The past 48 hours have been brutal for defenders. The BeyondTrust RCE vulnerability — already a known critical flaw — has been confirmed by CISA as actively exploited in ransomware campaigns, not just APT intrusions. Web shells, backdoors, and data exfiltration are all in the mix. Japanese semiconductor testing giant Advantest was simultaneously hit by ransomware, disrupting supply chains for chip manufacturers globally. A Mississippi medical center closed all clinics after a ransomware hit — the healthcare sector continues to be a soft target with catastrophic real-world consequences.
On the supply chain and AI threat front, Cline CLI 2.3.0 was compromised in a targeted supply chain attack that silently installed "OpenClaw" malware on developer systems — and a follow-up infostealer is now confirmed to be specifically targeting OpenClaw AI agent config files and gateway tokens. This is a new attack vector: compromise the dev tool, steal the AI agent credentials, own the automation pipeline. Meanwhile, PromptSpy is being called the first Android malware to use generative AI (Gemini) at runtime for persistence — threat actors are now weaponizing the same AI features users trust.
Rounding out the week: PayPal disclosed a data breach exposing user info for 6 months before detection, and a French bank registry breach hit 1.2 million accounts. Three former Google engineers were indicted for transferring trade secrets to Iran. The attack surface is expanding on every axis simultaneously — developer tools, AI infrastructure, financial systems, and critical healthcare.