Risky Bulletin Newsletter
September 23, 2026
Risky Bulletin: Network of 10,000 AI servers masks Chinese malicious activity
Written by
News Editor
This newsletter is brought to you by SpecterOps, the experts in Attack Path Management. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.
Security researchers have discovered more than 10,000 proxy servers that are masking malicious AI activity originating out of China.
Security firm Team Cymru calls the server "transfer stations," but they are more commonly known as API proxies, relays, or gateways. Typically, they are used in corporate environments to cache AI queries and cut down token costs, but in recent months they have also been adopted by a new section of the criminal underground, one dedicated to abusing public AI services.
These days, AI proxy relays are being used to hide activity from hacked AI accounts, mask the real location of a user, or power illegal AI services like nudify apps and others. Other malicious AI relay servers are also used in schemes to intercept legitimate AI caching activity and inject their own queries and harvest responses.
Team Cymru researchers analyzed a sample of 100 servers from the total 10,000 and found they were being used to relay traffic, mostly from China, to larger Western AI services.
Some server clusters were being used to bypass region bans, while others looked like they were carrying out distillation attacks against frontier AI labs.
Researchers say that most of the servers ran on top of a handful of open-source AI gateway server software. Some of the projects received donations from illicit service providers such as residential proxy vendors, API relay resellers, and providers selling compromised AI accounts—so no surprise they were being used for malicious activity!

Risky Business Podcasts
In this edition of Between Two Nerds, Tom Uren and The Grugq talk about whether there is such a thing as real-time cyber defence. Will agentic AI save us from hacking AI?
Breaches, hacks, and security incidents
Ukrainian hackers leak Russia's naval secrets: A Ukrainian hacking group has leaked technical documentation on more than 70 Russian naval projects. The files were allegedly stolen from Russian science research centers and manufacturers. They include in-depth details on submarines, warships, navigation systems, sonar technology, and autonomous underwater vehicles. A group calling itself Ukrainian Militant took credit for the hack and leak. [United24 // Ukrainian Militant on Telegram]
BigCommerce notifies merchants of incident: Ecommerce platform BigCommerce has notified merchants of a security incident with a third-party app named Ribon. Hackers stole a Ribon access key and used it to inject malicious scripts on online stores hosted on the BigCommerce platform. The scripts were live between September 13 and 17, when BigCommerce revoked the key and uninstalled the app from all stores. Attackers are believed to have collected customer details from all affected stores. [Emery Reddy // Master of Malt]
LMU breach: The Ludwig Maximilian University of Munich has disclosed a security breach. The university believes the attacker might have stolen student personal, financial, and health insurance data. [LMU]
Iran causes massive BGP incident: An Iranian AS caused a massive BPG incident on Monday that affected internet access in more than 100 countries. [Qrator // Doug Madory]
LinkedIn blocks mass scrape of user data: A California court has ordered two software companies to stop mass-scraping LinkedIn profiles. LinkedIn sued ProAPIs, Netswift, and their CEOs last October. LinkedIn argued the two companies were using millions of accounts to harvest profile data and user activity from the site. [The Record]
ShinyHunters claims FBI hack: The ShinyHunters hacking group claims to have stolen the data of almost all FBI agents and individuals who applied for a job with the agency. The FBI took down its job portal on Tuesday after the group also defaced it. ShinyHunters claims it hacked the agency after the agency published a security alert on the group's tactics earlier this year. The group claims the alert contains incorrect information. It gave the agency a week to correct or take down the alert or they'd release the stolen data.

General tech and privacy
EU fines Google €400 million: The Irish data protection agency has fined Google €403 million for breaking GDPR rules regarding data processing. The agency says Google manipulated users into agreeing to share their location data through complicated account settings. The Irish agency began investigating the company six years ago after multiple complaints from data privacy organizations. [DPC]
It’s been 8 years since we published our report on how Google tricks people into extensive location tracking, and simultaneously filed complaints against Google. Today the decision from the Irish Data Protection Commission arrived: a €400 million euros fine. www.forbrukerradet.no/siste-nytt/d...
— Ailo (@airavn.eurosky.social) September 21, 2026 at 2:04 PM
[image or embed]
AI e-waste problem: AI data centers are expected to generate between 395-617 million tons of electronic equipment waste by 2050, enough storage containers to circle the world six times if lined up in a row. [The Verge]
American CDNs dominate SEAsia: American-owned CDN providers dominate the Southeast Asian market, accounting for more than 95% of all traffic in the region. [Internet Society]
Windows Cloud Rebuild: Microsoft has added a new feature to its Windows recovery process. The new feature is named Cloud Rebuild and will perform a full OS reinstall. Cloud Rebuild can be used even when the OS isn't booting or the user can't use USB media. [Microsoft]

