Cyber Threat Intelligence 08 September 2026
-
New Tooling
- ToolHive: The Open-Source Way To Run Any MCP Server Securely
"ToolHive is an open-source platform that runs Model Context Protocol servers inside containers. An MCP server is the connector that lets an AI client like Cursor or Claude Code reach an outside tool, and Stacklok ships ToolHive under Apache 2.0, so the runtime, the Kubernetes operator, and the registry cost nothing to self-host. A server you install by hand sits on the machine with the machine’s credentials and the machine’s network access. ToolHive drops each one into its own container with a minimal permission file and no local credentials attached. Point it at an authentication source and it starts enforcing identity and access policy per request, with audit logs to match. Don’t, and you have a sandbox and not much else."
https://www.helpnetsecurity.com/2026/09/07/toolhive-open-source-mcp-server-security/
https://github.com/stacklok/toolhive
Vulnerabilities
- N-Able Patches Max Severity N-Central Flaw Amid Ongoing Attacks
"N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform. IT departments and managed service providers (MSPs) use the N-central platform to monitor, manage, and maintain client networks and devices from a centralized web-based console. Tracked as CVE-2026-86218, this RCE vulnerability allows threat actors without privileges to execute malicious code on unpatched N-central instances exposed online in low-complexity attacks."
https://www.bleepingcomputer.com/news/security/n-able-patches-max-severity-n-central-flaw-amid-ongoing-attacks/
https://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html
https://www.infosecurity-magazine.com/news/nable-hotfix-critical-rce/
https://www.helpnetsecurity.com/2026/09/07/n-able-n-central-hotfix-cve-2026-86218/ - ConnectWise Warns Of New ScreenConnect Flaw Without Patch
"ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week. ScreenConnect is an on-premises or cloud-hosted remote access platform typically used by managed service providers (MSPs), IT departments, and support teams for troubleshooting, patching, and system maintenance. The security flaw affects both cloud and on-premises deployments, and it has not yet received a CVE ID for easy tracking."
https://www.bleepingcomputer.com/news/security/connectwise-warns-of-new-screenconnect-flaw-without-patch/
https://thehackernews.com/2026/09/rogue-screenconnect-clients-spread-four.html
https://www.securityweek.com/modified-screenconnect-clients-used-in-worm-like-campaign/
https://www.helpnetsecurity.com/2026/09/07/connectwise-screenconnect-file-transfer-flaw/ - LG TV Flaws Could Let Attackers Listen In, Even In Standby Mode
"Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices. In the past, we reported on Samsung settling a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR)."
https://www.malwarebytes.com/blog/privacy/2026/09/lg-tv-flaws-could-let-attackers-listen-in-even-in-standby-mode - Telerik UI Padding-Oracle Bug Chained To Unauthenticated RCE — Public Exploit Released
"Security firm TantoSec has published a working exploit chain targeting vulnerabilities in Telerik UI for ASP.NET AJAX that can allow an unauthenticated attacker to execute remote code on the server hosting a vulnerable application. Progress Software patched the flaws in July, and exploitation requires a non-default configuration — but the release pairs a detailed write-up with a ready-to-run tool and two payloads, putting a complete attack path in public hands for the first time."
https://thehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html - Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
"The security researcher known as Nightmare Eclipse has dropped three zero-day exploits targeting products from Avast, CrowdStrike, and Nvidia. Also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, the security researcher came to fame for a series of zero-day exploits targeting Microsoft’s products, but has recently moved to other vendors as well. In late August, Nightmare Eclipse released a privilege escalation zero-day in a Kaspersky endpoint security product. Dubbed HardBreacher, the exploit has been patched by Kaspersky on August 31."
https://www.securityweek.com/nightmare-eclipse-drops-crowdstrike-nvidia-avast-zero-day-exploits/
https://securityaffairs.com/198589/hacking/chaotic-eclipse-released-a-poc-for-nvidia-greensection-memory-corruption-zero-day.html
Malware
- Tracking BigBear 2.0 Evilginx2 Phishing Campaign
"CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA."
