HackMyIP
← Back to News
2026-08-07 SecurityWeek

AI Slop Overwhelms Apple Bug Bounty as QuickFox VPN Supply Chain Attack Drops FDMTP Implant

AI ThreatsSupply ChainBug Bounty

OpenAI has banned a coordinated set of ChatGPT accounts tied to a Cambodia-based scam operation that weaponized the model to run investment, romance, gambling, and law enforcement impersonation schemes. The network generated fake personas, translated messages, created promotional images, and forged official documents to defraud victims. Separately, Amgen confirmed unauthorized access to data stored in third-party cloud environments, detected in July 2026, with proprietary information and patient protected health information confirmed exfiltrated. The pharmaceutical giant reported no impact on products, manufacturing, financial systems, or patient care, though notifications are still pending. Users concerned about credential exposure can verify their accounts using the email breach checker.

Apple has quietly capped the number of vulnerability submissions researchers can file through its bug bounty program after a surge of low-quality, AI-hallucinated reports buried legitimate findings. Cybersecurity firm Bynario hit the new ceiling after using ChatGPT to surface more than 50 macOS issues, including a privilege-escalation exploit it could not immediately report. While researchers can request higher limits, Apple has begun deploying its own AI to triage incoming submissions. The episode underscores how generative AI is reshaping both offense and defense across the vulnerability disclosure pipeline.

A long-running supply chain compromise of the QuickFox VPN and game-accelerator app delivered a trojanized Electron installer that executed a JavaScript loader and ultimately deployed the FDMTP implant on Windows systems. The loader used process-based guardrails to avoid Steam users while preferring endpoints running development, database, or crypto tools before fetching the next stage. QuickFox removed the malicious components after Fortinet's disclosure. Users of consumer VPNs should validate their traffic routing with a DNS leak test and the VPN/proxy detector to confirm requests are not bypassing their tunnel. Multiple Zbtlink router models have also been found shipping with a built-in backdoor, while the FCC is drafting rules that would block imports of new Chinese optical transceivers used inside hyperscale data centers to limit data theft and malware risks in AI infrastructure.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →