Cyware at MM-ISAC Conference
Understand Where You Are on the CTI Maturity Curve
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - September 21, 2026

9 min read
shutterstock 2290138299

Attackers are turning trusted enterprise infrastructure against defenders, as seen in a recent campaign where domain-wide Active Directory Group Policy Objects were weaponized to disable administrator accounts and push ransom notes across entire organizations. The PAYLOAD attack, reported by Kaspersky Securelist, began with compromised VPN credentials and led to data exfiltration before the full impact was realized. Cyware.com highlights how this approach bypasses traditional ransomware binaries, forcing defenders to rethink detection and response.

A critical authentication flaw in cPanel & WHM has been exploited in the wild, giving attackers unauthenticated access to hosting servers and exposing customer data, mailboxes, and admin credentials. The spike in attacks tied to CVE-2026-41940 was observed across the United States, Germany, France, Canada, and Japan, with Mirai-like scanning on ports including 23, 443, 80, and 3389. Cyware.com urges immediate patching and monitoring as attackers shift focus to high-value infrastructure.

Routine code review has become a supply-chain risk as the Lazarus Group embedded PolinRider malware in two open GitHub pull requests, hiding obfuscated JavaScript in configuration files. The submissions, linked to compromised accounts, threaten to poison downstream builds if merged. Cyware.com spotlights the growing risk of trusted repositories becoming vectors for widespread compromise.

Top Malware Reported in the Last 24 Hours

PAYLOAD ransomware weaponizes Active Directory policies

PAYLOAD is a ransomware-style attack that leverages Active Directory Group Policy Objects (GPOs) to achieve widespread disruption without deploying traditional malware binaries. PAYLOAD uses domain admin-equivalent control to push ransom notes, disable administrator accounts, and deactivate Windows Firewall across all domain-joined systems after endpoints reboot and apply the malicious policies. PAYLOAD initiates its intrusion via compromised credentials on a FortiGate SSL VPN, with data exfiltration occurring between April 13 and April 14 before the attack becomes apparent on April 14. PAYLOAD targets organizations with domain-joined Windows environments, exploiting centralized management infrastructure. Kaspersky Securelist reported the case, emphasizing that attackers can create ransomware-like outcomes even without file encryption.

PolinRider slips into GitHub pull requests

PolinRider is malware attributed to the DPRK-linked Lazarus group, discovered embedded in configuration files within two open GitHub pull requests. PolinRider hides obfuscated JavaScript appended to legitimate config files and executes via eval and spawn, with command-and-control traffic routed through Ethereum JSON-RPC endpoints. PolinRider was identified in PR #7716 and PR #10321, submitted from the accounts shakin-shahria/ui and stefann01/ui, suggesting possible account compromise. PolinRider targets software supply chains by exploiting trusted repositories and code review processes. The report recommends not merging the affected PRs, verifying account integrity, and monitoring for similar obfuscation and execution patterns.

GraphWorm and EtherHiding hijack trusted infrastructure

GraphWorm is a malware implant linked to the China-nexus APT group Webworm, using Microsoft Graph and OneDrive as command-and-control channels to blend malicious traffic with legitimate cloud activity. GraphWorm polls a OneDrive account for encrypted tasking, executes shell commands and file transfers, and can upgrade itself by replacing OAuth credentials after token revocation. EtherHiding is a campaign that hides its command-and-control on the Polygon blockchain, deploying 15 smart contracts across six waves since November 2025 and using FakeCaptcha/ClickFix-style lures to trigger malware downloads via scheduled tasks. GraphWorm and EtherHiding target organizations relying on cloud APIs and public blockchains, making detection and disruption more challenging. The report recommends focusing GraphWorm detection on endpoint and cloud telemetry, and for EtherHiding, monitoring for unexpected Polygon RPC traffic and investigating scheduled task creation.

