Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
A management-plane zero-day, a CVSS 10.0 orchestrator flaw and an AI-enabled cybercrime service all landed on the same day, and the first two share an uncomfortable property: they hand an unauthenticated attacker control of the systems defenders use to defend. Check Point released emergency hotfixes for CVE-2026-93616, a path-traversal flaw in the Security Management Server that lets an unauthenticated attacker upload and run arbitrary scripts on the console that stores security policies for the whole estate; the company says it is exploited in the wild and that "a handful of customers" have been attacked. Arista disclosed CVE-2026-93952 in on-premises VeloCloud Orchestrator at a CVSS score of 10.0, with active exploitation confirmed and no fix yet for the 6.1 and 7.0 release trains. CISA added both — plus a second Check Point flaw and an F5 BIG-IP APM overflow — to the KEV catalog the same day. The third thread is what happens when AI is pointed at the criminal workflow rather than at the message. Microsoft's Digital Crimes Unit dismantled EvilTokens, an end-to-end AI service selling for US$1,500 up front and US$500 a month that automated target selection, impersonation and monetisation planning across 12,000+ compromised inboxes in more than 10,000 organisations, and two men were arrested in the UK. Separately, Cisco Talos documented CLOSEDQUORUM, the first publicly documented Windows implant to delegate command and control to a quorum of commercial LLMs abroad rather than to attacker infrastructure of its own.
Australia is named in the victim geography of the day's largest disruption, and the national product pipeline is quiet. Microsoft's EvilTokens figures place the compromised organisations' concentration in the United States, Canada, the United Kingdom, Australia, India and France, so the service that was taken offline was aimed at Australian inboxes among others — the device-code flow it abused needs only a user who enters a code they were sent, which is an awareness problem as much as a Microsoft Entra one, and Australian organisations remain in the affected cohort until credential hygiene catches up. The ACSC has published nothing new since its 18 September WaterPlum advisory; the newest guidance is the 17 September network segmentation and segregation package (overview plus anti-patterns) and, before that, the 15 September Active Directory guidance, and the GreyNoise campaign below exploited Zyxel GS1900 switches in 48 countries, a device class that sits in exactly the small-business and branch networks the ACSC's small-and-medium-business audience runs. Closer to home, Telstra has put an AI agent into its customer service guarantee reporting, and Anthropic's special envoy used an Australian platform to argue for AI investment before regulation — the same tension the NCSC's chief technology officer for architecture set out this week when he said defenders "simply cannot put AI to work in the same way attackers can".
This week's constant is that the exploited systems are the security infrastructure, not the business systems. In five days the digest has covered KEV additions for Linux kernel race conditions, a Zyxel switch overflow, Cisco ISE, and now Check Point's management server, an SD-WAN orchestrator and F5's access policy manager — a run of vulnerabilities in consoles, controllers and gateways rather than in applications. That is the shape to expect when attackers optimise for reach: one console holds trust relationships to thousands of endpoints, so the same effort buys more. The AI thread splits in two directions and only one is speculative. Talos explicitly says it has no confirmation that CLOSEDQUORUM was deployed in the wild, and its public build ships placeholder keys; EvilTokens, by contrast, was a running business with subscribers, support and abuse at scale, and it is the operationally real one. The gap between the two is the honest framing for the week: AI has already industrialised the criminal back office, and autonomous attack decision-making remains demonstrated rather than deployed. Geopolitically, the espionage tempo is unchanged and the Chinese ecosystem is the through-line — Volexity's shared exploit kit across multiple Chinese groups (reported 21 September), SideCopy's move into Indian academia, and a Chinese-speaking actor now confirmed to have pulled configurables and hashed root credentials out of 996 Zyxel switches. For the week ahead: whether the 6.1 and 7.0 VeloCloud trains get fixes, whether Check Point's "handful of customers" grows, and whether the CrowdSec disclosure of a May supply-chain compromise five months after the fact prompts other security vendors to audit their own ex-employee token hygiene.
Incident Map
Global (Macro) 5 stories
Check Point Patches a Management Server Zero-Day That Lets an Unauthenticated Attacker Run Scripts on the Console Holding Every Security Policy
Check Point released emergency hotfixes for CVE-2026-93616, a path-traversal flaw in its Security Management Server that lets an unauthenticated attacker upload arbitrary scripts and execute them, and confirmed the vulnerability is exploited in the wild — "Check Point is aware of a handful of customers who have been attacked". The affected product list is the reason this matters more than a single-appliance bug: Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent all carry it, and the management server is the central repository that stores security policies, processes administrator changes and collects logs across an enterprise estate. The fix is the R82.20 Security Hotfix; Check Point published indicators of compromise in advisory SK1000171 and, for organisations that cannot deploy immediately, mitigation by placing the management server behind a firewall and restricting access to trusted IP addresses under SmartConsole's Trusted Clients. CISA added CVE-2026-93616 to the KEV catalog on 22 September, alongside a second Check Point flaw, CVE-2026-85102. Check Point's recent record on this product line explains the urgency: three separate management-plane flaws have been exploited since June, including two authentication bypasses linked to the Qilin ransomware affiliate and to administrator-privilege access on SmartConsole.
Microsoft Dismantles EvilTokens, an AI Cybercrime Service With 12,000 Compromised Inboxes, and Two Men Are Arrested in the UK
Microsoft's Digital Crimes Unit used a court-authorised action in US District Court, brought with the health-sector non-profit Health-ISAC, to dismantle EvilTokens — an AI-powered phishing and fraud platform sold on Telegram for a US$1,500 initiation fee and a US$500 monthly subscription — seizing 50 websites and disabling 150 further domains. Two men, aged 32 and 38, were arrested by the Metropolitan Police Service's cybercrime team and released on bail. Microsoft says the service launched in February 2026 and was linked to more than 12,000 compromised email inboxes across over 10,000 organisations, concentrated in the United States, Canada, the United Kingdom, Australia, India and France. Its distinctive capability was automating the criminal's decision-making rather than just the lure: the platform summarised and translated mailbox content, mapped organisational roles and trusted relationships, found wire-transfer discussions and vendor invoices, named the "money movers" worth impersonating, and drafted messages in a trusted contact's voice. It abused device-code phishing, in which the victim enters an attacker-supplied code and authorises a session without ever handing over a password — access that can survive a password change. Microsoft describes the takedown as its 40th court-authorised disruption and its first against an end-to-end AI-enabled cybercrime service.
Arista Discloses a CVSS 10.0 Flaw in On-Premises VeloCloud Orchestrator and Says It Is Being Exploited
Arista disclosed CVE-2026-93952 in on-premises VeloCloud Orchestrator (VCO) — the server that manages the Edge devices in a VeloCloud SD-WAN — with a CVSS 3.1 score of 10.0, and said the flaw "was discovered externally and is known to be actively exploited". A remote attacker with no login access can use it to privilege internal functions and affect the VCO host; because the orchestrator holds the trust relationships and configuration for the Edges it manages, a compromise there reaches the managed estate as well. Only orchestrators configured to authenticate their Edges by certificate are exposed, and the attacker also needs network access to the VCO web interface plus the public part of an Edge's authentication certificate. Fixes were available on 22 September for the 5.2 (5.2.3.16 and later) and 6.4 (6.4.2.8 and later) trains, with no fix yet for 6.1 and 7.0 and hosted and dedicated instances already patched. The affected releases include versions that had been patched against a *different* VCO flaw, CVE-2026-16812, reported as exploited in July — the second time this year that VCO has been attacked through a vulnerability in the product itself rather than through customer misconfiguration. CISA added it to the KEV catalog the same day.
