Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
The day's lead is a five-nation advisory on a North Korean campaign that has turned the job interview into the intrusion vector: the ACSC joined the FBI, the US Department of Defense, Japan's National Police Agency and German authorities on 18 September to name "WaterPlum" — better known as Contagious Interview — and put numbers to it: at least 30,000 devices infected across 100 countries between December 2025 and July 2026, roughly 7,000 cryptocurrency wallets drained or credential-stolen, and more than $10.5 million taken. Targets are web designers, engineers and cryptocurrency specialists recruited through social media, gig-work sites and freelance portals, then asked to run a "skills test" file during the interview process; Japanese police recovered BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle variants from victim devices, and some of the stolen identity documents were reused by other North Korean operatives to get hired elsewhere. A second critical, this time from a perimeter vendor: Check Point has patched CVE-2026-91843, a stack-based buffer overflow in the login process of Security Management Server and Log Server that gives an unauthenticated attacker root remote code execution at low complexity and with no user interaction. Microsoft and WordPress supply the tier below. Microsoft fixed a maximum-severity missing-authentication flaw in Azure AI Foundry — CVE-2026-85889, CVSS 10.0 — alongside 9.9-rated bugs in Microsoft 365 Copilot and Azure Database for PostgreSQL, all mitigated server-side with no customer action required, while WordPress shipped 7.1.1 on 17 September to kill "Click2Shell," a chain in which a crafted link opened by a logged-in administrator installs an attacker-chosen theme from the official directory without anyone pressing Install and can reach code execution when paired with a second flaw in that theme. Rounding out the top tier, CISA added two Linux kernel flaws — CVE-2025-39964 and CVE-2026-53266 — to its Known Exploited Vulnerabilities catalog on evidence of active exploitation, the same week it confirmed it will stop publishing weekly vulnerability bulletins from 28 September.
The ACSC's WaterPlum advisory of 18 September is its first new publication since the 09 September critical alert on active exploitation of CVE-2026-75650 in Adobe Commerce, and it is a rare case of the ACSC co-sealing a named-actor advisory with the FBI, the US Department of Defense, Japan's National Police Agency and German authorities — the operational read for Australian organisations is that this is a jointly attributed, currently active campaign rather than a historical retrospective. The targeting profile is the part Australian employers should act on: the campaign recruits through freelance portals and gig-work platforms, so the exposed population is contractors, designers and engineers who are not covered by an employer's endpoint build, use personal devices for take-home exercises, and hold personal crypto assets. Australia's role in the advisory is as a co-sealing authority — ASD's ACSC signs the joint determination alongside Japan's NPA and NCO, the FBI and DoD's DC3, and Germany's BND and BfV — and that signature is itself an assessment that the campaign is material to Australian audiences, which is the inference worth drawing from it. What the advisory does not do is quantify: its victim geography names individual IT professionals in Japan, the United States, Europe and other countries, the one concrete national case is a Japanese "laptop farm" that authorities identified and dismantled, and no country-level counts are published for any partner. So the exposure question for an Australian organisation is answered against its own contractor and gig-hiring surfaces rather than against a published national figure. On the vendor side, check whether Check Point management infrastructure — SmartConsole and Log Server deployments, which are typically internet-reachable in remote-access designs — carries any of CVE-2026-91843's exposure before the weekend, since the flaw is unauthenticated and Check Point's own interim mitigation is to restrict the Trusted Clients list. Two further AU-relevant notes: Microsoft's cloud CVEs require no customer action, which matters for the large Australian Azure estate that cannot patch anything itself, and the WIRED/404 Media analysis of a physically seized Flock licence-plate camera — storage copied, on-device encryption key recovered, 1.6 million images from a single unit — is the sharpest available evidence on what fixed ALPR hardware yields once someone has it in hand, a question Australian agencies weighing camera-based road and policing infrastructure have not had answered in public. The visible leak-watch window carried no Australian victim.