https://www.cloudsek.com/blog/tracking-bigbear-2-0-evilginx2-phishing-campaign
https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/ - NoName057(16) Renews #OpJapan
"On August 24, 2026, NoName057(16), a pro-Russian hacktivist collective active since 2022, best known for its crowdsourced DDoSia attack platform, announced the (re)launch of #OpJapan, a DDoS campaign against Japanese entities. Motivation is cited as Japan’s continued support for Ukraine and NATO amid the Russia-Ukraine war."
https://blog.checkpoint.com/exposure-management/noname05716-renews-opjapan/ - Beyond Lazarus: Organization Of DPRK Cyber Capabilities
"The Democratic People's Republic of Korea (DPRK) has established itself as one of the more prominent state actors in cyberspace. For Pyongyang, cyber operations serve as an instrument of sanctions evasion, a means of projecting reach beyond a diplomatically and economically constrained periphery, and a source of revenue for a structurally weakened economy. These capabilities are the product of a deliberate strategy, considerably reinforced under Kim Jong-un, which situates information warfare at the centre of contemporary geopolitical confrontation."
https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities
https://www.infosecurity-magazine.com/news/north-korea-lazarus-six-cyber/ - PEEP: A Browser RAT Posing As a Chrome Extension
"The Threat Research Unit (STRU) at SOCRadar’s Extended Threat Intelligence (XTI) platform identified and analyzed PEEP, a Chromium-based emerging post-exploitation toolkit disguised as “Smart Bookmarks.” Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium’s own Secure Preferences integrity values. A native-messaging tool then extends it beyond browser telemetry to host-level command execution and file management."
https://socradar.io/blog/peep-browser-rat-chrome-extension/
https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html - Fake IT Calls Target Executives In Microsoft 365 Data Theft And Extortion Attacks
"Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff, is being tracked by Arctic Wolf under the moniker PREY-0058, adding it shares significant tradecraft similarities with a data extortion group that Google-owned Mandiant calls UNC6671."
https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html
https://github.com/rtkwlf/wolf-tools/tree/main/pack_alerts/202609-cloud-data-theft-extortion-vishing-proxies - Breaking The Seal: Static Deobfuscation Of JSCeal’s Compiled V8 Bytecode
"JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early 2025. Our previous publication from July 2025 [1] focused on the campaigns, delivery chain, and targeting. In this article, we focus on the analysis problem hidden inside the final payload."
https://research.checkpoint.com/2026/breaking-the-seal-static-deobfuscation-of-jsceals-compiled-v8-bytecode/
https://thehackernews.com/2026/09/jsceal-malware-can-bypass-google.html
https://securityaffairs.com/198573/malware/jsceal-hides-crypto-malware-in-v8-bytecode.html
Breaches/Hacks/Leaks
- Mathspace Discloses Data Breach Affecting Over 1 Million People
"Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. Founded in Sydney in 2010, Mathspace is now used by thousands of schools across Australia, New Zealand, the United States, and the United Kingdom (3,432 in Australia and 3,557 abroad according to statistics reported by the company in 2023). In a Saturday blog post, Mathspace CTO Alvin Savoy said that unknown attackers gained access to the company's systems and stole personal information belonging to school staff and students, as well as their parents and guardians."
https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/ - Berlin Investigates New Data Leak After Hackers Publish Stolen Login Credentials
"German authorities are investigating another trove of data stolen from Berlin’s government network after hackers published login credentials and other information over the weekend. The latest release follows a cyberattack discovered in mid-August that compromised two Berlin ministries responsible for urban development and housing, and for transport, mobility, climate protection and the environment. Berlin’s government said Sunday that the newly released data includes login credentials but did not say what systems they could be used to access or whether they were still valid. The authorities have not attributed the attack to a specific threat actor."
https://therecord.media/germany-berlin-second-data-breach-city-agencies
https://www.bankinfosecurity.com/berlin-responds-after-data-leaked-by-cyber-extortion-group-a-32763
https://www.infosecurity-magazine.com/news/rhysida-berlin-data-extortion/
https://securityaffairs.com/198545/cyber-crime/berlin-ransomware-leak-exposes-state-secrets.html - Hackers Drain $320M In Bitcoin From Liquid Network, Claim They're The Good Guys
"Hackers have drained roughly $320 million in Bitcoin from the federation wallet backing the Liquid Network, while claiming to be the good guys. Liquid, a Bitcoin sidechain developed by Blockstream and used by exchanges and other financial institutions, said in a post on X on Sunday that around 4,000 BTC had been withdrawn from its federation wallet by what it cautiously described as "purported white-hat hackers.""
