Cyber Threat Intelligence 07 September 2026
-
Industrial Sector
- IXON VPN Client
"Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-02 - Pyramid Solutions NetStaX EtherNet/IP Stack
"Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-07 - Inductive Automation Ignition
"Successful exploitation of this vulnerability could allow any authenticated user to create projects."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-06 - Tycon Systems TPDIN-Monitor-WEB3
"Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-08 - OPCFoundation OPC UA LocalDiscoveryServer (LDS)
"Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-01 - Rockwell Automation ControlFLASH
"Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-03 - Rockwell Automation ArmorStart LT
"Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-04 - Rockwell Automation 1756-ENBT Module
"Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-05
Vulnerabilities
- Critical Citrix NetScaler Auth Bypass Now Leveraged In Attacks
"Attackers have begun targeting a critical-severity Citrix NetScaler flaw in the wild, according to vulnerability intelligence company Previdian. Tracked as CVE-2026-19490, this security flaw can allow unprivileged threat actors to bypass authentication remotely when the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the NetScaler firmware version and whether SAML Action is configured."
https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/ - Google Warns Of New Chrome Zero-Day Flaw Exploited In Attacks
"Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. The exploited security issue, identified as CVE-2026-85046, is described as a type confusion. It was reported to Google by researcher Salvatore Gulizia, known online as “Serotav.” The update brings Chrome to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, as part of a gradual rollout. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the advisory reads."
https://www.bleepingcomputer.com/news/security/google-warns-of-new-chrome-zero-day-flaw-exploited-in-attacks/
https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html
https://www.securityweek.com/google-patches-6th-chrome-zero-day-of-2026/
https://securityaffairs.com/198405/security/google-fixes-the-sixth-actively-exploited-chrome-zero-day-of-2026.html
https://www.helpnetsecurity.com/2026/09/04/google-chrome-zero-day-cve-2026-85046/ - StyleSmuggler: Magento And Adobe Commerce 0-Day RCE Under Active Attack
"Sansec discovered StyleSmuggler, an unpatched Magento and Adobe Commerce zero-day that gives unauthenticated attackers remote code execution. All current versions are affected, including 2.4.9. Attacks started September 4th. Sansec is rolling out emergency mitigation."
https://sansec.io/research/stylesmuggler
https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html - Critical Vulnerabilities In MikroTik RouterOS Are Being Actively Exploited. Immediate Update Recommended
"The CERT Polska team has identified and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS. Combining two of them allows an attacker to take full control of the device without authentication if the device supports remote access using the SSH protocol. To make this chain easier to identify, we have given it a common name, MikroTrick. In recent days we have been observing attacks against RouterOS devices accessible from the internet. We have obtained confirmation that the attackers are exploiting this combination of vulnerabilities to take full control of devices whose SSH service is accessible from public networks. It has also been confirmed that the released patches prevent the observed attacks. We recommend applying the update immediately."
https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html
https://securityaffairs.com/198538/security/your-mikrotik-router-may-already-be-compromised-look-for-ssh-user-2.html - CISA Adds One Known Exploited Vulnerability To Catalog
"CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability"
https://www.cisa.gov/news-events/alerts/2026/09/04/cisa-adds-one-known-exploited-vulnerability-catalog
https://securityaffairs.com/198455/security/u-s-cisa-adds-google-chromium-v8-flaw-to-its-known-exploited-vulnerabilities-catalog-2.html - PostGREShell: The Database Powering Much Of The Internet Had An Open Door For 12 Years
"Imagine you've built a fortress. Guards at the front gate, scanners at every door, a guest list checked twice. You hired the best architects, ran the audits, passed the compliance reviews. By every measure, the place is locked down. But you missed something. Around the back, there's a small, unmarked entrance used by the cleaning crew. It's been there for years, and nobody thought to put a guard on it. Then one day, someone figures out that if you walk in through that entrance wearing a cleaning uniform, the entire fortress opens up: the armory, the vault, the control room. Once you're inside, everyone assumes you belong."
