Sep 28
The Hot Drop for 09-28-2026
ShinyHunters already breached the FBI jobs portal with a PeopleSoft zero-day. WordPress patches were ignored within hours. Citrix NetScaler zero-days remain unpatched and active. What’s next?
Since the last show: 2 new · 6 developing · 2 returning · 4 dropped · 43% overlap with the previous show
Contents
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day
- WordPress 7.1.2 Patches Critical RCE as Attackers Exploit Within Hours
- Citrix NetScaler Zero-Days Under Active Exploitation
- Citrix NetScaler Zero-Days Now in CISA KEV
- Infostealers drive 74% surge in cookie theft, exposing 94 billion credentials
- ShinyHunters claims FBI breach to refute reports, while sextortion and healthcare vishing campaigns exploit leaked data
- STAR Labs researcher earns $113k for 14-year-old Linux AF_ALG race condition enabling root and Docker escape
- Lazarus Group Steals $292M From KelpDAO Bridge
- Huntress: Attackers Exploit Samsung MagicINFO Flaw to Compile Monero Miner on Endpoint
- KELA reports 3.9B credentials stolen by infostealers as Vidar 2.0 targets Azure
1. ShinyHunters Exploits Oracle PeopleSoft Zero-Day (Lead)
Blast radius expanded: new vendor(s): microsoft; 6 new indicator(s) observed; 1 new attacker infrastructure indicator(s)
What changed
ShinyHunters, tracked by Google Mandiant as UNC6240, breached over one hundred organizations, including the FBI’s jobs portal, by exploiting a critical zero-day in Oracle PeopleSoft. The group exploited CVE-2026-35273 between May 27 and June 9, 2026. Oracle issued an advisory on June 10, rating the flaw a CVSS 9.8 and urging immediate patching for PeopleTools versions 8.61 and 8.62. The University of Nottingham confirmed the exposure of roughly 455,000 email addresses. ShinyHunters claims to have stolen two to three terabytes of data from the FBI, a claim the FBI is currently investigating. Google’s Mandiant confirmed UNC6240 targeted Oracle PeopleSoft servers using a zero-day to bypass security updates. They exploited the PSEMHUB endpoint via URL-encoding to deploy JSP web shells and backdoors like SIDEEYE. Detect unauthenticated PSEMHUB access and anomalous JSP file creation. Watch for connections to azurenetfiles[.]net or IP 162[.]219[.]30[.]165. Verify PeopleSoft patch status immediately. The FBI investigates ShinyHunters’ claim of stealing two to three terabytes of employee data.
How it works
UNC6240 modified its exploit to bypass web application firewall rules by using URL-encoding tricks to access the vulnerable Environment Management Hub endpoint. This technique allowed the attackers to deploy JSP web shells and backdoors like SIDEEYE, utilizing Java deserialization to execute remote code on the target systems. The attack chain reached dozens of systems globally across higher education, healthcare, and technology sectors, achieving unauthenticated remote code execution with a CVSS score of 9.8.
What to do
UNC6240 bypassed WAF rules by URL-encoding the PSEMHUB endpoint, exposing unpatched PeopleSoft servers to remote code execution. Apply the Oracle Security Alert Advisory patch immediately for PeopleTools versions 8.61 and 8.62 to close the remote, authentication-less exploitability of CVE-2026-35273. Disable the EMHub service and remove unauthorized web shell files to mitigate the expanded global campaign targeting higher education, healthcare, and technology sectors.
Limits and watch
The specific patch release date for CVE-2026-35273 remains uncertain, so organizations cannot yet confirm the exact timeline for full remediation of the Updates Environment Management component. Threat actors may use any percent-encoded, mixed-case, or otherwise non-normalized variant of /PSEMHUB/ to bypass WAFs, meaning static path blocking is insufficient. Watch for unexpected file creation in web directories followed by web server processes spawning command shells or script interpreters to detect web shell deployment.
Vulnerabilities
- CVE-2026-35273 — CVSS 9.8 (Critical) · CISA KEV · Oracle Corporation PeopleSoft Enterprise PeopleTools. Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management).
