CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (23 September 2026)

Published: Loading…

At a Glance

  • Microsoft's DCU led a takedown of EvilTokens, arresting two UK suspects and seizing over 50 phishing kit websites tied to 12,000 inbox compromises.
  • ShinyHunters claims it breached FBI systems via an Oracle PeopleSoft zero-day, stealing 2-3TB of employee and applicant data.
  • WordPress released 7.1.2 to fix CVE-2026-87902, an unauthenticated local file inclusion flaw already being actively probed hours after patching.
  • Cisco Talos disclosed CLOSEDQUORUM, a Windows implant that queries Gemini, DeepSeek, Qwen, and Mistral to autonomously choose post-compromise actions.
  • A Chinese-speaking threat actor exploited CVE-2026-7273 to exfiltrate data from nearly 1,000 Zyxel GS1900 switches across 48 countries.
  • Researcher Abdelhamid Naceri released BigDiskBuster, an unpatched zero-day that fills disk space to block Microsoft Defender updates.

Editorial Analysis

WordPress issued its second core patch in a week, with CVE-2026-93485 and CVE-2026-87902 exposing different weaknesses in how requests move between rendering and file-resolution stages. Attackers began probing the second flaw within hours of disclosure. For a platform used across a large share of the web, that leaves little time between a fix becoming public and vulnerable sites being tested, particularly when the affected code is widely reused.

CLOSEDQUORUM uses four LLM providers as a voting panel for its operations, with the models queried independently by the malware rather than directed interactively by an operator. The design effectively turns commercial AI APIs into part of the command infrastructure. Talos has not observed the malware operating with live credentials, so its capabilities remain largely demonstrated rather than confirmed in the wild, but the approach provides another way to distribute operational decisions across external services.

ShinyHunters' claimed FBI breach and Microsoft's EvilTokens takedown also illustrate the different levels of certainty surrounding major cyber incidents. ShinyHunters' claim of compromising a law-enforcement agency through an Oracle zero-day remains unverified, while Microsoft and law enforcement have confirmed arrests and infrastructure seizures against EvilTokens after the service had compromised 12,000 inboxes.

Highlights of the Day

WordPress Core Flaw Allowed Zero-Click Admin Takeover

Researchers disclosed CVE-2026-93485, an unauthenticated stored cross-site scripting flaw in WordPress core comment handling. A mismatch between comment sanitisation and later HTML formatting filters allowed attackers to inject a working JavaScript event handler without needing an approved comment or any user interaction. If triggered in an administrator's session, the flaw could be chained to remote code execution via the plugin upload feature. WordPress 7.1.1 fixes the issue with a corrected regular expression, backported to all supported branches down to 4.7.36.

Source: IDNSEC

Researchers Find First Malware Using AI Models as C2

Cisco Talos disclosed CLOSEDQUORUM, a Windows implant that delegates attack decisions to a panel of commercial large language models instead of a traditional command-and-control server. Four providers vote on actions such as credential theft, process injection, or persistence, with the majority choice executed automatically. The malware targets browser passwords, LSASS memory, and cryptocurrency wallets, exfiltrating stolen data through an encrypted Discord webhook.

ShinyHunters Claims FBI Breach via Oracle PeopleSoft Zero-Day

The ShinyHunters extortion group claims it breached FBI systems using an unpatched zero-day vulnerability in Oracle PeopleSoft, stealing 2–3TB of employee and applicant data. The group defaced the FBI Jobs website and says it is now exploiting the same flaw against other organisations, including Fortune 500 companies. The FBI confirmed it is investigating unauthorised activity affecting FBIjobs.gov but has not confirmed a breach or data theft.

Microsoft Exposes AI-Powered Phishing Kit Behind Mass Breaches

Microsoft detailed EvilTokens, a phishing-as-a-service platform that abused OAuth device code authentication to steal tokens from over 12,000 inboxes across 10,000 organisations. The AI-assisted kit, sold by threat actor Storm-2992, automated lure creation, target identification, and post-compromise reconnaissance via Microsoft Graph. Microsoft's Digital Crimes Unit worked with partners to disrupt the infrastructure supporting the service.

Source: Microsoft

Zero-Day Tool Blocks Microsoft Defender From Updating

A researcher published BigDiskBuster, an unpatched proof-of-concept tool that fills available disk space to prevent Microsoft Defender from installing signature and platform updates. The tool, released by former Microsoft researcher Abdelhamid Naceri, also blocks Windows Update from replacing the Malicious Software Removal Tool. No CVE or vendor advisory exists, and Naceri's three prior Defender exploits were each exploited in live attacks before being patched.

npm Package Compromise Delivered Self-Deleting Remote Shell

Attackers compromised a maintainer account for the npm package @dforge-core/dforge-mcp, using GitHub Actions trusted publishing to ship a malicious version 0.2.21 with valid provenance signatures. The four-stage payload activated only when the MCP server launched, installing a remote shell that deleted itself from disk afterwards. Researchers linked the loader to 65 repositories and found a related payload using Ethereum transactions for command-and-control communication.

Daily Coverage

Developments
Eviltokens TakedownShinyhunters Fbi ClaimWordpress 7.1.2 PatchClosedquorum Ai Malware
Vulnerabilities
CVE-2026-7273Gs1900-48Hpv2 Firmware <= 2.90(Abtq.1)C0 (High)CVE-2026-93485Wordpress 7.1 (High)CVE-2026-87902Wordpress (High)CVE-2026-65660Microsoft Sharepoint Enterprise Server 2016 16.0.0 (High)CVE-2026-89775Linux 7270Cc9157F474Dfc46750A34C9D7Defc686B2Eb (Critical)CVE-2026-93952Velocloud Orchestrator (Vco) On-Prem 5.2.0 (Critical)CVE-2026-86296Dir-822A A_101 (Critical)CVE-2026-90898Bifrost (Critical)CVE-2026-93616Quantum Security Management R82.20 With No Jumbo Hotfix (Critical)CVE-2026-94488Telegram Desktop 4.15.1 (High)
Threat Groups
SideCopySideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019. SideCopy's name comes from its infection chain that tries to mimic that of Sidewinder, a suspected Indian threat group.LAPSUS$LAPSUS$ is cyber criminal threat group that has been active since at least mid2021. LAPSUS$ specializes in largescale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.