π΅οΈ RESEARCH & DEEP DIVES
β οΈ 5 | Underground sellers resell discounted access to Claude and ChatGPT
Criminals are reselling discounted access to frontier AI models.
- Chinese users and other customers are buying access to Claude, ChatGPT and other frontier models.
- Poison Claude offers Anthropic Opus 4.8, 4.7, 4.6 and Sonnet 4.6 access.
- Ecomagent offers below-market or unlimited access to Opus 4.8, Opus 4.6, Sonnet 4.6 and GPT Codex 5.5.
- Operators exploit free trials, AWS Bedrock bonuses and startup credits, then resell pooled accounts through API gateways.
- Gateway providers can see customer prompts; Poison Claude accepts cryptocurrency payments and routes Claude Code traffic through its API.
:page_facing_up: Source: okta.com Β· :paperclip: Coverage: helpnetsecurity.com Β· :eye: via Cybersecurity Dive
β οΈ 5 | AmnesiaStealer hijacks Chromium sessions for live macOS browser control
AmnesiaStealer hijacks Chromium sessions on macOS.
- macOS users are targeted by the Rust-based AmnesiaStealer infostealer.
- The malware steals Keychain data, browser credentials and cookies, Apple Notes, Telegram sessions, files and cryptocurrency data.
- A counterfeit GitHub download page uses a ClickFix lure to make victims paste a Base64-encoded Terminal command.
- A remote script downloads a password-protected ZIP containing the payload, which stages data under a random /tmp directory and exfiltrates it to debug.allllowef[.]space/send/.
- A second-stage module launches Chrome, Brave, Edge, Arc, Opera, Vivaldi or Chromium headlessly through CDP for live remote control; Safari theft uses CVE-2020-9771 on macOS Catalina and requires Full Disk Access on macOS 26.
:page_facing_up: Source: jamf.com Β· :paperclip: Coverage: appleinsider.com Β· :eye: via Cyber Security News
:pushpin: 4 | Unauthenticated Hybrid-Inverter API Could Create Grid Safety Risks
Researchers found an unauthenticated API flaw in a hybrid inverter.
- The issue affects hybrid inverters used in solar, battery-storage, and grid-connected energy systems.
- An unauthenticated API exposes inverter control functions.
- Attackers can send commands over the inverterβs internal CAN bus.
- The flaw can disable protections, alter configurations, damage connected devices, or permanently disable the inverter.
:paperclip: Coverage: saiflow.com Β· :eye: via r/netsec
:pushpin: 4 | Chrome adds device-bound credentials to thwart session-cookie account takeovers
Chrome is rolling out DBSC to make stolen session cookies unusable on other devices.
- Chrome users on Windows and macOS are covered, with limited support in Chrome 147 and 150 respectively.
- Session cookies targeted by infostealers and adversary-in-the-middle attacks can enable account takeovers despite MFA or passkeys.
- DBSC stores a non-exportable private key in a Windows TPM or macOS Secure Enclave.
- Chrome signs server challenges with the device key, causing stolen cookies used elsewhere to fail validation.
:page_facing_up: Source: blog.google Β· :paperclip: Coverage: arstechnica.com Β· :eye: via securityboulevard.com (discovered)
π CVEs & KEV
CVE-2026-70452 β CVSS 9.1 β rsync 3.1.0 before 3.5.0 Access Control Bypass via DNS Resolution Failure
CVE-2025-62164 β Vllm Vllm β CVSS 8.8 β vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent processes
CVE-2026-70456 β CVSS 8.8 β rsync 3.0.1 before 3.5.0 Heap Out-of-Bounds Write via read_args()
CVE-2026-70453 β CVSS 8.7 β rsync before 3.5.0 Algorithmic Complexity DoS via hash_search()
CVE-2026-70455 β CVSS 8.7 β rsync 3.4.2 before 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion
CVE-2026-63423 β CVSS 8.5 β During an internal security assessment, a potential vulnerability was discovered
CVE-2026-63425 β CVSS 8.5 β During an internal security assessment, a potential improper permissions vulnerability was discovered
CVE-2026-70457 β CVSS 8.3 β rsync 3.2.3 before 3.5.0 Out-of-Bounds Write via parse_size_arg()
CVE-2026-70454 β CVSS 7.6 β rsync before 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL Mode
CVE-2026-15994 β CVSS 7.3 β During an internal security assessment, an improper link following vulnerability was discovered
CVE-2026-6387 β CVSS 7.3 β A potential authentication bypass vulnerability was reported in Lenovo System
CVE-2026-63424 β CVSS 7.0 β During an internal security assessment, an improperly protected key was discovered
CVE-2026-63426 β CVSS 6.9 β During an internal security assessment, a potential vulnerability was discovered
CVE-2026-12036 β CVSS 6.9 β An improper link following vulnerability was reported in the VantageCoreAddin
CVE-2026-73557 β CVSS 6.3 β vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent processes
π ADVISORIES
:page_facing_up: Source for Microsoft patches August 2026 Exchange Server vulnerabilities β support.microsoft.com