Techniques
- AML.T0000 Search Open Technical Databases (Reconnaissance)
- AML.T0006 Active Scanning (Reconnaissance)
- AML.T0049 Exploit Public-Facing Application (Initial Access)
- AML.T0050 Command and Scripting Interpreter (Execution)
- AML.T0055 Unsecured Credentials (Credential Access)
- AML.T0072 Reverse Shell (Command And Control)
- T1016 System Network Configuration Discovery (Discovery)
- T1018 Remote System Discovery (Discovery)
- T1027 Obfuscated Files or Information (Stealth)
- T1036.005 Match Legitimate Resource Name or Location (Stealth)
- and 10 more
Named actors and malware
- ShinyHunters (actor)
- Neo-reGeorg (malware)
Indicators
- 19 indicators on file
Coverage
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
- Oracle Security Alert Advisory - CVE-2026-35273
- ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
- ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
- Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
- ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
- Oracle PeopleSoft Servers Targeted Again as ShinyHunters Expands Extortion Operations
- Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
- Oracle PeopleSoft Zero-Day RCE Vulnerability Exploited by ShinyHunters
2. WordPress 7.1.2 Patches Critical RCE as Attackers Exploit Within Hours (Segment)
Blast radius expanded: new vendor(s): google, github
What changed
WordPress released version 7.1.2 on September 22 to patch CVE-2026-87902, a critical flaw allowing unauthenticated remote code execution. The vulnerability, classified as CWE-98 with a CVSS score of 9.2, allows unauthenticated users to include local PHP files outside theme directories via the get_page_template function. Within hours of the patch, Patchstack and Previdian observed a surge in malicious traffic. Attackers moved from reconnaissance to writing malicious PHP files to disk using the pearcmd[.]php utility. Reports differ on the exact blast radius, with some noting new vendor involvement, but the core mechanism is consistent: exploitation requires PEAR and specific PHP settings. CISA has added this to the Known Exploited Vulnerabilities catalog, mandating rapid remediation for federal agencies. If you run WordPress, verify you are on 7.1.2 or the backported 4.7.37. Check your web server logs for requests to pearcmd[.]php or unusual file writes in non-theme directories. Look for traffic from IPs in New Jersey and Indonesia, specifically addresses like 104 dot 194 dot 9 dot 227 and 107 dot 189 dot 14 dot 87. WordPress versions from 4.7.0 through 7.1.1 contain a flaw in the get_page_template() functionality. This improper page-template resolution allows an unauthenticated attacker to include a locally readable PHP file located outside the active theme directories.
How it works
Threat actors are exploiting CVE-2026-87902 in WordPress to force remote file inclusion via the get_page_template function. An unauthenticated attacker manipulates template resolution to force the application to execute a chosen local PHP file, bypassing standard theme directory restrictions. This execution path allows attackers to write files to disk that run shell commands when accessed, establishing a foothold on the server. This weakness allows attackers to read arbitrary local PHP files and execute unauthorized commands because the server permits remote file inclusion. This weakness, CWE-98, allows attackers to write executable files to disk and run shell commands, achieving a CVSS 8.1 impact with high confidentiality, integrity, and availability consequences. This unauthenticated flaw allows attackers to bypass theme directory restrictions and execute arbitrary code via the get_page_template function. Compromised servers are used to deploy web shells, steal database credentials, and create administrator accounts to maintain persistent access. The compromised infrastructure serves as a launchpad for threat actors to target other systems and distribute malware to visitors.
What to do
An unauthenticated remote code execution flaw in WordPress versions 4.7.0 through 7.1.1 exposes your infrastructure to immediate compromise, allowing attackers to deploy web shells and pivot to other internal systems. Because the vulnerability allows the inclusion of arbitrary local PHP files outside theme directories, a single compromised instance can serve as a launchpad for broader network attacks and data exfiltration. Update WordPress to version 7.1.2 or the backported 4.7.37 to close the unauthenticated file inclusion vector. Restrict include and require statements immediately, as manual analysis and static tools are the primary detection methods for this flaw. Verify that your PHP runtime enforces strict filename mapping and avoids unvetted include or require calls to prevent unauthorized file inclusion.
Limits and watch
While the CVSS score is 8.1, we cannot confirm a specific patch date for WordPress 0.000 yet, so manual white-box analysis remains the only known detection method. While the vulnerability is confirmed to affect versions back to 4.7.0, the specific pre-conditions required for successful exploitation on your specific server configuration are not yet fully established. Watch your logs for suspicious requests to public endpoints followed by web server processes spawning shells or writing webshells, which signals active exploitation of T1190.
Vulnerabilities
- CVE-2026-87902 — CVSS 8.1 (High) · CISA KEV · CWE-98 · WordPress WordPress. An unauthenticated attacker can make
get_page_template()page-template resolution include a chosen readable local.phpfile outside the active theme directories.
Techniques
- AML.T0072 Reverse Shell (Command And Control)
- T1189 Drive-by Compromise (Initial Access)
- T1190 Exploit Public-Facing Application (Initial Access)
- T1195.001 Compromise Software Dependencies and Development Tools (Initial Access)
- T1203 Exploitation for Client Execution (Execution)
- T1210 Exploitation of Remote Services (Lateral Movement)
- T1212 Exploitation for Credential Access (Credential Access)
- T1505.003 Web Shell (Persistence)
- T1608.004 Drive-by Target (Resource Development)
- T1659 Content Injection (Initial Access)
Named actors and malware
- page (malware)
Indicators
- 12 indicators on file
Coverage
- CVE-2026-87902: how close is your WordPress to remote code execution?
