Threat Newsletter September 21, 2026

Share

AI-assisted offense moved from theory to documented cases this week. A ransomware crew let an agent run an intrusion end to end, Anthropic published a misuse report, and Spain's data regulator logged its first AI-agent breach notification. Edge devices got hit again: Cisco, Check Point, GitLab, MikroTik and others are all in play. On the identity side, attackers are getting past MFA with passkey-themed vishing, and old supply chain compromises are still surfacing months later.


AI agents now run ransomware end to end (JADEPUFFER)

SOCRadar documented JADEPUFFER, a campaign where an AI agent planned and executed an extortion operation with no evidence of human approval. It got in through an exposed Langflow server (CVE-2025-3248), found a MinIO service with default credentials, and forged a token using a public default Nacos signing key. It then encrypted 1,342 configuration records. A follow-on locker, ENCFORGE, targets model checkpoints, vector databases and training data.

Key takeaways

  • Nothing here is a new technique. It's exposed services, default credentials and missing patches, exploited at machine speed.
  • Inventory internet-facing AI workflow platforms and code-execution endpoints.
  • Back up AI assets (models, vector data, training sets) offline and immutable. Most backup plans don't cover them.
AI Agents Now Run Ransomware Attacks End-to-End Without Human Operators
AI-driven JADEPUFFER ransomware autonomously stole credentials, encrypted data, and targeted AI models using exposed services.

Anthropic's misuse report: ShinyHunters, Midnight Blizzard, GTG-10007

Anthropic's report covers December 2025 to August 2026. A ShinyHunters-linked actor ("frkoo") ran a pipeline that scanned 1.8 million Android APKs for hardcoded secrets, and another actor pulled 2,100+ Azure AD token sets across 40+ tenants in about 34 hours. Midnight Blizzard automated malware development and phishing, and a Chinese-speaking group (GTG-10007) ran autonomous vulnerability research against security appliances. Anthropic banned the accounts and notified authorities and victims.

Key takeaways

  • Compressed timelines are the story: one case went from a single stolen developer token to full admin in under three hours.
  • Hardcoded secrets in mobile apps and repos are being harvested at scale.
  • Autonomous vuln research against security products means more appliance zero-days.
Hackers Leverage Claude to Exfiltrate Secrets from 1.8M Android apps
ShinyHunters-linked criminals used Claude to scan 1.8M Android apps for hardcoded secrets, turning exposed credentials into rapid enterprise access.

Spain's data agency gets its first AI-powered breach report

The AEPD was notified of an attack allegedly run by an AI agent. It searched for flaws, logged in, probed the application for more weaknesses, then modified personal data and accessed invoices. The agency hasn't verified the claim yet, but says the notification shows AI-driven breaches are no longer theoretical.

Key takeaways

  • Regulators are now telling organizations to build AI-driven attacks into their risk models.
  • Response playbooks written for human-speed attackers may not hold up.
  • Over-permissioned tokens and API keys are what agents exploit best.
First Agentic AI Data Breach Reported to Spanish Regulator
Spanish Data Protection Agency investigates a reported data breach in which an AI agent allegedly chained together login, vulnerability discovery, and personal-data access.

China rejects AI "fearmongering" after Amodei urges a slowdown

Over the weekend, Anthropic CEO Dario Amodei publicly called for companies to slow the pace at which they improve AI capabilities, and Sam Altman and Elon Musk backed him. China's Foreign Ministry rejected the call as fearmongering. Amodei had also advocated restricting Chinese access to advanced chips and cracking down on distillation.

Key takeaways

  • The AI-governance divide between the US and China is widening, not closing.
  • Chip controls and model distillation are now central to the dispute.
  • Expect this to shape how state-linked actors get access to frontier models.
China Rejects AI ‘Fearmongering’ After Amodei Urges Slowdown
China criticized calls from leading US technology executives to put the brakes on artificial intelligence development and impose tighter curbs on Chinese model makers.

CISA adds 5 exploited flaws (Artifactory, ScreenConnect, RouterOS)

Two JFrog Artifactory bugs (CVE-2026-42016, CVE-2026-42018) are being chained with CVE-2026-82329 to take admin control, drop Groovy plugins and install Rust backdoors. ScreenConnect CVE-2026-84869 (CVSS 9.9) is a client-side flaw allowing file transfer and execution in an active session without host confirmation. Two MikroTik RouterOS flaws (CVE-2026-67277, CVE-2026-86060) are the "MikroTrick" exploit chain CERT Polska reported

Key takeaways

  • Federal deadlines for RouterOS and ScreenConnect have already passed. The Artifactory deadline is September 25.
  • ScreenConnect: update to 26.6.5.
  • Artifactory is a high-value target, so hunt for rogue admin accounts and unexpected plugins.
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
CISA adds five exploited flaws in Artifactory, ScreenConnect, and RouterOS to KEV, with fixes due by September 25.

Cisco Secure Email Gateway zero-day (CVE-2026-76461)

Attackers exploited this before Cisco disclosed and patched it on September 15. It allows unauthenticated remote root command execution, reachable by sending an email through the appliance. CISA added it to KEV quickly. Cisco said it contacted Secure Email Cloud customers where it saw signs of compromise.

Key takeaways

  • No authentication, root access, in-the-wild exploitation. Patch first, then hunt.
  • On-prem deployments carry more risk because a compromised gateway can pivot internally.
  • Attackers may have wiped Cisco's published IOCs, so a clean IOC sweep isn't proof of a clean box.
Cisco warns customers of actively exploited zero-day in email gateways
The company confirmed the defect was exploited before it was disclosed and patched, but it did not describe the nature of the attacks or the scope of impact across its customer base.

Dutch NCSC: Check Point VPN exploitation is imminent

The NCSC expects exploitation soon of two critical Check Point VPN flaws: CVE-2026-85102 (certificate validation) and CVE-2026-85103 (heap overflow in the certificate ASN.1 decoder). Both can lead to remote code execution. Check Point patched on September 9, and there's no public PoC yet.

Key takeaways

  • The window between patch and exploit is closing fast. Patch now, before a PoC lands.
  • R82.20 isn't affected. LivePatch Take 24 covers R81.20, R82 and R82.10.
  • If you run Site-to-Site VPN, restrict rules to trusted IPs.
Dutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk
Two critical Check Point VPN flaws could enable remote code execution. Patch now and restrict VPN access before exploitation begins.

GitLab's perfect-10 bug under attack days after patching (CVE-2026-85706)

A path traversal in GitLab's repository commits API lets unauthenticated attackers read arbitrary files. GitLab fixed it September 10 (19.3.2, 19.2.6, 19.1.8). CISA confirmed exploitation and watchTowr saw probing, noting it can take just one HTTP request.

Key takeaways

  • GitLab servers hold source code, configs and credentials, so treat exposed instances as potentially compromised.
  • Patch, or pull self-hosted instances off the internet.
  • Hunt for POST requests to the commits API containing file.path parameters.
Perfect-10 GitLab bug under attack days after patch lands
CISA confirms active exploitation as watchTowr spots miscreants probing internet-facing servers

Passkey phishing hijacks Microsoft cloud accounts

Microsoft detailed two campaigns. One was a million-plus CEO-fraud emails (August 3–5) pushing fake ServiceNow ACH payments. The other is passkey-themed vishing and smishing that leads victims to AitM or device-code flows. Once in, attackers register their own MFA method, then use Microsoft Graph for recon and bulk SharePoint, OneDrive and mailbox exfiltration. Initial access overlaps with UNC6671 and the ShinyHunters/Falcon extortion ecosystem.

Key takeaways

  • Attackers are abusing passkey enrollment as a lure, not breaking passkeys.
  • Watch for new MFA method registrations and Graph API behavior across events, not single calls.
  • Help desk impersonation via personal phones bypasses your email controls.
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Microsoft details a million-email CEO fraud campaign and passkey-themed attacks that compromised cloud accounts and enabled data exfiltration.

TanStack supply chain attack leads to 170 stolen CrowdSec repos

CrowdSec disclosed that attackers cloned about 170 private GitHub repositories on May 22. They used an OAuth token from a former employee's account, compromised through May's TanStack npm attack. The theft went unnoticed until the code appeared on a cybercrime forum on September 16. Production systems weren't touched, but some user emails and investor details were exposed.

