Daily Drop (1349)
08-18-26
Tuesday, Aug 18, 2026 // Buy Bob a Coffee // Ghostwire
Machine Traffic Overtakes Humans: AI Agents Reshape the Internet’s Automated Threat Landscape
Bottom Line Up Front (BLUF): A new 2026 automated threat report from 瑞数信息 (River Security) says non-human traffic now represents the majority of internet activity, with bots accounting for roughly 68% of observed traffic between early 2025 and Q2 2026. Malicious bots reportedly make up 55%, while AI Agent-driven traffic has climbed from less than 1% in early 2025 to approximately 8%-12% by Q2 2026. The shift matters because AI Agents can do more than execute predefined scripts: they can interpret objectives, invoke tools, interact with APIs, and adapt their behavior, forcing defenders to move beyond simply identifying bots toward continuously evaluating machine identity, behavior, and intent.
Analyst Comments: What is changing is the capability of the automated actor behind the traffic. Traditional bots are generally predictable enough to fingerprint, rate-limit, or challenge. AI-enabled agents can operate through real browsers, use valid identities, adjust workflows after failure, and interact with applications in ways that look increasingly legitimate. If the report’s measurements hold across broader internet environments, defenders are approaching a point where “human versus bot” becomes the wrong security question. An authenticated Agent may be completely legitimate, compromised, impersonated, or acting outside its intended scope. That pushes organizations toward machine identity governance: determining what an automated entity is authorized to access, whether its behavior matches its expected purpose, and when its trust level should change.
READ THE STORY: AnQuanKe
Attackers Use AI to Identify High-Value Data, Harvest Credentials, and Support Live Intrusions
Bottom Line Up Front (BLUF): Gambit Security researchers documented three unrelated threat actors using AI across multiple stages of cyber operations, including ransomware intrusions, credential harvesting, exploitation-tool development, infrastructure management, and cryptomining campaigns. In one case, a suspected ransomware operator used Claude Code during attacks against six organizations to identify valuable systems and data, generate commands, modify firewall configurations, and stage databases for exfiltration. Separate actors used OpenAI Codex, Claude Code, and a DeepSeek-backed orchestration component to build credential-harvesting and exploitation frameworks.
Analyst Comments: The important shift here is not simply that attackers are using AI to write malware. The more consequential development is AI being used inside active intrusions to interpret environments, prioritize targets, and decide what information is worth stealing. That moves AI from a code-generation assistant into something closer to an operational copilot. The ransomware case is particularly instructive. Claude reportedly helped the operator identify domain controllers, file servers, backup infrastructure, production databases, and document repositories, then assisted with staging data for exfiltration. That type of business-context analysis can reduce the amount of manual triage an attacker needs after gaining access.
READ THE STORY: HNS
Bits of Gold Data Breach Exposes Personal and Banking Information of 200,000 Customers
Bottom Line Up Front (BLUF): Israeli cryptocurrency broker Bits of Gold disclosed a data breach affecting approximately 200,000 customers after attackers gained unauthorized access through a supply-chain compromise. Exposed information reportedly includes names, national ID numbers, email addresses, phone numbers, IP addresses, bank details, and public cryptocurrency wallet addresses. Bits of Gold says customer funds, private keys, passwords, CVV data, and identity-document scans were not compromised.
Analyst Comments: The lack of private-key or account-credential exposure reduces the likelihood of immediate wallet theft, but this is still a high-value identity dataset. National ID numbers, banking information, contact details, IP addresses, and known cryptocurrency ownership create an ideal foundation for targeted phishing, impersonation, SIM-swap attempts, account-recovery abuse, and social-engineering campaigns. The supply-chain angle is the bigger concern. Bits of Gold says the incident was part of a wider global attack affecting multiple organizations, which suggests the compromise may extend beyond a single cryptocurrency company. Until the upstream provider and intrusion path are publicly identified, organizations should be cautious about treating this as an isolated event.
READ THE STORY: Xakep
VMware vCenter RCE Exploitation Turns Management Appliances Into Tier-0 Compromise Paths
Bottom Line Up Front (BLUF): Incident responders at QUIRSO report active exploitation of CVE-2026-59310, a critical VMware vCenter Server Syslog directory-traversal vulnerability rated CVSS 9.8. Attackers are reportedly using the flaw to achieve code execution on exposed vCenter appliances, establish root-level persistence, deploy reverse SSH tooling, and pivot into vSphere identity and management infrastructure. Researchers observed 361 victim IP addresses across 47 countries, with exploitation beginning within days of public disclosure. Broadcom has stated that no workaround is available; organizations must apply the fixed releases listed in VMSA-2026-0006.
Analyst Comments: vCenter compromise is rarely just an appliance problem. It is a control-plane problem. Once an attacker gains privileged access to vCenter, the blast radius can extend to ESXi hosts, virtual machines, datastores, networks, and centralized authentication. In practical terms, that can turn one vulnerable management server into a path toward large-scale ransomware deployment, destructive operations, credential theft, or infrastructure-wide persistence. The reported exploitation chain is straightforward and effective. Attackers appear to abuse the Syslog Server path traversal to write attacker-controlled files into /etc/cron.d/, resulting in commands executed as root. From there, operators reportedly deploy reverse_ssh, establish systemd and cron persistence, enable SSH access, plant keys, drop a JSP web shell, and modify local privilege paths.
