New Tooling
Permify: Open-Source Authorization As a Service"Permify is an open-source authorization service that answers access questions at run time: can user X view document Y, which posts can members of team Y edit. It keeps those rules in one place, apart from the application code that would otherwise carry them. Permify follows the design of Google Zanzibar, the authorization system Google runs across its own products. Teams reach for something like it when permissions get specific and start nesting inside each other, and when the same rules have to hold across several applications at once."
https://www.helpnetsecurity.com/2026/09/14/permify-open-source-authorization-as-a-service/
https://github.com/Permify/permify
Vulnerabilities
ConnectWise Patches ScreenConnect Vulnerability Exploited In Worm-Like Attacks"ConnectWise has released urgent patches for a critical-severity vulnerability in the ScreenConnect remote access and support software that has been exploited in worm-like attacks. Tracked as CVE-2026-84869 (CVSS score of 9.9/10), the security defect is described as a missing authorization and improper privilege management issue. The bug creates “a condition in the ScreenConnect client that may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances,” ConnectWise explains in its advisory."
https://www.securityweek.com/connectwise-patches-screenconnect-vulnerability-exploited-in-worm-like-attacks/ CISA Adds One Known Exploited Vulnerability To Catalog
"CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability"
https://www.cisa.gov/news-events/alerts/2026/09/14/cisa-adds-one-known-exploited-vulnerability-catalog New DDRop Attack Breaks Intel TDX And AMD SEV-SNP Confidential Computing
"Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server's memory, so the processor keeps reading old encrypted data as if it were current. The attack requires an attacker who already controls the server's software and can briefly access the machine to insert a small circuit board, called an interposer, between the processor and a memory module."
https://thehackernews.com/2026/09/new-ddrop-attack-breaks-intel-tdx-and.html
https://ddropattack.eu/
https://www.theregister.com/security/2026/09/14/new-hardware-device-can-ram-into-encrypted-memory-expose-your-data/5296377
Malware
Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens To Russian Bot Service"Socket’s Threat Research Team identified a cross-store browser extension, “Twitch Enhanced Viewer | JeetBot,” that forwards each user’s live Twitch OAuth session token to proxy servers operated by a Russian commercial bot service. The extension ships on both the Chrome Web Store (extension ID pnhhdhhcadcjfckjhpmjneldiegbojfb, 30,000 users) and Firefox Add-ons (twitchenhancedviewer@example[.]com, 552 users). Both listings are live at time of writing."
https://socket.dev/blog/malicious-twitch-browser-extension
https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html
https://www.bleepingcomputer.com/news/security/twitch-extension-with-30k-installs-exposes-users-oauth-tokens/
https://www.infosecurity-magazine.com/news/malicious-twitch-extension-oauth/ HBO Max Ads On a Compromised Reddit Account Exposed a Massive PasteSwitch ClickFix Operation
"In September 2026, the cybersecurity community uncovered a massive, highly coordinated malvertising campaign leveraging the official, verified HBO Max Reddit account (u/hbomax). Over a frantic 48-hour period, the compromised account pushed 108 distinct “ClickFix” advertisements to users across the platform. Through joint research conducted by Hudson Rock and Kirk from ADAMnetworks (with additional thanks to Tuxxin from Whack.sh and Emiliano from The Matrix Project), we can confirm this incident is part of a massive, cross-platform delivery operation we are dubbing PasteSwitch. This operation spans macOS stealers, Windows loaders, deceptive TLS tactics, and contract-controlled cryptocurrency clippers."
https://www.hudsonrock.com/blog/hbo-max-ads-on-a-compromised-reddit-account-exposed-a-massive-pasteswitch-clickfix-operation
https://adamnet.works/blog/hbo-max-ads-exposed-the-pasteswitch-clickfix-operation/
https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/
https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408 Cloud Takeover: Mass Scanning For Exposed Vite Endpoints (CVE-2026-39364)
"August 2026 saw an escalation in automated reconnaissance targeting internet-exposed developer tooling. Honeynet sensors recorded a sustained scanning operation focused on pulling cloud credentials and infrastructure state files out of exposed Vite development servers. The campaign generated 807 session-grouped attacks, roughly 32,000 raw events over the monthly analysis window. The activity was anchored by probes matching CVE-2026-39364, a high-severity file-read vulnerability that entered the monthly top-CVE tracking list, alongside recurring signatures for older Vite bypass flaws. Rather than target a single file, the scanning fleet systematically cycled through extensive wordlists of environment files, AWS keys, Azure tokens, and Infrastructure-as-Code state files."
