- Actively exploited zero-day vulnerability in Cisco Secure Email Gateway
- Previously exploited vulnerability in Cisco Identity Services Engine
- Previously exploited vulnerability in Cisco Identity Services Engine
- Actively exploited zero-day vulnerability in Cisco Identity Services Engine
ThreatNoir Morning Brief — September 18
Morning Review in IT Security — September 18, 2026
The threat landscape continues to intensify as critical vulnerabilities emerge across multiple platforms and supply-chain attacks demonstrate evolving sophistication. Today's security briefing covers urgent zero-day disclosures, infrastructure compromises affecting downstream customers, and emerging malware capabilities powered by artificial intelligence.
Cisco Alerts Customers to Second Actively Exploited Zero-Day in as Many Days
Cisco has disclosed a second actively exploited zero-day vulnerability affecting its Identity Services Engine platform, carrying a maximum-severity rating. The vulnerability joins three other actively exploited flaws in the same product since June 2025, indicating a persistent targeting pattern against this critical authentication infrastructure component. The newly disclosed vulnerabilities include CVE-2025-20281, CVE-2025-20337, CVE-2026-76460, and CVE-2026-76461. Source: Cisco alerts customers to second actively exploited zero-day in as many days
Organizations running Cisco ISE should prioritize immediate patching and enhanced monitoring of authentication systems. The repeated targeting of this platform underscores the value attackers place on compromising identity services, which serve as gateways to broader network access.
Brevo Supply-Chain Attack Injected ClickFix Scripts on Customer Sites
Brevo confirmed a significant supply-chain attack in which threat actors stole a Cloudflare API key and leveraged it to inject malicious ClickFix scripts into the company's websites and JavaScript files embedded on customer sites. The attack enabled distribution of malware to downstream users relying on Brevo's services and third-party integrations. The compromised infrastructure delivered malicious payloads through multiple malicious domains including boiseno[.]club, cdn10.sendibt1[.]com/p/wm.zip, corralos[.]beer/a412dkoq.js, glegchner.com/ads.php, and yelahaye[.]surf. Source: Brevo supply-chain attack injected ClickFix scripts on customer sites
This incident demonstrates the cascading risk inherent in cloud service provider compromises. By obtaining a Cloudflare API key, attackers gained the ability to manipulate content delivery at scale, affecting not only Brevo's direct customers but also any organization consuming JavaScript resources through Brevo's infrastructure. Organizations should audit their third-party dependencies and implement content security policies to mitigate similar attacks.
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
The PolinRider campaign continues its persistent expansion across multiple package ecosystems, with researchers identifying malicious code in the dev-main version of visanduma/nova-two-factor, a Packagist package with over 700,000 cumulative downloads. The campaign demonstrates a sophisticated approach to supply-chain compromise by prioritizing Git repository access over rapid package distribution, allowing operators to maintain persistent footholds across developer environments and private projects. Source: PolinRider Spreads Through Compromised GitHub Accounts and Packagist
PolinRider's operational model differs fundamentally from conventional supply-chain attacks. Rather than publishing malicious stable releases to reach maximum downstream users, the campaign uses compromised developer accounts to inject malicious code directly into source repositories, employing techniques including Git history rewriting, payload concealment in configuration files and font files, and automatic execution through IDE triggers. The malware uses staged payload delivery mechanisms with dead-drop resolvers to fetch information-stealing payloads, with apparent primary objectives centered on cryptocurrency theft and credential harvesting. Affected packages include visanduma/nova-two-factor@dev-nova4support, visanduma/nova-two-factor@dev-main, visanduma/nova-two-factor@dev-using-inertia, and visanduma/nova-two-factor@dev-nova5. Associated indicators include resolved command-and-control IP addresses 193[.]247[.]144[.]38, 166[.]88[.]73[.]46, 166[.]88[.]134[.]62, and 23[.]27[.]13[.]135, along with multiple SHA256 file hashes of payload files. Organizations should audit repository history for force-push events, inspect automatic execution paths in VS Code configuration, treat any developer system exposure as a potential host compromise, and rotate all accessible credentials including GitHub tokens and cloud keys.
New RatHat Android Malware Uses AI to Automate Device Control
Security researchers have identified RatHat, a newly discovered Android malware family that incorporates artificial intelligence capabilities to automate remote device control and navigation of compromised handsets. The malware represents an evolution in mobile threat sophistication by combining traditional remote access trojan functionality with AI-driven automation. Source: New RatHat Android malware uses AI to automate device control
RatHat's integration of AI subsystems enables threat operators to remotely control Android devices with reduced manual intervention, potentially streamlining the exploitation of accessibility permissions and other elevated device capabilities. The emergence of AI-enhanced malware on mobile platforms signals a concerning trend toward more autonomous and adaptive threats that can respond dynamically to device configurations and user behavior.
As threats continue to evolve across infrastructure, supply chains, and mobile platforms, security teams must maintain elevated vigilance regarding zero-day disclosures, third-party dependency risks, and emerging malware capabilities that leverage advanced technologies. The combination of persistent zero-day exploitation, supply-chain compromises affecting downstream customers, and AI-enhanced mobile malware underscores the need for defense-in-depth strategies spanning vulnerability management, software composition analysis, and endpoint detection capabilities.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
hxxps://yelahaye[[.]]surfDomain distributing the malicious WordPress plugin and scripts.hxxps://cdn10[.]sendibt1[[.]]com/p/wm[.]zipURL for a malicious WordPress plugin distributed via the attack.hxxps://boiseno[[.]]clubDomain distributing the malicious WordPress plugin and scripts.hxxps://glegchner[.]com/ads[.]phpAttacker-controlled server contacted by the malicious WordPress plugin.hxxps://corralos[[.]]beer/a412dkoq[.]jsJavaScript fetched by the plugin to display ClickFix lures.
166.88.134.62Resolved C2 IP Address166.88.73.46Resolved C2 IP Address193.247.144.38Resolved C2 IP Address23.27.13.135Resolved C2 IP Address
139ea03dcddf…Payload file: tailwind.config.jsccb187dc9de0…Payload file: tailwind.config.jsb7ede935d497…Payload file: tailwind.config.js515a53291d25…Payload file: tailwind.config.js7d47c430e6e4…Payload file: tailwind.config.js
- ToxicPandaPreviously observed Android malware family with similar mechanisms.
- RedHookPreviously observed Android malware family with similar mechanisms.
- RatHatName of the new Android malware family.