Malicious actors are exploiting the current interest in artificial intelligence by distributing malware. They are using deceptive AI-themed documents that contain hidden scripts to install AsyncRAT, a tool that grants them remote control over compromised systems.

Cybercriminals are leveraging the widespread interest in artificial intelligence to distribute malware, according to a recent analysis by FortiGuard Labs. Threat actors are creating malicious files that appear to be guides or resources related to AI, aiming to trick individuals searching for information on the technology.
These deceptive files, often distributed within ZIP archives, are designed to initiate a multi-stage attack chain. The initial lure might be a shortcut file that, when opened, executes a series of obfuscated commands. These commands are designed to extract hidden components from other files within the archive, which are marked with a "Hidden" attribute.
The attack chain involves several stages of script execution. An initial script, extracted from a file disguised as a PDF, sets up a hidden PowerShell process. This PowerShell script then searches for encrypted data within the same "PDF" file, identified by specific markers. Using a fixed password and deriving keys through PBKDF2, it decrypts the payload using AES-CBC.
The decrypted content is saved as another PowerShell script in a directory designed to mimic a legitimate Windows component, such as "Microsoft.WindowsSoundDiagnostics." This script further extracts additional components from the original "PDF" file, including a PowerShell script and a batch file, which are saved with names like "RealtekAudioService64.ps1" and "RealtekAudioService64.bat."
To ensure persistence, the malware establishes a scheduled task named "CheckRealtekAudioVersion." This task is configured to run the dropped batch file, masquerading as a Realtek audio service. The task is set up to execute shortly after infection and upon each subsequent user logon, employing privilege-aware settings and dual triggers.
The batch file, "RealtekAudioService64.bat," acts as a stealthy launcher for the main PowerShell payload. It first ensures it is running in a hidden mode, relaunching itself via PowerShell with hidden window settings if necessary. To evade detection, it reconstructs the string "powershell.exe" from split variables rather than referencing it directly. It also creates a timestamped log file, intended to appear as a diagnostic artifact, before executing the primary PowerShell script and then deleting the log to remove traces.
The core PowerShell script, "RealtekAudioService64.ps1," employs significant obfuscation techniques. It reconstructs all built-in PowerShell cmdlets from character arrays and uses variable names in Simplified Chinese, such as "$测试路径" and "$新建项目." This approach makes the script difficult for analysts to understand and helps bypass signature-based detection rules that rely on English cmdlet names. Directory paths and binary filenames are also hidden as Base64-encoded strings, decoded at runtime.
The ultimate goal of this complex infection chain is to deploy AsyncRAT, a .NET remote access trojan. This allows attackers to gain control over infected systems, enabling command-and-control communication and further malicious activities. The analysis suggests that the threat actors may have utilized AI tools during the development process, citing the structured coding style and the presence of Simplified Chinese variable names and comments alongside English text. This indicates a potential workflow where AI assists in code implementation, with the overall attack logic designed by human operators.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed