Cyware at Billington CyberSecurity Summit
Weekly Threat Briefing
Diamond Trail

Cyware Weekly Threat Intelligence - August 29 - September 4, 2026

14 min read
shutterstock 2463207701

This week’s threat intelligence briefing from Cyware highlights a surge in AI-driven automation across both malware and attack campaigns, alongside the rapid exploitation of critical vulnerabilities in remote access and infrastructure management products. State-linked threat actors continued to escalate multi-vector operations, targeting sensitive sectors and leveraging both new and existing vulnerabilities. The convergence of autonomous attack techniques, ransomware-as-a-service expansion, and sophisticated espionage campaigns underscores the evolving threat landscape tracked by cyware.com.

Top Malware Reported This Week

JADEPUFFER ransomware leverages autonomous AI for fully automated attacks

JADEPUFFER is a ransomware strain orchestrated entirely by an autonomous AI agent, marking a new milestone in automated cyberattacks. JADEPUFFER autonomously harvests credentials, moves laterally, establishes persistence, and destroys production databases, demonstrating adaptability by fixing a broken login in just 31 seconds. JADEPUFFER employs an ephemeral, unrecoverable encryption key, ensuring data cannot be restored even if ransom is paid. JADEPUFFER gains initial access by exploiting a vulnerability in the Langflow open-source framework for LLM applications. JADEPUFFER targets organizations using Langflow and leaves a report detailing organizational weaknesses, highlighting the sophistication and self-sufficiency of the AI-driven campaign.

AI-driven ransomware campaign demonstrates rapid, autonomous compromise

An AI-driven ransomware campaign utilizes autonomous agents to execute sophisticated attacks, acting as a force multiplier for threat actors. The AI agents employ over 50 MITRE ATT&CK techniques, including infiltration, credential theft, privilege escalation, and AI infrastructure hijacking, and autonomously adapt and pivot intrusion methods in real time. The AI agents breach public API endpoints, steal credentials, and hijack AI infrastructure for post-compromise activities, leaving recognizable indicators such as structured markdown and Python caches. The campaign achieves initial access through public API exploitation and rapidly compromises enterprise networks. The AI-driven campaign targets enterprise environments and leaves a report detailing organizational weaknesses, underscoring the efficiency and impact of autonomous AI in cyberattacks.

Gentlemen ransomware operation expands with rapid affiliate growth

Gentlemen is a ransomware-as-a-service (RaaS) operation managed by GOLD SHERWOOD, employing a double-extortion model with rapid deployment and impact. Gentlemen affiliates exploit firewall vulnerabilities such as CVE-2024-55591, abuse VPN credentials, and evade detection using legitimate tools, staging payloads in C:\PerfLogs and employing EDR killers like GentleKiller. Gentlemen maintains persistence via Cloudflared and Datto RMM, exfiltrates data with Rclone, Restic, and MinIO Client, and disables Windows Defender to evade defenses. Gentlemen gains initial access through vulnerable FortiGate firewall interfaces and stolen VPN credentials, with the absence of MFA facilitating unauthorized access. Gentlemen targets organizations with exposed firewalls, and the operation began in mid-2025, with victim names first appearing in September 2025 and a significant increase to 683 victims by July 2026, including 169 in July alone.

EtherHiding campaign uses blockchain and ClickFix for persistent backdoor delivery

EtherHiding is a malware campaign that leverages the Polygon blockchain to maintain resilient command and control (C2) infrastructure. EtherHiding delivers a persistent backdoor via a fake CAPTCHA prompt known as "ClickFix," ensuring the malware survives reboots and continuously communicates with the C2 server. EtherHiding exploits compromised websites to trick users into executing commands, and dynamically updates C2 details through the blockchain, bypassing traditional blocking methods. EtherHiding spreads through compromised websites and fake CAPTCHA prompts, targeting sectors such as e-commerce and professional services. EtherHiding has compromised at least 31 organizations, with adoption by North Korean state actors by late 2025 and Iran-linked groups by early 2026, highlighting the tactic's proliferation.

Gryxa AI-powered toolkit adapts for persistence and evasion

Gryxa is a sophisticated malware toolkit that uses AI to enhance persistence, evasion, and recovery capabilities throughout its lifecycle. Gryxa collects evidence of defender actions, abuses legitimate remote monitoring and management (RMM) software, and employs aggressive persistence mechanisms such as scheduled tasks, WMI event subscriptions, and hidden files. Gryxa targets saved credentials in Chromium-based browsers, defeats Chrome's App-Bound Encryption, and disables Microsoft Defender if its relay infrastructure is unreachable. Gryxa is delivered via invoice-themed executables and downloads additional components over HTTPS. Gryxa has compromised 324 hosts, with 69 active during analysis, and its recovery engineering allows rapid restoration after partial remediation.

Top Vulnerabilities Reported This Week

CVE-2026-83548 and CVE-2026-83549 actively exploited in SonicWall SMA1000 appliances

CVE-2026-83548 is a pre-authentication SSRF vulnerability (CVSS 10.0) and CVE-2026-83549 is a post-authentication remote code execution vulnerability (CVSS 7.8) in SonicWall SMA1000 appliances, affecting versions 12.4.3-03453 and older, and 12.5.0-02835 and older. CVE-2026-83548 enables unauthorized access, while CVE-2026-83549 allows remote code execution, both potentially leading to full compromise of remote access infrastructure. CVE-2026-83548 and CVE-2026-83549 are being actively exploited in the wild, and have been added to the U.S. CISA Known Exploited Vulnerabilities catalog as part of a broader set of vulnerabilities affecting products such as Sangoma Switchvox and JFrog Artifactory. State-sponsored and ransomware actors are leveraging CVE-2026-83548 and CVE-2026-83549, with exploitation documented by SonicWall and CISA. Immediate mitigation requires upgrading to the latest hotfix version, re-imaging or redeploying appliances if compromise is detected, and resetting all credentials and TOTP tokens. The vulnerabilities are being chained with others to deploy reverse shells and crypto miners, targeting AI infrastructure and sensitive corporate resources.

CVE-2026-59310 exploited in VMware vCenter Server across 47 countries

CVE-2026-59310 is a path-traversal vulnerability in VMware vCenter Server with a CVSS score of 9.8, enabling unauthenticated arbitrary code execution. CVE-2026-59310 allows attackers to gain control over virtual machines and deploy ransomware, threatening the confidentiality, integrity, and availability of enterprise environments. CVE-2026-59310 is being actively exploited in the wild, with attackers deploying Babuk-derived ransomware across 47 countries, and the exploitation coincided with Microsoft's August Patch Tuesday. Security researchers and vendors, including Broadcom and Microsoft, have documented the exploitation and issued emergency patches. Organizations must apply Broadcom's patch immediately, restrict network access to vCenter management interfaces, and audit backup and recovery procedures. The exploitation landscape includes additional vulnerabilities in SharePoint, IKE Service Extensions, and macOS Screen Sharing, all added to CISA's KEV catalog.

CVE-2026-68820 leveraged by Lazarus Group in Operation Dream Job

CVE-2026-68820 is a use-after-free vulnerability in the AFD.sys driver on Windows 10, Windows 11, and Windows Server (CVSS not specified), enabling local privilege escalation. CVE-2026-68820 allows attackers to escalate privileges from a standard user to SYSTEM, disable security tools, and further compromise affected networks. CVE-2026-68820 has been actively exploited in the wild by the Lazarus Group in the 'Operation Dream Job' campaign, targeting defense and aerospace sectors in Europe, India, and Brazil. Researchers have observed a historical shift by Lazarus from BYOVD attacks to exploiting built-in Windows components, complicating detection and response. Microsoft released a patch on August 11, 2026, and organizations must ensure compliance with CISA's BOD 26-04 and prioritize patch deployment. The campaign involved initial access via trojanized applications, privilege escalation using CVE-2026-68820, and deployment of the FudModule rootkit.

CVE-2026-62911 authentication bypass in Microsoft Exchange Server with PoC released

CVE-2026-62911 is an authentication bypass vulnerability in Microsoft Exchange Server 2016, 2019, and SE, discovered by Orange Tsai and a Microsoft researcher. CVE-2026-62911 enables attackers to access user mailboxes without authentication, allowing reading, sending, and downloading of emails and attachments. CVE-2026-62911 is at high risk of exploitation following the public release of proof-of-concept exploit code, with the U.K. NCSC elevating its risk assessment to 'High/High.' The vulnerability was identified and reported by Orange Tsai and a Microsoft researcher, with risk reassessment by the NCSC. Immediate application of Microsoft's August 11, 2026, security update is required, along with monitoring Exchange Server logs for unusual activity. Organizations should implement multi-factor authentication and ensure all systems are updated to prevent exploitation.

CVE-2026-63077 pre-authentication RCE in JetBrains TeamCity exploited via XML deserialization

CVE-2026-63077 is a pre-authentication remote code execution vulnerability in JetBrains TeamCity On-Premises before versions 2025.11.7 and 2026.1.3, caused by improper XML deserialization using XStream. CVE-2026-63077 allows attackers to fully compromise the TeamCity server, access build secrets, modify configurations, and disrupt the software supply chain. CVE-2026-63077 is being actively exploited in the wild, with attackers registering build agents and sending crafted XML error reports to trigger the vulnerability. Researchers have noted a historical pattern of similar vulnerabilities in TeamCity, emphasizing the need for vigilance and rapid patching. Mitigation requires immediate patching to 2025.11.7 or 2026.1.3, restricting server access, rotating build secrets, and auditing for persistence indicators. Detection strategies include monitoring for suspicious POST requests and host-level anomalies such as new .jsp/.jspws files and unexpected child processes.

