ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

Ravie LakshmananOct 01, 2026Hacking News / Cybersecurity News

This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years.

That is the lesson running through the list. Attackers do not always need a brilliant new trick. They can hide commands in public infrastructure, reuse old flaws, abuse weak defaults, or let automation stitch together a rough path that still works. Faster tools are changing the pace, but basic mistakes are still doing plenty of the work.

So the interesting question this week is not “what broke?” It is “what did we assume was safe because it looked ordinary?” The full list has answers.

The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.

  1. ATM jackpotting crackdown

    The U.S. Treasury’s Office of Foreign Assets Control (OFAC) sanctioned 10 targets involved in a Tren de Aragua ATM jackpotting scheme that stole at least $40.73 million from U.S. financial institutions. The network used cryptocurrency to launder the proceeds. Tren de Aragua is a designated Foreign Terrorist Organization. Jackpotting uses Ploutus malware to force ATMs to dispense cash. Treasury estimates show reported losses totaling $40.73 million from more than 1,500 alleged TdA jackpotting attacks in the U.S. as of August 2025. TRM Lab said the seven designated crypto wallet addresses have received approximately $6.1 million in total inflows since March 2022. “Tren de Aragua is using ATM malware as a terrorist financing tool, then moving the cash onto TRON so it looks like ordinary exchange deposits,”  said Ari Redbord, Global Head of Policy at TRM Labs. “That is the same playbook we keep seeing from FTOs with on-chain infrastructure. These sanctions target that playbook. We are seeing the Treasury go after both the bad actors and their financial facilitators.”

The useful part is not remembering every story. It is noticing the small choices behind them: what gets trusted, what stays exposed, what runs without much checking, and what nobody looks at because it seems routine. Those are the places attackers keep finding room.

The tools are getting faster, and some attacks are getting stranger, but the basic lesson is still pretty simple. Know what your systems can reach, what they are allowed to do, and which old assumptions are still hanging around. That will matter next week too.

The post “ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories” appeared first on The Hacker News

Source:The Hacker News – [email protected] (The Hacker News)