- Linux kernel out-of-bounds write in ebtables SNAT implementation.
- Linux kernel TLS receive-path logic flaw mishandling zero-length records.
- Linux kernel race condition in AF_ALG cryptographic socket interface.
ThreatNoir Morning Brief — September 22
Morning Review in IT Security — September 22, 2026
The cybersecurity landscape continues to face mounting pressure from multiple threat vectors as critical vulnerabilities and sophisticated supply-chain campaigns dominate the threat intelligence landscape. Today's briefing covers urgent warnings from federal agencies, malicious campaigns targeting cryptocurrency users, and newly disclosed exploits affecting widely deployed platforms.
CISA Alerts of Active Exploitation of Three Linux Kernel Flaws
The U.S. Cybersecurity and Infrastructure Security Agency has issued a warning regarding active exploitation of three Linux kernel vulnerabilities, with one rated as critical severity. The affected vulnerabilities include CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266, with at least one of these flaws being a fourteen-year-old vulnerability that has only recently come under active attack. Source: CISA alerts of active exploitation of three Linux kernel flaws
The exploitation of these kernel-level vulnerabilities represents a significant risk to Linux infrastructure worldwide, particularly given the age of at least one flaw and the critical nature of the threat. Organizations running affected Linux systems should prioritize patching efforts immediately to mitigate the risk of compromise.
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
Researchers at LastPass and Delphos Labs have discovered a malicious campaign distributing a counterfeit LastPass Authenticator installer through GitHub that contains a sophisticated attack mechanism. The fake installer deploys a Windows kernel driver, identified as Alinubx.sys and CcProtect.sys, which is signed by Microsoft's own hardware-compatibility program and initially evaded detection on VirusTotal with zero detections. Source: Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
The attack chain operates by disabling antivirus and endpoint detection and response solutions before deploying a password stealer payload. This technique demonstrates the growing sophistication of supply-chain attacks that leverage legitimate Microsoft infrastructure to bypass security controls. Users downloading authentication tools should verify the source directly from official vendor websites rather than third-party repositories.
Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
North Korean threat actors have orchestrated a sophisticated social engineering campaign targeting technology professionals that has compromised at least 30,000 devices across more than 100 countries. The Contagious Interview campaign has successfully stolen funds or account credentials from over 7,000 cryptocurrency wallets, resulting in losses exceeding ten million dollars. The malware toolkit associated with this campaign includes BeaverTail, FlexibleFerret, GolangGhost, InvisibleFerret, OtterCandy, OtterCookie, PylangGhost, RATatouille, and StoatWaffle. Source: Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
The campaign specifically targets web designers, engineers, and cryptocurrency specialists through fraudulent job recruitment processes. This operation underscores the persistent threat posed by nation-state actors leveraging social engineering and targeted malware to compromise high-value targets in the technology and financial sectors.
WordPress Click2Shell Flaw Lets Hackers Execute PHP on the Server
A critical cross-site request forgery vulnerability in WordPress Core, designated as Click2Shell, has been disclosed with public technical details and proof-of-concept exploits now available. The vulnerability enables attackers to execute arbitrary PHP code on affected WordPress servers through a CSRF attack vector. Source: WordPress Click2Shell flaw lets hackers execute PHP on the server
The public disclosure of exploitation techniques for this WordPress vulnerability significantly increases the risk of widespread attacks against unpatched installations. Website administrators should prioritize updating their WordPress Core installations to patched versions to prevent unauthorized code execution and potential server compromise.
Organizations face a complex threat environment requiring immediate attention to multiple critical vulnerabilities and active campaigns. Prioritizing patching efforts, verifying software sources, and implementing robust email security training remain essential defensive measures in the current threat landscape.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Alinubx.sysName of the malicious kernel driver
- CcProtect.sysOriginal name of the malicious kernel driver
- FlexibleFerretMalware family deployed in the Contagious Interview campaign.
- GolangGhostMalware family deployed in the Contagious Interview campaign.
- PylangGhostMalware family deployed in the Contagious Interview campaign.
- RATatouilleMalware family deployed in the Contagious Interview campaign.
- OtterCandyMalware family deployed in the Contagious Interview campaign.
- StoatWaffleMalware family deployed in the Contagious Interview campaign.
- OtterCookieMalware family deployed in the Contagious Interview campaign.
- BeaverTailMalware family deployed in the Contagious Interview campaign.
- InvisibleFerretMalware family deployed in the Contagious Interview campaign.