Threat Newsletter September 21, 2026
AI-assisted offense moved from theory to documented cases this week. A ransomware crew let an agent run an intrusion end to end, Anthropic published a misuse report, and Spain's data regulator logged its first AI-agent breach notification. Edge devices got hit again: Cisco, Check Point, GitLab, MikroTik and others are all in play. On the identity side, attackers are getting past MFA with passkey-themed vishing, and old supply chain compromises are still surfacing months later.
AI agents now run ransomware end to end (JADEPUFFER)
SOCRadar documented JADEPUFFER, a campaign where an AI agent planned and executed an extortion operation with no evidence of human approval. It got in through an exposed Langflow server (CVE-2025-3248), found a MinIO service with default credentials, and forged a token using a public default Nacos signing key. It then encrypted 1,342 configuration records. A follow-on locker, ENCFORGE, targets model checkpoints, vector databases and training data.
Key takeaways
- Nothing here is a new technique. It's exposed services, default credentials and missing patches, exploited at machine speed.
- Inventory internet-facing AI workflow platforms and code-execution endpoints.
- Back up AI assets (models, vector data, training sets) offline and immutable. Most backup plans don't cover them.

Anthropic's misuse report: ShinyHunters, Midnight Blizzard, GTG-10007
Anthropic's report covers December 2025 to August 2026. A ShinyHunters-linked actor ("frkoo") ran a pipeline that scanned 1.8 million Android APKs for hardcoded secrets, and another actor pulled 2,100+ Azure AD token sets across 40+ tenants in about 34 hours. Midnight Blizzard automated malware development and phishing, and a Chinese-speaking group (GTG-10007) ran autonomous vulnerability research against security appliances. Anthropic banned the accounts and notified authorities and victims.
Key takeaways
- Compressed timelines are the story: one case went from a single stolen developer token to full admin in under three hours.
- Hardcoded secrets in mobile apps and repos are being harvested at scale.
- Autonomous vuln research against security products means more appliance zero-days.

Spain's data agency gets its first AI-powered breach report
The AEPD was notified of an attack allegedly run by an AI agent. It searched for flaws, logged in, probed the application for more weaknesses, then modified personal data and accessed invoices. The agency hasn't verified the claim yet, but says the notification shows AI-driven breaches are no longer theoretical.
Key takeaways
- Regulators are now telling organizations to build AI-driven attacks into their risk models.
- Response playbooks written for human-speed attackers may not hold up.
- Over-permissioned tokens and API keys are what agents exploit best.

China rejects AI "fearmongering" after Amodei urges a slowdown
Over the weekend, Anthropic CEO Dario Amodei publicly called for companies to slow the pace at which they improve AI capabilities, and Sam Altman and Elon Musk backed him. China's Foreign Ministry rejected the call as fearmongering. Amodei had also advocated restricting Chinese access to advanced chips and cracking down on distillation.
Key takeaways
- The AI-governance divide between the US and China is widening, not closing.
- Chip controls and model distillation are now central to the dispute.
- Expect this to shape how state-linked actors get access to frontier models.

CISA adds 5 exploited flaws (Artifactory, ScreenConnect, RouterOS)
Two JFrog Artifactory bugs (CVE-2026-42016, CVE-2026-42018) are being chained with CVE-2026-82329 to take admin control, drop Groovy plugins and install Rust backdoors. ScreenConnect CVE-2026-84869 (CVSS 9.9) is a client-side flaw allowing file transfer and execution in an active session without host confirmation. Two MikroTik RouterOS flaws (CVE-2026-67277, CVE-2026-86060) are the "MikroTrick" exploit chain CERT Polska reported
Key takeaways
- Federal deadlines for RouterOS and ScreenConnect have already passed. The Artifactory deadline is September 25.
- ScreenConnect: update to 26.6.5.
- Artifactory is a high-value target, so hunt for rogue admin accounts and unexpected plugins.

Cisco Secure Email Gateway zero-day (CVE-2026-76461)
Attackers exploited this before Cisco disclosed and patched it on September 15. It allows unauthenticated remote root command execution, reachable by sending an email through the appliance. CISA added it to KEV quickly. Cisco said it contacted Secure Email Cloud customers where it saw signs of compromise.
Key takeaways
- No authentication, root access, in-the-wild exploitation. Patch first, then hunt.
- On-prem deployments carry more risk because a compromised gateway can pivot internally.
- Attackers may have wiped Cisco's published IOCs, so a clean IOC sweep isn't proof of a clean box.

Dutch NCSC: Check Point VPN exploitation is imminent
The NCSC expects exploitation soon of two critical Check Point VPN flaws: CVE-2026-85102 (certificate validation) and CVE-2026-85103 (heap overflow in the certificate ASN.1 decoder). Both can lead to remote code execution. Check Point patched on September 9, and there's no public PoC yet.
Key takeaways
- The window between patch and exploit is closing fast. Patch now, before a PoC lands.
- R82.20 isn't affected. LivePatch Take 24 covers R81.20, R82 and R82.10.
- If you run Site-to-Site VPN, restrict rules to trusted IPs.

