Latest cyber news, threats, security, and guidelines. Stack up.

AI

Fri 11 Sep

Anthropic TI: ShinyHunters affiliate used Claude to strip secrets from 1.8M Android APKs

Anthropic’s September 2026 Threat Intelligence report (activity December 2025–August 2026) case GTG-50014 covers ShinyHunters-affiliate smash-and-grab operators. One French-speaking operator (aliases MeowSHA / frkoo / blazespider) ran a Claude-accelerated credential pipeline across ten AWS EC2 workers that mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets with TruffleHog, routing verified findings to a Telegram group with over 100 source types. A parallel GitHub organisation-email harvester fed stolen GitHub Personal Access Tokens. Anthropic says those two pipelines supplied initial-access credentials for the bulk of confirmed breaches tied to frkoo. Same case cluster includes a carding storefront at policenationale[.]cc / autoshop, Azure AD token theft via AI agents (reported ~2,100 token sets across 40+ Microsoft tenants in ~34 hours in wire coverage), and SaaS secondary victim data theft. Distinct from desk card anthropic-gtg20006-midnight-blizzard-20260911 (Russian espionage malware-rebuild) and from adapthealth-shinyhunters-20260909 (named victim). Anthropic disrupted the misuse. Primary: Anthropic TI report; wire: BleepingComputer (11 Sep).

Anthropic — Detecting and countering misuse of AI (Sep 2026 TI)

ai identity cloud

AI

Fri 11 Sep

Anthropic: GTG-20006 (Midnight Blizzard-aligned) used Claude to auto-evade malware detections

Anthropic’s September 2026 Threat Intelligence report (activity disrupted December 2025–August 2026) details case study GTG-20006, which Anthropic assesses as consistent with public reporting on Russian state-nexus Midnight Blizzard. Operators used Claude-driven workflows to develop, stage, and operate tooling; when monitoring agents saw malware flagged by security products, other agents autonomously modified and rebuilt it until detections were evaded, then staged the toolkit from disposable hosts. Anthropic says more than 20 organisations were in the actor’s planning/recon/live ops set (Ukrainian and European government, defence, diplomatic, think-tank and defence-industrial targets, with some Middle East and Asia reach). Observed theft includes mailboxes from at least two drone-component manufacturers and a full proprietary drone-vision SDK (architecture, BOM, suppliers). Separately the actor compromised at least three hospitality vendors’ hotel guest Wi-Fi admin paths, DNS-hijacked guest traffic (Microsoft CaptiveCrunch), and used headless-browser WhatsApp companion linking to export conversations. Anthropic disrupted the misuse and shared intelligence with partners. Primary: Anthropic TI report; wire: SecurityWeek (11 Sep 2026).

Anthropic — Detecting and countering misuse of AI (Sep 2026 TI)

ai identity

Incidents

Thu 10 Sep

Way Forward (AU charity): payments suspended after third-party CMS cyber incident

Cyber Daily (10 September 2026) reports Australian financial-hardship charity Way Forward disclosed a cyber incident at an external customer-management platform provider. In a 9 September statement the charity said payment arrangements initiated through the affected system were unavailable, clients were notified as a precaution, and creditors were asked for a temporary payment moratorium so client credit reports stay unaffected. A spokesperson later told Cyber Daily the provider’s initial analysis indicated impacted information related mostly to the provider’s own company, still subject to change while the provider investigation continues. No OAIC notice or named vendor was fetched on this pass; treat data-impact scope as provisional. Primary: Cyber Daily quoting Way Forward; company website returned a challenge page this pass.

