Secret CISO 9/11: One Missed Call Hijacks WeChat, ShinyHunters Hits 1M Students, Anthropic Catches AI Hackers, Fake Claude App Drains Crypto

A zero-click worm hijacks WeChat before you answer, ShinyHunters hits 1 million Mathspace students, Anthropic catches AI running its own hacking campaigns, and a fake Claude app drains crypto wallets. Plus PaperCut's twice-broken patch and today's top CVEs.

Share
cracked smartphone with WeChat's green chat-bubble icon leaking glowing data during an incoming call

Your phone does not need you to pick up anymore. A missed WeChat call, a fake AI app, and Anthropic's own threat hunters all made the same point today: the device in your pocket is now doing the attacking and the defending.

Today's Top 5

  1. One Missed Call, Full Takeover: Researchers built a zero-click worm that hijacks a WeChat account while the phone is still ringing, no tap required. It jumped from one test phone to two more in minutes.
  2. ShinyHunters' Education Sweep: Over 1 million students, parents, and teachers across Australia and New Zealand just learned their account data sat exposed. The database flaw had a patch available for three weeks before anyone used it.
  3. Anthropic Catches AI Doing the Hacking: Anthropic's threat hunters disrupted state-linked operators who let Claude run entire intrusion campaigns with almost no human typing. One operation touched two dozen targets over four months.
  4. A Fake AI App Steals Your Wallet: Criminals built a bogus free version of a popular AI chatbot desktop app that quietly drains more than 50 different cryptocurrency wallets the moment you install it.
  5. Patched Twice, Broken Twice: A print-server vendor rushed out an emergency fix for a chain of bugs letting anyone take over its servers, only for researchers to crack that patch days later, too.

Full stories, CVEs, and today's listening are below. Let's dig in.

Data Breaches

graduation cap unzipping with data streaming out
  1. Mathspace's Metabase Zero-Day Exposes 1 Million Students: Online math platform Mathspace confirmed attackers stole personal data on more than 1,079,000 students, parents, and school staff across Australia and New Zealand after exploiting a maximum-severity SQL injection flaw, tracked as CVE-2026-72898, in its self-hosted Metabase reporting tool. A patch had been available for three weeks before Mathspace updated its own instance. ShinyHunters claimed the intrusion; usernames, emails, and account metadata were taken, though Mathspace says passwords and academic records were not. Source: BleepingComputer
  2. Panzer Ransomware Claims Spain's National Weather Agency: A month-old ransomware operation called Panzer says it broke into Agencia Estatal de Meteorologia, the Spanish government agency that issues weather forecasts and aviation and maritime advisories. Panzer has hit 16 to 21 victims across at least 11 countries since its leak site appeared in early August, using a double-extortion model of data theft plus encryption. Spain has not confirmed the intrusion, and leak-site claims remain unverified pending forensic review. Source: Hendry Adrian
  3. Trezor's Shipping Breach Grows to 81,000 Customers: Hardware wallet maker Trezor disclosed that a breach at its former shipping partner ShipMonk is worse than first reported, now covering roughly 81,000 US customers after 67,000 more records surfaced. The newly found data, dating from 2019 to 2021, includes names, emails, phone numbers, and shipping addresses. ShipMonk had repeatedly told Trezor the old data was deleted; it was not. Trezor says its own systems and the wallets themselves were never touched. Source: The Hacker News
  4. Healthcare Chain Nutex Confirms Patient Data Theft: Houston-based micro-hospital operator Nutex Health, which treats nearly 100,000 patients every six months across 27 facilities, confirmed that attackers exfiltrated patient, employee, and financial data from its network. The Gentlemen ransomware gang, a double-extortion crew claiming more than 580 victims in 75-plus countries, added Nutex to its leak site after the company first flagged unauthorized activity in late August. Nutex says it is still determining exactly what was taken. Source: The Record
  5. Indian Bank Hit for 41GB in New Extortion Claim: A financial-sector extortion crew calling itself Global Secret Group says it pulled 41.3GB, nearly 126,000 files, from CO-OP Urban Bank Ltd in India. The group, active only since January, has built a victim list spanning the US, Europe, Canada, and the UAE, and recently claimed Indian IT services firm Hinduja Tech for more than 500GB. The bank has not issued a public statement. Source: RedPacket Security

