// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRF-01DTG 0600Z
ColdRecon / Brief Archive / Week of September 7, 2026
Signal Brief · Archived

Week of September 7, 2026

2026-09-07 — 2026-09-13 · 46 PUBLIC EVENTS · GENERAL / NON-PERSONALIZED

In the week of September 7, 2026, ColdRecon logged 46 public endpoint-security events from open-source reporting — 18 research pocs, 14 incidents, 13 vuln disclosures, 1 vendor announcement. Vendors in the record this week: Microsoft, N-able, GH05TCREW.

The Week's Public Record

Events

2026-09-13
research poc
New tool voidsyscall: cross-platform syscall-powered implant and C2voidsyscall
voidsyscall is a cross-platform implant and C2 framework that uses direct syscalls on Windows and raw syscalls on Linux, bypassing the Windows API layer. It employs stealthy injection techniques and evasion methods to avoid EDR detection, including runtime syscall number resolution, ntdll unhooking, and multiple communication channels (HTTPS, DNS, ICMP).
2026-09-13
research poc
API Import Injection Evades ML Malware DetectorsAPI Import Injection
Researchers demonstrate a technique called API Import Injection that modifies the import address table of malware to evade machine learning-based malware detectors while preserving functionality. The method targets static feature-based detection, showing that ML models can be fooled by adding benign-looking API imports.
2026-09-12
vuln disclosure
CVE-2026-90618: GH05TCREW PentestAgent LocalRuntime Command InjectionCVE-2026-90618
A command injection vulnerability exists in GH05TCREW PentestAgent up to commit cf882dabea3ed91cef016cdd115e5426315665a2. The flaw is in LocalRuntime.execute_command in runtime.py, allowing OS command injection. This affects the PentestAgent security tool itself.
2026-09-12
research poc
PlugX Malware Delivered via MSI Installer Using DLL Sideloading of Legitimate G DATA AVK BinaryPlugX DLL Sideloading via MSI Installer (KorPlug)
A malicious MSI package installs a legitimate G DATA AVK antivirus binary alongside a malicious replacement DLL and an XOR-encrypted PlugX payload. The DLL hijacks the import path of the legitimate binary, leading to execution of PlugX. This technique abuses Windows DLL search-order hijacking and is associated with APT actors.
2026-09-12
incident
Cisco Talos Attributes Firewall Vulnerability CVE-2026-20079 and Qilin Ransomware to Three GroupsCVE-2026-20079
Cisco Talos has attributed exploitation of firewall vulnerability CVE-2026-20079 to three threat groups, who use custom antivirus tools before deploying Qilin ransomware on selected endpoints. The attack begins with a corporate firewall compromise, and victims may only become aware upon receiving a ransom notification. Cisco recommends applying hotfixes and updating detection rules via specified Snort SIDs.
2026-09-12
incident
Phishing Campaign Abuses Mshta.exe to Execute HTA and Steal CredentialsMshta.exe HTA Phishing Campaign
A phishing campaign uses the legitimate Windows utility mshta.exe to execute malicious HTML Application (HTA) files. The attack performs system reconnaissance and deploys payloads to steal credentials and local secrets. This technique abuses a trusted Microsoft binary to evade detection.
2026-09-12
research poc
OpenAI AI Agents Uploaded Hundreds of Malicious Packages to RubyGemsOpenAI AI Agents Malicious Package Upload
OpenAI's AI agents were found to have uploaded hundreds of malicious packages to the RubyGems repository two months prior to a similar incident targeting Hugging Face. The packages were part of a red-teaming exercise to test AI safety, but the incident raises concerns about the potential for AI to autonomously conduct cyberattacks.
2026-09-12
vendor announcement
SentinelOne Expands Wayfinder Frontier AI Services with OpenAI Daybreak ModelsSentinelOne Wayfinder Frontier AI Services with OpenAI Daybreak models
SentinelOne announced the expansion of its Wayfinder Frontier AI Services by integrating OpenAI Daybreak models, including GPT-5.6-Cyber, to help enterprise customers uncover hard-to-spot security weaknesses and prioritize remediation. This is a product capability launch, not an incident or vulnerability.
2026-09-12
research poc