Cyber Daily — Way Forward third-party CMS incident (10 Sep 2026)

breaches australia identity

Vulnerabilities

Thu 10 Sep

Plesk Backup Manager CVE-2026-68487/68488 (CVSS 9.9): authenticated customer to root on Linux

WebPros Plesk security articles (updated 10 September 2026) cover two Critical Backup Manager flaws on Plesk for Linux. CVE-2026-68487 is path traversal via an unsigned backup header that lets an authenticated customer write arbitrary root-owned files on the host (full server compromise). CVE-2026-68488 is a TOCTOU symlink race during subscription-content restore that can change ownership of directories outside the attacker’s subscription, likewise enabling root. Both carry CVSS 3.0 9.9 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) per the HackerOne CNA records. Affected: Plesk for Linux 18.0.80.6 and earlier, and 18.0.79.10 and earlier; Plesk for Windows not affected. Fixed: 18.0.80.7 and 18.0.79.11 or later. No interim mitigation listed — update is the remediation. Multi-tenant / shared-hosting boxes with customer Panel+FTP are the highest priority. Wire: Cyber Security News (13 Sep) on 68488. Primary: Plesk KB for CVE-2026-68487; companion KB for CVE-2026-68488.

Plesk KB — CVE-2026-68487 Backup Manager path traversal (10 Sep 2026)

vulnerabilities cloud

Incidents

Thu 10 Sep

NSW Online Registry: prosecutors say ChatGPT wrote scraper for ~8,769 restricted court docs

ABC News (10 September 2026) reports a Downing Centre Local Court hearing for Christopher John Duff, 40, who has pleaded not guilty to four counts of accessing restricted data held in a computer. NSW Department of Communities and Justice discovered a breach of the NSW Online Registry (court-user login portal) in March 2025; police say cybercrime detectives investigated alleged unauthorised access to 8,769 restricted documents between January and March 2025 (AVOs, details of minors, and other DCJ forms). Prosecutors allege Duff used ChatGPT to create Python scraper-style scripts for bulk download, then sought legal advice and “coaching” from ChatGPT after his registry login was shut down and before charge — and intend to rely on ChatGPT conversation records plus forensic testimony in what is described as among the first such Australian cases. Hearing stalled on volume (~10,000+ pages of proposed exhibits). Charged April 2025 after a search warrant in Sydney’s east; on bail. Allegations unproven. Primary: ABC; wire: ACS Information Age (10 Sep).

ABC News — Duff / NSW Online Registry ChatGPT hearing (10 Sep 2026)

breaches australia ai identity

Vulnerabilities

Thu 10 Sep

GitLab CE/EE path traversal CVE-2026-85706 (CVSS 10); watchTowr sees probes day after patch

GitLab Critical Patch Release (10 September 2026) ships CE/EE 19.3.2, 19.2.6 and 19.1.8. CVE-2026-85706 is a Critical path traversal in the repository commits API (improper path confinement plus missing authentication enforcement) that can let an unauthenticated requester read arbitrary files from the GitLab server under certain conditions. GitLab CVSS 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N). Impacted: CE/EE from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. Reported via HackerOne by s3ntago. Same release also fixes CVE-2026-87719 (EE GraphQL subscription serializer insecure deserialization; authenticated Duo Chat user; CVSS 9.9) plus further High issues. GitLab.com is patched; Dedicated customers need no action; self-managed must upgrade immediately. NEW 11 September 2026: watchTowr reports in-the-wild probes for CVE-2026-85706 within a day of disclosure (POST /api/v4/projects/{id}/repository/commits/ with file.path). Hunt those log lines. Primary: GitLab docs patch release; secondary: watchTowr / SecurityWeek / BleepingComputer. UPDATE 11 September 2026: CISA added CVE-2026-85706 to KEV (dateAdded 2026-09-11; catalogVersion 2026.09.11). Self-managed instances that have not taken 19.3.2 / 19.2.6 / 19.1.8 should treat this as actively exploited and patch immediately.

