BagheeraAltered's CyberSecurity Newsletter logo

BagheeraAltered's CyberSecurity Newsletter

Archives
Subscribe
September 8, 2026

The cleanup code is the attack surface

This week, a story about the part of your endpoint agent that exists to clean up after an attacker, and what happens when the attacker chooses the file it cleans.

In one week, the researcher known as Nightmare Eclipse published three proof-of-concept zero-days: PrettyPrague against the Avast sandbox, FalconFlank against CrowdStrike's Falcon Sensor, and GreenSection against a shared memory section used by Nvidia's Windows display components. It follows HardBreacher, a Kaspersky endpoint privilege escalation patched on 31 August. Kevin Beaumont says the Avast, CrowdStrike and Kaspersky exploits work.

Three of the four target the software you installed to stop this, and they cluster in the remediation path. FalconFlank abuses Falcon's Office macro removal to get an attacker-chosen DLL written into System32 and loaded as SYSTEM, on fully patched Windows 11 25H2 and Server 2025. HardBreacher hit Kaspersky's remediation engine; PrettyPrague hit Avast's sandbox. Same shape each time: highly privileged code, acting automatically, on a file the attacker put there. The severities differ, though, and the shared headline flatters the weakest: Gen Digital has fixed PrettyPrague, CrowdStrike has no CVE and no patch, and GreenSection so far crashes graphics applications rather than escalating anything.

https://www.securityweek.com/nightmare-eclipse-drops-crowdstrike-nvidia-avast-zero-day-exploits/

Did someone forward you this? Subscribe to this newsletter.

Anthropic has warned some Claude users that criminals are using information stealers to take over their accounts. Rather than guessing passwords or intercepting two-factor authentication (2FA) codes, the attackers steal the browser sessions that prove a user is already logged in. According to a warning email shared publicly by an affected user, the attackers used common infostealer malware to copy Claude login sessions from victims’ computers. They then used those sessions to access the accounts and consume their usage.
https://www.malwarebytes.com/blog/news/2026/09/infostealers-are-hijacking-claude-accounts-at-users-expense

Germany’s Federal Ministry of the Interior plans to establish a comprehensive set of measures to counter Russian sabotage, including cyberattacks. Federal Interior Minister Alexander Dobrindt told this to Bild. The security plan calls for the rapid deployment of special units in strategically important cities across the country — Berlin, Munich, Hamburg, Stuttgart, Düsseldorf, Frankfurt, Leipzig, Hanover and Cologne.
https://militarnyi.com/en/news/germany-to-create-comprehensive-measures-to-counter-russian-sabotage-and-cyberattacks/

FBI investigating 153 million US and Canadian driver’s licenses leaked on Russian cybercrime forum, including that of US SecDef Pete Hegseth — data is suspected to have come from an ID-authentication service provider
https://www.yahoo.com/news/us/articles/fbi-investigating-153-million-us-131405015.html

ATF confirms cyberattack hit system containing info on its investigation targetsThe prolific ransomware group Qilin claimed responsibility for the attack. ATF insists the incident was limited to a standalone system and hasn’t impacted critical operations.
https://cyberscoop.com/atf-doj-cyberattack-qilin-ransomware/

A large amount of personal data has also been leaked, particularly relating to state civil servants, including birth certificates, what appear to be absence lists, telephone numbers and home addresses. The hacker group "Rhysida" has published almost six terabytes of data from
Berlin's state administration on the dark web. Among the data is said to be highly sensitive information.
https://www.euronews.com/next/2026/09/05/berlin-cyberattack-hackers-leak-highly-sensitive-data-across-dark-web

Attackers are actively exploiting CVE-2026-32475, a CVSS 9.0 file upload flaw in the Elementor Pro WordPress plugin, to plant webshells on unpatched sites. If you run Elementor Pro 4.2.1 or earlier, update to 4.2.2 now. Active exploitation means adversaries are scanning for unpatched installs right now, not eventually.
https://0daynews.com/articles/2026-09-04-elementor-pro-cve-2026-32475-wordpress-webshell/