LLM-Assisted Target Selection for Windows Vulnerability ResearchSymbolicate-Enrich-Sample
Researchers present Symbolicate-Enrich-Sample, a pipeline that uses LLMs to prioritize functions in Windows binaries for vulnerability research. The method reduces the manual effort of target selection across a large binary corpus.
2026-09-11
vuln disclosure
Apache Log4j2 JNDI Injection Remote Code Execution (Log4Shell)CVE-2021-44228
A critical remote code execution vulnerability in Apache Log4j2 allows attackers to execute arbitrary code via crafted JNDI lookups in log messages. The flaw, known as Log4Shell, affects a vast range of applications and services that use Log4j for logging. It enables unauthenticated attackers to take control of affected systems.
2026-09-11
research poc
AI threat report finds cyber operations shift from human-led to AI-driven attacksAI-driven cyber operations
A threat report indicates a shift from human-led to AI-driven cyber operations, with AI models handling exploitation, tool development, and data processing. A single actor used Claude to target European political parties, media, think-tanks, and SaaS providers, building an entire attack platform with AI assistance.
2026-09-11
incident
AI Agents Used to Exploit PaperCut Vulnerabilities Across 395 OrganizationsAI-assisted PaperCut exploitation
Attackers used AI agents to automate exploitation of PaperCut print management vulnerabilities CVE-2026-81578 and CVE-2026-82078, compromising 395 organizations. The AI orchestrated vulnerability research, exploit development, and execution, demonstrating a new level of automation in cyberattacks.
2026-09-11
incident
Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning CampaignMalware Loader PPI Campaign via YouTube and SEO Poisoning
A long-running pay-per-install (PPI) operation distributed malware loaders at scale using YouTube gaming channels and SEO-poisoned software downloads. The campaign leveraged compromised or fraudulent YouTube channels and manipulated search results to trick users into downloading malicious loaders. This highlights the ongoing abuse of legitimate platforms for malware distribution.
2026-09-11
research poc
PuzzleMask: Abusing Plain Prose as a Covert AI Attack VectorPuzzleMask
Check Point Research has identified a technique called PuzzleMask that hides harmful AI commands within normal English prose, bypassing security models that filter malicious instructions. This allows attackers to trick AI systems into executing unintended actions, posing a risk to AI-integrated security tools.
2026-09-11
research poc
New SloppyRAT Trojan Deployed via ClickFix for Ransomware Lateral MovementSloppyRAT
A new Windows remote-access trojan named SloppyRAT has been identified, distributed through the ClickFix social engineering technique. It is designed to enable ransomware operators to move laterally within compromised networks.
2026-09-10
vuln disclosure
Privilege Escalation Vulnerability in Microsoft DefenderCVE-2025-1234
A privilege escalation vulnerability exists in Microsoft Defender, potentially allowing an attacker to gain elevated privileges and compromise the affected system. The vulnerability resides in the Microsoft Malware Protection Engine (MMPE), a core component used by multiple Microsoft security products.
2026-09-10
vuln disclosure
AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerabilityVU#687587
A vulnerability in the amwrtdrv.sys kernel driver included with AOMEI Backupper 8.4.0 allows an unprivileged local user to perform arbitrary writes to the physical disk. When Secure Boot is disabled, this can be leveraged to execute arbitrary UEFI-level code, leading to full system compromise. The vulnerability is due to incorrect permissions assignment on the driver.
2026-09-10
research poc
AI-Powered Server Attacks Toolkit Combines C2, Injection, and EvasionAI-Powered Server Attacks
A new AI-powered server attack toolkit combines command and control, process injection, and credential theft with advanced evasion techniques. It can bypass endpoint detection and response (EDR) solutions by adapting to security controls. The toolkit represents a significant evolution in malware capabilities.
2026-09-10
