PUBLISHED ON

SSeepp  2200,,  22002266
EEDDIITTIIOONN  002255

When Mail Gateways And Identity Brokers Failed Open

Supply chains, AI agents, and Microsofts patch record all broke in the same week

WEEKLY OPENING

Good evening. The perimeter spent this week auditioning for the role of payload, and it got the part.

[+] Microsoft did not just break its patch record. It mailed 974 vulnerabilities, two Windows zero days already in the wild, and a year to date pile that consulted sources put past 2600.

[+] CISA stuffed 14 exploited CVEs into the KEV catalog in five days, nine of them on three day federal clocks, while Cisco handed out root on the mail gateway and a CVSS 10.0 skip past the identity bouncer on ISE.

[+] If your architecture assumed identity appliances would actually check identity, send flowers. Management plane bypasses, marketing scripts serving paste to terminal lures, and unsandboxed Chromium inside desktop utilities all clocked in for overtime.

[+] Consulted sources also documented an AI coding assistant session used to ship a worm across about 100 repositories, ShinyHunters walking into the Clop leak site, and ransomware crews treating firewall consoles like shared coworking space.

[+] One review set in this window argued verification itself was the main event, because a loud claim is not the same thing as confirmed intelligence. That caution stays on the desk. The combined material still left plenty of vendor and KEV backed trouble to inspect.

[+] Patch fatigue is not a vibe. It is a calendar with multiple federal deadlines in a single week. Let us inspect the damage.

EXECUTIVE TAKE

Density defined the window. In seven days defenders absorbed a Microsoft Patch Tuesday that dwarfed prior 2026 baselines, KEV velocity that compressed remediation to three days for nine vulnerabilities, and Cisco zero days against mail and identity control planes.

[+] This was an edge control plane week, not a content week. CVE-2026-76461 turns a crafted message into root on the box that reads inbound mail. CVE-2026-76460 turns a crafted API call into the policy brain that decides who gets on the network. Consulted sources and KEV listings treated both as exploited, with federal clocks measured in days, and Cisco warned that root is enough to hide the evidence.

[+] Supply chain risk hardened from theory to operations. JFrog Artifactory, GitLab, ConnectWise ScreenConnect, and a Brevo widget compromise all showed trusted pipelines becoming delivery systems, including public proof of concept code against self hosted DevOps tooling.

[+] AI assisted development left the hypothetical lane. Consulted sources documented Shai-Hulud as a worm launched from a hijacked coding assistant session, Hugging Face residue tied to an earlier OpenAI agent incident, and exposed LiteLLM gateways still accepting the documented default master key sk-1234.

[+] Identity failed in two directions at once. Appliance API bypass dissolved segmentation policy without a traditional access denied event, while the IDScan breach put more than 153 million driver licenses into a fraud economy that does not need your password to hurt you.

[+] Ransomware did not take the week off. Consulted sources flagged VMware vCenter CVE-2026-59310 with a ransomware KEV update, Qilin and The Gentlemen pressure against manufacturing and Japan incident volume, leak site claims across healthcare, transportation, and agriculture, and a Cisco FMC path used for smash and encrypt as well as implant persistence.

[+] A separate identity story never needed a new CVE. Microsoft threat intelligence described Storm-2945, a Midnight Blizzard subcluster, manipulating DNS and HTTP on hospitality captive portals so one redirect becomes sign in abuse or malware. Another campaign used Microsoft Teams helpdesk theater, legitimate remote support tools, PowerShell, a portable Node.js runtime, and WinRM toward domain controllers. Patching Cisco does not close that path.

[+] For leadership, patching velocity, supply chain visibility, and AI governance are no longer parallel workstreams. They are the same workstream. Internet reachable ISE, Secure Email Gateway, ScreenConnect, GitLab, Artifactory, and firewall managers should be treated as presumed touch until logs, rebuilds, and credential rotation say otherwise.

[+] Verification still earns its keep. One combined review set could not retrieve primary advisories for every circulating claim, including MikroTik CVE-2026-86060 and a reported Chrome to Windows chain. Those items stay watchlisted rather than promoted. The KEV listed and vendor confirmed set is still large enough to ruin a change window.

KEY FINDINGS

[+] CVE-2026-81963 and CVE-2026-85880: Microsoft patched two actively exploited Windows zero days, Update Stack privilege escalation and ALPC privilege escalation, inside a record 974 CVE September Patch Tuesday.

[+] CVE-2026-76461: Cisco Secure Email Gateway zero day, consulted sources split on CVSS 9.8 versus 10.0, actively exploited before disclosure, unauthenticated root via AsyncOS web interface and via SQL injection in inbound email parsing.

[+] CVE-2026-76460: Cisco ISE and ISE-PIC unauthenticated API authentication bypass, CVSS 10.0, configuration independent, added to CISA KEV with a three day federal deadline, root possible and evidence may be wiped.

[+] CVE-2026-85706: GitLab path traversal, CVSS 10.0, unauthenticated credential and secret theft, public proof of concept, treated as actively exploited in the stronger backed set.

[+] CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329: JFrog Artifactory chain exploited 15 August to 8 September against self hosted instances, anonymous token to administrator rights, Groovy plugins, web shells, and Rust backdoors.

[+] CVE-2026-84869: ConnectWise ScreenConnect improper privilege management, CVSS 9.9, KEV with a three day deadline, privilege escalation toward root plus unauthenticated remote file transfer and execution during active sessions without host confirmation.

[+] CVE-2026-59310: VMware vCenter remote code execution, ransomware flag added to KEV on 15 September, multiple gangs exploiting a July patched flaw.

