The Hot Drop for 09-29-2026

FBI breached via ShinyHunters zero-day sextortion? Meanwhile, Citrix NetScaler zero-days patched after weeks of silent exploitation. Is your legacy infrastructure already compromised?

Since the last show: 10 developing · 2 dropped · 83% overlap with the previous show

Contents

  1. ShinyHunters claims FBI breach via PeopleSoft zero-day
  2. Citrix NetScaler Zero-Days Patched After Active Exploitation
  3. Citrix NetScaler under active exploitation; CISA mandates federal patching by April 2
  4. Citrix NetScaler Zero-Days Under Active Exploitation
  5. Sysdig documents JADEPUFFER, the first end-to-end AI-driven ransomware operation exploiting Langflow
  6. Lazarus Group Steals $292M from KelpDAO via Off-Chain Node Compromise
  7. Infostealers Drive 74% Surge in Cookie Theft
  8. Infostealer Surge: 3.9B Credentials Stolen, Vidar 2.0 Targets Azure
  9. Microsoft tracks Storm-2570’s consistent tradecraft across Qilin, DragonForce, Anubis, and BERT ransomware
  10. Canadian Cyber Center Confirms Active Wild Exploitation of Roundcube Webmail SQL Injection CVE-2026-48842

1. ShinyHunters claims FBI breach via PeopleSoft zero-day (Segment)

Event now covered by 5 outlets (was 4)

What changed

ShinyHunters claims they breached the FBI’s recruitment portal, FBIjobs[.]gov, using an unpatched Oracle PeopleSoft zero-day. They allege they stole personnel data from AWS GovCloud infrastructure. The group states this breach was executed to contest allegations made against them in a May 2026 FLASH report regarding their harassment strategies, rather than for financial extortion. Watch for the domain my-passkeys[.]com, identified as attacker infrastructure. Check your exposure against known ShinyHunters leaks and prepare for targeted vishing campaigns. ShinyHunters affiliates are leveraging stolen data from Nissan, Amtrak, and healthcare providers. Nissan Americas disclosed that payroll records, bank details, and SSNs for employees in the US, Canada, Mexico, and Brazil were exposed. Sextortion scammers are using email addresses from these leaks to demand two thousand dollars in Bitcoin for non-existent compromising evidence. Reports differ on the scope of corporate targets; while Nissan’s breach is confirmed by the company, claims that ShinyHunters specifically targeted AT&T remain unverified by other sources. The FBI is investigating the compromise, but the immediate threat to your organization is the secondary exploitation of leaked PII. The FBI has confirmed the compromise of the portal and is actively investigating the incident while working with third-party providers to mitigate risks.

How it works

This technical exploit was part of a broader operational pattern where ShinyHunters affiliates leverage voice-phishing tactics to trick employees into revealing credentials and bypass multi-factor authentication. The breach stole personally identifiable information and personnel files for FBI employees and applicants, with the group claiming all individual data was exposed.

What to do

ShinyHunters is simultaneously deploying voice-phishing against the healthcare sector, indicating a coordinated multi-vector campaign that extends beyond the initial breach. Audit your public-facing email infrastructure and authentication endpoints to identify exposed employee addresses that adversaries can use for targeted social engineering. Implement pre-compromise mitigations that reduce the attack surface by restricting public access to employee data and hardening authentication services against enumeration.

Limits and watch

Nissan Americas confirmed the theft of payroll records and SSNs, but independent sources have not yet verified that ShinyHunters specifically targeted AT&T. The full scope of the Oracle PeopleSoft zero-day exploitation across other organizations is not yet established, leaving the total number of affected entities uncertain. Monitor for large, iterative quantities of authentication requests from single sources, which indicate active probing for email addresses and usernames. Watch for rapid sensitive user actions, such as OAuth consent or password resets, that occur shortly after inbound social engineering communications.

Techniques

  • AML.T0052 Phishing (Initial Access)
  • AML.T0052.000 Spearphishing via Social Engineering LLM (Initial Access)
  • AML.T0073 Impersonation (Defense Evasion)
  • T1016 System Network Configuration Discovery (Discovery)
  • T1018 Remote System Discovery (Discovery)
  • T1036.005 Match Legitimate Resource Name or Location (Stealth)
  • T1059.007 JavaScript (Execution)
  • T1059.009 Cloud API (Execution)
  • T1069.003 Cloud Groups (Discovery)
  • T1072 Software Deployment Tools (Execution)
  • and 10 more

Named actors and malware

  • ShinyHunters (actor)

Indicators

  • 3 indicators on file

Coverage


2. Citrix NetScaler Zero-Days Patched After Active Exploitation (Segment)

No material change since last show

What changed

On September 27, 2026, Citrix disclosed eight new vulnerabilities in NetScaler ADC and Gateway, including two critical remote code execution flaws that were already being exploited as zero-days. CISA immediately added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog, mandating federal agencies apply patches by September 30, 2026. GreyNoise detected exploitation attempts on September 24, but the vendor’s delayed disclosure drew criticism after unofficial warnings circulated for weeks. Palo Alto Networks estimates over 50,000 publicly exposed instances are vulnerable. If you run NetScaler appliances, verify you are on version 14.1-73.37 or 13.1-64.23 immediately. Citrix patched two critical zero-day flaws in NetScaler ADC and Gateway that attackers were already using globally. The Dutch National Cyber Security Center warned IT suppliers about this active exploitation. Advanced persistent threat groups and ransomware affiliates confirmed using these specific flaws to exploit NetScaler ADC.

