AI Gateways Expose SSRF Flaws as Ransomware Hunts Cloud Backups

Charm · September 22, 2026 · 2 min read · 6 sources

Threat Intelligence

FBI Warns of Luna Moth Callback Phishing Campaign Resurgence

The FBI has issued a fresh warning against Luna Moth. They are using fake subscription invoices and tech support numbers to get initial access. The callback is the hook, so better train your end users to call IT through official channels.

Qilin Ransomware Targets Linux Environments and ESXi with New Encryptor

Qilin has rolled out a new encryptor specifically targeting Linux Virtual Machine configurations and ESXi. They are moving faster than ever; if your backup server runs on Linux, patch and isolate it immediately.

Ransomware Actors Now Aggressively Wiping Cloud Backups

Ransomware groups are now specifically seeking out and wiping cloud-based backups before encryption starts. They are taking away your safety net first, so you better test your immutable storage policies right now.

Offensive Security

Nuclei Templates Add SSRF Detection for AI Infrastructure

Projectdiscovery merged a new template set allowing scanners to detect Server-Side Request Forgery in AI infrastructure. If you are heavily relying on LLMs, run this to see if your endpoints can be used as a pivot point.

Vulnerability Analysis

Critical SSRF Flaws Expose AI Service Gateways to Internal Networks

Critical SSRF flaws were identified in popular AI service gateways, allowing attackers to pivot into internal networks. This confirms that LLM wrappers are the new perimeter, and it is the weakest one to break right now.

Malware

PumaBot Targets Linux Systems via SSH Brute-Force

PumaBot is a high-volume SSH brute-forcer chaining infected Linux boxes into a bot-net. It validates that weak SSH configs are still the easiest way to build an attack fleet.

Stay Ahead

Delivered each morning.