US and Canadian court data exposed in Thomson Reuters breach. Sealed court information and sensitive personal data were exposed in a breach of a Thomson Reuters records platform affecting courts in at least 12 U.S. states, the U.S. Virgin Islands and Canada, the company publicly disclosed Wednesday. Thomson Reuters has not said how the attacker gained access, who was responsible or how much data was taken. The number of people affected also remains unclear. The company stressed the breach occurred within its environment and was not caused by the networks, systems or data security of the affected courts.
https://therecord.media/thomson-reuters-cyberattack-data

Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices. In the past, we reported on Samsung settling a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR).
https://www.malwarebytes.com/blog/privacy/2026/09/lg-tv-flaws-could-let-attackers-listen-in-even-in-standby-mode

Google is suing to dismantle the infrastructure behind an alleged massive AI-powered cybercrime operation. On Friday, the tech giant announced a lawsuit against an alleged Chinese cybercrime network called Outsider Enterprise, which Google says uses AI in its campaigns to send scam text messages impersonating Google and other brands to steal passwords and credit card numbers.
https://techcrunch.com/2026/06/12/chinese-cybercrime-operation-that-used-ai-to-scam-hundreds-of-thousands-of-victims-sued-by-google/

A spate of cyberattacks on water systems in at least 12 states this July, which the U.S. government tentatively attributed to Iran, brought national attention to a growing concern for water operators in New Hampshire and across the country. The New Hampshire Department of Environmental Services is not aware of any impacts to New Hampshire systems from that particular spree of attacks, spokesperson James Martin said in an email to the Bulletin. But, he added, “systems are always being probed.”
https://www.nhpr.org/environment/2026-09-05/cyber-threats-challenge-for-nh-water-suppliers

Group-IB researchers have discovered BraZetsu, a malicious Python framework that turns infected Windows systems into a commodity for other criminals. The malware collects data about the victim and uses generative AI to assess the value of the compromised machine, after which access to it can be purchased on the criminal Infected Marketplace. According to the researchers, BraZetsu powers the criminal platform Infected Marketplace (also known as Banco de Infects), where attackers can purchase initial access to compromised hosts and remotely launch their own tools and malware on them. A $5.80 deposit is required to access the platform.
https://hackmag.com/news/brazetsu

Russian network monitoring firm confirms cyberattack claimed by pro-Ukraine hackers. Russian software developer Microolap confirmed that hackers had compromised some of its systems but denied claims that they gained access to its network monitoring platform or stole data belonging to major Russian companies.
https://therecord.media/russian-network-monitoring-firm-confirms-cyberattack-claimed-by-pro-ukraine-group

Boston Scientific has warned that a cyberattack will materially affect its third-quarter and full-year financial performance, putting consensus expectations at risk. The company said some revenue was disrupted and that it expects to recover only a portion of the impact, without yet providing a quantified estimate. The disclosure creates an immediate operational-risk overhang for the medical-device maker, particularly around sales continuity and the timeline for restoring affected systems. Investors will focus on any revised revenue guidance, the scale of lost business, and whether the disruption extends beyond the current quarter.
https://stop-fake.org/alerts/boston-scientific-flags-cyberattack-hit-to-q3-full-year-outl-aaefe5

A new malware campaign associated with the REVSTEALER information stealing malware has been discovered using another four additional malicious programs to secretly mine cryptocurrency, steal cryptocurrency data, and maintain access to compromised Windows systems.
https://www.cysecurity.news/2026/09/revstealer-malware-disables-window.html

A cybercrime group targeting Russian organizations has begun using custom Windows backdoors that send command traffic through two legitimate communication services. One version uses HiveMQ, an MQTT broker that relays messages between connected devices. The second communicates through an attacker-controlled server using Element, a messaging platform built on the Matrix protocol.
https://hackread.com/toy-ghouls-russia-windows-backdoors/