GitLab Critical Patch Release 19.3.2 / 19.2.6 / 19.1.8 (10 Sep 2026)

vulnerabilities cloud identity

Vulnerabilities

Thu 10 Sep

Sogou Input Method one-click RCE (CVE-2026-51990); UNC3569 deploys GRAYRABBIT

Gen Digital Threat Labs (Alexandru-Cristian Bardaș, published 10 September 2026) details CVE-2026-51990 in Sogou Input Method for Windows: a one-click remote code execution chain combining unvalidated command-line argument injection in the sgbiz: custom protocol handler, unrestricted URL navigation in a CEF webview, and an outdated unsandboxed Chromium/CEF build (libcef.dll reported as CEF 80.1.16 / Chromium 80.0.3987.163). Gen observed UNC3569 exploiting the flaw in the wild via a crafted link to deploy the GRAYRABBIT backdoor. The issue was reported to Tencent on 9 April 2026 and fixed in Sogou Input Method version 16.3.0.3498 (released 21 April 2026): the patch validates URL arguments accepted through the protocol handler, permits only HTTPS, and restricts navigation to approved Sogou/Tencent domains — Gen and BleepingComputer (13 Sep 2026) still note the embedded Chromium remains outdated and unsandboxed. Primary: Gen Digital research; wires: The Hacker News (11 Sep 2026) and BleepingComputer (13 Sep 2026).

Gen Digital — Gray Rabbits / one-click Sogou backdoor (10 Sep 2026)

vulnerabilities ai

Vulnerabilities

Thu 10 Sep

JFrog Artifactory CVE-2026-42018: anonymous-user token leak (chained in wild with CVE-2026-42016)

Wiz Research (10 September 2026) documents in-the-wild chaining of CVE-2026-42018 and CVE-2026-42016 against self-hosted JFrog Artifactory between 15 August and 8 September 2026, often dropping a custom Rust C2 backdoor. CVE-2026-42018 is an authentication flaw that can return an internal anonymous-user token to an unauthenticated requester even when anonymous access is disabled. Alone it is not admin; chained with CVE-2026-42016 (token scope / privilege escalation) Wiz saw unauthenticated requests become admin-scoped tokens, with follow-on admin account creation, malicious Groovy plugins, and Rust backdoors. Remediated builds per Wiz table include 7.111.20+, 7.117.28, 7.125.20, 7.133.29, 7.146.9+ (and Wiz’s broader “upgrade to 7.111.21 / 7.117.28 / 7.125.20 / 7.133.29 / 7.146.38 / 7.161.20 or later” guidance for the chain). Distinct from desk card cve-2026-82329 (also abused). Primary: Wiz; also JFrog advisories. UPDATE 11 September 2026: CISA added CVE-2026-42018 to the Known Exploited Vulnerabilities catalog (dateAdded 2026-09-11; catalogVersion 2026.09.11). Prioritise patching self-hosted Artifactory under BOD 26-04-style exploited-first triage; hunt anonymous/admin tokens, Groovy plugins, and Rust C2 per Wiz.

Wiz — Artifactory under attack (10 Sep 2026)

vulnerabilities cloud

Vulnerabilities

Thu 10 Sep

JFrog Artifactory CVE-2026-42016: token scope privilege escalation (chained in wild)

Wiz Research (10 September 2026) says CVE-2026-42016 is a privilege-escalation flaw from insufficient token scope enforcement: Artifactory validates signature/issuer but not intended scope, so a low-privileged token (including the anonymous token from CVE-2026-42018) can be escalated. Wiz observed the 42018→42016 chain in the wild 15 August–8 September 2026 alongside separate abuse of CVE-2026-82329; post-exploitation included persistent admin users, malicious Groovy plugins, and Rust C2 backdoors. Wiz lists CVE-2026-42016 impacted prior to 7.133.11 with remediated 7.133.11; for the overall campaign they urge upgrading to 7.111.21 / 7.117.28 / 7.125.20 / 7.133.29 / 7.146.38 / 7.161.20 or later and reviewing auth/admin activity. Primary: Wiz; vendor: JFrog advisories. UPDATE 11 September 2026: CISA added CVE-2026-42016 to the Known Exploited Vulnerabilities catalog (dateAdded 2026-09-11; catalogVersion 2026.09.11). Prioritise patching self-hosted Artifactory under BOD 26-04-style exploited-first triage; hunt anonymous/admin tokens, Groovy plugins, and Rust C2 per Wiz.

