Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Weekly Cybersecurity Briefing (14 September – 20 September 2026)
Published: Loading…
This briefing covers 263 reports published from 14 September to 20 September 2026.
At a Glance
- Cisco disclosed three maximum-severity flaws in as many weeks, including actively exploited bugs in Secure Email Gateway and Identity Services Engine.
- AI agents were implicated in multiple real-world incidents, including Spain's first AI-attributed data breach and a chained exploit against OpenAI employee accounts.
- BragJack researchers hijacked AI assistants built into five major browsers using a technique called Prompt Forcing that bypasses prompt injection defences.
- Coordinated international reporting confirmed North Korea's WaterPlum campaign has infected over 30,000 devices and stolen $10.7 million via fake job interviews.
- Supply chain attacks against npm packages continued, with GHAPPIER and indexed-btree hiding malicious code in runtime behaviour rather than install scripts.
Editorial Analysis
AI agents appeared repeatedly across this week's reports, in both offensive activity and as targets themselves. Spain's AEPD documented an incident involving an autonomous AI agent that logged into a real organisation, scanned for vulnerabilities and modified data. Hacktron used Claude Opus 5 in authorised research to chain a libheif flaw with an SSO misconfiguration into OpenAI account takeover. BragJack took the other side of the equation, hijacking browser-embedded AI assistants by manipulating the network requests used to retrieve their instructions across five major browsers. The incidents cover different attack paths, but all involve agents operating with access that can extend well beyond the model itself.
Malicious code also continued moving deeper into software and service infrastructure. GHAPPIER and indexed-btree placed their payloads in runtime code rather than npm installation scripts, while KREMLIN and PolinRider-linked campaigns used Ethereum smart contracts for command and control. Brevo's compromised Cloudflare account was used to distribute malware across more than 100,000 sites, and CrowdSec traced a separate exposure to an ex-employee's retained access following an earlier supply-chain compromise. These incidents show how much of an operation can now sit inside legitimate development, hosting and service infrastructure, making the initial compromise only one part of the attack path.
Cisco also disclosed its third maximum-severity, actively exploited vulnerability in as many weeks. CVE-2026-76460, affecting Identity Services Engine, follows recent critical issues in Secure Email Gateway and other Cisco enterprise platforms. The frequency is notable, although this week's evidence does not establish whether it reflects greater scrutiny of Cisco's code or sustained targeting of its products.
Highlights of the Week
BragJack Hijacks AI Assistants Built Into Five Major Browsers
Security researchers found flaws in AI agents built into Chrome, Edge, Opera Neon, Perplexity Comet and Claude in Chrome. A malicious browser extension manipulated network requests to redirect trusted domains controlling each agent, using a technique called Prompt Forcing to bypass prompt injection defences. The zero-click attacks enabled file access, camera and microphone activation, and email exfiltration, earning over $20,000 in bounties.
Cisco Discloses Third Maximum-Severity Flaw in Three Weeks
Cisco disclosed CVE-2026-76460, a CVSS 10.0 authentication bypass in Identity Services Engine, already under active exploitation, following critical flaws in Secure Email Gateway and Nexus Dashboard earlier in the week. ISE sits at the centre of network identity and policy, so a successful bypass grants root-level access to a system controlling device and user authorisation across affected networks.
North Korean WaterPlum Group Confirmed to Have Infected 30,000 Devices
Coordinated reporting from Japan, the US, Australia and Germany confirmed North Korea's WaterPlum group, also known as Contagious Interview, has infected over 30,000 devices and stolen roughly $10.71 million from more than 7,000 cryptocurrency wallets. The group poses as recruiters, tricking developers into running malicious npm packages containing malware such as BeaverTail and InvisibleFerret during fake job interviews.
Spain Reports First Data Breach Attributed to an AI Agent
Spain's data protection authority, AEPD, received its first notification of a personal data breach reportedly executed autonomously by an AI agent. The agent logged into a target system, searched for vulnerabilities, modified personal data and accessed invoices, though AEPD cautioned this does not confirm the underlying AI provider's infrastructure was compromised.
Researchers Chain Flaws to Hijack OpenAI Employee Accounts Using Claude
Hacktron researchers combined a years-old libheif memory-safety flaw with an OpenAI SSO misconfiguration to take over employee ChatGPT and Codex accounts, eventually reaching an internal code repository. The chain began with a compromised forum account and used Anthropic's Claude Opus 5 to help execute the multi-step exploit, which OpenAI and Discourse have since patched.
