- Cisco Identity Services Engine (ISE) authentication bypass vulnerability
ThreatNoir Weekend Brief — September 19
Morning Review in IT Security — September 19, 2026
September 19, 2026 brings critical security developments across multiple threat vectors, from zero-day vulnerabilities in enterprise infrastructure to ongoing supply chain attacks and nation-state activity targeting job seekers. Organizations face pressure on multiple fronts as public exploits emerge for Linux kernel flaws and WordPress vulnerabilities continue to evolve.
Cisco Zero-Day Highlights API Endpoint Authentication Issues
A critical authentication bypass vulnerability in Cisco's Identity Services Engine (ISE) has been assigned CVE-2026-76460 and received a maximum CVSS score of 10.0 out of 10. The flaw impacts API endpoint authentication mechanisms, making it one of the most severe vulnerabilities affecting Cisco infrastructure. Source: Dark Reading
Happy Birthday, Shai-Hulud
One year has passed since the tinycolor npm package compromise launched what has become the worst year for npm security on record. The original attack introduced a self-propagating worm that harvested credentials using TruffleHog and exfiltrated npm tokens, GitHub credentials, and cloud keys to a public GitHub repository named Shai-Hulud. The worm used stolen npm tokens to inject itself into other packages and republish them, ultimately compromising hundreds of packages within days.
A second major wave arrived in November 2025, moving execution to the pre-install step to widen impact across developer machines and CI pipelines. This iteration added destructive payloads including setup_bun.js and bun_environment.js, along with a fallback mechanism that could attempt to wipe user home directories. Additional waves struck in April 2026 and again at the end of that month, with May 2026 seeing TeamPCP publish the worm's source code publicly and run a contest offering $1,000 in Monero for compromising the most-downloaded packages.
The Australian Federal Police, working with the FBI and Western Australia Police, arrested two alleged TeamPCP members in August 2026, aged 21 and 23. The AFP estimated the group enabled the theft of more than 500,000 credentials and at least 300GB of data, with remediation costs reaching hundreds of millions of dollars across more than a thousand organizations. However, the original September 2025 Shai-Hulud authors remain unidentified, and attribution has become increasingly difficult as the code spread across multiple operators. Source: Socket.dev
International Security Agencies Warn About North Korean Hackers Exploiting Job Seekers
The U.S., Japan, Germany, and Australia have jointly warned about WaterPlum operators who pose as prospective employers to target job seekers. The threat group has infected more than 30,000 devices worldwide through this social engineering approach. The campaign aims to steal cryptocurrency and sensitive data from victims who believe they are engaging with legitimate hiring processes. Source: CyberScoop
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
The Pakistan-aligned threat group Transparent Tribe, also tracked as APT36 and Earth Karkaddan, has launched fresh cyber attacks targeting government and defense entities in India and Afghanistan. The campaign introduces previously undocumented tools including RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH, with malicious infrastructure leveraging domains such as indiatodays[.]org and theprints[.]org. The group's use of private GitHub repositories for command and control communications represents a notable evolution in their operational tradecraft. Source: The Hacker News
Early Scattered Spider Member Pleads Guilty to Cybercrime Spree
Ahmed Elbadawy, an early member of the Scattered Spider threat group, has pleaded guilty to cybercrime charges. Prosecutors are seeking the forfeiture of approximately $17.6 million in virtual currency, luxury vehicles, and an extensive collection of jewelry and designer bags accumulated through his criminal activities. Source: CyberScoop
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
Working exploit code has been released for four Linux kernel vulnerabilities that enable local users to gain root access. The affected CVEs are CVE-2026-68121, CVE-2026-74469, CVE-2026-80844, and CVE-2026-81000. While kernel maintainers have patched all four flaws in recent weeks, systems running older kernel versions remain vulnerable and should be updated immediately. Source: The Hacker News
Researchers Use AI to Find Widespread Software Decoder Flaw
Security researchers have leveraged artificial intelligence techniques to discover a widespread vulnerability in software decoders that has since been patched. The flaw granted attackers remote code execution privileges and access to user accounts and production environments, including Meta's core product suite and an OpenAI software repository. Source: CyberScoop
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
WordPress has released patches addressing a new vulnerability chain called Click2Shell, discovered by security firm pwn.ai. The flaw allows a crafted web link, when opened by a logged-in administrator, to install a theme from the official WordPress.org directory without requiring manual installation confirmation. This capability can be chained to achieve code execution on vulnerable installations. Source: The Hacker News
Today's threat landscape underscores the critical importance of maintaining current patch levels across all infrastructure, from enterprise authentication systems to Linux kernels and content management platforms. Organizations should prioritize credential rotation, supply chain auditing, and user awareness training as attackers continue to exploit both technical vulnerabilities and human trust.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Mini Shai-HuludLater wave of Shai-Hulud worm
- Shai-HuludSelf-propagating npm worm
- Sha1-Hulud: The Second ComingSecond wave of Shai-Hulud worm
hxxps://github[.]com/TeamPCP/Shai-HuludOpen-sourced worm framework by TeamPCP
- WaterPlumName of the North Korean hacking group
- Contagious InterviewAlternative name for the WaterPlum hacking group
- Data from Local System (PSNATCH file exfiltration)
- Obfuscated Files or Information (Implied by encrypted C2)
- Ingress Tool Transfer (Fetching file stealers from GitHub gist)
- Non-Standard Port (Implied by GitHub API usage)
- Phishing: Spearphishing Attachment (Implied by malicious scripts/payloads)
- User Execution: Malicious File (Implied by LNK file execution)
- Application Layer Protocol: HTTP/S (GitHub REST API)
- Remote Access Software (RUSTYSHADE backdoor functionality)
- Application Layer Protocol: DNS (Implied by domain usage)
- Application Layer Protocol: Web Protocols (GitHub API usage for C2)
- Exfiltration Over C2 Channel (GitHub repositories for C2)
- Encrypted Channel: Asymmetric Cryptography (Used in RUSTYSHADE C2)
- Exfiltration Over Alternative Protocol (GitHub REST API)
- Application Layer Protocol (GitHub API)
- Command and Scripting Interpreter: PowerShell (PSNATCH)
- Command and Scripting Interpreter: Unix Shell (BASHNATCH)
- Remote System Discovery (Implied by lateral movement and reconnaissance)
- Network Share Discovery (Implied by lateral movement and file exfiltration)
theprints[.]orgTyposquatted domain impersonating The Print for C2/payload hosting.indiatodays[.]orgTyposquatted domain impersonating India Today for C2/payload hosting.
- PPPoEject Linux kernel vulnerability
- TUNderflow Linux kernel vulnerability
- DiagSpill Linux kernel vulnerability
- DirtyAH6 Linux kernel vulnerability