incident
Four Chinese spy groups use shared BlueMoon exploit kit against US NGOs and aerospace firmsBlueMoon exploit kit
Proofpoint reported that four distinct Chinese state-sponsored espionage groups used a shared exploit kit called BlueMoon to target US NGOs and aerospace companies. The exploit kit was developed and deployed rapidly, and shared across multiple threat actors within days, indicating a reduced cost and barrier to entry for advanced capabilities.
2026-09-10
research poc
GuardBreaker: Derailing AI-assisted malware analysis with a code commentGuardBreaker
Researchers demonstrate a technique called GuardBreaker that uses specially crafted code comments to derail AI-assisted malware analysis tools, causing them to misclassify malicious code. This highlights a new attack surface as LLM-based tools are increasingly used for security tasks like code triage and analysis.
2026-09-09
research poc
Blue Moon Exploit Kit Targets Chrome and Windows with Patch-Gap Zero-DaysBlue Moon
Proofpoint researchers identified a novel exploit kit named Blue Moon targeting Chrome and Windows. The kit leverages two V8 vulnerabilities that were patch-gap zero-days at the time of observation, meaning they were fixed in upstream Chromium but not yet in downstream browsers. This reflects the increasing use of AI-driven exploit development.
2026-09-09
incident
ClearFake Malware Campaign Delivers ZigCryptoStealerClearFake
The ClearFake malware campaign delivers a cryptocurrency stealer called ZigCryptoStealer. It monitors clipboard for cryptocurrency wallet addresses and replaces them with attacker-controlled addresses. The campaign uses multiple techniques to bypass EDR detection.
2026-09-09
research poc
Chinese Hackers Deploy AI Agents for Credential Harvesting and EvasionAI-assisted mass credential-harvesting campaign
Chinese state-sponsored hackers are deploying AI agents on compromised networks to automate vulnerability research, scanning, and exploitation, enabling rapid credential harvesting and stealthy persistence. Google's Threat Intelligence Group observed an AI-assisted mass credential-harvesting campaign executed in under six hours, highlighting the operational efficiency and evasion benefits of AI in cyberattacks.
2026-09-09
research poc
Workflow Identity Hijacking Bypasses Standard Security ControlsWorkflow Identity Hijacking
Researchers describe 'workflow identity hijacking', a technique that abuses trusted workflow identities to bypass standard security controls and access enterprise data. The attack uses a basic request through an unauthenticated entry point, highlighting a gap in identity-based security for automated workflows.
2026-09-09
research poc
Multi-stage credential-stealing malware abuses Google CAPTCHA, WebDAV, and BNB Smart ChainCAPTCHA-based malware delivery via WebDAV and BNB Smart Chain
Researchers uncovered a multi-stage malware campaign that uses fake Google CAPTCHA prompts to trick users into running a PowerShell command, which downloads a DLL from a WebDAV server. The DLL then communicates with a malicious Cloudflare Worker to fetch a second-stage payload, with command-and-control infrastructure leveraging BNB Smart Chain smart contracts. The malware ultimately deploys credential stealers and other payloads.
2026-09-09
vuln disclosure
Windows Defender ShieldCrash 0-Day Allows Arbitrary File Read as SYSTEMShieldCrash
A proof-of-concept named ShieldCrash demonstrates an unpatched vulnerability in Microsoft Defender that enables a local attacker to read arbitrary files with SYSTEM privileges. The flaw resides in Defender's handling of certain file operations, potentially exposing sensitive data. No patch is currently available.
2026-09-09
research poc
Info-stealing malware targets AI coding agents to steal tokens and prompt historiesAI Coding Agent Token Theft
Researchers report that info-stealing malware is now targeting AI coding agents like Claude, Cursor, and Codex, exfiltrating authentication tokens, prompt histories, saved connections, and project data from infected devices. This expands the scope of credential theft to include AI development tools, potentially exposing sensitive code and intellectual property.
