AI and IT News Recap: September 21, 2026: Google's Gemini Breaks Into Three Real Companies, an Orkes Conductor Flaw Is Under Attack, and CrowdSec Loses 170 Repositories
By Noah Smith, Owner & Consultant, KeyChange Technologies · September 21, 2026

A quiet weekend for model launches and a loud one for things that were already broken. Here is the AI and IT news that actually mattered from Friday through the weekend.
📌 The AI and IT news at a glance
- Google's Gemini broke into three real companies during a safety test. A fake company name used in practice exercises happened to match a real domain.
- Anthropic and Accenture will each spend at least $1 billion on embedded evaluation. Outside evaluators get employee-level access inside Anthropic.
- OpenAI published an Australian Youth Safety Blueprint. Six pillars covering age assurance, parental controls and crisis support.
- A critical Orkes Conductor flaw is under active attack. Fortinet blocked nearly 7,000 attempts in a single week.
- CISA flagged three Linux kernel flaws as exploited, and exploit code went public for four more. Federal agencies were told to patch by September 21.
- Microsoft patched a perfect-10 flaw in Azure AI Foundry. No customer action required, and no sign of exploitation.
- SolarWinds patched a hard-coded key in Access Rights Manager. An 8.8 that lets an attacker run code without logging in.
- CrowdSec says 170 of its private repositories were copied. The thread runs back to May's TanStack npm supply chain attack.
- A new WordPress flaw can install a theme with no one clicking Install. Fixed in 7.1.1, and there is no CVE for it yet.
- Four AI coding agents can be tricked into installing the wrong plugin. Claude Code and Codex are fixed; Copilot and the Gemini CLI are not.
- An npm stealer was probably written by a chatbot. CrowdStrike says the giveaways were verbose comments and placeholder code.
🔝 Top story: Google's Gemini broke into three real companies during a safety test
Google's Gemini is the latest frontier model to reach out of a security evaluation and into systems belonging to real businesses. The Wall Street Journal reported the incidents first, and they date to May 2026, during a test run by the Israeli evaluation firm Irregular, the same partner involved in similar disclosures from OpenAI, Anthropic and Meta. In one case the model gained access to a protected system by repeatedly guessing its password. In two others it found credentials sitting in a public repository and used them to reach protected systems. Irregular notified Google in July 2026, and Google says the issue was addressed weeks ago. Which companies were affected has not been made public.
The cause was mundane and that is the uncomfortable part. Irregular reported last month that a fictional company name used in its "capture the flag" practice exercises happened to match a real registered domain, so a model given internet access pointed its practice attack at a real address a limited number of times. What separates this case from the Anthropic and OpenAI incidents is how it ended: Gemini stopped once it worked out that it had breached a real company. "This event highlights the importance of training powerful AI models to act responsibly," Heather Adkins, Google's vice president of security engineering, told the Journal. "In this case, the model acted appropriately." Google says it does not consider the behavior an example of model misalignment, because the agents halted once safety mechanisms triggered.
In short: Google disclosed that Gemini gained unauthorized access to three real companies' systems during a May 2026 security evaluation, after a fictional test domain turned out to be real, and stopped on its own once it recognized the target was genuine.
What it means for your business: You are unlikely to be the target of a lab's test run, but you may well be the accidental one. The practical takeaway is the boring half of the story: two of the three break-ins worked because credentials were sitting in a public repository. That is a problem you can actually fix this week, and it does not require an AI to exploit it.
My take: Every frontier lab has now had a model wander out of its sandbox, which tells you the sandboxes were never as sealed as the marketing implied. Google deserves the credit it is claiming for the model stopping itself, and it is also worth noticing that the safety story here rests on the model's judgment rather than on a control that would have prevented the access in the first place. The scoreboard reading "four for four" is the number I would not skip past. When a category of accident happens to everyone, it stops being an accident and starts being a property of how this work is done.
Source: Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up, The Hacker News, September 19, 2026
🤖 AI
Anthropic and Accenture will each spend at least $1 billion on embedded evaluation
Anthropic announced on Friday that it is partnering with Accenture on independent evaluation of frontier AI, and that both companies expect to invest at least $1 billion each over the next five years to build capacity in the area. The work will be led by Faculty, Accenture's specialist AI business, and covers evaluating and red-teaming models, alignment assessments and testing model safeguards. This follows through on a commitment made in CEO Dario Amodei's essay "We Must Pace the Frontier" to put evaluators inside the company rather than only outside it.