[+] CVE-2026-19490: Citrix NetScaler authentication bypass added to KEV and treated as actively exploited.

[+] CVE-2026-20079: Cisco Secure Firewall Management Center authentication bypass with sustained exploitation by ransomware and extortion groups against network boundaries.

[+] CVE-2026-20316: Cisco FMC static credential abuse enabling low privilege login before escalation, used in a Qilin affiliate access path tracked as UAT-11988.

[+] CVE-2026-9586: Sangoma Switchvox unauthenticated SQL injection on the /pa endpoint, CVSS 9.3, automated exploitation to PostgreSQL backed remote code execution.

[+] CVE-2026-51990: Tencent Sogou Input Method protocol handler argument injection chained with unsandboxed Chromium, used by UNC3569 to deploy the GrayRabbit backdoor via DLL sideloading.

[+] CVE-2026-58704: Google Pixel cellular modem improper authorization, adjacent or proximal privilege escalation, no user interaction, KEV on 16 September, Google cited limited targeted use, actor Under Attribution.

[+] CVE-2026-87886: Acronis Backup plugin for cPanel WHM and Plesk, insecure permissions, local privilege escalation, KEV on 16 September, targeting scope INSUFFICIENT DATA.

[+] CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964: Linux kernel TLS memory disclosure, ebtables SNAT out of bounds write, and AF_ALG race condition added to KEV with a 21 September federal deadline.

[+] CVE-2026-59822: LiteLLM authentication bypass via any bearer token, enabling cloud metadata access when default or weak master keys are present.

[+] CVE-2026-68820: Windows AFD.sys flaw associated in consulted sources with Lazarus linked Operation Dream Job activity deploying the Troy backdoor and FudModule 3.1, Under Attribution pending further corroboration.

[+] CVE-2026-76423: shipped in Ciscos 16 September hardening set across ISE, Secure Firewall FMC, Nexus Dashboard, and email products, not KEV confirmed this week.

[+] Shai-Hulud: consulted sources documented the first confirmed AI coding assistant hijack deploying a supply chain worm across about 100 PyPI repositories.

[+] Hugging Face correlation: accounts 0Time and Nyx9 tied to the May 2026 OpenAI agent incident, with capability probing against internet, filesystem, and Azure metadata plus Chinese language registration tooling adapted for credential harvesting, actor Under Attribution.

[+] LiteLLM default keys: about 1 in 10 exposed AI gateways accepted the documented default master key sk-1234, enabling cloud account takeover.

[+] IDScan[.]net breach: more than 153 million driver licenses, 10 million ID cards, 3 million travel documents, and 579000 medical cards exposed, FBI New Orleans inquiry, Nexus advertising the dataset on Exploit forum.

[+] Brevo supply chain compromise: stolen overprivileged Cloudflare API key used to inject ClickFix overlays and backdoor plugins across customer storefronts.

[+] ClickFix expanded from illicit streaming sites into enterprise and SaaS vendor supply chains, including fake verification overlays that tell users to paste commands into the Windows Run dialog.

[+] ShinyHunters versus Clop: extortion operators breached the Clop leak site, defaced the Tor service, and stole onion private keys.

[+] Qilin leak site activity this week included claims against Imperial Healthcare Solutions, RoadEx America, Alicotrans, and agriculture technology targets, none independently confirmed by named victims.

[+] Storm, a newer ransomware entrant, claimed PANTHERx Rare, a US specialty pharmacy, claim unconfirmed by the victim.

[+] The Gentlemen led Japan ransomware incident counts in H1 2026 per consulted sources, 14 Japan cases, leak site listings moving from 48 in January to 105 in July, tooling including AdaptixC2, Chisel, Ligolo-ng, Impacket, Responder, and Rclone, plus attempts on CVE-2025-24799, CVE-2020-1472, and MS17-010, Russian keyboard traces remain Under Attribution.

[+] UNC5342, DPRK linked in consulted sources, used a redundant TRON, Aptos, and BNB Smart Chain relay to deliver credential stealing malware to cryptocurrency developers via fake job interviews.

[+] Consulted sources described a Palo Alto Unit 42 case of AI agent directed ransomware completing reconnaissance to encryption in roughly ten hours using more than 50 mapped ATT&CK techniques.

[+] Microsoft documented more than 1 million BEC emails in early August, with passkey themed phishing and AI generated executive impersonation still in the mix.

[+] CVE-2026-86060: MikroTik RouterOS privilege escalation through SSH related handling remains NOT CONFIRMED in the combined set.

[+] A reported Chrome to Windows exploit chain of CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 was not corroborated as a chain. CVE-2026-85880 still stands separately as a Microsoft patched, exploited ALPC zero day.

[+] Sandworm, also tracked as APT44, Cyclops Blink resurrection on new Linux infrastructure, and Cisco FMC clustering remain Under Attribution where explicit primary confirmation was uneven across the combined set.

WEEKLY THREAT NARRATIVE

The Patch Tuesday that changed the baseline. Microsofts September release addressed 974 vulnerabilities, nearly double Julys record of 570, and pushed 2026 year to date volume past 2600. CVE-2026-81963 and CVE-2026-85880 both sit at CVSS 7.8, but exploitation in the wild is the part that pays. Volume itself creates paralysis. Organizations on a monthly cycle now face a backlog that can exceed quarterly capacity. AI assisted vulnerability discovery is the stated driver. Defenders still have to rank by exploitation, not by calendar.

