// daily digest · 2026-09-16
Wednesday·16 September 2026

Cyber Digest

A daily roundup of key cybersecurity developments across sectors

15 stories9 sectors10 sourcesAU/NZ watchlist active

Executive Summary

The day's most consequential publication is a spyware advisory with a physical-security dimension. British, American and Dutch agencies issued a joint warning on CHOSEN BRICK, malware used by Iranian state-sponsored operators against individuals the regime regards as threats — dissidents, activists and journalists. The UK's National Cyber Security Centre named the tool and set out an attack chain that begins in WhatsApp or Telegram rapport-building and ends in a Windows implant that harvests contacts, inboxes, social-media messages, screen content and microphone audio, reporting back through a dedicated Telegram bot per victim. The agencies are explicit that the collection supports a pattern of life — a map of location, contacts and routine — and that Iranian intelligence services have in some cases plotted to kidnap and assassinate targets abroad; stolen personal details have then appeared on pro-Iranian leak sites to compound the harassment. Two features make this the story to read in full: the lures were tailored per target, including a fabricated MRI scan of a disc herniation, and the tooling is deliberately ordinary, adding Microsoft Defender exclusions and surviving reboot. The second thread is virtualisation and developer infrastructure as the cheapest way in. CISA has updated the KEV catalogue to record that ransomware gangs are now among those exploiting CVE-2026-59310, the critical vCenter Syslog directory-traversal flaw Broadcom patched on 29 July — the flaw's second escalation after the agency ordered federal remediation in August. In the same lane, F5 has documented a mass-scanning campaign against internet-exposed Vite development servers that strips `.env` files, AWS credential files and Azure tokens from hostnames developers exposed with a `--host` flag, while Wordfence reports more than 100,000 blocked attacks on an unauthenticated file-upload flaw in the WooCommerce Wholesale Lead Capture plugin, patched in February and exploited regardless. Third, the cost of offensive capability keeps falling while the cost of discovery falls with it. SOCRadar has documented VectraRAT, a from-scratch Windows remote-access platform with its own Linux control server, protocol and licensing, sold at US$250 a month. On the defensive side of the same economics, Apple's iOS 27 and macOS 27 releases carry 122 and 200-plus vulnerability fixes respectively, several credited to AI systems — Claude and OpenAI's Codex Security — a detail that sits directly alongside China's intelligence chief naming Anthropic's Claude Mythos and OpenAI's GPT-5.5-Cyber as cyber risks to Chinese critical infrastructure.

The ACSC has published nothing new since its 09 September Critical alert on active exploitation of CVE-2026-75650 in Adobe Commerce and Magento Open Source; its most recent non-alert publication remains the 08 September advisory on crypters, and the top of the alerts archive still carries the 24 August development-platform and 19 August remote-monitoring notices. Today's WooCommerce story is the one that lands squarely on an existing ACSC campaign: the agency's standing alert on large-scale exploitation of content-management-system and plugin vulnerabilities names WordPress plugin flaws specifically — Simple File List, WavePlayer, BerqWP, WPBookit, Ninja Forms and others — and describes exactly the tradecraft Wordfence is now reporting, scanning for an unauthenticated upload path and dropping a webshell. CVE-2026-27540 in WooCommerce Wholesale Lead Capture is a new entry in that campaign rather than a new technique, and Australian retail and e-commerce operators running WordPress should treat the ACSC alert as the assessment baseline and the Wordfence offender list as the immediate blocklist. The VMware vCenter escalation matters for a different population: Australian critical-infrastructure entities that run vCenter on-premises sit inside the SOCI Act's asset classes, and the timeline here — patch on 29 July, KEV listing on 18 August with a three-day federal remediation window, ransomware attribution in mid-September — is the clearest argument available for treating internet-exposed management planes on the ASD Essential Eight patch cycle rather than the project cycle. Two further threads bear on Australian defenders. The Vite campaign is a reminder that development infrastructure is production attack surface: a `--host` flag or a Docker port mapping can publish a developer's environment files and cloud credentials to the internet, and the exposure is invisible to the application's own security testing. And the FMCSA impersonation of a government registration portal is the same mechanism that Australian agencies and business have been fighting in myGov, ATO and state-tolling impersonation — the trigger is a deadline-shaped message, and the control that defeats it is looking up the portal rather than clicking it. On payment crime, Australian issuers and acquirers should note the Tajin Group's use of mainstream gateways and card BIN lists drawn from twelve countries; Australian banks and issuers are inside that targeting set and should expect the group's techniques to be replicated by other vendors on Chinese-language guarantee marketplaces. The CISA-NIST identity-token guidance is US-scoped but applies directly to any Australian organisation with federated SSO and API access into a cloud environment — token theft and forgery defeat MFA without ever touching the credential.

