Summary
A single poisoned npm package can turn a routine software update into a full-scale breach. The Tensorlake 0.5.144 release, flagged by Socket, hijacks developer and CI environments to steal credentials and execute remote code, forcing organizations to block the package, revoke secrets, and audit for unauthorized access. Cyware.com tracks this as part of a broader wave of supply chain attacks targeting AI agent infrastructure.
Attackers are slashing through network defenses by exploiting zero-day flaws in Cisco Secure Firewall Management Center. The Interlock ransomware group used CVE-2026-20131, rated CVSS 10.0, to gain root access and pivot from management servers to security devices, with Amazon’s MadPot sensors detecting exploitation 36 days before Cisco’s disclosure. Fixed releases are now available, but active exploitation continues.
A $388 million cryptocurrency heist has exposed the fragility of third-party security tools. North Korea-linked hackers breached Bitget by exploiting a zero-day in external software, harvesting credentials and draining hot and warm wallets while cold storage remained untouched. The incident underscores how a single vendor flaw can trigger massive unauthorized withdrawals and ripple across the crypto market.
Top Malware Reported in the Last 24 Hours
Tensorlake npm package ships credential-stealing malware
Tensorlake version 0.5.144 was published as a booby-trapped npm release in a ChainDrop/Shai-Hulud-style supply chain attack, turning a routine dependency install into credential theft and remote code execution. It uses a preinstall hook to run during installation, then hunts for secrets such as npm and GitHub tokens, AWS credentials, Kubernetes and HashiCorp Vault data, and other sensitive files from developer machines and CI environments. The payload also establishes persistence via a PowerShell monitor and can execute remotely supplied code, raising the risk that a single compromised build pipeline becomes a launchpad into broader environments. Socket flagged the malicious release shortly after it appeared on October 8, 2026, describing it as consistent with prior ChainDrop/Shai-Hulud compromises aimed at AI agent infrastructure. Organizations are being told to block tensorlake@0.5.144, identify and isolate any environment where it executed, revoke and replace exposed credentials from a clean system, and audit connected accounts for unauthorized access and changes.
DarkSword iPhone exploits target crypto wallets
DarkSword is an exposed iOS exploitation platform that researchers say is being used to compromise iPhones and steal cryptocurrency wallet information as part of a commercial exploitation-as-a-service operation. It targets wallet apps including MetaMask, Phantom, Trust Wallet, Coinbase, Exodus, and imToken, using purpose-built modules designed to inject theft capabilities into those applications. The reporting ties the activity to CVE-2026-31001 and describes supporting infrastructure such as an admin application and a database that exposed operational details, with signs of Chinese-language administration panels. For victims, the outcome is direct financial loss: the platform searches for BIP39 recovery phrases in photos and Notes and exfiltrates only validated mnemonics that can unlock funds. The write-up recommends monitoring for connections to the specific IP addresses and domains listed in its IOC section, updating iOS devices, and conducting targeted threat hunting for signs of compromise.
ChainDrop and PolinRider hide C2 on blockchains
ChainDrop and PolinRider are being tracked as campaigns that use poisoned open-source packages to steal cloud and CI/CD credentials, then rely on blockchain networks for resilient command-and-control that is harder to take down. Instead of pinning their infrastructure to a traditional server, they resolve where compromised systems should connect by querying blockchain transactions, letting operators redirect victims without changing the malware. The campaigns are described as delivering payloads such as DEV#POPPER and OmniStealer for credential theft, browser-data collection, wallet theft, and remote command execution, with persistence mechanisms including VS Code tasks and other hooks. Coverage of the activity says ChainDrop—linked to the Shai-Hulud code lineage—infected over 400 npm packages, while PolinRider expanded across multiple package registries and extensions. For software teams, the human cost is operational and financial: a single tainted dependency can spill secrets that attackers reuse to breach repositories, CI systems, and production cloud environments.