https://www.cyera.com/research/postgreshell-the-database-powering-much-of-the-internet-had-an-open-door-for-12-years
https://thehackernews.com/2026/09/postgresql-fixes-12-year-old-logical.html
https://www.securityweek.com/12-year-old-postgresql-vulnerability-enables-database-server-takeover/
https://securityaffairs.com/198433/security/postgresql-hit-by-12-year-old-vulnerability-allowing-server-takeover.html
Malware
- Attack Cases In Korea Involving The Installation Of Radmin And UltraVNC
"The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases that exploited Radmin and UltraVNC. Although the Initial Intrusion method remains unknown, the attackers installed Radmin—a remote control tool—and then installed UltraVNC. The threat actors exploited the remote control tools to gain control of the infected systems and installed Netch and CCProxy to use the infected systems as proxy nodes. Recently, they have been installing SoftEther VPN to exploit the infected systems as VPN servers."
https://asec.ahnlab.com/en/95230/ - X Money Rollout Linked To Password-Reset Attacks
"X says attackers may be targeting accounts because its X Money payments service is now more widely available. The company is investigating a wave of unsolicited password-reset emails sent to users. While their arrival alongside the wider X Money rollout has fueled account-takeover concerns, X says it has found no evidence of a breach or successful account takeovers so far."
https://www.malwarebytes.com/blog/scams/2026/09/x-money-rollout-linked-to-password-reset-attacks - Angry Birds: Toy Ghouls’ New Toys
"We continue tracking the activity of Toy Ghouls (also known as Bearlyfy, Laboo.boo, and Feral Wolf), a financially motivated group that has been targeting Russian organizations since 2025. The attackers initially relied exclusively on tools pulled from public GitHub repositories along with leaked Babuk and LockBit ransomware builders, later shifting to their own custom ransomware, GenieLocker. In early July 2026, we observed the group using a custom backdoor for the first time. We identified two versions of this backdoor: one uses the HiveMQ MQTT broker as its C2 server, while the other relies on the Element messenger."
https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/ - ASCII Smuggling Crosses Over From AI Prompt Injection To Phishing Evasion
"Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII Smuggling. Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as ‘funding’ to prevent email filters from parsing them. The finding emerged from Microsoft Defender for Office 365 prompt injection protection research, showing how AI-era evasion techniques can surface in traditional phishing campaigns. In Microsoft telemetry, hits on a hunting signature designed to detect ASCII-smuggling increased sharply beginning February 9, 2026, and remained elevated on weekdays for approximately three months. Microsoft Defender for Office 365 telemetry showed that the majority of messages were flagged by layered protections rather than by reliance on a single Unicode-specific signal."
https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/
https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html
https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/
https://www.theregister.com/security/2026/09/04/ascii-smuggling-isnt-just-an-ai-security-risk/5294595 - DPRK APTs: Ted Backdoor And CurlRAT Target South Korean Media And Automotive Sectors
"A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and engage in long-term surveillance."
https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/
https://thehackernews.com/2026/09/new-ted-backdoor-hides-inside-victims.html - Attackers Actively Exploiting Critical Vulnerability In Super Forms Plugin
"On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an estimated 13,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution. The vendor released the fully patched version on July 8th, 2026, and we disclosed this vulnerability in the Wordfence Intelligence vulnerability database on July 9th, 2026. Our records indicate that attackers started exploiting the issue on July 14th, 2026, the same day we released the firewall rule. The Wordfence Firewall has already blocked over 250,000 exploit attempts targeting this vulnerability."
https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-super-forms-plugin/
https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html - Chinese-Speaking Operator Uses AI Agents To Target Government And Education Systems Across Asia
"In July, we published research on a Chinese-speaking operator who embedded Claude Code and DeepSeek into intrusions across four countries. This is a second, separate campaign with different infrastructure, tooling, and targets, but the same pattern: commercial AI models used as operational components. Targets included Taiwan's Kuomintang Party History Archives, Indonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Da Nang, Vietnam. The most extensive compromise hit a Fengtai District government environment, where the operator achieved command execution, collected LSASS and registry hives, accessed government and health records, and deployed multiple Windows implants. Separate activity exposed a Chinese education AI platform and obtained root database access to a university campus-card system."
https://hunt.io/blog/chinese-operator-secflow-claude-qwen-deepseek-asia
https://securityaffairs.com/198417/ai/chinese-hackers-use-ai-agents-in-multi-country-cyber-campaign.html - Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizations
"Datadog Security Research observed a password spraying campaign targeting the AWS root user account. The campaign ran from July 24 to August 23, 2026. During this period, attackers made repeated failed authentication attempts against AWS root user accounts at more than 150 organizations. Organizations saw a median of two attempts each, with some experiencing up to eight attempts across the campaign window."
https://securitylabs.datadoghq.com/articles/aws-root-user-bruteforce-campaign/ - Chained Account Takeovers: AiTM Phishing Campaign Propagating Across Healthcare And Academic Medical Institutions
"SRA identified an active adversary-in-the-middle (AiTM) phishing campaign propagating across healthcare and healthcare-education organizations by chaining compromised accounts. SRA reconstructed one chain across a university and two health systems, where a single compromised account phished recipients at more than 90 distinct .edu domains in roughly 13 minutes. Open-source analysis shows the observed chain is a part of a broader operation that pairs credential and session theft with a parallel malware delivery track, masking its infrastructure so effectively it scores clean on public reputation tools. Organizations in healthcare and higher education should hunt for the redirect and inbox-rule patterns detailed below, confirm session-token revocation on any affected account, and prioritize phishing-resistant MFA."
https://sra.io/blog/chained-account-takeovers-aitm-phishing-campaign-propagating-across-healthcare-and-academic-medical-institutions/ - Anatomy Of a Silent Domain Takeover
"Modern AD attacks use legitimate protocols end-to-end, no malware, no exploit, nothing for signature tools to fingerprint. The evidence is already in the logs; what is missing is the narrative linking five benign-looking Windows events into a single attack. A full domain takeover can be completed in 54 minutes, from the first password spray to the forged Golden Ticket, with each individual event appearing normal."
https://blog.qualys.com/product-tech/2026/09/02/anatomy-of-a-silent-domain-takeover-ad-real-time-monitoring - Malware On The Blockchain: An Ongoing Campaign’s New WebRTC Twist
"EtherHiding, a technique that uses blockchain smart contracts as takedown-resistant payload storage, has been seen across more than 5,400 compromised websites in the last few months. The compromised websites have little in common beyond being small businesses (clinics, plumbers, e-commerce shops) with no shared industry, region, or owner. These compromised sites include either an inline script or a spoofed package that calls the BSC testnet and downloads a ClickFix overlay as the next step of the attack, which instructs visitors to run a command on their PC. We also observed a newer variant that, instead of a ClickFix overlay, opens a covert WebRTC data channel for Command and Control."
https://www.netskope.com/blog/malware-on-the-blockchain-an-ongoing-campaigns-new-webrtc-twist
https://www.bleepingcomputer.com/news/security/over-5-400-hacked-sites-serve-clickfix-payloads-stored-on-the-blockchain/ - Discovery Of a New OpenAI Agent Message Board
"We found ~18,000 posts from autonomous AI agents (self-identifying as from OpenAI) using the public internet to communicate during a web-retrieval task. These AIs colluded to share answers, research their environment, and bypass sandbox restrictions. Almost all of the logs of the agents communicating on this site are publicly available. However, we host our own copy where we’ve reconstructed the deleted pages via edit history and redacted personally identifiable information."