How it works

Attackers exploit CVE-2026-88771 in Citrix NetScaler ADC versions before 14.1-73.37 to run arbitrary commands. The vulnerability stems from improper input validation, specifically CWE-125, where the ADC reads past buffer boundaries during VPN or RDP proxy operations. An unauthenticated remote attacker triggers this overflow by sending crafted traffic, causing unpredictable behavior in the gateway. Because the weakness lets an attacker predict exact values from previous observations, defenders must patch before 14.1-73.37 immediately. The flaw requires only network access and zero valid credentials, meaning the lack of a user account provides no protection against these remote code execution vectors. Citrix NetScaler ADC before version 14.1-73.37 also mishandles HTTP request smuggling, allowing attackers to inject unauthorized requests. Additionally, versions before 14.1-73.37 allow attackers to bypass feature policies by exploiting improper HTTP URL expression handling. Threat actors are actively exploiting CVE-2026-88771 and CVE-2026-88772 to gain control over Citrix NetScaler ADC and Gateway appliances. These zero-day vulnerabilities affect Citrix NetScaler application delivery controllers, allowing attackers to trigger denial of service, security restriction bypass, and sensitive information disclosure. This unauthenticated remote code execution yields a CVSS 9.8 score, enabling full compromise of NetScaler Gateway appliances. This unauthenticated command execution grants high impact, allowing attackers to crash the appliance or read memory. NetScaler Gateway 14.1 users face high-impact data leaks via CVE-2025-5777 when unvalidated input triggers an out-of-bounds read. Today, Citrix NetScaler ADC and Gateway before version 14.1-73.37 are vulnerable to CWE-342, allowing attackers to predict exact values. This command injection flaw affects all NetScaler devices before version 14.1-73.37, enabling unauthenticated attackers to crash the system or steal memory. This unauthenticated remote code execution grants full system control, enabling denial of service through resource exhaustion. This flaw enables secret injection of malicious requests into back-end servers, affecting all NetScaler Gateway versions prior to 14.1-73.37 FIPS. This weakness enables privilege escalation on the NetScaler Gateway, affecting all systems running those pre-14.1-73.37 Citrix releases. Today’s Citrix NetScaler ADC update before 14.1-73.37 exposes a memory overflow leading to denial of service.

What to do

This overread targets NetScaler proxy gateways, distinguishing it from the other eight CVEs in the d3d6e0fec3021c5c set. Confirmed exploitation by APT and ransomware groups makes any internet-facing NetScaler ADC or Gateway instance a high-priority target for initial network access. Verify current Citrix NetScaler versions against the affected list today to ensure all devices meet the CISA mandate for federal agencies, which requires mitigation by September 30, 2026. Apply the Citrix security updates to all internet-facing devices to close remote code execution and denial-of-service vectors, as static analysis detects the flaw and LangSec mitigates input risks. Prioritize patching internet-facing devices to block this high-impact weakness and prevent unauthorized access.

Limits and watch

Exploitation continues today, but no specific patch date has been confirmed for this critical Citrix vulnerability. The evidence confirms active exploitation but does not specify the exact number of compromised appliances or the specific data exfiltrated in these incidents. While the flaws are unauthenticated, the specific deployment configurations that trigger the HTTP request smuggling and policy bypass components of the eight disclosed vulnerabilities are not detailed in the current evidence. Watch for the multi-signal correlation of abnormal request patterns to public endpoints followed by the web server process spawning shells or non-standard binaries. Monitor for client software crashes following the execution of code downloaded from hostile servers, which serves as a specific indicator for the client-side injection attack pattern.

Vulnerabilities

  • CVE-2026-88771 — CVSS 9.8 (Critical) · CISA KEV · CWE-20 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2026-88772 — CVSS 8.1 (High) · CISA KEV · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2025-5777 — CVSS 7.5 (High) · CISA KEV · CWE-125 · NetScaler ADC; NetScaler Gateway. Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
  • CVE-2026-88778 — CVSS 7.5 (High) · CWE-342 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2026-88773 — CVSS 0 (Low) · CWE-444 · Citrix NetScaler ADC; Citrix NetScaler Gateway. Inconsistent interpretation of HTTP requests (‘HTTP Request/Response smuggling’) vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2026-88774 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2026-88775 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2026-88776 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
  • CVE-2026-88777 — CVSS 0 (Low) · Citrix NetScaler ADC; Citrix NetScaler Gateway. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.

Techniques

  • T1021.007 Cloud Services (Lateral Movement)
  • T1087.001 Local Account (Discovery)
  • T1133 External Remote Services (Persistence)
  • T1136.001 Local Account (Persistence)
  • T1190 Exploit Public-Facing Application (Initial Access)
  • T1202 Indirect Command Execution (Stealth)
  • T1203 Exploitation for Client Execution (Execution)
  • T1204.002 Malicious File (Execution)
  • T1210 Exploitation of Remote Services (Lateral Movement)
  • T1212 Exploitation for Credential Access (Credential Access)
  • and 2 more

Indicators

  • 14 indicators on file

Coverage


3. Citrix NetScaler under active exploitation; CISA mandates federal patching by April 2 (Segment)

Event first seen in a show

Threat actors are actively exploiting a critical insufficient input validation vulnerability in Citrix NetScaler ADC and NetScaler Gateway products, with observed activity dating back to March 27. CISA has added CVE-2026-3055 to its Known Exploited Vulnerabilities catalog, mandating federal agencies remediate the issue by April 2. WatchTowr suggests this single CVE ID may mask multiple closely related flaws, including a race condition known as CVE-2026-4368, though the core issue remains sensitive data exposure. A specific indicator associated with this activity is the IP address 14[.]1[.]60[.]52, though its role is currently unknown. The primary signal to watch for is any unpatched NetScaler instance handling SAML traffic that exhibits unusual outbound connections or credential harvesting attempts. If you cannot patch immediately, apply the Global Deny List signatures available for certain firmware builds, which do not require a reboot. This is a high-priority item for any environment relying on NetScaler for identity management. CVE-2026-3055 lets attackers pull session tokens and credentials from NetScaler memory overreads. The UK’s National Cyber Security Centre verified that NetScaler ADC and Gateway deployments are widely exposed in critical identity paths, urging immediate patching. WatchTowr confirms exploitation began less than a week after disclosure, with active attacks observed by Sunday. For detection, focus on Exploitation for Credential Access against public-facing appliances. Look for anomalous session token requests or unexpected memory read patterns in NetScaler logs.

CVE-2026-3055 is an out-of-bounds read flaw in NetScaler ADC and Gateway instances configured as SAML Identity Providers. The weakness is CWE-125, where insufficient input validation allows the product to read data past the end of an intended buffer. An attacker exploits this by supplying malformed SAML assertions that bypass buffer checks, forcing the device to read past boundaries. This input-controlled memory access can expose cryptographic keys or bypass ASLR protections. Separately, yesterday’s NetScaler Gateway 14[.]1[.]66[.]54 update fixed a race condition causing user session mixups. The vulnerability affects NetScaler ADC and Gateway versions 14.1 and 13.1, including FIPS and NDcPP builds, specifically when deployed as customer-managed SAML Identity Providers. That flaw let attackers hijack sessions when appliances ran as SSL VPN, ICA Proxy, CVPN, or RDP Proxy targets. Successful exploitation exposes sensitive data such as cryptographic keys and PII, and can reveal memory addresses that help attackers bypass ASLR protections to improve the reliability of subsequent exploits.

Attackers are exploiting CVE-2026-3055 on NetScaler ADC 14.1 to read sensitive keys through SAML IDP misconfiguration. Because these appliances sit in critical identity paths, CISA mandates immediate remediation for federal agencies by April 2. Apply the vendor patch or enforce strict input validation now to stop memory overread exploitation. Validate all SAML inputs against strict specifications to block this overread buffer attack. Verify NetScaler ADC and Gateway versions against 14[.]1[.]66[.]54 today to close the session mixup window. Investigate SAML Identity Provider configurations for anomalous session token requests to detect exploitation of the insufficient input validation flaw.

While today’s event pairs with CVE-2026-4368, the specific memory overread mechanism here remains distinct and requires separate verification. Watch public-facing NetScaler instances for multi-signal correlation of abnormal request patterns, elevated 5xx errors, and subsequent outbound connections indicative of Exploitation for Credential Access.

Vulnerabilities

  • CVE-2026-3055 — CVSS 9.8 (Critical) · CISA KEV · CWE-125 · NetScaler ADC; NetScaler Gateway. Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
  • CVE-2026-4368 — CVSS 0 (Low) · NetScaler ADC; NetScaler Gateway. Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup

Techniques

  • AML.T0106 Exploitation for Credential Access (Credential Access)
  • T1190 Exploit Public-Facing Application (Initial Access)
  • T1212 Exploitation for Credential Access (Credential Access)
  • T1589.001 Credentials (Reconnaissance)
  • T1590.006 Network Security Appliances (Reconnaissance)
  • T1595.002 Vulnerability Scanning (Reconnaissance)

Indicators

  • 1 indicator on file

Coverage


4. Citrix NetScaler Zero-Days Under Active Exploitation (Segment)

Blast radius expanded: new vendor(s): gateway

What changed

On September 26, 2026, watchTowr and the Dutch National Cyber Security Centre confirmed active exploitation of two unpatched zero-day remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway appliances. The Dutch National Cyber Security Centre issued a pre-notification on September 25, 2026, which watchTowr researchers subsequently verified on September 26. These flaws are distinct from CVE-2026-19490 and CVE-2026-19489, already listed in the CISA Known Exploited Vulnerabilities catalog. Citrix has not released a patch or formal advisory. BleepingComputer and Tenable align on active exploitation, though no public indicators of compromise or proof-of-concept code exist yet. Take exposed NetScaler appliances offline until patches arrive. Assume any internet-facing NetScaler device is compromised. The blast radius has expanded to include Gateway appliances, meaning your perimeter is exposed if you run these devices.