The United Arab Emirates has detected and contained coordinated cyberattacks on the aviation, energy, and education sectors since February, when fighting began between Iran, Israel, and the U.S., the country’s Cyber Security Council said on August 10. Hackers have made about 800,000 attempts a day since February, four times the prewar level.
https://restofworld.org/2026/uae-ai-cyberattacks-cyber-factory-defenses/

German authorities are investigating another trove of data stolen from Berlin’s government network after hackers published login credentials and other information over the weekend. The latest release follows a cyberattack discovered in mid-August that compromised two Berlin ministries responsible for urban development and housing, and for transport, mobility, climate protection and the environment.
https://therecord.media/germany-berlin-second-data-breach-city-agencies

A major security breach has hit the cryptocurrency sector as actors allegedly accessed a primary federation wallet to siphon hundreds of millions of dollars. Purported white-hat hackers have withdrawn approximately $320 million worth of Bitcoin from the Liquid Network following a significant security incident. The breach targeted the network's federation wallet, which holds reserves backing the digital assets circulating on the platform. Security analysts and network operators are currently auditing the intrusion to determine the exact vectors used to bypass multi-signature security controls.
https://leverageonheroesmedia.com/tech/hackers-breach-bitcoin-based-liquid-network-withdraw-320-million

An Advance Passenger Information System (APIS) database holding more than 220 million passenger and crew records, including passport numbers and flight details, was accessible online through a chain of security misconfigurations. The system appears linked to a Vietnamese organization, according to the researchers who discovered it.
https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/

Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect Solutions LLC (previously iConnect Soft Solutions LLC) and Garage2Global.
https://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.html

A zero-day vulnerability dubbed “StyleSmuggler” affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. The first exploitation incident was recorded on September 4 on a target running the latest security updates. E-commerce security company Sansec says that Adobe Enterprise Support confirmed earlier today that it was working on a fix but did not provide a timeline for its release. Magento is a popular open-source e-commerce platform by Adobe installed on more than 160,000 websites, including 14,000 of the top 1 million sites.
https://www.bleepingcomputer.com/news/security/magento-stylesmuggler-zero-day-exploited-to-deploy-linux-backdoor/

Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins.
https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html

A newly analyzed Linux malware sample, dubbed Tengu, combines Mirai-style botnet tradecraft with broad persistence, DDoS, SSH probing, and proxy capabilities. The stripped 32-bit ELF masquerades as a Linux kernel worker process while targeting servers, embedded devices, and IoT-adjacent systems.
https://gbhackers.com/tengu-mirai-style-linux-bot/

Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. Founded in Sydney in 2010, Mathspace is now used by thousands of schools across Australia, New Zealand, the United States, and the United Kingdom (3,432 in Australia and 3,557 abroad according to statistics reported by the company in 2023).
https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/

A newly exposed threat called PEEP turns Chrome and Edge into persistent backdoors, enabling attackers to run commands on the host system and steal sensitive browser data. Security researchers uncovered this Chromium-based toolkit after observing its ability to inject itself as a bookmarks extension and bypass browser and system protections.
https://thedailytechfeed.com/peep-malware-exploits-chrome-edge-to-become-remote-backdoor/

Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. In total, the breach has affected 81,000 customers after Trezor initially disclosed on August 13 that attackers accessed the data of nearly 14,000 customers, including their full names, shipping addresses, email addresses, and phone numbers.
https://www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/

ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week. ScreenConnect is an on-premises or cloud-hosted remote access platform typically used by managed service providers (MSPs), IT departments, and support teams for troubleshooting, patching, and system maintenance.
https://www.bleepingcomputer.com/news/security/connectwise-warns-of-new-screenconnect-flaw-without-patch/

MikroTik has found a security vulnerability in RouterOS and releases containing a fix have been published in all channels. This is an important security update. Most configurations are not at risk, but upgrading is highly recommended.
https://mikrotik.com/supportsec/september-2026-vulnerability

Don't miss what's next. Subscribe to BagheeraAltered's CyberSecurity Newsletter:
Older → The malware comment that makes AI refuse to keep reading
Powered by Buttondown, the easiest way to start and grow your newsletter.