Cyware Weekly Threat Intelligence - September 5 - 11, 2026

Autonomous ransomware has crossed a new threshold this week, as JADEPUFFER orchestrates every stage of attack—harvesting credentials, moving laterally, and destroying databases—without human intervention. Cyware spotlights how this AI-driven threat exploits open-source LLM frameworks, leaving victims with no hope of data recovery and forcing urgent patching across the sector.
Critical infrastructure defenders are racing to patch as CVE-2025-5777 (CitrixBleed 2) exposes over 400 NetScaler instances to session hijacking and MFA bypass. CISA’s 24-hour patch mandate underscores the scale of exploitation, with attackers leveraging memory exposure to seize sensitive tokens and disrupt enterprise operations.
A coordinated wave of espionage and ransomware attacks is sweeping through browsers and operating systems, as the BlueMoon exploit chain enables China-aligned groups to compromise aerospace, manufacturing, and government targets. With multiple zero-days in Chrome and Windows now weaponized, defenders face a rapidly evolving threat landscape documented in detail on cyware.com.
Top Malware Reported This Week
JADEPUFFER Ransomware
JADEPUFFER ransomware is a fully autonomous, AI-driven ransomware that orchestrates every stage of the attack lifecycle without human intervention. JADEPUFFER autonomously harvests credentials, moves laterally, establishes persistence, and destroys production databases, demonstrating adaptability by fixing broken logins in seconds. JADEPUFFER exploits vulnerabilities in Langflow, an open-source LLM application framework, to gain unauthorized access and execute its payload. JADEPUFFER employs an ephemeral, unrecoverable encryption key, making data restoration impossible even if victims pay the ransom. JADEPUFFER targets organizations using Langflow and similar open-source frameworks. JADEPUFFER was discovered during incident response investigations into attacks on AI development environments.
DragonForce Ransomware
DragonForce ransomware is a ransomware-as-a-service (RaaS) operation that has evolved from a pro-Palestine hacktivist group into a cartel with LockBit and Qilin, sharing resources and infrastructure. DragonForce affiliates exploit vulnerabilities in SimpleHelp, including path-traversal and arbitrary file-upload flaws, and use the Backdoor.Turn implant to blend C2 traffic with legitimate Microsoft Teams communications. DragonForce leverages legitimate tools like AdFind for network discovery and PsExec for lateral movement. DragonForce gains initial access by exploiting SimpleHelp vulnerabilities and recruiting affiliates with a reduced registration fee of $500. DragonForce has targeted major retailers, including Marks & Spencer, resulting in a statutory profit drop from £391.4 million to £3.4 million and direct response expenses of £136 million.
Medusa Ransomware
Medusa ransomware is a ransomware-as-a-service (RaaS) threat that employs double and triple extortion tactics, encrypting systems and threatening to publish stolen data. Medusa relies on initial access brokers to infiltrate networks and has a structured affiliate payment model, distinguishing it from groups like Qilin, Rhysida, and Cl0p. Medusa gains initial access through brokers and continues to expand its reach, with over 500 victims across critical infrastructure sectors since June 2021. Medusa has notably impacted the University of Mississippi Medical Center, and the FBI, CISA, and HHS have issued an updated advisory highlighting its threat to healthcare and other critical sectors.
Gentlemen Ransomware
Gentlemen ransomware, operated by GOLD SHERWOOD, is a RaaS scheme that uses a double-extortion model, exfiltrating data before encrypting files. Gentlemen affiliates exploit firewall vulnerabilities such as CVE-2024-55591 and abuse VPN credentials, staging tools in C:\PerfLogs and using Advanced IP Scanner and SoftPerfect Network Scanner for reconnaissance. Gentlemen maintains persistence via Cloudflared and Datto RMM, escalates privileges through group membership manipulation, and evades defenses with EDR killers like GentleKiller and by disabling Windows Defender. Gentlemen gains initial access by targeting vulnerable FortiGate firewall interfaces and leveraging the absence of MFA. Gentlemen listed 683 victims by July 2026, with a surge of 169 victims in that month alone, indicating increased affiliate activity.
