Weekly Threat Intel Report — 2026-W38: 14-20 September 2026
TL;DR
The week's headline event came from within the criminal ecosystem. ShinyHunters compromised the Cl0p ransomware leak site, defaced its Tor presence, and claimed to have exfiltrated server data along with the onion service's private keys. The group is now threatening to extort Cl0p directly and re-extort organizations that already paid Cl0p ransoms. Nation-state activity included ESET's publication of SparroWocky, a new backdoor attributed to the China-nexus FamousSparrow (Earth Estries) group, and SentinelLabs' report on DPRK TraderTraitor operators resurfacing with backdoors delivered through Terraform lock-file lures during fake job interviews. Cisco disclosed a maximum-severity authentication bypass in Identity Services Engine (CVE-2026-76460, CVSS 10.0). CISA added three actively exploited Linux kernel flaws to KEV. Microsoft's September Patch Tuesday shipped 973 CVE fixes. A joint law-enforcement advisory attributed 30,000 device compromises and more than $10.7M in cryptocurrency theft to a DPRK cluster tracked as WaterPlum.
Notable Activity by Actor
ShinyHunters versus Cl0p
Over the weekend of 19-21 September, ShinyHunters defaced the Cl0p ransomware group's dark-web leak site, according to reporting from BleepingComputer, The Record, and DarkReading. Beyond the defacement, ShinyHunters claimed to have stolen server data and the private keys used to operate Cl0p's Tor hidden service. Posts left on the site threaten both Cl0p itself and Cl0p's prior victims with further extortion.
If ShinyHunters genuinely obtained server-side data, victims that paid Cl0p ransoms now face renewed exposure from a second actor. That risk is not hypothetical: DarkReading reports that ShinyHunters is signaling intent to monetize any recovered victim data. Organizations that engaged with Cl0p in prior incidents should assume the possibility of re-extortion and prepare communications and legal responses accordingly.
The incident is notable regardless of the veracity of every claim. A well-known extortion crew publicly compromising the infrastructure of a peer group suggests continued turbulence in the ransomware and extortion market following law-enforcement actions and reputational damage across multiple major brands.
Earth Estries (FamousSparrow) and SparroWocky
ESET published detailed research on SparroWocky, described as the new flagship backdoor of the FamousSparrow group (tracked as Earth Estries and overlapping with GhostEmperor). DarkReading, drawing on the same ESET research, reported that the campaign is aimed at US political interests in Latin America and framed it in the context of US-China competition for regional influence.
SparroWocky supports a broad command set for post-compromise tasking. Defenders should treat the ESET publication as a source for detection engineering opportunities and hunt for the described host and network indicators.
TraderTraitor macOS backdoors resurface
SentinelLabs documented DPRK TraderTraitor operators building a foothold on a DevOps engineer's Mac at a target with no cryptocurrency ties. The delivery mechanism was a Terraform dependency lock file supplied as part of a fake job interview coding assessment. The campaign confirms two patterns worth flagging.
First, DPRK job-interview lures continue to be effective against technical staff, and their target scope now extends beyond crypto-adjacent employers to any organization with high-value engineering talent. Second, the abuse of dependency lock files as a malware carrier is a supply-chain vector that most host-based defenses do not inspect closely. Engineering teams should treat interview coding materials as untrusted code and run them only in isolated environments.
Qilin and Japan's ransomware landscape
Cisco Talos reported that ransomware incidents in Japan rose 4.7% year over year in the first half of 2026. A group calling itself The Gentlemen was the most active, with leak-site listings more than doubling from January to July. Qilin ranked second and, per Talos, showed signs of using AI in its operations. Small and medium enterprises with capital under one billion yen accounted for 80% of victims.
Emerging Threats
Cisco ISE authentication bypass rated 10.0
DarkReading covered CVE-2026-76460, an authentication bypass affecting API endpoints in Cisco's Identity Services Engine. The flaw carries a CVSS score of 10.0. ISE is commonly deployed as the network access control brain for enterprise environments, so any successful bypass has downstream consequences for network segmentation and identity assertions. Organizations running ISE should treat vendor patching as urgent and audit API-exposed interfaces for unexpected access.
CISA adds three exploited Linux kernel CVEs to KEV
CISA warned on 21 September that three Linux kernel vulnerabilities are being actively exploited, with one rated critical. Kernel-level exploitation typically yields privilege escalation or persistence, so patch cycles for Linux fleets should be prioritized. Organizations that manage large numbers of embedded or appliance-based Linux systems should review vendor advisories, since many such devices lag mainline kernel patching.
September Patch Tuesday: 973 CVEs
Sophos reported that Microsoft's September Patch Tuesday addressed 973 CVEs, with 718 fixes across Windows components. Microsoft also warned that the September updates broke the built-in File History backup feature on some systems, which is worth flagging for teams that rely on Windows-native backups as part of ransomware recovery.
WaterPlum joint advisory
A joint law-enforcement advisory covered by BleepingComputer attributed roughly 30,000 device compromises and more than $10.7 million in stolen cryptocurrency to a DPRK-linked cluster tracked as WaterPlum between December 2025 and July 2026. The activity is consistent with the broader DPRK pattern of revenue generation through cryptocurrency theft.
