Cyware at Auto-ISAC Summit 2026
Understand Where You Are on the CTI Maturity Curve
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - October 02, 2026

10 min read
Share this article
shutterstock 1951619836

Summary

Attackers are hijacking browser sessions and trusted update channels to bypass multi-factor authentication and quietly steal credentials at scale. On cyware.com, analysts are tracking the Remus infostealer as it targets AI developer tools and browser sessions, while the Shai-Hulud worm has exposed over 500,000 credentials across more than 1,000 organizations by poisoning npm package updates.

Ransomware operations are evolving into global cartels that cripple business operations in minutes. DragonForce, now operating as a white-label RaaS, has claimed several hundred victims worldwide by terminating security software, deleting backups, and encrypting both local and network drives, forcing organizations into high-pressure ransom negotiations.

Critical vulnerabilities are under active exploitation, with federal agencies facing urgent patch deadlines. Attackers are leveraging CVE-2026-104286 in Fortinet FortiMail and CVE-2026-76504 in Cisco SD-WAN Manager—both rated CVSS 9.8—to gain code execution or admin access, while Finland’s NCSC-FI warns that NetScaler flaws may have enabled persistent intrusions even before patches were released.

Espionage and ransomware groups are targeting policy insiders and critical infrastructure with tailored campaigns. TA419 is impersonating AI policy figures to phish US government insiders, Longlegs is exploiting SharePoint vulnerabilities to spread Warlock ransomware across utilities and universities, and Shai-Hulud’s supply-chain attacks are cascading through developer ecosystems, putting source code and cloud environments at risk.

CTA_1_LI_Wednesday_Friday_DTI_WTI_After_Overview

Top Malware Reported in the Last 24 Hours

Remus infostealer hijacks sessions via MaaS

Remus is a MaaS infostealer built to steal authenticated browser sessions so attackers can slip past MFA, and it has expanded into harvesting data from AI clients including Claude, Codex, OpenCode, Cursor, and Devin. It uses PLYCHIP pre-filtering and screening to reduce detection while pulling credentials, session tokens, and even clipboard contents through browser-focused theft. The campaign runs through multiple delivery chains, including ClickFix, DonutLoader, and GoFlateLoader, and it has been observed using delivery domains such as one-verif[.]lol and genuskox[.]biz. It also spoofs Host headers to look like microsoft[.]com or github[.]com, while relying on EtherHiding to rotate C2 locations by querying the Ethereum blockchain. For organizations, the practical impact is account takeover that can look like normal, already-authenticated activity, turning stolen sessions into fast paths to email, cloud consoles, and developer tools.

Shai-Hulud worm spreads through npm updates

Shai-Hulud is a credential-stealing worm driving a new wave of supply-chain attacks by abusing trusted software update channels inside developer environments. It self-propagates by using stolen npm publishing credentials to push malicious package versions, letting it spread quickly wherever dependencies are routinely updated. The campaign also leverages locally installed AI tools such as Claude and Gemini to help identify high-value secrets like GitHub credentials and cloud keys before sending them out to attacker-controlled repositories. The reporting ties this activity to broader campaigns including S1ngularity, with more than 1,000 organizations compromised and over 500,000 credentials exposed. For affected teams, the immediate fallout is that a routine dependency update can turn into a quiet leak of the keys that protect source code, CI/CD pipelines, and cloud infrastructure.

DragonForce ransomware cartel cripples networks globally

DragonForce is a RaaS operation that has evolved from hacktivism into a profit-driven cartel, advertising a white-label model that lets affiliates keep their own branding while using its infrastructure. It pushes infections forward by interfering with defenses and operations, including terminating security and productivity software processes and deleting shadow copies using WMIC commands. It also maps a victim environment by discovering network targets through ARP-based SMB share enumeration, enabling concurrent encryption across local and network drives. Seqrite reports it had claimed several hundred victims across multiple countries by mid-2026, while ransom notes assert data theft even though no exfiltration was observed in the analysis. For victims, the result is the familiar business-level disruption—file access collapses across shared drives and endpoints at once—paired with pressure tactics designed to force payment under tight timelines.