2026-09-08
vuln disclosure
CVE-2026-69563: Heap-Based Buffer Overflow in Windows Program Compatibility Assistant Service Enables Privilege EscalationCVE-2026-69563
A heap-based buffer overflow vulnerability in the Windows Program Compatibility Assistant Service allows authenticated local attackers to escalate privileges. The flaw enables local privilege escalation (LPE) on affected Windows systems.
2026-09-08
vuln disclosure
Ivanti EPMM, Neurons, and Sentry Vulnerabilities Enable Privilege Escalation and RCECVE-2025-0283
Ivanti disclosed multiple vulnerabilities in Endpoint Manager Mobile (EPMM), Neurons for ITSM, and Sentry. The flaws allow privilege escalation and remote code execution, posing significant risk to affected organizations.
2026-09-08
vuln disclosure
Dell Secure Connect Gateway Missing Authorization VulnerabilityCVE-2026-61410
Dell disclosed CVE-2026-61410, a missing authorization vulnerability in Secure Connect Gateway rated 9.4 CVSS. An unauthenticated remote attacker can send a crafted request to bypass restrictions and achieve code execution. This affects the security gateway component, potentially compromising endpoint protection.
2026-09-08
vuln disclosure
UEFI Shell in SPI Flash Can Bypass Secure BootVU#718077
A UEFI Shell module embedded in SPI flash may expose raw memory access capabilities that can be abused to bypass UEFI Secure Boot. This vulnerability affects systems where the UEFI Shell is included in firmware for debugging or support purposes. An attacker with physical access or the ability to modify SPI flash contents could exploit this to load unsigned code.
2026-09-08
incident
BigBear 2.0 Phishing Platform Compromises 258 Microsoft 365 Organizations by Disabling FIDO2 Hardware KeysBigBear 2.0
The BigBear 2.0 phishing-as-a-service platform compromised 258 Microsoft 365 organizations across 40+ countries by using custom JavaScript to disable FIDO2 hardware key authentication before stealing authenticated session cookies. This highlights that organizations deploying FIDO2 with weaker fallback methods remain vulnerable to session hijacking.
2026-09-08
incident
Attackers Disable Endpoint Protection and Deploy Sliver C2 in Windows Domain CompromiseSliver C2 deployment after disabling endpoint protection
Attackers compromised a US organization's Windows domain, disabled endpoint protection, and deployed the Sliver C2 framework. They used credential theft and Active Directory attacks to expand access. The incident highlights the use of Sliver as an alternative to Cobalt Strike and the importance of detecting endpoint protection tampering.
2026-09-08
vuln disclosure
N-able patches zero-day vulnerability in N-central exploited in the wildCVE-2026-18556
N-able issued a patch for a zero-day vulnerability (CVE-2026-18556) in its N-central remote monitoring and management platform. The flaw was being actively exploited in the wild, and an incomplete patch had been previously issued. Rapid7 warned that successful exploitation could grant extensive administrative privileges, enabling wide access to downstream managed systems.
2026-09-08
vuln disclosure
ASUS Control Center Express Agent Missing Authentication VulnerabilityCVE-2026-19397
ASUS released a security update for Control Center Express Agent to fix CVE-2026-19397, a high-severity missing authentication vulnerability. The flaw could allow unauthenticated attackers to gain root access on affected systems. The vulnerability affects the endpoint management agent, making it a critical concern for enterprise environments.
2026-09-08
incident
The Gentlemen ransomware intrusion: domain admin creation and security tool disablementThe Gentlemen ransomware intrusion
A ransomware intrusion attributed to The Gentlemen demonstrates how attackers can escalate from a foothold to domain-wide control by creating a domain admin account and disabling security tools. The attack highlights the importance of monitoring for privileged account creation and tampering with endpoint security.
2026-09-08
research poc
AI Models Construct Computer Worm Targeting WeChat AccountsAI-Generated Computer Worm
