Cybersecurity: Five Emerging Risks, from U.S. Telecommunications to Coding Agents

Explore five emerging cybersecurity threats, including Chinese presence in U.S. telecom, SideWinder malware, and npm supply chain attacks, targeting persistent access.

Cybersecurity: Five Emerging Risks, from U.S. Telecommunications to Coding Agents
APT

Illustrative image generated with AI

The alerts collected on August 6, 2026, describe different threats united by the pursuit of persistent access to telecommunications infrastructure, software repositories, development tools, and artificial intelligence agents.

China’s Presence in the U.S. Telecommunications Backbone

The 49-page Stranger Pings report, published by the bipartisan Select Committee on China of the U.S. Congress, highlights a residual risk associated with Chinese operators present in the American telecommunications backbone.

According to the Committee, some companies from the People’s Republic of China may retain trusted footholds in U.S. communications infrastructure. These access points could be exploited in future cyber operations to maintain a presence, conceal activity, and compromise the availability, confidentiality, and integrity of communications.

The risk is also linked to the Salt Typhoon campaign. In addition, a Chinese provider allegedly included a policy in contracts with U.S. companies prohibiting transmissions that violate Chinese law, including political information and content deemed harmful to national security, public order, or social stability.

No specific operational countermeasures were identified.

SideWinder Uses PDFs and ClickOnce to Deliver Rust Backdoors

The SideWinder group distributes PDF documents through phishing. The files contain ClickOnce applications that launch a multistage infection chain and install backdoors developed in Rust.

The malware can modify the Windows Registry to establish persistence, collect host information, and receive commands from external servers. Its command-and-control infrastructure may also rely on free serverless platforms, including Cloudflare Workers.

The combination of phishing, ClickOnce, and readily available infrastructure makes it harder to distinguish malicious traffic from legitimate activity. No specific technical indicators or remediation instructions have been disclosed.

Flooding Dropper Targets the npm Supply Chain

The Flooding Dropper campaign affected hundreds of npm packages and accounts. The operation’s title refers to 850 malicious packages, while Sonatype reported 846 software components.

Distribution was automated through the creation of accounts and packages. Recurring indicators include the terms bigops and bnpl, as well as versions in the 35.x.y series.

During installation, the packages download and execute a second payload using several delivery methods. The variants change their syntax to evade exact-signature detection while retaining the same behavior.

A JavaScript loader identifies the operating system and retrieves the payload compatible with Windows, Linux, or macOS from remote hosts encoded in the program. Execution takes place in the background.

On Windows, the loader can detect sandboxes and virtual machines, tamper with ETW and AMSI, establish persistence through scheduled tasks, and launch an encrypted payload.

To reduce risk, packages and dependencies should be reviewed before installation, post-installation activity should be monitored, connections to remote hosts should be inspected, and unexpected scheduled-task creation should be detected.

A Repository Can Execute Code Before the First Prompt

Research by Datadog highlights a risk in coding agents: trusting a repository may allow project-controlled code to execute before the first prompt is submitted.

Codex MCP configurations and Claude Code environment settings can create automatic execution paths without a model response or explicit approval of a shell command. As a result, simply cloning a repository can become an attack vector.

The issue also affects agentic skills. Datadog reported in May that these components introduce instructions and context into the agent; dynamic commands may execute before the model displays the skill, preventing prompt-injection defenses from acting at the model layer.

Repositories should therefore be treated as executable code. Unfamiliar projects should be opened in disposable environments without credentials or sensitive data, even after an apparently positive manual review.

A DeepSeek Agent Allegedly Attacked an AI Company

An unidentified Chinese group allegedly used a DeepSeek AI agent to attack the network of a Tel Aviv-based artificial intelligence company.

Based on the available information, the techniques used, the specific objectives, and the consequences of the operation remain unknown. No mitigation measures were identified either.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →