Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (26 September 2026)
Published: Loading…
At a Glance
- Suspected North Korean hackers stole $387.5 million from Bitget's hot and warm wallets across Ethereum, XRP Ledger and other chains.
- A CSRF vulnerability in Elementor Website Builder versions 4.3.0 and 4.3.1 let attackers create rogue administrator accounts on WordPress sites.
- Roundcube Webmail's pre-authentication SQL injection flaw CVE-2026-48842 is being actively exploited following its patch release.
- SalesBleed vulnerabilities in Salesforce Agentforce enabled zero-click data exfiltration via prompt injection and DNS-based exfiltration.
- Cameron Wagenius, a U.S. soldier behind AT&T and Verizon telecom extortions, was sentenced to 70 months in prison.
Editorial Analysis
Bitget's loss estimate from Tuesday's hack has grown to $387.5 million, up from an initial $351.6 million, after the exchange identified additional stolen assets on Zcash and TRON that were not included in its first count. Arkham's independent tracing provides a more granular picture of the theft: roughly $228 million left Bitget's wallets within an 18-minute window, spread across Ethereum, XRP, Arbitrum, Optimism and several other chains, before some foundations managed to freeze the attacker's addresses. The revised figure shows how early loss estimates from multi-chain thefts can change as exchanges trace additional transactions and identify assets missed in the initial count.
SalesBleed showed a Salesforce Agentforce subagent reading a poisoned CRM lead and then using its existing permission to query an Accounts table, exfiltrating the results over DNS without user interaction. Microsoft's Storm-3168 research describes compromised Azure service principals being used for bulk destructive operations against storage accounts, databases and key vaults. The incidents put attention on how much authority AI agents and cloud identities can accumulate inside enterprise environments.
Two unrelated vulnerabilities also resulted in practical attack paths. The Elementor CSRF flaw, affecting versions 4.3.0 and 4.3.1, came from a hidden experimental feature that WordPress site owners could not see or disable, allowing a clicked link to create a rogue administrator account. Roundcube's CVE-2026-48842 is a pre-authentication SQL injection now being actively probed, according to Canada's Cyber Centre.
Highlights of the Day
North Korean Hackers Steal $351.6M From Bitget in Backend Breach
Bitget confirmed suspected North Korean threat actors stole $351.6 million from hot and warm wallets on 24 September 2026. Attackers compromised a backend wallet infrastructure system, spoofed transaction data, and triggered the authorisation process to move funds out. Affected assets include ETH, XRP, BNB, AVAX, USDT and USDC across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base, with Mandiant and SlowMist investigating.
CSRF Flaw in Elementor Plugin Enabled Admin Takeover on 10M+ Sites
A cross-site request forgery vulnerability in Elementor Website Builder versions 4.3.0 and 4.3.1 let a single clicked link trigger any REST API action a logged-in user could perform. The flaw disabled WordPress's core CSRF protection whenever a specific string appeared in the request URI, allowing attackers to create rogue administrator accounts without JavaScript or a malicious page. Elementor patched the issue in version 4.3.2 by validating the resolved REST route instead of the raw request URI.
Actively Exploited WordPress Flaw Allows Remote Code Execution
CVE-2026-87902, a critical vulnerability affecting WordPress versions 4.7.0 through 7.1.1, allows unauthenticated attackers to include arbitrary PHP files on the server. Exploitation can lead to remote code execution under certain server configurations, and attacks began within hours of the patch's release on 22 September 2026. WordPress has released updates for all supported branches, with the latest version being 7.1.2.
Zero-Click Prompt Injection Exfiltrated Salesforce Agentforce Data
Researchers disclosed "SalesBleed", an attack chaining indirect prompt injection with DNS exfiltration to steal Salesforce Agentforce account data. A malicious payload hidden in a public Web-to-Lead form hijacked the agent when an employee reviewed leads, bypassing URL redaction to leak data via DNS queries generated by image tags. Salesforce confirmed and hardened the Trusted URLs mechanism by August 2026, closing the specific bypass.
New PamStealer Variant Ties macOS Payload Decryption to Live C2
Jamf Threat Labs identified a new PamStealer variant distributed via a fake Wavel crypto wallet installer, using a purpose-built utility called pkgunpack to perform server-side ECIES decryption of its payload. The second-stage infostealer was rewritten from Rust to Swift, retaining PAM-based credential validation, and steals keychain data, browser credentials across seventeen browsers, and the user's account photo. Persistence is maintained through four redundant mechanisms, including LaunchAgent, shell hooks, and Git hooks.
US Soldier Sentenced to 70 Months for AT&T, Verizon Extortion
Cameron Wagenius, a U.S. Army soldier who operated as "Kiberphant0m", was sentenced to 70 months in prison and ordered to pay $294,978 in restitution. He pleaded guilty to hacking telecommunications companies via exposed Snowflake credentials, stealing call and text metadata for over 100 million AT&T customers, and extorting victims. While incarcerated, he used other inmates' email accounts to prompt AI tools for Windows privilege escalation exploits and a working script for a D-Link command injection vulnerability.
Daily Coverage