This website uses cookies

Read our Privacy policy and Terms of use for more information.

MCP — the Model Context Protocol — has become the connective tissue of agentic AI deployments. It's how AI tools talk to external services, access data sources, and chain actions together. It's also, as of this week, a largely unaudited attack surface. Researchers examined 15,465 public MCP servers and found servers running on personal computers, through expired domains, hosted abroad with no clear accountability, and with little to no security oversight as a baseline. Nobody is checking. The marketplaces that list these servers have not added meaningful vetting. Organizations deploying AI agents are trusting infrastructure they haven't verified.

The Tensorlake npm compromise this week makes the point more concretely: a malicious package that targets Claude Code and VS Code workspaces, steals credentials, spreads to other packages, and stays active after removal. The AI development layer is now a specific, named target — not collateral damage in a broader npm campaign, but a deliberate focus. The pattern from the last year of supply chain attacks is repeating itself one layer up: attackers found the developer toolchain, exploited it for months, and the ecosystem is now discovering that the AI infrastructure layer is next. The security model for that layer doesn't exist yet.

Table of Contents

🔓 BREACHES & SECURITY INCIDENTS

🇨🇭 TheGentlemen ransomware group breached Ixa Systems, a Vaud-based physical security firm, stealing sensitive data from clients including prisons, banks, hospitals, and schools. Stolen data reportedly includes surveillance camera locations, access control passwords, and security installation blueprints. The stolen files were put up for sale on the dark web roughly a month after the late-August attack.

🇺🇸 A 2025 hack of legacy Cerner systems may have exposed the personal and health information of about 20 million people. The breach involved data such as Social Security numbers and medical records, and affected patients across several states. Oracle is facing proposed class-action lawsuits over the incident.

🇰🇷 🏦 South Korea is investigating cyberattacks and data breaches at several banks. The incidents reportedly exposed customer and credit card information. Officials suspect AI-powered tools may have been used, but this has not been confirmed.

🗾 A ransomware attack shut down part of IDC Frontier’s IDCF Cloud service in eastern Japan, affecting 495 companies and local governments. The company isolated affected systems and disabled customer console access while it checks security and investigates the damage. Other Japanese firms have also faced cyber incidents, and experts say attacks are increasing.

🗾 Attackers broke into two Nikkei employees’ email accounts — One breach exposed contact details, while the other sent 9,000 phishing emails. Nikkei reset passwords and warned recipients to delete the messages.

🇺🇸 Two healthcare companies, Clover Health and AngMar Management Services, suffered separate data breaches affecting more than 250,000 people. Stolen information included personal and medical details, such as Social Security numbers, insurance information, and health records. Both companies reported the incidents to federal health authorities.

🇩🇰 Hackers accessed Danish DTU’s user system and may have exposed personal data belonging to up to 200,000 people. The data may include CPR numbers, contact details, work information, and next-of-kin details. DTU advises anyone connected to the university since 2003 to watch for scams and secure reused passwords.

🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s

🇨🇳 ❌ The DOJ and FBI seized Microscan and FishHub, hacking tools tied to Chinese group Flax Typhoon and company Integrity Technology Group. U.S. agencies say the tools helped target organizations worldwide, including critical infrastructure and universities. They warned that Chinese-linked hackers may be seeking ways to disrupt vital systems.

🗾 🇩🇪 A suspected Qilin ransomware member was arrested in Japan and extradited to Germany. He is accused of hacking a logistics company and demanding over $160,000 in cryptocurrency. Qilin has attacked hundreds of organizations, causing major disruptions and data breaches.

🔐 Attackers hijacked the .gh, .sl, and .as domain registries and obtained fake security certificates for Google and YouTube sites. Google and the certificate providers blocked or revoked the certificates, but it is unknown whether attackers used them to steal data. Domain owners should monitor certificate records, restrict which providers can issue certificates, and report certificates they did not request.

🇺🇸 A former CIA officer admitted to inventing a secret government program to steal nearly $200 million. Authorities found gold bars, cash, and luxury items at his home. He faces up to 20 years in prison.

🇺🇸 ⚖ A former engineer was sentenced to 32 months in prison for locking thousands of his employer’s devices. He changed passwords, deleted administrator accounts, and demanded about $750,000 to restore access. He also threatened further attacks unless the company paid.

🇨🇳 🎣 🇺🇸 A China-aligned group called TA419 is targeting U.S. AI policy experts with convincing phishing emails. It uses fake Microsoft sign-in pages to steal passwords and session cookies without raising suspicion. Experts should verify unexpected messages, and organizations should use phishing-resistant sign-in methods such as passkeys.

🇬🇧 🇨🇳 MI5 says a Chinese organization linked to China’s state security service funded research involving more than 100 U.K.-linked academics. It warns that the work could support espionage and urges universities to check research funding and collaborations. China’s embassy denies the allegations and says U.K.-China academic exchanges are lawful and beneficial.

🇯🇴 🇺🇸 A suspected ShinyHunters member known as Rey was reportedly detained in Jordan and is helping the FBI identify other members. The arrest follows a wider investigation into the group, which has been linked to major data theft and extortion attacks. ShinyHunters’ online activity briefly went quiet, but a new leak site suggests the group is still operating.