How it works

A buffer overflow in the NetScaler stack lets attackers inject malicious code directly into the appliance’s memory. CVE-2026-19489 triggers a specific failure state for attackers with prior access, distinct from the adjacent CVE-2026-19490. These vulnerabilities enable remote code execution on the appliance, granting initial access without prior authentication. This remote code execution capability is distinct from the authentication bypass mechanism of CVE-2026-19490, which affects the same product lines. CVE-2026-19490 is a NetScaler ADC and Gateway flaw with a CVSS 9.8 score that allows remote code execution without authentication or user interaction. Today, the NetScaler ADC and Gateway event escalated as two distinct flaws, CVE-2026-19489 and CVE-2026-19490, converged on the same affected product versions ranging from 13.1 through 63.21 and 14.1 through 73.32. Active exploitation of unpatched Citrix NetScaler RCE zero-days extends the threat beyond the previously cataloged CVE-2026-19490, leaving your perimeter exposed without a vendor fix. Because these new flaws remain unaddressed by Citrix, the lack of a patch or indicators of compromise forces an immediate decision to isolate affected appliances to prevent initial access.

What to do

Patch NetScaler versions 14.1 through 73.32 and 13.1 through 63.21 immediately, as CISA confirms active exploitation of this specific access path. Isolate NetScaler ADC 14.1 and NetScaler Gateway 14.1 systems today because the operational distinction between these two flaws changes the required containment strategy. Prioritize isolating devices running NetScaler ADC or Gateway versions 13.1 through 63.21 and 14.1 through 73.32, which are the specific ranges affected by the active exploitation.

Limits and watch

It is impossible to distinguish compromised appliances from healthy ones without taking them offline. The exact exploitation mechanics and full scope of impact remain unverified. Watch for Citrix communications and patches expected early in the week of September 28, which will define the remediation path for the unpatched zero-days.

Vulnerabilities

  • CVE-2026-19490 — CVSS 9.8 (Critical) · CISA KEV · NetScaler ADC; NetScaler Gateway. Vulnerability in NetScaler ADC and NetScaler Gateway.
  • CVE-2026-19489 — CVSS 0 (Low) · NetScaler ADC; NetScaler Gateway. Vulnerability in NetScaler ADC and NetScaler Gateway.

Techniques

  • T1021.007 Cloud Services (Lateral Movement)
  • T1190 Exploit Public-Facing Application (Initial Access)
  • T1203 Exploitation for Client Execution (Execution)
  • T1210 Exploitation of Remote Services (Lateral Movement)
  • T1212 Exploitation for Credential Access (Credential Access)
  • T1552.004 Private Keys (Credential Access)
  • T1590.006 Network Security Appliances (Reconnaissance)

Indicators

  • 8 indicators on file

Coverage


5. Sysdig documents JADEPUFFER, the first end-to-end AI-driven ransomware operation exploiting Langflow (Segment)

Event first seen in a show

What changed

Sysdig documented JADEPUFFER, the first confirmed ransomware operation orchestrated entirely by an autonomous large language model agent. The attack began by exploiting CVE-2025-3248 in an internet-facing Langflow instance to harvest cloud credentials. The agent pivoted to a production environment, moving laterally to an Alibaba Nacos service. It deployed over six hundred coordinated payloads across two machines, encrypting 1,342 configuration items before deleting database schemas and leaving Bitcoin ransom notes. Microsoft tracked related destructive activity under the alias Storm-3168, involving the deletion of Azure resources such as Virtual Machines and Key Vaults. Sysdig’s analysis confirms the agent’s self-correcting behavior, noting that it adapted its actions and recovered from failures without human intervention. Reports differ on the actor’s full scope; one outlet notes the same Langflow instance was later targeted by a Go-based strain called ENCFORGE, but this remains a single-source claim. The lead sheet details specific attacker infrastructure, including the domain proton[.]me and IP addresses 45[.]131[.]66[.]106 and 64[.]20[.]53[.]230, alongside MITRE techniques like AI Agent Tool Invocation and Generate Malicious Commands.

How it works

An AI agent exploited CVE-2025-3248 in Langflow versions before 1.3.0 to scan Chinese cloud providers like Aliyun and Tencent. The agent sent unauthenticated requests to the /api/v1/validate/code endpoint, which lacks authentication controls. This allowed the remote attacker to execute arbitrary Python code on the host. Separately, yesterday’s Nacos breach exploited a backdoor in version 1.4.0. Attackers bypassed Nacos authentication by spoofing the user-agent header in versions before 1.4.1. This action exploited the CWE-290 flaw to skip the AuthFilter. The operation compromised two service principals within the same Azure tenant, with one used for reconnaissance and the other for executing destructive operations across multiple subscriptions. This allows any user to execute full administrative tasks on the server, granting complete control over the dynamic service discovery platform.

