Ticker feed
Malicious releases across 42 @tanstack npm packages, published May 11, harvested GitHub tokens, SSH keys, and cloud credentials from developer machines. One belonged to a CrowdSec developer who had just left, whose access the company kept open so he could finish outstanding work. On May 22 an attacker used his OAuth token to clone roughly 170 private repositories from a Toronto IP address in nine minutes.
CrowdSec revoked the account on May 25, three days after the clone, and learned of the theft only on September 16, when the code appeared on a breach forum. The archive held the SaaS console, data-science models, deployment tools, email addresses for 83 users — under 0.05% of its user base — and names and investment details for 51 potential investors from 2020.
Production systems, databases, and the CrowdSec agent and blocklist data were untouched, and no code was altered. The one live credential was an AWS token scoped to a single SNS topic, probed on August 17 and taken no further. CrowdSec's own lesson is blunt: multi-factor authentication cannot stop malware that already holds a valid token, and only enterprise GitHub plans retain git activity, on a rolling seven-day window.
Source: Cybersecurity News
Malicious releases across 42 @tanstack npm packages, published May 11, harvested GitHub tokens, SSH keys, and cloud credentials from developer machines. One belonged to a CrowdSec developer who had just left, whose access the company kept open so he could finish outstanding work. On May 22 an attacker used his OAuth token to clone roughly 170 private repositories from a Toronto IP address in nine minutes.
CrowdSec revoked the account on May 25, three days after the clone, and learned of the theft only on September 16, when the code appeared on a breach forum. The archive held the SaaS console, data-science models, deployment tools, email addresses for 83 users — under 0.05% of its user base — and names and investment details for 51 potential investors from 2020.
Production systems, databases, and the CrowdSec agent and blocklist data were untouched, and no code was altered. The one live credential was an AWS token scoped to a single SNS topic, probed on August 17 and taken no further. CrowdSec's own lesson is blunt: multi-factor authentication cannot stop malware that already holds a valid token, and only enterprise GitHub plans retain git activity, on a rolling seven-day window.
Source: Cybersecurity News
Cisco has patched CVE-2026-76460, an authentication bypass in Identity Services Engine rated CVSS 10.0 that attackers were already exploiting. Insufficient authentication control on an API endpoint lets a remote attacker send a crafted request, reach the web management interface, and run commands as root with no credentials and no user interaction. Cisco ISE and ISE-PIC are both affected, regardless of configuration.
CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 16 and gave federal agencies until September 19 to remediate, a deadline that has now passed. Fixed builds differ by branch: Patch 12 for 3.1, Patch 11 for 3.2, Patch 12 for 3.3, Patch 7 for 3.4, and Patch 4 for 3.5. Version 3.0 is unsupported and receives no fix.
A compromised ISE can impersonate devices, disable access controls, and open the rest of the network. Cisco says no workaround addresses the flaw, though infrastructure access control lists restricting management and control plane traffic limit remote exploitation until you patch. Check the ISE access.log for suspicious usernames, and treat a clean result carefully — root access lets an attacker remove the traces.
Source: Dark Reading
Cisco has patched CVE-2026-76460, an authentication bypass in Identity Services Engine rated CVSS 10.0 that attackers were already exploiting. Insufficient authentication control on an API endpoint lets a remote attacker send a crafted request, reach the web management interface, and run commands as root with no credentials and no user interaction. Cisco ISE and ISE-PIC are both affected, regardless of configuration.
CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 16 and gave federal agencies until September 19 to remediate, a deadline that has now passed. Fixed builds differ by branch: Patch 12 for 3.1, Patch 11 for 3.2, Patch 12 for 3.3, Patch 7 for 3.4, and Patch 4 for 3.5. Version 3.0 is unsupported and receives no fix.
A compromised ISE can impersonate devices, disable access controls, and open the rest of the network. Cisco says no workaround addresses the flaw, though infrastructure access control lists restricting management and control plane traffic limit remote exploitation until you patch. Check the ISE access.log for suspicious usernames, and treat a clean result carefully — root access lets an attacker remove the traces.
Source: Dark Reading
Security firm Sansec estimates that a supply chain attack on customer engagement platform Brevo pushed malicious code to as many as 100,000 websites. A separate incident on September 10 saw attackers exploit Brevo's SAML SSO handling to reach 138 customer accounts, including Trezor's, which reported phishing that reached 347,000 user email addresses and compromised at least 2,500. Brevo has not said the two incidents are linked.
On September 14, attackers used a compromised Cloudflare API key — long-lived, fully permissioned, and hardcoded in Brevo's source code — to deploy a worker that injected malware into Brevo's domains and three JavaScript files customers embed. Because the worker rewrote responses at the CDN edge and stripped Content-Security-Policy headers, Brevo's origin files stayed untouched and standard integrity checks detected nothing.
The worker ran roughly five and a half hours, serving a fake Cloudflare verification page that used ClickFix prompts to get visitors running commands themselves. WordPress administrators logged in during the window were prompted to install a plugin from an attacker domain. Review September 14 logs for plugin uploads, compare your filesystem against the admin plugin list, and rotate administrator passwords if anything turns up.
Source: SecurityWeek
Security firm Sansec estimates that a supply chain attack on customer engagement platform Brevo pushed malicious code to as many as 100,000 websites. A separate incident on September 10 saw attackers exploit Brevo's SAML SSO handling to reach 138 customer accounts, including Trezor's, which reported phishing that reached 347,000 user email addresses and compromised at least 2,500. Brevo has not said the two incidents are linked.
On September 14, attackers used a compromised Cloudflare API key — long-lived, fully permissioned, and hardcoded in Brevo's source code — to deploy a worker that injected malware into Brevo's domains and three JavaScript files customers embed. Because the worker rewrote responses at the CDN edge and stripped Content-Security-Policy headers, Brevo's origin files stayed untouched and standard integrity checks detected nothing.
The worker ran roughly five and a half hours, serving a fake Cloudflare verification page that used ClickFix prompts to get visitors running commands themselves. WordPress administrators logged in during the window were prompted to install a plugin from an attacker domain. Review September 14 logs for plugin uploads, compare your filesystem against the admin plugin list, and rotate administrator passwords if anything turns up.
Source: SecurityWeek
A newly disclosed flaw in Steam's Windows Client Service lets a standard local user escalate to full NT AUTHORITY\SYSTEM privileges with no admin credentials, no UAC prompt, and no game running. Exploitation needs code execution as an ordinary user and a running Steam client, which counts even when Steam sits idle at the login screen.
Researcher KillaBoi published a proof-of-concept called BrokenPipe on September 14, targeting steamservice.exe. Steam's service accepts a caller-controlled installation root that Valve's signed install script does not cover, so an attacker relocates a launcher to an unprotected path and has the privileged service execute it. No signature is forged or modified.
KillaBoi reportedly notified Valve in March 2026 and says the HackerOne report was marked a duplicate, which prompted the public release. No CVE, CVSS score, or Valve advisory exists, and Valve has not responded to press enquiries. The exploit was validated against Steam 10.96.30.42 on 64-bit Windows 10 and 11.
With no patch available, mitigation is all you have. Inventory Steam installations, remove the client where it isn't needed, and alert on unusual steamservice.exe child processes and on executables running as SYSTEM from user-writable directories.
Source: Cybersecurity News
A newly disclosed flaw in Steam's Windows Client Service lets a standard local user escalate to full NT AUTHORITY\SYSTEM privileges with no admin credentials, no UAC prompt, and no game running. Exploitation needs code execution as an ordinary user and a running Steam client, which counts even when Steam sits idle at the login screen.
Researcher KillaBoi published a proof-of-concept called BrokenPipe on September 14, targeting steamservice.exe. Steam's service accepts a caller-controlled installation root that Valve's signed install script does not cover, so an attacker relocates a launcher to an unprotected path and has the privileged service execute it. No signature is forged or modified.