- WordPress 7.1.2 Security Release: Unauthenticated LFI to RCE
- WordPress 7.1.2 Release
- Critical WordPress Flaw Lets Unauthenticated Attackers Execute Remote Code
- WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)
- WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
- Critical WordPress Core Vulnerability Lets Attackers Execute Code Without Logging In
- CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch
- Hackers start exploiting critical WordPress flaw for code execution
-
[CVE-2026-87902 Exploitation Observed — WordPress Previdian](https://previdian.com/CVE-2026-87902) - Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
- Critical WordPress Vulnerability Exploited Immediately After Disclosure
- WordPress Exploitation Surge: CVE-2026–87902 Attack Analysis
- CVE-2026-87902: Critical WordPress file inclusion and conditional RCE — Robert Ressl
- WordPress patches a critical severity security vulnerability
- Hackers Actively Exploiting WordPress Vulnerability to Execute Malicious Code
- CISA Adds One Known Exploited Vulnerability to Catalog
3. Citrix NetScaler Zero-Days Under Active Exploitation (Segment)
Blast radius expanded: new vendor(s): gateway
What changed
On September 26, 2026, watchTowr and the Dutch National Cyber Security Centre confirmed that two unpatched zero-day remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway appliances are under active exploitation. These flaws are distinct from the earlier CVE-2026-19490 and CVE-2026-19489 entries, and Citrix had not released a patch or formal advisory as of September 27, 2026. The MITRE techniques involve exploiting public-facing applications and remote services, making any internet-facing NetScaler a primary target. Do not wait for the patch, which Citrix is expected to release early this week. Multiple national cybersecurity agencies, including Singapore’s Cyber Security Agency and CISA, have confirmed active exploitation of these specific unpatched flaws. The Dutch National Cyber Security Centre issued a pre-notification on September 25, 2026, which watchTowr researchers subsequently verified on September 26, 2026. The key signal to watch for is any unexpected outbound connection from a NetScaler appliance, as that indicates successful exploitation and potential lateral movement.
How it works
The NetScaler stack weakness requires no authentication or network access, letting attackers execute arbitrary code immediately upon discovery. This flaw bypasses standard access controls in ADC and Gateway components, affecting versions 14.1 through 73.32 or 13.1 through 63.21. With no vendor fix or indicators of compromise available, some administrators have taken internet-exposed appliances offline immediately.
What to do
Today’s event centers on two flaws in Citrix NetScaler, but CVE-2026-19489 stands out because it targets the older 13.x line alongside the 14.x series, creating a wider attack surface than its sibling. Internet-facing NetScaler ADC and Gateway appliances are the primary exposure surface for these unpatched remote code execution flaws, which are distinct from the previously cataloged CVE-2026-19490 and CVE-2026-19489. The absence of a vendor patch or indicators of compromise forces immediate operational decisions, such as taking appliances offline, rather than relying on standard remediation timelines. Patch NetScaler 14.1 and 13.1 lines immediately to close the high-impact execution path before adversaries leverage the zero-day. Isolate NetScaler 13.1 and 14.1 systems today because the dual-series impact means legacy infrastructure faces the same risk as modern deployments. Prioritize isolating appliances running NetScaler ADC or Gateway versions 13.1 through 63.21 and 14.1 through 73.32, which are affected by CVE-2026-19490 and the current unpatched zero-days.
Limits and watch
Citrix has not published a formal security advisory or technical details for the two new zero-day vulnerabilities, leaving defenders without specific indicators of compromise to verify past exploitation. The exact scope of the new unpatched flaws remains unverified beyond the confirmed remote code execution capability, as the available intelligence is credible but lacks the granular technical data present in the CVE-2026-19490 and CVE-2026-19489 catalog entries. Watch for unexpected outbound connections from NetScaler appliances, which signals successful exploitation and potential lateral movement via remote services.
Vulnerabilities
- CVE-2026-19490 — CVSS 9.8 (Critical) · CISA KEV · NetScaler ADC; NetScaler Gateway. Vulnerability in NetScaler ADC and NetScaler Gateway.
- CVE-2026-19489 — CVSS 0 (Low) · NetScaler ADC; NetScaler Gateway. Vulnerability in NetScaler ADC and NetScaler Gateway.
Techniques
- T1021.007 Cloud Services (Lateral Movement)
- T1190 Exploit Public-Facing Application (Initial Access)
- T1203 Exploitation for Client Execution (Execution)
- T1210 Exploitation of Remote Services (Lateral Movement)
- T1212 Exploitation for Credential Access (Credential Access)
- T1552.004 Private Keys (Credential Access)
- T1590.006 Network Security Appliances (Reconnaissance)
Indicators
- 8 indicators on file
Coverage
- Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
- CVE-2026-19490
- Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities
- Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks
- Citrix confirms two NetScaler RCE zero-days exploited in attacks
4. Citrix NetScaler Zero-Days Now in CISA KEV (Segment)
Event first seen in a show
Citrix NetScaler appliances are under active attack, and the clock is ticking. On September 27, 2026, Citrix disclosed eight new vulnerabilities in NetScaler ADC and Gateway products, including two critical remote code execution flaws that were already actively exploited as zero-days. Two of these, CVE-2026-88771 and CVE-2026-88772, are critical remote code execution flaws that allow unauthenticated attackers to execute arbitrary commands or crash the system. CISA immediately added these vulnerabilities to its Known Exploited Vulnerabilities catalog, prompting global CERT alerts and urgent vendor-supplied patches for affected systems. Federal agencies have until September 30th to apply fixes. If you run NetScaler, verify your patch status against the eight new CVEs today. The Dutch National Cyber Security Center confirmed that exploitation of these NetScaler flaws began weeks before the official disclosure. Advanced persistent threat groups and ransomware affiliates have been identified as the actors exploiting Citrix NetScaler ADC in these attacks.