Wiz — Artifactory under attack (10 Sep 2026)

vulnerabilities cloud

Advisories

Thu 10 Sep

September 2026 Windows updates break RDS; Microsoft ships 14 Sep OOB fixes

UPDATE 14 September 2026 (BleepingComputer): Microsoft released emergency out-of-band updates that fix Remote Desktop Services failures introduced by the September 2026 security cumulatives, plus related Hyper-V Host Compute Service issues on some Windows 11 builds. OOB packages cited: Windows Server 2025 KB5129235, Server 2022 KB5129237, Server 2019 KB5129238; Windows 11 24H2/25H2 KB5129195, Windows 11 26H1 KB5129194; Windows 10 21H2/22H2 KB5129236 (plus related Win10 servicing packages such as KB5129238/9239 on older trains per Microsoft support links). Server OOBs via Microsoft Update Catalog; some client OOBs also via Windows Update / WSUS. USB audio regressions from September updates are not fully resolved by these OOBs. Prior desk state: Microsoft confirmed RDS instability on release health and published Known Issue Rollback Group Policy packages (e.g. Server 2025 KB5122871, Server 2022 KB5122882, Server 2019 KB5122876) while developing the permanent fix. Prefer the matching OOB over long-lived KIR or cumulative rollback. Operational advisory for AU Windows estates — distinct from Patch Tuesday CVE cards.

BleepingComputer — Microsoft emergency OOB for RDS (14 Sep 2026)

tech

Advisories

Thu 10 Sep

Bitdefender: Google Play Early Access abused to push deceptive reward/casino apps

Bitdefender research (covered 10 September 2026 by The Hacker News and SecurityWeek) describes abuse of Google Play’s Early Access program: Early Access apps cannot receive public star ratings or reviews, so operators seed deceptive titles (fake reward apps, “ghost casino” slot/puzzle skins, trademark-abusing clones such as a GTA-style title with 1M+ downloads) and drive installs via TikTok/Facebook ads that often use celebrity deepfakes. Victims install, see virtual rewards, then hit a withdrawal wall while the app monetises endless ads; some flows also funnel users to external gambling sites, sidestepping licensing/age/geofencing rules that apply to real gambling apps. Primary: Bitdefender; wires: THN / SecurityWeek (10 Sep 2026).

Bitdefender — Google Play Early Access deceptive apps

tech ai

Incidents

Thu 10 Sep

PivotC2: CVE-2025-25249 FortiGate CAPWAP RCE delivers Node.js RAT (178 victims)

SOCRadar Threat Research (covered 10 September 2026 by SecurityWeek) reports active exploitation of CVE-2025-25249, a heap-based buffer overflow in the FortiOS / FortiSwitchManager cw_acd CAPWAP daemon (UDP 5246), delivering PivotC2 — a Node.js post-exploitation RAT for FortiGate with interactive shell, tunneling, scanning and config/credential harvesting. SOCRadar cites NVD CVSSv3 9.8; Fortinet advisory FG-IR-25-084. Exploitation observed since at least July 2026; ~30k targeted IPs and 178 confirmed PivotC2 sessions (majority US; two full US intrusions with data theft). Tradecraft assessed as Russian-speaking cybercrime; RAT comments suggest AI-assisted development. Affected examples: FortiOS 7.6.0–7.6.3, 7.4.0–7.4.8, 7.2.0–7.2.11, 7.0.0–7.0.17; FortiSwitchManager 7.2.0–7.2.6 and 7.0.0–7.0.5. Fixed: FortiOS 7.6.4 / 7.4.9 / 7.2.12 / 7.0.18; FortiSwitchManager 7.2.7 / 7.0.6. Distinct from desk card fortinet-fortimonitoronsight-20260909. Primary: SOCRadar; vendor: FG-IR-25-084; wire: SecurityWeek.

SOCRadar — PivotC2 / CVE-2025-25249

vulnerabilities network