- Authentication bypass zero-day exploited for administrator privileges.
- Authentication bypass zero-day exploited by Qilin ransomware affiliate.
- Critical vulnerability in Check Point management systems.
- Critical RCE flaw in Check Point VPN certificate ASN.1 decoding.
- Critical authentication bypass and RCE flaw in Check Point firewalls.
ThreatNoir Afternoon Brief — September 18
Afternoon Review in IT Security — September 18, 2026
The threat landscape continues to evolve with multiple critical vulnerabilities and active exploitation campaigns emerging today. Organizations face urgent patching demands across infrastructure management platforms, open-source repositories, and supply chain dependencies, while nation-state actors demonstrate renewed interest in harvesting sensitive data through malware distribution channels.
New Check Point Flaw Lets Hackers Execute Code with Root Privileges
Check Point Software has released security updates to address a critical vulnerability that enables attackers to execute code with root privileges on management systems. The vulnerability affects the company's security infrastructure and poses a significant risk to organizations relying on Check Point for network protection. Source: New Check Point flaw lets hackers execute code with root privileges
Five distinct CVE identifiers have been assigned to related flaws in this disclosure: CVE-2026-16232, CVE-2026-50751, CVE-2026-85102, CVE-2026-85103, and CVE-2026-91843. The root privilege execution capability represents an escalated threat vector, as successful exploitation could grant attackers complete control over Check Point management infrastructure. Organizations operating Check Point solutions should prioritize immediate patching to mitigate this critical risk.
Critical Orkes Conductor Vulnerability Exploited in Attacks
CVE-2026-58138 represents an unauthenticated remote code execution vulnerability in Orkes Conductor that attackers are actively exploiting in the wild. The flaw can be leveraged through inline workflow definitions, allowing threat actors to execute arbitrary code without requiring authentication credentials. Source: Critical Orkes Conductor Vulnerability Exploited in Attacks
The active exploitation of this vulnerability underscores the urgency of patching efforts for organizations using Orkes Conductor in their environments. The unauthenticated nature of the attack vector means that any internet-facing instance remains vulnerable to compromise without proper security updates.
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Cybersecurity researchers have discovered a cluster of 13 npm packages delivering a previously undocumented JavaScript stealer malware family designated WeaselBiscuit. The malware exhibits functional overlaps with BeaverTail and other strains associated with the Democratic People's Republic of Korea's Contagious Interview campaign. Source: WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
WeaselBiscuit specifically targets Chrome extension storage, indicating a focused effort to harvest sensitive data from browser-based applications and credentials. The malware communicates with infrastructure including api.ipify.org, ip-api.com, npoint.io, and the IP address 103.170.217.184. Developers and organizations should audit their npm dependencies immediately to identify and remove any of the 13 compromised packages from their supply chains.
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
A supply chain attack leveraging a compromised API key from Brevo has resulted in malicious script injection affecting approximately 100,000 websites. Threat actors deployed a Cloudflare worker to distribute the ClickFix malware across the affected sites. Source: Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
This incident demonstrates the cascading risk inherent in supply chain compromises, where a single compromised credential can amplify attack surface across thousands of downstream organizations. The use of a legitimate platform's infrastructure to distribute malware highlights the sophistication of modern supply chain attack techniques and the importance of API key rotation and access control policies.
The convergence of these threats—from infrastructure vulnerabilities to open-source compromises and supply chain attacks—reinforces the critical need for comprehensive security monitoring, rapid patching protocols, and supply chain visibility across all organizational systems.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Critical unauthenticated remote code execution vulnerability in Orkes Conductor
103.170.217.184Command-and-control (C2) server IP address
api.ipify.orgUsed for public IP and geolocation lookupip-api.comUsed for public IP and geolocation lookupnpoint.ioUsed for dead drop and C2 configuration
- ClickFixName of the social-engineering technique used to trick users into running malicious commands.