Attackers exploit improper input validation in Citrix NetScaler ADC before version 14.1-73.37 to execute arbitrary commands. They trigger this flaw by sending crafted requests that bypass standard access controls. The root cause is improper HTTP URL based expression usage, which enables unauthorized access to restricted features. An unauthenticated remote attacker can exploit this flaw to execute arbitrary commands on the appliance. This vulnerability allows bypassing security restrictions to trigger denial of service or remote code execution without prior authentication. Within the event’s eight CVE cluster, an attacker triggers an overflow to cause unpredictable behavior or denial of service. This specific weakness causes unpredictable behavior, distinct from the other seven CVEs in the set. An attacker triggers this overflow by sending malformed requests, crashing the gateway without requiring authentication. Citrix NetScaler ADC and Gateway versions before 14.1-73.37 face remote code execution risks today. These appliances suffer from feature policy bypass via improper HTTP URL expression. The flaw enables Cross Zone Scripting by forcing zone-aware browsers to load malicious content that bypasses security controls. This weakness causes resource exhaustion or memory reads, enabling cross-zone scripting only if the victim uses a zone-aware browser. Additionally, the system faces a memory overflow that triggers denial of service. The flaws affect internet-facing NetScaler Gateway and ADC appliances, with exploitation observed on unmitigated deployments. Federal agencies are required to apply mitigations for these vulnerabilities by September 30, 2026. Citrix NetScaler ADC and Gateway versions before 14.1-73.37 face HTTP smuggling via CWE-444, letting attackers inject unauthorized requests. This weakness in the eight-event set bypasses feature policies without extra authentication. APT and ransomware groups actively exploit this to run arbitrary commands on unauthenticated appliances.
Verify versions are at least 14.1-73.37 or 13.1-64.23 to patch the input validation flaw. Check specific version numbers immediately to confirm exposure. Patch today’s releases to stop the client-side injection buffer overflow that crashes after downloading hostile code. Patch affected versions immediately to prevent resource exhaustion or privilege elevation. Patch these instances immediately to stop the back-end injection this CVE enables. Patch these specific versions immediately to stop the exploit chain. Verify NetScaler versions immediately to avoid the denial of service consequence. Patch versions 14.1-73.37 and earlier immediately to stop the crash cascade. Apply patches immediately, as static analysis tools can detect the missing input validation logic.
Until the vendor releases 14.1-73.37, no concrete mitigation exists beyond blocking the specific request smuggling patterns observed today. The full scale of global exploitation remains undetermined, as experts have not yet quantified the total number of compromised devices. It is not yet established whether the observed webshell planting is part of a coordinated nation-state espionage campaign or isolated ransomware activity. Monitor for Indirect Command Execution behavior where utilities like forfiles[.]exe or pcalua[.]exe spawn secondary commands to bypass security restrictions.
Vulnerabilities
- CVE-2026-88771 — CVSS 0 (Low) · CWE-20 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88772 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88773 — CVSS 0 (Low) · CWE-444 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Inconsistent interpretation of HTTP requests (‘HTTP Request/Response smuggling’) vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88774 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88775 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88776 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88777 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
- CVE-2026-88778 — CVSS 0 (Low) · CWE-342 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
Techniques
- T1087.001 Local Account (Discovery)
- T1133 External Remote Services (Persistence)
- T1136.001 Local Account (Persistence)
- T1190 Exploit Public-Facing Application (Initial Access)
- T1202 Indirect Command Execution (Stealth)
- T1203 Exploitation for Client Execution (Execution)
- T1210 Exploitation of Remote Services (Lateral Movement)
- T1212 Exploitation for Credential Access (Credential Access)
- T1590.006 Network Security Appliances (Reconnaissance)
Indicators
- 5 indicators on file
Coverage
- CVE-2026-88771: Citrix NetScaler: Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway
- Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772
- Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778
- CISA Warns of Citrix NetScaler 0-Day RCE Vulnerabilities Exploited in Attacks
- CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
- Citrix Products Multiple Vulnerabilities
- Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)
5. Infostealers drive 74% surge in cookie theft, exposing 94 billion credentials (Segment)
Event first seen in a show
What changed
Lumma, RedLine, and Vidar infostealers are driving the threat by exploiting unmanaged personal devices and CI/CD pipelines to bypass multi-factor authentication and access AWS and Azure. The Miasma payload targets cloud identities via malicious npm package releases. RedLine infected nine point nine million devices before its October twenty twenty-four disruption. NordVPN reports a 74% year-over-year surge in leaked cookies, with the total count rising from 54 billion to nearly 94 billion. The United States ranks fourth globally with over 3.6 billion affected cookies linked to major platforms including Google, Microsoft, and Bing.
How it works
Lumma Stealer steals active session cookies to bypass multi-factor authentication, allowing attackers to hijack sessions without requiring user login credentials. These infostealers exploit software vulnerabilities to harvest credentials, API keys, and session tokens from compromised developer workstations. Stolen data is rapidly validated and resold within hours to access brokers and ransomware operators who monetize verified enterprise access through mature malware-as-a-service ecosystems. Approximately 90% of organizations breached in 2024 had their credentials leaked for sale on dark web marketplaces, a statistic largely driven by infostealer malware such as RedLine Stealer and its successor Lumma Stealer. Leaked cookies jumped from fifty-four to ninety-four billion, making stolen session tokens the main way attackers bypass multi-factor authentication in cloud environments. Ninety percent of breached organizations found their credentials sold on dark web marketplaces, extending exposure beyond individual devices to the entire enterprise identity perimeter.
