PUBLISHED ON
Edge Zero Days, Autonomous AI Agents, and Cloud Identity Wipeouts
The perimeter shattered, cloud identities wiped storage in seven minutes, AI agents went autonomous, and the patch window became an open bar.
WEEKLY OPENING
Good evening, defenders, and welcome to Sunday night. If your security strategy still relies on waiting for a ransomware note or trusting a literal path rule on your web application firewall, this week was a masterclass in why the house always wins. In a single week, nine critical vulnerabilities landed on the federal Known Exploited Vulnerabilities catalog with 72 hour remediation clocks, two brand new unpatched zero days began burning through Citrix NetScaler appliances, and both Russian state operators and ransomware crews shared the same exploit against Cisco management planes.
Across the cloud and identity horizon, the machines started taking over the night shift. Threat actors handed operational keys to autonomous AI agents that built and launched credential phishing campaigns in under six hours, while researchers caught OpenAI agent activity leaving a trail of breadcrumbs across Hugging Face repositories. In Azure, compromised service principals demonstrated that an attacker does not need an encryptor when they can attempt over a hundred storage deletions in seven minutes and harvest the backup keys for dessert.
From North Korea's suspected 351.6 million USD Bitget hot wallet heist and trojanized Terraform modules on DevOps MacBooks to Iranian spyware on dissidents' phones and encryptionless extortion pushed through Active Directory Group Policy, the message is unmistakable. We are well past the inflection point, and the monologue is over. Let us look at the tape.
EXECUTIVE TAKE
Edge Infrastructure and Enterprise Applications Are the Primary Initial Access Vector: Four network edge vulnerabilities entered the Known Exploited Vulnerabilities catalog on September 22 alone (
CVE-2026-85102andCVE-2026-93616in Check Point Quantum gateways and management servers,CVE-2026-93952in Arista VeloCloud Orchestrator, andCVE-2026-94127in F5 BIG-IP APM), followed on September 24 and 25 by five more exploited flaws (CVE-2026-5430in WSO2,CVE-2026-71362in Adobe Commerce and Magento,CVE-2026-65660in Microsoft SharePoint Server,CVE-2026-67279in MikroTik RouterOS, andCVE-2026-87902in WordPress Core). Compounding the emergency, two unpatched zero day RCE vulnerabilities in Citrix NetScaler entered active exploitation on September 26 with fixes not expected until the week of September 28, whileUNC6240(ShinyHunters) bypassed literal WAF rules on Oracle PeopleSoft (CVE-2026-35273) using/%50SEMHUB/.Adversarial AI Has Shifted From Prompting to Autonomous Lifecycle Execution: Consulted threat intelligence sources confirm threat actors are operationalizing multi agent AI frameworks that autonomously plan, build, and execute campaigns, including a six hour cloud credential harvesting operation. Model distillation is lowering the compute barrier for local adversarial models. Forensic tracking of Hugging Face accounts
0TimeandNyx9tied to OpenAI agent activity proves that catching autonomous agents requires logging build triggers, container starts, request logs, token lineage, and deletion tombstones. Meanwhile, theCLOSEDQUORUMimplant demonstrates autonomous C2 via four LLM providers voting on post exploitation actions,Carbonatomalware is installing theHermes AgentAI framework on exposed Docker daemons, and 9.6 percent of internet facing LiteLLM gateways (294 of 3,074 instances) accept the default master keysk-1234, exposing cloud IAM credentials via IMDSv2 header pass through.Identity Abuse and Affiliate Consistency Outlive the Ransomware Payload: Leadership must treat this cycle as an identity control failure rather than a malware family problem.
Storm-2570has deployedQilin,DragonForce,Anubis, andBERTsince April 2025 using an identical pre encryption playbook of commercial RMM tools,ntdsutilIFM credential dumps, Defender tampering, ands5cmdorRclonecloud exfiltration.PAYLOADransomware abandoned file encryption entirely in favor of Group Policy Object (GPO) deployment. In Azure,Storm-3168(JADEPUFFER) used two compromised service principals to enumerate resources and execute a seven minute destructive blitz against storage accounts, Key Vault, Function Apps, and recovery locks before running over 30ListKeyscalls, all without dropping a ransom note. Simultaneously,EvilTokens(Storm-2992) industrialized OAuth device code phishing to compromise over 12,000 inboxes across 10,000 organizations.Supply Chain Persistence, Crypto Heists, and Targeted State Espionage Escalate: Disabling a compromised asset is not the same as cleaning it: GitHub Actions compromised in the
Mini Shai-Huludcampaign were re-enabled between September 16 and 25 with malicious payload references still intact, while JFrog Artifactory instances faced a two request unauthenticated admin takeover chain (CVE-2026-42016,CVE-2026-42018,CVE-2026-82329). North Korean operations dominated financial and developer theft via the suspected 351.6 million USDBitgethot wallet breach,Jade Sleetdeploying Rust macOS backdoors (FLATROOFandROOFDECK) via tampered Terraform dependencies, andWaterPluminfecting 30,000 hosts via npm. Concurrently, state espionage expanded through IranianCHOSEN BRICKspyware,Mirage Kitten(UNC1549) in Middle East aviation and FinTech,NightEagledeployingGhostContaineron Russian Exchange servers,UNC3569exploiting Tencent Sogou Input Method (CVE-2026-51990) to dropGrayRabbit, andFamousSparrowdeployingSparroWockyacross eight Latin American governments.
KEY FINDINGS
Citrix NetScaler Unpatched Zero Days: Two unpatched RCE vulnerabilities in Citrix NetScaler ADC and Gateway were reported under active exploitation on September 26 by consulted sources; distinct from
CVE-2026-19490(patched in August, cataloged September 9), these flaws have no public CVEs, IOCs, or patches until the week of September 28.September 22 Known Exploited Vulnerabilities Wave: Four unauthenticated edge RCE flaws entered the federal catalog on September 22 with a September 25 deadline under BOD 26 04:
CVE-2026-85102(Check Point Quantum improper certificate validation RCE, CVSS 9.8),CVE-2026-93616(Check Point Management/Log/SmartEvent path traversal RCE, CVSS 9.8),CVE-2026-93952(Arista VeloCloud Orchestrator input validation RCE, CVSS 9.8), andCVE-2026-94127(F5 BIG-IP APM heap buffer overflow RCE in OAuth Authorization Server data plane configurations, CVSS 9.8).September 24 and 25 Known Exploited Vulnerabilities Wave: Five additional flaws entered the catalog with September 27 and 28 federal deadlines:
CVE-2026-5430(WSO2 API products, CVSS 9.8 to 10.0, where the CVE record describes JWT algorithm mismatch auth bypass while the catalog short text describes path traversal file upload RCE),CVE-2026-71362(Adobe Commerce and Magento incorrect authorization and privilege escalation, CVSS 9.1),CVE-2026-65660(on premises Microsoft SharePoint Server 2016, 2019, and Subscription Edition authenticated code injection with observed web shell drops, CVSS 8.8 / 6.5),CVE-2026-67279(MikroTik RouterOS 7.24 prior to 7.24.2 SSH pre auth workflow bypass, CVSS 6.9, reported chaining withCVE-2026-86060as MikroTrick), andCVE-2026-87902(WordPress Core path traversal and remote file inclusion RCE exploited within hours of disclosure, CVSS 9.2 / 8.1).Oracle PeopleSoft WAF Bypass and Clop Leak Site Compromise (
UNC6240/ShinyHunters):UNC6240resumed mass exploitation ofCVE-2026-35273(CVSS 9.8) across higher education, technology, IT services, healthcare, agriculture, transportation, and government using the URL encoded path/%50SEMHUB/to bypass literal WAF rules, deploying JSP web shells (x.jsp,u.jsp,u2.jsp,tunnel.jsp,tunnel.jspx),SIDEEYE(Ple64.exe),Neo-reGeorg, and MeshCentral. Separately,ShinyHuntersreportedly exploited an unauthenticated Grav CMS flaw (CVE unconfirmed) to compromise theClopransomware leak site.Cisco FMC, Cisco ISE, SolarWinds, Roundcube, TeamCity, and Windows Zero Days:
CVE-2026-20079(CVSS 10.0 auth bypass) andCVE-2026-20316(CVSS 5.3) in Cisco Secure Firewall Management Center were exploited bySandworm(APT28) andQilinransomware (activity clustered September 9 to 11, hardening release week of September 14). Cisco ISECVE-2026-76460(CVSS 10.0 API auth bypass zero day) received an emergency patch September 17. SolarWinds Observability Self Hosted RCEs (CVE-2026-28324,CVE-2026-28325) were patched. Roundcube Webmail pre auth SQL injectionCVE-2026-48842(CVSS 8.1 invirtuser_query) and a May Roundcube code injection flaw saw active exploitation, alongside a July JetBrains TeamCity flaw exploited by ransomware groups. Microsoft patched 974 CVEs in September, including exploited Windows privilege escalation zero daysCVE-2026-85880(ALPC) andCVE-2026-81963(Windows Update Stack). Kiteworks issued a precautionary nine hour shutdown advisory following federal warnings of an imminent attack.Autonomous AI Threats and LiteLLM Exposure: Threat actors used multi agent AI frameworks to plan, build, and execute a cloud credential harvesting campaign in under six hours. Hugging Face accounts
0TimeandNyx9revealed OpenAI agent commit and probe trails. TheCAIRNhunting toolkit was released alongside analysis ofCLOSEDQUORUM, an experimental Windows implant (no confirmed wild deployment) using four commercial LLMs to vote on injection, persistence, and credential theft.Carbonatomalware targeted exposed Docker APIs to install theHermes AgentAI framework. Meanwhile, 294 of 3,074 internet facing LiteLLM gateways (9.6 percent) accepted the default master keysk-1234(191 had no key configured), exposing provider keys and cloud IAM credentials via IMDSv2 header pass through.Storm-2570 Affiliate Standardization and PAYLOAD GPO Extortion: Active since April 2025 across the US, Canada, UK, Spain, Netherlands, and Puerto Rico,
Storm-2570deploysQilin,DragonForce,Anubis, andBERTwith identical post exploitation tradecraft: renamedMeshAgentand commercial RMMs,ngrokandCloudflaredRDP tunnels, Defender exclusions onC:\PerfLogs,ntdsutilIFM dumps inC:\Windows\Temp,Mimikatz,LaZagne,pypykatz,PsExec,Impacket,NetExec, and exfiltration vias5cmdandRclone. Separately,PAYLOADransomware weaponized Active Directory GPOs for encryptionless extortion.Storm-3168 (
JADEPUFFER) Seven Minute Cloud Destruction: Using two compromised Azure service principals sharingpython-requests/2.34.2and IPs45.131.66[.]106,34.153.223[.]102, and64.20.53[.]230,Storm-3168performed over 300 discovery reads followed by a seven minute destructive sequence attempting over 100 storage account deletions, deleting Key Vault, Function App, and App Service plan resources, targeting Site Recovery and Backup locks, failing SQL deletes due to an API version mismatch, and executing over 30ListKeyscalls. A client secret previously edited out of a public GitHub issue remained recoverable in history, though initial access and ransomware deployment remain unconfirmed.EvilTokens (
Storm-2992) Device Code Phishing at Scale: Sold on Telegram for 1,500 USD upfront and 500 USD monthly,EvilTokensused AI assisted lures and high reputation redirectors (Vercel, Cloudflare Workers, AWS Lambda) to abuse the OAuth device code flow, compromising over 12,000 inboxes across 10,000 organizations before law enforcement and vendor disruption.JFrog Artifactory Chain, Mini Shai-Hulud GitHub Actions, and x47.c: Attackers chained
CVE-2026-42016,CVE-2026-42018, andCVE-2026-82329(CVSS 9.8) for two request unauthenticated admin takeover of JFrog Artifactory between August 15 and September 8 (with 49 to 59 percent of instances still unpatched weeks later). Compromised GitHub Actions from theMini Shai-Huludcampaign (which previously hit 323 npm packages and 639 versions) were re-enabled September 16 to 25 with malicious payloads intact. Thex47.cWindows botnet combined DDoS, SOCKS5 proxying, and theft of browser credentials, wallets, Discord tokens, and AI tokens.Bitget 351.6M USD Heist, North Korean DevOps Intrusion, and Client Malware:
Bitgetlost 351.6 million USD from hot and warm wallets on September 24 via backend transaction spoofing linked by on chain and IP patterns to suspected North KoreanLazarus Groupclusters. North Korea'sJade Sleet(PUKCHONG/TraderTraitor/UNC4899) breached an Indian IT provider via fake coding interviews and a tampered Terraform dependency to deploy Rust macOS backdoorsFLATROOF(Telegram C2) andROOFDECK(Nostr C2), whileWaterPluminfected 30,000 devices via malicious npm packages (StoatWaffle,BeaverTail,OtterCookie,InvisibleFerret).MacSyncevolved a macOS backdoor delivered viaClickFixfake verification prompts and public iCloud Calendar invites;MovieReaperhid Solana blockchain C2 inside movie torrents (The Odyssey);ClearFakeWebDAV deliveredAmatera,ZigCryptoStealer, andNetSupport;RemControlAndroid MaaS impersonated TVTap IPTV;Astrana Healthsuffered a voice spoofing breach on September 22; and Wales'Dyfed-Powys Policedisclosed a September 14 cyberattack.State Espionage (
CHOSEN BRICK,NightEagle,Mirage Kitten,UNC3569,FamousSparrow): Joint government advisories exposed IranianCHOSEN BRICKspyware targeting dissidents and journalists via WhatsApp and Telegram lures.NightEagledeployedGhostContaineron Russian Exchange servers in manufacturing and construction.Mirage Kitten(UNC1549) deployedNightLedger,ArcBridge, andBridgeHeadagainst Middle East and African aviation and FinTech. China linkedUNC3569exploited Tencent Sogou Input MethodCVE-2026-51990(sgbiz:URI and Chromium 80 chain) to dropGrayRabbit, andFamousSparrowdeployedSparroWockyagainst governments in eight Latin American jurisdictions.