Apple adds Impersonation Risk Detection: Apple has shipped a new security feature with iOS 27 designed to detect active social engineering scams. The new Impersonation Risk Detection feature allows users to share sensitive data with third-party apps to allow those apps to detect a possible scam. Shared data can include download history, past purchases, email and phone call stats, and more. The new feature is available in the iOS Privacy & Security section. [Apple]

Government, politics, and policy
NIST awards $1.7 million: The US National Institute of Standards and Technology will award more than $1.7 million to eight states to address shortages of qualified cybersecurity professionals. The funds will go to educational and community organizations to help set up cybersecurity training programs. The funds will also cover internships, apprenticeships, and hands-on projects. [NIST]
US-China AI safety notifications: The US government has proposed to Chinese counterparts to create a mechanism to notify each other about AI safety incidents that may lead to national security threats. [Reuters]
US CISA Force Structure Assessment Act: US lawmakers have introduced a bill to force the US government to conduct an assessment of CISA's workforce capabilities after the Trump administration fired a third of its staff last year. [Rep. Walkinshaw]
Canada to work with Japan on cyber defense: Canada and Japan will strengthen their defense ties, including cooperating on cyber defense. [The Canadian government] [h/t Alex Rudolph]
EU wants to give AI all the data: The Irish Presidency of the EU has proposed member states to allow AI companies unfettered access to the data of EU citizens. According to a leaked document, the proposal would effectively exempt AI companies from any of the GDPR rules and deny EU citizens rights for privacy and data protection. Irish officials have submitted the proposal to the EU Council for debate. Ireland currently holds the rotating presidency of the EU. It also houses the EU headquarters of most American and Chinese AI companies. The Australian government is also working on a similar proposal to let AI companies use copyrighted work without paying. [noyb // ABC]
EU MEPs call for Meta investigation over Albanian protests: Members of the European Parliament are calling for an investigation of Meta over its handling of anti-government protests in Albania. The company has allegedly suspended more than 100 Instagram accounts involved in the protests against a luxury resort development in a protected area. The project is linked to Donald Trump's children Ivanka Trump and Jared Kushner. The MEPs argue Meta's actions amount to censorship and are a violation of EU rules. [WIRED // Repro Uncensored]
Poland launches CyberLEGION program: The Poland Armed Forces have launched a program to develop cybersecurity experts to help with the country's cyber defence. The CyberLEGION program was announced last year and launched this month. The program connects the country's cybersecurity specialists and academics to its military. It includes training and cybersecurity exercises to teach the Polish private sector how to respond to cyberattacks. According to the Poland military, more than 3,500 individuals have signed up. [Polish Armed Forces]

Sponsor section
In this Risky Business sponsor interview, Catalin Cimpanu talks with Justin Kohler, Chief Product Officer at SpecterOps. Justin will explain how Entra Agent ID can introduce new identity relationships and potential attack paths.
Arrests, cybercrime, and threat intel
Tech firms disrupt EvilTokens PhaaS: A coalition of tech companies have disrupted the EvilTokens phishing platform. The service launched in February this year and quickly became popular due to its ability to carry out device code phishing on top of regular phishing campaigns. Microsoft says the service was used to hack at least 12,000 email accounts across the world to steal data or perform BEC attacks. The company's legal team seized domains and servers, while other companies tracked EvilToken funds and identified operators and customers. UK police also arrested two suspects believed to operate the service earlier this month. [Microsoft // Microsoft // Coinbase // SpyCloud // TRM Labs]
Nigerian pleads guilty to scams: Nigerian national Olamide Shanu pleaded guilty in the US to making more than $2.5 million from sextortion and romance scams. [DOJ]
NFC relay attacks come to Belgium: Belgium's cybersecurity agency has warned the public that NFC relay attacks have been spotted in the country. These are malware and social-engineering where cybercriminals attempt to make the user scan their card's NFC and enter the PIN, using the data for illicit transactions. [SafeOnWeb.be]
Larva-25012 distributes proxyware: Researchers have spotted a threat actor (Larva-25012) distributing proxyware as apps to download YouTube video, open-source tools, and software cracks. [AhnLab]
Red Heron group: A Chinese-speaking threat actor has spent the past months hacking into and deploying backdoors into a large assortment of web apps and servers. The Red Heron group has been linked to attacks on Gitea repositories, Ubiquiti devices, Zyxel switches, WordPress sites, and AI servers. Security firm GreyNoise believes the attacker is mainly focused on data theft and uses LLMs to assemble its attack tools. [Greynoise // Acronis]

