View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Underground sellers resell discounted access to Claude and ChatGPT

πŸ•΅οΈ RESEARCH & DEEP DIVES

⚠️ 5 | Underground sellers resell discounted access to Claude and ChatGPT
Criminals are reselling discounted access to frontier AI models.

  • Chinese users and other customers are buying access to Claude, ChatGPT and other frontier models.
  • Poison Claude offers Anthropic Opus 4.8, 4.7, 4.6 and Sonnet 4.6 access.
  • Ecomagent offers below-market or unlimited access to Opus 4.8, Opus 4.6, Sonnet 4.6 and GPT Codex 5.5.
  • Operators exploit free trials, AWS Bedrock bonuses and startup credits, then resell pooled accounts through API gateways.
  • Gateway providers can see customer prompts; Poison Claude accepts cryptocurrency payments and routes Claude Code traffic through its API.
    :page_facing_up: Source: okta.com Β· :paperclip: Coverage: helpnetsecurity.com Β· :eye: via Cybersecurity Dive

⚠️ 5 | AmnesiaStealer hijacks Chromium sessions for live macOS browser control
AmnesiaStealer hijacks Chromium sessions on macOS.

  • macOS users are targeted by the Rust-based AmnesiaStealer infostealer.
  • The malware steals Keychain data, browser credentials and cookies, Apple Notes, Telegram sessions, files and cryptocurrency data.
  • A counterfeit GitHub download page uses a ClickFix lure to make victims paste a Base64-encoded Terminal command.
  • A remote script downloads a password-protected ZIP containing the payload, which stages data under a random /tmp directory and exfiltrates it to debug.allllowef[.]space/send/.
  • A second-stage module launches Chrome, Brave, Edge, Arc, Opera, Vivaldi or Chromium headlessly through CDP for live remote control; Safari theft uses CVE-2020-9771 on macOS Catalina and requires Full Disk Access on macOS 26.
    :page_facing_up: Source: jamf.com Β· :paperclip: Coverage: appleinsider.com Β· :eye: via Cyber Security News

:pushpin: 4 | Unauthenticated Hybrid-Inverter API Could Create Grid Safety Risks
Researchers found an unauthenticated API flaw in a hybrid inverter.

  • The issue affects hybrid inverters used in solar, battery-storage, and grid-connected energy systems.
  • An unauthenticated API exposes inverter control functions.
  • Attackers can send commands over the inverter’s internal CAN bus.
  • The flaw can disable protections, alter configurations, damage connected devices, or permanently disable the inverter.
    :paperclip: Coverage: saiflow.com Β· :eye: via r/netsec

:pushpin: 4 | Chrome adds device-bound credentials to thwart session-cookie account takeovers
Chrome is rolling out DBSC to make stolen session cookies unusable on other devices.

  • Chrome users on Windows and macOS are covered, with limited support in Chrome 147 and 150 respectively.
  • Session cookies targeted by infostealers and adversary-in-the-middle attacks can enable account takeovers despite MFA or passkeys.
  • DBSC stores a non-exportable private key in a Windows TPM or macOS Secure Enclave.
  • Chrome signs server challenges with the device key, causing stolen cookies used elsewhere to fail validation.
    :page_facing_up: Source: blog.google Β· :paperclip: Coverage: arstechnica.com Β· :eye: via securityboulevard.com (discovered)

πŸ”“ CVEs & KEV

CVE-2026-70452 β€” CVSS 9.1 β€” rsync 3.1.0 before 3.5.0 Access Control Bypass via DNS Resolution Failure
CVE-2025-62164 β€” Vllm Vllm β€” CVSS 8.8 β€” vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent processes
CVE-2026-70456 β€” CVSS 8.8 β€” rsync 3.0.1 before 3.5.0 Heap Out-of-Bounds Write via read_args()
CVE-2026-70453 β€” CVSS 8.7 β€” rsync before 3.5.0 Algorithmic Complexity DoS via hash_search()
CVE-2026-70455 β€” CVSS 8.7 β€” rsync 3.4.2 before 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion
CVE-2026-63423 β€” CVSS 8.5 β€” During an internal security assessment, a potential vulnerability was discovered
CVE-2026-63425 β€” CVSS 8.5 β€” During an internal security assessment, a potential improper permissions vulnerability was discovered
CVE-2026-70457 β€” CVSS 8.3 β€” rsync 3.2.3 before 3.5.0 Out-of-Bounds Write via parse_size_arg()
CVE-2026-70454 β€” CVSS 7.6 β€” rsync before 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL Mode
CVE-2026-15994 β€” CVSS 7.3 β€” During an internal security assessment, an improper link following vulnerability was discovered
CVE-2026-6387 β€” CVSS 7.3 β€” A potential authentication bypass vulnerability was reported in Lenovo System
CVE-2026-63424 β€” CVSS 7.0 β€” During an internal security assessment, an improperly protected key was discovered
CVE-2026-63426 β€” CVSS 6.9 β€” During an internal security assessment, a potential vulnerability was discovered
CVE-2026-12036 β€” CVSS 6.9 β€” An improper link following vulnerability was reported in the VantageCoreAddin
CVE-2026-73557 β€” CVSS 6.3 β€” vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent processes

πŸ“‹ ADVISORIES

:page_facing_up: Source for Microsoft patches August 2026 Exchange Server vulnerabilities β€” support.microsoft.com

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check