Three threads persist from the week's coverage. North Korean monetisation is now the most industrialised threat in the dataset, and this week it showed up in three distinct places: the WaterPlum advisory with hard numbers, the Multilateral Sanctions Monitoring Team report that pushed Vietnam, Laos, Pakistan and Argentina into legal action against facilitators, and a new npm stealer, WeaselBiscuit, whose code openly borrows from the same BeaverTail and OtterCookie toolchain. That last point is the one to watch — the DPRK kit has been copied by a smaller, lighter, self-contained imitator, which suggests the campaign's tooling is now cheap enough to be replicated by actors with no connection to Pyongyang. Espionage geography is tracking the live diplomatic fault lines rather than the old blocs. Transparent Tribe (APT36) is running Operation RapidRust against Indian and Afghan government and defence targets with four new tools, while NightEagle (APT-Q-95) has moved from China's high-tech sector into Russian enterprises — a China-nexus group now spying on Russia is the reciprocal of the two-front dynamic this digest covered in the 18 September FamousSparrow disclosure. Both groups lean on the same two techniques: stolen credentials for the initial foothold and developer platforms for infrastructure. Ransomware is absent from today's top tier, and the reasons are visible: two of today's four headline items are vendor vulnerabilities that required no customer action, and the extortion trackers produced allegations rather than disclosures. The vulnerability firehose is the structural story of the week. CISA ending weekly bulletins, BOD 26-04 reframing remediation around exposure rather than severity, and Microsoft's near-1,000-CVE month are all downstream of the same cause — AI-assisted vulnerability discovery is finding bugs faster than organisations can triage them, which is why supply-chain defences are being re-tested from a new direction. This week alone produced a forged GitHub repository set impersonating LastPass and 39 other brands with a kernel-mode EDR killer strapped to it, a plugin-swap flaw affecting four major AI coding agents, and a re-registered abandoned CDN domain still called by thousands of sites. When patching cannot keep pace, the third-party component an organisation never chose to trust is where the breach arrives — and this week that component was as often an AI agent's plugin as a piece of software.
Incident Map
Defence 3 stories
Five Nations Attribute the "WaterPlum" Job-Seeker Campaign to North Korea, With 30,000 Devices and $10.7M in Losses
The FBI, the US Department of Defense, Japan's National Police Agency, the ACSC and German authorities issued a joint advisory on 18 September attributing the "WaterPlum" campaign — widely tracked as Contagious Interview — to North Korean actors, and for the first time put figures to the intrusion. Between December 2025 and July 2026 the campaign infected at least 30,000 devices in more than 100 countries and stole funds or account credentials from over 7,000 cryptocurrency wallets, transferring 1.7 billion Japanese yen — about US$10.71 million — of cryptocurrency assets to the DPRK. Victims are recruited through social media, online job and gig-work platforms and freelance marketplaces, often under the cover of an AI, cryptocurrency or NFT company, and asked to download and execute files during virtual interviews or coding assignments; the loaders install infostealers and remote-access trojans, and the NPA and FBI assess that WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department. Japanese police recovered BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle variants from victim devices, dismantled a "laptop farm" operated by an enabler in Japan — the first such case in the country — and found stolen identity documents being reused by other North Korean operatives to obtain employment elsewhere. The advisory names individual IT professionals in Japan, the United States, Europe and other countries as the victim population. Verification: Verified
Transparent Tribe Runs "Operation RapidRust" With Four New Tools and GitHub Repositories for C2
The Pakistan-aligned group Transparent Tribe (APT36, Earth Karkaddan) has been attributed by Zscaler ThreatLabz to a fresh campaign against government and defence entities in India and Afghanistan, using four previously undocumented tools: RUSTYSHADE, a Rust-based backdoor that reads and writes files in attacker-controlled private GitHub repositories for encrypted command-and-control over the GitHub REST API; RUSTYMOVE, a lateral-movement utility; and the Windows and Linux file-stealers PSNATCH and BASHNATCH. Delivery leans on typosquatted domains impersonating Indian news brands — theprints[.]org for theprint[.]in and indiatodays[.]org for indiatoday[.]in — hosting malicious PowerShell. RUSTYSHADE shares functionality with GITSHELLPAD, the Golang implant used in the September 2025 Gopher Strike campaign, and the disclosure lands a month after Acronis Threat Research Unit tied APT36 to the PATCHCORD backdoor campaign against Afghan telecoms. Verification: Verified
NightEagle Moves From China's Technology Sector to Russian Enterprises With the GhostContainer Backdoor