What to do
Isolate applications and sandbox them to block infostealers from reaching sensitive data on developer machines. Deploy rules to catch abnormal LSASS memory access and forged Kerberos tickets during credential validation.
Limits and watch
The full extent of credential exposure is unknown if an employee downloads compromised software, as infostealers can silently harvest the entire database of digital credentials. Monitor for unauthorized API requests using stolen container service account tokens to detect adversaries leveraging compromised CI/CD pipelines.
Techniques
- T1005 Data from Local System (Collection)
- T1027.014 Polymorphic Code (Stealth)
- T1195 Supply Chain Compromise (Initial Access)
- T1212 Exploitation for Credential Access (Credential Access)
- T1219 Remote Access Tools (Command And Control)
- T1528 Steal Application Access Token (Credential Access)
- T1539 Steal Web Session Cookie (Credential Access)
- T1550.004 Web Session Cookie (Lateral Movement)
- T1552.004 Private Keys (Credential Access)
- T1555.005 Password Managers (Credential Access)
- and 6 more
Named actors and malware
- Lumma (malware)
- RedLine (malware)
- Lumma Stealer (malware)
- RedLine Stealer (malware)
Indicators
- 2 indicators on file
Coverage
- Lumma, RedLine and Vidar Infostealers Fuel Cloud Credential Theft Campaigns
- From 54 billion to 94 billion: Cookie theft skyrockets as hackers exploit your browser
-
[Infostealer Malware: The Silent Threat to Your Digital Credentials - Managed IT Services & Technology Consulting OSIbeyond](https://osibeyond.com/blog/infostealer-malware-the-silent-threat-to-your-digital-credentials)
6. ShinyHunters claims FBI breach to refute reports, while sextortion and healthcare vishing campaigns exploit leaked data (Segment)
Event first seen in a show
ShinyHunters claims to have breached the FBI’s recruitment portal to refute negative allegations in a recent FLASH report, rather than for financial gain. Simultaneously, threat intelligence firms report ShinyHunters is employing sophisticated voice-phishing tactics against the healthcare sector. They have successfully compromised entities such as Clover Health and AdaptHealth. AdaptHealth disclosed a July breach exposing data for more than four point one million patients. One source attributes the FBIJobs[.]gov compromise to an Oracle PeopleSoft zero-day flaw on AWS GovCloud servers, but this detail comes from a single report and lacks broader confirmation. The group is leveraging AI and social engineering techniques previously associated with Scattered Spider to target high-profile brands like Chanel and Workday. Watch for the domain my-passkeys[.]com, identified as attacker infrastructure. The FBI confirmed the compromise of the FBIJobs[.]gov portal and is actively investigating the incident while working with third-party providers to mitigate risks. ReliaQuest confirmed a sustained cluster of phishing infrastructure targeting the healthcare sector through mid-September 2026, while Unit 42 identified a domain linked to The Com underground network used in these attacks.
In the healthcare sector, attackers utilized aggressive voice-phishing tactics to bypass multi-factor authentication and access employee accounts at compromised entities. Third-party scammers are using email addresses from Amtrak and Panera Bread data leaks to send sextortion demands for two thousand dollars in Bitcoin for compromising evidence that does not exist. This tactic exploits the T1589.002 condition of exposed email addresses to tailor impersonation narratives. The attack chain relies on identifying targets before executing the social engineering call. The threat actor operates with a non-financial, reputation-driven motive. This breach validates the PeopleSoft zero-day as a high-fidelity initial access vector for enterprise environments. It elevates the risk for any organization running unpatched Oracle instances.
ShinyHunters is leveraging voice-phishing to bypass MFA at Clover Health and AdaptHealth. Defenders must immediately audit account use policies and logs to detect voice-initiated credential requests. Audit Oracle PeopleSoft instances for the specific zero-day exploit to close the initial access vector used in the FBI breach. Implement pre-compromise controls to reduce the attack surface exposed to reconnaissance, specifically limiting public-facing email infrastructure that aids in target identification.
ShinyHunters claims the breach aimed to contest allegations in a FLASH report, but the full scope of data exfiltration and specific technical mechanics remain under active FBI investigation. Watch for large, iterative batches of authentication requests from single sources to catch active probing for email addresses and usernames.
Techniques
- AML.T0052 Phishing (Initial Access)
- AML.T0052.000 Spearphishing via Social Engineering LLM (Initial Access)
- AML.T0073 Impersonation (Defense Evasion)
- T1016 System Network Configuration Discovery (Discovery)
- T1018 Remote System Discovery (Discovery)
- T1036.005 Match Legitimate Resource Name or Location (Stealth)
- T1059.007 JavaScript (Execution)
- T1059.009 Cloud API (Execution)
- T1069.003 Cloud Groups (Discovery)
- T1072 Software Deployment Tools (Execution)
- and 10 more
Named actors and malware
- ShinyHunters (actor)
Indicators
- 3 indicators on file
Coverage
- ShinyHunters Claims FBI Breach Exposed Data of All Employees and Applicants
- Sextortion scammers are exploiting ShinyHunters data leaks
- Threat groups ramp up social-engineering attacks against healthcare sector
- Nissan says Oracle PeopleSoft break-in may have spilled payroll records, SSNs
- ShinyHunters tells The Reg: We hacked the FBI to ‘protect our business’
- ‘Impersonation as a service’ next big thing in cybercrime
7. STAR Labs researcher earns $113k for 14-year-old Linux AF_ALG race condition enabling root and Docker escape (Segment)
No material change since last show
CISA added CVE-2025-39964 to its Known Exploited Vulnerabilities catalog, confirming active exploitation of a fourteen-year-old Linux kernel flaw. The vulnerability is a race condition in the AF_ALG interface, present since kernel version 2.6.38. STAR Labs researcher Muhammad Alifa Ramdhan identified the flaw in September 2025 and used the exploit for a Google kernelCTF submission, securing an $113,337 reward. The team disclosed this responsibly. Researchers confirmed that the vulnerability is distinct from the Copy Fail bug, as it relies on a race condition rather than a straight-line logic flaw in the AEAD path.
The Linux kernel resolved CVE-2025-39964 by disallowing concurrent writes in af_alg_sendmsg to stop data interleaving. The exploit works by issuing two concurrent writes to the same af_alg socket, which interleaves data in an unpredictable fashion and creates inconsistencies in the internal socket state. This race condition allows an unprivileged local attacker to manipulate memory metadata through a carefully timed interleaving of socket writes. A race condition in Linux versions 5.10 through 6.17 lets attackers trigger resource exhaustion or instability. Successful exploitation enables local users to escalate privileges to root and escape Docker containers on affected systems. The vulnerability affects Linux kernel versions from 2.6.38 through 6.17, including specific releases such as 5.10.245, 5.15.194, and 6.1.154.
The vulnerability enables local privilege escalation to root and Docker container escape, exposing multi-tenant systems to full host compromise if unprivileged users can access the AF_ALG interface. Defenders must now apply the T1068 mitigation of Execution Prevention by auditing application control policies to ensure no unauthorized scripts or drivers can execute on the affected Linux hosts. Simultaneously, the T1611 mitigation of Application Isolation and Sandboxing requires confirming that all containers are running with strict isolation and that no bind mounts provide access to the host’s filesystem or management sockets like docker[.]sock. Apply kernel patches that introduce the ctx->write field to enforce exclusive ownership for AF_ALG socket writes, specifically targeting versions 5.10.245, 5.15.194, 6.1.154, 6.6.108, 6.12.49, 6.16.9, and 6.17. Verify your kernel version matches the patched commit 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 to close the synchronization gap. Implement application isolation and sandboxing to restrict execution environments, preventing unprivileged processes from accessing the vulnerable AF_ALG interface and limiting the blast radius of potential exploitation. The remaining uncertainty is whether attackers are currently targeting this specific 14-year-old race condition or if they are using it as a stepping stone for broader lateral movement. The immediate watch item is monitoring system logs for concurrent socket write errors or unexpected kernel panic events on affected Linux 5.10.245 and 5.15.194 systems.
Black-box detection methods may fail to identify this race condition if the timing window is too narrow to cause observable instability or crashes during concurrent connection attempts. The exact scope of exploitation in the wild remains limited to the CISA KEV listing, with no public evidence yet detailing specific attacker infrastructure or targeted sectors. Watch for unusual process or token behavior after exploitation attempts on vulnerable kernel components, which signals successful privilege escalation via T1068.
Vulnerabilities
- CVE-2025-39964 — CVSS 7.8 (High) · CISA KEV · CWE-362 · Linux Linux; Linux Linux. In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in…
Techniques
- T1068 Exploitation for Privilege Escalation (Privilege Escalation)
- T1611 Escape to Host (Privilege Escalation)
Coverage
- How I Found a $113,337 AF_ALG Linux Local Privilege Escalation Before Copy Fail
- 14-Year-Old Linux Kernel Vulnerability Enables Root Access and Docker Escape
- 14-Year-Old Linux Kernel Flaw Lets Local Users Gain Root Access and Escape Containers
8. Lazarus Group Steals $292M From KelpDAO Bridge (Segment)
No material change since last show
What changed
Lazarus Group drained two hundred ninety-two million dollars from KelpDAO by exploiting a single-node configuration in its off-chain verification network. The TraderTraitor cell executed this theft on April 18, 2026, by compromising internal RPC nodes to feed false data to Ethereum contracts. On April 18, the TraderTraitor cell compromised internal RPC nodes in KelpDAO’s off-chain verification network. They DDoSed external nodes to feed false data, tricking Ethereum contracts into releasing funds based on phantom token burns. KelpDAO paused its contracts and blacklisted attacker addresses, while the Arbitrum Security Council moved to freeze downstream funds to limit further loss. LayerZero Labs confirmed the protocol functioned as intended, isolating the breach to KelpDAO’s specific single-node configuration rather than a systemic protocol failure. The lead sheet details the full IOC list and MITRE techniques, including PyLangGhost RAT usage.