First, the exploited-vulnerability queue has stopped growing but is getting worse. CISA added seven flaws between 09 and 11 September — Artifactory, ScreenConnect, RouterOS, GitLab, NetScaler, Fortinet and Chromium — then exactly one on 14 September, the Cisco Secure Email Gateway SQL injection carried in yesterday's digest, and none since; the catalogue's published version is still 2026.09.14. The escalation today came without a new CVE at all: CVE-2026-59310 in VMware vCenter was patched on 29 July, listed on 18 August, and has now been re-flagged as exploited in ransomware campaigns. That is the pattern worth tracking — when the discovery pipeline slows, the exploited-in-the-wild set gets worked harder and re-classified upward rather than refreshed, and it means the practical risk signal is the exposure of the asset, not the arrival of a new identifier. Second, AI has moved from a capability claim on both sides to an accounting entry. China's Ministry of State Security chief named Anthropic's Claude Mythos and OpenAI's GPT-5.5-Cyber as risks to Chinese critical infrastructure and described "vulnerability industrialisation" as the new phase — days after Anthropic published a report on a Chinese-speaking group running what it called an autonomous vulnerability research programme. On the defensive ledger, Apple credited Claude and OpenAI's Codex Security among the finders of the 122 iOS 27 and 200-plus macOS 27 fixes released this week, and the earlier CISA-NSA-FBI advisory on industrial-scale knowledge distillation rounds out a week in which model capability is being cited as both threat and control. The careful reading is that AI is measurably increasing the *rate of vulnerability discovery* — the fixes and the attributions both support that — while the projected uptick in actual attacks remains asserted rather than observed, which is where the Five Eyes assessment landed in June. Third, identity is being transacted rather than stolen. The Tajin Group's Telegram username and anonymous virtual-number brokerage, the FMCSA lookalike registration domains, and the 12 deepfake platforms the Manhattan DA removed all monetise or manufacture identity without needing to breach anything: the market price of a verified-looking presence is falling, and the verification steps organisations rely on are the product being sold. Across the 91 stories carried in the past seven days, zero-day and vulnerability items remain the largest category at 34, with breach and leak next at 18 — the balance is unchanged, but the composition of the breach category is shifting toward identity instruments rather than database dumps.

2
Financial Services
1
Legal Services
2
Defence
1
Healthcare
2
Government

Incident Map

(static view)
CriticalSevereElevatedGuardeddarker = more incidents
United States
6
Russia
3
China
2
United Arab Emirates
1
Netherlands
1
Australia
1

Pan-regional / not map-pinned: 🇪🇺 Europe: 1

6 countries · 15 stories · click a country for its stories. Interactive map loads on the hosted site.

🎯 Geo-attribution: 11/15 stories located directly from text (73%). Low-confidence (region-bucket only, check): United States.

🎯 Geo-attribution: 11/15 stories located directly from text (73%). Low-confidence (region-bucket only, check): United States.

Financial Services 2 stories

1

Elastic Ties 15 Months of Brazilian Banking Fraud to an Extension That Forges Chrome's Integrity Checks

