ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories
A security roundup covers Cisco patching an SSRF flaw, sanctions on Nobitex, and several active malware and forum abuse trends.
Intelligence analysis by GPT-5.4 Mini

This ThreatsDay bulletin stitches together multiple security developments: a Cisco Unified CM flaw with PoC code available, claims of mobile spyware targeting Russian officials, VIP Keylogger delivery chains, U.S. sanctions on Nobitex, forum fragmentation after the XSS takedown, Tiflux abuse, and DriveSurge malware campaigns.
This story is like a report card for cyber trouble: some computers have a broken lock that needs fixing, some bad guys are hiding malware inside fake work messages, and criminal hangouts are splitting into smaller groups. It shows defenders trying to patch holes while attackers keep finding new tricks.
Analysis
Overview
This bulletin is a broad snapshot of the current threat landscape, framed as a mix of old problems in new packaging. The opening tone emphasizes that attackers are using bad plugins, outdated bugs, fake tools, and trusted apps to do shady things, while defenders are left to keep up.
Notable items
Cisco said it fixed a high-severity flaw in Unified Communications Manager, tracked as CVE-2026-20230 with a CVSS score of 8.6. The issue affects Unified CM and Unified CM SME Release 14SU6 and 15SU5, and Cisco said proof-of-concept exploit code is already available, though it has not seen active exploitation. The company described the bug as an SSRF issue caused by improper input validation for specific HTTP requests.
The bulletin also covers a claim by Russia’s FSB that foreign intelligence services carried out a large-scale operation to implant spyware on mobile devices used by high-ranking officials. According to the FSB, the spyware was used to exfiltrate data, intercept conversations, and enable covert audio and video surveillance.
On the malware front, Splunk said VIP Keylogger is being distributed through loaders written in JavaScript, batch scripts, and VBS, often disguised as business messages such as payment notices, procurement orders, and logistics updates. Huntress separately reported a surge in abuse of Tiflux, a lesser-known remote desktop tool, with attackers using it for persistence, screenshots, command execution, and system profiling. The same incidents also involved UltraVNC, sideloaded commercial RMM tools like Splashtop and ScreenConnect, and an outdated driver that could help privilege escalation.
The bulletin further notes that the July 2025 takedown of the Russian-speaking XSS forum did not end the ecosystem; Flashpoint says it fractured it into competing factions and new, less trusted communities. Finally, a cluster called DriveSurge is linked to large-scale malware distribution through ClickFix and FakeUpdates-style social engineering on compromised sites.
Key points
- Cisco patched a high-severity SSRF flaw in Unified Communications Manager and said PoC exploit code exists.
- The FSB claims foreign intelligence services used spyware against Russian officials, but it did not name the operators.
- VIP Keylogger is being spread through social engineering using JavaScript, batch, and VBS loaders.
- OFAC sanctioned Nobitex and several related exchanges over alleged support for terrorist activity and sanctions evasion.
- The XSS forum takedown appears to have fractured the cybercrime scene rather than dismantled it.
Cisco’s fix for the Unified CM flaw gives defenders a concrete patch path before the bug appears to be widely exploited. The sanctions on Nobitex and the reporting on abuse patterns may also help investigators and security teams spot risky infrastructure and delivery tricks sooner.
The availability of proof-of-concept code raises the chance that the Cisco flaw could be exploited later, even if it is not active now. The fragmentation of criminal forums and the use of trusted remote access tools suggest attackers are getting harder to track, not easier.