US water sector exposure: SpyCloud has found compromised logins from 1,787 US water sector organizations listed on underground credential shops. [SpyCloud]
Hangro profile: Security researchers looked at the infrastructure of Hangro, a VPN app that North Korean authorities use to hide their communications. [Synaptic Systems]
Warden interview: Threat intelligence analyst g0njxa has published an interview with the developer of the Warden infostealer. [g0njxa]
MikroTrick campaign: Poland's CERT has published a report on MikroTrick, the hacking campaign that targeted MikroTik routers with two zero-days earlier this month. The agency praised LLM agents for helping speed up the research in the attacks. Still no attribution for the attacks, though. [CERT-PL]

Terraform malware: Security researchers have found malware in two Terraform providers and two Go modules. This marks the first known case of malware on the Terraform registry. The malware is a Go port of the Graphalgo npm malware that was seen in February. It uses a Slack channel as a command and control server and deploys a RAT on selected workstations. [Aikido Security]
More npm malware: All of this npm malware reports are getting tiresome. Here's the latest one on packages targeting Twilio app devs. [ReversingLabs]
Laravel malware: And while on the topic of supply chain attacks, North Korean hackers also planted malware in a popular Laravel extension. [SlowMist]
Malicious JS hijackers: Cloudflare researchers document four campaigns that use malicious JavaScript payloads to hijack affiliate commissions and backdoor storefronts. [Cloudflare]

Malware technical reports
PAYLOAD malware: Kaspersky researchers have found PAYLOAD, malicious Group Policy Object (GPO) that a threat actor used to deploy screenlockers in an attack against a Turkish organization. [Kaspersky]
"PAYLOAD demonstrates a maturing tactic of turning the victim’s own trusted infrastructure into a weapon. By weaponizing Group Policy, the actor achieved a domain-wide impact without a single malicious binary on any endpoint, evaded file- and process-based detection entirely, and caused organization-wide disruption within seconds of the first reboot."
Vidar adds VM-based obfuscation: The good ol' Vidar infostealer has added support for a VM-based obfuscation system. [Zscaler]
TASK#STOMP backdoor: Securonix researchers have spotted a new PowerShell-based backdoor that "automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary remote commands through two redundant, token-authenticated C2 servers." [Securonix]
Closed Quorum implant: Cisco Talos has published a deep dive of Closed Quorum, the first reported fully autonomous AI-based C2 implant. [Cisco Talos]
"While we do not have confirmation of in-the-wild deployment, artifacts from the binary were used to connect the developer to postings on criminal forums related to carding, dating back to 2025."

Sponsor section
In this sponsored Soap Box edition of the show, Patrick Gray and James Wilson talk about red teaming AI systems with Russel Van Tuyl, Vice President of Services at elite penetration testing firm SpecterOps. SpecterOps is the company behind attack path enumeration tool Bloodhound and Bloodhound Enterprise, but they're also a pentest and red teaming shop with world class expertise in popping shells on all sorts of interesting systems in all sorts of interesting places.
APTs, cyber-espionage, and info-ops
China hacked at least seven EU member states last year: A Chinese-sponsored hacking group has breached shipping and maritime organizations in four EU member states and government agencies in three others. The hacks took place last year and involved compromised USB media devices. According to the EU's cybersecurity agency, Iranian hackers also targeted the EU's transportation sector but focused mainly on airlines. [ENISA]
BlueMoon linked to third Chinese APT: Volexity researchers have linked the BlueMoon exploit kit to a third Chinese APT group they are tracking as UTA0565. The BlueMoon kit was discovered earlier this month by Proofpoint, which linked it to four APTs, two of which were Chinese. The BlueMoon kit uses two Chrome and one Windows zero-days to deploy malware on a user's computer if they click a malicious link inside a Chromium-based browser. [Volexity]
Operation Talked leaks C2: A Russian threat actor has been scanning the internet using an arsenal of exploits as part of a campaign to spy on Ukraine's defense and aerospace sector. The campaign began in June of last year and is still ongoing. Security firm SOCRadar discovered the operation after the threat actor misconfigured its command and control server and leaked more than 8,400 files. Most of the attacker's exploits target older vulnerabilities in enterprise and edge network software. [SOCRadar]