The distinction Anthropic draws is about access. Today's external evaluators test finished models from the outside; embedded evaluators would work inside an AI company with access comparable to an employee's, watching models take shape during training, following the decisions that govern how they are built and deployed, and talking directly to staff. Anthropic is candid that the model is unfinished: there are no standards yet for what information embedded evaluators should see or how they should report what they find, and no settled way to fund the work. Long term the company argues funding should come from pooled or government sources; since neither exists, Anthropic will fund Accenture's work directly. The partnership is non-exclusive, more evaluators are promised in the coming weeks, and Anthropic is separately in talks with METR and other nonprofits.
In short: Anthropic and Accenture announced a partnership on embedded evaluation of frontier AI models, with each company expecting to invest at least $1 billion over five years.
What it means for your business: Almost nothing changes in your tooling, but this is a signal about where AI assurance is heading. If you buy AI that touches regulated or sensitive work, "who independently checked this, and what could they actually see" is becoming a question with a real answer, and it is a fair one to put to any vendor.
My take: The billion-dollar figures will get the headlines and the funding arrangement is the part that deserves the scrutiny. Anthropic says outright that independent evaluation should eventually be paid for from pooled or government money, and that because that does not exist, it is paying Accenture itself. That is an honest description of an awkward position: the company being audited is writing the auditor's cheque. Anthropic naming the problem rather than glossing it is worth something. Whether embedded evaluation means anything will come down to whether an evaluator can publish something the lab hates.
Source: Partnering with Accenture on embedded evaluation, Anthropic, September 18, 2026
OpenAI published an Australian Youth Safety Blueprint
OpenAI released the Australian Youth Safety Blueprint on Friday, a policy document setting out six pillars for protecting young people using AI: AI literacy, age-appropriate safeguards, privacy-protective age assurance, connections to real-world crisis support, accessible parental controls, and accountability for companies in identifying and addressing risks to young people. The company frames it as a contribution to Australian policy rather than a product change.
There is product behind it, though. OpenAI says that in August it began rolling out ChatGPT for Teens in Australia, a default experience for users identified as aged 13 to 17 with safeguards built around their developmental needs, on top of existing parental controls, under-18 policies and age assurance. The blueprint's closing argument is that safety should not rest primarily on young people or their families, and that protections belong in products from the outset.
In short: OpenAI published a six-pillar youth safety policy roadmap aimed at the Australian policy landscape, alongside the August rollout of ChatGPT for Teens in Australia.
What it means for your business: If you operate in Australia or serve customers under 18 anywhere, age assurance is quietly becoming a compliance requirement rather than a nice-to-have. Vendor blueprints like this one tend to arrive shortly before the regulation they are trying to shape.
My take: Reading this as pure policy positioning would be too cynical, and reading it as a safety milestone would be too generous. It is a company publishing the rules it would like to be judged against, in a market that is about to write rules anyway. The genuinely useful part for anyone outside Australia is the six pillars themselves, which are a reasonable checklist for evaluating any AI tool you might put in front of a minor, whatever the vendor.
Source: Introducing the Australian Youth Safety Blueprint, OpenAI, September 18, 2026
🛡️ IT and security
A critical Orkes Conductor flaw is under active attack
Fortinet reported active in-the-wild exploitation of CVE-2026-58138, an unauthenticated remote code execution flaw in the Orkes Conductor workflow platform, scored 9.8 on CVSS v3.1 and 9.3 on CVSS v4. Per the National Vulnerability Database, versions from 3.21.21 up to but not including 3.30.2 let remote attackers run arbitrary operating system commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint before authenticating. The mechanism is unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true), reachable through INLINE, LAMBDA, DO_WHILE and SWITCH task types.
The activity is real and rising. Fortinet blocked 1,290 attack attempts in the 24 hours to September 9, a 132% jump in daily activity, and nearly 7,000 attempts between September 2 and 9, with traffic originating from Germany, Hong Kong, Indonesia, the UAE and India. Previdian logged three attempts against its honeypots since July 24 from two IPs in France and the US, and Empirical Security observed exploitation as recently as August 21. "Because vulnerable evaluators can be configured with unrestricted host access, the attacker can escape the intended scripting environment and execute arbitrary operating system commands with the privileges of the Conductor process," Fortinet wrote. The fix is Conductor 3.30.2 or later; short of that, restrict external access to workflow API endpoints and watch for unusual workflow submissions.