https://www.theregister.com/security/2026/09/07/hackers-drain-320m-in-bitcoin-from-liquid-network-claim-theyre-the-good-guys/5294770 - Condé Nast Data Of 32.8 Million Users Offered For Sale After WIRED Leak
"A database said to contain 32.8 million Condé Nast user records is being offered for $15,000 on a Russian-language cybercrime forum. Ransomnews reviewed a 5,000-record sample and concluded that it is consistent with genuine Condé Nast account data collected between September and late October 2025, including records that have not appeared publicly before. Ransomnews’ original report provides the underlying analysis."
https://securityaffairs.com/198628/data-breach/conde-nast-data-of-32-8-million-users-offered-for-sale-after-wired-leak.html
General News
- Qatar’s Digital Boom Has a Blind Spot: What The 2025-26 Threat Data Is Telling Us
"Qatar is racing toward a knowledge-based, fully digital economy. Smart infrastructure, cloud-first government services, a financial sector that’s increasingly API-driven, and critical energy assets like QatarEnergy’s LNG operations layering more connected OT/ICS systems every year. That pace of transformation makes Qatar an attractive target in the cyber realm, right now. Attackers don’t need to compromise everything; they just need one high-value foothold, and Qatar’s expanding digital footprint keeps handing them more doors to try. This risk is showing up in the data as well."
https://cyble.com/blog/qatar-digital-boom-blindspot/ - Zero Trust AI Agents Demand a Different Kind Of Security
"In this interview, Chris Webber, VP, Product Marketing at Teleport, explains why zero trust principles need to change for AI agents. He covers how agents act fast, unpredictably, and continuously, and why old ideas like least privilege and point-in-time verification fall short. Webber also discusses Teleport’s approach: trusted runtimes with zero starting privileges, and identity security that watches agent behavior in real time. He argues that security teams must move from spotting anomalies after the fact to enforcing rules at every step an agent takes."
https://www.helpnetsecurity.com/2026/09/07/chris-webber-teleport-zero-trust-ai-agents/ - 18 Ways To Check Whether Data Can Be Trusted For AI
"ETSI has published TR 104 180, a technical report that defines 18 metrics for measuring data quality, giving companies a way to check whether their data is good enough for AI before they use it. The report defines each metric and includes the formulas needed to calculate it. The metrics fall into four groups. The first deals with the basics, whether data is complete, accurate, consistent, and free of duplicates. The second asks whether the data can be used, meaning it’s available when needed, documented well enough to trace back to its source, and up to date."
https://www.helpnetsecurity.com/2026/09/07/etsi-ai-data-quality-metrics/ - The Hidden Risks Of Shadow AI
"Over the past few years, the use of artificial intelligence (AI) has grown rapidly in many workplaces with employees increasingly exploring how such tools can be incorporated into their jobs. AI can help people complete tasks more quickly, improve decision-making, save costs and increase productivity. However, organisations’ policies and guidance, which should reflect and manage the risks associated with using these new technologies, have not always developed at the same pace."
https://www.ncsc.gov.uk/blogs/the-hidden-risks-of-shadow-ai
https://www.infosecurity-magazine.com/news/ncsc-warns-shadow-ai-security-risks/ - Why AI Agent Sandboxes Are Failing Security Tests
"The recent case involving OpenAI test agents and Hugging Face should concern security teams, but not for the reason implied by headlines about an imminent AI “takeover.” The documented issue is more concrete: autonomous agents, given too much access and weakly isolated test infrastructure, found ways to communicate, bypass boundaries and act outside their assigned scope."
https://securityaffairs.com/198563/ai/why-ai-agent-sandboxes-are-failing-security-tests.html
อ้างอิง
Electronic Transactions Development Agency (ETDA)
- ToolHive: The Open-Source Way To Run Any MCP Server Securely