https://www.f5.com/labs/articles/cloud-takeover-mass-scanning-for-exposed-vite-endpoints-cve-2026-39364
https://www.bleepingcomputer.com/news/security/hackers-target-exposed-vite-dev-servers-to-steal-aws-azure-secrets/ Fake Voicemail Transcript Emails Target 7,800+ Organizations In Large-Scale Credential Phishing
"Automated voicemail transcripts have become part of the daily rhythm of enterprise communication. They arrive with familiar subject lines, system-generated formatting, and little human context, exactly the qualities that make them easy to trust and easy to overlook. Attackers are now exploiting that familiarity, turning routine call-transcription notifications into a vehicle for credential phishing. Check Point researchers identified a large-scale phishing campaign that exploits this shift in enterprise behavior. The emails impersonate automated voicemail-transcript notifications and deliver malicious Scalable Vector Graphics (SVG) attachments that redirect users to credential-harvesting pages, converting a familiar collaboration workflow into a potential path for account takeover."
https://blog.checkpoint.com/security/fake-voicemail-transcript-emails-target-7800-organizations-in-large-scale-credential-phishing/ “Eye” Spy: Cyclops Blink Returns With Extended Capabilities
"In August 2026, Counter Threat Unit™ (CTU) researchers analyzed a malicious 64-bit Linux executable named timezone_check that was discovered on multiple compromised Cisco Firewall Management Center (FMC) devices. The sophisticated modular implant provides persistent remote access to a compromised Linux system. CTU™ analysis indicates that it is a variant of the Cyclops Blink malware previously analyzed by the UK National Cyber Security Centre (NCSC) in 2022 and is likely associated with the Russia-based IRON VIKING threat group (also known as Sandworm and Seashell Blizzard). Cisco published details about this campaign on September 9, prompting CTU researchers to publicly release their analysis."
https://www.sophos.com/en-gb/blog/-eye-spy-cyclops-blink-returns-with-extended-capabilities
https://www.darkreading.com/cyberattacks-data-breaches/sandworm-chains-cisco-vulnerabilities-cyclops-blink Smish. Click. Drained: Inside The Smishing Triad's Phishing Cockpit
"A widespread smishing campaign was identified in which victims received fraudulent SMS messages impersonating official entities and were instructed to click a link inside the SMS in order to “complete a verification“, “settle an outstanding fee”, or “re-confirm delivery details”. The link resolved through a short URL into a disposable apex domain hosting the phishing kit analysed in this writeup. The kit then walked the victim through a multi-stage credential capture funnel identity, card, OTP, sometimes a second bank, sometimes a wallet while a human operator on the back end watched the session in near-realtime and pushed control instructions as needed."
https://www.group-ib.com/blog/smishing-triad-outsider-jwr/ Machine Speed, Hold The AI: Hand-Rolled Marimo CVE-2026-39987 Exploit
"AI is lowering the barrier to entry for attackers; that much is settled. But what’s still up for debate is whether skilled threat actors can keep up with their LLM-driven competitors. Recently, the Sysdig Threat Research Team (TRT) watched a single threat actor go from an open WebSocket to a live SSH session on a bastion host in eight seconds. There was no agent in the loop, nor was there any sign of LLM-generated scripts or tooling. Instead, the operator used a Python toolkit they wrote and debugged by hand, in-session, over the preceding four hours."
https://www.sysdig.com/blog/machine-speed-hold-the-ai-hand-rolled-marimo-cve-2026-39987-exploit
https://www.infosecurity-magazine.com/news/human-attacker-machine-speed/ The Fake Worker Threat And The Rise Of Human Infiltration
"The Democratic People’s Republic of Korea (DPRK), commonly known as North Korea, has thousands of highly skilled workers engaged in remote employment and related activities around the world. In most cases these workers have constructed false identities as individuals based in the United States (U.S.), Germany, Portugal, the United Kingdom (UK) and other Western countries. They often mask their locations through something like remote laptop farms and virtual private networks (VPNs). This is the ‘North Korea fake worker scam,’ also known as the ‘fake IT worker scam.’ It is believed to have cost victim organizations hundreds of millions of dollars since its emergence in 2017."
https://blog.barracuda.com/2026/09/14/the-fake-worker-threat-and-the-rise-of-human-infiltration Red Heron Exploits Gitea n-Day Flaw In Multinational Campaign, Exposing New Linux Rootkit
"Acronis Threat Research Unit (TRU) uncovered a multinational campaign in which a Chinese-speaking threat actor, tracked as Red Heron, rapidly weaponized CVE-2026-60004 to compromise internet-facing instances of Gitea, a self-hosted source-code management platform. The activity progressed from source-code theft to persistent access, credential collection, and lateral movement, including root-level access to a three-node Proxmox cluster. TRU traced a Linux implant to Red Heron’s exposed staging server, revealing the actor’s exploitation tools, reconnaissance databases, command history, stolen repositories, and malware. This provided rare visibility into the operation, from target selection and vulnerability weaponization to post-exploitation activity."