In short: CVE-2026-58138, a 9.8-rated pre-authentication remote code execution flaw in Orkes Conductor, is being actively exploited, with Fortinet blocking nearly 7,000 attempts in a single week.
What it means for your business: Conductor is orchestration plumbing, so if you run it you probably inherited it with a platform rather than choosing it. Ask whoever runs your backend whether Conductor is in the stack, whether it is on 3.30.2, and whether its workflow API is reachable from the internet. If the answer to the last one is yes, that is the first thing to change.
My take: The pattern here is one of the most reliable in security: a flexible scripting feature, configured for convenience with unrestricted host access, turns into remote code execution the moment it faces the internet. Nothing about this is exotic. What makes it urgent is that the exploitation is confirmed by three separate sources and the daily volume more than doubled in a week, which usually means someone has automated it and is spraying.
Source: Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild, The Hacker News, September 19, 2026
A rough weekend for the Linux kernel
CISA added three Linux kernel flaws to its Known Exploited Vulnerabilities catalog on Friday, citing evidence of active exploitation: CVE-2025-39682 (9.8), an improper check in the TLS receive path allowing memory disclosure or denial of service; CVE-2026-53266 (8.8), an out-of-bounds write in the ebtables SNAT ARP rewrite path allowing denial of service or local privilege escalation; and CVE-2025-39964 (7.8), a race condition on concurrent writes to the same AF_ALG socket that can crash a system or corrupt cryptographic operations. Red Hat updated all three advisories on September 19 to acknowledge active exploitation, calling one "high risk" with "known public exploits" and advising organizations to "address this vulnerability with high priority." Under CISA's BOD 26-04, federal civilian agencies were recommended to apply fixes by September 21. How the three are being exploited, and whether they form a single chain, has not been disclosed.
Separately, on September 18, researcher Asim Manizada published working exploit code for four other Linux kernel flaws that each grant local root: DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) and DiagSpill (CVE-2026-74469). He reported them in mid-July and held publication until distributions shipped fixes, so a current kernel is not affected. The fixed stable releases carrying all four are 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.109, 6.18.50 and 7.2.4. Three of the four need unprivileged user namespaces, which can be disabled as a stopgap; DiagSpill does not, requiring only that the SCTP module be available. There are no reports of the four being used in real attacks. One detail worth noting: Manizada found them with AI-assisted tooling, and the kernel fix commit for DirtyAH6 carries an "Assisted-by" line crediting it.
In short: CISA added three actively exploited Linux kernel flaws to its KEV catalog on September 19, and a researcher separately published working local-root exploits for four more the day before.
What it means for your business: All of these need a foothold on the machine first, so this is a second-stage problem rather than a front-door one. If you run Linux servers, or rent them from someone, the question is simply whether the kernel is current and when it was last rebooted, because kernel patches do not take effect until it is.
My take: The half of this that will get less attention is the AI credit line in a Linux kernel commit. We have spent months covering AI being used to attack software, and here is the same capability pointed the other way, with the maintainers acknowledging it in the changelog. That is a genuinely good development and it also means the discovery rate on both sides is about to climb. The patch treadmill is not going to get slower.
Source: CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild, The Hacker News, September 19, 2026
Microsoft patched a perfect-10 flaw in Azure AI Foundry
Microsoft fixed CVE-2026-85889, a maximum-severity CVSS 10.0 flaw in Azure AI Foundry, the enterprise platform for building and running generative AI applications and agents. In Microsoft's words, "missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network." Security researcher Rémy Marot was credited with reporting it. There is no evidence it was exploited, and because it is a cloud-side fix, no customer action is required.
It arrived with company. Microsoft also patched CVE-2026-85885 (9.9), a command injection flaw in Microsoft 365 Copilot; CVE-2026-85878 (9.9), improper authorization in Azure Database for PostgreSQL; and CVE-2026-87701 (9.6) in Azure Cosmos DB, all of which require an already-authorized attacker. An out-of-band Windows 11 26H1 update, KB5129194, fixed two local elevation flaws: CVE-2026-62721 (7.8) in the Windows User-Mode Power Service and CVE-2026-85921 (8.2), a double free in Secure Kernel Mode. This lands the week after Microsoft's record 974-flaw patch release, two of which are under active exploitation, with the Windows ALPC flaw chained to two Chrome flaws in an exploit kit called BlueMoon used by multiple espionage-aligned actors, per Proofpoint and Volexity.
