ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-09-07
▶The Wire — Daily Briefing

The Wire — Monday, September 7, 2026

The Convergence: AI-Weaponized Threats Meet Overlooked Infrastructure Under Coordinated Attack

15 stories analyzed

The Convergence: AI-Weaponized Threats Meet Overlooked Infrastructure Under Coordinated Attack

We're watching something shift in real time. Today's 15 critical vulnerabilities and exploits don't read like random security incidents—they're the signature of a coordinated, multi-layered campaign targeting the infrastructure we've systematically deprioritized. From phone systems that security teams ignore to industrial monitors running hardcoded credentials, from payment platforms to virtualization boundaries, the attackers have found where we're not looking. And they've brought new weapons: advanced AI, invisible text exploits, and a seven-year patience to harvest encrypted data for future decryption.

This is no longer about opportunistic patching. This is about strategic targeting.

The AI Weaponization Threshold

ChatGPT Astra is now rolling out to $20 Plus subscription marks a turning point that security professionals need to internalize immediately. Nation-state-grade AI capability is now $20 per month. That's not a marketing event—that's a threshold crossed. Threat actors no longer need advanced R&D budgets to generate convincing phishing emails, custom malware, or sophisticated social engineering at scale. We're already seeing the early stage of this weaponization in the wild: attackers are using AI-generated voice calls impersonating Apple support to trick theft victims into handing over Apple ID credentials, as documented in Smashing Security podcast #483. The attack is trivial but effective. The AI handles the voice. Victims hear a trusted authority and comply. Activation Lock gets bypassed. Stolen phones get resold. This is the baseline now.

Combine that with attackers concealing phishing lures using invisible Unicode characters, and the gap between human perception and machine parsing becomes a weapon. Email filters see binary characters; your users see clean text. This isn't advanced. It's meta: weaponize the fact that our defenses aren't trained on invisible text while humans still fall for it. It's a reminder that as we automate detection, we create new blind spots.

Supply Chain Under Systematic Siege

The most alarming pattern today is supply chain infiltration happening at multiple layers simultaneously. N-able patches max severity N-central flaw amid ongoing attacks is a CVSS 10.0 RCE in one of the most trusted RMM platforms used by thousands of MSPs. Hundreds of downstream client networks are now compromised via a single vendor. This isn't theoretical attack surface—it's active exploitation right now.

But N-Central isn't alone. Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication reveals that millions of routers globally are under active exploitation through a simple SSH auth bypass. MikroTik routers sit at the edge of networks—they're the gateway. Compromise them, and you own the perimeter. The fact that this has been exploited since at least September 2 means we're likely watching the aftermath of a massive campaign. Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores shows that payment infrastructure is being compromised with no fix available yet. Attackers are installing skimmers as you read this. And Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code—a CVSS 9.3 hypervisor boundary escape—means that the virtual machines we use to isolate workloads aren't isolated at all if the guest has admin access.

Each vulnerability alone is manageable. Together, they're a map of the entire attack surface: networks, payment systems, virtualization boundaries, and trusted platforms all compromised or under active exploitation.

The Overlooked Infrastructure Bet

There's a pattern in today's vulnerabilities that reveals attacker strategy: Sangoma Switchvox Vulnerabilities Exploited in the Wild is being actively exploited, yet most security teams treating phone systems as "telecom, not security." On-premise Switchvox deployments at SMBs almost never get patched because nobody thinks of them as critical infrastructure. That's the bet. Attackers know that. Phone systems are a backdoor into the corporate network that nobody's watching. Similar logic applies to industrial controls: Pyramid Solutions NetStaX EtherNet/IP Stack flaws allow unauthenticated remote attacks on thousands of OEM products, and Tycon Systems TPDIN-Monitor-WEB3 power monitors contain hardcoded credentials, missing auth checks, and CSRF flaws—allowing full device takeover. Industrial networks still run these systems because they're "part of the plant" rather than "part of IT security." IXON VPN Client CVE-2026-75925 is a silent, persistent unauthenticated root code execution in VPN clients that connect industrial networks to the outside world. The attacker gets a foothold that survives reboots. That's not a bug—that's a permanent implant opportunity.

The sophistication here is strategic, not technical. Attackers have realized they don't need to break Microsoft or Google. They need to break the platforms we've decided aren't security problems yet.

The Long Game: Harvest, Hold, Decrypt Later

Perhaps the most alarming development isn't the current exploits—it's the acknowledgment that Preparing for the Post-Quantum Era: A Call to Action is urgent because nation-state actors are already harvesting encrypted data today. They're betting that quantum computers will mature in the next 7-15 years, and when they do, they'll decrypt decades of stolen communications, credentials, and financial records. This isn't speculative. This is happening now. CISA and the G7 are sounding alarms because the window to migrate to post-quantum cryptography is closing, and we're losing the race against adversaries who are actively executing harvest-now-decrypt-later campaigns.

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted ties this together. The breach exposed home addresses of crypto owners—data that identifies targets for physical theft. But it also exposed customer data that Trezor thought was deleted. What other encrypted data is being harvested while we assume it's safe? When quantum computers arrive, those attackers don't need to find today's victims. The data has already been stolen.

What We're Missing

We're in the middle of something that looks like random attacks but reads like coordinated strategy. Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner shows the modular weaponization approach: steal credentials, then deploy separate modules to disable defenses and install persistent revenue generators. The sophistication isn't in the code—it's in the orchestration.

And Revolut scam wave steals 180,000 from Jersey residents in just four weeks reveals coordinated social engineering targeting a specific neo-bank's vulnerability: speed of transfer before fraud detection. Seventy-five percent of fraud reports in one month targeted Revolut. That's not random. That's a chosen target and a systematic campaign.

What's Next

The convergence is clear: advanced AI lowers barriers to social engineering, supply chain vulnerabilities guarantee broad reach, overlooked infrastructure guarantees persistence, and patience guarantees long-term leverage. The post-quantum threat is the longest game of all—one that's already in motion.

We need to stop treating these as separate incidents and start seeing them as symptoms of a systematic reorientation of the attack surface away from our visibility. Patch N-Central. Patch MikroTik. Patch Magento. But also audit your phone systems, your industrial controls, your payment infrastructure, and your virtualization boundaries. The attacker's strategy is to find what you're not watching. What infrastructure have you decided isn't a security problem?

Key Takeaways

  • AI-weaponized threats are now commoditized: ChatGPT Astra at $20/month gives threat actors nation-state-grade AI capability for phishing, malware customization, and social engineering at scale. Start stress-testing your defense against AI-generated attack vectors now.
  • Supply chain attacks are systemic across multiple layers: RMM platforms (N-Central), routers (MikroTik), payment systems (Magento), and hypervisors (VMware) are under active, coordinated exploitation. The perimeter is no longer a perimeter—it's a series of interconnected vulnerable gateways.
  • Overlooked infrastructure is the primary attack surface: Phone systems, industrial monitors, and power management devices run with default credentials and zero security patches because they're not considered "IT security" by anyone. Stop treating them as telecom/facilities problems and start treating them as compromised entry points.
  • Post-quantum harvest is active today: Nation-state actors are collecting encrypted data now to decrypt later when quantum computers mature. Start your cryptographic migration immediately—the window is closing, and adversaries have already begun the race.

The Wire is HackWire's daily editorial briefing, published every morning.