Cyber Threat Intelligence 14 September 2026
-
Vulnerabilities
- Artifactory Under Attack: In-The-Wild Exploitation Of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
"Wiz Research has identified active, in-the-wild exploitation of three critical and high-severity vulnerabilities affecting JFrog Artifactory: CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329. Attackers are chaining these vulnerabilities to bypass authentication, escalate privileges, and gain administrative control over vulnerable Artifactory instances. Observed post-exploitation activity includes the creation of persistent administrator accounts, the deployment of malicious Groovy plugins for code execution, and the installation of Rust-based backdoors to establish persistence. This blogpost provides an analysis of the exploitation patterns observed, the impact on affected organizations, and actionable guidance for security teams to detect and remediate these threats."
https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201
https://www.bleepingcomputer.com/news/security/artifactory-flaws-chained-in-attacks-deploying-backdoor-malware/
https://thehackernews.com/2026/09/attackers-chain-jfrog-artifactory-flaws.html
https://www.theregister.com/security/2026/09/11/more-jfrog-artifactory-bugs-under-attack-and-all-3-have-patches/5295943 - GitLab Urges Users To Patch Max Severity Path Traversal Flaw
"GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. The security flaw, discovered by a security researcher using the 's3ntago' handle and reported via GitLab's HackerOne bug bounty program, stems from improper path confinement and missing authentication enforcement in the repository commits API. Unauthenticated attackers can exploit CVE-2026-85706 "under certain conditions" to read arbitrary data (e.g., credentials, secrets, and sensitive information) from vulnerable servers."
https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/
https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html
https://cyberscoop.com/gitlab-critical-flaws-path-traversal-scans/
https://www.securityweek.com/gitlab-vulnerability-exploited-one-day-after-disclosure/
https://securityaffairs.com/198945/hacking/gitlab-cve-2026-85706-one-http-request-no-authentication-full-file-read-exploited-within-24-hours.html - PaperCut Replaces Emergency Patches With Fixes For Two Actively Exploited Flaws
"PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. "These are Regular Maintenance Releases (MR) that have gone through complete QA testing," it said. "They contain all of the security fixes issued in Emergency Patch Releases 1, 2 and 3, plus additional security hardening, and they have been through our standard release testing process.""
https://thehackernews.com/2026/09/papercut-replaces-emergency-patches.html
https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ - CISA Adds Three Known Exploited Vulnerabilities To Catalog
"CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability
CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability
CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability"
https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog
https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html - CISA Adds One Known Exploited Vulnerability To Catalog
"CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability"
https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog - GuardBreaker: Derailing AI-Assisted Malware Analysis With a Code Comment
"Malware developers have long adapted their code and tactics to the defenses and scrutiny that are likely to stand in their way. Using various evasion and anti-analysis methods, they routinely attempt to hinder code analysis or prevent their malware from revealing its true behavior while under inspection. Other tools – notably, EDR killers, documented extensively by ESET researchers – go straight after security solutions themselves. As LLM-based tools increasingly assist with various security tasks, including code triage and analysis, it was only a matter of time before threat actors began to look for practical ways to subvert them, too. Alongside conventional evasion techniques, some are taking a different tack: the adversarial input that’s intended to frustrate analysis is left in plain sight."
https://www.welivesecurity.com/en/business-security/guardbreaker-derailing-ai-assisted-malware-analysis-code-comment/
https://www.darkreading.com/cyber-risk/ai-governance-cannot-wait - Direct Send: How Attackers Weaponize Your Infrastructure Against You
"An employee at your company receives an email from [email protected]. The domain matches. There is no warning banner. The message asks them to review a payment approval document. They click. That email was never sent by your HR team. An attacker sent it, and your own Microsoft email infrastructure delivered it, with no password and no credentials required."
https://blog.knowbe4.com/direct-send-how-attackers-weaponize-your-infrastructure-against-you
https://www.infosecurity-magazine.com/news/hackers-us-business-hours-m365/ - The Exposed AI Supply Chain — Mysterium VPN Research
"36,769 self-hosted AI endpoints across model servers, agent builders, and vector stores are reachable and identify themselves in a single scanning index. Only 2.02% return an HTTP authentication challenge; for the overwhelming majority, there’s no network-layer gate whatsoever. Open WebUI: 18,529 reachable, 1 behind a gate: The most widely deployed local-LLM front-end has, as a population, no perimeter."