NightEagle (APT-Q-95), an espionage group active since at least 2023 that had focused on sensitive technology and defence organisations in China, has expanded into Russian companies, according to Kaspersky investigations over the past year. Initial access in most cases came from stolen credentials used over VPNs; inside the network the group targeted Microsoft Exchange servers and deployed GhostContainer, a backdoor that allows remote control, evades Windows security and logging mechanisms, and redirects network traffic. Kaspersky could not establish how the backdoor was first planted, but believes the group used a technique it has observed before: extracting encryption keys from Exchange and manipulating Microsoft's web application framework to run the implant in server memory. The actors stored tooling in GitHub repositories disguised as legitimate software, including names resembling AdobeSync and TrueConf, and exploited Active Directory weaknesses after establishing a foothold. Verification: Verified
Government 10 stories
CISA Adds Two Linux Kernel Flaws to KEV — and Confirms It Is Ending Weekly Vulnerability Bulletins
CISA added CVE-2025-39964 (Linux kernel race condition) and CVE-2026-53266 (Linux kernel out-of-bounds write) to its Known Exploited Vulnerabilities catalog on 18 September, both on evidence of active exploitation, alongside the earlier additions this week of CVE-2026-58704 (Google Pixel), CVE-2026-76460 (Cisco Identity Services Engine) and CVE-2026-87886 (Acronis Backup). The KEV alert explicitly ties the catalog to BOD 26-04, the binding directive that requires federal civilian agencies to prioritise KEV-listed flaws on publicly exposed assets that grant total control post-exploitation, and to check for prior compromise before patching. Separately, CISA confirmed it will discontinue its weekly vulnerability bulletins effective 28 September, describing the move as consistent with its shift from severity-based to risk-based vulnerability management — a doctrine being stress-tested by disclosure volume, with Microsoft's most recent monthly release approaching 1,000 CVEs as AI-assisted discovery accelerates. Verification: Verified
Nations Take Legal Action Against North Korean IT-Worker Facilitators After Multilateral Sanctions Report
The US-led Multilateral Sanctions Monitoring Team published a report on Wednesday expanding on the United Nations' 140-page October study of North Korea's illicit IT-worker scheme, which places teams of DPRK nationals in China and roughly 40 other countries earning hard currency in high-paying IT roles obtained with stolen or purchased identities. As of July, Vietnam, Laos, Pakistan and Argentina had taken meaningful responsive steps: Argentina opened an investigation into Antonia Doroganova over the alleged laundering of IT workers' earnings through a network of payment accounts and froze assets tied to her activity, while Pakistan opened a case against Syeda Aliya Batool Zaidi, accused of forging the identity documents that let DPRK nationals pass employment screening. The advisory and sanctions work runs in parallel with the WaterPlum enforcement action, and both describe the same population: operatives who use either stolen documents or their own technical skill to reach Western employers. Verification: Reported
Hackers Copy a Flock Licence-Plate Camera's Storage and Recover Its On-Device Encryption Key
Hackers physically removed a Flock Safety camera mounted above a roadway, made a near-complete copy of its stored data and recovered an encryption key held on the device, unlocking video of thousands of vehicle detections — including, per WIRED's and 404 Media's joint analysis, 1.6 million images from a single camera and detections of people as well as cars. The material was shared with 404 Media and the transparency organisation Distributed Denial of Secrets, which passed it to WIRED; the hackers say they are publishing details of how they obtained the camera's software so others can repeat it. The disclosure directly contradicts Flock's public position that its cameras are protected by on-device encryption, and it lands amid scrutiny of the company's contracts — Boston has just replaced Flock with a different licence-plate reader vendor. No vendor statement on the copies' authenticity had been published at the time of writing. Verification: Verified
Check Point Patches CVE-2026-91843, an Unauthenticated Root RCE in Security Management Server and Log Server
Check Point has released security updates for a critical stack-based buffer overflow in the login process of Security Management Server, the component that manages Security Gateways and monitors network events, which also affects the dedicated Log Server. Tracked as CVE-2026-91843, the flaw lets an unprivileged, unauthenticated attacker gain root remote code execution in a low-complexity attack requiring no user interaction. Check Point states that all Security Management Server deployments are vulnerable regardless of configuration. For customers who cannot apply the LivePatch immediately, the vendor recommends hardening vulnerable systems and restricting access to trusted IP addresses and subnets via Manage & Settings > Permissions & Administrators > Trusted Clients in SmartConsole, and says administrators can hunt for exploitation by searching Audit and Admin login logs for "Administrator failed to log in: Username too long" alerts. Check Point has not marked the flaw as actively exploited; last week it patched CVE-2026-85103, a heap overflow in VPN certificate ASN.1 decoding. Verification: Verified
