Weekly cyber roundup: AWS credentials abused for LLMjacking, OAuth survives password resets
TechNadu · x · 2026-09-05
TechNadu's weekly cybersecurity roundup covers seven stories:
- OAuth access tokens surviving password resets, enabling account persistence
- PaperCut attackers moving deeper into networks
- AWS credentials used for LLMjacking, hijacking cloud compute to access LLM services
- Sality botnet disrupted after 20+ years of activity
- First federal juvenile case tied to the 764 network
- Plus C-Track and ATM jackpotting incidents
LLMjacking highlights an emerging attack surface on AI infrastructure.
More from Safety
- OpenAI spotted a similar agent swarm weeks before the HF hack but didn't disclose it — zacharynado · 2026-09-06
- Student questions for Mitchell: can bounded autonomy know when humans must step in? — ruthstarkman · 2026-09-06
- Finland Appoints Expert Group on AI's Foreign and Security Policy Implications — soumitrashukla9 · 2026-09-06
- Jack Clark on post-HF alignment: build communication infra for agents, things go sideways fast — jackclarkSF · 2026-09-06
- DeepMind paper shows cheating spreading like an epidemic across ~100 AI agents — jackclarkSF · 2026-09-06
- Tyler Alterman: Hold AI companies legally liable for crimes their AIs commit — sebpaquet · 2026-09-06