chiprook

Cybersecurity News

September 18
Security

Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia

Cyber-espionage group NightEagle (APT-Q-95), which previously attacked Chinese defense and technology companies, has shifted to Russian organizations. According to Kaspersky, the hackers entered networks via VPN using stolen credentials, then deployed the GhostContainer backdoor on Microsoft Exchange servers.

Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia
Security

Russia Claims Strikes on De Novo Data Center in Kyiv, Ukraine

Russian forces claimed strikes on Ukrainian infrastructure, including the De Novo data center in Kyiv — one of the country's largest. According to TASS, the facility served Ukrainian military servers. De Novo calls itself a sovereign cloud and AI provider serving Ukraine's largest banks.

Russia Claims Strikes on De Novo Data Center in Kyiv, Ukraine
Security

Microsoft patches CVSS 10.0 Azure AI Foundry flaw enabling privilege escalation

Microsoft released patches for a maximum-severity vulnerability CVE-2026-85889 in Azure AI Foundry with a CVSS score of 10.0. Missing authentication in a critical function allowed an unauthenticated attacker to escalate privileges over the network. No customer action is required.

Microsoft patches CVSS 10.0 Azure AI Foundry flaw enabling privilege escalation
Security

Calendar-based phishing jumps 33,000% since May, researchers say

Sublime researchers report a sharp rise in ICS phishing: from May to September 2026, attacks via calendar invitations grew by about 33,000%. Attackers send invitations from free services like Gmail, bypassing filters, and lead victims to install RMM tools such as ScreenConnect.

Calendar-based phishing jumps 33,000% since May, researchers say
Security

LG, Samsung vow to ban apps hijacking Smart TVs for botnets

LG and Samsung said they will ban apps that hijack smart TVs and use them in botnets. The companies promised stricter software vetting in their app stores.

LG, Samsung vow to ban apps hijacking Smart TVs for botnets
Security

Abandoned CDN domain re-registered, thousands of sites still call it

In July 2025, an unknown party registered a domain previously owned by a defunct CDN. Thousands of sites, repositories, and documentation pages still contain hardcoded links to hosts under this domain, creating a risk of content substitution.

Abandoned CDN domain re-registered, thousands of sites still call it
Security

Plugin4Shell lets repository owners swap pinned plugin code across four AI coding agents

Air Security disclosed the Plugin4Shell vulnerability: a plugin repository owner can replace a pinned version with malicious code in four popular AI coding agents. Anthropic fixed the issue in Claude Code 2.1.179, OpenAI in Codex 0.146.0; GitHub Copilot remains vulnerable.

Plugin4Shell lets repository owners swap pinned plugin code across four AI coding agents
Security

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

Microsoft released patches for 18 vulnerabilities in Azure cloud services and Copilot AI products. Most are privilege escalation; all fixes are server-side, requiring no customer action. A separate Windows privilege escalation vulnerability (CVE-2026-85921) was also fixed.

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Security

WeaselBiscuit Stealer spreads via 13 npm packages

Researchers discovered 13 npm packages distributing a new JavaScript stealer called WeaselBiscuit. The malware steals data from Chrome extension storage and shares traits with BeaverTail malware from the North Korean Contagious Interview campaign.

WeaselBiscuit Stealer spreads via 13 npm packages
Security

RTIA Investigates Fake AARTO Fine Scam, Possible eNatis Breach

South Africa's RTIA is investigating a possible breach of the eNatis system after scammers sent fake AARTO fine notices from Fines SA using real vehicle numbers. The fraudsters use cloned payment portals, SMS, WhatsApp and email, offering a 50% discount for payment.

RTIA Investigates Fake AARTO Fine Scam, Possible eNatis Breach
Security

Hacker turns 25 cents into 46 billion fake Bitcoins to steal $770,000 from Symbiosis DeFi exchange

On September 11, DeFi network Symbiosis lost about $770,000 (9.97 BTC) due to two smart contract vulnerabilities. The attacker gained admin rights, set a negative fee, and issued 46 billion unbacked syBTC, exchanging them for BTCB, cbBTC, WBTC, and RBTC.

Hacker turns 25 cents into 46 billion fake Bitcoins to steal $770,000 from Symbiosis DeFi exchange
Security

Sophos: South African organizations under pressure from ransomware

Sophos published its State of Ransomware in South Africa 2026 report: 63% of incidents resulted in data encryption, 58% of organizations paid a ransom, the median demand was 6.9 million rand, and the average recovery cost exceeded 17 million rand.

Sophos: South African organizations under pressure from ransomware
Security

Polite bots are better at fooling people on social media

Surfshark surveyed 1,722 people worldwide and found participants recognized only 40% of AI bots on social media. Positive and friendly bots were noticed in 38% of cases versus 50.2% for negative ones, and bots with emojis were caught in over 60% of cases.

Polite bots are better at fooling people on social media
Security

CISA Upgrades Vulnerability Reporting Platform with More Automation

The US cybersecurity agency CISA has been using the new VINCE-NT platform since September 17, 2026, to receive and coordinate vulnerability reports. It adds automation, simplified bulletin publication, and new tools for researchers.

CISA Upgrades Vulnerability Reporting Platform with More Automation
Security

Proxmox VE authentication bypass: port 8006 count not the key number

An authentication bypass was found in Proxmox VE 7.x–8.0.3: with the tfa-challenge parameter, code skipped password verification for accounts without 2FA, including root@pam. The vendor confirmed attacks with data encryption for extortion; PVE 7 will not receive a patch as the branch is end-of-life.