Top Vulnerabilities Reported in Last 24 hours

CVE-2026-41940: Authentication flaw in cPanel & WHM (CVSS critical)

CVE-2026-41940 is a critical authentication vulnerability in cPanel & WHM with a high CVSS score, affecting session-management and Basic Authentication handling. CVE-2026-41940 enables unauthenticated attackers to access hosted websites, databases, mailboxes, backup archives, customer credentials, and admin accounts. CVE-2026-41940 is actively exploited in the wild, with attacks beginning on April 30, 2026, shortly after public disclosure and patch release. Monitoring linked the spike to Mirai-like scanning across TCP/23, HTTPS/443, HTTP/80, 8080, SSH/22, RDP/3389, and management ports 8443 and 8728. The patch is available, and affected systems are widespread, with significant activity in the United States, Germany, France, Canada, and Japan.

Gyazo breach exposes millions of users

A vulnerability in Gyazo’s image upload server allowed attackers to run arbitrary commands and steal 23.62 million user records and metadata tied to approximately 490 million images. The breach exposes user IDs, device IDs, login session IDs, X integration tokens, Google SSO email addresses, profile details, language preferences, registration and login timestamps, subscription plans, and billing status, though no payment information was disclosed. Attackers are actively exploiting this vulnerability, with the intrusion detected on September 11 and access routes blocked by September 12. The incident also affected Helpfeel’s broader ecosystem, with some images embedded in Helpfeel tools via Gyazo still unavailable and Gyazo’s homepage displaying a maintenance notice. Gyazo is investigating whether private images were viewed, raising concerns about potential user content exposure.

Exim mail servers face smuggling risks

Four critical vulnerabilities—GCVE-25-2026-09-50-1, GCVE-25-2026-09-51-1, GCVE-25-2026-09-55-1, and GCVE-25-2026-09-56-1—affect the Exim mail server, enabling SMTP smuggling and heap-memory corruption that may result in message injection or server crashes. The most severe issue is an out-of-bounds write in Exim’s handling of Proxy Protocol v1 data, impacting versions 4.83 through 4.100, while SMTP smuggling affects 4.98 through 4.100. Exploitation requires Proxy Protocol to be enabled and depends on a buggy or compromised upstream proxy, limiting risk to specific mail environments. No active exploitation has been reported. A fix is available in Exim 4.100.1, and administrators should update immediately to mitigate exposure.

Top Threat Actors Reported in Last 24 hours

Lazarus Group (also tracked as Hidden Cobra): PolinRider supply-chain compromise

Lazarus Group (also tracked as Hidden Cobra) is a suspected DPRK-origin threat actor focused on financial gain and espionage. Lazarus Group recently embedded PolinRider malware in GitHub pull requests, using obfuscated JavaScript payloads and Ethereum JSON-RPC endpoints for command-and-control. Lazarus Group leverages compromised developer accounts to submit malicious code changes, exploiting trust in open-source repositories. Lazarus Group targets software supply chains and developer ecosystems. The campaign involved PR #7716 and PR #10321, submitted from shakin-shahria/ui and stefann01/ui, with evidence of account compromise. The risk is that a single merged change could cascade into poisoned builds or malicious packages reaching many machines.

Webworm (China-nexus APT): GraphWorm cloud persistence

Webworm is a suspected China-nexus APT group with a primary motive of espionage. Webworm employs GraphWorm to use Microsoft Graph and OneDrive as command-and-control, blending malicious activity with normal cloud usage. Webworm uses a OneDrive account as a dead drop, polling for encrypted task files, executing commands, and uploading results over TLS to Microsoft endpoints. Webworm can swap OAuth credentials to maintain persistence even after defenders revoke tokens. Webworm targets organizations relying on Microsoft 365 and cloud infrastructure. The campaign stretches out investigations and recovery timelines, as intruders operate under the cover of legitimate cloud activity.