Top Vulnerabilities Reported in Last 24 hours
Ransomware used Cisco firewall bug as zero-day
Two unauthenticated remote code execution flaws in Cisco Secure Firewall Management Center let internet attackers run code as root and potentially take over the management plane for Firepower Threat Defense devices (CVE-2026-20131 and CVE-2026-20079, both CVSS 10.0). In practical terms, a compromise can ripple from the management server to the security devices it controls, turning defensive infrastructure into an entry point for broader network access. Attackers are already exploiting this in the wild, and the Interlock ransomware group exploited CVE-2026-20131 as a zero-day. Amazon’s MadPot sensor network detected exploitation on January 26, 2026—36 days before Cisco became aware—and Cisco disclosed both vulnerabilities on March 4, 2026; CVE-2026-20079 was also observed in the wild in August 2026. Fixed releases are available: 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2, and 10.1.0.
Citrix NetScaler flaw enables remote root takeover
A critical log-injection bug in Citrix NetScaler ADC and Gateway lets unauthenticated attackers execute arbitrary commands as root, opening the door to full appliance takeover (CVE-2026-88771). The abuse is straightforward in outcome: attackers can move from a single crafted request to persistent access, data theft, and follow-on intrusion activity that can outlast a reboot. Attackers are already exploiting this in the wild, with exploitation beginning on September 28, 2026 and surpassing 1,069 injection attempts from 30 distinct IPs by October 7, 2026, according to Huntback’s analysis. Researchers at Huntback describe multiple operators with different goals, including credential theft, implants, and a “log-channel” command-and-control method. Patches are available in 14.1-73.37 and 13.1-64.24.
Cisco Nexus switch bugs risk network outages
Three critical flaws in Cisco Nexus 3000 and 9000 Series switches could let unauthenticated remote attackers execute code with root privileges—or crash key processes and force reloads—putting core network availability at risk (CVE-2026-76485, CVE-2026-76486, CVE-2026-76501; CVSS 9.8). The vulnerabilities sit in Cisco NX-OS’s Next Generation OAM (NGOAM) feature, meaning a single vulnerable interface exposed to hostile traffic can become the trigger for disruption or takeover. No active exploitation has been publicly reported yet. Cisco’s advisories tie the issue to improper input validation of IP traffic when NGOAM is enabled, with some cases requiring additional features such as SRv6 or NV Overlay to be turned on. Software updates are available from Cisco.
Top Threat Actors Reported in Last 24 hours
UAC-0099 spreads MATCHBOIL spyware in Ukraine
UAC-0099, a Russia-aligned threat group believed to act as an initial access broker, is using its evolving MATCHBOIL malware to quietly plant an espionage backdoor on Windows systems in Ukraine. They have recently focused on transportation, manufacturing, and energy targets, using spear-phishing emails that push victims to a link that downloads a VBScript and kicks off the infection chain. For organizations running critical services, the human cost is operational disruption and the loss of sensitive internal data that can be leveraged for follow-on intrusions by other APT actors. Researchers say the toolset has shifted over two years, including changes in how payloads are hidden and delivered, and defenders are being told to look for artifacts such as MeowMeowProgramm.exe, SMTPClientApplication.exe, and a scheduled task named Checker. The malware also uses Eziriz .NET Reactor for obfuscation and performs sandbox checks by inspecting system uptime and installation dates. Recommended actions from the report include targeted threat hunting for those filenames/tasks, enhancing email security against spear phishing, and updating endpoint protection to detect and block MATCHBOIL-related activity.
North Korea-linked hackers hit Bitget
The Bitget breach that surfaced on September 24, 2026 turned into a $388 million loss after attackers exploited a zero-day flaw in third-party security software, according to a public write-up and comments from Bitget’s CEO pointing to likely North Korean involvement. Rather than stealing private keys, the intruders allegedly used the third-party weakness to harvest internal credentials and insert fraudulent withdrawal instructions, draining the exchange’s hot and warm wallets while cold storage stayed secure. For customers and the broader crypto market, the episode is a reminder that a vendor dependency can become the single point of failure that enables large-scale unauthorized withdrawals. Investigators traced unauthorized transfers back to August 31, 2026, and the attackers reportedly ran two test transfers before executing the larger theft. The incident’s central takeaway is the fragility of third-party security tooling in high-value environments, where a single unknown bug can be monetized at scale. Recommended actions cited include rebuilding protection funds and publishing vendor security attestations for third-party tools, alongside continuous auditing and monitoring of that software.