KillaBoi reportedly notified Valve in March 2026 and says the HackerOne report was marked a duplicate, which prompted the public release. No CVE, CVSS score, or Valve advisory exists, and Valve has not responded to press enquiries. The exploit was validated against Steam 10.96.30.42 on 64-bit Windows 10 and 11.
With no patch available, mitigation is all you have. Inventory Steam installations, remove the client where it isn't needed, and alert on unusual steamservice.exe child processes and on executables running as SYSTEM from user-writable directories.
Source: Cybersecurity News
CISA added CVE-2026-84869, a ConnectWise ScreenConnect flaw rated CVSS 9.9 (Critical), to its Known Exploited Vulnerabilities catalog on September 11, 2026. Missing authorization and improper privilege management let an attacker transfer files to a device and execute them during an active remote session, with no host confirmation.
Huntress observed exploitation from August 20, three weeks before the KEV listing, so the forensic window opens there rather than at the catalog date. Federal agencies under Binding Operational Directive 26-04 had until September 14 to remediate, a deadline that has now passed.
ConnectWise fixed the flaw in ScreenConnect 26.6.5 on September 8. On-premises servers must already run 25.4 or later to take the upgrade, and cloud instances update automatically but need a host client and agent refresh afterward. If you cannot patch, revoke the TransferFiles permission. Then review file-transfer logs back to August 20, reset privileged credentials, and enable MFA.
Source: Cybersecurity News
CISA added CVE-2026-84869, a ConnectWise ScreenConnect flaw rated CVSS 9.9 (Critical), to its Known Exploited Vulnerabilities catalog on September 11, 2026. Missing authorization and improper privilege management let an attacker transfer files to a device and execute them during an active remote session, with no host confirmation.
Huntress observed exploitation from August 20, three weeks before the KEV listing, so the forensic window opens there rather than at the catalog date. Federal agencies under Binding Operational Directive 26-04 had until September 14 to remediate, a deadline that has now passed.
ConnectWise fixed the flaw in ScreenConnect 26.6.5 on September 8. On-premises servers must already run 25.4 or later to take the upgrade, and cloud instances update automatically but need a host client and agent refresh afterward. If you cannot patch, revoke the TransferFiles permission. Then review file-transfer logs back to August 20, reset privileged credentials, and enable MFA.
Source: Cybersecurity News
Acronis researchers say Red Heron, a Chinese-speaking threat actor, is exploiting CVE-2026-60004, a Gitea remote code execution flaw rated CVSS 9.8 (Critical). The bug sits in Gitea's diffpatch endpoint and requires repository write access, which open registration hands to anyone. Gitea fixed it in version 1.27.1 on July 27, 2026.
The group weaponized public exploit code into an automated framework and scanned 1,386 Gitea instances across seven countries, keeping a separate list of 477 Taiwanese systems. Confirmed compromises stand at 13 organizations in six countries. Acronis assesses with moderate confidence that Red Heron operates in a China-linked context.
Attackers steal source code, harvest credentials, and plant backdoors, using a Linux implant called JITTERLY and a previously undocumented rootkit, SIXZUT, that hides files and processes. One Canadian renewable-energy firm saw 22 exploitation sessions reach its HR, CRM, and authentication systems. A Taiwanese target lost root access to a three-node Proxmox cluster.
Versions 1.17 through 1.27.0 are affected. Upgrade to 1.27.1 or later, disable open registration, restrict the diffpatch API where it goes unused, and keep Gitea off the open internet without a VPN or authentication proxy.
Source: Cybersecurity News
Acronis researchers say Red Heron, a Chinese-speaking threat actor, is exploiting CVE-2026-60004, a Gitea remote code execution flaw rated CVSS 9.8 (Critical). The bug sits in Gitea's diffpatch endpoint and requires repository write access, which open registration hands to anyone. Gitea fixed it in version 1.27.1 on July 27, 2026.
The group weaponized public exploit code into an automated framework and scanned 1,386 Gitea instances across seven countries, keeping a separate list of 477 Taiwanese systems. Confirmed compromises stand at 13 organizations in six countries. Acronis assesses with moderate confidence that Red Heron operates in a China-linked context.