CLOSEDQUORUM Is the First Publicly Documented Windows Implant to Run Command and Control Through a Quorum of Commercial LLMs
Cisco Talos has published static analysis of CLOSEDQUORUM, a 16.4 MB 64-bit Go implant it describes as the first publicly documented Windows malware to apply AI to tactical command and control. Instead of attacker-operated C2 infrastructure — a domain, an IP, a protocol and a listener, all attributable, blockable and costly to rotate — the binary queries up to four commercial LLM providers (DeepSeek, Qwen, Mistral and Google Gemini) in sequence, tallies their independent verdicts on the next action and executes the plurality decision. A `ModelOrchestrator` aggregates the responses and `interModelDiscussion()` resolves them; the intended ends are LSASS dumping, crypto-wallet extraction, early-bird process injection and exfiltration to Discord. Talos is explicit about the limits: it has no confirmation of in-the-wild deployment, the public distribution build ships placeholder API keys and a dummy webhook, and the payload's developer was connected to criminal carding-forum postings dating to 2025. Talos frames the significance as effort displacement — moving a whole attack phase from the operator to the system, so the intrusion does not stop when the attacker sleeps. The analysis accompanies Talos's release of CAIRN, an open-source toolkit for tracking AI-integrated malware.
The Graphalgo Campaign Ports to Go and Terraform, Using Two Fake Module Ecosystems and a Slack-and-Blockchain RAT
Aikido has documented malware distributed through at least two Terraform providers and two Go modules — the first time it has observed malicious Terraform providers — as the Graphalgo campaign moves beyond the npm ecosystem where ReversingLabs first reported it in February 2026. The packages are `gocommunity-io/dockerd` and `kreuzwenker/docker` (a typosquat of the legitimate `kreuzwerker/docker` provider, which reports 56 million downloads), and the Go modules `gocommunity.io/orderedbtree` and `gogets.dev/btreex`; OpenSourceMalware verified both Go modules on 22 September and archived them as part of today's 24 new records, noting the attacker stood up at least two fake Go package-ecosystem websites (`gocommunity[.]io`, `gogets[.]dev`) to lend them legitimacy. The payload is inert unless the SHA256 hash of specific runtime inputs equals `b9966e37…8ad5`, which then serves as an AES key to decrypt an embedded archive and run it through a detached `go run`; the second stage is a Go RAT with dual C2 — system reconnaissance posted in plaintext to a `frontend-devs` Slack channel before encrypted traffic moves to a second workspace, and commands polled every three seconds from an Ethereum smart contract on the Arbitrum Sepolia testnet. Both channels share the actor's public key with earlier npm samples, and OSM records 18 unique victim hostnames across Windows, Linux and macOS, which is consistent with a small, targeted operation rather than a broad campaign.
Government 2 stories
CISA Adds Four Exploited Vulnerabilities to the KEV Catalog, Including Both Check Point Flaws and the VeloCloud Orchestrator Bug
CISA added four vulnerabilities to the Known Exploited Vulnerabilities catalog on 22 September on evidence of active exploitation: CVE-2026-85102 (Check Point Multiple Products improper certificate validation), CVE-2026-93616 (Check Point path traversal), CVE-2026-93952 (Arista VeloCloud Orchestrator improper input validation) and CVE-2026-94127 (F5 BIG-IP APM heap-based buffer overflow). The F5 entry is the one without a matching news cycle behind it and deserves separate attention from administrators of the access policy manager, since BIG-IP APM is the component that brokers remote access into corporate applications. The additions land under Binding Operational Directive 26-04, CISA's risk-based vulnerability management directive, which requires federal civilian agencies to prioritise rapid remediation of KEV entries on publicly exposed assets that grant total control after exploitation, and which sets an expectation that agencies check for pre-compromise rather than simply patching. CISA notes the directive binds only federal civilian agencies but encourages all organisations to adopt the same prioritisation. The cadence is the point worth noting: this is the third KEV tranche in a week, following the 18 September Linux kernel additions and the 21 September Zyxel switch entry.
