- MikroTrickName given by CERT Polska to the two-flaw combination used in the attacks.
ThreatNoir Weekend Brief — September 6
Afternoon Review in IT Security — September 6, 2026
The cybersecurity landscape continues to shift as threat actors actively exploit both legacy infrastructure vulnerabilities and newly disclosed software flaws. Today's threat intelligence reveals coordinated campaigns targeting critical systems across multiple sectors, from educational institutions to internet-connected networking equipment, alongside the emergence of sophisticated malware modules designed to evade detection and facilitate cryptocurrency theft.
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
MikroTik routers are facing active exploitation through their Secure Shell remote-access service when exposed to the internet, allowing attackers to gain full administrative control without requiring authentication. According to a warning published by CERT Polska on September 5, successful attacks have been documented since at least September 2. Source: The Hacker News
The campaign demonstrates a critical risk for organizations that have exposed administrative interfaces to the public internet without proper access controls. The exploitation of MikroTik devices represents a significant threat to network infrastructure, as compromised routers can be leveraged for lateral movement, traffic interception, and further network compromise.
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic Security Labs has identified four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer that persists on infected systems after the initial stealer component removes itself. The modules, named ProManager, WinUpdate, SoftManager, and LockAppHost, work in concert to disable Windows Update and Microsoft Defender before deploying a cryptocurrency miner. Source: The Hacker News
This discovery reveals the sophisticated post-exploitation capabilities of the REVSTEALER ecosystem. By systematically disabling security mechanisms, the threat actors create an environment where malicious cryptocurrency mining operations can run undetected and uninterrupted. The modular architecture of this malware family suggests ongoing development and refinement of attack techniques.
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
A critical vulnerability tracked as CVE-2026-32475 has been identified in the Elementor Pro WordPress plugin, carrying a CVSS score of 9.8. The flaw is characterized as an arbitrary file upload issue within the form submission handling function and is being actively exploited in the wild. Source: SecurityWeek
The high severity rating and immediate exploitation of this vulnerability underscore the urgency for WordPress administrators to apply patches without delay. Given the widespread adoption of Elementor Pro among website builders, this flaw represents a significant attack surface for threat actors seeking to compromise web properties.
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Threat actors are actively exploiting newly disclosed PaperCut vulnerabilities to conduct credential theft campaigns targeting educational institutions in the United States and Europe. The Arctic Wolf Adversary Research Team has observed attackers leveraging CVE-2026-81578 and CVE-2026-82078, an authentication bypass and remote code execution chain, to execute commands and perform reconnaissance on compromised systems. Source: The Hacker News
The attacks employ tools including lsa_collect_small.exe, lsa_collect.exe, and save_hives.exe to extract credentials from affected systems. The education sector's reliance on PaperCut for print management makes these institutions particularly vulnerable, and the combination of authentication bypass with remote code execution capabilities creates a direct pathway to full system compromise and credential exfiltration.
As September 6 progresses, security teams across all sectors must prioritize vulnerability patching and threat hunting activities to identify and remediate potential compromises. The convergence of infrastructure exploitation, malware sophistication, and targeted attacks on critical software underscores the need for comprehensive security strategies that address both prevention and detection capabilities.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- LockAppHostREVSTEALER-linked module disabling defenses and running crypto miner
- SoftManagerREVSTEALER-linked module turning victim into a reverse proxy
- WinUpdateREVSTEALER-linked module replacing cryptocurrency addresses in clipboard
- ProManagerREVSTEALER-linked module stealing wallet files and logging passwords
- REVSTEALEREmerging Windows information stealer and associated modules
- Arbitrary file upload vulnerability in Elementor Pro
- Authentication bypass vulnerability in PaperCut.
- Remote code execution vulnerability in PaperCut.
- save_hives.exeCredential harvesting tool.
- lsa_collect_small.exeCredential harvesting tool.
- lsa_collect.exeCredential harvesting tool.
194.180.48.134IP address used for retrieving Meterpreter payloads and establishing sessions.45.142.193.132IP address used for delivering credential harvesting tools and requesting data files.