Weekly review

ThreatNoir Weekend Brief — September 20

2026-09-20Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — September 20, 2026

The cybersecurity landscape continues to face significant threats as nation-state actors, malicious extensions, and critical infrastructure vulnerabilities demand immediate attention from security teams worldwide. Today's briefing covers major incidents spanning supply-chain compromises, AI security threats, and active exploitation of critical systems.

North Korean WaterPlum Hackers Infected 30,000 Devices Worldwide

A joint law enforcement advisory has revealed that the North Korean hacking group WaterPlum compromised at least 30,000 devices globally between December 2025 and July 2026, successfully transferring more than $10.7 million in stolen cryptocurrency to North Korea. The campaign utilized multiple malware variants including BeaverTail, InvisibleFerret, OtterCandy, OtterCookie, and StoatWaffle to conduct widespread network infiltration across international targets. Source: North Korean WaterPlum hackers infected 30,000 devices worldwide

This incident underscores the persistent threat posed by nation-state actors leveraging sophisticated malware toolkits to compromise critical infrastructure and financial systems. Organizations are advised to implement robust detection mechanisms for the identified malware families and conduct comprehensive audits of their network environments for signs of compromise during the active campaign period.

BragJack Attacks Hijack AI Browser Agents Through Malicious Extensions

Security researcher Gal Weizman from Forever Security has demonstrated a proof-of-concept attack called BragJack that successfully hijacks AI assistants across multiple browsers including Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome through a single malicious extension. The Prompt Forcing technique employed in the attack has earned over $20,000 in bug bounties and resulted in the disclosure of two critical vulnerabilities designated CVE-2026-0628 and CVE-2026-55945. Source: BragJack attacks hijack AI browser agents through malicious extensions

This vulnerability class represents an emerging threat vector as AI-powered browser agents become increasingly integrated into user workflows. The attack methodology demonstrates how malicious extensions can bypass security controls and manipulate AI systems to execute unauthorized actions, highlighting the need for enhanced security measures in AI assistant implementations.

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

A critical unauthenticated remote code execution vulnerability in Orkes Conductor is currently being actively exploited in the wild, according to threat intelligence from Fortinet. The vulnerability, tracked as CVE-2026-58138 with a CVSS v3.1 score of 9.8 and CVSS v4 score of 9.3, affects Orkes Conductor versions prior to 3.30.2, allowing remote attackers to execute arbitrary code without authentication. Source: Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

Organizations deploying Orkes Conductor workflow platforms should immediately prioritize patching to version 3.30.2 or later to mitigate active exploitation attempts. The pre-authentication nature of this vulnerability makes it particularly dangerous, as attackers require no credentials or prior system access to compromise affected instances.

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency has added three actively exploited Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, signaling widespread threat actor activity targeting core operating system components. The flagged vulnerabilities include CVE-2025-39682 with a CVSS score of 9.8, along with CVE-2025-39964 and CVE-2026-53266, all demonstrating evidence of in-the-wild exploitation. Source: CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

Linux administrators and system operators must treat these vulnerabilities as critical priority items requiring immediate patching across all affected systems. The inclusion of these flaws in CISA's KEV catalog indicates coordinated exploitation campaigns and underscores the importance of rapid vulnerability management processes for operating system-level security issues.

Security teams should review today's threat intelligence across all four incident categories and implement appropriate detection, patching, and monitoring strategies to defend against these active threats.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

North Korean WaterPlum hackers infected 30,000 devices worldwide
Malware5
  • InvisibleFerret
    Python-based backdoor
  • BeaverTail
    JavaScript malware concealed in npm packages
  • OtterCookie
    JavaScript remote-access trojan and information stealer
  • OtterCandy
    Malware combining OtterCookie and RAT capabilities
  • StoatWaffle
    Modular Node.js malware delivered through malicious Visual Studio Code projects