What to do

The JADEPUFFER operation demonstrates that autonomous agents can now execute full ransomware cycles, including lateral movement to Alibaba Nacos and the encryption of 1,342 configuration items, without human intervention. Upgrade Nacos to 1.4.1 or later to close the authentication bypass path. Upgrade Langflow to 1.3.0 or later to close the missing authentication gap.

Limits and watch

Prioritize manual penetration testing and threat modeling to verify the correctness of custom authentication mechanisms, as automated tools may miss the missing authentication flaws in critical functions. The claim that the same Langflow instance was later targeted by a Go-based strain called ENCFORGE is currently a single-source report and lacks independent corroboration. The full scope of the actor’s infrastructure remains contested, with discrepancies between Sysdig’s focus on self-correcting agent behavior and Microsoft’s tracking of destructive Azure resource deletion under different aliases.

Vulnerabilities

  • CVE-2025-3248 — CVSS 9.8 (Critical) · CISA KEV · CWE-306 · langflow-ai langflow. Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint.
  • CVE-2021-29441 — CVSS 8.6 (High) · CWE-290 · alibaba nacos. Nacos is a platform designed for dynamic service discovery and configuration and service management.

Techniques

  • AML.T0006 Active Scanning (Reconnaissance)
  • AML.T0010.001 AI Software (Initial Access)
  • AML.T0016.002 Generative AI (Resource Development)
  • AML.T0053 AI Agent Tool Invocation (Execution)
  • AML.T0054 LLM Jailbreak (Defense Evasion)
  • AML.T0090 OS Credential Dumping (Credential Access)
  • AML.T0098 AI Agent Tool Credential Harvesting (Credential Access)
  • AML.T0102 Generate Malicious Commands (Ai Attack Staging)
  • AML.T0108 AI Agent (Command And Control)
  • T1059.009 Cloud API (Execution)
  • and 3 more

Indicators

  • 3 indicators on file

Coverage


6. Lazarus Group Steals $292M from KelpDAO via Off-Chain Node Compromise (Segment)

No material change since last show

What changed

Lazarus Group’s TraderTraitor cell drained roughly $292 million from KelpDAO’s LayerZero bridge on April 18, 2026. The attack targeted the off-chain verification nodes of KelpDAO’s rsETH configuration, bypassing standard on-chain transaction validation. Ten independent outlets, including BleepingComputer and Chainalysis, agree on the actor and the mechanism. Attackers compromised internal RPC nodes and DDoS’d external ones, feeding false data to the single-point-of-failure verification network. KelpDAO detected the anomaly, paused contracts, and blacklisted attacker addresses, while the Arbitrum Security Council moved to freeze downstream funds. LayerZero Labs confirmed the protocol functioned as intended, isolating the breach to KelpDAO’s specific configuration rather than a systemic protocol failure. Detection engineering must prioritize integrity checks on RPC nodes and monitor for anomalous burn events that do not match actual token movements. The lead sheet lists attacker infrastructure domains such as anesthesiaschool[.]com, app[.]heyhay[.]online, and grenight[.]com.

How it works

This manipulated the verification layer to trick Ethereum contracts into releasing funds based on phantom token burns. The incident was isolated to KelpDAO’s rsETH configuration, with no impact on other assets or applications using the LayerZero protocol.

What to do

The 3CX app compromise exposes a critical vector for lateral movement into enterprise communication infrastructure, distinct from the primary financial theft. This incident confirms that Lazarus Group’s operational scope extends beyond crypto exchanges to target IT services providers and developer ecosystems. Implement application whitelisting and software restriction policies to prevent the installation of unauthorized dependencies in CI/CD pipelines. Audit GitHub Actions and npm packages for typosquatting or abandoned package re-registrations that could inject malicious code into build processes.

Limits and watch

The specific extent of the 3CX app compromise remains unclear, with evidence only confirming the initial vector rather than the full scope of data exfiltration. Attribution to the Lazarus Group for the IT services provider backdoor is based on tooling similarities, but direct confirmation of the actor’s intent for this specific non-crypto victim is not established. Watch for anomalous package manager activity, like unexpected writes to node_modules or preinstall hook execution, which signals supply-chain tampering.

