CVE-2025-49113, CVE-2025-68461, CVE-2026-100206, CVE-2026-100208, CVE-2026-35273, CVE-2026-48842, CVE-2026-65660, CVE-2026-67279, CVE-2026-86060, CVE-2026-95274, CVE-2026-95275, CVE-2026-95276, CVE-2026-95277, CVE-2026-95278, CVE-2026-95279, CVE-2026-95280, CVE-2026-95281, CVE-2026-95293, CVE-2026-95303, CVE-2026-95304, CVE-2026-95311, CVE-2026-95316, CVE-2026-95328, CVE-2026-95362, CVE-2026-95366, CVE-2026-95376, CVE-2026-95385
Domains:
wavel[.]app, apple03cloudstore[.]com.
Get tomorrow's brief in your inbox
Today: CISA added two actively exploited flaws affecting SharePoint and MikroTik routers to the KEV catalog, with the SharePoint RCE requiring immediate patching by September 28. ShinyHunters escalated from defacing Clop's leak site to resuming mass exploitation of Oracle PeopleSoft using WAF bypasses, while suspected North Korean actors stole $351.6 million from Bitget after compromising backend wallet infrastructure.
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
CISA added CVE-2026-65660 (SharePoint Server code injection, CVSS 8.8) and CVE-2026-67279 (MikroTik RouterOS workflow enforcement bypass, CVSS 6.9) to the Known Exploited Vulnerabilities catalog on September 25, 2026. Microsoft confirmed reliable evidence of active exploitation against CVE-2026-65660, which was initially described as a spoofing vulnerability but has been reclassified as enabling remote code execution. CVE-2026-67279 chains with CVE-2026-86060 (added to KEV on September 11) in an exploit called MikroTrick that grants full unauthenticated administrative access to vulnerable RouterOS 7.x builds. CERT Polska and Bishop Fox confirmed the exploit allows attackers to bypass authentication entirely by combining a session channel creation flaw with a login policy mask injection vulnerability.
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
The Canadian Centre for Cyber Security confirmed active exploitation of CVE-2026-48842 (CVSS 8.1), a pre-authentication SQL injection in Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The vulnerability stems from a preg_replace() backslash escape bypass in the virtuser_query plugin, allowing unauthenticated attackers to inject arbitrary SQL statements and potentially expose mail account credentials and stored messages. Patches were released in May 2026, but active exploitation continues. The Shadowserver Foundation reports more than 523,000 Roundcube instances exposed to the internet. China-aligned threat actor UNK_MassTraction has previously exploited Roundcube vulnerabilities to deliver web shells and the VShell post-exploitation tool.
ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
ShinyHunters (UNC6240) modified exploits for CVE-2026-35273 to bypass WAF rules by URL-encoding a single character in the request path, requesting /%50SEMHUB/ instead of /PSEMHUB/. String-based WAF rules match the literal path before URL decoding, while PeopleSoft application servers decode the request and route it to the vulnerable servlet. Google Threat Intelligence and Mandiant identified dozens of compromised systems globally spanning higher education, technology, IT services, healthcare, agriculture, transportation, and government. The threat actor exploited this vulnerability as a zero-day in June 2026, predominantly against academic institutions. Oracle released an out-of-band Security Alert on June 10, 2026. The current campaign targets organizations that implemented WAF rules but did not patch the underlying vulnerability. Exploitation involves Java deserialization abuse to deploy web shells and perform hands-on-keyboard activity.
ShinyHunters Defaced Clop's Leak Site in Grudge Match
ShinyHunters defaced the Tor data leak site of the Cl0p ransomware gang, claiming to have stolen server logs, source code, and private keys for Clop's onion service. The extortion group demanded an eight-figure payment and a public apology, threatening to expose companies that allegedly paid Cl0p during its Oracle E-Business Suite campaign. ShinyHunters states the attack is payback for threats allegedly made by a Clop representative during a feud dating back to that campaign.
Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
Cryptocurrency exchange Bitget reported suspected North Korean threat actors stole $351.6 million from hot and warm wallets on September 24, 2026, at 18:31 UTC. The attacker compromised a critical backend system within wallet infrastructure, used it to spoof transaction data, and triggered Bitget's authorization process to move funds out. Assets impacted include ETH, XRP, BNB, AVAX, USDT, and USDC across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base chains. Bitget CEO Gracy Chen stated the attack method is highly consistent with known patterns of North Korean hacker organizations based on IP behavior and on-chain analysis. Elliptic and TRM Labs identified connections between stolen Bitget funds and wallets used to launder previous North Korean hacks, including Bybit and AFX Bridge, pointing to involvement of the TraderTraitor group. If confirmed as North Korean, 2026 would become the second-largest year on record for North Korean crypto theft at $1.04 billion, behind 2025's $1.68 billion. Bitget has engaged Mandiant and SlowMist for third-party investigation.
Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
Kiteworks (formerly Accellion) recommended customers shut down systems for nine hours over the weekend after receiving credible threat intelligence from federal intelligence authorities indicating a threat actor may attempt to target some Kiteworks systems. CISO Frank Balonis stated the company has not found evidence that customer systems have been compromised and characterized the advisory as preventative rather than a response to a confirmed hack. Kiteworks said all known vulnerabilities have been addressed in software release 9.5.1 and recommended customers apply patches for optimal protection. Other subsidiaries including Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, and 123FormBuilder are not affected. In late 2020-early 2021, the Clop threat actor exploited multiple zero-day vulnerabilities in Accellion's file transfer program to conduct a data theft and extortion campaign.
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
A cross-site request forgery vulnerability in Elementor Website Builder WordPress plugin versions 4.3.0 and 4.3.1 (CVSS 8.8) allows unauthenticated attackers to create rogue administrator accounts and take full control of a site. The flaw affects over 2 million of the 10 million+ sites running Elementor. The vulnerability stems from the Editor Events module skipping CSRF protection for cookie-authenticated REST API requests whenever the string "elementor/v1/events/" appears anywhere in the request URI. Because the query string is written by whoever composes the link, any REST request can bypass CSRF protection by appending a parameter containing that string. The bypass applies to the entire REST API surface including WordPress core routes and all installed plugin routes. One link opened by a logged-in WordPress user makes that user carry out any REST API action their account permits, including creating administrator accounts through /wp/v2/users. The attack requires no JavaScript, submitted form, or attacker-controlled web page. Patchstack credited security researcher "Saggre" with discovering the bug. Elementor released version 4.3.2 addressing the issue.
Storm-3168: Agentic-driven cloud attacks using compromised service principals
Microsoft identified extensive Azure-focused resource destruction activity by Storm-3168 (JADEPUFFER) using compromised service principals. The threat actor, first documented by Sysdig in July 2026 as the first agentic ransomware operation, performed bulk destructive operations targeting Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines, and App Services. Two compromised service principals belonging to the same tenant were observed. One performed reconnaissance and resource discovery with 300+ successful read operations over 15.5 hours in early June 2026. The second performed discovery, destructive operations, and credential collection, executing 150+ destructive or credential collection operations in 35 minutes. The actual destructive sequence lasted approximately 7 minutes with 100+ storage account deletion attempts. Most targeted storage accounts were successfully deleted, though Azure resource locks and storage account-level deletion protection blocked some attempts. The threat actor used infrastructure with the same network fingerprint and user agent python-requests/2.34.2.
AI Relay Networks Funnel Chinese Traffic to Western Frontier Models
Team Cymru identified nearly 11,000 servers running Claude Relay Service or its successor, sub2api. These open source gateways pool AI accounts so many users can share them, while model providers see only the relay and never the real user or their location. In one US-hosted cluster, more than 4,000 IP addresses in China and Hong Kong (regions that Anthropic, OpenAI, and Google exclude) connected to 304 relays that also reached OpenAI, Anthropic, xAI, and Google endpoints.
Infostealer Logs Expose Remote Access Keys Across US Water Sector
SpyCloud analyzed stolen identity data tied to 10,000 US water and wastewater utilities and technology vendors, finding active infostealer exposure at 1,787 organizations and credentials for OT or remote-access systems at 258. In one case, malware on a single device at an advanced-metering technology provider captured saved logins for roughly 167 utility metering portals. Exposed credentials at utilities were mostly for remote-administration tools such as TeamViewer and SonicWall and Fortinet management portals. SpyCloud stresses the findings reflect potential access paths, not confirmed intrusions.