How it works
This attack bypassed on-chain transaction validation by exploiting a single-point-of-failure in the verification network, a critical layer for cross-chain protocols. The incident stayed isolated to KelpDAO’s rsETH configuration, affecting roughly $290 million in assets without touching other applications or LayerZero’s broader protocol. The compromised LayerZero Labs DVN forced the deprecation of affected RPC nodes and activated a live LayerZero Labs DVN to secure the network.
What to do
Lazarus recruits developers via social engineering to deploy Graphalgo, forcing you to audit user behavior and restrict software installation to approved whitelists. Trace PyLangGhost RAT to the specific workstation and verify if the compromised 3CX app came from a trusted channel, since technical signatures alone miss the full scope. The 3CX compromise exposes your remote access infrastructure to the same tactics used in KelpDAO and Bybit incidents. This threat extends beyond crypto to IT services providers, making your internal RPC nodes and development tools primary targets for data exfiltration and lateral movement. Implement application whitelisting and software restriction policies to block unauthorized installation of compromised dependencies like those found in the 3CX and GitHub Actions supply-chain attacks. Audit your CI/CD pipelines for malicious GitHub Actions that collect runtime credentials or insert backdoors into build processes, specifically targeting the npm and PyPI package managers used in your development environment.
Limits and watch
The full extent of the 3CX compromise and whether it has already been used to pivot into your internal network remains unconfirmed by current evidence. While the campaign targets open-source repositories, the specific version of the 3CX app affected in your environment is not yet established in the available data. Watch for unexpected package manager invocations writing executable files or triggering post-install scripts spawning shells, indicating supply-chain tampering. Also watch for social engineering prompting rapid OAuth consent or credential submission, preceding malicious development tool deployment.
Techniques
- AML.T0011.001 Malicious Package (Execution)
- AML.T0097 Virtualization/Sandbox Evasion (Defense Evasion)
- EMERGING-0006 PyLangGhost RAT
- T1001.003 Protocol or Service Impersonation (Command And Control)
- T1005 Data from Local System (Collection)
- T1008 Fallback Channels (Command And Control)
- T1010 Application Window Discovery (Discovery)
- T1012 Query Registry (Discovery)
- T1016 System Network Configuration Discovery (Discovery)
- T1021.001 Remote Desktop Protocol (Lateral Movement)
- and 10 more
Named actors and malware
- Lazarus Group (actor)
- Lazarus (actor)
- threat (actor)
Indicators
- 25 indicators on file
Coverage
- Inside the KelpDAO Bridge Exploit
- North Korean hackers now launder stolen crypto via YoMix tumbler
- Hunting Lazarus, Part 5: Eleven Hours on His Disk
- KelpDAO Incident Statement
-
[Don’t Call Us, We’ll Call Your APIs TraderTraitor Backdoors Resurface on Victim With No Crypto Ties](https://sentinelone.com/labs/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties) - Lazarus Group’s ‘Graphalgo’ Fake Recruiter Campaign Exploits GitHub, npm, and PyPI to Distribute Malware
- The 3CX Supply Chain Attack: A Threat Intelligence Investigation
- Bitget Hot Wallet Hacked – Attackers Stole $351.6 Million From Hot Wallets
- FBI confirms Lazarus hackers were behind $1.5B Bybit crypto heist
- Bybit declares war on Lazarus crew to regain stolen $1.5B
- Polin Rider
9. Huntress: Attackers Exploit Samsung MagicINFO Flaw to Compile Monero Miner on Endpoint (Segment)
No material change since last show
Huntress analysts identified a threat actor compiling a custom Monero miner directly on a victim’s endpoint, a tactic that bypasses standard signature detection. In early September 2026, attackers exploited CVE-2025-4632 in Samsung MagicINFO Premium to seize local administrator access on a Windows host. After Microsoft Defender blocked two attempts to download AnyDesk from IP 194[.]87[.]89[.]30, the intruders succeeded on the third try, disabled the security software, and used native tools like Donut, TCC, and MinGW64 to build the miner locally. The resulting binary was configured to connect to auto[.]c3pool[.]org to harvest cryptocurrency using the host’s CPU and GPU resources.
Samsung MagicINFO 9 Server before 21.1052 lets attackers write arbitrary files via path traversal on today. The flaw stems from improper pathname limitation where external input constructs a path that escapes the restricted directory. The weakness allows control of requested paths to bypass directory restrictions and overwrite critical system libraries. This local compilation allowed the threat actor to customize the binary for the target environment, specifically optimizing it for the endpoint’s CPU architecture. This CWE-22 flaw yields a CVSS 9.8 score, enabling full integrity modification of critical programs and libraries. The vulnerability grants full system authority to overwrite critical binaries without requiring user interaction.
This high-severity weakness enables full system compromise, distinct from the other event CVE by allowing direct file creation as root. This tactic transforms a standard intrusion into a persistent resource theft operation, as the attacker leverages the compromised host’s own processing power to harvest cryptocurrency without deploying a pre-built payload. Apply Samsung’s SVP-MAY-2025 update to patch CVE-2025-4632, upgrading all MagicINFO 9 Server instances to version 21.1052 or later to close the unauthenticated path traversal flaw. Validate all pathname inputs against a strict allowlist, rejecting any path containing dot-dot-slash sequences or unencoded slashes. Hunt for the Silent XMR Miner Builder[.]exe process chain and native tools like Donut or MinGW64 on Windows hosts to identify endpoints where the miner was compiled locally.
