Weekly review

ThreatNoir Morning Brief — September 23

2026-09-23Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — September 23, 2026

Today's security landscape reflects an intensifying threat environment marked by state-sponsored actors exploiting unpatched infrastructure, zero-day vulnerabilities in widely-used platforms, and sophisticated phishing operations enhanced by artificial intelligence. Organizations face mounting pressure to rapidly deploy patches and strengthen authentication mechanisms across their networks.

Chinese Hackers Exploit WordPress and Zyxel Flaws to Steal Government Data

A Chinese-speaking threat actor has been actively exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress installations to compromise sensitive government systems. The campaign has successfully targeted 996 devices and exfiltrated more than 18,500 records from backend databases. The attackers leveraged multiple CVE identifiers including CVE-2022-0847, CVE-2023-54391, and a series of 2026-dated vulnerabilities spanning CVE-2026-34908 through CVE-2026-63030, demonstrating a sophisticated understanding of both legacy and recently disclosed flaws.

Source: Bleeping Computer

China-Aligned Threat Group Exploits Chrome and Microsoft Zero-Days

Volexity has identified a threat group designated UTA0565 that is exploiting zero-day vulnerabilities in Google Chrome and Microsoft products using the same exploit kit employed by multiple Chinese threat actors. The group demonstrates variance in operational tactics while maintaining consistency in technical infrastructure, suggesting possible coordination or shared resources among Chinese-aligned cyber operations. The campaign involved CVE-2026-85046, CVE-2026-85880, and CVE-2026-87491, with exploitation occurring before vendor patches became available.

Source: CyberScoop

Check Point Management Server Zero-Day Exploited in Targeted Attacks

Check Point has disclosed a previously unknown vulnerability in its Security Management Server that was actively exploited in targeted attacks beginning July 23. CVE-2026-93616 permits unauthenticated attackers with access to the server's web service to execute arbitrary scripts without authentication credentials. The vulnerability is particularly critical given that the affected server controls firewall policies across enterprise networks. Check Point released a patch on September 22, addressing the flaw alongside related vulnerabilities CVE-2026-85102 and CVE-2026-91843.

Source: The Hacker News

Microsoft Dismantles AI-Powered Device-Code Phishing Operation

Microsoft has successfully taken down the EvilTokens device-code phishing service, which leveraged artificial intelligence throughout its attack chain to compromise approximately 12,000 email inboxes. The operation was conducted with authorization from the U.S. District Court for the Eastern District of Virginia and involved collaborative efforts from Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, and The Shadowserver Foundation. The takedown represents a significant enforcement action against infrastructure that weaponized AI to automate and scale phishing campaigns.

Source: The Hacker News

As threat actors continue to evolve their capabilities through zero-day exploitation and artificial intelligence integration, organizations must prioritize rapid patch deployment, network segmentation, and enhanced monitoring of management infrastructure to mitigate escalating risks.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Chinese hackers exploit WordPress, Zyxel flaws to steal govt data
CVE12