CLOSEDQUORUM: First Malware to Use Commercial AI APIs for C2
Cisco Talos documented CLOSEDQUORUM, a Go-based Windows implant believed to be the first publicly documented malware to hand command-and-control decisions to commercial LLMs instead of a human operator or attacker-run server. Up to four models (DeepSeek, Qwen, Mistral, and Gemini) vote on operational decisions.
PamStealer macOS Malware Adds Live C2 Payload Decryption
Jamf Threat Labs identified a new version of PamStealer that ensures the main payload can only be recovered using a server-side decryption chain. The latest artifacts continue to rely on JavaScript for Automation (JXA) dropper mechanisms but now fetch a purpose-built decryption utility and complete an X25519 key exchange with the server before the payload can be unwrapped. Without the server's cooperation, the payload cannot be recovered statically. Victims are lured through a bogus website (wavel[.]app) advertising a non-existent cryptocurrency wallet service. The malware installs four redundant persistence methods via LaunchAgent, a repair script that restores the payload bundle and LaunchAgent if removed, a shell hook appended to ~/.zshrc that triggers the repair script on every new interactive zsh session, and Git hooks in ~/Library/Application Support/System/.githooks/ that silently activate the repair script on any git checkout or git commit action. The final stage is a Swift-based stealer that captures system passwords via fake crash dialogs, enumerates keychain items, and steals credentials from Chromium- and Firefox-based browsers.
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
Two actions-cool GitHub Actions (issues-helper@v1 and issues-helper@v2) were disabled for a second time after the repositories became accessible on September 16, 2026, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. Release tags were not cleaned up and still pointed to malicious content introduced on May 18, so any workflow referencing either action by a version tag resumed downloading and executing the payload on its next run. The malicious code harvests sensitive credentials from CI/CD pipelines and exfiltrates details to an attacker-controlled server. The repositories were re-enabled between 11:09 a.m. and 6:16 p.m. GMT+2 on September 16, 2026, for unknown reasons. Most affected repositories likely ran the payload within a day of re-enablement with no further action needed from the threat actor.
Microsoft Office CVE-2026-100208 (Outlook RCE) and CVE-2026-100206 (Information Disclosure)
Microsoft published two CVEs that were addressed in previous updates but inadvertently omitted from Security Update announcements. CVE-2026-100208 was addressed in August 2026 updates. CVE-2026-100206 was addressed in July 2026 updates. Customers who have already installed the respective monthly updates do not need to take further action.
Chromium Vulnerabilities in Microsoft Edge
Microsoft published 19 Chromium CVEs addressed in Microsoft Edge (Chromium-based): CVE-2026-95274 (improper output encoding in DevTools), CVE-2026-95275 (incorrect reference resolution in MediaStream), CVE-2026-95276 (improper input validation in Themes), CVE-2026-95277 (use after free in Views), CVE-2026-95278 (missing authorization in WakeLock), CVE-2026-95279 (UI misrepresentation in Omnibox), CVE-2026-95280 (race condition in V8), CVE-2026-95281 (buffer overflow in ANGLE), CVE-2026-95293 (uninitialized resource in GPU), CVE-2026-95376 (externally controlled reference in DevTools), CVE-2026-95385 (inappropriate implementation in PlatformIntegration), CVE-2026-95303 (incomplete cleanup in SmartCard), CVE-2026-95304 (out of bounds write in V8), CVE-2026-95311 (free of non-heap memory in Fonts), CVE-2026-95316 (unchecked return value in Performance), CVE-2026-95328 (confused deputy in Mobile), CVE-2026-95362 (CSRF in DevTools), CVE-2026-95366 (use of released resource in Core).
The most significant pattern today is the convergence of AI capabilities in both offensive and defensive operations. Storm-3168's agentic ransomware, CLOSEDQUORUM's use of commercial LLMs for C2 decision-making, and the broader shift toward AI-orchestrated attacks documented in Anthropic's misuse report all point to attackers compressing the loop between reconnaissance, exploitation, and impact. Defenders must similarly use AI to investigate and respond across large environments rather than manually following individual actions. The second pattern is infrastructure exploitation at scale: ShinyHunters' WAF bypass demonstrates that published defensive guidance becomes the research roadmap for adversary adaptation, while the Bitget compromise shows backend authorization systems remain a high-value target for state-sponsored theft operations.