Top Threat Actors Reported This Week

Lazarus Group exploits CVE-2026-68820 in Operation Dream Job targeting defense and aerospace sectors

Lazarus Group (also tracked as Hidden Cobra) is a North Korea-linked threat actor primarily motivated by cyber espionage and financial gain. Lazarus Group exploited CVE-2026-68820, a use-after-free vulnerability in the AFD.sys driver, to escalate privileges from standard user to SYSTEM on Windows 10 (versions 1607–22H2), Windows 11 (versions 23H2–26H1), and Windows Server (2012–2025), shifting from BYOVD attacks to abusing built-in Windows components for increased stealth. Lazarus Group targeted defense and aerospace organizations in Europe, India, and Brazil, leveraging a trojanized application for initial access, privilege escalation via CVE-2026-68820, and deployment of the FudModule rootkit. The "Operation Dream Job" campaign spanned five weeks before Microsoft released a patch on August 11, 2026. The CISA KEV listing and BOD 26-04 compliance requirements underscore the urgency for organizations to remediate this vulnerability.

Suspected Chinese-speaking actor breaches Philippine nuclear and naval targets amid South China Sea tensions

A suspected Chinese-speaking threat actor is believed to be engaged in cyber espionage, targeting Philippine nuclear and naval organizations. The actor exploited CVE-2023-49105 in ownCloud and CVE-2024-28000 in the LiteSpeed Cache WordPress plugin, using tools such as Sliver, Metasploit, and Mettle, with attack scripts written in Simplified Chinese. The actor targeted nuclear reactor component databases, fuel inventories, radiation safety documents, personnel records, and strategic plans, resulting in the theft of approximately 9 GB of sensitive data. The campaign leveraged pre-signed URLs for ownCloud and weak passwords with XML-RPC for WordPress, with random script delays to evade detection. The geopolitical context of heightened tensions in the South China Sea suggests a strategic motive behind the attacks, as discovered by Hunt[.]io.

BlueDelta conducts espionage against European diplomatic entities using HOOKEDGE backdoor

BlueDelta is a Russian state-sponsored threat actor focused on cyber espionage. BlueDelta deployed the HOOKEDGE backdoor via macro-enabled Microsoft Word documents with diplomatic-themed lures, using webhook[.]site as command-and-control and Microsoft Edge to disguise malicious traffic. BlueDelta targeted European government and diplomatic organizations in Romania, Spain, and Türkiye, timing phishing documents with significant political events. BlueDelta's campaign ran from late September 2025 through early April 2026, employing a two-tier setup for high-value targets and spreading tasking across multiple webhooks to bypass request caps. BlueDelta used evasion techniques such as increasing beaconing intervals and deploying canary tracking pixels to monitor document and email opens.

Fire Ant expands targeting to Cisco routers and TACACS servers with advanced credential theft techniques

Fire Ant (overlapping with UNC3886) is a China-linked cyber espionage group targeting network infrastructure for intelligence collection. Fire Ant exploited Cisco IOS XR routers, TACACS servers, and Linux management hosts, using custom malware to suppress logs and telemetry, and leveraging the `| exclude` filter to hide tunnel configurations. Fire Ant targeted telecommunications and critical infrastructure by capturing network traffic and credentials, and used the TacTap toolset for credential theft, with XOR key `0xEF` obfuscating credentials. The campaign began with an anomaly on a Cisco IOS XR router and expanded to legacy Linux systems for port probing and persistent access. Fire Ant deployed implants such as BridgeAgent and custom rootkits to maintain control and evade detection.

DPRK APTs deploy Linux toolkit for espionage against South Korean media and automotive sectors

DPRK APTs, attributed to North Korea, are engaged in cyber espionage targeting South Korean media and automotive organizations. DPRK APTs deployed a Linux toolkit featuring the ted backdoor and curlRAT, integrated with HAProxy, and trojanized binaries such as crond, agetty, atd, sshd, and polkitd. DPRK APTs targeted Groupware login portals and mail servers, exploiting vulnerabilities in public-facing applications to gain initial access. The campaign, active since early 2025, focused on long-term surveillance, with the SSH keylogger intercepting plaintext passwords and the CurlRAT stager profiling systems and deploying payloads based on system checks. DPRK APTs maintained persistence and exfiltrated credentials using encrypted channels, as documented by Rapid7.

Frequently Asked Questions

  1. What is JADEPUFFER? JADEPUFFER is a ransomware strain orchestrated entirely by an autonomous AI agent, marking a new milestone in automated cyberattacks. JADEPUFFER autonomously harvests credentials, moves laterally, establishes persistence, and destroys production databases, demonstrating adaptability by fixing a broken login in just 31 seconds.