A Chinese-Speaking Actor Pulled Credentials From 996 Zyxel Switches and 18,566 Government Records Through WordPress
GreyNoise has attributed a sustained campaign to a Chinese-speaking actor it links to the Red Heron cluster, exploiting the wp2shell WordPress Core vulnerabilities CVE-2026-63030 and CVE-2026-60137 against at least 49 organisations in 29 countries, and the Zyxel GS1900 switch flaw CVE-2026-7273 against 996 devices in 48 countries since 17 August. The WordPress intrusions yielded at least 18,566 records — accounts, plaintext passwords and personally identifiable information tied to government and law-enforcement agencies — after the actor located credentials for a backend SQL database and used them in a password-spraying attack against an internal SQL server. In one Western government intrusion the operator spent 36 minutes running 17 scripts to bypass AMSI, escalate privileges through token impersonation and create a local administrator account. On the switch side, the exploitable payload was a PyArmor-obfuscated Python script that used TFTP to retrieve a collector covering device configurations, network information and hashed root-level credentials. The same actor also breached a Russian state organisation in occupied Ukraine — a red-on-red compromise — and this is the campaign behind yesterday's KEV addition for CVE-2026-7273, now with the exploitation figures attached.
Defence 1 story
SideCopy Moves From Indian Government Targets to Academic Institutions, With an mshta-Driven ReverseRAT Chain
Trellix researchers have documented the Pakistan-linked APT SideCopy — also tracked as TAG-140 and overlapping Transparent Tribe — using spear-phishing lures against Indian academic institutions, an expansion of a group whose historical focus has been Indian defence forces and government officials. The chain delivers a weaponised ZIP containing a Windows shortcut with a spoofed PDF icon and a `.docx` extension (`commskll.docx.lnk`); the LNK fetches an obfuscated HTML Application from `docsportal[.]in` and runs it through `mshta.exe`, which reflectively loads a DLL payload and self-deletes the HTA once the next stage initialises. That DLL drops three components — a batch script launched from a Windows Registry Run key to re-invoke `startT.hta` without user interaction, the secondary HTA stage, and a decoy document — and the HTA reconstructs a two-part XAML payload in memory to reflectively load a final DLL, keeping the core payload off disk. The relevance beyond India is the tradecraft pattern: a signed-by-nobody document lure, a living-off-the-land binary, and in-memory staging, which is the same combination the digest reported from Chinese-nexus groups this month. Active since at least 2019, SideCopy was attributed in June 2026 to a campaign against Afghanistan's Ministry of Finance.
Legal Services 1 story
Canada's Privacy Commissioner Opens an Investigation of IDScan Over a Breach Exposing Driver's Licence Scans
The Privacy Commissioner of Canada, Philippe Dufresne, has launched an investigation of IDScan.net, the identity-verification vendor whose cloud platform was breached in an incident reported to involve scans of 153 million people's driver's licences. The probe, announced on 21 September, will examine the company's security practices and whether its notifications to affected individuals met the requirements of Canada's federal private-sector privacy law — a second question that regulators increasingly ask separately from the breach itself, because the adequacy of notification is where most enforcement actions are ultimately grounded. IDScan told users on 4 September that hackers had obtained user data held in its cloud platform without saying how many customers were affected; the company learned of the incident on or around 1 September, hours after journalist Brian Krebs revealed the scans were for sale on the dark web. The technology is widely deployed in retail and hospitality for age and identity checks, so the affected population sits with the businesses that scanned documents as much as with the vendor, and no Australian or New Zealand equivalent action has been announced.
Healthcare 1 story
New Zealand's Privacy Commissioner Issues Compliance Notices to Manage My Health and Health NZ Over the December 2025 Breach
The New Zealand Privacy Commissioner issued Compliance Notices to both Manage My Health (MMH) and Health NZ this morning, finding that neither complied at the time of the December 2025 cyber attack with the security requirements of rule 5 of the Health Information Privacy Code. The notices follow the Commissioner's Phase 1 report in May 2026, which identified seven areas where security protections were ineffective; MMH has since improved three — the effectiveness of multi-factor authentication controls, restricting user access to information, and controlling unauthorised external access — and must complete the remaining requirements by 31 August 2027. Health NZ's notice concerns rule 5(1)(b) and the obligation to do everything reasonably in its power to prevent unauthorised use or disclosure before giving information to a service provider; its deadline is 29 January 2027. Commissioner Michael Webster drew attention to the affected population rather than the volume, noting that 90 per cent of the patients whose data was stolen are Māori in Northland. The significance is procedural: these are the notices the Commissioner signalled in May, and they convert a completed inquiry into enforceable, dated remediation obligations.