WEEKLY THREAT NARRATIVE
Edge Infrastructure and Enterprise Applications Under Sustained Assault
The perimeter did not merely take fire this week; it became the primary staging ground for state and criminal groups alike:
Unpatched Citrix NetScaler Zero Days: On September 26, consulted researchers warned of two unpatched zero day RCE vulnerabilities in Citrix NetScaler ADC and Gateway under active in the wild exploitation. Unlike
CVE-2026-19490(an authentication bypass patched in August and added to the federal exploited catalog on September 9), these two flaws have no assigned CVEs, public IOCs, or vendor patches yet. Fixes and advisories are expected the week of September 28, leaving network isolation, strict ACLs, and virtual WAF patching as the only immediate defenses.The September 22 Federal Catalog Dump: Four network edge vulnerabilities landed on the Known Exploited Vulnerabilities catalog in a single day with a 72 hour federal remediation deadline (September 25):
CVE-2026-85102(CVSS 9.8): Unauthenticated RCE in Check Point Quantum Gateways and Spark Firewalls via improper certificate validation in VPN certificate handling.CVE-2026-93616(CVSS 9.8): Unauthenticated path traversal allowing arbitrary script upload and execution on Check Point Management, Log, and SmartEvent servers.CVE-2026-93952(CVSS 9.8): Improper input validation in on premises Arista VeloCloud Orchestrator granting unauthenticated privileged internal function access and RCE.CVE-2026-94127(CVSS 9.8): Heap based buffer overflow in F5 BIG-IP Access Policy Manager (APM) exploited as a zero day. The vulnerability triggers in the data plane when an APM access policy and an OAuth profile (configured as an OAuth Authorization Server) share the same virtual server. F5 released hotfixes and an iRule mitigation.
The September 24 and 25 Federal Catalog Wave and Taxonomy Conflicts: Five more actively exploited vulnerabilities entered the catalog with September 27 and 28 deadlines under BOD 26 04:
CVE-2026-5430(WSO2 API Manager, API Control Plane, Traffic Manager, Universal Gateway, and Carbon API Manager REST API Utility): Exploitation is confirmed, but public documentation splits on root cause. The August CVE record describes JWT acceptance of an unsupported signing algorithm leading to authentication bypass and account takeover (CVSS 10.0 across security boundaries, 9.8 within a tenant), whereas the catalog short description and secondary mirrors describe path traversal with unrestricted file upload and RCE. Defenders should validate directly against WSO2 fixed build versions and patch immediately without waiting for the taxonomy debate to settle.CVE-2026-71362(Adobe Commerce and Magento): Incorrect authorization flaw (CVSS 9.1 in consulted reporting) allowing unauthenticated privilege escalation to sensitive resources.CVE-2026-65660(Microsoft SharePoint Server 2016, 2019, and Subscription Edition): Authenticated code injection flaw (CVSS 8.8 / 6.5). While it requires a low privileged authenticated user (or chaining with a separate auth bypass), low privileged credentials are readily available to attackers, and consulted sources confirmed active exploitation attempts dropping SharePoint web shells as of September 25.CVE-2026-67279(MikroTik RouterOS 7.24 prior to 7.24.2): Pre authentication SSH workflow and rekey flaw (CVSS 6.9) allowing an unauthenticated client to open a session channel and send an exec request. Consulted secondary sources report attackers chainCVE-2026-67279withCVE-2026-86060(argument injection) in an exploit dubbed MikroTrick for full unauthenticated admin takeover.CVE-2026-87902(WordPress Core): Path traversal and remote file inclusion flaw (CVSS 9.2 / 8.1) allowing unauthenticated inclusion of local.phpfiles outside theme directories for RCE, exploited within hours of disclosure.
Oracle PeopleSoft WAF Bypass (
CVE-2026-35273) and Clop Leak Site Intrusion:UNC6240(ShinyHunters) resumed mass exploitation ofCVE-2026-35273(CVSS 9.8 Java deserialization in PeopleSoft Environment Management Hub), expanding victimology from higher education into technology, IT services, healthcare, agriculture, transportation, and government.To defeat WAF rules written after earlier waves that matched the literal
/PSEMHUB/string,UNC6240sent repeatedPOSTrequests with serialized Java objects to/%50SEMHUB/hub. The WAF ignored the encoded%50(P), while PeopleSoft normalized and decoded the URL on the backend.Post compromise,
UNC6240dropped JSP web shells (x.jsp,u.jsp,u2.jsp,tunnel.jsp,tunnel.jspx) intoPSEMHUB.warandPORTAL.war, ran fileless commands via WebLogic spawned shells (cmd.exe,/bin/sh,bashexecutingbase64 -d,curl,/dev/tcp,tasklist,start /b), extracted credentials from configuration files, deployedSIDEEYEvia a trojanized VMProtect packed Light Alloy binary (Ple64.exeusing TCP ports 3333 and 3334), established HTTP/HTTPS SOCKS tunnels withNeo-reGeorg, and installed MeshCentral (MeshAgent).In a separate incident,
ShinyHuntersreportedly exploited an unauthenticated Grav CMS vulnerability (CVE unconfirmed) to deface and compromise theClopransomware operation's leak site.
Cisco FMC, Cisco ISE, Roundcube, SolarWinds, TeamCity, Windows Patch Tuesday, and Kiteworks:
Cisco Secure Firewall Management Center (
CVE-2026-20079, CVSS 10.0 auth bypass, andCVE-2026-20316, CVSS 5.3) saw opportunistic exploitation across at least three activity clusters, includingSandworm(APT28/ GRU) andQilinransomware (activity clustered September 9 to 11; hardening release week of September 14). Separately, Cisco patchedCVE-2026-76460(CVSS 10.0 API auth bypass zero day in Cisco ISE) on September 17.Roundcube Webmail (
CVE-2026-48842, CVSS 8.1) suffered active in the wild exploitation of a pre authentication SQL injection via apreg_replacebackslash bypass in thevirtuser_queryplugin (patched in 1.6.16 and 1.7.1), alongside separate reports of a May Roundcube code injection flaw under exploitation.Additional enterprise pressure included ransomware groups exploiting a July JetBrains TeamCity vulnerability, critical patches for SolarWinds Observability Self Hosted RCEs (
CVE-2026-28324andCVE-2026-28325), Microsoft's record 974 CVE September Patch Tuesday featuring two actively exploited Windows privilege escalation zero days (CVE-2026-85880in ALPC andCVE-2026-81963in the Windows Update Stack), and a precautionary nine hour shutdown advisory from Kiteworks after federal intelligence warned of an imminent attack.
Operationalized Adversarial AI and Exposed AI Gateways
Adversarial AI graduated from chat prompts to autonomous operational infrastructure:
Six Hour Autonomous Multi Agent Campaigns: Consulted Q3 2026 threat tracking confirms threat actors are deploying multi agent AI frameworks that plan, write custom code, and execute operations autonomously. In one documented intrusion, a financially motivated actor compromised a cloud resource and used an agentic workflow to plan, build, and deploy a mass credential harvesting campaign in under six hours. Model distillation is further accelerating adoption by shrinking frontier capabilities into low cost local models.