READ THE STORY: GBhackers
CISA Adds Actively Exploited Ray RCE Flaw to KEV Catalog
Bottom Line Up Front (BLUF): CISA added CVE-2025-62593, a critical vulnerability in the Ray distributed computing framework, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The flaw, rated CVSS 9.4, can allow remote code execution through DNS rebinding when a developer using Firefox or Safari visits a malicious site or is served malicious content. Ray fixed the issue in version 2.52.0. U.S. Federal Civilian Executive Branch agencies must remediate the vulnerability by August 20, 2026.
Analyst Comments: Ray’s lack of authentication on sensitive endpoints such as /api/jobs and /api/job_agent/jobs/ significantly increases the impact because an attacker who successfully pivots through the victim’s browser may be able to execute arbitrary commands without first defeating an authentication layer. The browser angle makes this more concerning than a typical exposed-service vulnerability. An attacker does not necessarily need direct network access to the Ray instance. DNS rebinding can turn the victim’s browser into a proxy for reaching services bound to localhost or accessible only from an internal network. A malicious website, phishing lure, or compromised advertising chain could therefore become the initial access mechanism.
READ THE STORY: THN
Shadow hVNC Malware Kit Gives Attackers Covert Windows Desktop Access and Session Hijacking
Bottom Line Up Front (BLUF): A malware-as-a-service toolkit called Shadow hVNC gives attackers covert control of Windows systems by creating a hidden desktop session that operates separately from the victim’s visible screen. Advertised in March 2026 by an actor using the handle “RemoteX,” the toolkit combines browser-session hijacking, credential theft, cookie replay, LSASS dumping, persistence, reverse proxying, and hidden remote-control capabilities. Its most dangerous feature, “Backstage Mode,” can launch a browser against a victim’s live Chrome profile, allowing attackers to inherit authenticated sessions without needing to steal or reuse passwords.
Analyst Comments: What raises the risk is Shadow hVNC’s ability to operate inside a parallel Windows desktop while interacting with the victim’s real browser state. That gives operators a path to authenticated email, SSO, financial services, cryptocurrency platforms, and other web applications while reducing the visibility of malicious activity to the user. Session theft is increasingly more valuable than password theft. If an attacker can reuse active cookies or launch Chrome against an existing profile, MFA may never be challenged because the application sees what appears to be an already authenticated session. Shadow hVNC’s use of Chrome DevTools Protocol to inject cookies further reinforces that model.
READ THE STORY: GBhackers
Items of interest
DEFCON: Researchers Infiltrate Suspected North Korean IT Worker Scheme Through Fake Crypto Startup
Bottom Line Up Front (BLUF): Security researchers created a fake decentralized-finance startup and hired three individuals they assess were North Korean IT workers, giving the team a rare inside view of how DPRK-linked operatives pass remote hiring checks and establish legitimate access inside Western companies. The suspected workers used inconsistent identity documents, VPN infrastructure, AI-assisted job tools, and remote-access software while operating inside researcher-controlled virtual machines. The campaign highlights a persistent insider-access problem: these actors do not need to exploit a vulnerability if an organization hires them and grants them credentials, source-code access, and trusted employee status.
Analyst Comments: The most important point is that the suspected operatives entered through normal recruiting workflows, passed interviews, signed contracts, and received authorized access. Once inside, their activity could resemble that of any legitimate remote developer unless defenders are specifically looking for identity inconsistencies, unusual access patterns, or infrastructure associated with DPRK IT-worker operations. The onboarding indicators are especially useful for defenders. Researchers observed mismatched states across claimed residences, driver’s licenses, and banking information; one submitted identity image reportedly contained signs of Google Gemini processing and a SynthID watermark. Another used a legitimate Social Security number with unrelated banking details. These are not definitive attribution signals individually, but taken together they reinforce the value of repeated identity verification rather than treating pre-employment checks as a one-time control.
READ THE STORY: THN
How North Korea Hid an IT Workforce Inside US Companies (Video)
FROM THE MEDIA: This is the story of Christina Chapman, a suburban TikTok creator who ran a covert “laptop farm” from her Arizona home. The scheme became a gateway for North Korean IT operatives who infiltrated US companies and, according to the Justice Department, funneled millions of dollars to the North Korean government.
The North Korean Operatives Hiding Inside U.S. Companies (Video)
FROM THE MEDIA: North Korea has built a secret workforce inside American companies. Using stolen identities, AI tools and U.S. accomplices, its operatives have cheated their way into remote jobs in an effort to earn money for Kim Jong Un’s regime. The FBI says there are likely thousands of them applying for jobs across America and hundreds of millions of dollars have been funneled back to the regime.
The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don’t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com.


