Threat Brief — 2026-09-28 — AI agents deepen attack surface
Executive summary: Most of today's feed volume re-covers stories already reported earlier today — Keio ransomware, Times Car breach, Apple CoreGraphics patch, NeedyMantis, Carbonato, Supabase exposures, and the ShinyHunters arrest — with no material new developments. Two stories do advance: Bitget has identified the vector behind its $388M theft as a flaw in a third-party security product, and Cleafy has published new technical detail on the RatHat Android banking trojan's use of Gemini for victim prioritisation. Two additional analysis pieces reinforce a growing theme: autonomous AI agents operating with privileged access are an under-audited insider-threat vector.
Top items
- Bitget identifies third-party security product flaw as vector for $388M theft. Bitget stated the attacker exploited a vulnerability in a third-party security product the exchange used to gain access and steal approximately $388 million. This is a genuine development in the story first reported 2026-09-25 by SecurityLab, which initially covered the heist as a suspected North Korean operation and the exchange resuming Bitcoin withdrawals. The attribution to a third-party tool flaw shifts the incident's threat model from direct exchange compromise to supply-chain-style dependency risk. (src: The Hacker News) — first reported 2026-09-25 by SecurityLab
- Cleafy details RatHat Android trojan's use of Gemini for victim triage. Security company Cleafy traced nearly 100 deployments of the RatHat banking trojan's control console since April 2026 and revealed that operators use Google Gemini to analyse infected device data and identify higher-value victims. This adds new technical detail to the story first reported 2026-09-17 by BleepingComputer, which covered RatHat's AI-assisted remote device control. The integration of a mainstream LLM into victim-prioritisation workflow marks a further erosion of the boundary between commodity malware and AI-augmented operations. (src: The Hacker News) — first reported 2026-09-17 by BleepingComputer
- Analysis highlights autonomous AI agents as unaudited privileged users. Dark Reading published commentary noting that enterprises rigorously monitor human employees while autonomous AI agents quietly operate with broad privileges, positioning them as a next-generation insider-threat vector. A complementary framework piece from The Hacker News covers IAM architecture for governing AI agents that authenticate, invoke tools, and act across enterprise systems with delegated authority. Neither reports a specific incident, but together they articulate a governance gap that multiple active stories — Carbonato's AI-agent botnet, RatHat's Gemini integration, and the OpenAI agent Medicare breach — already illustrate in practice. (src: Dark Reading · The Hacker News)
Themes
AI agents as both weapon and blind spot. Today's feed reinforces a pattern visible across the week: threat actors are embedding AI agents into malware operations (Carbonato's Hermes Agent framework on Docker hosts, RatHat's Gemini-driven victim triage) while defenders lag on auditing the privileged access that legitimate AI agents hold inside enterprises. The Bitget development adds a third dimension — a third-party security product became the entry point for a $388M theft, underscoring that AI-adjacent tooling and its dependencies are now part of the attack surface whether or not they are "AI" themselves.
===
