CyberSecurity SEE

Thousands of AI Relays Conceal Chinese Users

Thousands of AI Relays Conceal Chinese Users

Cybersecurity Weekly Roundup: Major Incidents and Developments

In the ever-evolving landscape of cybercrime and cybersecurity, weekly incidents and developments have become a crucial focus for organizations and individuals alike. This week’s roundup, presented by ISMG, highlights a series of notable cybersecurity incidents, revealing a spectrum of threats that range from significant data breaches to innovative vulnerabilities. Key developments include Team Cymru’s discovery of thousands of illicit AI relay servers, the end of CISA’s long-running CVE Bulletin, and various criminal prosecutions linked to cyber activities.

Team Cymru Uncovers 10,000 Illicit AI Relay Servers

Cybersecurity firm Team Cymru recently conducted an extensive analysis that unveiled over 10,000 AI relay servers acting as "transfer stations." These servers enable users, particularly those in restricted regions, to bypass provider access controls by routing their connections to frontier artificial intelligence models without revealing their actual identities or locations. The findings indicated that more than 4,000 connections originated from Chinese and Hong Kong IP addresses, primarily hosted on U.S. infrastructure. During a concentrated eight-day analysis period, approximately 14 terabytes of data were transferred, with the servers primarily connecting to AI services, including DeepSeek and Alibaba’s Qwen, alongside Western providers like OpenAI and Google.

Team Cymru’s report raised alarming concerns about potential exploitation involving AI-model abuse, particularly through the connections to Anthropic’s infrastructure. The data exchange observed on these servers led to an estimated range of 16 to 23 billion input tokens over the course of the analysis.

CISA Concludes Weekly CVE Bulletin After Two Decades

Significant changes are underway at the U.S. Cybersecurity and Infrastructure Security Agency (CISA), as it has announced the retirement of its weekly Vulnerability Bulletin, effective September 28. For over 22 years, the Bulletin provided valuable information on Common Vulnerabilities and Exposures (CVEs), categorizing them by severity. However, CISA is shifting its focus from severity score-based alerts to a more contextualized risk management approach. This transition aims to prioritize vulnerabilities based on real-world risk factors rather than solely evaluating them by their CVSS scores.

Subscribers to the Bulletin have been encouraged to switch their notifications to the Known Exploited Vulnerabilities Catalog and Cybersecurity Advisories to continue receiving essential threat updates. This significant change corresponds with current discussions in the industry regarding the effectiveness of static vulnerability ratings in an era marked by an unprecedented influx of vulnerabilities.

Felony Convictions and Sentences in Noteworthy Cyber Crime Cases

This week also observed significant legal actions against individuals involved in cybercrime. Ardit Kutleshi, one half of the brother duo behind the illegal Rydox marketplace, has pleaded guilty to multiple charges, including conspiracy to commit money laundering and aggravated identity theft in a Pittsburgh federal court. The Rydox marketplace facilitated over 7,600 transactions involving stolen personal information and cybercrime tools, generating $232,000 in revenue. Kutleshi is now facing substantial prison time and may not return to Kosovo anytime soon, with sentencing scheduled for February 2027.

Additionally, Armenian national Karen Vardanyan was sentenced to two years in prison by a federal court in Oregon for his involvement in Ryuk ransomware attacks. Prosecutors believe these attacks extorted more than $15 million from global victims, marking Vardanyan as a significant player in the ransomware landscape.

Emerging Threats: Google Maps Hijacking and VPN Exploits

In a shocking turn of events, drug dealers in London have been hijacking Google Maps listings to promote illegal drugs by setting up fake "pharmacy" profiles. This alarming trend misleads individuals searching for legitimate pharmacies and illustrates the challenges law enforcement faces in combating online drug trade.

Furthermore, Check Point reported that attackers are actively exploiting a critical vulnerability (CVE-2026-85102) in its Security Gateway VPN. The flaw allows unauthenticated attackers to execute code on affected gateways, with Check Point rating the vulnerability a severe 9.8 out of 10. Federal agencies have been warned to apply available fixes or mitigations in light of the ongoing exploitation attempts.

Elsevier Under Cyber Attack from Lapsus$

In a separate incident, academic publisher Elsevier briefly redirected users from its websites to a page associated with the Lapsus$ cybercrime group. The company described the attack as limited and asserted that no customer data or core systems were compromised. However, the incident highlights the ongoing threat posed by cybercriminal groups like Lapsus$, which recently announced a resurgence with ambitions to target high-revenue companies.

Conclusion: A Dynamic Cybersecurity Landscape

As cyber incidents continue to rise and evolve, organizations must remain vigilant and proactive in their cybersecurity posture. Awareness of emerging threats, such as illicit AI relay servers and critical vulnerabilities, alongside understanding the implications of legal actions against cybercriminals, is essential. This week’s roundup serves as a reminder that the fight against cybercrime is complex and multifaceted, demanding coordinated efforts across sectors and borders to mitigate risks effectively. With developments expected to unfold continually, staying informed will be crucial in navigating this dynamic cybersecurity landscape.

Source link

Exit mobile version