Security Research

cartoon worm poking out of a vintage telephone handset
  1. Anthropic Catches State-Linked Hackers Running Claude Solo: Anthropic's latest threat intelligence report describes disrupting cyber operations where AI moved from assisting hackers to running entire intrusion campaigns with minimal human input, a pattern the company calls vibe hacking. A Russian cluster hit more than 20 organizations and a Hunan-based Chinese group targeted roughly 50, while a separate 130-day campaign touched two dozen Ukrainian government, defense, and drone-supply targets. Anthropic also says seven China-based AI labs tried to extract Claude's capabilities through systematic distillation. Source: Anthropic
  2. A Missed Call Can Now Hijack Your WeChat: Security firm Calif built WeWorm, described as the first zero-click worm to spread through WeChat voice calls, taking over an account before the victim even answers the phone. In a demo, one Android phone infected an iPhone mid-ring, which then infected a second Android phone the same way, giving full read, send, and call control of the account. Calif reported the flaw to Tencent in July, and the company has since blocked the exploit; no real-world attacks have been reported. Source: The Hacker News
  3. Fake 'Free Claude' App Hides Crypto-Draining Malware: Morphisec researchers uncovered a trojanized Electron app posing as a free version of Anthropic's Claude Opus 5, distributed through GitHub and game-cheat sites, that installs a stealer called RevStealer. The malware checks for virtual machines before running, then harvests more than 50 cryptocurrency wallets plus browser passwords, cookies, VPN configs, and messaging data, exfiltrating everything before removing itself instead of sticking around. Source: crypto.news
  4. Phishing Pages Now Hide Inside Your Own Browser: Barracuda researchers detailed a technique that builds a fake login page as a blob URL generated locally inside the victim's browser instead of hosting it on attacker infrastructure, routing victims through legitimate Microsoft redirect links along the way. Because the page never touches a suspicious external domain, it slips past URL reputation checks and looks like a normal in-browser tab. Source: Barracuda Blog
  5. One Phishing Kit, 46 Countries, Same Fake Invoice: ANY.RUN researchers tracked a campaign that uses fake business documents to trick victims into installing legitimate remote monitoring and management software, handing attackers hands-on-keyboard access disguised as a helpdesk tool. The operation spun up 425 kit URLs across 240 hosts, with 94 percent of pages surviving only a single day before rotating, and the US and Canada account for nearly half of observed targeting. Source: The Hacker News

Top CVEs

  1. CVE-2026-85880: A local elevation-of-privilege flaw in the Windows Advanced Local Procedure Call component lets an attacker who already has code execution trigger a heap-based buffer overflow to escape a sandboxed process and reach SYSTEM privileges. Microsoft confirmed active exploitation and shipped a fix in September's Patch Tuesday batch alongside a second exploited Windows Update Stack bug. Source.
  2. CVE-2026-82078: A critical unsafe dynamic class-loading flaw in PaperCut NG and MF's database connection utilities, rated 9.4, can be chained with a separate authentication-bypass bug for unauthenticated remote code execution on internet-facing print servers. PaperCut has now shipped three rounds of emergency patches after researchers at watchTowr broke the first two fixes; the federal remediation deadline for this flaw lands September 14. Source.
  3. CVE-2026-86060: A command-injection flaw in MikroTik RouterOS lets an attacker who can reach the device's management interface smuggle extra arguments into system commands, potentially leading to full device takeover. CISA added it to its Known Exploited Vulnerabilities catalog on September 10 alongside a related RouterOS authentication-bypass bug, both under active exploitation. Source.
  4. CVE-2026-87491: An out-of-bounds write bug in Chromium's V8 JavaScript engine can be triggered by a malicious web page to corrupt memory and potentially achieve remote code execution inside the browser sandbox. Google patched it, and CISA added it to the KEV catalog on September 9 after confirming in-the-wild exploitation against Chrome and other Chromium-based browsers. Source.
  5. CVE-2026-20079: An authentication-bypass flaw in Cisco Firewall Management Center lets a remote attacker reach the management interface through an alternate path without valid credentials, to reconfigure managed firewalls. CISA confirmed active exploitation and added the bug to its KEV catalog on September 9, giving federal agencies a short window to patch or disconnect exposed instances. Source.

Podcasts & Talks

microphone with headphones and a tiny owl also wearing headphones
  1. Risky Business #852: Cyber Command Wants to Buy Shells: This week's Risky Business digs into US Cyber Command's push to acquire offensive tooling and exploits from private vendors, plus the week's news roundup of major breach and vulnerability stories. Hosts Patrick Gray and Adam Boileau break down what buying access at scale means for how Cyber Command operates versus building in-house. A solid listen for anyone tracking how governments are professionalizing offensive cyber procurement. Listen: https://risky.biz/RB852/

Final Words

Today's throughline is the device in your pocket. A WeChat worm that fires before you tap accept, a fake AI app that helps itself to your crypto wallet, and a print server exploit chain that a vendor could not patch cleanly on the first two tries: the attack surface keeps shrinking to the things we trust the most.

Anthropic's report is the more interesting long game. When the company that builds the model is also the one hunting its misuse, security teams get a rare look at the other side's workflow: twenty targets hit by one operator, fifty by another, almost no human typing after the first prompt. Expect more disclosures like this as agentic tooling keeps getting cheaper to run than to defend against.

If today's edition was useful, forward it to a colleague or friend who should be reading it too. And if this landed in your inbox because someone forwarded it, or you're reading it on the web, subscribe free at secretciso.org to get Secret CISO delivered every morning.

Stay vigilant, stay informed, and see you in the next edition of Secret CISO!

Read more