AI Korean Bank Breaches, Poem-Guided Botnet, Empire Admin 40 Years
SecurityWeek’s weekly cybersecurity news roundup provides a comprehensive overview of critical developments shaping the threat landscape.
PoeLLM Malware and GitHub Poem C&C
Black Lotus Labs reports that a novel malware variant, PoeLLM, has been identified as leveraging a GitHub-hosted poem to conceal its command-and-control (C&C) infrastructure. This malware, active since at least April 2026, targets open-source AI services such as LiteLLM, Ollama, Gotenberg, and Gitea to mine cryptocurrency and expand its botnet. The malicious payload extracts four keywords from a GitHub poem, which are then converted into the IP address of the current C&C server. This method allows the operator, believed to be Italian-speaking, to dynamically switch servers by modifying the poem’s content. The poem has been updated 11 times since its deployment.
GhostAction Supply Chain Campaign
GitGuardian revealing that secret-stealing GitHub Actions workflows were deployed to 772 public repositories between August 31 and September 30. The attack, which targeted 2,577 secrets including SSH keys and cloud credentials, reused tactics from a 2025 campaign. A new exfiltration server was introduced, but the operation has persisted without interruption.
Jonathan Spalletta Conviction
A Maryland resident, Jonathan Spalletta, has been convicted of orchestrating two 2021 hacks of the decentralized crypto exchange Uranium Finance. By exploiting smart contract vulnerabilities, he stole approximately $1.4 million and $53.3 million, leading to the platform’s collapse. The stolen funds were laundered through crypto transactions, including Tornado Cash, and used to purchase collectibles such as rare gaming cards and historical artifacts. Spalletta faces up to 10 years for fraud and 20 years for money laundering.
CISA Cybersecurity Retention Incentive Program
The Cybersecurity and Infrastructure Security Agency (CISA) has revised its Cybersecurity Retention Incentive program, extending it through fiscal 2027. New criteria require participants to maintain an “exceeds expectations” performance rating and dedicate at least 51% of their time to cybersecurity roles within specified job series. Employees outside these series may apply for exceptions if they spend 75% or more of their time on cyber duties. The changes follow a Department of Homeland Security audit that highlighted mismanagement and overreach in the original program.
OTCC CISA Directive Proposal
The Operational Technology Cybersecurity Coalition (OTCC) has proposed a CISA directive to address operational technology (OT) security at federal civilian agencies. The plan emphasizes designating senior officials to oversee OT security, applying existing cybersecurity requirements, and prioritizing CISA’s Cybersecurity Performance Goals. Federal agencies managing over 8,000 GSA facilities, including HVAC and power systems, would be subject to these measures.
Domino’s Credential Stuffing Incident
Domino’s has notified a small group of customers that their accounts were compromised through credential stuffing attacks using leaked username-password pairs. The company confirmed its systems were not breached and does not store payment information, but it has reset affected accounts to mitigate risks.
South Korea’s AI-Related Bank Cyberattacks
South Korean authorities are investigating the use of artificial intelligence in recent bank cyberattacks, though details remain limited. President Lee Jae Myung noted signs that AI tools may have been involved in breaches exposing customer data.
CrowdStrike Analysis of Threat Actor
CrowdStrike’s analysis of the attack infrastructure revealed evidence of a Chinese-speaking threat actor, including Claude Code session histories and ARTEX configuration files.
Raheim Hamilton’s Sentence
Raheim Hamilton, co-founder of the dark web marketplace Empire Market, has received a 40-year prison sentence and a $5 million fine. The platform, operational from 2018 to 2020, facilitated over four million transactions valued at more than $430 million, primarily involving narcotics and stolen data. His co-founder, Thomas Pavey, is set to be sentenced later this month.
CVE-2026-47483 Vulnerability
A critical vulnerability, CVE-2026-47483, has been disclosed in Nvidia’s DCGM Exporter GPU monitoring tool. The flaw allows unauthenticated attackers to overwhelm profiling endpoints, causing service disruptions that could impact AI workloads. Researchers identified approximately 2,100 internet-exposed hosts running the tool, leaking telemetry from over 12,000 GPUs. Nvidia has released patches in version 4.8.2.
Credential-Stealing Worm in Tensorlake SDK
A credential-stealing worm was embedded in a compromised version of the Tensorlake npm SDK, according to Socket and Sonatype. The malware, linked to a ChainDrop/Shai-Hulud supply chain attack, harvests credentials from npm, GitHub, AWS, Kubernetes, and Vault, as well as AI coding tool configurations. It can execute attacker-provided code and propagate through other packages.
Additional Cybersecurity Developments
Additional developments include the discovery of $15,000 in iCloud spoofing vulnerabilities, phishing attacks targeting AI policy experts, and a browser extension spying on AI chat interactions. New cybersecurity startups, such as Osavul and RemoteThreat, have secured significant funding to address emerging threats. CISA’s ongoing efforts to strengthen OT security, coupled with the proliferation of AI-driven attacks, underscore the evolving challenges facing organizations. As threat actors increasingly exploit supply chains and advanced technologies, enterprises must prioritize robust defense strategies and continuous monitoring.