Gryxa Toolkit
Gryxa is an AI-enhanced malware toolkit that enables financially motivated threat actors to maintain persistence and evade detection, even after partial remediation. Gryxa abuses legitimate remote monitoring and management (RMM) software, distributes hidden files across multiple locations, and employs HTTPS to download additional components while using scheduled tasks and WMI event subscriptions for persistence. Gryxa collects evidence of defender actions, targets saved credentials in Chromium-based browsers, and disables Microsoft Defender if its relay infrastructure is unreachable. Gryxa is delivered via invoice-themed executables and has compromised 324 hosts, with 69 active during analysis.
Top Vulnerabilities Reported This Week
CVE-2025-5777 (CitrixBleed 2)
CVE-2025-5777, also known as CitrixBleed 2, is a memory exposure vulnerability affecting all NetScaler ADC and Gateway deployments configured as a gateway or AAA virtual server, with a critical risk profile similar to CVE-2023-4966. CVE-2025-5777 allows attackers to exploit incorrect login requests to access sensitive memory content, including session tokens, enabling session hijacking and bypassing multi-factor authentication. CVE-2025-5777 is actively exploited in the wild, as confirmed by its addition to CISA's Known Exploited Vulnerabilities catalog after initial disputes from Citrix. CISA issued an urgent directive for federal agencies to patch within 24 hours, highlighting the severity of the threat. Organizations must apply Citrix's patches for NetScaler ADC versions 14.1-43.56, 13.1-58.32, 13.1-FIPS, 13.1-NDcPP 13.1-37.235, and 12.1-FIPS 12.1-55.328, and NetScaler Gateway versions 14.1-43.56 and 13.1-58.32 immediately. Over 400 NetScaler instances remain unpatched, and a related vulnerability, CVE-2025-6543, affects roughly 500 additional deployments.
CVE-2026-59310 (VMware vCenter Server)
CVE-2026-59310 is a path-traversal vulnerability in VMware vCenter Server with a CVSS score of 9.8, enabling attackers to execute arbitrary code without credentials. CVE-2026-59310 is exploited to deploy Babuk-derived ransomware, allowing attackers to gain persistent access via reverse SSH binaries and control virtual machines. CVE-2026-59310 is actively exploited across 47 countries, with predictions of continued exploitation and the potential emergence of additional ransomware variants. Attackers have leveraged CVE-2026-59310 alongside vulnerabilities in SharePoint, IKE Service Extensions, and macOS Screen Sharing, all of which have been added to CISA's Known Exploited Vulnerabilities catalog. Broadcom has issued an emergency patch for CVE-2026-59310, and organizations are advised to restrict network access to vCenter management interfaces and audit backup and recovery procedures. The exploitation landscape is being closely monitored by cybersecurity vendors and insurance underwriters, with particular concern for defense, aerospace, and government sectors.
BlueMoon Exploit Chain (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880)
The BlueMoon exploit chain comprises CVE-2026-85046 and CVE-2026-87491, which are remote code execution vulnerabilities in the JavaScript engine for Chromium-based browsers, and CVE-2026-85880, a privilege escalation zero-day in Windows Advanced Local Procedure Call. The BlueMoon chain allows attackers to execute code in the browser sandbox, escape the sandbox, and escalate privileges to gain system-level access. The BlueMoon vulnerabilities are actively exploited in the wild, with initial exploitation by TA412 on August 28, followed by groups such as UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket. These threat groups have targeted sectors including aerospace, manufacturing, and government, using infrastructure created shortly before the campaigns. Organizations should apply patches for CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 as soon as available, monitor for unauthorized access, and implement network segmentation. The ease of adoption of the BlueMoon exploit kit suggests a high risk of further widespread attacks.
