Cyware Daily Threat Intelligence - September 10, 2026

Attackers are turning critical Fortinet vulnerabilities into remote-controlled footholds, with over 30,000 IP addresses targeted and 178 devices infected by the PivotC2 RAT. Cyware spotlights how a single unpatched device can quickly escalate into a network-wide compromise, with US organizations facing the brunt of these hands-on attacks.
A chained set of zero-day exploits, dubbed BlueMoon, is slashing through Chrome and Windows defenses, letting espionage groups like TA412 leap from a browser session to full system control. With attacks first observed on August 28, the campaign is targeting aerospace, manufacturing, and government sectors, raising the stakes for organizations worldwide.
Healthcare data is under siege as extortion groups like ShinyHunters and The Gentlemen breach patient records at scale. The AdaptHealth incident alone exposed information tied to 4.1 million individuals, fueling identity theft and fraud risks that persist long after the initial compromise.
Top Malware Reported in the Last 24 Hours
PivotC2 RAT via Fortinet CVE-2025-25249
PivotC2 RAT is a remote-access trojan that provides attackers with persistent, hands-on control over compromised Fortinet devices. PivotC2 RAT enables command execution, traffic tunneling, network scanning, and configuration harvesting, allowing attackers to escalate a single breach into a network-wide incident. PivotC2 RAT leverages a critical remote-code-execution flaw (CVE-2025-25249) to gain initial access and maintain control. PivotC2 RAT primarily targets US entities, with SecurityWeek reporting over 30,000 IP addresses hit and 178 devices infected since July 2026, with at least two cases involving data exfiltration. The campaign is attributed to a likely Russian-speaking cybercrime actor, and patches are available for FortiOS 7.6.4, 7.4.9, 7.2.12, 7.0.18 and FortiSwitchManager 7.2.7, 7.0.6.
MacSync Stealer targets macOS users
MacSync Stealer is a macOS-focused infostealer designed to harvest sensitive data from Apple devices. MacSync Stealer collects browser credentials, Keychain data, SSH keys, and cryptocurrency-wallet information, enabling account takeovers and financial theft. MacSync Stealer spreads through ClickFix lures, search-engine malvertising, and SEO poisoning, tricking users into running Terminal commands that bypass macOS security controls. MacSync Stealer targets macOS users globally, often using landing pages impersonating brands like Claude AI, ChatGPT, and Google Meet. Researchers have observed Russian-language artifacts in the campaign, but have not attributed it to a specific actor.
Malicious browser extensions siphon crypto trading sessions
Malicious Chrome and Firefox extensions are being used to steal session tokens and wallet data from cryptocurrency traders using Axiom Trade and Padre. These extensions, including J7Tracker, VREO, and Orbit Tracker, leverage browser marketplace credibility to blend into user workflows and facilitate credential theft. The campaign employs shared code and command-and-control infrastructure, indicating an organized and repeatable attack method. The extensions target users of cryptocurrency trading platforms, with theft occurring inside authenticated browser sessions. Socket researchers have linked the campaign to earlier extensions like GhostApe and GhostApe Color, highlighting a persistent threat to crypto traders.
Top Vulnerabilities Reported in Last 24 hours
CVE-2025-25249: Fortinet remote code execution flaw
CVE-2025-25249 is a heap-based buffer overflow vulnerability in FortiOS and FortiSwitchManager with a CVSS score of critical. Successful exploitation allows attackers to execute arbitrary code, pivot deeper into victim environments, and deploy remote-access trojans like PivotC2. CVE-2025-25249 is actively exploited in the wild by likely Russian-speaking cybercrime actors. SecurityWeek reports over 30,000 IP addresses targeted and 178 devices infected, with at least two cases of data exfiltration. Patches are available in FortiOS 7.6.4, 7.4.9, 7.2.12, 7.0.18 and FortiSwitchManager 7.2.7, 7.0.6, and organizations should conduct thorough network scans and enhance monitoring.
CVE-2025-14733: WatchGuard Firebox RCE vulnerability
CVE-2025-14733 is a critical remote code execution vulnerability in WatchGuard Firebox firewalls. Exploitation allows unauthenticated attackers to run malicious code on exposed devices, potentially persisting even after vulnerable configurations are deleted. CVE-2025-14733 is actively exploited by ransomware gangs, with CISA confirming ongoing attacks and Shadowserver identifying over 115,000 unpatched Firebox firewalls online and nearly 9,000 still unsecured. BleepingComputer notes similarities to previous WatchGuard vulnerabilities, indicating a recurring issue. A patch is available from WatchGuard, and organizations should ensure secure configurations and conduct regular security audits.
BlueMoon zero-days: CVE-2026-85046, CVE-2026-87491, CVE-2026-85880
The BlueMoon exploit chain comprises two Chromium JavaScript-engine RCE vulnerabilities (CVE-2026-85046, CVE-2026-87491) and a Windows privilege-escalation zero-day (CVE-2026-85880), affecting Chrome and Microsoft Windows. Successful exploitation enables attackers to execute code, escape the browser sandbox, and escalate privileges to full system control. BlueMoon vulnerabilities are actively exploited in the wild, with Cyberscoop attributing early activity to Chinese espionage actors including TA412 and clusters UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket. The campaign targets aerospace, manufacturing, and government sectors, and patches are expected or becoming available. Organizations should apply patches promptly and implement network segmentation to limit potential fallout.
