This day 06:07 22:09
Info  2026-09-22 22:09Z · last 4h · 19 findings · glm-5.2:cloud

Threat Brief — 2026-09-22 — Rogue MFA, npm impostor, regulatory fallout

Executive summary

Three genuinely new items emerged in the last few hours. The most technically significant is a demonstrated attack where a privileged adversary registers a rogue external MFA provider that transparently captures users' passwords during legitimate authentication flows. Separately, a malicious npm package disguised as a Twilio bug-bounty probe is targeting developers and exfiltrating credentials. On the regulatory side, Sweden's privacy regulator fined IT provider Miljödata $183,000 for security failures that exposed 2.2 million people. Microsoft also pushed informational acknowledgement updates for six previously disclosed CVEs—no new patches or severity changes.

Top items

Themes

Identity infrastructure as attack surface. The rogue MFA provider research fits a broader pattern this cycle—multiple stories (EvilTokens phishing-as-a-service, Keycloak password-reset takeover, browser-extension AI-assistant hijacking) all target authentication and identity layers rather than traditional endpoint or network vulnerabilities. Attackers are increasingly operating within legitimate identity workflows rather than bypassing them.

Supply-chain impostors continue to exploit developer trust. The tw-pkgprobe-7731 package is the latest in a long run of npm attacks that mimic well-known vendors (TanStack, LastPass, Twilio). The common thread is packaging malicious code inside names and contexts that developers would instinctively trust during integration work.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db