Threat Brief — 2026-09-10 — WatchGuard RCE fuels ransomware
Executive summary: CISA confirms that a critical WatchGuard Firebox RCE vulnerability flagged as actively exploited since December is now being used by ransomware operators, raising the stakes for any unpatched firewall appliances. Trezor reports that criminals are now actively phishing customers whose data was exposed through the earlier ShipMonk breach. Microsoft's September Patch Tuesday resolves the desktop-settings-wipe bug first identified in KB5120998 preview updates.
Top items
- WatchGuard Firebox RCE now linked to ransomware attacks. CISA has confirmed that ransomware gangs are exploiting the same critical WatchGuard firewall vulnerability the agency flagged as actively exploited in December. The escalation from initial access brokers to ransomware operators significantly increases the risk to organisations with exposed, unpatched Firebox appliances. Administrators should treat any unpatched WatchGuard device as a potential ransomware entry point. (src: BleepingComputer)
- Trezor warns of active phishing following ShipMonk breach. Threat actors who breached Trezor's third-party email provider are now actively targeting affected customers with phishing campaigns. This is a development in the breach first reported on 2026-09-05 by The Hacker News, which initially covered the exposure of approximately 67,000 additional U.S. customer records. The shift from data exposure to active phishing exploitation means customers with exposed contact details face elevated social-engineering risk. (src: BleepingComputer)
- Microsoft Patch Tuesday fixes desktop-settings-wipe bug. The September 2026 Patch Tuesday updates resolve the known issue that caused Windows desktop settings to be lost or reset on some devices. This closes a bug first reported on 2026-09-03 by BleepingComputer in relation to preview update KB5120998. Organisations that deferred the preview update to avoid the settings regression can now deploy the stable September release. (src: BleepingComputer)
- Ukrainian prosecutor general resigns amid "Carthage" scam-center investigation. NABU's investigation into alleged protection of fraudulent call centres — dubbed the "Carthage" case — has led to the resignation of Prosecutor General Ruslan Kravchenko after his subordinates were implicated. While primarily a law-enforcement and political story, the scale of the call-centre network underscores the continued operational maturity of transnational fraud infrastructure. (src: SecurityLab)
Themes
Vulnerability lifecycle escalation. The WatchGuard Firebox story illustrates a familiar pattern: a flaw flagged as actively exploited transitions from initial-access use to full ransomware operations. The gap between CISA's December warning and confirmed ransomware exploitation highlights the window during which unpatched edge devices remain lucrative targets. Separately, Microsoft's resolution of the desktop-settings bug shows the Patch Tuesday cycle closing preview-update regressions — a reminder that deferring patches to avoid one issue can extend exposure to others.
Breach-to-phishing pipeline. The Trezor development is a textbook example of third-party data exposure enabling follow-on social engineering. Customer data stolen through a vendor breach is being weaponised directly against the affected organisation's users, compressing the time between breach disclosure and active exploitation.