Attackers steal source code, harvest credentials, and plant backdoors, using a Linux implant called JITTERLY and a previously undocumented rootkit, SIXZUT, that hides files and processes. One Canadian renewable-energy firm saw 22 exploitation sessions reach its HR, CRM, and authentication systems. A Taiwanese target lost root access to a three-node Proxmox cluster.
Versions 1.17 through 1.27.0 are affected. Upgrade to 1.27.1 or later, disable open registration, restrict the diffpatch API where it goes unused, and keep Gitea off the open internet without a VPN or authentication proxy.
Source: Cybersecurity News
A threat actor posted a 2.5 GB archive on a cybercrime forum on September 12, claiming it holds 7.49 million records belonging to CenterPoint Energy customers. The listing cites names, contact and billing details, move-in dates, driver's license information, and the last four digits of Social Security numbers, and says the data came from a poorly secured API.
CenterPoint's Form 8-K confirms far less. An unauthorized third party obtained personal information relating to a portion of its customers through an external-facing system. The Houston utility serves around 7 million customers in Texas, Indiana, Minnesota, and Ohio, so the claimed record count exceeds its entire customer base. Nobody has verified the archive.
Gas and electricity delivery are unaffected, and CenterPoint does not expect a material financial impact. The company is still working with outside experts to determine scope, and intends to notify affected customers and regulators. The poster also threatened to move from stealing data to attacking the main infrastructure.
Source: SecurityWeek
A threat actor posted a 2.5 GB archive on a cybercrime forum on September 12, claiming it holds 7.49 million records belonging to CenterPoint Energy customers. The listing cites names, contact and billing details, move-in dates, driver's license information, and the last four digits of Social Security numbers, and says the data came from a poorly secured API.
CenterPoint's Form 8-K confirms far less. An unauthorized third party obtained personal information relating to a portion of its customers through an external-facing system. The Houston utility serves around 7 million customers in Texas, Indiana, Minnesota, and Ohio, so the claimed record count exceeds its entire customer base. Nobody has verified the archive.
Gas and electricity delivery are unaffected, and CenterPoint does not expect a material financial impact. The company is still working with outside experts to determine scope, and intends to notify affected customers and regulators. The poster also threatened to move from stealing data to attacking the main infrastructure.
Source: SecurityWeek
Cisco is warning of a zero-day in its Secure Email Gateway appliances, CVE-2026-76461, rated CVSS 9.8 (Critical) and under active exploitation. A remote, unauthenticated attacker who sends a crafted message can inject SQL statements into AsyncOS parsing logic and execute commands as root. Physical and virtual appliances are affected in any configuration.
Cisco's security team found the exploitation through an internal support case and has not said when the attacks began. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 14 and gave federal agencies until September 17 to patch. Secure Email and Web Manager and Secure Web Appliance are not affected.
No workarounds exist. Update to AsyncOS 16.5.0-780 on the 16.5 branch, 16.0.4-302 on 16.0, or 15.5.5-0141 on 15.5 and earlier. Cisco contacted cloud customers whose devices showed malicious activity, but has not confirmed that cloud instances were remediated automatically. On-premises admins must apply the update themselves.
Source: Cybersecurity News
Cisco is warning of a zero-day in its Secure Email Gateway appliances, CVE-2026-76461, rated CVSS 9.8 (Critical) and under active exploitation. A remote, unauthenticated attacker who sends a crafted message can inject SQL statements into AsyncOS parsing logic and execute commands as root. Physical and virtual appliances are affected in any configuration.
Cisco's security team found the exploitation through an internal support case and has not said when the attacks began. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 14 and gave federal agencies until September 17 to patch. Secure Email and Web Manager and Secure Web Appliance are not affected.
No workarounds exist. Update to AsyncOS 16.5.0-780 on the 16.5 branch, 16.0.4-302 on 16.0, or 15.5.5-0141 on 15.5 and earlier. Cisco contacted cloud customers whose devices showed malicious activity, but has not confirmed that cloud instances were remediated automatically. On-premises admins must apply the update themselves.
