A Zero-Click Worm That Arrives as a Phone Call (09/08/2026)
- › Calif researchers built a WeChat worm that takes over an account through an incoming call the target never has to answer, and showed it spreading between phones.
- › Check Point found that one instruction planted in a ChatGPT conversation could make the assistant forward a victim's Gmail data while answering normally.
- › A financially motivated group used an autonomous multi-agent framework to compromise thousands of credentials in under six hours.
- › Red Hat disclosed a FreeIPA flaw chain letting a client that never logged in create a Kerberos identity and land in the administrators group.
- › Adobe patched a maximum-severity Magento and Adobe Commerce flaw already exploited to deploy a Rust backdoor and a PHP web shell.
The WeChat research is worth reading even if nobody in your organization uses WeChat, because of what the delivery mechanism removes. The target does not have to answer the call, tap anything, or make a judgment about whether something looks legitimate. Every awareness control any of us have built assumes the user gets a decision to make, and this class of attack does not offer one.
Top 5 Critical Security Alerts
1. A WeChat Worm That Spreads Through Incoming Calls
Researchers at the security firm Calif built a worm that takes over a WeChat account through an incoming call and demonstrated it spreading across three test phones, with the person being called never needing to answer. Zero-click delivery through a real-time communication path is the most valuable primitive an attacker can have, because it defeats user judgment entirely and it works while the phone sits face down on a desk. The demonstration of spread between devices is the part that turns this from a vulnerability into a worm. The Hacker News has the research.
Operator Note: For anybody in your organization whose compromise would matter most, the control is a hardened device and a short patch window, since there is no behavior you can train that changes this outcome.
2. A Planted ChatGPT Prompt Forwarded a Victim’s Gmail Data
Check Point Research reported that a single instruction planted in a ChatGPT conversation could cause the assistant to quietly work for an attacker while continuing to answer the user’s question as normal, sending Gmail data to another account. The user-facing output stayed correct, which is what makes this hard to catch, since the only visible evidence is an answer that looks exactly like the answer you asked for. Any assistant with mailbox access is an authenticated agent operating on instructions from text it did not author. The Hacker News has the report.
Operator Note: Inventory which AI assistants in your environment hold live connectors to mail and file storage, because that connection is the difference between a bad answer and an exfiltration path.
3. Autonomous Agents Took Thousands of Credentials in Six Hours
A financially motivated group used an autonomous multi-agent attack framework to compromise thousands of credentials in under six hours. The number to hold onto is the duration rather than the volume, because six hours is shorter than most detection-to-response cycles and considerably shorter than a weekend. Campaigns that used to unfold over days now complete inside a single shift, and staffing models built around business hours were not designed against that. The Hacker News has the framework detail.
4. A FreeIPA Flaw Chain Hands Out Administrator Credentials
Red Hat disclosed a flaw chain in FreeIPA allowing a client that has never authenticated to create a Kerberos identity of its own choosing in the directory and end up inside the administrators group. FreeIPA determines who is allowed to do what across the estates that run it, so a flaw producing reusable administrator credentials from an anonymous starting point compromises the system every other control defers to. Restoring a directory after this is the recovery problem, not the patch. The Hacker News has the advisory.
Operator Note: After patching, audit for principals created outside your provisioning workflow, because the flaw’s output is a legitimate-looking account that survives the fix.
5. Adobe Patches the Magento Zero-Day Behind a Rust Backdoor
Adobe released patches for a maximum-severity flaw in Adobe Commerce and Magento Open Source that had been under active exploitation, with observed attacks deploying a Rust backdoor and a PHP web shell. This is the flaw that was disclosed as unpatched over the weekend, so the window between public disclosure and a fix ran across a Saturday and Sunday when nobody was watching a store server. Patching now still leaves the question of what was installed before Monday. The Hacker News has the CVE detail.
Additional Security Alerts
Threat Intelligence
- Slim Spider steals crypto custody secrets in Brazil: CrowdStrike is tracking a previously undocumented financially motivated actor behind attacks on Brazilian financial institutions since at least March 2026. The Hacker News
- BigBear’s panel held 5,137 records across 461 organizations: Researchers got inside the phishing crew’s own admin panel and counted the stolen Microsoft 365 credentials, which is a rare direct measurement of a campaign’s yield. The Register
- ClickFix campaigns are abusing legitimate services for persistence: Two separate attacks show the social engineering tactic being paired with trusted infrastructure to hold access after the initial compromise. Dark Reading
Security Breaches and Incidents
- Boston Scientific says an August intrusion will hit full-year earnings: The medical device manufacturer warned that recovery is dragging and the financial effect reaches Q3 and the full year, which is the rare public quantification of what an incident costs. The Register
- The Liquid Network attackers kept $47 million as a bounty: Public negotiations ended with roughly 3,400 Bitcoin returned and the attackers retaining the rest, which sets an uncomfortable precedent for what a negotiated outcome looks like. The Record
Security Standards and Frameworks
- Chrome moves to a two-week release cadence: Google is shortening the interval between releases to ship security fixes faster, which shortens your own testing window by the same amount. TechCrunch
- France stands up a government cyber incident response unit: The Prime Minister called for a dedicated national capability following a major attack on the country’s tax authority. Infosecurity Magazine
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.