Elastic Security Labs has published a full account of the operation it tracks as REF9334, a Brazilian banking-malware ecosystem whose toolkit the malware author names KREMLIN — an artefact of the author's handle, `Kr3mlin4rt1st`, rather than any Russian nexus: the lures impersonate twelve Brazilian banks, the error messages and code comments are in Portuguese, and the operators' Ethereum transactions cluster during São Paulo working hours. Elastic has followed the group since May 2025 and documents seven campaigns across fifteen months. The infection chain begins with a JavaScript file masquerading as a bank receipt, invoice or company document that the user executes manually; the loader checks for sandbox and virtual-machine indicators, then pulls staged binaries from multiple hosts. The notable engineering is in the payload: a malicious browser extension that installs itself into Chrome and Edge and which the browser subsequently loads as though the user had approved it. It achieves that by manipulating Chromium's Secure Preferences store and regenerating the required HMACs and App-Bound encrypted hashes, so the browser's own tamper-detection logic is satisfied by forged values. Command-and-control resolution is handled through Ethereum smart contracts used as dead-drop resolvers, letting the operators rotate C2 endpoints and payload hosting without touching the malware. The operation's objective is banking sessions — credentials, session tokens and sensitive data — and Elastic assesses the primary focus as Brazilian banking users and financial institutions. Elastic's Threat Command team also disrupted the campaign at the infrastructure layer, registering the network canary — kill-switch — domain and disrupting more than 1,500 infections in the reported campaign, which is still counting. The transferable lesson for defenders is not the banking angle: it is that a browser's integrity-checked extension store is a defence that can be forged offline by an attacker who understands the format, so endpoint detection of unexpected extension loads matters more than trust in the store's tamper protection. Verification: Verified

Elastic Security Labs Tier 1/4 — Very High2026-09-14
2

Recorded Future Maps the Tajin Group's Card-Theft and Laundering Business Inside China's Guarantee Marketplaces

Recorded Future has published a profile of the Tajin Group, a third-party vendor advertising phishing, payment-card theft and money-laundering services on two Telegram-based Chinese-language guarantee marketplaces, Dabai Guarantee and Xinbi Guarantee. The group's principal victims are mainland Chinese citizens and Chinese banks, but the operation is not geographically contained: researchers found the group conducting extensive live testing of payment cards belonging to multiple countries against the gateways CCAvenue and Geidea, and holding Bank Identification Numbers for cards from twelve countries — the BIN being the card's issuer and product identifier, and the group's inventory of them being the practical measure of how far its supply reaches. It actively seeks partner groups able to offer direct payment channels accepting UnionPay, VISA, Mastercard, JCB and Apple Pay, and to exploit 2D and 3D payment gateways, settling through UAE Dirhams and electronic gift cards. The operation is also visible in its supplier choices: it pivoted from Dabai Guarantee to Xinbi Guarantee, indicating that vendors on these marketplaces do not stay loyal to a single platform, and it has bought and sold at least 100 Telegram usernames and multiple virtual phone numbers through Fragment Market, giving operators multiple linked handles and an anonymous number in place of a SIM. That identity layer is the analytically significant finding, because it means the same criminal can present as several distinct, verified-looking parties without registering a single SIM. Recorded Future's assessment is that the potential financial return will push other vendors on these marketplaces to replicate the same tactics on a global scale — the group's methods are, in effect, a playbook that is now circulating. Verification: Verified

Recorded Future Research Tier 2/4 — High2026-09-15

Defence 2 stories

1

UK, US and Dutch Agencies Expose CHOSEN BRICK, Iranian Spyware Built to Map Targets for Physical Harm

The UK's National Cyber Security Centre, the FBI and the Netherlands' AIVD issued a joint advisory naming CHOSEN BRICK, a spyware tool used by Iranian state-sponsored operators against individuals the regime treats as threats. The NCSC's framing is unusually direct: Iran has used this and similar activity to "support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists", and in some cases Iranian intelligence services have plotted to kidnap and assassinate individuals internationally, including people perceived as enemies of the regime. The tool harvests contacts, email inboxes and social-media messages, captures screen content and can switch on the device microphone; the agencies state that the resulting collection supports a pattern of life — a map of the victim's location, contacts and daily routine — which increases the physical risk to the person involved. Stolen personal details have surfaced on pro-Iranian leak sites to compound the harassment. The attack chain is rapport-led and highly tailored: initial contact comes over WhatsApp or Telegram, often impersonating a known contact or technical support, with operators building a relationship before delivering a file disguised to match the pretext. Lures have impersonated Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player and KeePass, and the advisory illustrates the tailoring with a fabricated MRI scan showing a disc herniation. CHOSEN BRICK is Windows-only, relaunches at login to survive reboot, and adds exclusions to Microsoft Defender to reduce detection; it uses a separate Telegram bot per victim for command and control, which limits the blast radius if one device is discovered, and sends exfiltrated files through Telegram alongside commercial cloud storage, with the most recent versions using proxies to conceal traffic. The advisory covers victims in all three countries dating back to at least 2025. The NCSC did not attribute the campaign to a specific Iranian entity, but notes the tradecraft closely matches an FBI flash warning circulated in March 2026 that attributed similar Telegram-based malware activity to actors operating on behalf of the Government of Iran Ministry of Intelligence and Security, and linked a July 2025 hack-and-leak to a persona the bureau assesses is also MOIS-operated. The agencies warn that attackers may try to move targets onto personal devices to bypass workplace security, and urge organisations with at-risk staff to circulate the warning and help employees check their own phones and computers — a recognition that the workplace perimeter is not the boundary of the risk. Verification: Verified

