Cyware at MM-ISAC Conference
Understand Where You Are on the CTI Maturity Curve
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - September 16, 2026

9 min read
shutterstock 1453727786

AI-driven ransomware is slashing the time it takes to breach enterprise networks, with one attack clocking in at under 10 hours and leaving behind an 80-page audit report as both a technical artifact and an extortion tactic. Cyware highlights how attackers now use over 50 MITRE ATT&CK techniques at machine speed, forcing defenders to rethink traditional, human-paced security strategies.

A single email can now hand over root access on Cisco Secure Email Gateways, as attackers actively exploit CVE-2026-76461. With federal agencies facing a remediation deadline of September 17, 2026, and no workarounds available, the race is on to patch before attackers can manipulate logs and pivot deeper into networks.

Iranian state actors are turning WhatsApp and Telegram into hunting grounds, using CHOSEN BRICK spyware to surveil dissidents and journalists worldwide. By disguising malware as legitimate apps and assigning each victim a unique Telegram bot ID, these campaigns threaten both digital privacy and real-world safety, according to warnings from UK, US, and Dutch authorities on cyware.com.

Top Malware Reported in the Last 24 Hours

AI-driven ransomware

AI-driven ransomware is a new class of ransomware leveraging autonomous AI agents to breach enterprise networks and deploy extortionware. AI-driven ransomware executes reconnaissance, credential theft, lateral movement, and ransomware deployment using over 50 MITRE ATT&CK techniques with minimal human involvement. AI-driven ransomware leaves behind an 80-page audit report listing vulnerabilities and misconfigurations, serving as both a technical artifact and an extortion pressure tactic. AI-driven ransomware gains initial access and spreads through cloud infrastructure, identity systems, CI/CD pipelines, and SaaS platforms at machine speed. AI-driven ransomware targets enterprise environments, dramatically shortening the window for defenders to detect and respond. Palo Alto Networks Unit 42 investigated the incident and described it as a shift from AI-assisted to AI-autonomous operations.

Atomic macOS (AMOS)

Atomic macOS (AMOS) is a macOS stealer designed to siphon login credentials and system information from victims. Atomic macOS (AMOS) tricks users into self-infection through malicious ads, cracked-software offers, and ClickFix-style instructions that prompt users to copy and paste commands into Terminal. Atomic macOS (AMOS) pulls additional payloads and begins staged data theft after initial execution, requesting user passwords and broad permissions. Atomic macOS (AMOS) spreads via websites offering fake “macOS toolkits” and uses Z-shell scripts to fetch further components. Atomic macOS (AMOS) targets both individuals and businesses running macOS, with a single install potentially leading to account takeover and downstream fraud. Palo Alto Networks Unit 42 observed frequent infrastructure and indicator changes complicating detection.

BambooToken, PeckBirdy, and Noodle RAT

BambooToken, PeckBirdy, and Noodle RAT are cross-platform backdoors engineered for persistent access and espionage across Windows and Linux environments. BambooToken uses MQTT-based command-and-control and arrives via side-loading through digitally signed USB-token software or by impersonating productivity tools. PeckBirdy, linked to China-aligned actors, hides its C2 behind low-quality Chinese-language casino and adult sites, using web-delivered scripts and living-off-the-land binaries to support remote JavaScript execution and modular backdoor delivery tied to MKDOOR and HOLODONUT. Noodle RAT, active since at least mid-2016, maintains covert access across endpoints and servers, using Windows for internal reconnaissance and lateral movement and Linux to reach exposed infrastructure and cloud-hosted applications. BambooToken, PeckBirdy, and Noodle RAT target legal, financial, and cryptocurrency sectors, as well as internet-facing business infrastructure. The campaigns were documented by multiple sources, with recommendations to monitor MQTT traffic, audit digital signatures, and treat suspicious casino/adult-site traffic as an intelligence signal.

