CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (9 October 2026)

Published: Loading…

At a Glance

  • The FBI seized seven domains and, with six partner agencies, warned that Integrity Technology Group-enabled Flax Typhoon actors steal email and credentials worldwide.
  • The tensorlake@0.5.144 npm package delivers a Shai-Hulud worm that steals credentials and deletes the home directory if stolen GitHub tokens are revoked.
  • ASOS said attackers impersonated a trusted contact to obtain employee credentials and downloaded customer names, addresses, phone numbers, emails and dates of birth.
  • MonsterCloud owner Zohar Pinhasi was charged with wire fraud for secretly paying ransoms while claiming proprietary decryption tools, billing clients over $19 million.
  • Attackers are exploiting Atlassian CVE-2026-21589 and Bricksforge flaw CVE-2026-85097, a CVSS 10.0 unauthenticated file upload leading to remote code execution.
  • Cisco patched five critical NX-OS flaws allowing root code execution on Nexus switches, while SonicWall and Splunk also fixed critical vulnerabilities.

Editorial Analysis

The Tensorlake compromise exposes the limits of software provenance attestations. The malicious tensorlake@0.5.144 was committed to the project's main branch under a maintainer's name and published through the official release workflow, giving it a valid npm attestation. This records where the package was built, not whether its code is trustworthy, so a policy relying on provenance alone would have accepted it. The payload also makes credential revocation a destructive trigger: gh-token-monitor checks the stolen GitHub token every 60 seconds for up to 24 hours and deletes the victim's home directory if GitHub rejects it. The malware writes .claude/settings.json and .vscode/tasks.json into accessible repositories, allowing it to run again when a project opens in an AI coding tool or editor. The package reportedly has around 12,000 weekly downloads and shares code with the ChainDrop variant used in August.

The MonsterCloud case and the ASOS update highlight the consequences of incomplete incident reporting. Prosecutors allege that Zohar Pinhasi advertised an alternative to paying ransoms while secretly paying attackers for decryption keys, billing clients more than $19 million against over $8 million in ransoms. In one case, an $8,200 payment sat behind a $150,000 invoice. ASOS initially said basic contact details may have been accessed, then expanded the list after BBC reporting revealed that attackers held names, addresses, phone numbers, dates of birth and search histories. The company now says an employee's credentials were obtained through impersonation of a trusted contact, separate from the Snowflake compromise claimed in its original notification.

The Integrity Technology Group advisory documents state-linked intrusions using widely available tools: open-source scanners, EBurst password spraying against Exchange, SoftEther VPN clients for persistence and DCSync to extract Active Directory credentials. Because SoftEther is legitimate software, its presence may be less likely to trigger endpoint alerts. The FBI's seizure of seven domains linked to the MicroScan and FishHub tools disrupts part of the group's infrastructure, but some indicators date back to 2016 and should be checked before blocking.

Highlights of the Day

Joint Advisory Details China-Linked Actors Stealing Email and Credentials Globally

CISA, the FBI and partner agencies attribute the activity to threat actors enabled by Integrity Technology Group, who combine open-source scanning tools, cross-site scripting and password spraying against Microsoft Exchange servers. After access, they install SoftEther VPN clients for persistence and use DCSync to copy credentials from Active Directory. Custom scripts and the office-cli utility then exfiltrate email from on-premises and Microsoft 365 accounts across government, healthcare, manufacturing and IT sectors.

Source: CISA

US Charges Ransomware Remediation Firm Owner Over Secret Ransom Payments

Zohar Pinhasi, owner of MonsterCloud, was arraigned on wire fraud charges for allegedly claiming to decrypt ransomware with proprietary tools while secretly paying attackers for decryption keys. Prosecutors say he charged clients more than $19 million and paid over $8 million in ransoms, including one case of about $8,200 paid against a $150,000 fee. He faces up to 20 years in prison if convicted.

Tensorlake npm Package Steals Credentials and Wipes Home Directory on Token Revocation

StepSecurity reported that tensorlake@0.5.144 on npm runs a preinstall hook that steals GitHub, npm and cloud credentials, then republishes victims' packages and commits files that re-run it in Claude Code and VS Code. If a stolen GitHub token is revoked, a background service called gh-token-monitor deletes the victim's home directory. The malicious code was pushed to the project's main branch under a maintainer's name, so the release carries a valid npm provenance attestation.

ESET Tracks Two Years of MATCHBOIL Downloader Upgrades by UAC-0099

ESET documented the evolution of MATCHBOIL, a C# downloader used by the Russia-aligned UAC-0099 group, with samples dating from April 2024 to April 2026. Later versions switched to the .NET Reactor obfuscator, added sandbox checks, and began polling the command server every two minutes. All observed victims were in Ukraine, spanning transportation, manufacturing and energy companies, and the downloader typically installs the MATCHWOK backdoor.

Source: ESET

ASOS Breach Exposed Names, Addresses and Birth Dates of Customers

ASOS told customers that attackers hold detailed profiles including names, addresses, phone numbers, emails, customer numbers, dates of birth and website search history. The retailer said hackers gained access to an employee account by impersonating a trusted contact to obtain login credentials, then downloaded the data from an unnamed service. ASOS says bank details and passwords were not accessed, and the group Xuanyewen claimed to have used Simon AI.

Source: BBC News

Samsung Galaxy S26 Hacked Three More Times on Pwn2Own Ireland Day Two

On the second day of Pwn2Own Ireland 2026, researchers earned $232,500 by exploiting 45 unique zero-day vulnerabilities. The Samsung Galaxy S26 was compromised three times, while the Home Assistant Green hub and the Oracle Autonomous AI Database were also breached. Vendors have 90 days to patch the disclosed flaws before the Zero Day Initiative publishes them.

Daily Coverage

Developments
Flax Typhoon TakedownTensorlake Shai-Hulud WormAsos Data ExposureMonstercloud Fraud Charges
Vulnerabilities
CVE-2026-85097Bricksforge (Critical)CVE-2026-21589Bamboo Data Center All Other Versions (Critical)CVE-2021-36260N/A N/A (Critical)CVE-2026-47483Dcgm 0.0 To 4.5.2 (High)CVE-2026-102489Zammad 6.3.0 (Critical)CVE-2026-14990Datapower Gateway 10.6.0 10.6.0.0 (Critical)
Threat Groups
HAFNIUMHAFNIUM is a likely statesponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. HAFNIUM has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices.