Weekly review

ThreatNoir Morning Brief — September 18

2026-09-18Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — September 18, 2026

The threat landscape continues to intensify as critical vulnerabilities emerge across multiple platforms and supply-chain attacks demonstrate evolving sophistication. Today's security briefing covers urgent zero-day disclosures, infrastructure compromises affecting downstream customers, and emerging malware capabilities powered by artificial intelligence.

Cisco Alerts Customers to Second Actively Exploited Zero-Day in as Many Days

Cisco has disclosed a second actively exploited zero-day vulnerability affecting its Identity Services Engine platform, carrying a maximum-severity rating. The vulnerability joins three other actively exploited flaws in the same product since June 2025, indicating a persistent targeting pattern against this critical authentication infrastructure component. The newly disclosed vulnerabilities include CVE-2025-20281, CVE-2025-20337, CVE-2026-76460, and CVE-2026-76461. Source: Cisco alerts customers to second actively exploited zero-day in as many days

Organizations running Cisco ISE should prioritize immediate patching and enhanced monitoring of authentication systems. The repeated targeting of this platform underscores the value attackers place on compromising identity services, which serve as gateways to broader network access.

Brevo Supply-Chain Attack Injected ClickFix Scripts on Customer Sites

Brevo confirmed a significant supply-chain attack in which threat actors stole a Cloudflare API key and leveraged it to inject malicious ClickFix scripts into the company's websites and JavaScript files embedded on customer sites. The attack enabled distribution of malware to downstream users relying on Brevo's services and third-party integrations. The compromised infrastructure delivered malicious payloads through multiple malicious domains including boiseno[.]club, cdn10.sendibt1[.]com/p/wm.zip, corralos[.]beer/a412dkoq.js, glegchner.com/ads.php, and yelahaye[.]surf. Source: Brevo supply-chain attack injected ClickFix scripts on customer sites

This incident demonstrates the cascading risk inherent in cloud service provider compromises. By obtaining a Cloudflare API key, attackers gained the ability to manipulate content delivery at scale, affecting not only Brevo's direct customers but also any organization consuming JavaScript resources through Brevo's infrastructure. Organizations should audit their third-party dependencies and implement content security policies to mitigate similar attacks.

PolinRider Spreads Through Compromised GitHub Accounts and Packagist

The PolinRider campaign continues its persistent expansion across multiple package ecosystems, with researchers identifying malicious code in the dev-main version of visanduma/nova-two-factor, a Packagist package with over 700,000 cumulative downloads. The campaign demonstrates a sophisticated approach to supply-chain compromise by prioritizing Git repository access over rapid package distribution, allowing operators to maintain persistent footholds across developer environments and private projects. Source: PolinRider Spreads Through Compromised GitHub Accounts and Packagist

PolinRider's operational model differs fundamentally from conventional supply-chain attacks. Rather than publishing malicious stable releases to reach maximum downstream users, the campaign uses compromised developer accounts to inject malicious code directly into source repositories, employing techniques including Git history rewriting, payload concealment in configuration files and font files, and automatic execution through IDE triggers. The malware uses staged payload delivery mechanisms with dead-drop resolvers to fetch information-stealing payloads, with apparent primary objectives centered on cryptocurrency theft and credential harvesting. Affected packages include visanduma/nova-two-factor@dev-nova4support, visanduma/nova-two-factor@dev-main, visanduma/nova-two-factor@dev-using-inertia, and visanduma/nova-two-factor@dev-nova5. Associated indicators include resolved command-and-control IP addresses 193[.]247[.]144[.]38, 166[.]88[.]73[.]46, 166[.]88[.]134[.]62, and 23[.]27[.]13[.]135, along with multiple SHA256 file hashes of payload files. Organizations should audit repository history for force-push events, inspect automatic execution paths in VS Code configuration, treat any developer system exposure as a potential host compromise, and rotate all accessible credentials including GitHub tokens and cloud keys.

New RatHat Android Malware Uses AI to Automate Device Control

Security researchers have identified RatHat, a newly discovered Android malware family that incorporates artificial intelligence capabilities to automate remote device control and navigation of compromised handsets. The malware represents an evolution in mobile threat sophistication by combining traditional remote access trojan functionality with AI-driven automation. Source: New RatHat Android malware uses AI to automate device control

RatHat's integration of AI subsystems enables threat operators to remotely control Android devices with reduced manual intervention, potentially streamlining the exploitation of accessibility permissions and other elevated device capabilities. The emergence of AI-enhanced malware on mobile platforms signals a concerning trend toward more autonomous and adaptive threats that can respond dynamically to device configurations and user behavior.

As threats continue to evolve across infrastructure, supply chains, and mobile platforms, security teams must maintain elevated vigilance regarding zero-day disclosures, third-party dependency risks, and emerging malware capabilities that leverage advanced technologies. The combination of persistent zero-day exploitation, supply-chain compromises affecting downstream customers, and AI-enhanced mobile malware underscores the need for defense-in-depth strategies spanning vulnerability management, software composition analysis, and endpoint detection capabilities.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Brevo supply-chain attack injected ClickFix scripts on customer sites
URL5
  • hxxps://yelahaye[[.]]surf
    Domain distributing the malicious WordPress plugin and scripts.
  • hxxps://cdn10[.]sendibt1[[.]]com/p/wm[.]zip
    URL for a malicious WordPress plugin distributed via the attack.
  • hxxps://boiseno[[.]]club
    Domain distributing the malicious WordPress plugin and scripts.
  • hxxps://glegchner[.]com/ads[.]php
    Attacker-controlled server contacted by the malicious WordPress plugin.
  • hxxps://corralos[[.]]beer/a412dkoq[.]js
    JavaScript fetched by the plugin to display ClickFix lures.
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
IP Address4
  • 166.88.134.62
    Resolved C2 IP Address
  • 166.88.73.46
    Resolved C2 IP Address
  • 193.247.144.38
    Resolved C2 IP Address
  • 23.27.13.135
    Resolved C2 IP Address
SHA-2565
  • 139ea03dcddf…
    Payload file: tailwind.config.js
  • ccb187dc9de0…
    Payload file: tailwind.config.js
  • b7ede935d497…
    Payload file: tailwind.config.js
  • 515a53291d25…
    Payload file: tailwind.config.js
  • 7d47c430e6e4…
    Payload file: tailwind.config.js