Remus infostealer raids AI and cloud tokens

Remus is a Windows infostealer suspected to originate from financially motivated actors, targeting API tokens and credentials from AI platforms such as OpenAI and Anthropic. Remus uses ClickFix-to-SmokeLoader delivery chains, leveraging fake CAPTCHA-style prompts delivered via phishing, malvertising, or compromised sites to trick victims into executing malicious commands. Remus employs evasion and staged theft techniques and can target 2FA-related browser extensions, increasing the risk of account takeover even with multi-factor authentication enabled. Remus targets software development teams and cloud administrators managing AI services. Stolen tokens can result in unauthorized access, unexpected usage charges, or secondary breaches that are difficult to trace to the original infection.

Frequently Asked Questions

  1. What is PAYLOAD? PAYLOAD is a ransomware-style attack that caused widespread disruption by abusing Active Directory Group Policy Objects (GPOs) instead of deploying typical malware binaries. It used domain admin-equivalent control to push ransom notes, disable the administrator account, and turn off defenses like Windows Firewall across all domain-joined systems after endpoints rebooted and applied the policies.

  2. What is PolinRider? PolinRider is malware attributed to the DPRK-linked Lazarus group that was found embedded in configuration files inside two open GitHub pull requests, turning routine code review into a supply-chain risk. It hid obfuscated JavaScript appended to legitimate config files and executed through eval/spawn, with command-and-control traffic described as using Ethereum JSON-RPC endpoints.

  3. What is GraphWorm? GraphWorm is a malware implant linked to the China-nexus APT group Webworm that uses Microsoft Graph and OneDrive as command-and-control, making its traffic look like normal cloud activity. It polls a OneDrive account for encrypted tasking, runs commands like shell execution and file transfer, and can even “upgrade” itself by replacing OAuth credentials to change identity after token revocation.

  4. What is CVE-2026-41940? Threat actors exploited a critical cPanel & WHM flaw (CVE-2026-41940) to compromise hosting servers, turning them into higher-value footholds than typical IoT bots because of their bandwidth and access to hosted customer data. The issue sits in cPanel’s session-management and Basic Authentication handling, enabling unauthenticated access that can expose hosted websites, databases, mailboxes, backup archives, customer credentials, and admin accounts.

  5. What is Gyazo breach exposes millions of users? Hackers exploited a vulnerability in Gyazo’s image upload server to run arbitrary commands and steal 23.62 million user records plus metadata tied to roughly 490 million images. The exposed data includes user IDs, device IDs, login session IDs, X integration tokens, Google SSO email addresses, profile details, language preferences, registration and login timestamps, subscription plans, and billing status, while Gyazo said no payment information was disclosed.

  6. What is GCVE-25-2026-09-50-1? Four critical vulnerabilities in the Exim mail server—GCVE-25-2026-09-50-1, GCVE-25-2026-09-51-1, GCVE-25-2026-09-55-1, and GCVE-25-2026-09-56-1—can enable SMTP smuggling and heap-memory corruption that may lead to message injection or crashes. The most severe issue is an out-of-bounds write in Exim’s handling of Proxy Protocol v1 data (affecting 4.83 through 4.100), while the SMTP smuggling issues affect 4.98 through 4.100.

  7. What is PolinRider? PolinRider, malware attributed to the DPRK-linked Lazarus Group, was found hiding in two open pull requests—turning routine code review into a potential compromise point for developers who trust popular repositories. They embedded obfuscated JavaScript payloads inside otherwise legitimate-looking configuration files, a change that can be easy to miss in large diffs.

  8. What is Webworm? Webworm, a China-nexus APT group, is tied to GraphWorm, an implant that treats Microsoft Graph and OneDrive as its command-and-control channel so the traffic blends in with everyday cloud activity. They were observed using a OneDrive account as a dead drop, polling for encrypted task files, executing commands, and uploading results over TLS to Microsoft’s own endpoints.

  9. What is Remus? Remus is a Windows infostealer focused on stealing API tokens and credentials from AI platforms such as OpenAI and Anthropic, alongside a broad set of browsers and apps. It has been linked to ClickFix-to-SmokeLoader delivery chains, using fake CAPTCHA-style prompts delivered via phishing, malvertising, or compromised sites to trick victims into running malicious commands.

Discover Related Resources