Proxmox VE authentication bypass: port 8006 count not the key number
Security

NCSC issues advice on cyber adversary simulation

The UK's NCSC published documents for its Cyber Adversary Simulation (CyAS) program — certification of red teaming services. The scheme will launch in November, covering two approaches: full-spectrum external attack and a scenario with pre-existing access.

NCSC issues advice on cyber adversary simulation
Security

Brevo supply chain attack injects malware into 100,000 websites

Hackers breached Brevo twice: on September 10 via a SAML SSO vulnerability, accessing 138 accounts, and on September 14 using a stolen Cloudflare API key to inject malicious scripts into brevo.com, sibforms.com, and three client JS files. Sansec estimates over 100,000 sites were affected, with attackers showing a fake Cloudflare check and infecting WordPress admin panels.

Brevo supply chain attack injects malware into 100,000 websites
Security

Cisco's two exploited flaws and CISA's patch clock

CISA added two Cisco vulnerabilities to the KEV catalog: CVE-2026-76461 in Secure Email Gateway (RCE with root via SQL injection in email) and CVE-2026-76460 in ISE (authentication bypass, CVSS 10.0). US federal agencies have deadlines of September 17 and 19 respectively.

Cisco's two exploited flaws and CISA's patch clock
Security

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

Researchers linked a financially motivated hacker to the development and distribution of the JavaScript stealer PhantomRaven via the npm registry. With high confidence, the malware was written using a large language model, indicated by verbose comments, stub code, and statistical token analysis.

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
Security

Anthropic and OpenAI warn AI-enabled bioweapons risk is a wake-up call for biotech

Anthropic and OpenAI leaders publicly acknowledged the risk of AI-enabled bioweapons and called for slower development. Anthropic reported attempts to use its models to enhance chikungunya and avian flu; some scientists consider the threat overstated.

Anthropic and OpenAI warn AI-enabled bioweapons risk is a wake-up call for biotech
Security

Critical Orkes Conductor vulnerability exploited in attacks

CVE-2026-58138 (CVSS 9.8) in Orkes Conductor allows unauthenticated remote code execution via inline workflow tasks. A patch shipped in June in version 3.30.2, a PoC appeared in August, and attacks have been observed since August 21; Fortinet blocked about 1,300 attempts on September 8-9.

Critical Orkes Conductor vulnerability exploited in attacks
Security

Thales launches Luna 8 as AI and quantum computing pressure cryptography

Thales introduced the Luna 8 hardware security module for generating and protecting cryptographic keys. It supports existing and post-quantum algorithms, with an updatable architecture allowing migration without replacing applications or infrastructure.

Thales launches Luna 8 as AI and quantum computing pressure cryptography
Security

SK Shieldus reports rise in ransomware targeting public vulnerabilities, AI abuse cases emerge

SK Shieldus in its August EQST report said 849 ransomware attacks were recorded worldwide in July. Attackers increasingly breach networks through public vulnerabilities, steal data, and use built-in AI features as attack tools.

SK Shieldus reports rise in ransomware targeting public vulnerabilities, AI abuse cases emerge
Security

Manufacturing accounts for 22% of all ransomware victims

According to Black Kite, from April 2025 to March 2026 the manufacturing sector accounted for 22% of all ransomware victims — the fifth consecutive year the industry is most attacked. From January to July 2026, incidents rose 40% — from 847 to 1183, with an 85.4% increase in Europe.

Manufacturing accounts for 22% of all ransomware victims
Security

DHS watchdog finds TSA lacked oversight of vendor access to passenger ID images

A DHS Inspector General audit found that a TSA CAT-2 biometric system contractor could extract passenger driver's license and passport images while servicing equipment without the agency's knowledge. TSA did not track such extractions and could not confirm data deletion; recommendations to strengthen controls were accepted, but one remains unresolved.

DHS watchdog finds TSA lacked oversight of vendor access to passenger ID images
Security

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

Check Point warned of a critical vulnerability CVE-2026-91843 in Security Management and Log Server: an unauthenticated attacker can execute code with root privileges via the login process. No exploitation has been observed, but the vendor published IoCs and urged immediate updates. Tanium closed five vulnerabilities, Kaspersky fixed a Redis issue in Security 10 for Linux Mail Server.

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Security

AI Agent Breaches Spanish Organization, Modifies Personal Data

An AI agent carried out a cyberattack on a Spanish organization and modified personal data in its systems. According to Dark Reading, such attacks using autonomous agents are moving from exotic to commonplace.

AI Agent Breaches Spanish Organization, Modifies Personal Data
Security

Abandoned IoT apps keep sending sensitive data to broken servers

Researchers at UMass Amherst analyzed 61,500 abandoned Android smart home apps: nearly three in four have dependencies with known vulnerabilities, and 40.8% of data transmission points lead to unreachable or dangerous domains.

Abandoned IoT apps keep sending sensitive data to broken servers
Security

Hardcoded MCP Credentials Found in Public GitHub Files

Hush Security analyzed about 82,000 MCP configuration files on GitHub and found that 12% of credential slots contained keys and tokens in plaintext. 24% of found secrets have broad permissions and do not expire by default, and 243 secrets remained in Git history after removal from the current version.

Hardcoded MCP Credentials Found in Public GitHub Files
Security

98% of Fraudulent Hires Have Company Credentials by the Time They’re Caught

A HYPR report showed: 98% of HR leaders have encountered candidate fraud, and 96% are confident their company would detect deception. By the time they are caught, 98% of fake employees already have corporate credentials and access to the internal network.

98% of Fraudulent Hires Have Company Credentials by the Time They’re Caught