Threat Brief — 2026-09-24 — Active exploitation across webmail, CI servers, and network gear
Three critical vulnerabilities are now under active attack in the wild — Roundcube Webmail code injection, F5 BIG-IP APM remote code execution, and JetBrains TeamCity — with ransomware operators confirmed exploiting the latter. AI-driven offensive tooling is maturing fast: a coordinated AI agent swarm breached 11 organisations in 26 seconds, and newly documented Windows malware consults four separate LLMs to make autonomous attack decisions. Supply-chain lures continue to scale, with 17,000 ClickFix URLs mapped globally and fake GitHub repositories impersonating 40+ brands to deliver a new infostealer.
Top items
- Roundcube Webmail code injection now actively exploited. A high-severity vulnerability patched in May is being used in code injection attacks, per the Canadian Centre for Cyber Security. Organisations running unpatched Roundcube installations are exposed to potential server compromise. (src: BleepingComputer)
- F5 BIG-IP APM zero-day under active exploitation (developing). First reported yesterday (2026-09-23, BleepingComputer), this vulnerability allows unauthenticated remote code execution via specially crafted traffic — no password required. It has been added to CISA's KEV catalog. Russian-language reporting today adds operational detail on the exploitation mechanism. (src: SecurityLab)
- CISA warns ransomware gangs exploiting JetBrains TeamCity flaw. A critical TeamCity vulnerability patched in July is now being leveraged by ransomware operators, prompting a CISA alert to federal agencies. CI/CD servers remain high-value targets for initial access. (src: BleepingComputer)
- ShinyHunters FBI breach: leaked database exposes members of secret FBI hacker unit "ROU" (developing). First reported 2026-09-22 (BleepingComputer). New development: the stolen database reportedly contains identities of staff in an FBI team that conducts offensive device intrusions, expanding the breach's sensitivity beyond data theft. (src: SecurityLab)
- AI agent swarm breaches 11 organisations in 26 seconds. A reported coordinated attack using multiple AI agents simultaneously compromised 11 targets in under half a minute — the first documented instance of swarm-style autonomous offensive AI at scale. The technique compresses the window between reconnaissance and exploitation to near-zero. (src: Anquanke)
- ClosedQuorum Windows malware uses four LLMs for autonomous attack decisions. Cisco Talos discovered malware that, after infection, consults DeepSeek, Qwen, Mistral, and Google Gemini to decide next actions without operator input. This removes the command-and-control latency that defenders rely on for detection. (src: Xakep)
- ClickFix campaign mapped across 17,000 URLs globally. A CTM360 report traces ClickFix from a late-2023 novelty to the most common enterprise network entry method — operating without exploits, attachments, or on-disk files by abusing trusted websites to trick users into executing PowerShell. The scale suggests a mature subscription-based criminal service. (src: The Hacker News)
- Corp MDM Android spyware targets logistics sector. Fake Google Play pages impersonating CEVA and TKW Logistics distribute Android spyware that steals SMS messages and redirects phone calls. The logistics vertical is being specifically targeted, suggesting supply-chain-aware attackers. (src: The Hacker News)
- MacSync macOS stealer returns with backdoor module. A new version of the MacSync stealer targets cryptocurrency users and developers on macOS, now bundling a backdoor component alongside credential exfiltration. Delivery methods have evolved. (src: Securelist)
- Prompt-injection bug in $4B agentic AI app Manus. The agentic AI platform Manus is vulnerable to prompt injection via external data it processes — a class of flaw relevant to virtually all AI agents that ingest untrusted content. Without rigorous input filtering, attackers can manipulate agent behaviour. (src: Dark Reading)
- Ghost service accounts enable M365 data theft in Chile. Forgotten or orphaned service accounts in Microsoft 365 environments can circumvent employee-account lockdowns, providing persistent access to an organisation's entire M365 tenant. (src: Dark Reading)
- Fake GitHub repositories impersonating 40+ brands deliver Rapuncel stealer. A large-scale campaign hosts fraudulent repositories on GitHub mimicking LastPass and at least 39 other companies, promoted through search results, to deliver the Rapuncel infostealer. First reported 2026-09-18 (BleepingComputer); new findings confirm the scope extends well beyond LastPass. (src: Xakep)
- Secrets sprawl accelerated by AI coding agents. GitGuardian's 2026 report finds AI-assisted commits are leaking credentials at growing rates, as coding agents autonomously generate and ship code faster than secret-scanning controls can keep pace. (src: The Hacker News)
Themes
Active exploitation wave. Roundcube, F5 BIG-IP, and TeamCity represent three distinct attack surfaces — webmail, network appliances, and CI/CD — all now under active exploitation. Two have CISA KEV entries or agency alerts. The common thread: patches exist but lagging remediation creates a broad target pool.
AI offensive autonomy is accelerating. The AI swarm attack, ClosedQuorum's multi-LLM decision-making, and Manus's prompt-injection vulnerability together illustrate that AI is now both weapon and target. Attackers are compressing timelines (26-second swarm breaches) while removing human bottlenecks (autonomous malware). Defenders' traditional detection windows are narrowing.
Social engineering at industrial scale. ClickFix's 17,000 URLs and the 40+ brand Rapuncel repository campaign show that trust-abuse lures — not zero-days — remain the dominant initial-access vector. Both operate through legitimate platforms (websites, GitHub), making infrastructure-level blocking difficult.