Forensic Telemetry for Autonomous Agents (
0TimeandNyx9): Consulted researchers traced public Hugging Face accounts0TimeandNyx9to OpenAI agent activity, uncovering relay code, internal probes, and automated ChatGPT account registration (with separate public reports noting autonomous agent probing without confirmed patient data compromise). Minute by minute commit histories showed that while public commits prove stage one, proving build, deployment, request handling, and external egress requires retaining build/start logs, public route request logs, token lineage (identifying the specific token rather than just the account), session/source IDs, and deletion tombstones.CLOSEDQUORUM Autonomous C2 and the CAIRN Toolkit: Consulted researchers released the
CAIRNhunting toolkit and analyzedCLOSEDQUORUM, an experimental Windows implant that replaces traditional C2 channels by querying up to four commercial LLM APIs (api.deepseek.com,api.mistral.ai,generativelanguage.googleapis.com, andopenrouter.ai) with a system prompt ("advanced malware strategist") and a voting mechanism to select its next action ("inject","persist","steal"). Capabilities include Early Bird APC injection (NtQueueApcThread), process hollowing, LSASS dumping (MiniDumpWriteDump), browser credential and crypto wallet theft, Windows Update themed Registry Run keys,schtasks.exescheduled tasks, WMI event subscriptions, and Discord webhook exfiltration. WhileCLOSEDQUORUMhas not been confirmed in the wild (the public sample contained placeholder keys and a dummy webhook), it establishes a vital behavioral signature for AI orchestrated malware.LiteLLM Default Master Key Exposure (
sk-1234): A scan of 3,074 internet facing LiteLLM gateways revealed 294 instances (9.6 percent) accepted the documented default master keysk-1234, and 191 had no authentication configured at all. Compromising the gateway exposes all proxied LLM API keys and allows attackers to pass IMDSv2 headers through to cloud metadata services to steal cloud IAM credentials.Carbonato Malware and Hermes Agent on Docker:
Carbonatomalware actively targeted exposed Docker APIs (ports 2375 and 2376) to install theHermes AgentAI framework for persistent host control.
Ransomware Affiliate Standardization and Seven Minute Cloud Destruction
Across both on premises domains and cloud tenants, identity and affiliate tradecraft proved far more durable than any individual ransomware binary:
Storm-2570 Affiliate Standardization: Tracked since April 2025 across the United States, Canada, the United Kingdom, Spain, the Netherlands, and Puerto Rico across healthcare, education, government, financial services, energy, retail, IT, manufacturing, and transportation,
Storm-2570deploys four separate ransomware families (Qilin,DragonForce,Anubis, andBERT) using the exact same pre encryption playbook (whileQilinandGentlemenalso drove a ransomware surge in Japan). With initial access still unconfirmed,Storm-2570relies on:Commercial RMM tools (
MeshAgentrenamed with the victim's organization string,Atera,ScreenConnect,Splashtop,NinjaRMM,Remotely_Agent) and tunnels (ngrok,Cloudflaredexposing TCP 3389).Defense evasion by disabling Windows Defender real time monitoring, modifying the registry, clearing indicators, and adding exclusions on
C:\PerfLogs.Credential access via
ntdsutilIFM Active Directory dumps underC:\Windows\Temp,Mimikatz,LaZagne,pypykatz,procdump,comsvcs.dll,Rubeus, andInvoke-DCSync.Discovery and lateral movement via
BloodHound,SharpHound,AdFind,PsExec,wmiexec,smbexec,atexec,Impacket, andNetExec, followed bys5cmdandRclonecloud exfiltration.
PAYLOAD Encryptionless GPO Extortion: Consulted researchers identified
PAYLOADransomware skipping file encryption entirely, instead weaponizing Active Directory Group Policy Objects (GPO) to deploy extortion payloads domain wide.Storm-3168 (
JADEPUFFER) Seven Minute Azure Wipe: Associated withJADEPUFFER(an operation previously linked to agentic cloud extortion),Storm-3168compromised two Azure service principals in a single tenant usingpython-requests/2.34.2and IPs45.131.66[.]106,34.153.223[.]102, and64.20.53[.]230. After the first identity executed over 300 discovery reads across subscriptions, VMs, resource groups, App Services, storage, locks, and Recovery Services, the second identity launched a seven minute destructive blitz: attempting over 100 storage account deletions, deleting a Key Vault, Function App, and App Service plan, failing SQL database deletes due to an unsupported API version, and attempting to delete Site Recovery and Backup locks (where resource locks blocked several deletions). Thirty minutes later, it issued over 30 successfulListKeyscalls against storage accounts, including Site Recovery accounts. No ransom note or confirmed exfiltration was observed. A plaintext client secret previously posted and edited out of a public GitHub issue remained accessible in edit history, though initial access was not definitively confirmed. SeparateStorm-3168infrastructure probed Azure App Service paths (WordPress admin, PHP CGI, and LangFlow/api/v1/validate/code) on non overlapping subscriptions.
Identity Phishing Kits, Supply Chain Traps, and Multi Purpose Botnets
EvilTokens (
Storm-2992) Device Code Phishing: Sold on Telegram for 1,500 USD upfront and 500 USD per month,EvilTokenscompromised more than 12,000 inboxes across over 10,000 organizations (concentrated in the US, Canada, UK, Australia, India, and France across wholesale, construction, financial services, real estate, higher education, and healthcare) before digital crimes disruption. Using AI generated lures (invoices, shared documents, password expiry notices) and redirectors on Vercel (*.vercel.app), Cloudflare Workers (*.workers.dev), and AWS Lambda,EvilTokensdirects victims to complete the legitimate Microsoft OAuth device code login (microsoft.com/devicelogin). The victim completes MFA for the attacker's session, enabling token theft, inbox rule persistence, Microsoft Graph reconnaissance, and new device registration for Primary Refresh Tokens (PRT).JFrog Artifactory Admin Takeover Chain: Between August 15 and September 8, attackers chained
CVE-2026-42016(token scope validation bypass),CVE-2026-42018(anonymous token disclosure), andCVE-2026-82329(CVSS 9.8 JWT forgery) to seize unauthenticated admin control of self hosted JFrog Artifactory in two HTTP requests. Six weeks post patch, 59 percent of scanned instances remained vulnerable toCVE-2026-42016, and 49 percent remained vulnerable toCVE-2026-82329.Mini Shai-Hulud Re-Enabled GitHub Actions and x47.c Botnet: Maintainers re-enabled GitHub Actions previously compromised in the
Mini Shai-Huludsupply chain campaign (which infected 323 npm packages and 639 package versions) between September 16 and September 25 without removing malicious payload references, re-exposing CI/CD secrets and developer tokens. Concurrently, thex47.cWindows botnet combined DDoS and SOCKS5 proxying with theft of browser passwords, cookies, Discord tokens, crypto wallets, and AI service tokens.
