Threat Brief — 2026-09-11: VPNs and build pipelines in the crosshairs
Executive Summary
Today's most significant developments centre on actively exploited infrastructure flaws. Cisco FMC CVE-2026-20079KEV — already in CISA KEV — is now confirmed to be leveraged by three distinct threat clusters including Qilin ransomware operators. PaperCut has replaced interim emergency patches with a proper maintenance release for its two actively exploited flaws. Two new Chromium V8 vulnerabilities were disclosed via MSRC, and the Trezor phishing campaign has been attributed to the Brevo breach with confirmed scale of 347,000 targeted users.
Top Items
- Cisco FMC exploitation expands to Qilin ransomware — CVE-2026-20079KEV, already in CISA KEV and known exploited in the wild, is now confirmed to be leveraged by three distinct threat clusters spanning both ransomware and state-sponsored activity, with Qilin ransomware specifically named for credential theft and deployment. This is a developing story first reported 2026-09-09; the new development is identification of three clusters and Qilin as the ransomware payload. (src: The Hacker News)
- PaperCut replaces emergency patches with proper fixes — PaperCut released a security maintenance release that replaces all previously published emergency patches for two flaws under active exploitation. This is a developing story first reported 2026-08-27; the development is the availability of a proper (non-emergency) maintenance release. (src: The Hacker News)
- Two Chromium V8 vulnerabilities disclosed by MSRC — CVE-2025-1920 (type confusion in V8) and CVE-2025-2137 (out-of-bounds read in V8) were published by Microsoft's security response centre. No exploit activity is indicated in either disclosure. (src: MSRC CVE-2025-1920), (src: MSRC CVE-2025-2137)
- Trezor phishing attributed to Brevo breach, scale confirmed — Phishing targeting Trezor customers has been linked to the Brevo email platform breach, with 347,000 email addresses targeted and 2,500 users clicking a malicious link. This is a developing story first reported 2026-09-05; the new development is Brevo attribution and confirmed victim numbers. (src: BleepingComputer)
- JFrog Artifactory flaw chaining detailed by Wiz — A Wiz report describes how attackers chain two Artifactory flaws (including CVE-2026-82329KEV) to seize admin control of self-hosted servers and plant backdoors in software build pipelines. This is a developing story first reported 2026-09-01; the development is the full attack-chain technical analysis from Wiz. (src: The Hacker News)
- Fake IT-helpdesk vishing evolves to abuse passkeys — Attackers posing as IT support now use passkeys as a phishing pretext: after the victim logs in, attackers register their own MFA factor to persist access and exfiltrate Microsoft 365 data. This is a developing story first reported 2026-09-07; the new development is the passkey-specific abuse technique. (src: SecurityLab)
- GTA VI used as malware lure targeting Russian-speaking users — A Russian-language installer purporting to be GTA VI delivers trojans that steal passwords and destroy files. The campaign leverages anticipation around the unreleased game. (src: SecurityLab)
- Hacking Cat hacktivist toolkit analysed — Securelist published analysis of the Hacking Cat group's toolkit and its operational partnerships with Ukrainian Cyber Alliance and Cyber Anarchy Squad, detailing the group's capabilities and targeting. (src: Securelist)
- Conti ransomware member sentenced to four years — A Ukrainian national was sentenced for involvement in Conti ransomware operations between 2021 and 2022, a reminder that law enforcement outcomes for ransomware actors continue to accrue. (src: BleepingComputer)
- Microsoft fixes Teams and Outlook launch failures on ARM Windows — Microsoft resolved a bug preventing Teams and Outlook from launching on ARM-based Windows devices after August 2026 Patch Tuesday updates. (src: BleepingComputer)
Themes
Infrastructure as the entry point. Cisco FMC, JFrog Artifactory, and (still tracked) Check Point VPN all illustrate attackers targeting management interfaces and build-pipeline infrastructure rather than endpoints. The consistent pattern is unauthenticated or auth-bypass flaws in perimeter and DevOps tooling as the preferred initial foothold — these systems sit on the network edge, often with privileged access, and their compromise cascades downstream.
Social engineering adapting to modern auth. The Trezor/Brevo phishing campaign and the passkey-abusing vishing both show attackers evolving techniques to weaponise modern authentication mechanisms — including passkeys and MFA — rather than defeating them cryptographically. The attack surface is shifting from the credential itself to the recovery and enrolment flows around it.
===
THREAT-TOPICS===
[{"slug":"cisco-secure-fmc-cve-2026-20079KEV-auth-bypass-active-exploitation","headline":"Cisco FMC exploitation linked to Qilin ransomware and three threat clusters","findingIds":[11626],"status":"developing","development":"Three distinct threat clusters identified including Qilin ransomware deployment; CVE-2026-20079KEV confirmed in CISA KEV"},{"slug":"papercut-ng-mf-zero-day-actively-exploited","headline":"PaperCut replaces emergency patches with proper maintenance release","findingIds":[11625],"status":"developing","development":"Security maintenance release replaces all previously published emergency patches for two actively exploited flaws"},{"slug":"chromium-v8-cve-2025-1920-2025-2137","headline":"Two Chromium V8 vulnerabilities disclosed via MSRC","findingIds":[11620,11619],"status":"new","development":""},{"slug":"trezor-shipmonk-breach-expands-us-customer-data","headline":"Trezor phishing attributed to Brevo breach with 347K targeted users","findingIds":[11627],"status":"developing","development":"Phishing attributed to Brevo breach; 347,000 emails targeted, 2,500 users clicked malicious link"},{"slug":"jfrog-artifactory-cve-2026-82329KEV-exploited","headline":"Wiz details JFrog Artifactory flaw chaining for admin takeover and backdoors","findingIds":[11623],"status":"developing","development":"Wiz publishes full attack-chain analysis showing how two chained flaws achieve admin control and backdoor deployment"},{"slug":"fake-it-call-vishing-executive-extortion","headline":"Fake IT vishing evolves to abuse passkeys for M365 persistence","findingIds":[11616],"status":"developing","development":"Passkeys identified as new phishing pretext; attackers register own MFA after victim login"},{"slug":"gta-vi-malware-lure-russian-users","headline":"GTA VI installer delivers password-stealing trojans to Russian users","findingIds":[11632],"status":"new","development":""},{"slug":"hacking-cat-hacktivist-toolkit-analysis","headline":"Securelist analyses Hacking Cat group toolkit and partnerships","findingIds":[11628],"status":"new","development":""},{"slug":"conti-ransomware-member-sentenced","headline":"Conti ransomware member sentenced to four years in prison","findingIds":[11618],"status":"new","development":""},{"slug":"microsoft-teams-outlook-arm-windows-fix","headline":"Microsoft fixes Teams and Outlook launch failures on ARM Windows","findingIds":[11634],"status":"new","development":""}]
