- SSH BruteHacking tool developed and used by Wagenius to steal credentials.
ThreatNoir Weekend Brief — September 26
Morning Review in IT Security — September 26, 2026
Today's security landscape reflects an escalating threat environment spanning military insider threats, actively exploited vulnerabilities across enterprise platforms, supply-chain compromises targeting development infrastructure, and sophisticated cloud-based attacks leveraging artificial intelligence. Organizations face mounting pressure to patch critical flaws and strengthen access controls across their infrastructure.
Army Soldier Sentenced for Spree of Attacks on AT&T, Snowflake and Other Major Companies
Cameron Wagenius, an active-duty Army soldier, has been sentenced for orchestrating some of 2024's most high-profile cyberattacks against major corporations including AT&T and Snowflake. The case underscores the critical insider threat risk posed by military personnel with both technical expertise and network access. Source: Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies
CISA Warns of SharePoint, WSO2, Adobe Commerce Flaws Exploited in Attacks
The Cybersecurity and Infrastructure Security Agency has issued warnings regarding multiple actively exploited vulnerabilities affecting enterprise software platforms. A critical authentication bypass vulnerability in WSO2 products, tracked as CVE-2026-5430, is being actively leveraged in attacks alongside three additional flaws: CVE-2026-65660, CVE-2026-67279, and CVE-2026-71362. These vulnerabilities impact SharePoint, WSO2, Adobe Commerce, and MikroTik platforms, making immediate patching essential for affected organizations. Source: CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
Two GitHub Actions repositories from the actions-cool organization have been disabled for a second time after becoming accessible again and resuming execution of the Mini Shai-Hulud malware. The affected repositories, issues-helper and maintain-one-comment, were originally compromised during the May 2026 campaign. This reactivation demonstrates persistent supply-chain risks in open-source development infrastructure and the need for continuous monitoring of previously compromised assets. Source: Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
Kiteworks Urges 6-Hour Server Shutdown Over Potential Zero-Day Attacks
Secure file-sharing software company Kiteworks has issued an urgent directive to customers worldwide to temporarily shut down their servers for a six-hour window on Saturday following receipt of threat intelligence indicating a potentially imminent cyberattack exploiting a zero-day vulnerability. The proactive shutdown measure reflects the company's rapid incident response posture in the face of unpatched security flaws. Source: Kiteworks urges 6-hour server shutdown over potential zero-day attacks
ShinyHunters Hacked Clop Leak Site Using Grav CMS Path Traversal Flaw
The Clop ransomware gang has relocated its data leak site to a new Tor address after confirming that ShinyHunters compromised and defaced its previous server through an unpatched Grav CMS vulnerability. The vulnerability, identified as CVE-2026-42608, is an unauthenticated path traversal flaw that allowed attackers to gain unauthorized access to the ransomware operation's infrastructure. This incident highlights the irony of criminal organizations falling victim to the same unpatched vulnerabilities they exploit against others. Source: ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
5G-Shark Lures Phones to Rogue 5G Cells Without Network Jamming
Security researchers have developed 5G-Shark, a tool capable of luring mobile devices onto rogue base stations and collecting subscriber identifiers while forcing network downgrades without requiring network jamming. The technique represents a sophisticated attack vector against mobile infrastructure and individual device security, enabling attackers to intercept communications and harvest sensitive authentication credentials. Source: 5G-Shark Lures Phones to Rogue 5G Cells Without Network Jamming
Elementor WordPress Flaw Lets Attackers Create Admin Accounts
A cross-site request forgery vulnerability in the widely deployed Elementor WordPress plugin enables unauthenticated attackers to create administrator accounts on affected websites. The flaw poses a significant risk to the millions of WordPress installations utilizing this popular page builder plugin, allowing attackers to establish persistent administrative access without legitimate credentials. Source: Elementor WordPress flaw lets attackers create admin accounts
Storm-3168: Agentic-Driven Cloud Attacks Using Compromised Service Principals
Microsoft has disclosed Storm-3168, a sophisticated cloud attack campaign linked to JADEPUFFER that leverages compromised Azure service principals to conduct reconnaissance, delete resources, and harvest additional credentials. The campaign demonstrates the emerging threat of artificial intelligence-orchestrated attacks targeting cloud infrastructure through compromised identity credentials. Organizations must implement robust service principal access controls and continuous monitoring to detect unauthorized cloud activity. Source: Storm-3168: Agentic-driven cloud attacks using compromised service principals
The convergence of insider threats, unpatched critical vulnerabilities, supply-chain compromises, and AI-driven cloud attacks reflects an increasingly complex threat landscape requiring comprehensive security strategies spanning identity management, vulnerability remediation, and advanced threat detection capabilities.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Medium-severity pre-authentication SSH state-machine/workflow bypass in Mikrotik RouterOS
- Critical authentication bypass in WSO2 API Manager
- Critical incorrect authorization in Adobe Commerce
- High-severity code injection in Microsoft SharePoint
- Mini Shai-HuludMalware family associated with the campaign and compromised GitHub Actions.
t.m-kosche[.]comExfiltration domain used in GitHub Actions workflows and linked to Mini Shai-Hulud campaign.
- Unauthenticated path traversal vulnerability in Grav CMS exploited by ShinyHunters.
- JADEPUFFERThreat actor associated with the observed malicious cloud activity.
- Storm-3168Microsoft's tracking name for the threat actor and observed activity.