← Carolina Clear Tech

Cyber Threat Brief

2026-09-22

Listen to this brief (17:49)

Download MP3
Show Notes

Show Notes - 2026-09-22

Stories Covered

CVEs Referenced

CVE-2025-61882, CVE-2026-32996, CVE-2026-50343, CVE-2026-66804, CVE-2026-7273, CVE-2026-76460, CVE-2026-76461, CVE-2026-77692, CVE-2026-91843, CVE-2026-93485

Indicators of Compromise

Domains: corecloudfileshare[.]xyz, attachmentsharingdrive[.]xyz, educationportals[.]biz, 157[.]22, docsportal[.]in

Hashes: f5f1eb6d43dd61d5b069c250e5c666384f7417d0c95014773bf9edf8ff13bebe

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Today: ShinyHunters hijacked Clop's leak site and is threatening to expose ransom payment records from the Oracle EBS campaign (CVE-2025-61882). Zyxel GS1900 switches (CVE-2026-7273) and Veeam Agent for Windows (CVE-2026-32996) are under active exploitation; CISA's KEV deadline for Zyxel is September 24. Cisco ISE auth bypass (CVE-2026-76460, CVSS 10.0) remains actively exploited. Cisco Talos published CLOSEDQUORUM, the first documented malware using autonomous AI-driven C2 with no human operator required.


Critical Alerts

Cisco ISE Authentication Bypass (CVE-2026-76460)

Cisco's Identity Services Engine has a maximum-severity (CVSS 10.0) authentication bypass under active exploitation. An unauthenticated remote attacker can bypass the web management interface via a crafted API request. CISA KEV deadline was September 19. EPSS score: 0.008 (54th percentile). A second ISE/Secure Email Gateway flaw, CVE-2026-76461 (CVSS 9.8), was also patched; CISA KEV deadline was September 17.

Zyxel GS1900 Series Stack-Based Buffer Overflow (CVE-2026-7273)

CISA added CVE-2026-7273 (CVSS 8.8) to the KEV catalog. A stack-based buffer overflow in the CGI program of Zyxel GS1900 switch firmware allows a LAN-based unauthenticated attacker to execute OS commands via crafted HTTP requests. All GS1900 models through firmware 2.90(x.1)C0 are affected.

Veeam Agent for Windows Local Privilege Escalation (CVE-2026-32996)

Arctic Wolf confirmed active exploitation of CVE-2026-32996 (CVSS 7.3) in Veeam Agent for Microsoft Windows. The Veeam Endpoint Backup service caches an elevated administrator principal against a client-controlled session UID written to a world-readable log file. A local attacker can read the UID and execute commands as SYSTEM. A public PoC exists on GitHub.

Check Point Security Management Critical RCE (CVE-2026-91843)

Check Point released a fix for CVE-2026-91843 (CVSS 9.8), a stack overflow in the login process of Security Management and Log Servers. Unauthenticated remote attackers can execute code as root on R80 through R82 systems.


Ransomware & Extortion

ShinyHunters Hijacks Clop's Leak Site, Threatens Payment Exposure

ShinyHunters breached Clop's dark web leak site on September 19 by exploiting an unauthenticated file upload vulnerability in its Grav CMS. ShinyHunters claims to have stolen source code, Grav plugins, system logs, and private keys for Clop's Onion service. The group is demanding an eight-figure Bitcoin payment, claiming Clop stole an Oracle E-Business Suite zero-day (CVE-2025-61882, EPSS 0.997/100th percentile, CISA KEV ransomware-linked) that ShinyHunters discovered first. ShinyHunters has threatened to publish identities of companies that paid Clop, along with payment amounts and Bitcoin addresses. These claims are unverified. Clop removed the defacement and posted a note claiming ShinyHunters' email does not work. If ShinyHunters obtained victim payment records, organizations that paid Clop could face renewed extortion.

INC Ransomware: Dual Ransom Notes and 17-Day Dwell Time

Huntress documented an INC ransomware incident affecting 175+ endpoints. The attackers dropped two ransom notes 53 minutes apart: a standard decryption demand and a "press release" threat. Activity spanned early to late August with a 17-day gap, suggesting an initial access broker handoff to a ransomware affiliate. A BYOVD tool was found on a domain controller alongside scheduled tasks with randomized names.


IOCs & Detection

TASK#STOMP PowerShell Backdoor

Securonix disclosed a campaign delivering a PowerShell backdoor that harvests business documents, Wi-Fi passwords, clipboard data, and screenshots. Uses dual C2 channels with mutual watchdog processes. Persistence via scheduled tasks named to mimic Windows services (Local Credential Manager, Network Audio Service, Windows Display Manager, Device Credential Handler). Performs timestomping on artifacts.

SideCopy / ReverseRAT Targeting India

SideCopy is using spear-phishing to deploy ReverseRAT against Indian academic institutions via mshta.exe abuse. C2 traffic encrypted with key "NMXIKS09?:709,!~lnsYUS", exfiltrated via port 5863.

TerminalFix: PNG Steganography for Payload Delivery

Microsoft Security Research documented a campaign using PNG steganography to embed PE files and malicious DLLs in image pixel data. The technique uses all available bits (not just LSBs), producing visually garbled images but valid PNG files. The embedded executable (LockScreenContentServer.exe) is used for DLL sideloading.


