AI Agents Skimmed 600,000 Cards (09/23/2026)

September 23, 2026
AI Agents Skimmed 600,000 Cards (09/23/2026)
Key Intel / TL;DR
  • › A single operator gave short instructions to three open-source agent frameworks and let them run, and they stole more than 600,000 card records.
  • › The agents launched 105 attack waves in six days and infected at least 119 sites, including a Fortune 500 hospitality company and a major US airline.
  • › F5's BIG-IP APM zero-day gives unauthenticated code execution where APM acts as an OAuth authorization server, and federal agencies have until Thursday.
  • › The private email address GitLab issues for filing tickets is a credential that can commit code in your name.
  • › A public exploit now exists for an unpatched Ubuntu kernel flaw that escapes containers to host root.

Yesterday’s lead was an implant that lets AI models vote on its next move, and the honest caveat was that the build was experimental. Today’s lead is the version that is not experimental. One operator handed brief instructions to three open-source agent frameworks and let them work through online retailers for two months, and the result is more than 600,000 stolen card records. Alongside that, F5 has a BIG-IP zero-day under active exploitation with a federal deadline of Thursday.

Top 5 Critical Security Alerts

1. AI Agents Ran a Card Skimming Campaign Against Real Retailers

Gambit found the campaign after getting into an attacker’s staging server, and the evidence shows a financially motivated operator, apparently based in China, directing three open-source frameworks: Strix for scanning and vulnerability discovery, an exploitation engine called Cairn tasked with objectives like gaining a shell or admin access, and Hermes for coordination and post-exploitation. Between September 10 and 15 the agents launched 105 distinct attack waves and succeeded against at least 27 targets, and across a campaign running from at least July through September 22 they infected at least 119 sites with payment skimmers and took more than 600,000 card records from two companies, with targets including a Fortune 500 hospitality company and a major US airline, per BleepingComputer. This Cairn is unrelated to the Talos tracking project of the same name in yesterday’s briefing.

Operator Note: 105 attack waves in six days is the number to hold onto, because it describes the attacker’s labor cost falling toward zero. Against an attacker whose cost per attempt is close to nothing, the controls that pay off are the dull ones, such as patched plugins, integrity monitoring on checkout pages, and a content security policy that blocks scripts you did not approve.

2. F5 BIG-IP APM Zero-Day Exploited for Unauthenticated Code Execution

F5 and CISA are warning of active exploitation of CVE-2026-94127, a heap-based buffer overflow scoring 9.8 on CVSS v3.1 and 9.3 on v4 that affects BIG-IP Access Policy Manager where an APM access policy and an OAuth authorization server profile sit on the same virtual server. The malicious traffic goes to the virtual server itself, so restricting the management interface does not help, and CISA added it to the catalog on September 22 with a September 25 deadline for federal agencies, per The Hacker News and The Register. Hotfixes exist for the 21.1, 17.5, and 17.1 branches.

Operator Note: The usual advice for BIG-IP is to lock down the management plane, and this one arrives through the data plane instead. Check whether you run APM as an OAuth authorization server before assuming you are out of scope.

3. Chinese Actor Uses Chrome and Windows Zero-Day Chain to Deliver CLEANGULP

A China-linked actor tracked as UTA0565 has been exploiting the recently disclosed Chrome and Windows exploit chain as zero-days through fake websites to deploy malware called CLEANGULP, per The Hacker News. A browser-to-kernel chain delivered by a website means the user’s only mistake was visiting a page, which puts browser update speed at the top of the list.

4. A GitLab Issue Email Address Is a Credential

The private address GitLab gives each user for filing issues by email can be used by anybody who obtains it to email a patch that GitLab commits in that user’s name, to any branch they can push to, per The Hacker News. Those addresses end up in forwarding rules, support tooling, and shared inboxes, which is a long list of places to keep something that can write code.

5. Public Exploit for an Unpatched Ubuntu Container Escape

DepthFirst published research on a use-after-free in the Linux kernel’s AF_UNIX socket subsystem that escapes a container to root on the host, with an exploit now public and no patch yet shipped, per The Hacker News. Anybody running untrusted workloads in containers on shared Ubuntu hosts should treat the container boundary as advisory until the fix lands.

Additional Security Alerts

Threat Intelligence

  • Ransomware hit a record for 2026 in August: NCC counted 1,073 victims globally in the month, with the industrial sector hit hardest. Infosecurity Magazine
  • Most ransomware groups are working the healthcare sector: An analysis of US ransomware activity finds 77% of groups targeting healthcare. HIPAA Journal
  • Compromised MemTensor packages deliver a credential stealer: Two legitimate packages on npm and PyPI were hijacked to push a Go implant tracked as sckit. The Hacker News

Security Breaches & Incidents

  • FBI confirms it is investigating the ShinyHunters claim: The group replaced images on the FBIjobs.gov site on Tuesday, following its claim of a PeopleSoft zero-day breach. The Record
  • Elsevier hit by a LAPSUS$ redirect: Customers trying to reach journals landed on the crew’s calling card instead. The Register
  • Ryuk member sentenced to two years: An Armenian national involved in Ryuk attacks received a two-year federal prison sentence. The Record

Cloud & Network Security

  • 474 leaked GitHub App keys still authenticate: GitGuardian found hundreds of exposed App private keys that still work, including some with admin access. Infosecurity Magazine
  • One Kubernetes YAML can hand over a GCP organization: Varonis shows a user with limited Kubernetes permissions escalating to organization control through Config Connector’s authority. BleepingComputer
  • MikroTrick takes over MikroTik routers with no credentials: Two chained RouterOS SSH flaws give full admin control of exposed routers without a password or key. The Hacker News
  • cPanel flaw lets any hosting account run code as root: A bug in the CalDAV and CardDAV service hands a shared hosting customer full server control. The Hacker News
  • Next.js ImageResponse can execute code from a crafted SVG: The feature that generates social preview images is the entry point. The Hacker News

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)