Threat Brief — 2026-09-02: AI Agents in the Crosshairs
Executive summary: AI coding agents are emerging as a prime attack surface — eight disclosed flaws let malicious Git repositories execute attacker code on developer machines, with four still unpatched. Separately, an active malware campaign is distributing fake software installers that disable Windows Update and weaken Defender. A Chinese-speaking cybercrime cluster continues to hijack Brazilian government web traffic via malicious Apache modules.
Top items
- Malicious .git configs force AI coding agents to execute attacker code — Manifold Security disclosed eight flaws across seven command-line AI coding agents (including Claude, Codex, and Cursor) in which a repository's Git configuration names a command the agent runs on the developer's machine. Four of the eight flaws remain unpatched at time of publication. Any developer whose agent clones an attacker-controlled repo is exposed to remote code execution. (src: The Hacker News)
- Fake software installers disable Windows Update and weaken Microsoft Defender — An active campaign uses bogus software-download websites impersonating trusted vendors to distribute malicious installers. Once executed, the malware disables Windows Update and weakens Defender, leaving machines persistently exposed to further compromise. (src: The Hacker News)
- Gambling Goblin cluster hijacks Brazilian government sites via malicious Apache modules — A Chinese-speaking cybercrime group is installing malicious Apache modules on compromised Brazilian government and educational web servers, diverting visitor traffic to gambling pages. The campaign demonstrates server-side content injection that is difficult to detect from the client side. (src: The Hacker News)
- Pentagon investigates mass refrigeration failure as possible cyberattack — All freezers at multiple facilities triggered defrost mode simultaneously across several states. A cyberattack is among the hypotheses under active investigation. First reported today. (src: SecurityLab)
- METR API key theft results in $600K AI credit spend — Attackers stole an API key from AI safety research organisation METR and used it for three weeks to run AI model queries, consuming approximately $600,000 in credits. Authorization was quietly disabled during the incident; anomalies were initially dismissed as planned testing. First reported 2026-09-01 by The Hacker News. (src: Xakep)
- Trojans hidden in corrupted MP4 files bypass content protections — Researchers demonstrate that corrupted MP4 containers can carry trojans past built-in content-filtering defences, which accept the malformed files as ordinary video. (src: SecurityLab)
Themes
AI agents as attack surface. Two distinct stories underscore that AI tooling is now both a target and a vector. Malicious .git configs exploit the trust AI coding agents place in repository metadata to achieve code execution, while the METR incident shows how AI infrastructure credentials can be quietly exfiltrated and abused at significant cost. Organisations adopting AI agent tooling should treat agent-executed code paths and API key governance as first-class security concerns — not peripheral risks.
Defender degradation as a persistence tactic. The fake-installer campaign's deliberate disabling of Windows Update and Defender echoes a broader pattern of attackers seeking to neutralise host-based defences before delivering secondary payloads. This reinforces the value of monitoring for unexpected changes to security tool configuration and update service state.
