Weekly review

ThreatNoir Weekend Brief — September 19

2026-09-19Morning8 articles
Audio
Listen to the episode

Morning Review in IT Security — September 19, 2026

September 19, 2026 brings critical security developments across multiple threat vectors, from zero-day vulnerabilities in enterprise infrastructure to ongoing supply chain attacks and nation-state activity targeting job seekers. Organizations face pressure on multiple fronts as public exploits emerge for Linux kernel flaws and WordPress vulnerabilities continue to evolve.

Cisco Zero-Day Highlights API Endpoint Authentication Issues

A critical authentication bypass vulnerability in Cisco's Identity Services Engine (ISE) has been assigned CVE-2026-76460 and received a maximum CVSS score of 10.0 out of 10. The flaw impacts API endpoint authentication mechanisms, making it one of the most severe vulnerabilities affecting Cisco infrastructure. Source: Dark Reading

Happy Birthday, Shai-Hulud

One year has passed since the tinycolor npm package compromise launched what has become the worst year for npm security on record. The original attack introduced a self-propagating worm that harvested credentials using TruffleHog and exfiltrated npm tokens, GitHub credentials, and cloud keys to a public GitHub repository named Shai-Hulud. The worm used stolen npm tokens to inject itself into other packages and republish them, ultimately compromising hundreds of packages within days.

A second major wave arrived in November 2025, moving execution to the pre-install step to widen impact across developer machines and CI pipelines. This iteration added destructive payloads including setup_bun.js and bun_environment.js, along with a fallback mechanism that could attempt to wipe user home directories. Additional waves struck in April 2026 and again at the end of that month, with May 2026 seeing TeamPCP publish the worm's source code publicly and run a contest offering $1,000 in Monero for compromising the most-downloaded packages.

The Australian Federal Police, working with the FBI and Western Australia Police, arrested two alleged TeamPCP members in August 2026, aged 21 and 23. The AFP estimated the group enabled the theft of more than 500,000 credentials and at least 300GB of data, with remediation costs reaching hundreds of millions of dollars across more than a thousand organizations. However, the original September 2025 Shai-Hulud authors remain unidentified, and attribution has become increasingly difficult as the code spread across multiple operators. Source: Socket.dev

International Security Agencies Warn About North Korean Hackers Exploiting Job Seekers

The U.S., Japan, Germany, and Australia have jointly warned about WaterPlum operators who pose as prospective employers to target job seekers. The threat group has infected more than 30,000 devices worldwide through this social engineering approach. The campaign aims to steal cryptocurrency and sensitive data from victims who believe they are engaging with legitimate hiring processes. Source: CyberScoop

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

The Pakistan-aligned threat group Transparent Tribe, also tracked as APT36 and Earth Karkaddan, has launched fresh cyber attacks targeting government and defense entities in India and Afghanistan. The campaign introduces previously undocumented tools including RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH, with malicious infrastructure leveraging domains such as indiatodays[.]org and theprints[.]org. The group's use of private GitHub repositories for command and control communications represents a notable evolution in their operational tradecraft. Source: The Hacker News

Early Scattered Spider Member Pleads Guilty to Cybercrime Spree

Ahmed Elbadawy, an early member of the Scattered Spider threat group, has pleaded guilty to cybercrime charges. Prosecutors are seeking the forfeiture of approximately $17.6 million in virtual currency, luxury vehicles, and an extensive collection of jewelry and designer bags accumulated through his criminal activities. Source: CyberScoop

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

Working exploit code has been released for four Linux kernel vulnerabilities that enable local users to gain root access. The affected CVEs are CVE-2026-68121, CVE-2026-74469, CVE-2026-80844, and CVE-2026-81000. While kernel maintainers have patched all four flaws in recent weeks, systems running older kernel versions remain vulnerable and should be updated immediately. Source: The Hacker News

Researchers Use AI to Find Widespread Software Decoder Flaw

Security researchers have leveraged artificial intelligence techniques to discover a widespread vulnerability in software decoders that has since been patched. The flaw granted attackers remote code execution privileges and access to user accounts and production environments, including Meta's core product suite and an OpenAI software repository. Source: CyberScoop

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

WordPress has released patches addressing a new vulnerability chain called Click2Shell, discovered by security firm pwn.ai. The flaw allows a crafted web link, when opened by a logged-in administrator, to install a theme from the official WordPress.org directory without requiring manual installation confirmation. This capability can be chained to achieve code execution on vulnerable installations. Source: The Hacker News

Today's threat landscape underscores the critical importance of maintaining current patch levels across all infrastructure, from enterprise authentication systems to Linux kernels and content management platforms. Organizations should prioritize credential rotation, supply chain auditing, and user awareness training as attackers continue to exploit both technical vulnerabilities and human trust.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Happy Birthday, Shai-Hulud
Malware3
  • Mini Shai-Hulud
    Later wave of Shai-Hulud worm
  • Shai-Hulud
    Self-propagating npm worm
  • Sha1-Hulud: The Second Coming
    Second wave of Shai-Hulud worm
URL1
  • hxxps://github[.]com/TeamPCP/Shai-Hulud
    Open-sourced worm framework by TeamPCP
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
MITRE ATT&CK18
  • Data from Local System (PSNATCH file exfiltration)
  • Obfuscated Files or Information (Implied by encrypted C2)
  • Ingress Tool Transfer (Fetching file stealers from GitHub gist)
  • Non-Standard Port (Implied by GitHub API usage)
  • Phishing: Spearphishing Attachment (Implied by malicious scripts/payloads)
  • User Execution: Malicious File (Implied by LNK file execution)
  • Application Layer Protocol: HTTP/S (GitHub REST API)
  • Remote Access Software (RUSTYSHADE backdoor functionality)
  • Application Layer Protocol: DNS (Implied by domain usage)
  • Application Layer Protocol: Web Protocols (GitHub API usage for C2)
  • Exfiltration Over C2 Channel (GitHub repositories for C2)
  • Encrypted Channel: Asymmetric Cryptography (Used in RUSTYSHADE C2)
  • Exfiltration Over Alternative Protocol (GitHub REST API)
  • Application Layer Protocol (GitHub API)
  • Command and Scripting Interpreter: PowerShell (PSNATCH)
  • Command and Scripting Interpreter: Unix Shell (BASHNATCH)
  • Remote System Discovery (Implied by lateral movement and reconnaissance)
  • Network Share Discovery (Implied by lateral movement and file exfiltration)
Domain2
  • theprints[.]org
    Typosquatted domain impersonating The Print for C2/payload hosting.
  • indiatodays[.]org
    Typosquatted domain impersonating India Today for C2/payload hosting.