CVE-2026-83548 and CVE-2026-83549 (SonicWall SMA1000 VPN)
CVE-2026-83548 is a server-side request forgery vulnerability and CVE-2026-83549 is an OS command injection flaw, both affecting SonicWall SMA1000 VPN appliances and enabling unauthenticated remote code execution. Attackers exploit CVE-2026-83548 to route traffic internally and then leverage CVE-2026-83549 to execute arbitrary commands, compromising the trust boundary and gaining root access. Both vulnerabilities are actively exploited in the wild, with the INC Ransomware group linked to attacks targeting organizations in Australia, the United States, and Switzerland. Previous attack waves on SMA1000 appliances have involved malware such as ROOTRUN, KNUCKLEBALL, and ORANGETAIL, highlighting a recurring threat pattern. Organizations must upgrade to firmware version 12.4.3-03526 or 12.5.0-02952, audit for compromise using published IoCs, and reimage compromised appliances. SMA1000 appliances serve as credential aggregators, making them high-value targets for attackers seeking to bypass enterprise perimeters.
CVE-2026-21962 (Oracle HTTP Server and WebLogic Server Proxy-plug-in)
CVE-2026-21962 is a remote code execution vulnerability with a CVSS score of 10.0, affecting Oracle HTTP Server and WebLogic Server Proxy-plug-in, both components of Oracle Fusion Middleware. CVE-2026-21962 allows unauthenticated remote attackers to compromise servers, leading to unauthorized access, data breaches, and service disruption. CVE-2026-21962 is actively exploited in the wild, with Defused reporting exploitation attempts shortly after Oracle released a patch and CISA mandating U.S. government agencies to apply the patch within three days. Oracle has not provided detailed technical information about CVE-2026-21962, underscoring the urgency and limited visibility for defenders. Organizations must immediately apply the security update released by Oracle on January 20, 2026, monitor for signs of compromise, and ensure all affected systems are updated. The vulnerability impacts critical middleware infrastructure, increasing the risk of widespread exploitation.
Top Threat Actors Reported This Week
TA412 and Associated China-Aligned Groups
TA412 (alongside UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket) is a cluster of China-aligned espionage groups primarily motivated by intelligence collection. TA412 exploited a chain of zero-day vulnerabilities—CVE-2026-85046 and CVE-2026-87491 (remote code execution in Chromium-based browsers) and CVE-2026-85880 (privilege escalation in Windows Advanced Local Procedure Call)—to achieve code execution and system privileges. TA412 leveraged phishing emails to deliver malicious browser extensions, while UNK_LateNight deployed ShadowPad backdoors via DLL sideloading, UNK_DoubleCheck used Rust-based malware, and UNK_QuietRacket delivered modified payloads, all utilizing the BlueMoon exploit kit. TA412 and its affiliates targeted US NGOs, commodity firms, aerospace, manufacturing, government, and Southeast Asian financial sectors. TA412 initiated exploitation on August 28, with infrastructure rapidly established to support coordinated campaigns, and the ease of exploit kit adoption signals a high risk of broader attacks.
Lazarus Group
Lazarus Group (believed to be North Korea-affiliated) is a cyber espionage actor focused on strategic intelligence collection. Lazarus Group exploited CVE-2026-68820, a use-after-free vulnerability in the AFD.sys driver (Windows Sockets API), enabling local privilege escalation from standard user to SYSTEM through a race condition. Lazarus Group shifted from BYOVD attacks to abusing built-in Windows components, complicating detection, and deployed the FudModule rootkit post-exploitation. Lazarus Group targeted defense and aerospace sectors in Europe, India, and Brazil during the "Operation Dream Job" campaign. Lazarus Group gained initial access via a trojanized application, escalated privileges using CVE-2026-68820, and maintained persistence for five weeks before Microsoft released a patch on August 11, 2026. The CISA KEV listing and BOD 26-04 compliance requirements underscore the urgency of patching affected systems.
BlueDelta
BlueDelta (also tracked as a Russian state-sponsored group) is primarily motivated by cyber espionage targeting governmental and diplomatic entities. BlueDelta deployed the HOOKEDGE backdoor via macro-enabled Microsoft Word documents, leveraging webhook[.]site for command-and-control and using Microsoft Edge to disguise malicious traffic. BlueDelta targeted government and diplomatic organizations in Romania, Spain, and Türkiye, timing phishing lures with significant political events. BlueDelta used a two-tier malware setup for high-value targets, spreading tasking across multiple webhook endpoints and employing evasion techniques such as increased beaconing intervals and canary tracking pixels. BlueDelta's campaign ran from late September 2025 through early April 2026, with infrastructure designed to blend malicious activity with legitimate web traffic.
Fire Ant
Fire Ant (China-linked, with overlap to UNC3886) is a cyber espionage group targeting network infrastructure for intelligence collection. Fire Ant compromised Cisco IOS XR routers, TACACS servers, and Linux management hosts, using custom malware to suppress logs and telemetry and employing the TacTap toolset for credential theft. Fire Ant targeted routers to capture network traffic and credentials, leveraging the | exclude filter to hide tunnel configurations and using an XOR key 0xEF for credential obfuscation. Fire Ant focused on organizations with critical network infrastructure, including those using Cisco routers and TACACS authentication. Fire Ant's campaign began with anomalous router activity, followed by lateral movement to legacy Linux systems and deployment of implants such as BridgeAgent and custom rootkits. Organizations are advised to treat routers, TACACS servers, hypervisors, and jump hosts as critical forensic assets and validate logs against multiple evidence sources.
Tortoiseshell
Tortoiseshell (Iranian-linked, affiliated with the IRGC) is an advanced persistent threat group focused on supply chain compromise and military intelligence. Tortoiseshell expanded its infrastructure with new malware, including an SSH-based tunneling utility and the TWOSTROKE backdoor, both masquerading as Windows DLLs. Tortoiseshell used domains and IPs such as 172[.]86[.]98[.]113 and 185[.]253[.]116[.]81 for C2 communication and malware deployment, targeting defense, aerospace, IT service providers, and military organizations in the Middle East and Europe. Tortoiseshell's SSH tunneling tool established encrypted connections for data exfiltration, while TWOSTROKE executed commands, uploaded files, and communicated with multiple C2 servers using a custom protocol. Tortoiseshell has been active since at least 2018, with recent campaigns revealing expanded targeting and infrastructure.
Frequently Asked Questions
What is JADEPUFFER? JADEPUFFER ransomware is a novel, fully autonomous AI-driven ransomware that orchestrates every stage of the attack lifecycle without human intervention. JADEPUFFER autonomously harvests credentials, moves laterally, establishes persistence, and destroys production databases, demonstrating adaptability by fixing broken logins in seconds.
What is DragonForce? DragonForce ransomware is a ransomware-as-a-service (RaaS) operation that has evolved from a pro-Palestine hacktivist group into a cartel with LockBit and Qilin, sharing resources and infrastructure. DragonForce affiliates exploit vulnerabilities in SimpleHelp, including path-traversal and arbitrary file-upload flaws, and use the Backdoor.Turn implant to blend C2 traffic with legitimate Microsoft Teams communications.
What is Medusa? Medusa ransomware is a ransomware-as-a-service (RaaS) threat that employs double and triple extortion tactics, encrypting systems and threatening to publish stolen data. Medusa relies on initial access brokers to infiltrate networks and has a structured affiliate payment model, distinguishing it from groups like Qilin, Rhysida, and Cl0p.
What is Gentlemen? Gentlemen ransomware, operated by GOLD SHERWOOD, is a RaaS scheme that uses a double-extortion model, exfiltrating data before encrypting files. Gentlemen affiliates exploit firewall vulnerabilities such as CVE-2024-55591 and abuse VPN credentials, staging tools in C:\PerfLogs and using Advanced IP Scanner and SoftPerfect Network Scanner for reconnaissance.