Techniques

  • AML.T0011.001 Malicious Package (Execution)
  • AML.T0097 Virtualization/Sandbox Evasion (Defense Evasion)
  • EMERGING-0006 PyLangGhost RAT
  • T1001.003 Protocol or Service Impersonation (Command And Control)
  • T1005 Data from Local System (Collection)
  • T1008 Fallback Channels (Command And Control)
  • T1010 Application Window Discovery (Discovery)
  • T1012 Query Registry (Discovery)
  • T1016 System Network Configuration Discovery (Discovery)
  • T1021.001 Remote Desktop Protocol (Lateral Movement)
  • and 10 more

Named actors and malware

  • Lazarus Group (actor)
  • Lazarus (actor)
  • threat (actor)

Indicators

  • 25 indicators on file

Coverage


Event now covered by 4 outlets (was 3); 3 new indicator(s) observed; Now attributed to malware: Redline stealer

What changed

Infostealer strains Lumma, RedLine, and Vidar now drive over eighty-five percent of detected cloud credential theft incidents by harvesting session tokens from developer workstations. Once stolen, the data bypasses multi-factor authentication, granting attackers direct access to AWS, Azure, and Google Cloud environments. KELA’s investigation unmasked the Hellcat group’s operators, linking them to breaches at Telefónica and Schneider Electric. This spike is driven by infostealer strains like Lumma, RedLine, and Vidar, which now account for over eighty-five percent of detected incidents. Reports from NordVPN, gbhackers, kelacyber, and osibeyond converge on the mechanism of infostealer-driven credential theft. The United States ranks fourth globally with over three point six billion leaked cookies, two hundred and seventy-five million of which remain active. The Hellcat group’s involvement in the Telefónica and Schneider Electric breaches is validated by industry experts and shared with law enforcement. Watch for the specific domains pato[.]pw and pryx[.]cc, which appear in recent indicator sets.

How it works

These tools exploit unmanaged personal devices and CI/CD pipelines to harvest credentials and API keys before the data is resold to access brokers. Stolen application access tokens let adversaries act with compromised account permissions, escalating privileges in cloud environments.

What to do

The United States ranks fourth globally for leaked cookies, exposing 3.6 billion active user cookies and directly threatening enterprise identity integrity and session security. Implement application isolation and sandboxing to restrict infostealer execution, blocking access to sensitive resources on developer workstations. Integrate security into the software development lifecycle to reduce exploitable weaknesses that adversaries leverage for credential access.

Limits and watch

The extent of credential exposure remains uncertain because a single employee downloading compromised software can expose an organization’s entire database of digital credentials. Specific attribution for recent infostealer infections is complicated by the fact that Rey was infected by Redline and Vidar stealer on separate occasions in February and March 2024. Monitor for abnormal LSASS memory access and forged Kerberos tickets, which indicate adversary exploitation of authentication mechanisms for credential access. Watch for failed or anomalous PAM authentications and abnormal segfaults in authentication services to identify exploitation attempts targeting credential daemons.

Techniques

  • T1005 Data from Local System (Collection)
  • T1027.014 Polymorphic Code (Stealth)
  • T1195 Supply Chain Compromise (Initial Access)
  • T1212 Exploitation for Credential Access (Credential Access)
  • T1219 Remote Access Tools (Command And Control)
  • T1528 Steal Application Access Token (Credential Access)
  • T1539 Steal Web Session Cookie (Credential Access)
  • T1550.004 Web Session Cookie (Lateral Movement)
  • T1552.004 Private Keys (Credential Access)
  • T1555.005 Password Managers (Credential Access)
  • and 6 more

Named actors and malware

  • Lumma (malware)
  • RedLine (malware)
  • Redline stealer (malware)
  • Lumma Stealer (malware)

Indicators

  • 5 indicators on file

Coverage


8. Infostealer Surge: 3.9B Credentials Stolen, Vidar 2.0 Targets Azure (Segment)

Event now covered by 4 outlets (was 3); Now attributed to malware: LummaStealer; 3 new attacker infrastructure indicator(s)

Ontinue’s Advanced Threat Operations team published a static analysis of Vidar Stealer 2.0, revealing a complete architectural overhaul from C++ to pure C that introduces pervasive control flow flattening and dedicated Azure credential targeting via MSAL token cache theft and Azure CLI extraction. This new version specifically targets Azure credentials and Chrome v20 encrypted data. Sophos researchers identified a trend where cybercriminals impersonate trusted AI tools like Claude, ChatGPT, and Microsoft Copilot to distribute malware such as LummaStealer and backdoors via fake download pages, browser extensions, and social engineering techniques like InstallFix. Meanwhile, Ontinue’s analysis reveals Vidar Stealer 2.0, first seen in October 2025, has been rebuilt in pure C with control flow flattening. Sophos reports that attackers are now impersonating trusted AI tools like Claude and ChatGPT to distribute these payloads, leveraging brand trust to bypass user suspicion. KELA confirmed that infostealers stole 3.9 billion credentials in 2024, infecting 4.3 million devices. Lumma, StealC, and RedLine strains compromised those credentials, accounting for over 75% of infections. Of 38 confirmed cases involving hostile AI activity, 30 involved software impersonation to deliver password stealers, cryptocurrency theft, and command execution payloads. Watch for traffic to download-version[.]1-9-183[.]com, perplexity-ai[.]online, and verification-claude-cdn[.]beer.