[+] KEV velocity compressed decision cycles. Between 8 and 11 September, CISA added 14 KEV entries, one of the densest single week waves in the combined material. Nine carried three day federal deadlines. The set spanned GitLab CVE-2026-85706, Artifactory CVE-2026-42016 and CVE-2026-42018, ScreenConnect CVE-2026-84869, Cisco ISE CVE-2026-76460, Citrix NetScaler CVE-2026-19490, Google Pixel CVE-2026-58704, Acronis CVE-2026-87886, and the Linux kernel trio. DevOps toolchains, identity infrastructure, and network edge devices are now a standing KEV class.

[+] Ciscos week was a targeting signal, not a product quality speech. CVE-2026-76461 in Secure Email Gateway allows unauthenticated root. A compromised SEG sits inline on mail flow, which means credential harvesting, rule injection, and persistence at the trust boundary. CVE-2026-76460 in ISE bypasses management API authentication even when the appliance is “configured correctly,” which is a phrase that did not age well. ISE is the policy brain for segmentation, RADIUS, and 802.1X. Bypass it and downstream policy dissolves without a tidy access denied event. The 16 September hardening bundle added more than 20 CVEs across ISE, FMC, Nexus Dashboard, and ASA or FTD, four of them at CVSS 10.0.

[+] Firewall consoles became a shared address. Consulted sources described unrelated operators hitting Cisco management and gateway products in a tight span: suspected Russian state tooling overlap with Cyclops Blink, a Qilin affiliate path through static credentials and tunnels, and opportunistic access attempts. That is concentration on a vendor family, not proof of one coordinated campaign. Cisco also warned that patching does not remove implants already planted on exploited FMC instances. Compromise assessment is not optional for exposed boxes.

[+] Supply chain exploitation operationalized in the build system. Attackers chained CVE-2026-42016 and CVE-2026-42018 in JFrog Artifactory: unauthenticated caller, anonymous internal token, token exchange for administrator rights. Post exploitation included persistent admin creation, hostile Groovy plugins, web shells, and Rust backdoors. GitLab CVE-2026-85706 turns path traversal into secret theft. ScreenConnect CVE-2026-84869 turns a remote support plane into unauthorized file movement and code execution. Remediation that only bumps versions, without looking for persistence, is how you patch a house while the guest keeps a key.

[+] Supply chain also moved into the browser. Brevo customers inherited a stolen Cloudflare API token that could rewrite JavaScript and tracker widgets on commercial sites. Attackers served ClickFix overlays dressed as human verification, pushing PowerShell through the Windows Run dialog and dropping malicious WordPress admin plugins. Staging domains included yelahaye[.]surf and boiseno[.]club behind commercial reverse proxies. Backend code review means little if a trusted widget still has unmonitored script injection authority.

[+] AI agents left the slideware. Shai-Hulud moved from session hijack to dependency confusion to worm propagation to code exfiltration, poisoning a PyPI package and spreading across about 100 repositories. Baseline controls in consulted sources were blunt: verify dependencies by checksums and allowlists, keep secrets out of extension reach, and treat AI recommendations as signals, not permissions. Hugging Face accounts 0Time and Nyx9 showed capability probing, including spreadsheet tests of internet, filesystem, and Azure metadata access. LiteLLM exposure showed default key sk-1234 still working in about 1 in 10 internet reachable gateways, with CVE-2026-59822 as a bearer token bypass into cloud metadata. AI tooling is expanding attack surface faster than governance.

[+] Identity data supply chains remain fragile. IDScan[.]net exposed government issued documents at scale, not a pile of recycled passwords. Nexus listed the set on Exploit forum. Downstream risk is synthetic identity, account opening, and benefit fraud. KYC and AML programs that trust document verification as a clean reference should assume the reference data is tainted.

[+] Ransomware tempo did not cool. CISA marked CVE-2026-59310 for ransomware use on 15 September. Shadowserver tracked more than 450 internet exposed vCenter servers, and earlier incident work found 361 affected IPs across 47 countries with reverse SSH persistence. Qilin kept leak site pressure on healthcare, transportation, and agriculture. The Gentlemen led Japan H1 2026 counts. Storm claimed a specialty pharmacy. Leak site listings remain claims until victims or investigators corroborate scope. ShinyHunters compromising the Clop leak site added a rare public fight between extortion shops, with possible exposure of victim negotiation data.

[+] Espionage took the desktop utility entrance. UNC3569 weaponized CVE-2026-51990 in Tencent Sogou Input Method, software with enormous installed base. The chain used argument injection in the sgbiz protocol handler plus embedded unsandboxed Chromium, then DLL sideloading of GrayRabbit. One click, full user privilege, no need for a glamorous browser zero day.

[+] Hospitality networks and helpdesk theater remained an identity path. Storm-2945 activity on captive portals shows DNS and HTTP manipulation turning a hotel network into device code phishing or malware delivery. A separate unnamed campaign used Microsoft Teams helpdesk pretext, legitimate remote support tooling, PowerShell, portable Node.js, and WinRM toward domain controllers. That is social engineering with enterprise furniture, not a missing patch on ISE.

[+] Switchvox and other internet facing admin services rounded out the opportunistic scan surface. CVE-2026-9586 on /pa is unauthenticated SQL injection with a straight line to command execution. Exposed PBX, NAC, FMC, GitLab, ScreenConnect, and backup plugins do not need a nation state speech to ruin a weekend.

[+] DPRK linked UNC5342 used multi chain blockchain lookups as a dead drop for C2 configuration, targeting crypto developers with fake job interviews. Lazarus associated reporting around CVE-2026-68820, Troy, and FudModule 3.1 against defense and aerospace stays Under Attribution. Consulted sources also described an AI agent directed ransomware intrusion that compressed reconnaissance to encryption into about ten hours.