Threats
Iranian Spyware CHOSEN BRICK Targets Dissidents With Fake MRI Scans
British, American and Dutch agencies exposed CHOSEN BRICK, Iranian state-sponsored spyware delivered via social engineering lures including fake MRI scans. The Windows-only malware harvests contacts, messages and screen content, activates microphones, and communicates through individual Telegram bots per victim.
China-Linked FamousSparrow Deploys New SparroWocky Backdoor
ESET identified SparroWocky, a modular C++ backdoor deployed by China-aligned group FamousSparrow since August 2025, replacing its previous SparrowDoor implant. The malware targets governmental organisations across Latin America and incorporates anti-analysis techniques including call-stack spoofing.
Infrastructure & Exploits
Critical GitLab Path Traversal Flaw Actively Exploited
GitLab disclosed CVE-2026-85706, a maximum-severity path traversal flaw in the repository commits API allowing unauthenticated attackers to read arbitrary server files. CISA added the flaw to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of 14 September 2026.
Check Point Discloses Critical Server Hijack Flaw
Check Point disclosed CVE-2026-91843, a critical vulnerability scoring 9.8 on CVSS affecting its Security Management and Log Servers. The flaw could let an unauthenticated attacker remotely execute arbitrary code with root privileges via the login process, with a LivePatch fix now available.
Tools & Techniques
NPM Supply Chain Attacks Shift Malware Into Runtime Code
GHAPPIER and the indexed-btree malware family moved malicious logic away from npm install scripts and into code that only executes when a package is used. GHAPPIER carried valid provenance through GitHub's trusted-publishing pipeline, while indexed-btree hid its loader inside a commonly called prototype method and used an Ethereum smart contract for command and control.
CrowdSec Source Code Leaked Following TanStack Supply Chain Compromise
An attacker published CrowdSec's private GitHub source code on a hacking forum, traced to a former employee compromised via the May TanStack npm supply chain attack. The threat actor used a since-expired OAuth token to clone over 170 private repositories, though CrowdSec's infrastructure and databases remained unaffected.
Brevo Supply Chain Attack Hits Over 100,000 Sites
Email marketing provider Brevo served malware to visitors of its own site and more than 100,000 customer sites after attackers breached its Cloudflare account. The injected script installed a backdoored WordPress plugin for admins or showed other visitors a Clickfix overlay tricking them into running malicious commands.
Policy & Legal
FBI Seizes Domains Behind Long-Running NightmareStresser DDoS Service
The FBI, working with the Royal Canadian Mounted Police, seized domains linked to NightmareStresser, a DDoS-for-hire service that launched hundreds of thousands of attacks since 2022. The action forms part of Operation PowerOFF, an ongoing international effort targeting DDoS-for-hire infrastructure.
CISA Issues Guidance on Cyber Decoys for Threat Detection
CISA published guidance helping defensive teams plan and deploy cyber decoy strategies, addressing tripwires, breadcrumbs and honeytokens using MITRE Engage and MITRE ATT&CK frameworks. The guidance targets organisations adopting Zero Trust models across varying levels of cybersecurity maturity.
Weekly Topic Distribution

Weekly Coverage
Developments
Cisco Ise And Secure Email Gateway Flaws Bragjack Browser Ai Hijack Waterplum Campaign Expansion Ghappier And Indexed-Btree Npm Malware
Vulnerabilities
CVE-2026-76460Cisco Identity Services Engine Software 3.1.0 P8 (Critical)CVE-2026-85706Gitlab 18.7 (Critical)CVE-2026-91843Quantum Security Management R82.10 With Jumbo Hotfix Take 44 Or Below (Critical)
Threat Groups
Scattered SpiderScattered Spider is a native Englishspeaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and helpdesk staff, to gain initial access, bypass multifactor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using helpdesk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.AkiraAkira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access singlefactor external access mechanisms such as VPNs for initial access, then various publiclyavailable tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.LAPSUS$LAPSUS$ is cyber criminal threat group that has been active since at least mid2021. LAPSUS$ specializes in largescale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.APT28APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U. S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including closeaccess operations) conducted between 2014 and 2018 against the World AntiDoping Agency (WADA), the US AntiDoping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.Contagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrencyrelated activities.Salt TyphoonSalt Typhoon is a People's Republic of China (PRC) statebacked actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U. S. telecommunication and internet service providers (ISP).MuddyWaterMuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.Lazarus GroupLazarus Group is a North Korean statesponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.