The Record Tier 2/4 — High2026-09-15
2

Zelensky Puts a Former National Police Chief in Charge of Ukraine's Cyber Coordination Centre

Ukrainian President Volodymyr Zelensky appointed Ihor Klymenko, a career law-enforcement official, to lead the National Cybersecurity Coordination Center — the body that sits under Ukraine's National Security and Defense Council and brings together the government agencies responsible for cybersecurity. The NCCC was created in 2016 and monitors cyberthreats facing Ukraine, coordinates the work of the responsible agencies and oversees delivery of the national cybersecurity strategy; it was previously headed by Rustem Umerov, a former NSDC secretary. Klymenko does not appear to have a technical cybersecurity background, which is the point of interest: he headed Ukraine's National Police from 2019 — an organisation that includes the country's cyber police department — became interior minister in 2023 with responsibility for several law-enforcement and emergency agencies, and was appointed head of the NSDC in August 2026. Zelensky has said Klymenko's experience would be useful in coordinating Ukraine's defence and security agencies against threats including Russian cyber operations and criminal networks. The appointment is part of a broader reshuffle of Ukraine's security leadership: in July, intelligence and counterterrorism official Yevhenii Khmara became acting defence minister, and his first deputy, Oleksandr Poklad, became acting head of the Security Service of Ukraine. Separately, parliament approved the dismissal of Prosecutor General Ruslan Kravchenko over allegations that officials in his office accepted bribes to protect scam call centres from law enforcement — a corruption finding that matters to the cyber picture, because it describes criminal infrastructure being sheltered inside the prosecutorial service. Read together, the reshuffle places a police-intelligence generalist over a coordination body at the moment Ukraine is consolidating both its cyber-defence apparatus and its domestic cybercrime enforcement. Verification: Verified

The Record Tier 2/4 — High2026-09-15

Healthcare 1 story

1

LHC Group Tells Patients a Vishing Call to a Vendor's Staff Opened Their Records to an Attacker for Eight Days

LHC Group, a Lafayette, Louisiana provider of home health, hospice and home- and community-based services operating in 28 US states and the District of Columbia, has begun notifying patients about a data security incident that ran through a third-party technology vendor. The unnamed vendor supported referral management, care coordination and clinical workflows, and required access to patients' personal and protected health information to do so. LHC established on 7 April 2026 that an employee may have been the victim of a voice-phishing attack; the vendor then reported suspicious activity on its platform tied to an LHC user account. The threat actor had stolen credentials and accessed a large volume of files on the vendor's platform, including files containing protected health information, with access running from 7 April to 15 April 2026. LHC began confirming the identities of affected individuals on 9 July 2026, roughly three months after the access window closed. The data types vary by individual and include full names, addresses, dates of birth and demographic information, plus clinical summaries, treatment plans, diagnosis codes, dates of service, physician and provider information, Medicare and Medicaid numbers, health insurance information and, in limited cases, Social Security numbers and financial information. LHC disabled the compromised account, enhanced authentication and monitoring, strengthened other controls, and is offering two years of complimentary credit monitoring and identity-theft protection. Based on the breach notifications sent to state attorneys general, more than 28,000 individuals are affected, and the true total is likely higher because not all states publish resident counts. This is the second breach LHC Group has announced this year, the earlier one arising from a vendor called Doctor Alliance. The operationally important detail is the access vector: a single successful telephone call to one employee at a supplier, not an intrusion into the healthcare provider. Verification: Verified

HIPAA Journal Tier 2/4 — High2026-09-15

Government 2 stories

1

CISA and NIST Publish Final Federal Guidance on Protecting Identity Tokens From Theft and Forgery

