Attackers are impersonating popular AI brands like Perplexity, Claude, ChatGPT, and Copilot to spread information stealers, backdoors, malicious browser extensions, and other malware, according to Sophos. Overview of MDR cases with AI involvement (Source: Sophos) Sophos X-Ops reviewed 12 months of managed detection and response cases, covering July 2, 2025 through June 29, 2026. Of 86 cases initia

Cybersecurity researchers have identified a widespread campaign where attackers impersonate popular artificial intelligence brands such as Perplexity, Claude, ChatGPT, and Copilot to distribute various forms of malware, including information stealers, backdoors, and malicious browser extensions. The findings are based on an analysis of 38 confirmed incidents over a 12-month period, from July 2025 to June 2026.
In 35 of these cases, the malicious activity directly targeted AI products, brands, or their associated ecosystems. Software impersonation was the most common tactic, accounting for 30 incidents. Claude was the most frequently impersonated brand, appearing in 26 cases.
Many incidents involved a technique dubbed "InstallFix," which mimics a legitimate software installation process. Unlike "ClickFix" attacks that simulate error or verification steps, InstallFix pages present detailed, step-by-step installation guides. These guides ultimately instruct users to copy and execute obfuscated commands, leading to malware infection. For instance, a fake Claude website was observed guiding a victim through an `mshta` command that retrieved a payload from a deceptive domain. The download was packaged as a Windows application, either `claude` or `claude.msixbundle`, which, upon execution, fetched code that ran in memory and attempted to compromise browser processes. Other variants included a booby-trapped `Claude Setup.zip` archive and a repackaged `claude.exe` acting as a malware loader.
Beyond direct software impersonation, attackers also leveraged malicious browser extensions. Several extensions posing as AI assistants, including one marketed as "AI Sidebar with DeepSeek, ChatGPT, Claude," were found to function as information stealers, communicating with command-and-control infrastructure. In one notable case, four customers installed a fake Perplexity extension distributed via the Chrome Web Store. This extension hijacked search queries, rerouted them through a lookalike domain, and transmitted browsing data to attacker infrastructure in real time. The extension had accumulated a 4.7-star rating from 67 reviews and claimed over 10,000 users, lending it an appearance of legitimacy.
The investigation also uncovered instances where attackers appeared to use AI for malware development. In one case involving a financial services organization, researchers identified a remote access Trojan (RAT) written in Rust that communicated via Slack. The malware was linked to a public GitHub repository whose commit history indicated collaboration between a human account and a Claude coding agent. This RAT was designed to poll a Slack channel for commands, with planned capabilities including command execution, file retrieval, configuration data downloads, persistence through scheduled tasks, and the potential to open a reverse shell. The development of this malware was tracked over several days through the repository's commit history.
Additionally, during a separate ransomware investigation, researchers observed potential signs of AI-generated code, characterized by unusually detailed comments and structured PowerShell code. However, these characteristics were considered circumstantial evidence and did not definitively confirm AI involvement in code generation.
Despite these findings, there is no evidence to suggest that AI is autonomously conducting attacks. The observed use of AI by attackers has been at the "lightest-touch end of the scale," primarily in generating code, with human operators remaining in control of the attack process. The most effective defenses against these impersonation tactics rely on conventional protections against malicious delivery and payload behaviors, rather than AI-specific characteristics. Users are strongly advised to install AI tools exclusively from confirmed vendor domains to mitigate risk.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed