🛡️ InfoSec Blue Team Briefing

Thursday, September 24, 2026

🎧 Audio Briefing

Download MP3

Security briefing for Thursday the 24th of September 2026, pulled from the BlueTeamSec community on infosec.pub. A busy one, with ten stories to get through.

SOCRadar published details on Operation TALKED, a Russia-linked espionage campaign hitting Ukrainian defence and aviation contractors to exfiltrate Git repositories. The attackers exposed their own command and control infrastructure in the process, revealing over eight thousand files from both targeted espionage and opportunistic mass exploitation of more than a million internet-facing devices. ESET covered related Russian activity earlier in the week.

Aikido Security detailed Graphalgo, the first known supply chain attack targeting Terraform providers alongside Go modules. The campaign uses typosquatting and conditional malware to deploy a second-stage remote access tool that uses Slack and Ethereum smart contracts for command and control, aiming to harvest production credentials from DevOps workstations.

CERT Polska wrote up MikroTrick, a two-vulnerability chain in MikroTik RouterOS that allows authentication bypass and privilege escalation via SSH rekeying flaws and policy mask injection. Attackers can create admin accounts and exfiltrate data without valid credentials. CISA added the related vulnerabilities to the Known Exploited list earlier this week.

Reuters reports that ShinyHunters claim to have breached the FBI's jobs portal, allegedly stealing personal data on current and former employees and applicants, including Social Security numbers and family member details. Reuters partially verified the data by cross-referencing with credit bureau records and previous leaks. The FBI has confirmed unauthorised activity and opened an investigation. We covered ShinyHunters twice in the last fortnight, including a Dutch police appeal for information.

Google Project Zero disclosed a Windows privilege escalation flaw stemming from dangling COM object registrations left behind after an incomplete patch of a vulnerability known as Dark Elevator. Attackers can place malicious libraries in writable directories to achieve code execution when privileged processes resolve custom COM objects. The research includes PowerShell-based detection scripts for auditing COM hygiene. Volexity covered related Windows exploitation earlier this week involving zero-days in Chrome and Windows.

WordPress disclosed a critical path traversal vulnerability allowing unauthenticated attackers to execute arbitrary PHP files outside theme directories. It affects installations using themes with page-prefixed directories, including several widely deployed themes, and can lead to remote code execution on vulnerable PHP configurations. CVSS score of nine point two. CISA added this to the Known Exploited list two days ago.

Team Cymru identified a network of over eighty thousand gateway servers being used to bypass geographic restrictions and terms-of-service protections on frontier AI models from OpenAI, Anthropic, Google, and others. The infrastructure enables model distillation attacks, primarily from China and Hong Kong, where actors programmatically query advanced models at scale to train cheaper local versions and steal proprietary intelligence whilst evading attribution.

A researcher detailed the house of windy, an exploit technique that weaponises glibc's stack unwinding and exception handling by corrupting thread metadata. By manipulating pointers to exception frame sections, attackers can execute malicious bytecode through the unwinder, bypassing a range of protections including pointer mangling and control-flow integrity. It affects glibc two point forty-four and potentially other C standard libraries.

Jamf published analysis of Wavel, an evolved variant of the PamStealer macOS infostealer distributed through a fake cryptocurrency wallet site. The malware uses server-dependent decryption for evasion, harvests credentials from seventeen browsers and the macOS Keychain, and maintains persistence through four redundant mechanisms including launch agent registration and shell hook injection. We covered macOS tooling developments from Bad Packets and Open Source Malware last weekend.

And finally, Cisco Talos documented CLOSEDQUORUM, the first publicly reported Windows implant using autonomous AI for command and control. The malware uses a quorum of commercial large language models to make tactical decisions independently, targeting credentials, browser data, and cryptocurrency wallets without human operator input. Which is either impressive tradecraft or a sign that threat actors are outsourcing their thinking, depending on your perspective.

That's all for today. Credit for the articles goes to their original authors — the analysis here was automated.

📰 Articles Covered