Weekly review

ThreatNoir Afternoon Brief — September 18

2026-09-18Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — September 18, 2026

The threat landscape continues to evolve with multiple critical vulnerabilities and active exploitation campaigns emerging today. Organizations face urgent patching demands across infrastructure management platforms, open-source repositories, and supply chain dependencies, while nation-state actors demonstrate renewed interest in harvesting sensitive data through malware distribution channels.

New Check Point Flaw Lets Hackers Execute Code with Root Privileges

Check Point Software has released security updates to address a critical vulnerability that enables attackers to execute code with root privileges on management systems. The vulnerability affects the company's security infrastructure and poses a significant risk to organizations relying on Check Point for network protection. Source: New Check Point flaw lets hackers execute code with root privileges

Five distinct CVE identifiers have been assigned to related flaws in this disclosure: CVE-2026-16232, CVE-2026-50751, CVE-2026-85102, CVE-2026-85103, and CVE-2026-91843. The root privilege execution capability represents an escalated threat vector, as successful exploitation could grant attackers complete control over Check Point management infrastructure. Organizations operating Check Point solutions should prioritize immediate patching to mitigate this critical risk.

Critical Orkes Conductor Vulnerability Exploited in Attacks

CVE-2026-58138 represents an unauthenticated remote code execution vulnerability in Orkes Conductor that attackers are actively exploiting in the wild. The flaw can be leveraged through inline workflow definitions, allowing threat actors to execute arbitrary code without requiring authentication credentials. Source: Critical Orkes Conductor Vulnerability Exploited in Attacks

The active exploitation of this vulnerability underscores the urgency of patching efforts for organizations using Orkes Conductor in their environments. The unauthenticated nature of the attack vector means that any internet-facing instance remains vulnerable to compromise without proper security updates.

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

Cybersecurity researchers have discovered a cluster of 13 npm packages delivering a previously undocumented JavaScript stealer malware family designated WeaselBiscuit. The malware exhibits functional overlaps with BeaverTail and other strains associated with the Democratic People's Republic of Korea's Contagious Interview campaign. Source: WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

WeaselBiscuit specifically targets Chrome extension storage, indicating a focused effort to harvest sensitive data from browser-based applications and credentials. The malware communicates with infrastructure including api.ipify.org, ip-api.com, npoint.io, and the IP address 103.170.217.184. Developers and organizations should audit their npm dependencies immediately to identify and remove any of the 13 compromised packages from their supply chains.

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

A supply chain attack leveraging a compromised API key from Brevo has resulted in malicious script injection affecting approximately 100,000 websites. Threat actors deployed a Cloudflare worker to distribute the ClickFix malware across the affected sites. Source: Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

This incident demonstrates the cascading risk inherent in supply chain compromises, where a single compromised credential can amplify attack surface across thousands of downstream organizations. The use of a legitimate platform's infrastructure to distribute malware highlights the sophistication of modern supply chain attack techniques and the importance of API key rotation and access control policies.

The convergence of these threats—from infrastructure vulnerabilities to open-source compromises and supply chain attacks—reinforces the critical need for comprehensive security monitoring, rapid patching protocols, and supply chain visibility across all organizational systems.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).