Cyware at MM-ISAC Conference
Understand Where You Are on the CTI Maturity Curve
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - September 25, 2026

11 min read
shutterstock 2285963477

Summary

Ransomware crews are slashing through backup defenses and pushing double-extortion threats, with the n0n group targeting financial services (23% of victims) and leveraging countdown timers to force quick ransom decisions. Cyware spotlights how these tactics are driving operational disruption and immediate data exposure across sectors, as organizations scramble to defend against both encryption and public leaks.

Attackers are turning critical software flaws into rapid compromise vectors, with a WordPress remote code execution bug (CVE-2026-87902) and a Roundcube SQL injection (CVE-2026-48842) both under active exploitation. Over 523,000 Roundcube instances are exposed online, and defenders are racing to patch as exploits emerge within hours of disclosure.

Crypto exchanges are reeling after North Korea-linked hackers pulled off a $351.6 million theft from Bitget’s hot and warm wallets, using spoofed transaction data to bypass controls. Meanwhile, ransomware groups like Qilin and affiliates such as Storm-2570 are escalating extortion campaigns, breaching government systems and leveraging stolen credentials to maximize pressure and impact.

Top Malware Reported in the Last 24 Hours

n0n ransomware threatens to destroy backups

n0n is a ransomware operation pushing victims with a double-extortion playbook that includes threats to destroy backups if a ransom is not paid. After getting in with compromised credentials sourced from third-party infostealer malware, it escalates privileges and stages stolen data to increase pressure during negotiations. The group also uses countdown timers to rush decisions, and when some targets refuse to pay, it publishes the stolen data. According to reporting cited by Infosecurity Magazine, its victim mix spans multiple industries, with financial services accounting for 23% and technology, retail, and education each at 15%. For businesses hit by it, the outcome can be twofold: operational disruption from encryption and immediate exposure of sensitive files that were expected to remain private. Enforcing multi-factor authentication, restricting exposure of internet-facing services, and monitoring for unauthorized access are among the recommended steps described in the report.

TeamCity RCE flaw draws ransomware

A critical JetBrains TeamCity remote code execution vulnerability (severity 9.8) is being exploited by ransomware to break into exposed servers and take control of systems. Once attackers gain that foothold, they can deploy ransomware, encrypt data, and trigger costly downtime for teams that rely on TeamCity for software delivery. The reporting describes the impact as unauthorized access that can spiral into data breaches and business disruption when systems are locked and services stop. Ransomware groups are already using it in active exploitation, turning an exposed build environment into a rapid path to a broader compromise. A patch is available, and applying the latest TeamCity updates and implementing network segmentation are the main actions highlighted to reduce risk.

Psychedelic Stealer spreads via hacked sites

Psychedelic Stealer is an infostealer being distributed through compromised Ukrainian websites that push visitors toward fake Cloudflare verification pages and malware-laced downloads. It harvests browser credentials, account tokens, and cryptocurrency wallet data, leaving victims exposed to account takeover and direct financial theft. The campaign uses a lure management panel called Rublevka TDS that recorded 557 views, 426 clicks, and 79 complete events across 32 countries, with targeting concentrated on Ukraine but also affecting the U.S., Poland, Germany, Canada, and the Netherlands. Researchers describe a modular ecosystem around it, including components named RemotePanel and BoundSiphon, and they assess the operation as suggesting a potential Russian-speaking origin. Blocking the identified malicious domains, scanning systems for the referenced MSI payloads, and using endpoint protection to detect and block malicious scripts and executables are the recommended actions described in the coverage.

Top Vulnerabilities Reported in Last 24 hours

WordPress bug turns patches into playbooks

A critical WordPress remote code execution flaw, CVE-2026-87902, is being used to run attacker-controlled PHP code on vulnerable sites—opening the door to data theft and full site takeover. The issue affects WordPress versions 4.7.0 to 7.1.1, and attackers have been using pearcmd.php to write malicious PHP files onto servers. Attackers are already exploiting this in the wild, with activity reported within hours of the patch release. CSO Online highlighted how quickly attackers can turn fresh fixes into practical exploit guides, shrinking the window for defenders. A fix is available in version 7.1.2 or later.