The report does not specify if other systems were affected by the initial exploitation of CVE-2025-4632, leaving the full scope of the intrusion uncertain. While CVE-2025-4632 is unauthenticated, the related CVE-2024-7399 requires local privileges, meaning the remediation scope must account for different access requirements across the affected MagicINFO versions. Monitor for the creation of VSCode tunnel configuration files combined with interactive remote sessions via the code CLI, as this indicates potential IDE tunneling for persistence.
Vulnerabilities
- CVE-2025-4632 — CVSS 9.8 (Critical) · CISA KEV · CWE-22 · Samsung Electronics MagicINFO 9 Server. Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.
- CVE-2024-7399 — CVSS 8.8 (High) · CISA KEV · CWE-22, CWE-434 · Samsung Electronics MagicINFO 9 Server. Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.
Techniques
- T1027.002 Software Packing (Stealth)
- T1027.013 Encrypted/Encoded File (Stealth)
- T1027.015 Compression (Stealth)
- T1087.001 Local Account (Discovery)
- T1136.001 Local Account (Persistence)
- T1203 Exploitation for Client Execution (Execution)
- T1204.002 Malicious File (Execution)
- T1219 Remote Access Tools (Command And Control)
- T1219.001 IDE Tunneling (Command And Control)
- T1496 Resource Hijacking (Impact)
Indicators
- 6 indicators on file
Coverage
- Hackers Used a Samsung Flaw to Build a Cryptominer Inside Victim Systems
- The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint
- Samsung MagicINFO 9 Server Vulnerability Let Attackers Write Arbitrary File
10. KELA reports 3.9B credentials stolen by infostealers as Vidar 2.0 targets Azure (Segment)
Event first seen in a show
What changed
Ontinue’s Advanced Threat Operations team published a static analysis of Vidar Stealer 2.0, first observed in October 2025. The strain shifted to pure C code with pervasive control flow flattening, specifically targeting Azure credentials and Chrome version 20 passwords. This redesign positions the infostealer to capitalize on operational disruptions affecting competitors like Lumma Stealer. KELA quantified the 2024 credential crisis: 3.9 billion credentials were stolen from 4.3 million devices. Infostealer strains Lumma, StealC, and RedLine drove this theft, accounting for over 75% of infections. Reports from esecurityplanet, ontinue, and seraphicsecurity confirm these tools are persistent and evolving. Cybercriminals now trade these stolen logins on black markets to execute account takeovers, identity theft, and extortion.
How it works
The malware uses Chrome v20 AES-GCM decryption at function 0x140014d6c with Windows BCrypt APIs to extract credentials, targeting over 50 cryptocurrency wallets across multiple browsers. Adversaries may log into accessible cloud services using valid accounts synchronized with on-premises identities to perform management actions or access cloud-hosted resources as the logged-on user. Infostealers are persistent malware strains that stealthily infiltrate devices to harvest sensitive data such as session tokens, login credentials, and financial information, often leading to identity theft and session hijacking. This surge in credential theft significantly increases the risk of large-scale security breaches and unauthorized access to corporate systems. Lumma, StealC, and RedLine stole 3.9 billion credentials in 2024, creating a persistent pool of valid identities for account takeovers and extortion. Vidar Stealer 2.0 shifts to pure C with control flow flattening, targeting Azure MSAL token caches to increase direct cloud infrastructure compromise risk via stolen session tokens.
What to do
Enforce multi-factor authentication for all cloud service logins to prevent adversaries from using stolen valid accounts to access the cloud control plane. Implement privileged account management controls to restrict and audit the usage of administrative accounts that may be used for cloud resource enumeration.
Limits and watch
Vidar Stealer 2.0 uses computed jumps to evade static analysis, limiting the ability to fully map its exfiltration logic without dynamic execution. The malware exfiltrates Azure credentials via HTTP POST, but the specific scope of targeted enterprise tenants remains unconfirmed in available static analysis. Watch for federated logins using SSO or OAuth grants to the cloud control plane that are immediately followed by directory or permissions enumeration.
Techniques
- AML.T0037 Data from Local System (Collection)
- AML.T0048.001 Reputational Harm (Impact)
- AML.T0055 Unsecured Credentials (Credential Access)
- AML.T0087 Gather Victim Identity Information (Reconnaissance)
- AML.T0091.000 Application Access Token (Lateral Movement)
- AML.T0097 Virtualization/Sandbox Evasion (Defense Evasion)
- T1003.001 LSASS Memory (Credential Access)
- T1005 Data from Local System (Collection)
- T1021.007 Cloud Services (Lateral Movement)
- T1027 Obfuscated Files or Information (Stealth)
- and 10 more
Named actors and malware
- Lumma (malware)
- RedLine (malware)
- Lumma Stealer (malware)
- Emotet (malware)
Indicators
- 1 indicator on file