Energy & Utilities 2 stories
Nearly Two in Ten US Water and Wastewater Organisations Have Credentials Sitting in Infostealer Logs
SpyCloud built a database of 66,845 EPA-registered water systems, analysed 10,000 organisations and found 1,787 — close to two in ten — with identity data actively exposed through infostealer-harvested credentials, 258 of which carried logins for operational technology or remote-access systems. The most consequential finding is a supply-chain cascade rather than a utility: a single infected device at an unnamed smart-meter technology provider held saved logins tied to roughly 167 different US utility metering tenants, so one compromised laptop opened a door to many operators. SpyCloud is careful about what the measurement is — "it measures identity exposure, not confirmed intrusion" — and notes the study did not examine OT devices, though its own conclusion is that exposure concentrates in larger operators and in the vendor supply chain rather than in small utilities. The report follows months of attacks on the sector that US officials suspect are tied to Iran, and SpyCloud has begun a responsible-disclosure process, starting with a briefing for CISA. The practical use is as a proactive check: for utilities, whether their own vendor or contractor credentials appear in stealer logs is now an answerable question.
CISA Published Nine ICS Advisories in Two Days, Seven of Them for Siemens Products
CISA's industrial control systems team published a dense tranche of advisories on 21–22 September: eight covering Siemens products — Siveillance Control (icsa-26-265-03), SIPLUS and SIMATIC Products (04), the Desigo CC family (05), Industrial Edge Management (06), SIMOVE Fleetmanager and SIPLANT (07), WTV676 and WTV776 (08) — alongside OpenPLC Runtime v3 (09) and the lwIP lightweight TCP/IP stack (01–02). The spread is the interesting part: Desigo CC and Siveillance Control sit in building management and physical security, Industrial Edge Management in the industrial-DMZ layer that connects plant networks to the cloud, and OpenPLC is open-source logic-controller software used in small and research environments where patch discipline is thin. Advisories of this shape matter to the sector because the products are the ones asset owners cannot easily take offline — building management platforms run continuously and are frequently reachable from corporate networks. Repair guidance is vendor and version specific, and the advisories should be read against the operator's own asset inventory rather than treated as a single patch event.
Retail & Entertainment & Sport 1 story
A Hidden Muse Setting Lets Local Malware Turn Meta's Assistant Into a Dictation Interceptor and Account Takeover Path
Security researcher Patrick Wardle has published a proof of concept showing that malware already running as the logged-in macOS user can quietly take over Meta's Muse assistant by redirecting where it sends dictated prompts. The mechanism is an undocumented application preference, `endo_voyager_dictation_endpoint`, which any process running as that user can repoint at an attacker-controlled address without additional permissions. From there Wardle demonstrated three consequences: reading what the user dictated, injecting extra instructions that Muse treats as trusted, and capturing the account token — which matters because a Muse account can be signed in on multiple devices, so a stolen token lets the attacker direct the assistant beyond the compromised Mac. Muse is the personal AI agent Meta launched this month in the United States; it works across files, email, messages, the calendar, shopping and smart-home apps, using whatever access the user grants, and Wardle's argument is that this is exactly why it is a target: macOS Data Protection normally limits what malware can reach, and steering a signed app with broad permissions bypasses that limit without triggering security tooling, because the commands come from an app the user trusted. He also notes a remote attacker could deliver it through a ClickFix-style trick. Wardle's advice is blunt: do not install Muse.
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| ● Tier 1 | Very High | Official / first-party |
| ● Tier 2 | High | Established cyber journalism |
| ● Tier 3 | Moderate | General tech/news media |
| ● Tier 4 | Low | Social / unverified |