Roundcube webmail flaw hit in wild

A critical Roundcube Webmail vulnerability, CVE-2026-48842, lets attackers bypass authentication and run unauthorized database queries that can expose sensitive email-related data. The weakness is a pre-auth SQL injection in the virtuser_query plugin, meaning an internet-facing server can be hit without user interaction or prior access. Attackers are already exploiting this in the wild, according to an updated advisory from the Canadian Centre for Cyber Security. Researchers also warn the product has a history of being targeted by groups such as Winter Vivern and APT28, keeping attention high when new Roundcube bugs surface. Shadowserver reports more than 523,000 Roundcube instances exposed online. Fixes are available in versions 1.6.16 and 1.7.1.

CISA flags exploited WSO2, Magento bugs

U.S. CISA has added two flaws to its Known Exploited Vulnerabilities list: CVE-2026-5430 impacting WSO2 products and CVE-2026-71362 affecting Adobe Commerce and Magento—an escalation that signals confirmed attacker interest. In WSO2, attackers use a path traversal weakness to reach sensitive resources across products including WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway. For Adobe Commerce and Magento, the issue is incorrect authorization that can allow unauthorized access to protected functions or data. Attackers are already exploiting these in the wild; watchTowr reported exploitation attempts against CVE-2026-5430 on September 13, 2026, and Sansec observed and blocked attempts tied to CVE-2026-71362 in August 2026, while noting a single Australian IP attempting exploitation on September 10, 2026. Patches are available for both issues.

Top Threat Actors Reported in Last 24 hours

North Korea-linked hackers hit Bitget wallets

North Korean hackers, a state-linked cluster blamed for financially motivated crypto thefts, are being attributed to a $351.6 million raid on Bitget’s hot and warm wallets that relied on spoofed transaction data to push transfers through. They allegedly compromised a critical backend system inside the exchange’s wallet infrastructure, though Bitget says the specific intrusion method is still under investigation. The theft spans multiple assets including ETH, XRP, BNB, AVAX, USDT, and USDC, while the company says its cold wallets and most platform assets remained secure. For customers, the immediate fallout is disrupted access—withdrawals have been temporarily suspended—alongside the risk that trust in exchange controls can be shaken even when cold storage is intact. Bitget says it is cooperating with global institutions as the probe continues, with Mandiant and SlowMist assisting, and it has pointed to monitoring for unauthorized transfers and tightening backend controls as part of the response.

Qilin ransomware breach hits ATF system

Qilin, a ransomware-as-a-service group, has been linked to a breach of a standalone Bureau of Alcohol, Tobacco, Firearms and Explosives system that the Department of Justice classified as a “major incident,” exposing sensitive information about people under federal investigation. They posted the claim on their leak site before ATF publicly acknowledged the incident, while the agency has not formally attributed the intrusion to them and says the investigation is ongoing. The affected system was isolated from ATF’s main network, limiting broader operational disruption, but the data involved raises real-world risks such as retaliation against informants and insight into law-enforcement methods. The episode also spotlights a persistent government weak point: standalone and legacy systems can receive less routine patching and monitoring, making them easier to compromise quietly. In July 2026, the group was reported as the second-most active ransomware gang with 127 attacks, as calls grow for federal agencies to secure standalone environments, modernize legacy systems, and strengthen monitoring and patching routines.

Storm-2570 and n0n escalate extortion

Storm-2570, a ransomware affiliate tracked across ecosystems including Qilin, DragonForce, Anubis, and BERT, is being described by Microsoft as repeating the same playbook across deployments—using remote access, credential theft, lateral movement, security tampering, and data exfiltration to set up ransomware runs. After getting in, they have been observed leaning on remote management tooling for persistence, using tunneling utilities, and turning common credential and discovery tools into a fast lane to broader control, while also tampering with defenses by changing Microsoft Defender settings to reduce visibility. In parallel, the emerging n0n ransomware group is pressuring victims with double extortion that includes threats to destroy backups and psychological tactics like countdown timers, with reported victim distribution led by financial services at 23% and technology, retail, and education at 15% each. For organizations and the people they serve, these campaigns translate into operational disruption plus the fear of data exposure—especially when stolen credentials from infostealer malware are used to open the door. Microsoft’s advisory highlights tenant-wide tamper protection and broader ransomware hardening guidance, while coverage of n0n emphasizes treating them as an active extortion risk and focusing on credential hygiene, access monitoring, and isolating backups to reduce leverage.

