In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years
AI malware, supply chain attacks, crypto hacks, and CISA retention pay updates.
Summary
This roundup covers several cybersecurity incidents, including PoeLLM malware using GitHub poems for C&C communication, the GhostAction campaign expanding to more GitHub repos, a jury convicting a hacker for the Uranium Finance breach, CISA updating its cyber retention pay criteria, and South Korea investigating AI's potential role in bank cyberattacks.
Full text
SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers stay well-informed about the evolving cybersecurity environment. Here are this week’s highlights: PoeLLM malware finds its C&C server hidden in a GitHub poem Black Lotus Labs has detailed PoeLLM, a malware active since at least April 2026 that targets exposed AI and open-source services (mainly LiteLLM, Ollama, Gotenberg and Gitea) to mine cryptocurrency and expand its botnet. Infected machines extract four keywords from a poem hosted on GitHub and convert them into the IP address of the current C&C server, so the operator can switch servers by changing those words. The operator, assessed to be Italian-speaking, has updated the poem 11 times. Advertisement. Scroll to continue reading. GhostAction secret theft spreads to 772 more GitHub repos GitGuardian says the GhostAction supply chain campaign pushed its secret-stealing GitHub Actions workflow to 772 public repositories (belonging to 373 users and organizations) between August 31 and September 30, targeting 2,577 secrets such as SSH keys and Azure, AWS and database credentials. Apart from a new exfiltration server, the attacker reused the 2025 playbook, and GitGuardian’s data shows the campaign never really stopped. Jury convicts Uranium Finance hacker A jury has convicted Jonathan Spalletta, 36, of Maryland, of computer fraud and money laundering over two 2021 hacks of decentralized crypto exchange Uranium Finance. He abused smart contract flaws to take roughly $1.4 million and then $53.3 million (the second attack forced Uranium to shut down), laundered the funds through a series of crypto transactions that included Tornado Cash, and used them to buy collectibles such as rare Magic: The Gathering and Pokémon cards and antique Roman coins. He faces up to 10 years in prison on the fraud count and 20 years on the money laundering count. CISA narrows cyber retention pay CISA will keep its Cybersecurity Retention Incentive program (worth up to 25% of base salary) through fiscal 2027, but under new criteria staff must hold an “exceeds expectations” or higher rating and spend at least 51% of their time on cyber duties in one of three job series. Those outside the series who spend 75% or more on cyber work can apply to a review board. The overhaul follows a DHS inspector general finding that the program was mismanaged and applied too broadly. Coalition maps out what a CISA directive for federal OT should require The Operational Technology Cybersecurity Coalition (OTCC) has published a proposal for a CISA BOD focused solely on OT at federal civilian agencies, which rely on more than 8,000 GSA-managed facilities with HVAC, power management, access control and building automation systems. The group wants the directive to require agencies to designate a senior official or office accountable for OT security, apply relevant existing requirements, and prioritize CISA’s Cybersecurity Performance Goals. Domino’s resets accounts hijacked with recycled passwords Domino’s is telling a small number of customers that their accounts were accessed by an unauthorized third party through credential stuffing, using email and password pairs leaked in unrelated breaches. The company says its systems were not compromised and it doesn’t store payment details, but it has reset the affected accounts. AI under suspicion as South Korea probes bank cyberattacks South Korean President Lee Jae Myung said there are signs that AI was used in some of the recent hacking incidents targeting the country’s banks. Police have reportedly launched a full-scale investigation into the attacks, which led to a breach of customers’ personal information. Authorities have yet to reveal which AI tools were used or the full scale of the breaches. CrowdStrike this week reported finding Claude Code session histories, ARTEX configuration files, and Claude memory files while analyzing the attack infrastructure. The security firm believes with moderate confidence that a Chinese-speaking financially motivated threat actor is likely behind the attacks. Empire Market co-founder gets four decades behind bars Raheim Hamilton, 30, of Virginia, has been sentenced to 40 years in prison and fined $5 million after pleading guilty to a drug conspiracy charge over Empire Market, the dark web marketplace he co-created and ran with Thomas Pavey from 2018 to 2020. The site handled more than four million transactions worth over $430 million, mostly drug sales, and also sold stolen credentials and personal information, counterfeit currency and hacking tools. Pavey, who pleaded guilty last year, is scheduled to be sentenced later this month. Exposed Nvidia DCGM exporters leak telemetry from 12,000 GPUs Researchers have disclosed CVE-2026-47483, a high-severity flaw in Nvidia’s DCGM Exporter GPU monitoring tool. Unauthenticated attackers can flood its profiling endpoints with requests to exhaust resources and crash the service, potentially slowing AI workloads running on the same host. In scans between March and May 2026, the researchers found roughly 2,100 hosts exposing the exporter to the internet without authentication, leaking telemetry from more than 12,000 GPUs. Nvidia has addressed the flaw, and users are advised to update to version 4.8.2 or later. Shai-Hulud-style worm slips into Tensorlake’s npm SDK Version 0.5.144 of tensorlake, the npm SDK for Tensorlake’s AI agent sandboxes, was compromised to run a credential-stealing worm during installation, in what Socket describes as a ChainDrop/Shai-Hulud supply chain attack. Socket and Sonatype say the malware harvests npm, GitHub, AWS, Kubernetes and Vault credentials, as well as AI coding tool configurations. It can execute code supplied by the attacker and republish itself through other packages the victim can publish. Related: In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure Related: In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats Written By SecurityWeek News Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from SecurityWeek News In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI ChatsOsavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical DomainsRemoteThreat Launches With $7 Million for Offensive Operations PlatformIn Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility ExposureIsland Raises $400 Million at $6.4 Billion ValuationCyera Raises $400 Million at $12+ Billion ValuationIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawVirtual Event Today: Attack Surface Management Summit Latest News Google Domains Impacted by Recent ccTLD HijacksUnpatched AhsayCBS Vulnerabilities Exploited in the WildPre-Baked Firmware Malware Hits Budget Android Devices in 150+ CountriesUS Disrupts Chinese State-Sponsored Hacking ToolsAnthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT SecurityCitrix Urges Immediate Patching of Critical NetScaler VulnerabilityGoogle Pixel 10 Exploits Earned Hackers $560,000 at Pwn2OwnFormula Predicts When AI Chatbots Are at Risk of Turning Bad Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a cen
Indicators of Compromise
- malware — PoeLLM
- malware — Tornado Cash