[+] Verification remains part of the narrative, not a footnote. Circulating claims against MikroTik RouterOS and a Chrome to Windows chain did not meet the confirmation bar in the combined set. Exposure review of internet facing admin planes is still the defensible move even when a specific CVE remains watchlisted. Escalate with evidence. Do not turn every headline into an incident declaration.

NOTABLE TECHNICAL SIGNALS

[+] Top CVEs: CVE-2026-81963 Windows Update Stack EoP, CVSS 7.8, exploited Patch Tuesday zero day.

[+] CVE-2026-85880 Windows ALPC EoP, CVSS 7.8, exploited Patch Tuesday zero day.

[+] CVE-2026-76461 Cisco Secure Email Gateway unauthenticated root, CVSS 9.8 or 10.0 depending on consulted sources, exploited before disclosure.

[+] CVE-2026-76460 Cisco ISE API authentication bypass, CVSS 10.0, KEV three day deadline.

[+] CVE-2026-85706 GitLab path traversal, CVSS 10.0, unauthenticated secret theft.

[+] CVE-2026-42016 JFrog Artifactory auth bypass, CVSS 8.8, KEV chain component.

[+] CVE-2026-42018 JFrog Artifactory improper auth, CVSS 7.5, KEV chain component.

[+] CVE-2026-82329 JFrog Artifactory follow on in the same chain.

[+] CVE-2026-84869 ConnectWise ScreenConnect privilege abuse, CVSS 9.9, KEV three day deadline.

[+] CVE-2026-59310 VMware vCenter RCE, ransomware flag on KEV.

[+] CVE-2026-19490 Citrix NetScaler auth bypass, KEV.

[+] CVE-2026-20079 Cisco Secure Firewall Management Center auth bypass, exploited.

[+] CVE-2026-20316 Cisco FMC static credential abuse preceding escalation and tunneling.

[+] CVE-2026-9586 Sangoma Switchvox /pa SQL injection, CVSS 9.3.

[+] CVE-2026-51990 Tencent Sogou protocol handler injection, UNC3569.

[+] CVE-2026-58704 Google Pixel modem improper auth, KEV.

[+] CVE-2026-53266 Linux kernel ebtables SNAT out of bounds write, CVSS 8.8, KEV.

[+] CVE-2025-39682 Linux kernel TLS receive path memory disclosure, CVSS 9.8, KEV.

[+] CVE-2025-39964 Linux kernel AF_ALG race, CVSS 7.8, KEV.

[+] CVE-2026-87886 Acronis backup plugin local privilege escalation, KEV.

[+] CVE-2026-59822 LiteLLM bearer token auth bypass.

[+] CVE-2026-68820 Windows AFD.sys, Lazarus associated reporting, Under Attribution.

[+] Attack vectors this week: unauthenticated API and parser abuse on internet accessible admin services, including ISE, FMC, GitLab, ScreenConnect, Switchvox, and Secure Email Gateway.

[+] Supply chain compromise through DevOps tooling, PyPI worming, and stolen CDN or marketing API tokens that rewrote trusted JavaScript.

[+] User executed ClickFix commands via explorer.exe to PowerShell or cmd, plus passkey themed phishing and AI generated BEC.

[+] Credential theft through GitLab secret read, Artifactory token exchange, LiteLLM default keys, IDScan document dumps, and AI gateway metadata access.

[+] Privilege escalation via Windows zero days, Linux kernel KEV entries, ScreenConnect, and Acronis plugins.

[+] Ransomware adoption of fresh KEV items, leak site claims, intra criminal leak site theft, protocol tunneling, and service stop before encryption.

[+] Desktop protocol handler injection and DLL sideloading through ubiquitous input method software.

[+] Blockchain dead drop C2 configuration and fake job interview delivery against crypto developers.

[+] Actor and infrastructure patterns: UNC3569 used Sogou, unsandboxed Chromium, and GrayRabbit memory staging.

[+] ShinyHunters demonstrated extortion versus ransomware conflict by taking Clop leak site keys.

[+] Nexus operated as a commercial PII broker on Exploit forum.

[+] Shai-Hulud used PyPI plus hijacked assistant sessions.

[+] 0Time and Nyx9 showed pre operational capability development on Hugging Face.

[+] ClickFix infrastructure used yelahaye[.]surf and boiseno[.]club behind reverse proxies to serve encoded PowerShell and fake browser error modals.

[+] Qilin, including UAT-11988, combined FMC credential abuse, Active Directory reconnaissance, SOCKS or reverse SSH tunnels, and encryption.

[+] The Gentlemen tooling set in Japan reporting included AdaptixC2, Chisel, Ligolo-ng, Impacket, Responder, and Rclone.

[+] Storm-2945 / Midnight Blizzard used hospitality captive portals for device code phishing or malware.

[+] UNC5342 used TRON, Aptos, and BNB Smart Chain relays.

[+] Sandworm / APT44 and Cyclops Blink on new Linux infrastructure remain Under Attribution in this combined edition.

[+] MITRE ATT&CK and D3FEND themes: T1190 Exploit Public Facing Application across Cisco SEG, ISE, FMC, GitLab, Citrix NetScaler, vCenter, ScreenConnect, and Switchvox.

[+] T1195.001 Compromise Software Dependencies for Shai-Hulud and Artifactory repo takeover.

[+] T1195.002 Compromise Software Supply Chain for Brevo widget tampering.

[+] T1068 Exploitation for Privilege Escalation for CVE-2026-81963, CVE-2026-85880, CVE-2026-53266, CVE-2026-84869.

[+] T1078 Valid Accounts for static credential abuse and privileged session theft.

[+] T1204.002 User Execution for ClickFix paste to terminal.

[+] T1059.001 PowerShell for encoded ClickFix payloads.

