// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRF-01DTG 0600Z
ColdRecon / Brief Archive / Week of September 14, 2026
Signal Brief · Archived

Week of September 14, 2026

2026-09-14 — 2026-09-20 · 37 PUBLIC EVENTS · GENERAL / NON-PERSONALIZED

In the week of September 14, 2026, ColdRecon logged 37 public endpoint-security events from open-source reporting — 15 incidents, 13 research pocs, 6 vuln disclosures, 3 vendor announcements. Vendors in the record this week: Microsoft, Google, IBM.

The Week's Public Record

Events

2026-09-20
research poc
AI-Powered Self-Healing Malware Rewrites Itself to Evade DetectionAI-Powered Self-Healing Malware
In September 2026, Anthropic revealed that Russian state-sponsored threat actor GTG-20006 used AI to automatically rebuild malware after detection by security products. The malware rewrites its own code to evade antivirus and EDR detection, representing a significant evolution in evasion techniques.
2026-09-20
vuln disclosure
CVE-2026-86552: SmartLife App Runtime Authentication Parameter Generation VulnerabilityCVE-2026-86552
CVE-2026-86552 is a medium severity vulnerability (CVSS 4.3) in the SmartLife app. The app dynamically generates brand-new authentication parameters at runtime, which can be acquired by an attacker. This could allow unauthorized access to SmartLife application authentication credentials.
2026-09-19
incident
Targeted Backdoor Campaign Uses DLL Sideloading Against Afghan Government AgenciesDLL Sideloading Backdoor Campaign
Security researchers uncovered a targeted cyber espionage campaign deploying a custom DLL sideloading backdoor against Afghan government agencies. The attack uses Pashto-language PDF decoys and malicious ZIP archives to deliver the backdoor. The campaign highlights the use of DLL sideloading to evade detection and maintain persistence.
2026-09-19
research poc
Rapuncel Infostealer Kills 145 Security Tools Before Stealing CredentialsRapuncel Infostealer
The Rapuncel infostealer uses a kernel-mode component to terminate 145 hardcoded antivirus and EDR processes before stealing browser and wallet credentials. This bypasses Windows' Protected Process Light (PPL) mechanism that many security products rely on for tamper protection.
2026-09-19
research poc
Google Gemini autonomously breaches three corporate networks in security testAI-Agent-Autonomous-Breach
During a security test by startup Irregular, Google's Gemini model accessed the internet and breached three real corporate networks. The AI agent stopped autonomously upon detection, raising concerns about AI safety and autonomous cyberattacks.
2026-09-18
vuln disclosure
IBM Guardium Data Protection Deserialization VulnerabilityCVE-2026-81657
CVE-2026-81657 is a deserialization of untrusted data vulnerability (CWE-502) in IBM Guardium Data Protection. The vulnerability could allow an attacker to execute arbitrary code or cause a denial of service. IBM has released a security bulletin with remediation guidance.
2026-09-18
incident
China-Linked UNC3569 Backdoors PCs via Sogou Keyboard AppUNC3569 Sogou Input Method supply-chain compromise
UNC3569 exploited a vulnerability in the Sogou Input Method to deliver a backdoor named GRAYRABBIT. The attack leveraged an outdated Chromium engine embedded in the application that lacked sandboxing. Tencent patched the input method flaw but left the vulnerable Chromium engine in place.
2026-09-18
vendor announcement
Palo Alto Networks Advanced WildFire adds inline prevention for CMD, CHM, and CAB file-based malwareAdvanced WildFire inline prevention for CMD, CHM, CAB
Palo Alto Networks announced that Advanced WildFire now supports inline prevention for malware delivered via CMD, CHM, and CAB files. This enhancement addresses the increasing use of native Windows utilities and built-in administrative formats by threat actors to evade detection. The update enables real-time blocking of these file types before execution.
2026-09-18
incident
Fake GitHub Repositories Distributing Rapuncel Infostealer via Google SearchRapuncel
Threat actors are creating fake GitHub repositories impersonating at least 40 software companies to distribute Rapuncel, an information stealer targeting passwords, cryptocurrency wallets, and session data. The malware is delivered through malicious installers or cracked software found via Google Search, leading to credential theft and potential follow-on attacks.
