Threat Brief — 2026-09-11 — Browser backdoors and AI weaponised
Executive summary. A post-exploitation framework dubbed PEEP turns Chrome and Edge extensions into full backdoors, expanding the browser-as-attack-surface problem beyond simple credential theft. GitLab's maximum-severity file-read flaw is now being probed in the wild within hours of disclosure, and JFrog Artifactory attackers have escalated from auth bypass to deploying a Rust backdoor. Anthropic's latest threat report adds detail on Russian state actors using Claude to rebuild evasive malware, while separate research shows trusted AI platforms themselves being abused to serve malicious payloads.
Top items
- GitLab CVSS 10 file-read flaw draws in-the-wild probes. CVE-2026-85706KEV, a maximum-severity path-traversal/file-read vulnerability in GitLab, is now being actively probed by attackers within hours of public disclosure. This is a development in a story first reported earlier today; the escalation from "patch available" to "scanners are probing" shortens the remediation window considerably. (src: The Hacker News)
- JFrog Artifactory flaws chained to deploy Rust backdoor on self-hosted servers. Threat actors are combining critical and high-severity Artifactory vulnerabilities to bypass authentication, escalate to admin, and deploy a Rust-based backdoor. This extends the Artifactory exploitation story first reported 2026-09-01 by RSS:The Hacker News, which initially covered the auth bypass being added to CISA KEV. (src: BleepingComputer)
- PEEP framework turns Chrome and Edge into post-exploitation backdoors. SOCRadar researchers identified a post-exploitation framework that masquerades as a browser extension and uses Chrome or Edge as a full backdoor, capable of executing commands and exfiltrating browser data after an initial breach. This represents a shift from browsers as credential targets to browsers as active command-and-control channels. (src: Xakep)
- Passkey-themed phishing campaigns target Microsoft 365 for data theft. Microsoft reports that threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey- and single-sign-on-themed social engineering to compromise corporate Microsoft accounts and steal M365 data. This is a new social-engineering vector in the ongoing M365 extortion campaign ecosystem, distinct from the vishing and fake-helpdesk approaches reported earlier this week. (src: BleepingComputer)
- Anthropic details Russian state actor abusing Claude to rebuild evasive malware. Anthropic disrupted a campaign by a Russian state-sponsored threat actor that used Claude to build an AI-assisted workflow for rewriting malware after detection, getting ahead of defender signatures. This adds concrete operational detail to the broader Claude abuse report first published today by RSS:The Hacker News. (src: The Hacker News)
- Trusted AI platforms weaponised as malware delivery surfaces. Huntress reports that threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware via weaponised Claude Artifacts and shared AI conversation links. This extends the AI-abuse theme from AI-as-tool to AI-platform-as-attack-surface. (src: BleepingComputer)
- Google Play Early Access program abused to distribute fraudulent Android apps. Bitdefender reports that developers are exploiting the Early Access program — which suppresses public reviews — to push deceptive apps that amass installs with no user feedback visible. This develops a story first reported 2026-09-10 by RSS:The Hacker News; the new detail is the scale of the scheme and the specific abuse of the review-suppression mechanism. (src: Xakep)
Themes
AI as both tool and target. Three distinct threads converge today: state actors and criminals using Claude to automate exploitation and rebuild evasive malware (Anthropic's report); trusted AI platforms being abused to host and deliver malicious payloads (Huntress); and AI-assisted "swarm" attacks reshaping the kill chain (Dark Reading on PaperCut). The attack surface now includes the AI services organisations may be adopting internally.
Browser trust exploited at multiple layers. The PEEP framework demonstrates browsers being used as persistent command-and-control channels, not merely credential stores. Meanwhile, passkey-themed phishing exploits user trust in emerging authentication mechanisms. Both trends underscore that the browser remains a primary contested ground for both persistence and initial access.
Exploitation windows continue to shrink. GitLab's CVSS 10 flaw saw in-the-wild probes within hours of disclosure, and Artifactory attackers have already moved from initial access to backdoor deployment. The interval between patch availability and active exploitation continues to compress.