[+] T1059.006 Python for Shai-Hulud and agent probing scripts.

[+] T1574.002 DLL Side Loading for GrayRabbit.

[+] T1552.001 Credentials In Files for GitLab, LiteLLM, and Artifactory secrets.

[+] T1586.002 Email Account Compromise for SEG interception, passkey phishing, and BEC.

[+] T1583.006 Web Services for Hugging Face staging and LiteLLM gateways.

[+] T1656 Impersonation for AI generated executive BEC and helpdesk theater.

[+] T1572 Protocol Tunneling for SOCKS and reverse SSH in the Qilin path.

[+] T1071.001 Web Protocols and inferred T1102 Web Service, blockchain variant, for UNC5342 multi chain lookup, behavioral basis rather than a fully source mapped ATT&CK lock.

[+] T1489 Service Stop before Qilin encryption.

[+] T1505.003 Web Shell as a hunt hypothesis on internet facing apps, including Artifactory post exploitation.

[+] D3FEND D3-PSE Process Spawn Analysis for anomalous children of AI assistants and build tools.

[+] D3FEND D3-CFP Credential Forwarding Protection for blocking metadata endpoints from AI gateway containers and rotating provider keys.

[+] SIGMA: suspicious AI coding assistant process behavior.

title: AI Coding Assistant Spawning Suspicious Child Processes
id: d4f8a2b1-9c3e-4f7a-8b2d-1e6f5a9c3d2e
status: experimental
description: Detects AI coding assistants spawning unusual child processes indicative of session hijack or supply chain compromise matching the Shai-Hulud pattern
author: Inferlume NightWatch
date: 2026-09-20
references:
  - hxxps[://]www[.]mandiant[.]com/resources/blog/ai-risk-resilience-2026
  - hxxps[://]www[.]sentinelone[.]com/labs/agents-at-large-tracing-illicit-openai-agent-activity-on-hugging-face/
logsource:
  category: process_creation
  product: windows
detection:
  selection_ai_parent:
    ParentImage|endswith:
      - '\\GitHub Copilot.exe'
      - '\\Cursor.exe'
      - '\\Codeium.exe'
      - '\\Tabnine.exe'
  selection_suspicious_child:
    Image|endswith:
      - '\\powershell.exe'
      - '\\cmd.exe'
      - '\\wscript.exe'
      - '\\cscript.exe'
      - '\\python.exe'
      - '\\pip.exe'
      - '\\twine.exe'
  condition: selection_ai_parent and selection_suspicious_child
fields:
  - ParentImage
  - Image
  - CommandLine
  - User
  - ParentCommandLine
falsepositives:
  - Legitimate build or deployment scripts triggered from AI assisted development
level: high
tags:
  - attack.t1059.006
  - attack.t1195.001

[+] SIGMA: ClickFix clipboard execution via Run dialog.

title: Potential ClickFix Clipboard Command Execution via Run Dialog
id: 5a8e1b32-94b1-4f81-a832-72648eef9201
status: experimental
description: Detects powershell.exe or cmd.exe spawned directly from explorer.exe with hidden window, encoded command, or download strings typical of ClickFix user execution
references:
  - hxxps[://]sansec[.]io/research/brevo-supply-chain-attack
author: Inferlume NightWatch
date: 2026-09-20
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith: '\\explorer.exe'
  selection_child:
    Image|endswith:
      - '\\powershell.exe'
      - '\\pwsh.exe'
      - '\\cmd.exe'
  selection_cli:
    CommandLine|contains:
      - ' -w hidden '
      - ' -windowstyle hidden '
      - ' -enc '
      - ' -encodedcommand '
      - 'Net.WebClient'
      - 'DownloadString'
      - 'Invoke-Expression'
      - 'IEX('
  condition: selection_parent and selection_child and selection_cli
falsepositives:
  - Administrative maintenance scripts initiated manually via Run dialog, rare on enterprise workstations
level: high
tags:
  - attack.execution
  - attack.t1204.002
  - attack.t1059.001

[+] SIGMA: suspicious traversal and sensitive file requests.

title: Suspicious Traversal and Sensitive File Requests to Web Application
id: 8c5c54bc-447d-4d40-9c5e-95d8f5a4d84a
status: experimental
description: Detects requests commonly associated with path traversal, secret discovery, or source control metadata access
author: Inferlume NightWatch
date: 2026-09-20
logsource:
  category: webserver
detection:
  selection_method:
    cs-method:
      - GET
      - POST
      - HEAD
  selection_path:
    cs-uri-query|contains:
      - '../'
      - '..%2f'
      - '%2e%2e%2f'
      - '%252e%252e%252f'
    cs-uri-stem|contains:
      - '/.git/'
      - '/.env'
      - '/etc/passwd'
      - '/proc/self/environ'
      - '/api/v4/projects/'
  condition: selection_method and selection_path
falsepositives:
  - Authorized security testing
  - Vulnerability scanning from approved scanners
level: high
tags:
  - attack.t1190
  - attack.t1552.001

[+] YARA: Shai-Hulud worm indicators.

