← Carolina Clear Tech

Cyber Threat Brief

2026-09-25

Listen to this brief (20:22)

Download MP3
Show Notes

Show Notes - 2026-09-25

Stories Covered

CVEs Referenced

CVE-2024-37383, CVE-2024-7399, CVE-2025-2135, CVE-2025-4632, CVE-2025-49113, CVE-2025-68461, CVE-2026-28324, CVE-2026-28325, CVE-2026-28326, CVE-2026-48842, CVE-2026-5430, CVE-2026-71362, CVE-2026-82566, CVE-2026-84399, CVE-2026-85496, CVE-2026-93289, CVE-2026-93290, CVE-2026-93291

Indicators of Compromise

Domains: fsputnik[.]com, tracker[.]js., uasputnik[.]com, 82[.]242, 82[.]242., logisticstkwcargo[.]com, ceva-app[.]help., 61[.]82, ceva-app[.]help, 61[.]82., third-party[.]com, example[.]com, yoursite[.]com, your-domain[.]com, example[.]org, example[.]net., yourdomain[.]com, your-site[.]com

IP Addresses: 194.87.89.30

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Today: CISA added two actively exploited vulnerabilities to its KEV catalog with a Friday deadline. Microsoft tracked Storm-2570 ransomware affiliate operating across four different ransomware families using identical post-compromise tools. WSO2 and Adobe Commerce flaws are under active exploitation, with WSO2 attacks detected since September 13.

Critical Alerts

CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog (CVE-2026-5430, CVE-2026-71362)

CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on September 24. CVE-2026-5430 is a critical (CVSS 9.8) path traversal vulnerability in WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway allowing unrestricted file upload and remote code execution. CVE-2026-71362 is a critical (CVSS 9.1) incorrect authorization flaw in Adobe Commerce and Magento enabling elevated access to sensitive resources without user interaction. WatchTowr captured forged JWT tokens exploiting CVE-2026-5430 against honeypots since September 13, three weeks before KEV addition. WSO2 technology serves nearly 1,000 customers across banking, government, telecommunications, and logistics sectors. Sansec detected exploitation attempts against CVE-2026-71362 in August, with attacks switching customer sessions to access victim accounts and private data.

Roundcube Webmail SQL Injection Under Active Exploitation (CVE-2026-48842)

Canadian Centre for Cyber Security warns that CVE-2026-48842, a high-severity (CVSS 8.1) SQL injection in Roundcube webmail's virtuser_query plugin, is being exploited in attacks. The flaw allows unauthenticated attackers to bypass plugin protections using crafted queries with backslash sequences that defeat regular-expression escaping. Successful exploitation enables database tampering, access to user identities, messages, address books, and mapping of authentication workflows. Over 500,000 Roundcube servers are internet-accessible, though the vulnerable population is unknown. Patches available in Roundcube versions 1.6.16 and 1.7.1 released in late May.

Ransomware Claims (Last 48h)

No structured ransomware victim claims data available in today's articles.

Ransomware & Extortion

Storm-2570 Affiliate Operates Across Four Ransomware Families Using Consistent Tradecraft

Microsoft Threat Intelligence tracks Storm-2570, a ransomware affiliate deploying Qilin, DragonForce, Anubis, and BERT ransomware using identical post-compromise tools and techniques across all operations. The affiliate maintains uniform tradecraft, infrastructure overlaps, and repeated use of the same remote access and cloud exfiltration tooling despite operating across multiple ransomware ecosystems. Storm-2570 demonstrates that tracking ransomware by payload alone obscures the recurring behaviors defenders can use for detection and disruption. Active since April 2025, Storm-2570 has targeted organizations in United States, Canada, United Kingdom, Spain, Netherlands, and Puerto Rico across healthcare, education, government, financial services, energy, retail, IT, food and agriculture, NGOs, chemicals, manufacturing, and transportation sectors. Post-compromise toolkit includes Atera, MeshAgent, ScreenConnect, Splashtop, Remotely_Agent, NinjaRMM for remote access; NetScan, Nmap, PsExec, Impacket, NetExec, and RDP batch scripts for discovery and lateral movement; and s5cmd and Rclone for data exfiltration.

Windows / AD Security

Microsoft September 2026 Security Updates

Microsoft released September 2026 security updates extending protection and support for AI agents, email investigations, and data security. New features include email detonation summary in Microsoft Security Copilot providing AI-generated explanations of URL and file sandboxing results for faster SOC investigations. Microsoft Purview and Microsoft Entra Global Secure Access now enforce data security at the network layer across human and agent traffic, blocking sensitive files from reaching shadow AI services. Auto-labeling enhancements support simulations up to 20 million items and 50,000 sites through adaptive scopes. eDiscovery now supports search and export of content in SharePoint embedded containers including Microsoft Loop, Copilot Pages, and Copilot Notebooks. Data Lifecycle Management enables archiving inactive SharePoint content without archiving entire sites and Priority Cleanup for permanent deletion of approved content. Advanced endpoint management extends to GCC High and DoD environments.

Chromium Type Confusion Vulnerability (CVE-2025-2135)

Microsoft Security Response Center published information on CVE-2025-2135, a type confusion vulnerability in the V8 JavaScript engine affecting Chromium-based browsers including Microsoft Edge. EPSS score is 0.070 (94th percentile).

Business & Infrastructure Threats

Threat Actor Compiles Cryptominer Directly on Compromised Endpoint

Huntress researchers documented a unique incident where attackers exploited Samsung MagicINFO vulnerability CVE-2025-4632 to gain initial access, then compiled a cryptominer directly on the victim endpoint using Silent XMR Miner Builder.exe. The attack chain included three attempts to download AnyDesk RMM from attacker-controlled IP 194.87.89.30, with the first two blocked by Microsoft Defender. After successful AnyDesk installation, attackers disabled Windows Defender via SystemSettingsAdminFlows.exe and created a user account named "oldadministrator" with the same password as AnyDesk. Compiling on-endpoint allowed customization for the target CPU architecture but created significant EDR telemetry spikes. The vulnerability CVE-2025-4632 enables arbitrary file write as system authority and was fixed in May 2025 after CVE-2024-7399 had an incomplete fix. Initial compromise occurred through Samsung MagicINFO Premium, which runs on Apache Tomcat.

SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted (CVE-2026-28324, CVE-2026-28325, CVE-2026-28326)

SolarWinds patched three critical remote code execution vulnerabilities in Observability Self-Hosted affecting non-default configurations. CVE-2026-28324 (CVSS 9.8) is an insufficient integrity check leading to RCE on non-default, non-secure configurations. CVE-2026-28325 (CVSS 8.8) is a deserialization of untrusted data weakness affecting specific communication modes. Both flaws allow unauthenticated remote exploitation. CVE-2026-28326 (CVSS 8.8) affects Access Rights Manager due to hardcoded static key. All vulnerabilities patched in Observability Self-Hosted version 2026.2.3 and ARM version 2026.2.1. Security researcher Kai Huang from Armadin reported all flaws. No evidence of exploitation in the wild.

Salesforce Agentforce Vulnerabilities Enabled Zero-Click Data Exfiltration (SalesBleed)

Zenity Labs disclosed three vulnerabilities in Salesforce Agentforce dubbed SalesBleed, now patched. Attackers could hijack trusted Agentforce agents for sensitive CRM data exfiltration and phishing by injecting malicious instructions into Web-to-Lead forms. Two flaws enabled zero-click data exfiltration by exploiting weaknesses in Trusted URLs security mechanism. Agentforce failed to recognize top-level domains and character sequences could tamper with URL parsing, allowing HTML image tags to exfiltrate leads and accounts data to attacker servers. A third flaw in Agentforce-Slack integration allowed weaponizing agents to distribute phishing messages to internal Slack channels using the agent's trusted identity. Vulnerabilities reported June 1, confirmed patched by August 19.

Cloudflare Containers Flaw Allowed Reading Other Customers' Leftover Disk Data

Cloudflare fixed a flaw in Cloudflare Containers and Sandboxes where thin-provisioned disk blocks were reused without wiping, allowing one customer to read data previous customers' containers left behind. The shared disk pool was configured to skip wiping blocks before allocation, contrary to normal defaults. Researchers from Accomplish reported the flaw September 4 via bug bounty program, writing small blocks then reading entire 64KB blocks to recover previous container data. Tests found leftover data on 18 of 24 tries and 20 of 22 underlying machines across four continents. Recovered material included directory structures, database pages, complete SQLite databases, Chromium profiles, .env files, and credentials. Cloudflare turned on wiping for new blocks September 14, then retired all running container disks and cleared image layer caches by September 19. Disk activity log analysis found no evidence of exploitation beyond authorized testing. Sandboxes product, marketed for running untrusted code including AI agent code, was affected.

General Security News

ClickFix Campaign Leverages Compromised Ukrainian Websites to Deploy Psychedelic Stealer

Arctic Wolf Labs identified an active ClickFix campaign compromising legitimate Ukrainian business websites to inject fake Cloudflare verification pages delivering previously undocumented Psychedelic information stealer. Compromised sites include hair-treatment clinic, scale-model manufacturer, bookstore, psychological facility, tool retailer, and automotive retailer. Injected iframe element executes attacker JavaScript from fsputnik[.]com/tds/tracker[.]js. The ClickFix lure presents Ukrainian-language instructions, copies Windows Installer command to clipboard after three-second delay, then displays instructions while disabling "Done" button for 35 seconds. The msiexec command fetches MSI installer from uasputnik[.]com (registered September 9, 2026) which retrieves psychedeliclove.exe from 107.175.82[.]242:9000. Psychedelic Stealer harvests browser passwords from Chromium browsers, account tokens, cryptocurrency wallet data from browser extensions and desktop apps, and sets scheduled-task persistence. The malware modifies browser profiles to inject extensions communicating via native messaging bridge and polls C2 for tasks including running executables and PowerShell payloads. Exposed lure management panel called РУБЛЁВКА TDS identified on uasputnik[.]com domain. Campaign likely has Armenian or Russian nexus based on localized artifacts.