Top Vulnerabilities Reported in Last 24 hours

CVE-2026-76461 – Cisco Secure Email Gateway zero-day

CVE-2026-76461 is a critical remote command execution vulnerability in Cisco Secure Email Gateway, allowing attackers to gain root privileges by sending specially crafted emails. CVE-2026-76461 enables attackers to turn a perimeter email appliance into an entry point for data theft, system manipulation, or broader network compromise. CVE-2026-76461 is being actively exploited in the wild, with US CISA adding it to the Known Exploited Vulnerabilities catalog and setting a remediation deadline of September 17, 2026. Cisco has warned that attackers may alter on-device logs to hide activity, and detection commands are available for investigation. A fix is available in AsyncOS 15.5.5-0141, 16.0.4-3021, and 16.5.0-780, with no workarounds available.

CVE-2026-5430 – WSO2 API Manager JWT authentication bypass

CVE-2026-5430 is a critical authentication-bypass vulnerability in WSO2 API Manager (CVSS 9.8/10.0) affecting versions 4.1.0 through 4.6.0. CVE-2026-5430 allows attackers to forge JWTs and potentially take over accounts, including administrative ones. CVE-2026-5430 is under active exploitation, with forged tokens capturing administrator privileges as of September 13, 2026. The Hacktron Team discovered the flaw, and researcher Yordan Ganchev highlighted that tokens signed with unsupported algorithms could be accepted. Fixes are available from WSO2, and the vulnerability affects API Control Plane, Traffic Manager, and Universal Gateway components.

CVE-2026-15315 and CVE-2026-15316 – TP-Link Tapo C200 zero-days

CVE-2026-15315 and CVE-2026-15316 are zero-day vulnerabilities in TP-Link Tapo C200 cameras that could enable unauthorized surveillance and denial of service. CVE-2026-15315 allows attackers on the same network to bypass authentication and obtain an administrative session, while CVE-2026-15316 can crash the camera’s HTTPS service. No active exploitation was reported, but researchers described a third critical flaw under investigation that could lead to full device compromise with root-level code execution. Researcher Dahvid Schloss warned that exposure through port forwarding increases risk. A fix is available in firmware version V5_1.4.6, and the vulnerabilities affect home and small business environments.

Top Threat Actors Reported in Last 24 hours

CHOSEN BRICK (Iranian state actors)

CHOSEN BRICK is spyware deployed by Iranian state cyber actors, suspected to originate from Iran, with the primary motive of surveillance and repression. CHOSEN BRICK uses rapport-building scams on WhatsApp and Telegram, including fake MRI test results, to convince targets to install malware disguised as legitimate apps such as Pictory, RunwayML, or Norton Antivirus. CHOSEN BRICK harvests sensitive personal data and enables ongoing digital surveillance by persisting via the HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Run registry key and using Telegram bots for command and control. CHOSEN BRICK targets dissidents, activists, and journalists worldwide. The campaign involves assigning each victim a unique bot ID for individualized tracking. The UK NCSC published the warning with US and Dutch partners.

NightEagle

NightEagle is an APT group suspected to originate from an unknown region, with a primary motive of espionage and persistent access. NightEagle uses the GhostContainer backdoor to maintain access inside networks, leveraging compromised credentials and VPN access for initial entry. NightEagle employs traffic tunneling tools such as Microsoft dev tunnels and rdp2tcp to sustain connectivity and uses the Impacket toolkit’s atexec utility to create scheduled tasks for network port forwarding. NightEagle targets Russian companies, putting email systems and internal operations at risk. The group’s recent campaign involves maintaining long-lived access and moving laterally through compromised environments. Researchers documented NightEagle’s use of covert tunneling and scheduled task creation.

