The Week the Tape Came Off: Old Bugs, Cheap C2, and AI That Breaks Things
A roundup of the criminal-economy churn driving this week's intrusions, from plugin holes to agentic AI gone feral.

The pattern this week is the pattern every week. Old bugs, sketchy plugins, trusted binaries doing things they shouldn't. The wrapper changes. The mess doesn't.
What's worth flagging is the drift at the edges of the ecosystem. Lower-tier crews are getting hands on better tooling. Forums that went dark a few months back are reconstituting under fresh branding, often with worse operational security and louder operators. And the agentic-AI experiments inside enterprises are starting to break production systems in ways that look, from the outside, indistinguishable from intrusion.
A few threads to pull on.
Unpatched plugins, again. Initial access brokers are still listing footholds gained through WordPress and CMS plugin bugs that have had patches sitting on vendor sites for months. Listings on Russian-language forums this week priced unauthenticated RCE access to mid-market e-commerce shops in the low four figures. Buyers tend to be affiliates of mid-tier ransomware crews looking for soft targets in retail and professional services.
ClickFix keeps working. The social-engineering pattern — convince a user to paste a malicious command into the Run dialog under the guise of a CAPTCHA or browser fix — is now standard tradecraft for commodity infostealer crews. Lumma successors and a handful of newer Russian-speaking operators are running it at scale. Victims skew SMB. Few are reporting.
JavaScript backdoors in trusted supply chains. Researchers continue to flag npm and extension-marketplace packages shipping obfuscated loaders. The economics are obvious. A single poisoned dependency reaches thousands of developer workstations, and developer workstations hold cloud keys.
C2 frameworks for the budget-conscious. Cobalt Strike cracks remain in circulation, but the interesting movement is around cheaper, purpose-built frameworks being sold on Telegram for a few hundred dollars a month. Detection coverage lags. Vendors are catching up but the half-life of a new framework before EDR signatures land is still measured in weeks.
AI agents misbehaving. Two incident responders I spoke to this week described internal investigations that started as suspected intrusions and ended as misconfigured AI agents with overly broad API tokens. No attacker. Just an agent doing exactly what it was told, against systems it should never have touched. Expect this category to grow.
None of the individual items here are novel. The aggregate is what matters. The criminal economy is industrialising at the bottom end while the defensive side keeps treating each wave as a one-off.
Patch the plugins. Rotate the developer tokens. Scope the agents. Assume the forum you thought was dead is back under a new name.