Microsoft Patches a CVSS 10.0 Azure AI Foundry Flaw and 9.9-Rated Copilot and PostgreSQL Bugs
Microsoft has fixed a maximum-severity flaw in Azure AI Foundry — CVE-2026-85889, CVSS 10.0 — described as "missing authentication for critical function" that allows an unauthorised attacker to elevate privileges over a network. The platform, also called Microsoft Foundry, is the enterprise service for building, deploying and managing generative-AI applications and agents; the bug was reported by researcher Rémy Marot. No exploitation has been observed. The same batch carried CVE-2026-85885 (CVSS 9.9), command injection in Microsoft 365 Copilot, CVE-2026-85878 (CVSS 9.9), improper authorisation in Azure Database for PostgreSQL, and CVE-2026-87701 (CVSS 9.6), improper neutralisation in Azure Cosmos DB. As with most cloud CVEs, Microsoft says all four were mitigated service-side with no customer action required. Two local privilege-escalation bugs were also patched: CVE-2026-62721 (CVSS 7.8) in Windows User-Mode Power Service and CVE-2026-85921 (CVSS 8.2) in Windows Secure Kernel Mode. Verification: Verified
WordPress 7.1.1 Fixes "Click2Shell", Which Installs a Theme From a Single Crafted Link
WordPress released 7.1.1 on 17 September to fix a set of core vulnerabilities, one of which lets a crafted web link opened by a logged-in administrator install a theme from the official WordPress.org directory without anyone clicking Install. The reporting firm, pwn.ai, calls the chain Click2Shell. The mechanism is a parser differential: the WordPress.org directory reads the value in the link as an ordinary theme name and returns a real theme, while the administrator's browser reuses the original text — punctuation included — inside code that selects an item on the page, and attacker-added characters steer it to the Install button. Because the administrator is already authenticated, their session supplies both the capability and the security token; the attacker supplies neither. The installed theme stays inactive, so the site looks unchanged, and reaching code execution required a second flaw in the theme pwn.ai used (Mobile Repair Zone), whose background handler fetched and executed a package without checking permissions or a nonce. There is no sign of exploitation in the wild. Verification: Verified
Fake GitHub Repositories Impersonating 40 Brands Deliver Rapuncel — With a Signed EDR-Killer Driver
An ongoing campaign uses SEO-optimised GitHub repositories impersonating well-known software vendors to push a previously undocumented infostealer called Rapuncel. LastPass and Delphos Labs, which uncovered it, say the repositories impersonate the password-manager brand and at least 40 other companies, and that victims arrive by searching for software such as LastPass Authenticator and following the fake repository links. Download buttons trigger a chain of redirects to payload servers that return ZIP archives inflated to as much as 148 MB to evade scan limits. The installer is a renamed copy of Microsoft's legitimate Visual Studio CoreCLR Debugger, vsdbg.exe, configured to sideload a malicious vsdbg.dll, which deploys Rapuncel alongside the kernel driver Alinubx.sys — disguised as an NVIDIA component, nvfsflt64.sys, registered as the NvFsFilter service. The driver carries a hardcoded list of 145 antivirus and EDR processes it terminates, and defeats Protected Process Light by opening processes in kernel mode. Verification: Verified
"Plugin4Shell" Lets a Plugin Repository Swap Code Under a Pinned Commit Hash Across Four AI Coding Agents
Security firm Air Security disclosed a flaw that lets whoever controls an AI coding agent's plugin repository replace the plugin an agent installs even when the marketplace has pinned it to one reviewed version. The agents fetch the reviewed snapshot but never verify that the code they end up with matches it; on a code host that permits a branch or tag named to look like a commit hash, the repository owner can point that name at different code, and the agent installs it while reporting it is on the pinned version. Because plugins run with the user's own access, swapped code reaches their files, saved credentials and reachable systems. Anthropic patched Claude Code 2.1.179 and OpenAI patched Codex 0.146.0; GitHub Copilot has no fix, and Google will not patch the retiring Gemini CLI, whose installer can instead be tricked by a repository whose main branch is named FETCH_HEAD. GitHub blocks hash-shaped branch and tag names, so GitHub-hosted plugins are not exposed; Bitbucket and self-hosted git servers are. Verification: Reported
WeaselBiscuit: 13 npm Packages Carry a Stripped-Down Stealer Borrowing North Korean Code
Researchers at OpenSourceMalware identified a cluster of 13 npm packages delivering a previously undocumented JavaScript stealer named WeaselBiscuit, including seven scoped `@biz44/*` packages (id10-client, id12-client, id44-client, id79-client, id95-client, id99-client, process-runtime-utils, runtime-utils) and the unscoped `engin1`, `id79-client`, `process-lhpm`, `process-mite` and `process-tailwind`. The malware shows functional overlap with BeaverTail and OtterCookie, the strains associated with North Korea's Contagious Interview campaign, but is markedly smaller: it has no remote access, no persistence, no cryptocurrency wallet-draining code and no secondary-payload delivery, and is triggered by importing the package, which causes `loader.js` to pull the main payload from an Npoint dead drop and execute it in memory. Harvesting targets Chrome extension storage. The re-use of DPRK tradecraft in a lighter, self-contained imitator is the notable part — the toolchain is being copied by actors who are not the original operators. Verification: Verified