https://collusion.wiki/
https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/
https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html
https://securityaffairs.com/198524/ai/ai-agents-hijacked-german-wiki-to-cheat-openai-delayed-disclosure.html - Attackers Exploit PaperCut Flaws To Steal Credentials From Schools And Universities
"Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as create privileged accounts. "Observed post-exploitation activity included delivery of Windows registry hive collection tools, Metasploit/Meterpreter-related Java payloads, and commands used to identify hosts, users, processes, and sensitive configuration data," Arctic Wolf said."
https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html
https://securityaffairs.com/198476/hacking/papercut-flaws-exploited-in-attacks-on-u-s-and-european-schools.html - REVSTEALER Ramps Up: Analysis Of Up-And-Coming Infostealer
"Elastic Security Labs is tracking an emerging infostealer, REVSTEALER, under REF2859. This family has gained momentum in recent months, with higher distribution volume, and has emerged as a formidable threat, featuring a comprehensive credential harvester, an embedded sandbox scoring system, and a Polygon blockchain-based dead drop for resilience. Beyond credential theft, REVSTEALER targets gaming platforms for additional monetization; the developer clearly understands that victim accounts on these platforms hold real monetary value in resale markets."
https://www.elastic.co/security-labs/threat-command/revstealer-credential-harvesting-infostealer
https://assets.contentstack.io/v3/assets/bltefdd0b53724fa2ce/blt9cd59668ba5a104d/6a97978bd04dac6f166ca8ce/REVSTEALER_-_White_paper.pdf - Detection And Removal Of The Syslogk Rootkit In a Linux Environment
"The AhnLab SEcurity intelligence Center (ASEC) continuously monitors various threats targeting Linux environments. Techniques that modify the Linux kernel to conceal malware and signs of compromise have been used for a long time, and Syslogk is one such rootkit that operates in this manner. This document provides an analysis of the key features and operational mechanisms of the Syslogk rootkit, along with detection and remediation strategies for our products developed based on this analysis."
https://asec.ahnlab.com/en/95254/
Breaches/Hacks/Leaks
- Cybercrooks Trawl Fishbrain To Net Password Hashes
"Cybercriminals have reeled in password hashes and corresponding salts belonging to users of popular fishing app Fishbrain, opening the door to cracking attempts. Fishbrain AB, which says its eponymous app serves more than 20 million anglers, disclosed the August 19 breach to the California Attorney General's Office this week. The unknown perpetrators helped themselves to a trawl of user data, including names, dates of birth, email addresses, phone numbers, Fishbrain usernames, country information, password hashes, and salts."
https://www.theregister.com/cyber-crime/2026/09/03/cybercrooks-trawl-fishbrain-to-net-password-hashes/5294158 - Attackers Breached JetBrains Cadence Via Unpatched TeamCity, Extracting AWS Credentials
"JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said. "They should also treat all executions, including their inputs and outputs in your Cadence project, as potentially untrusted.""
https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html - Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
"Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets."
https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html
General News
- Why Judgment Is Emerging As Cybersecurity’s Defining Skill
"AI is getting better at much of what security teams have long spent time on: analyzing information, identifying patterns, and providing technically sound recommendations quickly. As those capabilities become more routine, they are changing what security practitioners spend their time on. Reaching a technically sound recommendation is also getting easier, which puts more weight on the judgment about what to do with it. A recommendation can make complete sense from a security perspective and still carry consequences for the systems, people and business around it that change what the right decision is."
https://cyberscoop.com/ai-security-operations-human-context-ciso-op-ed/ - Insurers Search For Answers To Rein In Rogue AI
"When Maria Long heard about OpenAI's rogue model attacking AI-model service provider Hugging Face, her first stop was to review her firm's technology errors and omissions (Tech E&O) policy. As the chief underwriting officer for cybersecurity insurance services firm Resilience, she understood that rogue AI agents causing inadvertent compromises could result in significant losses to insurers in the future. This incident showed that the future wasn't that far off. For Hugging Face, the incident would almost certainly be covered by cyber-liability insurance as a classic security breach. However, if AI agents routinely escape containment, insurers have to consider that the volume of policy claims could grow."
https://www.darkreading.com/cyber-risk/insurers-search-answers-rogue-ai - What The AI Warning Letter Completely Missed
"Recently, more than 100 technology companies — OpenAI, Anthropic, Microsoft, and Google among them — published an open letter warning that AI is about to make sophisticated cyberattacks far cheaper and far more common, and that "we have a limited window to strengthen cyber defenses." I read it twice. The first time as the head of a security organization, nodding along to very nearly every line. The second time hunting for the part about who actually does the work. I did not find it."
https://www.darkreading.com/cyberattacks-data-breaches/ai-warning-letter-missed-people - Companies Have 6 Months To Prepare For Automated Attacks
"With multiple benchmarks confirming that at least one frontier model can autonomously execute an end-to-end compromise, cybersecurity experts are warning that companies have to pick up the pace in securing their attack surfaces and adopting AI-speed defenses. On Sept. 2, consulting firm Booz Allen became the latest organization to confirm that a frontier model — Anthropic's Mythos 5 — can act as a fully autonomous hacker and compromise a production-grade enterprise network. The company also released a metric, dubbed the Cyber Weapon Index (CWI), to benchmark a model's capabilities, pairing the ability to find and exploit vulnerabilities with the ability to execute and attack a target."
https://www.darkreading.com/cybersecurity-operations/companies-six-months-prepare-automated-attacks - AI Is Ending The Era Of Hidden Vulnerabilities — Are Vendors Ready?
"Vulnerabilities are running out of places to hide, thanks to frontier AI models, and it could create problems for those that sell software. The "vulnpocalypse," or the onslaught of vulnerabilities surfaced through the proliferation of AI, is having far-reaching consequences on the economics and demands previously associated with bug hunting. Software publishers are used to operating in a world where code reviews, researcher attention, and discovery capacity are finite. But over the past two years, things have changed. Large language models (LLMs) have automated and sped up large portions of the bug discovery pipeline, and frontier models could accelerate that process even further."
https://www.darkreading.com/vulnerabilities-threats/ai-ending-era-hidden-vulnerabilities-are-vendors-ready - US Offers $10 Million For Info On Iranian Allegedly Behind Cyberattacks On Critical Infrastructure
"A $10 million reward has been posted by the State Department for information on the whereabouts of senior Iranian official Amir Yaryab. Yaryab allegedly leads the Islamic Revolutionary Guard Corps’ (IRGC) Cyber-Electronic Command (CEC). U.S. officials accused Yaryab of directing multiple Iranian hacking groups that have targeted “critical infrastructure sectors including defense, news, shipping, travel (hotels and airlines), energy, and financial and telecommunications systems in the United States, Europe, and the Middle East.”"
https://therecord.media/us-reward-amir-yaryab-iran-irgc-cyberattacks - H1 2026 Malware And Vulnerability Trends
"H1 2026 activity showed a continued adversary preference for abusing legitimate tools, trusted platforms, and routine workflows already present in enterprise and consumer environments. Threat actors used exposed software, developer tools, remote access utilities, payment workflows, and third-party services to gain access, steal credentials, move laterally, and monetize intrusions while blending into expected activity. This emphasis on evasion through normalcy rather than technical novelty increases the risk that malicious activity will progress through approved tools and trusted services before defenders recognize it, reinforcing the need for stronger exposure management, identity and credential governance, behavioral detection, developer-environment security, backup resilience, mobile fraud monitoring, and third-party oversight."
https://www.recordedfuture.com/research/h1-2026-malware-vulnerability-trends
https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-2026-0903.pdf
อ้างอิง
Electronic Transactions Development Agency (ETDA)
- IXON VPN Client