Top Vulnerabilities Reported in Last 24 hours

FortiMail zero-day lets attackers run code

A critical flaw in Fortinet FortiMail (CVE-2026-104286, CVSS 9.8) is being used in zero-day attacks to execute unauthorized code or commands on exposed mail-security systems. The attack path hinges on path traversal combined with null byte injection, allowing attackers to break out of intended directories and reach code-execution outcomes. Attackers are already exploiting this in the wild. Fortinet disclosed the issue as CISA set an October 4 mitigation deadline for U.S. federal agencies. The vulnerable range includes FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9; Fortinet recommends disabling the IBE feature and restricting exposure of the management interface, alongside applying available updates.

Cisco SD-WAN bug bypasses admin login

A critical authentication bypass in Cisco Catalyst SD-WAN Manager (CVE-2026-76504, CVSS 9.8) lets unauthenticated attackers reach the management API with administrator privileges, effectively weakening the security policies organizations rely on to control network traffic. While it is not described as direct remote code execution, admin-level API access can enable follow-on actions that reshape configurations and access. Attackers are already exploiting this in the wild, and Cisco confirmed active exploitation in September 2026. CISA has added the bug to its Known Exploited Vulnerabilities catalog with an October 3, 2026 deadline for federal agencies. Affected releases include 20.12.x earlier than 20.12.8.2, 20.15.x earlier than 20.15.6.1, 20.18.x earlier than 20.18.4.1, 26.1.x earlier than 26.1.2.1, 26.2.x earlier than 26.2.1, and releases earlier than 20.9; Cisco’s guidance includes moving to a fixed release, collecting admin-tech files for Cisco TAC, restricting management access, and reviewing administrator accounts.

Finland warns NetScaler attacks may linger

Finland’s National Cyber Security Centre (NCSC-FI) says attackers have actively exploited vulnerabilities in Citrix NetScaler ADC and Gateway, enabling remote code execution and denial-of-service against internet-facing systems. The agency warns the activity began before security updates were released, raising the risk that intruders established persistence that routine patching alone might not reveal. Attackers have already exploited these flaws in the wild in Finland. NCSC-FI reported identifying hundreds of NetScaler instances in the country and contacting administrators as part of the response. The affected products include NetScaler ADC and Gateway 13.1 and 14.1 (including FIPS and NDcPP builds) prior to patched releases; NCSC-FI’s advice centers on updating to the latest fixed versions, conducting thorough investigations for signs of compromise, and reporting observed exploitation attempts back to NCSC-FI.

Top Threat Actors Reported in Last 24 hours

TA419 phishes US AI policy insiders

TA419, a China-aligned espionage group, is impersonating AI policy figures such as Lynne Parker and Heidi Crebo-Rediker to lure US policy insiders into handing over account access. They send invitations to a fictitious “AI Policy Advisory Committee” or requests to assist with a Senate Committee report, pushing targets toward a fake Microsoft sign-in flow. After the first mention, they route victims through shortened links to a spoofed OneDrive login page designed to capture credentials and Microsoft 365 session cookies for longer-lived access. For policy professionals, this can turn a routine-looking email about AI governance into a compromise of calendars, documents, and sensitive conversations. The write-up says organizations are urged to adopt phishing-resistant sign-in methods such as passkeys, while individuals are advised to verify unexpected requests through independent channels.

Longlegs spreads Warlock via SharePoint flaws

Longlegs, a China-nexus threat actor, is driving the Warlock ransomware campaign by continuing to exploit Microsoft SharePoint Server vulnerabilities to break into organizations. In the past two months, they have attacked at least four victims, including a water utility, a telecommunications provider, a regional government body, and a university across Europe, Africa, and Latin America. For critical infrastructure operators and public-sector institutions, these intrusions can quickly become operational outages and service disruptions, not just an IT incident. The reporting says they also rely on DLL sideloading and living-off-the-land techniques to blend into normal system activity while pushing ransomware through a victim’s network. The source adds that defenders are monitoring a set of file and network indicators tied to this activity.

