Cyware Daily Threat Intelligence - September 08, 2026

A ransomware cartel is slashing through enterprise defenses, as a former hacktivist crew pivots to profit and leaves a trail of financial damage. Cyware spotlights how a single attack on a major retailer triggered a plunge from £391.4 million to £3.4 million in statutory profit, with £136 million spent on direct response—underscoring the real-world impact of ransomware-as-a-service alliances.
A critical flaw in e-commerce platforms is exposing over 100,000 webstores to full takeover, as attackers run their own code and silently install backdoors. With a CVSS 10.0 bug already exploited in the wild, organizations face a 72-hour race to patch and rotate credentials before customer data and payment details are siphoned away.
Phishing-as-a-service is scaling credential theft to new heights, with one operation bypassing multi-factor authentication at 258 organizations and exfiltrating over 5,000 Microsoft 365 credentials. Attackers are hijacking sessions in real time, turning stolen cookies and passwords into mailbox takeovers and internal fraud across the cloud.
Top Malware Reported in the Last 24 Hours
DragonForce
DragonForce is a ransomware-as-a-service operation that has evolved from a pro-Palestine hacktivist group into a cartel-style alliance with LockBit and Qilin, sharing resources and infrastructure. DragonForce exploits SimpleHelp vulnerabilities for initial access and leverages admin tools such as AdFind for network discovery and PsExec for lateral movement. DragonForce wipes traces and encrypts files, mapped to MITRE ATT&CK techniques T1070 (Indicator Removal on Host) and T1486 (Data Encrypted for Impact). DragonForce gains entry by exploiting SimpleHelp flaws and then uses familiar admin tools to blend into IT environments. DragonForce targeted Marks & Spencer, causing statutory profit to fall from £391.4 million to £3.4 million, with £136 million in direct response expenses. DragonForce lowers the barrier for affiliates by charging a $500 registration fee, enabling rapid scaling through partnerships.
PoisonedRefresh
PoisonedRefresh is a stealthy malware strain targeting F5 BIG-IP systems, exploiting CVE-2025-53521 for remote code execution while leaving original files unchanged on disk. PoisonedRefresh intercepts file and memory operations inside Apache’s PHP module, running altered PHP in memory to evade forensic checks. PoisonedRefresh uses a custom ELF loader to seize control before normal application flow and communicates via a UNIX domain socket at /run/bigtlog.pipe. PoisonedRefresh supports HTTP-driven code execution and local interactive access once inside. PoisonedRefresh targets organizations relying on BIG-IP APM, enabling attackers to maintain access and manipulate web-facing behavior without obvious on-disk tampering. Researchers documented PoisonedRefresh’s architecture and techniques.
ClearFake and Interlock
ClearFake is a WebDAV-based infection chain delivering credential and cryptocurrency theft tools, including the Amatera stealer, ZigCryptoStealer, and NetSupport Manager, using DLL loaders such as verification[.]google and pf[.]ch to execute payloads. ClearFake begins with Cloudflare Workers injecting JavaScript from BNB Smart Chain, then stealthily loads additional components for remote control and data theft. ClearFake has targeted Ukrainian government organizations, highlighting the risk to public-sector operations. Interlock distributes a new RAT variant via compromised websites using a FileFix lure, where a fake “Open File Explorer” button copies PowerShell to the clipboard and prompts users to paste it, resulting in self-delivered malware. Interlock uses trycloudflare URLs for command-and-control, and hands-on-keyboard activity has been observed, exposing victims to direct, interactive intrusions.
Top Vulnerabilities Reported in Last 24 hours
CVE-2026-75650 in Magento and Adobe Commerce
CVE-2026-75650 is a critical remote code execution vulnerability in Magento and Adobe Commerce with a CVSS score of 10.0. Successful exploitation allows attackers to run arbitrary code on vulnerable webstore servers, enabling full takeover and theft of customer data, including credit card information. CVE-2026-75650 is actively exploited in the wild, with criminal groups deploying backdoors and stealing data since September 4, 2026. Adobe released an emergency patch outside its regular schedule in response to these attacks. Organizations are urged to apply the patch within 72 hours, rotate encryption keys and credentials, and monitor for Indicators of Compromise. Over 100,000 webstores use these platforms.
CVE-2026-80172, CVE-2026-61410, CVE-2026-80238 in Dell Secure Connect Gateway
CVE-2026-80172 (CVSS 9.8), CVE-2026-61410 (CVSS 9.4), and CVE-2026-80238 (CVSS 9.3) are critical vulnerabilities in Dell Secure Connect Gateway (SCG) that allow unauthenticated attackers to gain administrative access and execute remote commands, potentially leading to full host takeover. Exploitation could result in replay-style request abuse and container escape via an exposed Docker socket. No active exploitation has been reported. Dell disclosed the issues, highlighting how CVE-2026-80238 increases post-compromise risk. Dell recommends upgrading to fixed SCG versions, restricting management interfaces to trusted networks, and reviewing logs for unusual activity.
CVE-2026-76578 and CVE-2026-79678 in FreeIPA and 389 Directory Server
CVE-2026-76578 (CVSS 9.8) is a critical vulnerability chain in FreeIPA and 389 Directory Server that allows an anonymous client to create reusable administrator credentials, granting high-privilege access across identity environments. Successful exploitation enables unauthorized Kerberos identity creation and privilege escalation, while CVE-2026-79678 can expose server environment variables, posing additional risk for container deployments. No in-the-wild exploitation has been reported, but the issue is reproducible on default installations. Red Hat reproduced and verified the exploit using standard administrator commands. Patches are available (including FreeIPA 4.13.4), and organizations should restrict LDAP access to trusted hosts and disable anonymous LDAP binds.
