Cyber News / Article / ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More

⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
The boring parts caused most of the trouble.
A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional.
Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept things moving. Different attacks, same useful mistake: something familiar was trusted without a second look.
Here is the week...
U.S. Disrupts Chinese Proxy Network Enabling Cyber Espionage— The U.S. Federal Bureau of Investigation (FBI) disrupted infrastructure associated with a technical quartermaster who sold reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities. The QTYF group is said to have created and operated the QScan and QTRouter frameworks, which have been used to target U.S. critical infrastructure networks. It's employed by the China-based Nanjing Xinjiuwei Network Technology Company.
Spiking AI bills have left IT teams scrambling. Leadership wants to know how much is being spent on AI, but getting an answer means checking five dashboards for data that’s stale by the time you read it. Read 1Password’s blog to learn how IT can manage AI spend across vendors, models, and teams.
Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.
Check the list, patch what you have, and hit the ones marked urgent first — FromCVE-2025-30237 through CVE-2025-30241,CVE-2025-15628, CVE-2026-9254, CVE-2026-16348, CVE-2026-78541(TP-Link),CVE-2026-17106aka CopyEscape (Docker),CVE-2026-70426(Jenkins),CVE-2026-15307, CVE-2026-15337, CVE-2026-15830, CVE-2026-15920(Django),CVE-2026-19598(Pods),CVE-2026-19874(Konami Metal Gear Online 3),CVE-2026-75149, CVE-2026-67618(Marimo),CVE-2026-77775, CVE-2026-77776(Headroom LLM Proxy),CVE-2026-0251(Palo Alto Networks GlobalProtect App),CVE-2026-59568, CVE-2026-59567, CVE-2026-59565(Zscaler Client Connector),CVE-2026-69251,CVE-2026-73601,CVE-2026-69253,CVE-2026-69256,CVE-2026-73602,CVE-2026-69259,CVE-2026-69264,CVE-2026-73484,CVE-2026-69255,CVE-2026-70477,CVE-2026-73485,CVE-2026-73486,CVE-2026-73487,CVE-2026-70470,CVE-2026-69254(Flowise),CVE-2026-19912, CVE-2026-19913(Kaltura HTML5 Player Library),CVE-2026-79282, CVE-2026-79290, CVE-2026-79054, CVE-2026-79121, CVE-2026-79224, CVE-2026-79052, CVE-2026-79150, CVE-2026-78935, CVE-2026-79012, CVE-2026-79200(Google Chrome),CVE-2026-77537, CVE-2026-77550, CVE-2026-77554(Ubiquiti UniFi),CVE-2026-18431(Avada WordPress theme),CVE-2026-7791(Amazon Skylight Workspace Config Service),CVE-2026-73554(DoltHub),CVE-2026-19516(Grafana MCP),CVE-2026-75604,GHSA-2xp9-vwfh-vxw4(Next.js),CVE-2026-65643(cPanel and WebHost Manager),CVE-2026-76639, CVE-2026-76640(Unitree G1 EDU),CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820(ServiceNow AI Platform).
The useful lesson is not that every attack became smarter. It is that more of them arrived through things already trusted: shipped devices, familiar prompts, support tools, valid access, and systems meant to protect the network.
That changes the question. “Is it working?” is no longer enough. Ask what else it can do, who else can reach it, and whether the evidence it produces can be trusted. Quiet systems deserve a second look.
Related articles
ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
8 days ago
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
9 days ago
Hackers Use Popular Messaging Services to Control New Windows Backdoors
7 days ago
You might Also like

IDScan sued over alleged data breach affecting 153 million drivers

Microsoft Unveils Project Zenith Windows PCs That Can Run 30B+ AI Models Locally

