Cyber Threat Intelligence 29 September 2026
-
Financial Sector
- Security Issues In The Korean & Global Financial Sector In August 2026
"In Attack Stage 1, phishing was the highest at 2.1, Up from 1.8 The previous month. In Attack Stage 2, dropper/downloader was the highest at 1.1, Down from 3.2 The previous month. In Stage 3 of the attack, Infostealers were the most prevalent at 0.3, Down from 0.4 The previous month. WebShells, Backdoors, HackTools, Ransomware, and CoinMiners remained at low levels."
https://asec.ahnlab.com/en/95589/
Industrial Sector
- One Packet Can Crash OT Servers In Industrial Sectors
"A newly disclosed flaw in an open source database used in industrial and Internet of Things (IoT) environments could let unauthenticated attackers crash vulnerable servers with a single specially crafted network packet. The zero-day vulnerability, tracked as CVE-2026-42542 affects TDengine, a time-series database that organizations in sectors like manufacturing, energy, automotive, and IoT use to store and analyze large volumes of data collected over time. Examples of such data include readings from sensors and industrial equipment, as well as application- and infrastructure-related performance metrics."
https://www.darkreading.com/ics-ot-security/one-packet-crash-servers-tdengine
New Tooling
- Authorizer: Open-Source Authentication And Authorization For Your Apps
"Authorizer is an open-source server for sign-in and access control in web and mobile apps. Teams run it on their own infrastructure and keep user accounts in a database they choose. Its maintainers have built a permissions engine and an interface for AI agents into the same Go program that logs users in, so a chatbot can ask whether a user may see a document before it fetches that document. This affects any team that connects an AI assistant to company files. A vector search, which is the lookup that finds text similar to a question, returns close matches without checking who asked. Authorizer gives the search a list of documents the user is allowed to see, and everything else is dropped before it is scored."
https://www.helpnetsecurity.com/2026/09/28/authorizer-open-source-authentication-server/
https://github.com/authorizerdev/authorizer
Vulnerabilities
- How I Could've Accessed 17 Trillion Microsoft Records
"An estimated 17.3 trillion stored rows across a wide range of Microsoft datasets were reachable through a single internal analytics service, all because it never checked the signature on a login token. That flaw let me claim an administrator’s identity and submit unauthorized SQL queries without any real credentials. I used only table descriptions, metadata, and bounded sample rows to understand the potential scope."
https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records
https://www.helpnetsecurity.com/2026/09/28/microsoft-titan-jwt-signature-flaw/ - “Drunk” AI Is Terrible At Keeping Secrets
"AI models taught to write like drunk people became easier to jailbreak and more likely to leak secrets shared in confidence. That is the finding of UNSW Sydney researchers Anudeex Shetty, Aditya Joshi and Salil Kanhere, published in their paper “In Vino Veritas and Vulnerabilities.” “The key research question from the natural language processing (NLP) side for me was, how do we get LLMs drunk?” said Aditya Joshi, a senior lecturer at the UNSW School of Computer Science and Engineering. “And the cyber security question was, how do we measure their vulnerabilities once they are drunk?”"
https://www.helpnetsecurity.com/2026/09/28/drunk-ai-models-jailbreak-research/ - Apple Patches CoreGraphics Flaw Possibly Exploited In Targeted Attacks
"Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. The iPhone maker said the issue was addressed with improved bounds checking. It credited Meta Product Security with discovering and reporting the issue."
https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html
Malware
- Vulnerability Attack Case: Installation Of a Web Shell And Execution Of a Scanner By Exploiting a Telerik UI Vulnerability
"The AhnLab SEcurity intelligence Center (ASEC) has identified two vulnerability attack cases that exploited a remote code execution vulnerability (CVE-2019-18935) targeting unpatched Telerik UI for ASP.NET AJAX servers. In the first incident, after exploiting the vulnerability, the attacker executed a reverse shell, attempted to perform privilege escalation, and installed a web shell; in the second incident, the attacker ran a scanner tool to search for additional Attack Targets."
https://asec.ahnlab.com/en/95561/ - Storm-3168: Agentic-Driven Cloud Attacks Using Compromised Service Principals
"Microsoft Security Research has identified malicious cloud activity associated with JADEPUFFER, a threat actor discovered by Sysdig in July 2026 and reported to be the first documented agentic ransomware operation. Our investigation found an extensive Azure-focused resource destruction activity using compromised service principals and cloud credential collection that could be used to facilitate future exfiltration."
https://www.microsoft.com/en-us/security/blog/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/
https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html
https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/
https://www.darkreading.com/cloud-security/jadepuffer-ai-actor-azure-tenant-destructive-cloud-attack
https://securityaffairs.com/199905/cyber-crime/storm-3168-linked-to-jadepuffer-abused-stolen-azure-identities.html - Chrome Store Hosts 'Poper Blocker' Spyware Downloaded By Millions
"Millions of people have downloaded infostealers disguised as legitimate ad-blocking browser extensions, in part because Google has provided them with seals of approval on the Chrome Web Store. That's the word from Bay Area Labs, which uncovered one such app, "Poper Blocker," lurking in the Chrome Web Store. Poper Blocker has every trapping of a legitimate, mainstream app: It sports a big, green "Featured" badge, and its developer has earned a trustworthy "Established Publisher" status with Google. It enjoys a 4.8 out of 5 star rating from more than 81,000 reviewers. It claims more than 2 million active users. In short, no user could spot anything untoward about this program were they to come across it while shopping for an ad blocker."
https://www.darkreading.com/application-security/chrome-store-poper-blocker-spyware-downloaded-millions - NeedyMantis: Unpacking a Post-Compromise Malware Family Used In Targeted Operations
"Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family observed in a limited number of targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Based on observed activity, NeedyMantis is typically deployed after a threat actor has already established access to a target environment, indicating that the malware is used to maintain long-term access and support follow-on operations."
https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/
https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html - RatHat Android Malware Console Uses Gemini To Identify Higher-Value Victims
"RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone, including text messages and passwords entered into fake login screens overlaid on banking apps. Its latest version asks Google's Gemini AI model to estimate each victim's bank balance from those messages and sorts the phones into high-value and mid-value groups."
https://thehackernews.com/2026/09/rathat-android-malware-console-uses.html - The Infostealer Incursion: How Stolen Credentials Breach Cloud, Code, And AI Environments
"Identity has long been the primary attack surface of the cloud. Infostealer malware, distributed through an industrialized cybercrime economy, is a leading initial access vector for compromising enterprise cloud, code, and AI environments. By targeting unsecured endpoints of developers through social engineering and supply chain attacks, threat actors steal credentials, API keys, and active session tokens, thereby bypassing the stronger defenses protecting most cloud environments from more direct attacks. Stolen credentials are widely recognized as one of the most common initial infection vectors - Microsoft, Recorded Future, and Verizon’s DBIR all point to infostealers as a cause of major concern. These attacks begin with a simple malware infection on a personal device, and end with attackers gaining privileged access to your AWS, Azure, or GCP estate, and more recently to the code platforms used by your organization, such as GitHub or GitLab."
https://www.wiz.io/blog/infostealer-incursion-cloud-ai-credentials - A Fake Security Locker, Delivered By Google Ads
"Netskope Threat Labs has been tracking a cloud-hosted tech-support-scam (TSS) kit that hijacks a victim’s browser with a fake security alert and pressures them into calling a bogus support line, where the goal is to either extract payment for fake “support,” gain remote access, or collect personal and financial details. Victims arrive by clicking a Google ad and land on a loading spinner webpage then into what looks like an ordinary online store, with nothing that reads as malicious."
https://www.netskope.com/blog/a-fake-security-locker-delivered-by-google-ads
Breaches/Hacks/Leaks
- Japan's Keio Confirms Ransomware Attack Disrupted Business Systems
"Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. Following a system failure in the early hours of Saturday, the company confirmed the attack and shut down its network to prevent additional damage. The company said it is investigating the extent of the impact and whether the attackers accessed any customer or business partner information."
https://www.bleepingcomputer.com/news/security/japans-keio-confirms-ransomware-attack-disrupted-business-systems/ - Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
"Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. The company announced the incident on September 25, saying that a third party had accessed its systems at the beginning of the month. Times Car took action to block the unauthorized access on September 26. At the time, the company said it was investigating whether the attackers accessed members' personal information, but confirmed the data theft in an update earlier today."
https://www.bleepingcomputer.com/news/security/times-car-confirms-data-breach-affecting-66-million-user-accounts/ - Everything Everywhere: Systemic Data Exposure In Supabase Apps
"Since 2025, the database service Supabase has been known to leak data through a variety of configuration issues. Despite improvements to Supabase product security, those issues continue to exist; multiplied by Supabase’s growth as a favorite tool for Claude Code, there are now thousands of Supabase instances exposing personal information and other data. In the largest study of its kind, UpGuard Research shows how Supabase misconfigurations expose personal data for people all over the world."