Crypto Heists, Developer Toolchain Intrusions, and Client Malware Evolution
Bitget 351.6 Million USD Crypto Heist: On September 24, attackers drained 351.6 million USD from
Bitgethot and warm wallets by compromising a backend wallet system, spoofing transaction data, and tricking the authorization workflow. Cold wallets were unaffected and the user protection fund is expected to cover losses. Exchange leadership noted IP patterns and on chain links to North KoreanLazarus Groupclusters (currently Under Attribution).Jade Sleet and WaterPlum Developer Targeting: North Korea's
Jade Sleet(PUKCHONG/TraderTraitor/UNC4899) breached an Indian IT services provider by targeting a DevOps engineer's MacBook with fake coding interviews and a tampered Terraform dependency, deploying Rust macOS backdoorsFLATROOF(Telegram C2, browser andlogin.keychain-dbtheft) andROOFDECK(Nostr C2, lateral movement, LaunchAgent persistence). Separately, North Korea'sWaterPluminfected over 30,000 devices via malicious npm packages droppingStoatWaffle,BeaverTail,OtterCookie(OtterCandy), andInvisibleFerret.MacSync, MovieReaper, ClearFake, RemControl, Astrana Health, and Dyfed-Powys Police:
MacSyncevolved from an AMOS stealer variant into a multi stage macOS infostealer and backdoor targeting Keychain (SecItemCopyMatching), browser data, and crypto wallets (Bitcoin, Ethereum, MetaMask, Phantom, Exodus, Ledger, Trezor), delivered viaClickFixfake verification prompts (osascriptandbase64 -d) and malicious public iCloud Calendar invitations.MovieReaperdistributed multi stage malware via pirated torrents of the film The Odyssey using the Solana blockchain for C2 resolution.ClearFakeabused WebDAV to deliverAmatera,ZigCryptoStealer, andNetSupport.RemControlAndroid MaaS used malvertising impersonating the TVTap IPTV app.Astrana Healthdisclosed a September 22 breach caused by phone number spoofing and employee impersonation (vishing), while Wales'Dyfed-Powys Policedisclosed a September 14 cyberattack affecting non emergency systems and staff data.
State Espionage Across Four Continents
Iranian
CHOSEN BRICKandMirage Kitten(UNC1549): A September 15 joint international advisory detailedCHOSEN BRICK, Iranian spyware active since 2025 targeting dissidents, activists, and journalists via WhatsApp and Telegram spear phishing (including fake medical documents) to steal contacts, messages, emails, and location telemetry. Meanwhile,Mirage Kitten(UNC1549/Smoke Sandstorm/Nimbus Manticore) targeted aviation and FinTech in the Middle East and Africa with theNightLedgerbackdoor andArcBridgeandBridgeHeadtunneling tools.NightEagleon Russian Exchange Servers: Consulted researchers documentedNightEagleusing compromised VPN credentials to breach Russian manufacturing and construction firms, deploying theGhostContainerbackdoor on Microsoft Exchange and using GitHub hosted tools for AD enumeration and GPO abuse.UNC3569(GrayRabbit) andFamousSparrow(SparroWocky): China linkedUNC3569exploited Tencent Sogou Input MethodCVE-2026-51990(chaining an unvalidatedsgbiz:URI handler, unrestricted webview navigation, and an unsandboxed Chromium 80 engine; patched in 16.3.0.3498 in April 2026) for one click RCE deploying theGrayRabbitbackdoor. China alignedFamousSparrowdirected 90 percent of its mid 2025 to mid 2026 activity at Latin America, deployingSparroWockyagainst government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.
NOTABLE TECHNICAL SIGNALS
CVEs
CVE ID | Affected Product | Vulnerability Type / Impact | CVSS | Catalog / Patch Status | Operational Context & Reconciliation |
|---|---|---|---|---|---|
| Check Point Quantum Gateway / Spark Firewall / Mgmt | Improper Certificate Validation to Unauth RCE | 9.8 | Cataloged Sep 22 (Due Sep 25) | Exploited in VPN certificate handling |
| Check Point Mgmt / Log / SmartEvent Servers | Path Traversal to Unauth Script Upload / RCE | 9.8 | Cataloged Sep 22 (Due Sep 25) | Unauthenticated management plane takeover |
| Arista VeloCloud Orchestrator (On Premises) | Improper Input Validation to Unauth RCE | 9.8 | Cataloged Sep 22 (Due Sep 25) | Privileged internal function access |
| F5 BIG-IP Access Policy Manager (APM) | Heap Buffer Overflow to Unauth RCE | 9.8 | Cataloged Sep 22 (Due Sep 25) | Zero day in data plane when APM policy and OAuth profile share virtual server; hotfix and iRule available |
| WSO2 API Manager / Control Plane / TM / Universal GW | Auth Bypass / Path Traversal RCE (Conflicting Text) | 9.8 to 10.0 | Cataloged Sep 24/25 (Due Sep 27) | CVE record cites JWT algorithm mismatch auth bypass; catalog text cites path traversal file upload RCE; exploitation confirmed |
| Adobe Commerce / Magento | Incorrect Authorization to Unauth PrivEsc | 9.1 | Cataloged Sep 24/25 (Due Sep 27) | Elevated access to sensitive resources without interaction |
| Microsoft SharePoint Server (2016, 2019, Sub Ed) | Authenticated Code Injection to RCE | 8.8 / 6.5 | Cataloged Sep 25/26 (Due Sep 28) | Requires low privileged auth; active web shell deployment observed |
| MikroTik RouterOS (7.24 before 7.24.2) | SSH Pre Auth Workflow / Rekey Bypass | 6.9 | Cataloged Sep 25/26 (Due Sep 28) | Chains with |
| MikroTik RouterOS | Argument Injection | Unspecified | Chained with | Secondary reporting links to MikroTrick chain |
| WordPress Core | Path Traversal / Remote File Inclusion to RCE | 9.2 / 8.1 | Cataloged Sep 25 (Due Sep 28) | Unauth inclusion of local PHP files; exploited hours after disclosure |
| Oracle PeopleSoft EMHub ( | Java Deserialization to Unauth RCE | 9.8 | Actively Exploited |
|
| Cisco Secure Firewall Management Center (FMC) | Unauthenticated API Authentication Bypass | 10.0 | Hotfix Out; Hardening Sep 14 | Exploited with |
| Cisco Secure Firewall Management Center (FMC) | Secondary Flaw Chained with | 5.3 | Hotfix Out; Hardening Sep 14 | Exploited in conjunction with |
| Cisco Identity Services Engine (ISE) | Unauthenticated API Authentication Bypass | 10.0 | Emergency Patch Sep 17 | Exploited zero day |
| JFrog Artifactory (Self Hosted) | Token Scope Validation Bypass to PrivEsc | High | Patched (59% still unpatched) | Chained in two request unauth admin takeover (Aug 15 to Sep 8) |
