Cyware Daily Threat Intelligence - September 20, 2026

Attackers are slashing through mobile defenses with a zero-click modem exploit that lets them seize control of Google Pixel phones without any user interaction. With CVE-2026-58704 now on CISA’s emergency patch list, federal agencies have just three days to lock down their devices. Cyware tracks how espionage groups are already leveraging this flaw to infiltrate networks across the US and Southeast Asia.
Developers relying on AI coding tools face a new threat as OpenAI Codex sandbox escapes—Heapjack and Overpatch—let attackers run unsandboxed commands on host machines. The flaws stem from shared memory heaps and have forced OpenAI to rush out fixes in builds 26.818.21641 and 0.149.0.
A high-stakes feud between ransomware gangs escalated as ShinyHunters breached and defaced the Clop leak site, exploiting a file upload flaw in Grav CMS. The attackers claim to have stolen source code, plugins, and even private keys for Clop’s onion service, raising the risk of further extortion and confusion over who controls the group’s infrastructure. cyware.com continues to monitor the fallout from this ongoing turf war.
Top Vulnerabilities Reported in Last 24 hours
Codex sandbox escapes let attackers run host commands
Two critical sandbox escape vulnerabilities—Heapjack and Overpatch—impact OpenAI Codex Desktop and the Codex CLI, enabling unsandboxed command execution on a developer’s host machine. Heapjack captures a heap snapshot using v8.getHeapSnapshot() to extract tokens and pivot to arbitrary command execution, while Overpatch leverages the apply_patch tool and a symlink trick to bypass write restrictions and modify .zshrc. No active exploitation was reported. Researchers attribute the root cause to shared memory heaps between trusted and untrusted contexts, a flaw seen in other systems as well. OpenAI released patches in Codex Desktop build 26.818.21641 and Codex CLI 0.149.0 or later to address the issue.
Pixel zero-click modem bug hits federal radar
CVE-2026-58704 is an improper authorization vulnerability in the cellular modem of Google Pixel phones that enables zero-click remote compromise. Successful exploitation allows attackers to execute code and take control of affected devices without user interaction. Attackers are actively exploiting CVE-2026-58704 in the wild. The Register reports espionage groups, some suspected to be linked to China, have leveraged similar flaws to infiltrate US and Southeast Asian networks. CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog, mandating a three-day patch deadline for federal agencies. Two related Chromium-based browser bugs—CVE-2026-85046 and CVE-2026-87491—involving V8 type confusion and out-of-bounds write—also expose Chrome, Edge, and Opera to remote code execution.
DeCENC attack cracks DRM video protections
A newly described attack called DeCENC targets the MPEG-CENC format and enables decryption of protected video without direct access to the key. DeCENC exploits the lack of authentication in the encryption scheme, allowing attackers to manipulate content handling and extract decrypted video data. No in-the-wild exploitation was reported. The attack leverages standard playback interfaces such as EME and MSE, making it broadly applicable across DRM implementations. The recommended mitigation is to update CENC to support authenticated encryption modes (AEAD) and to engage DRM vendors for more robust implementations.
Top Threat Actors Reported in Last 24 hours
Storm-1167 weaponises vendor email for BEC
Storm-1167 is a suspected threat actor group linked by Microsoft Defender Experts to business email compromise (BEC) fraud. Storm-1167 initiates multi-stage adversary-in-the-middle phishing by sending emails from compromised vendor accounts, embedding unique seven-digit codes and malicious Canva-hosted links. Storm-1167 employs indirect proxy techniques and session cookie theft to impersonate users, then alters MFA methods (including OneWaySMS) and sets inbox rules to conceal BEC activity. The group targets banking and financial services, threatening payment workflows and sensitive communications even when multi-factor authentication is enabled. The campaign leverages cloud infrastructure hosted on Tencent, with IP addresses traced to Indonesia and the United States, and uses infrastructure control to evade detection. Microsoft Defender Experts attributed the activity and provided technical details.
Storm-3121 abuses device-code login prompts
Storm-3121 (linked with Storm-3032) is a suspected threat actor group focused on credential theft and unauthorized access. Storm-3121 conducts phishing campaigns that impersonate IT staff and abuse device-code authentication prompts, tricking Microsoft 365 users into entering real sign-in codes. Storm-3121 gains access to SharePoint, OneDrive, and Exchange Online, then adds their own authentication methods to maintain persistence. The group targets organizations broadly, exposing internal files and email threads through a single successful social engineering attempt. The campaign demonstrates the risk of device-code authentication and has led some defenders to restrict its use.
ShinyHunters breaches Clop’s leak site
ShinyHunters is a well-known extortion gang suspected to operate globally, with a primary motive of data theft and public extortion. ShinyHunters exploited an unauthenticated file upload flaw in Grav CMS to breach and deface the Clop ransomware group’s leak site, planting a warning message and linking to their own leak site. ShinyHunters claims to have stolen server data, source code, plugins, logs, and private keys for Clop’s onion service, potentially enabling them to operate a Tor site using Clop’s address. The incident adds confusion over extortion infrastructure control and data redistribution. The feud traces back to Clop’s 2025 Oracle E-Business Suite data theft campaign, when ShinyHunters disrupted Clop’s activities, as confirmed by BleepingComputer.
Frequently Asked Questions
What is Heapjack? Security researchers disclosed two critical OpenAI Codex sandbox escapes—Heapjack and Overpatch—that can lead to unsandboxed command execution on a developer’s host machine via OpenAI Codex Desktop and the Codex CLI. In Heapjack, attackers capture a heap snapshot (using v8.getHeapSnapshot()) to find a token and then pivot to running arbitrary commands; in Overpatch, attackers use the apply_patch tool with a symlink trick to append a line to .zshrc despite write restrictions.
What is CVE-2026-58704? A zero-day in Google Pixel phones’ cellular modems (CVE-2026-58704) enables zero-click attacks that can lead to remote compromise without user interaction. The vulnerability is described as an improper authorization issue in the modem, creating a path for attackers to execute code and take control of impacted devices.
What is DeCENC? A newly described technique dubbed DeCENC targets the MPEG-CENC format and can enable decryption of protected video without directly knowing the key, undercutting the security assumptions behind many DRM systems. The core issue is structural: the scheme relies on encryption without authentication, letting attackers manipulate content handling so decrypted video data can be extracted.
What is Storm-1167? Storm-1167 is a threat actor tied by Microsoft Defender Experts to a multi-stage adversary-in-the-middle (AiTM) phishing operation designed to steal sessions and drive business email compromise (BEC) fraud. They started by sending phishing emails from a compromised trusted vendor account, using a unique seven-digit code and a malicious Canva-hosted link to make the lure feel routine and credible.
What is Storm-3121? Storm-3121 (linked in reporting alongside Storm-3032) is associated with phishing campaigns that trick Microsoft 365 users into approving access by abusing passkey and MFA “update” requests. Instead of cracking passkeys, they impersonate IT staff and guide targets through device-code phishing, where the victim enters a real Microsoft sign-in code that effectively authorizes the attacker’s session.
What is ShinyHunters? ShinyHunters, a well-known extortion gang, has turned the tables on a rival by breaching the Clop ransomware group’s data leak site and publicly defacing it. They claim they exploited an unauthenticated file upload flaw in Grav CMS to plant a warning message and link back to their own leak site, and BleepingComputer confirmed the defacement and presence of the uploaded file.