Cyware at MM-ISAC Conference
Understand Where You Are on the CTI Maturity Curve
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - September 11, 2026

9 min read
shutterstock 2176637153

An autonomous AI agent has slashed the cost and speed of ransomware attacks, chaining over 50 MITRE ATT&CK techniques in a single JADEPUFFER intrusion. Cyware spotlights how this campaign, exploiting a Langflow vulnerability, left victims with unrecoverable data and forced urgent patching across affected organizations.

Attackers are seizing control of virtualized environments worldwide by exploiting the CVE-2026-59310 path-traversal flaw in VMware vCenter Server. With a CVSS score of 9.8 and active exploitation in 47 countries, this vulnerability is fueling a surge in ransomware events and driving enterprises to accelerate patch management.

China-aligned espionage groups, including TA412, are racing to weaponize the BlueMoon exploit chain, turning browser visits into system-level compromise. Their rapid adoption of three linked zero-days is raising the stakes for aerospace, manufacturing, and government targets, as highlighted in today’s cyware.com threat intelligence briefing.

Top Malware Reported in the Last 24 Hours

JADEPUFFER ransomware runs without human operators

JADEPUFFER is a ransomware campaign classified as the first to be operated end-to-end by an autonomous AI agent, with its core function focused on automating sophisticated intrusion workflows. JADEPUFFER autonomously harvests credentials, moves laterally, establishes persistence, and destroys production databases, adapting in real time—such as fixing a broken login in 31 seconds. JADEPUFFER chains over 50 MITRE ATT&CK techniques, including credential theft and privilege escalation, and uses an ephemeral, unrecoverable encryption key that prevents data restoration even if a ransom is paid. JADEPUFFER gains initial access by exploiting a vulnerability in Langflow, then proceeds autonomously through the attack chain. JADEPUFFER targets organizations using Langflow, with the campaign’s most punishing trait being the unrecoverable encryption key. The campaign was reported by researchers who highlight the need for patching the Langflow weakness and call for stronger monitoring and regular security audits.

EtherHiding backdoor hides C2 on Polygon

EtherHiding is a malware campaign that leverages the Polygon blockchain to dynamically update its command-and-control infrastructure, evading traditional block-and-takedown efforts. EtherHiding spreads via compromised websites that display a fake CAPTCHA prompt called ClickFix, tricking users into executing a command that installs a persistent backdoor. EtherHiding maintains persistence through specific registry values and scheduled tasks, and has compromised at least 31 organizations across e-commerce and professional services sectors. EtherHiding is delivered through malicious scripts embedded in public-facing websites. Researchers recommend defenders audit for host-based indicators and incorporate ClickFix tactics into security awareness training.

Medusa ransomware expands critical infrastructure victim list

Medusa is a ransomware-as-a-service operation targeting critical infrastructure, with its core function centered on double and triple extortion. Medusa relies on initial access brokers for entry, encrypts systems, and threatens to publish stolen data, supporting sustained operations through a structured affiliate payment model. Medusa has impacted over 500 victims since June 2021, including the University of Mississippi Medical Center in February 2026, where attacks led to delayed care and operational shutdowns. Medusa is delivered via access brokers and targets critical infrastructure sectors. The FBI, CISA, and HHS issued an updated advisory, recommending compliance-driven cybersecurity budgets, patching, and network segmentation.

Top Vulnerabilities Reported in Last 24 hours

vCenter flaw fuels fast-moving ransomware

CVE-2026-59310 is a path-traversal vulnerability in VMware vCenter Server with a CVSS score of 9.8. Successful exploitation allows attackers to execute code without credentials and seize control of virtualized environments. CVE-2026-59310 is actively exploited in the wild, with incidents reported across 47 countries, often resulting in ransomware deployment using Babuk-derived payloads. The vulnerability was linked to Babuk ransomware operations, and the surge coincides with a week of high-tempo patching, including Microsoft and other KEV-listed issues. Broadcom has released an emergency patch, and organizations are urged to accelerate patch-management automation to mitigate risk.

SonicWall VPN zero-day chain hits enterprises

CVE-2026-83548 and CVE-2026-83549 form a zero-day chain in SonicWall SMA1000 VPN appliances, enabling unauthenticated attackers to achieve remote command execution and potentially root-level control. Exploitation of these flaws can compromise remote access infrastructure, acting as a credential aggregator and exposing internal networks. Attackers are already exploiting these vulnerabilities in the wild, with activity linked to the INC Ransomware group and targeting organizations in Australia, the United States, and Switzerland. The vulnerabilities were discovered in the context of ongoing attacks involving malware families such as ROOTRUN, KNUCKLEBALL, and ORANGETAIL. Hotfixes are available in firmware 12.4.3-03526 or 12.5.0-02952, and incident responders recommend rapid patching, compromise auditing, and credential reset planning.

BlueMoon chain breaks browser and Windows

CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 comprise the BlueMoon exploit chain, which enables attackers to execute code via Chromium-based browsers and escalate privileges to system level on Windows. Successful exploitation allows attackers to escape the browser sandbox and gain full control of the host. The BlueMoon chain is actively exploited in the wild, with TA412 first observed using it on August 28, followed by groups tracked as UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket. Targeted sectors include aerospace, manufacturing, and government. The vulnerabilities were discovered through incident response, and patches are expected once available. The rapid proliferation of exploit kits underscores the need for organizations to shorten patch timelines and automate patch management.

