Weekly review

ThreatNoir Morning Brief — September 25

2026-09-25Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — September 25, 2026

The cybersecurity landscape continues to face significant threats across multiple vectors this morning. From supply chain compromises resurfacing months after initial containment to nation-state-backed cryptocurrency theft and emerging malware leveraging cloud services, organizations face an expanding attack surface requiring immediate attention and remediation efforts.

Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud

Two compromised GitHub Actions repositories that were disabled following the May 2026 Mini Shai-Hulud campaign became accessible again on September 16, 2026, reactivating a months-old supply chain compromise. The actions-cool/issues-helper and actions-cool/maintain-one-comment repositories had their release tags cleaned up during the initial containment, but those tags still pointed to malicious code introduced on May 18, 2026. When GitHub re-enabled both repositories, the malicious content remained in place, allowing any workflow referencing either action by version tag rather than commit SHA to resume executing the payload automatically.

The exposure is substantial, with the dependency graph showing approximately 15,000 repositories dependent on actions-cool/issues-helper alone. Workflows using these actions typically run on daily schedules or trigger on issue and pull request events, meaning most affected repositories likely executed the malicious payload within a day of re-enablement without requiring any additional threat actor intervention. The malicious code, wrapped within what appears to be legitimate issue and comment housekeeping automation, installs the Bun JavaScript runtime and executes an obfuscated payload with access to the workflow's GitHub token and any exposed secrets.

This incident demonstrates how a temporary containment measure such as repository disablement provides only surface-level protection when the underlying malicious content remains unaddressed. Organizations are advised to search their workflows for tag-based references to these actions, pin all third-party actions to known-clean commit SHAs, rotate any secrets accessible to affected workflows, and audit repository histories for unexpected commits since September 16. Source: Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud

Bitget Confirms $351.6 Million Hack, Suspects North Korea's Lazarus Group

Bitget has confirmed a cryptocurrency theft totaling $351.6 million and has suspended all withdrawals while investigators examine the breach in detail. Initial indicators suggest that North Korea's Lazarus Group, a nation-state threat actor with a documented history of targeting financial institutions and cryptocurrency platforms, may be responsible for the attack. The confirmation comes as the exchange works to contain the incident and determine the full scope of the compromise.

This incident underscores the persistent threat posed by nation-state actors targeting the cryptocurrency ecosystem. Lazarus Group has previously conducted multiple high-profile attacks against exchanges and blockchain platforms, demonstrating sophisticated capabilities and sustained interest in digital asset theft. Source: Bitget Confirms $351.6 Million Hack, Suspects North Korea's Lazarus Group

MacSync Malware Uses Public iCloud Calendars to Deliver New Payloads

A new variant of the MacSync malware targeting macOS systems has evolved to leverage public iCloud calendar events as a delivery mechanism for native payloads. This approach allows threat actors to distribute malicious code through a legitimate Apple service, potentially evading traditional security controls that may not scrutinize calendar event content. The use of public iCloud calendars represents an innovative abuse of cloud services to maintain persistent command and control capabilities.

The shift to calendar-based payload delivery demonstrates how attackers continue to adapt their infrastructure to exploit trusted services and reduce detection likelihood. Organizations and users should remain vigilant for unexpected calendar invitations and suspicious calendar events, particularly those containing executable content or unusual links. Source: MacSync malware uses public iCloud calendars to deliver new payloads

New Carbonato Malware Uses AI Agents to Hijack Exposed Docker Hosts

A newly identified botnet malware called Carbonato is targeting insecure Docker daemon installations to deploy the Hermes Agent AI framework and establish control over compromised hosts. The malware exploits exposed Docker APIs that lack proper authentication or network segmentation, allowing attackers to gain initial access and install AI agent infrastructure for command execution and lateral movement. This represents an emerging threat vector that combines container technology exploitation with artificial intelligence frameworks.

The Carbonato campaign highlights the critical importance of securing container infrastructure through proper network isolation, authentication mechanisms, and access controls. Organizations running Docker environments should audit their daemon configurations, restrict network exposure, implement strong authentication, and monitor for unexpected container deployments or suspicious process execution. Source: New Carbonato malware uses AI agents to hijack exposed Docker hosts


Today's threat landscape reflects a diversified attack approach spanning supply chain compromises, nation-state financial theft, cloud service abuse, and container infrastructure exploitation. Organizations must prioritize immediate remediation of exposed GitHub Actions, implement robust authentication and network controls for cloud and container environments, and maintain vigilant monitoring across all external-facing infrastructure.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).