CrowdStrike (covered by The Hacker News, 8 September 2026) tracks Slim Spider, a Brazil-based e-crime cluster active against Brazilian financial institutions since at least March 2026. In a late-March 2026 multi-stage intrusion at a Brazilian financial institution, the actor targeted crypto custody assets and Pix instant-payment infrastructure: custom Bash scripts queried cloud instance metadata for temporary credentials, enumerated secrets in the cloud credential manager, used Foundry cast to derive an Ethereum wallet address from a stolen private key, and implemented cloud-native signing via OpenSSL. The actor also pivoted to Azure DevOps to run malicious pipelines that deployed implants across a managed Kubernetes cluster, including backdoors mimicking legitimate infrastructure binaries (e.g. "spi" impersonating Sistema de Pagamentos Instantâneos). Primary: CrowdStrike adversary page; wire: The Hacker News.
CrowdStrike — Slim Spider adversary page
breaches cloud identity
Vulnerabilities
Tue 8 Sep
The Hacker News (8 September 2026) reports security firm Calif built a worm that takes over a WeChat account via an incoming call and demonstrated spread across three test phones. The callee does not need to answer or touch the phone, but the caller must already be a WeChat contact. Calif reported the flaw to Tencent in July and says the company has since shipped a fix (wire does not name a CVE in the RSS abstract). Treat as a messenger client/patch urgency item for WeChat on iPhone and Android; confirm your app store build is current. Wire-only until a Tencent/CVE primary is linked. Primary wire: The Hacker News.
The Hacker News — WeChat Calif worm (8 Sep 2026)
vulnerabilities identity australia
UPDATE 11 September 2026: the Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a DAVID driver-database breach after ShinyHunters claimed compromise. In a statement posted to X (status 2098239548660514979), FLHSMV said it learned of the breach on 4 September 2026, that it was quickly mitigated, and that no further breach is ongoing. Investigation found attackers used compromised credentials of a single Plant City Police Department user that had been improperly stored on the employee’s personal electronic device. FLHSMV notified the Florida Office of the Attorney General and is working with the Florida Digital Service and Florida Department of Law Enforcement; further detail withheld pending the criminal investigation. FLHSMV has not disclosed how many records were accessed and has not confirmed ShinyHunters’ claim of 200,000+ records. ShinyHunters had claimed a password-reset flaw and multi-account access (including DMV/FBI accounts) iterating DAVID record IDs from 3 September — FLHSMV’s credential finding differs from that claim. Original 8 September desk card covered the unconfirmed extortion claim with Epstein DAVID screenshot as purported proof. No Australian nexus identified. Primary: FLHSMV X statement; wire: BleepingComputer (11 Sep).
FLHSMV statement on X (4 Sep learn / posted around claim period)
breaches identity
Vulnerabilities
Tue 8 Sep
SAP’s September 2026 security patch day (covered 8 September 2026 by BleepingComputer and SecurityWeek) includes CVE-2026-44756, a maximum-severity memory-corruption bug in Extended Passport (EPP) processing in the SAP kernel, dubbed OVERPASS by Onapsis. Missing boundary checks on externally supplied length fields during EPP deserialization can let unauthenticated attackers run OS commands as the SAP installation owner, recover DB credentials/password hashes, read live user sessions, and modify data/binaries. Onapsis says EPP is hit as a session opens (before authz controls), via web/ICM, SAP GUI, and RFC; products relying on the vulnerable kernel include S/4HANA, ERP/ECC, NetWeaver, Web Dispatcher, BW/4HANA, Enterprise Portal, PI/PO, Solution Manager and others. Onapsis estimates >10,000 internet-facing SAP web interfaces; no in-the-wild exploitation indicators reported for OVERPASS at publish. Same cycle: CVE-2026-58240 (S4GET) missing authentication on NetWeaver Message Server enabling unauth cluster RCE as <sid>adm; also critical CVE-2026-76969 (CAP credential disclosure) and CVE-2026-66768 (NetWeaver access control). Apply SAP Security Notes for September 2026 immediately; do not invent CVSS for sister CVEs beyond vendor/Onapsis statements. Primary research: Onapsis; wires: BleepingComputer / SecurityWeek.
