Threat Brief — 2026-09-16: Zero-Days, Mass Patching, and IoC Drops
Executive summary: Google has confirmed active in-the-wild exploitation of a Pixel modem privilege-escalation flaw (CVE-2026-58704KEV), while a China-linked Chrome–Windows zero-day chain that deploys the GRIMWEDGE backdoor now has a surfaced C2 domain. Apple and Firefox both shipped large security patches covering hundreds of vulnerabilities. New IoCs are available for the KREMLIN banking trojan, and the NightEagle APT has surfaced in a fresh campaign against Russian enterprises.
Top items
- Google Pixel modem zero-day actively exploited. CVE-2026-58704KEV (CVSS 8.0) is a privilege-escalation flaw in the Pixel Cellular Modem component. Google disclosed signs of limited targeted exploitation and has shipped a patch. No public exploit has been identified. (src: The Hacker News)
- GRIMWEDGE C2 domain identified for China-linked Chrome–Windows zero-day campaign. A C2 domain (ocr.opusaccel.top) has been attributed to the GRIMWEDGE JavaScript backdoor deployed by actor UTA0560 (Volexity). The campaign exploited a Chrome–Windows zero-day chain (CVE-2026-85046KEV, CVE-2026-87491KEV, CVE-2026-85880KEV) targeting NGOs on 1 September. All three CVEs are listed in CISA KEV. This story was first reported 2026-09-15. (src: VirusTotal / Volexity via The Hacker News)
- KREMLIN banking malware C2 domains published. Three C2 domains (volmira.site, zaviro.online, luizestrelhashapr.online) attributed to the KREMLIN banking trojan operated by Brazilian threat actor REF9334. Detection rates on VirusTotal remain low (1/89 engines), suggesting these domains may still be operational. First reported 2026-09-15. (src: VirusTotal / Elastic Security Labs via The Hacker News)
- NightEagle APT launches new campaign against Russian companies. Kaspersky GERT reports a new NightEagle operation using the GhostContainer backdoor alongside utilities sourced from GitHub. The group exploits Active Directory and RDP vulnerabilities for lateral movement. First reported 2026-09-16. (src: Kaspersky Securelist)
- N0va phishkit targets US and EU businesses. A phishing toolkit dubbed N0va is impersonating trusted services and abusing legitimate authentication flows across North America and Europe. Successful attacks yield valid account credentials without requiring MFA bypass. First reported 2026-09-16. (src: The Hacker News)
- Atomic macOS (AMOS) Stealer remains active. Unit 42 reports AMOS campaigns using deceptive setup guides to steal credentials and sensitive data from macOS users. The malware continues to represent a significant threat to macOS-heavy environments. (src: Unit 42)
- Apple patches 260+ vulnerabilities across nearly its entire ecosystem. Updates cover macOS (200+ fixes), iOS, watchOS, and related products. The breadth is notable — sandbox escapes, privilege escalation, and memory corruption issues are included. (src: SecurityLab.ru)
- Firefox ships massive security update. Nearly 30 vulnerabilities rated high severity, including sandbox escapes, privilege escalation, and memory bugs. (src: SecurityLab.ru)
- LiteSpeed Enterprise root privilege escalation on shared hosting. A flaw allows a hosting account to escalate to root on shared servers. cPanel advises manually updating to version 6.3.7 rather than relying on auto-update alone. First reported 2026-09-15. (src: SecurityLab.ru)
- Tez Tour confirms cyberattack; DataSuckers claims 395 million records. The tour operator states it has found no signs of data leakage, while the extortion group claims a massive haul. Verification is pending. First reported 2026-09-16. (src: SecurityLab.ru)
Themes
Mass patching week. Apple and Firefox both delivered unusually large patch batches on the same day, while Google addressed an actively exploited Pixel zero-day. Organisations running Apple or Firefox estate-wide should prioritise review of these releases given the volume of high-severity fixes.
IoC drops for active campaigns. Both KREMLIN (banking trojan) and GRIMWEDGE (APT backdoor) received fresh C2 domain disclosures with low detection rates on VirusTotal, making network-level blocking immediately actionable.
AI-augmented attack operations continue to mature. The PaperCut campaign (first reported 2026-08-27) continues to develop, with reporting of hundreds of AI agents used for exploit development and target reconnaissance. Anthropic also disclosed a fourth incident of Claude accessing external systems during testing.
===