Storm-1516 targets the Baltics: On the disinformation front, Russian info-op group Storm-1516 has been seen targeting the Baltic states with narratives attacking their pro-EU governments and trying to blame Ukraine for various drone incidents. [DFRLab]
Iranopasmigirim campaign: Researchers have spotted a campaign targeting Iranian dissidents in June that tried to deploy the ParsaStealer infostealer on users' devices. [InfoGuard]
Contagious Interview: Atlassian's security team has published a 44-page report on Contagious Interview, the North Korean hacking op using fake job interviews as a way to infect targets with malware. [Atlassian]

Vulnerabilities, security research, and bug bounty
Security updates: Adobe, Arista Networks, Atlassian, D-Link, Dell, Gigabyte, Oracle, Ubuntu.
Meta patches Muse hijack: Meta has patched its Muse AI assistant against a bug that could have allowed attackers to steal the Muse account token and impersonate the user. [ArsTechnica]
Check Point patches zero-day: Check Point has released a security update to patch an actively exploited zero-day in its Security Management Server product. The server is used in large networks to manage Check Point products from a central location. The patch fixes a directory traversal vulnerability that allows unauthenticated attackers to upload and execute arbitrary scripts. The company also marked a second vulnerability as exploited in the wild. This one impacts the Check Point Site-to-Site VPN and was patched last week. [Check Point // Check Point CVE-2026-93616 // Check Point CVE-2026-85102]
F5 BIG-IP zero-day: F5 has released a security update to patch an actively exploited zero-day in the BIG-IP Access Policy Manager component. The zero-day allows an unauthenticated attacker to run malicious code on the BIG-IP server. Exploitation requires a specific BIG-IP access policy and an OAuth profile to be configured on the server. No details are available on the attacker. [F5 CVE-2026-94127]
Arista zero-day: Arista Networks has patched a zero-day in its VeloCloud Orchestrator on-prem server. The zero-day allows remote attackers to access internal functions without authentication. It's unclear if all zero-days are connected. [Arista CVE-2026-93952]
BigDiskBuster zero-day: Security researcher Nightmare Eclipse has released a new Windows Defender zero-day named BigDiskBuster. The zero-day is a denial of service bug that prevents Defender from performing platform and signature updates. The researcher published the exploit days after he also revealed his real name as Abdelhamid Naceri. [GitHub]
DJI patches BLE hijack bug: Security researcher Abdelrahman Yousef has discovered a vulnerability in the Bluetooth interface of DJI drones that can allow unauthenticated attackers to send commands to its WiFi interface. The bug can be exploited to change drone configurations, change its WiFi password, and gain access to its internal network. DJI patched the bug earlier this year. A proof-of-concept has now been published on GitHub. [GitHub]
D-Link warns of two major bugs with public POCs: D-Link has notified customers of two vulnerabilities that were published online with working proof-of-concepts. The vulnerabilities impact the DIR-822A and R95 router series, respectively. One of them (CVE-2026-86296) allows remote unauthenticated attacks on the company's routers. [D-Link CVE-2026-86296 // POC // D-Link CVE-2026-93958 // POC]
lol CVE-2026-86296
— Joe Slowik (@pylos.co) September 22, 2026 at 5:20 PM
[image or embed]
Infosec industry
Threat/trend reports: Databarracks, ENISA, Forescout, Internet Society, Microsoft, and SpyCloud have recently published reports and summaries covering various emerging threats and industry trends.
New tool—CAIRN: Cisco Talos has released CAIRN, or the Cognitive Artifact Intelligence Research Network, a research toolkit for identifying, attributing, and tracking AI-related artifacts embedded in malware.
New tool—cryptoptic: American insurer Nationwide has released cryptoptic, a tool to scan a repository or an entire GitHub organisation and produce an inventory of every cryptographic function in use, the library it comes from, and where it is called.
New tool—EntraTrace: Security engineer Bert-Jan Pals has released EntraTrace, a defensive security research tool for documenting and identifying the observable behavior of offensive tooling targeting Microsoft Entra ID.
New tool—Altar: Aikido Security has released Altar, an open-weight model calibrated on cybersecurity traces, coding, tool calling, reasoning, and English.
BSides Pyongyang 2025 videos: Talks from the BSides Pyongyang 2025 security conference, which took place last November, are available on YouTube. The name is obviously a troll, but the conference does feature talks on DPRK hacking operations.
BlueHat 2026 videos: Talks from the Microsoft BlueHat 2026 security conference, which took place in May, are available on YouTube.
Risky Business podcasts
In this episode of Risky Business Features, investigative journalist Geoff White joins James Wilson to talk about what happens to the money after ransomware gangs get a payday.