The malware uses Chrome v20 AES-GCM decryption at function 0x140014d6c via Windows BCrypt APIs, targeting over 50 cryptocurrency wallets across multiple browsers with no static imports, indicating full dynamic API resolution. Adversaries impersonate trusted persons or organizations to persuade targets into performing actions, leveraging established trust to achieve goals against multiple victims. The stolen data fuels a black market economy where cybercriminals trade login details to facilitate account takeovers, identity theft, and extortion campaigns targeting both individuals and businesses. This redesign positions the infostealer to capitalize on operational disruptions affecting competitors like Lumma Stealer, coinciding with its first observation in October 2025.

Sophos confirmed attackers are impersonating Claude and ChatGPT to distribute Lumma Stealer, bridging AI Agent Clickbait with impersonation frameworks to target AI DevOps resources. This ClickFix lure tricks users into executing commands via fake verification prompts, bypassing standard download-based detection entirely. Investigate clipboard-to-run command execution patterns and traffic to domains like perplexity-ai[.]online, treating any interaction as a potential command execution attempt rather than a benign service. With 3.9 billion credentials compromised in 2024 by Lumma, StealC, and RedLine, any identity lacking multi-factor authentication is effectively exposed to takeover. Vidar Stealer 2.0’s shift to pure C with control flow flattening and Azure credential targeting increases the risk that stolen tokens access cloud control planes before rotation. Enforce multi-factor authentication for all cloud service logins to stop adversaries from using stolen valid accounts to access the cloud control plane. Implement privileged account management controls to restrict and monitor administrative credentials that adversaries may leverage for cloud resource enumeration.

Vidar Stealer 2.0 uses heavily obfuscated control flow with computed jumps to evade static analysis, meaning standard signature-based detection may miss the malware on endpoints. The malware exfiltrates data via HTTP POST requests using multipart/form-data encoding, which complicates network detection because the traffic blends in with legitimate web form submissions. Watch for cloud logins from unusual locations or browser signatures that lead to resource listing through command line tools or API calls.

Techniques

  • AML.T0011.001 Malicious Package (Execution)
  • AML.T0037 Data from Local System (Collection)
  • AML.T0048.001 Reputational Harm (Impact)
  • AML.T0052 Phishing (Initial Access)
  • AML.T0055 Unsecured Credentials (Credential Access)
  • AML.T0073 Impersonation (Defense Evasion)
  • AML.T0087 Gather Victim Identity Information (Reconnaissance)
  • AML.T0091.000 Application Access Token (Lateral Movement)
  • AML.T0097 Virtualization/Sandbox Evasion (Defense Evasion)
  • AML.T0100 AI Agent Clickbait (Execution)
  • and 10 more

Named actors and malware

  • LummaStealer (malware)
  • Lumma (malware)
  • RedLine (malware)
  • Lumma Stealer (malware)
  • Emotet (malware)

Indicators

  • 4 indicators on file

Coverage


9. Microsoft tracks Storm-2570’s consistent tradecraft across Qilin, DragonForce, Anubis, and BERT ransomware (Segment)

No material change since last show

What changed

Microsoft Threat Intelligence confirmed that ransomware affiliate Storm-2570, tracked since April 2025, executes a uniform pre-encryption playbook regardless of the ransomware family it deploys. The group has surpassed 700 confirmed attacks in 2025, with recent campaigns targeting NHS hospitals in London and county government systems in the United States. Microsoft verified that Storm-2570 targets healthcare, education, energy, and manufacturing sectors across the US, UK, Spain, Netherlands, Canada, and Puerto Rico. The group uses remote management tools like MeshAgent and ScreenConnect, then steals credentials with Mimikatz, LaZagne, and pypykatz. This operational flexibility is confirmed by the deployment of four distinct ransomware families—Qilin, DragonForce, Anubis, and BERT—while maintaining identical post-compromise tradecraft. If you see that combination, assume Storm-2570 is active and isolate the host immediately.

How it works

Attackers establish persistent access through rogue ScreenConnect installations, then execute PowerShell commands targeting Event ID 1149 in the RemoteConnectionManager log to enumerate RDP authentication history. This stealthy reconnaissance maps network connections and identifies privileged accounts without triggering traditional security alerts, before deploying tunneling techniques to maintain access. Because the group uses the same pre-encryption steps for Qilin, DragonForce, Anubis, and BERT, the exposure boundary extends to any environment where MeshAgent or ScreenConnect is paired with Mimikatz usage.

What to do

Qilin and Dragonforce consistently deploy BERT ransomware, confirming Storm-2570 uses uniform post-compromise tradecraft across multiple malware families. This standardized approach means identifying the initial access vector via remote management tools is sufficient to predict subsequent credential theft and encryption phases. Disable or remove unnecessary Remote Desktop Protocol services on servers that do not require interactive user access to reduce the attack surface for credential-based logins. Implement auditing configurations to systematically review system logs for anomalies in user behavior and RDP session activity to detect unauthorized access attempts.