Wazza phishkit targets US and EU
Wazza is a phishing kit being used to target banking, government, and manufacturing organizations across the US, the EU, and Australia by selectively showing victims an Adobe-themed credential-stealing page. The operators rely on a multi-stage routing chain that starts from a wildcard landing domain and then filters and validates visitors before letting only chosen requests reach the final phishing lure. For employees who handle invoices, documents, or admin portals, that means a single convincing login prompt can lead to account takeover, trusted identity abuse, and follow-on phishing from a legitimate-looking foothold. The campaign is designed to frustrate defenders by hiding the real payload from automated scanners and casual inspection, using session tokens and browser validation to control access. The reporting describes the kit as actively used and geared toward high-value targets, suggesting the infrastructure is being maintained to keep phishing pages reachable while reducing exposure to takedowns.
Frequently Asked Questions
What is Tensorlake? Tensorlake version 0.5.144 was published as a booby-trapped npm release in a ChainDrop/Shai-Hulud-style supply chain attack, turning a routine dependency install into credential theft and remote code execution. It uses a preinstall hook to run during installation, then hunts for secrets such as npm and GitHub tokens, AWS credentials, Kubernetes and HashiCorp Vault data, and other sensitive files from developer machines and CI environments.
What is DarkSword? DarkSword is an exposed iOS exploitation platform that researchers say is being used to compromise iPhones and steal cryptocurrency wallet information as part of a commercial exploitation-as-a-service operation. It targets wallet apps including MetaMask, Phantom, Trust Wallet, Coinbase, Exodus, and imToken, using purpose-built modules designed to inject theft capabilities into those applications.
What is ChainDrop? ChainDrop and PolinRider are being tracked as campaigns that use poisoned open-source packages to steal cloud and CI/CD credentials, then rely on blockchain networks for resilient command-and-control that is harder to take down. Instead of pinning their infrastructure to a traditional server, they resolve where compromised systems should connect by querying blockchain transactions, letting operators redirect victims without changing the malware.
What is CVE-2026-20131? Two unauthenticated remote code execution flaws in Cisco Secure Firewall Management Center let internet attackers run code as root and potentially take over the management plane for Firepower Threat Defense devices (CVE-2026-20131 and CVE-2026-20079, both CVSS 10.0). In practical terms, a compromise can ripple from the management server to the security devices it controls, turning defensive infrastructure into an entry point for broader network access.
What is CVE-2026-88771? A critical log-injection bug in Citrix NetScaler ADC and Gateway lets unauthenticated attackers execute arbitrary commands as root, opening the door to full appliance takeover (CVE-2026-88771). The abuse is straightforward in outcome: attackers can move from a single crafted request to persistent access, data theft, and follow-on intrusion activity that can outlast a reboot.
What is CVE-2026-76485? Three critical flaws in Cisco Nexus 3000 and 9000 Series switches could let unauthenticated remote attackers execute code with root privileges—or crash key processes and force reloads—putting core network availability at risk (CVE-2026-76485, CVE-2026-76486, CVE-2026-76501; CVSS 9.8). The vulnerabilities sit in Cisco NX-OS’s Next Generation OAM (NGOAM) feature, meaning a single vulnerable interface exposed to hostile traffic can become the trigger for disruption or takeover.
What is UAC-0099? UAC-0099, a Russia-aligned threat group believed to act as an initial access broker, is using its evolving MATCHBOIL malware to quietly plant an espionage backdoor on Windows systems in Ukraine. They have recently focused on transportation, manufacturing, and energy targets, using spear-phishing emails that push victims to a link that downloads a VBScript and kicks off the infection chain.
What is Bitget? The Bitget breach that surfaced on September 24, 2026 turned into a $388 million loss after attackers exploited a zero-day flaw in third-party security software, according to a public write-up and comments from Bitget’s CEO pointing to likely North Korean involvement. Rather than stealing private keys, the intruders allegedly used the third-party weakness to harvest internal credentials and insert fraudulent withdrawal instructions, draining the exchange’s hot and warm wallets while cold storage stayed secure.
What is Wazza? Wazza is a phishing kit being used to target banking, government, and manufacturing organizations across the US, the EU, and Australia by selectively showing victims an Adobe-themed credential-stealing page. The operators rely on a multi-stage routing chain that starts from a wildcard landing domain and then filters and validates visitors before letting only chosen requests reach the final phishing lure.


