- Cisco Identity Services Engine (ISE) authentication bypass vulnerability
ThreatNoir Weekend Brief — September 20
Afternoon Review in IT Security — September 20, 2026
The threat landscape continues to evolve across multiple fronts on September 20, 2026, with critical vulnerabilities in enterprise infrastructure, persistent supply chain attacks reaching their one-year anniversary, nation-state actors targeting job seekers, and advanced persistent threat groups deploying novel backdoors. Today's review covers four significant developments affecting organizations worldwide.
Cisco Zero-Day Highlights API Endpoint Authentication Issues
Source: Cisco Zero-Day Highlights API Endpoint Authentication Issues
A critical authentication bypass vulnerability has been discovered in Cisco's Identity Services Engine (ISE) platform, tracked as CVE-2026-76460 and assigned a maximum severity rating of 10.0 on the CVSS scale. The flaw impacts API endpoint authentication mechanisms, creating substantial risk for organizations relying on Cisco ISE for identity and access management. Source: Dark Reading
The maximum CVSS score underscores the severity of this vulnerability and its potential for widespread exploitation. Organizations deploying Cisco ISE should prioritize assessment and patching efforts immediately.
Happy Birthday, Shai-Hulud
September 2025 marked the beginning of what has become the worst year for npm ecosystem security on record, initiated by a malicious version of the @ctrl/tinycolor package that introduced the first known self-propagating worm into the npm supply chain. The original attack harvested credentials using TruffleHog, a legitimate secret scanner, and exfiltrated npm tokens, GitHub credentials, and cloud keys to a hardcoded webhook and a public GitHub repository named Shai-Hulud after the sandworms in Dune. Within days, the worm had spread across dozens of packages and infiltrated CrowdStrike's npm namespace through stolen credentials. Source: Socket.dev
The worm's evolution continued through multiple waves across 2026. A second wave arrived in November 2025, branded "Sha1-Hulud: The Second Coming," which shifted execution to the pre-install step to expand its reach across developer machines and CI pipelines while adding destructive capabilities including potential home directory wiping. Additional waves emerged in April 2026 ("The Third Coming") and late April ("Mini Shai-Hulud"), with a particularly aggressive burst in May pushing over 400 malicious versions across 172 packages in five hours by hijacking short-lived OIDC tokens from CI systems.
The threat evolved further when TeamPCP published the worm's source code on GitHub in May 2026 and launched a contest offering $1,000 in Monero to compromise the most-downloaded packages. This action removed the final barrier to entry for lower-tier actors and democratized the attack technique. On August 26, 2026, the Australian Federal Police arrested two men aged 21 and 23 in Western Australia in connection with TeamPCP, with the FBI and Western Australia Police assisting. The AFP estimated the group enabled the theft of over 500,000 credentials and at least 300GB of data, with remediation costs reaching hundreds of millions of dollars across more than a thousand organizations. Google disclosed it had maintained an undercover analyst within TeamPCP for much of the group's operational period, allowing it to revoke stolen credentials before exploitation. The original authors of the September 2025 Shai-Hulud attack remain unattributed, and with the code now public and widely forked, attribution becomes increasingly difficult as the worm framework spreads across the threat landscape.
International Security Agencies Warn About North Korean Hackers Exploiting Job Seekers
A coordinated warning from the United States, Japan, Germany, and Australia has exposed a North Korean threat operation targeting job seekers worldwide. The WaterPlum group, also known by the campaign name Contagious Interview, has infected more than 30,000 devices globally by posing as prospective employers and delivering malware designed to steal cryptocurrency and sensitive data. Source: CyberScoop
The campaign exploits the trust inherent in employment recruitment processes, leveraging social engineering to deliver malware payloads to unsuspecting job applicants. This represents a significant shift in targeting methodology, as threat actors increasingly focus on individuals during vulnerable moments in their career transitions.
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
The Pakistan-aligned threat group Transparent Tribe, tracked under aliases APT36 and Earth Karkaddan, has launched fresh cyber attacks against government and defense entities in India and Afghanistan utilizing previously undocumented tools. The campaign, attributed by Zscaler ThreatLabz, introduces new malware families including RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH, with the operation leveraging private GitHub repositories for command and control communications. Source: The Hacker News
The use of private GitHub repositories for C2 infrastructure represents an evolution in operational security tradecraft, allowing threat actors to blend malicious traffic with legitimate cloud service communications. The deployment of Rust-based backdoors demonstrates the group's continued investment in modern development practices and evasion techniques.
Closing Perspective
Today's threat landscape reflects the maturation of both state-sponsored and criminal operations across infrastructure, supply chains, and social engineering vectors. Organizations must prioritize patching critical vulnerabilities, implementing robust dependency management practices, and educating personnel about recruitment-based social engineering schemes while monitoring for indicators of compromise from advanced persistent threat groups operating across multiple geographic regions.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Shai-HuludSelf-propagating npm worm
- Sha1-Hulud: The Second ComingSecond wave of Shai-Hulud worm
- Mini Shai-HuludLater wave of Shai-Hulud worm
hxxps://github[.]com/TeamPCP/Shai-HuludOpen-sourced worm framework by TeamPCP
- Contagious InterviewAlternative name for the WaterPlum hacking group
- WaterPlumName of the North Korean hacking group
- Command and Scripting Interpreter: PowerShell (PSNATCH)
- Command and Scripting Interpreter: Unix Shell (BASHNATCH)
- Remote System Discovery (Implied by lateral movement and reconnaissance)
- Network Share Discovery (Implied by lateral movement and file exfiltration)
- Data from Local System (PSNATCH file exfiltration)
- Obfuscated Files or Information (Implied by encrypted C2)
- Non-Standard Port (Implied by GitHub API usage)
- Application Layer Protocol: DNS (Implied by domain usage)
- Phishing: Spearphishing Attachment (Implied by malicious scripts/payloads)
- User Execution: Malicious File (Implied by LNK file execution)
- Application Layer Protocol: HTTP/S (GitHub REST API)
- Remote Access Software (RUSTYSHADE backdoor functionality)
- Ingress Tool Transfer (Fetching file stealers from GitHub gist)
- Application Layer Protocol: Web Protocols (GitHub API usage for C2)
- Exfiltration Over C2 Channel (GitHub repositories for C2)
- Encrypted Channel: Asymmetric Cryptography (Used in RUSTYSHADE C2)
- Exfiltration Over Alternative Protocol (GitHub REST API)
- Application Layer Protocol (GitHub API)
theprints[.]orgTyposquatted domain impersonating The Print for C2/payload hosting.indiatodays[.]orgTyposquatted domain impersonating India Today for C2/payload hosting.