Summary
Phishing emails disguised as payment plans are slashing through enterprise defenses, as the Global Group ransomware operation abuses WinMerge downloads to deploy file-encrypting payloads and threaten double extortion. Cyware highlights how this campaign leverages legitimate tools, disables security processes, and collaborates with Initial Access Brokers to widen its reach, with domains like globalsupportupdate[.]top flagged for blocking.
A zero-day vulnerability tracked as CVE-2026-76504 is letting attackers bypass authentication in Cisco Catalyst SD-WAN Manager, granting admin-level access with a single crafted HTTP request. This marks the fifth Cisco SD-WAN zero-day exploited in 2026, and Cisco has released fixed software while urging organizations to monitor logs for suspicious j_security_check entries.
ThreeAM, a ransomware group, has claimed access to St James’ Anglican School in Western Australia and is threatening to leak stolen data. The school began a cybersecurity audit after disclosing the incident on September 14, and authorities are monitoring the dark web for leaks as families and staff face the risk of personal information exposure.
Top Malware Reported in the Last 24 Hours
Global Group ransomware abuses WinMerge downloads
Global Group is a ransomware-as-a-service operation that rebrands the legacy Black Lock and Mamona families, using phishing to push a file-encrypting payload into large enterprises. It starts with a “Suggested Payment Plan” lure and a PDF “Download” button that leads to a malicious ISO, where an executable abuses the legitimate WinMerge application to fetch the encryptor from globalsupportupdate[.]top. Once running, it scans local drives, network shares, and databases, disables security processes, then encrypts files and switches the wallpaper to a ransom note while adding the nZASJgT extension. The group also uses double extortion—stealing sensitive data and threatening to publish it—and it collaborates with Initial Access Brokers (IABs) to widen its paths into victim networks. The report also flags driverupdate[.]sbs and globalsupportupdate[.]top as domains to block.
2CLoader sneaks Vidar and Remus
2CLoader is a newly identified malware loader that Zscaler ThreatLabz observed being used in August 2026 to deliver the Vidar and Remus information stealers. It is built to survive scrutiny: it uses inline trampoline hooks to tamper with Windows API behavior in ways that can confuse sandboxes and evade endpoint detection. The loader also uses the Hell’s Gate technique for indirect system calls, targeting Nt* APIs such as NtProtectVirtualMemory and NtQueryInformationProcess as it prepares and runs follow-on payloads. Zscaler says its configuration is stored as a PE resource and includes a magic value 2C 3D 4E 5F, along with fields that control execution flags and AES-GCM parameters used during payload decryption. For affected organizations, the outcome is practical and immediate: this kind of loader’s job is to quietly pave the way for credential theft that can lead to account takeover and broader intrusion.
CloudSyncD fake Zoom steals macOS passwords
CloudSyncD is a macOS backdoor disguised as a Zoom installer, discovered during routine monitoring inside a fake Zoom disk image and then seen moving from development to active deployment with live C2 infrastructure within two days. It leans on social engineering to get users to bypass macOS Gatekeeper, then validates local passwords using dscl and hides harvested credentials in ~/.config/zoom/data.json using zero-width Unicode characters to conceal where the base64-encoded data sits. If fileless execution fails, it can fall back to running a payload via mkstemp, and a second-stage daemon then runs in the background collecting system information. The campaign’s C2 endpoints are hosted on orchid-led[.]com and bjzhishang[.]com. For victims, the immediate consequence is loss of account secrets and a persistent foothold on their Macs that can enable follow-on access without an obvious warning.
Top Vulnerabilities Reported in Last 24 hours
Hackers exploit Cisco SD-WAN login bypass
Cisco says a zero-day in Catalyst SD-WAN Manager lets unauthenticated attackers gain admin-level access by bypassing authentication (CVE-2026-76504). The company attributes the bug to improper handling of URI encoding in HTTP requests, allowing crafted requests to slip past the login check and escalate privileges. Attackers are already exploiting this in the wild. Reporting highlighted by BleepingComputer places it as the fifth Cisco SD-WAN zero-day exploited in 2026, with earlier SD-WAN flaws previously tied by CISA to ransomware activity. Cisco says fixed software releases are available, and it also calls out serviceproxy-access.log and vmanage-server.log as places to look for suspicious j_security_check entries.
Zimbra mail servers hit by command injection
Microsoft says attackers can remotely run OS commands on internet-facing Zimbra Collaboration Suite servers through an unauthenticated command injection flaw (CVE-2026-73570), turning email infrastructure into an entry point for deeper compromise. The activity targets environments where SNMP notifications are enabled, with attackers using crafted SMTP requests to trigger Zimbra’s SNMP notification processing and execute commands as the zimbra service account. Attackers are exploiting this in the wild. Microsoft’s investigation describes a broader attack chain that includes pre-disclosure reconnaissance (including out-of-band scanning), JSP web shell deployment, privilege escalation using Zimbra’s legitimate helpers and interactions with tools like zmmailboxdmgr, and persistence via disguised systemd services and passwordless sudo entries. A fix is available in Zimbra version 10.1.20 or later.
CISA flags exploited Apple memory bug
CISA added an Apple out-of-bounds write vulnerability to its Known Exploited Vulnerabilities Catalog, warning it can be used to take total control of affected assets after exploitation (CVE-2026-86950). The practical risk is that a successful attack can translate into unauthorized access and data breaches, a high-consequence outcome for enterprises that depend on Apple devices and services. Attackers are already exploiting this in the wild. CISA’s alert ties the KEV Catalog to Binding Operational Directive 26-04 for federal agencies, and it also highlights how new KEV entries get proposed: submissions must include a CVE ID, evidence of exploitation, and clear mitigation guidance. Apple has provided fixes for affected products.