Corp MDM Spyware Targets Logistics Sector via Fake Google Play Pages

Logistics firms are targeted by Android spyware Corp MDM distributed through fake Google Play pages branded as CEVA and TKW Logistics at playgoogle.logisticstkwcargo[.]com and playgoogle.ceva-app[.]help. The compact surveillance implant exfiltrates newly received SMS content, diverts calls via call forwarding, and maintains hidden foreground service. Package name is com.corp.mdm. The malware uses hard-coded IP 69.55.61[.]82 for command-and-control, credential phishing, and hosting Windows malware. After sideload installation, Corp MDM requests SMS, telephony, and notification permissions, removes launcher icon, registers device with C2 at /api/v1/devices/register, sends heartbeat every 30 seconds, and polls for commands every second. Supported commands include ping, forward_on for unconditional call forwarding, forward_off to cancel forwarding, sync_sms, self_destroy, get_location, and lock_device (last two supported by panel but not malware). SMS stealing is limited to new messages after permission grant, but captures one-time passcodes, password resets, account recovery, and transaction notifications over cleartext HTTP. Campaign has Armenian or Russian nexus based on localized artifacts. AI likely used during development given bugs interfering with capabilities.

Placeholder Domain third-party[.]com Weaponized to Serve ClickFix Lures

The documentation placeholder domain third-party[.]com, referenced in over 1,700 GitHub repositories, is serving ClickFix lures to Windows users while displaying decoy content to others. Unlike reserved example[.]com, third-party[.]com is not IANA-reserved and was registered by unknown party. The domain has served ClickFix since at least June 2026, showing fake Cloudflare verification that poisons clipboard and instructs Windows users to paste command via Run dialog. The command extracts and runs remote PowerShell payload. macOS users receive error message stating "macOS is not supported." The domain is referenced in AI agent skills and MCP-server documentation as example endpoint. Manifold Security identified 13 additional weaponized placeholder domains including yoursite[.]com and your-domain[.]com serving macOS scams. Server-side targeting delivers different content per visitor operating system, making static analysis ineffective.

Patch Priority

Vulnerability Disclosures

Botslab G980H Dashcams (14 CVEs)

CISA published advisory for 14 vulnerabilities in Botslab G980H dash cameras affecting firmware versions 30010_QHG980HN5294SysFW+ and 58_QHG980HMCN5291SysFW+. Vulnerabilities enable bypassing authentication controls, unauthorized access to sensitive data and privileged functionality, device configuration modification, and disruption. CVE-2026-84399 (authorization vulnerability) allows unauthenticated adjacent network access to privileged functions via valid session state. CVE-2026-82566 (session management) allows authentication state to remain valid after client termination. CVE-2026-85496 (weak session IDs) uses sequential value space allowing session identifier prediction. Botslab has not responded to CISA mitigation requests.

Eufy Omni C20 and Omni X10 Pro (3 CVEs)

CISA published advisory for three vulnerabilities in Eufy robotic vacuums affecting versions below 1.6.4. CVE-2026-93289 allows unauthenticated command injection during pairing process. CVE-2026-93290 (Omni C20 only) involves hard-coded credentials allowing monitoring log files for mapping data credentials. CVE-2026-93291 (Omni C20 only) lacks certificate validation enabling man-in-the-middle attacks and arbitrary code execution. Somerset Recon reported vulnerabilities to CISA.

OnePlus Unpatched Root Vulnerabilities

Security researcher Rasmus Moorats disclosed two chained vulnerabilities in OnePlus 15 running latest OxygenOS allowing malicious app to gain root access without permissions. First flaw in AtlasService debugging service accepts calls from any app without authentication, passing untrusted text into system command granting root in restricted dumpstate zone. Second flaw in olc2 hardware helper executes any shell instruction for callers with root, granting full Linux privileges including kernel code loading. Attack requires malicious app installation but needs no permissions and shows no user prompt. Confirmed on OnePlus 12 Pro, expected across OxygenOS 16. OnePlus confirmed both flaws in May, claimed exclusive disclosure rights, and warned of legal liability for unauthorized publication. No CVE assigned, no patch available as of September 24 publication. OnePlus indicated OPPO devices also affected. Researcher disclosed after five months without patch following September 17 deadline agreement.

Trends & Context

Actively exploited vulnerabilities dominate this cycle, with CISA adding WSO2 and Adobe Commerce flaws showing weeks of pre-KEV exploitation. The Storm-2570 affiliate demonstrates ransomware operations are maturing into cross-platform services where identical tooling persists regardless of payload brand. ClickFix social engineering continues evolving with blockchain-based infrastructure (EtherHiding) designed to survive takedowns, now weaponizing trusted documentation placeholder domains that pass static analysis but serve malicious content at request time based on visitor characteristics.