rule Shai_Hulud_Worm_Indicators
{
    meta:
        description = "Detects Shai-Hulud worm artifacts from 2026 AI risk reporting"
        author = "Inferlume NightWatch"
        date = "2026-09-20"
        reference = "hxxps[://]www[.]mandiant[.]com/resources/blog/ai-risk-resilience-2026"
        threat_actor = "Unknown (AI assistant hijack)"
        malware_family = "Shai-Hulud"
    strings:
        $pypi_publish = "twine upload" nocase
        $dependency_confusion = "dependency_confusion" nocase
        $shai_hulud_str = "Shai-Hulud" nocase
        $ai_assistant_hijack = "ai_assistant" nocase
        $coding_assistant = "coding_assistant" nocase
        $copilot = "copilot" nocase
        $credential_exfil = "GITHUB_TOKEN" nocase
        $pypi_token = "PYPI_TOKEN" nocase
        $npm_token = "NPM_TOKEN" nocase
        $obfuscated_payload = /eval\(compile\(base64\.b64decode/
    condition:
        2 of ($pypi_publish, $dependency_confusion, $shai_hulud_str, $ai_assistant_hijack, $coding_assistant, $copilot, $credential_exfil, $pypi_token, $npm_token, $obfuscated_payload)
}

[+] YARA: GrayRabbit backdoor.

rule Win_Backdoor_GrayRabbit_UNC3569 {
    meta:
        description = "Detects GrayRabbit backdoor binaries and related memory staging modules used by UNC3569"
        author = "Inferlume NightWatch"
        reference = "CVE-2026-51990 / UNC3569 Campaign"
        date = "2026-09-20"
        score = 80
    strings:
        $str1 = "GrayRabbit" ascii wide nocase
        $str2 = "sgbiz://protocol" ascii wide
        $str3 = "rundll32.exe" ascii wide
        $magic_header = { 4D 5A 90 00 }
        $hex_pattern = { 8B 45 ?? 33 D2 89 45 ?? 8A 04 11 30 04 17 42 }
    condition:
        $magic_header at 0 and (2 of ($str*) or $hex_pattern)
}

[+] YARA: generic web shell triage.

rule Suspicious_WebShell_Execution_Primitives
{
  meta:
    description = "Triage rule for common web shell execution and command launch primitives"
    author = "Inferlume NightWatch"
    date = "2026-09-20"
    confidence = "heuristic"

  strings:
    $php_exec_1 = "shell_exec(" nocase
    $php_exec_2 = "system(" nocase
    $php_exec_3 = "passthru(" nocase
    $php_exec_4 = "proc_open(" nocase
    $php_decode = "base64_decode(" nocase
    $asp_exec_1 = "ProcessStartInfo" nocase
    $asp_exec_2 = "cmd.exe" nocase
    $jsp_exec_1 = "Runtime.getRuntime().exec" nocase
    $py_exec_1 = "subprocess.Popen" nocase
    $py_exec_2 = "os.popen(" nocase

  condition:
    filesize < 500KB and
    (
      2 of ($php_exec_*) or
      ($php_decode and 1 of ($php_exec_*)) or
      1 of ($asp_exec_*) or
      $jsp_exec_1 or
      1 of ($py_exec_*)
    )
}

[+] SIEM pseudocode: KEV exploitation hunting.

SEARCH sourcetype=firewall OR sourcetype=web_proxy
  (destination_port IN (80, 443, 8080, 8443) AND
   uri_path MATCHES ".*(/cgi-bin/|/webvpn/|/admin/).*")
| WHERE http_method IN ("POST", "PUT") AND response_code = 200
| STATS count BY src_ip, dest_ip, uri_path, user_agent
| WHERE count > 5

SEARCH sourcetype=web_server (uri_path LIKE "%/../%" OR uri_path LIKE "%..\\%")
  AND (uri_path LIKE "%/api/v4/%" OR uri_path LIKE "%/.git/%")
| WHERE http_status = 200 AND bytes_out > 1024
| STATS count, sum(bytes_out) BY src_ip, dest_ip, uri_path

SEARCH sourcetype=application_logs (uri_path LIKE "%/access/api/v1/aws/token/%")
| WHERE http_method = "POST"
| STATS count BY src_ip, dest_ip, http_status, user_agent
| WHERE (http_status = 200 AND count > 10) OR (http_status = 401 AND count > 50)

SEARCH sourcetype=screenconnect_logs
  (event_type IN ("SessionCreated", "UserAdded", "RoleChanged") AND
   user_name IN ("anonymous", "token:anonymous", "admin*"))
| STATS count BY src_ip, user_name, event_type

SEARCH sourcetype=syslog OR sourcetype=auditd
  (message MATCHES ".*(tls|ebtables|af_alg).*") AND
  (message MATCHES ".*(OOB|out.of.bounds|race.condition|memory.disclosure).*")
| STATS count BY host, message

[+] SIEM pseudocode: Sangoma Switchvox /pa exploitation.

SELECT
    timestamp,
    source_ip,
    destination_ip,
    http_method,
    uri_path,
    request_headers,
    http_payload,
    response_code
FROM web_proxy_events
WHERE uri_path LIKE '%/pa'
  AND http_method = 'POST'
  AND (
      http_payload LIKE '%<PolycomIPPhone>%'
      OR http_payload LIKE '%PhoneIP%'
  )
  AND (
      http_payload LIKE '%SELECT%'
      OR http_payload LIKE '%UNION%'
      OR http_payload LIKE '%pg_sleep%'
      OR http_payload LIKE '%copy%from%program%'
      OR http_payload LIKE '%\\x27%'
  )
GROUP BY source_ip, destination_ip, uri_path
HAVING count(*) >= 1

[+] SIEM pseudocode: correlate probing with follow on admin activity.

