Weekly review

ThreatNoir Afternoon Brief — September 22

2026-09-22Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — September 22, 2026

The cybersecurity landscape continues to face mounting threats across multiple domains on September 22, 2026. Today's briefing covers critical vulnerabilities in enterprise infrastructure, dangerous supply chain compromises, and kernel-level flaws affecting virtualization environments that demand immediate attention from security teams worldwide.

Malicious B-tree NPM Package Accumulates Millions of Downloads

A sophisticated supply chain attack has compromised the npm ecosystem through a malicious package masquerading as the legitimate sorted-btree library. The malicious indexed-btree package conceals a malware trigger within its prototype method, allowing attackers to execute code on systems that have installed the compromised dependency. The package has achieved millions of downloads, creating widespread exposure across development environments and production systems relying on npm dependencies. Source: SecurityWeek

The discovered indicators of compromise include communications to slack.com and telegram.org, as well as connections to https://sepolia.etherscan.io/, suggesting the attackers may be leveraging blockchain infrastructure for command and control or data exfiltration purposes. Organizations using npm packages should immediately audit their dependency trees and verify the integrity of installed packages against official sources.

CISA Orders Feds to Patch Zyxel Flaw Exploited for Data Theft

The U.S. Cybersecurity and Infrastructure Security Agency has issued a mandatory patching directive for federal agencies following active exploitation of a high-severity vulnerability in Zyxel GS1900 series switches. The flaw, identified as CVE-2026-7273, is being weaponized by threat actors to conduct data theft operations against government infrastructure. CISA's enforcement action reflects the critical nature of this vulnerability and the active threat posed by adversaries leveraging it in the wild. Source: BleepingComputer

Federal agencies have been directed to apply patches by Thursday, establishing a compressed timeline that underscores the severity of ongoing exploitation. Organizations operating Zyxel GS1900 series switches in any capacity should prioritize patching efforts immediately, as the active exploitation indicates that threat actors possess functional exploit code and are actively targeting vulnerable systems.

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

A critical vulnerability in the Linux kernel's KVM virtualization layer for ARM64 processors has been discovered that enables guest virtual machines to access and modify host kernel memory. Tracked as CVE-2026-89775, this flaw affects systems with nested virtualization enabled and can be exploited by a malicious guest to escape the virtualized environment and execute arbitrary code on the underlying host system. The vulnerability exposes freed memory regions to guest access, creating a direct path for privilege escalation and complete system compromise. Source: The Hacker News

The implications of this vulnerability extend across cloud infrastructure providers, container platforms, and any organization relying on ARM64-based virtualization for workload isolation. Linux systems administrators should prioritize kernel updates addressing CVE-2026-89775, particularly in multi-tenant environments where guest isolation is essential for security posture.

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

Microsoft's initial classification of a SharePoint Server vulnerability has been revealed as significantly understating its actual severity and impact. The flaw, CVE-2026-65660, was originally categorized as a spoofing issue with a CVSS score of 6.5, but technical analysis by Viettel Cyber Security researcher Dinh Ho Anh Khoa demonstrates that it enables authenticated remote code execution on affected systems. The vulnerability impacts SharePoint Server 2016, 2019, and Subscription Edition, affecting organizations across all supported deployment models. Source: The Hacker News

The misclassification of this vulnerability's true attack vector represents a significant risk to enterprise environments, as security teams may have deprioritized patching based on the initial CVSS assessment. Organizations operating any version of SharePoint Server should treat CVE-2026-65660 as a critical remote code execution vulnerability and apply available patches immediately, regardless of their initial patch management schedules.

Conclusion

Today's threat landscape demonstrates the persistent and evolving nature of security challenges facing organizations globally. From supply chain compromises in open source ecosystems to kernel-level virtualization flaws and misclassified enterprise vulnerabilities, security teams face a complex patching and remediation environment. Immediate action on these threats is essential to maintain system integrity and prevent unauthorized access.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Malicious B-tree NPM Package Accumulates Millions of Downloads
Domain2
  • slack.com
    Malware sends system information to a hardcoded Slack channel.
  • telegram.org
    Malware sends system information to a hardcoded Telegram chat.
URL1
  • hxxps://sepolia[.]etherscan[.]io/
    Malware connects to a blockchain contract deployed on Sepolia for C2.