Back to Feed
Threat IntelligenceSep 17, 2026

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

New threats include AI agent self-modification, PPI malware distribution, and LocalAI instance exploits.

Summary

This week's threat landscape highlights new attack vectors including AI agents that can retrain their own models, potentially leaking secrets and bypassing safety protocols. A pay-per-install (PPI) marketplace, CL-CRI-1171, has been identified distributing malware like Docro Hijacker and ARKTunnel via YouTube and SEO poisoning. Additionally, a large-scale campaign is exploiting unauthenticated LocalAI instances, leading to command execution, data exfiltration including sensitive personal information and AWS credentials, and cryptocurrency theft.

Full text

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories Ravie LakshmananSep 17, 2026Hacking News / Cybersecurity News Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough. So the threat landscape is not getting cleaner. It is just getting more places to make the same mistake. Here’s what showed up this week. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out. Malware PPI operation exposed CL-CRI-1171 Offers PPI Marketplace A threat actor known as CL-CRI-1171 has stayed under the radar for at least two years, offering a pay-per-install (PPI) marketplace that allows other threat actors to distribute their malware through YouTube channels and a parallel search engine optimization (SEO)-poisoning funnel. "These channels were actively interacting with viewers to promote gaming content laced with links to download malware," Palo Alto Networks Unit 42 said. "Although the videos provided real content for gamers, they also served as the delivery vehicle for infection, prompting viewers to download malicious tools. The SEO funnel targeted a more professional audience, promoting trojanized software that resulted in malware deployment on corporate endpoints, including critical infrastructure and even government entities." Both these chains lead to a custom loader called OfferLoader that has delivered three payloads between July 2025 and April 2026: Docro Hijacker (a Chrome backdoor that can bypass modern integrity protections), ARKTunnel (a WebSocket tunneling RAT), and a new variant of a previously unnamed cross-platform backdoor that's been codenamed Insomnia remote access Trojan (RAT) and can target both Windows and macOS. Post-April 2026, the PPI infrastructure has led to GCleaner and Socks5Systemz. Exposed LocalAI instances compromised Large-Scale Attacks Target LocalAI Infrastructure A large-scale campaign has been found to target LocalAI instances exposed to the internet without authentication and achieve command execution inherent in MCP STDIO configuration. "Attacker artifacts indicated that 230 of 243 unauthenticated LocalAI instances were assessed as exploitable," Oasis Security said. "Callback logs independently confirmed command execution with root privileges on 23 servers. Post-compromise activity included exfiltration from a workstation associated with the Thai military and collection of 127 AWS credential records." The unknown threat actor is said to have selected high-value infrastructure from those LocalAI targets and compromised a desktop LocalAI workstation and a related private network. This was followed by exfiltration of sensitive data, including personal information, GPS coordinates, banking-application screenshots, and national ID card scans. Additional compromise activity consisted of exploitation of legacy infrastructure, authentication bypass, a broad sweep of cryptocurrency wallets and API keys, and theft of AWS ECS task credentials. Agents rewrite their own models AI Agents Can Retrain Own Models Mid-Task New research from Irregular has found that AI agents can retrain the model that powers them, in the process leaking secrets and eliminating refusals the model had been previously trained to enforce. "Given a routine software-maintenance task to fix incorrect application responses, the agent identified the shared model as the source of the problem, fine-tuned it, and replaced the model powering both the application and future instances of the agent itself," Irregular said. "It did so without being instructed to train, modify the model, or deploy a replacement." This phenomenon has been codenamed agentic self-modification. "Nothing in these experiments establishes malicious intent, self-preservation, or deception; the agents modified models because training appeared to help accomplish the assigned engineering task," Irregular added. "Agentic self-modification can arise during ordinary software maintenance when a coding agent has access to the model weights, training tools, and a deployment path to modify the model directly." AI agent linked to data breach Spain's Data Protection Agency Receives First Report of AI-Powered Data Breach The Spanish Data Protection Agency (AEPD) said it was notified of a data breach that was allegedly executed by an AI agent. "The attacker launched a scan for vulnerabilities in generic files and successfully logged in," AEPD said. "Once inside the system, the attacker began independently searching for vulnerabilities in the application; once found, this allowed the attacker to modify personal data and access invoices. What is relevant from a data protection perspective is that a third party appears to have used an AI agent as a tool to successfully chain together different phases of the attack." Ransomware exploits VMware RCE Critical VMware RCE Flaw Now Exploited by Ransomware Gangs The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that ransomware gangs have now started exploiting a critical VMware vCenter vulnerability patched in July. The flaw, tracked as CVE-2026-59310, is a critical directory traversal vulnerability in the vCenter Syslog server that unauthenticated attackers can exploit to execute arbitrary code. In August 2026, German incident response company QUIRSO uncovered evidence that a China-nexus advanced persistent threat (APT) has been exploiting the flaw shortly after public disclosure. Oracle patches 800-plus flaws Oracle Announces Patches for 100s of Flaws Oracle has announced the release of new security patches as part of its September 2026 Critical Security Patch Update (CSPU). The patches address over 800 flaws. None of them have been flagged as actively exploited. "It's hard not to sound like a broken record these days when talking about security updates," Tyler Reguly, Fortra's Associate Director of Security Research and Development, said. "We're continually seeing large numbers of vulnerabilities and we're all starting to feel a little burnt out. I've said it before and I say it again, there is a light at the end of this tunnel and the record numbers of patches for record numbers of vulnerabilities will not last. I'm confident of this. Do everything you can to avoid burning out and just work on surviving this onslaught. I think that CISA BOD 26-04 did a great job of helping people to understand how to prioritize based on risk. I think that a 3-day turnaround is very tight when you need to also test your patches, but it helps lay out priorities that make a real difference – is it publicly exposed, is it on the Known Exploited Vulnerabilities list, can it be automated, and does it give complete control. When you can answer these questions, you can start to identify the risk that it plays. Are there other components you can include? Sure, but this is a great start if you don’t really know what risk looks like for your organization. Once you know what risk looks like, you can start to prioritize your patches more appropriately." Insider SIM swaps draw prison term Oregon Man Sentenced to 16 Months in Prison for SIM Swaps Former Oregon-based AT&T Store employee, Kenneth Carter, 44, has been sentenced to 16 months in prison for abusing his access to perform SIM swaps that helped criminals take over customers' bank accounts. Three victims suffered intended losses of nearly $600,0000, with Carter typically receiving $1,000 to $2,000 for each fraudulent SIM swap. Carter, who worked at the store from May 2018 to November 2019, has also been ordered to pay $99,528 in restitution. Carter pleaded guilty to the crimes earlier this March. AI drives malware evasion Threat Actors Use AI for Polymorphic Mal

Indicators of Compromise

  • malware — Docro Hijacker
  • malware — ARKTunnel
  • malware — Insomnia
  • malware — GCleaner
  • malware — Socks5Systemz
  • malware — OfferLoader

Entities

CL-CRI-1171 (threat_actor)LocalAI (product)YouTube (product)SEO poisoning (technology)