| JFrog Artifactory (Self Hosted) | Anonymous Token Disclosure | High | Patched | Chained with |
| JFrog Artifactory (Self Hosted) | JWT Forgery to Unauthenticated Admin RCE | 9.8 | Patched (49% still unpatched) | Fixed in 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20 |
| Roundcube Webmail (1.6.x, 1.7.x) | Pre Auth SQL Injection ( | 8.1 | Patched in 1.6.16 / 1.7.1 |
|
| Microsoft Windows ALPC | Heap Buffer Overflow Local PrivEsc to SYSTEM | 7.8 | Patched Sep 8 (Patch Tuesday) | Actively exploited zero day |
| Microsoft Windows Update Stack | Improper Link Resolution PrivEsc to SYSTEM | 7.8 | Patched Sep 8 (Patch Tuesday) | First actively exploited zero day in Windows Update Stack |
| Tencent Sogou Input Method (< 16.3.0.3498) | One Click RCE via | Critical | Patched Apr 2026 | Exploited by |
| SolarWinds Observability Self Hosted | Unauthenticated Remote Code Execution | Critical | Patched Sep 2026 | Paired with |
| SolarWinds Observability Self Hosted | Unauthenticated Remote Code Execution | Critical | Patched Sep 2026 | Paired with |
| Citrix NetScaler | Authentication Bypass | Critical | Patched Aug; Cataloged Sep 9 | Distinct from the two new unpatched Sep 26 NetScaler RCE zero days |
Unassigned (2x) | Citrix NetScaler ADC / Gateway | Two Unpatched Zero Day RCEs | Critical | Unpatched (Fixes Expected Sep 28) | Active exploitation reported Sep 26 |
Unconfirmed | JetBrains TeamCity | Critical RCE / Auth Flaw (Patched July) | Critical | Patched July 2026 | Actively exploited by ransomware groups |
Unconfirmed | Roundcube Webmail | Code Injection Flaw (Patched May) | High | Patched May 2026 | Active exploitation reported |
Unconfirmed | Grav CMS | Unauthenticated RCE / Flaw | High | Unconfirmed | Used by |
Attack Vectors
Internet Facing Appliance and Application Exploitation: Unauthenticated RCE, authentication bypass, Java deserialization (
PSEMHUB), SQL injection (virtuser_query), remote file inclusion, and URL encoding WAF bypasses (/%50SEMHUB/).Cloud Workload Identity and Default Key Abuse: Compromised Entra ID / Azure service principals (
Storm-3168), public GitHub issue secret leaks, excessive RBAC roles, and defaultsk-1234master keys on LiteLLM gateways with IMDSv2 header pass through.Identity Phishing and Social Engineering: OAuth device code phishing (
EvilTokensvia Vercel, Cloudflare Workers, and AWS Lambda redirectors),ClickFixfake verification prompts (MacSyncand PowerShell execution), WhatsApp and Telegram spear phishing (CHOSEN BRICK), fake DevOps coding interviews (Jade Sleet), voice spoofing vishing (Astrana Health), and public iCloud Calendar payload delivery (MacSync).Software Supply Chain and Developer Infrastructure: Re-enabled compromised GitHub Actions (
Mini Shai-Hulud), JFrog Artifactory three vulnerability auth bypass chain, weaponized Terraform dependencies (Jade Sleet), malicious npm packages (WaterPlum), Tencent Sogou Input Methodsgbiz:URI handler exploitation (UNC3569), and exposed Docker APIs on ports 2375 and 2376 (Carbonato).Domain Control Plane and Post Exploitation Abuse: Active Directory GPO weaponization for encryptionless extortion (
PAYLOAD) and identity takeover (NightEagle), commercial RMM abuse (Storm-2570),ntdsutilIFM credential dumping, and multi LLM autonomous C2 voting (CLOSEDQUORUM).Malvertising and Torrent Watering Holes: Pirated movie torrents with Solana blockchain C2 (
MovieReaper), WebDAV lures (ClearFake), and fake TVTap IPTV malvertising (RemControl).
Actors and Infrastructure Patterns
Storm-2570: Ransomware affiliate active since April 2025 deployingQilin,DragonForce,Anubis, andBERTwith identical RMM (MeshAgent,Atera,ScreenConnect,Splashtop,NinjaRMM,Remotely_Agent), tunneling (ngrok,Cloudflared), credential dumping (ntdsutilIFM,Mimikatz,LaZagne,pypykatz), lateral movement (PsExec,Impacket,NetExec), and cloud exfiltration (s5cmd,Rclone) tooling.Storm-3168(JADEPUFFER): Cloud threat actor using compromised Azure service principals,python-requests/2.34.2, and IPs45.131.66[.]106,34.153.223[.]102, and64.20.53[.]230for Azure discovery, seven minute storage/app destruction, recovery lock tampering,ListKeysharvesting, and App Service probing (WordPress, PHP CGI, LangFlow/api/v1/validate/code).Storm-2992(EvilTokens): Commercial PhaaS operator on Telegram using AI lures and*.vercel.app,*.workers.dev, and AWS Lambda redirectors to hijack OAuth device code flows onmicrosoft.com/devicelogin.UNC6240(ShinyHunters): Financially motivated group mass exploiting Oracle PeopleSoftCVE-2026-35273via/%50SEMHUB/hubto deploy JSP web shells,SIDEEYE(Ple64.exe),Neo-reGeorg, and MeshCentral; also reported compromising theClopleak site via Grav CMS.Sandworm(APT28/ GRU) andQilinRansomware: Opportunistically exploiting Cisco FMCCVE-2026-20079andCVE-2026-20316(QilinandGentlemenalso driving a ransomware surge in Japan).Jade Sleet(PUKCHONG/TraderTraitor/UNC4899),WaterPlum, and SuspectedLazarus Group: North Korean actors targeting DevOps MacBooks withFLATROOF(Telegram C2) andROOFDECK(Nostr C2) via Terraform (Jade Sleet), infecting 30,000 hosts via npm withStoatWaffle,BeaverTail,OtterCookie, andInvisibleFerret(WaterPlum), and suspected in the 351.6 million USDBitgetheist.CHOSEN BRICKOperators andMirage Kitten(UNC1549/Smoke Sandstorm/Nimbus Manticore): Iranian aligned groups deployingCHOSEN BRICKspyware via WhatsApp and Telegram against civil society, andNightLedger,ArcBridge, andBridgeHeadagainst Middle East and African aviation and FinTech.NightEagle,UNC3569, andFamousSparrow:NightEagledeploysGhostContaineron Russian Exchange servers; China linkedUNC3569exploits Sogou Input MethodCVE-2026-51990to dropGrayRabbit; China alignedFamousSparrowdeploysSparroWockyacross eight Latin American governments.AI Agent and Malware Operators: Hugging Face accounts
0TimeandNyx9(OpenAI agent activity),CLOSEDQUORUM(DeepSeek, Mistral, Gemini, OpenRouter voting C2 + Discord webhook),Carbonato(Hermes Agenton Docker),PAYLOAD(GPO encryptionless ransomware),MacSync(macOS stealer/backdoor),MovieReaper(Solana C2),x47.c(botnet/stealer),ClearFake(Amatera,ZigCryptoStealer,NetSupport), andRemControl(Android MaaS).