Business & Infrastructure Threats

Fake LastPass Installers Deploy Kernel-Level EDR Killer and Rapuncel Stealer

A campaign using SEO-optimized fake GitHub pages impersonating LastPass Authenticator delivers a Microsoft-attested kernel driver (renamed CcProtect.sys from CnCrypt) that terminates 145 antivirus and EDR products from kernel level, then deploys the Rapuncel infostealer. The driver was signed via Microsoft's hardware compatibility program and had zero VirusTotal detections. The stealer targets passwords from 25 browsers (including bypassing Chrome/Edge app-bound encryption via injection), 30 crypto wallets, Discord/Steam/Telegram tokens, and Windows Credential Manager. The malware persists as a Windows service and continuously monitors for restarted security products.

CrowdSec Source Code Stolen via TanStack Supply Chain Attack

CrowdSec confirmed ~300 repositories (170 private) were compromised and source code exfiltrated in May 2026. The breach traces to the TanStack supply chain attack, where a compromised npm package exposed an API key. CrowdSec states no customer credentials were leaked and the code cannot be used out of context without their data infrastructure. Affected tokens were rotated immediately.

Contagious Interview (North Korea): 30,000 Devices, $10.71M Stolen

A joint advisory from Japan, US, Australia, and Germany confirms North Korean threat actors behind the "Contagious Interview" campaign have compromised 30,000+ devices across 100+ countries, stealing $10.71M in cryptocurrency from 7,000+ wallets. The campaign targets developers and crypto/Web3 specialists through fake job interviews deploying BeaverTail, InvisibleFerret, OtterCookie, and related malware families.

CLOSEDQUORUM: First Autonomous AI-Driven C2 Malware

Cisco Talos published research on CLOSEDQUORUM, a Windows implant that delegates command-and-control decisions to a quorum of four commercial LLMs (DeepSeek, Qwen, Mistral, Gemini). The malware queries models in sequence, tallies votes on the next action, and executes without human operator involvement. It targets credentials and crypto wallets. The public build contains placeholder API keys, so full autonomous execution was not observed in the wild. Talos simultaneously released CAIRN, an open-source toolkit for hunting AI-integrated malware via cognitive artifacts (embedded prompts, provider endpoints, API key prefixes).


Windows / AD Security

Windows Dangling COM Object Privilege Escalation (CVE-2026-66804)

Google Project Zero detailed CVE-2026-66804 (EPSS 0.053, 92nd percentile), an incomplete fix for CVE-2026-50343 ("Dark Elevator"). A dangling COM object registration for the CrossDevice COM object points to a missing DLL in %PROGRAMDATA%\CrossDevice\. Because C:\ProgramData is world-writable, any user can plant a malicious DLL. The exploit abuses custom COM marshaling to force privileged services to load the DLL, achieving local privilege escalation to SYSTEM.

WordPress Comment2Shell (CVE-2026-93485)

CVE-2026-93485 (CVSS 7.1) allows an anonymous visitor to plant a stored XSS payload via a comment that, when viewed by an admin using a block theme, can escalate to full RCE by uploading a web shell through the plugin installer. Comment moderation is off by default. Fixed in WordPress 7.1.1 (and backported to branches as far back as 4.7.36).


General Security News

Meta Muse AI Assistant Zero-Day (macOS)

Security researcher Patrick Wardle disclosed a local zero-day in Meta's Muse macOS app. An unprivileged local process can modify an undocumented setting (endo_voyager_dictation_endpoint) to redirect dictation traffic to an attacker-controlled endpoint, capturing the user's Muse authentication token. Because Muse requests broad OS permissions (files, mic, camera, calendar, email), a compromised Muse account gives an attacker access to everything the user granted the app. The token works across devices. Amazon has begun blocking Muse from its site. Meta has pushed an unconfirmed fix.

Plugin4Shell: Zero-Click RCE in AI Coding Agents

AIR Security demonstrated Plugin4Shell, a zero-click RCE that bypasses SHA-pinning verification in Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. A trusted plugin's repo is manipulated so the checkout resolves to malicious code while the SHA pin still appears valid.

Brevo Supply Chain Attack via Compromised Cloudflare API Key

A compromised Cloudflare API key allowed attackers to inject malicious ClickFix scripts into ~100,000 websites using Brevo marketing components.

Oracle September 2026 Critical Patch Update

Oracle addressed 800+ vulnerabilities across 17 product families. Over 100 are rated critical; 240+ are remotely exploitable without authentication. Affected products include E-Business Suite, Fusion Middleware, Hyperion, Siebel CRM, and Communications.


Patch Priority


Vulnerability Disclosures

BIND 9 Security Updates (14 vulnerabilities)

ISC published patches for BIND 9 addressing 14 vulnerabilities, including seven high-severity flaws enabling denial-of-service. CVE-2026-77692 allows unauthenticated remote DoS.

Windows COM Object Privilege Escalation (CVE-2026-66804)

Incomplete fix for "Dark Elevator" (CVE-2026-50343). Local privilege escalation via dangling COM registration in C:\ProgramData\CrossDevice\. EPSS 0.053 (92nd percentile).


Trends & Context

Threat actor-on-threat actor attacks are producing collateral damage for enterprises: ShinyHunters' Clop breach could re-expose organizations that paid ransoms, creating a secondary extortion vector that defenders cannot directly mitigate. The CLOSEDQUORUM malware marks a concrete step toward autonomous offensive AI, where the attacker's presence is no longer required after deployment. Meanwhile, the fake LastPass campaign demonstrates that Microsoft's driver signing and attestation pipeline remains exploitable for BYOVD attacks, with kernel drivers scoring zero AV detections despite being known-abusable components.