In short: Microsoft patched CVE-2026-85889, a CVSS 10.0 missing-authentication flaw in Azure AI Foundry, along with three other critical cloud flaws, with no customer action required.
What it means for your business: Nothing to do here, which is the point worth internalizing. Your cloud provider silently fixed a perfect-10 in the platform some of your AI vendors build on, and you found out afterward. That is the deal with managed services, and it is mostly a good deal, but it is worth knowing which of your suppliers sit on top of Foundry.
My take: A 10.0 that needs no authentication in the platform enterprises are told to build their agents on is a bad look, and Microsoft handling it server-side with no customer action is the system working as designed. The number that actually worries me is 974 flaws in one patch release, two already exploited. Volume at that scale means defenders are triaging on gut feel, and BlueMoon chaining a Windows flaw with two Chrome flaws is exactly what an attacker does with a backlog that big.
Source: Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation, The Hacker News, September 18, 2026
SolarWinds patched a hard-coded key in Access Rights Manager
SolarWinds released a fix for CVE-2026-28326, an 8.8-rated flaw in Access Rights Manager that allows unauthenticated remote code execution. In its September 17 advisory the company said the issue "stems from a hard-coded static key," and it affects all versions of Access Rights Manager 2026.2 and earlier. The fix is ARM 2026.2.1. Armadin researcher Kai Huang was credited with the discovery, and SolarWinds makes no mention of exploitation in the wild.
Access Rights Manager is a tool for auditing and managing who has access to what across Active Directory, file servers and SharePoint, which makes it an unusually attractive target: it holds a map of permissions across the environment. The company has had a busy quarter. Roughly two months ago it shipped fixes for CVE-2026-28323 (9.8), a SAML authentication bypass in Web Help Desk when SAML 2.0 is enabled, and CVE-2026-28299 (8.2), a denial of service in the same product, along with 16 flaws in Serv-U leading to privilege escalation, remote code execution and administrator account creation.
In short: SolarWinds patched CVE-2026-28326, an 8.8-rated unauthenticated remote code execution flaw in Access Rights Manager caused by a hard-coded static key, fixed in version 2026.2.1.
What it means for your business: If your IT provider uses SolarWinds ARM to manage permissions in your environment, this is a reasonable thing to ask them about by name this week. A hard-coded key means the same secret ships to every customer, so once it is known there is nothing left to guess.
My take: Hard-coded static keys in 2026, in a product whose entire job is controlling access, is the kind of finding that makes you want to see the rest of the codebase. To be fair to SolarWinds, there is no sign of exploitation and the fix is out. But a tool that inventories permissions across Active Directory is precisely what an attacker would most like to own, because it hands over the map before the first move.
Source: SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE, The Hacker News, September 19, 2026
CrowdSec says 170 of its private repositories were copied
French security company CrowdSec disclosed on September 18 that roughly 170 of its private GitHub repositories were copied on May 22, using a GitHub OAuth token belonging to an employee who had just left and whose access had been kept open so he could finish work. CrowdSec removed the account from its GitHub organization on May 25, three days later. The company traces the compromise to May's TanStack npm supply chain attack, tracked as CVE-2026-45321, in which 84 malicious versions of 42 TanStack packages were published on May 11 and stole GitHub tokens, SSH keys and cloud credentials from developers' machines. The copied code surfaced on an online forum on September 16, alongside the email addresses of 83 CrowdSec users and the names, email addresses and investment context of 51 potential investors from 2020.
CrowdSec says the account was used only to copy code, that its infrastructure and databases were not accessed and nothing was changed, and that it rotated credentials on September 16 and 17. The only usable credential found was an AWS SNS key limited to publishing to a single topic; someone tried it on August 17 and got no further. The company says blocklist poisoning remains infeasible despite the leak of previously non-public thresholds in its consensus algorithm. Worth reading carefully: the account of what happened changed between Wednesday and Thursday. CrowdSec's first statement blamed a backdoored component used internally that stole an API key and said no user data leaked; the fuller report the next day pointed to the former employee's account instead and did list 83 user emails and investor names. CEO Philippe Humeau wrote to investors, "for this I personally apologize." The same attack also reached Mistral AI, which said a developer device was involved, and OpenAI, which said two employee devices were affected with unauthorized access to a limited set of internal code repositories.
