firmsLINK
  • Hikvision Camera Vulnerability Targeted in Remote Code Execution Exploitation AttemptsLINK
  • Warden Stealer Malware Targets Claude, Codex, Grok and Cursor to Steal AI Agent DataLINK
  • Suspected TraderTraitor Hackers Trojanize Terraform Provider to Deploy Cross-Platform MalwareLINK
  • Malicious PDF Reader With 10,000+ Installs on Google Play Delivers Anatsa Banking TrojanLINK

🧰 Trending tools

VibeDefend: embeds your security and business rules into AI coding agents like Cursor, Copilot and Codex, catching vulnerabilities and policy violations before the PR.LINK

Google Gemini 3.8 Flash and Cyber: fast, affordable models for agentic coding, multi-step reasoning, autonomous tasks, and cybersecurity work like vulnerability detection.LINK

Axari: an AI security twin that works across your tools and teams, taking goals or recurring tasks from Slack and MS Teams until done.LINK

mcpgawk: locally records a baseline of your MCP servers and blocks tool calls when behavior or descriptions change, until you approve the shift.LINK

Strac Comply: automates SOC 2, ISO 27001, HIPAA and PCI compliance by connecting your cloud tools, running 100+ continuous tests, and mapping AI apps to sensitive dataLINK

PortAura: monitors which processes listen on which ports locally on macOS, flagging changes from your baseline without needing Terminal commands.LINK

πŸ“š Trending papers & reports

Security certification failures are mapped into a clear catalog of why products stall or fail the main international IT-security evaluation standard, giving vendors a checklist to prepare before evaluation instead of discovering problems during it.LINK

Expert-routing logs leak whether specific data was used to customize a model, with these internal traffic signals boosting the odds of detecting training examples by up to ~9 percentage points over standard methods.LINK

Chatbot forensics can identify which company's AI powers an anonymous scam bot with 98% accuracy from a few normal messages, and tell whether two bots share identical instructions, helping investigators trace AI scams to their source.LINK

Security alert triage by AI investigators missed at least 40% of attack-related alerts across every tested approach, so the researchers built a system that forces tougher evidence and an independent challenge before dismissing any alert.LINK

AI safety filters can be fully bypassed by a new attack that slipped malicious prompts past 6 multi-layer guardrail systems every time, using 72% fewer attempts and transferring to commercial defenses it had never seen.LINK

See you tomorrow for a new dose of β˜•οΈ Cyberpresso!

More from the archive