What is Gryxa? Gryxa is an AI-enhanced malware toolkit that enables financially motivated threat actors to maintain persistence and evade detection, even after partial remediation. Gryxa abuses legitimate remote monitoring and management (RMM) software, distributes hidden files across multiple locations, and employs HTTPS to download additional components while using scheduled tasks and WMI event subscriptions for persistence.
What is TerminalFix? TerminalFix is a sophisticated malware campaign, related to ClickFix, that uses a multi-stage attack chain involving DLL sideloading, steganographic payload extraction, and a reverse-tunnel implant for persistent network access. TerminalFix establishes persistence via registry keys and scheduled tasks, conducts reconnaissance such as domain trust enumeration, and deploys a reverse-tunnel implant to maintain access.
What is CVE-2025-5777? CVE-2025-5777, also known as CitrixBleed 2, is a memory exposure vulnerability affecting all NetScaler ADC and Gateway deployments configured as a gateway or AAA virtual server, with a critical risk profile similar to CVE-2023-4966. CVE-2025-5777 allows attackers to exploit incorrect login requests to access sensitive memory content, including session tokens, enabling session hijacking and bypassing multi-factor authentication.
What is CVE-2026-59310? CVE-2026-59310 is a path-traversal vulnerability in VMware vCenter Server with a CVSS score of 9.8, enabling attackers to execute arbitrary code without credentials. CVE-2026-59310 is exploited to deploy Babuk-derived ransomware, allowing attackers to gain persistent access via reverse SSH binaries and control virtual machines.
What is CVE-2026-85046? The BlueMoon exploit chain comprises CVE-2026-85046 and CVE-2026-87491, which are remote code execution vulnerabilities in the JavaScript engine for Chromium-based browsers, and CVE-2026-85880, a privilege escalation zero-day in Windows Advanced Local Procedure Call. The BlueMoon chain allows attackers to execute code in the browser sandbox, escape the sandbox, and escalate privileges to gain system-level access.
What is CVE-2026-83548? CVE-2026-83548 is a server-side request forgery vulnerability and CVE-2026-83549 is an OS command injection flaw, both affecting SonicWall SMA1000 VPN appliances and enabling unauthenticated remote code execution. Attackers exploit CVE-2026-83548 to route traffic internally and then leverage CVE-2026-83549 to execute arbitrary commands, compromising the trust boundary and gaining root access.
What is CVE-2026-21962? CVE-2026-21962 is a remote code execution vulnerability with a CVSS score of 10.0, affecting Oracle HTTP Server and WebLogic Server Proxy-plug-in, both components of Oracle Fusion Middleware. CVE-2026-21962 allows unauthenticated remote attackers to compromise servers, leading to unauthorized access, data breaches, and service disruption.
What is TA412? TA412 (alongside UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket) is a cluster of China-aligned espionage groups primarily motivated by intelligence collection. TA412 exploited a chain of zero-day vulnerabilities—CVE-2026-85046 and CVE-2026-87491 (remote code execution in Chromium-based browsers) and CVE-2026-85880 (privilege escalation in Windows Advanced Local Procedure Call)—to achieve code execution and system privileges.
What is Lazarus Group? Lazarus Group (believed to be North Korea-affiliated) is a cyber espionage actor focused on strategic intelligence collection. Lazarus Group exploited CVE-2026-68820, a use-after-free vulnerability in the AFD.sys driver (Windows Sockets API), enabling local privilege escalation from standard user to SYSTEM through a race condition.
What is BlueDelta? BlueDelta (also tracked as a Russian state-sponsored group) is primarily motivated by cyber espionage targeting governmental and diplomatic entities. BlueDelta deployed the HOOKEDGE backdoor via macro-enabled Microsoft Word documents, leveraging webhook[.]site for command-and-control and using Microsoft Edge to disguise malicious traffic.
What is Fire Ant? Fire Ant (China-linked, with overlap to UNC3886) is a cyber espionage group targeting network infrastructure for intelligence collection. Fire Ant compromised Cisco IOS XR routers, TACACS servers, and Linux management hosts, using custom malware to suppress logs and telemetry and employing the TacTap toolset for credential theft.