CHOSEN BRICK spyware
UK NCSC and allied partners on 15 September exposed CHOSEN BRICK, spyware attributed to Iranian state actors and used to target dissidents, activists, and journalists. NCSC published technical analysis and defensive guidance. The advisory reinforces the personal-device threat model for individuals in politically sensitive roles.
AI agent and browser-extension attacks
Several items this week reinforced that AI-integrated tools are now a live attack surface. BleepingComputer covered BragJack, a proof-of-concept that hijacks AI browser agents in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome through a single malicious extension. Researchers also escaped OpenAI's Codex sandbox two separate ways, including from its most restrictive mode; OpenAI has patched both issues. DarkReading reported a case in which an AI agent was used to breach a Spanish organization and modify personal data.
Supply chain: BigCommerce and npm
BigCommerce notified merchants of breaches after attackers compromised credentials for third-party Ribon applications and injected malicious scripts into online stores. Separately, a malicious npm package named indexed-btree evaded install-script sandboxing by hiding malicious behavior in runtime code paths, per BleepingComputer. Both incidents highlight that install-time and third-party-integration inspection remain gaps in most software supply chain programs.
Defender Takeaways
- Treat CVE-2026-76460 (Cisco ISE, CVSS 10.0) as immediate-priority patching. Audit ISE API exposure to internal and external networks.
- Prioritize the three Linux kernel CVEs added to CISA KEV on 21 September and confirm coverage across appliance and embedded fleets.
- Assume Cl0p victim data is now in ShinyHunters' possession and prepare for the possibility of re-extortion. Review prior communications and legal posture with counsel.
- Warn engineering staff that job-interview coding exercises, particularly those involving Terraform, npm, or other dependency lock files, should be executed only in isolated environments.
- Review install-script and runtime inspection for npm and other package dependencies. The indexed-btree case shows install-script hooks alone are insufficient.
- Validate that Windows-native backups (including File History) still function after September updates, given Microsoft's own advisory that they may break.
- For any AI browser agent or coding-assistant deployment, restrict extension installation, sandbox execution surfaces, and monitor for prompt-injection indicators consistent with BragJack and Codex sandbox escape research.
- Distribute the UK NCSC CHOSEN BRICK advisory to any staff or affiliates who may be targeted based on political activity or journalism work.
Sources
- BleepingComputer, "ShinyHunters hacks Clop leak site, threatens to extort ransomware gang," 19 September 2026. https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/
- The Record, "ShinyHunters cybercrime gang takes over Cl0p ransomware site," 21 September 2026. https://therecord.media/shinyhunters-clop-cyberattack-website
- DarkReading, "ShinyHunters Hacked Clop. Now What About Clop's Victims?" 21 September 2026. https://www.darkreading.com/cyberattacks-data-breaches/shinyhunters-hacked-clop-what-about-clops-victims
- ESET WeLiveSecurity, "Beware the SparroWock: The backdoor that bites, the commands that catch," 17 September 2026. https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/
- DarkReading, "China's FamousSparrow APT Spies on US Politics in Latin America," 17 September 2026. https://www.darkreading.com/cyberattacks-data-breaches/china-famoussparrow-spies-latin-america
- SentinelLabs, "TraderTraitor Backdoors Resurface on Victim With No Crypto Ties," 18 September 2026. https://www.sentinelone.com/labs/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties/
- Cisco Talos, "Ransomware incidents in Japan in the first half of 2026," 17 September 2026. https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/
- DarkReading, "Cisco Zero-Day Highlights API Endpoint Authentication Issues," 18 September 2026. https://www.darkreading.com/vulnerabilities-threats/cisco-zero-day-api-endpoint-authentication-issues
- BleepingComputer, "CISA alerts of active exploitation of three Linux kernel flaws," 21 September 2026. https://www.bleepingcomputer.com/news/security/cisa-alerts-of-active-exploitation-of-three-linux-kernel-flaws/
- Sophos, "September Patch Tuesday haul includes 973 CVEs," 16 September 2026. https://www.sophos.com/en-us/blog/september-2026-patch-tuesday
- BleepingComputer, "North Korean WaterPlum hackers infected 30,000 devices worldwide," 19 September 2026. https://www.bleepingcomputer.com/news/security/north-korean-waterplum-hackers-infected-30-000-devices-worldwide/
- UK NCSC, "Iranian cyber targeting of dissidents, activists and journalists," 15 September 2026. https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists
- BleepingComputer, "BigCommerce alerts merchants of data breach linked to Ribon apps," 21 September 2026. https://www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/
- BleepingComputer, "Malicious npm packages evade install-script defenses at runtime," 20 September 2026. https://www.bleepingcomputer.com/news/security/malicious-npm-packages-evade-install-script-defenses-at-runtime/
- BleepingComputer, "BragJack attacks hijack AI browser agents through malicious extensions," 19 September 2026. https://www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/
- BleepingComputer, "Researchers escape OpenAI Codex sandbox to run commands on host," 20 September 2026. https://www.bleepingcomputer.com/news/security/researchers-escape-openai-codex-sandbox-to-run-commands-on-host/
- Check Point Research, "21st September Threat Intelligence Report," 21 September 2026. https://research.checkpoint.com/2026/21st-september-threat-intelligence-report/