- Pre-authentication RCE vulnerability in Security Gateway VPN certificate handling.
- Pre-authentication path traversal flaw in Management web service.
ThreatNoir Morning Brief — September 24
Morning Review in IT Security — September 24, 2026
The cybersecurity landscape continues to face mounting pressure as threat actors exploit critical vulnerabilities across enterprise infrastructure and supply chains. Today's review covers active exploitation campaigns targeting VPN gateways, content management systems, and development tools, alongside an emerging threat leveraging artificial intelligence for large-scale payment card theft.
Check Point Warns of Hackers Exploiting Security Gateway VPN RCE Flaw
Check Point has confirmed that threat actors are actively exploiting CVE-2026-85102, a pre-authentication remote code execution vulnerability affecting the VPN certificate-handling functionality of its Security Gateway product. The flaw allows unauthenticated attackers to execute arbitrary code on affected systems, presenting an immediate risk to organizations relying on Check Point's VPN infrastructure for secure remote access. Source: Bleeping Computer
The vulnerability underscores the critical importance of timely patching in VPN appliances, which often serve as critical network perimeter defenses. Organizations using affected Security Gateway deployments should prioritize applying available security updates to mitigate the active threat.
Hackers Start Exploiting Critical WordPress Flaw for Code Execution
Threat actors have escalated their campaign against WordPress sites vulnerable to CVE-2026-87902, moving beyond reconnaissance to active exploitation. The attackers are now writing files to disk that execute shell commands when accessed, enabling remote code execution on compromised WordPress installations. Source: Bleeping Computer
The exploitation activity has been traced to multiple IP addresses including 169.58.48.193, 169.58.48.195, and 2001:df1:e8c0::106b. WordPress site administrators should immediately apply patches for CVE-2026-87902 and audit their installations for signs of compromise, as the window between vulnerability disclosure and active exploitation has narrowed considerably.
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Cybersecurity researchers have identified a novel supply chain attack in which threat actors distributed Go-based malware through the HashiCorp Registry, using both malicious Go Modules and Terraform providers as distribution vectors. This marks the first documented instance of the centralized HashiCorp repository being weaponized for malware delivery. Source: The Hacker News
The compromised packages, including gocommunity-io/dockerd which accumulated 222 downloads, demonstrate the expanding attack surface within software development ecosystems. Organizations using Terraform and Go dependencies should review their supply chain security practices and verify the integrity of packages currently in use.
Malicious AI Agents Steal 600K Credit Cards, Infect 100+ Sites with Skimmers
A financially motivated threat actor is deploying artificial intelligence agents powered by open-source frameworks to conduct large-scale attacks against online retailers. The campaign has successfully stolen over 600,000 credit card records by infecting more than 100 e-commerce sites with payment card skimmers. Source: Bleeping Computer
This represents a significant escalation in attack sophistication, as threat actors leverage AI-driven automation to identify vulnerabilities and deploy skimming malware at unprecedented scale. E-commerce organizations should strengthen their payment processing security, implement robust intrusion detection systems, and conduct forensic investigations to determine if their infrastructure has been compromised.
As threat actors continue to innovate across multiple attack vectors—from exploiting enterprise infrastructure vulnerabilities to weaponizing development tools and artificial intelligence—organizations must maintain heightened vigilance and prioritize rapid patching cycles. The convergence of active exploitation campaigns and supply chain threats demands immediate attention from security teams across all sectors.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Critical WordPress vulnerability allowing RCE
169.58.48.193Source IP observed in reconnaissance activity169.58.48.195Source IP observed in reconnaissance activity2001:df1:e8c0::106bSource IP observed in reconnaissance activity
- skimmerMalware deployed on websites to collect payment data.