ThreatsDay Roundup: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + More

This week’s security news has a common thread. Everything looks fine until someone checks the edges.

Browsers, bots, sandboxes, AI systems, email — they all have the same problem in different forms. Small permissions left open. Weak checks not tested. Tools doing exactly what they were allowed to do.

Here’s what’s worth knowing.

Sandbox root escape on Claude Cowork. Armadin found an attack chain affecting Claude Cowork on Windows. An attacker with local code execution can plant a malicious file in Claude Desktop’s app directory, then hijack a trusted process to get root inside the sandbox — with no network egress restrictions. Anthropic said it’s not a security issue because you’d need local execution first. Fair enough, but it’s a reminder that “local access required” doesn’t mean safe.

Apple Hide My Email flaw still unpatched. Researcher Tyler Murphy disclosed that Apple’s email privacy feature can be bypassed to reveal users’ real addresses. He reported it over a year ago. Still no fix. In limited testing, 100% of addresses were exploitable. Apple has not commented.

BlueHammer and the phishing wave. A campaign targeting small businesses across Europe, Asia, the Middle East, and the US uses fake law enforcement emails with password-protected archives hosted on Proton Drive. Bitdefender says the payload is a custom ransomware, not a known family.

China-linked BeepRAT. Rubrik Zero Labs found a customized DCRat variant called BeepRAT, distributed inside a Chinese phone number management tool. It establishes persistence via scheduled tasks, uses DNS-over-HTTPS for C2, and can record webcams, log keystrokes, and run .NET assemblies in memory.

Platform-aware phishing is the new normal. Cofense reports attackers are fingerprinting victims by User-Agent and serving different payloads per OS: malware on Windows, credential harvesters on Mac and Android. It’s not one-size-fits-all anymore.

Opera fights clipboard attacks. Opera launched Paste Protect to block ClickFix-style attacks. ClickFix accounted for over 53% of malware loader activity in 2025, per Huntress, and remains the dominant delivery method in 2026.

FTC fined Amazon $2.25 million for refusing identity theft victims access to their own transaction records, citing “security” reasons. The FTC called the practice “Kafkaesque.”

Millennium RAT went native. Group-IB reports the malware shifted from .NET to C++ but kept Telegram Bot API for C2. It’s sold as MaaS for $50/month.

References