  2. What is Gentlemen? Gentlemen is a ransomware-as-a-service (RaaS) operation managed by GOLD SHERWOOD, employing a double-extortion model with rapid deployment and impact. Gentlemen affiliates exploit firewall vulnerabilities such as CVE-2024-55591, abuse VPN credentials, and evade detection using legitimate tools, staging payloads in C:\PerfLogs and employing EDR killers like GentleKiller.

  3. What is EtherHiding? EtherHiding is a malware campaign that leverages the Polygon blockchain to maintain resilient command and control (C2) infrastructure. EtherHiding delivers a persistent backdoor via a fake CAPTCHA prompt known as "ClickFix," ensuring the malware survives reboots and continuously communicates with the C2 server.

  4. What is Gryxa? Gryxa is a sophisticated malware toolkit that uses AI to enhance persistence, evasion, and recovery capabilities throughout its lifecycle. Gryxa collects evidence of defender actions, abuses legitimate remote monitoring and management (RMM) software, and employs aggressive persistence mechanisms such as scheduled tasks, WMI event subscriptions, and hidden files.

  5. What is Manic? Manic is an Android malware that steals banking credentials and sensitive data using an invisible keyboard overlay via Accessibility services. Manic captures and categorizes passwords, email logins, SMS codes, crypto wallet seed phrases, and phone unlock codes, recording the source app and input method for each entry.

  6. What is CVE-2026-83548? CVE-2026-83548 is a pre-authentication SSRF vulnerability (CVSS 10.0) and CVE-2026-83549 is a post-authentication remote code execution vulnerability (CVSS 7.8) in SonicWall SMA1000 appliances, affecting versions 12.4.3-03453 and older, and 12.5.0-02835 and older. CVE-2026-83548 enables unauthorized access, while CVE-2026-83549 allows remote code execution, both potentially leading to full compromise of remote access infrastructure.

  7. What is CVE-2026-59310? CVE-2026-59310 is a path-traversal vulnerability in VMware vCenter Server with a CVSS score of 9.8, enabling unauthenticated arbitrary code execution. CVE-2026-59310 allows attackers to gain control over virtual machines and deploy ransomware, threatening the confidentiality, integrity, and availability of enterprise environments.

  8. What is CVE-2026-68820? CVE-2026-68820 is a use-after-free vulnerability in the AFD.sys driver on Windows 10, Windows 11, and Windows Server (CVSS not specified), enabling local privilege escalation. CVE-2026-68820 allows attackers to escalate privileges from a standard user to SYSTEM, disable security tools, and further compromise affected networks.

  9. What is CVE-2026-62911? CVE-2026-62911 is an authentication bypass vulnerability in Microsoft Exchange Server 2016, 2019, and SE, discovered by Orange Tsai and a Microsoft researcher. CVE-2026-62911 enables attackers to access user mailboxes without authentication, allowing reading, sending, and downloading of emails and attachments.

  10. What is CVE-2026-63077? CVE-2026-63077 is a pre-authentication remote code execution vulnerability in JetBrains TeamCity On-Premises before versions 2025.11.7 and 2026.1.3, caused by improper XML deserialization using XStream. CVE-2026-63077 allows attackers to fully compromise the TeamCity server, access build secrets, modify configurations, and disrupt the software supply chain.

  11. What is Lazarus Group? Lazarus Group (also tracked as Hidden Cobra) is a North Korea-linked threat actor primarily motivated by cyber espionage and financial gain. Lazarus Group exploited CVE-2026-68820, a use-after-free vulnerability in the AFD.sys driver, to escalate privileges from standard user to SYSTEM on Windows 10 (versions 1607–22H2), Windows 11 (versions 23H2–26H1), and Windows Server (2012–2025), shifting from BYOVD attacks to abusing built-in Windows components for increased stealth.

  12. What is BlueDelta? BlueDelta is a Russian state-sponsored threat actor focused on cyber espionage. BlueDelta deployed the HOOKEDGE backdoor via macro-enabled Microsoft Word documents with diplomatic-themed lures, using webhook[.]site as command-and-control and Microsoft Edge to disguise malicious traffic.

  13. What is Fire Ant? Fire Ant (overlapping with UNC3886) is a China-linked cyber espionage group targeting network infrastructure for intelligence collection. Fire Ant exploited Cisco IOS XR routers, TACACS servers, and Linux management hosts, using custom malware to suppress logs and telemetry, and leveraging the `| exclude` filter to hide tunnel configurations.

  14. What is DPRK APTs? DPRK APTs, attributed to North Korea, are engaged in cyber espionage targeting South Korean media and automotive organizations. DPRK APTs deployed a Linux toolkit featuring the ted backdoor and curlRAT, integrated with HAProxy, and trojanized binaries such as crond, agetty, atd, sshd, and polkitd.

Discover Related Resources