BleepingComputer — SAP OVERPASS CVE-2026-44756 (8 Sep 2026)
vulnerabilities cloud identity ot ics
Vulnerabilities
Tue 8 Sep
Microsoft’s 8 September 2026 Patch Tuesday is its largest security release on record. BleepingComputer counts 966 flaws shipped on Patch Tuesday itself (105 Critical, including 81 RCE), excluding 204 flaws fixed earlier in the month in cloud products; SecurityWeek and Krebs count about 974 CVEs across the broader September bundle. Two actively exploited elevation-of-privilege zero-days are fixed: CVE-2026-81963 (Windows Update Stack link-following to SYSTEM; credited to Romain Deperne and MSTIC) and CVE-2026-85880 (Windows ALPC heap buffer overflow to SYSTEM / AppContainer sandbox escape; Volexity and Proofpoint researchers). Coverage notes ~20 potentially wormable unauthenticated RCEs in the set and calls out Exchange (CVE-2026-55007), SharePoint (CVE-2026-69465), RDS (CVE-2026-69525), SQL (CVE-2026-65669), and Authenticator (CVE-2026-80097) among high-priority items. Microsoft attributes the volume increase partly to AI-assisted vulnerability discovery. NEW 8 Sep KEV: CISA added both exploited zero-days to the Known Exploited Vulnerabilities catalog on 2026-09-08 (catalog 2026.09.08) — CVE-2026-81963 and CVE-2026-85880 (FCEB dueDate 2026-09-22). WA SOC advisory 20260909001 (9 September 2026, TLP:CLEAR) summarises the September Monthly Updates as addressing 973 vulnerabilities, highlights critical CVE-2026-69730 and CVE-2026-69525 (CVSS 9.8) plus the two known-exploited EoPs (CVSS 7.8), notes Microsoft detected exploitation of one or more of the mentioned vulnerabilities, and says WASOC has not received WA Government exploitation reports at the time of writing. Prioritise the two exploited EoPs, internet-facing roles, and Extended Security Updates where applicable.
BleepingComputer — September 2026 Patch Tuesday (8 Sep 2026)
vulnerabilities cloud identity australia
Vulnerabilities
Tue 8 Sep
The Hacker News (8 September 2026) summarises Red Hat guidance that a FreeIPA flaw lets a client that has never logged in create a Kerberos identity of its choosing in the directory and end up in the administrators group. FreeIPA stores identities in 389 Directory Server over LDAP; the attack also needs a second flaw in that database software. Wire abstract does not list CVE IDs or fixed package versions — operators should pull current RHEL/FreeIPA errata from Red Hat rather than inventing patch levels. Primary wire: The Hacker News pending RHSA deep-link. Watchlist relevance: Red Hat / identity plane.
The Hacker News — FreeIPA admin credential chain (8 Sep 2026)
vulnerabilities identity cloud
BleepingComputer (8 September 2026) reports Sophos analysis of a Linux rootkit targeting F5 BIG-IP APM environments that intercepts PHP loading and injects a fileless web shell in memory so on-disk PHP files stay unchanged. ESET tracks the family as PoisonedRefresh. Sophos describes a separate installer/propagation stage that tampers with Apache /usr/sbin/httpd, SELinux policy, and persistence across BIG-IP upgrade images; the second stage uses RC4 string hiding, hooks __libc_start_main and apr_dso_load, and injects into APM webtop scripts such as apm_css.php3, full_wt.php3, and webtop_popup_css.php3. The web shell accepts magic requests, eval()s decrypted content, and returns HTTP 201 disguised as text/css; a password-protected local UNIX socket can spawn Bash without a TCP listener. Sophos says the payload was likely deployed after exploitation of CVE-2025-53521 (critical RCE that F5 reclassified from DoS in March). Shadowserver reportedly tracked about 795 internet-exposed BIG-IP APM endpoints still vulnerable to that CVE at time of writing. Hunt: Apache workers reading /proc/self/maps, changing libphp memory protections, creating /run/bigtlog.pipe, launching /bin/bash, unusual POSTs to targeted .php3 paths, or HTTP 201 + text/css responses. Wire: BleepingComputer; research: Sophos / ESET.
BleepingComputer — BIG-IP APM PoisonedRefresh rootkit (8 Sep 2026)
breaches network cloud identity
BleepingComputer (8 September 2026) covers German firm Nebty’s report on DoppelCart, a fake e-shop cluster of more than 119,000 domains (mostly .SHOP; Nebty says ~2.72% of that TLD), with more than 105,000 still active in latest scans. About 96% of confirmed shops share identical build files and resolve to 27 commerce backends; they impersonate ~44,182 brands (median two clones each; some brands >30 clones) and advertise discounts up to ~65%. Checkout pages collect PAN, expiry, CVV, name, email, phone and address over WebSockets to C2 in real time, and can relay bank OTPs. Victims sometimes email the real brand’s support address shown on the fake shop. Nebty built a searchable brand-abuse database and said the main hosting provider did not respond. Distinct from BogusBazaar (~75k sites). Wire: BleepingComputer; research: Nebty.
