Weekly review

ThreatNoir Afternoon Brief — September 29

2026-09-29Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — September 29, 2026

The security landscape continues to face critical challenges as Apple addresses an actively exploited zero-day vulnerability, while threat actors leverage artificial intelligence and social engineering tactics to compromise systems globally. Today's briefing covers emerging threats spanning from sophisticated mobile exploits to AI-weaponized attack chains.

Apple Patches CoreGraphics Zero-Day Flaw Exploited in Attacks

Apple has released security updates addressing a zero-day vulnerability in CoreGraphics that has been actively exploited in extremely sophisticated targeted attacks against iOS devices. The vulnerability, tracked as CVE-2026-20700, represents a critical gap that threat actors have already weaponized before a patch became available to users. This incident underscores the ongoing challenge of zero-day exploitation in the mobile ecosystem and the importance of rapid patching cycles.

Source: Apple patches CoreGraphics zero-day flaw exploited in attacks

Four Cyber Threats Harboring Big Plans for the Future

Organizations face an expanding threat landscape shaped by four emerging vectors: artificial intelligence integration, supply-chain exposure, quantum computing capabilities, and geopolitical conflict dynamics. Security programs must evolve beyond reactive incident response to embed disruption preparedness into daily operational frameworks. These interconnected threats—including malware variants such as Skynet and Terminators—demand that enterprises adopt proactive resilience planning to withstand both current and anticipated attack methodologies.

Source: Four Cyber Threats Harboring Big Plans for the Future

Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation

Dutch law enforcement has arrested Pepijn van der Stap, a previously convicted hacker, as part of an ongoing ShinyHunters investigation. Van der Stap was convicted in 2023 for orchestrating attacks against multiple organizations, stealing sensitive data, and conducting extortion campaigns. The arrest highlights the persistence of recidivist threat actors who continue exploiting unpatched systems, as evidenced by the associated CVE-2026-35273 vulnerability, and demonstrates law enforcement's sustained commitment to disrupting organized cybercrime networks.

Source: Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation

Attackers Weaponise ChatGPT Custom GPTs to Deliver RAT via Eight-Stage ClickFix Chain

Threat actors are exploiting ChatGPT's Custom GPT feature to execute sophisticated multi-stage attacks culminating in remote access trojan deployment. Researchers at Huntress identified a malicious Custom GPT titled "Plus 5.6" designed to impersonate legitimate ChatGPT functionality, leveraging the trusted chatgpt.com domain to bypass user skepticism. The eight-stage ClickFix attack chain demonstrates how adversaries are rapidly adapting AI-powered platforms for social engineering purposes, transforming generative AI tools into delivery mechanisms for full-featured malware.

Source: Attackers weaponise ChatGPT Custom GPTs to deliver RAT via eight-stage ClickFix chain

Closing Summary

Today's threat landscape reflects a convergence of technological advancement and adversarial innovation. From zero-day exploitation in established platforms to the weaponization of cutting-edge AI interfaces, security teams must maintain vigilance across traditional and emerging attack vectors while prioritizing rapid patch deployment and user awareness training.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).