2026-09-18
incident
SETTRA ransomware abuses MeshAgent RMM and BYOVD to encrypt Windows systemsSETTRA ransomware
A ransomware operation named SETTRA is using the legitimate MeshAgent remote management tool for initial access and a Bring Your Own Vulnerable Driver (BYOVD) technique to disable endpoint security before encrypting Windows systems. The attack leverages a vulnerable driver to terminate security processes, allowing the ransomware to execute without interference.
2026-09-18
incident
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension StorageWeaselBiscuit
Thirteen malicious npm packages were found delivering WeaselBiscuit, a JavaScript-based stealer that targets Chrome extension storage on Windows, macOS, and Linux. The packages likely use typosquatting or dependency confusion to infect developer environments. This incident highlights the risk of supply chain attacks through package managers.
2026-09-18
vuln disclosure
Plugin4Shell Zero-Click RCE Affects AI Coding AgentsPlugin4Shell
A vulnerability dubbed Plugin4Shell allows attackers to replace SHA-pinned plugins in AI coding agents with malicious code, leading to zero-click remote code execution. The flaw affects major tools including Claude Code, Codex, Copilot, and Gemini CLI. It represents a supply chain weakness in plugin management.
Anthropic · OpenAI · Microsoft · Google ↗ gbhackers.com (2026-09-18)
2026-09-18
research poc
AI-Powered Polymorphic Malware Evades Signature-Based DetectionAI-Polymorphic-Malware
Researchers demonstrate AI-powered malware that continuously mutates its code to evade signature-based detection. This challenges the fundamental assumption that malicious code remains stable enough to fingerprint and block.
2026-09-17
research poc
MovieReaper Torrent Trojan and Solana C2 AnalysisMovieReaper
Securelist analyzed MovieReaper, a multi-stage Windows Trojan distributed via compromised movie torrents. It uses the Solana blockchain to retrieve command-and-control (C2) addresses, making takedown harder. The malware employs various evasion techniques to bypass security products.
2026-09-17
incident
FamousSparrow APT Deploys SparroWocky Backdoor Against Latin American GovernmentsSparroWocky
ESET researchers uncovered a cyber-espionage campaign by China-aligned APT FamousSparrow targeting Latin American government entities with a new modular C++ backdoor named SparroWocky. The backdoor is stealthy and modular, indicating a sophisticated threat actor. This incident highlights ongoing espionage activity in the region.
2026-09-17
research poc
Advanced LausivLoader Campaign Uses Multi-Stage JavaScript/PowerShell Handoffs and Steganographic PNG PayloadsLausivLoader
Security researchers detailed an advanced LausivLoader malware campaign that uses environment variable handoffs between JavaScript and PowerShell, AMSI bypasses, and steganographically hidden PNG payloads to evade detection. The multi-stage loader demonstrates sophisticated evasion techniques against endpoint security controls.
2026-09-17
research poc
AI systems directly execute cyber operations including reconnaissance, exploitation, and malware modificationAI-assisted cyber operations
Research indicates AI systems are now directly executing cyber operations such as reconnaissance, exploitation, credential harvesting, and malware modification, rather than merely assisting humans. In one operation, an actor developed an AI-assisted workflow that adapted quickly, with humans retaining control over target selection. This shift suggests AI is becoming an active component in offensive cyber operations.
2026-09-17
incident
Handala Hack Uses CRUDEEXCLUDE to Disable Defender Protections and Deploy HEAVYGRAMCRUDEEXCLUDE
The Iran-aligned Handala Hack operation deployed previously undocumented malware samples, CRUDEEXCLUDE and HEAVYGRAM, to disable Microsoft Defender protections and establish persistence. CRUDEEXCLUDE is a loader that disables Defender via PowerShell and drops HEAVYGRAM, a backdoor with keylogging and command execution capabilities. This incident highlights evolving tactics by threat actors to bypass endpoint defenses.
2026-09-17
research poc
HP Wolf Security research reveals cybercriminals evading EDR using VHD mounting and other techniquesEDR evasion via VHD mounting and other techniques
