- Previously added Artifactory vulnerability used in chaining attacks
- JFrog Artifactory incorrect authorization vulnerability
- JFrog Artifactory improper authentication vulnerability
- ConnectWise ScreenConnect improper privilege management and missing authorization vulnerability
- MikroTik RouterOS missing authentication for critical function vulnerability
- MikroTik RouterOS improper neutralization of argument delimiters in a command vulnerability
ThreatNoir Weekend Brief — September 13
Morning Review in IT Security — September 13, 2026
The cybersecurity landscape continues to face mounting pressure as critical vulnerabilities across enterprise infrastructure, VPN systems, and development tools are actively exploited in the wild. Today's briefing covers urgent threats spanning government warnings, exploit kit deployments, and AI model abuse by state-sponsored actors.
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency has added five security flaws to its Known Exploited Vulnerabilities catalog following confirmed active exploitation. The vulnerabilities impact widely deployed software including JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. CVE-2026-42016 carries a CVSS score of 8.1 and involves incorrect authorization, representing a significant risk to supply chain integrity and network infrastructure. The inclusion of these flaws in CISA's KEV catalog signals immediate exploitation risk and underscores the need for rapid patching across affected organizations.
Source: CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
Dutch NCSC: Critical Check Point VPN Flaws Exploitation is Imminent
The Dutch Nationaal Cyber Security Centrum has issued a warning regarding imminent exploitation of two critical vulnerabilities in Check Point VPN systems. The flaws, tracked as CVE-2026-85102 and CVE-2026-85103, pose immediate risk to organizations relying on Check Point infrastructure for remote access and network security. The NCSC's assessment of imminent exploitation indicates active threat actor preparation and reconnaissance, making immediate patching a critical priority for affected organizations.
Source: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
The BlueMoon exploit kit has been adopted by multiple espionage-motivated threat actors in opportunistic deployments that chain recent Chrome and Windows zero-day vulnerabilities. The kit's ability to combine CVE-2026-85046, CVE-2026-85880, and CVE-2026-87491 demonstrates the rapid weaponization of zero-day flaws for targeted campaigns. The rushed nature of these deployments suggests threat actors are prioritizing speed and operational effectiveness over stealth, indicating heightened competitive pressure within the espionage-focused threat actor community.
Source: BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
Hackers Abused Claude to Extract Secrets from 1.8M Android Apps
Anthropic has disclosed that multiple threat groups, including financially motivated and state-sponsored actors linked to Russia and China, attempted to abuse its Claude AI model for malicious purposes. These threat actors leveraged Claude to extract hardcoded secrets and sensitive information from approximately 1.8 million Android applications at scale. The abuse of AI models for reconnaissance and secret extraction represents an emerging attack vector that combines artificial intelligence capabilities with traditional supply chain targeting, highlighting the need for enhanced security controls around AI model access and output monitoring.
Source: Hackers abused Claude to extract secrets from 1.8M Android apps
Today's threat landscape reflects a convergence of supply chain vulnerabilities, infrastructure weaknesses, and emerging AI-powered attack techniques. Organizations must prioritize patching of known exploited flaws while maintaining vigilance against zero-day exploitation and AI-assisted reconnaissance activities.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Improper validation of certificate data during VPN negotiation
- Heap overflow in VPN certificate ASN.1 decoder
- Chrome zero-day impacting V8 JavaScript and WebAssembly engine.
- Chrome zero-day impacting V8 JavaScript and WebAssembly engine.
- Windows zero-day, privilege escalation in ALPC.
policenationale[.]ccCarding shop impersonating French national police