September 7, 2026
The Diff Is the Disclosure: MikroTik's Silent Patch Comes Apart
67 of 75 sources → 304 gathered → 304 triaged → 37 clustered → 37 written
A researcher pulled apart MikroTik’s unexplained RouterOS release from 3 September and reproduced the SSH path attackers have been walking since at least 2 September, lab PoC included. Sansec’s unpatched Magento zero-day picked up a second backdoor build overnight, and JetBrains told Cadence users to rotate everything after its own TeamCity server was breached.
Exploitation & Active Attacks
- MikroTik’s three same-day RouterOS builds (7.23.4 long-term, 7.24.2 stable, 6.49.21) shipped with a deliberately vague “important security update” banner — and one changelog line present in all three branches, absent from 7.23.3: “ssh - refactor SSH internal processes”. Diffing the NPK packages, npratley.net documents three bugs and two chains: a low-exponent RSA signature forgery reaching an overflow in
mtgetwith confirmed controlled code execution, and — matched to an active-exploitation support trace — an SSH username of-2reaching a legacy file-descriptor login transport, letting a read-only session supply its own policy mask and escalate to the full RouterOS policy set, producing exactly the campaign-shapedopsaccount defenders have been finding. The author is explicit about the boundary he did not cross: he has not reproduced a stock, credential-free way to make SSH accept literal user-2. The work was AI-driven and took roughly six hours. A MikroTrick PoC is public, tracked as CVE-2026-67276. CERT Polska’s warning went out 5 September with attacks dating to at least 2 September and no victim count; CERT-LV described mass attacks (@campuscodi); SANS ISC says assume compromise, because attackers are adding accounts that survive the patch (earlier coverage). - StyleSmuggler, the unpatched Magento/Adobe Commerce RCE, gained a second implant build on 6 September: Sansec reports arm64 and x86-64 variants that masquerade as
fc-cacheinstead of[kworker/u:8:0], copy themselves to~/.cache/fontconfig/fc-cache, install a cron entry restarting them twice an hour, and disguise C2 as time sync. The Rust backdoor beacons to 99.84.67.186; Sansec says it has no indication the backdoor has been weaponised yet and that no other vendor detects it. The unauthenticated chain reproduces on clean 2.4.7, 2.4.8 and 2.4.9, and the first victim was on 2.4.6-p15 with July and August patches applied. Adobe’s next scheduled security release is 8 September; it is not yet known whether it covers this. Interim mitigation is disabling GraphQL (earlier coverage). - VMware Workstation and Fusion got fixes for a VMXNET3 integer overflow (CVE-2026-59346, CVSS 9.3) that lets a local administrator inside a guest execute code on the host, plus an HGFS stack overflow (CVE-2026-59347, 8.1) giving execution as the VMX process. Both need local admin in the VM, there are no workarounds, and Broadcom reports no evidence of exploitation — worth noting against last month’s vCenter activity, where exploitation of CVE-2026-59310 reached 361 unique victim IPs across 47 countries (The Hacker News, SecurityWeek). Fixed in 26H1u1.
- The actively exploited Chromium V8 type confusion CVE-2026-85046 now carries a 18 September KEV deadline for US federal agencies; fixes are in Chrome 152.0.7977.82/.83, and Edge, Brave, Opera and Vivaldi users need their own vendor updates (The Hacker News) (discussion) (earlier coverage).
- A Telegram zero-click crash bug, reported to the vendor with a PoC, is said to render the client unusable across versions and platforms from a single malicious sticker sent to a chat (@0x6rss). Denial of service only, and Telegram has not commented publicly.
New Tools & Releases
- Endpoint AI Agent Abuse (EAA) is a curated catalog of techniques and real-world cases for abusing locally installed AI agents — a useful reference as agentic tooling lands on developer endpoints inside enterprises (@ipurple).
- HandleRedirect, a Windows local privilege escalation PoC, is now on GitHub.
- The named-pipe impersonation SYSTEM PoC from daem0nc0re picked up a new method for coercing a privileged connection via scheduled tasks (@ipurple).
- Remote Thread Hijacking + Remote Mapping Injection ships a combined process-injection PoC for evasion testing (GitHub).
