Threat Brief — 2026-09-24: Trusted paths under siege
Attackers are increasingly weaponising the applications, platforms, and development workflows that organisations already trust — from Salesforce AI agents that relay phishing into Slack, to GitLab issue-email addresses quietly allowing unauthenticated code pushes, to macOS malware arriving through public iCloud calendar invitations. Two unpatched OnePlus 15 privilege-escalation flaws give any installed app root without requesting permissions, and a new Docker-targeting botnet called Carbonato deploys an AI agent framework on exposed hosts. Separately, an electronic highway road sign near a major Iranian diaspora centre was hacked to display execution threats — a reminder that low-tech infrastructure remains vulnerable to defacement with political impact.
Top items
- Unpatched OnePlus 15 / OxygenOS root chain — any installed app can gain root without permissions. Researcher Rasmus Moorats chained two flaws in OnePlus's own software to achieve root on a device running the latest OxygenOS, with the malicious app requesting no special permissions. No patch is available yet. This affects any OnePlus 15 user and underscores that OEM-supplied software can introduce privilege-escalation paths that bypass standard Android permission models. (src: The Hacker News)
- Carbonato malware hijacks exposed Docker hosts using an AI agent framework. A new botnet called Carbonato targets Docker daemons with insecure exposures, installing the Hermes Agent AI framework to take control of compromised hosts. Exposed Docker APIs remain a persistent attack surface; this campaign adds AI-driven autonomy to the post-compromise toolset. (src: BleepingComputer)
- GitLab issue-by-email addresses deliberately exposed to enable unauthenticated code pushes and CI abuse. Following the initial disclosure on 2026-09-23 by The Hacker News, new reporting reveals that private GitLab project email addresses are being deliberately surfaced in READMEs, contributing guides, and support pages. Anyone who finds these addresses can push code or trigger CI jobs without authentication, creating a silent supply-chain risk. (src: BleepingComputer)
- "Salesbleed" — agentic AI smuggles arbitrary instructions from the web through Salesforce agents into Slack. Web-sourced content consumed by Salesforce AI agents can carry injected instructions that propagate into trusted internal Slack channels, enabling phishing lures to appear in communications users assume are safe. This is a cross-application prompt-injection problem: the trust boundary between external data and internal messaging breaks when an AI agent bridges the two. (src: Dark Reading)
- SectopRAT resurfaces hiding inside legitimate applications. The latest activity from this remote access Trojan demonstrates it embedding within trusted software to evade detection, reinforcing the case for behavioural monitoring over application allow-listing alone. (src: Dark Reading)
- MacSync malware adds public iCloud calendar delivery for new native payloads (developing). First reported 2026-09-24 by Securelist as a macOS stealer with a backdoor module targeting cryptocurrency users, new reporting now details a delivery mechanism using public iCloud calendar events to distribute native macOS payloads — a vector that bypasses traditional email-based gateways. (src: BleepingComputer)
- Electronic road sign hacked to display execution threats near Iranian diaspora centre. An electronic highway road sign was compromised to display messages threatening executions, located near one of the largest centres of the Iranian diaspora. The incident illustrates how unsecured IoT-style infrastructure can be co-opted for political intimidation with minimal technical sophistication. (src: SecurityLab.ru)
Themes
- Trusted-path abuse dominates. Nearly every item today involves an attacker leveraging a channel the victim already trusts: Salesforce-to-Slack agent pipelines, GitLab issue-email integrations, iCloud calendar invites, legitimate application wrappers for malware, and OEM-signed phone software. The common gap is that these paths are assumed safe by default and lack behavioural scrutiny.
- AI agents as both target and weapon. Carbonato installs an AI agent framework on hijacked hosts; Salesbleed exploits AI agents as a conveyance for injected instructions. AI tooling is simultaneously a new attack surface and a new offensive capability — defenders should treat agent-mediated data flows with the same scrutiny as any untrusted input boundary.