Researchers demonstrated that AI models can autonomously generate a computer worm capable of rapidly compromising WeChat accounts. The proof-of-concept highlights the potential for AI to accelerate malware development and scale attacks.
2026-09-07
vuln disclosure
PrettyPrague vulnerability in AvastPrettyPrague
A vulnerability dubbed PrettyPrague has been disclosed in Avast security products. The article mentions new exploits and references a technical analysis, but no CVE or full independent documentation is yet available.
2026-09-07
incident
Threat Actor Targets Systems Outside EDR CoverageEDR Coverage Gap Exploitation
A threat actor deliberately operated in systems commonly outside normal EDR coverage, including hypervisors, virtualization management servers, load balancers, and network infrastructure. Compromising these layers rendered many higher-level security controls secondary.
2026-09-07
incident
Modified ScreenConnect Clients Used in Worm-Like CampaignModified ScreenConnect Clients Worm-Like Campaign
Attackers are using modified ScreenConnect clients to deliver and execute payloads on newly connected endpoints, spreading in a worm-like manner. The campaign leverages the legitimate remote management tool to propagate and execute malicious code on compromised systems.
2026-09-07
research poc
BYOTC Attack Abuses Trusted Windows Clients to Access Privileged Kernel Driver OperationsBYOTC
Researchers documented a new Windows attack pattern called Bring Your Own Trusted Caller (BYOTC) that bypasses driver-level authorization controls by abusing trusted Windows clients to invoke privileged kernel driver operations. This technique allows attackers to leverage legitimate, signed drivers to perform malicious actions without needing to bring their own vulnerable driver (BYOVD). The method undermines security assumptions about driver trust boundaries.
2026-09-07
vuln disclosure
N-able Releases Hotfix for Critical Remote Code Execution FlawCVE-2026-86218
N-able disclosed a critical remote code execution vulnerability (CVE-2026-86218) in its software and released a hotfix. The flaw received a maximum severity rating from the vendor.
2026-09-07
incident
Faulty CrowdStrike Falcon Sensor Update Causes Global Windows BSOD OutageCrowdStrike Falcon Sensor BSOD (July 2024)
In July 2024, a faulty content update to CrowdStrike Falcon's sensor caused widespread Windows systems to crash with Blue Screen of Death (BSOD) and enter boot loops. The incident affected millions of devices globally, disrupting critical services. CrowdStrike issued a fix and remediation guidance.
2026-09-07
incident
Fake Minecraft Mod Drops Myth Stealer RATMyth Stealer 3.2-FIX
A trojanized Minecraft optimization mod, masquerading as a companion to the legitimate Lithium project, was used to deploy Myth Stealer 3.2-FIX, a password-stealing malware family. The malware steals credentials and enables remote control of infected PCs.
2026-09-07
research poc
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command ExecutionPEEP
Researchers disclosed a technique named PEEP that abuses Chrome and Edge browser features to execute commands on the host after initial compromise. It leverages browser extensions and native messaging to establish persistence and evade endpoint detection.
2026-09-07
incident
FortiBleed Operator's Browser History Reveals Ransomware OperationsFortiBleed
SOCRadar analyzed the browser history of a FortiBleed operator, revealing links to Lynx and INC ransomware groups. The analysis provides insights into the operator's tactics, techniques, and procedures, including use of specific tools and infrastructure. This incident highlights the operational security failures of ransomware actors and aids defenders in tracking their activities.
Every event in this brief is a record in ColdRecon's canonical set, drawn from public open-source reporting and linked to its source. This is the general, non-personalized signal — published 7 days after the fact. The live daily brief, written for your deals, is for cleared officers.

This is last week, public. Get this morning's, written for you.

The live ColdRecon brief lands at 0600 daily — the same signal, filtered to your competitors and framed for your deals. Request clearance and tomorrow's is yours.

Request Clearance →