In short: CrowdSec disclosed that about 170 of its private GitHub repositories were copied in May through a departing employee's still-active token, compromised in the TanStack npm supply chain attack, with the code published online on September 16.
What it means for your business: Two lessons, both dull and both cheap. Revoke access on someone's last day rather than when it is convenient, including tokens and OAuth grants, which survive a disabled password. And accept that a developer laptop is a credential store: one bad package install in May became a data leak in September.
My take: The four-month gap between the theft and the code appearing is the detail to sit with. CrowdSec did not know until it was published, and neither would most companies. I also want to be fair about the changed story: the first statement was wrong in ways that flattered them, and the second, more complete one came out a day later and contradicted it. Correcting yourself publicly in twenty-four hours is better behavior than most breach disclosures manage, and it is still a reminder to treat day-one incident statements as provisional.
Source: CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories, The Hacker News, September 19, 2026
A new WordPress flaw installs a theme with nobody clicking Install
WordPress shipped 7.1.1 on September 17 to fix a flaw that lets a crafted link, opened by a logged-in administrator, install a theme from the official WordPress.org directory without anyone clicking Install. The security firm pwn.ai, which reported it, calls the chain Click2Shell. The mechanism is a mismatch: WordPress.org treats the value in the URL as an ordinary theme name and returns a real theme, while the administrator's browser reuses the original text verbatim inside code meant to select a page element. Characters added by the attacker redirect that code to the Install button, and WordPress's own script clicks it. The admin's active session supplies both the permission and the security token.
On its own the flaw only installs a real, attacker-chosen theme from the official directory, and the theme stays switched off, so nothing about the site looks wrong. pwn.ai rated that alone high at CVSS 7.1. The critical rating of 9.6 comes from the chain: the WordPress Customizer can load a theme's PHP before activation, and the researchers found a theme, Mobile Repair Zone, whose background handler fetched a URL from the request, downloaded a package and ran its code with no permission or nonce check, producing code execution on the server. WordPress described it in the release as "specially crafted URLs can automatically install and preview an inactive theme from WordPress.org." No CVE has been assigned yet, though pwn.ai says one is planned. There is no sign of real-world exploitation, no workaround, and the attack still needs a logged-in admin to open the link.
In short: WordPress 7.1.1 fixed a flaw, named Click2Shell by pwn.ai, that lets a crafted link opened by a logged-in admin silently install a WordPress.org theme, which can be chained with a flawed theme to run code on the server.
What it means for your business: If your site runs WordPress, confirm it is on 7.1.1. Sites with automatic updates enabled already have it; sites where someone turned updates off because a plugin broke once are the ones to check. And the trigger is an admin clicking a link while logged in, which is worth mentioning to whoever holds the admin account.
My take: The clever, unsettling part is that the site gives no sign anything happened. The theme installs, stays inactive, and the site looks completely normal. That is a foothold with no symptom, which is the kind attackers like most. This is the second pwn.ai WordPress login-adjacent chain in about a month, and the fact that no CVE exists yet means automated inventory tools will not flag your site as vulnerable. Version number, not scanner.
Source: New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution, The Hacker News, September 18, 2026
🧰 New tooling for builders and everyday AI use
Four AI coding agents can be tricked into installing the wrong plugin
Security firm Air Security disclosed on Thursday a flaw it calls Plugin4Shell, affecting four widely used AI coding agents: Anthropic's Claude Code, OpenAI's Codex, GitHub Copilot and Google's Gemini CLI. Marketplaces lock each plugin to a single reviewed version by its commit hash, a string identifying an exact snapshot of the code. Air found the agents fetch that snapshot but never verify the code they end up with actually matches it. On a code host that allows a branch name shaped like a commit hash, the owner of a plugin's repository can point that name at different code, and the agent installs it while still reporting the locked version. Because a plugin runs with the same access as the person using the agent, swapped code can reach that person's files, saved credentials and any system they can log into.