https://www.mysteriumvpn.com/blog/data-and-research/we-exposed-ai-supply-chain
https://securityaffairs.com/198898/ai/the-ai-supply-chain-has-a-security-problem-and-much-of-it-is-sitting-on-the-open-internet.html
Malware
- Protecting Organizations From AI-Assisted Executive Impersonation And Invoice Fraud
"Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims, deploying techniques that impersonate internally sent emails from executive team members. While this technique is not new, the adoption of AI has enabled threat actors to improve their campaign templates and construct emails tailored to their recipients. Additionally, threat actors are incorporating multiple techniques within the same email to improve the overall narrative further."
https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/
https://www.darkreading.com/cyberattacks-data-breaches/1m-personalized-fraud-emails-3-days
https://therecord.media/invoice-scam-emails-new-features-microsoft-researchers
https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html - Gray Rabbits And The Tale Of a One-Click Backdoor
"Gen Threat Labs discovered a critical remote code execution vulnerability (CVE-2026-51990) in Sogou Input Method, one of the most widely used Chinese-language input method editors with hundreds of millions of installations. The vulnerability chains three separate weaknesses into a single, one-click exploit: unvalidated command-line argument injection in the sgbiz: custom protocol handler, unrestricted URL navigation in a CEF-based webview, and a severely outdated, unsandboxed Chromium browser engine. We observed this vulnerability actively exploited in the wild by the UNC3569 threat group to deploy the GRAYRABBIT backdoor through a crafted link."
https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou
https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html
https://www.bleepingcomputer.com/news/security/hackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware/
MacSync: The Evasive MacOS Stealer Exploiting ClickFix Lures
"MacSync Stealer is a family of macOS information stealers and remote-access stagers designed to evade detection and sold commercially under a malware-as-a-service (MaaS) model. In the attack chain, MacSync binaries are native stagers and multi-part exfiltration engines. Rather than standalone harvesters, the payloads are lightweight 64-bit Mach-O executables that detach silently from terminal sessions, load credential-dumping modules directly into memory, and reliably exfiltrate stolen credentials back to campaign infrastructure."
https://www.seqrite.com/blog/macsync-the-evasive-macos-stealer-exploiting-clickfix-lures/ - DarkTortilla Malware: How It Works And How To Test Your Defenses
"DarkTortilla is a highly configurable .NET-based crypter and multi-stage loader active since at least August 2015. It targets Windows systems, spreading through logistics-themed phishing emails. Unlike typical loaders, DarkTortilla hides its encrypted configuration inside bitmap pixel data and can pull its core processor DLL from public paste sites. It runs payloads only inside injected legitimate processes, applies three interchangeable persistence mechanisms, and pairs a WatchDog executable with the loader so each restarts the other."
https://www.picussecurity.com/resource/blog/darktortilla-malware-how-it-works-and-how-to-test-your-defenses - I Just Trusted The Security Certificate Prompt… Beware Of The LegionLoader Malware Being Distributed Via The ClickFix Method
"The AhnLab SEcurity intelligence Center (ASEC) recently identified the LegionLoader malware, which is currently being distributed via the ClickFix method. There are two main distribution methods identified so far; both involve tricking users into visiting a malicious URL and then prompting them to directly execute malicious PowerShell commands through a fake Cloudflare CAPTCHA screen."
https://asec.ahnlab.com/en/95374/ - OpenAI Agents Linked To RubyGems Campaign That Gained RCE On RubyDoc Servers
"The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the Ruby programming language with hundreds of junk gems, prompting the maintainers to suspend new user sign-ups for about four days."
https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html
https://www.rubyhack.ai/
Breaches/Hacks/Leaks
- Novo Nordisk Data Breach Tied To Stolen GitHub Access Tokens
"Hardcoded credentials recovered from corporate cloud environments are giving hackers ongoing, easy access to experimental drug data, customer records and more. Cyber extortionist group FulcrumSec, which specializes in ransoming sensitive data, continues to employ this strategy, going so far as to dub it the "Hardcoded Horrorshow." The group's victims have included England's Manchester Airport Groups, London-based consultancy Arup Group and Singapore-based Global Schools Group, among others."
https://www.bankinfosecurity.com/novo-nordisk-data-breach-tied-to-stolen-github-access-tokens-a-32802 - UK Council Attack Linked To Mass Exploitation Of SonicWall Flaw
"On July 17, 2026, the Borough Council of King’s Lynn and West Norfolk announced it had detected a cyberattack affecting council services. Hunt.io has since published a detailed technical analysis linking that incident, with moderate confidence, to a wider mass-exploitation campaign against SonicWall SMA1000 appliances using CVE-2026-15409, a maximum-severity SSRF flaw that received a CVSS score of 10.0."
https://securityaffairs.com/198864/hacking/uk-council-attack-linked-to-mass-exploitation-of-sonicwall-flaw.html - Revolut Confirms Customer Data Breach Through Fake Government Requests
"British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. The exposed data included customers’ identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver’s licenses, according to a notification emailed to affected customers and reviewed by TechCrunch. The data may have also included verification selfies, account statements, and transaction histories, the firm said in its notification."