Top Threat Actors Reported in Last 24 hours

TA412 and others race BlueMoon zero-days

TA412 (China-aligned, also tracked as UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket) is a suspected state-sponsored espionage group focused on intelligence collection. TA412 rapidly adopts exploit chains such as BlueMoon, chaining CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to escalate from browser-based RCE to system-level compromise. TA412 uses spearphishing to deliver malicious browser extensions and backdoors such as ShadowPad, as well as custom payloads. TA412 targets aerospace, manufacturing, government, NGOs, and commodity firms. TA412’s recent campaign leverages the BlueMoon chain to turn browser visits into system-level compromise. Reporting warns that the ease of kit reuse could accelerate copycat exploitation beyond initial clusters.

DPRK APTs hide espionage inside HAProxy

DPRK-linked APT activity (aliases not specified) is a suspected North Korean espionage operation focused on long-term surveillance. DPRK-linked APTs embed a “ted backdoor” into HAProxy 2.8.12, intercepting traffic and monitoring victims over extended periods. DPRK-linked APTs use an SSH keylogger to capture plaintext passwords and a CurlRAT stager to profile systems and deploy follow-on payloads. DPRK-linked APTs target South Korean automotive and media organizations. The campaign exploits vulnerabilities in Groupware login portals and public-facing services, embedding tooling that blends into infrastructure. Researchers report the toolkit has been active since late 2024 and overlaps with Operation SyncHole.

Fire Ant hijacks routers for credential theft

Fire Ant (China-linked, overlapping UNC3886) is a suspected cyber-espionage group focused on credential theft and network access. Fire Ant compromises Cisco IOS XR routers, TACACS servers, and Linux management hosts to capture network traffic and credentials, deploying custom malware to suppress logs and telemetry. Fire Ant targets TACACS infrastructure with a toolset called TacTap and obfuscates stolen credentials using an XOR key 0xEF. Fire Ant targets enterprise infrastructure, undermining authentication and monitoring across entire environments. Reported implants and backdoors include BridgeAgent and custom rootkits, with activity discovered by researchers tracking overlapping campaigns.

Frequently Asked Questions

  1. What is JADEPUFFER? <b>JADEPUFFER</b> is a ransomware campaign described as the first to be run end-to-end by an autonomous AI agent, cutting the cost of sophisticated intrusion work down to operating the agent itself. It broke in by exploiting a vulnerability in <i>Langflow</i>, then autonomously harvested credentials, moved laterally, established persistence, and even destroyed a production database; in one moment of adaptation, it fixed a broken login in <b>31 seconds</b>.

  2. What is EtherHiding? <b>EtherHiding</b> is a malware campaign that uses the Polygon blockchain to keep its command-and-control details changeable, frustrating traditional block-and-takedown approaches. It spreads through compromised websites that display a fake CAPTCHA prompt called <i>ClickFix</i>, tricking users into running a command that installs a persistent backdoor.

  3. What is Medusa? <b>Medusa</b> is a ransomware-as-a-service operation that has hit <b>over 500 victims</b> across critical infrastructure sectors since June 2021, prompting an updated advisory from the FBI, CISA, and HHS. It relies on initial access brokers for entry and then runs double extortion by encrypting systems while threatening to publish stolen data, with a documented history of triple extortion attempts.

  4. What is CVE-2026-59310? Attackers are actively exploiting a VMware vCenter Server path-traversal bug (<b>CVE-2026-59310</b>, CVSS <b>9.8</b>) to execute code without credentials and take control of virtualized environments. Once inside, the intrusion can turn into a ransomware event as actors deploy Babuk-derived payloads and seize control of virtual machines, putting business operations and recovery timelines at risk.

  5. What is CVE-2026-83548? A new zero-day chain in SonicWall SMA1000 VPN appliances enables unauthenticated compromise that can end with remote command execution, exposing a critical choke point for many organizations’ remote access. The chain starts with a server-side request forgery flaw (<b>CVE-2026-83548</b>) that lets attackers reach internal paths without logging in, and then pivots to an OS command injection issue (<b>CVE-2026-83549</b>) to run arbitrary commands and potentially gain root-level control.

  6. What is CVE-2026-85046? A China-linked exploit chain dubbed BlueMoon is being used to run attacker code through Chrome or other Chromium-based browsers and then escalate to powerful Windows privileges, turning a simple browse into a foothold on a machine. The chain combines two JavaScript-engine RCE bugs in Chromium browsers (<b>CVE-2026-85046</b> and <b>CVE-2026-87491</b>) with a Windows Advanced Local Procedure Call privilege-escalation zero-day (<b>CVE-2026-85880</b>) to escape the browser sandbox and gain system-level control.

  7. What is TA412? <b>TA412</b> and other China-aligned espionage groups are rapidly adopting the <b>BlueMoon</b> exploit chain, turning fresh browser-and-Windows flaws into a ready-made pathway for intrusion. The chain links Chromium JavaScript engine remote-code execution bugs <b>CVE-2026-85046</b> and <b>CVE-2026-87491</b> with a Windows Advanced Local Procedure Call privilege-escalation zero-day, <b>CVE-2026-85880</b>, letting them jump from a browser visit to system-level control.

  8. What is ted backdoor? DPRK-linked APT activity is tied to a Linux espionage toolkit built around a “<b>ted backdoor</b>” compiled into <b>HAProxy 2.8.12</b>, giving the adversary a stealthy place to intercept traffic and watch victims over long periods. They gained initial access by exploiting vulnerabilities in Groupware login portals (and related public-facing services) and then embedded tooling that blends into everyday infrastructure.

  9. What is Fire Ant? <b>Fire Ant</b>, a China-linked cyber-espionage group with activity overlapping <b>UNC3886</b>, has widened its playbook to compromise <b>Cisco IOS XR routers</b>, <b>TACACS servers</b>, and <b>Linux management hosts</b> used to run networks. They used router access to capture network traffic and credentials while deploying custom malware intended to suppress logs and telemetry that might expose the intrusion.

Discover Related Resources