PeckBirdy (China-aligned)

PeckBirdy is a malware campaign linked to China-aligned threat actors, suspected to originate from China, with a primary motive of persistent access and espionage. PeckBirdy blends command-and-control activity into low-quality Chinese-language casino and adult websites, making malicious traffic appear as routine gambling activity. PeckBirdy supports modular payload delivery and is tied to follow-on backdoors including MKDOOR and HOLODONUT. PeckBirdy targets organizations whose network traffic may include casino or adult site browsing, complicating detection. The campaign’s recent activity includes service-worker-delivered JavaScript and suspicious outbound WebSocket activity. Reporting highlights the challenge of distinguishing PeckBirdy’s C2 from legitimate web browsing.

Frequently Asked Questions

  1. What is AI-driven ransomware? AI-driven ransomware breached an enterprise network in under 10 hours, ripping through cloud infrastructure, identity systems, CI/CD pipelines, and SaaS platforms at a pace normally associated with automated testing, not extortion. The attackers used more than 50 MITRE ATT&CK techniques as AI agents handled reconnaissance, credential theft, lateral movement, and ransomware deployment with minimal human involvement.

  2. What is Atomic macOS (AMOS)? Atomic macOS (AMOS) is a macOS stealer designed to siphon login credentials and system information, and recent activity shows it can lure victims into running the infection themselves. It spreads through malicious ads, cracked-software offers, and ClickFix-style instructions that push users to copy and paste text into Terminal, after which it pulls additional payloads and begins staged data theft.

  3. What is BambooToken? BambooToken, PeckBirdy, and Noodle RAT illustrate how modern operators are blending into everyday enterprise traffic and software ecosystems to keep long-running access on both Windows and Linux. BambooToken uses MQTT-based command-and-control and has been seen arriving via side-loading through digitally signed USB-token software and by impersonating productivity tools, with reported targeting that includes legal and financial services and even a cryptocurrency website in Lithuania.

  4. What is CVE-2026-76461? A critical Cisco Secure Email Gateway zero-day (CVE-2026-76461) is being actively exploited to let remote attackers execute arbitrary commands with root privileges simply by sending specially crafted emails. In practice, that kind of control can turn a perimeter email appliance into an entry point for data theft, system manipulation, or wider network compromise.

  5. What is CVE-2026-5430? A critical authentication-bypass flaw in WSO2 API Manager (CVE-2026-5430, CVSS 9.8/10.0) is under active exploitation, letting attackers forge JWTs and potentially take over accounts — including administrative ones. The issue affects WSO2 API Manager versions 4.1.0 through 4.6.0 as well as related components such as API Control Plane, Traffic Manager, and Universal Gateway, putting sensitive API credentials and secrets at risk.

  6. What is CVE-2026-15315? Two zero-day vulnerabilities in TP-Link Tapo C200 cameras — CVE-2026-15315 and CVE-2026-15316 — could enable unauthorized surveillance and service disruption, raising the risk of live video exposure inside homes and small businesses. One bug allows an attacker on the same network to bypass authentication and obtain an administrative session, while the other can crash the camera’s HTTPS service and cause denial of service.

  7. What is CHOSEN BRICK? CHOSEN BRICK, spyware used by Iranian state cyber actors, is being pushed at dissidents, activists, and journalists worldwide through rapport-building scams on WhatsApp and Telegram, including lures like fake MRI test results. After they convince a target to install what looks like legitimate software (including apps branded as Pictory, RunwayML, or Norton Antivirus), the malware can harvest sensitive personal data and enable ongoing digital surveillance.

  8. What is NightEagle? NightEagle, an APT group, has shifted from targeting parts of Asia to targeting Russian companies, using the GhostContainer backdoor to maintain access inside networks. They get in using compromised credentials and VPN access, then work to keep their presence hidden while moving through environments.

  9. What is PeckBirdy? PeckBirdy, a malware campaign linked to China-aligned threat actors, is blending command-and-control activity into the noise of low-quality Chinese-language casino and adult websites. By routing malware traffic through infrastructure that looks like routine gambling activity, they make it harder for defenders to tell malicious communication from everyday web browsing.

Discover Related Resources