Cyber Threat Intelligence 11 September 2026
-
Healthcare Sector
- NextGen Healthcare Mirth Connect
"Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition."
https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-01
https://www.bankinfosecurity.com/nextgen-mirth-connect-flaws-expose-downstream-system-logins-a-32789 - Orthanc DICOM Server
"Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition."
https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-02
Industrial Sector
- AVEVA Pipeline Integrity Monitor
"Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-253-01
Vulnerabilities
- Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
"Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security Management Server, the console used to configure them. Check Point disclosed the flaws on September 9 in a notice to its customer community, and began delivering fixes the same day. The company says it found both itself and has no indication that either has been used in an attack."
https://thehackernews.com/2026/09/check-point-discloses-two-98-rated-vpn.html - CISA Adds Two Known Exploited Vulnerabilities To Catalog
"CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability"
https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog - Off Guard: Breaking LiteLLM From Authentication Bypass To Cloud Compromise
"Nearly 1 in 10 publicly accessible LiteLLM instances accept a default master key or require no authentication at all. We found this while scanning roughly 3,000 internet-facing deployments of the most popular open-source LLM gateway. The usual concern with that kind of exposure is LLMjacking -someone using the credentials to run API calls on your bill - however, we wanted to check whether an attacker could do worse than that: could they achieve code execution on the host? Furthermore, could they exploit this to compromise the wider environment? We decided to use Claude Code to work through LiteLLM's codebase, looking for features that accept user-controlled input and pass it to an execution context. We found multiple issues, as detailed below."
https://www.wiz.io/blog/off-guard-breaking-litellm-from-authentication-bypass-to-cloud-compromise
https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html
Malware
- Mantax Otax: Indonesian Mobile Ransomware With Spyware Integration
"The zLabs research team has discovered a sophisticated and highly aggressive mobile malware strain linked to Indonesian threat actors, that marks a dangerous tactical evolution by seamlessly integrating comprehensive spyware capabilities with traditional ransomware functionality into a single attack vector. This hybrid threat systematically compromises user privacy through an intrusive suite of surveillance features, which includes recording device screens in real-time, extracting browser history, stealing lock screen PINs, harvesting contact lists, call logs, and SMS messages, exfiltrating local files, and capturing unauthorized photographs."
https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration
https://www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/
https://www.darkreading.com/mobile-security/indonesia-android-banking-app-cloning-campaign
https://www.infosecurity-magazine.com/news/mantaxotax-android-malware/ - CISA: WatchGuard RCE Flaw Now Exploited In Ransomware Attacks
"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. This flaw is tracked as CVE-2025-14733 and stems from an out-of-bounds write allowing unauthenticated threat actors to execute malicious code remotely in low-complexity attacks. This vulnerability affects firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and 2025.1 through 2025.1.3."
https://www.bleepingcomputer.com/news/security/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks/ - PuzzleMask: The Prompt Injection Hiding In Plain Sight
"Most prompt injection detection is built to catch the obvious. Encoding anomalies, invisible unicode, emoji smuggling, the signatures a classifier can pattern match against. PuzzleMask, a newly disclosed technique, sidesteps all of it. It embeds a policy-violating payload inside fluent, properly punctuated prose, and gets that payload past an LLM-based gatekeeper without tripping any heuristics naively looking for obfuscation on the input side."
https://blog.checkpoint.com/security/puzzlemask-the-prompt-injection-hiding-in-plain-sight/
https://research.checkpoint.com/2026/puzzlemask-abusing-plain-prose-as-a-covert-ai-attack-vector/ - False Allegations, Real Threats: Sexual Misconduct Claims Used As Phishing Lures
"Threat actors are impersonating leaders of partner universities in emails alleging a sexual misconduct violation has occurred, using sensitive claims to trick victims into installing abused, technically legitimate Remote Access Tools (RATs) on their computers. The alleged misconduct case is entirely fabricated, serving as a façade for delivering malware."