CISA and NIST released Interagency Report (IR) 8587, *Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers*, the final version of guidance covering the identity tokens and assertions that underpin single sign-on, federation and API-based access in federal cloud environments. The agencies frame the target directly: these are the systems adversaries increasingly attack in order to move laterally through enterprise networks and reach sensitive data, and the practical goal of the report is that a stolen or forged credential cannot become a foothold across an enterprise. The final report incorporates feedback from nearly 250 public comments on token validation, secrets management and detection at scale, and reflects CISA's work with cloud service providers and interagency partners through the Joint Cyber Defense Collaborative — including a June 2025 technical exchange with more than 50 industry experts and a January 2026 webinar on the draft, with individual engagement sessions involving Google, HashiCorp, IBM, Microsoft, Okta, the OpenID Foundation, Oracle, Amazon Web Services and Wiz. Substantively it expands on Release 5.1.1 of NIST SP 800-53 and its IA-13 control, and provides architectural considerations for identity providers and authorisation servers, enhancements to key management and token verification and token-lifecycle controls, guidance for securing SSO, federation and API access built on digitally signed and asymmetrically encrypted tokens, and principles for configurable, transparent and interoperable controls supporting threat-adaptive defence across cloud environments. The recommendations apply across commercial and government-operated cloud services and support the secure-software-development requirements of Executive Order 14306. On the same day, China's intelligence chief was naming US AI models as a cyber risk to Chinese critical infrastructure — a reminder that identity infrastructure is now treated as strategic terrain by both sides. The operational reading for non-US organisations is that the report is the most concrete public specification available for the token-theft problem that defeats MFA without touching the password. Verification: Verified

CISA Tier 1/4 — Very High2026-09-15
2

CISA Re-Flags the July vCenter Directory-Traversal Flaw as Exploited by Ransomware Gangs

CISA has updated its Known Exploited Vulnerabilities catalogue to record that ransomware gangs are now among those exploiting CVE-2026-59310, the critical directory-traversal vulnerability in the VMware vCenter Syslog server that Broadcom patched on 29 July. The flaw allows unauthenticated attackers to execute arbitrary code, and Broadcom's own supplemental FAQ at the time told customers to treat remediation as an emergency and patch as soon as possible. The exploitation history since then is the part worth tracking: two weeks after the patch, the incident-response firm QUIRSO reported finding more than 361 IP addresses across 47 countries compromised after a suspected advanced persistent threat actor began exploiting the flaw to deploy a reverse SSH tool for persistence and remote access. CISA added the CVE to the KEV catalogue on 18 August and ordered US federal agencies to secure their vCenter systems within three days. The update now attributed to ransomware operations is a second escalation of the same identifier rather than a new vulnerability, and CISA has not published details of which ransomware groups are involved or which victims have been hit. The exposure baseline is the concrete risk figure: internet monitor Shadowserver currently tracks more than 450 VMware vCenter servers reachable from the internet, with no public information on how many have been patched. Iran's and other actors' use of reverse SSH for persistence follows a pattern this digest has tracked through Fire Ant's pivot from VMware hypervisors to Cisco routers; the reason vCenter recurs as a target is structural — a compromised vCenter or ESXi host provides reconnaissance across the virtual estate and a route to the data stored on it, which is why multiple ransomware families now maintain dedicated ESXi encryptors. Any organisation still running an unpatched vCenter Syslog endpoint should treat the flaw as exploited, not merely exposed. Verification: Verified

BleepingComputer Tier 2/4 — High2026-09-15

Energy & Utilities 1 story

1

CenterPoint Energy Tells the SEC an External-Facing System Gave Up Customer Data

CenterPoint Energy, the Texas-based electric and gas utility serving 7 million customers across Indiana, Minnesota, Ohio and Texas, disclosed to the Securities and Exchange Commission that hackers obtained personal information from its systems during a recent data breach. In an 8-K filing made on the evening of Monday 15 September, the company said it became aware of a dark-web post this month claiming to offer data stolen from CenterPoint, and that its investigation established hackers had obtained "personal information relating to a portion of the Company's customers through one of the Company's external facing systems". The utility confirmed that delivery of electric and gas services has not been affected, has reported the incident to law enforcement, and says it is working with third-party experts to determine the scope of affected customers and information and will notify customers and regulators as required by applicable law. A company spokesperson declined to answer further questions about the criminal post, which claims roughly 7.5 million records containing customer names, account information, the last four digits of Social Security numbers and billing information. The company says it will incur investigation-related costs but does not expect a material financial impact; it reported net income of $244 million in the second quarter. This is the second time CenterPoint has worked a customer-data incident of this kind — last year it disclosed an investigation into a breach arising from the 2023 MOVEit file-transfer campaign. Breach classification: the victim has disclosed to a regulator and confirmed that customer personal information was taken from its own external-facing system, which makes this a confirmed breach. The scope figure of 7.5 million records, however, is the claimant's number published in the dark-web post, not a figure the company has verified — the victim's own statement describes an undetermined "portion" of customers, and the difference between those two numbers is the whole of the outstanding uncertainty. Verification: Verified