https://www.acronis.com/en/tru/posts/red-heron-exploits-gitea-n-day-flaw-in-multinational-campaign-exposing-new-linux-rootkit/
https://thehackernews.com/2026/09/red-heron-exploits-gitea-rce-to.html Pro-Ukraine Hacking Cat Group Deploying New Malware Against Russian Targets
"Researchers have uncovered new hacking tools used by the pro-Ukraine hacktivist group Hacking Cat, which has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets. The group often works alongside other Ukraine-linked hackers and uses a wide range of custom-built tools, making it “significantly more difficult” to attribute individual attacks to a specific threat actor, Russian cybersecurity firm Kaspersky said in a recent report."
https://therecord.media/ukraine-malware-russia-ransomware Hundreds Of Fake Government Websites Target Users In Central Asia
"Cybercriminals have created hundreds of fake government and news websites to target people in Uzbekistan, Belarus and Tajikistan with bogus offers promising cash payments or passive income. Researchers at cybersecurity firm F6 identified more than 360 fraudulent domains tied to the campaign. The sites are designed to collect victims’ contact details, which scammers then use to target them through phone or email to steal money, personal information or gain access to their devices."
https://therecord.media/hundreds-of-fake-gov-websites-central-asia-scam One Host, Six Operations: How Two Open Directories Exposed a Multi-Target Campaign
"Hunt.io Attack Capture™↗ (opens in a new tab) flagged two open directories at IP Address "69[.]48[.]228[.]86" on port 80 (August 14) and on port 9001 (August 24), ten days apart in August 2026. A full inventory of both directories reveals a single operator running six parallel operations such as fraud against roughly 2,500 self-hosted "New API" LLM-reseller gateways, LLM-assisted mapping of Vietnam's government and military hierarchy, password-spraying and reconnaissance against Pakistan's National Defence University and armed forces, SQL-injection probing of the Chinese social platform uu-chatroom.com, opportunistic census-style scanning of unrelated hosting-provider IP ranges, and one completed database breach of commercial targets in Mexico."
https://www.infrahunter.com/research/two-open-directories-on-a-singapore-vps The Ghost In The Chat: How a Bot That Isn't In Your Group Steals Messages From Telegram HTML Exports
"A stored XSS in Telegram Desktop lets an attacker plant invisible JavaScript in an exportable chat through a bot's inline keyboard button. The payload can sit in message history for months and detonates when a participant opens an HTML export page containing that message. No second click, no warning: every message and metadata field rendered in that document can be shipped to the attacker's server, and the page itself can be rewritten. The bot never joins the target chat — one forwarded message can be enough."
https://expatch.com/writeups/telegram-html-export-xss.html
https://thehackernews.com/2026/09/telegram-desktop-flaw-lets-hidden.html
Breaches/Hacks/Leaks
Japan's Digital Agency Says VPN Flaw Exposed 246,000 Personnel Records"Japan’s Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. The agency says that the attacker gained initial access by exploiting a vulnerability in a VPN device used by the Government Solution Service (GSS). An investigation started on June 25, after the agency detected a large-scale file access from the account of a maintenance and operations staff member."
https://www.bleepingcomputer.com/news/security/japans-digital-agency-says-vpn-flaw-exposed-246-000-personnel-records/ Telus Warns Customers Of Account Breaches
"Telus, one of Canada’s largest telecom providers, is notifying some customers that their accounts have been breached and their personal information has been accessed. In data breach notifications sent to customers whose consumer telecom accounts were affected, Telus said the intrusions occurred between February 2025 and June 2026. According to the company, the attacker used compromised credentials to access Telus accounts and the information they store, including names, account numbers, phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history."
https://www.securityweek.com/telus-warns-customers-of-account-breaches/ Thai Broadband Provider Targeted Via FortiGate SSL-VPN And MeshCentral Persistence
"Open directories are one of the most reliable windows into active threat actor operations. When an attacker misconfigures their staging server, everything they have been doing becomes accessible. Hunt.io's AttackCapture™ discovered an open directory hosted at 92[.]63[.]180[.]133:8888, a server on Bangmod Enterprise Co., Ltd. infrastructure in Thailand. The directory contained 298 files across 30 subdirectories totaling 19 MB, first captured on June 3, 2026, including exploitation scripts, privilege escalation tools, brute-force utilities, a live MeshCentral agent configuration, and a device inventory of already-compromised machines, all targeting 3BB (Triple T Broadband). Before going deeper, these are the findings that shaped the entire analysis."
