Here is your briefing for Monday, August 31, 2026. The Aurora ransomware crew has been using Cursor as a hands-on operator. CloudSEK and Gambit Security pulled months of leaked activity, including a full Active Directory Certificate Services attack plan written in Russian. Gambit watched Cursor Agent, running Claude Sonnet, work ten targets between April and May. The agent got credentials or a SOCKS tunnel, then scanned subnets, enumerated domain privileges, tried N.T.L.M. relays, and ran Certipy. Sometimes the attacker just picked a number off the agent's next-step list. This is not a demo. It is a ransomware shop with a coding assistant on the keyboard. Sygnia says the China-nexus group Fire Ant has moved past VMware hypervisors and into Cisco I.O.S. X.R. routers, TACACS servers, and Linux jump hosts. Investigators first spotted a G.R.E. tunnel on a router with no config history. The malware hides show commands, drops logs unless they contain the word Health, and dumps packet captures to F.T.P. On the TACACS box, a new toolkit called TacTap injects a library into the authentication daemon and obfuscates stolen credentials. A second implant, BridgeAgent, pretends to be Zabbix. When they own the router, they do not just get reach. They get the view. OpenAI published an open letter signed by more than one hundred companies, including Anthropic, Google, Microsoft, and A.W.S., warning that A.I.-enabled attacks will get far more common in the coming months. Hospitals, water plants, and internet infrastructure sit at the top of the risk list. Meta, Nvidia, and Apple did not sign. The letter tells organizations to treat cyber defense as a leadership problem and to raise the bar on A.I.-generated code. It does not include deadlines or spending pledges. One critic called it an arsonist selling fire extinguishers. Aurora using Cursor this morning is the part they did not have to invent. Microsoft disclosed TerminalFix, a ClickFix variant that skips the Run dialog and sends victims to Windows Terminal or PowerShell instead. Fake Cloudflare CAPTCHA pages tell people to paste a command, which makes longer scripts much more likely to land. The chain uses D.L.L. sideloading, payloads hidden in P.N.G. files, Active Directory recon, and a Python reverse tunnel over an encrypted WebSocket. From there, the attacker can reach anything the victim machine can see. Treat unexpected Terminal prompts like a phishing email that already has a shell. Wordfence and Patchstack flagged critical bugs in the WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. Four of them score nine point eight. GiveWP is a perfect ten, chaining a broken serializer into remote code execution on sites with a live donation form. These are not obscure plugins. Avada and GiveWP sit on a lot of production sites. If you run WordPress, patch the dashboard, the theme, the translation plugin, Pods, and the donation form before the scanners finish breakfast. A ransomware crew with a coding agent, a China-nexus group living in the routers, a hundred vendors warning that this gets worse in months, a fake CAPTCHA that hands over a tunnel, and five WordPress tens hiding in plain sight. The common thread is tools we already trust doing work we never reviewed. That's your brief. Stay sharp, patch your systems, and we'll see you tomorrow.
Support the show