BleepingComputer Tier 2/4 — High2026-09-15

Transport 1 story

1

FMCSA Warns Carriers That Four Lookalike Domains Are Impersonating Its New Motus Registration Portal

The US Federal Motor Carrier Safety Administration has warned trucking companies that scammers are sending emails impersonating Motus, the USDOT registration system the agency launched on 19 May as a replacement for several legacy processes, and directing recipients to four bogus websites built to resemble the federal portal. The campaign uses the subject line "Notice of Required Off-Cycle Update- Motus email" and urges recipients to click a "New MOTUS Portal" button that routes them to an external destination. The four fraudulent domains — dot.motusdatasboard.com, dot.motusdatadesk.com, dot.motuswebdeck.com and dot.motusfunction.com — all prefix the genuine `dot` label while ending in a commercial domain rather than the government's `.gov` namespace; the legitimate service operates only at motus.dot.gov. FMCSA notes a second tell in its own alert: official correspondence writes the name as "Motus", not the all-capitalised "MOTUS" used by the fraudulent messages. The agency has published no information on when the campaign began, how many recipients encountered it, victim counts, financial losses or confirmed account takeovers, and has not linked the pages to unauthorised registration changes or cargo theft. The scam follows a predictable pattern of exploiting a system transition: regulators suspended biennial-update enforcement on 10 September to reduce disruption during the Motus rollout, which paused USDOT-number inactivation for missed filings due after 1 June — a grace period that gives a deadline-shaped phishing message unusual plausibility for carriers who know their filings are outstanding. The reason this matters beyond nuisance is what carrier registration records are used for: brokers and shippers verify who controls a trucking company through that federal identity data, so a successful account takeover would weaken the verification chain that underpins freight fraud controls. Verification: Verified

FreightWaves Tier 3/4 — Moderate2026-09-15

Retail & Entertainment & Sport 1 story

1

Wordfence Blocks 100,000 Attacks on an Unauthenticated Upload Flaw in a WooCommerce Wholesale Plugin

Attackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload PHP backdoors, according to Defiant, whose Wordfence web application firewall has blocked more than 100,000 attacks linked to the flaw. The vulnerability is tracked as CVE-2026-27540 and affects plugin versions 2.0.3.1 and older; it is an unauthenticated arbitrary file-upload flaw discovered by researcher Teemu Saarentaus and addressed in version 2.0.3.2, released on 20 February. The mechanism is a classic allowlist bypass: the plugin exposes an unauthenticated AJAX action named `wwlc_file_upload_handler`, which checks file extensions against an allowlist supplied through the user-controlled `file_settings` request parameter. Because the caller supplies the allowlist it is checked against, adding `php` to the permitted types makes the plugin accept executable PHP uploads. In the observed attacks the actor submits a forged `file_settings` parameter alongside a malicious `.php` file; the uploaded `shell.php` is a PHP webshell that reports host details and presents a browser-based upload form for writing further malicious files to the site. Wordfence reports exploitation activity spiked between 4 and 17 June, and again on 1 July and 30 August — a pattern of repeated automated waves rather than a single campaign, which is consistent with a published exploit being reused by multiple operators. The remediation guidance is unusually blunt about the limits of cleaning: after checking upload directories for unexpected or recently created PHP files, examining logs for requests to `/wp-admin/admin-ajax.php` invoking `wwlc_file_upload_handler` and removing unknown administrator accounts, Defiant advises that if compromise is confirmed the recommended action is to restore from a safe backup, because removing every persistence mechanism, user and backdoor from a compromised WordPress install is not reliably achievable. Wordfence has published a set of high-offender IP addresses responsible for tens of thousands of attempts. For Australian and New Zealand retail and e-commerce operators this is the same exploitation class the ACSC's standing CMS campaign alert describes, and the February patch date is the operative point: the fix has been available for seven months. Verification: Verified