https://cofense.com/blog/false-allegations,-real-threats-sexual-misconduct-claims-used-as-phishing-lures - From Infostealer Log To Marketplace Listing: A Technical Walkthrough Of The Credential Theft Pipeline
"Infostealer malware is behind a large share of today’s credential compromise — and it usually doesn’t start with a breach at all. When a security team hears “data breach,” the instinct is to look for the moment a database was exfiltrated or a network was penetrated. But more often, the real starting point is a single endpoint infection, often on a personal device, that has nothing to do with the organization’s perimeter. By the time stolen credentials show up in a breach notification or a dark web alert, they’ve already passed through several distinct, mechanical stages. Understanding that pipeline — rather than waiting for the final alert — is what separates reactive security teams from ones that catch exposure early."
https://cyble.com/blog/infostealer-malware-credential-theft-pipeline/ - Passkey-Themed Social Engineering Leads To Identity And Cloud Compromise
"Microsoft Security Research is tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins were followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and email collection through REST APIs. Microsoft Security Research assesses that this sequence is consistent with automated collection from compromised cloud identities using proxy-associated infrastructure, the activity has been observed since May 2026."
https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/
https://www.darkreading.com/threat-intelligence/voice-callers-exploit-byod-microsoft-365-corporate-data
https://www.helpnetsecurity.com/2026/09/10/microsoft-365-social-engineering-personal-phones/ - Casbaneiro: A Banking Trojan With Distributed Data-Receiving Servers
"In August 2026, FortiGuard Labs observed a Casbaneiro attack campaign targeting users in Latin America, using phishing emails and PDF files themed around fake invoices and legal notices as the initial stage. Casbaneiro exhibits characteristics common to other malware families targeting financial institutions and users in Latin America, including clipboard injection and the use of fake windows to facilitate fraudulent activities. However, our analysis of the recent attack revealed several distinctive network behaviors that differentiate this campaign from previously observed Casbaneiro behavior."
https://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers - Grand Theft Auto VI Hype Leads To Malware
"Threat actors are taking advantage of overeager gamers searching for a leaked version of the upcoming Grand Theft Auto VI (GTA6), using fake game downloads as an initial access lure. Huntress has seen several examples of SEO poisoning designed to rank highly in searches for GTA6, as well as ISOs published on gaming forums, social media, and various torrenting sites. Huntress analyzed an ISO file masquerading as a leaked version of GTA6 found in a sandbox. The package includes a fake installer, several RATs, an infostealer, ransomware being used as a wiper, and a web browser. Based on the language in the initial prompts and eventual ransom note, the malware appears to be targeting Russian gamers."
https://www.huntress.com/blog/fake-gta6-download-malware-analysis
https://www.helpnetsecurity.com/2026/09/10/fake-gta-6-downloads-malware-ransomware/ - SloppyRAT: A New Tool For Ransomware Attacks
"In June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. ThreatLabz observed SloppyRAT being delivered through a multi-stage ClickFix infection chain. The malware supports a variety of features including a large number of built-in PowerShell-like commands, encrypted code blocks, EtherHiding for command-and-control (C2) resolution through the Polygon JSON-RPC protocol, and multiple anti-analysis techniques. Beyond SloppyRAT’s capabilities, the malware is notable because the codebase includes numerous software flaws, which suggest that it is still under development."
https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks - Google Play's Early Access Program May Be Exploited By Potentially Deceptive Apps
"An analysis of Google Play apps installed by Bitdefender users reveals thousands of Early Access applications that appear to include fake casino games and reward apps, as well as titles that may infringe on third-party trademarks and potentially misleading utilities. Many are aggressively promoted through TikTok, Facebook, and other social media platforms using misleading advertisements that include videos using AI-generated celebrity deepfakes. The result is an ecosystem in which consumers have almost no way to warn one another before installing questionable software."
https://www.bitdefender.com/en-au/blog/hotforsecurity/google-play-early-access-exploit-deceptive-apps
https://thehackernews.com/2026/09/google-play-early-access-abused-to-push.html
https://www.securityweek.com/deceptive-android-apps-exploit-google-play-early-access-to-evade-reviews/ - Trezor Warns Users Of Email Provider Breach, Phishing Attacks
"Cryptocurrency hardware wallet maker Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. Affected customers received fake "critical security alert" emails from [email protected] claiming that a "hardware microcontroller vulnerability" in the STM32 microcontrollers used by Trezor cold storage wallets could expose their seeds to brute-force cracking. The company said that it's investigating the breach and that the domain has been taken down to stop the attacks."