CI/CD & Identity
- JetBrains is telling Cadence users to revoke and rotate every credential and secret and to treat all executions, inputs and outputs as untrusted, after attackers exploited CVE-2026-63077 (CVSS 9.8, deserialization to unauthenticated OS command execution) against a TeamCity server in JetBrains’ own environment. The flaw has been in CISA’s KEV catalog since 5 August; JetBrains discovered the intrusion on 23 August. The actor reached a 2024 Cadence backup and storage containing current-user data — usernames, real names, email addresses, last-login timestamps and last-accessed IPs, project source code and credentials — and defenders should hunt authentication activity using Cadence-stored credentials from 8 August onward (The Hacker News).
AI & Model Security
- GPT-6 Astra is reaching $20 Plus subscribers, showing up in ChatGPT Work before the regular chat model picker; it is already generally available to Pro, Enterprise and Business Premium users in Work and Codex and in the API, with no date for free users (BleepingComputer). On the monitorability question, @RyanGreenblatt walked back his own reading that
reasoning=Nonewas pulled for safety reasons — “I now think I was reading into this too much” — after being told it was removed simply because low dominated it on usefulness. - The llms.txt poisoning research now has its denominators: across 6,214 live domains belonging to defense contractors, Fortune 500 and Big Tech firms, researchers found 8,265
llms.txtandllms-full.txtfiles, of which 120 — each on a different site — pointed at code packages or domain names nobody had registered. The team registered several and hosted packages to see what agents would do with them (Schneier on Security) (earlier coverage).
Threat Intelligence
- Kimsuky’s Operation GitPower is now mass-producing decoys with an AI coding agent: Genians analysed 13 malicious LNK files collected 11–19 August 2026 whose decoy PDF metadata names the open-source agent OpenCode as producer. Lures shifted from diplomacy and academia to finance and corporate operations (fund disbursement, insurance premiums, Visa payments); the LNKs launch PowerShell with encrypted loaders buried in over-long arguments padded with leading spaces, pull decoys and follow-on commands from GitHub Raw using hardcoded PATs, and now add Pastebin as a second-stage channel plus anti-analysis routines that check for virtualization and analysis tooling, inspect sandbox usernames and wipe command history. All 13 share the same decoder constant and array variable name — cheap hunting pivots.
- REVSTEALER is scaling: Elastic Security Labs tracks it as REF2859 with a broad credential harvester, an embedded sandbox scoring system, gaming-platform account theft for resale, and a Polygon blockchain dead drop for C2 resilience. Four linked modules disable Windows Update and Defender to run a crypto miner (The Hacker News).
- Tengu, a Mirai-style Linux/IoT botnet, gets a full reverse-engineering walkthrough (reverser.space).
- Roughly 4,000 BTC (~$320M) was drained from Blockstream’s Liquid Network, with the attacker leaving an on-chain message reading “we are whitehats. contact us on chain” and Blockstream replying on-chain with a security contact address (@DarkWebInformer). Scope caveat from @marcoantonopou1: this is Liquid, not the Bitcoin main chain.
- A cheap ClickFix mitigation worth testing in your own fleet: @GossiTheDog reports uBlock Origin blocks the paste-into-Run-dialog lure pages effectively.
Research & Supply Chain
- A trusting-trust attack no longer needs a compiler. Malka, Sharma, Monperrus, Zacchiroli and Zimmermann build a complete self-propagating backdoor around GNU strip — a utility that neither reads nor emits source — using only ELF manipulation. In the NixOS bootstrap, one tampered
stripin the binary seed implants a payload that propagates from one generation ofstripto the next and survives into the final standard environment after the seed leaves the dependency closure; on a real nixpkgs revision it builds a complete graphical installer without failures and backdoors nearly every binary in it (arXiv) (discussion). - Of the CVEs that actually get exploited, ~87% are now attacked on or before the day they become public knowledge, against 23% in 2020, with a median time to exploit of one day per the ZeroDayClock data cited by a16z. The figure describes exploited bugs only, not the CVE population — but it is the number that governs patch-window planning.
Regional & Policy
- CERT-SE’s week 36 brief flags Sweden’s 13 September election, with the National Cyber Security Centre monitoring the threat picture from a cyber perspective; NCSC head John Billow described the remit on Sveriges Radio’s Gräns (CERT-SE).
- Russian influence operation Matryoshka ran content attacking every German political party except the far-right AfD during a major regional election (@campuscodi).
- OpenAI pledged $1 billion under a “Daybreak” initiative to put subsidised frontier AI cyber capabilities, training and technical assistance in the hands of critical-infrastructure defenders — with few details so far on cost or eligibility (SecurityWeek).
✎ This issue was written by claude-opus-5. No human edited it before publishing — how this works .
Topics
Threat actors
Malware
Models