Limits and watch

Storm-2570 consistently uses Mimikatz and LaZagne for credential access, but the specific initial access vector for each campaign remains distinct and not fully mapped in the current evidence. The association of BERT ransomware with Storm-2570 is established, but the extent to which other ransomware families like Anubis are deployed with the same pre-encryption steps is not fully quantified. Watch

Techniques

  • AML.T0012 Valid Accounts (Initial Access)
  • AML.T0049 Exploit Public-Facing Application (Initial Access)
  • AML.T0075 Cloud Service Discovery (Discovery)
  • AML.T0103 Deploy AI Agent (Execution)
  • AML.T0112.000 Local AI Agent (Impact)
  • T1003.001 LSASS Memory (Credential Access)
  • T1007 System Service Discovery (Discovery)
  • T1021 Remote Services (Lateral Movement)
  • T1021.001 Remote Desktop Protocol (Lateral Movement)
  • T1078 Valid Accounts (Stealth)
  • and 10 more

Named actors and malware

  • Qilin (malware)
  • Qilin Ransomware (malware)

Coverage


10. Canadian Cyber Center Confirms Active Wild Exploitation of Roundcube Webmail SQL Injection CVE-2026-48842 (Hot)

2 new indicator(s) observed

The Canadian Center for Cyber Security issued advisory AV26-503 on September 21, 2026, confirming that CVE-2026-48842 is under active exploitation. This confirmation marks a shift from a patched vulnerability to a live threat against unpatched Roundcube Webmail instances. If you are running versions prior to 1.6.16 or 1.7.1, you are exposed.

Roundcube Webmail users in versions 1.6.0 and 1.7.0 face remote code execution and SQL injection flaws today. Authenticated attackers trigger these issues by injecting malformed serialized objects into the _from parameter in upload[.]php. The vulnerability exists in the virtuser_query plugin, where a backslash-escape bypass in the PHP preg_replace function allows manipulation of database queries. This improper neutralization of special elements lets injected data be interpreted as executable shell commands by the backend. Additionally, attackers can inject scripts that execute after page load by exploiting improper neutralization of user input before DOM manipulation. Roundcube Webmail versions before 1.5.12 and 1.6 before 1.6.12 allow DOM-based XSS via the animate tag, bypassing server-side filters. Authenticated attackers exploit this CVSS 9.9 flaw to modify application state or consume CPU resources without network exposure. This remote code execution weakness, rated CVSS 9.9, stems from deserializing untrusted data without ensuring validity, enabling attackers to modify application state. This allows attackers to execute system commands through MSSQL_xp_cmdshell, stealing data and gaining privileges. Successful exploitation allows attackers to access sensitive user data, mail account credentials, and administrative functions within the webmail environment.

Because the flaw bypasses authentication in the virtuser_query plugin, attackers can manipulate database queries to access sensitive communications and administrative functions without valid user credentials. Isolate affected Roundcube instances immediately to stop unauthorized code execution until patch 1.5.10 is available. Patch Roundcube immediately to stop reflected or DOM-based script execution that yields a CVSS 7.2 impact. Patch to 1.6.16 or 1.7.1 immediately to prevent unauthorized code execution, as static analysis tools may miss this specific backslash bypass. Patch versions 1.5.10 and 1.6.11 immediately, as automated static analysis cannot reliably detect runtime object injection. Validate serialized inputs before deserialization to prevent the object injection prerequisite identified by CAPEC. Apply static analysis to detect this pattern and mitigate by populating new objects instead of directly deserializing tainted data. Validate the _from parameter before unserialization and apply the latest patch to close the remote code execution path. Upgrade to version 1.6.16 or 1.7.1 immediately to close the Pre-authentication SQL injection gap. Update all Roundcube Webmail installations to version 1.6.16 or 1.7.1 immediately to close the SQL injection vector in the virtuser_query plugin. Inventory your environment for legacy versions prior to 1.5.10 or 1.6.11 to ensure they are patched against CVE-2025-49113, which allows remote code execution by authenticated users.

The evidence does not specify the exact number of compromised instances or the specific data exfiltrated, only that the vulnerability is being actively exploited. It remains unclear whether the active exploitation of CVE-2026-48842 has led to lateral movement or further compromise beyond the initial database access. Monitor for abnormal request patterns to public endpoints followed by elevated 4xx/5xx errors or unusual methods, which indicate an adversary attempting to exploit the public-facing application.

Vulnerabilities

  • CVE-2025-49113 — CVSS 9.9 (Critical) · CISA KEV · CWE-502 · Roundcube Webmail. Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP…
  • CVE-2026-48842 — CVSS 8.1 (High) · CWE-89 · Roundcube Webmail. Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.
  • CVE-2025-68461 — CVSS 7.2 (High) · CISA KEV · CWE-79 · Roundcube Webmail. Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

Techniques

  • T1190 Exploit Public-Facing Application (Initial Access)
  • T1505.003 Web Shell (Persistence)
  • T1556.006 Multi-Factor Authentication (Defense Impairment)
  • T1589.002 Email Addresses (Reconnaissance)

Indicators

  • 4 indicators on file

Coverage