Weekly review

ThreatNoir Morning Brief — September 10

2026-09-10Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — September 10, 2026

The cybersecurity landscape on September 10, 2026 reflects an intensifying threat environment marked by active exploitation of critical vulnerabilities, sophisticated malware campaigns targeting financial assets, and the emerging risks posed by artificial intelligence in security research. Organizations face simultaneous pressures from nation-state actors, supply chain compromises, and novel attack vectors that underscore the urgency of rapid detection and response capabilities.

Cisco Confirms CVE-2026-20079 Secure FMC Flaw Exploited in Attacks

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. The vulnerability carries a CVSS score of 10.0, indicating critical severity, and represents an immediate threat to organizations relying on Cisco's firewall management infrastructure. Source: Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

The active exploitation of this authentication bypass before widespread vendor awareness highlights a significant gap in vulnerability disclosure and patching cycles. A related vulnerability, CVE-2026-20316, has also been identified in connection with this campaign. Organizations operating Secure FMC deployments should prioritize immediate assessment of their systems and implementation of available security updates to prevent unauthorized access to critical firewall management capabilities.

Malicious Chrome and Firefox Extensions Steal Crypto Traders' Session and Wallet Data

Socket has uncovered a cross-browser extension operation targeting cryptocurrency traders through six malicious extensions linked by shared code, command and control infrastructure, and targeting patterns. Four malicious extensions—J7Tracker and VREO for Chrome, VREO for Firefox, and Orbit Tracker for Firefox—contain identical or nearly identical malicious collection modules that automatically harvest authenticated user information, wallet-related data, Firebase access tokens, and application state from Axiom Trade and Padre users. Source: Malicious Chrome and Firefox Extensions Steal Crypto Traders' Session and Wallet Data

The campaign demonstrates sophisticated tradecraft designed to operate silently within authenticated trading sessions. The malware uses browser navigation to bypass Content Security Policy restrictions and transmit stolen data to threat actor-controlled Vercel and Bonto infrastructure, avoiding detection mechanisms that would flag conventional cross-origin requests. Two earlier extensions, GhostApe and GhostApe Color, represent repackaged derivatives of the MockApe trading extension, indicating a pattern of brandjacking and marketplace abuse. While Chrome extensions were removed in July 2026, Orbit Tracker remains active on Mozilla Add-ons as of publication. The operation targets traders handling substantial cryptocurrency volumes, with Axiom processing more than $15 billion in trading volume across over 650,000 wallets and Padre holding approximately 4–5 percent of Solana's trading-bot market. Organizations and individual traders should revoke affected sessions and authentication tokens, rotate credentials, and review wallet activity for unauthorized transactions.

Chinese Espionage Groups Swarm to Exploit Triple-Link Chain of Zero-Days

Multiple China-aligned threat groups have rapidly exploited a chain of three zero-day vulnerabilities to target various organizations, according to Proofpoint. The vulnerabilities, tracked as CVE-2026-85046, CVE-2026-85880, and CVE-2026-87491, represent a coordinated exploitation pattern typical of state-sponsored actors leveraging newly discovered flaws before patches become available. Source: Chinese espionage groups swarm to exploit triple-link chain of zero-days

Proofpoint indicates that the activity is ongoing and expects the exploitation campaign to widen as additional threat groups gain access to exploit code or vulnerability details. The chaining of multiple zero-days suggests a sophisticated attack infrastructure capable of combining multiple attack vectors to achieve persistent access or lateral movement within targeted networks. Organizations should maintain heightened vigilance for indicators of compromise associated with these vulnerabilities and consider implementing compensating controls pending the availability of security updates.

AI Models Exploit Weak Passwords and Misconfigurations to Breach Real Organizations

Frontier AI models have demonstrated the ability to identify thousands of previously unknown vulnerabilities across major operating systems and browsers, with Claude Mythos Preview discovering flaws including a 27-year-old denial-of-service condition in OpenBSD. The research conducted by Anthropic and Project Glasswing partners in April 2026 raised critical questions about AI-assisted vulnerability discovery and its dual-use implications. Source: The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords

The concerning follow-up finding reveals that these same AI models successfully exploited weak passwords and security misconfigurations to breach three real organizations, demonstrating that the vulnerability discovery capability extends to practical exploitation. The discovery of a certificate forgery flaw in wolfSSL exemplifies the breadth of vulnerabilities now accessible to AI-assisted threat actors. This development signals a fundamental shift in the threat landscape where artificial intelligence accelerates both defensive security research and offensive attack capabilities, requiring organizations to prioritize fundamental security hygiene including strong credential management and proper configuration hardening.

The September 10 threat landscape demands immediate organizational action across multiple fronts: patching critical infrastructure vulnerabilities, securing cryptocurrency trading environments, monitoring for state-sponsored exploitation activity, and addressing fundamental security weaknesses that AI-assisted attackers can readily exploit.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data
Domain4
  • cloudflare[.]bonto[.]run
    C2 domain for Orbit Tracker
  • dcfdc-eight[.]vercel[.]app
    C2 domain for J7Tracker/VREO
  • snipex-iota[.]vercel[.]app
    C2 domain for J7Tracker/VREO
  • susi[.]bonto[.]run
    C2 domain for Orbit Tracker
URL3
  • hxxps://susi[[.]]bonto[[.]]run/collect?d=
    C2 infrastructure for Orbit Tracker
  • hxxps://dcfdc-eight[[.]]vercel[[.]]app/api/collect?d=
    C2 infrastructure for J7Tracker/VREO
  • hxxps://snipex-iota[[.]]vercel[[.]]app/api/code/
    C2 infrastructure for J7Tracker/VREO
Email1
  • z1417699[@]gmail[.]com
    VREO Chrome Web Store developer email
SHA-2561
  • 5b4fbe0658ff…
    Malicious module vamp/axiom-fetch-intercept.js