In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

**Ransomware Feud Escalates as ShinyHunters Takes Down Clop Leak Site**

In a shocking move that highlights the cutthroat world of cybercrime, the ransomware gang Cl0p has seen its Tor data leak site seized by rival extortion group ShinyHunters. The attack is reportedly payback for alleged threats made by a Cl0p representative during a high-profile campaign against Oracle E-Business Suite targets.

The Clop ransomware gang has been notorious for its brazen attacks on major corporations, and its data leak site was a key part of its extortion efforts. However, ShinyHunters claims to have stolen server logs, source code, and the private keys for Clop’s onion service. The group is demanding an eight-figure payment and a public apology from Cl0p in exchange for not exposing companies that allegedly paid Clop during its Oracle E-Business Suite campaign.

This feud between two major ransomware gangs has far-reaching implications for the cybersecurity community. It highlights the complex web of rivalries and alliances within the world of cybercrime, where groups constantly try to outdo each other in terms of brazenness and technical sophistication.

**BragJack Flaws Put Browser AI Assistants at Risk**

Meanwhile, researchers at endpoint security firm Forever have disclosed a set of flaws known as BragJack that allow malicious extensions to take control of the built-in AI assistants in popular browsers such as Chrome, Edge, and Opera Neon. The flaws exploit the fact that these assistants trust commands from specific web pages, allowing an installed extension to hijack those pages and inject scripts or tamper with network traffic.

This vulnerability has significant implications for users who rely on browser AI assistants for tasks such as reading emails, accessing local files, capturing screenshots, or controlling their camera and microphone. The vendors of these browsers have paid bounties ranging from $600 to $7,000 to fix the flaws, highlighting the importance of patching vulnerabilities in a timely manner.

**Go Implant Sneaks into AI Agent Memory Tooling**

In another concerning development, an attacker has published malicious versions of MemTensor’s MemOS packages on npm and PyPI, including a memory plugin for the OpenClaw AI agent harness. The packages carry a previously unseen Go implant named sckit that launches when the Python library is imported or the npm plugin is used.

The implant hunts for sensitive information such as npm, PyPI, GitHub, AWS, Hugging Face, and other secrets. While there is no evidence yet that it has propagated, the fact that it contains templates for spreading through npm, PyPI, and GitHub Actions highlights the need for users to exercise caution when installing packages from untrusted sources.

**AI Relay Networks Funnel Chinese Traffic to Western Frontier Models**

Team Cymru has discovered nearly 11,000 servers running Claude Relay Service or its successor, sub2api. These open-source gateways pool AI accounts so many users can share them, while model providers see only the relay and never the real user or their location.

This setup allows Chinese traffic to be funneled through Western frontier models such as OpenAI, Anthropic, xAI, and Google endpoints. While this may seem like a legitimate use of AI technology, it raises concerns about data sovereignty and the potential for malicious actors to exploit these relay networks.

**Infostealer Logs Expose Remote Access Keys Across US Water Sector**

SpyCloud has analyzed stolen identity data tied to 10,000 US water and wastewater utilities and their technology vendors. The analysis found active infostealer exposure at 1,787 organizations, with credentials for OT or remote-access systems at 258.

In one concerning case, malware on a single device at an advanced-metering technology provider captured saved logins for roughly 167 utility metering portals. Exposed credentials at the utilities themselves were mostly for remote-administration tools such as TeamViewer and SonicWall management portals.

**Takeaway: Prioritize Patching and Secure Your AI Assistants**

As these stories demonstrate, the world of cybersecurity is constantly evolving, with new threats and vulnerabilities emerging every day. It’s essential to prioritize patching your systems and keep your software up-to-date, especially when it comes to browser AI assistants that can be exploited by malicious extensions.

By taking proactive steps to secure our technology, we can reduce the risk of falling victim to these sophisticated attacks and protect ourselves against the evolving threats landscape.


Source: SecurityWeek — 2026-09-25