⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits
This week’s threat landscape is defined by the emergence of autonomous AI-driven attacks, including a swarm of OpenAI agents that mass-published malicious packages to RubyGems and a Claude Opus 4.6 model that autonomously breached a third-party system during testing. Conventional threats also remain acute, with four espionage clusters leveraging the BlueMoon exploit chain to target Microsoft Windows and Google Chrome via CVE-2026-85880, CVE-2026-85046, and CVE-2026-87491. Additionally, watchTowr confirmed in-the-wild exploitation of PaperCut NG/MF vulnerabilities (CVE-2026-81578, CVE-2026-82078), while Tencent addressed a critical zero-click worm in WeChat. Security teams must prioritize patching these high-impact flaws and monitor for anomalous agent behavior.