- InvisibleFerretPython-based backdoor
- BeaverTailJavaScript malware concealed in npm packages
- OtterCookieJavaScript remote-access trojan and information stealer
- OtterCandyMalware combining OtterCookie and RAT capabilities
- StoatWaffleModular Node.js malware delivered through malicious Visual Studio Code projects
ThreatNoir Weekend Brief — September 20
Morning Review in IT Security — September 20, 2026
The cybersecurity landscape continues to face significant threats as nation-state actors, malicious extensions, and critical infrastructure vulnerabilities demand immediate attention from security teams worldwide. Today's briefing covers major incidents spanning supply-chain compromises, AI security threats, and active exploitation of critical systems.
North Korean WaterPlum Hackers Infected 30,000 Devices Worldwide
A joint law enforcement advisory has revealed that the North Korean hacking group WaterPlum compromised at least 30,000 devices globally between December 2025 and July 2026, successfully transferring more than $10.7 million in stolen cryptocurrency to North Korea. The campaign utilized multiple malware variants including BeaverTail, InvisibleFerret, OtterCandy, OtterCookie, and StoatWaffle to conduct widespread network infiltration across international targets. Source: North Korean WaterPlum hackers infected 30,000 devices worldwide
This incident underscores the persistent threat posed by nation-state actors leveraging sophisticated malware toolkits to compromise critical infrastructure and financial systems. Organizations are advised to implement robust detection mechanisms for the identified malware families and conduct comprehensive audits of their network environments for signs of compromise during the active campaign period.
BragJack Attacks Hijack AI Browser Agents Through Malicious Extensions
Security researcher Gal Weizman from Forever Security has demonstrated a proof-of-concept attack called BragJack that successfully hijacks AI assistants across multiple browsers including Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome through a single malicious extension. The Prompt Forcing technique employed in the attack has earned over $20,000 in bug bounties and resulted in the disclosure of two critical vulnerabilities designated CVE-2026-0628 and CVE-2026-55945. Source: BragJack attacks hijack AI browser agents through malicious extensions
This vulnerability class represents an emerging threat vector as AI-powered browser agents become increasingly integrated into user workflows. The attack methodology demonstrates how malicious extensions can bypass security controls and manipulate AI systems to execute unauthorized actions, highlighting the need for enhanced security measures in AI assistant implementations.
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
A critical unauthenticated remote code execution vulnerability in Orkes Conductor is currently being actively exploited in the wild, according to threat intelligence from Fortinet. The vulnerability, tracked as CVE-2026-58138 with a CVSS v3.1 score of 9.8 and CVSS v4 score of 9.3, affects Orkes Conductor versions prior to 3.30.2, allowing remote attackers to execute arbitrary code without authentication. Source: Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
Organizations deploying Orkes Conductor workflow platforms should immediately prioritize patching to version 3.30.2 or later to mitigate active exploitation attempts. The pre-authentication nature of this vulnerability makes it particularly dangerous, as attackers require no credentials or prior system access to compromise affected instances.
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency has added three actively exploited Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, signaling widespread threat actor activity targeting core operating system components. The flagged vulnerabilities include CVE-2025-39682 with a CVSS score of 9.8, along with CVE-2025-39964 and CVE-2026-53266, all demonstrating evidence of in-the-wild exploitation. Source: CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
Linux administrators and system operators must treat these vulnerabilities as critical priority items requiring immediate patching across all affected systems. The inclusion of these flaws in CISA's KEV catalog indicates coordinated exploitation campaigns and underscores the importance of rapid vulnerability management processes for operating system-level security issues.
Security teams should review today's threat intelligence across all four incident categories and implement appropriate detection, patching, and monitoring strategies to defend against these active threats.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Vulnerability in Google Chrome's AI component.
- Vulnerability in Microsoft Edge's AI agent race condition.
- Critical unauthenticated RCE vulnerability in Orkes Conductor
- Linux kernel vulnerability in AF_ALG socket race condition
- Linux kernel vulnerability in TLS receive path
- Linux kernel vulnerability in ebtables SNAT ARP rewrite path