Weekly review

ThreatNoir Morning Brief — September 24

2026-09-24Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — September 24, 2026

The cybersecurity landscape continues to face mounting pressure as threat actors exploit critical vulnerabilities across enterprise infrastructure and supply chains. Today's review covers active exploitation campaigns targeting VPN gateways, content management systems, and development tools, alongside an emerging threat leveraging artificial intelligence for large-scale payment card theft.

Check Point Warns of Hackers Exploiting Security Gateway VPN RCE Flaw

Check Point has confirmed that threat actors are actively exploiting CVE-2026-85102, a pre-authentication remote code execution vulnerability affecting the VPN certificate-handling functionality of its Security Gateway product. The flaw allows unauthenticated attackers to execute arbitrary code on affected systems, presenting an immediate risk to organizations relying on Check Point's VPN infrastructure for secure remote access. Source: Bleeping Computer

The vulnerability underscores the critical importance of timely patching in VPN appliances, which often serve as critical network perimeter defenses. Organizations using affected Security Gateway deployments should prioritize applying available security updates to mitigate the active threat.

Hackers Start Exploiting Critical WordPress Flaw for Code Execution

Threat actors have escalated their campaign against WordPress sites vulnerable to CVE-2026-87902, moving beyond reconnaissance to active exploitation. The attackers are now writing files to disk that execute shell commands when accessed, enabling remote code execution on compromised WordPress installations. Source: Bleeping Computer

The exploitation activity has been traced to multiple IP addresses including 169.58.48.193, 169.58.48.195, and 2001:df1:e8c0::106b. WordPress site administrators should immediately apply patches for CVE-2026-87902 and audit their installations for signs of compromise, as the window between vulnerability disclosure and active exploitation has narrowed considerably.

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Cybersecurity researchers have identified a novel supply chain attack in which threat actors distributed Go-based malware through the HashiCorp Registry, using both malicious Go Modules and Terraform providers as distribution vectors. This marks the first documented instance of the centralized HashiCorp repository being weaponized for malware delivery. Source: The Hacker News

The compromised packages, including gocommunity-io/dockerd which accumulated 222 downloads, demonstrate the expanding attack surface within software development ecosystems. Organizations using Terraform and Go dependencies should review their supply chain security practices and verify the integrity of packages currently in use.

Malicious AI Agents Steal 600K Credit Cards, Infect 100+ Sites with Skimmers

A financially motivated threat actor is deploying artificial intelligence agents powered by open-source frameworks to conduct large-scale attacks against online retailers. The campaign has successfully stolen over 600,000 credit card records by infecting more than 100 e-commerce sites with payment card skimmers. Source: Bleeping Computer

This represents a significant escalation in attack sophistication, as threat actors leverage AI-driven automation to identify vulnerabilities and deploy skimming malware at unprecedented scale. E-commerce organizations should strengthen their payment processing security, implement robust intrusion detection systems, and conduct forensic investigations to determine if their infrastructure has been compromised.


As threat actors continue to innovate across multiple attack vectors—from exploiting enterprise infrastructure vulnerabilities to weaponizing development tools and artificial intelligence—organizations must maintain heightened vigilance and prioritize rapid patching cycles. The convergence of active exploitation campaigns and supply chain threats demands immediate attention from security teams across all sectors.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).