LET suspicious_requests =
  web_logs
  WHERE uri CONTAINS_ANY (
    "../", "%2e%2e%2f", "/.git/", "/.env",
    "/etc/passwd", "/proc/self/environ"
  )
  OR response_status IN (401, 403, 500)
  GROUP BY source_ip, destination_host, user_agent
  HAVING count(*) >= 10

LET follow_on_admin_activity =
  application_audit
  WHERE action IN (
    "user_created", "token_created", "api_key_created",
    "role_changed", "plugin_installed", "repository_exported",
    "configuration_changed"
  )

RETURN suspicious_requests
  JOIN follow_on_admin_activity
    ON destination_host = target_host
   AND follow_on_admin_activity.timestamp
       BETWEEN suspicious_requests.first_seen
       AND suspicious_requests.first_seen + 30m
  ENRICH WITH identity_events, endpoint_process_events
  ORDER BY risk_score DESC

[+] SIEM pseudocode: static credential login to a management interface followed by tunneling tools.

SEARCH auth_events
WHERE dest_asset_role = network_management_interface
  AND auth_result = success
  AND account_type = low_privilege_static
FLAG known low priv default style accounts WITHIN last 24h
JOIN process_or_network_events ON same_host
WHERE process_name IN (ssh, plink, ncat, socat)
   OR dest_port IN (22, 443)
  AND connection_direction = outbound_or_reverse
  WITHIN 30m AFTER auth_events.timestamp
ALERT SEVERITY high
MESSAGE Static credential login to management interface followed by tunneling tool execution, possible CVE-2026-20316 style post exploitation

DEFENDER PRIORITIES

[+] First, treat internet reachable Cisco Secure Email Gateway as an incident candidate, not a patch ticket. CVE-2026-76461 is unauthenticated root on the box that reads the mail. If the fix cannot land now, pull the appliance off untrusted inbound paths, lock admin interfaces, require phishing resistant MFA, and look for rule changes, unexpected accounts, and missing logs. Cisco has already warned that root is enough to hide the evidence.

[+] Second, do the same for Cisco ISE and ISE-PIC on CVE-2026-76460, plus Secure Firewall Management Center on CVE-2026-20079 and CVE-2026-20316. ISE is the policy brain for segmentation, RADIUS, and 802.1X. FMC is the console that other people have been sharing this week, including ransomware and implant operators. Patching does not evict a guest who already kept a key. Isolate management listeners behind bastion hosts or a dedicated management network, then run compromise assessment.

[+] Third, triage the rest of the dense KEV wave as presumed targeting, not routine maintenance. GitLab CVE-2026-85706, JFrog Artifactory CVE-2026-42016 and CVE-2026-42018, ConnectWise ScreenConnect CVE-2026-84869, Citrix NetScaler CVE-2026-19490, and the Linux kernel set CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 all came with short federal clocks and, in several cases, public proof of concept code. Audit internet exposure first. Read logs, tokens, plugins, and persistence before you celebrate the version bump.

[+] Fourth, put AI assisted development under governance that would embarrass last quarter’s slideware. Enforce dependency checksums and allowlists, keep long lived secrets out of assistant reach, review recent PyPI and npm publications from developer identities, hunt Shai-Hulud patterns, and pull LiteLLM gateways off the open internet. Default master key sk-1234 is not a vibe. It is an account takeover.

[+] Fifth, if vCenter still lacks the CVE-2026-59310 fix from July, assume ransomware operators got the memo. Consulted sources tracked hundreds of internet exposed instances and reverse SSH persistence. Run control plane assessment, not a quiet patch window.

[+] Sixth, identity fraud and leak site claims need owners outside the SOC. IDScan[.]net exposed government issued documents at scale, so KYC and AML checks should step up verification rather than trust the scan. Healthcare, transportation, and agriculture teams should internally verify Qilin and Storm leak site claims even when the named victim has not confirmed. Hospitality networks still need a look for Storm-2945 captive portal tricks that no Cisco patch will fix.

[+] Seventh, build the exposure picture before the next headline does it for you. Inventory internet facing GitLab, Artifactory, ScreenConnect, ISE, FMC, SEG, NetScaler, vCenter, Switchvox, VPN, firewall managers, and equivalent admin planes. Compare deployed versions to vendor advisories and the KEV catalog directly. Where a circulating CVE stays NOT CONFIRMED, treat it as a verification task, not an instant incident declaration.

[+] Eighth, turn on the boring telemetry that makes the rest of this list possible. Keep reverse proxy, WAF, application audit, identity provider, and endpoint logs long enough to join reconnaissance, privileged changes, token creation, plugin installs, exports, and process execution. A management plane without audit logs is a private office for someone you did not hire.

RECOMMENDED ACTIONS

[+] Patch CVE-2026-76461 on Cisco Secure Email Gateway immediately. If delayed, isolate inbound internet mail handling and restrict admin access.

[+] Patch CVE-2026-76460 on Cisco ISE and ISE-PIC immediately. There is no useful workaround in the combined material. Take management APIs off untrusted networks.

[+] Patch CVE-2026-20079 and CVE-2026-20316 on Cisco Secure Firewall Management Center, then hunt for implants, static credential reuse, tunnels, and unexpected admin sessions. Do not treat the upgrade as clearance.

[+] Upgrade ConnectWise ScreenConnect to 26.6.5 or later for CVE-2026-84869. Confirm no unauthorized file transfer, session creation, or role changes landed first.

[+] Update Sangoma Switchvox to 8.4.0.2 to close unauthenticated SQL injection on /pa, and review PostgreSQL command execution artifacts.

[+] Run compromise assessment on internet facing GitLab, Artifactory, ScreenConnect, Citrix NetScaler, vCenter, Switchvox, FMC, ISE, and SEG before or while patching. Look for new admins, tokens, plugins, web shells, Groovy payloads, reverse SSH, and wiped logs.

[+] Inventory every internet facing administrative, VPN, firewall management, source code, artifact repository, PBX, backup plugin, and remote management service. If it answers the whole internet, it is already on someone else’s scan list.