BleepingComputer Tier 2/4 — High2026-09-15

Global (Macro) 4 stories

1

F5 Traces a Month-Long Campaign Stripping Cloud Credentials From Exposed Vite Dev Servers

F5 Labs has documented a mass-scanning campaign against internet-exposed Vite development servers that attempts to lift cloud credentials and configuration files out of AWS and Azure deployments. The operation exploits CVE-2026-39364, a high-severity flaw that bypasses file read and access controls in Vite versions 7.1.0 through 7.3.2 and the 8.x branch before 8.0.5, disclosed on 7 April. The bug is a parameter-manipulation bypass: an unauthenticated attacker appends parameters such as `?raw`, `?import&raw` or `?import&url&inline` to an HTTP GET request, the server fails to enforce its deny-list filtering, and it serves the target file with an HTTP 200 response in plaintext from a location that should have been out of reach. F5 detected the activity through its honeypot sensors, observing more than 800 attacks and roughly 32,000 raw events over a month. What the scanners are hunting for shows the attacker's understanding of developer environments: `.env`, `.env.production` and `.env.local` files; AWS credential files across several possible home directories plus AWS configuration and credential backups; Azure credentials and access tokens; Terraform state and variable files; serverless configuration and state; the process environment files `/proc/self/environ`, `/proc/1/environ` and `/proc/self/cwd/.env`; and `/etc/passwd` for a fallback inventory. The campaign also attempted traversal and encoding variants including double-encoded traversal sequences, apparently to slip past reverse proxies and WAF normalisation. Most observed activity originated from the United States, Belgium and the Netherlands, with attackers using Google Cloud IP ranges for evasion, and the most active addresses were also leveraging older access-control flaws in the same project (CVE-2025-30208, CVE-2025-31125 and CVE-2024-45811). The exposure is self-inflicted rather than a design defect: Vite binds to localhost by default, and F5 attributes the exposures to developers passing a `--host` flag, setting `server.host`, or misconfiguring Docker port mappings. Recommended mitigations are to patch, block access to port 5173, block suspicious `/@fs/` requests and stop trusting crawler User-Agent strings as a trust signal; F5 names three source addresses for blocklisting. Where unpatched servers were publicly exposed, all secrets within reach should be rotated rather than merely reviewed. Verification: Verified

F5 Labs Tier 1/4 — Very High2026-09-14
2

SOCRadar Documents VectraRAT, a Full-Stack Windows RAT Platform Sold at US$250 a Month

Researchers at SOCRadar have documented VectraRAT, a previously undocumented malware-as-a-service platform that includes a full-featured Windows implant, its own command-and-control infrastructure and an operator panel. What distinguishes it from the rest of the criminal market is that it was built from scratch rather than assembled from leaked or cracked components: "every layer of it, the Linux control server, the Windows implant, the protocol between them, the licensing that keeps operators paying, was written by the same developer", and none of it had been publicly documented before the report. That is a meaningful departure from the norm, where most remote-access tools sold on crimeware forums are a leaked AsyncRAT build, a cracked XWorm licence or a QuasarRAT fork with a new icon and name. The pricing is the point for defenders and for anyone assessing the market's maturity: the platform costs customers US$250 a month for turnkey access to enterprise Windows environments, including the licensing mechanism that sustains recurring revenue for the developer. A full-stack product at consumer-subscription pricing compresses both the technical skill and the capital required to run an intrusion — the operator no longer needs to understand, maintain or update anything below the operator panel. Read alongside the KREMLIN ecosystem documented today by Elastic, where a single developer maintained multi-stage JavaScript loaders, custom C++ installers and a Chrome extension capable of forging the browser's own integrity checks across fifteen months and seven campaigns, the picture is one of vertically integrated criminal toolmakers who own their entire stack. For defenders, the practical consequence is that tool-specific indicator lists age quickly when the developer can push an update to every customer; behavioural detection of remote-access tooling patterns and of the licence-driven persistence these platforms require is the more durable control. Verification: Verified

Dark Reading Tier 2/4 — High2026-09-15
3

Apple Fixes 122 Vulnerabilities in iOS 27 and More Than 200 in macOS 27, Crediting AI Finders

