VYPR
trendPublished Oct 9, 2026· 1 source

AI-Controlled Botnet, Dark Web Marketplace Admin Sentenced, and Supply Chain Attacks Highlighted in Security News Roundup

A weekly cybersecurity news roundup covers a novel AI-driven botnet, the sentencing of an Empire Market co-founder, and ongoing supply chain threats including a compromised npm SDK.

SecurityWeek's latest cybersecurity news roundup sheds light on a diverse array of threats and legal developments, from innovative malware control methods to significant legal repercussions for dark web operators and persistent supply chain vulnerabilities.

One of the most intriguing developments is the emergence of PoeLLM, a malware strain identified by Black Lotus Labs that has been actively targeting exposed AI and open-source services since at least April 2026. PoeLLM leverages a unique command-and-control (C2) mechanism, embedding the C2 server's IP address within a poem hosted on GitHub. Threat actors can alter the C2 by simply changing keywords within the poem, demonstrating a novel approach to maintaining operational resilience and evading detection. The operator, believed to be Italian-speaking, has updated the poem multiple times, indicating ongoing activity and adaptation.

In a significant legal development, Raheim Hamilton, a co-founder of the notorious dark web marketplace Empire Market, has been sentenced to 40 years in prison and fined $5 million. Hamilton pleaded guilty to a drug conspiracy charge related to his role in operating the marketplace from 2018 to 2020. Empire Market facilitated over four million transactions, totaling more than $430 million, primarily in drug sales, but also dealing in stolen credentials, personal information, counterfeit currency, and hacking tools. His co-founder, Thomas Pavey, is awaiting sentencing.

Supply chain attacks continue to pose a persistent threat, with GitGuardian reporting that the GhostAction campaign has expanded its reach. The secret-stealing GitHub Actions workflow has been pushed to an additional 772 public repositories, impacting 373 users and organizations between August and September 2026. The campaign targeted over 2,500 secrets, including SSH keys and cloud credentials, and the attacker has reused previous tactics while introducing a new exfiltration server, suggesting the campaign has been ongoing without significant interruption.

Further compounding supply chain concerns, version 0.5.144 of tensorlake's npm SDK was compromised. This malicious version contained a credential-stealing worm designed to execute during the installation process, a tactic described by Socket as a ChainDrop/Shai-Hulud-style supply chain attack. This incident highlights the ongoing risks associated with third-party code dependencies, particularly in the rapidly evolving AI development ecosystem.

In other news, a jury convicted Jonathan Spalletta for his role in two 2021 hacks of the decentralized crypto exchange Uranium Finance, where he stole approximately $54.7 million by exploiting smart contract flaws. The funds were laundered through Tornado Cash and used to purchase collectibles. Separately, Domino's is notifying a small number of customers about account compromises due to credential stuffing, emphasizing that its own systems were not breached. South Korean authorities are also investigating cyberattacks on banks, with preliminary signs pointing to the use of AI tools and a Chinese-speaking threat actor.

Finally, a high-severity vulnerability, CVE-2026-47483, has been disclosed in Nvidia's DCGM Exporter tool. This flaw allows unauthenticated attackers to crash the GPU monitoring service by overwhelming its profiling endpoints, potentially disrupting AI workloads. Researchers found thousands of internet-exposed instances leaking telemetry data from over 12,000 GPUs. Nvidia has released a patch, urging users to update to version 4.8.2 or later.

These diverse incidents underscore the multifaceted nature of current cybersecurity challenges, encompassing sophisticated malware, persistent supply chain risks, significant legal consequences for cybercriminals, and vulnerabilities in critical infrastructure components like GPU monitoring tools.

Synthesized by Vypr AI