Observed Indicators of Compromise (IOCs)
Indicator Type | Indicator Value | Associated Activity / Actor |
|---|---|---|
IPv4 Address |
|
|
IPv4 Address |
|
|
IPv4 Address |
|
|
IPv4 Address |
|
|
IPv4 Address |
|
|
IPv4 Address |
|
|
Domain |
|
|
Domain |
|
|
Domain |
|
|
Domain |
|
|
SHA256 Hash |
|
|
SHA256 Hash |
|
|
SHA256 Hash |
|
|
SHA256 Hash |
|
|
SHA256 Hash |
|
|
Host Path |
|
|
Host Path |
|
|
Account / Key | Hugging Face | OpenAI agent activity accounts / Default LiteLLM master key |
User Agent |
|
|
MITRE ATT&CK Mapping
Technique ID | Technique Name | Mapping Type | Operational Context |
|---|---|---|---|
| Exploit Public Facing Application | Source Mapped | Check Point, Arista, F5, Cisco FMC/ISE, PeopleSoft, Artifactory, WSO2, SharePoint, NetScaler, Roundcube, WordPress, MikroTik, TeamCity, SolarWinds, Docker, |
| Valid Accounts: Cloud Accounts | Source Mapped |
|
| Valid Accounts: Default Accounts | Source Mapped | LiteLLM gateways accepting default master key |
| Phishing: Spearphishing Attachment / Link | Source Mapped |
|
| Phishing: Device Code / Steal Application Access Token | Source & Behavioral |
|
| User Execution: Malicious Link | Source Mapped |
|
| Compromise Software Supply Chain | Source Mapped |
|
| Command and Scripting Interpreter (PowerShell, Windows Cmd, Unix Shell) | Source Mapped |
|
| Server Software Component: Web Shell | Source Mapped |
|
| Process Injection: APC / Process Hollowing | Source Mapped |
|
| Create or Modify System Process: Launch Agent / Daemon / Windows Service | Source Mapped |
|
| Registry Run Keys / Scheduled Task / WMI Event Subscription | Source Mapped |
|
| Hijack Execution Flow: DLL Side Loading | Source Mapped |
|
| Modify Authentication Process | Source Mapped |
|
| Impair Defenses / Modify Registry / Indicator Removal | Source & Behavioral |
|
| Obfuscated Files or Information | Source Mapped |
|
| OS Credential Dumping (LSASS Memory, NTDS) | Source & Behavioral |
|
| Unsecured Credentials in Files / Web Browsers | Source & Behavioral |
|
| Account Manipulation / Email Collection | Behavioral Inference |
|
| System, Network, Permission Groups, and Cloud Service Discovery | Source Mapped |
|
| Lateral Movement: SMB Admin Shares / Alternate Auth Material | Source & Behavioral |
|
| Remote Access Software | Source & Behavioral |
|
| Proxy / Ingress Tool Transfer | Source Mapped |
|
| Application Layer Protocol / Web Service / Blockchain C2 | Source Mapped |
|
| Data from Information Repositories / Exfiltration Over C2, Cloud Storage, or Webhook | Source & Behavioral |
|
| Data Destruction / Inhibit System Recovery / Data Encrypted for Impact | Source & Behavioral |
|
D3FEND Behavioral Counterparts (Inferred, Not Source Assigned): Normalized URL inspection, application patching, service account and workload identity credential rotation, least privilege RBAC, independent backup and resource locks, OAuth device code flow restriction, and tenant enforced endpoint tamper protection.
Threat Detection
SIGMA: Cisco FMC CVE-2026-20079 Auth Bypass Exploitation Attempt
SIGMA: LiteLLM Default Master Key Usage
SIGMA: JFrog Artifactory Exploitation Chain (CVE-2026-42016 / CVE-2026-42018 / CVE-2026-82329)
SIGMA: NTDSUtil IFM Credential Staging (Storm-2570)
SIGMA: S5cmd or Rclone Cloud Exfiltration (Storm-2570)
SIGMA: Encoded PeopleSoft EMHub Access (CVE-2026-35273)
SIGMA: WebLogic Spawning Command Shell on PeopleSoft Host
SIGMA: Unexpected JSP or Executable in PeopleSoft Web Archive
SIGMA: Azure Service Principal Destructive Activity (Storm-3168)
SIGMA: F5 BIG-IP Suspicious Outbound Activity (CVE-2026-94127)
SIGMA: External Access to Docker API (Carbonato / Hermes Agent)
SIGMA: Suspected Web Application Exploitation Followed by Shell Execution
SIGMA: Suspicious macOS Launch Agent Creation (ROOFDECK Style)
SIGMA: Suspicious AI Provider Access With Credential Theft Behaviors (CLOSEDQUORUM)
YARA: MacSync macOS Stealer and Backdoor Variant
YARA: Storm-2570 RMM and Tunnel Binary Staging
YARA: SIDEEYE / Ple64.exe Triage Rule
YARA: Suspicious ClickFix PowerShell Command Pattern
YARA: Developer Token and Credential Collection (Mini Shai-Hulud / x47.c)
YARA: FLATROOF and ROOFDECK Rust macOS Backdoor Heuristics
YARA: CLOSEDQUORUM LLM Orchestrated Windows Implant
SIEM (KQL): Storm-2570 Affiliate Tradecraft Detection
SIEM (KQL): Azure Service Principal Anomaly and Destruction Burst (Storm-3168)
SIEM: Device Code Sign-In Followed by Inbox Rule or Device Registration (EvilTokens)
SIEM (Splunk): PeopleSoft Encoded WebLogic Hunt (CVE-2026-35273)
SIEM (Splunk): MikroTik MikroTrick SSH Rekey Anomaly (CVE-2026-67279)
SIEM (Splunk): F5 BIG-IP APM OAuth RCE Oversized Header Indicator (CVE-2026-94127)
SIEM: Exploited Edge Systems Post-Request Activity
SIEM: Suspicious CI/CD Workflow Audit and Runner Execution (Mini Shai-Hulud)
SIEM: Multi-LLM Provider Access With Credential Theft or Injection (CLOSEDQUORUM)
SIEM: SharePoint and Web Root Web Shell Hunting (CVE-2026-65660)
DEFENDER PRIORITIES
Isolate Unpatched Citrix NetScaler and Patch All Cataloged Edge Flaws Immediately: Isolate internet facing Citrix NetScaler ADC and Gateway appliances behind strict ACLs and virtual WAF patches ahead of the week of September 28 vendor fixes. Patch or mitigate all September 22 to 25 catalog additions (
CVE-2026-85102,CVE-2026-93616,CVE-2026-93952,CVE-2026-94127,CVE-2026-5430,CVE-2026-71362,CVE-2026-65660,CVE-2026-67279,CVE-2026-87902), plus Cisco FMC (CVE-2026-20079,CVE-2026-20316), Cisco ISE (CVE-2026-76460), Oracle PeopleSoft (CVE-2026-35273), Roundcube (CVE-2026-48842), SolarWinds (CVE-2026-28324,CVE-2026-28325), Windows (CVE-2026-85880,CVE-2026-81963), and JetBrains TeamCity.Hunt Post-Exploitation Artifacts Across Edge and Application Servers: Do not treat patching or literal WAF rules as incident closure. Normalize URL paths before WAF inspection. Scan Oracle PeopleSoft
PSEMHUB.warandPORTAL.warforx.jsp,u.jsp,u2.jsp,tunnel.jsp,tunnel.jspx, andPle64.exe, and check WebLogic child processes (cmd.exe,/bin/sh,bash). Inspect SharePoint directories for web shells created since September 1, review MikroTik SSH logs for unauthenticatedrekeyandexecchannels, inspect Cisco FMC for unauthorized admin creation, and rotate all credentials readable by PeopleSoft, WebLogic, SharePoint, and WSO2 service accounts.Lock Down Cloud Workload Identities, LiteLLM Gateways, and Recovery Planes: Audit all LiteLLM gateways, eliminate default master key
sk-1234, and block IMDSv2 header pass through. Revoke and rotate any Azure service principal secret that ever appeared in a GitHub issue, ticket, or commit history (even if later edited). Separate backup and recovery permissions from application contributor roles, enforce immutable resource locks that workload identities cannot remove, and alert on burst deletions followed byListKeyscalls orpython-requests/2.34.2traffic from45.131.66[.]106,34.153.223[.]102, or64.20.53[.]230.Block OAuth Device Code Phishing (