BleepingComputer — DoppelCart (8 Sep 2026)
tech cloud identity
Check Point Research (published 8 September 2026; covered by The Hacker News the same day) found a covert two-way channel between code-execution containers of separate ChatGPT accounts via an internal JFrog Artifactory package service those containers could all reach. Containers could write/read shared item metadata, turning package-delivery properties into a clipboard between supposedly isolated sessions. A planted prompt, shared conversation link, or custom GPT instruction could make a victim session pull a hidden task, use the victim’s already-granted connected-app permissions (CPR demo: Gmail), and exfiltrate results to the attacker’s session while the visible reply looked normal; CPR noted a small “Talked to Gmail” label after the fact. OpenAI confirmed the specific internal Artifactory instance was decommissioned after disclosure. CPR also notes its PoC predated separate activity on that Artifactory instance linked to a Hugging Face compromise OpenAI has disclosed. Lesson: AI assistants with tool/connectors are coerced-insider risk. Primary: Check Point Research blog.
Check Point Research — ChatGPT hidden channel / Gmail (8 Sep 2026)
ai cloud identity network
BleepingComputer exclusive (8 September 2026): Kinryū Labs found an internet-reachable Elasticsearch cluster named "pax-info" (Viettel-assigned IP space, Hanoi) holding Advance Passenger Information System (APIS) data — 210,318,069 passenger and 10,465,631 crew records (220,783,700 entries, ~107 GB across 29 indices) spanning January 2017 to April 2026. Fields included names, dates of birth, sex, nationalities, passport/travel-document numbers and expiry, issuing countries, plus flight numbers/dates, airlines, origin/destination/transit airports, seats, baggage refs, and scheduled/estimated/actual times. Sample records reviewed included Korean, Chinese, Canadian, and New Zealand nationalities among others; many international carriers across Asia-Pacific, Europe, and the Middle East appear, so travellers who flew to/from/through Vietnam may be affected (counts are travel records, not unique people). Access path: open internet returned HTTP 401, but a cloud-based path reached the cluster which then accepted default credentials (FOFA saw the host/port from Oct 2022; exposure duration via the second path unknown). Kinryū reported to Vietnamese authorities, airlines, and national CERTs from 3 June 2026; access remediated 8 June 2026 after Singapore Airlines security helped coordinate containment. No ransom notes or sales listings found; without server logs, prior copying cannot be ruled out. Operator organisation not confirmed. Kinryū expects a fuller technical write-up on its blog later this week. Primary wire: BleepingComputer; researcher: Kinryū Labs.
BleepingComputer — Vietnam-linked APIS leak (8 Sep 2026)
breaches australia cloud identity
Sophos analysis (published ~7 September 2026; THN 9 September) describes malware on compromised F5 BIG-IP Access Policy Manager appliances that injects a PHP web shell into memory when Apache loads APM webtop scripts apm_css.php3, full_wt.php3 or webtop_popup_css.php3 — so on-disk file hashes can look clean. F5 previously tracked related activity as malware family c05d5254 and warned those three scripts can be modified or hold in-memory-only shells (IoC list from March). Defenders must not rely on disk-only webshell scans; compare runtime/Apache memory and hunt the F5 IoCs. Related CVE context in wires includes CVE-2025-53521 in some coverage. Watchlist: F5. Primary research: Sophos; wire: THN; vendor IoC context: F5.
Sophos — in-memory PHP web server rootkit (BIG-IP APM)
vulnerabilities network
SOCRadar (covered by The Hacker News, ~7 September 2026) documents PEEP, a Chromium-based post-exploitation toolkit that requires prior admin or code-execution access. An installer injects a malicious extension masquerading as "Smart Bookmarks" into Chrome/Edge profiles; the extension (based on the open-source RedExt framework) beacons for commands, harvests browser data, and uses a native messaging host (nm_host.exe) for host-level command execution and file management. Chinese-language artifacts in the source point to a Chinese-speaking actor; activity remains unattributed. Distinct from browser-infostealer cards: this is a post-compromise backdoor, not an initial-access drop. Primary wire: The Hacker News; research: SOCRadar.
The Hacker News — PEEP Chromium toolkit (~7 Sep 2026)
tech identity cloud