https://www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/
https://therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders
https://www.helpnetsecurity.com/2026/09/08/trezor-shipping-partner-breach-phishing-attacks/ - The Machine With Many Faces: Post-Exploitation Identity Misuse In SPIFFE/SPIRE
"This research demonstrates post-exploitation techniques that could allow an attacker with root access on a compromised Kubernetes node to misuse an open standard and reference implementation for machine identity known as SPIFFE/SPIRE to impersonate co-located workloads and harvest SPIFFE Verifiable Identity Documents (SVIDs). We show how the trust assumption at the core of every machine-identity system — that the node is trusted — collapses once an attacker obtains root on that node. Unit 42 has not observed this technique exploited in the wild."
https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ - CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT
"One of the most common entry points for attackers is the exploitation of public-facing edge devices (such as VPNs, routers, and firewalls). Over the years, FortiGate firewalls have remained a consistent target, as evidenced by the recent widespread FortiBleed campaign conducted jointly by the INC and Lynx ransomware groups. The SOCRadar Threat Research Unit (STRU) identified, with high confidence, exploitation of CVE-2025-25249, a heap-based buffer overflow vulnerability in FortiOS and FortiSwitchManager cw_acd daemon. Successful exploitation delivers PivotC2, a Node.js Remote Access Trojan (RAT) designed specifically as a FortiGate post-exploitation tool. PivotC2 supports features such as interactive shells, tunneling, network scanning, and configuration harvesting."
https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/
https://www.securityweek.com/fortinet-code-execution-flaw-exploited-in-pivotc2-rat-attacks/ - Shai-Hulud Rises From The Dead After 111 Days
"Hello internet, Do you remember the Shai-Hulud attack that hit @AntV on May 19th, 2026? I know, it feels like a lifetime ago by now in the supply chain world. A compromised maintainer account pushed 639 malicious versions of @antv packages to npm in a single hour. We, along with most of the npm security community, tore that payload apart within hours. It was nothing novel, technique-wise. It was just another day of waking up and there being a supply chain attack. Business as usual."
https://www.aikido.dev/blog/shai-hulud-npm-resurfaces
Breaches/Hacks/Leaks
- Surfshark VPN Says Hackers Breached Internal Testing, Proxy Servers
"Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. The VPN service provider said the incident did not affect its customers and did not extend to other parts of its infrastructure, but it exposed service configurations and build-related credentials. “Due to a human error, an internal test server used by our engineering teams was misconfigured in a way that made it reachable from the internet,” Surfshark explained on its website."
https://www.bleepingcomputer.com/news/security/surfshark-vpn-says-hackers-breached-internal-testing-proxy-servers/ - An Alignment Assessment Of Recent Cybersecurity Incidents
"We present an alignment assessment of four incidents in which Claude models gained unauthorized access to real third-party systems. We described three of these incidents on July 30; we identified these after a scan of roughly 141,000 transcripts in which we believed Claude could have obtained internet access during a cyber evaluation. Given the volume of transcripts and our desire to disclose incidents quickly, our scan relied on an agentic search. This missed a set of transcripts that also turned out to have internet access; we identified these in August while assembling transcripts to share with METR. We scanned these transcripts and identified a fourth incident, from January 2026, involving an early version of Claude Opus 4.6. We have notified all affected parties."
https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents
https://thehackernews.com/2026/09/anthropic-ai-models-breached-real.html
https://www.infosecurity-magazine.com/news/anthropic-another-cybersecurity/
https://www.theregister.com/ai-and-ml/2026/09/10/anthropic-reveals-fourth-likely-crime-committed-by-its-ai/5295412
https://www.securityweek.com/widened-scan-turns-up-fourth-rogue-claude-cyber-incident/
https://securityaffairs.com/198814/hacking/a-new-claude-s-sandbox-failure-shows-how-ai-can-rationalize-real-world-harm.html - IDScan Confirms Breach After Hackers Offer 153 Million Driver’s License Scans For Sale
"Identity verification firm IDScan said hackers obtained customer data held in its cloud platform following recent reports connecting the company to a database breach exposing scans of some 153 million driver’s licenses. The company confirmed a hack in a notice published on its website on September 4 and said it became aware of the breach on or around September 1 — the same day a journalist reported the news based on dark web activity."