Key takeaways

  • MFA doesn't stop malware stealing an already-authorized OAuth token.
  • Remove access the day someone leaves. CrowdSec removed the account three days after the theft.
  • GitHub's enterprise audit log keeps Git events for only seven days, so stream them to your own storage.
TanStack Supply Chain Attack Lets Hackers Steal 170 Private CrowdSec GitHub Repositories
CrowdSec has disclosed that attackers copied about 170 private GitHub repositories after a former employee’s account was compromised through May’s TanStack npm supply chain attack.

Florida DMV breach traced to an officer's personal device

Florida's motor vehicle agency confirmed the breach ShinyHunters claimed. Attackers used one Plant City Police user's credentials that were stored on the employee's personal device. The agency learned of it September 4.

Key takeaways

  • One credential on a personal device was enough to reach a state-level database.
  • This is the ShinyHunters pattern: social engineering and account compromise, then bulk data theft.
  • Audit where credentials for sensitive government or partner systems actually live.
Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device
The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police officer’s personal device.

Feral Wolf hits Russian firms via Confluence and 1C

BI.ZONE tracked Feral Wolf hitting Russian retail, construction, manufacturing and IT from May through August 2026. Entry points were Confluence (CVE-2023-22515), a weak PostgreSQL password that let attackers escape a container, and unprotected 1C:Enterprise clusters. The group used new MQTT- and Matrix-based backdoors, an RDP tunneling proxy and the GenieLocker ransomware.

Key takeaways

  • C2 over MQTT and Matrix blends into normal traffic, so baseline your outbound protocols.
  • Container isolation only helps if the services behind it are hardened.
  • Keep 1C management services off the public internet and disable debug mode.
Feral Wolf Ransomware Attacks Exploit Atlassian Confluence and Misconfigured 1C Systems
Feral Wolf targets Russian firms via exposed software and weak credentials, using backdoors and GenieLocker ransomware to encrypt data.

Tajin Group: a guarantee-marketplace vendor in phishing and money laundering

Recorded Future's Insikt Group profiled Tajin Group, a vendor on Chinese-language Telegram guarantee marketplaces (it moved from Dabai to Xinbi). It does phishing, card theft and laundering, using UAE payment gateways like CCAvenue, Geidea and N-Genius plus Selfridges gift cards. It buys anonymous numbers and usernames via Fragment Market for OPSEC.

Key takeaways

  • Guarantee marketplaces are the new hub for Chinese-speaking fraud groups, and vendors hop between them when they get sanctioned or disrupted.
  • Fragment anonymous numbers make attribution harder than burner SIMs do.
  • Payment processors and gift-card issuers should watch for the small-amount, randomized testing patterns.
Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group
Analyze Tajin Group’s role in phishing and Chinese money laundering. Discover how this Telegram-based vendor exploits payment gateways and adapts its financial fraud operations.

KREMLIN banking malware hijacks Chrome and Edge

Elastic Security Labs (REF9334) documented a Brazilian banking operation delivering KREMLIN, a toolkit that installs a malicious browser extension to steal credentials, cookies and session tokens. It uses Ethereum smart contracts as dead-drop resolvers for C2, so takedowns are harder. Elastic's sinkholed canary domain saw 1,515 infected systems, over 98% in Brazil.

Key takeaways

  • Malicious extensions bypass Chromium integrity checks by forging Secure Preferences entries.
  • Blockchain-based C2 resolution defeats domain takedowns.
  • Hunt for unexpected extensions and Secure Preferences tampering.
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
KREMLIN targets Brazilian bank users with malicious Chrome and Edge extensions that steal credentials, session tokens, cookies, and browser data.

CenterPoint Energy confirms breach after data leak

After a hacker leaked a 2.5 GB archive and claimed roughly 7.5 million customer records, CenterPoint told the SEC that an unauthorized party obtained personal information on a portion of customers through an external-facing system. Service delivery wasn't affected. SecurityWeek couldn't verify the data or the claimed volume.

Key takeaways

  • Treat the 7.5M figure as an unverified claim. The company has only confirmed "a portion" of customers.
  • The actor also threatened to attack "main infrastructure" next time, so watch for escalation.
  • CenterPoint data has surfaced before via third-party incidents like MOVEit.
Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data
Texas utility CenterPoint Energy has informed the SEC about a data breach after a hacker leaked files stolen from its systems.