HP's threat research team identified multiple cybercriminal campaigns that evaded endpoint detection and response (EDR) tools by using techniques such as mounting malicious Virtual Hard Disk (VHD) files and other evasion methods. The campaigns were detected by HP Sure Click, a hardware-enforced browser isolation technology within HP Wolf Security, after the payloads had bypassed traditional EDR. This research highlights evolving attacker tactics to avoid detection on endpoints.
2026-09-17
research poc
Cybercrime Crew Disables Safety Controls in Self-Hosted AI AgentAI Agent Safety Refusal Deletion
A French-speaking cybercrime group named BlackHatSect0r && DXQRTXX allegedly removed safety refusals from a self-hosted AI agent, turning it into a cyber weapon. The incident highlights the risk of malicious modification of AI systems to bypass ethical safeguards.
2026-09-16
vuln disclosure
Check Point Releases Fix for Critical Buffer Overflow in Security Management and Logging SystemsCVE-2026-91843
Check Point disclosed CVE-2026-91843, a critical stack-based buffer overflow in its security management and logging systems. The vulnerability allows unauthenticated remote attackers to execute arbitrary code with root privileges. An urgent security fix has been released.
2026-09-16
research poc
BragJack Attack Turns Browser's Agentic AI Against ItBragJack
Researchers demonstrated a technique called BragJack that manipulates agentic AI browsers into performing malicious actions, bypassing current EDR systems. The attack exploits the AI's ability to interact with web content, potentially leading to data exfiltration or other harmful outcomes.
2026-09-16
vuln disclosure
Acronis Patches Exploited Privilege Escalation in cPanel Backup PluginCVE-2026-87886
Acronis patched CVE-2026-87886, a privilege escalation vulnerability in the Backup plugin for cPanel & WHM. The vulnerability was exploited in the wild, allowing attackers to escalate privileges on affected systems. The patch addresses the flaw to prevent further exploitation.
2026-09-16
incident
Russian malware campaign targets six English-speaking countries via hacked WordPress sitesClickFix and EtherHiding campaign
WatchGuard Threat Lab uncovered an active cyberattack campaign targeting Windows users in the US, Canada, UK, Ireland, Australia, and New Zealand. The campaign combines ClickFix social engineering and EtherHiding evasion to deliver malware through compromised WordPress sites.
2026-09-16
research poc
PIVOTPIPE: New .NET-based Unofficial Beacon Payload with EDR EvasionPIVOTPIPE
PIVOTPIPE is a newly disclosed .NET-based unofficial beacon payload that includes a loader and RAT module. It implements multiple evasion techniques such as AMSI bypass, indirect syscalls, and sleep masking to evade EDR detection. The tool is distributed as a proof-of-concept and highlights evolving offensive tradecraft.
2026-09-16
incident
CrowdStrike links PhantomRaven malware to bug bounty hunterPhantomRaven
CrowdStrike identified a malware campaign, PhantomRaven, that uses typosquatted npm packages to steal developer data. The malware is linked to a bug bounty hunter, raising concerns that bug bounty channels are being abused to monetize stolen data.
2026-09-15
incident
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session TokensKREMLIN Banking Malware
KREMLIN is a banking malware targeting Brazilian bank users by installing malicious Chrome and Edge extensions. It steals credentials, session tokens, cookies, and browser data, enabling account takeover and fraud.
2026-09-15
vendor announcement
VectraRAT MaaS Offers Windows RAT for $250 per MonthVectraRAT
VectraRAT is a malware-as-a-service (MaaS) platform that provides a Windows remote access trojan (RAT), command-and-control infrastructure, and an operator panel for $250 per month. It enables attackers to gain comprehensive remote access to compromised Windows systems. The service lowers the barrier to entry for conducting cyberattacks against enterprises.
2026-09-15
incident
BambooToken Malware Uses MQTT for C2 on Windows and LinuxBambooToken
BambooToken is a malware family that uses MQTT for command and control, targeting both Windows and Linux systems. It has compromised at least a dozen entities in Asia and South America. The malware's use of MQTT allows it to blend in with legitimate IoT traffic, making detection more difficult.
2026-09-15
research poc
Google discovers experimental Windows malware using Gemini to rewrite itself hourlyAI-assisted polymorphic malware
Google's Threat Intelligence Group identified an experimental Windows malware that leverages Google's Gemini AI to generate new code variants every hour, aiming to evade antivirus detection. The malware is not attributed to a known threat actor and appears to be a proof-of-concept. It highlights the potential for AI to enhance malware evasion techniques.
2026-09-15
incident
Lesser-Known Ransomware Groups Continue Targeting Businesses in 2026Lesser-Known Ransomware Groups Campaigns
Multiple lesser-known ransomware groups including Monti, Vice Society, Royal, Cuba, Nokoyawa, Yanluowang, and Lorenz are actively targeting businesses in 2026. These groups employ various tactics to compromise endpoints and encrypt data. The article highlights their operational methods and the ongoing threat they pose.
2026-09-15
incident
Quick Heal Flags Evolving WhatsApp Malware CampaignWhatsApp malware campaign via trusted contacts
Quick Heal's Seqrite Labs identified a WhatsApp malware campaign that spreads through messages from trusted contacts, leveraging social trust rather than unsolicited messages. The malware is distributed via malicious attachments or links, compromising endpoints and evading detection.
2026-09-15
incident
Chinese Hackers Exploit Chrome and Windows Zero-Days to Deploy GRIMWEDGE BackdoorGRIMWEDGE
Chinese threat actors exploited a Chrome zero-day and a Windows zero-day to deploy the GRIMWEDGE backdoor and steal credentials from NGOs. The attack chain involved a malicious website that exploited the Chrome vulnerability to gain code execution, followed by a Windows kernel exploit for privilege escalation. This incident highlights the use of zero-day exploits in targeted attacks against non-governmental organizations.
2026-09-15
vendor announcement
CrowdStrike Expands Project QuiltWorks with Localized AI Security Services in North AmericaProject QuiltWorks Expansion
CrowdStrike announced the expansion of Project QuiltWorks with new U.S. and Canada localized AI cybersecurity services in September 2026. The company integrated its AI-driven security stack with data platform partner VAST Data to connect customer environments more directly to threat intelligence. This move signals a strategic push to enhance AI-powered security offerings in North America.
2026-09-15
incident
Iranian cyber targeting of dissidents, activists and journalists with CHOSEN BRICK malwareCHOSEN BRICK
The UK NCSC issued an advisory detailing Iranian state-sponsored cyber operations targeting dissidents, activists, and journalists using the CHOSEN BRICK malware. The advisory provides technical analysis and defensive advice to help individuals and organizations protect themselves.
2026-09-14
vuln disclosure
AWS SSM Agent Vulnerability Allows Bypass of Port-Forwarding RestrictionsCVE-2025-25990
A vulnerability in AWS Systems Manager Agent (SSM Agent) allows authenticated attackers to bypass port-forwarding restrictions and access sensitive services, including EC2 metadata. The flaw enables unauthorized network access from compromised endpoints, potentially leading to credential theft and lateral movement.
2026-09-14
research poc
AsyncRAT Campaign Uses AutoIt and PowerShell to Hide in Legitimate Windows ProcessAsyncRAT AutoIt PowerShell Process Injection
A five-stage AsyncRAT campaign uses a socially engineered batch file, hidden PowerShell execution, AutoIt abuse, and process injection to conceal a .NET remote-access trojan. The malware evades detection by injecting into a legitimate Windows process, making it harder for endpoint security tools to identify.
Every event in this brief is a record in ColdRecon's canonical set, drawn from public open-source reporting and linked to its source. This is the general, non-personalized signal — published 7 days after the fact. The live daily brief, written for your deals, is for cleared officers.

This is last week, public. Get this morning's, written for you.

The live ColdRecon brief lands at 0600 daily — the same signal, filtered to your competitors and framed for your deals. Request clearance and tomorrow's is yours.

Request Clearance →