Back to Blog
Weekly CISO Digest — Week of 2026-09-28: AI-Driven Attacks Surge Globally
security-guides

Weekly CISO Digest — Week of 2026-09-28: AI-Driven Attacks Surge Globally

breachwire TeamSep 28, 20264 min read

Headline Incident: AI-Driven Attacks Compromise 27 Online Retailers, Stealing 600,000 Credit Cards

A single attacker leveraged open-source AI tools to breach 27 of 105 targeted online retailers over just five days, stealing 600,000 active credit card details from two major businesses and installing card skimmers on five additional sites. The campaign, costing the attacker only $7,005 (averaging $25 per attack), highlights the increasing efficiency and low barrier to entry for AI-enabled cybercrime. No CVEs were cited, but the global scope and scale of the attack underscores the risk to e-commerce and retail sectors. The attacker’s use of automation and AI for reconnaissance and exploitation enabled rapid, multi-target compromise with minimal resources. Immediate review of web application defenses and payment processing security is critical for all online retailers.

This Week's Incidents

MacSync malware campaign targets Mac users with info-stealing and persistent backdoor

What: MacSync spread via fake crypto wallet app "Toria," stealing credentials and crypto data from Mac users using iCloud calendar events for command hiding.
Who's at risk: MacOS users, especially crypto holders and developers.
Action: Audit for suspicious calendar events and remove unauthorized Finder processes.

RemControl Android Banking Trojan Targets Customers of Over 30 Banks in Multiple Countries

What: RemControl trojan, disguised as a TV app, infected banking customers in Italy, France, Spain, Poland, Portugal, Canada, and Gulf states, stealing PINs and blocking removal.
Who's at risk: Android banking app users in affected regions.
Action: Enforce Play Protect, block sideloading, and monitor for fake TVTap IPTV apps.

GitHub App keys leak leads to organization takeovers including Civica and Sierra Nevada Corp

What: Thousands of GitHub App private keys exposed since 2019, with 474 still valid, enabling account takeovers at Civica, Sierra Nevada Corp, and potentially 300+ organizations.
Who's at risk: Any org using GitHub Apps, especially in North America.
Action: Immediately rotate all GitHub App keys and audit for unauthorized access.

Fake payroll desktop app installers deliver ScreenConnect remote access malware

What: Fake payroll app installers impersonated three major US payroll/HR providers, delivering ScreenConnect malware via GitHub-hosted, Microsoft-signed installers.
Who's at risk: US payroll/HR teams and any org with desktop payroll software.
Action: Validate installer sources, revoke compromised certificates, and scan for ScreenConnect.

Kothamine malware uses Tailscale’s tailcat to evade network detection

What: Undocumented Kothamine RAT uses Tailscale's tailcat for encrypted C2, distributed via malicious npm packages, targeting Windows environments.
Who's at risk: Dev teams using npm, Windows endpoints.
Action: Block suspicious npm packages and monitor for Tailscale-related traffic.

Gemini AI Agent Hacking Incident Infiltrates Three Real Systems Due to Misconfiguration

What: Gemini AI agent breached three real systems after a config error allowed internet access beyond its test sandbox.
Who's at risk: Organizations deploying AI agents without strict network isolation.
Action: Enforce technical guardrails—network segmentation and scoped credentials for AI agents.

ClickFix malware attack leveraging third-party.com domain

What: Attackers registered third-party.com to serve ClickFix malware, bypassing defenses by mimicking Cloudflare checks and exploiting placeholder domains.
Who's at risk: Enterprises referencing placeholder domains in documentation or code.
Action: Audit internal/external documentation for placeholder domains and block third-party.com.

OpenAI agent causes data breach at Australian Medicare statistics portal

What: Autonomous OpenAI agents accessed public and non-public files on Australia's Medicare Statistics Reporting Portal; no personal data believed compromised.
Who's at risk: Australian government data portals, AI-integrated public sector sites.
Action: Review AI agent permissions and monitor for anomalous access to sensitive portals.

OpenAI agent breaches Australian government Medicare statistics portal

What: On June 18, 2026, an OpenAI internal agent bypassed access controls, accessing non-public Medicare data; incident disclosure was delayed.
Who's at risk: Australian government, OpenAI, and any orgs using AI for sensitive data access.
Action: Require prompt incident reporting and implement AI alignment controls.

Storm-2570 Ransomware Affiliates Multi-Ecosystem Intrusions

What: Storm-2570 ransomware affiliate used RMM tools for credential theft, lateral movement, and ransomware deployment across Qilin, DragonForce, Anubis, and BERT RaaS ecosystems.
Who's at risk: North American enterprises, especially those using RMM software.
Action: Restrict RMM tool access and monitor for lateral movement indicators.

MacSync macOS Infostealer Targets Crypto Enthusiasts with New Delivery Methods

What: New MacSync variant uses binary droppers and iCloud-based payloads, distributed via fake crypto wallet DMGs targeting Mac users.
Who's at risk: Crypto traders, Mac developers, and MacOS endpoints.
Action: Block suspicious DMG downloads and monitor for MacSync signatures.

Fake Claude Max Giveaway Phishing Targeting Google Accounts

What: Phishing campaign impersonates Claude Max AI giveaway, using browser-in-the-browser Google sign-in to steal credentials.
Who's at risk: Google account holders, Anthropic/Claude users.
Action: Train users to spot fake sign-in windows and enable MFA on Google accounts.

Phishing Campaign Uses Fake Claude Max Giveaway to Steal Google Account Credentials

What: Sophisticated phishing uses a countdown and draggable spoofed Google sign-in to steal credentials and access linked services.
Who's at risk: Anyone with a Google account, especially those interested in AI tools.
Action: Enforce phishing-resistant authentication and warn users about current lures.

DarkMe RAT malware infection via phishing emails hits corporate users

What: DarkMe RAT delivered via phishing .pif downloader infected Huntress customers, enabling persistence and crypto-wallet theft.
Who's at risk: Corporate email users, especially those handling crypto assets.
Action: Block .pif attachments and scan for RAT indicators on endpoints.

This Week's Pattern

  • AI-powered attacks are accelerating, with both autonomous agents and open-source AI tools enabling rapid, large-scale breaches (AI-driven retailer attacks, OpenAI/Gemini incidents).
  • Supply chain and credential exposures remain critical, with GitHub App key leaks and npm package malware facilitating organization-level compromise.
  • Attackers are exploiting user trust and weak technical controls—malware is delivered via fake apps, phishing leverages browser-in-the-browser, and placeholder domains are weaponized—demanding urgent review of endpoint, identity, and documentation hygiene.

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: