Cyber Threat Intelligence 18 September 2026
-
Industrial Sector
- Hitachi Energy FACTS Control Platform (FCP)
"Hitachi Energy is aware of vulnerabilities that affect the FACTS Control systems with GWS component listed in this document. An attacker exploiting these vulnerabilities can cause impact on confidentiality, integrity and availability of the product. Following FACTS Control systems with GWS component deployed from year 2020 onwards are likely affected by the above vulnerabilities. Product deployments without GWS component are not affected. • SVC Light (STATCOM) • Fixed Series Capacitor • Thyristor Controlled Series Capacitor • Static Var Compensator • Static Watt Compensator • Hybrid Synchronous Condensers Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The affected FCP versions are only applicable if GWS component is present."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-03 - Mitsubishi Electric GX Works3 And Motion Control Settings
"Successful exploitation of this vulnerability could allow a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-02 - Bransys ELD
"Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-01 - Schneider Electric Modicon M340 Controller And Communication Modules
"Schneider Electric is aware of a vulnerability in its Modicon M340"
https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-04 - Schneider Electric NetBotz 5 750/755
"Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities. Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-05 - ABB Ability Edgenius
"ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete control of the system"
https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-06 - Schneider Electric PowerChute Serial Shutdown
"Schneider Electric is aware of vulnerabilities in its PowerChute Serial Shutdown product. The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. Failure to apply the remediation provided below may risk improper authentication validation which could result in disruption of operations and access to system data."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-07 - Ransomware Attacks On Manufacturers Surge As Supply Chain Risk Grows
"Manufacturing remains a primary target for ransomware, possibly due to the long tail of effects. Incidents this year are 40% up on the same period last year. Throughout September 2025, Jaguar Land Rover shut down its UK plants because of an attack and halted the daily production of around 1,000 luxury vehicles. More than 5,000 other companies were affected by the shutdown, and the Bank of England suggested it was a contributory factor in a slowdown in national growth figures. The longer-term repercussions are still being felt: Jaguar Land Rover has said it will cut 4,000 jobs, blaming the cyberattack."
https://www.securityweek.com/ransomware-attacks-on-manufacturers-surge-as-supply-chain-risk-grows/
https://blackkite.com/reports/2026-manufacturing-distribution
Vulnerabilities
- Cisco Warns Of Max Severity ISE Zero-Day Exploited In Attacks
"Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. Cisco ISE is a centralized policy platform that IT administrators use to manage endpoints, users, and device access to network resources, often while enforcing Zero Trust security models. The security flaw (tracked as CVE-2026-76460) lets remote attackers bypass authentication by exploiting a weakness in an API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) regardless of configuration."
https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html
https://cyberscoop.com/cisco-ise-zero-day-cve-2026-76460/
https://www.infosecurity-magazine.com/news/cisco-active-exploitation-critical/
https://www.theregister.com/security/2026/09/17/cisco-drops-another-exploited-zero-day-this-time-a-perfect-10/5297180
https://www.securityweek.com/active-exploitation-triggers-emergency-patch-for-cisco-ise-zero-day/
https://www.helpnetsecurity.com/2026/09/17/cisco-ise-vulnerability-exploited-cve-2026-76460/ - Critical Unbound DNSSEC Validator Flaw Could Allow RCE Via a Malicious DNS Zone
"Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642, along with eight other flaws. One of the eight, CVE-2026-82717, is a heap corruption bug in CNAME synthesis reported by Ben Morris of Anthropic. It could also lead to remote code execution "under certain systems and compilation options," NLnet Labs said."
https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.html - Cisco Fixes Dozens Of Flaws Across FMC, ISE And Nexus Dashboard
"Cisco on Wednesday announced patches for dozens of critical-severity CVEs in Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard. The ISE security updates stand out with patches for 20 CVEs, including 12 critical-severity flaws. Three of the issues have already been publicly disclosed, Cisco warned. Tracked as CVE-2026-20282, CVE-2026-20283, and CVE-2026-20284, they can be exploited by remote attackers for SQL injection, data tampering, and arbitrary command execution. Administrative access is required for all three."
https://www.securityweek.com/cisco-fixes-dozens-of-flaws-across-fmc-ise-and-nexus-dashboard/ - BIND 9 Update Fixes 14 Flaws, Including An Unauthenticated Crash Over DNS-Over-HTTPS
"The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH). A sender with no credentials can crash the server process, named, with a single request that carries an invalid SIG(0) signature, if the sender closes the connection before named finishes checking the signature. ISC said in its advisories that it is not aware of any of the fourteen being exploited."
https://thehackernews.com/2026/09/bind-9-update-fixes-14-flaws-including.html
https://www.securityweek.com/isc-patches-14-vulnerabilities-in-bind-9-security-update/ - Plugin4Shell - Zero Click RCE Vulnerability Found In Top 4 Most Popular Coding Agents, Millions Of Agents Affected
"Plugin4Shell is a zero-click, high-severity RCE affecting all four major AI coding agents - Claude Code, Codex, Copilot, and Gemini. In this first-of-its-kind AI supply-chain attack, a trusted plugin is silently swapped for a malicious one and auto-installed past the agent's SHA pinning - a flaw no marketplace can fix, so users must update their agent."
https://www.air.security/blog-posts/plugin4shell
https://www.theregister.com/security/2026/09/17/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom/5297335
Malware
- RatHat: AI-Powered Mobile Threat Is Here For Your Credentials & Bank Accounts
"The zLabs team has uncovered RatHat, a novel Android malware strain linked to threat actors that appear to be operating in China. RatHat incorporates novel techniques for persistence and leverage generative AI for operational control. Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses an automated multi-stage infection pipeline. Once deployed, it pairs Accessibility abuse with autonomous local ADB (Android Debug Bridge) self-pairing to break out of the standard Android application sandbox, staging independent native daemons that execute with shell-level privileges."
https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts
https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/
https://www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/ - Brevo Supply-Chain Attack Injected ClickFix Scripts On Customer Sites
"Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. The customer relationship management and digital marketing company says the attackers used the API key to create a malicious Cloudflare Worker that modified content at the CDN edge for approximately five and a half hours on September 14. The attack affected pages on brevo.com, sendinblue.com, login/account/my/onboarding.brevo.com, and sibforms.com. The Cloudflare worker also modified the Brevo forms script, Brevo Conversations widget, and the Brevo SDK loader scripts that customers embed on their websites."
https://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/ - Beware The SparroWock: The Backdoor That Bites, The Commands That Catch
"ESET Research’s ongoing monitoring of FamousSparrow has borne fruit once again. Our previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor. This time, we discovered that FamousSparrow has switched to a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025."
https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/
https://www.bleepingcomputer.com/news/security/chinese-hackers-use-sparrowocky-malware-in-govt-espionage-attacks/
https://thehackernews.com/2026/09/china-aligned-famoussparrow-deploys.html
https://www.darkreading.com/cyberattacks-data-breaches/china-famoussparrow-spies-latin-america
https://therecord.media/china-hackers-latin-america-espionage
https://www.infosecurity-magazine.com/news/famoussparrow-sparrowocky-latin/
https://www.theregister.com/security/2026/09/17/chinas-salt-typhoon-backdoors-latin-american-orgs-with-new-snooping-malware/5297286 - Chatbot Conundrum: Phishing Attempts Of OpenAI’s ChatGPT
"As generative AI tools like OpenAI’s ChatGPT become increasingly common, their large user bases create new opportunities for threat actors. ChatGPT offers subscription-based access to additional features, providing attackers with a familiar payment process to impersonate. By sending fake notifications claiming that a user’s payment method needs to be updated, threat actors can turn a routine billing request into a phishing lure designed to steal credentials and payment information."
https://cofense.com/blog/chatbot-conundrum-phishing-attempts-of-openai-s-chatgpt - HEAVYGRAM: A Telegram-Based Surveillance Backdoor Linked To Handala Hack
"Group-IB Threat Intelligence has uncovered previously undocumented samples of the HEAVYGRAM and CRUDEEXCLUDE malware families. These findings build upon public disclosures of HEAVYGRAM from the U.S. Department of Justice regarding the seizure of infrastructure linked to Iran’s Ministry of Intelligence and Security (MOIS), as well as associated indicators and technical descriptions from a recent U.S. Federal Bureau of Investigation (FBI) FLASH report."
https://www.group-ib.com/blog/heavygram-handala-hack-telegram-c2/ - The Odyssey And Trojans Again: MovieReaper Attacks Users In Multiple Countries Via Compromised Torrents
"Torrent trackers have long been abused for distributing malicious software, disguised as popular films, games, and other content. Our previous research has shown that cybercriminals repeatedly turn torrents as an initial infection vector, using trojanized cracks and installers to reach a large number of users. Installation guides for pirated software routinely instruct users to disable their antivirus, conditioning them to ignore potential threats they are inviting onto their computers."
https://securelist.com/moviereaper-malware-torrent-odyssey-solana/121344/ - SilkParasite Infrastructure: SpiceRAT Servers Tied To Energy And Government Targets Across Central Asia
"This research was carried out jointly with researcher Guy Yasur. Together, we tracked a cluster of SpiceRAT command and control servers active from late 2025 through August 2026 across a small subset of European hosting providers. A TLS certificate issued by a Chinese state-affiliated certificate authority associated with the infrastructure impersonates Uzbekistan's state railway authority. Additionally, this cluster also shares registration-level relationships with hosts Bitdefender attributed to three separate malware families in its August 19, 2026 SilkParasite report. Detection logic built from Cisco Talos' 2024 SpiceRAT research first flagged these servers in late 2025, and in mid-March 2026, we noticed a small group of C2's coming online within days of each other. This analysis relies on internet-wide scan data, and does not address malware behavior, delivery, or initial access."
https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure
https://securityaffairs.com/199267/apt/silkparasite-infrastructure-links-spicerat-to-central-asian-targets.html - Flock Cameras Are Tracking People As Well As Cars
"Flock Safety’s cameras are automated license plate readers (ALPRs) designed to help police find stolen cars or wanted suspects. A joint investigation by 404 Media and WIRED, based on data recovered from a physically removed Flock camera, found that its on-device software explicitly detects people as well as vehicles, bicycles, and license plates. Separately, Washington DC’s police union says the Metropolitan Police Department used Flock data to track officers under Internal Affairs investigation without their knowledge."
https://www.malwarebytes.com/blog/privacy/2026/09/flock-cameras-are-tracking-people-as-well-as-cars
Breaches/Hacks/Leaks
- Gyazo Breach Exposes 23.62 Million User Records And 490 Million Image Metadata Records
"A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday. It also exposed about 490 million image metadata records, mostly for images from January 2019 or earlier, including the IDs that make up Gyazo image links. Helpfeel said those IDs could be used to view the images without permission, and that it has temporarily disabled viewing of some of them."
https://thehackernews.com/2026/09/gyazo-breach-exposes-2362-million-user.html - Hackers Claim Breach Of Russian Election Systems Days Before Parliamentary Vote
"An anonymous hacking group claimed to have broken into computer systems connected to Russia’s election infrastructure just days before the country begins voting for a new parliament. The group, calling itself CikLeak, said it gained access to systems belonging to Russia’s Central Election Commission and companies involved in developing Vybory, the state-run platform used to administer elections. The hackers claimed to have stolen internal documents, server configurations, passwords and employee communications from the commission and its contractors, including Russian telecom giant Rostelecom."
https://therecord.media/russia-election-hackers-breach - London Property Manager Breach May Have Exposed Bank Details And Lockbox Codes
"London property management biz City Relay has warned customers that intruders may have stolen financial data, passwords, and codes used to access keys after compromising its Metabase Cloud instance. City Relay, marketing itself as "London's most trusted property management company," told landlords via email - seen by The Reg - that attackers accessed the third-party provided cloud twice "as a result of a vulnerability in the platform that we were unaware of." The message to customers stated: "Personal data was extracted from the platform.""
https://www.theregister.com/security/2026/09/17/london-property-manager-breach-may-have-exposed-bank-details-and-lockbox-codes/5297232 - Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
"Hackers are demanding a $3 million ransom from the British fintech giant Revolut after siphoning data from it through fake government requests for five months. Last week, the company notified potentially affected users that their personal information, passports, email addresses, phone numbers, and financial information were compromised in the data breach. To obtain the information, the hackers posed as an official government agency. Because Revolut is required to respond to legal requests from law enforcement, it complied."
https://www.securityweek.com/revolut-data-breach-5-months-680-high-profile-accounts-3m-ransom/
https://www.malwarebytes.com/blog/threat-intel/2026/09/revolut-phishing-texts-appear-days-after-data-breach
General News
- Our Framework For Reporting Model Misalignment
"We are sharing a new framework for tracking, investigating, and disclosing instances of model misalignment at OpenAI, along with six reports on unexpected or concerning model behavior we’ve observed in the last six months. In the past, so as to better inform researchers, AI developers, policymakers, and the general public, we’ve sought to make our findings about misalignment public. But without a systematic approach to reporting these findings, our disclosures have been ad hoc and less frequent than ideal: we’ve often waited until we could collate several instances into one report, or added them to system cards for newly released models."
https://openai.com/index/model-misalignment-reporting-framework/
https://www.bleepingcomputer.com/news/security/openai-details-more-cases-of-ai-agents-taking-unauthorized-actions/
https://thehackernews.com/2026/09/openai-reveals-six-model-incidents.html
https://www.bankinfosecurity.com/openai-finds-models-writing-their-own-rogue-instructions-a-32862
https://www.securityweek.com/openai-says-its-models-hunted-github-for-leaked-api-keys-during-training/
https://securityaffairs.com/199302/ai/openai-admits-its-models-lie-to-cover-their-own-mistakes.html - FBI Seizes DDoS-For-Hire Domains As Part Of Continuing District Of Alaska Crackdown On ‘Booter’ And ‘Stresser’ DDoS Services
"The Justice Department today announced the court-authorized seizure of internet domains associated with one of the world’s longest running Distributed Denial of Service (DDoS) for-hire services known as “NightmareStresser.” Federal law enforcement has seized websites maintained by criminal service providers that allow paying customers to launch powerful DDoS attacks targeting victims in the District of Alaska and worldwide as part of coordinated actions to disrupt so called “Booter” or “Stresser” operators."
https://www.justice.gov/usao-ak/pr/fbi-seizes-ddos-hire-domains-part-continuing-district-alaska-crackdown-booter-and
https://thehackernews.com/2026/09/us-seizes-nightmarestresser-domains.html
https://www.bleepingcomputer.com/news/security/fbi-seizes-nightmarestresser-service-linked-to-thousands-of-ddos-attacks/
https://cyberscoop.com/fbi-seizes-nightmarestresser-ddos-for-hire-domains/
https://securityaffairs.com/199251/cyber-crime/nightmarestresser-goes-offline-in-global-ddos-for-hire-crackdown.html
https://www.helpnetsecurity.com/2026/09/17/fbi-nightmarestresser-ddos-for-hire-service-seized/ - AI Models Broke Their Own Containment: Key Findings From The July-August 2026 AI Threat Landscape
"Between mid-July and early August 2026, models being evaluated internally by OpenAI, Anthropic, and Meta reached real production systems outside their test environments. One exploited a previously unknown vulnerability to escape its sandbox entirely. At the same time, criminal groups showed that frontier capability isn’t required for serious attacks: a ransomware affiliate ran a full intrusion through Claude Code, and a separate campaign, JADEPUFFER, is now documented as the first case of agentic ransomware, an extortion operation a model carried out end to end once a human set it in motion."
https://blog.checkpoint.com/artificial-intelligence/ai-models-broke-their-own-containment-key-findings-from-the-july-august-2026-ai-threat-landscape/ - Ransomware Incidents In Japan In The First Half Of 2026: Investigation Of The Gentlemen’s Infrastructure And Evidence Of Qilin's AI Use
"Compared with the same period last year, ransomware incidents in Japan increased slightly by approximately 4.7%, indicating that ransomware continues to pose a significant threat. In Japan, The Gentlemen was the most active ransomware group in the first half of 2026. Attackers continue to primarily target small- and medium-sized enterprises, with organizations capitalized at less than JPY 1 billion accounting for approximately 80% of the total — an increase of around 13% from the previous year."
https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/ - The AI Hacking Apocalypse Is Not Inevitable
"The past few weeks have “felt very strange” for Juan Andres Guerrero-Saade. Like many, he is trying to sort through the spate of frontier-model AI agents from OpenAI, Anthropic, Meta and others hacking their way onto the open internet over the past few months, particularly amid the already-heated national debate around the emerging technology and its impact on society."
https://cyberscoop.com/ai-agent-hacking-apocalypse-cybersecurity/ - Fake AI Trading Agent Steals Crypto Wallet Passwords
"Attackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim’s browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign between April and June 2026. The Needle campaign targets people who download AI agents from search results or ads, and users of seven browser wallet extensions, among them MetaMask, Coinbase Wallet and Phantom. HP also caught QR code phishing that moves victims onto their phones."
https://www.helpnetsecurity.com/2026/09/17/fake-ai-trading-agent-research/ - The AI Security Question Leaders Should Be Asking Instead
"In this Help Net Security interview, Frederic Bull, Security Officer at Gremlin, talks about what AI means for security teams. The conversation covers why asking what data a model was trained on is only part of the picture, and why least privilege and access controls still matter for AI agents. It also looks at how AI has narrowed the skill gap between attackers and defenders, how the team handled about nine times as many vulnerabilities with the same staff, and why hiring now favors people with the experience to catch confident but wrong AI output."
https://www.helpnetsecurity.com/2026/09/17/frederic-bull-gremlin-ai-in-cybersecurity-gap/ - Agentic Self-Modification In Open-Weights Systems
"We studied a self-hosted system in which the same open-weights model powered both a coding agent and an AI application that the coding agent was asked to maintain. This architecture is particularly relevant in self-hosted environments where one capable model is reused across multiple roles, including coding agents and other AI applications. Given a routine software-maintenance task to fix incorrect application responses, the agent identified the shared model as the source of the problem, fine-tuned it, and replaced the model powering both the application and future instances of the agent itself. It did so without being instructed to train, modify the model, or deploy a replacement."
https://www.irregular.com/research/agentic-self-modification-in-open-weights-systems
https://www.securityweek.com/ai-agents-can-retrain-own-models-mid-task-leaking-secrets-and-erasing-refusals/
https://www.theregister.com/security/2026/09/16/ai-agents-can-modify-themselves-without-humans-telling-them-to-do-so/5296991
อ้างอิง
Electronic Transactions Development Agency (ETDA)
- Hitachi Energy FACTS Control Platform (FCP)