- Proxmox VE vulnerability exploited
- Ubiquiti UniFi OS vulnerability exploited
- Ubiquiti UniFi OS vulnerability exploited
- Linux kernel Dirty Pipe vulnerability exploited
- Gitea vulnerability exploited
- Nuclio vulnerability exploited
- FlowiseAI vulnerability exploited
- SENAITE LIMS vulnerability exploited
- WordPress Core vulnerability exploited
- WordPress Core vulnerability exploited
- ZyXEL GS1900 Smart Managed Switch vulnerability exploited
- Ubiquiti UniFi OS vulnerability exploited
ThreatNoir Morning Brief — September 23
Morning Review in IT Security — September 23, 2026
Today's security landscape reflects an intensifying threat environment marked by state-sponsored actors exploiting unpatched infrastructure, zero-day vulnerabilities in widely-used platforms, and sophisticated phishing operations enhanced by artificial intelligence. Organizations face mounting pressure to rapidly deploy patches and strengthen authentication mechanisms across their networks.
Chinese Hackers Exploit WordPress and Zyxel Flaws to Steal Government Data
A Chinese-speaking threat actor has been actively exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress installations to compromise sensitive government systems. The campaign has successfully targeted 996 devices and exfiltrated more than 18,500 records from backend databases. The attackers leveraged multiple CVE identifiers including CVE-2022-0847, CVE-2023-54391, and a series of 2026-dated vulnerabilities spanning CVE-2026-34908 through CVE-2026-63030, demonstrating a sophisticated understanding of both legacy and recently disclosed flaws.
Source: Bleeping Computer
China-Aligned Threat Group Exploits Chrome and Microsoft Zero-Days
Volexity has identified a threat group designated UTA0565 that is exploiting zero-day vulnerabilities in Google Chrome and Microsoft products using the same exploit kit employed by multiple Chinese threat actors. The group demonstrates variance in operational tactics while maintaining consistency in technical infrastructure, suggesting possible coordination or shared resources among Chinese-aligned cyber operations. The campaign involved CVE-2026-85046, CVE-2026-85880, and CVE-2026-87491, with exploitation occurring before vendor patches became available.
Source: CyberScoop
Check Point Management Server Zero-Day Exploited in Targeted Attacks
Check Point has disclosed a previously unknown vulnerability in its Security Management Server that was actively exploited in targeted attacks beginning July 23. CVE-2026-93616 permits unauthenticated attackers with access to the server's web service to execute arbitrary scripts without authentication credentials. The vulnerability is particularly critical given that the affected server controls firewall policies across enterprise networks. Check Point released a patch on September 22, addressing the flaw alongside related vulnerabilities CVE-2026-85102 and CVE-2026-91843.
Source: The Hacker News
Microsoft Dismantles AI-Powered Device-Code Phishing Operation
Microsoft has successfully taken down the EvilTokens device-code phishing service, which leveraged artificial intelligence throughout its attack chain to compromise approximately 12,000 email inboxes. The operation was conducted with authorization from the U.S. District Court for the Eastern District of Virginia and involved collaborative efforts from Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, and The Shadowserver Foundation. The takedown represents a significant enforcement action against infrastructure that weaponized AI to automate and scale phishing campaigns.
Source: The Hacker News
As threat actors continue to evolve their capabilities through zero-day exploitation and artificial intelligence integration, organizations must prioritize rapid patch deployment, network segmentation, and enhanced monitoring of management infrastructure to mitigate escalating risks.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Remote code execution vulnerability in Chromium JavaScript engine
- Remote code execution vulnerability in Chromium JavaScript engine
- Privilege escalation vulnerability in Windows ALPC
- Zero-day vulnerability in Check Point Security Management Server allowing unauthenticated script execution.
- VPN flaw affecting Check Point gateways and Spark firewalls, targeted since September 12.
- Separate flaw in Check Point management server fixed via LivePatch on September 16.
hxxps://t[.]me/+wNBoU1Gl2mRiYmU0Telegram group linked to EvilTokens