Security news from the BlueTeamSec community for Thursday the 10th of September 2026. A busy one, with twelve stories to cover.
Cisco Talos have written up a ClearFake campaign from a Russian-based actor that's using WebDAV to deliver multiple stealers and remote access tools β Amatera, ZigCryptoStealer, and NetSupport Manager. The chain uses blockchain-hosted JavaScript for what they're calling EtherHiding, and there's a bring-your-own-driver technique in there to evade detection. We've seen this actor lean on driver abuse before; it appeared in coverage earlier this week.
Gen Digital are reporting that infostealers have started targeting AI development tools. Variants like Amatera, Remus, and Djinn Stealer are now going after local data stores from Cursor, Claude, Cline, and Gemini β lifting API keys, session tokens, and conversation logs that are often stored in plaintext. One for anyone running those tools locally with access to proprietary work.
CloudSEK have tracked a phishing-as-a-service operation called BigBear 2.0, first spotted in June, that's using Evilginx2 to run adversary-in-the-middle attacks against Microsoft 365 users. It's hit over four hundred organisations across forty countries, primarily IT and managed service providers, harvesting credentials and session cookies to bypass multi-factor authentication. We've seen some of the follow-on techniques in late August coverage on remote token extraction and cloud-based implants.
The US Department of Justice announced the extradition of a Russian national running a large-scale bank account takeover scheme. The operation used search-engine poisoning and spoofed banking sites to harvest over five thousand credentials, contributing to more than two hundred and sixty million dollars in reported losses since January last year.
Cisco Talos disclosed a type confusion vulnerability in the Windows Cloud Files Mini Filter Driver β that's the component behind things like OneDrive file placeholders. The flaw stems from a race condition and can crash the kernel or potentially give an attacker code execution with kernel-level privileges. Microsoft patched it on the eighth; it's scored eight-point-eight.
A researcher going by MSNightmare has published ShieldCrash, which bypasses Microsoft's patch for a previous Windows Defender vulnerability. It still allows arbitrary file reads with SYSTEM privileges and affects all supported Windows versions as of this month. There's a public proof-of-concept, and the researcher notes it could potentially be escalated further.
Matthew McPherrin has factored the RSA keys of a Certificate Authority from the nineteen-nineties. The keys were five-twelve-bit, so not exactly a surprise, but it's a useful reminder that legacy root certificates can still linger in trust stores. Adds useful context if you're managing certificate policy or conducting infrastructure reviews.
Researchers have disclosed WeWorm, described as the first zero-click worm that spreads through WeChat calls across iOS and Android. It exploits a memory corruption flaw in WeChat's VoIP stack, hijacks accounts, and then propagates autonomously by calling the victim's contacts β no user interaction required. Given WeChat's user base, this one's significant.
And another RouterOS issue: a proof-of-concept has been published for an SSH authentication bypass in MikroTik devices. The flaw allows unauthenticated access by exploiting weak RSA signature validation β specifically, using an exponent of one. MikroTik released patches on the third for current and legacy versions.
A researcher has published root-cause analysis and a proof-of-concept for a critical authentication bypass in Citrix NetScaler ADC and Gateway. The vulnerability affects SAML implementations using HTTP-Redirect binding and allows attackers to forge sessions by sending unsigned assertions that aren't properly validated. Patches are available for versions fourteen-point-one and thirteen-point-one, and there are configuration-based workarounds if patching isn't immediately possible. We covered a similar NetScaler issue back in early September.
Aikido are reporting that the Shai-Hulud NPM supply chain attack has resurfaced after a hundred and eleven days dormant. Four new packages were published on the seventh containing the identical malicious payload from May's incident β same file hash, same command-and-control domain. What's notable here is that it bypassed NPM's automated scanning despite being previously fingerprinted. The malware steals tokens, injects itself into downloaded packages, and republishes them. We covered the earlier wave and related registry incidents earlier this month.
Finally, a clarification: the repository ashwa is a legitimate open-source library providing hardware-accelerated substring search routines. No vulnerability, no incident β just a case of mistaken identity in the feed.
That's everything for today. The original articles are the work of their authors β the analysis here was automated. We'll be back tomorrow.