Top Threat Actors Reported in Last 24 hours
ThreeAM hits Australian school, threatens leaks
ThreeAM, a ransomware group, has claimed unauthorized access to St James’ Anglican School in Western Australia and threatened to publish stolen data. The school disclosed the incident on September 14 and began a cybersecurity audit, then the group publicly asserted involvement on September 28 as pressure for extortion. For families and staff, the immediate concern is potential exposure of personal information, even as the school says learning has not been disrupted and it will provide specific guidance if anyone’s information is confirmed affected. The school also said it notified the Australian Cyber Security Centre and the Office of the Australian Information Commissioner when the incident was discovered, and it is monitoring the dark web for any leak. ThreeAM has been linked to tactics including spoofed phone calls, running activity inside virtual machines, and data theft prior to ransomware deployment, and it previously attacked ANU Enterprise in November 2024.
Global Group rebrands BlackLock into RaaS
Global Group, a Ransomware-as-a-Service operation described as a rebranding of Black Lock and Mamona, is targeting large enterprises with phishing that leads to file encryption and data-theft extortion. The campaign begins with an email posing as a “Suggested Payment Plan,” pushing recipients toward a booby-trapped download that ultimately pulls down the encryptor. For large organisations, the impact is operational disruption paired with the risk of sensitive data being exposed publicly if ransom demands aren’t met. The report says the operation also works with Initial Access Brokers, widening the ways affiliates can get ransomware into corporate environments. Recommended actions in the report focus on strengthening detection for unauthorized access paths used by brokers, tightening segmentation to limit spread, and reinforcing user awareness against phishing lures.
DarkSword and UAC crews target Ukraine mobiles
DarkSword, described as an exploit kit used by Russian hackers, is being used in watering-hole attacks to compromise iPhones used by Ukrainian military personnel and government officials, alongside Android malware pushed by UAC-0244 and UAC-0263. Ukrainian authorities said DarkSword was used against a regional news outlet, a local court, and a food processing company, reflecting a wider pressure campaign on the country’s institutions. For people in the crosshairs, the consequence is that a routine visit to a trusted website or a convincing impersonation can turn a personal phone into a surveillance device. The Android side of the activity relies on fake websites and impersonation to distribute trojanized apps, while DarkSword is characterized as “hit-and-run,” quickly extracting sensitive information before disappearing. Recommended actions in the advisory emphasize reducing exposure to watering-hole and impersonation attempts and keeping mobile platforms updated to reduce risk from browser and OS exploitation.
Frequently Asked Questions
What is Global Group? Global Group is a ransomware-as-a-service operation that rebrands the legacy Black Lock and Mamona families, using phishing to push a file-encrypting payload into large enterprises. It starts with a “Suggested Payment Plan” lure and a PDF “Download” button that leads to a malicious ISO, where an executable abuses the legitimate WinMerge application to fetch the encryptor from globalsupportupdate[.]top.
What is 2CLoader? 2CLoader is a newly identified malware loader that Zscaler ThreatLabz observed being used in August 2026 to deliver the Vidar and Remus information stealers. It is built to survive scrutiny: it uses inline trampoline hooks to tamper with Windows API behavior in ways that can confuse sandboxes and evade endpoint detection.
What is CloudSyncD? CloudSyncD is a macOS backdoor disguised as a Zoom installer, discovered during routine monitoring inside a fake Zoom disk image and then seen moving from development to active deployment with live C2 infrastructure within two days. It leans on social engineering to get users to bypass macOS Gatekeeper, then validates local passwords using dscl and hides harvested credentials in ~/.config/zoom/data.json using zero-width Unicode characters to conceal where the base64-encoded data sits.
What is CVE-2026-76504? Cisco says a zero-day in Catalyst SD-WAN Manager lets unauthenticated attackers gain admin-level access by bypassing authentication (CVE-2026-76504). The company attributes the bug to improper handling of URI encoding in HTTP requests, allowing crafted requests to slip past the login check and escalate privileges.
What is CVE-2026-73570? Microsoft says attackers can remotely run OS commands on internet-facing Zimbra Collaboration Suite servers through an unauthenticated command injection flaw (CVE-2026-73570), turning email infrastructure into an entry point for deeper compromise. The activity targets environments where SNMP notifications are enabled, with attackers using crafted SMTP requests to trigger Zimbra’s SNMP notification processing and execute commands as the zimbra service account.
What is CVE-2026-86950? CISA added an Apple out-of-bounds write vulnerability to its Known Exploited Vulnerabilities Catalog, warning it can be used to take total control of affected assets after exploitation (CVE-2026-86950). The practical risk is that a successful attack can translate into unauthorized access and data breaches, a high-consequence outcome for enterprises that depend on Apple devices and services.
What is ThreeAM? ThreeAM, a ransomware group, has claimed unauthorized access to St James’ Anglican School in Western Australia and threatened to publish stolen data. The school disclosed the incident on September 14 and began a cybersecurity audit, then the group publicly asserted involvement on September 28 as pressure for extortion.
What is Global Group? Global Group, a Ransomware-as-a-Service operation described as a rebranding of Black Lock and Mamona, is targeting large enterprises with phishing that leads to file encryption and data-theft extortion. The campaign begins with an email posing as a “Suggested Payment Plan,” pushing recipients toward a booby-trapped download that ultimately pulls down the encryptor.
What is DarkSword? DarkSword, described as an exploit kit used by Russian hackers, is being used in watering-hole attacks to compromise iPhones used by Ukrainian military personnel and government officials, alongside Android malware pushed by UAC-0244 and UAC-0263. Ukrainian authorities said DarkSword was used against a regional news outlet, a local court, and a food processing company, reflecting a wider pressure campaign on the country’s institutions.