GitLab's perfect-10 bug under attack days after patching (CVE-2026-85706)
A path traversal in GitLab's repository commits API lets unauthenticated attackers read arbitrary files. GitLab fixed it September 10 (19.3.2, 19.2.6, 19.1.8). CISA confirmed exploitation and watchTowr saw probing, noting it can take just one HTTP request.
Key takeaways
- GitLab servers hold source code, configs and credentials, so treat exposed instances as potentially compromised.
- Patch, or pull self-hosted instances off the internet.
- Hunt for POST requests to the commits API containing
file.pathparameters.

Passkey phishing hijacks Microsoft cloud accounts
Microsoft detailed two campaigns. One was a million-plus CEO-fraud emails (August 3–5) pushing fake ServiceNow ACH payments. The other is passkey-themed vishing and smishing that leads victims to AitM or device-code flows. Once in, attackers register their own MFA method, then use Microsoft Graph for recon and bulk SharePoint, OneDrive and mailbox exfiltration. Initial access overlaps with UNC6671 and the ShinyHunters/Falcon extortion ecosystem.
Key takeaways
- Attackers are abusing passkey enrollment as a lure, not breaking passkeys.
- Watch for new MFA method registrations and Graph API behavior across events, not single calls.
- Help desk impersonation via personal phones bypasses your email controls.

TanStack supply chain attack leads to 170 stolen CrowdSec repos
CrowdSec disclosed that attackers cloned about 170 private GitHub repositories on May 22. They used an OAuth token from a former employee's account, compromised through May's TanStack npm attack. The theft went unnoticed until the code appeared on a cybercrime forum on September 16. Production systems weren't touched, but some user emails and investor details were exposed.
Key takeaways
- MFA doesn't stop malware stealing an already-authorized OAuth token.
- Remove access the day someone leaves. CrowdSec removed the account three days after the theft.
- GitHub's enterprise audit log keeps Git events for only seven days, so stream them to your own storage.

Florida DMV breach traced to an officer's personal device
Florida's motor vehicle agency confirmed the breach ShinyHunters claimed. Attackers used one Plant City Police user's credentials that were stored on the employee's personal device. The agency learned of it September 4.
Key takeaways
- One credential on a personal device was enough to reach a state-level database.
- This is the ShinyHunters pattern: social engineering and account compromise, then bulk data theft.
- Audit where credentials for sensitive government or partner systems actually live.

Feral Wolf hits Russian firms via Confluence and 1C
BI.ZONE tracked Feral Wolf hitting Russian retail, construction, manufacturing and IT from May through August 2026. Entry points were Confluence (CVE-2023-22515), a weak PostgreSQL password that let attackers escape a container, and unprotected 1C:Enterprise clusters. The group used new MQTT- and Matrix-based backdoors, an RDP tunneling proxy and the GenieLocker ransomware.
Key takeaways
- C2 over MQTT and Matrix blends into normal traffic, so baseline your outbound protocols.
- Container isolation only helps if the services behind it are hardened.
- Keep 1C management services off the public internet and disable debug mode.

Tajin Group: a guarantee-marketplace vendor in phishing and money laundering
Recorded Future's Insikt Group profiled Tajin Group, a vendor on Chinese-language Telegram guarantee marketplaces (it moved from Dabai to Xinbi). It does phishing, card theft and laundering, using UAE payment gateways like CCAvenue, Geidea and N-Genius plus Selfridges gift cards. It buys anonymous numbers and usernames via Fragment Market for OPSEC.
Key takeaways
- Guarantee marketplaces are the new hub for Chinese-speaking fraud groups, and vendors hop between them when they get sanctioned or disrupted.
- Fragment anonymous numbers make attribution harder than burner SIMs do.
- Payment processors and gift-card issuers should watch for the small-amount, randomized testing patterns.

KREMLIN banking malware hijacks Chrome and Edge
Elastic Security Labs (REF9334) documented a Brazilian banking operation delivering KREMLIN, a toolkit that installs a malicious browser extension to steal credentials, cookies and session tokens. It uses Ethereum smart contracts as dead-drop resolvers for C2, so takedowns are harder. Elastic's sinkholed canary domain saw 1,515 infected systems, over 98% in Brazil.
Key takeaways
- Malicious extensions bypass Chromium integrity checks by forging Secure Preferences entries.
- Blockchain-based C2 resolution defeats domain takedowns.
- Hunt for unexpected extensions and Secure Preferences tampering.

CenterPoint Energy confirms breach after data leak
After a hacker leaked a 2.5 GB archive and claimed roughly 7.5 million customer records, CenterPoint told the SEC that an unauthorized party obtained personal information on a portion of customers through an external-facing system. Service delivery wasn't affected. SecurityWeek couldn't verify the data or the claimed volume.
Key takeaways
- Treat the 7.5M figure as an unverified claim. The company has only confirmed "a portion" of customers.
- The actor also threatened to attack "main infrastructure" next time, so watch for escalation.
- CenterPoint data has surfaced before via third-party incidents like MOVEit.