Top Threat Actors Reported in Last 24 hours
TA412 (China-linked espionage group)
TA412 (also tracked as a China-linked espionage group) is suspected to operate with a primary motive of intelligence collection. TA412 has recently leveraged a BlueMoon zero-day chain, using remote-code execution flaws in Chromium’s JavaScript engine (CVE-2026-85046, CVE-2026-87491) and a Windows privilege-escalation zero-day (CVE-2026-85880) to break out of browser sandboxes and gain elevated privileges. TA412 rapidly expanded the campaign to include clusters UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket, indicating the technique is spreading. TA412 targets aerospace, manufacturing, and government sectors, seeking long-term access to sensitive projects and communications. The campaign infrastructure was created shortly before attacks began, reflecting a coordinated effort to exploit the vulnerabilities before patches became available.
ShinyHunters (data extortion group)
ShinyHunters is a financially motivated data extortion group suspected of orchestrating large-scale breaches for profit. ShinyHunters used social engineering to compromise a third-party contractor’s privileged account and exfiltrated data from AdaptHealth’s cloud-based business applications. ShinyHunters targets healthcare providers, exposing patient management and health record data. In the AdaptHealth breach, 4.1 million individuals’ data was exposed, with a ransom demanded on June 15, 2026, and the incident disclosed via SEC filing on July 2, 2026. BleepingComputer noted AdaptHealth was not visible on ShinyHunters’ extortion site, suggesting the listing may have been removed.
The Gentlemen (ransomware group)
The Gentlemen is a ransomware group suspected of using double-extortion tactics for financial gain. The Gentlemen employ tooling such as SystemBC and GentleKiller to support data theft and defense evasion. The Gentlemen target healthcare technology firms, recently claiming responsibility for a breach at Veradigm linked to a third-party vendor incident. The Gentlemen stole patient data including names, addresses, Social Security numbers, emails, phone numbers, and guarantor information, exposing victims to identity theft and phishing. Veradigm reported no operational disruption and limited customer impact, but the exposed data types present long-term risk.
Frequently Asked Questions
What is CVE-2025-25249? CVE-2025-25249 is a critical Fortinet remote-code-execution flaw that attackers are already exploiting to install the PivotC2 RAT, turning exposed devices into remote-controlled footholds. Once in, it gives the intruder hands-on access for command execution, traffic tunneling, network scanning, and configuration harvesting, which can quickly widen a single breach into a network-wide incident.
What is MacSync Stealer? MacSync Stealer is a macOS-focused infostealer spreading through ClickFix lures and search-engine malvertising that coax users into running Terminal commands, effectively sidestepping normal macOS guardrails. It then goes after high-value secrets including browser credentials, Keychain data, SSH keys, and cryptocurrency-wallet information—data that can translate directly into account takeovers and financial theft.
What is CVE-2025-25249? Attackers are actively exploiting a critical remote code execution flaw in Fortinet products to install the PivotC2 remote-access trojan on vulnerable network gear (CVE-2025-25249). The bug is a heap-based buffer overflow in FortiOS and FortiSwitchManager, exploited via crafted requests to run attacker-controlled code and then pivot deeper into a victim environment using interactive shell access, tunneling, and network scanning.
What is CVE-2025-14733? Ransomware gangs are exploiting a critical remote code execution vulnerability in WatchGuard Firebox firewalls that lets unauthenticated attackers run malicious code on exposed devices (CVE-2025-14733). The issue is an out-of-bounds write, exploited to gain remote execution, and the report warns devices may remain compromised even if vulnerable configurations are deleted in some cases involving a branch office VPN to a static gateway peer.
What is BlueMoon? A chained set of zero-day vulnerabilities dubbed BlueMoon is being used to run code through Chrome and then escalate to full system privileges on Microsoft Windows, turning a web visit into potential device takeover. The chain includes two Chromium JavaScript-engine RCE bugs (CVE-2026-85046, CVE-2026-87491) and a Windows privilege-escalation zero-day in Advanced Local Procedure Call (CVE-2026-85880), allowing attackers to execute code, escape the browser sandbox, and gain elevated control.
What is TA412? TA412, a China-linked espionage group, was first seen abusing a new “BlueMoon” zero-day chain that turns a routine web browsing session into full system-level access. They used remote-code execution flaws in Chromium’s JavaScript engine (CVE-2026-85046 and CVE-2026-87491) alongside a Windows privilege-escalation zero-day (CVE-2026-85880) to break out of the browser sandbox and gain elevated privileges.
What is ShinyHunters? ShinyHunters, a financially motivated data extortion group, has been linked to a major breach at healthcare provider AdaptHealth that the company says exposed data tied to 4.1 million individuals. They gained access via a social engineering attack that compromised a third-party contractor’s privileged account, then exfiltrated information from cloud-based business applications used for patient management and health record portals.
What is The Gentlemen? The Gentlemen, a ransomware group known for double-extortion pressure tactics, has claimed responsibility for a breach affecting healthcare technology firm Veradigm tied to a cybersecurity incident at a third-party vendor. They say they stole patient data including names, home addresses, Social Security numbers, emails, phone numbers, and guarantor-related information.