[+] Verify vendor advisories and the CISA KEV catalog directly before classifying a circulating CVE as actively exploited. Promote KEV listed and vendor confirmed items. Keep MikroTik CVE-2026-86060 and the reported Chrome to Windows chain as watch items.

[+] Restrict remaining admin interfaces behind VPN, zero trust access, IP allowlists, out of band proxies, or a dedicated management network.

[+] Require phishing resistant MFA for privileged access to code hosting, remote management, appliance management, cloud admin, and identity planes.

[+] Audit AI coding assistant configurations. Enforce dependency checksums and allowlists, remove long lived tokens from extension scope, and review recent package publications from developer identities.

[+] Rotate credentials that may have leaked through GitLab path traversal, Artifactory token exchange, LiteLLM default key sk-1234, stolen Cloudflare or CDN tokens, and any SEG or ISE admin path.

[+] Block internet access to LiteLLM and similar AI gateways. Set a strong master key, isolate cloud metadata endpoints, and watch for bearer token bypass CVE-2026-59822.

[+] Deploy the SIGMA rules for AI assistant child processes and ClickFix explorer.exe to PowerShell or cmd. Hunt with the Shai-Hulud and GrayRabbit YARA rules and the web shell triage rule.

[+] Put the supplied web request, Switchvox /pa, Artifactory token, ScreenConnect, kernel, and tunneling detections in monitoring mode, then tune against approved scanners.

[+] Hunt web server and application directories for newly written scripts, encoded payloads, command execution primitives, unexpected binaries, and hostile plugins.

[+] Implement Content Security Policy script src controls and subresource integrity on production web properties so a poisoned marketing widget cannot become your payload server.

[+] Rotate Cloudflare, CDN, and marketing SaaS API tokens to least privilege. Confirm no leftover keys can rewrite JavaScript on customer storefronts.

[+] Update document verification and fraud rules for the IDScan[.]net license, ID card, travel document, and medical card exposure. Coordinate with KYC, AML, and fraud teams on synthetic identity.

[+] Review Hugging Face organizational accounts for commits and artifacts matching 0Time and Nyx9 capability probing, including metadata and filesystem tests.

[+] Validate Linux kernel patching for CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 against the 21 September federal deadline.

[+] If vCenter was unpatched for CVE-2026-59310 since July, assume compromise, reduce internet exposure, and hunt reverse SSH plus control plane changes.

[+] Apply remaining Cisco 16 September hardening across ISE, FMC, Nexus Dashboard, ASA, and FTD, including items that are not yet KEV listed.

[+] Audit public IP space for exposed NAC, firewall, PBX, backup, and remote support listeners. If the management plane is on the internet, assume it is being polled.

[+] Review privileged account creation, API token issuance, role changes, plugin installation, repository or configuration exports, and authentication or federation edits across the window.

[+] For healthcare, transportation, agriculture, and specialty pharmacy environments, internally verify Qilin and Storm leak site claims even when the victim has not confirmed.

[+] Document ShinyHunters versus Clop leak site theft in threat intelligence and watch for dumped negotiation data or unpublished extortion material.

[+] Document evidence before assigning actor names, incident scope, or external notification. Under Attribution is a valid status. Guesswork is not.

CONFIDENCE & LIMITATIONS


Claim

Confidence

Rationale

Microsoft 974 CVE Patch Tuesday

High

Vendor patch record in consulted sources

CVE-2026-81963 and CVE-2026-85880

High

Exploited Windows zero days in the same release

CVE-2026-76460 Cisco ISE

High

Vendor confirmation plus KEV and three day clock

CVE-2026-76461 Cisco SEG

High

Vendor confirmation plus KEV, CVSS 9.8 vs 10.0 split

CVE-2026-84869 ScreenConnect

High

Vendor confirmation plus KEV

CVE-2026-85706 GitLab

High

Stronger backed set shows exploitation and public PoC

CVE-2026-42016 and CVE-2026-42018

High

Chained abuse plus KEV listing

CVE-2026-59310 vCenter ransomware flag

High

KEV update, exposure counts less precise

CVE-2026-20079 and CVE-2026-20316 FMC

High

Vendor and KEV backed exploitation paths

CVE-2026-9586 Switchvox

High

Independent exploitation reporting in consulted sources

CVE-2026-51990 UNC3569 GrayRabbit

Moderate

Vendor research line, not a KEV item in this set

Brevo ClickFix widget poison

High

Vendor post mortem plus forensic reconstruction

Shai-Hulud worm scale

Moderate

Single research line, repo count not independently verified

LiteLLM sk-1234 exposure

Moderate

Research snapshot, environment specific

0Time and Nyx9 Hugging Face tie

Moderate

Strong technical correlation, actor Under Attribution

IDScan[.]net document counts

Moderate

Consulted reporting plus FBI inquiry, Nexus claims unverified

ShinyHunters vs Clop leak site

Moderate

On site defacement reported, single reporting line

Qilin, Storm, The Gentlemen victim names

Low

Leak site claims, victim confirmation incomplete

Storm-2945 captive portal path

Moderate

Microsoft threat intelligence in consulted sources

CVE-2026-86060 MikroTik

NOT CONFIRMED

Primary advisory not established in combined set

Chrome to Windows chain

NOT CONFIRMED

Chain not corroborated, CVE-2026-85880 stands alone

Sandworm Cyclops Blink on FMC

Under Attribution

Tooling overlap reported, explicit confirmation uneven

Lazarus CVE-2026-68820 Troy FudModule

Under Attribution

Association not locked in this edition

UNC5342 blockchain dead drop

Moderate

Technical pattern described, campaign scope incomplete