Threat Brief — 2026-08-07 — AI patches break, botnets reboot
Executive summary: Today's fresh intel highlights a new Mirai-derived botnet with an unusual persistence trick and a damning study showing AI-generated code patches fail roughly half the time — sometimes introducing new bugs. Social-engineering trends continue to evolve, with voice deepfakes now targeting hedge funds and Wall Street, while Gen's H1 2026 report documents two practical attack chains combining compromised inboxes with browser and clipboard manipulation.
Top items
- New Tengu botnet reboots infected devices to survive process termination. Nozomi Networks Labs identified a new Mirai variant called Tengu that monitors its own process and triggers an emergency system reboot if the malware is killed, making cleanup significantly harder. This is a notable persistence evolution for IoT-class botnets. (src: RSS:xakep)
- Study of 6,000+ AI-generated patches finds ~50% failure rate, including patches that introduce new bugs or bypasses. Even when an AI patch appears to fix the target vulnerability, it can silently break unrelated functionality or leave the fix open to circumvention. This is a critical caveat for any team considering AI-assisted remediation workflows. (src: RSS:darkreading-all)
- Voice deepfakes used to socially engineer hedge funds and Wall Street firms. Attackers are impersonating executives via synthetic voice calls to manipulate staff into taking actions — a natural escalation of vishing campaigns that financial security teams should brief front-desk and back-office personnel about. (src: RSS:securitylab-ru)
- Gen H1 2026 threat report details two attack chains: BEC + browser manipulation for banking malware, and clipboard hijacking for crypto-payment redirection. The report underscores that adversaries are chaining compromised business email with client-side browser tricks and clipboard interception to redirect funds — a reminder that endpoint hygiene matters as much as email security. (src: RSS:bleepingcomputer-main)
- Italy formalises cyberspace as a separate military operational domain, expanding General Staff powers over offensive hacking units. The reform signals continued nation-state investment in offensive cyber capability and may increase the pool of skilled operators targeting Western infrastructure. (src: RSS:securitylab-ru)
- Russian operators flag SMS delivery failures to children's SIM cards for VKontakte and Max services. Child SIM-card restrictions, under discussion for over a year, are now producing real-world messaging gaps — relevant for any platform relying on SMS OTP for age-restricted user segments. (src: RSS:securitylab-ru)
Themes
AI as a double-edged sword: The patch-failure study joins a growing pattern this week of AI security concerns — from autonomous agents backdooring OSS projects to prompt-injection in AI browsers. The takeaway for engineering teams is that AI-generated fixes and AI-assisted tooling require the same human review rigour as any untrusted code contribution.
Social engineering keeps levelling up: Voice deepfakes targeting finance professionals, ClickFix-style browser-cache payloads, and BEC-plus-clipboard-hijacking chains all point to attackers investing in techniques that bypass traditional email and endpoint controls by exploiting human trust at the point of action.