Shai-Hulud supply-chain worm steals credentials

The Shai-Hulud campaign is a supply-chain operation using trusted software update paths to plant credential-stealing malware and then spread further through developer ecosystems. After first appearing in reporting alongside related activity, it uses stolen npm publishing credentials to push malicious package versions that can self-propagate across environments that consume those updates. The same coverage says the malware can use locally installed AI tools such as Claude and Gemini to help identify high-value secrets—like GitHub credentials and cloud keys—and exfiltrate them to attacker-controlled repositories. For organizations, the risk is that a single poisoned dependency update can cascade into wider access across build pipelines, source code, and cloud infrastructure. Recommended actions highlighted in the report include shifting package publishing to short-lived, workload-bound credentials via trusted publishing and OIDC, enforcing least privilege on repository and registry tokens, requiring review and provenance checks for dependency updates, and continuously monitoring for unexpected preinstall and postinstall behavior.

CTA_2_LI_Wednesday_Friday_DTI_WTI_Before_FAQ

Frequently Asked Questions

  1. What is Remus? <b>Remus</b> is a MaaS infostealer built to steal authenticated browser sessions so attackers can slip past MFA, and it has expanded into harvesting data from AI clients including Claude, Codex, OpenCode, Cursor, and Devin. It uses PLYCHIP pre-filtering and screening to reduce detection while pulling credentials, session tokens, and even clipboard contents through browser-focused theft.

  2. What is Shai-Hulud? <b>Shai-Hulud</b> is a credential-stealing worm driving a new wave of supply-chain attacks by abusing trusted software update channels inside developer environments. It self-propagates by using stolen npm publishing credentials to push malicious package versions, letting it spread quickly wherever dependencies are routinely updated.

  3. What is DragonForce? <b>DragonForce</b> is a RaaS operation that has evolved from hacktivism into a profit-driven cartel, advertising a white-label model that lets affiliates keep their own branding while using its infrastructure. It pushes infections forward by interfering with defenses and operations, including terminating security and productivity software processes and deleting shadow copies using WMIC commands.

  4. What is CVE-2026-104286? A critical flaw in Fortinet FortiMail (<b>CVE-2026-104286</b>, CVSS <b>9.8</b>) is being used in zero-day attacks to execute unauthorized code or commands on exposed mail-security systems. The attack path hinges on <b>path traversal</b> combined with <b>null byte injection</b>, allowing attackers to break out of intended directories and reach code-execution outcomes.

  5. What is CVE-2026-76504? A critical authentication bypass in Cisco Catalyst SD-WAN Manager (<b>CVE-2026-76504</b>, CVSS <b>9.8</b>) lets unauthenticated attackers reach the management API with administrator privileges, effectively weakening the security policies organizations rely on to control network traffic. While it is not described as direct remote code execution, admin-level API access can enable follow-on actions that reshape configurations and access.

  6. What is TA419? <b>TA419</b>, a China-aligned espionage group, is impersonating AI policy figures such as Lynne Parker and Heidi Crebo-Rediker to lure US policy insiders into handing over account access. They send invitations to a fictitious “AI Policy Advisory Committee” or requests to assist with a Senate Committee report, pushing targets toward a fake Microsoft sign-in flow.

  7. What is Longlegs? <b>Longlegs</b>, a China-nexus threat actor, is driving the <b>Warlock</b> ransomware campaign by continuing to exploit Microsoft SharePoint Server vulnerabilities to break into organizations. In the past two months, <i>they</i> have attacked at least <b>four</b> victims, including a water utility, a telecommunications provider, a regional government body, and a university across Europe, Africa, and Latin America.

  8. What is Shai-Hulud? The <b>Shai-Hulud</b> campaign is a supply-chain operation using trusted software update paths to plant credential-stealing malware and then spread further through developer ecosystems. After first appearing in reporting alongside related activity, <i>it</i> uses stolen npm publishing credentials to push malicious package versions that can self-propagate across environments that consume those updates.

Share this article

Discover Related Resources