https://www.upguard.com/blog/everything-everywhere-systemic-data-exposure-in-supabase-apps
https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/ - FBI Job Portals Remain Offline After ShinyHunters Claims Breach Via PeopleSoft Zero-Day
"The FBI’s online portals for job applicants (at apply.fbijobs.gov) and special agent applicants (at fbijobs.gov/special-agents) are still unavailable, following what appears to be successful compromises by the ShinyHunters cyber extortion group. Last week, the United States’ domestic intelligence and security service confirmed it was investigating ShinyHunters’ claim of having compromised personal information of FBI employees. ShinyHunters told The Register they leveraged a currently unspecified and unconfirmed Oracle PeopleSoft zero-day vulnerability to breach the portals."
https://www.helpnetsecurity.com/2026/09/28/fbi-job-portals-offline-shinyhunters-breach/
https://cyberscoop.com/fbi-data-breach-shinyhunters-agent-safety-risk/
https://www.malwarebytes.com/blog/data-breaches/2026/09/fbi-agents-blood-tests-and-doctors-notes-surface-after-breach - Bitget Says Attacker Exploited Third-Party Security Product Flaw To Steal $388M
"The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most customer funds in offline cold wallets and use hot and warm wallets to process withdrawals. Transfers from those wallets must still be approved before they are signed. The stolen funds came from part of Bitget's hot and warm wallets, and its cold wallets were not affected."
https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html
https://www.bleepingcomputer.com/news/security/bitget-resumes-bitcoin-withdrawals-after-3875-million-crypto-heist/
https://www.infosecurity-magazine.com/news/bitget-restarts-withdrawals-387-5m/ - Cyberattack On Polish Medical Software Provider Exposes Patient Data
"Hackers stole personal data from a Polish healthcare software provider in the latest cyberattack to hit the country’s medical sector in recent months. Qbusoft, which develops the Medyc medical records and practice management platform, was breached after an attacker exploited an SQL injection vulnerability in August, according to a notification issued last week by one of the healthcare providers affected by the incident. SQL injection is a security flaw that allows hackers to trick a website into giving them access to information stored in its database."
https://therecord.media/poland-cyberattack-medical-medyc - DC Health Agency Exposes 400,000 Beneficiary Records
"The District of Columbia Department of Health Care Finance (DHCF) is notifying nearly 400,000 people that their personal information was potentially compromised in a data breach. According to the agency, the incident impacts Medicaid and the DC Healthcare Alliance beneficiaries who enrolled between 2023 and 2026. The data breach was not the result of hacking. Instead, DHCF discovered in July that two reports on its website contained hidden personal information accessible to unauthorized individuals."
https://www.securityweek.com/dc-health-agency-exposes-400000-beneficiary-records/
https://securityaffairs.com/199926/data-breach/nearly-400000-medicaid-beneficiaries-caught-in-medicaid-and-dc-healthcare-alliance-data-exposure.html
General News
- August 2026 Threat Trend Report On Ransomware
"This report summarizes statistics on new ransomware samples, affected systems, and statistics on targeted businesses collected during the month of August 2026, as well as major Korean & Global ransomware issues. Statistics on targeted businesses were compiled based on the time when publicly available information from ransomware groups’ DLS (Dedicated Leak Sites, i.E., Ransomware PR sites or PR pages) was collected via the ATIP (AhnLab TIP, Threat Intelligence Platform) infrastructure."
https://asec.ahnlab.com/en/95567/ - Dutch Police Arrest ‘Reformed’ Hacker In Shiny Hunters Investigation
"Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p."
https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/
https://databreaches.net/2026/09/28/still-on-probation-from-previous-arrest-for-hacking-and-extortion-dutch-national-is-arrested-again/
https://www.bleepingcomputer.com/news/security/dutch-police-confirm-arrest-in-shinyhunters-hacking-investigation/ - AI Agents Are Privileged Users; Who Is Auditing Their Access?