Apple's updated operating systems have left beta with a substantial security payload: iOS 27 addresses 122 vulnerabilities, and macOS 27 fixes more than 200, with some fixes backported to earlier supported releases. The vulnerabilities span memory-corruption bugs, privilege escalation, kernel memory access and remote code execution — the classes that matter most on a platform where the attack surface runs from the browser to the kernel. The notable detail in the release documentation is attribution: several of the fixes are credited to artificial intelligence systems, including Anthropic's Claude and OpenAI's Codex Security. That is a concrete data point for the debate framed elsewhere in today's digest by China's intelligence chief, who described vulnerability industrialisation as the defining phase of cyber operations; here the same capability is being credited on the defensive side of the ledger, in a shipping consumer release. Beyond the patch counts, Apple has strengthened enterprise authentication, added new executable code controls on Macs and retired its legacy update-management mechanism in favour of declarative management, a change with migration consequences for organisations running fleets through the older tooling and one that administrators should schedule rather than discover. One feature announced in the betas has not shipped: an ambitious AI agent that would detect compromised passwords and change them automatically has been put on hold, which is worth noting given that automated credential remediation is precisely what the token-theft and credential-harvesting stories elsewhere in this digest argue for. For enterprises, the practical task is to sequence a patch cycle that is one of the largest of the year while confirming that declarative management is in place before the legacy path is removed. Verification: Verified

iTnews Tier 3/4 — Moderate2026-09-15
4

China's Intelligence Chief Names Two US AI Models as Risks to Chinese Critical Infrastructure

Chen Yixin, head of China's Ministry of State Security, used the journal of the Cyberspace Administration of China to name two US artificial-intelligence models as cybersecurity risks to the country's critical infrastructure. Chen identified Anthropic's Claude Mythos and OpenAI's GPT-5.5-Cyber as evidence of what he called a "disruptive upgrade" in cyber capability, increasing the speed and potential weaponisation of vulnerability discovery and malware development. He cited their capabilities but did not allege that either model had been used against China — a distinction that separates this from an attribution. His framing is the analytically useful part: "Cybersecurity is entering a new phase characterized by vulnerability industrialisation, fully automated attack and defense, and AI versus AI", and he warned that some countries and organisations can "rapidly and in large quantities discover vulnerabilities, automatically connect attack paths, and complete complex hacking tasks, drastically lowering the technical barriers and costs of launching cyberattacks". Chen listed six major AI risks, leading with the technology's threat to what he termed political, institutional and ideological security — the concern that generative AI lets hostile actors fabricate political rumours and incite confrontation at low cost and at scale. Western agencies have made analogous arguments: the Five Eyes alliance warned in June that frontier models could reshape offensive and defensive cyber operations within months, though a proportionate rise in actual attacks has not yet been observed. The timing is pointed — Chen's article followed an Anthropic threat report describing a Chinese-speaking group, including two operators identified as undergraduates at a university in Hunan, that used Claude to run what the company called an autonomous vulnerability research programme and found several zero-days in a major security product. A day later, China's Cyberspace Administration released a new version of its AI governance framework at National Cybersecurity Week, addressing autonomous agents and embodied AI and naming "loss of control" as a core risk; the framework is guidance rather than law, and China already requires public-facing AI services to pass security review and register before launch. Verification: Verified

The Record Tier 2/4 — High2026-09-15

Analytics

Sector distribution

Financial Services
2
Legal Services
1
Defence
2
Healthcare
1
Government
2
Energy & Utilities
1
Transport
1
Retail & Entertainment & Sport
1
Global (Macro)
4

Source breakdown

The Record
4
BleepingComputer
3
Elastic Security Labs
1
Recorded Future Research
1
HIPAA Journal
1
CISA
1
FreightWaves
1
F5 Labs
1
Dark Reading
1
iTnews
1
15stories
Financial Services 2
Legal Services 1
Defence 2
Healthcare 1
Government 2
Energy & Utilities 1
Transport 1
Retail & Entertainment & Sport 1
Global (Macro) 4

Source Reliability Index

TierLabelDescription
● Tier 1Very HighOfficial / first-party
● Tier 2HighEstablished cyber journalism
● Tier 3ModerateGeneral tech/news media
● Tier 4LowSocial / unverified