Top Threat Actors Reported in Last 24 hours
DragonForce
DragonForce (no known aliases), suspected to originate from a pro-Palestine hacktivist background, now operates as a ransomware-as-a-service group with a primary motive of financial gain. DragonForce forms a cartel with LockBit and Qilin, sharing infrastructure and lowering affiliate entry barriers with a $500 registration fee. DragonForce exploits SimpleHelp vulnerabilities, including path-traversal and arbitrary file-upload flaws, and uses the Backdoor.Turn implant to blend command-and-control traffic with legitimate Microsoft Teams activity. DragonForce targets enterprise organizations, as seen in the Marks & Spencer attack, which resulted in statutory profit dropping from £391.4 million to £3.4 million and £136 million in direct response expenses. DragonForce’s affiliates use MITRE ATT&CK techniques T1070 and T1486, and the group’s tradecraft is documented in recent reporting.
TeamPCP (UNC6780)
TeamPCP (tracked as UNC6780), suspected to operate as an extortion crew, focuses on stealing proprietary data powering AI systems for financial leverage. TeamPCP uses compromise paths targeting developer and build environments, including malicious GitHub Actions workflows, and employs agentic AI to autonomously scan for vulnerabilities and execute attacks. TeamPCP targets technology, healthcare, pharmaceutical, and media and entertainment sectors across North America and Europe. TeamPCP’s campaign centers on exfiltrating unique IP, product roadmaps, and sensitive data for use in negotiations or reputational attacks. The report frames TeamPCP’s activity as part of a broader trend of extortion crews targeting “AI data” as a premium asset class.
BigBear 2.0
BigBear 2.0, a phishing-as-a-service operation, is suspected to be financially motivated and has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. BigBear 2.0 uses an Evilginx2-style adversary-in-the-middle approach to intercept passwords and session cookies, enabling account hijacking even after MFA. BigBear 2.0 exfiltrated 5,137 credential records, including 474 MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies. BigBear 2.0 targets organizations using Microsoft 365, exposing them to mailbox takeovers, internal fraud, and downstream compromise. The operation’s multi-user panel was leased to at least five affiliates and used live Telegram exfiltration bots to push stolen credentials in real time.
Frequently Asked Questions
What is DragonForce? DragonForce has shifted from a pro-Palestine hacktivist identity into a full ransomware-as-a-service operation by forming a cartel-style alliance with LockBit and Qilin that shares resources and infrastructure. It breaks in by exploiting SimpleHelp vulnerabilities and then uses familiar admin tools such as AdFind for network discovery and PsExec for lateral movement, making activity harder to spot in busy IT environments.
What is PoisonedRefresh? PoisonedRefresh is a stealthy malware strain aimed at F5 BIG-IP systems, using CVE-2025-53521 to gain remote code execution while keeping original files on disk unchanged. It does this by intercepting file and memory operations inside Apache’s PHP module so altered PHP runs in memory, helping it blend into routine web traffic and evade quick forensic checks.
What is ClearFake? ClearFake is a WebDAV-based infection chain that delivers credential and cryptocurrency theft tools including the Amatera stealer, ZigCryptoStealer, and NetSupport Manager, using DLL loaders such as “verification[.]google” and “pf[.]ch” to execute payloads. It starts with Cloudflare Workers injecting JavaScript retrieved from BNB Smart Chain, then moves through stealthy loading tricks to pull in additional components that enable remote control and data theft.
What is CVE-2026-75650? A critical remote code execution bug in Magento and Adobe Commerce (CVE-2026-75650, CVSS 10.0) is being used to run attacker-controlled code directly on vulnerable webstore servers, giving criminals a path to full takeover. In practical terms, that can translate into stolen customer data (including credit card information) and the silent installation of backdoors that keep access open even after the initial break-in.
What is CVE-2026-80172? Three critical flaws in Dell Secure Connect Gateway (SCG) can let an unauthenticated attacker gain administrative access and execute remote commands, potentially taking over the host system (CVE-2026-80172 CVSS 9.8; CVE-2026-61410 CVSS 9.4; CVE-2026-80238 CVSS 9.3). The most dangerous outcomes include replay-style abuse of requests (due to missing nonce validation and time limits) and a container escape scenario via an exposed Docker socket that can turn a foothold into full host compromise.
What is CVE-2026-76578? A critical vulnerability chain in FreeIPA and 389 Directory Server lets an anonymous client create reusable administrator credentials, effectively minting high-privilege access that can put an entire identity environment at risk (CVE-2026-76578, CVSS 9.8). The chain allows unauthorized Kerberos identity creation and privilege gain, and a related issue (CVE-2026-79678) can expose server environment variables—an added concern for container-based deployments.
What is DragonForce? DragonForce, a ransomware group that the source says evolved from pro-Palestine hacktivism into a ransomware-as-a-service business, is growing by behaving more like a coalition than a lone crew. They have formed a cartel model with LockBit and Qilin, sharing resources and infrastructure while lowering affiliate entry barriers, including a $500 registration fee.
What is TeamPCP? TeamPCP (tracked as UNC6780) is described as an extortion crew increasingly focused on stealing the data that powers AI systems, turning proprietary models and source code into leverage for payouts. The campaign centers on compromise paths that reach developer and build environments, including malicious GitHub Actions workflows, and the report also describes the use of agentic AI to autonomously scan for vulnerabilities and execute attacks with less manual effort.
What is BigBear 2.0? BigBear 2.0, a phishing-as-a-service operation, has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials, according to the report. Built around an Evilginx2-style adversary-in-the-middle approach, they intercept passwords and session cookies so attackers can hijack accounts even after MFA is completed.