OFAC Sanctions BitBank, the Crypto Exchange Treasury Says Moved Hormuz Transit Payments to Tehran
The Treasury Department's Office of Foreign Assets Control designated BitBank, an Iranian digital-asset exchange controlled by the sanctioned financier Babak Zanjani, along with its software developer and three Zanjani associates. The maritime link is Hormuz Safe Marine Services Authority, the Iranian entity at the centre of Tehran's alternative system for managing commercial traffic through the Strait of Hormuz: Treasury says Hormuz Safe has used BitBank since June to transfer the payments it collects into Iran's financial system. Separately, OFAC alleges Zanjani used BitBank between June and July to move hundreds of millions of dollars' worth of Bitcoin to the Islamic Revolutionary Guard Corps. The action extends Washington's campaign against the financial architecture built around shipping through Hormuz, following July designations of Hormuz Safe and the Persian Gulf Marine Insurance Company. For compliance teams, the designation is a sanctions-screening event as much as a cyber one: it names an exchange, a corporate financer and the payment rails behind transit fees levied on commercial shipping. Verification: Verified
Healthcare 1 story
Ambry Genetics Pays $700,000 and Accepts a Corrective Action Plan Over a 2020 Phishing Breach
The HHS Office for Civil Rights and California-based genetic testing company Ambry Genetics agreed a settlement resolving alleged HIPAA violations arising from a breach of the electronic protected health information of 225,370 individuals. Ambry will pay a $700,000 penalty and adopt a corrective action plan addressing the non-compliance OCR identified during its investigation. The company detected suspicious activity in its email environment on 22 January 2020; the forensics found an unauthorised third party had accessed an employee's mailbox after the employee responded to a phishing email, with access from 22 to 24 January 2020. The exposed data included names, addresses, dates of birth, driver's licence numbers, diagnosis and condition information, medications, treatment information and some Social Security numbers. The breach was reported to OCR on 22 March 2020 as affecting 232,772 people, a figure later revised down. The delay between the 2020 breach, the 2020 report and a 2026 financial settlement is itself the enforcement signal. Verification: Verified
Legal Services 1 story
US Senators Reintroduce Healthcare Cybersecurity Legislation as OCR Logs 426 Hacking Breaches This Year
Senators Mark Warner and Ron Wyden reintroduced the Health Infrastructure Security and Accountability Act on 17 September, seeking to impose cybersecurity standards on the US healthcare system and make funding available for rural and underserved hospitals to invest in essential controls. The bill was first introduced on 25 September 2024 in the 118th Congress, when 394 hacking-related healthcare breaches had been reported to HHS OCR involving the protected health information of 43 million Americans. Two years on, OCR's breach portal lists 426 hacking-related breaches for 1 January to 31 August 2026, involving 73 million individuals — an 8 per cent increase in breach count and a 70 per cent increase in affected individuals. The senators' argument is unchanged: attacks delay patient care and the losses stem from lax practices by providers and their business partners. OCR published voluntary cybersecurity performance goals for the sector in January 2024, which as the agency predicted proved insufficient on their own. Verification: Reported
Transport 1 story
Foodservice Distributors Told to Architect for Resilience as Third-Party Cyber Risk Turns Physical
Cybersecurity executives used a panel at the International Foodservice Distributors Association's 2026 Solutions Conference in San Antonio — "The CISO Perspective: Navigating Cyber Risk in Foodservice Distribution" — to argue that cyberattacks on distributors should be planned for as operational disruptions affecting warehouses, trucks, customer orders and the physical movement of freight, not as IT incidents. The session covered the links between cybersecurity, transportation, warehouse operations, third-party vendors and business continuity, including the risk that carriers and other partners expose distributors to cargo theft as well as ransomware. Moderator Brett Perry, head of cybersecurity and network at Dot Foods, and the panel — Frank Smith (The Palmer Family of Companies), James Cusack (Van Eerden Foodservice) and Jeff Shaffer (Ben E. Keith) — pushed a resilience posture over prevention: "We know identities are going to get stolen. We know bad things are going to happen. But if we can alert and contain those types of incidents, we're going to be a much more resilient business without any operational impact." Verification: Reported
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| ● Tier 1 | Very High | Official / first-party |
| ● Tier 2 | High | Established cyber journalism |
| ● Tier 3 | Moderate | General tech/news media |
| ● Tier 4 | Low | Social / unverified |