→ More breaches:

🗓️ {Cyber,Info}Sec Events — A community-maintained list of infosec conferences worldwide. Subscribe to the ICS calendar feed to get events straight into your calendar, or follow @[email protected] on Mastodon for weekly digests. Contributions and ⭐ welcome!

👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY

🇨🇳 🇹🇼 A think tank warns that China could pressure Taiwan through ongoing cyberattacks and disruptions to communications, rather than invading. The attacks could strain backup systems and spill over into power and other parts of daily life. Taiwan’s resilience and support from allies such as the U.S. and Japan could help it withstand the pressure.

🇺🇸 👋 The FBI removed an Accenture contractor after a missed security patch helped ShinyHunters breach its job portal. The attackers stole personal details of thousands of FBI employees. The FBI is investigating, and more arrests may follow.

🇮🇹 Italy fined IQVIA $7.8 million for failing to properly protect patients’ health data — Unique codes and detailed records could have allowed about one million patients to be identified. Authorities also found legal and data-retention violations and ordered IQVIA to fix its practices within 120 days.

🦠 MALWARE & THREATS

📦 The compromised Tensorlake npm version 0.5.144 contained malware that steals credentials and secrets, spreads to other packages, and can run attacker-controlled code. It may also stay active after removal and target affected projects when opened in Claude Code or VS Code. Anyone who installed it should remove it and rotate all exposed credentials.

📦 A long-running NPM malware campaign dubbed MALFEX has gained more than 40,000 downloads across its malicious packages. The packages can install spyware and stealers that target Windows users and steal data from browsers, Discord, and crypto wallets. Exposure is limited to systems that directly installed the packages.

🤖 PoeLLM malware has infected more than 3,400 servers by targeting open-source AI services. It uses changing words in a GitHub poem to secretly find its command server. The infected servers form a growing botnet that can scan for weaknesses, mine cryptocurrency, and enable further attacks.

📄 A malicious spreadsheet can run code in LibreOffice or OpenOffice without a macro warning, but Java must be enabled. LibreOffice has fixed the flaw; OpenOffice has not, and a fix is still being tested. Until then, OpenOffice users should turn off Java or avoid untrusted spreadsheets.

🐧 🔙 🚪 ClingSTUN is a Linux backdoor that turns infected devices into proxies using the STUN protocol. It exploits many security flaws to spread, stay active after reboot, and run remote commands. It also uses public STUN servers, so defenders should look for suspicious processes and repeated UDP traffic.

🤖 🧰 AI, CRYPTO, TECH & TOOLS

🔎 🐛 Anthropic launched a free, opt-in AI scanner that periodically checks selected open-source projects for security flaws. Maintainers can enroll their projects through GitHub, and the scanner sends reports without human review. Anthropic says the effort aims to help defenders fix vulnerabilities faster as AI-powered cyber threats grow.

🔬 Researchers examined 15,465 public MCP servers and found little to no security oversight. Some servers run abroad, on personal computers, or through expired domains, putting data at risk. Until marketplaces add stronger checks, companies must verify the servers their AI tools use.

🍎 🔑 Apple is changing macOS privacy settings to limit apps’ access to message histories. The move follows a report that Meta’s Muse AI referenced a private Apple Messages conversation. Meta says users must grant Muse two permissions for it to access Messages.

🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE

➝ From the Patching Department:

🐛 💥 Hackers found 32 zero-day flaws on the first day of Pwn2Own Ireland and won $388,500. They attacked phones, smart-home devices, printers, and AI products, including hacking the Samsung Galaxy S26 twice. The contest helps vendors fix security flaws before they are publicly disclosed.

🩸 The FBI and Secret Service warn that FortiBleed is still stealing credentials from exposed Fortinet devices. Attackers use stolen passwords to break in, create hidden accounts, and move through victim networks. Organizations should secure affected devices, reset passwords, and check for suspicious activity.

🛑 Google has temporarily stopped paying rewards for product vulnerability reports in its open-source software program because most recent automated submissions were invalid. Supply-chain reports are still accepted, and reports filed before October 1 remain eligible. Google plans to update the program in early 2027, but has not said when product reports will reopen.

⚠ A critical flaw in eight self-hosted Atlassian products could let unauthenticated attackers read files if they know the exact file path. Atlassian has released fixes and urges customers to upgrade; temporary blocking rules are not a substitute. Cloud products are patched, but self-hosted customers should check access logs for suspicious requests.

🛰️ ICS, OT & IoT

🤖 Anthropic is pairing its Claude AI with human experts to help 11 providers find and fix security risks in critical infrastructure. Many industrial systems are difficult to patch without disrupting essential services. Experts say AI can help spot problems, but people must guide safe repairs.

🇺🇸 A coalition wants CISA to require federal agencies to improve security for operational technology, such as water and building systems. It recommends naming a security lead, setting basic protections, and using existing guidance. The goal is to help agencies manage risks and send a clear example to private companies.

💬 CONNECT

Follow me on Mastodon for quick daily updates and bite-sized content.

Prefer using an RSS feed? Add Infosec MASHUP to your feed here.

Enjoying our newsletter? Forward it to a colleague—
it’s one of the best ways to support us.

Thanks for reading today’s newsletter, and if you're enjoying it and want to support my work, you can buy me a coffee ☕ over at https://www.buymeacoffee.com/0x58

See you next time!

-X.

Reply

Avatar

or to participate