https://hunt.io/blog/thai-broadband-fortigate-sslvpn-meshcentral-intrusion
https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html
General News
Turn It Off And On Again, But For Critical Infrastructure"Researchers at KTH Royal Institute of Technology built a container replica of a segmented industrial network, attacked it repeatedly across 14 days of running time, and used the captured traffic to train a defense agent that decides on its own when to intervene. The agent sees six numbers per interval: packet counts crossing the network’s segments and moving to and from individual machines. From those counts it infers how far an intruder has progressed, and acts."
https://www.helpnetsecurity.com/2026/09/14/ot-intrusion-response-agent/
https://arxiv.org/pdf/2609.10298 Cybersecurity Attention Fades Within Months After a Breach
"Cybersecurity attention often rises after an incident, then recedes as organizations return to their existing priorities and practices, according to a new ManageEngine survey of 700 IT and cybersecurity leaders in the US and Canada. All of them had already been through a breach or incident. Still, 91% said they trust their organization’s current cybersecurity posture. Only 8% said cybersecurity becomes a permanent priority once the incident is behind them. “The belief that breaches are inevitable has lowered the bar for security,” said Dr. Erik Huffman, a cyberpsychology researcher who commented on the findings. “We’ve said ‘it’s not a matter of if, but when’ for far too long. But we still have control over the security processes that directly influence the outcome.”"
https://www.helpnetsecurity.com/2026/09/14/manageengine-cybersecurity-breach-confidence-report/ Certificate Failures Can Cost Firms Over $250,000
"The move toward 47-day public TLS certificates by 2029 will increase the certificate management workload for enterprises, according to DigiCert’s Certificate Management Outlook. Organizations will need to renew certificates more than eight times as often as under the previous certificate lifecycle and conduct 40 times as many domain validations. Certificate failures can disrupt business operations. Some 34% of companies experienced a service outage caused by an expired certificate, while 40% reported downtime linked to certificate mismanagement."
https://www.helpnetsecurity.com/2026/09/14/digicert-certificate-management-automation-report/ Google’s New Search Redirects Make Links Harder To Check Before You Click
"Google is changing how some links in its search results work. Instead of linking directly to the destination, Google has started routing some search result links through opaque google.com/goto?url=... redirects. The url parameter does not show a readable version of the destination but uses a custom, Google-specific encoding."
https://www.malwarebytes.com/blog/news/2026/09/googles-new-search-redirects-make-links-harder-to-check-before-you-click Security Through Obscurity Is Dead, And AI Delivered The Fatal Blow
"The term "security through obscurity" describes an old idea that networks and systems will remain secure so long as their architecture, along with any vulnerabilities or other weaknesses, remains secret or hidden. It was never a sound strategy for protecting sensitive assets and systems, but many organizations leaned on it due to lack of resources or complacency. Now it’s obsolete. Don’t believe us? Here’s proof."
https://www.theregister.com/security/2026/09/13/security-through-obscurity-is-dead-and-ai-delivered-the-fatal-blow/5296000 New Warnings About The Risks Of AI To Humanity Revive a Long-Running Debate
"New warnings from within the artificial intelligence industry have revived a long-running debate over whether advanced AI could escape human control and ultimately threaten humanity’s survival, and whether the companies developing the technology are doing enough to prevent such a scenario. The CEO of Anthropic, the San Francisco company behind Claude, said he thought the industry needed to reduce the speed of its work, cautioning Saturday that a swarm of AI agents might be able to take over the internet in six months to a year unless companies devoted more time to putting safeguards in place."
https://www.securityweek.com/new-warnings-about-the-risks-of-ai-to-humanity-revive-a-long-running-debate/ SecondSight Threat Hunting Report
"Authored by the Trellix Advanced Research Center, this report (1) highlights threat hunting insights, intelligence, and guidance gleaned from multiple sources of critical data, including Trellix SecondSight, on the top five critical campaigns observed in the first half of 2026, and (2) develops expert, thorough case studies to inform and enable best practices in defending against these types of campaigns. This edition focuses on data and insights captured primarily between January 1, 2026, and June 30, 2026."
https://www.trellix.com/advanced-research-center/threat-reports/secondsight-threat-hunting-report-september-2026/
อ้างอิง
Electronic Transactions Development Agency (ETDA) 08fc5bc9-d01a-45e0-9a3e-e2f00007494b-image.png