Weekly review

ThreatNoir Morning Brief — September 22

2026-09-22Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — September 22, 2026

The cybersecurity landscape continues to face mounting pressure from multiple threat vectors as critical vulnerabilities and sophisticated supply-chain campaigns dominate the threat intelligence landscape. Today's briefing covers urgent warnings from federal agencies, malicious campaigns targeting cryptocurrency users, and newly disclosed exploits affecting widely deployed platforms.

CISA Alerts of Active Exploitation of Three Linux Kernel Flaws

The U.S. Cybersecurity and Infrastructure Security Agency has issued a warning regarding active exploitation of three Linux kernel vulnerabilities, with one rated as critical severity. The affected vulnerabilities include CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266, with at least one of these flaws being a fourteen-year-old vulnerability that has only recently come under active attack. Source: CISA alerts of active exploitation of three Linux kernel flaws

The exploitation of these kernel-level vulnerabilities represents a significant risk to Linux infrastructure worldwide, particularly given the age of at least one flaw and the critical nature of the threat. Organizations running affected Linux systems should prioritize patching efforts immediately to mitigate the risk of compromise.

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

Researchers at LastPass and Delphos Labs have discovered a malicious campaign distributing a counterfeit LastPass Authenticator installer through GitHub that contains a sophisticated attack mechanism. The fake installer deploys a Windows kernel driver, identified as Alinubx.sys and CcProtect.sys, which is signed by Microsoft's own hardware-compatibility program and initially evaded detection on VirusTotal with zero detections. Source: Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

The attack chain operates by disabling antivirus and endpoint detection and response solutions before deploying a password stealer payload. This technique demonstrates the growing sophistication of supply-chain attacks that leverage legitimate Microsoft infrastructure to bypass security controls. Users downloading authentication tools should verify the source directly from official vendor websites rather than third-party repositories.

Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto

North Korean threat actors have orchestrated a sophisticated social engineering campaign targeting technology professionals that has compromised at least 30,000 devices across more than 100 countries. The Contagious Interview campaign has successfully stolen funds or account credentials from over 7,000 cryptocurrency wallets, resulting in losses exceeding ten million dollars. The malware toolkit associated with this campaign includes BeaverTail, FlexibleFerret, GolangGhost, InvisibleFerret, OtterCandy, OtterCookie, PylangGhost, RATatouille, and StoatWaffle. Source: Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto

The campaign specifically targets web designers, engineers, and cryptocurrency specialists through fraudulent job recruitment processes. This operation underscores the persistent threat posed by nation-state actors leveraging social engineering and targeted malware to compromise high-value targets in the technology and financial sectors.

WordPress Click2Shell Flaw Lets Hackers Execute PHP on the Server

A critical cross-site request forgery vulnerability in WordPress Core, designated as Click2Shell, has been disclosed with public technical details and proof-of-concept exploits now available. The vulnerability enables attackers to execute arbitrary PHP code on affected WordPress servers through a CSRF attack vector. Source: WordPress Click2Shell flaw lets hackers execute PHP on the server

The public disclosure of exploitation techniques for this WordPress vulnerability significantly increases the risk of widespread attacks against unpatched installations. Website administrators should prioritize updating their WordPress Core installations to patched versions to prevent unauthorized code execution and potential server compromise.

Organizations face a complex threat environment requiring immediate attention to multiple critical vulnerabilities and active campaigns. Prioritizing patching efforts, verifying software sources, and implementing robust email security training remain essential defensive measures in the current threat landscape.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
Malware9
  • FlexibleFerret
    Malware family deployed in the Contagious Interview campaign.
  • GolangGhost
    Malware family deployed in the Contagious Interview campaign.
  • PylangGhost
    Malware family deployed in the Contagious Interview campaign.
  • RATatouille
    Malware family deployed in the Contagious Interview campaign.
  • OtterCandy
    Malware family deployed in the Contagious Interview campaign.
  • StoatWaffle
    Malware family deployed in the Contagious Interview campaign.
  • OtterCookie
    Malware family deployed in the Contagious Interview campaign.
  • BeaverTail
    Malware family deployed in the Contagious Interview campaign.
  • InvisibleFerret
    Malware family deployed in the Contagious Interview campaign.