https://therecord.media/idscan-data-breach-notice-drivers-licenses
https://www.bleepingcomputer.com/news/security/idscan-confirms-breach-tied-to-153-million-stolen-drivers-licenses/ - ShinyHunters Expose 6.4M In Attack On Medical Supplier McKesson
"McKesson's cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP). The breach notification service added data leaked by serial extortionists ShinyHunters, revealing the scale of the attack for the first time. ShinyHunters initially claimed to have stolen 284 million documents from the medical and pharmaceutical supply company in August, although HIBP did not confirm that figure."
https://www.theregister.com/security/2026/09/10/shinyhunters-expose-64m-in-attack-on-medical-supplier-mckesson/5295550
General News
- Ukrainian National Sentenced To Four Years In Prison For Wire Fraud Conspiracy In Connection With Conti Ransomware
"Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, was sentenced today to four years in prison for conspiracy to commit wire fraud in connection with a conspiracy to deploy Conti, a ransomware variant that infected the computers of more than 1,000 victims worldwide. According to court documents, Lytvynenko, formerly of Cork, Ireland, conspired with others to deploy Conti ransomware to extort victims and steal their data. From 2020 until 2022, Conti was used to attack computers and networks in 47 states, 31 foreign countries, the District of Columbia, and Puerto Rico. The FBI estimates that, as of January 2022, there had been victim payouts associated with Conti ransomware exceeding $150,000,000."
https://www.justice.gov/opa/pr/ukrainian-national-sentenced-four-years-prison-wire-fraud-conspiracy-connection-conti
https://cyberscoop.com/conti-ransomware-developer-sentenced/ - Detecting And Countering Misuse Of AI: September 2026
"Over the past eight months, our Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity. In this report, we share case studies from those operations and describe how malicious use of Claude has evolved since our previous threat reports in March, August, and November 2025. In each case, we disrupted the activity, used what we learned to strengthen our safeguards, and shared intelligence with authorities and industry partners, where appropriate."
https://www.anthropic.com/threat-intelligence-report-september-2026
https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf
https://cyberscoop.com/anthropic-report-ai-enabled-cyber-attacks/ - AI Adoption Brings New Security Headaches For Already Stretched CISOs
"CISOs are taking on AI governance without a matching increase in resources or expertise, adding to an already broad remit spanning data protection, identity, resilience and compliance, according to Proofpoint’s 2026 Voice of the CISO report. GenAI is creating new concerns around sensitive data, access and employee activity. Seventy-eight percent of CISOs consider it a security risk, with the potential loss of customer data through public AI platforms a key concern."
https://www.helpnetsecurity.com/2026/09/10/proofpoint-ciso-ai-security-risks-report/ - CISA Updates Insider Threat Guide With New Mitigation Advice
"The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Insider Threat Mitigation Guide with new case studies, statistics and guidance on hybrid and remote work, artificial intelligence and adverse employee separations. The agency published the revision on September 9. First issued in 2020, the guide supports security and human resources professionals who run insider threat programs, along with leaders at any level, and CISA said any organization can use it regardless of the maturity of its security."
https://www.infosecurity-magazine.com/news/cisa-updates-insider-threat-guide/ - More Capable AI, Not Enough Guardrails
"Jacob Coxon, a researcher who spent three years working on model training at OpenAI and later Anthropic, left Anthropic this week with a blunt warning: AI companies are moving toward increasingly capable systems faster than they can build reliable safeguards around them. I resigned from Anthropic today. I spent the last three years doing pretraining research at both OpenAI and Anthropic. Neither company is acting responsibly. They are racing straight to self-improving superintelligence and gambling with our lives. More thoughts below."
https://securityaffairs.com/198833/ai/more-capable-ai-not-enough-guardrails.html
อ้างอิง
Electronic Transactions Development Agency (ETDA)
- NextGen Healthcare Mirth Connect