In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure
Summary
This cybersecurity news roundup covers several AI-related threats: the BragJack vulnerability, which lets malicious browser extensions hijack built-in AI assistants to read emails and access files; a malicious Go implant called sckit hidden in AI memory management packages that searches for API keys and secrets; and a Windows malware called CLOSEDQUORUM that uses commercial AI models to make attack decisions instead of relying on traditional command servers.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.securityweek.com/in-other-news-clop-leak-site-takeover-docker-botnet-hunts-ai-keys-water-utility-exposure/
First tracked: September 25, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 85%