Threat Brief — 2026-09-25 — KEV additions and V8 flaws dominate
CISA added WSO2 and Adobe Commerce (Magento) flaws to its Known Exploited Vulnerabilities catalog on Thursday, confirming active exploitation of both. Two additional Chromium V8 engine CVEs were published by MSRC, extending an ongoing batch of browser engine vulnerabilities first disclosed earlier this week. A $351.6 million theft from Bitget exchange and a cross-customer data leak in Cloudflare Containers underscore sustained pressure on infrastructure and crypto-custody providers.
Top items
- CISA KEV: WSO2 and Adobe Commerce/Magento flaws actively exploited. CISA added both critical flaws to its KEV catalog based on evidence of active exploitation. The WSO2 API Manager JWT bypass (enabling forged admin tokens) was first reported September 16; the Adobe Commerce/Magento addition is a new development. (src: The Hacker News)
- Chromium V8: CVE-2026-4450 (out-of-bounds write) and CVE-2025-2135 (type confusion) disclosed. MSRC published information on both V8 engine vulnerabilities. These extend an ongoing series of Chromium V8 disclosures first reported September 23. (src: MSRC CVE-2026-4450, MSRC CVE-2025-2135)
- Bitget exchange loses $351.6 million to suspected North Korean actors. Hot and warm wallets were drained; stolen tokens are being rapidly converted to Ethereum. First reported today. (src: BleepingComputer, SecurityLab)
- Cloudflare Containers cross-customer disk data leak patched. A flaw allowed a paying customer to read leftover disk data from other customers' containers on the same server. Cloudflare and the researchers who found it confirmed the fix. First reported today. (src: The Hacker News)
- Malicious Terraform provider delivered RAT via HashiCorp Registry. A typosquatted package differing from the popular original by a single letter was published to the registry, targeting developers with Go-based malware. First reported September 23; not previously featured. (src: SecurityLab)
- RedWing Android trojan compromised over 10,000 devices in Russia. Active since summer 2026, the malware masquerades as legitimate apps and video files, granting operators full device access post-infection. First reported today. (src: Xakep)
- Research: cross-platform file system metadata enables user surveillance. Windows, Android, Linux, and macOS file systems expose user activity patterns without requiring access to document contents. (src: SecurityLab)
- Russia's hybrid cyber-physical campaign intensifies across Europe. Cyber sabotage, disinformation, and drone attacks are escalating against European nations providing material support to Ukraine. (src: Dark Reading)
Themes
Supply-chain abuse continues via package registries — today's typosquatted Terraform provider follows recent npm/PyPI incidents, reinforcing that developer tooling registries remain a soft target. Separately, CISA KEV additions remain the most actionable signal for prioritising remediation, with two more flaws confirmed exploited in the wild this week.