https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/
https://securityaffairs.com/198922/data-breach/revolut-exposed-kyc-data-after-fraudulent-government-email-passed-security-checks.html
General News
- Why AI Is So Good At Scamming Humans
"If there's one thing that AI models are remarkably good at, it's manipulation. That's according to security researcher Fred Heiding, who spoke with Dark Reading's senior news director, Rob Wright, at the Dark Reading News Desk at Black Hat USA 2026 last month. Heiding, executive director at Menlo Park Intelligence, and former US National Cyber Director Chris Inglis, spoke at the conference about their research on AI security."
https://www.darkreading.com/cyber-risk/ai-scamming-humans - Phishing Research Challenges Conventional Security Awareness Testing
"The message is simple: fine-tune future in-house phishing simulation tests through the findings and analysis of Pistachio’s research. Pistachio was founded in Oslo Norway in 2019, with additional offices in London and Valencia. It specializes in automated human risk management, employee security awareness training, and phishing simulations. Between 1 June, 2025 and 31 May, 2026, Pistachio sent 2.47 million simulated phishing attempts to more than 123,000 employees in more than 1,200 organizations. Its subsequent analysis looked at clicking, leaking, and reporting."
https://www.securityweek.com/phishing-research-challenges-conventional-security-awareness-testing/
https://hs-5440974.f.hubspotemail.net/hubfs/5440974/The-Phishing-Behaviour-Report-2026-Pistachio.pdf
https://www.helpnetsecurity.com/2026/09/11/pistachio-employee-phishing-risk-report/ - AI Is Changing What Salesforce Security Needs To Govern
"Existing security and governance practices have largely focused on identities, permissions, access, configurations and controls. WithSecure’s Navigating Trust in the Modern Salesforce Ecosystem paper says Salesforce environments also require organizations to understand what information they rely on, how trust extends across connected systems, what actions are performed and what outcomes those actions produce."
https://www.helpnetsecurity.com/2026/09/11/withsecure-salesforce-ai-trust-governance-paper/ - Most Organizations Skip Permissions Reviews Before Deploying AI Tools
"AI is being deployed faster than the data foundation beneath it is being checked, a new Syskit study has revealed. In its latest State of Microsoft 365 Governance Report, published on September 10, security governance firm Syskit has found that three-quarters (76%) of organizations in the UK and the US have deployed or piloted an enterprise AI tool such as Copilot on Microsoft 365 data. Despite this wide adoption, only 43% of respondents confirmed they had completed a thorough review of permissions and oversharing risk before deploying these tools. The rest admitted to only having run a partial review or none at all."
https://www.infosecurity-magazine.com/news/organizations-skip-permissions-ai/
https://www.syskit.com/ebooks/state-of-m365-governance-report-2026 - Anthropic CEO Dario Amodei Says AI Industry Needs To Give Safety Measures Time To Catch Up
"The CEO of Anthropic said Saturday the artificial-intelligence industry should slow its fast-moving development to give safety measures time to catch up. Without such a slowdown, Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet. The warning comes as worries about AI grow inside and outside the industry and reports continue to emerge about increasingly powerful systems that solve problems beyond human capacity but could also go rogue and carry out other, more harmful tasks. The worries have grown so loud that the CEO of OpenAI, the company behind ChatGPT, said in an interview with Fortune that his company would wait until next year to start selling its stock to investors on Wall Street as it focuses on safety."
https://www.securityweek.com/anthropic-ceo-dario-amodei-says-ai-industry-needs-to-give-safety-measures-time-to-catch-up/ - August 2026 Dark Web Breach Incident Trend Report
"In August 2026, widespread instances of database leaks, the sale of internal data, and the trading of initial access privileges were observed on dark web and deep web forums. Due to the nature of the sources, it was difficult to fully verify the accuracy of some posts."
https://asec.ahnlab.com/en/95385/ - August 2026 Dark Web Threat Actor Trend Report
"The August 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—active on the deep web and dark web. It is noted that the accuracy of some information could not be verified."
https://asec.ahnlab.com/en/95390/ - August 2026 Dark Web Issue Trend Report
"The August 2026 Dark Web Issue Trend Report summarizes Major Issues that occurred on the deep web and dark web. The report notes that, due to the nature of its sources, it may contain some information whose accuracy cannot be fully verified."
https://asec.ahnlab.com/en/95391/
อ้างอิง
Electronic Transactions Development Agency (ETDA)
- Artifactory Under Attack: In-The-Wild Exploitation Of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329