ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
Weekly ThreatsDay digest: OFAC sanctions Tren de Aragua ATM jackpotting network, blockchain malware dead drops surge, plus cache-poisoning and EDR-evasion research.
The roundup covers OFAC sanctions on 10 Tren de Aragua targets behind $40.73 million in Ploutus-based ATM jackpotting losses across more than 1,500 U.S. attacks, and Chainalysis reporting a 440% surge in blockchain dead drop (EtherHiding) malware delivery. It also summarizes Moonshot's internal AI safety review after Mindgard found Kimi K2.6 and K3 Swarm could bypass guardrails, Tracebit's Context Bombs prompt-injection defense, and YesWeHack's cache key injection poisoning technique. Additional items include a named-pipe process injection EDR evasion technique and a Huntress incident where attackers compiled a cryptominer on the victim host after exploiting Samsung MagicINFO (CVE-2025-4632).