Frequently Asked Questions

  1. What is n0n? <b>n0n</b> is a ransomware operation pushing victims with a double-extortion playbook that includes threats to <i>destroy backups</i> if a ransom is not paid. After getting in with compromised credentials sourced from third-party infostealer malware, it escalates privileges and stages stolen data to increase pressure during negotiations.

  2. What is JetBrains TeamCity? A critical <b>JetBrains TeamCity</b> remote code execution vulnerability (severity <b>9.8</b>) is being exploited by ransomware to break into exposed servers and take control of systems. Once attackers gain that foothold, they can deploy ransomware, encrypt data, and trigger costly downtime for teams that rely on TeamCity for software delivery.

  3. What is Psychedelic Stealer? <b>Psychedelic Stealer</b> is an infostealer being distributed through compromised Ukrainian websites that push visitors toward fake Cloudflare verification pages and malware-laced downloads. It harvests browser credentials, account tokens, and cryptocurrency wallet data, leaving victims exposed to account takeover and direct financial theft.

  4. What is CVE-2026-87902? A critical WordPress remote code execution flaw, <b>CVE-2026-87902</b>, is being used to run attacker-controlled PHP code on vulnerable sites—opening the door to data theft and full site takeover. The issue affects WordPress versions <b>4.7.0 to 7.1.1</b>, and attackers have been using <i>pearcmd.php</i> to write malicious PHP files onto servers.

  5. What is CVE-2026-48842? A critical Roundcube Webmail vulnerability, <b>CVE-2026-48842</b>, lets attackers bypass authentication and run unauthorized database queries that can expose sensitive email-related data. The weakness is a pre-auth <b>SQL injection</b> in the <i>virtuser_query</i> plugin, meaning an internet-facing server can be hit without user interaction or prior access.

  6. What is CVE-2026-5430? U.S. CISA has added two flaws to its Known Exploited Vulnerabilities list: <b>CVE-2026-5430</b> impacting WSO2 products and <b>CVE-2026-71362</b> affecting Adobe Commerce and Magento—an escalation that signals confirmed attacker interest. In WSO2, attackers use a <b>path traversal</b> weakness to reach sensitive resources across products including <b>WSO2 API Control Plane</b>, <b>API Manager</b>, <b>Traffic Manager</b>, and <b>Universal Gateway</b>.

  7. What is North Korean hackers? <b>North Korean hackers</b>, a state-linked cluster blamed for financially motivated crypto thefts, are being attributed to a <b>$351.6 million</b> raid on Bitget’s hot and warm wallets that relied on spoofed transaction data to push transfers through. They allegedly compromised a critical backend system inside the exchange’s wallet infrastructure, though Bitget says the specific intrusion method is still under investigation.

  8. What is Qilin? <b>Qilin</b>, a ransomware-as-a-service group, has been linked to a breach of a standalone Bureau of Alcohol, Tobacco, Firearms and Explosives system that the Department of Justice classified as a “major incident,” exposing sensitive information about people under federal investigation. They posted the claim on their leak site before ATF publicly acknowledged the incident, while the agency has not formally attributed the intrusion to them and says the investigation is ongoing.

  9. What is Storm-2570? <b>Storm-2570</b>, a ransomware affiliate tracked across ecosystems including Qilin, DragonForce, Anubis, and BERT, is being described by Microsoft as repeating the same playbook across deployments—using remote access, credential theft, lateral movement, security tampering, and data exfiltration to set up ransomware runs. After getting in, they have been observed leaning on remote management tooling for persistence, using tunneling utilities, and turning common credential and discovery tools into a fast lane to broader control, while also tampering with defenses by changing Microsoft Defender settings to reduce visibility.

Discover Related Resources