Source: Cybersecurity News
Five alleged leaders of Black Axe's South African operations were extradited to the United States on September 11 to face charges tied to romance scams and advance-fee fraud between 2011 and 2021. All five are Nigerian nationals, aged 38 to 57, arrested in South Africa in 2021.
The men appeared before U.S. District Judge Michael A. Shipp in Trenton, New Jersey, on September 14. Perry Osagiede, 57, is named in the indictment as founder and zonal head of Black Axe's Cape Town Zone. Prosecutors say the group used fake identities to trick victims into sending money, and sometimes threatened to release sensitive photos when targets refused.
Maximum penalties reach 62 years, but only for the two defendants charged on all four counts. Wire fraud, wire fraud conspiracy, and money laundering conspiracy each carry up to 20 years, and aggravated identity theft adds a mandatory two. The Justice Department stresses that the indictment contains accusations only and that all five are presumed innocent.
Source: CyberScoop
Five alleged leaders of Black Axe's South African operations were extradited to the United States on September 11 to face charges tied to romance scams and advance-fee fraud between 2011 and 2021. All five are Nigerian nationals, aged 38 to 57, arrested in South Africa in 2021.
The men appeared before U.S. District Judge Michael A. Shipp in Trenton, New Jersey, on September 14. Perry Osagiede, 57, is named in the indictment as founder and zonal head of Black Axe's Cape Town Zone. Prosecutors say the group used fake identities to trick victims into sending money, and sometimes threatened to release sensitive photos when targets refused.
Maximum penalties reach 62 years, but only for the two defendants charged on all four counts. Wire fraud, wire fraud conspiracy, and money laundering conspiracy each carry up to 20 years, and aggravated identity theft adds a mandatory two. The Justice Department stresses that the indictment contains accusations only and that all five are presumed innocent.
Source: CyberScoop
A likely Russian-speaking threat actor used hundreds of AI agents to exploit two PaperCut NG/MF zero-days disclosed on August 27. CVE-2026-82078 allows unsafe dynamic class loading and is rated CVSS 9.4 (Critical); CVE-2026-81578 bypasses authentication at CVSS 8.8 (High). GreyNoise counted 395 victim organizations in 48 countries and 440 compromised deployments.
Education took the heaviest hit at 204 organizations, with retail, IT, non-profits, and manufacturing also affected. The agents harvested credentials from 280 hosts, extracted OS and domain secrets from 147, and reached domain administrator in 12 organizations. Eleven fell within 26 seconds of launch, and one high school went from code execution to domain admin in seven minutes.
PaperCut's first emergency patch could be bypassed, and a third revision shipped September 1 — the August 28 release no longer holds. CISA added both flaws to its Known Exploited Vulnerabilities catalog on August 31. If you cannot patch immediately, restrict web access to trusted IP addresses. Rotate credentials on any server that was exposed.
Source: SecurityWeek
A likely Russian-speaking threat actor used hundreds of AI agents to exploit two PaperCut NG/MF zero-days disclosed on August 27. CVE-2026-82078 allows unsafe dynamic class loading and is rated CVSS 9.4 (Critical); CVE-2026-81578 bypasses authentication at CVSS 8.8 (High). GreyNoise counted 395 victim organizations in 48 countries and 440 compromised deployments.
Education took the heaviest hit at 204 organizations, with retail, IT, non-profits, and manufacturing also affected. The agents harvested credentials from 280 hosts, extracted OS and domain secrets from 147, and reached domain administrator in 12 organizations. Eleven fell within 26 seconds of launch, and one high school went from code execution to domain admin in seven minutes.
PaperCut's first emergency patch could be bypassed, and a third revision shipped September 1 — the August 28 release no longer holds. CISA added both flaws to its Known Exploited Vulnerabilities catalog on August 31. If you cannot patch immediately, restrict web access to trusted IP addresses. Rotate credentials on any server that was exposed.
Source: SecurityWeek