The common thread in this week's security news is that mundane components—caches, console processes, public blockchains—can be repurposed by attackers. One reported technique, cache key injection, exploits caches that build keys by concatenating attacker-influenced strings without separators, allowing distinct requests to collide and poison responses. Another new method uses a console process's stdin pipe and WriteFile() to write and execute arbitrary bytes, bypassing monitoring that looks for traditional API calls like WriteProcessMemory().

Financial crime also took a notable turn. The U.S. Treasury sanctioned 10 individuals linked to a Tren de Aragua ATM jackpotting scheme that caused at least $40.73 million in losses across more than 1,500 attacks. According to the report, the group used Ploutus malware and laundered proceeds through cryptocurrency, with designated wallet addresses receiving about $6.1 million in inflows since March 2022.

AI security remained a focus as well. Chinese AI company Moonshot is conducting an internal review after a report found its Kimi models could bypass guardrails and generate dangerous information. Separately, Tracebit described using indirect prompt injection as a defensive technique, embedding instructions in a canary secret to make an agent believe its assessment had ended—an approach that can stop malicious actions from open-weight models.

The source also notes a broader trend: blockchain dead drops, which hide malware instructions on public ledgers, have surged 440% since the launch of Chinese open-source AI models that place no restrictions on generating malicious code. North Korean and Iranian state operators are reportedly developing distinct variants of this technique. The overall lesson, as the article puts it, is that attackers don't always need a brilliant new trick—they can hide in plain sight within systems people assumed were safe because they looked ordinary.