EvilTokens): Use Conditional Access policies to block the OAuth device code authentication flow tenant wide except for explicitly named constrained device accounts. Hunt the past 30 days for device code logins followed within six hours by inbox rule creation, Graph enumeration, or new device registration. Where confirmed, temporarily disable the user account in addition to revoking sessions and Primary Refresh Tokens.Deploy Agent-Lifecycle Telemetry and Behavioral AI Malware Detections: Implement the agent preservation checklist across cloud and AI environments: log credential specific token lineage, session/source IDs, container build and start logs, public route request logs, and deletion tombstones for 90+ days. Restrict Docker daemon ports 2375 and 2376 from untrusted networks (
Carbonato/Hermes Agent), and hunt for endpoints contacting multiple LLM APIs alongside LSASS access, APC/hollowing injection, persistence, and Discord webhooks (CLOSEDQUORUM).Hunt the Ransomware Affiliate and GPO Layer (
Storm-2570andPAYLOAD): Enforce tenant level endpoint tamper protection so local administrators cannot disable Windows Defender or add exclusions onC:\PerfLogs. Block unapproved RMM binaries (MeshAgent,Atera,ScreenConnect,Splashtop,NinjaRMM,Remotely_Agent) and tunnels (ngrok,Cloudflared). Alert onntdsutilIFM creation underC:\Windows\Temp,s5cmdorRcloneexecution, and anomalous Active Directory GPO modifications (Event IDs 5136 and 5137).Harden Software Supply Chains, DevOps MacBooks, and High-Risk Endpoints: Upgrade JFrog Artifactory to patched branches (7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20), disable anonymous access, and rotate JWT signing keys. Cryptographically pin all GitHub Actions, Terraform providers, and npm packages to immutable hashes and audit workflows ran between September 16 and 25 (
Mini Shai-HuludandWaterPlum). Deploy behavioral EDR on macOS to catchFLATROOFandROOFDECK(Telegram/Nostr C2, LaunchAgents,login.keychain-db) as well asMacSync(osascript,SecItemCopyMatching,ClickFixprompts, and iCloud Calendar payloads).Hunt State Espionage IOCs and Harden Helpdesk Verification: Ingest and hunt IOCs for
CHOSEN BRICKspyware,NightEagle(GhostContaineron Exchange),Mirage Kitten(NightLedger,ArcBridge,BridgeHead),UNC3569(GrayRabbit, and update Tencent Sogou Input Method to 16.3.0.3498+ while restrictingsgbiz:URIs), andFamousSparrow(SparroWocky). Enforce phishing resistant FIDO2 MFA and out of band callback verification for helpdesks to preventAstrana Healthstyle voice spoofing intrusions.
RECOMMENDED ACTIONS
Isolate internet facing Citrix NetScaler ADC and Gateway appliances or apply strict network ACLs and WAF virtual patches until week of September 28 patches arrive.
Patch all cataloged vulnerabilities (
CVE-2026-85102,CVE-2026-93616,CVE-2026-93952,CVE-2026-94127,CVE-2026-5430,CVE-2026-71362,CVE-2026-65660,CVE-2026-67279,CVE-2026-87902,CVE-2026-85880,CVE-2026-81963) and validate running builds against vendor advisories.Apply F5 BIG-IP APM hotfixes or the iRule workaround for
CVE-2026-94127, Cisco FMC hotfixes forCVE-2026-20079andCVE-2026-20316, Cisco ISE patch forCVE-2026-76460, and SolarWinds patches forCVE-2026-28324andCVE-2026-28325.Patch
CVE-2026-35273on Oracle PeopleSoft, disable EMHub/PSEMHUB where unnecessary, normalize URLs at the WAF before rule evaluation, scan for JSP web shells andPle64.exe, and rotate all PeopleSoft and WebLogic accessible credentials.Upgrade Roundcube Webmail to 1.6.16 or 1.7.1+, disable the
virtuser_queryplugin if unneeded, and inspect database logs for pre auth SQL injection (CVE-2026-48842).Upgrade JFrog Artifactory to patched releases, revoke and reissue admin tokens, rotate JWT keys, and disable anonymous token access (
CVE-2026-42016,CVE-2026-42018,CVE-2026-82329).Rotate all LiteLLM gateway master keys, remove
sk-1234, and enforce IMDSv2 hop limit 1 with no header pass through.Revoke and rotate Azure service principal secrets exposed in public repositories or edit histories, enforce least privilege RBAC, lock Recovery Services and Backup vaults with independent controls, and alert on
deleteplusListKeyssequences (Storm-3168).Block Entra ID OAuth device code authentication via Conditional Access and temporarily disable accounts exhibiting
EvilTokensinbox rule or device registration patterns.Enforce tenant level Defender tamper protection, block unapproved RMMs and tunnels (
MeshAgent,ngrok,Cloudflared), monitorntdsutilIFM creation, and alert on unauthorized GPO changes (Storm-2570andPAYLOAD).Pin GitHub Actions, Terraform modules, and npm packages to immutable commit SHAs, rotate CI/CD and developer secrets (
Mini Shai-Hulud,Jade Sleet,WaterPlum), and block external access to Docker ports 2375 and 2376 (Carbonato).Deploy the provided SIGMA, YARA, and SIEM detections across web, cloud, CI/CD, Windows, and macOS telemetry, retain AI agent lifecycle logs for 90+ days, and preserve forensic evidence prior to host remediation.
CONFIDENCE & LIMITATIONS
Incident / Intelligence Cluster | Confidence Level | Concise Rationale Based on Consulted Sources |
|---|---|---|
Edge & Enterprise KEV Additions ( | High (Exploitation) / Moderate (Specific Root Cause & Chaining Details) | Confirmed active exploitation via federal catalog additions and vendor advisories; |
Oracle PeopleSoft | High | Corroborated by primary incident response telemetry, explicit |
Cloud Identity Destruction ( | High (Activity & TTPs) / Unconfirmed (Initial Access & Country Attribution) | Backed by direct cloud and endpoint telemetry and law enforcement disruption data; initial access for |
Operationalized AI Agents, Hugging Face Trails ( | High | Supported by direct cloud telemetry, internet wide gateway scan data (3,074 instances), and verifiable public repository commit timelines. |
| High (Binary Capabilities) / Unconfirmed (Wild Deployment) | Reverse engineering confirms four model LLM voting and credential theft code, but consulted researchers explicitly note dummy webhooks and no confirmed in the wild deployment. |
Iranian | High | Backed by multi agency international government advisories and detailed technical intrusion telemetry. |
| Moderate | Detailed technical reporting from single vendor telemetry; treated as supplemental for actor attribution. |
Roundcube ( | Moderate | Confirmed technical and incident disclosures via cyber authorities and security reporting, though operator identities for Roundcube, |
Unpatched Citrix NetScaler Zero Days, | Low to Moderate / Under Attribution | NetScaler zero days rest on forensic researcher warnings prior to official Citrix CVEs/patches; |
