RatHat, a new Android malware linked to Chinese threat actors, uses AI to automate remote device control by serializing the accessibility tree into XML and leveraging an AI assistant for intelligent interface navigation. Distributed via malvertising and phishing, it abuses Accessibility permissions and enables Developer Options to gain shell-level execution, deploying Go-based agents for persistence and credential theft from banking and cryptocurrency apps.
Microsoft released a workaround for Windows 11 domain login failures caused by September 2026 security updates that inadvertently enable Machine Identity Isolation enforcement. The feature breaks domain authentication on systems not connected to Windows Server 2025 domain controllers, and Microsoft advises disabling it via registry, Group Policy, or Intune until a permanent fix is available.
Microsoft's Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. The issue appears linked to the Windows Machine Identity Isolation security feature being set to enforcement mode after the update, causing machines to lose their secure channel with Active Directory. Administrators can restore access by disabling the feature and repairing the secure channel using PowerShell.
Hackers compromised HBO Max's verified Reddit account and posted 108 malicious ads using ClickFix social engineering to distribute information-stealing malware to Windows and macOS users. The campaign, linked to a broader operation called PasteSwitch, tricked victims into pasting commands into their terminals to install fake applications, including counterfeit HBO Max apps and cryptocurrency wallets.
CISA warned that hackers are actively exploiting a maximum-severity GitLab vulnerability (CVE-2026-85706) that allows unauthenticated attackers to read credentials and sensitive data. GitLab released patches on Thursday, and CISA added the flaw to its catalog of exploited vulnerabilities, requiring federal agencies to patch within three days.