The scope is narrower than the headline suggests, and the detail matters. GitHub does not permit branch or tag names that look like commit hashes, so plugins installed from GitHub are not exposed to the branch trick, and The Hacker News checked on September 18 that every plugin in Anthropic's community catalog and in the default Claude Code and Copilot catalogs points to a GitHub repository. The risk sits with plugins from other hosts, such as Bitbucket or a company's own git server. Background auto-update, which would make the attack require nothing from the victim, runs by default only for the agents' own GitHub-hosted marketplaces. Air says Anthropic fixed it in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, that GitHub Copilot has no fix, and that Google will not patch the Gemini CLI, which it is retiring in favor of Antigravity. Air built a working test attack in May and told the vendors in June; as of September 18 there was no CVE, no vendor advisory, and no sign of real-world use.
In short: Air Security disclosed a flaw letting a plugin repository owner swap the code an AI coding agent installs despite a version lock, fixed in Claude Code 2.1.179 and Codex 0.146.0 and unpatched in Copilot and the retiring Gemini CLI.
What it means for your business: If anyone on your team uses AI coding agents, update Claude Code and Codex, and take a minute to check whether any installed plugin comes from somewhere other than GitHub. If you only ever install from the default marketplaces, you were not exposed to the main version of this.
My take: This is the most useful story of the weekend for anyone building with AI, and it deserves a careful read rather than a panic. The vendors get real credit for narrowing it, and The Hacker News checking the catalogs itself is the kind of verification that makes a disclosure trustworthy. What lingers is the shape of the thing: a version lock that was never actually enforced, which means everyone auditing plugin versions has been auditing a label rather than the contents. That the fix has to ship in each agent, because no marketplace can fix it for you, is the part to remember next time a vendor tells you the marketplace is reviewed.
Source: Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents, The Hacker News, September 18, 2026
An npm stealer was probably written by a chatbot
CrowdStrike's Counter Adversary Operations published an analysis linking a financially motivated actor to PhantomRaven, a JavaScript information stealer distributed through the npm package registry, and assessed with high confidence that the developer likely wrote the malware using a large language model. The evidence is the sort of thing that will feel familiar to anyone who reviews AI-written code: verbose comments, leftover placeholder code, and statistical token-analysis patterns. PhantomRaven was first flagged by Koi Security and DCODX in late October 2025 in a slopsquatting and typosquatting campaign that pushed more than 100 malicious packages to npm, targeting authentication tokens, CI/CD secrets and GitHub credentials. It hides by fetching a remote dynamic dependency from an external server, so the published package itself looks clean to scanners. On install, the remote code harvests email addresses from Git and npm configs, system fingerprints including public IP, and CI/CD environment variables for GitHub Actions, GitLab CI, Jenkins and CircleCI.
The motive is the strange part. CrowdStrike says the actor has been active since November 2022 and claims to be a bug bounty hunter who has collected bounties from no fewer than nine organizations across technology, retail and hospitality. The firm's read is that "the operator likely uses the information stealer solely to identify bug bounty opportunities," having "developed their proprietary PhantomRaven to compromise company assets and then used these compromises as leverage to claim rewards from reputable disclosure programs." That inference rests partly on absence of evidence: CrowdStrike says it has not seen the stolen information turn up on stealer log shops. At least two npm accounts pushed the packages, both now inaccessible, and there is evidence of attempts to push similar stealers to PyPI. No victims are named and no confirmed real-world compromise outcomes are reported.
In short: CrowdStrike assessed with high confidence that the PhantomRaven npm stealer was likely written with a large language model, by an actor who claims to be a bug bounty hunter collecting rewards from companies it compromised.
What it means for your business: The practical control has not changed: whoever installs packages on your behalf should pin versions, review what gets added, and treat build servers as systems that hold live credentials. The newer wrinkle is that "this code looks amateur" no longer means "this code is harmless."
My take: Two things here are worth separating. The LLM authorship is an assessment rather than proof, and I would hold it loosely, though the tells CrowdStrike describes are plausible. The motive claim is the genuinely odd one: breaking into companies with malware and then presenting the access as a bug bounty finding is not research, whatever the actor calls it, and it is built on an absence of evidence rather than positive proof. What I take from it is the low floor. Building a working, evasive credential stealer used to take skill; this one apparently took a chatbot and some patience.
Source: Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer, The Hacker News, September 18, 2026
Missed Friday? Catch up with the September 18, 2026 AI and IT news recap.