Info
2026-09-09 22:09Z · last 4h · 7 findings
· glm-5.2:cloud
Threat Brief — 2026-09-09 — Active exploitation and espionage tooling surge
Executive summary: Cisco has confirmed in-the-wild exploitation of a maximum-severity authentication bypass in Secure Firewall Management Center, while CISA added four more known-exploited CVEs to its KEV catalog including a Fortinet heap overflow. A previously undocumented exploit kit chaining Chrome and Windows flaws was deployed by four separate espionage clusters within a single week. Separately, AdaptHealth disclosed a 4.1-million-record breach attributed to ShinyHunters, and US agencies published new details on Chinese firms conducting industrial-scale AI model distillation against leading US AI providers.
Top items
- Cisco Secure FMC CVE-2026-20079KEV — actively exploited, maximum severity. Cisco confirmed that a maximum-severity authentication bypass vulnerability in its Secure Firewall Management Center software is being exploited in attacks. This is a first report. (src: BleepingComputer)
- CISA adds four CVEs to Known Exploited Vulnerabilities catalog. New additions based on evidence of active exploitation include CVE-2025-25249KEV (Fortinet multiple products heap-based buffer overflow) and three others. This catalog has been updated repeatedly since first reported on 2026-08-17 via CISA; today's addition is the latest batch. (src: CISA Current Activity)
- BlueMoon exploit kit chains Chrome and Windows flaws for espionage. A previously undocumented exploit kit was used by four distinct espionage-motivated threat clusters within a single week, chaining multiple vulnerabilities in Microsoft Windows and Google Chrome. This is a first report. The kit's rapid reuse across multiple actors suggests shared infrastructure or a commercial provider. (src: The Hacker News)
- AdaptHealth confirms 4.1 million records exposed in ShinyHunters-attributed breach. The healthcare company confirmed the July cyberattack exposed data of 4.1 million people, attributed to the ShinyHunters threat group. This is a first report. (src: BleepingComputer)
- US agencies detail Chinese AI distillation campaign against frontier models. US government agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce their own development costs. This story was first reported 2026-09-08 via a CISA joint advisory; today's DarkReading article provides additional reporting on the scope and targets. (src: Dark Reading)
- US disrupts Xinbi Guarantee scam marketplace, freezes $52.8M in crypto. The DOJ announced coordinated actions against an illicit online marketplace that offered scam services, seizing Telegram channels and confiscating cryptocurrency. This is a first report. (src: The Hacker News)
- Skullcandy Dime 3 earbuds accept unauthenticated Bluetooth pairing. CERT/CC warns that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without user interaction, enabling hijacking. This is a first report. (src: BleepingComputer)
Themes
- Exploit convergence across actors: The BlueMoon kit's deployment by four separate espionage clusters within one week mirrors a broader pattern of shared tooling lowering the barrier to sophisticated attacks. Combined with Cisco FMC active exploitation and fresh CISA KEV additions, defenders face multiple concurrent known-exploited vectors across network, endpoint, and browser surfaces.
- Data theft at scale continues: AdaptHealth's 4.1M-record disclosure and the AI distillation campaign both illustrate large-scale exfiltration — one targeting healthcare PII, the other targeting proprietary model outputs — underscoring that data remains the primary adversary objective across both criminal and state-sponsored activity.
