Weekly review

ThreatNoir Weekend Brief — September 26

2026-09-26Morning8 articles
Audio
Listen to the episode

Morning Review in IT Security — September 26, 2026

Today's security landscape reflects an escalating threat environment spanning military insider threats, actively exploited vulnerabilities across enterprise platforms, supply-chain compromises targeting development infrastructure, and sophisticated cloud-based attacks leveraging artificial intelligence. Organizations face mounting pressure to patch critical flaws and strengthen access controls across their infrastructure.

Army Soldier Sentenced for Spree of Attacks on AT&T, Snowflake and Other Major Companies

Cameron Wagenius, an active-duty Army soldier, has been sentenced for orchestrating some of 2024's most high-profile cyberattacks against major corporations including AT&T and Snowflake. The case underscores the critical insider threat risk posed by military personnel with both technical expertise and network access. Source: Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies

CISA Warns of SharePoint, WSO2, Adobe Commerce Flaws Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency has issued warnings regarding multiple actively exploited vulnerabilities affecting enterprise software platforms. A critical authentication bypass vulnerability in WSO2 products, tracked as CVE-2026-5430, is being actively leveraged in attacks alongside three additional flaws: CVE-2026-65660, CVE-2026-67279, and CVE-2026-71362. These vulnerabilities impact SharePoint, WSO2, Adobe Commerce, and MikroTik platforms, making immediate patching essential for affected organizations. Source: CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Two GitHub Actions repositories from the actions-cool organization have been disabled for a second time after becoming accessible again and resuming execution of the Mini Shai-Hulud malware. The affected repositories, issues-helper and maintain-one-comment, were originally compromised during the May 2026 campaign. This reactivation demonstrates persistent supply-chain risks in open-source development infrastructure and the need for continuous monitoring of previously compromised assets. Source: Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Kiteworks Urges 6-Hour Server Shutdown Over Potential Zero-Day Attacks

Secure file-sharing software company Kiteworks has issued an urgent directive to customers worldwide to temporarily shut down their servers for a six-hour window on Saturday following receipt of threat intelligence indicating a potentially imminent cyberattack exploiting a zero-day vulnerability. The proactive shutdown measure reflects the company's rapid incident response posture in the face of unpatched security flaws. Source: Kiteworks urges 6-hour server shutdown over potential zero-day attacks

ShinyHunters Hacked Clop Leak Site Using Grav CMS Path Traversal Flaw

The Clop ransomware gang has relocated its data leak site to a new Tor address after confirming that ShinyHunters compromised and defaced its previous server through an unpatched Grav CMS vulnerability. The vulnerability, identified as CVE-2026-42608, is an unauthenticated path traversal flaw that allowed attackers to gain unauthorized access to the ransomware operation's infrastructure. This incident highlights the irony of criminal organizations falling victim to the same unpatched vulnerabilities they exploit against others. Source: ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

5G-Shark Lures Phones to Rogue 5G Cells Without Network Jamming

Security researchers have developed 5G-Shark, a tool capable of luring mobile devices onto rogue base stations and collecting subscriber identifiers while forcing network downgrades without requiring network jamming. The technique represents a sophisticated attack vector against mobile infrastructure and individual device security, enabling attackers to intercept communications and harvest sensitive authentication credentials. Source: 5G-Shark Lures Phones to Rogue 5G Cells Without Network Jamming

Elementor WordPress Flaw Lets Attackers Create Admin Accounts

A cross-site request forgery vulnerability in the widely deployed Elementor WordPress plugin enables unauthenticated attackers to create administrator accounts on affected websites. The flaw poses a significant risk to the millions of WordPress installations utilizing this popular page builder plugin, allowing attackers to establish persistent administrative access without legitimate credentials. Source: Elementor WordPress flaw lets attackers create admin accounts

Storm-3168: Agentic-Driven Cloud Attacks Using Compromised Service Principals

Microsoft has disclosed Storm-3168, a sophisticated cloud attack campaign linked to JADEPUFFER that leverages compromised Azure service principals to conduct reconnaissance, delete resources, and harvest additional credentials. The campaign demonstrates the emerging threat of artificial intelligence-orchestrated attacks targeting cloud infrastructure through compromised identity credentials. Organizations must implement robust service principal access controls and continuous monitoring to detect unauthorized cloud activity. Source: Storm-3168: Agentic-driven cloud attacks using compromised service principals

The convergence of insider threats, unpatched critical vulnerabilities, supply-chain compromises, and AI-driven cloud attacks reflects an increasingly complex threat landscape requiring comprehensive security strategies spanning identity management, vulnerability remediation, and advanced threat detection capabilities.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).