"Enterprises spend heavily protecting the human perimeter. Security teams deploy phishing-resistant multifactor authentication (MFA), enforce rigid conditional access policies, and scrutinize every login from an unexpected IP address. Yet while we closely monitor the human employee, engineering teams are quietly granting broad production access to autonomous AI agents, which often operate as non-human identities (NHIs) backed by service accounts, API tokens, or delegated cloud permissions."
https://www.darkreading.com/vulnerabilities-threats/ai-agents-are-privileged-users-who-is-auditing-their-access - If You Do One Security Check This Quarter, Make It Agent Memory
"In this interview with Help Net Security, Chris Latimer, CEO of Vectorize, talks about the security risks hiding in AI agent memory. He found coding agents storing API keys, credentials, and sensitive documents in plain text on developer machines and in cloud services. Latimer explains how attackers could plant poisoned memories through plugins, skills, and MCP integrations, often aimed at new coders who trust too easily. He covers why access control for agent memory lags behind other areas, what to track after an incident, and the one audit he thinks every CISO should run this quarter."
https://www.helpnetsecurity.com/2026/09/28/chris-latimer-vectorize-agent-memory-security/ - AI Tests The Limits Of Enterprise Security Governance
"AI agents are forcing enterprises to rethink security governance, human accountability and oversight as deployments scale. AWS’s Reimagine 2026 argues that organizations need to build governance into their systems and keep humans accountable for outcomes. The findings come from confidential interviews of 45 to 60 minutes with 154 executives at 128 organizations in 23 industries, conducted over nine months. A number of the organizations interviewed still apply review processes designed for six-month IT programs to work that takes days. If a two-week experiment waits a month for approval, some teams stop asking for permission. Policy in that situation is “pushing it underground,” the authors write."
https://www.helpnetsecurity.com/2026/09/28/ai-agent-security-governance-aws-report/ - Quantum Random Numbers Can Pass The Tests And Still Leak Clues To Attackers
"The European Telecommunications Standards Institute’s (ETSI) technical report, ETSI TR 104 171, offers guidance on building and evaluating quantum random number generators (QRNGs). It focuses on weaknesses in the devices and their supporting systems that could make the numbers they produce less secure. A QRNG measures a quantum process and turns the raw results into usable random numbers. Cryptographic systems rely on unpredictable numbers to generate keys and perform other security functions. If an attacker can predict those numbers, the protection those systems provide may be weakened."
https://www.helpnetsecurity.com/2026/09/28/quantum-random-number-generator-qrng-guidance/ - Deepfakes Are Becoming a Costly Reality For Businesses, Report Warns
"Three quarters of cybersecurity leaders say their organization has faced a suspected deepfake incident during the last year and a quarter of those hit by one say it cost the business over $1m in total, a new report has warned. The 2026 Pindrop Deepfake Readiness Index, published on 28 September, warned there is a significant gap between the threat of deepfake attacks and enterprise readiness to defend against them. Deepfakes are AI generated audio and videos of people. The technology has become increasingly sophisticated, making it difficult for anyone watching or listening to the deepfake to tell that it isn’t footage of a real person."
https://www.infosecurity-magazine.com/news/deepfakes-costly-reality-for/ - MCP Is Creating Major Governance Gaps, Researchers Warn
"Model Context Protocol (MCP) servers are creating a silent enterprise governance gap which threatens to undermine cybersecurity efforts as AI deployments proliferate, according to new research from Ox Security. MCP connects AI applications to external tools and data in a standardized manner, so that developers don’t have to write custom code each time they want to connect AI to an API or database."
https://www.infosecurity-magazine.com/news/mcp-creating-major-governance-gaps/ - AI Accounts Are Becoming The New Target For Infostealers
"SOCRadar analyzed stealer log data from the last 90 days and found 482 companies with exposed AI accounts and credentials. Of those, 295 appeared in active logs during that period, suggesting the exposure is recent rather than the result of historical cleanup. Together, these companies account for 5,434 stealer log records linked to 1,500 distinct corporate email addresses. The number that really stands out is the ChatGPT figure. A captured ChatGPT or OpenAI session appeared at 358 of the 482 companies, accounting for roughly 90% of all records in the study. Other platforms, including Zapier, Notion, Hugging Face, Replit, Lovable and ElevenLabs, were far behind."
https://securityaffairs.com/199933/ai/ai-accounts-are-becoming-the-new-target-for-infostealers.html
https://socradar.io/resources/report/ai-identity-exposure-report-2026.html
อ้างอิง
Electronic Transactions Development Agency (ETDA)
- Security Issues In The Korean & Global Financial Sector In August 2026