Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments.

A sophisticated espionage campaign, dubbed "SilkParasite," has been uncovered, targeting government entities across Central Asia with previously undocumented malware strains, some of which show signs of AI-assisted development. Cybersecurity firm Bitdefender identified seven distinct malware families in use, five of which had not been previously documented, and linked the operation to state-sponsored actors based in China.
The investigation began with a suspicious infection at an economic-related government institution in an unspecified Central Asian nation. Forensic analysis revealed an operation that had been active for nearly a year, with 65 confirmed infections, predominantly in Asia. The campaign's lure documents were designed to appear relevant to government agencies in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Georgia, and Kazakhstan, often impersonating official ministries.
Initial access for the attackers was typically gained through spearphishing emails containing malicious Microsoft Office documents. These documents were frequently packaged within archives to bypass email gateway scanning mechanisms.
One of the most widely deployed malware strains, "DriveSilkRAT," exhibited a unique command and control (C2) mechanism. Unlike conventional malware that communicates with dedicated C2 servers, DriveSilkRAT leverages shared Google Drive folders. This method allows the threat actors to blend their malicious traffic with legitimate Google Drive activity, making it less conspicuous to network monitoring tools.
Bitdefender’s attribution of SilkParasite to China is based on several factors, including links between one of the malware strains and another known China-based espionage group, as well as the use of IP addresses tied to Chinese telecommunications companies. The firm theorizes that China's economic expansion in Central Asia, potentially filling a vacuum left by Russia's declining influence, has driven this espionage activity against the region's economic ministries. Bitdefender has also tracked two other China-nexus campaigns in the past year, targeting Europe and South Asia, including recent incidents in the South Caucasus.
A notable aspect of the SilkParasite campaign is the evidence suggesting the use of artificial intelligence in both the creation of lure documents and the development of the malware itself. Bitdefender found that two of the email lures were AI-generated, and placeholders within the malware code indicated AI assistance in its development.
Despite the AI involvement, Bitdefender emphasizes that sophisticated, state-backed malware like that used in SilkParasite remains primarily the work of human professionals. The AI appears to be used as an accelerant, enabling human engineers to work more quickly, rather than fully automating the development process. This approach allows threat actors to leverage AI's speed without introducing the "mediocrity" that could compromise an operation.
This campaign serves as an example of advanced espionage tooling designed for minimal footprint, dynamic in-memory execution, and code deliberately crafted to avoid resemblance to previously identified malware families. The findings highlight the evolving landscape of cyber threats, where even highly capable state-sponsored actors are beginning to integrate AI into their operational workflows.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed