Skip to main content
New SPF lookups must resolve in milliseconds — why a DMARC tool's add-on isn't enough Learn Why → →
Intermediate

Aurora Uses Cursor, Astra Creates Exploits, Enterprise Network Breached

Brad Slavin
Brad Slavin General Manager

Quick Answer

The top cybersecurity threats from September 1–7 included AI-powered ransomware, zero-day exploits, phishing, BEC scams, supply-chain attacks, and malware. Strong SPF, DKIM, and DMARC can help organizations prevent email spoofing and strengthen email security.

AI Cybersecurity Threat Report

This past week was dominated by one theme: AI is now on both sides of the fight. Attackers used AI coding agents to run live ransomware operations, a frontier model built working zero-day exploits in tests, and researchers showed autonomous agents breaching a full enterprise network in under 10 hours. Meanwhile, defenders dealt with a wave of actively exploited zero-days in PaperCut, Chrome, and CrowdStrike’s own security agent — plus a fresh crop of phishing, BEC, and supply-chain attacks. Here are the 18 stories that mattered most.

Aurora ransomware crew used the Cursor AI coding agent for hands-on hacking

A ransomware group used the Cursor AI agent to perform hands-on exploitation and attacks against VMware ESXi servers — a real-world example of criminals folding AI coding tools directly into live intrusion operations rather than just using AI for phishing copy. Source: GBHackers

OpenAI’s GPT-6 Astra found zero-days and built working exploits in tests

OpenAI disclosed that its GPT-6 Astra model discovered zero-day vulnerabilities and built functioning exploits during internal cyber-capability testing, intensifying long-running concerns about frontier models being used offensively. Source: GBHackers

Researchers breached an enterprise network in under 10 hours using AI agents

Spf Record Checker 9711 A red-team exercise using frontier AI agents compromised a full enterprise network in less than 10 hours, setting a new benchmark for how fast autonomous attack tooling can move from initial access to full compromise. Source: GBHackers

CrowdStrike investigating a Falcon zero-day and a proof-of-concept exploit

CrowdStrike is investigating a published proof-of-concept exploit that reportedly turns its own Office macro cleanup feature into a path to full system control on already-patched Windows machines, and has advised customers to disable the feature in the meantime. Source: DataBreachToday

CISA orders urgent patching of two chained PaperCut NG/MF flaws

CISA added CVE-2026-81578 and CVE-2026-82078 to its Known Exploited Vulnerabilities catalog on August 31, warning that the two flaws can be chained to let an unauthenticated attacker reconfigure a PaperCut server and then execute arbitrary Java code under its process. Federal agencies have until September 14 to remediate, and researchers found nearly half of tracked PaperCut installs are still running unpatched, unsupported versions. Source: CISA

Metasploit shipped a working exploit for the PaperCut zero-day

Within days of CISA’s warning, a Metasploit module was published for the PaperCut RCE chain, sharply raising the urgency for organizations running exposed print servers to patch immediately rather than wait. Source: GBHackers

Google patched an actively exploited Chrome V8 zero-day

Spf Flattening 5107 Google shipped an emergency Chrome update after confirming a V8 engine flaw was being actively exploited in the wild — a reminder that browser zero-days affecting billions of users demand immediate patching regardless of platform. Source: GBHackers

APT28-linked hackers deployed a new HOOKEDGE backdoor across Europe

Russian state-sponsored group BlueDelta (tracked as APT28) deployed a previously undocumented backdoor called HOOKEDGE in espionage campaigns across Europe, giving the group stealthy, persistent access to compromised networks. Source: GBHackers

New “Panzer” ransomware hit 16 victims across 11 countries

A new ransomware-as-a-service operation called Panzer emerged this week, already claiming 16 victims spread across 11 countries using the now-standard double-extortion model of data theft plus encryption. Source: GBHackers

The “Shai-Hulud Trinitite” worm infected the widely used TanStack Query npm package in order to harvest developer secrets — another sign that supply-chain worms embedded in open-source package registries can spread fast and quietly across thousands of projects. Source: GBHackers

REVSTEALER malware leaves hidden programs behind after “self-deleting”

Spf Record Example 3930

Elastic Security Labs documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself, with one of them disabling Windows Update and Microsoft Defender before running a cryptocurrency miner. Source: The Hacker News

A Microsoft 365 “Direct Send” bypass lets attackers spoof internal users with no credentials

A flaw in Microsoft 365’s Direct Send feature allows attackers to spoof internal-looking emails without needing any valid credentials at all — a serious boost for phishing campaigns since messages appear to come from a trusted colleague or department. Source: GBHackers

Hackers stole Claude AI session cookies to hijack accounts

A new infostealer campaign is specifically targeting and stealing session cookies for Claude AI accounts, letting attackers hijack sessions and bypass multi-factor authentication entirely — since a stolen session cookie doesn’t need a password or MFA code at all. Source: GBHackers

Attackers sent malicious Excel files to 80,000 freelancers using 255 fake accounts

A large-scale campaign used 255 fake accounts to blast malicious Excel files at roughly 80,000 freelancers, showing how the gig-economy workforce — often without enterprise-grade email filtering — makes an attractive, broad target for mass malware delivery. Source: GBHackers Spf Lookup 2220

Hackers posed as IT support on Microsoft Teams to target 150+ employees

A social-engineering campaign impersonated internal IT helpdesk staff over Microsoft Teams to target more than 150 employees at a single organization — the same “fake IT support” pretext that has proven effective against major companies over the past year. Source: GBHackers

A fake acquisition scam used forged NDAs to demand a €626,000 payment

Business email compromise crews are refining their pretexts: one campaign used a fabricated company-acquisition scenario, complete with forged NDAs, to try to trick a target company into wiring €626,000 to attacker-controlled accounts. Source: GBHackers

QR-code phishing (“quishing”) hit record levels

Attackers are increasingly hiding malicious links inside QR codes to sidestep traditional link-scanning email defenses, and this tactic has now hit record volume — a reminder that any QR code in an unsolicited email or text should be treated with the same suspicion as a raw link. Source: GBHackers

Hackers compromised more than 14,500 Dahua security cameras

A mass-exploitation campaign compromised over 14,500 internet-connected Dahua security cameras, building a ready-made pool of hijacked IoT devices that can be repurposed for botnets, proxying attack traffic, or further reconnaissance. Source: GBHackers

As AI-powered attacks, phishing, and BEC campaigns continue to evolve, strong SPF, DKIM, and DMARC protections are becoming increasingly important for organizations seeking to strengthen email security and prevent domain spoofing.

Brad Slavin
Brad Slavin

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead for AutoSPF's 2,000+ customer base.

LinkedIn Profile →

Ready to get started?

Try AutoSPF free — no credit card required.

Book a Demo